Lab 9 - Application-Layer Protocols

Updated 4 Oct 2026

Topics Covered

  • Domain Name System (DNS)
  • Hyper-Text Transfer Protocol (HTTP)
  • File Transfer Protocol (FTP)

Section 1: Domain Name System (DNS)

Key Definitions

  • Domain name — the name of a website (e.g., google.com, siit.tu.ac.th)
    • What comes after @ in an email, or after www. in a web address
  • URL (Universal Resource Locator) — the complete web address to a specific page
    • The domain is just the name; the URL tells you how to find a specific page within it
  • Website — what users actually see and interact with

Think of a domain like a building's name ("SIIT"), the URL like the full address including floor and room number, and the website like what's actually inside the room.

URL Structure

http:// www .google .com
│        │    │       └── Top Level Domain (TLD)
│        │    └── Domain (name) — you BUY this yearly
│        └── Subdomain
└── Protocol (HyperText Transfer)
  • Common TLDs and yearly costs (approx.): .com ~8.03, ‘.net‘  8.03, `.net` ~9.95, .info ~11.02, ‘.org‘  11.02, `.org` ~10.11

How DNS Works

  1. User types www.siit.tu.ac.th into browser
  2. Computer sends a DNS query packet to DNS server asking for the IP address
  3. DNS server replies with the IP address
  4. Computer then sends HTTP request to the web server at that IP
  5. Web server sends back the HTTP response (the page content)

DNS Key Facts

  • DNS Port: 53\boxed{53}
  • DNS uses UDP for transport
  • The DNS server translates domain names → IP addresses
  • Two query types per domain:
    • A record → IPv4 address
    • AAAA record → IPv6 address

DNS is like a phone book: you look up someone's name (domain), and it gives you their number (IP address).


Section 2: Hyper-Text Transfer Protocol (HTTP)

Overview

  • HTTP defines how web pages are requested and delivered between client and server
  • Client sends an HTTP request → Server replies with an HTTP response
  • HTTP Port: 80\boxed{80}
  • HTTPS Port: 443\boxed{443} (encrypted with SSL/TLS)

HTTP is like ordering food: you (client) give your order (request), the kitchen (server) prepares and sends it back (response).


2.1 HTTP Request Message Structure

The request message has 4 sections:

SectionContent
Request LineMethod sp URL sp Version cr lf
Header LinesMultiple Header name: Value pairs
Blank Linecr lf — marks end of headers
BodyData sent to server (present only in some messages, e.g., POST)

Request Line Fields

  • Method — most common is GET; others: POST, HEAD, PUT
  • URL — the resource being requested
  • Version — currently HTTP/1.1

HTTP Methods

  • GET — request a resource; body is empty; data goes in the URL after ? (max ~2,048 chars)
  • POST — sends data in the body (e.g., form submissions)
  • HEAD — like GET but returns only headers, no body
  • PUT — uploads/replaces a file on the server

Request Header Fields

HeaderDescription
User-AgentIdentifies the client program (browser)
AcceptShows the media format the client can accept
Accept-CharsetShows the character set the client can handle
Accept-EncodingShows the encoding scheme the client can handle
Accept-LanguageShows the language the client can accept
AuthorizationShows what permissions the client has
HostShows the host and port number of the client
DateShows the current date
UpgradeSpecifies the preferred communication protocol
CookieReturns the cookie to the server
If-Modified-SinceOnly send content if modified since a specific date

Example HTTP Request

GET /index.html HTTP/1.1\r\n
Host: www-net.cs.umass.edu\r\n
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0\r\n
Accept: text/html,application/xhtml+xml\r\n
Accept-Language: en-us,en;q=0.5\r\n
Accept-Encoding: gzip,deflate\r\n
Connection: keep-alive\r\n
\r\n

2.2 HTTP Response Message Structure

The response message also has 4 sections:

SectionContent
Status LineVersion sp Status Code sp Phrase cr lf
Header LinesMultiple Header name: Value pairs
Blank Linecr lf
BodyThe actual webpage source code / content

HTTP Status Codes

CodeMeaningCodeMeaning
200OK400Bad Request
201Created401Unauthorized
202Accepted403Forbidden
301Moved Permanently404Not Found
303See Other410Gone
304Not Modified500Internal Server Error
307Temporary Redirect503Service Unavailable

Status codes: 2xx = success, 3xx = redirection, 4xx = client error, 5xx = server error

Response Header Fields

HeaderDescription
DateShows the current date
UpgradeSpecifies the preferred communication protocol
ServerGives information about the server
Set-CookieThe server asks the client to save a cookie
Content-EncodingSpecifies the encoding scheme
Content-LanguageSpecifies the language
Content-LengthShows the length of the document
Content-TypeSpecifies the media type
LocationAsk the client to send request to another site
Accept-RangesThe server will accept the requested byte-ranges
Last-ModifiedGives the date and time of the last change

Example HTTP Response

HTTP/1.1 200 OK
Date: Tue, 08 Sep 2020 00:53:20 GMT
Server: Apache/2.4.6 (CentOS)
Last-Modified: Tue, 01 Mar 2016 18:57:50 GMT
Content-Length: 2651
Content-Type: text/html; charset=UTF-8
\r\n
<html>... (webpage data) ...

2.3 HTTP Versions

VersionConnection TypeBehaviour
HTTP 1.0Short-lived connectionsNew TCP connection for every request
HTTP 1.1Persistent connectionReuses the same TCP connection
HTTP 2.0HTTP PipeliningMultiple requests sent without waiting for responses

2.4 HTTPS

  • HTTPS = HTTP + SSL/TLS encryption
  • Port: 443\boxed{443}
  • With HTTP: password sent in plaintext → attacker can see abc123
  • With HTTPS: password encrypted → attacker sees xyaerXzabc (gibberish)
  • Uses certificates issued by Certificate Authorities (CA) to verify server identity

Section 3: File Transfer Protocol (FTP)

Overview

  • FTP is the standard TCP/IP protocol for copying files between hosts
  • Better than HTTP for large files or files in different formats
  • FTP Control Port: 21\boxed{21}
  • FTP Data Port: 20\boxed{20}

FTP is like a file courier: you authenticate yourself (username + password), then the courier picks up or delivers files.

FTP Connection Flow

Client                          Server
  |  ←── 220 (Service ready) ──── |   ① Server announces it's ready
  |  ──── USER forouzan ─────────→ |   ② Client sends username
  |  ←── 331 (Password?) ──────── |   ③ Server asks for password
  |  ──── PASS xxxxxx ───────────→ |   ④ Client sends password (PLAINTEXT!)
  |  ←── 230 (User login OK) ──── |   ⑤ Server confirms login

FTP Common Status Codes

CodeMeaning
220Service ready
331User name OK, password required
230User logged in

FTP Security Issue ⚠️

  • FTP was designed when security was not a priority
  • Passwords are sent in plaintext (unencrypted)
  • An attacker can intercept the password with packet capture tools (like Wireshark)
  • Secure alternative: SFTP (SSH File Transfer Protocol) or FTPS (FTP over SSL)

Section 4: Step-by-Step Lab Guides

Login credentials for Ubuntu: username: student | password: Siit@1992


Assignment 1 — DNS Mechanisms (Step-by-Step)

Goal: Capture DNS packets when visiting www.tu.ac.th and identify the IPv4 and IPv6 addresses returned.

Steps

  1. Clear the browser cache (so DNS queries are actually sent, not served from cache)
    • Open Mozilla Firefox
    • Go to Menu → Preferences → Advanced
    • Click "Clear Now" next to Cached Web Content
    • Do NOT open any website yet
  2. Open Wireshark
    • Launch Wireshark from the desktop or Applications menu
    • Select the active network interface (usually ens33 or eth0)
    • Click the blue shark fin button (Start Capture)
  3. Trigger DNS traffic
    • Go back to Firefox
    • Type www.tu.ac.th in the address bar and press Enter
    • Wait for the page to load
  4. Stop capturing
    • Go back to Wireshark
    • Click the red square (Stop Capture)
  5. Filter DNS packets
    • In the filter bar at the top, type: dns
    • Press Enter or click Apply
  6. Analyze the packets — look for 4 DNS packets:
PacketDirectionQuery TypeInfo
1stClient → DNS serverA (IPv4)Standard query for www.tu.ac.th
2ndClient → DNS serverAAAA (IPv6)Standard query for www.tu.ac.th
3rdDNS server → ClientA responseContains the IPv4 address
4thDNS server → ClientAAAA responseContains the IPv6 address
  1. Click on the 3rd packet to expand the details pane below
    - Expand "Domain Name System (response)"
    • Expand "Answers"
    • Look for the A record → note the IPv4 address
  2. Click on the 4th packet
    • Same steps → look for the AAAA record → note the IPv6 address
  3. Show to TA for signature ✍️

Assignment 2 — HTTP Mechanisms (Step-by-Step)

Goal: Capture HTTP GET request and response when visiting http://library.siit.tu.ac.th

Steps

  1. Continue from Assignment 1 — Wireshark should still be open
  2. Change the Wireshark filter
    • Clear the old dns filter
    • Type: dns || http
    • Press Enter or click Apply
  3. Start a new capture (or continue the existing one)
    • Click the green shark fin (Restart) or start a new capture
  4. Visit the library website
    • In Firefox, type: http://library.siit.tu.ac.th
    • Press Enter and wait for it to load
  5. Stop capturing when the page loads
  6. Find the HTTP GET packet (blue highlighted row with HTTP protocol and GET in Info column)
    • Click on it to select it
    • In the detail pane, expand "Hypertext Transfer Protocol"
    • Look for and note:
      • Request line: GET / HTTP/1.1 → the version is HTTP/1.1
      • Host: library.siit.tu.ac.th → this is the website name
      • User-Agent: something like Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:96.0) Gecko/20100101 Firefox/96.0
  7. Find the HTTP Response packet (row with HTTP protocol and 200 OK or similar in Info column)
    • Click on it
    • Expand "Hypertext Transfer Protocol"
    • Look for and note:
      • Status line: e.g., HTTP/1.1 200 OK → status code = 200, phrase = OK
      • Date: the timestamp of when the page was requested
  8. Show to TA for signature ✍️

Tip: If you see HTTPS traffic instead of HTTP, the site redirected to the secure version. Make sure you typed http:// (not https://) in the address bar.


Assignment 3 — FTP Mechanisms (Step-by-Step)

Goal: Capture FTP login packets and observe the plaintext username and password.

Steps

  1. Open Wireshark and start a new capture on the active interface

  2. Open a Terminal

    • Right-click the desktop → "Open Terminal" (or find it in Applications)
  3. Connect to the FTP server

    ftp test.rebex.net
    • When prompted for Name: type demo and press Enter
    • When prompted for Password: type password and press Enter
    • You should see 230 User logged in. if successful
    • You can type quit to exit the FTP session
  4. Stop capturing in Wireshark

  5. Filter FTP packets

    • In the filter bar, type: ftp
    • Press Enter or click Apply
  6. Analyze the 5 key FTP packets in order:

#SourceInfoWhat to note
1stFTP Server220 Microsoft FTP ServiceServer IP and port (21)
2ndClientRequest: USER demoClient IP and port; username = demo
3rdFTP Server331 Password required for demoStatus code + meaning
4thClientRequest: PASS passwordPassword visible in plaintext = password
5thFTP Server230 User logged inStatus code + meaning
  1. Click each packet and expand "File Transfer Protocol (FTP)" in the detail pane to read the exact content

  2. For the 1st packet, also check the IP layer for the server's IP address:

    • Expand "Internet Protocol Version 4"
    • Source = FTP server IP
    • Look at "Transmission Control Protocol" → Source Port = 21
  3. Show to TA for signature ✍️

⚠️ Notice how the password password is completely readable in plain text in Wireshark. This is the FTP security issue — anyone on the same network can intercept it!


Assignment 4 — More DNS & HTTP (Step-by-Step, using pcap file)

Goal: Open a pre-captured packet file and answer questions about DNS and HTTP traffic.

Steps

  1. Open Wireshark

  2. Open the pcap file

    • Go to File → Open
    • Navigate to where Lab9_Assign4.pcap is saved (Google Classroom download)
    • Click Open
  3. Find the client IP address (Q1)

    • Apply filter: dns
    • Look at any DNS query packet (sent from client to server)
    • The Source column = client IP address
  4. Find the DNS server IP address (Q2)

    • In the same DNS query packet
    • The Destination column = DNS server IP address
  5. Find which websites were accessed (Q3)

    • Keep filter: dns
    • Look through DNS query packets
    • Expand each one → "Domain Name System (query)" → "Queries" → look at the Name field
    • Each unique domain name = one website accessed
  6. Find the IPv4 addresses (Q4)

    • Look at DNS response packets where the query type is A
    • Expand "Answers" → find the A record → note the IP address
  7. Find the IPv6 addresses (Q5)

    • Look at DNS response packets where the query type is AAAA
    • Expand "Answers" → find the AAAA record → note the IPv6 address
  8. Find the User-Agent / browser (Q6)

    • Change filter to: http
    • Find an HTTP GET request packet
    • Expand "Hypertext Transfer Protocol" → find the User-Agent line
  9. Find the date the webpage was requested (Q7)

    • Find the HTTP GET request packet
    • Look at the Date header line in the request
    • OR look at the Date header in the HTTP response
  10. Find DNS port and HTTP port of the first website (Q8)

    • DNS port is always 53 (standard)
    • HTTP port is always 80 (standard)
    • But verify: in the first DNS packet → expand "User Datagram Protocol" → check Dst Port
    • In the first HTTP packet → expand "Transmission Control Protocol" → check Dst Port
  11. Show to TA for signature ✍️


Assignment 5 — More FTP (Step-by-Step, using pcap file)

Goal: Open a pre-captured FTP packet file and extract server info, client info, username, and password.

Steps

  1. Open Wireshark
  2. Open the pcap file
    • Go to File → Open
    • Navigate to Lab9_Assign5.pcap
    • Click Open
  3. Filter FTP packets
    • In the filter bar type: ftp
    • Press Enter
  4. Find the FTP server IP and port (Q1)
    • Click on the 1st FTP packet (the 220 response from the server)
    • Expand "Internet Protocol Version 4"
      • Source = FTP server IP address
    • Expand "Transmission Control Protocol"
      • Source Port = FTP server port (should be 21)
  5. Find the client IP and port (Q2)
    • Click on the 2nd FTP packet (the USER request from the client)
    • Expand "Internet Protocol Version 4"
      • Source = client IP address
    • Expand "Transmission Control Protocol"
      • Source Port = client port (ephemeral/random high port)
  6. Find the username and password (Q3)
    • Click on the packet with Request: USER xxxxx in the Info column
    • Expand "File Transfer Protocol (FTP)"
    • Read the USER command → that's the username
    • Click on the packet with Request: PASS xxxxx in the Info column
    • Expand "File Transfer Protocol (FTP)"
    • Read the PASS command → that's the password (in plaintext!)
  7. Show to TA for signature ✍️

💡 Wireshark Quick Tips

ActionHow to do it
Start captureClick blue shark fin button
Stop captureClick red square button
Apply a filterType in filter bar → press Enter or click Apply
Clear a filterClick X on the filter bar or delete the text
Expand a packet layerClick the ▶ triangle next to the layer name
Follow a TCP streamRight-click a packet → "Follow" → "TCP Stream"
Open a pcap fileFile → Open

Common Wireshark Filters

FilterShows
dnsOnly DNS packets
httpOnly HTTP packets
ftpOnly FTP control packets
dns | httpDNS and HTTP packets
ip.addr == x.x.x.xPackets to/from a specific IP
tcp.port == 80Packets on port 80

Section 5: Assignments Summary

Assignment 1 — DNS Mechanisms (Wireshark)

  • Filter in Wireshark: dns
  • Navigate to www.tu.ac.th
  • Observe 4 DNS packets:
    • Packet 1: Client → DNS server: query IPv4 (A record) of www.tu.ac.th
    • Packet 2: Client → DNS server: query IPv6 (AAAA record) of www.tu.ac.th
    • Packet 3: DNS server → Client: IPv4 answer
    • Packet 4: DNS server → Client: IPv6 answer
  • DNS server port is always 53
  • Client port is ephemeral (random high port, e.g., 57493)

Assignment 2 — HTTP Mechanisms (Wireshark)

  • Filter: dns || http
  • Navigate to http://library.siit.tu.ac.th
  • Observe the GET request and response
  • Key things to note from the HTTP Request:
    • HTTP version (e.g., HTTP/1.1)
    • Host name (e.g., library.siit.tu.ac.th)
    • User-Agent (browser info, e.g., Mozilla/5.0 ... Firefox/96.0)
  • Key things to note from the HTTP Response:
    • Status code and phrase (e.g., 200 OK)
    • Date header (date the page was requested)

Assignment 3 — FTP Mechanisms (Wireshark)

  • Filter: ftp
  • Connect to ftp test.rebex.net with demo / password
  • Observe 5 key FTP packets:
    1. Server → Client: 220 (Service ready) — note FTP server IP:port
    2. Client → Server: USER demo — note client IP:port and username
    3. Server → Client: 331 (Password required)
    4. Client → Server: PASS password — password visible in plaintext!
    5. Server → Client: 230 (User logged in)

Assignment 4 — More DNS & HTTP (pcap file: Lab9_Assign4)

Questions to answer from the captured file:

  1. IP address of the client?
  2. IP address of the DNS server?
  3. How many websites were accessed? Which ones?
  4. IPv4 addresses of those web servers?
  5. IPv6 addresses of those web servers?
  6. User agent (browser) the client was using?
  7. Date the webpage was requested?
  8. DNS port number and HTTP port number of the first web server accessed?

Assignment 5 — More FTP (pcap file: Lab9_Assign5)

Questions to answer from the captured file:

  1. IP address and port number of the FTP server?
  2. IP address and port number of the client?
  3. Username and password to access the FTP server?

Quick Reference: Port Numbers

ProtocolPort
DNS53\boxed{53}
HTTP80\boxed{80}
HTTPS443\boxed{443}
FTP Control21\boxed{21}
FTP Data20\boxed{20}

🧠 Quiz Prep

These are potential quiz questions based on this lab's content. Study these carefully!

Multiple Choice Style

  1. What port does the DNS server use?

    • A) 80 B) 21 C) 53 D) 443
  2. What port does an HTTP web server use?

    • A) 53 B) 80 C) 21 D) 443
  3. What port does FTP use for control?

    • A) 20 B) 80 C) 53 D) 21
  4. What method does the client usually use in an HTTP request?

    • A) POST B) HEAD C) GET D) PUT
  5. Which HTTP status code means "OK" (success)?

    • A) 404 B) 301 C) 500 D) 200
  6. Which HTTP status code means "Not Found"?

    • A) 200 B) 301 C) 404 D) 500
  7. What is sent in plaintext in FTP that is a security risk?

    • A) Username B) IP address C) Password D) Port number
  8. Which HTTP version introduced persistent connections?

    • A) HTTP 1.0 B) HTTP 1.1 C) HTTP 2.0 D) HTTPS
  9. What is the HTTPS port number?

    • A) 80 B) 21 C) 53 D) 443
  10. In a DNS query, which record type resolves to an IPv6 address?

    • A) A B) MX C) PTR D) AAAA

Short Answer Style

  • What are the 4 sections of an HTTP request message?

    • Request line, Header lines, Blank line, Body
  • What does the User-Agent header in an HTTP request tell us?

    • It identifies the client program (web browser) being used
  • What is the difference between a domain name and a URL?

    • Domain = name of the website; URL = full address to a specific page
  • Why is FTP considered insecure?

    • Because the password is sent in plaintext (unencrypted), making it vulnerable to interception
  • What is the difference between FTP port 20 and port 21?

    • Port 21 = control channel (commands), Port 20 = data channel (file transfer)
  • What Wireshark filter would you use to see both DNS and HTTP packets together?

    • dns || http
  • What does HTTP status code 301 mean?

    • Moved Permanently
  • What does HTTP status code 304 mean?

    • Not Modified (used for caching — the client already has the latest version)

Explanation Style

  • Explain the full process of what happens when you type www.siit.tu.ac.th into a browser:

    1. Browser sends DNS query (port 53) to DNS server asking for the IPv4/IPv6 of www.siit.tu.ac.th
    2. DNS server responds with the IP address
    3. Browser sends HTTP GET request to the web server at that IP (port 80)
    4. Web server sends back HTTP response with the page source code (status 200 OK)
    5. Browser renders and displays the page
  • Explain why FTP is a security risk and what can be done about it:

    • FTP sends passwords in plaintext over the network. Any attacker using packet capture (e.g., Wireshark) on the same network can read the password directly. Secure alternatives include SFTP (uses SSH encryption) or FTPS (FTP over SSL/TLS).