Safari Cookies on A...
 
Notifications
Clear all

Safari Cookies on Apple iPad 2

6 Posts
4 Users
0 Reactions
1,002 Views
dpenrod
(@dpenrod)
Active Member
Joined: 19 years ago
Posts: 16
Topic starter  

I have a case in which the client wishes to recover date and time stamps from Safari's Internet cookies. We can see the cookies but not the date and time stamps, which are critical - of course. Unforturnately, the user had deleted Internet history so all that is left are the cookies. When I imaged the iPad in MPE+, no cookies were recorded - although they are clearly there.

Is there any way to download the cookies along with their date and time stamps?


   
Quote
(@mobileforensicswales)
Reputable Member
Joined: 17 years ago
Posts: 274
 

You will need to Jailbreak the device and download its files using the AFC protocol. What are your clients looking for… Have you considered all the tasty internet artifacts in the Cache.db

http//forensicsfromthesausagefactory.blogspot.co.uk/2010/06/safari-browser-cache-examination-of.html


   
ReplyQuote
(@alexc)
Reputable Member
Joined: 16 years ago
Posts: 301
 

Hi, if you have the ".binarycookies" files then you should be able to parse the files using Dunk

http//www.cclgroupltd.com/Buy-Software/dunk-web-cookie-analysis-tool.html

And if you can get hold of the Cache.db, I second mobileforensicswales enthusiasm that file is a goldmine.


   
ReplyQuote
dpenrod
(@dpenrod)
Active Member
Joined: 19 years ago
Posts: 16
Topic starter  

Thank you for your help. I purchased Dunk! from CCL Forensics and it works great. I have one question

Are the timestamps local time (Denver, Colorado) or are they UTC, which is 7 hours ahead of Denver time?


   
ReplyQuote
(@randomaccess)
Reputable Member
Joined: 14 years ago
Posts: 385
 

You will need to Jailbreak the device and download its files using the AFC protocol. What are your clients looking for… Have you considered all the tasty internet artifacts in the Cache.db

have you found a way to jailbreak the device?
i thought that the ipad1 was the only one that could be jailbroken


   
ReplyQuote
(@randomaccess)
Reputable Member
Joined: 14 years ago
Posts: 385
 

Thank you for your help. I purchased Dunk! from CCL Forensics and it works great. I have one question

Are the timestamps local time (Denver, Colorado) or are they UTC, which is 7 hours ahead of Denver time?

firstly, do you have another ipad to test it on?
and secondly, what ever your findings can you please post them up here?

or iphonewiki
or forensicwiki

thanks


   
ReplyQuote
Share: