Host protected area
How it works
The IDE controller has registers that contain data that can be queried using ATA commands. The data returned gives information about the drive attached to the controller. There are three ATA commands involved in creating and using a hidden protected area. The commands are:
- IDENTIFY DEVICE
- SET MAX ADDRESS
- READ NATIVE MAX ADDRESS
Operating systems use the IDENTIFY DEVICE command to find out the addressable space of a hard drive. The IDENTIFY DEVICE command queries a particular register on the IDE controller to establish the size of a drive.
This register however can be changed using the SET MAX ADDRESS ATA command. If the value in the register is set to less than the actual hard drive size then effectively a host protected area is created. It is protected because the OS will work with only the value in the register that is returned by the IDENTIFY DEVICE command and thus will normally be unable to address the parts of the drive that lie within the HPA.
The HPA is useful only if other software or firmware (e.g. BIOS) is able to use it. Software and firmware that are able to use the HPA are referred to as 'HPA aware'. The ATA command that these entities use is called READ NATIVE MAX ADDRESS. This command accesses a register that contains the true size of the hard drive. To use the area, the controlling HPA-aware program changes the value of the register read by IDENTIFY DEVICE to that found in the register read by READ NATIVE MAX ADDRESS. When its operations are complete, the register read by IDENTIFY DEVICE is returned to its original fake value.
- HPA can be used by various booting and diagnostic utilities, normally in conjunction with the BIOS. An example of this implementation is the Phoenix FirstBIOS, which uses BEER (Boot Engineering Extension Record) and PARTIES (Protected Area Run Time Interface Extension Services).
- Computer manufacturers may use the area to contain a preloaded OS for install and recovery purposes (instead of providing DVD or CD media).
- Dell notebooks hide Dell MediaDirect utility in HPA. IBM and LG notebooks hide system restore software in HPA.
- HPA is also used by various theft recovery and monitoring service vendors. For example the laptop security firm Computrace use the HPA to load software that reports to their servers whenever the machine is booted on a network. HPA is useful to them because even when a stolen laptop has its hard drive formatted the HPA remains untouched.
- HPA can also be used to store data that is deemed illegal and is thus of interest to government and police computer forensics teams.
- Some vendor-specific external drive enclosures (Maxtor) are known to use HPA to limit the capacity of unknown replacement hard drives installed into the enclosure. When this occurs, the drive may appear to be limited in size (e.g. 128 GB), which can look like a BIOS or dynamic drive overlay (DDO) problem. In this case, one must use software utilities (see below) that use READ NATIVE MAX ADDRESS and SET MAX ADDRESS to change the drive's reported size back to its native size, and avoid using the external enclosure again with the affected drive.
- Some rootkits hide in the HPA to avoid being detected by anti-rootkit and antivirus software.
Identification and manipulation
Identification of HPA on a hard drive can be achieved by a number of tools and methods.
- The Sleuth Kit (free, open software) by Brian Carrier. (HPA identification is currently Linux-only.)
- The ATA Forensics Tool (TAFT) by Arne Vidstrom.
- EnCase by Guidance Software
- Access Data's Forensic Toolkit
Using Linux, there are various ways to detect the existence of an HPA. Recent versions of Linux will print a message when the system is booting if an HPA is detected. For example:
dmesg | less [...] hdb: Host Protected Area detected. current capacity is 12000 sectors (6 MB) native capacity is 120103200 sectors (61492 MB)
The program hdparm (version >= 8.0) will detect an HPA on drive sdX when invoked with these parameters:
hdparm -N /dev/sdX
For versions of hdparm < 8, one can compare the number of sectors output from 'hdparm -I' with the number of sectors reported for the hard drive model's published statistics.
Creating and manipulating HPA on a hard drive can be achieved by a number of tools.
- HPARemove by Aron Molnar.
- HDAT2 by Lubomir Cabla.
- setmax by Andries E. Brouwer
- Feature Tool by Hitachi Global Storage Technologies.
- MHDD (created by Dmitry Postrigan) is a freeware tool for hard drives that among other low-level functionalities provides information about the HPA state of a disk and can manipulate it.
- hdparm is a Linux program for reading and writing ATA and SATA hard drive parameters.
- FreeBSD has the hw.ata.setmax sysctl which can be set to 1.
The Linux program hdparm (version >= 8.0) will create an HPA when invoked with these parameters: (sdX: target drive, #: number of non-HPA visible sectors)
hdparm -N p# /dev/sdX
- Hidden Protected Area - ThinkWiki
- Host Protected Areas
- Blunden, Bill. The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System. 1st ed. Jones & Bartlett Publishers, 2009 p.538
- vidstrom.net - security tools
- HDAT2/CBL Hard Disk Repair Utility
- Support - Downloads and Utilities