Penetration Testing mailing list archives

RE: Wiping Solaris Servers


From: "Levenglick, Jeff" <JLevenglick () fhlbatl com>
Date: Thu, 13 Sep 2007 09:23:12 -0400


Easy- free way.. 

http://www.sun.com/software/solaris/trustedsolaris/ts_tech_faq/faqs/purge..xml

Nut shell -
Run format, get defect list, run purge, get second defect list, purge again.

More About format

The format command works as follows when purging a disk.

   1. Three patterns are written to the disk:

      0xaaaaaaaa
      0x55555555
      0xaaaaaaaa
   2. The disk is read to verify that the third pattern is in each location.
   3. If the read pass is successful, the alpha_pattern is written to each location.

      0x40404040

-----Original Message-----
From: listbounce () securityfocus com on behalf of Brett Cunningham
Sent: Wed 9/12/2007 10:07 PM
To: Holstein, Robert - BLS CTR
Cc: pen-test () securityfocus com
Subject: Re: Wiping Solaris Servers
 
Darik's Boot and Nuke
dban.sourceforge.net

-B



On 9/12/07,  Holstein, Robert - BLS CTR <Holstein.Robert () bls gov> wrote:
 Hey everyone,

I need to find a method of securly wiping Solaris servers using the DOD
standard disk sanitization requirements. So far the only thing I have
come up with is customized bootable Solaris CD of some sort with bcwipe
on it.  There has got to be a better way.  Does anyone know of a
bootable (or other) solution that's a little less complicated.
Essentially we would need the end process to be so easy a monkey could
perform the task.

Ideally, during the surplus phase a wharehouse employee would boot the
server up, run a simple command, and the server would be on its way...

Any assistance is apprecited.

Regards,
Bobby



------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
 Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------





------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



-----------------------------------------
This e-mail message is private and may contain confidential or
privileged information.

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------


Current thread: