CARVIEW |
iPhone Forensics
Recovering Evidence, Personal Data, and Corporate Assets
By Jonathan Zdziarski
September 2008
Pages: 138
ISBN 10: 0-596-15358-9 |
ISBN 13: 9780596153588
Press Release
(4) (Average of 1 Customer Reviews)
With iPhone use increasing in business networks, IT and security professionals face a serious challenge: these devices store an enormous amount of information. If your staff conducts business with iPhones, you need to know how to recover, analyze, and securely destroy sensitive data. iPhone Forensics supplies the knowledge necessary to conduct complete and highly specialized forensic analysis of the iPhone, iPhone 3G, and iPod Touch.
Full Description
With iPhone use increasing in business networks, IT and security professionals face a serious challenge: these devices store an enormous amount of information. If your staff conducts business with an iPhone, you need to know how to recover, analyze, and securely destroy sensitive data. iPhone Forensics supplies the knowledge necessary to conduct complete and highly specialized forensic analysis of the iPhone, iPhone 3G, and iPod Touch. This book helps you:
- Determine what type of data is stored on the device
- Break v1.x and v2.x passcode-protected iPhones to gain access to the device
- Build a custom recovery toolkit for the iPhone
- Interrupt iPhone 3G's "secure wipe" process
- Conduct data recovery of a v1.x and v2.x iPhone user disk partition, and preserve and recover the entire raw user disk partition
- Recover deleted voicemail, images, email, and other personal data, using data carving techniques
- Recover geotagged metadata from camera photos
- Discover Google map lookups, typing cache, and other data stored on the live file system
- Extract contact information from the iPhone's database
- Use different recovery strategies based on case needs
And more. iPhone Forensics includes techniques used by more than 200 law enforcement agencies worldwide, and is a must-have for any corporate compliance and disaster recovery plan.
Featured customer reviews
Need to examine an iphone/ipod touch? Get this book., September 16 2008





For such a popular device, you'd think you would find alot more resources for forensic examination of it. Alas, this text is the largest single wealth of information on the subject I could find. It's a good thing for us that it's very well written.
Be warned, this is not for the forensic newbie. You'll want to be comfortable with the command line at the least. More likely you're experienced with computer forensic work in general, or I hope so if you're expecting to go to court! While Jonathan does a great job writing at length about recovering the evidence and of iphone specific discovery, you're going to have to apply general forensics knowledge after that to finish and complete your discovery. This shouldn't be a problem for the audience of the book though.
The book covers recovery for firmware 1.0.2 through the latest release as of this writing, 2.1. Pre-1.0.2 recovery requires either a method that the author does not know about or is perhaps not feasible. In that case the author recommends upgrading the firmware as a last resort. Not a very good solution, but that's not Jonathan's fault. If anyone knows another way, please do shoot him an e-mail and he'll probably add it to the errata.
All in all an excellent book on the subject. Anyone who needs to do some iphone/ipod touch forensics would be remiss not to pick this up. Even if think you can just grab the payloads and do it yourself, there's alot of pitfalls and helpful advice on evidence collection and discovery you'll be missing out on!
Media reviews
Read all reviews

- iPhone Forensics Developer Workshop
- Sample Code
- Colophon
- Register Your Book
- View/Submit Errata
- View/Submit Review
Webcast with Jonathan
![]() ©2009, O'Reilly Media, Inc. (707) 827-7000 / (800) 998-9938 All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners. |
About O'Reilly
Academic Solutions Authors Contacts Customer Service Jobs Newsletters O'Reilly Labs Press Room Privacy Policy RSS Feeds Terms of Service User Groups Writing for O'Reilly Content Archive Business Technology Computer Technology Microsoft Mobile Network Operating System Digital Photography Programming Software Web Web Design |
More O'Reilly Sites
O'Reilly Radar Ignite Tools of Change for Publishing Digital Media Inside iPhone O'Reilly FYI makezine.com craftzine.com hackszine.com perl.com xml.com Partner Sites InsideRIA java.net O'Reilly Insights on Forbes.com |
More Technology News Ars Technica BBC News - Technology CNET News - Technology Guardian - Technology News Mashable ReadWriteWeb Slashdot TechCrunch Technology Review The New York Times - Technology The Washington Post - Technology Wired News |