Read encrypted Apple disk images with their password - #341
Merged
Merged
Conversation
Raw image input now opens an encrypted .dmg, a split .dmg with its .dmgpart files, an encrypted .sparseimage and an encrypted sparse bundle, AES-128 or AES-256, with the image's password. The command line takes it from --image_password_file or --image_password_env, or asks at a terminal; the GUI asks in a masked dialog and checks it against the image before the run starts. The password is held in memory for the run. The vendored readers move to qnxprobe 1.41 (d268ec9) and ewfprobe 0.5.0 (20513a1), which add the decryption. It uses PyCryptodome, already in requirements.txt. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds encrypted Apple disk images to raw image input (
-t raw)..dmg, split.dmgwith its.dmgpartfiles,.sparseimageand sparse bundle, AES-128 or AES-256--image_password_fileor--image_password_env, or asked at a terminal. The password is never taken as an argument value.The password is held in memory for the run and is not written to the report or logs. Decryption uses PyCryptodome, already in requirements.txt.
🤖 Generated with Claude Code