Download Macintosh Forensics
Transcript
rev. May 29, 2007 Create a Brute Force Dictionary File The MacOS X Terminal makes it rather easy to create a brute force dictionary for attacking various encoded files. It certainly isn’t a guarantee, but it offers hope. Creating this dictionary is useful when the source is not encrypted. For instance, if you try to make a dictionary file from a sparseimage file, you will get nothing useful. However, making a dictionary from the entire device may yield the password to a user’s login, a website, their keychain, and so-on. The terminal command “strings” can create a text file with the useful words contained in a file or raw device. The MAN entry for “strings” is as follows: strings - find the printable strings in a object, or other binary, file We can use this against a device file such as /dev/disk0 or against an unencrypted DMG file such as /Evidence/sample.dmg and have a text file created with the useful strings. The command would look like this: Moofs-House:~ moof$ strings /Evidence/UnencryptedDMG.dmg > /Evidence/strings.txt This command will output a text file that contains all of the useful strings contained in the DMG file. You can now use this file as a “dictionary” in a brute force attack on passwords. It might be further useful to take the repeated strings out of this file. 58 of 72