The alert was generated from a PCẤP file (Monday.pcap). Now, its time to start investigating the alert. Based on the information abov e, Q1. What is the size of the IP header in bytes? Answer: (This answer should be based on the alert data) Q2. For the above alert, what field in the rule matches with the name given t o the intrusion description? Answer:

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question
You receive the following alert...
[**] [1:1002:7] WEB-IIS cmd.exe access [**] 'Classification: Web Application Attack]
[Priority: 1] 04/25-08:28:49.731955 192.168.202.19:46601 -> 204.126.133.121:80
TCP TTL:117 TOS:0x20 ID:24436 IpLen:20 DgmLen:178 DF
***A**** Seq: OX4E00C2D2 Ack: OXB71DFC3 Win: Ox0 TcpLen: 32
You look up the SID at https://www.snort.org/rule_docs/1-1002 - and and find:
Snort Rule SID: 1002
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg: "WEB-IIS
cmd.exe access"; flow:to_server,established; content:"cmd.exe"; nocase;
classtype:web-application-attack; sid:1002; rev:5;)
The alert was generated from a PCAP file (Monday.pcap).
Now, its time to start investigating the alert. Based on the information abov
е,
Q1. What is the size of the IP header in bytes?
Answer:
(This answer should be based on the alert data)
Q2. For the above alert, what field in the rule matches with the name given t
o the intrusion description?
Answer:
Now, using the above info, you open up the PCAP file (monday.pcap). Using Wireshark, and
following TCP stream, you start to do analysis.
GET /login?cmd.exe HTTP/1.1
User-Agent: CMSY164 attack
Aссерt: */*
Host: campusweb.howardcc.edu
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Mic rosoft-IIS/7.5
X-Powe red-By: ASP.NET
X-Frame-Op tions: SAMEORIGIN
Date: Mon , 25 Apr 2016 18:31:43 GMT
Content-Leng th: 1245
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://
www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xh tml">
<head>
<me ta http-equiv="Content-Type" content=" text/html;
charset=iso-8859-1"/>
<title>404 - File or directo ry not found.</title>
<style type=" text/css">
<!--
Q3. Based on the TCP stream display, Please provide the full http command which triggered the rule
into action (note that http command is everything on a command-line and not a portion of it).
Ans:
Q4. What is the Web Server's IP address?
Answer:
Q5. What is the Client/Attackers IP address?
Answer:
Q6. What was the server's response code?
Answer:
Transcribed Image Text:You receive the following alert... [**] [1:1002:7] WEB-IIS cmd.exe access [**] 'Classification: Web Application Attack] [Priority: 1] 04/25-08:28:49.731955 192.168.202.19:46601 -> 204.126.133.121:80 TCP TTL:117 TOS:0x20 ID:24436 IpLen:20 DgmLen:178 DF ***A**** Seq: OX4E00C2D2 Ack: OXB71DFC3 Win: Ox0 TcpLen: 32 You look up the SID at https://www.snort.org/rule_docs/1-1002 - and and find: Snort Rule SID: 1002 alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg: "WEB-IIS cmd.exe access"; flow:to_server,established; content:"cmd.exe"; nocase; classtype:web-application-attack; sid:1002; rev:5;) The alert was generated from a PCAP file (Monday.pcap). Now, its time to start investigating the alert. Based on the information abov е, Q1. What is the size of the IP header in bytes? Answer: (This answer should be based on the alert data) Q2. For the above alert, what field in the rule matches with the name given t o the intrusion description? Answer: Now, using the above info, you open up the PCAP file (monday.pcap). Using Wireshark, and following TCP stream, you start to do analysis. GET /login?cmd.exe HTTP/1.1 User-Agent: CMSY164 attack Aссерt: */* Host: campusweb.howardcc.edu Connection: Keep-Alive HTTP/1.1 404 Not Found Content-Type: text/html Server: Mic rosoft-IIS/7.5 X-Powe red-By: ASP.NET X-Frame-Op tions: SAMEORIGIN Date: Mon , 25 Apr 2016 18:31:43 GMT Content-Leng th: 1245 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http:// www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xh tml"> <head> <me ta http-equiv="Content-Type" content=" text/html; charset=iso-8859-1"/> <title>404 - File or directo ry not found.</title> <style type=" text/css"> <!-- Q3. Based on the TCP stream display, Please provide the full http command which triggered the rule into action (note that http command is everything on a command-line and not a portion of it). Ans: Q4. What is the Web Server's IP address? Answer: Q5. What is the Client/Attackers IP address? Answer: Q6. What was the server's response code? Answer:
Expert Solution
trending now

Trending now

This is a popular solution!

steps

Step by step

Solved in 2 steps

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY