Girl Geekette dotNet

Where the Girl Ends and the Geekette Begins


Archive for the '2000' Category

NTFS Alternate Data Streams

While searching around, I happen to run across something that caught my eye. It deals with Microsoft’s NTFS and security. ADS 0r Alternate Data Streams - was originally created to provide compatibility with HFS (Macintosh Hierarchical File System).

Although widely unknown by most that ADS even exists, it is has been used by sometime by people to exploit Windows Boxes that use NTFS. Not all anti-virus programs will pick up alternate data streams. It is easy to exploit the ADS and let it go undetected for some time. Although with technology getting better, some anti-virus scanners are now picking up the ADS when changes have been made to the default configuration.

Security Focus has a demonstration of how this is used by rooting or exploiting a lab box using the MS04–011 vulnerability. The Metaspoilt Framework can allow someone to break into a computer via the lsass overflow.

The demonstration can be found at securityfocus.com/infocus/1822

An easier way to demonstrate the idea of ADS is to use a simple command such as

“type c:\anyfile.exe > c:\winnt\system32\calc.exe:anyfile.exe”

This will "fork" or run the calculator program in Windows with any executable that is chosen. So, by running a command like this, almost anything can be hidden behind a valid (Windows) program. When seen in task manager, this program looks like or almost like a normal program (depending on the operating system, and that is explained later) and most people will pay no notice.

Many people have noticed when using the MSCONFIG with windows that there are some programs in the startup file that might look like that in the path. It is possible to write it so that in the registry, a program that is used by ADS will start up with every boot up of the Windows box. (Think spyware, viruses, trojans and the like)




Search: Cosmos | BlogPulse
Submit: Digg This | Shout this! | Slashdot
Bookmark: Del.icio.us | Furl It | Spurl | Tag!RawSugar | Simpy This! | Shadows Tag! | Blink It | My Web
GirlGeekette dotNet Tags: , , ,
Technorati Tags: , , , , ,
Archived in Security , 2000 , XP , Ramblings , 2003 , Windows
No Comments »

Top of the Page Top of the Page









Windows 2000 - Disabling IDE Detection When Windows 2000 Boots

Every time Win2k boots it will check the onboard controller if there is any drives attached. If you don’t have the habit of swapping IDE units in and out or you have none installed at all, then you might want to disable the scanning for IDE units and get a faster bootup.

Go here : Control Panel - System - Hardware-tab - Device Manager-button - IDE ATA/ATAPI Controllers-node

There select properties for your Primary- and Secondary-Channel and go to Advanced Settings where you can change the Device Type from "Auto detection" to "None" when there is no IDE Unit attached

End of Article
 




Search: Cosmos | BlogPulse
Submit: Digg This | Shout this! | Slashdot
Bookmark: Del.icio.us | Furl It | Spurl | Tag!RawSugar | Simpy This! | Shadows Tag! | Blink It | My Web
GirlGeekette dotNet Tags: , , , , , , , , ,
Technorati Tags: , , , , , , , ,
Archived in Tips , 2000 , Windows
No Comments »

Top of the Page Top of the Page










About the Geekette

I am a Computer and Network Technician. I love what I do for a living, as my work is also my hobby.

All of the technical information from the original Aleeya.net site became this site - GirlGeekette dotNet - and the remaining became what is now known as Aleeya dotNet. This site is where I store all of my notes related to computers and Technology so I may share it with others.

  Google


Web This site

Feeds

Validations

Ratings

Computer Links

Blog Links

Security Links

Geek Links

You Are Here

You are currently browsing the archives for the 2000 category.

Archives

Powered by WordPress with a modified version of Ragiels Dream theme.

43 queries complete in 0.209 seconds.