Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum
Ethical Hacker Community Forums
January 08, 2009, 06:02:32 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
  Home Help Calendar Login Register  
  Show Posts
Pages: [1] 2 3 ... 164
1  Resources / Mass Media / Re: Daniel Suarez Interview on: Yesterday at 11:02:27 PM
Here's another one at USA Today:

http://www.usatoday.com/life/books/news/2009-01-05-daemon_N.htm

Don
2  EH-Net / News Items and General Discussion About EH-Net / [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC on: Yesterday at 03:40:26 PM
More Black hat fun in the nation's capital. Join our very own Chris Gates as he covers this event for EH-Net in our forums and Twitter.

Permanent link: [Article]-January 2009 Free Giveaway Sponsor - Black Hat DC

Quote

Win Ticket to Black Hat DC = $1395!!



Attend Black Hat DC on us, EH-Net. The Washington, DC version of the world's premier technical event for ICT security experts is being held February 18 - 19, 2009. Featuring hands-on training courses and Briefings presentations with lots of new content-including a focus on wireless security and offensive attack analysis. Network with 400+ delegates and review products from leading vendors in a relaxed setting, including Diamond sponsor Microsoft. This should be a great incentive to really get those forums hopping with participation. At stake is a Passport Admission Ticket worth $1395 that allows entry into the Briefings portion of the event. This year's venue is the Hyatt Regency Crystal City in Arlington, VA.

Good luck.

We'd also like to thank Black Hat for continuing to support our own security event, ChicagoCon. Our 2009 event will be held May 4 - 9, 2009. They are a rare organization indeed and deserve our full support.
         
Participation is the ONLY way to win. Start a thread that sparks lots of interest; share thoughts and experiences; help a newbie... quality is more important than quantity.
         
Only members are eligible!
Registration Is FREE!



Hope you like these prizes,
Don
3  Features / Oct 2008 - Scooby Doo and the Crypto Caper / [Article]-Scooby Doo and the Crypto Caper - Answers and Winners on: Yesterday at 12:16:18 PM
Thanks again Kev and Ed. More skillz goodness to come in 2009! Look for the answers and winners to Santa Claus is Hacking to Town in the next week(ish).

Permanent link: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners

Quote



And the Scooby Snacks go to...

Thanks again to all who participated in this multi-faceted challenge. Although we all love Ed Skoudis' creations, Kevin Bong has once again proven to be more than worthy of penning some of our fun and educational contests. Where else can you find a 70s classic cartoon intermixed with some crypto to reveal a little Zeppelin all in the name of expanding your forensics skillz? Well done, Kevin. We look forward to another one of his creations later in 2009.

Since it is the start of a new year and yet another perfect time to show appreciation, this one goes out to our gracious host, Ed Skoudis on InGuardians. I've mentioned this in the past, but it is worth pointing out once again. For the betterment of EH-Net and the Ethical Hacking / Pen Testing Community as a whole, Ed volunteers his vast talents and resources to bring you what I truly believe to be a unique, educational experience. It is an honor to have him, and I look forward to many more years of collaboration.

Donald C. Donzal

Editor-In-Chief



Please leave your comments or recommendations,
Don
4  Features / Oct 2008 - Scooby Doo and the Crypto Caper / Skillz October 08 Winning Entry - Creative on: Yesterday at 11:59:23 AM
Ralph Forsythe

For PDF with original formatting, click HERE.

Congrats,
Don
5  Features / Oct 2008 - Scooby Doo and the Crypto Caper / Skillz October 08 Winning Entry - Technical on: Yesterday at 10:54:15 AM
Text version below. For PDF and original formatting, click HERE.

Dan Roberts

Quote

26 October 2008

1. Can you figure out who killed Dr. Wilson, and why?

Starting with the partial disk image, I recovered a couple of files using foremost (see appendix 1). In addition to these two files, I recovered an e-mail (see appendix 2) by inspecting the strings within the disk image. The identity of the recipient is not clear from the e-mail text, but the Base64-encoded file attachment reveals a jpeg photograph of a messy office decorated with anime figurines. The e-mail states that the sender knows the
recipient is behind the cheating, and that the photo is proof of this.
Based on these findings, I suspect that Dr. Miller is the murderer. He knew that Dr. Wilson could identify him, and so used his opportunity in the darkened computer room to shut Dr. Wilson up.. for good.

2. How were the passwords stolen to steal the exams?

I suspect the encryption key was stolen using a hardware keylogger. The photo shows packaging for a 256K in-line key logging device in the waste basket of Dr. Miller's office. Dr. Taylor said that she scanned the PC for various malware, but a hardware keystroke logger would not have been detected with such a scan.

3. Can you provide a copy of the cryptography final exam? Can you create an answer key?

The final exam was stored in Excel format. Although foremost was able to recover the file from the partial disk image, it was also perfectly readable using strings. Here is the content of the final exam:

Cryptography Final Exam

Question 1

Q BEDW JYCU QWE, YD Q WQBQNO VQH, VQH QMQO
YJ YI Q FUHYET EV SYLYB MQH. HURUB
IFQSUIXYFI, IJHYAYDW VHEC Q XYTTUD
RQIU, XQLU MED JXUYH VYHIJ LYSJEHO
QWQYDIJ JXU ULYB WQBQSJYS UCFYHU.
TKHYDW JXU RQJJBU, HURUB IFYUI CQDQWUT
JE IJUQB IUSHUJ FBQDI JE JXU UCFYHU'I
KBJYCQJU MUQFED, JXU TUQJX IJQH, QD
QHCEHUT IFQSU IJQJYED MYJX UDEKWX
FEMUH JE TUIJHEO QD UDJYHU FBQDUJ.
FKHIKUT RO JXU UCFYHU'I IYDYIJUH QWUDJI,
FHYDSUII BUYQ HQSUI XECU QREQHT XUH
IJQHIXYF, SKIJETYQD EV JXU IJEBUD FBQDI
JXQJ SQD IQLU XUH FUEFBU QDT HUIJEHU
VHUUTEC JE JXU WQBQNO

Question 2

NOTCAESAR

fvtnlmdorgvxaoyfoncokkslgnvecajeejhzzqatiwlirakbvhmfmvvhlvivkmpfwgvhijimrfhjslwsnrzeuwmlhfhfequwanvfgtnlqqlzsspklpwnusckjiqoeiroenoylowfwzpsmcnfjwfuovlajucvmehloyrokvhidoiqariohfonjwensenedrcakwmdlerfugseneuosvcuwwicvjxyixzsrgogqnioijuhhfaclhrgmhwlpslccftafsjtyesxyhsoicyatmemlhvesecti

Question 3

Wheel Order 123
Stecker Pairs IJ ST
Indicator Settings AYB
Reflector B
EEHVWXXDGZJKFDLAANJCBK

An answer key does not seem to be included in the partial disk image. But who needs a key when you've got Velma on hand? Here's what she came up with:

Cryptography Final Exam Answer Key

Answer 1

This is a Caesar cipher with an alphabet shift of -10. It works by substituting letters from the normal alphabet (A-Z) with an alphabet that has been shifted, like such:

ABCDEFGHIJKLMNOPQRSTUVWXYZ <- the original character
KLMNOPQRSTUVWXYZABCDEFGHIJ <- translates to the character beneath it

The plaintext reads:

A LONG TIME AGO, IN A GALAXY FAR, FAR AWAY
IT IS A PERIOD OF CIVIL WAR. REBEL
SPACESHIPS, STRIKING FROM A HIDDEN
BASE, HAVE WON THEIR FIRST VICTORY
AGAINST THE EVIL GALACTIC EMPIRE.
DURING THE BATTLE, REBEL SPIES MANAGED
TO STEAL SECRET PLANS TO THE EMPIRE'S
ULTIMATE WEAPON, THE DEATH STAR, AN
ARMORED SPACE STATION WITH ENOUGH
POWER TO DESTROY AN ENTIRE PLANET.
PURSUED BY THE EMPIRE'S SINISTER AGENTS,
PRINCESS LEIA RACES HOME ABOARD HER
STARSHIP, CUSTODIAN OF THE STOLEN PLANS
THAT CAN SAVE HER PEOPLE AND RESTORE
FREEDOM TO THE GALAXY

This is the prologue to the movie Star Wars.

Answer 2

This ciphertext was generated using a Vigenere table (a matrix like the one shown
below) and a secret key to perform character substitution.

ABCDEFGHIJKLMNOPQRSTUVWXYZ
A ABCDEFGHIJKLMNOPQRSTUVWXYZ
B BCDEFGHIJKLMNOPQRSTUVWXYZA
C CDEFGHIJKLMNOPQRSTUVWXYZAB
D DEFGHIJKLMNOPQRSTUVWXYZABC

…and so on…

Each character of the cipher text is decoded by finding the letter in the matrix where a cipher character along the top and a secret key character down the side intersect. Each character of the secret key is used in succession, and repeated until the entire message is decoded.

The plaintext reads:

shalliloatheyounowparishonerohhearhimchristianwithinmeitstirsmysintheriverohsheswellswithourlousinessallmylifewillendforhimwerealloutofsignsiknowimsortashockedtohearthelordmygodnowwillsavemeohiwillnerbesavedbecauseilivewithsatanonewishtodaythatyoullallprayforthreewhowillmakeitherelate

With spaces, this reads: "Shall I loathe you now parishioner oh hear him Christian within me it stirs my sin the river oh she swells with our lousiness all my life will end for him were all out of signs I know im sorta shocked to hear the lord my god now will save me oh i will ner be saved because I live with satan one wish today that youll all pray for three who will make it here late." These are the words to Stairway to Heaven, heard when played backwards.

Answer 3

The parameters listed in the question refer to settings on a WWII German Enigma machine. When set properly, this mechanical device decodes the cipher text to read:

SOMEBODYSETUPUSTHEBOMB

"Somebody set us up the bomb".. the immortal words of CATS in A.D. 2101 from the game Zero Wing. All of your base are belong to us!

Several tools that helped with the decoding:

Enigma emulator: http://homepages.tesco.net/~andycarlson/enigma/enigma_j.html

ROT-13 decoder (and more):
http://web.forret.com/tools/rot13.asp

Vigenere decoder: http://islab.oregonstate.edu/koc/ece575/02Project/Mun+Lee/VigenereCipher.html

4. Also, provide some analysis of Velma's incident handling process. What did she do right? What should she have done differently?

Velma did right in creating a disk image to work from rather than directly manipulating the original media, and she went for the right tools to extract the relevant data. What she could have done differently:

Firstly, she should not have disturbed the evidence. Immediately upon discovering the crime, the proper thing to do would be to clear out and secure the data center and allow qualified law enforcement personnel to properly survey the scene. It also wouldn't hurt to keep the suspects together.

Supposing she was qualified to conduct a forensic investigation. The pocket knife should have been photographed as found, then tagged and bagged for safe-keeping. Two copies of the storage device would have been better: one for archival purposes and another to work from.

Velma should have used a hashing algorithm like MD5 or SHA1 to take fingerprints of the media. This could help later in establishing the integrity of the data if used as evidence in court.

The pocket knife should probably first undergo a more comprehensive physical examination, such as fingerprinting and DNA testing, before anyone diddles with it. By picking it up, Velma has contaminated potential evidence.

The device should have been operated in a controlled environment to avoid possible damage. Optimal conditions would have ensured no blood or other debris would interfere with operation of the USB drive. It's hard to know now whether the data was already corrupt, or if blood caused a short, or if the data was corrupted just by clumsy handling.

A digital forensic analysis should follow carefully planned procedures, and all steps performed should be documented. Digital evidence is often suspect due to the ease of its fabrication and modification, so a methodical approach is crucial in establishing the reliability of the data as evidence.

This case is interesting because the murder weapon and digital media are one in the same. Velma's missteps and lack of documentation could put the success of a future trial in jeopardy.. not only from the perspective of the data, but also the murder weapon.

5. Hey, was I just rick rolled?

Okay, so that wasn't a question in the challenge.. but we know these challenges well enough by now that Rick Astley's music video didn't end up in that partial disk image by accident! :-)

Rickrolling is an Internet meme involving the music video for the 1987 Rick Astley song "Never Gonna Give You Up". The meme is a bait and switch: a person provides a Web link they claim is relevant to the topic at hand, but the link actually takes the user to the Astley video. – Wikipedia

Appendix 1:

Output from foremost when processing partialdriveimage.bin
Foremost version 1.5.4 by Jesse Kornblum, Kris Kendall, and Nick Mikus
Audit File
Foremost started at Thu Oct 23 14:02:30 2008
Invocation: ./foremost partialdriveimage.bin
Output directory: /home/roberts/foremost-1.5.4/output
Configuration file: /home/roberts/foremost-1.5.4/foremost.conf
------------------------------------------------------------------
File: partialdriveimage.bin
Start: Thu Oct 23 14:02:30 2008
Length: 5 MB (5242880 bytes)
Num Name (bs=512) Size File Offset Comment
0: 00005372.xls 82 KB 2750464
1: 00005536.mpg 2 MB 2834432
Finish: Thu Oct 23 14:02:30 2008
2 FILES EXTRACTED
ole:= 1
mpg:= 1
------------------------------------------------------------------
Foremost finished at Thu Oct 23 14:02:30 2008

Appendix 2:

Contents of the e-mail from Dr. Wilson to Dr. Miller
Subject: Exam Questions
I know how you've been obtaining our passwords to steal the exams provide them to the students. You'll see I have the proof in the attachment. I expect you to resign your position and leave the University at the end of the semester or I will be forced to disclose this information and fire you.
Dr. Wilson

Attachment (file/jpg):


Click for larger image

Note: To obtain this image, I copied the Base64 encoded content from the strings output and pasted it into a decoder (http://www.motobit.com/util/base64-decoder-encoder.asp). Several incomplete lines had to be padded in order to get a usable image.. it didn't come out perfect, but good enough to solve the puzzle!


Don
6  EH-Net / News Items and General Discussion About EH-Net / EH-Net Milestone - 2 Articles Cross 1 Million Page Views on: January 06, 2009, 03:08:19 PM
What a great way to start the New Year!!

2 of our articles have crossed the 1 million page view mark, something not accomplished on this site before now.

- EH-Net Presents BackTrack 2 with Metasploit 3 as a Virtual Appliance, a joint project between EH-Net and Offensive Security.

- Essential Wireless Hacking Tools, one of our earliest articles published on November 15, 2005 by Dan Hoffman.

Thanks and here's to continued success for the site and all of its readers worldwide.

Don
7  EH-Net / Calendar Of Events / RSA 2009 on: January 06, 2009, 08:33:20 AM
RSA 2009
April 20 - 24, 2009
Moscone Center, San Francisco, CA


World's Largest Informarion Security Industry Conference & Expo

In a security environment where every day brings new challenges, staying ahead isn't just an option, it's mandatory. Featuring over 240 targeted sessions and 500+ speakers, RSA® Conference 2009 is your best opportunity to build on your previous Conference experience and keep up with the latest information security issues. It's your chance to connect with industry experts and develop practical strategies that will help you combat these ever-emerging threats.

RSA Conference 2009 will help you create viable solutions to help ensure your company's immediate and long-term program success. This is the one information security event you can't afford to miss.

http://www.rsaconference.com/2009/US/Home.aspx

Don
8  Ethical Hacking Discussions and Related Certifications / CEH - Certified Ethical Hacker / Re: Any Practice Environment for learning tool for CEH? on: January 05, 2009, 09:42:20 AM
 Grin

Good job guys.

Don
9  Ethical Hacking Discussions and Related Certifications / Wireless / Re: a petri-dish bridge on: January 05, 2009, 09:36:30 AM
I agree. That least common denom. theory makes the weakest link in the chain your highest possible security posture. Here's a thought from an architectural standpoint. Don't just use another AP. Get a full wireless router, and put them on a different subnet. You can dumb it down to WEP and still use the same radius server for auth. Or, since it is only 3 devices, don't worry about radius and just set them up on the dumbed down router using MAC filtering as well. Many routers now also come with a nice little feature that disallows anyone connected via the wireless network from accessing the control panel. This makes it so that only those with physical access to your network via the wired LAN can make changes to your router's settings.

Hope this helps,
Don
10  Ethical Hacking Discussions and Related Certifications / Programming / Python 3.0 Released on: January 02, 2009, 12:18:48 PM
Quote

Python 3.0 (a.k.a. "Python 3000" or "Py3k") is a new version of the language that is with the 2.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed. Also, the standard library has been reorganized in a few prominent places.


For more details, resources and download links:
http://www.python.org/download/releases/3.0/

Don
11  Ethical Hacking Discussions and Related Certifications / Forensics / Re: SANS SIFT Forensic toolkit on: January 02, 2009, 11:32:13 AM
Great post, and if Rob is reading this... thanks!

Don
12  Resources / Tools / Re: tool to trace users on: January 02, 2009, 09:28:31 AM
Hey blackazarro,

Sounds like a great tutorial for our readers.  Wink

Don
13  Ethical Hacking Discussions and Related Certifications / Other / Re: Happy New Year! on: January 01, 2009, 05:41:25 PM
Happy New Year, all. Looks like we are in the minority with all of our excitement for 2009. Life is what you make, and I'm totally jazzed about 2009, so bring it on naysayers!!

Don
14  Ethical Hacking Discussions and Related Certifications / Other / Re: Math Review on: December 31, 2008, 08:45:55 AM
I agree. That's some extensive list of free courses. Good find.

Don
15  Ethical Hacking Discussions and Related Certifications / Other / Re: will this get me anywhere? on: December 30, 2008, 11:42:06 AM
Without even looking at it closely, I can say that it will "get you somewhere." But the more important question is where do you want to be? Tell us more about your goals and desires, and then we might be able to help answer your question a little better as to whether this will get you there.

Hope that wasn't too vague,
Don
Pages: [1] 2 3 ... 164
Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.084 seconds with 21 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.