11 ms·
Windows NTFS Tricks Collection
- strkek 8y agoLast time I checked you could create a directory with a name "like:this" from Linux or something, and Windows would display it but not allow you to access it in any way. Have they fixed this? (Just pure curiosity)
- marzell 8y agoI think that was outlined as one of the very first tricks in the post. I don't have a system available at the moment to test that with. Also, it explores doing the same thing without a Linux system, and shows the various ways such files/folders can/cannot be accessed.
- kingaillas 8y agoI can't view the post right now, so no idea about the content or if anything is fixed, but that colon syntax is supported by NTFS and called "alternate data streams". Granted the feature isn't exactly prominent and tools have various support for them, but it is getting better. Powershell's Get-Item has a -stream option, for example.
- eco 8y agoAs a teenager in the 90s I remember using a trick where if you created a directory on the command line with the character inserted by pressing alt-255 (I think) in the name you couldn't access it from the Windows GUI. Very useful for hiding stuff from my parents. I imagine this was FAT32 but can't remember for certain.
- aksss 8y agoAlt-255 was/is ascii null if I remember correctly
- da_chicken 8y agoNo, Alt-255 corresponds to ASCII character 255, which is a non-breaking space character.
- Avery3R 8y agoAlt-255 corresponds to code-page 437 255, which is ascii 160
- raphlinus 8y agoUnicode 0+00A0 (decimal Unicode codepoint 160). ASCII only defines 0..127.
- da_chicken 8y agoNo, ASCII stops at 127. Everything above that is extended ASCII specific to a code page. As you say, DOS's code code page is 437 [0], and character 255 is a non-breaking space on code page 437. The problem you're having is that you're using Windows, which uses either Windows-1252 or UTF-16-LE (Windows Unicode). On those code page, non-breaking space is 0xA0 (160). Windows is converting extended ASCII 255 from code page 437 to either Windows-1252's [1] non-breaking space, which is 0xA0 or 160, or UTF-16-LE's code page [2] where non-breaking space is 0x00A0. The glyph is silently translated. However, even on Windows 10 you can still get to a place where you're using the original code page of 437. Fire up cmd.exe. Run "chcp" and it should tell you that the active code page is 437. Run "copy con C:\text.txt" to create a new file from the console input. Type <Alt+255>. Press Enter. Hit F6 or Ctrl+Z and hit enter to finish the file. Now type "powershell.exe -Command "[io.file]::ReadAllBytes('C:\text.txt')"". Your output will be: 255 13 10 That's code page 437's extended ASCII non-breaking space followed by carriage return and line feed. Now run "type text.txt". You'll get blank output lines. Now run "powershell -Command "Get-Content text.txt"". Your output will be "ÿ" which is Windows-1252 or Unicode character 255 or 0xFF. Even if you try "Get-Content text.txt -Encoding ASCII" you won't get the same output as you do from cmd.exe because PowerShell's ASCII encoding is actually code page 20127 (7 bit ASCII), not code page 437. Now try to run "powershell.exe -Command "[int][char]'<Alt+255>'"". You'll get 160. That's also why you can fire up PowerShell and type this: '<Alt+255>' -eq '<Alt+0160>' And the result is true. (Note: Alt codes with a leading zero indicate a Unicode alt code.) Windows is translating the glyph from the alt code for you in the background. You have to use a program which doesn't try to do that for you. [0]: https://en.wikipedia.org/wiki/Code_page_437 https://en.wikipedia.org/wiki/Code_page_437 [1]: https://en.wikipedia.org/wiki/Windows-1252 https://en.wikipedia.org/wiki/Windows-1252 [2]: https://www.fileformat.info/info/unicode/char/00a0/index.htm https://www.fileformat.info/info/unicode/char/00a0/index.htm
- lysp 8y agoUsed to hide games on my high school's network using that trick.
- poizan42 8y agoWhat is there to fix? The colon has a special meaning to the Windows NTFS driver - if you use that in a filename then that file is inaccessible with that driver. If you put a null or forward slash in a filename on an ext2 filesystem then that file becomes inaccessible on linux, should they somehow "fix" that?
- derefr 8y agoPresumably, fsck-ing the NTFS volume (or the Windows equivalent) should canonicalize the colon into some escaped/mangled form, since it isn't valid for it to be there in the filename.
- deleted 8y ago[deleted]
- Sylos 8y agoOf course, they should. It may be hard to fix it, too hard for it to be worth the disruption in stability, but it is a design error that breaks user expectations and can cause severe issues when interoperating with other filesystems. And with NTFS, this is much more severe than your example with ext2. For one, ext2 is a niche filesystem at this point, users practically never interact with an ext2 filesystem. It's not the main filesystem used on Linux. And secondly, as a user, I have created files with '/', ':', '*', '?', '"', '<' or '>' in the name ('\' and '|' are also forbidden on Windows, but I admittedly have not yet needed those AFAIK). Not being able to use these characters limits the ways I can express myself in what a file contains. For example, I've had to rename a list with different levels of grouping from "List of members: City > Lastname > Firstname.pdf" to "List of members - City, Lastname, Firstname.pdf". And I'm still not convinced the recipients of that file actually understood that the levels of grouping were listed in the filename in the order from biggest to smallest grouping level.
- blattimwind 8y agoYou can still put in backslashes from Linux as well. Technically NTFS allows for this (Win32 vs. Unix-y namespaces).
- ppog 8y agoThey di seem to have fixed this, at least as far as WSL is concerned. If I open a bash shell on Win10 and do `echo foo >/mnt/d/temp/like:this` then I can open the resulting file in Notepad and see the content `foo`. `mkdir like:this` works too. The file or directory name does appear a bit mangled in Explorer, but still works (and still looks like a colon from inside bash). I think you are right that this used not to work in earlier versions of WSL. You could use colons within the WSL home directory, but not on the mounted NTFS drives. But it seems sorted now.
- j4_james 8y agoInterestingly, when you create a file name from the WSL shell using reserved Windows characters, those characters will get mapped to unicode codepoints from the private use area when viewed in Windows. So for example a colon (\u003A) will show up in Windows as \uF03A. This means you can create a filename in Windows using the character \uF03A, and that character will show up in the WSL shell as a colon. You can even do the same thing with "regular" characters, e.g. using \uF061 instead of "a", and produce a filename that appears to be ASCII in the WSL shell, but is not actually accessible.
- chungy 8y agoThis is compatible with the mechanism Cygwin came up with: https://cygwin.com/cygwin-ug-net/using-specialnames.html#pathnames-specialchars https://cygwin.com/cygwin-ug-net/using-specialnames.html#pat...
- lloeki 8y agoMac OS X maps filenames between slash `/` and colon `:` to match with UFS, the colon used to be the path separator on old MacOS, which HFS+ inherited. Try it: $ touch foo:bar $ open . # Look at the filename in Finder. # Try it the other way around by saving a file # with / in TextEdit, then ls in Terminal. [0]: https://stackoverflow.com/questions/13298434/colon-appears-as-forward-slash-when-creating-file-name#13298479 https://stackoverflow.com/questions/13298434/colon-appears-a...
- cryptonector 8y agoOh dear. How fun! These little sins are truly terrible. I prefer openat(2) and friends for dealing with ADS. It means you have to have specialized programs to deal with them from shell scripts, as open(2) and friends provide no naming conventions for getting at ADS. This approach is much much safer than the WIN32 approach of using :$HACK_ME_PLEASE and :$THANK_YOU_MAY_I_HAVE_ANOTHER. Note that Linux has openat(2), but it doesn't support ADS. Solaris/Illumos does. Linux has xattrs, which, like ADS in Solaris/Illumos, requires separate system calls to access -- no open(2) naming conventions there. Both, ADS and xattrs are extremely useful. Let's say you need to associate some metadata with a file, but you can't change its contents' format. You could use some separate file that goes with it, but now you can't atomically rename(2) the thing... But with ADS/xattrs you just attach those to the file, and then when you rename(2) the file the ADS/xattrs go with it atomically. (Yes, you could rename a directory, but it doesn't quite have the same semantics as renaming a file. In particular, rename(2) of a directory won't rm -rf the target if it exists.)
- voltagex_ 8y agoSite is down, http://web.archive.org/web/20180613213214/https://movaxbx.ru/2018/06/13/windows-ntfs-tricks-collection/ http://web.archive.org/web/20180613213214/https://movaxbx.ru... should be an archive but I can't check from my current location
- bb88 8y agoImages seem to be down off the archive, so it's hard to see what he's talking about really.
- rbanffy 8y agohttps://webcache.googleusercontent.com/search?q=cache:4L1CWH8fqqQJ:https://movaxbx.ru/2018/06/13/windows-ntfs-tricks-collection/+&cd=1&hl=en&ct=clnk&gl=ie https://webcache.googleusercontent.com/search?q=cache:4L1CWH... seems OK
- nkkollaw 8y agoWhen I used Windows, I remember you couldn't create folders named "con", for compatibility reasons. It kind of sucked because it means "with" in Italian, and I often could have organized files within "with"/"without"subfolders.
- kingaillas 8y agoThat's just one of the many reserved file/device names in Windows! "Do not use the following reserved names for the name of a file: CON, PRN, AUX, NUL, COM1, COM2, COM3, COM4, COM5, COM6, COM7, COM8, COM9, LPT1, LPT2, LPT3, LPT4, LPT5, LPT6, LPT7, LPT8, and LPT9." [0] [0] https://msdn.microsoft.com/en-us/library/windows/desktop/aa365247(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
- cesarb 8y agoNote, they are not just reserved names, they are reserved names with any extension. So when a Unix user checks in a file named "aux.c" to your project, it will cause problems for Windows users.
- deleted 8y ago[deleted]
- aksss 8y agoCon was short for console, I think. “Copy con:test.bat” was a quick way to create and fill out a batch file provided you could write it error-free in one go.
- rbanffy 8y agoIt's appeal is mostly you didn't need to use `edlin`.
- marcofatica 8y agostill works on win10! and you can backspace, but only the current line, so don't press enter until you're really sure
- zokier 8y agoAre ADS used for anything useful anywhere? It is kinda interesting how long MS has been carrying that feature around, especially as it is not really highly advertised feature; is it really even supported? ADS does constantly pop up in these sorts of (semi-)malicious contexts, simply dropping them seems like sensible thing.
- MikusR 8y agoAll the new compression methods use them. Also windows Subsystem for Linux.
- mehrdadn 8y agoAFAIK the Windows subsystem for Linux only uses extended attributes, not alternate data streams. But yes, :WofCompressedData is used for the (awesome) transparent read-only LZX compression.
- MikusR 8y agohttps://blogs.msdn.microsoft.com/wsl/2016/06/15/wsl-file-system-support/ https://blogs.msdn.microsoft.com/wsl/2016/06/15/wsl-file-sys... says that something is also kept in ads
- mehrdadn 8y agoOh wow, interesting, thanks for sharing! So it says: > In addition, if a file has any file capabilities, these are stored in an alternate data stream for the file. Note that WSL currently does not allow users to modify file capabilities for a file. I've never actually seen this used... I wonder what commands would trigger it?
- orf 8y agoThey are used extensively in SQL server, as well as Windows itself. It's a pretty fundamental part of the NTFS design and you can't just drop it. ADS underpins pretty much every FS operation on windows, including listing directories. MacOS has something similar.
- mehrdadn 8y ago> Another interesting fact is that ADS names can contain symbols which are normally forbidden for filenames like ” or * OK, this is going to completely mess up all of my (and most likely everyone else's) shell scripts. I always assume these characters cannot legally occur on Windows anywhere in the path... _________________________________________ And wow, this is quite clever and also quite difficult to foresee: > The best security vulnerability to explain directory junctions is in my opinion AVGater, where the attacker places a file in folder x. Then he marks the file as a virus and the installed AntiVirus solution will move it into the quarantine. After that the attacker removes the folder x and replaces it with a directory junction named “x” which points to C:\windows\System32\. If the attacker now clicks on the “restore” button the AntiVirus solution will copy the file to the x folder which now points to system32 with SYSTEM privileges (which directly leads to EoP).
- quietbritishjim 8y agoFor that second one: That sounds like a vulnerability in virus scanners even without junctions, although junctions make it enormously easier to exploit: * Create a directory in a location you have permission to, but you think a higher-privilege user will create it later. * Create and quarantine a file in it. * Delete the directory. * When the higher privilege user creates the directory, you can restore your file into it. The fix is for virus scanners to operate at user permission level when restoring the file.
- zaat 8y ago> The fix is for virus scanners to operate at user permission level when restoring the file. "user permission" as such doesn't exist, it is always a specific user. Which user should the restore function run as? There is no easy solution to this, as the restore must be able to restore the file to locations like the windows directory as well as directories that only specific user have access to, like a home folder on a file server.
- quietbritishjim 8y ago> Which user should the restore function run as? The one that clicks the "restore" button. > the restore must be able to restore the file to locations like the windows directory Then the user will need to get the help of someone with an admin account i.e. their IT department (they probably have an admin account themself if it's a home computer). If this happened regularly it would be a problem, but how often do virus scanners false positive on system files and users quarantine them? I would bet not very often.
- dc_gregory 8y agoIf you created some directories to test, you can delete them with bash (whatever git installs works). It does create nested directories, so you need to do: rmdir .../.../ rmdir .../
- ocdtrekkie 8y agoSpeaking of, my favorite stupid Windows trick I discovered, was before long file support, you could get nested folders too long for Windows to handle due to some cool bugs and couldn't delete them with rmdir. But I discovered I could robocopy sync a blank folder over them, and it was more than happy to oblige. robocopy is seemingly a more robust deletion tool than rmdir.
