Advertisement
unhappyghost

‪#‎Mobile‬ ‪#‎Forensic‬ Tools

Jul 25th, 2013
1,099
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.71 KB | None | 0 0
  1. ‪#‎Mobile‬ ‪#‎Forensic‬ Tools
  2. -------------------------------
  3.  
  4. ‪#‎BitPIM‬
  5. -----------
  6. BitPim is a free, open source, cross-platform program for viewing and editing data on a CDMA cell phone. Roger Binns was the founder, project manager, and lead developer of the project, first releasing it on March 1st, 2003. Since then leadership has been handed over to another party and over two million users have downloaded it. ‪#‎UnhappyGhost‬
  7. The program has been developed in python and originally only supported the LG VX4400 but it now supports a variety of phone manufactures including Audiovox, Kyocera, LG, Motorola, Nokia, Palm, Samsung, Sanyo, and Toshiba. In order to use the program, a data cable and it's drivers, usually available from the supplier/manufacturer, are required. BitPim will try and automatically detect a phone but its recommended that settings are manually configured. ‪#‎GeekSchool‬ ‪#‎GeekSch00l‬
  8.  
  9. - Features : The program can examine the phonebook, calendar, media (e.g. sounds, ringers, images), memos, todo lists, SMS messages, call history, play lists, and raw filesystem from devices. http :// www. facebook .com/geeksch00l
  10.  
  11. Features are dependent on the phone model. For a full list of each phones supported features see BitPim's supported phones list. The data can be manipulated through the software and changes can be uploaded to the phone. Calendar, Phonebook, Memo, Todo, and Playlist data can all be imported from an external file. For backup purposes all of the data can be exported to external files.
  12.  
  13. - Forensics - If doing a forensic investigation the application should always be in read only mode, which claims to block all write commands to the phone. The program will not recover deleted data nor does it always recover all undeleted data. http :// www. facebook .com/geeksch00l The file system view is a very important feature forensically as it allows a raw view of data from the phone, possibly uncovering data that BitPim missed or found unimportant. An advanced feature that could also be vital to a forensic investigation is BitFling. This feature allows another computer to remotely access a phones data over the internet. A phone could be confiscated in California, connected to BitPim with BitFling configured, and be forensically analyzed in New York. Lastly exporting the data is very important so that copies of the data can be made, ensuring no data is lost or manipulated.
  14.  
  15. - Compatability - BitPIM runs on Windows, Linux, and MacOS.
  16.  
  17. Official site : http:// www .bitpim .org/
  18.  
  19. for more posts visit : http :// goo .gl/O0omO
  20.  
  21. ‪#‎Cellebrite‬ ‪#‎UFED‬
  22. ------------------------
  23. The Cellebrite 'Universal Forensic Extraction Device' (UFED) is a tool for mobile phone, smartphone, and PDA forensics. As of September 2010 the UFED was compatible with over 2,500 mobile phones (including ‪#‎GSM‬, ‪#‎TDMA‬, ‪#‎CDMA‬, ‪#‎iDEN‬). The standard package containing several dozen phone cables. http :// www. facebook .com/geeksch00l The UFED had an intergrated SIM reader, with Wireless connection options also being integrated, such as IR and Bluetooth.
  24.  
  25. The UFED also supports native Apple ‪#‎iPOD‬ Touch, and Apple ‪#‎iPHONE‬ extraction on both 2G and 3G versions, as well as ‪#‎iOS4‬. This is clientless, and via a physical cable, and works on ‪#‎jailbroken‬ and non-jailbroken devices. Subject data can be retrieved via logical extraction or via physical extraction (ie: hex dump). http :// www. facebook .com/geeksch00l Moreover, all cable connectors from subject (source) side act as a write-blocker, being read only via the onboard hardware chipset. Extracted data includes basic handset data, the ‪#‎phonebook‬, ‪#‎SMS‬ and ‪#‎MMS‬ messages, SIM data, multimedia (e.g. images and videos stored on the phone), and time and date stamps.
  26.  
  27. Official site : http: //www .cellebrite .com/UFED-Standard-Kit.html
  28.  
  29. for more posts visit : http :// goo .gl/O0omO
  30.  
  31. ‪#‎MOBILedit‬!
  32. -----------------
  33. MOBILedit! is an application that provides an interface between a cell phone and a personal computer. It is designed to help improve productivity and communication by allowing input using the computer to be downloaded into the phone. It it used to send photos, SMS messages, documents, and other important data to and from a cell phone. http :// www. facebook .com/geeksch00l
  34.  
  35. MOBILedit! Lite is designed for the casual user, while MOBILedit! Forensics is designed to help aid in forensic investigations. MOBILedit! Liteis available as an evaluation version and can be purchased at MOBILedit's website. It supports more makes and models than any other program of its type. It allows edits to anything from the time on the phone to the contacts in the phonebook, all from a computer. http :// www. facebook .com/geeksch00l It also can backup all the information on the phone to a computer in case you lose the phone. This makes for an easy way to get everything back onto the new phone. This application allows communication with phones via ‪#‎BlueTooth‬, ‪#‎Infrared‬, or cable, depending on the model of phone. The basic drivers for each phone are installed with the program. However, if another driver is needed, they can be downloaded from the website assuming the phone is supported.
  36.  
  37. Features
  38. --------------
  39. As a cell phone forensics software tool, MOBILedit! has the ability to:
  40. - send SMS messages and phone calls directly from a computer connected to a cell phone
  41. - monitor a cell phone's battery life, signal quality, and the current network operator
  42. - http :// www. facebook .com/geeksch00l
  43. - display everything on a phone to the screen of a computer, allowing easier use of the phone.
  44. - allow the user to control a phone from a personal computer.
  45. - synchronize e-mail onto a cell phone with ‪#‎Microsoft‬ ‪#‎Outlook‬
  46. - configure multiple devices to connect to MOBILedit!.
  47. - generate secure reports in any language
  48. - create specific templates for specific functions and insert gathered data into a template
  49.  
  50. All functions of the program are located on the main screen. It is also fully compatible with Microsoft Outlook, allowing the user to synchronize email onto his or her phone with Outlook. http :// www. facebook .com/geeksch00l Multiple devices can be configured to connect to MOBILedit!.
  51. MOBILedit! collects all the data from the mobile phone and generates an extensive report onto a PC that can be saved or printed. MOBILedit! Forensic allows for the customization of the output from the cell phone which makes the data completely adaptable to the needs of each judicial system. http :// www. facebook .com/geeksch00l MOBILedit! Forensic also has frequent updates and upgrades.
  52.  
  53. Report Generation
  54. -------------------------
  55. MOBILedit! Forensic has the ability to generate reports in any language. The ability to create specific templates for specific functions is also a function of MOBILedit!. These template files can be created in tools such as MS Word and many other text editors. MOBILedit! Forensic will read this template and insert all data gathered from the device. This means that there is no need to import or export stubs of data from SIM cards or phones. http :// www. facebook .com/geeksch00l
  56.  
  57. The reports that MOBILedit! Forensic generates are secure, as the final report document is created automatically. MOBILedit! Forensic is read-only, thereby preventing changes in the device, avoiding potentially damaging losses of evidence. http :// www. facebook .com/geeksch00l All items are also protected against later modifications by a hash code used in digital signatures. All blocks of data, such as the phonebook, are protected by the ‪#‎MD5‬ ‪#‎hash_algorithm‬. Each item has its own MD5 code to help quickly locate the possible place of modification. MOBILedit! also has the ability to generate reports from devices presently connected to the computer, as well as from phones that were connected in the past using a backup file.
  58.  
  59. Applications and Drivers
  60. ----------------------------
  61. MOBILedit! is designed with architecture similar to that of operating systems. The result is that you can add new applications and drivers, and in the same way that Windows or Linux resolves the complexity of computer hardware, MOBILedit! reconciles the differences between mobile phones. http :// www. facebook .com/geeksch00l MOBILedit! supports adding applications to enhance its functionality for future phones and new features. For example, if a phone supports MMS, one can add an MMS application to MOBILedit!; one can add the ability to edit, upload, or download pictures, control a camera and view movies. In addition to applications, drivers can also be added, which cover the differences between mobile phones at a low-level. Therefore, any mobile phone can be supported. The driver interface is open, ‪#‎COMPELSON‬ Labs offers the source codes of their drivers.
  62.  
  63. Official site : http: //www .mobiledit .com/
  64.  
  65. for more posts visit : http :// goo .gl/O0omO
  66. .
  67.  
  68. ##############################################################
  69. # ṲИℋÅℙℙУḠ♓☮$✝ #
  70. ##############################################################
  71. || Website --------> http://unhappyghost.com/ ||
  72. || Facebook -------> https://www.facebook.com/unhappygh0st ||
  73. || FB Page --------> https://www.facebook.com/geeksch00l ||
  74. || Twitter --------> https://twitter.com/unhappygh0st ||
  75. || Google+ --------> http://goo.gl/WCHeJR ||
  76. || Youtube --------> http://goo.gl/A3mQIE ||
  77. || IPv6 Vids ------> http://goo.gl/Rbcxk ||
  78. || IPv6 Event -----> http://goo.gl/TaeXv ||
  79. ##############################################################
  80.  
  81. .
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement