SlideShare a Scribd company logo
1 of 14
Download to read offline
Lab​ ​04
Name :​ ​Om​ ​Rakesh​ ​Thakkar
Roll​ ​No. :​ ​201501109
Subject :​ ​Computer​ ​Networks
Batch :​ ​1
Topic :​ ​Wireshark
Q.1)​ ​Run​ ​​nslookup​​ ​to​ ​obtain​ ​the​ ​IP​ ​address​ ​of​ ​a​ ​Web​ ​server​ ​in
Asia.
nslookup​​ ​has​ ​been​ ​performed​ ​for​ ​“​www.paytm.com​”.
Q.2)​ ​Run​ ​nslookup​ ​to​ ​determine​ ​the​ ​authoritative​ ​DNS​ ​servers
for​ ​a​ ​university​ ​in​ ​Europe.
nslookup​ ​​has​ ​been​ ​performed​ ​on​ ​Oxford​ ​University​ ​situated​ ​in
Europe.
Q.3)​ ​Run​ ​nslookup​ ​so​ ​that​ ​one​ ​of​ ​the​ ​DNS​ ​servers​ ​obtained​ ​in
Question​ ​2​ ​is​ ​queried​ ​for​ ​the​ ​mail​ ​servers​ ​for​ ​Yahoo!​ ​Mail.
Connection​ ​is​ ​timed​ ​out​ ​and​ ​no​ ​servers​ ​are​ ​reached.
Q.4)​ ​Locate​ ​the​ ​DNS​ ​query​ ​and​ ​response​ ​messages.​ ​Are​ ​they​ ​sent
over​ ​UDP​ ​or​ ​TCP?
DNS​ ​Queries​ ​and​ ​Response​ ​Messages​ ​have​ ​been​ ​located.​ ​They​ ​are
sent​ ​over​ ​UDP.
DNS​ ​Query
DNS​ ​Response
Q.5)​ ​What​ ​is​ ​the​ ​destination​ ​port​ ​for​ ​the​ ​DNS​ ​query​ ​message?
What​ ​is​ ​the​ ​source​ ​port​ ​of​ ​DNS​ ​response​ ​message?
The​ ​Destination​ ​Port​ ​for​ ​DNS​ ​Query​ ​is​ ​53​ ​and​ ​Source​ ​Port​ ​of​ ​DNS
Response​ ​is​ ​53.
DNS​ ​Query
DNS​ ​Response
Q.6)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Use
ipconfig​ ​to​ ​determine​ ​the​ ​IP​ ​address​ ​of​ ​your​ ​local​ ​DNS​ ​server.
Are​ ​these​ ​two​ ​IP​ ​addresses​ ​the​ ​same?
The​ ​DNS​ ​Query​ ​message​ ​has​ ​been​ ​sent​ ​to​ ​208.67.222.222,​ ​which​ ​is
the​ ​IP​ ​Address​ ​of​ ​one​ ​of​ ​my​ ​local​ ​DNS​ ​Servers​ ​as​ ​shown​ ​in​ ​the
image.
Q.7)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS
query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”?
It​ ​is​ ​a​ ​​type​ ​A​​ ​Standard​ ​Query​ ​and​ ​it​ ​doesn’t​ ​contain​ ​any​ ​answers.
Q.8)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​How​ ​many​ ​“answers”
are​ ​provided?​ ​What​ ​do​ ​each​ ​of​ ​these​ ​answers​ ​contain?
There​ ​are​ ​2​ ​answers​ ​provided​ ​in​ ​the​ ​DNS​ ​Response​ ​Message.​ ​They
contain​ ​information​ ​about​ ​the​ ​Name​ ​of​ ​host,​ ​Type​ ​of​ ​address,​ ​Class,
Time​ ​to​ ​Live,​ ​Data​ ​Length,​ ​IP​ ​Address.
Q.9)​ ​Consider​ ​the​ ​subsequent​ ​TCP​ ​SYN​ ​packet​ ​sent​ ​by​ ​your​ ​host.
Does​ ​the​ ​destination​ ​IP​ ​address​ ​of​ ​the​ ​SYN​ ​packet​ ​correspond​ ​to
any​ ​of​ ​the​ ​IP​ ​addresses​ ​provided​ ​in​ ​the​ ​DNS​ ​response​ ​message?
The​ ​first​ ​SYN​ ​packet​ ​was​ ​sent​ ​to​ ​104.20.0.85​ ​which​ ​corresponds​ ​to
the​ ​first​ ​IP​ ​address​ ​provided​ ​in​ ​the​ ​DNS​ ​response​ ​message.
Q.10)​ ​This​ ​web​ ​page​ ​contains​ ​images.​ ​Before​ ​retrieving​ ​each
image,​ ​does​ ​your​ ​host​ ​issue​ ​new​ ​DNS​ ​queries?
No,​ ​the​ ​host​ ​issues​ ​DNS​ ​Queries​ ​after​ ​retrieving​ ​the​ ​image.
● nslookup​ ​www.mit.edu
Q.11)​ ​What​ ​is​ ​the​ ​destination​ ​port​ ​for​ ​the​ ​DNS​ ​query​ ​message?
What​ ​is​ ​the​ ​source​ ​port​ ​of​ ​DNS​ ​response​ ​message?
Destination​ ​port​ ​of​ ​DNS​ ​Query​ ​message​ ​is​ ​53​ ​and​ ​Source​ ​Port​ ​of
DNS​ ​Response​ ​message​ ​is​ ​53.
DNS​ ​Query
DNS​ ​Response
Q.12)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Is​ ​this
the​ ​IP​ ​address​ ​of​ ​your​ ​default​ ​local​ ​DNS​ ​server?
It’s​ ​sent​ ​to​ ​208.67.222.222​ ​which​ ​is​ ​the​ ​IP​ ​Address​ ​of​ ​one​ ​of​ ​my​ ​local
DNS​ ​Servers​ ​as​ ​shown​ ​in​ ​the​ ​image.
Q.13)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS
query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”?
The​ ​Query​ ​is​ ​​Type​ ​A​ ​​and​ ​the​ ​query​ ​message​ ​contains​ ​no​ ​answers.
Q.14)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​How​ ​many​ ​“answers”
are​ ​provided?​ ​What​ ​do​ ​each​ ​of​ ​these​ ​answers​ ​contain?
The​ ​DNS​ ​Response​ ​message​ ​contains​ ​3​ ​answers​ ​as​ ​shown​ ​below.​ ​It
contains​ ​Name​ ​of​ ​host,​ ​type​ ​of​ ​address,​ ​Class,​ ​TTL,​ ​Data​ ​Length​ ​and
CName.
● nslookup​ ​–type=NS​ ​mit.edu
Q.16)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Is​ ​this
the​ ​IP​ ​address​ ​of​ ​your​ ​default​ ​local​ ​DNS​ ​server?
It​ ​is​ ​sent​ ​to​ ​208.67.222.222​ ​which​ ​is​ ​one​ ​of​ ​my​ ​local​ ​DNS​ ​Servers.
Q.17)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS
query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”?
It​ ​is​ ​​NS​ ​Type​ ​​DNS​ ​Query​ ​Message​ ​and​ ​contains​ ​no​ ​answers.
Q.18)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​What​ ​MIT
nameservers​ ​does​ ​the​ ​response​ ​message​ ​provide?​ ​Does​ ​this
response​ ​message​ ​also​ ​provide​ ​the​ ​IP​ ​addresses​ ​of​ ​the​ ​MIT
nameservers?
The​ ​nameservers​ ​are​ ​usw2,​ ​ns1-173,​ ​ns1-37,​ ​asia1,​ ​use2,​ ​use5,​ ​eur5,
asia2.​ ​We​ ​can​ ​find​ ​their​ ​IP​ ​addresses​ ​if​ ​we​ ​expand​ ​the​ ​Additional
records​ ​field​ ​in​ ​Ethereal​ ​as​ ​shown​ ​in​ ​the​ ​image​ ​below.
● nslookup​ ​www.aiit.or.kr​ ​bitsy.mit.edu
Q.20)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Is​ ​this
the​ ​IP​ ​address​ ​of​ ​your​ ​default​ ​local​ ​DNS​ ​server?​ ​If​ ​not,​ ​what​ ​does
the​ ​IP​ ​address​ ​correspond​ ​to?
The​ ​DNS​ ​Query​ ​is​ ​sent​ ​to​ ​18.72.0.3​ ​which​ ​corresponds​ ​to
bitsy.mit.edu.
Q.21)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS
query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”?
It​ ​is​ ​a​ ​standard​ ​​Type​ ​A​ ​​DNS​ ​Query​ ​and​ ​contains​ ​no​ ​answers.
Q.22)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​How​ ​many​ ​“answers”
are​ ​provided?​ ​What​ ​does​ ​each​ ​of​ ​these​ ​answers​ ​contain?
The​ ​DNS​ ​Response​ ​message​ ​contains​ ​one​ ​answer​ ​as​ ​follows​ ​:

More Related Content

What's hot

Bh us-02-kaminsky-blackops
Bh us-02-kaminsky-blackopsBh us-02-kaminsky-blackops
Bh us-02-kaminsky-blackops
Dan Kaminsky
 
BasepaperControlling IP Spoofing through Interdomain Packet Filters
BasepaperControlling IP Spoofing through Interdomain Packet FiltersBasepaperControlling IP Spoofing through Interdomain Packet Filters
BasepaperControlling IP Spoofing through Interdomain Packet Filters
bhasker nalaveli
 
Controlling ip spoofing through inter domain packet filters(synopsis)
Controlling ip spoofing through inter domain packet filters(synopsis)Controlling ip spoofing through inter domain packet filters(synopsis)
Controlling ip spoofing through inter domain packet filters(synopsis)
Mumbai Academisc
 

What's hot (20)

Dns
DnsDns
Dns
 
Early Detection of Malicious Flux Networks via Large Scale Passive DNS Traffi...
Early Detection of Malicious Flux Networks via Large Scale Passive DNS Traffi...Early Detection of Malicious Flux Networks via Large Scale Passive DNS Traffi...
Early Detection of Malicious Flux Networks via Large Scale Passive DNS Traffi...
 
Lecture17
Lecture17Lecture17
Lecture17
 
Distributed System by Pratik Tambekar
Distributed System by Pratik TambekarDistributed System by Pratik Tambekar
Distributed System by Pratik Tambekar
 
Bh us-02-kaminsky-blackops
Bh us-02-kaminsky-blackopsBh us-02-kaminsky-blackops
Bh us-02-kaminsky-blackops
 
Hands-on getdns Tutorial
Hands-on getdns TutorialHands-on getdns Tutorial
Hands-on getdns Tutorial
 
Distributed System by Pratik Tambekar
Distributed System by Pratik TambekarDistributed System by Pratik Tambekar
Distributed System by Pratik Tambekar
 
Week6 final
Week6 finalWeek6 final
Week6 final
 
Network Security Primer
Network Security PrimerNetwork Security Primer
Network Security Primer
 
Review of TCP- IP CS105 Norwalk CC
Review of TCP- IP CS105 Norwalk CCReview of TCP- IP CS105 Norwalk CC
Review of TCP- IP CS105 Norwalk CC
 
Dns
DnsDns
Dns
 
Network security
Network securityNetwork security
Network security
 
BasepaperControlling IP Spoofing through Interdomain Packet Filters
BasepaperControlling IP Spoofing through Interdomain Packet FiltersBasepaperControlling IP Spoofing through Interdomain Packet Filters
BasepaperControlling IP Spoofing through Interdomain Packet Filters
 
Cryptography and Network security # Lecture 5
Cryptography and Network security # Lecture 5Cryptography and Network security # Lecture 5
Cryptography and Network security # Lecture 5
 
Peer to peer Paradigms
Peer to peer ParadigmsPeer to peer Paradigms
Peer to peer Paradigms
 
Controlling ip spoofing through inter domain packet filters(synopsis)
Controlling ip spoofing through inter domain packet filters(synopsis)Controlling ip spoofing through inter domain packet filters(synopsis)
Controlling ip spoofing through inter domain packet filters(synopsis)
 
Network (IP)
Network (IP)Network (IP)
Network (IP)
 
Kademlia introduction
Kademlia introductionKademlia introduction
Kademlia introduction
 
Introduction to DNS
Introduction to DNSIntroduction to DNS
Introduction to DNS
 
2017 Devoxx MA Deconstructing and Evolving REST Security
2017 Devoxx MA Deconstructing and Evolving REST Security2017 Devoxx MA Deconstructing and Evolving REST Security
2017 Devoxx MA Deconstructing and Evolving REST Security
 

Similar to Lab 04

Wireshark Lab DNS v6.01 Supplement to Computer Networkin.docx
Wireshark Lab DNS v6.01  Supplement to Computer Networkin.docxWireshark Lab DNS v6.01  Supplement to Computer Networkin.docx
Wireshark Lab DNS v6.01 Supplement to Computer Networkin.docx
alanfhall8953
 

Similar to Lab 04 (20)

Wireshark Lab DNS v6.01 Supplement to Computer Networkin.docx
Wireshark Lab DNS v6.01  Supplement to Computer Networkin.docxWireshark Lab DNS v6.01  Supplement to Computer Networkin.docx
Wireshark Lab DNS v6.01 Supplement to Computer Networkin.docx
 
DNS (Domain Name System)
DNS (Domain Name System)DNS (Domain Name System)
DNS (Domain Name System)
 
Dns and irc
Dns and ircDns and irc
Dns and irc
 
Week3 lec 2
Week3 lec 2Week3 lec 2
Week3 lec 2
 
The Application Layer
The Application LayerThe Application Layer
The Application Layer
 
Computer Networks Module 1 - part 2.pdf
Computer Networks Module 1 - part 2.pdfComputer Networks Module 1 - part 2.pdf
Computer Networks Module 1 - part 2.pdf
 
Dns detail understanding
Dns detail understandingDns detail understanding
Dns detail understanding
 
Dns 2
Dns 2Dns 2
Dns 2
 
DNS Security Issues NES 554 for DNS Security
DNS Security Issues  NES 554 for DNS SecurityDNS Security Issues  NES 554 for DNS Security
DNS Security Issues NES 554 for DNS Security
 
08Mapping.ppt
08Mapping.ppt08Mapping.ppt
08Mapping.ppt
 
Domain Name System
Domain Name SystemDomain Name System
Domain Name System
 
Dns
DnsDns
Dns
 
DNSSEC: The Antidote to DNS Cache Poisoning and Other DNS Attacks
DNSSEC: The Antidote to DNS Cache Poisoning and Other DNS AttacksDNSSEC: The Antidote to DNS Cache Poisoning and Other DNS Attacks
DNSSEC: The Antidote to DNS Cache Poisoning and Other DNS Attacks
 
Domain name system
Domain name systemDomain name system
Domain name system
 
Wireshark Lab HTTP, DNS and ARP v7 solution
Wireshark Lab HTTP, DNS and ARP v7 solutionWireshark Lab HTTP, DNS and ARP v7 solution
Wireshark Lab HTTP, DNS and ARP v7 solution
 
Footprinting LAB SETUP GUIDE.pdf
Footprinting LAB SETUP GUIDE.pdfFootprinting LAB SETUP GUIDE.pdf
Footprinting LAB SETUP GUIDE.pdf
 
DNS.pptx
DNS.pptxDNS.pptx
DNS.pptx
 
DIAPOSITIVAS DNS HTTP SMTP
DIAPOSITIVAS DNS HTTP SMTPDIAPOSITIVAS DNS HTTP SMTP
DIAPOSITIVAS DNS HTTP SMTP
 
DNS(Domain Name System)
DNS(Domain Name System)DNS(Domain Name System)
DNS(Domain Name System)
 
Domain Name System Explained
Domain Name System Explained Domain Name System Explained
Domain Name System Explained
 

Recently uploaded

Maher Othman Interior Design Portfolio..
Maher Othman Interior Design Portfolio..Maher Othman Interior Design Portfolio..
Maher Othman Interior Design Portfolio..
MaherOthman7
 
electrical installation and maintenance.
electrical installation and maintenance.electrical installation and maintenance.
electrical installation and maintenance.
benjamincojr
 
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
drjose256
 

Recently uploaded (20)

21scheme vtu syllabus of visveraya technological university
21scheme vtu syllabus of visveraya technological university21scheme vtu syllabus of visveraya technological university
21scheme vtu syllabus of visveraya technological university
 
"United Nations Park" Site Visit Report.
"United Nations Park" Site  Visit Report."United Nations Park" Site  Visit Report.
"United Nations Park" Site Visit Report.
 
CLOUD COMPUTING SERVICES - Cloud Reference Modal
CLOUD COMPUTING SERVICES - Cloud Reference ModalCLOUD COMPUTING SERVICES - Cloud Reference Modal
CLOUD COMPUTING SERVICES - Cloud Reference Modal
 
What is Coordinate Measuring Machine? CMM Types, Features, Functions
What is Coordinate Measuring Machine? CMM Types, Features, FunctionsWhat is Coordinate Measuring Machine? CMM Types, Features, Functions
What is Coordinate Measuring Machine? CMM Types, Features, Functions
 
AI in Healthcare Innovative use cases and applications.pdf
AI in Healthcare Innovative use cases and applications.pdfAI in Healthcare Innovative use cases and applications.pdf
AI in Healthcare Innovative use cases and applications.pdf
 
Augmented Reality (AR) with Augin Software.pptx
Augmented Reality (AR) with Augin Software.pptxAugmented Reality (AR) with Augin Software.pptx
Augmented Reality (AR) with Augin Software.pptx
 
5G and 6G refer to generations of mobile network technology, each representin...
5G and 6G refer to generations of mobile network technology, each representin...5G and 6G refer to generations of mobile network technology, each representin...
5G and 6G refer to generations of mobile network technology, each representin...
 
Operating System chapter 9 (Virtual Memory)
Operating System chapter 9 (Virtual Memory)Operating System chapter 9 (Virtual Memory)
Operating System chapter 9 (Virtual Memory)
 
Low Altitude Air Defense (LAAD) Gunner’s Handbook
Low Altitude Air Defense (LAAD) Gunner’s HandbookLow Altitude Air Defense (LAAD) Gunner’s Handbook
Low Altitude Air Defense (LAAD) Gunner’s Handbook
 
8th International Conference on Soft Computing, Mathematics and Control (SMC ...
8th International Conference on Soft Computing, Mathematics and Control (SMC ...8th International Conference on Soft Computing, Mathematics and Control (SMC ...
8th International Conference on Soft Computing, Mathematics and Control (SMC ...
 
Autodesk Construction Cloud (Autodesk Build).pptx
Autodesk Construction Cloud (Autodesk Build).pptxAutodesk Construction Cloud (Autodesk Build).pptx
Autodesk Construction Cloud (Autodesk Build).pptx
 
Research Methodolgy & Intellectual Property Rights Series 1
Research Methodolgy & Intellectual Property Rights Series 1Research Methodolgy & Intellectual Property Rights Series 1
Research Methodolgy & Intellectual Property Rights Series 1
 
Maher Othman Interior Design Portfolio..
Maher Othman Interior Design Portfolio..Maher Othman Interior Design Portfolio..
Maher Othman Interior Design Portfolio..
 
Fuzzy logic method-based stress detector with blood pressure and body tempera...
Fuzzy logic method-based stress detector with blood pressure and body tempera...Fuzzy logic method-based stress detector with blood pressure and body tempera...
Fuzzy logic method-based stress detector with blood pressure and body tempera...
 
Dynamo Scripts for Task IDs and Space Naming.pptx
Dynamo Scripts for Task IDs and Space Naming.pptxDynamo Scripts for Task IDs and Space Naming.pptx
Dynamo Scripts for Task IDs and Space Naming.pptx
 
electrical installation and maintenance.
electrical installation and maintenance.electrical installation and maintenance.
electrical installation and maintenance.
 
Module-III Varried Flow.pptx GVF Definition, Water Surface Profile Dynamic Eq...
Module-III Varried Flow.pptx GVF Definition, Water Surface Profile Dynamic Eq...Module-III Varried Flow.pptx GVF Definition, Water Surface Profile Dynamic Eq...
Module-III Varried Flow.pptx GVF Definition, Water Surface Profile Dynamic Eq...
 
Lab Manual Arduino UNO Microcontrollar.docx
Lab Manual Arduino UNO Microcontrollar.docxLab Manual Arduino UNO Microcontrollar.docx
Lab Manual Arduino UNO Microcontrollar.docx
 
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
Tembisa Central Terminating Pills +27838792658 PHOMOLONG Top Abortion Pills F...
 
Worksharing and 3D Modeling with Revit.pptx
Worksharing and 3D Modeling with Revit.pptxWorksharing and 3D Modeling with Revit.pptx
Worksharing and 3D Modeling with Revit.pptx
 

