- Practical Mobile Forensics(Third Edition)
- Rohit Tamma Oleg Skulkin Heather Mahalik Satish Bommisetty
- 330字
- 2021-06-30 19:33:06
Disk layout
By default, the filesystem is configured as two logical disk partitions: system (root or firmware) partition and user data partition.
The system partition contains the OS and all of the preloaded applications used with the iPhone. The system partition is mounted as read-only unless an OS upgrade is in progress or the device is jailbroken. The partition is updated only when a firmware upgrade is performed on the device. During this process, the entire partition is formatted by iTunes without affecting any of the user data. The system partition takes only a small portion of storage space, normally between 0.9 GB and 2.7 GB, depending on the size of the NAND drive. As the system partition was designed to remain in factory state for the entire life of the iPhone, there is typically little useful evidentiary information that can be obtained from it. If the iOS device is jailbroken, files containing information regarding the jailbreak and user data may be resident on the system partition. Jailbreaking an iOS device allows the user root access to the device, but voids the manufacturer warranty. Jailbreaking will be discussed later in this chapter.
The user data partition contains all user-created data, ranging from music and contacts to third-party application data. The user data partition occupies most of the NAND memory and is mounted at /private/var on the device. Most of the evidentiary information can be found in this partition. During a physical acquisition, both the user data and system partitions should be captured and saved as a .dmg or .img file. Most Windows tools and acquisition methods will create an .img file, while macOS X tools and acquisition methods will create a .dmg file. Both of the output image files are supported by most commercial forensic analysis tools.
These raw image files can be mounted as read-only for forensic analysis, which is covered in detail in Chapter 3, Data Acquisition from iOS Devices and Chapter 5, iOS Data Analysis and Recovery.
- 地方檔案與文獻(xiàn)研究(第2輯)
- 科學(xué)普及組織活動(dòng)讀本
- 一本書(shū)讀懂檔案管理
- 公共文化館治理研究(2015年):四川省文化館“十三五”規(guī)劃重大課題調(diào)研成果集
- 北宋書(shū)籍刊刻與古文運(yùn)動(dòng)
- 文獻(xiàn)保護(hù)中英雙解詞語(yǔ)手冊(cè)
- 海源閣史
- 知中16·西南聯(lián)大的遺產(chǎn)
- 檔案修復(fù)與歷史資料的數(shù)字化:第六屆東亞史料研究編纂機(jī)構(gòu)聯(lián)席會(huì)議論文集
- 檔案記憶觀的理論與實(shí)踐
- 梁思成林徽因影像與手稿珍集
- 數(shù)字信息環(huán)境下圖書(shū)館信息資源建設(shè)與共享
- 圖書(shū)館出版物國(guó)際交換
- 數(shù)字圖書(shū)館資源管理與建設(shè)
- 文化與詩(shī)學(xué)(2009年第1輯)(總第8輯)