NTFS EFS Decryption 05 - Decrypting DATA with AES-256 FEK

preview_player
Показать описание
Video Timeline:
0:40 Overview of AES
5:04 How does EFS use the AES cipher?
6:45 OpenSSL command to decrypt AES
7:53 Fixing OpenSSL errors: Wrong final block block length:
10:59 Fixing OpenSSL errors: "EVP_DecryptFInal_ex: bad decrypt"
12:23 The Initialization vector problem
14:20 Overview of XOR and using it to find the IV
17:21 Getting the IV from open-source implementation of efs decryption

All the files used in this demo are available here:

AES specification (FIPS):

Padding schemes:

Microsoft support article on how AES is used by EFS:

Git Issues with icat for dumping an encrypted attribute:

OpenSSL evp-decryptfinal-ex-bad-decrypt reference:

IV used by EFS for AES encryption:
Рекомендации по теме
Комментарии
Автор

This is one of the best videos about AES and details about the decryption process. Thank you so much from New Zealand.

dmahal
Автор

Maaan, that's literally an extremely valuable content, thank you so much 🎉

bobo-pxgy
Автор

Thanx for explaining in such quality
I redid all the steps and I was surprised that iv, in my machine, has the same value😳 it seems that it has a fixed value in all Windows, however, mine is 10 pro edition.
iv =

infosecurity
welcome to shbcf.ru