|
|
File Wiping
When you type 'del file' or 'rm file' to
remove a file, it is
in fact not deleted at all. Usually, all that happens is that the file's name is removed
from the disk's index, but the data still remains on the disk itself. In particular, the
magnetic properties of a hard disk can be exploited to recover data. There are many
undelete programmes
which can easily recover this data. By overwriting the data with random
junk, there is no way to recover it anymore.
More advanced techniques to recover lost data also exist. Overwriting data once is
usually not good enough for these solutions. A popular
standard states that you should overwrite three times with zeros and ones
(zero-one-zero-one-zero-one over every byte), and then with random junk. This should even
erase the magnetic remains of your data, which still can be detected after it has been
overwritten once. Of course, you can overwrite with ones, zeros and random junk
as many times as you like.
Another thing to consider is the file name, location and date/timestamps. Even if you can
erase the data itself, the information about the file may still be availabe in system files
somewhere, giving the attacker some information on the deleted files. Several of the programmes
below are capable of also erasing the filename and related information from the administration
table.
Evidence Eliminator
[ Affiliate Link ]
Some of the things Evidence Eliminator will remove with a single click:
Windows SWAP file
Windows Application logs
Windows Temporary Files
Windows Recycle Bin
Windows Registry Backups
Windows Clipboard Data
Start Menu Recent Documents history
Start Menu Run history
Start Menu Find Files History
Start Menu Find Computer History
Start Menu Order Data
Start Menu Click History
Microsoft Internet Explorer temporary typed URLs, index files, cache and history
Microsoft Internet Explorer AutoComplete memory of form posts and passwords
Microsoft Internet Explorer Cookies (Selective cookie keeping for versions 5)
Microsoft Internet Explorer Internet components (Selective keeping of components)
Microsoft Internet Explorer Download Folder memory
Microsoft Internet Explorer Favorites List
Microsoft Outlook Express v5+ database(Selective keeping of mail and news groups)
Windows Media Player History
Windows Media Player PlayLists in Media Library
America OnLine Instant Messenger contacts
Netscape Navigator temporary typed URLs, files, cache and history.
Netscape Navigator Cookies (Selective cookie keeping for versions 4 and above)
Netscape Mail v4+ sent and deleted e-mails
Netscape Mail hidden files
Customizable lists of files and folders, with or without their contents
Customizable scan lists of file types in specific folders
Customizable scan lists of file types on all drives
Deleted filenames, sizes and attributes from drive directory structures
Free cluster space ("Slack") from all file tips
Magnetic remenance from underneath existing files/folders
All free unallocated space on all hard drives
Evidence of activity in many other programs, using Plug-In modules
Slack space and deleted entries in the Windows registry
Created and modified dates and times on all files and folders
Windows Registry Streams
Common Dialog load/save location history
To witness the full awesome power of Evidence Eliminator, download the Demo software for
yourself by clicking on the banner above
BCWipe v.3
BCWipe software enables you to confidently erase files that can never be recovered by an intruder.
BCWipe embeds itself within Windows and can be activated from the Explorer FILE Menu OR from the
context sensitive (right click) menu OR from a command-line prompt. BCWipe v.3 is a powerful set
of utilities which complies with options to invoke either the US DoD 5200.28-STD standard or the
Peter Gutmann wiping scheme. You can also create and use your own customized wiping scheme to wipe
sensitive information from storage devices installed on your computer.
A free 30 day fully functional trial is available at the Download Centre.
That should give you plenty of time to do what you have to.
Eraser
Eraser is an advanced security tool (for Windows), which allows you to completely remove
sensitive data from your hard drive by overwriting it several times with carefully selected
patterns. Works with Windows 95, 98, ME, NT, 2000, XP and DOS.
Eraser is FREE software and its source code is released under GNU General Public License.
Active@ Kill Disk - Hard Drive Eraser
Active@ KillDisk - Hard Drive Eraser is powerful and compact DOS software that allows
you to destroy all data on hard and floppy drives completely, excluding any possibility
of future recovery of deleted files and folders. It's a hard drive and partition eraser utility.
This is security software for unrecoverable data elimination for any computer capable of booting
in DOS mode from floppy drive. It uses access to the drive’s data on a physical level via BIOS
bypassing logical drive structure organization, thus it does not matter what operating systems
and file systems located on the machine.
Darik's Boot and Nuke
Darik's Boot and Nuke ("DBAN") is a self-contained boot floppy that securely wipes the hard disks
of most computers. DBAN is appropriate for bulk or emergency data destruction.
DBAN is a means of ensuring due diligence in computer recycling, a way of preventing identity
theft if you want to sell a computer, and a good way to totally clean a Microsoft Windows
installation of viruses and spyware. DBAN prevents or thoroughly hinders all known techniques
of hard disk forensic analysis.
An excellent utility - I am never without a copy.
|
Vanish.Org |
Copyright © 2006 |
All rights reserved
|
|
|