Some Little Known Computer Info Just For SETI Users

Message boards : Cafe SETI : Some Little Known Computer Info Just For SETI Users
Message board moderation

To post messages, you must log in.

1 · 2 · Next

AuthorMessage
AC
Avatar

Send message
Joined: 22 Jan 05
Posts: 3413
Credit: 119,579
RAC: 0
United States
Message 79424 - Posted: 14 Feb 2005, 20:48:59 UTC

The NTFS filing system contains Alternat Data Streams (ADS) wich are located within normal system and program files, and are hard to detect by your operating system. A malicious hacker can install a "hacker tool", Trojan Horse, or other spy tool in the ADS wich sometimes escapes detection by antivirus scanners.

It's commonly known that ADS was meant to support the MAC Hierarchical File System... hehe.

A little well placed birdy told me that a certain "agency" with a three letter abreviation was really behind this!
ID: 79424 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 79427 - Posted: 14 Feb 2005, 21:07:35 UTC - in response to Message 79424.  

> The NTFS filing system contains Alternat Data Streams (ADS) wich are located
> within normal system and program files, and are hard to detect by your
> operating system. A malicious hacker can install a "hacker tool", Trojan
> Horse, or other spy tool in the ADS wich sometimes escapes detection by
> antivirus scanners.
>
> It's commonly known that ADS was meant to support the MAC Hierarchical File
> System... hehe.
>
> A little well placed birdy told me that a certain "agency" with a three letter
> abreviation was really behind this!
>

So whats the Fix?


ID: 79427 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 79430 - Posted: 14 Feb 2005, 21:15:08 UTC - in response to Message 79427.  

http://www.windowsecurity.com/articles/Alternate_Data_Streams.html




ID: 79430 · Report as offensive
AC
Avatar

Send message
Joined: 22 Jan 05
Posts: 3413
Credit: 119,579
RAC: 0
United States
Message 79434 - Posted: 14 Feb 2005, 21:23:58 UTC - in response to Message 79427.  

> > The NTFS filing system contains Alternat Data Streams (ADS) wich are
> located
> > within normal system and program files, and are hard to detect by your
> > operating system. A malicious hacker can install a "hacker tool", Trojan
> > Horse, or other spy tool in the ADS wich sometimes escapes detection by
> > antivirus scanners.
> >
> > It's commonly known that ADS was meant to support the MAC Hierarchical
> File
> > System... hehe.
> >
> > A little well placed birdy told me that a certain "agency" with a three
> letter
> > abreviation was really behind this!
> >
>
> So whats the Fix?
>
>

Well Captain Avatar... there are a couple of monitoring progs out there that check for changes in files, but I would suggest something a little more simple like a GOOD wiping utility that destroys ADS's by overwriting them altogether.

I think a utility like East-Tec Eraser would just do the job pretty well.
>
ID: 79434 · Report as offensive
wrzwaldo
Avatar

Send message
Joined: 16 Jul 00
Posts: 113
Credit: 1,073,284
RAC: 0
United States
Message 79447 - Posted: 14 Feb 2005, 22:37:04 UTC - in response to Message 79427.  
Last modified: 14 Feb 2005, 22:45:39 UTC

> > The NTFS filing system contains Alternat Data Streams (ADS) wich are
> located
> > within normal system and program files, and are hard to detect by your
> > operating system. A malicious hacker can install a "hacker tool", Trojan
> > Horse, or other spy tool in the ADS wich sometimes escapes detection by
> > antivirus scanners.
> >
> > It's commonly known that ADS was meant to support the MAC Hierarchical
> File
> > System... hehe.
> >
> > A little well placed birdy told me that a certain "agency" with a three
> letter
> > abreviation was really behind this!
> >
>
> So whats the Fix?
>
>

Try This. And This.



<img src="http://boinc.mundayweb.com/seti2/stats.php?userID=2259&amp;team=off">
ID: 79447 · Report as offensive
AC
Avatar

Send message
Joined: 22 Jan 05
Posts: 3413
Credit: 119,579
RAC: 0
United States
Message 79453 - Posted: 14 Feb 2005, 23:01:22 UTC - in response to Message 79447.  

> > > The NTFS filing system contains Alternat Data Streams (ADS) wich
> are
> > located
> > > within normal system and program files, and are hard to detect by
> your
> > > operating system. A malicious hacker can install a "hacker tool",
> Trojan
> > > Horse, or other spy tool in the ADS wich sometimes escapes detection
> by
> > > antivirus scanners.
> > >
> > > It's commonly known that ADS was meant to support the MAC
> Hierarchical
> > File
> > > System... hehe.
> > >
> > > A little well placed birdy told me that a certain "agency" with a
> three
> > letter
> > > abreviation was really behind this!
> > >
> >
> > So whats the Fix?
> >
> >
>
> Try This. <a> href="http://www.heysoft.de/Frames/f_faq_ads_en.htm">And This.[/url]
>

I've tried this util some months ago, and found that it has inaccurate scanning results.
ID: 79453 · Report as offensive
7822531

Send message
Joined: 3 Apr 99
Posts: 820
Credit: 692
RAC: 0
Message 79745 - Posted: 16 Feb 2005, 0:44:39 UTC - in response to Message 79424.  

It's commonly known that ADS was meant to support the MAC Hierarchical File System... hehe.
Ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha - I'm not rolling on the floor.
ID: 79745 · Report as offensive
AC
Avatar

Send message
Joined: 22 Jan 05
Posts: 3413
Credit: 119,579
RAC: 0
United States
Message 79790 - Posted: 16 Feb 2005, 2:40:03 UTC - in response to Message 79745.  

> It's commonly known that ADS was meant to support the MAC Hierarchical File
> System... hehe.

> Ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha
> ha ha ha - I'm not rolling on the floor.
>

I'm glad to hear that your not rolling on the floor... hehe.

But the ADS support concept was being pushed so that it could be possible to deploy reconaissance and data interception tools in a computer system with NTFS.
ID: 79790 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 79792 - Posted: 16 Feb 2005, 2:41:33 UTC - in response to Message 79790.  


> But the ADS support concept was being pushed so that it could be possible to
> deploy reconaissance and data interception tools in a computer system with
> NTFS.
>

I take it the feds all use Apples?




ID: 79792 · Report as offensive
AC
Avatar

Send message
Joined: 22 Jan 05
Posts: 3413
Credit: 119,579
RAC: 0
United States
Message 79794 - Posted: 16 Feb 2005, 2:48:00 UTC - in response to Message 79792.  

>
> > But the ADS support concept was being pushed so that it could be possible
> to
> > deploy reconaissance and data interception tools in a computer system
> with
> > NTFS.
> >
>
> I take it the feds all use Apples?
>

I didn't specify that it was the feds. But THEY do like to use D.I.R.T. (Data Interception by Remote Trasmission).
ID: 79794 · Report as offensive
Profile Siran d'Vel'nahr
Volunteer tester
Avatar

Send message
Joined: 23 May 99
Posts: 7379
Credit: 44,181,323
RAC: 238
United States
Message 79819 - Posted: 16 Feb 2005, 3:39:46 UTC - in response to Message 79792.  

>
> > But the ADS support concept was being pushed so that it could be possible
> to
> > deploy reconaissance and data interception tools in a computer system
> with
> > NTFS.
> >
>
> I take it the feds all use Apples?
>

Well, their not using oranges or plums. ;-)

L8R....

T'Khasi Time: Tuesday, 15 February 2005 - 07:39 PM --800 (Pacific Standard Time)

CAPT Siran d'Vel'nahr - L L & P _\\//
Winders 11 OS? "What a piece of junk!" - L. Skywalker
"Logic is the cement of our civilization with which we ascend from chaos using reason as our guide." - T'Plana-hath
ID: 79819 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 79823 - Posted: 16 Feb 2005, 3:46:00 UTC - in response to Message 79819.  

> >
> > I take it the feds all use Apples?
> >
>
> Well, their not using oranges or plums. ;-)
>
Careful Siran your druelling juice all over the keyboard.




ID: 79823 · Report as offensive
Paul Zimmerman
Avatar

Send message
Joined: 22 Jan 05
Posts: 1440
Credit: 11
RAC: 0
United States
Message 79824 - Posted: 16 Feb 2005, 3:47:00 UTC

I''m a fed ....now?
ID: 79824 · Report as offensive
Profile Siran d'Vel'nahr
Volunteer tester
Avatar

Send message
Joined: 23 May 99
Posts: 7379
Credit: 44,181,323
RAC: 238
United States
Message 79828 - Posted: 16 Feb 2005, 3:54:24 UTC - in response to Message 79823.  

> > > ....
> Careful Siran your druelling juice all over the keyboard.
>

At least it's not apple juice. ;-)

L8R....

T'Khasi Time: Tuesday, 15 February 2005 - 07:54 PM --800 (Pacific Standard Time)

CAPT Siran d'Vel'nahr - L L & P _\\//
Winders 11 OS? "What a piece of junk!" - L. Skywalker
"Logic is the cement of our civilization with which we ascend from chaos using reason as our guide." - T'Plana-hath
ID: 79828 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 79830 - Posted: 16 Feb 2005, 3:56:28 UTC - in response to Message 79824.  

> I''m a fed ....now?
Who called you a fed?


Didn't they say fred?
ID: 79830 · Report as offensive
Profile Siran d'Vel'nahr
Volunteer tester
Avatar

Send message
Joined: 23 May 99
Posts: 7379
Credit: 44,181,323
RAC: 238
United States
Message 79831 - Posted: 16 Feb 2005, 3:57:05 UTC - in response to Message 79824.  

> I''m a fed ....now?
>

Let's see what Timmy comes back with.

@Timmy: Come on Timmy, I want to see a witty comeback to this. ;-)

L8R....

T'Khasi Time: Tuesday, 15 February 2005 - 07:56 PM --800 (Pacific Standard Time)

CAPT Siran d'Vel'nahr - L L & P _\\//
Winders 11 OS? "What a piece of junk!" - L. Skywalker
"Logic is the cement of our civilization with which we ascend from chaos using reason as our guide." - T'Plana-hath
ID: 79831 · Report as offensive
Profile Fat B
Volunteer tester
Avatar

Send message
Joined: 3 Apr 99
Posts: 1688
Credit: 4,205,162
RAC: 0
United Kingdom
Message 79833 - Posted: 16 Feb 2005, 3:58:03 UTC

An apple a day keeps the feds at bay...




ID: 79833 · Report as offensive
AC
Avatar

Send message
Joined: 22 Jan 05
Posts: 3413
Credit: 119,579
RAC: 0
United States
Message 79839 - Posted: 16 Feb 2005, 4:21:24 UTC - in response to Message 79833.  

> An apple a day keeps the feds at bay...
>
>
>

Well Fat B, try this instead of an apple: HookProtect.
ID: 79839 · Report as offensive
7822531

Send message
Joined: 3 Apr 99
Posts: 820
Credit: 692
RAC: 0
Message 79842 - Posted: 16 Feb 2005, 4:28:33 UTC

Or use EXT3+SELinux, or HFS+J with FileVault-ed 128-bit OtF encrypting...

.o0(Hmm... "Do not use obscene language or threaten other participants; we may delete such messages." Methinks that Berkeley a-stretches ye avatar columnae with message a-proof of how profundly the users have sunketh...)
ID: 79842 · Report as offensive
Profile Captain Avatar
Volunteer tester
Avatar

Send message
Joined: 17 May 99
Posts: 15133
Credit: 529,088
RAC: 0
United States
Message 79845 - Posted: 16 Feb 2005, 4:33:43 UTC - in response to Message 79831.  
Last modified: 16 Feb 2005, 4:34:49 UTC

> > I''m a fed ....now?
> >
>
> Let's see what Timmy comes back with.
>
> @Timmy: Come on Timmy, I want to see a witty comeback to this. ;-)
>
> L8R....
>
> T'Khasi Time: Tuesday, 15 February 2005 - 07:56 PM --800 (Pacific Standard
> Time)
>
[url=http://www.summercon.org/2003/hackers_and_feds.jpg]
ID: 79845 · Report as offensive
1 · 2 · Next

Message boards : Cafe SETI : Some Little Known Computer Info Just For SETI Users


 
©2024 University of California
 
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.