首页 > 其他 > 详细

iTunes - Forensic guys' best friend

时间:2015-11-07 17:36:50      阅读:288      评论:0      收藏:0      [点我收藏+]

What chances do you think to acquire suspect‘s data from his/her iDevice? If suspects also use iTunes or iCloud, I will say it‘s in the bag.

What‘s inside a seized iPhone? Suspect refused to tell us and he was very confident that no one could unlock his iPhone.

技术分享

 

Fortuneately we got suspect‘s Laptop and found our best friend "iTunes". Why iTunes is our best friend? Because when you connect your iDevice to the PC/Mac/laptop with iTunes installed, iTunes will sync and backup data from iDevice. The "secret" is the plist in the lockdown folder. If you got this plist of suspect‘s iDevice, you could take advantage of it to establish "Trust" relationship between your forensic workstation and suspect‘s iDevice. Of course a plist file corresponds to certain iDevice.

技术分享

 

Copy those plist files to the lockdown folder on forensic workstation, and connect suspect‘s iPhone to the forensic workstation. The Magic works~ You don‘t have to press any buttion on that iPhone. The "Trust" relationship is already there. Now we could use iTunes to backup data from suspect‘s iPhone, and we don‘t need to unlock supsect‘s iphone. After backup completed, you could got everything in suspect‘s iPhone now.

技术分享

 

Congraulations!!! Even you don‘t have any forensic tools, you could use iTunes to restore that backup file to another iPhone. So you will know whether there is any clue or not.

 

Never doubt that~ Even you use commercial mobile forensic tool, the secret is still the plist file.

技术分享

 

iTunes - Forensic guys' best friend

原文:http://www.cnblogs.com/pieces0310/p/4945571.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!