Vulnerability Development mailing list archives

RE: How to hide a file ?


From: "Farahbakhshian, Mike (OD)" <FarahbaM () OD NIH GOV>
Date: Tue, 8 Jan 2002 13:36:56 -0500

I was using vi because I was using Cygwin, not Interix. POSIX, or more
specifically, Cygwin, can be used to handle ADS's because (I believe) it can
*remove* alternate data streams whereas CMD.EXE's 'del' or Windows Explorer
cannot. The tried-and-true method of "copy a file to a non-NTFS partition
and copy it back" then seems like overkill; you can simply embed 'rm' in a
script to remove the data stream and leave the original intact. 



-----Original Message-----
From: Mike Theriault [mailto:Mike_Theriault () Jabil com]
Sent: Tuesday, January 08, 2002 1:32 PM
To: Farahbakhshian, Mike (OD); vuln-dev () security-focus com
Subject: RE: How to hide a file ?


Yes I can reduplicate this, but I'm not sure I see the relevance of using
the POSIX subsystem on Win2K to hide a file.  By the way, where did you get
VI from?  My latest version of Interix doesn't come with it or emacs.

Mike Theriault



Current thread: