Skip to Main Content
Learning Android Forensics - Second Edition
book

Learning Android Forensics - Second Edition

by Oleg Skulkin, Donnie Tindall, Rohit Tamma
December 2018
Beginner to intermediate content levelBeginner to intermediate
328 pages
8h 29m
English
Packt Publishing
Content preview from Learning Android Forensics - Second Edition

Facebook Messenger analysis

Facebook Messenger is messaging app, separate from the main Facebook application. It has over 500,000,000 downloads in the Play Store.

Package name: com.facebook.orca

Files of interest:

  • /cache/
    • audio/
    • fb_temp/
    • image/
  • /sdcard/com.facebook.orca
  • /files/ rti.mqtt.analytics.xml
  • /databases/
    • call_log.sqlite
    • contacts_db2
    • prefs_db
    • threads_db2

The /cache/audio directory contains audio messages sent through the application. The files have a .cnt file extension, but are actually RIFF files that can be played with Windows Media Player, VLC media player, and other programs.

The /cache/fb_temp path contains temp files for images and video sent through the application. It is unclear how long these files will remain; in ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Learning Android Forensics

Learning Android Forensics

Rohit Tamma, Donnie Tindall
Windows Forensics Cookbook

Windows Forensics Cookbook

Scar de Courcier, Oleg Skulkin
Hacking Android

Hacking Android

Mohammed A. Imran, Srinivasa Rao Kotipalli

Publisher Resources

ISBN: 9781789131017Other