First, one thousand of thanks at all, for your interest to my problem
Firace wrote:Just one thing to be aware of: ADS is a property of the NTFS file system, so the information is lost if you copy the file to another drive (or if you zip it).
I suppose you talk about a drive in FAT32 ? or even if the drive is in NTFS ?
It's sure i think my tips is not the most secure of the world
But except the case name, it's the more simple i have found

So your way is when even very interesting, at less for learning
Normeus wrote:It is used when you are creating documents so that the system will know you are going to delete this file so it has an option to save to cache.
since you are not creating the file then the system will just ignore #FILE_ATTRIBUTE_TEMPORARY.
Happy to read your advice about my choice

There surely another flag or another simple old function forgotten, or simply not really knowing by everybody, who can be deturned for do something completely different that the first and original function
Anyway, it's the main activity of the hacker to search this style of functions, forgotten of all
Normeus wrote:The only problem I see is that, some backup and replication programs will not copy files marked as temp.
It's good to know that, before throwing his pc in the trash, because he decided not to backup our programs anymore
Mijikai wrote:Run shellcode in another application to override the stateflag once ur application closes.
I don't know really what is Shellcode
You mean, like a batch ? i have do one time this style of way, when i close the exe, i write a batch in tempfolder, with inside the rename of the exe, and after the batch can delete itself
But i don't know it's possible to poke an exe with a script
HanPBF wrote:Normally an exe is not allowed to be changed as malicious software could do so and that's prevented.
A file storing the state beside the exe is the only way or writing in the registry of the user.
Yes you have right, an EXE is not an ACCESS file

I understand perfectly what you say, and it's normal, when we see the engineering of hacker for put something just at the place where nobody thinking

But my request is not for store DATAS, it's all the cool members of this thread who talk about DATAS, me i just ask for store one bit, 0/1, or better 0/255, and i don't think even Kevin Mitnick before the better hacker of the world

can be create malicious thing wit one value 0/255..
Finally i hope

because the legend say he so much strong the judge not allow him to have even a simple calculator when he is condamned
So your two links is very interesting, i don't understand all, but it's more easy to understand how the PE works

Now, i'm not sure that even the ASM can writing in the EXE when it works, because it's surely windows who not allow this behaviour no ??
Interesting new way, even if use it for just a txt file with 0 or 1 inside, it's a little bit, use an elephant for carry your stylus for your smartphone
It's always good to know for sandboxed area...
RSBasic wrote:But be careful: Some antivirus programs sound the alarm.
Yes you have right, it's also a thing to consider
