iOS Forensic Tool o...
 
Notifications
Clear all

iOS Forensic Tool of Choice?

17 Posts
11 Users
0 Reactions
3,367 Views
XRY_Mike
(@xry_mike)
Eminent Member
Joined: 16 years ago
Posts: 28
 

XRY v6.3.2 has just been released with functionality to bypass a complex passcode.

It supports iOS6 and you can bypass a complex (more than 4 digit) passcode now on the iPhone 3G, iPhone 3GS, iPhone 4 GSM, iPhone 4 CDMA, iPod touch 3G, iPod touch 4 & iPad 1.

http//www.msab.com/app-data/downloads/Release_Notes_(English)/V6.3.2_release_notice.pdf


   
ReplyQuote
(@randomaccess)
Reputable Member
Joined: 14 years ago
Posts: 385
 

Is anyone working on finding a flaw in the a5/6 chip to allow physical extraction again?
Might have to get ahold of George hotz and see if he wants to work his magic again


   
ReplyQuote
 Doug
(@doug)
Estimable Member
Joined: 16 years ago
Posts: 185
 

Remember that if your device is jail broken already then you can us the 'dirty' tool kit from Elcomsoft to take an image. I say 'dirty' because it does indicate that the process is not forensically sound.

It falls down to the examiner if you wanted to jailbreak the device prior to performing your examination.


   
ReplyQuote
jmburns27
(@jmburns27)
Active Member
Joined: 14 years ago
Posts: 5
 

use Cellebrite to crack passwords, but for quick report, nothing is faster than IPEX on my MAC. It's free to law enforcement after registering on https://www.acesle.org. It extracts deleted SMS and separates SMS in conversation view which is very helpful.


   
ReplyQuote
(@randomaccess)
Reputable Member
Joined: 14 years ago
Posts: 385
 

Remember that if your device is jail broken already then you can us the 'dirty' tool kit from Elcomsoft to take an image. I say 'dirty' because it does indicate that the process is not forensically sound.

It falls down to the examiner if you wanted to jailbreak the device prior to performing your examination.

i would prefer not to, but i guess theres the case by case basis
havent tried jail breaking a locked device though and taking a physical….might add it to the very long to do list


   
ReplyQuote
(@Anonymous)
Guest
Joined: 1 second ago
Posts: 0
 

Thanks for giving us helpful and also useful info.


   
ReplyQuote
(@ryanp)
Active Member
Joined: 15 years ago
Posts: 19
 

Last night I started experimenting with acquiring an iPhone with the Latern Imager and then processing the image file in ILooKIX. So far so good. It mapped the data partition of the 32GB iPhone in seconds. We use XRY logical to download whatever the device is willing to give us, but this is a nice option to make use of the money we're already spending on ILooKIX for computer forensics.


   
ReplyQuote
Page 2 / 2
Share: