Slacker.exe and Tim...
 
Notifications
Clear all

Slacker.exe and Timestomp.exe

7 Posts
4 Users
0 Reactions
6,416 Views
(@mhibert)
Active Member
Joined: 8 years ago
Posts: 12
Topic starter  

Hi Guys,

I have been searching all Internet for couple of days trying to find these Anti-Forensics Tools slacker.exe which hides secret data in slack space and timestomp.exe that covers timestamps. It seems someone deleted from all possible sources even Metasploit anti-forensics software.

Could you please advice me where websites or sources where it could be found.

Thank you in advance!


   
Quote
bshavers
(@bshavers)
Estimable Member
Joined: 20 years ago
Posts: 211
 

Try here for Timestomp https://www.dfir.training/tools/anti-counter-forensics


   
ReplyQuote
Igor_Michailov
(@igor_michailov)
Honorable Member
Joined: 20 years ago
Posts: 529
 

Hi Guys,

I have been searching all Internet for couple of days trying to find these Anti-Forensics Tools slacker.exe which hides secret data in slack space and timestomp.exe that covers timestamps. It seems someone deleted from all possible sources even Metasploit anti-forensics software.

Could you please advice me where websites or sources where it could be found.

Thank you in advance!

LOL


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

I have been searching all Internet for couple of days …

"*all* Internet" is a rather bold statement. 😯

timestomp
https://www.jonrajewski.com/resources/

Both slacker and timestomp
https://github.com/codejanus/ToolSuite

jaclaz


   
ReplyQuote
(@mhibert)
Active Member
Joined: 8 years ago
Posts: 12
Topic starter  

I came across this link yesterday, but 54KB size of slacker.exe, made me doubt. Anyways, thank you very much 😉


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

I came across this link yesterday, but 54KB size of slacker.exe, made me doubt.

Why?

You don't need megabytes of bloat in simple tools.

Meet the DSFOK toolkit (a good example of compact executables)
http//members.ozemail.com.au/~nulifetv/freezip/freeware/
http//members.ozemail.com.au/~nulifetv/freezip/freeware/dsfok.zip

Sort of dd for Windows
dsfi.exe 5,061 bytes
dsfo.exe 6,637 bytes
fsz 6,144 bytes <- same use as /dev/zero can create files filled with 00's

Anyways, thank you very much 😉

You are welcome ) .

jaclaz


   
ReplyQuote
(@mhibert)
Active Member
Joined: 8 years ago
Posts: 12
Topic starter  

members.ozemail.com.au…/dsfok.zip

I like it very much! Thank you very much again!


   
ReplyQuote
Share: