So... I thought I was going to get away with doing a 5 in 1 post here with all of the Crosshairs challenges but apparently there is some sort of image limit. Yay.
This is certainly not the "sexy"
part of the CTF, it's nothing new and exciting but worst case scenario somebody
learns something.
The forensics challenge began with downloading what appeared to be a modified copy of SANS SIFT with two files on the desktop that were of immediate interest.
The forensics challenge began with downloading what appeared to be a modified copy of SANS SIFT with two files on the desktop that were of immediate interest.
After poking around aimlessly in
wireshark just looking for anything of interest I pulled up the first
challenge.

Note: The level of ease denoted next
to each challenge is that of which the organizers determined.
Note: Answering these to the best of
my ability... did a wr erase on mem nearly immediately after answering.
Crosshairs 1 (Easy):
The answer really just depended on
what your definition of attack is... if you include recon in your definition
then the timestamp we are looking for will be found in the first packet of the
pcap.
The answer would then be
"2013-02-08 17:45:08".
No comments:
Post a Comment