Elcomsoft
547 subscribers
573 photos
1 video
1 file
458 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
iOS Forensic Toolkit 6.0: jailbreak-free extraction for iOS 11 through 13.4.1

Elcomsoft iOS Forensic Toolkit 6.0 offers direct, forensically sound extraction for Apple devices running all versions of iOS from iOS 11 through iOS 13.4.1 without a jailbreak. This release adds full file system extraction support for the latest iOS builds including iOS 13.3.1, 13.4, and 13.4.1 for the iPhone 6s, 7, 8, X, Xr/Xs, 11, and 11 Pro generation devices (including the corresponding Plus and Max versions), as well as latest iPhone SE.

👉 https://www.elcomsoft.com/news/747.html

📝 Release Notes (PDF)

#ios #iphone #mobileforensics #dfir #mobilesecurity #itsecurity #dataextraction
iOS Jailbreaks, SSH, and root Password

Modern jailbreaks, in addition to removing several iOS restrictions (for example, disabling signature verification, escalating privileges or bypassing the sandbox), allow obtaining low-level access to the device’s file system. This allows connecting to an iOS device via SSH and gaining almost unlimited access to the system. Some jailbreaks install an OpenSSH (or dropbear) server immediately as they are installed. If not, then SSH can be installed manually from the Cydia repository (OpenSSH package). In this article, I’ll discuss several issues related to SSH, including the following.

- How to understand if SSH is installed and working on the device?
- How to change the root password?
- How to reset the root password to its default value if one is unknown?

👉 https://blog.elcomsoft.com/2020/05/ios-jailbreaks-ssh-and-root-password/

#mobileforensics #ios #iphone #smartphone #jailbreak #password #ssh
Clearing Confusion About our Password Recovery Tools

There is a bit of confusion about our software designed to allow breaking into password-protected systems, files, documents, and encrypted containers. We have as many as three products (and five different tools) dealing with the matter: Elcomsoft Forensic Disk Decryptor (with an unnamed memory dumping tool), Elcomsoft System Recovery and Elcomsoft Distributed Password Recovery, which also includes Elcomsoft Hash Extractor as part of the package. Let’s briefly go through all of them. Hopefully it will help you select the right product for your needs and save time in your investigation.

👉 https://blog.elcomsoft.com/2020/05/clearing-confusion-about-our-password-recovery-tools/

By Oleg Afonin

#password #passwordrecovery #encryption #itsecurity #cybersecurity #dataaccess #dfir #difitalforensics
Full File System and Keychain Acquisition with unc0ver jailbreak: iOS 13.1 to 13.5

The unc0ver v5 jailbreak has been available for a while now. It supports the newest versions of iOS up to and including iOS 13.5, and this is fantastic news for DFIR community, as it allows extracting the full file system and the keychain when acquiring the newest latest iPhone models such as the iPhone 11 and 11 Pro, and SE 2020. In this article, I’ll talk about the unc0ver jailbreak, the installation and usage for the purpose of file system extraction, and discuss the differences between jailbreak-based and jailbreak-free extraction.

👉 https://blog.elcomsoft.com/2020/05/full-file-system-and-keychain-acquisition-with-unc0ver-jailbreak-ios-13-1-to-13-5/

By Vladimir Katalov

#uncover #ios #iphone #iOS135 #cybersecurity #itsecurity #mobileforensics
Forensic Disk Decryptor 2.12 and System Recovery 7.04 Display File System Data, Expand VeraCrypt Support

Elcomsoft releases two product updates. Forensic Disk Decryptor 2.12 can display file system data and adds VeraCrypt support for GPT partitions, while System Recovery 7.04 can discover plaintext passwords for cached domain credentials and also shows file system data.

👉 https://www.elcomsoft.com/news/748.html

#fde #veracrypt #encryption #truecrypt #desktopforensic #cybersecurity
checkra1n & unc0ver: How Would You Like to Jailbreak Today?

Extracting the fullest amount of information from the iPhone, which includes a file system image and decrypted keychain records, often requires installing a jailbreak. Even though forensically sound acquisition methods that work without jailbreaking do exist, they may not be available depending on the tools you use. A particular combination of iOS hardware and software may also render those tools ineffective, requiring a fallback to jailbreak. Today, the two most popular and most reliable jailbreaks are checkra1n and unc0ver. How do they fare against each other, and when would you want to use each?

👉 https://blog.elcomsoft.com/2020/06/checkra1n-unc0ver-jailbreak-today/

#checkra1n #unc0ver #jailbreak #smartphone #mobileforensics #iOS #iPhone
Researching Confide Messenger Encryption

iPhone users have access to literally hundreds of instant messaging apps. These apps range all the way from the built-in iMessage app to the highly secure Signal messengers, with all stops in between. Many of the messaging apps are marketed as ‘secure’ or ‘protected’ messengers, touting end-to-end encryption and zero retention policies. We routinely verify such claims by analyzing the security of various instant messaging apps. It turned out that the degree of protection can vary greatly, having little to do with the developers’ claims. Today we’ll check out Confide, a tool advertising unprecedented level of security.

👉 https://blog.elcomsoft.com/2020/06/researching-confide-messenger-encryption/

#confide #cybersec #mobileforensics #dfir #smartphone #iphone #messenger #datasecurity
Elcomsoft iOS Forensic Toolkit 6.10: jailbreaking all the way

Elcomsoft iOS Forensic Toolkit 6.10 delivers major improvements to jailbreak-based extraction, now offering keychain acquisition and file system extraction for iOS 13.5, 13.4.1, 13.4 and 13.3.1 with unc0ver v5, as well as keychain acquisition and file system extraction for iOS 13.5 and 13.5.1 with checkra1n. Jailbreak-based acquisition engine received a major overhaul, now offering greater than ever speed and stability.

👉 https://www.elcomsoft.com/news/749.html

#jailbreak #iphone #itsecurity #unc0ver #checkra1n #keychain #mobilesecurity #dfir #mobileforensics
Apple Two-Factor Authentication: SMS vs. Trusted Devices

Multi-factor authentication is the new reality. A password alone is no longer considered sufficient. Phishing attacks, frequent leaks of password databases and the ubiquitous issue of reusing passwords make password protection unsafe. Adding “something that you have” to “something that you know” improves the security considerably, having the potential of cutting a chain attack early even in worst case scenarios. However, not all types of two-factor authentication are equally secure.

Let’s talk about the most commonly used type of two-factor authentication: the one based on text messages (SMS) delivered to a trusted phone number.

👉 https://blog.elcomsoft.com/2020/06/apple-two-factor-authentication-sms-vs-trusted-devices/

#2fa #itsecurity #cybersecurity #authentication #clouds #mobilesecurity #smartphone
Demystifying iOS Data Security

Today, James Duffy, a security researcher and developer, is our guest in Elcomsoft Blog.

“Recently I’ve been sent over a few questions from members of the community, such as “Why can’t we decrypt the data from a disabled iPhone over SSH if we know the passcode?” and “I tried to SCP a file from the device to the Mac, but getting permission errors”. Today I’m going to answer these questions in a Q&A format for you all so hopefully we can shed some light on how this works! The article is aimed to be accessible for everybody, including beginners and non-technical users. Without further ado…”

👉 https://blog.elcomsoft.com/2020/06/demystifying-ios-data-security/

#ios #iphone #mobilesecurity #mobileforensics #cybersec #smartphone #encryption
iCloud Backups, Synced Data and End-to-End Encryption

Initially, iCloud backups were similar in content to local (iTunes) backups without the password. However, the introduction of iCloud sync has changed the rules of the game. With more types of data synchronized through iCloud as opposed to being backed up, the content of iCloud backups gets slimmed down as synchronized information is excluded from cloud backups, though still present in local backups.

Two-factor authentication (or lack thereof) affects what can and what cannot be synchronized. Sounds confusing? Let’s shed some light on the types of data that might be available in iCloud backups and how they are affected by the optional data sync.

👉 https://blog.elcomsoft.com/2020/06/icloud-backups-synced-data-and-end-to-end-encryption/

#ios #iphone #sync #backup #icloud #2fa #cloud
ElcomSoft Phone Breaker 9.60 and Elcomsoft Phone Viewer 5.10 streamline iCloud data analysis

Elcomsoft Phone Breaker 9.60 streamlines access to iCloud data, breaking down the 17 types of iCloud synced data, the content of iCloud Drive and iCloud backups, into three large groups. By accessing the categories via three distinct groups, experts will be able to save time by analyzing the available information faster.

👉 https://www.elcomsoft.com/news/750.html

#ios #iphone #cloud #mobilesecurity #mobileforensics #keychain #cybersecurity #itsecurity
iCloud Extraction Streamlined

Apple iCloud contains massive amounts of data, which may become highly valuable evidence. The oldest and most frequently mentioned are iCloud backups, which ElcomSoft were the first to extract back in 2012. A lot has changed since then. Today, iCloud backups account for a very minor part of the evidence available in iCloud. Learn what types of data are stored in iCloud, how Apple protects the data with end-to-end encryption, and how to access that valuable evidence with the updated Elcomsoft Phone Breaker.

👉 https://blog.elcomsoft.com/2020/06/icloud-extraction-streamlined/

#ios #iphone #sync #backup #icloud #2fa #cloud #dataextraction
Jailbreaking Apple TV 4K

Is jailbreaking an Apple TV worth it? If you are working in the forensics, it definitely is. When connected to the user’s Apple account with full iCloud access, the Apple TV synchronizes a lot of data. That data may contain important evidence, and sometimes may even help access other iCloud data. I have some great news for the forensic crowd: the Apple TV does not have a passcode. And some bad news: jailbreaking is not as easy and straightforward as we’d like it to be. Let’s have a look at what can be done.

