Showing posts with label examiners. Show all posts
Showing posts with label examiners. Show all posts

Sunday, June 14, 2015

Android Copy and Paste - what risks?

This discussion may be relevant and useful to the process of evidence gathering, eDiscovery investigations and examiner procedures. Experienced examiners or investigators, new to industry or students that may be unaware of this subject matter.

The Android clipboard-based framework (Android Content Provider) enables copy and paste directly to and from the clipboard not only of simple text but also complex data structures, text and binary stream data and application assets.


Key Classes

- ClipboardManager
- ClipData
- ClipData.Item
- ClipDescription
- Uri
- ContentProvider
- Intent
This content provider enables the distribution of objects stored on the clipboard to be distributed among user applications subject to the permission granted for copying and pasting outside of a particular application.
The practical application for using clipboard copy and paste might be generally understood by smartphone users but the less experienced smartphone user may not know or realise that items stored on the clipboard may still reside in memory on particular smartphones long after the paste function was used. The same might also apply to examiners relying on extracted and harvested data from a DUT (device under test) using a particular examination tool of choice. The tool may not logically recover clipboard objects. Moreover, the copied data may not be distinguishable from a deleted SMS message when carving data from a physical extracted dump (JTAG/chip off), so checking the clipboard identifies is important.
 
 
Conduct a test on a smartphone of your choice. Tests run on a random number of makes/models not all were found to allow revisiting pasted data from previous copying, not all allowed data copied in one application (e.g. WhatsApp) to be made available to another (e.g. text messaging). Thus, manual examination might need to be applied during an examination process in order to determine during discovery any vital data (evidence) excluded during a tool’s recovery procedure.
As there are variances between makes/models it equally raises concerns of any missed opportunities to recover data during past examination.
DUT – Samsung GT-I9100P
 
 
Android OS version – Ice Cream Sandwich

COPY AND PASTE

The manual examination test applied: select a new, blank SMS test message page and apply continued finger pressure to the text message field. The DUT vibrates and the dialogue box offers two options: PASTE or CLIPBOARD (see image below). Select CLIPBOARD.



The DUT responds with multiple choice of previously copied data that may be reused.  The first entry box is a copy message from the Samsung SMS text message application. The copied data with a stated date and time stamp in the fourth entry box is data copied from a message in WhatsApp.



Note the format change of the date and the clock is out by one minute, when cross-referenced to the WhatsApp image below. Is this down conversion from one application to another?  Are there two clocks being used on the same smartphone? Was the SMS message created first and copied and pasted into WhatsApp? Or is it something else?



Further issues to be considered. Subject to the matter as mentioned above regarding permission granted to copy and paste outside of a particular application; Android in itself does not require any permission to be entered to write data to or read data from the clipboard. Consequently, this can leave a security loophole in place where an application requires a user to copy their credentials (passwords, PINs etc.) first before the user may make use of an application.
Moreover, the android.content.ClipboardManager.OnPrimaryClipChangedListener is an interface within Android SDK enabling listener call-back that is invoked each time a clipboard item changes. A change in password, PIN etc updated by a particular application could update the clipboard previously stored data. This could be problematical by causing a breach in security if malware were to be unintentionally installed to the smartphone and then credentials leaked to an outside source. The smartphone security for copy and paste therefore can only be as good as the permission granted within the applications being installed and used.

Observations. When making analysis of security an examiner/investigator simply referring to the latest makes/models of smartphones or apps on the market may well be flawed in using that analytical approach. There are a considerable number of handsets out there which are in use on a day-to-day basis for work and personal activity. These can be e.g. 5yrs to 10yrs old. Operators are currently offering an alternative to subsidised handsets by offering SIM ONLY contracts. The smartphone won’t be updated. Companies may well fail in their fiduciary responsibilities and duty of care at board level owed to the company to offload natural company expenditure by avoiding providing communication devices to company employees. To foster the notion to employees to BYOD (bring your own device) the employee is in fact playing a part in subsidising a company’s communications system and therefore its security; retains the opportunity for security loopholes to be created by employers assuming that smartphone users know everything about their smartphone, which is a fallacy.

Saturday, February 08, 2014

Smart/Mobile Devices Brand Names Listing

Examiners regularly come into contact with Brand name mobile/smart devices and the list is continuously increasing. The problem that increase creates is that there is no one website that holds a complete list.  The listing below identifies how many Brand names I have managed to harvest at this stage. I shall be updating this listing as I go along and adding useful info that examiners may find of interest.

Number - Smart/Mobile Devices Brand Names Listing

3 Skypephone


A - Smart Devices Brand Names Listing

Acer
Airo Wireless
Alcatel
Allview
Altek
Amoi
Amazon
AnexTEK
AnyCool
AnyDATA
Apple
Asus
Archos
Arnova
AT Mobile
AT&T
AU (KDDI)
Audiovox
Auro
Axia

B - Mobile/Smart Device Brand Name Listing

Barnes And Noble
BBK Mobiles
Bell
Bendix King
Benefon
BenQ
BenQ-Siemens
Bird
BlackBerry
Blu
Bluebird
Blumax
BMW
Bookeen
Bushnell


C - Mobile/Smart Device Brand Name Listing

Cal Comp
Camangi
Canmore
Casio
Cat Mobile
Cect
Celkon
Changhong
Changjiang
Cheacomm
China Mobile
Cingular
Claro
CLIE
Concord
Coolpad
Cowon
CPA
Creative
Cricket
CSL



D - Mobile/Smart Device Brand Name Listing

Daewoo
Dallab
Danger
Dapeng
Dell
Donod
Dopod
Doro
Duet



E - Mobile/Smart Device Brand Name Listing

E-Ten
Enol
Emgeton
EMobile
Emporia
EPhone
Era
Ericsson
Eten
Ever
Everex
Evolve
Eyo


F - Mobile/Smart Device Brand Name Listing

Fifth Media
Firefly Mobile
Fly
Fly-Ying
Fujifilm
Fujitsu-Siemens
Fusion Garage



G - Mobile/Smart Device Brand Name Listing

G-Five
G-Tide
Garmin
Garmin-Asus
General Mobile
Gigabyte
Gionee
GiSTEQ
Global High Tech
GlobalSat
Google
GPS Technologijos
Gresso
Grundig


H - Mobile/Smart Device Brand Name Listing

Haier
Handspring
Helio
Hertz
Hewlett Packard (HP)
Highscreen
Hisense
HKC
Holux
Hop-on
HTC
Huawei
Hyundai (Electronics)


I - Mobile/Smart Device Brand Name Listing

IBM
Icemobile
I-mate
I-MOBILE
Innostream
I-node
I-teq
INQ
Insignia
iPAC
iPro
Iridium
I-teq
IzenMobile


J - Mobile/Smart Device Brand Name Listing

Jaga
JCB
Jincen
Jolla
JVC



K - Mobile/Smart Device Brand Name Listing

Karbonn Mobiles
Kendo
Kinpo
KPN
K-Touch
Kyocera



L - Mobile/Smart Device Brand Name Listing

Lark
Laser
Lava
Lemon Mobiles
Lenovo
Levi's
LG
Limited Label
Linx
Lowrance
Lumigon


M - Mobile/Smart Device Brand Name Listing

Magellan
Manta
Mappy
Maxon
MaxWest
MediaTek
Meizu
MemUp
Micromax
MIO
MiTAC
Mitsubishi
Mivvy
Mobiado
Mobin-Nova
Mobistel
ModeLabs
Modeo
Modu
Motorola
MTK
MTT
MWg
myPhone



N - Mobile/Smart Device Brand Name Listing

NavGear
Navin
Navitech
Navman
NDrive
Nec
Neonode
Newgen
Nexian
Nextar
NG Mobile
Nikon
Niu
No Brand
Nokia
Nordic
NotionInk
Novogo
NTT DoCoMo



O - Mobile/Smart Device Brand Name Listing

O2
Okta
Okwap
Olympus
Oppo
Opticon 
Orange
Orsio


P - Mobile/Smart Device Brand Name Listing

Packard-Bell
Palm
Panasonic
Pantech
Papago
Paragon Wireless
Parla
PCD
Pharos
PC-EPhone
Philips
Philips PDA
Pidion
Plum
Pocket Navigator
Prestigio
Psion
Puma


Q - Mobile/Smart Device Brand Name Listing

Qigi
Qool Labs
QStarz
Qtek
Quanta
Quest



R - Mobile/Smart Device Brand Name Listing

Rand-McNally
Reliance
Rogers
Rover
RoverPC


S - Mobile/Smart Device Brand Name Listing

Sagem
Samsung
SanDisk
Sanyo
Saygus
SciPhone
Sendo
Sewon
SFR 
Sharp
Siemens
SiGMATek
Sigmatel
Sim Valley
SK Telecom
SKY
Skype
Smart GPS
Socket Mobile
SoftBank
Sonim
Sony
SonyEricsson
Soutec
Spice
Sprint
Sunno
SVP
SwissCom
Sylvania


T - Mobile/Smart Device Brand Name Listing

TagHeuer
Takara
Tatung
TDS
TechFaithWireless
Telecom New Zealand
Telit
Tel.Me
Telsda
Telstra
Terrestar
Thuraya
Tiger
T-Mobile
TomTom
Torg
Toshiba
Toshiba PDA
TranSystem
Turkcell



U - Mobile/Smart Device Brand Name Listing

Ubiquam
UBiQUiO
UMX
Unnecto
UTano
UTStarcom


V - Mobile/Smart Device Brand Name Listing

Velocity Mobile
Ventus
Verizon
Verzo
Vertu
VeryKool
Videocon
Viewsonic
Virgin Mobile Lobster
Visor
vivo
Vizio 
VK Mobile
Vodafone
Voxtel


W - Mobile/Smart Device Brand Name Listing

WayWay
Wentto
WND


X - Mobile/Smart Device Brand Name Listing

XCute
Xiaomi
XKSSTEL
Xolo
XPhoneX


Y - Mobile/Smart Device Brand Name Listing

Yezz
Yoo Digital


Z - Mobile/Smart Device Brand Name Listing

Zakang
ZAP
ZEN Mobile
Zonda
ZTE

Saturday, September 22, 2012

Threats and Forcing SMS delay

Following my article France Car Shootings and Mobile Evidence http://www.trewmte.blogspot.co.uk/2012/09/france-car-shootings-and-mobile-evidence.html an investigator, previously working with a well-known cellular and fixed network manufacturer, confirmed to me the results of an internal forensics investigation which he conducted.


An employee had made threats to a Director. The employee had been found to use a 'prepaid sim' card to send theat messages but added a delay period for the sent messages of 2-hours. The employee then switched OFF the handset and inserted the company SIM card into the same handset which had previously held the prepaid SIM that had sent the threat messages. The handset with the company SIM card in it was then switched ON; the employee claimed not to have been responsible for the threats sent from a different IMSI (SIM card).  The intention of the employee was to mask any connection with the threats. However, tracing the IMSIs of the prepaid SIM card and the company SIM card found both to have been operating in the same handset (IMEI). Such trace capability can be made from enquiries of network databases such as BTS, HLR etc. Moreover with high levels of text messaging that are sent and received whilst roaming there is trace capability that can be made by interrogating CAMEL.

There is also useful data that can be obtained for linking with cell site analysis (CSA), which is a bonus although there appears to be some confusion occuring in the US at the moment as to the value of CSA evidence http://www.forensicfocus.com/Forums/viewtopic/t=9679/ and how the material may be applied on a case by case basis. I am not convinced that licenced operators with highly developed as they are in the US cellular networks simply could not/would not sufficient call record/cell data available to know what is happening when an MS has been active in their networks, about the arrangement at a particular mast (cell tower) as used by an MS, the configuration of the radio network operating at the time an MS has been used and so on.

Monday, September 17, 2012

France Car Shootings and Mobile Evidence

France Car Shootings and Mobile Evidence

It is well known by now that the team investigating the shootings in the French Alps discovered two mobile phones: http://news.sky.com/story/982481/alps-shootings-police-find-two-phones-in-car. The following has nothing to do with the French authorities investigation and does not seek to speculate on what might be. However the case is very useful in that it provides a useful example to apply a conceptual method to seeking out evidence originally discussed in my thread back in January 2009: http://www.trewmte.blogspot.co.uk/2009_01_01_archive.html.

The diagrams below illustrate one method of taking a crime scene event and postulating the possibilities of mobile phone evidence and mobile events that might occur prior to and after e.g. a murder. Yes, it is quite possible that activity on a victim's switched ON mobile phone may still occur after the victim's death. This is in addition to evidence that can accrue when it is switched OFF.  





