Disk Wiping by any other name Flashcards
What was the name of the Windows built-in disk wiping utility?
Cipher
How did Cipher work?
By filling a file with enough data to consume all available unallocated space
What was the problem with Cipher?
Could take up too much space so the OS would hang up
Windows doesn’t delete file data. What does it do when the delete file command is executed?
It marks the physical space that the files occupy as unallocated and available for reuse
What are the two problems caused when a disk sanitizer fails to overwrite old MFT entries?
Information can be inferred from these and some data may still remain if small enough
Were the majority of disk wiping utilities effective at removing Alternate Data Streams?
No
Did the majority of disk wiping utilities effectively remove small datafiles that were present in the MFT?
No
Why do the disk wiping utilities frequently miss small files that are stored in the MFT?
The area where these reside is not slack space
Do disk wiping utilities typically clean the registry hive?
No
What is the other category of utilities that are designed to be used prior to repurposing or recycling disk drives?
Disk sanitizers and disk purgers
Of the 7 disk wiping utilities analyzed, how many were shown to be effective?
One
What is the term used to describe data that was unaffected by the disk wiping?
HKLM is an example