10/11 - Chip-Off & JTAG Flashcards

1
Q

What are the drawbacks of flasher tools?

A

Since the tool developer is not concerned about digital forensics, some of the features one would expect in a forensic examination tool are not included such as an audit trail or hashing function.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Name a common flasher tool?

A

Advanced Turbo Flasher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the benefits of engineering ports?

A

Some flusher tools require connectivity via an engineering port. The benefit of using an engineering port is that they are usually protected from the daily wear and pair exposure and damage in comparison to the regular data port. However, connection via an engineering port often requires a proprietary cable or proprietary pinout.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are boot loaders?

A

Boot loaders provide an option to unlock and acquire certain mobile devices memory by booting them into a custom recovery mode which replaces the standard Android recovery partition. This is particularly applicable to a range of Android devices which will depend on the model chipset, vendor, and even network carrier.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Name two custom recovery developers?

A
  • Clockwork Mod Recovery
  • team WIN recovery project or TWRP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does FRP stand for?

A

Factory Reset Protection

is a security method that was designed to make sure someone can’t just wipe and factory reset your phone if you’ve lost it or it was stolen.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Explain the Qualcomm EDL Mode?

A

Special boot mode can be enabled to allow direct memory access. This involves forcing the mobile device into a special state called emergency download or EDL mode. It is also known as deep flash, or 9008 mode.

The EDL mode implements the Sahara protocol, which allows an original equipment manufacturer or OEM to accept a digitally signed programmer over USB. The OEM vendors programmer uses a protocol known as Firehose to interact with Qualcomm chips.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does ISP stand for?

A

In system programming - or ISP or more commonly known as direct eMMC, involves interfacing directly with the flash memory chip in a mobile device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Chip Off Forensics?

A

is a technique which involves the removal of the flash memory chip from the mobile device printed circuit board and the reading and imaging of its content via some form of memory reading device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the Popcorn effect?

A

Prior to removing a memory chip, some considerations need to take place. For example, is there any likelihood that moisture has been trapped inside the memory chip. If this is a possibility, then the board should be dried in an oven for a number of hours to ensure any moisture has evaporated. Failure to do this could potentially cause the memory chip to be damaged. Commonly known as the popcorn effect, when heat is applied as part of the chip removal technique and moisture trapped inside the chip package rapidly expands due to the increase in heat.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is JEDEC?

A

Solid State Technology Association

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does JTAG stand for?

A

Joint Test Action Group

JTAG uses a serial communications interface to probe the key components on a printed circuit board in order to validate their correct operation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the TAP?

A

The connection interface used for JTAG is known as the test access port or TAP. Connection points for the Tap are located on a mobile device printed circuit board.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Explain the following JTAG TAP pins:

  1. TCK
  2. TDI
  3. TDO
  4. TRST
  5. NRST
  6. RTCK
A
  1. TCK - Test Clock.
    Synchronize the internal machine operation state.
  2. TDI - Test Data In.
    For data input.
  3. TDO - Test Data Out.
    For data output
  4. TRST - Test Reset
    To force controller into a known state.
  5. NRST - Normal Reset.
    Set device into unknown state.
  6. RTCK - Return Clock.
    Control maximum clock speed
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Name a few JTAG tools?

A
  • Rift-to-box
  • Advance Turbo Flasher
  • Z3-X
How well did you know this?
1
Not at all
2
3
4
5
Perfectly