Professional Documents
Culture Documents
Perícia Forense Computacional em Telefones Celulares Com Sistema Operacional Android
Perícia Forense Computacional em Telefones Celulares Com Sistema Operacional Android
WĂůĂǀƌĂƐͲĐŚĂǀĞ͗ϭ͘ǀŝĚġŶĐŝĂƐĚŝŐŝƚĂŝƐ͘Ϯ͘Smartphones. ϯ͘ŶĚƌŽŝĚ͘ϰ͘džƚƌĂĕĆŽĚĞĚĂĚŽƐ͘
Abstract: Smartphones are mobile phones with greatest processing power, and storage and
are becoming more and more popular around the world. These devices can originate and
ƌĞĐĞŝǀĞĐĂůůƐ͕ĞdžĐŚĂŶŐĞĮůĞƐ͕ĐŽŶŶĞĐƚƚŽŶĞƚǁŽƌŬƐĂŶĚĂůůŽǁŝŶƚĞƌŶĞƚĂĐĐĞƐƐ͕ŵĂŬŝŶŐƚŚĞŵ
ƌĞĂůĐŽŵƉƵƚĞƌƐ͘:ƵƐƚĂƐĂĐŽŵƉƵƚĞƌ͕ĂĐĞůůƉŚŽŶĞĂůƐŽƐƚŽƌĞƵƐĞƌ͛ƐĚĂƚĂ͕ƐƵĐŚĂƐĂŐĞŶĚĂƐ͕
originated and received calls and messages, emails and photos, to name a few. These data,
ŬŶŽǁŶĂƐĚŝŐŝƚĂůĞǀŝĚĞŶĐĞŝŶƚŚĞĐŽŵƉƵƚĞƌĨŽƌĞŶƐŝĐĮĞůĚ͕ĐĂŶďĞǀĂůƵĂďůĞĂƐƐĞƚĨŽƌĐƌŝŵĞ
ŝŶǀĞƐƟŐĂƟŽŶĂŶĚƐŽůǀŝŶŐ͘,ŽǁĞǀĞƌ͕ƚŚĞƉƌŽĐĞƐƐŽĨĚĂƚĂĂĐƋƵŝƐŝƟŽŶŽĨŵŽďŝůĞƉŚŽŶĞƐŝƐĂ
ĚŝĸĐƵůƚƚĂƐŬ͕ĞƐƉĞĐŝĂůůLJǁŚĞŶƚŚĞĚĞǀŝĐĞƐĂƌĞůŽĐŬĞĚĂŶĚh^ĚĞďƵŐŐŝŶŐĨƵŶĐƟŽŶĚŝƐĂďůĞĚ͘
dŚĞŽďũĞĐƟǀĞŽĨƚŚŝƐƉĂƉĞƌŝƐƚŽĚĞƐĐƌŝďĞƚĞĐŚŶŝƋƵĞƐ͕ŵĞƚŚŽĚƐĂŶĚƚŽŽůƐƚŚĂƚĐĂŶďĞĂƉƉůŝĞĚ
ƚŽ ƚŚĞ ĚŝŐŝƚĂů ĚĂƚĂ ĂĐƋƵŝƐŝƟŽŶ ŽŶ ƐŵĂƌƚƉŚŽŶĞƐ ǁŝƚŚ ŶĚƌŽŝĚ ŽƉĞƌĂƟŶŐ ƐLJƐƚĞŵ͕ ǁŝĐŚ ĂƌĞ
ůŽĐŬĞĚĂŶĚŝƚƐh^ĚĞďƵŐŐŝŶŐĚŝƐĂďůĞĚ͘ƚƚŚĞĞŶĚ͕ǁĞƉƌĞƐĞŶƚĂŵĞƚŚŽĚŽĨĚĂƚĂĞdžƚƌĂĐƟŽŶ
ďLJƌĞƉůĂĐŝŶŐƚŚĞƌĞĐŽǀĞƌLJƉĂƌƟƟŽŶ͕ĂŶĚŝƚƐƌĞƐƵůƚƐ͘
Keywords: ϭ͘ŝŐŝƚĂůĞǀŝĚĞŶĐĞ͘Ϯ͘^ŵĂƌƚƉŚŽŶĞƐ͘ϯ͘ŶĚƌŽŝĚ͘ϰ͘ĂƚĂĞdžƚƌĂĐƟŽŶ͘
ϭ ŽƵƚŽƌĞŵŶŐĞŶŚĂƌŝĂůĠƚƌŝĐĂ͕ĐŽŵWſƐͲĚŽƵƚŽƌĂĚŽĞŵŝġŶĐŝĂĚĂŽŵƉƵƚĂĕĆŽ͕WĞƌŝƚŽƌŝŵŝŶĂůĚĂ^Wdͬ'KĞWƌŽĨĞƐƐŽƌĚĂWh
'ŽŝĄƐũƵŶƚŽĂŽĞƉĂƌƚĂŵĞŶƚŽĚĞŽŵƉƵƚĂĕĆŽ͘
Ϯ 'ƌĂĚƵĂŶĚŽĞŵŝġŶĐŝĂĚĂŽŵƉƵƚĂĕĆŽƉĞůĂWh'K/^͕ƉƌŽŐƌĂŵĂĚŽƌƐġŶŝŽƌĚŽ^Eͬ'K͘
ϭ͘ϭĞĮŶŝĕĆŽĚŽƉƌŽďůĞŵĂ
K ŶĚƌŽŝĚ ƐĞ ƚŽƌŶŽƵ Ž ƐŝƐƚĞŵĂ ŽƉĞƌĂĐŝŽŶĂů ŵſǀĞů ŵĂŝƐ ƉŽƉƵůĂƌ
ĚŽ ŵƵŶĚŽ ŶŽ ĐŽŵĞĕŽ ĚĞ ϮϬϭϭ͘ ;,KK'͕ ϮϬϭϭͿ ĞƐƚĂ ĨŽƌŵĂ͕ Ġ ŶĂƚƵƌĂů ƋƵĞ Ă
ƋƵĂŶƟĚĂĚĞĚĞĂƉĂƌĞůŚŽƐĂƉƌĞĞŶĚŝĚŽƐƉĂƌĂƉĞƌşĐŝĂĐŽŵĞƐƚĞƐŝƐƚĞŵĂƚĂŵďĠŵƐĞũĂ
ƉƌŽƉŽƌĐŝŽŶĂůŵĞŶƚĞŐƌĂŶĚĞ͘hŵĚŽƐƌĞĐƵƌƐŽƐĚĞƐĞŐƵƌĂŶĕĂƋƵĞŽŶĚƌŽŝĚƉŽƐƐƵŝĠ
ƉĞƌŵŝƟƌŽďůŽƋƵĞŝŽĚĂƚĞůĂĚŽĂƉĂƌĞůŚŽ͘ƐƐĞďůŽƋƵĞŝŽƉŽĚĞƐĞƌĨĞŝƚŽĚĞĚŝĨĞƌĞŶƚĞƐ
ŵĂŶĞŝƌĂƐ ƚĂŝƐ ĐŽŵŽ͗ ƐĞŶŚĂ ŶƵŵĠƌŝĐĂ͕ ƐĞŶŚĂ ĂůĨĂŶƵŵĠƌŝĐĂ͕ ƉĂĚƌƁĞƐ ĞƚĐ͘ KƵƚƌŽ
ƌĞĐƵƌƐŽĠĂĚĞƐĂƟǀĂĕĆŽĚĂĚĞƉƵƌĂĕĆŽh^͕ƵƟůŝnjĂĚĂƉĞůŽƐĚĞƐĞŶǀŽůǀĞĚŽƌĞƐƉĂƌĂ
ĂĐĞƐƐŽĂŽƚĞůĞĨŽŶĞĂƚƌĂǀĠƐĚŽWĚƵƌĂŶƚĞĂĚĞƉƵƌĂĕĆŽĚĞĂƉůŝĐĂƟǀŽƐĞƵƟůŝnjĂĚĂ
ƚĂŵďĠŵƉĞůŽƐƉĞƌŝƚŽƐĐƌŝŵŝŶĂŝƐ͕ƉĂƌĂĞdžƚƌĂĕĆŽĚŽƐĚĂĚŽƐĚŽƵƐƵĄƌŝŽ͘
ƉſƐ Ă ĂƉƌĞĞŶƐĆŽ ĚĞ Ƶŵ ĂƉĂƌĞůŚŽ ĐĞůƵůĂƌ͕ Ž ƉƌŝŵĞŝƌŽ ƉĂƐƐŽ ƉĂƌĂ
ƵŵĂ ĂŶĄůŝƐĞ ƉĞƌŝĐŝĂů Ġ ƌĞĂůŝnjĂƌ Ă ĞdžƚƌĂĕĆŽ ĚŽƐ ĚĂĚŽƐ ĚŽ ĂƉĂƌĞůŚŽ ƉĂƌĂ Ƶŵ
ĐŽŵƉƵƚĂĚŽƌ͕ ĚĞ ĨŽƌŵĂ Ă ƉƌĞƐĞƌǀĂƌ Ž ĂƌƚĞĨĂƚŽ ŽƌŝŐŝŶĂů Ğ ŶĆŽ ĐŽŵƉƌŽŵĞƚĞƌ Ă
ŝŶƚĞŐƌŝĚĂĚĞĚŽƐĚĂĚŽƐĞdžƚƌú̎Ɛ͘ĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐĚĞ smartphones pode
ϭ͘ϮKďũĞƟǀŽŐĞƌĂů
KŽďũĞƟǀŽŐĞƌĂůĚĞƐƚĞƚƌĂďĂůŚŽĠĂŶĂůŝƐĂƌ͕ƉƌŽƉŽƌĞƚĞƐƚĂƌƵŵŵĠƚŽĚŽ
ƉĂƌĂĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐĚĞsmartphonesĚĞĚŝǀĞƌƐĂƐŵĂƌĐĂƐ͕ƋƵĞƐĞĞŶƋƵĂĚƌĂŵŶŽ
ĐĞŶĄƌŝŽŵĞŶĐŝŽŶĂĚŽĂŶƚĞƌŝŽƌŵĞŶƚĞ͕ĂƐĂďĞƌ͕^ŝƐƚĞŵĂKƉĞƌĂĐŝŽŶĂůŶĚƌŽŝĚ͕ĐŽŵ
ďůŽƋƵĞŝŽĚĞƚĞůĂĂƟǀĂĚŽĞĂŽƉĕĆŽĚĞĚĞƉƵƌĂĕĆŽh^ĚĞƐĂďŝůŝƚĂĚĂ͘
ϮZ&ZE/>dMZ/K
Ϯ͘Ϯ͘ϭƉůŝĐĂƟǀŽƐ
ƉŽƌŵĞŝŽĚŽƐĂƉůŝĐĂƟǀŽƐƋƵĞŽŶĚƌŽŝĚŽĨĞƌĞĐĞĨƵŶĐŝŽŶĂůŝĚĂĚĞƐƉĂƌĂ
Ž ƵƐƵĄƌŝŽ ĚŽ ĐĞůƵůĂƌ͘ džŝƐƚĞŵ ǀĄƌŝŽƐ ƟƉŽƐ ĚĞ ĂƉůŝĐĂƟǀŽƐ͕ ƚĂŝƐ ĐŽŵŽ ũŽŐŽƐ͕ ƌĞĚĞƐ
ƐŽĐŝĂŝƐ͕ ŽƌŐĂŶŝnjĂĚŽƌĞƐƉĞƐƐŽĂŝƐ͕ĐĂůĞŶĚĄƌŝŽƐ ĞƚĐ͘ĞĨĂƚŽ͕ĂƚĠĂƐĨƵŶĐŝŽŶĂůŝĚĂĚĞƐ
ďĄƐŝĐĂƐ ĚŽ ĐĞůƵůĂƌ͕ ƚĂŝƐ ĐŽŵŽ ĞŶǀŝĂƌ Ğ ƌĞĐĞďĞƌ ŵĞŶƐĂŐĞŶƐ Ğ ŽƌŝŐŝŶĂƌ Ğ ƌĞĐĞďĞƌ
ůŝŐĂĕƁĞƐ͕ƐĆŽĂƉůŝĐĂƟǀŽƐ͘;,^DE͕ϮϬϬϴͿ
ůŐƵŶƐ ĂƉůŝĐĂƟǀŽƐ ĂƌŵĂnjĞŶĂŵ ĚĂĚŽƐ ĚŽ ƵƐƵĄƌŝŽ͘ K ĂƉůŝĐĂƟǀŽ ĚĞ
ƚĞůĞĨŽŶĞ͕ƉŽƌĞdžĞŵƉůŽ͕ĂƌŵĂnjĞŶĂĂƐĐŚĂŵĂĚĂƐŽƌŝŐŝŶĂĚĂƐĞƌĞĐĞďŝĚĂƐĞĚƵƌĂĕĆŽ
ĚĂƐŵĞƐŵĂƐ͘KĂƉůŝĐĂƟǀŽĚĞŵĞŶƐĂŐĞŶƐ^D^ĂƌŵĂnjĞŶĂĂƐŵĞŶƐĂŐĞŶƐĞŶǀŝĂĚĂƐĞ
ƌĞĐĞďŝĚĂƐƉĞůŽƵƐƵĄƌŝŽ͘;,^DE͕ϮϬϬϴͿƐƚĞƐĚĂĚŽƐƉŽĚĞŵƐĞƌƵƟůŝnjĂĚŽƐƉĞůŽ
ƉĞƌŝƚŽĨŽƌĞŶƐĞŶĂĞůĂďŽƌĂĕĆŽĚĞƵŵůĂƵĚŽƉĞƌŝĐŝĂů͕ƉŽƌĞdžĞŵƉůŽ͘
ƌƋƵŝǀŽƐƋƵĞŽĚĞƐĞŶǀŽůǀĞĚŽƌƐĂůǀŽƵŶŽ
&ŝůĞƐ
ĂƌŵĂnjĞŶĂŵĞŶƚŽŝŶƚĞƌŶŽ
ĂĐŚĞ ƌƋƵŝǀŽƐĚĞĐĂĐŚĞ
ĂƚĂďĂƐĞƐ ĂŶĐŽĚĞĚĂĚŽƐ^Y>ŝƚĞ
Ϯ͘Ϯ͘ϯKŶĚƌŽŝĚ^ŽŌǁĂƌĞĞǀĞůŽƉŵĞŶƚ<ŝƚ;^<ͿĞŽďĂŶĐŽĚĞ
dados SQLite
K^Y>ŝƚĞĠƵŵďĂŶĐŽĚĞĚĂĚŽƐůĞǀĞ͕ƉĞƋƵĞŶŽ͕ĚĞĐſĚŝŐŽĨŽŶƚĞĂďĞƌƚŽ
Ğ ƋƵĞ ƉŽƐƐƵŝ ĂƐ ĐĂƌĂĐƚĞƌşƐƟĐĂƐ ďĄƐŝĐĂƐ͕ ƚĂŝƐ ĐŽŵŽ ƚĂďĞůĂƐ͕ ŐĂƟůŚŽƐ Ğ ǀŝƐƁĞƐ͕
ŶĞĐĞƐƐĄƌŝĂƐ ƉĂƌĂ Ă ĞƐƚƌƵƚƵƌĂĕĆŽ ĚĞ ĚĂĚŽƐ͘ KƵƚƌĂ ĐĂƌĂĐƚĞƌşƐƟĐĂ Ġ ƋƵĞ ƚŽĚŽƐ ŽƐ
ĚĂĚŽƐƐĆŽĂƌŵĂnjĞŶĂĚŽƐĞŵƵŵƷŶŝĐŽĂƌƋƵŝǀŽĐƌŽƐƐͲƉůĂƞŽƌŵ͕ŽƵƐĞũĂ͕ŽĂƌƋƵŝǀŽ
ĚĞĚĂĚŽƐƉŽĚĞƐĞƌůŝĚŽƚĂŶƚŽŶĂŝŵƉůĞŵĞŶƚĂĕĆŽĚŽ^Y>ŝƚĞƉĂƌĂŶĚƌŽŝĚƋƵĂŶƚŽŶĂ
ŝŵƉůĞŵĞŶƚĂĕĆŽƉĂƌĂtŝŶĚŽǁƐ͘
KŶĚƌŽŝĚ^<ĠƵŵĐŽŶũƵŶƚŽĚĞďŝďůŝŽƚĞĐĂƐ͕ĚŽĐƵŵĞŶƚŽƐ͕ƵƟůŝƚĄƌŝŽƐĞ
ĐŽŵƉŝůĂĚŽƌĞƐŶĞĐĞƐƐĄƌŝŽƐƉĂƌĂĂĐŽĚŝĮĐĂĕĆŽ͕ĐŽŵƉŝůĂĕĆŽ͕ƚĞƐƚĞĞĚŝƐƚƌŝďƵŝĕĆŽĚĞ
ĂƉůŝĐĂƟǀŽƐ͘K^<ĐŽŶƚĠŵ͕ƉŽƌĞdžĞŵƉůŽ͕ŽƵƟůŝƚĄƌŝŽĂĚďƵƐĂĚŽƉĂƌĂĚĞƉƵƌĂĕĆŽĞŽ
ƵƟůŝƚĄƌŝŽfastboot͕ƵƟůŝnjĂĚŽƉĂƌĂŇĂƐŚĚĞƉĂƌƟĕƁĞƐ͘
K ^< ĚŽ ŶĚƌŽŝĚ ƉĞƌŵŝƚĞ ƋƵĞ ŽƐ ĚĞƐĞŶǀŽůǀĞĚŽƌĞƐ ĐƌŝĞŵ ďĂŶĐŽ
ĚĞ ĚĂĚŽƐ ^Y>ŝƚĞ ƉĂƌĂ ŽƐ ĂƉůŝĐĂƟǀŽƐ͘ ƐƚĞƐ ďĂŶĐŽƐ ĚĞ ĚĂĚŽƐ ƐĆŽ ĂƌŵĂnjĞŶĂĚŽƐ
ŶŽƌŵĂůŵĞŶƚĞ ŶŽ ƐƵďĚŝƌĞƚſƌŝŽ ͬĚĂƚĂͬĚĂƚĂͬфĂƉƉхͬĚĂƚĂďĂƐĞƐ͘ ;,KK'͕ ϮϬϭϭͿ ƋƵŝ
ƌĞƐŝĚĞ ƵŵĂ ŝŵƉŽƌƚĂŶƚĞ ĨŽŶƚĞ ĚĞ ĚĂĚŽƐ ƉĂƌĂ ĂŶĄůŝƐĞ ƉĞƌŝĐŝĂů͘ ĂŶĄůŝƐĞ ĚĞƐƚĞƐ
ďĂŶĐŽƐĚĞĚĂĚŽƐĚĞĂƉůŝĐĂƟǀŽƐĐŽŵŽƚĞůĞĨŽŶĞĞŵĞŶƐĂŐĞŶƐƉĞƌŵŝƚĞƋƵĞŽƉĞƌŝƚŽ
ŝĚĞŶƟĮƋƵĞ͕ ƉŽƌ ĞdžĞŵƉůŽ͕ ĐŚĂŵĂĚĂƐ ŽƌŝŐŝŶĂĚĂƐ ƉĂƌĂ ĚĞƚĞƌŵŝŶĂĚŽ ŶƷŵĞƌŽ ŽƵ
ƚƌŽĐĂĚĞŵĞŶƐĂŐĞŶƐƐƵƐƉĞŝƚĂƐ͘
Ϯ͘Ϯ͘ϰŶĚƌŽŝĚĞďƵŐƌŝĚŐĞ;Ϳ
KŶĚƌŽŝĚĞďƵŐƌŝĚŐĞ;ͿĠƵŵĂĨĞƌƌĂŵĞŶƚĂĚŽƉƌſƉƌŝŽ^<ƋƵĞ
ƉĞƌŵŝƚĞ Ă ĐŽŵƵŶŝĐĂĕĆŽ ĞŶƚƌĞ Ƶŵ ĐŽŵƉƵƚĂĚŽƌ Ğ Ƶŵ ĚŝƐƉŽƐŝƟǀŽ ĐŽŵ ŶĚƌŽŝĚ͘
ůĂ ĂƐƐĞŵĞůŚĂͲƐĞ ĂŽ ^^, ĚŽ >ŝŶƵdž͘ ŶƚƌĞ ĂƐ ǀĄƌŝĂƐ ƵƟůŝĚĂĚĞƐ ĚĞƐƚĂ ĨĞƌƌĂŵĞŶƚĂ͕
ĚĞƐƚĂĐĂŵͲƐĞ͗ ŝŶƐƚĂůĂĕĆŽ ĚĞ ĂƉůŝĐĂƟǀŽƐ͕ ĞdžĞĐƵĕĆŽ ĚĞ ĐŽŵĂŶĚŽƐ ĚŝƌĞƚĂŵĞŶƚĞ ŶŽ
shellĚŽĚŝƐƉŽƐŝƟǀŽĞĐſƉŝĂĚĞĂƌƋƵŝǀŽƐĞŶƚƌĞŽĐŽŵƉƵƚĂĚŽƌĞŽĚŝƐƉŽƐŝƟǀŽĞǀŝĐĞͲ
ǀĞƌƐĂ͘KƉŽƐƐƵŝƚƌġƐĐŽŵƉŽŶĞŶƚĞƐ;EZK/s>KWZ^͕ϮϬϭϰĂͿ͗
ĂĚďŝŶƐƚĂůůĂƉƉ͘ĂƉŬ /ŶƐƚĂůĂƵŵĂƉůŝĐĂƟǀŽŶŽĂƉĂƌĞůŚŽ͘
&ŽŶƚĞ͗ŶĚƌŽŝĚĞǀĞůŽƉĞƌƐ͕ϮϬϭϰĂ͘
Ϯ͘Ϯ͘ϲWĂƌƟĕƁĞƐơƉŝĐĂƐ
hŵĂƉĂƌƟĕĆŽĠƵŵĂĚŝǀŝƐĆŽůſŐŝĐĂĚĞƵŵĚŝƐƉŽƐŝƟǀŽĚĞĂƌŵĂnjĞŶĂŵĞŶƚŽ
ĚĞ ĚĂĚŽƐ͘ ŵďŽƌĂ Ž ĨĂďƌŝĐĂŶƚĞ ĚŽ ĂƉĂƌĞůŚŽ ƉŽƐƐĂ ŵŽĚŝĮĐĂƌ Ž ĞƐƋƵĞŵĂ ĚĞ
ƉĂƌƟĕƁĞƐƉĂĚƌĆŽ͕ĂƐƉĂƌƟĕƁĞƐŵŽƐƚƌĂĚĂƐŶĂdĂďĞůĂϯĞƐƚĆŽƉƌĞƐĞŶƚĞƐŶĂŵĂŝŽƌŝĂ
dos smartphones ĐŽŵŶĚƌŽŝĚ͘ƐƉĂƌƟĕƁĞƐĚĞƐŝƐƚĞŵĂ͕ĚĂĚŽƐĚŽƵƐƵĄƌŝŽ͕boot͕
cache e recovery ƟƉŝĐĂŵĞŶƚĞ ĞƐƚĆŽ ƉƌĞƐĞŶƚĞƐ ŶŽƐ ĂƉĂƌĞůŚŽƐ͘ ;s/^͖ ,E'͖
,Z/^d/E͕ ϮϬϭϭͿ KƐ ĂƉůŝĐĂƟǀŽƐ ƋƵĞ ĂƌŵĂnjĞŶĂŵ ĚĂĚŽƐ ĚŽ ƵƐƵĄƌŝŽ ŶĂ ŵĞŵſƌŝĂ
ŝŶƚĞƌŶĂ ĚŽ ƚĞůĞĨŽŶĞ ŐƌĂǀĂŵ ĞƐƚĞƐ ĚĂĚŽƐ ŶĂ ƉĂƌƟĕĆŽ ͬĚĂƚĂ͕ ŶŽ ĐĂŵŝŶŚŽ ͬĚĂƚĂͬ
ĚĂƚĂͬфĂƉƉх͘;,KK'͕ϮϬϭϭͿ
ͬĚĞǀͬŵƚĚͬ Dados de
pds LJĂīƐϮ ͬĐŽŶĮŐ
mtd0 ĐŽŶĮŐƵƌĂĕƁĞƐ
ͬĚĞǀͬŵƚĚͬ
ŵŝƐĐ Ͳ Eͬ DĞŵſƌŝĂ
ŵƚĚϭ
/ŶŝĐŝĂůŝnjĄǀĞů
ͬĚĞǀͬŵƚĚͬ ;ƉĂƌƟĕĆŽ
ƚ ƟŵŐ Eͬ
mtd2 ƉĂĚƌĆŽĚĞ
bootͿ
/ŶŝĐŝĂůŝnjĄǀĞů
ͬĚĞǀͬŵƚĚͬ
ƌĞĐŽǀĞƌLJ ƟŵŐ Eͬ ;ƉĂƌƟĕĆŽ
ŵƚĚϯ
recoveryͿ
ƌƋƵŝǀŽƐĚĞ
ͬĚĞǀͬŵƚĚͬ
ƐLJƐƚĞŵ LJĂīƐϮ ͬƐLJƐƚĞŵ sistemas e
ŵƚĚϰ
ĂƉůŝĐĂƟǀŽƐ
ͬĚĞǀͬŵƚĚͬ ƌƋƵŝǀŽƐĚĞ
ĐĂĐŚĞ LJĂīƐϮ ͬĐĂĐŚĞ
mtd5 cache
ͬĚĞǀͬŵƚĚͬ Dados do
ƵƐĞƌĚĂƚĂ LJĂīƐϮ ͬĚĂƚĂ
ŵƚĚϲ ƵƐƵĄƌŝŽ
ͬĚĞǀͬŵƚĚͬ
ŬƉĂŶŝĐ Ͳ Eͬ LogsĚĞĨĂůŚĂƐ
ŵƚĚϳ
&ŽŶƚĞ͗sŝĚĂƐ͕ŚĂŶŐĞŚƌŝƐƟŶ͕ϮϬϭϭ͘
Ϯ͘Ϯ͘ϳDŽĚŽƐĚĞŝŶŝĐŝĂůŝnjĂĕĆŽ
KƐ ĂƉĂƌĞůŚŽƐ ƉŽĚĞŵ ƐĞƌ ŝŶŝĐŝĂůŝnjĂĚŽƐ ĚĞ ĚŝĨĞƌĞŶƚĞƐ ŵŽĚŽƐ͘ ůŐƵŶƐ
ĨĂďƌŝĐĂŶƚĞƐĚŝƐƉŽŶŝďŝůŝnjĂŵƐŽŌǁĂƌĞƐĞƐƉĞĐşĮĐŽƐƉĂƌĂŝƐƚŽ͘WŽƌĠŵ͕ŶĂŵĂŝŽƌŝĂĚŽƐ
ĚŝƐƉŽƐŝƟǀŽƐŽŵŽĚŽĚĞŝŶŝĐŝĂůŝnjĂĕĆŽƉŽĚĞƐĞƌĂůƚĞƌĂĚŽĂƚƌĂǀĠƐĚĞƵŵĂĐŽŵďŝŶĂĕĆŽ
ĚĞƚĞĐůĂƐĞŶƋƵĂŶƚŽŽĚŝƐƉŽƐŝƟǀŽĞƐƚĄƐĞŶĚŽůŝŐĂĚŽ͘
ŵďŽƌĂ Ž ŶĚƌŽŝĚ ĨŽƌŶĞĕĂ ƉĂƌĂ ŽƐ ĚĞƐĞŶǀŽůǀĞĚŽƌĞƐ ĚĞ ĂƉůŝĐĂƟǀŽƐ
ĐĞƌƚŽ ŶşǀĞů ĚĞ ĂďƐƚƌĂĕĆŽ ĚĞ hardware͕ ĞdžŝƐƚĞ ƵŵĂ ŐƌĂŶĚĞ ĚŝǀĞƌƐŝĚĂĚĞ ĚĞ
ĨĂďƌŝĐĂŶƚĞƐ Ğ ŵŽĚĞůŽƐ͘ ůŐƵŶƐ ĂƉĂƌĞůŚŽƐ ƉŽƐƐƵĞŵ ŐƌĂŶĚĞ ƋƵĂŶƟĚĂĚĞ ĚĞ
ƚĞĐůĂƐ͘ :Ą ŽƵƚƌŽƐ ƉŽƐƐƵĞŵ ĂƉĞŶĂƐ ƵŵĂ ŽƵ ĚƵĂƐ ƚĞĐůĂƐ͘ :ƵƐƚĂŵĞŶƚĞ ƉŽƌ ĐĂƵƐĂ
ĚĞƐƚĂ ĚŝǀĞƌƐŝĚĂĚĞ͕ ŶĞŵ ƐĞŵƉƌĞ Ă ŵĞƐŵĂ ĐŽŵďŝŶĂĕĆŽ ĚĞ ƚĞĐůĂƐ ƉĂƌĂ ĂůƚĞƌŶĂƌ
Ž ŵŽĚŽ ĚĞ ŝŶŝĐŝĂůŝnjĂĕĆŽ ĨƵŶĐŝŽŶĂ Ğŵ ŵŽĚĞůŽƐ ĚŝĨĞƌĞŶƚĞƐ͘ dĂďĞůĂ ϰ ĞdžŝďĞ ĂƐ
ĐŽŵďŝŶĂĕƁĞƐĚĞƚĞĐůĂƐƉĂƌĂĂůƚĞƌŶĂƌŽŵŽĚŽĚĞŝŶŝĐŝĂůŝnjĂĕĆŽĚĞĂůŐƵŶƐŵŽĚĞůŽƐ͘
;s/^͖,E'͖,Z/^d/E͕ϮϬϭϭͿ
DŽĚŽƋƵĞƉĞƌŵŝƚĞ
DŽƚŽƌŽůĂƌŽŝĚ Flash ĐąŵĞƌĂнpower
ŇĂƐŚŝŶŐǀŝĂZ^>ŝƚĞ
BootŶĂƉĂƌƟĕĆŽ
recovery;ĂƉſƐ͕
DŽƚŽƌŽůĂƌŽŝĚ Recovery powerнdž ĐąŵĞƌĂнǀŽů͘
up para mostrar
ŵĞŶƵͿ
DŽĚŽĚĞboot
,d'ϭ Flash powerнĐąŵĞƌĂ ;backƉĂƌĂƚƌŽĐĂƌ
para fastbootͿ
