Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow Hiding data
EH-Net
May 24, 2013, 03:17:29 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Hiding data  (Read 4482 times)
0 Members and 1 Guest are viewing this topic.
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« on: July 01, 2012, 12:09:30 PM »

Hello all,

After a recent college class (online) about computer forensics, they discussed how evidence can be hidden on a PC nd discovered, but they didnt go into how to hide the data. I am familiar with tools that hide data in files, but I would be interested in learning how to hide data in a hidden partition, or  slack space, ect. anyone know of any resources for learning how to do this? I've heard that you can create a partition, add the data, then delete the partition, but that sounds like the premises for deleting files, while the data is still there, it could be overwritten...
Logged

fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #1 on: July 01, 2012, 01:32:43 PM »

Hey sephstorm,If u using windows u already know every partition in computer has a letter c: d: and... So u can use disk manager to remove the partition's letter and make it hidden
www.windows.microsoft.com/en-us/windows-vista/change-add-or-remove-a-drive-letter
But its better to encrypt data with truecrypt its more secure and trustable.
« Last Edit: July 01, 2012, 01:44:31 PM by cyber.spirit » Logged

ICS Academy Network Security Certified
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #2 on: July 01, 2012, 01:48:39 PM »

Take a look at alternate data streams

http://www.irongeek.com/i.php?page=security/altds
Logged

Joshsevo
Sr. Member
****
Offline Offline

Posts: 278


View Profile
« Reply #3 on: July 01, 2012, 04:17:11 PM »

Alternate data streams.  We learned how to do them in a gov class I took.  You can use a .txt file let's say and save it and alter it somehow...by adding more text to it.. and the file size nor the file itself shows up.  It's pretty tricky.
Logged

Security+, Network+, C|EH, CHFI, CPT
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #4 on: July 02, 2012, 01:50:52 AM »

Hi all, thanks for the replies. First, when it comes to encryption, its a good solution, with one main fault, you can immediately tell that someone is trying to hide something. I remember EFS used to turn the folder title green. Much more subtle is having a hidden folder with no name and a background color icon...

ADS, I remember seeing a few articles about them a while ago, i'll have to look into it. What might be good is to combine all of the above, make an document, add the data on an ADS, encrypt it, and put it on a unallocated drive.
Logged

fred
Sr. Member
****
Offline Offline

Posts: 351


The World is sick, Save your mind...


View Profile
« Reply #5 on: July 02, 2012, 01:20:12 PM »

I remember EFS used to turn the folder title green. Much more subtle is having a hidden folder with no name and a background color icon..
No do not use efs because u may lose data even if u take backup of file's certificate. As i said use truecrypt its free and awsome.
Logged

ICS Academy Network Security Certified
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #6 on: July 02, 2012, 02:24:50 PM »

Check out Volume Shadow Copies as well...


http://www.securitytube.net/video/3767
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.088 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.