<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>the Forensics Ferret Blog</title>
	<atom:link href="http://forensicsferret.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://forensicsferret.wordpress.com</link>
	<description>Verb, 1. ferret out - search and discover through persistent investigation;</description>
	<lastBuildDate>Mon, 31 Oct 2011 02:03:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='forensicsferret.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/4619df142302990d5f37f31a295929e0?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>the Forensics Ferret Blog</title>
		<link>http://forensicsferret.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://forensicsferret.wordpress.com/osd.xml" title="the Forensics Ferret Blog" />
	<atom:link rel='hub' href='http://forensicsferret.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Samsung Galaxy S, Gingerbread and Kies.</title>
		<link>http://forensicsferret.wordpress.com/2011/08/23/samsung-galaxy-s-gingerbread-and-kies/</link>
		<comments>http://forensicsferret.wordpress.com/2011/08/23/samsung-galaxy-s-gingerbread-and-kies/#comments</comments>
		<pubDate>Tue, 23 Aug 2011 10:02:44 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=506</guid>
		<description><![CDATA[To say that Samsung Kies is a poor piece of software is an understatement. You only need to trawl through the Android or Samsung forums to see the frustration it causes people. It&#8217;s buggy, unstable and in many cases just doesn&#8217;t do what it&#8217;s supposed to do especially in terms of firmware upgrades. If you [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=506&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>To say that Samsung Kies is a poor piece of software is an understatement. You only need to trawl through the Android or Samsung forums to see the frustration it causes people. It&#8217;s buggy, unstable and in many cases just doesn&#8217;t do what it&#8217;s supposed to do especially in terms of firmware upgrades. If you are plagued by lag issues on Eclair and Froyo then you&#8217;ll probably argue that Samsung just can&#8217;t write software at all &#8211; for all their prowess in the  hardware space. </p>
<p>Anyway I struggled with the Froyo upgrade for months before finally getting Kies to work albeit with a newer &#8216;improved&#8217; version of Kies (v2). I&#8217;ve documented the steps below. These also apply to the recent Gingerbread 2.3.3. Do note that Google recently (April 2011) put a stop to any further downloads of Gingerbread for the Galaxy S due to unknown reasons but knowing Samsung&#8217;s track record it doesn&#8217;t really surprise me. The update was subsequently reinstated and having run Gingerbread on my Galaxy S for a few weeks already it&#8217;s well worth the effort. It&#8217;s given new life to my oldish phone and I&#8217;ve put off any future Android purchase until Ice Cream Sandwich is available later this year. </p>
<p>So here goes:  </p>
<p>Preparation: </p>
<p>+ Remove any One Click Lag Fixes (OCLF). This step is critically important as you can brick your phone trying to do an upgrade if you don&#8217;t remove all OCLFs. </p>
<p>+ Some people say to unroot your phone if it&#8217;s rooted but I didn&#8217;t do this and had no issues. You will lose root however and you will need to reapply it after the upgrade. </p>
<p>+ Charge the phone fully to 100%. Actually the upgrade appears to work as long as you are somewhere above 50% charge. </p>
<p>+ Ensure 3GB free space on the Windows PC being used to do the upgrade or you&#8217;ll get errors. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/space.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/space.png?w=412&#038;h=259" alt="" title="space" width="412" height="259" class="alignnone size-full wp-image-521" /></a> </p>
<p>+ Remove any home screens and revert back to twlauncher default. You don&#8217;t need to uninstall. I use the home switcher app in Marketplace to switch between Launcher Pro and TWLauncher. If you&#8217;re on Froyo there&#8217;s a Froyo version of Home Switcher but the older Eclair version worked fine for me. </p>
<p>+ Remove the external sd card from the phone. This is quirk with MTP protocol that can send the phone (and you) loopy. </p>
<p>+ Finally if you use your phone for critical communications like work you may want to keep an old spare phone at hand in case the upgrade fails on you.  </p>
<p>+ Download and install the latest version of Samsung Kies (v2) </p>
<p>Steps: </p>
<p>+ Close Kies</p>
<p>+ Put the phone in USB Debugging Mode (Settings, Applications, Development) </p>
<p>+ Connect phone to the Windows PC and allow Windows to install the relevant drivers</p>
<p>+ Check Device Manager for proper install </p>
<p>+ The following screenshots show correct installation in Device Manager</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/1-gt-i9000.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/1-gt-i9000.png?w=279&#038;h=162" alt="" title="1-gt-i9000" width="279" height="162" class="alignnone size-full wp-image-513" /></a></p>
<p>+ Now take the phone out of USB debugging mode</p>
<p>+ Put the phone into Kies Mode under USB Settings </p>
<p>+ Put the phone at the Idle screen and unlock any lock pattern </p>
<p>+ Connect the phone to the PC</p>
<p>+ Wait for the Connected message from MTP on the phone</p>
<p>+ You must have the Connected message before going any further. If the phone sits at Initialising and never moves to Connect try rebooting the PC and then the phone is still having issues. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/2-modem.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/2-modem.png?w=338&#038;h=123" alt="" title="Modem" width="338" height="123" class="alignnone size-full wp-image-515" /></a></p>
<p>+ Now open Kies.</p>
<p>+ Don&#8217;t touch Kies when you see it in the Taskbar. Don&#8217;t maxmize it. Not sure what difference this makes and maybe it doesn&#8217;t on the majority of machines but it caused issues for me if I maximized it. </p>
<p>+ Kies should pop up a dialog that your phone needs a firmware upgrade and prompt you to click Update .</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/08/update-firmware.png"><img src="http://forensicsferret.files.wordpress.com/2011/08/update-firmware.png?w=487&#038;h=372" alt="" title="update-firmware" width="487" height="372" class="alignnone size-full wp-image-532" /></a> </p>
<p>+ If you are on Eclair you will need two upgrades &#8211; one to Froyo and a second to Gingerbread and again this is confirmed by a dialog box.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/notice.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/notice.png?w=585&#038;h=271" alt="" title="notice" width="585" height="271" class="alignnone size-full wp-image-518" /></a></p>
<p>+ The following screens are shown on the PC.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/caution.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/caution.png?w=600&#038;h=503" alt="" title="caution" width="600" height="503" class="alignnone size-full wp-image-516" /></a></p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/prepare.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/prepare.png?w=436&#038;h=383" alt="" title="prepare" width="436" height="383" class="alignnone size-full wp-image-519" /></a></p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/08/firmware-progress.png"><img src="http://forensicsferret.files.wordpress.com/2011/08/firmware-progress.png?w=600&#038;h=523" alt="" title="firmware progress" width="600" height="523" class="alignnone size-full wp-image-536" /></a></p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/07/complete.png"><img src="http://forensicsferret.files.wordpress.com/2011/07/complete.png?w=600&#038;h=523" alt="" title="complete" width="600" height="523" class="alignnone size-full wp-image-517" /></a></p>
<p>Then a big yellow &#8220;Downloading. Do not turn off target&#8221; graphic appears on the phone screen with a blue progress indicator. A progress indicator also appears in Kies.</p>
<p>Phone reboots by itself after some final installation steps scroll past on the phone display.<br />
Kies confirms that upgrade is complete and provides backup/restore message.<br />
The phone can take a long time to reboot after the upgrade. Much longer than usual. Be patient.</p>
<p>When the phone reboots it asks questions like:</p>
<p>1. Setting On-screen keyboard settings<br />
2. Internet connection (3G network or wifi)<br />
3. Whether you wish to use google location services (no thanks I uncheck this)</p>
<p>Then finally it scans all media files on the sd card which can take a minute or so.</p>
<p>To confirm your firmware update go to Settings, About Phone and check the Firmware version. </p>
<p>To update to Gingerbread you need to go through the same steps again with Kies. </p>
<p>That&#8217;s it. Good luck. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/506/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/506/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/506/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=506&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2011/08/23/samsung-galaxy-s-gingerbread-and-kies/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/space.png" medium="image">
			<media:title type="html">space</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/1-gt-i9000.png" medium="image">
			<media:title type="html">1-gt-i9000</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/2-modem.png" medium="image">
			<media:title type="html">Modem</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/08/update-firmware.png" medium="image">
			<media:title type="html">update-firmware</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/notice.png" medium="image">
			<media:title type="html">notice</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/caution.png" medium="image">
			<media:title type="html">caution</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/prepare.png" medium="image">
			<media:title type="html">prepare</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/08/firmware-progress.png" medium="image">
			<media:title type="html">firmware progress</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/complete.png" medium="image">
			<media:title type="html">complete</media:title>
		</media:content>
	</item>
		<item>
		<title>Cable connectivity for Tableau T35e Forensic SATA bridge</title>
		<link>http://forensicsferret.wordpress.com/2011/07/13/cable-connectivity-for-tableau-t35e-forensic-sata-bridge/</link>
		<comments>http://forensicsferret.wordpress.com/2011/07/13/cable-connectivity-for-tableau-t35e-forensic-sata-bridge/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 08:21:22 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=509</guid>
		<description><![CDATA[This is less of a blog entry and more of a reference image for correct cable connectivity when attaching a SATA drive to a Tableau T35e USB to SATA forensic bridge. So here it goes:<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=509&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is less of a blog entry and more of a reference image for correct cable connectivity when attaching a SATA drive to a Tableau T35e USB to SATA forensic bridge. </p>
<p>So here it goes:</p>
<div id="attachment_510" class="wp-caption alignnone" style="width: 610px"><a href="http://forensicsferret.files.wordpress.com/2011/07/2011-07-13-09-54-24.jpg"><img src="http://forensicsferret.files.wordpress.com/2011/07/2011-07-13-09-54-24.jpg?w=600&#038;h=450" alt="" title="Tableau T35e " width="600" height="450" class="size-full wp-image-510" /></a><p class="wp-caption-text">Tableau T35e SATA bridge</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/509/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/509/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/509/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/509/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/509/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/509/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/509/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/509/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=509&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2011/07/13/cable-connectivity-for-tableau-t35e-forensic-sata-bridge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/07/2011-07-13-09-54-24.jpg" medium="image">
			<media:title type="html">Tableau T35e </media:title>
		</media:content>
	</item>
		<item>
		<title>Importance of Preparedness</title>
		<link>http://forensicsferret.wordpress.com/2011/05/26/importance-of-preparedness/</link>
		<comments>http://forensicsferret.wordpress.com/2011/05/26/importance-of-preparedness/#comments</comments>
		<pubDate>Wed, 25 May 2011 21:50:34 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=446</guid>
		<description><![CDATA[This is my first non-technical blog post but arguably on a topic of similar importance to technical ability namely the importance of being prepared in advance of a forensics engagement. Rather than write an essay I&#8217;m going to put this down in ten bullet points. 1. Firstly prepare a forensics jump bag. There are plenty [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=446&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is my first non-technical blog post but arguably on a topic of similar importance to technical ability namely the importance of being prepared in advance of a forensics engagement. Rather than write an essay I&#8217;m going to put this down in ten bullet points. </p>
<p>1. Firstly prepare a forensics jump bag. There are plenty of web sites that list the basics of a jump bag and in time you&#8217;ll customize your own. Don&#8217;t pilfer from the bag when not in use. Have it beside you at all times so you can pick it up and go at a moment&#8217;s notice. Include the following items at a minimum: </p>
<p>- Pens<br />
- Paper<br />
- Notepads where you can&#8217;t easily remove pages. No ring pads.<br />
- Name cards<br />
- LAN/cross cables (clearly marked as such)<br />
- Forensics CDs (Helix, Backtrack, Linen)<br />
- Thumb drives<br />
- Screwdriver set<br />
- IDE/SATA cables<br />
- Evidence labels<br />
- Cheap Digital camera </p>
<p>2. Have a forensics laptop separate from your production laptop. Install Encase, FTK, Sleuthkit, Tableau software and any other forensics tools you need. Avoid using it as your production laptop. i.e. No email, Microsoft Office, Web Browsing. </p>
<p>3. Bring documented procedures to double check your approach against. Also bring soft and hard copies of Chain of Custody and Acquisition Seizure Log documents. Have everything written down even for the most simple tasks. You&#8217;d be amazed at how much and how quickly you forget things even from a recent engagement. </p>
<p>4. Test carry your forensics field kit through airport customs in advance of any engagement to ensure you have anticipated questions or security/customs issues. The last thing you want is to arrive on site without your Tableau or Webetech hardware write blockers. If you are in a geographically dispersed region (as I am in Asia) it pays to understand how different customs practices differ between countries. You may be good-to-go in one country but hopelessly stymied in another. It&#8217;s not practical to test every location so some background research might be the only other option. </p>
<p>5. When imaging take two sets of images and send one set back via company internal mail or courier. Password-protect the other set of images and hand carry back with you to the office. This means that if customs take possession of your hand-carried set at least the couriered set should make it to the office within a couple of days. Also make allowances for the additional time needed for taking two sets instead of one.  </p>
<p>6. Make sure you have IT support available on the other end especially if it&#8217;s over a weekend and you need access to machine rooms, other secure areas or information about other peculiarities of the IT setup at your destination. </p>
<p>7. Make sure there isn&#8217;t a building power down the weekend of your engagement. (yes this happened to me once). If there is then ensure you arrange for a UPS protected area to do your work. </p>
<p>8. There will be cases when you go on-site and are faced with a completely new set of circumstances. However try to test different scenarios in the lab as much as possible. It&#8217;s impossible to preempt all situations but have the basic stuff tested and documented and be comfortable with it. </p>
<p>9. Know your tools. Know their strengths and just as important &#8211; know their weaknesses. Stick with what you know works. A customer engagement isn&#8217;t the best time for experimenting. </p>
<p>10. Have an agreed means of contacting your other team members should the need arise. You can&#8217;t know everything about every scenario and some situations require group-think to resolve.  </p>
<p>Note: Make sure you know where to buy snacks and drinks. If you need to work into the night get the phone number of a food delivery service from the local staff or stock up on sandwiches and chocolate before all the stores close for the day. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/446/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/446/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/446/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=446&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2011/05/26/importance-of-preparedness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>
	</item>
		<item>
		<title>Imaging with the Tableau T35e and Encase</title>
		<link>http://forensicsferret.wordpress.com/2011/04/27/imaging-with-the-tableau-t35e-and-encase/</link>
		<comments>http://forensicsferret.wordpress.com/2011/04/27/imaging-with-the-tableau-t35e-and-encase/#comments</comments>
		<pubDate>Wed, 27 Apr 2011 10:06:00 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=457</guid>
		<description><![CDATA[The Tableau T35e is a SATA/IDE forensic write blocker and allows imaging of 3.5&#8243; and 2.5&#8243; IDE and SATA drives. The kit comes with a 2.5&#8243; hard drive adapter for imaging notebook drives. The below image shows the T35e connected to a 2.5&#8243; 120GB Western Digital drive. The Tableau is then connected to an imaging [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=457&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The Tableau T35e is a SATA/IDE forensic write blocker and allows imaging of 3.5&#8243; and 2.5&#8243; IDE and SATA drives. The kit comes with a 2.5&#8243; hard drive adapter for imaging notebook drives. </p>
<p>The below image shows the T35e connected to a 2.5&#8243; 120GB Western Digital drive. The Tableau is then connected to an imaging workstation (out of picture) via the provided USB cable. Power is provided to the WD drive via the Tableau device as shown. For correct connectivity the IDE Detect, Host Detect and Write Block LEDs should be illuminated. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/2011-04-27-11-29-56.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/2011-04-27-11-29-56.png?w=600&#038;h=450" alt="" title="Tableau T35e" width="600" height="450" class="alignnone size-full wp-image-458" /></a></p>
<p>Below screenshot shows the Tableau software on the imaging workstation confirming Tableau connectivity to the target drive. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/tableau.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/tableau.png?w=600&#038;h=171" alt="" title="tableau software" width="600" height="171" class="alignnone size-full wp-image-462" /></a></p>
<p>Note that under &#8216;Forensic Bridge Information&#8217; the entry for the T35e says &#8216;Read Only Mode&#8217;. On the underside of the Tableau there is a 4-position DIP switch that can be used to set a variety of configurations. The switches are accessed by removing a small knockout panel on the bottom edge of the bridge’s plastic enclosure. The default READ-ONLY mode can be used to take forensically sound images from subject hard disks. In most circumstances Windows XP handles Tableau READ-ONLY bridges correctly with switches 2 and 3 in the OFF (default) state. See the T35e User&#8217;s Guide for more details. </p>
<p>Imaging was done using Encase and is detailed in the following screenshots.</p>
<p>1. Launch Encase</p>
<p>2. Create a New Case</p>
<p>3. Click Add Device</p>
<p>4. Uncheck &#8216;Sessions&#8217; check box</p>
<p>5. Blue check &#8216;Local Drives&#8217;</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/encase1.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/encase1.png?w=600&#038;h=397" alt="" title="Add Device" width="600" height="397" class="alignnone size-full wp-image-469" /></a></p>
<p>6. Allow Encase to process locally attached drives</p>
<p>The following screenshot shows the list of local drives processed by Encase.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/encase2.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/encase2.png?w=600&#038;h=397" alt="" title="Choose Devices" width="600" height="397" class="alignnone size-full wp-image-470" /></a></p>
<p>7. Blue check the drive to be Previewed and then Click Next and Finish as in the screenshot below.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/encase3.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/encase3.png?w=600&#038;h=395" alt="" title="Preview Devices" width="600" height="395" class="alignnone size-full wp-image-471" /></a></p>
<p>8. The activity LED on the Tableau device should flicker red as the drive is being previewed</p>
<p>9. When completed the preview will be added to the case</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/encase4.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/encase4.png?w=600&#038;h=227" alt="" title="add to case " width="600" height="227" class="alignnone size-full wp-image-473" /></a></p>
<p>10. You can then acquire a physical image of the drive by right clicking and choosing &#8216;Acquire&#8217;</p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/04/encase5.png"><img src="http://forensicsferret.files.wordpress.com/2011/04/encase5.png?w=387&#038;h=397" alt="" title="acquire" width="387" height="397" class="alignnone size-full wp-image-474" /></a></p>
<p>A full bit for bit, forensically sound image will be taken of your target drive. The image is stored in Encase E01 format. Make sure to save the case before you exit. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/457/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/457/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/457/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=457&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2011/04/27/imaging-with-the-tableau-t35e-and-encase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/2011-04-27-11-29-56.png" medium="image">
			<media:title type="html">Tableau T35e</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/tableau.png" medium="image">
			<media:title type="html">tableau software</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/encase1.png" medium="image">
			<media:title type="html">Add Device</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/encase2.png" medium="image">
			<media:title type="html">Choose Devices</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/encase3.png" medium="image">
			<media:title type="html">Preview Devices</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/encase4.png" medium="image">
			<media:title type="html">add to case </media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/04/encase5.png" medium="image">
			<media:title type="html">acquire</media:title>
		</media:content>
	</item>
		<item>
		<title>Extracting domain names from proxy logs with python&#8217;s &#8216;urlparse&#8217;</title>
		<link>http://forensicsferret.wordpress.com/2011/02/28/extracting-domain-names-from-proxy-logs-with-pythons-urlparse/</link>
		<comments>http://forensicsferret.wordpress.com/2011/02/28/extracting-domain-names-from-proxy-logs-with-pythons-urlparse/#comments</comments>
		<pubDate>Mon, 28 Feb 2011 10:14:51 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=432</guid>
		<description><![CDATA[During a malware investigation it helps to be able to extract the domain portion of a URL from a web proxy log to identify the communications between a compromised host and an external botnet command and control server. This assumes you know the URL being used for outbound communication, have an infrastructure where all outbound [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=432&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>During a malware investigation it helps to be able to extract the domain portion of a URL from a web proxy log to identify the communications between a compromised host and an external botnet command and control server. This assumes you know the URL being used for outbound communication, have an infrastructure where all outbound http traffic is routed through a proxy under control of your organization or have access to the logs from the proxy server. </p>
<p>There are plenty of complicated regex expressions for parsing URLs and extracting domains but Python provides a much more elegant way to do this using its &#8216;urlparse&#8217; module. The following sample code takes a single proxy log file as input and extracts only the domain portion of the URL for further analysis. </p>
<p>[usage: python parseurl.py logfilename] </p>
<p><strong>#!/usr/bin/python<br />
import re<br />
import sys<br />
from urlparse import urlparse</p>
<p>f = open(sys.argv[1], &#8220;r&#8221;)</p>
<p>for line in f.readlines():<br />
&nbsp;line = re.findall(r&#8217;(https?://\S+)&#8217;, line)<br />
&nbsp;if line:<br />
&nbsp;&nbsp;parsed=urlparse(line[0])<br />
&nbsp;&nbsp;print parsed.hostname<br />
f.close()<br />
</strong></p>
<p>You can carry out further log reduction by piping the results through &#8216;uniq&#8217;.</p>
<p><strong>$ python parseurl.py proxylog-zeus-10.1.1.1-2011.02.16_15.54.csv</strong></p>
<p>bits.wikimedia.org<br />
upload.wikimedia.org<br />
geoiplookup.wikimedia.org<br />
en.wikipedia.org<br />
bits.wikimedia.org<br />
en.wikipedia.org<br />
ad.doubleclick.net<br />
s0.2mdn.net<br />
ad.doubleclick.net<br />
s0.2mdn.net<br />
tools.google.com<br />
library.municode.com<br />
tools.google.com<br />
15february.adina-blog.co.cc<br />
freephoenixbirdspace.com<br />
www.adb.cba.pl </p>
<p>[SNIP] </p>
<p>The last three domains look like they need further investigation. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/432/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/432/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/432/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/432/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/432/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/432/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/432/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/432/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=432&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2011/02/28/extracting-domain-names-from-proxy-logs-with-pythons-urlparse/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>
	</item>
		<item>
		<title>Investigating the Samsung Galaxy Tab</title>
		<link>http://forensicsferret.wordpress.com/2011/01/24/samsung-galaxy-tab-forensics/</link>
		<comments>http://forensicsferret.wordpress.com/2011/01/24/samsung-galaxy-tab-forensics/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 07:23:52 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=330</guid>
		<description><![CDATA[- Introduction I now have a new addition to my Android family of devices namely the Galaxy Tab. I had a play around with the device to see if there were any differences between it and the Galaxy phone from a forensics analyst point of view. I didn&#8217;t expect to find many. The Tab ships [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=330&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>- Introduction</strong></p>
<p>I now have a new addition to my Android family of devices namely the Galaxy Tab. I had a play around with the device to see if there were any differences between it and the Galaxy phone from a forensics analyst point of view. I didn&#8217;t expect to find many. The Tab ships by default with Android 2.2 Froyo. My Galaxy phone came with Android 2.1 and the responsiveness of 2.2 is immediately obvious. None of the infamous 2.1 lag. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/01/tab1.jpg"><img src="http://forensicsferret.files.wordpress.com/2011/01/tab1.jpg?w=540&#038;h=493" alt="" title="tab" width="540" height="493" class="alignnone size-full wp-image-427" /></a></p>
<p>Unlike the Samsung Galaxy phone the back of the Tab is sealed. The SIM and SD Card slots are situated along the right edge together with the power/screen lock and volume rocker. It&#8217;s not immediately obvious how to orient the SIM card when you slot it in for the first time. I had to find an online diagram to assist me. The SIM card itself (as with the Galaxy phone) is the traditional SIM size and not the micro SIM that the iPad uses. </p>
<p>The device doesn&#8217;t have the standard micro USB connector that the Galaxy phone sports. On its underside it does however have a proprietary Samsung 30-pin connector which allows you (along with the shipped USB cable) to connect a Galaxy tab to a PC or Mac. The connector looks similar to the Apple iPad / iPhone connector  but it is in actual fact different. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/connector1.jpg"><img src="http://forensicsferret.files.wordpress.com/2010/12/connector1.jpg?w=256&#038;h=192" alt="" title="connector1" width="256" height="192" class="alignnone size-full wp-image-366" /></a></p>
<p>Apparently Samsung did consider using a standard microUSB port instead, but that would’ve ruled out accessories such as HDMI cables, so they went for the proprietary connector. Once connected via USB to my Mac I was able to connect to the device via ./adb and the Android SDK as I did previously with the Galaxy phone.  </p>
<p>One item of note with the Galaxy Tab (maybe it&#8217;s an Android 2.2 thing, not sure) but on the Tab if you connect the device to your workstation via USB first and then try to enabled USB Debugging you&#8217;ll find the option dimmed. The solution is to remove the USB cable between the Tab and your workstation then go into Settings/Applications first, enable USB Debugging then reconnect the Tab. Once you do this you can run ./adb devices and you&#8217;ll see the Tab show up in the list of attached devices. </p>
<p>$ ./adb devices<br />
List of devices attached<br />
10000c22c5e5	device</p>
<p>$</p>
<p><strong>- Turning off radio devices</strong></p>
<p>Use &#8216;Flight Mode&#8217; to turn off wireless and data network access on a seized Galaxy Tab. This prevents any data being received by the phone externally. This means an examiner can avoid turning off a phone which when turned on again may present a PIN password prompt. Turning off and on a phone may also interfere with date and time stamps of files on the phone. The &#8216;Flight Mode&#8217; menu can be accessed on the Galaxy Tab by pressing and holding the power button for 2 seconds. </p>
<p>Remember that you should only submit as evidence data recovered from the phone before it was seized so it&#8217;s important to drop the phone in a Faraday bag or turn off radio devices as soon as possible after the phone is seized. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/01/flightmode.png"><img src="http://forensicsferret.files.wordpress.com/2011/01/flightmode.png?w=366&#038;h=264" alt="" title="flightmode" width="366" height="264" class="alignnone size-full wp-image-407" /></a></p>
<p><strong>- Rooting the Tab</strong></p>
<p>Pulling data off the Tab requires admin access so although it&#8217;s not ideal as a forensically sound approach we do need to &#8216;root&#8217; the Tab to gain superuser privileges. I used the Z4Root one click root from ZDA to root the phone. It&#8217;s decidedly easier than the 2.1 root process of rebooting into recovery mode and downloading and applying the required update.zip. With Z4Root you have the option of a temporary root until the next reboot or a permanent root. You also have the option of unrooting the phone. Z4Root used to be available on the Marketplace but it was pulled. You can still find it online through Google. The .apk file installs an app in the Applications folder which you then tap on to root the phone. Following is a screenshot of Z4Root after rooting my Tab. The install screen looks similar. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/z4root.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/z4root.png?w=300&#038;h=512" alt="" title="z4root" width="300" height="512" class="alignnone size-full wp-image-337" /></a></p>
<p>When an application requests superuser privileges z4root pops up the following request dialog:</p>
<p> <a href="http://forensicsferret.files.wordpress.com/2011/01/request.png"><img src="http://forensicsferret.files.wordpress.com/2011/01/request.png?w=406&#038;h=336" alt="" title="Request for superuser privileges" width="406" height="336" class="alignnone size-full wp-image-375" /></a></p>
<p><strong>- Forensic Analysis </strong></p>
<p>Circling back to my earlier Android forensics blog posts <a href="http://forensicsferret.wordpress.com/2010/09/30/android-browser-forensics/">here</a> and <a href="http://forensicsferret.wordpress.com/2010/12/06/extracting-android-call-history-with-mobiledit/">here</a> I first wanted to see if the ViaForensics and MobilEdit applications installed and ran without issue on the Galaxy tab. They both did and I won&#8217;t recycle the earlier work for this blog post.  </p>
<p>Once the phone was rooted the next thing I did was to run ./adb shell from the Android SDK and su to root then run mount. I noticed that the /data folder was not mounted as loop0 as it was with the Galaxy phone. On my Tab it was mounted as /dev/block/mmcblk0p2. I found this unusual so I did some research and it appears that the One Click Lag Fix (OCLF) for Android makes use of loopback mounts and I had run OCLF on my Galaxy phone to help with the lag issues. To test I removed the OCLF from my Galaxy phone and after removal my /data folder was no longer mounted on /dev/loop0 but mounted as /dev/block/mmcblk0p2. </p>
<p>So the default device for /data on the Galaxy Tab or Galaxy S phone is /dev/block/mmcblk0p2 &#8211; (where &#8216;mmc&#8217; refers to MultiMediaCard &#8211; a flash memory card standard and is a block specific device and on the Galaxy tab is formatted as vfat).   </p>
<p>The following shows the results of issuing the mount command on the Tab. </p>
<p><strong>$ su<br />
# mount<br />
rootfs / rootfs ro,relatime 0 0<br />
tmpfs /dev tmpfs rw,relatime,mode=755 0 0<br />
devpts /dev/pts devpts rw,relatime,mode=600 0 0<br />
proc /proc proc rw,relatime 0 0<br />
sysfs /sys sysfs rw,relatime 0 0<br />
none /acct cgroup rw,relatime,cpuacct 0 0<br />
/dev/block/stl6 /mnt/.lfs j4fs rw,relatime 0 0<br />
tmpfs /mnt/asec tmpfs rw,relatime,mode=755,gid=1000 0 0<br />
none /dev/cpuctl cgroup rw,relatime,cpu 0 0<br />
/dev/block/stl9 /system rfs ro,relatime,vfat,log_off,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /data rfs rw,nosuid,nodev,relatime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/stl10 /dbdata rfs rw,nosuid,nodev,relatime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/stl11 /cache rfs rw,nosuid,nodev,relatime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/stl3 /efs rfs rw,nosuid,nodev,relatime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/vold/179:1 /mnt/sdcard vfat rw,dirsync,nosuid,nodev,noexec,relatime,uid=1000,gid=1015,fmask=0002,dmask=0002,allow_utime=0020,codepage=cp437,iocharset=iso8859-1,shortname=mixed,utf8,errors=remount-ro 0 0</strong></p>
<p>We then try to image /data. As you can see below the process for imaging the /data folder is no different to the process we followed for the Galaxy S phone. The only slight difference is that sdcard is mounted on /mnt/sdcard. </p>
<p><strong># cd /mnt/sdcard</strong></p>
<p><strong># ls -l<br />
drwxrwxr-x system   sdcard_rw          2005-01-01 00:00 svox<br />
drwxrwxr-x system   sdcard_rw          2010-11-06 03:45 Android<br />
drwxrwxr-x system   sdcard_rw          2010-11-06 03:46 LOST.DIR<br />
drwxrwxr-x system   sdcard_rw          2010-11-06 03:46 external_sd<br />
drwxrwxr-x system   sdcard_rw          2010-12-13 22:18 DCIM<br />
drwxrwxr-x system   sdcard_rw          2010-12-14 00:23 download<br />
drwxrwxr-x system   sdcard_rw          2010-12-07 19:30 mabilo<br />
drwxrwxr-x system   sdcard_rw          2010-12-31 17:00 data<br />
drwxrwxr-x system   sdcard_rw          2010-12-13 22:18 ScreenCapture<br />
drwxrwxr-x system   sdcard_rw          2011-01-22 15:33 screenshots<br />
drwxrwxr-x system   sdcard_rw          2010-12-13 23:40 Video<br />
drwxrwxr-x system   sdcard_rw          2010-12-14 13:33 SpeedSoftware<br />
-rwxrwxr-x system   sdcard_rw        8 2010-12-14 13:47 devicefriendlyname.txt<br />
drwxrwxr-x system   sdcard_rw          2010-12-22 23:10 Music<br />
#<br />
</strong><br />
<strong># pwd<br />
/mnt/sdcard</strong></p>
<p>Create a new directory on the sdcard called &#8216;forensics&#8217; to take the new image file then &#8216;dd&#8217; the /data folder. </p>
<p><strong># mkdir forensics</strong></p>
<p><strong># dd if=/dev/block/mmcblk0p2 of=/mnt/sdcard/forensics/imagefile.dd<br />
3932032+0 records in<br />
3932032+0 records out<br />
2013200384 bytes transferred in 360.356 secs (5586698 bytes/sec)<br />
#</strong></p>
<p>We then exit back to our Mac Terminal prompt and issue an ./adb pull to copy the image file off the phone and back to our forensics workstation. </p>
<p><strong>#exit<br />
$exit</p>
<p>$ ./adb pull /mnt/sdcard/forensics/imagefile.dd /Applications/android-sdk-mac_x86/tools<br />
5821 KB/s (2013200384 bytes in 337.709s)<br />
$ </strong></p>
<p><strong>- Investigating the &#8216;System&#8217; Folder</strong></p>
<p>In certain circumstances it may be worth while imaging the /system folder. /System contains operating system files and configuration details and is mapped to /dev/block/stl9. </p>
<p><strong>#mount </strong></p>
<p><strong>[snip]</p>
<p>/dev/block/stl9 /system rfs ro,relatime,vfat,log_off,check=no,gid/uid/rwx,iocharset=utf8 0 0</strong></p>
<p>Let&#8217;s go ahead and image the /system folder. </p>
<p><strong># dd if=/dev/block/stl9 of=/mnt/sdcard/forensics/imagefile_sys.dd<br />
656384+0 records in<br />
656384+0 records out<br />
336068608 bytes transferred in 38.858 secs (8648633 bytes/sec)<br />
# exit<br />
$ exit</strong></p>
<p>Again we pull the resulting image back to our forensics workstation. </p>
<p><strong>#<br />
$./adb pull /mnt/sdcard/forensics/imagefile_sys.dd /Applications/android-sdk-mac_x86/tools<br />
3533 KB/s (336068608 bytes in 92.888s)<br />
$<br />
</strong></p>
<p>The system folder is unlikely to see major file activity so it may be worthwhile creating a timeline of file system activity on this folder to detect unusual activity especially if you&#8217;re dealing with a malware investigation. You can create a rudamentary timeline using the &#8216;ls&#8217; command and sorting by date. This will sort files by subfolder so it&#8217;s not ideal. A more efficient approach is to use the Sleuthkit&#8217;s &#8216;fls&#8217; and &#8216;mactime&#8217; tools to respectively create a Bodyfile and resulting Timeline. In the example below there are very few files with date stamps later than the date the phone was installed. This doesn&#8217;t of course mean malware couldn&#8217;t manipulate time stamps to hide among system files but a timeline is still a good place to start. </p>
<p><strong># ls -latrR /media/android &gt;&gt; timeline.android<br />
# gedit timeline.android</p>
<p>/media/android:<br />
total 144<br />
drwxr-xr-x 14 root root  4096 1970-01-01 08:00 .<br />
drwxr-xr-x  5 root root 28672 2010-10-02 01:24 lib<br />
drwxr-xr-x  2 root root  4096 2010-10-02 01:24 xbin<br />
drwxr-xr-x  4 root root  4096 2010-10-02 01:24 media<br />
drwxr-xr-x  7 root root  4096 2010-10-02 01:24 usr<br />
drwxr-xr-x  2 root root  8192 2010-10-02 01:24 framework<br />
drwxr-xr-x  2 root root  4096 2010-10-02 01:24 fonts<br />
drwxr-xr-x 11 root root  4096 2010-10-02 01:24 etc<br />
-rwxr-xr-x  1 root root    227 2010-10-02 01:24 default.prop<br />
drwxr-xr-x  2 root root  4096 2010-10-02 01:24 cameradata<br />
-rwxr-xr-x  1 root root  2276 2010-10-02 01:24 build.prop<br />
drwxr-xr-x  3 root root  4096 2010-11-06 03:45 wallpaper<br />
-rwxr-xr-x  1 root root  1104 2010-11-06 03:45 SW_Configuration.xml<br />
-rwxr-xr-x  1 root root    12 2010-11-06 03:45 CSCVersion.txt<br />
-rwxr-xr-x  1 root root   278 2010-11-06 03:45 CSCFiles.txt<br />
drwxr-xr-x 16 root root  4096 2010-11-06 03:45 csc<br />
drwxr-xr-x  3 root root 16384 2010-12-14 00:58 bin<br />
drwxr-xr-x  2 root root 32768 2010-12-14 00:58 app<br />
drwxr-xr-x 14 root root  4096 2011-02-03 14:49 ..</p>
<p>/media/internal/lib:<br />
total 57364<br />
drwxr-xr-x 14 root root    4096 1970-01-01 08:00 ..<br />
-rwxr-xr-x  1 root root   75136 2010-10-02 01:24 libz.so<br />
-rwxr-xr-x  1 root root 2012648 2010-10-02 01:24 libXt9core.so<br />
-rwxr-xr-x  1 root root   42752 2010-10-02 01:24 libxml2wbxml.so<br />
-rwxr-xr-x  1 root root    9492 2010-10-02 01:24 libwpa_client.so<br />
-rwxr-xr-x  1 root root    5870 2010-10-02 01:24 libwmx_oma.so<br />
-rwxr-xr-x  1 root root  116232 2010-10-02 01:24 libwmlscriptcore.so<br />
-rwxr-xr-x  1 root root  342360 2010-10-02 01:24 libwmdrm.so<br />
-rwxr-xr-x  1 root root   13544 2010-10-02 01:24 libwmdrm_jni.so<br />
-rwxr-xr-x  1 root root   29812 2010-10-02 01:24 libwlservice.so</p>
<p>[snip]<br />
</strong></p>
<p><strong>- Android 2.2 and applications on SD card</strong> </p>
<p>With Android 2.2 a user now has the ability to install apps on an external SD card. By default, applications continue to be installed in internal memory however in the Settings/Applications menu you can move apps to the SD Card with one click if the application itself supports it. This is something to keep in mind when investigating the use of Android applications. The application itself may be found in one of two different locations on the phone. Note however that the application data continues to reside on internal memory in the /data folder. </p>
<p>The following screenshot shows the &#8220;Move to SD card&#8221; option for the Skype application on Android 2.2. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2011/01/move_to_sd1.png"><img src="http://forensicsferret.files.wordpress.com/2011/01/move_to_sd1.png?w=430&#038;h=326" alt="" title="move_to_sd" width="430" height="326" class="alignnone size-full wp-image-394" /></a></p>
<p><strong>- Conclusion</strong></p>
<p>Apart from the different physical attributes of the Galaxy Tab over the Galaxy phone there is very little difference in the way the two are approached from a forensics standpoint. The underlying OS on both devices is Linux and the File system format is VFAT so many of the open source Linux based forensics tools work well on the Samsung Android devices. </p>
<p>There is talk in the industry of Google standardizing on the EXT4 filesystem for all future releases of the Android OS. This should make life a little easier for forensic examiners confronted with the YAFFS flash filesystems used on certain other Android smartphones. As of the date of publishing of this article neither Encase nor Sleuthkit currently support EXT4. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/330/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/330/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/330/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=330&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2011/01/24/samsung-galaxy-tab-forensics/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/01/tab1.jpg" medium="image">
			<media:title type="html">tab</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/connector1.jpg" medium="image">
			<media:title type="html">connector1</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/01/flightmode.png" medium="image">
			<media:title type="html">flightmode</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/z4root.png" medium="image">
			<media:title type="html">z4root</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/01/request.png" medium="image">
			<media:title type="html">Request for superuser privileges</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2011/01/move_to_sd1.png" medium="image">
			<media:title type="html">move_to_sd</media:title>
		</media:content>
	</item>
		<item>
		<title>Extracting Android call history with MobilEdit</title>
		<link>http://forensicsferret.wordpress.com/2010/12/06/extracting-android-call-history-with-mobiledit/</link>
		<comments>http://forensicsferret.wordpress.com/2010/12/06/extracting-android-call-history-with-mobiledit/#comments</comments>
		<pubDate>Mon, 06 Dec 2010 07:52:41 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=246</guid>
		<description><![CDATA[MobilEdit Forensics edition is a Forensics investigation tool for Mobile devices allowing recovery of SMS/Call Logs/Calendar Data and more from a comprehensive range of mobile phones. Pricing for the Forensics Edition is USD600 for unlimited phones and unlimited updates. A trial version is available with the Reporting Module disabled. It appears only to be available [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=246&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MobilEdit Forensics edition is a Forensics investigation tool for Mobile devices allowing recovery of SMS/Call Logs/Calendar Data and more from a comprehensive range of mobile phones. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/me0.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/me0.png?w=522&#038;h=406" alt="" title="me0" width="522" height="406" class="alignnone size-full wp-image-247" /></a> </p>
<p>Pricing for the Forensics Edition is USD600 for unlimited phones and unlimited updates. A trial version is available with the Reporting Module disabled. It appears only to be available to Law Enforcement.  </p>
<p>With MobilEdit the approach to analysing an Android phone is very similar to the ViaForensics method described in an <a href="http://forensicsferret.wordpress.com/2010/09/30/android-browser-forensics/">earlier</a> blog post. A small .apk file is provided which installs an application called &#8220;Backup ME&#8221; on the Android phone. Running the application extracts phone data into a .mea file on the phones internal sd card which is then used by MobilEdit to create a Forensics Report. Let&#8217;s step through the process. Again we&#8217;re interacting directly with the phone as we did before. </p>
<p>On the phone itself open your browser of choice and navigate to http://download.mobiledit.com/MeReports.apk and click &#8220;Save&#8221; to begin download. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_401.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_401.png?w=360&#038;h=600" alt="" title="screenshot_40" width="360" height="600" class="alignnone size-full wp-image-266" /></a></p>
<p>Once the .apk file has downloaded click &#8216;Open&#8217; to install it. Confirm the install by tapping the Install button. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_421.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_421.png?w=360&#038;h=600" alt="" title="screenshot_42" width="360" height="600" class="alignnone size-full wp-image-264" /></a></p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_43.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_43.png?w=346&#038;h=576" alt="" title="screenshot_43" width="346" height="576" class="alignnone size-full wp-image-252" /></a></p>
<p>Locate the &#8220;Backup ME&#8221; application in the Android Applications folder. Tap on the application icon to run it. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_44.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_44.png?w=360&#038;h=600" alt="" title="screenshot_44" width="360" height="600" class="alignnone size-full wp-image-253" /></a></p>
<p>In the resulting screen click &#8220;Backup Now&#8221;. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_45.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_45.png?w=360&#038;h=600" alt="" title="screenshot_45" width="360" height="600" class="alignnone size-full wp-image-254" /></a></p>
<p>A progress indicator shows progress of the backup process. The application creates a file in the root of the sdcard on the phone with the naming convention mereport_YYMMDD.mea. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_47.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_47.png?w=360&#038;h=600" alt="" title="screenshot_47" width="360" height="600" class="alignnone size-full wp-image-255" /></a></p>
<p>Confirmation that the backup was successful and the time taken to run. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_48.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_48.png?w=360&#038;h=600" alt="" title="screenshot_48" width="360" height="600" class="alignnone size-full wp-image-256" /></a></p>
<p>You now need to connect the Android phone under investigation to your forensics workstation. The internal sdcard where the .mea file is stored is auto dismounted when you connect the phone via USB cable. Pull down the Notifications tray and mount the sd card. On a Windows machine launch the MobilEdit application. When you first launch the application the wizard should appear automatically. Alternatively you can run the Connection Wizard from the File menu. As mentioned above the Reporting Module is disabled unless you&#8217;ve purchased and activated the full product. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/me7.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/me7.png?w=288&#038;h=286" alt="" title="me7" width="288" height="286" class="alignnone size-full wp-image-273" /></a> </p>
<p>The Connection wizard then launches. Click &#8220;Connect a Phone&#8221; to continue. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/me1.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/me1.png?w=600&#038;h=413" alt="" title="me1" width="600" height="413" class="alignnone size-full wp-image-283" /></a></p>
<p>In the resulting screen click on &#8220;Cell Phone (Mobile Phone)&#8221; and click <strong>Next&gt;</strong>. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/me2.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/me2.png?w=444&#038;h=292" alt="" title="me2" width="444" height="292" class="alignnone size-full wp-image-284" /></a></p>
<p>Then choose the &#8220;File (Android Phones)&#8221; option. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/me3.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/me3.png?w=399&#038;h=377" alt="" title="me3" width="399" height="377" class="alignnone size-full wp-image-290" /></a></p>
<p>The next screen reminds you to install and run the &#8220;Backup ME&#8221; Android application that we ran earlier. Click Next&gt; on this screen. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/me4.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/me41.png?w=422&#038;h=377" alt="" title="me4" width="422" height="377" class="alignnone size-full wp-image-294" /></a></p>
<p>You will then be prompted to browse to the earlier created .mea file on the phone. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/12/me81.png"><img src="http://forensicsferret.files.wordpress.com/2010/12/me81.png?w=567&#038;h=533" alt="" title="me8" width="567" height="533" class="alignnone size-full wp-image-328" /></a></p>
<p>Once you choose the .mea file the application generates the Forensics report. I don&#8217;t have the full version of MobilEdit so I&#8217;m not able to show the resulting report. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/246/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/246/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/246/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=246&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2010/12/06/extracting-android-call-history-with-mobiledit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/me0.png" medium="image">
			<media:title type="html">me0</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_401.png" medium="image">
			<media:title type="html">screenshot_40</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_421.png" medium="image">
			<media:title type="html">screenshot_42</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_43.png" medium="image">
			<media:title type="html">screenshot_43</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_44.png" medium="image">
			<media:title type="html">screenshot_44</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_45.png" medium="image">
			<media:title type="html">screenshot_45</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_47.png" medium="image">
			<media:title type="html">screenshot_47</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_48.png" medium="image">
			<media:title type="html">screenshot_48</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/me7.png" medium="image">
			<media:title type="html">me7</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/me1.png" medium="image">
			<media:title type="html">me1</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/me2.png" medium="image">
			<media:title type="html">me2</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/me3.png" medium="image">
			<media:title type="html">me3</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/me41.png" medium="image">
			<media:title type="html">me4</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/12/me81.png" medium="image">
			<media:title type="html">me8</media:title>
		</media:content>
	</item>
		<item>
		<title>Packet Sniffing on the Samsung Galaxy Android phone.</title>
		<link>http://forensicsferret.wordpress.com/2010/10/08/packet-sniffing-on-the-samsung-galaxy-android-phone/</link>
		<comments>http://forensicsferret.wordpress.com/2010/10/08/packet-sniffing-on-the-samsung-galaxy-android-phone/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 13:30:57 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=88</guid>
		<description><![CDATA[Following on from my earlier post where I mentioned that all browser traffic using Opera Mini is routed through Opera&#8217;s own proxy I set out to confirm this by sniffing my browser traffic. The Android Marketplace provides an Android version of Wireshark called &#8220;Shark for Root&#8221;. The &#8220;Root&#8221; simply means you need a rooted phone [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=88&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Following on from my earlier post where I mentioned that all browser traffic using Opera Mini is routed through Opera&#8217;s own proxy I set out to confirm this by sniffing my browser traffic.</p>
<p>The Android Marketplace provides an Android version of Wireshark called &#8220;Shark for Root&#8221;. The &#8220;Root&#8221; simply means you need a rooted phone for it to capture packets. There&#8217;s also a Shark Reader which gives rudimentary ability to view .pcap files captured from Shark. Shark Reader can be launched independently of Shark or from within the Shark App itself. Below is a screenshot from the MarketPlace showing both apps.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot1.png"><img class="alignnone size-full wp-image-101" title="Marketplace" src="http://forensicsferret.files.wordpress.com/2010/11/screenshot1.png?w=240&#038;h=283" alt="" width="240" height="283" /></a></p>
<p>Once the apps are installed they appear on your phone as follows:</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot2.png"><img class="alignnone size-full wp-image-103" title="Applications" src="http://forensicsferret.files.wordpress.com/2010/11/screenshot2.png?w=240&#038;h=400" alt="" width="240" height="400" /></a></p>
<p>Now launch Shark for Root. The default parameters are for verbose capture and snap length 0 which gives the entire packet. Click Start and start capturing packets. The app is ad supported so you&#8217;ll need to put up with the adverts on the top of the screen. You can also see the option I mentioned earlier to open Shark Reader from within Shark for Root.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot3.png"><img class="alignnone size-full wp-image-106" title="Shark1" src="http://forensicsferret.files.wordpress.com/2010/11/screenshot3.png?w=240&#038;h=291" alt="" width="240" height="291" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=88&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2010/10/08/packet-sniffing-on-the-samsung-galaxy-android-phone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot1.png" medium="image">
			<media:title type="html">Marketplace</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot2.png" medium="image">
			<media:title type="html">Applications</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot3.png" medium="image">
			<media:title type="html">Shark1</media:title>
		</media:content>
	</item>
		<item>
		<title>Android Browser Forensics</title>
		<link>http://forensicsferret.wordpress.com/2010/09/30/android-browser-forensics/</link>
		<comments>http://forensicsferret.wordpress.com/2010/09/30/android-browser-forensics/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 15:29:26 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=76</guid>
		<description><![CDATA[Introduction Reconstructing browser history is a well worn forensics task whether it be Internet Explorer, Firefox or Safari history and whether on Windows, Linux or Mac OSX. Occasionally we are faced with updating our skill sets and tools for example when Firefox switched from Mork to sqlite format for its browser history storage. With the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=76&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Introduction</strong></p>
<p>Reconstructing browser history is a well worn forensics task whether it be Internet Explorer, Firefox or Safari history and whether on Windows, Linux or Mac OSX. Occasionally we are faced with updating our skill sets and tools for example when Firefox switched from Mork to sqlite format for its browser history storage. With the steady flow of new devices especially in the mobile space the learning curve has become steep again. The following looks at some of the basics of browser history on Android mobile phones.  </p>
<p><strong>Hardware </strong></p>
<p>The following analysis was done on the Samsung Android Galaxy S i9000 phone. The Galaxy is the international version of the U.S. Samsung Vibrant but they&#8217;re essentially the same phone. My Galaxy came with 16GB of internal memory. The card is formatted as a vfat file system and can be removed and imaged in the traditional way. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/samsung-sdcard.jpg"><img src="http://forensicsferret.files.wordpress.com/2010/09/samsung-sdcard.jpg?w=300&#038;h=225" alt="" title="samsung-sdcard" width="300" height="225" class="alignnone size-medium wp-image-215" /></a></p>
<p><strong>Software </strong></p>
<p>The Samsung Galaxy runs a Linux 2.6 kernel and comes with a 1Ghz ARM processor. Currently I&#8217;m running Android 2.1 Eclair and the phone was rooted using the instructions at <a href="http://www.xda-developers.com/android/one-click-rootunroot-for-most-galaxy-devices/">XDA</a> and as detailed in my <a href="https://forensicsferret.wordpress.com/2010/08/17/rooting-the-samsung-galaxy-android-phone/">previous</a> blog post. I have also pre-installed the Android SDK on my Mac OSX machine. You&#8217;ll find links to the different SDKs for your version of Android <a href="http://developer.android.com/sdk/index.html">here</a> including install instructions. </p>
<p><strong>Internet browsing on Android </strong></p>
<p>There are a number of different browser applications available for Android. All store their browser history in sqlite .db format. Some of the more common browsers include:</p>
<p>1. Firefox Mobile<br />
2. Android Browser (default on all Android phones)<br />
3. Dolphin<br />
4. Opera Mini<br />
5. Opera Mobile<br />
6. Skyfire</p>
<p>During a forensics examination you may come across and need to account for browsing activity from one or a combination of the above. It&#8217;s advisable to determine in advance of an investigation what browsers you&#8217;re dealing with to ensure a thorough investigation. </p>
<p><strong>Android Security Model </strong></p>
<p>Under the Android security model an application&#8217;s (i.e. browser) process runs in a security sandbox. This ensures that no application has permission to perform any operations that would negatively impact other applications or the operating system. Each application gets its own unique User ID and Group ID and files for that application are sandboxed. This includes the applications .db files. Android also provides the developer with &#8220;Content Providers&#8221; which allow developers to share data across applications but this is beyond the scope of this article. This sandbox security model creates challenges for the forensics investigator. Browser history files are only available to the browser application itself or with root access to the phone. The below screenshot shows the User and Group IDs (app_108) for the Skyfire browser application. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/screenshot_bte.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/screenshot_bte.png?w=600&#038;h=360" alt="" title="screenshot_bte" width="600" height="360" class="alignnone size-full wp-image-181" /></a></p>
<p>The paths to the .db files for each browser above are as follows:</p>
<p>1.  /data/data/org.mozilla.fennec<br />
2.  /data/data/com.android.browser<br />
3. /data/data/??????<br />
4. /data/data/com.opera.mini.android<br />
5. /data/data/opera.browser<br />
6. /data/data/com.skyfire.browser</p>
<p><strong>Approaches </strong></p>
<p>We examine a number of approaches to acquiring and reconstructing the browser history from an Android phone and where relevant the downsides of each approach. </p>
<p>First we look at pulling the browser history files directly off the device using the Android SDK and adb (the Android Debug Bridge). Adb is available once you install the Android SDK. For my Mac OSX install it&#8217;s found under /Applications/android-sdk-mac_x86/tools</p>
<p>First we open a Terminal Window and change directory to /Applications/android-sdk-mac_x86/tools. After putting the phone in USB Debug mode (Settings&gt;Applications&gt;Development&gt;USB Debugging) and connecting it to the Mac via USB cable we issue the following command to confirm we have connectivity to the phone. </p>
<p><strong>$ ./adb devices<br />
* daemon not running. starting it now on port 5037 *<br />
* daemon started successfully *<br />
List of devices attached<br />
90000a7896ac	device</p>
<p>$ ./adb shell</p>
<p>$ id<br />
uid=2000(shell) gid=2000(shell) groups=1003(graphics),1004(input),1007(log),1011(adb),1015(sdcard_rw),<br />
3001(net_bt_admin),3002(net_bt),3003(inet)</strong></p>
<p>We don&#8217;t have superuser permissions and shouldn&#8217;t be able to pull browser history files from the device. Let&#8217;s test. </p>
<p><strong>$ ./adb pull /data/data/com.skyfire.browser/databases/webviewCache.db<br />
failed to copy &#8216;/data/data/com.skyfire.browser/databases/webviewCache.db&#8217; to &#8216;./webviewCache.db&#8217;: Permission denied<br />
$</strong></p>
<p>So confirmed by default we don&#8217;t have permissions to pull browser history for Skyfire from the device. Let&#8217;s try su to root and give ourselves read permissions.<br />
<strong><br />
$ su<br />
# </strong></p>
<p>Make sure the connected phone is not on the lock screen and when prompted confirm to allow super user permissions. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/screen-shot-2010-11-20-at-pm-05-59-49.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/screen-shot-2010-11-20-at-pm-05-59-49.png?w=452&#038;h=483" alt="" title="Screen shot 2010-11-20 at PM 05.59.49" width="452" height="483" class="alignnone size-full wp-image-178" /></a></p>
<p>Change directory into the /databases folder and chmod webviewCache.db so that &#8216;everyone&#8217; has read permissions. </p>
<p><strong># cd /data/data/com.skyfire.browser/databases<br />
# ls -l<br />
-rw-rw&#8212;- app_108  app_108     25600 2010-11-17 17:51 webview.db<br />
-rw-rw&#8212;- app_108  app_108     27648 2010-11-17 17:52 webviewCache.db<br />
-rw-r&#8211;r&#8211;  app_108  app_108       8192 2010-10-28 10:33 skyfire.db<br />
#</strong></p>
<p><strong># chmod 664 webviewCache.db<br />
# ls -l<br />
-rw-rw&#8212;-   app_108  app_108     25600 2010-11-17 17:51 webview.db<br />
-rwxrwxrwx app_108  app_108     27648 2010-11-17 17:52 webviewCache.db<br />
-rw-r&#8211;r&#8211;    app_108  app_108       8192 2010-10-28 10:33 skyfire.db<br />
# exit<br />
$ exit</strong></p>
<p>Let&#8217;s then go back to Terminal and using adb we try again to pull the web browser history file off the device and onto the local Mac OSX machine. </p>
<p><strong>$ ./adb pull /data/data/com.skyfire.browser/databases/webviewCache.db /Applications/android-sdk-mac_x86/tools<br />
666 KB/s (27648 bytes in 0.040s)<br />
$<br />
</strong></p>
<p>This time it works. Once we have the web cache file we can dump the history using the sqlite client. </p>
<p><strong>$ sqlite3 webviewCache.db &#8220;SELECT * FROM cache;&#8221;<br />
1|http://my.skyfire.com/|00a44035|||1290073890765|Thu, 18 Nov 2010 09:51:31 GMT|text/html|utf-8|200||10950|<br />
2|http://my.skyfire.com/css/style-min.css|73742daa|Fri, 17 Sep 2010 22:58:52 GMT||1292406691342|Fri, 17 Dec 2010 09:51:32 GMT|text/css||200||3901|<br />
3|http://my.skyfire.com/js/jquery/jquery-1.4.2.min.js|85dbb447|Fri, 17 Sep 2010 22:58:42 GMT||1292579491526|Fri, 17 Dec 2010 09:51:32 GMT|application/x-javascript||200||72174|<br />
4|http://www.google-analytics.com/ga.js|7daacc1c|Mon, 08 Nov 2010 08:48:36 GMT||1290073892505|Wed, 17 Nov 2010 20:06:48 GMT|text/javascript||200||24505|<br />
5|http://my.skyfire.com/js/jquery/jquery.cookie.min.js|5575125f|Fri, 17 Sep 2010 22:58:42 GMT||1292579492915|Fri, 17 Dec 2010 09:51:34 GMT|application/x-javascript||200||693|<br />
$</strong></p>
<p>From left to right the fields are:</p>
<p>_id<br />
url<br />
filepath<br />
lastmodify<br />
etag<br />
expires<br />
expirestring<br />
mimetype<br />
encoding<br />
httpstatus<br />
location<br />
contentlength<br />
contentdisposition</p>
<p>ok so this works but it&#8217;s not ideal. First off you would need a rooted phone to pull the web cache file. You&#8217;re also giving additional permissions to the browser history file. Neither would be considered sound forensic approaches. </p>
<p><strong>Traditional Forensics approach </strong></p>
<p>The traditional approach to a forensics investigation of a device is to take a bit for bit copy of the entire physical device, mount the copy as read only and examine it. With a mobile device such as an Android phone one challenge is the inability to remove a drive, attach a write-blocker and image the drive in this traditional way. A certain amount of interaction with the phone is necessary. </p>
<p>The Android phone uses NAND flash memory. However Linux only understands character and block devices. With Linux on flash, because flash memory devices are not seen as character or block devices a Flash Transition layer called Memory Technology Device (MTD) provides the interface between the Linux OS and the physical flash device. </p>
<p>Interestingly the Samsung Galaxy, unlike The Nexus G1 and HTC phones, mounts the /data folder on /dev/loop0 as an &#8216;ext2&#8242; filesystem.  If you do a cat /proc/mtd you get nothing. This makes it slightly easier for an examiner as the /data folder is not stored in the mtd memory on the phone.  </p>
<p>If we run &#8216;mount&#8217; on the phone we see /data mounted as /dev/loop0.  </p>
<p>UPDATE: While doing further analysis it appears that the One Click Lag Fix (OCLF) for Android makes use of loopback mounts and I had run OCLF on my Galaxy phone to help with the known lag issues with the Galaxy and it subsequently reconfigured the OS to mount /data as loop0. /data is mounted as /dev/block/mmcblk0p2 on my Samsung Galaxy Tab and I expect that prior to applying OCLF that my Galaxy phone also used this mmc block device. </p>
<p><strong># mount<br />
rootfs / rootfs rw 0 0<br />
tmpfs /dev tmpfs rw,mode=755 0 0<br />
devpts /dev/pts devpts rw,mode=600 0 0<br />
proc /proc proc rw 0 0<br />
sysfs /sys sysfs rw 0 0<br />
/dev/block/stl6 /mnt/.lfs j4fs rw 0 0<br />
tmpfs /sqlite_stmt_journals tmpfs rw,size=4096k 0 0<br />
none /dev/cpuctl cgroup rw,cpu 0 0<br />
/dev/block/stl9 /system rfs rw,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /data rfs rw,nosuid,nodev,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/stl10 /dbdata rfs rw,nosuid,nodev,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/stl11 /cache rfs rw,nosuid,nodev,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/stl3 /efs rfs rw,nosuid,nodev,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /dbdata/rfsdata rfs rw,nosuid,nodev,noatime,nodiratime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/loop0 /dbdata/ext2data ext2 rw,noatime,nodiratime,errors=continue 0 0<br />
<em>/dev/loop0 /data ext2 rw,noatime,nodiratime,errors=continue 0 0</em><br />
/dev/block/mmcblk0p2 /data/gps rfs rw,nosuid,nodev,noatime,nodiratime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /data/misc rfs rw,nosuid,nodev,noatime,nodiratime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /data/wifi rfs rw,nosuid,nodev,noatime,nodiratime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /data/local rfs rw,nosuid,nodev,noatime,nodiratime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block/mmcblk0p2 /data/property rfs rw,nosuid,nodev,noatime,nodiratime,vfat,llw,check=no,gid/uid/rwx,iocharset=utf8 0 0<br />
/dev/block//vold/179:1 /sdcard vfat rw,dirsync,nosuid,nodev,noexec,uid=1000,gid=1015,fmask=0102,dmask=0002,allow_utime=0020,codepage=cp437,iocharset=iso8859-1,shortname=mixed,utf8,errors=remount-ro 0 0<br />
#</strong></p>
<p>We can then &#8216;dd&#8217; the /data folder across to our /sdcard. </p>
<p><strong># dd if=/dev/loop0 of=/sdcard/forensics/imagefile.dd<br />
1776592+0 records in<br />
1776592+0 records out<br />
909615104 bytes transferred in 458.374 secs (1984438 bytes/sec)<br />
#</strong></p>
<p>The resulting image file is approx 909MB. We then exit back to our host Mac OSX machine to the /tools folder and pull the .dd file to our local analysis machine. </p>
<p><strong>$ ./adb pull /sdcard/forensics/imagefile.dd /Applications/android-sdk-mac_x86/tools<br />
4395 KB/s (909615104 bytes in 202.080s)<br />
$</strong></p>
<p>We mount the image as we would any typical forensics image file and do our analysis. </p>
<p><strong>$ sudo mount -o loop imagefile.dd /media/galaxy<br />
$ cd /media/galaxy/data/data/com.skyfire.browser/databases/<br />
$<br />
$ ls -l<br />
-rw-r&#8211;r&#8211; 1 10108 10108 8192 2010-10-28 10:33 skyfire.db<br />
-rw-rw-r&#8211; 1 10108 10108 27648 2010-11-17 17:52 webviewCache.db<br />
-rw-rw&#8212;- 1 10108 10108 25600 2010-11-17 17:51 webview.db<br />
$</strong></p>
<p><strong>$<br />
$ file webviewCache.db<br />
webviewCache.db: SQLite 3.x database, user version 3<br />
$</strong></p>
<p>The same approach as we used earlier to extract the browser history will work for us. </p>
<p><strong># sqlite3 webviewCache.db &#8220;SELECT * from cache;&#8221;<br />
1|http://my.skyfire.com/|00a44035|||1290073890765|Thu, 18 Nov 2010 09:51:31 GMT|text/html|utf-8|200||10950|<br />
2|http://my.skyfire.com/css/style-min.css|73742daa|Fri, 17 Sep 2010 22:58:52 GMT||1292406691342|Fri, 17 Dec 2010 09:51:32 GMT|text/css||200||3901|<br />
3|http://my.skyfire.com/js/jquery/jquery-1.4.2.min.js|85dbb447|Fri, 17 Sep 2010 22:58:42 GMT||1292579491526|Fri, 17 Dec 2010 09:51:32 GMT|application/x-javascript||200||72174|<br />
4|http://www.google-analytics.com/ga.js|7daacc1c|Mon, 08 Nov 2010 08:48:36 GMT||1290073892505|Wed, 17 Nov 2010 20:06:48 GMT|text/javascript||200||24505|<br />
5|http://my.skyfire.com/js/jquery/jquery.cookie.min.js|5575125f|Fri, 17 Sep 2010 22:58:42 GMT||1292579492915|Fri, 17 Dec 2010 09:51:34 GMT|application/x-javascript||200||693|<br />
[snip]<br />
#<br />
</strong></p>
<p>The advantage of taking an image in this manner is that we have access to the full /data folder and can extend our investigation and analyze data storage for multiple applications if necessary. </p>
<p><strong>Open Source Android browser framework </strong></p>
<p>It&#8217;s worth mention an open source Android forensics framework by a company called ViaForensics. The application is installed and runs on the Android phone itself and pulls &#8211; among other things &#8211; browsing history from the phone. The application appears to only be available to law enforcement although there was some mention of it being made available to the public. For now it doesn&#8217;t appear to be possible to download the .apk from its Google Code <a href="https://code.google.com/p/android-forensics/">site</a>. In addition it&#8217;s my understanding that it only works for the default Android Browser.   </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/usb_debug.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/usb_debug.png?w=360&#038;h=600" alt="" title="usb_debug" width="360" height="600" class="alignnone size-full wp-image-196" /></a></p>
<p><strong>$ ./adb devices<br />
List of devices attached<br />
90000a7896ac    device<br />
$</p>
<p>$ ./adb install AndroidForensics.apk<br />
21 KB/s (20138 bytes in 0.907s)<br />
pkg: /data/local/tmp/AndroidForensics.apk<br />
Success</p>
<p>$<br />
</strong><br />
Under Applications you&#8217;ll find an icon for the newly installed Android Forensics app called ViaForensics.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/viaforensics.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/viaforensics.png?w=360&#038;h=600" alt="" title="viaforensics" width="360" height="600" class="alignnone size-full wp-image-198" /></a></p>
<p>Click on the application and you&#8217;re presented with the following screen.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/providers.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/providers.png?w=360&#038;h=600" alt="" title="providers" width="360" height="600" class="alignnone size-full wp-image-200" /></a></p>
<p>Each option is checked by default. Click Capture. A folder is created on the internal sdcard called &#8216;forensics&#8217; with 6 .csv files.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/csv.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/csv.png?w=360&#038;h=600" alt="" title="csv" width="360" height="600" class="alignnone size-full wp-image-202" /></a></p>
<p>You can then use the Android SDK and adb as we did earlier to pull the resulting csv files off the sdcard onto your host machine. </p>
<p><strong>$ ./adb pull /sdcard/forensics /Applications/android-sdk-mac_x86/<br />
pull: building file list&#8230;<br />
pull: /sdcard/forensics/20101112.2331.SMS.csv -&gt; /Applications/android-sdk-mac_x86/20101112.2331.SMS.csv<br />
pull: /sdcard/forensics/20101112.2331.People.csv -&gt; /Applications/android-sdk-mac_x86/20101112.2331.People.csv<br />
pull: /sdcard/forensics/20101112.2331.Organizations.csv -&gt; /Applications/android-sdk-mac_x86/20101112.2331.Organizations.csv<br />
pull: /sdcard/forensics/20101112.2331.ContactMethods.csv -&gt; /Applications/android-sdk-mac_x86/20101112.2331.ContactMethods.csv<br />
pull: /sdcard/forensics/20101112.2331.CallLogCalls.csv -&gt; /Applications/android-sdk-mac_x86/20101112.2331.CallLogCalls.csv<br />
pull: /sdcard/forensics/20101112.2331.Browser.csv -&gt; /Applications/android-sdk-mac_x86/20101112.2331.Browser.csv<br />
6 files pulled. 0 files skipped.<br />
15 KB/s (92966 bytes in 5.857s)<br />
$</strong></p>
<p>Then it&#8217;s a simple matter to load up the CSV files in something like OpenOffice for analysis. </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/09/screen-shot-2010-11-21-at-pm-06-22-10.png"><img src="http://forensicsferret.files.wordpress.com/2010/09/screen-shot-2010-11-21-at-pm-06-22-10.png?w=600&#038;h=197" alt="" title="Screen shot 2010-11-21 at PM 06.22.10" width="600" height="197" class="alignnone size-full wp-image-193" /></a></p>
<p><strong>Conclusion</strong></p>
<p>Although there is some good research in the field, Android forensics in general is quite new. Research in this area is moving fast however and there&#8217;s rumours of an Android forensics book in the making so keep an eye on Amazon. In my next blog post I may look at further analysis of the android dd image above including Skype and Meebo chat logs.  </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/76/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=76&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2010/09/30/android-browser-forensics/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/samsung-sdcard.jpg?w=300" medium="image">
			<media:title type="html">samsung-sdcard</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/screenshot_bte.png" medium="image">
			<media:title type="html">screenshot_bte</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/screen-shot-2010-11-20-at-pm-05-59-49.png" medium="image">
			<media:title type="html">Screen shot 2010-11-20 at PM 05.59.49</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/usb_debug.png" medium="image">
			<media:title type="html">usb_debug</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/viaforensics.png" medium="image">
			<media:title type="html">viaforensics</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/providers.png" medium="image">
			<media:title type="html">providers</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/csv.png" medium="image">
			<media:title type="html">csv</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/09/screen-shot-2010-11-21-at-pm-06-22-10.png" medium="image">
			<media:title type="html">Screen shot 2010-11-21 at PM 06.22.10</media:title>
		</media:content>
	</item>
		<item>
		<title>Rooting the Samsung Galaxy Android phone</title>
		<link>http://forensicsferret.wordpress.com/2010/08/17/rooting-the-samsung-galaxy-android-phone/</link>
		<comments>http://forensicsferret.wordpress.com/2010/08/17/rooting-the-samsung-galaxy-android-phone/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 04:42:37 +0000</pubDate>
		<dc:creator>forensicsferret</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicsferret.wordpress.com/?p=153</guid>
		<description><![CDATA[An assembly line issue in Korea means that some phones were shipped with the three button Recovery Mode (Vol Up + Home + Power) disabled. Unfortunately I ended up purchasing one of these neutered phones. To root the phone I had to install the Android SDK and boot into recovery mode. There are more detailed [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=153&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>An assembly line issue in Korea means that some phones were shipped with the three button Recovery Mode (Vol Up + Home + Power) disabled. Unfortunately I ended up purchasing one of these neutered phones. To root the phone I had to install the Android SDK and boot into recovery mode. There are more detailed instructions online but very quickly the procedure to root the phone is as follows:</p>
<p>1. Download and install the Android SDK. I installed the x86 version for Mac OSX.</p>
<p>2. On the phone go to Settings&gt;Applications&gt;Development and turn on USB Debugging.</p>
<p>3. Copy the Update.zip (here) to the root of your internal SD card. This is /sdcard on your phone.</p>
<p>4. Connect the phone to the Mac via USB cable.</p>
<p>5. Go to a Terminal prompt</p>
<p>5. cd to /Applications/android-sdk-mac_x86/tools</p>
<p>6. Run ./adb reboot recovery</p>
<p>7. The phone will reboot into Recovery Mode.</p>
<p>8. Use the Volume rocker to highlight the option to apply Update.zip and then hit the Home key. The phone will reboot.</p>
<p>9. Once the phone reboots check for the existence of the Ninja icon with the sniper rifle in Applications. See screenshot below.</p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_su2.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_su2.png?w=480&#038;h=800" alt="" title="screenshot_su2" width="480" height="800" class="alignnone size-full wp-image-154" /></a></p>
<p>A sample of applications requiring Superuser access are:</p>
<p>1. Root Explorer &#8211; Allows you to browse protected areas of the file system.<br />
2. One Click Lag Fix &#8211; Fixes Lag issues on the Samung Galaxy<br />
3. </p>
<p>Once your phone is rooted and you try to run a program that requires root privileges a dialog will pop up asking you to confirm su access for the application and if we should continue to provide root access in future whenever the application is launched. The below screenshot shows Root Explorer requesting superuser privileges.  </p>
<p><a href="http://forensicsferret.files.wordpress.com/2010/11/screenshot_u1.png"><img src="http://forensicsferret.files.wordpress.com/2010/11/screenshot_u1.png?w=480&#038;h=800" alt="" title="screenshot_u1" width="480" height="800" class="alignnone size-full wp-image-155" /></a></p>
<p>Note: You won&#8217;t see any files in the data folder if you try to browse using Astro or the built in File Manager as you require root privileges to browse this folder. With a rooted phone and a Marketplace app called Root Manager you will see these hidden files. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/forensicsferret.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/forensicsferret.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/forensicsferret.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/forensicsferret.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/forensicsferret.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/forensicsferret.wordpress.com/153/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/forensicsferret.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/forensicsferret.wordpress.com/153/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=forensicsferret.wordpress.com&amp;blog=14151680&amp;post=153&amp;subd=forensicsferret&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://forensicsferret.wordpress.com/2010/08/17/rooting-the-samsung-galaxy-android-phone/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/172f6dbbb56c260a83cb3cc12f7b9c47?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">forensicsferret</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_su2.png" medium="image">
			<media:title type="html">screenshot_su2</media:title>
		</media:content>

		<media:content url="http://forensicsferret.files.wordpress.com/2010/11/screenshot_u1.png" medium="image">
			<media:title type="html">screenshot_u1</media:title>
		</media:content>
	</item>
	</channel>
</rss>
