Digital Forensics Assignment 1
Exercise 1 File : 1.pcap Question : reconstruct the telnet session Q1 : who logged into ? – Username : ________ password :__________ Q2 : after logged in what did the user do?
Exercise 2 File : 02a.pcap & 02b.pcap Q1: 02a.pcap is a ___________ attempt. Q2: 02b.pcap is a ___________ attempt. Explain both of two files
Exercise 3 You’re an IT admin on company. You had a report that jono can not browse or sending with his laptop. After researching you found that raisa, sitting next to jono can browse without any problem File : jono.pcap & raisa.pcap Compare the capture file from both machines and find out why jono’s machine is not online
Exercise 4 File : 04.dmp Q1 : what kind protocol is used ? Q2 : this is conversation between _____ and ____ What do they say about you (sys/net admin)?
Exercise 4 File : 05ftp1.pcap Question – Q1 : is FTP _____ – Q2 : is FTP ______ – Q3 : FTP Err Code 503 means ________ – Q4 : attempt to _____ (explain!)