Elcomsoft
548 subscribers
574 photos
1 video
1 file
459 links
Elcomsoft official channel is the place where you can find news, events and the latest updates of our products.

website: elcomsoft.com
twitter: twitter.com/elcomsoft
youtube: youtube.com/c/ElcomsoftCompany
blog: blog.elcomsoft.com
t.me/elcomsoftru
Download Telegram
Password Reuse vs. Master Password: Two Sides of Password Managers

Password managers or password reuse? This is the question faced by most consumers. Reusing a password or its minor variations for different accounts has never been a good idea, yet in today’s world of online everything the rate of password reuse reaches astonishing values. Using a password manager helps reduce password reuse, supposedly offering increased security. In this article, we’ll perform forensic analysis of some of the most common password managers.

👉 https://blog.elcomsoft.com/2020/04/password-reuse-vs-master-password-two-sides-of-password-managers/

by Oleg Afonin

#cryptocontainer #encryption #password #passwordrecovery #apsf #GPU #itsecurity #systempasswords #passwordmanager #1password
Tally ERP 9 Vault: How to Not Implement Password Protection

Tally ERP 9 is a “new-age business management software for new-age businesses” that is “tailor-made to delight”. With more than two million users, Tally is one of the most popular tools of its kind in India. The product includes the company’s implementation of secure storage named Tally Vault. How secure is Tally Vault, and what does one need to break in? In this article, we’ve provided some insights on how ElcomSoft researchers work when adding support for a new file format.

👉 https://blog.elcomsoft.com/2020/04/tally-erp-9-vault-how-to-not-implement-password-protection/

by Oleg Afonin

#encryption #password #passwordrecovery #apsf #tallyvault #GPU #itsecurity #systempasswords #passwordmanager #TallyERP9
Using Microsoft Azure to Break Passwords

Modern applications use highly secure and thus deliberately slow algorithms for verifying passwords. For this reason, the password recovery process may take a lot of time and require extreme computational resources. You can build your own powerful cluster to accelerate brute-force attacks, but if you only need to recover a password every once in a while, maintaining your own cluster may not be the best investment. Cloud services can help do a one-off job faster. For a long time, Elcomsoft Distributed Password Recovery had supported Amazon cloud services with automatic deployment on Amazon’s powerful GPU-accelerated servers. The latest update brings support for Microsoft Azure, adding the ability to automatically deploy Password Recovery Agents to virtual machines created in Microsoft Azure.

👉 https://rb.gy/785g4j

by Andrey Malyshev

#encryption #password #microsoftazure #passwordrecovery #apsf #GPU #itsecurity
Accelerating Password Recovery: GPU Acceleration, Distributed and Cloud Attacks

Modern encryption tools employ strong encryption with multiple hash iterations, making passwords extremely difficult to break. The November article “What is password recovery and how it is different from password cracking” explains the differences between instantly accessing protected information and attempting to break the original plain-text password. In that article, I briefly mentioned GPU acceleration and distributed attacks as methods to speed up the recovery. In this article, I’ll discuss the two acceleration techniques in more detail.

Why do we need GPU acceleration?
Literally, we need GPU acceleration to break passwords faster. How much faster, exactly, depends on several things...

👉 https://blog.elcomsoft.com/2020/04/accelerating-password-recovery-gpu-acceleration-distributed-and-cloud-attacks/

By Oleg Afonin

#passwords #passwordrecovery #GPU #passwordmanager #1Password #Dashlane #Keepass #LastPass #Nvidia
Breaking LastPass: Instant Unlock of the Password Vault

Password managers such as LastPass are designed from the ground up to withstand brute-force attacks on the password database. Using encryption and thousands of hash iterations, the protection is made to slow down access to the encrypted vault that contains all of the user’s stored passwords. In this article, we’ll demonstrate how to unlock LastPass password vault instantly without running a length attack.

👉 https://blog.elcomsoft.com/2020/04/breaking-lastpass-instant-unlock-of-the-password-vault/

by Oleg Afonin

#itsecurity #password #passwordmanager #LastPass #cybersec #chrome #sync #dataprotection #ebcryption
Extracting Passwords from Microsoft Edge Chromium

Last week, Microsoft Edge has become the second most popular desktop Web browser based on NetMarketShare usage figures. The new, Chromium-powered Edge offers impressive levels of customization and performance, much better compatibility with Web sites. The new browser is available on multiple platforms including older versions of Windows. With Chromium-based Edge quickly gaining momentum, we felt the urge of researching its protected storage.

👉 https://blog.elcomsoft.com/2020/04/extracting-passwords-from-microsoft-edge-chromium/

By Oleg Afonin

#Google #Chrome #Chromium #Microsoft #Edge #Opera #password #webcredentials
Cloudy Times: Extracting and Analyzing Location Evidence from Cloud Services

Geolocation data can provide a wealth of evidence to various government agencies. Law enforcement agencies use location data to help place suspects near a crime scene in a given time frame. However, the use of location is not limited to criminal or civil investigations. Emergency response services use geolocation to locate persons, taxi and delivery services use location to improve service. There are many more examples where location evidence is vital. Recently, governments have started using (or are considering using) geolocation data to help identify and isolate infected citizens. Where does the location evidence come from and how one can extract it?

by Oleg Afonin

👉 https://blog.elcomsoft.com/2020/04/cloudy-times-extracting-and-analyzing-location-evidence-from-cloud-services/

#cloud #locations #applehealth #googlefit #geolocation #maps #EXIFfiles #extractdata
Elcomsoft Internet Password Breaker 3.10 extracts Edge Chromium passwords, updates Chrome support

Elcomsoft Internet Password Breaker 3.10 adds the ability to extract stored passwords from the newest Chromium-based Microsoft Edge browser. We’ve also updated the tool to support the latest versions of Google Chrome, Opera and Chromium.

👉 https://www.elcomsoft.com/news/741.html

#Chrome #Chromium #Opera #Microsoft #Edge #browser #password #Google
iOS acquisition methods compared: logical, full file system and iCloud

The iPhone is one of the most popular smartphone device. Thanks to its huge popularity, the iPhone gets a lot of attention from the forensic community. Multiple acquisition methods exist, allowing forensic users to obtain more or less information with more or less efforts. Some of these acquisition methods are based on undocumented exploits and public jailbreaks, while some other methods utilize published APIs to access information. In this article, we’ll compare the types and amounts of data one can extract from the same 256-GB iPhone 11 Pro Max using three different acquisition methods: advanced logical, full file system and iCloud extraction.

👉 https://blog.elcomsoft.com/2020/04/ios-acquisition-methods-compared-logical-full-file-system-and-icloud/

by Vladimir Katalov

#iOS #security #iphone #macOS #macbook #applewatch #ipad #smartphone #icloud #keychain #dataextraction #dataaccess #apple
Elcomsoft System Recovery update: enhanced password extraction and account recovery algorithms

We updated Elcomsoft System Recovery, a Windows PE-based tool to recover or reset passwords to local Windows accounts and Microsoft accounts in all versions of Windows. Elcomsoft System Recovery now utilizes an enhanced, smarter and significantly more efficient algorithms for recovering account passwords.

👉 https://www.elcomsoft.com/news/742.html

#cybersecurity #passwords #fde #windows #encryption #diskencryption #datasecurity #itsecurity
Elcomsoft Phone Viewer 5.0 displays Telegram secret chats

Elcomsoft Phone Viewer is updated with support for Telegram conversation histories. Telegram analysis is available when accessing a file system image extracted from the iPhone or iPad device with Elcomsoft iOS Forensic Toolkit by using agent-based or jailbreak-based file system imaging. Experts can now decrypt and analyse the complete Telegram communication histories including secure chats when analysing the results of iOS file system acquisition.

👉 https://www.elcomsoft.com/news/743.html

📝 Release Notes

#telegram #signal #ios #iphone #mobileforensics #itsecurity #secretchats #datasecurity
How To Extract Telegram Secret Chats from the iPhone


With nearly half a billion users, Telegram is an incredibly popular cross-platform instant messaging app. While Telegram is not considered the most secure instant messaging app (this title belongs to Signal), its conversation histories do not appear in either iTunes or iCloud backups. Moreover, Telegram secure chats are not stored on Telegram servers. As a result, Telegram secret chats can be only extracted from the device of origin. Learn how to extract and analyse Telegram secret chats from the iPhone file system image.

Keep reading 👉 https://blog.elcomsoft.com/2020/04/how-to-extract-telegram-secret-chats-from-the-iphone/

By Oleg Afonin

#telegram #secretchats #ios #iphone #communications #messages
Forensic guide to iMessage, WhatsApp, Telegram, Signal and Skype data acquisition

Instant messaging apps have become the de-facto standard of real-time, text-based communications. The acquisition of instant messaging chats and communication histories can be extremely important for an investigation. In this article, we compare the five top instant messaging apps for iOS in the context of their forensic analysis.

👉 https://blog.elcomsoft.com/2020/04/forensic-guide-to-imessage-whatsapp-telegram-signal-and-skype-data-acquisition/

#telegram #skype #imessage #whatsapp #signal #iphone #messengers #secretchats #messages #mobilesecurity #mobileforensics
How to Unlock Windows Systems with a Bootable Flash Drive


Accessing a locked system is always a challenge. While you might be tempted to pull the plug and image the disk, you could miss a lot of valuable evidence if you do. Full-disk encryption, EFS-encrypted files and folders and everything protected with DPAPI (including the passwords stored in most modern Web browsers) are just a few obstacles to mention. Recovering the original Windows logon is a must to access the full set of data, while resetting the logon password may help unlock working accounts in emergencies.

Dealing with Full Disk Encryption

Full-disk encryption presents an immediate challenge to forensic experts...

👉 https://blog.elcomsoft.com/2020/04/how-to-unlock-windows-systems-with-a-bootable-flash-drive/

#windows #systempasswords #passwords #EFS #encryption #dataprotection #desktopforensics
Elcomsoft Cloud Explorer 2.31 extracts more of Google Dashboard

The updated Elcomsoft Cloud Explorer 2.31 offers enhanced support for extracting Google Dashboard data, a Google service for storing and managing personal data collected by Google Inc about its users. In this release, Elcomsoft Cloud Explorer significantly expands the number of categories obtained from Google Dashboard, extracting significantly more information than ever before. The newly added Dashboard categories include Maps, Calendar, Disk, Alerts, Analytics, Books, Groups, News, Package tracking, Payments, Photos, Google Play Music, Google Play, Tasks, Blogger, AdSense, Brand Accounts, FeedBurner, Search, and Keep.

👉 https://www.elcomsoft.com/news/744.html

#google #googlecloud #itsecurity #dashboard #googleservices #chrome #gmail #photos #mobileforensics #dfir
Extracting Google Dashboard Data

We have updated Elcomsoft Cloud Explorer, our Google Account extraction tool, with Google Dashboard support. The Google Dashboard service is little known among computer forensic specialists since Dashboard data cannot be downloaded from Google or obtained by serving a legal request. Yet, Dashboard aggregates massive amounts of data collected and stored in the user’s Google Account, offering an essential overview of the user’s activities. In this article, we’ll demonstrate how to obtain Dashboard data directly from the user’s Google account.

👉 https://blog.elcomsoft.com/2020/05/extracting-google-dashboard-data/

#google #googleservice #googlecloud #dashboard #gmail #chrome #googlefit #locations #datasecurity #itsecurity #mobilesecurity #dfir
Google Account Access Without a Password

Cloud acquisition is one of the most common ways to obtain valuable evidence. When it comes to Google, the Google Account analysis may return significantly more data compared to the extraction of a physical Android device. However, there is one feature that is often overlooked: the ability to extract data stored in the user’s Google Account without the login and password. Let’s talk about Google authentication tokens and what they bring for the mobile forensics.

👉 https://blog.elcomsoft.com/2020/05/google-account-access-without-a-password/

#google #password #token #authentication #dataaccess #datasecurity #itsecurity #mobileforensics #cloudsecurity
iOS Forensic Toolkit 5.50: iPhone extraction simplified

Elcomsoft iOS Forensic Toolkit 5.50 features a new communication channel empowering the tool’s acquisition engine. The newly designed communication channel offers faster and more robust extractions and simplifies the acquisition process by removing the need of disabling wireless connectivity.

👉 https://www.elcomsoft.com/news/745.html

📝 EIFT Release Notes

#iphone #ios #dataextraction #elcomsoftagent #toolkit #iOS13.5 #mobileforensics #mobilesecurity #filesystem #keychain
iOS Acquisition Reloaded

The new build of iOS Forensic Toolkit is out. This time around, most of the changes are “internal” and do not add much functionality, but there is a lot going on behind the scenes. In this article, we will describe in details what is new and important, and how it’s going to affect you. We’ll share some tips on how to use the software in the most effective way, making sure that you extract all the data from iOS devices in the most forensically sound possible.

👉 https://blog.elcomsoft.com/2020/05/ios-acquisition-reloaded/

#eift #iphone #ios #mobilesecurity #mobileforensics #dfir #itsecurity #smartphone #dataextraction #ElcomsoftAgent #decryption
Working Around the iPhone USB Restricted Mode

The USB restricted mode was introduced in iOS 11.4.1, improved in iOS 12 and further strengthened in iOS 13. The USB restrictions are a real headache for iPhone investigators. We’ve discovered a simple yet effective trick to fool it in some cases, but currently it securely protects the iPhones from passcode cracking and BFU (Before First Unlock) extractions. However, there is a trick allowing you to obtain some information from devices with disabled USB interface. Learn how to use this trick with the recently updated iOS Forensic Toolkit.

👉 https://blog.elcomsoft.com/2020/05/iphone-usb-restricted-mode-workaround/

#ios #iphone #ecx #dataextraction #mobileforensics #dfir #usbrestrictedmode #mobilesecurity
Apple vs. Law Enforcement – iOS 4 through 13.5

Today’s smartphones are a forensic goldmine. Your smartphone learns and knows about your daily life more than everything and everyone else. It tracks your location and counts your footsteps, AI’s your pictures and takes care of your payments. With that much data concentrated in a single device, it is reasonable to expect the highest level of protection. In this article, we’ll review the timeline of Apple’s measures to protect their users’ data and the countermeasures used by the law enforcement. This time no cloud, just pure device forensics.

👉 https://blog.elcomsoft.com/2020/05/apple-vs-law-enforcement-ios-4-through-13-5/

#ios #iphone #apple #encryption #protection #itsecurity #cybersecurity #mobileforensics #dfir #mobilesecurity