• “WireDive is a combo traffic analysis exercise that contains various traces to help you understand how different protocols look on the wire where you can evaluate your DFIR skills against an artifact you usually encounter in today’s case investigations as a security blue team member.”

DHCP

Question 1

  • “What IP address is requested by the client?”

Question 2

  • “What is the transaction ID for the DHCP release?”

alttext

Answer: 0x2a7d544b

Question 3

  • “What is the MAC address of the client?”

Answer: 00:0c:29:82:f5:94

DNS

Question 1

  • “What is the response for the lookup for flag.fruitinc.xyz?”

alttext

Answer: ACOOLDNSFLAG

Question 2

  • “Which root server responds to the google.com query? Hostname.”

alttext

SMB

Question 1

  • “What is the path of the file that is opened?”

Answer: HelloWorld\TradeSecrets.txt

Question 2

  • “What was the hex status code when the user SAMBA\jtomato logs in?”

alttext

Answer: 0xc000006d

Question 3

  • “What is the tree that is being browsed?”

alttext

Answer: \\192.168.2.10\public

Question 4

  • “What is the flag in the file?”

alttext

CONSOLE
$ grep 'flag' TradeSecrets.txt
flag <OneSuperDuperSecret>
Click to expand and view more

Answer: OneSuperDuperSecret

Shell

Question 1

  • “What port is the shell listening on?”

Question 2

  • “What is the port for the second shell?”

alttext

Question 3

  • “What version of netcat is installed?”

alttext

Answer: 1.10-41.1

Question 4

  • “What file is added to the second shell”

alttext

Answer: /etc/passwd

Question 5

  • “What password is used to elevate the shell?”

Answer: *umR@Q%4V&RC

Question 6

  • “What is the codename of the target system’s OS version?”

alttext

Answer: Bionic

Question 7

  • “How many users are on the target system?”

Answer: 30

Network

Question 1

  • “What is the IPv6 NTP server IP?”

Answer: 2003:51:6012:110::dcf7:123

Question 2

  • “What is the first IP address that is requested by the DHCP client?”

Answer: 192.168.20.11

Question 3

  • “What is the first authoritative name server returned for the domain that is being queried?”

alttext

Answer: ns1.hans.hosteurope.de

Question 4

  • “What is the number of the first VLAN to have a topology change occur?”
  • “Switch encounters a topology change whenever it detects link status change on one of its interfaces due to a link or another switch failure. After detecting topology change within the network it generates a Topology Change Notification BPDU with all the information about the topology that is currently being used and sends it towards the root switch through its root port.” – GeeksForGeeks

Answer: 20

Question 5

  • “What is the port for CDP for CCNP-LAB-S2?”

Question 6

  • “What is the MAC address for the root bridge for VLAN 60?”

Answer: 00:21:1b:ae:31:80

Question 7

  • “What is the IOS version running on CCNP-LAB-S2?”

Answer: 12.1(22)EA14

Question 8

  • “What is the virtual IP address used for HSRP group 121?”

Answer: 192.168.121.1

Question 9

  • “How many router solicitations were sent?”
  • “The format for Router Solicitation (RS) Message is defined in RFC 4861. The format for a Router Solicitation (RS) Message is based on a normal ICMPv6 message format.” – OmniSecu
    alttext

alttext
Answer: 3

Question 10

  • “What is the management address of CCNP-LAB-S2?”

alttext

Answer: 192.168.121.20

Question 11

  • “What is the interface being reported on in the first SNMP query?”

alttext
Answer: Fa0/1

Question 12

  • “When was the NVRAM config last updated?”

alttext

Answer: 2017-03-03 21:02

Question 13

  • “What is the IPv6 of the RADIUS server?”

alttext

Answer: 2001:DB8::1812

HTTPS

Question 1

  • “What has been added to web interaction with web01.fruitinc.xyz?”

Answer: y2*Lg4cHe@Ps

Question 2

  • “What is the name of the photo that is viewed in slack?”

Answer: get_a_new_phone_today__720.jpg

Question 3

  • “What is the username and password to login to 192.168.2.1?”

Answer: admin:Ac5R4D9iyqD5bSh

Question 4

  • “What is the certStatus for the certificate with a serial number of 07752cebe5222fcf5c7d2038984c5198?”

Answer: good

Question 5

  • “What is the email of someone who needs to change their password?”

Answer: Jim.Tomato@fruitinc.xyz

Question 6

  • “A service is assigned to an interface. What is the interface, and what is the service?”

alttext

Answer: lan:ntp

Copyright Notice

Author: Devobass

Link: http://localhost:1313/posts/misc/cyberdefenders/wiredive/

License: CC BY-NC-SA 4.0

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. Please attribute the source, use non-commercially, and maintain the same license.

Start searching

Enter keywords to search articles

↑↓
ESC
⌘K Shortcut