I have an image in which I have a truecrypt volume and a 256-bit AES encrypted zip file. I have been trying to crack them with not much success. I have tried Ultimate Zip Cracker and Passware. I was wondering if there is a better way to achieve this? Any suggestions are welcome!
Try to build a library from the case. I use FTK and PRTK for this.
Greg,
The image was created using Encase v6. The FTK version I use is old and is unable to work with it. Worse, Mount Image Pro is not able to mount it as well so I cannot attempt data recovery beyond Encase. Encase indexing returns indexes of 60 kb each which are nothing actually.
Cinux
Index your storage drive (including the .eo1 files) in ftk and export that wordlist. Only the latest version of PRTK (6.3) has truecrypt support. You really don't need to use the wordlist, but I think your odds go way up. Truecrypt is a tough one to crack.
Greg,
The image was created using Encase v6. The FTK version I use is old and is unable to work with it. Worse, Mount Image Pro is not able to mount it as well so I cannot attempt data recovery beyond Encase. Encase indexing returns indexes of 60 kb each which are nothing actually.
Cinux
Use FTK imager to Export Disk image to a DD image then you can bring that into your version of FTK.
Cinux- contact me here earndd at gmail dot Com
I have an image in which I have a truecrypt volume and a 256-bit AES encrypted zip file. I have been trying to crack them with not much success. I have tried Ultimate Zip Cracker and Passware. I was wondering if there is a better way to achieve this? Any suggestions are welcome!
I know this is a late post, but another thing to keep in mind is that Truecrypt allows the user to encrypt with not only a password, but a keyfile, and any type of file for that matter. So the user's encryption password could be "Windows", which would come up in any index of the hard drive, but unless you also choose to decrypt with the keyfile as well, I do not think you're getting into it. Just an FYI to keep in mind. The password may not be the only thing you need to look for.