LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-19-2009, 06:59 AM   #1
Completely Clueless
Member
 
Registered: Mar 2008
Location: Marbella, Spain
Distribution: Many and various...
Posts: 899

Rep: Reputation: 70
Formatting versus wiping


HI all,

When you go through an install procedure and you get to the part that says, "are you sure you want to format this partition; all data will be destroyed!"
It's not technically true, is it? I mean, formatting doesn't wipe all the data on a partition in the same way that over-writing it with zeros using 'dd' for example would do, does it?
Is it possible that re-formatting alone could still leave some malware behind on an infected partition?

thanks.
 
Old 11-19-2009, 07:04 AM   #2
Komakino
Senior Member
 
Registered: Feb 2004
Location: Somerset, England
Distribution: Slackware 10.2, Slackware 10.0, Ubuntu 9.10
Posts: 1,938

Rep: Reputation: 55
Sort of, apart from the malware part. The contents of the data is there, but there is no way to access it directly so there's no way for the malware to run.
 
Old 11-19-2009, 07:07 AM   #3
pixellany
LQ Veteran
 
Registered: Nov 2005
Location: Annapolis, MD
Distribution: Mint
Posts: 17,809

Rep: Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743
"formatting" I think typically means only to install the filesystem. You are correct that it does not destroy all data, but --from the users perspective-- all access to that data is lost.

"malware"--like any other SW--has to be somehow "connected" to the rest of the system---ie a piece of executable code left behind after formatting cannot just magically start running, since nothing in the OS or other SW has a way to call it.
 
Old 11-19-2009, 08:43 AM   #4
Completely Clueless
Member
 
Registered: Mar 2008
Location: Marbella, Spain
Distribution: Many and various...
Posts: 899

Original Poster
Rep: Reputation: 70
Okay, thanks guys. That's as I thought. The only point of wiping therefore is if you might have some credit card numbers or other secure ascii data lying around on a disk; they can still be read, but programs can't be run.
 
Old 11-19-2009, 08:55 AM   #5
pixellany
LQ Veteran
 
Registered: Nov 2005
Location: Annapolis, MD
Distribution: Mint
Posts: 17,809

Rep: Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743Reputation: 743
Correct--the data (and the malware) can still be read---but only using raw device access. For example, recovery SW such as photorec or testdisk uses raw device access.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] wiping HDD using /dev/urandom versus /dev/zero, a theoretical question H_TeXMeX_H Linux - General 6 06-29-2009 06:55 AM
Wiping out Vista TentativeChaos Linux - Newbie 3 04-07-2008 07:13 PM
Wiping the HD NEVICA Linux - Newbie 7 02-20-2008 03:35 PM
Wiping MBR? orange400 Linux - General 8 06-25-2004 09:30 AM
Suggested way of wiping HD mymojo Linux - General 4 12-01-2003 01:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration