Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 35 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Open Source Forensics on Android
EH-Net
May 23, 2013, 04:12:12 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Open Source Forensics on Android  (Read 4046 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« on: June 03, 2011, 03:27:10 PM »

Alright, since no one has posted in a little bit, decided to post some of my ramblings I sent to some friends. As some may or may not know, I'm doing the DFRWS Android forensics challenge for fun and thought I would share, in the event any of you ever have to do some open source "scalpel/foremost" forensics scalpelnig on Android images....

I already did my entry for the challenge using both EnCase and FTK but also am doing it the freebie way now with a modified version CAINE. (Mines now has testdisk, Android SDK, yaffs2 file system, Volatility, etc.)


My quick way to parse out the numbers dialed from the forensic image:

Code:
strings *.img | grep '^\![0-9]\{10\}' | grep -vi [a-z] | sort -u

In action: (numbers are X'd out to avoid giving away answers to the challenge)

Code:
root@phorensix:/media/sdb1/DFRWS# strings *.img | grep '^\![0-9]\{10\}'
| grep -vi [a-z] | sort -u
!2xxxxxxxxxxxxxxxxxx
!4xxxxxxxxx
!4xxxxxxxxx
!5xxxxxxxxx

I can pipe it out and do a reverse lookup for the number(s) found as well from a terminal:

Code:
strings *.img | grep '^\![0-9]\{10\}' | grep -vi [a-z] |\
sort -u | sed 's:\!::g;s:^:links -dump "http\://www.whitepages.com/search/ReversePhone?full_phone=:g;s:$:":g'|sh

God AW(K)ful parsing of sms message addressees: (in action)

Code:
root@phorensix:/media/sdb1/DFRWS# strings mtdblock6.img | awk
'/FORW/{print $7}' | awk '/@/{gsub(/:/,"");print $1|"sort"}' | awk 'a !~
$0; {a=$0}'
sxxxxxx@xxxxxxxx.com
sxx.xxxxxxx@xxxxx.com

Still working on the disks as time allows however, foremost and scalpel are raping my storage space forcing me to plop on another 500GB for this Android image:

Code:
root@phorensix:/media/sdb1/DFRWS#  df -h | grep G
/dev/sda1             195G  4.6G  180G   3% /
/dev/sdb1             493G  226G  242G  49% /media/sdb1

Original sizes of forensics:

Code:
root@phorensix:/media/sdb1/DFRWS# ls -ltha *.img | awk '{print $8"\t"$5}'
mtdblock6.img   262M
mtdblock7.img   2.0M
mtdblock5.img   93M
mtdblock4.img   141M
mtdblock0.img   1.5M
mtdblock1.img   384K
mtdblock3.img   4.5M
SDCard.img      0

After Scalpel rapes my disk with its carving:


Code:
root@phorensix:/media/sdb1/DFRWS# du -h DFRWS{0..7}|grep -vi /
du: cannot access `DFRWS2': No such file or directory
du: cannot access `DFRWS4': No such file or directory
4.5M    DFRWS0
8.0K    DFRWS1
7.9M    DFRWS3
16M     DFRWS5
219G    DFRWS6
8.0K    DFRWS7

Mind you I'm not even done,  I have to re-scalp mtdblock4.img and mtdblock7.img. The total process for *6.img has taken so far 5 hours, has grown to 219G and its only 72.6% done as of right now. Like crawlingly slow. Not even my industrial music makes it seem any faster and that is averaging about 120+bpms give or take 80bpms if its KMFDM.

Logged

sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« Reply #1 on: June 03, 2011, 03:38:33 PM »

More fun (because I'm painfully waiting for scalpel to finish, to get a quick glimpse at anything that was saved (files, pdf, doc, ppt, etc.)


Code:

strings *.img|grep -i "/sdcard/\|/data/"|\
grep -vi "<\|>\|\!\|(\|)\|system\|;\|=\|#\|*\|com.\|%"|\
awk '!($0 in a) {a[$0];print}'


Unfortunately that this carving will likely be running until circa 10PM it seems
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.