mirror of
https://github.com/mvt-project/mvt.git
synced 2026-08-15 23:50:56 +02:00
First commit
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
# Check a Filesystem Dump with `mvt-ios`
|
||||
|
||||
When you are ready, you can proceed running `mvt-ios` against the filesystemp dump or mount point:
|
||||
|
||||
$ mvt-ios check-fs --help
|
||||
Usage: mvt-ios check-fs [OPTIONS] DUMP_PATH
|
||||
|
||||
Extract artifacts from a full filesystem dump
|
||||
|
||||
Options:
|
||||
-i, --iocs PATH Path to indicators file
|
||||
-o, --output PATH Specify a path to a folder where you want to store JSON
|
||||
results
|
||||
|
||||
-f, --fast Avoid running time/resource consuming features
|
||||
-l, --list-modules Print list of available modules and exit
|
||||
-m, --module TEXT Name of a single module you would like to run instead of
|
||||
all
|
||||
|
||||
--help Show this message and exit.
|
||||
|
||||
Following is an example of basic usage of `check-fs`:
|
||||
|
||||
```bash
|
||||
mvt-ios check-fs /path/to/filesystem/dump/ --output /path/to/output/
|
||||
```
|
||||
|
||||
This command will create a few JSON files containing the results from the extraction. If you do not specify a `--output` option, `mvt-ios` will just process the data without storing results on disk.
|
||||
|
||||
Through the `--iocs` argument you can specify a [STIX2](https://oasis-open.github.io/cti-documentation/stix/intro) file defining a list of malicious indicators to check against the records extracted from the backup by mvt. Any matches will be highlighted in the terminal output as well as saved in the output folder using a "*_detected*" suffix to the JSON file name.
|
||||
@@ -0,0 +1,48 @@
|
||||
# Dumping the filesystem
|
||||
|
||||
While iTunes backup provide a lot of very useful databases and diagnistic data, in some cases you might want to jailbreak the device and perform a full filesystem dump. In that case, you should take a look at [checkra1n](https://checkra.in/), which provides an easy way to obtain root on most recent iPhone models.
|
||||
|
||||
!!! warning
|
||||
Before you checkra1n any device, make sure you take a full backup, and that you are prepared to do a full factory reset before restoring it. Even after using checkra1n's "Restore System", some traces of the jailbreak are still left on the device and [apps with anti-jailbreaks will be able to detect them](https://github.com/checkra1n/BugTracker/issues/279) and stop functioning.
|
||||
|
||||
After having jailbroken the device, you should be able to access the phone over ssh. In order to do this you will typically need to use iproxy, which on Debian/Ubuntu systems can be installed with `libusbmuxd-tools`. Run the command:
|
||||
|
||||
```bash
|
||||
iproxy 2222 44
|
||||
```
|
||||
|
||||
Now you will be able to ssh as root to localhost on port 2222 and password `alpine`. Note: if you used a jailbreak other than checkra1n, you might need to specify a different port number instead of 44.
|
||||
|
||||
At this point you need to get access to the content of the device from your computer. One way is to run a command like `ssh root@localhost -p 2222 tar czf - /private > dump.tar.gz` which will save a tarball on the host of the */private/* folder from the phone. This will take a while.
|
||||
|
||||
Alternatively, you can try run `sftp-server` for iOS and mount the filesystem locally using `sshfs`.
|
||||
|
||||
|
||||
## Use `sshfs` on iOS
|
||||
|
||||
If you decide to try to use sshfs, you first have to download locally a compiled copy of sftp-server:
|
||||
|
||||
```bash
|
||||
wget https://github.com/dweinstein/openssh-ios/releases/download/v7.5/sftp-server
|
||||
```
|
||||
|
||||
Then upload the binary to the iPhone:
|
||||
|
||||
```bash
|
||||
scp -P2222 sftp-server root@localhost:.
|
||||
```
|
||||
|
||||
You will need to ssh into the device and set some entitlements in order to allow `sftp-server` to run. This entitlements can be copied from an existing binary:
|
||||
|
||||
```bash
|
||||
chmod +x sftp-server
|
||||
ldid -e /binpack/bin/sh > /tmp/sh-ents
|
||||
ldid -S /tmp/sh-ents sftp-server
|
||||
```
|
||||
|
||||
Now you can create a folder on the host and use it as a mount point (**note:** do not create this folder in /tmp/):
|
||||
|
||||
```bash
|
||||
mkdir root_mount
|
||||
sshfs -p 2222 -o sftp_server=/var/root/sftp-server root@localhost:/ root_mount
|
||||
```
|
||||
Reference in New Issue
Block a user