Forensic Identification of Unique Kali Systems Through the Use of File Hashes and Names
Total Page:16
File Type:pdf, Size:1020Kb
Forensic Identification of Unique Kali Systems Through the Use of File Hashes and Names Troy Ward January 25, 2021 Troy Ward Table of Contents Introduction .................................................................................................................................................. 4 Kali Linux ....................................................................................................................................................... 4 Methodology ................................................................................................................................................. 4 Analysis ......................................................................................................................................................... 5 Unique Names ............................................................................................................................................... 6 Eth0.lease .................................................................................................................................................. 6 Font Config ................................................................................................................................................ 7 LightDM ..................................................................................................................................................... 8 System.Journal .......................................................................................................................................... 9 Hashes ........................................................................................................................................................... 9 /boot ....................................................................................................................................................... 11 Initrd.img............................................................................................................................................. 11 grub.cfg ............................................................................................................................................... 11 /etc .......................................................................................................................................................... 12 adjtime ................................................................................................................................................ 12 cacerts ................................................................................................................................................. 13 fstab .................................................................................................................................................... 14 machine-id .......................................................................................................................................... 14 resume ................................................................................................................................................ 15 server_config.yml ............................................................................................................................... 15 shadow ................................................................................................................................................ 16 ssh_host_*_key................................................................................................................................... 18 ssl_cert_snakeoil ................................................................................................................................. 19 Wired Connection 1 ............................................................................................................................ 20 /usr .......................................................................................................................................................... 20 .uuid .................................................................................................................................................... 20 classes.jsa ............................................................................................................................................ 21 pyc files ............................................................................................................................................... 21 /var .......................................................................................................................................................... 23 .Xauthority .......................................................................................................................................... 23 aux-cache ............................................................................................................................................ 23 boot_duration ..................................................................................................................................... 23 cookie .................................................................................................................................................. 24 default_cert.pem ................................................................................................................................ 24 Index.db .............................................................................................................................................. 25 kali-amd64 .......................................................................................................................................... 26 mlocate.db .......................................................................................................................................... 26 MySQL files ......................................................................................................................................... 26 pubring.kbx ......................................................................................................................................... 27 questions.dat ...................................................................................................................................... 27 random-seed ....................................................................................................................................... 28 timestamps ......................................................................................................................................... 29 Conclusion ................................................................................................................................................... 30 Appendix 1: Always Unique Hashes ............................................................................................................ 31 Appendix 2: Uniquely Named Files ............................................................................................................. 36 2 1/25/2021 Troy Ward Table of Tables Table 1 Count of Files by Directory ............................................................................................................... 5 Table 2 Top 20 Repeated Hashes ................................................................................................................ 10 Table 3 Byte Comparison of /usr/lib/python3/dist- packages/IPython/core/__pycache__/application.cpython-38.pyc ........................................................... 22 Table 4 Always Unique Hash Listing ............................................................................................................ 35 Table 5 Uniquely Named Files ..................................................................................................................... 37 Table of Figures Figure 1 Network Interface Card UID/Lease Comparison ............................................................................. 6 Figure 2 NIC UID Appearances in Logs .......................................................................................................... 6 Figure 3 Uniquely named files located in /var/cache/fontfig ....................................................................... 7 Figure 4 /etc/machine-id and /var/lib/lightdm/.configure/pulse comparison ............................................ 8 Figure 5 /etc/machine-id vs /var/log/journal/<UID> Comparison ............................................................... 9 Figure 7 /boot/grub/grub.cfg Differences .................................................................................................. 12 Figure 8 /etc/adjtime differences ............................................................................................................... 13 Figure 9 File Comparission of /etc/ssl/certs/java/cacerts .......................................................................... 13 Figure 10 /etc/fstab differences ................................................................................................................. 14 Figure 11 /etc/machine-id Comparison ...................................................................................................... 15 Figure 12 /etc/initramfs-tools/conf.d/resume Differences ........................................................................ 15 Figure 13 /etc/king-phisher/server_config.yml Comparison ....................................................................