{"id":549,"date":"1999-04-22T18:51:12","date_gmt":"1999-04-22T18:51:12","guid":{"rendered":"https:\/\/anti-forensics.com\/blog\/?p=549"},"modified":"2024-04-23T18:33:44","modified_gmt":"2024-04-23T18:33:44","slug":"modify-truecrypt-encryption-boot-loader-strings","status":"publish","type":"post","link":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/","title":{"rendered":"Modify TrueCrypt Encryption Bootloader Strings"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Requirements<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hex editor such as WinHex<\/li>\n\n\n\n<li>A hard disk that has been encrypted with TrueCrypt full disk encryption<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In a&nbsp;<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/?p=3\" target=\"_blank\" rel=\"noreferrer noopener\">previous post<\/a>&nbsp;I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/wp-content\/uploads\/2009\/03\/winhex-truecrypt-shrunk.jpg\"><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Modified TrueCrypt Boot Loader<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This quick edit takes about ten second to complete. Just open the boot disk with a hex editor and modify the string.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you don\u2019t understand what I\u2019ve done then here are the steps:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Open the TrueCrypt encrypted hard disk (physical disk) with a hex editor<\/li>\n\n\n\n<li>Locate the TrueCrypt boot loader at the \u201cstart\u201d of the hard drive (in sector 0)<\/li>\n\n\n\n<li>Use a hex editor to overwrite the \u201cTrueCrypt Boot Loader\u201d string<\/li>\n\n\n\n<li>Save changes<\/li>\n\n\n\n<li>Boot from the disk to make sure you haven\u2019t messed up the boot loader<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>So what does this mean?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many computer forensic examiners will probably not realize what they\u2019re looking at if they actually do take a look at the boot loader. Removing this string ensures that they\u2019re kept in the dark. That is unless they do their own digging around and can figure out that the instructions in sector 0 are in fact part of a TrueCrypt boot loader.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is plenty of other code in the boot loader. I\u2019m sure patterns in this data can giveaway the fact that the disk has been encrypted with TrueCrypt. I have not researched it and I have not attempted to figure out what this other data actually means, is or does. You should be fine modifying the strings in the boot loader though.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You will want to keep the strings at their original length so as not to mess up code\/instructions in other parts of the loader as well. If you start over-writing other code in the boot loader that is not a string, you are probably modifying instructions which will most likely cause boot failure or the loader to crash.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is another one of those anti-forensic methods that\u2019s not real strong but it gets rid of the word \u201cTrueCrypt\u201d from the drive which would be a dead giveaway to most examiners that TrueCrypt could have been used to encrypt the hard drive (I would hope so anyways). I\u2019ve ran a keyword search in EnCase forensic software as well as other software to verify that there is no other reference to the name TrueCrypt on the fully encrypted disk. There were no other hits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If there are any papers written on the construction of the TrueCrypt loader or if you\u2019ve done your own research on this then please share what you\u2019ve found. I as well as others will be very interested.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">old comments:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/blog.banditdefense.com\/\">Micah<\/a><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-9\">March 2, 2009 at 3:44 am<\/a>Nice idea. I like that there\u2019s someone else out there looking at the boot sector of a TrueCrypt Windows system encryption drive. I\u2019m currently trying to develop an proof-of-concept exploit to bypass TrueCrypt system encryption, if you\u2019re interested in helping at all. Check out my first post about it at my blog:\u00a0<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/blog.banditdefense.com\/2009\/03\/02\/attacking-truecrypt-part-1-the-vulnerability\/\">http:\/\/blog.banditdefense.com\/2009\/03\/02\/attacking-truecrypt-part-1-the-vulnerability\/<\/a><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=9#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Hans Henrik<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-16\">March 11, 2009 at 12:31 am<\/a>isnt TrueCrypt open source? \u2013 yes it is.<br>technically, nuf said :pyou could just modify the name\/boot procedures abit by source, if you got the compiler\/libsmuch easier, and much safer (as you pointed out, messing with it in hex is likely to mess with every single jmp\/cmp instructions..)<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=16#respond\">REPLY<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/\">Yar<\/a><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-17\">March 11, 2009 at 8:23 pm<\/a>I\u2019m looking forward seeing more of your work on bypassing\/exploiting the truecrypt header Micah.Great idea Hans!I may do something like that for each version that comes out and re-upload the binary here as well as the sourcecode. If that\u2019s allowed in the license anyways.If anyone else does this or something similar, please share here in the comments section.<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=17#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Myforwik<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-199\">March 3, 2010 at 7:11 pm<\/a>I have done extensive research on the Truecrypt boot loader.From your screenshot of the HEXs editor I can tell that you were running truecrypt 6.1a. Changing that 1 line of text fools no one.You have to realise that the truecrypt boot loader takes up sectors 1 to 63 of the harddisk \u2013 and it is not encrypted.The only way you can really hide truecrypt is to delete your first 63 sectors and use the rescue disk to boot your PC every time you boot up.The strings for the main loggin screen aren\u2019t encrypted. They are simple compressed. If you copy from 0xA00 to about 0\u00d73700 into a file, you can open it, as its a zip file, then all the truecrypt strings that you see on the login screen are available for everyone to see.<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=199#respond\">REPLY<\/a>\n<ul class=\"wp-block-list\">\n<li>Max (Admin)<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-200\">March 3, 2010 at 8:33 pm<\/a>Great information Myforwik!I currently cannot confirm or deny your claims but if you could point the readers to some documentation on that it would be great.It would make a great addition to the article or a secondary article, with props to you of course.<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=200#respond\">REPLY<\/a><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Lars<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-201\">March 4, 2010 at 9:32 pm<\/a>Myfor how is it you are extracting or uncompressing the data?<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=201#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Max (Admin)<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-202\">March 4, 2010 at 9:38 pm<\/a>Here it is uncompressed, I setup a test environment with the latest TrueCrypt version and a Windows XP system in VMWare. It is the last 460 bytes after uncompressing the offsets that Myforwik provided. Bravo Myforwik, I had stopped all research on Truecrypt so this is some exciting information for me, even if it might be public or widely known now. I don\u2019t know if it is but props to Myforwik for the info.Error: .Write.Read.. error:. Drive:. Sector:.. CHS:. MB ..Drive .. not found: \u2026.No bootable partition found. TrueCrypt Boot Loader 6.3a\u2026 Keyboard Controls:\u2026. [Esc] .Boot Non-Hidden System (Boot Manager).Skip Authentication (Boot Manager)..? (y\/n): .y\u2026n\u2026[.] .[Esc] Cancel\u2026..Enter password.. for hidden system:\u2026: ..Booting\u2026\u2026.BIOS reserved too much memory: .- Upgrade BIOS..- Use a different motherboard model\/brand\u2026Warning: Caps Lock is on\u2026.Incorrect password\u2026\u2026If you are sure the password is correct, the key data may be damaged. Boot your..TrueCrypt Rescue Disk and select \u2018Repair Options\u2019 > \u2018Restore key data\u2019\u2026\u2026.Bootable Partitions:\u2026.Drive: ., Partition: ., Size: ..Press 1-9 to select partition: .Your BIOS does not support large drives. due to a bug\u2026- Enable LBA in BIOS\u2026.Copying system to hidden volume. To abort, press Esc\u2026\u2026.If aborted, copying will have to start from the beginning (if attempted again)\u2026..Abort.To fix bad sectors: 1) Terminate 2) Encrypt and decrypt sys partition 3) Retry\u2026..Remaining: \u2026Copying completed..MMAP: ..Memory corrupted.. \u00e8..PAMSC\u2019mon TrueCrypt, this isn\u2019t cool\u00a0<img decoding=\"async\" src=\"https:\/\/web.archive.org\/web\/20120622150850im_\/http:\/\/www.anti-forensics.com\/wp-includes\/images\/smilies\/icon_razz.gif\" alt=\":P\"><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=202#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Max (Admin)<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-203\">March 4, 2010 at 9:55 pm<\/a>I guess what probably needs to happen to do anything serious is to just start going through the TrueCrypt source code as Hans had suggested.I\u2019m currently in the process of \u201cmodernizing\u201d the site with a new theme and I\u2019ve a ton of other projects ongoing so I\u2019ve no time to come up with a way to get rid of these strings.I mean the simple option would probably be to modify the source and rebuild (truecrypt binary) but it would be cool to have some process of editing this data, compressing it all again and then adding it back to the boot loader.Also, Lars, here is the process I went through. There are probably better methods but this is what worked for me:<ul><li>1. Using HXD hex editor copy out the data between the offsets myforwik mentions and save to a file.<\/li><li>2. Extract the data using 7-zip, you\u2019ll have to force it<\/li><li>3. Open the extracted data and the last 460 bytes should be these extra strings<\/li><\/ul><a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=203#respond\">REPLY<\/a><\/li>\n\n\n\n<li>myforwik<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-205\">March 12, 2010 at 4:07 pm<\/a>Its not exactally to 0\u00d73700,If you go to address 0x1B0 there is a two byte integer that is the size of the file.