The Challenge:
The folks from Digital Forensic Research WorkShop
have created a unique challenge for you. Your mission is to analyze a recovered
floppy and answer the questions below. What makes this challenge unique, you will
need to read the police report before continuing
your challenge. Just like an investigation in the real world, you will have some
background information and some evidence, but its up to you and your technical
skills to dig up the answers. Below is the dd image of the recovered floppy. This
is the image that will provide you the answers, providing you can 'extract' the
data.
Download:
image.zip MD5 = b676147f63923e1f428131d59b1d6a72 ( image.zip )
Make sure you check the MD5 checksum of your download before you unzip it.
Questions
You can find all the criteria for judging and rules at the SotM
main page.
- Who is Joe Jacob's supplier of marijuana and what is the address listed
for the supplier?
- What crucial data is available within the coverpage.jpg file and why is
this data crucial?
- What (if any) other high schools besides Smith Hill does Joe Jacobs
frequent?
- For each file, what processes were taken by the suspect to mask them from
others?
- What processes did you (the investigator) use to successfully examine the
entire contents of each file?
Bonus Question:
- What Microsoft program was used to create the Cover Page file. What is your
proof (Proof is the key to getting this question right, not just making a
guess).
Some URLs to help you out
The Results:
This months challenge questions, judging and team write-up are done by
the Digital Forensic Research WorkShop.
Also, Honeynet member Brian Carrier detailed how he analyzed the floppy image
using his OpenSource forensics tool, TASK.
Daniel J. Kalil, DFRWS
Brian Carrier
Writeup from the Security Community
We received over 90 submissions for the challenge, by far the most we have
ever received! After judging all of them, we decided to post only the
Top 30. We are hitting the point where we can no longer post ever single
entry as we are running out of resources. This will become a new
policy for SotM challenges, whenever we receive more then 30 submissions,
only the top 30 will be posted. We hope you folks will understand.
TOP 30
- Dennis Ruck
- Fox-IT Management Team
- Redhive Labs
- Eloy Paris
- Nick DeBaggis
- Chan Chun Fai
- Erik Cabetas
- Tyler Hudak
- CERIAS
- NCSU
- NST-NDCA
- Yoann Le Corvic
- Peter Mc Laughlin
- Charley Pfaff
- Jason Scheuerman
- Marc Bayerkohler
- Daniel Sedory
- Bill Moylan
- Bob Mathews
- Fox-IT Technical Team
- Nicola Gatta
- Jeff Craig
- Josh Berghouse
- Albert Bendicho
- Jeff Wichman
- Derek Marcotte
- John Henry
- Artjom Grudnitsky
- Azzazzin
- Barbara Pease
|