
Tool for checking passwords against TrueCrypt encrypted volumes and disks, and/or decrypting the data.
Released as open source by NCC Group Plc - http://www.nccgroup.com/
Developed by Richard Turnbull, richard [dot] turnbull [at] nccgroup [dot] com
http://www.github.com/nccgroup/untrue
Released under AGPL, see LICENSE for more information
Untrue is a tool for checking passwords against TrueCrypt encrypted volumes and disks, and/or decrypting the data.
Windows, with version 4.0 of the .NET Framework.
TCHead is a tool which also checks passwords against volume headers, but its website seems to be down, and in any case, it offers no capability to decrypt the data. Bjrn Edstrm released some Python code, which is effective at checking passwords, but has only limited decryption capabilities.
There are three different tasks you can perform using Untrue, and the usage is a bit different for each. Note that Untrue will try its best to intelligently determine the location of the volume header, and the location and size of the encrypted area. However, if this doesn't work, or you want more flexibility, there are options to control this.
Untrue.exe [general_options] --password_check_only -p passphrase (--volume_header_file=input_file | --volume_header_hex=hex_string) [algorithm_options] [password_checking_options]
You need to provide the volume header. Normally you would do this by specifying a file, using the --volume_header_file option (normally this file would be a TrueCrypt encrypted volume, an image of a TrueCrypt encrypted drive, or an image of a TrueCrypt Rescue CD).
However, you can also provide the volume header as a hex string (512 bytes long), with the --volume_header_hex option.
Untrue.exe [general_options] -i input_file -o output_file (-k hex_string | --key_file=file_containing_key) [algorithm_options] [decryption_options]
You need to provide the volume encryption key, either as a hex string (with the -k option) or by pointing to a file containing it (with the --key_file option).
You also need to specify an input file (i.e. the encrypted volume or drive) and an output file. Untrue will refuse to write to an existing output file (to avoid accidental overwrites).
Untrue.exe [general_options] -p passphrase -i input_file (--volume_header_file=input_file | --volume_header_hex=hex_string) -o output_file [password_checking_options] [algorithm_options] [decryption options]
You also need to specify an input file (i.e. the encrypted volume or drive) and an output file. Untrue will refuse to write to an existing output file (to avoid accidental overwrites).
If the volume header is not present in the input file (e.g. it's on a Rescue CD image), you can optionally specify the file containing the volume header (using --volume_header_file) or provide the volume header bytes (using --volume_header_hex). If you don't do either of these, the volume header will be read from the input file.
If the passphrase is wrong, decryption won't proceed.
-h, --help Show usage information and exit
-V, --version Show version and exit
-v, --verbose Verbose mode (verbose information written to standard output)
-d, --debug Debug mode (even more information written to standard output)
-q, --quiet Quiet mode (nothing written to standard output)
--volume_header_location=VALUE
Location of the volume header in the volume header file. Note that this is specified as the sector number, assuming a sector size of 0x200 bytes.
In most cases you should be safe to omit this option - Untrue will try to intelligently guess it if not specified. If no volume header file is specified (i.e. the volume header is in the input file) then Untrue will try to determine if the input file is an encrypted volume or encrypted drive image, and will set the volume header location accordingly. If a volume header file is specified, and appears to be a Rescue CD image, then the volume header location will again be set accordingly. Otherwise, the volume header location will default to 0.
You can specify the encryption algorithms to be attempted by Untrue (note that TrueCrypt offers various encryption algorithms, and there is no way to tell which has been used from inspection of an encrypted volume). When password checking, if none of the options below are specified, all of them will be tried. However, if any of the below options are specified, only these algorithms will be tried. When decrypting with a given key, if none of the options below are specified, TrueCrypt's default algorithm of AES will be used. Otherwise, if any one of the options below is specified (it is an error to select more than one), then that will be used. When decrypting based on a successful password check, the algorithm specified in the decrypted volume header will be used (regardless of any of the options below).
--aes Try AES encryption algorithm
--serpent Try Serpent encryption algorithm
--twofish Try Twofish encryption algorithm
--aes_twofish Try AES-Twofish encryption cascade
--aes_twofish_serpent Try AES-Twofish-Serpent encryption cascade
--serpent_aes Try Serpent-AES encryption cascade
--serpent_twofish_aes Try Serpent-Twofish-AES encryption cascade
--twofish_serpent Try Twofish-Serpent encryption cascade
--all_encryption_algorithms Try all encryption algorithms
You can specify the hash algorithms to be attempted by Untrue (note that TrueCrypt offers various hash algorithms, and there is no way to tell which has been used from inspection of an encrypted volume). When password checking, if none of the options below are specified, all of them will be tried. However, if any of the below options are specified, only these hash algorithms will be tried. Note that TrueCrypt uses a different number of PBKDF2 iterations for RIPEMD-160 when it is used for system (full-disk) encryption than when it is used for volume encryption. This is treated as two different hash algorithms by Untrue.
--ripemd160 Try RIPEMD-160 hash algorithm
--ripemd160_system Try RIPEMD-160 hash algorithm (system encryption)
--whirlpool Try Whirlpool hash algorithm
--sha512 Try SHA-512 hash algorithm
--all_hash_algorithms Try all hash algorithms
-e, --encrypt
Perform encryption instead of decryption. Only likely to be useful when the Rescue CD decryption operation has been (accidentally) run multiple times against a drive.
--first_decrypt_sector=VALUE
Sector number in input file where decryption should begin. In most cases you can omit this option. If it is not specified, Untrue will read the correct value from the decrypted volume header (if available) or will otherwise attempt to determine the correct value by checking if the input file appears to be an encrypted volume or encrypted drive.
--sectors_to_process=VALUE
Number of sectors to decrypt In most cases you can omit this option. If it is not specified, Untrue will read the correct value from the decrypted volume header (if available) or will otherwise attempt to determine the correct value by checking the length of the input file.