Challenge 7 - Forensic Analysis of a Compromised Server - (provided by Guillaume Arcas from the French Honeynet Project Chapter, Hugo Gonzales from the Mexican Honeynet Project Chapter, Julia Cheng from the Taiwan Honeynet Project Chapter)
Pls submit your solution using the submission template below by March 30th 2011 at http://www.honeynet.org/challenge2010/. Results will be announced around the third week of April. For any questions and inquiries, please contact forensicchallenge2010@honeynet.org.
Skill Level: Beginner
The Challenge:
A Linux server was possibly compromised and a forensic analysis is required in order to unterstand what really happened. Hard disk dumps and memory snapshots of the machine are provided in order to solve the challenge.
Bonus question: From memory image, can you say what network connections were opened and in which state ?
Download:
victoria-v8.kcore.img.zip
victoria-v8.memdump.img.zip
victoria-v8.sda1.img.zip
victoria-v8.kcore.img: memory dump done by dd'ing /proc/kcore
victoria-v8.memdump.img: memory dump done with memdump[1]
[1]http://www.porcupine.org/forensics/tct.html
MD5:
victoria-v8.kcore.img.zip = 3b74b32279422e93f93927b80f18df2c
victoria-v8.memdump.img.zip = 7d271455ad65e55678a530aaed696040
victoria-v8.sda1.img.zip = cba614f59020ce8910346cc43056692f
SHA1:
victoria-v8.kcore.img.zip = e971ccfd4853d4b7459eb6862e4b747074f23a7
victoria-v8.memdump.img.zip = eae53cb9fb1e98f9f9ba334edfe8a4b3e7ca9104
victoria-v8.sda1.img.zip = cddc70ca67db4f3cfca4d48c755c43bb286738c3
The Winners:
1. Dev Anand (Submission SHA-1: 8150e907a114d862a4c25387f2ea42371569781c)
2. Fernando Quintero & Camilo Zapata (Submission SHA-1: f122f9a93b8ec2c708a447cb74ba214569d8716f)
3. (3 submissions)
Matt Erasmus (Submission SHA-1: a49543b0022416b946e89134839d916ea25d94c9)
Joseph Kahlich (Submission SHA-1: fc2d1898edc542bd1f2b7f82b962d361503b3e8b)
Kevin Mau (Submission SHA-1: 0eef1421350edcd5b3266006d07df19aa342c431)