<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GL.IB.LY &#187; wireshark</title>
	<atom:link href="http://gl.ib.ly/tag/wireshark/feed/" rel="self" type="application/rss+xml" />
	<link>http://gl.ib.ly</link>
	<description>Thoughts on security, computing, business and stuff!</description>
	<lastBuildDate>Sun, 18 May 2014 11:51:56 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.9.1</generator>
	<item>
		<title>Ann skips bail. Cue forensics puzzle.</title>
		<link>http://gl.ib.ly/computing/2009/11/27/ann-skips-bail-cue-forensics-puzzle/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ann-skips-bail-cue-forensics-puzzle</link>
		<comments>http://gl.ib.ly/computing/2009/11/27/ann-skips-bail-cue-forensics-puzzle/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 09:00:01 +0000</pubDate>
		<dc:creator><![CDATA[tariq]]></dc:creator>
				<category><![CDATA[Computing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[grep]]></category>
		<category><![CDATA[puzzle]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://gl.ib.ly/?p=69</guid>
		<description><![CDATA[<p>Found a website and a forensics contest yesterday quite by accident. I was waiting for somebody before going out for the night and I thought this might be a little fun while I waited. Now the contest had closed and<span class="ellipsis">&#8230;</span><div class="read-more"><a href="http://gl.ib.ly/computing/2009/11/27/ann-skips-bail-cue-forensics-puzzle/">Read more &#8250;</a></div><!-- end of .read-more --></p><p>The post <a href="http://gl.ib.ly/computing/2009/11/27/ann-skips-bail-cue-forensics-puzzle/">Ann skips bail. Cue forensics puzzle.</a> appeared first on <a href="http://gl.ib.ly">GL.IB.LY</a>.</p>]]></description>
				<content:encoded><![CDATA[<p><span style="color: #545454;">Found a website and a forensics contest yesterday quite by accident. I was waiting for somebody before going out for the night and I thought this might be a little fun while I waited. Now the contest had closed and the results where available, which I ignored until the end and went straight to </span><a style="color: #7da939;" title="http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail" href="https://web.archive.org/web/20100526211205/http://gl.ib.ly/exit.php?url_id=105&amp;entry_id=39">Puzzle #2: Ann skips bail</a><span style="color: #545454;">.</span><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">The puzzle revolves around a packet capture of Ann&#8217;s network taken by wily investigators before she skipped bail. Police are confident that she communicated with a secret lover prior to her disappearance. And so follows a number of competition questions. It is important to note that the organizers are looking for the most elegant solutions, and you won&#8217;t see that here. What you will see is how to solve the puzzle very quickly.</span></p>
<p style="padding-left: 30px;"><span style="color: #545454;">1. What is Ann’s email address?</span><br style="color: #545454;" /><span style="color: #545454;">2. What is Ann’s email password?</span><br style="color: #545454;" /><span style="color: #545454;">3. What is Ann’s secret lover’s email address?</span><br style="color: #545454;" /><span style="color: #545454;">4. What two items did Ann tell her secret lover to bring?</span><br style="color: #545454;" /><span style="color: #545454;">5. What is the NAME of the attachment Ann sent to her secret lover?</span><br style="color: #545454;" /><span style="color: #545454;">6. What is the MD5sum of the attachment Ann sent to her secret lover?</span><br style="color: #545454;" /><span style="color: #545454;">7. In what CITY and COUNTRY is their rendez-vous point?</span><br style="color: #545454;" /><span style="color: #545454;">8. What is the MD5sum of the image embedded in the document?</span></p>
<p><br style="color: #545454;" /><span style="color: #545454;">I downloaded the </span><a style="color: #7da939;" title="http://forensicscontest.com/contest02/evidence02.pcap" href="https://web.archive.org/web/20100526211205/http://gl.ib.ly/exit.php?url_id=106&amp;entry_id=39">packet dump file</a><span style="color: #545454;"> from the organiser&#8217;s site and verified the hash using </span><code style="color: #545454;">md5</code><span style="color: #545454;"> as I am on a Mac, otherwise </span><code style="color: #545454;">md5sum</code><span style="color: #545454;"> does the job.</span><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">I fired up </span><code style="color: #545454;">wireshark</code><span style="color: #545454;"> and opened the packet capture file. There appeared to be a good bit of SMTP traffic. So I did a quick</span></p>
<pre style="color: #545454; padding-left: 30px;">grep -an "To:.*\|From:*\|Subject:.*" evidence02.pcap</pre>
<p><br style="color: #545454;" /><span style="color: #545454;">on the packet dump which revealed the following.</span><br style="color: #545454;" /><code style="color: #545454;"></code></p>
<p style="padding-left: 30px;"><code style="color: #545454;"><br />
From: "Ann Dercover" &lt;sneakyg33k@aol.com&gt;<br />
To: &lt;sec558@gmail.com&gt;<br />
Subject: lunch next week<br />
From: "Ann Dercover" &lt;sneakyg33k@aol.com&gt;<br />
To: &lt;mistersecretx@aol.com&gt;<br />
Subject: rendezvous</code></p>
<p><span style="color: #545454;">Its clear that Ann Dercover&#8217;s email address is </span><code style="color: #545454;">sneakyg33k@aol.com</code><span style="color: #545454;">. This is the answer to question 1. We also see she sent two emails. One to </span><code style="color: #545454;">mistersecretx@aol.com</code><span style="color: #545454;">, could this be Ann&#8217;s secret lover? I expanded the grep to </span></p>
<pre style="color: #545454; padding-left: 30px;">grep -aA50 "mistersecretx@aol.com" evidence02.pcap</pre>
<p><br style="color: #545454;" /><span style="color: #545454;">This gives me 50 lines after and including lines matching </span><code style="color: #545454;">mistersecretx@aol.com</code><span style="color: #545454;">. </span></p>
<p style="padding-left: 30px;"><code style="color: #545454;">To: &lt;mistersecretx@aol.com&gt;<br />
Subject: rendezvous<br />
Date: Sat, 10 Oct 2009 07:38:10 -0600<br />
MIME-Version: 1.0<br />
Content-Type: multipart/mixed;<br />
boundary="----=_NextPart_000_000D_01CA497C.9DEC1E70"<br />
X-Priority: 3<br />
X-MSMail-Priority: Normal<br />
X-Mailer: Microsoft Outlook Express 6.00.2900.2180<br />
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180</code></p>
<p>This is a multi-part message in MIME format.</p>
<p>&#8212;&#8212;=_NextPart_000_000D_01CA497C.9DEC1E70<br />
Content-Type: multipart/alternative;<br />
boundary=&#8221;&#8212;-=_NextPart_001_000E_01CA497C.9DEC1E70&#8243;</p>
<p>&#8212;&#8212;=_NextPart_001_000E_01CA497C.9DEC1E70<br />
Content-Type: text/plain;<br />
charset=&#8221;iso-8859-1&#8243;<br />
Content-Transfer-Encoding: quoted-printable</p>
<p>Hi sweetheart! Bring your fake passport and a bathing suit. Address =<br />
attached. love, Ann<br />
&#8212;&#8212;=_NextPart_001_000E_01CA497C.9DEC1E70<br />
Content-Type: text/html;<br />
charset=&#8221;iso-8859-1&#8243;<br />
Content-Transfer-Encoding: quoted-printable</p>
<p>&#8230;SNIP&#8230;</p>
