Forensics toolkit cracks open the Xbox gaming console


May 5, 2009

The XFT toolkit lays the contents of the Xbox hard drive bare

The XFT toolkit lays the contents of the Xbox hard drive bare

May 6, 2009 Those who think the Xbox game console may be the perfect place to hide illicit material from prying eyes – principally because it isn't seen as a regular-joe PC – had better think again. Computer scientist David Collins has developed a toolkit that allows police and other law-enforcement agencies to recover criminal data more easily from hard drives like the Xbox.

The problem for investigators lies in the FATX file system used by the Xbox. Unlike the standard FAT32, NTFS and similar systems used by regular PC hard disks, there is little documentation on the proprietary FATX system. Collins' XFT utility, however, mounts an image of the FATX file system, allowing investigators to explore in detail the directory structure. An analyst can use shell commands to browse the directory tree, open files, view files in hex editor mode, list the contents of the current directory, in short or long mode, and expand the current directory to list all associated subdirectories and files. Importantly, from a legal perspective, XFT can also record such investigative sessions to play back in court, if required.

At the moment the XFT toolkit is limited to cracking open the data on an Xbox, but Collins hopes to extend the utility into a fully functional forensic operating system, which will be packaged as both a bootable operating system from a hard disk and a "live" bootable compact disc. "This implementation will be open source, verbosely commented and designed from the ground up as a forensic OS," says Collins.

So the message for any one thinking of using their Xbox for anything nefarious: stick to virtual crime, like Grand Theft Auto 3.

More detailed information about the XFT forensics toolkit is available in volume 2, issue 2, 2009 of the International Journal of Electronic Security and Digital Forensics.

Darren Quick

About the Author
Darren Quick Darren's love of technology started in primary school with a Nintendo Game & Watch Donkey Kong (still functioning) and a Commodore VIC 20 computer (not still functioning). In high school he upgraded to a 286 PC, and he's been following Moore's law ever since. This love of technology continued through a number of university courses and crappy jobs until 2008, when his interests found a home at Gizmag. All articles by Darren Quick
Post a Comment

Login with your Gizmag account:

Related Articles
Looking for something? Search our articles