Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 45 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Forensicsarrow VoIP Forensics failure(s)
EH-Net
May 21, 2013, 02:35:27 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: VoIP Forensics failure(s)  (Read 7253 times)
0 Members and 1 Guest are viewing this topic.
sil
Hero Member
*****
Offline Offline

Posts: 549



View Profile WWW
« on: July 24, 2010, 01:10:59 PM »

So I participated in the VoIP Forensics challenge earlier this year (http://www.honeynet.org) and I could have swore I'd be at least third. How wrong I was:

Quote
With your score of 57, you came into position 7. You placed into the top third. With the many great submissions and the competitive field, this is a great accomplishment. Congratulations.

Below you will find your score per answer:
    Answer 1.1 (1point): 1 points
    Answer 1.2 (1point): 1 points
    Answer 1.3a (1point): 1 points
    Answer 1.3b (1point): 1 points
    Answer 1.3c (2points): 2 points
    Answer 1.4a (2points): 2 points
    Answer 1.4b (6points (2 each)): 6 points
    Answer 1.5 (1point): 1 points
    Answer 1.6 (3points): 3 points
    Answer 1.7 (5points): 4 points
    Answer 1.8a (3points): 3 points
    Answer 1.8b (3points): 3 points
    Answer 2.1 (4points): 4 points
    Answer 2.2a (1points): 1 points
    Answer 2.2b (1points): 0 points
    Answer 2.3 (2points): 2 points
    Answer 2.4 (2points): 2 points
    Answer 2.5a (10points): 10 points
    Answer 2.5b (3points): 3 points
    Answer 2.5c (2points): 2 points
    Answer 2.6 (3points): 1 points
    Answer 3.1 (2points): 2 points
    Answer 3.2 (2points): 1 points
    Answer 3.3 (2points): 1 points

My faults if I had to analyze them, is rushing through the contest. The contest was announced the 1st of June and my results were submitted 3 hours after seeing the contest: (From an email I sent to their moderators concerning my submission)

Quote
I submitted my files approximately two minutes ago (06/01/2010 4:34PM
EST) and just wanted confirmation they went through. ...

Anyhow, I will contact the staff @ Honeynet to see if I can do a write-up about the steps I took to analyze the content, tools I used, methodologies I used. AFTER my submission I did notice a "damnit can't believe I forgot that!" But, we live and we learn. Moral of this story, take your time. In a forensics examination, someone's life could potentially be in your hands. Unlike a contest you CANNOT rush through analysis', this happened to me also when I did the DC3 challenge.

For those performing or interested in performing VoIP analysis slash forensics, stay tuned. I hope to write a descriptive how-to explaining the tools I chose, why I chose them, how I used them and why some are better than others. For anyone wondering, no standard forensics tools were used (FTK, EnCase) but rather typical freely available tools.

Don, if you browse upon this thread, be advised when done (if I get the nod to write about the challenge) I will shoot you an email for the write-up.
Logged

hamdaalali89
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #1 on: June 03, 2012, 07:44:43 AM »

Hi Sil,
i was wondering what are the tools that can be used for VOIP forensics other than FTK and Encase? I have a project regarding the topic mentioned, and unfortunately i haven't found any logs regarding the matter.
it would be a lot of help if you can support me with info and tools.

Thanks.
 
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.056 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.