Vulnerability Development mailing list archives

Re: How to hide a file ?


From: "J. J. Horner" <jhorner () 2jnetworks com>
Date: Wed, 9 Jan 2002 10:26:14 -0500

* H C (keydet89 () yahoo com) [020109 09:59]:
JJ,

<snip> 
When I ran the above, I didn't get a listing for
Sol.exe *at all*.  I tried using the Task Manager,
pulist.exe, as well as pslist.exe from SysInternals. 
In every case, the new process showed up as
'explorer.exe'.

Very odd behavoir.

Now, I made a change to the setup above.  Instead of
an executable, I put the ADS behind a text file:

C:\ads>type c:\winnt\system32\sol.exe > 
c:\ads\myfile2.txt:sol.exe

Running it w/ the 'start' command appears as
'myfile.txt' in Task Manager, pulist, and pslist. 


I did the following:

C:\>cd ads

C:\ads>type c:\winnt\system32\sol.exe > c:\ads\myfile2.txt:sol.exe

C:\ads>start c:\ads\myfile2.txt:sol.exe

C:\ads>

When I right-click on the Taskbar, and select Task Manager, I see
solitaire on the Applications tab, and myfile2.txt on the Processes list.

Perhaps my terminology was different, and that misled you.  Regardless of
terminology, though, solitaire does show up in the Applications listing.

Now, if we could mask the application from the Application tab, which I don't doubt
will be somewhat trivial, we will be in business.

I hope this clears it up.

Thanks,
JJ


-- 
J. J. Horner
"H*","6a686f726e657240326a6e6574776f726b732e636f6d"
***************************************************
"H*","6a6a686f726e65724062656c6c736f7574682e6e6574"

Freedom is an all-or-nothing proposition:  either we 
are completely free, or we are subjects of a
tyrannical system.  If we lose one freedom in a
thousand, we become completely subjugated.

Attachment: _bin
Description:


Current thread: