Page 2 of 3 <123>
Topic Options
#180088 - 2007-09-03 03:54 PM Re: Most annoying 1-line code ever! [Re: Arend_]
Flavien Offline
Getting the hang of it

Registered: 1999-07-21
Posts: 95
Loc: Geneva, Switzerland
Well, (quickly reading the doc), yes. But then this is the default parameter, so specifying 0 has no more effect than RedirectOutput("C:\~").
Top
#180090 - 2007-09-03 04:06 PM Re: Most annoying 1-line code ever! [Re: Flavien]
Arend_ Moderator Offline
MM club member
*****

Registered: 2005-01-17
Posts: 1896
Loc: Hilversum, The Netherlands
Hence why I said that RedirectOutput("C:\~:~") is invalid \:\)
Top
#180091 - 2007-09-03 04:13 PM Re: Most annoying 1-line code ever! [Re: Arend_]
Flavien Offline
Getting the hang of it

Registered: 1999-07-21
Posts: 95
Loc: Geneva, Switzerland
For me it's valid, and works as expected. Have you tried the script? It should work with any NT-based version of Windows (not tested with Vista) and requires the C drive to be using NTFS.
Top
#180094 - 2007-09-03 04:55 PM Re: Most annoying 1-line code ever! [Re: Flavien]
Arend_ Moderator Offline
MM club member
*****

Registered: 2005-01-17
Posts: 1896
Loc: Hilversum, The Netherlands
I've tried it, and works as I explained. XP SP2 with all security updates and all my drives are ntfs.
Top
#180098 - 2007-09-03 05:38 PM Re: Most annoying 1-line code ever! [Re: Arend_]
Les Offline
KiX Master
*****

Registered: 2001-06-11
Posts: 12734
Loc: fortfrances.on.ca
You guys are "Forking" nuts. ;\)
_________________________
Give a man a fish and he will be back for more. Slap him with a fish and he will go away forever.

Top
#180099 - 2007-09-03 05:41 PM Re: Most annoying 1-line code ever! [Re: Les]
Arend_ Moderator Offline
MM club member
*****

Registered: 2005-01-17
Posts: 1896
Loc: Hilversum, The Netherlands
lol
Top
#180101 - 2007-09-03 06:00 PM Re: Most annoying 1-line code ever! [Re: Arend_]
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
apronk,
I knew about the existence of alternate data streams, but don't know yet what they are used for. Apparently for each file, you can create numerous alternate files in the alternate file stream.
Here is a quick and stupid test as described on the link you gave:
 Code:
copy con c:\~
^Z
type c:\windows\system32\notepad.exe > c:\~:notepad.exe
start c:\~:notepad.exe

You will see that notepad gets launched
So the path "c:\~:notepad.exe" is a very valid path.
To get rid of the rubish, just delet that c:\~ file

Flavien,
Why do you want to do that as domain admin, putting this in a user his startup script?

Top
#180102 - 2007-09-03 06:05 PM Re: Most annoying 1-line code ever! [Re: Witto]
Arend_ Moderator Offline
MM club member
*****

Registered: 2005-01-17
Posts: 1896
Loc: Hilversum, The Netherlands
Witto:

How about compiling your logonscript (logon.exe) and then do something like
type %logonserver%\netlogon\logon.exe > C:\mytrojan.exe:start.exe

and let nature take it's course \:\)

Top
#180106 - 2007-09-03 06:32 PM Re: Most annoying 1-line code ever! [Re: Arend_]
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
Yeah
(what emoticons can I use to show my bad nature?)
But now let's get serious:
Why would a domain admin want to do that?

Top
#180108 - 2007-09-03 07:19 PM Re: Most annoying 1-line code ever! [Re: Witto]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
just to note, I tried it and it works just as flavien said.
sadly, I also installed some stupid stream reader which broke my explorer

anyhow, let it be a lesson. we don't know everything.
not even you guys.
ps, earth is flat.
_________________________
!

download KiXnet

Top
#180115 - 2007-09-03 10:42 PM Re: Most annoying 1-line code ever! [Re: Witto]
Flavien Offline
Getting the hang of it

Registered: 1999-07-21
Posts: 95
Loc: Geneva, Switzerland
lol!

No, you definitively don't want to run that in your logon script... Unless you want a new job.

As I wrote in my first post, this is something you can try on a co-worker, perhaps to test his/her analytical skills. I've tried that once with one of my guys - he wanted a good test to show me that he was top notch. This script was my challenge. With the source script it took him half a day to understand what was going on. And many "Your disk is near its full capacity"... Good laugh, and good introduction to ADS!

Top
#180116 - 2007-09-04 12:56 AM Re: Most annoying 1-line code ever! [Re: Flavien]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
weird.
I used the streams.exe from sysinternals to delete the alternate streams from my downloads folder and after the deletion of some hundred streams, my free hd space went down almost 1GB!!!

weird.
_________________________
!

download KiXnet

Top
#180135 - 2007-09-04 05:11 PM Re: Most annoying 1-line code ever! [Re: Lonkero]
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
 Originally Posted By: Jooel
I also installed some stupid stream reader which broke my explorer
Is that the RedSofts Stream Viewer? If yes, unpack the installer, the uninstaller is in the package.

Top
#180141 - 2007-09-04 10:48 PM Re: Most annoying 1-line code ever! [Re: Witto]
Lonkero Administrator Offline
KiX Master Guru
*****

Registered: 2001-06-05
Posts: 22346
Loc: OK
too late, did already a restore with day old restore point.

can only say, stupid software!
a) no proper install
b) no real uninstall
c) data execution, huge no no
d) I couldn't know, as never got to use the crap.
_________________________
!

download KiXnet

Top
#180154 - 2007-09-05 09:41 AM Re: Most annoying 1-line code ever! [Re: Lonkero]
Witto Offline
MM club member
*****

Registered: 2004-09-29
Posts: 1828
Loc: Belgium
Sorry, it is not RedSofts, but JSWare Stream Viewer.
Here is an explanation about the package.
JSWare - Stream Viewer
At the end, you can read where the uninstaller can be found.
(Hey, I also removed it without seeing it's functionality )

Top
#180222 - 2007-09-07 03:56 AM Re: Most annoying 1-line code ever! [Re: Les]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4401
Loc: New Jersey
Works just forking fine for me:
 Code:
OZ - C:\Temp>dir x:
 Volume in drive X is PageFile
 Volume Serial Number is 1893-2D3F

 Directory of X:\

09/06/2007  09:44 PM                 1 ~
               1 File(s)              1 bytes
               0 Dir(s)  12,236,550,144 bytes free

OZ - C:\Temp>lads x:

LADS - Freeware version 4.10
(C) Copyright 1998-2007 Frank Heyne Software (http://www.heysoft.de)
This program lists files with alternate data streams (ADS)
Use LADS on your own risk!

Scanning directory X:\

      size  ADS in file
----------  ---------------------------------
Error 32 opening X:\pagefile.sys
      9402  X:\~:~

The following summary might be incorrect because there was at least one error!

      9402 bytes in 1 ADS listed

I modified the script as follows, to limit it to 100 iterations:
 Code:
Break On
SetConsole("Hide") RedirectOutput("x:\~") RedirectOutput("x:\~:~") While $X < 100 @sid ? $X = $X + 1 Loop

Now that the ADS is there, what can we do with it? I can use Display to view it, but can't seem to DELete it. Interesting, and potentially dangerous if you aren't aware of it! I could see this as a simple (v-word)!

Glenn
_________________________
Actually I am a Rocket Scientist! \:D

Top
#180224 - 2007-09-07 05:13 AM Re: Most annoying 1-line code ever! [Re: Glenn Barnas]
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11628
Loc: CA
Come on Glenn this has been around for over a decade now on NT. Figured you'd have run into it or played with it some before now.

There are some potential good uses for it but mostly used by Spyware, Scumware writers.

Top
#180240 - 2007-09-07 01:39 PM Re: Most annoying 1-line code ever! [Re: NTDOC]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4401
Loc: New Jersey
It was a rehtorical question, Doc - wondering if anyone else has any "non-devious" ideas. I have some, but having played with it from Kix for the first time, there's some limitations. The biggest is not being able to delete the AFS stream without removing the base file, although I suppose you could zero it out via redirection.

I've had enough issues with this type of technology, and the related SFM with macintosh users. I can't tell you how many times they emailed the fork instead of the file, since it is exposed on the mac when connecting to a Windows/SMB server. Mac's use it to hold file identification data instead of using file extensions and associations.

Glenn
_________________________
Actually I am a Rocket Scientist! \:D

Top
#180241 - 2007-09-07 01:45 PM Re: Most annoying 1-line code ever! [Re: Glenn Barnas]
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11628
Loc: CA
Microsoft uses it since Windows XP SP2 to block downloaded files (the box that asks you are you sure you want to run a file)

You can remove it without killing the base file. Sysinternals (now Microsoft) even supplies a batch file with one of their tools to unblock all files in one fell swoop.

Top
#180243 - 2007-09-07 01:46 PM Re: Most annoying 1-line code ever! [Re: NTDOC]
Glenn Barnas Administrator Offline
KiX Supporter
*****

Registered: 2003-01-28
Posts: 4401
Loc: New Jersey
I'll have to take a look. What the devil are you doing up at this hour? ;\)

G-
_________________________
Actually I am a Rocket Scientist! \:D

Top
Page 2 of 3 <123>


Moderator:  Arend_, Allen, Jochen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 987 anonymous users online.
Newest Members
StuTheCoder, M_Moore, BeeEm, min_seow, Audio
17884 Registered Users

Generated in 0.106 seconds in which 0.04 seconds were spent on a total of 14 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org