<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Puzzle Contest &#187; sherri</title>
	<atom:link href="http://forensicscontest.com/author/sherri/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicscontest.com</link>
	<description></description>
	<lastBuildDate>Wed, 04 Jan 2012 16:02:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Puzzle #10: $150 Cash Prize &amp; Deadline Extension</title>
		<link>http://forensicscontest.com/2011/11/23/puzzle-10-150-cash-prize-deadline-extension</link>
		<comments>http://forensicscontest.com/2011/11/23/puzzle-10-150-cash-prize-deadline-extension#comments</comments>
		<pubDate>Wed, 23 Nov 2011 06:26:53 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #10]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1019</guid>
		<description><![CDATA[Hi everybody! It&#8217;s been a whirlwind around here, and in all the rush of fall we never did get around to announcing the prize for Puzzle #10: The L33t Pill. So here it is: First place: $150 Cash (w00t!) Second place: A hollow spy half-dollar! Since we only just announced the prize, we&#8217;re moving the <a href='http://forensicscontest.com/2011/11/23/puzzle-10-150-cash-prize-deadline-extension'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Hi everybody! It&#8217;s been a whirlwind around here, and in all the rush of fall we never did get around to announcing the prize for <a href="https://forensicscontest.com/2011/10/11/puzzle-10-the-l33t-pill">Puzzle #10: The L33t Pill</a>. So here it is:</p>
<p>First place: <strong>$150 Cash</strong> (w00t!)<br />
Second place: A <a href="http://www.thinkgeek.com/images/products/zoom/b308_hollow_spy_coins.jpg">hollow spy half-dollar</a>!</p>
<p>Since we only just announced the prize, we&#8217;re moving the submission deadline to <strong>January 3, 2012</strong>. Bust out your forensics kung-fu over winter break and find the secret ingredient to the L33t Pill! May the best solution win. <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/11/23/puzzle-10-150-cash-prize-deadline-extension/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #10: The L33t Pill</title>
		<link>http://forensicscontest.com/2011/10/11/puzzle-10-the-l33t-pill</link>
		<comments>http://forensicscontest.com/2011/10/11/puzzle-10-the-l33t-pill#comments</comments>
		<pubDate>Tue, 11 Oct 2011 20:35:29 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #10]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=967</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p><!-- Want to take a crack at a DEFCON contest? Or did you play at DEFCON, and want to do BETTER? Now's your chance! -->Our popular DEFCON 2011 puzzle is now open for public competition! This six-round puzzle is our best challenge yet. Since the answers to the puzzle have been released, this challenge now has a twist: The winner will be the person who submits the MOST ELEGANT solution. </p>
<p><em>WARNING: This contest contains off-color humor which may not be appropriate for the classroom, children, rodents, etc.</em></p>
<p><em>
<p> The lead chemist of a high-profile pharmaceutical company was involved in a serious accident, leaving him in a coma days before the release of the company&#8217;s highly publicized &#8220;133t pill.&#8221; The chemist was the only person in possession of the list of ingredients required to produce the wonder drug, and it is not known if he will ever recover.    All chemical evidence of the drug has been destroyed, but the company believes that the missing ingredients may have been stored electronically.  <u>You have been hired as a forensic investigator, to recover the final ingredient of their 133t pill.</u> Can you find the missing ingredient? </em></p>
<p>Prizes To Be Announced! <strong>Deadline is 11/22/11 (11:59:59PM UTC-11)</strong> (In other words, if it&#8217;s still 11/22/11 anywhere in the world, you can submit your entry.) Please use the <a href="http://forensicscontest.com/submit-your-answers-for-puzzle-10">Official Submission Form</a> to submit your answers.</p>
<p>Remember, the MOST ELEGANT solution wins. The <a href="http://forensicscontest.com/2011/08/16/puzzle-9-answers">answers to this puzzle have already been published</a>; now your job is to demonstrate excellent ways to solve it. In the event of a tie, the entry submitted first will receive the prize. Coding is always encouraged. We love to see well-written, easy-to-use tools which automate even small sections of the evidence recovery. Graphical and command-line tools are all eligible. You are welcome to build upon the work of others, <strong>as long as their work has been released under an approved <a href="http://www.opensource.org/licenses" target="_blank">Open Source License</a></strong>. All responses should be submitted as <strong>PLAIN TEXT</strong>. Microsoft Word documents, PDFs, etc will NOT be reviewed. Feel free to collaborate with other people and discuss ideas back and forth. You can even submit as a team (there will be only one prize).</p>
<p>Here&#8217;s a link to the encrypted contest volume:<br />
