<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2009://3/tag:ask-leo.com,2007://3.3057-</id>
  <updated>2009-12-09T23:48:56Z</updated>
  <title>Comments for What are alternate data streams, and are they a security risk?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

  <entry>
    <id>tag:ask-leo.com,2007://3.3057-comment:40543</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2007://3.3057" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html#c40543" />
    <title>Comment from David Spector on 2009-11-30</title>
    <author>
      <name>David Spector</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Alternate data streams are used by some antivirus software (Kaspersky Labs) to store a unique "hash" value that works as a short signature that represents the file contents. The allows the antivirus program to detect any simple change in contents that does not also update the signature stream. The cost of this otherwise excellent feature is the expansion in disk size of every file.</p>

<p>By the way, the excellent freeware program <b>FileAlyzer 2</b> has a tab for showing the Alternate data streams in any file, including special (inaccessible) streams such as <b>Security</b> and <b>Object identifier</b>. The default stream type is <b>Alternate</b>.</p>

<p>Alternate data strings can be nested. Internally, an alternate string named foo is represented as :foo:$DATA, so some alternate stream programs may use this syntax.</p>

<p>In Windows, Microsoft Word uses an alternate data stream to store extra information about a file, such as the Author name. Also, downloaded files are marked by the presence of an <b>Alternate</b>-type stream named <b>:Zone.Identifier</b>, which contains the text "INI file"</p>

<p>[ZoneTransfer]<br />
ZoneId=3</p>

<p>to indicate which "Zone" was used for the download (3 means "Internet"). On the Properties context dialog box for the file, you can click Unblock to delete this stream.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html">What are alternate data streams, and are they a security risk?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-11-30T13:56:27Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2007://3.3057-comment:29238</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2007://3.3057" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html#c29238" />
    <title>Comment from Michael Dalton on 2007-12-11</title>
    <author>
      <name>Michael Dalton</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Hello Leo,</p>

<p>The erasure software programme 'Cyberscrub' provides an option to erase Alternate Data Stream files. CyberScrub warns that it will try to save the ADS Main File(s) when it is deleting the others, but it does not guarantee that it will be able to do so. Are these Main Files essential to the healthy operation of the platform (XP) - can I risk their erasure? Can anyone know? If CyberScrub fails to preserve one, some, or all of the Main Files, will these be regenerated, if necessary/essential, at the next boot, or could erasure result in a catastrophe? </p>

<p>It seems a wee bit anomalous that a programme which is designed to execute comprehensive erasure processes cannot in fact do this safely, because of the existence of these files which move in mysterious ways.</p>

<p>Cyberscrub  searches for, and identifies, the ADS files on your system. The ADSs it finds on mine are as follows:-</p>

<p></p>

<p>C:\Documents and Settings\All Users\...1:     :encryptable $DATA (1 entry)</p>

<p>C:\Documents and Settings\My Name\...1     :Zone Identifer:$DATA (3 identical entries)</p>

<p>C:\Documents and Settings\My Name\...1     :Favicon:$DATA (1 entry)</p>

<p>C:\RECYCLER\S-1-5-21-124738149-13...1 :Zone Identifier:$DATA (3 identical entries)</p>

<p>C:\System Volume Information\_restor...       :Zone Identifier:$DATA (4 identical entries)</p>

<p>and then dozens of these:-</p>

<p>C:\SystemVolume Information\_restor	        :a:$DATA</p>

<p>Perhaps it is all imponderable.</p>

<p>Best wishes,</p>

<p>MD</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html">What are alternate data streams, and are they a security risk?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2007</a>.</p>
    </content>
    <published>2007-12-11T16:12:05Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2007://3.3057-comment:29237</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2007://3.3057" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html#c29237" />
    <title>Comment from George Birbilis on 2007-06-17</title>
    <author>
      <name>George Birbilis</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>actually there are malware exploiting ADS, else Ad-Aware and other s/w wouldn't be scanning them</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html">What are alternate data streams, and are they a security risk?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2007</a>.</p>
    </content>
    <published>2007-06-17T09:23:00Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2007://3.3057-comment:29236</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2007://3.3057" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html#c29236" />
    <title>Comment from Ken Crook on 2007-06-16</title>
    <author>
      <name>Ken Crook</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Just downloaded and installed LavaSoft Ad-Aware2007.  On the Settings page there is a button for "Scan Alternate Data Streams".  When I saw this I had no idea what it was about.  It is a nice coincidence your newsletter has an article on Alternate Data Streams.  So there is now at least one way to scan for Alternate Data Streams.</p>

<p>Thank you Leo.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html">What are alternate data streams, and are they a security risk?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2007</a>.</p>
    </content>
    <published>2007-06-17T04:32:16Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2007://3.3057-comment:29235</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2007://3.3057" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html#c29235" />
    <title>Comment from Leo A. Notenboom on 2007-06-15</title>
    <author>
      <name>Leo A. Notenboom</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1</p>

<p>To be honest, I'm not sure. I've heard tell that they were an attempt to<br />
provide the same functionality as "forks" I think it is on Macintosh systems at<br />
the time.  If so, I think it was doomed for backwards-compatibility reasons.</p>

<p>But I'm not totally sure.</p>

<p>And again, once in, it's incredibly difficult to remove a "feature" -- for<br />
backwards compatibility reasons. :-(</p>

<p>Leo<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: GnuPG v1.4.6 (MingW32)</p>

<p>iD8DBQFGcryiCMEe9B/8oqERAnLpAKCKLGKUw9xcIAVVyESHm0PiQENK1QCcCsAS<br />
CEZ/ke2Y8mIxskqIC/RV8gY=<br />
=Csa/<br />
-----END PGP SIGNATURE-----</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html">What are alternate data streams, and are they a security risk?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2007</a>.</p>
    </content>
    <published>2007-06-15T16:21:47Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2007://3.3057-comment:29234</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2007://3.3057" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html#c29234" />
    <title>Comment from Dan Ullman on 2007-06-15</title>
    <author>
      <name>Dan Ullman</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Is there a reason that alternate data streams exist?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/what_are_alternate_data_streams_and_are_they_a_security_risk.html">What are alternate data streams, and are they a security risk?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2007</a>.</p>
    </content>
    <published>2007-06-15T15:51:46Z</published>
  </entry>

</feed>
