Elcomsoft
548 subscribers
574 photos
1 video
1 file
459 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Full File System Acquisition of iPhone 11 and Xr/Xs with iOS 13

The popular unc0ver jailbreak has been updated to v4, and this quite a big deal. The newest update advertises support for the latest A12 and A13 devices running iOS 13 through 13.3. The current version of iOS is 13.3.1. None of the older versions (including iOS 13.3) are signed, but still there are a lot of A12/A12X/A13 devices floating around. Until now, file system and keychain extraction was a big problem. The newest unc0ver jailbreak makes it possible.

👉🏻 https://blog.elcomsoft.com/2020/02/full-file-system-acquisition-of-iphone-11-and-xr-xs-ios-13/

by Vladimir Katalov

#unc0ver #jailbreak #iPhone #iOS #dataextraction #mobileforensic
Advanced Office Password Recovery: it’s all about the speed

Advanced Office Password Recovery (AOPR) received an important performance update, doubling or even quadrupling the recovery speed on certain versions of Microsoft Office when running CPU-only attacks. This performance update thoroughly optimizes the engine, resulting in the 2x improvement on password recovery speeds for Microsoft Office 2003 documents and the 4x improvement for Office 2016 documents when running CPU-only attacks.

In addition, we’ve improved the speed of GPU-assisted attacks 30 to 100% on some NVIDIA GPUs.

👉 https://www.elcomsoft.com/news/733.html

#MSOffice #CPU #GPU #password #passwordrecovery #attacks #NVIDIA
iPhone Acquisition Without a Jailbreak (iOS 11 and 12)

Elcomsoft iOS Forensic Toolkit can perform full file system acquisition and decrypt the keychain from non-jailbroken iPhone and iPad devices. The caveat: the device must be running iOS 11 or 12 (except iOS 12.3, 12.3.1 and 12.4.1), and you must use an Apple ID registered in Apple’s Developer Program.
In this article, I’ll explain the pros and contras of the new extraction method compared to traditional acquisition based on the jailbreak.

👉 https://blog.elcomsoft.com/2020/02/iphone-acquisition-without-a-jailbreak-ios-11-and-12/

by Oleg Afonin

#iphone #iOS #keychain #jailbreak #EIFT #mobileforensic #dataextraction #ElcomsoftAgent
iOS Forensic Toolkit 5.30: jailbreak-free extraction for multiple Apple devices

Elcomsoft iOS Forensic Toolkit 5.30 is updated to support forensically sound, jailbreak-free extraction of iPhone and iPad devices running iOS 11 through 12.4. The new extraction method is based on direct access to the file system, and does not require jailbreaking the device. Users of EIFT 5.30 can perform the full file system extraction and decrypt the keychain without the risks and footprint associated with third-party jailbreaks.

Supported devices range from the iPhone 5s all the way up to the iPhone Xr, Xs and Xs Max if they run any version of iOS from iOS 11 through iOS 12.4 (except iOS 12.3 and 12.3.1). Apple iPad devices running on the corresponding SoC are also supported.

👉 https://www.elcomsoft.com/news/734.html

#iphone #iOS #keychain #jailbreak #EIFT #mobileforensic #dataextraction #ElcomsoftAgent
Meet with us at Regional Digital and Cyber Investigation CPD Workshops in Bedfordshire Police HQ (covers Bedfordshire, Hertfordshire, Cambridgeshire, Norfolk, Suffolk and Kent forces) and learn more about New approaches and possibilities in data acquisition from iOS devices. 📲

This and other future events can be found here: https://www.elcomsoft.com/events.html

#jailbreak #unc0ver #iPhone #iOS #dataextraction #mobileforensic #eift #toolkit #ios #iPhone #privacy #security #digitalforensics #computercrime
VOTE FOR US ! 🙌

In our blog, we endeavour to highlight the most interesting facts and publish the results of our research. We cordially invite you to support us and nominate our blog in the following categories:

DFIR Blog of the Year:
*Elcomsoft Blog*

DFIR Article of the Year:
*‘The Worst Mistakes in iOS Forensics’*

*Voting is live until May 15, 2020!*

Vote here 👉 https://forensic4cast.com/forensic-4cast-awards/2020-forensic-4cast-awards/

#blog #blogger #vote #elcomsoft #mobileforensics #cloudforensics #computerforensics #decryption #itsecurity #software #cybersecurity #bestoftheday #nomination
Why Mobile Forensic Specialists Need a Developer Account with Apple

In our recent article iPhone Acquisition Without a Jailbreak I mentioned that agent-based extraction requires the use of an Apple ID that has been registered in Apple’s Developer Program. Participation is not free and comes with a number of limitations. Why do you need to become a “developer”, what are the limitations, and is there a workaround? Read along to find out.

👉 https://blog.elcomsoft.com/2020/03/why-mobile-forensic-specialists-need-a-developer-account-with-apple/

by Oleg Afonin

#dfir #iOS13 #iphone #mobileforensics #iOS #keychain #jailbreak #EIFT #dataextraction #ElcomsoftAgent #apple
Breaking Wi-Fi Passwords

Modern wireless networks are securely protected with WPA/WPA2. The most frequently used method of securing access to a wireless network is pre-shared passphrase, or, simply put, a text password. The WPA standard enforces the minimum length of 8 characters for all Wi-Fi passwords. Considering the relatively low performance of WPA/WPA2 password attacks, brute force attacks are rarely effective even when performed with a network of GPU-accelerated computers. In this article, I will show how to attack wireless passwords for the purpose of security audit.

👉 https://blog.elcomsoft.com/2020/03/breaking-wi-fi-passwords/

#wifi #passwords #encryption #network #WPA #EWSA #humanfactor #mutations #attacks
iOS Forensic Toolkit 5.40: jailbreak-free extraction for iOS 11-13.3

Elcomsoft iOS Forensic Toolkit 5.40 offers direct, forensically sound extraction for Apple devices running all versions of iOS from iOS 11 through iOS 13.3. Agent-based acquisition provides full file system extraction and keychain decryption without a jailbreak and literally no footprint.

👉 https://www.elcomsoft.com/news/736.html

#dfir #iOS13 #iphone #mobileforensics #iOS #keychain #jailbreak #EIFT #dataextraction #ElcomsoftAgent #apple
Attached Storage Forensics: Security Analysis of ASUSTOR NAS


ASUSTOR advertises secure AES encryption with a 256-bit key. According to the manufacturer, AES-256 encryption is made available through the entire range of its current NAS devices. Unlike other manufacturers, ASUSTOR is very upfront regarding the type of encryption employed by its NAS devices: “ASUSTOR NAS offers folder based military grade AES 256-bit encryption”. As a result, we’re once again dealing with folder-based encryption running on top of the open-source encrypting file system eCryptfs. We’ve already seen eCryptfs-based encryption in attached storage devices made by Synology and TerraMaster. Does ASUSTOR have any surprises, or will its implementation of folder-based encryption suffer from the many restrictions and limitations? Let’s find out.

👉 https://blog.elcomsoft.com/2020/03/attached-storage-forensics-security-analysis-of-asustor-nas/

#ASUSTOR #aesencryption #storage #forensics #security #encryptionkey #decryption #eCryptfs
Breaking VeraCrypt containers

VeraCrypt is a de-facto successor to TrueCrypt, one of the most popular cryptographic tools for full-disk encryption of internal and external storage devices. VeraCrypt employs a newer and more secure format for encrypted containers and significantly expands the number of supported encryption algorithms and hash functions. Learn how to break VeraCrypt containers with distributed password attacks.

VeraCrypt Encryption
Full-disk encryption tools employ one-way hash functions to protect the binary data encryption key with the password. When attacking an encrypted container, the expert must either know the exact combination of the cipher and hash function or try all of their possible combinations. If the expert makes the wrong choice of a hash function or cipher, the data will not be decrypted even if the correct password is known.

👉 https://blog.elcomsoft.com/2020/03/breaking-veracrypt-containers/

#veracrypt #encryption #dataprotection #cryptocontainer
New Elcomsoft System Recovery 7.2 and Forensic Disk Decryptor 2.11 are available: macOS encryption and VeraCrypt support

We updated Elcomsoft System Recovery and Elcomsoft Forensic Disk Decryptor. Elcomsoft System Recovery can now create a bootable flash drive allowing experts boot macOS computers and extract data required to launch attacks on full-disk encryption. Elcomsoft Forensic Disk Decryptor receives support for VeraCrypt volumes.

👉 https://www.elcomsoft.com/news/737.html

#veracrypt #apfs #hfs #encryption #cryptocontainer #hiddendisks #macOS #fulldiskencryption #passwords #pgpwde
ElcomSoft Phone Breaker 9.50 fixes iCloud access, upgrades Home licenses to Pro

Elcomsoft Phone Breaker 9.50 fixes access to iCloud accounts protected with two-factor authentication, supports keychain data extracted with Cellebrite software, and enables the extraction of Apple Map data protected with end-to-end encryption. In addition, we deprecated the Home edition; existing non-expired licenses automatically upgraded to the Professional edition.

👉 https://www.elcomsoft.com/news/738.html

Download Elcomsooft Phone Breaker 9.50

#smartphone #iphone #icloud #keychain #messages #applehealth #screentime #maps #dataprotection #dataextraction #dataaccess
macOS, iOS and iCloud updates: forensic consequences

Every other day, Apple makes the work of forensic specialists harder. Speaking of iCloud, we partially covered this topic in Apple vs. Law Enforcement: Cloud Forensics and Apple vs Law Enforcement: Cloudy Times, but there is more to it today. The recent iOS (13.4) and macOS (10.15.4) releases brought some nasty surprises. Let’s talk about them.

iOS 13

It is difficult to say when it actually happened, but iOS stopped syncing call logs, and does not sync them for the time being. We covered call log sync some three years ago:

- iOS Call Syncing: How It Works
- iPhone User? Your Calls Go to iCloud

We even tried to bring the matter to Apple, but the only response was 'we take privacy very seriously' (I am not surprised). Anyway; call logs are no longer synchronized (com’on, Apple, did you forget about Continuity? 😊)

👉 https://blog.elcomsoft.com/2020/04/macos-ios-and-icloud-updates-forensic-consequences/

By Vladimir Katalov

#iOS #security #iphone
Elcomsoft breaks VeraCrypt containers, expands cloud support with Microsoft Azure deployment

Elcomsoft Distributed Password Recovery 4.20 helps forensic experts gain effective access to even more encrypted and locked evidence. The update adds support for VeraCrypt containers and introduces the ability to deploy on-demand cloud instances in Microsoft Azure. In addition, the update adds support for FileVault 2 encrypted volumes located on APFS-formatted partitions, and offers ultra-fast attacks for Tally Vault passwords.

👉 https://www.elcomsoft.com/news/739.html

Download EDPR 4.20 Release Notes 📝

#VeraCrypt #cryptocontainer #encryption #password #microsoftazure #passwordrecovery #apsf #tallyvault #GPU #itsecurity #systempasswords #passwordmanager #FileVault2 #1password #dashlane #lastpass #keepas
Password Reuse vs. Master Password: Two Sides of Password Managers

Password managers or password reuse? This is the question faced by most consumers. Reusing a password or its minor variations for different accounts has never been a good idea, yet in today’s world of online everything the rate of password reuse reaches astonishing values. Using a password manager helps reduce password reuse, supposedly offering increased security. In this article, we’ll perform forensic analysis of some of the most common password managers.

👉 https://blog.elcomsoft.com/2020/04/password-reuse-vs-master-password-two-sides-of-password-managers/

by Oleg Afonin

#cryptocontainer #encryption #password #passwordrecovery #apsf #GPU #itsecurity #systempasswords #passwordmanager #1password
Tally ERP 9 Vault: How to Not Implement Password Protection

Tally ERP 9 is a “new-age business management software for new-age businesses” that is “tailor-made to delight”. With more than two million users, Tally is one of the most popular tools of its kind in India. The product includes the company’s implementation of secure storage named Tally Vault. How secure is Tally Vault, and what does one need to break in? In this article, we’ve provided some insights on how ElcomSoft researchers work when adding support for a new file format.

👉 https://blog.elcomsoft.com/2020/04/tally-erp-9-vault-how-to-not-implement-password-protection/

by Oleg Afonin

#encryption #password #passwordrecovery #apsf #tallyvault #GPU #itsecurity #systempasswords #passwordmanager #TallyERP9
Using Microsoft Azure to Break Passwords

Modern applications use highly secure and thus deliberately slow algorithms for verifying passwords. For this reason, the password recovery process may take a lot of time and require extreme computational resources. You can build your own powerful cluster to accelerate brute-force attacks, but if you only need to recover a password every once in a while, maintaining your own cluster may not be the best investment. Cloud services can help do a one-off job faster. For a long time, Elcomsoft Distributed Password Recovery had supported Amazon cloud services with automatic deployment on Amazon’s powerful GPU-accelerated servers. The latest update brings support for Microsoft Azure, adding the ability to automatically deploy Password Recovery Agents to virtual machines created in Microsoft Azure.

👉 https://rb.gy/785g4j

by Andrey Malyshev

#encryption #password #microsoftazure #passwordrecovery #apsf #GPU #itsecurity
Accelerating Password Recovery: GPU Acceleration, Distributed and Cloud Attacks

Modern encryption tools employ strong encryption with multiple hash iterations, making passwords extremely difficult to break. The November article “What is password recovery and how it is different from password cracking” explains the differences between instantly accessing protected information and attempting to break the original plain-text password. In that article, I briefly mentioned GPU acceleration and distributed attacks as methods to speed up the recovery. In this article, I’ll discuss the two acceleration techniques in more detail.

Why do we need GPU acceleration?
Literally, we need GPU acceleration to break passwords faster. How much faster, exactly, depends on several things...

👉 https://blog.elcomsoft.com/2020/04/accelerating-password-recovery-gpu-acceleration-distributed-and-cloud-attacks/

By Oleg Afonin

#passwords #passwordrecovery #GPU #passwordmanager #1Password #Dashlane #Keepass #LastPass #Nvidia
Breaking LastPass: Instant Unlock of the Password Vault

Password managers such as LastPass are designed from the ground up to withstand brute-force attacks on the password database. Using encryption and thousands of hash iterations, the protection is made to slow down access to the encrypted vault that contains all of the user’s stored passwords. In this article, we’ll demonstrate how to unlock LastPass password vault instantly without running a length attack.

👉 https://blog.elcomsoft.com/2020/04/breaking-lastpass-instant-unlock-of-the-password-vault/

by Oleg Afonin

#itsecurity #password #passwordmanager #LastPass #cybersec #chrome #sync #dataprotection #ebcryption
Extracting Passwords from Microsoft Edge Chromium

Last week, Microsoft Edge has become the second most popular desktop Web browser based on NetMarketShare usage figures. The new, Chromium-powered Edge offers impressive levels of customization and performance, much better compatibility with Web sites. The new browser is available on multiple platforms including older versions of Windows. With Chromium-based Edge quickly gaining momentum, we felt the urge of researching its protected storage.

👉 https://blog.elcomsoft.com/2020/04/extracting-passwords-from-microsoft-edge-chromium/

By Oleg Afonin

#Google #Chrome #Chromium #Microsoft #Edge #Opera #password #webcredentials