All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 14 posts ] 
Author Message
 Post subject: Bitlocker Decryption query
PostPosted: October 4th, 2022, 8:45 
Offline

Joined: September 1st, 2012, 6:16
Posts: 182
Location: Universe
I have got a nvme SSD which was upgraded to windows 11 automatically. Bitlocker has suddenly started appearing and customer says he was not aware of bitlocker.
I have checked protectors which are not "clear key" type so I am unable to decrypt them in pc3000 .
Is there anything I can try before giving up. Data on ssd is very important research data collected over time.
protectors are TPM and Numerical password.
Raw recovery in udma gives bitlocker headers. Are they of any use ? Attached are the same ------
download link - https://drive.google.com/file/d/1RIhD3d ... sp=sharing


Attachments:
b.PNG
b.PNG [ 29.64 KiB | Viewed 6116 times ]
11.PNG
11.PNG [ 11.78 KiB | Viewed 6116 times ]
Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 5th, 2022, 7:02 
Offline

Joined: November 23rd, 2010, 13:32
Posts: 461
Location: brisbane
I think full decryption not possible in this case as TPM is involved.
User might not be aware of Bitlocker but when he signs into microsoft account ( with administrative privilege ) automatically Clearkey password is converted in TPM type when key is backed up in microsoft account.
regarding those 2 files I am not aware of , opening in notepad shows something but it is least likely of any use.


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 5th, 2022, 23:48 
Offline

Joined: June 5th, 2006, 1:09
Posts: 92
Location: INDIA
Recovery seems to be impossible.


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 6th, 2022, 7:22 
Offline

Joined: September 1st, 2012, 6:16
Posts: 182
Location: Universe
terminator2 wrote:
I think full decryption not possible in this case as TPM is involved.
User might not be aware of Bitlocker but when he signs into microsoft account ( with administrative privilege ) automatically Clearkey password is converted in TPM type when key is backed up in microsoft account.
regarding those 2 files I am not aware of , opening in notepad shows something but it is least likely of any use.


Thanks , I have given up & informed customer that recovery not possible.


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 9th, 2022, 9:41 
Offline

Joined: October 24th, 2009, 15:22
Posts: 875
Location: Poland
We have some success at such cases. If client is still interested, we need laptop + drive at lab.

_________________
Flash Killer - everyday new resources (pinout, XOR, ECC,config) for flash devices


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 9th, 2022, 23:04 
Offline

Joined: November 23rd, 2010, 13:32
Posts: 461
Location: brisbane
arvika wrote:
We have some success at such cases. If client is still interested, we need laptop + drive at lab.


Wo , that means even Bitlocker TPM and numerical password can be cracked ?


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 14th, 2022, 23:00 
Offline
User avatar

Joined: April 22nd, 2015, 20:32
Posts: 413
Location: Portugal
terminator2 wrote:
arvika wrote:
We have some success at such cases. If client is still interested, we need laptop + drive at lab.


Wo , that means even Bitlocker TPM and numerical password can be cracked ?


Yes it can.

_________________
BTC Wallet - 3AoQPTBsz9PbfoanCx44Lw76Y2TwtKa1x5
Instagram https://www.instagram.com/datarecovery_morde.pt/


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 15th, 2022, 1:39 
Offline

Joined: November 23rd, 2010, 13:32
Posts: 461
Location: brisbane
DRUG wrote:
terminator2 wrote:
arvika wrote:
We have some success at such cases. If client is still interested, we need laptop + drive at lab.


Wo , that means even Bitlocker TPM and numerical password can be cracked ?


Yes it can.


That is incredible .Lots of clients are ready to pay hugh costs involved in this type of work. I will refer all such clients to you. :good: :-D :beer:


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 15th, 2022, 22:56 
Offline
User avatar

Joined: April 22nd, 2015, 20:32
Posts: 413
Location: Portugal
terminator2 wrote:
DRUG wrote:
terminator2 wrote:
arvika wrote:
We have some success at such cases. If client is still interested, we need laptop + drive at lab.


Wo , that means even Bitlocker TPM and numerical password can be cracked ?


Yes it can.


That is incredible .Lots of clients are ready to pay hugh costs involved in this type of work. I will refer all such clients to you. :good: :-D :beer:



I don't know how arvika deals with his cases, but here in our lab we can only deal with that issue if the device doesn't display the typical recovery blue screen. In that case we have no solution to offer.

_________________
BTC Wallet - 3AoQPTBsz9PbfoanCx44Lw76Y2TwtKa1x5
Instagram https://www.instagram.com/datarecovery_morde.pt/


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 17th, 2022, 14:24 
Offline

Joined: March 7th, 2009, 12:43
Posts: 1080
Location: Angel Data Recovery
DRUG wrote:
terminator2 wrote:
DRUG wrote:
terminator2 wrote:

Wo , that means even Bitlocker TPM and numerical password can be cracked ?


Yes it can.


That is incredible .Lots of clients are ready to pay hugh costs involved in this type of work. I will refer all such clients to you. :good: :-D :beer:



I don't know how arvika deals with his cases, but here in our lab we can only deal with that issue if the device doesn't display the typical recovery blue screen. In that case we have no solution to offer.


So, you deal with laptops when something prevent windows to boot (system corruption or bad sectors) and you simply intercept key on bus of tpm ? For the blue screen with requesting bitlocker key if you understand what triggered laptop to that condition, you can roll back situation. For example for dell XPS 13 models, bios update (along with windows update) triggers to request bitlocker key, and you can roll back bios to previous.
And about my own experience, in 8 out of 10 cases, when user doesn't know about active bitlocker, we found keys under his microsoft account (one of 3 : original microsoft, onedrive, azure account) , which he also doesn't know does exist, even if he "think" never created the one.

_________________
Angel Data Recovery


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 17th, 2022, 15:21 
Offline
User avatar

Joined: March 6th, 2010, 3:46
Posts: 601
Location: Kolding | Denmark
Dammed, here only 7 out of 10 whoa has recovery key in MS account client never created :)

_________________
Digitalsupport Data Recovery
https://digitalsupport.dk


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 18th, 2022, 3:08 
Offline

Joined: September 1st, 2012, 6:16
Posts: 182
Location: Universe
digisupport wrote:
Dammed, here only 7 out of 10 whoa has recovery key in MS account client never created :)


Exactly this has happened last week. I have got a laptop from a student whose laptop was updated to windows 11 and was asking Bitlocker key.
She searched her hotmail account where she found keys of her another old laptop alongwith many entries which she was not aware of .
But required key was missing.


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 18th, 2022, 9:27 
Offline

Joined: March 7th, 2009, 12:43
Posts: 1080
Location: Angel Data Recovery
higgsboson wrote:
digisupport wrote:
Dammed, here only 7 out of 10 whoa has recovery key in MS account client never created :)


Exactly this has happened last week. I have got a laptop from a student whose laptop was updated to windows 11 and was asking Bitlocker key.
She searched her hotmail account where she found keys of her another old laptop alongwith many entries which she was not aware of .
But required key was missing.


Did she check all 3 accounts under that email? Student's accounts MS usually put keys to Azure location. Check that email in there.

_________________
Angel Data Recovery


Top
 Profile  
 
 Post subject: Re: Bitlocker Decryption query
PostPosted: October 18th, 2022, 12:21 
Offline

Joined: November 23rd, 2010, 13:32
Posts: 461
Location: brisbane
DR-Kiev wrote:
higgsboson wrote:
digisupport wrote:
Dammed, here only 7 out of 10 whoa has recovery key in MS account client never created :)


Exactly this has happened last week. I have got a laptop from a student whose laptop was updated to windows 11 and was asking Bitlocker key.
She searched her hotmail account where she found keys of her another old laptop alongwith many entries which she was not aware of .
But required key was missing.


Did she check all 3 accounts under that email? Student's accounts MS usually put keys to Azure location. Check that email in there.


Oh , I suggested them to keep M.2 NvMe SSD aside for future work ,but they decided to go ahead with format as student who was having her project and 4 years research was lost without her mistake was frustated . I was not aware of Azure location.
Thank you I will note down this for future.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 14 posts ] 

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 181 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group