<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1994500777340825026</id><updated>2011-11-25T05:43:45.487-08:00</updated><title type='text'>Don't Panic Tech</title><subtitle type='html'>Random stuff from @crucialcarl</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-1337728307112751910</id><published>2011-08-28T19:58:00.005-07:00</published><updated>2011-08-28T19:58:58.201-07:00</updated><title type='text'>Defcon 19 Packet Challenge - Level 6</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:OfficeDocumentSettings&gt;   &lt;o:AllowPNG/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */ table.MsoNormalTable	{mso-style-name:"Table Normal";	mso-tstyle-rowband-size:0;	mso-tstyle-colband-size:0;	mso-style-noshow:yes;	mso-style-priority:99;	mso-style-parent:"";	mso-padding-alt:0in 5.4pt 0in 5.4pt;	mso-para-margin-top:0in;	mso-para-margin-right:0in;	mso-para-margin-bottom:10.0pt;	mso-para-margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;The last ingredient is stored away in Dr. Creedence Clearwater's private Truecrypt volume. On his hard drive there was a file titled "cipher". Perhaps it contains a clue that you can use to unlock the volume and help Inter0ptic find out the last ingredient.&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;1)&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;What is the final ingredient?&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;This one took a short while to figure out what the cipher.txt was telling us.&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;chester@bluestem:~/DRILL$ cat cipher.txt&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;1-2&lt;span&gt;&amp;nbsp; &lt;/span&gt;5-1 3-8 4-1 1-3 2-3 1-1 3-5 5-5 4-7&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;It not-so-quickly dawned on me that the first number in each pair was 1-5, and we had 5 previous answers.&lt;span&gt;&amp;nbsp; &lt;/span&gt;So, the second number must be which character from the previous passwords to use.&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;After working that out, the answer was found to be: 00gmu1rt#?&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Using that key to open the Truecrypt volume, you find a file named “133t pill” with the following message:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Dear Inter0ptic, &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;If you are reading this message, then you must have escaped. Congrats. You didn't think that I was going to let you have the ingredients to the 133t pill, did you? As you have probably guessed, I obtained the creditcard numbers and the ingredients of the 133t pill myself, and sold them for a very nice profit. &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Just in case you are curious, the missing ingredient for the 133t pill was "2oz Vodka." &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;It was great workin with you, my pawn. &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;XOXO,&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Ann&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;And so the final answer is “20z Vodka”&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-1337728307112751910?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/1337728307112751910/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-6.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/1337728307112751910'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/1337728307112751910'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-6.html' title='Defcon 19 Packet Challenge - Level 6'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-1541590385047951531</id><published>2011-08-28T19:58:00.003-07:00</published><updated>2011-08-28T19:58:33.097-07:00</updated><title type='text'>Defcon 19 Packet Challenge - Level 5</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:OfficeDocumentSettings&gt;   &lt;o:AllowPNG/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */ table.MsoNormalTable	{mso-style-name:"Table Normal";	mso-tstyle-rowband-size:0;	mso-tstyle-colband-size:0;	mso-style-noshow:yes;	mso-style-priority:99;	mso-style-parent:"";	mso-padding-alt:0in 5.4pt 0in 5.4pt;	mso-para-margin-top:0in;	mso-para-margin-right:0in;	mso-para-margin-bottom:10.0pt;	mso-para-margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;The network at Factory-Made-Winning had been acting strange all day and Tim was getting very concerned what was happening at his company. He began looking over some traffic.... &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Use the packet capture in this folder to help Tim find out what's happening:&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;1)&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;What is the 3rd ingredient on the list from the mysterious file that was transfered?&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;This is pretty much the same process as the last challenge.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The only difference is a new file.&lt;span&gt;&amp;nbsp; &lt;/span&gt;In this case the file is “\ingredients-list-133t-pi11.7z”.&lt;span&gt;&amp;nbsp; &lt;/span&gt;This time the password is the word that the attacker found on a sticky note : useonce@.&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/05$ &lt;/b&gt;tcpdump -s0 -r Evidence05.pcap -w SMB.cap port 445&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/05$ &lt;/b&gt;tshark -r SMB.cap | grep "Create AndX Request"&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;12&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;0.007632&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path: \srvsvc&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;39&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;3.045251&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path:&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;44&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;3.060912&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path: \desktop.ini&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;47&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;3.062061&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path:&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;66&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.659435&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path: \Thumbs.db&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;69&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;8.996870&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path:&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;73&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;9.002135&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path: &lt;b&gt;\ingredients-list-133t-pi11.7z&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/05$ &lt;/b&gt;tcpxtract -c /etc/tcpxtract.conf -f SMB.cap&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Found file of type "p7z" in session [172.30.1.214:48385 -&amp;gt; 172.30.1.90:25280], exporting to 00000000.p7z&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Opening the file, you can find the password : 8.4 oz- Red Bull&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-1541590385047951531?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/1541590385047951531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-5.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/1541590385047951531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/1541590385047951531'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-5.html' title='Defcon 19 Packet Challenge - Level 5'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-7694447253826143790</id><published>2011-08-28T19:58:00.001-07:00</published><updated>2011-08-28T19:58:01.644-07:00</updated><title type='text'>Defcon 19 Packet Challenge - Level 4</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:OfficeDocumentSettings&gt;   &lt;o:AllowPNG/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */ table.MsoNormalTable	{mso-style-name:"Table Normal";	mso-tstyle-rowband-size:0;	mso-tstyle-colband-size:0;	mso-style-noshow:yes;	mso-style-priority:99;	mso-style-parent:"";	mso-padding-alt:0in 5.4pt 0in 5.4pt;	mso-para-margin-top:0in;	mso-para-margin-right:0in;	mso-para-margin-bottom:10.0pt;	mso-para-margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;Inter0ptic arrived to Factory-Made-Winning, and casually made his way past the front security desk. He then slipped into a secure access area by tailgating behind an employee. On the way in he found a sticky note with a password on it "useonce@". The password might come in handy later! With a grin and a chuckle, Inter0ptic found an empty cubical and plugged in his laptop. &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Use the packet capture in this folder to learn more about Inter0ptic's adventure at the pharmaceutical company and answer the question below: &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;What is the 16th name inside the mysterious file transfered?&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Very early in the pcap you will notice some SMB traffic.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I started there. First I created a new pcap with only the port 445 traffic.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Then I ran it through tshark to decode and see what we could find.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I found a file name CCfiles.7z.