Alternative Data Streams by Halla
Anyway this is Halla from Information Leak and I'm going to show you some ADS, Alternative Data Streams. Hopefully, I can figure out the zoom on this and make it work a little bit better. In any case, what we’ll going to do is I'm going to create a new text document and we’re going to name it, I don’t know test for example, test.txt. We’ll open it up and I’ll just type in some stuff so you can see it. I’ll make the font a little bigger, there we go, file, save, okay.
So we just created this file. So let's take a look at the properties of it. So here hopefully you can see it, showing here that it is 11 bytes and if we click it you can see here it just says “Hello there” all ready. So back to the desktop and we should be able to take it from there. Now at this point what we’re going to do is, we’re going to take this file over here with audacity. Now if you're unfamiliar with audacity it’s just an audio program freeware, so we double click that. You can see it right here. Audacity opens up just like you would expect. Now what we’re going to do is we’re going to take audacity in this exe and we’re going actually hide it within this text file. And the way we’re going to do that is, we’re going to open up the command prompt just like this here and we’re going to set this up.
So first things, first we got to go to the desktop, so here we are. Actually let me zoom in on this so you can see it a little bit better. Okay, hopefully you can see this a bit better so right now we’re just going to—I forgot the name of the file already, it’s called test.txt and then audacity.exe. So here we go, we’re going to type audacity.exe. We’re going to put that into test.txt:audacity.exe.
Now what that’s going to do is put audacity.exe into the test.txt and that should do it now. Well, not yet, it’s taking an awful long time for whatever reason. I spelled it right. I hope I did, yeah, that will do it. So now, you’ll see it just came up like this here, so now what I’ll do is take audacity and delete it. So say goodbye to audacity and we’ll delete out of the recycle bin as well. And that’s it, so now it’s gone off the desktop and if we look at the test.txt you see that the functionality hasn’t changed. It looks the same and we if we zoom in to the properties you’ll see it’s still the same size as it was previously which was 11 byte. As you can see here 11 bytes still. So now how do we run audacity? Since we’ve put it into this text file, it’s very simple back to your command prompt here. What we’re going to do is we’re going to click were going to type the following.
We’re going to type start and let it know where it is dot slash, we’re going to say test.txt and colon and the executable which happens to be audacity.exe and with the simple click of enter it should load audacity which has been attach to an alternative data stream into the text file and as you can see it has done just that. Hope you enjoy the tutorial. This is Halla from Information Leak, until next time, copy system.
Transcription by:
Scribe4you Transcription Services