期刊文献+

一种基于Checkm8漏洞的iPhone取证方法研究 被引量:1

Research on iPhone Forensic Method Based on Checkm8 Vulnerability
下载PDF
导出
摘要 Checkm8漏洞是一种基于i Phone手机固件强制升降机模式的硬件漏洞。在电子数据取证工作中,针对未知锁屏密码的i Phone手机检材,文章提出一种利用Checkm8漏洞绕过密码验证提取i Phone手机数据的方法,并通过实验演示了漏洞利用、证据数据挖掘与提取、数据解密分析与证据展示。同时利用堆漏洞对锁屏状态下的i Phone手机进行最高权限提升,获取端口通信权限与数据提取传输权限,解决了密码缺失情况下数据提取问题。 The Checkm8 vulnerability is a hardware vulnerability based on the device firmware upgrade(DFU) mode of the iPhone firmware. This paper proposed a method of using Checkm8 vulnerability to bypass password verification to extract iPhone data, and demonstrated the exploitation of the vulnerability, digital data mining and extraction, data decryption analysis and evidence display. At the same time, the heap vulnerabilities were utilized to upgrade the highest authority, obtain the authority of port communication and transmission on the iPhone in the locked state, which could solve the problem of data extraction in the absence of passwords. This method has high practical value for forensic science.
作者 陈光宣 吴家健 操丹妮 谢清泉 CHEN Guangxuan;WU Jiajian;CAO Danni;XIE Qingquan(Key Laboratory of Public Security Information Application Based on Big-data Architecture,Ministry of Public Security,Zhejiang Police College,Hangzhou 310053,China;Suzhou Longxintec Co.,Suzhou 215125,China)
出处 《信息网络安全》 CSCD 北大核心 2021年第12期44-50,共7页 Netinfo Security
基金 浙江省自然科学基金委员会基础公益研究计划项目[LGF19F020006] 国家级大学生创新创业训练计划[202111481006] 浙江省大学生科技创新活动计划暨新苗人才计划[2021R422003]。
关键词 电子数据取证 IPHONE Checkm8漏洞 锁屏密码 digital forensics iPhone Checkm8 vulnerability lockdown password
  • 相关文献

参考文献3

二级参考文献7

共引文献13

同被引文献1

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部