±Forensic Focus Partners
New Today: 0
New Yesterday: 4
±Follow Forensic Focus
· TDFCon 2015 – Middlesbrough 15th May
· Electronic Voiceprints: The Crime Solving Power of Biometric Forensics
· DFRWS Europe 2015 Annual Conference – Recap
· DFRWS EU 2015 – Dublin 23rd – 26th March
· SQLite Database Forensics – ‘Sleep Cycle’ Case Study
· Data Recovery As A Medium For Email Forensics
· Carving out the Difference between Computer Forensics and E-Discovery
· Forensic Analysis of SQLite Databases: Free Lists, Write Ahead Log, Unallocated Space and Carving
· How Secure Is Your Password? A Friendly Advice from a Company That Breaks Passwords
iPhone 4 + iOS 6
Subforums: Mobile Telephone Case Law
Firstly, let me say hi, and thanks for having me on this forum.
Secondly, a bit of background information. A colleague of mine has had her kids update her phone to iOS 6. Subsequently all the photos of her kids have gone. Her partner tried to restore from backup and used Dr Fone from wondershare to try recover her photos, however this did not work.
The phone does not have a pin and also, unfortunately she does not have any backups.
So, I have a little experience with PhotoRec & dd etc so offered to see if I could recover the photos (well, the ones that haven't been overwritten anyway). I have recovered information for some other colleagues (and my own) laptops and external hard drives after failures and accidental formats.
Thus far, I have successfully jailbroken and established an SSH connection to the phone and from the phone to my Linux box
However when I try to dd the drives 2nd partition, I get dd: opening `/dev/disk0s1s2': Resource busy.
Also, I have tried to un-mount the drive so that I can dd it and as soon as I have unmounted it the phones screen starts wheeling until my SSH session closes and the phone restarts.
Finally, my question, is there anyone here who would be able to point me in the right direction? Or even better tell me how I can successfully un-mount the drive/load into a hacked dfu mode to allow me to dd the drive without the resource busy error?. Any help would be appreciated! Essentially I would like to parse over the disk with photorec and recover what I can or confidently tell her that her photos are long-gone (although this is looking more and more likely).
Thanks & Regards
When I updated an iPhone 4 to iOS6 and also iPhone 5 to iOS6 the devices ended up being wiped clean, new OS installed and then my data was restored from the previous backups. This sounds like it may be what happened to her device.
The issue here is that if the device reinstalled a new OS rather than updating the previous there is a good chance that the encryption keys for the old OS were dumped during the process and new ones generated upon installation of the updated OS.
If this is the case, unfortunately that means that you will not have any luck recovering any of the data which has been lost.
- Senior Member
May they have at some point charged their phone in another persons laptop or tower to charge? If so there computer may have made a backup without them even realsing
- Senior Member