Home  
  Microsoft  
  Cisco  
  CompTIA  
  CWNP  
  InfoSecurity  
  Forums  
  Blogs  
  Topsites  
  Watch free videos online  
     
  Subnet Calculator  
  Online Degrees  
  Exam Vouchers  
  Free Magazines  
     

  Watch free videos online  
   

 

Register Practice Exams TechNotes Members List Search Today's Posts Mark Forums Read
Go Back   TechExams.net IT Certification Forums > General > Off-Topic
Reply
 
Thread Tools
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 07-03-2009, 03:34 PM   #1 (permalink)
Default calling all PoSh gurus encrypt question..?

Hey PoSh gurus,

with the encryption on a PoSh file to run them, does the encryption on the file hide all the code and text from anything but the Posh Environment? or to what extent....I have some programs/scripts I have built that I would like to change to PoSh so it can hide the passwords that I have used in some of my scripts...vs text only file easily readable by spyware. Is this possible with PoSh?



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote

Login/register to remove this advertisement.
Senior Member
Registered Member
 
HeroPsycho's Avatar
 
Join Date: Jan 2008
Posts: 1,813

Certifications: MCITP: EA, EMA; MCSE 2000/2003: M; MCSE 2000: S; MCSA 2000/2003: S; MCTS: ISA 2006; VCP3/4
HeroPsycho is a jewel in the roughHeroPsycho is a jewel in the roughHeroPsycho is a jewel in the roughHeroPsycho is a jewel in the rough
Old 07-03-2009, 03:37 PM   #2 (permalink)

It is possible with Posh to encrypt the credentials natively, but it is security through obscurity level encryption, not industrial strength. If someone got ahold of the encrypted blob, they would easily be able to get the passwords out.

http://www.leeholmes.com/blog/Import...owerShell.aspx



__________________
Next up, EMC storage!

HeroPsycho is offline   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 07-03-2009, 03:56 PM   #3 (permalink)

HeryPsycho

hey thanks for the article.I appreciate your insight. You would think they would have a file that is shared by many scripts (i like that idea) that is decrypted for the password each time say program required it as a norm..that is cool if I can encrypt it with something. I wish some of my commands could just run on a the machine as admin but they don't...they need that dam n password that is senstive..hum!?
I guess some encryption is better than none...thanks man!



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote
Senior Member
Registered Member
 
HeroPsycho's Avatar
 
Join Date: Jan 2008
Posts: 1,813

Certifications: MCITP: EA, EMA; MCSE 2000/2003: M; MCSE 2000: S; MCSA 2000/2003: S; MCTS: ISA 2006; VCP3/4
HeroPsycho is a jewel in the roughHeroPsycho is a jewel in the roughHeroPsycho is a jewel in the roughHeroPsycho is a jewel in the rough
Old 07-03-2009, 04:32 PM   #4 (permalink)

Might consider invoking the script with a scheduled task using a bat file that invokes Powershell.exe and the script.



__________________
Next up, EMC storage!

HeroPsycho is offline   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 07-03-2009, 04:36 PM   #5 (permalink)

Rob Costello : Powershell Tip - Storing and Using Password Credentials

Master-PowerShell | With Dr. Tobias Weltner - PowerShell.com



dude found this link..and your idea of running it from a scheduled task is good tooo..for the encryption good idea...

yeah what sucks is nowadays sha1 2 and md5 can be cracked haha
I am sure you have seen it like I have in some CeH snippet courses hee hee...I was hoping PoSh would use SSL to encrypt its credentials.;(



__________________
itdaddy

"...so many toys....so little time!"


Last edited by itdaddy; 07-03-2009 at 04:41 PM.
itdaddy is offline   Reply With Quote
was here.
Registered Member
 
Join Date: Apr 2008
Location: UK
Posts: 2,805

tiersten is a glorious beacon of lighttiersten is a glorious beacon of lighttiersten is a glorious beacon of lighttiersten is a glorious beacon of lighttiersten is a glorious beacon of light
Old 07-03-2009, 04:48 PM   #6 (permalink)

Quote:
Originally Posted by itdaddy View Post
Rob Costello : Powershell Tip - Storing and Using Password Credentials
I wouldn't rely on that to secure any important passwords.

Quote:
Originally Posted by itdaddy View Post
yeah what sucks is nowadays sha1 2 and md5 can be cracked haha
SHA-1 and MD5 have both been shown to be vulnerable to collisions with examples. SHA-2 is only mathematically proven to be vulnerable to similar techniques used on SHA-1.

They're hash functions anyway. They're not used to encrypt.

Quote:
Originally Posted by itdaddy View Post
I was hoping PoSh would use SSL to encrypt its credentials.
SSL and TLS are protocols to handle encryption of network connections. They're not encryption algorithms themselves.

tiersten is online now   Reply With Quote
Senior Member
Registered Member
 
itdaddy's Avatar
 
Join Date: Jan 2006
Posts: 1,106

Certifications: A+, CCNA, MCP
itdaddy will become famous soon enough
Old 07-03-2009, 09:12 PM   #7 (permalink)

tiersten

what would you suggest? I thought powershell was suppose to be this super secure CLI???

thanks..I need to do some looking into what each does sha1, sha2, md5 ssl /tls etc.... I just know when I was watching Winstructor videos he used SHA1 for something ? in power shell scripts along with the makecert.exe program...
need to brush up on all this Sec+ .. I know enough to be dangerous hee hee
thanks



__________________
itdaddy

"...so many toys....so little time!"

itdaddy is offline   Reply With Quote
Bookmarks
Go Back TechExams.net IT Certification Forums > General > Off-Topic
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT. The time now is 05:07 PM.

 
 
Featured Sponsors

TrainSignal - “Hands On” computer training for IT professionals. Network+ Training, MCSE, Cisco & more! Visit Train Signal’s free training site to get loads of Free Computer Training, videos, articles and practice exams.

Preplogic - Sign up now to get Unlimited Access to PrepLogic's entire video training library. Enjoy open access to Microsoft Server 2008, CCNA, CISSP®, PMP and many more. Get Unlimited Access

 

Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
TechExams.net 2009