Jonathan Zdziarski ...
 
Notifications
Clear all

Jonathan Zdziarski method

18 Posts
10 Users
0 Reactions
2,031 Views
(@marec4)
New Member
Joined: 16 years ago
Posts: 3
Topic starter  

Recently we've had problems with iPhone 4 (can't get e-mail messages out). As I understand the best method to get these is JZ's. So as we are LE, I wrote to Zdziarski through www.iphoneinsecurity.com contact. I wrote on monday but he isn't answered yet (sent all required information). We have to give the phone back soon and need the messages (about 200).

How long it takes him to answer? I think some guys in this forum should know that.

Thank in advance.


   
Quote
(@tonydearing)
New Member
Joined: 17 years ago
Posts: 3
 

Hi Marec4

JZ is currently working on a method to decrypt the e-mail messages.He is based in the US and gets a lot of requests to deal with so you will get a responce eventually.

Regards Tony


   
ReplyQuote
4Rensics
(@4rensics)
Reputable Member
Joined: 16 years ago
Posts: 255
 

As far as I am aware the JZ method is only working for iPhone 3 / 3GS and not iPhone 4?

Correct me if I am wrong!


   
ReplyQuote
(@tonydearing)
New Member
Joined: 17 years ago
Posts: 3
 

Using the Zdziarski method on ubuntu you can do a logical extraction of data from an iphone 4 up to but not including firmware version 4.2.1

regards tony


   
ReplyQuote
4Rensics
(@4rensics)
Reputable Member
Joined: 16 years ago
Posts: 255
 

Using the Zdziarski method on ubuntu you can do a logical extraction of data from an iphone 4 up to but not including firmware version 4.2.1

regards tony

Ah, so just not iOS then. Maybe thats where I'm getting my confusion!

Thanks.


   
ReplyQuote
(@dficsi)
Reputable Member
Joined: 19 years ago
Posts: 283
 

If you want to get in touch with him you could always try talking to him on Twitter.


   
ReplyQuote
jekyll
(@jekyll)
Trusted Member
Joined: 17 years ago
Posts: 60
 

I tried emailing directly and through www.iphoneinsecurity.com to see if I could purchase the tools for use in corporate CF work more than 2 weeks ago. I even emailed him to let him know his book is being distributed illegally and gave links, but got no reply.


   
ReplyQuote
(@marec4)
New Member
Joined: 16 years ago
Posts: 3
Topic starter  

Maybe someone from this forum could send me JZ-tools for iPhone, if i prove that I am LE. I could send same email with credentials as I sent to JZ. I can't see any restriction in www.iphoneinsecurity.com website that tools cannot be shared with LE.


   
ReplyQuote
 Doug
(@doug)
Estimable Member
Joined: 16 years ago
Posts: 185
 

That will not work.

In order to set the new tools up (Mac ones) you will need login credentials to download additional material. The Ubuntu ones could in theory be shared but I doubt anyone would be willing to do that as there is a level of trust with the tools.


   
ReplyQuote
(@thepm)
Reputable Member
Joined: 17 years ago
Posts: 254
 

Marec4,

I am in LE too and if I may give you some advice, don't wait for JZ… We've sent 5 investigators to his iPhone Forensics training in the last year. His classes were correct, but the problem is that after the training, he NEVER replied to our emails when we needed help (and we've sent a bunch).

Basically, his scripts are great when you encounter an iOS device that fits exactly in the specs of his working scripts. Aside from that, you're on your own…

Also know that all his iPhone 4 scripts are all marked as "Experimental" so basically, you're even more on your own as I haven't been able to extract any data with those experimental scripts yet. His documentation available on his restricted-access website is detailed, but outdated.

Just to make things clear, my post is not just to rant against JZ. I know he's great, but before investing (lots of) time and money in learning his technique, I thought you might want to know what you're getting into. If we had known about the lack of post-training support and current documentation beforehand, we wouldn't have gone with the training.

Right now we are looking for an alternative to the JZ method and we will probably buy a licence of FTS iXAM product.


   
ReplyQuote
Page 1 / 2
Share: