index.js 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507
  1. #!/usr/bin/env node
  2. const chalk = require('chalk')
  3. const fs = require('fs-extra')
  4. const program = require('commander')
  5. const path = require('path')
  6. const { URL } = require('url')
  7. const stripAnsi = require('strip-ansi')
  8. const iPhoneBackup = require('./util/iphone_backup.js').iPhoneBackup
  9. const normalizeCols = require('./util/normalize.js')
  10. var base = path.join(process.env.HOME, '/Library/Application Support/MobileSync/Backup/')
  11. program
  12. .version('2.0.2')
  13. .option('-l, --list', 'List Backups')
  14. .option('-c, --conversations', 'List Conversations')
  15. .option('-m, --messages <conversation_id>', 'List Conversations')
  16. .option('-r, --report <report_type>', 'Report types: apps, notes, webhistory, photolocations, manifest')
  17. .option(`-d, --dir <directory>`, `Backup Directory (default: ${base})`)
  18. .option(`-u, --device <device>`, 'Device UUID')
  19. .option(`-b, --backup <backup>`, 'Backup ID')
  20. .option(`-v, --verbose`, 'Verbose debugging output')
  21. .option(`-x, --no-color`, 'Disable colorized output')
  22. .option('-z, --dump', 'Dump a ton of raw JSON formatted data instead of formatted output')
  23. .option(`-e, --extract <dir>`, 'Extract data for commands. reports: voicemail')
  24. program.on('--help', function(){
  25. console.log('')
  26. console.log("If you're interested to know how this works, check out my post:")
  27. console.log("https://www.richinfante.com/2017/3/16/reverse-engineering-the-ios-backup")
  28. console.log('')
  29. })
  30. program.parse(process.argv);
  31. if(!process.stdout.isTTY) { program.color = false }
  32. base = program.dir || base
  33. if(program.verbose) console.log('Using source:', base)
  34. if(program.list) {
  35. var items = fs.readdirSync(base, { encoding: 'utf8' })
  36. .filter(el => (el.length == 40))
  37. .map(file => iPhoneBackup.fromID(file, base))
  38. // Possibly dump output
  39. if(program.dump) {
  40. console.log(JSON.stringify(items, null, 4))
  41. return
  42. }
  43. items = items.map(el => {
  44. return {
  45. encrypted: el.manifest ? el.manifest.IsEncrypted
  46. ? chalk.green('encrypted')
  47. : chalk.red('not encrypted')
  48. : 'unknown encryption',
  49. device_name: el.manifest ? el.manifest.Lockdown.DeviceName : 'Unknown Device',
  50. device_id: el.id,
  51. serial: el.manifest.Lockdown.SerialNumber,
  52. iOSVersion: el.manifest.Lockdown.ProductVersion + '(' + el.manifest.Lockdown.BuildVersion + ')',
  53. backupVersion: el.status ? el.status.Version : '?',
  54. date: el.status ? new Date(el.status.Date).toLocaleString() : ''
  55. }})
  56. .map(el => [
  57. chalk.gray(el.device_id),
  58. el.encrypted,
  59. el.date,
  60. el.device_name,
  61. el.serial,
  62. el.iOSVersion,
  63. el.backupVersion
  64. ])
  65. items = [
  66. ['UDID', 'Encryption', 'Date', 'Device Name', 'Serial #', 'iOS Version', 'Backup Version'],
  67. ['-','-','-','-','-','-','-'],
  68. ...items
  69. ]
  70. items = normalizeCols(items)
  71. items = items.map(el => el.join(' | ')).join('\n')
  72. if(!program.color) { items = stripAnsi(items) }
  73. console.log('BACKUPS LIST')
  74. console.log(items)
  75. } else if (program.conversations) {
  76. if(!program.backup) {
  77. console.log('use -b or --backup <id> to specify backup.')
  78. process.exit(1)
  79. }
  80. // Grab the backup
  81. var backup = iPhoneBackup.fromID(program.backup, base)
  82. backup.getConversations(program.dump)
  83. .then((items) => {
  84. if(program.dump) return
  85. var items = items.map(el => [
  86. el.ROWID + '',
  87. chalk.gray(el.XFORMATTEDDATESTRING || '??'),
  88. el.chat_identifier + '',
  89. el.display_name + ''
  90. ])
  91. items = [['ID', 'DATE', 'Chat Name', 'Display Name'], ['-', '-', '-', '-',], ...items]
  92. items = normalizeCols(items).map(el => el.join(' | ')).join('\n')
  93. if(!program.color) { items = stripAnsi(items) }
  94. console.log(items)
  95. })
  96. .catch((e) => {
  97. console.log('[!] Encountered an Error:', e)
  98. })
  99. } else if(program.messages) {
  100. if(!program.backup) {
  101. console.log('use -b or --backup <id> to specify backup.')