<br>So if you read those two bytes (in version 6.3a it is usually 0\u00d797 0x2D = 0x2D97 = 11671 bytes. And the bytes start at 0xA00.The file format is actually gzip, which is openable by most zip programs including windows zip folders etc.Unfortuently if you edit the strings and re-zip, and save it back to 0xA00 it won\u2019t work, because there is a checksum at 434d. Thats why I wrote a program.<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=205#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Ammie<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-240\">May 23, 2010 at 5:18 pm<\/a>Hi!1. Create Truecrypt rescue disc.<br>2. Use Winhex application to erase sector 1 to 63.<br>3. Then, you are required to use Truecrypt Rescue Disc each PC start.Question:<br>1. Erasing sector 1 to 63 once is enough?<br>2. Anything to erase\/remove\/modify aside from Truecrypt boot loader, disregarding network\/server tracks?<br>3. Is there anyone can verified that this is 100% false-positive, even from new\/updated forensic application?<br>4. How about Truecrypt volume tracks?Thanks for reply.<br>-am<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=240#respond\">REPLY<\/a><\/li>\n\n\n\n<li>LAR<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-250\">June 11, 2010 at 6:53 pm<\/a>Truecrypt is great and stable.Truecrypt drived by the features and marketing strategies.<br>Then People and IT Pros like it.<br>They just don\u2019t care if it is 100% safe.But any security product which is not 100% open sourced is very dangerous for keeping very sensitive data on your expensive laptop or your super tiny usb flash disk.We can\u2019t prove that it is really safe if we do not have the complete source code and a certification.Imagine have sex with someone you don\u2019t really know.<br>Then 1 week later you are positive.Forum is not also open to anyone.I believe any security free\/open source products should be certified (not recognized) as 100% safe (certified (not by anyone but by a legit institution like NIST)If i am working on the goverment.<br>Should I tell anyone that the conspired product gave us backdoor on it.<br>If i am one of the developer.<br>Should i tell anyone that i created a personal backdoor on it.LAR<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=250#respond\">REPLY<\/a><\/li>\n\n\n\n<li>sub<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-290\">September 1, 2010 at 2:00 pm<\/a>If an expert hacker access my drive whether in person or over the net, could he modify the boot loader (or extend the size if need be) to insert a keylogger (still keeping the TC boot screen intact) that would load a NIC driver then transmit the password over the net, therefore, compromising the use of TC encryption? or would the checksum defeat the extension and modification of the boot loader?<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=290#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Scizor<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-350\">October 29, 2010 at 9:16 am<\/a>Tried more than once, the strings change on the HEX code but on the boot they keep the same\u2026 Any help here?<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=350#respond\">REPLY<\/a><\/li>\n\n\n\n<li>emily<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-352\">October 30, 2010 at 6:10 am<\/a>LAR i agree for what you\u2019d said. Especially the last four line.Other things is even the source code is 100% provided and reviewed\/analyzed by the best coder and most notorious hacker in the world, maybe they already seen the hole and patched it themselves and they don\u2019t inform anyone.<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=352#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Joaquin<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-392\">December 27, 2010 at 9:08 am<\/a>HelloI created a File container with a keyfile in an external HD partition. (78 GB of data encrypted)Everything was fine until I changed the name of my file container. Since then I can not mount. It shows an error message \u201cIncorrect password or not a TrueCrypt volume.. \u201d I put back the original name and get the same error messageI did not create any backup head, I do not think there was any problem, simply renaming the file and now I\u2019m going crazy because of the importance of the documentsI exposed this case in forum of Truecrypt, one member of this forum says \u201cyou can always look at the file using a hex editor such as WinHex, with special emphasis on the locations of the headers, to see if anything looks amiss\u201d but I have no information or help, I tried to open the container file with this program but do not understand nothing.Can you help, please?I use Truecrypt 7 and Windows XP<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=392#respond\">REPLY<\/a><\/li>\n\n\n\n<li>Joaquin<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-393\">December 27, 2010 at 9:12 am<\/a>Sorry\u2026<br>I forgot to say that I tried to recover the embedded header file \u201cUse backup header embedded in volume if avariable\u201d but I keep seeing the same error message<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings?replytocom=393#respond\">REPLY<\/a><\/li>\n\n\n\n<li>felixk<a href=\"https:\/\/web.archive.org\/web\/20120622150850\/http:\/\/www.anti-forensics.com\/modify-truecrypt-encryption-boot-loader-strings\/comment-page-1#comment-933\">June 27, 2011 at 7:40 am<\/a>Hiding the fact that you are using Truecrypt is not the answer. If you want to hide your \u2018real\u2019 true crypt volume then use a hidden volume, which uses stenography. The real problem with the Truecrypt bootloader being unencrypted is that it can be completely an utterly replaced(cracked) with ones own code that does something like copy the user\/s keys as they type them in. This was first presented by Joanna Rutkowska founder and CEO of Invisible Things Lab, at a White hat conference. The only way to allow the use of an encrypted bootloader to my knowledge is with the use of a hardware component that decrypts and has checks etc\u2026 the bootloader everytime. The hardware component sets up a secure way of entering the users key and using the truecrypt bootloader. This is sort of what a TPM chip does. Of course TPM is not secure enough if you have the resources of an organisation like the NSA who can literally crack your CPU with an electron microscope and lithography machine. It is safe to say that there is no real total security yet. If your anything but a so called terrorist that the NSA( i.e. the US governemnt i.e. a mega corp) absoutely wants to \u2018get\u2019 then there are plenty of secure solutions. But then if you are wanted that badly then normal option is to send in the CIA or something equivalent and use what is called the rubber mallet decryption method or the bullet-in-the head method. For all those want a superb source of information on computer security, cryptography and the like then look no further than Bruce Schneier\u2019s resources like one of his many books or his Cryptograms.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d<\/p>\n","protected":false},"author":1,"featured_media":551,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[29,91],"class_list":["post-549","post","type-post","status-publish","format-standard","has-post-thumbnail","category-blog","tag-encryption","tag-truecrypt"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Modify TrueCrypt Encryption Bootloader Strings - Anti-Forensics.com<\/title>\n<meta name=\"description\" content=\"In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Modify TrueCrypt Encryption Bootloader Strings - Anti-Forensics.com\" \/>\n<meta property=\"og:description\" content=\"In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d\" \/>\n<meta property=\"og:url\" content=\"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/\" \/>\n<meta property=\"og:site_name\" content=\"Anti-Forensics.com\" \/>\n<meta property=\"article:author\" content=\"https:\/\/facebook.com\/stercutis\" \/>\n<meta property=\"article:published_time\" content=\"1999-04-22T18:51:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-23T18:33:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/04\/anti-forensics.com-truecrypt.png\" \/>\n\t<meta property=\"og:image:width\" content=\"512\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Max\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Max\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/\"},\"author\":{\"name\":\"Max\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/person\\\/ac3dd160cb42b1409a2a55dea58beec2\"},\"headline\":\"Modify TrueCrypt Encryption Bootloader Strings\",\"datePublished\":\"1999-04-22T18:51:12+00:00\",\"dateModified\":\"2024-04-23T18:33:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/\"},\"wordCount\":2278,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/anti-forensics.com-truecrypt.png\",\"keywords\":[\"encryption\",\"truecrypt\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/\",\"name\":\"Modify TrueCrypt Encryption Bootloader Strings - Anti-Forensics.com\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/anti-forensics.com-truecrypt.png\",\"datePublished\":\"1999-04-22T18:51:12+00:00\",\"dateModified\":\"2024-04-23T18:33:44+00:00\",\"description\":\"In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#primaryimage\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/anti-forensics.com-truecrypt.png\",\"contentUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/anti-forensics.com-truecrypt.png\",\"width\":512,\"height\":512},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/modify-truecrypt-encryption-boot-loader-strings\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Modify TrueCrypt Encryption Bootloader Strings\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/\",\"name\":\"Anti-Forensics.com\",\"description\":\"Rendering Digital Investigations Irrelevant\",\"publisher\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#organization\",\"name\":\"Anti-Forensics.com\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cropped-anti-forensics.com_.jpg\",\"contentUrl\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/cropped-anti-forensics.com_.jpg\",\"width\":512,\"height\":512,\"caption\":\"Anti-Forensics.com\"},\"image\":{\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/groups\\\/14345620\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/#\\\/schema\\\/person\\\/ac3dd160cb42b1409a2a55dea58beec2\",\"name\":\"Max\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g\",\"caption\":\"Max\"},\"description\":\"Anti-forensics involves attempts to hide data, damage the confidentiality, integrity, and availability of data in an effort to make analysis and examination of this data (evidence) difficult or impossible.\",\"sameAs\":[\"https:\\\/\\\/anti-forensics.com\\\/blog\",\"https:\\\/\\\/facebook.com\\\/stercutis\",\"https:\\\/\\\/linkedin.com\\\/in\\\/jesse-shelley\"],\"url\":\"https:\\\/\\\/anti-forensics.com\\\/blog\\\/author\\\/realjesseshelley_hkwwlra2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Modify TrueCrypt Encryption Bootloader Strings - Anti-Forensics.com","description":"In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/","og_locale":"en_US","og_type":"article","og_title":"Modify TrueCrypt Encryption Bootloader Strings - Anti-Forensics.com","og_description":"In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d","og_url":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/","og_site_name":"Anti-Forensics.com","article_author":"https:\/\/facebook.com\/stercutis","article_published_time":"1999-04-22T18:51:12+00:00","article_modified_time":"2024-04-23T18:33:44+00:00","og_image":[{"width":512,"height":512,"url":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/04\/anti-forensics.com-truecrypt.png","type":"image\/png"}],"author":"Max","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Max","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#article","isPartOf":{"@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/"},"author":{"name":"Max","@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/person\/ac3dd160cb42b1409a2a55dea58beec2"},"headline":"Modify TrueCrypt Encryption Bootloader Strings","datePublished":"1999-04-22T18:51:12+00:00","dateModified":"2024-04-23T18:33:44+00:00","mainEntityOfPage":{"@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/"},"wordCount":2278,"commentCount":0,"publisher":{"@id":"https:\/\/anti-forensics.com\/blog\/#organization"},"image":{"@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#primaryimage"},"thumbnailUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/04\/anti-forensics.com-truecrypt.png","keywords":["encryption","truecrypt"],"articleSection":["Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/","url":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/","name":"Modify TrueCrypt Encryption Bootloader Strings - Anti-Forensics.com","isPartOf":{"@id":"https:\/\/anti-forensics.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#primaryimage"},"image":{"@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#primaryimage"},"thumbnailUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/04\/anti-forensics.com-truecrypt.png","datePublished":"1999-04-22T18:51:12+00:00","dateModified":"2024-04-23T18:33:44+00:00","description":"In a\u00a0previous post\u00a0I mentioned that TrueCrypt leaves behind a string in its boot loader (that identifies it as a TrueCrypt boot loader) when using the full disk encryption feature. As you can see in the screenshot below I have modified the original \u201cTrueCrypt Boot Loader\u201d string to read \u201cWindows Boot Loader.\u201d","breadcrumb":{"@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#primaryimage","url":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/04\/anti-forensics.com-truecrypt.png","contentUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/04\/anti-forensics.com-truecrypt.png","width":512,"height":512},{"@type":"BreadcrumbList","@id":"https:\/\/anti-forensics.com\/blog\/modify-truecrypt-encryption-boot-loader-strings\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/anti-forensics.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Modify TrueCrypt Encryption Bootloader Strings"}]},{"@type":"WebSite","@id":"https:\/\/anti-forensics.com\/blog\/#website","url":"https:\/\/anti-forensics.com\/blog\/","name":"Anti-Forensics.com","description":"Rendering Digital Investigations Irrelevant","publisher":{"@id":"https:\/\/anti-forensics.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/anti-forensics.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/anti-forensics.com\/blog\/#organization","name":"Anti-Forensics.com","url":"https:\/\/anti-forensics.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/01\/cropped-anti-forensics.com_.jpg","contentUrl":"https:\/\/anti-forensics.com\/blog\/wp-content\/uploads\/2024\/01\/cropped-anti-forensics.com_.jpg","width":512,"height":512,"caption":"Anti-Forensics.com"},"image":{"@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/groups\/14345620\/"]},{"@type":"Person","@id":"https:\/\/anti-forensics.com\/blog\/#\/schema\/person\/ac3dd160cb42b1409a2a55dea58beec2","name":"Max","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7ca31cae39a49ab947496651bc5c75ee545a72f31c02db1a5c31f80b28714601?s=96&d=mm&r=g","caption":"Max"},"description":"Anti-forensics involves attempts to hide data, damage the confidentiality, integrity, and availability of data in an effort to make analysis and examination of this data (evidence) difficult or impossible.","sameAs":["https:\/\/anti-forensics.com\/blog","https:\/\/facebook.com\/stercutis","https:\/\/linkedin.com\/in\/jesse-shelley"],"url":"https:\/\/anti-forensics.com\/blog\/author\/realjesseshelley_hkwwlra2\/"}]}},"_links":{"self":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts\/549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/comments?post=549"}],"version-history":[{"count":2,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts\/549\/revisions"}],"predecessor-version":[{"id":552,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/posts\/549\/revisions\/552"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/media\/551"}],"wp:attachment":[{"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/media?parent=549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/categories?post=549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anti-forensics.com\/blog\/wp-json\/wp\/v2\/tags?post=549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}