Full Disclosure mailing list archives

RE: Windows covert channel


From: "Bojan Zdrnja" <Bojan.Zdrnja () LSS hr>
Date: Mon, 20 Oct 2003 12:40:46 +1300

 

-----Original Message-----
From: full-disclosure-admin () lists netsys com 
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of 
James Kelly
Sent: Monday, 20 October 2003 12:04 p.m.
To: full-disclosure () lists netsys com
Subject: [Full-disclosure] Windows covert channel

I seem to remember in the dim reaches of my memory a covert 
channel in 
the Windows file system where you could paste one file at the end of 
another without it being detectible when you edited the orginal file.


can someone aim me at the right "buzz phrase" that describes this so I 
can Google it further?

You are probably referring to ADS (Alternate Data Stream).
Find more info in this nice paper:

http://patriot.net/~carvdawg/docs/dark_side.html

Regards,

Bojan Zdrnja

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: