Greg Kelley
2005-08-18 23:10:16 UTC
I have been talking with Karl Dunnagan and he said I should post the
following here...
I believe I have found where the date is stored in the Inbox messages.
Here is what I did:
1. Took 4 messages exported from an LG LX5450 using BitPim
2. Noted the time and date stamp for each message as stored in the phone
OS
3. Downloaded QualComms Brew SDK and tools.
4. Used the Brew Simulator and SMS Emulator to get a Timestamp (in
decimal format) for the dates of the stored SMS message using the date
time reported in the phone OS. In doing further inspection, this
"Timestamp" is the number of seconds from 1/1/1980 12:00:00am to the
current time and date.
5. Converted the Timestamp to hexadecimal and looked for the value
inside of the stored SMS message
6. I believe I found the timestamp stored in bytes 78 through 7B.
However, the bytes are in reverse order.
7. Of the 4 messages I played with, 2 of them had a stored timestamp
that was 3 hours off of the file date/time. The other 2 messages were 2
hours off. Well, in looking further, the 2 that were 3 hours off came
in on or before 10/30/2004 and the 2 that were just 2 hours off came in
after 10/30/2004. Why is 10/30/2004 important? Because day light
savings ended on 10/31/2004 at 2am.
I hope this proves helpful and others can test to prove or disprove my
hypothesis. Now, if someone could help me with an issue I have, I would
be VERY GRATEFUL. I need to take these Inbox and Outbox messages that I
exported using BitPim and convert the portion that has the 7bit message
body into a readable message. Can somone help with this? I know they
are in a packed format and I thought I read and executed the conversion
properly, but I got gibberish after the conversion.
Greg Kelley, EnCE
Vestige Digital Investigations
Computer Forensics | Electronic Discovery | Corporate Surety
46 Public Square, Ste 220
Medina, OH 44256
(330)721-1205 x5432
(330)721-1206 Fax
http://www.vestigeltd.com
following here...
I believe I have found where the date is stored in the Inbox messages.
Here is what I did:
1. Took 4 messages exported from an LG LX5450 using BitPim
2. Noted the time and date stamp for each message as stored in the phone
OS
3. Downloaded QualComms Brew SDK and tools.
4. Used the Brew Simulator and SMS Emulator to get a Timestamp (in
decimal format) for the dates of the stored SMS message using the date
time reported in the phone OS. In doing further inspection, this
"Timestamp" is the number of seconds from 1/1/1980 12:00:00am to the
current time and date.
5. Converted the Timestamp to hexadecimal and looked for the value
inside of the stored SMS message
6. I believe I found the timestamp stored in bytes 78 through 7B.
However, the bytes are in reverse order.
7. Of the 4 messages I played with, 2 of them had a stored timestamp
that was 3 hours off of the file date/time. The other 2 messages were 2
hours off. Well, in looking further, the 2 that were 3 hours off came
in on or before 10/30/2004 and the 2 that were just 2 hours off came in
after 10/30/2004. Why is 10/30/2004 important? Because day light
savings ended on 10/31/2004 at 2am.
I hope this proves helpful and others can test to prove or disprove my
hypothesis. Now, if someone could help me with an issue I have, I would
be VERY GRATEFUL. I need to take these Inbox and Outbox messages that I
exported using BitPim and convert the portion that has the 7bit message
body into a readable message. Can somone help with this? I know they
are in a packed format and I thought I read and executed the conversion
properly, but I got gibberish after the conversion.
Greg Kelley, EnCE
Vestige Digital Investigations
Computer Forensics | Electronic Discovery | Corporate Surety
46 Public Square, Ste 220
Medina, OH 44256
(330)721-1205 x5432
(330)721-1206 Fax
http://www.vestigeltd.com