forensic
Recovering Windows Secrets and EFS Certificates Offline
By Elie Bursztein, Jean-Michel Picod @WOOT 2010
0 reaction(s) | 1357 downloads
Based on our reverse-engineering
we show how DPAPI, the Windows API for safe data storage on disk work.
Our analysis reveals that it is possible to recover all previous passwords
used by any user on a system. We have implemented DPAPI data decryption
and previous password extraction in a free and open-source tool called DPAPIck.
Downloads
You might also like reading
Forensic 2010
Reversing DPAPI and Stealing Windows Secrets Offline
Forensic 2011
OWADE Offline Windows Analysis and Data Extraction
Blog 2011
Using the Microsoft Geolocalization API to retrace where a Windows laptop has been
Forensic 2011
Beyond files recovery OWADE cloud-based forensic
Forensic 2010
DPAPIck
Comments
Thanks for downloading!
You may want to share it with your friends
You might also like reading
Forensic 2010
Reversing DPAPI and Stealing Windows Secrets Offline
Forensic 2011
OWADE Offline Windows Analysis and Data Extraction
Blog 2011
Using the Microsoft Geolocalization API to retrace where a Windows laptop...
Forensic 2011
Beyond files recovery OWADE cloud-based forensic