OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[Full-Disclosure] Re: Windows Registry Analzyer

From: Dave Korn (davek_throwawayhotmail.com)
Date: Thu Mar 03 2005 - 13:39:45 CST


"Eric Windisch" wrote in message news:1109872449.8117.25.camellocalhost...
> Perhaps this is just the Unix user in me, but I ask:
> How about just making a copy of the registry on boot (or at intervals)
> and compare it to the last copy?
>
> Note that the following example is untested, but should be mostly
> accurate.

  No, it would be completely useless. In case you didn't realise, the
registry is not an ASCII text file, it's megabytes of unintelligible binary
gibberish.

    cheers,
      DaveK
--
Can't think of a witty .sigline today....

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html