-
Beta Was this translation helpful? Give feedback.
Replies: 8 comments 38 replies
-
The WhatsApp database (ChatStorage.sqlite) in the iCloud backup seems encrypted (enc suffix). You would need the encryption key to decrypt it. Anyway, even with the encryption key, currently IPED doesn't support decrypting that database, it needs the database already decrypted to extract the chats, calls, etc. |
Beta Was this translation helpful? Give feedback.
-
Hi Nassif. Inside the FileInfoList.txt it has, as example:
IPED can process all files, .opus,. jpg, etc... inside the backup folder and those files are in this FileInfoList.txt file, but ChatStorage.sqlite it doesnt process. So we have to process first in PA and then in IPED. |
Beta Was this translation helpful? Give feedback.
-
Thanks, I'll try to get a sample for testing. |
Beta Was this translation helpful? Give feedback.
-
A título de informação, se não for fornecido o arquivo FileInfoList.txt o Cellebrite não consegue decodificar o ChatStorage |
Beta Was this translation helpful? Give feedback.
-
Got 01 sample iCloud data with a few LZFSE files from André (PC/MG), thank you! Decompressed them using RagingMoose library, referenced on #1294, then processed the resulting data with IPED. WhatsApp conversations were decoded fine! Attachments were also linked properly, with no file renaming/mapping from I should have a working draft in the next days. But for a final implementation, I would need more samples to properly test the feature, for example, with LZIP compression. @tlragazzan, do you mean some files are LZFSE compressed and others LZIP compressed? Or some files really are LZIP compressed after LZFSE compression, or the opposite? This seems strange to me... If you or anyone else could provide more samples, that would be very useful to finish the feature. |
Beta Was this translation helpful? Give feedback.
-
We tested it and can confirm that the snapshot is working and bringing the whatsapp conversations, including linking media files. |
Beta Was this translation helpful? Give feedback.
-
Hello all, Just finished my planned enhancement to better detect WhatsApp iOS account info, to be independent of a specific plist file name. Now the owner account should be detected fine and will be shown in all chat balloons to the right in WA conversations, and also displayed fine in the graph analysis. Snapshot will be ready here in 10 minutes: Please give it a try. After some of you test it and report results are fine, I'll integrate the new feature in main version. |
Beta Was this translation helpful? Give feedback.
-
Obs: Apaguei a postagem anterior pq faltou ocultar alguns dados |
Beta Was this translation helpful? Give feedback.
Got 01 sample iCloud data with a few LZFSE files from André (PC/MG), thank you! Decompressed them using RagingMoose library, referenced on #1294, then processed the resulting data with IPED. WhatsApp conversations were decoded fine! Attachments were also linked properly, with no file renaming/mapping from
FileInfoList.txt
, that's not needed by our WhatsApp parser, as I said before. Interestingly, most files in the sample set are not encoded, just a few of them are LZFSE compressed, including ChatStorage.sqlite and other sqlite databases, as @tlragazzan said.I should have a working draft in the next days. But for a final implementation, I would need more samples to properly test the featu…