<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description>This is a forensic tool to deal, in an offline way, with Microsoft Windows® protected data, using the DPAPI (Data Protection API).
Written by: Elie BurszteinJean-Michel Picod</description><title>DPAPIck</title><generator>Tumblr (3.0; @dpapick)</generator><link>http://dpapick.com/</link><item><title>Let's talk about roadmap</title><description>&lt;p&gt;I recently discovered that Bitbucket is not duplicating the issue tracker while forking a repository. Thus you don’t have any visibility on what’s going on for DPAPIck and that’s why I’m writing this post.&lt;/p&gt;
&lt;p&gt;So, as far as we are going, this is why we planned to release for version 0.3:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;EFS Certificate recovery&lt;/li&gt;
&lt;li&gt;Inline documentation&lt;/li&gt;
&lt;li&gt;bin tools rewriting to keep only one binary and link it to the probes (usage should be similar to volatility for those who are familiar)&lt;/li&gt;
&lt;li&gt;Okteta support but low priority for this one…&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;Inline documentation is already done, EFS private decryption is done too but we need to add a PKCS#12 export function to keep the certificate with its private key and make it easy to work on EFS from Linux.&lt;/p&gt;
&lt;p&gt;The bin tools rewriting is stale for the moment as I need to focus on another project. But as soon as I have time to go back on DPAPIck, I will finish this part and release a new version. Okteta support may be for a further version.&lt;/p&gt;
&lt;p&gt;If you have any suggestion, any wish-list to add to our roadmap, feel free to leave a comment ! This blog is here for that kind of stuff too :-)&lt;/p&gt;</description><link>http://dpapick.com/post/12234875819</link><guid>http://dpapick.com/post/12234875819</guid><pubDate>Wed, 02 Nov 2011 04:28:19 -0400</pubDate></item><item><title>Maybe I just don't know or understand enough about this tool.  Where is the MasterKey or Credhist stored in windows?</title><description>&lt;p&gt;Don’t worry, there is no stupid question :)&lt;/p&gt;
&lt;p&gt;You have a masterkey directory and one CREDHIST file per user account. For each user account, they are both located under Application Data\Microsoft\Protect (for XP) or AppData\Roaming\Microsoft\Protect (Vista &amp; Seven). SYSTEM account also has masterkeys (but no CREDHIST), located under Windows\System32\Microsoft\Protect&lt;/p&gt;
&lt;p&gt;Be aware that they are hidden and system files so they are not displayed by default on Windows (could be configured in explorer).&lt;/p&gt;</description><link>http://dpapick.com/post/10002407127</link><guid>http://dpapick.com/post/10002407127</guid><pubDate>Fri, 09 Sep 2011 15:17:12 -0400</pubDate></item><item><title>It's out !!!</title><description>&lt;p&gt;As promised, today we are releasing the source code of DPAPIck v0.2 !&lt;/p&gt;
&lt;p&gt;The project is hosted at Bitbucket and you can freely check it out to play with it.&lt;/p&gt;
&lt;p&gt;You can also report bugs/issues on the tracker and see part of the roadmap for our tool.&lt;/p&gt;
&lt;p&gt;A wiki will also be put online as soon as we take time to write documentation.&lt;/p&gt;
&lt;p&gt;But no more waiting, here is the URL to have a look at DPAPIck : &lt;a href="http://bitbucket.org/jmichel/dpapick"&gt;http://bitbucket.org/jmichel/dpapick&lt;/a&gt;&lt;/p&gt;</description><link>http://dpapick.com/post/8428274745</link><guid>http://dpapick.com/post/8428274745</guid><pubDate>Wed, 03 Aug 2011 10:32:00 -0400</pubDate><category>BlackHat</category><category>Release</category></item><item><title>D-6 ?</title><description>&lt;p&gt;Next week, DPAPIck will finally became the first opensource tool    (GPLv3 licence) which is able to deal with DPAPI structures as well as    the first tool that can do so from another operating system than    Microsoft’s !&lt;/p&gt;
&lt;p&gt;It has been entirely re-written in Python and only  requires OpenSSL   for decryption to be fully cross-platform. It is coming  along with   several applicative probes that embeds the decryption logic  specific to   each application that uses DPAPI (eg. Google Talk, Skype,  Wireless   keys, Internet Explorer, etc.).&lt;/p&gt;
&lt;p&gt;And we are not releasing DPAPIck v0.2 alone ! It comes along with other surprises that we let you discover on August :-)&lt;/p&gt;
&lt;p&gt;Until  the public release, you will be able to meet us, for the lucky   ones who  are attending BlackHat USA 2011 or DefCon 19. And if you are   attending  BlackHat, do not forget to go and see our presentation of   OWADE, our new  advanced forensic tool !&lt;/p&gt;</description><link>http://dpapick.com/post/8185721656</link><guid>http://dpapick.com/post/8185721656</guid><pubDate>Thu, 28 Jul 2011 17:21:58 -0400</pubDate><category>DPAPI</category><category>BlackHat</category><category>python</category><category>OWADE</category></item><item><title>No, we're not dead !</title><description>&lt;p&gt;Pour la population francophone intéressée par DPAPI, nous avons rédigé un article qui sera publié dans la revue française &lt;a href="http://www.ed-diamond.com/index_misc.php"&gt;MISC&lt;/a&gt; pour son numéro 56 (Juillet/Août).&lt;/p&gt;
&lt;p&gt;Il reprend l’analyse des structures que nous avons publiée à BlackHat DC 2010, en incluant quelques corrections et quelques unes de nos avancées. Des bouts de scripts Python permettant de déchiffrer les structures sont également fournis dans l’article.&lt;/p&gt;
&lt;p&gt;Nous continuons nos travaux sur le sujet et DPAPIck a été entièrement réécrit en Python pour faciliter les développements et les tests. Cette version devrait prochainement être mise à disposition de la communauté.&lt;/p&gt;
&lt;hr&gt;&lt;p&gt;For non-French people, the above paragraphs are telling that we are about to publish an article about DPAPI in a French magazine that includes code snipplets in Python to decrypt the structures we talked about at BlackHat DC 2010.&lt;/p&gt;
&lt;p&gt;We are still working on that subject and our tool, DPAPIck, has been entirely rewrote in Python to help us adding new features more easily. This new version may soon be made available to the community. Stay tuned !&lt;/p&gt;</description><link>http://dpapick.com/post/5728989841</link><guid>http://dpapick.com/post/5728989841</guid><pubDate>Sun, 22 May 2011 08:00:00 -0400</pubDate><category>publication</category><category>magazine</category><category>python</category><category>DPAPI</category></item><item><title>Presented @BlackHat dc+2010</title><description>&lt;a href="http://www.blackhat.com/html/dc2010/dc2010-home.html"&gt;Presented @BlackHat dc+2010&lt;/a&gt;: &lt;p&gt;Our tool was presented during the &lt;a title="BlackHat dc+2010" target="_blank" href="http://www.blackhat.com/html/dc2010/dc2010-home.html"&gt;BlackHat dc+2010&lt;/a&gt;&lt;/p&gt;</description><link>http://dpapick.com/post/5576502435</link><guid>http://dpapick.com/post/5576502435</guid><pubDate>Tue, 17 May 2011 10:37:00 -0400</pubDate><category>BlackHat</category></item><item><title>What is DPAPIck?</title><description>&lt;p&gt;&lt;span&gt;This is a forensic tool to deal, in an offline way, with Microsoft Windows® protected data, using the DPAPI (Data Protection API).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;
&lt;p&gt;A non-exhaustive list of those recoverable secrets are :&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;EFS certificates&lt;/li&gt;
&lt;li&gt;MSN Messenger credentials&lt;/li&gt;
&lt;li&gt;Internet Explorer form passwords&lt;/li&gt;
&lt;li&gt;Outlook passwords&lt;/li&gt;
&lt;li&gt;Google Talk credentials&lt;/li&gt;
&lt;li&gt;Google Chrome form passwords&lt;/li&gt;
&lt;li&gt;Wireless network keys (WEP key and WPA-PMK)&lt;/li&gt;
&lt;li&gt;Skype credentials&lt;/li&gt;
&lt;li&gt;…&lt;/li&gt;
&lt;/ul&gt;&lt;/span&gt;&lt;/p&gt;</description><link>http://dpapick.com/post/5576215468</link><guid>http://dpapick.com/post/5576215468</guid><pubDate>Tue, 17 May 2011 10:19:25 -0400</pubDate><category>Presentation</category></item></channel></rss>

