obrienforensics.blogspot.com
Android Cloud Forensics: January 2014
http://obrienforensics.blogspot.com/2014_01_01_archive.html
Wednesday, January 22, 2014. Welcome to my blog, I am a senior at Champlain College. This semester I will be conducting a research project on cloud apps on android devices. This research is part of my Capstone class here at Champlain. From now until the end of the semester I will be keeping this blog updated with my research of these applications. Subscribe to: Posts (Atom). Other Blogs to Follow. Google Drive App vs. Mobile Web Browser. Patrick OBrien is currently a senior at Champlain College, he is pu...
obrienforensics.blogspot.com
Android Cloud Forensics: Final Findings
http://obrienforensics.blogspot.com/2014/04/final-findings.html
Thursday, April 17, 2014. While looking at the data that was retrieved from the Dropbox folder I was able to find information that detailed the app version along with the device type and the android version that the device is running. This data was found in the prefs.db database and the table is DropboxPersistentPrefs. I was unable to retrieve user information from the dropbox data, however I was able to find a listing of all of the files along with the timestamps for each of them. Within the Shared Pref...
lahaie4n6.blogspot.com
Under the Hill Forensics: January 2014
http://lahaie4n6.blogspot.com/2014_01_01_archive.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Monday, January 20, 2014. IDrive Forensics: Up in the Clouds. Welcome to my first blog post for my Capstone project! I will be doing my Capstone on a cloud service called IDrive. Before I start with what I am doing, let me introduce myself. My name is Colby Lahaie. And I am currently a senior attending Champlain College. In the Computer and Digital Forensics. For this p...
lahaie4n6.blogspot.com
Under the Hill Forensics: Hidden Behind the Cumulonimbus Part 2A
http://lahaie4n6.blogspot.com/2014/04/the-cloud-continues-to-dissipate.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Sunday, April 13, 2014. Hidden Behind the Cumulonimbus Part 2A. This is part two of "Hidden Behind the Cumulonimbus Part. Blog post. This blog continues to cover the IDTEMP folder. Delete and Archive Cleanup Files. After deleting files within IDrive there is one additional file created in the IDTEMP folder. This files is called “Delete.txt”. This file is similar to the ...
lahaie4n6.blogspot.com
Under the Hill Forensics: March 2014
http://lahaie4n6.blogspot.com/2014_03_01_archive.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Friday, March 21, 2014. Hidden Behind the Cumulonimbus. After conducting some additional analyses, I have found a very important folder. I found this folder located at: C: Users Capstone PC AppData Local IDrive. This folder is called IDTEMP. However, after searching through the RAM image, with WinHex, which I dumped with DumpIt, I found an entry pointing to this folder.
lahaie4n6.blogspot.com
Under the Hill Forensics: Hidden Behind the Cumulonimbus Part 2
http://lahaie4n6.blogspot.com/2014/04/the-cloud-begins-to-dissipate.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Sunday, April 13, 2014. Hidden Behind the Cumulonimbus Part 2. I have been very busy over the past few weeks trying to finish analyzing my data and finalizing my capstone paper. This blog post is a continuation of the previous and will consist of 2 parts because there is a lot of data that I would like to present to my fellow investigators. Within this file, an investig...
lahaie4n6.blogspot.com
Under the Hill Forensics: Not a Cloud in the Sky
http://lahaie4n6.blogspot.com/2014/04/not-cloud-in-sky_16.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Wednesday, April 16, 2014. Not a Cloud in the Sky. This is my last blog post for my Capstone and will detail my conclusion for my findings. After conducting this forensic analysis of the IDrive Windows application, the investigator found that the data is stored in two default locations, which are: “ C: Program Files (x86) IDriveWindows. Furthermore, if a user shares fil...
obrienforensics.blogspot.com
Android Cloud Forensics: April 2014
http://obrienforensics.blogspot.com/2014_04_01_archive.html
Thursday, April 17, 2014. While looking at the data that was retrieved from the Dropbox folder I was able to find information that detailed the app version along with the device type and the android version that the device is running. This data was found in the prefs.db database and the table is DropboxPersistentPrefs. I was unable to retrieve user information from the dropbox data, however I was able to find a listing of all of the files along with the timestamps for each of them. Within the Shared Pref...
obrienforensics.blogspot.com
Android Cloud Forensics: March 2014
http://obrienforensics.blogspot.com/2014_03_01_archive.html
Wednesday, March 12, 2014. Pull, Analyze, Repeat. The first step that I had to perform to do my research is to root the device, to do this I used a tutorial that I found here. Using the su command I could copy the data from the /data/data folder to the sdcard which I had unrestricted access to. After I had copied the data to the sdcard I could then pull the data to my hard drive using the command. The highlighted folders are for the Dropbox application and for the Google Drive application. Patrick OBrien...
lahaie4n6.blogspot.com
Under the Hill Forensics: The Cloud Begins to Dissipate
http://lahaie4n6.blogspot.com/2014/04/the-cloud-begins-to-dissipate_16.html
Under the Hill Forensics. A blog about my capstone and my life as a forensicator. And no, I do not live in the Shire with Bilbo Baggins. Wednesday, April 16, 2014. The Cloud Begins to Dissipate. In this blog post I will be talking about the local database file and the Session files. After a backup has completed within IDrive, a local SQLite 3 database file is create. This file is located: C: Users Username AppData Local IDrive IBCOMMON idriveusername LDBNEW. Number (DIRID), the file. The “Backup...