(PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

download (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

of 19

Transcript of (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    1/19

    (DEAD) (LIVE)

    INFOSECURITYRUSSIA 2012

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    2/19

    -

    ,

    / API-

    .

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    3/19

    Type BB Smartphone BB PlayBook Android

    / + + +

    + + +

    ,

    + + +

    / /

    + - +

    + + +

    SMS/EMAIL/IM- + - +

    - + + + + + +

    + + +

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    4/19

    :

    ,

    : , , LIVE-

    :

    BLACKBERRY ( ) ANDROID (

    ) ANDROIDa

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    5/19

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    6/19

    BLACKBERRY SMARTPHONE ,

    BLACKBERRY TABLET, ANDROID - / ; ,

    /

    BLACKBERRY SMARTPHONE PUSH

    + EXCHANGE BLACKBERRY TABLET

    IMAP4, POP3 + EXCHANGEACTIVESYNC

    ANDROIDGOOGLE SYNC,

    IDLE, IMAP4, POP3 +EXCHANGE ACTIVESYNC

    PUSH

    : GUI:

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    7/19

    BLACKBERRY

    ASCII

    , (ELCOMSOFT)

    ANDROID

    PATTERN LOCK ACCESS

    PIN ROOT ASCII ROOT

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    8/19

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    9/19

    API (ANDROID)

    ()

    ()

    (BLACKBERRY) FAKE- ()

    ELCOMSOFT BLACKBERRY ,

    ROOT (ANDROID) GESTURE.KEY, PC.KEY

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    10/19

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    11/19

    , , SDK :

    , , EXE- + , , (BB SMARTPHONE)

    Wi-Fi, EXE- + , (BB TABLET)

    -, ,, (ANDROID)

    : + (BB

    SMARTPHONE) , , (BB TABLET) , API(ANDROID)

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    12/19

    DEVICE INFORMATION > PHYSICAL ADDRESS:

    E8:XX:XX:XX:XX:XX > DEVICE OS: BLACKBERRY PLAYBOOK

    OS > DEVICE PIN: 500XXXXX > OS VERSION: 2.0.1.668

    INTERNET CONNECTION > IP ADDRESS: 192.168.1.31 > SUBNET MASK: 255.255.255.0 > DEFAULT GATEWAY: 192.168.1.1 > PRIMARY DNS: 192.168.1.1 > DOMAIN SUFFIX: > MTU: 1500

    > PROXY SERVER/PORT:

    WI-FI INFORMATION > STATUS: CONNECTED > FAILURE REASON: > PROFILE NAME: XXXX > SSID: XXXX > CHANNEL: 11 > AP MAC ADDRESS:

    48:XX:XX:XX:XX:XX > SECURITY TYPE: WPA2

    PERSONAL > SIGNAL LEVEL: -41 DBM > CONNECTION DATA RATE:

    65 MBPS > NETWORK TYPE: 802.11G/N

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    13/19

    EXIF

    RIM/BLACKBERRY/ANDR

    OID/HTC

    EXIF ,,

    , EXIF

    IMG20120103-XXXX

    -MOSKVA

    VN-20120319-XXXX.AMR

    / M4A 20120319 --

    VID-YYYYMMDD-XXXXXX.3GP / MP4

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    14/19

    LIVE

    API

    BLACKBERRY (EMAIL, ,, , . )

    ANDROID SQL DB VCARD,FB, TWITTER

    /DATA/DATA/COM.FACEBOOK/FB.DB

    API SD-CARD

    , , , ,

    SQL DB, EXIF ,

    EXIF GEO

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    15/19

    LIVE + IM API SD-CARD

    IM (BLACKBERRY) | ID | ID | |

    (BLACKBERRY)

    SQL DB MMS /DATA/DATA/COM.ANDROID.PROVIDERS.TELEPHONY

    PASSWORD HAPPENS API-: GetClipboard(), GetData(), GetText()

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    16/19

    LIVE

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    17/19

    LIVE

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    18/19

    DEAD LIVE

    ,

    LIVE

    DEAD , LIVE, ,

  • 8/13/2019 (PDF) YURY CHEMERKIN InfoSecurityRussia 2012.PDF

    19/19

    , HAKIN9 MAGAZINE