<p>Hi sweetheart! Bring your fake passport =<br />
and a=20<br />
bathing suit. Address attached. love, Ann</p>
<p>&#8230;SNIP&#8230;</p>
<p>&#8212;&#8212;=_NextPart_000_000D_01CA497C.9DEC1E70<br />
Content-Type: application/octet-stream;<br />
name=&#8221;secretrendezvous.docx&#8221;<br />
Content-Transfer-Encoding: base64<br />
Content-Disposition: attachment;<br />
filename=&#8221;secretrendezvous.docx&#8221;<br />
<br style="color: #545454;" /><br style="color: #545454;" /></p>
<p><span style="color: #545454;">Wow. So </span><code style="color: #545454;">mistersecretx@aol.com</code><span style="color: #545454;"> IS the email address of Ann&#8217;s lover. This is the answer to question 3. We also see in her message she instructs them to &#8220;bring your fake passport and bathing suit&#8221;, this is the answer to question 4. Towards the bottom we see an attachment that probably appears later than the lines we grep&#8217;d called </span><code style="color: #545454;">secretrendezvous.docx</code><span style="color: #545454;"> which will appear base64 encoding. This is the answer to question 5.</span><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">I then returned to </span><code style="color: #545454;">wireshark</code><span style="color: #545454;">, looking down through the packets I quickly see SMTP traffic with </span><i style="color: #545454;">C: DATA fragment</i><span style="color: #545454;"> which tells us this traffic was broken up into smaller pieces. This is likely to be an email with a large attachment. I right clicked on one of these packets as shown below and clicked on </span><i style="color: #545454;">Follow TCP Stream</i><span style="color: #545454;"> as shown below.</span><br style="color: #545454;" /><br style="color: #545454;" /></p>
<p><center style="color: #545454;"><img src="https://web.archive.org/web/20100526211205im_/http://gl.ib.ly/uploads/forensicspuzzle2/wireshark.png" alt="" width="500px" /></center><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">This gives me the following.</span><br style="color: #545454;" /><code style="color: #545454;"><br />
</code></p>
<p style="padding-left: 30px;"><code style="color: #545454;">220 cia-mc07.mx.aol.com ESMTP mail_cia-mc07.1; Sat, 10 Oct 2009 15:37:56 -0400<br />
<span style="color: #ff0000;">EHLO annlaptop</span><br />
250-cia-mc07.mx.aol.com host-69-140-19-190.static.comcast.net<br />
250-AUTH=LOGIN PLAIN XAOL-UAS-MB<br />
250-AUTH LOGIN PLAIN XAOL-UAS-MB<br />
250-STARTTLS<br />
250-CHUNKING<br />
250-BINARYMIME<br />
250-X-AOL-FWD-BY-REF<br />
250-X-AOL-DIV_TAG<br />
250-X-AOL-OUTBOX-COPY<br />
250 HELP<br />
<span style="color: #ff0000;">AUTH LOGIN</span><br />
334 VXNlcm5hbWU6<br />
<span style="color: #ff0000;">c25lYWt5ZzMza0Bhb2wuY29t</span><br />
334 UGFzc3dvcmQ6<br />
<span style="color: #ff0000;">NTU4cjAwbHo=</span><br />
235 AUTHENTICATION SUCCESSFUL<br />
<span style="color: #ff0000;">MAIL FROM: &lt;sneakyg33k@aol.com&gt;</span><br />
250 OK<br />
<span style="color: #ff0000;">RCPT TO: &lt;mistersecretx@aol.com&gt;</span><br />
250 OK<br />
<span style="color: #ff0000;">DATA</span><br />
354 START MAIL INPUT, END WITH "." ON A LINE BY ITSELF<br />
<span style="color: #ff0000;">Message-ID: &lt;001101ca49ae$e93e45b0$9f01a8c0@annlaptop&gt;<br />
From: "Ann Dercover" &lt;sneakyg33k@aol.com&gt;<br />
To: &lt;mistersecretx@aol.com&gt;<br />
Subject: rendezvous<br />
Date: Sat, 10 Oct 2009 07:38:10 -0600<br />
MIME-Version: 1.0<br />
Content-Type: multipart/mixed;<br />
.boundary="----=_NextPart_000_000D_01CA497C.9DEC1E70"<br />
X-Priority: 3<br />
X-MSMail-Priority: Normal<br />
X-Mailer: Microsoft Outlook Express 6.00.2900.2180<br />
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180</span></code></p>
<p>This is a multi-part message in MIME format.</p>
<p>&#8212;&#8212;=_NextPart_000_000D_01CA497C.9DEC1E70<br />
Content-Type: multipart/alternative;<br />
.boundary=&#8221;&#8212;-=_NextPart_001_000E_01CA497C.9DEC1E70&#8243;</p>
<p>&#8212;&#8212;=_NextPart_001_000E_01CA497C.9DEC1E70<br />
Content-Type: text/plain;<br />
.charset=&#8221;iso-8859-1&#8243;<br />
Content-Transfer-Encoding: quoted-printable</p>
<p>Hi sweetheart! Bring your fake passport and a bathing suit. Address =<br />
attached. love, Ann<br />
&#8212;&#8212;=_NextPart_001_000E_01CA497C.9DEC1E70<br />
Content-Type: text/html;<br />
.charset=&#8221;iso-8859-1&#8243;<br />
Content-Transfer-Encoding: quoted-printable</p>
<p>&lt;!DOCTYPE HTML PUBLIC &#8220;-//W3C//DTD HTML 4.0 Transitional//EN&#8221;&gt;<br />
&lt;HTML&gt;&lt;HEAD&gt;<br />
&lt;META http-equiv=3DContent-Type content=3D&#8221;text/html; =<br />
charset=3Diso-8859-1&#8243;&gt;<br />
&lt;META content=3D&#8221;MSHTML 6.00.2900.2853&#8243; name=3DGENERATOR&gt;<br />
&lt;STYLE&gt;&lt;/STYLE&gt;<br />
&lt;/HEAD&gt;<br />
&lt;BODY bgColor=3D#ffffff&gt;<br />
&lt;DIV&gt;&lt;FONT face=3DArial size=3D2&gt;Hi sweetheart! Bring your fake passport =<br />
and a=20<br />
bathing suit. Address attached. love, Ann&lt;/FONT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</p>
<p>&#8212;&#8212;=_NextPart_001_000E_01CA497C.9DEC1E70&#8211;</p>
<p>&#8212;&#8212;=_NextPart_000_000D_01CA497C.9DEC1E70<br />
Content-Type: application/octet-stream;<br />
.name=&#8221;secretrendezvous.docx&#8221;<br />
Content-Transfer-Encoding: base64<br />
Content-Disposition: attachment;<br />
.filename=&#8221;secretrendezvous.docx&#8221;</p>
<p><span style="color: #0000ff;">UEsDBBQABgAIAAAAIQDleUAGfwEAANcFAAATAAgCW0NvbnRlbnRfVHlwZXNdLnhtbCCiBAIooAAC<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC0<br />
VMluwjAQvVfqP0S+VsTQQ1VVBA5dji1S6QcYexKsepNttr/vOEBEKQSpwCVSPH7LPI/dHy61yubg<br />
g7SmIL28SzIw3AppqoJ8jd86jyQLkRnBlDVQkBUEMhzc3vTHKwchQ7QJBZnG6J4oDXwKmoXcOjBY<br />
Ka3XLOKvr6hj/JtVQO+73QfKrYlgYicmDjLov0DJZipmr0tcXjtxpiLZ83pfkiqI1Amf1ulBhAcV<br />
9iDMOSU5i9gbnRux56uz8ZQjst4TptKFOzR+RCFVfnvaFdjgPjBMLwVkI+bjO9PonC6sF1RYPtPY<br />
dd5Oc8CnLUvJocEnNucthxDwlLTKm4pm0mz9H/VhZnoCHpGXN9JQnzQR4kpBuLyDNW+bPIY18tYF<br />
imd3tj6kgRUgOngeDnyU0MzP0fwDxIjpX6P5DXNb+/UoRrymQOtv7+wMapqTkiVe5TGbKDhb78/4<br />
N9QnTSxg8nm19HfI24w088et/0cY2zcroQ9MHa2f5cEPAAAA//8DAFBLAwQUAAYACAAAACEAHpEa<br />
t/MAAABOAgAACwAIAl9yZWxzLy5yZWxzIKIEAiigAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIyS20oDQQyG7wXfYch9N9sKItLZ3kihdyLr<br />
A4SZ7AF3Dsyk2r69oyC6UNte5vTny0/Wm4Ob1DunPAavYVnVoNibYEffa3htt4sHUFnIW5qCZw1H<br />
zrBpbm/WLzyRlKE8jDGrouKzhkEkPiJmM7CjXIXIvlS6kBxJCVOPkcwb9Yyrur7H9FcDmpmm2lkN<br />
aWfvQLXHWDZf1g5dNxp+Cmbv2MuJFcgHYW/ZLmIqbEnGco1qKfUsGmwwzyWdkWKsCjbgaaLV9UT/<br />
X4uOhSwJoQmJz/N8dZwDWl4PdNmiecevOx8hWSwWfXv7Q4OzL2g+AQAA//8DAFBLAwQUAAYACAAA<br />
ACEApOAquCABAAA6BAAAHAAIAXdvcmQvX3JlbHMvZG9jdW1lbnQueG1sLnJlbHMgogQBKKAAAQAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA<br />
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACsk01OwzAQhfdI3MHynjgpUBCq0w1C6hbCAdxkkljE<br />
P7KnQG7PKFKbVJSwycbSvCjvfZ7xbLbfpmOfEKJ2VvIsSTkDW7pK20by9+Ll5pGziMpWqnMWJO8h<br />
8m1+fbV5hU4h/RRb7SMjFxslbxH9kxCxbMGomDgPlr7ULhiFVIZGeFV+qAbEKk3XIkw9eH7myXaV<br />
5GFX3XJW9J6S//d2da1LeHblwYDFCxEiAiLdLJKnCg2g5EclIU4uLiM8LImA1BoY84dSDGc2x7Ba<br />
kiFi39EcxyYM9Vx8tmS8PZg9BJrDSHCS5iDWS0LUzmKh9t1kFidpDuJ+SQhtaBfGLhiotBKDmCWe</span></p>
