25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CO42019 – Project 4<br />

Modify <strong>the</strong> sectors<br />

• Produce a pice <strong>of</strong> code that directly modifys <strong>the</strong> Hex Data contained with <strong>the</strong><br />

drive secotrs.<br />

• This will bypass <strong>the</strong> file locking.<br />

• This process would be slower, as it would need to copy <strong>the</strong> entire log file, but<br />

would be harder to detect.<br />

Swap <strong>the</strong> pointers<br />

• Produce a piece <strong>of</strong> s<strong>of</strong>tware that modifys <strong>the</strong> pointers to <strong>the</strong> cluster chains<br />

• This would bypass <strong>the</strong> file locking.<br />

• This process would be fast since it only has to change a coulpe <strong>of</strong> dozen Hex<br />

values, however, it would be easier to detect since <strong>the</strong> ‘new log’ cluster chains<br />

would start nearer to <strong>the</strong> end <strong>of</strong> <strong>the</strong> disc.<br />

Project – Week 5.doc Page 3 <strong>of</strong> 8

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!