Skip to main content

Windows NTFS Alternate Data Streams

posted onFebruary 17, 2005
by hitbsecnews

The purpose of this article is to explain the existence of alternate data streams in Microsoft Windows, demonstrate how to create them by compromising a machine using the Metasploit Framework, and then use freeware tools to easily discover these hidden files.

The first step is to understand what alternate data streams are, and how they can be a threat to your organizations. Then, a comprehensive demonstration will be completed, that compromises a remote machine with an exploit, provides a reverse shell, and allows one to hide files on the victim's machine. Finally, there will be a discussion of freeware tools that can be used to easily locate this activity and allow one to take steps to stop it. Let's begin.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th