Daily Blog #610: Sunday Funday 1/27/19 - Single Shellbags Entry Challenge

Single Shellbags Entry Challenge by David Cowen - Hacking Exposed Computer Forensics Blog



Hello Reader,
            Last week I may have asked a bit much, so I'm reeling myself back in. This week I've posted a lot of links to other peoples work as I've been teaching SANS FOR500 during the day at the CTI Summit and doing my case work at night. However thanks to great students sharing stories and asking great questions I'm walking away with even more insights and questions to answer. This week let's push our knowledge of shellbags forward.

The Prize:

$100 Amazon Giftcard

The Rules:

  1. You must post your answer before Friday 2/1/19 7PM CST (GMT -5)
  2. The most complete answer wins
  3. You are allowed to edit your answer after posting
  4. If two answers are too similar for one to win, the one with the earlier posting time wins
  5. Be specific and be thoughtful
  6. Anonymous entries are allowed, please email them to dcowen@g-cpartners.com. Please state in your email if you would like to be anonymous or not if you win.
  7. In order for an anonymous winner to receive a prize they must give their name to me, but i will not release it in a blog post


The Challenge:
Within a single shellbags entry answer the following:
1. What within the shellbags entry would tell you how the user had set their directory viewing preferences (sort order, thumbnail view, standard view)
2. What is the default view if they don't change anything?
3. If a user attempts to access the system volume information directory and a shellbag entry gets created (it should deny them access) what directory viewing settings are left behind


Also Read: Daily Blog #609

Post a Comment