Hiding data from En...
 
Notifications
Clear all

Hiding data from Encase

27 Posts
13 Users
0 Reactions
3,164 Views
Beerbaron
(@beerbaron)
Trusted Member
Joined: 20 years ago
Posts: 71
Topic starter  

Are there ways to hide data on a hdd that Encase wont be able to find? ?


   
Quote
(@jonathan)
Prominent Member
Joined: 20 years ago
Posts: 878
 

Password protection of a file/container usually means that the data will be 'hidden' from EnCase.


   
ReplyQuote
Beerbaron
(@beerbaron)
Trusted Member
Joined: 20 years ago
Posts: 71
Topic starter  

So password protecting a .rar file for example would hide the contents from Encase


   
ReplyQuote
jhup
 jhup
(@jhup)
Noble Member
Joined: 16 years ago
Posts: 1442
 

Nothing will make data "invisible" (other than destruction), but encryption will make it uninterpretable.

So no, password protecting a "rar" file will not make it invisible.


   
ReplyQuote
Beerbaron
(@beerbaron)
Trusted Member
Joined: 20 years ago
Posts: 71
Topic starter  

Are their places on a hdd that would make it difficult to find then?


   
ReplyQuote
(@jonathan)
Prominent Member
Joined: 20 years ago
Posts: 878
 

Are their places on a hdd that would make it difficult to find then?

Can I ask why you'd want to know?


   
ReplyQuote
Beerbaron
(@beerbaron)
Trusted Member
Joined: 20 years ago
Posts: 71
Topic starter  

Im studying a computer forensics masters, nothing sinister ) More interest than anything


   
ReplyQuote
(@neofito)
Active Member
Joined: 17 years ago
Posts: 18
 

try this tool, is very interesting (but not definitive, of course)

Slacker - First ever tool that allows you to hide files within the slack space of the NTFS file system.

http//www.metasploit.com/data/antiforensics/slacker.exe


   
ReplyQuote
Beerbaron
(@beerbaron)
Trusted Member
Joined: 20 years ago
Posts: 71
Topic starter  

Thanks, I have already used that tool before


   
ReplyQuote
(@swako)
Active Member
Joined: 16 years ago
Posts: 18
 

Here are a few tweets from @Disklabs (www.disklabs.com) about hiding data…

@robtlee @Schizophreud You spoke to me about data recovery. Hashing a disk - I put data on it - hash it again - same hash.

@robtlee @Schizophreud Makes no difference. We put data in system areas. Nothing can find it - well no standard equipment or software anyhow

@swako Looked at the hash thing. No good for me. We can only do this on certain hard drives - we access the system area and write there below the level that Encase, FTK, or any other tools can access, hence the hash isnt changed.


   
ReplyQuote
Page 1 / 3
Share: