Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 50 guests and 5 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Recreating files from packet capture
EH-Net
May 25, 2012, 10:09:00 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Recreating files from packet capture  (Read 8896 times)
0 Members and 2 Guests are viewing this topic.
Vedder
Newbie
*
Offline Offline

Posts: 26


View Profile WWW
« on: July 28, 2009, 10:26:12 AM »

Hi

Can anyone help me recreate files from a packet capture.

I have found a good page on hex headers (http://www.garykessler.net/library/file_sigs.html), and I know that there are at least two bmp images and one zip file.

I have tried copying them all to notepad, then loading them up in a hex editor, and saving them as the required file type, but if I try opening them up in paint, or winzip, I just get a "file is corrupt" message.

Is there a step I am missing?
Logged

C|EH, MCSE, MCSA: Security, Security+, Network+, A+
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 3916


Editor-In-Chief


View Profile WWW
« Reply #1 on: July 28, 2009, 10:44:41 AM »

Try NetWitness Investigator.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Ketchup
Hero Member
*****
Offline Offline

Posts: 1006



View Profile
« Reply #2 on: July 28, 2009, 10:50:35 AM »

NetWitness is great, like Don indicated.   I've used it and it really makes viewing HTML, Email, and other types of documents amazingly easy as they travel across the wire.

Wireshark can also do this, depending on the protocol.  Files transmitted through HTTP can be exported using the File, Export, Objects menu.    For other protocols, you would have to isolate the packets that belong to your file, and then export the packets.   Wireshark will put the fragments of the transmission back together for you.  You can use the Follow TCP Stream feature for this.
Logged

~~~~~~~~~~~~~~
Ketchup
Vedder
Newbie
*
Offline Offline

Posts: 26


View Profile WWW
« Reply #3 on: July 28, 2009, 11:31:17 AM »

Thanks Don and Ketchup

It's SSL traffic, I've decrypted it in Wireshark using the key, and can see them in hex code in the outputted file. Wireshark just shows the encrypted data still.

I'll carry on with NetWitness, as it does look like a very nice tool.

*EDIT*

NetWitness has come up trumps, and given me the files.

Thanks again Don and Ketchup
« Last Edit: July 28, 2009, 11:37:06 AM by Vedder » Logged

C|EH, MCSE, MCSA: Security, Security+, Network+, A+
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #4 on: July 29, 2009, 12:18:01 AM »

Thanks for the hint about NetWitness, haven't heard about it before. Definitely sounds interesting and useful.
Logged
dalepearson
Sr. Member
****
Offline Offline

Posts: 356


View Profile WWW
« Reply #5 on: July 29, 2009, 04:47:11 AM »

Late to the party on this one.
As previously said, Netwitness is a cracking product, I used it when they charged for it in the Corporate environment.

Now they have the free one, I have it on my personal machine, and its good stuff.

Deffo worth a download.
Logged

305mia
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #6 on: August 21, 2009, 09:53:09 AM »

So I have an AIM conversation in which a document was exchanged via AIM's file sharing function.

NetWitness recreated the conversation from my pcap file and shows the document name.

I am having trouble reconstructing the attachment document. I know it is a word doc but how can I actually reconstruct the document?

Thanks in advance
Logged
nebu10uz
Sr. Member
****
Offline Offline

Posts: 363



View Profile WWW
« Reply #7 on: August 25, 2009, 11:20:04 AM »


Available tools on the Internet for the purpose of extracting files from packet dumps:

NetworkMiner

Xplico

TcpXtract

And to do it manually using WireShark and a Hex editor check out the following blog:

Pulling binaries from pcaps

Enjoy!
Logged

Security+, OSCP, CEH
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 394



View Profile
« Reply #8 on: August 25, 2009, 05:19:23 PM »

Nice.  I've not worked with the Netwitness Investigator program before.  My first interaction with Netwitness was out at an afterparty with some of the folks in Vegas this year.  And watching my girlfriend verbally emasculate one of their VPs as he drunkenly tried to impress/pick her up.  It was one of those times where I was reminded on why I want to marry her hehehe.
Logged

"Bad.. Good?  I'm the guy with the gun"
aweSEC
Hero Member
*****
Offline Offline

Posts: 1100


View Profile
« Reply #9 on: August 26, 2009, 12:32:02 AM »

[...]

And to do it manually using WireShark and a Hex editor check out the following blog:

Pulling binaries from pcaps

Enjoy!

Thanks for this one, especially for the blog itself. Read once an article there but couldn't find the address anymore.
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 997


View Profile
« Reply #10 on: August 26, 2009, 12:29:14 PM »

I used the site too (about pulling hex from pcap). It allowed me to finish the ISC.SANS.Org puzzle. Which I actually had a lot of fun doing. While TCPXtract was close at pulling the file out, and it worked on my nix box with Open Office, it didnt' work on my office window's box with office 2k3 (with 2k7 plugin).
Logged

OSWP, Sec+
nebu10uz
Sr. Member
****
Offline Offline

Posts: 363



View Profile WWW
« Reply #11 on: August 26, 2009, 04:54:20 PM »


Hey chrisj, check this perl script out for extracting Office 2007 Metadata:

read_open_xml.pl

The script works, I tried against the docx file from the evidence pcap and it gave me some info such as the name of the file creator, creation and modify timestamp. Thats some cool info that you can include in your network forensic report.

You don't need the script to get this info but its quicker.
Logged

Security+, OSCP, CEH
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.167 seconds with 24 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.