An IP machine Q has a path to another IP machine H via three IP routers R1, R2, and R3. Q—R1—R2—R3—H H acts as an HTTP server, and Q connects to H via HTTP and downloads a file. Session layer Encryption is used, with DES as the shared key encryption protocol. Consider the following four Pieces of information: [I1] The URL of the file downloaded by Q [I2] The TCP port numbers at Q and H [I3] The IP addresses of Q and H [I4] The link layer addresses of Q and H Which of I1, I2, I3, and I4 can an intruder learn through sniffing at R2 alone?
An IP machine Q has a path to another IP machine H via three IP routers R1, R2, and R3. Q—R1—R2—R3—H H acts as an HTTP server, and Q connects to H via HTTP and downloads a file. Session layer Encryption is used, with DES as the shared key encryption protocol. Consider the following four Pieces of information: [I1] The URL of the file downloaded by Q [I2] The TCP port numbers at Q and H [I3] The IP addresses of Q and H [I4] The link layer addresses of Q and H Which of I1, I2, I3, and I4 can an intruder learn through sniffing at R2 alone? Correct Answer Only I2 and I3
Explanation:
ü At router R2 only R1 and R3 link address is available so intruder can’t see the link address of Q and H.
ü At Session layer URL is very well encrypted by DES so intruder can’t see the URL address.
ü At Network layer header contains source as well as destination IP address so intruder can easily see at Router R2.
ü TCP port number of source and destination are present in TCP header so intruder can easily see at Router R2.
Hence option 3 is the correct answer.