FileVault2 with extracted keybag from Apple T2 chip
#2
Hi,

I'm struggling with the same problem.

I guess that you successfully got the root sheel into T2 by relying on the checkm8 + blackbird vulnerability.
I also copied easily with scp the systembag.kb but I'm still struggling with the extraction of IV and payload key from Effaceable Storage to decrypt the keybag. Any suggestions?

I tried the tool from https://github.com/russtone/systembag.kb but it didn't work for me.

Sincerely,
gostep
Reply


Messages In This Thread
RE: FileVault2 with extracted keybag from Apple T2 chip - by gostep - 01-29-2021, 07:56 PM