Apr 14, 2023 / By Wael Alnahari / in Digital ForensicsCybersecurity
./EIFT_cmd boot -w
./EIFT_cmd ramdisk diskdump -o data.dmg
[Error] [!] Data partition is in an unclean state, please run fsck first to fix potential inconsistencies! Alternatively pass --unclean, to ignore this and proceed with dumping anyways!
./EIFT_cmd ramdisk diskdump --unclean -o data.dmg
./EIFT_cmd ramdisk diskdump --system -o system.dmg
./EIFT_cmd ramdisk dumpkeys -n -o keys_bfu.plist
./EIFT_cmd hfstool -i data.dmg -p /keybags/systembag.kb -e -o systembag.kb -k keys_bfu.plist --no-passcode
head -c 6 systembag.kb | hexdump -C
00000000 62 70 6c 69 73 74 |bplist| 00000006
./EIFT_cmd ramdisk passcode -b systembag.kb -k keys_bfu.plist
./EIFT_cmd ramdisk dumpkeys -k keys_bfu.plist -b systembag.kb -o keys.plist -p
./EIFT_cmd ramdisk dumpkeys -k keys_bfu.plist -b systembag.kb -o keys.plist -p 0000
./EIFT_cmd tools decrypthfs -i data.dmg -o data_dec.dmg -k keys.plist -j 16
./EIFT_cmd tools keychain -i data.dmg -k keys.plist -o keychain.xml
May 31, 2024 by Wael Alnahari
May 15, 2024 by Wael Alnahari
WGN | وغن