sec 503.5 case 2 solution. find a string in a packet

21
Sec 503.5 Case 2 Solution

Upload: maximillian-harris

Post on 30-Dec-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Sec 503.5 Case 2 Solution. Find a string in a packet

Sec 503.5 Case 2

Solution

Page 2: Sec 503.5 Case 2 Solution. Find a string in a packet

Find a string in a packet

Page 3: Sec 503.5 Case 2 Solution. Find a string in a packet

Find the string smsses.exe

Page 4: Sec 503.5 Case 2 Solution. Find a string in a packet

Frame 208 is the 1st Fragment

Page 5: Sec 503.5 Case 2 Solution. Find a string in a packet

Frame 209 gives us the last fragment frame

Page 6: Sec 503.5 Case 2 Solution. Find a string in a packet

Frame 231 is the Last Fragment and Contains the File Size

Page 7: Sec 503.5 Case 2 Solution. Find a string in a packet

Analyze>Follow TCP Stream shows the PE Header (MZ)

Page 8: Sec 503.5 Case 2 Solution. Find a string in a packet

Further into the stream is the end of the executable

Page 9: Sec 503.5 Case 2 Solution. Find a string in a packet

Save the raw file

Page 10: Sec 503.5 Case 2 Solution. Find a string in a packet

The extract_file.raw is considerably larger than SMSSES.EXE

(file size 24576)

Page 11: Sec 503.5 Case 2 Solution. Find a string in a packet

Open extract_file.raw in Hex Editor

Page 12: Sec 503.5 Case 2 Solution. Find a string in a packet

Locate the Header MZ or Hex 4D5A90

Page 13: Sec 503.5 Case 2 Solution. Find a string in a packet

Remove Packet Data before MZ Header

Page 14: Sec 503.5 Case 2 Solution. Find a string in a packet

File after removing bytes preceeding MZ Header

Page 15: Sec 503.5 Case 2 Solution. Find a string in a packet

24576 is 6000 in Hex

Page 16: Sec 503.5 Case 2 Solution. Find a string in a packet

Remove everything after the offset

Page 17: Sec 503.5 Case 2 Solution. Find a string in a packet

Find ics.exe

Page 18: Sec 503.5 Case 2 Solution. Find a string in a packet

Packet 8092 start of tranfer

Page 19: Sec 503.5 Case 2 Solution. Find a string in a packet

Packet 8093 shows last fragment is 8134 (which will have the file size)

Page 20: Sec 503.5 Case 2 Solution. Find a string in a packet

File size is 45056

Page 21: Sec 503.5 Case 2 Solution. Find a string in a packet

Total size of raw file