<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Khoahoc by mai1 Quyug</title>
      <link>https://padlet.com/ngochoangquydu5/Hoc</link>
      <description>Được tạo ra từ phép thuật</description>
      <language>en-us</language>
      <pubDate>2021-01-27 01:31:02 UTC</pubDate>
      <lastBuildDate>2021-01-29 02:21:04 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Khóa giám sát, phân tích, an toàn hệ thống 27-02-2021(Day 1_PDF_503.1)</title>
         <author></author>
         <link>https://padlet.com/ngochoangquydu5/Hoc/wish/1129573564</link>
         <description><![CDATA[<div>- Mô hình TCP/IP: 4 lớp.<br>- Khái niệm: bits, nibbles, byte,<br><strong>I. Mô hình TCP/IP:<br>1.</strong><br><em>- Applocation : https, smtp, dns<br>- Transport: TCP, UDP (bắt tay ba bước)<br>- Internet: IP <br>- Network Access: IEEE 802.x  <br>-IPV4: 32 bit<br>-Nibble= 4 bít or one hexadecimal value.<br>-Bit= smallest unit - has a value of 0 or 1<br>-Byte= 8 bit</em><br><strong>2. tcpdum -r *.pcap -n -x </strong><br>-r: là  read file *.pcap<br>-n: không hiển thị gói tin dưới dạng hex phải thêm -x thì mới hiển thị.<br>wireshark: <br>-Tính năng File packet <br>802.3: Ethernet<br>802.11: <br>- install xarp + arpwatch.<br>-Time to Live: gói tin đi nhiều nơi qua nhiều router. Được set các giá trị ttl giảm dần đến 0 rồi bị drop. (tracert sử dụng timetolive để xác định đường đi xác định điểm bị ngắt kết nối/ )<br><strong>- IPV6:<br>DAY 2 (PDF 503.2)</strong><br>-Wireshark Display Filters: ------( Điểm manh, tập trung gói tin quan trọng)<br>+ tcp.port == 25 -----(lọc ra port 25)<br>+ ip.src == 192.168.11.65<br>+ simple indicator of presence of protocol/field</div><ul><li> dns</li><li> ftp.response</li></ul><div>+ Indicator of condition</div><ul><li> ip.fragment.overlap</li><li>udp.checksum_bad</li></ul><div>+ Tim theo dns</div><ul><li>dns.qry.name contains "evil"</li><li>dns.qry.name matches "^evil" ----(tìm tên miền bắt đầu bằng evil)</li><li>ip.addr != 65.55.111.78 ----(Lọc trừ ip * ra khỏi hiển thị tìm kiếm.)</li><li>ip.addr == 65.55.111.78 ---(gói tin có IP * được hiển thị)</li><li>http.accept contains "hinh1" --------(Tìm trong giao thức http có key hinh1)</li><li>Analyze&gt;Display Filters --------(Thêm những phương thức  gợi ý để search)</li><li>Analyze&gt;Display Filter Expression -------(gợi ý lệnh để search)</li><li>Statistics&gt;Converstations&gt;TCP 27 (Xem byte nhiều thì có thế ai đó đang dowload)</li><li>ip.options.record_route == 07:03:04 ----()</li><li>edit&gt;Mark All Display ------(Lưu mới các gói tin đang được filter</li><li>)</li></ul><div>-Scan = hping3  &gt;&gt; des port =0<br>- ptunnel: ptunnel -x 123123 -c eth0 -v 4 -f ptunnel.log (sever)<br>- client: sudo ptunnel -p 10.1.1.11 -lp 80 -da 127.0.0.1 -dp 80 -v 4 -f pTunnel-c.log -x 123123<br>-<a href="https://www.mediafire.com/folder/mxh23szwtskcu/training123123"> </a> attack-trace  pcap</div>]]></description>
         <pubDate>2021-01-27 01:32:48 UTC</pubDate>
         <guid>https://padlet.com/ngochoangquydu5/Hoc/wish/1129573564</guid>
      </item>
   </channel>
</rss>
