Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  Deep Freeze - Low Level VXD

Topic created on: July 21, 2011 17:15 CDT by zvodd .

So i was wondering if anyone had looked at Deep Freeze.
Deep Freeze - http://www.faronics.com/

So my question is, does anyone know how this program keeps a nice frozen version of your system state, on a single hardisk whilst still giving you almost complete system access ( sans the slightly restrictive VXD driver that my block access to the BIOS and have other unknown functionality). And if so is it possible to modify that frozen version of the system?

From what I've read about it, and my experience using it at a few net cafes. Deep Freeze allows you admin access to your operating system(windows for this example); you can install what ever you want on the system(with admin privs), but after a restart, the disk is returned to it's original state.
What seems strange about this is that, in theory you could make a 119GB junk file on your 120GB C: Drive, be able to access  even write it straight over C:\Windows and C:\Program Files. But after a restart it would be restored to it original state.
That seems impossible unless they take advantage of network image storage or the HardDisk's magnetic plates underlying layer of old data: in theory using the right low level driver and a couple of re-reads, you can access data that has been written over a few times, without much difficulty.

BTW Deepfreeze also works with Mac and *nix systems now.

No posts found under this topic.
Note: Registration is required to post to the forums.

There are 31,313 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit