Welcome to Smokey's Security Forums.
Guests have only limited access to the board and it's features, please consider registering to gain full access!
Registration is free and it only takes a few moments to complete.

Smokey's Security Forums

Please login or register.

Login with username, password and session length
Advanced search  

News:

According to hundreds of reports posted in the past 48 hours on Russian forums and blogs, there's a new computer worm currently spreading and infecting users on ICQ.

New ICQ Worm Infects Thousands of Users

Multilingual OTL (OldTimer ListIt) Log Analysis * Multilingual OTL Tutorials * OTL Downloads * Malware Removal * Microsoft Security Info & Alert Center * Official Jetico Inc. Support Forums

Share this topic on FacebookShare this topic on MySpaceShare this topic on Del.icio.usShare this topic on DiggShare this topic on RedditShare this topic on StumbleUponShare this topic on TwitterAuthorTopic: Question about secure wipe of deleted data?  (Read 714 times)

0 Members and 1 Guest are viewing this topic.

Jetico

  • Jetico Support Engineer
  • *
  • Offline Offline
  • Posts: 684
Re: Question about secure wipe of deleted data?
« Reply #8 on: February 04, 2010, 07:20:04 AM »
BCWipe can wipe only file slacks with the command line. Let me cite the info from our Help documentation:

================
To run BCWipe for wiping file slacks, run BCWipe.exe with the following parameters:

BCWipe.exe FileSlack [-Mode] [-Options] [file or folder name or @listFile] [file or folder name]...

[Options]

View - Start BCView twice before and after file slack wiping.
@listFile - Text file where every file name starts from a new line.
EXAMPLE:
> BCWipe FileSlack -UD3 -View C:\Test.txt


Note that when you run BCWipe.exe with the FileSlack parameter, the program does not shred the file itself, it only wipes slack of the file. Neither contents of the file, nor its attributes become changed.
====================================================
Average reported time... Certainly it is not "days" but rather "minutes" or "hours" for large amount of files.

JTW555Topic starter

  • Member
  • *
  • Offline Offline
  • Posts: 5
Re: Question about secure wipe of deleted data?
« Reply #7 on: February 04, 2010, 07:08:15 AM »
And one last question.  Is there any option on just doing file slacks in of there own wipe? 

As in, can one wipe free space one day?  Then do a only file slacks wipe another time?

And I understand that there is no way to predict like you were saying.  But there must be an average reported time.  Are people ever reporting it taking days to wipe file slacks with one wipe?  Or are they saying in general something like 6 hours or something?

Jetico

  • Jetico Support Engineer
  • *
  • Offline Offline
  • Posts: 684
Re: Question about secure wipe of deleted data?
« Reply #6 on: February 04, 2010, 06:10:34 AM »
Time for wiping file slacks depends on how many files reside on the disk.
It hardly can be estimated somehow.

BCWipe allows to skip some files/folders during this procedure.
It is recommended to skip all system folders like Windows, Program Files, Boot, Program Data, etc.

I would like to add that wiping process will take more time on fragmented disks.
So it is recommended to run defragmentation previously to speed up the process.

JTW555Topic starter

  • Member
  • *
  • Offline Offline
  • Posts: 5
Re: Question about secure wipe of deleted data?
« Reply #5 on: February 04, 2010, 05:14:17 AM »
Sorry, I meant how long it would take with all those other options turned on that you mentioned last.

And by slack files I meant "File Slacks".

Would those be significant on time?  Doing your time math with just wiping I'm coming out with it just under an hour probably for one pass.  Three passes would probably be about 2 1/2 hours.  What would adding on all those other features probably cost on time (assuming the hd did 50mb/sec)?

Jetico

  • Jetico Support Engineer
  • *
  • Offline Offline
  • Posts: 684
Re: Question about secure wipe of deleted data?
« Reply #4 on: February 04, 2010, 04:05:09 AM »
I guess that by "slack files" you mean files that were deleted previously.
Certainly, BCWipe wipes such files.
You understand right that many factors are involved in this, but generally the speed of wiping free space is equal to the speed of writing.
So, if your hard drive allows writing with the speed, say, 50mb/sec, then the time will be:
(130*1024)/50 seconds for one pass.

This evaluation concerns only free space, without wiping options -
'wipe swap file', 'wipe MFT records', 'wipe file slacks' (slack space of existing files).

JTW555Topic starter

  • Member
  • *
  • Offline Offline
  • Posts: 5
Re: Question about secure wipe of deleted data?
« Reply #3 on: February 03, 2010, 11:39:21 PM »
I apologize.  I was going to ask about BCwipe after I got an answer to this. 

So, I'm guessing if I did a wipe with BCwipe on the "free space" that should pretty much take care of that old data then, correct?

Also, I have read that BCwipe can deal with files like slack files.  If the hard drive had about 130 gb of free space, including the slack files, how long would it probably take to run BCwipe to deal with all of that (lets just say you only did three passes)?  I know there are many factors involved in this, but lets just say for an average computer how long would that take? 

Jetico

  • Jetico Support Engineer
  • *
  • Offline Offline
  • Posts: 684
Re: Question about secure wipe of deleted data?
« Reply #2 on: February 03, 2010, 04:44:02 AM »
The question is hardly related to BCWipe.
You should search Internet for this information.
I have performed the cursory search and it seems that the data are deleted (become rewritable).
I have read on a forum that there is an option "Keep files" when you delete a user account.
If you enabled the option, then the files are not deleted.
But I was not able to find this option on Windows XP.

JTW555Topic starter

  • Member
  • *
  • Offline Offline
  • Posts: 5
Question about secure wipe of deleted data?
« Reply #1 on: February 02, 2010, 10:53:56 PM »
So I gave away my computer to a friend about 4 years ago.  I knew about security a lot less then than I do now.  What I did before I gave it to him was make a new user name and made it an administrator (it was windows xp btw).  I then downgraded my username to a user and had it deleted via the new administrative account.

What I want to know is, did my account (programs, internet history/cache, pictures, videos, etc.) become rewritable data, aka free space?  Or did it somehow do something else?  Also, what happened to my index.dat files for that account (rewrittable data or retained somewhere else)?

Thanks for any information.
 

* Permissions
You can't post new topics.
You can't post replies.
You can't post attachments.
You can't modify your posts.
BBCode Enabled
Smilies Enabled
[img] Enabled
HTML Disabled


Except where otherwise stated, all content © 2006 - 2010 Smokey Services™ -- All rights reserved
Design of all board graphics, banners and images by Emma aka Tinker - © 2006 - 2010 Smokey Services™ -- All rights reserved
Smokey's Security Forums is member AQMRB - Alliance of Qualified Malware Removal Boards™, an organisation of Approved Qualified Malware Removal Help & Support Boards
Member ASAP - Alliance of Security Analysis Professionals™

    

  

Smokey's provide fully qualified OTL (OldTimer ListIt) Log Analysis & Malware Removal services in English, German and Spanish language