Lab 9

Updated 4 Oct 2026

🌐 Lab 9 — Application-Layer Protocols · Cheat Sheet

ITS352/DES352 · SIIT · Thammasat University


1 · Port Numbers (Memorise All!)

ProtocolPortTransportPurpose
DNS53UDPDomain name → IP translation
FTP Data20TCPFile transfer (data channel)
FTP Control21TCPCommands (login, list, get)
HTTP80TCPWeb pages (plaintext)
HTTPS443TCPWeb pages (encrypted SSL/TLS)

2 · DNS — Domain Name System

What it does: Translates domain name → IP address (like a phone book)

URL:  http:// www  .google  .com
               │      │       └── TLD (Top Level Domain)
               │      └── Domain (you BUY this)
               └── Subdomain

How DNS Works (step by step)

1. You type www.siit.tu.ac.th in browser
2. Computer → DNS server: "What is the IP for www.siit.tu.ac.th?" (port 53, UDP)
3. DNS server → Computer: "Here is the IP"
4. Computer → Web server at that IP: HTTP GET request (port 80)
5. Web server → Computer: HTTP response (the page)

DNS Record Types

RecordResolves to
AIPv4 address
AAAAIPv6 address

DNS in Wireshark — 4 packets per domain visit

#DirectionTypeContent
1Client → DNS serverQuery A"What is IPv4 of www.tu.ac.th?"
2Client → DNS serverQuery AAAA"What is IPv6 of www.tu.ac.th?"
3DNS server → ClientResponse AIPv4 answer
4DNS server → ClientResponse AAAAIPv6 answer

DNS port = 53. Client uses ephemeral port (random high port e.g. 57493).


3 · HTTP — HyperText Transfer Protocol

HTTP Request — 4 Sections

GET /index.html HTTP/1.1\r\n          ← Request Line: Method SP URL SP Version
Host: www.example.com\r\n            ← Header Lines
User-Agent: Mozilla/5.0 ...\r\n
Accept-Language: en-us\r\n
\r\n                                  ← Blank Line (marks end of headers)
                                      ← Body (empty for GET, has data for POST)

HTTP Methods

MethodWhat it doesBody?
GETRequest a resource❌ Empty (data in URL after ?)
POSTSend data to server✅ Yes (form submissions)
HEADLike GET but headers only❌
PUTUpload/replace file on server✅ Yes

HTTP Response — 4 Sections

HTTP/1.1 200 OK\r\n                   ← Status Line: Version SP StatusCode SP Phrase
Date: Tue, 08 Sep 2020 00:53:20 GMT\r\n ← Header Lines
Server: Apache/2.4.6\r\n
Content-Length: 2651\r\n
Content-Type: text/html; charset=UTF-8\r\n
\r\n                                  ← Blank Line
<html>...</html>                      ← Body (the actual webpage)

Quiz tip: Status code is in the Status Line, NOT in the header lines. ← (quiz answer: "Status code" is NOT defined in header line)

HTTP Status Codes

CodeMeaningCodeMeaning
200OK ✅400Bad Request
201Created401Unauthorized
202Accepted403Forbidden ← quiz answer
301Moved Permanently404Not Found
303See Other410Gone
304Not Modified500Internal Server Error
307Temporary Redirect503Service Unavailable

2xx = success · 3xx = redirect · 4xx = client error · 5xx = server error

Key HTTP Request Headers

HeaderWhat it tells the server
User-AgentClient program/browser info (OS, browser type) ← quiz: identifies device type
HostHostname and port of the client
AcceptMedia formats client accepts
Accept-LanguageLanguage client prefers
Accept-EncodingEncoding schemes client handles
CookieReturns cookie to server
If-Modified-SinceOnly send if modified since date
AuthorizationClient permissions

Key HTTP Response Headers

HeaderWhat it tells the client
ServerWeb server software info
Content-TypeMedia type of the body
Content-LengthSize of the body
Set-CookieAsk client to save a cookie
LocationRedirect client to another URL
Last-ModifiedDate of last content change
DateCurrent date/time

HTTP Versions

VersionConnectionBehaviour
HTTP 1.0Short-livedNew TCP connection per request
HTTP 1.1PersistentReuses same TCP connection
HTTP 2.0PipeliningMultiple requests without waiting for responses

HTTPS

  • HTTP + SSL/TLS encryption → port 443
  • HTTP: password sent as plaintext → attacker sees abc123
  • HTTPS: password encrypted → attacker sees xyaerXzabc (gibberish)
  • Uses certificates from Certificate Authorities (CA)

4 · FTP — File Transfer Protocol

Purpose: Copy files between hosts (better than HTTP for large/different-format files)

  • Port 21 = Control channel (commands: USER, PASS, QUIT)
  • Port 20 = Data channel (actual file bytes)

FTP Login Flow (5 key packets)

Client                          Server
  |  ←── 220 (Service ready) ──── |   ① Server ready — NOTE server IP:port 21
  |  ──── USER demo ─────────────→ |   ② Client sends username
  |  ←── 331 (Password required)── |   ③ Server asks for password
  |  ──── PASS password ──────────→ |   ④ Password sent in PLAINTEXT ⚠️
  |  ←── 230 (User logged in) ──── |   ⑤ Login success

FTP Status Codes

CodeMeaning
220Service ready
331Username OK, password required
230User logged in

FTP Security Issue ⚠️

  • Password sent in plaintext — anyone on network can read it with Wireshark
  • Secure alternatives: SFTP (SSH-based) or FTPS (FTP over SSL)

FTP Lab Command

ftp test.rebex.net
# Name: demo
# Password: password
# → 230 User logged in.
quit

5 · Wireshark Filters

sudo wireshark    # launch Wireshark
GoalFilter
DNS onlydns
HTTP onlyhttp
FTP onlyftp
DNS + HTTP togetherdns | http
Packets from/to an IPip.addr == 192.178.18.8
Specific porttcp.port == 80
IP + protocol combinedip.addr == 192.178.18.8 && tcp

6 · Assignment Quick Reference

Assignment 1 — DNS (live capture)

Filter: dns
Visit: www.tu.ac.th
→ See 4 packets: 2 queries (A + AAAA) + 2 responses (IPv4 + IPv6)
To find IP: click 3rd packet → expand "Answers" → A record = IPv4
            click 4th packet → expand "Answers" → AAAA record = IPv6

Assignment 2 — HTTP (live capture)

Filter: dns || http
Visit: http://library.siit.tu.ac.th   ← must type http:// not https://
→ Find GET packet: note HTTP version, Host, User-Agent
→ Find 200 OK packet: note Status code, Date header

Assignment 3 — FTP (live capture)

# Terminal:
ftp test.rebex.net    # connect
# Name: demo
# Password: password
 
# Wireshark filter: ftp
# Packet 1 (220): server IP = source IP, port = 21
# Packet 2 (USER demo): client IP = source IP
# Packet 4 (PASS password): password visible in PLAINTEXT

Assignment 4 — DNS + HTTP (pcap file: Lab9_Assign4.pcap)

Filter: dns → find client IP (source of query), DNS server IP (destination)
             → find domain names in "Queries → Name"
             → A response = IPv4, AAAA response = IPv6
Filter: http → find User-Agent header, Date header
DNS port = 53, HTTP port = 80 (verify in packet details)

Assignment 5 — FTP (pcap file: Lab9_Assign5.pcap)

Filter: ftp
Packet 1 (220): Source IP = FTP server, Source Port = 21
Packet 2 (USER): Source IP = client, Source Port = ephemeral
Packet with "PASS": expand FTP layer → password in plaintext

7 · Quiz Question Patterns

QuestionAnswer
What does DNS do?Maps domain name to IP address
True about DNS?DNS maps the name of website to the IP address
DNS port?53
DNS transport protocol?UDP
HTTP port?80
HTTPS port?443
FTP control port?21
FTP data port?20
HTTP method to request a document?GET
HTTP status code: forbidden?403
HTTP status code: not found?404
HTTP status code: OK?200
HTTP status code: moved permanently?301
HTTP status code: not modified?304
Which header identifies device type (mobile/Windows/Linux)?User-Agent
Which header is NOT in HTTP response header line?Status code (it's in the Status Line, not headers)
Secure HTTP protocol?HTTPS
First line of HTTP response format?HTTP/1.1 200 OK → A = HTTP, B = 200
FTP server IP from Wireshark?Source IP of packet with 220 response
FTP server port?21 (shown as Src Port in TCP layer)
FTP security problem?Password sent in plaintext
Which HTTP version uses persistent connections?HTTP 1.1
DNS record type for IPv4?A
DNS record type for IPv6?AAAA
What is a URL?Full address to a specific page (protocol + domain + path)
What is a domain name?Just the name of the website (e.g., google.com)

Explanation: Full process when typing a URL in browser

  1. Browser sends DNS query (UDP, port 53) → DNS server returns IP
  2. Browser sends HTTP GET (TCP, port 80) to web server at that IP
  3. Web server replies with HTTP response (200 OK + HTML body)
  4. Browser renders and displays the page

Explanation: Why FTP is insecure

FTP sends passwords in plaintext — any attacker using Wireshark on the same network can read the password directly from the PASS packet. Fix: use SFTP (SSH encryption) or FTPS (SSL/TLS encryption).