UB University of Baltimore
Merrick School of Business


INSS 453/753 - Internet and Network Security

Mini-project 4: testing network and wireless devices.

All mini-projects are due on Wednesdays by 11 PM.

Go to the MISLAB and log in Windows or Linux, as needed, like you did in prior mini-projects, then prepare a report including the following:

  1. Select a well known organization and use traceroute to find a border router, as seen in class.

  2. Use SuperScan and WUPS seen previously or Nmap (in Linux) to scan ports belonging to routers. Hint: Use or adapt my file routers.txt to use with SuperScan (rename the file to routers.lst) or Nmap. Consult the table in page 361 of the textbook and try to identify the brand of the router.

  3. Using Nmap and other Windows tools identify the Operating system running in the router. Go to the company Web site and locate a manual for the OS you found (e.g, for the in class example - IOS 12.2.1 you can see its page here).

  4. Read the documentation for the OS you found and explain how it can be accessed remotely with telnet, if possible. Telnet to the router and, using the database of passwords, try to login, capture the image even if you are denied login (fail password). In the remote possibility you succeed, capture the image, and try to issue a simple command to list the configuration file (see book and OS documentation), and, of course, capture the image with the list of the configuration file.

  5. Install Dsniff in Linux using an rpm file (If you forgot how to install using RPM see this tutorial). Start it, ftp to home.ubalt.edu, disconnect and see what happens. What other functions than capturing passwords can Dsniff be used for? Try to use it to do, at least, one other type of packet sniffing, and capture the image.

  6. If you have a laptop with a wireless card install NetStumbler and use it at UB to identify some APs you can find. (If you don't see if you can borrow one temporarily).
  7. Explain the difference between WEP, EAP, and WAP. What kind of authentication is used at UB?

  8. Use Ethereal again in Linux. See if you can place it in promiscuous mode, then show me what you did and what you captured. (Note: this operation would be similar to having a laptop running Linux in a wardriving).

Submitting the report


This page is maintained by Al Bento who can be reached at abento@ubalt.edu This page was last updated on October 28, 2007. Although we will attempt to keep this information accurate, we can not guarantee the accuracy of the information provided.