Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, April 12, 2009

Secure Drive Wiping postscript…

Posted on 1:00 PM by Unknown

In a very recent GSD post Economic Stimulus Package Linkfest I covered the following items related to secure free-space disk wiping:

  • Eraser – Freeware secure erasing tool has gotten a radical site update.
  • Eraser 6-rc4 released! – Amazing new and fresh GUI to Eraser. Still has some bugs to be worked out. Looks like it will be a great update when finally released. Not sure if it will survive in a “portable” mode release as I think .NET will be required moving forward.
  • InstallingBetas – Eraser – Read this page as well as you need to download a signed security certificate to install the latest Eraser beta versions. Not that big a deal, but a bit of work.
  • Disk Redactor – New free disk freespace wiping tool (portable) that I found this week. I like the interface and it seems to run very fast.

Side note: Is it just me or do none of these freespace wiping program tools seem to work under Vista very well. I think I’m missing something here. I’ve been playing with them and I can run DiskDigger and find a large number of deleted (but recoverable) files. Then I do a freespace wipe (as admin level) using either of these tools. Then I rerun DiskDigger and the files are still all there and recoverable. Surely I’m doing something wrong? It’s not just the “names” but the actual files themselves as I can preview most of them just fine in the clear. Thoughts?

It took me a while but I eventually worked it out. Turns out I didn’t RTFM closely enough:

Turns out this issue looks like a "Doh!"moment. I went back and re-read the DiskDigger product info and on the page (linked above) found this tidbit: "Because DiskDigger bypasses the file system of the device being read, it will detect files that haven’t been deleted in addition to files that have. This means that you might have to sift through files that still “exist” in the file system before you find a file that’s actually been deleted. However, the Preview feature makes this process quick and painless."

Looks like the freespace was probably getting wiped effectively after all. DiskDigger is just displaying all files it finds. I'm going to have to retest with Recuva as I believe it only reports truly "deleted" files. That and do some sector-based testing as well (create file, observe sector location, delete file, wipe freespace, go back with sector viewer tool and see if now gone).

I did—in fact—go back and use Recuva to test a number of free-space wiping tools.

Turns out that Eraser appeared to offer the most effective free-space wiping solution when using Recuva to count the number of files that could be potentially recovered after free-space wiping.  There wasn’t much left to see after Eraser chewed on things.

In getting to that point as I was doing research, I located yet another tiny tool that could be used to clear free-space on a drive.

SDelete – Microsoft Sysinternals – This is a command-line only tool that has a number of flexible options for secure wiping and cleaning of free space.  It is tiny and relatively fast at what it does.  Mark Russinovich also goes into great detail explaining just what the tool does and why it is good information to know about.  Read the page closely to understand the command-line arguments particular to it as well as the method it uses.

Then there is the previously described…

cipher.exe -- nV News Forums.  Another command-line only tool that should be present on most XP/Vista systems, this Microsoft utility can also wipe out deleted files and remnants from free-space on a drive.  The basic command is CIPHER /W:directory  so to wipe the free space on your C: partition you would issue the command CIPHER /W:C:

Add these tools to the CLI tools those I have also mentioned here for whole disk wiping:

Team up XP/Vista’s DISKPART and the “clean all” command to zero out a physical drive, or try “wipe.exe” which is included as part of the Forensic Acquisition Utilities package offered by George M. Garner Jr.  I spent some time a few weeks ago playing with this one and it is very fast and full-featured. (for example: use the command: wipe –w 00 \\.\PhysicalDrive0 to irrevocably zero out the primary physical drive.)

Yes there are lots of other larger, GUI-based tools to secure wipe a disk/system/freespace, but with proper usage, these free and tiny CLI tools should cover most of your storage sanitization needs pretty well.

Want more information?

Secure Wipe/Delete Utilities - Provider Wiki – University of Pennsylvania information page.  Great overview discussion on secure wipe/delete tools with lots of great links.

Looking for something with more a more technical bent?

SANS white paper - Secure Deleting – Excellent paper from John R. Mallery and SANS Institute that details the whole package relating to secure deleting of file information on storage media.  Covers unallocated space, slack space, common files created by the system and applications that may contain useful information for forensic investigators and system administrators, methods of erasing data securely, verification methods, discussion of legal and ethical issues, and a lot of great links and reference material to pursue further.

Additional Grand Stream Dreams Subject Reading

Partition and Disk Management: Part IV – Secure Wiping – Grand Stream Dreams blog

Secure Disk-wiping Software – Grand Stream Dreams blog

Security and Forensics Roundup #4: Eyes on you – Grand Stream Dreams blog

Cheers.

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in command-line interface, hardware, security, utilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ▼  April (9)
      • Weird but Fixed
      • Clever Printing Tricks
      • Security and Utility Linkfest Smackdown
      • Secure Drive Wiping postscript…
      • Chrome/Chromium Theming…maturing nicely.
      • Economic Stimulus Package Linkfest
      • Clever Card Design
      • Give IT a Break!
      • Cleaning up the Attic: Convert command
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile