<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Gl.ib.ly - Forensics</title>
    <link>http://gl.ib.ly/</link>
    <description>(glibly); Just another techie blog.</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Fri, 27 Nov 2009 22:04:37 GMT</pubDate>

    <image>
        <url>http://gl.ib.ly/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Gl.ib.ly - Forensics - (glibly); Just another techie blog.</title>
        <link>http://gl.ib.ly/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Ann skips bail. Cue forensics puzzle.</title>
    <link>http://gl.ib.ly/archives/39-Ann-skips-bail.-Cue-forensics-puzzle..html</link>
            <category>Forensics</category>
    
    <comments>http://gl.ib.ly/archives/39-Ann-skips-bail.-Cue-forensics-puzzle..html#comments</comments>
    <wfw:comment>http://gl.ib.ly/wfwcomment.php?cid=39</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://gl.ib.ly/rss.php?version=2.0&amp;type=comments&amp;cid=39</wfw:commentRss>
    

    <author>nospam@example.com (Tariq)</author>
    <content:encoded>
    Found a website and a forensics contest yesterday quite by accident. I was waiting for somebody before going out for the night and I thought this might be a little fun while I waited. Now the contest had closed and the results where available, which I ignored until the end and went straight to &lt;a href=&quot;http://gl.ib.ly/exit.php?url_id=105&amp;amp;entry_id=39&quot; title=&quot;http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail&quot;  onmouseover=&quot;window.status=&#039;http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Puzzle #2: Ann skips bail&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The puzzle revolves around a packet capture of Ann&#039;s network taken by wily investigators before she skipped bail. Police are confident that she communicated with a secret lover prior to her disappearance. And so follows a number of competition questions. It is important to note that the organizers are looking for the most elegant solutions, and you won&#039;t see that here. What you will see is how to solve the puzzle very quickly.&lt;br /&gt;
&lt;br /&gt;
1. What is Ann’s email address?&lt;br /&gt;
2. What is Ann’s email password?&lt;br /&gt;
3. What is Ann’s secret lover’s email address?&lt;br /&gt;
4. What two items did Ann tell her secret lover to bring?&lt;br /&gt;
5. What is the NAME of the attachment Ann sent to her secret lover?&lt;br /&gt;
6. What is the MD5sum of the attachment Ann sent to her secret lover?&lt;br /&gt;
7. In what CITY and COUNTRY is their rendez-vous point?&lt;br /&gt;
8. What is the MD5sum of the image embedded in the document?&lt;br /&gt;
&lt;br /&gt;
I downloaded the &lt;a href=&quot;http://gl.ib.ly/exit.php?url_id=106&amp;amp;entry_id=39&quot; title=&quot;http://forensicscontest.com/contest02/evidence02.pcap&quot;  onmouseover=&quot;window.status=&#039;http://forensicscontest.com/contest02/evidence02.pcap&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;packet dump file&lt;/a&gt; from the organiser&#039;s site and verified the hash using &lt;code&gt;md5&lt;/code&gt; as I am on a Mac, otherwise &lt;code&gt;md5sum&lt;/code&gt; does the job.&lt;br /&gt;
&lt;br /&gt;
I fired up &lt;code&gt;wireshark&lt;/code&gt; and opened the packet capture file. There appeared to be a good bit of SMTP traffic. So I did a quick&lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;grep -an &quot;To:.*\|From:*\|Subject:.*&quot; evidence02.pcap&lt;/pre&gt; &lt;br /&gt;
&lt;br /&gt;
on the packet dump which revealed the following.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
From: &amp;quot;Ann Dercover&amp;quot; &amp;lt;sneakyg33k@aol.com&amp;gt;&lt;br /&gt;
To: &amp;lt;sec558@gmail.com&amp;gt;&lt;br /&gt;
Subject: lunch next week&lt;br /&gt;
From: &amp;quot;Ann Dercover&amp;quot; &amp;lt;sneakyg33k@aol.com&amp;gt;&lt;br /&gt;
To: &amp;lt;mistersecretx@aol.com&amp;gt;&lt;br /&gt;
Subject: rendezvous&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Its clear that Ann Dercover&#039;s email address is &lt;code&gt;sneakyg33k@aol.com&lt;/code&gt;. This is the answer to question 1. We also see she sent two emails. One to  &lt;code&gt;mistersecretx@aol.com&lt;/code&gt;, could this be Ann&#039;s secret lover? I expanded the grep to &lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;grep -aA50 &quot;mistersecretx@aol.com&quot; evidence02.pcap&lt;/pre&gt;&lt;br /&gt;
&lt;br /&gt;
This gives me 50 lines after and including lines matching &lt;code&gt;mistersecretx@aol.com&lt;/code&gt;. &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
To: &amp;lt;mistersecretx@aol.com&amp;gt;&lt;br /&gt;
Subject: rendezvous&lt;br /&gt;
Date: Sat, 10 Oct 2009 07:38:10 -0600&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: multipart/mixed;&lt;br /&gt;
	boundary=&amp;quot;----=_NextPart_000_000D_01CA497C.9DEC1E70&amp;quot;&lt;br /&gt;
X-Priority: 3&lt;br /&gt;
X-MSMail-Priority: Normal&lt;br /&gt;
X-Mailer: Microsoft Outlook Express 6.00.2900.2180&lt;br /&gt;
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180&lt;br /&gt;
&lt;br /&gt;
This is a multi-part message in MIME format.&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_000_000D_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: multipart/alternative;&lt;br /&gt;
	boundary=&amp;quot;----=_NextPart_001_000E_01CA497C.9DEC1E70&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_001_000E_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: text/plain;&lt;br /&gt;
	charset=&amp;quot;iso-8859-1&amp;quot;&lt;br /&gt;
Content-Transfer-Encoding: quoted-printable&lt;br /&gt;
&lt;br /&gt;
Hi sweetheart! Bring your fake passport and a bathing suit. Address =&lt;br /&gt;
attached. love, Ann&lt;br /&gt;
------=_NextPart_001_000E_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: text/html;&lt;br /&gt;
	charset=&amp;quot;iso-8859-1&amp;quot;&lt;br /&gt;
Content-Transfer-Encoding: quoted-printable&lt;br /&gt;
&lt;br /&gt;
...SNIP...&lt;br /&gt;
&lt;br /&gt;
Hi sweetheart! Bring your fake passport =&lt;br /&gt;
and a=20&lt;br /&gt;
bathing suit. Address attached. love, Ann&lt;br /&gt;
&lt;br /&gt;
...SNIP...&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_000_000D_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: application/octet-stream;&lt;br /&gt;
	name=&amp;quot;secretrendezvous.docx&amp;quot;&lt;br /&gt;
Content-Transfer-Encoding: base64&lt;br /&gt;
Content-Disposition: attachment;&lt;br /&gt;
	filename=&amp;quot;secretrendezvous.docx&amp;quot;&lt;br /&gt;
&lt;/code&gt; &lt;br /&gt;
&lt;br /&gt;
Wow. So &lt;code&gt;mistersecretx@aol.com&lt;/code&gt; IS the email address of Ann&#039;s lover. This is the answer to question 3. We also see in her message she instructs them to &quot;bring your fake passport and bathing suit&quot;, this is the answer to question 4. Towards the bottom we see an attachment that probably appears later than the lines we grep&#039;d called &lt;code&gt;secretrendezvous.docx&lt;/code&gt; which will appear base64 encoding. This is the answer to question 5.&lt;br /&gt;
&lt;br /&gt;
I then returned to &lt;code&gt;wireshark&lt;/code&gt;, looking down through the packets I quickly see SMTP traffic with  &lt;i&gt;C: DATA fragment&lt;/i&gt; which tells us this traffic was broken up into smaller pieces. This is likely to be an email with a large attachment. I right clicked on one of these packets as shown below and clicked on &lt;i&gt;Follow TCP Stream&lt;/i&gt; as shown below.&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;img src=&quot;http://gl.ib.ly/uploads/forensicspuzzle2/wireshark.png&quot; width=&quot;500px&quot; /&gt;&lt;/center&gt;&lt;br /&gt;
&lt;br /&gt;
This gives me the following.&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
220 cia-mc07.mx.aol.com ESMTP mail_cia-mc07.1; Sat, 10 Oct 2009 15:37:56 -0400&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;EHLO annlaptop&lt;/span&gt;&lt;br /&gt;
250-cia-mc07.mx.aol.com host-69-140-19-190.static.comcast.net&lt;br /&gt;
250-AUTH=LOGIN PLAIN XAOL-UAS-MB &lt;br /&gt;
250-AUTH LOGIN PLAIN XAOL-UAS-MB &lt;br /&gt;
250-STARTTLS&lt;br /&gt;
250-CHUNKING&lt;br /&gt;
250-BINARYMIME&lt;br /&gt;
250-X-AOL-FWD-BY-REF&lt;br /&gt;
250-X-AOL-DIV_TAG&lt;br /&gt;
250-X-AOL-OUTBOX-COPY&lt;br /&gt;
250 HELP&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;AUTH LOGIN&lt;/span&gt;&lt;br /&gt;
334 VXNlcm5hbWU6&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;c25lYWt5ZzMza0Bhb2wuY29t&lt;/span&gt;&lt;br /&gt;
334 UGFzc3dvcmQ6&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;NTU4cjAwbHo=&lt;/span&gt;&lt;br /&gt;
235 AUTHENTICATION SUCCESSFUL&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;MAIL FROM: &amp;lt;sneakyg33k@aol.com&amp;gt;&lt;/span&gt;&lt;br /&gt;
250 OK&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;RCPT TO: &amp;lt;mistersecretx@aol.com&amp;gt;&lt;/span&gt;&lt;br /&gt;
250 OK&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;DATA&lt;/span&gt;&lt;br /&gt;
354 START MAIL INPUT, END WITH &quot;.&quot; ON A LINE BY ITSELF&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;Message-ID: &lt;001101ca49ae$e93e45b0$9f01a8c0@annlaptop&gt;&lt;br /&gt;
From: &amp;quot;Ann Dercover&amp;quot; &amp;lt;sneakyg33k@aol.com&amp;gt;&lt;br /&gt;
To: &amp;lt;mistersecretx@aol.com&amp;gt;&lt;br /&gt;
Subject: rendezvous&lt;br /&gt;
Date: Sat, 10 Oct 2009 07:38:10 -0600&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: multipart/mixed;&lt;br /&gt;
.boundary=&quot;----=_NextPart_000_000D_01CA497C.9DEC1E70&quot;&lt;br /&gt;
X-Priority: 3&lt;br /&gt;
X-MSMail-Priority: Normal&lt;br /&gt;
X-Mailer: Microsoft Outlook Express 6.00.2900.2180&lt;br /&gt;
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180&lt;br /&gt;
&lt;br /&gt;
This is a multi-part message in MIME format.&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_000_000D_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: multipart/alternative;&lt;br /&gt;
.boundary=&quot;----=_NextPart_001_000E_01CA497C.9DEC1E70&quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_001_000E_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: text/plain;&lt;br /&gt;
.charset=&quot;iso-8859-1&quot;&lt;br /&gt;
Content-Transfer-Encoding: quoted-printable&lt;br /&gt;
&lt;br /&gt;
Hi sweetheart! Bring your fake passport and a bathing suit. Address =&lt;br /&gt;
attached. love, Ann&lt;br /&gt;
------=_NextPart_001_000E_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: text/html;&lt;br /&gt;
.charset=&quot;iso-8859-1&quot;&lt;br /&gt;
Content-Transfer-Encoding: quoted-printable&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!DOCTYPE HTML PUBLIC &amp;quot;-//W3C//DTD HTML 4.0 Transitional//EN&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&lt;br /&gt;
&amp;lt;META http-equiv=3DContent-Type content=3D&amp;quot;text/html; =&lt;br /&gt;
charset=3Diso-8859-1&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META content=3D&amp;quot;MSHTML 6.00.2900.2853&amp;quot; name=3DGENERATOR&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;/HEAD&amp;gt;&lt;br /&gt;
&amp;lt;BODY bgColor=3D#ffffff&amp;gt;&lt;br /&gt;
&amp;lt;DIV&amp;gt;&amp;lt;FONT face=3DArial size=3D2&amp;gt;Hi sweetheart! Bring your fake passport =&lt;br /&gt;
and a=20&lt;br /&gt;
bathing suit. Address attached. love, Ann&amp;lt;/FONT&amp;gt;&amp;lt;/DIV&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_001_000E_01CA497C.9DEC1E70--&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_000_000D_01CA497C.9DEC1E70&lt;br /&gt;
Content-Type: application/octet-stream;&lt;br /&gt;
.name=&quot;secretrendezvous.docx&quot;&lt;br /&gt;
Content-Transfer-Encoding: base64&lt;br /&gt;
Content-Disposition: attachment;&lt;br /&gt;
.filename=&quot;secretrendezvous.docx&quot;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: #00f;&quot;&gt;UEsDBBQABgAIAAAAIQDleUAGfwEAANcFAAATAAgCW0NvbnRlbnRfVHlwZXNdLnhtbCCiBAIooAAC&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC0&lt;br /&gt;
VMluwjAQvVfqP0S+VsTQQ1VVBA5dji1S6QcYexKsepNttr/vOEBEKQSpwCVSPH7LPI/dHy61yubg&lt;br /&gt;
g7SmIL28SzIw3AppqoJ8jd86jyQLkRnBlDVQkBUEMhzc3vTHKwchQ7QJBZnG6J4oDXwKmoXcOjBY&lt;br /&gt;
Ka3XLOKvr6hj/JtVQO+73QfKrYlgYicmDjLov0DJZipmr0tcXjtxpiLZ83pfkiqI1Amf1ulBhAcV&lt;br /&gt;
9iDMOSU5i9gbnRux56uz8ZQjst4TptKFOzR+RCFVfnvaFdjgPjBMLwVkI+bjO9PonC6sF1RYPtPY&lt;br /&gt;
dd5Oc8CnLUvJocEnNucthxDwlLTKm4pm0mz9H/VhZnoCHpGXN9JQnzQR4kpBuLyDNW+bPIY18tYF&lt;br /&gt;
imd3tj6kgRUgOngeDnyU0MzP0fwDxIjpX6P5DXNb+/UoRrymQOtv7+wMapqTkiVe5TGbKDhb78/4&lt;br /&gt;
N9QnTSxg8nm19HfI24w088et/0cY2zcroQ9MHa2f5cEPAAAA//8DAFBLAwQUAAYACAAAACEAHpEa&lt;br /&gt;
t/MAAABOAgAACwAIAl9yZWxzLy5yZWxzIKIEAiigAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIyS20oDQQyG7wXfYch9N9sKItLZ3kihdyLr&lt;br /&gt;
A4SZ7AF3Dsyk2r69oyC6UNte5vTny0/Wm4Ob1DunPAavYVnVoNibYEffa3htt4sHUFnIW5qCZw1H&lt;br /&gt;
zrBpbm/WLzyRlKE8jDGrouKzhkEkPiJmM7CjXIXIvlS6kBxJCVOPkcwb9Yyrur7H9FcDmpmm2lkN&lt;br /&gt;
aWfvQLXHWDZf1g5dNxp+Cmbv2MuJFcgHYW/ZLmIqbEnGco1qKfUsGmwwzyWdkWKsCjbgaaLV9UT/&lt;br /&gt;
X4uOhSwJoQmJz/N8dZwDWl4PdNmiecevOx8hWSwWfXv7Q4OzL2g+AQAA//8DAFBLAwQUAAYACAAA&lt;br /&gt;
ACEApOAquCABAAA6BAAAHAAIAXdvcmQvX3JlbHMvZG9jdW1lbnQueG1sLnJlbHMgogQBKKAAAQAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACsk01OwzAQhfdI3MHynjgpUBCq0w1C6hbCAdxkkljE&lt;br /&gt;
P7KnQG7PKFKbVJSwycbSvCjvfZ7xbLbfpmOfEKJ2VvIsSTkDW7pK20by9+Ll5pGziMpWqnMWJO8h&lt;br /&gt;
8m1+fbV5hU4h/RRb7SMjFxslbxH9kxCxbMGomDgPlr7ULhiFVIZGeFV+qAbEKk3XIkw9eH7myXaV&lt;br /&gt;
5GFX3XJW9J6S//d2da1LeHblwYDFCxEiAiLdLJKnCg2g5EclIU4uLiM8LImA1BoY84dSDGc2x7Ba&lt;br /&gt;
kiFi39EcxyYM9Vx8tmS8PZg9BJrDSHCS5iDWS0LUzmKh9t1kFidpDuJ+SQhtaBfGLhiotBKDmCWe&lt;br /&gt;
&lt;br /&gt;
...SNIP: not publishing the whole thing, its a bit long. &lt;a href=&quot;http://gl.ib.ly/uploads/forensicspuzzle2/attachment.b64&quot; target=&quot;_blank&quot;&gt;See the whole thing?&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
JZ2ekPwNAAD//wMAUEsBAi0AFAAGAAgAAAAhAOV5QAZ/AQAA1wUAABMAAAAAAAAAAAAAAAAAAAAA&lt;br /&gt;
AFtDb250ZW50X1R5cGVzXS54bWxQSwECLQAUAAYACAAAACEAHpEat/MAAABOAgAACwAAAAAAAAAA&lt;br /&gt;
AAAAAAC4AwAAX3JlbHMvLnJlbHNQSwECLQAUAAYACAAAACEApOAquCABAAA6BAAAHAAAAAAAAAAA&lt;br /&gt;
AAAAAADcBgAAd29yZC9fcmVscy9kb2N1bWVudC54bWwucmVsc1BLAQItABQABgAIAAAAIQA6Q0kI&lt;br /&gt;
FQQAAFgKAAARAAAAAAAAAAAAAAAAAD4JAAB3b3JkL2RvY3VtZW50LnhtbFBLAQItAAoAAAAAAAAA&lt;br /&gt;
IQBg7VaATPYCAEz2AgAVAAAAAAAAAAAAAAAAAIINAAB3b3JkL21lZGlhL2ltYWdlMS5wbmdQSwEC&lt;br /&gt;
LQAUAAYACAAAACEAlrWt4pYGAABQGwAAFQAAAAAAAAAAAAAAAAABBAMAd29yZC90aGVtZS90aGVt&lt;br /&gt;
ZTEueG1sUEsBAi0AFAAGAAgAAAAhAIkUT0qVAwAAcQgAABEAAAAAAAAAAAAAAAAAygoDAHdvcmQv&lt;br /&gt;
c2V0dGluZ3MueG1sUEsBAi0AFAAGAAgAAAAhAErYipK7AAAABAEAABQAAAAAAAAAAAAAAAAAjg4D&lt;br /&gt;
AHdvcmQvd2ViU2V0dGluZ3MueG1sUEsBAi0AFAAGAAgAAAAhADVKHsm+CgAALFoAAA8AAAAAAAAA&lt;br /&gt;
AAAAAAAAew8DAHdvcmQvc3R5bGVzLnhtbFBLAQItABQABgAIAAAAIQCQUuGobwEAANcCAAARAAAA&lt;br /&gt;
AAAAAAAAAAAAAGYaAwBkb2NQcm9wcy9jb3JlLnhtbFBLAQItABQABgAIAAAAIQAXVdHWCQQAAMsZ&lt;br /&gt;
AAASAAAAAAAAAAAAAAAAAAwdAwB3b3JkL251bWJlcmluZy54bWxQSwECLQAUAAYACAAAACEAu6G5&lt;br /&gt;
NXECAACGCAAAEgAAAAAAAAAAAAAAAABFIQMAd29yZC9mb250VGFibGUueG1sUEsBAi0AFAAGAAgA&lt;br /&gt;
AAAhAKVR8wbYAQAA2QMAABAAAAAAAAAAAAAAAAAA5iMDAGRvY1Byb3BzL2FwcC54bWxQSwUGAAAA&lt;br /&gt;
AA0ADQBEAwAA9CYDAAAA&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
------=_NextPart_000_000D_01CA497C.9DEC1E70--&lt;br /&gt;
&lt;br /&gt;
.&lt;/span&gt;&lt;br /&gt;
250 OK&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;QUIT&lt;/span&gt;&lt;br /&gt;
221 SERVICE CLOSING CHANNEL&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
You may or may not realise that parts of the communication are base64 encoded. Lets take a look at some information encoded at the beginning of this communication again.  &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;AUTH LOGIN&lt;/span&gt;&lt;br /&gt;
334 VXNlcm5hbWU6&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;c25lYWt5ZzMza0Bhb2wuY29t&lt;/span&gt;&lt;br /&gt;
334 UGFzc3dvcmQ6&lt;br /&gt;
&lt;span style=&quot;color: #f00;&quot;&gt;NTU4cjAwbHo=&lt;/span&gt;&lt;br /&gt;
235 AUTHENTICATION SUCCESSFUL&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
Here Ann is authenticating with the service. Her responses are shown in red, and as you can see they&#039;re a bit cryptic; however, they look like they are encoded in base64. So we run the following two commands.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
$ echo &quot;c25lYWt5ZzMza0Bhb2wuY29t&quot; | openssl base64 -d&lt;br /&gt;
&lt;span style=&quot;color: #080;&quot;&gt;sneakyg33k@aol.com&lt;/span&gt;&lt;br /&gt;
$ echo &quot;NTU4cjAwbHo=&quot; | openssl base64 -d&lt;br /&gt;
&lt;span style=&quot;color: #080;&quot;&gt;558r00lz&lt;/span&gt;&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;i&gt;Note: $ is the command prompt, what follows it is the command with output in green.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
So we find Ann&#039;s email password is &lt;code&gt;558r00lz&lt;/code&gt;. This the answer to question 2. &lt;br /&gt;
&lt;br /&gt;
Next we have a look at the attachment which is base64 encoded. We copy all the blue text above and paste into a file called &lt;code&gt;attachment.b64&lt;/code&gt; and issue the following commands.&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
$ openssl base64 -d &lt; attachment.b64 &gt; secretrendezvous.docx&lt;br /&gt;
$ md5 secretrendezvous.docx&lt;br /&gt;
&lt;span style=&quot;color: #080;&quot;&gt;MD5 (secretrendezvous.docx) = 9e423e11db88f01bbff81172839e1923&lt;/span&gt;&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
This decodes the data and outputs to &lt;code&gt;secretrendezvous.docx&lt;/code&gt;. We can open the file, verifying it is good and thus the md5 sum of &lt;code&gt;9e423e11db88f01bbff81172839e1923&lt;/code&gt; is the answer to question 6. When we open the file we see an image like the one below.&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;img src=&quot;http://gl.ib.ly/uploads/forensicspuzzle2/map.png&quot; width=&quot;500px&quot; /&gt;&lt;/center&gt;&lt;br /&gt;
&lt;br /&gt;
This tells us that Ann was off to  Playa del Carmen in Mexico. This is the answer to question 7. We only now need to get the md5 sum of the image in the document. This is easy enough as we can just do the following:&lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
$ unzip  secretrendezvous.docx -d attachment&lt;br /&gt;
&lt;span style=&quot;color: #080;&quot;&gt;Archive:  out-1.docx&lt;br /&gt;
  inflating: attachment/[Content_Types].xml  &lt;br /&gt;
  inflating: attachment/_rels/.rels  &lt;br /&gt;
  inflating: attachment/word/_rels/document.xml.rels  &lt;br /&gt;
  inflating: attachment/word/document.xml  &lt;br /&gt;
 extracting: attachment/word/media/image1.png  &lt;br /&gt;
  inflating: attachment/word/theme/theme1.xml  &lt;br /&gt;
  inflating: attachment/word/settings.xml  &lt;br /&gt;
  inflating: attachment/word/webSettings.xml  &lt;br /&gt;
  inflating: attachment/word/styles.xml  &lt;br /&gt;
  inflating: attachment/docProps/core.xml  &lt;br /&gt;
  inflating: attachment/word/numbering.xml  &lt;br /&gt;
  inflating: attachment/word/fontTable.xml  &lt;br /&gt;
  inflating: attachment/docProps/app.xml  &lt;/span&gt;&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
The only image file in there is &lt;code&gt;attachment/word/media/image1.png&lt;/code&gt;. Open it up to verify it is the business and then just do &lt;br /&gt;
&lt;br /&gt;
&lt;code&gt;&lt;br /&gt;
$ md5 attachment/word/media/image1.png  &lt;br /&gt;
&lt;span style=&quot;color: #080;&quot;&gt;MD5 (attachment/word/media/image1.png) = aadeace50997b1ba24b09ac2ef1940b7&lt;/span&gt;&lt;br /&gt;
&lt;/code&gt;&lt;br /&gt;
&lt;br /&gt;
This is the answer to question 8, and we&#039;re finished. That was quick! The &lt;a href=&quot;http://gl.ib.ly/exit.php?url_id=107&amp;amp;entry_id=39&quot; title=&quot;http://forensicscontest.com/2009/11/24/puzzle-2-answers&quot;  onmouseover=&quot;window.status=&#039;http://forensicscontest.com/2009/11/24/puzzle-2-answers&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;answers&lt;/a&gt; have been published so you can verify. Now that person has turned up and is dragging me away from my computer so that&#039;s all for now. 
    </content:encoded>

    <pubDate>Fri, 27 Nov 2009 11:20:00 -0700</pubDate>
    <guid isPermaLink="false">http://gl.ib.ly/archives/39-guid.html</guid>
    <category>forensics</category>
<category>grep</category>
<category>puzzle</category>
<category>security</category>
<category>tcpdump</category>
<category>wireshark</category>

</item>
<item>
    <title>Analysing the byte entropy of a FAT formatted disk</title>
    <link>http://gl.ib.ly/archives/14-Analysing-the-byte-entropy-of-a-FAT-formatted-disk.html</link>
            <category>Forensics</category>
    
    <comments>http://gl.ib.ly/archives/14-Analysing-the-byte-entropy-of-a-FAT-formatted-disk.html#comments</comments>
    <wfw:comment>http://gl.ib.ly/wfwcomment.php?cid=14</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://gl.ib.ly/rss.php?version=2.0&amp;type=comments&amp;cid=14</wfw:commentRss>
    

    <author>nospam@example.com (Tariq)</author>
    <content:encoded>
    Over at the &lt;a href=&quot;http://gl.ib.ly/exit.php?url_id=26&amp;amp;entry_id=14&quot; title=&quot;http://www.honeynet.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.honeynet.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Honeynet Project&lt;/a&gt; they used to run security competitions which were quite a bit of fun. I remembered one in particular which I looked at but hadn&#039;t completed. It dealt with the &lt;a href=&quot; http://old.honeynet.org/scans/scan24/&quot;&gt;forensic investigation of a floppy disk&lt;/a&gt;. I was tinkering with an application to measure byte entropy and thinking of a way that it could be used in a forensic investigation. There is no point using the little application to analyse my terabyte (TB) sized drives so remembering the floppy disk challenge I downloaded the &lt;a href=&quot;http://gl.ib.ly/exit.php?url_id=39&amp;amp;entry_id=14&quot; title=&quot;http://old.honeynet.org/scans/scan24/image.zip&quot;  onmouseover=&quot;window.status=&#039;http://old.honeynet.org/scans/scan24/image.zip&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;floppy disk image&lt;/a&gt; (1.44MB;MD5 = b676147f63923e1f428131d59b1d6a72).    &lt;br /&gt;&lt;a href=&quot;http://gl.ib.ly/archives/14-Analysing-the-byte-entropy-of-a-FAT-formatted-disk.html#extended&quot;&gt;Continue reading &quot;Analysing the byte entropy of a FAT formatted disk&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 27 Jan 2009 21:57:00 -0700</pubDate>
    <guid isPermaLink="false">http://gl.ib.ly/archives/14-guid.html</guid>
    <category>analysis</category>
<category>dd</category>
<category>entropy</category>
<category>fat</category>
<category>floppy</category>
<category>forensics</category>
<category>mssf</category>
<category>od</category>
<category>password</category>
<category>winhex</category>
<category>xxd</category>

</item>

</channel>
</rss>