Skip to content

Latest commit

 

History

31 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Computer-Forensics



Case-1: Dell Hacking Case

Scenario

On 09/20/04 , a Dell CPi notebook computer, serial # VLQLW, was found abandoned along with a wireless PCMCIA card and an external homemade 802.11b antennae. It is suspected that this computer was used for hacking purposes, although cannot be tied to a hacking suspect, G=r=e=g S=c=h=a=r=d=t. (The equal signs are just to prevent web crawlers from indexing this name; there are no equal signs in the image files.) Schardt also goes by the online nickname of “Mr. Evil” and some of his associates have said that he would park his vehicle within range of Wireless Access Points (like Starbucks and other T-Mobile Hotspots) where he would then intercept internet traffic, attempting to get credit card numbers, usernames & passwords.

Find any hacking software, evidence of their use, and any data that might have been generated. Attempt to tie the computer to the suspect, G=r=e=g S=c=h=a=r=d=t.v


1. What is the image hash? Does the acquisition and verification hash match?

Ans.aee4fcd9301c03b3b054623ca261959a, no acquistion hash found


2. What operating system was used on the computer?

Ans. Microsoft Windows XP Professional


3. When was the install date?

Ans. step-1: Go to the path:“C:\Windows\system32\config\Software\Microsoft\Windows NT\CurrentVersion\InstallDate."
     step-2: Thursday, August 19, 2004 10:48:27 PM UTC


4. What is the timezone settings?

Ans. Step-1: Go to the path:“C:\windows\system32\config\system\CurrentControlSet001\Control\TimeZoneInformation”.
     Step-2: Central Standard time.

5. Who is the registered owner?

Ans. Step-1: Go to the path:“C:\windows\system32\config\software\Microsoft\Windows NT\CurrentVersion\RegisteredOwner”.
     Step-2: Greg Schardt


6. What is the computer account name?

Ans. Step-1: Go to the path:“C:\windows\system32\config\SAM\Domains\Users\Names”
     Step-2: Mr.Evil


7. What is the primary domain name?

Ans. Step-1: Go to the path:“C:\windows\system32\config\software\Microsoft\Windows NT\CurrentVersion\Winlogon”
     Step-2: N-1A9ODN6ZXK4LQ


8. When was the last recorded computer shutdown date/time?

Ans. Step-1: Go to the path:“C:\windows\system32\config\system\CurrentControlSet001\Control\Windows\ShutdownTime”
     Step-2: C4 FC 00 07 4D 8C C4 01 


9. How many accounts are recorded (total number)?

Ans. Step-1: Go to the path:“C:\windows\system32\config\SAM\Domains\Users\Names."


Step-2: There are total 5 Accounts recorded Below

  • Administrator
  • HelpAssitant
  • Mr. Evil
  • Guest
  • HelpAssitant
  • Support_388945a0


10. What is the account name of the user who mostly uses the computer?

Ans. Mr. Evil logged into the system 15 times.


11. Who was the last user to logon to the computer?

Ans. Mr. Evil


12. A search for the name of “G=r=e=g S=c=h=a=r=d=t” reveals multiple hits. One of these proves that G=r=e=g S=c=h=a=r=d=t is Mr. Evil and is also the administrator of this computer. What file is it? What software program does this file relate to?

Ans. The name of the file is “irunin.ini” & the name of the software program is “Look@LAN”
The program name Look@LAN is an application that allows users to monitor the clients who are connected to network.
So in the irunin.ini file, it is mentioned that regowner is Greg Schardt while the LAN user is Mr. Evil which proves that user Mr. Evil & Greg Schardt both are same.


13. List the network cards used by this computer

Ans.There are two network cards: 
    1)Compaq WL110 Wireless LAN PC Card  
    2)Xircom CardBus Ethernet 100 + Modem 56
Go to the path:"C:\windows\system32\config\software\Microsoft\Windows NT\CurrentVersion\NetworkCards" 


14. This same file reports the IP address and MAC address of the computer. What are they?

Ans. IP Address  : 192.168.1.111
     MAC Address : 00:10:a4:93:3e:09
Go to the path:"C:\Program Files\Look@LAN\irunin.ini".


15. An internet search for vendor name/model of NIC cards by MAC address can be used to find out which network interface was used. In the above answer, the first 3 hex characters of the MAC address report the vendor of the card. Which NIC card was used during the installation and set-up for LOOK@LAN?

Ans. On looking for the MAC lookup we found out that company name was: XIRCOM
     So, the NIC card used for setup the Look@LAN is: Xircom CardBus Ethernet 100 + Modem 56 (Ethernet Interface)


16. Find 6 installed programs that may be used for hacking.

Ans. Here Six installed Programs that used for Hacking is below table.

Program Found Description
(1) 123WASP It used to get all stored passwords.
(2) Look@LAN Network Monitoring tool.
(3) Ethereal Packet sniffing tool.
(4) NetStumbler Wireless Networking tool.
(5) Cain & Abel Password Cracking tool.
(6) Anonymizer It is tool which is used to create a proxy.

17. What is the SMTP email address for Mr. Evil?

Ans. E-mail Address of Mr. Evil is : whoknowsme@sbcglobal.net
     To find this do the keyword search of SMTP.
     Then search for the file NTUSER.DAT, click on it and in the lower pane click on Text Tab. You will find it there.


18. What are the NNTP (news server) settings for Mr. Evil?

Ans.NNTP(news server) is: news.dallas.sbcglobal.net 
    NNTP User Name: whoknowsme@sbcglobal.net
    NNTP Password:news.dallas.sbcglobal.netF6E2BA30

For finding the server setting of NNTP search for the NNTP in the keyword and then look for the file NTUSER.DAT


19. What two installed programs show this information?

Ans.Forte Agent & MS Outlook Express reveals the email address of the Mr. Evil
Go to the path: Path: "C:\Document and Settings\Mr. Evil\NTUSER.dat\Software\Microsoft\Windows\CurrentVersion\UnreadMail\whoknowsme@sbcglobal.net\Application"
In these we will see that msimn application is the executable for Microsoft Outlook Express.


20. List 5 newsgroups that Mr. Evil has subscribed to?

Ans. List of 5 newsgropus that Mr.Evil has subscribed are:
     1)Alt.binaries.hacking.utilities 
     2)Alt.stupidity.hackers.malicious 
     3)Free.binaries.hackers.malicious 
     4)Free.binaries.hacking.talentless.troll_haven 
     5)alt.dss.hack
Go to the path:“C:\Document and Settings\Mr. Evil\Local Settings\Application Data\Identities\{EF086998–1115–4ECD-9B13 9ADC067B4929} \Microsoft\Outlook Express”


21. A popular IRC (Internet Relay Chat) program called MIRC was installed. What are the user settings that was shown when the user was online and in a chat channel?

Ans. User settings when the user was online are:
     1)user=Mini Me 
     2)email=none@of.ya
     3)nick=Mr
     4)anick=mrevilrulez
Go to the path:“C:\Program Files\mIRC\mirc.ini”.


22. This IRC program has the capability to log chat sessions. List 3 IRC channels that the user of this computer accessed.

Ans. List of 3 IRC channels that the user of this computer accessed are:
     1)Ushells.UnderNet.log
     2)m5tar.UnderNet.log
     3)CyberCafe.UnderNet.log
Go to the path:"C:\Program Files\mIRC\logs"


23. Ethereal, a popular “sniffing” program that can be used to intercept wired and wireless internet packets was also found to be installed. When TCP packets are collected and re-assembled, the default save directory is that users \My Documents directory. What is the name of the file that contains the intercepted data?

Ans. The name of the file which stores intercepted data is “interception”.
Go to the path:"C:\Documents and Settings\Mr. Evil\Application Data\Ethereal\recent"
On viewing the recent file we find that the location of the file which stores capture or intercepted data is “C:\Documents and Settings\Mr. Evil\interception”


24. Viewing the file in a text format reveals much information about who and what was intercepted. What type of wireless computer was the victim (person who had his internet surfing recorded) using?

Ans.The wireless computer that was used by the victim is: Windows CE (Pocket PC) - Version 4.20
Go to the path:"C:\Documents and Settings\Mr. Evil\interception".


25. What websites was the victim accessing?

Ans. The website accessed by the victim is: mobile.msn.com & MSN Hotmail
Go to the path:"C:\Documents and Settings\Mr. Evil\interception".


26. Search for the main users web based email address. What is it?

Ans. For these search in the web history which is present in the Data Artifacts.
     After searching through all the files, I found a file in which I found that 
     the user has a login to some FTP service using his email id.
     Yahoo! Mail - mrevilrulez@yahoo.com


27. Yahoo mail, a popular web based email service, saves copies of the email under what file name?

Ans.Setp 1: Go to Path Document and Settings/Mr. Evil/Local Settings/Temporary Internet Files/Contet.IE5/HYU1BON0/ShowLetter[1].htm
    The file found is: "ShowLetter[1].htm"


28. How many executable files are in the recycle bin?

Ans. There are 4 executable files in the recycle bin.
     Go to the path:"C:\RECYCLER\S-1–5–21–2000478354–688789844–1708537768–1003\".


29. Are these files really deleted?

Ans. No, they are not deleted. As they are in recyle bin we can restore it.

30. How many files are actually reported to be deleted by the file system?


Ans. For this look in the deleted files and we found out that there are total 1371 files that are deleted by the file system.


31. Perform a Anti-Virus check. Are there any viruses on the computer?

Ans. Autopsy itself performs an antivirus check & it shows its result inside Interesting Items.
     On seeing that we find out one zip bomb inside our computer whose location is
     
     Go to Path: "C:\My Documents\FOOTPRINTING \UNIX\unix_hack.tgz".


linkedin

About

This my repository for details about Computer Forensics each and every details are given to related computer forensics.

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors