Saturday, April 02, 2016

Update: Mobile Weapons and Seizure Procedure


UPDATED: FCORD2016 Chapter 27 Discussion Document Seizure and Handling preparing a Best Practice Model - DOWNLOAD DISCUSSION DOCUMENT

Update: Mobile Weapons and Seizure Procedure

Regrettably a further manufacturer has entered into the arena by adapting a mobile device design(above) that transforms into a weapon for firing bullets.


The MTEB (Mobile Telephone Examination Board) Eighth Edition Section 4 Mobile Telephone Seizure Procedure (Mobile Weapons) updates on new items and handling procedures for them.  



There has been a slow but persistent level in mobile/smart phones being adapted for use as some form of weapon.

Back in 2008 trewmte.blogspot reported about the mobile phone that fires bullets. The story of this wasn't new, by any means, but was highlighted to illustrate the variety and exposure of devices that those involved in seizure procedure and mobile phone examiners can come into contact. 



Report: http://trewmte.blogspot.co.uk/2008/11/mobile-phone-that-fires-bullets.html

UPDATED: 2015 Imitation Style Mobile: Cost Approx 20-euros
Note the gloves for handling procedure. https://www.youtube.com/watch?v=ieeW617pT2I

UPDATED: 2014 Officer suffered shock conducting search
An officer conducting the search suffered a shock as he examined the fake handset but was not seriously injured. Good photo example shown of safe evidence container: iphone-stun-gun-seized-from-a-14-year-old-by-greater-manchester-police
.
Over time the trewmte.blogspot has highlighted other weapons, such as Stun Guns:



 http://trewmte.blogspot.co.uk/2007/07/stun-gun-cellphone.html



http://trewmte.blogspot.co.uk/2007/10/another-mobile-telephone-stun-gun.html

But mobile/smart phones that propel objects or inflict severe shock are not the only adaptations out there. Take for instance the age old weapon of a knife adapted for use with a mobile phone ( seized 2005):



And now in 2012 we now have another weapon that uses an adapted iPhone case which the manufacturers purport can be used for personal protection to spray pepper in the eyes:


The above are by no means the end of mobile/smart phones adapted for some form of weapons. We only know too well how mobile phones have been rigged to set off incendiary devices etc, which the MTEB labels IMD (improvised mobile devices):  

 


Yes the photos above all present disburbing images, but not for sensational purposes. Thankfully, it is not common for those involved with seizing items and examiners to come into contact with adapted and improvised devices like these on a regular basis. We still need to be aware and have a proposed handling procedure in place to deal with them though. That is on the basis that mobile/smart phone seizure and examination happens globally. The trewmte.blogspot is not simply local to the UK but deals with international matters and therefore articles like this are not only for UK consumption but for other countries that are involved in and employ seizure and examination procedures.

Lastly, and of specific relavance to seizure and examination procedure, it is priority to deal with mobile/smart phone weapon/s as opposed to figuring out what a person may have intended to do with it/them; figuring out is a thought process that can come later on. Why? One very good reason, the person who is seizing an adapted device (e.g. iPhone case above) and accidently sprays pepper into his/her face because s/he had no prior knowledge about the adapted device is clearly a priority. It is immaterial that the owner of such a device may have had genuine reasons (attacker pepper spray) for having such a device. Apart from mal-intention and recklessness of IMDs etc, for the majority of persons seizing or examining the device they wouldn't be the intended target and are nothing more than innocent bystanders.

Sunday, March 27, 2016

The Rise of (IoT) Domestic Appliance Forensic Examiners

The future looks bright for forensic digital examiners as the world of Internet of Things (IoT) has brought the rush of products on to the markets to compete in the IoT domestic appliances market. Already, due to time-to-market products flaws in the secure processes that allow users to initiate personal identity protocols to active appliances have been identified.

Just follow the links to read these articles for some enlightenment on what Pen Testing discovered.

iKettle and Coffee Machine

Protocol for the iKettle

Hacking a Wi-Fi Coffee Machine

Hacking Kettles

Internet map used to showed location of IoT appliances

This could all seem laughable save-to-say that the idea of bleeding details or house locations was an issue raised over 10 years ago when, due to a large spate of house burglaries, it was suggested householders should put device specific RFID tags on their household goods just in case of theft. It didn't take long for people to work out that a burglar could create a shopping list of items to theft order by walking down a street with an RFID scanner and GPS tracker.

The next stage is domestic appliances hijacked for malicious damage to devices, burglaries for those using unsafe appliances bleedings personal details and so on.

With IoT appliances expect to see a boon for law enforcement labs with examinations of kettles, tumble driers, washing machines etc. Of course, test equipment will be necessary.

A training course to assist in the examination process is soon to be available.

Saturday, March 26, 2016

iMessage shown to have encryption flaw

Discussion article here:  https://www.washingtonpost.com/world/national-security/johns-hopkins-researchers-discovered-encryption-flaw-in-apples-imessage/2016/03/20/a323f9a0-eca7-11e5-a6f3-21ccdbc5f74e_story.html

Apparently, the research has found:

"It took a few months, but they succeeded, targeting phones that were not using the latest operating system on iMessage, which launched in 2011.

"To intercept a file, the researchers wrote software to mimic an Apple server. The encrypted transmission they targeted contained a link to the photo stored in Apple’s iCloud server as well as a 64-digit key to decrypt the photo.

"Although the students could not see the key’s digits, they guessed at them by a repetitive process of changing a digit or a letter in the key and sending it back to the target phone. Each time they guessed a digit correctly, the phone accepted it. They probed the phone in this way thousands of times.

“And we kept doing that,” Green said, “until we had the key.

"With the key, the team was able to retrieve the photo from Apple’s server. If it had been a true attack, the user would not have known.

"To prevent the attack from working, users should update their devices to iOS 9.3. Otherwise, their phones and laptops could still be vulnerable, Green said."

The research report is here: https://isi.jhu.edu/~mgreen/imessage.pdf

The Internet of Things (IoT)

Quality. The reality of IoT future?

Sunday, March 20, 2016

British Exports


Just flying the flag for Great Britain and British Exports.

We're not just known for Brexit, you know.

Great Britain - probably the World's greatest leader in manufacturing and services.

eMMC



Frequently data recovery work undertaken is on eMMC (embedded MultiMediaCard) found in a large number of the smartphones and memory sticks etc. on the market. I was asked what tool I would use for working with e.g. eMMC. One tool that is most frequently turned to is Up-n-Up UP828P Ultra Programmer ('P' is the latest version).

The hardware reader which can be found here http://www.up48.com/english/product.htm. It supports the newest types of FLASH, NAND FLASH, SERIAL FLASH, MoviNAND, iNAND , eMMC etc., in addition, the BOOT area of iNAND, eMMC and MoviNAND can be read and written

Also required are the chip adaptors http://www.up48.com/english/adapter.htm.


And if you want to try your hand with iPhone there are adaptors for them too.


Of course, once an image has been acquired soft tools are still needed to read and interpret the data. Chip removal from iPhone (depending upon version involved A6, A8) would be problematical where data are encrypted.

Evidentially, do not experiment with exhibits (seized items) to avoid contaminating or corrupting data on the chip. Instead take the common path to chip exploration and obtain second-hand devices to gain your experience.

The above does not include additional hardware and tools used for the actual chip removals.

Hope this helps.

Saturday, March 19, 2016

Emergency Cases - Smartphone Examination


Capturing the target subject's smartphone activities is not as easy as is thought, as we are all finding out with the current Apple and law enforcement debacle.  The Apple case though is not the norm as the two opposing sides are fighting about the "right to access". The public are engaged with this story that continues to unfold as to what "Privacy" actual means, should terrorism enjoy the comfort of privacy and so on. However, there is a sub-text going on here (as well) concerning examination procedures for smartphones and methodology in emergency cases. Having been involved with mobile phone evidence in criminal and civil proceedings for over 30-years I can tell you it isn't as easy at all.

Consider the current Apple case (and the articles still keep coming) and mistakes that are said to have occurred. The - TECH INSIDER - reported (http://www.techinsider.io/apple-the-fbi-screwed-up-san-bernardino-investigation-2016-2)

"The fact that the password was reset means that Apple was unable to retrieve info from the iPhone's unencrypted iCloud backup like it has for past investigations, according to reporters Apple spoke with. If the password hadn't somehow been reset while in law enforcement custody, the FBI likely wouldn't need Apple to create a tool that lets it brute force hack the iPhone's lock screen passcode and gain access to the device's encrypted contents."

It is the words "password hadn't somehow" that has significance for me because in those words it doesn't take account of the intense situation people are operating under, speed of investigation operations, timescales, prevention for potential further attacks and pressure to resolve the case etc.  So the sub-text here is learning from adverse outcomes in emergency cases. Put on hold demands for back-door access as the golden cure because, in itself, it is not. There can be a plethora of superlative elements that will be sifted, considered and discarded where found not  to be relevant. For elements that may be relevant they still need to be sifted, considered and conceptualised.

From a range of materials I use in my training courses I use the following which I originated back in 2006 (and I published it back in 2010).


Primer(C now) = Point in time and Space (which is a constant reference point) in the present tense when the examiner is contacted for an investigation and from which the examiner uses to look back in time at and into the future regarding mobile telephone evidence.
.
(T) = Time is the timeline, limited by how far the examiner can see into the past and future based upon discovery.
.
(S) = Space is the space line that is used as a constant reference point from which all other events occurring in space can be considered based upon discovery (seizure of device, chain of custody of an exhibit etc)
.
(F) = Future relates to things that have yet to happen (future events). This is based upon things that maybe discovered from the time the examiner is contacted
.
(F d) = F d represents, as far as possible, thus not set to a specific period of time, how far into the future the examiner can identify events beyond which no further discovery is possible.
.
(PU usage) = Past User usage (below Blue line represents past recorded events, and below the red dotted line events unfolding during and after investigation)
.
(PR usage) = Past Record usage (below Blue line represents past recorded events, and below the red dotted line events unfolding during and after investigation)

The proposition in Smith Diag 1 is intended to represent, by use of visualization, how mobile telephone usage can be investigated. The diagram tests your powers of observation and, more importantly, your depth of knowledge. So do not be fooled by what you believe to be my poor graphics skills. I deliberately intended that (PU usage) area to be shown larger than the (PR usage) area in order to suggest more data may be found in the mobile telephone than maybe obtained from the network records. That is because not all activity on a mobile telephone leads to activity in the radio and fixed mobile network. Network records are not limited to billing records therefore issues associated with cell site analysis also need to be considered. It does not automatically follow there shall be parity between data obtained from the mobile telephone and the network records and vice versa. The diagram below (Smith Diag 2) represents a number of suggested data elements commonly arising during an investigation.


The third diagram (Smith Diag 3) uses the classic representation of Time (T) and Space (S). Use of a Time line may be obvious but the Space line may not be so obvious. The point of using Space is as a determinate for e.g. the seized exhibit in the examiner's possession. Let's say the examiner receives the mobile telephone exhibit on the 30th March 2008 at 3.00pm. The exhibit was seized 10th March 2008 at 11.00am. So, the examiner has two facts to work with (a) the exhibit in the laboratory (in time and space) and (b) the exhibit seized at a location from premises or person (in time and space).. So at the point the examiner has initial Contact (C now) with the exhibit then past events can now start to be determined. By way of illustration, following examination let’s say the examiner finds that the data recovered from the device reveals activity not connected with Space where the mobile telephone was seized at (b). Space would therefore be highly relevant, because (i) the examiner would need to demonstrate that as a fact and (ii) to demonstrate the separation in Space between each of the locations (a) laboratory, (b) the seizure, and the intervening factor between (a) and (b). This may be supported, for instance, by the last location and frequency details stored on the SIM card or may be the handset has GPS or one of the smartphone mapping system that might be set to automatic logging.


Have a go at designing one of these diagrams and show how you would handle the Apple phone (in this case) - the seizure and examination procedure. Just as a heads up F d is intended to represent a text message in the future that has been sent but not yet delivered to the target's handset. So how would you know if a text message is pending and who would you have to cooperate with to get that information (and the text content too)?

Hope this helps.

Exploration - missing the micro-evidence

If you are new to or have all but forgotten the humble (U)SIM Card now maybe as good time as any to refresh on the physical state of (U)SIM Card, in particular the hardware, so to speak.

To assist that refresh process, below are links to previously published materials that investigators and examiners might find useful:

http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt1.html
http://trewmte.blogspot.co.uk/2013/09/usim-examination-physical-pt2.html

It has been noted that such is the sophistication of attackers skillsets in areas, e.g. in-card listening devices, the skillsets applied borders on high-academic results that to the untrained eye could miss a forgery. [Images courtesy of Houda Ferradi, Rémi Gérau d, David Naccache, and Assia Tria: When Organized Crime Applies Academic Results. A Forensic Analysis of an In-Card Listening Device]

 
 
Hope this helps

Saturday, March 12, 2016

Global Emergency and Disaster Website

This has been one of my go-to website regarding global emergencies and disasters for many years. Even terrorist evens show up. The map refreshes every 5-mins. One surprising aspect is to note how many earthquakes are happening at any one time.


Friday, February 19, 2016

Moral Ethics of Backdoor iPhone 5C

Backdoor iPhone 5C

The discussion below is entirely hypothetical and is not intended to make or shift people into making decisions, legally or morally, nor create detriment at all.

There has been a huge amount of press regarding the balance between lawful investigation / national security versus Apple's company policy not to backdoor their products precisely for privacy and security reasons. It is laudable stand-off Apple have created because they ask where is the demarcation between full access and privacy and security. I cannot say this is David and Goliath being played out because Apple are far too big to be labelled a minnow (unjustly facing might versus right).

However, are Apple's arguments being raised legal ones or moral ones or both. Is Apple your moral barometer in life? Does Apple think for you and make/take your moral decisions for you? Only you can answer these. Apple appear to have made a good fist of standing by their publicised policy for legal reasons and, in fairness, it is understandable, they could have a fear of being accused of misleading statements to suddenly confirm there was always a backdoor into their product. They have done well and spoken in their statement that they never tried to make one in the first place.

[u][b]Apple's Open Letter[/b][/u]
https://www.apple.com/customer-letter/
"But now the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create. They have asked us to build a backdoor to the iPhone."

The public statement was made following a US Judge's Order:
https://assets.documentcloud.org/documents/2714001/SB-Shooter-Order-Compelling-Apple-Asst-iPhone.pdf

There is a point at which peoples' morals are woven in the fabric of their country's constitution where those moral become tenets that become doctrines for the society in which they wish to live. These can lead these morals being inextricably linked (not easy to disentangle) in the decision making process where an organisation like Apple might bend and could say for example "Okay, hands up, we have stood by our customers and promises we made to them but a greater good needs our help. If customers wish us to assist law enforcement and national security carefully set down by a strict and specific set of criteria allowing Apple to (firstly) build the access and (secondly) to deploy it, then we need customers' support to loosen are obligations?"  That statement is hypothetical only created for the following question to ask what would criteria do Apple customers morally consider should release Apple to allow access and deployment (backdooring)?

Below is a short list of graduated crimes against society. It is accepted straightaway that some may not figure in your moral domain (but then create one for yourself and see how you feel about it?). Put the list in order so that you create a moral demarcation where you believe Apple could (not should) allow backdooring on a single make/model of smartphone. The stage is now yours, and yours alone, as this is about you and not me, national security, law enforcement or Apple for that matter. Where do you think you feel and stand on this matter.

Place in your order of importance the below and highlight at what stage you would expect Apple to concede and backdoor their device for the greater good?

10....................backdoor device to find a burglary/car thief
9....................backdoor device to find local cannabis supplier
8..................backdoor device to find IIoC photo distributor/procurer
7................backdoor device to find people trafficker
6..............backdoor device to find arms smuggler
5...........backdoor device to find LE or civilian murderer
4.........backdoor device to find agent spreading bacterial warfare
3.......backdoor device to find murderer of national president
2.....backdoor device to find kidnapper of 30 babies from hospital
1...backdoor device to find where nuclear device placed before explodes

Remember more is less and less is more.  

Sunday, February 07, 2016

Threatware - legally speaking


LEGALLY SPEAKING – OBSERVATIONS CHART FOR JUDGES BARRISTERS AND SOLICIT0RS
The courts maybe faced with dealing with a wide range of mobile and computer criminal cases and civil disputes. These may include exploitation of the latter devices. Given the explosion of discontent in the world the use of "threatware" (a vernacular term adopted for this discussion) requires identification as to the type of threat defined by the outcome.
SKILLED OPINION
The supposed threat may not be enough by simply labelling it a threat - a victim's experience may not amount to a skilled opinion: The evidence was held not to be admissible on the grounds inter alia that no expert had given evidence as to the records, and that any connection they displayed between the cars stolen and those connected with the accused was a question of fact, not as in Abadom a question of opinion - Myers .v. D.P.P. [1965] A.C. 1001.
LABELLING THREATWARE
Calling a program "threatware" may require more than a simple label being attached to it; proof that it is what it is claimed to be a court may require substantiation: Patel v Controller of  Customs [1966] AC356 held the words “produce of  Morocco” stamped upon bags of coriander were inadmissible to prove the country of origin of the coriander.  The words were stamped on the bag with express intention of asserting a fact and were thus hearsay.
STORAGE MEDIA
A person having threatware may amount to possession but not intention to use. Equally, the definition of storage container vis-à-vis stored computer may also be subject to definition of 'computer' in e.g. civil law: Section 5 ss6 Civil Evidence Act 1968 - (6) Subject to subsection (3) above, in this Part of this Act " computer " means any device for storing and processing information, and any reference to information being derived from other information is a reference to its being derived therefrom by calculation, comparison or any other process. Also see Civil Evidence Act 1972 and 1995 for hearsay and opinion.
CONTRACTUAL DISPUTE
Where threatware is involved in the form of ransomware that arises in contractual dispute between parties see - Ordanduu GmbH & Anor, R (On the Application Of) v Phonepayplus Ltd [2015] EWHC 50 (Admin) (16 January 2015)
DATA PROTECTION
For a case where ransomware and data protection are involved see - CASE STUDIES 2013 - Data Protection Commissioner - Ireland [2013] IEDPC 18 (2013)    
MALWARE AS THREATWARE
Cyber Warfare: A Review of Theories, Law, Policies, Actual Incidents – and the Dilemma of Anonymity | Reich | European Journal of Law and Technology:   

Speaking of the problem of attributing, General Alexander notes that it is very hard "telling one actor from another and divining actors' intentions":
Not every event that affects our networks rises to the level of a national security threat. It is important to remember that hacking, spreading malware and other malicious activities are crimes, defined domestically as well as internationally by the Convention on Cybercrime, and accordingly have legal consequences. Even if you spot an intrusion and you know it originated from an adversary, you usually cannot tell an intelligence operation from a military one. (*page 5)
As part of the overall strategic plan of the US Department of Defense, emphasis must be placed on deterrence. General Alexander notes:
Attacks by hackers and criminals can cause "nation-state sized" effects; indeed, the accidental "release" of malware might do the same, and the problem of attributing the attack to a particular actor similarly remains difficult to impossible. We have to study deterrence anew, from a variety of perspectives, and to gain clarity on our authorities. To take a thought from Sun Tzu, we must understand the cyber environment and, the capabilities of our adversaries, and our own abilities as well. This is not going to be easy, and it is not going to yield answers soon. If we know one thing from the Cold War, it is that stable deterrence can take years to achieve, and is the product of planning, analysis, and dialogue across the government, academe, and industry, and with other nations as well. Cyber deterrence will require progress in situational awareness, defense, and offensive capabilities that adversaries know we will use if we deem necessary. (*page 5)
The above is a small sample of what is available regarding title variations, possible definitions and legal classification that may have bearing when dealing with threatware. I am not a lawyer merely I am simply using legal references to help support points in this discussion and suggesting a possible direction to seek further clarifications, observations or advice.
 

 

Monday, February 01, 2016

Investigation USIM EFs and Service Table

There has been so much going on over the past year and with research and testing I haven't posted as much as I would like. The growth areas in the variety of methods and tools for logical data and physical data extraction, harvesting and examination; impact that apps and malware might have on evidence; wireless options available on smartphones and tablets changing the way traditional cell site analysis can be conducted; and the generally the explosion in mobile information and standards needing to be absorbed and understood has been mind-blowing to say the least. These and other matters have consumed my time and the casualty has been fewer posts at the blog. However, from all the work and research I will endeavour to post here, hopefully, useful examination and investigative information on areas that may have either become outdated or evolved such that particular methods applied or tools used could be out-of-date or updated.

USIM (UICC) Cards memory storage and network/user files have seen a massive increase since 2010. Just have a look back at a post in 2010 I made here at trewmte.blogspot and compare the EFUST (elementary files usim service table) in TS 31.102 back then 3g-usim-2g-sim-service-numbers.html compared to the latest releases 12 ( 31_series/31.102/31102-ca0.zip ) and 13 ( 31.102/31102-d20.zip )

The first thing an examiner might wish do first thing in the morning at work is check whether the USIM reader tool is up-to-date. Have a look at the EFUST list and list of elementary files below and check that your reader has the capability to detect, extract and harvest data from these files. Then ask yourself do you actually understand when they are allocated and activated in a USIM what use is made of them? What evidence maybe harvested from them? How would the acquired data assist investigations in the following categories as they would apply to the use of mobile communications?

i)                    Contract Law

ii)                  Tort Law

iii)                Intellectual Property Law

iv)                Criminal (including the new Cybercrime) Law

v)                  Data Protection Law

vi)                Taxation Law

vii)              Computer Law

viii)            Communications Law

ix)                Internet Law

x)                  Etc.


EFUST
Service n°1: Local Phone Book
Service n°2: Fixed Dialling Numbers (FDN)
Service n°3: Extension 2
Service n°4: Service Dialling Numbers (SDN)
Service n°5: Extension3
Service n°6: Barred Dialling Numbers (BDN)
Service n°7: Extension4
Service n°8: Outgoing Call Information (OCI and OCT)
Service n°9: Incoming Call Information (ICI and ICT)
Service n°10: Short Message Storage (SMS)
Service n°11: Short Message Status Reports (SMSR)
Service n°12: Short Message Service Parameters (SMSP)
Service n°13: Advice of Charge (AoC)
Service n°14: Capability Configuration Parameters 2 (CCP2)
Service n°15: Cell Broadcast Message Identifier
Service n°16: Cell Broadcast Message Identifier Ranges
Service n°17: Group Identifier Level 1
Service n°18: Group Identifier Level 2
Service n°19: Service Provider Name
Service n°20: User controlled PLMN selector with Access Technology
Service n°21: MSISDN
Service n°22: Image (IMG)
Service n°23: Support of Localised Service Areas (SoLSA)
Service n°24: Enhanced Multi Level Precedence and Pre emption Service
Service n°25: Automatic Answer for eMLPP
Service n°26: RFU
Service n°27: GSM Access
Service n°28: Data download via SMS-PP
Service n°29: Data download via SMS CB
Service n°30: Call Control by USIM
Service n°31: MO-SMS Control by USIM
Service n°32: RUN AT COMMAND command
Service n°33: shall be set to '1'
Service n°34: Enabled Services Table
Service n°35: APN Control List (ACL)
Service n°36: Depersonalisation Control Keys
Service n°37: Co-operative Network List
Service n°38: GSM security context
Service n°39: CPBCCH Information
Service n°40: Investigation Scan
Service n°41: MexE
Service n°42: Operator controlled PLMN selector with Access Technology
Service n°43: HPLMN selector with Access Technology
Service n°44: Extension 5
Service n°45: PLMN Network Name
Service n°46: Operator PLMN List
Service n°47: Mailbox Dialling Numbers
Service n°48: Message Waiting Indication Status
Service n°49: Call Forwarding Indication Status
Service n°50: Reserved and shall be ignored
Service n°51: Service Provider Display Information
Service n°52 Multimedia Messaging Service (MMS)
Service n°53 Extension 8
Service n°54 Call control on GPRS by USIM
Service n°55 MMS User Connectivity Parameters
Service n°56 Network's indication of alerting in the MS (NIA)
Service n°57 VGCS Group Identifier List (EFVGCS and EFVGCSS)
Service n°58 VBS Group Identifier List (EFVBS and EFVBSS)
Service n°59 Pseudonym
Service n°60 User Controlled PLMN selector for I-WLAN access
Service n°61 Operator Controlled PLMN selector for I-WLAN access
Service n°62 User controlled WSID list
Service n°63 Operator controlled WSID list
Service n°64 VGCS security
Service n°65 VBS security
Service n°66 WLAN Reauthentication Identity
Service n°67 Multimedia Messages Storage
Service n°68 Generic Bootstrapping Architecture (GBA)
Service n°69 MBMS security
Service n°70 Data download via USSD and USSD application mode
Service n°71 Equivalent HPLMN
Service n°72 Additional TERMINAL PROFILE after UICC activation
Service n°73 Equivalent HPLMN Presentation Indication
Service n°74 Last RPLMN Selection Indication
Service n°75 OMA BCAST Smart Card Profile
Service n°76 GBA-based Local Key Establishment Mechanism
Service n°77 Terminal Applications
Service n°78 Service Provider Name Icon
Service n°79 PLMN Network Name Icon
Service n°80 Connectivity Parameters for USIM IP connections
Service n°81 Home I-WLAN Specific Identifier List
Service n°82 I-WLAN Equivalent HPLMN Presentation Indication
Service n°83 I-WLAN HPLMN Priority Indication
Service n°84 I-WLAN Last Registered PLMN
Service n°85 EPS Mobility Management Information
Service n°86 Allowed CSG Lists and corresponding indications
Service n°87 Call control on EPS PDN connection by USIM
Service n°88 HPLMN Direct Access
Service n°89 eCall Data
Service n°90 Operator CSG Lists and corresponding indications
Service n°91 Support for SM-over-IP
Service n°92 Support of CSG Display Control
Service n°93 Communication Control for IMS by USIM
Service n°94 Extended Terminal Applications
Service n°95 Support of UICC access to IMS
Service n°96 Non-Access Stratum configuration by USIM
Service n°97 PWS configuration by USIM
Service n°98 RFU
Service n°99 URI support by UICC
Service n°100 Extended EARFCN support
Service n°101 ProSe
Service n°102 USAT Application Pairing

Particular note: when looking at the EFUST service list above this should not be taken as all the services that may be allocated and activated on modules in a UICC. GSM EFSST (sim service table) has particular services unique to GSM SIM (GSM 11.11), such as Service n°29: Proactive SIM which does not appear in the EFUST list. And if Service n°29: Proactive SIM is important to an investigation (and it can be) it is worth the reminder to look at GSM 11.14 (sim application toolkit) that adds services and most importantly "capabilities" between SIM and smartphone. Perhaps you might think, such as, how this can assist an investigation? My responses is consider (a) man-in-the-middle attacks (b) crime (c) cybercrime.

There has been an abundance in the growth of elementary files, too, in USIM Releases 12/13. The increase in access to varying networks by smartphones and tablets has meant the technical, privacy, commercial and monetisation influences how a subscriber latches and attaches to networks. The relevance being recovered message data for instance requires understanding and identifying how the data got there via which particular network access point etc.

3GPP TS 31.102 V12.10.0 (2016-01)
4 Contents of the Files 18
4.1 Contents of the EFs at the MF level 18
4.2 Contents of files at the USIM ADF (Application DF) level 18
4.2.1 EFLI (Language Indication) 18
4.2.2 EFIMSI (IMSI) 19
4.2.3 EFKeys (Ciphering and Integrity Keys) 20
4.2.4 EFKeysPS (Ciphering and Integrity Keys for Packet Switched domain) 21
4.2.5 EFPLMNwAcT (User controlled PLMN selector with Access Technology) 21
4.2.6 EFHPPLMN (Higher Priority PLMN search period) 22
4.2.7 EFACMmax (ACM maximum value) 23
4.2.8 EFUST (USIM Service Table) 25
4.2.9 EFACM (Accumulated Call Meter) 27
4.2.10 EFGID1 (Group Identifier Level 1) 28
4.2.11 EFGID2 (Group Identifier Level 2) 28
4.2.12 EFSPN (Service Provider Name) 28
4.2.13 EFPUCT (Price per Unit and Currency Table) 29
4.2.14 EFCBMI (Cell Broadcast Message identifier selection) 30
4.2.15 EFACC (Access Control Class) 31
4.2.16 EFFPLMN (Forbidden PLMNs) 31
4.2.17 EFLOCI (Location Information) 32
4.2.18 EFAD (Administrative Data) 33
4.2.19 Void 35
4.2.20 EFCBMID (Cell Broadcast Message Identifier for Data Download) 35
4.2.21 EFECC (Emergency Call Codes) 36
4.2.22 EFCBMIR (Cell Broadcast Message Identifier Range selection) 37
4.2.23 EFPSLOCI (Packet Switched location information) 37
4.2.24 EFFDN (Fixed Dialling Numbers) 39
4.2.25 EFSMS (Short messages) 39
4.2.26 EFMSISDN (MSISDN) 41
4.2.27 EFSMSP (Short message service parameters) 41
4.2.28 EFSMSS (SMS status) 43
4.2.29 EFSDN (Service Dialling Numbers) 43
4.2.30 EFEXT2 (Extension2) 44
4.2.31 EFEXT3 (Extension3) 44
4.2.32 EFSMSR (Short message status reports) 45
4.2.33 EFICI (Incoming Call Information) 45
4.2.34 EFOCI (Outgoing Call Information) 49
4.2.35 EFICT (Incoming Call Timer) 50
4.2.36 EFOCT (Outgoing Call Timer) 50
4.2.37 EFEXT5 (Extension5) 51
4.2.38 EFCCP2 (Capability Configuration Parameters 2) 51
4.2.39 EFeMLPP (enhanced Multi Level Precedence and Pre-emption) 52
4.2.40 EFAaeM (Automatic Answer for eMLPP Service) 53
4.2.41 Void 54
4.2.42 EFHiddenkey (Key for hidden phone book entries) 54
4.2.43 Void 54
4.2.44 EFBDN (Barred Dialling Numbers) 54
4.2.45 EFEXT4 (Extension4) 55
4.2.46 EFCMI (Comparison Method Information) 55
4.2.47 EFEST (Enabled Services Table) 56
4.2.48 EFACL (Access Point Name Control List) 56
4.2.49 EFDCK (Depersonalisation Control Keys) 57
4.2.50 EFCNL (Co-operative Network List) 57
4.2.51 EFSTART-HFN (Initialisation values for Hyperframe number) 59
4.2.52 EFTHRESHOLD (Maximum value of START) 59
4.2.53 EFOPLMNwACT (Operator controlled PLMN selector with Access Technology) 59
4.2.54 EFHPLMNwAcT (HPLMN selector with Access Technology) 60
4.2.55 EFARR (Access Rule Reference) 61
4.2.56 Void 62
4.2.57 EFNETPAR (Network Parameters) 62
4.2.58 EFPNN (PLMN Network Name) 64
4.2.59 EFOPL (Operator PLMN List) 65
4.2.60 EFMBDN (Mailbox Dialling Numbers) 66
4.2.61 EFEXT6 (Extension6) 67
4.2.62 EFMBI (Mailbox Identifier) 67
4.2.63 EFMWIS (Message Waiting Indication Status) 67
4.2.64 EFCFIS (Call Forwarding Indication Status) 69
4.2.65 EFEXT7 (Extension7) 70
4.2.66 EFSPDI (Service Provider Display Information) 70
4.2.67 EFMMSN (MMS Notification) 71
4.2.68 EFEXT8 (Extension 8) 73
4.2.69 EFMMSICP (MMS Issuer Connectivity Parameters) 73
4.2.70 EFMMSUP (MMS User Preferences) 76
4.2.71 EFMMSUCP (MMS User Connectivity Parameters) 77
4.2.72 EFNIA (Network's Indication of Alerting) 77
4.2.73 EFVGCS (Voice Group Call Service) 78
4.2.74 EFVGCSS (Voice Group Call Service Status) 80
4.2.75 EFVBS (Voice Broadcast Service) 80
4.2.76 EFVBSS (Voice Broadcast Service Status) 82
4.2.77 EFVGCSCA (Voice Group Call Service Ciphering Algorithm) 83
4.2.78 EFVBSCA (Voice Broadcast Service Ciphering Algorithm) 84
4.2.79 EFGBABP (GBA Bootstrapping parameters) 84
4.2.80 EFMSK (MBMS Service Keys List) 85
4.2.81 EFMUK (MBMS User Key) 86
4.2.82 Void 87
4.2.83 EFGBANL (GBA NAF List) 87
4.2.84 EFEHPLMN (Equivalent HPLMN) 88
4.2.85 EFEHPLMNPI (Equivalent HPLMN Presentation Indication) 88
4.2.86 EFLRPLMNSI (Last RPLMN Selection Indication) 89
4.2.87 EFNAFKCA (NAF Key Centre Address) 89
4.2.88 EFSPNI (Service Provider Name Icon) 90
4.2.89 EFPNNI (PLMN Network Name Icon) 91
4.2.90 EFNCP-IP (Network Connectivity Parameters for USIM IP connections) 91
4.2.91 EFEPSLOCI (EPS location information) 94
4.2.92 EFEPSNSC (EPS NAS Security Context) 96
4.2.93 EFUFC (USAT Facility Control) 97
4.2.94 EFNASCONFIG (Non Access Stratum Configuration) 98
4.2.95 EFUICCIARI (UICC IARI) 102
4.2.96 EFPWS (Public Warning System) 102
4.2.97 EFFDNURI (Fixed Dialling Numbers URI) 103
4.2.98 EFBDNURI (Barred Dialling Numbers URI) 104
4.2.99 EFSDNURI (Service Dialling Numbers URI) 104
4.2.100 EFIWL (IMEI(SV) White Lists) 105
4.2.101 EFIPS (IMEI(SV) Pairing Status) 106
4.2.102 EFIPD (IMEI(SV) of Pairing Device) 107

