<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Puzzle Contest &#187; Puzzle #2</title>
	<atom:link href="http://forensicscontest.com/category/contest/puzzle-2/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicscontest.com</link>
	<description>&#34;No Hard Drive? No Problem!&#34;</description>
	<lastBuildDate>Fri, 23 Jul 2010 00:42:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Puzzle #2 Winners and Solutions</title>
		<link>http://forensicscontest.com/2009/12/18/puzzle-2-winners-and-solutions</link>
		<comments>http://forensicscontest.com/2009/12/18/puzzle-2-winners-and-solutions#comments</comments>
		<pubDate>Fri, 18 Dec 2009 05:25:56 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #2]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=176</guid>
		<description><![CDATA[We were blown away by the quality of your submissions for Puzzle #2. There were many excellent, automated, well-documented solutions, including production-quality tools. Congratulations to everyone who submitted the correct answers, and a special thanks to all of you who pushed forward network forensics technology, either by writing your own tools or by improving those [...]]]></description>
			<content:encoded><![CDATA[<p>We were blown away by the quality of your submissions for Puzzle #2. There were many excellent, automated, well-documented solutions, including production-quality tools. Congratulations to <a href="#correct">everyone who submitted the correct answers</a>, and a special thanks to all of you who pushed forward network forensics technology, either by writing your own tools or by improving those which already exist. </p>
<p>You sent in nearly 150 unique entries.  After testing each entry for usability and functionality, we narrowed it down to <a href="#correct">79 correct solutions</a>, <a href="#semifinalists">15 Semifinalists</a>, and <a href="#finalists">8 Finalists</a>. After much debate we declared TWO (yes, two) <a href="#winners">winners</a>, with different and complementary approaches:</p>
<p><a href="http://forensicscontest.com/contest02/Finalists/Franck_Guenichot/">Franck Guénichot</a> and <a href="http://forensicscontest.com/contest02/Finalists/Jeremy_Rossi/">Jeremy Rossi</a></p>
<p>Both Franck and Jeremy will receive a Lenovo Ideapad S10-2, similar to the netbooks that will be distributed in <a href="http://www.sans.org/security-training/network-forensics-1227-mid">SANS Sec558 classes</a>.</p>
<p><strong><u>Franck wrote two tools:</u></strong><br />
- <a href="http://forensicscontest.com/contest02/Finalists/Franck_Guenichot/smtpdump">smtpdump</a> (home made ruby script to extract some smtp info from a pcap file)<br />
- <a href="http://forensicscontest.com/contest02/Finalists/Franck_Guenichot/docxtract">docxtract</a> (home made ruby script to extract files from a docx package)</p>
<p>Franck&#8217;s smtpdump is an easy-to-use tool for analyzing SMTP traffic in pcap files. It can export emails and attachments, automatically generate MD5sums, and display SMTP-related information. You can narrow your search down to a specific flow, or extract information from the entire packet capture. The docxtract script extracts files from a Microsoft .docx file, and can take the MD5sum of each extracted item. We especially appreciated that both of Franck&#8217;s tools were very well documented and user-friendly. </p>
<p><strong><u>Jeremy wrote a fantastically simple tool</u></strong> called <a href="http://forensicscontest.com/contest02/Finalists/Jeremy_Rossi/findsmtpinfo.py">findsmtpinfo.py</a>. As he describes, the &#8220;script creates a report of the SMTP information, stores any emails in msg format, stores any attachments from the emails, decompresses them if they are a compressed format (zip, docx), checks MD5 hashes of all files including the msg files (and generates MD5 hash of output report).&#8221; The result? An easy-to-follow report with complete paths to the extracted files and corresponding MD5sums. The report itself is detailed enough to be used as an attachment to a real-world forensics report.</p>
<p>Franck and Jeremy&#8217;s tools, smtpdump and findsmtpinfo.py, complement each other well. They can be used individually or together as part of a real-world investigation. Smtpdump facilitates inspection and makes it easy to drill down on the SMTP traffic of interest. Once you have identified specific flows of interest, you can use findsmtpinfo.py to automatically generate a report and quickly extract all of the SMTP-related information, emails, attachments, etc. </p>
<p>Don&#8217;t miss the excellent tools and narratives by the <a href="#finalists">eight Finalists.</a> We&#8217;d like to specifically call attention to Erik Hjelmvik&#8217;s latest version of <a href="http://networkminer.sourceforge.net/">Network Miner</a>, which he submitted as his entry. Erik extended Network Miner to include an SMTP parser and &#8220;Messages&#8221; tab. His GUI tool is both effective and very easy to use.</p>
<p><a href="http://forensicscontest.com/contest02/Finalists/Amar_Yousif/">Amar Yousif</a> (smtpcat), <a href="http://forensicscontest.com/contest02/Finalists/Jeff_Jarmoc/">Jeff Jarmoc</a> (smtpcat.rb), <a href="http://forensicscontest.com/contest02/Finalists/Kristinn_Gudjonsson/">Kristinn Gudjonsson</a> (smtp_anex), <a href="http://forensicscontest.com/contest02/Finalists/Richard_Springs/">Richard Springs</a> (carnivorous.rb) and <a href="http://forensicscontest.com/contest02/Finalists/Serge_Gorbunov/">Serge Gorbunov</a> (smtpParser.py) each wrote their own excellent SMTP analysis and data extraction tools. <a href="http://forensicscontest.com/contest02/Finalists/Tom_Samstag/">Tom Samstag</a> submitted patches for dsniff and mailsnarf which substantially improved their functionality,  fixing dsniff&#8217;s SMTP authentication decoding and allowing mailsnarf to examine traffic on port 587. <a href="http://forensicscontest.com/contest02/Finalists/Alan_Tu/">Alan Tu</a> wrote a great walk-through using tshark&#8217;s new tcp.stream field to identify TCP streams, and created a script based on this to output data from the application layer of selected streams. </p>
<p>As before, what we considered &#8220;elegant&#8221; was the construction of some automated process for solving the puzzle which was easy to use, easy to understand, portable, and would easily be able to scale to much larger and more difficult problems.</p>
<p>We received a number of solutions which were almost, but not quite, correct. For example, several people submitted MD5sums and left out one or two digits, or submitted email addresses with a &#8220;1&#8243; instead of an &#8220;l&#8221;. In forensics, exactness matters, and unfortunately being off-by-one is still not correct. If your name is not on the list of correct answers, please check your submission carefully. We appreciated *every* submission, and encourage you to try again next time!</p>
<p>Fifteen people were named Semifinalists because they contributed to an automated process  that would significantly facilitate future investigations. Eight Finalists took this to a level beyond and created polished, novel solutions involving considerable amounts of scripting. Please take a look at <a href="http://forensicscontest.com/contest02/Finalists/">each of their solutions</a> as WE learned something from every one.</p>
<p>Thank you all for playing! Puzzle Contest #3 will be coming out soon&#8230; <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><hr /></p>
<table style="margin: 15px;"  width="95%" align="center">
<tbody>
<tr>
<td>
<A NAME="winners"></a></p>
<h4>WINNERS:</h4>
<table cellpadding="20" cellspacing="20">
<tr>
<td  valign=top>
<a href="http://forensicscontest.com/contest02/Finalists/Franck_Guenichot/">Franck Guénichot</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Jeremy_Rossi/">Jeremy Rossi</a><br />
<em><a href="http://www.sans.org/security-training/network-forensics-1227-mid">(Win a Lenovo Ideapad S-10, like the ones distributed to SANS Sec558 students)</a></em></td>
</td>
</tr>
</table>
</tr>
<tr>
<td>
<A NAME="finalists"></a></p>
<h4>Finalists:</h4>
<table cellpadding="20" cellspacing="20">
<tr>
<td  valign=top>
<a href="http://forensicscontest.com/contest02/Finalists/Alan_Tu/">Alan Tu</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Amar_Yousif/">Amar Yousif</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Erik_Hjelmvik/">Erik Hjelmvik</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Jeff_Jarmoc/">Jeff Jarmoc</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Kristinn_Gudjonsson/">Kristinn Gudjonsson</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Richard_Springs/">Richard Springs</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Serge_Gorbunov/">Serge Gorbunov</a><br />
<a href="http://forensicscontest.com/contest02/Finalists/Tom_Samstag/">Tom Samstag</a>
</td>
</tr>
</table>
</td>
</tr>
<tr>
<td>
<A NAME="semifinalists"></a></p>
<h4>Semifinalists:</h4>
<table cellpadding="20" cellspacing="20">
<tr>
<td  valign=top>
Adam James<br />
Ahmed Adel Mohamed<br />
Alexandre Teixeira<br />
Andrew Neitsch<br />
Arvind Doraiswamy
</td>
<td  valign=top>
Elizabeth Greene<br />
Eric Davis<br />
Eric Kollmann<br />
Jeff Bryner<br />
Jim Clausing
</td>
<td  valign=top>
John Scillieri<br />
Lou Arminio<br />
Preston Wiley<br />
Sebastien Damaye<br />
Troy Schlueter
</td>
</tr>
</table>
</td>
</tr>
<tr>
<td>
<A NAME="correct"></a></p>
<h4>Correct Answers:</h4>
<table cellpadding="20" cellspacing="20">
<tr>
<td  valign=top>
Adam James<br />
Ahmed Adel Mohamed<br />
Alan Tu<br />
Alessandro Frossi<br />
Alexandre Teixeira<br />
Ali Mersin<br />
Andrew Laman<br />
Andrew Neitsch<br />
Andrew Rabie<br />
Andrew Scharlott<br />
Arvind Doraiswamy<br />
Carrie Schaper<br />
C.D.A.<br />
Chet Kress<br />
Chris Anderson<br />
Chris Steenkamp<br />
Christiaan Beek<br />
Daniel Dickerman<br />
David Clements<br />
David Gilmore<br />
Derek Lidbom<br />
Elizabeth Greene<br />
Eric Davis<br />
Eric Kollmann<br />
Erik Hjelmvik<br />
Franck Guénichot
</td>
<td  valign=top>
Halil Ozgur BAKTIR<br />
Jairam Ramesh<br />
Jason Powell<br />
Jason Setzer<br />
Jason Stanley<br />
Jay Radcliffe<br />
Jeff Bryner<br />
Jeff Jarmoc<br />
Jeff Lafferty<br />
Jeremy Rossi<br />
Jim Clausing<br />
Jim Goltz<br />
John Scillieri<br />
Jon Cook<br />
Juha Lampinen<br />
Kaio Rafael de Souza Barbosa<br />
Kevin Schultz<br />
Kristinn Gudjonsson<br />
Lance Mueller<br />
Larry McDonald<br />
Lorenzo De Toro III<br />
Lou Arminio<br />
Masashi Fujiwara<br />
Michael Spohn<br />
Michael Thomas<br />
Mike Pilkington<br />
Nick McKerrall
</td>
<td  valign=top>
Omair Hamid<br />
Osama Elnaggar<br />
Peter Chong<br />
Peter Nguyen<br />
Preston Wiley<br />
Richard Springs<br />
Rob VandenBrink<br />
Rodney Driggers<br />
Russ Klanke<br />
Ryan Linn<br />
Sébastien Damaye<br />
Serge Gorbunov<br />
Seung-hoon Kang<br />
Shane Hartman<br />
Shane Kennedy<br />
Shane Vonarx<br />
steponequit<br />
Steward DeWitt<br />
Tareq Saade<br />
Thom Carlin<br />
Thor Ollila<br />
Timothy Lawton<br />
Tom Samstag<br />
Troy Schlueter<br />
Valter Santos<br />
wiretapp
</td>
</tr>
</table>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2009/12/18/puzzle-2-winners-and-solutions/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tune into PaulDotCom Tonight for Puzzle #2 Winners</title>
		<link>http://forensicscontest.com/2009/12/17/tune-into-pauldotcom-tonight-for-puzzle-2-winners</link>
		<comments>http://forensicscontest.com/2009/12/17/tune-into-pauldotcom-tonight-for-puzzle-2-winners#comments</comments>
		<pubDate>Thu, 17 Dec 2009 16:47:14 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #2]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=199</guid>
		<description><![CDATA[The winners for Puzzle #2 will be announced tonight on PaulDotCom. The show starts at 7:30PM EST. We&#8217;ll have all the results posted here shortly thereafter. Talk to you soon!]]></description>
			<content:encoded><![CDATA[<p>The winners for Puzzle #2 will be announced <a href="http://pauldotcom.com/2009/12/pauldotcom-episode-180---recor.html">tonight on PaulDotCom</a>. The show starts at 7:30PM EST. We&#8217;ll have all the results posted here shortly thereafter. Talk to you soon!</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2009/12/17/tune-into-pauldotcom-tonight-for-puzzle-2-winners/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #2 Answers</title>
		<link>http://forensicscontest.com/2009/11/24/puzzle-2-answers</link>
		<comments>http://forensicscontest.com/2009/11/24/puzzle-2-answers#comments</comments>
		<pubDate>Tue, 24 Nov 2009 05:34:07 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #2]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=143</guid>
		<description><![CDATA[Thank you all for your contest submissions! We received well over a hundred and we are busily reviewing them. In the meantime, here are the answers: 1. What is Ann’s email address? Answer 1: sneakyg33k@aol.com 2. What is Ann’s email password? Answer 2: 558r00lz 3. What is Ann’s secret lover’s email address? Answer 3: mistersecretx@aol.com [...]]]></description>
			<content:encoded><![CDATA[<p>Thank you all for your contest submissions! We received well over a hundred and we are busily reviewing them. In the meantime, here are the answers: <img src="http://forensicscontest.com/wp-content/uploads/2009/11/image1-300x174.png" alt="image1" title="image1" width="300" height="174" class="alignright size-medium wp-image-145" /></p>
<p>1. What is Ann’s email address?<br />
Answer 1: sneakyg33k@aol.com</p>
<p>2. What is Ann’s email password?<br />
Answer 2: 558r00lz</p>
<p>3. What is Ann’s secret lover’s email address?<br />
Answer 3: mistersecretx@aol.com</p>
<p>4. What two items did Ann tell her secret lover to bring?<br />
Answer 4: A fake passport and a bathing suit</p>
<p>5. What is the NAME of the attachment Ann sent to her secret lover?<br />
Answer 5: secretrendezvous.docx</p>
<p>6. What is the MD5sum of the attachment Ann sent to her secret lover?<br />
Answer 6: 9e423e11db88f01bbff81172839e1923</p>
<p>7. In what CITY and COUNTRY is their rendez-vous point?<br />
Answer 7: Playa del Carmen, Mexico</p>
<p>8. What is the MD5sum of the image embedded in the document?<br />
Answer 8: aadeace50997b1ba24b09ac2ef1940b7</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2009/11/24/puzzle-2-answers/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Contest #2 Deadline Extended to 11/22/09</title>
		<link>http://forensicscontest.com/2009/11/11/contest-2-deadline-extended-to-112209</link>
		<comments>http://forensicscontest.com/2009/11/11/contest-2-deadline-extended-to-112209#comments</comments>
		<pubDate>Thu, 12 Nov 2009 00:50:27 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #2]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=131</guid>
		<description><![CDATA[The Contest #2 deadline has been EXTENDED to 11/22/09 (11:59:59PM UTC-11). That&#8217;s a whole extra week to polish up your code The winner will receive a Lenovo IdeaPad S10-2 &#8211; just like the free netbooks Sec558 students will get in Orlando.]]></description>
			<content:encoded><![CDATA[<p>The Contest #2 deadline has been EXTENDED to 11/22/09 (11:59:59PM UTC-11). That&#8217;s a whole extra week to polish up your code <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   The winner will receive a Lenovo IdeaPad S10-2 &#8211; just like the <a href="http://www.sans.org/sans-2010/description.php?tid=3992">free netbooks Sec558 students will get in Orlando</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2009/11/11/contest-2-deadline-extended-to-112209/feed</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Contest #2 Prize: Free Netbook!</title>
		<link>http://forensicscontest.com/2009/11/08/contest-2-prize-free-netbook</link>
		<comments>http://forensicscontest.com/2009/11/08/contest-2-prize-free-netbook#comments</comments>
		<pubDate>Mon, 09 Nov 2009 04:33:19 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #2]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=126</guid>
		<description><![CDATA[We&#8217;re pleased to announce the PRIZE for Network Forensics Contest #2: A Lenovo IdeaPad S10-2 &#8211; just like the free netbooks Sec558 students will get in Orlando! The MOST ELEGANT solution wins. Deadline is 11/15/09 11/22/09. Good luck!!]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re pleased to announce the PRIZE for Network Forensics Contest #2:</p>
<p>A Lenovo IdeaPad S10-2 &#8211; just like the <a href="http://www.sans.org/sans-2010/description.php?tid=3992">free netbooks Sec558 students will get in Orlando!</a></p>
<p>The MOST ELEGANT solution wins. Deadline is <del>11/15/09</del> 11/22/09.  Good luck!!</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2009/11/08/contest-2-prize-free-netbook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #2: Ann Skips Bail</title>
		<link>http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail</link>
		<comments>http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail#comments</comments>
		<pubDate>Sat, 10 Oct 2009 22:15:56 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #2]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=81</guid>
		<description><![CDATA[After being released on bail, Ann Dercover disappears! Fortunately, investigators were carefully monitoring her network activity before she skipped town. &#8220;We believe Ann may have communicated with her secret lover, Mr. X, before she left,&#8221; says the police chief. &#8220;The packet capture may contain clues to her whereabouts.&#8221; You are the forensic investigator. Your mission [...]]]></description>
			<content:encoded><![CDATA[<p>After being released on bail, Ann Dercover disappears! Fortunately, investigators were carefully monitoring her network activity before she skipped town. </p>
<p>&#8220;We believe Ann may have communicated with her secret lover, Mr. X, before she left,&#8221; says the police chief. &#8220;The <a href="http://forensicscontest.com/contest02/evidence02.pcap">packet capture</a> may contain clues to her whereabouts.&#8221;</p>
<p><u>You are the forensic investigator.</u> Your mission is to figure out what Ann emailed, where she went, and recover evidence including: </p>
<p>1. What is Ann&#8217;s email address?<br />
2. What is Ann&#8217;s email password?<br />
3. What is Ann&#8217;s secret lover&#8217;s email address?<br />
4. What two items did Ann tell her secret lover to bring?<br />
5. What is the NAME of the attachment Ann sent to her secret lover?<br />
6. What is the MD5sum of the attachment Ann sent to her secret lover?<br />
7. In what CITY and COUNTRY is their rendez-vous point?<br />
8. What is the MD5sum of the image embedded in the document?</p>
<p>Please use the <a href="http://forensicscontest.com/puzzle-2-submissions">Official Submission form</a> to submit your answers. <del>Prize TBD.</del> Prize will be a  Lenovo IdeaPad S10-2 &#8211; just like the <a href="http://www.sans.org/sans-2010/description.php?tid=3992">free netbooks Sec558 students will get in Orlando.</a></p>
<p>Here is your <a href="http://forensicscontest.com/contest02/evidence02.pcap">evidence file</a>:</p>
<p><a href="http://forensicscontest.com/contest02/evidence02.pcap">http://forensicscontest.com/contest02/evidence02.pcap</a><br />
MD5 (evidence02.pcap) = cfac149a49175ac8e89d5b5b5d69bad3</p>
<p><span style="font-size:large;">The MOST ELEGANT solution wins.</span> In the event of a tie, the entry submitted first will receive the prize. Scripting is always encouraged.  We love to see well-written, easy-to-use tools which automate even small sections of the evidence recovery. You are welcome to build upon the work of others, <strong>as long as their work has been released under a GPL license</strong>.  (If it has been released under another free-software license, <a href="mailto:contest@jhamcorp.com">email us</a> to confirm eligibility.) All responses should be submitted as plain text. Microsoft Word documents, PDFs, etc will NOT be reviewed. </p>
<p>Exceptional solutions may be incorporated into the SANS Network Forensics Toolkit. Authors agree that their code submissions will be freely published under the GPL license, in order to further the state of network forensics knowledge. Exceptional submissions may also be used as examples and tools in the Network Forensics class. All authors will receive full credit for their work.</p>
<p><em>Deadline is <del>11/15/09</del> 11/22/09.</em> Here&#8217;s the <a href="http://forensicscontest.com/puzzle-2-submissions">Official Submission form</a>. Good luck!!</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
