Welcome nishith123, the newest member New user?    Register    Login
http://www.packetsource.com

Categories
Attacks and Exploits
Certifications and Career
Cryptology
Detection and Prevention
Industry and Userbase
Legal and Regulatory
Network and Infrastructure
Policies and Processes
Protocols and Services
Response and Recovery
Scanning and Auditing
Servers and Systems
Software and Applications
Standards and Methods
Tools and Utilities

Popular Tags
forensics, legal, microsoft, china, vista, spam, ddos, dos, disaster recovery, patriotact

Top Members (rating)
Kelsea (1065)
Mitchell (256)
Jennifer (207)
Paperboy (0)
Melrose2703 (0)
santhoshk (0)
Bulltrader (0)
nishith123 (0)
Atony (0)

RSS Feeds
Papers
Forum Posts

Alternate Data Streams: Out of the Shadows and into the Light


Written by Ryan L. Means Source SANS Institute
0 Save | Report | Email
Added on (Edited 10/28/07)

Alternate Data Streams: Out of the Shadows and into the Light examines alternate data streams in NTFS. It provides a thorough technical background in alternate streams before proceeding to compare them to regular files and directories. There is then a study of several techniques by which alternate data streams can be exploited by malicious users. The paper then examines software from Microsoft and third-party vendors, evaluating each application's effectiveness in finding and manipulating alternate data streams. Finally, the paper presents a set of Windows shell extensions designed to make alternate stream information an integral part of the operating system and eliminate a loophole that malicious users can use to hide alternate data streams from current scanners.

PDF Format Read the Complete Paper



Current Tags:
None

Add Tags:

Current Rating:
0 (0 votes)

Add Rating:


Similar content:
Shedding some light on Voice Authentication, in Biometrics

Post Comment
Your Name:

Title


Comment You may use Posting Codes in your message.
Security Image:
Type the letters and numbers shown. (This is to prevent automated submissions.)

Cite in Modern Language Association (MLA) Style
"Alternate Data Streams: Out of the Shadows and into the Light" SANS Institute, , UTC. 01 Jul 2008, 17:18 <http://www.sans.org/reading_room/whitepapers/honors/1503.php>

Cite in Chicago Style
Ryan L. Means, "Alternate Data Streams: Out of the Shadows and into the Light," http://www.sans.org/reading_room/whitepapers/honors/1503.php (accessed Jul 01, 2008 ).