<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows Hibernation and hiberfil.sys</title>
	<atom:link href="http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Sat, 05 Nov 2011 19:36:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: EM</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-1816</link>
		<dc:creator>EM</dc:creator>
		<pubDate>Thu, 04 Aug 2011 23:16:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-1816</guid>
		<description>Some more information about HiberFil.sys: http://antiforensics.net/Computer-Forensics/hiberfil-xpress.html

In particular, discussing its compressed state and an EnCase EnScript for parsing it.</description>
		<content:encoded><![CDATA[<p>Some more information about HiberFil.sys: <a href="http://antiforensics.net/Computer-Forensics/hiberfil-xpress.html" rel="nofollow">http://antiforensics.net/Computer-Forensics/hiberfil-xpress.html</a></p>
<p>In particular, discussing its compressed state and an EnCase EnScript for parsing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-1477</link>
		<dc:creator>Alexander</dc:creator>
		<pubDate>Sat, 23 Jul 2011 13:05:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-1477</guid>
		<description>Now, Truecrypt support Hibernation file encryption. 
http://www.truecrypt.org/docs/hibernation-file 
But some issues with hibernation on XP. Use Win 7 and Truecrypt 7+</description>
		<content:encoded><![CDATA[<p>Now, Truecrypt support Hibernation file encryption.<br />
<a href="http://www.truecrypt.org/docs/hibernation-file" rel="nofollow">http://www.truecrypt.org/docs/hibernation-file</a><br />
But some issues with hibernation on XP. Use Win 7 and Truecrypt 7+</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Max</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-921</link>
		<dc:creator>Max</dc:creator>
		<pubDate>Mon, 27 Jun 2011 03:11:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-921</guid>
		<description>That&#039;s why we have an entire forum and author blog dedicated to all encompassing topics, kind sir.</description>
		<content:encoded><![CDATA[<p>That&#8217;s why we have an entire forum and author blog dedicated to all encompassing topics, kind sir.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-900</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Sun, 26 Jun 2011 11:24:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-900</guid>
		<description>Haha, if you&#039;re so worried about forensics then you have other issues than hibernation. Pathetic.</description>
		<content:encoded><![CDATA[<p>Haha, if you&#8217;re so worried about forensics then you have other issues than hibernation. Pathetic.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Sykes</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-380</link>
		<dc:creator>Marc Sykes</dc:creator>
		<pubDate>Sat, 27 Nov 2010 14:29:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-380</guid>
		<description>Hello there.
I agree with facts that you wrote, that&#039;s all true, but you kinda forget to mention, that the hiberfil.sys is not the only file that forensics can use to read your private data. As for example, have you known that windows is actually keeping last 120 pressed  keyboard entryes (for a case of freeze, you can notice that as pressed many keys, and later they all apear at the same time, as windows process them with a delay)... And of course, we should mention the temp files which, esspecially Internet Explorer and Opera browsers are creating to use in a case if they crashes.... =)

Anyway, I do have one question. As I already got a version of SandMan, I kinda can&#039;t get any info about reading hiberfil files... I mean, is it possible that I got incomplete copy of SandMan? I can&#039;t manage to run it... 
One more thing... for what I need it, I got my Win7 x64 on intel i5 in hibernation 3 times (without shutting it down meanwhile), and last time it didn&#039;t wake up, just simply warned me about resume error and all-alone went to normal startup. It&#039;s home version, because it&#039;s original with the laptop, but as I use enterprise (win7 x64 on i7 desktop pc), I know that in enterprise there&#039;s a choice to delete hibernation file, where I simply press ctrl+alt+del and sometimes I actually can resume from hibernation, even though at first windows said it failed. So, as it went to normal startup, of course everything that was opened was &#039;&#039;lost in time&#039;&#039;, or better said, locked in hiberfil.sys. So, at first, I got out the disk and make a backup copy of both hiberfil.sys and pagefile.sys, so I do have them.
As I was reading around, there is kinda no way to force windows to resume hibernation from other hiberfil.sys files, as they said, there appears kernel error a few seconds after resuming. But, I actually once DID success in resuming hibernation from old file in windows xp sp2... I tried here on win7, but when I change the new hiberfil.sys with the olderone, windows doesnt even mention anything at all at startup, it simply goes to &#039;&#039;Starting windows&#039;&#039;... Is there anything I missed? I mean, I searched all over the internet, and, I must confess, your post is kinda interesting and you surely do know much about computers, so I hope that you know at least any little peace of information that I need.
Since the kernel stop and that Windows is from Microsoft, I&#039;m sure everyone who has at least any knowledge about their software knows, that there is NO WAY that they&#039;d make hibernation process as simple as writing everything in hiberfil.sys. There are definitly other informations changed, as bootmgr, where is written the state of pc (hibernation or shutdown etc...), and some system files. So I&#039;m pretty sure that there&#039;s a way of prevent kernel error because of different (but still pretty fresh (not even 1 day old file) and from the same system with same hardware and software, except for time and date, but it can be changed) hiberfil files, also, Microsoft definly has such option left for a security reasons, forensics or any...
Are you maybe having any idea, since I can&#039;t manage to get reply from Microsoft?
Or at least, how to get files such as unsaved printscreens in paint and photoshop, opened tabs in any of browsers, opened notepads (MS Word saves its backups), Cubase (audio tool) recordings, and all similar non-autosaving contents in different programs? It&#039;s not only (also I&#039;d be glad to have it back, but I can live without my tabs and print screens lost... that&#039;s all I had) for me, I want to do at least one step forward in getting information about all this. 
The reason I haven&#039;t save my opened contents is autohibernation on low battery state (which is afterall really good ability for such cases... I have similar setting on my desktop pc, where I made myself sort of cheap ups, which holds up to 2 minutes, and in a case of power blackout small circuit made of a few transistors and ne555 timers triggers via secondary usb &#039;&#039;keyboard&#039;&#039; (modified only with keyboard circuit) a shortcut to batch file which sends a pc into hibernation to save data. So, even in case of some attacks and so, hibernations kinda good ability for me... =)
I&#039;d be glad to get your reply... =)

Bye, Marc</description>
		<content:encoded><![CDATA[<p>Hello there.<br />
I agree with facts that you wrote, that&#8217;s all true, but you kinda forget to mention, that the hiberfil.sys is not the only file that forensics can use to read your private data. As for example, have you known that windows is actually keeping last 120 pressed  keyboard entryes (for a case of freeze, you can notice that as pressed many keys, and later they all apear at the same time, as windows process them with a delay)&#8230; And of course, we should mention the temp files which, esspecially Internet Explorer and Opera browsers are creating to use in a case if they crashes&#8230;. =)</p>
<p>Anyway, I do have one question. As I already got a version of SandMan, I kinda can&#8217;t get any info about reading hiberfil files&#8230; I mean, is it possible that I got incomplete copy of SandMan? I can&#8217;t manage to run it&#8230;<br />
One more thing&#8230; for what I need it, I got my Win7 x64 on intel i5 in hibernation 3 times (without shutting it down meanwhile), and last time it didn&#8217;t wake up, just simply warned me about resume error and all-alone went to normal startup. It&#8217;s home version, because it&#8217;s original with the laptop, but as I use enterprise (win7 x64 on i7 desktop pc), I know that in enterprise there&#8217;s a choice to delete hibernation file, where I simply press ctrl+alt+del and sometimes I actually can resume from hibernation, even though at first windows said it failed. So, as it went to normal startup, of course everything that was opened was &#8221;lost in time&#8221;, or better said, locked in hiberfil.sys. So, at first, I got out the disk and make a backup copy of both hiberfil.sys and pagefile.sys, so I do have them.<br />
As I was reading around, there is kinda no way to force windows to resume hibernation from other hiberfil.sys files, as they said, there appears kernel error a few seconds after resuming. But, I actually once DID success in resuming hibernation from old file in windows xp sp2&#8230; I tried here on win7, but when I change the new hiberfil.sys with the olderone, windows doesnt even mention anything at all at startup, it simply goes to &#8221;Starting windows&#8221;&#8230; Is there anything I missed? I mean, I searched all over the internet, and, I must confess, your post is kinda interesting and you surely do know much about computers, so I hope that you know at least any little peace of information that I need.<br />
Since the kernel stop and that Windows is from Microsoft, I&#8217;m sure everyone who has at least any knowledge about their software knows, that there is NO WAY that they&#8217;d make hibernation process as simple as writing everything in hiberfil.sys. There are definitly other informations changed, as bootmgr, where is written the state of pc (hibernation or shutdown etc&#8230;), and some system files. So I&#8217;m pretty sure that there&#8217;s a way of prevent kernel error because of different (but still pretty fresh (not even 1 day old file) and from the same system with same hardware and software, except for time and date, but it can be changed) hiberfil files, also, Microsoft definly has such option left for a security reasons, forensics or any&#8230;<br />
Are you maybe having any idea, since I can&#8217;t manage to get reply from Microsoft?<br />
Or at least, how to get files such as unsaved printscreens in paint and photoshop, opened tabs in any of browsers, opened notepads (MS Word saves its backups), Cubase (audio tool) recordings, and all similar non-autosaving contents in different programs? It&#8217;s not only (also I&#8217;d be glad to have it back, but I can live without my tabs and print screens lost&#8230; that&#8217;s all I had) for me, I want to do at least one step forward in getting information about all this.<br />
The reason I haven&#8217;t save my opened contents is autohibernation on low battery state (which is afterall really good ability for such cases&#8230; I have similar setting on my desktop pc, where I made myself sort of cheap ups, which holds up to 2 minutes, and in a case of power blackout small circuit made of a few transistors and ne555 timers triggers via secondary usb &#8221;keyboard&#8221; (modified only with keyboard circuit) a shortcut to batch file which sends a pc into hibernation to save data. So, even in case of some attacks and so, hibernations kinda good ability for me&#8230; =)<br />
I&#8217;d be glad to get your reply&#8230; =)</p>
<p>Bye, Marc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: albert</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-262</link>
		<dc:creator>albert</dc:creator>
		<pubDate>Mon, 12 Jul 2010 04:08:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-262</guid>
		<description>at last this is my best secure final batch keeping almost the same speed as the original hibernation.
