Latest version
Released:
DPAPI decryption toolkit
Computerworld covers a range of technology topics, with a focus on these core areas of IT: Windows, Mobile, Apple/enterprise, Office and productivity suites, collaboration, web browsers.
Project description
OVERVIEW
DPAPIck is a python toolkit to provide a platform-independant implementation
of Microsoft's cryptography subsytem called DPAPI (Data Protection API).
It can be used either as a library or as a standalone tool.
It is also the first open-source tool that allows decryption of DPAPI
structures in an offline way and, moreover, from another plateform than
Windows.
It is provided with some application probes that includes the built-in logic
to retreive the corresponding secrets that are protected.
To have more information or to contact us, go to our website:
http://www.dpapick.com
REQUIREMENTS
This application has been developped and tested on python 2.7.
M2Crypto is required to provide all the requireds algorithms. To obtain it,
see: http://chandlerproject.org/bin/view/Projects/MeTooCrypto
Probes and other tool may require other modules to be able to retreive
information such as:
* python-sqlite3 for Google Chrome password database
* CFPropertyList for Apple Safari keychain.plist
see https://github.com/bencochran/CFPropertyList
* python-registry for low-level manipulation of hives
see https://github.com/williballenthin/python-registry
* pyASN1 for the RSA key pair manipulation
see http://pyasn1.sourceforge.net/
We also recommend the use of MoonSols Windows Memory Toolkit to convert
hibernation file to usable memory dumps and be able to extract credentials
from it.
For more information about Moonsols products, see <http://www.moonsols.com>
AUTHOR
DPAPIck is written by Jean-Michel Picod (jean-michel.picod@cassidian.com)
with the help from Ivan Fontarensky (ivan.fontarensky@cassidian.com)
who work for the Cyber Security Center of Cassidian, an EADS company,
and Elie Bursztein (dpapi@elie.im)
LICENSE
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation version 3 of the License.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
DPAPIck is a python toolkit to provide a platform-independant implementation
of Microsoft's cryptography subsytem called DPAPI (Data Protection API).
It can be used either as a library or as a standalone tool.
It is also the first open-source tool that allows decryption of DPAPI
structures in an offline way and, moreover, from another plateform than
Windows.
It is provided with some application probes that includes the built-in logic
to retreive the corresponding secrets that are protected.
To have more information or to contact us, go to our website:
http://www.dpapick.com
REQUIREMENTS
This application has been developped and tested on python 2.7.
M2Crypto is required to provide all the requireds algorithms. To obtain it,
see: http://chandlerproject.org/bin/view/Projects/MeTooCrypto
Probes and other tool may require other modules to be able to retreive
information such as:
* python-sqlite3 for Google Chrome password database
* CFPropertyList for Apple Safari keychain.plist
see https://github.com/bencochran/CFPropertyList
* python-registry for low-level manipulation of hives
see https://github.com/williballenthin/python-registry
* pyASN1 for the RSA key pair manipulation
see http://pyasn1.sourceforge.net/
We also recommend the use of MoonSols Windows Memory Toolkit to convert
hibernation file to usable memory dumps and be able to extract credentials
from it.
For more information about Moonsols products, see <http://www.moonsols.com>
AUTHOR
DPAPIck is written by Jean-Michel Picod (jean-michel.picod@cassidian.com)
with the help from Ivan Fontarensky (ivan.fontarensky@cassidian.com)
who work for the Cyber Security Center of Cassidian, an EADS company,
and Elie Bursztein (dpapi@elie.im)
LICENSE
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation version 3 of the License.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program. If not, see <http://www.gnu.org/licenses/>.
Decrypt Iphone Keychain-backup.plist
Release historyRelease notifications | RSS feed
- EPB is able to decrypt keychain data from password-protected backups (iOS 4 and later) if the backup password is known (or has been recovered using EPB for Windows). For iTunes backups that do not have the password set, as well as for iCloud backups, keychain can be decrypted only if the 'security key' is known.
- McAfee Drive Encryption: DD, IMG, BIN, E01, EX01: Yes: Instant Removal / Brute-force - Slow: Microsoft Edge Website-Instant Recovery: Mozilla Firefox Website-Instant Recovery: MS Access 2.0: MDB-Instant Recovery: MS Access 95: MDB-Instant Recovery: MS Access 97: MDB-Instant Recovery: MS Access 2000: MDB-Instant Recovery: MS Access 2002: MDB.
- Decrypt Keychain.plist 6,7/10 9514 votes Apr 11, 2012. This post details the step-by-step method required to extract a plist/OAuth token from a standard (non encrypted) iTunes backup of any iOS device.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Filename, size | File type | Python version | Upload date | Hashes |
---|---|---|---|---|
Filename, size dpapick-0.3-py2.7.egg (83.5 kB) | File type Egg | Python version 2.7 | Upload date | Hashes |
Filename, size dpapick-0.3-py2-none-any.whl (39.5 kB) | File type Wheel | Python version py2 | Upload date | Hashes |
Filename, size dpapick-0.3.tar.gz (78.8 kB) | File type Source | Python version None | Upload date | Hashes |
Hashes for dpapick-0.3-py2.7.egg
Algorithm | Hash digest |
---|---|
SHA256 | 9515290dfe11793b706638512a32afbb33dac2f75b1a0de9809f743f042bc24c |
MD5 | 3c10bf63bab1d408206ad025f2bed5a0 |
BLAKE2-256 | 4da7e7d5bfa8144fe8b33a3905b3013e304768619cef5c6e5fcf75007760c45b |
Hashes for dpapick-0.3-py2-none-any.whl
Algorithm | Hash digest |
---|---|
SHA256 | b52dc5fd784ec128a973dcfedf8dccc039f4f519721df95433800bbe961b5752 |
MD5 | 0c07be9695a97232cbbb448fb73ccde0 |
BLAKE2-256 | 445a066f5d9791d3799a0d2cd52b44cfe9caecefa7be14013ceb79953d13014b |
Hashes for dpapick-0.3.tar.gz
Decrypt Keychain-backup.plist
Algorithm | Hash digest |
---|---|
SHA256 | 129bc9b3924d9efa95f99cf5c5eabd980439925023f0f83011c1b774dd6cc32e |
MD5 | 7a25d928c98d54c43f825d03aba40489 |
BLAKE2-256 | 8e45cdb1b13d7076c6e9b5b060ab0b0a2b202661866bdff00efb0d2627571ae2 |