[ << ALL_FEED ]

Don't throw away your old iPhone until you read this post (and after that too)

More in General

Don’t throw away your old iPhone until you read this post (and after, too) 🚮

Recently, our expert Vitaly, who investigates incidents involving mobile devices, received an iPhone 5s for analysis, with the familiar text displayed on its screen: “iPhone is disabled. Connect to iTunes.” This meant that after 10 incorrect password attempts, the device had locked itself. It would seem that all data was lost, but Vitaly had an idea for how it could be extracted 💡

🔑 Using checkm8

To access the data, he decided to use a hardware vulnerability in the iPhone that is present in A5–A11 processors. The checkm8 exploit allows loading a mobile device in BFU mode (before first unlock) and extracting data from it.

💰 What data was extracted

Using Elcomsoft iOS Forensic Toolkit and UFED 4PC, he extracted data from the device’s keychain and file system.

During analysis, the expert discovered:

• Device artifacts: model, iOS version, serial number, IMEI.

• User data: phone number, information about SIM cards, accounts, favorite and blocked contacts, etc.

• Network connection parameters: list of previously connected Wi-Fi networks, Bluetooth devices, and their MAC addresses.

• Application artifacts: data from unencrypted databases and the cache of certain applications.

🎆 Conclusion

This experiment showed that even locked iPhones store valuable information that can be extracted with the right tools and knowledge. This once again confirms the importance of reliable encryption and timely deletion of confidential data before selling a device.

You can read the full text of the study in the article on SecurityLab.

#dfir #mobile #ios
@ptescalator

More from oUth0R

More from oUth0R

More in General