&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~/DRILL/04$&lt;/b&gt; tcpdump -s0 -r Evidence04.pcap -w SMB.cap port 445&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;reading from file Evidence04.pcap, link-type EN10MB (Ethernet)&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/04$&lt;/b&gt; tshark –r SMB.cap&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;48&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.157845 172.30.1.214 -&amp;gt; 172.30.1.90&lt;span&gt;&amp;nbsp; &lt;/span&gt;SMB NT Create AndX Response, FID: 0x8003&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;49&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.158411&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB Close Request, FID: 0x8003&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;50&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.158476 172.30.1.214 -&amp;gt; 172.30.1.90&lt;span&gt;&amp;nbsp; &lt;/span&gt;SMB Close Response, FID: 0x8003&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;51&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.163547&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB NT Create AndX Request, Path: \CCfiles.7z&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;52&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.163652 172.30.1.214 -&amp;gt; 172.30.1.90&lt;span&gt;&amp;nbsp; &lt;/span&gt;SMB NT Create AndX Response, FID: 0x8004&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;53&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;6.163945&lt;span&gt;&amp;nbsp; &lt;/span&gt;172.30.1.90 -&amp;gt; 172.30.1.214 SMB Trans2 Request, QUERY_FILE_INFO, FID: 0x8004, Query File Internal Info&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;This time we’ll use tcpxtract by Nick Harbour. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/04$&lt;/b&gt; cat /etc/tcpxtract.conf&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;p7z(5000000, \x37\x7a\xbc\xaf\x27\x1c);&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/04$&lt;/b&gt; tcpxtract -c /etc/tcpxtract.conf -f SMB.cap&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Found file of type "p7z" in session [172.30.1.214:48385 -&amp;gt; 172.30.1.90:4032], exporting to 00000000.p7z&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;I tried to decompress the 7zip with p7zip, but I got unsupported method error.&lt;span&gt;&amp;nbsp; &lt;/span&gt;It appears to be due to a password protection on the file.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I copied the file over to windows and used 7zip there to decompress.&lt;span&gt;&amp;nbsp; &lt;/span&gt;It opened fine there and prompted me for a password.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I first tried useonce@ but failed.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Then I tried Romulus password from challenge 3 and it was correct. &lt;span&gt;&amp;nbsp;&lt;/span&gt;Inside is an xls file.&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;chester@bluestem:~/DRILL/04$&lt;/b&gt; p7zip -d 00000000.p7z&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;7-Zip (A) 9.04 beta&lt;span&gt;&amp;nbsp; &lt;/span&gt;Copyright (c) 1999-2009 Igor Pavlov&lt;span&gt;&amp;nbsp; &lt;/span&gt;2009-05-30&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;p7zip Version 9.04 (locale=en_US.UTF-8,Utf16=on,HugeFiles=on,1 CPU)&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Processing archive: 00000000.p7z&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Extracting&lt;span&gt;&amp;nbsp; &lt;/span&gt;CCfiles.xlsx&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Unsupported Method&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Sub items Errors: 1&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Scrolling down to the 16&lt;sup&gt;th&lt;/sup&gt; line inside the XLS file, you get the answer: &lt;b&gt;Jason Wilson&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-7694447253826143790?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/7694447253826143790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-4.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/7694447253826143790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/7694447253826143790'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-4.html' title='Defcon 19 Packet Challenge - Level 4'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-827454137479038808</id><published>2011-08-28T19:57:00.001-07:00</published><updated>2011-08-28T19:57:31.515-07:00</updated><title type='text'>Defcon 19 Packet Challenge - Level 3</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:OfficeDocumentSettings&gt;   &lt;o:AllowPNG/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:EnableOpenTypeKerning/&gt;    &lt;w:DontFlipMirrorIndents/&gt;    &lt;w:OverrideTableStyleHps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt; /* Style Definitions */ table.MsoNormalTable	{mso-style-name:"Table Normal";	mso-tstyle-rowband-size:0;	mso-tstyle-colband-size:0;	mso-style-noshow:yes;	mso-style-priority:99;	mso-style-parent:"";	mso-padding-alt:0in 5.4pt 0in 5.4pt;	mso-para-margin-top:0in;	mso-para-margin-right:0in;	mso-para-margin-bottom:10.0pt;	mso-para-margin-left:0in;	line-height:115%;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:"Calibri","sans-serif";	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;A mysterious call is made to Romulus (a new accounts manager) at Factory-Made-Winning. &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Use the packet capture in this folder to learn more about the phone call and answer the following question: &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;span&gt;&lt;span&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;What is Romulus' password?&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;I opened the pcap in Wireshark first, but it did not identify any voip converstaions.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I then tried xplico:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$&lt;/b&gt; ./xplico -m pcap -f /home/chester/DRILL/Evidence03.pcap&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;xplico v0.6.3&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Internet Traffic Decoder (NFAT).&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;&lt;snip&gt;&lt;/snip&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Cap. time: Thu Jun 23 13:40:49 2011&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Total elaboration time: 4s&lt;span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;&lt;snip&gt;&lt;/snip&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;ls xdecode/172.30.1.101/http/74.125.224.116&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;http_rs_body_1314482374_0xa51a2a8_1&lt;span&gt;&amp;nbsp; &lt;/span&gt;post&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$&lt;/b&gt; cat http_rs_body_1314482374_0xa51a2a8_1&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;relay.ip=74.125.127.126&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;relay.udp_port=19295&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;relay.tcp_port=19294&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;relay.ssltcp_port=443&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;stun.ip=74.125.127.126&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;stun.port=19302&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;username=1ZUfriXYKVltcU72&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;password=IyUDFIcH1JL8Ho8N&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;magic_cookie=rÆKÆ&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Not a smoking gun, but the ip 74.125.127.126 is owned by google, so we’re probably looking at googlechat voip call.&lt;span&gt;&amp;nbsp; &lt;/span&gt;After some searching I found that xplico can take advantage of a tool called videosnarf to decode VOIP calls.&lt;span&gt;&amp;nbsp; &lt;/span&gt;I set up this tool and ran it on its own.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$&lt;/b&gt; videosnarf -i Evidence03.pcap&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;added new stream. :172.30.1.101(56213) to 74.125.127.126(19295). codec is 00&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;added new stream. :74.125.127.126(19295) to 172.30.1.101(56213). codec is 00&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;[+]Stream saved to file G711ULAW-media-1.wav&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;[+]Stream saved to file G711ULAW-media-2.wav&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;snip&gt; &lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Bingo.&lt;span&gt;&amp;nbsp; &lt;/span&gt;If you listen to the G711ULAW wav files, you can hear both sides of a staged social-engineering call to Romulus.&lt;span&gt;&amp;nbsp; &lt;/span&gt;He willingly gives over his password to the caller.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Answer:&lt;span&gt;&amp;nbsp; &lt;/span&gt;rom127#&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-827454137479038808?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/827454137479038808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-3.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/827454137479038808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/827454137479038808'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenge-level-3.html' title='Defcon 19 Packet Challenge - Level 3'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-8478246357756206554</id><published>2011-08-28T19:56:00.000-07:00</published><updated>2011-08-28T20:07:44.100-07:00</updated><title type='text'>Defcon 19 Packet Challenges - Level 2</title><content type='html'>&lt;div class="MsoNormal"&gt;Ann, afraid that someone may be watching her, decides to capture all of her home traffic. She mentions her fear to Mr. X and explains that she has been capturing her home traffic for days and will be sending the packets out for analysis later in the day. She sends her captures to the one person she knows can trust. After their discussion, Mr. X rushes to his lab, to see if he can intercept Ann's outbound message and use her capture to get more detail on her upcoming activities.. &lt;/div&gt;&lt;div class="MsoListParagraph" style="text-indent: -0.25in;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;What is the date, as it appears in the capture, of the cryptographer's speaking engagement? (hint: It isn't at Defcon)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="color: red;"&gt;This one was slightly more difficult.&amp;nbsp; The scenario says Mr X. is trying to capture Ann’s message, so I went looking for emails. First I used tcpflow to dump all the network conversations into separate files. This probably could have been easier by using NetworkMiner or NetWitness, but I preferred to work on these on a Linux shell.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&lt;i&gt;&lt;span style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;tcpflow -r Evidence02.pcap&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="color: red;"&gt;Then I searched for the word “Subject” in the resulting files, since that should be in any Email.&amp;nbsp; One hit stood out: &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;grep -a Subject *&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;172.030.001.100.51805-205.188.192.001.00080:&amp;nbsp;&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;From":"ann1smysterious@aol.com","To":"d_tangent@aol.com,","Cc":"","Bcc":"","&lt;span style="color: red;"&gt;Subject&lt;/span&gt;":"My Trusted Friend","RichBody":"You are the only one that I can trust.&amp;nbsp; I need to know if someone monitoring me.&amp;nbsp; Attached is a capture of my traffic&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&amp;nbsp;  &lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;As the scenario said, Ann sent a pcap to a person she could trust.&amp;nbsp; Let’s get that pcap.&amp;nbsp; Using foremost, the magic number for a pcap is 0xd4c3b2a1. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;cat /etc/foremost.conf&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;pcap n&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5000000 \xd4\xc3\xb2\xa1&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;foremost -c /etc/foremost.conf -i 172.030.001.100.51805-205.188.192.001.00080&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Processing: 172.030.001.100.51805-205.188.192.001.00080&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;|*|&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;file output/pcap/00000030.pcap&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;output/pcap/00000030.pcap: tcpdump capture file (little-endian) - version 2.4 (Ethernet, capture length 65535)&amp;nbsp; &lt;span style="color: red;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;This is the Help.pcap plus some extra data on the end, since we didn’t specify a specific file size.&amp;nbsp; Tcpdump will still parse the file.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;A quick look around this cap and we see the site of a well-known cryptographer (remember we are looking for the date of a cryptographer’s speaking engagement).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;tcpdump -nn -r Help.pcap -A -s0 port 80 | grep Host | sort | uniq&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;snip&gt;&lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;Host: www.schneier.com&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;snip&gt;&lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Looking at the pcap, we determine the IP of schneier.com to be 204.11.246.48, so we can focus on that.&amp;nbsp; Once again, tcpflow to break up this pcap into parse-friendly conversations.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;tcpflow -r Help.pcap host 204.11.246.48&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;grep GET *&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;snip&gt;&lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;172.030.001.100.60176-204.011.246.048.00080:GET /schedule.html HTTP/1.1&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;snip&gt;&lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Looks promising.&amp;nbsp; So, we’ll use the other half of this file that matches this request to get the response.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;carl@bluestem:~$ head 204.011.246.048.00080-172.030.001.100.60176&amp;nbsp; &lt;span style="color: red;"&gt;(server response)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;HTTP/1.1 200 OK&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Date: Wed, 22 Jun 2011 21:05:31 GMT&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Server: Apache&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Vary: User-Agent,Accept-Encoding&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Last-Modified: Tue, 17 May 2011 01:51:36 GMT&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;ETag: "e78-4a36f03207a00"&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Accept-Ranges: none&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Content-Encoding: gzip&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Gzipped data.&amp;nbsp; So we’ll use foremost again to carve the gzip file. &amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$&lt;/b&gt; cat /etc/foremost.conf&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;gz n 50000 \x1f\x8b&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;foremost -c /etc/foremost.conf -i 204.011.246.048.00080-172.030.001.100.60176&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Processing: 204.011.246.048.00080-172.030.001.100.60176&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;|*|&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;b&gt;carl@bluestem:~$ &lt;/b&gt;&amp;nbsp;file output/gzip/00000000.gzip&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;output/gzip/00000000.gzip: gzip compressed data, from Unix&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Gunzip it and inside we have an HTML file.&amp;nbsp; And searching the html file, we find: &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Global AppSec Latin America 2011 Conference&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;October 6-7, 2011&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;Keynote&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNoSpacing"&gt;&lt;span style="color: red;"&gt;Answer: October 6-7, 2011&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoNoSpacing"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-8478246357756206554?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/8478246357756206554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenges-level-2.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/8478246357756206554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/8478246357756206554'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenges-level-2.html' title='Defcon 19 Packet Challenges - Level 2'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-632741189347338459</id><published>2011-08-28T19:50:00.000-07:00</published><updated>2011-08-28T20:00:45.897-07:00</updated><title type='text'>Defcon 19 Packet Challenges - Level 1</title><content type='html'>The challenges can be found here: &lt;a href="http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011"&gt;http://forensicscontest.com/2011/08/16/puzzle-9-anns-deception-defcon-2011&lt;/a&gt;&amp;nbsp; THERE ARE SPOILERS ON THIS PAGE. &lt;br /&gt;&lt;br /&gt;I didn't attempt these challenges while at the conference, but I finally sat down to do them this weekend. &amp;nbsp;They were pretty straightforward and didn't give me too many WTF moments. &amp;nbsp;I intentionally used Linux tools and avoided some tools that could have made this challenge very easy, namely NetworkMiner and Netwitness. &amp;nbsp;These are both great tools but I wanted to get some practice with a few others. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;After Mr. X learns that Ann has been in contact with Inter0ptic, he begins to wonder about their relationship, and decides to monitor Ann's network traffic. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;1. What is the name of the Company being attacked?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="color: red;"&gt;This one is an easy one.&amp;nbsp; Luckily I picked the word “company” pretty early in my guessing and came to the answer quickly.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;carl@bluestem:~$ strings Evidence01.pcap | grep -i company&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;snip&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;nt-size%3A%2010pt%3B%20color%3A%20black%3B%5C%22%3E-----Original%20Message-----%3Cbr%3E%5CnFrom%3A%20Ann%20Imal%20%26lt%3Bann1smysterious%40aol.com%26gt%3B%3Cbr%3E%5CnTo%3A%20inter0pticon%20%26lt%3Binter0pticon%40aol.com%26gt%3B%3Cbr%3E%5CnSent%3A%20Fri%2C%20Jul%2015%2C%202011%202%3A45%20pm%3Cbr%3E%5CnSubject%3A%20Re%3A%20Tip%3Cbr%3E%5Cn%3Cbr%3E%5Cn%5Cn%5Cn%5Cn%5Cn%5Cn%5Cn%3Cdiv%20id%3D%5C%22AOLMsgPart_1_e7a3f7f4-b5d1-49c1-b77e-d4d8f5388d6c%5C%22%3E%5Cn%5Cn%3Cfont%20color%3D%5C%22black%5C%22%20face%3D%5C%22arial%5C%22%20size%3D%5C%222%5C%22%3E%3Cfont%20color%3D%5C%22black%5C%22%20face%3D%5C%22arial%5C%22%20size%3D%5C%222%5C%22%3E%5Cn%5Cn%5Cn%3Cdiv%3E%20%3Cbr%3E%5Cn%5Cn%5Cn%3C%2Fdiv%3E%5Cn%5Cn%5Cn%5Cn%5Cn%5Cn%3Cdiv%3E%20%3Cfont%20color%3D%5C%22black%5C%22%20face%3D%5C%22arial%5C%22%20size%3D%5C%222%5C%22%3E%3Cfont%20size%3D%5C%222%5C%22%3E%3Cfont%20face%3D%5C%22Arial%2C%20Helvetica%2C%20sans-serif%5C%22%3ENext%5Cn%20week%2C%20you%20will%20travel%20to%20Metropia%2C%20where%20%&lt;span style="color: red;"&gt;5Cn&lt;b&gt;Factory-Made-Winning-Pharmaceuticals&lt;/b&gt;&lt;/span&gt;%20is%20headquartered.%26nbsp%3B%20You%20will%20break%20%5Cninto%20the%20&lt;b&gt;&lt;span style="color: red;"&gt;company&lt;/span&gt;&lt;/b&gt;'s%20customer%20credit%20card%20database%20and%20retrieve%20the%20card%20%5Cnnumbers.%26nbsp%3B%20%3Cbr%3E%5Cn%5Cn%5Cn%3Cbr%3E%5Cn%5Cn%5CnAnn%3C%2Ffont%3E%3C%2Ffont%3E%3C%2Ffont%3E%5Cn%3C%2Fdiv%3E%5Cn%5Cn%5Cn%5Cn%5Cn%5Cn%3Cdiv%20style%3D%5C%22clear%3A%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;snip&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/snip&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="color: red;"&gt;Answer: Factory-Made-Winning-Pharmaceuticals&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-632741189347338459?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/632741189347338459/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenges-level-1.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/632741189347338459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/632741189347338459'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/08/defcon-19-packet-challenges-level-1.html' title='Defcon 19 Packet Challenges - Level 1'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-4715777910055521125</id><published>2011-02-21T13:20:00.000-08:00</published><updated>2011-02-21T13:20:48.572-08:00</updated><title type='text'>Ghostintheshellcode Stage 14 TootsieRoll Packet 175 pts</title><content type='html'>Stage 14&lt;br /&gt;Question: TootsieRoll&lt;br /&gt;175 Points&lt;br /&gt;What is the password? &lt;br /&gt;&lt;br /&gt;File: tootsieroll-4fafc83198440078a616080e3d44419c&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ file tootsieroll-4fafc83198440078a616080e3d44419c&lt;br /&gt;tootsieroll-4fafc83198440078a616080e3d44419c: tcpdump capture file (little-endian) - version 2.4 (Ethernet, capture length 65535)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Dump the payloads with tcpflow:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ tcpflow -r tootsieroll-4fafc83198440078a616080e3d44419c&lt;br /&gt;carl@b:~/tootsie$ ls -al&lt;br /&gt;-rw-r--r--&amp;nbsp; 1 carl carl&amp;nbsp;&amp;nbsp; 180 2011-02-21 16:20 127.000.000.001.01337-127.000.000.001.50451&lt;br /&gt;-rw-r--r--&amp;nbsp; 1 carl carl&amp;nbsp;&amp;nbsp; 676 2011-02-21 16:20 127.000.000.001.50451-127.000.000.001.01337&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ file 127*&lt;br /&gt;127.000.000.001.01337-127.000.000.001.50451: ASCII text, with no line terminators&lt;br /&gt;127.000.000.001.50451-127.000.000.001.01337: ASCII text, with very long lines, with no line terminators&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ more 127.000.000.001.01337-127.000.000.001.50451&lt;br /&gt;WGB6bWljNw==UWd9KHxgYWZjKHxgbXEvem0ob2dhZm8ofGcoan17fCh9ezc=XGBtKHhpe3t/Z3psKHxgaXwoe3xpenx7KH9hfGAoNGNtcTZdO0pkUTpkYGpLSkpS&lt;br /&gt;Ol59bEs0J2NtcTYkKGp9fChhKG5nem9nfCh8YG0oem17fDc=R2YoYXwp&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ more 127.000.000.001.50451-127.000.000.001.01337&lt;br /&gt;R2p2Iy9meyh8L2JqIQ==RihiL2l9am5kZmFoLi9FYGp2L3hufGEoey9ibmRmYWgvZnsven8uL0dqL31qbmNjdi9nbmxkamsvZmF7YC9KY2NmYWh8YGEuL0dqL2hu&lt;br /&gt;eWovYmove2dqL2tmfGwveGZ7Zy9uL2lmY2ovZ2ovbGB/ZmprL25hay9hYHgvRihiL2ZhL2VuZmMuL1tnanYofWovbGdufWhmYWgvYmoveGZ7Zy98YGJqL3xqfWZg&lt;br /&gt;enwvfGdmey4vTmFrL3tnan1qKHwvfHt6aWkvRi9rZmthKHsvanlqYS9rYCMvY2Zkai9mYXxqfXtmYWgvfGBiai95Zn16fC9sbmNjamsvS24vWWZhbGYjL25hay97&lt;br /&gt;Z2p2L2Rqan8vbnxkZmFoL25tYHp7L3Zgei9oenZ8IQ==VmpuZy4vVmB6L21qe3tqfS9pZmh6fWovYHp7L3hnbnsofC9gYS97Z257L2tmfGwjL2xuenxqL3hqKH1q&lt;br /&gt;L21qZmFoL2l9bmJqayEvRnsofC9mYS97Z257L39jbmxqL3hnan1qL0Yvf3p7L3tnbnsve2dmYWgve2duey97ZmJqL3hme2cve2duey9/bnx8eGB9ay4=S3pnIy9m&lt;br /&gt;ey9qYWt8L3hme2c1LzNkanYxTnZCW0Z7QVtaPkNbZD9AW14yMyBkanYx&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Looks like base64:&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ cat 127.000.000.001.50451-127.000.000.001.01337 | base64 -d&lt;br /&gt;Gjv#/f{(|/bj!F(b/i}jndfah./E`jv/xn|a({/bndfah/f{/./Gj/}jnccv/gnldjk/fa{`/Jccfah|`a./Gj/hnyj/bj/{gj/kf|l/xf{g/n/ifcj/gj/lfjk/nak/a`x/F(b/fa/enfc./[gjv(}j/lgn}hfah/bj/xf{g/|`bj/|j}f`z|/|gf{./Nak/{gj}j(|/|{zii/F/kfka({/jyja/k`#/cfdj/fa|j}{fah/|`bj/yf}z|/lnccjk/Kn/Yfalf#/nak/{gjv/dj/n|dfah/nm`z{/v`z/hzv|!Vjng./V`z/mj{{j}/ifhz}j/`z{/xgn{(|/`a/{gn{/kf|l#/lnz|j/xj(}j/mjfah/i}nbjk!/F{(|/fa/{gn{cnlj/xgj}j/Fz{/{gn{/{gfah/{gn{/{fbj/xf{g/{gn{n||x`}k.Kzg#/f{/jak|/xf{g5/3djv1NvB[F{A[Z&amp;gt;C[d?@[^23 djv1carl@b:~/tootsie$ cat 12ls -al^C&lt;br /&gt;carl@b:~/tootsie$ cat 127.000.000.001.01337-127.000.000.001.50451 | base64 -d&lt;br /&gt;X`zmic7Qg}(|`afc(|`mq/zm(ogafo(|g(j}{|(}{7\`m(xi{gzl(|`i|({|iz|{a|`(4cmq6];JdQ:d`jKJJR:^}lK4'cmq6$(j}|(a(ngzog|(|`m(zm{|7Gf(a|)carl@b:~/tootsie$ cat 127.000.000.001.50451-127.000.000.001.01337 | base64 -d &amp;gt; file.out&lt;br /&gt;carl@b:~/tootsie$ cat 127.000.000.001.01337-127.000.000.001.50451 | base64 -d &amp;gt; file2.out&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;XOR is pretty common.&amp;nbsp; Didier Stevens tool XORSearch makes it easy to look for text that might be XORed.&amp;nbsp; You can find it here: http://blog.didierstevens.com/programs/xorsearch/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;The word "pass" was a lucky first guess:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ xorsearch file.out pass&lt;br /&gt;Found XOR 0F position 01BD: password!Duh, it ends with: &lt;key&gt;AyMTItNTU1LTk0OTQ&lt;br /&gt;carl@b:~/tootsie$ xorsearch file2.out pass&lt;br /&gt;Found XOR 08 position 002E: password that starts with &lt;key&gt;U3BlY2lhbCBBZ2VudC&amp;lt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Cat those two strings together and you get a base64 encoded string that you can decode:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/tootsie$ echo "U3BlY2lhbCBBZ2VudCAyMTItNTU1LTk0OTQ" | base64 -d&lt;br /&gt;Special Agent 212-555-9494&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;The key is "Special Agent 212-555-9494"&lt;/span&gt;&lt;br /&gt;&lt;/key&gt;&lt;/key&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-4715777910055521125?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/4715777910055521125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-14.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/4715777910055521125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/4715777910055521125'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-14.html' title='Ghostintheshellcode Stage 14 TootsieRoll Packet 175 pts'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-7413420775234795895</id><published>2011-02-21T13:09:00.000-08:00</published><updated>2011-02-21T13:09:04.652-08:00</updated><title type='text'>Ghostintheshellcode  Stage 1  apd  Forensics 100pts</title><content type='html'>Stage 1&lt;br /&gt;Question: apd&lt;br /&gt;100 Points&lt;br /&gt;&lt;br /&gt;Who?&lt;br /&gt;File:apd-d54c4e84df46239dd&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ file apd-d54c4e84df46239ddd453f19909468c3&lt;br /&gt;apd-d54c4e84df46239ddd453f19909468c3: gzip compressed data, from Unix, last modified: Sun Dec 26 14:06:22 2010&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ tar zxf apd-d54c4e84df46239ddd453f19909468c3&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ ls -al | more&lt;br /&gt;total 9668&lt;br /&gt;drwxr-xr-x 2 carl carl&amp;nbsp;&amp;nbsp; 20480 2011-02-21 15:36 .&lt;br /&gt;drwxr-xr-x 3 carl carl&amp;nbsp;&amp;nbsp; 20480 2011-02-21 15:34 ..&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19354 2010-12-26 14:06 0002abbac6e704c7196509c2bdfc61c6&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19772 2010-12-26 14:06 01149038c6aac54204c2850f5f8104c9&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19772 2010-12-26 14:06 01bf66971ba7601dc9bd99b2e9c38c90&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19354 2010-12-26 14:06 023326ab4a8cbcc4494485bb2d4997c9&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19355 2010-12-26 14:06 0390f811e8ed5846d3cac7f8b4c8ad23&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19772 2010-12-26 14:06 03ced4264f06a6e2a35e5fa950bece65&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19354 2010-12-26 14:06 04869a26051364f0c308eefd562ab8e4&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19354 2010-12-26 14:06 06966a475ca30d06421f1e662dad4fda&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19354 2010-12-26 14:06 08bf0534c5168bfc2e020269e90bf9b3&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19355 2010-12-26 14:06 09aa52fff54918a33c397e44efcf4339&lt;br /&gt;-rw-r--r-- 1 carl carl&amp;nbsp;&amp;nbsp; 19354 2010-12-26 14:06 09ed6bd70d00ef97e6a4c8bc89249613&lt;br /&gt;&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;MP3s.. rock out!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ file *&lt;br /&gt;0002abbac6e704c7196509c2bdfc61c6:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;01149038c6aac54204c2850f5f8104c9:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;01bf66971ba7601dc9bd99b2e9c38c90:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;023326ab4a8cbcc4494485bb2d4997c9:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;0390f811e8ed5846d3cac7f8b4c8ad23:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;03ced4264f06a6e2a35e5fa950bece65:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;04869a26051364f0c308eefd562ab8e4:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;06966a475ca30d06421f1e662dad4fda:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;08bf0534c5168bfc2e020269e90bf9b3:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;09aa52fff54918a33c397e44efcf4339:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;09ed6bd70d00ef97e6a4c8bc89249613:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;0bfc1634806148c28b7a375b85b95e44:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, Stereo&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;So obviously we had a bunch of really short mp3s.&amp;nbsp; It was obvious they were spliced up from the same sample.&amp;nbsp; So, we had to reconstruct them. Lets check the metadata:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ exiftool 107deef8d71148a6f2d27d82918fd5fe&lt;br /&gt;ExifTool Version Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 8.15&lt;br /&gt;File Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 107deef8d71148a6f2d27d82918fd5fe&lt;br /&gt;Directory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : .&lt;br /&gt;File Size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 19 kB&lt;br /&gt;File Modification Date/Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2010:12:26 14:06:20-05:00&lt;br /&gt;File Permissions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : rw-r--r--&lt;br /&gt;File Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : MP3&lt;br /&gt;MIME Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : audio/mpeg&lt;br /&gt;MPEG Audio Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&lt;br /&gt;Audio Layer&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3&lt;br /&gt;Audio Bitrate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 128000&lt;br /&gt;Sample Rate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 44100&lt;br /&gt;Channel Mode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Stereo&lt;br /&gt;MS Stereo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Off&lt;br /&gt;Intensity Stereo&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Off&lt;br /&gt;Copyright Flag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : False&lt;br /&gt;Original Media&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : True&lt;br /&gt;Emphasis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : None&lt;br /&gt;ID3 Size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 128&lt;br /&gt;Title&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2hvc3RJblRoZVNoZWxsY29kZSAK&lt;br /&gt;Artist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : VElNRTogMTQ6MDY6MjAK&lt;br /&gt;Album&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : V2UgYXJlIHdhdGNoaW5nIHlvdSAK&lt;br /&gt;Year:&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0wNDUK&lt;br /&gt;Genre&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : None&lt;br /&gt;Date/Time Original&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;br /&gt;Duration&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.20 s (approx)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Title, Artist, Album and Comment are all encoded.&amp;nbsp; They happen to be base64. Looking at all of the files, the Title and Album are the same.&amp;nbsp; The artist varies only slightly.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ exiftool * | grep Title | sort | uniq -c&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 250 Title&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2hvc3RJblRoZVNoZWxsY29kZSAK&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ echo "R2hvc3RJblRoZVNoZWxsY29kZSAK" | base64 -d&lt;br /&gt;GhostInTheShellcode&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ exiftool * | grep Album | sort | uniq -c&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 250 Album&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : V2UgYXJlIHdhdGNoaW5nIHlvdSAK&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ echo "V2UgYXJlIHdhdGNoaW5nIHlvdSAK" | base64 -d&lt;br /&gt;We are watching you&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ exiftool * | grep Artist | sort | uniq -c&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 91 Artist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : VElNRTogMTQ6MDY6MjAK&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 94 Artist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : VElNRTogMTQ6MDY6MjEK&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 22 Artist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : VElNRTogMTQ6MDY6MjIK&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 43 Artist&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : VElNRTogMTQ6MDY6MTkK&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ echo "VElNRTogMTQ6MDY6MjAK" | base64 -d&lt;br /&gt;TIME: 14:06:20&lt;br /&gt;carl@b:~/apd/$ echo "VElNRTogMTQ6MDY6MjEK" | base64 -d&lt;br /&gt;TIME: 14:06:21&lt;br /&gt;carl@b:~/apd/$ echo "VElNRTogMTQ6MDY6MjIK" | base64 -d&lt;br /&gt;TIME: 14:06:22&lt;br /&gt;carl@b:~/apd/$ echo "VElNRTogMTQ6MDY6MTkK" | base64 -d&lt;br /&gt;TIME: 14:06:19&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Though the comments are all different:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ for i in `ls`; do exiftool $i | grep Comment; done&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0wNTcK&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0wMjEK&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0yMDAK&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0wNDMK&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0yNDEK&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0wNTkK&lt;br /&gt;Comment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : R2l0cy0wODQK&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ for i in `ls`; do exiftool $i | grep Comment | awk '{print $3}' ; done&lt;br /&gt;R2l0cy0wNTcK&lt;br /&gt;R2l0cy0wMjEK&lt;br /&gt;R2l0cy0yMDAK&lt;br /&gt;R2l0cy0wNDMK&lt;br /&gt;R2l0cy0yNDEK&lt;br /&gt;R2l0cy0wNTkK&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Decode the comments and we get some numbers that we can sort:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ for i in `ls`; do exiftool $i | grep Comment | awk '{print $3}' |base64 -d&amp;nbsp; ; done&lt;br /&gt;Gits-057&lt;br /&gt;Gits-021&lt;br /&gt;Gits-200&lt;br /&gt;Gits-043&lt;br /&gt;Gits-241&lt;br /&gt;Gits-059&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ for i in `ls`; do mv $i `exiftool $i | grep Comment | awk '{print $3}' |base64 -d `; done&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ ls&lt;br /&gt;Gits-020&amp;nbsp; Gits-040&amp;nbsp; Gits-060&amp;nbsp; Gits-080&amp;nbsp; Gits-100&amp;nbsp; Gits-120&amp;nbsp; Gits-140&amp;nbsp; Gits-160&amp;nbsp; Gits-180&amp;nbsp; Gits-200&amp;nbsp; Gits-220&amp;nbsp; Gits-240&lt;br /&gt;Gits-001&amp;nbsp; Gits-021&amp;nbsp; Gits-041&amp;nbsp; Gits-061&amp;nbsp; Gits-081&amp;nbsp; Gits-101&amp;nbsp; Gits-121&amp;nbsp; Gits-141&amp;nbsp; Gits-161&amp;nbsp; Gits-181&amp;nbsp; Gits-201&amp;nbsp; Gits-221&amp;nbsp; Gits-241&lt;br /&gt;Gits-002&amp;nbsp; Gits-022&amp;nbsp; Gits-042&amp;nbsp; Gits-062&amp;nbsp; Gits-082&amp;nbsp; Gits-102&amp;nbsp; Gits-122&amp;nbsp; Gits-142&amp;nbsp; Gits-162&amp;nbsp; Gits-182&amp;nbsp; Gits-202&amp;nbsp; Gits-222&amp;nbsp; Gits-242&lt;br /&gt;Gits-003&amp;nbsp; Gits-023&amp;nbsp; Gits-043&amp;nbsp; Gits-063&amp;nbsp; Gits-083&amp;nbsp; Gits-103&amp;nbsp; Gits-123&amp;nbsp; Gits-143&amp;nbsp; Gits-163&amp;nbsp; Gits-183&amp;nbsp; Gits-203&amp;nbsp; Gits-223&amp;nbsp; Gits-243&lt;br /&gt;[...]&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;br /&gt;We got stuck here for a minute, but then figured out that you could cat each of these individual mp3s together and end up with a playable mp3. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/apd/$ cat Gits-* &amp;gt; full.mp3&lt;br /&gt;carl@b:~/apd/$ ls -al full.mp3&lt;br /&gt;-rw-r--r-- 1 carl carl 4865279 2011-02-21 16:09 full.mp3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;If you open the song in an mp3 player, you should quickly identify that it is Prodigy - One Love, from the Experience album, and also from the Hackers sound track.&amp;nbsp; If you listen through the song you will get to some dialogue from the movie where Cereal is talking about the Da Vinci virus.&amp;nbsp; At ~ 3:50 you'll hear the quote "The password for this hungry little sucker belongs to Margo Wallace".&amp;nbsp; "Margo Wallace" is repeated a number of times and "Wallace" is distorted.&amp;nbsp; Presumably they wanted us to look up the movie script and confirm.. easy stuff.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Margo Wallace is the key. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-7413420775234795895?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/7413420775234795895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-1-apd.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/7413420775234795895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/7413420775234795895'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-1-apd.html' title='Ghostintheshellcode  Stage 1  apd  Forensics 100pts'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-8990986716411477163</id><published>2011-02-21T12:19:00.000-08:00</published><updated>2011-02-21T12:19:32.729-08:00</updated><title type='text'>Ghostintheshellcode Stage 5 CCTV Forensics 250pts</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-Ky46yzjKoog/TWLHvL7QlQI/AAAAAAAAABY/YSszi1PsQuI/s1600/cctv.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="177" src="http://2.bp.blogspot.com/-Ky46yzjKoog/TWLHvL7QlQI/AAAAAAAAABY/YSszi1PsQuI/s320/cctv.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;Stage 5&lt;br /&gt;Question: cctv&lt;br /&gt;250 Points&lt;br /&gt;File: cctv-88cbfd616c1ce146ca6b738772c10bea&lt;br /&gt;&lt;br /&gt;The CCTV page has 9 animated gifs. Collect them all!&lt;br /&gt;&lt;br /&gt;carl@b:~/cctv$ ls&lt;br /&gt;code.gif&amp;nbsp; davinci.gif&amp;nbsp; destroycard.gif&amp;nbsp; game.gif&amp;nbsp; gibson1.gif&amp;nbsp; gibson2.gif&amp;nbsp; gibson3.gif&amp;nbsp; hops.gif&amp;nbsp; otv.gif&lt;br /&gt;&lt;br /&gt;This took a long time while we tried a bunch of useless ideas. &lt;br /&gt;-All of the gifs were exploded into single frames and each was checked for any watermarks or interesting information. &lt;br /&gt;-We tried to find any hidden data stored between the frames.&amp;nbsp; I hear you can append a zip file to the end of a gif file and each can be opened with native tools. &lt;br /&gt;-Looked for something interesting based on the timing of each frames.&lt;br /&gt;-Loaded them into gimp and noticed the timing was between 0-70ms per frame, which made me think hidden octal numbers, but this was a dead end, for now.&lt;br /&gt;&lt;br /&gt;We massaged each of the files through imagemagick over and over with no results.&amp;nbsp; At one point, I came across this page: http://www.imagemagick.org/discourse-server/viewtopic.php?f=1&amp;amp;t=11988 which led me to look for "ticks".&amp;nbsp; Imagemagick's identify command can show ticks if you use %T. &lt;br /&gt;&lt;br /&gt;carl@b:~/cctv$ info="%T"&lt;br /&gt;carl@b:~/cctv$ identify -format "$info" *.gif&lt;br /&gt;&lt;br /&gt;1531521641211231061411441461531541461521411631460120001101211051441441661701721261011071011061460120014616116414516116410112310410610110614716116414401200001031621411631501451441011561441021651621561451440120014114711010712116114116314414614112413111011014101201461411231071241211041431701411471461611470120000147131121161145141146144163166170147141141147012012114514114114614116314414612110513112210516301214612116414414717112514114416614217210114614614101200&lt;br /&gt;&lt;br /&gt;I'm pretty certain the only reason this looked interesting to me was because I saw the file in gimp earlier and 0-70ms made me think "octal".&amp;nbsp; Otherwise, I probably would have missed it.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;carl@b:~/cctv$ identify -format "$info" *.gif &amp;gt; file.out&lt;br /&gt;carl@b:~/cctv$ more file.out&lt;br /&gt;1531521641211231061411441461531541461521411631460120001101211051441441661701721261011071011061460120014616116414516116410112310410610110614716116414401200001031621411631501451441011561441021651621561451440120014114711010712116114116314414614112413111011014101201461411231071241211041431701411471461611470120000147131121161145141146144163166170147141141147012012114514114114614116314414612110513112210516301214612116414414717112514114416614217210114614614101200&lt;br /&gt;&lt;br /&gt;Break up the string into sets of 3 digits:&lt;br /&gt;&lt;br /&gt;carl@b:~/cctv$ egrep -o "[0-9]{3}" file.out &amp;gt; file2.out&lt;br /&gt;carl@b:~/cctv$ more file2.out&lt;br /&gt;153&lt;br /&gt;152&lt;br /&gt;164&lt;br /&gt;121&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;carl@b:~/cctv$ perl octa -a file2.out&lt;br /&gt;carl@b:~/cctv$ more file2.out.as&lt;br /&gt;kjtQSFadfklfjasf&lt;br /&gt;NULHQEddvxzVAGAFf&lt;br /&gt;SOH&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; !1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1PNULCrashedAndBurned&lt;br /&gt;SOHA9AAPfaSGTQDcxagfqg&lt;br /&gt;NULFFJNLLFFLL))Q&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P&lt;br /&gt;&lt;br /&gt;The key is in octal in the ticks inside game.gif.&amp;nbsp; The key is "CrashedAndBurned".&lt;br /&gt;&lt;br /&gt;The octa file is octala.pl from Mike Golvach: http://linuxshellaccount.blogspot.com/2008/05/perl-script-to-do-lame-encryption-with.html.&amp;nbsp; Thanks to him for his script.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-8990986716411477163?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/8990986716411477163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-5-cctv.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/8990986716411477163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/8990986716411477163'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-5-cctv.html' title='Ghostintheshellcode Stage 5 CCTV Forensics 250pts'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-Ky46yzjKoog/TWLHvL7QlQI/AAAAAAAAABY/YSszi1PsQuI/s72-c/cctv.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-6605657775442328023</id><published>2011-02-21T11:45:00.000-08:00</published><updated>2011-02-21T11:48:09.416-08:00</updated><title type='text'>Ghostintheshellcode  Stage10  Forensics 400 points.</title><content type='html'>Stage 10&lt;br /&gt;Question: Hackerlife&lt;br /&gt;400 Points&lt;br /&gt;&lt;br /&gt;John doesn't see a problem. &lt;br /&gt;&lt;br /&gt;File: hackerlife-0b8724a229d81bbb727d27d735eaca86&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;&lt;b&gt;The file is pretty large by itself.&amp;nbsp; It is a bzipped tarball.&amp;nbsp; Extract it out. &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ file hackerlife-0b8724a229d81bbb727d27d735eaca86&lt;br /&gt;hackerlife-0b8724a229d81bbb727d27d735eaca86: bzip2 compressed data, block size = 900k&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ bunzip2 hackerlife-0b8724a229d81bbb727d27d735eaca86&lt;br /&gt;bunzip2: Can't guess original name for hackerlife-0b8724a229d81bbb727d27d735eaca86 -- using hackerlife-0b8724a229d81bbb727d27d735eaca86.out&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ ls -al&lt;br /&gt;total 73560&lt;br /&gt;drwxr-xr-x&amp;nbsp; 3 carl carl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4096 2011-02-21 11:00 .&lt;br /&gt;drwxr-xr-x 38 carl carl&amp;nbsp;&amp;nbsp;&amp;nbsp; 69632 2011-02-20 22:53 ..&lt;br /&gt;-rw-r--r--&amp;nbsp; 1 carl carl 75243520 2011-02-21 11:00 hackerlife-0b8724a229d81bbb727d27d735eaca86.out&lt;br /&gt;drwxr-xr-x&amp;nbsp; 3 carl carl&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4096 2011-02-21 11:00 new&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ file hackerlife-0b8724a229d81bbb727d27d735eaca86.out&lt;br /&gt;hackerlife-0b8724a229d81bbb727d27d735eaca86.out: POSIX tar archive&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ tar xf hackerlife-0b8724a229d81bbb727d27d735eaca86.out&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ file 6661024a3d7bbe441f8930e761a138f4&lt;br /&gt;6661024a3d7bbe441f8930e761a138f4: ASCII text, with CRLF line terminators&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ ls -al 6661024a3d7bbe441f8930e761a138f4&lt;br /&gt;-rw-r--r-- 1 carl carl 75231938 2010-12-31 00:42 6661024a3d7bbe441f8930e761a138f4&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Looking at the file, it looks like an oddly formatted passwd dump.&amp;nbsp; Looking through the list, it's obviously the well-publicized dump of gawker.com users.&amp;nbsp;&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ more 6661024a3d7bbe441f8930e761a138f4&lt;br /&gt;nicka ::: NULL ::: NULL ::: naster@gawker.com&lt;br /&gt;Lisanti ::: NULL ::: NULL ::: tips@defamer.com&lt;br /&gt;Choire ::: NULL ::: NULL ::: choire@gawker.com&lt;br /&gt;Defamer ::: NULL ::: NULL ::: tips@defamer.com&lt;br /&gt;gabriela ::: NULL ::: NULL ::: gabriela@gawker.com&lt;br /&gt;trackbacker ::: NULL ::: NULL ::: trackbacker@gawker.com&lt;br /&gt;wonkette ::: NULL ::: NULL ::: tips@wonkette.com&lt;br /&gt;lev ::: NULL ::: NULL ::: tips@gizmodo.com&lt;br /&gt;[...]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;So, I got a hold of the actual list and compared them.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ more gawker.passwd&lt;br /&gt;nicka:NULL:NULL:naster@gawker.com&lt;br /&gt;Lisanti:NULL:NULL:tips@defamer.com&lt;br /&gt;Choire:NULL:NULL:choire@gawker.com&lt;br /&gt;Defamer:NULL:NULL:tips@defamer.com&lt;br /&gt;gabriela:NULL:NULL:gabriela@gawker.com&lt;br /&gt;trackbacker:NULL:NULL:trackbacker@gawker.com&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ wc -l gawker.passwd&lt;br /&gt;1247893 gawker.passwd&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ wc -l 6661024a3d7bbe441f8930e761a138f4&lt;br /&gt;1247912 6661024a3d7bbe441f8930e761a138f4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Those are pretty close.&amp;nbsp; Lets find what is different.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ awk -F"[: ]" '{print $1}' gawker.passwd &amp;gt; gawker.users&lt;br /&gt;carl@b:~/hackerlife$ awk -F"[: ]" '{print $1}' 6661024a3d7bbe441f8930e761a138f4 &amp;gt; 666.users&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ diff -y --suppress-common-lines gawker.users2 666.users&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; havlarflake&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; dragosr&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; dino&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; dakami&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; 41414141&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; ChrisPaget&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; 0xcharlie&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; taviso&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; ero&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; thedarktangent&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; hdm&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; invisig0th&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; alexsotirov&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; mdowd&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; dionthegod&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; evilcazz&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; scarybeasts&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; egyp7&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; s7ephen&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Those guys look familiar.&amp;nbsp; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ cat users &lt;br /&gt;havlarflake ::: UtTv7enb7F7eo ::: NULL ::: Rmd4@gmail.com&lt;br /&gt;dragosr ::: /3EK9FFao4Pg6 ::: NULL ::: aD92@gmail.com&lt;br /&gt;dino ::: V2ImDfHvvzeGM ::: NULL ::: L3d3@gmail.com&lt;br /&gt;dakami ::: HH1Ib3DcdRGSk ::: NULL ::: IGtl@gmail.com&lt;br /&gt;41414141 ::: S8/2fLdvnSKM. ::: NULL ::: bS93@gmail.com&lt;br /&gt;ChrisPaget ::: aRHvyiutiwz3A ::: NULL ::: PThp@gmail.com&lt;br /&gt;0xcharlie ::: NVDC2543t.EKw ::: NULL ::: eSBp@gmail.com&lt;br /&gt;taviso ::: 6vqZ23UFznzuc ::: NULL ::: czog@gmail.com&lt;br /&gt;ero ::: Alj6D38tP79g6 ::: NULL ::: YXRj@gmail.com&lt;br /&gt;thedarktangent ::: 0dOYtkSGSMR4. ::: NULL ::: LmNv@gmail.com&lt;br /&gt;hdm ::: TxuDvnUnk94wU ::: NULL ::: VGhl@gmail.com&lt;br /&gt;invisig0th ::: hBYhGy4dotTCc ::: NULL ::: TGY4@gmail.com&lt;br /&gt;alexsotirov ::: oMCKEbmr9Kcx6 ::: NULL ::: ZHZH@gmail.com&lt;br /&gt;mdowd ::: TGW6yISW/Ezzo ::: NULL ::: b3V0@gmail.com&lt;br /&gt;dionthegod ::: 79mrBN2Qrejrk ::: NULL ::: dWJl@gmail.com&lt;br /&gt;evilcazz ::: L6D79o81B8rL6 ::: NULL ::: cDov@gmail.com&lt;br /&gt;scarybeasts ::: 6/gvMSbzDN1a. ::: NULL ::: aHR0@gmail.com&lt;br /&gt;egyp7 ::: boREOx6UFvQF. ::: NULL ::: Lg==@gmail.com&lt;br /&gt;s7ephen ::: m4bjrTwr9hbt6 ::: NULL ::: dy55@gmail.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Those email addresses look suspicious, especially "Lg==@gmail.com".&amp;nbsp; Anytime I see ==, I assume base64 padding.&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ cat users-original-order | egrep -o ".{4}@gmail.com"&amp;nbsp; | cut -c1-4 | tr -d '\n'&lt;br /&gt;Rmd4aD92L3d3IGtlbS93PThpeSBpczogYXRjLmNvVGhlTGY4ZHZHb3V0dWJlcDovaHR0Lg==dy55&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ cat users-original-order | egrep -o ".{4}@gmail.com"&amp;nbsp; | cut -c1-4 | tr -d '\n' | base64 -d&lt;br /&gt;Fgxh?v/ww kem/w=8iy is: atc.coTheLf8dvGoutubep:/htt.w.y&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;Rearrange the parts of the base64 string and you end up with: &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;carl@b:~/hackerlife$ echo "VGhlIGtleSBpczogaHR0cDovL3d3dy55b3V0dWJlLmNvbS93YXRjaD92PThpZHZHRmd4TGY4Lg==" | base64 -d&lt;br /&gt;The key is: http://www.youtube.com/watch?v=8idvGFgxLf8.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: large;"&gt;If you visit that link, and you should.&amp;nbsp; You'll also find somebody has beaten you to it:&amp;nbsp; &lt;/span&gt;&lt;br /&gt;"Wow,﻿ this URL is totally the key. Seriously. The key. The url. The key.&amp;nbsp; realnamehere 1 month ago "&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-6605657775442328023?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/6605657775442328023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage10-forensics.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/6605657775442328023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/6605657775442328023'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage10-forensics.html' title='Ghostintheshellcode  Stage10  Forensics 400 points.'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-2814014198342611868</id><published>2011-02-21T07:07:00.000-08:00</published><updated>2011-02-21T13:23:40.769-08:00</updated><title type='text'>Ghostintheshellcode Stage 26 BeatBoxing  Packet  75pts</title><content type='html'>&lt;span style="font-family: inherit;"&gt;Stage 26&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;Question: BeatBoxing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;75 Points&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;File: beatboxing-da09c691e2613581f1f4db70810c6e5c&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ file beatboxing-da09c691e2613581f1f4db70810c6e5c&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;beatboxing-da09c691e2613581f1f4db70810c6e5c: tcpdump capture file (little-endian) - version 2.4 (Ethernet, capture length 65535)&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;First just reviewed the dump file to see if anything stood out. I went down a few paths checking the delay between packets and any variance in the packet size, but they didnt lead me anywhere. The source and destination ports didn't seem to be of note either.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ tcpdump -nnn -r beatboxing-da09c691e2613581f1f4db70810c6e5c&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ tcpdump -nnn -A -r beatboxing-da09c691e2613581f1f4db70810c6e5c&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;I extracted the payload using tcpflow. The only thing I noticed was the file was exactly 65535 bytes. That didn't lead me to any conclusions other than it was likely custom generated.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ tcpflow -r beatboxing-da09c691e2613581f1f4db70810c6e5c&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ ls -al 127.000.000.001.42405-127.000.000.001.04242&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;-rw-r--r-- 1 carl carl 65535 2011-02-20 15:18 127.000.000.001.42405-127.000.000.001.04242&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ file 127.000.000.001.42405-127.000.000.001.04242&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;127.000.000.001.42405-127.000.000.001.04242: data&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;After reading some other CTF write ups, it dawned on me to look for the number of occurrences of specific characters, which led me to this:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;carl@b:~/beatbox$ egrep --binary-files=text -o "[A-Za-z0-9]" 127.000.000.001.42405-127.000.000.001.04242 | sort | uniq -c | sort -n&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;[...]&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;175 H&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;176 a&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;177 c&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;178 k&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;179 E&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;180 R&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;181 s&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;182 F&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;183 o&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;184 r&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;185 L&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;186 i&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;187 f&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;188 e&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;190 G&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;191 I&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;192 T&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;193 S&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;227 h&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;231 1&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;238 V&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;240 6&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;240 A&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;243 K&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;244 U&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;245 W&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;246 u&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;248 p&lt;/span&gt;&lt;br style="font-family: inherit;" /&gt;&lt;span style="font-family: inherit;"&gt;[...]&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;and thus the answer: HackERsForLifeGITS&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-2814014198342611868?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/2814014198342611868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-26-packet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/2814014198342611868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/2814014198342611868'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2011/02/ghostintheshellcode-stage-26-packet.html' title='Ghostintheshellcode Stage 26 BeatBoxing  Packet  75pts'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-5439925716513152844</id><published>2010-01-15T12:08:00.000-08:00</published><updated>2010-01-15T12:10:00.408-08:00</updated><title type='text'>Mental Note on argus</title><content type='html'>from #man ra&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;-n  Modify number to name converstion.  This flag supports 3 states, specified by the modulus of the number of -n flags set. The  first -n  will suppress address to hostname lookups.  -nn will suppress port number to service conversion and -nnn will suppress translation of protocol numbers to names.  -nnnn will return you to full conversion.   Because this indicator can  be  set  in  the  .rarc file, multiple -n flags can be used to specify to a specific state of number to name conversion.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Therefor, when I type 'ra -nnnn ' as I am expected to do, I am actually failing to suppress lookups like I expected. &lt;br /&gt;&lt;br /&gt;Always good to RTFM.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-5439925716513152844?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/5439925716513152844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2010/01/mental-note-on-argus.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/5439925716513152844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/5439925716513152844'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2010/01/mental-note-on-argus.html' title='Mental Note on argus'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-3078429599242028700</id><published>2009-12-14T16:15:00.001-08:00</published><updated>2009-12-27T19:17:26.451-08:00</updated><title type='text'>Syslog and UDP issues</title><content type='html'>&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Going to use this space to outline an issue I'm currently experiencing and hopefully to later post a resolution as I find one.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;I recently helped set up a couple syslog servers to consolidate a lot of data for a client.  We ran into a problem where data was not being logged even though logs were being sent to the system.  We used tcpdump to confirm that the logs were reaching the server and formatted correctly, but syslog was not writing them to disk.  However, other logs were being written.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;The problem seems to relate to the UDP recv-q.  Here's what we were seeing: &lt;/span&gt;&lt;br /&gt;&lt;blockquote  style="font-family:courier new;"&gt;[root@test-lab ~]# netstat -anu | grep 514&lt;br /&gt;udp   &lt;span style="font-weight: bold;"&gt;110160 &lt;/span&gt;     0 0.0.0.0:514                 0.0.0.0:*&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-family:courier new;"&gt;That 110160 as best I can tell, is the number of bytes waiting on the interface's buffer, but syslog has not picked them up and processed them.  Watching that number of the course of a few days, it would occasionally rise or fall ever so slightly, but I was unable to determine what it was actually doing.  &lt;/span&gt;&lt;br /&gt;&lt;blockquote  style="font-family:courier new;"&gt;[root@test-lab ~]# netstat -ansu&lt;br /&gt;Udp:&lt;br /&gt;  &lt;span style="font-weight: bold;"&gt;103235 packets received&lt;/span&gt;&lt;br /&gt;  58248 packets to unknown port received.&lt;br /&gt; &lt;span style="font-weight: bold;"&gt; 425450 packet receive errors&lt;/span&gt;&lt;br /&gt;  144175 packets sent&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-family:courier new;"&gt;Running this command repeatedly, it looked like the packet receive errors were increasing by 20-30 for every 1 packet received.  Strange.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;We tried making some tweaks to the buffer size.  This did not make an immediate difference, but likely requires a reboot, which we were unable to do at the time.  Will update sysctl.conf and reboot when available.  If I recall correctly, I've seen this behavior before, but the buffer would fill up close to max regardless of how large we set the rmem_max value.  Here it's set to 8MB:  &lt;/span&gt;&lt;br /&gt;&lt;blockquote  style="font-family:courier new;"&gt;[root@test-lab ~]# sysctl net.core.rmem_max&lt;br /&gt;net.core.rmem_max = 131071&lt;br /&gt;[root@test-lab ~]# sysctl -w net.core.rmem_max=8192000&lt;br /&gt;net.core.rmem_max = 8192000&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-family:courier new;"&gt;Also, someone suggested we try offloading some of the work to the hardware using UDP Fragmentation Offload.  This is disabled by default in Linux.  It sounded like a good idea, and makes sense because some of these log messages are quite large and likely fragmented.  Unfortunately, it appears our NICs or drivers do not support this feature.  &lt;/span&gt;&lt;br /&gt;&lt;blockquote face="courier new"&gt;[root@test-lab ~]# ethtool -k eth0&lt;br /&gt;Offload parameters for eth0:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cannot get device udp large send offload settings: Operation not supported&lt;/span&gt;&lt;br /&gt;rx-checksumming: on&lt;br /&gt;tx-checksumming: on&lt;br /&gt;scatter-gather: on&lt;br /&gt;tcp segmentation offload: off&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;udp fragmentation offload: off&lt;/span&gt;&lt;br /&gt;generic segmentation offload: off&lt;br /&gt;generic-receive-offload: off&lt;br /&gt;[root@test-lab ~]# ethtool -K eth0 ufo on&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cannot set device udp large send offload settings: Operation not supported&lt;/span&gt;&lt;br /&gt;[root@test-lab ~]#&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-family:courier new;"&gt;So, the current plan is to try an increase the buffers, decrease the amount of UDP data being sent to the server, and possibly a hardware upgrade in the form of new NICS.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;UPDATE:&lt;br /&gt;Just wanted to add a few more details to this conversation.&lt;br /&gt;&lt;br /&gt;During troubleshooting, we made an attempt to figure out which hosts were causing the most UDP traffic that the socket could not keep up with.  To do this, I did the following rough command:&lt;br /&gt;&lt;br /&gt;#tcpdump -nnn -c 1000 -i bond0 udp and port 514 | awk '{print $3}' | egrep -o "&lt;span style="font-family:courier new;"&gt;[0-9]{1,3}\.&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;[0-9]{1,3}\.&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;[0-9]{1,3}\.&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;[0-9]{1,3}" | sort | uniq -c | sort -nr&lt;br /&gt;&lt;br /&gt;This command spit captured the next 1000 UDP syslog hits, parsed out the source IP addresses, sorted, counted, and then reverse sorted (highest at the top) the results.  The results were that some of the firewalls and some of the DNS servers in the local zone were sending tons of UDP logs.  After speaking with the owners, we trimmed some of the 'noise' out of the syslogs and also switched over to TCP.  After a few of these changes, the Recv-Q fell to 0, and only rarely accumulated up.  It would quickly revert back to zero as the application kept up.  Additionally our netstat -ansu command showed that packets were being correctly received and not errored.  Neat!&lt;br /&gt;&lt;br /&gt;Just to be sure, we also ran #netstat -ant and #netstat -antu to make sure that the TCP recv-q wasn't filling, and there were no packets being dropped on the TCP side.  It looks like we were able to resolve the issue.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-3078429599242028700?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/3078429599242028700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2009/12/syslog-and-udp-issues.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/3078429599242028700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/3078429599242028700'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2009/12/syslog-and-udp-issues.html' title='Syslog and UDP issues'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-6589241505498762231</id><published>2009-11-28T16:19:00.001-08:00</published><updated>2009-11-28T16:30:14.576-08:00</updated><title type='text'>To do:</title><content type='html'>Here's a quick list of NSM things going around my head that I'd like to put some time into: &lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Know your network &amp;amp; Asset management - Put together documentation on every host/subnet/service/etc that you can.  You can craft very explicit alert, firewall and IDS rules, but you NEED this information to make them accurate. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Egress filtering - Don't just block outbound traffic, but set up alerts/review logs to see who/what is making those blocked connections.&lt;/li&gt;&lt;li&gt;Limit the noise - If you can reduce the amount of unidentified traffic in your network, you can focus on these anomalies. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Snort - The easiest way to get into customized deep packet inspection.&lt;/li&gt;&lt;li&gt;Keep netflow and URL history - Invaluable for incident response.&lt;/li&gt;&lt;li&gt;Don't trust AV.  If you're spending all your time focusing on your AV alerts, you're missing the real threats. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Honeypots - They don't need to be complex to be effective.  The false positive rate is minimal and this is a very very VERY good thing.  It's so simplistic, I can't believe it's not standard practice.&lt;/li&gt;&lt;li&gt;User's don't need admin rights.  OK, political battle here, but if you can't remove admin rights, how about white-listing sites allowing .exe downloads?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;User education doesn't work so well, I like user punishment.  Reduce privileges for users who create work for IT staff by infecting themselves. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;If you're not going to document your policy exceptions, how can you create/audit rules that you have for those policies?&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;I'm sure this list will grow as more comes to mind.  Hopefully I'll find the time to write more on each of them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-6589241505498762231?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/6589241505498762231/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2009/11/to-do.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/6589241505498762231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/6589241505498762231'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2009/11/to-do.html' title='To do:'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1994500777340825026.post-5446460194987371226</id><published>2009-11-06T17:42:00.000-08:00</published><updated>2009-11-06T18:29:56.199-08:00</updated><title type='text'>New blog</title><content type='html'>Here's what I'm into right now.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.dojocon.org/"&gt;Dojocon&lt;/a&gt; - The 2 day security conference put together by Marcus Carey.  I spent most of the day there today and enjoyed the talks.  The whole event is being streamed and archived in quite good quality on &lt;a href="http://live.saecur.com/dojocon/"&gt;Ustream.&lt;/a&gt;  I most enjoyed Matt Watchinski's talk about managing a security group and some of the things we're doing wrong as an industry. I was considering participating in the CTF event, though I have not done one before and do not know what to expect.  However, I've heard it was cancelled. &lt;br /&gt;&lt;/li&gt;&lt;li&gt;My FreeBSD sensor - I set up a very bare installation of FreeBSD and am running a few network monitoring tools for the home network.  I'll go into these more in a future post:  snort, urlsnarf, dsniff and argus.  &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nintendo.com/games/detail/YL1RxLS0Ihba1dEx6j7IJqbnNtu1xB6a"&gt;Punch Out! (Wii)&lt;/a&gt; - I remember playing Mike Tyson's Punch Out on the NES, and later Super Punch Out on the SNES.  I'm glad I gave this game a shot on the Wii, it's good fun.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.zombievilleusa.com/"&gt;Zombieville (Iphone) &lt;/a&gt;- This is a fun little game that only costs $.99 and has provided many hours of entertainment.  For it's simplicity, it is challenging and fun. &lt;/li&gt;&lt;/ul&gt;Hopefully more interesting posts to come.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1994500777340825026-5446460194987371226?l=dontpanictech.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dontpanictech.blogspot.com/feeds/5446460194987371226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://dontpanictech.blogspot.com/2009/11/new-blog.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/5446460194987371226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1994500777340825026/posts/default/5446460194987371226'/><link rel='alternate' type='text/html' href='http://dontpanictech.blogspot.com/2009/11/new-blog.html' title='New blog'/><author><name>Dont Panic</name><uri>http://www.blogger.com/profile/14225803942084300379</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='25' src='http://3.bp.blogspot.com/_8ICPVGqpMoE/SvTcizNtTNI/AAAAAAAAAAM/c-jBPyw60_Y/S220/dontpanic.JPG'/></author><thr:total>0</thr:total></entry></feed>
