Showing posts from 2019

Checkra1n Era - Ep 5 - Automating extraction and processing (aka "Merry Xmas!")

After my third post on  how to automate an extraction BFU , my great friend, colleague and fellow citizen Giovanni 'sug4r' Rattaro , Tsurugi Linux team leader and core developer, wrote me a message saying: " Belin Mattia! You had a great idea! But we can quickly improve your script!" And I answered: "Yes, why not. How is it going for you in the next couple of weeks? Do you have time?". And Giovanni: "No, I have to deliver the newest version of Tsurugi before Christmas. But still, we can do it!". And I said: "I am also very busy. But yes, we can do it!". Starting from my original idea, we completely redesigned and organized the script, both in terms of "user interface" (thanks Giovanni for the idea of using ncurses menu!) and functions. Still, our script is a PoC and must be used just for testing, studying, developing and learning purposes . It is not meant to be a "forensic tool", but we decided in any case to c

Checkra1n Era - Ep 4 - Analyzing extractions "Before First Unlock"

I spent the last couple of weeks investigating iOS 13 acquisitions "Before First Unlock". I want to start this blog post with an important point: USB Restricted Mode . Since iOS 11.4.1, Apple introduced a new security measure called "USB Restricted Mode" that, basically, disables USB data connection under certain conditions. The effects of USB Restricted Mode on an iOS device and possible ways to overcome it in a non-jailbroken device were intensively discussed on various blogs. Some references on this topic are: iOS 11.4 to Disable USB Port After 7 Days: What It Means for Mobile Forensics on Elcomsoft Blog iOS 11.4.1 Beta: USB Restricted Mode Has Arrived  on Elcomsoft Blog This $39 Device Can Defeat iOS USB Restricted Mode  on Elcomsoft Blog iOS 11.4.1 Second Beta Extends USB Restricted Mode with Manual Activation  on Elcomsoft Blog USB Restricted Mode Inside Out  on Elcomsoft Blog iOS 12 Enhances USB Restricted Mode  on Elcomsoft Blog iOS 11.4.1 F