Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Computer Network & Security Expert

QUESTION 1

(a) Describe what a Turtle Shell Architecture is and give an instance.

(b) Briefly clarify the principle of least privilege using an appropriate instance.

(c) Judge the following block of codes underneath.

Include("db_connect.php")://handles database connection
$sql="INSERT
INTO users(reg_username,
Reg_password,
Reg_email)
VALUES(‘{$_POST[‘reg_username']}'
‘$reg_password'.
‘{$_POST[reg_email']})':
Mysql_close():
?>

Imagine that this query is creating a new account. The user gives a desired username and an email address. The registration application generates a temporary password and emails it to the user to verify the email address.

If a valid email address is given (jeff.shield@gmail.com, for example), and "hamp98" is what the application generates for the password.
Give explanation whether an SQL injection attack is possible. Explicate your reasoning with an appropriate example.

(d) Let's presume a query in a product detail page as follows:
$sql="SELECT*FROMproductWHEREproduct_id='".$_GET[‘product_id]."'";

Now an intruder inserts an SQL command in the URL of the page, the code is like this 10'; DROP TABLE product; # and the URL looks like this:

http://abcfoods.com/product.php?id=10'; DROP TABLE product; #

At this instant the query becomes this:

SELECT * FROM product WHERE product_id='10'; DROP TABLE product; #';

You might be doubting what the meaning of hash "#" is. It simply tells the MYSQL server to ignore the rest of the query.
Explain what happen when the URL is processed with the injection as shown above.

(e) Briefly portray four methods how confidentiality can be ensured.

(f) Jane wishes to transfer $100 to Bob using bank.com. The request generated by Jane will look similar to the subsequent:

POST http://bank.com/transfer.phpHTTp/1.1
....
....
....
Content-Length:19:
Acct=BOB&amount=100

On the other hand, Maria notices that the same web application will execute the same transfer using URL parameters as tag along:

GET http://bank.com/transfer.php?acct=100HTTP/1.1


Maria now made a decision to exploit this web application vulnerability using Jane as her victim. Maria has to construct the URL which will transfer $100,000 from Jane's account to her account.

(i) Create the above URL for Maria

At this instant that her malicious request is generated, Maria must trick Jane into submitting the request. The most basic method is to send Jane an HTML email containing the link and expect Jane to click on it.

Assuming Jane is authenticated with the application when she clicks the link, the transfer of $100,000 to Maria's account will occur. However, Maria realizes that if Jane clicks the link, then Jane will notice that a transfer has occurred. as a result, Maria come to a decision to hide the attack in a zero-byte image.

(ii) Write the code that Maria must send to Jane in the email making use of a zero-byte representation.

(iii) Describe using an appropriate example how bank.com can prevent such security vulnerability.

(g) Portray three types of biometric identification schemes.

QUESTION 2

(a) In essence security is holistic. Explain this reasoning using appropriate examples.

(b) All secure systems should aim at providing some security concepts. Explain seven of them.

(c) Explicate three ways to authenticate a user and give an example of a real world two-factor authentication.

(d) What is an Access Control List?

(e) Present two ways how webmasters can ensure maximum availability of their web applications.

(f) Describe what happen during a DNS Cache Poisoning attack.

QUESTION 3

(a) Tell apart symmetric and public key encryption cryptographic systems and their modes of operation.

(b) Describe what hash functions are and using a suitable example show how to Work out the hash on a string using MD5.

(c) Elucidate what you understand by the terms hash collision and rainbow tables giving an appropriate example for each. Also describe how they can be prevented.

(d) Mark a 16-pass iterative and 9-pass recursive PHP function using hash algorithm sha1 and salt "iamsexyandiknowit" to hash password "passwordcanon".

Computer Network & Security, Computer Science

  • Category:- Computer Network & Security
  • Reference No.:- M9133739

Have any Question?


Related Questions in Computer Network & Security

With smaller companies saving thousands and larger

With smaller companies saving thousands and larger companies saving billions through flexible manufacturing, if you are a discrete parts manufacturer seeking to be more lean, it is important to consider whether this migh ...

From the product designed expanded as follows1 from your

From the product designed expanded as follows. 1. From your list of possible responses to the threat, choose one that you will focus on in this product. Create the requirements for your product by completely identifying ...

You just signed a 30-year lease agreement for a business

You just signed a 30-year lease agreement for a business property. The monthly rent for the first year is $1,000/month, with the ?rst month's rent due today. Starting from the second year onward, the monthly rent will be ...

Two countries australia and france have their interest

Two Countries Australia and France have their interest rates to be 8% and 2 %, respectively. If their currencies trade according to 2 Australian $s buy one euro in the spot market, what will their future spot rate be in ...

Advanced network design assessment - human factors in

Advanced Network Design Assessment - Human factors in network analysis and design Purpose of the assessment - This assignment is designed to assess students' knowledge and skills related to the following learning outcome ...

Advanced network design assessment - human factors in

Advanced Network Design Assessment - Human factors in network analysis and design Purpose of the assessment - This assignment is designed to assess students' knowledge and skills related to the following learning outcome ...

Metasoft ltd is a software development company which works

MetaSoft Ltd is a software development company which works across Australia and New Zealand. The company is considering the following strategic proposal: - They plan to close down the Melbourne data centre rather than up ...

Overviewthis assignment has three major aims- to help

Overview This assignment has three major aims: - To help students gain good understanding of theoretical and practical material. - To encourage students to use content analysis summaries to prepare for tests, examination ...

Question for the remaining questions consider a 4-bit block

Question : For the remaining questions, consider a 4-bit block cipher, described in hexadecimal by the following table: Plaintext Ciphertext Plaintext Ciphertext 0 a 8 e 1 c 9 d 2 f a 0 3 6 b 7 4 3 c 5 5 8 d b 6 4 e 9 7 ...

Assessment - network analysis using wiresharkpurpose of the

Assessment - Network Analysis using Wireshark Purpose of the assessment (with ULO Mapping) This assignment is designed to develop deeper analytical understanding of different distributed network conditions. At the comple ...

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As