[Full-disclosure] Re: Windows XP Home LSA secrets storesXP loginpassphrase in plain text (John Doe)



John Doe sayed:
> As what comes to EFS, once you get hold of the administrator
> account, you can decrypt the EFS for _all_ users on the computer. It
> doesn't matter how you acquired the password.

In Windows 2000 this is true, however, in Windows XP this is NOT TRUE. In Windows XP the EFS private key is encrypted using users passphrase and without the passphrase, you cannot decrypt it.

In Win2k this is not the case, in Win2k
1) Administrator is the (compulsory) recovery agent and can decrypt all EFS files anyway.
2) Users private keys are not stored encrypted in the system and anyone who can simply sign in with that users credentials (like with 3rd party tools) can decrypt users EFS files.

If you dont believe me, I promise to give you 10000 euros if you can decrypt my EFS files by simply signing into my computer as administrator. If you cannot do that, you will pay me 1000 euros, ok?

--
My computer security & privacy related homepage
http://www.markusjansson.net
Use HushTools or GnuPG/PGP to encrypt any email
before sending it to me to protect our privacy.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: EFS Certs in AD or local PC?
    ... Just to add that EFS files can not be copied by anyone other then a user ... that can decrypt them but a user can use NTbackup to back them up to be ... If there are no correct EFS private keys [user ...
    (microsoft.public.windows.server.sbs)
  • Re: DRA is Decrypting Files when it shouldnt be!!!
    ... Policy then the user's EFS files can be updated automagically to reflect the ... fact to attempt to decrypt EFS files for a user that does not have their EFS ... > you didn't go far enough, after you log in as the built-in administrator ... >> RA though I rebooted the computer after encrypting the files and before ...
    (microsoft.public.windowsxp.security_admin)
  • Re: VS2005 website deployment problems with EFS
    ... It is not WIndows EFS, but it does encrypt. ... publish website or copy website deployment methods without manually ... If I manual decrypt the files then the manual copy the files it is quick as ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: EFS Questions
    ... EFS: ... If someone encrypts files on their local computer (in a domain ... > based environment) and later needs to be decrypted by the FRA, ... Then I'm able to decrypt the files. ...
    (microsoft.public.win2000.security)
  • Re: EFS Certs in AD or local PC?
    ... If his profile is in AD and we import his cert, will he be able to decrypt ... The users EFS private key is stored in the user's profile but not in a way ... If there are no correct EFS private keys [user ... configured then the RA [usually built in domain administrator account] ...
    (microsoft.public.windows.server.sbs)