Extracting Image Geotags with Exifprobe
Geotagging is the process of embedding geographical metadata to a piece of media. In the iPhone’s case, these are images. An iPhone running firmware v2.0 or greater can embed longitude and latitude coordinates inside images snapped with the built-in camera. Geotagging can be disabled when photos are taken, but in many cases, a suspect may either forget to disable it or fail to realize its consequences. By extracting the geotag from an image, you’ll be able to pinpoint the general location where the photo was snapped.
Warning
As of firmware v2.0, geotag information is missing the degree of seconds, making an exact pinpoint impossible. This may be corrected in future versions.
Exifprobe is a camera image file utility developed by Duane Hesser. Among its features is the ability to extract image metadata. Download Exifprobe from http://www.virtual-cafe.com/~dhh/tools.d/exifprobe.d/exifprobe.html.
To check an image for geotags, call exifprobe on the command line:
%exifprobe –Lfilename.jpg
If the image was tagged, you’ll see a GPS latitude and longitude reported, as shown below:
JPEG.APP1.Ifd0.Gps.LatitudeRef = 'N' JPEG.APP1.Ifd0.Gps.Latitude = 42,57.45,0 JPEG.APP1.Ifd0.Gps.LongitudeRef = 'W\000' JPEG.APP1.Ifd0.Gps.Longitude = 71,32.9,0
In this example, the photo was taken at 42.57450, −71.3290.
In addition to a geotag for the image, the timestamp that the actual photo was taken can be recovered:
JPEG.APP1.Ifd0.Exif.DateTimeOriginal = '2008:07:26 22:07:35' ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access