How to hide a file ?

From: Kurt Seifried (bugtraq@seifried.org)
Date: 01/11/02


From: "Kurt Seifried" <bugtraq@seifried.org>
To: <vuln-dev@security-focus.com>
Date: Thu, 10 Jan 2002 20:14:41 -0700

Just a note: Tripwire will pick it up, i.e. if you add an ADS to a file
tripwire will flag it, and if a file has an ADS that is modified or removed
tripwire will also flag it (with MD5sum/etc just like a normal file). The
other good news is if you add an ADS stream to a directory such as WINNT or
system32 it will detect it. Of course any files or dirs not listed in your
policy will escape tripwire, but then that's no big surprise. So my advice:
use ADS on files specifically excluded by tripwire if you want to hide
things.

Kurt Seifried, kurt@seifried.org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://www.seifried.org/security/



Relevant Pages

  • How to hide a file ?
    ... Tripwire will pick it up, i.e. if you add an ADS to a file ... tripwire will also flag it. ... streams cannot be deleted - to delete a stream you must delete ...
    (Vuln-Dev)
  • Re: How to hide a file ? (From McAfee)
    ... > McAfee Vshield doesn't pick up ADS's by default. ... Tripwire and some other stuff does by default. ... Handling ADS doesn't ... > access denied error as opening the original. ...
    (Vuln-Dev)
  • OT: I just plain refused to play that game...flagging
    ... but it was a temp yahoo account originating from San Jose, ... to go to Craigslist SF Bay and flag all pinball ads. ... I did notice yesterday someone posted a section of Mr. Pinball ... If a group like this was to say all go to a Craigslist site and flag ...
    (rec.games.pinball)
  • Re: Tripwire config ???
    ... this file is present while root is ... > scheduled Triipwire reports are run unattended via cron, ... > Leaving Triipwire flag this file gives me a little extra comfort level. ... ** If it gets erased and recreated it will be flagged by tripwire. ...
    (Fedora)
  • User deletet in AD still in MOSS and owner of Sites which leads to
    ... I have the issue, that if a user is deleted in the ADS, that the things he ... was owner of are still in MOSS. ... is, that I get errors when I try to change or delete, because MOSS do not ... UserInfo Table with the delete flag but that flag only show the user which ...
    (microsoft.public.sharepoint.windowsservices)

Quantcast