How to: Crack Bitlocker encrypted drives

Поделиться
HTML-код
  • Опубликовано: 10 июл 2024
  • UPDATE: Because of the requirement of TPM 2.0 in Windows 11, this method no longer works. On older Windows 10 systems that are not using TPM it will still work as described.
    NOTE: This is a very long process, and may not always be successful. There are people who crack hashes for money, I AM NOT ONE OF THEM. Do not contact me to crack "your" hash.
    This is for educational purposes only and is only to be used on computers that you own or have permission to test.
    In this video we go through the steps of creating a Bitlocker drive, imaging it, turning the image into a crackable hash and then cracking that hash with Hashcat.
    FTK imager: marketing.accessdata.com/imag...
    Article I used: openwall.info/wiki/john/OpenC...
    Intro: (0:00)
    Bitlocker settings: (1:10)
    FTK imager: (1:50)
    Bitlocker2john: (4:27)
    Hashcat (Crack the Hash): (7:20)
    Password cracked: (8:40)
    Outro: (9:27)
    My setup:
    CPU: amzn.to/35CsCsO
    GPU: amzn.to/33uLB5E
    Ram: amzn.to/2ZzNfBQ
    SSD: amzn.to/32uDiHW
    Motherboard: amzn.to/2RqgNgP
    PSU: amzn.to/2Rq0SiD
  • НаукаНаука

Комментарии • 799

  • @PentestsandTech
    @PentestsandTech  3 года назад +38

    Here is the command if you want to crack the recovery key: John --format=bitlocker-opencl -mask=?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d target_hash

    • @SamuelVanlalruatsaka
      @SamuelVanlalruatsaka 3 года назад +2

      Can you tell me which code to be replaced?

    • @PentestsandTech
      @PentestsandTech  3 года назад +2

      Target_hash

    • @commandojas
      @commandojas 3 года назад

      @@PentestsandTech Awesome video. How can I carry this out with hashcat? Target_hash only seems to exist as part of the John attack.

    • @bckhaw9855
      @bckhaw9855 3 года назад +1

      @@PentestsandTech Hi, can I know what is the code I need to replace for the "Target_hash"? Do you mean the Txt file name where I saved the hash?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      Yes, the text file containing the hash

  • @mariadiosa2619
    @mariadiosa2619 Год назад +8

    Best soft soft tutorial for beginners on RUclips! I'm an absolute beginner and all the other tutorials I've found on RUclips have been so

  • @nwj2468
    @nwj2468 2 года назад +2

    Thank you for this video. This seems to be the only method I could get to work (I originally had trouble just making the image of the drive).

  • @antoniocptsl
    @antoniocptsl 3 года назад +3

    Hey! I deleted my comment before seeing your response, but I just had to press Enter and it showed the results! Currently running Hashcat, hopefully should be cracked soon. Great video, you got yourself a subscriber. Keep up the good work! ;)

  • @inadaizz
    @inadaizz 4 года назад +11

    Hey I needed this today... and you uploaded it today. Hello =D

  • @ScottPlude
    @ScottPlude Месяц назад +1

    How on earth have I not seen this until now?!?!?! Thanks!

    • @PentestsandTech
      @PentestsandTech  Месяц назад +1

      You’re welcome, just so you know, it dosen’t work on windows 11 anymore

  • @MrHappy702
    @MrHappy702 2 года назад +9

    This is a great video! Though as a preventative, what is the best thing (besides long complex password) that one can do to make cracking the bitlocker driver extremely difficult to almost impossible?

  • @michalbicki6196
    @michalbicki6196 2 месяца назад +2

    IT WORKED!!! THANK YOU SO MUCH!!!!

  • @a_fading_shadow
    @a_fading_shadow 3 года назад +30

    how many people here are like me where I lost the key and password...

    • @bibizarafshan4723
      @bibizarafshan4723 Год назад +1

      Do you find any solution for this problem ?

    • @halalpolice594
      @halalpolice594 6 месяцев назад

      😢

    • @prashanth5091
      @prashanth5091 5 месяцев назад

      ​​@bibizarafshan4723 do you find any solution for the problem

    • @iamnotthecia
      @iamnotthecia 5 месяцев назад +3

      I'm here because windows decided to permanently encrypt my entire fucking ssd because I had the audacity to disable boot security in my bios. I never even activated the fucking thing and never set up a password

  • @andrzejwojewodzki6983
    @andrzejwojewodzki6983 2 года назад +1

    I had two partitions on my bitlockered 1TB drive. jumbo-john stops always at "VMK entry found at 0xede90f8a90" after around 24 hours of work. How, in that case, find the hashes of only one partition instead of a whole disk? Any suggestions? How to make a bit-to-bit image of chosen partition only?

  • @CodeDynamo
    @CodeDynamo 3 года назад +2

    Awesome Buddy

  • @jumpieva
    @jumpieva 2 года назад +1

    quick question, since this is specific to bitlocker can i still use these tools for other types of brute forcing? I got a computer in an estate auction, and strangely there was also a disk labeled "merlin encrypted HD". i can't seem to find much specific to merlin and encryption other than 'merlincryption' but not sure if that's relevant? it mentions an m70 which is a dell laptop, does dell have proprietary encryption?

    • @modernkangal
      @modernkangal 3 месяца назад

      I was tempted to answer, so here I am. Yes, Dell does have proprietary encryption
      I'm sitting here struggling to get bitlocker removed😂

  • @IcySilverPig
    @IcySilverPig 2 года назад +2

    For the bitlocker2john how long does it take? I have a 500gb HDD if that helps.

  • @SrMasterSimpson
    @SrMasterSimpson Год назад

    It's working thanks my friend

  • @benl3115
    @benl3115 4 месяца назад +1

    Amazing tutorial

  • @jalen68
    @jalen68 3 года назад

    do we really need the full image to be stored somewhere? because my bitlockered drive is 4tb and my other drive is only 1tb will it still be possible to use this method?

  • @user985121
    @user985121 3 года назад +4

    Can you give some stats on end-to-end cracking time? Ie. against recovery keys, since they are fixed in size and complexity. Which means cracking time of a fixed volume size should be relatively constant.

  • @BlitzYT_.
    @BlitzYT_. Год назад

    TNice tutorialS IS WHAT I NEEDED BRO, thank you for taking the ti and doing tNice tutorials for most of that are starting with tNice tutorials beautiful tNice tutorialng called

  • @steveb936
    @steveb936 3 года назад +6

    Hi, I have FTK imager downloaded, where do I find the other 2 that I need
    Thanks

  • @sanithomer
    @sanithomer 3 года назад

    Sorry, I don't totally get how to crack the recovery key per se...I understand the mask part, but where to place the command during the hashcat part? or will it be a file with different recovery keys that will do the same trick as if it was a dictionary?

  • @Mickatronix
    @Mickatronix 3 года назад +2

    Good job, thx !

  • @zaheeryoonoos8156
    @zaheeryoonoos8156 2 года назад

    Hi.. when I ran the Jumbo John, i got the following error. Does that mean it didn't generate any hash for the Bitlocker drive?
    Error while extracting data: No signature found!

  • @FDNYC
    @FDNYC 3 года назад +3

    You showed how to crack it with a dictionary "wordlist" passwords. What about a recovery key? there is no wordlist for it so how is it done?

  • @renjithbalan6417
    @renjithbalan6417 2 года назад +1

    I created disk image using external hard disk.when using code commend it shows invalid version.is it necessary to create image with TPM chip and possible to extract the image using another system with TPM Chip

  • @justytchannel
    @justytchannel 2 года назад +1

    Hey, I have a big problem - the thing is that I saved the key on an encrypted disk - I only saved it there and I do not have access to it, unfortunately I do not remember the password, is there any possibility to crack the password, recover the key or, for example, recover files from of an encrypted disk, and then clean it and upload a new system to have access to this disk?

  • @rashidmehmood-bf7ro
    @rashidmehmood-bf7ro Год назад

    Hey, I'm just starting to get into making soft and tNice tutorials 17 minute video helped a LOT MORE than those one hour long tutorials out

  • @timhamilton2304
    @timhamilton2304 Год назад

    Thanx for the video, good stuff! When I run the command to crack the recovery key I get the error "No OpenCL devices found". My target_hash file has the $bitlocker$2 and $bitlocker$3 hashes listed. What could be the cause of the error?

  • @janekmachnicki2593
    @janekmachnicki2593 Год назад +1

    Super video cute !!!! Thanks

  • @kasztan4236
    @kasztan4236 2 года назад

    I got to 7:56 and it gets stuck at "Initializing backend runtime for device #1..." I left it alone for half an hour and still nothing. Any suggestions as to why that's happening?

  • @itzcybermusicwala
    @itzcybermusicwala 3 года назад +1

    What can I do with numerical password ID and external key id ?

  • @bestsf
    @bestsf 2 года назад

    Hello
    Thank for this video.
    At the end, I don't understand that you said (i'm french) : More the disc image is bigger, fast the crack is ?

    • @PentestsandTech
      @PentestsandTech  2 года назад +1

      The bigger the disk, the longer it takes to extract the hash. The bigger the password, the longer it takes to crack.

    • @bestsf
      @bestsf 2 года назад +1

      @@PentestsandTech Tank you !

  • @gitaproductionlive9772
    @gitaproductionlive9772 Год назад

    Please does soft soft need a driver for midi controller? Coz it's not reading my midi controller, m-content oxygen49, thanks if it need please

  • @alessandro91
    @alessandro91 3 года назад

    Is it possibile to crack the 48 digits that you enter before booting the system?

  • @UmerFarooq-ch3sv
    @UmerFarooq-ch3sv 3 года назад +1

    I always got error notification receive like this (error recovering disk G: A Recovery key was not found on this drive) any one can give me any soloution ???

  • @malkisj2010
    @malkisj2010 2 года назад +1

    Greeting, I have WD my passport portable drive bitlocker and I do not have the password or they backup key. so my question is it possible to access the drive and backup all files saved on it ?
    please let me know I appreciated your quick replay

  • @zigafide
    @zigafide 2 года назад +1

    interesting vid 👍

  • @totto599
    @totto599 3 года назад +1

    While trying to install FTK imager, I'm getting a Processor not supported error - is it because I'm on a 32 bit system??
    If so from where can I get the 32 bit one??

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      Sorry man, they don’t make a 32 bit version. 32 bit is being phased out because 32 bit processors are not being made anymore. I’m guessing you have a 64 bit processor but your windows install is probably 32 bit. Consider reinstalling windows and making sure you select 64 bit.

  • @adithya00
    @adithya00 2 года назад

    If the all drives are encrypted and don't know any decrypt key what I can do ? (Only hope is cmd with X: drive in the blu screen.)

  • @vdk996
    @vdk996 3 года назад +1

    how u get 6gb from 8gb of ur video memory? i have 3070

  • @claudiooliveira8039
    @claudiooliveira8039 3 года назад

    Hi. I ran jumbo john, but didn't get any hash at the end. All results were "Invalid Version" or "Error: VMK not encrypted with AES-CCM". Do you know why?

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      Sounds like it’s a different encryption method, not sure how you would crack it. Sorry.

  • @trollerbladdering
    @trollerbladdering Год назад +1

    I've had a rapid influx of people coming into my tech repair store because the Windows 22H2 update has been bricking systems left and right and unfortunately many of these people don't even know what bitlocker is, why it was enabled, and don't have their key. I'm hoping this method might be a solution for these people.

  • @vinodkanaujia
    @vinodkanaujia 3 года назад +1

    Hi i m badly facing the problem of forget pwd and recovery key of my ext hd, plz guide me in simple words how can i get my data recovered plz

  • @pattheitguy
    @pattheitguy 2 года назад +2

    To increase performance (lower times), what hardware would be best? A video card? If so, what brands/models do best?

    • @PentestsandTech
      @PentestsandTech  2 года назад +1

      Nvidia graphics card, as high end as your budget can go

  • @k00lk33f420
    @k00lk33f420 2 года назад +1

    Thank you for this demonstration. Have you ever encountered a scenario where bl2j did NOT return any hashes, but detected an unencrypted VMK stored clear? Does the lack of a hash return indicate no 48 digit recovery key or user-created password is present, only a VMK?

    • @bernhardandresen
      @bernhardandresen Год назад

      Error: VMK not encrypted with AES-CCM. Like in my case

    • @rubenkaczmarek3962
      @rubenkaczmarek3962 Год назад

      @@bernhardandresen And what did You do? I have this problem

    • @bernhardandresen
      @bernhardandresen Год назад +2

      @@rubenkaczmarek3962 sadly, couldn't solve the problem

  • @christianez6899
    @christianez6899 Год назад

    If I encrypted my personal USB on a work computer and don't have that original device anymore that encrypted - does this work?

  • @gabrielrossirocha
    @gabrielrossirocha 2 года назад

    and if my result on john is: VMK encrypted with TPM...not supported! (0x71bbf928)
    There's an alternative method or game over for my HD?

  • @Yansa1908
    @Yansa1908 3 года назад

    Please help me....
    The bitlocker encryption on this Drive isn't compatible with your version of Windows, try opening the drive using a never version of Windows.

  • @AlexJoneses
    @AlexJoneses 3 года назад

    If i was doing a recovery key attack with hashcat, can I create a wordlist of a couple of six digit numbers (some of which I know to work), to use on the bitlocker decryption? This is assuming I am using a $bitlocker$2 hash

    • @PentestsandTech
      @PentestsandTech  3 года назад

      You can enter in manual numbers when you are using mask attack.

    • @AlexJoneses
      @AlexJoneses 3 года назад

      @@PentestsandTech where would I enter those and how?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      Hashcat -a 3 yourhash.txt 1223456-?d?d?d?d?d

  • @kr1216
    @kr1216 3 года назад

    is it ok that you unlocked the drive before the operation ? is it the same with locked drives ?

  • @ScottPlude
    @ScottPlude Месяц назад +1

    Thanks!

  • @bennypr0fane
    @bennypr0fane 2 года назад

    Could it be that this doesn't work if the image was encrypted by the TPM?

  • @letsgetto1millwithoutvids
    @letsgetto1millwithoutvids 2 года назад

    So is it better to get a USB like the Kingston datatraveler 2000 that has hardware encryption with a keypad on is it possible to crack those

  • @fursan7525
    @fursan7525 Год назад

    Hi there, I actually have the recovery key, but when i enter the Bitlocker-Key it opens the lock but I still cannot access the drive! I get the Message: I need to format the drive before using it; file location is not available ! any Idea?
    thank you in advance

  • @jamesli3097
    @jamesli3097 2 года назад

    HI, my hdd was locked by bitlocker when after re-install windows. However, i don't have the recovery key and no record in my hotmail account. is it can unlock my hdd & save the data?

  • @slack3r21
    @slack3r21 2 года назад +2

    Great video bro, I'm in the midst of doing a pen test for a client now. About to try this out, I'll report back if you helped me gain access to them :)

  • @imakethis7628
    @imakethis7628 3 года назад

    is this step possible if i format boot drive and the one im trying to unlock is the other drive (different hard drive).

  • @gabrielT93x
    @gabrielT93x 3 года назад +2

    so no matter how strong the password is, it can be broken by the recovery key
    right?

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      Yes, the recovery key and password are independent.

  • @Lisamarie1222
    @Lisamarie1222 3 года назад

    Hi there, I am trying to download the FTK on my old computer, windows 7 and it is stating the program wont work on this processor. Is there any other way to get around this or use another program? Thank you.

    • @PentestsandTech
      @PentestsandTech  3 года назад

      There’s other ways to image a hard drive, just search online and I’m sure you’ll find something

  • @ambientskai
    @ambientskai 2 года назад

    I know this is 2 years old. But What do I do if john keeps saying No opencl devices found? I'm trying to crack a recovery key since thats all I am getting

  • @dandyprihatnolo2817
    @dandyprihatnolo2817 3 года назад +1

    Hi, im having a little trouble down here. when i ran a hashcat.exe it gives me an error it says "salt value exception", how im supposed to do?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      It sounds like your drive may be encrypted with a different version of bitlocker, or a TPM chip was used.

    • @dandyprihatnolo2817
      @dandyprihatnolo2817 3 года назад

      @@PentestsandTech okey, but i try with this step
      "John --format=bitlocker-opencl -mask=?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d[-]?d?d?d?d?d?d target_hash"
      it takes forever to find that key, is this normal?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      Yeah, that process takes very very long

  • @swooshnike5514
    @swooshnike5514 3 года назад

    can a sd card that was encrypted with “bit locker to go” be bypassed as well? Can i use this same method on the sd card?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      Haven’t tried it, but i think the to go version can also be cracked with this method.

  • @alirezakarimian7459
    @alirezakarimian7459 3 года назад

    hi after using "ftk imager" who software use for browsing image?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      You can’t browse the image because it is encrypted. But if it was not you would need to use a forensic tool like Phyiscal analyzer, FTk, Encase, Autopsy or magnet forensics.

  • @swordguy8
    @swordguy8 3 года назад +2

    Is it possible to use a similar method to decrypt files encrypted with ransomware?

    • @traida111
      @traida111 2 года назад

      yes and no. an example: ruclips.net/video/Sv8yu12y5zM/видео.html

  • @atithirath4129
    @atithirath4129 Год назад

    Hi - instead of a specific drive, my laptop has been locked with BitLocker, I need assistance to retrieve my data. Is there a way I can use another system to run your hashing technique to get my BitLocker key? Thanks in advance!

    • @rocky6578
      @rocky6578 Год назад

      Assuming you no longer can log on the original Laptop , your only option is check and see if you backed up the bitlocker recovery keys in your Microsoft account. If you no longer have the original computer and try to install the hard drive and try to recover the data with another computer , this method won’t work.

  • @dabeersboys
    @dabeersboys 2 года назад

    Is this if the whole drive is BitLocker encrypted? If I have an encrypted partition would I need to separate the encrypted partition to it's own image file and then run it? When running it on the physical disk image it failed saying no HASHES were found. THANKS! and Subscribed!

    • @dabeersboys
      @dabeersboys 2 года назад +2

      Disregard- I imaged out the encrypted partition and it appeared to fix the issue. Great video. I appreciate it.

    • @PentestsandTech
      @PentestsandTech  2 года назад

      Glad you got it figured out!

  • @liquiddenmark1315
    @liquiddenmark1315 3 года назад

    So i got the hash, but when i use hashcat it says that -n is out of date and i have to use --force. Then when i do that, it says that no hash loaded? plus where did you get the password list?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      It’s -m, and i got the password list from a GitHub called seclists. You can get the rockyou file from basically anywhere, and there are other good ones as well.

  • @Crazyfaith
    @Crazyfaith 3 года назад

    Hey sorry for bother but I can't use dictionary since my password had special characters, is there any way to configure and download a dictionary with a maximum of 14 characters alphanumeric and with special characters? Sorry I literally have no idea how to code but I'm guessing this would be a lot faster than using the recovery password method

    • @PentestsandTech
      @PentestsandTech  3 года назад

      You would need to make your own, or just brute force it.

  • @the_shridhar
    @the_shridhar 2 года назад

    How much time it will take for 300gb disk with 80 gb of data?

  • @abhirupom4634
    @abhirupom4634 2 года назад +1

    hey , i m in a trouble , due to hadware change of my system my hardisk has been encrypted . and its 48 digit recovery key is not saved in my microsoft account . will i get accsses to those data , through this method ?

    • @parmarpratik8000
      @parmarpratik8000 Месяц назад

      If you found any solution for it, kindly share. Thanking you in advance

  • @antoniojamastin2617
    @antoniojamastin2617 3 года назад

    I have a doubt will this work on partitioned drive. Like I have a 500Gig drive with a 100gig locked away. So will creating the whole 500gig disk image work?

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      The drive i used had multiple partitions.

    • @antoniojamastin2617
      @antoniojamastin2617 3 года назад

      @@PentestsandTech Thanks a lot ! Oh and I might have follow up questions cause currently it's running the FTK Imager :)

    • @antoniojamastin2617
      @antoniojamastin2617 3 года назад +1

      @@PentestsandTech Ok so I tried doing this method in hashcat but it is showing hash input is slow and then goes looping. And when I tried the mask method it says Hashfile Salt value exception error. what to do?

  • @Hirenkabariya
    @Hirenkabariya 2 года назад

    my HDD is lock by bitlocker for some reason the drive got locked after an update and the Bitlocker key ID has changed,

  • @laradebiasi3907
    @laradebiasi3907 Год назад

    Pls clarify my doubt sir does it have tabla soft????? Pls tell sir

  • @xmercer4701
    @xmercer4701 3 года назад +1

    Interesting Video, great Quality 👍
    Cool to see how active you respond to all the people having questions in the comments 👍👌
    And I have a question as well but not like the others before me. I'd like to ask about whats the conclusion for using Bitlocker safely (if you don't want to get your encrypted files decrypted with the technologies available (at least today))?
    Is it enough to set a 'strong' password (for example a 30 digit letters and special symbol combination not fitting a dictionary attack)?
    Or what kind of password would I need so it's impossible with today's technical possibilities to crack the encryption by brute forcing the passphrase? (impossible in the meaning of not possible in under like 40 years or something like that)

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      Bitlocker is much stronger when paired with a TPM module, (found in newer laptops and macs). A 30 character complex password is more than enough for today’s technology.

    • @xmercer4701
      @xmercer4701 3 года назад

      @@PentestsandTech okay, thanks and thank you for that ultra fast answer as well :)
      And one more question about the TPM module, I mainly thought about using Bitlocker on a desktop pc but especially for USB drives, I guess the encryption will still be enough without a TPM module on the mainboard as long as you got a safe password and the recovery file somewhere external and safe?
      PS: (off topic to my question) I saw a video about the TPM module being a potential surface for multiple kinds of attacks on the Bitlocker mechanism, interesting to watch:
      ruclips.net/video/eRuca6eAdFM/видео.html
      You have a great channel mate, keep up the good work :)

    • @jeffreytagoc19
      @jeffreytagoc19 2 года назад

      @@PentestsandTech Hello, Sir. Do you mean, the tutorial will not work if I use BitLocker with TPM?

  • @cuocsongxanh85
    @cuocsongxanh85 Месяц назад

    Hi Ad,If I delete old windows and reinstall new windows, can I still open bitlocker on drive D?

    • @PentestsandTech
      @PentestsandTech  Месяц назад

      As long as you know the password it should be fine

  • @xx3868
    @xx3868 8 месяцев назад

    HI, Have a ASUS tablet with soldered HD so cant connect to other computer to erase drive. All boot USB attempts keep triggering Bitlocker. So i want to erase drive and install Win 8 but how can i do this? Can i use command prompt in recovery blue screen F8 area or will i still need key. As you explained, will erasing drive totally still leave Key with TPM and still lock me out?

    • @PentestsandTech
      @PentestsandTech  8 месяцев назад

      You’re gonna need to get usb boot to work, in the bios you should be able to set usb to boot before windows. Either use a Linux usb or the windows installer usb. Both will let you wipe the hard drive.

  • @s.d.plissken8986
    @s.d.plissken8986 2 года назад

    I have my hashes so how do I do the recovery key process?

  • @waseemhacks707
    @waseemhacks707 3 года назад

    What is 22100 you typed ? Appreciate if help is it random number or any specific

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      That’s the code for bitlocker hashes so hashcat knows what type of hash you’re trying to crack.

  • @TheViralClovers
    @TheViralClovers 4 года назад +4

    Thanks

  • @kankinping120466
    @kankinping120466 3 года назад

    Hi hi - my external drive freezes after I enter my bitlocker password - how can I attack this problem?

  • @leonwallace8646
    @leonwallace8646 2 года назад +3

    I encrypted my 250g drive from my Dell laptop and for some reason the drive got locked after an update and the Bitlocker key ID has changed, making my backed-up key obsolete.
    I know the password which is composed of 12 characters (1 capital letter + 8 lower case letters + 1 special character + 2 numbers)
    Whats the best method to retrieve the key and not the password?
    Thanks for the video.

    • @m3awna
      @m3awna Год назад

      @Leon Wallace I have a similar problem (bitlocker screen after update) but I never used bitlocker on the computer. Any success on your part? have you succeeded in recovering your data?

    • @alexhall2514
      @alexhall2514 Год назад

      Hi I have the same problem, did you ever find a solution?

    • @leonwallace8646
      @leonwallace8646 Год назад

      @@alexhall2514 unfortunately no
      I tried a bunch of different solutions and ultimately the ssd got corrupted so I had it replaced

  • @userwest626
    @userwest626 2 года назад

    I tried all the steps did get work out. I have 64GB sd pulled from lumia 950 when testing arm on windows, the phone suddently when dead. i found this video and tried all steps, the bitlokerjohn end up empty, no password, also tried different pirated data recovery, tried to open the image file, still get nothing. what do to?

  • @jamesedwards3923
    @jamesedwards3923 2 года назад +1

    If I understand him right. The recovery key is easier to hack in brute force scenarios. Am I right?

    • @12Burton24
      @12Burton24 6 месяцев назад

      Hm m8 i dont know why is it even possible to crack...i mean AES 256 is not hacked yet but ifyo can hack bitlocker it makes no sense to encrypt anything.

  • @sm2655
    @sm2655 3 года назад

    when running jumbo john...how long does it take to find a signature? thanks

    • @PentestsandTech
      @PentestsandTech  3 года назад

      For me it took 6 hours, but it depends on the drives size and speed. I’ve had some peoples take two days.

    • @sm2655
      @sm2655 3 года назад

      @@PentestsandTech okay thanks. i let it run for 40+ hours and last night....i went back to check on it and jumbo john cml screen was closed out. =(

    • @PentestsandTech
      @PentestsandTech  3 года назад +1

      That sucks man, I’m sorrry.

    • @krishchan8223
      @krishchan8223 3 года назад

      add the command to write your progress to a text file. The same thing happened with me. Windows update messed up inbetween in the night. So i am rerunning with writing the stdout to file

  • @remmy42
    @remmy42 Год назад

    nice thank u

  • @theangryhobos
    @theangryhobos 2 года назад

    what if the john output is only 2 hashes?

  • @thiagosoria9266
    @thiagosoria9266 3 года назад

    will I lose the data inside de HD bitlocked?

  • @MineCraftDarien
    @MineCraftDarien 3 года назад

    Do you help people with this as I struggled and need access to a harddrive with my old resume on it

    • @PentestsandTech
      @PentestsandTech  3 года назад

      I'm sorry, I don't help people crack passwords

  • @duncanmckie3984
    @duncanmckie3984 2 года назад

    I can't see how to install or download Jumbo John...you mention that was covered earlier, but I can't see anything here. Thanks.

  • @repairmobilecenter4656
    @repairmobilecenter4656 2 года назад

    Thanks for you video but i'm not sure to understand all steps. I have some keys on John but i don't think that's the good one... I have a RP MAC / RP VMK / RP NONCE only.
    Does it mean i have to wait more ? It's a M2 from a Surface Pro 4, my customer doesn't know the password and he think he never set a password... His tablet is out and i just have to unlock the M2 for put it on a external box.
    I'm scared because i think it doesn't have any password but only a recovery key :/
    Can you help me please? I try to put the RP VMK hash on the txt but i have a "No hashes loaded" on Hashcat.
    Thank you :)

  • @tonycole9593
    @tonycole9593 2 года назад +6

    I don't get it. If you have logged onto the pc, then you have access to the drive, and can manage bitlocker. It would be more useful to see how you would access a drive that you dont have access to the Windows credentials.

  • @xcemp
    @xcemp 3 года назад

    hello ! when use the hashcat show this error No hashes loaded any idea?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      That could mean a number of things, make sure you have the right hash identifier, the -m and the number that goes with it. Also make sure your hash is complete and matches the description from example hashes on hashcat.

  • @mmkamalraj8931
    @mmkamalraj8931 2 года назад

    Neat hack. Is there same tools in Linux?

    • @PentestsandTech
      @PentestsandTech  2 года назад

      Same tools different names, replace ftk imager with dd, also mounting bitlocker drives on Linux is a bit different

  • @arifsahabaccountant7598
    @arifsahabaccountant7598 3 года назад

    Help ME this error in USB BitLocker Drive Encryption failed to recover from an abruptly terminated Conversion. This
    Could be due to either all conversion logs being corrupted or the media being write-protected.

  • @MEMES-lm4qx
    @MEMES-lm4qx Год назад

    yayy

  • @efsouza78
    @efsouza78 7 месяцев назад

    Can you explain about file "rock you"? I don´t understand how I create this file. What content will this file contain?

    • @PentestsandTech
      @PentestsandTech  7 месяцев назад

      It’s a wordlist of possible passwords, if you google rock you it’ll come up

  • @greenwavemonster
    @greenwavemonster Год назад

    i was preparing to crack my friends Disk... luckily he found his Key last minute

  • @robertfeynman3174
    @robertfeynman3174 3 года назад

    Your guide won't work for a 20 character password with 256bit Bitlocker encryption in 2021 :) What modifications would you do to the guide for a 256bit 20+ char Bitlocker encryption ? Thanks

    • @PentestsandTech
      @PentestsandTech  3 года назад +2

      Wait for technology to improve, or wait for quantum computers to crack it lol

  • @HasimCoskun
    @HasimCoskun 3 года назад

    how long time would you say it should take for a 1tb drive? Mine has been running for 24 hours and still no bitlocker hashes yet.

    • @PentestsandTech
      @PentestsandTech  3 года назад

      Shouldn’t take more than two days

    • @HasimCoskun
      @HasimCoskun 3 года назад

      Well mine is seems like its frozen after some while. Possible to have somekind of status bar to see whether it works or not? It has been running for 2 days and still no hashes output.

    • @PentestsandTech
      @PentestsandTech  3 года назад

      I do not believe there is any status bar, you could try rerunning it, but that’s all that i can think of.

    • @HasimCoskun
      @HasimCoskun 3 года назад

      @@PentestsandTech mate can I get in contact with you through LinkedIn, FB or mail. Could I hire you to get the hash out for me?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      Sorry i don’t crack hashes.

  • @jetso2000
    @jetso2000 3 года назад

    Does it usually take long to pass the "Invalid version, looking for a signature with a valid version..."?

    • @PentestsandTech
      @PentestsandTech  3 года назад

      it's kind of hit or miss, if it is spamming that then its not going to work, but if you get a couple then you're probably fine, unless it says TPM

    • @alfdib
      @alfdib 2 года назад

      @@PentestsandTech to me it says "VMK encrypted with TPM....not supported". Should I drop or keep it running? thanks from italy

    • @PentestsandTech
      @PentestsandTech  2 года назад

      @@alfdib drop it, TPM is not supported

    • @alfdib
      @alfdib 2 года назад

      @@PentestsandTech thanks done. Something doable over TPM?

  • @aphroditeschild5980
    @aphroditeschild5980 3 года назад

    just want to share my terrible experience. I had my maxtor 1T send to netherlands to recover data which only have 2 years life time then sudden death. Journey took 2 months. Yesterday i get my recovered data stored in a 2T seagate expansion+ but encrypted by bitlocker. the decryption process is hell long only 52% stuck, then i pause and shut down, next day it is unreadable and no way to format it. So bad seagate quality!
    Is the microsoft bit locker kill the 2T seagate expension+ or it is a defective product manufactured in china 2020?