Friday, June 14, 2013

Crosshairs 1

So... I thought I was going to get away with doing a 5 in 1 post here with all of the Crosshairs challenges but apparently there is some sort of image limit. Yay. 

This is certainly not the "sexy" part of the CTF, it's nothing new and exciting but worst case scenario somebody learns something.

The forensics challenge began with downloading what appeared to be a modified copy of SANS SIFT with two files on the desktop that were of immediate interest.
After poking around aimlessly in wireshark just looking for anything of interest I pulled up the first challenge.


Note: The level of ease denoted next to each challenge is that of which the organizers determined.
Note: Answering these to the best of my ability... did a wr erase on mem nearly immediately after answering.

Crosshairs 1 (Easy):
The answer really just depended on what your definition of attack is... if you include recon in your definition then the timestamp we are looking for will be found in the first packet of the pcap.

 

The answer would then be "2013-02-08 17:45:08".

No comments:

Post a Comment