iPhone extraction i...
 
Notifications
Clear all

iPhone extraction issues due to encryption

17 Posts
11 Users
0 Reactions
2,130 Views
 Doug
(@doug)
Estimable Member
Joined: 16 years ago
Posts: 185
Topic starter  

Hi,

We are trying to extract an iPhone 3GS using .XRY, Cellebrite and Oxygen. .XRY fails to extract anything bar the multimedia and Cellebrite gives a warning to indicate that encryption is being used. It suggests using iTunes to disable the encryption.

The exact message that Cellebrite gives is

Data encryption is enabled on this device. Phonebook and SMS extraction is not possible unless the device is connected to iTunes and encryption is disabled.

Any ideas on this?


   
Quote
(@cscottvance)
Active Member
Joined: 17 years ago
Posts: 15
 

IF you are military or law enforcement, it is possibly to use the Zdidarski method to bypass the encryption on the iPhone and do a full low-level disk image.

I would check out his methods on www.iphoneinsecurity.com


   
ReplyQuote
 Doug
(@doug)
Estimable Member
Joined: 16 years ago
Posts: 185
Topic starter  

Scott,

We are fortunate enough to have access to the tools so this will be the route we take.

I was curious as to how the device is encrypted. I have had a look through the menu structure and could not find anything that obviously looked like encryption settings.

Is it something that is activated in iTunes or on the device itself?

Regards,

Doug


   
ReplyQuote
(@oxygen_software)
Trusted Member
Joined: 17 years ago
Posts: 53
 

Doug,

It seems the backup password was set in iTunes fro this device. If you have PRO version of Oxygen Forensic Suite, you can use iPhone Password Breaker (special utility developed by Elcomsoft and included into OFS package) to find the password. Then OFS will decrypt and load backup files as it would be the normal device.

Check http//www.oxygen-forensic.com/en/features/iphonebackup/ or contact our support for more information about how it works.

WBR, Oleg.


   
ReplyQuote
(@cscottvance)
Active Member
Joined: 17 years ago
Posts: 15
 

Doug,

I believe that the encryption is done through iTunes while the passcode can be set up on the iPhone itself.

Hope this helps.


   
ReplyQuote
Forensication-can-be-fun
(@forensication-can-be-fun)
Eminent Member
Joined: 17 years ago
Posts: 27
 

Hi
I am having the same problem with an iPhone 4, have considered gaining authorisation to backup the phone with iTunes then examine this backup with oxygen 2010 PRO.
Will attempt to use the iPhone Password Breaker, as have had no luck with XRY or UFED or Radio Tactics.


   
ReplyQuote
 RonS
(@rons)
Reputable Member
Joined: 17 years ago
Posts: 358
 

Did Elcomsoft iPhone password breaker work for you?


   
ReplyQuote
Forensication-can-be-fun
(@forensication-can-be-fun)
Eminent Member
Joined: 17 years ago
Posts: 27
 

Hi
I have not used the password breaker yet as it will mean backing up the iphone using itunes here at the lab. I am awaiting the original backup from the OIC, and will then use Elcomsofts brute force attack.


   
ReplyQuote
(@forensicakb)
Reputable Member
Joined: 16 years ago
Posts: 316
 

Who would you be getting authorization from, and why would you need it, just curious.

Hi
I am having the same problem with an iPhone 4, have considered gaining authorisation to backup the phone with iTunes then examine this backup with oxygen 2010 PRO.
Will attempt to use the iPhone Password Breaker, as have had no luck with XRY or UFED or Radio Tactics.


   
ReplyQuote
jekyll
(@jekyll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

I would be testing this procedure on a non-evidentiary iphone first… just saying 😉


   
ReplyQuote
Page 1 / 2
Share: