Skype main.db unall...
 
Notifications
Clear all

Skype main.db unallocated

9 Posts
5 Users
0 Reactions
2,251 Views
(@jaappie)
Active Member
Joined: 13 years ago
Posts: 11
Topic starter  

Hello all,

What if the suspect deleted his main.db file?(Where chat-conversations are stored from Skype).
I still find some text messages back by keyword searches. However there are a lot of weird symbols around the message. It's hard to define a structure/header/footer.

Is there any possibility to carve out the main.db file itself?

All tips are welcome.


   
Quote
minime2k9
(@minime2k9)
Honorable Member
Joined: 14 years ago
Posts: 481
 

I created a tool for recovering Skype messages from unallocated clusters

http//www.myforensictools.co.uk/skype-chat-recovery.php

Just use FTK imager to mount the image and then point it at the physical disk


   
ReplyQuote
(@belkasoft)
Estimable Member
Joined: 17 years ago
Posts: 169
 

Hello all,

What if the suspect deleted his main.db file?(Where chat-conversations are stored from Skype).
I still find some text messages back by keyword searches. However there are a lot of weird symbols around the message. It's hard to define a structure/header/footer.

Is there any possibility to carve out the main.db file itself?

All tips are welcome.

Please try our Belkasoft Evidence Center at http//belkasoft.com (demo is free).


   
ReplyQuote
PaulSanderson
(@paulsanderson)
Honorable Member
Joined: 19 years ago
Posts: 651
 

SkypeAlyzer can also recover deleted skype sqlite messages and can scan a physical/logical volume, dd or e01 image

http//sandersonforensics.com/forum/content.php?116-SkypeAlyzer


   
ReplyQuote
(@jaappie)
Active Member
Joined: 13 years ago
Posts: 11
Topic starter  

That's all nice for suggesting these products, but I'm not planning on buying these.
I'm a student that is focussing on a school project. The main focus is on carving data with EnCase, by using EnScripts for example.

So the main point is trying to understand the structure, because I know it should be possible.
That's what this topic is for, exchanging information or thoughts.


   
ReplyQuote
minime2k9
(@minime2k9)
Honorable Member
Joined: 14 years ago
Posts: 481
 

Hello all,
However there are a lot of weird symbols around the message. It's hard to define a structure/header/footer.
All tips are welcome.

The records you are seeing are SQLite records which have a well defined header and are easy to carve if you know how to figure out the structure. I suggest you read up on recovery of SQLite records, I believe Sausage Factory has a good article on this.


   
ReplyQuote
(@armresl)
Noble Member
Joined: 21 years ago
Posts: 1011
 

Hi,

You mentioned that all tips are welcome.

The 2 software recommendations are good ones and the fact that you are a student should have 0 bearing on the answer you are given.

When you graduate and get into RL, you will see that you will need to have these programs, why not get into them now and see what they do and how they do it so you can grasp the ideals and principles.

Hello all,

What if the suspect deleted his main.db file?(Where chat-conversations are stored from Skype).
I still find some text messages back by keyword searches. However there are a lot of weird symbols around the message. It's hard to define a structure/header/footer.

Is there any possibility to carve out the main.db file itself?

All tips are welcome.


   
ReplyQuote
(@jaappie)
Active Member
Joined: 13 years ago
Posts: 11
Topic starter  

Hi,

You mentioned that all tips are welcome.

The 2 software recommendations are good ones and the fact that you are a student should have 0 bearing on the answer you are given.

When you graduate and get into RL, you will see that you will need to have these programs, why not get into them now and see what they do and how they do it so you can grasp the ideals and principles.

Because using these programs isn´t hard at all, the program does all the work for you.

If you dig in deeper you´ll find out how exactly things work, which I believe are great for boosting your forensic skills.

@minime2k9 Thanks, very useful info!


   
ReplyQuote
minime2k9
(@minime2k9)
Honorable Member
Joined: 14 years ago
Posts: 481
 

Hi,

You mentioned that all tips are welcome.

The 2 software recommendations are good ones and the fact that you are a student should have 0 bearing on the answer you are given.

When you graduate and get into RL, you will see that you will need to have these programs, why not get into them now and see what they do and how they do it so you can grasp the ideals and principles.

Going to disagree there.
If he is a student then he is pretty abstracted from real life.
Also "I ran a tool" doesn't quite cut it in a piece of coursework, although they may be useful for comparisons.

To get a true understanding of the structure and the records themselves, his idea of creating an Enscript which would recover the records would give him the best understanding of Skype SQLite records, their structure and their recovery.


   
ReplyQuote
Share: