Showing posts with label Magnet Forensics. Show all posts
Showing posts with label Magnet Forensics. Show all posts

Thursday, April 5, 2018

About Those Other Texting Apps in iOS…



April 5, 2018

About Those Other Texting Apps in iOS…

In the age of ubiquitous mobile device usage and the seemingly ever-present need for digital evidence in the form of text messages to be used in legal proceedings, we see lots of requests for forensic data retrieval of standard (SMS & MMS) text message retrieval, Snap Chat messages, Facebook Messenger Messages, iMessages and the like.  What is not so often discussed is the need for text messaging data from other apps that may not be as popular or supported by any of the major mobile forensic tools. Toward that end, this article will explore a sample of them. 

To facilitate this analysis, we conducted an advanced logical encrypted data extraction from an iPhone 8 Plus running iOS 11.3.  The extraction was conducted using Cellebrite Physical Analyzer v. 7.2.1.4.  Among the apps explored are:

Magic Jack:  An app used to provide an alternative phone number to the mobile device.  Currently at Pro Digital, the phone number is through Magic Jack and many clients send and receive text messages on this number

Sideline:  Another app used to provide an alternative phone number to the mobile device, other than the primary wireless number.  Some test text messages were sent using Sideline.

Discord:  An app used primarily by gamers to communicate.  The app has both mobile and desktop functionality.

Linked In:  The popular professional social networking app, with built-in messaging capability for both mobile and desktop/web application.

The primary tool for analysis used was Cellebrite Physical Analyzer, but supplemental analysis was conducted and information was obtained using Magnet Forensics Internet Evidence Finder (IEF) v. 6.12.6.

Magic Jack Artifacts

The main database within Magic Jack that stores not only text messages, but contacts, phone calls, etc. is storage-##########.sqlite (where the # is the phone number assigned to the app/device by Magic Jack.  Within that database, the “message” table specifically stores messages between the user and those contacting the user.  Each conversation with a given party is given a “conversation ID”, making following of the conversation back-and-forth relatively simple, even if the party is not readily identified by name or phone number.  It is prudent to also note that Magic Jack does ask for permission to access contacts contained within the main iPhone contact database and when permission is granted, those contacts are also present within the Magic Jack sqlite database.  Also notable is the fact that each messages is assigned a “message ID” in sequential order.  This could mean that if a message were deleted, the sequence would show missing numbers, much like in the iPhone pictures/images database.

Figure 1 below shows a sample of what the Magic Jack message database looks like in Cellebrite PA:



Fig. 1: Magic Jack Message Table

Also present in the “Message” table are dates and times of delivery of each message and the length (in characters) of each message.  None of this data is encrypted, beyond the encryption of the device itself.  All of this data is also historical, meaning the data contained in this database has been carried over through multiple devices.

Sideline Artifacts

An interesting little nugget that I didn’t know before conducting these tests is the fact that Sideline is part of the Pinger/Textfree family.  The file path for the Sqlite Database in this instance is “com.pinger.side.line” and the main database where the information we are researching is stored is “Textfree.sqlite”.  In fact, the IEF report viewer lists these artifacts under “Text Free” as indicated below in Figure 2.  This is notable because the Textfree app is not present on the device, only Sideline is.


Fig. 2: IEF Rendering Sideline as “Textfree”

The table in which all of the messages are stores is “ZEVENT” and contains not only test text messages sent to and from the app, but all voice-to-text translations of voicemail messages.  This is very helpful when potentially researching voicemails that have either been deleted and/or are not part of the main iPhone voicemail database .amr files.  Also of note, as displayed in Figure 3, is the existence of the IP address with each phone call received and answered.  For example, the IP address of 67.231.9.110 is listed in the table for certain answered calls and renders back to Bandwidth.com, which is listed on Search.org as being in Raleigh, NC.  I’m not exactly sure what Bandwidth.com has to do with Sideline, Pinger or Textfree, but it does offer another investigative angle. 



Fig. 3: Sideline Database w/ Calls IP Address Highlighted

Also present in this database under the “ZCONTACT” table are all synced contacts within the iPhone by name.

Discord & Linked In Artifacts

Although the encrypted advanced logical extraction was conducted on the device in this instance, there is very limited data obtained from both Linked In and Discord, especially as it relates to messaging.  This is likely due to one of three explanations – the data is either stored in the cloud, encoded or encrypted (or a combination thereof).  For what it’s worth, no large SQLite database files were discovered with either of these apps, only .plist files and smaller SQLite databases containing limited information.

Discord, in particular, is used by gamers, many of whom are children.  Investigators involved in child exploitation investigations should pay particular attention to this app if present on the device and attempt to document the data by whatever means possible.

Additional Items of Note

While IEF indicates that there is support for Instagram in the “Social Network” category list as seen in Figure 4, there are no recoverable Instagram messages parsed out in IEF: 


Fig. 4: Social Networking Support in IEF (Partial)

Conversely, there were many Facebook Messenger messages obtained by IEF as detailed below in Figure 5.  This is of particular note as many have asked across digital forensic list serves about the potential presence and recovery of Facebook Messenger messages.  While not every bit of information is readily apparent in IEF (i.e., the other party involved in the message), identifying the sender and receiver is a simple matter of looking in the detail tab to identify the Facebook user IDs involved in the chat.




Fig. 5: Facebook Messenger Messages in IEF

Conclusions

Those of us familiar with the strengths and limitations of the commonly used commercially available mobile forensic tools know their limitations very well.  Experiments like these start to push us beyond what is natively supported and help us take a deeper dive into the data to see what (sort of) hidden gems exist beyond what is served up on a silver platter.  There’s a ton of data out there to be had.  Companies like Cellebrite, Oxygen, MSAB and Magnet Forensics can’t be expected to support every version of every app.  It’s simply not possible, or if it were, the costs for these tools would be astronomically higher than they are now. 

It is incumbent upon the examiner to know what to look for, where to look for it (i.e., how to find it) and how to read and interpret what they find.  Missing valuable data can mean the difference between determining culpable or responsible parties in civil matters or not and in criminal cases, could mean the difference between guilt or innocence.

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Wherever You Need Us!


We Find the Truth for a Living!

Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:

Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others).  He is a Cellebrite Certified Operator and Physical Analyst.  He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.

Twitter: @ProDigital4n6

Friday, January 13, 2017

Mobile Forensics Monkey Wrench: iOS 10.2 and Encryption




January 13, 2017

Mobile Forensics Monkey Wrench: iOS 10.2 and Encryption

It’s not secret to those involved in the study and practice of mobile forensics that Apple likes to throw us curve balls with almost every new iteration of the iOS operating system.  It turns out, iOS 10.2 is no different (released December 12, 2016).  A conversation began recently on the IACIS list serve and got me thinking about trying to problem solve and figure out a work-around, so I spent the past day or so trying to do just that.  (For those interested, I also wrote an article about the problem-solving aspect of digital forensics and you can read it here.)

The background is as follows:  When an i-Device user running iOS 10.2 connects the device to a computer, they are automatically prompted by iTunes for an encryption password:



When the option to encrypt is selected, a prompt is displayed for an encryption password, which may be entirely different from the device passcode or the iTunes account password:



This default encryption prompt becomes an issue for examiners due to the fact that users often don’t remember these passwords because in the age of cloud-driven storage and wireless *everything*, users don’t routinely connect their devices to a computer and therefore, don’t remember the encryption password.  This was the issue raised by another examiner on the list serve and it prompted many replies and potential work-arounds because when examiners attempt to analyze the extractions from these devices, they’re encrypted.  Pretty much game over.
(For additional background on this issue as was introduced in iOS 10.0.1, please refer to Heather Mahalik’s blog on the topic located here.)