<p>&#8230;SNIP: not publishing the whole thing, its a bit long. <a style="color: #7da939;" href="https://web.archive.org/web/20100526211205/http://gl.ib.ly/uploads/forensicspuzzle2/attachment.b64" target="_blank">See the whole thing?</a></p>
<p>JZ2ekPwNAAD//wMAUEsBAi0AFAAGAAgAAAAhAOV5QAZ/AQAA1wUAABMAAAAAAAAAAAAAAAAAAAAA<br />
AFtDb250ZW50X1R5cGVzXS54bWxQSwECLQAUAAYACAAAACEAHpEat/MAAABOAgAACwAAAAAAAAAA<br />
AAAAAAC4AwAAX3JlbHMvLnJlbHNQSwECLQAUAAYACAAAACEApOAquCABAAA6BAAAHAAAAAAAAAAA<br />
AAAAAADcBgAAd29yZC9fcmVscy9kb2N1bWVudC54bWwucmVsc1BLAQItABQABgAIAAAAIQA6Q0kI<br />
FQQAAFgKAAARAAAAAAAAAAAAAAAAAD4JAAB3b3JkL2RvY3VtZW50LnhtbFBLAQItAAoAAAAAAAAA<br />
IQBg7VaATPYCAEz2AgAVAAAAAAAAAAAAAAAAAIINAAB3b3JkL21lZGlhL2ltYWdlMS5wbmdQSwEC<br />
LQAUAAYACAAAACEAlrWt4pYGAABQGwAAFQAAAAAAAAAAAAAAAAABBAMAd29yZC90aGVtZS90aGVt<br />
ZTEueG1sUEsBAi0AFAAGAAgAAAAhAIkUT0qVAwAAcQgAABEAAAAAAAAAAAAAAAAAygoDAHdvcmQv<br />
c2V0dGluZ3MueG1sUEsBAi0AFAAGAAgAAAAhAErYipK7AAAABAEAABQAAAAAAAAAAAAAAAAAjg4D<br />
AHdvcmQvd2ViU2V0dGluZ3MueG1sUEsBAi0AFAAGAAgAAAAhADVKHsm+CgAALFoAAA8AAAAAAAAA<br />
AAAAAAAAew8DAHdvcmQvc3R5bGVzLnhtbFBLAQItABQABgAIAAAAIQCQUuGobwEAANcCAAARAAAA<br />
AAAAAAAAAAAAAGYaAwBkb2NQcm9wcy9jb3JlLnhtbFBLAQItABQABgAIAAAAIQAXVdHWCQQAAMsZ<br />
AAASAAAAAAAAAAAAAAAAAAwdAwB3b3JkL251bWJlcmluZy54bWxQSwECLQAUAAYACAAAACEAu6G5<br />
NXECAACGCAAAEgAAAAAAAAAAAAAAAABFIQMAd29yZC9mb250VGFibGUueG1sUEsBAi0AFAAGAAgA<br />
AAAhAKVR8wbYAQAA2QMAABAAAAAAAAAAAAAAAAAA5iMDAGRvY1Byb3BzL2FwcC54bWxQSwUGAAAA<br />
AA0ADQBEAwAA9CYDAAAA</p>
<p>&#8212;&#8212;=_NextPart_000_000D_01CA497C.9DEC1E70&#8211;</p>
<p>.<br />
250 OK<br />
<span style="color: #ff0000;">QUIT</span><br />
221 SERVICE CLOSING CHANNEL</p>
<p><span style="color: #545454;">You may or may not realise that parts of the communication are base64 encoded. Lets take a look at some information encoded at the beginning of this communication again. </span><code style="color: #545454;"><br />
</code></p>
<p style="padding-left: 30px;"><code style="color: #545454;"><span style="color: #ff0000;">AUTH LOGIN</span><br />
334 VXNlcm5hbWU6<br />
<span style="color: #ff0000;">c25lYWt5ZzMza0Bhb2wuY29t</span><br />
334 UGFzc3dvcmQ6<br />
<span style="color: #ff0000;">NTU4cjAwbHo=</span><br />
235 AUTHENTICATION SUCCESSFUL</code></p>
<p><span style="color: #545454;">Here Ann is authenticating with the service. Her responses are shown in red, and as you can see they&#8217;re a bit cryptic; however, they look like they are encoded in base64. So we run the following two commands.</span></p>
<p style="padding-left: 30px;"><code style="color: #545454;">$ echo "c25lYWt5ZzMza0Bhb2wuY29t" | openssl base64 -d<br />
<span style="color: #008800;">sneakyg33k@aol.com</span><br />
$ echo "NTU4cjAwbHo=" | openssl base64 -d<br />
<span style="color: #008800;">558r00lz</span><br />
</code><br style="color: #545454;" /><i style="color: #545454;"></i></p>
<p><i style="color: #545454;">Note: $ is the command prompt, what follows it is the command with output in green.</i><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">So we find Ann&#8217;s email password is </span><code style="color: #545454;">558r00lz</code><span style="color: #545454;">. This the answer to question 2. </span><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">Next we have a look at the attachment which is base64 encoded. We copy all the blue text above and paste into a file called </span><code style="color: #545454;">attachment.b64</code><span style="color: #545454;"> and issue the following commands.</span><code style="color: #545454;"><br />
</code></p>
<p style="padding-left: 30px;"><code style="color: #545454;">$ openssl base64 -d &lt; attachment.b64 &gt; secretrendezvous.docx<br />
$ md5 secretrendezvous.docx<br />
<span style="color: #008800;">MD5 (secretrendezvous.docx) = 9e423e11db88f01bbff81172839e1923</span><br />
</code></p>
<p><br style="color: #545454;" /><span style="color: #545454;">This decodes the data and outputs to </span><code style="color: #545454;">secretrendezvous.docx</code><span style="color: #545454;">. We can open the file, verifying it is good and thus the md5 sum of </span><code style="color: #545454;">9e423e11db88f01bbff81172839e1923</code><span style="color: #545454;"> is the answer to question 6. When we open the file we see an image like the one below.</span><br style="color: #545454;" /><br style="color: #545454;" /></p>
<p><center style="color: #545454;"><img src="https://web.archive.org/web/20100526211205im_/http://gl.ib.ly/uploads/forensicspuzzle2/map.png" alt="" width="500px" /></center><br style="color: #545454;" /><br style="color: #545454;" /><span style="color: #545454;">This tells us that Ann was off to Playa del Carmen in Mexico. This is the answer to question 7. We only now need to get the md5 sum of the image in the document. This is easy enough as we can just do the following:</span><br style="color: #545454;" /><br style="color: #545454;" /><code style="color: #545454;"><br />
</code></p>
<p style="padding-left: 30px;"><code style="color: #545454;">$ unzip secretrendezvous.docx -d attachment<br />
<span style="color: #008800;">Archive: out-1.docx<br />
inflating: attachment/[Content_Types].xml<br />
inflating: attachment/_rels/.rels<br />
inflating: attachment/word/_rels/document.xml.rels<br />
inflating: attachment/word/document.xml<br />
extracting: attachment/word/media/image1.png<br />
inflating: attachment/word/theme/theme1.xml<br />
inflating: attachment/word/settings.xml<br />
inflating: attachment/word/webSettings.xml<br />
inflating: attachment/word/styles.xml<br />
inflating: attachment/docProps/core.xml<br />
inflating: attachment/word/numbering.xml<br />
inflating: attachment/word/fontTable.xml<br />
inflating: attachment/docProps/app.xml </span></code></p>
<p><br style="color: #545454;" /><span style="color: #545454;">The only image file in there is </span><code style="color: #545454;">attachment/word/media/image1.png</code><span style="color: #545454;">. Open it up to verify it is the business and then just do </span></p>
<p style="padding-left: 30px;"><code style="color: #545454;">$ md5 attachment/word/media/image1.png<br />
<span style="color: #008800;">MD5 (attachment/word/media/image1.png) = aadeace50997b1ba24b09ac2ef1940b7</span></code></p>
<p><span style="color: #545454;">This is the answer to question 8, and we&#8217;re finished. That was quick! The </span><a style="color: #7da939;" title="http://forensicscontest.com/2009/11/24/puzzle-2-answers" href="https://web.archive.org/web/20100526211205/http://gl.ib.ly/exit.php?url_id=107&amp;entry_id=39">answers</a><span style="color: #545454;"> have been published so you can verify. Now that person has turned up and is dragging me away from my computer so that&#8217;s all for now.</span></p>
<p><span style="color: #545454; font-family: Arial, Verdana, sans-serif; font-size: 14px; line-height: normal;"> </span></p>
<p>The post <a href="http://gl.ib.ly/computing/2009/11/27/ann-skips-bail-cue-forensics-puzzle/">Ann skips bail. Cue forensics puzzle.</a> appeared first on <a href="http://gl.ib.ly">GL.IB.LY</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://gl.ib.ly/computing/2009/11/27/ann-skips-bail-cue-forensics-puzzle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
