SlideShare ist ein Scribd-Unternehmen logo
1 von 8
Image (evidence) Recovery
in Android Device
Dafiz Adi Nugroho 113090005
Caisar Oentoro 113090064
M. Jafar Sidik 113091011
The Goal

  Recovering deleted image files (.jpeg
  and(or) png ) from the external Android
                   phones
The device
 The device used in this case is Nexian
  NX-A891 with Android Froyo 2.2.2.
 The devices already rooted and can
  be commanded through adb shell.
First Step (for external
memory)
 Calculating the device hash values
  with WinHex.
 Creating image from the external
  memory with WinHex.
 After getting images files from SD
  Card, compare the hash values, if
  matched then imaging process is
  succeded
First Step (for external
    memory)
   There are two ways:
    ◦ Using dd command:
      dd if=/dev/mtd/mtd1 of=/sdcard/recovery.img
       bs=4096

• There are two ways:
    – Using YaffsExpert, just click and follow
      instructions
Backing Up Images
   After images acquired, just back it up
    (make clone) in hard drives / flash disk, or
    everywhere else.
Doing Analysis
   We little bit stack here.
That’s all we doing till now
   Hope better next time

Weitere ähnliche Inhalte

Andere mochten auch

Розслідування Bellingcat щодо збитого на Донбасі МН17
Розслідування Bellingcat щодо збитого на Донбасі МН17Розслідування Bellingcat щодо збитого на Донбасі МН17
Розслідування Bellingcat щодо збитого на Донбасі МН17tsnua
 
Toksikologi forensik smallpox ppt.
Toksikologi forensik smallpox ppt. Toksikologi forensik smallpox ppt.
Toksikologi forensik smallpox ppt. anna maria manullang
 
Digital Forensic: Brief Intro & Research Challenge
Digital Forensic: Brief Intro & Research ChallengeDigital Forensic: Brief Intro & Research Challenge
Digital Forensic: Brief Intro & Research ChallengeAung Thu Rha Hein
 

Andere mochten auch (6)

Digital forensic upload
Digital forensic uploadDigital forensic upload
Digital forensic upload
 
Розслідування Bellingcat щодо збитого на Донбасі МН17
Розслідування Bellingcat щодо збитого на Донбасі МН17Розслідування Bellingcat щодо збитого на Донбасі МН17
Розслідування Bellingcat щодо збитого на Донбасі МН17
 
Toksikologi forensik smallpox ppt.
Toksikologi forensik smallpox ppt. Toksikologi forensik smallpox ppt.
Toksikologi forensik smallpox ppt.
 
Siasatan Forensik
Siasatan ForensikSiasatan Forensik
Siasatan Forensik
 
Digital Forensic: Brief Intro & Research Challenge
Digital Forensic: Brief Intro & Research ChallengeDigital Forensic: Brief Intro & Research Challenge
Digital Forensic: Brief Intro & Research Challenge
 
Computer forensics ppt
Computer forensics pptComputer forensics ppt
Computer forensics ppt
 

Ähnlich wie Android forensik 2

Sandisk card recovery guide
Sandisk card recovery guideSandisk card recovery guide
Sandisk card recovery guidebob simpson
 
First Responder Course - Session 10 - Static Evidence Collection [2004]
First Responder Course - Session 10 - Static Evidence Collection [2004]First Responder Course - Session 10 - Static Evidence Collection [2004]
First Responder Course - Session 10 - Static Evidence Collection [2004]Phil Huggins FBCS CITP
 
Dell Venue 7 3740
Dell Venue 7 3740Dell Venue 7 3740
Dell Venue 7 3740Kojo King
 
NMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptxNMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptxLEGENDARYTECHNICAL
 
NMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptxNMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptxLEGENDARYTECHNICAL
 
Wd usb hdd image un locker pro-sw6316
Wd usb hdd image un locker pro-sw6316Wd usb hdd image un locker pro-sw6316
Wd usb hdd image un locker pro-sw6316Dolphin Data Lab
 
Digital Image Processing
Digital Image ProcessingDigital Image Processing
Digital Image ProcessingAzharo7
 
Image restoration manual with equipment clone zilla
Image restoration manual with equipment clone zillaImage restoration manual with equipment clone zilla
Image restoration manual with equipment clone zillapulsar2013
 
Convolution Neural Network (CNN)
Convolution Neural Network (CNN)Convolution Neural Network (CNN)
Convolution Neural Network (CNN)Suraj Aavula
 
HKG15-409: ARM Hibernation enablement on SoCs - a case study
HKG15-409: ARM Hibernation enablement on SoCs - a case studyHKG15-409: ARM Hibernation enablement on SoCs - a case study
HKG15-409: ARM Hibernation enablement on SoCs - a case studyLinaro
 
Introduction to Mixed Reality
Introduction to Mixed RealityIntroduction to Mixed Reality
Introduction to Mixed RealityClemente Giorio
 
Having Bad Sectors on Hard drive?
Having Bad Sectors on Hard drive?Having Bad Sectors on Hard drive?
Having Bad Sectors on Hard drive?sangysimmons
 
Pic Frame
Pic FramePic Frame
Pic Framegenti74
 
Resolution Independent 2D Cartoon Video Conversion
Resolution Independent 2D Cartoon Video ConversionResolution Independent 2D Cartoon Video Conversion
Resolution Independent 2D Cartoon Video ConversionFaathima Fayaza
 
Thinking cpu & memory - DroidCon Paris 18 june 2013
Thinking cpu & memory - DroidCon Paris 18 june 2013Thinking cpu & memory - DroidCon Paris 18 june 2013
Thinking cpu & memory - DroidCon Paris 18 june 2013Paris Android User Group
 

Ähnlich wie Android forensik 2 (20)

Sandisk card recovery guide
Sandisk card recovery guideSandisk card recovery guide
Sandisk card recovery guide
 
First Responder Course - Session 10 - Static Evidence Collection [2004]
First Responder Course - Session 10 - Static Evidence Collection [2004]First Responder Course - Session 10 - Static Evidence Collection [2004]
First Responder Course - Session 10 - Static Evidence Collection [2004]
 
Dell Venue 7 3740
Dell Venue 7 3740Dell Venue 7 3740
Dell Venue 7 3740
 
NMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptxNMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptx
 
Q6 evaluation
Q6 evaluationQ6 evaluation
Q6 evaluation
 
Q6 evaluation
Q6 evaluationQ6 evaluation
Q6 evaluation
 
NMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptxNMO IE-2 Activity Presentation.pptx
NMO IE-2 Activity Presentation.pptx
 
Wd usb hdd image un locker pro-sw6316
Wd usb hdd image un locker pro-sw6316Wd usb hdd image un locker pro-sw6316
Wd usb hdd image un locker pro-sw6316
 
Digital Image Processing
Digital Image ProcessingDigital Image Processing
Digital Image Processing
 
Image restoration manual with equipment clone zilla
Image restoration manual with equipment clone zillaImage restoration manual with equipment clone zilla
Image restoration manual with equipment clone zilla
 
Convolution Neural Network (CNN)
Convolution Neural Network (CNN)Convolution Neural Network (CNN)
Convolution Neural Network (CNN)
 
HKG15-409: ARM Hibernation enablement on SoCs - a case study
HKG15-409: ARM Hibernation enablement on SoCs - a case studyHKG15-409: ARM Hibernation enablement on SoCs - a case study
HKG15-409: ARM Hibernation enablement on SoCs - a case study
 
Introduction to Mixed Reality
Introduction to Mixed RealityIntroduction to Mixed Reality
Introduction to Mixed Reality
 
groupProject-1-Win8
groupProject-1-Win8groupProject-1-Win8
groupProject-1-Win8
 
Having Bad Sectors on Hard drive?
Having Bad Sectors on Hard drive?Having Bad Sectors on Hard drive?
Having Bad Sectors on Hard drive?
 
Pic Frame
Pic FramePic Frame
Pic Frame
 
Resolution Independent 2D Cartoon Video Conversion
Resolution Independent 2D Cartoon Video ConversionResolution Independent 2D Cartoon Video Conversion
Resolution Independent 2D Cartoon Video Conversion
 
Thinking cpu & memory - DroidCon Paris 18 june 2013
Thinking cpu & memory - DroidCon Paris 18 june 2013Thinking cpu & memory - DroidCon Paris 18 june 2013
Thinking cpu & memory - DroidCon Paris 18 june 2013
 
Gif recovery
Gif recoveryGif recovery
Gif recovery
 
Gif recovery
Gif recoveryGif recovery
Gif recovery
 

Mehr von Caisar Oentoro

Mehr von Caisar Oentoro (6)

D3.JS Data-Driven Documents
D3.JS Data-Driven DocumentsD3.JS Data-Driven Documents
D3.JS Data-Driven Documents
 
Android forensik
Android forensikAndroid forensik
Android forensik
 
Greedy algorithm
Greedy algorithmGreedy algorithm
Greedy algorithm
 
Mini magazine
Mini magazineMini magazine
Mini magazine
 
Metode SMART
Metode SMARTMetode SMART
Metode SMART
 
How Reflex Works
How Reflex WorksHow Reflex Works
How Reflex Works
 

Android forensik 2

  • 1. Image (evidence) Recovery in Android Device Dafiz Adi Nugroho 113090005 Caisar Oentoro 113090064 M. Jafar Sidik 113091011
  • 2. The Goal Recovering deleted image files (.jpeg and(or) png ) from the external Android phones
  • 3. The device  The device used in this case is Nexian NX-A891 with Android Froyo 2.2.2.  The devices already rooted and can be commanded through adb shell.
  • 4. First Step (for external memory)  Calculating the device hash values with WinHex.  Creating image from the external memory with WinHex.  After getting images files from SD Card, compare the hash values, if matched then imaging process is succeded
  • 5. First Step (for external memory)  There are two ways: ◦ Using dd command:  dd if=/dev/mtd/mtd1 of=/sdcard/recovery.img bs=4096 • There are two ways: – Using YaffsExpert, just click and follow instructions
  • 6. Backing Up Images  After images acquired, just back it up (make clone) in hard drives / flash disk, or everywhere else.
  • 7. Doing Analysis  We little bit stack here.
  • 8. That’s all we doing till now  Hope better next time