码迷,mamicode.com
首页 > 其他好文 > 详细

iTunes - Forensic guys' best friend

时间:2015-11-07 17:38:27      阅读:301      评论:0      收藏:0      [点我收藏+]

标签:

What chances do you think to acquire suspect‘s data from his/her iDevice? If suspects also use iTunes or iCloud, I will say it‘s in the bag.

What‘s inside a seized iPhone? Suspect refused to tell us and he was very confident that no one could unlock his iPhone.

技术分享

 

Fortuneately we got suspect‘s Laptop and found our best friend "iTunes". Why iTunes is our best friend? Because when you connect your iDevice to the PC/Mac/laptop with iTunes installed, iTunes will sync and backup data from iDevice. The "secret" is the plist in the lockdown folder. If you got this plist of suspect‘s iDevice, you could take advantage of it to establish "Trust" relationship between your forensic workstation and suspect‘s iDevice. Of course a plist file corresponds to certain iDevice.

技术分享

 

Copy those plist files to the lockdown folder on forensic workstation, and connect suspect‘s iPhone to the forensic workstation. The Magic works~ You don‘t have to press any buttion on that iPhone. The "Trust" relationship is already there. Now we could use iTunes to backup data from suspect‘s iPhone, and we don‘t need to unlock supsect‘s iphone. After backup completed, you could got everything in suspect‘s iPhone now.

技术分享

 

Congraulations!!! Even you don‘t have any forensic tools, you could use iTunes to restore that backup file to another iPhone. So you will know whether there is any clue or not.

 

Never doubt that~ Even you use commercial mobile forensic tool, the secret is still the plist file.

技术分享

 

iTunes - Forensic guys' best friend

标签:

原文地址:http://www.cnblogs.com/pieces0310/p/4945571.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!