<a href="http://forensicscontest.com/contest09/Defcon2011-Contest.tc">Defcon2011-Contest.tc</a></p>
<p><strong> SHA256 CHECKSUM:</strong><br />
6906e4a08bd498c6ff78928b1c8d292a9f89f2ecfac60094528f4497e2254474
</p>
<p>The Defcon2011-Contest.tc is an encrypted password-protected Truecrypt volume. Inside are six individual Truecrypt archives which each contain a single round of the contest. You will need to mount each encrypted volume using Truecrypt before you can access its contents. <a href="http://www.truecrypt.org/docs/?s=tutorial4">Here is a page</a> which shows you how to mount a Truecrypt volume.</p>
<p>The password to unlock Defcon2011-Contest.tc is: !#$h1d3&#038;&#038;s33k$#!<br />
The password to unlock round1 is: r0und1g0!!</p>
<p><em>At DEFCON, when a team found the answer to a round, they texted it to Headquarters (HQ). If their answer was correct, staff texted back the key to unlock the next round.</em><br />
<em><br />
<font color="yellow">SPOILER ALERT</font>: You can find the keys to each of the encrypted volumes <a href="http://forensicscontest.com/contest09/spoilers/decryption_keys.txt">here</a>.</p>
<p><font color="yellow">SUPER SPOILER ALERT</font>: For your convenience, we&#8217;ve also unlocked all the rounds for those of you who just want to play around with individual round puzzles without having to solve the whole thing in order. You can find the individual round puzzles here:</p>
<p><a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round1/defcon2011contest-round1.html">Round1</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round2/defcon2011contest-round2.html">Round2</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round3/defcon2011contest-round3.html">Round3</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round4/defcon2011contest-round4.html">Round4</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round5/defcon2011contest-round5.html">Round5</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round6/defcon2011contest-round6.html">Round6</a></p>
<p><font color="yellow">SUPER DUPER SPOILER ALERT</font>: Here are the <a href="http://forensicscontest.com/2011/08/16/puzzle-9-answers">ANSWERS TO THE PUZZLE</a>. Remember, your job is to come up with the MOST ELEGANT solution.<br />
</em></p>
<p>Exceptional solutions will be published on this site with full attribution. We are happy to link to your site if you intend to maintain an up-to-date version of your tool. Exceptional submissions may also be used as examples and tools in the Network Forensics course and book, with full attribution. By submitting your answer to this puzzle, you agree that your code submissions will be freely published under the <a href="http://www.gnu.org/licenses/gpl.html" target="_blank">GPL license</a>, and your solution&#8217;s text will be licensed according to the <a href="http://creativecommons.org/licenses/by/3.0/" target="_blank">Creative Commons v3 &#8220;Attribution&#8221; License</a>. All authors will receive full credit for their work.</p>
<p><strong>Deadline is 1/3/12 (11:59:59PM UTC-11)</strong> (In other words, if it&#8217;s still 1/3/12 anywhere in the world, you can submit your entry.) Please use the <a href="http://forensicscontest.com/submit-your-answers-for-puzzle-10">Official Submission Form</a> to submit your answers.</p>
<p> Good luck!!!</p>
<p><em>This puzzle was created by Scott Fretheim, Randi Price, Eric Fulton, Sherri Davidoff, and Jonathan Ham (Lake Missoula Group, LLC).</em></p>
<p><em>Copyright 2011, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/10/11/puzzle-10-the-l33t-pill/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #9: Ann&#8217;s Deception (DEFCON 2011)</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011</link>
		<comments>http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011#comments</comments>
		<pubDate>Tue, 16 Aug 2011 06:19:09 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #9 (DEFCON 2011)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=900</guid>
		<description><![CDATA[This year&#8217;s DEFCON contest was a huge success, with over 200 teams entering! The contest was split up into six rounds of increasing difficulty. The first team to complete all six rounds won the contest. Now that the contest is over, we&#8217;re placing the materials here for folks who would like to play around on <a href='http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><em>This year&#8217;s DEFCON contest was a huge success, with over 200 teams entering! The contest was split up into six rounds of increasing difficulty. The first team to complete all six rounds won the contest. Now that the contest is over, we&#8217;re placing the materials here for folks who would like to play around on their own.<br />
</em></p>
<p><em>WARNING: This contest contains off-color humor which may not be appropriate for the classroom, children, rodents, etc.</em></p>
<p> The lead chemist of a high-profile pharmaceutical company was involved in a serious accident, leaving him in a coma days before the release of the company&#8217;s highly publicized &#8220;133t pill.&#8221; The chemist was the only person in possession of the list of ingredients required to produce the wonder drug, and it is not known if he will ever recover.    All chemical evidence of the drug has been destroyed, but the company believes that the missing ingredients may have been stored electronically.  <u>You have been hired as a forensic investigator, to recover the final ingredient of their 133t pill.</u> Can you find the missing ingredient? </p>
<p>Here&#8217;s a link to the encrypted contest volume:<br />
<a href="http://forensicscontest.com/contest09/Defcon2011-Contest.tc">Defcon2011-Contest.tc</a></p>
<p><strong> SHA256 CHECKSUM:</strong><br />
6906e4a08bd498c6ff78928b1c8d292a9f89f2ecfac60094528f4497e2254474
</p>
<p>The Defcon2011-Contest.tc is an encrypted password-protected Truecrypt volume. Inside are six individual Truecrypt archives which each contain a single round of the contest. You will need to mount each encrypted volume using Truecrypt before you can access its contents. <a href="http://www.truecrypt.org/docs/?s=tutorial4">Here is a page</a> which shows you how to mount a Truecrypt volume.</p>
<p><em>At the start time, DEFCON attendees visited the contest booth to obtain the first decryption passwords, provided below:</p>
<p>The password to unlock Defcon2011-Contest.tc is: !#$h1d3&#038;&#038;s33k$#!<br />
The password to unlock round1 is: r0und1g0!!<br />
</em><br />
<em>When a team found the answer to a round, they texted it to Headquarters (HQ). If their answer was correct, staff texted back the key to unlock the next round.</em><br />
<em><br />
<font color="yellow">SPOILER ALERT</font>: You can find the keys to each of the encrypted volumes <a href="http://forensicscontest.com/contest09/spoilers/decryption_keys.txt">here</a>.</p>
<p><font color="yellow">SUPER SPOILER ALERT</font>: For your convenience, we&#8217;ve also unlocked all the rounds for those of you who just want to play around with individual round puzzles without having to solve the whole thing in order. You can find the individual round puzzles here:</p>
<p><a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round1/defcon2011contest-round1.html">Round1</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round2/defcon2011contest-round2.html">Round2</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round3/defcon2011contest-round3.html">Round3</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round4/defcon2011contest-round4.html">Round4</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round5/defcon2011contest-round5.html">Round5</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round6/defcon2011contest-round6.html">Round6</a><br />
</em></p>
<p><u>A few notes:</u></p>
<p>1. You will not get the correct answer simply by running &#8220;strings&#8221; on the packet captures. It is more complicated than that.<br />
<br />2. Please do not attempt to brute-force the answer by guessing. We reserve the right to cut you off from submitting answers if you abuse the privilege.<br />
<br />3. There are six contest rounds containing six evidence files.  You must analyze the evidence files in order to answer the question(s) which go along with each capture. </p>
<p>Have fun! <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><em><br />This puzzle was created by Scott Fretheim, Randi Price, Eric Fulton, Sherri Davidoff, and Jonathan Ham (Lake Missoula Group, LLC).</p>
<p>Copyright 2011, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Puzzle #9 Answers</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers</link>
		<comments>http://forensicscontest.com/2011/08/16/puzzle-9-answers#comments</comments>
		<pubDate>Tue, 16 Aug 2011 06:18:36 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #9 (DEFCON 2011)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=936</guid>
		<description><![CDATA[Here are the answers to Puzzle #9: Ann&#8217;s Deception (DEFCON 2011): Round 1 Decryption Key: r0und1g0!! In this capture we were looking for the name of the company. This is located inside an email. Answer: Factory-Made-Winning-Pharmaceuticals&#160; Round 2 Decryption Key: !n1c3?w0rk In this capture we were looking for the date of a speech given by <a href='http://forensicscontest.com/2011/08/16/puzzle-9-answers'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Here are the answers to Puzzle #9: Ann&#8217;s Deception (DEFCON 2011):</p>
<ol>
<li>Round 1 Decryption Key: r0und1g0!!<br />
In this capture we were looking for the name of the company. This is located inside an email.<br />
Answer: Factory-Made-Winning-Pharmaceuticals<br />&nbsp;
</li>
<li>Round 2 Decryption Key: !n1c3?w0rk<br />
In this capture we were looking for the date of a speech given by Bruce Schneier. To solve this puzzle you must carve out a packet capture which was sent as an email attachment. Inside that packet capture, you can find the data by looking through the web traffic to see the pages Ann viewed.<br />
Answer: October 6-7, 2011<br />&nbsp;</li>
<li>Round 3 Decryption Key:?g3tting!t0ugh<br />
In this capture we were looking for Romulus&#8217;s password. This can be found by carving out the VOIP conversation and listening to it.<br />
Answer: rom127#<br />&nbsp;</li>
<li>Round 4 Decryption Key: m4k1ng?pr0g<br />
In this packet capture we were looking for the name on the 16th line in a spread sheet. To find the answer, you need to carve out the SMB transfer of the 7zip file containing the credit card file.  In order to unlock the 7zip file you will need to use the password YOU found in Round 3.<br />
Answer: Jason Wilson<br />&nbsp;</li>
<li>Round 5 Decryption Key: 0v3r#h4lf?w4y<br />
In this packet capture, you need to carve out the SMB file transfer of the ingredients list. To unlock the 7zip file containing the ingredients list, you will need to use the password you found in in Round 4.<br />
Answer:8.4 oz- Red Bull;  Tim<br />&nbsp;</li>
<li>Round 6 Decryption Key: ch33rs!0n3$m0r3<br />
Round 6 requires you to find the final ingredient of the 133t pill.  To unlock the volume, you must use the cipher along with the previous answers from Rounds 1-5.  Begin by solving the cipher, and then use the cipher as the password to unlock the Truecrypt volume.<br />
Cipher Solution: 00gmu1rt#?<br />
Answer: 2oz Vodka</li>
<p><em>Copyright 2011, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/08/16/puzzle-9-answers/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Gearing Up for DEFCON 19!</title>
		<link>http://forensicscontest.com/2011/07/31/gearing-up-for-defcon-19</link>
		<comments>http://forensicscontest.com/2011/07/31/gearing-up-for-defcon-19#comments</comments>
		<pubDate>Sun, 31 Jul 2011 22:14:11 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #9 (DEFCON 2011)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=865</guid>
		<description><![CDATA[We are totally psyched for DEFCON 19! The Network Forensics Puzzle Contest (NFPC) will be running in the contest area. Watch our DEFCON forum for updates this week. Prizes include a Verizon 3g Network Extender and $150 ThinkGeek gift certificate (many thanks to ThinkGeek for sponsoring that prize). To whet your appetite even more, check <a href='http://forensicscontest.com/2011/07/31/gearing-up-for-defcon-19'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>We are totally psyched for DEFCON 19! The Network Forensics Puzzle Contest (NFPC) will be running in the contest area. Watch our <a href="https://forum.defcon.org/forumdisplay.php?f=586">DEFCON forum</a> for updates this week. Prizes include a <font color="yellow"><a href="http://www.pcmag.com/article2/0,2817,2371097,00.asp">Verizon 3g Network Extender</a></font> and <font color="yellow"><a href="http://thinkgeek.com">$150 ThinkGeek gift certificate</a></font> (many thanks to ThinkGeek for sponsoring that prize).</p>
<p>To whet your appetite even more, check out the hot new graphic on the DEFCON 19 NFPC CD, designed by Mr. Scott Fretheim:</p>
<table cellspacing="10">
<tr>
<td><img src="http://forensicscontest.com/wp-content/uploads/DEFCON2011-DISC-small.jpg">
</td>
<td valign="top">Players can pick up their CDs at the contest booth starting Thursday @ 10:00 AM. The contest will officially start on Friday. (Of course, we&#8217;ll post the contest materials online afterwards, too, so everyone can check out the latest challenge, just for fun.</p>
<p>Cheers!
</td>
</table>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/07/31/gearing-up-for-defcon-19/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Puzzle #7 Answers</title>
		<link>http://forensicscontest.com/2011/07/31/puzzle-7-answers</link>
		<comments>http://forensicscontest.com/2011/07/31/puzzle-7-answers#comments</comments>
		<pubDate>Sun, 31 Jul 2011 21:50:14 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #7 (DEFCON)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=840</guid>
		<description><![CDATA[Here is the solution to Puzzle #7: Ann&#8217;s Dark Tangent (DEFCON 2010). There are many ways to arrive at the solution. Here is our method; there are other tools you can use to reach the same answer. You received a CD containing, among other things, a packet capture: evidence-defcon2010.pcap Check the MD5 sum: $ md5sum <a href='http://forensicscontest.com/2011/07/31/puzzle-7-answers'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Here is the solution to <a href="http://forensicscontest.com/2011/07/31/puzzle-7-anns-dark-tangent-defcon-2010">Puzzle #7: Ann&#8217;s Dark Tangent (DEFCON 2010)</a>. There are many ways to arrive at the solution. Here is our method; there are other tools you can use to reach the same answer.</p>
<p>You received a CD containing, among other things, a packet capture: <a href="http://forensicscontest.com/contest07/evidence-defcon2010.pcap">evidence-defcon2010.pcap</a></p>
<p>Check the MD5 sum:</p>
<pre>
$ md5sum evidence-defcon2010.pcap
7c416421a626600f86e3702df0cac8ef evidence-defcon2010.pcap
</pre>
<p>If you examine the packet capture, you will see that it contains WEP-encrypted wireless traffic.</p>
<p>Crack the WEP key. You can do this using aircrack-ng in less than one second:</p>
<pre>
$ aircrack-ng evidence-defcon2010.pcap
Opening evidence-defcon2010.pcap
Read 426642 packets.
# BSSID    ESSID    Encryption
1 00:1C:10:B3:CC:F0 w00t    WEP (98923 IVs)
Choosing first network as target.
Opening evidence-defcon2010.pcap
</pre>
<p>Once you have the WEP key, use it to decrypt the traffic:</p>
<pre>
$ airdecap-ng -w 4A:7D:B5:08:CD evidence-defcon2010.pcap
Total number of packets read    426642
Total number of WEP data packets 187650
Total number of WPA data packets 0
Number of plaintext data packets 0
Number of decrypted WEP packets 187650
Number of corrupted WEP packets 0
Number of decrypted WPA packets 0
</pre>
<p>If you run strings on the packet capture (or view it in Wireshark), you will see IMAP and SMTP traffic, including an email with an attachment. This attachment is the key to the entire puzzle.</p>
<pre>
Dark Tangent,
I know you've been watching me. You should be able to figure out the =
location of our rendezvous point from my traffic. Contact me first with =
the name of the city where we will meet, and you win <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  I'll send you =
more details after that.=20
Ann
ps. See the attachment for a clue.
</pre>
<p>Carve out the email attachment. You can do this manually, or use the <a href="http://forensiccontest.com/contest02/Finalists/Franck_Guenichot/smtpdump">smtpdump</a> tool by <a href="http://forensicscontest.com/contest02/Finalists/Franck_Guenichot/">Franck Guénichot</a> from Contest #2.</p>
<p>The email attachment is a GIF image, shown below:</p>
<p><img src="http://forensicscontest.com/wp-content/uploads/IMG_0002.GIF"> </p>
<p>There were five lines in the image, which read (from top to bottom):</p>
<pre>
App Store - App Name
Podcast Title
YouTube Video Title
Google Earth City Name
AIM Buddy Name
</pre>
<p>If you go through the packet capture, you will find that Ann used her iPad to:</p>
<ul>
<li>Download the iPad app called “Solitaire”</li>
<li>Download and watch an Onion podcast called “Onion Radio News for Kids”</li>
<li>View a YouTube video called “Cry for Help – Rick Astley”</li>
<li>Search on Google Earth for “Hacker Valley, West Virginia”</li>
<li>IM her buddy, “inter0pt1c”</li>
</ul>
<p>Line all the answers up, as shown in the GIF image, and read down the first column:</p>
<ul>
<li><strong>S</strong>olitaire</li>
<li><strong>O</strong>nion Radio News for Kids</li>
<li><strong>C</strong>ry for Help</li>
<li><strong>H</strong>acker Valley</li>
<li><strong>i</strong>nter0pt1c</li>
</ul>
<p>The answer is &#8220;SOCHI&#8221;, a resort town in Russia where the winter Olympics will be held.</p>
<p>Thanks to everyone who played!</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/07/31/puzzle-7-answers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #7 Winners</title>
		<link>http://forensicscontest.com/2011/07/31/puzzle-7-winners</link>
		<comments>http://forensicscontest.com/2011/07/31/puzzle-7-winners#comments</comments>
		<pubDate>Sun, 31 Jul 2011 21:26:24 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #7 (DEFCON)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=831</guid>
		<description><![CDATA[Over 221 teams registered to play Puzzle #7: Ann&#8217;s Aurora at DEFCON 18 (2010)! Each team was given a CD which contained the evidence, and teams were asked to text the answer to the phone at NFPC Headquarters. The first team to text the correct answer won the contest. The Winner of Puzzle #7 (and <a href='http://forensicscontest.com/2011/07/31/puzzle-7-winners'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>Over 221 teams registered to play <a href="http://forensicscontest.com/2011/07/31/puzzle-7-anns-dark-tangent-defcon-2010">Puzzle #7: Ann&#8217;s Aurora</a> at DEFCON 18 (2010)! Each team was given a CD which contained the evidence, and teams were asked to text the answer to the phone at NFPC Headquarters. The first team to text the correct answer won the contest.</p>
<p>The Winner of Puzzle #7 (and the shiny new iPad) was <em>(drumroll&#8230;)</em></p>
<p><strong><font size="+1">Team Bam Bam!</font></strong></p>
<p>These guys solved the puzzle after about 5 hours. We also have to give mad props to team Preset Kill Limit, who texted the correct answer just one minute after team Bam Bam. Wow, that was close!</p>
<p>Great job to everyone! </p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/07/31/puzzle-7-winners/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #7: Ann&#8217;s Dark Tangent (DEFCON 2010)</title>
		<link>http://forensicscontest.com/2011/07/31/puzzle-7-anns-dark-tangent-defcon-2010</link>
		<comments>http://forensicscontest.com/2011/07/31/puzzle-7-anns-dark-tangent-defcon-2010#comments</comments>
		<pubDate>Sun, 31 Jul 2011 21:14:56 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #7 (DEFCON)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=823</guid>
		<description><![CDATA[At long last! Here is a copy of Puzzle #7, &#8220;Ann&#8217;s Dark Tangent,&#8221; which was run at Defcon 18 (2010). This contest was unusual in that the answer was a single word. The contest was open to DEFCON 18 attendees who were at the conference. Although the contest has long since closed, you might enjoy <a href='http://forensicscontest.com/2011/07/31/puzzle-7-anns-dark-tangent-defcon-2010'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><em>At long last! Here is a copy of Puzzle #7, &#8220;Ann&#8217;s Dark Tangent,&#8221; which was run at Defcon 18 (2010). This contest was unusual in that the answer was a single word. The contest was open to DEFCON 18 attendees who were at the conference. Although the contest has long since closed, you might enjoy playing around with the packet capture, which contains wireless iPad traffic.</em></p>
<p>Ann has arranged a rendezvous with Dark Tangent. You are the forensic investigator. Can you figure out their destination? </p>
<p>Here&#8217;s a copy of their network traffic: </p>
<p><a href="http://forensicscontest.com/contest07/evidence-defcon2010.pcap">evidence-defcon2010.pcap</a><br />
MD5sum: 7c416421a626600f86e3702df0cac8ef </p>
<p>The first team to submit the correct answer wins a brand new Apple iPad.</p>
<p>A few notes:<br />
1. You will not get the correct answer simply by running &#8220;strings&#8221; on the packet capture. It is more complicated than that.<br />
2. Please do not attempt to brute-force the answer by guessing. We reserve the right to cut you off from submitting answers if you abuse the privilege. </p>
<p>Have fun! <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><em>Puzzle #7 was written by Sherri Davidoff, Eric Fulton and Jonathan Ham.</em></p>
<p><em>Copyright 2010, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/07/31/puzzle-7-anns-dark-tangent-defcon-2010/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Defcon 2010</title>
		<link>http://forensicscontest.com/2010/07/22/defcon-2010</link>
		<comments>http://forensicscontest.com/2010/07/22/defcon-2010#comments</comments>
		<pubDate>Fri, 23 Jul 2010 00:42:13 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Puzzle #7 (DEFCON)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=720</guid>
		<description><![CDATA[For all those attending DEFCON 2010, we&#8217;ll be hosting a puzzle contest starting Friday afternoon in the contest area. It&#8217;s a race against time; the first person to complete the puzzle wins a brand-new iPad. We&#8217;ll be posting the packet capture here after the contest for those of you who like the intellectual challenge. Contest <a href='http://forensicscontest.com/2010/07/22/defcon-2010'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p>For all those attending DEFCON 2010, we&#8217;ll be hosting a puzzle contest starting Friday afternoon in the contest area. It&#8217;s a race against time; the first person to complete the puzzle wins a brand-new iPad. We&#8217;ll be posting the packet capture here after the contest for those of you who like the intellectual challenge. Contest description below&#8230; See you there!</p>
<p><em>Ann Dercover is on the run, and you&#8217;re hot on her trail as she travels around the globe hacking companies, stealing intellectual property, launching 0-day attacks and setting up sneaky backdoors. *You are the forensic investigator.* You&#8217;ve got a packet capture of Ann&#8217;s network traffic.  Can you analyze Ann&#8217;s malicious traffic and solve the crime by Sunday?  Prize: Win a brand-spanking new Apple iPad!<br />
</em></p>
<p>cheers!<br />
Eric</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2010/07/22/defcon-2010/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Puzzle #6 Winners</title>
