파일시스템
2011.03.17 13:42

Issues with EFS

조회 수 1475 추천 수 0 댓글 0
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 수정 삭제
?

단축키

Prev이전 문서

Next다음 문서

크게 작게 위로 아래로 댓글로 가기 인쇄 수정 삭제

Issues with EFS

Temporary file is not erased. When EFS encrypts file, it copies its contents into temporary hidden file named Efs0.tmp in the same folder, as encrypting file. Then, it encrypts plain text by blocks and writes encrypted data into original file. After the process is done, temporary file is deleted. The problem is that EFS simply marks it as deleted without actually erasing its contents, which makes possible easy access to unprotected data by low-level data recovery software like Active@ Undelete. Solution - to wipe free disk space. Usually, even if plain text overwritten ones, small magnetic traces remain detectible, thus giving a chance to read erased data with proper equipment. To minimize this possibility, use commercially available software providing sophisticated data erasing algorithms like Active@ Eraser or ZDelete.NET or wipe unused volume and MFT space with Active@ KillDisk.

File names in encrypted folder are not protected. Actually, encrypting folder contents means automatically applying encryption to all files in the folder, not encrypting directory data itself. Since the file name itself could contain sensitive information, it could be a breach in security. One of the solutions would be using encrypted .zip archives instead of folders, which are treated by Windows XP almost like folders. Thus, only one file is needed to be encrypted and archived data themselves are harder to crack.

EFS security relies on public/private key pair which is stored on local computer. Windows protects all private keys by encrypting them through Protected Storage service. Protected Storage encrypts all private keys with Session Key, derived from 512 bit Master Key, and stores them in %User Profile%Application DataMicrosoftCryptoRSAUser SID. The Master Key is encrypted by Master Key Encryption Key, which is derived from user password by using a Password Based Key Derivation Function and stored in %User Profile%Application DataMicrosoftProtectUser SID. Despite the efforts Windows takes to protect keys, the fact, that all information is stored on local computer, gives an attacker, who's got an access to hard drive, a chance to figure out keys and use them to decrypt protected data. The overall security could be significantly enhanced by encrypting private keys with System Key. The syskey.exe utility can be used to store System Key on a floppy disk and remove it from computer. In this case user must insert a diskette with System Key when computer boots up. Nevertheless, this method should be taken with precautions since if key diskette is lost, there's no way to get access to computer.

?

  1. NTFS Optimization

    Date2011.03.17 Category파일시스템 Byadmin Views9388
    Read More
  2. NTFS vs FAT

    Date2011.03.17 Category파일시스템 Byadmin Views4183
    Read More
  3. Data Integrity and Recoverability with NTFS

    Date2011.03.17 Category파일시스템 Byadmin Views1489
    Read More
  4. NTFS Sparse Files (NTFS5 only)

    Date2011.03.17 Category파일시스템 Byadmin Views1659
    Read More
  5. Issues with EFS

    Date2011.03.17 Category파일시스템 Byadmin Views1475
    Read More
  6. $EFS Attribute

    Date2011.03.17 Category파일시스템 Byadmin Views1515
    Read More
  7. EFS Internals

    Date2011.03.17 Category파일시스템 Byadmin Views112687
    Read More
  8. Using EFS

    Date2011.03.17 Category파일시스템 Byadmin Views1589
    Read More
  9. EFS - Encrypting File System

    Date2011.03.17 Category파일시스템 Byadmin Views1565
    Read More
  10. NTFS Compressed Files

    Date2011.03.17 Category파일시스템 Byadmin Views1480
    Read More
  11. NTFS Multiple Data Streams

    Date2011.03.17 Category파일시스템 Byadmin Views1389
    Read More
  12. NTFS 시스템 파일

    Date2011.03.17 Category파일시스템 Byadmin Views1560
    Read More
  13. NTFS 파일속성

    Date2011.03.17 Category파일시스템 Byadmin Views1313
    Read More
  14. NTFS MFT 분석

    Date2011.03.17 Category파일시스템 Byadmin Views1434
    Read More
  15. NTFS 파티션 부트섹터

    Date2011.03.17 Category파일시스템 Byadmin Views2072
    Read More
  16. NTFS 기초

    Date2011.03.17 Category파일시스템 Byadmin Views1087
    Read More
  17. 레이드란?

    Date2011.03.17 Category서버/레이드 Byadmin Views1077
    Read More
  18. 맥사용시 주요장애원인과 대처

    Date2011.03.17 Category매킨토시 Byadmin Views1532
    Read More
  19. ATA/ATAPI-5 — the fifth revision of the ATA standard released in 2000

    Date2011.03.16 Category하드디스크 Byadmin Views1163
    Read More
  20. ATA/ATAPI-6 — the sixth revision of the ATA standard released in 2001

    Date2011.03.16 Category하드디스크 Byadmin Views1103
    Read More
Board Pagination Prev 1 2 3 4 5 6 Next
/ 6