ceic 2011 - ios application forensics

204
iOS Applica*on Forensics Sarah Edwards [email protected] @iamevltwin CEIC May 2011 © 2011 Harris Corporation

Upload: iamevltwin

Post on 05-Jul-2015

1.574 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: CEIC 2011 - iOS Application Forensics

iOS  Applica*on  Forensics  Sarah  Edwards    

[email protected]  @iamevltwin  

CEIC  -­‐  May  2011  

© 2011 Harris Corporation

Page 2: CEIC 2011 - iOS Application Forensics

About  Me  �  Digital  Forensic  Analyst  with  Harris  Corpora*on  

�  Computer  Intrusions  

�  Free  *me  is  used  for  iOS/Mac  forensic  research  

© 2011 Harris Corporation

Page 3: CEIC 2011 - iOS Application Forensics

Objec*ves  �  If  you  sit  through  this,  you’ll  get:  

�  Contacts  �  Pictures  �  Documents  �  Usernames  �  Passwords    �  Loca*onal  Data  �  …much  more.  

�  It  is  so  easy,  almost  too  easy.  

�  iOS  Applica*on  Security  Awareness  �  What  about  Android/Blackberry/Windows?  

© 2011 Harris Corporation

Page 4: CEIC 2011 - iOS Application Forensics

iOS  Apps  �  Prevalence  

�  iPhone  �  iPad  �  iPod  Touch  

�  How  many  Apps?  �  10  Billion  downloads  �  ~350,000  Apps    

�  [hZp://www.buzzbiznews.com/035133/apple’s-­‐app-­‐store-­‐hits-­‐10-­‐billion-­‐downloads/]  

© 2011 Harris Corporation

Page 5: CEIC 2011 - iOS Application Forensics

Caveats  �  Third-­‐party  applica*ons  only.  �  Redac*on…lots  of  personal  informa*on  in  Apps.  

�  Lots  of  pictures  �  So^ware  Verifica*on  and  Valida*on  �  Evidence  Admissibility  

�  Detailed  acquisi*on  techniques  �  Applica*ons  Versions    

© 2011 Harris Corporation

Page 6: CEIC 2011 - iOS Application Forensics

ACCESSING  THE  DATA  

© 2011 Harris Corporation

Page 7: CEIC 2011 - iOS Application Forensics

State  of  Forensic  So^ware  �  There  are  many  tools.  

�  Some  are  beZer  than  others.  

�  Some  get  only  logical  data.  

�  Some  require  the  passcode.  

�  Most  are  expensive.  

�  Most  do  not  auto-­‐magically  parse  3rd  party  applica*on  data.  

�  Proprietary  data  formats  

© 2011 Harris Corporation

Page 8: CEIC 2011 - iOS Application Forensics

Backups  vs.  Physical  vs.  Logical  

© 2011 Harris Corporation

Backups  

• Easy  Access  • Historical  Context  

• Encryp*on  • Must  have  HDD  • Limited  Data  

Physical  

• Difficult  to  capture  

• Up-­‐to-­‐date  • Access  to  physical  device  

• Poten*al  to  get  EVERYTHING  

• Encryp*on  

Logical  

• Easy  Access  • Up-­‐to-­‐date  • Access  to  physical  device  

• Limited  to  logical  data  

Page 9: CEIC 2011 - iOS Application Forensics

Backup  Files  

© 2011 Harris Corporation

Page 10: CEIC 2011 - iOS Application Forensics

Backup  File  Loca*ons  �  Windows  

�  <APPDATA>\Apple  Computer\MobileSync\Backup  �  \Users\<user>\AppData\Roaming\Apple  Computer

\MobileSync\Backup  

�  Mac  �  ~/Library/Applica*on  Support/MobileSync/Backup/  

© 2011 Harris Corporation

Page 11: CEIC 2011 - iOS Application Forensics

Backup  Files  (iOS  4.x)  �  Info.plist  

�  Manifest.mbdb  

�  Manifest.mbdx  

�  Manifest.plist  

�  Status.plist  

© 2011 Harris Corporation

Page 12: CEIC 2011 - iOS Application Forensics

Backup  Files  (iOS  4.x)  –  Info.plist  �  Build  Version  �  Device  Name  �  Last  Backup  Date  �  Serial  Number  �  Device  Iden*fier  �  Device  Type  �  iOS  Version  �  ICCID  �  IMEI  �  Phone  Number  �  List  of  applica*ons:  

�  In  Library  �  Synced  

© 2011 Harris Corporation

Page 13: CEIC 2011 - iOS Application Forensics

Backup  Files  (iOS  4.x)  –  Manifest.plist  

�  Contains  applica*on  versions.  

© 2011 Harris Corporation

Page 14: CEIC 2011 - iOS Application Forensics

Backup  Files  (iOS  4.x)  �  Manifest.mbdb  &  Manifest.mbdx  

�  Database  files  of  the  backup  contents.  

© 2011 Harris Corporation http://code.google.com/p/iphonebackupbrowser/wiki/MbdbMbdxFormat

Page 15: CEIC 2011 - iOS Application Forensics

Backup  Files  (iOS  3.x)  �  *.mddata  

�  *.mdinfo  

�  Info.plist  

�  Manifest.plist  

�  Status.plist  

© 2011 Harris Corporation

Page 16: CEIC 2011 - iOS Application Forensics

Backup  Files  (iOS  3.x)  �  *.mddata  

�  *.mdinfo  

© 2011 Harris Corporation

Page 17: CEIC 2011 - iOS Application Forensics

So^ware  for  Backups  •  iPhone  Backup  Extractor  

–  Mac  only  –  Available  at  supercrazyawesome.com  –  Free!  (Dona*ons  are  welcome.)  

© 2011 Harris Corporation

Page 18: CEIC 2011 - iOS Application Forensics

So^ware  for  Backups  �  iPhone  Backup  Extractor  

�  Windows,  Linux  &  Mac  �  Available  at:    

�  iphonebackupextractor.com  

�  Free  &  Paid  Versions  

© 2011 Harris Corporation

Page 19: CEIC 2011 - iOS Application Forensics

So^ware  for  Backups  �  iBackupBot  

�  Windows  Only  �  Available  at:  

�  icopybot.com  

�  Free  Trial  ($35)  

© 2011 Harris Corporation

Page 20: CEIC 2011 - iOS Application Forensics

So^ware  to  Access  Physical  Device  �  Forensic  So^ware  �  Jailbreak  

�  SSH/DD/SCP  

�  "Zdziarski"  Method  �  NIST  Approved  �  LE/Military  Only  

�  Commercial  Non-­‐Forensic  So^ware  (For  Research  Purposes)  �  PhoneDisk  �  PhoneView  

© 2011 Harris Corporation

Page 21: CEIC 2011 - iOS Application Forensics

So^ware  to  Access  Physical  Device  �  PhoneDisk  

�  Mac  &  Windows  �  Available  at:  macroplant.com/phonedisk/  �  $20    

© 2011 Harris Corporation

Page 22: CEIC 2011 - iOS Application Forensics

So^ware  to  Access  Physical  Device  �  PhoneView  

�  Mac  �  Available  at:  ecamm.com/mac/phoneview/  �  $20  

© 2011 Harris Corporation

Page 23: CEIC 2011 - iOS Application Forensics

What  am  I  looking  at?  

© 2011 Harris Corporation

Page 24: CEIC 2011 - iOS Application Forensics

/User/Applica*ons  Directory  

© 2011 Harris Corporation

Page 25: CEIC 2011 - iOS Application Forensics

Applica*on  Directory  

© 2011 Harris Corporation

Page 26: CEIC 2011 - iOS Application Forensics

Applica*on  Directories  �  /private/var/mobile/Applica6on    

�  (Actual  Path,  linked  to  /User/Applica6on)  

�  /User/Applica6ons/########-­‐####-­‐####-­‐####-­‐############  �  Universally  Unique  ID  

�  <Applica6on_Home>/AppName.app  �  Applica*on  Bundle  (Not  Backed  Up)  

�  <Applica6on_Home>/Documents/  �  Contains  user  documents  and  data  files.  (Backed  Up)  

�  <Applica6on_Home>/Library/  �   Contains  applica*on  specific  files.  (Backed  Up)  

�  <Applica6on_Home>/Library/Preferences  �  Applica*on  Preference  Files  (Backed  Up)  

�  <Applica6on_Home>/Library/Caches    �  Applica*on  specific  support  files.  Persistent  between  applica*on  launches.  (Not  Backed  Up)  

�  <Applica6on_Home>/tmp/  �  Temporary  files,  not  persistent  between  applica*on  launches.  (Not  Backed  Up)  

© 2011 Harris Corporation

Page 27: CEIC 2011 - iOS Application Forensics

iTunesMetadata.plist  �  Contains  informa*on  such  as:  

�  Product  Informa*on  �  Purchase  Data  �  Apple  Account  Data  

© 2011 Harris Corporation

Page 28: CEIC 2011 - iOS Application Forensics

iTunesMetadata.plist  

 

© 2011 Harris Corporation

hZp://itunes.apple.com/app/id321506742    

Page 29: CEIC 2011 - iOS Application Forensics

/Library/Caches/Snapshots/  •  Might  get  lucky.    •  This  directory  may  

contain  a  screenshot  of  the  screen  when  the  device  was  screen  locked.  

 

© 2011 Harris Corporation

Page 30: CEIC 2011 - iOS Application Forensics

Other  System  Files  •  /var/mobile/Library/Caches/com.apple.mobile.installa5on.plist  

•  Useful  to  map  applica*on  GUIDs  to  specific  apps  •  47328AE1-­‐CB56-­‐4FE4-­‐8EEE-­‐2A771109DC55  =  com.aol.aim  

•  Contains  App  Specific  data  

•  /var/mobile/Library/Preferences/com.apple.appstore.plist  •  App  Store  –  Last  Search  entry  

•  /var/mobile/Library/Preferences/com.apple.loca5ond.plist  •  List  of  Apps  that  use  the  Loca*on  Services  •  Binary  seyng  show  if  Loca*on  Services  are  enabled  

•  /var/mobile/Library/Preferences/com.apple.springboard.plist  •  Contains  the  order  of  Applica*ons  on  each  “screen”  

 

© 2011 Harris Corporation

Page 31: CEIC 2011 - iOS Application Forensics

com.apple.mobile.installa*on.plist  

© 2011 Harris Corporation

 

Page 32: CEIC 2011 - iOS Application Forensics

com.apple.appstore.plist  

© 2011 Harris Corporation

 

Page 33: CEIC 2011 - iOS Application Forensics

com.apple.loca*ond.plist  

© 2011 Harris Corporation

 

Page 34: CEIC 2011 - iOS Application Forensics

com.apple.springboard.plist  

© 2011 Harris Corporation

 

Page 35: CEIC 2011 - iOS Application Forensics

GOOD  THINGS  TO  KNOW  

© 2011 Harris Corporation

Page 36: CEIC 2011 - iOS Application Forensics

Dates  �  Many  use  Absolute  Time  

�  Seconds  from  1/1/2001  00:00:00  GMT  

�  Tools:  �  Mac:  CFAbsoluteTimeConverter    

�  (hsoi.com/hsoishop/so^ware/)  �  Windows:  Dcode    

�  (digital-­‐detec*ve.co.uk/freetools/decode.asp)  �  BlackBag’s  Epoch  Converter  

�  (blackbagtech.com/resources/freetools/epochconverter.html)  

�  …or  add  978307200  and  use  date -ur

© 2011 Harris Corporation

Page 37: CEIC 2011 - iOS Application Forensics

Blackbag’s  Epoch  Converter  

© 2011 Harris Corporation

Page 38: CEIC 2011 - iOS Application Forensics

Popular  File  Formats  -­‐  Plist  �  Property  List  

�  XML  or  Binary  

�  Tools  �  Property  List  Editor  

�  Mac  Only  �  Xcode  �  Free!  (w/  Mac  OS)  

�  Ibackupbot  Plist  Editor  �  Windows  Only  �  icopybot.com/download.htm  �  Free!  

© 2011 Harris Corporation

Page 39: CEIC 2011 - iOS Application Forensics

Popular  File  Formats  -­‐  SQLite  �  SQL-­‐based  rela*onal  database  �  SQLite  Database  Browser  �  Tools  

�  Mac  &  Windows  �  sqlitebrowser.sourceforge.net  �  Free!  

© 2011 Harris Corporation

Page 40: CEIC 2011 - iOS Application Forensics

NOW  TO  THE  GOOD  STUFF…  

© 2011 Harris Corporation

Page 41: CEIC 2011 - iOS Application Forensics

SOCIAL  NETWORKING  

© 2011 Harris Corporation

Page 42: CEIC 2011 - iOS Application Forensics

Facebook  v.3.4  

© 2011 Harris Corporation

Page 43: CEIC 2011 - iOS Application Forensics

com.facebook.Facebook.plist  

© 2011 Harris Corporation

Page 44: CEIC 2011 - iOS Application Forensics

com.facebook.Facebook.plist  

© 2011 Harris Corporation

Page 45: CEIC 2011 - iOS Application Forensics

/Documents/friends.db  

© 2011 Harris Corporation

Page 46: CEIC 2011 - iOS Application Forensics

Facebook  Profile  �  hZp://www.facebook.com/profile.php?id=<UID>  

© 2011 Harris Corporation

Page 47: CEIC 2011 - iOS Application Forensics

User  Picture  (pic_square)  

© 2011 Harris Corporation

Page 48: CEIC 2011 - iOS Application Forensics

/Documents/analy*cs_buffer  

© 2011 Harris Corporation

Page 49: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  May  contain:  

�  Profile  Icons  �  XML  Text  Files  �  Album  Photos  �  Miscellaneous  Pictures  

© 2011 Harris Corporation

Page 50: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  <fql_result>  

�  <name>checkins_ac*vity<name>  �  Contains  User  IDs  &  coordinates  �  Lots  of  other  data  

© 2011 Harris Corporation

Page 51: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  <profile_response><user      

�  Contains  profile  data.  �  User  ID  �  Last  Load  Time  �  Birthday  �  Name  �  Hometown  �  Rela*onship  Status  �  Friend  Count  �  Email  �  Link  to  user  picture  �  Etc.  

© 2011 Harris Corporation

Page 52: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  <fql_result>  

�  <name>event<name>  �  Contains  Event  data  

© 2011 Harris Corporation

Page 53: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  <stream_post>  

�  Contains  “Wall”  pos*ngs  for  a  par*cular  user  in  <source_id>  

�  Includes    �  Message  �  Client  post  came  from  (Web,  TwiZer,  etc.)  �  User  comments  that  include  who  and  when.  �  Links  to  photo  aZachments  �  Link  to  permalink  

�  hZp://www.facebook.com/<uid>/posts/<post_id>  �  <post_id>  is  aZached  to  the  User  ID  by  an  underscore.  

© 2011 Harris Corporation

Page 54: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  <stream_post>  

 

© 2011 Harris Corporation

Page 55: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  �  <photos_response>  

�  Contains  links  to  photos,  including  descrip*ons,  comments  and  user  data.  

�  <profile_response><album    �  Contains  photo  album  informa*on.  

© 2011 Harris Corporation

Page 56: CEIC 2011 - iOS Application Forensics

/Library/Caches/SDURLCache/  �  Another  cache  directory.  

May  contain:  �  Javascript  �  Pictures,  complete  with  

origina*ng  URL.  

© 2011 Harris Corporation

Page 57: CEIC 2011 - iOS Application Forensics

LinkedIn  v.3.6  

© 2011 Harris Corporation

Page 58: CEIC 2011 - iOS Application Forensics

com.linkedin.LinkedIn.plist  

© 2011 Harris Corporation

Page 59: CEIC 2011 - iOS Application Forensics

“user”  Field  (com.linkedin.LinkedIn.plist)  

© 2011 Harris Corporation

Page 60: CEIC 2011 - iOS Application Forensics

/Documents/connec*ons_<memberid>.plist  

© 2011 Harris Corporation

Page 61: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn/  

© 2011 Harris Corporation

Page 62: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn/member_<memberid>.plist  

© 2011 Harris Corporation

Page 63: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn/member_<memberid>.plist  

© 2011 Harris Corporation

Page 64: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn/network_update_*  

© 2011 Harris Corporation

Page 65: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn<GUID>.sqlite  

�  ZBUZZTOPICOBJECT  

© 2011 Harris Corporation

Page 66: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn<GUID>.sqlite  

�  ZLIMESSAGE  

© 2011 Harris Corporation

Page 67: CEIC 2011 - iOS Application Forensics

/Documents/LinkedIn<GUID>.sqlite  

�  ZLIMESSAGEMEMBER  

© 2011 Harris Corporation

Page 68: CEIC 2011 - iOS Application Forensics

/Library/Caches/Three20/  

© 2011 Harris Corporation

Page 69: CEIC 2011 - iOS Application Forensics

SHOPPING  &  FINANCIAL  

© 2011 Harris Corporation

Page 70: CEIC 2011 - iOS Application Forensics

Amazon  v1.4  

© 2011 Harris Corporation

Page 71: CEIC 2011 - iOS Application Forensics

com.amazon.Amazon.plist  

© 2011 Harris Corporation

Page 72: CEIC 2011 - iOS Application Forensics

Chase  v.2.8.1202  

© 2011 Harris Corporation

Page 73: CEIC 2011 - iOS Application Forensics

User  IDs  

© 2011 Harris Corporation

com.chase.plist

/Documents/localcache.dat

Page 74: CEIC 2011 - iOS Application Forensics

Mint  v1.7.2  

© 2011 Harris Corporation

Page 75: CEIC 2011 - iOS Application Forensics

/Documents/mint_gala.db  

© 2011 Harris Corporation

“transaction_bankcc” Table

“account” Table

Page 76: CEIC 2011 - iOS Application Forensics

E*Trade  v1.8.4  

© 2011 Harris Corporation

Page 77: CEIC 2011 - iOS Application Forensics

User  ID  

© 2011 Harris Corporation

Page 78: CEIC 2011 - iOS Application Forensics

Ebay  v2.1.1  

© 2011 Harris Corporation

Page 79: CEIC 2011 - iOS Application Forensics

com.ebay.iphone.plist  

© 2011 Harris Corporation

Page 80: CEIC 2011 - iOS Application Forensics

/Library/Caches/Seyngs/<userid>-­‐X-­‐0-­‐user.cache  

�  Contains  User  Informa*on  �  Full  Address  �  Email  Address  �  Account  Name  �  Phone  Number  

© 2011 Harris Corporation

Page 81: CEIC 2011 - iOS Application Forensics

Paypal  v3.2  

© 2011 Harris Corporation

Page 82: CEIC 2011 - iOS Application Forensics

com.yourcompany.PPClient.plist  

© 2011 Harris Corporation

Page 83: CEIC 2011 - iOS Application Forensics

/Documents/PayPalUserDetailsCache  

© 2011 Harris Corporation

Street Address

Secure Merchant ID

Page 84: CEIC 2011 - iOS Application Forensics

PageOnce  –  Personal  Finance    v3.84  &  v4.01  

© 2011 Harris Corporation

Page 85: CEIC 2011 - iOS Application Forensics

Difference  between  v3.84  &  4.01  

© 2011 Harris Corporation

Version 3.84

Page 86: CEIC 2011 - iOS Application Forensics

Difference  between  v3.84  &  4.01  

© 2011 Harris Corporation Version 4.01

Page 87: CEIC 2011 - iOS Application Forensics

GOOGLE  

© 2011 Harris Corporation

Page 88: CEIC 2011 - iOS Application Forensics

iGmail  v5.6.8  

© 2011 Harris Corporation

Page 89: CEIC 2011 - iOS Application Forensics

com.idemfactor.iGmail.plist  

© 2011 Harris Corporation

Page 90: CEIC 2011 - iOS Application Forensics

/Library/WebKit/Databases/hZps_mail.google.com_0/0000000000000001.db  

© 2011 Harris Corporation

Page 91: CEIC 2011 - iOS Application Forensics

Mul*G  v1.3  

© 2011 Harris Corporation

Page 92: CEIC 2011 - iOS Application Forensics

/Documents/Mul*G/People.sqlite  

© 2011 Harris Corporation

Page 93: CEIC 2011 - iOS Application Forensics

La*tude  v2.1.2  

© 2011 Harris Corporation

Page 94: CEIC 2011 - iOS Application Forensics

/Documents/loca*on.plist      Library/Preferences/com.google.GoogleLa*tude.plist  

© 2011 Harris Corporation

Page 95: CEIC 2011 - iOS Application Forensics

CalenGoo  v1.5.11  

© 2011 Harris Corporation

Page 96: CEIC 2011 - iOS Application Forensics

/Documents/gca.sqlite  “DbProperty”  Table  

© 2011 Harris Corporation

Page 97: CEIC 2011 - iOS Application Forensics

/Documents/gca.sqlite  “Event”  Table  

© 2011 Harris Corporation

Page 98: CEIC 2011 - iOS Application Forensics

/Documents/gca.sqlite  “Times”  Table  

© 2011 Harris Corporation

1305432000 = Sun May 15 00:00:00 EDT 2011 1305777600 = Thu May 19 00:00:00 EDT 2011

Page 99: CEIC 2011 - iOS Application Forensics

/Documents/gca.sqlite  “GTasksTask”  Table  

© 2011 Harris Corporation

CEIC q  Check on hotel Reservation q Make Changes to Presentation

Page 100: CEIC 2011 - iOS Application Forensics

UTILITIES  

© 2011 Harris Corporation

Page 101: CEIC 2011 - iOS Application Forensics

TouchTerm  v2.4.2  

© 2011 Harris Corporation

Page 102: CEIC 2011 - iOS Application Forensics

net.jbrink.mobile.TouchTerm.plist  

© 2011 Harris Corporation

Page 103: CEIC 2011 - iOS Application Forensics

“connec*ons”  Field  

© 2011 Harris Corporation

Item  1  &  3  =  Hostname  Item  4  =  Username  Item  6  =  Password  

Page 104: CEIC 2011 - iOS Application Forensics

/Documents/pinchmedia/*.sql  

© 2011 Harris Corporation

Page 105: CEIC 2011 - iOS Application Forensics

Anonymous  Web  Browser  v2.0  

© 2011 Harris Corporation

Page 106: CEIC 2011 - iOS Application Forensics

/Documents/Cookies.plist  

© 2011 Harris Corporation

Page 107: CEIC 2011 - iOS Application Forensics

/Library/WebKit/LocalStorage/hZp_www.google.com_0.localstorage  

© 2011 Harris Corporation

Page 108: CEIC 2011 - iOS Application Forensics

Quick  Password  Manager  v2.2  

© 2011 Harris Corporation

Page 109: CEIC 2011 - iOS Application Forensics

com.yourcompany.passwd.plist  

© 2011 Harris Corporation

Page 110: CEIC 2011 - iOS Application Forensics

Passwords  

© 2011 Harris Corporation

Page 111: CEIC 2011 - iOS Application Forensics

MobileRSS  HD  Free  v3.2.1  

© 2011 Harris Corporation

Page 112: CEIC 2011 - iOS Application Forensics

/Documents/<username>@gmail.com.seyng  

© 2011 Harris Corporation

Page 113: CEIC 2011 - iOS Application Forensics

/Documents/<username>@gmail.com.sqlite  

�  Unencrypted  password!  

�  VERY  large  SQLite  database  �  Text  of  RSS  Feeds  �  Metadata  about  feeds  

© 2011 Harris Corporation

Page 114: CEIC 2011 - iOS Application Forensics

com.nibirutech.MobileRSSHDFree.plist  

© 2011 Harris Corporation

Page 115: CEIC 2011 - iOS Application Forensics

/Library/Caches/download/images/<username>@gmail.com  

© 2011 Harris Corporation

Page 116: CEIC 2011 - iOS Application Forensics

OpenTable  v3.2  

© 2011 Harris Corporation

Page 117: CEIC 2011 - iOS Application Forensics

com.contextop*onal.OpenTable.plist  

© 2011 Harris Corporation

Page 118: CEIC 2011 - iOS Application Forensics

BLOGGING  

© 2011 Harris Corporation

Page 119: CEIC 2011 - iOS Application Forensics

Tumblr  v1.2.2  

© 2011 Harris Corporation

Page 120: CEIC 2011 - iOS Application Forensics

/Documents/userData.mxdata  

© 2011 Harris Corporation

Unencrypted Password

Email

Page 121: CEIC 2011 - iOS Application Forensics

/Documents/textPost.details  

© 2011 Harris Corporation

Page 122: CEIC 2011 - iOS Application Forensics

WordPress  v2.6.4  

© 2011 Harris Corporation

Page 123: CEIC 2011 - iOS Application Forensics

/Documents/wordpress/blogs.archive  

© 2011 Harris Corporation

Item  21  =  Username  Item  22  =  BlogID  Item  23  =  Blog  URL  Item  24  =  Blog  name  Item  25  =  Blog  URL  

Page 124: CEIC 2011 - iOS Application Forensics

/Documents/wordpress/<blog>.wordpress.com/<blogid>/comment.1.archive  

© 2011 Harris Corporation

Page 125: CEIC 2011 - iOS Application Forensics

/Documents/wordpress/<blog>.wordpress.com/<blogid>/post.1.archive  

© 2011 Harris Corporation

Page 126: CEIC 2011 - iOS Application Forensics

org.wordpress.plist  

© 2011 Harris Corporation

Page 127: CEIC 2011 - iOS Application Forensics

Bing  for  iPad  v1.0  

© 2011 Harris Corporation

Page 128: CEIC 2011 - iOS Application Forensics

/Library/Preferences/com.microso^.binghd.plist  

© 2011 Harris Corporation

Page 129: CEIC 2011 - iOS Application Forensics

/Documents/BingTab.sqlite  

© 2011 Harris Corporation

Page 130: CEIC 2011 - iOS Application Forensics

/Documents/weatherSearch  

© 2011 Harris Corporation

Page 131: CEIC 2011 - iOS Application Forensics

/Documents/MapsCache  

© 2011 Harris Corporation

Page 132: CEIC 2011 - iOS Application Forensics

/Documents/MapsCache  

© 2011 Harris Corporation

Page 133: CEIC 2011 - iOS Application Forensics

TRAVEL  

© 2011 Harris Corporation

Page 134: CEIC 2011 - iOS Application Forensics

TripIt  v2.4    

© 2011 Harris Corporation

Page 135: CEIC 2011 - iOS Application Forensics

/Documents/TripIt.sqlite  

© 2011 Harris Corporation

Page 136: CEIC 2011 - iOS Application Forensics

/Documents/TripIt.sqlite  

© 2011 Harris Corporation

Page 137: CEIC 2011 - iOS Application Forensics

/Documents/TripIt.sqlite  

© 2011 Harris Corporation

“ZTRAVELER” Table

Page 138: CEIC 2011 - iOS Application Forensics

/Documents/TripIt.sqlite  

© 2011 Harris Corporation

“ZTRIPITOBJECT” Table

Page 139: CEIC 2011 - iOS Application Forensics

Navigon  v1.7  

© 2011 Harris Corporation

Page 140: CEIC 2011 - iOS Application Forensics

com.navigon.NavigonNorthAmerica.plist  �  Program  Preferences  

�  Audio  �  Terrain  �  POIs  �  Speed  Warnings  �  Traffic  �  Etc.    

© 2011 Harris Corporation

Page 141: CEIC 2011 - iOS Application Forensics

/Library/Preferences/com.navigon.NavigonNorthAmerica.plist  

© 2011 Harris Corporation

Last  Posi*on  &  Angle  

Metadata

Page 142: CEIC 2011 - iOS Application Forensics

/Documents/LastSearchResult.dat  

© 2011 Harris Corporation

Page 143: CEIC 2011 - iOS Application Forensics

/Documents/Favourite.targets  

© 2011 Harris Corporation

Page 144: CEIC 2011 - iOS Application Forensics

/Documents/Recent.targets  

© 2011 Harris Corporation

Page 145: CEIC 2011 - iOS Application Forensics

FourSquare  v2.2.2    

© 2011 Harris Corporation

Page 146: CEIC 2011 - iOS Application Forensics

/Documents/foursquare.sqlite  

© 2011 Harris Corporation

“ZFSVENUE” Table

Page 147: CEIC 2011 - iOS Application Forensics

/Documents/foursquare.sqlite  

© 2011 Harris Corporation

http://foursquare.com/user/<userid>

“ZFSNOTIFICATIONOBJECT” Table

Page 148: CEIC 2011 - iOS Application Forensics

DOCUMENTS  &  FILES  

© 2011 Harris Corporation

Page 149: CEIC 2011 - iOS Application Forensics

Evernote  v4.0.2  

© 2011 Harris Corporation

Page 150: CEIC 2011 - iOS Application Forensics

com.evernote.iPhone.Evernote.plist  

© 2011 Harris Corporation

Page 151: CEIC 2011 - iOS Application Forensics

Evernote2.sqlite.md  

© 2011 Harris Corporation

<IncomingEmail>@m.evernote.com

Page 152: CEIC 2011 - iOS Application Forensics

Library/Caches/www.evernote.com  

© 2011 Harris Corporation

Page 153: CEIC 2011 - iOS Application Forensics

applog.txt  

© 2011 Harris Corporation

Page 154: CEIC 2011 - iOS Application Forensics

Evernote2.sqlite  ZENSERVICEENTITY  Table  

© 2011 Harris Corporation

Page 155: CEIC 2011 - iOS Application Forensics

Evernote2.sqlite  

© 2011 Harris Corporation

“LOCALFILE”  Table  

Page 156: CEIC 2011 - iOS Application Forensics

Dropbox  v1.3.1  

© 2011 Harris Corporation

Page 157: CEIC 2011 - iOS Application Forensics

/Documents/Dropbox.sqlite  

© 2011 Harris Corporation

“ZCACHEDFILE”  Table  

/Library/Caches/Dropbox/  

Page 158: CEIC 2011 - iOS Application Forensics

com.getdropbox.Dropbox.plist  

© 2011 Harris Corporation

Page 159: CEIC 2011 - iOS Application Forensics

com.getdropbox.Dropbox.plist  �  Content  from  “DefaultsAccountInfoKey”  in  bplist  format,  

can  be  viewed  by  extrac*ng  into  separate  file  –  shown  below.  

© 2011 Harris Corporation

Page 160: CEIC 2011 - iOS Application Forensics

/Library/Caches/FavoriteFiles.plist  

© 2011 Harris Corporation

Page 161: CEIC 2011 - iOS Application Forensics

/Library/Caches/cache.db  

© 2011 Harris Corporation

Page 162: CEIC 2011 - iOS Application Forensics

/Library/Caches/cache.db  

© 2011 Harris Corporation

Page 163: CEIC 2011 - iOS Application Forensics

/Library/Caches/cache.db  

© 2011 Harris Corporation

Page 164: CEIC 2011 - iOS Application Forensics

/Library/Caches/cache.db  

© 2011 Harris Corporation

Page 165: CEIC 2011 - iOS Application Forensics

Private  Photo  Lite  v1.3  

© 2011 Harris Corporation

Page 166: CEIC 2011 - iOS Application Forensics

/Documents/  

© 2011 Harris Corporation

Page 167: CEIC 2011 - iOS Application Forensics

/Documents/photodb.sqlite  

© 2011 Harris Corporation

Page 168: CEIC 2011 - iOS Application Forensics

cn.mmxd.privatephotoslite.plist  

© 2011 Harris Corporation

Page 169: CEIC 2011 - iOS Application Forensics

TWITTER  

© 2011 Harris Corporation

Page 170: CEIC 2011 - iOS Application Forensics

Echofon  v3.1.8  

© 2011 Harris Corporation

Page 171: CEIC 2011 - iOS Application Forensics

/Preferences/net.naan.TwiZerFon.plist  

© 2011 Harris Corporation

Page 172: CEIC 2011 - iOS Application Forensics

db3.1.5.db    �  “users”  Table  

�  Contains  user  details:  �  TwiZer  User  ID  �  Name  &  Screen  Name  �  User  entered  loca*on,  descrip*on  and  website.  �  Count  of  followers/friends/favorites/tweets  �  Is  the  account  protected  or  verified?  �  Link  to  profile  icon  (hZp://a2.twimg.com/profile_images/647123757/Muppet-­‐Beaker_normal.jpg)  

 

© 2011 Harris Corporation

Page 173: CEIC 2011 - iOS Application Forensics

/Library/profile_images  �  hZp://a2.twimg.com/profile_images/647123757/Muppet-­‐Beaker_normal.jpg  

© 2011 Harris Corporation

Page 174: CEIC 2011 - iOS Application Forensics

db3.1.5.db  �  hZp://twiZer.com/statuses/user_*meline/105533433.rss  

© 2011 Harris Corporation

Fill in the twitter user ID to get their latest tweets

Page 175: CEIC 2011 - iOS Application Forensics

db3.1.5.db  

© 2011 Harris Corporation

“queries”  Table:  

“saved_search”  Table:  

Page 176: CEIC 2011 - iOS Application Forensics

db3.1.5.db    �  “direct_messages”  Table  

�  Contains  direct  messages.  �  To  &  From  (TwiZer  IDs  and  Screen  

Names)  �  Dates  

 

© 2011 Harris Corporation

Page 177: CEIC 2011 - iOS Application Forensics

Library/Cookies/Cookies.plist  

© 2011 Harris Corporation

Page 178: CEIC 2011 - iOS Application Forensics

HootSuite  v2.1.0  

© 2011 Harris Corporation

Page 179: CEIC 2011 - iOS Application Forensics

com.hootsuite.hootsuitelite.plist  

© 2011 Harris Corporation

Page 180: CEIC 2011 - iOS Application Forensics

com.hootsuite.hootsuitelite.plist  

© 2011 Harris Corporation

Page 181: CEIC 2011 - iOS Application Forensics

com.hootsuite.hootsuitelite.plist  

© 2011 Harris Corporation

Page 182: CEIC 2011 - iOS Application Forensics

TwiZeriffic  v3.0.2  

© 2011 Harris Corporation

Page 183: CEIC 2011 - iOS Application Forensics

/Documents/accounts.plist  

© 2011 Harris Corporation

Page 184: CEIC 2011 - iOS Application Forensics

Timeline  

© 2011 Harris Corporation

Page 185: CEIC 2011 - iOS Application Forensics

/Documents/searches.plist  

© 2011 Harris Corporation

Page 186: CEIC 2011 - iOS Application Forensics

Search  Databases  

© 2011 Harris Corporation

Page 187: CEIC 2011 - iOS Application Forensics

Tweetdeck  v1.4.1    

© 2011 Harris Corporation

Page 188: CEIC 2011 - iOS Application Forensics

/Documents/tddb.0.2.sqlite3  

© 2011 Harris Corporation

Page 189: CEIC 2011 - iOS Application Forensics

/Documents/column_cache_1  

© 2011 Harris Corporation

Page 190: CEIC 2011 - iOS Application Forensics

/Documents/tddb.0.2.sqlite3  

© 2011 Harris Corporation

Page 191: CEIC 2011 - iOS Application Forensics

COMMUNICATION  

© 2011 Harris Corporation

Page 192: CEIC 2011 - iOS Application Forensics

Skype  v3.0.1  

© 2011 Harris Corporation

Page 193: CEIC 2011 - iOS Application Forensics

/Library/Preferences/com.skype.skype.plist  

© 2011 Harris Corporation

Page 194: CEIC 2011 - iOS Application Forensics

Skype  Logs  

© 2011 Harris Corporation

Page 195: CEIC 2011 - iOS Application Forensics

Skype  Logs  

© 2011 Harris Corporation

Page 196: CEIC 2011 - iOS Application Forensics

Skype  Logs  

© 2011 Harris Corporation

Page 197: CEIC 2011 - iOS Application Forensics

Skype  Logs  

© 2011 Harris Corporation

Page 198: CEIC 2011 - iOS Application Forensics

Skype  Logs  (Windows)  �  Skype  Parsing  So^ware  

�  SkypeLogView  �  Nirso^    

�  Available  at:  nirso^.net/u*ls/skype_log_view.html  �  Free!  

�  Skype  Parser  �  Redwolf  Computer  Forensics  �  Available  at:  redwolfcomputerforensics.com/downloads/skype-­‐

log-­‐installer-­‐1.7.exe  

© 2011 Harris Corporation

Page 199: CEIC 2011 - iOS Application Forensics

AIM  (Free)  v4.5.2  

© 2011 Harris Corporation

Page 200: CEIC 2011 - iOS Application Forensics

com.aol.aim.plist  

© 2011 Harris Corporation

Page 201: CEIC 2011 - iOS Application Forensics

/Documents/userAccounts/<GUID>.account  

© 2011 Harris Corporation

Page 202: CEIC 2011 - iOS Application Forensics

/Documents/userAccounts/<GUID>.buddylist  

© 2011 Harris Corporation

Page 203: CEIC 2011 - iOS Application Forensics

/Documents/userAccounts/<GUID>.history  

© 2011 Harris Corporation

Page 204: CEIC 2011 - iOS Application Forensics

WRAPPING  UP  

© 2011 Harris Corporation