<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Black Berry Forensic Exams-How-To</title>
	<atom:link href="http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/feed/" rel="self" type="application/rss+xml" />
	<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/</link>
	<description>Cell Phone Forensic Tips, Tricks and Tutorials</description>
	<lastBuildDate>Wed, 11 Nov 2009 22:57:20 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Forensics:Blackberry Links &#171; Data &#8211; Where is it?</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-1015</link>
		<dc:creator>Forensics:Blackberry Links &#171; Data &#8211; Where is it?</dc:creator>
		<pubDate>Mon, 24 Aug 2009 21:16:05 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-1015</guid>
		<description>[...] How to image a blackberry (2007) [...]</description>
		<content:encoded><![CDATA[<p>[...] How to image a blackberry (2007) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cognitive</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-981</link>
		<dc:creator>Cognitive</dc:creator>
		<pubDate>Tue, 27 Jan 2009 02:13:10 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-981</guid>
		<description>I just got a 8707g to analyze and we had purchased Encase for a computer forensic job earlier this year.  When the customer asked to look at the Blackberry we got Neutrino since we got a discount for buying Encase.  Mistake!!!  Only after I got the phone and learned the model number did I find out through the Guidance Software forums that Neutrino will only look at the logical data and not the physical.  The SIM card was removed so there was only the 64MB of RAM, which Neutrino can&#039;t read.  I did make a backup of the phone using the desktop software, even prior to reading this article.  But, I feel as if I&#039;m at a dead end now.  Is there a way to access the data and what I guess would be unallocated space on the 64MB of RAM?  The 8707g doesn&#039;t have any SD card slots so there are no external memory options.

I downloaded the demo version of Paraben&#039;s Device Seizure because they claim it will grab the physical memory, which is what I need.  But, I didn&#039;t find anything useful and maybe they limited it so I can&#039;t see anything.</description>
		<content:encoded><![CDATA[<p>I just got a 8707g to analyze and we had purchased Encase for a computer forensic job earlier this year.  When the customer asked to look at the Blackberry we got Neutrino since we got a discount for buying Encase.  Mistake!!!  Only after I got the phone and learned the model number did I find out through the Guidance Software forums that Neutrino will only look at the logical data and not the physical.  The SIM card was removed so there was only the 64MB of RAM, which Neutrino can&#8217;t read.  I did make a backup of the phone using the desktop software, even prior to reading this article.  But, I feel as if I&#8217;m at a dead end now.  Is there a way to access the data and what I guess would be unallocated space on the 64MB of RAM?  The 8707g doesn&#8217;t have any SD card slots so there are no external memory options.</p>
<p>I downloaded the demo version of Paraben&#8217;s Device Seizure because they claim it will grab the physical memory, which is what I need.  But, I didn&#8217;t find anything useful and maybe they limited it so I can&#8217;t see anything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: numenorian</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-978</link>
		<dc:creator>numenorian</dc:creator>
		<pubDate>Wed, 07 Jan 2009 13:56:41 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-978</guid>
		<description>The short answer is no. This is a logical dump of the Blackberry database file. You will have to find a way to get at the internal memory at a lower level to look for the hexidecimal headers (such as FFh D8h for a jpeg).</description>
		<content:encoded><![CDATA[<p>The short answer is no. This is a logical dump of the Blackberry database file. You will have to find a way to get at the internal memory at a lower level to look for the hexidecimal headers (such as FFh D8h for a jpeg).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dyo</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-977</link>
		<dc:creator>dyo</dc:creator>
		<pubDate>Tue, 06 Jan 2009 19:12:01 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-977</guid>
		<description>Can you recover deleted pictures from a blackberry curve&#039;s internal memory using this method?</description>
		<content:encoded><![CDATA[<p>Can you recover deleted pictures from a blackberry curve&#8217;s internal memory using this method?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keith</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-966</link>
		<dc:creator>Keith</dc:creator>
		<pubDate>Tue, 18 Nov 2008 18:58:19 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-966</guid>
		<description>Thanks for the article.
J. Oquendo&#039;s comment mentions that suite which has a bunch of features, but it does not support most of the &quot;advanced&quot; features for the Blackberry anyway so your advice is helpful. AccessData&#039;s product does not yet support Blackberries and Paraben&#039;s Device Seizure product supports them but does not suck in deleted data. They are working on that.
http://www.oxygen-forensic.com/en/models/</description>
		<content:encoded><![CDATA[<p>Thanks for the article.<br />
J. Oquendo&#8217;s comment mentions that suite which has a bunch of features, but it does not support most of the &#8220;advanced&#8221; features for the Blackberry anyway so your advice is helpful. AccessData&#8217;s product does not yet support Blackberries and Paraben&#8217;s Device Seizure product supports them but does not suck in deleted data. They are working on that.<br />
<a href="http://www.oxygen-forensic.com/en/models/" rel="nofollow">http://www.oxygen-forensic.com/en/models/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Oquendo</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-965</link>
		<dc:creator>J. Oquendo</dc:creator>
		<pubDate>Tue, 18 Nov 2008 17:29:36 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-965</guid>
		<description>Definitely not trying to impress so please excuse my choice of words. Trying to give relevant information. Remember, the purpose of the forensics is to preserve and to detect. If done improperly, your evidence goes out the door. So once again apologies for my tone.

Sincerely
Jesus Oquendo</description>
		<content:encoded><![CDATA[<p>Definitely not trying to impress so please excuse my choice of words. Trying to give relevant information. Remember, the purpose of the forensics is to preserve and to detect. If done improperly, your evidence goes out the door. So once again apologies for my tone.</p>
<p>Sincerely<br />
Jesus Oquendo</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: numenorian</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-958</link>
		<dc:creator>numenorian</dc:creator>
		<pubDate>Sun, 12 Oct 2008 23:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-958</guid>
		<description>I approved your comment J. Oquendo because I dont censor. However, the size of your ego is immense. Manners my friend, manners. If your really wanted to help people you might post helpful comments. 

I look forward to seeing you in court.</description>
		<content:encoded><![CDATA[<p>I approved your comment J. Oquendo because I dont censor. However, the size of your ego is immense. Manners my friend, manners. If your really wanted to help people you might post helpful comments. </p>
<p>I look forward to seeing you in court.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: J. Oquendo</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-956</link>
		<dc:creator>J. Oquendo</dc:creator>
		<pubDate>Sun, 12 Oct 2008 19:28:16 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-956</guid>
		<description>And how exactly is this &quot;Blackberry Forensics&quot;? If all you&#039;re doing is retrieving information from the IPD files, then you&#039;re doing a half baked job. Remember information stored on memory that has been wiped can be retrieved. The IPD file solely stored what someone has backed up. The bits off the memory cards are worth going after. For this I recommend Oxygen Forensic Suite. Or you can simply create a bit by bit copy of the device and do some filecarving to recreate what&#039;s missing. 

Your definition of simply looking at an IPD file doesn&#039;t do much in fact if I was going against you in a court of law, I&#039;d retrieve enough evidence to make you go back and study forensics for a couple more years.

J. Oquendo
http://www.infiltrated.net/?page_id=2</description>
		<content:encoded><![CDATA[<p>And how exactly is this &#8220;Blackberry Forensics&#8221;? If all you&#8217;re doing is retrieving information from the IPD files, then you&#8217;re doing a half baked job. Remember information stored on memory that has been wiped can be retrieved. The IPD file solely stored what someone has backed up. The bits off the memory cards are worth going after. For this I recommend Oxygen Forensic Suite. Or you can simply create a bit by bit copy of the device and do some filecarving to recreate what&#8217;s missing. </p>
<p>Your definition of simply looking at an IPD file doesn&#8217;t do much in fact if I was going against you in a court of law, I&#8217;d retrieve enough evidence to make you go back and study forensics for a couple more years.</p>
<p>J. Oquendo<br />
<a href="http://www.infiltrated.net/?page_id=2" rel="nofollow">http://www.infiltrated.net/?page_id=2</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony Harris</title>
		<link>http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-937</link>
		<dc:creator>Anthony Harris</dc:creator>
		<pubDate>Thu, 04 Sep 2008 08:03:31 +0000</pubDate>
		<guid isPermaLink="false">http://mobileforensics.wordpress.com/2007/02/22/black-berry-forensic-exams-how-to/#comment-937</guid>
		<description>Great article, many thanks, would it be possible to restore the graphics on the BlackBerry page please, the graphics referred to in the documentation do not display.  Again many thanks very helpful.</description>
		<content:encoded><![CDATA[<p>Great article, many thanks, would it be possible to restore the graphics on the BlackBerry page please, the graphics referred to in the documentation do not display.  Again many thanks very helpful.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
