Documente Academic
Documente Profesional
Documente Cultură
Android Forensics
Manish Chasta, CISSP | CHFI
Agenda
Introduction to Android
Rooting Android Seizing Android Device
Introduction to Android
Most widely used mobile OS Developed by Google OS + Middleware + Applications Android Open Source Project (AOSP) is responsible for maintenance and further development
Android Architecture
Dalvik VM:
Java based VM, a lightweight substitute to JVM Unlike JVM, DVM is a register based Virtual Machine DVM is optimized to run on limited main memory and less CPU usage Java code (.class files) converted into .dex format to be able to run on Android platform
7
SQLite Database
SQLite Database:
SQLite is a widely used, lightweight database Used by most mobile OS i.e. iPhone, Android, Symbian, webOS SQLite is a free to use and open source database Zero-configuration - no setup or administration needed. A complete database is stored in a single crossplatform disk file.
8
10
12
13
14
15
16
17
18
19
20
21
23
24
Recovering Data
Using WinHex
25
Analysing Image
Reading the Image
Looking for KEY data Searching techniques (DT Search)
26
Analysing Image
Winhex Manual Intelligence viaExtract
27
Analyzing SQLite
SQLite stores most critical information Interesting place for Investigators Tools
Epilog sqlite database browser sqlite_analyzer
28
Analyzing SQLite
Epilog
29
Indian Laws:
IT Act 2000
IT(Amendment) Act, 2008 Rules under section 6A, 43A and 79
31
Manish Chasta
manish.chasta@owasp.org chasta.manish@gmail.com