Difference between pages "Tools:Data Recovery" and "Chip-Off BlackBerry Curve 9320"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
(Carving)
 
(Created page with "== Tear Down == <ol start="1"> <li>Remove the back panel.</li> </ol> {| border="1" cellpadding="2" |- | 300px |- |} <ol start="2"> ...")
 
Line 1: Line 1:
= Partition Recovery =
+
== Tear Down ==
  
*[http://www.ptdd.com/index.htm Partition Table Doctor]
+
<ol start="1">
: Recover deleted or lost partitions (FAT16/FAT32/NTFS/NTFS5/EXT2/EXT3/SWAP).
+
<li>Remove the back panel.</li>
 +
</ol>
  
*[http://www.diskinternals.com/ntfs-recovery/ NTFS Recovery]
+
{| border="1" cellpadding="2"
: DiskInternals NTFS Recovery is a fully automatic utility that recovers data from damaged or formatted disks.
+
|-
 +
| [[File:1-bb9320-BackPanelRemoved.jpg| 300px ]]
 +
|-
 +
|}
  
*[http://www.stud.uni-hannover.de/user/76201/gpart/ gpart]
+
<ol start="2">
: Gpart is a tool which tries to guess the primary partition table of a PC-type hard disk in case the primary partition table in sector 0 is damaged, incorrect or deleted.
+
<li>Remove the SIM and SD Memory Card.</li>
 +
</ol>
  
*[http://www.cgsecurity.org/wiki/TestDisk TestDisk]
+
<ol start="3">
: [[TestDisk]] is an OpenSource software and is licensed under the GNU Public License (GPL).
+
<li>Using a torx-6 screw driver remove the 2 visible screws on the back of the phone.</li>
 +
</ol>
  
*[http://www.stellarinfo.com/partition-recovery.htm Partition Recovery Software]
+
{| border="1" cellpadding="2"
: Partition Recovery software for NTFS & FAT system that examines lost windows partition of damaged and corrupted hard drive.
+
|-
 +
| [[File:2-bb9320-ScrewRemoval.jpg| 300px ]]
 +
|-
 +
|}
  
== See Also ==
+
<ol start="4">
 +
<li>Remove the screen protector using a shim, guitar pick, or prying tool.</li>
 +
</ol>
  
* [http://support.microsoft.com/?kbid=166997 Using Norton Disk Edit to Backup Your Master Boot Record]
+
{| border="1" cellpadding="2"
 +
|-
 +
| [[File:3-bb9320-ScreenRemoval.jpg| 300px ]]
 +
|-
 +
|}
  
== Notes ==
+
<ol start="5">
 +
<li>Remove 2 torx-5 screws.</li>
 +
</ol>
  
* "fdisk /mbr" restores the boot code in the [[Master Boot Record]], but not the partition itself. On newer versions of Windows you should use fixmbr, bootrec, mbrfix, or [[MBRWizard]]. You can also extract a copy of the specific standard MBR code from tools like bootrec.exe and diskpart.exe in Windows (from various offsets) and copy it to disk with dd (Use bs=446 count=1). For Windows XP SP2 c:\%WINDIR%\System32\diskpart.exe the MBR code is found between offset 1b818h and 1ba17h.
+
{| border="1" cellpadding="2"
 +
|-
 +
| [[File:4-bb9320-ScrewRemoval.jpg| 300px ]]
 +
|-
 +
|}
  
= Data Recovery =
+
<ol start="6">
The term "Data Recovery" is frequently used to mean forensic recovery, but the term really should be used for recovering data from damaged media.  
+
<li>Use the shim to detach the outer bezel/keyboard from the device.</li>
 +
</ol>
  
*[http://www.salvationdata.com/data-recovery-equipment/hd-doctor.htm HD Doctor Suite]
+
{| border="1" cellpadding="2"
: HD Doctor Suite is a set of professional tools used to fix firmware problem
+
|-
 +
| [[File:5-bb9320-TopPlate.jpg| 300px ]] 5-1-bb9320-TopPlate.jpg| 300px ]]
 +
|-
 +
|}
  
*[http://www.salvationdata.com SalvationDATA]
+
<ol start="7">
: Claims to have a program that can read the "bad blocks" of Maxtor drives with proprietary commands.
+
<li>Remove 4 additional torx-6 screws. The main board will now easily be separated from the back plate</li>
 +
</ol>
  
*[http://www.toolsthatwork.com/bringback.htm BringBack]  
+
{| border="1" cellpadding="2"
: BringBack offers easy to use, inexpensive, and highly successful data recovery for Windows and Linux (ext2) operating systems and digital images stored on memory cards, etc.
+
|-
 +
| [[File:6-bb9320-ScrewRemoval.jpg| 300px ]]
 +
|-
 +
|}
  
*[http://www.runtime.org/raid.htm RAID Reconstructor]
+
<ol start="8">
: Runtime Software's RAID Reconstructor will reconstruct RAID Level 0 (Striping) and RAID Level 5 drives.
+
<li>Peel off the vendor sticker.</li>
 +
</ol>
 +
{| border="1" cellpadding="2"
 +
|-
 +
| [[File:7-bb9320-VendorPlate.jpg| 300px ]]
 +
|-
 +
|}
  
* [http://www.e-rol.com/en/ e-ROL]
+
<ol start="9">
: Erol allows you to recover through the internet files erased by mistake. Recover your files online for free.
+
<li>Remove the plastic cover protecting the track pad ribbon cable, and disconnect the track pad.</li>
 +
</ol>
  
* [http://www.recuva.com/ Recuva]
+
<ol start="10">
: Recuva is a freeware Windows tool that will recover accidentally deleted files.
+
<li>Remove the final torx-4 screw located beneath the plastic protector, to remove the plastic keyboard overlay.</li>
 +
</ol>
  
* [http://www.snapfiles.com/get/restoration.html Restoration]
+
{| border="1" cellpadding="2"
: Restoration is a freeware Windows software that will allow you to recover deleted files
+
|-
 +
| [[File:8-bb9320-ScrewRemoval.jpg| 300px ]]
 +
|-
 +
|}
  
* [http://www.undelete-plus.com/ Undelete Plus]
+
<ol start="11">
: Undelete Plus is a free deleted file recovery tool that works for all versions of Windows (95-Vista), FAT12/16/32, NTFS and NTFS5 filesystems and can perform recovery on various solid state devices.
+
<li>Disconnect the ribbon cable connected to the LCD. Then using a pick separate the display from the main board.</li>
 +
</ol>
  
* [http://www.data-recovery-software.net/ R-Studio]
+
{| border="1" cellpadding="2"
: R-Studio is a data recovery software suite that can recover files from FAT(12-32), NTFS, NTFS 5, HFS/HFS+, FFS, UFS/UFS2 (*BSD, Solaris), Ext2/Ext3 (Linux) and so on.
+
|-
 +
| [[File:9-bb9320-ScreenRemoval.jpg| 300px ]]
 +
|-
 +
|}
  
* [http://www.stellarinfo.com/ Stellar Phoenix]
+
<ol start="12">
: Data recovery software services & tools to recover lost data from hard drive.
+
<li>The tear down is now complete</li>
 +
</ol>
  
* [http://www.deepspar.com/ DeepSpar Disk Imager]
+
{| border="1" cellpadding="2"
: DeepSpar Disk Imager is a dedicated disk imaging device built to handle disk-level problems and to recover bad sectors on a hard drive.
+
|-
 +
| [[File:9-1-bb9320-TearDownComplete.jpg| 300px ]]
 +
|-
 +
|}
  
* [http://digital-assembly.com/products/adroit-photo-recovery/ Adroit Photo Recovery]
+
eMMC Removal
: Adroit Photo Recovery is a photo recovery tool that uses validated carving and is able to recover fragmented photos. Adroit Photo Recovery is able
+
: to recover high definition RAW images from Canon, Nikon etc.
+
  
See also [[Data Recovery Stories]]
+
<ol start="1">
 +
<li>The eMMC is located beneath the heat shield directly above the Micro SD card slot.</li>
 +
</ol>
  
=Carving=
+
{| border="1" cellpadding="2"
*[http://www.datalifter.com/products.htm DataLifter® - File Extractor Pro]
+
|-
: Data carving runs on multiple threads to make use of modern processors
+
| [[File:10-bb9320-EMMC-Location.jpg| 300px ]]
 +
|-
 +
|}
  
*[http://www.simplecarver.com/ Simple Carver Suite]
+
<ol start="2">
: Simple Carver Suite is a collection of unique tools designed for a number of purposes including data recovery, forensic computing and eDiscovery. The suite was originally designed for data recovery and has since expanded to include unique file decoding, file identification and file classification.
+
<li>Place the main board in a stand or holder and position it approximately 2 1/2" - 3" inches away from a heat gun or device the blows super hot air.</li>
 +
</ol>
  
*[http://foremost.sourceforge.net/ Foremost]
+
{| border="1" cellpadding="2"
: Foremost is a console program to recover files based on their headers, footers, and internal data structures.
+
|-
 +
| [[File:11-bb9320-HeatShield.jpg| 300px ]]
 +
|-
 +
|}
  
*[http://www.digitalforensicssolutions.com/Scalpel/ Scalpel]
+
<ol start="3">
: Scalpel is a fast file carver that reads a database of header and footer definitions and extracts matching files from a set of image files or raw device files. Scalpel is filesystem-independent and will carve files from FATx, NTFS, ext2/3, or raw partitions.
+
<li>Monitoring the temperature the heat shield will come off easily between 190-200 Centigrade.</li>
 +
</ol>
  
*[[EnCase]]
+
{| border="1" cellpadding="2"
: EnCase comes with some enScripts that will do carving.
+
|-
 +
| [[File:12-bb9320-HeatShield.jpg| 300px ]] 13-bb9320-HeatShieldRemoved.jpg| 300px ]]
 +
|-
 +
|}
  
*[[CarvFs]]
+
<ol start="4">
: A virtual file system (fuse) implementation that can provide carving tools with the possibility to do recursive multi tool zero-storage carving (also called in-place carving). Patches and scripts for scalpel and foremost are provided. Works on raw and encase images.  
+
<li>Continue working under the high heat. With the 9315/9320's I've worked on the eMMC has been ready to lift off of the main board using tweezers immediately after removing the heat shield.</li>
 +
</ol>
  
*[[LibCarvPath]]
+
{| border="1" cellpadding="2"
: A shared library that allows carving tools to use zero-storage carving on carvfs virtual files.
+
|-
 +
| [[File:14-bb9320-EMMC-Removed.jpg| 300px ]]
 +
|-
 +
|}
  
*[http://www.cgsecurity.org/wiki/PhotoRec PhotoRec]
+
<ol start="5">
: PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from Hard Disks and CDRom and lost pictures (thus, its 'Photo Recovery' name) from digital camera memory.
+
<li>Using liquid flux, or flux paste and a soldering iron clean the pads on the eMMC in preparation for a read</li>
 +
</ol>
  
*[http://www.datarescue.com/photorescue/ PhotoRescue]
+
{| border="1" cellpadding="2"
: Datarescue PhotoRescue Advanced is picture and photo data recovery solution made by the creators of IDA Pro. PhotoRescue will undelete, unerase and recover pictures and files lost on corrupted, erased or damaged compact flash (CF) cards, SD Cards, Memory Sticks, SmartMedia and XD cards.
+
|-
 +
| [[File:15-bb9320-EMMC-Cleanup.jpg| 300px ]]  
 +
| [[File:16-bb9320-EMMC-Clean.jpg| 300px ]]
 +
|-
 +
|}
  
* [https://www.uitwisselplatform.nl/projects/revit RevIt]
+
<ol start="6">
: RevIt (Revive It) is an experimental carving tool, initially developed for the DFRWS 2006 carving challenge. It uses 'file structure based carving'. Note that RevIt currently is a work in progress.
+
<li>The eMMC is now ready to read using the appropriate adapter/programmer and software.</li>
 +
</ol>
  
* [http://jbj.rapanden.dk/magicrescue/ Magic Rescue]
+
At the time of this writing (2013OCT29) the eMMC that was removed in this example was read using an UP828 programmer via the "VBGA169E" adapter. The resulting image was then parsed via the CelleBrite Physical Analyzer (V. 3.8.5.108).
: Magic Rescue is a file carving tool that uses "magic bytes" in a file contents to recover data.
+
 
+
* [[FTK]]
+
: FTK2 includes some file carvers
+
 
+
* [[http://www.forensicswiki.org/wiki/X-Ways]]
+
: X-Ways Forensic provides a robust list of file types as well as the ability to specific custom file headers/trailers. File types are available for carving, identification and filtering.  
+
 
+
*[[Adroit Photo Forensics]]
+
: Adroit Photo Forensics supports data carving of popular image formats. Also supports fragmented carving using [[File_Carving:SmartCarving|SmartCarving]] and [[File_Carving:GuidedCarving|GuidedCarving]].
+

Revision as of 13:26, 30 October 2013

Tear Down

  1. Remove the back panel.
1-bb9320-BackPanelRemoved.jpg
  1. Remove the SIM and SD Memory Card.
  1. Using a torx-6 screw driver remove the 2 visible screws on the back of the phone.
2-bb9320-ScrewRemoval.jpg
  1. Remove the screen protector using a shim, guitar pick, or prying tool.
3-bb9320-ScreenRemoval.jpg
  1. Remove 2 torx-5 screws.
4-bb9320-ScrewRemoval.jpg
  1. Use the shim to detach the outer bezel/keyboard from the device.
5-bb9320-TopPlate.jpg 5-1-bb9320-TopPlate.jpg| 300px ]]
  1. Remove 4 additional torx-6 screws. The main board will now easily be separated from the back plate
6-bb9320-ScrewRemoval.jpg
  1. Peel off the vendor sticker.
7-bb9320-VendorPlate.jpg
  1. Remove the plastic cover protecting the track pad ribbon cable, and disconnect the track pad.
  1. Remove the final torx-4 screw located beneath the plastic protector, to remove the plastic keyboard overlay.
8-bb9320-ScrewRemoval.jpg
  1. Disconnect the ribbon cable connected to the LCD. Then using a pick separate the display from the main board.
9-bb9320-ScreenRemoval.jpg
  1. The tear down is now complete
9-1-bb9320-TearDownComplete.jpg

eMMC Removal

  1. The eMMC is located beneath the heat shield directly above the Micro SD card slot.
10-bb9320-EMMC-Location.jpg
  1. Place the main board in a stand or holder and position it approximately 2 1/2" - 3" inches away from a heat gun or device the blows super hot air.
11-bb9320-HeatShield.jpg
  1. Monitoring the temperature the heat shield will come off easily between 190-200 Centigrade.
12-bb9320-HeatShield.jpg 13-bb9320-HeatShieldRemoved.jpg| 300px ]]
  1. Continue working under the high heat. With the 9315/9320's I've worked on the eMMC has been ready to lift off of the main board using tweezers immediately after removing the heat shield.
14-bb9320-EMMC-Removed.jpg
  1. Using liquid flux, or flux paste and a soldering iron clean the pads on the eMMC in preparation for a read
15-bb9320-EMMC-Cleanup.jpg 16-bb9320-EMMC-Clean.jpg
  1. The eMMC is now ready to read using the appropriate adapter/programmer and software.

At the time of this writing (2013OCT29) the eMMC that was removed in this example was read using an UP828 programmer via the "VBGA169E" adapter. The resulting image was then parsed via the CelleBrite Physical Analyzer (V. 3.8.5.108).