forensic
Reversing DPAPI and Stealing Windows Secrets Offline
By Jean-Michel Picod, Elie Bursztein @BlackHat DC 2010
0 reaction(s) | 2354 downloads
We show how DPAPI, the Windows API for safe data storage on disk work.
Our analysis reveals that it is possible to recover all previous passwords used by any user
on a system. We have implemented DPAPI data decryption and previous password extraction
in a free and open-source tool called DPAPIck.
Downloads
You might also like reading
Forensic 2010
Recovering Windows Secrets and EFS Certificates Offline
Forensic 2011
OWADE Offline Windows Analysis and Data Extraction
Blog 2011
Using the Microsoft Geolocalization API to retrace where a Windows laptop has been
Forensic 2011
Beyond files recovery OWADE cloud-based forensic
Forensic 2010
DPAPIck
Comments
Thanks for downloading!
You may want to share it with your friends
You might also like reading
Forensic 2010
Recovering Windows Secrets and EFS Certificates Offline
Forensic 2011
OWADE Offline Windows Analysis and Data Extraction
Blog 2011
Using the Microsoft Geolocalization API to retrace where a Windows laptop...
Forensic 2011
Beyond files recovery OWADE cloud-based forensic