
çè«ã®ããã
æ€æ»äžãã»ãšãã©ã®å Žåãããã€ã¹ãžã®ç©ççã¢ã¯ã»ã¹ãæ瀺ããããšãã¹ããŒãã«ã¯2ã€ã®ã¿ã¹ã¯ããããŸããããã€ã¹ããå¯èœãªéãå€ãã®ããŒã¿ãšæ å ±ãæœåºããããšãšããã¬ãŒã¹ïŒã¢ãŒãã£ãã¡ã¯ãïŒãã§ããã ãå°ãªãããããšã§ãã æ€æ»ã®çµæãæ³å»·ã§æ瀺ãããå Žåã2çªç®ã®ã¿ã¹ã¯ã¯ç¹ã«éèŠã§ããéå°ãªã¢ãŒãã£ãã¡ã¯ããåæ€æ»ã劚ããå¯èœæ§ãããããã®çµæãæåã®æ€æ»ã®çµæã«çåãæããããå¯èœæ§ããããŸãã å€ãã®å Žåãã¢ãŒãã£ãã¡ã¯ãã®åºçŸãé¿ããããšã¯äžå¯èœã§ãã ç 究ã®ããŸããŸãªæ®µéã§äœæãããã¢ãŒãã£ãã¡ã¯ãã詳现ã«ææžåããããšã«ããããã®åé¡ã解決ããããšããŠããŸãã
iOSããã€ã¹ã«ä¿åãããããŒã¿ã¯æ¯èŒçååã«ä¿è·ãããŠãããããŒã¿ãæœåºããã«ã¯ãéåžžã次ã®é害ãå æããå¿ èŠããããŸãã
- ãã¹ã³ãŒãã äžæ£ã¢ã¯ã»ã¹ïŒæ€æ»ãå«ãïŒããããã€ã¹ãä¿è·ããããŒã¿ã®äžéšãæå·ã§ä¿è·ããŸãã ããã¯ãããã€ã¹ããã¹ã³ãŒããç¥ããªããŠã察å¿ããæå·åããŒãååŸã§ããªãããããã¹ã³ãŒãããªãããã®æ¹æ³ã§ãã€ãã¹ãããŠããäžéšã®ããŒãã§ãŒã³ãã¡ã€ã«ããã³ã¬ã³ãŒããå©çšã§ããªãããšãæå³ããŸãã
- ããŒãã«ã㌠ããã¯ããã¹ã¯ãŒããããŒã¯ã³ãæå·åããŒããã®ä»ã®ç§å¯ã®éäžãªããžããªã§ãããã¢ããªã±ãŒã·ã§ã³éçºè ã貎éãªããŒã¿ãä¿æããããšãAppleãæšå¥šããŠããŸãã ç©ççã«ã¯ãSQLite3ããŒã¿ããŒã¹ã§ããããšã³ããªã¯æå·åãããã¢ã¯ã»ã¹ã¯ãsecuritydããµãŒãã¹ãžã®ãªã¯ãšã¹ããä»ããŠéæ¥çã«å®è¡ãããŸãã
- ãã¡ã€ã«ã®æå·åã ãã«ãã£ã¹ã¯æå·åïŒFDEïŒã·ã¹ãã ãšã¯ç°ãªããiOSã¯åãã¡ã€ã«ãåå¥ã®ããŒïŒWindows EFSãªã©ïŒã§æå·åããŸãã äžéšã®ãã¡ã€ã«ã¯ãäžæã®ããã€ã¹ããŒãã掟çããããŒã§ä¿è·ãããŠããããã¹ã³ãŒããç¥ããªããŠã埩å·åã§ããŸããäžéšã®ãã¡ã€ã«ã¯ããã¹ã³ãŒããç¥ããªããšåŸ©å·ã§ããªãããã«ä¿è·ãããŠããŸãã
ããã3ã€ã®ã¡ã«ããºã ãããŒã¿ä¿è·ãµãã·ã¹ãã ã圢æããŸããããã¯iOS 4ã«ç»å Žããå€èŠ³äžãè©Šéšã®å®æœãèããè€éã«ããŸããã iOS 4ã®ãªãªãŒã¹åŸãããŒã¿ä¿è·ã¯ããã»ã©å€åããŸããã§ãããã1ã€äŸå€ããããŸã-iPhone 5sããã³ãã以éã®ã¢ãã«ã§ã®Secure Enclaveã®åºçŸã Secure Enclaveã¯ãæçŽããã¹ã³ãŒããæå·åããŒãªã©ã䜿çšããæäœã®ããŒã¿ä¿è·ã®äžéšãšããŠäœ¿çšãããŸããããã®èšäºã§ã¯èæ ®ããŸããã
ããŒã¿æœåº
iOSããã€ã¹ããããŒã¿ãæœåºããããã«ãå®éã«ã¯ããã€ãã®æ¹æ³ãäŒçµ±çã«äœ¿çšãããŠããŸãïŒ
