Topics Covered
- Domain Name System (DNS)
- Hyper-Text Transfer Protocol (HTTP)
- File Transfer Protocol (FTP)
Section 1: Domain Name System (DNS)
Key Definitions
- Domain name — the name of a website (e.g.,
google.com,siit.tu.ac.th)- What comes after
@in an email, or afterwww.in a web address
- What comes after
- URL (Universal Resource Locator) — the complete web address to a specific page
- The domain is just the name; the URL tells you how to find a specific page within it
- Website — what users actually see and interact with
Think of a domain like a building's name ("SIIT"), the URL like the full address including floor and room number, and the website like what's actually inside the room.
URL Structure
http:// www .google .com
│ │ │ └── Top Level Domain (TLD)
│ │ └── Domain (name) — you BUY this yearly
│ └── Subdomain
└── Protocol (HyperText Transfer)
- Common TLDs and yearly costs (approx.):
.com~9.95,.info~10.11
How DNS Works
- User types
www.siit.tu.ac.thinto browser - Computer sends a DNS query packet to DNS server asking for the IP address
- DNS server replies with the IP address
- Computer then sends HTTP request to the web server at that IP
- Web server sends back the HTTP response (the page content)
DNS Key Facts
- DNS Port:
- DNS uses UDP for transport
- The DNS server translates domain names → IP addresses
- Two query types per domain:
- A record → IPv4 address
- AAAA record → IPv6 address
DNS is like a phone book: you look up someone's name (domain), and it gives you their number (IP address).
Section 2: Hyper-Text Transfer Protocol (HTTP)
Overview
- HTTP defines how web pages are requested and delivered between client and server
- Client sends an HTTP request → Server replies with an HTTP response
- HTTP Port:
- HTTPS Port: (encrypted with SSL/TLS)
HTTP is like ordering food: you (client) give your order (request), the kitchen (server) prepares and sends it back (response).
2.1 HTTP Request Message Structure
The request message has 4 sections:
| Section | Content |
|---|---|
| Request Line | Method sp URL sp Version cr lf |
| Header Lines | Multiple Header name: Value pairs |
| Blank Line | cr lf — marks end of headers |
| Body | Data sent to server (present only in some messages, e.g., POST) |
Request Line Fields
- Method — most common is
GET; others:POST,HEAD,PUT - URL — the resource being requested
- Version — currently
HTTP/1.1
HTTP Methods
- GET — request a resource; body is empty; data goes in the URL after
?(max ~2,048 chars) - POST — sends data in the body (e.g., form submissions)
- HEAD — like GET but returns only headers, no body
- PUT — uploads/replaces a file on the server
Request Header Fields
| Header | Description |
|---|---|
User-Agent | Identifies the client program (browser) |
Accept | Shows the media format the client can accept |
Accept-Charset | Shows the character set the client can handle |
Accept-Encoding | Shows the encoding scheme the client can handle |
Accept-Language | Shows the language the client can accept |
Authorization | Shows what permissions the client has |
Host | Shows the host and port number of the client |
Date | Shows the current date |
Upgrade | Specifies the preferred communication protocol |
Cookie | Returns the cookie to the server |
If-Modified-Since | Only send content if modified since a specific date |
Example HTTP Request
GET /index.html HTTP/1.1\r\n
Host: www-net.cs.umass.edu\r\n
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0\r\n
Accept: text/html,application/xhtml+xml\r\n
Accept-Language: en-us,en;q=0.5\r\n
Accept-Encoding: gzip,deflate\r\n
Connection: keep-alive\r\n
\r\n
2.2 HTTP Response Message Structure
The response message also has 4 sections:
| Section | Content |
|---|---|
| Status Line | Version sp Status Code sp Phrase cr lf |
| Header Lines | Multiple Header name: Value pairs |
| Blank Line | cr lf |
| Body | The actual webpage source code / content |
HTTP Status Codes
| Code | Meaning | Code | Meaning |
|---|---|---|---|
| 200 | OK | 400 | Bad Request |
| 201 | Created | 401 | Unauthorized |
| 202 | Accepted | 403 | Forbidden |
| 301 | Moved Permanently | 404 | Not Found |
| 303 | See Other | 410 | Gone |
| 304 | Not Modified | 500 | Internal Server Error |
| 307 | Temporary Redirect | 503 | Service Unavailable |
Status codes: 2xx = success, 3xx = redirection, 4xx = client error, 5xx = server error
Response Header Fields
| Header | Description |
|---|---|
Date | Shows the current date |
Upgrade | Specifies the preferred communication protocol |
Server | Gives information about the server |
Set-Cookie | The server asks the client to save a cookie |
Content-Encoding | Specifies the encoding scheme |
Content-Language | Specifies the language |
Content-Length | Shows the length of the document |
Content-Type | Specifies the media type |
Location | Ask the client to send request to another site |
Accept-Ranges | The server will accept the requested byte-ranges |
Last-Modified | Gives the date and time of the last change |
Example HTTP Response
HTTP/1.1 200 OK
Date: Tue, 08 Sep 2020 00:53:20 GMT
Server: Apache/2.4.6 (CentOS)
Last-Modified: Tue, 01 Mar 2016 18:57:50 GMT
Content-Length: 2651
Content-Type: text/html; charset=UTF-8
\r\n
<html>... (webpage data) ...
2.3 HTTP Versions
| Version | Connection Type | Behaviour |
|---|---|---|
| HTTP 1.0 | Short-lived connections | New TCP connection for every request |
| HTTP 1.1 | Persistent connection | Reuses the same TCP connection |
| HTTP 2.0 | HTTP Pipelining | Multiple requests sent without waiting for responses |
2.4 HTTPS
- HTTPS = HTTP + SSL/TLS encryption
- Port:
- With HTTP: password sent in plaintext → attacker can see
abc123 - With HTTPS: password encrypted → attacker sees
xyaerXzabc(gibberish) - Uses certificates issued by Certificate Authorities (CA) to verify server identity
Section 3: File Transfer Protocol (FTP)
Overview
- FTP is the standard TCP/IP protocol for copying files between hosts
- Better than HTTP for large files or files in different formats
- FTP Control Port:
- FTP Data Port:
FTP is like a file courier: you authenticate yourself (username + password), then the courier picks up or delivers files.
FTP Connection Flow
Client Server
| ←── 220 (Service ready) ──── | ① Server announces it's ready
| ──── USER forouzan ─────────→ | ② Client sends username
| ←── 331 (Password?) ──────── | ③ Server asks for password
| ──── PASS xxxxxx ───────────→ | ④ Client sends password (PLAINTEXT!)
| ←── 230 (User login OK) ──── | ⑤ Server confirms login
FTP Common Status Codes
| Code | Meaning |
|---|---|
| 220 | Service ready |
| 331 | User name OK, password required |
| 230 | User logged in |
FTP Security Issue ⚠️
- FTP was designed when security was not a priority
- Passwords are sent in plaintext (unencrypted)
- An attacker can intercept the password with packet capture tools (like Wireshark)
- Secure alternative: SFTP (SSH File Transfer Protocol) or FTPS (FTP over SSL)
Section 4: Step-by-Step Lab Guides
Login credentials for Ubuntu: username:
student| password:Siit@1992
Assignment 1 — DNS Mechanisms (Step-by-Step)
Goal: Capture DNS packets when visiting www.tu.ac.th and identify the IPv4 and IPv6 addresses returned.
Steps
- Clear the browser cache (so DNS queries are actually sent, not served from cache)
- Open Mozilla Firefox
- Go to
Menu → Preferences → Advanced - Click "Clear Now" next to Cached Web Content
- Do NOT open any website yet
- Open Wireshark
- Launch Wireshark from the desktop or Applications menu
- Select the active network interface (usually
ens33oreth0) - Click the blue shark fin button (Start Capture)
- Trigger DNS traffic
- Go back to Firefox
- Type
www.tu.ac.thin the address bar and press Enter - Wait for the page to load
- Stop capturing
- Go back to Wireshark
- Click the red square (Stop Capture)
- Filter DNS packets
- In the filter bar at the top, type:
dns - Press Enter or click Apply
- In the filter bar at the top, type:
- Analyze the packets — look for 4 DNS packets:
| Packet | Direction | Query Type | Info |
|---|---|---|---|
| 1st | Client → DNS server | A (IPv4) | Standard query for www.tu.ac.th |
| 2nd | Client → DNS server | AAAA (IPv6) | Standard query for www.tu.ac.th |
| 3rd | DNS server → Client | A response | Contains the IPv4 address |
| 4th | DNS server → Client | AAAA response | Contains the IPv6 address |
- Click on the 3rd packet to expand the details pane below
- Expand "Domain Name System (response)"- Expand "Answers"
- Look for the
Arecord → note the IPv4 address
- Click on the 4th packet
- Same steps → look for the
AAAArecord → note the IPv6 address
- Same steps → look for the
- Show to TA for signature ✍️
Assignment 2 — HTTP Mechanisms (Step-by-Step)
Goal: Capture HTTP GET request and response when visiting http://library.siit.tu.ac.th
Steps
- Continue from Assignment 1 — Wireshark should still be open
- Change the Wireshark filter
- Clear the old
dnsfilter - Type:
dns || http - Press Enter or click Apply
- Clear the old
- Start a new capture (or continue the existing one)
- Click the green shark fin (Restart) or start a new capture
- Visit the library website
- In Firefox, type:
http://library.siit.tu.ac.th - Press Enter and wait for it to load
- In Firefox, type:
- Stop capturing when the page loads
- Find the HTTP GET packet (blue highlighted row with
HTTPprotocol andGETin Info column)- Click on it to select it
- In the detail pane, expand "Hypertext Transfer Protocol"
- Look for and note:
- Request line:
GET / HTTP/1.1→ the version isHTTP/1.1 - Host:
library.siit.tu.ac.th→ this is the website name - User-Agent: something like
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:96.0) Gecko/20100101 Firefox/96.0
- Request line:
- Find the HTTP Response packet (row with
HTTPprotocol and200 OKor similar in Info column)- Click on it
- Expand "Hypertext Transfer Protocol"
- Look for and note:
- Status line: e.g.,
HTTP/1.1 200 OK→ status code =200, phrase =OK - Date: the timestamp of when the page was requested
- Status line: e.g.,
- Show to TA for signature ✍️
Tip: If you see
HTTPStraffic instead ofHTTP, the site redirected to the secure version. Make sure you typedhttp://(nothttps://) in the address bar.
Assignment 3 — FTP Mechanisms (Step-by-Step)
Goal: Capture FTP login packets and observe the plaintext username and password.
Steps
-
Open Wireshark and start a new capture on the active interface
-
Open a Terminal
- Right-click the desktop → "Open Terminal" (or find it in Applications)
-
Connect to the FTP server
ftp test.rebex.net- When prompted for Name: type
demoand press Enter - When prompted for Password: type
passwordand press Enter - You should see
230 User logged in.if successful - You can type
quitto exit the FTP session
- When prompted for Name: type
-
Stop capturing in Wireshark
-
Filter FTP packets
- In the filter bar, type:
ftp - Press Enter or click Apply
- In the filter bar, type:
-
Analyze the 5 key FTP packets in order:
| # | Source | Info | What to note |
|---|---|---|---|
| 1st | FTP Server | 220 Microsoft FTP Service | Server IP and port (21) |
| 2nd | Client | Request: USER demo | Client IP and port; username = demo |
| 3rd | FTP Server | 331 Password required for demo | Status code + meaning |
| 4th | Client | Request: PASS password | Password visible in plaintext = password |
| 5th | FTP Server | 230 User logged in | Status code + meaning |
-
Click each packet and expand "File Transfer Protocol (FTP)" in the detail pane to read the exact content
-
For the 1st packet, also check the IP layer for the server's IP address:
- Expand "Internet Protocol Version 4"
- Source = FTP server IP
- Look at "Transmission Control Protocol" → Source Port =
21
-
Show to TA for signature ✍️
⚠️ Notice how the password
passwordis completely readable in plain text in Wireshark. This is the FTP security issue — anyone on the same network can intercept it!
Assignment 4 — More DNS & HTTP (Step-by-Step, using pcap file)
Goal: Open a pre-captured packet file and answer questions about DNS and HTTP traffic.
Steps
-
Open Wireshark
-
Open the pcap file
- Go to
File → Open - Navigate to where
Lab9_Assign4.pcapis saved (Google Classroom download) - Click Open
- Go to
-
Find the client IP address (Q1)
- Apply filter:
dns - Look at any DNS query packet (sent from client to server)
- The Source column = client IP address
- Apply filter:
-
Find the DNS server IP address (Q2)
- In the same DNS query packet
- The Destination column = DNS server IP address
-
Find which websites were accessed (Q3)
- Keep filter:
dns - Look through DNS query packets
- Expand each one → "Domain Name System (query)" → "Queries" → look at the Name field
- Each unique domain name = one website accessed
- Keep filter:
-
Find the IPv4 addresses (Q4)
- Look at DNS response packets where the query type is
A - Expand "Answers" → find the
Arecord → note the IP address
- Look at DNS response packets where the query type is
-
Find the IPv6 addresses (Q5)
- Look at DNS response packets where the query type is
AAAA - Expand "Answers" → find the
AAAArecord → note the IPv6 address
- Look at DNS response packets where the query type is
-
Find the User-Agent / browser (Q6)
- Change filter to:
http - Find an HTTP GET request packet
- Expand "Hypertext Transfer Protocol" → find the User-Agent line
- Change filter to:
-
Find the date the webpage was requested (Q7)
- Find the HTTP GET request packet
- Look at the Date header line in the request
- OR look at the Date header in the HTTP response
-
Find DNS port and HTTP port of the first website (Q8)
- DNS port is always 53 (standard)
- HTTP port is always 80 (standard)
- But verify: in the first DNS packet → expand "User Datagram Protocol" → check Dst Port
- In the first HTTP packet → expand "Transmission Control Protocol" → check Dst Port
-
Show to TA for signature ✍️
Assignment 5 — More FTP (Step-by-Step, using pcap file)
Goal: Open a pre-captured FTP packet file and extract server info, client info, username, and password.
Steps
- Open Wireshark
- Open the pcap file
- Go to
File → Open - Navigate to
Lab9_Assign5.pcap - Click Open
- Go to
- Filter FTP packets
- In the filter bar type:
ftp - Press Enter
- In the filter bar type:
- Find the FTP server IP and port (Q1)
- Click on the 1st FTP packet (the
220response from the server) - Expand "Internet Protocol Version 4"
- Source = FTP server IP address
- Expand "Transmission Control Protocol"
- Source Port = FTP server port (should be
21)
- Source Port = FTP server port (should be
- Click on the 1st FTP packet (the
- Find the client IP and port (Q2)
- Click on the 2nd FTP packet (the
USERrequest from the client) - Expand "Internet Protocol Version 4"
- Source = client IP address
- Expand "Transmission Control Protocol"
- Source Port = client port (ephemeral/random high port)
- Click on the 2nd FTP packet (the
- Find the username and password (Q3)
- Click on the packet with
Request: USER xxxxxin the Info column - Expand "File Transfer Protocol (FTP)"
- Read the USER command → that's the username
- Click on the packet with
Request: PASS xxxxxin the Info column - Expand "File Transfer Protocol (FTP)"
- Read the PASS command → that's the password (in plaintext!)
- Click on the packet with
- Show to TA for signature ✍️
💡 Wireshark Quick Tips
| Action | How to do it |
|---|---|
| Start capture | Click blue shark fin button |
| Stop capture | Click red square button |
| Apply a filter | Type in filter bar → press Enter or click Apply |
| Clear a filter | Click X on the filter bar or delete the text |
| Expand a packet layer | Click the ▶ triangle next to the layer name |
| Follow a TCP stream | Right-click a packet → "Follow" → "TCP Stream" |
| Open a pcap file | File → Open |
Common Wireshark Filters
| Filter | Shows |
|---|---|
dns | Only DNS packets |
http | Only HTTP packets |
ftp | Only FTP control packets |
dns | http | DNS and HTTP packets |
ip.addr == x.x.x.x | Packets to/from a specific IP |
tcp.port == 80 | Packets on port 80 |
Section 5: Assignments Summary
Assignment 1 — DNS Mechanisms (Wireshark)
- Filter in Wireshark:
dns - Navigate to
www.tu.ac.th - Observe 4 DNS packets:
- Packet 1: Client → DNS server: query IPv4 (A record) of
www.tu.ac.th - Packet 2: Client → DNS server: query IPv6 (AAAA record) of
www.tu.ac.th - Packet 3: DNS server → Client: IPv4 answer
- Packet 4: DNS server → Client: IPv6 answer
- Packet 1: Client → DNS server: query IPv4 (A record) of
- DNS server port is always 53
- Client port is ephemeral (random high port, e.g., 57493)
Assignment 2 — HTTP Mechanisms (Wireshark)
- Filter:
dns || http - Navigate to
http://library.siit.tu.ac.th - Observe the GET request and response
- Key things to note from the HTTP Request:
- HTTP version (e.g.,
HTTP/1.1) - Host name (e.g.,
library.siit.tu.ac.th) - User-Agent (browser info, e.g.,
Mozilla/5.0 ... Firefox/96.0)
- HTTP version (e.g.,
- Key things to note from the HTTP Response:
- Status code and phrase (e.g.,
200 OK) - Date header (date the page was requested)
- Status code and phrase (e.g.,
Assignment 3 — FTP Mechanisms (Wireshark)
- Filter:
ftp - Connect to
ftp test.rebex.netwithdemo/password - Observe 5 key FTP packets:
- Server → Client:
220(Service ready) — note FTP server IP:port - Client → Server:
USER demo— note client IP:port and username - Server → Client:
331(Password required) - Client → Server:
PASS password— password visible in plaintext! - Server → Client:
230(User logged in)
- Server → Client:
Assignment 4 — More DNS & HTTP (pcap file: Lab9_Assign4)
Questions to answer from the captured file:
- IP address of the client?
- IP address of the DNS server?
- How many websites were accessed? Which ones?
- IPv4 addresses of those web servers?
- IPv6 addresses of those web servers?
- User agent (browser) the client was using?
- Date the webpage was requested?
- DNS port number and HTTP port number of the first web server accessed?
Assignment 5 — More FTP (pcap file: Lab9_Assign5)
Questions to answer from the captured file:
- IP address and port number of the FTP server?
- IP address and port number of the client?
- Username and password to access the FTP server?
Quick Reference: Port Numbers
| Protocol | Port |
|---|---|
| DNS | |
| HTTP | |
| HTTPS | |
| FTP Control | |
| FTP Data |
🧠 Quiz Prep
These are potential quiz questions based on this lab's content. Study these carefully!
Multiple Choice Style
-
What port does the DNS server use?
- A) 80 B) 21 C) 53 D) 443
-
What port does an HTTP web server use?
- A) 53 B) 80 C) 21 D) 443
-
What port does FTP use for control?
- A) 20 B) 80 C) 53 D) 21
-
What method does the client usually use in an HTTP request?
- A) POST B) HEAD C) GET D) PUT
-
Which HTTP status code means "OK" (success)?
- A) 404 B) 301 C) 500 D) 200
-
Which HTTP status code means "Not Found"?
- A) 200 B) 301 C) 404 D) 500
-
What is sent in plaintext in FTP that is a security risk?
- A) Username B) IP address C) Password D) Port number
-
Which HTTP version introduced persistent connections?
- A) HTTP 1.0 B) HTTP 1.1 C) HTTP 2.0 D) HTTPS
-
What is the HTTPS port number?
- A) 80 B) 21 C) 53 D) 443
-
In a DNS query, which record type resolves to an IPv6 address?
- A) A B) MX C) PTR D) AAAA
Short Answer Style
-
What are the 4 sections of an HTTP request message?
- Request line, Header lines, Blank line, Body
-
What does the
User-Agentheader in an HTTP request tell us?- It identifies the client program (web browser) being used
-
What is the difference between a domain name and a URL?
- Domain = name of the website; URL = full address to a specific page
-
Why is FTP considered insecure?
- Because the password is sent in plaintext (unencrypted), making it vulnerable to interception
-
What is the difference between FTP port 20 and port 21?
- Port 21 = control channel (commands), Port 20 = data channel (file transfer)
-
What Wireshark filter would you use to see both DNS and HTTP packets together?
dns || http
-
What does HTTP status code
301mean?- Moved Permanently
-
What does HTTP status code
304mean?- Not Modified (used for caching — the client already has the latest version)
Explanation Style
-
Explain the full process of what happens when you type
www.siit.tu.ac.thinto a browser:- Browser sends DNS query (port 53) to DNS server asking for the IPv4/IPv6 of
www.siit.tu.ac.th - DNS server responds with the IP address
- Browser sends HTTP GET request to the web server at that IP (port 80)
- Web server sends back HTTP response with the page source code (status 200 OK)
- Browser renders and displays the page
- Browser sends DNS query (port 53) to DNS server asking for the IPv4/IPv6 of
-
Explain why FTP is a security risk and what can be done about it:
- FTP sends passwords in plaintext over the network. Any attacker using packet capture (e.g., Wireshark) on the same network can read the password directly. Secure alternatives include SFTP (uses SSH encryption) or FTPS (FTP over SSL/TLS).