powercfg at start create file hiberfil.sys and at end delete from disk when powerup from hibernation. =)
--------------------------------------------------------------------------------------
@echo off
powercfg.exe /hibernate on
taskkill /IM iexplore.exe /F
taskkill /IM firefox.exe /F
&quot;C:\Program Files\CCleaner\CCleaner.exe&quot; /AUTO
&quot;C:\Program Files\you_truecrypt_directory\TrueCrypt.exe&quot; /dismount /quit
rundll32.exe PowrProf.dll, SetSuspendState Hibernate
powercfg.exe /hibernate off</description>
		<content:encoded><![CDATA[<p>at last this is my best secure final batch keeping almost the same speed as the original hibernation.<br />
powercfg at start create file hiberfil.sys and at end delete from disk when powerup from hibernation. =)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
@echo off<br />
powercfg.exe /hibernate on<br />
taskkill /IM iexplore.exe /F<br />
taskkill /IM firefox.exe /F<br />
&#8220;C:\Program Files\CCleaner\CCleaner.exe&#8221; /AUTO<br />
&#8220;C:\Program Files\you_truecrypt_directory\TrueCrypt.exe&#8221; /dismount /quit<br />
rundll32.exe PowrProf.dll, SetSuspendState Hibernate<br />
powercfg.exe /hibernate off</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: albert</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-260</link>
		<dc:creator>albert</dc:creator>
		<pubDate>Sat, 10 Jul 2010 08:26:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-260</guid>
		<description>and you can add ccleaner utility:
&quot;C:\Program Files\CCleaner\CCleaner.exe&quot; /AUTO
ofcourse before set, at least, DOD 5220-22-M in configuration.</description>
		<content:encoded><![CDATA[<p>and you can add ccleaner utility:<br />
&#8220;C:\Program Files\CCleaner\CCleaner.exe&#8221; /AUTO<br />
ofcourse before set, at least, DOD 5220-22-M in configuration.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: albert</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-259</link>
		<dc:creator>albert</dc:creator>
		<pubDate>Sat, 10 Jul 2010 08:16:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-259</guid>
		<description>maybe a batch on desktop can resolve this problem:
###############################################################
taskkill /IM iexplore.exe /F
taskkill /IM firefox.exe /F
&quot;C:\Program Files\TrueCrypt\TrueCrypt.exe&quot; /dismount /quit
rundll32.exe PowrProf.dll, SetSuspendState Hibernate
###############################################################</description>
		<content:encoded><![CDATA[<p>maybe a batch on desktop can resolve this problem:<br />
###############################################################<br />
taskkill /IM iexplore.exe /F<br />
taskkill /IM firefox.exe /F<br />
&#8220;C:\Program Files\TrueCrypt\TrueCrypt.exe&#8221; /dismount /quit<br />
rundll32.exe PowrProf.dll, SetSuspendState Hibernate<br />
###############################################################</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yar (Admin)</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-182</link>
		<dc:creator>Yar (Admin)</dc:creator>
		<pubDate>Sat, 06 Feb 2010 19:43:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-182</guid>
		<description>Hey ST, it is very possible that your laptop was set to hibernate when the lid was closed. Does a hiberfil.sys file exist on the root of your system partition? Usually &quot;C:&quot;</description>
		<content:encoded><![CDATA[<p>Hey ST, it is very possible that your laptop was set to hibernate when the lid was closed. Does a hiberfil.sys file exist on the root of your system partition? Usually &#8220;C:&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sunday treat</title>
		<link>http://www.anti-forensics.com/the-risks-of-windows-hibernation-the-hiberfil-sys-and-web-browsing/comment-page-1#comment-181</link>
		<dc:creator>sunday treat</dc:creator>
		<pubDate>Thu, 04 Feb 2010 01:03:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=704#comment-181</guid>
		<description>I am waiting for the true crypt/hibernation article! I have disabled hibernation since reading this even though I don&#039;t use it, at least I don&#039;t think I do. Maybe when I just close the lid on my laptop it was doing this.</description>
		<content:encoded><![CDATA[<p>I am waiting for the true crypt/hibernation article! I have disabled hibernation since reading this even though I don&#8217;t use it, at least I don&#8217;t think I do. Maybe when I just close the lid on my laptop it was doing this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

