본문 바로가기
포렌식/SANS Forensic Contest Puzzle

Puzzle #1: Ann’s Bad AIM

by HackingPractice 2026. 6. 3.
반응형

Anarchy-R-Us, Inc. suspects that one of their employees, Ann Dercover, is really a secret agent working for their competitor. Ann has access to the company’s prize asset, the secret recipe. Security staff are worried that Ann may try to leak the company’s secret recipe.

Security staff have been monitoring Ann’s activity for some time, but haven’t found anything suspicious– until now. Today an unexpected laptop briefly appeared on the company wireless network. Staff hypothesize it may have been someone in the parking lot, because no strangers were seen in the building. Ann’s computer, (192.168.1.158) sent IMs over the wireless network to this computer. The rogue laptop disappeared shortly thereafter.

“We have a packet capture of the activity,” said security staff, “but we can’t figure out what’s going on. Can you help?”

You are the forensic investigator. Your mission is to figure out who Ann was IM-ing, what she sent, and recover evidence including:

 

1. What is the name of Ann’s IM buddy?

Ann's 컴퓨터의 IP 주소 필터링하여 검색합니다.

 

 Follow → TCP Stream 통해 확인한 결과 Sec558user1  입니다.


2. What was the first comment in the captured IM conversation?

Here's the secret recipe... I just downloaded it from the file server. Just copy to a thumb drive and you're good to go


3. What is the name of the file Ann transferred?

recipe.docx


4. What is the magic number of the file you want to extract (first four bytes)?

recipe.docx => 504B0304


5. What was the MD5sum of the file?

8350582774e1d4dbe1d61d64c89e0ea1


6. What is the secret recipe?

반응형

'포렌식 > SANS Forensic Contest Puzzle' 카테고리의 다른 글

Puzzle #6: Ann’s Aurora  (0) 2026.06.03
Puzzle #5: Ms. Moneymany’s Mysterious Malware  (0) 2026.06.03
Puzzle #4: The Curious Mr. X  (0) 2026.06.03
Puzzle #3: Ann’s AppleTV  (0) 2026.06.03
Puzzle #2: Ann Skips Bail  (0) 2026.06.03