Main > System > System Miscellaneous >

Alternate Data Streams Scan Engine 1.1.0.4

Alternate Data Streams Scan Engine 1.1.0.4

Sponsored Links

Alternate Data Streams Scan Engine 1.1.0.4 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 576 KB
Platform: Windows All
License: Freeware
Price: FREE
Downloads: 37
Date added: 2009-06-26

Alternate Data Streams Scan Engine 1.1.0.4 description

Alternate Data Streams Scan Engine 1.1.0.4 is such a simple and easy to use Alternate Data Streams scanner which will scan your partions for dangerous data streams.

When dealing with network security, administrators often times don’t truly appreciate the lengths that a sophisticated hacker would go through to hide his tracks. Simple defacements and script kiddies aside, a sophisticated hacker with more focused goals looks to a perimeter system breach as an opportunity to progress further inside a network or to establish a new anonymous base from which other targets can be attacked.

In order to achieve this task, a sophisticated hacker would need time and resources to install what is known as a root kit or hacker tools with which he can execute further attacks. With this, comes the need to hide the tools of his trade, and prevent detection by the systems administrator of the various hacking applications that he might be executing on the breached system.

One popular method used in Windows Systems is the use of Alternate Data Streams (ADS). A relatively unknown compatibility feature of NTFS, ADS is the ability to fork file data into existing files without affecting their functionality, size, or display to traditional file browsing utilities like dir or Windows Explorer. Found in all version of NTFS, ADS capabilities where originally conceived to allow for compatibility with the Macintosh Hierarchical File System, HFS; where file information is sometimes forked into separate resources. Alternate Data Streams have come to be used legitimately by a variety of programs, including native Windows operating system to store file information such as attributes and temporary storage.

Amazingly enough, Alternate Data Streams are extremely easy to make and require little or no skill on the part of the hacker.

Alarmingly files with an ADS are almost impossible to detect using native file browsing techniques like command line or windows explorer. In or example, the file size of calc.exe will show as the original size of 90k regardless of the size of the ADS anyfile.exe. The only indication that the file was changed is the modification time stamp, which can be relatively innocuous.

Once injected, the ADS can be executed by using traditional commands like type, or start or be scripted inside typical scripting languages like VB or Perl. When launched, the ADS executable will appear to run as the original file - looking undetectable to process viewers like Windows Task Manager. Using this method, it is not only possible to hide a file, but to also hide the execution of an illegitimate process.

Unfortunately, it is virtually impossible to natively protect your system against ADS hidden files if you use NTFS. The use of Alternate Data Streams is not a feature that can be disabled and currently there is no way to limit this capability against files that the user already has access to.

Major Features:

  1. Scanning one or more NTFS drives for Alternate Data Streams and list them;
  2. Rate them as Good, Risky or Dangerous automatically;
  3. Remove with a single click all to a file attached alternate data streams;
  4. Examine each alternate data stream in the integrated hex editor;
  5. Save the alternate data streams to files;
  6. Remove individual alternate data streams from a file;
  7. Show the status of the Windows Security Center (Vista only).

Enhancements

  • Code optimization only.

Alternate Data Streams Scan Engine 1.1.0.4 Screenshot

Advertisements

Alternate Data Streams Scan Engine 1.1.0.4 Keywords

Bookmark Alternate Data Streams Scan Engine 1.1.0.4

Hyperlink code:
Link for forum:

Alternate Data Streams Scan Engine 1.1.0.4 Copyright

WareSeeker periodically updates pricing and software information of Alternate Data Streams Scan Engine 1.1.0.4 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Alternate Data Streams Scan Engine 1.1.0.4 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
NTFS Alternate Data Streams Viewer is a free tool which will search for alternate streams and allows you to delete them Free Download
ADSTools allows users to find, make and use NTFS Alternate Data Stream files Free Download
Easy way to detect & manipulate(read/write/delete) a NTFS alternate data streams... Free Download
BetterStreams - Easy asynchronous I/O, alternate data streams, and efficient stream seeking Free Download
A useful and advanced data recovery software that helps you recover accidentally deleted files Free Download
FileMetadata.NET working with metadata of file/folders based on NTFS file system Free Download
FireLite is a scan only version of Fire Anti-virus and it contains only limited features Free Download
View and delete alternate data stream files. Free Download