You are browsing the archive for 2012 January.

Forensic Riddle #9b – Answer

January 29, 2012 in Forensic Riddles - Answers

NTFS file system is by design case-sensitive, yet this option is disabled by default.

One needs to change the following option in Registry:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel]

and restart the system to be able to create files and directories that are case-sensitive.

Notably, Windows APIs e.g. CreateDirectoryA/W are mapped to NtCreateFile API with OBJ_CASE_INSENSITIVE flag on, so they can’t be used to create case-sensitive files/directories.

Forensic Riddle #9b

January 26, 2012 in Forensic Riddles

This is a second part of the riddle – this time there is no Unicode characters, no GUI attacks, nothing malicious.

Question: What happened here?

