이 영역을 누르면 첫 페이지로 이동
포렌식 & 개발 이야기 - Forensics & Development 블로그의 첫 페이지로 이동

포렌식 & 개발 이야기 - Forensics & Development

페이지 맨 위로 올라가기

포렌식 & 개발 이야기 - Forensics & Development

Pental - Forensics / iOS / Windows / Android / Kakaotalk / Telegram / Etc

Puzzle #2: Ann Skips Bail

  • 2017.08.11 13:15
  • CTF/Puzzel - Network Forensics
글 작성자: pental

Puzzle #2: Ann Skips Bail

OCTOBER 10, 2009 / SHERRI / 7 COMMENTS

After being released on bail, Ann Dercover disappears! Fortunately, investigators were carefully monitoring her network activity before she skipped town.

“We believe Ann may have communicated with her secret lover, Mr. X, before she left,” says the police chief. “The packet capture may contain clues to her whereabouts.”

You are the forensic investigator. Your mission is to figure out what Ann emailed, where she went, and recover evidence including:

1. What is Ann’s email address?
2. What is Ann’s email password?
3. What is Ann’s secret lover’s email address?
4. What two items did Ann tell her secret lover to bring?
5. What is the NAME of the attachment Ann sent to her secret lover?
6. What is the MD5sum of the attachment Ann sent to her secret lover?
7. In what CITY and COUNTRY is their rendez-vous point?
8. What is the MD5sum of the image embedded in the document?

Please use the Official Submission form to submit your answers. Prize TBD. Prize will be a Lenovo IdeaPad S10-2 – just like the free netbooks Sec558 students will get in Orlando.

Here is your evidence file:

http://forensicscontest.com/contest02/evidence02.pcap
MD5 (evidence02.pcap) = cfac149a49175ac8e89d5b5b5d69bad3

The MOST ELEGANT solution wins. In the event of a tie, the entry submitted first will receive the prize. Scripting is always encouraged. We love to see well-written, easy-to-use tools which automate even small sections of the evidence recovery. You are welcome to build upon the work of others, as long as their work has been released under a GPL license. (If it has been released under another free-software license, email us to confirm eligibility.) All responses should be submitted as plain text. Microsoft Word documents, PDFs, etc will NOT be reviewed.

Exceptional solutions may be incorporated into the SANS Network Forensics Toolkit. Authors agree that their code submissions will be freely published under the GPL license, in order to further the state of network forensics knowledge. Exceptional submissions may also be used as examples and tools in the Network Forensics class. All authors will receive full credit for their work.

Deadline is 11/15/09 11/22/09. Here’s the Official Submission form. Good luck!!


 

 

Forensic Questions Write-up

▷ http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail

▷ Puzzle #2: Ann Skips Bail

 

Questions

 

1. What is Ann’s email address?

2. What is Ann’s email password?

3. What is Ann’s secret lover’s email address?

4. What two items did Ann tell her secret lover to bring?

5. What is the NAME of the attachment Ann sent to her secret lover?

6. What is the MD5sum of the attachment Ann sent to her secret lover?

7. In what CITY and COUNTRY is their rendez-vous point?

8. What is the MD5sum of the image embedded in the document?

 

 

 


 

 

Answer

 

1. What is Ann’s email address?

First, We use wireshark filter by tcp.stream eq 0

53        82.707578          192.168.1.159      64.12.102.142     TCP       62        1036 → 587 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1

54        82.817457          64.12.102.142      192.168.1.159     TCP       58        587 → 1036 [SYN, ACK] Seq=0 Ack=1 Win=64240 Len=0 MSS=1460

 

View TCP Stream

Answer : sneakyg33k@aol.com

2. What is Ann’s email password?

AUTH LOGIN

334 VXNlcm5hbWU6

c25lYWt5ZzMza0Bhb2wuY29t

334 UGFzc3dvcmQ6

NTU4cjAwbHo=

https://www.base64decode.org/

 

Answer : 558r00lz

 

3. What is Ann’s secret lover’s email address?

 

Filter : tcp.stream eq 1

Follow TCP stream

Answer : misterscrectx@aol.com

 

4. What two items did Ann tell her secret lover to bring?

 

<Mail>

Hi sweetheart! Bring your fake passport and a bathing suit. Address =

attached. love, Ann

 

           Answer : fake passport & bathing suit

 

5. What is the NAME of the attachment Ann sent to her secret lover?

Answer : secretrendezvoux.docx

6. What is the MD5sum of the attachment Ann sent to her secret lover?

 

Answer : 9E423E11DB88F01BBFF81172839E1923

 

7. In what CITY and COUNTRY is their rendez-vous point?

 

8. What is the MD5sum of the image embedded in the document?

I don't more..

 

 

 

'CTF > Puzzel - Network Forensics' 카테고리의 다른 글

Puzzle #1: Ann’s Bad AIM  (0) 2017.08.11

댓글

이 글 공유하기

  • 구독하기

    구독하기

  • 카카오톡

    카카오톡

  • 라인

    라인

  • 트위터

    트위터

  • Facebook

    Facebook

  • 카카오스토리

    카카오스토리

  • 밴드

    밴드

  • 네이버 블로그

    네이버 블로그

  • Pocket

    Pocket

  • Evernote

    Evernote

다른 글

  • Puzzle #1: Ann’s Bad AIM

    Puzzle #1: Ann’s Bad AIM

    2017.08.11
다른 글 더 둘러보기

정보

포렌식 & 개발 이야기 - Forensics & Development 블로그의 첫 페이지로 이동

포렌식 & 개발 이야기 - Forensics & Development

  • 포렌식 & 개발 이야기 - Forensics & Development의 첫 페이지로 이동

검색

메뉴

  • 홈
  • 태그
  • 미디어로그
  • 위치로그
  • 방명록

카테고리

  • Category (449) N
    • Forensics (105) N
      • Magnet AXIOM (28)
      • Digital Forensics Informati.. (9)
      • Iphone Forensics (24) N
      • DFC (7)
      • 디지털포렌식전문가2급 자격증 (10)
      • FTK ACE 자격증 (7)
    • 이것저것 (7)
      • Ubuntu (6)
      • 디스코드 봇 (4)
      • Volatility GUI (2)
    • CTF (32)
      • NEWSECU (14)
      • CTF-d (5)
      • Puzzel - Network Forensics (2)
      • Security Traps (2)
      • system32.kr (5)
      • HMCTF (4)
    • Programming (257) N
      • C (10)
      • Python (11)
      • 백준 (203) N
      • 프로그래머스 (32)
    • 그냥 개발 및 잡담 (16)
      • Docker (2)
      • Google Cloud (3)
      • OS 개발 (3)
    • Best of Best (20)

최근 글

인기 글

댓글

공지사항

아카이브

태그

  • Forensics
  • pental
  • 포렌식
  • 디지털포렌식
  • 파이썬
  • axiom
  • 백준
  • 프로그래머스
  • 전체 보기…

정보

pental의 포렌식 & 개발 이야기 - Forensics & Development

포렌식 & 개발 이야기 - Forensics & Development

pental

블로그 구독하기

  • 구독하기
  • RSS 피드

방문자

  • 전체 방문자
  • 오늘
  • 어제

티스토리

  • 티스토리 홈
  • 이 블로그 관리하기
  • 글쓰기
Powered by Tistory / Kakao. Copyright © pental.

티스토리툴바