IPhone 3G wth broke...
 
Notifications
Clear all

IPhone 3G wth broken home button

9 Posts
4 Users
0 Likes
277 Views
(@dave_g)
Posts: 3
New Member
Topic starter
 

Our unit has received an iPhone for examination which is in pretty bad shape. Its an IPhone3G, with a huge crack down the screen. The phone will boot up, and the screen responds to touch input, however the 'home' button does not seem to be working. The iPhone is passcode protected so the standard phone examination tools that we use (Cellebrite) will not touch it.

I have used Zadairski's tools in the past to recover an image of a passcode protected iPhone, but the recovery tools require the IPhone to be in DFU mode, which I cannot put the phone into due to the broken home button.

I have found software (recboot) which puts the iPhone into 'Recovery Mode', which allows me to run the 'irecovery -s' command, and from this I know the phone is running IOs 4.1 (iBoot 931.18.27). I did try to run Zadairski's recovery tools, for both mac and Linux, with the phone in recovery mode but had no joy.

The reason for this post is to ask if anyone knows of any software tools or low level command suites which will allow me to force the iPhone3G into DFU mode? Numerous Google searches have not yielded much useful information, although I did find a tool which claims to do it at this website however I could not get it to work (I believe it may be for older versions of iOS).

The requesting officer has offered to get the iPhone repaired, however I was hoping to leave that to a last resort.

Any help will be much appreciated

 
Posted : 16/12/2010 2:26 pm
 Doug
(@doug)
Posts: 185
Estimable Member
 

As far as I am aware there are no software solutions to put a device into DFU mode.

Taking an iPhone apart is actually pretty painless. For an intricate product it comes apart and goes back together without too much need for swearing !

There is a link to buy a new home button flex cable - £2.75
http//cgi.ebay.co.uk/IPHONE-3G-REPLACEMENT-HOME-BUTTON-MODULE-FLEX-UK-Seller-/150514713490?pt=UK_Mobiles_Accessories_RL&hash=item230b604392

Follow this link to for disassembly of the iPhone 3G
http//www.formymobile.co.uk/iphone3gdisassembly.php

 
Posted : 16/12/2010 3:18 pm
(@dficsi)
Posts: 283
Reputable Member
 

I may be naive, or even out of date, but I don't think Jonathan Zdziarski's software will allow the forensic acquisition of any firmware past 3.1.3 anyway so getting into DFU mode is unlikely to help with this particular method. AFAIK we're still waiting for a way to get into any devices with IOS 4+.
If this is accurate then getting the phone repaired will accomplish nothing.
Not the news you were hoping for, but at least you know where you stand with it.

 
Posted : 16/12/2010 3:23 pm
 Doug
(@doug)
Posts: 185
Estimable Member
 

DFICSI,

It is worth checking iPhoneinsecurity.com as there are scripts availible to recover the file system from an iOS4+ device. Sadly not a full disk image at this stage but you are atleast getting the full live file system.

 
Posted : 16/12/2010 4:12 pm
(@dficsi)
Posts: 283
Reputable Member
 

Thanks for that.

 
Posted : 16/12/2010 4:27 pm
(@dficsi)
Posts: 283
Reputable Member
 

Doug, scratch that. Full time LE or Military only. Not even forensic contractors allowed.

WHY?

 
Posted : 16/12/2010 4:29 pm
 Doug
(@doug)
Posts: 185
Estimable Member
 

The tools are free to LE but can be used 'at cost' in the private sector.

If you are interested in using the tools then it cannot hurt to drop him an e-mail to see if he will sell the tools to you.

I agree, it's not ideal. I get frustrated with LE only parts at conferences along with different pricing structures for LE vs private when it comes to training.

 
Posted : 16/12/2010 4:53 pm
(@dave_g)
Posts: 3
New Member
Topic starter
 

Thanks for the responses guys

I have taken an iphone apart before (my old one), as I remember it was quite painless, just a case of removing the two screws at the bottom and prising out the glass, however as this is an evidential device I am very nervous about doing that myself, especially with those flimsy ribbon cables inside.

I have the latest Zdairski tools as I am LE. He has a new recovery module for iOS 4.0 and 4.1 which can be used in Ubuntu 10.04. I have tried this module on my own iPhone3G with some success … it has issues with what version of itunes you are running, requires you to load the boot kernel and recovery module on itunes9.1 then downgrade to 8.1 before you run 'recover.sh', and regularly hangs or fails before a full image is taken. His latest scripts for mac will support 4.0 - 4.2 but only in iphone 3Gs and 4

To save me the heartache I may request the phone sent for repair, or if they are happy for me to have a pop at it I will try myself … if I can get the phone in DFU mode then that at least gives me a chance to run Zdairski's tools.

 
Posted : 16/12/2010 7:58 pm
sideshow018
(@sideshow018)
Posts: 84
Trusted Member
 

Hi Dave

We have a solution using chipoff to get the RAW data if that helps. Let me know if you want to go to that level to get your evidence.

Bob

cop.geek@gmail.com

 
Posted : 23/01/2011 3:03 pm
Share: