728x90

[๋ฌธ์ œ]

https://forensicscontest.com/2009/10/10/puzzle-2-ann-skips-bail

 

Puzzle #2: Ann Skips Bail – Network Forensics Puzzle Contest

After being released on bail, Ann Dercover disappears! Fortunately, investigators were carefully monitoring her network activity before she skipped town. “We believe Ann may have communicated with her secret lover, Mr. X, before she left,” says the pol

forensicscontest.com

After being released on bail, Ann Dercover disappears! Fortunately, investigators were carefully monitoring her network activity before she skipped town.

“We believe Ann may have communicated with her secret lover, Mr. X, before she left,” says the police chief. “The packet capture may contain clues to her whereabouts.”

You are the forensic investigator. Your mission is to figure out what Ann emailed, where she went, and recover evidence including:

1. What is Ann’s email address?
2. What is Ann’s email password?
3. What is Ann’s secret lover’s email address?
4. What two items did Ann tell her secret lover to bring?
5. What is the NAME of the attachment Ann sent to her secret lover?
6. What is the MD5sum of the attachment Ann sent to her secret lover?
7. In what CITY and COUNTRY is their rendez-vous point?
8. What is the MD5sum of the image embedded in the document?


[๋ฌธ์ œ ํ’€์ด]

1. What is Ann’s email address?

  • ๋จผ์ € TCP stream์„ ์—ด์–ด ๋‚ด์šฉ์„ ์‚ดํŽด๋ณด๋‹ˆ ๋ฉ”์ผ์˜ ๋‚ด์šฉ์„ ๋‹ด๊ธด ๋ฐ์ดํ„ฐ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฉ”์‹œ์ง€ ๋‚ด์šฉ ์‹œ์ž‘ ๋ถ€๋ถ„์— From: "Ann Dercover" <sneakyg33k@aol.com>์„ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

โ–ถ neakyg33k@aol.com

 

 



2. What is Ann’s email password?

  • SMTP๋Š” base64์ธ์ฝ”๋”ฉ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•˜๋Š”๋ฐ, ์ƒ๋‹น ๋ถ€๋ถ„์— ๋‚ด์šฉ์„ ๋””์ฝ”๋”ฉํ•˜๋‹ˆ ๋จผ์ € ๋กœ๊ทธ์ธ์„ ์š”์ฒญ์„ ํ•˜๊ณ NTU4cjAwbHo=์ž…๋ ฅ ํ›„์— 235 AUTHENTICATION SUCCESSFUL๋กœ๊ทธ์ธ์ด ์„ฑ๊ณต๋๋‹ค๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ํ†ตํ•ด ์ด ๋ถ€๋ถ„์ด ํŒจ์Šค์›Œ๋“œ๋ผ ์ƒ๊ฐํ•˜๊ณ  ๋””์ฝ”๋”ฉํ•ด๋ณด๋‹ˆ 558r00lz ํŒจ์Šค์›Œ๋“œ๋ฅผ ์•Œ๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค!

โ–ถ 558r00lz 

 



3. What is Ann’s secret lover’s email address?

  • ์ฒซ ๋ฒˆ์งธ ๋ฌธ์ œ์ฒ˜๋Ÿผ ๋ฉ”์ผ ์ƒ๋‹จ ๋ถ€๋ถ„์—์„œ To: <sec558@gmail.com>์„ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

โ–ถ sec558@gmail.com



4. What two items did Ann tell her secret lover to bring?

  • ๋‹ค์Œ ์ŠคํŠธ๋ฆผ์œผ๋กœ ๋„˜์–ด๊ฐ€์„œ ๋ฉ”์ผ ๋‚ด์šฉ์„ ๋ถ„์„ํ•ด ๋ณด๋‹ˆ Bring your fake passport and a bathing suit. ๋ฉ”์‹œ์ง€๋ฅผ ์ฃผ๊ณ ๋ฐ›์€ ๊ฒƒ์„ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.

โ–ถ fake passport and a bathing suit


5. What is the NAME of the attachment Ann sent to her secret lover?

  • ๋งˆ์ง€๋ง‰ ๋ถ€๋ถ„์— Ann์ด ๋ณด๋‚ธ ํŒŒ์ผ์˜ ์ด๋ฆ„์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

โ–ถ secretrendezvous.docx


6. What is the MD5sum of the attachment Ann sent to her secret lover?

  • ๊ทธ๋‹ค์Œ์—๋Š” NetworkMiner ๋ถ„์„ ํˆด์„ ์ด์šฉํ•ด์„œ ๋ถ„์„์„ ํ–ˆ๊ณ  ํŒŒ์ผ ์ค‘์— secretrendezvous.docx MD5์„ ์‰ฝ๊ฒŒ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
  • NetworkMiner ๋‹ค์šด๋กœ๋“œ ์‚ฌ์ดํŠธ

โ–ถ 9e423e11db88f01bbff81172839e1923


7. In what CITY and COUNTRY is their rendez-vous point?

  • Open file ์˜ต์…˜์„ ์ด์šฉํ•˜์—ฌ ๋ฐ”๋กœ ํŒŒ์ผ์„ ์—ด์–ด์„œ ํ™•์ธํ•˜๋‹ˆ ์œ„์น˜ ์ •๋ณด๋ฅผ ๋ฐ”๋กœ ์•Œ์•„๋ƒˆ์Šต๋‹ˆ๋‹ค.

โ–ถ Playa del Carmen, Mexico


8. What is the MD5sum of the image embedded in the document?

  • ์ฒ˜์Œ์—๋Š” ๊ทธ๋ƒฅ ํŒŒ์ผ์˜ ์ด๋ฏธ์ง€๋ฅผ ๋”ฐ๋กœ ์ €์žฅํ•ด์„œ md5 ์ฒดํฌ์„ฌ์„ ํ–ˆ๋Š”๋ฐ ๋‹ต์„ ํ™•์ธํ•˜๋‹ˆ ๊ทธ๋ ‡๊ฒŒ ๊ตฌํ•˜๋ฉด ๊ฐ’์ด ๋‹ค๋ฅด๊ฒŒ ๋‚˜์˜จ๋‹ค๊ณ  ํ•ด์„œ ๋‹ค๋ฅธ ๋ฐฉ๋ฒ•์œผ๋กœ ์••์ถ•์„ ํ•˜๊ณ  ์••์ถ•ํ•ด์ œํ•˜๋ฉด media์—์„œ ์ด๋ฏธ์ง€ ํŒŒ์ผ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•ด์„œ ์‹œ๋„ํ–ˆ์ง€๋งŒ ์ €๋Š” ์ด๋ฏธ์ง€ ํŒŒ์ผ์ด ๋‚˜์˜ค์ง€ ์•Š์•„ ๋‹ค๋ฅธ ๋ฐฉ๋ฒ•์„ ์‹œ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ๋จผ์ € docxํŒŒ์ผ์„ html ํ™•์žฅ์ž๋กœ ๋ฐ”๊ฟจ๋”๋‹ˆ ํด๋” ํ•˜๋‚˜๊ฐ€ ๋” ์ƒ๊ฒผ๊ณ  ๊ทธ ํด๋” ์•ˆ์— ์ด๋ฏธ์ง€๋ฅผ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

  • ๊ทธ๋‹ค์Œ image001.png์˜ MD5 ๊ฐ’์„ ์•Œ์•„๋ƒˆ์Šต๋‹ˆ๋‹ค.
  • ์œˆ๋„์šฐ๋Š” cmd๋กœ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. [Windows ๋ช…๋ น์–ด]: certutil -hashfile [filename] [Hashalgorithm]
  • ๋ฌธ์ œ๋Š” imageํŒŒ์ผ์˜ md5sum์„ ์•Œ์•„๋‚ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— certutil -hashfile image001.png md5์„ ์ž…๋ ฅํ•ด์„œ ๋งˆ์ง€๋ง‰ ๋ฌธ์ œ๊นŒ์ง€ ํ•ด๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค!

โ–ถ aadeace50997b1ba24b09ac2ef1940b7

 

 

 

+ Recent posts