Showing posts with label Investigators. Show all posts
Showing posts with label Investigators. Show all posts

Sunday, June 14, 2015

Android Copy and Paste - what risks?

This discussion may be relevant and useful to the process of evidence gathering, eDiscovery investigations and examiner procedures. Experienced examiners or investigators, new to industry or students that may be unaware of this subject matter.

The Android clipboard-based framework (Android Content Provider) enables copy and paste directly to and from the clipboard not only of simple text but also complex data structures, text and binary stream data and application assets.


Key Classes

- ClipboardManager
- ClipData
- ClipData.Item
- ClipDescription
- Uri
- ContentProvider
- Intent
This content provider enables the distribution of objects stored on the clipboard to be distributed among user applications subject to the permission granted for copying and pasting outside of a particular application.
The practical application for using clipboard copy and paste might be generally understood by smartphone users but the less experienced smartphone user may not know or realise that items stored on the clipboard may still reside in memory on particular smartphones long after the paste function was used. The same might also apply to examiners relying on extracted and harvested data from a DUT (device under test) using a particular examination tool of choice. The tool may not logically recover clipboard objects. Moreover, the copied data may not be distinguishable from a deleted SMS message when carving data from a physical extracted dump (JTAG/chip off), so checking the clipboard identifies is important.
 
 
Conduct a test on a smartphone of your choice. Tests run on a random number of makes/models not all were found to allow revisiting pasted data from previous copying, not all allowed data copied in one application (e.g. WhatsApp) to be made available to another (e.g. text messaging). Thus, manual examination might need to be applied during an examination process in order to determine during discovery any vital data (evidence) excluded during a tool’s recovery procedure.
As there are variances between makes/models it equally raises concerns of any missed opportunities to recover data during past examination.
DUT – Samsung GT-I9100P
 
 
Android OS version – Ice Cream Sandwich

COPY AND PASTE

The manual examination test applied: select a new, blank SMS test message page and apply continued finger pressure to the text message field. The DUT vibrates and the dialogue box offers two options: PASTE or CLIPBOARD (see image below). Select CLIPBOARD.



The DUT responds with multiple choice of previously copied data that may be reused.  The first entry box is a copy message from the Samsung SMS text message application. The copied data with a stated date and time stamp in the fourth entry box is data copied from a message in WhatsApp.



Note the format change of the date and the clock is out by one minute, when cross-referenced to the WhatsApp image below. Is this down conversion from one application to another?  Are there two clocks being used on the same smartphone? Was the SMS message created first and copied and pasted into WhatsApp? Or is it something else?



Further issues to be considered. Subject to the matter as mentioned above regarding permission granted to copy and paste outside of a particular application; Android in itself does not require any permission to be entered to write data to or read data from the clipboard. Consequently, this can leave a security loophole in place where an application requires a user to copy their credentials (passwords, PINs etc.) first before the user may make use of an application.
Moreover, the android.content.ClipboardManager.OnPrimaryClipChangedListener is an interface within Android SDK enabling listener call-back that is invoked each time a clipboard item changes. A change in password, PIN etc updated by a particular application could update the clipboard previously stored data. This could be problematical by causing a breach in security if malware were to be unintentionally installed to the smartphone and then credentials leaked to an outside source. The smartphone security for copy and paste therefore can only be as good as the permission granted within the applications being installed and used.

Observations. When making analysis of security an examiner/investigator simply referring to the latest makes/models of smartphones or apps on the market may well be flawed in using that analytical approach. There are a considerable number of handsets out there which are in use on a day-to-day basis for work and personal activity. These can be e.g. 5yrs to 10yrs old. Operators are currently offering an alternative to subsidised handsets by offering SIM ONLY contracts. The smartphone won’t be updated. Companies may well fail in their fiduciary responsibilities and duty of care at board level owed to the company to offload natural company expenditure by avoiding providing communication devices to company employees. To foster the notion to employees to BYOD (bring your own device) the employee is in fact playing a part in subsidising a company’s communications system and therefore its security; retains the opportunity for security loopholes to be created by employers assuming that smartphone users know everything about their smartphone, which is a fallacy.

Saturday, September 22, 2012

Threats and Forcing SMS delay

Following my article France Car Shootings and Mobile Evidence http://www.trewmte.blogspot.co.uk/2012/09/france-car-shootings-and-mobile-evidence.html an investigator, previously working with a well-known cellular and fixed network manufacturer, confirmed to me the results of an internal forensics investigation which he conducted.


An employee had made threats to a Director. The employee had been found to use a 'prepaid sim' card to send theat messages but added a delay period for the sent messages of 2-hours. The employee then switched OFF the handset and inserted the company SIM card into the same handset which had previously held the prepaid SIM that had sent the threat messages. The handset with the company SIM card in it was then switched ON; the employee claimed not to have been responsible for the threats sent from a different IMSI (SIM card).  The intention of the employee was to mask any connection with the threats. However, tracing the IMSIs of the prepaid SIM card and the company SIM card found both to have been operating in the same handset (IMEI). Such trace capability can be made from enquiries of network databases such as BTS, HLR etc. Moreover with high levels of text messaging that are sent and received whilst roaming there is trace capability that can be made by interrogating CAMEL.

There is also useful data that can be obtained for linking with cell site analysis (CSA), which is a bonus although there appears to be some confusion occuring in the US at the moment as to the value of CSA evidence http://www.forensicfocus.com/Forums/viewtopic/t=9679/ and how the material may be applied on a case by case basis. I am not convinced that licenced operators with highly developed as they are in the US cellular networks simply could not/would not sufficient call record/cell data available to know what is happening when an MS has been active in their networks, about the arrangement at a particular mast (cell tower) as used by an MS, the configuration of the radio network operating at the time an MS has been used and so on.

Monday, September 17, 2012

France Car Shootings and Mobile Evidence

France Car Shootings and Mobile Evidence

It is well known by now that the team investigating the shootings in the French Alps discovered two mobile phones: http://news.sky.com/story/982481/alps-shootings-police-find-two-phones-in-car. The following has nothing to do with the French authorities investigation and does not seek to speculate on what might be. However the case is very useful in that it provides a useful example to apply a conceptual method to seeking out evidence originally discussed in my thread back in January 2009: http://www.trewmte.blogspot.co.uk/2009_01_01_archive.html.

The diagrams below illustrate one method of taking a crime scene event and postulating the possibilities of mobile phone evidence and mobile events that might occur prior to and after e.g. a murder. Yes, it is quite possible that activity on a victim's switched ON mobile phone may still occur after the victim's death. This is in addition to evidence that can accrue when it is switched OFF.  





To assist the investigation to make it a more managable task for this case scenario discussion the investigator/examiner can separate, but without severing the links, the case into four stages:

 i) possible evidence before and leading upto the crime
 ii) possible evidence at the approximate time of (a)shooting, (b)death
iii) possible evidence when attending the scene of crime
 iv) possible evidence that might still be collated post scene of crime 

The depth and breadth of mobile evidence has substantially increased given the evolving and fast developmental pace of mobile technology and services. To try and discuss all of them would over-complicate this discussion, so the discussion will consider the diagram below and highlight possible mobile evidence and events iv).

The previous 2009 discussion (link given above) needs to be read to understand the diagram below, after which an examiner/investigator then begin to recognise where possible post crime mobile evidence might be generated/occur and create a check list of those possibilities.   


Using the 'C now' constant this could represent the position of the investigation in physical space, say where the two mobiles have been recovered but still at the scene of crime. Time is important, too, and therefore the investigator (hypothetically, of course, for this discussion) records a time one-hour after mobile phones recovered at the crime location. This is important for timeline because anything occurring before that time have one set of evidential/event values (prior to approximate time of death) and evidence/events occurring after have another set of evidential values (post approximate time of death). By way of illustrating the latter, the dead victim wont be operating the handset his/herself so that fact is important, but that doesn't exclude the possibility the victim, prior to death, having pre-programmed the handset to do something (e.g. send a birthday text, set an alarm and so on).  

The perpetrator/s fled the crime scene and therefore the time delay occuring between that and the discovered mobile phones could be minutes/hours/days. The race is on to catch up if the investigation is not to be caught up on the tide of diminishing returns. 

The use of text messaging is prolific and therefore knowing which material to discard and which is important evidence is not an easy task. Commonly, texting is perceived on the basis that a user:

- sends and receives texts
- known or unknown called/calling party  
- content based upon 'familiarity' of communicating parties

There is a whole host of investigative information that may need to be practically assessed as to possibility of text occuring on a mobile phone after a victim's death, such as:

- text generated by mobile phone as opposed to text generated on PC sent via the internet e.g: check the SMS header details:

Originating Address type: 91
Type of number: International
Numbering plan identifier: E.164
Originating Address: 44798021XXXX

and where you see 'Originating address' that does not contain the commonly understood mobile telephone number (E.164) but it contains an hex-decimal representation then it might indicate the message originated from the internet. Example

Originating Address type: 91
Type of number: International
Numbering plan identifier: E.164
Originating Address: 35fac2457c0be2008

To start with go back to basics (this is necessary due to the requirements of backward compatibility) and check out GSM standards GSM-0340; 0338, 0411, 0902 etc

- text maybe generated due to a set-calendar event e.g. check user profiling relevant to proactive SIM, STKs and handset calendar

- text may appear as an SMS but what if it is Wi-Fi direct data e.g. depending make/model of mobile phone check settings such as 'wireless and network'

What can happen when received test messages arrive later than the date the text was originated and sent? - http://trewmte.blogspot.co.uk/2007/10/conflicts-call-records-sms-delivery.html - Local and roaming issues maybe relevant?

Check also SMS 'validity period' for sent text messages, thus messages can be held in 'escrow' by a network operator. See GSM 11.11; 3GPP 31102



Additional time values for 'Validity Period' can be found in GSM03.40



There can be other aspects of post-crime related mobile evidence activity on a victim's mobile phone, such as voicemail. Moreover, cell site analysis can have a role here too for a switched ON mobile phones and post-crime generated evidence.

Determining possible evidence and events on a mobile phone or mobile account,, for that matter, which may occur post-crime might be highly beneficial in death, kidnap or missing person cases. 

Saturday, July 28, 2012

Clueful knows what iPhone apps are doing



For those wishing to retain privacy or those involved in eDiscovery, investigation, examination and/or evidence Bitdefender's Clueful identifies deviant apps on an iPhone currently running in memory allowing user's to identifying what an apps is doing and read an audit report accessed at Clueful Cloud. The audit report identifies:
  • which apps can access your address book;
  • which apps gather analytics in order to monitor you;
  • which apps can track your location;
  • which apps can access your Facebook or Twitter credentials;
  • which apps display ads;
  • which apps drain your battery through their improper use of background services, such as GPS or audio services.
This is one of those tools which highlights why mobile/smart phone examination is not simply limited to physical and logical data extraction but places an emphasis on examiners/investigators having additional capability to possess a wide range of information beyond harvested data and provide interpretations about possible activities on a particular handset.

Faqs - http://www.cluefulapp.com/faq.html