Prof. Price Lab 2 - Rhino Hunt!

Class: CYBR-405


Notes:

Questions

Q1

Do the reported hash values match the evidence?

Options:

Overall explanation:

Q2

How many files were visible (not deleted) on the USB thumb drive image?

Options:

Overall explanation:

Q3

How many image (picture) files did you recover from the file carve process?

Options:

Overall explanation:

Q4

How many recovered files from the USB image were rhino pictures?

Options:

Overall explanation:

Run the following command to open the .jpg files and inspect them:

feh *.jpg

Run the following command to open the .gif files and inspect them:

feh *.gif

Q5

Were any files recovered from the network captures?

Options:

Overall explanation:

Q6

Who gave the accused a telnet/ftp account?

Options:

Overall explanation:

Go to the Evidence directory and list all files:

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ ll
total 257132
drwxrwxr-x 2 root root      4096 Feb 27 13:13 ftp_capture
drwxrwxr-x 2 kali kali     12288 Feb 27 00:12 http_capture1
drwxrwxr-x 2 kali kali      4096 Feb 27 16:02 http_capture2
drwxrwxr-x 2 kali kali      4096 Feb 27 16:09 http_capture3
-rw-r--r-- 1 kali kali     41118 Feb 26 21:47 photorec.se2
drwxr-xr-x 2 root root      4096 Feb 26 21:56 recup_dir.1
drwxr-xr-x 2 root root      4096 Feb 26 21:47 recup_dir.2
-rw-r--r-- 1 kali kali    292604 Sep 15 12:04 rhino2.log
-rw-r--r-- 1 kali kali    226094 Sep 15 12:04 rhino3.log
-rw-r--r-- 1 kali kali   3187907 Sep 15 12:04 rhino.log
-rw-r--r-- 1 kali kali 259506176 Sep 15 12:04 RHINOUSB.dd

Use grep to search globally among all the files in the current directory:

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "jeremy" .
grep: ./RHINOUSB.dd: binary file matches
grep: ./recup_dir.1/f0335017_She_died_in_February_at_the_age_of_74.doc: binary file matches

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "mary" .

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "frederick" .

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "boudreaux" .

Used strings on the USB disk image:

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ strings RHINOUSB.dd | grep -i jeremy

Output:

m gonna reformat my USB key after this entry, but try not to destroy the good stuff.  I need to change the password on the gnome account that Jeremy gave me.  I can probably just do that at Radio Shack.

Just to check the second appearance of the word Jeremy, I will also run strings on the recovered file:

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ strings recup_dir.1/f0335017_She_died_in_February_at_the_age_of_74.doc | grep -i jeremy
m gonna reformat my USB key after this entry, but try not to destroy the good stuff.  I need to change the password on the gnome account that Jeremy gave me.  I can probably just do that at Radio Shack.

Q7

What’s the password for the account?

Options:

Overall explanation:

Q8

Do the network traces contain Rhino pictures?

Options:

Overall explanation:

Q10

Where is the hard drive that used to be in the computer?

Options:

Overall explanation:

I will use grep to find among all the files in the Evidence directory.

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "Radio Shack" .
grep: ./RHINOUSB.dd: binary file matches
grep: ./recup_dir.1/f0335017_She_died_in_February_at_the_age_of_74.doc: binary file matches

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "Mississippi" .
grep: ./RHINOUSB.dd: binary file matches
grep: ./recup_dir.1/f0335017_She_died_in_February_at_the_age_of_74.doc: binary file matches

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ grep -R -i "Tatooine" .

Now I will use strings to show the content around this appearances.

┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ strings RHINOUSB.dd | grep -i -C 10 "Radio Shack"

Output:

Feeling certain there was a curse upon my head, I gave up, returned home, and took a shower.
Do you have to be a gold member to put in background pics??
A little background: When I was 14, I had eye surgery to correct a birth defect. When I called them the other day to find out when they were open, I got someone very, very stern. And they sent a snotty fool down from Buffalo to run the store. However, after a while of dealing with her crap, management decided they wanted some more room in the store to put...whatever.  What
s the point.
Most of the rides we wanted to take were sold out, but we got to ride on a tall ship from 3-5, which is exactly what we wanted. I found this site that is full of surveys through some people who are now obsessed with the site.
Rhino pictures illegal?   Makes me sick.  I
 the photos
hehehehe.  Apparently, if there are less than 10 photos, it
s no big deal.
OK.  Things are getting a little weird.  I zapped the hard drive and then threw it into the Mississippi River.  I
m gonna reformat my USB key after this entry, but try not to destroy the good stuff.  I need to change the password on the gnome account that Jeremy gave me.  I can probably just do that at Radio Shack.
┌──(kali㉿kali)-[~/Desktop/ProfPriceLabs/Lab2/Evidence]
└─$ strings RHINOUSB.dd | grep -i -C 10 "Mississippi"

Output:

I still have to tell my Tom & Jerry story... probably tomorrow if I have time.
Feeling certain there was a curse upon my head, I gave up, returned home, and took a shower.
Do you have to be a gold member to put in background pics??
A little background: When I was 14, I had eye surgery to correct a birth defect. When I called them the other day to find out when they were open, I got someone very, very stern. And they sent a snotty fool down from Buffalo to run the store. However, after a while of dealing with her crap, management decided they wanted some more room in the store to put...whatever.  What
s the point.
Most of the rides we wanted to take were sold out, but we got to ride on a tall ship from 3-5, which is exactly what we wanted. I found this site that is full of surveys through some people who are now obsessed with the site.
Rhino pictures illegal?   Makes me sick.  I
 the photos
hehehehe.  Apparently, if there are less than 10 photos, it
s no big deal.
OK.  Things are getting a little weird.  I zapped the hard drive and then threw it into the Mississippi River.  I
m gonna reformat my USB key after this entry, but try not to destroy the good stuff.  I need to change the password on the gnome account that Jeremy gave me.  I can probably just do that at Radio Shack.

Q10

What happened to the USB key?

Options:

Overall explanation: