Welcome!

.NET Authors: Lori MacVittie, Yeshim Deniz, Ivan Antsipau, Liz McMillan, Michael Bushong

News Feed Item

ElcomSoft Gives iOS Forensics a Boost, Adds Physical Acquisition Support for iOS 7 Devices

MOSCOW, January 30, 2014 /PRNewswire/ --

ElcomSoft Co. Ltd. updates  iOS Forensic Toolkit, adding physical acquisition support for jailbroken iOS 7 devices. Physical acquisition support is now available for jailbroken devices running Apple iOS 7 including iPhone 4S, 5 and 5C, iPad 2nd to 4th gen, iPad Mini, iPod Touch 5th gen, and either having no passcode protection or carrying a jailbreak installed. In addition, the new release adds support for previously unavailable versions of iOS 6.1.3-6.1.5.

With more than 83% of all iOS devices now running iOS 7, ElcomSoft gives the mobile forensic industry a boost. Elcomsoft iOS Forensic Toolkit is still remaining the only commercially available forensic product that is able to perform physical acquisition of iPhone 4S, iPad 2 and newer generation hardware.

Physical acquisition allows extracting information from Apple's protected storage, the keychain. In many cases, the enhanced iOS 7 keychain contains the original passwords to Apple ID accounts. This allows investigators seamlessly accessing information stored in the iCloud as well as tracking the users' geolocation coordinates in real-time by using the Apple iCloud Find My Phone service.

At this time, physical acquisition of last-generation iOS 7 devices is only possible if either of the following is true:

  • There is no passcode protection on the device, or
  • The investigator knows the passcode, or
  • The device has been jailbroken by the user

"Apple users are fast when it comes to upgrades," says Vladimir Katalov, ElcomSoft CEO. "The latest version of iOS, iOS 7, is already installed on some 83 per cent of compatible devices. We are proud to be the first to make a tool for our customers that gives them access to valuable information stored in these devices."

Background

At this time, 8 models of iPhone, 7 models of iPad and 5 generations of iPod Touch are available. With more than 700 million iOS devices around and 83% of them using iOS 7, the updated iOS Forensic Toolkit opens the door to acquiring information from some 580 million devices.

iOS 7 Physical Acquisition

Physical acquisition has long been the method of choice for accessing information stored in iOS devices among law enforcement and forensic customers. Physical acquisition allows investigators obtain the complete bit-precise image of the device in real time, including device secrets and unallocated data blocks that may contain deleted files and destroyed evidence. Physical acquisition returns significantly more information from the device than any other method such as logical acquisition or backup analysis, including data stored in Apple's protected storage, the keychain.

Finally, physical acquisition operates on a fixed-timeframe basis, which guarantees timely delivery of the entire contents of the device. Acquisition time depends on the model of the device being acquired, as well as on the amount of memory carried by that device. For example, acquisition time for a 32-GB iPhone 5 device is 25 minutes, while a 32-GB iPhone 4 with a slower controller is acquired in approximately 40 minutes.

With the release of iPhone 4S featuring stronger security, physical acquisition became impossible to all but ElcomSoft customers. Elcomsoft iOS Forensic Toolkit has been the first and remains the only commercially available product that can perform physical acquisition of last-generation Apple hardware running the latest versions of iOS up to and including iOS 7.

On jailbroken iOS 7 devices, iOS Forensic Toolkit can break the original passcode with brute force or dictionary attack. Passcode recovery speed on jailbroken iPhone 5 and 5C devices is approximately 15.5 passcodes per second, allowing iOS Forensic Toolkit to break typical 4-digit passcodes in about 10 minutes.

Physical Acquisition Benefits

Physical acquisition offers numerous benefits over other acquisition methods. Fixed timeframe and guaranteed delivery are just a few things to mention. Physical is the only acquisition method that can extract the following information:

  1. Cached (downloaded) mail, regardless of the type of email account. Cached mail is not available in offline or online backups.
  2. Geolocation data. While iTunes and iCloud backups contain only some very basic geolocation data, physical acquisition extracts comprehensive information including frequent locations and geolocation data requested by all Apple and third-party applications and system services. Geolocation information is requested (and stored) on many events such as using maps, calibrating the compass, for the purpose of tracking advertisements, when looking for mobile and Wi-Fi networks, etc. As a result, comprehensive geolocation data extracted with physical acquisition makes it possible to create a precise reconstruction of the phone owner's whereabouts for every minute of time.
  3. System logs and crash logs, detailing which applications were launched or installed.
  4. Cached application data, such as cached Web pages and addresses, and many other types of data are only available via physical acquisition. Considering that many iOS applications are using Internet access, the amount of cached data available via physical acquisition can be overwhelming.

Extended Keychain Acquisition

iOS 7 introduced some changes to the format and content of Apple's protected storage, the keychain. In iOS 7 devices, a device registered to a certain Apple ID may contain a cached copy of the iCloud keychain for that Apple account, depending on whether or not the user authorized this feature. If present, this data opens a whole new perspective to forensic specialists, enabling instant access to stored passwords and credit card information stored in other Apple devices on the same Apple ID.

iCloud Access as a Bonus

iOS 7 keeps more information in the keychain than any previous version of iOS. As a result, investigators performing physical acquisition may be able to receive, among other things, the online credentials required to log in to Apple iCloud (subject to certain conditions). If present, this information enables forensic specialists to download information Apple iCloud, acquiring online backups to all iOS devices registered on the same account. A separately available product, Elcomsoft Phone Password Breaker, is required to download information from the iCloud. In addition, by using Find My Phone service from Apple iCloud investigators can track geographic location of iOS devices on that account in real time.

Compatibility

Windows and Mac OS X versions of Elcomsoft iOS Forensic Toolkit are available. Physical acquisition support for the various iOS devices varies depending on lock state, jailbreak state and the version of iOS installed.

The tool can perform physical acquisition of the following iOS devices regardless of lock and jailbreak state, and regardless of iOS version:

  • Legacy iPhone models up to and including iPhone 4, all GSM & CDMA models supported
  • The original iPad
  • iPod Touch generations 1 through 4

Physical acquisition can be performed for the following models if they are running iOS 5, all versions of iOS 6, or iOS 7 and are jailbroken, or if jailbreak code can be installed by the investigator:

  • iPhone 4S, 5 and 5C
  • iPad 2, 3 and 4
  • iPad Mini
  • iPod Touch 4th and 5th gen

Support for iPhone 5S, iPad Air and iPad Mini with Retina is under development.

For non-jailbroken iOS 7 devices with unknown passcode physical acquisition support is currently unavailable.

About Elcomsoft iOS Forensic Toolkit

Elcomsoft iOS Forensic Toolkit provides forensic access to encrypted information stored in popular Apple devices running iOS versions 3 to 7. By performing a physical acquisition analysis of the device itself, the Toolkit offers instant access to all protected information including SMS and email messages, call history, contacts and organizer data, Web browsing history, voicemail and email accounts and settings, stored logins and passwords, geolocation history, the original plain-text iTunes password and conversations carried over various social networks such as Facebook, as well as all application-specific data saved in the device. The tool can also perform logical acquisition of iOS devices, or provide forensic access to encrypted iOS file system dumps.

About ElcomSoft Co. Ltd.

Founded in 1990, ElcomSoft Co.Ltd. is a global industry-acknowledged expert in computer and mobile forensics providing tools, training, and consulting services to law enforcement, forensics, financial and intelligence agencies. ElcomSoft pioneered and patented numerous cryptography techniques, setting and exceeding expectations by consistently breaking the industry's performance records. ElcomSoft is Microsoft Gold Independent Software Vendor, Intel Software Premier Elite Partner, member of Russian Cryptology Association (RCA) and Computer Security Institute.

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
Software AG helps organizations transform into Digital Enterprises, so they can differentiate from competitors and better engage customers, partners and employees. Using the Software AG Suite, companies can close the gap between business and IT to create digital systems of differentiation that drive front-line agility. We offer four on-ramps to the Digital Enterprise: alignment through collaborative process analysis; transformation through portfolio management; agility through process automation and integration; and visibility through intelligent business operations and big data.
There will be 50 billion Internet connected devices by 2020. Today, every manufacturer has a propriety protocol and an app. How do we securely integrate these "things" into our lives and businesses in a way that we can easily control and manage? Even better, how do we integrate these "things" so that they control and manage each other so our lives become more convenient or our businesses become more profitable and/or safe? We have heard that the best interface is no interface. In his session at Internet of @ThingsExpo, Chris Matthieu, Co-Founder & CTO at Octoblu, Inc., will discuss how these devices generate enough data to learn our behaviors and simplify/improve our lives. What if we could connect everything to everything? I'm not only talking about connecting things to things but also systems, cloud services, and people. Add in a little machine learning and artificial intelligence and now we have something interesting...
Last week, while in San Francisco, I used the Uber app and service four times. All four experiences were great, although one of the drivers stopped for 30 seconds and then left as I was walking up to the car. He must have realized I was a blogger. None the less, the next car was just a minute away and I suffered no pain. In this article, my colleague, Ved Sen, Global Head, Advisory Services Social, Mobile and Sensors at Cognizant shares his experiences and insights.
We are reaching the end of the beginning with WebRTC and real systems using this technology have begun to appear. One challenge that faces every WebRTC deployment (in some form or another) is identity management. For example, if you have an existing service – possibly built on a variety of different PaaS/SaaS offerings – and you want to add real-time communications you are faced with a challenge relating to user management, authentication, authorization, and validation. Service providers will want to use their existing identities, but these will have credentials already that are (hopefully) irreversibly encoded. In his session at Internet of @ThingsExpo, Peter Dunkley, Technical Director at Acision, will look at how this identity problem can be solved and discuss ways to use existing web identities for real-time communication.
Can call centers hang up the phones for good? Intuitive Solutions did. WebRTC enabled this contact center provider to eliminate antiquated telephony and desktop phone infrastructure with a pure web-based solution, allowing them to expand beyond brick-and-mortar confines to a home-based agent model. It also ensured scalability and better service for customers, including MUY! Companies, one of the country's largest franchise restaurant companies with 232 Pizza Hut locations. This is one example of WebRTC adoption today, but the potential is limitless when powered by IoT. Attendees will learn real-world benefits of WebRTC and explore future possibilities, as WebRTC and IoT intersect to improve customer service.
From telemedicine to smart cars, digital homes and industrial monitoring, the explosive growth of IoT has created exciting new business opportunities for real time calls and messaging. In his session at Internet of @ThingsExpo, Ivelin Ivanov, CEO and Co-Founder of Telestax, will share some of the new revenue sources that IoT created for Restcomm – the open source telephony platform from Telestax. Ivelin Ivanov is a technology entrepreneur who founded Mobicents, an Open Source VoIP Platform, to help create, deploy, and manage applications integrating voice, video and data. He is the co-founder of TeleStax, an Open Source Cloud Communications company that helps the shift from legacy IN/SS7 telco networks to IP-based cloud comms. An early investor in multiple start-ups, he still finds time to code for his companies and contribute to open source projects.
The Internet of Things (IoT) promises to create new business models as significant as those that were inspired by the Internet and the smartphone 20 and 10 years ago. What business, social and practical implications will this phenomenon bring? That's the subject of "Monetizing the Internet of Things: Perspectives from the Front Lines," an e-book released today and available free of charge from Aria Systems, the leading innovator in recurring revenue management.
The Internet of Things will put IT to its ultimate test by creating infinite new opportunities to digitize products and services, generate and analyze new data to improve customer satisfaction, and discover new ways to gain a competitive advantage across nearly every industry. In order to help corporate business units to capitalize on the rapidly evolving IoT opportunities, IT must stand up to a new set of challenges.
There’s Big Data, then there’s really Big Data from the Internet of Things. IoT is evolving to include many data possibilities like new types of event, log and network data. The volumes are enormous, generating tens of billions of logs per day, which raise data challenges. Early IoT deployments are relying heavily on both the cloud and managed service providers to navigate these challenges. In her session at 6th Big Data Expo®, Hannah Smalltree, Director at Treasure Data, to discuss how IoT, Big Data and deployments are processing massive data volumes from wearables, utilities and other machines.
All major researchers estimate there will be tens of billions devices – computers, smartphones, tablets, and sensors – connected to the Internet by 2020. This number will continue to grow at a rapid pace for the next several decades. With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo in Silicon Valley. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be!
P2P RTC will impact the landscape of communications, shifting from traditional telephony style communications models to OTT (Over-The-Top) cloud assisted & PaaS (Platform as a Service) communication services. The P2P shift will impact many areas of our lives, from mobile communication, human interactive web services, RTC and telephony infrastructure, user federation, security and privacy implications, business costs, and scalability. In his session at Internet of @ThingsExpo, Erik Lagerway, Co-founder of Hookflash, will walk through the shifting landscape of traditional telephone and voice services to the modern P2P RTC era of OTT cloud assisted services.
While great strides have been made relative to the video aspects of remote collaboration, audio technology has basically stagnated. Typically all audio is mixed to a single monaural stream and emanates from a single point, such as a speakerphone or a speaker associated with a video monitor. This leads to confusion and lack of understanding among participants especially regarding who is actually speaking. Spatial teleconferencing introduces the concept of acoustic spatial separation between conference participants in three dimensional space. This has been shown to significantly improve comprehension and conference efficiency.
The Internet of Things is tied together with a thin strand that is known as time. Coincidentally, at the core of nearly all data analytics is a timestamp. When working with time series data there are a few core principles that everyone should consider, especially across datasets where time is the common boundary. In his session at Internet of @ThingsExpo, Jim Scott, Director of Enterprise Strategy & Architecture at MapR Technologies, will discuss single-value, geo-spatial, and log time series data. By focusing on enterprise applications and the data center, he will use OpenTSDB as an example to explain some of these concepts including when to use different storage models.
SYS-CON Events announced today that Gridstore™, the leader in software-defined storage (SDS) purpose-built for Windows Servers and Hyper-V, will exhibit at SYS-CON's 15th International Cloud Expo®, which will take place on November 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA. Gridstore™ is the leader in software-defined storage purpose built for virtualization that is designed to accelerate applications in virtualized environments. Using its patented Server-Side Virtual Controller™ Technology (SVCT) to eliminate the I/O blender effect and accelerate applications Gridstore delivers vmOptimized™ Storage that self-optimizes to each application or VM across both virtual and physical environments. Leveraging a grid architecture, Gridstore delivers the first end-to-end storage QoS to ensure the most important App or VM performance is never compromised. The storage grid, that uses Gridstore’s performance optimized nodes or capacity optimized nodes, starts with as few a...
The Transparent Cloud-computing Consortium (abbreviation: T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data processing High speed and high quality networks, and dramatic improvements in computer processing capabilities, have greatly changed the nature of applications and made the storing and processing of data on the network commonplace. These technological reforms have not only changed computers and smartphones, but are also changing the data processing model for all information devices. In particular, in the area known as M2M (Machine-To-Machine), there are great expectations that information with a new type of value can be produced using a variety of devices and sensors saving/sharing data via the network and through large-scale cloud-type data processing. This consortium believes that attaching a huge number of devic...
Innodisk is a service-driven provider of industrial embedded flash and DRAM storage products and technologies, with a focus on the enterprise, industrial, aerospace, and defense industries. Innodisk is dedicated to serving their customers and business partners. Quality is vitally important when it comes to industrial embedded flash and DRAM storage products. That’s why Innodisk manufactures all of their products in their own purpose-built memory production facility. In fact, they designed and built their production center to maximize manufacturing efficiency and guarantee the highest quality of our products.
All major researchers estimate there will be tens of billions devices - computers, smartphones, tablets, and sensors - connected to the Internet by 2020. This number will continue to grow at a rapid pace for the next several decades. Over the summer Gartner released its much anticipated annual Hype Cycle report and the big news is that Internet of Things has now replaced Big Data as the most hyped technology. Indeed, we're hearing more and more about this fascinating new technological paradigm. Every other IT news item seems to be about IoT and its implications on the future of digital business.
Can call centers hang up the phones for good? Intuitive Solutions did. WebRTC enabled this contact center provider to eliminate antiquated telephony and desktop phone infrastructure with a pure web-based solution, allowing them to expand beyond brick-and-mortar confines to a home-based agent model. Download Slide Deck: ▸ Here
BSQUARE is a global leader of embedded software solutions. We enable smart connected systems at the device level and beyond that millions use every day and provide actionable data solutions for the growing Internet of Things (IoT) market. We empower our world-class customers with our products, services and solutions to achieve innovation and success. For more information, visit www.bsquare.com.
With the iCloud scandal seemingly in its past, Apple announced new iPhones, updates to iPad and MacBook as well as news on OSX Yosemite. Although consumers will have to wait to get their hands on some of that new stuff, what they can get is the latest release of iOS 8 that Apple made available for most in-market iPhones and iPads. Originally announced at WWDC (Apple’s annual developers conference) in June, iOS 8 seems to spearhead Apple’s newfound focus upon greater integration of their products into everyday tasks, cross-platform mobility and self-monitoring. Before you update your device, here is a look at some of the new features and things you may want to consider from a mobile security perspective.