Microsoft KB Archive/298009

= Cipher.exe Security Tool for the Encrypting File System =

Article ID: 298009

Article Last Modified on 2/21/2007

-

APPLIES TO


 * Microsoft Windows 2000 Service Pack 1
 * Microsoft Windows 2000 Service Pack 2
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Advanced Server
 * Microsoft Windows 2000 Service Pack 1
 * Microsoft Windows 2000 Service Pack 2

-



This article was previously published under Q298009



SUMMARY
Cipher.exe is a command-line tool (included with Windows 2000) that you can use to manage encrypted data by using the Encrypting File System (EFS). As of June 2001, Microsoft has developed an improved version of the Cipher.exe tool that provides the ability to permanently overwrite (or &quot;wipe&quot;) all of the deleted data on a hard disk. This feature improves security by ensuring that even an attacker who gained complete physical control of a Windows 2000 computer would be unable to recover previously-deleted data.

IMPORTANT: Please note the following important information:  You must install Cipher.exe by using the installer package instead of copying the new version of Cipher.exe to your computer. The tool relies on additional NTFS functionality that is added as part of the installation process. If you only copy the Cipher.exe file to your computer and then run it, you could destroy data on the drive. You must close all programs before you start Cipher.exe. Cipher.exe is not a cure-all that makes it safe to store sensitive data in a plain-text format. Although you can use this tool to remove sensitive data from a drive, if best practices are followed, such data would not normally be created on the drive. For additional information about these best practices, click the following article number to view the article in the Microsoft Knowledge Base:

223316 Best Practices for the Encrypting File System



For additional information about the latest service pack for Windows 2000, click the article number below to view the article in the Microsoft Knowledge Base:

260910 How to Obtain the Latest Windows 2000 Service Pack



How to Obtain Cipher.exe
Cipher.exe is available in Windows 2000 Service Pack 3 or later or the Windows 2000 Security Rollup Package 1 (SRP1) or individually via the links below. For additional information on SRP1, click the article number below to view the article in the Microsoft Knowledge Base:

311401 Windows 2000 Security Rollup Package 1 (SRP1), January 2002

Q298009_W2K_SP3_x86_en.exe contains the following files:   Date         Time   Version        Size     Filename --  May-30-2001  16:25  5.0.2195.3653   36,112  Cipher.exe May-26-2001 07:48  5.0.2195.3649  512,272  Ntfs.sys

How to Use Cipher.exe
To overwrite the deallocated data:
 * 1) Quit all programs.
 * 2) Click Start, click Run, and type cmd, and then press ENTER.
 * 3) Type cipher /w:' ', and then press ENTER, where   is optional and can be any folder in a local volume that you want to clean. For example, the cipher /w:c:\test command causes the deallocated space on drive C: to be overwritten. If c:\test is a mount point or points to a folder in another volume, deallocated space on that volume will be cleaned.

For more information about EFS, please see the following Microsoft Web site:

http://www.microsoft.com/technet/security/topics/cryptographyetc/efs.mspx

Additional query words: kbWin2000srp1 security_patch kbsectools

Keywords: kbinfo kbwin2000presp3fix kbqfe kbwin2000sp3fix kbenv kbsecurity kbhotfixserver KB298009

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.