Showing posts with label Samsung. Show all posts
Showing posts with label Samsung. Show all posts

Sunday, July 23, 2017

USER INVASION TESTS ON SAMSUNG GALAXY J3-6 J320FN

 
Smart Switch is a useful back-up and restore tool for particular user-content on various (but not all) Samsung smartphones. To coin a phrase the program "does what it says on the tin". For general user back-up and restore of certain data it avoids the need for uploading to the cloud.
 
We've been running some tests to see if Samsung Smart Switch back-up/restore utility could be used for capturing forensic images from e.g. the J3. The program was initially checked using CFF to check the internals to find files guarded by MD5 and SHA-1:
 
 
Before forensic examinations are undertaken we ran tests as a user and purchased 3 x J3.
 
 
The J3 handsets were UK versions:
 
 
We see the US versions are compatible for use with Samsung Knox for BYOD:
 
 
This is an early evaluation, so the post is just a heads-up so you can check within your organisation/s.
 
This post is not a legal notice or  anything else.

Thursday, February 23, 2017

Secrets and Evidence of Older Mobiles

It is good to learn that the Nokia 3310 may make a return, albeit with an Android operating system. The nostalgia for these types of mobile phones has clearly not been lost. What it might suggest is that consumers still want a mobile telephone to remain a mobile telephone and to look like one.

The older mobile phones I have in mind though are the ones that are still used in examinations, investigations and research. Since there is nostalgic sentiment in the air I thought you might be interested in some examples of older mobile phones from my lab toolkit.


Now these old buzzards are used for basic GSM telephony services. There isn't a universal SIM that will work with these as some from my collection operate with a 5-volt SIM and so on. Importantly they are used due to the fact they have an external antenna and extendable external antenna. In some investigation instances RSSI will show network detection and a small amount of RF power whereas mobiles/smartphones with embedded antennas show Emergency Calls Only.

You might recall I have written numerous articles on radio surveys and two that may seem appropriate to this discussion are:

CSA: Mobile Phones and Fringe Coverage
http://trewmte.blogspot.co.uk/2010/06/csa-mobile-phones-and-fringe-coverage.html

GSM Radio Test Measurements
http://trewmte.blogspot.co.uk/2010/06/gsm-radio-test-measurements.html

The next selection of mobiles/smartphones each provide different radio characteristics due to the manufacturer's selection of RF chipset and functionality.


My five beauties, as I call them, are my Nokia 3210s. Great phones and they still operate perfectly well today. You can also see in the photo that all bar one mobile have embedded antenna. Some are mobile phones and some are smartphones. Combined they offer the ability for RF surveys and testing voice telephony, data downloads, instant messaging etc. The common laptop application Network Monitor (NMonitor/NetMonitor) still provides good feedback when connected to the Nokia 3210 (nmon activated). Blackberry requires a bit of setting up with applications such as MagicBerry, BBHTool, etc., and creating JAD-files (depending on what you want to achieve). Now with the Samsung models GT-I8160 and GT-I9100 both are used with 2G and 3G networks and illustrates the point that two models of smartphone from the same manufacturer display didn't RF survey details.


Now I wont bore you with an explanation of the details just to say these investigation RF surveys require knowing the various ServiceMode states. In particular, if you are conducting a PRACH and RACH survey, relevant to investigations for Access Requests (e.g. the phone is not in idle mode but seeking a service), then the GT-I9100 is useful in that it displays not just the LAC but also the Cell ID the RACH (access) request was made. Quite a few mobiles do not do this when looking into the ServiceMode states. You have to be quick, mind you, as the ServiceMode screen changes fairly quickly if you are not ready to take a photo.


