└── README.md /README.md: -------------------------------------------------------------------------------- 1 | # Multipass 2 | Multipass is a reference tool intended for researchers to demonstrate how to extract secrets from locked password managers on the Windows platform. 3 | 4 | Terminology: 5 | A password manager exists in 3 possible states: 6 | 1) Not running – the password manager has been configured with a master password and secret and contains password entries. However, the process is not running – all secrets are supposed to remain on disk encrypted. 7 | 2) Running Unlocked – The password manager has been unlocked using the master password and a user can interact with entries to view/edit contents. 8 | 3) Running Locked – The password manager was previously ‘Running Unlocked’ but has been placed into a locked state where the master password must be entered to place it into a ‘Running Unlocked’ State. 9 | 10 | 11 | In a running locked state, the master password is recoverable from: 12 | * 1Password 4 13 | * 1Password 7 14 | * ~~LastPass for Applications~~ (Fixed Feb 18 2019:https://lastpass.com/upgrade.php?fromwebsite=1&releasenotes=1) 15 | * ~~RoboForm~~ (Fixed Feb 20 2019:https://www.roboform.com/news-windows) 16 | 17 | In a running locked state, one or more entries are recoverable from: 18 | * 1Password 4 19 | * 1Password 7 20 | * ~~LastPass for Applications~~ (Fixed Feb 18 2019:https://lastpass.com/upgrade.php?fromwebsite=1&releasenotes=1) 21 | * Dashlane 22 | * KeePass 2 23 | 24 | --------------------------------------------------------------------------------