The hidden Lightning port

Big surprise: the Apple TV 4K does have the port for wired connections, and the port is…

👉 https://blog.elcomsoft.com/2020/06/jailbreaking-apple-tv-4k/

#ios #appletv #checkra1n #jailbreak #iosforensics #dfir
iOS Forensic Toolkit 6.20: filling the gaps

Elcomsoft iOS Forensic Toolkit 6.20 fills the gaps for jailbreak-free extraction of previously unsupported versions of iOS. The new release expands the availability of the extraction agent all the way back to the original iOS 10.0, while adding compatibility for previously unsupported versions of iOS 12 on the iPhone 5s and 6.

👉 https://www.elcomsoft.com/news/751.html

📝 Get Release Notes in PDF

#eift #mobileforensics #dfir #keychain #filesystem #iphone #dataextraction #ios
iOS Extraction Without a Jailbreak: Full iOS 10 Support

One is hardly likely to encounter an iOS 10 in the wild, however forensic labs still process devices running the older version of the OS. In today's update of Elcomsoft iOS Forensic Toolkit, we’ve brought support for jailbreak-free extraction back to the roots, adding support for the oldest version of iOS capable of running on the iPhone 7 generation of devices.

Let’s see what it takes to extract an older iPhone without a jailbreak!

Keep reading: https://blog.elcomsoft.com/2020/06/ios-extraction-without-a-jailbreak-full-ios-10-support/

#ios10 #iphone7 #dfir #mobileforensics #datasecurity #infosec #extractionagent
iOS, watchOS and tvOS Acquisition Methods Compared: Compatibility Notes

How can you obtain the highest amount of data from an iPhone, iPad, Apple TV or Apple Watch? This is not as simple as it may seem. Multiple overlapping extraction methods exist, and some of them are limited to specific versions of the OS. Let’s go through them and summarize their availability and benefits.

👉 https://blog.elcomsoft.com/2020/06/ios-watchos-and-tvos-acquisition-methods-compared-compatibility-notes/

#iOS #tvOS #watchOS #mobilesecurity #dfir #mobileforensics #cloud #keychain #dataaccess
The Mysterious Apple DCSD Cable Demystified

A lot of people have asked me over the past couple of months – “What’s that cable on your desk, James?”. Today I’ll tell you all about it. Every accessory that connects to your iPhone via lightning is ‘flashed’ with an Accessory ID. The Accessory ID essentially identifies the device connected to the iPhone as a specific type. For example, a Lightning-To-Ethernet adapter will identify itself with it’s assigned Accessory ID so the iPhone knows how to treat the device and interact with it. It’s sort of like directing the iPhone to use a specific driver to interact with said device.

👉 https://blog.elcomsoft.com/2020/06/the-mysterious-apple-dcsd-cable-demystified/

#ios #iphone #mobileforensics #itsecurity #dcsd #cybersecurity
Unlocking BitLocker Volumes by Booting from a USB Drive

BitLocker is Windows default solution for encrypting disk volumes. A large number of organizations protect startup disks with BitLocker encryption. While adding the necessary layer of security, BitLocker also has the potential of locking administrative access to the encrypted volumes if the original Windows logon password is lost. We are offering a straightforward solution for reinstating access to BitLocker-protected Windows systems with the help of a bootable USB drive.

👉 https://blog.elcomsoft.com/2020/06/unlocking-bitlocker-volumes-by-booting-from-a-usb-drive/

#bitlocker #password #recoverykey #usbkey #boot #encryption #fde #cybersecurity #itsecurity #tpm
Elcomsoft System Recovery adds BitLocker support

We updated Elcomsoft System Recovery, a Windows PE-based tool to recover or reset passwords to local Windows accounts and Microsoft accounts in all versions of Windows. The tool adds native support for BitLocker volumes, enabling users to mount BitLocker-encrypted partitions using one of the three supported disk protectors.

📝 Release Notes

👉 https://www.elcomsoft.com/news/752.html

#bitlocker #password #recoverykey #usbkey #boot #encryption #fde #cybersecurity #itsecurity #computerforensics
Extracting and Using Stored Passwords from Web Browsers

Breaking passwords becomes more difficult with every other update of popular software. Microsoft routinely bumps the number of hash iterations to make Office document protection coherent with current hardware. Apple uses excessive protection of iTunes backups since iOS 10.1, making brute force attacks a thing of the past. VeraCrypt and BitLocker were secure from the get go. However, everything is not lost if you consider human nature.

👉 https://blog.elcomsoft.com/2020/07/extracting-and-using-stored-passwords-from-web-browsers/

#browsers #password #passwordrecovery #cybersecurity #itsecurity #digitalforensics