iPhone Jailbreak - ...
 
Notifications
Clear all

iPhone Jailbreak - Anyone Doing It?

8 Posts
5 Users
0 Reactions
1,181 Views
(@the_grinch)
Estimable Member
Joined: 14 years ago
Posts: 136
Topic starter  

I saw that there is now a jailbreak available for 11.4 and was wondering if anyone is jailbreaking devices in order to get more from their extractions? Assuming you either have the passcode or there isn't one, are you taking the extra step of jailbreaking the device in order to obtain more? Elcomsoft is saying they can obtain a physical on iDevices once jailbroken which got me thinking is this a step I should be taking for devices I receive.


   
Quote
(@tinybrain)
Reputable Member
Joined: 9 years ago
Posts: 354
 

You better take Cellebrite for your issue.


   
ReplyQuote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

It really depends on the task you need to do…

For example if you need to examine some malware or spyware, which probably is already at root level, you better don't destroy evidence by trying to jailbrake.

If you need to gather more information over a logical filesystem extraction, if documented in the right way, jailbrake can be ok.


   
ReplyQuote
(@the_grinch)
Estimable Member
Joined: 14 years ago
Posts: 136
Topic starter  

Got it! This was all a hypothetical just to see the value vs risk and to see what others are doing. Obviously, the aim is to get the most evidence as possible with destroying it and the question has to be asked. Thanks as always!!


   
ReplyQuote
passcodeunlock
(@passcodeunlock)
Prominent Member
Joined: 9 years ago
Posts: 792
 

Before doing this kind of stuff on a live device, ALWAYS try it first on a similar dummy device. If that works as expected, I don't see any major problem repeating the process )


   
ReplyQuote
(@randomaccess)
Reputable Member
Joined: 14 years ago
Posts: 385
 

Check out Sarah Edwards' research
Some answers you will only get with a jailbreak->file system extraction


   
ReplyQuote
(@the_grinch)
Estimable Member
Joined: 14 years ago
Posts: 136
Topic starter  

Awesome! Thanks I will check her out…seems she has a podcast on iOS forensics.


   
ReplyQuote
(@v-katalov)
Trusted Member
Joined: 12 years ago
Posts: 52
 

Well, there are some problems related to jailbreaking

1. This is of course not "forensically sound" – user partition is being modified.

2. Jailbreaking usually requires Internet connection (on the phone) to trust the certificate. That means that device can be remotely wiped, or at least it can sync with the cloud, so some data can be changed or deleted.

3. Potential risk to corruption of user data. It is in fact minimal for iOS 10-12 jailbreaks due to the way jailbreaks now work – in worst case, device can just reboot.

So using CAS is probably safer, but… We do not know exactly how it works. They probably sideload their "agent" (signed by enterprise certificate) into the device; in any case, "no jailbreak" is not equal to "no changes to the device" and "no risk".


   
ReplyQuote
Share: