Question

RYERSON UNIVERSITY Page 1 of 15 Assignment 2: Encryption and Security Protocols 100 Marks The pure purpose of this assignment is to sample application layer services. Using packet capturing software,

you will be demonstrating the basic concepts of the OSI, Specifically HTTP, FTP, SSL, Telnet, and SSH protocols are demonstrated based on the stack. General Information and Policies - Solutions must to be submitted on through the blackboard system. - Ideal reports include screen snapshots of all of the exercises. Objectives Map the theoretical context of the material learned in class to their implementation in the real world. Dissect popular network services using protocols analysis software. Differentiate between network services based on the TCP/IP Reference Model. Demonstrate secure application layer protocols. Observe differences between Telnet and SSH. Observe differences between HTTP and HTTPS Demonstrate the process of RSA encryption and decryption. - - - - - Keywords IP, ipconfig, netstat, promiscuous mode, HTTP, FTP, HTTPS, SSL, SSH, Telnet, TCP, UDP, RSA. Readings and Resources: Review the "Introduction to Wireshark" video. http://wiresharkdownloads.riverbed.com/video/wireshark/introduction-to- wireshark/ - Read pages 1-3 of Chapter-1 (The WireShark User's Guide). Review Week-1 and Week-2 Lecture notes. Read about the functionalities of the keywords above. Deliverables Answers to the Pre-Lab environment auditing information. Wireshark Exercises. Encryption problems. TED ROGERS SCHOOL OF RYERSON MANAGEMENT UNIVERSITY (C)ITM 820 Information Systems Security and Privacy RYERSON UNIVERSITY PartA: Wireshark Packet Sniffing - 70Marks (C)ITM 820 The Wireshark Network Analyzer [Wireshark 1.6.5 (SVN Rev 40429 from /trunk-1.6)] File Edit View Go Capture Analyze Statistics Telephony Tools Internals Help Filter: Capture Interface List Live list of the capture interfaces (counts incoming packets) Start capture on interface: QQQQQUA The World's Most Popular Network Protocol Analyzer WIRESHARK Version 1.6.5 (SVN Rev 40429 from /trunk-1.6) Atheros L1C PCI-E Ethernet Controller Microsoft Microsoft Sun VMware Virtual Ethernet Adapter VMware Virtual Ethernet Adapter Capture Options Start a capture with detailed options Page 2 of 15 Capture Help Ready to load or capture Open Recent: Files Open Open a previously captured file Same as Capture/Options menu or toolbar item Expression... Clear Apply Sample Captures A rich assortment of example capture files on the wiki 111 No Packets Information Systems Security and Privacy Profile: Default SCHOOL OF RYERSON MANAGEMENT UNIVERSITY TED ROGERS O Lim X Online Website Visit the project's websi User's Guide The User's Guide (local Security Work with Wireshark as Part-A: Wire RYERSON UNIVERSITY - From the Edit menu, select Edit Preference: - Click Apply. (C)ITM 820 Wireshark: Preferences - Profile: Default Capture User Interface. Layout Columns Font Colors Capture Printing Name Resolution Statistics Protocols Page 3 of 15 Help Copy Find Packet... Find Next Find Previous Mark Packet (toggle) Toggle Marking Of All Displayed Packets Mark All Displayed Packets Unmark All Displayed Packets Find Next Mark Find Previous Mark Ignore Packet (toggle) Ignore All Displayed Packets (toggle) Un-Ignore All Packets Set Time Reference (toggle) Un-Time Reference All Packets Find Next Time Reference Find Previous Time Reference Configuration Profiles... Preferences... - From User Interface tab, select Capture Deselect the "``Capture packets in promiscuous mode`` option Interfaces: Capture packets in promiscuous mode: Capture packets in pcap-ng format: Update list of packets in real time: Automatic scrolling in live capture: Hide capture info dialog: Syntax check capture filter: Shift+Ctrl+Alt+M Shift+Ctrl+M Ctrl+Alt+M Shift+Ctrl+N Shift+Ctrl+B V Ctrl+F Ctrl+N Ctrl+B ✔ 7 Ctrl+M Information Systems Security and Privacy Ctrl+D Shift+Ctrl+D Ctrl+Alt+D Default interface: soft: \Device\NPF (3C0EA006-040B-4CA5-AE4D-7BE134D689BA} Ctrl+T Ctrl+Alt+T Ctrl+Alt+N Ctrl+Alt+B Shift+Ctrl+A Shift+Ctrl+P 4 OK Edit... Apply OOX TED ROGERS SCHOOL OF RYERSON MANAGEMENT UNIVERSITY Cancel RYERSON UNIVERSITY - What is promiscuous mode? - Click on ``Interfaces List`` and Start the capturing service for all physical interfaces on your computer. (C)ITM 820 Capturing from Microsoft [Wireshark 1.6.5 (SVN Rev 40429 from /trunk-1.6)] File Edit View Go Capture Analyze Statistics Telephony Iools Internals Help Filter: No. Page 4 of 15 < Time 1 0.000000000 fe80::b110:8497:f41a:iff02::c 2 2.340446000 Tp-LkT_d1:06:57 3 3.000767000 fe80::b110:8497:f41a::ff02::c 4 3.536405000 192.168.0.10 5 3.658952000 157.55.1.215 6 3.858498000 192.168.0.10 7 4.318237000 192.168.0.11 Source Destination Broadcast ✓ Expression... Clear Apply Protocol SSDP ARP SSDP TLSV1 TLSV1 TCP BROWSER 157.55.1.215 192.168.0.10 157.55.1.215 192.168.0.255 - Document your steps to be included in your lab report. 0000 33 33 00 00 00 0c 60 d8 0010 00 00 00 9a 11 01 fe 80 0020 84 97 f4 1a 70 54 ff 02 0030 00 00 00 00 00 0c ce b9 0040 53 45 41 52 43 48 20 2a 0050 21 - 10 of 72 71 3¬ 19 8f b5 9a 86 dd 60 00 00 00 00 00 00 00 b1 10 00 00 00 00 00 00 00 00 07 6c 00 9a 2e 8e 4d 2d 20 48 54 54 50 2f 31 2e 5h 16 16 20 27 3 3 13 1 Microsoft: File: C:... Packets: 7 Displayed: 7 Marked: 0 Frame 1: 208 bytes on wire (1664 bits), 208 bytes captured (1664 bits) + Ethernet II, Src: HonHaiPr_8f:b5:9a (60:d8:19:8f:b5:9a), Dst: IPv6mcast 00:00:00:0c (33: Internet Protocol Version 6, Src: fe80::b110:8497:f41a:7054 (fe80::b110:8497:f41a:7054), User Datagram Protocol, Src Port: 52921 (52921), Dst Port: ssdp (1900) Hypertext Transfer Protocol. Information Systems Security and Privacy 33.... TED ROGERS SCHOOL OF RYERSON MANAGEMENT UNIVERSITY ...PT.. SEARCH * Length Info L .1....M- HTTP/1. [rrnoi.r Profile: Default 208 M-SEARCH * HTTP 42 who has 192.168. 208 M-SEARCH * HTTP, 81 Application Dat 81 Application Dat 54 49313> pop3s [ 251 Local Master An >> RYERSON UNIVERSITY Page 5 of 15 1. HTTP Demonstration: Download the PuTTY for Telnet utility using Hypertext Transfer Protocol This section demonstrates a method for downloading a file using the Hypertext Transfer Protocol. 1.1 Open your Internet browser and request the Putty download page using the following URL: http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html 1.2 Make sure that your WireShark is running and from the Capture Menu click Restart. 1.3 Switch to Putty Homepage using Alt-key and Tab-key. 1.4 From the Putty Homepage, click on puttytel.exe hyperlink and download the file. TED ROGERS SCHOOL OF RYERSON MANAGEMENT UNIVERSITY For Windows on Intel x86 PuTTY: putty.exe PuTTYtel puttytel exe (C)ITM 820 (or by FTP) (or by FTP) 1.5 On the WireShark Capture menu, click stop. 1.6 Save the captured segment in the file: http-puttytel.pcap 1.7 On the Putty Homepage: Right-click the mouse on the on puttytel.exe hyperlink and select Properties. From the dialog box obtain the URL for the hyperlink. 1.8 From the hyper link extract the URL for the putty server: 1.9 Ping URL's domain. 1.10 Identify the IP address of the pinged server: 1.11 Display the segment of frames for that particular IP using the WireShark captured data. Information Systems Security and Privacy