Pieces0310

取证须让证物说话,莫妄以自我心证来给案情下定论.切忌画靶射箭,为找而找. 取证的根基仰赖经验与判断,在IT各领域的经验愈丰富,愈能看出端倪. 取证须善用工具,但不过度依赖工具.工具只能帮你缩小可能范围,但无法告诉你答案,仍需靠人进行分析判断.

首页 新随笔 联系 订阅 管理

QQ is one of the most popular chat App in the world. Now let me show you how to extract QQ from iPhone and analyze it.

The version of iOS is 9.3.2 and the version of QQ is 6.5.3.

 

As you could see that QQ saved lots of important info in the text format files. Such as telecom, uin, e-mails which belongs to the suspect. Also user log in info, etc.

 

 

What else? If suspect transfer files between PC version QQ and Mobile version QQ, those files are saved in the  Filerecv folder.

 

The most important is the chat messages including the deleted ones. As you could see that all chat messages are only plain text. No encryption is definitely a good news to forensic guys.

 

posted on 2016-08-31 10:09  Pieces0310  阅读(372)  评论(0)    收藏  举报