Question

In: Computer Science

What is an Alternate Data Stream? How is time stomping performed? What is the command to...

  1. What is an Alternate Data Stream?
  2. How is time stomping performed?
  3. What is the command to display an ADS from the command line?
  4. How do you encrypt a file using the EFS feature of NTFS?
  5. What is the byte range for in decimal for the first partition?
  6. What number indicated that a partition is bootable?
  7. What does LBA stand for and what does it do?
  8. The Master Boot Record ends with what signature?

Please answer this question in an easy way?

Solutions

Expert Solution

1. Alternate Data Stream which is also termed as ADS is a program feature of Windows NTFS (New Technology File System).
It contains metadata that helps locating a specific file. It has compatibility support with all versions of Windows starting from Windows NT.
It is used to store file information such as attributes and temporary storage.

2.Time stomping is a technique that modifies the timestamps of a file like modify,access,create and change time of file.
This is often used to duplicate files with same attributes in a folder. Time stomping can be performed using various procedures like APT28,APT32, 3PARA RAT etc..

3. You can use Command dir /R to display an ADS from command line

4. Here's how you can encrypt file using EFS

  • Launch File Explorer from StartMenu/Desktop/Taskbar.
  • Right click the file or folder that has to be encrypted.
  • Select Properties.
  • Click Advanced.
  • Check the checkbox next to encrypt contents to secure data.
  • Click OK.
  • Click apply.

5. The byte range of the First Partition(Boot Partition) is -
446 to 461 in decimal and 1BE to 1CD in hexadecimal

6. Hex numbers

7. LBA stands for Logical Block Addressing.It is common model scheme that helps in specifying the location of blocks of data stored on computer storage devices,generally secondary storage devices like hard disks. It provides a simple linear address space to the host which only needs to to provide the LBA address without knowing anything of the physical sector positions.

8. Disk Signatures


Related Solutions

1. Define NTFS alternate data stream( 1 Marks). What is the Significance of whole disk encryption...
1. Define NTFS alternate data stream( 1 Marks). What is the Significance of whole disk encryption and challenges it poses in digital forensics investigations?Total
In AutoCAD, ILLUSTRATE how the following command prompts can be performed and INDICATE when it is...
In AutoCAD, ILLUSTRATE how the following command prompts can be performed and INDICATE when it is necessary to perform EACH command prompt. Note that all steps are very important and must be mentioned. (i) EXPLODE (ii) LAYERS (iii) HATCH (iv) TRIM AND EXTEND (v) BREAK (vi) CALIBRATING PAPER SIZE (vii) FILLET (viii) CREATING TABLE (ix) OFFSET   
What is alternate (differential) splicing? How do specific splicing factors regulate alternate (differential) splicing?
What is alternate (differential) splicing? How do specific splicing factors regulate alternate (differential) splicing?
What is the advantage of ln command over cp command?
What is the advantage of ln command over cp command?
What is the incident command system (ICS)? How does it work and why is it a...
What is the incident command system (ICS)? How does it work and why is it a good basis for National Incident Management System in USA
What are the key activities performed in the implementation phase and how are they connected in...
What are the key activities performed in the implementation phase and how are they connected in project management?
Explain what the stroop test is, how its performed and what are the strengths of its...
Explain what the stroop test is, how its performed and what are the strengths of its research.
Consider how the economy has performed throughout your life. Identify a time you believed the economy...
Consider how the economy has performed throughout your life. Identify a time you believed the economy was in a peak or a trough. When was the economy expanding? When was it contracting? Describe the overall trajectory of the economy throughout your life.
How is nitric oxide generated in vivo, and why is its production important? What alternate sources...
How is nitric oxide generated in vivo, and why is its production important? What alternate sources of nitric oxide exist and what advantages or disadvantages might these offer? what is the link between dietary nitrate and nitric oxide? Give examples where this approach has been applied effectively to humans?
1. What command is used to change the current working directory at the command line?
1. What command is used to change the current working directory at the command line?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT