Banner leads to the best police officer books written by over 220 state and local police officers who have authored over 550 books, many on law enforcement.

Trends, tactics and terrorism - Open Source Information for law Enforcement
Hi Tech Criminal Justice online
 Join our Newsletter

 Enter Your Email:
Privacy Policy

the latest book on leadership, leading and leaders

 Home Page | Links to Resources | Contact Us

Google


Members

Help

Home
Login | Register 




 Moderated by: cjustice  

New Topic

Reply

Print
AuthorPost
Gabrielelohim
Member
 

Joined: Sat Feb 16th, 2008
Location:  
Posts: 4
Status:  Offline
Mana: 
 Posted: Tue Apr 15th, 2008 09:09 pm

Quote

Reply
hello all,
got a forensic password recovery question... i promise that this IS REALLY A CLASS ASSIGNMENT and i'm not doing anything nefarious lol ;~)

we roll play in class and go through all the steps of a forensic examination / investigation, from getting a warrant / or permission from the company, to photographing the scene interviewing witnesses, writing reports etc. etc.etc.

anyway for this assignment we were hired by xxx company, to do a forensic examination on a particular employees machine. human resources is already involved, and the companies IT dept thinks that this particular workstation has been compromised...

among the 35k + files on the image, there are three (3) encrypted files, problem is they were encrypted using AES-256 bit encryption...

a known plain text attack doesn't seem to work although i may not have the correct plain text. but i'm sure that i have the correct compression scheme used to compress the files (PKZIp 9.0).

i exported a word list from the image, and have been running a dictionary attack against it using PRTK for about 18 hours now. so far no luck...

i have attached a copy of the file for you all to try if you would like and i would like to make it clear that if you DO crack the encryption i don't just want the answer. what i would like is some hints to point me in the right direction...

best regards,

gabrielelohim

Attachment: hardfile[19090][19090].zip (Downloaded 0 times)


 Current time is 02:18 am

Visit our Sponsors

Computer Forensics

Colleges and Universities

Phoenix University

Technology Schools

 

Powered by WowBB 1.7 - Copyright © 2003-2006 Aycan Gulez
cjhitech theme by: wowbbthemes.com
Page processed in 0.2663 seconds (15% database + 85% PHP). 18 queries executed.