Skip to Main Content
Learning Android Forensics
book

Learning Android Forensics

by Rohit Tamma, Donnie Tindall
April 2015
Beginner to intermediate content levelBeginner to intermediate
322 pages
7h 11m
English
Packt Publishing
Content preview from Learning Android Forensics

Facebook analysis

Facebook is a social-media application with more than 1 billion downloads from Google Play.

Package name: com.facebook.katana

Version: 25.0.0.19.30

Files of interest:

  • /files/video-cache/
  • /cache/images/
  • /databases/
    • bookmarks_db2
    • contacts_db2
    • nearbytiles_db
    • newsfeed_db
    • notifications_db
    • prefs_db
    • threads_db2

The /files/video-cache directory contains videos from the user's newsfeed, though there does not appear to be a way to correlate them back to the user who posted them.

The /cache/images directory contains images from the user's newsfeed as well as the profile photos of contacts. This directory contains a multitude of other directories (65 on our test phone), and each directory can contain multiple .cnt files. The .cnt files are typically ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Android Forensics

Android Forensics

Andrew Hoog
Learning Android Forensics - Second Edition

Learning Android Forensics - Second Edition

Oleg Skulkin, Donnie Tindall, Rohit Tamma
Hacking Android

Hacking Android

Mohammed A. Imran, Srinivasa Rao Kotipalli

Publisher Resources

ISBN: 9781782174578