I was peeking into the WOF compression a bit, trying to figure out if I can directly create compressed file (instead of creating it "raw", then packing with IOCTL/compact.exe). Turns out wof.sys will block any attempt to open :WofCompressedData ADS :(
-
-
havent tested- if you want me to do that then send me a cmd to use it. If you look at fltCreateFile you can see there is a input for what filter to start at to avoid infinite loops it will be skipped. fltCreateFile ends up in iocreatefile - reverse and duplicate the technique
-
compact /c /s /a /exe:lzx "filename" Then simply open/read the filename. However filename:WofCompressedData will be hidden and opening will get access denied.
End of conversation
New conversation -
-
-
Thanks. So... no chance of bypassing the wof.sys while it's still loaded, I guess?
-
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.