Forensic

这篇博客介绍了ASIS-CTF2013中的网络取证分析题目,包括rm -rf、spcap、pcap和memdump等环节,探讨了这些有趣的热身题目。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

这种类型的题,比较有趣,大概是热身一类的题吧。

rm -rf (ASIS-CTF2013)

这道题,给了一个镜像文件。里面文件貌似挺多的。
不过直接用WinHex打开搜一下ASIS_密码就出来了。



spcap (ASIS-CTF2013)

这个题目名字的意思大概就是,simple pcap
拿Wireshark打开这个包,Statistics->Conversations 里面看到
有两个IP通信比较频繁


Statistics->Protocol Hierarchy Statistics
里面看到有一个图片格式的数据传输了




File - > export -> object 吧图片导出来,就可以看到Flag了





pcap (ASIS-CTF2013)

这题应该是比较难一点的,pcap
照例上wireshark    Statistics->Protocol Hierarchy Statistics 里面看到一些乱七八糟的东西,
虽然没大看懂但是还是装作很懂的看了一下。
一般情况下容易藏数据的地方在  HTTP traffic  TCP Data  UDP Data 这
Windows Forensic Analysis Toolkit: Advanced Analysis Techniques for Windows 7 provides an overview of live and postmortem response collection and analysis methodologies for Windows 7. It considers the core investigative and analysis concepts that are critical to the work of professionals within the digital forensic analysis community, as well as the need for immediate response once an incident has been identified. Organized into eight chapters, the book discusses Volume Shadow Copies (VSCs) in the context of digital forensics and explains how analysts can access the wealth of information available in VSCs without interacting with the live system or purchasing expensive solutions. It also describes files and data structures that are new to Windows 7 (or Vista), Windows Registry Forensics, how the presence of malware within an image acquired from a Windows system can be detected, the idea of timeline analysis as applied to digital forensic analysis, and concepts and techniques that are often associated with dynamic malware analysis. Also included are several tools written in the Perl scripting language, accompanied by Windows executables. This book will prove useful to digital forensic analysts, incident responders, law enforcement officers, students, researchers, system administrators, hobbyists, or anyone with an interest in digital forensic analysis of Windows 7 systems. Timely 3e of a Syngress digital forensic bestseller Updated to cover Windows 7 systems, the newest Windows version New online companion website houses checklists, cheat sheets, free tools, and demos
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值