XBox forensics

Have a read and let us know what you think.
Post Reply
User avatar
CoFree
Robinhood
Robinhood
Posts: 13414
Joined: Wed Nov 07, 2007 1:38 pm
Location: In the Forest
Contact:

XBox forensics

Post by CoFree »

XBox forensics
unknown
Image

A forensics toolkit for the Xbox gaming console is described by US researchers in the latest issue of the International Journal of Electronic Security and Digital Forensics. The toolkit could allow law enforcement agencies to scour the inbuilt hard disk of such devices and find illicit hidden materials easily. Computer scientist David Collins has probably spent more time messing around with the Microsoft XBox, other gaming consoles, and PDAs in the name of forensic science than anyone else. He is a digital forensics expert at Sam Houston State University, and is working hard to replicate "mods" - both hardware and software for the Xbox and other devices.

Criminals often hide illicit data on the XBox in the hope that a gaming console will not be seen as a likely evidence target especially when conventional personal computers are present in the same premises, for instance. The toolkit developed by Collins will allow police and other investigators the chance to lay bare the contents of XBox hard disks.

Cell phones, smart phones, PDAs, game consoles and other devices provide a convenient means to store data of all kinds, including images, video, audio and text files. But they also provide a simple way for criminals to possess and hide illegal material too.

Collins' XFT utility can mount an image of the FATX file system used by the XBox, allowing the user to explore in detail the directory structure. Collins points out that unlike the standard FAT32, NTFS, and similar systems used by the hard disks in personal computers, there is little documentation on the proprietary FATX system. However, it is possible nevertheless to acquire an image of a FATX hard disk and to mount it on another device.

"Once the Xbox file system is mounted, the analyst can use shell commands to browse the directory tree, open files, view files in hex editor mode, list the contents of the current directory in short or long mode and expand the current directory to list all associated subdirectories and files," explains Collins.

Importantly, from the legal perspective, XFT can also record such investigative sessions for playback in a court of law, which protects the defendant from falsified as well as providing more solid evidence for the prosecution.

Collins explains how future work on XFT will involve making the toolkit into a fully functional forensic operating system (OS). This OS will be packaged as both a bootable operating system from a hard disk and a "live" bootable compact disk. "This implementation will be open source, verbosely commented and designed from the ground up as a forensic OS," says Collins, "This will remove any and all proprietary operating system dependencies, making the forensic process as transparent as possible."
"FIGHTING TYRANNY in a TECHNOLOGICAL NOTTINGHAM"
Image
No Questions by PM.
User avatar
Shootsteel
Ally of Robinhood
Ally of Robinhood
Posts: 546
Joined: Tue Feb 03, 2009 1:28 pm
Location: Florida...Somewhere in the Swamp.

Re: XBox forensics

Post by Shootsteel »

ahh ;) the "Twins" once again, they never get old. :D
Image
iamwatt
Ally of Robinhood
Ally of Robinhood
Posts: 875
Joined: Wed Jan 21, 2009 5:50 pm
Location: new york

Re: XBox forensics

Post by iamwatt »

no they don't, however i think it's one person just different shots. . . im wit it none the less.
User avatar
HaGGardSmurf
Ally of Robinhood
Ally of Robinhood
Posts: 4088
Joined: Tue Feb 03, 2009 9:46 am
Location: Alberta, Canada

Re: XBox forensics

Post by HaGGardSmurf »

Wernt people doing this for quite some time now? Using FatX to explore their HDD?
User avatar
technoe
Ally of Robinhood
Ally of Robinhood
Posts: 1767
Joined: Wed Jan 14, 2009 2:30 pm
Location: Clarksville, TN

Re: XBox forensics

Post by technoe »

HaGGardSmurf wrote:Wernt people doing this for quite some time now? Using FatX to explore their HDD?
We don't use FATX to explore the HDD that's the format that the Xbox 360 Hard drive is formatted in. We use programs like X-Port to see the drive. Too bad they don't wanna give me a whole bunch of money to make them not stupid!!
Image
Today Money, Tomorrow the WORLD!!
sadalius
Robinhood
Robinhood
Posts: 4039
Joined: Wed Nov 07, 2007 6:06 pm

Re: XBox forensics

Post by sadalius »

Fatx was used on the original xbox. Fatx only makes an appearance on the 360 as a single partition for backwards compatibility. The rest is in a FS called big indian.

But yeah, we (the hackers and hacker wanna be's) have been browsing through most game console storage devices for a while now :)
Sadalius

No questions by PM please
User avatar
Shootsteel
Ally of Robinhood
Ally of Robinhood
Posts: 546
Joined: Tue Feb 03, 2009 1:28 pm
Location: Florida...Somewhere in the Swamp.

Re: XBox forensics

Post by Shootsteel »

iamwatt wrote:no they don't, however i think it's one person just different shots. . . im wit it none the less.

Messin with my imagination....darn you :cry:
Image
User avatar
Shootsteel
Ally of Robinhood
Ally of Robinhood
Posts: 546
Joined: Tue Feb 03, 2009 1:28 pm
Location: Florida...Somewhere in the Swamp.

Re: XBox forensics

Post by Shootsteel »

Too bad they don't wanna give me a whole bunch of money to make them not stupid!!
I'll take $20 worth...
Image
adain
Peasant
Peasant
Posts: 1
Joined: Wed Dec 09, 2009 6:44 am
Contact:

Re: XBox forensics

Post by adain »

Thanks for taking the time to help, I really apprciate it.

ViVo Mobiles Price
Post Reply

Return to “Front Page News”