Before iOS 10, I ran across this problem a few times with iOS devices.  My work-around then was to simply connect the device to a foreign computer (i.e., one that it had not been connected to previously) and de-select the encryption option and create another unencrypted backup, then pull the new backup into any number of commercial tools for analysis.  This doesn’t work any longer because when the device is connected to a foreign computer and encryption is de-selected, iTunes prompts for the encryption password for verification.  Darn the luck!

Methodology

For this testing, I used an iPhone 6, which we have on-hand for testing purposes.  The phone has a handful of iMessages, pictures, videos, Kik messages and some other data on it.  I updated the phone to iOS 10.2 and encrypted the backup on the Mac side of my forensic machine.  I then switched to the Windows side and attempted to create another backup by de-selecting the “Encrypt iPhone Backup” option, which is when I quickly learned that in all updated versions of iOS and iTunes, the encryption password is needed to complete this action:



Being that I know the encryption password, I entered it and created a new backup via iTunes on my local machine.  To be sure, unless you want to use a tool such as Elcomsoft to brute-force the password or attempt a dictionary attack based upon investigation and/or social engineering, you’ll need the encryption password to make this work.  But even having the password doesn’t get us too far with Cellebrite under the current version.

How Does UFED Handle This?

Cellebrite Universal Forensic Extraction Device (UFED) Physical Analyzer (PA) has heretofore been one of the best commercial tools for acquiring and analyzing iOS devices.  Indeed, you can use UFED PA to attempt a brute-force dictionary attack on these extractions if you have decent intelligence through additional investigation or social engineering by pointing UFED PA at a text file containing case-specific dictionary words:




In conducting this test and comparison, I used the latest version (as of this publication) of UFED PA, 5.4.7.5, which was released just 24 hours prior.  As you can see from the below image, even when the proper password is entered after an advanced logical extraction directly from the device, UFED PA still doesn’t parse the “analyzed data” into chats, web history, etc. like it used to with older versions of iOS:



That’s it.  That’s pretty much all we get.  When the “Backup” folder is expanded, we are presented with this:


The red arrow is used to illustrate that the listing of files keeps going.  Further inspection of these files indicates it would be a very lengthy, tedious process to try and located you sms.db, let alone DBs from many third-party apps which can be crucial in many cases.

My next step was to create an unencrypted backup through iTunes to see if that could be pulled into UFED PA and parsed a bit nicer.  It wasn’t.  We are presented with a file structure identical to that which is created by iTunes, with one folder with a long alphanumeric name and dozens of sub-folders, each with a shorter alphanumeric designation.  The only data that was automatically parsed in the backup was images, videos and device locations.  Again, combing through all of this for your crucial evidence and databases can be a time-waster, so what else can we do?  Try to use another tool!

How About IEF?

So now we have an advanced logical image in UFED PA (that is all but useless) and a backup through iTunes that is only slightly better when viewed through UFED PA.  Now, I profess that push-button tools are the end of true forensics.  Anyone who reads this blog knows that I firmly believe that you have to know and articulate where the data is located and how it got there.  But sometimes, certain tools can help point us in the right direction.  Enter Magnet Forensics’ Internet Evidence Finder (IEF, v. 6.8.4.3639).  IEF is widely accepted as one of the best and easiest tools on the market to use.  I love it for helping me out, for getting me a leg up on where I need to look, perhaps even with another tool.  So I decided to try and pull the iTunes backup into IEF, just to see what would happen. 

First, I selected the Mobile and iOS options in IEF:



Then, I selected “File Dump” to point IEF where I wanted it to look.   



The next decision is probably the most crucial to the process.  I selected the Windows file browser, then navigated to the (now exported) iTunes backup folder - the one with the very long alphanumeric name.  But then I drilled down to the sub-folders and files immediately under the parent file and selected all of them, including all of the .plist and .db files:



Next, I had to tell IEF what I wanted it to look for.  The data set isn’t large and I’d rather have too much data to sift through than not enough, so I just chose everything and selected “next”:



It’s important to note here that I conducted a subsequent test selecting “iOS Backups” ONLY and did not receive a favorable outcome.  Also, if the backup or device is encrypted, IEF will prompt for a password.
The processing took about 15 minutes.  Once it was finished, the data was parsed out as you would have expected pre-iOS 10.2:



I have highlighted the file path of the location of the sms.db in the above image because now, IEF has told us where to look in UFED PA or other tools.  Consequently, we can now switch back to UFED to examine and export the .DB files as necessary.  The below image shows what we find in UFED PA when we follow the file path indicated through IEF in the iTunes backup of the iPhone:



So to wrap it up, get your encryption password, create a backup using iTunes on a foreign machine and bring the backup into IEF to point in you the right direction.  From there, you can expand to UFED PA or another tool of your choosing, if necessary. 

Take-Aways

There are several important things to take-away from this experiment.  First, it has become vital in mobile forensics to have more than one tool at your disposal.  Having access to two or more tools can actually save you time and effort.  Imagine how tedious it would have been to sift through all of those folders (none of which contained a .db file extension by the way) to find the text messages or other pertinent data. 

Second, the problem-solving aspect of “boots on the ground” forensics, especially mobile forensics, cannot be ignored.  To make problem-solving a little easier, start to ask about encryption FIRST and save yourself some grief down the road. It’s also becoming apparent that we simply cannot rely on the pretty push-button features of many tools in the coming years, especially with regard to Apple and their iOS… and it’s only going to get more prevalent.

Finally, things are always changing.  Never forget that.  When I was conducting this testing and writing this article, I did so knowing full well that Cellebrite may push out a solution in the next week or two.  But until those updates happen, we all need to collaborate to find solutions to these issues, because just like no one tool can do it all, no single examiner can always do it all.

UPDATE: February 13, 2017

After this article was originally published, I was contacted by Ron Serber at Cellebrite.  We discussed the issues presented by UFED and it's parsing of the data in this test case and I happily sent him a copy of the UFED file and all extraction data.  He indicated at that time that UFED PA v. 6.0 would likely solve the issue(s).

UFED for PC and Physical Analyzer v. 6.0 was released on February 7th, 2017.  Shown below is the original, unencrypted extraction that was performed in UFED, nicely parsed out in v. 6.0.


While we all know that we still need to dive into the sqlite dbs and all the other relevant files in any given case, this update to UFED for PC and UFED PA has made the job a little bit easier.  Thanks to the great folks at Cellebrite for always working hard to solve problems that practitioners may encounter in the field!

Author:
Patrick J. Siewert
Principal Consultant
Professional Digital Forensic Consulting, LLC
Virginia DCJS #11-14869
Based in Richmond, Virginia
Available Globally


We Find the Truth for a Living!
Computer Forensics -- Mobile Forensics -- Specialized Investigation

About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation investigations in Virginia court history.  Patrick is a graduate of SCERS, BCERT, the Reid School of Interview & Interrogation and multiple online investigation schools (among others). He continues to hone his digital forensic expertise in the private sector while growing his consulting & investigation business marketed toward litigators, professional investigators and corporations, while keeping in touch with the public safety community as a Law Enforcement Instructor.
Twitter: @ProDigital4n6

Tuesday, October 13, 2015

What Social Media Activity Tells a Trained Forensic Examiner



October 13, 2015

What Social Media Activity Tells a Trained Forensic Examiner

For better or for worse, social media has become a driving force in many aspects of our lives.  It helps individuals stay in touch with friends, relatives, former classmates and other acquaintances.  It also helps business drive users to websites, advertise and (hopefully) generate revenue.  Heck, even this little ole blog gets posted across multiple social media platforms to help generate "buzz" for a startup digital forensic consulting business.  But what value does that social media activity have when conducting investigations?  What can the social media data tell a trained digital forensic examiner?

This subject is yet another where I'll emphasize the value of possessing honed investigative skills in addition to being a practicing, competent, trained forensic examiner.  The basis of how to conduct investigations involving social media, web activity or other electronically stored information (ESI) or even simply basic online investigations, comes through training and experience.  Through the Internet Crimes Against Children (ICAC) Task Force, I was trained how to effectively track down people and gather intelligence online, mostly without their knowledge.  This served me quite well in law enforcement and now serves me well in private investigations. But taking that training a step further into the findings of a digital forensic examination, we can incorporate that training and experience to dig even deeper to find out what the user(s) may be doing online.



As an example, we'll use the current “flagship” of social media, Facebook.  Facebook has revolutionized how people stay in touch and they are constantly evolving the offerings they put forth.  What was once an online yearbook for college students has now become a multi-billion dollar mega online conglomerate of services.  Over time, users have gained the ability to search for other users, chat with other users, send links, videos, pictures and now even voice messages.  And the best part is, most or all of this data is available to us when we get ahold of your computer and/or mobile device.  Because Facebook is so ubiquitous across the user spectrum, almost everyone has an account, which means there's social media evidence almost everywhere.

And the great thing about social media is, it's tailor-made for us by us.  We choose who we want to be "friends" with.  We decide who to communicate with and for what purpose(s).  We seek out and "follow" or "like" different social causes, businesses, political candidates, entertainers... the number and scope of what we can tell the social media world about ourselves is virtually boundless.  Most social media users don't give much thought to the fact that they are sacrificing personal information security when they follow these things, too.

So when we conduct a digital forensic investigation, we’re looking for clues about all of these things.  If the case involves a subject suspected of infidelity, perhaps they were using Facebook messenger to send messages to their paramour instead of regular text or email.  And even if they were somewhat clever and never became "friends" with the other party on Facebook, the account information for the other user is recoverable and will lead right back to that person almost instantly.  In the case of a law enforcement agent investigating someone suspected of having terrorist ties, perhaps they "liked" or followed anarchist, hate or radical religious groups.  With tools that specialize in extracting and reporting this information like Magnet Forensics Internet Evidence Finder, the forensic evidence in these cases becomes vital to painting the picture of the truth.  The best thing for us in the digital age is, if there's any digital evidence of it, we'll probably find it.



And while Facebook is a good example, the potential for valuable evidence doesn't end there.  Twitter, Tindr, Snap Chat, Linked In... they all provide valuable pieces of information by way of personal and/or professional interests, potential romantic relationships, life events and random online rants (which happen more often than you might think).  One final point that should not be overlooked is the responsibility of the investigator and/or examiner to stay abreast of the changes in social media.  Like with most things in the digital age, social media is ever-changing.  It’s a competitive market and their challenge is to gain new users while still maintaining a certain level of service and user expectation, lest they become MySpace.  But the investigators and forensic examiners have to stay up with these changes to be able to consistently deliver quality service.  Is it time-consuming?  You bet!  But it’s also extremely important to successful, accurate investigations.

Regardless of the platform, social media really does intertwine into all of our lives.  Because of that, it becomes a virtual mountain of valuable personal information that a digital forensic examiner and investigator can use to help find the truth.  Now go search for it!


Author:
Patrick J. Siewert, SCERS, BCERT, LCE
Principal Consultant
Professional Digital Forensic Consulting, LLC
Based in Richmond, Virginia
Available Globally

About the Author:
Patrick Siewert is the Principal Consultant of Pro Digital Forensic Consulting, based in Richmond, Virginia.  In 15 years of law enforcement, he investigated hundreds of high-tech crimes, incorporating digital forensics into the investigations, and was responsible for investigating some of the highest jury and plea bargain child exploitation cases in Virginia court history.  A graduate of both SCERS and BCERT (among others), Siewert continues to hone his digital forensic expertise in the private sector while growing his consulting business marketed toward litigators, professional investigators and corporations.
Twitter: @ProDigital4n6