Bitcoin Forum
May 22, 2024, 03:18:32 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 »  All
  Print  
Author Topic: Content of wallet.dat - Bounty  (Read 3947 times)
Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 09, 2014, 06:05:58 PM
 #21

Thanks! But I have about 20 different coins... I guess I'll have to try and match which key goes to what wallet?
import every private key to every wallet. you can import keys using RPC or command line so it shouldn't be too tedious.

Holy crap - didn't know this. Man you guys are going to take my bitchange, lol. But it's cool Smiley

Just so you guys know... I'm going to try everything I can obviously. You guys gave me lots of direction here... so you'll end of splitting the bounty.

Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 09, 2014, 06:09:13 PM
 #22

lucky did u ever look at the link i post before?? there u can find the answer

science

So I've already ran Photorec (this is second time around actually - 6 hours left). Do I have to run it again so that the wallet.dat signature file can be included in the recovery? I was under the impression that maybe they'd be in the 1mil files I got on the first run, just perhaps a .txt format....

0xAli
Member
**
Offline Offline

Activity: 72
Merit: 10

42


View Profile
August 09, 2014, 06:21:54 PM
 #23

So I've already ran Photorec (this is second time around actually - 6 hours left). Do I have to run it again so that the wallet.dat signature file can be included in the recovery? I was under the impression that maybe they'd be in the 1mil files I got on the first run, just perhaps a .txt format....

Didn't you get a backup in the external drive? then just run (assuming you are on ubuntu now)
Code:
grep -RH 'defaultkey' EXTERNAL_DRIVE
Against your backed up files, and it will get the wallets for you no matter what their name/extension is.

(And put the real path of the external drive instead of EXTERNAL_DRIVE)

Only god can judge me.
Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 09, 2014, 06:29:46 PM
 #24

So I've already ran Photorec (this is second time around actually - 6 hours left). Do I have to run it again so that the wallet.dat signature file can be included in the recovery? I was under the impression that maybe they'd be in the 1mil files I got on the first run, just perhaps a .txt format....

Didn't you get a backup in the external drive? then just run (assuming you are on ubuntu now)
Code:
grep -RH 'defaultkey' EXTERNAL_DRIVE
Against your backed up files, and it will get the wallets for you no matter what their name/extension is.

(And put the real path of the external drive instead of EXTERNAL_DRIVE)

Ah! Yes, Photorec saved all of my copied files over to my external drive. But because they're a default file signature type I was asking whether the wallet files were recovered to begin with. It looks like you have to add a custom signature prior to running Photorec so the files can be included in the recovery:

http://www.cgsecurity.org/wiki/Add_your_own_extension_to_PhotoRec

science
Member
**
Offline Offline

Activity: 72
Merit: 10


View Profile
August 09, 2014, 06:41:53 PM
 #25

Hi!


Here are the sig for DB Berkeley (wallet.dat) add it to photorec and run it again...
Code:

dat 0x0 0x00061561
dat 0x0 0x61150600
dat 0x0 0x00053162
dat 0x0 0x62310500
dat 0xc 0x00061561
dat 0xc 0x61150600
dat 0xc 0x00053162
dat 0xc 0x62310500
dat 0xc 0x00042253
dat 0xc 0x53220400
dat 0xc 0x00040988
dat 0xc 0x88090400

Science

BTC: 1B12Kz4nzkjZPzeKrAJi3fcqJ9CDoGXaup
Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 09, 2014, 07:03:46 PM
 #26

Hi!

Here are the sig for DB Berkeley (wallet.dat) add it to photorec and run it again...
Code:

dat 0x0 0x00061561
dat 0x0 0x61150600
dat 0x0 0x00053162
dat 0x0 0x62310500
dat 0xc 0x00061561
dat 0xc 0x61150600
dat 0xc 0x00053162
dat 0xc 0x62310500
dat 0xc 0x00042253
dat 0xc 0x53220400
dat 0xc 0x00040988
dat 0xc 0x88090400

Science

Sweet! So I do have to run it again... guess I'll go ahead and stop this session. Before I do though, I want to see if FaSan's method of using keyhunter is faster than Photorec. It's been running now for 17hours and says I still have 6 hours left. I'm scanning the entire disk.

EDIT - this might be a stupid question... do all wallets use this signature, or will this only find my bitcoin wallat.dat?

science
Member
**
Offline Offline

Activity: 72
Merit: 10


View Profile
August 09, 2014, 07:30:41 PM
 #27

nearly all cryptocoins use the DB Berkeley format

science

BTC: 1B12Kz4nzkjZPzeKrAJi3fcqJ9CDoGXaup
harlenadler
Sr. Member
****
Offline Offline

Activity: 430
Merit: 250


Agent of Chaos


View Profile
August 10, 2014, 01:37:35 AM
 #28

How much do you have in those wallets, if you don't mind me asking!
Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 10, 2014, 02:03:01 AM
 #29

How much do you have in those wallets, if you don't mind me asking!

10s of 1000s of a few pretty much worthless coins

bigasic
Hero Member
*****
Offline Offline

Activity: 924
Merit: 1000



View Profile
August 10, 2014, 03:42:19 AM
 #30

Wouldn't you only need the private address? no need for the public one if you have the private one, correct? I hope you are able to find your cons, I know it sucks to lose coins from technical issues.
Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 10, 2014, 05:08:06 AM
 #31

Wouldn't you only need the private address? no need for the public one if you have the private one, correct? I hope you are able to find your cons, I know it sucks to lose coins from technical issues.

I have to find the wallet.dat files first! Tongue  Here's hoping Smiley  I was able to find a couple of my most precious files... my index.html and style css for my website. Lots of me went into those... they're not the latest iteration, but at least I can work from that. Tomorrow I'll work on the wallet.dats.

Muhammed Zakir
Hero Member
*****
Offline Offline

Activity: 560
Merit: 506


I prefer Zakir over Muhammed when mentioning me!


View Profile WWW
August 10, 2014, 11:20:45 AM
 #32

Thanks... but I don't even know my addresses.
Your post history does (only had a quick look):
16K6t4BtQwhbeTBaRrocCuptESyKcXTcuZ
1BUJ92LbERYLEPxfaxcRJECm5rXYasvsxE

Nice detective work Smiley  But those are from my online wallet... This is a new system I built a couple of months ago to start to start hosting pools so I had to download the client.

Try checking history of your browser. Somehow if you checked your balance of an address in blockchain or any other exploerer, you might get it from browser.

Kindly,
      MZ

Dare
Hero Member
*****
Offline Offline

Activity: 508
Merit: 500


Techwolf on #bitcoin and Reddit


View Profile WWW
August 13, 2014, 10:09:51 AM
 #33

Another option, if you have Linux/Cygwin/(probably)OSX, you can search through all of the extensionless files recovered by Photorec and use the `file` command to determine the type. Wallet files appear as "Berkeley DB (Btree, version 9, little-endian)", and so you should be able to find it relatively easily by running something like `file ** | grep "Berkeley DB"` (if you have globstar enabled, though there are many other ways of recursively searching every file within a specified location). You can use this technique for other file types as well, though anything plaintext will simply show up as "ASCII text" so it'll only help for binary file types with a specific identifier such as PNG (though presumably Photorec handles much of this, given the name).

BTC: 1M8oUcBnkRDEhWWgV8ZXLTB6p1mgnejVbX
How Forum Activity Works
Bitcointalk Forum Rules
|
|
|
Firstbits (lucky vanitygen): 1WoLfRUGDx1
How Forum Trust Works
Bitcoin Source Code
0xAli
Member
**
Offline Offline

Activity: 72
Merit: 10

42


View Profile
August 13, 2014, 11:05:06 AM
 #34

Another option, if you have Linux/Cygwin/(probably)OSX, you can search through all of the extensionless files recovered by Photorec and use the `file` command to determine the type. Wallet files appear as "Berkeley DB (Btree, version 9, little-endian)", and so you should be able to find it relatively easily by running something like `file ** | grep "Berkeley DB"` (if you have globstar enabled, though there are many other ways of recursively searching every file within a specified location). You can use this technique for other file types as well, though anything plaintext will simply show up as "ASCII text" so it'll only help for binary file types with a specific identifier such as PNG (though presumably Photorec handles much of this, given the name).

Yeah actually that's a very good idea.

And you can simply do (without globstar)
Code:
find ./ -type f -exec file {} \; | grep "Berkeley DB"
(And replace ./ with the directory path)

Only god can judge me.
Nexigen
Full Member
***
Offline Offline

Activity: 297
Merit: 100



View Profile
August 14, 2014, 08:32:26 AM
 #35

Did you already get your wallet data back?
I had this problem as well, using a simple recovery tool. Anything should work really.
I hope you get yours back!
zahra4571
Sr. Member
****
Offline Offline

Activity: 467
Merit: 250



View Profile WWW
August 14, 2014, 09:46:06 AM
 #36

Try Recuva recovery software and search for wallet.dat or just type .dat you can search it in specific participation, you can also search for any other format you need for.

Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 15, 2014, 02:41:08 AM
 #37

Try Recuva recovery software and search for wallet.dat or just type .dat you can search it in specific participation, you can also search for any other format you need for.

I think I tried that - I think it's only for Windows. But even so, the majority of the files I recovered extension was renamed to .txt.

Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 15, 2014, 02:43:42 AM
 #38

Did you already get your wallet data back?
I had this problem as well, using a simple recovery tool. Anything should work really.
I hope you get yours back!

Thanks! I haven't yet, but here's hoping!

Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 15, 2014, 02:44:13 AM
 #39

Another option, if you have Linux/Cygwin/(probably)OSX, you can search through all of the extensionless files recovered by Photorec and use the `file` command to determine the type. Wallet files appear as "Berkeley DB (Btree, version 9, little-endian)", and so you should be able to find it relatively easily by running something like `file ** | grep "Berkeley DB"` (if you have globstar enabled, though there are many other ways of recursively searching every file within a specified location). You can use this technique for other file types as well, though anything plaintext will simply show up as "ASCII text" so it'll only help for binary file types with a specific identifier such as PNG (though presumably Photorec handles much of this, given the name).

Yeah actually that's a very good idea.

And you can simply do (without globstar)
Code:
find ./ -type f -exec file {} \; | grep "Berkeley DB"
(And replace ./ with the directory path)

Sweet!!! Will try this next Smiley

Lucky Cris (OP)
Sr. Member
****
Offline Offline

Activity: 280
Merit: 250


View Profile
August 15, 2014, 01:30:57 PM
 #40

Another option, if you have Linux/Cygwin/(probably)OSX, you can search through all of the extensionless files recovered by Photorec and use the `file` command to determine the type. Wallet files appear as "Berkeley DB (Btree, version 9, little-endian)", and so you should be able to find it relatively easily by running something like `file ** | grep "Berkeley DB"` (if you have globstar enabled, though there are many other ways of recursively searching every file within a specified location). You can use this technique for other file types as well, though anything plaintext will simply show up as "ASCII text" so it'll only help for binary file types with a specific identifier such as PNG (though presumably Photorec handles much of this, given the name).

Yeah actually that's a very good idea.

And you can simply do (without globstar)
Code:
find ./ -type f -exec file {} \; | grep "Berkeley DB"
(And replace ./ with the directory path)

I'm getting this error back:

find: missing argument to '-exec'  I guess something's missing from the line?

Pages: « 1 [2] 3 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!