  102. process.exit(1)
  103. }
  104. // Grab the backup
  105. var backup = iPhoneBackup.fromID(program.backup, base)
  106. backup.getMessages(program.messages, program.dump)
  107. .then((items) => {
  108. if(program.dump) return
  109. items = items.map(el => [
  110. chalk.gray(el.XFORMATTEDDATESTRING + ''),
  111. chalk.blue(el.x_sender + ''),
  112. el.text || ''
  113. ])
  114. items = normalizeCols(items, 2).map(el => el.join(' | ')).join('\n')
  115. if(!program.color) { items = stripAnsi(items) }
  116. console.log(items)
  117. })
  118. .catch((e) => {
  119. console.log('[!] Encountered an Error:', e)
  120. })
  121. } else if(program.report) {
  122. ///
  123. /// APPS REPORT
  124. ///
  125. if(program.report == 'apps') {
  126. if(!program.backup) {
  127. console.log('use -b or --backup <id> to specify backup.')
  128. process.exit(1)
  129. }
  130. // Grab the backup
  131. var backup = iPhoneBackup.fromID(program.backup, base)
  132. if (!backup.manifest) return {}
  133. // Possibly dump output
  134. if(program.dump) {
  135. console.log(JSON.stringify(backup.manifest, null, 4))
  136. return
  137. }
  138. // Enumerate the apps in the backup
  139. var apps = []
  140. for (var key in backup.manifest.Applications) {
  141. apps.push(key)
  142. }
  143. console.log(`Apps installed inside backup: ${backup.id}`)
  144. console.log(apps.map(el => '- ' + el).join('\n'))
  145. } else if(program.report == 'oldnotes') {
  146. if(!program.backup) {
  147. console.log('use -b or --backup <id> to specify backup.')
  148. process.exit(1)
  149. }
  150. // Grab the backup
  151. var backup = iPhoneBackup.fromID(program.backup, base)
  152. backup.getOldNotes(program.dump)
  153. .then((items) => {
  154. // Dump if needed
  155. if(program.dump) {
  156. console.log(JSON.stringify(items, null, 4))
  157. return
  158. }
  159. // Otherwise, format table
  160. items = items.map(el => [el.XFORMATTEDDATESTRING + '', (el.Z_PK + ''), (el.ZTITLE + '').substring(0, 128)])
  161. items = [['Modified', 'ID', 'Title'], ['-', '-', '-'], ...items]
  162. items = normalizeCols(items).map(el => el.join(' | ')).join('\n')
  163. if(!program.color) { items = stripAnsi(items) }
  164. console.log(items)
  165. })
  166. .catch((e) => {
  167. console.log('[!] Encountered an Error:', e)
  168. })
  169. } else if(program.report == 'notes') {
  170. if(!program.backup) {
  171. console.log('use -b or --backup <id> to specify backup.')
  172. process.exit(1)
  173. }
  174. // Grab the backup
  175. var backup = iPhoneBackup.fromID(program.backup, base)
  176. backup.getNotes(program.dump)
  177. .then((items) => {
  178. // Dump if needed
  179. if(program.dump) {
  180. console.log(JSON.stringify(items, null, 4))
  181. return
  182. }
  183. // Otherwise, format table
  184. items = items.map(el => [
  185. (el.XFORMATTEDDATESTRING || el.XFORMATTEDDATESTRING1 )+ '',
  186. (el.Z_PK + ''),
  187. (el.ZTITLE2+ '').trim().substring(0, 128),
  188. (el.ZTITLE1+ '').trim() || ''
  189. ])
  190. items = [['Modified', 'ID', 'Title2', 'Title1'], ['-', '-', '-', '-'], ...items]
  191. items = normalizeCols(items, 3).map(el => el.join(' | ')).join('\n')
  192. if(!program.color) { items = stripAnsi(items) }
  193. console.log(items)
  194. })
  195. .catch((e) => {
  196. console.log('[!] Encountered an Error:', e)
  197. })
  198. } else if(program.report == 'webhistory') {
  199. if(!program.backup) {
  200. console.log('use -b or --backup <id> to specify backup.')
  201. process.exit(1)
  202. }
  203. // Grab the backup
  204. var backup = iPhoneBackup.fromID(program.backup, base)
  205. backup.getWebHistory(program.dump)
  206. .then((history) => {
  207. if(program.dump) {
  208. console.log(JSON.stringify(history, null, 4))
  209. return
  210. }
  211. var items = history.map(el => [
  212. el.XFORMATTEDDATESTRING + '' || '',
  213. new URL(el.url || '').origin || '',
  214. (el.title || '').substring(0, 64)
  215. ])
  216. items = [['Time', 'URL', 'Title'], ['-', '-', '-'], ...items]
  217. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  218. if(!program.color) { items = stripAnsi(items) }
  219. console.log(items)
  220. })
  221. .catch((e) => {
  222. console.log('[!] Encountered an Error:', e)
  223. })
  224. } else if(program.report == 'photolocations') {
  225. if(!program.backup) {
  226. console.log('use -b or --backup <id> to specify backup.')
  227. process.exit(1)
  228. }
  229. // Grab the backup
  230. var backup = iPhoneBackup.fromID(program.backup, base)
  231. backup.getPhotoLocationHistory(program.dump)
  232. .then((history) => {
  233. if(program.dump) {
  234. console.log(JSON.stringify(history, null, 4))
  235. return
  236. }
  237. var items = history.map(el => [
  238. el.XFORMATTEDDATESTRING + '' || '',
  239. el.ZLATITUDE + '' || '',
  240. el.ZLONGITUDE + '' || '',
  241. el.ZFILENAME + '' || ''
  242. ])
  243. items = [['Time', 'Latitude', 'Longitude', 'Photo Name'], ['-', '-', '-'], ...items]
  244. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  245. if(!program.color) { items = stripAnsi(items) }
  246. console.log(items)
  247. })
  248. .catch((e) => {
  249. console.log('[!] Encountered an Error:', e)
  250. })
  251. } else if(program.report == 'manifest') {
  252. if(!program.backup) {
  253. console.log('use -b or --backup <id> to specify backup.')
  254. process.exit(1)
  255. }
  256. // Grab the backup
  257. var backup = iPhoneBackup.fromID(program.backup, base)
  258. backup.getFileManifest()
  259. .then((items) => {
  260. if(program.dump) {
  261. console.log(JSON.stringify(items, null, 4))
  262. return
  263. }
  264. var items = items.map(el => [
  265. el.fileID + '',
  266. el.relativePath + ''
  267. ])
  268. items = [['ID', 'Path'], ['-', '-'], ...items]
  269. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  270. if(!program.color) { items = stripAnsi(items) }
  271. console.log(items)
  272. })
  273. .catch((e) => {
  274. console.log('[!] Encountered an Error:', e)
  275. })
  276. } else if(program.report == 'calls') {
  277. if(!program.backup) {
  278. console.log('use -b or --backup <id> to specify backup.')
  279. process.exit(1)
  280. }
  281. // Grab the backup
  282. var backup = iPhoneBackup.fromID(program.backup, base)
  283. backup.getCallsList()
  284. .then((items) => {
  285. if(program.dump) {
  286. console.log(JSON.stringify(items, null, 4))
  287. return
  288. }
  289. var items = items.map(el => [
  290. el.Z_PK + '',
  291. el.XFORMATTEDDATESTRING,
  292. el.ZANSWERED + '',
  293. el.ZORIGINATED + '',
  294. el.ZCALLTYPE + '',
  295. el.ZDURATION + '',
  296. el.ZLOCATION + '',
  297. el.ZISO_COUNTRY_CODE + '',
  298. el.ZSERVICE_PROVIDER + '',
  299. (el.ZADDRESS || '').toString()
  300. ])
  301. items = [['ID', 'Date', 'Answered', 'Originated', 'Type', 'Duration', 'Location', 'Country', 'Service', 'Address'], ['-', '-', '-', '-', '-', '-', '-', '-', '-', '-'], ...items]
  302. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  303. if(!program.color) { items = stripAnsi(items) }
  304. console.log(items)
  305. })
  306. .catch((e) => {
  307. console.log('[!] Encountered an Error:', e)
  308. })
  309. } else if(program.report == 'voicemail') {
  310. if(!program.backup) {
  311. console.log('use -b or --backup <id> to specify backup.')
  312. process.exit(1)
  313. }
  314. // Grab the backup
  315. var backup = iPhoneBackup.fromID(program.backup, base)
  316. backup.getVoicemailsList()
  317. .then((items) => {
  318. if(program.dump) {
  319. console.log(JSON.stringify(items, null, 4))
  320. return
  321. }
  322. var items = items.map(el => [
  323. el.ROWID + '',
  324. el.XFORMATTEDDATESTRING,
  325. el.sender + '',
  326. el.token + '',
  327. el.duration + '',
  328. el.expiration + '',
  329. el.trashed_date + '',
  330. el.flags + ''
  331. ])
  332. items = [['ID', 'Date', 'Sender', 'Token', 'Duration', 'Expiration', 'Trashed', 'Flags'], ['-', '-', '-', '-', '-', '-', '-', '-'], ...items]
  333. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  334. if(!program.color) { items = stripAnsi(items) }
  335. console.log(items)
  336. })
  337. .catch((e) => {
  338. console.log('[!] Encountered an Error:', e)
  339. })
  340. } else if(program.report == 'voicemail-files') {
  341. if(!program.backup) {
  342. console.log('use -b or --backup <id> to specify backup.')
  343. process.exit(1)
  344. }
  345. // Grab the backup
  346. var backup = iPhoneBackup.fromID(program.backup, base)
  347. backup.getVoicemailFileList()
  348. .then((list) => {
  349. if(program.dump) {
  350. console.log(JSON.stringify(list, null, 4))
  351. return
  352. }
  353. if(program.extract) {
  354. for(var item of list) {
  355. try {
  356. var outDir = path.join(program.extract, path.basename(item.relativePath))
  357. fs.ensureDirSync(path.dirname(outDir))
  358. fs.createReadStream(backup.getFileName(item.fileID)).pipe(fs.createWriteStream(outDir));
  359. item.output_dir = outDir
  360. }catch(e) {
  361. console.log(`Couldn't Export: ${item.relativePath}`, e)
  362. }
  363. }
  364. }
  365. var items = list.map(el => [
  366. el.fileID + '',
  367. el.relativePath,
  368. el.output_dir || '<not exported>'
  369. ])
  370. items = [['ID', 'Path', 'Exported Path'], ['-', '-', '-'], ...items]
  371. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  372. if(!program.color) { items = stripAnsi(items) }
  373. console.log(items)
  374. })
  375. .catch((e) => {
  376. console.log('[!] Encountered an Error:', e)
  377. })
  378. } else if(program.report == 'wifi') {
  379. if(!program.backup) {
  380. console.log('use -b or --backup <id> to specify backup.')
  381. process.exit(1)
  382. }
  383. // Grab the backup
  384. var backup = iPhoneBackup.fromID(program.backup, base)
  385. backup.getWifiList()
  386. .then((items) => {
  387. if(program.dump) {
  388. console.log(JSON.stringify(items, null, 4))
  389. return
  390. }
  391. var items = items['List of known networks'].map(el => [
  392. el.lastJoined + '' || '',
  393. el.lastAutoJoined + '' || '',
  394. el.SSID_STR + '',
  395. el.BSSID + '',
  396. el.SecurityMode || '',
  397. el.HIDDEN_NETWORK + '',
  398. el.enabled + '',
  399. ]).sort((a, b) => new Date(a[0]).getTime() - new Date(b[0]).getTime())
  400. items = [['Last Joined', 'Last AutoJoined', 'SSID', 'BSSID','Security', 'Hidden', 'Enabled'], ['-', '-', '-', '-', '-', '-'], ...items]
  401. items = normalizeCols(items).map(el => el.join(' | ').replace(/\n/g, '')).join('\n')
  402. if(!program.color) { items = stripAnsi(items) }
  403. console.log(items)
  404. })
  405. .catch((e) => {
  406. console.log('[!] Encountered an Error:', e)
  407. })
  408. } else {
  409. console.log('')
  410. console.log(' [!] Unknown Option type:', program.report)
  411. console.log(' [!] It\'s possible this tool is out-of date.')
  412. console.log('')
  413. program.outputHelp()
  414. }
  415. } else {
  416. program.outputHelp()
  417. }