- Practical Mobile Forensics(Third Edition)
- Rohit Tamma Oleg Skulkin Heather Mahalik Satish Bommisetty
- 330字
- 2021-06-30 19:33:06
Disk layout
By default, the filesystem is configured as two logical disk partitions: system (root or firmware) partition and user data partition.
The system partition contains the OS and all of the preloaded applications used with the iPhone. The system partition is mounted as read-only unless an OS upgrade is in progress or the device is jailbroken. The partition is updated only when a firmware upgrade is performed on the device. During this process, the entire partition is formatted by iTunes without affecting any of the user data. The system partition takes only a small portion of storage space, normally between 0.9 GB and 2.7 GB, depending on the size of the NAND drive. As the system partition was designed to remain in factory state for the entire life of the iPhone, there is typically little useful evidentiary information that can be obtained from it. If the iOS device is jailbroken, files containing information regarding the jailbreak and user data may be resident on the system partition. Jailbreaking an iOS device allows the user root access to the device, but voids the manufacturer warranty. Jailbreaking will be discussed later in this chapter.
The user data partition contains all user-created data, ranging from music and contacts to third-party application data. The user data partition occupies most of the NAND memory and is mounted at /private/var on the device. Most of the evidentiary information can be found in this partition. During a physical acquisition, both the user data and system partitions should be captured and saved as a .dmg or .img file. Most Windows tools and acquisition methods will create an .img file, while macOS X tools and acquisition methods will create a .dmg file. Both of the output image files are supported by most commercial forensic analysis tools.
These raw image files can be mounted as read-only for forensic analysis, which is covered in detail in Chapter 3, Data Acquisition from iOS Devices and Chapter 5, iOS Data Analysis and Recovery.
- 企業(yè)數(shù)字檔案館建設(shè)理論與實(shí)踐
- 中國人民大學(xué)復(fù)印報(bào)刊資料轉(zhuǎn)載指數(shù)排名研究報(bào)告2016
- 全民閱讀組織活動(dòng)讀本
- 從私藏到公共展覽:民國時(shí)期廣州的博物館和展覽會(huì)
- 醫(yī)學(xué)文獻(xiàn)管理
- 新時(shí)代檔案工作新思維
- 非物質(zhì)文化遺產(chǎn)數(shù)字化研究
- 混搭文綴
- 信息系統(tǒng)工程(第2版)
- 中國人民大學(xué)“復(fù)印報(bào)刊資料”轉(zhuǎn)載指數(shù)排名研究報(bào)告(2014)
- 探索與實(shí)踐:博物館與口述歷史
- 國際集郵聯(lián)合會(huì)(FIP)集郵展覽評(píng)審規(guī)則
- 圖書館合理分享著作權(quán)利益訴求研究
- 大學(xué)圖書館信息服務(wù)與信息素養(yǎng)教育理論與實(shí)踐研究
- 圖書情報(bào)與圖書館服務(wù)探究