Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 05-24-2006, 07:45 AM   #1 (permalink)
Smithers, release the hounds
 
ironman's Avatar
 
Location: Guatemala, Guatemala
Problem with back-uped encrypted files

In the last 3 years my office was robbed twice, and my laptops, along with all my honeymoon pictures, were lost forever. So, when i bought my last laptop one year ago, i decided to make regular backups of my info in an external HDD at home and to encrypt all my files.
It all worked flawless untill my lappy started to overheat, so i sold it after copying all my files to the external HDD, i made sure to place all my important files into one folder and to remove the encryption to the whole folder. Problem was that after formatting and selling the laptop, i realized that only half my files had been unencrypted for a reason i still don't understand. So i have over 11GB of info i can't access and don't know what to do.
I have a backup made with the xp backup utility around 3 months ago, but when i tried to restore it in my new computer, it does not create my previous user, nor can i access the encypted files. Does anyone have any idea what can i do to recover this files? Please help me! i can stand loosing data because of a robbery, but not because of a dumb error.
__________________
If I agreed with you we´d both be wrong
ironman is offline  
Old 05-24-2006, 07:44 PM   #2 (permalink)
Tilted
 
What did you use to encrypt the files? If it was Windows 2000 or XP, try using the same username and password you encrypted the files with, even if that means you have to create a new local login to test it.
syquestrd270 is offline  
Old 05-24-2006, 09:53 PM   #3 (permalink)
Devils Cabana Boy
 
Dilbert1234567's Avatar
 
Location: Central Coast CA
Creating the user with the same name and password wont work, you needed to make a recovery agent before all this happened, exported it's certificate somewhere safe, you would use it to recover your data. I store mine in a locked RAR file, with an extra 2 mb of Shakespeare (to make encryption of the RAR even harder) you would import the certificate onto a use on the computer used to recover the data giving you access.

Here is a good article about it, actually it’s a 5 part article
http://www.practicalpc.co.uk/computi...xpencrypt1.htm
And Microsoft’s stance on it
http://www.microsoft.com/technet/pro...y/cryptfs.mspx


In your case, there are few options, I don’t know of any programs that will allow you to brute force it, I hope some one can recommend one. Encryption is not based just off of the user name and password, it goes much deeper. By default windows uses a 1024 bit RSA encryption, so you’re in trouble for cracking it. This is all assuming you’re not in a domain environment, if you are a larger cooperation and have a windows server domain, talk with your net admins, they should be able to get it back in a few minutes.
__________________
Donate Blood!

"Love is not finding the perfect person, but learning to see an imperfect person perfectly." -Sam Keen
Dilbert1234567 is offline  
Old 05-24-2006, 09:57 PM   #4 (permalink)
Devils Cabana Boy
 
Dilbert1234567's Avatar
 
Location: Central Coast CA
Oh and by the way, I do sympathies, I to have lost allot of data, about half a terra byte; several gigs of my artwork and their source files.
__________________
Donate Blood!

"Love is not finding the perfect person, but learning to see an imperfect person perfectly." -Sam Keen
Dilbert1234567 is offline  
Old 05-24-2006, 11:35 PM   #5 (permalink)
Adequate
 
cyrnel's Avatar
 
Location: In my angry-dome.
http://www.crackpassword.com/products/prs/mswin/efs/
$99 for home users. I have no idea if it's effective but the demo may be enough to test.

There are surely others. That's just the first that popped up.

Good luck. Painful situation. Must be the phase of the moon. I just lost another WD drive today. &*#&(*#&)!@#$!!!
__________________
There are a vast number of people who are uninformed and heavily propagandized, but fundamentally decent. The propaganda that inundates them is effective when unchallenged, but much of it goes only skin deep. If they can be brought to raise questions and apply their decent instincts and basic intelligence, many people quickly escape the confines of the doctrinal system and are willing to do something to help others who are really suffering and oppressed." -Manufacturing Consent: Noam Chomsky and the Media, p. 195
cyrnel is offline  
Old 05-25-2006, 07:05 AM   #6 (permalink)
Devils Cabana Boy
 
Dilbert1234567's Avatar
 
Location: Central Coast CA
Quote:
Known problems and limitations

- The program can decrypt protected files only if encryption keys (at least, some of them) are still exist in the system and have not been tampered.
- Only "Basic" (but not "Dynamic") NTFS partitions are supported.
- For files encrypted on Windows 2000, if Account Database Key (SYSKEY) is stored on floppy disk, or if "Password Startup" option has been set, you should know/have one of the following in order to be able to decrypt the files:
- startup password or startup floppy disk
- the password of user who encrypted the files
- the password of Recovery Agent (if one is availbale)
- If password of the user (who encrypted the files) have been changed after encryption, you may need to enter the old password into the program.
- If files were encrypted under Windows XP (with or without SP1/SP2) or Windows Server 2003, the password of user who encrypted the files (or Recovery Agent) is needed for decryption.
- The program has been tested only on files encrypted under U.S. version of Windows; if any other (international) version has been used, correct work is not guaranteed.
if you only backed up the encrypted files, it wont work, if you backed up your entire system, it could.

Basically the program is helping people who have everything they need to decrypt the files but don’t know how to do it.

oh and after rereading your first post, one word of warning, formatting does not always wipe the data, a quick format erases the table that points to the data, not the actual data, but what most people don’t know is that a full format (windows full format) it does not either, it only checks for bad sectors, not erasing data. You need to use a program that actually rewrites at least once. Heh at work last yesterday, I took some old hard drives with sensitive data on them over to the welding shop and took a torch to them, blasted a hole through the drives.
__________________
Donate Blood!

"Love is not finding the perfect person, but learning to see an imperfect person perfectly." -Sam Keen
Dilbert1234567 is offline  
Old 05-25-2006, 07:21 AM   #7 (permalink)
Tilted Cat Head
 
Cynthetiq's Avatar
 
Administrator
Location: Manhattan, NY
because I am afraid of photos disappearing, I ALWAYS upload to a photosharing site, my choice is KodakGallery because I can always "buy" them back on CD.

as for the encryption I'll keep thinking about that part
__________________
I don't care if you are black, white, purple, green, Chinese, Japanese, Korean, hippie, cop, bum, admin, user, English, Irish, French, Catholic, Protestant, Jewish, Buddhist, Muslim, indian, cowboy, tall, short, fat, skinny, emo, punk, mod, rocker, straight, gay, lesbian, jock, nerd, geek, Democrat, Republican, Libertarian, Independent, driver, pedestrian, or bicyclist, either you're an asshole or you're not.
Cynthetiq is offline  
Old 05-25-2006, 07:37 AM   #8 (permalink)
Insane
 
tres's Avatar
 
Location: Long Island, NY
I've had a similar problem.... I had files set as "private" when I transfered them to another harddrive I could not open them on any other computer...

Try this..

See if anyone you know has the same model laptop that you had. Take out their hard drive and put yours in. Intall windows onto the drive with the data... this MIGHT work.. I know windows also uses the hardware config as part of the encription. Matching the hardware worked for me... of course.. i still had windows installed on the old hard drive.. hope this helps.
__________________
"Its better to be hated for who you are, then loved for what your not" --Van Zant

"Tell me and I forget. Show me and I remember. Involve me and I learn."
tres is offline  
Old 05-25-2006, 07:48 AM   #9 (permalink)
Adequate
 
cyrnel's Avatar
 
Location: In my angry-dome.
Good reading Dilbert. So much for quick googles.

The only vulnerabilities I found had to do with key security. Brute force could take a very, very long time.

On Dilbert's point about erasure, I'd contact the person who bought the laptop. If you didn't wipe the drive and they upgraded there's a chance your certs are still on that drive. Recovering them would be a trick but it would be the simplest option. One of those things I'd want to rule out before giving up.
__________________
There are a vast number of people who are uninformed and heavily propagandized, but fundamentally decent. The propaganda that inundates them is effective when unchallenged, but much of it goes only skin deep. If they can be brought to raise questions and apply their decent instincts and basic intelligence, many people quickly escape the confines of the doctrinal system and are willing to do something to help others who are really suffering and oppressed." -Manufacturing Consent: Noam Chomsky and the Media, p. 195
cyrnel is offline  
Old 05-25-2006, 08:07 AM   #10 (permalink)
Devils Cabana Boy
 
Dilbert1234567's Avatar
 
Location: Central Coast CA
Yeah brute forcing a 1024 bit RSA encryption takes for ever. Getting the same hardware would not work, they key is generated by much more than the hard ware, and even then the hard drive would be different. The only chance is to get the certificate that has the key to decrypt the data. Unless you are on a domain, then you should be just fine when you talk with the domain admin.

and btw I tried the free version of that cracker on a virtual machine, it did not work at all, I created 2 admin users, encrypted a file with one and ran the software as the other, no go, it found all the keys, I gave it the original password, but nothing.
__________________
Donate Blood!

"Love is not finding the perfect person, but learning to see an imperfect person perfectly." -Sam Keen
Dilbert1234567 is offline  
Old 05-25-2006, 08:41 AM   #11 (permalink)
Adequate
 
cyrnel's Avatar
 
Location: In my angry-dome.
Ironman, our comments about brute forcing the files has to do with immediate recovery. RSA 1024 is strong. But everything secure becomes less so with discoveries and ever-increasing computing horsepower. If the files are pictures or things that only increase in value with time I'd definitely keep multiple copies in separate locations. Even though you can't read them now, in 5-10 years RSA 1024 could be a cinch to crack.

Just thought I should mention it. For me it'd be worth a few DVD sets in the hope of progress.
__________________
There are a vast number of people who are uninformed and heavily propagandized, but fundamentally decent. The propaganda that inundates them is effective when unchallenged, but much of it goes only skin deep. If they can be brought to raise questions and apply their decent instincts and basic intelligence, many people quickly escape the confines of the doctrinal system and are willing to do something to help others who are really suffering and oppressed." -Manufacturing Consent: Noam Chomsky and the Media, p. 195
cyrnel is offline  
 

Tags
backuped, encrypted, files, problem


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 10:11 PM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360