<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Puzzle Contest</title>
	<atom:link href="http://forensicscontest.com/feed" rel="self" type="application/rss+xml" />
	<link>http://forensicscontest.com</link>
	<description></description>
	<lastBuildDate>Tue, 30 Apr 2013 02:27:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Puzzle #10 Winners!</title>
		<link>http://forensicscontest.com/2012/08/22/puzzle-10-winners</link>
		<comments>http://forensicscontest.com/2012/08/22/puzzle-10-winners#comments</comments>
		<pubDate>Wed, 22 Aug 2012 19:56:41 +0000</pubDate>
		<dc:creator>eric</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1145</guid>
		<description><![CDATA[Network Forensics Puzzle Contest #10 posed a serious challenge, requiring contestants to demonstrate advanced reasoning and meticulous attention to detail, even when reading the scenario. Thank you to everyone who submitted an entry for Puzzle #10, and a special congratulations to the relatively small number of folks who submitted correct answers. The winner of this <a href='http://forensicscontest.com/2012/08/22/puzzle-10-winners'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Network Forensics Puzzle Contest #10 posed a serious challenge, requiring contestants to demonstrate advanced reasoning and meticulous attention to detail, even when reading the scenario. Thank you to everyone who submitted an entry for <a href="http://forensicscontest.com/2012/05/31/puzzle-10-pauldotcom-goes-off-the-air">Puzzle #10</a>, and a special congratulations to the relatively small number of folks who submitted correct answers.</p>
<p>The winner of this contest is&#8230;<strong>Steve B. </strong>! Steve was both the first person to solve the contest AND the person to have the most eloquent solution.  He&#8217;ll be receiving a prize for being first and the Blackhat Black Card!  We&#8217;ll be posting a walkthrough and answers in the coming weeks.  Steve wrote a great write-up <a href="http://0x53-0x42.blogspot.com.au/2012/08/puzzle-10-pauldotcom-goes-off-air.html ">[available here]</a>.</p>
<p><strong>Honorable Mentions</strong>:</p>
<ul>
<li>Jatiki</li>
<li>Zak</li>
</ul>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2012/08/22/puzzle-10-winners/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DEFCON 2012 Contest: Decryption Keys and Answers</title>
		<link>http://forensicscontest.com/2012/08/02/defcon-2012-contest-encryption-keys-and-answers</link>
		<comments>http://forensicscontest.com/2012/08/02/defcon-2012-contest-encryption-keys-and-answers#comments</comments>
		<pubDate>Thu, 02 Aug 2012 17:44:14 +0000</pubDate>
		<dc:creator>randi</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1125</guid>
		<description><![CDATA[We received several requests from DEFCON attendees asking us to post the decryption keys and answers for the DEFCON 2012 contest. The decryption keys and answers are posted below. We will post the list of winners, and a walk-through of the solutions soon. Thank you for playing! Decryption Keys Contest Container: W3lc0m3toNFPC2012@defcon Round2: Aw3s0m3s4uc3@ Round3: <a href='http://forensicscontest.com/2012/08/02/defcon-2012-contest-encryption-keys-and-answers'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>We received several requests from DEFCON attendees asking us to post the decryption keys and answers for the DEFCON 2012 contest.  The decryption keys and answers are posted below.   We will post the list of winners, and a walk-through of the solutions soon.  Thank you for playing!</p>
<p><strong>Decryption Keys</strong><br />
Contest Container: W3lc0m3toNFPC2012@defcon<br />
Round2: Aw3s0m3s4uc3@<br />
Round3: DFC=w00t!<br />
Round4: 4r3g3ttingh4rd<br />
Round5: tHiswi11b3fun#<br />
Round6: Th3R4c3is0n$</p>
<p><em><font color="yellow">SPOILER ALERT!!!</font></em></p>
<p><strong>Answers to DEFCON 2012 Contest Questions</strong></p>
<p>Round 1 Answer: 99901</p>
<p>Round 2 Answer: Golden Alley</p>
<p>Round 3 Answer: ICdarkwater</p>
<p>Round 4 Answer: 15684-b5.12</p>
<p>Round 5 Answer: 2300</p>
<p>Round 6 Answer: Dogfort</p>
<p><em>Copywrite 2012, LMG Security.  All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2012/08/02/defcon-2012-contest-encryption-keys-and-answers/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #10: PaulDotCom Goes Off the Air</title>
		<link>http://forensicscontest.com/2012/05/31/puzzle-10-pauldotcom-goes-off-the-air</link>
		<comments>http://forensicscontest.com/2012/05/31/puzzle-10-pauldotcom-goes-off-the-air#comments</comments>
		<pubDate>Thu, 31 May 2012 21:59:58 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #10]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1060</guid>
		<description><![CDATA[Our latest puzzle was created by Eric Fulton, Sherri Davidoff, Jonathan Ham and Scott Fretheim. &#8220;Oh god&#8221; is the first thought running through your mind as you crack open the door. An odious wafting of day old vomit, sweat, and stale cigar washes across you as the door moves from cracked to ajar. The room <a href='http://forensicscontest.com/2012/05/31/puzzle-10-pauldotcom-goes-off-the-air'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p><em>Our latest puzzle was created by Eric Fulton, Sherri Davidoff, Jonathan Ham and Scott Fretheim.</em></p>
<p>&#8220;Oh god&#8221; is the first thought running through your mind as you crack open the door. An odious wafting of day old vomit, sweat, and stale cigar washes across you as the door moves from cracked to ajar. The room is pitch black, a dirty and exposed hallway light bulb does nothing to cut into the dark abyss of the room. Peering inside you see only shapes, but deep down you know it isn&#8217;t going to be pretty.</p>
<p>Itâ€™s been three weeks since the <a href="http://pauldotcom.com/">PaulDotCom</a> crew went missing. Through extensive research and cyberstalking, millions of PDC fans gathered information relating to their disappearance and hired you to find them. This is John Strand&#8217;s safe house, and a quick Google image search was all you needed to know about his seedy life. Who knows what&#8217;s in this room? Donning rubber gloves you feel for a light switch with your left hand, both intensely afraid and curious for what you are about to see. Wincing in anticipation you flick the switch with a â€œclickâ€.</p>
<p>Nothing happens. &#8220;Why do I always get the messed up jobs&#8221; you whisper to yourself, digging around in your black bag. Corporate espionage isn&#8217;t a clean game, but usually the tech jobs involve threatening geeks in suburban houses, not sneaking around what looks to be North Dakotan project housing. Pulling a sleek Pelican flashlight from the bag, you click it on and begin to survey the damage. Starting from the left you identify the location of the puke smell; there&#8217;s day old vomit trailing its way down peeling wallpaper toward a box of empty tequila bottles. Smell one located.</p>
<p>Further to the right you spot a human shape on a couch. You freeze with the flashlight beam aimed at the shape. Itâ€™s Larry, wrapped in a dirty pink blanket almost too small to cover him, rocking back and forth and muttering something unintelligible. What&#8217;s he saying? You suspect itâ€™s key. His fingers are pale as he grips a WRT54G router which appears to have twenty-four overlapping bites taken out of it. Seconds tick by. Nothing happens; he pays no attention to your entry. Smells two and three probably located. Your light continues its sweep as you spot a table hosting two 24â€ monitors surrounded by miscellaneous cables. Jackpot.</p>
<p>Ignoring the rest of the room you step over martini glasses and other unidentified objects, making a beeline to the desk. The little voice in your head shouts &#8220;Damn! Damn! Damn!&#8221; There is evidence that someone left only recently. The scene is almost out of a second rate Hollywood movie, being so incredibly obvious:a puddle of spilled cosmopolitan makes apparent the distinct outlines where a laptop and external hard drive once sat.</p>
<p>Disheartened, you rummage though the desk, hopeful of finding a forgotten USB drive or other storage device. No dice. You slide a few sticky quarters off of the desk (it&#8217;s not like you&#8217;re getting a per-diem) and continue the search&#8211; wait. One of the quartersâ€¦ splits a little. You pick it up and play with it. Viola! A small micro SDHC card lies inside the quarter. Your heart starts beating faster. You have a clue.</p>
<p>As a matter of habit you go through the rest of the room, quietly, as the eerie sound of Larry chanting in the background never stops. Old coffee mugs, a dirty microwave, hundreds of empty frozen food wrappers, and magnetic buckyballs cover the floor like a sort of 21st century urban underbrush&#8230;and then you see something peculiar. A stack of hard drives sits in the corner. The top drive looks like someone shot it 7 or 8 times, a strange method for data destruction, but certainly an effective one. Rummaging through the stack of drives you find one at the bottom looking as if it survived the data massacre. Grabbing it, you give one last look around as you walk to the door. The sounds of Larry go from muffled to silent as you shut the door and make your exit.</p>
<h4>The Evidence</h4>
<p><strong><span style="text-decoration: underline;">You are the forensic investigator.</span></strong>The items found in the safe house have been <a href="http://forensicscontest.com/contest10/evidence10.7z">uploaded to this server</a> for your analysis. These include:</p>
<ul>
<li>quarter-SDHC-snippet.dd â€“ <em>A DD image of a the SDHC card found inside the quarter.</em></li>
<li>pcap-from-surviving-hard-drive.pcap â€“ <em>A packet capture that you copied off the surviving hard drive.</em></li>
</ul>
<p>Download the 7-zipped evidence file <a href="http://forensicscontest.com/contest10/evidence10.7z">here</a>.</p>
<p>SHA256 sum:<br />
44450915addb8bdbe1766a3fad1c03059393a0f1f01839b19f98f235dc3b97bd</p>
<h4>The Adoring Fans&#8217; Questions</h4>
<p>Can you solve the puzzle and find out what happened to PaulDotCom? Their adoring legions of fans have asked you to find the answers to the following questions along the way:</p>
<p>1. In his conversation with juniorkeyy, how old does Larry initially say he is?</p>
<p>2. What was the filename of the file that had the following SHA256 sum:</p>
<p>e56931935bc60ac4c994eabd89b003a7ae221d941f1b026b05a7947a48dc9366</p>
<p>3. What is the SHA256sum of the photo from the &#8220;dd&#8221; image that shows Larry taking a bite out of a wireless router?</p>
<p>4. What is the SHA256sum of the image that shows zombie Larry taking a<br />
bite out of a cat?</p>
<p>5. What is Larry saying as he rocks back and forth? (No spaces or<br />
capital letters.)</p>
<p>6. Where are Paul and John? Report their GPS coordinates:<br />
a) Latitude<br />
b) Longitude</p>
<p>BONUS. What is the name of the nearest bar?</p>
<h4>Submission Form</h4>
<p>Please submit your answers using the <a href="http://forensicscontest.com/submit-your-answers-for-puzzle-10">Official Submission Form</a>.<br />
<em>Deadline is 7/23/12 (11:59:59PM UTC-11)</em> (In other words, if it&#8217;s still 7/23/12 anywhere in the world, you can submit your entry.)</p>
<h4>Prize</h4>
<p>The Grand Prize will be a Black Hat &#8220;Black Card&#8221;! Thanks, Black Hat, for sponsoring such an awesome prize.</p>
<p>There will also be prizes for the first correct submission, as well as the 2nd and 3rd place runner-ups. Stay tuned for more info!</p>
<h4>How to Win</h4>
<p>The MOST ELEGANT solution wins. In the event of a tie, the entry submitted first will receive the prize. Coding is always encouraged. We love to see well-written, easy-to-use tools which automate even small sections of the evidence recovery. Graphical and command-line tools are all eligible. You are welcome to build upon the work of others, <strong>as long as their work has been released under a an approved <a href="http://www.opensource.org/licenses">Open Source License</a></strong>. All responses should be submitted as plain text. Microsoft Word documents, PDFs, etc will NOT be reviewed.</p>
<h4>More Details</h4>
<p>Feel free to collaborate with other people and discuss ideas back and forth. You can even submit as a team (there will be only one prize). However, <span style="text-decoration: underline;">please do not publish the answers before the deadline</span>, or you (and your team) will be automatically disqualified. Also, please understand that the contest materials are copyrighted and that we&#8217;re offering them publicly for the community to enjoy. You are welcome to publish full solutions after the deadline, but please use proper attributions and link back. If you are interested in using the contest materials for other purposes, <a href="mailto:answer@lakemissoulagroup.com">just ask first.</a></p>
<p>Authors agree that their code submissions will be freely published under the GPL license, in order to further the state of network forensics knowledge. Exceptional submissions may be used as examples and tools in the Network Forensics course or book. All authors will receive full credit for their work.</p>
<h4>To Recap</h4>
<p><a href="http://forensicscontest.com/contest10/evidence10.7z">Evidence File</a><br />
Sha256sum: 44450915addb8bdbe1766a3fad1c03059393a0f1f01839b19f98f235dc3b97bd</p>
<p><em>Deadline is 7/23/12 (11:59:59PM UTC-11)</em>. Here&#8217;s the <a href="http://forensicscontest.com/submit-your-answers-for-puzzle-10">Official Submission form</a>. Good luck!!</p>
<p><em>Copyright 2012, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2012/05/31/puzzle-10-pauldotcom-goes-off-the-air/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network Forensics: Uncovering Secrets of Mobile Applications</title>
		<link>http://forensicscontest.com/2012/05/31/network-forensics-uncovering-secrets-of-mobile-applications</link>
		<comments>http://forensicscontest.com/2012/05/31/network-forensics-uncovering-secrets-of-mobile-applications#comments</comments>
		<pubDate>Thu, 31 May 2012 18:24:49 +0000</pubDate>
		<dc:creator>eric</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1116</guid>
		<description><![CDATA[Join Eric Fulton on Thursday, June 14 at 1:00 PM ET for the BlackHat Webcast, &#8220;Network Forensics: Uncovering Secrets of Mobile Applications&#8220;. You might even learn something for contest 10&#8230;which will be presented live later today on PaulDotCom! On the Internet, every action leaves a mark&#8212;in routers, firewalls, web proxies, and within network traffic itself. <a href='http://forensicscontest.com/2012/05/31/network-forensics-uncovering-secrets-of-mobile-applications'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Join Eric Fulton on Thursday, June 14 at 1:00 PM ET for the BlackHat Webcast, &#8220;<a href="https://www.blackhat.com/html/webcast/netforensics-2012-june.html">Network Forensics: Uncovering Secrets of Mobile Applications</a>&#8220;.  You might even learn something for contest 10&#8230;which will be presented live later today on <a href="http://pauldotcom.com/2012/05/episode-290---forensics-tool-s.html">PaulDotCom</a>!</p>
<blockquote><p>On the Internet, every action leaves a mark&#8212;in routers, firewalls, web proxies, and within network traffic itself. When a hacker breaks into a bank, or an insider smuggles secrets to a competitor, evidence of the crime is always left behind. But what about mobile devices? What seemingly innocuous information are they sharing with, and without, your knowledge?</p>
<p>In this webcast, watch as Eric Fulton analyzes mobile network traffic and discover some interesting details about your favorite applications. You will see him locate GPS co-ordinates, identify installed mobile applications, and more.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2012/05/31/network-forensics-uncovering-secrets-of-mobile-applications/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tune into PaulDotCom for Puzzle #10 Release!</title>
		<link>http://forensicscontest.com/2012/05/30/tune-into-pauldotcom-for-puzzle-10-release</link>
		<comments>http://forensicscontest.com/2012/05/30/tune-into-pauldotcom-for-puzzle-10-release#comments</comments>
		<pubDate>Thu, 31 May 2012 03:24:07 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #10]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1053</guid>
		<description><![CDATA[Tune into the PaulDotCom Security Podcast TOMORROW, May 31 where we&#8217;ll release Puzzle 10: PaulDotCom Goes Off the Air! Eric Fulton will do a live reading of the puzzle scenario (which he wrote) in his best film noir voice. Sherri Davidoff and Jonathan Ham will follow up with a Tech Segment called &#8220;AntiForensics and Bugs&#8211; <a href='http://forensicscontest.com/2012/05/30/tune-into-pauldotcom-for-puzzle-10-release'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Tune into the <a href="http://pauldotcom.com/">PaulDotCom Security Podcast</a> TOMORROW, May 31</a> where we&#8217;ll release Puzzle 10: PaulDotCom Goes Off the Air! Eric Fulton will do a live reading of the puzzle scenario (which he wrote) in his best <em>film noir</em> voice. </p>
<p>Sherri Davidoff and Jonathan Ham will follow up with a Tech Segment called &#8220;AntiForensics and Bugs&#8211; When Forensics Tools Lie to You.&#8221; </p>
<p>Check out the show notes <a href="http://pauldotcom.com/wiki/index.php/Episode290">here</a> for more details.</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2012/05/30/tune-into-pauldotcom-for-puzzle-10-release/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PaulDotCom, Blackhat USA 2012, Defcon #20</title>
		<link>http://forensicscontest.com/2012/05/18/pauldotcom-blackhat-usa-2012-defcon-20</link>
		<comments>http://forensicscontest.com/2012/05/18/pauldotcom-blackhat-usa-2012-defcon-20#comments</comments>
		<pubDate>Fri, 18 May 2012 19:12:32 +0000</pubDate>
		<dc:creator>eric</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=1037</guid>
		<description><![CDATA[Hello Everyone! It has been a busy year, and once again we find ourselves nearing Defcon where we run the wildly popular Network Forensics Puzzle Contest. We have some good things in store for the coming months and would like to share. PaulDotCom We are running a NFPC over at PaulDotCom in the coming month. <a href='http://forensicscontest.com/2012/05/18/pauldotcom-blackhat-usa-2012-defcon-20'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Hello Everyone!<br />
It has been a busy year, and once again we find ourselves nearing Defcon where we run the wildly popular Network Forensics Puzzle Contest. We have some good things in store for the coming months and would like to share.</p>
<p><strong>PaulDotCom</strong><br />
We are running a NFPC over at <a title="PaulDotCom" href="http://pauldotcom.com">PaulDotCom</a> in the coming month.  When it&#8217;s live we will share the link here.  You should also check out PaulDotCom for a heap of great articles and videos.</p>
<p><strong>Blackhat USA 2012</strong><br />
Want to be taught by the people who literally wrote the book on <a href="http://www.amazon.com/Network-Forensics-Tracking-Hackers-Cyberspace/dp/0132564718/ref=sr_1_2?ie=UTF8&amp;qid=1336494506&amp;sr=8-2">Network Forensics</a>?  Register for their highly praised course &#8220;<a href="https://www.blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_network_forensics.html">NETWORK FORENSICS: BLACK HAT RELEASE</a>&#8221; to learn the latest techniques in the field of Network Forensics.  You&#8217;ll even get the book at 25% off, since it is the course text.</p>
<p><strong><strong>Defcon 20</strong><br />
</strong>Going to DEFCON? Join us at for the annual <a href="https://forum.defcon.org/forumdisplay.php?f=654">DEFCON Network Forensics Puzzle Contest</a>, and win a shiny new iPad!<br />
&nbsp;</p>
<p>Other updates can be found following our twitter (<a href="https://twitter.com/#!/LMGSecurity">@LMGSecurity</a> or <a href="https://twitter.com/#!/trisk3t">@trisk3t</a>), our <a href="https://www.linkedin.com/company/lmg-security">LinkedIn Page</a>, or our <a href="https://www.facebook.com/LMGSec">Facebook Page</a>.  Cheers!</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2012/05/18/pauldotcom-blackhat-usa-2012-defcon-20/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #8 Winners</title>
		<link>http://forensicscontest.com/2011/09/07/puzzle-8-winners</link>
		<comments>http://forensicscontest.com/2011/09/07/puzzle-8-winners#comments</comments>
		<pubDate>Wed, 07 Sep 2011 20:28:34 +0000</pubDate>
		<dc:creator>eric</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=884</guid>
		<description><![CDATA[Network Forensics Puzzle Contest #8 posed a serious challenge, requiring contestants to demonstrate an advanced knowledge of protocols and meticulous attention to detail. Thank you to everyone who submitted an entry for Puzzle #8, and a special congratulations to the relatively small number of folks who submitted correct answers. The winner of this contest is&#8230;Stefan <a href='http://forensicscontest.com/2011/09/07/puzzle-8-winners'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Network Forensics Puzzle Contest #8 posed a serious challenge, requiring contestants to demonstrate an advanced knowledge of protocols and meticulous attention to detail.  Thank you to everyone who submitted an entry for <a href="http://forensicscontest.com/2011/04/27/puzzle-8" title="Puzzle #8">Puzzle #8</a>, and a special congratulations to the relatively small number of folks who submitted correct answers. </p>
<p>The winner of this contest is&#8230;<strong>Stefan S. Op de Beek </strong>!  Stefan wins a <a href="http://www.newegg.com/Product/Product.aspx?Item=N82E16833162047" title="Buffalo Wireless Router">Buffalo Wireless Router</a> for his correct answers and UTScapy test script.  While the script didn&#8217;t work perfectly on my system, it is a great example of leveraging existing frameworks to analyze packet captures. Contestants, answers, and solutions below.</p>
<p><strong>Contestants</strong>:<br />
Joerg Gerschuetz<br />
Winter Faulk<br />
Aaron Wamapch<br />
Kazunori Kojima<br />
Adam Jenkins<br />
Steeve Barbeau<br />
Tyler Dean<br />
Ward Perry<br />
J-Michael Roberts<br />
Anthony<br />
Stefan S. of de Beek</p>
<p><strong>Answers:</strong><br />
<strong>1) Joe&#8217;s WAP is beaconing. Based on the contents of the packet capture, what are the SSID and BSSID of his access point?</strong><br />
     SSID: Ment0rNet<br />
     BSSID: 00:23:69:61:00:d0</p>
<p><strong>2) How long is the packet capture, from beginning to end (in SECONDS &#8211; please round to the nearest full second)?</strong><br />
   A: 414s</p>
<p><strong>3) How many WEP-encrypted data frames are there total in the packet capture?</strong><br />
<em>$ tshark -r evidence08.pcap -R &#8216;((wlan.fc.type_subtype == 0&#215;20) &#038;&#038; (wlan.fc.protected == 1)) &#038;&#038; (wlan.bssid == 00:23:69:61:00:d0)&#8217;|wc -l</em><br />
  A: 59274</p>
<p><strong>4) How many *unique* WEP initialization vectors (IVs) are there TOTAL in the packet capture relating to Joe&#8217;s access point?</strong><br />
<em>$ tshark -r evidence08.pcap -R &#8216;(wlan.bssid == 00:23:69:61:00:d0) &#038;&#038; wlan.wep.iv&#8217; -T fields -e wlan.wep.iv | sort -u | wc -l</em><br />
  A: 29719 </p>
<p><strong>5) What was the MAC address of the station executing the Layer 2 attacks?</strong><br />
  A: 1c:4b:d6:69:cd:07</p>
<p><strong>6) How many *unique* IVs were generated (relating to Joe&#8217;s access point):<br />
  a) By the attacker station?</strong><br />
<em>$ tshark -r evidence08.pcap -R &#8216;(wlan.bssid == 00:23:69:61:00:d0) &#038;&#038; (wlan.sa == 1c:4b:d6:69:cd:07) &#038;&#038; wlan.wep.iv&#8217; -T fields -e wlan.wep.iv|sort -u|wc -l</em><br />
  A: 14133 (14132 also accepted)</p>
<p>  <strong>b) By all *other* stations combined?</strong><br />
<em>$ tshark -r evidence08.pcap -R &#8216;(wlan.bssid == 00:23:69:61:00:d0) &#038;&#038; (wlan.sa != 1c:4b:d6:69:cd:07) &#038;&#038; wlan.wep.iv&#8217; -T fields -e wlan.wep.iv|sort -u|wc -l</em><br />
   B : 15587</p>
<p><strong>7) What was the WEP key of Joe&#8217;s WAP?  </strong><br />
<em>$ aircrack-ng -b 00:23:69:61:00:d0 evidence08.pcap</em><br />
   A: D0:E5:9E:B9:04</p>
<p><strong>8.) What were the administrative username and password of the targeted wireless access point?</strong><br />
    username: admin<br />
    passphrase: admin</p>
<p><strong>9) What was the WAP administrative passphrase changed to?</strong><br />
    passphrase: hahp0wnedJ00</p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/09/07/puzzle-8-winners/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #9: Ann&#8217;s Deception (DEFCON 2011)</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011</link>
		<comments>http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011#comments</comments>
		<pubDate>Tue, 16 Aug 2011 06:19:09 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #9 (DEFCON 2011)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=900</guid>
		<description><![CDATA[This year&#8217;s DEFCON contest was a huge success, with over 200 teams entering! The contest was split up into six rounds of increasing difficulty. The first team to complete all six rounds won the contest. Now that the contest is over, we&#8217;re placing the materials here for folks who would like to play around on <a href='http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p><em>This year&#8217;s DEFCON contest was a huge success, with over 200 teams entering! The contest was split up into six rounds of increasing difficulty. The first team to complete all six rounds won the contest. Now that the contest is over, we&#8217;re placing the materials here for folks who would like to play around on their own.<br />
</em></p>
<p><em>WARNING: This contest contains off-color humor which may not be appropriate for the classroom, children, rodents, etc.</em></p>
<p> The lead chemist of a high-profile pharmaceutical company was involved in a serious accident, leaving him in a coma days before the release of the company&#8217;s highly publicized &#8220;133t pill.&#8221; The chemist was the only person in possession of the list of ingredients required to produce the wonder drug, and it is not known if he will ever recover.    All chemical evidence of the drug has been destroyed, but the company believes that the missing ingredients may have been stored electronically.  <u>You have been hired as a forensic investigator, to recover the final ingredient of their 133t pill.</u> Can you find the missing ingredient? </p>
<p>Here&#8217;s a link to the encrypted contest volume:<br />
<a href="http://forensicscontest.com/contest09/Defcon2011-Contest.tc">Defcon2011-Contest.tc</a></p>
<p><strong> SHA256 CHECKSUM:</strong><br />
6906e4a08bd498c6ff78928b1c8d292a9f89f2ecfac60094528f4497e2254474
</p>
<p>The Defcon2011-Contest.tc is an encrypted password-protected Truecrypt volume. Inside are six individual Truecrypt archives which each contain a single round of the contest. You will need to mount each encrypted volume using Truecrypt before you can access its contents. <a href="http://www.truecrypt.org/docs/?s=tutorial4">Here is a page</a> which shows you how to mount a Truecrypt volume.</p>
<p><em>At the start time, DEFCON attendees visited the contest booth to obtain the first decryption passwords, provided below:</p>
<p>The password to unlock Defcon2011-Contest.tc is: !#$h1d3&#038;&#038;s33k$#!<br />
The password to unlock round1 is: r0und1g0!!<br />
</em><br />
<em>When a team found the answer to a round, they texted it to Headquarters (HQ). If their answer was correct, staff texted back the key to unlock the next round.</em><br />
<em><br />
<font color="yellow">SPOILER ALERT</font>: You can find the keys to each of the encrypted volumes <a href="http://forensicscontest.com/contest09/spoilers/decryption_keys.txt">here</a>.</p>
<p><font color="yellow">SUPER SPOILER ALERT</font>: For your convenience, we&#8217;ve also unlocked all the rounds for those of you who just want to play around with individual round puzzles without having to solve the whole thing in order. You can find the individual round puzzles here:</p>
<p><a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round1/defcon2011contest-round1.html">Round1</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round2/defcon2011contest-round2.html">Round2</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round3/defcon2011contest-round3.html">Round3</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round4/defcon2011contest-round4.html">Round4</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round5/defcon2011contest-round5.html">Round5</a><br />
<a href="http://forensicscontest.com/contest09/spoilers/2011-Defcon-Contest-Round6/defcon2011contest-round6.html">Round6</a><br />
</em></p>
<p><u>A few notes:</u></p>
<p>1. You will not get the correct answer simply by running &#8220;strings&#8221; on the packet captures. It is more complicated than that.<br />
<br />2. Please do not attempt to brute-force the answer by guessing. We reserve the right to cut you off from submitting answers if you abuse the privilege.<br />
<br />3. There are six contest rounds containing six evidence files.  You must analyze the evidence files in order to answer the question(s) which go along with each capture. </p>
<p>Have fun! <img src='http://forensicscontest.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><em><br />This puzzle was created by Scott Fretheim, Randi Price, Eric Fulton, Sherri Davidoff, and Jonathan Ham (Lake Missoula Group, LLC).</p>
<p>Copyright 2011, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Puzzle # 9 Winners</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-winners</link>
		<comments>http://forensicscontest.com/2011/08/16/puzzle-9-winners#comments</comments>
		<pubDate>Tue, 16 Aug 2011 06:19:00 +0000</pubDate>
		<dc:creator>scott</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #9 (DEFCON 2011)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=889</guid>
		<description><![CDATA[Over 200 teams entered the Network Forensics Puzzle Contest at DEFCON 19. Five teams were able to finish the challenge during the DEFCON conference. Congratulations to this year&#8217;s winning team: &#8220;5154c&#8221;! It was a really close match. Each of the top three teams came in only 15 minutes apart. We really hope all of you <a href='http://forensicscontest.com/2011/08/16/puzzle-9-winners'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Over 200 teams entered the Network Forensics Puzzle Contest at DEFCON 19. Five teams were able to finish the challenge during the DEFCON conference. Congratulations to this year&#8217;s winning team: &#8220;5154c&#8221;! It was a really close match. Each of the top three teams came in only 15 minutes apart. We really hope all of you enjoyed competing, and we look forward to seeing you again next year!</p>
<h3>Top Ten Finalists at DEFCON 19:</h3>
<p>1.  5154c <em>(Winner!)</em><br />
2.  C2 eye<br />
3.  Barnhaus Crew<br />
4.  ArchMage<br />
5.  PSKL<br />
6.  Team Cheese<br />
7.  8008<br />
8.  Team Moosey Fate<br />
9.  Chippendales<br />
10. Kyle Bragle</p>
<p><em>
<p>Copyright 2011, Lake Missoula Group, LLC. All rights reserved.</p>
<p></em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/08/16/puzzle-9-winners/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Puzzle #9 Answers</title>
		<link>http://forensicscontest.com/2011/08/16/puzzle-9-answers</link>
		<comments>http://forensicscontest.com/2011/08/16/puzzle-9-answers#comments</comments>
		<pubDate>Tue, 16 Aug 2011 06:18:36 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Contest]]></category>
		<category><![CDATA[Puzzle #9 (DEFCON 2011)]]></category>

		<guid isPermaLink="false">http://forensicscontest.com/?p=936</guid>
		<description><![CDATA[Here are the answers to Puzzle #9: Ann&#8217;s Deception (DEFCON 2011): Round 1 Decryption Key: r0und1g0!! In this capture we were looking for the name of the company. This is located inside an email. Answer: Factory-Made-Winning-Pharmaceuticals&#160; Round 2 Decryption Key: !n1c3?w0rk In this capture we were looking for the date of a speech given by <a href='http://forensicscontest.com/2011/08/16/puzzle-9-answers'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p>Here are the answers to Puzzle #9: Ann&#8217;s Deception (DEFCON 2011):</p>
<ol>
<li>Round 1 Decryption Key: r0und1g0!!<br />
In this capture we were looking for the name of the company. This is located inside an email.<br />
Answer: Factory-Made-Winning-Pharmaceuticals<br />&nbsp;
</li>
<li>Round 2 Decryption Key: !n1c3?w0rk<br />
In this capture we were looking for the date of a speech given by Bruce Schneier. To solve this puzzle you must carve out a packet capture which was sent as an email attachment. Inside that packet capture, you can find the data by looking through the web traffic to see the pages Ann viewed.<br />
Answer: October 6-7, 2011<br />&nbsp;</li>
<li>Round 3 Decryption Key:?g3tting!t0ugh<br />
In this capture we were looking for Romulus&#8217;s password. This can be found by carving out the VOIP conversation and listening to it.<br />
Answer: rom127#<br />&nbsp;</li>
<li>Round 4 Decryption Key: m4k1ng?pr0g<br />
In this packet capture we were looking for the name on the 16th line in a spread sheet. To find the answer, you need to carve out the SMB transfer of the 7zip file containing the credit card file.  In order to unlock the 7zip file you will need to use the password YOU found in Round 3.<br />
Answer: Jason Wilson<br />&nbsp;</li>
<li>Round 5 Decryption Key: 0v3r#h4lf?w4y<br />
In this packet capture, you need to carve out the SMB file transfer of the ingredients list. To unlock the 7zip file containing the ingredients list, you will need to use the password you found in in Round 4.<br />
Answer:8.4 oz- Red Bull;  Tim<br />&nbsp;</li>
<li>Round 6 Decryption Key: ch33rs!0n3$m0r3<br />
Round 6 requires you to find the final ingredient of the 133t pill.  To unlock the volume, you must use the cipher along with the previous answers from Rounds 1-5.  Begin by solving the cipher, and then use the cipher as the password to unlock the Truecrypt volume.<br />
Cipher Solution: 00gmu1rt#?<br />
Answer: 2oz Vodka</li>
<p><em>Copyright 2011, Lake Missoula Group, LLC. All rights reserved.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://forensicscontest.com/2011/08/16/puzzle-9-answers/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
