LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-05-2012, 11:59 PM   #1
jamendo10
LQ Newbie
 
Registered: May 2012
Posts: 8

Rep: Reputation: Disabled
photorec + .ecryptfs to restore files


I got myself in a bit of situation. In a poorly meditated event, I was trying to make some room on my ssd and I was using disk usage analyzer to interpret my volume. I saw that .ecryptfs folder was taking up "double" the space so I went ahead and deleted it. Later found out that disk usage analyzer is not a completely true indication of volume in regards to .ecryptfs. Turns out that everything in .ecryptfs is your actual stored data wrapped with encryption data to protect your data while your not logged in into your cpu. Ecryptfs continually decrypts the data while you read/write to files.

That being said, I learned all this after the fact that I permanently deleted my files. Devastated. lol. So I promise from here to invest in back-up technology.

I ended up using photorec to recover 20 gigs of my ssd. Within the 20 gigs I have f*.eCryptfs files that I would like to decrypt. I have my passphrase.

I was wondering if this has been done before? if so how?
 
Old 08-06-2012, 11:33 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Maybe with ecryptfs-recover-private?
http://blog.dustinkirkland.com/2011/...r-private.html
http://bodhizazen.net/Tutorials/Ecryptfs/#Live
 
Old 08-07-2012, 01:25 AM   #3
jamendo10
LQ Newbie
 
Registered: May 2012
Posts: 8

Original Poster
Rep: Reputation: Disabled
I went ahead and tried ecryptfs-recover-private. I was able to successfully mount the directory with my *.eCryptfs files however they were not decrypted but simply just duplicated onto the /tmp/ecryptfs.#######/ directory. ecryptfs-recover-private does require that all folders and symlinks be organize/setup as ecryptfs-setup-private would. I may have a folder/file configuration that does not allow ecryptfs-recover-private to decrypt. I need to read more about how ecryptfs-recover-private works. If I do not come up with anything else I will attempt to run ecryptfs-setup-private, add the *.ecryptfs files i recovered with photorec and then ecryptfs-recover-private.

Not sure how else to go about it. I am a bit afraid that I will lose necessary configuration if a go about using ecryptfs-setup-private because it may require overwriting the current seemingly half broken setup.

Also, looking at the second website: http://bodhizazen.net/Tutorials/Ecryptfs/#Live

See below @ <<<<<<<<<<
Code:
ubuntu@ubuntu:~$ sudo mount /dev/sda1 /mnt

ubuntu@ubuntu:~$ sudo ecryptfs-recover-private
INFO: Searching for encrypted private directories (this might take a while)...
INFO: Found [/mnt/home/.ecryptfs/cryptotheslow/.Private].
Try to recover this directory? [Y/n]: Y
INFO: Found your wrapped-passphrase
Do you know your LOGIN passphrase? [Y/n] Y
INFO: Enter your LOGIN passphrase...
Passphrase: 
Inserted auth tok with sig [fa0516369a9d60dd] into the user session keyring <<<<<< this line of never appears for me
INFO: Success!  Private data mounted read-only at [/tmp/ecryptfs.yxyLYWVG].

ubuntu@ubuntu:~$ gksu nautilus /tmp/ecryptfs.yxyLYWVG

Last edited by unSpawn; 08-07-2012 at 06:23 AM. Reason: //Merge, BB code tags
 
Old 08-07-2012, 05:45 AM   #4
jamendo10
LQ Newbie
 
Registered: May 2012
Posts: 8

Original Poster
Rep: Reputation: Disabled
So i have found a solution to this problem! Hope this helps others!

http://www.kubuntuforums.net/archive...p/t-58140.html


Invest in backups. Enough said.

Last edited by jamendo10; 08-07-2012 at 05:52 AM.
 
1 members found this post helpful.
Old 08-07-2012, 06:24 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Thanks for posting your solution.


Quote:
Originally Posted by jamendo10 View Post
Invest in backups. Enough said.
Still a shame people need to find out the hard way though...
 
  


Reply

Tags
decryption, ecryptfs, photorec, recovery, ubuntu 12.04



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Using PhotoRec - Recovers 30+ GB files ... plarser46 Linux - Software 5 03-28-2010 09:21 PM
[ECRYPTFS] ecryptfs_init_miscdev: Error whilst attempting to open [/dev/ecryptfs] nitinarora Linux - Kernel 0 03-22-2010 05:36 AM
How to remove multiple Photorec files (recup_dir.) ausber71 Linux - Newbie 2 01-14-2010 12:12 PM
LXer: Recover deleted files in linux with Photorec LXer Syndicated Linux News 0 10-12-2009 09:41 AM
recover directories & files from ext. HDD using testdisk or photorec esteeven Linux - Hardware 1 11-13-2008 10:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration