Challenge 1 – pcap attack trace – (provided by Tillmann Werner from the Giraffe Chapter) is to investigate a network attack.
Send submissions no later then 17:00 EST, Monday, February 1st 2010. Results will be released on Monday, February 15th 2010. Small prizes will be awarded to the top three submissions.
Skill Level: Intermediate
The Challenge:
A network trace with attack data is provided. (Note that the IP address of the victim has been changed to hide the true location.) Analyze and answer the following questions:
- Which systems (i.e. IP addresses) are involved? (2pts)
- What can you find out about the attacking host (e.g., where is it located)? (2pts)
- How many TCP sessions are contained in the dump file? (2pts)
- How long did it take to perform the attack? (2pts)
- Which operating system was targeted by the attack? And which service? Which vulnerability? (6pts)
- Can you sketch an overview of the general actions performed by the attacker? (6pts)
- What specific vulnerability was attacked? (2pts)
- What actions does the shellcode perform? Pls list the shellcode. (8pts)
- Do you think a Honeypot was used to pose as a vulnerable victim? Why? (6pts)
- Was there malware involved? Whats the name of the malware? (We are not looking for a detailed malware analysis for this challenge) (2pts)
- Do you think this is a manual or an automated attack? Why? (2pts)
Sample Solution:
Forensic Challenge 2010 – Scan 1 – Solution_final.pdf Sha1: 7482a4d020cddde845344f8b02e05012
This work by Tillmann Werner is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.
The Winners:
- Ivan Rodriguez Almuina (Switzerland) – Ivan’s submission – Sha1: 988d675a83ab8a4d6487ef69b16b3cfd41d1c7d6
- Franck Guenichot (France) – Franck’s submission – Sha1: c951552faf6118a352cc33a9b001350df9050575
- Tareq Saade (USA) – Tareq’s subission – Sha1: 969e73527a2c7a1b27e6b36f4cfa324fd8a66e94
Attachment | Size |
---|---|
attack-trace.pcap_.gz | 151.16 KB |
Forensic Challenge 2010 – Challenge 1 – Submission Template.doc | 76 KB |
Forensic Challenge 2010 – Challenge 1 – Submission Template.odt | 18.47 KB |
Franck Guenichot – Forensic Challenge 2010 – Challenge 1_Eval.pdf | 1.47 MB |
Ivan Rodriguez Almuina – Forensic Challenge 2010 – Challenge 1_Eval.pdf | 285.58 KB |
Tareq Saade – Forensic Challenge 2010 – Challenge 1_Eval.pdf | 486.45 KB |
Forensic Challenge 2010 – Scan 1 – Solution_final.pdf | 649.89 KB |