Uploaded by sarwaqoali2022

lab9 digital forensics

advertisement
1)→ Tell me the name of Anna's friend.
→ I decoded as a Instant Messaging
→ username : Sec558user1
2)→ Name the first comment in the captured IM a dialogue?
3)→ Tell me the name of the file that Anna sent.
→ I searched on the internet what port AIM uses to transfer and I found 5190 so I followed
the TCP stream.
4)→ Name the magic number of the file
you want to extract (the first 4 bytes).
→ I saved the file in raw
→ I opened in Hex editor online
→ the file signature of word PK and it stands for ‘Phil Katz’ the inventor of the ZIP file
format and the magic number is 50 4B 03 04
→ the word file signature is PK
5)→ Calculate the MD5sum of the file?
→ with networkminer you can find MD5 instead of on Linux
6)→ Provide a secret recipe.
→ I opened with networkminer in order to get the recipe.docx
Download