Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 40 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow AIM attachments, NetWitness question
EH-Net
May 24, 2013, 07:57:14 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: AIM attachments, NetWitness question  (Read 9984 times)
0 Members and 1 Guest are viewing this topic.
305mia
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: August 21, 2009, 08:58:26 AM »

So I have an AIM conversation in which a document was exchanged via AIM's file sharing function.

NetWitness recreated the conversation from my pcap file and shows the document name.

I am having trouble reconstructing the attachment document. I know it is a word doc but how can I actually reconstruct the document?

Thanks in advance
Logged
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« Reply #1 on: August 21, 2009, 04:49:38 PM »


Hey, btw, are you doing the challenge that was posted in SANS?

Network Forensics Puzzle Contest

Because I am and basically I have answered almost all of their questions. The only thing I need is to reconstruct the doc file from the dump file.

I found this tool (tcpxtract) which is used for extracting files from network traffic based on file signatures including Word Documents. I haven't tried yet... I have to wait when I get home or over the weekend but try it and let me know if it works.

Hope this helps.
Logged

Security+, OSCP, CEH
Ketchup
Hero Member
*****
Offline Offline

Posts: 1021



View Profile
« Reply #2 on: August 22, 2009, 01:52:32 AM »

That's a great tool, blackazarro, thank you.   I just tested it on the problem you two are working on and I was able to get the file pretty quickly.  It didn't parse out the file a word doc because of the Office 2007 XML file format, but it definitely works and quite well. 
Logged

~~~~~~~~~~~~~~
Ketchup
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« Reply #3 on: August 22, 2009, 07:12:45 PM »


It worked for me as well, I was able to get the files, now I just need to properly assemble it to calculate the hash and so forth. Have you accomplish this?
Logged

Security+, OSCP, CEH
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #4 on: August 22, 2009, 09:21:15 PM »

I saw when this hit ISC.SANS.ORG yesterday. My first thought was, this is great, but I don't even know where to start. I know I can load a pcap file into wireshark, but can't get it to go via tcpdump sadly  Sad .

I found in the file the person she was im'ing. I think. now I'm trying to figure out what I need to know so I can figure out howto extract the file.

Blackazarro, you're tool post up there was a stepping stone I needed. I'm actually trying this tonight, thinking I probably don't know enough to pull it off.

I'd like to see a walk through, with what tools were chosen and why at some point to learn from. I know go read the great books mentioned around here, starting with hacking for dummies. (though seriously I think my next read will be on how to improve my reading speed  Smiley ).

----
(added later):
Ok, so I got to the point where I have the xml files. Figured that one out while eating a bowl of cereal took all my will not to toss the bowl into the sink and run to the computer. Part I'm stuck at now, are reconstructing the file into the right format (from zip archive / xml) to get the last of the data.

What a way to spend a Saturday Night.
« Last Edit: August 22, 2009, 11:24:41 PM by chrisj » Logged

OSWP, Sec+
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #5 on: August 22, 2009, 11:34:11 PM »

I think I have everything but the magic number of the docx file. Doing the md5sum now. However I don't know if I did it right.

PM Me, and I'll share if you're interested. Everyone will laugh if I did it right. (I don't run windows at home, only Gnu\Linux, and at work I don't have window 2007), so I can't test if what I did to make the docx file was the right way or not.
Logged

OSWP, Sec+
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #6 on: August 23, 2009, 12:50:27 PM »

A couple of people (not me) have posted comments in the original thread on SANS. One even went as far as including a this is what I did post, with the answers.

I did it a different way, and my md5sum doesn't match his. Everything else does though... So now I'm curious.

(by the way, I got the magic number googling file signatures, probably not the way they expected but it worked for me).
Logged

OSWP, Sec+
nebu10uz
Sr. Member
****
Offline Offline

Posts: 368



View Profile WWW
« Reply #7 on: August 23, 2009, 06:42:09 PM »

There's nothing wrong searching the magic number via Google. This is exactly what I did.

I was able to reconstruct the docx using wireshark and a Hex editor. My md5 hash matches with the one posted in SANS commentaries. The tool tcpxtract help me a lot because I was able to extract the recipe contents and made me realize that the files extracted were zipped XML. This enticed me to research on the docx office 2007 format and such.

It was a cool challenge, to bad that someone posted his answers to SANs. Overall a good learning experience.

Oh yeah, in tcpxtract there's a config file where you can add new signatures. I don't know if docx is included, got to check that out. If not, I'm going to try to create a signature and add it to the config file to see if it works.
« Last Edit: August 24, 2009, 10:20:25 AM by blackazarro » Logged

Security+, OSCP, CEH
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #8 on: August 23, 2009, 10:26:56 PM »

blackazarro

actually, I just took the zip file from the tcpxtract and changed it to a docx file. I figured that'd work since tcpxtract didn't have a docx finger print, but the finger print does match the zip archive listed finger prints in the magic number file, that file uses.

It opened fine in Open Office.

I guess however tcpxtract pulls it out, changes the md5sum for the file. I'll have to find out how to do the wireshark and hex way later.

I agree, it was a lot of fun, and I did learn some stuff along the way.
Logged

OSWP, Sec+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.064 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.