Lab 04

  • 1. Lab​ ​04 Name :​ ​Om​ ​Rakesh​ ​Thakkar Roll​ ​No. :​ ​201501109 Subject :​ ​Computer​ ​Networks Batch :​ ​1 Topic :​ ​Wireshark Q.1)​ ​Run​ ​​nslookup​​ ​to​ ​obtain​ ​the​ ​IP​ ​address​ ​of​ ​a​ ​Web​ ​server​ ​in Asia. nslookup​​ ​has​ ​been​ ​performed​ ​for​ ​“​www.paytm.com​”.
  • 2. Q.2)​ ​Run​ ​nslookup​ ​to​ ​determine​ ​the​ ​authoritative​ ​DNS​ ​servers for​ ​a​ ​university​ ​in​ ​Europe. nslookup​ ​​has​ ​been​ ​performed​ ​on​ ​Oxford​ ​University​ ​situated​ ​in Europe.
  • 3. Q.3)​ ​Run​ ​nslookup​ ​so​ ​that​ ​one​ ​of​ ​the​ ​DNS​ ​servers​ ​obtained​ ​in Question​ ​2​ ​is​ ​queried​ ​for​ ​the​ ​mail​ ​servers​ ​for​ ​Yahoo!​ ​Mail. Connection​ ​is​ ​timed​ ​out​ ​and​ ​no​ ​servers​ ​are​ ​reached. Q.4)​ ​Locate​ ​the​ ​DNS​ ​query​ ​and​ ​response​ ​messages.​ ​Are​ ​they​ ​sent over​ ​UDP​ ​or​ ​TCP? DNS​ ​Queries​ ​and​ ​Response​ ​Messages​ ​have​ ​been​ ​located.​ ​They​ ​are sent​ ​over​ ​UDP. DNS​ ​Query
  • 4. DNS​ ​Response Q.5)​ ​What​ ​is​ ​the​ ​destination​ ​port​ ​for​ ​the​ ​DNS​ ​query​ ​message? What​ ​is​ ​the​ ​source​ ​port​ ​of​ ​DNS​ ​response​ ​message? The​ ​Destination​ ​Port​ ​for​ ​DNS​ ​Query​ ​is​ ​53​ ​and​ ​Source​ ​Port​ ​of​ ​DNS Response​ ​is​ ​53. DNS​ ​Query
  • 5. DNS​ ​Response Q.6)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Use ipconfig​ ​to​ ​determine​ ​the​ ​IP​ ​address​ ​of​ ​your​ ​local​ ​DNS​ ​server. Are​ ​these​ ​two​ ​IP​ ​addresses​ ​the​ ​same? The​ ​DNS​ ​Query​ ​message​ ​has​ ​been​ ​sent​ ​to​ ​208.67.222.222,​ ​which​ ​is the​ ​IP​ ​Address​ ​of​ ​one​ ​of​ ​my​ ​local​ ​DNS​ ​Servers​ ​as​ ​shown​ ​in​ ​the image.
  • 6. Q.7)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”? It​ ​is​ ​a​ ​​type​ ​A​​ ​Standard​ ​Query​ ​and​ ​it​ ​doesn’t​ ​contain​ ​any​ ​answers. Q.8)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​How​ ​many​ ​“answers” are​ ​provided?​ ​What​ ​do​ ​each​ ​of​ ​these​ ​answers​ ​contain? There​ ​are​ ​2​ ​answers​ ​provided​ ​in​ ​the​ ​DNS​ ​Response​ ​Message.​ ​They contain​ ​information​ ​about​ ​the​ ​Name​ ​of​ ​host,​ ​Type​ ​of​ ​address,​ ​Class, Time​ ​to​ ​Live,​ ​Data​ ​Length,​ ​IP​ ​Address.
  • 7. Q.9)​ ​Consider​ ​the​ ​subsequent​ ​TCP​ ​SYN​ ​packet​ ​sent​ ​by​ ​your​ ​host. Does​ ​the​ ​destination​ ​IP​ ​address​ ​of​ ​the​ ​SYN​ ​packet​ ​correspond​ ​to any​ ​of​ ​the​ ​IP​ ​addresses​ ​provided​ ​in​ ​the​ ​DNS​ ​response​ ​message? The​ ​first​ ​SYN​ ​packet​ ​was​ ​sent​ ​to​ ​104.20.0.85​ ​which​ ​corresponds​ ​to the​ ​first​ ​IP​ ​address​ ​provided​ ​in​ ​the​ ​DNS​ ​response​ ​message. Q.10)​ ​This​ ​web​ ​page​ ​contains​ ​images.​ ​Before​ ​retrieving​ ​each image,​ ​does​ ​your​ ​host​ ​issue​ ​new​ ​DNS​ ​queries? No,​ ​the​ ​host​ ​issues​ ​DNS​ ​Queries​ ​after​ ​retrieving​ ​the​ ​image.
  • 8. ● nslookup​ ​www.mit.edu Q.11)​ ​What​ ​is​ ​the​ ​destination​ ​port​ ​for​ ​the​ ​DNS​ ​query​ ​message? What​ ​is​ ​the​ ​source​ ​port​ ​of​ ​DNS​ ​response​ ​message? Destination​ ​port​ ​of​ ​DNS​ ​Query​ ​message​ ​is​ ​53​ ​and​ ​Source​ ​Port​ ​of DNS​ ​Response​ ​message​ ​is​ ​53. DNS​ ​Query
  • 9. DNS​ ​Response Q.12)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Is​ ​this the​ ​IP​ ​address​ ​of​ ​your​ ​default​ ​local​ ​DNS​ ​server? It’s​ ​sent​ ​to​ ​208.67.222.222​ ​which​ ​is​ ​the​ ​IP​ ​Address​ ​of​ ​one​ ​of​ ​my​ ​local DNS​ ​Servers​ ​as​ ​shown​ ​in​ ​the​ ​image. Q.13)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”? The​ ​Query​ ​is​ ​​Type​ ​A​ ​​and​ ​the​ ​query​ ​message​ ​contains​ ​no​ ​answers.
  • 10. Q.14)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​How​ ​many​ ​“answers” are​ ​provided?​ ​What​ ​do​ ​each​ ​of​ ​these​ ​answers​ ​contain? The​ ​DNS​ ​Response​ ​message​ ​contains​ ​3​ ​answers​ ​as​ ​shown​ ​below.​ ​It contains​ ​Name​ ​of​ ​host,​ ​type​ ​of​ ​address,​ ​Class,​ ​TTL,​ ​Data​ ​Length​ ​and CName.
  • 11. ● nslookup​ ​–type=NS​ ​mit.edu Q.16)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Is​ ​this the​ ​IP​ ​address​ ​of​ ​your​ ​default​ ​local​ ​DNS​ ​server? It​ ​is​ ​sent​ ​to​ ​208.67.222.222​ ​which​ ​is​ ​one​ ​of​ ​my​ ​local​ ​DNS​ ​Servers. Q.17)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”? It​ ​is​ ​​NS​ ​Type​ ​​DNS​ ​Query​ ​Message​ ​and​ ​contains​ ​no​ ​answers.
  • 12. Q.18)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​What​ ​MIT nameservers​ ​does​ ​the​ ​response​ ​message​ ​provide?​ ​Does​ ​this response​ ​message​ ​also​ ​provide​ ​the​ ​IP​ ​addresses​ ​of​ ​the​ ​MIT nameservers? The​ ​nameservers​ ​are​ ​usw2,​ ​ns1-173,​ ​ns1-37,​ ​asia1,​ ​use2,​ ​use5,​ ​eur5, asia2.​ ​We​ ​can​ ​find​ ​their​ ​IP​ ​addresses​ ​if​ ​we​ ​expand​ ​the​ ​Additional records​ ​field​ ​in​ ​Ethereal​ ​as​ ​shown​ ​in​ ​the​ ​image​ ​below.
  • 13. ● nslookup​ ​www.aiit.or.kr​ ​bitsy.mit.edu Q.20)​ ​To​ ​what​ ​IP​ ​address​ ​is​ ​the​ ​DNS​ ​query​ ​message​ ​sent?​ ​Is​ ​this the​ ​IP​ ​address​ ​of​ ​your​ ​default​ ​local​ ​DNS​ ​server?​ ​If​ ​not,​ ​what​ ​does the​ ​IP​ ​address​ ​correspond​ ​to? The​ ​DNS​ ​Query​ ​is​ ​sent​ ​to​ ​18.72.0.3​ ​which​ ​corresponds​ ​to bitsy.mit.edu.
  • 14. Q.21)​ ​Examine​ ​the​ ​DNS​ ​query​ ​message.​ ​What​ ​“Type”​ ​of​ ​DNS query​ ​is​ ​it?​ ​Does​ ​the​ ​query​ ​message​ ​contain​ ​any​ ​“answers”? It​ ​is​ ​a​ ​standard​ ​​Type​ ​A​ ​​DNS​ ​Query​ ​and​ ​contains​ ​no​ ​answers. Q.22)​ ​Examine​ ​the​ ​DNS​ ​response​ ​message.​ ​How​ ​many​ ​“answers” are​ ​provided?​ ​What​ ​does​ ​each​ ​of​ ​these​ ​answers​ ​contain? The​ ​DNS​ ​Response​ ​message​ ​contains​ ​one​ ​answer​ ​as​ ​follows​ ​: