Hello all. I'm new to the forum and new to digital forensics in general. I'm sorta flying solo in my office right now so I figured it would tap into the community for assistance.
The subject hard drive I am analyzing has check generating software installed on it and the aforementioned program appears to create Microsoft Access database files (.mbd) for each "project/check" created by the used. All of the .mbd files associated with this program are encrypted (red in FTK) and not viewable. I assume this was done by the program itself, as no other user files on the drive are encrypted. I subsequently exported several of the .mbd files out of FTK and onto my desktop and was able to crack the password using a Nirsoft program…and the password seems to work on all of them (at least the sample I tried). The .mbd files are your typical Access database files that include several tables of data etc. As such, I then went back into FTK, added the password (Tools/Decrypt etc), and reprocessed; however none of the .mbd files were decrypted as a result. Am I doing something wrong here?
Ultimately I'd like to include these .mbd files in the final report and give the reader access to non-password protected files via FTK. Am I out of bounds with this goal? As a last resort, I can export all of the .mbd files out of FTK and onto a disk to provide it to the end-user with the password. I apologize if this is a silly question…still coming up the learning curve. Thanks again!
Welcome to the industry and the forum, and congratulations on cracking the files. First question, do you mean .mdb (Microsoft Database) files or is .mbd correct? I am wondering if there are MS Office DRM issues going on here maybe.
Did you try and fail to decrypt the files with the built in AD decryption engine? Last resort will be exporting them out, removing the password, and reingesting into FTK but that's suboptimal for several reasons.
You don't state what version of FTK you're running; if it's quite old maybe the files are in some newer format that it's struggling with.