<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Puzzle #4 Update</title>
	<atom:link href="http://forensicscontest.com/2010/02/17/puzzle-4-update/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicscontest.com/2010/02/17/puzzle-4-update</link>
	<description></description>
	<lastBuildDate>Sat, 22 Oct 2011 00:14:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Steve</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-550</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Fri, 28 May 2010 11:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-550</guid>
		<description>@Ahmed: an exploit/a port scan could be unsuccessful from the hacker&#039;s point of view. Although, it implies an attacker and one or more targets. A target is a host that you try to attack as an attacker. In other terms, even if there is no answer from a target, it remains a target although.</description>
		<content:encoded><![CDATA[<p>@Ahmed: an exploit/a port scan could be unsuccessful from the hacker&#8217;s point of view. Although, it implies an attacker and one or more targets. A target is a host that you try to attack as an attacker. In other terms, even if there is no answer from a target, it remains a target although.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-324</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 24 Mar 2010 19:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-324</guid>
		<description>Nice solution, Sébastien DAMAYE!  I also used a database (SQLite) to solve the puzzle, but mine doesn&#039;t have nice graphs ;)  It looks like we both got the same answers so hopefully we&#039;re both correct.

As far as your open question about telling the difference between SYN and TCP Connect scans when there aren&#039;t any open ports...  AFAIK you&#039;re only option is to find the scanner used and differences between the two scan types.  For example, Nmap apparently doesn&#039;t change the source port on SYN segments sent during a SYN scan, but it does change the source port for each TCP Connect SYN segment it sends.</description>
		<content:encoded><![CDATA[<p>Nice solution, Sébastien DAMAYE!  I also used a database (SQLite) to solve the puzzle, but mine doesn&#8217;t have nice graphs <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   It looks like we both got the same answers so hopefully we&#8217;re both correct.</p>
<p>As far as your open question about telling the difference between SYN and TCP Connect scans when there aren&#8217;t any open ports&#8230;  AFAIK you&#8217;re only option is to find the scanner used and differences between the two scan types.  For example, Nmap apparently doesn&#8217;t change the source port on SYN segments sent during a SYN scan, but it does change the source port for each TCP Connect SYN segment it sends.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sébastien DAMAYE</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-314</link>
		<dc:creator>Sébastien DAMAYE</dc:creator>
		<pubDate>Fri, 19 Mar 2010 04:16:53 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-314</guid>
		<description>@Ahmed: an exploit/a port scan could be unsuccessful from the hacker&#039;s point of view. Although, it implies an attacker and one or more targets. A target is a host that you try to attack as an attacker. In other terms, even if there is no answer from a target, it remains a target although.</description>
		<content:encoded><![CDATA[<p>@Ahmed: an exploit/a port scan could be unsuccessful from the hacker&#8217;s point of view. Although, it implies an attacker and one or more targets. A target is a host that you try to attack as an attacker. In other terms, even if there is no answer from a target, it remains a target although.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ahmed Adel</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-311</link>
		<dc:creator>Ahmed Adel</dc:creator>
		<pubDate>Thu, 18 Mar 2010 18:08:26 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-311</guid>
		<description>I wanted to make sure that I understand the question about the targets right, does this question means all the IPs that responded even if they had no open ports on them??</description>
		<content:encoded><![CDATA[<p>I wanted to make sure that I understand the question about the targets right, does this question means all the IPs that responded even if they had no open ports on them??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Deepak Khemani</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-229</link>
		<dc:creator>Deepak Khemani</dc:creator>
		<pubDate>Mon, 22 Feb 2010 06:22:12 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-229</guid>
		<description>Hi 

I have submitted my ansewres for puzzle 4. Before resubmitting I would like to clarify the meaning of &quot;First Port Scan&quot;.

And regarding the sweet part of competion. If I win the competition will the prize be delivered to India as I am participating from India.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi </p>
<p>I have submitted my ansewres for puzzle 4. Before resubmitting I would like to clarify the meaning of &#8220;First Port Scan&#8221;.</p>
<p>And regarding the sweet part of competion. If I win the competition will the prize be delivered to India as I am participating from India.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sherri</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-227</link>
		<dc:creator>sherri</dc:creator>
		<pubDate>Sun, 21 Feb 2010 09:31:03 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-227</guid>
		<description>Hi Sébastien,

Normally we use &quot;tcpdump -s 0 -nn&quot; to get our captures. The &quot;-s 0&quot; flag tells tcpdump to capture the entire packet, and the &quot;-nn&quot; tells it not to resolve hostnames or portnames. Hope that helps! If you have questions about specific discrepancies, feel free to post them and we&#039;ll be happy to give you feedback.

best,
Sherri</description>
		<content:encoded><![CDATA[<p>Hi Sébastien,</p>
<p>Normally we use &#8220;tcpdump -s 0 -nn&#8221; to get our captures. The &#8220;-s 0&#8243; flag tells tcpdump to capture the entire packet, and the &#8220;-nn&#8221; tells it not to resolve hostnames or portnames. Hope that helps! If you have questions about specific discrepancies, feel free to post them and we&#8217;ll be happy to give you feedback.</p>
<p>best,<br />
Sherri</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sébastien DAMAYE</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-225</link>
		<dc:creator>Sébastien DAMAYE</dc:creator>
		<pubDate>Sat, 20 Feb 2010 09:35:38 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-225</guid>
		<description>Just for information, would it be possible to know the tool (and parameters) you use for your captures? It would help me understanding why my tcpdump gives me different results. Many thanks in advance.</description>
		<content:encoded><![CDATA[<p>Just for information, would it be possible to know the tool (and parameters) you use for your captures? It would help me understanding why my tcpdump gives me different results. Many thanks in advance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sébastien DAMAYE</title>
		<link>http://forensicscontest.com/2010/02/17/puzzle-4-update/comment-page-1#comment-221</link>
		<dc:creator>Sébastien DAMAYE</dc:creator>
		<pubDate>Wed, 17 Feb 2010 17:18:04 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=443#comment-221</guid>
		<description>Maybe you should precise what you hear by &quot;FIRST port scan&quot;. Do you want us to precise THE scan type Mr. X uses for the VERY FIRST port he scans (may only include ONE port) OR the ports scans techniques used for the FIRST campaign of port scan (may include many techniques and many ports)? Thank you for your precisions.</description>
		<content:encoded><![CDATA[<p>Maybe you should precise what you hear by &#8220;FIRST port scan&#8221;. Do you want us to precise THE scan type Mr. X uses for the VERY FIRST port he scans (may only include ONE port) OR the ports scans techniques used for the FIRST campaign of port scan (may include many techniques and many ports)? Thank you for your precisions.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