- ãç©ççæœåºãã䜿çšãããšããã£ã¹ã¯ã®ãããåäœã®ã€ã¡ãŒãžãããã€ã¹ã®ãã¹ãŠã®æå·åããŒãååŸã§ããã»ãšãã©ã®å Žåããã¹ã³ãŒãïŒã€ã³ã¹ããŒã«ãããŠããå ŽåïŒã䞊ã¹æ¿ããããšãã§ããŸãã éåžžãç©ççãªæœåºã«ã¯ãå®å šãªæš©éãæã€ãŠãŒã¶ãŒïŒã«ãŒãïŒããã³ãµã³ãããã¯ã¹ã®å€éšïŒãµã³ãããã¯ã¹ïŒã®ã³ã³ããã¹ãã§ããã€ã¹äžã§ã³ãŒããå®è¡ããå¿ èŠããããŸãã ãã®æ¹æ³ã¯ãå€ãããã€ã¹ïŒiPhone 4ãæåã®iPadãªã©ïŒã®ããŒãããŒããŒã®è匱æ§ã«ãããããã€ã¹äžã§ä»»æã®ã³ãŒããå®è¡ã§ãããããæ°å¹Žåã«æ®åããŸããã æ°ããããã€ã¹ã§ã¯ããžã§ã€ã«ãã¬ã€ã¯ãããå Žåã«ã®ã¿ç©ççãªæœåºãå¯èœã§ãïŒäºçŽãããå Žåã§ãïŒããããã£ãŠãä»æ¥ã¯ãããèæ ®ããŸããã
- è«çæœåºã§ã¯ãããã€ã¹äžã«æ¢ã«ååšããiTunesãXcodeãªã©ã®ããã°ã©ã ãããŒã¿ãååŸããããã«äœ¿çšããã€ã³ã¿ãŒãã§ã€ã¹ãšãµãŒãã¹ã䜿çšããŸãã ããã§ã®å žåçãªäŸã¯ãiTunesã®ããã¯ã¢ãããäœæããããšã§ãïŒäœæããããã«ãããã€ã¹ã«è¿œå ã®ããã°ã©ã ãã€ã³ã¹ããŒã«ããå¿ èŠã¯ãããŸããããåæã«ããã€ã¹ã«é¢ããå€ãã®è²Žéãªæ å ±ïŒé£çµ¡å ãšé話ã®ãªã¹ããéä¿¡å±¥æŽããã±ãŒã·ã§ã³å±¥æŽãåç/ãããªãå«ãïŒãå«ãŸããŠããŸãã ããããåé¡ã¯ããã¯ã¢ããã®ã¿ã«éå®ãããŸãã-ããŒã¿ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããiOSããã€ã¹ã«ã¯ä»ã®ãµãŒãã¹ããããŸãã
- iCloudããååŸãããšãããã€ã¹ã®ããã¯ã¢ãããã¯ã©ãŠãããããŠã³ããŒãã§ããŸãã ãããè¡ãã«ã¯ãApple IDããã€ã¹ã§èšå®ãããŠããèªèšŒããŒã¿ïŒApple IDãšãã¹ã¯ãŒããŸãã¯èªèšŒããŒã¯ã³ïŒãç¥ãå¿ èŠããããŸãã iCloudããã¯ã¢ããã«ã¯ã倧éã®è²Žéãªæ å ±ãå«ãŸããŠããŸãã
åµå
ãè«çãæœåºã«é¢ããŠã¯ãéèŠãªæŠå¿µã®1ã€ã¯ããã€ã¹ãšãã¹ãã®ãã¢ãªã³ã°ã§ãã ã»ãšãã©ã®å Žåãããã€ã¹ã¯ããã¢ã«ãªã£ããã¹ãããã®èŠæ±ã«ã®ã¿å¿çããŸãïŒãã®ãããªãã¹ãã¯è€æ°ããå ŽåããããŸãïŒã ãã¢ãªã³ã°ã¬ã³ãŒãã¯2ã€ã®éšåã§æ§æãããŸãã1ã€ã¯ããã€ã¹ã«ä¿åããããã1ã€ã¯ãã¹ãã«ä¿åãããããã€ã¹ãæ°ãããã¹ãã«åããŠæ¥ç¶ããããšãã«äœæãããŸãã ãã®ãããªã¬ã³ãŒããäœæããã«ã¯ãããã€ã¹ã®ããã¯ã解é€ããå¿ èŠããããŸãïŒã€ãŸããäžè¬ã«ãã¢ãªã³ã°ããã«ã¯ãã¹ã³ãŒããå ¥åããå¿ èŠããããŸãïŒããŠãŒã¶ãŒã¯ããã€ã¹ã§ãã¢ãªã³ã°ã¬ã³ãŒãã®äœæã確èªããå¿ èŠããããŸãïŒiOS 7以éã以åã®ããŒãžã§ã³ã§ã¯ãã¬ã³ãŒãã¯èªåçã«äœæãããŸããïŒã

ãã¢ãªã³ã°ã¬ã³ãŒãã«ã¯ãããã€ã¹ã«ä¿åãããŠãããã¹ãŠã®ã³ã³ãã³ãã®æå·åããŒãå«ãŸããŠãããããããã€ã¹ãžã®æ¥ç¶ãšããã¯è§£é€ã«äœ¿çšã§ããŸãã èšãæãããšãæå·åãããããŒã¿ãžã®ã¢ã¯ã»ã¹ã®èŠ³ç¹ããèŠããšããã¢ãªã³ã°ã¬ã³ãŒãã¯ãã¹ã³ãŒããç¥ãããšãšåçã§ãããããã®2ã€ã®èŠå ã®ãããããååšãããšãããã€ã¹ã®ããã¯ã解é€ãããã¹ãŠã®ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸãïŒæå·åã®æå³ã§ïŒã
å®çšçãªèŠ³ç¹ãããäžèšã®ããšã¯ãäžè¬çãªå Žåã®è«ççãªæœåºã«ã¯ãä¿¡é Œã§ããã³ã³ãã¥ãŒã¿ãŒã®1ã€ããã®æ¢åã®ãã¢ãªã³ã°ã¬ã³ãŒããŸãã¯ãã¹ã³ãŒãïŒãã®ã¬ã³ãŒããäœæããããïŒãå¿ èŠã§ããããšãæå³ããŸãã ããããªããšãã»ãšãã©ã®iOSãµãŒãã¹ã¯åäœãæåŠããããŒã¿ãè¿ããŸãã
ç·Žç¿ãã
å®éšã«ã¯ãLinuxãå®è¡ããä»®æ³ãã·ã³ãŸãã¯ç©çãã·ã³ãå¿ èŠã§ãã Linuxã¯ååãšããŠäœã§ãæ§ããŸããã`libusb`ãš `libimobiledevice`ãéåžžåäœãããã®äžã§åäœããããšãéèŠã§ãã Santoku Linuxã䜿çšããŸããããã¯ãAndroidããã³iOSãå®è¡ããŠããããã€ã¹ãç 究ããããã«äœæãããé åžãããã§ãã æ®å¿µãªãããSantoku Linuxã«ã¯å¿ èŠãªãã®ããã¹ãŠå«ãŸããŠããªãããããŸã äœããä»äžããå¿ èŠããããŸãã

è«çæœåº
ããã€ã¹ããããŒã¿ãè«ççã«æœåºããã«ã¯ãããŸããŸãªiOSãµãŒãã¹ãšéä¿¡ããããã®ã¯ãã¹ãã©ãããã©ãŒã ã©ã€ãã©ãªlibimobiledeviceãå¿ èŠã§ã ã æ®å¿µãªãããSantoku Linux 0.5ã«ã¯ `libimobiledevice`ã®å€ãããŒãžã§ã³ïŒ1.1.5ïŒãä»å±ããŠããŸããããã¯iOS 8ãå®å šã«ãµããŒãããŠããªãããããŸãææ°ããŒãžã§ã³ïŒ1.1.7ïŒãšãã®ãã¹ãŠã®äŸåé¢ä¿ãã€ã³ã¹ããŒã«ããŸãïŒæå®ããããªã³ã¯ã§ã¢ãŒã«ã€ããããŠã³ããŒããã解åããŸãïŒ ãçµæã®ãã©ã«ããŒã«ç§»åãã `ã/ autogen.sh && make && sudo make install`ãå®è¡ããŸãïŒïŒ
- libplist-1.12 ;
- libusbmuxd-1.0.10 ;
- libimobiledevice-1.1.7-ããã§ã¯ã `--enable-dev-tools`ããŒã«æ³šæããŠãã ãããããã«ã¯ãè¿œå ã®ãŠãŒãã£ãªãã£ã®ã¢ã»ã³ããªãå«ãŸããŠããŸããããã¯ãä»åŸãããã€ãã®iOSãµãŒãã¹ãšã®éä¿¡ã«äœ¿çšããŸãã`./autogen.sh --enable- dev-tools`;
- usbmuxd-1.1.0 -Santoku 0.5ã§ã¯ãusbmuxdãèµ·åããªãããã `--without-systemd`ããŒãå¿ èŠãªããã§ãïŒ` ./autogen.sh --without-systemd`;
- ideviceinstaller-1.1.0 ;
- ifuse-1.1.3 ã
ãã¹ãŠãããŸãããã°ãããããiOSããã€ã¹ãã³ã³ãã¥ãŒã¿ãŒïŒãŸãã¯ä»®æ³ãã·ã³ïŒã«æ¥ç¶ãããã¹ãããããèªèããŠããããšã確èªããŸãã
santoku@santoku-vm:~$ idevice_id -l 23f88587e12c30376f8ab0b05236798fdfa4e853 santoku@santoku-vm:~$
ãã®ã³ãã³ãã¯ãæ¥ç¶ãããããã€ã¹ã®èå¥åïŒUUIDïŒã衚瀺ããå¿ èŠããããŸãã
ããã€ã¹æ å ±
次ã®ã¹ãããã¯ãããã€ã¹ã«é¢ãããã詳现ãªæ å ±ãååŸããããšã§ãã ããã«ã¯ãideviceinfoããŠãŒãã£ãªãã£ã䜿çšãããŸãã 次ã®2ã€ã®ããŒãžã§ã³ã§äœ¿çšã§ããŸãã
- ãideviceinfo -sãã¯ãæ°ããããã€ã¹ãäœæãããããã¹ããšããã€ã¹éã®æ¢åã®ãã¢ã䜿çšããããšããã«ãããã€ã¹ã«é¢ããå ¬éæ å ±ã衚瀺ããŸãã
- ãideviceinfo [-q <ãã¡ã€ã³>] [-x]ãã¯ãããªã詳现ãªæ å ±ã衚瀺ããŸãããããã€ã¹ãšãã¹ãã®ãã¢ãªã³ã°ãå¿ èŠã§ãã ãŠãŒãã£ãªãã£ã¯ãããã€ã¹ã§å®è¡ãããŠãããlockdowndããµãŒãã¹ã«æ å ±ãèŠæ±ããŸãã æ å ±ã¯ããŒãšå€ã®ãã¢ã§ãããããŒã¯ãã¡ã€ã³ã«ã°ã«ãŒãåãããŸãã `-q`ãã©ã¡ãŒã¿ãŒã䜿çšããŠãããŒã¿ãååŸããç¹å®ã®ãã¡ã€ã³ãæå®ã§ããŸãã
`-x`ãã©ã¡ãŒã¿ã䜿çšãããšãããã°ã©ã ã®åºåãXML圢åŒïŒãŸãã¯ããããã£ãªã¹ãã®åœ¢åŒïŒã§ãã©ãŒãããã§ãããããåºåããã¡ã€ã«ã«ãªãã€ã¬ã¯ãããä»ã®ããã°ã©ã ãã¹ã¯ãªããã§ããã«åŠçã§ããŸãã

çšé
è«çæœåºã®äžéšãšããŠãã¢ããªã±ãŒã·ã§ã³ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸãã ãããè¡ãã«ã¯ãæåã«ãideviceinstallerããŠãŒãã£ãªãã£ã䜿çšããŠã€ã³ã¹ããŒã«æžã¿ã¢ããªã±ãŒã·ã§ã³ã®ãªã¹ããååŸããå¿ èŠããããŸãã
santoku@santoku-vm:~$ ideviceinstaller -l Total: 4 apps com.viaforensics.viaprotect-app - NowSecure 1 com.facebook.Facebook - Facebook 6017145 ph.telegra.Telegraph - Telegram 39280 com.getdropbox.Dropbox - Dropbox 3.6.2 santoku@santoku-vm:~$
ãã®çµæãã¢ããªã±ãŒã·ã§ã³ããšã«ããã®èå¥åïŒãããããã³ãã«IDïŒãååãããã³ããŒãžã§ã³ãååŸããŸãã ã¢ããªã±ãŒã·ã§ã³èå¥åãç¥ã£ãŠããã°ããã®ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããŸãã ãã®ããã«ã2ã€ã®iOSãµãŒãã¹-ãhouse_arrestããšãafcããé¢ä¿ããŠããŸãã AFCïŒApple File ConduitïŒã¯ãã¡ã€ã«ã¢ã¯ã»ã¹ãµãŒãã¹ã§ãã ç¹ã«ãiTunesã䜿çšãããšãããã€ã¹äžã®é³æ¥œããã®ä»ã®ã¡ãã£ã¢ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãã ãhouse_arrestãã¯ããŸãç¥ãããŠããŸããããç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã®ãµã³ãããã¯ã¹ã§AFCãµãŒããŒãèµ·åã§ããŸãã ç¹ã«ãiTunesã§ãã¡ã€ã«å ±ææ©èœãå®è£ ããããã«äœ¿çšãããŸãã
ããããããã¯ãã¹ãŠçè«ã§ãã å®éã«ã¯ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããã«ã¯ãifuseãŠãŒãã£ãªãã£ã䜿çšããã ãã§ååã§ãã