Yet another, quite old-ish, mobile phone that I haven't shown so far is the Nokia 6303. The photo shown below should explain everything. But for those not familiar to testing and examination; where a charge in the billing appears for an SMS or at least details of a called number sent an SMS (even if sent message is free) it is quite possible the party receiving the message can read it but the message wont be saved. This is known as a Class 0 message (commonly referred to as a Flash Message). Depending on make and model of mobile phone, part or all of the message which is only held in RAM might still be recoverable, provided seizure and examination is undertaken and completed fairly quickly, as RAM is updating perpetually. 



The Nokia 6303 is one of those mobiles that the handset manufacturer in combination with mobile network operator enabled this feature as they foresaw revenue generation from it and also recognised that a reasonable memory storage capacity in handset and SIM card need not be blocked up with trivial messages.

The 6303 came with a 940 MB memory card for downloaded applications etc. This proved to be useful in an investigation where text messages didn't have alphabet characters but a series of dots and dashes. At first it was thought this was incomplete text chat messages or some sort of smiley face that didn't form properly when typed on the screen.



When reviewing hundreds of text messages recovered from a mobile or smart phone it is quite easy to overlook or ignore a message as being meaningless. However, I researched the matter and following testing the message turned out to be Morse Code. I tracked down the application for this and cross-checked with the device that had been examined.

            

So next time you see a text message with an odd presentation look closely to see if it has relevance and whether your mobile phone forensic suite software has the capability to either identify the message contains additional features or can translate the message.

Hope you have enjoyed this brief look at older mobile phones used in and for mobile forensic examination, investigations and research.

Sunday, June 14, 2015

Android Copy and Paste - what risks?

This discussion may be relevant and useful to the process of evidence gathering, eDiscovery investigations and examiner procedures. Experienced examiners or investigators, new to industry or students that may be unaware of this subject matter.

The Android clipboard-based framework (Android Content Provider) enables copy and paste directly to and from the clipboard not only of simple text but also complex data structures, text and binary stream data and application assets.


Key Classes

- ClipboardManager
- ClipData
- ClipData.Item
- ClipDescription
- Uri
- ContentProvider
- Intent
This content provider enables the distribution of objects stored on the clipboard to be distributed among user applications subject to the permission granted for copying and pasting outside of a particular application.
The practical application for using clipboard copy and paste might be generally understood by smartphone users but the less experienced smartphone user may not know or realise that items stored on the clipboard may still reside in memory on particular smartphones long after the paste function was used. The same might also apply to examiners relying on extracted and harvested data from a DUT (device under test) using a particular examination tool of choice. The tool may not logically recover clipboard objects. Moreover, the copied data may not be distinguishable from a deleted SMS message when carving data from a physical extracted dump (JTAG/chip off), so checking the clipboard identifies is important.
 
 
Conduct a test on a smartphone of your choice. Tests run on a random number of makes/models not all were found to allow revisiting pasted data from previous copying, not all allowed data copied in one application (e.g. WhatsApp) to be made available to another (e.g. text messaging). Thus, manual examination might need to be applied during an examination process in order to determine during discovery any vital data (evidence) excluded during a tool’s recovery procedure.
As there are variances between makes/models it equally raises concerns of any missed opportunities to recover data during past examination.
DUT – Samsung GT-I9100P
 
 
Android OS version – Ice Cream Sandwich

COPY AND PASTE

The manual examination test applied: select a new, blank SMS test message page and apply continued finger pressure to the text message field. The DUT vibrates and the dialogue box offers two options: PASTE or CLIPBOARD (see image below). Select CLIPBOARD.



The DUT responds with multiple choice of previously copied data that may be reused.  The first entry box is a copy message from the Samsung SMS text message application. The copied data with a stated date and time stamp in the fourth entry box is data copied from a message in WhatsApp.



Note the format change of the date and the clock is out by one minute, when cross-referenced to the WhatsApp image below. Is this down conversion from one application to another?  Are there two clocks being used on the same smartphone? Was the SMS message created first and copied and pasted into WhatsApp? Or is it something else?



Further issues to be considered. Subject to the matter as mentioned above regarding permission granted to copy and paste outside of a particular application; Android in itself does not require any permission to be entered to write data to or read data from the clipboard. Consequently, this can leave a security loophole in place where an application requires a user to copy their credentials (passwords, PINs etc.) first before the user may make use of an application.
Moreover, the android.content.ClipboardManager.OnPrimaryClipChangedListener is an interface within Android SDK enabling listener call-back that is invoked each time a clipboard item changes. A change in password, PIN etc updated by a particular application could update the clipboard previously stored data. This could be problematical by causing a breach in security if malware were to be unintentionally installed to the smartphone and then credentials leaked to an outside source. The smartphone security for copy and paste therefore can only be as good as the permission granted within the applications being installed and used.

Observations. When making analysis of security an examiner/investigator simply referring to the latest makes/models of smartphones or apps on the market may well be flawed in using that analytical approach. There are a considerable number of handsets out there which are in use on a day-to-day basis for work and personal activity. These can be e.g. 5yrs to 10yrs old. Operators are currently offering an alternative to subsidised handsets by offering SIM ONLY contracts. The smartphone won’t be updated. Companies may well fail in their fiduciary responsibilities and duty of care at board level owed to the company to offload natural company expenditure by avoiding providing communication devices to company employees. To foster the notion to employees to BYOD (bring your own device) the employee is in fact playing a part in subsidising a company’s communications system and therefore its security; retains the opportunity for security loopholes to be created by employers assuming that smartphone users know everything about their smartphone, which is a fallacy.

Tuesday, December 11, 2012

A European Focused Mobile Consumer Survey

A European Focused Mobile Consumer Survey

Informa Telecom and Media have published the results of their Smartphone Usage and Behaviour Survey 2012 conducting the survey in four european countries UK, Spain, Germany and the Netherlands http://www.informatandm.com/mobile-consumer-survey/ .

The results for the UK identified the brand of mobile phone owned in particular age groups.













The responses to the survey confirm that the smartphone market in the UK is segmented and therefore mobile operators attempting to forecast device usage and data/services activity may require enabling customers the selection and choice of a range of platforms to sink their teeth into optimising any consumer initiative to enable the growth of smartphones to continue.

For examiners the survey illustrates that predominantly the smartphones to be examined fall into a fairly small category, which could be quite useful for forecasting future examinations and, in particular, the expenditure on tools etc.

Saturday, May 26, 2012

Trace Log Generator

Trace Log Generator

I am looking into creating a new handset tool that generates a trace log of commands sent to the handset and responses received.

Quite a few times I have raised this and largely there is a stone-wall silence about why examiners 'cannot' or 'will not' provide the actual trace log associated with their examination, so that this can be checked. That is an unhealthy taboo to be active in forensics (and for evidence) and needs to be side-stepped.

The idea of the trace log that produces units of information and exported for consideration is similar to that generated by some imaging tools, which allow, as complete as possible, an examination.

This tool I believe should not compete with current tools in the same way that they perform, but the trace log should be inexpensive as the generated file will be a trace log, secured in such a manner that the original should not be altered by accident and when an examination takes place should avoid accidental contamination of the original. However, the managed principle extraction technique is based upon starting at binary and working upwards in order to allow the data to be viewed through independent products.

Additionally, I expect the trace log generator to perform tracing on a make-by-make basis, which means there should be a trace log generator module for each make. This will allow examiners to only buy what they need as opposed to have the reading capability of X-makes/models where it is an extremely low probability of examiners coming into contact with them.

There is a list of benefits but I suspect two key objectives that will benefit in the mobile forensics industry

1) Those whose job requirement limits them to push-button selection for reading an exhibit can produce the trace log first and then use another tool

2) Those who are experienced can use the trace log without needing to hector the less experienced to qualify what they have done during the acquistion examination period.

Additionally, I also envisage some form of (self)employment to arise out of this where programmers can create modules within the framework of the trace log generator and share in the revenue generation stream and at the same time see their contribution in a product generated by and for the forensic community.

I liked to know what you think?

Sunday, May 20, 2012

Evidence is one thing, Understanding is another

Evidence is one thing, Understanding is another

I like Nokia. They were in at the beginning and presented the World with options, and so many walked behind, in their footsteps.  The Nokia 110 and 112 still hasn't stopped the examiner from seeing potential evidence:


Seeing through the eyes of experienced examiners:


Mobile phones - understanding their contribution to evidence.

Sunday, April 01, 2012

Blinking Ice Cream Sandwich (ICS)

Blinking Ice Cream Sandwich (ICS)

Security issue concerns raised about Samsung's 'Face Unlock' has received a boost in the new OS upgrade release of ICS as it is reported to contain an additional security feature requiring the user to 'blink', in addition to existing security already in place, according to global.samsungtomorrow. So for those who thought using a photo of the user for 'Face Unlock' now could require, additionally, a moving image of the user blinking. Whether that requires the genuine user to blink naturally or forced blinking is unclear. Certainly something else to consider when dealing with a DUT with ICS OS during mobile phone examination.

Sunday, July 03, 2011

HTML5: holds a future for and after other mobile apps

HTML5: holds a future for and after other mobile apps

I have just written about mobile apps and forensics (windows-phone-apps-reach-new-market) because it is here and now and requires attention. An aspect of Forensics though is equally not being blinked to future trends. The question of future trends was asked by the House of Commons Science and Technology Committee in their recent report cmselect 855. It is really worth the time and effort to download and read this report.

HTML5 is a future trend and one that has already started to take hold. As nebusiness's The Journal pointed out (http://www.nebusiness.co.utechnology-leap-set-to-make-apps-redundant) "HTML5 builds on the technology of the existing internet but, as every web user knows, if you lose your connection, you lose your work. With HTML5 you don’t – you can go from connected to disconnected and never notice: files can be saved locally and remotely when needed, just like normal apps. Quietly, we’re starting to see more HTML5 apps, like that of the FT, which work on all devices. The FT app is amazing. Try it out. It’s all in HTML5 and as good as, if not better, than a native iPhone app."

With HTML5 there is a sense that forensics might see improvement in interpreting data that could be properly rendered for viewing; currently this can require other apps to assist that process. Moreover, vast quantities of unintelligible random code and data which could not be rendered by handsets can be found during physical dumps that no one really makes sense to identify what it is. Were unravelling and decoding of random code/data to be explained in itself it still might not explicitly or implicity confirm whether the handset user could see/access rendered versions of that code and data on the handset screen or select content by using the handset UI. HTML5 may yet assist in solving some of these issues, so is it a future trend forensic practitioners should be aware?

Well, I think it is something that cannot be excluded largely due to the fact it is at present being used, mobile browsers are making use of it and widely used mobile handsets support or portions of it in e.g. Apple's iOS 4.2, Android, Samsung, Nokia and so on.

So what can HTML5 do for mobile web browsing?
Well, it helps standardise those issues which had previously been problematical to mobile web browsing and, for mobile web developers, to get testable, cross-platform and standards-based interface for developing content that, prior to HTML5, required _fit_the_need_of_the_technology_ methods or proprietory APIs to achieve the level of rendering needed for rich content and browsing.

HTML5 and Forensics
It opens up the door for new or improved evidence. Do remember, particularly for those readers not involved with forensics, evidence doesn't necessarily mean recovered data that is detrimental or that some massive spying operation is in progress. Mobile HTML5 could have benefits to assist retain data that could help resolve a dispute, track a missing person and so on. Location awareness, localised data caching when mobile connectivity is lost and a range of other features that I shall be discussing later on.

What is possible to say at this stage, omitted data previously breaking the chain of causation needed for forensic evaluation may well be greatly assisted by HMTL5 but without a forensic examiner having to put, metaphorically speaking, all his/her sought artefact-eggs into one evidential-methodology basket. Nice !

Saturday, March 05, 2011

Passcode locked iPhone may still make calls

Passcode locked iPhone may still make calls

We have known for awhile that many users can answer calls on their bluetooth earpiece even though they have the phone keypad lock set to ON. Moreover, handsets like Samsung GT-S5600 with keypad lock ON that have a synchronised bluetooth earpiece can call the last number received (LNR) or the number of the last received text message by simply pushing the key on the earpiece. Even if the user isn't using bluetooth earpiece, many handsets (eg Nokia 6303) with a locked keypad can still allow the user to answer a ringing phone.  

If you have a passcode lock on your iPhone it is possible, where the owner haven't yet changed the voice default security setting from when it was purchased, to still be able to make phone calls or worst still it can allow a thief (if your iPhone is stolen) to make calls with the handset. By switching the default setting to OFF can help prevent this occur. 

The image courtesy of The Register

The passcode lock vulnerability has been reaffirmed in a recent article published at the technology website, The Register: http://www.theregister.co.uk/2011/03/04/iphone_voice_dialling/.

Sunday, February 20, 2011

Mobile Phone Chip Off

Mobile Phone Chip Off

If you have produced or know of a mobile phone chip off video showing methods and techniques for removing ICs/memory from various makes/models of mobile handsets then email (trewmte@gmail.com) your youtube link and then it can be added to the thread 'Mobile Phone Chip Off'.



UPDATED:

Thank you Paul for this N70 video


Nathan, thanks for the SonyEricsson W850 video


Another SE W850 video


Nokia UEM removal




Tuesday, August 03, 2010

One-Size-Fits-All Power Charger

One-Size-Fits-All Power Charger

Manufacturers have agreed to create a single one-size-fits-all power charger, thus the expectation of a standard PSU interface will be used. The approach is being applied to data-enabled mobile phones for models to be distributed in 2011 according to the EU, as reported by Business Week:

http://www.businessweek.com/ap/financialnews/D9H9F7H00.htm?

Business Week identify the manufacturers as Apple, Emblaze Mobile, Huawei Technologies, LGE, Motorola, NEC, Nokia, Qualcomm, Research in Motion (RIM), Samsung, SonyEricsson, TCT Mobile, Texas Instruments.

The news of a single charger has been around for a while but is a useful reminder as apparently the 2011 handsets wont be supplied with charger according to the Business Week article.

Handsets with the new charger design could prove helpful when we are examining mobile phones where there is no charger supplied with the 'exhibit' or the customer's DFE.

Tuesday, November 28, 2006

Samsung Toolbox

Samsung Toolbox



Tests over 17 different models of Samsung Mobile Phones - models: A800, A1xx, T108, N628, N625, N620, N611, N600, N500, N400, N300, N2xx, N1xx, R225, R210, R208, R200,

Features: WinTracer, E2P Manager, Downloader, H/W Tester, Remote Key, Camera Tester, Flash Dump, Environment Tester.

http://system7428.files-upload.com/380870/ToolBox5NewMMI.zip.html

Tuesday, November 07, 2006

Vodafone move to standardise handset software

The Daily Mail City&Finance Page 68 (Tuesday, November 7, 2006) ran a short piece on Vodafone unveiling "plans to become the first mobile operator to standardise the software of its handsets". It is to "slash the number of operating systems it would develop applications for in the next five years". This will reduce to three, that of Microsoft Windows Mobile, Symbian/S60 and Linux.

The three choices Vodafone have made are not bad, but there is always the worry from end-users point of view that they end up with largely a fait accompli, that of limited choices dished up by an operator.

It will be interesting to see whether the handset manufacturers follow suit and downsize their operating systems to comply with Vodafone's plans

Alternatively, the likes of Nokia, Motorola, SonyEricsson, Samsung etc could create mobile 'phones with the appropriate GSM/GPRS/WCDMA/WiFi wireless operating systems on them and allow the general public to profile their handsets with the application features (download) they not only like, but actually want.