Four|S|
User CP Private Messages Calendar Members List Team Members Search Frequently Asked Questions Absent Members: Go to portal 4-S Contributors Banned Members Go to the Main Page


Four|S| » Support Section » Tutorials » miscelaneous » REALLY hidden files with NTFS's ADS - Run Programs Hidden from taskmanager » Hello ddl_gds [Logout]
Last Post | My last post | First Unread Post Print Page | Recommend to a Friend | Add Thread to Favorites
Post New Thread Post Reply
Go to the bottom of this page REALLY hidden files with NTFS's ADS - Run Programs Hidden from taskmanager  
Author
Post « Previous Thread | Next Thread »
fast_rizwaan
Junior Member


images/avatars/avatar-94.gif

Registration Date: 11-04-2003
Member #: 5106
Location: india

Level: 16 [?]
Experience: 9,626
Next Level: 10,000

374 points of experience needed for next level

Thumb Up! REALLY hidden files with NTFS's ADS - Run Programs Hidden from taskmanager Reply to this Post Post Reply with Quote Edit/Delete Posts Report Post to a Moderator       Go to the top of this page

You may be interested to know about another "SECRET" that the boys in Redmond try not to advertise. It is called Alternative Data Streams, and it basically allows you to "hide" files within other files.

M$ provides no tools (other than low level SDK functions) to even know that these Alternative Data Streams exist. Niether "Explorer", nor "dir", nor "attrib", nor any other resource kit app will help you discover these streams. In fact, to the best of my knowledge, most virus detection programs only scan the primary stream, and not any of the associated alternative streams. In addition, once an ADS has been associated with a file, it copies right along with the file when going from NTFS to NTFS.

To see a non destructive example, drop down to the CMD line and try the following. (Win NT/2k/XP w/ NTFS ... no FAT)

First create a basic host file ... lets say a text file in the root dir on the c drive

C:\>echo Hello World > MyTest.txt


Then attach, your favorite exe (or whatever you want), as an ADS (solitare ?)

C:\>type c:\WINNT\system32\sol.exe > MyTest.txt:MyProg.Exe


Inspect your file all you want. Even delete the original program if you really want to (sol.exe).

Now run your hidden version of solitare anytime you'd like.

C:\>start c:\MyTest.txt:MyProg.exe


(Look at Task Manager and check out Solitare's new process name)

Scary ... isn't it? Do you know what's on your hard drive?



For more info see:
http://patriot.net/~carvdawg/docs/dark_side.html

http://www.codeproject.com/csharp/NTFSStreams.asp - C# P-Invoke SDK wrappers

http://www.heysoft.de/Frames/f_sw_la_en.htm - A tool to view ADS via the command line (no source code provided).

http://www.winnetmag.com/Articles/Print.cfm?ArticleID=19878
02-13-2004 02:58 fast_rizwaan is offline Send an Email to fast_rizwaan Search for Posts by fast_rizwaan Add fast_rizwaan to your Buddy List Send a Private Message to fast_rizwaan
Auto_Bot
System Bot


Registration Date: 06-17-2004
Member #: 12189

Level: 30 [?]
Experience: 254,591
Next Level: 300,073

45,482 points of experience needed for next level

For this contribution- A Thank You from the following 1 user(s): Reply to this Post Post Reply with Quote Edit/Delete Posts Report Post to a Moderator       Go to the top of this page

jestyr8

Click here, in order to send the author of this post an auto thank you!
02-13-2004 02:58 Auto_Bot is offline Send an Email to Auto_Bot Search for Posts by Auto_Bot Add Auto_Bot to your Buddy List Send a Private Message to Auto_Bot
brainbug brainbug is a male
Member


images/avatars/avatar-1841.jpg

Registration Date: 04-27-2004
Member #: 12153
Location: crazy sector of your brain

Level: 16 [?]
Experience: 8,764
Next Level: 10,000

1,236 points of experience needed for next level

Reply to this Post Post Reply with Quote Edit/Delete Posts Report Post to a Moderator       Go to the top of this page

just want to say this is great!
there has also been a tool to view this ntfs streams on this forum, but I cannot find it Frown
09-06-2004 16:29 brainbug is offline Send an Email to brainbug Search for Posts by brainbug Add brainbug to your Buddy List Send a Private Message to brainbug
Tree Structure | Board Structure
Jump to:
Post New Thread Post Reply

Post Reply - No Serial Numbers
Messages:

Smilies: 15 of 146
Big Grin Red Face Confused
Cool Crying Shocked
Pleased Frown Happy
Mad Smile Tongue
Wink Roll Eyes Baby
Options:

Rate Thread: 

very bad very bad 

1

2

3

4

5

6

7

8

9

10
 very good very good

Four|S| » Support Section » Tutorials » miscelaneous » REALLY hidden files with NTFS's ADS - Run Programs Hidden from taskmanager

Powered by Burning Board 2.1.5 © 2001-2004 WoltLab GbR
Four|S|_Blue V2 © Quazar
This page was generate in 1.290 seconds, whereby 0.244 seconds were allotted to 31 MySQL inquiries.