LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-31-2010, 01:56 AM   #1
njstaticuser
LQ Newbie
 
Registered: Mar 2010
Posts: 2

Rep: Reputation: 0
Unusual hard drive security method.


I was assigned to erase and fresh install windows on this Dell desktop machine. It has become quite the chore believe it or not! Firstly, I had to remove the CMOS password by shorting some pins on the RTC Timer IC. There was no jumper on the motherboard and removing the battery didn't do anything.

So as soon as I tried installing windows xp pro, it said that it cannot reinstall windows on this machine and crashed. I have seen this before on virus infected machines so I put in my trusty ubuntu disk and ran gparted. Each time I tried making a new dos MBR it would always revert back to an NTFS format. I thought this was kind of weird. So i went under the terminal and went into fdisk to create a new dos partition. No errors!

Great, so I put my windows xp back in but no! I get the same error! So when I put my ubuntu disk back I have the NTFS filesystem back as if nothing happened!!! So i took drastic measures! I ran dd (input was /dev/zero, output was the hardrive root node and I had the conv=noerror flag set) and zero'd out the first 1 Gb of the hardrive. I got an input/output error and it only zeroed out the first 45 MB!! When I restarted Ubuntu it had the entire filesytem intact as if I never did anything!

Now it calls for drastic measures. I took the hardrive out of the computer and placed it into a SATA enclosure. I plugged the enclosure (via USB) into my Macbook and (what a surprise!) NTFS filesystem popped up on my computer. I unmounted it and ran dd again (yes! mac os x is BSD-based!) and it gave the same error! input/output error and only zeroed out 45 MB of the hd! I unmounted it and and remounted it and the NTFS filesystem is back!!

I have never seen this method of security before! I took the board off of the hd to see if there was a hidden device that monitors I/O traffic and found none. It is a SATA Seagate hardrive 40 Gb. On the label it says: "This drive is manufactured by Seagate for OEM distribution". So my question is (and I apologize for the immense explanation, but I couldn't miss a single detail) is there any other utility I can use that can write raw data onto a device like this in linux. I mean I cannot imagine anything lower than dd but it doesn't seem to do the job!!

Thanks! John
 
Old 03-31-2010, 05:40 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599Reputation: 3599
Hello and welcome to LQ. Posting an account of things is nice but cold hard nfo like 'sfdisk -l; hdparm -Ii' would be better.
 
Old 04-01-2010, 09:21 AM   #3
skola
Member
 
Registered: Nov 2009
Posts: 66

Rep: Reputation: 19
If you had an actual disk editor that ran from a booted cd you could examine any sector to see what was there. Experimenting first with a test disk formatted with various ext2,3; fat; ntfs and probably an installed op.sys would let you know what to expect when looking at a dodgy or suspect hdd.

and also, the disk editor should let you modify any sectors, copy and paste etc so you could see if anything was interfering. Plus, doing any partitioning and file system formatting.

I use Acronis Disk Director myself. Alas I've never seen any opensource alternatives.

Last edited by skola; 04-01-2010 at 09:31 AM.
 
Old 04-02-2010, 08:08 PM   #4
njstaticuser
LQ Newbie
 
Registered: Mar 2010
Posts: 2

Original Poster
Rep: Reputation: 0
Thank you!

Thank you very much. Still do not know what the problem is, but I got someone else to figure it out, I just swapped out hard drives and the computer works fine. Thank you again for all of your support!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
I want to know the best method to put a complete linux on usb hard drive madbull737 Linux - Newbie 3 08-13-2009 04:11 AM
Best method to secure erase an external hard drive xri Linux - Hardware 1 01-16-2009 11:40 PM
Want to install FC 5 from a hard drive but don't know the method n need help roonjha Fedora 3 07-28-2006 12:40 PM
Hard drive dying, good backup method cadj Linux - Software 3 12-14-2004 07:28 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration