Chapter Four Test


Appendix A contains the answers to this chapter test. Use whatever means possible to identify the values and offsets required to build the following filter patterns.

  1. Fill out the fields to build a pattern that would catch all FTP STOR commands.

    click to expand

  2. Fill out the fields to build a pattern that would catch all DNS queries for www.antionline.com.

    click to expand

  3. Fill out the fields to build a pattern that would catch the first two packets of the TCP handshake process (refer to “Analysis and Troubleshooting TCP/IP Networks” or the TCP RFC if required).

    click to expand

    click to expand

  4. Fill out the fields to build a pattern that would catch all IPX traffic that comes from a hardware address 0x00001C342A33. These IPX packets use the Ethernet II frame type.

    click to expand

    click to expand

  5. Fill out the fields to build a pattern that would catch all ICMP Destination Unreachable/Host Unreachable packets.

    click to expand

  6. Fill out the fields to build a pattern that would catch all HTTP traffic that contains the “GET /images/” command.

    click to expand

  7. You are working on a system that uses the IP address 130.57.77.5 with the subnet mask 255.255.252.0. Fill out the fields to build a pattern that would catch all traffic to or from devices in the same subnet as 130.57.77.5.

    click to expand

    click to expand

  8. TCP Resets can be an indication of a misconfigured network service or reconnaissance process. Fill out the fields to build a pattern that would catch all TCP Reset packets.

    click to expand

  9. You are working on a network that supports Unix and Net- Ware hosts. Fill out the fields to build a pattern set that would catch all IP traffic except the NetWare IP traffic (port 524).

    click to expand

    click to expand

    click to expand

    Write down the boolean equation you would use to catch these packets:

    _____________________________________________

  10. Put together several other boolean equations that could be used to catch interesting traffic on your network:

    _____________________________________________

    _____________________________________________

    _____________________________________________

    _____________________________________________

    _____________________________________________




Packet Filtering. Catching the Cool Packets.
Packet Filtering: Catching the Cool Packets
ISBN: 1893939383
EAN: 2147483647
Year: 2000
Pages: 65

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net