{"id":85,"date":"2011-11-18T16:40:52","date_gmt":"2011-11-18T16:40:52","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=85"},"modified":"2015-04-08T05:20:34","modified_gmt":"2015-04-08T05:20:34","slug":"forensic-riddle-1","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2011\/11\/18\/forensic-riddle-1\/","title":{"rendered":"Forensic Riddle #1"},"content":{"rendered":"<p>I have always been interested in riddles and puzzles, and I have a lot of respect for people who create them. So, when I&#8217;ve been thinking of opening this blog I always had in mind a section that would be dedicated to riddles. The idea is of course\u00a0not new. I borrowed this particular one from <a title=\"Richard Wiseman's blog\" href=\"https:\/\/richardwiseman.wordpress.com\/blog-2\/\">Richard Wiseman<\/a> &#8211; one of my favorite authors. He posts a puzzle every Friday and provides an answer to it on Monday.<\/p>\n<p>So, stepping on giant&#8217;s shoulders I will be posting a new riddle every Friday as well. The topic will be forensics, malware analysis, and any sort of binary-data related fun facts. The goal is to post something short, simple, and relatively easy to crack, yet a bit quirky or with a twist, so that you may have fun and hopefully learn something new. Of course, if you are in the industry long enough, you will crack it in no time.<\/p>\n<p>I will start with something I have came up with 2 years ago while working for my previous employer. I modified it to avoid potential copyright issues, yet the fundamental principle stays the same. In a hindsight, it is not that difficult, yet I think the guys who faced it found it challenging at that time and their interesting approach to the problem (they generated a lot of ideas!) led me to post a few more riddles on our internal mail list.<\/p>\n<p>The Riddle:<\/p>\n<ul>\n<li>command executed on the same system<\/li>\n<li>command is &#8220;dir wimmount.sys&#8221;<\/li>\n<li>2 different windows, 2 different results<\/li>\n<li>why?<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2011\/11\/riddle1.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-127\" title=\"riddle1\" alt=\"\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2011\/11\/riddle1-300x156.png\" width=\"300\" height=\"156\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2011\/11\/riddle1-300x156.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2011\/11\/riddle1-1024x532.png 1024w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2011\/11\/riddle1.png 1138w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAnswer <a title=\"Forensic Riddle #1 \u2013 Answer\" href=\"https:\/\/www.hexacorn.com\/blog\/2011\/11\/21\/forensic-riddle-1-answer\/\">here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have always been interested in riddles and puzzles, and I have a lot of respect for people who create them. So, when I&#8217;ve been thinking of opening this blog I always had in mind a section that would be &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2011\/11\/18\/forensic-riddle-1\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[7],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/85"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=85"}],"version-history":[{"count":10,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/85\/revisions"}],"predecessor-version":[{"id":2971,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/85\/revisions\/2971"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=85"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=85"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=85"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}