Vulnerability Development mailing list archives

Re: How to hide a file ?


From: Blue Boar <BlueBoar () thievco com>
Date: Tue, 08 Jan 2002 16:46:26 -0800

Apologies, I'm not sure whom I am quoting...

Not to belabour the point, but I don't see a lot of
NT/2K admins doing examinations of last modification
times (or even last access times) during incident
response.  How does someone not necessarily familiar
with or comfortable with working at the command prompt
go about determining what is 'suspicious'?  Or even
via Explorer?  After all, ADSs can be bound to only to
files, but directory listings as well.

I do it all the time:

Start->Find-Files or Folders->Date->during the previous 1 days(s)->Find Now

                                BB


Current thread: