Don't throw away your old iPhone until you read this post (and after that too)

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Don’t throw away your old iPhone until you read this post (and after, too) 🚮
Recently, our expert Vitaly, who investigates incidents involving mobile devices, received an iPhone 5s for analysis, with the familiar text displayed on its screen: “iPhone is disabled. Connect to iTunes.” This meant that after 10 incorrect password attempts, the device had locked itself. It would seem that all data was lost, but Vitaly had an idea for how it could be extracted 💡
🔑 Using checkm8
To access the data, he decided to use a hardware vulnerability in the iPhone that is present in A5–A11 processors. The checkm8 exploit allows loading a mobile device in BFU mode (before first unlock) and extracting data from it.
💰 What data was extracted
Using Elcomsoft iOS Forensic Toolkit and UFED 4PC, he extracted data from the device’s keychain and file system.
During analysis, the expert discovered:
• Device artifacts: model, iOS version, serial number, IMEI.
• User data: phone number, information about SIM cards, accounts, favorite and blocked contacts, etc.
• Network connection parameters: list of previously connected Wi-Fi networks, Bluetooth devices, and their MAC addresses.
• Application artifacts: data from unencrypted databases and the cache of certain applications.
🎆 Conclusion
This experiment showed that even locked iPhones store valuable information that can be extracted with the right tools and knowledge. This once again confirms the importance of reliable encryption and timely deletion of confidential data before selling a device.
You can read the full text of the study in the article on SecurityLab.
#dfir #mobile #ios
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



