Hiding data from En...
 
Notifications
Clear all

Hiding data from Encase

27 Posts
13 Users
0 Likes
1,853 Views
Beerbaron
(@beerbaron)
Posts: 71
Trusted Member
Topic starter
 

Are there ways to hide data on a hdd that Encase wont be able to find? ?

 
Posted : 24/03/2010 10:01 pm
(@jonathan)
Posts: 878
Prominent Member
 

Password protection of a file/container usually means that the data will be 'hidden' from EnCase.

 
Posted : 24/03/2010 10:35 pm
Beerbaron
(@beerbaron)
Posts: 71
Trusted Member
Topic starter
 

So password protecting a .rar file for example would hide the contents from Encase

 
Posted : 24/03/2010 10:55 pm
jhup
 jhup
(@jhup)
Posts: 1442
Noble Member
 

Nothing will make data "invisible" (other than destruction), but encryption will make it uninterpretable.

So no, password protecting a "rar" file will not make it invisible.

 
Posted : 25/03/2010 12:10 am
Beerbaron
(@beerbaron)
Posts: 71
Trusted Member
Topic starter
 

Are their places on a hdd that would make it difficult to find then?

 
Posted : 25/03/2010 1:18 am
(@jonathan)
Posts: 878
Prominent Member
 

Are their places on a hdd that would make it difficult to find then?

Can I ask why you'd want to know?

 
Posted : 25/03/2010 1:25 am
Beerbaron
(@beerbaron)
Posts: 71
Trusted Member
Topic starter
 

Im studying a computer forensics masters, nothing sinister ) More interest than anything

 
Posted : 25/03/2010 2:04 am
(@neofito)
Posts: 18
Active Member
 

try this tool, is very interesting (but not definitive, of course)

Slacker - First ever tool that allows you to hide files within the slack space of the NTFS file system.

http//www.metasploit.com/data/antiforensics/slacker.exe

 
Posted : 25/03/2010 2:32 am
Beerbaron
(@beerbaron)
Posts: 71
Trusted Member
Topic starter
 

Thanks, I have already used that tool before

 
Posted : 25/03/2010 2:46 am
(@swako)
Posts: 18
Active Member
 

Here are a few tweets from @Disklabs (www.disklabs.com) about hiding data…

@robtlee @Schizophreud You spoke to me about data recovery. Hashing a disk - I put data on it - hash it again - same hash.

@robtlee @Schizophreud Makes no difference. We put data in system areas. Nothing can find it - well no standard equipment or software anyhow

@swako Looked at the hash thing. No good for me. We can only do this on certain hard drives - we access the system area and write there below the level that Encase, FTK, or any other tools can access, hence the hash isnt changed.

 
Posted : 25/03/2010 3:13 am
Page 1 / 3
Share: