Modern smartphones are not only used for communication via phone calls but also for a variety of other purposes such as emailing or storing personal data. To enable these services, most smartphones possess a large memory capacity to save files and application data. As smartphones are not only used for legal purposes but also for criminal actions, this data can contain valuable evidence for forensic investigators. In order to be able to analyze this data, it is very important to understand the way smartphones store and delete data. Therefore, it is necessary to understand the file system that is used to handle the smartphone’s internal flash memory. The major focus within this diploma thesis is the analysis of the flash file system YAFFS2 which is used by the popular Android smartphones. To that purpose, YAFFS2 is theoretically and practically analyzed in a forensic perspective in order to determine possibilities to recover modified or deleted files from a smartphone’s flash memory. Additionally, YAFFS2 is compared to the common file system NTFS within this diploma thesis. This diploma thesis also includes a chapter discussing ways to safely delete files from a YAFFS2 flash memory.
Abstract In order to efficiently reverse engineer code tools are necessary which perform signifi- cantly more than simple disassembly. Such tools should aid the reverse engineer in the areas in which manual work is known,to be tedious and error-prone. The engineer on his part aids the tool in the areas where automatic disassembly fails due to code obfuscation. This way the reverse engineer can concentrate on the actual work and can delegate the tedious parts to the utility at hand. To show how such an utility could look like and of
Valentin Dallmeier合作论文数UniversitA¤t des Saarlandes, FR Informatik1
Stephan Didas合作论文数Faculty of Mathematics and Computer Science; Saarland University,1