信息网络安全 ›› 2021, Vol. 21 ›› Issue (12): 44-50.doi: 10.3969/j.issn.1671-1122.2021.12.007

• 入选论文 • 上一篇    下一篇

一种基于Checkm8漏洞的iPhone取证方法研究

陈光宣1, 吴家健1(), 操丹妮1, 谢清泉2   

  1. 1.浙江警察学院基于大数据架构的公安信息化应用公安部重点实验室,杭州 310053
    2.苏州龙信信息科技有限公司,苏州 215125
  • 收稿日期:2021-10-10 出版日期:2021-12-10 发布日期:2022-01-11
  • 通讯作者: 吴家健 E-mail:jiajianwuinv@163.com
  • 作者简介:陈光宣(1984—),男,浙江,副教授,博士,主要研究方向为电子数据取证、大数据、信息安全|吴家健(2001—),男,浙江,本科,主要研究方向为iOS取证、信息安全|操丹妮(2000—),女,浙江,本科,主研究方向为iOS取证|谢清泉(1988—),男,福建,工程师,本科,主要研究方向为电子数据取证
  • 基金资助:
    浙江省自然科学基金委员会基础公益研究计划项目(LGF19F020006);国家级大学生创新创业训练计划(202111481006);浙江省大学生科技创新活动计划暨新苗人才计划(2021R422003)

Research on iPhone Forensic Method Based on Checkm8 Vulnerability

CHEN Guangxuan1, WU Jiajian1(), CAO Danni1, XIE Qingquan2   

  1. 1. Key Laboratory of Public Security Information Application Based on Big-data Architecture, Ministry of Public Security, Zhejiang Police College, Hangzhou 310053, China
    2. Suzhou Longxintec Co., Suzhou 215125, China
  • Received:2021-10-10 Online:2021-12-10 Published:2022-01-11
  • Contact: WU Jiajian E-mail:jiajianwuinv@163.com

摘要:

Checkm8漏洞是一种基于iPhone手机固件强制升降机模式的硬件漏洞。在电子数据取证工作中,针对未知锁屏密码的iPhone手机检材,文章提出一种利用Checkm8漏洞绕过密码验证提取iPhone手机数据的方法,并通过实验演示了漏洞利用、证据数据挖掘与提取、数据解密分析与证据展示。同时利用堆漏洞对锁屏状态下的iPhone手机进行最高权限提升,获取端口通信权限与数据提取传输权限,解决了密码缺失情况下数据提取问题。

关键词: 电子数据取证, iPhone, Checkm8漏洞, 锁屏密码

Abstract:

The Checkm8 vulnerability is a hardware vulnerability based on the device firmware upgrade(DFU) mode of the iPhone firmware. This paper proposed a method of using Checkm8 vulnerability to bypass password verification to extract iPhone data, and demonstrated the exploitation of the vulnerability, digital data mining and extraction, data decryption analysis and evidence display. At the same time, the heap vulnerabilities were utilized to upgrade the highest authority, obtain the authority of port communication and transmission on the iPhone in the locked state, which could solve the problem of data extraction in the absence of passwords. This method has high practical value for forensic science.

Key words: digital forensics, iPhone, Checkm8 vulnerability, lockdown password

中图分类号: