<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>I Smell Packets</title>
	<atom:link href="http://ismellpackets.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ismellpackets.com</link>
	<description>Sometimes they stink...</description>
	<lastBuildDate>Mon, 18 Jun 2012 20:35:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ismellpackets.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/d698264d715f47f73f28c624de28b235?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>I Smell Packets</title>
		<link>http://ismellpackets.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ismellpackets.com/osd.xml" title="I Smell Packets" />
	<atom:link rel='hub' href='http://ismellpackets.com/?pushpress=hub'/>
		<item>
		<title>The Spy Hunter, Part III &#8211; Solution Posted</title>
		<link>http://ismellpackets.com/2012/02/14/the-spy-hunter-part-iii-solution-posted/</link>
		<comments>http://ismellpackets.com/2012/02/14/the-spy-hunter-part-iii-solution-posted/#comments</comments>
		<pubDate>Tue, 14 Feb 2012 16:20:56 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[pcap]]></category>

		<guid isPermaLink="false">http://ismellpackets.wordpress.com/?p=378</guid>
		<description><![CDATA[The Spy Hunter, Part III – Solution posted. http://t.co/HPInnFD<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=378&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The Spy Hunter, Part III – Solution posted. <a href="http://t.co/HPInnFD">http://t.co/HPInnFD</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/378/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=378&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2012/02/14/the-spy-hunter-part-iii-solution-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;The Spy Hunter 3&#8243; Packet Challenge</title>
		<link>http://ismellpackets.com/2012/01/24/the-spy-hunter-3-packet-challenge/</link>
		<comments>http://ismellpackets.com/2012/01/24/the-spy-hunter-3-packet-challenge/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 15:40:56 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[pcap]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=370</guid>
		<description><![CDATA[+++++ Investigators’ briefing &#8211; Operation CHASTISE ++++ Operation NEPTUNE, whilst yielding significant intelligence product, also represented a gross failing of Yellow Sun’s personnel security procedures. An agent of the Adversary (now known to be the Sinister Icy Black Hand Of Death, aka SIBHOD) was unwittingly employed as part of NEPTUNE’s plan to conduct offensive operations. Once the agent (known as [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=370&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;"><span style="font-family:'Courier New';font-size:14px;"><img style="float:left;" src="http://ismellpackets.files.wordpress.com/2012/01/operationchastise.png?w=84&h=84" border="0" alt="OperationCHASTISE" width="84" height="84" /></span></p>
<p style="text-align:left;"><span style="font-family:'Courier New';font-size:15px;"><strong>+++++ Investigators’ briefing &#8211; Operation CHASTISE ++++</strong></span></p>
<p style="text-align:left;"><span style="font-family:'Courier New';font-size:12px;">Operation NEPTUNE, whilst yielding significant intelligence product, also represented a gross failing of Yellow Sun’s personnel security procedures. An agent of the Adversary (now known to be the Sinister Icy Black Hand Of Death, aka SIBHOD) was unwittingly employed as part of NEPTUNE’s plan to conduct offensive operations. Once the agent (known as Keith Starr, real name now known to be Kerry Nitpick) discovered the nature of his target he swiftly left Yellow Sun’s HQ either fearing exposing SIBHOD, or fearing SIBHOD’s harsh HR stance on errant staff&#8230;</span></p>
<div>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-family:Helvetica;font-size:12px;">The remainder of mission brief and the pcap can be downloaded from Google docs at the following URL:</span></p>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-family:Helvetica;font-size:12px;"><a href="http://bit.ly/xT7ZE3">http://bit.ly/xT7ZE3</a></span></p>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-size:12px;font-family:Helvetica;">The filenames are:</span></p>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-family:Helvetica;font-size:12px;">OperationCHASTISE.pdf</span></p>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-family:Helvetica;font-size:12px;">OperationCHASTISE.pcap</span></p>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-family:Helvetica;font-size:12px;">Send your answers to chris (dot) christianson (at) gmail (dot) com.</span></p>
<p><span style="border-collapse:collapse;color:#500050;font-family:Helvetica;font-size:12px;"> **************************** </span></p>
<p style="font-family:'Courier New';font-size:14px;"><span style="font-family:Helvetica;font-size:12px;">Disclaimer: All characters and organisations in this challenge are fictitious. Any resemblance to real or virtual persons, living or dead, is purely coincidental.</span></p>
<p><span style="font-family:Helvetica;font-size:12px;">This challenge requires you to interact with a live website. There is no need to probe or otherwise attack the website. All necessary information has been provided in the challenge materials, and if the domain name doesn’t contain the string “nybblecomms”, you’re in the wrong place. Any hostile activity directed at the site may result in the challenge being taken offline.</span><span style="font-family:'Courier New';font-size:14px;"></p>
<p><span style="font-family:Helvetica;font-size:12px;">******************************</span></p>
<p><a class="addthis_button" href="http://www.addthis.com/bookmark.php?v=250&amp;username=cchristianson"> <img style="border:0 initial initial;" src="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" alt="Bookmark and Share" width="125" height="16" /></a><br /></span></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/370/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=370&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2012/01/24/the-spy-hunter-3-packet-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>

		<media:content url="http://ismellpackets.files.wordpress.com/2012/01/operationchastise.png" medium="image">
			<media:title type="html">OperationCHASTISE</media:title>
		</media:content>

		<media:content url="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" medium="image">
			<media:title type="html">Bookmark and Share</media:title>
		</media:content>
	</item>
		<item>
		<title>The Spy Hunter, Part II – Solution posted.</title>
		<link>http://ismellpackets.com/2011/08/16/the-spy-hunter-part-ii-%e2%80%93-solution-posted/</link>
		<comments>http://ismellpackets.com/2011/08/16/the-spy-hunter-part-ii-%e2%80%93-solution-posted/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 07:09:52 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Spyhunter]]></category>

		<guid isPermaLink="false">http://ismellpackets.com/?p=365</guid>
		<description><![CDATA[The Spy Hunter, Part II – Solution posted. http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=365&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The Spy Hunter, Part II – Solution posted. <a href="http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/">http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/365/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/365/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/365/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/365/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/365/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/365/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/365/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/365/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=365&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/08/16/the-spy-hunter-part-ii-%e2%80%93-solution-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>
	</item>
		<item>
		<title>“THE SPY HUNTER 2” PACKET CHALLENGE CONTINUES</title>
		<link>http://ismellpackets.com/2011/08/13/%e2%80%9cthe-spy-hunter-2%e2%80%9d-packet-challenge-continues/</link>
		<comments>http://ismellpackets.com/2011/08/13/%e2%80%9cthe-spy-hunter-2%e2%80%9d-packet-challenge-continues/#comments</comments>
		<pubDate>Sat, 13 Aug 2011 01:00:06 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[Spyhunter]]></category>

		<guid isPermaLink="false">http://ismellpackets.com/?p=357</guid>
		<description><![CDATA[The &#8220;The Spy Hunter 2&#8243; Packet Challenge saga continues.  Go to Alec R Waters (@alecrwaters on twitter) blog at wirewatcher.wordpress.com for the rest of the story.  Results and Solution posted soon. Related articles The Spy Hunter, Part II &#8211; Epilogue (wirewatcher.wordpress.com) &#8220;The Spy Hunter 2″ Packet Challenge (ismellpackets.com) The Spy Hunter, Part II (wirewatcher.wordpress.com)<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=357&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The &#8220;The Spy Hunter 2&#8243; Packet Challenge saga continues.  Go to Alec R Waters (<a href="http://twitter.com/alecrwaters">@alecrwaters</a> on twitter) blog at <a href="http://wirewatcher.wordpress.com/2010/09/13/the-spy-hunter-solution/">wirewatcher.wordpress.com</a> for the rest of the story.  Results and Solution posted soon.</p>
<h6 class="zemanta-related-title" style="font-size:1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://wirewatcher.wordpress.com/2011/08/10/the-spy-hunter-part-ii-epilogue/">The Spy Hunter, Part II &#8211; Epilogue</a> (wirewatcher.wordpress.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ismellpackets.com/2011/07/13/the-spy-hunter-2-packet-challenge/">&#8220;The Spy Hunter 2″ Packet Challenge</a> (ismellpackets.com)</li>
<li class="zemanta-article-ul-li"><a href="http://wirewatcher.wordpress.com/2011/07/13/the-spy-hunter-part-ii/">The Spy Hunter, Part II</a> (wirewatcher.wordpress.com)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/357/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=357&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/08/13/%e2%80%9cthe-spy-hunter-2%e2%80%9d-packet-challenge-continues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;The Spy Hunter 2&#8243; Packet Challenge</title>
		<link>http://ismellpackets.com/2011/07/13/the-spy-hunter-2-packet-challenge/</link>
		<comments>http://ismellpackets.com/2011/07/13/the-spy-hunter-2-packet-challenge/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 13:01:56 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[pcap]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=353</guid>
		<description><![CDATA[+++++ Investigators’ briefing &#8211; Operation NEPTUNE +++++ In the wake of the Donald Burgess affair, Yellow Sun Heavy Industries finds itself in an uncomfortable situation. The top secret plans for Project ThatsNoMoon are in the hands of an unknown Adversary, and the traitorous Burgess has disappeared. Only by taking positive action of its own can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=353&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div style="padding:10px 20px;">
<div id="bodyText"><img style="float:left;" src="http://ismellpackets.files.wordpress.com/2011/07/screen-shot-2011-07-12-at-8-54-16-am.png?w=121&h=121" border="0" alt="Screen shot 2011 07 12 at 8 54 16 AM" width="121" height="121" /></p>
<p><span style="font-family:'Courier New';"><span style="font-family:'Courier New';font-size:15px;"><strong>+++++ Investigators’ briefing &#8211; Operation NEPTUNE +++++</strong></span></span></p>
<p><span style="font-family:'Courier New';">In the wake of the Donald Burgess affair, Yellow Sun Heavy Industries finds itself in an uncomfortable situation. The top secret plans for Project ThatsNoMoon are in the hands of an unknown Adversary, and the traitorous Burgess has disappeared. Only by taking positive action of its own can Yellow Sun hope to salvage the situation&#8230;</span></p>
<p>So begins the next chapter of Alec R Waters&#8217; Spy Hunter saga.</p>
<p>The remainder of mission brief and the pcap can be downloaded from Google docs at the following URL:</p>
<p><a href="http://goo.gl/kUbWo">http://goo.gl/kUbWo</a></p>
<p>The filenames are:</p>
<p>Operation NEPTUNE.pdf</p>
<p>OperationNEPTUNE.pcap</p>
<p>Send your answers to chris (dot) christianson (at) gmail (dot) com.</p>
<p><span style="border-collapse:collapse;color:#500050;font-size:13px;">﻿****************************</span></p>
<p>Disclaimer: All characters in this challenge are fictitious. Any resemblance to real or virtual persons, living or dead, is purely coincidental.</p>
<p>At no point in this challenge should you attack any system. All tasks can be accomplished by performing simple analysis.</p>
<p>There is malware embedded.</p>
<p>******************************</p>
<p><a class="addthis_button" href="http://www.addthis.com/bookmark.php?v=250&amp;username=cchristianson">﻿<img src="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" alt="Bookmark and Share" width="125" height="16" /></a></div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/353/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=353&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/07/13/the-spy-hunter-2-packet-challenge/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>

		<media:content url="http://ismellpackets.files.wordpress.com/2011/07/screen-shot-2011-07-12-at-8-54-16-am.png" medium="image">
			<media:title type="html">Screen shot 2011 07 12 at 8 54 16 AM</media:title>
		</media:content>

		<media:content url="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" medium="image">
			<media:title type="html">Bookmark and Share</media:title>
		</media:content>
	</item>
		<item>
		<title>Files Moving</title>
		<link>http://ismellpackets.com/2011/07/13/files-moving/</link>
		<comments>http://ismellpackets.com/2011/07/13/files-moving/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 13:01:07 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[pcap]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=350</guid>
		<description><![CDATA[Please note that files from all previous challenges have moved to the following url: http://goo.gl/kUbWo<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=350&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Please note that files from all previous challenges have moved to the following url:</p>
<p><a href="http://goo.gl/kUbWo">http://goo.gl/kUbWo</a></p>
<p><a class="addthis_button" href="http://www.addthis.com/bookmark.php?v=250&amp;username=cchristianson"><img style="border:0 initial initial;" src="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" alt="Bookmark and Share" width="125" height="16" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/350/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=350&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/07/13/files-moving/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>

		<media:content url="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" medium="image">
			<media:title type="html">Bookmark and Share</media:title>
		</media:content>
	</item>
		<item>
		<title>Solution to the &#8220;Check It Out&#8221; Packet Challenge using Scapy</title>
		<link>http://ismellpackets.com/2011/04/22/solution-to-the-check-it-out-packet-challenge-using-scapy/</link>
		<comments>http://ismellpackets.com/2011/04/22/solution-to-the-check-it-out-packet-challenge-using-scapy/#comments</comments>
		<pubDate>Fri, 22 Apr 2011 01:03:51 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[scapy]]></category>
		<category><![CDATA[Checksum]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=339</guid>
		<description><![CDATA[Here&#8217;s a nifty solution to the &#8220;Check It Out&#8221; Packet Challenge by StalkR (@stalkr_ on Twitter) that uses Scapy: StalkR writes: Just seen the challenge and wanted to try 1) save the hexdump on the blog post into packet.txt 2) turn it back into a hex string$ awk &#8216;$0!=&#8221;"{print $0}&#8217; packet.txt &#124;sed &#8216;s/ //g&#8217; &#124;tr -d &#8216;\n&#8217; &#62; packet.hex [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=339&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a nifty solution to the &#8220;Check It Out&#8221; Packet Challenge by StalkR (<a href="http://twitter.com/#!/stalkr_">@stalkr_</a> on Twitter) that uses Scapy:</p>
<p><strong>StalkR writes:</strong></p>
<p>Just seen the challenge and wanted to try <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>1) save the hexdump on the blog post into packet.txt</p>
<p>2) turn it back into a hex string<br />$ awk &#8216;$0!=&#8221;"{print $0}&#8217; packet.txt |sed &#8216;s/ //g&#8217; |tr -d &#8216;\n&#8217; &gt; packet.hex</p>
<p>3) run scapy<br />$ scapy<br />Welcome to Scapy (2.1.0)</p>
<p>4) load hex and decode<br />$ scapy<br />&gt;&gt;&gt; p = open(&#8216;packet.hex&#8217;).read().decode(&#8216;hex&#8217;)<br />&gt;&gt;&gt; p<br />&#8216;E\x00\x05\&#8217;\x00\x01@\x0[...]&#8216;</p>
<p>5) load it as an IP packet<br />&gt;&gt;&gt; p = IP(p)<br />&gt;&gt;&gt; p<br />&lt;IP  version=4L ihl=5L tos=0&#215;0 len=1319 [...] chksum=0&#215;0</p>
<p>6) remove chksum to force calculation<br />&gt;&gt;&gt; p.chksum = None</p>
<p>7a) force calculation of chksum either with show2()<br />&gt;&gt;&gt; p.show2()<br />###[ IP ]###<br />[...]<br /> chksum= 0xb27c</p>
<p>7b) or just turn packet into string and load it again:<br />&gt;&gt;&gt; &#8217;0x%04x&#8217; % IP(str(p)).chksum<br />&#8217;0xb27c&#8217;</p>
<p>&#8230;</p>
<p>Hurray for scapy \o/</p>
<p><strong>Chris continues:</strong></p>
<p style="font-family:'Lucida Grande';">Very cool use of scapy.  What other tools could we use to solve this?</p>
<p style="font-family:'Lucida Grande';font-weight:normal;">As always, if you&#8217;d like to submit a challenge to www.ismellpackets.com contact me at chris (dot) christianson (at) gmail (dot) com.</p>
<p><a class="addthis_button" href="http://www.addthis.com/bookmark.php?v=250&amp;username=cchristianson"><img style="border:0 initial initial;" src="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" alt="Bookmark and Share" width="125" height="16" /></a></p>
<p> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/339/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/339/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/339/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=339&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/04/22/solution-to-the-check-it-out-packet-challenge-using-scapy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>

		<media:content url="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" medium="image">
			<media:title type="html">Bookmark and Share</media:title>
		</media:content>
	</item>
		<item>
		<title>Solution to the &#8220;Check It Out&#8221; Packet Challenge</title>
		<link>http://ismellpackets.com/2011/04/19/solution-to-the-check-it-out-packet-challenge/</link>
		<comments>http://ismellpackets.com/2011/04/19/solution-to-the-check-it-out-packet-challenge/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 16:21:32 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[checksum]]></category>
		<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Checksum]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=331</guid>
		<description><![CDATA[﻿The winner of the &#8220;Check It Out&#8221; Packet Challenge is Jamie Starkel (@jstarkel on Twitter) Here&#8217;s Jamie&#8217;s solution: Jamie writes: Given the sample packet beginning with 4500 tells us a few things. The first is that the first byte (45) means that it is an IPv4 packet, and the 5 is the Internet Header Length, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=331&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="font-family:'Lucida Grande';">﻿The winner of the &#8220;Check It Out&#8221; Packet Challenge is Jamie Starkel (<a href="http://twitter.com/#!/jstarkel">@jstarkel</a> on Twitter) Here&#8217;s Jamie&#8217;s solution:</p>
<p><strong>Jamie writes:</strong><strong> </strong></p>
<p>Given the sample packet beginning with 4500 tells us a few things. The first is that the first byte (45) means that it is an IPv4 packet, and the 5 is the Internet Header Length, which is actually 20, because the field is measured in 32-bit multiples.</p>
<p>So our working set of bytes is the first 20:</p>
<p>4500 0527 0001 4000 4006 0000 c0a8 0102</p>
<p>c0a8 0101</p>
<p>Putting alongside the binary value makes the calculations easier.</p>
<p>I ended up with a table like the following:<br />Hex     Binary<br />4500    0100010100000000<br />0527    0000010100100111<br />0001    0000000000000001<br />4000    0100000000000000<br />4006    0100000000000110<br />0000    0000000000000000 &lt;&#8211; the checksum is set to zero<br />c0a8    1100000010101000<br />0102    0000000100000010<br />c0a8    1100000010101000<br />0101    0000000100000001</p>
<p>We are going to take the binary value of the first two bytes and add them together. Then we&#8217;ll take that result and add it to the next two bytes, and so on. If we need to carry a bit, we&#8217;ll go ahead and do that but drop the extra bit when adding it to the next two bytes since we have to keep them as 16-bit words. Once we get the eighth and last result, we&#8217;ll have to take the ones complement of it and that will give us our final checksum.</p>
<p>So here we go:</p>
<div class="im" style="color:#500050;">4500    0100010100000000<br />0527    0000010100100111<br />4a27    0100101000100111    &lt;&#8211; This is the 1st result.</p>
<p>4a27    0100101000100111    &lt;&#8211; First result plus next 16-bit word.<br />0001    0000000000000001<br />4a28    0100101000101000    &lt;&#8211; This is the 2nd result.</p>
<p>4a28    0100101000101000    &lt;&#8211; Second result plus next 16-bit word.<br />4000     0100000000000000<br />8a28    1000101000101000    &lt;&#8211; This is the 3rd result.</p>
<p>8a28    1000101000101000    &lt;&#8211; Third result plus next 16-bit word.<br />4006    0100000000000110<br />ca2e    1100101000101110    &lt;&#8211; This is the 4th result.</p>
<p>ca2e    1100101000101110    &lt;&#8211;Fourth result plus next 16-bit word.</p></div>
<p>c0a8    1100000010101000<br />18ad6  11000101011010110    &lt;&#8211; Fifth result has a carry bit. Since we need to keep these in 16-bit words, we add the carry bit to the result.</p>
<p>18ad6   11000101011010110<br />.8ad7     1000101011010111    &lt;&#8211; This is the final 5th result</p>
<p>8ad7    1000101011010111    &lt;&#8211; Final 5th result plus next 16-bit word<br />0102    0000000100000010<br />8bd9    1000101111011001    &lt;&#8211; This is the 6th result</p>
<p>8bd9    1000101111011001    &lt;&#8211;    Sixth result plus next 16-bit word.<br />c0a8    1100000010101000<br />14c81  10100110010000001    &lt;&#8211; Seventh result has a carry bit. Since we need to keep these in 16-bit words, we add the carry bit to the result.</p>
<p>14c81  10100110010000001<br />.4c82    0100110010000010    &lt;&#8211; This is the final 7th result</p>
<p>4c82    0100110010000010    &lt;&#8211;    Seventh result plus last 16-bit word.<br />0101    0000000100000001<br />4d83    0100110110000011    &lt;&#8211; Last result</p>
<p>4d83    0100110110000011<br />b27c    1011001001111100    &lt;&#8211; Ones complement of last result is the checksum</p>
<p>So the final checksum of this packet is b27c.</p>
<p> </p>
<p style="font-family:'Lucida Grande';"><strong>Chris continues:</strong></p>
<p style="font-family:'Lucida Grande';"><strong> </strong>Congrats Jamie! Even though there are many cool tools that can do this work for you, it&#8217;s nice to know how the checksum is actually calculated.  Speaking of cool tools, Thursday I&#8217;ll post a solution that was sent in using Scapy.</p>
<p style="font-family:'Lucida Grande';font-weight:normal;">Also, did anyone take a look at the payload? <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a class="addthis_button" href="http://www.addthis.com/bookmark.php?v=250&amp;username=cchristianson"><img src="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" alt="Bookmark and Share" width="125" height="16" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/331/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=331&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/04/19/solution-to-the-check-it-out-packet-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>

		<media:content url="http://s7.addthis.com/static/btn/v2/lg-share-en.gif" medium="image">
			<media:title type="html">Bookmark and Share</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Check It Out&#8221; Packet Challenge</title>
		<link>http://ismellpackets.com/2011/03/25/check-it-out-packet-challenge/</link>
		<comments>http://ismellpackets.com/2011/03/25/check-it-out-packet-challenge/#comments</comments>
		<pubDate>Fri, 25 Mar 2011 23:51:54 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Checksum]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=320</guid>
		<description><![CDATA[It&#8217;s time for another packet challenge.  This time the challenge is to calculate the IP Header checksum of the following packet: &#8212; 4500 0527 0001 4000 4006 0000 c0a8 0102 c0a8 0101 2b67 0014 0000 006f 0000 006f 5018 0200 aa32 0000 ffd8 ffe0 0010 4a46 4946 0001 0200 0064 0064 0000 ffec 0011 4475 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=320&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="font-family:'Lucida Grande';">It&#8217;s time for another packet challenge.  This time the challenge is to calculate the IP Header checksum of the following packet:</p>
<p style="font-family:'Lucida Grande';">&#8212;</p>
<p>4500 0527 0001 4000 4006 0000 c0a8 0102</p>
<p>c0a8 0101 2b67 0014 0000 006f 0000 006f</p>
<p>5018 0200 aa32 0000 ffd8 ffe0 0010 4a46</p>
<p>4946 0001 0200 0064 0064 0000 ffec 0011</p>
<p>4475 636b 7900 0100 0400 0000 0a00 00ff</p>
<p>ee00 0e41 646f 6265 0064 c000 0000 01ff</p>
<p>db00 8400 1410 1019 1219 2717 1727 3226</p>
<p>1f26 322e 2626 2626 2e3e 3535 3535 353e</p>
<p>4441 4141 4141 4144 4444 4444 4444 4444</p>
<p>4444 4444 4444 4444 4444 4444 4444 4444</p>
<p>4444 4444 0115 1919 201c 2026 1818 2636</p>
<p>2620 2636 4436 2b2b 3644 4444 4235 4244</p>
<p>4444 4444 4444 4444 4444 4444 4444 4444</p>
<p>4444 4444 4444 4444 4444 4444 4444 4444</p>
<p>4444 4444 44ff c000 1108 004f 004f 0301</p>
<p>2200 0211 0103 1101 ffc4 0075 0000 0203</p>
<p>0101 0000 0000 0000 0000 0000 0000 0401</p>
<p>0305 0602 0101 0000 0000 0000 0000 0000</p>
<p>0000 0000 0000 1000 0201 0204 0403 0308</p>
<p>0b00 0000 0000 0001 0203 0011 2131 1204</p>
<p>4151 6105 8122 1371 9132 a1b1 e142 5262</p>
<p>72d2 c1d1 8292 a233 7393 1415 0611 0100</p>
<p>0000 0000 0000 0000 0000 0000 0000 00ff</p>
<p>da00 0c03 0100 0211 0311 003f 00ec e8a2</p>
<p>8a08 a5e7 df6d f6e4 2cd2 2213 c198 0aa7</p>
<p>72cf 3c83 6d19 2a00 0d23 2e76 37b2 8ea6</p>
<p>c71e 0075 156c 1b28 36ea 4468 0039 9e27</p>
<p>da4e 2683 da6e 6274 f515 d4a0 cd81 b8af</p>
<p>50cc 93a0 9232 191b 222b 13bf 47b5 dbed</p>
<p>a57f 8257 52ab a0e9 2c7a 81f1 0e77 bd87</p>
<p>2a5b fe65 a6dc 6d2c 252a aacc 2c14 13cf</p>
<p>337e 7ca8 3a9a 2926 dbce b8c7 31bf 2915</p>
<p>48f9 029a 9837 4598 c530 d122 8d59 f948</p>
<p>e6a7 e7e4 7c2e 0e51 5153 4054 1c2a 6b27</p>
<p>be6f 7fc6 db32 a8bc 8e19 5074 b5d8 f82d</p>
<p>cfb7 0a05 e0ef 1b78 e52a f706 521e ff00</p>
<p>56ed 8229 e44a a83e 3577 fb19 774d e96c</p>
<p>d6ce 3095 e41e 58cf d9fb cc39 0c38 deb8</p>
<p>5ee6 026f 24c0 140f 80e8 b97b c575 bff3</p>
<p>bbaf 5142 31b9 2194 fe28 ec2f e28c bfbb</p>
<p>eda0 d28f b444 11c4 a4c9 2480 abc8 ff00</p>
<p>158f 2fb2 3a0a 3b3f 6c1d b213 0ab6 abb1</p>
<p>6bda d4de eb72 bb58 ccaf 7205 be11 7389</p>
<p>b655 306e 239d 03c6 da94 d05d 58bd fe29</p>
<p>1a38 de00 0cca fa50 3006 faf0 e387 5f0a</p>
<p>d2dc eee2 db0d 5230 5be4 389f 60cc f852</p>
<p>d0c7 26e6 513c ca51 13f9 4873 b916 2cc3</p>
<p>81b6 0070 c49c 6d60 bbb7 c524 5085 9459</p>
<p>b3d3 7be9 e97e 9f45 3945 1405 5524 4925</p>
<p>8b00 48bd ae39 e06d ed15 6d14 1c07 77ed</p>
<p>13a3 8529 e41e 5f58 02c0 afd5 d400 2750</p>
<p>1e53 cec0 df9e b765 edfb 8450 ea74 841a</p>
<p>53d4 4b6b d56b 9b5f 5016 0a01 cce2 4819</p>
<p>5753 4506 5b4c 2571 b4dd 2697 61a9 0a9f</p>
<p>29d3 63e5 3810 c33e 99dc d67c 9db2 4138</p>
<p>8a19 003a 492e cbe6 0320 d704 5df8 5f97</p>
<p>c57c 2ecf 7585 f73b adbc 31b9 423d 472c</p>
<p>83cc a2d6 cfad edf2 d7a6 ed02 02bb 8819</p>
<p>9a74 fad2 393a c715 3c05 f9db 038d 031b</p>
<p>2ed3 06d0 eb03 5ca7 e295 f162 7f47 8568</p>
<p>d2db 3dca ee63 f517 0372 aca7 3561 983d</p>
<p>47d3 4cd0 1451 4501 4514 5015 141a cc59</p>
<p>7773 ab59 3d33 6c14 f3ea d8df f657 a5e8</p>
<p>16d9 6ecc 9dc2 60c3 062d 1c67 fa5a 6e3d</p>
<p>ec4f 8568 c339 79a5 85f0 29a1 97f0 b0fc</p>
<p>c1ab 9e48 f7bd b1e3 32a0 941f 2974 c717</p>
<p>7b9b 5ed6 66be 937c f020 e62b 5f60 93bc</p>
<p>cdb8 dc80 8ccb a123 e3a6 f7bb 75e8 3e1f</p>
<p>1a0f 7b70 21df 4a83 2915 2523 8061 e53e</p>
<p>fb0f 7569 d677 6f53 297d d3e7 21d2 8392</p>
<p>2e5e 24dc 9f6d 68d0 1451 4501 4514 5015</p>
<p>54d2 a408 6490 e955 cc9a b694 dec3 14d1</p>
<p>6995 b4ad d7cd 7b63 7f2e 7867 6fd5 40af</p>
<p>aafb e68f 446e b12b eb2e f65d 416f 6b2d</p>
<p>f562 6c71 030a 6771 0c8d 224b 115b a061</p>
<p>66fb d6e5 ecaf 036f ba53 e59c 11f7 e204</p>
<p>ff00 0b27 cd53 e9ee f8c9 1ff6 cfe7 a0ce</p>
<p>2dbc d90d 2b8a 8bb6 95b3 d85f ecd9 1ac3</p>
<p>a5cf 4ad0 da6e de56 f4e5 02e5 43a3 21ba</p>
<p>ba9e 38d8 8e17 1ee2 6978 f692 068c 34cb</p>
<p>e507 4e85 b310 73c4 b361 e1cb 2a6b 670e</p>
<p>da2b 8db9 5370 326d 474e 36e2 70ce dc28</p>
<p>1da2 8a28 3fff d9</p>
<p>&#8212;</p>
<p>As always, best explanation wins. Send your answers to chris (dot) christianson (at) gmail (dot) com.</p>
<p> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/320/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=320&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/03/25/check-it-out-packet-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Ping me!&#8221; Packet Challenge Follow Up</title>
		<link>http://ismellpackets.com/2011/01/06/ping-me-packet-challenge-follow-up/</link>
		<comments>http://ismellpackets.com/2011/01/06/ping-me-packet-challenge-follow-up/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 05:37:26 +0000</pubDate>
		<dc:creator>cchristianson</dc:creator>
				<category><![CDATA[hping]]></category>
		<category><![CDATA[nping]]></category>
		<category><![CDATA[spoof]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[Packet Challenge]]></category>

		<guid isPermaLink="false">https://ismellpackets.wordpress.com/?p=311</guid>
		<description><![CDATA[This is a follow up to the &#8220;Ping me!&#8221; packet challenge.  In the previous post I asked how you could spoof MAC addresses using Nping and Hping.  Here is the answer: Using Nping # nping &#8211;icmp -c 1 &#8211;icmp-type 0 &#8211;dest-ip 192.168.200.128 &#8211;source-ip 192.168.200.129 &#8211;icmp-id 0 &#8211;icmp-seq 555 &#8211;data-string &#8216;Ping me!&#8217; &#8211;source-mac 00:0c:29:48:55:1f &#8211;dest-mac 00:0c:29:a6:5e:2f [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=311&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is a follow up to the &#8220;Ping me!&#8221; packet challenge.  In the previous post I asked how you could spoof MAC addresses using Nping and Hping.  Here is the answer:</p>
<p><strong>Using Nping</strong></p>
<p># nping &#8211;icmp -c 1 &#8211;icmp-type 0 &#8211;dest-ip 192.168.200.128 &#8211;source-ip 192.168.200.129 &#8211;icmp-id 0 &#8211;icmp-seq 555 &#8211;data-string &#8216;Ping me!&#8217; &#8211;source-mac 00:0c:29:48:55:1f &#8211;dest-mac 00:0c:29:a6:5e:2f</p>
<p> Starting Nping 0.5.35DC1 ( http://nmap.org/nping ) at 2011-01-02 09:34 PSTSENT (0.0000s) ICMP 192.168.200.129 &gt; 192.168.200.128 Echo reply (type=0/code=0) ttl=64 id=17243 iplen=36</p>
<p> Max rtt: N/A | Min rtt: N/A | Avg rtt: N/A<br /> Raw packets sent: 1 (50B) | Rcvd: 0 (0B) | Lost: 1 (100.00%)<br /> Tx time: 0.00083s | Tx bytes/s: 59952.04 | Tx pkts/s: 1199.04<br /> Rx time: 0.99989s | Rx bytes/s: 0.00 | Rx pkts/s: 0.00<br /> Nping done: 1 IP address pinged in 1.00 seconds</p>
<p>The following is the output from tcpdump:</p>
<p># tcpdump -i en1 -e  host 192.168.200.128<br /> tcpdump: verbose output suppressed, use -v or -vv for full protocol decodelistening on en1, link-type EN10MB (Ethernet), capture size 65535 bytes21:31:24.609114 00:0c:29:48:55:1f (oui Unknown) &gt; 00:0c:29:a6:5e:2f (oui Unknown), ethertype IPv4 (0&#215;0800), length 50: 192.168.200.129 &gt; 192.168.200.128: ICMP echo reply, id 0, seq 555, length 16</p>
<p><strong>Using Hping</strong></p>
<p>Hping doesn&#8217;t have the ability to spoof MAC addresses, but that still doesn&#8217;t prevent us from working around it.</p>
<p>The MAC address of most *nix machines can be changed by doing something close to the following:</p>
<p># ifconfig en1 ether 00:0c:29:48:55:1f</p>
<p>For instructions on how to change MAC addresses on other OSs see the following link:</p>
<p><a href="http://www.irongeek.com/i.php?page=security/changemac">Changing Your MAC Address In Window XP/Vista, Linux And Mac OS X </a><a href="http://www.irongeek.com/i.php?page=security/changemac">(Sometimes known as MAC spoofing)</a><a href="http://www.irongeek.com/i.php?page=security/changemac"><br /></a></p>
<p>That takes care of the source MAC address, but what about the destination MAC address?  This can be spoofed by creating a static ARP entry:</p>
<p>arp -S 192.168.200.128 00:0c:29:a6:5e:2f</p>
<p>Now just run hping as demonstrated in the previous post.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ismellpackets.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ismellpackets.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ismellpackets.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ismellpackets.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ismellpackets.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ismellpackets.wordpress.com/311/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ismellpackets.wordpress.com/311/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ismellpackets.wordpress.com/311/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ismellpackets.com&#038;blog=7494520&#038;post=311&#038;subd=ismellpackets&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ismellpackets.com/2011/01/06/ping-me-packet-challenge-follow-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/1c46d977fab3a1f00718b46a5c4a444c?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">Chris Christianson</media:title>
		</media:content>
	</item>
	</channel>
</rss>