To assist the investigation to make it a more managable task for this case scenario discussion the investigator/examiner can separate, but without severing the links, the case into four stages:

 i) possible evidence before and leading upto the crime
 ii) possible evidence at the approximate time of (a)shooting, (b)death
iii) possible evidence when attending the scene of crime
 iv) possible evidence that might still be collated post scene of crime 

The depth and breadth of mobile evidence has substantially increased given the evolving and fast developmental pace of mobile technology and services. To try and discuss all of them would over-complicate this discussion, so the discussion will consider the diagram below and highlight possible mobile evidence and events iv).

The previous 2009 discussion (link given above) needs to be read to understand the diagram below, after which an examiner/investigator then begin to recognise where possible post crime mobile evidence might be generated/occur and create a check list of those possibilities.   


Using the 'C now' constant this could represent the position of the investigation in physical space, say where the two mobiles have been recovered but still at the scene of crime. Time is important, too, and therefore the investigator (hypothetically, of course, for this discussion) records a time one-hour after mobile phones recovered at the crime location. This is important for timeline because anything occurring before that time have one set of evidential/event values (prior to approximate time of death) and evidence/events occurring after have another set of evidential values (post approximate time of death). By way of illustrating the latter, the dead victim wont be operating the handset his/herself so that fact is important, but that doesn't exclude the possibility the victim, prior to death, having pre-programmed the handset to do something (e.g. send a birthday text, set an alarm and so on).  

The perpetrator/s fled the crime scene and therefore the time delay occuring between that and the discovered mobile phones could be minutes/hours/days. The race is on to catch up if the investigation is not to be caught up on the tide of diminishing returns. 

The use of text messaging is prolific and therefore knowing which material to discard and which is important evidence is not an easy task. Commonly, texting is perceived on the basis that a user:

- sends and receives texts
- known or unknown called/calling party  
- content based upon 'familiarity' of communicating parties

There is a whole host of investigative information that may need to be practically assessed as to possibility of text occuring on a mobile phone after a victim's death, such as:

- text generated by mobile phone as opposed to text generated on PC sent via the internet e.g: check the SMS header details:

Originating Address type: 91
Type of number: International
Numbering plan identifier: E.164
Originating Address: 44798021XXXX

and where you see 'Originating address' that does not contain the commonly understood mobile telephone number (E.164) but it contains an hex-decimal representation then it might indicate the message originated from the internet. Example

Originating Address type: 91
Type of number: International
Numbering plan identifier: E.164
Originating Address: 35fac2457c0be2008

To start with go back to basics (this is necessary due to the requirements of backward compatibility) and check out GSM standards GSM-0340; 0338, 0411, 0902 etc

- text maybe generated due to a set-calendar event e.g. check user profiling relevant to proactive SIM, STKs and handset calendar

- text may appear as an SMS but what if it is Wi-Fi direct data e.g. depending make/model of mobile phone check settings such as 'wireless and network'

What can happen when received test messages arrive later than the date the text was originated and sent? - http://trewmte.blogspot.co.uk/2007/10/conflicts-call-records-sms-delivery.html - Local and roaming issues maybe relevant?

Check also SMS 'validity period' for sent text messages, thus messages can be held in 'escrow' by a network operator. See GSM 11.11; 3GPP 31102



Additional time values for 'Validity Period' can be found in GSM03.40



There can be other aspects of post-crime related mobile evidence activity on a victim's mobile phone, such as voicemail. Moreover, cell site analysis can have a role here too for a switched ON mobile phones and post-crime generated evidence.

Determining possible evidence and events on a mobile phone or mobile account,, for that matter, which may occur post-crime might be highly beneficial in death, kidnap or missing person cases. 

Wednesday, November 30, 2011

CDR Toll Ticket

CDR Toll Ticket

Essential to any police inquiry and/or investigation is the availability of mobile network call detail records. Significantly, the data to be found in a CDR usually contains far more detail than data produced in eg compilation records; the latter data being selected based upon the 'subjective' mindset of the person creating the compilations.

Toll Ticket Enquiry is very different from Toll Ticket Analysis as the latter document only extrapolates those fields of data chosen by the person eg making selective choices from data stored in a database; thus an unsuspecting officer with little-to-no-experience may have no concept of the range of fields of data available that could be useful to an inquiry and investigation. Thus any objectivity by the officer to form an appropriate opinion or conclusion might be blocked.     

