source: trunk/doc/devel/references.txt @ 129

Last change on this file since 129 was 120, checked in by tim, 16 years ago

added some references

File size: 1.3 KB
RevLine 
[120]1- The Windows NT Registry File Format
2  (A work in progress to support this tool.)
3  http://sentinelchicken.com/research/registry_format/
[14]4
[120]5- Recovering Deleted Data From the Windows Registry
6  (The research that is implemented as a PoC in reglookup-recover.)
7  http://sentinelchicken.com/research/registry_recovery/
8
[14]9- Petter Nordahl-Hagen.  Windows NT registry file format description.
10  (The file 'winntreg.txt' included in this distribution is derived from this.)
11  http://home.eunet.no/~pnordahl/ntpasswd/WinReg.txt
[64]12
13- Some useful information on how Windows reads from and writes to registry
14  hives:
15  http://www.microsoft.com/technet/archive/winntas/tips/winntmag/inreg.mspx
16
[77]17- Registry key, value, and depth limits:
18  http://msdn2.microsoft.com/en-us/library/ms724872.aspx
19
[76]20- Misc references for windows registry permissions and ownership:
21  http://msdn2.microsoft.com/en-gb/library/ms724878.aspx
22  http://technet2.microsoft.com/WindowsServer/en/library/86cf2457-4f17-43f8-a2ab-7f4e2e5659091033.mspx?mfr=true
23  http://msdn2.microsoft.com/en-gb/library/aa374892.aspx
24
25- ACL/ACE flags information
26  http://support.microsoft.com/kb/220167
27  http://msdn2.microsoft.com/en-us/library/aa772242.aspx
[77]28
29- Info on SAM hive, syskey, and hash extraction (with tools bkhive and samdump2):
30  http://www.studenti.unina.it/~ncuomo/syskey/
Note: See TracBrowser for help on using the repository browser.