Re: Desktop.ini file ignored by Windows Encryption...

From: Adam Piggott (adam_at_PROACTIVESERVICES.CO.UK)
Date: 11/08/04

  • Next message: support_at_maedata.net: "possible regedit bulk key deletion vulnerability (Revised)"
    Date:         Mon, 8 Nov 2004 19:47:02 +0000
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Scott Lockington wrote:
    | Hello All,
    |
    | In working with Windows EFS (i.e. 2000 sp4 and XP sp2) Any file named
    | "desktop.ini" is ignored when encrypting the containing directory with EFS.
    | The contents of this file are not verified to be that of a valid desktop.ini
    | file, instead it can contain anything. Any file dropped named desktop.ini
    | could avoid requiring decryption at a later date. Abuses of such an exclusion
    | are left as an exercise for the reader.

    Are you creating the desktop.ini before applying encryption to it's parent
    directory?

    I think you'll find in that case the "Folder Settings" directory and its
    contents are not encrypted either. As they're all set as system and hidden
    they don't show up unless you (for some reason) have Explorer set to show
    protected OS files.

    <Example one>

    C:\>mkdir test

    C:\>cipher /e test

    ~ Encrypting directories in C:\

    test [OK]

    1 directorie(s) within 1 directorie(s) were encrypted

    C:\>echo woo > test\file.txt

    C:\>echo yay > test\desktop.ini

    C:\>cipher test\*

    ~ Listing C:\test\
    ~ New files added to this directory will be encrypted.

    E desktop.ini
    E file.txt

    </Example one>

    The above example which shows that encryption *is* applied is also true if
    you create a directory, encrypt it, then apply directory customisations.

    <Example two>

    C:\>cipher /h test\*

    ~ Listing C:\test\
    ~ New files added to this directory will be encrypted.

    E desktop.ini
    E Folder Settings

    </Example two>

    Personally my best practise when it comes to EFS is to encrypt a folder
    before doing anything to it. That way you cannot forget to encrypt one of
    the files later etc.

    Regards,

    Adam Piggott.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (MingW32)

    iD8DBQFBj8027uRVdtPsXDkRAoJ+AJwJHALQyiw4CHa8WnivzuiCUoonJQCfVwod
    pGEmM4KdHIY/MdnZwhlKtpw=
    =HyPv
    -----END PGP SIGNATURE-----

    --
    Editor's Note: The 43rd Most Powerful Person in Networking says...
    Register today to take the TruSecure ICSA exam by 12/31/04  at
    <http://www.2test.com> ,  use promo code "CT1204" and you will pay just
    $221.25 US Dollars for domestic exam delivery and  $296.25 US Dollars
    for international delivery.
    Visit <https://ticsa.trusecure.com>  for complete details regarding the
    TICSA credential and to take the free sample exam.
    --
    

  • Next message: support_at_maedata.net: "possible regedit bulk key deletion vulnerability (Revised)"

    Relevant Pages

    • Re: Regarding Private key
      ... That way you can only encrypt and decrypt the message if you are in possession of the physical token and know the pin passphrase. ... Storing the AES key/IV in file is one option? ... InfoSec Institute's CISSP Boot Camp in both Instructor-Led and Online formats is the most concentrated exam prep available. ...
      (Security-Basics)
    • RE: Laptop Security - Microsoft EFS
      ... With EFS the keyare unique to the drive. ... EFS to encrypt system files. ... cleartext during a mount attack, but the easiest way for an attacker to gain ... who can also decrypt the respective persons info. ...
      (Security-Basics)
    • RE: EFS rollout using Active Directory
      ... I just have something to add to the Final Thought regarding laptop users: ... You can implement EFS on systems running Windows 2000 and Windows XP ... Stand-alone workstations generate their own public key certificate that you ... encrypt the contents of their files or folders. ...
      (Focus-Microsoft)
    • Re: VS2005 website deployment problems with EFS
      ... It is not WIndows EFS, but it does encrypt. ... publish website or copy website deployment methods without manually ... If I manual decrypt the files then the manual copy the files it is quick as ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: How can I share encripted files between two user accounts?
      ... Strong protection on keys doesn't work with EFS. ... Find the EFS recovery cert in the Personal store ... We just pick one of them to encrypt a file - there's no guarantee which one ... "George Valkov" wrote in message ...
      (microsoft.public.windows.server.security)