4.3 DFs at the USIM ADF (Application DF) Level 108
4.4 Contents of DFs at the USIM ADF (Application DF) level 108
4.4.1 Contents of files at the DF SoLSA level 108
4.4.1.1 EFSAI (SoLSA Access Indicator) 109
4.4.1.2 EFSLL (SoLSA LSA List) 109
4.4.1.3 LSA Descriptor files 112

4.4.2 Contents of files at the DF PHONEBOOK level 113
4.4.2.1 EFPBR (Phone Book Reference file) 113
4.4.2.2 EFIAP (Index Administration Phone book) 115
4.4.2.3 EFADN (Abbreviated dialling numbers) 116
4.4.2.4 EFEXT1 (Extension1) 119
4.4.2.5 EFPBC (Phone Book Control) 120
4.4.2.6 EFGRP (Grouping file) 121
4.4.2.7 EFAAS (Additional number Alpha String) 122
4.4.2.8 EFGAS (Grouping information Alpha String) 123
4.4.2.9 EFANR (Additional Number) 123
4.4.2.10 EFSNE (Second Name Entry) 125
4.4.2.11 EFCCP1 (Capability Configuration Parameters 1) 125
4.4.2.12 Phone Book Synchronisation 126
4.4.2.12.1 EFUID (Unique Identifier) 126
4.4.2.12.2 EFPSC (Phone book Synchronisation Counter) 127
4.4.2.12.3 EFCC (Change Counter) 128
4.4.2.12.4 EFPUID (Previous Unique Identifier) 128
4.4.2.13 EFEMAIL (e-mail address) 129
4.4.2.14 Phonebook restrictions 130
4.4.2.15 EFPURI (Phonebook URIs) 130

4.4.3 Contents of files at the DF GSM-ACCESS level  (Files required for GSM Access) 131
4.4.3.1 EFKc (GSM Ciphering key Kc) 131
4.4.3.2 EFKcGPRS (GPRS Ciphering key KcGPRS) 132
4.4.3.3 Void 132
4.4.3.4 EFCPBCCH (CPBCCH Information) 132
4.4.3.5 EFInvScan (Investigation Scan) 133
4.4.4 Contents of files at the MexE level 134
4.4.4.1 EFMexE-ST (MexE Service table) 134
4.4.4.2 EFORPK (Operator Root Public Key) 134
4.4.4.3 EFARPK (Administrator Root Public Key) 136
4.4.4.4 EFTPRPK (Third Party Root Public Key) 137
4.4.4.5 EFTKCDF (Trusted Key/Certificates Data Files) 138

4.4.5 Contents of files at the DF WLAN level 138
4.4.5.1 EFPseudo (Pseudonym) 138
4.4.5.2 EFUPLMNWLAN (User controlled PLMN selector for I-WLAN Access) 139
4.4.5.3 EFOPLMNWLAN (Operator controlled PLMN selector for I-WLAN Access) 139
4.4.5.4 EFUWSIDL (User controlled WLAN Specific Identifier List) 140
4.4.5.5 EFOWSIDL (Operator controlled WLAN Specific IdentifierList) 141
4.4.5.6 EFWRI (WLAN Reauthentication Identity) 141
4.4.5.7 EFHWSIDL (Home I-WLAN Specific Identifier List) 142
4.4.5.8 EFWEHPLMNPI (I-WLAN Equivalent HPLMN Presentation Indication) 143
4.4.5.9 EFWHPI (I-WLAN HPLMN Priority Indication) 143
4.4.5.10 EFWLRPLMN (I-WLAN Last Registered PLMN) 144
4.4.5.11 EFHPLMNDAI (HPLMN Direct Access Indicator) 144

4.4.6 Contents of files at the DF HNB level 145
4.4.6.1 Introduction 145
4.4.6.2 EFACSGL (Allowed CSG Lists) 145
4.4.6.3 EFCSGT (CSG Type) 148
4.4.6.4 EFHNBN (Home NodeB Name) 150
4.4.6.5 EFOCSGL (Operator CSG Lists) 150
4.4.6.6 EFOCSGT (Operator CSG Type) 152
4.4.6.7 EFOHNBN (Operator Home NodeB Name) 153
4.4.7 Void 153

4.4.8 Contents of files at the DF ProSe level 153
4.4.8.1 Introduction 153
4.4.8.2 EFPROSE_MON (ProSe Monitoring Parameters) 153
4.4.8.3 EFPROSE_ANN (ProSe Announcing Parameters) 154
4.4.8.4 EFPROSEFUNC (HPLMN ProSe Function) 155
4.4.8.5 EFPROSE_RADIO_COM (ProSe Direct Communication Radio Parameters) 156
4.4.8.6 EFPROSE_RADIO_MON (ProSe Direct Discovery Monitoring Radio Parameters) 157
4.4.8.7 EFPROSE_RADIO_ANN (ProSe Direct Discovery Announcing Radio Parameters) 158
4.4.8.8 EFPROSE_POLICY (ProSe Policy Parameters) 158
4.4.8.9 EFPROSE_PLMN (ProSe PLMN Parameters) 160
4.4.8.10 EFPROSE_GC (ProSe Group Counter) 161
4.4.8.11 EFPST (ProSe Service Table) 162
4.4.8.12 EFPROSE_UIRC (ProSe UsageInformationReportingConfiguration) 162

4.5 Contents of Efs at the TELECOM level 166
4.5.1 EFADN (Abbreviated dialling numbers) 166
4.5.2 EFEXT1 (Extension1) 166
4.5.3 EFECCP (Extended Capability Configuration Parameter) 166
4.5.4 EFSUME (SetUpMenu Elements) 166
4.5.5 EFARR (Access Rule Reference) 166
4.5.6 EFICE_DN (In Case of Emergency – Dialling Number) 167
4.5.7 EFICE_FF (In Case of Emergency – Free Format) 167
4.5.8 EFRMA (Remote Management Actions) 168
4.5.9 EFPSISMSC (Public Service Identity of the SM-SC) 168

4.6 Contents of DFs at the TELECOM level 168
4.6.1 Contents of files at the DFGRAPHICS level 169
4.6.1.1 EFIMG (Image) 169
4.6.1.2 EFIIDF (Image Instance Data Files) 170
4.6.1.3 EFICE graphics (In Case of Emergency – Graphics) 171
4.6.1.4 EFLAUNCH SCWS 171
4.6.1.5 EFICON 175

4.6.2 Contents of files at the DFPHONEBOOK under the DFTELECOM 176
4.6.3 Contents of files at the DFMULTIMEDIA level 176
4.6.3.1 EFMML (Multimedia Messages List) 176
4.6.3.2 EFMMDF (Multimedia Messages Data File) 179
4.7 Files of USIM 180

I will leave you to conclude whether you may think USIM has little or no relevance to an investigation.

Sunday, January 17, 2016

Malicious Code - training simulator

If you have ever had to assist others understand malware behaviour then every trainer needs a useful tool to illustrate basic concept. Marco Schweighauser has launched a useful online webpage with such a tool ( https://schweigi.github.io/assembler-simulator/ ) or a github page ( https://github.com/Schweigi/assembler-simulator ) to download the working tool so that trainers can play with creating harmless scripts.

Marco has produced a "simulator which provides a simplified assembler syntax (based on NASM) and is simulating a x86 like cpu." The tool is demonstrated by using default code "HELLO WORLD" and presented as a visualisation for illustrative and activity purposes relating to registers, flags, Instruction Pointer (IP), Stack Pointer (SP), RAM, machine code, stack, and memory mapping when following how the harmless code is executed either in RUN or STEP mode.


Iko Knyphausen (Computer Forensic Examiner, Intrusion & Malware Analyst at /d/b/a Datasource Forensics) has played with a simple but harmless malicious code (https://www.linkedin.com/pulse/using-simple-8-bit-assembler-simulation-illustrate-iko-knyphausen) to demonstrate malware in action by overwriting HELLO WORLD. Cut and paste the example into the online or downloaded tool and watch the activity.

=============================


; Writes Hello World to the output and emulates an infection; At the beginning of the PRINT function a simulated buffer
; overwrite called "stack_smash" pushes 12 values to
; the stack. After the print function has printed Hello World !
; it RETURNs but sets the Instruction Pointer to a manipulated
; address on the stack. From there execution continues on the
; stack, in this example overwriting all output with asterisk *
; characters.

; Single step through this demo for best results ;-)

    JMP start
name:     DB "Hello World!" ; Variable
           DB 0    ; String terminator

start:
    MOV C, name    ; Point to var
    MOV D, 232    ; Point to output
    CALL print
        HLT             ; Stop execution

print:            ; print characters from var to output
    
    stack_smash:     ; this would typically be a buffer
            ; overwrite which we simulate by
            ; pushing 12 values onto the stack
            ; in reverse order
            ; the RET operation from the print
            ; function puts the instruction pointer
            ; to 0xDC and overwrites the output
            ; with * characters in reverse order
    
    PUSH 0        ; HLT
    PUSH 0xDC    ; LOOP back to this address on stack
    PUSH 39        ; JNZ 0xDB
    PUSH 232    ; the beginning of the output memory
    PUSH 3
    PUSH 23        ; CMP D, 232
    PUSH 42        ; character to overwrite output
    PUSH 3
    PUSH 8        ; MOV number to reg_address
    PUSH 3
    PUSH 19        ; DEC register #3 = D
    PUSH 0xDC    ; RET from print will pull this address

    MOV B, 0
.loop:
    MOV A, [C]    ; Get char from var
    MOV [D], A    ; Write to output
    INC C
    INC D  
    CMP B, [C]    ; Check if end
    JNZ .loop    ; jump if not

    RET        ; loads malicious return address from stack


=============================

To understand assembler code visit:

https://schweigi.github.io/assembler-simulator/instruction-set.html
https://en.wikipedia.org/wiki/Assembly_language
http://www.nasm.us/xdoc/2.10.09/html/nasmdoc3.html