santoku@santoku-vm:~$ ifuse --container com.getdropbox.Dropbox ~/Desktop/Applications/ santoku@santoku-vm:~$
ãã®ã³ãã³ãã®çµæãã¢ããªã±ãŒã·ã§ã³ããŒã¿ã®ãããã£ã¬ã¯ããªãã/ Desktop / Applicationsãã£ã¬ã¯ããªã«ããŠã³ããããŸãã
santoku@santoku-vm:~$ ls ~/Desktop/Applications/ Documents Library StoreKit tmp santoku@santoku-vm:~$
ã³ãã³ã `fusermount âuã/ Desktop / Applications`ã§ã¢ããªã±ãŒã·ã§ã³ããŒã¿ãã¢ã³ããŠã³ãã§ããŸãã
iTunesããã¯ã¢ãã
åŸæ¥ãããã€ã¹ã®ããã¯ã¢ããã¯æã人æ°ã®ããããŒã¿æœåºãã¯ãã«ã®1ã€ã§ããããå®çŸ©äžãããã¯ã¢ããã«ã¯ããã€ã¹ãšãã®ææè ã«é¢ããå€ãã®è²Žéãªæ å ±ãå«ãŸããŠããããšãèãããšãåœç¶ã®ããšã§ãã ããã¯ã¢ãããäœæããã«ã¯ã `idevicebackup2`ãŠãŒãã£ãªãã£ã䜿çšã§ããŸãïŒ
santoku@santoku-vm:~$ idevicebackup2 backup --full ~/Desktop Backup directory is "/home/santoku/Desktop" Started "com.apple.mobilebackup2" service on port 50066. Negotiated Protocol Version 2.1 Starting backup... Enforcing full backup from device. Backup will be unencrypted. Requesting backup from device... Full backup mode. [= ] 1% Finished Receiving files .... Received 237 files from device. Backup Successful. santoku@santoku-vm:~$
ããã€ã¹äžã®ã³ã³ãã³ãã®éã«ãã£ãŠã¯ãããã¯ã¢ããã®äœæã«é·ãæéããããå ŽåããããŸãïŒæ倧30åïŒã
ããã¯ã¢ããã®å¥ã®æœåšçãªåé¡ã¯ãããã¯ã¢ãããæå·åã§ããããšã§ãã iOSã®ããã¯ã¢ããã®æå·åã¯ããã€ã¹åŽã§å®è¡ãããããããŠãŒã¶ãŒãããã¯ã¢ããããã¹ã¯ãŒãã§ä¿è·ããŠããå Žåãããã¯ã¢ããäžã«ããã€ã¹ã«ãã£ãŠéä¿¡ããããã¹ãŠã®ããŒã¿ãæå·åãããŸãã ãã¹ã¯ãŒããèŠã€ããããšãã§ããŸã-ããã«ã¯åçšããŒã«ãšç¡æããŒã«ã®äž¡æ¹ããããŸãã ãã¹ã¯ãŒãããªããšãããã¯ã¢ãããã¡ã€ã«ã®å 容ã«ã¢ã¯ã»ã¹ã§ããŸããã
ããã©ã«ãã§ã¯ã `idevicebackup2`ã¯ããã¯ã¢ãããå éšiOS圢åŒã§ä¿åããŸããããã¯ãããšãã°ããã¡ã€ã«åã®ä»£ããã«ãã¡ã€ã«ãã¹ã®SHA-1ããã·ã¥é¢æ°ã®å€ã䜿çšãããããæåã®æ¢çŽ¢ã«ã¯ããŸãé©ããŠããŸããã ãã®å éšiOS圢åŒã®å©ç¹ã¯ãå€ãã®ããã°ã©ã ããã®æäœæ¹æ³ãç¥ã£ãŠããããšã§ãããããã£ãŠãããã¯ã¢ããã®å 容ãåæããã«ã¯ããããã®ããã°ã©ã ã®1ã€ïŒããšãã°ã iOS Backup Analyzer ã iBackupBot ã iExplorer ïŒã§éããŸãã
äœããã®çç±ã§ããã¯ã¢ãããããèªã¿ããã圢åŒã§ååŸãããå Žåã¯ã `unback`ã³ãã³ãã䜿çšã§ããŸãã
santoku@santoku-vm:~$ idevicebackup2 unback ~/Desktop
ãã®ã³ãã³ãã¯ããã¹ã¯ãããäžã« `_unback_`ãã£ã¬ã¯ããªãäœæããŸãããã®ãã£ã¬ã¯ããªã§ã¯ãããã€ã¹ã®ããã¯ã¢ããã³ããŒã¯ãåŸæ¥ã®æ¬äŒŒã©ã³ãã åãæã€ãã¡ã€ã«ã®ãªã¹ããšããŠã§ã¯ãªããåŸæ¥ã®ãã¡ã€ã«ããªãŒãšããŠä¿åãããŸãã
ãã¡ã€ã«ã·ã¹ãã
ifuseãŠãŒãã£ãªãã£ã䜿çšããŠãiOSããã€ã¹ã®ãã¡ã€ã«ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããšãã§ããŸãã ããã«ãæšæºã®AFCãµãŒãã¹ã§ã¯ãåç/åç»ãã¡ã€ã«ãæ ç»ãé³æ¥œããã®ä»ã®ã¡ãã£ã¢ã³ã³ãã³ããä¿åãã `/ var / mobile / Media`ãã£ã¬ã¯ããªã®ã³ã³ãã³ãã«ã®ã¿ã¢ã¯ã»ã¹ã§ããããšã«æ³šæããŠãã ããã ãã®ãã£ã¬ã¯ããªã¯ãã³ãã³ããifuseã/ Desktop / Media /ãã䜿çšããŠããŠã³ãã§ããŸãã
ããã€ã¹ã«ãžã§ã€ã«ãã¬ã€ã¯ãè¡ãããAFC2ãµãŒãã¹ãã€ã³ã¹ããŒã«ãããå Žåããã¡ã€ã«ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ã®å¯èœæ§ãå€§å¹ ã«æ¡å€§ããŸãã AFC2ã¯åãAFCã§ã `/ var / mobile / Media`ãã£ã¬ã¯ããªã ãã§ãªãããã¡ã€ã«ã·ã¹ãã å šäœã«ã®ã¿ã¢ã¯ã»ã¹ã§ããŸãã ããã€ã¹ã®ã«ãŒããã¡ã€ã«ã·ã¹ãã ã¯ããifuse --rootã/ Desktop / Media /ãã®ããã«ããŠã³ãã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ããŒã¿ãžã®ã¢ã¯ã»ã¹ã®å Žåãšåæ§ã«ãã³ãã³ããfusermount âuã/ Desktop / Mediaãã䜿çšããŠãããã€ã¹ã®ã¢ã³ããŠã³ããå®è¡ããŸãã
FILE_RELAY
File_relayã¯ããŸãç¥ãããŠããªãiOSãµãŒãã¹ã®1ã€ã§ãä»ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯å©çšã§ããªãããŒã¿ãåä¿¡ã§ããå ŽåããããŸãã ãã®ãµãŒãã¹ã¯ã2.0ããïŒiOSã¯iPhone OSãšãåŒã°ããŠããŸããïŒiOSã®ãã¹ãŠã®ããŒãžã§ã³ã«ååšããŸãããå©çšå¯èœãªããŒã¿ã®ãªã¹ãã¯ããŒãžã§ã³ããšã«ç°ãªããŸãã
file_relayãµãŒãã¹ãéããŠããŒã¿ãååŸããã«ã¯ã `filerelaytest`ãŠãŒãã£ãªãã£ã䜿çšã§ããŸãïŒ` --enable-dev-tools`ãã©ã¡ãŒã¿ãŒã `libimobiledevice`èšå®äžã«æå®ãããŠããå Žåã«ã®ã¿ã³ã³ãã€ã«ãããŸãïŒïŒ
santoku@santoku-vm:~$ filerelaytest Connecting... Requesting AppleSupport, Network, VPN, WiFi, UserDatabases, CrashReporter, tmp, SystemConfiguration Receiving ......................................................................................................... Total size received: 393414 santoku@santoku-vm:~$
iOS 8ã® `file_relay`ã®ãœãŒã¹
AppleTVã®ããŒã¹ãã³ãBluetoothã®ãã£ãã·ã¥CoreLocation CrashReporter CLTMã¯SafeHarbor SystemConfiguration Ubiquityã®UserDatabases AppSupporãã³ãã€ã¹ã¡ãŒã«VPNã®WiFi WirelessAutomation MapsLogs NANDDebugInfo IORegUSBDevice VARFS HFSMeta tmpã®MobileAsset GameKitLogsããã€ã¹-O-MaticãMobileDeleteã¯ãã¢ãã¬ã¹åž³FindMyiPhone DATAACCESS DataMigrator EmbeddedSocial MobileCal MobileNotesã¢ã«ãŠã³ããitunesstoredããŒããŒãã®ããã¯ããŠã³MobileBackup MobileInstallation MobileMusicPlayerãããã¯ãŒã¯åçãDEMOD
ãã®ã³ãã³ãã¯ãfile_relayãµãŒãã¹ã«æ¥ç¶ãããœãŒã¹ã®åºå®ã»ããïŒAppleSupportãNetworkãVPNãWiFiãUserDatabasesãCrashReporterãtmpãSystemConfigurationïŒãèŠæ±ããŸãã ãã®ãããªåãœãŒã¹ã¯ãããã€ã¹ããã®1ã€ä»¥äžã®ãã¡ã€ã«ã§ãã iOS 8ã®ãœãŒã¹ã®å®å šãªãªã¹ãã«ã€ããŠã¯ããµã€ãããŒãã芧ãã ããã ç¹å®ã®ãœãŒã¹ããªã¯ãšã¹ãããã«ã¯ãåã«ãã®ååã `filerelaytest`ã®ãã©ã¡ãŒã¿ãŒãšããŠäœ¿çšããŸãïŒ
santoku@santoku-vm:~$ filerelaytest Accounts Connecting... Requesting Accounts Receiving .......... Total size received: 31217 santoku@santoku-vm:~$
çµæïŒã€ãŸããæœåºãããããŒã¿ïŒã¯ãçŸåšã®ãã£ã¬ã¯ããªã®dump.cpio.gzã«æžã蟌ãŸããŸãã æšæºã®gunzipããã³cpioãŠãŒãã£ãªãã£ã䜿çšããŠå±éã§ããŸãã
santoku@santoku-vm:~$ gunzip dump.cpio.gz santoku@santoku-vm:~$ cpio -idmv < dump.cpio . ./var ./var/mobile ./var/mobile/Library ./var/mobile/Library/Accounts ./var/mobile/Library/Accounts/Accounts3.sqlite ./var/mobile/Library/Accounts/Accounts3.sqlite-shm ./var/mobile/Library/Accounts/Accounts3.sqlite-wal ./var/mobile/Library/Preferences ./var/mobile/Library/Preferences/com.apple.accountsd.plist 6297 blocks santoku@santoku-vm:~$
iOS 8ããåã¯ããã®ãµãŒãã¹ã¯éåžžã«äŸ¿å©ã§ãä»ã®ã€ã³ã¿ãŒãã§ã€ã¹ããã¢ã¯ã»ã¹ã§ããªãããŒã¿ãååŸã§ããŸããïŒããšãã°ãããã¯ã¢ãããæå·åãããŠããå ŽåïŒã ãã ããiOS 8以éãAppleã¯è¿œå ã®ãã§ãã¯ãå°å ¥ããŸãããfile_relayãµãŒãã¹ãæ©èœããããã«ã¯ãAppleã«ãã£ãŠçœ²åãããç¹å¥ãªæ§æãããã¡ã€ã«ãããã€ã¹ã«ã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
ãã®ãããªãããã¡ã€ã«ã `/ Library / Managed Preferences / mobile /`ãã£ã¬ã¯ããªã«ã€ã³ã¹ããŒã«ãããšããã¡ã€ã« `com.apple.mobile_file_relay.plist`ã次ã®å 容ã§äœæãããŸãïŒ
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>Enabled</key> <true /> </dict> </plist>
å®è¡æã«ãfile_relayãã¯ãã®ãã¡ã€ã«ã®ååšãšãã®äžã®ãEnabledãããŒã®å€ããã§ãã¯ãããtrueãã«èšå®ãããŠããå Žåã«ã®ã¿ããŒã¿ãè¿ããŸãã
èªåå
ãlibimobiledeviceãã®å€§ããªç¹åŸŽã®1ã€ã¯ããã®ã©ã€ãã©ãªã¯ãããã€ã¹ãšéä¿¡ããããã®æ¢è£œã®ãŠãŒãã£ãªãã£ã«å ããŠãç¬èªã®ããŒã«ãäœæããããã®APIãæäŸããããšã§ãã ããšãã°ãããŸããŸãªããã€ã¹ãµãŒãã¹ãžã®åãã¬ãã«ã®ã¢ã¯ã»ã¹ãæäŸããPythonã®ãã€ã³ãã£ã³ã°ãå«ãŸããŠããŸãã ãã®APIã䜿çšãããšãå¿ èŠãªããŒã«ãæ£ç¢ºã«ãã°ããäœæã§ããŸãã
iCloud
iOS 5以éãããã€ã¹ã¯iCloudã¯ã©ãŠãã«ç¬èªã®ããã¯ã¢ãããäœæã§ããåæã»ããã¢ããäžã«ãã®ãããªã³ããŒããå埩ã§ããŸãã ããŒã¿ã«ã¢ã¯ã»ã¹ããã«ã¯ãApple IDãšãã¹ã¯ãŒãã®ç¥èãå¿ èŠã§ãã ãã®ããã®1ã€ã®ãªãŒãã³ãœãŒã¹ãœãªã¥ãŒã·ã§ã³ã¯iLootã§ãã ãã®ãŠãŒãã£ãªãã£ã¯éåžžã«äœ¿ããããã®ã§ã説æã¯äžèŠã§ããAppleIDãšãã¹ã¯ãŒããå ¥åããåºåãiCloudããããŠã³ããŒãããŸãã å·çæç¹ã§ã¯ãiLootã¯2段éèªèšŒãæå¹ã«ãªã£ãŠããã¢ã«ãŠã³ãã§ã¯æ©èœããŸããã
ãããã«
ãã®èšäºã§ã¯ãå©çšå¯èœãªiOSããã€ã¹ããããŒã¿ãæœåºããæ¹æ³-çµæžçã³ã¹ããå¿ èŠãšããªãæ¹æ³-ã«ã€ããŠè©±ãããšããŸããã æœåºãããããŒã¿ã®åæãªã©ãç 究ã®éèŠãªåŽé¢ã¯èå°è£ã«æ®ãããŸãã-ãã®ãããã¯ã¯ã¯ããã«åºç¯ã§ãããiOSã®ããŒãžã§ã³ãšã€ã³ã¹ããŒã«ãããŠããããã°ã©ã ã«å€§ããäŸåããŠãããããåæã®ãããã¯ããäžè¬ã«ãæããã«ããããšã¯é£ããããã§ãã ããã§ããæ瀺ãããè³æãèå³æ·±ããã®ã§ãããçãããããããæ°ããããšãåŠãã ããšãé¡ã£ãŠããŸãã ããããŒãããã³ã°ïŒ

2015幎2æããæåã«Hackerèªã«æ²èŒãããŸããã
æçš¿è ïŒAndrey BelenkoïŒ @abelenko ïŒ
ããã«ãŒã賌èªãã