Slide 1
Slide 1
Slide 1
Slide 1
Slide 1
Slide 1

PRESENTATION MATERIALS

PHOTOS / VIDEOS

Official conference photos and HD videos will be made available in the next 2-3 weeks. Please follow @hitbsecconf on Twitter for links or join our Facebook Group

Ivo Pooters (Senior Digital Forensic Investigator, Fox-IT)

PRESENTATION TITLE: Turning Android Inside Out

PRESENTATION ABSTRACT:

In 2011 a team of Fox-IT forensic experts won the DFRWS 2011 challenge which focused on advancing forensic analysis of Android mobile devices. This presentation shows how the challenge was completed and discusses some of the results in detail such as carving of SQ lite databases, understanding YAFFS2 file systems and visualization of the facts. The winning submission for the DFRWS2011 Forensics Challenge was created by Ivo Pooters, Steffen Moorrees & Pascal Arends from Fox-IT in the Netherlands and has multiple parts:

o An open source toolkit for extracting and analyzing data stored on Android devices;
o The analysis of the Challenge scenario that addresses the scenario questions;
o Tool output organizing extracted data to facilitate analysis;
o Technical documentation detailing the data structures and low-level analysis required to develop tools.

The submission developed Python utilities for extracting information from the Android data in both scenarios. For the Scenario 1, data structures were carved from the dd image. For the Scenario 2, the YAFFS2 file system was mounted in Linux and information was extracted from files and databases on the system. The report provided a great overall synthesis of evidence and application to the overall scenario, including an analysis of malware installed on one device. The analysis culminated with an impressive visual reconstruction of evidence.

ABOUT IVO POOTERS

Ivo Pooters is a senior digital forensic investigator and trainer at Fox-IT. He graduated from the Technical University of Eindhoven in the area of mobile device forensics on forensic data acquisition from smart phones. Ivo has been in charge of numerous digital investigations and is specialized in the area of mobile device forensics. He has published in the digital investigations magazine and presented at international summits on the topic of digital forensics on Android devices.

Okura Hotel Amsterdam
Ferdinand Bolstraat 333, 1072 LH Amsterdam,
The Netherlands

1-Day Intensive Training Sessions – 21st of May / 0900 – 1800

 

SPECIAL OPS 1  - WIRELESS SECURITY KUNGF00

SPECIAL OPS 2  – THE ART OF EXPLOITING SQL INJECTION FLAWS

SPECIAL OPS 3 – MOBILE APPLICATION HACKING – ATTACK & DEFENSE



2-Day Hands on Training Sessions – 22nd – 23rd of May / 0900 – 1800

TECH TRAINING 1  – HUNTING WEB ATTACKERS

TECH TRAINING 2  – ADVANCED LINUX EXPLOITATION METHODS

TECH TRAINING 3  - ADVANCED APPLICATION HACKING – ATTACKS, EXPLOITS & DEFENSE

 

 



3-Day Hands on Training Sessions – 21st, 22nd & 23rd of May / 0900 – 1800

TECH TRAINING 4  – THE EXPLOIT LABORATORY: ADVANCED EDITION




QUAD TRACK CONFERENCE – 24th & 25th of May / 0900 – 1800

Featuring keynotes by BRUCE SCHNEIER and ANDY ELLIS



EVENT ORGANIZER

LOCAL PARTNER

PLATINUM SPONSORS

GOLD SPONSORS

TITANIUM SPONSOR (POST CONFERENCE RECEPTION + SPEAKER RECEPTION)

SILVER SPONSOR

HACKWEEKDAY SPONSOR

ALCO_PWN SPONSOR (POST CONFERENCE RECEPTION)

HITB LAB / SIGINT SPONSOR

NETWORK SPONSORS AND UPLINK

ADDITIONAL SUPPORT BY

SUPPORTING MEDIA

FRIENDS OF HITB

Copyright © 2012 Hack In The Box | http://www.hackinthebox.org

( / 10 )