Join Us!

Cellebrite PA iPhon...
 
Notifications
Clear all

Cellebrite PA iPhone extraction error  

  RSS
JohnNW
(@johnnw)
New Member

good evening all,

im fairly new to digital forensics, and I have recently encountered a problem that I have never seen before.  

I am attempting to extract an iPhone XR by utilizing cellebrite physical analyzer.  When I get to the extraction to choose between method 1 and method 2, I get the following error:

“method 1 and method 2 cannot be used, because the device was not unlocked (with a pin code) after it was reset”.

i have reset the device and used the proper security pin code, but I am still getting the same error.  

any help would be much appreciated!!

Quote
Posted : 27/07/2020 10:34 pm
jadams951
(@jadams951)
New Member

Have you tried using UFED 4 PC for an advanced logical?

ReplyQuote
Posted : 28/07/2020 2:57 am
badams
(@badams)
New Member

I use UFED PA & 4PC on a weekly basis and haven't come across that specific error message when dealing with reset phones. I would update the PA to the latest release. Are you able to unlock the phone with the pin and view the phone's contents?

ReplyQuote
Posted : 28/07/2020 3:51 am
AmNe5iA
(@amne5ia)
Active Member

Is it a work iPhone?  Does it have some kind of MDM (Mobile Device Management) enabled?

I have come across a few MDM enabled iPhones and they generally disable data over the cable port.  The only exception to accessing data over teh cable port is the administation computer that exists somewhere in the company that administers the phone.  There are two ways to get data from an iPhone under these circumstances:

1. Use the checkm8 exploit to get a full filesystem.  The boot loader basically negates the MDM from preventing access to cable port. (This method won't work on an iPhone XR though)

2. Contact the business/company that own the phone and get them to do an iTunes backup (or MDM equivelent) using the adminstration terminal.

One of the common ways I first spot that MDM is enabled is when I go to set the Auto-Lock to "Never" but the "Never" option isn't avaiable.  Quite often I have found with MDM that the maximum I can set autolock for is 5 minutes.

ReplyQuote
Posted : 28/07/2020 9:55 am
JohnNW
(@johnnw)
New Member

@jadams951 Yes, but I only get pictures and videos.  Text messages, e-mails, etc. are not extracted. 

ReplyQuote
Posted : 28/07/2020 1:41 pm
JohnNW
(@johnnw)
New Member

@badams Yes, I have the pin code to unlock the phone and I can view all of the contents.

@AmNe5iA I do not believe it is a work phone with MDM.  I have read about checkm8 but I have never used it.  Our IT department is super strict about what the programs I install, so I may give that a shot.  

 

ReplyQuote
Posted : 28/07/2020 1:44 pm
AmNe5iA
(@amne5ia)
Active Member

@johnnw Checkm8 won't work on an XR

ReplyQuote
Posted : 28/07/2020 1:57 pm
JohnNW
(@johnnw)
New Member

@amne5ia I also have an SE that is giving me the same problem; is checkm8 a viable option for this model?

ReplyQuote
Posted : 28/07/2020 2:01 pm
AmNe5iA
(@amne5ia)
Active Member

@johnnw I don't think it is. You should also check that your installation of iTunes is up to date on the computer you are attempting to use Cellebrite PA from.

ReplyQuote
Posted : 28/07/2020 2:09 pm
JohnNW
(@johnnw)
New Member

@amne5ia Just checked; I'm running the latest version.  

ReplyQuote
Posted : 28/07/2020 2:12 pm
Em-Belkasoft
(@em-belkasoft)
Junior Member
Posted by: @johnnw

@amne5ia I also have an SE that is giving me the same problem; is checkm8 a viable option for this model?

I can confirm that checkm8 works on iPhone SE. 

ReplyQuote
Posted : 02/08/2020 6:28 pm
Share: