<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Network Forensics Puzzle Contest</title>
	<atom:link href="http://forensicscontest.com/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicscontest.com</link>
	<description></description>
	<lastBuildDate>Sat, 22 Oct 2011 00:14:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Puzzle #5: Ms. Moneymany&#8217;s Mysterious Malware by Ingeniowerks Security &#187; Ms. Moneymany’s Mysterious Malware</title>
		<link>http://forensicscontest.com/2010/04/01/ms-moneymanys-mysterious-malware/comment-page-1#comment-2223</link>
		<dc:creator>Ingeniowerks Security &#187; Ms. Moneymany’s Mysterious Malware</dc:creator>
		<pubDate>Sat, 22 Oct 2011 00:14:20 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=524#comment-2223</guid>
		<description>[...] Analysis Challenge to Strengthen Your Skills. The challenge is actually a modified version of the Ms. Moneymany&#8217;s Mysterious Malware puzzle with additional malware analysis questions. So, here we [...]</description>
		<content:encoded><![CDATA[<p>[...] Analysis Challenge to Strengthen Your Skills. The challenge is actually a modified version of the Ms. Moneymany&#8217;s Mysterious Malware puzzle with additional malware analysis questions. So, here we [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #8 by Puzzle #8 Winners &#187; Network Forensics Puzzle Contest</title>
		<link>http://forensicscontest.com/2011/04/27/puzzle-8/comment-page-1#comment-2124</link>
		<dc:creator>Puzzle #8 Winners &#187; Network Forensics Puzzle Contest</dc:creator>
		<pubDate>Wed, 07 Sep 2011 20:28:39 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=734#comment-2124</guid>
		<description>[...] of protocols and meticulous attention to detail. Thank you to everyone who submitted an entry for Puzzle #8, and a special congratulations to the relatively small number of folks who submitted correct [...]</description>
		<content:encoded><![CDATA[<p>[...] of protocols and meticulous attention to detail. Thank you to everyone who submitted an entry for Puzzle #8, and a special congratulations to the relatively small number of folks who submitted correct [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #8 Answers by Thanassis</title>
		<link>http://forensicscontest.com/2011/08/02/contest-8-answers/comment-page-1#comment-2117</link>
		<dc:creator>Thanassis</dc:creator>
		<pubDate>Sat, 03 Sep 2011 19:24:12 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=880#comment-2117</guid>
		<description>Have you announced the winners of this puzzle?</description>
		<content:encoded><![CDATA[<p>Have you announced the winners of this puzzle?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #8 Answers by NeonFlash</title>
		<link>http://forensicscontest.com/2011/08/02/contest-8-answers/comment-page-1#comment-2114</link>
		<dc:creator>NeonFlash</dc:creator>
		<pubDate>Fri, 02 Sep 2011 11:54:33 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=880#comment-2114</guid>
		<description>For question 4:

Am I using the correct display filter?

wlan.wep.iv &amp;&amp; wlan.fc.retry == 0 &amp;&amp; wlan.bssid == 00:23:69:61:00:d0

It shows me the output as: 57009 frames

Below is the reason for using each of those display filters:

wlan.wep.iv -&gt; displays the frames with IVs
wlan.fc.retry == 0 -&gt; don&#039;t display retransmitted frames. IV value is the same for retransmitted frames or when the R flag is set
wlan.bssid == 00:23:69:61:00:d0 -&gt; Joe&#039;s WAP BSSID

Regards,
NeonFlash</description>
		<content:encoded><![CDATA[<p>For question 4:</p>
<p>Am I using the correct display filter?</p>
<p>wlan.wep.iv &amp;&amp; wlan.fc.retry == 0 &amp;&amp; wlan.bssid == 00:23:69:61:00:d0</p>
<p>It shows me the output as: 57009 frames</p>
<p>Below is the reason for using each of those display filters:</p>
<p>wlan.wep.iv -&gt; displays the frames with IVs<br />
wlan.fc.retry == 0 -&gt; don&#8217;t display retransmitted frames. IV value is the same for retransmitted frames or when the R flag is set<br />
wlan.bssid == 00:23:69:61:00:d0 -&gt; Joe&#8217;s WAP BSSID</p>
<p>Regards,<br />
NeonFlash</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #8 Answers by ste7an</title>
		<link>http://forensicscontest.com/2011/08/02/contest-8-answers/comment-page-1#comment-2113</link>
		<dc:creator>ste7an</dc:creator>
		<pubDate>Thu, 01 Sep 2011 12:39:41 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=880#comment-2113</guid>
		<description>When will the winners of contest 8 be announced?</description>
		<content:encoded><![CDATA[<p>When will the winners of contest 8 be announced?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #9 Answers by NeonFlash</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers/comment-page-1#comment-2112</link>
		<dc:creator>NeonFlash</dc:creator>
		<pubDate>Thu, 01 Sep 2011 09:26:37 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=936#comment-2112</guid>
		<description>Thanks sherri! :)

That was a crystal clear explanation.

I got the answer:

GET /schedule.html HTTP/1.1

HTTP/1.1 200 OK
.....
Content-Encoding: gzip
Content-Type: text/html; charset=utf-8

Global AppSec Latin America 2011 Conference
October 6-7, 2011 

Regards,
NeonFlash</description>
		<content:encoded><![CDATA[<p>Thanks sherri! <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>That was a crystal clear explanation.</p>
<p>I got the answer:</p>
<p>GET /schedule.html HTTP/1.1</p>
<p>HTTP/1.1 200 OK<br />
&#8230;..<br />
Content-Encoding: gzip<br />
Content-Type: text/html; charset=utf-8</p>
<p>Global AppSec Latin America 2011 Conference<br />
October 6-7, 2011 </p>
<p>Regards,<br />
NeonFlash</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #9 Answers by sherri</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers/comment-page-1#comment-2111</link>
		<dc:creator>sherri</dc:creator>
		<pubDate>Thu, 01 Sep 2011 06:30:30 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=936#comment-2111</guid>
		<description>@NeonFlash: The HTML embedded in the packet capture from the site lists the dates Oct 6-7, 2011. The site has changed since the time of capture; but everything you need is in the capture itself. Note that the page is COMPRESSED in the pcap (I believe as a gzip file; Scott, please correct me if I am wrong). That means you can&#039;t find it through a string search or simple by looking for HTML-formatted text. You must actually carve out the compressed HTML and decompress it in order to view the content at the time of capture.</description>
		<content:encoded><![CDATA[<p>@NeonFlash: The HTML embedded in the packet capture from the site lists the dates Oct 6-7, 2011. The site has changed since the time of capture; but everything you need is in the capture itself. Note that the page is COMPRESSED in the pcap (I believe as a gzip file; Scott, please correct me if I am wrong). That means you can&#8217;t find it through a string search or simple by looking for HTML-formatted text. You must actually carve out the compressed HTML and decompress it in order to view the content at the time of capture.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #9 Answers by NeonFlash</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers/comment-page-1#comment-2110</link>
		<dc:creator>NeonFlash</dc:creator>
		<pubDate>Thu, 01 Sep 2011 06:14:28 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=936#comment-2110</guid>
		<description>@scott: Thanks for the pointers.

I checked the &quot;Speaking Schedules&quot; section on his site. October 25, 2011, at the &quot;Hackers Halted&quot; conference in Miami, Florida. That&#039;s the closest date to what is mentioned in the answer given above: Oct 6-7, 2011.</description>
		<content:encoded><![CDATA[<p>@scott: Thanks for the pointers.</p>
<p>I checked the &#8220;Speaking Schedules&#8221; section on his site. October 25, 2011, at the &#8220;Hackers Halted&#8221; conference in Miami, Florida. That&#8217;s the closest date to what is mentioned in the answer given above: Oct 6-7, 2011.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #9 Answers by scott</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers/comment-page-1#comment-2108</link>
		<dc:creator>scott</dc:creator>
		<pubDate>Wed, 31 Aug 2011 15:47:06 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=936#comment-2108</guid>
		<description>@jay to move on to round 6 from round 5, you need to open the round 6 Truecrypt container with the password provided in the answers post. Once inside you will see another Truecrypt container. Opening that container is the last challenge in the contest. To open it you will need to use the cipher provided separately to find the password. 

Best,
  Scott</description>
		<content:encoded><![CDATA[<p>@jay to move on to round 6 from round 5, you need to open the round 6 Truecrypt container with the password provided in the answers post. Once inside you will see another Truecrypt container. Opening that container is the last challenge in the contest. To open it you will need to use the cipher provided separately to find the password. </p>
<p>Best,<br />
  Scott</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Puzzle #9 Answers by scott</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers/comment-page-1#comment-2107</link>
		<dc:creator>scott</dc:creator>
		<pubDate>Wed, 31 Aug 2011 15:40:43 +0000</pubDate>
		<guid isPermaLink="false">http://forensicscontest.com/?p=936#comment-2107</guid>
		<description>@NeonFlash you were very close to solving this puzzle! Look closer for sub pages from hxxp://www.schneier.com/. Bruce Schneier will be speaking at a conference later this year!

Cheers,
   Scott</description>
		<content:encoded><![CDATA[<p>@NeonFlash you were very close to solving this puzzle! Look closer for sub pages from hxxp://www.schneier.com/. Bruce Schneier will be speaking at a conference later this year!</p>
<p>Cheers,<br />
   Scott</p>
]]></content:encoded>
	</item>
</channel>
</rss>