BootŶĂƉĂƌƟĕĆŽ
,d'ϭ Recovery powerнhome
recovery
BootŶŽŵŽĚŽ
ǀŽů͘upнǀŽů͘down
^ĂŵƐƵŶŐĂƉƟǀĂƚĞ Flash ^ĂŵƐƵŶŐforce
;ĞŶƚĆŽŝŶƐŝƌĂh^Ϳ
download
powerнǀŽů͘upн BootŶĂƉĂƌƟĕĆŽ
^ĂŵƐƵŶŐĂƉƟǀĂƚĞ Recovery
ǀŽů͘down recovery
BootŶŽŵŽĚŽ
^ĂŵƐƵŶŐ'ĂůĂdžLJ
Flash powerнǀŽů͘down ^ĂŵƐƵŶŐforce
dĂď
download
^ĂŵƐƵŶŐ'ĂůĂdžLJ BootŶĂƉĂƌƟĕĆŽ
Recovery powerнǀŽů͘up
dĂď recovery
&ŽŶƚĞ͗sŝĚĂƐ͕ŚĂŶŐĞŚƌŝƐƟŶ͕ϮϬϭϭ͘
YƵĂŶĚŽŽĂƉĂƌĞůŚŽĠůŝŐĂĚŽŶŽƌŵĂůŵĞŶƚĞƐĞŵŶĞŶŚƵŵĂĐŽŵďŝŶĂĕĆŽ
ĚĞƚĞĐůĂƐ͕ĞůĞĞƐƚĄŶŽŵŽĚŽŶŽƌŵĂů͘EĞƐƚĞŵŽĚŽ͕ŽƐŝƐƚĞŵĂƉƌŝŶĐŝƉĂů͕ĐŽŵƵŵĞŶƚĞ
ŝŶƐƚĂůĂĚŽŶĂƉĂƌƟĕĆŽsystem͕ĠŝŶŝĐŝĂĚŽ͘WĂƌĂƋƵĞŽĂƉĂƌĞůŚŽƐĞũĂŝŶŝĐŝĂůŝnjĂĚŽĞŵ
Ƶŵ ŵŽĚŽ ĚŝĨĞƌĞŶƚĞ͕ Ġ ŶĞĐĞƐƐĄƌŝŽ ůŝŐĄͲůŽ ƉƌĞƐƐŝŽŶĂŶĚŽ Ă ĐŽŵďŝŶĂĕĆŽ ĚĞ ƚĞĐůĂƐ
ĐŽƌƌĞƐƉŽŶĚĞĂŽŵŽĚŽĚĞƐĞũĂĚŽ͘hŵŵŽĚŽĞƐƉĞĐŝĂůĚĞŝŶŝĐŝĂůŝnjĂĕĆŽĠĐŚĂŵĂĚŽ
ĚĞŵŽĚŽĚĞƌĞĐƵƉĞƌĂĕĆŽŽƵŵŽĚŽrecovery͘ŽůŝŐĂƌŽĂƉĂƌĞůŚŽ͕ƉƌĞƐƐŝŽŶĂŶĚŽĂ
ĐŽŵďŝŶĂĕĆŽĚĞƚĞĐůĂƐƉĂƌĂŝŶŝĐŝĂůŝnjĂĕĆŽŶŽŵŽĚŽrecovery͕ŽƐĂƌƋƵŝǀŽƐĚĂƉĂƌƟĕĆŽ
ĚĞ ŵĞƐŵŽ ŶŽŵĞ͕ ƉĂƌƟĕĆŽ recovery͕ ƐĆŽ ĐĂƌƌĞŐĂĚŽƐ͘ ƐƚĂ ƉĂƌƟĕĆŽ ĐŽŶƚĠŵ ƐĞƵ
ƉƌſƉƌŝŽkernelĚŽ>ŝŶƵdž͕ŝŶĚĞƉĞŶĚĞŶƚĞĚŽkernelĚĂŝŶƐƚĂůĂĕĆŽƉƌŝŶĐŝƉĂů͘
Ϯ͘Ϯ͘ϴƉĂƌƟĕĆŽƌĞĐŽǀĞƌLJ
ƉĂƌƟĕĆŽrecoveryĐŽŶƚĠŵŽƐĂƌƋƵŝǀŽƐĚĞŝŶŝĐŝĂůŝnjĂĕĆŽƉĂƌĂŽŵŽĚŽ
recovery͘ ůĂ ƉŽƐƐƵŝ ƐĞƵ ƉƌſƉƌŝŽ kernel >ŝŶƵdž͕ ƐĞƉĂƌĂĚŽ ĚŽ kernel do sistema
ƉƌŝŶĐŝƉĂů ĚŽ ŶĚƌŽŝĚ ;y s>KWZ^͕ ϮϬϭϰĂͿ Ğ ƉŽĚĞ ƐĞƌ ŝŶŝĐŝĂĚĂ ŵĞƐŵŽ
ƋƵĞĂŝŶƐƚĂůĂĕĆŽƉƌŝŶĐŝƉĂůĚŽƐŝƐƚĞŵĂĞƐƚĞũĂĐŽŵƉƌŽďůĞŵĂƐ͘KŵŽĚŽrecovery
ƉĂĚƌĆŽĚĞĨĄďƌŝĐĂŶŽƌŵĂůŵĞŶƚĞŽĨĞƌĞĐĞĂƉĞŶĂƐĨƵŶĐŝŽŶĂůŝĚĂĚĞƐďĄƐŝĐĂƐĞƐĞŵ
ĂĐĞƐƐŽĂŽ͘;,KK'͕ϮϬϭϭͿ
ƐƚĂƉĂƌƟĕĆŽŐĞƌĂůŵĞŶƚĞƉŽƐƐƵŝƵŵƚĂŵĂŶŚŽƉĞƋƵĞŶŽĞƐĞƵĚŝƐƉŽƐŝƟǀŽ
ĂƐƐŽĐŝĂĚŽƉŽĚĞƐĞƌĚŝĨĞƌĞŶƚĞ͕ĚĞƉĞŶĚĞŶĚŽĚŽŵŽĚĞůŽĞĚŽĨĂďƌŝĐĂŶƚĞ͘ĞƚĂůŚĞƐ
ƐŽďƌĞĞƐƚĂƉĂƌƟĕĆŽƉŽĚĞŵƐĞƌǀŝƐƚŽƐĞdžĂŵŝŶĂŶĚŽ ŽĂƌƋƵŝǀŽ ͬƉƌŽĐͬŵƚĚ;,KK'͕
ϮϬϭϭͿ͕ĐŽŶĨŽƌŵĞŵŽƐƚƌĂĂ&ŝŐƵƌĂϯ͘
Figura 3
ĞƚĂůŚĞƐĚĂƉĂƌƟĕĆŽƌĞĐŽǀĞƌLJ
&ŽŶƚĞ͗,ŽŽŐ͕ϮϬϭϭ͘
Ϯ͘ϯ͘ϭdžƚƌĂĕĆŽİƐŝĐĂ
Ğ ĂĐŽƌĚŽ ĐŽŵ ,ŽŽŐ ;ϮϬϭϭͿ͕ Ă ĞdžƚƌĂĕĆŽ İƐŝĐĂ ƉŽĚĞ ƐĞƌ ĐůĂƐƐŝĮĐĂĚĂ
ĞŵĞdžƚƌĂĕĆŽƉŽƌhardware e por ƐŽŌǁĂƌĞ͘ĞdžƚƌĂĕĆŽƉŽƌhardwareĠƌĞĂůŝnjĂĚĂ
ƵƟůŝnjĂŶĚŽ ĚƵĂƐ ƚĠĐŶŝĐĂƐ ĐŽŶŚĞĐŝĚĂƐ ĐŽŵŽ ĐŚŝƉͲŽī Ğ :ŽŝŶƚ dĞƐƚ ĐƟŽŶ 'ƌŽƵƉ
;:d'Ϳ͘ƐƚĞƟƉŽĚĞĞdžƚƌĂĕĆŽƐſĠƷƟůƋƵĂŶĚŽŽƐĚĂĚŽƐĂƌŵĂnjĞŶĂĚŽƐŶĂŵĞŵſƌŝĂ
ŇĂƐŚŶĆŽĞƐƚĆŽĐƌŝƉƚŽŐƌĂĨĂĚŽƐ͘ŽĐŽŶƚƌĄƌŝŽ͕ŽƐĚĂĚŽƐƉŽĚĞŵĂƚĠƐĞƌĞdžƚƌú̎Ɛ͘
Ϯ͘ϯ͘ϮdžƚƌĂĕĆŽůſŐŝĐĂ
Ɛ ƚĠĐŶŝĐĂƐ ĚĞ ĞdžƚƌĂĕĆŽ ůſŐŝĐĂ ĚŽƐ ĚĂĚŽƐ ƐĆŽ ŵĞŶŽƐ ĚĞƐƚƌƵƟǀĂƐ ĂŽ
ĂƉĂƌĞůŚŽ͕ ƉŽŝƐ ŶĆŽ ŶĞĐĞƐƐŝƚĂŵ ĚĞ ĂůƚĞƌĂĕƁĞƐ ĚĞ hardware ŶŽ ĚŝƐƉŽƐŝƟǀŽ Ă ƐĞƌ
ĂŶĂůŝƐĂĚŽ͘^ĞŐƵŶĚŽ,ŽŽŐ;ϮϬϭϭͿ͕ĂƐƚĠĐŶŝĐĂƐůſŐŝĐĂƐĚĞĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐĂƉĞŶĂƐ
ŶĞĐĞƐƐŝƚĂŵƋƵĞĂŽƉĕĆŽĞƉƵƌĂĕĆŽh^ĞƐƚĞũĂŚĂďŝůŝƚĂĚĂ͘
ƚĠĐŶŝĐĂ ĐŽŶŚĞĐŝĚĂ ĐŽŵŽ ADB pull ƵƟůŝnjĂ Ž ĐŽŵĂŶĚŽ pull ĚŽ
ƉĂƌĂƌĞĂůŝnjĂƌƵŵĂĐſƉŝĂƌĞĐƵƌƐŝǀĂĚŽƐĚŝƌĞƚſƌŝŽƐĞĂƌƋƵŝǀŽƐĂƐĞƌĞŵĂŶĂůŝƐĂĚŽƐĚŽ
ĂƉĂƌĞůŚŽƉĂƌĂĂŵĄƋƵŝŶĂĚŽƉĞƌŝƚŽ͘ƉĞƐĂƌĚĞƐŝŵƉůĞƐ͕ĞƐƐĂƚĠĐŶŝĐĂŶĞŵƐĞŵƉƌĞ
ĠǀŝĄǀĞů͕ƉŽŝƐŶĂŵĂŝŽƌŝĂĚŽƐĐĂƐŽƐ͕ŽƵƐƵĄƌŝŽƐŽďŽƋƵĂůŽADBĠĞdžĞĐƵƚĂĚŽŶĆŽ
ƉŽƐƐƵŝ ƉĞƌŵŝƐƐĆŽ ĚĞ ůĞŝƚƵƌĂ ŶŽƐ ĚŝƌĞƚſƌŝŽƐ ĚŽƐ ĂƉůŝĐĂƟǀŽƐ͘ ƉĂƌƟĕĆŽ ĚĞ ŵĂŝŽƌ
ŝŶƚĞƌĞƐƐĞĠĂͬĚĂƚĂ͕ŽŶĚĞƌĞƐŝĚĞŵƚŽĚŽƐŽƐĂƌƋƵŝǀŽƐĚŽƵƐƵĄƌŝŽ͘^ĞŽADBƉŽƐƐƵŝ
ĂĐĞƐƐŽĚĞroot͕ĞƐƚĂƉĂƌƟĕĆŽƉŽĚĞƐĞƌŝŶƚĞŝƌĂŵĞŶƚĞĐŽƉŝĂĚĂ͘
K ĂƉůŝĐĂƟǀŽ &>ŽŐŝĐĂů ƚĂŵďĠŵ ƉŽĚĞ ƐĞƌ ƵƟůŝnjĂĚŽ ƉĂƌĂ ĞdžƚƌĂĕĆŽ ĚŽƐ
ĚĂĚŽƐ͘ ƐƚĞ ĂƉůŝĐĂƟǀŽ ĨŽŝ ĚĞƐĞŶǀŽůǀŝĚŽ ƉĞůĂ ĞŵƉƌĞƐĂ ǀŝĂ&ŽƌĞŶƐŝĐƐ Ğ ƉŽĚĞ ƐĞƌ
ŝŶƐƚĂůĂĚŽ ŶŽ ĂƉĂƌĞůŚŽ ĂƚƌĂǀĠƐ ĚŽ ͘ hŵĂ ǀĞnj ŝŶƐƚĂůĂĚŽ͕ ĞůĞ ĞdžƚƌĂŝ ŽƐ ĚĂĚŽƐ
ĚĞ ĚŝǀĞƌƐŽƐ ĂƉůŝĐĂƟǀŽƐ ĐŽŵŽ ^D^͕ ĐŽŶƚĂƚŽƐ͕ ƌĞŐŝƐƚƌŽƐ ĚĞ ĐŚĂŵĂĚĂ͕ &ĂĐĞŬ͕
browser͕ ĞŶƚƌĞ ŽƵƚƌŽƐ͘ KƐ ĚĂĚŽƐ Ğdžƚƌú̎Ɛ ƐĆŽ ĂƌŵĂnjĞŶĂĚŽƐ ŶŽ ĐĂƌƚĆŽ ^͕ Ğŵ
ĨŽƌŵĂƚŽĐƐǀ͘;s/&KZE^/^͕ϮϬϭϰͿ
Ϯ͘ϰ^ƵďƐƟƚƵŝĕĆŽĚĂƉĂƌƟĕĆŽƌĞĐŽǀĞƌLJ
ƚƌŽĐĂĚĂƉĂƌƟĕĆŽrecoveryƉĂĚƌĆŽƉŽĚĞƐĞƌƌĞĂůŝnjĂĚĂĞŵĂƉĂƌĞůŚŽƐ
ĐƵũŽ boot loader ƐĞũĂ ĐŽŵƉĂơǀĞů ĐŽŵ Ž ŵŽĚŽ fastboot ŽƵ ŽĨĞƌĞĕĂ Ă ŽƉĕĆŽ ĚĞ
ƐƵďƐƟƚƵŝĕĆŽĚĞƉĂƌƟĕƁĞƐ;ƚĂŵďĠŵĐŽŶŚĞĐŝĚĂĐŽŵŽŇĂƐŚĚĞƉĂƌƟĕƁĞƐͿ͘džŝƐƚĞŵ
ĚŝǀĞƌƐĂƐƉĂƌƟĕƁĞƐrecoveryŵŽĚŝĮĐĂĚĂƐƋƵĞƉŽĚĞŵƐĞƌƵƟůŝnjĂĚĂƐƉĂƌĂƐƵďƐƟƚƵŝĕĆŽ
ĚĂƉĂƌƟĕĆŽƉĂĚƌĆŽ͘ŵĂŝŽƌŝĂĚĞƐƚĂƐƉĂƌƟĕƁĞƐƉĞƌŵŝƚĞĂĐĞƐƐŽǀŝĂĐŽŵŽroot.
ĞƐƚĂĨŽƌŵĂ͕ŽĂƉĂƌĞůŚŽƉŽĚĞƐĞƌŝŶŝĐŝĂůŝnjĂĚŽŶŽŵŽĚŽrecovery e o perito pode
ƵƟůŝnjĂƌĂƚĠĐŶŝĐĂĚĞADB pullƉĂƌĂĞdžƚƌĂĕĆŽĚŽƐĚĂĚŽƐ͘
Figura 4
Comando fastboot ĚĞǀŝĐĞƐ
Ϯ͘ϰ͘ϯWĂƌƟĕƁĞƐƌĞĐŽǀĞƌLJƉĞƌƐŽŶĂůŝnjĂĚĂƐ
džŝƐƚĞŵ ǀĄƌŝĂƐ ŝŵĂŐĞŶƐ ĚĂ ƉĂƌƟĕĆŽ recovery ŵŽĚŝĮĐĂĚĂƐ ƋƵĞ ƉŽĚĞŵ
ƐĞƌƵƟůŝnjĂĚĂƐĞŵƐƵďƐƟƚƵŝĕĆŽăƉĂƌƟĕĆŽĚĞĨĄďƌŝĐĂ͘EĂĞƐĐŽůŚĂĚĞƵŵĂŝŵĂŐĞŵ
ĂƉƌŽƉƌŝĂĚĂ͕ĚĞǀĞƐĞƌůĞǀĂĚŽĞŵĐŽŶƐŝĚĞƌĂĕĆŽƐĞĂŶŽǀĂŝŵĂŐĞŵƉĞƌŵŝƚĞŽƵŶĆŽ
ĂĐĞƐƐŽĐŽŵŽrootǀŝĂ͘ƐŵĂŝƐƉŽƉƵůĂƌĞƐƐĆŽ͗
a. ůŽĐŬǁŽƌŬDŽĚ͗ĞƐĐƌŝƚĂƉŽƌ<ŽƵƐŚƵƩĂ͕ĠďĂƐĞĂĚĂŶĂŝŵĂŐĞŵĚĂ
ƉĂƌƟĕĆŽ recovery ĚŽ ŶĚƌŽŝĚ Ϯ͘ϭ͘ WŽƐƐƵŝ ĚŝǀĞƌƐĂƐ ŽƉĕƁĞƐ ĐŽŵŽ
backup͕ƌĞƐƚĂƵƌĂĕĆŽ͕ĂƚƵĂůŝnjĂĕĆŽĚŽĂƉĂƌĞůŚŽĂƚƌĂǀĠƐĚĞĂƌƋƵŝǀŽƐ
͘njŝƉĞĂĐĞƐƐŽǀŝĂŚĂďŝůŝƚĂĚŽ;ys>KWZ^͕ϮϬϭϰĂͿ͖
ď͘ dtZW͗dĞĂŵtŝŶZĞĐŽǀĞƌLJWƌŽũĞĐƚ ƉŽƐƐƵŝ͕ĂůĠŵĚĂƐŽƉĕƁĞƐƉĂĚƌĆŽ͕
ĨƵŶĕƁĞƐĐŽŵŽbackup͕ƌĞƐƚĂƵƌĂĕĆŽĞĂĐĞƐƐŽǀŝĂŚĂďŝůŝƚĂĚŽ͘^ƵĂ
ŝŶƚĞƌĨĂĐĞĠƐĞŶƐşǀĞůĂŽƚŽƋƵĞĞĠƉĞƌƐŽŶĂůŝnjĄǀĞů͘;dDt/E͕ϮϬϭϰͿ
ϯDdZ//^DdKK^
WĂƌĂ Ă ƌĞĂůŝnjĂĕĆŽ ĚŽƐ ĞdžƉĞƌŝŵĞŶƚŽƐ ĚĞƐƚĞ ƚƌĂďĂůŚŽ͕ ƋƵĂƚƌŽ ŵŽĚĞůŽƐ
ĚŝĨĞƌĞŶƚĞƐĚĞsmartphones ĨŽƌĂŵƵƟůŝnjĂĚŽƐ͘ƐĞƐƉĞĐŝĮĐĂĕƁĞƐĚĞĐĂĚĂĂƉĂƌĞůŚŽ
ĨŽƌĂŵĚĞƐĐƌŝƚĂƐĞŵĐĂĚĂĞdžƉĞƌŝŵĞŶƚŽ͘ůĠŵĚŝƐƐŽ͕ĂĐĞƐƐſƌŝŽƐĐŽŵŽĐĂďŽƐh^Ğ
ĐĂƌƌĞŐĂĚŽƌĞƐĐŽŵƉĂơǀĞŝƐĐŽŵĐĂĚĂŵŽĚĞůŽĚĞĂƉĂƌĞůŚŽĨŽƌĂŵŶĞĐĞƐƐĄƌŝŽƐ͘WĂƌĂ
Ă ĞůĂďŽƌĂĕĆŽ ĚŽ ŵĠƚŽĚŽ ĚĞ ĞdžƚƌĂĕĆŽ ĚĞ ĚĂĚŽƐ ƉƌŽƉŽƐƚŽ͕ ŽƉƚŽƵͲƐĞ ŝŶĐŝĂůŵĞŶƚĞ
ϯ͘Ϯ/ŶƐƚĂůĂĕĆŽĚŽ^ŽŌǁĂƌĞĞǀĞůŽƉŵĞŶƚ<ŝƚ;^<Ϳ
ŝŶƐƚĂůĂĕĆŽ ĚŽ ^< ŶŽ ƐŝƐƚĞŵĂ ŽƉĞƌĂĐŝŽŶĂů tŝŶĚŽǁƐ ϳ ƉŽĚĞ ƐĞƌ
ĨĞŝƚĂďĂŝdžĂŶĚŽͲƐĞŽĂƌƋƵŝǀŽĚĞŝŶƐƚĂůĂĕĆŽĚŝƌĞƚŽĚŽƉŽƌƚĂůĚŽĚĞƐĞŶǀŽůǀĞĚŽƌ
ƉĂƌĂ ŶĚƌŽŝĚ ;ŚƚƚƉƐ͗ͬͬĚĞǀĞůŽƉĞƌ͘ĂŶĚƌŽŝĚ͘ĐŽŵͬƐĚŬͬͿ͘ ƉſƐ ŽďƚĞƌ Ž ĂƌƋƵŝǀŽ
ĚĞŝŶƐƚĂůĂĕĆŽĠŶĞĐĞƐƐĄƌŝŽĞdžĞĐƵƚĄͲůŽ͕ĂĐĞŝƚĂƌƚĞƌŵŽƐĚĞƵƐŽĞĐŽŶĨŝƌŵĂƌŽƐ
ůŽĐĂŝƐĚĞŝŶƐƚĂůĂĕĆŽ͘
hŵƉŽŶƚŽĐŚĂǀĞĚĂŝŶƐƚĂůĂĕĆŽĚŽŶĚƌŽŝĚ^<ĠĂĞƐĐŽůŚĂĐŽƌƌĞƚĂĚŽ
ŶşǀĞůĚĂW/;W/LevelͿ͘ĐĂĚĂĂůƚĞƌĂĕĆŽŶŽframeworkĚĞĚĞƐĞŶǀŽůǀŝŵĞŶƚŽ
ƐĆŽ ĂĐƌĞƐĐĞŶƚĂĚĂƐ Ğ ƌĞŵŽǀŝĚĂƐ ĨƵŶĕƁĞƐ͕ ƐƵƉŽƌƚĞ Ă ŶŽǀĂƐ ƉůĂƚĂĨŽƌŵĂƐ ĞƚĐ͘
WĂƌĂ ƐŽůƵĐŝŽŶĂƌ ƉƌŽďůĞŵĂƐ ĚĞ ĐŽŵƉĂƚŝďŝůŝĚĂĚĞ ĚĞ ĂƉůŝĐĂƚŝǀŽƐ͕ ĨŽŝ ĐƌŝĂĚŽ
Ž ĐŽŶĐĞŝƚŽ ĚĞ ŶşǀĞů ĚĞ W/͘ hŵĂ ĚĞƚĞƌŵŝŶĂĚĂ ǀĞƌƐĆŽ ĚŽ ŶĚƌŽŝĚ ƐƵƉŽƌƚĂ
ŝŶƐƚĂůĂĕĆŽ ĚĞ ĂƉůŝĐĂƚŝǀŽƐ ĐƌŝĂĚŽƐ ĂƚĠ ĐĞƌƚŽ ŶşǀĞů ĚĞ W/͘ ƉůŝĐĂƚŝǀŽƐ ĐƌŝĂĚŽƐ
ĐŽŵŶşǀĞŝƐĚĞW/ŵĂŝƐƌĞĐĞŶƚĞƐŶĆŽƉŽĚĞŵƐĞƌŝŶƐƚĂůĂĚŽƐĞŵǀĞƌƐƁĞƐĂŶƚŝŐĂƐ
ĚŽ ŶĚƌŽŝĚ͘ ;EZK/ s>KWZ^͕ ϮϬϭϰďͿ ǀĞƌƐĆŽ Ϯ͘ϯ ĚŽ ŶĚƌŽŝĚ͕ ƉŽƌ
ĞdžĞŵƉůŽ͕ ĨŽŝ ĐƌŝĂĚĂ ƵƚŝůŝnjĂŶĚŽ Ž ŶşǀĞů ĚĞ W/ ŶƷŵĞƌŽ ϵ͘ ƉůŝĐĂƚŝǀŽƐ ĐƌŝĂĚŽƐ
ƵƚŝůŝnjĂŶĚŽŽŶşǀĞůĚĞW/ŶƷŵĞƌŽϭϬŶĆŽƉŽĚĞŵƐĞƌŝŶƐƚĂůĂĚŽƐŶĞƐƚĂǀĞƌƐĆŽ͕
ƉŽŝƐŽƐĚĞƐĞŶǀŽůǀĞĚŽƌĞƐƉŽĚĞŵƚĞƌƵƚŝůŝnjĂĚŽĂůŐƵŵĂĨƵŶĕĆŽƋƵĞŶĆŽĞdžŝƐƚŝĂ
ŶĂǀĞƌƐĆŽĂŶƚĞƌŝŽƌĚĂW/͘dĂďĞůĂϱƌĞůĂĐŝŽŶĂĂǀĞƌƐĆŽĚŽŶĚƌŽŝĚĂŽŶşǀĞů
ĚĞW/ƐƵƉŽƌƚĂĚŽ͘
Tabela 5
Versões do Android e seus níveis de API
Versão Nível da API Codenome
ŶĚƌŽŝĚϰ͘ϰ ϭϵ </d<d
ŶĚƌŽŝĚϰ͘ϯ ϭϴ :>>zͺEͺDZϮ
ŶĚƌŽŝĚϰ͘Ϯ͘Ϯ
ϭϳ :>>zͺEͺDZϭ
ŶĚƌŽŝĚϰ͘Ϯ
ŶĚƌŽŝĚϰ͘ϭ͘ϭ
ϭϲ :>>zͺE
ŶĚƌŽŝĚϰ͘ϭ
ŶĚƌŽŝĚϰ͘Ϭ͘ϰ /ͺZDͺ^Et/,ͺ
ϭϱ
ŶĚƌŽŝĚϰ͘Ϭ͘ϯ DZϭ
ŶĚƌŽŝĚϰ͘Ϭ͘Ϯ
ŶĚƌŽŝĚϰ͘Ϭ͘ϭ ϭϰ /ͺZDͺ^Et/,
ŶĚƌŽŝĚϰ͘Ϭ
ŵďŽƌĂŶĆŽƐĞũĂŶĞĐĞƐƐĄƌŝŽ͕ƚĂŵďĠŵĠƉŽƐƐşǀĞůĂĐƌĞƐĐĞŶƚĂƌŽĐĂŵŝŶŚŽ
ĚĞŝŶƐƚĂůĂĕĆŽĚŽ^<ŶĂǀĂƌŝĄǀĞůĚĞĂŵďŝĞŶƚĞWd,͘/ƐƐŽĞǀŝƚĂƋƵĞŽĞdžĂŵŝŶĂĚŽƌ͕
ĂŽ ƚĞŶƚĂƌ ĞdžĞĐƵƚĂƌ Ž ĐŽŵĂŶĚŽ ĂĚď͕ ƉŽƌ ĞdžĞŵƉůŽ͕ ƚĞŶŚĂ ƋƵĞ ĚŝŐŝƚĂƌ Ž ĐĂŵŝŶŚŽ
ĐŽŵƉůĞƚŽŽŶĚĞŽƵƟůŝƚĄƌŝŽĞƐƚĄŝŶƐƚĂůĂĚŽ͕ĞĐŽŶŽŵŝnjĂŶĚŽƚĞŵƉŽĞĞǀŝƚĂŶĚŽĞƌƌŽƐ͘
ϯ͘ϯWƌŽĐĞĚŝŵĞŶƚŽĚĞĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐĚŽ>'KƉƟŵƵƐϯ;WϵϮϬŚͿ
KƉƌŽĐĞƐƐŽĚĞĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐĚĞƵŵWϵϮϬŚĐŽŵĞĕĂƉŽƌƵŵĂĂŶĄůŝƐĞ
ĚŽĞƐƚĂĚŽŝŶŝĐŝĂůĚŽĂƉĂƌĞůŚŽ͘^ĞŽĂƉĂƌĞůŚŽĞƐƟǀĞƌĚĞƐůŝŐĂĚŽ͕ĚĞǀĞƐĞƌǀĞƌŝĮĐĂĚĂ
ĂƉƌĞƐĞŶĕĂĚĞĐĂƌƚƁĞƐ^/DĞ^͘KĐĂƌƚĆŽ^͕ĐĂƐŽƉƌĞƐĞŶƚĞ͕ƉŽĚĞƐĞƌƌĞŵŽǀŝĚŽ
ƉĂƌĂ ĂŶĄůŝƐĞ ŶĂ ŵĄƋƵŝŶĂ ĚŽ ĞdžĂŵŝŶĂĚŽƌ͘ K ĐĂƌƚĆŽ ^/D ĚĞǀĞ ƐĞƌ ƌĞŵŽǀŝĚŽ ƉĂƌĂ
ĞǀŝƚĂƌƋƵĞŽĂƉĂƌĞůŚŽƚĞŶƚĞƐĞĐŽŶĞĐƚĂƌăƐƚĂĕĆŽZĄĚŝŽĂƐĞ;ZͿƋƵĂŶĚŽůŝŐĂĚŽ͘
ŵďŽƐŽƐĐĂƌƚƁĞƐĮĐĂŵŶĂƉĂƌƚĞƚƌĂƐĞŝƌĂĚŽĂƉĂƌĞůŚŽ͕ĐŽŵŽŵŽƐƚƌĂĚŽŶĂ&ŝŐƵƌĂϳ͘
Figura 7
WϵϮϬŚͲ^/DCard e SD Card
ƉſƐĂĐŽŶƐƚĂƚĂĕĆŽĚĞƋƵĞĂŽƉĕĆŽĞƉƵƌĂĕĆŽh^ĞƐƚĄĚĞƐĂďŝůŝƚĂĚĂ͕
Ž ďůŽƋƵĞŝŽ ĚĞ ƚĞůĂ ĞƐƚĄ ĂƟǀŽ Ğ Ž ƉĂĚƌĆŽ͕ W/E ŽƵ ƐĞŶŚĂ ĚĞ ĚĞƐďůŽƋƵĞŝŽ ŶĆŽ Ġ
ĐŽŶŚĞĐŝĚŽ͕ŽƉƌſdžŝŵŽƉĂƐƐŽĠŝŶŝĐŝĂůŝnjĂƌŽĐĞůƵůĂƌŶŽŵŽĚŽrecovery.
EŽŵŽĚŽrecovery͕ŽƉĞƌŝƚŽĚĞǀĞůŝŐĂƌŽĐĂďŽh^ĞƚĞŶƚĂƌǀĞƌŝĮĐĂƌƐĞĠ
ƉŽƐƐşǀĞůĐŽŶĞĐƚĂƌͲƐĞĂŽĂƉĂƌĞůŚŽƵƐĂŶĚŽŽ͘/ƐƐŽƉŽĚĞƐĞƌĨĞŝƚŽĐŽŵŽĐŽŵĂŶĚŽ
ĂĚďdevices͕ƋƵĞůŝƐƚĂƚŽĚŽƐŽƐĂƉĂƌĞůŚŽƐĐŽŶĞĐƚĂĚŽƐăƉŽƌƚĂh^ĞƋƵĞĞƐƚĆŽĐŽŵ
ŽƐĞƌǀŝĕŽĚŽĂĚďĞŵĞdžĞĐƵĕĆŽ͘ĞdžĞĐƵĕĆŽĚĞƐƚĞĐŽŵĂŶĚŽĞŵƵŵWϵϮϬŚĐŽŵĂ
ƉĂƌƟĕĆŽrecoveryƉĂĚƌĆŽŶĆŽůŝƐƚŽƵĚŝƐƉŽƐŝƟǀŽƐ͕ĐŽŵŽŵŽƐƚƌĂĂ&ŝŐƵƌĂϵ͘
Figura 9
Execução do comando adb ĚĞǀŝĐĞŶŽWϵϮϬŚ
ϯ͘ϯ͘Ϯ^ƵďƐƟƚƵŝĕĆŽĚĂƉĂƌƟĕĆŽƌĞĐŽǀĞƌLJƵƐĂŶĚŽŽĨĂƐƚƚ
ƐƵďƐƟƚƵŝĕĆŽ ĚĂ ƉĂƌƟĕĆŽ recovery ŽƌŝŐŝŶĂů ĚŽ WϵϮϬŚ Ġ ŶĞĐĞƐƐĄƌŝĂ͕
ƉŽŝƐĞƐƚĂƉĂƌƟĕĆŽŶĆŽƉĞƌŵŝƚĞĐŽŶĞdžĆŽǀŝĂ͘ƐƐĂƐƵďƐƟƚƵŝĕĆŽƉŽĚĞƐĞƌĨĞŝƚĂ
ƵƟůŝnjĂŶĚŽĂĨĞƌƌĂŵĞŶƚĂ>'dŽŽů;ŚƩƉ͗ͬͬǁǁǁ͘ůŐƚŽŽů͘ŶĞƚͬͿŽƵƵƟůŝnjĂŶĚŽŽfastboot.
EĞƐƚĞ ĞdžƉĞƌŝŵĞŶƚŽ͕ Ă ƐƵďƐƟƚƵŝĕĆŽ ĨŽŝ ĨĞŝƚĂ ĐŽŵ Ž ƵƟůŝƚĄƌŝŽ fastboot͕ ƉŽŝƐ Ă
ĨĞƌƌĂŵĞŶƚĂ>'dŽŽůĠƉƌŽƉƌŝĞƚĄƌŝĂĞŶĞĐĞƐƐŝƚĂĚĞĂƟǀĂĕĆŽ͘
Figura 11
Modo fastboot e modo download no WϵϮϬŚ
Figura 12
Comando ĨĂƐƚƚĚĞǀŝĐĞƐ
ƉƌſdžŝŵĂĞƚĂƉĂĠĂƐƵďƐƟƚƵŝĕĆŽĚĂƉĂƌƟĕĆŽĞŵƐŝ͘/ƐƐŽƉŽĚĞƐĞƌĨĞŝƚŽ
ĐŽŵ Ž ĐŽŵĂŶĚŽ ĨĂƐƚƚ ŇĂƐŚ ƌĞĐŽǀĞƌLJ ƌĞĐŽǀĞƌLJ͘ŝŵŐ͘ ƐƚĞ ĐŽŵĂŶĚŽ ƐƵďƐƟƚƵŝ
Ă ƉĂƌƟĕĆŽ recovery ƉĞůĂ ŝŵĂŐĞŵ ƌĞĐŽǀĞƌLJ͘ŝŵŐ ĨŽƌŶĞĐŝĚĂ͘ K ƌĞƐƵůƚĂĚŽ ĚĞƐƚĞ
ĐŽŵĂŶĚŽƉŽĚĞƐĞƌǀŝƐƵĂůŝnjĂĚŽŶĂ&ŝŐƵƌĂϭϯ͘
WŽƌĮŵ͕ŽƚĞůĞĨŽŶĞĚĞǀĞƐĞƌůŝŐĂĚŽŶŽǀĂŵĞŶƚĞŶŽŵŽĚŽrecovery͘^Ğ
ƚŽĚĂƐĂƐĞƚĂƉĂƐĨŽƌĂŵĐŽŶĐůƵşĚĂƐĐŽŵƐƵĐĞƐƐŽ͕ĂƚĞůĂĚŽĂƉĂƌĞůŚŽĚĞǀĞĂƉƌĞƐĞŶƚĂƌ
ĂŝŶƚĞƌĨĂĐĞĚĂůŽĐŬǁŽƌŬDŽĚ͕ĐŽŵŽŝůƵƐƚƌĂĂ&ŝŐƵƌĂϭϰ͘ŐŽƌĂ͕ĠƉŽƐƐşǀĞůĐŽŶĞĐƚĂƌ
ŽĐĂďŽh^ĞĐŽŵƵŶŝĐĂƌͲƐĞĂŽĂƉĂƌĞůŚŽƵƟůŝnjĂŶĚŽĂƉĂƌƟĕĆŽrecoveryŝŶƐƚĂůĂĚĂ͘
Figura 14
WϵϮϬŚĂƉƌĞƐĞŶƚĂŶĚŽŽƌĞĐŽǀĞƌLJŵŽĚĞĐŽŵůŽĐŬǁŽƌŬDŽĚ
ϯ͘ϯ͘ϯſƉŝĂĚŽƐĚĂĚŽƐ
KŵĠƚŽĚŽĚĞĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐƵƟůŝnjĂĚŽŶĞƐƚĞĞdžƉĞƌŝŵĞŶƚŽĨŽŝŽĂĚďpull.
ƐƚĞĠƵŵŵĠƚŽĚŽƌĄƉŝĚŽĞƐŝŵƉůĞƐĚĞƐĞƌĞdžĞĐƵƚĂĚŽ͕ƉŽŝƐĐŽŶƐŝƐƚĞƐŝŵƉůĞƐŵĞŶƚĞŶĂ
ĐſƉŝĂĚĂƉĂƌƟĕĆŽͬĚĂƚĂƉĂƌĂĂŵĄƋƵŝŶĂĚŽĞdžĂŵŝŶĂĚŽƌƵƟůŝnjĂŶĚŽŽ͘
/ŶŝĐŝĂůŵĞŶƚĞ͕ĠŶĞĐĞƐƐĄƌŝŽƋƵĞŽĂƉĂƌĞůŚŽƐĞũĂůŝŐĂĚŽŶŽŵŽĚŽrecovery.
ŵ ƐĞŐƵŝĚĂ͕ Ġ ŶĞĐĞƐƐĄƌŝŽ ƋƵĞ Ă ƉĂƌƟĕĆŽ ͬĚĂƚĂ ƐĞũĂ ŵŽŶƚĂĚĂ͘ WĂƌĂ ĨĂnjĞƌ ŝƐƐŽ͕ Ġ
ƉƌĞĐŝƐŽĐŽŶĞĐƚĂƌͲƐĞĐŽŵŽĂƉĂƌĞůŚŽĂƚƌĂǀĠƐĚŽĐŽŵĂŶĚŽĂĚďshellĞĞdžĞĐƵƚĂƌŽ
ĐŽŵĂŶĚŽmountͬĚĂƚĂ͘hŵĚŝƌĞƚſƌŝŽŶĂŵĄƋƵŝŶĂĚŽĞdžĂŵŝŶĂĚŽƌƚĂŵďĠŵĚĞǀĞ
ƐĞƌĐƌŝĂĚŽƉĂƌĂĂƌŵĂnjĞŶĂƌŽƐĂƌƋƵŝǀŽƐĐŽƉŝĂĚŽƐĚŽƚĞůĞĨŽŶĞ͘WŽƌĮŵ͕ŽĐŽŵĂŶĚŽ
ĂĚďpullĚĞǀĞƐĞƌĞŵŝƟĚŽƉĂƌĂƌĞĂůŝnjĂƌĂĐſƉŝĂĚŽƐĂƌƋƵŝǀŽƐ͘ĞdžĞĐƵĕĆŽĚĞƐƚĞƐ
ĐŽŵĂŶĚŽƐŶŽWϵϮϬŚĠŵŽƐƚƌĂĚĂŶĂ&ŝŐƵƌĂϭϱ͘
ϰZ^h>dK^/^h^^K
ϰ͘ϭZĞƐƵůƚĂĚŽƐƉĂƌĂŽ>'KƉƟŵƵƐϯ;WϵϮϬŚͿ
ŽŶĨŽƌŵĞ ĂƉƌĞƐĞŶƚĂĚŽ ŶĂ ƐĞĕĆŽ ϯ͘ϯ͕ Ă ƐƵďƐƚŝƚƵŝĕĆŽ ĚĂ ƉĂƌƚŝĕĆŽ
recovery ĨŽŝ ƌĞĂůŝnjĂĚĂ͕ Ž ƋƵĞ ƉĞƌŵŝƚŝƵ Ă ŝŶŝĐŝĂůŝnjĂĕĆŽ ĚŽ ĂƉĂƌĞůŚŽ ŶŽ ŵŽĚŽ
recoveryĐŽŵŽůŽĐŬǁŽƌŬDŽĚ͕ĞĂƐƵďƐĞƋƵĞŶƚĞĞdžƚƌĂĕĆŽĚĞĚĂĚŽƐǀŝĂĂĚď
pull͕ ĐŽŶĞĐƚĂŶĚŽͲƐĞ ĂŽ ĂƉĂƌĞůŚŽ ĂƚƌĂǀĠƐ ĚŽ ĐŽŵĂŶĚŽ ĂĚď shell͘ ƉĂƌƚŝƌ
ĚĂş͕ ƚŽĚŽƐ ŽƐ ĂƌƋƵŝǀŽƐ ĚĂ ƉĂƌƚŝĕĆŽ ĚĞ ĚĂĚŽƐ ƉƵĚĞƌĂŵ ƐĞƌ ĐŽƉŝĂĚŽƐ ƉĂƌĂ Ă
ŵĄƋƵŝŶĂ ĚŽ ĞdžĂŵŝŶĂĚŽƌ͘ hŵĂ ǀĞnj Ğdžƚƌú̎Ɛ ŽƐ ĚĂĚŽƐ͕ Ž ĞdžĂŵŝŶĂĚŽƌ ĚĞǀĞ
ĂŶĂůŝƐĂƌĨŽƚŽƐ͕ĐŽŶƚĂƚŽƐ͕ŝŵĂŐĞŶƐ͕ďĂŶĐŽƐĚĞĚĂĚŽƐĞƚĐ͘ĞŵďƵƐĐĂĚĞƉŽƐƐşǀĞŝƐ
ĞǀŝĚġŶĐŝĂƐĚŝŐŝƚĂŝƐ͘
Z&ZE/^/>/K'Z&/^
EZK/s>KWZ^͘Android Debug Bridge.ŝƐƉŽŶşǀĞůĞŵ͗фŚƩƉ͗ͬͬĚĞǀĞůŽƉĞƌ͘ĂŶĚƌŽŝĚ͘ĐŽŵͬƚŽŽůƐͬ
ŚĞůƉͬĂĚď͘Śƚŵůх͘ĐĞƐƐŽĞŵ͗ϭϯũĂŶ͘ϮϬϭϰĂ͘
'/d,hʹKDWϰKKd͘dŽŽůƐƚŽďŽŽƚŽŵĂƉϰdždžŽǀĞƌh^͘ŝƐƉŽŶşǀĞůĞŵ͗фŚƩƉƐ͗ͬͬŐŝƚŚƵď͘ĐŽŵͬƐǁĞƚͲ
ůĂŶĚͬŽŵĂƉϰƚх͘ĐĞƐƐŽĞŵ͗ϭϴĂďƌ͘ϮϬϭϰ͘
,^DE͕͘ŶĚƌŽŝĚƐƐĞŶƟĂůƐ͘EĞǁzŽƌŬ͗ƉƌĞƐƐ͕ϮϬϬϴ͘
,KK'͕ŶĚƌĞǁ͘ŶĚƌŽŝĚ&ŽƌĞŶƐŝĐƐͲ/ŶǀĞƐƟŐĂƟŽŶ͕ŶĂůLJƐŝƐĂŶĚDŽďŝůĞ^ĞĐƵƌŝƚLJĨŽƌ'ŽŽŐůĞŶĚƌŽŝĚ.
tĂůƚŚĂŵ͗ůƐĞǀŝĞƌ͕ϮϬϭϭ͘
<>/DE͕ĂǀĞ͘dŚĞKĸĐŝĂů,&/^ƚƵĚLJ'ƵŝĚĞ;džĂŵϯϭϮͲϰϵͿĨŽƌŽŵƉƵƚĞƌ,ĂĐŬŝŶŐ&ŽƌĞŶƐŝĐ/ŶǀĞƐƟŐĂ-
tors͘ƵƌůŝŶŐƚŽŶ͗^LJŶŐƌĞƐƐ͕ϮϬϬϳ͘
>'>dZKE/^͘>'ͲWϵϮϬŚ͘DĂŶƵĂůĚŽƵƐƵĄƌŝŽ͕ϮϬϭϭ͘
D,WdZ͕>͘dĞĐŚͬ^Đŝ͘/ŶƚĞƌŶĂƟŽŶĂůƵƐŝŶĞƐƐdŝŵĞƐ͘ϮϬϭϯ͘ŝƐƉŽŶşǀĞůĞŵ͗фŚƩƉ͗ͬͬǁǁǁ͘ŝďƟŵĞƐ͘
ĐŽŵͬĂŶĚƌŽŝĚͲǀƐͲŝŽƐͲǁŚĂƚƐͲŵŽƐƚͲƉŽƉƵůĂƌͲŵŽďŝůĞͲŽƉĞƌĂƟŶŐͲƐLJƐƚĞŵͲLJŽƵƌͲĐŽƵŶƚƌLJͲϭϰϲϰϴϵϮх͘ ĐĞƐƐŽ
Ğŵ͗ϮϲŶŽǀ͘ϮϬϭϯ͘
^/DK͕ŶĚƌĠDŽƌƵŵĚĞ>͘WƌŽƉŽƐƚĂĚĞŵĠƚŽĚŽƉĂƌĂŶĄůŝƐĞWĞƌŝĐŝĂůĞŵ^ŵĂƌƚƉŚŽŶĞĐŽŵ^ŝƐƚĞŵĂKƉ-
eracional Android͘ϮϬϭϭ͘ŝƐƐĞƌƚĂĕĆŽ;DĞƐƚƌĂĚŽĞŵŶŐĞŶŚĂƌŝĂůĠƚƌŝĐĂͿͲĞƉĂƌƚĂŵĞŶƚŽĚĞŶŐĞŶŚĂƌŝĂ
ůĠƚƌŝĐĂ͕hŶŝǀĞƌƐŝĚĂĚĞĚĞƌĂƐşůŝĂ͕ƌĂƐşůŝĂ͕ϮϬϭϭ͘
^KE͕EĂŵŚĞƵŶ͖>͕zƵŶŚŽ͖</D͕ŽŚLJƵŶ͖:D^͕:ŽƐŚƵĂ͖>͕^ĂŶŐũŝŶ͖>͕<LJƵŶŐŚŽ͘ƐƚƵĚLJŽĨƵƐĞƌ
ĚĂƚĂŝŶƚĞŐƌŝƚLJĚƵƌŝŶŐĂĐƋƵŝƐŝƟŽŶŽĨŶĚƌŽŝĚĚĞǀŝĐĞƐ͘ŝŐŝƚĂů/ŶǀĞƐƟŐĂƟŽŶ͗dŚĞ/ŶƚĞƌŶĂƟŽŶĂů:ŽƵƌŶĂůŽĨ
Digital Forensics & Incident Response͕ϭϬ͕Ɖ͘^ϯͲ^ϭϭ͕ĂŐŽ͘ϮϬϭϯ͘
s/^͕dŝŵŽƚŚLJ͖,E'͕ŚĞŶŐLJĞ͖,Z/^d/E͕EŝĐŽůĂƐ͘dŽǁĂƌĚĂŐĞŶĞƌĂůĐŽůůĞĐƟŽŶŵĞƚŚŽĚŽůŽŐLJĨŽƌŶͲ
ĚƌŽŝĚĚĞǀŝĐĞƐ͘ŝŐŝƚĂů/ŶǀĞƐƟŐĂƟŽŶ͗dŚĞ/ŶƚĞƌŶĂƟŽŶĂů:ŽƵƌŶĂůŽĨŝŐŝƚĂů&ŽƌĞŶƐŝĐƐΘ/ŶĐŝĚĞŶƚZĞƐƉŽŶƐĞ͕
ϴ͕Ɖ͘^ϭϰͲ^Ϯϰ͕ĂŐŽ͘ϮϬϭϭ͘
ys>KWZ^͘Recovery͘ŝƐƉŽŶşǀĞůĞŵ͗фŚƩƉ͗ͬͬĨŽƌƵŵ͘džĚĂͲĚĞǀĞůŽƉĞƌƐ͘ĐŽŵͬǁŝŬŝͬZĞĐŽǀĞƌLJх͘ĐĞƐͲ
ƐŽĞŵ͗ϬϭŵĂƌ͘ϮϬϭϰĂ͘
ys>KWZ^͘Boot Loader͘ŝƐƉŽŶşǀĞůĞŵ͗фŚƩƉ͗ͬͬĨŽƌƵŵ͘džĚĂͲĚĞǀĞůŽƉĞƌƐ͘ĐŽŵͬǁŝŬŝͬŽŽƚůŽĂĚĞƌ
х͘ĐĞƐƐŽĞŵ͗ϬϯŵĂƌ͘ϮϬϭϰď͘