		<link>http://forensicscontest.com/2010/07/09/puzzle-6-winners</link>
		<comments>http://forensicscontest.com/2010/07/09/puzzle-6-winners#comments</comments>
		<pubDate>Fri, 09 Jul 2010 06:57:32 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #6]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=663</guid>
		<description><![CDATA[Ann&#8217;s Aurora was one of our hardest contests yet. To get all the answers right, you had to carve out two Windows executable files, dissect Vick Timmes&#8217; HTTP traffic, analyze malware, build a timeline and pinpoint connection open and close times to within a tenth of a second. Thanks to everyone who submitted an entry <a href='http://forensicscontest.com/2010/07/09/puzzle-6-winners'>[...]</a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://forensicscontest.com/2010/05/21/puzzle-6-anns-aurora">Ann&#8217;s Aurora</a> was one of our hardest contests yet. To get all the <a href="http://forensicscontest.com/2010/07/08/puzzle-6-answers">answers</a> right, you had to carve out two Windows executable files, dissect Vick Timmes&#8217; HTTP traffic, analyze malware, build a timeline and pinpoint connection open and close times to within a tenth of a second. Thanks to everyone who submitted an entry for <a href="http://forensicscontest.com/2010/05/21/puzzle-6-anns-aurora">Puzzle #6, &#8220;Ann&#8217;s Aurora,&#8221;</a> and a special congratulations to the relatively small number of folks who submitted correct answers. </p>
<p>The winner of &#8220;Ann&#8217;s Aurora&#8221; is (*drumroll*)&#8230;. <a href="http://forensicscontest.com/contest06/Finalists/Wesley_McGrew/">Wesley McGrew</a>, for his fantastic new forensics tool, <a href="http://forensicscontest.com/contest06/Finalists/Wesley_McGrew/pcapline.py">pcapline</a>.  Pcapline automatically parses a packet capture and generates an HTML report. Through your web browser, you can view a summary of all flows and drill down into each one. Pcapline automatically carves out all the files&#8211; not just the tiny GIFs embedded inside a single packet, but Windows executable files broken up throughout the packet capture. Wesley also included MD5sums in the report output.</p>
<p>Best of all, it&#8217;s simple to use&#8211; you just type &#8220;pcapline.py&#8221; and the evidence file name, and pcapline does the rest. Wesley has put a copy of the pcapline report output here:</p>
<p><a href="http://mcgrewsecurity.com/codedump/evidence06.pcap_output/">http://mcgrewsecurity.com/codedump/evidence06.pcap_output/</a></p>
<p>Erik Hjelmvik, our Silver medalist, released a new version of <a href="http://networkminer.sourceforge.net/">Network Miner</a> (.92) for Contest #6.  We know a lot of you already know and love Network Miner, because in previous contests  about half of the entries relied on Erik&#8217;s tool! For this contest, Erik noticed that Network Miner was not properly detecting the HTML transfers at the beginning of the pcap file, because the TCP handshake was missing. He added functionality so that Network Miner more intelligently figures out which host is the server, and which is the client, when the TCP handshake is missing. Thanks, Erik, for a shiny new release of your fantastic tool.</p>
<p><a href="http://forensicscontest.com/contest06/Finalists/Leendert_Pieter_van_Drimmelen/">Leendert Pieter van Drimmelen</a> built three utilities for this contest: stream_ts.py, which automatically displays TCP connection established/closed times; analyse_syn_packets.py, which calculates how often an IP or TCP field changes (it also accepts tshark filters); and pextract.c, which extracts PE files from packet captures or incoming traffic. Pextract also accepts BPF filters and tries to find executables that are XOR obfuscated. These are three small, sharp utilities which are good to have in your toolkit.</p>
<p><a href="http://forensicscontest.com/contest06/Finalists/Eric_Kollmann/">Eric Kollmann</a> wrote three handy tools: mzcarver.exe (PE carving utility), contest6.pl (provides info about conversations), and contest6.exe (produces info about individual packets. You can limit by TCP flag and use BPFs). Nice work, Eric!</p>
<p><a href="http://forensicscontest.com/contest06/Finalists/Jeff_Wichman/">Jeff Wichman</a> and <a href="http://forensicscontest.com/contest06/Finalists/Ruben_Recabarren/">Ruben Recabarren</a> both created fantastic writeups, which you can read to get two detailed (and very different) methods for solving the contest.  <a href="http://forensicscontest.com/contest06/Finalists/Iulian_Anton/">Iulian Anton</a> also had a thorough narrative and created a couple of Perl utilities to assist with solving the contest.  <a href="http://forensicscontest.com/contest06/Finalists/Candice_Quates/">Candice Quates</a> went &#8220;down the rabbit hole of javascript and exploit analysis,&#8221; and created  trimexe.c, which extracts PE files from exported streams.</p>
<p>Thanks to the SANS Institute and the generosity of their vendor sponsors, the winners and finalists get to choose from the following list of prizes (winner picks first):</p>
<ul>
<li>Lenovo Ideapad Netbooks (2 Netbooks &#8211; 1 netbook per winner )<br />
Apple iPad &#8211; Sponsored by NetWitness Corporation</li>
<li>Flip Video Recorder &#8211; Sponsored by MANDIANT Inc.</li>
<li>F-Response TACTICAL (1 licensed copy) &#8211; Sponsored by F-Response</li>
<li>Forensic Toolkit 3 (1 licensed copy) &#8211; Sponsored by AccessData Corp.</li>
<li>Digital Forensics Magazine Subscriptions: Free print subscription for 12 months for the winner, and 2 digital online subscriptions for Finalists. The winner will also receive the backlist issues (i.e. 1-3). &#8211; Sponsored by Digital Forensics Magazine</li>
<li>2011 Digital Forensics/IR Summit Passes (3 passes &#8211; 1 pass per top three winners)</li>
</ul>
<p>Many thanks to everyone who made this contest possible, including Rob Lee, Jeremy Scott, Jeff Murri, Brian Corcoran, Ryan Corvetti, Dennis Kirby, and the wonderful SANS A/V crew.</p>
<p>Thanks most of all to everyone out there who participated.  See you next time! <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><hr /></p>
<table style="margin: 15px;" width="95%" align="center">
<tbody>
<tr>
<td><a name="winners"></a></p>
<h4>WINNERS:</h4>
<table cellspacing="20" cellpadding="20">
<tbody>
<tr>
<td valign="top"><a href="http://forensicscontest.com/contest06/Finalists/Wesley_McGrew/">Wesley McGrew</a></td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td><a name="finalists"></a></p>
<h4>Finalists:</h4>
<table cellspacing="20" cellpadding="20">
<tbody>
<tr>
<td valign="top">
<a href="http://forensicscontest.com/contest06/Finalists/Erik_Hjelmvik/">Erik Hjelmvik</a><br />
<a href="http://forensicscontest.com/contest06/Finalists/Leendert_Pieter_van_Drimmelen/">Leendert Pieter van Drimmelen</a><br />
<a href="http://forensicscontest.com/contest06/Finalists/Eric_Kollmann/">Eric Kollmann</a><br />
<a href="http://forensicscontest.com/contest06/Finalists/Jeff_Wichman/">Jeff Wichman</a><br />
<a href="http://forensicscontest.com/contest06/Finalists/Ruben_Recabarren/">Ruben Recabarren</a><br />
<a href="http://forensicscontest.com/contest06/Finalists/Iulian_Anton/">Iulian Anton</a><br />
<a href="http://forensicscontest.com/contest06/Finalists/Candice_Quates/">Candice Quates</a>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td><a name="semifinalists"></a></p>
<h4>Semifinalists:</h4>
<table cellspacing="20" cellpadding="20">
<tbody>
<tr>
<td valign="top">Francesco Acchiappati<br />
Mark Hillick<br />
Richard Shawn O&#8217;Connell<br />
Ashish, Garima, Vikrant<br />
Jon Larimer</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td><a name="correct"></a></p>
<h4>Correct Answers:</h4>
<table cellspacing="20" cellpadding="20">
<tbody>
<tr>
<td valign="top">
Andy Patrick<br />
Brian Sommers<br />
Candice Quates<br />
Carlos Pérez López<br />
David Rodriguez<br />
Eric Kollmann<br />
Erik Hjelmvik<br />
Francesco Acchiappati<br />
Hsiang-Jen Shih<br />
Iulian Anton<br />
Jeremy Scott<br />
Jon Larimer<br />
Kazunori Kojima<br />
Leendert Pieter van Drimmelen<br />
Mark Hillick<br />
Masashi Fujiwara<br />
Peter Chong<br />
Rakesh Mukundan<br />
Richard Shawn O&#8217;Connell<br />
Ruben Recabarren<br />
Seth Leone &#038; Ryan Sommers<br />
Takuro Uetori<br />
Wesley McGrew<br />
Winter Faulk<br />
Yogesh Khatri<br />
Zoher Anis
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2010/07/09/puzzle-6-winners/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

