Home > Windows Server Tips > Windows Hardware Strategies > Hijacked disks fill overnight: How to take action
Windows Server Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WINDOWS HARDWARE STRATEGIES

Hijacked disks fill overnight: How to take action


Rick Cook, Contributor
07.19.2005
Rating: -3.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Please let us know how useful you find this tip by rating it below. Do you have a useful Windows tip, timesaver or workaround to share? Submit it to our tip contest and you could win a prize!


If you ignore an NTFS disk that fills up suddenly, you should take notice. Not only does a mysteriously full disk waste system resources, but it may also indicate a more serious problem, such as malicious activity or disk corruption.

Generally speaking, if the problem is a mundane one like too-large cluster size, the disk will fill up slowly. But a hijacked or corrupted disk tends to fill very quickly -- literally overnight.

Computer criminals routinely use compromised systems to store everything from stolen copies of files to the tools of their trade, not to mention running everything from FTP sites to illicit chat rooms. These activities can eat up gigabytes of disk space on systems belonging to unsuspecting enterprises. Typically they will hide these files from a routine inspection. However, they can't hide the fact that the disk is suddenly filling up.

Your first step is to check the drive with Internet Explorer with the "display hidden files" option turned on. However, this is only the beginning. The bad guys have a number of techniques for hiding files from IE.

One common method of hiding files involves the use of Alternate Data Streams, a Windows feature which was designed to store properties and other meta-information along with a file. A file stored using Alternate Data Streams (ADS) can be an executable or just about anything else.

The nasty thing about ADS files is that not only don't they show up as separate files in a directory listing, they don't change the displayed size of the file they are attached to. A 1.5 megabyte file stays 1.5 megabytes even if the attached ADS is many gigabytes in size.

To make matters worse, ADS is just about undetectable by tools like Internet Explorer or the Windows command line. Examining the time stamp will reveal the changed file, but the only other tip-off is the sudden growth in disk use for no apparent reason. Generally you need a special tool, such as LADS, which is freeware you can download from http://www.heysoft.de/Frames/f_home_en.htm. LADS will find and remove ADS files from your system.

Depending on the criminal's level of sophistication (or the sophistication of the tools he uses), figuring out what is going on can be a major undertaking. You will probably see other signs of intrusion, such as unexplained network activity or services running on unusual ports.

Another possibility is that the drive has become corrupted by a computer malfunction or power failure. This is a good deal less sinister than an intrusion, but it is still a serious problem. In this case you may have to rebuild or even replace the drive.

In part two, I will look at additional problems that are related to the way Windows Server 2003 and the NTFS work.

Click here to read part two.


Rick Cook has been writing about mass storage since the days when the term meant an 80 K floppy disk. The computers he learned on used ferrite cores and magnetic drums. For the last 20 years he has been a freelance writer specializing in storage and other computer issues.

Rate this Tip
To rate tips, you must be a member of SearchWindowsServer.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Disk Drives and Disk Arrays for Windows
Case Study: Building a low-cost SATA array
How to use the g4u network-based hard disk cloning utility
Create a script to check integrity of your server's drives
Can freezing a hard drive that's crashed restore it to life?
Move from PATA to SATA could complicate data recovery
Use RAID to increase write performance on three-drive arrays
Stop disk drive overload to increase system performance
A Windows administrator's guide to Diskpart commands
Use RoboCopy to copy files from crashed hard disk drives
Findpart utility locates lost partitions on disk

Microsoft Windows Data Backup and Protection
Avoid the big mistakes when backing up virtual servers
Are security concerns over cloud computing unfounded?
How to configure backups and perform restores in Windows Server 2008
When to use VM backups versus snapshots in Hyper-V
Microsoft Hyper-V: Best practices for performance, backups and management
Working with snapshots in Microsoft Hyper-V
Self-healing NTFS keeps admins one step ahead of data corruption
The efficacy of backup-as-a-service solutions
Using WBAdmin to create backups in Windows Server 2008
Breaking down the Windows Server Backup tool for Windows 2008
Microsoft Windows Data Backup and Protection Research

Windows Hardware Strategies
Availability in the virtualized Windows server
Hardware considerations for Windows server virtualization
Scaling Windows server resources for virtualization
Troubleshooting your toughest Windows server crashes
High-tech solutions for monitoring computer heat
Server virtualization at the hardware level with Hyper-V
Virtualization and 64-bit: A match made in Windows heaven
How to use the g4u network-based hard disk cloning utility
Multi-core processors on the desktop offer major boost
When and how to migrate to a 64-bit platform

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cold/warm/hot server  (SearchWindowsServer.com)
Dolly  (SearchWindowsServer.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Server Room Design - Planning, Cooling, Maintenance
HomeTopicsBlogsITKnowledge ExchangeTipsNewsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts