Honeynet Project
Scan of the Month 24
2002

OFFICAL RESULTS PAGES

Questions/Answer 5

Question:
What processes did you (the investigator) use to successfully examine the entire contents of each file?

Answer:
simmy jungle.doc  - deleted/Recovered

The "J" in Jimmy jungle.doc was replaced with hexadecimal value 5h "sigma".
-Replaced the "s" with the letter "J"

In regards to the Long File Name, the File ID "LFN" was replaced with "Del LFN".

-Did not change - no reason to do so.

In Regards to the DOS legal name (8+3 ), the File ID "File" was replaced with "Erased".
-Replaced the "sigma" with the "J", "Erased" was replaced with automatically replaced with "File".

The pointers in FAT for each cluster starting at cluster 2 up to and including cluster 41 were zeroed (0) out.

-Clusters 2 up to and including cluster 41 were re-chained in FAT

The data area was left untouched.

-No modifications were performed in the data area of the