OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Kurt Seifried (bugtraqseifried.org)
Date: Thu Jan 10 2002 - 21:14:41 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Just a note: Tripwire will pick it up, i.e. if you add an ADS to a file
    tripwire will flag it, and if a file has an ADS that is modified or removed
    tripwire will also flag it (with MD5sum/etc just like a normal file). The
    other good news is if you add an ADS stream to a directory such as WINNT or
    system32 it will detect it. Of course any files or dirs not listed in your
    policy will escape tripwire, but then that's no big surprise. So my advice:
    use ADS on files specifically excluded by tripwire if you want to hide
    things.

    Kurt Seifried, kurtseifried.org
    A15B BEE5 B391 B9AD B0EF
    AEB0 AD63 0B4E AD56 E574
    http://www.seifried.org/security/