Notifications
Clear all

Android Forensics

9 Posts
5 Users
0 Reactions
943 Views
(@ashfp)
Active Member
Joined: 15 years ago
Posts: 6
Topic starter  

I am currently working on a project for my computer forensics course. I am trying to gather methods used to root Android's without having to install a custom ROM and lose the data held on the internal memory. I would appreciate it if people could help me generate a list of known methods for older and newer versions of Android.
————–
E.g. AndRoot - used on versions lower than v2.27.651.6?
Universal AndRoot - used on v2.1
SuperOneClick
Unrevoked
Z4Root
————–
I plan to roll back my HTC Hero to use the older ROM's and attempt the exploits. Does anyone recommend somewhere to get older stock ROM's from?

Once I have gained root on the phone, I plan to DD the memory and data carve the image to find any data of interest. Has anyone had an experience in doing similar? Any advice or tips?

Any help is greatly appreciated.

Thanks in advance.


   
Quote
4Rensics
(@4rensics)
Reputable Member
Joined: 16 years ago
Posts: 255
 

I'd say your best bet to get you started on the ROMs would be

http//www.xda-developers.com/

they have a lot of cooked ROMs, but you might be able to find an original there somewhere!

Best of luck…


   
ReplyQuote
(@ashfp)
Active Member
Joined: 15 years ago
Posts: 6
Topic starter  

Great thanks, Any ideas of root exploits?


   
ReplyQuote
4Rensics
(@4rensics)
Reputable Member
Joined: 16 years ago
Posts: 255
 

haha, I'm in the same boat as you, sorry! We have the iPhone cracked, but not got around to trying an Android phone of how to bypass the screen / PIN lock/Swipe. When when you figure it out, post it on here please D


   
ReplyQuote
(@ashfp)
Active Member
Joined: 15 years ago
Posts: 6
Topic starter  

haha, I'm in the same boat as you, sorry! We have the iPhone cracked, but not got around to trying an Android phone of how to bypass the screen / PIN lock/Swipe. When when you figure it out, post it on here please D

Yeh, doesn't look like its been done before, so I doubt i'll even look into it, as I don't have long to do my project as it is.

What software would you recommend for data calving?


   
ReplyQuote
(@gh05teh)
Active Member
Joined: 15 years ago
Posts: 15
 

the swipe lock can be removed if usb debugging is available 😉


   
ReplyQuote
(@ashfp)
Active Member
Joined: 15 years ago
Posts: 6
Topic starter  

the swipe lock can be removed if usb debugging is available 😉

Yeh, I think I read something about being able to change the database file, but root was required to access the database file in the first place? Was this the exploit you had seen?


   
ReplyQuote
(@techspy1337)
New Member
Joined: 14 years ago
Posts: 1
 

Check this link out for rooting the Droid 1 (A855).

http//www.droidforums.net/forum/droid-hacks/86420-howto-pseudo-bypass-screen-locked-droid.html

I'll mention the sbf's are for the droid 1 only, I've noticed the others primarily use Clockwork. I'm looking into using a program called Unrevoked on some other types of droids atm.


   
ReplyQuote
(@angrybadger)
Estimable Member
Joined: 18 years ago
Posts: 164
 

the swipe lock can be removed if usb debugging is available 😉

Yeh, I think I read something about being able to change the database file, but root was required to access the database file in the first place? Was this the exploit you had seen?

with debugging on you can go in and kill processes over adb


   
ReplyQuote
Share: