Android 8.0 Forensics through autopsy 4.17 ( device= Samsung C7000 ) - General Questions and Answers

Hi !
I wanted to ask the experts ,some details regarding forensic analysis of android device.
I have been stuck for few months and need urgent assistance.
device details = Samsung C7000
I rooted the phone suing magisk and odin tool.
The version is android OS 8.0 and memory size is 64 gb ( adb image size is 61.9 gb ).
I installed some apps like ( foodpanda, daraz, wish , health apps and logged in fb and linked )
I created adb image for this device .
Now I am analyzing the dd image in autopsy 4.19, but I cannot see the userdata partition data,
the use case is not completed yet, it has been analyzing since 24 hours.
I am attaching screenshots for reference.
Kindly help me..

Related

Mount your Android device properly on Linux.

Hi all ,
This topic is about how to mount your Android device and have it transferring files easily & smoothly using Linux on your PC.
- This topic is related to solving the unstable file transfer between the linux system and MTP file system included in Android version 4.xxx & Higher ( Starting from Ice Cream Sandwich - ICS ).
- All Android version before ICS should not continue reading , as their devices should be read as ( Mass storage Device ) , in other words , the Linux OS will read devices as if it was a USB flash memory.
- The is solution for the laggy Folder opening , Solving the problem of which the files transfer suddenly stops before completing the transfer , specially with big files such as Films , Albums ,...etc.
- I'M NOT SURE that this is going to work with all ICS , JB & Higher devices but the below was tested on a Samsung Tab 2 P5100 device running Jelly bean ( JB ) 4.1.2 official stock ROM , & The below worked perfectly for me.
- Using Linux Mint 14 Cinnamon ( MINT is based on UBUNTU ) / 64 Bit version / Kernel Upgraded _unofficially_ to the latest stable kernel release 3.9.2
1. get Android SDK for Linux from : developer.android.com/sdk/index.html
2. Unpack it to your location
Note: if you have already downloaded Android SDK before, check that the version of SDK tools is latest.
3. turn on Debug mode in your Samsung tab.
4. run the command:
[your location]/android-sdk-linux_x86/tools/ddms
OR just open the folder TOOLS from the extracted folder & Run DDMS ( RUN it normally , Not RUN IN TERMINAL).
5. Click in menu Device -> File Explorer
Here you drag-n-drop your files to any location on your device.
Source (Including snapshots) :
- misha.beshkin.lv/how-to-copy-files-to-samsung-galaxy-ii-tab-from-linux-via-usb/
Thank you & Sorry if my topic looks messy , this is my first time here.
mehrdadfisher said:
This is my own experience as well.
Would it be possible please send me the details.
Click to expand...
Click to collapse
Hi there , wud u plz clarify what do u mean by the details ? , I think the details are already mentioned up there , If you are talking about using the developer's SDK to transfer files.

Oppo F3 Root Help

Dear Xda,
Im An Oppo user my Device details As follows.
Device: Oppo F3 ( CPH1609)
MTK6750T
4Gb Ram, 64 GB ROM
Running on ColorOs 3.0.0i (Based on Android 6.0)
There are lot of problems / bugs in Os which Oppo Even failed to rectify.
When ever i Mailed them they simply quoting their common quotes
So i decided to Root my phone to develop ( no i cant do it lone )
During search of Root i found few obstacles
1) Oppo made decision to remove fastboot option fron their device
Ref: https://forum.xda-developers.com/r7-plus/help/decision-oppo-bootloader-fastboot-t3348114
2) MTK droid Tools not fully supporting the chipset
Ref:https://forum.xda-developers.com/attachment.php?attachmentid=4178413&thumb=1&d=1497202499
3) One click Root is not working ( king, farma etc)
4) cannot obtain boot & Recovery imgs to development
5) i thought stock firmware flash file may have useful but there are 2 types of probles
(A) flashablezip version : it has boot. Img but no recovery.img included. Also it is With. Ozip Not with. Zip extension
(B) PC version : it is like encrypted file. With. Ofp extension And With some other type file. And it is not flashing through SP-FLASH TOOLS. The flashing tool is different.
Ref https://m.youtube.com/watch?v=qw4HIQER0mg
Guys thease are my problems. Coz of those i failed to root my device.
My only Hope is Xda, you people know better than me ( probably Best) . Please analyze and and give suggestions.
Thanks In Advance

[Q] Please link for ZTE K3DX-V5G firmware.

Please link for ZTE K3DX-V5G firmware.
ZTE K3DX-V5G firmware
Why do you need ZTE K3DX-V5G firmware?
Is there something wrong with your device?
Do you recommend buying the ZTE K3DX-V5G?
The brand name is V5 or ZTE or Guan or Mango.
It is the same device, manufatured by V5 and sold by ZTE, Guan and Mango.
Guan K3DX-V5G
https://deviceatlas.com/device-data/devices/guan/k3dx-v5g/28213760
BangGearWatch | ZTE V5G-K3DX
https://www.banggearwatch.com/pricetracker/zte-v5g-k3dx-5-5-inch-3gb-1369255/
The price was €64 at BangGood, for a short time.
The price was €70 at MyeFOX.
V5 K3DX-V5G 3GB RAM 32GB ROM Qualcomm Snapdragon 617 1.5GHz Octa Core FHD Display 5.5 inches Android 5.1 4G LTE Smartphone
https://www.myefox.fr/telephones/v5...a-core-fhd-ecran-55-pouces-android-5-g-223880
K3DX-V5G supports naked-eye 3D and eye-tracking.
It has a K3DX display with column interlaced mode.
Therefore is fully compatible with PhereoRol3D app.
https://github.com/JackDesBwa/PhereoRoll3D
Get the latest release here
https://github.com/JackDesBwa/PhereoRoll3D/releases
Have you tried PhereoRol3D ?
BootStomp and DR.CHECKER
Your phone has a locked bootloader.
You need to run these two tools: DR.CHECKER and BootStomp.
DR.CHECKER : A Soundy Vulnerability Detection Tool for Linux Kernel Drivers.
It is a single script!
This repo contains all the sources, including setup scripts. Now with an Amazing UI to view the warnings along with corresponding source files.
https://github.com/ucsb-seclab/dr_checker
BootStomp
https://seclab.cs.ucsb.edu/academic/publishing/#bootstomp-security-bootloaders-mobile-devices-2017
Did you manage to root ZTE K3DX-V5G ?
Partitions table
Get an excellent partitions table of ZTE K3DX-V5G
This format is ideal for recovery.
Device Info HW
https://play.google.com/store/apps/details?id=ru.andr7e.deviceinfohw&hl=en_US
NOTE - Find attached the partitions table of SuperD D1 (SuperD C1001). It is another device with Naked-eye 3D and eye-tracking.
Do you own a ZTE K3DX-V5G ?
You do not own a ZTE K3DX-V5G, do you?
V5 K3DX V5G Smartphone Unboxing (3D Video Camera)
https://www.youtube.com/watch?v=KkQhQszdSYs
Mango K3DX-V5G
https://v.youku.com/v_show/id_XMjgxMDI4OTcyOA==.html
3D Dongdong APP: Over 10,000 3D movies provided
http://en.k3dx.com/prolist/7/17.html
Thank you for many information about it.
I did not own it now due to it heat up too much compare with SD 625 / 636 phone.
Discussion V5 K3DX-V5G at russian 4pda forum
Discussion V5 K3DX-V5G
http://4pda.ru/forum/index.php?showtopic=944204
There is new firmware available from chinese versions (latest 1.3)
Firmware in China
http://www.shuajibao.com/rom/Zte/23777
Version 1.3 is not official. It is a custom ROM by this russian guy... Sidorovvitalik.
But development has already stopped because he is selling his ZTE V5 K3DX-V5G.
K3DX V5G stockrom
Please can someone upload the stockrom.
After scouring the internet for hours, I stumbled upon this post:
https://4pda.ru/forum/index.php?showtopic=944204&st=220
And guess what, I found the firmware for the device! Eventually, I was able to fix my bricked K3DX V5G, and here it is:
https://yadi.sk/d/TSjrTYbKBV4KWA
What I did was:
1. Decompressing the file
2. Flashing it with fastboot
3. Device resurrected!
Fastboot commands:
Code:
fastboot flash:raw boot boot.img
fastboot flash system system.img
edit: found out that it is a clone of ZTE v5 pro N940SC
Ma'am/Sir. Can i ask what usb driver did you use to detect your k3dx-v5g? Because mine is not detecting. Thanks in advance.
Ma'am/Sir. Can i ask what usb driver did you use to detect your k3dx-v5g? Because mine is not detecting. Thanks in advance.
asce16 said:
Ma'am/Sir. Can i ask what usb driver did you use to detect your k3dx-v5g? Because mine is not detecting. Thanks in advance.
Click to expand...
Click to collapse
Are you on Linux or Windows?
Ma'am/Sir. What usb driver did you use to detect your k3dx v5g phone? I cant find compatible to mine, my pc cant detect my k3dx v5g phone. Plsss. Send link. Thanks in advance.
B83C said:
Are you on Linux or Windows?
Click to expand...
Click to collapse
Window.
B83C said:
Are you on Linux or Windows?
Click to expand...
Click to collapse
Also ma'am/sir. can i ask a little favor? Can you send me full guide how to flash this file. Plssss
asce16 said:
Also ma'am/sir. can i ask a little favor? Can you send me full guide how to flash this file. Plssss
Click to expand...
Click to collapse
Hmm well, have u tried peeking at the device manager when you phone is connected to your PC in fastboot mode?
If there's an entry showing your device you will need grab a fastboot binary to flash the firmware.
Here's a link to the tool called minimal ADB and Fastboot: here
You will also need to extract the firmware to somewhere in your drive.
Having done all the extraction and installation,
and since you're on Windows, you should do:
Bash:
\path\to\fastboot flash:raw boot \path\to\boot.img
\path\to\fastboot flash system \path\to\system.img
where \path\to\fastboot points to the path where you have extracted/installed the tool (or if you have added its path to the PATH environment variable, you can avoid the hassle to write the full path), and \path\to\boot.img and system.img points to absolute path of the extracted firmware.
Then, you are good to go!
B83C said:
Hmm well, have u tried peeking at the device manager when you phone is connected to your PC in fastboot mode?
If there's an entry showing your device you will need grab a fastboot binary to flash the firmware.
Here's a link to the tool called minimal ADB and Fastboot: here
You will also need to extract the firmware to somewhere in your drive.
Having done all the extraction and installation,
and since you're on Windows, you should do:
Bash:
\path\to\fastboot flash:raw boot \path\to\boot.img
\path\to\fastboot flash system \path\to\system.img
where \path\to\fastboot points to the path where you have extracted/installed the tool (or if you have added its path to the PATH environment variable, you can avoid the hassle to write the full path), and \path\to\boot.img and system.img points to absolute path of the extracted firmware.
Then, you are good to go!
Click to expand...
Click to collapse
Ma'am/sir. Thanks, it's fix now. Thanks for the help. Godbless and stay safe.
Hello, in case you are looking for a twrp image for the device, here's one I have ported myself:
TWRP_N940Sc_V3
MediaFire is a simple to use free service that lets you put all your photos, documents, music, and video in a single place so you can access them anywhere and share them everywhere.
www.mediafire.com
B83C said:
Hello, in case you are looking for a twrp image for the device, here's one I have ported myself:
https://www.mediafire.com/file/0547s4g8hdojctq/TWRP_N940Sc_V3.img/fileTh
Click to expand...
Click to collapse
Thankyou! Uhm is there any custom rom? Can you please port a custom rom or upload please i really need it[/url]
John072021 said:
Thankyou! Uhm is there any custom rom? Can you please port a custom rom or upload please i really need it[/url]
Click to expand...
Click to collapse
I regret to tell you that, no. Currently I have been using the phone as a debian server, since the LCD has been inadvertently broken ( I exerted too much force on it ). Moreover, the device doesn't recognize its battery, which suggests that I might have broken some part of it. Therefore, I have kinda lost any hopes for it. Plus, my linux machine is not powerful enough to build an android OS ( what do you expect much from an intel celeron? ).
PS: I might do it once I get my hands on a much powerful one, or maybe a powerful enough VPS? I am not quite sure but currently I am still in high school, meaning that I may or may not have time....
Best regards,
B83C

Lenovo Zuk Z2 plus Android 12 gsi bootloop

I flash android 12 beta Google gsi from the link below, I flashed it with twrp and I am facing bootloop in my z2 plus, any solution??
Generic System Image releases | Android Developers
Generic System Image releases | Platform | Android Developers
developer.android.com
I flashed the arm64
Exactly same problem here. If you find a solution please please please give a message on [email protected]
I am busy in fixing my sim card not working
If you flash a GSI image ( read: Vanilla ROM - AOSP ) then Android's OEM-created /vendor & /modem partitions gets lost. Probably /esf partition, too.
Hence you must not be surprised that phone is bootlooping
jwoegerbauer said:
If you flash a GSI image ( read: Vanilla ROM - AOSP ) then Android's OEM-created /vendor & /modem partitions gets lost. Probably /esf partition, too.
Hence you must not be surprised that phone is bootloop
Click to expand...
Click to collapse
jwoegerbauer said:
If you flash a GSI image ( read: Vanilla ROM - AOSP ) then Android's OEM-created /vendor & /modem partitions gets lost. Probably /esf partition, too.
Hence you must not be surprised that phone is bootlooping
Click to expand...
Click to collapse
This shouldn't be the case because earlier I have formatted my device using so flash tool. Each and every system partition got lost including efs(nvdata and nvram in my case). I actually found another reason: Kernel is 32 bit which doesn't support 64 bit gsi. I tried finding a 64 bit firmware for my device but there's none.

Toshido T12-EEA, HowTo root it?

Hi Everyone, I hope somebody can help me I've a Toshido Android tablet with mainly these specifications below:
- OS: Android 10;
- RAM 4GB;
- STORAGE: 64GB.
I own this tablet from several time, and now I'd like to root it, but it does not seem to be a widespread model. Could somebody help?...
Thanks in advance for any help, please sorry for my english and my poor experience too, let me know if I forgot something
Look inside here ( note: the method suggested is generic )
[ GUIDE ] [ ANDROID 10 ROOT ] [ HOW TO ] Patching Boot.img with Magisk
Here's how to root the Pixel 3 running on official and stock Android 10 release, step by step : (not tested on Pixel 3 XL but it might work the same, just use the right firmware for your device) What do you need : > Pixel 3 phone with Android...
forum.xda-developers.com
xXx yYy said:
Look inside here ( note: the method suggested is generic )
[ GUIDE ] [ ANDROID 10 ROOT ] [ HOW TO ] Patching Boot.img with Magisk
Here's how to root the Pixel 3 running on official and stock Android 10 release, step by step : (not tested on Pixel 3 XL but it might work the same, just use the right firmware for your device) What do you need : > Pixel 3 phone with Android...
forum.xda-developers.com
Click to expand...
Click to collapse
Thank you, I downloaded and installed Magisk on the tablet and yet downloaded the link of the described "Android 10 factory image" (it's valid for my Toshido tablet too, right?.. ), then I extracted all into my pc, and copied a file named "boot.img" into my tablet as described on the thread (as I understood..)...for now I wished ask you if till now I did right.. (I didn't install the "Boot.img" file yet, because I still have to install ADB and FASTBOOT tools because I tried but my Linux OS is giving me some problems w repository 'n I'm trying to solve hoping soon...)
I'd like if someone can follow me in these steps... I hope to not annoy you I'd be very gratefull if you can do, 'cause I still have very little experience...
The latest ADB / Fastboot drivers you can obtain here:
SDK Platform Tools release notes | Android Studio | Android Developers
Android SDK Platform-Tools is a component for the Android SDK.
developer.android.com
Sorry, I looked for the 32-bit version I supposed it was available on any architecture, but it doesn't seem to exist for me... I have a laptop with Linux OS on 32-bit Hardware, then I can not do anything? Thank you anyway

Categories

Resources