- ygra 8y agord might work when prefixing the path explicitly with \\?\; robocopy likely already uses that syntax internally to deal with long paths.
- gcbw2 8y agowonder if the "...\...\" trick can be used to overflow the counter of files to delete and execute arbitrary data as the system user.
- beefhash 8y agoAnother fun thing you can do with NTFS transactions: process doppelgänging; see https://hshrzd.wordpress.com/2017/12/18/process-doppelganging-a-new-way-to-impersonate-a-process/ https://hshrzd.wordpress.com/2017/12/18/process-doppelgangin...
- 0x9000beaf 8y agohow about using the original website of the researcher who identified all of this and not just a cheap copy? https://www.sec-consult.com/en/blog/2018/06/pentesters-windows-ntfs-tricks-collection/ https://www.sec-consult.com/en/blog/2018/06/pentesters-windo...
- txdv 8y agoThose tricks look like exploits to me. O, russian domain xD
- rbanffy 8y agoAssuming bad intentions from nationality is kind of racist. I get the tricks (and the examples given) seem to be usable maliciously, but we need to know the threats so we can protect against them.
- MaxBarraclough 8y agoThat's not what 'racist' means.
- pbhjpbhj 8y agoIt's within some dictionary definitions of racist; but xenophobia is barely better. Most people don't have control over their nationality.
- leibnitz27 8y agoI wrote a shell extension some time ago to make playing with ADS easier : http://www.benf.org/other/alternatestreamoverlay/index.html http://www.benf.org/other/alternatestreamoverlay/index.html
- SecABC 8y agoThe original blog can be found here: https://sec-consult.com/en/blog/2018/06/pentesters-windows-ntfs-tricks-collection/ https://sec-consult.com/en/blog/2018/06/pentesters-windows-n... The author of the above blog copy & pasted the full article, explicitly removed the author names and references to the original source. That's pretty disappointing.
- exikyut 8y agoWoohoo! The copy-paste URL now says > ОЙ! СТРАНИЦА НЕ НАЙДЕНА. > По данному адресу ничего не найдено. Попробуйте воспользоваться поиском. Google Translated: > OH! PAGE NOT FOUND. > Nothing was found at this address. Try to use the search. In case the URL is changed, it currently points at https://movaxbx.ru/2018/06/13/windows-ntfs-tricks-collection/ https://movaxbx.ru/2018/06/13/windows-ntfs-tricks-collection...
- landave 8y agoWow. It appears that movaxbx.ru copied multiple of my blog posts as well[1][2][3][4]. I wonder how hard it would be to take legal action (in particular to stop them from doing this altogether, as opposed to just taking down a single article). The site appears to be hosted in Russia[5]. From a quick glance over the Wikipedia page[6], it seems to me that Russian copyright law is quite similar to copyright law in most developed countries. [1]: https://movaxbx.**/2018/06/05/f-secure-anti-virus-remote-code-execution-via-solid-rar-unpacking/ https://movaxbx.**/2018/06/05/f-secure-anti-virus-remote-cod... [2]: https://movaxbx.**/2018/05/04/7-zip-from-uninitialized-memory-to-remote-code-execution/ https://movaxbx.**/2018/05/04/7-zip-from-uninitialized-memor... [3]: https://movaxbx.**/2018/05/04/7-zip-multiple-memory-corruptions-via-rar-and-zip/ https://movaxbx.**/2018/05/04/7-zip-multiple-memory-corrupti... [4]: https://movaxbx.**/2018/05/04/bitdefender-heap-buffer-overflow-via-7z-lzma/ https://movaxbx.**/2018/05/04/bitdefender-heap-buffer-overfl... [5]: http://ip-api.com/#movaxbx.ru http://ip-api.com/#movaxbx.ru [6]: https://en.wikipedia.org/wiki/Copyright_law_of_Russia https://en.wikipedia.org/wiki/Copyright_law_of_Russia
- sctb 8y agoWe've updated the link from https://movaxbx.ru/2018/06/13/windows-ntfs-tricks-collection/ https://movaxbx.ru/2018/06/13/windows-ntfs-tricks-collection.... Sorry for the trouble!
- jaclaz 8y agoSimilar to the ... (Trick 3) here is some fun with ALT+0160: https://msfn.org/board/topic/131103-win_nt~bt-can-be-omitted/?do=findComment&comment=842843 https://msfn.org/board/topic/131103-win_nt~bt-can-be-omitted...