TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: John Beamish
from: John Beamish
date: 2006-07-15 13:35:30
subject: Re: NTFS - ADS (Alternate Data Streams).

From: "John Beamish" 

And just after posting my original message I found this:

http://www.cio.com/blog_view.html?CID=23011

'Invisible' Rootkit Heralds Trouble Ahead

The sixth and seventh paras read:

F-Secure noted Rustockƒ ™s use of NTFSƒ ™ Alternate Data Streams (ADS) as
one significant example of its advanced behavior.

"Saving your data into Alternate Data Streams is usually enough to hide
 from many tools," wrote F-Secure researcher Antti Tikkanen in a company
blog.



On Fri, 14 Jul 2006 13:15:55 -0400, John Beamish  wrote:

> The more technically-minded probably already knew about this.  We mere
> mortal, otoh, are not so knowledgeable!
>
>
> Start here:
> http://www.heysoft.de/nt/ntfs-ads.htm
>
> What is an alternate data stream (ADS)?
>
> In NTFS, a file consits of different data streams. One stream holds the
> security information (access rights and such things), another one holds
> the "real data" you expect to be in a file. There may be
another stream
> with link information instead of the real data stream, if the file
> actually is a link. And there may be alternate data streams, holding
> data the same way the standard data stream does.
>
>
>
> Continue here: (thanks, Geo, for the link)
> http://www.sysinternals.com/Utilities/Streams.html

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270 5030/786
@PATH: 379/45 1 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.