Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Security Incidents mailing list archives

RE: strange windows behaviour.
From: "Pepijn Vissers" <vissers () fox-it com>
Date: Thu, 9 Oct 2003 15:57:37 +0200

//One trick that hackers are exploiting is to store executable 
//files as NTFS Streams.  You should check you registry for 
//programs set to run at startup with the following format
//      rundll32.exe C:\Some\Directory:trojan.dll
//NTFS Streams cannot be listed by the dir command.  What you 
//can do to verify the existence of one of the Streams is to do
//
//      notepad.exe C:\Some\Directory:trojan.dll
//
//If you see content, then the stream is really there.

Very true. There is a tool that will help you, called LADS (List
Alternate Data Streams), which is a modified 'dir'. Get it at
http://www.heysoft.de/nt/ep-lads.htm.

Best regards,
Pepijn Vissers

--
P. Vissers
Fox-IT Forensic IT Experts B.V.
www.fox-it.com

---------------------------------------------------------------------------
----------------------------------------------------------------------------


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]