Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • Book Overview & Buying Mastering Mobile Forensics
  • Table Of Contents Toc
  • Feedback & Rating feedback
Mastering Mobile Forensics

Mastering Mobile Forensics

By : Tahiri
close
close
Mastering Mobile Forensics

Mastering Mobile Forensics

By: Tahiri

Overview of this book

Mobile forensics presents a real challenge to the forensic community due to the fast and unstoppable changes in technology. This book aims to provide the forensic community an in-depth insight into mobile forensic techniques when it comes to deal with recent smartphones operating systems Starting with a brief overview of forensic strategies and investigation procedures, you will understand the concepts of file carving, GPS analysis, and string analyzing. You will also see the difference between encryption, encoding, and hashing methods and get to grips with the fundamentals of reverse code engineering. Next, the book will walk you through the iOS, Android and Windows Phone architectures and filesystem, followed by showing you various forensic approaches and data gathering techniques. You will also explore advanced forensic techniques and find out how to deal with third-applications using case studies. The book will help you master data acquisition on Windows Phone 8. By the end of this book, you will be acquainted with best practices and the different models used in mobile forensics.
Table of Contents (9 chapters)
close
close
7
A. Preparing a Mobile Forensic Workstation
8
Index

Identifying stored data

All iDevices use a type of non-volatile memory chip using NOT AND gates called NAND memory, this memory in iDevices is divided into two partitions: system and data. As suggested by their respective names, the system partition holds the firmware including the operating system and built-in applications and in general it's a read-only partition. Depending on models, this partition can range anywhere from 1 to 2.5 GB. In general this partition does not hold any forensically interesting evidence; however, it's important to note that the /private/etc/passwd path holds the preconfigured user's "mobile" and "root" passwords, as shown in following screenshot:

Identifying stored data

System partition of iOS 9.0

If you open the file with a text editor you should get the following:

Identifying stored data

Default password of users root and mobile

Note

The plaintext password is alpine and is the same in all iDevices. This password cannot be modified unless the device is jailbroken.

Data partition...

Visually different images
CONTINUE READING
83
Tech Concepts
36
Programming languages
73
Tech Tools
Icon Unlimited access to the largest independent learning library in tech of over 8,000 expert-authored tech books and videos.
Icon Innovative learning tools, including AI book assistants, code context explainers, and text-to-speech.
Icon 50+ new titles added per month and exclusive early access to books as they are being written.
Mastering Mobile Forensics
notes
bookmark Notes and Bookmarks search Search in title playlist Add to playlist font-size Font size

Change the font size

margin-width Margin width

Change margin width

day-mode Day/Sepia/Night Modes

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Confirmation

Modal Close icon
claim successful

Buy this book with your credits?

Modal Close icon
Are you sure you want to buy this book with one of your credits?
Close
YES, BUY

Submit Your Feedback

Modal Close icon
Modal Close icon
Modal Close icon