Re: Hidden files on NTFS

From: TageTora (tagetoraat_private)
Date: Tue Sep 17 2002 - 12:00:49 PDT

  • Next message: Eoghan Casey: "RE: Question about brute forcing EFS..."

    Hi Brian,
    
    only a few primary checks. Make sure that your "hidden files tools" work
    fine with NTFS (it may be designed for FAT ¿?). Next, examine the system
    logs searching for bad shutdowns and verify that the reboot was
    successfully accomplished. If the system didn't close fine, the free
    space counter will have troubles with the space used by the virtual
    memory. At last, check that this possible attacker didn't create any new
    partition.
    
    Sorry, I don't know more possibilities.
    
    
    brian levasseur wrote:
    > 
    > I have a 2K sever that I am unable to account for
    > several Gigs of used hard drive space.  I have used
    > several ADS and hidden files tools to no avail.  Are
    > there other ways to hide large amounts of data on
    > NTFS?  Also, I am pretty sure this box is compromised.
    >  It has every service known to man running on it (not
    > just 2K services).  Any help is greatly appreciated.
    
    -----------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Sep 18 2002 - 05:25:18 PDT