码迷,mamicode.com
首页 > 其他好文 > 详细

Find out files transfered via Bluetooth

时间:2016-12-21 00:06:59      阅读:208      评论:0      收藏:0      [点我收藏+]

标签:which   bsp   ima   pat   useful   9.png   rom   creation   date   

The case was about business secret and forensic guy did a physical acquisition from a smart phone. He‘d like to find out files relates to sensitive data by examining the image file.

技术分享

 

A file named "top-secret.docx" draw forensic guy‘s attention. Bingo there‘s lots of classified data inside this document.

技术分享

 

 

Where did this files come from? In which way? Who sent this file?  Take a look at the path and you‘ll know what‘s going on. This file was transfered via Bluetooth! All three timestamp including the creation time, accessed time and modified time are "2016/05/11 11:01:20 UTC". That means this file "top-secret.docx" was transfered to this volume on the smart phone at local time "2016/05/11 19:01:20". Also we could know the create date/time and the last person who modified this document. The "path" of a file is usually a useful hint to forensic guys.

技术分享

 

Find out files transfered via Bluetooth

标签:which   bsp   ima   pat   useful   9.png   rom   creation   date   

原文地址:http://www.cnblogs.com/pieces0310/p/6204585.html

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!