Remote Exploit Forums

Go Back   Remote Exploit Forums > Specialist Topics


Specialist Topics Suggestions for topic sections welcome!

   

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-03-2009, 09:32 PM
Member
 
Join Date: Jul 2009
Location: 1337 h4x0r str337
Posts: 32
Send a message via AIM to b3r00tb4ck
Default cracking an encrypted hard drive

im having a little trouble with this "challenge" my buddy gave me, he uses red hat (2.6 kernel) and the whole hard drive is encrypted except /boot/, which i could find out with backtrack by opening up the hard drive.. my question is what are the steps one would go through to get root on this machine, or some kind of trick to decrypt the hard drive, and view its files...total noob here on encryption but i thought i could find an experienced user here in the specialist section
Reply With Quote
  #2 (permalink)  
Old 11-03-2009, 09:57 PM
Barry's Avatar
Senior Member
 
Join Date: Feb 2006
Location: Right behind you. Using you as a shield.
Posts: 3,311
Default

Do you know what kind of encryption he's using? Sounds like luks, but could be something else. Most likely you're SOL.
Reply With Quote
  #3 (permalink)  
Old 11-03-2009, 10:12 PM
Member
 
Join Date: Mar 2006
Posts: 46
Default

Step 1: Install a keystroke logger
Step 2: Wait for you friend to log on
Step 3: Profit

Full hard drive encryption is tough to deal with. Technically it is also vulnerable to password cracking attacks, but most encryption packages make it very expensive, (time consuming), to make a guess, and there just aren't many good tools out there to even try simple password guesses.
Reply With Quote
  #4 (permalink)  
Old 11-03-2009, 10:26 PM
Member
 
Join Date: Jul 2009
Location: 1337 h4x0r str337
Posts: 32
Send a message via AIM to b3r00tb4ck
Default

thats what i was thinking, when you guess passwords at the login screen, it takes about 5 seconds, so brute forcing would be time consuming even i could get a dictionary to automatically be typed in...

what im going toward is fighting the boot loader, he uses grub, and i can freely edit the grub config file, so would there be some kind of argument that gets me a shell right at boot time?
Reply With Quote
  #5 (permalink)  
Old 11-03-2009, 10:45 PM
Barry's Avatar
Senior Member
 
Join Date: Feb 2006
Location: Right behind you. Using you as a shield.
Posts: 3,311
Default

Quote:
Originally Posted by b3r00tb4ck View Post
thats what i was thinking, when you guess passwords at the login screen, it takes about 5 seconds, so brute forcing would be time consuming even i could get a dictionary to automatically be typed in...

what im going toward is fighting the boot loader, he uses grub, and i can freely edit the grub config file, so would there be some kind of argument that gets me a shell right at boot time?
You'll get the grub shell, but that's not going to help you. The way the system works is the /boot partition is formatted ext3 or 4. The / partition is an encrypted container, which inside that container is a normally formatted system. Unless you know the encryption key, you're not going to see anything in there. The only thing in /boot is the kernel and the boot loader.
Reply With Quote
  #6 (permalink)  
Old 11-04-2009, 03:42 AM
Thorn's Avatar
Senior Member
 
Join Date: Jul 2007
Location: The Village, of course
Posts: 1,398
Default

If he's using Truecrypt, you can use Evil Maid. It hooks the Trucrypt function that asks user for the passphrase, so that the hook records whatever passphrase is provided to this function.

Game. Set. Match
__________________
Thorn

“Never try to teach a pig to sing; it wastes your time and it annoys the pig.”
- Robert Heinlein
Reply With Quote
  #7 (permalink)  
Old 11-04-2009, 09:01 PM
Member
 
Join Date: Jul 2009
Location: 1337 h4x0r str337
Posts: 32
Send a message via AIM to b3r00tb4ck
Default

i'm just gonna say SOLVED, i gave it back lol no use starting out with entire hard drive encryption if i'm gonna learn cryptography

thanks for the help!
Reply With Quote
  #8 (permalink)  
Old 11-05-2009, 06:23 AM
Senior Member
 
Join Date: Feb 2008
Posts: 473
Default

If your interested in cryptography might I suggest Bruce Schneier's Applied Cryptography.
__________________
The only real problems in life are the problems that are common to all humans.
Reply With Quote
  #9 (permalink)  
Old 11-05-2009, 07:09 AM
floyd's Avatar
Senior Member
 
Join Date: Mar 2009
Location: I'm in a laundry room
Posts: 233
Default

Quote:
Originally Posted by b3r00tb4ck View Post
thats what i was thinking, when you guess passwords at the login screen, it takes about 5 seconds, so brute forcing would be time consuming even i could get a dictionary to automatically be typed in...

what im going toward is fighting the boot loader, he uses grub, and i can freely edit the grub config file, so would there be some kind of argument that gets me a shell right at boot time?
start a live cd and you will have the same access to the encrypted drive.

Or you could just install coreboot with Grub Invaders and tell him that you wiped his hard disc . No, just kidding, don't mess with his bios
__________________
Auswaertsspiel
Reply With Quote
  #10 (permalink)  
Old 11-05-2009, 12:18 PM
archangel.amael's Avatar
Moderator
 
Join Date: Nov 2007
Location: I changed it for you.
Posts: 4,192
Default

Quote:
Originally Posted by hhmatt81 View Post
If your interested in cryptography might I suggest Bruce Schneier's Applied Cryptography.
Excellent book indeed.
__________________
Please visit the new forums for any and all help with Back Track 4 Final.
BackTrack-Linux is the new home.
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 04:02 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2