• Like
Network Forensics Puzzle Contest に挑戦 #1
Upcoming SlideShare
Loading in...5
×

Network Forensics Puzzle Contest に挑戦 #1

  • 1,271 views
Uploaded on

第8回「ネットワーク パケットを読む会(仮)」の「 Network Forensics Puzzle Contest に挑戦」での発表資料です。

第8回「ネットワーク パケットを読む会(仮)」の「 Network Forensics Puzzle Contest に挑戦」での発表資料です。

  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Be the first to comment
    Be the first to like this
No Downloads

Views

Total Views
1,271
On Slideshare
0
From Embeds
0
Number of Embeds
1

Actions

Shares
Downloads
9
Comments
0
Likes
0

Embeds 0

No embeds

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
    No notes for slide

Transcript

  • 1. Network Forensics PuzzleContest #1 を解析してみた 村地 彰 aka hebikuzure
  • 2. Puzzle #1: Anns Bad AIM• 出題 http://forensicscontest.com/2009/09/25 /puzzle-1-anns-bad-aim• 対象ファイル http://philosecurity.org/558/contest_01 /evidence.pcap
  • 3. NetworkMinor に喰わせてみた• NetworkMiner http://www.netresec.com/?page=Network Miner• [File] – [Open] で evidence.pcap を開くと…
  • 4. ファイルが抽出されたよ
  • 5. 抽出されたファイル
  • 6. IM メッセージも見えるよ
  • 7. 任務完了(^_^;)• NetworkMinor 最強っっっっっ!!!• という訳にはいかないですよね…….
  • 8. 1. What is the name of Ann’s IM buddy?
  • 9. 2. What was the first comment in the captured IM conversation?
  • 10. 3. What is the name of the file Ann transferred?
  • 11. 4. What is the magic number of the file you want to extract?
  • 12. 5. What was the MD5sum of the file?
  • 13. 6. What is the secret recipe?