Alternate Data Streams is a file system vulnerability, where the attacker can easily hide the malware in the Alternate Data Stream(ADS) of the file so that it can’t be scanned by the traditional file viewing softwares.
To understand the Alternate Data Streams, you’ve to read the following article which outlines it’s origin and how it’s useful in today’s world. It also showcases the security challenges which ADS faces.
💡
Article :
Even the size of test.txt will be zero if nothing is written in test.txt and secret.txt has some text.
To pass the exe file into the text file’s ADS, we can use the below command:
Still 0 KB
Now, we’ll need privileges in order to perform the winupdate link change so that we can run the executable. We can use UACMe to gain escalated privileges and run cmd.exe instead of the payload (backdoor.exe) with escalated privileges and then make this symbolic link.
SOCIAL SHARE CARD GENERATOR