Using Screen Time Password to Protect iPhone Local Backups
Elcomsoft Blog » Jailbreak
by Oleg Afonin
1y ago
The iOS backup system is truly unrivalled. The highly comprehensive, versatile and secure backups can be created with Apple iTunes. For the user, local backups are a convenient and easy way to transfer data to a new device or restore an existing one after a factory reset. For forensic experts, iOS backups are an equally convenient, versatile and easy way to obtain a copy of the user’s data without attempting to break into the device. In malicious hands, the backup becomes a dangerous weapon. Logins and passwords from the Keychain allow hackers accessing the user’s social accounts, messages ..read more
Visit website
Five Hundred Posts
Elcomsoft Blog » Jailbreak
by Vladimir Katalov
1y ago
Believe me or not, but this is exactly the 500th post in our blog! The first one was posted in March 2009 and was about Distributed Password Recovery and GPU acceleration. At that time, we even did not do mobile or cloud forensics. Today it’s not about our achievements. I want to thank you for being with us, and share a few bits and pieces about our blog that you may find handy or at least amusing. We started our blog more than ten years ago. We never planned to be a pure marketing instrument. Instead, we tried our best to serve our readers with information that is rarely published and never ..read more
Visit website
The Evolution of iOS Acquisition: Jailbreaks, Exploits and Extraction Agent
Elcomsoft Blog » Jailbreak
by Oleg Afonin
1y ago
The past two years have become a turning point in iOS acquisition. The release of a bootrom-based exploit and the corresponding jailbreak made BFU acquisition possible on multiple devices regardless of security patches. Another exploit covers the entire iOS 13 range on all devices regardless of their hardware revision. ElcomSoft developed a jailbreak-free extraction method for the entire iOS 9.0-13.7 range. Let’s see what low-level acquisition options are available today, and when to use what. The bootrom exploit checkm8 (“checkmate”) is a permanent, unpatchable bootrom exploit for a wide ra ..read more
Visit website
Jailbreaking Apple TV 4K
Elcomsoft Blog » Jailbreak
by Vladimir Katalov
1y ago
Is jailbreaking an Apple TV worth it? If you are working in the forensics, it definitely is. When connected to the user’s Apple account with full iCloud access, the Apple TV synchronizes a lot of data. That data may contain important evidence, and sometimes may even help access other iCloud data. I have some great news for the forensic crowd: the Apple TV does not have a passcode. And some bad news: jailbreaking is not as easy and straightforward as we’d like it to be. Let’s have a look at what can be done. Introduction We have already covered the Apple TV acquisition topic before (see Apple ..read more
Visit website
Mobile Forensics: Are You Ready for iOS 14?
Elcomsoft Blog » Jailbreak
by Vladimir Katalov
1y ago
The number of iOS 14 users is on the raise, and we will see it running on most Apple devices pretty soon. Apple had already stopped signing the last version of iOS 13 on all but legacy hardware. Soon, we will only see it running on the iPhone 5s and iPhone 6 which didn’t get the update, and on a small fraction of newer devices. If you are working in the forensic field, what do you need to do to make yourself ready for iOS 14? Our software may help. Speaking of iOS 14 itself, it does not bring much new that could be useful for forensic investigators. We’ve covered some of the changes in iOS 1 ..read more
Visit website
IOS, watchOS and tvOS Acquisition Methods Compared: Compatibility Notes
Elcomsoft Blog » Jailbreak
by Vladimir Katalov
1y ago
How can you obtain the highest amount of data from an iPhone, iPad, Apple TV or Apple Watch? This is not as simple as it may seem. Multiple overlapping extraction methods exist, and some of them are limited to specific versions of the OS. Let’s go through them and summarize their availability and benefits. Compatibility We did our best to compile the compatibility information into a single table. Sorry, the iPads are missing from the table; however, the compatibility is normally dependent on the version of iOS/iPadOS (that are in sync) and the SoC model. Note: FFS stands for “full file syste ..read more
Visit website
IOS Extraction Without a Jailbreak: Full iOS 10 Support
Elcomsoft Blog » Jailbreak
by Oleg Afonin
1y ago
Originally released in September 2016, iOS 10 was regularly updated for most devices until July 2017. The 64-bit iPhones capable of running iOS 10 range from the iPhone 5s to iPhone 7 and 7 Plus. While one is hardly likely to encounter an iOS 10 in the wild, forensic labs still process devices running the older version of the OS. In this update, we’ve brought support for jailbreak-free extraction back to the roots, adding support for the oldest version of iOS capable of running on the iPhone 7 generation of devices. Let’s see what it takes to extract an older iPhone without a jailbreak. In a ..read more
Visit website
Checkra1n & unc0ver: How Would You Like to Jailbreak Today?
Elcomsoft Blog » Jailbreak
by Vladimir Katalov
1y ago
Extracting the fullest amount of information from the iPhone, which includes a file system image and decrypted keychain records, often requires installing a jailbreak. Even though forensically sound acquisition methods that work without jailbreaking do exist, they may not be available depending on the tools you use. A particular combination of iOS hardware and software may also render those tools ineffective, requiring a fallback to jailbreak. Today, the two most popular and most reliable jailbreaks are checkra1n and unc0ver. How do they fare against each other, and when would you want to us ..read more
Visit website
Full File System Extraction for iOS 13.3.1, 13.4 and 13.4.1
Elcomsoft Blog » Jailbreak
by Vladimir Katalov
1y ago
Elcomsoft iOS Forensic Toolkit 6.0 is out, adding direct, forensically sound extraction for Apple devices running some of the latest versions of iOS including iOS 13.3.1, 13.4 and 13.4.1. Supported devices include the entire iPhone 6s, 7, 8, X, Xr/Xs, 11, and 11 Pro (including Plus and Max versions) range, the iPhone SE, and corresponding iPad models. Let’s review the changes and talk about the new acquisition method in general. Agent-based extraction: the technology For a long time, we relied on publicly available jailbreaks to perform full file system and keychain acquisition. That is not ..read more
Visit website

Follow Elcomsoft Blog » Jailbreak on FeedSpot

Continue with Google
Continue with Apple
OR