Quantcast
Channel: Forensic Focus Forums - Recent Topics
Viewing all articles
Browse latest Browse all 20112

Mobile Phone Forensics: Decrypt iOS Keychain

$
0
0
Just to confirm, are you taking about decrypting encrypted iTunes backups on a computer or are you talking about decrypting a keychain recorded from an acquisition of a mobile device? How are you using Elcomsoft? What data are you using to decrypt the files? How are you generating the wordlists? If talking about encrypted iTunes backups, I come across these quite often at work and I have only failed to decrypt one (I've managed to decrypt the other 100+) by finding passwords on the source device (the laptop). Some suggestions to identify passwords:- - Firefox Profile - I've had quite a lot of success with using passwords from here to decrypt an iTunes backup - If the source device is a Macbook, have a look at the login.keychain. EnCase7 allows you to decrypt the data of this or there is a great free CLI tool called 'dumpkeychain' which will process the login.keychain. - Data breach dumps freely available online - you can search these for an email address for the owner of the device and then try and passwords against this - Use Magnet Forensics free tool, Wordlist Generator. You do need to have AXIOM to use this though. This will create a dictionary that you can then import into Elcomsoft

Viewing all articles
Browse latest Browse all 20112

Trending Articles