1. You type www.siit.tu.ac.th in browser
2. Computer → DNS server: "What is the IP for www.siit.tu.ac.th?" (port 53, UDP)
3. DNS server → Computer: "Here is the IP"
4. Computer → Web server at that IP: HTTP GET request (port 80)
5. Web server → Computer: HTTP response (the page)
DNS port = 53. Client uses ephemeral port (random high port e.g. 57493).
3 · HTTP — HyperText Transfer Protocol
HTTP Request — 4 Sections
GET /index.html HTTP/1.1\r\n ← Request Line: Method SP URL SP Version
Host: www.example.com\r\n ← Header Lines
User-Agent: Mozilla/5.0 ...\r\n
Accept-Language: en-us\r\n
\r\n ← Blank Line (marks end of headers)
← Body (empty for GET, has data for POST)
HTTP Methods
Method
What it does
Body?
GET
Request a resource
❌ Empty (data in URL after ?)
POST
Send data to server
✅ Yes (form submissions)
HEAD
Like GET but headers only
❌
PUT
Upload/replace file on server
✅ Yes
HTTP Response — 4 Sections
HTTP/1.1 200 OK\r\n ← Status Line: Version SP StatusCode SP Phrase
Date: Tue, 08 Sep 2020 00:53:20 GMT\r\n ← Header Lines
Server: Apache/2.4.6\r\n
Content-Length: 2651\r\n
Content-Type: text/html; charset=UTF-8\r\n
\r\n ← Blank Line
<html>...</html> ← Body (the actual webpage)
Quiz tip: Status code is in the Status Line, NOT in the header lines. ← (quiz answer: "Status code" is NOT defined in header line)
Filter: dns
Visit: www.tu.ac.th
→ See 4 packets: 2 queries (A + AAAA) + 2 responses (IPv4 + IPv6)
To find IP: click 3rd packet → expand "Answers" → A record = IPv4
click 4th packet → expand "Answers" → AAAA record = IPv6
Assignment 2 — HTTP (live capture)
Filter: dns || http
Visit: http://library.siit.tu.ac.th ← must type http:// not https://
→ Find GET packet: note HTTP version, Host, User-Agent
→ Find 200 OK packet: note Status code, Date header
Assignment 3 — FTP (live capture)
# Terminal:ftp test.rebex.net # connect# Name: demo# Password: password# Wireshark filter: ftp# Packet 1 (220): server IP = source IP, port = 21# Packet 2 (USER demo): client IP = source IP# Packet 4 (PASS password): password visible in PLAINTEXT
Assignment 4 — DNS + HTTP (pcap file: Lab9_Assign4.pcap)
Filter: dns → find client IP (source of query), DNS server IP (destination)
→ find domain names in "Queries → Name"
→ A response = IPv4, AAAA response = IPv6
Filter: http → find User-Agent header, Date header
DNS port = 53, HTTP port = 80 (verify in packet details)
Assignment 5 — FTP (pcap file: Lab9_Assign5.pcap)
Filter: ftp
Packet 1 (220): Source IP = FTP server, Source Port = 21
Packet 2 (USER): Source IP = client, Source Port = ephemeral
Packet with "PASS": expand FTP layer → password in plaintext
7 · Quiz Question Patterns
Question
Answer
What does DNS do?
Maps domain name to IP address
True about DNS?
DNS maps the name of website to the IP address
DNS port?
53
DNS transport protocol?
UDP
HTTP port?
80
HTTPS port?
443
FTP control port?
21
FTP data port?
20
HTTP method to request a document?
GET
HTTP status code: forbidden?
403
HTTP status code: not found?
404
HTTP status code: OK?
200
HTTP status code: moved permanently?
301
HTTP status code: not modified?
304
Which header identifies device type (mobile/Windows/Linux)?
User-Agent
Which header is NOT in HTTP response header line?
Status code (it's in the Status Line, not headers)
Secure HTTP protocol?
HTTPS
First line of HTTP response format?
HTTP/1.1 200 OK → A = HTTP, B = 200
FTP server IP from Wireshark?
Source IP of packet with 220 response
FTP server port?
21 (shown as Src Port in TCP layer)
FTP security problem?
Password sent in plaintext
Which HTTP version uses persistent connections?
HTTP 1.1
DNS record type for IPv4?
A
DNS record type for IPv6?
AAAA
What is a URL?
Full address to a specific page (protocol + domain + path)
What is a domain name?
Just the name of the website (e.g., google.com)
Explanation: Full process when typing a URL in browser
Browser sends DNS query (UDP, port 53) → DNS server returns IP
Browser sends HTTP GET (TCP, port 80) to web server at that IP
Web server replies with HTTP response (200 OK + HTML body)
Browser renders and displays the page
Explanation: Why FTP is insecure
FTP sends passwords in plaintext — any attacker using Wireshark on the same network can read the password directly from the PASS packet. Fix: use SFTP (SSH encryption) or FTPS (SSL/TLS encryption).