RE: Is W2K EFS trivial to crack?

From: Potesta, David (David.Potesta@vw.com)
Date: 03/17/02


From: "Potesta, David" <David.Potesta@vw.com>
To: 'Kent James' <kent1@caspia.com>, Security-Basics <security-basics@securityfocus.com>
Date: Sun, 17 Mar 2002 08:32:20 -0600

Unless the laptop is a DC, the user account would not be on that machine so
one would be unable to change the EFS owner's password.

-----Original Message-----
From: Kent James [mailto:kent1@caspia.com]
Sent: Wednesday, March 13, 2002 9:56 PM
To: Security-Basics
Subject: Is W2K EFS trivial to crack?

In a recent thread here, it was reported how easy it is to gain access to
the administrator account on a W2K system. So in the stolen laptop with
EFS-encrypted files scenario, someone could just reset the administrator
account password, change the password of the user account, log on as that
user, then access all of the EFS-encrypted files.

Is this correct (which makes EFS useless as a file encryption scheme)?

+----------------+
  Kent James
  Kent@caspia.com
+----------------+



Relevant Pages

  • Re: Admin password wont work after restore point
    ... EFS is a bit trickier than it looks. ... I ended up booting the laptop in safe mode and resetting the admin password. ... whether the user was a local user account or a domain user even if they have ... The restore went ok, but now it doesn't like the password for the admin ...
    (microsoft.public.windowsxp.security_admin)
  • Re: NTFS File Encryption Question
    ... I am certainly no expert on EFS and the XP implementation, ... know it is tied to the SID of the user account in question. ... >>>What do I need to do to be able to access these files on my laptop? ...
    (microsoft.public.windowsxp.general)
  • RE: Is W2K EFS trivial to crack?
    ... > Unless the laptop is a DC, the user account would not be on that machine so one ... Microsoft saying that EFS does only work for domain members. ...
    (Security-Basics)
  • Re: Test Driving EFS - couple questions
    ... There is an interesting Wikipedia article on EFS, ... "Windows can store plaintext versions of user account passphrases, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Admin password wont work after restore point
    ... how they had years of data that was in EFS encrypted files and they had no ... The demo version will only recover small portion files but if it ... whether the user was a local user account or a domain user even if they ... The restore went ok, but now it doesn't like the password for the admin ...
    (microsoft.public.windowsxp.security_admin)