Click here to get back home

Selective Security Wipe

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Selective Security Wipe mark 07-08-2007
Get Chitika Premium
Posted by mark on July 8, 2007, 8:30 pm
Please log in for more thread options
Wondering if anyone has a suggestion for how to perform selective deletion
of data from multiple servers and volumes, that will meet DOD erasure
standards when completed?

One of our clients is not using our services any longer and has requested
all data pertaining to their business, be deleted from any and all servers.
Obviously backups will need to be addressed, but there are over 40 servers
with multiple volumes and MS SQL Server.

I have found a few utilities that appear to do this (like DODlete) but time
and efficiency are a key component.

Any advice would be appreciated.

Thanks,
mwheat



Posted by Steve Riley [MSFT] on July 13, 2007, 12:53 am
Please log in for more thread options
Do you really need DOD-level standards? You might consider the CIPHER
utility already included in Windows. CIPHER /W wipes erased space with three
passes: 00, FF, <random byte>. This is probably sufficient. I haven't
compared the speed of CIPHER to any third-party utilities, however.

Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley


> Wondering if anyone has a suggestion for how to perform selective deletion
> of data from multiple servers and volumes, that will meet DOD erasure
> standards when completed?
>
> One of our clients is not using our services any longer and has requested
> all data pertaining to their business, be deleted from any and all
> servers.
> Obviously backups will need to be addressed, but there are over 40 servers
> with multiple volumes and MS SQL Server.
>
> I have found a few utilities that appear to do this (like DODlete) but
> time
> and efficiency are a key component.
>
> Any advice would be appreciated.
>
> Thanks,
> mwheat
>
>

Posted by mwheat on July 17, 2007, 1:38 am
Please log in for more thread options
Thank you Steve for your response. The DOD standard is at the client's
request. I looked at the Cipher utility with the /W switch, but wasn't sure
if it would traverse sectors/folders on the drive and meet their
requirements.
I've also been looking at Microsoft's SDelete utility using the -p 3 -s -z
switches which should make 3 passes, recurse subdirectories and cleanse free
space. We'll be testing on a lab system to see which utility can perform
faster on a multi-disk array.

I apprecite your input and will revisit using the Cipher utility in our
tests.
Have a great week Steve!
Mark


> Do you really need DOD-level standards? You might consider the CIPHER
> utility already included in Windows. CIPHER /W wipes erased space with
> three passes: 00, FF, <random byte>. This is probably sufficient. I
> haven't compared the speed of CIPHER to any third-party utilities,
> however.
>
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
>
>
>> Wondering if anyone has a suggestion for how to perform selective
>> deletion
>> of data from multiple servers and volumes, that will meet DOD erasure
>> standards when completed?
>>
>> One of our clients is not using our services any longer and has requested
>> all data pertaining to their business, be deleted from any and all
>> servers.
>> Obviously backups will need to be addressed, but there are over 40
>> servers
>> with multiple volumes and MS SQL Server.
>>
>> I have found a few utilities that appear to do this (like DODlete) but
>> time
>> and efficiency are a key component.
>>
>> Any advice would be appreciated.
>>
>> Thanks,
>> mwheat
>>
>>



Posted by Al Dunbar on July 19, 2007, 12:05 am
Please log in for more thread options

> Thank you Steve for your response. The DOD standard is at the client's
> request. I looked at the Cipher utility with the /W switch, but wasn't
> sure if it would traverse sectors/folders on the drive and meet their
> requirements.

It is my impression that it has nothing to do with the folder structure, but
simply writes to all unallocated clusters on a volume, which seems to be
what sdelete does.

The proof would appear to be in the pudding. We have a test machine running
a variety of forensic tools designed to find data stored on disks, whether
within the storage allocated as files or within the available free space.
When we have the time we will try these out on disks we have wiped with
sdelete and cipher to see if we can find a unique string stored in a file
deleted before wiping it. If anyone out there has already done something
like this, I would be very interested in hearing of your experiences.


/Al

> I've also been looking at Microsoft's SDelete utility using the -p 3 -s -z
> switches which should make 3 passes, recurse subdirectories and cleanse
> free space. We'll be testing on a lab system to see which utility can
> perform faster on a multi-disk array.
>
> I apprecite your input and will revisit using the Cipher utility in our
> tests.
> Have a great week Steve!
> Mark
>
>
>> Do you really need DOD-level standards? You might consider the CIPHER
>> utility already included in Windows. CIPHER /W wipes erased space with
>> three passes: 00, FF, <random byte>. This is probably sufficient. I
>> haven't compared the speed of CIPHER to any third-party utilities,
>> however.
>>
>> Steve Riley
>> steve.riley@microsoft.com
>> http://blogs.technet.com/steriley
>>
>>
>>> Wondering if anyone has a suggestion for how to perform selective
>>> deletion
>>> of data from multiple servers and volumes, that will meet DOD erasure
>>> standards when completed?
>>>
>>> One of our clients is not using our services any longer and has
>>> requested
>>> all data pertaining to their business, be deleted from any and all
>>> servers.
>>> Obviously backups will need to be addressed, but there are over 40
>>> servers
>>> with multiple volumes and MS SQL Server.
>>>
>>> I have found a few utilities that appear to do this (like DODlete) but
>>> time
>>> and efficiency are a key component.
>>>
>>> Any advice would be appreciated.
>>>
>>> Thanks,
>>> mwheat
>>>
>>>
>
>



Similar ThreadsPosted
Domain Local Security vs Global Security vs Universal Security Groups October 16, 2006, 1:26 pm
Role-based security from Windows Server 2003 Security Guide gives problems November 6, 2006, 8:00 am
Windows Server Baseline Security - IE security warning June 5, 2007, 9:35 am
security in AD June 22, 2005, 5:38 am
VPN Security. July 19, 2005, 9:44 am
Security? July 25, 2005, 8:56 am
COM + Security October 13, 2005, 6:02 am
No Security Tab November 28, 2005, 2:33 pm
FTP security September 27, 2006, 1:21 am
Security July 24, 2007, 10:58 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap