• 1 Post
  • 366 Comments
Joined 3 years ago
cake
Cake day: June 16th, 2023

help-circle











  • The process is dead simple: grab any USB stick, get write access to the “System Volume Information,” and copy into it the “FsTx” folder and its contents. Shift+click Restart to get Windows to the recovery environment, but then switch to holding down the Control key and don’t let go. The machine will reboot, and without asking any questions or showing any menus, will drop you in an elevated command line with full access to the formerly Bitlocked drive, without asking for any keys.

    Its dead simple to get write access to System Volume Information

    Not even local admins have access to it. A local admin would have to take ownership of that folder (not recommended), but if a local admin is doing that for this exploit, they can just turn off Bitlocker rather than go through this nonsense.

    I misunderstood the exploit. See replies.