# Computernetwerken 2

# 2009 januari examen

1. De 3 eerste berichten van een TCP-verbinding.
2. Leg uit: 
    1. BGP
    2. Tunnel en transport mode bij IPSec
    3. Tier 1, 2 en 3
    4. Internet Exchange
3. Leg uit: Probleem bij firewall bij FTP
4. jitter bij voip uitleggen
5. je krijgt een ip6-adres waar nullen of andere getallen weg zijn, en jij moet het omzetten naar het normale ip6-adres  
    vb: ABCD:1234::4567:48 = ABCD:1234:0000:0000:0000:0000:4567:0048
6. vragen over kerberos (kan ze niet zo meer zeggen maar er was een vraag over)
7. wat is onweerlegbaarheid
8. hoe kan je dit doen met RSA
9. waarom kan dat niet met met symetrishe encrypty
10. Invulvraag over subnetten + Omgekeerd wildcardmask.

# 2010 augustus examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

1. Verdeel 10.34.0.0/16 in subnetten voor minstens 600 computers
2. Gegeven: TCP logs, je moet kunnen uitleggen wat er gebeurd
3. Leg Kerberos in schemavorm uit. Wat is een ticket? Waarom kan deze niet nagemaakt worden?
4. Wat is PGP? Hoe zorgt dit voor integrieit en authentificatie?
5. Wat is onweerlegbaarheid?
6. Waar of niet waar?  
    Een isp moet betalen voor zijn internetverbinding  
    IP-telefonie gaat via UDP  
    Bij https wordt alles met het certificaat van de server versleutelt

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

1. Schrijf een oneliner die in usr/share/dict/dutch alle woorden zoekt die zonder letter en zonder cijfer beginnen (dus é à - mogen wel), geef daar de 8ste van.
2. Schrijf een oneliner die /ldapusers/kubeh/geheim/geheim.txt decodeerd met cypher -aes128 en dit in het bestand ontcijferd.txt in je homedirectory zet.
3. In de map van Kubeh staan er 5 gecrypteerde tekstbestanden, 1 ervan kan je ontcijferen met de publieke sleutel kubeh.pub, welke? Geef de (meerdere) commando's die je gebruikte.
4. Gebruik je kennis over het HTTP protocol om met netcat, grep en echo de grootte te weten van de afbeelding hallo.png die op onze webserver staat met poort 8000 (debbie.nwlab.khleuven.be)

# 2010 januari examen

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

Alles moet in 1 commando!

1. Maak de bestandsstructuur ~/dir1/dir2/dir3/dir4/ als dir1 nog niet bestaat (in 1 commando!).

 if \[ ! -d dir1 \];then mkdir -p dir1/dir2/dir3/dir4; fi

1. Decrypteer een file met een AES-algoritme en een gegeven paswoord en schrijf de uitvoer naar een file.
2. verplaats 10 '.jpg'-bestanden van een gegeven map naar je home dir en verander de extensies van jpg naar avi (in 1 commando!).

 mv /home/ldapusers/512345/Gegevenmap/\*.jpg .. | rename -f 's/\\.jpg$/.avi/' /home/ldapusers/512345/\*.jpg

1. haal uit een woordenlijst alle woorden waar een x EN een y in voorkomen, geef enkel het 10de resultaat weer.
2. geef alle 10 letterwoorden met 10 unieke letters weer. (TIP: back referencing)

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

1. Subnetten verdelen en in CIDR vorm kunnen opschrijven 
    1. 10.20.0.0 verdelen in subnetten die elk minstens 365 hosts bevatten
2. Gegeven: TCPdump fragment. IP-adres van de DNS server zoeken; enkele stappen uitleggen en de waarde van de volgende ACK-bit berekenen. (goed kijken naar de vorige lijen --&gt; Waarde kan je zo aflezen)
3. Beschrijf in schemavorm hoe Kerberos authenticatie werkt. Is deze bestendig tegen een replay aanval? Waarom wel/niet?
4. Wat is een digitale handtekening? Hoe zorgt dit voor integriteit en authenticiteit.
5. Wat is onweerlegbaarheid? Hoe zorgt het voor authenticatie en integriteit?
6. IPv6 adres voluit schrijven vb: A5C2:CBE5:C::ABB5:ABBC
7. Juist of fout? Licht toe met 1 zin: 
    1. NAT werkt niet met IPsec (AH) in tunnelmode , met esp wel
    2. DMZ is enkel beveiligd door controle van de router, op elke server moet nog beveiliging opkomen, op DMZ moet de buitenwereld op kunnen, op het bedrijfsnetwerk niet en is dus beter beschermd. Wel kan een firewall die meer als 2 interfaces gebruikt ook de DMZ beveiligen
    3. De routetabellen van de AS'en worden manueel bijgewerkt wrong... routetabellen worden up-to-date gehouden door dat ze naar elkaar berichten zetten die voldoen aan het BGP (inmiddels versie 4)
    4. Een ISP heeft er belang bij om een peering overeenkomst te hebben met elke andere ISP?
    5. VOIP gebruikt UDP en enkel udp omdat voIP een real-time toepassing
    6. PGP heeft certificaten en genereert een zogenaamde digitale vingerafdruk die kan gebruikt worden om na te gaan of een gebruiker echt is
    7. Via een certificaat is de eindgebruik zeker dat de server waarmee hij verbinding heeft gemaakt effectief de gevraagde server (en houder van het certificaat) is.

# 2011 augustus examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

- 4 ip-adressen van subnetten: (6.3.64.0/21, 6.3.72.0/21, 6.3.80.0/21, 6.3.88.0/21) 
    - Geef het subnetmasker van subnet 1
    - Geef het wildcardmasker van subnet 1
    - Geef het kleinste netwerk waar deze 4 subnetten afkomstig kunnen van zijn (6.3.64.0/19)
- Welke twee protocollen worden bij ip-telefonie gebruikt. Leg deze uit en geef voobeelden van de verzonden signalen (of iets in die trend was de vraag)
- Juist/fout 
    - een ipv6 adres, is deze wel of niet correct (was correct)
    - Als een wiskundige een algoritme bedenkt om uit een getal snel de vermenigvuldiging van 2 priemgetallen te krijgen. Wordt RSA makkelijk om te kraken.
    - SSL wordt gebruikt bij HTTPS (of iets in die zin, het was correct)
- Geef de volledige naam van de afkortingen en leg kort uit. 
    - PGP
    - DMZ
    - VPN
- Wat zijn de voor- en nadelen van zowel symmetrische als asymmetrische encryptie. Hoe kan men deze het beste combineren.
- Indien Alice contact wilt maken met Bob. Hoe kan ze er dan voor zorgen dat Trudy niet als 'man in the middle' fungeert. En dus haar publieke sleutel aan Alice doorgeeft en doet alsof ze Bob is.

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

- Maak vanuit de directory /home/user/tmp de file resources met daarin de file images in de file /home/user. U moet echter in dezelfde directory blijven(tmp)

Oplossing : mkdir -p ../resources/images

- Zorg ervoor dat u een leeg bestand kan aanmaken waarin de datum dat het werd aangemaakt in de titel komt. Stel dat u bijvoorbeeld dit commando zou runnen op 7 september 2011 moet het bestand er als volgt uitzien: versie\_070911.txt

Oplossing: touch versie\_`date +%d%m%y`.txt

- Stel dat u een file report.txt heeft van enkele alineas. Zorg ervoor dat alle regels die test bevatten NIET worden getoond.

Oplossing : grep -v 'test' report.txt

- Zorg ervoor dat u alle WOORDEN die exact uit 4 karakters bestaat uit het document report.txt naar het bestand output.txt worden weggeschreven.

Oplossing: grep -Eo '\[ \]+\[^ \]{4}\[ \]+' report.txt &gt; output.txt

- Versleutel een bestand topSecret.txt met 256-bit AES-encryptie en cipher-block chaining en geef als uitvoerbestand topSecret.aes

Oplossing: openssl enc -aes-256-cbc -in topSecret.txt -out topSecret.aes -k xfile

- Geef een lijst bestanden in een directory met twee kolommen (bestandsnaam en grootte), gesorteerd op grootte.

Een oplossing: ls -l -S | awk {'print $8 " " $5;'}

# 2011 januari examen

- IP-adressen met subnetmaskers berekenen
- IPv4 versus IPv6: wat is het verschil, en wat is er beter aan v6?
- Verklaar: 
    - Persistent HTTP
    - BGP (Border Gateway Protocol)
    - RTP (Realtime Transport Protocol)
    - Signature-based IDS (Intrusion Detection System)
- Er worden 4 subnetten gegeven die aan een router zijn verbonden. Stel de ACL (Access Control List) op met vijf restricties/permissies). Het wildcard masker moet gekend zijn!
- Vragen over restricties.
- Cipher Block Chaining: wat is het?
- Diffie-Hellman in schemavorm uitleggen. Hoe kan je daar misbruik van maken (Man In The Middle).
- PGP in schema: wat gebeurt er als je de hash wegdoet, is dan integriteit en confidentialiteit en authenticiteit nog in orde? Wat is er symmetrisch en assymetrisch aan? Wat kan Trudy doen om toch de boodschap teweten te komen en wat is de oplossing (certificaten gebruiken)?

# 2012 augustus examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

1. Analyse van pakketten 
    1. Zoek IP-adres van de DNS server
    2. Hoeveel TCP connecties worden er opgebouwt?
    3. In pakket x wordt een http request gedaan. In welk pakket nog en waarom ziet er dat niet uit zoals in pakket x?
    4. Hoeveel data is verstuurd tijdens de connectie tussen x en y die in pakketten a tot b wordt beëindigd? Kijken naar SYN en ACK bytes
2. Schema van een netwerk 
    1. Leg volgende begrippen uit aan de hand van een schema (schema moet je zelf tekenen) : intern net, demiliteraized zone, firewall, router, webserver.
    2. Plaats een ACL waarbij enkel inkomende verbindingen op poort 80 geaccepteerd worden op het schema om de webserver beter te beveiligen.
    3. Schrijf een gegeven IPv6 adress voluit.
3. Encryptie 
    1. Geef 2 algoritmes waarbij het niet belangrijk is dat de data geheim is. Leg beide kort uit.
    2. Geef een voorbeeld van een service die met UDP werkt en wat zijn de voordelen hiervan.
4. Waar of niet waar 
    1. Een wiskundige vind een snelle manier om een product in 2 priemgetallen op te splitsen, is het RSA in gevaar?
    2. Door de komst van asymmetrische sleutels zijn symmetrische sleutels eigenlijk niet meer nuttig.
    3. Een IPSEC AH (Authentication Header) zorgt ervoor dat de header van een IP-pakket niet meer veranderd kan worden door een digitale handtekening (iets in die trand).
5. Leg kort uit 
    1. Ticket (Kerberos)
    2. Diffie Helman
    3. Internet exchange
    4. VPN

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

1\. op debbie.vlan77.be staat 1 vd volgende poorten open: 1234,2345,3456,4567. Hoe kan je dit vinden in 1 lijn

2\. schrijf de output die men krijgt bij verbinding met deze poort weg in ~/tmp/vraag2.txt

3\. doe een ping, die dit 12 keer stuurt en om de 0,5 seconde

4\. (bepaald comando, weet niet meer dewelke) geeft alle actieve bestanden, geef een lijst met diegene die het meest actief zijn.

5\. iets van bob en alice willen met elkaar veilig communiceren (ze hebben al een sleutel)

# 2012 januari examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

1. Analyse van pakketten 
    1. Zoek IP-adres van de DNS server
    2. Wat gebeurd er in pakketten x tot y (was de 3-way handshake)
    3. In pakket x wordt een http request gedaan. In welk pakket nog en waarom ziet er dat niet uit zoals in pakket x?
    4. Hoeveel data is verstuurd tijdens de connectie tussen x en y die in pakketten a tot b wordt beëindigd? Kijken naar SYN en ACK bytes
    5. Wat betekent de 301 status code van een http response
2. Je krijgt de uitvoer van netstat te zien 
    1. Wat is het IPv4 adres van de server
    2. Is de server een webserver?
    3. Welke poort kan je alleen aanspreken met een IPv4 adres? Kijken naar poorten in tcp en tcp6-output
    4. Is \[IPv6-adres local van bovenstaande netstat uitvoer\] het IPv6 adres van de server? (Was onwaar omdat de poort erbij stond)
3. Alice wil veilig communiceren met Bob via zijn publieke sleutel. Hoe kan ze zeker zijn dat ze met Bob communiceert en niet met Trudy die de pakketten probeert te onderscheppen. Geef twee manieren hoe de uitwisseling veilig kan gebeuren en leg kort uit.
4. Een IPv6 adres voluit in hexadecimaal uitschrijven
5. Juist of fout + leg uit 
    1. Een pakketfilter ontdekt geen virussen
    2. Het Session Initiation Protocol dient om media (audio/video) te versturen
    3. Het IPSEC AH beschermd de gehele IP header
    4. Door de komst van asymmetrische sleutels zijn symmetrische sleutels eigenlijk niet meer nuttig.
6. Geef een voorbeeld van een service die met UDP werkt en leg uit waarom.
7. Verklaar 
    1. Ticket (Kerberos)
    2. Onweerlegbaar
    3. ACL (Access Control List)
    4. Peering

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

- Van elk hoofdstuk zo goed als 1 vraag
- Vragen: 
    - Toon met alleen netcat, grep en echo de grootte van een foto die op het internet staat. ([Oplossing Tom](http://pastebin.com/ZmNCfL4b))
    - Port-scan met netcat op 1 poort met alleen een handshake. Als de poort open is moet hij "Poort open" tonen, anders niets. 
        - if nc -z debbie.vlan77.be 80; then echo "Poort open"; fi
    - Toon het e-mailadres van een certificaat 
        - openssl x509 -in ABAecom\_=sub.\_\_Am.\_Bankers\_Assn.=\_Root\_CA.crt -email -noout
    - Verifieer met gpg enkele files. 
        - gpg --import &lt;publickey&gt;
        - find /home/test/gpg/ -type f -name 'tekst\*\\.txt\\.asc' -exec gpg --verify {} \\;
    - Toon hoeveel woorden beginnen met be en eindigen met en 
        - grep -E '^be(.\*)en$' /usr/share/dict/dutch | wc -w

# 2013 augustus examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

1. Analyse van pakketten 
    1. Zoek IP-adres van de DNS server
    2. Hoeveel TCP connecties worden er opgebouwd?
    3. In pakket x wordt een http request gedaan. In welk pakket nog en waarom ziet er dat niet uit zoals in pakket x?
    4. Hoeveel data is er verstuurd wanneer je aan pakket x en y zit?
2. Je verstuurt een mail via de server mx debbie, zeg hier bij wat er gebeurt en maak gebruik van de volgende termen: smtp, DNS protocol, routering, ARP protocol, client-server model.
3. Uitleggen bij een packet filter en een inspection firewall hoe dat je die kunt omzeilen als je gebruik maakt van passive ftp
4. Bob en Alice hebben elk een publieke sleutel, twee manier geven hoe dat Trudy deze niet kan onderscheppen
5. Waar of niet waar 
    1. Zonder CBC is bij AES niet mogelijk om afbeeldingen te beveiligen
    2. Bij handshake heeft men 2 nonces(ofzoiets)
    3. Iets van een versleuteling bij https
    4. Door de komst van asymmetrische sleutels zijn symmetrische sleutels eigenlijk niet meer nuttig.
6. Leg uit het is beter om IP spoofing te gebruiken bij een DOS dan gewoon de documenten te stelen(ofzoiets)
7. Termen uitleggen 
    1. Content type(http header)
    2. jitter
    3. http hijacking
    4. een tekening waarbij je moest zeggen wat er gebeurt

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

1. Een variant op ping waarbij je een automatische ICMP doet
2. Een reeks van mappen aanmaken(vb tmp/dir1/dir2/dir3 als dir 1 ng niet bestaat)
3. Een code kraken die op een website staat
4. je hebt bestanden cert.pem en cert.key je moest er voor zorgen dat die de juiste permissies kregen met chmod
5. Een oefening met tshark

# 2013 januari examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

1. Analyse van pakketten 
    1. Zoek IP-adres van de DNS server
    2. Hoeveel TCP connecties worden er opgebouwt?
    3. In pakket x wordt een http request gedaan. In welk pakket nog en waarom ziet er dat niet uit zoals in pakket x?
2. Zet wat er gebeurt als je naar www.khleuven.be surft met je browser en gebruik hierbij de volgende termen: HTTP protocol, DNS protocol, routering, ARP protocol.
3. Waar of niet waar + woordje uitleg. 
    1. Een wiskundige vind een snelle manier om een product in 2 priemgetallen op te splitsen, is het RSA in gevaar?
    2. Door de komst van asymmetrische sleutels zijn symmetrische sleutels eigenlijk niet meer nuttig.
    3. Een IPSEC AH (Authentication Header) zorgt ervoor dat de header van een IP-pakket niet meer veranderd kan worden door een digitale handtekening.
4. Leg de volgende termen uit: FTP in passive mode, VPN, en nog 2 anderen.
5. Een video player streamt een video, maar deze blijft steeds haperen. Geef 2 manieren om dit te vermijden. (Jitterbuffer is er 1 van)
6. Geef in schema vorm een woordje uitleg over recursieve en niet recursieve DNS queries.

# 2013-2014 samenvatting - Filip Scheir

De samenvatting voor 2013-2014 met dank aan Filip Scheir: [Samenvattingen-20210617T081040Z-001.zip](/attachments/13)

# 2014 augustus examen

1. Het verschil tussen ECB en CBC en waarom dat het een beter is dan het andere
2. Waarom dat P2P beter is in het distruburen van files dan client-server
3. Prefetchen uitleggen
4. Kan er gezegd worden dat een CA een "Thrusted Thirth Party" is bij PKI
5. Leg onweerlegbaarheid uit bij het gebruik van PGP
6. Het belang van een nonce binnen authenticatie
7. Wat is de cryptografische functie een CA
8. Het verschil tussen end-to-end vertraging en pakketjitter
9. Waar/Niet waar + Uitleg 
    1. Kan Jitter (Variatie Delay) opgelost worden door gebruik te maken van QoS
    2. Als een hacker de Publieke Sleutel van een website in handen krijgt heeft deze toegang tot alle sessies, en alle voorgaande sessies als deze werden opgenomen (Sniffing)
    3. Een Packet-filter kan geen virussen tegenhouden
    4. Voorbeelden van applicatie gateway zijn web cache en een server
    5. Als je zo snel mogelijk een bestand wil versturen naar een verre locatie (+15 hops) dan gebruik je TCP
    6. Er zijn minder regels bij een packetfilter om een bepaalde TCP communicatie toe te staan tussen client-server dan bij stateful inspection firewall
    7. In een DMZ (Demilitarized Zone) staan geen interne servers
    8. Bij VoiP loopt verkeer van alle gesprekken via de SIP proxys
    9. Een systeem dat gebruikt maakt van HMAC is gevoelig voor replayaanvallen

# 2014 januari examen

1. Waarom maakt een website gebruikt van cookies. Leg uit met behulp van een schema.
2. Waarom is een gedistribueerde hashtabel een 'HASH'-tabel?
3. Alle voordelen en nadelen van UDP en TCP uitleggen, en 2 voorbeelden geven waarom/wanneer je gebruik zou maken van UDP of TCP.
4. Hoe werkt pgp en hoe garandeert het integriteit en authenticatie? Leg uit Onweerlegbaarheid/Non-repudiation
5. Leg DASH &amp; Manifestbestand uit + onderlinge relatie.
6. Noem de twee soorten redundantie bij videocompressie?
7. Hoe werkt een leaky bucketsheduler?
8. Vraag 8 (Waar/Niet) 
    1. Kan Jitter (Variatie Delay) opgelost worden door gebruik te maken van QoS?
    2. Als bij een diefstal de Private Sleutel van een Certification Authency (CA) gestolen wordt, heeft dit dan invloed op vooraf uitgedeelde certificaten door deze sleutel?
    3. Als een hacker de Private Sleutel van een website in handen krijgt heeft deze toegang tot alle sessies, en alle voorgaande sessies als deze werden opgenomen (Sniffing) ?
    4. Een Packet-filter kan geen virussen tegenhouden.
    5. ...(nog een 8 tal)

# 2015 augustus examen

1. Bespreek de 2 manieren die er zij om weergavevetraging tegen te gaan bij jitter + schema.
2. Hoe helpt leaky bucket bij iets van bandbreedte + schema?
3. Als netwerkbeheerder bij ICMP-ZERO moet je de firewall configureren zodat de DMZ niet kan gemapt worden door middel van traceroute. Teken deze configuratie en schrijf in pseudocode de FW-regels.
4. Een audiostukje is gesampeld aan 16 000 samples per seconde. Er zijn 12 000 verschillende niveaus. Wat is de bitrate wanneer het CMP gecodeerd is? Toon ook de berekening.
5. Leg volgende bewering uit: IPsec is een veiligheidsdeken.

waar of niet waar + leg uit (hierop krijg je punten)

1. In de HTTP header field byterange krijgt de gebruiker een indicatie van de grootte van het object.
2. Het deffel-hillman algoritme is een hashfunctie.
3. Een hasfunctie is veiliger dan een checksom.
4. Een DNS requests kan enkel interactieve requests aanvragen. (ja zo stond dat op het examen. Ik weet het, die zin klopt niet).

# 2016 januari examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

<dl id="bkmrk-dit-examen-werd-in-2"><dt>Dit examen werd in 2017, 2018 en 2019 getoond als voorbeeldexamen.</dt></dl>#### <span class="mw-headline" id="bkmrk-deel-1%3A-meerkeuzevra-0">Deel 1: meerkeuzevragen</span>

Principe: Per vraag zijn er vier tot 6 stellingen gegeven. Duid telkens aan welke allemaal juist zijn. Het aantal juiste mogelijkheden wordt gegeven. Elke aangeduide mogelijkheid moet juist zijn. Als de juiste antwoorden bv. zijn 'A, F &amp; G' en je duidt 'A, B &amp; G' aan dan is dit volledig fout. De vragen werken ook volgens het principe van eliminatie; er worden ook stellingen over ongeziene stof gegeven en door te elimineren wat je weet van de geziene stof kan je besluiten of de onbekende dingen juist zijn.

1\) Welke dingen zijn van toepassing op IPsec transportmode:

- Tussen eindstations
- Unicast
- Enkel payload
- <s>Tussen gateways</s>
- <s>Multicast</s> (Zie tekst over IPsec)
- <s>Hele pakket</s> (Is tunnelmode)

2\) Welke twee protocollen zorgen voor confidentialiteit van uitgewisselde data

- SSH
- HTTPS

3\) Welk systeem kan aanvallen **inline** tegenhouden. Bv. hacker wilt website defacen via Joomla Exploit.

- IPS (Intrusion Prevention System)
- <s>IDS</s> (Intrusion Detection System)
- <s>Pocketfilter</s>
- <s>Stateful Inspection Firewall</s>
- <s>Virusscanner</s>

4\) Beweringen over Telnet

- Machines op afstand beheren (e.g. router)
- <s>Telnet is geen protocol</s>
- <s>Telnet heeft een beveiligde verbinding</s>
- <s>Met Telnet kun je veilig inloggen</s>

5\) *Iets over access lists*

6\) Welke tools om mail te versturen

- Netcat
- Telnet
- <s>POP3</s> (Lezen)
- <s>ESP</s> (IPsec)
- <s>SSTP</s> (type)

7\) *Beweringen over IPsec-verbinding*

- Wanneer client achter NAT-gateway zit dan kan AH niet gebruikt worden.
- IPsec VPN-tunnel die gebruik maakt van AH biedt geen confidentialiteit.
- Gebruiker die via VPN van thuis toegang wil krijgen tot intern bedrijfsnetwerk gebruikt daarvoor best een ESP IPsec verbinding in tunnel mode.

  
8\) ACC’s

- Specifiekere ACC’s vanboven
- Zelfde trafiek filteren -&gt; meer regels dan Sateful Inspection Firewall

9\) Beweringen over NAT

- Portforwarding is een soort van NAT (Voorbeeldje met Plex)

10\) Iets over diensten die IPsec levert. Mensen struikelden hier over het woordje diensten, want in de lijst stonden implementaties ook.

11\) Welke zijn block cyphers? Dit was een kutvraag volgens Swennen. Afleiden door reductie.

12\) Alice mailt Bob. Je moet blijkbaar zo’n constructies kunnen begrijpen:

- Ḳ^+^~B~(K~C~)+K~S~((Ḳ^-^~A~(H(m))+m))

13\) Applicaties bovenop UDP

- DNS
- SIP

14\) Beweringen over HTTP

- Body is soms leeg (Bv. Conditional Get)

15\) Welke functies noodzakelijk voor IPsec?

- IKE om de SA af te spreken
- Diffie-Helman om shared-secret af te spreken

16\) Welk van onderstaande servers ook application gateway

- HTTP-proxy
- SIP-proxy

17\) Packet Jitter

- Variatie in delay
- Buffering kan negatieve effecten reduceren
- Jitter buffering zorgt voor algemene vertraging

18\) Router die QoS algoritme WFQ samen met ???? kan garantie leveren op

- Delay
- <s>Snelheid</s>
- <s>Packetsize</s>
- <s>Throughput</s>

19\) HTTP-conversatie, er stond geen 200 dus dat was sowieso al niet goed

- Server geen idee welke website.

20\) Router in welke laag OSI-model? **Hier was Swennen het meest in teleurgesteld!!!**

- Laag 3

21\) Beweringen ESP IPsec

- Tunnel mode wordt gebruikt tussen host en security gateway
- Tunnel mode wordt gebruikt tussen 2 security gateways
- Transport mode zal de originele IP header niet versleutelen

  
22\) TCP source ports.

- 20
- 21
- 10000

  
23\) Welke van de volgende zaken worden niet voorzien door TCP (transmission control protocol)?

- Timing
- Security

#### <span class="mw-headline" id="bkmrk-deel-2%3A-open-vragen-0">Deel 2: open vragen</span>

<dl id="bkmrk-1%29-in-bijlage-staat-"><dt>1) In bijlage staat een wiresharkoverzicht van een verbinding.</dt></dl><dl id="bkmrk-1a%29-hoeveel-verbindi"><dd><dl><dd>1a) Hoeveel verbindingen werden er gemaakt? Aan wat zie je dit?</dd></dl></dd></dl><dl id="bkmrk-twee.-dit-vind-je-do"><dd><dl><dd><dl><dd><dl><dd>Twee. Dit vind je door SYN, SYNACK, ACK te tellen.</dd></dl></dd></dl></dd></dl></dd></dl><dl id="bkmrk-1b%29-in-pakket-8-zien"><dd><dl><dd>1b) In pakket 8 zien we dat er een HTML-request is. In welk pakket is dit nog zo en waarom zien we dit niet zo als in pakket 8?</dd></dl></dd></dl><dl id="bkmrk-andere-is-https."><dd><dl><dd><dl><dd><dl><dd>Andere is HTTPS.</dd></dl></dd></dl></dd></dl></dd></dl><dl id="bkmrk-1c%29-hoeveel-data-%28by"><dd><dl><dd>1c) Hoeveel data (bytes) is er verstuurd in de connectie die op lijn 29 wordt beëindigd.</dd></dl></dd></dl><dl id="bkmrk-ack-%3D-2626--%3E-seq-26"><dd><dl><dd><dl><dd><dl><dd>ACK = 2626 -&gt; seq 2626 = aantal bytes</dd></dl></dd></dl></dd></dl></dd></dl><dl id="bkmrk-ergens-was-er-ook-no"><dd>Ergens was er ook nog een vraag over (a \* b)mod^n^. Hierbij moest je niet rekenen, is formule die je zo kunt omzetten.</dd></dl><dl id="bkmrk-2%29-geef-een-volledig"><dt>2) Geef een volledig schema over hoe mail van bij Alice die op haar mailclient (Mozilla Thunderbird) zit vanuit een telenetnetwerk tot aan Bob (ucll) geraakt. Volgende zaken moeten minstens voorkomen</dt><dd>DNS records, DNS, TLD, IMAP, SMTP, (nog iets denk ik maar ben het vergeten).</dd></dl><dl id="bkmrk-die-lijst-met-dingen"><dd><dl><dd>Die lijst met dingen die je moet aanduiden staat er niet voor niets. Die helpt je je antwoord logisch op te bouwen. Zie dat je eerst op kladblad tekent.</dd></dl></dd></dl>

# 2017 juni examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

- 8 moeilijke doordenk multiple choice vragen (met meerdere mogelijke juiste antwoorden, en je moet ze allemaal juist hebben)

- DNS query response gegeven van alle servers waarlangs de DNS query gaat. Leg uit met schema wat er gebeurt, wanneer wie welke responses geeft, welke queries iteratief/recursief zijn.

- Waarom wordt er bij SSL/TCL zowel symmetrische als asymmetrische encryptie gebruikt? Leg uit met een schema van SSL en zeg waar welke gebruikt wordt (toy of echte SSL)

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

#### <span id="bkmrk--8"></span><span class="mw-headline" id="bkmrk-praktijkexamen-22%2F05-0">Praktijkexamen 22/05/2017</span>

- Give a list of all words with 14, 15 or 16 unique letters. The output format should look like this:

<dl id="bkmrk-words-with-14-letter"><dd><dl><dd>Words with 14 letters: word1 word2 word3</dd><dd>Words with 15 letters: word4 word5</dd><dd>...</dd></dl></dd></dl>```
for n in 14 15 16; do echo "Words with $n letters:" $(grep -P "^.{$n}$" dutch | grep -vP '(.).*\1'); done
```

<div id="bkmrk-"></div>- Give a list of the usernames tried in ftp\_bruteforce.pcap. You can only use tshark and sort (Step by step solution: [https://wiki.uclllabs.be/index.php/TShark\_Tutorial#Exercises](https://wiki.uclllabs.be/index.php/TShark_Tutorial#Exercises))

```
tshark -r ftp_bruteforce.pcap -Y 'ftp.request.command == USER' -T fields -e ‘ftp.request.arg’ | sort -u
```

<div id="bkmrk--0"></div>- Give the current time (format: Time= hh:mm:ss (dd-mm-yyyy))

```
echo 'Time=' $(date +'%T (%x)') | tr / -
```

<div id="bkmrk--1"></div>- Write a oneliner to decode the following file "secret" (contents: RGUgcHVudGVuIG9wIGRlemUgdnJhYWcgemlqbiBhbCBiaW5uZW4uCg==)

```
The file ends with '==' indicating base64 padding: openssl enc -d -base64 < secret
```

<div id="bkmrk--2"></div>- Write a oneliner to display the fingerprint, serial and public key of wiki.uclllabs.be

```
echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -fingerprint -serial -pubkey -noout
```

<div id="bkmrk--3"></div>#### <span id="bkmrk--9"></span><span class="mw-headline" id="bkmrk-praktijkexamen-24%2F05-0">Praktijkexamen 24/05/2017</span>

- There is a website running - [https://darthvader.uclllabs.be/nw2/lab1](https://darthvader.uclllabs.be/nw2/lab1) - which is only accessible from 193.191.177.1. That is the IP address of leia.uclllabs.be. Create an ssh tunnel between server leia and the webserver darthvader

```
ssh -L 10000:darthvader.uclllabs.be:443 user@leia.uclllabs.be -p 22345
```

<div id="bkmrk--4"></div>- Give a list of words with 5 letters that are also palindromes.

```
grep -P '^(.)(.).\2\1$' dutch
```

<div id="bkmrk--5"></div>- Show the file /etc/debconf.conf on screen without comment lines (i.e. lines starting with a #).

```
grep -vP '^#' /etc/debconf.conf
```

<div id="bkmrk--6"></div>- Give a list of the usernames tried in ftp\_bruteforce.pcap. You can only use tshark and sort (Step by step solution: [https://wiki.uclllabs.be/index.php/TShark\_Tutorial#Exercises](https://wiki.uclllabs.be/index.php/TShark_Tutorial#Exercises))

```
tshark -r ftp_bruteforce.pcap -Y 'ftp.request.command == USER' -T fields -e ‘ftp.request.arg’ | sort -u
```

<div id="bkmrk--7"></div>- Write a oneliner to display the fingerprint, serial and public key of wiki.uclllabs.be

```
echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -fingerprint -serial -pubkey
```

# 2018 juni examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

- 8 multiple choice vragen

- DNS

- Waarom wordt er bij SSL/TCL zowel symmetrische als asymmetrische encryptie gebruikt? Leg uit met een schema van SSL en zeg waar welke gebruikt wordt.

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

#### <span id="bkmrk--8"></span><span class="mw-headline" id="bkmrk-praktijkexamen-23%2F05-0">Praktijkexamen 23/05/2018</span>

- 1. A simulated phone is running at [http://darthvader.uclllabs.be/nw2/phone/](http://darthvader.uclllabs.be/nw2/phone/). Create a oneliner to bruteforce the pincode. Tip: pincode range: 1200-1300.

```
for i in {1200..1300}; do if wget -q http://darthvader.uclllabs.be/nw2/phone/ --http-user=admin --http-password=$i; then echo $i; break; fi;done;
```

<div id="bkmrk-"></div>- 2. Ontcijfer de volgende boodschap: RGUgcHVudGVuIG9wIGRlemUgdnJhYWcgemlqbiBhbCBiaW5uZW4uCg== (deze boodschap staat in het bestand /home/logs/secret | base64 -d

```
cat /home/logs/secret | base64 -d
```

<div id="bkmrk--0"></div>- 3. Show the file /etc/debconf.conf on screen without comment lines (i.e. lines starting with a #).

```
cat /etc/debconf.conf | grep -Ev "^#"
```

<div id="bkmrk--1"></div>- 4. Use Netcat to download an image from "[http://darthvader.uclllabs.be/nw2/images/](http://darthvader.uclllabs.be/nw2/images/)". You can use a browser to choose an image. check the echo -ne options or use printf. If needed, slow down netcat with option -i. The image part in the HTTP stream starts after a blank line.

```
echo -ne "GET /nw2/images/image1.jpg HTTP/1.0\r\n\r\n" | nc darthvader.uclllabs.be 80 > image1.jpg; cat image1.jpg | tail -n +13 > imagetester.jpg
```

<div id="bkmrk--2"></div>- 5. Perform a zone transfer of the cnw2.uclllabs.be zone to see which hostnames you need to use. Use "dig axfr cnw2.uclllabs.be @ns2.uclllabs.be". Sort the output and format it as follows:

<dl id="bkmrk-%2A.1.cnw2.uclllabs.be"><dd><dl><dd>\*.1.cnw2.uclllabs.be. 3600 IN A 193.191.176.1</dd><dd>\*.2.cnw2.uclllabs.be. 3600 IN A 193.191.176.2</dd><dd>\*.3.cnw2.uclllabs.be. 3600 IN A 193.191.176.3</dd><dd>\*.4.cnw2.uclllabs.be. 3600 IN A 193.191.176.4</dd><dd>\*.5.cnw2.uclllabs.be. 3600 IN A 193.191.176.5</dd><dd>\*.6.cnw2.uclllabs.be. 3600 IN A 193.191.176.6</dd><dd>\*.7.cnw2.uclllabs.be. 3600 IN A 193.191.176.7</dd><dd>\*.8.cnw2.uclllabs.be. 3600 IN A 193.191.176.8</dd><dd>\*.9.cnw2.uclllabs.be. 3600 IN A 193.191.176.9</dd><dd>\*.10.cnw2.uclllabs.be. 3600 IN A 193.191.176.10</dd></dl></dd></dl>```
dig axfr cnw2.uclllabs.be @ns2.uclllabs.be | awk '{print $1,$2,$3,$4,$5}' | grep "IN A" | sort -V
```

<div id="bkmrk--3"></div>#### <span id="bkmrk--9"></span><span class="mw-headline" id="bkmrk-praktijkexamen-22%2F05-0">Praktijkexamen 22/05/2018</span>

- 1) A simulated phone is running at [http://darthvader.uclllabs.be/nw2/phone/](http://darthvader.uclllabs.be/nw2/phone/). Create a oneliner to bruteforce the pincode. Tip: pincode range: 1200-1300

```
for pin in {1200..1300}; do if wget -q --http-user='admin' --http-password=$pin http://darthvader.uclllabs.be/nw2/phone; then echo $pin; break; fi; done
```

<div id="bkmrk--4"></div>- Give a list of words with 5 letters that are also palindromes.

```
grep -P '^(.)(.).\2\1$' dutch
```

<div id="bkmrk--5"></div>- Show the file /etc/debconf.conf on screen without comment lines (i.e. lines starting with a #).

```
grep -vP '^#' /etc/debconf.conf
```

<div id="bkmrk--6"></div>- Give a list of the usernames tried in ftp\_bruteforce.pcap. You can only use tshark and sort (Step by step solution: [https://wiki.uclllabs.be/index.php/TShark\_Tutorial#Exercises](https://wiki.uclllabs.be/index.php/TShark_Tutorial#Exercises))

```
tshark -r ftp_bruteforce.pcap -Y 'ftp.request.command == USER' -T fields -e ‘ftp.request.arg’ | sort -u
```

<div id="bkmrk--7"></div>- Write a oneliner to display the fingerprint, serial and public key of wiki.uclllabs.be

```
echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -fingerprint -serial -pubkey
```

# 2019 extra oefeningen + oplossingen - Lars, Martijn, Jonas

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen)

### Opgave: [cnw2.pdf](https://examenwiki-test.diana.be/attachments/31)

Met dank aan Lars Lemmens

### Oplossingen

Met dank aan Jonas Berx

```
Monitoraat Netwerken - By JONAS BERX
 
# Neem niet zomaar de code over, zoek zelf een oplossing :) (man ...) of (... --help)
# Google is ook nog altijd je vriend
# Niet alle oefeningen zijn 100% juist
# Please geen haat als je uitkomst niet klopt
# Ik ben maar een arm studentje uit UCLL dat graag op Netwerken erdoor wilt zijn
# XXX JONAS XXX
#
 
1) wget -q -O -  http://crl3.digicert.com/TERENASSLCA3.crl | openssl crl -inform DER -text -noout | grep "Revocation Date" | wc -l
 
2) ssh -p 22345  rNummer@leia.uclllabs.be
 
3) ping 127.0.0.1 -c $(ls | grep \.crl$ |wc -l)
 
4) tshark -r Cnw2_ftp_bruteforce.pcap -Y 'ftp.request.command==PASS' -T fields -e 'ftp.request.arg' 2>/dev/null| sort | uniq -c | sort -rn | head -3 | cut -d ' ' -f 7
 
5) gebruik de filter : 'http.request.command==POST'
 
6) nc -z -n -v 193.191.177.1 1-66535 |& grep succeeded ----------- nmap -p- 193.191.177.1 --max-rate 50 (Max rate 50 is redelijk traag aangezien er +65000 poorten zijn)
 
7) who | awk '{print $1,$3}' | while read user time; do   echo $user $(($(($(date +%s) - $(date -d "$time" +%s)))/60)) minutes; done | sort | uniq -c (Klopt niet 100% maar geeft je wel de tijd in minuten)
7A) who -H (Simpele oplossing beter te combineren met 7B)
7B) who | awk '{print $3,$4,$1}' | sort | head -1
 
8) tar -cvf archive.tar /home/LDAP/r0748969 | openssl enc -aes-128-cbc -in archive.tar -out archive.tar.aes; openssl enc -aes-128-cbc -in archive.tar.aes -out archive.tar.aes.aes (GOOGLE : Tar on the fly -> geen tussenbestanden)
 
9)  ss -lnt4 | awk '/LISTEN/{print $4}' |cut -d ':' -f 2 | grep -vP '(.).*\1'
 
10) tshark -r Cnw2_ftp_bruteforce.pcap -Y 'ftp.response.code==230' (Juiste code wel : 230 maar niet juiste antwoord.. moet nog de login gegevens van de successfull login vinden)
 
11) #geen moeite in deze gestoken
 
12) grep -P '^([A-Za-z])([A-Za-z])\2\1$' (achteraf nog een dict toevoegen om in te zoeken)
 
14) ls -ld (-d staat voor directory)
 
15) String = "TGludXggUlVMRVM=" echo TGludXggUlVMRVM= | openssl enc -d -a
 
16) nmap 193.191.177.1 -p- -r --open -sT
 
39) cat /usr/share/dict/dutch | grep -vP '(.).*\1' | grep -P '^[a-zA-Z]{5}$' (voorlaatste)
 
#rest zal deze week er wel bijkomen.. Ik doe m'n best
#Good luck all
#De antwoorden hieronder zijn van het examen dat in de les overlopen is
 
Voor examen : History en dan nummer geven -> handig om op het examen niet je code over te schrijven maar gewoon het nummer van het command te geven.
-----------------------------------------------------------------------
!!!!!!!!!!!!!!!!!!!!!!!!!! 2>/dev/null = vuilnisbak !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
------------------------------------------------------------------------
EXAMENVRAGEN
1)for foo in 14 15 16; do echo "Words with $foo letters:" $(echo "grep -vP '(.).*\1' /usr/share/dict/dutch | grep -P '^.{$foo}$'"| sh);done
 
2) tshark -r Cnw2_ftp_bruteforce.pcap -Y 'ftp.request.command==USER' -T fields -e 'ftp.request.arg' | sort | uniq -c | sort -rn
 
3) date '+Time = %X (%X)' OF echo date : $(date +%Y.%m.%d)
 
4)  cat secret | base64 -d of cat secret | openssl enc -d -a
 
5) echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -noout -pubkey -serial -fingerprint -enddate
```

# 2019 juni examen

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

- 30 multiple choice vragen (waarvan 6-7 vragen letterlijk uit het voorbeeldexamen kwamen), hierbij zijn ook enkele vragen over de theorie in de labo's

  
DE VOLGENDE 3 VRAGEN WAREN EXACT HETZELFDE OP HET HEREXAMEN!

- Als er door ftp 6 files gedownload moeten worden hoeveel connecties dan op laag 4? (antwoord: 1 sessie)

- Hoe wordt er bij SSL/TCL ervoor gezorgd dat er geen truncation attack of lagere level encoding aanval kan gebeuren?

- Modulo rekenen (a\*b)modn a=17023 b=90004, n = 1000? Zeg ook welke eigenschap van modulo rekenen je gebruikt? (oplossing: 23 \* 4 = 92)

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

#### <span class="mw-headline" id="bkmrk-praktijkexamen-1-0">Praktijkexamen 1</span>

- Companies like Google and Microsoft make heavily use of the X.509 subjectAltName extension. UCLL also uses this extension to add an alternative name \*.ucll.be to the common name (ucll.be) of the certificate. Create a oneliner which calculates the amount of DNS Subject Alternate Names used in the SSL certificate of facebook.com.

```
echo | openssl s_client -connect facebook.com:443 | openssl x509 -text -noout | grep -o 'DNS' | wc -l
```

<div id="bkmrk-"></div>- Create a regular expression to match all words in a dictionary with 11 unique letters.

```
cat /usr/share/dict/dutch | grep -P '^[a-zA-Z]{11}$' | grep -vP '(.).*\1'
```

<div id="bkmrk--0"></div>- Show the file /etc/debconf.conf on screen without comment lines (i.e. lines starting with a #).

```
cat /etc/debconf.conf | grep -vP '^#'
```

<div id="bkmrk--1"></div>- Create a linux CLI oneliner to extract an overview of the different FTP usernames in the file ftp\_bruteforce.pcap. You can only use the commands tshark and sort.

```
tshark -r ftp_bruteforce.pcap -Y 'ftp.request.command == USER' -T fields -e ‘ftp.request.arg’ | sort -u
```

<div id="bkmrk--2"></div>- Create a CLI oneliner to find a match between different rsa private key files and their companion crt files. The output should look something like:

alfa.key matches to beta.crt gamma.key matches to delta.crt

```
for key in $(ls -1 *.key); do for crt in $(ls -1 *.crt); do if [ [ $(openssl rsa -in $key -noout -modulus | md5sum) == $(openssl x509 -in $crt -noout 
 -modulus | md5sum) ]]; then echo $key matches $crt; fi; done; done
```

<div id="bkmrk--3"></div>\--&gt; er is een bestand '/home/logs' op leia waar je dit mee kan testen

#### <span class="mw-headline" id="bkmrk-praktijkexamen-2-0">Praktijkexamen 2</span>

- Create a CLI oneliner to match all words with 14, 15 and 16 unique letters. The output should look like:

Words with 14 letters: bedrijfsomvang ... Words with 15 letters: ...

```
for foo in 14 15 16; do echo -e "Words with $foo letters:" && grep -P "^.{$foo}$" /usr/share/dict/dutch | grep -Pv '(.).*\1';done
```

<div id="bkmrk--4"></div>- Bob needs to send a text file through an encrypted tunnel to Alice. Both already agreed on a shared

secret 'mysecret' using the Diffie Hellman algorithm. Alice wants to display the contents of the file directly on her screen in stead of storing it locally and then opening it. Use a suitable encryption algorithm. The data is sent over a medium which only allows ASCII text. Alice is logged in on debbie and Bob on the virtual machine.

- As a web server administrator you have been asked to give your manager a linux CLI oneliner to extract

the 5 IP adresses that contacted the web server the most. The apache log is located in /home/log. Create a correct oneliner. The output should look something like this: (count IPs) 8000 10.10.10.10 ... 82 81.30.45.89

```
cat /home/logs/apache_google.log | awk '{print $1}' | sort | uniq -c | sort -rn | head -5
```

<div id="bkmrk--5"></div>- Log into leia with a RSA key pair instead of logging in with your password.

- ?????

#### <span class="mw-headline" id="bkmrk-praktijkexamen-3-0">Praktijkexamen 3</span>

- Use tshark to create an overview of the different HTTP servers in the file http.pcapng(you can find this file in /home/logs). Filter out all of the Apache servers. You can only use the commands tshark and sort.

- Create a oneliner which lists all palindromes with exactly 5 letters in a dictionary.

```
grep -P '^([a-zA-Z])([a-zA-Z])[a-zA-Z]\2\1$' /usr/share/dict/dutch
```

<div id="bkmrk--6"></div>- Create a CLI oneliner using openssl to retrieve the certificate of the server facebook.com and to display only it's fingerprint, serial and public key.

```
echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -fingerprint -serial -pubkey -noout
```

<div id="bkmrk--7"></div>- Bob needs to send a text file through an encrypted tunnel to Alice. Both already agreed on a shared secret 'mysecret' using the Diffie Hellman algorithm. Alice wants to display the contents of the file directly on her screen in stead of storing it locally and then opening it. Use a suitable encryption algorithm. The data is sent over a medium which only allows ASCII text. Alice is logged in on debbie and Bob on the virtual machine.

- Make the following directories with a oneliner ~/temp/dir1/dir2/dir3. The solution must be generic: It should work from any location.

```
mkdir -p ~/temp/dir1/dir2/dir3
```

# 2019 oplossingen labo 0 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# LABO 0

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-24)Exercise 24

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#create-2-files-with-random-text-then-create-a-third-file-containing-the-contents-of-the-two-other-files)Create 2 files with random text. Then create a third file containing the contents of the two other files

<div id="bkmrk-1%29-echo-%27some-random">```
1) <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">'</span>some random text<span class="pl-pds">'</span></span> <span class="pl-k">></span> file1
2) pwgen -n1 <span class="pl-k">></span> file2 
3) cat file1 file2 <span class="pl-k">></span> file3
```

</div>- The pwgen command generates passwords which are designed to be easily memorized by humans, while being as secure as possible.
- -n stands for minimum 1 number AND -1 stands for per line 1 password.
- '&gt;' means overwrite a file

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-25)Exercise 25

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#list-all-home-directories-which-are-open-for-other-users-group-or-others-should-have-rw-or-x-rights)List all home directories which are open for other users (group or others should have r,w or x rights)

<div id="bkmrk-%E2%80%A2-ls--l-%2Fhome%2Fldap%2F-">```
• ls -l /home/LDAP/ <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>drwx------<span class="pl-pds">'</span></span> <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>^total<span class="pl-pds">'</span></span> <span class="pl-k">|</span> tr -s <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f9
• ls -l /home/LDAP/ <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>drwx------<span class="pl-pds">'</span></span> <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>^total<span class="pl-pds">'</span></span> <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $9}<span class="pl-pds">'</span></span>
• ls -l /home/LDAP/ <span class="pl-k">|</span> grep -vP <span class="pl-s"><span class="pl-pds">'</span>^(drwx------|total)<span class="pl-pds">'</span></span><span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $9}<span class="pl-pds">'</span></span>
• ls -l /home/LDAP/ <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>$1 !~ /drwx------|total/{print $9}<span class="pl-pds">'</span></span>
```

</div>- grep prints lines matching a pattern.
- -v stands for inverted match.
- -P stands for perl expression
- ^ matches position just before the first character of the string.
- The tr command replaces all occurrences of a character in a file, and print the result.
- -s replaces each input sequence of a repeated character that is listed in SET1 with a single occurrence of that character
- The command cut removes sections from each line of files
- -d use DELIM instead of TAB for field delimiter
- -f(number) select only these fields
- awk '{print $(number)' prints the field with the matching number

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-26)Exercise 26

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#list-all-lines-in-the-file-usrsharedictdutch-containing-the-string-rare)List all lines in the file /usr/share/dict/dutch containing the string 'rare'

<div id="bkmrk-%E2%80%A2-cat-%2Fusr%2Fshare%2Fdic">```
• cat /usr/share/dict/dutch <span class="pl-k">|</span> grep rare
• grep rare /usr/share/dict/dutch
```

</div># [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-27)Exercise 27

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#only-show-the-columns-with-filenames-and-permissions-of-the-files-in-your-homedirectory-tip-use-ls-and-cut)Only show the columns with filenames and permissions of the files in your homedirectory. (tip: use ls and cut)

<div id="bkmrk-%E2%80%A2-ls--l-%7E-%7C-grep--v-">```
• ls -l <span class="pl-k">~</span> <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>^total<span class="pl-pds">'</span></span> <span class="pl-k">|</span> tr -s <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1,9
```

</div>- grep prints lines matching a pattern.
- -v stands for inverted match.
- The tr command replaces all occurrences of a character in a file, and print the result.
- -s replaces each input sequence of a repeated character that is listed in SET1 with a single occurrence of that character
- The command cut removes sections from each line of files
- -d use DELIM instead of TAB for field delimiter
- -f(number) select only these fields

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-28)Exercise 28

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#sort-the-lines-from-27-in-reverse-alphabetical-order)Sort the lines from 27 in reverse alphabetical order

<div id="bkmrk-%E2%80%A2-ls--l-%7E-%7C-grep--v--0">```
• ls -l <span class="pl-k">~</span> <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>^total<span class="pl-pds">'</span></span> <span class="pl-k">|</span> tr -s <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1,9 <span class="pl-k">|</span> sort -r -k2
```

</div>- grep prints lines matching a pattern.
- -v stands for inverted match.
- The tr command replaces all occurrences of a character in a file, and print the result.
- -s replaces each input sequence of a repeated character that is listed in SET1 with a single occurrence of that character
- The command cut removes sections from each line of files
- -d use DELIM instead of TAB for field delimiter
- -f(number) select only these fields
- The sort command sort lines of text files
- -r reverse the result of comparisons
- -k start a key at POS1 (origin 1), end it at POS2 (default end of line).

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-29)Exercise 29

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#use-the-command-cal-to-find-out-on-which-day-of-the-week-your-birthday-is-in-2050-and-write-your-output-to-a-newly-created-file)Use the command cal to find out on which day of the week your birthday is in 2050 and write your output to a newly created file

<div id="bkmrk-%E2%80%A2-ncal--m-6-2050-%7C-g">```
• ncal -m 6 2050 <span class="pl-k">|</span> grep <span class="pl-s"><span class="pl-pds">'</span> 9 <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1 <span class="pl-k">></span> file
• cal -N -m 6 2050 <span class="pl-k">|</span> grep <span class="pl-s"><span class="pl-pds">'</span> 9 <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1 <span class="pl-k">></span> file
```

</div>- The command ncal displays a calendar and the date of Easter
- The command cal displays a calendar and the date of Easter
- -m displays the specified month
- The command cut removes sections from each line of files
- -d use DELIM instead of TAB for field delimiter
- -f(number) select only these fields
- '&gt;' means overwrite a file

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-30)Exercise 30

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#append-the-sentence-the-end-to-the-file-you-created-in-the-previous-exercise-without-opening-this-file-in-an-editor-hence-use-a-one-liner)Append the sentence 'THE END' to the file you created in the previous exercise without opening this file in an editor (hence: use a one-liner)

<div id="bkmrk-%E2%80%A2-echo-%27the-end%27-%3E%3E-">```
• <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">'</span>THE END<span class="pl-pds">'</span></span> <span class="pl-k">>></span> file

<span class="pl-c"># >> makes a file and saves it</span>
```

</div># [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-31)Exercise 31

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#create-a-subdirectory-test-in-your-homedir-now-create-some-files-in-it-using-this-command-line-and-make-sure-you-understand-what-happens)Create a subdirectory TEST in your homedir. Now create some files in it using this command line (and make sure you understand what happens!)

<div id="bkmrk-for-foo-in-%60seq-1-9%60">```
<span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">`</span>seq 1 9<span class="pl-pds">`</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> touch <span class="pl-s"><span class="pl-pds">"</span>file <span class="pl-smi">$RANDOM</span><span class="pl-pds">"</span></span><span class="pl-k">;</span> <span class="pl-k">done</span> <span class="pl-k">&&</span> touch <span class="pl-s"><span class="pl-pds">'</span>file keep me<span class="pl-pds">'</span></span>
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#how-can-you-remove-all-files-except-the-file-file-keep-me-with-just-one-oneliner)How can you remove all files except the file “file keep me” with just one 'oneliner'"

<div id="bkmrk-1%29-mkdir-%7E%2Ftest%3B-cd-">```
1) mkdir <span class="pl-k">~</span>/TEST<span class="pl-k">;</span> <span class="pl-c1">cd</span> <span class="pl-k">~</span>/TEST
2) <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> {1..9}<span class="pl-k">;</span> <span class="pl-k">do</span> touch <span class="pl-s"><span class="pl-pds">"</span>file <span class="pl-smi">$RANDOM</span><span class="pl-pds">"</span></span><span class="pl-k">;</span> <span class="pl-k">done</span> <span class="pl-k">&&</span> touch <span class="pl-s"><span class="pl-pds">'</span>file keep me<span class="pl-pds">'</span></span>

• rm file<span class="pl-cce">\ </span>[0-9]<span class="pl-k">*</span>
• ls file<span class="pl-cce">\ </span>[0-9]<span class="pl-k">*</span> <span class="pl-k">|</span> <span class="pl-k">while</span> <span class="pl-c1">read</span> file<span class="pl-k">;</span> <span class="pl-k">do</span> rm <span class="pl-s"><span class="pl-pds">"</span><span class="pl-smi">$file</span><span class="pl-pds">"</span></span><span class="pl-k">;</span><span class="pl-k">done</span>
• ls -1 <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>file keep me<span class="pl-pds">'</span></span> <span class="pl-k">|</span> xargs -d <span class="pl-s"><span class="pl-pds">'</span>\n<span class="pl-pds">'</span></span> rm
• find <span class="pl-c1">.</span> -type f <span class="pl-k">!</span> -name <span class="pl-s"><span class="pl-pds">'</span>file keep me<span class="pl-pds">'</span></span> -delete
```

</div>- The for keyword indicates a for loop ==&gt; SYNTAX : for WORD \[ in WORDLIST ... \] ; do ACTIONS ; done
- The command touch creates a new empty file(s) or change the times for existing file(s) to current time
- The rm command removes files or directories
- Remove (unlink) the FILE(s)
- The while command continuously executes the list list-2 as long as the last command in the list-1 returns an exit status of zero.
- The command xargs builds and executes command lines from standard input
- -d stands for delimiter ==&gt; This can be used when the input consists of simply newline- separated items, although it is almost always better to design your program to use --null where this is possible.
- The find command searches for files in a directory hierarchy
- -f stands for regular file
- -delete stands for Delete files; true if removal succeeded.

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-32)Exercise 32

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#list-the-name-and-permissions-of-the-first-10-directories-in-etc)List the name and permissions of the first 10 directories in /etc.

<div id="bkmrk-sample-output%3A-drwxr">```
Sample output: 
drwxr-xr-x /etc/ 
drwxr-xr-x /etc/alternatives 
drwxr-xr-x /etc/apache2 
drwxr-xr-x /etc/apache2/conf.d 
drwxr-xr-x /etc/apache2/mods-available 
drwxr-xr-x /etc/apache2/mods-enabled 
drwxr-xr-x /etc/apache2/sites-available 
drwxr-xr-x /etc/apache2/sites-enabled 
drwxr-xr-x /etc/apt d
rwxr-xr-x /etc/apt/apt.conf.d<span class="pl-s"><span class="pl-pds">"</span></span>

<span class="pl-s">• ls -l /etc | head -10 | grep -v '^total' | awk '{print <span class="pl-smi">$1</span> <span class="pl-pds">"</span></span> <span class="pl-s"><span class="pl-pds">"</span> <span class="pl-smi">$9</span>}'</span>
```

</div>- The head command prints the first 10 lines of each FILE to standard output. With more than one FILE, precede each with aheader giving the file name. With no FILE, or when FILE is -, read standard input.
- grep prints lines matching a pattern
- -v stands for inverted match.
- awk '{print $(number)' prints the field with the matching number

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-33)Exercise 33

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#same-question-as-32-but-now-also-omit-all-error-messages-)Same question as #32, but now also omit all error messages. "

<div id="bkmrk-%E2%80%A2-ls--l-%2Fetc-2%3E%2Fdev%2F">```
• ls -l /etc <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> head -10 <span class="pl-k">|</span> grep -v <span class="pl-s"><span class="pl-pds">'</span>^total<span class="pl-pds">'</span></span> <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $1 " " $9}<span class="pl-pds">'</span></span>
```

</div>- 2&gt;/dev/null is used to redirect to a file
- The head command prints the first 10 lines of each FILE to standard output. With more than one FILE, precede each with aheader giving the file name. With no FILE, or when FILE is -, read standard input.
- grep prints lines matching a pattern.
- -v stands for inverted match.
- awk '{print $(number)' prints the field with the matching number

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#exercise-34)Exercise 34:

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%200.md#list-the-name-and-permissions-of-all-files-in-the-etc-directory-containing-the-word-host-in-their-name-do-this-without-the-use-of-the-commands-grep-andor-awk)List the name and permissions of all files in the /etc directory containing the word 'host' in their name. Do this without the use of the commands grep and/or awk."

<div id="bkmrk-%E2%80%A2-find-%2Fetc%2F--type-f">```
• find /etc/ -type f -name <span class="pl-s"><span class="pl-pds">'</span>*host*<span class="pl-pds">'</span></span> <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> xargs -d <span class="pl-s"><span class="pl-pds">'</span>\n<span class="pl-pds">'</span></span> ls -l <span class="pl-c"># (recursive search)</span>
• find /etc/ -maxdepth 1 -type f -name <span class="pl-s"><span class="pl-pds">'</span>*host*<span class="pl-pds">'</span></span> <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> xargs -d <span class="pl-s"><span class="pl-pds">'</span>\n<span class="pl-pds">'</span></span> ls -l
• ls -ld /etc/<span class="pl-k">*</span>host<span class="pl-k">*</span> <span class="pl-k">|</span> tr -s <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1,9 <span class="pl-c"># (also show files of type directory)   </span>
• ls -ld /etc/<span class="pl-k">*</span>host<span class="pl-k">*</span> <span class="pl-k">|</span> sed -e <span class="pl-s"><span class="pl-pds">'</span>/^d.*/d<span class="pl-pds">'</span></span> <span class="pl-k">|</span> tr -s <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1,9
```

</div>- The find command searches for files in a directory hierarchy
- -f stands for regular file
- -name stands for the name
- 2&gt;/dev/null is used to redirect to a file
- The command xargs builds and executes command lines from standard input
- -d stands for delimiter ==&gt; This can be used when the input consists of simply newline- separated items, although it is almost always better to design your program to use --null where this is possible.
- -maxdepth stands for the - levels of directories below the starting point
- The command cut removes sections from each line of files
- -d use DELIM instead of TAB for field delimiter
- -f(number) select only these fields
- The tr command replaces all occurrences of a character in a file, and print the result.
- -s replaces each input sequence of a repeated character that is listed in SET1 with a single occurrence of that character

# 2019 oplossingen labo 1 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# LABO 1

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#in-order-to-connect-to-a-remote-ssh-server-leiauclllabsbe-in-this-example-execute-the-following-command)In order to connect to a remote SSH server leia.uclllabs.be in this example, execute the following command

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ssh-r123">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh r1234567@leia.uclllabs.be -p 22345
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#the-client-configuration-file-can-make-your-life-easier-because-default-command-line-options-could-be-specified-in-this-configuration-file)The client configuration file can make your life easier because default command line options could be specified in this configuration file

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#normally-you-would-use-the-following-command-to-log-in-to-leia)Normally you would use the following command to log in to leia

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ssh--p-2">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh -p 22345 r1234567@leia.uclllabs.be  

<span class="pl-s"><span class="pl-pds">"</span>FILE: ~/.ssh/config<span class="pl-pds">"</span></span>
    Host leia
    HostName leia.uclllabs.be
    Port 22345
    User r1234567
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#the-following-command-creates-an-ssh-tunnel-local-tcp-port-cport-on-your-laptop-will-be-tunneled-through-gateway-to-server-port)The following command creates an ssh tunnel. Local tcp port CPORT (on your laptop) will be tunneled through GATEWAY to SERVER port

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ssh--f-g">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh -f GWUSERNAME@GATEWAY -L CPORT:SERVER:SPORT -N
```

</div>- The -f argument instructs the ssh instance to go into the background, and -N instructs it to not launch a shell.
- The -L argument specifies that the given port on the local (client) host is to be forwarded to the given host and port on the remote side.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#try-it-yourself-there-is-a-website-running---httpsdarthvaderuclllabsbenw2lab1-which-is-only-accessible-from-1931911771-thats-the-ip-address-of-leiauclllabsbe)Try it yourself: There is a website running - [https://darthvader.uclllabs.be/nw2/lab1](https://darthvader.uclllabs.be/nw2/lab1) which is only accessible from 193.191.177.1. That's the IP address of leia.uclllabs.be.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ifconfig">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ifconfig <span class="pl-k">|</span> grep -B1 inet
```

</div>- ifconfig configures a network interface
- The grep command grep searches the named input FILEs
- -B NUM prints NUM lines of leading context before matching lines

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#with-this-command-you-can-create-an-ssh-tunnel-between-server-leiauclllabsbe-and-the-webserver-darthvaderuclllabsbe)With this command, you can create an ssh tunnel between server leia.uclllabs.be and the webserver darthvader.uclllabs.be.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ssh--p-2-0">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh -p 22345 -f r0123456@leia.uclllabs.be -L 10000:darthvader.uclllabs.be:443 -N
```

</div>- The -p argument shows which port to connect to on the remote host
- The -f argument instructs the ssh instance to go into the background, and -N instructs it to not launch a shell.
- The -L argument specifies that the given port on the local (client) host is to be forwarded to the given host and port on the remote side.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#first-find-the-ssh-process-to-close)First find the ssh process to close:

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ps-fauxw">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ps fauxw <span class="pl-k">|</span> grep darthvader
```

</div>- The ps command reports a snapshot of the current processes
- The f argument does a full-format listing
- The a argument selects all processes except both session leaders and processes not associated with a terminal.
- The u argument selects by effective user ID (EUID) or name.
- The x arugment Lift the BSD-style "must have a tty" restriction, which is imposed upon the set of all processes when some BSD-style (without "-") options are used or when the ps personality setting is BSD-like.
- The w argument gives wide output
- grep searches the named input FILEs

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#next-send-a-sigterm-signal-to-the-correct-pid-process-identifier--second-column-in-ps-fauxw-output)Next send a sigterm signal to the correct pid (process identifier) = second column in ps fauxw output

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-kill-123">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">kill</span> 12345
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#and-if-you-need-to-close-all-running-ssh-sessionstunnels-use-the-following-command)And if you need to close all running ssh sessions/tunnels use the following command:

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-killall-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • killall ssh
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#by-default-kill-sends-a-sigterm-signal-similar-to-clicking-on-the-x-to-close-a-window-chrome-notepad-gnome-terminal-if-you-need-to-force-close-an-application-send-the-sigkill-signal)By default kill sends a SIGTERM signal (similar to clicking on the X to close a window (Chrome, Notepad, Gnome-terminal,..). If you need to force close an application, send the SIGKILL signal:

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-kill--9-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">kill</span> -9 12345
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • killall -9 ssh
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#use-a-text-based-browser-on-leia-to-verify-the-remote-website-is-accessible-through-the-ssh-tunnel)Use a text based browser on leia to verify the remote website is accessible through the ssh tunnel.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-lynx-htt">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • lynx https://localhost:10000/nw2/lab1-all-but-leia
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • curl -k -s https://localhost:10000/nw2/lab1-all-but-leia/ <span class="pl-k">|</span> html2text
```

</div>- The argument -k instructs curl not to verify the server certificate.
- The argument -s makes curl mute make sure that it doesn't show progress meter or error messages

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#openssh-has-built-in-support-for-dynamic-port-forwarding-via-the-socks-proxy-protocol-this-command-turns-your-ssh-client-on-your-laptop-into-a-socks-proxy-server-)OpenSSH has built-in support for dynamic port forwarding via the SOCKS proxy protocol. This command turns your SSH client (on your laptop) into a SOCKS proxy server: "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ssh--f-u">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh -f user@GATEWAY -D 10000 -N -p port
```

</div>- The -f argument instructs the ssh instance to go into the background, and -N instructs it to not launch a shell.
- The -p argument shows which port to connect to on the remote host
- The -D argument specifies a local “dynamic” application-level port forwarding

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#there-are-3-different-levels-of-debug-modes-that-can-help-troubleshooting-issues-with-the--v-option-ssh-prints-debugging-messages-about-its-progress)There are 3 different levels of debug modes that can help troubleshooting issues. With the -v option SSH prints debugging messages about its progress.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#this-is-helpful-in-debugging-connection-authentication-and-configuration-problems-multiple--v-options-increase-the-verbosity-maximum-verbosity-is-three-levels-deep)This is helpful in debugging connection, authentication, and configuration problems. Multiple -v options increase the verbosity. Maximum verbosity is three levels deep.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-ssh-leia">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh leia -v
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh leia -vv
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • ssh leia -vvv
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#this-command-will-aid-you-in-finding-an-available-tcp-port-)This command will aid you in finding an available tcp port: "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-netstat-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • netstat -lnt <span class="pl-k">|</span> grep -oP <span class="pl-s"><span class="pl-pds">'</span>:\K[^:][0-9]+<span class="pl-pds">'</span></span> <span class="pl-k">|</span> sort -un
```

</div>- The command netstat prints network connections, routing tables, interface statistics, masquerade connections, and multicast memberships
- The -l shows only listening sockets.
- The -n shows numerical addresses instead of trying to determine symbolic host, port or user names.
- The -t argument shows only TCP ports
- The command grep searches for PATTERNS in each FILE.
- The -o argument prints only the matched (non-empty) parts of a matching line, with each such part on a separate output line.
- The -p argument Interpret I as Perl-compatible regular expressions (PCREs).
- : matches the character : literally (case sensitive)
- \\K resets the starting point of the reported match.
- \[^:\] matches a single character not present in the list below
- \[0-9\] matches a single character present in the list below
- '+' matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- The command sort sorts lines of text files
- The -u argument output only the first of an equal run
- The -n argument compares according to string numerical value

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#for-instance-we-can-scan-all-ports-up-to-1000-by-issuing-this-command)For instance, we can scan all ports up to 1000 by issuing this command:

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-nc--vz-l">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc -vz leia.uclllabs.be 1-1000
```

</div>- The command nc is a TCP/IP swiss army knife
- The -v argument is for verbose
- The -z argument is for zero-I/O mode \[used for scanning\]

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#messages-returned-by-netcat-are-sent-to-standard-error-you-can-send-the-standard-error-messages-to-standard-out-which-will-allow-filtering-the-results-stderr-can-be-redirected-to-stdout-via-the-21-bash-syntax-then-use-grep-to-filter)"Messages returned by Netcat are sent to standard error. You can send the standard error messages to standard out, which will allow filtering the results. Stderr can be redirected to stdout via the 2&gt;&amp;1 bash syntax. Then use grep to filter

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#alternatively-you-could-use--as-a-shorthand-for-21--)Alternatively you could use |&amp; as a shorthand for 2&gt;&amp;1 |. "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-nc--z--n">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc -z -n -v 193.191.177.1 1-1000 <span class="pl-k">2>&1</span> <span class="pl-k">|</span> grep succeeded
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc -z -n -v 193.191.177.1 1-1000 <span class="pl-k">&</span><span class="pl-k">|</span> grep succeeded
```

</div>- The command nc is a TCP/IP swiss army knife
- The -z argument is for zero-I/O mode \[used for scanning\]
- The -v argument is for verbose
- The -v argument is used for short version

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#netcat-is-a-very-slow-tcp-port-scanner-as-it-will-wait-for-a-tcp-timeout-for-every-port-it-tries-add-option--w-1-to-increase-scanning-speed-and-execute-this-command-on-leia-to-circumvent-slowdown-due-to-firewalled-ports)Netcat is a very slow TCP port scanner as it will wait for a TCP timeout for every port it tries. Add option -w 1 to increase scanning speed, and execute this command on leia to circumvent slowdown due to firewalled ports.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#netcat-isnt-designed-to-scan-for-open-ports-its-functionality-is-very-limited-if-you-need-to-scan-for-open-ports-use-a-real-portscanner-like-nmap)Netcat isn't designed to scan for open ports, it's functionality is very limited. If you need to scan for open ports, use a real portscanner like Nmap"

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-nmap--p1">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nmap -p1-1000 193.191.177.1
```

</div>- The command nmap is a network exploration tool and security / port scanner
- The -p argument specifies which ports you want to scan

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#once-again-you-need-to-choose-one-end-of-the-connection-to-listen-for-connections)Once again, you need to choose one end of the connection to listen for connections.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#however-instead-of-printing-information-onto-the-screen-you-will-place-all-information-straight-into-a-file)However, instead of printing information onto the screen, you will place all information straight into a file

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-nc--l--p">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc -l -p 10000 <span class="pl-k">></span> received_file
```

</div>- The command nc is a TCP/IP swiss army knife
- The -l argument is used as listening mode
- The -p argument specifies which ports you want to scan
- The &gt; overwrites a file

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#on-the-second-computer-create-a-simple-text-file-by-typing-)On the second computer, create a simple text file by typing: "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-echo-%22he">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">"</span>Hello, this is a file<span class="pl-pds">"</span></span> <span class="pl-k">></span> original_file
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#you-can-now-use-this-file-as-an-input-for-the-netcat-connection-you-will-establish-to-the-remote-listening-computer)You can now use this file as an input for the Netcat connection you will establish to the remote listening computer.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#the-file-will-be-transmitted-just-as-if-you-had-typed-it-interactively-)The file will be transmitted just as if you had typed it interactively: "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-nc--l--p-0">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc -l -p 10000 <span class="pl-k"><</span> original_file
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#on-the-receiving-end-you-can-anticipate-a-file-coming-over-that-will-need-to-be-unzipped-and-extracted-by-typing-)On the receiving end, you can anticipate a file coming over that will need to be unzipped and extracted by typing: "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-nc--l--p-1">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc -l -p 10000 <span class="pl-k">|</span> tar xzvf -
```

</div>- The command nc is a TCP/IP swiss army knife
- The -l argument is used as listening mode
- The -p argument specifies which ports you want to scan
- The tar command is a GNU version of the tar archiving utility
- The -x argument extracts files from an archive
- The -z argument unzips the file
- The -v argument is for verbose
- The -f argument uses archive file
- The ending dash (-) means that tar will operate on standard input, which is being piped from Netcat across the network when a connection is made.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#on-the-side-with-the-directory-contents-you-want-to-transfer-you-can-pack-them-into-a-tarball-and-then-send-them-to-the-remote-computer-through-netcat)On the side with the directory contents you want to transfer, you can pack them into a tarball and then send them to the remote computer through Netcat:

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tar--czf">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tar -czf - <span class="pl-k">*</span> <span class="pl-k">|</span> nc leia.uclllabs.be 10000
```

</div>- The tar command is a GNU version of the tar archiving utility
- The -c argument creates a new archive
- The -z argument unzips the file
- The -f argument uses archive file
- The command nc is a TCP/IP swiss army knife

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#in-the-following-example-we-create-a-full-backup-of-our-home-directory-on-leia-all-files-and-folders-using-tar---netcat-method)In the following example, we create a full backup of our home directory on leia (all files and folders) using tar - Netcat method.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#execute-this-on-leia-)Execute this on leia: "

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tar--cz-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tar -cz <span class="pl-k">~</span> <span class="pl-k">|</span> nc -l -p 10000
```

</div>- The tar command is a GNU version of the tar archiving utility
- The -c argument creates a new archive
- The -z argument unzips the file
- The command nc is a TCP/IP swiss army knife
- The -l argument is used as listening mode
- The -p argument specifies which ports you want to scan

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#and-this-on-your-laptop-the-machine-receiving-backups)And this on your laptop (the machine receiving backups):

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-cd-%2Fpath">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">cd</span> /path/to/where_I_want_to_store_my_backup
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • nc leia.uclllabs.be 10000 <span class="pl-k">|</span> tar -xzf -
```

</div>- The command nc is a TCP/IP swiss army knife
- The tar command is a GNU version of the tar archiving utility
- The -x argument extracts files from an archive
- The -z argument unzips the file
- The -f argument uses archive file w

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#this-is-just-one-example-of-transferring-more-complex-data-from-one-computer-to-another-another-common-idea-is-to-use-the-dd-command-to-image-a-disk-on-one-side-and-transfer-it-to-a-remote-computer)This is just one example of transferring more complex data from one computer to another. Another common idea is to use the dd command to image a disk on one side and transfer it to a remote computer.

<div id="bkmrk-%27user%40leia%3A%7E%24%27-%E2%80%A2-tar">```
<span class="pl-s"><span class="pl-pds">'</span>user@leia:~$<span class="pl-pds">'</span></span> • tar -cz <span class="pl-k">~</span> <span class="pl-k">|</span> pv <span class="pl-k">|</span> nc -l -p 10000

<span class="pl-s"><span class="pl-pds">'</span>user@laptop:~$<span class="pl-pds">'</span></span> • nc leia.uclllabs.be 10000 <span class="pl-k">|</span> pv <span class="pl-k">></span> backup.tar.gz
```

</div>- The tar command is a GNU version of the tar archiving utility
- The command nc is a TCP/IP swiss army knife
- The -c argument creates a new archive
- The pv command monitors the progress of data through a pipe
- The -z argument unzips the file
- The &gt; argument overwrites the file
- The pv command monitors the progress of data through a pipe
- The command nc is a TCP/IP swiss army knife
- The -l argument is used as listening mode
- The -p argument specifies which ports you want to scan

<div id="bkmrk-%27user%40leia%3A%7E%24%27-%E2%80%A2-tar-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@leia:~$<span class="pl-pds">'</span></span> • tar -cz <span class="pl-k">~</span> <span class="pl-k">|</span> pv <span class="pl-k">|</span> nc <span class="pl-s"><span class="pl-pds">'</span>-N<span class="pl-pds">'</span></span> -l -p 10000

<span class="pl-s"><span class="pl-pds">'</span>user@laptop:~$<span class="pl-pds">'</span></span> • nc -d leia.uclllabs.be 10000 <span class="pl-k">|</span> pv <span class="pl-k">></span> backup.tar.gz
```

</div>- The tar command is a GNU version of the tar archiving utility
- The command nc is a TCP/IP swiss army knife
- The -c argument creates a new archive
- The -d argument makes sure that it does not attempt to read from stdin.
- The -z argument unzips the file

<div id="bkmrk-%27user%40laptop%3A%7E%24%27-%E2%80%A2-n">```
<span class="pl-s"><span class="pl-pds">'</span>user@laptop:~$<span class="pl-pds">'</span></span> • nc leia.uclllabs.be 10000 <span class="pl-k"><</span>/dev/null <span class="pl-k">|</span> pv <span class="pl-k">|</span> tar xzf -
```

</div>- The pv command monitors the progress of data through a pipe
- The -N argument shuts the network socket down after EOF on the input
- The -l argument is used as listening mode
- The -p argument specifies which ports you want to scan
- /dev/null is for error log

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#exercise-1)Exercise 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#how-do-you-verify-if-the-packages-openssh-server-and-openssh-client-are-installed-on-your-debian-system-hint-dpkg--l-)How do you verify if the packages openssh-server and openssh-client are installed on your Debian system? (Hint: dpkg -l ...)"

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-dpkg--l-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • dpkg -l openssh-server
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • dpkg -l openssh-client
```

</div>- The argument -l is used for list

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#exercise-2)Exercise 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#how-do-you-verify-if-the-openssh-server-is-running)How do you verify if the openssh-server is running?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-systemct">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • systemctl status ssh 
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#exercise-3)Exercise 3:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#how-to-check-which-port-is-used-by-the-ssh-server-daemon-hint-netstat-ss-or-lsof)How to check which port is used by the SSH server daemon? (Hint: netstat, ss or lsof)

<div id="bkmrk-%27root-%23%27-%E2%80%A2-netstat--">```
<span class="pl-s"><span class="pl-pds">'</span>root #<span class="pl-pds">'</span></span> • netstat -lntp <span class="pl-k">|</span> grep sshd
<span class="pl-s"><span class="pl-pds">'</span>root #<span class="pl-pds">'</span></span> • ss -lntp <span class="pl-k">|</span> grep sshd
<span class="pl-s"><span class="pl-pds">'</span>root #<span class="pl-pds">'</span></span> • lsof -i tcp <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>$1=="sshd" && $10=="(LISTEN)" {print $9}<span class="pl-pds">'</span></span> <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span>:<span class="pl-pds">'</span></span> -f2 <span class="pl-k">|</span> sort -u
```

</div>- The netstat command prints network connections, routing tables, interface statistics, masquerade connections, and multicast memberships
- The -l argument is used as listening mode
- The -n argument shows numerical addresses instead of trying to determine symbolic host, port or user names.
- The -p argument shows the PID and name of the program to which each socket belongs
- The grep command prints lines matching a pattern
- The ss command is another utility to investigate sockets
- The lsof command lists open files
- The -i argument selects the listing of files any of whose Internet address matches the address specified in i.
- The awk command is used for pattern scanning and processing language
- The cut command removes sections from each line of files
- The -d argument use DELIM instead of TAB for field delimiter
- The -f argument selects only these fields
- The sort command sort lines of text files
- The -u argument outputs only the first of an equal run

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#exercise-4)Exercise 4:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#how-do-you-disconnect-from-a-remote-ssh-session)How do you disconnect from a remote SSH session?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-exit-%27us">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">exit</span>
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">logout</span>
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-k"><</span>CTRL<span class="pl-k">></span>+d
```

<div><svg aria-hidden="true" class="octicon octicon-clippy js-clipboard-clippy-icon m-2" data-view-component="true" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg></div></div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#exercise-5)Exercise 5:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#is-there-a-config-file-for-the-openssh-server-if-so-where-is-it-located-in-the-file-system-tree)Is there a config file for the OpenSSH server? If so, where is it located in the file system tree?

<div id="bkmrk-yes%3A-%27%2Fetc%2Fssh%2Fsshd_">```
Yes: <span class="pl-s"><span class="pl-pds">'</span>/etc/ssh/sshd_config<span class="pl-pds">'</span></span>
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#exercise-6)Exercise 6:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%201.md#create-and-demonstrate-a-simple-web-server-with-netcat)Create and demonstrate a simple web server with Netcat.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-while-tr">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-k">while</span> <span class="pl-c1">true</span><span class="pl-k">;</span> <span class="pl-k">do</span> { <span class="pl-c1">echo</span> -e <span class="pl-s"><span class="pl-pds">"</span>HTTP/1.1 200 OK\r\n<span class="pl-pds">$(</span>date<span class="pl-pds">)</span>\r\n\r\n<h1>hello world from <span class="pl-pds">$(</span>hostname<span class="pl-pds">)</span> on <span class="pl-pds">$(</span>date<span class="pl-pds">)</span></h1><span class="pl-pds">"</span></span> <span class="pl-k">|</span> nc -vl -p 10000<span class="pl-k">;</span> } <span class="pl-k">done</span>
```

</div>- The while command The while command continuously executes the list list-2 as long as the last command in the list list-1 returns an exit status of zero.
- The echo command displays a line of text
- The -e argument enables interpretation of backslash escapes
- The command nc is a TCP/IP swiss army knife
- The -v argument uses verbose
- The -l argument is used for listen mode, for inbound connects
- The -p argument is used for local port number

# 2019 oplossingen labo 2 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# LABO 2

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#what-is-the-ip-address-of-your-computer)What is the IP address of your computer?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#what-is-the-status-code-returned-from-the-server-to-your-browser)What is the status code returned from the server to your browser?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#when-was-the-html-file-that-you-are-retrieving-last-modified-on-the-server)When was the HTML file that you are retrieving last modified on the server?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-echo--ne">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> -ne <span class="pl-s"><span class="pl-pds">'</span>HEAD /HTTP-Wireshark-file1.html HTTP/1.1\r\nHost:  virtualhostname.x.cnw2.uclllabs.be\r\n\r\n<span class="pl-pds">'</span></span> <span class="pl-k">|</span> nc localhost 80 <span class="pl-k">|</span> grep <span class="pl-s"><span class="pl-pds">'</span>Last-Modified:<span class="pl-pds">'</span></span>

<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http -T fields -e http.last_modified
```

</div>- The -n argument does not output the trailing newline
- The -e argument enables interpretation of backslash escapes
- The nc command is a TCP/IP swiss army knife
- The -r argument reads the packet date from infile
- The -Y command captures the link type
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#how-many-bytes-of-content-are-being-returned-to-your-browser)How many bytes of content are being returned to your browser?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#what-software-and-version-is-the-web-server-running)What software and version is the web server running?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark--">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http.server -T fields -e ip.src -e http.server <span class="pl-k">|</span> sort -u
```

</div>- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The -u argument output only the first of an equal run

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#explain-in-detail-the-above-tshark-command)Explain in detail the above tshark command.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#what-tcp-ports-are-in-use-at-the-client-and-the-server-during-your-browsing-session)What TCP ports are in use at the client and the server during your browsing session?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---0">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http -T fields -e tcp.port <span class="pl-k">|</span> sort -u
```

</div>- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The -u argument output only the first of an equal run

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-1)Exercise 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#which-http-method-was-used-the-most-during-the-entire-browsing-session)Which HTTP method was used the most during the entire browsing session?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---1">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http.request.method -T fields -e http.request.method <span class="pl-k">|</span> sort <span class="pl-k">|</span> uniq -c <span class="pl-k">|</span> head -1 <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $2}<span class="pl-pds">'</span></span>
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http.request.method -T fields -e http.request.method <span class="pl-k">|</span> sort <span class="pl-k">|</span> uniq -c <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>NR=1{print $2}<span class="pl-pds">'</span></span>
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The uniq command reports or omits repeated lines
- The -c argument prefixes lines by the number of occurences
- The head command shows output for only the first part of files
- The awk command is used for pattern scanning and processing language

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#in-case-you-would-like-to-automate-this-with-tshark-and-a-bash-loop)In case you would like to automate this: With tshark and a Bash loop"

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---2">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y <span class="pl-s"><span class="pl-pds">'</span>http.request.method==GET<span class="pl-pds">'</span></span> -T fields -e tcp.srcport <span class="pl-k">|</span> sort -u <span class="pl-k">|</span> <span class="pl-k">while</span> <span class="pl-c1">read</span> PORT<span class="pl-k">;</span><span class="pl-k">do</span> tshark -r http.pcapng -Y <span class="pl-s"><span class="pl-pds">"</span>tcp.dstport==<span class="pl-smi">$PORT</span> && http.server contains Apache<span class="pl-pds">"</span></span> -T fields -e ip.src<span class="pl-k">;</span><span class="pl-k">done</span> <span class="pl-k">|</span> sort -u
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The -u argument output only the first of an equal run
- The -Y command captures the link type

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-2)Exercise 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#how-many-http-get-request-messages-did-your-browser-send)How many HTTP GET request messages did your browser send?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---3">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http.request.method==GET <span class="pl-k">|</span> wc -l
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The wc command prints a newline, word, and byte counts for each file
- The -l argument prints the newline counts

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#to-which-internet-addresses-were-these-get-requests-sent)To which Internet addresses were these GET requests sent?

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---4">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y http.request.method==GET -T fields -e ip.dst <span class="pl-k">|</span> sort -u
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y command captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The -u argument output only the first of an equal run

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-5)Exercise 5:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#use-netcat-to-download-these-images-check-the-echo--ne-options-or-use-printf-if-needed-slow-down-netcat-with-option--i-the-image-part-in-the-http-stream-starts-after-a-blank-line)Use Netcat to download these images. check the echo -ne options or use printf. If needed, slow down netcat with option -i. The image part in the HTTP stream starts after a blank line.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-echo--ne-0">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> -ne <span class="pl-s"><span class="pl-pds">"</span>GET /nw2/images/image1.jpg HTTP/1.1\r\nHost: darthvader.uclllabs.be\r\n\r\n<span class="pl-pds">"</span></span> <span class="pl-k">|</span><span class="pl-cce">\ </span>nc darthvader.uclllabs.be 80 <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>1,/^\r/d<span class="pl-pds">'</span></span> <span class="pl-k">></span> image1.jpg

<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> -ne <span class="pl-s"><span class="pl-pds">"</span>GET /nw2/images/image1.jpg HTTP/1.1\r\nHost: darthvader.uclllabs.be\r\n\r\n<span class="pl-pds">"</span></span> <span class="pl-k">|</span><span class="pl-cce">\ </span>nc darthvader.uclllabs.be 80 <span class="pl-k">|</span> grep -A9999999999999999 -B0 -Pa <span class="pl-s"><span class="pl-pds">'</span>JFIF<span class="pl-pds">'</span></span> <span class="pl-k">></span> image1.jpg
```

</div>- The -n argument does not output the trailing newline
- The -e argument enables interpretation of backslash escapes
- The sed command is a stream editor for filtering and transforming text
- The nc command is a TCP/IP swiss army knife
- The -A argument prints NUM lines of trailing context after matching lines.
- The -B argument interprets PATTERN as a Perl regular expression (PCRE, see below).
- The -a argument processes a binary file as if it were text; this is equivalent to the --binary-files=text option.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-7)Exercise 7:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#use-httpie-a-curl-like-tool-for-humans-to-inspect-the-various-http-headers-in-request-and-responses-connect-to-various-websites-and-explain-the-use-of-the-http-headers)Use httpie, a cURL-like tool for humans to inspect the various HTTP headers in request and responses. Connect to various websites and explain the use of the HTTP headers.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-http--v-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • http -v -a Rey:StarWars http://darthvader.uclllabs.be/nw2/private/
```

</div>- The -v argument is for verbose

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-8)Exercise 8:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#a-simulated-phone-is-running-at-httpdarthvaderuclllabsbenw2phone-create-a-oneliner-to-bruteforce-the-pincode-tip-pincode-range-1200-1300)A simulated phone is running at [http://darthvader.uclllabs.be/nw2/phone/](http://darthvader.uclllabs.be/nw2/phone/). Create a oneliner to bruteforce the pincode. Tip: pincode range: 1200-1300

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-for-foo-">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> {1200..1300}<span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-k">if</span> wget -q --http-user=<span class="pl-s"><span class="pl-pds">'</span>admin<span class="pl-pds">'</span></span> --http-password=<span class="pl-smi">$foo</span> http://darthvader.uclllabs.be/nw2/phone<span class="pl-k">;</span> <span class="pl-k">then</span> <span class="pl-c1">echo</span> <span class="pl-smi">$foo</span><span class="pl-k">;</span><span class="pl-c1">break</span><span class="pl-k">;</span><span class="pl-k">fi</span><span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>- The wget command is the non-interactive network downloader
- The -q argument turns of the wget's output
- The --http-user AND --http-password specifies the username and the password on a http server

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-9)Exercise 9:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#put-the-following-texttxt-on-your-web-server-this-text-contains-the-string-goed-bezig--)"Put the following text.txt on your web server. This text contains the string Goed bezig :-)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#write-an-http-request-by-using-the-range-header-so-your-web-server-will-only-return-this-exact-string-goed-bezig---try-to-do-this-by-only-using-netcat)Write an HTTP request by using the Range header so your web server will only return this exact string 'Goed bezig :-)'. Try to do this by only using netcat

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-curl-htt">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • curl http://your.server.name/output.txt -i -H <span class="pl-s"><span class="pl-pds">"</span>Range: bytes=1-<span class="pl-pds">"</span></span>
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> -ne <span class="pl-s"><span class="pl-pds">"</span>GET /output.txt HTTP/1.1\r\nHost: your.server.name\r\nRange: bytes=1-\r\n\r\n<span class="pl-pds">"</span></span> <span class="pl-k">|</span> nc your.server.name 80
```

</div>- The curl command is used to transfer a URL
- The -i argument includes the HTTP-header in the output
- The -H argument is used as a extra header to use when getting a web page
- The nc command is a TCP/IP swiss army knife
- The -n argument does not output the trailing newline
- The -e argument enables interpretation of backslash escapes

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-10)Exercise 10:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#this-can-be-accomplished-by-sending-the-output-of-tshark-or-tcpdump-to-stdout-instead-of-a-regular-file-direct-this-stdout-stream-to-wireshark-running-on-your-local-computer)This can be accomplished by sending the output of tshark or tcpdump to STDOUT instead of a regular file. Direct this STDOUT stream to Wireshark running on your local computer.

<div id="bkmrk-%27root-%23%27-%E2%80%A2-ssh-myser">```
<span class="pl-s"><span class="pl-pds">'</span>root #<span class="pl-pds">'</span></span> • ssh myserver.X.cnw2.uclllabs.be tcpdump -nli eth0 not tcp port 22345 -s0 -w - <span class="pl-k">|</span> wireshark -nki -

<span class="pl-s"><span class="pl-pds">'</span>root #<span class="pl-pds">'</span></span> • ssh myserver.X.cnw2.uclllabs.be <span class="pl-s"><span class="pl-pds">'</span>tshark -nli eth0 -f "not tcp port 22345" -s0 -w -<span class="pl-pds">'</span></span> <span class="pl-k">|</span> wireshark -nki -
```

</div>- The ssh command is a remote login program
- The -n argument redirects stdin from /dev/null (actually, prevents reading from stdin).
- The -l argument specifies the user to log in as on the remote machine.
- The -i argument selects a file from which the identity (private key) for public key authentication is read.
- The -s argument may be used to request invocation of a subsystem on the remote system
- The -w argument Requests tunnel device forwarding with the specified tun(4) devices between the client (local\_tun) and the server (remote\_tun).
- The -n argument disables network object name resolution (such as hostname, TCP and UDP port names), the -N flag might override this one.
- The -k argument starts the capture session immediately.
- The -i argument sets the name of the network interface or pipe to use for live packet capture.
- The -f argument (in tshark command) sets the capture filter expression

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-11)Exercise 11:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#capture-some-http-traffic-while-browsing-several-websites-and-save-it-to-the-file-httppcapng)Capture some HTTP traffic while browsing several websites and save it to the file http.pcapng.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#you-can-also-use-the-test-capture-in-homelogs-on-leia-create-a-cli-oneliner-which-parses-the-captured-file-httppcapng-and-displays-all-http-server-strings-which-do-not-contain-apache)You can also use the test capture in /home/logs on leia. create a CLI oneliner which parses the captured file http.pcapng and displays all HTTP server strings which do not contain Apache.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#only-the-commands-tshark-and-sort-are-allowed)Only the commands tshark and sort are allowed.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---5">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y <span class="pl-s"><span class="pl-pds">'</span>http.server && !(http.server contains Apache)<span class="pl-pds">'</span></span> -T fields -e http.server <span class="pl-k">|</span> sort -u
```

</div>- The -r argument reads the packet date from infile
- The -Y command captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The -u argument output only the first of an equal run

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#exercise-12)Exercise 12:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%202.md#this-exercise-is-a-small-variation-of-the-previous-one-count-and-sort-all-http-server-strings-which-do-not-contain-apache-in-http-responses-on-your-get-requests)This exercise is a small variation of the previous one. Count and sort all HTTP server strings which do not contain Apache in HTTP responses on your GET requests.

<div id="bkmrk-%27user%3A%7E%24%27-%E2%80%A2-tshark---6">```
<span class="pl-s"><span class="pl-pds">'</span>user:~$<span class="pl-pds">'</span></span> • tshark -r http.pcapng -Y <span class="pl-s"><span class="pl-pds">'</span>!(http.request.method==GET)<span class="pl-pds">'</span></span> -T fields -e tcp.srcport <span class="pl-k">|</span> sort -u <span class="pl-k">|</span> <span class="pl-k">while</span> <span class="pl-c1">read</span> PORT<span class="pl-k">;</span><span class="pl-k">do</span> tshark -r http.pcapng -Y <span class="pl-s"><span class="pl-pds">"</span>tcp.dstport==<span class="pl-smi">$PORT</span> && http.server && !(http.server contains Apache)<span class="pl-pds">"</span></span> -T fields -e http.server<span class="pl-k">;</span><span class="pl-k">done</span> <span class="pl-k">|</span> sort <span class="pl-k">|</span> uniq -c <span class="pl-k">|</span> sort -rn
```

<div><svg aria-hidden="true" class="octicon octicon-clippy js-clipboard-clippy-icon m-2" data-view-component="true" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg></div></div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y command captures the link type
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The -u argument output only the first of an equal run
- The -T argument sets the format of the output when viewing decoded packet data.
- The uniq command reports or omits repeated lines
- The -c command prefixes lines by the number of occurrences
- The -r argument (in sort command) reverses the results of comparisons
- The -n compare according to string numerical value

# 2019 oplossingen labo 3 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# Labo 3

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#match-one-or-more-d-characters-d-dd-ddd-dddd-)Match one or more d characters: d dd ddd dddd "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--p">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -P <span class="pl-s"><span class="pl-pds">'</span>d+<span class="pl-pds">'</span></span> file

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • cat file <span class="pl-k">|</span> grep -P <span class="pl-s"><span class="pl-pds">'</span>d+<span class="pl-pds">'</span></span>
```

</div>- d matches the character d literally (case sensitive)
- The grep command prints lines matching a pattern
- The -P argument interprets PATTERN as a Perl regular expression

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#color-and-colour-are-different-spellings-of-the-same-word)Color and colour are different spellings of the same word.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#color-is-the-preferred-spelling-in-american-english-and-colour-is-preferred-in-all-other-main-varieties-of-english-the-following-regex-matches-both-)Color is the preferred spelling in American English, and colour is preferred in all other main varieties of English. The following regex matches both. "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--p-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -P <span class="pl-s"><span class="pl-pds">'</span>colou?r<span class="pl-pds">'</span></span> file
```

</div>- colo matches the characters colo literally (case sensitive)
- u matches the character u literally (case sensitive)
- ? matches the previous token between zero and one times, as many times as possible, giving back as needed (greedy)
- r matches the characters r literally (case sensitive)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#match-wh-following-by-one-two-or-three-e-character-whe-whee-wheee)Match wh following by one, two or three e character: 'whe whee wheee'

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--p-1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -P <span class="pl-s"><span class="pl-pds">'</span>whe{1,3}<span class="pl-pds">'</span></span> file
```

</div>- The grep command prints lines matching a pattern
- The -P argument interprets PATTERN as a Perl regular expression
- whe matches the characters whe literally (case sensitive)
- {1,3} matches the previous token between 1 and 3 times, as many times as possible, giving back as needed (greedy)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#match-either-gray-or-grey)Match either gray or grey

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--p-2">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -P <span class="pl-s"><span class="pl-pds">'</span>{gray|grey}<span class="pl-pds">'</span></span> file
```

</div>- The grep command prints lines matching a pattern
- The -P argument interprets PATTERN as a Perl regular expression
- '{gray|grey}' must match gray or gray

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#lets-say-you-want-to-match-a-text-like-abc-or-123-only-these-two-are-possible-and-you-want-to-capture-the-abc-or-123)Let's say you want to match a text like !abc! or !123!. Only these two are possible, and you want to capture the abc or 123.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--p-3">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -P <span class="pl-s"><span class="pl-pds">'</span>!(abc|123)!<span class="pl-pds">'</span></span> file
```

</div>- The grep command prints lines matching a pattern
- The -P argument interprets PATTERN as a Perl regular expression
- '{gray|grey}' must match !abc! or !123!

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#search-usrsharedictdutch-for-all-words-which-end-in-vuur-without-matching-the-word-vuur-itself)Search /usr/share/dict/dutch for all words which end in 'vuur', without matching the word 'vuur' itself.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--p-4">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -P <span class="pl-s"><span class="pl-pds">'</span>^.+vuur$<span class="pl-pds">'</span></span> /usr/share/dict/dutch
```

</div>- ^ asserts position at start of a line
- . matches any character (except for line terminators)
- matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- vuur matches the characters vuur literally

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-words-which-contain-32-or-more-letters)List all words which contain 32 or more letters.

<div id="bkmrk-user%40%3A%7E%24%27-%E2%80%A2-grep--p-">```
user@:<span class="pl-k">~</span><span class="pl-s"><span class="pl-pds">$'</span> • grep -P <span class="pl-pds">'</span></span>^.{32}<span class="pl-s"><span class="pl-pds">$'</span> /usr/share/dict/dutch</span>
```

</div>- ^ asserts position at start of a line
- . matches any character (except for line terminators)
- {32} matches the previous token exactly 32 times
- $ asserts position at the end of a line

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-words-starting-with-the-letter-b-ending-with-the-letter-l-which-are-exactly-4-letters-long-capitalize-the-output)List all words starting with the letter 'b', ending with the letter 'l' which are exactly 4 letters long. Capitalize the output

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-grep--e">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • grep -E <span class="pl-s"><span class="pl-pds">'</span>^b.{2}l$<span class="pl-pds">'</span></span> /usr/share/dict/dutch <span class="pl-k">|</span> tr [:lower:] [:upper:]
    
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • perl -ne <span class="pl-s"><span class="pl-pds">'</span>print uc if /^b.{2}l$/<span class="pl-pds">'</span></span> /usr/share/dict/dutch
```

</div>- ^ asserts position at start of a line
- b matches the character b literally (case sensitive)
- . matches any character (except for line terminators)
- {2} matches the previous token exactly 2 times
- l matches the character l literally (case sensitive)
- $ asserts position at the end of a line
- The perl command is how to execute the Perl interpreter
- The -n argument causes Perl to assume the following loop around your program, which makes it iterate over filename arguments somewhat like sed -n or awk:
- The -e argument may be used to enter one line of program.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-palindromes-with-exactly-4-characters)List all palindromes with exactly 4 characters

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-gre">```
```
'user@:~$' • grep -P '^([A-Za-z])([A-Za-z])\2\1$' /usr/share/dict/dutch

'user@:~$' • perl -lne 'print if $_ eq reverse && length($_) eq 4' /usr/share/dict/dutch
```

```

</div>- A-Z matches a single character in the range between A and Z (case sensitive)
- a-z matches a single character in the range between a and z (case sensitive)
- \\2 matches the same text as most recently matched by the 2nd capturing group
- \\1 matches the same text as most recently matched by the 1st capturing group
- $ asserts position at the end of a line

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-1)Exercise 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-words-out-of-the-file-usrsharedictdutch-which-contain-4-or-5-consecutive-vowels)List all words out of the file /usr/share/dict/dutch which contain 4 or 5 consecutive vowels.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat">```
```
'user@:~$' • cat /usr/share/dict/dutch | grep -P '[aeiou]{4,5}'
```

```

</div>- aeiou matches a single character in the list aeiou (case sensitive)
- {4,5} matches the previous token between 4 and 5 times, as many times as possible, giving back as needed (greedy)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-2)Exercise 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#count-the-number-of-words-out-of-the-file-usrsharedictdutch-which-which-start-with-ver-and-end-with-en-verplaatsen-is-ok-overkomen-and-vertrek-are-not-ok)Count the number of words out of the file /usr/share/dict/dutch which which start with 'ver', and end with 'en'. ('verplaatsen' is ok, 'overkomen' and 'vertrek' are not ok)

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-gre-0">```
```
'user@:~$' • grep -P '^ver.*en$' /usr/share/dict/dutch | wc -l
```

```

</div>- ^ asserts position at start of a line
- ver matches the characters ver literally (case sensitive)
- . matches any character (except for line terminators)
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy)
- $ asserts position at the end of a line
- The wc command prints newline, word, and byte counts for each file
- The -l argument prints the newline counts

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-3)Exercise 3:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#in-those-annoying-night-television-games-people-must-guess-words-given-are-all-the-letters-the-word-consist-of-and-a-list-of-dots-one-for-every-letter)In those annoying night television games people must guess words. Given are all the letters the word consist of and a list of dots, one for every letter.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#eg-we-are-looking-for-a-23-letter-word-with-a-v-in-position-8-v-use-the-letters-enrtiscau-for-the-other-positions)E.g. We are looking for a 23 letter word with a 'v' in position 8: '.......v...............'. Use the letters 'enrtiscau' for the other positions."

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-0">```
```
'user@:~$' • cat /usr/share/dict/dutch | grep -P '[enrtiscau]{7}v[enrtiscau]{15}'
```

```

</div>- enrtiscau matches a single character in the list enrtiscau (case sensitive)
- {7} matches the previous token exactly 7 times
- {15} matches the previous token exactly 15 times

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-4)Exercise 4:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#show-system-load--x-y-z-replacing-x-y-and-z-by-the-values-displayed-by-the-uptime-command)Show 'System load = X Y Z' replacing X, Y and Z by the values displayed by the uptime command.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-ech">```
```
'user@:~$' • echo "System load =" $(uptime | awk -F': ' '{print $2}'| tr -d ',')
```

```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-5)Exercise 5:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-the-usernames-of-the-students-who-logged-in-from-outside-of-the-ucll-network)List the usernames of the students who logged in from outside of the UCLL network.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-who">```
```
'user@:~$' • who | grep -Pv '(.*)\s+pts.*\s+\(10\.|tmux' | awk '/^r[0-9]/{print $1}' | sort -u
```

```

</div>- . matches any character (except for line terminators)
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy)
- \\s matches any whitespace character (equivalent to \[\\r\\n\\t\\f\\v \])
- r matches the character r literally (case sensitive)
- - matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- tmux matches the characters tmux literally (case sensitive)
- ^ asserts position at start of a line
- 0-9 matches a single character in the range between 0 and 9 (case sensitive)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-6)Exercise 6:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#how-many-times-have-students-logged-into-leia-from-outside-the-ucll-network)How many times have students logged into leia from outside the UCLL network?

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-las">```
```
'user@:~$' • last | grep -Pv '.*?pts.*?\s+10\.' | awk '/^r[0-9]/{print $1}' | wc -l
```

```

</div>- . matches any character (except for line terminators)
- \*? matches the previous token between zero and unlimited times, as few times as possible, expanding as needed (lazy)
- pts matches the characters pts literally (case sensitive)
- r matches the character r literally (case sensitive)
- \\s matches any whitespace character (equivalent to \[\\r\\n\\t\\f\\v \])
- '+' matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- ^ asserts position at start of a line

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-7)Exercise 7:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#show-the-file-etcdebconfconf-on-screen-without-comment-lines-ie-lines-starting-with-a-)Show the file /etc/debconf.conf on screen without comment lines (i.e. lines starting with a #)

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-1">```
```
'user@:~$' • cat /etc/debconf.conf | grep -vP '^#'
```

```

</div>- ^ asserts position at start of a line
- '#' matches the character # literally (case sensitive)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-8)Exercise 8:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-unique-ip-addresses-that-contacted-your-apache-web-server)List all unique IP addresses that contacted your Apache web server.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-2">```
```
'user@:~$' • cat /var/log/apache2/wiki-ssl-access.log | awk '{print $1}' | sort -u
```

```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-9)Exercise 9:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-unique-ip-addresses-that-contacted-the-ssh-daemon-of-your-apache-web-server)List all unique IP addresses that contacted the ssh daemon of your Apache web server.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-3">```
```
'user@:~$' • cat /var/log/auth.log | grep -oP 'sshd.*?\K[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | sort -u
```

```

</div>- sshd matches the characters sshd literally
- . matches any character (except for line terminators)
- \*? matches the previous token between zero and unlimited times, as few times as possible, expanding as needed (lazy)
- \\K resets the starting point of the reported match. Any previously consumed characters are no longer included in the final match
- \[0-9\]{1,3} matches the previous token between 1 and 3 times, as many times as possible, giving back as needed (greedy)
- 0-9 matches a single character in the range between 0 and 9 (case sensitive)
- . matches the character . literally (case sensitive)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-10)Exercise 10:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#create-a-regular-expression-to-match-all-words-in-the-dictionary-usrsharedictdutch-which-with-10-unique-letters)Create a regular expression to match all words in the dictionary /usr/share/dict/dutch which with 10 unique letters.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-4">```
```
'user@:~$' • cat /usr/share/dict/dutch | grep -P '^.{10}$' | grep -vP '(.).*\1'
```

```

</div>- ^ asserts position at start of a line
- . matches any character (except for line terminators)
- {10} matches the previous token exactly 10 times
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy)
- \\1 matches the same text as most recently matched by the 1st capturing group

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-11)Exercise 11:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#to-combat-spam-a-mail-server-administrator-wants-to-reject-mail-coming-from-home-users-the-ip-addresses-home-users-always-seem-to-connect-from-have-hostnames-like-this-ipdomain-create-a-regex-which-matches-all-these-host-names)To combat spam, a mail server administrator wants to reject mail coming from home users. The IP addresses home users always seem to connect from have hostnames like this: ip.domain. Create a regex which matches all these host names.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-5">```
```
'user@:~$' • cat mail.log | grep -oP 'NOQUEUE: reject: RCPT from \K[0-9]{1,3}.*?\[' | tr -d '['
```

```

</div>- \[0-9\]{1,3} matches the previous token between 1 and 3 times, as many times as possible, giving back as needed (greedy)
- . matches any character (except for line terminators)
- \*? matches the previous token between zero and unlimited times, as few times as possible, expanding as needed (lazy)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-12)Exercise 12:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-unique-firefox-200x-versions-used-to-connect-to-wwwkhleuvenbe-use-log-file-homelogsapache_googlelog-)List all unique firefox 2.0.0.x versions used to connect to [www.khleuven.be](http://www.khleuven.be/). Use log file /home/logs/apache\_google.log. "

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-cat-6">```
```
'user@:~$' • cat apache_google.log | grep -oP 'Firefox\/2\.0\.0\.[0-9]+' | sort -n -t '.' -k4 -u
```

```

</div>- Firefox matches the characters Firefox literally (case sensitive)
- / matches the character / literally (case sensitive)
- 2 matches the character 2 literally (case sensitive)
- . matches the character . literally (case sensitive)
- 0 matches the character 0 literally (case sensitive)
- \[0-9\]+ matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#exercise-13)Exercise 13:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%203.md#list-all-words-with-14-15-or-16-unique-letters)List all words with 14, 15 or 16 unique letters.

<div id="bkmrk-%60%60%60-%27user%40%3A%7E%24%27-%E2%80%A2-for">```
```
'user@:~$' • for foo in 14 15 16; do echo "Words with $foo letters:" $(echo "grep -vP '(.).*\1' /usr/share/dict/dutch | grep -P '^.{$foo}$'"| sh);done

'user@:~$' • for foo in 14 15 16; do echo "Words with $foo letters:" $(grep -vP '(.).*\1' /usr/share/dict/dutch | grep -P "^.{$foo}$");done

'user@:~$' • for foo in 14 15 16; do echo "Words with $foo letters:" && echo "grep -vP '(.).*\1' /usr/share/dict/dutch | grep -P '^.{$foo}$'"| sh;done

'user@:~$' • for foo in 14 15 16; do echo "Words with $foo letters:" && grep -vP '(.).*\1' /usr/share/dict/dutch | grep -P "^.{$foo}$";done
```

```

<div><svg aria-hidden="true" class="octicon octicon-clippy js-clipboard-clippy-icon m-2" data-view-component="true" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg></div></div>- . matches any character (except for line terminators)
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy)
- \\1 matches the same text as most recently matched by the 1st capturing group
- ^ asserts position at start of a line
- $ asserts position at the end of a line
- foo} matches the characters foo} literally (case sensitive) $ asserts position at the end of a line

# 2019 oplossingen labo 4 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# Labo 4

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#what-is-the-ip-address-of-the-client-and-what-ip-address-is-used-by-the-server)What is the IP address of the client and what IP address is used by the server?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#which-protocol-was-used-to-find-the-ip-address-of-the-ftp-server)Which protocol was used to find the IP address of the FTP server.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#does-ftp-use-udp-or-tcp-why)Does FTP use UDP or TCP? Why?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#is-the-session-using-active-or-passive-ftp)Is the session using active or passive FTP?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#who-chooses-the-ftp-version-active-or-passive-is-it-the-client-or-the-server)Who chooses the FTP version, active or passive? Is it the client or the server?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#sketch-the-three-way-handshake-used-to-negotiate-the-initial-sequence-numbers-do-this-both-for-the-relative-and-the-real-sequence-numbers)Sketch the three-way handshake used to negotiate the initial sequence numbers. Do this both for the relative and the real sequence numbers.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#what-is-the-benefit-in-using-relative-sequence-numbers-in-wiresharktshark)What is the benefit in using relative sequence numbers in Wireshark/Tshark?

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#which-credentials-were-used-to-login-to-the-ftp-service)Which credentials were used to login to the FTP service?

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">"</span>tcp.srcport == <span class="pl-pds">$(</span>tshark -r Cnw2_ftp.pcap -Y <span class="pl-pds">'</span>ftp.response.code == 230<span class="pl-pds">'</span> -T fields -e tcp.dstport<span class="pl-pds">)</span> && ftp.request.command == USER<span class="pl-pds">"</span></span> -T -e ftp.request.arg
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#step-1)"Step 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#when-a-users-login-attempt-is-successful-the-ftp-server-answers-with-ftp-response-code-230---response-code-user-logged-in-proceed-230)When a user's login attempt is successful, the FTP server answers with FTP response code 230 &lt;- Response code: User logged in, proceed (230).

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#this-message-is-sent-to-the-client-using-its-chosen-tcp-port-this-very-same-tcp-port-is-used-by-the-client-for-every-packet-sent-in-the-control-connection)This message is sent to the client using it's chosen TCP port. This very same TCP port is used by the client for every packet sent in the control connection.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#so-we-know-the-client-will-use-this-port-as-tcp-source-port-when-profiding-the-ftp-username-thus-the-first-step-is-to-find-this-tcp-port)So we know the client will use this port as TCP source port when profiding the FTP username. Thus the first step is to find this TCP port:

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#see-cnw2-theory---chapter-2-application-layer-active-vs-passive-ftp)See Cnw2 theory - Chapter 2: Application Layer: Active vs Passive FTP

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark--0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.response.code == 230<span class="pl-pds">'</span></span> -T fields -e tcp.dstport
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#step-2)Step 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#the-port-we-just-found-is-the-tcp-port-the-client-uses-for-the-ftp-control-connection)The port we just found is the TCP port the client uses for the FTP control connection.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#when-using-this-port-as-tcp-source-port-in-our-display-filter-well-only-list-packets-sent-from-client-to-ftp-server)When using this port as TCP source port in our display filter, we'll only list packets sent from client to FTP server

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark--1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">"</span>tcp.srcport == <span class="pl-pds">$(</span>tshark -r Cnw2_ftp.pcap -Y <span class="pl-pds">'</span>ftp.response.code == 230<span class="pl-pds">'</span> -T fields -e tcp.dstport<span class="pl-pds">)</span><span class="pl-pds">"</span></span>
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data. The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#step-3)Step 3:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#were-only-interested-in-the-packet-containing-the-username-so-lets-add-ftprequestcommand--user-to-the-display-filter)We're only interested in the packet containing the username, so let's add 'ftp.request.command == USER' to the display filter:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark--2">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">"</span>tcp.srcport == <span class="pl-pds">$(</span>tshark -r Cnw2_ftp.pcap -Y <span class="pl-pds">'</span>ftp.response.code == 230<span class="pl-pds">'</span> -T fields -e tcp.dstport<span class="pl-pds">)</span> && ftp.request.command == USER<span class="pl-pds">"</span></span>
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The server sends a 230 code in response to a command that has provided sufficient credentials to the server to grant the user access to the FTP server.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#step-4)Step 4:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#and-finally-use-the-tshark-fields-option-to-only-display-the-username-used)And finally use the tshark fields option to only display the username used:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark--3">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">"</span>tcp.srcport == <span class="pl-pds">$(</span>tshark -r Cnw2_ftp.pcap -Y <span class="pl-pds">'</span>ftp.response.code == 230<span class="pl-pds">'</span> -T fields -e tcp.dstport<span class="pl-pds">)</span> && ftp.request.command == USER<span class="pl-pds">"</span></span> -T fields -e ftp.request.arg debbie
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The server sends a 230 code in response to a command that has provided sufficient credentials to the server to grant the user access to the FTP server.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#which-file-was-downloadeduploaded-fromto-the-ftp-server-delete-as-appropriate)Which file was downloaded/uploaded from/to the FTP server? (delete as appropriate)

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark--">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.request.command == RETR<span class="pl-pds">'</span></span> <span class="pl-k">|</span> grep -Po <span class="pl-s"><span class="pl-pds">'</span>RETR \K.*<span class="pl-pds">'</span></span>
```

</div>- The RETR argument ==&gt; client issues the RETR command after successfully establishing a data connection when it wishes to download a copy of a file on the server.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The -P argument interprets I as Perl-compatible regular expressions (PCREs).
- The -o argument prints only the matched (non-empty) parts of a matching line, with each such part on a separate output line.32

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#can-you-reconstruct-this-file-from-the-wireshark-packet-dump-open-the-file-to-verify-its-contents-are-intact)Can you reconstruct this file from the Wireshark packet dump? Open the file to verify it's contents are intact.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#how-many-packets-have-their-destination-port-set-to-21)How many packets have their destination port set to 21?

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---0">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>tcp.dstport == 21<span class="pl-pds">'</span></span> <span class="pl-k">|</span> wc -l
```

</div>- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- tcp.dstport == 21 =&gt; TCP port
- The wc command prints newline, word, and byte counts for each file
- The argument -l prints the newline counts

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#list-all-packets-which-have-the-push-bit-set-what-is-the-benefit-in-setting-this-bit)List all packets which have the PUSH bit set. What is the benefit in setting this bit?

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---1">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>tcp.flags.push == 1<span class="pl-pds">'</span></span>
```

</div>- The -r argument reads the packet date from infile
- tcp.flags.push == 1 =&gt; Which means "check if the Push flag is set". Filtering for just "tcp.flags.push" would again mean "check if there's a push flag field" (which there is, always)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#how-can-you-manually-calculate-the-actual-port-advertised-by-the-pasvport-command)How can you manually calculate the actual port advertised by the PASV/PORT command?

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---2">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.response.code == 227<span class="pl-pds">'</span></span> <span class="pl-k">|</span> awk -F <span class="pl-s"><span class="pl-pds">'</span>,<span class="pl-pds">'</span></span> <span class="pl-s"><span class="pl-pds">'</span>{print $5*256+$6}<span class="pl-pds">'</span></span>
```

</div>- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- This is the response given by the server to the PASV command. It indicates that the server is ready for the client to connect to it for the purpose of establishing a data connection.
- The awk command is used for pattern scanning and processing language
- The -F argument
- 5 matches the character 5 literally (case sensitive)
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy)
- 25 matches the characters 25 literally (case sensitive)
- 6 matches the character 6 literally (case sensitive) + matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- $ asserts position at the end of a line
- 6 matches the character 6 literally (case sensitive)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#how-many-l4-sessions-were-created-in-the-ftp-session-note-passive-ftp-was-used-in-this-session)How many L4 sessions were created in the FTP session? Note: passive FTP was used in this session.

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---3">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.response.code == 230 || ftp.response.code == 227<span class="pl-pds">'</span></span> <span class="pl-k">|</span> wc -l
```

</div>- The server sends a 230 code in response to a command that has provided sufficient credentials to the server to grant the user access to the FTP server.
- This is the response given by the server to the PASV command. It indicates that the server is ready for the client to connect to it for the purpose of establishing a data connection.
- The wc command prints newline, word, and byte counts for each file
- The argument -l prints the newline counts

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#try-to-answer-these-questions-with-cnw2_ftp_bruteforcepcap-file)Try to answer these questions with 'cnw2\_ftp\_bruteforce.pcap: (file)'

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#how-many-password-guesses-were-made)How many password guesses were made?

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---4">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.request.command == PASS<span class="pl-pds">'</span></span> -T fields -e ftp.request.arg <span class="pl-k">|</span> wc -l
```

</div>- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- So, to see all login attempts, try this filter: ftp.request.command==USER || ftp.request.command==PASS
- The wc command prints newline, word, and byte counts for each file
- The argument -l prints the newline counts

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#did-the-attacker-finally-get-in)Did the attacker finally get in?

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---5">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.response.code == 230<span class="pl-pds">'</span></span> <span class="pl-k">|</span> grep -q <span class="pl-s"><span class="pl-pds">'</span>Response: 230<span class="pl-pds">'</span></span> <span class="pl-k">&&</span> <span class="pl-c1">echo</span> YES <span class="pl-k">||</span> <span class="pl-c1">echo</span> NO
```

</div>- The server sends a 230 code in response to a command that has provided sufficient credentials to the server to grant the user access to the FTP server.
- The -q argument = quiet - do not write anything to standard output
- The -r argument reads the packet date from infile
- The -Y argument captures the link type

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%204.md#which-usernames-did-heshe-try)Which usernames did he/she try?

<div id="bkmrk-%27user%40%7E%24%27-%E2%80%A2-tshark---6">```
<span class="pl-s"><span class="pl-pds">'</span>user@~$<span class="pl-pds">'</span></span> • tshark -r Cnw2_ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.request.command == USER<span class="pl-pds">'</span></span> -T fields -e ftp.request.arg <span class="pl-k">|</span> sort -u
```

</div>- The -r argument reads the packet date from infile
- The -Y argument captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The -u argument =&gt; with -c, checks for strict ordering; without -c, output only the first of an equal run

# 2019 oplossingen labo 5 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# LABO 5

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#encrypting-the-self-created-file-secrettxt-using-aes-can-be-done-like-this-)Encrypting the self created file secret.txt using AES can be done like this: "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl enc -aes-128-cbc -in secret.txt -out secret.txt.aes
```

</div>-The enc command is used for symmetric cipher routines

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#to-decrypt-the-file-created-above-and-show-the-decrypted-data-on-screen-use)To decrypt the file created above and show the decrypted data on screen, use:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl enc -d -aes-128-cbc -in secret.txt.aes
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#to-get-a-list-of-all-available-encryption-algorithms-in-openssl-type)To get a list of all available encryption algorithms in OpenSSL, type:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl list-cipher-commands
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#on-more-recent-openssl-versions-the-command-above-will-not-work-the-new-syntax-is-as-follows)On more recent OpenSSL versions the command above will not work. The new syntax is as follows:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-2">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl list -help
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl list -cipher-commands
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#thus-we-need-to-tell-our-application-that-ecrypted_picturebmp-is-indeed-a-bitmap-bitmaps-begin-with-a-54-byte-header)Thus we need to tell our application that ecrypted\_picture.bmp is indeed a bitmap. Bitmaps begin with a 54-byte header.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#the-idea-is-to-extract-the-first-54-bytes-of-the-unencrypted-bitmap-and-overwrite-the-first-54-bytes-of-the-encrypted-one-with-the-real-header-see-the-following-examples-)The idea is to extract the first 54 bytes of the unencrypted bitmap and overwrite the first 54 bytes of the encrypted one with the real header. See the following examples: "

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#aes-in-ecb-mode)AES in ECB mode

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-openss">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) openssl enc -aes-128-ecb -in slimmerik.bmp -out slimmerik_ECB.bmp
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) dd if=slimmerik.bmp of=slimmerik_ECB.bmp bs=1 count=54 conv=notrunc
```

</div>"We could, of course, automate this: "

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-dd-if%3D">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) dd if=slimmerik.bmp bs=1 count=54 <span class="pl-k">></span> slimmerik_ECB.bmp <span class="pl-k">&&</span> openssl enc -aes-128-ecb -k pass:t -in slimmerik.bmp <span class="pl-k">|</span> dd bs=1 skip=54 <span class="pl-k">>></span> slimmerik_ECB.bmp
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) dd if=slimmerik.bmp of=slimmerik_ECB.bmp bs=1 count=54 <span class="pl-k">&&</span> dd if=slimmerik.bmp bs=1 skip=54 <span class="pl-k">|</span> openssl enc -aes-128-ecb -k pass:t <span class="pl-k">>></span> slimmerik_ECB.bmp
```

</div>- The dd command converts and copy a file
- The -k argument forces nc to stay listening for another connection after its current connection is completed

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#aes-in-cbc-mode)AES in CBC mode

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-openss-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) openssl enc -aes-128-cbc -in slimmerik.bmp -out slimmerik_CBC.bmp
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) dd if=slimmerik.bmp of=slimmerik_CBC.bmp bs=1 count=54 conv=notrunc
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#rot13-encryption)ROT13 encryption

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-alias-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) <span class="pl-c1">alias</span> rot13=<span class="pl-s"><span class="pl-pds">"</span>tr '[A-Za-z]' '[N-ZA-Mn-za-m]'<span class="pl-pds">"</span></span>
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) cat slimmerik.bmp <span class="pl-k">|</span> rot13 <span class="pl-k">></span> slimmerik_rot13.bmpw
```

</div>- Match a single character present in the list below \[N-ZA-Mn-za-m\]
- N-Z matches a single character in the range between N (index 78) and Z (index 90) (case sensitive)
- A-M matches a single character in the range between A (index 65) and M (index 77) (case sensitive)
- n-z matches a single character in the range between n (index 110) and z (index 122) (case sensitive)
- a-m matches a single character in the range between a (index 97) and m (index 109) (case sensitive)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#you-need-a-key-pair-to-be-able-to-use-gnugp-you-can-generate-one-with-)You need a key pair to be able to use GnuGP. You can generate one with: "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-gpg---g">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • gpg --gen-key
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#after-your-keypair-is-created-you-should-immediately-generate-a-revocation-certificate-for-the-primary-public-key-using-the-option---gen-revoke)After your keypair is created you should immediately generate a revocation certificate for the primary public key using the option --gen-revoke.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#if-you-forget-your-passphrase-or-if-your-private-key-is-compromised-or-lost-this-revocation-certificate-may-be-published-to-notify-others-that-the-public-key-should-no-longer-be-used)If you forget your passphrase or if your private key is compromised or lost, this revocation certificate may be published to notify others that the public key should no longer be used

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-gpg---o">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • gpg --output revoke.asc --gen-revoke <span class="pl-k"><</span>mykey<span class="pl-k">></span> 
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#you-can-use-your-key-pair-to-encrypt-and-sign-but-without-exchanging-public-keys-this-is-useless-others-need-your-public-key-to-verify-your-signatures-and-to-send-encrypted-messages-to-you-you-need-their-keys-for-the-same-purposes)You can use your key pair to encrypt and sign, but without exchanging public keys this is useless. Others need your public key to verify your signatures and to send encrypted messages to you. You need their keys for the same purposes.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-gpg---l">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • gpg --list-keys
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#you-can-export-your-public-key-using)You can export your public key using:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-gpg---o-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • gpg --output <span class="pl-k"><</span>file<span class="pl-k">></span> --export <span class="pl-k"><</span>email<span class="pl-k">></span>
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#now-import-some-keys-from-classmates)Now import some keys from classmates:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-gpg---i">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • gpg --import <span class="pl-k"><</span>file<span class="pl-k">></span>
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#you-already-have-an-automatically-created-encryption-subkey-now-you-will-create-another-subkey-for-signing)You already have an automatically created encryption subkey. Now you will create another subkey for signing.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#instead-of-the-master-key-the-subkey-will-be-used-to-verifying-message-signatures)Instead of the master key the subkey will be used to verifying message signatures.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-gpg---e">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • gpg --edit-key YOURMASTERKEYID
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#exercise-1)Exercise 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#bob-needs-to-send-a-text-file-through-an-encrypted-tunnel-to-alice-both-already-agreed-on-a-shared-secret-secret-using-the-diffie-hellman-algorithm-alice-wants-to-display-the-contents-of-the-file-directly-on-her-screen-instead-of-storing-it-locally-and-then-opening-it-use-a-suitable-encryption-algorithm-the-data-is-sent-over-a-medium-which-only-allows-ascii-text)Bob needs to send a text file through an encrypted tunnel to Alice. Both already agreed on a shared secret 'secret' using the Diffie Hellman algorithm. Alice wants to display the contents of the file directly on her screen instead of storing it locally and then opening it. Use a suitable encryption algorithm. The data is sent over a medium which only allows ASCII text.

<div id="bkmrk-%27alice%40leia%3A%7E%24%27-%E2%80%A2-nc">```
<span class="pl-s"><span class="pl-pds">'</span>Alice@leia:~$<span class="pl-pds">'</span></span> • nc -l 10000 <span class="pl-k">|</span> openssl enc -a -d -aes-128-cbc -k pass:secret
<span class="pl-s"><span class="pl-pds">'</span>Bob@laptop:~$<span class="pl-pds">'</span></span> • cat file <span class="pl-k">|</span> openssl enc -a -aes-128-cbc -k pass:secret <span class="pl-k">|</span> nc leia.uclllabs.be 10000 
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#exercise-2)Exercise 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#bob-needs-to-send-a-text-file-through-an-encrypted-tunnel-to-alice-both-already-agreed-on-a-shared-secret-secret-using-the-diffie-hellman-algorithm-alice-wants-to-display-the-contents-of-the-file-directly-on-her-screen-instead-of-storing-it-locally-and-then-opening-it-use-a-suitable-encryption-algorithm-the-data-is-sent-over-a-medium-which-only-allows-ascii-text-)Bob needs to send a text file through an encrypted tunnel to Alice. Both already agreed on a shared secret 'secret' using the Diffie Hellman algorithm. Alice wants to display the contents of the file directly on her screen instead of storing it locally and then opening it. Use a suitable encryption algorithm. The data is sent over a medium which only allows ASCII text. "

**Step 1:**

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#as-bob-needs-to-send-an-encrypted-file-to-alice-he-will-need-her-public-key)As Bob needs to send an encrypted file to Alice, he will need her public key.

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#so-in-the-first-step-alice-needs-to-generate-a-keypair-and-export-her-public-key-so-she-could-provide-it-to-bob-)So in the first step Alice needs to generate a keypair, and export her public key so she could provide it to Bob. "

<div id="bkmrk-%27alice%40server-%7E-%24%27-%E2%80%A2">```
<span class="pl-s"><span class="pl-pds">'</span>Alice@Server ~ $<span class="pl-pds">'</span></span> • gpg --gen-key
<span class="pl-s"><span class="pl-pds">'</span>Alice@Server ~ $<span class="pl-pds">'</span></span> • gpg --output alice.gpg --export alice@uclllabs.be
```

</div>**Step 2:**

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#alice-has-exported-her-gpg-public-key-to-the-file-alicegpg)Alice has exported her gpg public key to the file alice.gpg.

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#she-sends-this-file-eg-by-email-to-bob-note-that-this-file-is-no-secret-it-is-just-a-public-key-now-bob-can-import-alices-public-key-into-gpg-)She sends this file e.g. by email to bob. Note that this file is no secret, it is just a public key. Now bob can import Alice's public key into gpg: "

<div id="bkmrk-%27bob%40leia-%7E-%24%27-%E2%80%A2-gpg">```
<span class="pl-s"><span class="pl-pds">'</span>Bob@leia ~ $<span class="pl-pds">'</span></span> • gpg --import alice.gpg 
```

</div>**Step 3:**

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#bob-is-ready-to-sent-his-secret-text-file-to-alice-while-providing-confidentiality)Bob is ready to sent his secret text file to Alice while providing confidentiality:

<div id="bkmrk-%27alice%40server-%7E-%24%27-%E2%80%A2-0">```
<span class="pl-s"><span class="pl-pds">'</span>Alice@Server ~ $<span class="pl-pds">'</span></span> • nc -l -p 10000 <span class="pl-k">|</span> gpg --decrypt --quiet

<span class="pl-s"><span class="pl-pds">'</span>Bob@leia ~ $<span class="pl-pds">'</span></span> • cat file.txt <span class="pl-k">|</span> gpg --encrypt --armor --output - --recipient alice@uclllabs.be <span class="pl-k">|</span> nc -N server.x.cnw2.uclllabs.be 10000 
```

</div>- The --encrypt argument encrypts data
- The --armor argument creates ASCII armored output
- The nc command is a TCP/IP swiss army knife

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#exercise-3)Exercise 3:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%205.md#same-exercise-as-above-but-now-use-gpg-and-netcat-to-create-a-simple-chat-application)Same exercise as above, but now use gpg and netcat to create a simple chat application.

<div id="bkmrk-%27alice%40server-%7E-%24%27-%E2%80%A2-1">```
<span class="pl-s"><span class="pl-pds">'</span>Alice@Server ~ $<span class="pl-pds">'</span></span> • nc -l -p 10000 <span class="pl-k">|</span> gpg --decrypt --quiet --allow-multiple-messages 

<span class="pl-s"><span class="pl-pds">'</span>Bob@leia ~ $<span class="pl-pds">'</span></span> • <span class="pl-k">while</span> <span class="pl-c1">read</span> line<span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-c1">echo</span> <span class="pl-smi">$line</span> <span class="pl-k">|</span> gpg --encrypt --armor --output - --recipient alice@uclllabs.be<span class="pl-k">;</span> <span class="pl-k">done</span> <span class="pl-k">|</span> nc -N server.x.cnw2.uclll
```

</div>

# 2019 oplossingen labo 6 - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# LABO 6

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#check-the-contents-of-the-ucllbe-wildcard-certificate-and-make-sure-you-understand-the-chain-of-trust)Check the contents of the ucll.be wildcard certificate, and make sure you understand the chain of trust.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect ucll.be:443 <span class="pl-k">|</span> openssl x509 -text -noout
```

</div>- x509 - is a certificate display and signing utility
- The -text argument prints out the certificate in text form.
- The -noout argument prevents output of the encoded version of the request

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#well-start-this-lab-by-making-our-very-own-ssl-certificate-before-we-can-create-a-certificate-we-need-to-generate-an-rsa-private-key)We'll start this lab by making our very own SSL certificate. Before we can create a certificate we need to generate an RSA private key.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl genrsa -aes128 -out TomBola.keys 2048
```

</div>- The genrsa command generates an RSA private key

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#use-the-following-command-to-remove-the-pass-phrase)Use the following command to remove the pass phrase:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl rsa -in TomBola.keys -out TomBola.keys
```

</div>- The -in command specifies the input filename to read a request from or standard input if this option is not specified
- The -out command specifies the output filename to write to or standard output by default.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#now-create-the-certificate-signing-request)Now create the Certificate Signing Request.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl req -new -key TomBola.keys -out TomBola.csr
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#lazy-admins-will-probably-prefer-the-following-command-its-result-is-the-same-as-all-three-commands-above-combined)Lazy admins will probably prefer the following command, its result is the same as all three commands above combined:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-2">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl req -new -newkey rsa:2048 -keyout TomBola.keys -nodes -out TomBola.csr
```

</div>- The -new command is used to generate a new certificate request
- The -newkey command creates a new certificate request and a new private key
- The -keyout command gives the filename to write the newly created private key to.
- The -nodes command is used if a private key is created it will not be encrypted.
- The -out command specifies the output filename to write to or standard output by default.
- The nodes argument -nodes tells OpenSSL not to encrypt the private key

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#this-verification-step-is-optional-but-recommended-now-we-need-somebody-to-sign-our-key-we-will-use-our-own-private-key-for-the-signature-creating-a-self-signed-certificate)This verification step is optional but recommended. Now we need somebody to sign our key. We will use our own private key for the signature, creating a self-signed certificate.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#as-a-self-signed-certificate-is-signed-by-itself-it-wont-be-trusted-by-client-software-like-email-clients-and-web-browsers)As a self-signed certificate is signed by itself it won't be trusted by client software like email clients and web browsers.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#only-public-keys-of-real-certificate-authorities-ca-are-included-in-the-browsers-or-oss-certificate-stores)Only public keys of real Certificate Authorities (CA) are included in the browsers or OSs certificate stores.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-3">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -req -days 365 -in TomBola.csr -signkey TomBola.keys -out TomBola.crt
```

</div>- The -req command is by default a certificate is expected on input. With this option a certificate request is expected instead.
- The -signkey command causes the input file to be self signed using the supplied private key.
- The -days command is used (when the -x509 option is being used) specifies the number of days to certify the certificate for.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#if-somehow-you-forgot-which-keycrtcsr-files-belong-to-each-other-compare-their-modulus-values-they-should-be-the-same-to-ease-the-comparing-process-create-a-hash-value-first)If somehow you forgot which key/crt/csr files belong to each other, compare their modulus values. They should be the same. To ease the comparing process create a hash value first.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-4">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -in TomBola.crt -noout -modulus <span class="pl-k">|</span> md5sum<span class="pl-k">;</span> <span class="pl-cce">\ </span>openssl req -in TomBola.csr -noout -modulus <span class="pl-k">|</span> md5sum<span class="pl-k">;</span> <span class="pl-cce">\ </span>openssl rsa -in TomBola.keys -noout -modulus <span class="pl-k">|</span> md5sum
```

</div>- The -in command specifies the input filename to read a certificate from or standard input if this option is not specified.
- The -noout command is used to prevent output of the encoded version of the request
- The -modulus command prints out the value of the modulus of the public key contained in the request.
- The -days command is used (when the -x509 option is being used) specifies the number of days to certify the certificate for.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#as-we-need-a-subject-alternative-name-san-field-to-specify-additional-names-associated-with-our-certificate-the-first-step-is-to-create-a-small-openssl-configuration-file)As we need a Subject Alternative Name (SAN) field to specify additional names associated with our certificate the first step is to create a small openssl configuration file.

<div id="bkmrk-file%3A-uclllabs_be.co">```
FILE: uclllabs_be.conf

[ req ]
default_bits = 4096
prompt = no
encrypt_key = no
default_md = sha512
distinguished_name = dn
req_extensions = v3_req

[ dn ]
C = BE
O = UC Leuven
CN = *.uclllabs.be

[ v3_req ]
subjectAltName = DNS:uclllabs.be

```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#in-the-next-step-we-generate-our-csr)In the next step, we generate our CSR

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-5">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl req -new -newkey rsa:4096 -nodes -out star_uclllabs_be.csr -keyout star_uclllabs_be.key -subj <span class="pl-s"><span class="pl-pds">"</span>/C=BE/ST=/L=/O=UC Leuven/CN=*.uclllabs.be<span class="pl-pds">"</span></span> -sha512 -config uclllabs_be.cnf
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl req -new -nodes -out star_uclllabs_be.csr -keyout star_uclllabs_be.key -config uclllabs_be.cnf
```

</div>- The command req is a certificate request and certificate generating utility
- The -new argument generates a new certificate request
- The -newkey argument creates a new certificate request and a new private key.
- The nodes argument -nodes tells OpenSSL not to encrypt the private key
- The -out argument is specified then if a private key is created it will not be encrypted.
- The -keyout argument gives the filename to write the newly created private key to.
- The -subj argument replaces subject field of input request with specified data and outputs modified request.
- The -config argument allows an alternative configuration file to be specified

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#first-check-whether-the-certificates-common-name-corresponds-with-the-server-name-check-the-expiration-date-and-check-the-chain-of-trust)First check whether the certificate's common name corresponds with the server name, check the expiration date and check the chain of trust.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C--0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect ucll.be:443 <span class="pl-k">|</span> openssl x509 -text -noout <span class="pl-k">|</span> grep -A2 Validity
```

</div>- x509 - is a certificate display and signing utility
- The -text argument prints out the certificate in text form.
- The -noout argument prevents output of the encoded version of the request

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#second-verify-the-certificate-is-not-listed-on-the-included-crl-certificate-revocation-list-httpcrl3digicertcomterenasslca3crl)Second, verify the certificate is not listed on the included CRL (Certificate Revocation List): [http://crl3.digicert.com/TERENASSLCA3.crl](http://crl3.digicert.com/TERENASSLCA3.crl)

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-wget-h">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) wget http://crl3.digicert.com/TERENASSLCA3.crl
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) openssl crl -in TERENASSLCA3.crl -text -noout
```

</div>- The -in argument specifies the input filename to read from or standard input if this option is not specified
- The -text argument prints out the CRL in text form.
- The -noout argument doesn't output the encoded version of the CRL

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#unfortunately-this-does-no-seem-to-work-openssl-stops-and-spawns-an-error-message)Unfortunately, this does no seem to work. OpenSSL stops and spawns an error message

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#the-reason-is-that-terena-published-their-crl-in-der-format-and-by-default-openssl-uses-the-pem-format-lets-convert-the-crl-to-the-correct-format-and-try-again)The reason is that TERENA published their CRL in DER format, and by default OpenSSL uses the PEM format. Lets convert the CRL to the correct format and try again:

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-openss">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) openssl crl -inform DER -in TERENASSLCA3.crl -outform PEM -out TERENASSLCA3.crl.pem
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) openssl crl -in TERENASSLCA3.crl.pem -text -noout
```

</div>- The -inform argument specifies the input format
- The -in argument specifies the input filename to read from or standard input if this option is not specified
- The -outform argument specifies the output format
- The -out argument specifies the output filename to write to or standard output by default.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#the-last-two-commands-could-be-combined-in-one-so-the-conversion-from-der-to-pem-format-is-not-necessary-anymore)The last two commands could be combined in one so the conversion from DER to PEM format is not necessary anymore:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-6">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl crl -inform DER -in TERENASSLCA3.crl -text -noout
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#and-without-first-downloading-the-crl)And without first downloading the crl:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-wget--q">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • wget -q -O - http://crl3.digicert.com/TERENASSLCA3.crl <span class="pl-k">|</span> openssl crl -inform DER -text -noout
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#and-with-extracting-the-crl-uri-automatically)And with extracting the CRL URI automatically:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-wget--q-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • wget -q -O - <span class="pl-s"><span class="pl-pds">$(</span>echo <span class="pl-k">|</span> openssl s_client -connect ucll.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -text -noout <span class="pl-k">|</span> grep -oP <span class="pl-pds">'</span>URI:\K.*\.crl<span class="pl-pds">'</span><span class="pl-k">|</span> head -1<span class="pl-pds">)</span></span> <span class="pl-k">|</span> openssl crl -inform DER -text -noout
```

</div>- The wget command is a non-interactive network downloader
- The -q command is used to turn off Wget's output
- The -o command is specified for the outpout document
- The -text argument prints out the CRL in text form.
- The -noout argument doesn't output the encoded version of the CRL

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#lets-find-the-serial-number-of-our-certificate)Let's find the serial number of our certificate:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-7">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -in cert.pem -text
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#shows-our-certificate-and-we-find-the-certificate-serial-number-being-0dd943240a84a5e63694ffc7ebe81e3f)shows our certificate and we find the certificate serial number being: "0d:d9:43:24:0a:84:a5:e6:36:94:ff:c7:eb:e8:1e:3f"

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#or-in-one-command-with)Or in one command with:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C--1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect ucll.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -text -noout <span class="pl-k">|</span> grep -A1 -i serial
```

</div>- The -text argument prints out the CRL in text form.
- The -noout argument doesn't output the encoded version of the CRL
- The -A prints NUM lines of trailing context after matching lines.
- The -i command is used to ignore case

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#if-we-would-like-to-verify-this-serial-number-manually-we-need-to-remove-the-colons-or-add-colons-to-the-serials-in-the-crt)If we would like to verify this serial number manually we need to remove the colons or add colons to the serials in the crt.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#removing-should-be-a-peace-of-cake-since-the-previous-labs-adding-a-colon-every-two-characters-is-a-bit-more-complex-)Removing should be a peace of cake since the previous labs. Adding a colon every two characters is a bit more complex: "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-0d">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0d:d9:43:24:0a:84:a5:e6:36:94:ff:c7:eb:e8:1e:3f <span class="pl-k">|</span> tr -d <span class="pl-s"><span class="pl-pds">'</span>:<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: 0dd943240a84a5e63694ffc7ebe81e3f

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0dd943240a84a5e63694ffc7ebe81e3f <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>s/..\B/&:/g<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: 0d:d9:43:24:0a:84:a5:e6:36:94:ff:c7:eb:e8:1e:3f
```

</div>- The .. mean: look for exactly two characters.
- &amp;: means: replace these two dots (their corresponding found characters) itself and add a colon. Thus ab becomes ab:
- The g at the end tells sed not to stop on the first occurrence
- And finally: /B makes sure that the .. only matches at the word boundary.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-0d-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0dd943240a84a5e63694ffc7ebe81e3f <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>s/..//<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: d943240a84a5e63694ffc7ebe81e3f

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0dd943240a84a5e63694ffc7ebe81e3f <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>s/../&/<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: 0dd943240a84a5e63694ffc7ebe81e3f

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0dd943240a84a5e63694ffc7ebe81e3f <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>s/../&:/<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: 0d:d943240a84a5e63694ffc7ebe81e3f

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0dd943240a84a5e63694ffc7ebe81e3f <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>s/../&:/g<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: 0d:d9:43:24:0a:84:a5:e6:36:94:ff:c7:eb:e8:1e:3f:

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> 0dd943240a84a5e63694ffc7ebe81e3f <span class="pl-k">|</span> sed <span class="pl-s"><span class="pl-pds">'</span>s/..\B/&:/g<span class="pl-pds">'</span></span>
=<span class="pl-k">></span> OUTPUT: 0d:d9:43:24:0a:84:a5:e6:36:94:ff:c7:eb:e8:1e:3f
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#of-course-much-easier-is-to-just-use-the--serial-parameter-of-openssl-it-will-be-displayed-in-the-correct-format-automatically)Of course, much easier is to just use the -serial parameter of OpenSSL, it will be displayed in the correct format automatically:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-8">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -in cert.pem -serial -noout
```

</div>- The -noout argument doesn't output the encoded version of the CRL
- The -serial command outputs the certificate serial number.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#of-course-it-is-even-more-easy-to-just-let-openssl-do-all-the-hard-work-just-like-we-do-with-our-web-browsers-and-mailclients-it-is-the-client-software-which-verifies-the-certificate-and-not-the-user)Of course it is even more easy to just let OpenSSL do all the hard work, just like we do with our web browsers and mailclients. It is the client software which verifies the certificate and not the user.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-9">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl verify -CAfile TERENASSLCA3.crl.pem -crl_check cert.pem cert.pem: C = BE, ST = Vlaams-Brabant, L = Leuven, O = UC Leuven, CN = <span class="pl-k">*</span>.ucll.be
```

</div>- The verify command is used to verify certificate chains
- The -CAfile command is a file of trusted certificates.
- The -crl\_check command checks end entity certificate validity by attempting to lookup a valid CRL

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#now-its-time-to-do-something-with-our-newly-created-certificate-tombolacrt-openssl-not-only-includes-ssltls-client-software-but-also-a-server-which-can-act-as-a-very-basic-web-server)Now its time to do something with our newly created certificate (TomBola.crt). OpenSSL not only includes SSL/TLS client software but also a server, which can act as a very basic web server:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-10">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl s_server -accept 10000 -cert TomBola.crt -key TomBola.key -www -state
```

</div>- The -www command sends a status message back to the client when it connects.
- The -state command prints out the SSL session states.
- The -cert command is to specify which certificate to use
- The -state argument is used to display the various SSL states and messages used to build the secure connection

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-11">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl s_client -connect localhost:10000
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#use-the-private-key-from-your-certificate-with-the-following-command-line)Use the private key from your certificate with the following command-line

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-12">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl dgst -sha256 -sign TomBola.key -out examenvragen.pdf.sha2 examenvragen.pdf
```

</div>- The dgst function outputs the message digest of a supplied file or files in hexadecimal form. They can also be used for digital signing and verification.
- The -sign command digitally signs the digest using the private key in "filename".

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#when-you-receive-the-document-its-signature-can-be-verified-with-the-following-command)When you receive the document it's signature can be verified with the following command:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-13">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl dgst -sha256 -verify TomBola.pub -signature examenvragen.pdf.sha2 examenvragen.pdf
```

</div>- The dgst function outputs the message digest of a supplied file or files in hexadecimal form. They can also be used for digital signing and verification.
- The -signature command is used to verify the actual signature

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#use-the-following-openssl-command-to-extract-the-public-key-from-the-certificate-and-execute-the-command-above-to-verify-the-integrity-of-the-document-and-also-authenticate-its-sendercreator)Use the following OpenSSL command to extract the public key from the certificate and execute the command above to verify the integrity of the document and also authenticate its sender/creator.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-14">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -in TomBola.crt -pubkey -noout <span class="pl-k">></span> TomBola.pub
```

</div>#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#use-wireshark-to-analyze-and-observe-the-tls-handshake-between-your-browser-and-a-https-site-of-your-choice-try-to-answer-the-following-questions)Use Wireshark to analyze and observe the TLS handshake between your browser and a https site of your choice. Try to answer the following questions:

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#which-version-of-the-ssltls-protocol-is-used)Which version of the SSL/TLS protocol is used?

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#which-signature-hash-algorithms-are-advertised-as-supported-by-your-browser)Which signature hash algorithms are advertised as supported by your browser?

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#which-cipher-suites-are-supported-by-the-client-browser-and-which-are-supported-by-the-server)Which cipher suites are supported by the client (browser), and which are supported by the server?

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#which-cipher-suite-is-chosen-explain-the-different-parts-of-the-cipher-suite)Which cipher suite is chosen? Explain the different parts of the cipher suite.

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#is-it-the-client-or-the-server-who-defines-the-cipher-suite-to-be-used)Is it the client or the server who defines the cipher suite to be used?

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#if-you-need-to-see-the-contents-of-ssltls-encrypted-packets-you-need-to-feed-the-correct-decryption-keys-into-wireshark)If you need to see the contents of SSL/TLS encrypted packets you need to feed the correct decryption keys into Wireshark.

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#if-you-have-access-to-the-private-key-and-no-diffie-hellman-is-used-to-calculate-the-session-keys-shared-secrets-wireshark-can-decrypt-all-data)If you have access to the private key and no Diffie-Hellman is used to calculate the session keys (shared secrets), Wireshark can decrypt all data.

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#in-most-cases-you-do-not-have-access-to-the-private-key-or-dhe-is-used-to-calculate-the-session-keys-thus-the-above-option-will-not-work)In most cases you do not have access to the private key or DHE is used to calculate the session keys, thus the above option will not work.

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#fortunately-some-browsers-like-firefox-have-the-ability-to-save-these-session-keys-to-a-file-allowing-wireshark-to-decrypt-all-ssltls-data-tofrom-any-website)Fortunately, some browsers (like firefox) have the ability to save these session keys to a file, allowing Wireshark to decrypt all SSL/TLS data to/from any website:

<div id="bkmrk-%27user%40%3A%7E%24%27-1%29-export">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 1) <span class="pl-k">export</span> SSLKEYLOGFILE=/home/slimmerik/sslkey.log
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) firefox <span class="pl-k">&</span>
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> 2) sudo wireshark -o ssl.keylog_file:/home/slimmerik/sslkey.log
```

</div><div id="bkmrk-%23-crl-certificate-re">```
<span class="pl-c"># crl 	            Certificate Revocation List (CRL) Management.</span>
<span class="pl-c"># rsa 	            RSA key management (private key).</span>
<span class="pl-c"># csr 	            Certificate Signing Request (CSR) Management.</span>
<span class="pl-c"># x509 	        X.509 Certificate Data Management (public key certificate).</span>
<span class="pl-c"># s_client 	    Openssl SSL/TLS client (e.g. an https client)</span>
<span class="pl-c"># s_server 	    Openssl SSL/TLS server (e.g. an https server)</span>
<span class="pl-c"># enc 	            Encoding with Ciphers (encryption and decription).</span>
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-1)Exercise 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#take-a-close-look-at-the-contents-of-certpem-it-is-a-pem-encoded-digital-certificate)Take a close look at the contents of cert.pem. It is a pem encoded digital certificate.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#with-the-following-openssl-magic-the-certificate-can-be-displayed-in-a-more-human-friendly-format)With the following OpenSSL magic the certificate can be displayed in a more human-friendly format."

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-15">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -text -noout -in cert.pem
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-2)Exercise 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#lets-say-we-would-like-to-check-the-expiration-date-of-the-certificate-used-on-httpswikiuclllabsbe-we-could-use-the-following-set-of-commands)Let's say we would like to check the expiration date of the certificate used on [https://wiki.uclllabs.be](https://wiki.uclllabs.be/). We could use the following set of commands:"

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-16">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">></span> tempfile
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#now-open-the-temp-file-with-vim-your-preferred-text-editor-and-delete-all-lines-before------begin-certificate------and-after------end-certificate-----)Now open the temp file with vim, your preferred text editor and delete all lines before -----BEGIN CERTIFICATE----- and after -----END CERTIFICATE-----.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#next-use-the-command-below-to-find-the-correct-expiration-date)Next use the command below to find the correct expiration date:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-17">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl x509 -noout -enddate -in tempfile
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#and-if-you-managed-to-understand-everything-this-far-in-this-lab-you-should-be-able-to-glue-the-above-together-in-just-one-command-line)And if you managed to understand everything this far in this lab, you should be able to glue the above together in just one command line.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C--2">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> perl -nle <span class="pl-s"><span class="pl-pds">'</span>print if /BEGIN/../END/<span class="pl-pds">'</span></span> <span class="pl-k">|</span> openssl x509 -noout -enddate
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -noout -enddate
```

</div>- The -enddate command prints out the expiry date of the certificate, that is the notAfter date.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#now-with-a-few-additions-the-above-could-be-used-as-a-base-for-a-fully-automated-certificate-expiration-checker)Now with a few additions, the above could be used as a base for a fully automated certificate expiration checker

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#create-a-textfile-with-all-your-domains-in-it-for-which-ssl-certificates-are-used-of-course-this-could-be-automated-too)Create a textfile with all your domains in it for which ssl certificates are used. Of course this could be automated too.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#there-are-of-course-less-ugly-ways-for-achieving-the-same)There are of course less ugly ways for achieving the same

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-foo">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>cat hosts<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-k">if</span> [[ <span class="pl-s"><span class="pl-pds">$(</span>echo <span class="pl-pds">$(</span>date -d<span class="pl-pds">"</span><span class="pl-pds">$(</span>echo <span class="pl-k">|</span> openssl s_client -connect <span class="pl-smi">$foo</span>:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -noout -enddate</span>
<span class="pl-s"><span class="pl-k">|</span> cut -d<span class="pl-pds">'</span>=<span class="pl-pds">'</span> -f2 <span class="pl-k">|</span> awk <span class="pl-pds">'</span>{print $2 " " $1 " " $4}<span class="pl-pds">'</span><span class="pl-pds">)</span><span class="pl-pds">"</span> +%s<span class="pl-pds">)</span> - <span class="pl-pds">$(</span>date +%s<span class="pl-pds">)</span> <span class="pl-k">|</span> bc<span class="pl-pds">)</span></span> <span class="pl-k">-gt</span> 0 ]]<span class="pl-k">;</span> <span class="pl-k">then</span> <span class="pl-c1">echo</span> <span class="pl-smi">$foo</span>: OK<span class="pl-k">;</span> <span class="pl-k">else</span> <span class="pl-c1">echo</span> <span class="pl-smi">$foo</span>: EXPIRED<span class="pl-k">;</span><span class="pl-k">fi</span><span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#and-now-a-shorter-version-with-some-more-openssl-magic)And now a shorter version with some more OpenSSL magic

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-foo-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>cat hosts<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-k">if</span> <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect <span class="pl-smi">$foo</span>:443 <span class="pl-k">2></span>/dev/null 
<span class="pl-k">|</span> openssl x509 -noout -checkend 0<span class="pl-k">;</span> <span class="pl-k">then</span> <span class="pl-c1">echo</span> <span class="pl-smi">$foo</span>: OK<span class="pl-k">;</span> <span class="pl-k">else</span> <span class="pl-c1">echo</span> <span class="pl-smi">$foo</span>: EXPIRED<span class="pl-k">;</span> <span class="pl-k">fi</span><span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>- The -checkend command checks if the certificate expires within the next arg seconds and exits non-zero if yes it will expire or zero if not.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#and-magic)And magic++:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-foo-1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>cat hosts<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> check_ssl_cert -H <span class="pl-smi">$foo</span><span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>- The check\_ssl\_cert checks the validity of X.509 certificates
- The -H command is used to specify the host

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-3)Exercise 3:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#create-a-oneliner-which-shows-the-amount-of-currently-revoked-certificates-in-the-terena-ssl-ca-revocation-list)Create a oneliner which shows the amount of currently revoked certificates in the Terena SSL CA revocation list.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#do-not-create-temporary-files-the-crl-can-be-found-at-httpcrl3digicertcomterenasslca3crl)Do not create temporary files. The CRL can be found at [http://crl3.digicert.com/TERENASSLCA3.crl](http://crl3.digicert.com/TERENASSLCA3.crl)."

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-wget--q-1">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • wget -q -O - http://crl3.digicert.com/TERENASSLCA3.crl <span class="pl-k">|</span> openssl crl -inform DER -text -noout <span class="pl-k">|</span> grep -P <span class="pl-s"><span class="pl-pds">'</span>^\s+Serial Number<span class="pl-pds">'</span></span> <span class="pl-k">|</span> wc -l
```

</div>- The -inform command specifies the input format normally the command will expect an X509 certificate but this can change if other options such as -req are present.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-4)Exercise 4:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#companies-like-google-and-microsoft-make-heavily-use-of-the-x509-subjectaltname-extension)Companies like Google and Microsoft make heavily use of the X.509 subjectAltName extension.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#ucll-also-uses-this-extension-to-add-an-alternative-name-ucllbe-to-the-common-name-ucllbe-of-the-certificate)UCLL also uses this extension to add an alternative name \*.ucll.be to the common name (ucll.be) of the certificate.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#create-a-oneliner-which-calculates-the-amount-of-dns-subject-alternate-names-used-in-the-ssl-certificate-of-gmailcom)Create a oneliner which calculates the amount of DNS Subject Alternate Names used in the SSL certificate of gmail.com."

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C--3">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect facebook.com:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -text -noout <span class="pl-k">|</span> grep -o <span class="pl-s"><span class="pl-pds">'</span>DNS:<span class="pl-pds">'</span></span> <span class="pl-k">|</span> wc -l
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-5)Exercise 5:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#create-a-cli-oneliner-to-find-a-match-between-different-rsa-private-key-files-and-their-companion-crt-files-the-output-should-look-something-like)Create a CLI oneliner to find a match between different rsa private key files and their companion crt files. The output should look something like:

<div id="bkmrk-alfa.key-matches-bet">```
alfa.key matches beta.crt
gamma.key matches delta.crt

```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#first-we-need-to-generate-some-certificates-so-we-can-actually-verify-our-solution-the-following-command-creates-a-self-signed-certificate-in-one-step)First we need to generate some certificates so we can actually verify our solution. The following command creates a self-signed certificate in one step:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-openssl-18">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • openssl req -x509 -sha256 -newkey rsa:2048 -keyout tombola_uclllabs_be.key -out tombola_uclllabs_be.crt -days 365 -nodes -subj 
<span class="pl-s"><span class="pl-pds">"</span>/C=BE/ST=/L=/O=UC Leuven/CN=tombola.uclllabs.be<span class="pl-pds">"</span></span>
```

</div>- The -subj command outputs the "hash" of the certificate subject name.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#with-the-following-for-loop-we-can-easily-generate-a-few-certificates-to-test-with)With the following for loop we can easily generate a few certificates to test with:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-foo-2">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> TomBola GreetSchap VanderNeffe LukRaak AlainProvist<span class="pl-k">;</span> <span class="pl-k">do</span> openssl req -x509 -sha256 -newkey rsa:2048 -keyout 
<span class="pl-s"><span class="pl-pds">"</span><span class="pl-smi">$foo</span><span class="pl-pds">"</span></span>_uclllabs_be.key -out <span class="pl-s"><span class="pl-pds">"</span><span class="pl-smi">$foo</span><span class="pl-pds">"</span></span>_uclllabs_be.crt -days 1024 -nodes -subj 
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#as-explained-in-this-lab-the-modulus-of-corresponding-files-csr-private-key-and-certificate-should-be-the-same-well-create-a-oneliner-which-tests-wich-files-belong-to-one-another-ie-which-files-have-the-same-modulus)As explained in this lab, the modulus of corresponding files (CSR, private KEY and Certificate) should be the same. We'll create a oneliner which tests wich files belong to one another. I.e. which files have the same modulus.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-key">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">key</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>ls -1 <span class="pl-k">*</span>.key<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-k">for</span> <span class="pl-smi">crt</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>ls -1 <span class="pl-k">*</span>.crt<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-k">if</span> [[ <span class="pl-s"><span class="pl-pds">$(</span>openssl rsa -in <span class="pl-smi">$key</span> -noout -modulus <span class="pl-k">|</span> md5sum<span class="pl-pds">)</span></span> <span class="pl-k">==</span> <span class="pl-s"><span class="pl-pds">$(</span>openssl x509 -in <span class="pl-smi">$crt</span> -noout -modulus <span class="pl-k">|</span> md5sum<span class="pl-pds">)</span></span> ]]<span class="pl-k">;</span> <span class="pl-k">then</span> <span class="pl-c1">echo</span> <span class="pl-smi">$key</span> matches <span class="pl-smi">$crt</span><span class="pl-k">;</span><span class="pl-k">fi</span> <span class="pl-k">;</span><span class="pl-k">done</span><span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#or-a-slightly-shorter-version)Or a slightly shorter version:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-key-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">key</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>ls <span class="pl-k">*</span>.key<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-k">for</span> <span class="pl-smi">cert</span> <span class="pl-k">in</span> <span class="pl-s"><span class="pl-pds">$(</span>ls <span class="pl-k">*</span>.pem<span class="pl-pds">)</span></span><span class="pl-k">;</span> <span class="pl-k">do</span> [[ <span class="pl-s"><span class="pl-pds">$(</span>openssl rsa -in <span class="pl-smi">$key</span> -noout -modulus <span class="pl-k">|</span> md5sum<span class="pl-pds">)</span></span> <span class="pl-k">==</span> <span class="pl-s"><span class="pl-pds">$(</span>openssl x509 -in <span class="pl-smi">$cert</span> -noout -modulus <span class="pl-k">|</span> md5sum<span class="pl-pds">)</span></span> ]] <span class="pl-k">&&</span> <span class="pl-c1">echo</span> <span class="pl-smi">$key</span> matches to <span class="pl-smi">$cert</span><span class="pl-k">;</span><span class="pl-k">done</span><span class="pl-k">;</span><span class="pl-k">done</span> 
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-6)Exercise 6:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#create-a-cli-oneliner-using-openssl-to-retrieve-the-certificate-of-the-server-wikiuclllabsbe-and-to-encrypt-the-text)Create a CLI oneliner using openssl to retrieve the certificate of the server wiki.uclllabs.be and to encrypt the text

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#lets-make-cnw2-great-again-with-its-public-key-in-the-first-step-we-willll-connect-to-httpswikiuclllabsbe-and-extract-the-public-key-from-the-presented-certificate)'Lets make CNW2 great again'" with it’s public key. In the first step, we willll connect to [https://wiki.uclllabs.be](https://wiki.uclllabs.be/) and extract the public key from the presented certificate:"

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C--4">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -noout -pubkey <span class="pl-k">></span> public.pem
```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#now-the-public-key-is-saved-in-a-tempfile-we-can-use-it-to-encrypt-arbitrary-data)Now the public key is saved in a tempfile we can use it to encrypt arbitrary data.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%22l">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">"</span>Let's make CNW2 great again<span class="pl-pds">"</span></span> <span class="pl-k">|</span> openssl rsautl -encrypt -pubin -inkey public.pem -out CNW2.encrypted
```

</div>- The rsautl command can be used to sign, verify, encrypt and decrypt data using the RSA algorithm.
- The -encrypt command encrypts the input data using an RSA public key.
- The -pubin command is used to input file is an RSA public key.
- The -out command specifies the output filename to write to or standard output by default.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#or-without-first-downloading-the-public-key)Or without first downloading the public key:

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%22l-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">"</span>Let's make CNW2 great again<span class="pl-pds">"</span></span> <span class="pl-k">|</span> openssl rsautl -encrypt -pubin -inkey <span class="pl-s"><span class="pl-pds"><(</span>echo <span class="pl-k">|</span> openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -noout -pubkey<span class="pl-pds">)</span></span> -out CNW2.encrypted
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-7)Exercise 7:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#experiment-with-the-tools-sslyze-and-nmap-to-enumerate-supported-ssl-cipher-suites-for-various-websites-make-sure-you-understand-its-output-see-the-folloing-example)Experiment with the tools sslyze and nmap to enumerate supported ssl cipher suites for various websites. Make sure you understand its output. See the folloing example:

<div id="bkmrk---sslyze---regular--">```
- sslyze --regular --http_headers wiki.uclllabs.be
- nmap --script ssl-enum-ciphers -p 443 wiki.uclllabs.be
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-8)Exercise 8:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#lets-encrypt-has-rate-limits-which-prevent-issuing-more-than-20-new-certificates-per-domain-per-week-they-use-the-public-suffix-list-for-this)Let’s Encrypt has rate limits which prevent issuing more than 20 new certificates per domain per week. They use the public suffix list for this.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#the-limit-is-per-registered-domain-not-per-subdomain-so-all-student-certificates-count-for-the-same-uclllabsbe-suffix)The limit is per registered domain, not per subdomain. So all student certificates count for the same uclllabs.be suffix.

<div id="bkmrk-%22root-%23%22-%E2%80%A2-certbot--">```
<span class="pl-s"><span class="pl-pds">"</span>root #<span class="pl-pds">"</span></span> • certbot --apache -d <span class="pl-s"><span class="pl-pds">"</span>tom.x.cnw2.uclllabs.be, bola.x.cnw2.uclllabs.be, tom.bola.x.cnw2.uclllabs.be<span class="pl-pds">"</span></span>
```

</div>- The certbot command is used to obtain and install HTTPS/TLS/SSL certificates
- The --apache command is used to use the Apache plugin for authentication &amp; installation
- The -d command is used for domain names to apply

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#exercise-9)Exercise 9:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%206.md#create-a-cli-oneliner-using-openssl-to-retrieve-the-certificate-of-the-server-wikiuclllabsbe-and-to-display-only-its-fingerprint-serial-and-public-key-sample-output)Create a CLI oneliner using OpenSSL to retrieve the certificate of the server wiki.uclllabs.be and to display only its fingerprint, serial and public key. Sample output:"

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C--5">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -noout -fingerprint -serial -pubkey
```

</div>

# 2019 oplossingen labo tussentest - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

# LABO TEST

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-1)Exercise 1:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#copy-the-content-of-your-it-enabled-grandmothers-id_rsapub-file-in-your-sshauthorized_keys-file)Copy the content of your it-enabled grandmothers id\_rsa.pub file in your ~/.ssh/authorized\_keys file"

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-ssh-use">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • ssh user@leia.uclllabs.be -p 22345 -i <span class="pl-s"><span class="pl-pds">"</span>/path/to/your grandmothers identity_file<span class="pl-pds">"</span></span>
```

</div>- The ssh command is a remote login program
- The -p argument is used for a port to connect to on the remote host.
- The -i argument selects a file from which the identity (private key) for public key authentication is read.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-ssh-use-0">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • ssh user@leia.uclllabs.be -p 22345
```

</div>- The ssh command is a remote login program
- The -p argument is used for a port to connect to on the remote host.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-2)Exercise 2:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#try-to-find-out-which-tcp-ports-are-open-on-leia-without-using-tools-like-netstat-or-ss-execute-on-leia-for-increased-speed)Try to find out which TCP ports are open on leia without using tools like netstat or ss. Execute on leia for increased speed.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-nc--zv-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • nc -zv -w 1 leia.uclllabs.be 1-65535 <span class="pl-k">2>&1</span> <span class="pl-k">|</span> grep succeeded <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $4}<span class="pl-pds">'</span></span>

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> {1..65535}<span class="pl-k">;</span> <span class="pl-k">do</span> nc -N -w1 leia.uclllabs.be <span class="pl-smi">$foo</span> <span class="pl-k"><</span>/dev/  null <span class="pl-k">></span>/dev/null <span class="pl-k">&&</span> <span class="pl-c1">echo</span> <span class="pl-smi">$foo</span><span class="pl-k">;</span><span class="pl-k">done</span>

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • nmap -p 1-65535 leia.uclllabs.be <span class="pl-k">|</span> grep -P <span class="pl-s"><span class="pl-pds">'</span>\d+/tcp.*open<span class="pl-pds">'</span></span> <span class="pl-k">|</span>cut -d<span class="pl-s"><span class="pl-pds">'</span>/<span class="pl-pds">'</span></span> -f1

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • nmap --reason -p 1-65535 leia.uclllabs.be <span class="pl-k">|</span> grep -oP <span class="pl-s"><span class="pl-pds">'</span>\d+(?=/tcp.*open)<span class="pl-pds">'</span></span>
```

</div>- The nc command is a TCP/IP swiss army knife
- The -z argument is used for scanning
- The -v argument is used for verbose
- The -w (# in seconds) arguments is timeout for connects and final net reads
- The grep command prints lines matching a pattern
- The awk command is used for pattern scanning and processing language
- \\d matches a digit (equivalent to \[0-9\])
- '+' matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- . matches any character (except for line terminators)
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy) open matches the characters open literally (case sensitive)
- The cut command removes sections from each line of files
- The -d argument use DELIM instead of TAB for field delimiter
- The command nmap is a network exploration tool and security / port scanner
- The --reason argument shows the reason each port is set to a specific state and the reason each host is up or down
- The -p argument specifies which ports you want to scan and overrides the default.
- The -o argument print only the matched (non-empty) parts of a matching line, with each such part on a separate output line.
- The -o argument prints only the matched (non-empty) parts of a matching line, with each such part on a separate output line.
- The -p argument Interpret I as Perl-compatible regular expressions (PCREs).

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-3)Exercise 3:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#create-a-oneliner-which-lists-all-palindromes-with-exactly-6-letters-in-a-dictionary)Create a oneliner which lists all palindromes with exactly 6 letters in a dictionary.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-cat-dut">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • cat dutch <span class="pl-k">|</span> grep -P <span class="pl-s"><span class="pl-pds">'</span>^(.)(.)(.)\3\2\1$<span class="pl-pds">'</span></span>
```

</div>- ^ asserts position at start of a line
- . matches any character (except for line terminators)
- in ^(.)(.)(.) ==&gt; the first (.) is the first capturing group, the second (.) is the second capturing group, the third (.) is the third capturing group,
- \\3 matches the same text as most recently matched by the 3rd capturing group, \\2 matches the same text as most recently matched by the 2nd capturing group and \\1 matches the same text as most recently matched by the 1st capturing group

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-4)Exercise 4:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#as-a-web-server-administrator-you-have-been-asked-to-give-your-manager-a-linux-cli-oneliner-to-extract-the-5-ip-addresses-that-contacted-the-web-server-the-most)As a web server administrator you have been asked to give your manager a Linux CLI oneliner to extract the 5 IP addresses that contacted the web server the most

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#the-apache-log-is-located-in-homelogs-create-a-correct-oneliner-the-output-should-look-something-like-this-count-ips)The apache log is located in /home/logs. Create a correct oneliner. The output should look something like this: (count IPs)

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-cat-apa">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • cat apache_google.log <span class="pl-k">|</span> cut -d <span class="pl-s"><span class="pl-pds">'</span> <span class="pl-pds">'</span></span> -f1 <span class="pl-k">|</span> sort <span class="pl-k">|</span> uniq -c <span class="pl-k">|</span> sort -rn <span class="pl-k">|</span> head -5
```

</div>- The cut command removes sections from each line of files
- The -d argument uses DELIM instead of TAB for field delimiter
- The -f argument selects only these fields
- The sort command sorts lines of text files
- The uniq command reports or omits repeated lines
- The -c argument prefixes lines by the number of occurrences
- The -r reverses the result of comparisons
- The head command shows output the first part of files

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-5)Exercise 5:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#what-linux-ssh-command-do-you-use-to-bind-your-local-port-3000-to-a-web-server-on-port-4444-on-the-network-of-the-ssh-server)What Linux ssh command do you use to bind your local port 3000 to a web server on port 4444 on the network of the ssh server

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-ssh--p-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • ssh -p 22345 username@leia.uclllabs.be -L 3000:IP_web_server:4444
```

</div>- The -p argument shows which port to connect to on the remote host
- The -L argument specifies that the given port on the local (client) host is to be forwarded to the given host and port on the remote side.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-6)Exercise 6:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#create-an-apache-vhost-netcatxcnw2uclllabsbe-which-displays-a-single-web-page-indexhtml-how-can-you-updatealter-this-website-indexhtml-via-a-netcat-connection-from-your-laptop)Create an apache vhost (netcat.X.cnw2.uclllabs.be) which displays a single web page (index.html). How can you update/alter this website (index.html) via a Netcat connection from your laptop."

<div id="bkmrk-%27root%40myserver%27-1%29-m">```
<span class="pl-s"><span class="pl-pds">'</span>root@myserver<span class="pl-pds">'</span></span> 1)  mkdir /var/www/html/netcat
<span class="pl-s"><span class="pl-pds">'</span>root@myserver<span class="pl-pds">'</span></span> 2)  nano netcat.conf
```

</div><div id="bkmrk-%3Cvirtualhost-%2A%3A80%3E-s">```
<VirtualHost *:80>
    ServerAdmin root@netcat.X.cnw2.uclllabs.be
    ServerName netcat.X.cnw2.uclllabs.be
    DocumentRoot /var/www/html/netcat

    LogLevel info
    ErrorLog ${APACHE_LOG_DIR}/netcat-error.log
    CustomLog ${APACHE_LOG_DIR}/netcat-access.log combined
</VirtualHost>

```

</div><div id="bkmrk-%27%23-root%40myserver%27-1%29">```
<span class="pl-s"><span class="pl-pds">'</span># root@myserver<span class="pl-pds">'</span></span> 1)  a2ensite netcat
<span class="pl-s"><span class="pl-pds">'</span># root@myserver<span class="pl-pds">'</span></span> 2)  systemctl reload apache2
<span class="pl-s"><span class="pl-pds">'</span># root@myserver<span class="pl-pds">'</span></span> 3)  nc -l -p 10000 <span class="pl-k">>></span> /var/www/html/netcat/index.html
<span class="pl-s"><span class="pl-pds">'</span>user@laptop:~$<span class="pl-pds">'</span></span>  4)  <span class="pl-c1">echo</span> <span class="pl-c1">test</span> <span class="pl-k">|</span> nc netcat.X.cnw2.uclllabs.be 10000
```

</div>## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-7)Exercise 7:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#on-server-leia-use-the-list-of-logged-in-users-to-print-only-the-username-that-has-been-logged-in-to-the-server-for-the-longest-time)On server Leia, use the list of logged in users to print only the username that has been logged in to the server for the longest time

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-who-%7C-a">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • who <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $3$4 " " $1}<span class="pl-pds">'</span></span> <span class="pl-k">|</span> sort -n <span class="pl-k">|</span> awk <span class="pl-s"><span class="pl-pds">'</span>{print $2}<span class="pl-pds">'</span></span> <span class="pl-k">|</span> head -1
```

</div>- The command who shows who is logged in
- The command sort sorts lines of text files
- The -n argument compares acoording to string numerical value
- The head command outputs the first part of files

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-8)Exercise 8:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#some-subdirectory-of-tmp-contains-a-bunch-of-movies-however-their-extension-is-wrong)Some subdirectory of /tmp contains a bunch of movies. However, their extension is wrong.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#the-extension-should-be-avi-instead-of-jpg-copy-these-files-to-your-homedirectory-and-correct-their-extensions-in-one-line-)The extension should be .avi instead of .jpg. Copy these files to your homedirectory and correct their extensions in one line. "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-ls--1-%2A">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • ls -1 <span class="pl-k">*</span>.jpg <span class="pl-k">|</span> <span class="pl-k">while</span> <span class="pl-c1">read</span> foo<span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-c1">echo</span> cp <span class="pl-smi">$foo</span> <span class="pl-k">~</span>/<span class="pl-s"><span class="pl-pds">$(</span>basename <span class="pl-smi">$foo</span> .jpg<span class="pl-pds">)</span></span>.avi<span class="pl-k">;</span><span class="pl-k">done</span>
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • ls -1 <span class="pl-k">*</span>.jpg <span class="pl-k">|</span> <span class="pl-k">while</span> <span class="pl-c1">read</span> foo<span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-c1">echo</span> cp <span class="pl-smi">$foo</span> <span class="pl-k">~</span>/<span class="pl-smi">${foo<span class="pl-k">%</span>.jpg}</span>.avi<span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>- The -1 argument lists one file per line
- cp $foo ~/$(basename $foo .jpg).avi ==&gt; Echo the STRING(s) to standard output.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-9)Exercise 9:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#create-a-linux-cli-oneliner-to-decode-the-following-string-swygew91ignhbibyzwfkihroaxmsihlvdsbmb3vuzcb0agugy29ycmvjdcbhbnn3zxik)Create a Linux CLI oneliner to decode the following string 'SWYgeW91IGNhbiByZWFkIHRoaXMsIHlvdSBmb3VuZCB0aGUgY29ycmVjdCBhbnN3ZXIK'

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%27s">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">'</span>SWYgeW91IGNhbiByZWFkIHRoaXMsIHlvdSBmb3VuZCB0aGUgY29ycmVjdCBhbnN3ZXIK<span class="pl-pds">'</span></span> <span class="pl-k">|</span> openssl enc -a -d

<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">'</span>SWYgeW91IGNhbiByZWFkIHRoaXMsIHlvdSBmb3VuZCB0aGUgY29ycmVjdCBhbnN3ZXIK<span class="pl-pds">'</span></span> <span class="pl-k">|</span> base64 -d
```

</div>- The -a argument ==&gt; Base64 process the data
- The -d argument ==&gt; decrypts the input data
- The -base64 argument = The -a argument

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-10)Exercise 10:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#create-a-regular-expression-to-match-all-words-in-a-dictionary-with-5-unique-letters-)Create a regular expression to match all words in a dictionary with 5 unique letters. "

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-cat-%2Fus">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • cat /usr/share/dict/dutch <span class="pl-k">|</span> grep -P <span class="pl-s"><span class="pl-pds">'</span>^[a-zA-Z]{5}$<span class="pl-pds">'</span></span><span class="pl-k">|</span> grep -vP <span class="pl-s"><span class="pl-pds">'</span>(.).*\1<span class="pl-pds">'</span></span>
```

</div>- ^ asserts position at start of a line
- A-Z matches a single character in the range between A and Z (case sensitive)
- a-z matches a single character in the range between a and z (case sensitive)
- {5} matches the previous token exactly 5 times
- . matches any character (except for line terminators
- '\*' matches the previous token between zero and unlimited times, as many times as possible, giving back as needed (greedy)
- -v stands for inverted match.
- -P stands for perl expression

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-11)Exercise 11:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#create-a-oneliner-to-show-time--154425-11101901-or-time--154425-11-10-1901-each-time-with-the-current-time-and-date)Create a oneliner to show ‘Time = 15:44:25 (11/10/1901)' or 'Time = 15:44:25 (11-10-1901)’ each time with the current time and date.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%22t">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">"</span>Time = <span class="pl-pds">$(</span>date <span class="pl-pds">'</span>+%X (%x)<span class="pl-pds">'</span><span class="pl-pds">)</span><span class="pl-pds">"</span></span>
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • date <span class="pl-s"><span class="pl-pds">'</span>+Time = %X (%x)<span class="pl-pds">'</span></span>
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • date <span class="pl-s"><span class="pl-pds">'</span>+Time = %X (%Y/%d/%m)<span class="pl-pds">'</span></span>
```

</div>- date matches the characters date literally (case sensitive)
- '+' matches the previous token between one and unlimited times, as many times as possible, giving back as needed (greedy)
- The %X argument sets locale's time representation
- the %x argument sets locale's date representation
- The %Y arguments = year
- The %d arguments = day
- The %m arguments = month

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#exercise-12)Exercise 12:

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/LABO%20TUSSSENTEST.md#create-a-oneliner-which-lists-the-top-3-most-used-passwords-in-the-ftp-brute-force-attack-captured-in-ftp_bruteforcepcap-use-a-suitable-sniffer-filter-which-only-displays-whats-really-needed)Create a oneliner which lists the top 3 most used passwords in the ftp brute force attack captured in "ftp\_bruteforce.pcap". Use a suitable sniffer filter which only displays whats really needed.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.request.command==PASS<span class="pl-pds">'</span></span> -T fields -e <span class="pl-s"><span class="pl-pds">'</span>ftp.request.arg<span class="pl-pds">'</span></span> <span class="pl-k">2></span>/dev/null<span class="pl-k">|</span> sort <span class="pl-k">|</span> uniq -c <span class="pl-k">|</span> sort -rn <span class="pl-k">|</span> head -3
```

</div>- The tshark command dumps and analyzes network traffic
- The -r argument reads the packet date from infile
- The -Y command captures the link type
- The -T argument sets the format of the output when viewing decoded packet data.
- The -e argument (in tshark command) adds a field to the list of fields to display if -T fields is selected
- The sort command sorts lines of text files
- The uniq command reports or omits repeated lines
- The -c command prefixes lines by the number of occurrences
- The -r argument (in sort command) reverses the results of comparisons
- The -n compare according to string numerical value
- The head command shows output for only the first part of files

# 2019 oplossingen Testexamen - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en natuurlijk Lars Lemmens

## Exercise 1

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#create-a-cli-oneliner-to-match-all-words-with-14-15-or-16-unique-letters-the-output-shouldlook-like)Create a CLI oneliner to match all words with 14, 15 or 16 unique letters. The output shouldlook like:

<div id="bkmrk-words-with-14-letter">```
Words with 14 letters: EHBO-diploma's bruiloftsdagen katrolschijven verontschuldig ...
Words with 15 letters: dampkringslucht sandwichformule ...
Words with 16 letters: ...

```

</div><div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-for-foo">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-k">for</span> <span class="pl-smi">foo</span> <span class="pl-k">in</span> 14 15 16<span class="pl-k">;</span> <span class="pl-k">do</span> <span class="pl-c1">echo</span> <span class="pl-s"><span class="pl-pds">"</span>Words with <span class="pl-smi">$foo</span> letters:<span class="pl-pds">"</span></span> <span class="pl-s"><span class="pl-pds">$(</span>grep -vP <span class="pl-pds">'</span>(.).*\1<span class="pl-pds">'</span> /usr/ share/dict/dutch <span class="pl-k">|</span> grep -P <span class="pl-pds">"</span>^.{<span class="pl-smi">$foo</span>}$<span class="pl-pds">"</span><span class="pl-pds">)</span></span><span class="pl-k">;</span><span class="pl-k">done</span>
```

</div>- for name \[ \[ in \[ word ... \] \] ; \] do list ; done The list of words following in is expanded, generating a list of items. The variable name is set to each element of this list in turn, and list is executed each time. If the in word is omitted, the for command executes list once for each positional parameter that is set (see PARAMETERS below). The return status is the exit status of the last command that executes. If the expansion of the items following in results in an empty list, no commands are executed, and the return status is 0.
- echo displays a line of text

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#exercise-2)Exercise 2

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#create-a-linux-cli-oneliner-to-extract-an-overview-of-the-different-ftp-usernames-in-the-file-ftp_bruteforcepcap-only-the-commands-tshark-and-sort-are-allowed)Create a linux CLI oneliner to extract an overview of the different FTP usernames in the file ftp\_bruteforce.pcap. Only the commands tshark and sort are allowed.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-tshark-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • tshark -r ftp_bruteforce.pcap -Y <span class="pl-s"><span class="pl-pds">'</span>ftp.request.command == USER<span class="pl-pds">'</span></span> -T fields -e ftp.request.arg <span class="pl-k">|</span>sort -u
```

</div>- The -r command opens the recording
- The -Y command is used for displaying the filter
- The -T fields -e is used to specify the fields you want to show
- The sort command is used to sort lines of text files
- The -u command is used to show the output of only the first of an equal run

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#exercise-3)Exercise 3

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#create-a-oneliner-to-show-time--154425-11101901-or-time--154425-11-10-1901-each-time-with-the-current-time-and-date)Create a oneliner to show ‘Time = 15:44:25 (11/10/1901)' or 'Time = 15:44:25 (11-10-1901)’ each time with the current time and date.

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-date-%27%2B">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • date <span class="pl-s"><span class="pl-pds">'</span>+Time = %X (%x)<span class="pl-pds">'</span></span>
```

</div>- The date command prints or sets the system date and time
- The +Time is used to set time
- The %X command is used to set the systems time
- The %x command is used to set the date -&gt; with () is used to put () around the date

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#exercise-4)Exercise 4

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#create-a-linux-cli-oneliner-to-decode-the-following-string-rgugchvudgvuig9wigrlemugdnjhywcgemlqbibhbcbiaw5uzw4ucg-homelogssecret)Create a linux CLI oneliner to decode the following string ‘RGUgcHVudGVuIG9wIGRlemUgdnJhYWcgemlqbiBhbCBiaW5uZW4uCg==’. (/home/logs/secret)

<div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-cat-%2Fho">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • cat /home/logs/secret <span class="pl-k">|</span> openssl enc -a -d
```

</div>- The cat command is used to concatenate files and print on the standard output
- The enc command is used to encrypt or decrypt a file
- The -a command is used if encryption is taking place the data is base64 encoded after encryption. If decryption is set then the input data is base64 decoded before being decrypted
- The -d command is used to decrypt

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#exercise-5)Exercise 5

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Labo's/SAMPLE%20EXAM.md#create-a-cli-oneliner-using-openssl-to-retrieve-the-certificate-of-the-server-wikiuclllabsbeand-to-display-only-its-fingerprint-serial-and-public-keysample-output)Create a CLI oneliner using openssl to retrieve the certificate of the server wiki.uclllabs.beand to display only it’s fingerprint, serial and public key.Sample output:

<div id="bkmrk-sha1-fingerprint%3D8c%3A">```
SHA1 Fingerprint=8C:CB:D9:A1:F3:3C:78:C2:2E:F6:EB:1C:CD:4B:F3:39:1B:9A:EE:4Eserial=0966DB4115B74092EE07D6DA585547D8-----BEGIN PUBLIC KEY-----MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE2NHdNb3iWbb7mx9UFYzbv05YvUe+uBD8IunSnpj4SSol+5RG5EKZhFAcXwH9FCUxXE7ZZP3FDLNG0qG8cLSHjg==-----END PUBLIC KEY-----

```

</div><div id="bkmrk-%27user%40%3A%7E%24%27-%E2%80%A2-echo-%7C-">```
<span class="pl-s"><span class="pl-pds">'</span>user@:~$<span class="pl-pds">'</span></span> • <span class="pl-c1">echo</span> <span class="pl-k">|</span> openssl s_client -connect wiki.uclllabs.be:443 <span class="pl-k">2></span>/dev/null <span class="pl-k">|</span> openssl x509 -noout -fingerprint -serial -pubkey
```

</div>- The s\_client command implements a generic SSL/TLS server which accepts connections from remote clients speaking SSL/TLS
- The x509 command outputs a self signed certificate instead of a certificate request.
- The -noout command is used to prevent output of the encoded version of the request
- The -fingerprint command is used to show the fingerprint
- The -serial command outputs the certificate serial number.
- The -pubkey command outputs the the certificate's SubjectPublicKeyInfo block in PEM format.

# 2019 samenvatting - Lars Lemmens

Met dank aan de [Github van Martijn](https://github.com/martijnmeeldijk/TI-oplossingen) en Lars Lemmens

# Hoofdstuk 2

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#21-principes-van-netwerkapplicaties)2.1 Principes van netwerkapplicaties

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#211-structuren-van-netwerkapplicaties)2.1.1 Structuren van netwerkapplicaties

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#client-server-structuur)**Client-server structuur**

- Host altijd-aan (server) &amp; handelt verzoeken van andere hosts (clients) af
- Meestal datacenters → anders overbelasting

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#p2p-structuur)**P2P-structuur**

- Infrastructuurservers die altijd aan zijn → minimaal of afwezig
- Maakt gebruik van rechtstreekse communicatie → periodiek met elkaar verbonden hosts → peers
- Zelfschaalbaarheid &amp; goedkoper

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#212-communicerende-processen)2.1.2 Communicerende processen

- Processen in 2 verschillende hosts → communiceren met elkaar door berichten uit te wisselen → verzendend proces creëert &amp; verzendt berichten over netwerk → ontvangend proces ontvangt berichten en verzendt eventueel antwoordbericht

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#client--en-serverprocessen)Client – en serverprocessen

- Voor elk paar comunnicerende processen → 1 van de 2 processen **client** &amp; andere **server**
- Definitie client- en serverprocessen: 
    - In context van een communicatiesessie tussen 2 processen noemen we het proces dat de communicatie initieert de **client**. Het wachtende proces noemen we de server
- In P2P kan een proces ophalen en beschikbaar stellen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#interface-tussen-proces-en-computernetwerk)Interface tussen proces en computernetwerk

- Proces verzendt berichten naar en ontvangt berichten van het netwerk via een netwerkinterface →**socket AKA API ( Application Programming Interface)**
- Socket = soort deur → proces bericht naar ander proces sturen → bericht door deur (socket) naar buiten → verzendende proces neemt aan → andere kant deur → infrastructuur aanwezig is waarmee bericht → bij deur van huis van bestemming zal bezorgd worden → zodra bericht arriveert bij ontvangende host → passeert het de toegangsdeur van ontvangende proces → waarna ontvangende proces bericht verwerkt

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#adresseren-van-processen)Adresseren van processen

- Om ontvangende proces te kennen moet het 2 gegevens bevatten: 
    - Het adres van de host
    - Unieke aanduiding van ontvangende proces in ontvangende host

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#213-transportdiensten-voor-applicaties)2.1.3 Transportdiensten voor applicaties

| **Data Integriteit:**

- Transportlaagprotocol → mogelijk een betrouwbare gegevensoverdracht tussen processen aan applicatie leveren → verzendend proces gegevens in socket duwen &amp; is zeker van geen fouten
- Als er geen betrouwbare gegevensoverdracht is → mogelijkheid dat deel gegevens niet aankomen bij ontvangend proces →\*\*verliestolerante apps (\*\*Skype,...) | **Doorvoer**
- Sommige apps (bijv. multimedia) vereisen een minimale verwerkingscapaciteit om "effectief" te zijn = **bandbreedtegevoelige apps** **→** stellen eisen aan doorvoercapaciteit
- Elastische apps gebruiken de doorvoercapaciteit die op het moment beschikbaar is

**Timing:**

- Sommige apps (bijv. internettelefonie, interactieve games) hebben een korte vertraging nodig om 'effectief' te zijn **Security**
- Encryptie, data integriteit,...

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#diensten-van-tcp--udp)Diensten van TCP &amp; UDP

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#beveiligen-van-tcp)Beveiligen van TCP

TCP gebruikt SSL/TLS → TCP met SSL/TLS → doet niet alleen wat oorspronkelijke TCP doet → levert ook beveiliginsdiensten voor communicerende processen → SSL niet een 3e transportprotocol voor internet is dat op zelfde niveau werkt als UDP &amp; TCP → uitbreiding van TCP → uitbreidingen geimplementeerd in applicatielaag

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#diensten-die-niet-geleverd-worden-door-internettransportprotocollen)Diensten die niet geleverd worden door internettransportprotocollen

- Huidig internet presteert goed voor tijdgevoelige apps → geen garanties voor timing of doorvoercapaciteit
- Internettelefonieapps kan enig verlies verwerken maar wel minimale snelheid eisen om te kunnen werken → Internettelefonieapps meestal UDP → grotendeel van firewalls blokkeren UDP → ontworpen voor TCP → als back-up communicatie via UDP niet lukt

[![](https://github.com/martijnmeeldijk/TI-oplossingen/raw/master/Semester_2/Computernetwerken%202/Samenvatting/RackMultipart20210428-4-1qa6j26_html_5c553c39278d388d.png)](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/RackMultipart20210428-4-1qa6j26_html_5c553c39278d388d.png)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#215-protocollen-voor-applicatielaag)2.1.5 Protocollen voor applicatielaag

In applicatielaag volgende aspecten gedefinieerd:

- Soorten berichten die uitgewisseld worden, request &amp; antwoordberichten
- Syntaxis van verschillende soorten berichten, velden in bericht &amp; manier waarop velden van elkaar gescheiden worden
- Semantiek van velden → betekenis informatie in velden
- Regels voor bepalen wanneer en hoe proces berichten verzendt &amp; beantwoordt

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#216-netwerkapplicaties-die-in-dit-boek-beschreven-worden)2.1.6 Netwerkapplicaties die in dit boek beschreven worden

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#22-web--http)2.2 Web &amp; HTTP

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#221-meer-over-http)2.2.1 Meer over HTTP

- Webpagina bestaat uit aantal objecten → object is een bestand
- HTTP definieert hoe webclient een webserver verzoekt om een webpagina op te zoeken &amp; hoe servers webpagina's versturen naar een client
- HTTP → TCP als transportprotocol
- HTTP-client initieert TCP-verbinding met server → verbinding tot stand → processen van browser &amp; server TCP via socketinterfaces → client verzendt HTTP-verzoekberichten door socket → server ontvangt op zelfde manier HTTP-verzoekberichten via socket &amp; verzendt HTTP-antwoordberichten door socket
- HTTP is staatloos → Server houdt geen informatie bij over eerdere clientaanvragen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#222-non-persistente-en-persistente-verbindingen)2.2.2 Non-persistente en persistente verbindingen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#non-persistent)Non persistent

Basis HTML-file met volgende url: [http://www.someschool.edu/someDepartment/home.index](http://www.someschool.edu/someDepartment/home.index)

1. HTTP-client starts TCP-verbinding met server → client &amp; server gebruiken socket
2. HTTP-client verzendt HTTP-verzoekbericht naar HTTP
3. HTTP-serverproces ontvangt verzoekbericht
4. HTTP-serverproces TCP opdracht → verbreek verbinding als bericht ontvangen
5. HTTP-client ontvangt antwoordbericht
6. Herhaal stap 1-4 voor elk object

RTT → tijd die packet nodig heeft → client naar server &amp; omgekeerd

Klikt op een hyperlink → 3-way handshakeproces nodig:

1. Client verzendt TCP-segment naar server
2. Server bevestigt &amp; antwoord met TCP-segment
3. Client verzendt 2e bevestiging naar server
    
    → 1 RTT

- Na 1&amp;2 → verzendt client HTTP-verzoekbericht + 3e deel van 3way-handshake
- Totale responstijd = 2 RTT's + transmissietijd HTML-bestand server

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#persistent)Persistent

- Bij non persistent → elk opgevraagd object een nieuwe verbinding tot stand gebracht &amp; gehouden worden
- Bij non persistent → elk object 2 RTT's vertraging → 1 voor TCP-verbinding starten &amp; 1 om TCP-verbinding object op te vragen &amp; ontvangen
- HTTP 1.1 persistent → server laat TCP-verbinding intact na respons

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#223-indeling-http-berichten)2.2.3 Indeling HTTP-berichten

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#http-verzoekbericht)HTTP-verzoekbericht

- Eerste regel → requestregels
- Volgende regels → headerregels
- Host → host waar opgeslagen object is
- Connection: close → geen persistente verbinding nodig
- User Agent: → type browser
- POST → stuurt velden dat gebruiker heeft ingevuld door
- GET → 2 velden ( x &amp; y ) → structuur URL →[www.eensite.nl/zoekIets?x&amp;y](http://www.eensite.nl/zoekIets?x&y)
- HEAD → server reageert HTTP-bericht zonder opgevraagde object te verzenden

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#http-antwoordbericht)HTTP-antwoordbericht

- Statusregel, 6 headerregels &amp; entity body
- Connection: close → client weet TCP-verbinding weg na bericht verstuurd
- Server: → geeft aan gegenereerd door Apache-webserver
- Last-Modified: cachen objecten → lokaal &amp; server
- Content-length: → grootte object

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#224-interactie-gebruikers--servers-cookies)2.2.4 Interactie gebruikers &amp; servers: cookies

1. Cookieheaderregel in HTTP-antwoordbericht
2. Cookieheaderregel in HTTP-verzoekbericht
3. Cookiebestand opgeslagen op host gebruiker &amp; browser van gebruiker beheerd
4. Back-enddatabase op website

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#225-webcaching)2.2.5 Webcaching

Netwerkentiteit die HTTP-verzoeken afhandelt names oorspronkelijke webserver waar verzoek oorspronkelijk naartoe is gestuurd

Browser object [http://www.someschool.edu/campus.gif](http://www.someschool.edu/campus.gif)

1. Browser start TCP-verbinding met webcache &amp; verzendt HTTP-verzoek voor object naar webcache
2. Webcache checks → exemplaar opgevraagde object aanwezig? → if yes → webcache verzendt object in HTTP-antwoordbericht naar browser client
3. Opgevraagde object niet op webcache → TCP-verbinding met oorspronkelijke server → webcache verzendt HTTP-verzoek voor object via TCP-verbinding → wanneer server ontvangen → verzendt object in HTTP-antwoordbericht naar webcache
4. Opslaan kopie lokaal &amp; stuurt een exemplaar naar browser

2 redenen webcaching

- Responstijd clientverzoek verkorten
- Webcaches belasting van link van instituut verlagen

**CDN** (Content Distribution Networks) → veel geografische verspreide cachegeheugens in internet → groot deel dataverkeer lokaal

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#226-the-conditional-get)2.2.6 The conditional GET

- Verzoekbericht methode GET
- Verzoekbericht bevat If-Modified-Since

1. Client maakt get request
2. Server reageert met header
3. Client checkt de Last-Modified header
4. ls Last nieuwer is dan cache → haal pagina opnieuw op &amp; zet opnieuw in cache
5. anders → laad van cache

<div id="bkmrk-get-%2Findex.html-http">```
GET /index.html HTTP/1.1\r\n
Host: www-net.cs.umass.edu\r\n
User-Agent: Firefox/3.6.10\r\n
Accept: text/html,application/xhtml+xml\r\n
Accept-Language: en-us,en;q=0.5\r\n
Accept-Encoding: gzip,deflate\r\n
Accept-Charset: ISO-8859-1,utf-8;q=0.7\r\n
Keep-Alive: 115\r\n
Connection: keep-alive\r\n
\r\n

```

</div>### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#http2)**HTTP/2**

**Goal:** vertraging verlagen in multi-object HTTP requests **HTTP1.1**\*\* :\*\* meerdere, pipelined GETs over 1 TCP connectie

- Server antwoord in-order ( **FCFS** : **first-come-first-served scheduling** ) naar GET requests
- Met FCFS, mogelijkheid dat kleine objects moeten wachten voor transmissie (Head-of-line (HOL) blocking) achter grote objects
- Herstel van loss (retransmissie van verloren TCP segmenten) stalls object transmissie

**HTTP/2**\*\* :\*\* flexibiliteit verhogen server in versturen van objects naar client **Goal:** vertraging verlagen in multi-object HTTP requests

- Methoden, status codes, meeste header velden onveranderd tov HTTP 1.1
- verzendvolgorde van aangevraagde objecten op basis van door de klant opgegeven objectprioriteit (Niet noodzakelijk FCFS)
- Push unrequested objects naar cleint
- Verdeel objects in frames, plan frames om HOL-blokkering te verminderen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#http2-to-http3)**HTTP/2 to HTTP/3**

**Goal:** vertraging verlagen in multi-object HTTP requests

HTTP/2 over single TCP connectie wil zeggen:

- Herstel packet loss vertraagt nog steeds alle objecttransmissies
- In HTTP 1.1 browsers → stimulans om meerdere TCP-verbindingen te openen → vertraging verminderen → algehele doorvoer te verhogen
- Geen security over vanilla TCP-verbinding
- HTTP/3 → adds security → per object fout- &amp; congestie-controle ( meer pipelining) over UDP

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#23-e-mail-op-het-internet)2.3 E-mail op het internet

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#231-smtp)2.3.1 SMTP

Werking:

1. Alice → UA opdracht verstuur bericht
2. Alice's UA stuurt bericht mailserver→ in berichtenwachtrij
3. Clientzijde van SMTP opent TCP-verbinding met Bob's e-mailserver
4. SMTP-client verzendt het bericht van Alice via de TCP-verbinding
5. Bob's mailserver plaatst het bericht in Bob's mailbox
6. Bob roept zijn user agent aan om bericht te lezen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#232-vergelijking-met-http)2.3.2 Vergelijking met HTTP

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#smtp)SMTP

- Transfers files van 1 mail server naar een andere mail server
- **PUSH** protocol: verzendende e-mailserver duwt bestand naar e-mailserver van ontvanger
- Elk bericht moet in 7-bit ASCII zijn
- Plaatst alle bericht objecten in 1 bericht

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#http)HTTP

- Transfers files van web server naar web client
- **PULL** protocol: Iemand zet informatie op een webserver &amp; gebruiker gebruikt HTTP om informatie van server ophalen wanneer het hem uitkomt
- Restrictie niet nodig
- Encapsuleert elk object in zijn eigen HTTP response message

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#233-formats-e-mailberichten)2.3.3 Formats e-mailberichten

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#234-mail-accessprotocollen)2.3.4 Mail accessprotocollen

SMTP: levering/opslag van e-mailberichten op de server van de ontvanger

Mail Access Protocol: Ophalen server

IMAP: **Internet Mail Access Protocol** \[RFC 3501\]: berichten opgeslagen op de server, IMAP biedt ophalen, verwijderen, mappen met opgeslagen berichten op de server

HTTP: Gmail, Hotmail, Yahoo! Mail, etc. biedt webgebaseerde interface bovenop STMP (om te verzenden), IMAP (of POP) om e-mailberichten op te halen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#pop3)POP3

UA → TCP-verbinding naar mailserver

1. Autorisatiefase: UA → verstuurt username &amp; password → identitetit gebruiker vaststellen
2. Transactiefase: UA haalt berichten op
3. Updatefase: client opdracht quit → POP3-sessie closed

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#imap)IMAP

- Koppelt elk bericht aan een map
- Biedt opdrachten → UA afzonderlijke componenten van bericht

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#webmail)Webmail

Ontvanger wil mailbox bekijken → bericht van mailserver naar browser van gebruiker verzonden → behulp van HTTP-protocol

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#24-dns)2.4 DNS

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#241-diensten-van-dns)2.4.1 Diensten van DNS

- Een gedistribueerde database → geïmplementeerd in hiërarchie van DNS-servers
- Applicatielaagprotocol waarmee hosts &amp; DNS-servers kunnen communiceren om vertaalslag ( omzetten IP → "te onthouden" adres &amp; omgekeerd)

DNS verzorgt aantal andere diensten naast vertalen hostnamen in IP-adressen:

- **Host-aliasing:** 1 of meerdere aliassen wanneer hostname te lastig is → canonieke hostnaam → aliashostnamen gebruikt → gemakkelijker te onthouden dan canonieke hostnamen
- **Mailserver-aliasing:** Hostnaam van een mailserver (bv. Yahoo) → moeilijker dan → eenvoudige Yahoo.com → DNS kan door mailapplicatie gebruikt worden → achterhalen canonieke hostnaam v/e bepaalde host + IP-adres van host → MX record maakt mogelijk dat mailserver &amp; webserver van bedrijf dezelfde hostnamen hebben → mailserver &amp; webserver van bedrijf kunnen dus bv. enterprise.com heten.

(Een MX-record (Mail eXchange-record) is een gegevenstype in het Domain Name System (DNS). Het specificeert de mail server die e-mailverkeer voor het betreffende domein afhandelt. Een domein kan meerdere MX-records hebben met een verschillende prioriteit waardoor het mogelijk is om bijvoorbeeld een back-up mailserver aan te geven als de computer met de hogere prioriteit niet bereikbaar blijkt. De naam die in het MX-record wordt gevonden kan via DNS op zijn beurt in een ip-adres worden vertaald. Src: Wikipedia)

- **Loadbalancing:** Belasting van gerepliceerde servers te verminderen → gerepliceerde webservers een serie IP-adressen gekoppeld aan canonieke hostname → DNS-database bevat serie IP-adressen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#242-overzicht-van-de-werking-van-het-dns)2.4.2 Overzicht van de werking van het DNS

Gecentraliseerd ontwerp levert volgende problemen op:

- **Single point of failure:** als DNS crashed hele internetonbruikbaar
- **Netwerkbelasting** : 1 DNS-server → alle DNS-verzoekberichten verwerken ( alle HTTP-verzoekberichten &amp; e-mails van honderden miljoenen hosts)
- **Afstand tot gecentraliseerde database** : 1 enkele DNS-server kan niet 'in de buurt' van alle verzoekende clients staan → centrale DNS bijvoorbeeld in Antwerpen → verzoeken uit Nieuw-Zeeland → kan vertraging veroorzaken
- **Onderhoud** : die DNS-server informatie over alle internethosts moeten beheren → database wordt dan heel groot &amp; telkens bijgewerkt moeten worden wanneer nieuwe host wordt aangemeld.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#een-gedistribueerde-hi%C3%ABrarchische-database)Een gedistribueerde, hiërarchische database

- **Root-DNS-servers:** meer dan 400 root-nameservers verspreid over de wereld → door 13 verschillende organisaties gemanaged → leveren IP adressen van TLD-servers
- **Topleveldomein (TLD) -servers:** voor elk TLD (com,org,net,edu,...) &amp; landTLD(nl,fr,ca,...) → is er een TLD → TLD leveren IP-adressen voor authoritative DNS-servers
- **Authoritative DNS-servers:** eigen DNS-server(s) van de organisatie, die gezaghebbende hostnaam biedt aan IP-toewijzingen voor de benoemde hosts van de organisatie + kan Dutch translation. kakjkworden onderhouden door organisatie of dienstverlener
- Lokale DNS-server behoort niet tot hiërarchie maar wel belangrijk voor DNS-structuur → elke ISP zoals een standaard ISP of ISP van instituut → lokale DNS-server → wanneer host verbinding tot stand wil brengen met ISP → ISP geeft aan die host IP-adressen van 1 of meer van diens lokale DNS-server → lokale DNS-server niet ver weg van host → bij residentiële ISP DNS-server → gescheiden enkele routers van host van client → host verzoekbericht aan DNS verzendt → doorgestuurd lokale DNS-server → fungeert als proxy → verzoek verder gestuurd in DNS-serverhiërarchie
- Recursief DNS-verzoek = host stuurt verzoek aan lokale DNS-server, die op zijn beurt een verzoek doet aan de root-server, die op zijn beurt een verzoek doet aan de TLD-server … (zie p127)
- Iteratief DNS-verzoek = host stuurt verzoek aan lokale DNS-server, die op zijn beurt een verzoek doot aan de root-server, de root-server stuurt antwoord naar lokal DNS-server die op haar beurt een verzoek doet aan de TLD-server… (zie p126)

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#dns-caching)DNS-caching

DNS-server → in verzoekberichtenketen → wanneer DNS-antwoord ontvangt → verwijzing in lokale cachegeheugen plaatsen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#243-dns-records-en--berichten)2.4.3 DNS-records en -berichten

DNS-servers bevatten bronrecords → (Naam, Waarde, Type, TTL)

1. **If Type = A** then naam bevat hostnaam en Waarde bevat IP-adres van hostnaam
2. **If Type = NS** then naam bevat domeinnaam en Waarde bevat hostnaam van authoritative DNS-server die de hostnaam en IP combinaties voor de hosts in dat domein weet
3. **If Type = CNAME** then waarde is canonieke hostname voor aliashostname
4. **IF Type = MX** then waarde is canonieke naam van mailserver met alias hostname name

Een authoritative DNS-server bevat een A-record

Een niet-authoritative DNS-server bevat een NS-record voor het domein waarin de DNS-server zich bevindt en ook een A-record met het IP-adres van de DNS-server die in het veld Waarde van het NS-record staat

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#dns-berichten)DNS-berichten

- Eerste 12 bytes voor de header:

1. Eerste veld is een uniek 16 bit getal waarmee het verzoek geïdentificeerd kan worden. Dat getal word gekopieerd in het antwoordbericht, zodat de client het antwoord en het verzoek kan kopellen
2. Vlaggen veld bevat een aantal vlaggen. Een 1-bit verzoek/antwoord-vlag (verzoek = 1 en antwoord = 0), 1-bit authoritative-vlag wordt in een antwoordbericht gezet als de DNS-server de authoritative DNS-server voor de hostnaam is, 1-bit recursienoodzaak-vlag wordt gebruikt als de client vraagt om recursief te werken als het gevraagde record niet op die DNS-server staat en een 1-bit recursiemogelijkheids-vlag die in het antwoordbericht staat na een verzoekbericht met een recursienoodzaak-vlag

- Vraagveld bevat informatie over het verzonden verzoek:

1. Bevat een naamveld met de naam waarvoor het IP-adres wordt gezocht
2. Bevat een typeveld met het type verzoek (Type A, Type NS…)

- In een antwoordbericht staat in het antwoordveld de bronrecords van het oorspronkelijke DNS-verzoek
- Het autorisatieveld bevat gegevens van andere authoritative DNS-servers
- Het aanvullingsveld bevat aanvullende bronrecords (Het antwoordveld in een antwoord op een MX-verzoek bevat een bronrecord met de canonieke hostnaam van de mailserver en het aanvullingsveld bevat het een Type A record met het IP-adres van de canonieke hostnaam van de mailserver

###  

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#dns-security)DNS-Security

**DDOS-attack:**

- root servers belasten met verkeer
- Tot op heden niet succesvol
- Verkeersfiltering
- Lokale DNS-servers cache-IP's van TLD-servers waardoor rootserver bypassed

**TLD servers bombarderen:**

- Kan gevaarlijker zijn maar moeilijker → TLD servers niet zo gemakkelijk bypassed

**Aanvallen omleiden**

- Man in the middle → DNS queries intercepten
- DNS poisoning → valse afhankelijkheden verzenden naar dns-server, die cachen

**DNS voor DdoS exploiteren**

- Queries versturen met vervalste bronadres → target IP
- Vereist versterking

**Laatste 2 vormen DNSSEC**

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#25-peer-to-peer-bestandsdistributie)2.5 Peer-to-peer bestandsdistributie

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#p2p-file-distributie-bittorrent)P2P file distributie: BitTorrent

Peer neemt deel aan torrent → meldt bij tracker → peer informeert tracker met regelmaat of nog aanwezig in torrent → nieuwe peer → tracker random # peers → verzendt IP-adressen van # peers → naar nieuwe peer → proberen TCP-verbinding met peers op lijst → bepaald tijdstip → elke peer → # chunks bestand → verschillende peers → verschillende verzamelingen chunks hebben → na een bepaalde tijd → gebruiker vraagt elke peer om lijst met chunks die ze hebben → gebruiker vraagt de "missing chunks" van de peerst → zeldzaamste eerst of **Rarest first**

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#tit-for-tat-principe)Tit-for-tat principe:

Gebruiker stuurt chunks naar die vier peers die momenteel haar chunks in het hoogste tempo verzenden → andere peers gestikt door gebruiker (ontvangen geen chunks van gebruiker) → herbeoordeeld top 4 elke 10 seconden

Elke 30 seconden → selecteert willekeurig een andere peers, begint met verzenden van chunks → optimistisch unchocked deze peer → nieuwe gekozen peer kan lid worden van top 4

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#26-videostreaming-en-content-distribution-networks)2.6 Videostreaming en content distribution networks

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#internetvideo)Internetvideo

- Video → sequentie van afbeeldingen → afgebeeld constante snelheid Bijvoorbeeld: 24 afbeeldingen / seconde
- Digital image → array van pixels Elke pixel gerepresenteerd door bits
- Coding: Gebruikt redundantie binnen en tussen afbeeldingen om # bits te verminderen die worden gebruikt om abeeldingen te gebruiken Spatial → binnen afbeelding Temporal → van 1 afbeelding naar volgende
- CBR → constant bit rate → video encoding rate is fixed
- VBR → variable bit rate → wijzigingen in videocoderingssnelheid als hoeveelheid spatial, temporal codering wijzigt

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#2611-streaming-stored-video)2.6.1.1 Streaming stored video

**Simpel Scenario:**

**Hoofddoelen:**

- Server to client bandbreedte varieert over tijd met veranderende netwerkcongestieniveaus → ( in huis, in acces network, network core, video server)
- pakketverlies en vertraging als gevolg van congestie zullen de play-out vertragen of resulteren in een slechte videokwaliteit

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#2612-streaming-stored-video--challenges)2.6.1.2 Streaming stored video : challenges

Continuous playout constraint → zodra play-out van client begint → afspelen overeenkomen met oorspronkelijke timing → **maar** network delays variabel (jitter) → heeft buffer aan clientzijde nodig om aan play-out vereisten te voldoen

Andere challenges

Client interactiviteit → pause, voortspoelen, terugspelen, verder in video gaan → video packets loss mogelijk → opnieuw verzonden

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#http-streaming-en-dash)HTTP-streaming en DASH

**D** ynamic **A** daptive **S** treaming over **H** TTP

- Server 
    - Deelt video bestand in meerdere chunks
    - Elke chunk stored, gecodeerd met verschillende snelheden
    - **Manifestbestand** : biedt URL's voor verschillende chunks
- Client 
    - Meet periodiek server-naar-client bandbreedte
    - Adviesmanifest, vraagt 1 chunk tegelijk 
        - Kiest voor max coderingssnelheid duurzaam gezien huidige bandbreedte
        - Kan verschillende coding rates kiezen op verschillende punten in tijd → afhankelijk vrije bandbreedte

STREAMING VIDEO = CODERING + DASH + PLAYOUT BUFFERING

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#content-distribution-networks-cdns)Content Distribution Networks (CDNs)

Challenge: Hoe content streamen naar 100 tot 1000'en gebruikers tegelijk

- **Optie 1: 1 grote server**
    
    
    - Single point of failuire
    - Punt van netwerkcongestie
    - Lange weg naar clients die verweg zijn
    - meerdere kopieën van video verzonden via uitgaande link
- Deze oplossing **schaalt niet**
- Optie 2: meerdere kopieën van video's opslaan/weergeven op meerdere geografisch gedistribueerde sites →**(CDN)**
    
    
    - Enter deep → push CDN servers diep in veel access networks → dichtbij users 
        - Bijvoorbeeld: Akamai → 240k in meer dan 120 landen
    - Bring home: kleinere nummers (10's) of grotere clusters in POP's dichtbij access netwerken
- CDN → slaagt kopieen van content op aan CDN nodes
- Subscriber vraagt content van CDN → gericht nabijgelegen kopie &amp; haalt inhoud op
- kan een andere kopie kiezen als het netwerkpad overbelast is

# [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#hoofdstuk-8-security-in-computer-networks)Hoofdstuk 8: Security in computer networks

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#81-wat-is-netwerkbeveiliging)8.1 Wat is netwerkbeveiliging

1. **Vertrouwelijkheid** : Alleen zender &amp; beoogde ontvanger inhoud van verzonden bericht begrijpen
2. **Berichtintegriteit** : de afzender en ontvanger zeker zijn dat inhoud van communicatie niet wordt gewijzigd
3. **Authenticatie op eindpunt:** zender &amp; ontvanger identiteit andere partij vaststellen zeker te zijn dat ander is wie hij beweert
4. **Operationele beveiliging:** bijna alle organisaties hebben netwerken aangesloten op het openbare internet.Deze netwerken kunnen daarom mogelijk worden aangetast.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#82-principes-van-cryptografie)8.2 Principes van cryptografie

**Verzender ( X )** verstuurt bericht naar **ontvanger (Y)**

1. X gebruikt sleutel **K**\*\* A\*\*→ invoer versleutelalgoritme
2. Versleutelalgoritme gebruikt sleutel → onversleutelde bericht m → versleutelde tekst → **K**\*\* A\*\*\*\*(m)\*\*
3. KA onderling afspreken
4. Y ook sleutel **K**\*\* B \*\*\*\* →\*\*invoer onsleutelalgoritme → versleutelde bericht X → plaintext
5. Y ontvangen versleutelde bericht KA(m) → ontsleutelen → berekenen van Kb(Ka(m)) = m

- Symmetrische sleutelsystemen → sleutels X &amp; Y identiek en geheim
- Openbare sleutelsystemen → 2 verschillende sleutels → 1 v/d 2 zowel bij X als Y bekend

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#821-cryptografie-met-symmetrische-sleutels)8.2.1 Cryptografie met symmetrische sleutels

1. **First** → Caeser cipher → elke letter in platte tekst → letter → k-letters in alfabet te vervangen
2. **Daarna** → monoalfabetisch cijfer → lettervervanging maar moet uniek zijn

**Bruteforce-benadering**→ uitproberen alle 10^26 → teveel werk

- **Aanval met alleen versleutelde tekst** → indringer beschikt alleen over onderschepte versleutelde tekst → niet over informatie van inhoud → onversleutelde bericht
- **Aanval met bekende onversleutelde tekst** →**Indringer (Z)**→ kent enkele combinaties van onversleutelde &amp; versleutelde tekst
- **Aanval met specifieke onversleutelde tekst** **→** Z kiest onversleuteld bericht → corresponderende versleutelde tekst krijgen → als Z → X een bepaalde zin kan laten verzenden → versleutelmethode verbroken

**Polyalfabetische codering** → verschillende monoalfabetische ciphers gebruikt → afwisselend ingezet → bepaalde positie in onversleutelde bericht te versleutelen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#block-ciphers-des--data-encryption-standard-3des-aes-advanced-encryption-standard)Block ciphers (DES = data encryption standard, 3DES, AES= advanced encryption standard)

**2 categorieën** van symmetrische versleuteltechnieken

- Stream cipher
- Block cipher

**Blockciphers**

1. versleutelen bericht → verwerkt blokken k bits
2. **IF** k = 64 → bericht opgesplitst in 64 blokken → elk blok onafhankelijk versleuteld
3. Codering 1 op 1 toewijzing om k-bit blok cleartext toe te wijzen aan k-bit blok Ciphertext

**Hoeveel mogelijke verwijzingen?**

- k = 3 dan zijn er 23 mogelijke ingangen. Deze ingangen kunnen in 8 worden gepermuteerd! = 40 320.

Zeer moeilijk uit te voeren. Voor k = 64 moeten Alice en Bob een tabel onderhouden met 2^64 invoerwaarden → onmogelijk → blokcoderingen meestal functies die willekeurig gepermuteerde tabellen simuleren.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#cipher-block-chaining-cbc)Cipher-block chaining (CBC)

Blockcipher → twee of meer blokken identiek zijn→aanvaller mogelijk **cleartext raden** en misschien het hele bericht decoderen. → solution → willekeur in ciphertext

**Werkwijze:**

1. voor bericht versleutelt → genereert Afzender **een willekeurige k-bit string,initialisatievector (IV) = c(0)** genoemd→ afzender stuurt IV naar ontvanger in leesbare vorm
2. Eerste blok berekent de afzender **m(1) + c(0) → exclusieve OR van eerste blok onversleutelde tekst &amp; IV. → verzender verwerkt met BC → bijhorende blok als versleutelde tekst c(1)=Ks(m(1)+c(0)** → verzender versleutelde blok (c1) naar ontvanger
3. Voor het i-blok genereert de afzender **c(i) = Ks(m(i) + c(i-1))**

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#822-cryptografie-met-openbare-sleutel)8.2.2 Cryptografie met openbare sleutel

- 2 partijen delen gedeeld geheim →Symmetrische sleutel voor encryptie &amp; decryptie

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#diffie-hellman-key-exchange)Diffie-Hellman key exchange

1. Alice haalt Bob's publieke sleutel
2. Alice versleutelt bericht (m) aan Bob → door public key van Bob en bekend encryptie-algoritme K+B(m).
3. Bob ontvangt → gecodeerde bericht van Alice → gebruikt private key &amp; bekend decoderingsalgoritme → gecodeerde bericht decoderen
4. Bob berekent K-B( K+B(m)).
5. Berekenen van Kb-(Kb+(m)) resulteert in m

**Note :** each party generates a public/private key pair and distributes the public key. After obtaining an authentic copy of each other's public keys, Alice and Bob can compute a shared secret offline. The shared secret can be used, for instance, as the key for a [symmetric cipher](https://en.wikipedia.org/wiki/Symmetric-key_algorithm).

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#rsa)RSA

**Maken van publieke en private RSA keys:**

1. Kies 2 grote priemgetallen p &amp; q → hoe groter de waarden hoe moeilijker RSA-algoritme te kraken
2. Bereken n = p \* q
3. Bereken z = (p – 1) \* (q-1)
4. Kies nummer e, dat kleiner is dan n &amp; geen factoren (buiten 1 ) gemeenschappelijk heeft met z
5. Zoek een getal d, zodanig dat ed – 1 precies deelbaar is door z. Wij kiezen d zodanig dat e\*d mod z = 1
6. Openbare sleutel (K+B) is het paar van de getallen (n, e)
7. The private key(K-B) is the pair of the numbers (n, d)

- Encrypteren → C = me mod n
- Decrypteren → m = cd mod n. Which requires the use of the private key (n, d)

**NOTE:** Diffie-Hellman niet zo veelzijdig als RSA omdat het niet gebruikt kan worden om berichten met willekeurige lengte te coderen → toegepast om symmetrische sessiesleutel tot stand te brengen → daarna coderen berichten

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#berichtintegriteit-en-digitale-handtekeningen)Berichtintegriteit en digitale handtekeningen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#831-cryptografische-hashfuncties)8.3.1 Cryptografische hashfuncties

- Rekentechnisch onmogelijk → 2 verschillende berichten x en y te vinden → waarbij

H(x) = H(Y)

- Onmogelijk voor indringer → bericht vervangen door ander bericht dat beveiligd is met hashfunctie
- **Om veiligheidsredenen** hebben we een krachtigere hash-functie nodig dan een checksum → het **MD5-hash-algoritme.** Het berekent een 128-bits hash in een proces in **vier stappen** dat bestaat uit: 
    - een opvulstap
    - een toevoegstap
    - een initialisatie van een accumulator
    - een laatste loopingstap waarin de blokken van 16 woorden van het bericht in vier rondes worden verwerkt
- Het tweede belangrijke hash-algoritme is het **Secure Hash Algorithm (SHA1).** Het produceert een 160-bits berichtcijfer. De langste output maakt SHA1 veiliger.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#832-berichtauthenticatiecode)8.3.2 Berichtauthenticatiecode

berichtintegriteit uit te voeren→Alice en Bob→ naast gebruik van cryptografische hashfuncties, → gedeeld geheim nodig→niets meer dan een reeks bits = verificatiesleutel.→ door gedeelde geheim kan berichtintegriteit als volgt worden uitgevoerd:

- Alice maakt bericht m, samenvoegt s met m om m + s te maken en berekent de hash (m+s). → berichtverificatiecode (MAC = **Message Authentication Code** )
- Alice voegt vervolgens de MAC toe aan het bericht m, maakt een uitgebreid bericht (m, H(m+s)) en stuurt het naar Bob
- Bob ontvangt het bericht (m, h) en weet s, berekent de MAC H(m+s). Als H(m+s) = h, dan is alles in orde met de boodschap

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#833-digitale-handtekeningen)8.3.3 Digitale handtekeningen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#certificering-van-openbare-sleutels)Certificering van openbare sleutels

Certificate authority → echtheid identiteiten authenticeert &amp; certificaten uitgeeft

1. Een certification authority controleert of een entiteit is wie het zegt dat het is.
2. certificeringsinstantie identiteit van entiteit verifieert, maakt certificeringsinstantie een certificaat → openbare sleutel van de entiteit aan de identiteit bindt → certificaat bevat openbare sleutel + wereldwijd unieke identificerende informatie over eigenaar van openbare sleutel. Het certificaat digitaal ondertekend door certification authority.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#authenticatie-op-het-eindpunt)Authenticatie op het eindpunt

Eindpuntverificatie →proces waarbij de ene entiteit zijn identiteit aan een andere entiteit bewijst via een computernetwerk.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#841-authenticatieprotocol-ap10)8.4.1 Authenticatieprotocol ap1.0

Trudy (indringer) stuurt bericht naar Bob → zegt "ik ben Alice" → Bob weet niet of het werkelijk Alice is 8.4.2 Authenticatieprotocol ap2.0 Alice bekend netwerkadres waaruit ze altijd communiceert→ Bob proberen Alice te verifiëren → bronadres IP-datagram met verificatiebericht overeenkomt met het bekende adres van Alice.

niet moeilijk om IP-datagram te maken, zet elk IP-bronadres dat we willen in het IP-datagram.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#843-authenticatieprotocol-ap30)8.4.3 Authenticatieprotocol ap3.0

Het wachtwoord is een gedeeld geheim tussen de authenticator en de persoon die wordt geverifieerd.

- Alice stuurt haar geheime wachtwoord naar Bob.
- De beveiligingsfout hier is dat als Trudy Alice's communicatie afluistert, ze Alice's wachtwoord kan leren.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#844-authenticatieprotocol-ap31)8.4.4 Authenticatieprotocol ap3.1

Door het wachtwoord te versleutelen→voorkomen Trudy Alice's wachtwoord leert→aannemen dat Alice en Bob een symmetrische geheime sleutel delen, KA – B,dan kan Alice het wachtwoord versleutelen en haar identificatiebericht en het gecodeerde wachtwoord naar Bob sturen. Bob decodeert vervolgens het wachtwoord en verifieert Alice.

**De fout:** **the playback attack** **:** Trudy hoeft alleen maar de communicatie van Alice af te luisteren, de gecodeerde versie van het wachtwoord op te nemen en de gecodeerde versie van het wachtwoord af te spelen naar Bob om te doen alsof ze Alice is.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#845-authenticatieprotocol-ap40)8.4.5 Authenticatieprotocol ap4.0

**Een nonce** is een getal dat een protocol maar één keer in een leven zal gebruiken. Dat wil zeggen dat zodra een protocol een nonce gebruikt, het het nummer nooit meer zal gebruiken. Onze ap4.0 **gebruikt een nonce in als volgt:**

1. Alice verzendt bericht 'ik ben Alice' aan Bob
2. Bob kiest een nonce en verzendt die naar Alice
3. Alice versleutelt de nonce met de symmetrische sleutel van Alice en Bob, KA– B,en stuurt de gecodeerde nonce KA\_B(R) terug naar Bob.
4. Bob ontsleutelt het ontvangen bericht. Als de gedecodeerde nonce gelijk is aan de nonce die hij Alice stuurt, dan is Alice geauthenticeerd

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#85-e-mail-beveiligen)8.5 E-mail beveiligen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#851-ontwerp-van-veilige-e-mail)8.5.1 Ontwerp van veilige e-mail

**Vertrouwelijkheid (Systeem 1)**

- Bericht versleutelen → symmetrische sleuteltechnologie (DES) → ontvanger bericht ontsleutelen
- Alternatief → cryptografie openbare sleutel (RSA)
- Om dit efficiëntieprobleem op te lossen, maken we **gebruik van een sessie** **key:**
    
    
    1. Alice selecteert een willekeurige symmetrische sessiesleutel (Ks)
    2. Versleutelt haar bericht m met de symmetrische sleutel
    3. Versleutelt de symmetrische sleutel met Bob's openbare sleutel K+b
    4. Voegt het gecodeerde bericht en de gecodeerde symmetrische sleutel samen om een pakket te vormen
    5. stuurt het pakket naar Bob's e-mailadres. **(zie p 586 onderaan voor schema)**
- Bob ontvangt pakket:

1. Gebruikt geheime sleutel Kb-→ verkrijgen symmetrische sleutem Ks
2. Symmetrische sleutel Ks → ontsleutelen bericht

**Sessie key = inefficient**

**1. Berichtintegriteit**

- Digitale handtekeningen:
    
    
    1. Alice past hashfunctie H toe
    2. Versleutelt resultaat met hashfunctie → met geheime sleutel KA- → digitale handtekening
    3. Oorspronkelijke bericht samen met handtekening → 1 pakket
    4. Verzend pakket → e-mail Bob
- Bob ontvangt het pakket
    
    
    1. Openbare sleutel Alice KA+ → op ondertekende hash
    2. Vergelijkt resultaat bewerking met eigen hash H van bericht

**The 2 combined:**

- Alice maakt eerst een voorlopig pakket, dat bestaat uit haar originele bericht samen met een digitaal ondertekende hash van het bericht
- Vervolgens behandelt ze dit voorlopige pakket als een bericht op zich en stuurt dit nieuwe bericht via **de stappen van de afzender van (a)**, waardoor een nieuw pakket wordt gemaakt dat naar Bob wordtverzonden **(zie schema p** **586**\*\* )\*\*

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#852-pgp)8.5.2 PGP

PGP-software gebruikt:

- MD5 of SHA → berekenen hash
- CAST, Triple-DES of IDEA → versleutelen symmetrische sleutel
- RSA versleuteling openbare sleutel

Als PGP installed:

1. Openbaar sleutelpaar voor gebruiker
2. Openbare sleutel → website gebruiker of openbare sleutelserver

- Persoonlijke sleutel beschermd → wachtwoord

PGP → mogelijkheid bericht digitaal ondertekenen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#86-tcp-verbindingen-beveiligen)8.6 TCP-verbindingen beveiligen

Noodzaak SSL:

- Geen versleuteling → indringer Bobs bestelling onderscheppen → creditcardgegevens achterhalen
- Integriteit gegevens niet gecontroleerd → bestelling veranderen
- Server niet geauthenticeerd → Valse website maken → gegevens stelen

SSL lost problemen op door volgende bovenop TCP uit te voeren:

1. Vertrouwelijkheid
2. Gegevensintegriteit
3. Serverauthenticatie
4. Clientauthenticatie

SSL → eenvoudige API vergelijkbaar API van TCP

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#861-het-hele-verhaal-maar-vereenvoudigd)8.6.1 Het hele verhaal, maar vereenvoudigd

**Fase 1: Handshake**

1. Bob TCP-verbinding met Alice maken
2. Verzekeren dat Alice echt Alice is
3. Alice geheime mastersleutel zenden → Alice &amp; Bob gebruiken → symmetrische sleutel genereren → nodig voor SSL

**Fase 2: Verkrijgen van een sleutel**

Alice &amp; Bob moeten MS gebruiken om vier sleutels te genereren:

- EB: **session encryption key** for data sent from Bob to Alice
- MB: **session MAC key** for data sent from Bob to Alice
- EA: session encryption key for data sent from Alice to Bob
- MA: session MAC key for data sent from Alice to Bob

**Fase 3: Gegevensoverdracht**

Geen goed idee → integriteit alle gegevens tijdens hele sessie dat Bob gestuurd heeft controleren

1. SSL splitst gegevensstream → records
2. SSL voegt berichtauthenticatiecode toe aan elk record → versleutelt combinatie
3. Maken van berichtauthenticatiecode → Bob hashfunctie toe → combinatie recordgegevens &amp; sleutel Mb
4. Versleutelen → Bob gebruikt sessievercijfersleutel Eb

**Man in the middle attack** **( MITM)** : kansegmenten in de TCP-stream vervangen, invoegen en verwijderen tussen Alice en Bob.

Aannemen dat elk TCP-segment exact 1 record verpakt is → kijken hoe Alice segmenten verwerkt

1. TCP in host Alice → denkt alles is OK → 2 records aan SSL-sublaag
2. SSL in host Alice → 2 records ontsleutelen
3. SSL in host Alice →berichtauthenticatiecode in elk record gebruiken → integriteit van gegevens in 2 records
4. SSL → ontsleutelde bytestream van 2 records doorgeven → applicatielaag → door Alice ontvangen bytestream → gevolg verwisseling records → niet in juiste volgorde

**Oplossing: gebruik volgnummers**.

1. Bob onderhoudt een reeksnummerteller, die begint bij nul en wordt verhoogd voor elke SSL-record die hij verzendt.
2. Wanneer hij de MAC berekent,neemt hij het volgnummer op in de MAC-berekening.

Zo is MAC = hash van gegevens + MAC-toets + huidig volgnummer.

Alice kan Bob's volgnummers opsporen, zodat ze de gegevensintegriteit kan verifiëren.

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#ssl-record)SSL record

Bestaat uit → typeveld, versieveld, lengteveld, gegevensveld &amp; berichtauthenticatiecode

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#862-het-hele-verhaal-maar-wat-minder-vereenvoudigd)8.6.2 Het hele verhaal, maar wat minder vereenvoudigd

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#ssl-handshake)SSL handshake

Alice &amp; Bob begin SSL-sessie zelf afspraken maken over cryptografische algoritmen → aka handshakeprocedurefase → + Alice &amp; Bob zenden elkaar nonces toe → gebruikt bij maken van sessiesleutels (EB,MB,EA,MA)

Handshakeprocedure bij SSL:

1. Client verzendt lijst → versleutelalgoritmen die hij ondersteunt &amp; zelfgekozen nonce
2. Server kiest uit ontvangen lijst algoritme voor → symmetrische sleutel, openbare sleutel &amp; berichtauthenticatiecode → server verstuurt bericht met voorkeuren, certificaat &amp; zelfgekozen nonce
3. Client authenticeert certificaat + berekent openbare sleutel server + genereert geheime pre-mastersleutel (PMS) → versleutelt PMS met openbare sleutel server → verzendt versleutelde PMS naar server
4. Afgesproken functie bepalen sleutel → berekenen client &amp; server onafhankelijk → geheime mastersleutel met PMS &amp; nonces → geheime mastersleutel in stukken gehakt → 2 coderingssleutels &amp; 2 berichtauthenticatiecodes genereren → gekozen symmetrische codering werkt met cipher-block-chaining → 2 initialisatievectoren gemaakt → geheime mastersleutel → daarna alle berichten versleuteld &amp; geauthenticeerd
5. Client verzendt berichtauthenticatiecode → alle handshakeprocedureberichten
6. Server verzendt berichtauthenticatiecode → alle handshakeprocedureberichten

Alleen nonces → niet mogelijk "replay attack" te voorkomen

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#verbinding-verbreken)Verbinding verbreken

Iemand geeft in het typeveld aan of de record dient om de SSL-sessie te beëindigen. Door zo'n veld op te nemen, zou Alice weten dat als ze een TCP FIN zou ontvangen voordat ze een SSL-sluitingsrecord zou ontvangen, ze weet dat er iets grappigs aan de hand is.

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#87-beveiliging-op-netwerklaag-ipsec--vpn)8.7 Beveiliging op netwerklaag: IPsec &amp; VPN

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#871-ipsec--vpn)8.7.1 IPsec &amp; VPN

Met VPN → interne dataverkeer van de instelling verzonden via het publiekelijk toegankelijke internet in plaats van via een fysiek gescheiden netwerk. → dataverkeer eerst versleuteld

**CHECK PAGINA 597 IN HANDBOEK VOOR AFBEELDING**

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#872-authentication-header-protocol-en-het-encapsulation-security-payload-protocol)8.7.2 Authentication header-protocol en het encapsulation security payload-protocol

Protocolsuite IPsec → Authentication header **(AH-protocol)** &amp; encapsulation security payload **(ESP-protocol)**

**AH-protocol** → bronauthenticatie &amp; gegevensintegriteit maar geen vertrouwelijkheid **ESP-protocol** → bronauthenticatie &amp; gegevensintegriteit &amp; vertrouwelijkheid Vertrouwelijkheid essentieel bij VPN &amp; andere IP-sec applicaties

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#873-beveiligingsassociaties)8.7.3 Beveiligingsassociaties

IPsec-datagrammen → verzonden tussen 2 netwerkentiteiten → voor bronentiteit IPsec-datagrammen verstuurt → 2 entiteiten → logische verbinding tot stand = **beveiligingsassociatie** → logische simplexverbinding → unidirectioneel van bron naar bestemmingsentiteit → beide entiteiten beveiligde datagrammen naar elkaar willen verzenden → noodzakelijk om 2 beveiligingsassociaties tot stand te brengen → voor elke richting 1

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#874-het-ipsec-datagram)8.7.4 Het IPsec-datagram

2 verschillende packetvormen → **tunnelmodus &amp; transportmodus** **PAGINA 589 HANDBOEK**

- R1 voegt achter aan oorspronkelijke IPv4-datagram een ESP-trailerveld toe
- R1 versleutelt resultaat met behulp van het algoritme &amp; de sleutel die voor de beveiligingsassociatie zijn overeengekomen
- R1 voeg aan voorkant van versleutelde geheel → veld toe → ESP-header → Resulterende pakket → enchilada
- R1 voegt berichtauthenticatiecode toe aan achterkant van versleutelde geheel → alles te samen → inhoud van payloadveld
- R1 creëert een nieuwe IP-header met alle klassieke IPv4-headervelden → voegt voor payloadveld toe

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#875-sleutelbeheer-in-ipsec-ike)8.7.5 sleutelbeheer in IPsec (IKE)

IKE kent twee fase

Fase1:

- Vaststellen bidirectionele IKE SA

*opmerking: IKE SA anders dan IPsec SA ook bekend als ISAKMP security association*

Fase 2:

- ISAKMP wordt gebruikt om veilig te onderhandelen over IPsec-paar SA's

fase 1 heeft twee modi: agressieve modus en hoofdmodus

- Agressieve modus gebruikt minder berichten
- Hoofdmodus biedt identiteitsbescherming en is flexibeler

IKE-berichtenuitwisseling voor algoritmen, geheime sleutels, SPI-nummers

- AH- of ESP-protocol (of beide) AH biedt integriteit, bronverificatie
- ESP-protocol (met AH) biedt bovendien versleuteling
- IPsec-peers kunnen twee eindsystemen zijn, twee routers/firewalls, of een router/firewall en een eindsysteem

##  

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#88-securing-wireless-lans)8.8 Securing wireless LANs

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#881-wired-equivalent-privacy)8.8.1 Wired equivalent privacy

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#leer-vanuit-slides-rarr-duidelijker)LEER VANUIT SLIDES $rarr; DUIDELIJKER

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#89-operationele-beveiliging-firewalls--intrusion-detectionsystemen)8.9 Operationele beveiliging: firewalls &amp; intrusion-detectionsystemen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#891-firewalls)8.9.1 Firewalls

3 doelen:

- Alle dataverkeer van buiten naar binnen &amp; omgekeerd passeert firewall
- Alleen geauthenticeerd dataverkeer → gedefinieerd in lokale beveiligingspolicy's mag passeren
- Firewall kan niet zelf benaderd worden

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#traditionele-packetfilters)Traditionele packetfilters

Filterbeslissingen meestal genomen op basis van:

- IP-bronadressen of IP-bestemmingsadressen
- Typeveld in IP-datagram
- TCP- of UDP-bronpoorten en -bestemmingspoorten
- TCP-vlagbits: SYN, ACK,...
- ICMP-berichttype
- Verschillende regels voor datagrammen die netwerk binnenkomen en verlaten
- Verschillende regels voor verschillende routerinterfaces

Organisatie kan filteren op:

- TCP-SYN-segmenten → geen inkomende TCP-verbindingen toestaan behalve voor publieke webserver → alle TCP-SYN-segmenten blokkeren behalve → TCP-SYN-segmenten bestemmingspoort 80 &amp; bestemmings-IP overeenkomt met webserver
- TCP-ack-bit → interne clients verbinden met externe servers → externe clients niet verbinden met interne servers 
    - 2e mogelijkheid → DNS-packets netwerk kunnen binnenkomen &amp; verlaten → blokkeert al het dataverkeer → behalve webdataverkeer binnen organistatie &amp; DNS-dataverkeer

Filterpolicy kan gebaseerd zijn op combinatie van adressen &amp; poortnummers

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#stateful-packetfilters)Stateful packetfilters

Bewaken alle bestaande TCP-verbindingen → firewall kan nieuwe verbinding detecteren → door 3-wayhandshake (SYN, SYNACK &amp; ACK) → + eind verbinding detecteren → FIN-packet → firewall kan ook veronderstellen → verbinding niet meer nodig is → geen activiteit

Packet bereikt firewall

1. Firewall controleert lijst met **toegangsbeheer** ( traditionele packetfilters )
2. Verbindingstabel controleren voor packet in netwerk van organisatie kan komen
3. Controleert verbindingstabel → geen deel van lopende TCP-verbinding → weigert
4. IF webserver stuurt packet terug → firewall controleert tabel → overeenkomstige verbinding → packet passeren

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#application-gateway)Application gateway

Firewalls moeten packetfilters combineren met applicatiegateways → die kijken verder dan headers van IP, TCP &amp; UDP → beslissingen op basis van applicatiegegevens **Applicatiegateway** → applicatiespecifieke server die door alle applicatiegegevens gepasseerd moet worden → verschillende applicatiegateways kunnen op dezelfde host uitgevoerd worden → elke gateway afzonderlijke server met eigen processen

**Stel:**

Firewall → geselecteerde groep interne gebruikers → Telnet-verbindingen met externe netwerken → tegelijk voorkomen → externe clients → Telnet-verbinding maken met interne host

**Stel nu:**

Interne gebruiker wil verbinding tot stand brengen met buitenwereld

1. Gebruiker Telnet-sessie starten met applicatiegateway → op gateway draait applicatie → wacht voor inkomende Telnet-sessies tot stand komen
2. Applicatie vraagt username &amp; password
3. IF informatie = correct → applicatiegateway checkt IF gebruiker = gerechtigd is → als dat het geval is
4. Gateway vraagt gebruiker → hostname externe host ingeven
5. Gateway Telnet-sessie → tussen gateway &amp; externe host
6. Gateway verzendt alle gegevens afkomstig van externe host naar gebruiker &amp; omgekeerd

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#892-intrusion-detectionsystems)8.9.2 Intrusion-detectionsystems

- Intrusiondetectionsysteem **(IDS)**→ waarschuwt wanneer mogelijk schadelijk dataverkeer detecteerd
- Intrusion-preventionsysteem **(IPS)**→ Apparaat dat schadelijk dataverkeer blokkeert

**IDS + IPS = IDS**

Organisatie → meerdere IDS's sensoren implementeren → meestal samenwerkend → sturen verdachte verkeersactiviteit → centrale IDS-processor → verzamelt info → alarmen verzendt naar netwerkbeheerder wanneer nodig

**Pagina 619 afbeelding 3.6**

Organisatie → 2 delen opgesplitst

1. Streng beveiligd deel → afgeschermd door → packetfilter &amp; applicatiegateway → bewaakt door IDS sensoren
2. Minder streng beveiligd deel →**gedemilitariseerde zone (DMZ)**→ alleen beveiligd door packetfilter maar ook bewaakt door sensoren IDS (*is een netwerksegment dat zich tussen het interne en externe netwerk bevindt. Het externe netwerk is meestal het [Internet](http://nl.wikipedia.org/wiki/Internet). Een DMZ is feitelijk een andere naam voor een [extranet](http://nl.wikipedia.org/wiki/Extranet), een gedeelte van het netwerk dat voor de buitenwereld volledig toegankelijk is. Op het netwerksegment van de DMZ zijn meestal [servers](http://nl.wikipedia.org/wiki/Server) aangesloten die diensten verlenen die vanuit het interne en externe netwerk aangevraagd kunnen worden)*

Sensoren voor IDS → verderop in systeem → elke sensor deel van dataverkeer → gemakkelijker taak uitvoeren

**IDS systemen in 2 categorieën**

1. **Systemen die werken met handtekeningen**

- database met aanvalskenmerken (handtekeningen) → elke handtekening → verzameling regels → gebruikt verdachte activiteit → kan lijst met kenmerken 1 packet → vergelijkt packets met handtekening in database → overeenkomst in database → waarschuwing

**Beperkingen:**

1. dit soort IDS → alleen als voorkennis over aanval is → gebruikt nauwkeurige handtekening te vervaardigen → blind als er nieuwe aanvallen zijn
2. packet → zelfs als er bekende handtekening is → niets te maken met een aanval → false-positive warning
3. IDS kan overvoerd geraken → elk packet vergeleken moet worden → uitgebreide verzameling handtekeningen → kan zover komen dat IDS schadelijke packets niet detecteert
4. **Op anomalie gebaseerde systemen**

- Creëert profiel → normale verloop → gecontroleerde dataverkeer → zoekt packetstreams statisctisch ongebruikelijk zijn
- Niet afhankelijk van voorkennis bestaande aanvallen
- Wel moeilijk → efficiënt onderscheid maken → normaal dataverkeer &amp; statistisch ongebruikelijk verkeer

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#snort)Snort

Maakt gebruik van generieke sniffingsinfterface, libpcap

Enorme groep gebruikers &amp; beveiliginsexperts → houden handtekeningdatabase actueel

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#9-multimedianetwerken)9 Multimedianetwerken

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#91-multimedianetwerkapplicaties)9.1 Multimedianetwerkapplicaties

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#911-eigenschappen-van-video)9.1.1 Eigenschappen van video

- **Hoge bit rate** : 100kbps voor low-quality video conferencing → 3 Mbps streaming high-definition movies. → bitsnelheidvereisten van video belangrijk ontwerpen netwerkvideotoepassing
- Een niet-gecomprimeerde, digitaal gecodeerde afbeelding → reeks pixels→ elke pixel gecodeerd in aantal bits om luminantie en kleur weer te geven.
- 2 Types redundantie in video → exploited door video compressie 
    1. **Tijdelijke redundantie** **→** werkt met verschillen tussen opeenvolgende afbeeldingen
    2. **Spatial redundancy** **→** redundantie binnen een bepaalde afbeeling

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#912-eigenschappen-van-audio)9.1.2 Eigenschappen van audio

- Digitale audio → lagere bandbreedte nodig dan video → Pulse Code Modulation (PCM) → coderen spraak → 8000 samples/seconde &amp; 8 bits per sample → bitsnelheid 64 kbps
- Compressietechniek voor stereomuziek → MP3 → bitsnelheid 128 kbps → geluidskwaliteit slechter
- Advanced Audio Coding (AAC) → meerdere versies vooropgenomen audio stream kan gemaakt worden → elke klein verschil bit rate

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#913-soorten-multimedianetwerkapplicaties)9.1.3 Soorten multimedianetwerkapplicaties

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#streamen-van-opgeslagen-audio--video)Streamen van opgeslagen audio / video

Streamen van opgeslagen video 3 belangrijke onderscheidende kenmerken

- Streamen → client begint video → binnen enkele seconden na ontvangst weer te geven → client video weergeeft → bepaalde plaats in opname &amp; tegelijk latere delen van die opname ontvangt van server = **streamen**
- Interactiviteit → media vooraf opgenomen → gebruiker weergave onderbreken, doorspoelen,... → voor aanvaardbare gebruikskwaliteit → tijd tussen moment gebruiker actie start &amp; uitvoering actie → enkele seconden
- Continue weergave → zelfde snelheid weergeegven als orgineel → gegevens op tijd van server ontvangen → voor moment client moet weergeven → anders haperingen
- Gemiddelde doorvooercapaciteit → netwerk streamapplicatie → gemiddelde doorvoorcapaciteit bieden → ten minste even groot als bitsnelheid video

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#voip)VOIP

Timing is belangrijk → spraak- en videoapplicaties → vertragingsgevoelig → meeste multimedianetwerkapplicaties → bestand tegen een zekere mate van gegevensverlies → resulteert in korte onderbrekingen van audio of video

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#streamen-van-live-audio--video)Streamen van live audio &amp; video

Meestal via CDN's → zelfde snelheid weergeegven als orgineel → gegevens op tijd van server ontvangen → voor moment client moet weergeven → anders haperingen → omdat evenement = live → vertraging probleem zijn → timingeisen minder streng dan voor spraakgebrekken

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#92-streamen-van-opgeslagen-video)9.2 Streamen van opgeslagen video

2 belangrijke voordelen bufferen door client

1. Fluctuaties in vertraging tussen server en client opvangen
2. Banbreedte tussen server &amp; client → daalt onder sneheid → waarmee videocontent wordt weergegeven → blijven kijken zolang buffer van clientcomponent niet leegraakt

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#921-streamen-met-udp)9.2.1 Streamen met UDP

Kleine buffer op clientcomponent van applicatie gebruikt → net groot genoeg voor minder dan seconde video → server die video aan UDP-verbinding vertrouwt → stukjes video verpakken in transportpackets speciaal ontworpen voor transporteren audio &amp; video → Realtime Transport Protocol ( RTP )

Server &amp; client → onderhouden verbinding voor videostream → ook afzonderlijke besturingsverbinding die door client wordt gebruikt geven opdrachten

Systeem 3 belangrijke nadelen:

1. Streamen met constante snelheid → voor continue weergave → problemen opleveren als gevolg van onvoorspelbaare &amp; wisselende beschikbare bandbreedte
2. Streamen met UDP → server nodig om media te besturen → interactieve verzoeken tussen client en server afhandelen &amp; toestand client bewaren → voor elke sessie
3. Veel firewalls geconfigureerd om UDP verkeer te blokkeren

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#922-streamen-met-http)9.2.2 Streamen met HTTP

Video in HTTP server → gewoon bestand met specifieke URL → gebruiker wil video zien

1. Client start TCP-verbinding met server
2. Verzendt HTTP-GET-bericht
3. Server verzendt video bestand in HTTP-antwoordbericht
4. Clientcomponent applicatie verzamelt bytes in buffer
5. Zodra # bytes in buffer &amp;gt; bepaalde drempelwaarde
6. Client begint met weergave + videoframes periodiek uit buffer opgehaald &amp; gecomprimeerd

Packets → vertraagd als gevolg opnieuw verzenden packets

Gebruik van HTTP over TCP → firewalls en NAT's gemakkelijker gepasseerd kunnen worden → van het UDP-dataverkeer tegen houden → HTTP-dataverkeer door te laten → streamen HTTP geen mediabesturingsserver nodig (RTSP-server) → kosten lager → meeste videostreamapplicaties werken met HTTP over TCP als streamprotocol

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#prefetchen-van-video)Prefetchen van video

Client probeert video downloaden → snelheid hoger dan weergavesnelheid → voorraad krijgen van videoframes → toekomst worden weergegeven

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#buffers-van-clientcomponent-van-de-applicatie--tcp-buffers)Buffers van clientcomponent van de applicatie &amp; TCP-buffers

Volledige client applicatie buffer → legt indirect limiet op rate → video verstuurd van server naar client wanneer streamen over HTTP

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#analyse-van-clientcomponent-van-applicatie-en-tcp-buffers)Analyse van clientcomponent van applicatie en TCP-buffers

If beschikbare rate &amp;lt; video rate → continue weergave afgewisseld worden → periodes beeld stilstaat → wanneer beschikbare rate in netwerk &amp;gt; video rate → na initiele buffering vertraging → continous playout tot einde video

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#vroegtijdige-be%C3%ABindiging-van-weergave--verplaatsen-van-weergavetijdstip)Vroegtijdige beëindiging van weergave &amp; verplaatsen van weergavetijdstip

HTTP-byterange-headerveld in HTTP-get-verzoekbericht → bevat informatie → bereik in bytes van gewenste video → client wil ontvangen → If gebruik springt naar ander tijdstip in video → client verzendt nieuw HTTP-verzoekbericht → in byterangeheaderveld van bericht → clientapplicatie specifieert vanaf welke byte in bestand → gegevens wil ontvangen → server nieuw HTTP-verzoek ontvangt → alle eerdere verzoeken weg &amp; bytes verzenden

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#923-dynamic-adaptive-streaming-over-http-dash)9.2.3 Dynamic Adaptive Streaming over HTTP (DASH)

Gebruikt meerdere versies → zelfde video → elk een bepaalde snelheid waarmee gestreamd wordt → gecomprimeerd → CDN's vaak gebruikt distribueren opgeslagen &amp; live video

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#93-voice-over-ip-voip)9.3 Voice-over-IP (VoIP)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#931-beperkingen-van-best-effortdienst-van-ip)9.3.1 Beperkingen van best-effortdienst van IP

IP → zo snel mogelijk van bron naar bestemming → geen beloften → vertraging of packet loss → belangrijke consequenties → ontwerp realtime spraakapplicaties → gevoelig voor packetvertraging, jitter &amp; verlies

1. Verzender genereert bytes met snelheid → 8000 bytes/seconde → iedere 20 ms verzamelt bytes in stuk → **chunk**
2. Chunk + speciale header → verpakt in UDP-segment → elke 20 ms UDP-segment verzonden

Als packet ontvanger bereikt → constante end-to-endvertraging → packets 20 ms na elke spraakactie van andere partij arriveren → ideale situatie → ontvanger elke chunk direct bij aankomst weergeven → sommige packets kwijt + niet zelfde end-to-endvertraging

Ontvanger moet

1. Bepalen wanneer chunk moet weergegeven worden
2. Bepalen wat er moet gebeuren als chunk ontbreekt

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#packetverlies)Packetverlies

Verlies zou voorkomen → packets over TCP versturen → mechanismen opnieuw verzenden packets → niet geschikt voor VoIP → vergroten end-to-endvertraging

Packetloss tussen 1% en 20% is acceptabel → afhankelijk hoe spraakgegevens gecodeerd &amp; verzonden zijn → manier hoe ontvanger verlies maskeert → Forward Error Correction (FEC) → hulpvol zijn packetverlies maskeren

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#end-to-endvertraging)End-to-endvertraging

Totaal van

- Transmission delay
- Processing delay
- Queing delays routers
- Propagation delays in verbindingen
- Processing delays hosts

Ontvanger bij VoIP-applicatie → packets negeren die vertraging groter dan bepaalde drempelwaarde

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#packetjitter)Packetjitter

Variatie in queuing delays → packet in netwerkrouters ondervindt = cruciaal → deze vertragingen variëren → dus ook verstreken tijd tussen moment → verzenden packet &amp; ontvangen packet → fenomeen = **jitter** → compenseren aan de hand van **volgnummers** , **tijdstempels** &amp; **weergavevertraging**

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#932-jitter-voor-audio-compenseren-bij-ontvanger)9.3.2 Jitter voor audio compenseren bij ontvanger

Gedaan door 2 mechanismes combineren

1. Elke chunk vooral laten gaan door tijdstempel → verzender voegt aan elk nieuw gegenereerd packet → informatie over tijdstip → packet werd gegenereerd
2. Weergave chunks → bij ontvanger vertragen → weergave ontvangen chunks → vertraagd worden → zodat grootste deel packets ontvangen is voor weergeven

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#1-onveranderlijke-weergavevertraging)1) Onveranderlijke weergavevertraging

Ontvanger kan weergavevertragingen variëren

Chunk tijdstempel bij afzender op tijdstip t → ontvanger speelt chunk (q) af op tijdstip t + q → assuming chunk tegen die tijd gearriveerd → packets na hun geplande speeltijd arriveren → weggegooid

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#2-variabele-weergavevertraging)2) Variabele weergavevertraging

Door initiële weergavevertraging groot te maken → meestg packets op tijd aankomen → verloren packets = klein →weergavevertraging variëren aan begin elke spraaksessie → stiltes voorafgaand aan spraaksessie → verkort of verlengd → niet hoorbaar wanneer verleningen / verkortingen stiltes niet te groot zijn

- Schatting van de pakketvertraging ( di ) = schatting gemiddelde netwerkvertraging moment i-de packet arriveert bij ontvanger
- ## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#schatting-gemiddelde-afwijking-van-vertraging--vi---geschatte-gemiddelde-afwijking-vertraging-ten-opzichte-van-de-geschatte-gemiddelde-vertraging--di-gemiddelde-werkelijke-netwerkvertragingen-rarr-r1---t1ri-ti)Schatting gemiddelde afwijking van vertraging ( vi ) = geschatte gemiddelde afwijking vertraging ten opzichte van de geschatte gemiddelde vertraging → di gemiddelde werkelijke netwerkvertragingen $rarr; r1 - t1,...,ri-ti
- Schattingen di &amp; vi berekend elk ontvangen pakket → als packet i → 1e packet in spraaksessie → weergavemoment pi berekend $rarr; pi = ti + di + Kvi
- Term Kvi → weergavemoment zover in toekomst verschoven → klein gedeelte packets te laat arriveren in spraaksessie
- Stel dat qi = tj + qi → tijd tussen moment 1e packet in spraaksessie genegeerd &amp; moment packet weergegeven → als packet j ook hoor bij spraaksessie → wergegeven op tijdstip → pj = tj + qi

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#933-compenseren-van-packetverlies)9.3.3 Compenseren van packetverlies

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#forward-error-correction--fec-)Forward Error Correction ( FEC )

**Mechanisme 1:**

Verzendt redundant gecodeerde 'chunk' na elke n chunks → geconstrueerd door exclusieve OR-bewerking uit te voeren op n oorspronkelijke chunk.

Als willekeurig packet van groep n+1 kwijtgeraakt → ontvanger verloren packet reconstrueren → meer dan 2 niet mogelijk → verhoogt overdrachtssnelheid &amp; weergavevertraging

**Mechanisme 2:**

Versturen van lagere resolutie audio stream → verzender genereert n-de packet door n-de chunk van nominale stream achter (n-1) de chunk van redundante stream te plaatsen → wanneer meerdere niet opeenvolgende packets kwijtraken → ontvanger verlies compenseren door chunk met lage bitsnelheid → volgende packet "meelift" geven → lagere geluidskwaliteit

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#interleaving)Interleaving

Verzender verstuurt eenheden audiogegevens in andere volgorde → oorspronkelijk aangrenzende eenheden in verzonden stream gescheiden zijn door afstand → effect packetverlies verkleinen → if packetloss → meeste van elke orginele chunk → geen redundantie overhead → verhoogt playout delay → voordeel → benodigde bandbreedte voor een stream niet vergroot

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#maskeren-van-fouten)Maskeren van fouten

Herhalen van packets → ontvanger vervangt kwijtgeraakte packets door kopieën

Interpolatie → kwijtgeraakte packet berekend p basis van voorgaande &amp; volgende packet in stream

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#934-casus-voip-met-skype)9.3.4 Casus: VoIP met Skype

- Skype werkt met hiërarchisch overlaynetwerk
- Peer kan "superpeer" of gewone peer zijn
- Werkt met index → koppelt IP-adressen aan gebruikers
- Index gedistribueerd over superpeers
- Alice belt Bob → Skype client zoekt distribueerde index → Bob's IP adres bepalen

Meeste thuisnetwerken → NAT netwerken → NAT voorkomt host buiten thuisnetwerk verbinding met host binnen thuisnetwerk → beide Skype-bellers NAT → probleem

Super peers lossen probleem op

1. Alice logt in → superpeer buiten netwerk toegewesen → Alice &amp; superpeer besturingsberichten uitwisselen → idem voor Bob
2. Alice belt Bob → informeert Alice superpeer → superpeer Bob informeert → brengt Bob op hoogte → inkomende oproep Alice
3. Bob accepteert → 2 superpeers kiezen 3e superpeer zonder NAT → gegevens Alice en Bob uitwisselen aan elkaar koppelen

Conference calls → elke gebruiker verzendt audiostream naar deelnemer die gesprek start → deelnemer combineert audiostreams tot 1 enkele stroom → verzendt kopie van elk gecomineerde stream → elk van andere N-1 deelnemers → video elke deelnemer → gestuurd in servercluster

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#94-protocollen-voor-realtime-spraakapplicaties)9.4 Protocollen voor realtime spraakapplicaties

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#941-rtp)9.4.1 RTP

Gebruikt PCM,MP3,... te transporteren

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#basisprincipes-van-rtp)Basisprincipes van RTP

RTP boven op UDP

1. Verzendende component verpakt chunk media-gegevens in RTP-packet
2. Verpakt packet in UDP-segment → naar IP
3. Ontvangende haalt RTP-packet uit UDP-segment
4. Chunk → mediaplayer → decodeert &amp; weergeven
5. Verzendende omponent voegt voor elke chunk audiogegevens → RTP-header toe

- Type van audiocodering
- Volgnummer
- Tijdstempel

6. RTP packet → in UDP socket interface
7. Ontvanger → applicatie ontvangt RTP van socket interface
8. Applicatie filtert audiogegevens &amp; headervelden van RTP packet → gegevens decoderen &amp; afspelen

RTP geen mechanismen → tijdige bezorging van gegevens of kwaliteit diensten → geen garantie of packets aankomen of juiste volgorde

RTP → elke bron → eigen onafhankelijke RTP-packetstream → routers geen onderscheid tussen IP-datagrammen met RTP-packets &amp; zonder RTP-packets

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#headervelden-van-rtp-packet)Headervelden van RTP-packet

- Volgnummerveld (16 bits) → verhoogt met 1 voor elk verstuurde RTP-packet → gebruikt door ontvanger om packet loss &amp; volgorde van packets herstellen
- Tijdstempelveld (32 bits) → ontvanger tijdstempels → packetjitter compenseren &amp; packets met zelfde snelheid weergeven als waarin verzonden → als applicaties 160 gecodeerde samples maakt → tijdstempelveld verhoogt met 160 voor elk RTP-packet wanneer bron actief → tijdstempelveld klok loopt met constante snelheid → zelfs if bron = inactief
- Bronidentificatieveld / ( **Synchronization Source Identifier** of **SSRC** (32 bits) → identificeerd bron van RTP stream → elke RTP sessie heeft unieke bronidentificatie

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#942-sip)9.4.2 SIP

- Levert mechanismen → gesprekken over IP-netwerk → beller kan diegene die gebeld wordt waarschuwen → gesprek wil → beide partijen afspraken maken over codering van media → beide deelnemers ook gesprek beëindigen
- Mechanismen → beller huidige IP-adres bepalen van gebelde → gebruikers geen vast IP → dynamisch toegewezen → verschillende IP-apparaten
- Mechanismen → beheren gesprekken → bv. Toevoegen nieuwe mediastreams, doorschakelen van gesprekken, ...

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#gesprek-tot-stand-brengen-met-bekend-ip-adres)Gesprek tot stand brengen met bekend IP-adres

1. Alice stuurt Bob → SIP INVITE bericht → over UDP naar poort 5060 voor SIP → geeft poort aan
2. INVITE-bericht identificatie voor Bob + indicatie huidig IP van Alice &amp; preferred codering
3. Bob antwoord met 200 OK bericht → poort weer, IP &amp; preferred codering
4. Na ontvangen Bob antwoord → SIP ontvangst bericht → erna praten

SIP kan over TCP of UDP verstuurd worden → default port 5060 → SIP berichten verstuurd en ontvangen in sockets → andere dan voor media data

SIP berichten → ASCII leesbaar → lijken op HTTP-ber

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#sip-berichten)SIP-berichten

Kijk pagina 663. Voor voorbeeld

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#vertalen-van-namen-en-het-traceren-van-een-gebruiker)Vertalen van namen en het traceren van een gebruiker

Alice kent alleen e-mailadres Bob → dit adres ook voor SIP-gesprekken

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#hoe-kent-proxyserver-het-huidige-ip-adres-van-bobdomaincom)Hoe kent proxyserver het huidige IP-adres van <bob@domain.com>

Elke SIP-gebruiker → registrar gekoppeld

1. Gebruiker start SIP-applicatie
2. Applicatie verzendt SIP-registerbericht naar registrar → informatie huidig IP gebruiker
3. Registrar Bob → bijhouden huidig IP-adres Bob → ander SIP-apparaat → nieuw registerbericht met nieuw IP

Gebruik langere tijd → register blijft registerberichten sturen → registrar overeenkomsten met DNS-name-server → vertaalt vaste hostnamen naar vaste IP → SIP-registrar vaste menselijke identificatiegegevens → dynamische IP-adressen → SIP-registrars &amp; proxy's op zelfde host

####  

####  

####  

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#hoe-kan-sip-proxy-huidige-ip-adres-van-bob-achterhalen)Hoe kan SIP proxy huidige IP-adres van Bob achterhalen

1. Alice verstuurt INVITE-bericht → SIP-proxy Bob
2. Proxy stuurt bericht naar SIP-apparaat van Bob
3. Bob ontvangt Alice INVITE-bericht → kan antwoord sturen naar Alice

#### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#jimumassedu-2171235689-wil-voip-starten-met-keithupennedu-197875421)<Jim@umass.edu> (217.123.56.89) wil VoIP starten met <Keith@upenn.edu> (197.87.54.21)

1. Jim verzendt INVITE-bericht naar SIP-proxy van umass
2. Proxy → DNS-lookup voor SIP-registrar upenn.edu → verzendt bericht naar registrarserver
3. Keith.upenn.edu → niet bekend bij registrar upenn → registrar omleidingsantwoordbericht → melding → umass keith.nyu.edu moet proberen
4. Proxy umass → INVITE-bericht → SIP-registrar van NYU
5. Registrar NYU → kent IP van <keith@upenn.edu>→ stuurt INVITE-bericht door naar host 197.87.54.21 → SIP-client van Keith uitvoert.
6. Verzendt SIP-antwoordbericht → registrars/proxy's → terug naar SIP-client → 217.123.56.89
7. Idem 6
8. Idem 6
9. Media → rechtstreeks tussen 2 clients verzonden → ook ACK

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#95-netwerkondersteuning-voor-multimedia)9.5 Netwerkondersteuning voor multimedia

- **Beste maken van de best-effortdienst** → toenames van vraag voorspeld → ISP's extra bandbreedte &amp; switches in → acceptabele mate vertraging &amp; packetloss te garanderen
- **Diensten in verschillende categorieën aanbieden** **→** 1 type van verkeer → kan hogere prioriteit krijgen dan een ander type
- **Per verbinding andere QoS-garanties geven** → per verbiending QoS garantie → elke instantie van applicatie → bandbreedte reserveren → garanties end-to-endperformance → **harde garantie** → applicatie zeker de gevraagde QoS zal ontvangen → **Zachte garantie** → grote waarschijnlijkheid de gevraagde QoS zal ontvangen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#951-best-effortnetwerken-dimensioneren)9.5.1 Best-effortnetwerken dimensioneren

Eerste manier kwaliteit multimedia-applicaties te verbeteren →

**Meer geld uitgeven**

Bij multimedia in netwerken → voorkomen tekort aan recources → als linkcapaciteit → groot genoeg → packets door huidige internet getransporteerd → zonder queuing delays of kans op vermissing

Vraag is → hoeveel capaciteit nodig? → kosten leveren benodigde bandbreedte → reële zakelijke optie is voor ISP's → hoe groot capaciteit netwerklinks → bepaalde topologie → bepaalde end-to-endperformance te leveren = **netwerkdimensioneringsprobleem**

**Volgende problemen moeten opgelost worden om performance van applicatielaag tussen 2 eindpunten in netwerk te kunnen voorspellen**

1. Modellen van het benodigde dataverkeer tussen eindpunten in het netwerk

- Mogelijk modellen gedefinieerd worden op gespreksniveau

2. Goed gedefinieerde performance-eisen

- Performance eis stellen dat gevoelig is voor vertraging → kans end-to-endvertraging van packets groter is dan max te tolereren vertraging

3. Modellen om end-to-endperformance bij een bepaald netwerkbelastingsmodel te voorspellen en technieken om zo gering mogelijke kosten zodanig bandbreete toe te wijzen dat aan alle eisen van de grebruikers wordt voldaan

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#952-verschillende-soorten-diensten-verlenen)9.5.2 Verschillende soorten diensten verlenen

Eenvoudigste uitbreiding → dataverkeer voor unitaire &amp; egalitaire best-effortdienst → huidige internet opsplitsen in categorieën → bij dienstverlening aan verschillende categorieën → verschillende niveaus

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#een-paar-scenarios)Een paar scenarios

Principe 1: **Packet markering** → markeren van packets → router packets die horen bij verschillende dataverkeercategorieën van elkaar onderscheiden → originele doel (ToS) veld in IPv4

Principe 2: **Isolatie dataverkeer** **→** zekere mate van isolatie tussen categorieën implementeren → ene klasse niet nadelig beïnvloed kan worden → als iets mis is met andere categorie

2 aanpakken mogelijk:

1. **Dataverkeerpolicy** → als dataverkeercategorie moet voldoen aan bepaalde criteria → controlemechanisme → zorgen policy nageleefd → als applicatie niet aan criteria houdt → mechanisme handelend optreden → dataverkeer netwerk binnenkomt voldoet aan criteria
2. **Packetschedulingmechanisme op datalinklaag** → expliciet een constante hoeveelheid van linkbandbreedte te laten reserveren → elke categorie

Principe 3: Belangrijk categorieën van elkaar scheiden → wenselijk recources → efficiënt mogelijk te benutten → manier packets in wachtrij voor verzending over link worden geselecteerd = **link-schedulingmethode**

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#leaky-bucket)Leaky bucket

Policing = belangrijk QoS-mechanisme

3 policycriteria:

1. **Gemiddelde snelheid:** Netwerk kan gemiddelde snelheid van packets van stream langere tijd beperken → cruciale factor → tijdsduur waarover de gemiddelde snelheid zal worden geregeld → bron begrensd 100 packets per seconde → sneller afgeremd dan bron 6000 packets/min → zelfs beide bronnen → zelfde gemiddelde snelheid
2. **Maximale snelheid:** beperking van gemiddelde snelheid → begrenst hoeveelheid dataverkeer → in netwerk gezonden kan worden → relatief lange periode **→** beperking van maximale snelheid → begrenst # packets verzonden in korte periode
3. **Burstgrootte** → Netwerk kan ook max # packets → begrenzen → dat gedurende extreem korte periode via netwerk wordt verzonden

Buckets bestaan uit → bucket dat max b tokens bevat

1. Nieuwe tokens → in bucket → snelheid van r tokens per seconde genereerd
2. IF bucket &amp;lt; b tokens → token direct in bucket
3. Else → token genegeerd → bucket blijft gevuld met b tokens

**Stel packet voor het verzonden wordt** **→** **token uit bucket halen**

Omdat maximaal b tokens in bucket zitten → maximale burstgrootte voor een met leaky bucket begrense stream gelijk aan b packets

Tokens genereerd met snelheid r → maximale aantal packets → netwerk kan binnenkomen in willekeurige periode met lengte t → rt + b → snelheid r waarmee tokens genereerd worden → maat om gemiddelde snelheid → packets netwerk kunnen binnenkomen op lange termijn → begrenzen

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#953-diffserv)9.5.3 Diffserv

Diffserv → differentiatie in dienstverlening → mogelijkheid verschillende categorieën dataverkeer → internet schaalbare manier

2 functionele elementen

1. **Functies aan de edge:** → classificeren en coditioneren van dataverkeer → ingaande edge netwerk ( bij Diffserv-host die dataverkeer genereert of eerste Diffserv-router waarlangs dataverkeer passeert) → arriverende packets gemarkeerd
2. **Functies in de core** **→** doorverzenden → wanneer Diffserv gemarkeerd packet → arriveert Diffserv router → doorverzonden naar volgende hop → volgens 'per-hop' voorschrift → geldt voor betreffende categorie packets → 'per-hop' voorschrift uitsluitend gebaseerd op markering van packet ( Diffserv-model)

Packets die bij edgerouter aankomen → gaclassificeerd &amp; gemarkeerd (AFBEELDING p.679)

1. Classificeerder selecteert packets → basis 1 of meer waarden in headervelden
2. Verzendt packet naar betreffende markeerfunctie

Sommige gevallen host afgesproken → packetverzendsnelheid → sturen → voldoet aan bepaald **dataverkeerprofiel** → kan limiet op maximale overdrachtsnelheid bevatten of maximale # packets verzonden in korte tijd

Zolang gebruiker packets verzendt → voldoen aan overeengekomen waarden in dataverkeerprofiel → packets voorkeursbehandeling → wanneer verzender niet houdt aan dataverkeerprofiel, packets buiten overeenkomst vallen → andere markering of vertraagd worden of zelfs genegeerd worden aan edge netwerk

**Meetfunctie** → ingaande stream vergelijken met overeengekomen dataverkeerprofiel → bepalen packet binnen dat profiel past → eigenlijke beslissing over packets → netwerkbeheerder

In per-hop gedrag belangrijke overwegingen

- 'per-hop' voorschrift → zorgen verschillende categorieën dataverkeer → verschillende diensten
- Per-hop voorschrift verschilt → behandeling tussen categorieën definieert → geen expliciete informatie hoe voorschrift uitvoeren
- Verschillen in performance moeten dus zichtbaar &amp; meetbaar zijn

**2 'per-hop' voorschriften gedefinieerd**

1. **Expedited forwarding** → 'per-hop' voorschrift → vertreksnelheid van categorie → bij router = &amp;gt; dan geconfigureerde snelheid
2. **Assured forwarding** → 'per-hop' voorschrift → verkeer in 4 categorieën → elke AF-categorie gegarandeerd → bepaalde minimale hoeveelheid bandbreedte &amp; buffers

**End-to-end-Diffserv-dienst** leverren → alle ISP's tussene eind systemen → service leveren &amp; samenwerken &amp; afspraken maken → klant → gedifferentieerde end-to-end dienst te bieden

##  

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#954-per-verbinding-qos-garanties-geven-recources-reserveren--streams-toelaten)9.5.4 Per verbinding Qos-garanties geven: recources reserveren &amp; streams toelaten

Principe 4: Nood aan nieuwe netwerk mechanics en protocollen → duidelijk wanneer stream gegearandeerde service moet ontvangen zodra gestart is

1. **Recources reserveren** → enige manier garanderen → stream beschikken over benodigde recources → recources gereserveerd → stream naar behoefte benutten → gedurende gereserveerde tijd ongeacht behoeften andere streams
2. **Streams toelaten** → recources gereserveerd → netwerk mechanisme hebben → streams verzoeken kunnen richten → recources niet oneindig → verzoek stream afgewezen → als gevraagde recources niet beschikbaar zijn
3. **Signaleren set-up streams** **→** toelatingsproces → stream die QoS nodig heeft → voldoende recources reserveren → elke netwerkrouter tussen bron &amp; bestemming → zeker zijn end-to-end-QoS-eisen hebben → elke router → lokale recources voor nieuwe stream nodig zijn berekenen → bekijken hoeveel beschikbare recources in gebruik zijn → opgestarte streams → of bepalen beschikbare per hop → toereikend QoS-eisen → honoreren Signaliseringsprotocol nodig activiteiten coördineren = **call-setupprotocol** **→** **RSVP-protocol** → voorgesteld voor dit doel binnen internetarchitectuur (PAGINA 683 AFBEELDING)

## [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#active-vs-passive-ftp)Active vs Passive FTP

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#active-ftp)Active FTP

1. Client contacteert server op command poort
2. Server stuurt ACK terug naar client's commandpoort
3. Server initieert connectie op lokale datapoort → naar datapoort client eerder aanduidde
4. Client stuurt ACK terug

###  

### [<svg aria-hidden="true" class="octicon octicon-link" height="16" version="1.1" viewbox="0 0 16 16" width="16"></svg>](https://github.com/martijnmeeldijk/TI-oplossingen/blob/master/Semester_2/Computernetwerken%202/Samenvatting/CN2.md#passive-ftp)Passive FTP

1. Client contacteert server op command poort
2. Server antwoord met poort 2024 → server verteld welke poort luisterd voor data connectie
3. Client initieert data connectie van zijn datapoort → gespecifieerde data poort
4. Server stuurt ACK terug naar client's datapoort

Active → SYN door client Passive → SYN door client

# 2020 juni examen

## <span class="mw-headline" id="bkmrk-%28corona%29---p.-geens-0">(Corona) - P. Geens</span>

### <span class="mw-headline" id="bkmrk-theorie-0">Theorie</span>

+- 24 multiple chose vragen

### <span class="mw-headline" id="bkmrk-praktijk-0">Praktijk</span>

Bij elke vraag moest je deze vorm van input meegeven: "oneliner - outputhash md5sum" ('| mdsum' toevoegen aan je oneliner geeft je de hash terug van je output)

- Vraag 1: Voorbeeldvraag (was gegeven en kon je geen punten mee verdienen)

```
ls -ld /etc
```

<div id="bkmrk-"></div>- Vraag 2: Create a linux CLI oneliner to extract the logged in user's username in the file Cnw2\_ftp.pcap (use tshark) (dit commando is eigenlijk voor meerdere users...)

```
tshark -r /home/logs/Cnw2_ftp.pcap -Y 'ftp.request.command==USER' -T fields -e 'ftp.request.arg' | sort | head -1
```

<div id="bkmrk--0"></div>- Vraag 3: Create a linux CLI oneliner to get the following output of wiki.uclllabs.be (use openssl)

```
echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -noout -text
```

<div id="bkmrk--1"></div>- Vraag 4: Create oneliner to decode string in the secret located at /home/logs (use openssl)

```
cat /home/logs/secret | openssl enc -a -d
```

# 2020 juni examen - versie 2

# Examen Juni 2020

**Dit examen was tijdens de corona periode. Labo en theorie waren dus samen gevoegd.**

**Voor theorie:** zie het bestande [THEORIE.md](/attachments/47)

Dank aan: Pablopicasso en [ISW](https://iswleuven.be/)

*cn2\_examen\_juni2020.zip* is gewoon een kopie van de Toledo website op dat moment,

## Labo

#### Instructies

Het examen is gesloten boek, je mag enkel gebruik maken van onderstaande hulpmiddelen:

- pcre handleiding + Linux comand line cheat sheet. Zie dat je een lokale kopie hebt op je laptop (of op papier) voor aanvang van het examen, tijdens het examen is toegang tot de wiki verboden.
- ssh sessie naar server leia.uclllabs.be.

Antwoorden bestaan steeds uit een enkele ‘oneliner’, net zoals in de geziene labo’s en het voorbeeldexamen. Je mag commando’s aan elkaar lijmen met unnamed pipes ( | symbool), maar &amp;&amp;, || en ; mogen enkel gebruikt worden wanneer dit echt noodzakelijk is (bijvoorbeeld voor de syntax van een for-loop).

**Let op:** Bij sommige opdrachten staat er vermeld welke commando's je (niet) mag gebruiken.  
  
Veel succes!

#### Vraag 1 (voorbeeld): 0 punten

Dit is een voorbeeld vraag, inclusief het correcte antwoord. Bekijk ze goed, zodat je weet wat er exact verwacht wordt.

Maak een CLI oneliner die de directory permissies, eigenaar, groep,... (via ls -l) oplijst van de /etc directory zelf (niet van de inhoud) op server leia.

Daarna pipe je de output van je CLI oneliner in het commando md5sum. In het antwoordveld vul je beide in op deze manier:

```
ONELINER - md5 hash

```

##### **Oplossing:**

```
# Met deze onliner kan je de permissies,... opvragen van de /etc directory zelf:
ls -ld /etc
# En zo pipe je de output van deze oneliner in md5sum:
ls -ld /etc | md5sum

# En dit vul je in in het antwoordveld:
ls  -ld /etc - 69ede2180c67f4a59fea0206e031101f

```

#### Vraag 2: 10 punten

Het bestand Cnw2\_ftp.pcap bevat een opgenomen FTP sessie. Je kan dit bestand vinden in /home/logs op server leia.

Maak een CLI oneliner met tshark die de gebruikersnaam toont van de gebruiker die succesvol inlogde. Enkel de gebruikersnaam mag getoond worden. Dus geen witregels, geen errors, geen andere tekst.  
In je oneliner mag je enkel gebruik maken van het commando tshark. Geen enkel ander commando is toegestaan. Je mag wel gebruik maken van Wireshark als hulpmiddel om de juiste display filter ('s) te vinden.

##### Oplossing

```
tshark -r /home/logs/Cnw2_ftp.pcap -Y "ftp.request.command==USER && tcp.srcport==$(tshark -r /home/logs/Cnw2_ftp.pcap -Y "ftp.response.code==230" -T fields -e tcp.dstport)" -T fields -e ftp.request.arg

# Deze kan ook maar is waarschijnlijk niet altijd juist
tshark -r /home/logs/Cnw2_ftp.pcap -Y 'ftp.request.command==USER' -T fields -e 'ftp.request.arg' | sort | head -1 

```

#### Vraag 3: 10 punten

Maak een CLI oneliner met openssl die het certificaat van de server *wiki.uclllabs.be* als tekst laat zien. Enkel dit mag getoond worden. Sample output:

```
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            0d:81:12:b8:1c:24:0c:f3:0d:46:af:cd:9a:9b:96:d2
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: C = NL, ST = Noord-Holland, L = Amsterdam, O = TERENA, CN = TERENA SSL CA 3
        Validity
            Not Before: Jan 22 00:00:00 2020 GMT
            Not After : Jan 26 12:00:00 2022 GMT
        Subject: C = BE, L = Leuven, O = UC Leuven, CN = *.uclllabs.be
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (384 bit)
                pub:
                    04:f5:46:f9:2c:94:f0:86:bd:6f:59:32:7c:4d:82:
                    06:da:d7:87:38:cb:74:98:6d:66:c0:4c:ca:f4:9e:
                    1f:5a:22:25:43:11:07:d4:86:1d:68:92:82:d3:eb:
                    4a:a5:bd:fb:4a:46:84:86:ed:40:be:92:7d:f1:f2:
                    56:3b:2b:9f:eb:84:33:59:0d:62:ef:8d:68:ac:4d:
                    d2:76:84:8c:69:93:47:cc:09:a2:2d:19:9d:ba:c6:
                    e7:e8:03:01:7d:df:44
                ASN1 OID: secp384r1
                NIST CURVE: P-384
        X509v3 extensions:
            X509v3 Authority Key Identifier: 
                keyid:67:FD:88:20:14:27:98:C7:09:D2:25:19:BB:E9:51:11:63:75:50:62

            X509v3 Subject Key Identifier: 
                1B:19:0F:9E:AE:E4:39:61:82:08:79:0C:06:42:75:4A:EE:86:BF:6C
            X509v3 Subject Alternative Name: 
                DNS:*.uclllabs.be, DNS:uclllabs.be
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 CRL Distribution Points: 

                Full Name:
                  URI:http://crl3.digicert.com/TERENASSLCA3.crl

                Full Name:
                  URI:http://crl4.digicert.com/TERENASSLCA3.crl

            X509v3 Certificate Policies: 
                Policy: 2.16.840.1.114412.1.1
                  CPS: https://www.digicert.com/CPS
                Policy: 2.23.140.1.2.2

            Authority Information Access: 
                OCSP - URI:http://ocsp.digicert.com
                CA Issuers - URI:http://cacerts.digicert.com/TERENASSLCA3.crt

            X509v3 Basic Constraints: critical
                CA:FALSE
            CT Precertificate SCTs: 
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : A4:B9:09:90:B4:18:58:14:87:BB:13:A2:CC:67:70:0A:
                                3C:35:98:04:F9:1B:DF:B8:E3:77:CD:0E:C8:0D:DC:10
                    Timestamp : Jan 22 11:03:02.541 2020 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:44:02:20:5B:C2:BD:AA:16:4F:D8:18:42:10:D7:48:
                                9D:37:37:0B:4D:D6:65:65:F1:BF:08:A4:8D:B4:81:31:
                                02:BF:15:06:02:20:0D:DB:02:07:86:E1:2B:C0:24:04:
                                BE:42:FC:13:5E:77:D5:BF:E9:4B:53:0D:F1:6D:5E:78:
                                51:0A:3F:E4:26:31
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : 87:75:BF:E7:59:7C:F8:8C:43:99:5F:BD:F3:6E:FF:56:
                                8D:47:56:36:FF:4A:B5:60:C1:B4:EA:FF:5E:A0:83:0F
                    Timestamp : Jan 22 11:03:02.760 2020 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:46:02:21:00:FF:25:60:84:19:69:76:91:D6:8E:C5:
                                54:ED:7C:D4:40:9F:9B:14:99:2F:22:89:F0:0A:3F:9E:
                                3F:15:98:A3:66:02:21:00:92:05:A1:8D:F3:06:A8:DD:
                                92:E2:86:83:54:C1:BC:F9:5F:03:2E:62:F9:DA:5A:17:
                                2D:F8:D1:E6:5B:A2:78:6A
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : EE:4B:BD:B7:75:CE:60:BA:E1:42:69:1F:AB:E1:9E:66:
                                A3:0F:7E:5F:B0:72:D8:83:00:C4:7B:89:7A:A8:FD:CB
                    Timestamp : Jan 22 11:03:02.616 2020 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:44:02:20:7E:42:D6:3A:55:8B:7B:5A:1E:E0:05:48:
                                09:80:89:E5:A5:7A:FD:8C:5F:EE:AB:2E:7E:D1:07:A0:
                                C2:B4:63:EA:02:20:3A:12:1E:14:28:50:F7:8D:C3:73:
                                EA:9E:6C:AB:5D:B4:A8:AE:27:4C:D1:40:18:23:80:1E:
                                F3:87:B8:A8:98:71
    Signature Algorithm: sha256WithRSAEncryption
         7b:8b:b1:71:c4:73:c9:1f:30:d9:74:ea:b0:e9:a3:a7:a0:7b:
         23:a3:24:cf:e4:c4:f3:8f:82:47:15:4a:e7:4a:05:da:57:0a:
         89:db:90:50:62:0f:a8:95:47:5a:22:eb:5b:2f:a3:fd:31:d0:
         b5:b1:86:02:a1:91:87:65:42:70:ea:fc:49:79:ea:2c:13:fb:
         b0:4e:a5:15:ab:80:82:9d:c9:82:e9:da:9e:bb:81:8a:f0:65:
         eb:ef:73:1c:e4:e2:69:ce:06:fc:38:92:fc:7a:06:72:ae:c7:
         7e:37:37:21:b9:71:52:93:ed:18:b4:5d:91:9c:95:48:62:d6:
         ed:ab:3a:db:1d:22:ed:01:de:7d:56:58:f3:0a:7a:49:4c:cb:
         8b:73:b9:5f:83:f8:c4:b3:1a:ec:54:52:b9:83:ae:db:f7:0b:
         b2:cb:76:d0:99:19:e9:26:f9:c2:12:5d:ec:ea:0b:e3:f4:28:
         8a:da:c2:f5:b3:76:a4:03:c7:02:da:d0:44:a8:7a:6b:19:a0:
         99:99:f4:e8:e9:6b:ab:2e:ce:c8:5f:31:bb:e9:bb:52:35:61:
         ed:5a:22:fa:1c:ed:d0:4c:fe:83:8d:78:8a:43:79:fa:a3:38:
         5b:c2:f0:6e:b5:13:8e:28:fc:c7:f4:2c:a1:fe:79:b4:5a:68:
         fa:41:d5:a3

```

##### Oplossing

```
echo | openssl s_client -connect wiki.uclllabs.be:443 2>/dev/null | openssl x509 -noout -text

```

#### Vraag 4: 10 punten

Met welke CLI oneliner kan je volgende string decoderen?

```
RGUgcHVudGVuIG9wIGRlemUgdnJhYWcgemlqbiBhbCBiaW5uZW4uCg==

```

Je kan deze string ook terugvinden in het bestand /home/logs/secret op server leia. Je mag enkel gebruik maken van het commando openssl. Geen andere commando's zijn toegestaan.

##### Oplossing

```
openssl base64 -d -in /home/logs/secret
# Of een andere oplossing:
cat /home/logs/secret | openssl base64 -d
# Of een andere oplossing:
echo "RGUgcHVudGVuIG9wIGRlemUgdnJhYWcgemlqbiBhbCBiaW5uZW4uCg==" | openssl base64 -d

```

Dit is ook mogelijk maar is volgende de vraag fout, je **moet** *openssl* gebruiken.

```
cat /home/logs/secret | base64 -d
# Of
base64 -d /home/logs/secret

```

### Examenbestanden: 

# 2021 juni examen

Met dank aan [ISW](https://iswleuven.be/)

# Praktijk test 21-05-2021

Let op, er waren twee testen en dus ook meerdere vragen.

```
###             Vraag 2      

1. Maak een CLI oneliner waarmee je alle woorden die uit exact 14 unieke letters bestaan toont. Sorteer het lijstje in omgekeerd alfabetische volgorde. Gebruik hiervoor het bestand /usr/share/dict/dutch.

   Daarna pipe je de output van je CLI oneliner in het commando md5sum. In het antwoordveld vul je beide in op deze manier:
   oneliner - md5 hash

```

```
2 punten  

###             Vraag 3      

1. Maak een CLI oneliner die uit de capture http.pcapng (/home/logs op leia)  alle HTTP server strings laat zien en telt die niet de string Apache  bevatten als antwoord op je GET requests. Sorteer van groot naar klein.
   Sample output:


```

2 ClientMapServer  
1 YouTube Frontend Proxy  
1 sffe  
1 Kestrel  
1 ECS (ams/D1E7)  
1 ECS (ams/499C)  
1 downloads  
1 CloudFront

```

Daarna pipe je de output van je CLI oneliner in het commando md5sum. In het antwoordveld vul je beide in op deze manier:
oneliner - md5 hash

```

```
2 punten  

###             Vraag 4      

1. Maak een CLI oneliner die alle unieke gebruikersnamen toont waarmee geprobeerd werd om in te loggen op de website http://darthvader.uclllabs.be/nw2/private. Maak gebruik van de capture http_basic_auth.pcapng (/home/logs op leia).

   Daarna pipe je de output van je CLI oneliner in het commando md5sum. In het antwoordveld vul je beide in op deze manier:
   oneliner - md5 hash

```

```
2 punten  

###             Vraag 5      

1. Maak een CLI oneliner waarmee je de uitgever, vervaldatum en  modulus (in deze volgorde) laat zien van het certificaat van de website  https://x.toledo.ucll.be.

   Daarna pipe je de output van je CLI oneliner in het commando md5sum. In het antwoordveld vul je beide in op deze manier:
   oneliner - md5 hash

```

```
2 punten  

###             Vraag 6      

1. Maak een CLI oneliner die de juiste (dus van vandaag) dag en datum toont zoals in onderstaand voorbeeld:

   Het is vandaag vrijdag (1996.09.13)

   Daarna pipe je de output van je CLI oneliner in het commando md5sum. In het antwoordveld vul je beide in op deze manier:
   oneliner - md5 hash

```

# Theorie test 31-05-2021

[theorie.pdf](https://examenwiki-test.diana.be/attachments/23)

# Algemeen

Dit vak bestaat uit theorielessen en computerzittingen. In de computerzittingen worden er oefeningen gemaakt in Linux, via SSH op een server van school. De leerstof van de praktijk lijkt eerst zot moeilijk, maar zorg gewoon dat je genoeg oefent en durf vragen te stellen en uiteindelijk zal het zichzelf uitwijzen

Het examen bestaat uit twee delen: een theorie-examen op 10 punten in de normale examenperiode en een praktijkexamen in de laatste week van het semester dat eveneens op 10 punten staat. Alles wat bij de Wiki op de pagina theorie staat is te kennen theorie. Er komt sowieso een vraag gebaseerd op hetgeen er in de filmpjes of extra teksten staat. Bij de meerkeuzevragen van het theorie-examen is er is geen giscorrectie, maar alles moet juist zijn om punten te kunnen krijgen. Het aantal juiste antwoorden wordt gegeven. Het is goed mogelijk dat er vragen terugkomen.

Het onderwerp cryptografie is een moeilijk onderdeel van computernetwerken. Als je het niet erg vindt om eens wat te lezen: het boek Computer Networks: A top-down approach is een zeer goed boek.

De puntenverdeling was oorspronkelijk 14 voor het theorie-examen en 6 voor het praktijkexamen. In 2015-2016 werd dit een eerste jaars vak en in schooljaar 2016-2017 veranderde de puntenverdeling naar 10/10 waarbij 10 punten op de theorie en 10 op de labo's.