PDA

View Full Version : OT: Alternate Data Streams


EaX
September 3rd, 2005, 06:55 PM
For those who don't know Alternate Data Stream is a NTFS "feature" wich is really a security risk, a program can be executed and you may not realice that, check out these link....

http://www.windowsecurity.com/articles/Alternate_Data_Streams.html

TurinTurambar
September 6th, 2005, 03:56 AM
GEEEZZZZ!!!

Nice of him to put in a "tutorial" for the would-be hacker... http://forum.shrapnelgames.com/images/smilies/Sick.gif

People are stupid. I'm embarrassed to be human.

Arkcon
September 7th, 2005, 04:03 PM
Now I'd seen something similar, and I wonder if it was the same thing. I use a tiny, efficient, command-line defragmenter called DIRMS. When I ran it on my sister's Dell laptop, I saw dozens of the folder hidden thumbnail files (Gak, big win XP waste of space and resources) displayed like: Thumbs.db:encryptable

I wonder if it has anything to do with this? And why would Dell have to do something like this? This was before she was on the net, so I don't think it was malicious.

EaX
September 8th, 2005, 02:07 AM
Well you can always create a ADS and see if you get the same result with the program, if it does well it's pretty sure its a ADS, i think.

narf poit chez BOOM
September 8th, 2005, 01:00 PM
Thumbs.db? I'm pretty sure that's image thumbnails to be displayed in folders.

(Just my mildly informed opinion)

EaX
September 8th, 2005, 03:48 PM
Apparently you were right Arkon, its a ADS, check this out

C: Enumerating detected ADS...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »

Location:C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable
StreamName:encryptable
StreamID:BACKUP_ALTERNATE_DATA (4)
StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0)
DataSize:0 Bytes
NameSize:36 Bytes

Location:C:\Documents and Settings\All Users.WINDOWS\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable
StreamName:encryptable
StreamID:BACKUP_ALTERNATE_DATA (4)
StreamAttributes:STREAM_NORMAL_ATTRIBUTE. (0)
DataSize:0 Bytes
NameSize:36 Bytes

see the whole thing here http://forums.scotsnewsletter.com/index.php?s=58ba5ad62a84164c87dcc5319a4b3506&showt opic=12854&pid=158041&st=0&#entry158041

Arkcon
September 8th, 2005, 08:09 PM
Sometime when I'm at her computer, I'll have to try those sugestions mentioned there. But they don't really explain what happened before she went online to cause this sort of thing. Either Dell or M$ are up to some sort of shenanigans, who knows if its good or bad?