Submit Your Answers for Puzzle 6!

So you’ve solved the puzzle! Enter your solutions in the form below. If you have code, please copy and paste it into the text boxes at the bottom. You can also email code as attachments to answer@lakemissoulagroup.com (we would prefer if you used this submission form, though). Thanks!


  • a. What was the filename of the object that was requested? 
  • b. What is the MD5sum of the object that was returned? 

6. In packet 17, the malicious server sent a file to the client.

  • a. What type of file was it? Choose one:

     Windows executable
     GIF image
     PHP script
     Zip file
     Encrypted data

7. Vick’s computer repeatedly tried to connect back to the malicious server on
port 4445, even after the original connection on port 4444 was closed. With
respect to these repeated failed connection attempts:

  •  Every packet
     Every third packet
     Every 10-15 seconds
     Every 30-35 seconds
     Every 60 seconds
  •  Every packet
     Every third packet
     Every 10-15 seconds
     Every 30-35 seconds
     Every 60 seconds
  •  Every packet
     Every third packet
     Every 10-15 seconds
     Every 30-35 seconds
     Every 60 seconds

By submitting this form, you agree to the following: Exceptional solutions may be incorporated into the SANS Network Forensics Investigative Toolkit (SNIFT kit). Exceptional submissions may also be used as examples and tools in the Network Forensics course, with full attribution. By submitting your answer to this puzzle, you agree that your code submissions will be freely published under the GPL license, and your solution’s text will be licensed according to the Creative Commons v3 “Attribution” License. All authors will receive full credit for their work.

Share and Enjoy:
  • Digg
  • StumbleUpon
  • del.icio.us
  • Facebook
  • Twitter
  • Google Bookmarks
  • Slashdot
  • Suggest to Techmeme via Twitter
  • Technorati

One Response to “Submit Your Answers for Puzzle 6!”

  1. I just got my answers in at the last second…that hint really threw me off because my MD5 sums were initially different! My notes were not ready at the time of submission but are 90% done. Is there any point in sending those in since its after the deadline, or not?

    Thanks for the contest – very interesting as always
    Brian

Leave a Reply

(required)

(required)

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>