I have produced below scanned headers from two Vodafone Toll Ticket Enquiry CDRs both dated in February 1998. Both of the headers come from genuine Toll Ticket Enquiry CDRs, the first is for a Toll Ticket relating to call traffic on 13-02-98 on Vodafone's analogue TACS mobile network and produced on the 24-02-98. The second Toll Ticket relates to call traffic on 13-02-98 on Vodafone's digital GSM mobile network and produced on the 21-02-98.  Both were served in evidence in a murder case, thus in the public domain. The scanned headers below do not contain any personal data.  


Vodafone's Toll Ticket Enquiry CDR (TACS)



Vodafone's Toll Ticket Enquiry CDR (GSM)

It is entirely consistent that as an expert I would seek these CDRs in cases (as I did in the above case) in order that I can properly and appropriately advise those who instruct. The two Toll Ticket Enquiry CDRs represent a useful historical guide of events in 1998. It is noteworthy to mention that the GSM and TACS records illustrate the position of a single mobile network operator running two different radio transmission mobile networks at the same time. Moreover, such a feat did not limit or prevent the operator capturing data for CDRs relating to call traffic from its switches (EMX/MSC). Note also the duration of time between the dates of the call traffic CDRs and the production of them. Thus any inquiry or investigation into serious crime in 1998 would or should have had access to such records. So when reading the transcripts from eg two Appeals involving the same case  ( NIHC/QB/2009/50NICA/2011/33 ) and Toll Ticket is mentioned by name, the above provides the reader with some insight as to the data that can be recorded in such CDRs.


Today, of course, CDRs from mobile operators may have changed with respect to the identified fields of data in them or by design due to the system that produced them. I have shown examples elsewhere. Historically and like today the CDRs referred to should not contain fields of data that would compromise security of an operator's secure protocols, encryption keys etc.  Toll Ticket or other types of CDRs are ideal for evidence and provided there is completeness in the data (as opposed to subjective content imported into compilation records) then CDRs are essential to call record analysis (CRA) and cell site analysis (CSA).

Historical and current material on this subject and other subjects are included in my training courses for police and examiners to assist inquiries and investigation to make the best use of data and, as equally as important, how to interpret such data.

Friday, November 13, 2009

Mobile Phones, Security, Economy and Employment

Mobile Phones, Security, Economy and Employment
.
An article in the Telegraph on the 6th November 2009 caught my eye, titled "Inventor of mobile phones says they have become 'too complicated" are the thoughts of Martin Cooper who was th lead engineer at Motorola and made the first mobile phone call in 1973.
.
.
Echos of how complicated mobile phones can be are common views heard from many users. However, we need to make the distinction that complicated doesn't mean they are "functionally unused". As usage and personal data populates many memory areas in mobiles it is because of that "functional use" it is so important to mobile telephone examination.
.
The places where user information proliferates are places in smart phones memory that are simply not being examined by practitioners as they are being led to place too much reliance upon the machinery (reading devices) where the output is being presented parrot fashion. The machinery does not contain the high level of competence necessary to cope with all the aspects associated mobile telephone evidence. Neither, for that matter, does the machinery examine all areas of memory. The current round up of forensic readers on the market simply surf certain quarters where certain information resides in memory. Data recovered can also vary dependent upon the machinery and the machinery recovering data from some makes, models and firmware versions. It is great having tools but they really do not supercede in any shape, manner or form the ability of the knowledge and skills needed by the practitioner.
.
The above are some issues that are influencing the need for a common mobile telephone forensics standard in the UK. Other factors that require change:
.
-No longer have unnecessary separated areas between law enforcement and the independent sector.
-No longer have poorly considered policies, practices and procedures regarding mobile telephone examination and evidence because they are not fully considered by all
-No longer have various public agencies promulgating confused and diametrically opposed procedures
.
Another reason why it is important to have a single common standard approach (and a second reason why I started the mobile forensics and evidence Pathfinder Approach) is the misrespresentation regarding the status of 'mobile phone'. Inspite of a hugh array of information about wireless, radio, radio signals and their role in the creation of a mobile phone, there still remains a persistence in the forensic and evidential system in indulging the notion that mobile phones are computers. That is rather ashame because whether it is done for cheap-labelling or getting bigger budgets (more than likely) it is largely unnecessarily and willful. Computer forensics in the area of data recovery from mobile phones has made an enormous contribution to our field. But after data recovery has been performed what else does computer forensics do for mobile phone wireless, radio, radio signals etc? Nothing. That is because computer forensics is not a discipline needed to embrace wireless; computing is rather a subset of wireless communications.
.
A mobile phone is a wireless device at first instance and designed for that purpose. It has a history, decades before the hybrid (computer) was created. Mobile phones allow for instantaneous radio telecommunications to place and to enable voice and data to be communicated. The device also allows for a memory area to record exchange of information. Overall this makes wireless devices useful to the user and gives them an appeal of user-friendliness.
.
Memory, code and data can be found in many systems and devices and code and data may be subjected to computation, but in their finite existence they are not a computer. These elements are storage, protocol and information. The only area where mobile telephones are connected with computer, per se, is that they have a CPU to enable computation. But mobile phones could operate without a CPU albeit currently the experience would no doubt not be too pleasureable, and in the future where the commonly understood CPU is dispensed with.
.
Yet a further reason why practitioners tacitly admit, through their conduct, that a mobile phone is a wireless device and not a computer is through the use of radio isolation (faraday rooms, tents or bags). Faraday rooms can cost £70K of tax payers money. So why would practitioners use radio isolation if the device under test was simply a computer? Moreover, how could cell site analysis be conducted if mobile telephones were simply a computer?
.
Moreover, wireless and mobile telephones have their own legalisation, directive, standards and guidelines - none of these designate them, technically or otherwise, as computers. Indeed there is a huge number of mobile telephone departments and labs in the public sector - none of them are labelled computer.
.
Two further reasons for a common standard created by all practitioners to underpin integrity:
.
- to give courts of law guarantee about the relability of mobile telephone evidence and opinion and to allow the legal system to it jobs as opposed to trying to hoodiwink the legal system or dictate to it; the current position is high% of evidence is being pushed through on the nod without any appropriate or independent assessment or scrutiny. This is occurring because many claiming themselves to be experts the basis for which is that they have had several mobile phones or owned mobile phones or visited forums or bought a piece of equipment that reads mobile phones. This area potentially opens the door to a huge range of appeal cases costing tax payers many millions of pounds which society can ill-afford given the economic pressures on the UK for the next 6 years.
.
- there is no single coherent standard for mobile telephone examination in the UK, despite the fact that up until 2003/4 Britain led the world in mobile telephone examination and evidence which was underpinned with alot of my work that begun the programme to help law enforcement understand the technological evidence with which they were dealing. When the public sector changes took place, experience was through out of the window in favour for opening pandora's box; anyone with relatively limited experience could give mobile evidence or had a desire to train others in mobile phone evidence, they could do so; Britain's international standing has been allowed to plummet and has been dropping further ever since. This is what awaits the Olympic Games in 2012 in this country and it is important to rectify this.
.
Lastly, I point out to Government Ministers looking at this matter, you will have seen the UK MTEB Mobile Forensics Conference 25th and 26th November 2009. The point of the Pathfinder Approach is to ensure Governement has the experience available to it, not simply from Law Enforcement, but from the independent sector where 90% of knowledge and skills are developed for mobile phone examination and evidence.
.
However, there is some disappointing news that many of the Constabularies are not even sending one representative to the Conference because we are told they have no money (even where everyone knows the Conference charge is extremely low and is a not-for-profits Conference). Also, that apparently it would impact for the attending person to justify how s/he will do their work to catch up after 2-days away from the office; this is on the basis that delegation of work doesn't exist. On the back of that, numerous outsources to those Constabulary not attending, have not signed up either. This is not a case of forcing them to attend, but it highlights the glaring obvious gaps across the UK and the regional educated pot-holed thinking in the country.
.
A list of delegates of those attending Conference and speakers supporting the Pathfinder Approach can be provided to Ministers. I can confirm there are some law enforcement and public agencies attending.
.
The Economy and Employment
Maybe the NAO and/or the Competition Commissioner might start to look and to see whether the way the forensic system is divvied up stilfes proper competition in the UK and impacts on town and urban regeneration to help develop small businesses, leading to employment. For instance, what is the point of a Constabulary throwing £1-million or more at one firm when a contract for 3 years @ £100,000.00p.a. to one small firm could enable eg one-person business to take on, say, one secretary and one assistance for 3 years:
.
- £50,000.00 Principal
- £27,0000 Secretary/Assistant
- £5,000.00 for equipment
- £1800.00 for compliance training and checking
- £16,200 for office rent/business rates/phone etc etc
.
Using the £1-million as the financial basis, multiply the above idea by 10 new small businesses, 20 people newly employed, rejuvernation of local funding to locals councils and suddenly spread across the country the grass roots of growth can start without the Governement having to increase current funding levels. Certainly, if I were offered a deal like this and with my understanding of the forensics arena I could have turned one of these businesses in two years providing employment for 10 people and in 3 years employ 25 people and teach other businesses how to do it as well. I have been in this business for over 20 years. The Police have never offered me a £1 million or £500K pa contract for that matter but still seek out my advice. So why can we not put my skills to help others.
.
To assist I have a plan that can keep those new businesses up to common standard for 3 years under their contracts. Also I have a team I have identified that along with myself could spear head this project to lift it off the ground.
.
How will this help Parliament. MPs from all parties can now go back to their constituencies and offer some hope of rejuvenation and employment.
.
Hmmm....I wonder if "Dragons' Den" might be interested in this.

Tuesday, November 18, 2008

Ultra-thin membrane changes (U)SIM card usage

Ultra-thin membrane changes SIM card usage

Examiners may come across an ultra-thin (0.3mm) membrane that lays over the contacts of a SIM card. Called the V200 SIM Dialer, the membrane is "Prefix base programmable (For routing prefix and bypass prefix setting)". What does that mean? Well, it allows mobile phones installed with SIM Tool Kit menu (most up to date phones have them) and define access to the network. The point being, if you are looking for least-cost routing for calls or want to use a calling card, rather than have mobile network call charges, then this device makes that happen, apparently.

How does it do it? "Dial the desired number directly each time you call, SIM dialer V200 will automatically dial IP access in front of the dialed number".
As the manufacturer promotes, using their device will not change your dialling habits and there is "No cutting, No pounching your SIM".

As the device has been programmed, and looking at the on-board chip, there should be a reader for it or one could be constructed. This throws me back to the old days of ponyprog and PIC basics. Of course, of equal importance is how does this device impact when examining the handset and SIM card? Will manual examination be the only course for examination or do the current handset and SIM readers detect changes this device makes to them? What evidence is there for call history or data usage? These are just a few of the questions to get examiners started.


It seems this programmable ultra-thin membrane is not limited to just SIM calls, but there is a USIM version (U-SIM V33G) that can be used to unlock iPhones. There is a video that is useful to watch so that examiners can at least comprehend how ultra-thin the membrane is and how it is installed:-
http://tw.youtube.com/watch?v=JQSNJxis7Ds



Please note, this is not a promotion or advert for these products, the information provided is to assist examiners with observations about these devices that may form part of their evidence.

Ultra-thin membrane changes (U)SIM card usage

Ultra-thin membrane changes SIM card usage

Examiners may come across an ultra-thin (0.3mm) membrane that lays over the contacts of a SIM card. Called the V200 SIM Dialer, the membrane is "Prefix base programmable (For routing prefix and bypass prefix setting)". What does that mean? Well, it allows mobile phones installed with SIM Tool Kit menu (most up to date phones have them) and define access to the network. The point being, if you are looking for least-cost routing for calls or want to use a calling card, rather than have mobile network call charges, then this device makes that happen, apparently.

How does it do it? "Dial the desired number directly each time you call, SIM dialer V200 will automatically dial IP access in front of the dialed number".
As the manufacturer promotes, using their device will not change your dialling habits and there is "No cutting, No pounching your SIM".

As the device has been programmed, and looking at the on-board chip, there should be a reader for it or one could be constructed. This throws me back to the old days of ponyprog and PIC basics. Of course, of equal importance is how does this device impact when examining the handset and SIM card? Will manual examination be the only course for examination or do the current handset and SIM readers detect changes this device makes to them? What evidence is there for call history or data usage? These are just a few of the questions to get examiners started.


It seems this programmable ultra-thin membrane is not limited to just SIM calls, but there is a USIM version (U-SIM V33G) that can be used to unlock iPhones. There is a video that is useful to watch so that examiners can at least comprehend how ultra-thin the membrane is and how it is installed:-
http://tw.youtube.com/watch?v=JQSNJxis7Ds



Please note, this is not a promotion or advert for these products, the information provided is to assist examiners with observations about these devices that may form part of their evidence.