Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 48 guests and 2 members online
Free Business and Tech Magazines and eBooks
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Mobile
Locked iPhone
EH-Net
May 22, 2013, 09:54:13 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Mobile
(Moderator:
don
) >
Locked iPhone
Pages: [
1
]
2
Go Down
« previous
next »
Print
Author
Topic: Locked iPhone (Read 2939 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 864
Locked iPhone
«
on:
March 14, 2013, 08:46:03 AM »
Hi everyone,
Ok first, I think most people here on this forum know me by now and I am not a bad guy. I say this because this story really look bad...
My accountant now has an iPhone 4S, but she still has her old iPhone 3G (no longer connect to a carrier). So she is only using her iPhone 4S. This old iPhone 3G was sync and backed up to iTunes, which was installed on her laptop. The problem is that last fall, somebody broke into her office and stole many things, including her laptop. And since she hasn't used her old iPhone 3G for a while, she couldn't remember her password. She tried login in many times and ended up locking her old phone...
The thing is she has pictures of her daughter that was taken by this phone and was backed up on her stolen laptop. She asked me if I could retrieve her pictures...
She contacted Apple and they said the only thing they can do is wipe out the phone for her (since they match the serial number to her name), but they cannot unlock it for her (which is a good thing!). So she came to me, knowing what I do for a leaving...
So you see? My story looks like the ones we get once in a while on this forum! I feel a bit lame for that...
But I have known her for many years now and I know she's telling the truth... The phone's id is under her name and there is a picture of her daughter in the logging screen... And no, I didn't steal/found an iPhone I try to steal data from.
I spent something around 6 hours trying to jailbreak this locked iPhone without success... I think she was using iOS 4.1 or something close to this.
So is it possible to recover pictures from a locked iPhone?
Thanks
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
chrisj
Hero Member
Offline
Posts: 1163
Re: Locked iPhone
«
Reply #1 on:
March 14, 2013, 11:04:02 AM »
probably not much help, but did you see this?
http://lifehacker.com/5852948/what-to-do-if-youve-forgotten-your-iphones-passcode
It says you can sync the phone even when it's locked. Not having an iphone, and not touching itunes in about 6 years, I don't know if you can add and sync a new device while it is locked.
«
Last Edit: March 14, 2013, 11:05:47 AM by chrisj
»
Logged
OSWP, Sec+
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Locked iPhone
«
Reply #2 on:
March 14, 2013, 02:11:42 PM »
Thanks chrisj but the problem with this is you need "the" iTunes that was used for the backup BEFORE the phone got locked. As you may or may not know, you can only sync your iPhone, iPod or iPad with a single version of iTunes. If she would still have her laptop (with the version of iTunes she used to sync with), she could recover her phone using this technique. Similarly, if she wouldn't care about her pictures, she could use this procedure with any iTunes to reset the phone to the factory state.
The problem is in the fact she wants her pictures back...
But thanks anyways!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Matthias2012
Newbie
Offline
Posts: 10
Re: Locked iPhone
«
Reply #3 on:
March 14, 2013, 02:52:32 PM »
Hello H1t M0nk3y,
how good is your german?
On the last IT-Security Exhibition in Nuernberg/Germany the CIO of ssys.de showed how to get into a locked iPad. Maybe this will give you an idea..
He also said that an iPhone works similiar...
http://www.techcast.com/events/it-sa-livehacking/dienstag-gruen-1015-schreiber
it shows him in action...
Regards
Logged
Matthias Dörfer
_______________________________________________________
eCPPT - C|EH - MCITP
m0wgli
Full Member
Offline
Posts: 248
Re: Locked iPhone
«
Reply #4 on:
March 14, 2013, 03:24:22 PM »
Unfortunately, from what I've been able to find (as I'm sure you have), given the circumstances, your friend needs to start considering those pictures lost.
I hope to be proved wrong!
Logged
Security + | OSWP | eCPPT | CSTA
Matthias2012
Newbie
Offline
Posts: 10
Re: Locked iPhone
«
Reply #5 on:
March 14, 2013, 04:48:30 PM »
I looked at the video and then I looked at your first posting again and I`am afraid but if your tried to "bruteforce" the pin for the GUI, then the device will have deleted the AES-decryption keys after X attempts and even for a forensic expert the data is lost...
Regards
Logged
Matthias Dörfer
_______________________________________________________
eCPPT - C|EH - MCITP
ajohnson
Recruiters
Hero Member
Online
Posts: 1057
aka dynamik
Re: Locked iPhone
«
Reply #6 on:
March 14, 2013, 05:33:32 PM »
I thought this was simple to do offline if you open up the phone and remove the storage device. Invalid attempts aren't going to wipe it since that depends on the running OS software. You should be able to do that almost instantly if she was only using a four-digit PIN. I don't work with this much, so I don't know the specific tools, but I swear I've heard this attack discussed multiple times.
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
chrisj
Hero Member
Offline
Posts: 1163
Re: Locked iPhone
«
Reply #7 on:
March 14, 2013, 10:08:42 PM »
Quote from: H1t M0nk3y on March 14, 2013, 02:11:42 PM
As you may or may not know, you can only sync your iPhone, iPod or iPad with a single version of iTunes.
This I did not know, I thought you could sync / back up to multiple version of iTunes (like I said, haven't used in forever).
what about attaching it to a linux box and just mounting it as a local device? I don't remember having to do anything special when I had my ipod color.
Logged
OSWP, Sec+
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Locked iPhone
«
Reply #8 on:
March 15, 2013, 11:02:26 AM »
Quote
what about attaching it to a linux box and just mounting it as a local device? I don't remember having to do anything special when I had my ipod color.
@chrisj: I tried but the phone itself is locked, so it doesn't work either...
Quote
the device will have deleted the AES-decryption keys after X attempts and even for a forensic expert the data is lost...
@Matthias2012: I don't know german at all (regarding the video), but do you know at which iOS version Apple has started to do this?
Quote
I thought this was simple to do offline if you open up the phone and remove the storage device. Invalid attempts aren't going to wipe it since that depends on the running OS software. You should be able to do that almost instantly if she was only using a four-digit PIN. I don't work with this much, so I don't know the specific tools, but I swear I've heard this attack discussed multiple times.
@ajohnson: I think I may have to follow this route... I will research on this topic and post my findings. I hope I won't have to buy new hardware...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
m0wgli
Full Member
Offline
Posts: 248
Re: Locked iPhone
«
Reply #9 on:
March 15, 2013, 11:29:12 AM »
I was looking through these last night, you might find something of use in here:
iOS hacking resource collection
«
Last Edit: March 15, 2013, 11:43:09 AM by m0wgli
»
Logged
Security + | OSWP | eCPPT | CSTA
jjwinter
Jr. Member
Offline
Posts: 76
Re: Locked iPhone
«
Reply #10 on:
March 16, 2013, 11:24:01 AM »
Did she use iCloud for backup?
Logged
m0wgli
Full Member
Offline
Posts: 248
Re: Locked iPhone
«
Reply #11 on:
March 16, 2013, 11:34:01 AM »
Quote from: jjwinter on March 16, 2013, 11:24:01 AM
Did she use iCloud for backup?
Unfortunately to use iCloud you need iOS 5 or higher, this isn't available for the iPhone 3G.
«
Last Edit: March 16, 2013, 01:55:50 PM by m0wgli
»
Logged
Security + | OSWP | eCPPT | CSTA
H1t M0nk3y
Hero Member
Offline
Posts: 864
Re: Locked iPhone
«
Reply #12 on:
March 18, 2013, 06:01:20 AM »
Well, I think her pictures are gone forever now...
Thanks everyone for you help. At least, I have learn quite a few things along the way...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
ajohnson
Recruiters
Hero Member
Online
Posts: 1057
aka dynamik
Re: Locked iPhone
«
Reply #13 on:
March 18, 2013, 09:37:42 AM »
Ah, turns out I was wrong. You can't do an offline attack because you need to extract the hardware key.
Have you tried something like this?
https://www.youtube.com/watch?v=S6OIK0oL6SI
It looks like Elcomsoft has a commercial tool too:
http://www.elcomsoft.com/eppb.html
That might be worth a shot if nothing else works and the photos are worth $80 to her.
«
Last Edit: March 18, 2013, 09:39:15 AM by ajohnson
»
Logged
WIP: GCFA |
www.infosiege.net
| @infosiege
The day you stop learning is the day you start becoming obsolete.
m0wgli
Full Member
Offline
Posts: 248
Re: Locked iPhone
«
Reply #14 on:
March 18, 2013, 04:03:48 PM »
Quote from: H1t M0nk3y on March 18, 2013, 06:01:20 AM
At least, I have learn quite a few things along the way...
Same here, I know now considerably more about iOS security than I did last week.
Quote from: ajohnson on March 18, 2013, 09:37:42 AM
Ah, turns out I was wrong. You can't do an offline attack because you need to extract the hardware key.
Elcomsoft also offer an
iOS Forensic Toolkit
which can extract the keys, however, it's availability is restricted to select government entities (such as law enforcement, forensic organizations and intelligence agencies).
Quote from: ajohnson on March 18, 2013, 09:37:42 AM
It looks like Elcomsoft has a commercial tool too:
http://www.elcomsoft.com/eppb.html
That might be worth a shot if nothing else works and the photos are worth $80 to her.
AFAIK this works on a backup of the device, not the physical device.
Logged
Security + | OSWP | eCPPT | CSTA
Pages: [
1
]
2
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Greetings
: Hi from the UK
(2) by
n37sh@rk
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
Programming
: Finished Python Course in Codecademy now what?
(15) by
hanyhasan
Network Pen Testing
: Ruby on Rails Vulnerabilities / Attacks in BackTrack 5 r3
(0) by
SUdoctstudent
Network Pen Testing
: De-ICE 1.140 released!
(2) by
superkojiman
General Certification
: CPT Practical Submission
(1) by
UNIX
OSCP - Offensive Security Certified Professional
: Failed my first attempt at the OSCP exam
(94) by
azmatt
Tools
: Social-Engineer Toolkit (SET) Version 5.0 “The Wild West” Released
(2) by
m0wgli
Malware
: EICAR?
(3) by
UKSecurityGuy
Advisories
: HTB23154: Multiple Vulnerabilities in Exponent CMS
(0) by
AndyP
Advisories
: HTB23153: Multiple Vulnerabilities in Jojo CMS
(0) by
AndyP
Advisories
: HTB23151: Cross-Site Request Forgery (CSRF) in UMI.CMS
(0) by
AndyP
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(7) by
Taemyks
OSCP - Offensive Security Certified Professional
: OSCP exam scheduled
(6) by
gbhat
Incident Response
: LinkedIn Forensics
(0) by
AFENTIS_Forensics
General Certification
: Red Team/Blue Team
(1) by
ajohnson
Career Central
: Starter cert?
(3) by
Grendel
Network Pen Testing
: Beginner Ethical Hacker
(1) by
m0wgli
Web Applications
: Nessus and Nikto
(4) by
Seen
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.