Cold Boot Attacks o...
 
Notifications
Clear all

Cold Boot Attacks on Encryption Keys

24 Posts
14 Users
0 Reactions
1,596 Views
azrael
(@azrael)
Honorable Member
Joined: 19 years ago
Posts: 656
 

Firewire 😉


   
ReplyQuote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Yea, the firewater port, that's what I meant.

I'm going to go do something involving a great deal of precision right now since I appear to be on a roll….

-David

P.S. I edited my previous message so this'll not make too much sense.


   
ReplyQuote
Jamie
(@jamie)
Moderator
Joined: 5 years ago
Posts: 1288
 

especially given the current case involving this very thing

Hi hogfly, which case are you referring to?

Cheers,

Jamie


   
ReplyQuote
hogfly
(@hogfly)
Reputable Member
Joined: 21 years ago
Posts: 287
 

Jamie,
The one from the FF front page a few days ago
http//ap.google.com/article/ALeqM5ivXyvdarS_IeGHfcdhZn5GDKNZEwD8ULMSJ00


   
ReplyQuote
erowe
(@erowe)
Estimable Member
Joined: 18 years ago
Posts: 144
 

I can't remember if I got this link from ForensicFocus or if it was something I dug up somewhere else, but the Guillotine method has been around for a little while and relies on the same "persistence" properties of data in memory.

"Guillotine Method" for RAM Acquisition.
http//forensiczone.blogspot.com/2008/01/guillotine-method-for-ram-acquisition.html

Guillotine Steps and Conditions
http//forensiczone.blogspot.com/2008/01/guillotine-steps-and-conditions.html

It may be more practical at the moment than the Princeton method (and not require unreleased software).

Guillotine + FTK to carve out strings to use when cracking passwords would be my current approach. Although liquid nitrogen would be fun to play with in the lab… 😯 😯 😯


   
ReplyQuote
jemartin
(@jemartin)
Active Member
Joined: 18 years ago
Posts: 16
 

SANS ISC is keeping tabs on what whole disk encryption products are/may be exposed

http//isc.sans.org/diary.html?storyid=4024&rss

Enjoy!
Jim


   
ReplyQuote
(@mialta)
Eminent Member
Joined: 18 years ago
Posts: 27
 

Anyone here got any suggestions for an extremely low ram footprint linux distro we could use to capture the ram after this or the Guillotine Method ?

ie something with USB, Fat Drivers, DD and anything else essential but nothing else..

Thanks

Mialta


   
ReplyQuote
(@wesleymcgrew)
New Member
Joined: 17 years ago
Posts: 1
 

Hi all! I'm dropping by here since this is one of the places that popped up when I was reading about the Princeton guys' techniques of dumping RAM. They haven't released their dumper, so I took it upon myself to write one very similar to it as a weekend project.

http//mcgrewsecurity.com/projects/msramdmp/

This is much lower profile than you could ever get a linux (or other OS) distro. It runs as a com32 executable from the SysLinux bootloader, so the footprint is measured on the order of kilobytes, rather than megabytes. The gotchas are that it really needs something that can boot from USB (or transfer memory after blasting it with r-134a to something that does), and it's not the most user-friendly thing in the world. It's also a bit slower than the princeton researchers' one, but at least you can get this one now.

Hope you enjoy! I'll definitely be lurking/posting here more, now that I've found it.


   
ReplyQuote
(@tgoldsmith)
Eminent Member
Joined: 19 years ago
Posts: 35
Topic starter  

Hi Wesley, welcome to the forums -)

I haven't had a chance to test your work out yet (frustratingly, all the systems at my disposal have more RAM than my largest USB drive, and I don't fancy taking some out to test right now!), but it looks very interesting and the instructions you've included look very comprehensive.

Thank you for sharing this publically, I'm sure a lot of people around will find it very useful! I'll attempt to test it myself soon…

Cheers,

Tom


   
ReplyQuote
(@illwill)
Active Member
Joined: 21 years ago
Posts: 17
 

Welcome Wes I was actually coming here to post about your tool
Good work.. I'm in the process of trying to borrow a laptop to test this out.. my toughbook doesnt allow booting from a usb device unfortunately


   
ReplyQuote
Page 2 / 3
Share: