Hi… Thank you for putting together such a neat challenge, not too easy and not too hard, just perfect. I am looking forward to the Network Forensics Class; I think it’ll be exciting. Further, please find the two files attached as my submission to the contest. The files attached are as follows: SOL.TXT: this is the solution file explaining the steps and the tools I used to answer the puzzle’s questions. LOL.PERL: this is the script that I wrote to automate the identification of AOL’s Oscar File Transfer 2 activities and then the retrieval of the transferred files. The script will accept any suspect PCAP file as an input, process it, and then outputs a list of the OFT2 transfers along with sender IP, receiver IP, and the file transferred for each instance. The script will scale to large PCAP files with many OFT2 conversations. Again, thank you so much for putting together this nice contest. Respectfully, Amar Yousif