Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsWhite Papers
Discussion GroupsFirst AidDatabasesJavaBeansGUIJava 3DVirtual MachineCORBASecurityToolsGeneral
Java DirectoryOpen Source ProjectsSample Book ChaptersUser GroupsWeb Resources
Related Topics
Databases.NETMore Topics ...

Java Forum / General / April 2007

Tip: Looking for answers? Try searching our database.

Potential embarrassment, Joudres and alternate Streams

Thread view: 
Roedy Green - 04 Apr 2007 19:06 GMT
I have discovered a potential embarrassment to Java developers.

Microsoft Windows has a rarely used feature called alternate streams,
something like Mac file forks, that allows you to attach little
descriptive files of metadata to your files.

The SysInternals people, now bought out by Microsoft, have a utility
called STREAMS.EXE to detect and optionally delete them.
http://www.microsoft.com/technet/sysinternals/FileAndDisk/Streams.mspx

The Joudres virus exploits this and hides in the alternate stream/
fork.  It attaches itself to every image file on your machine.  You
can then unwittingly pass it on embedded in image files. It does not
appear to be all that harmful, but it could be embarrassing.

Neither of the three virus checkers I used are aware of it. It never
occurs to them to look in image files, or in the alternate stream.

I discovered the little beasts when I was defragging and found tiny
locked files interfering with the defrag process.  You can perhaps
most quickly detect if you have the problem with a trial version of
O&O defragger http://mindprod.com/jgloss/defragger.html
and do an analyse followed by a double click on the drive and look at
the locked file report. Look for files of the form
myfile.png$joudres....
Signature

Canadian Mind Products, Roedy Green, http://mindprod.com
Priorities: Prevent global climate destabilisation. End both wars. Prepare for oil shortages.

Lew - 04 Apr 2007 23:54 GMT
> I discovered the little beasts when I was defragging and found tiny
> locked files interfering with the defrag process.  You can perhaps
[quoted text clipped - 3 lines]
> the locked file report. Look for files of the form
> myfile.png$joudres....

Ad-Aware checks alternate streams.

Signature

Lew

Jeff Higgins - 05 Apr 2007 01:49 GMT
> Microsoft Windows has a rarely used feature called alternate streams,

<http://msdn2.microsoft.com/en-us/library/aa364404.aspx>

<http://msdn.microsoft.com/msdnmag/issues/06/01/NETMatters/>


Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.