1
00:00:06,510 --> 00:00:08,627
- [Lecturer] In this segment,
we're gonna take a closer look

2
00:00:08,627 --> 00:00:13,595
at secure and insecure
protocols, specifically SSL

3
00:00:13,595 --> 00:00:16,407
and TLS and FTP.

4
00:00:16,407 --> 00:00:20,553
Now to do this we're gonna use
Wireshark to capture packets.

5
00:00:21,600 --> 00:00:25,140
So I have Wireshark installed
and configure it on my system.

6
00:00:25,140 --> 00:00:28,860
I've configured it to resolve
IP addresses to host names.

7
00:00:28,860 --> 00:00:31,770
So you won't just see source
IP and destination IP,

8
00:00:31,770 --> 00:00:34,080
but you'll also see the host names.

9
00:00:34,080 --> 00:00:38,220
And we're going to start with
capturing wireless traffic.

10
00:00:38,220 --> 00:00:41,280
So I'm gonna go to wifi

11
00:00:41,280 --> 00:00:44,370
and I'm going to start
capturing wireless traffic.

12
00:00:44,370 --> 00:00:47,550
I do happen to have a
browser open right now,

13
00:00:47,550 --> 00:00:51,360
pointing to Google and
I'm actually gonna go over

14
00:00:51,360 --> 00:00:54,420
to my browser as you're
watching the screen.

15
00:00:54,420 --> 00:00:57,430
And I am going to open up cnn.com

16
00:01:02,700 --> 00:01:05,913
and we'll need to resolve to cnn.com.

17
00:01:07,920 --> 00:01:09,030
We're gonna get some news,

18
00:01:09,030 --> 00:01:12,720
but we're also going to
get some advertising.

19
00:01:12,720 --> 00:01:15,135
We're gonna get some video feeds

20
00:01:15,135 --> 00:01:18,723
and we're gonna get some
content from other providers.

21
00:01:20,133 --> 00:01:23,700
So you can see all the
connections going at this point.

22
00:01:23,700 --> 00:01:26,763
And just having CNN open on my browser.

23
00:01:30,480 --> 00:01:33,213
All right, I am going
to close my browser now.

24
00:01:34,560 --> 00:01:37,710
I'm gonna come back over to Wireshark

25
00:01:37,710 --> 00:01:41,220
and I am going to stop the packet capture.

26
00:01:41,220 --> 00:01:44,460
So what you're seeing in
Wireshark on the top third

27
00:01:44,460 --> 00:01:47,940
of the screen, these are all
the packets that were captured

28
00:01:47,940 --> 00:01:49,650
during that session.

29
00:01:49,650 --> 00:01:53,940
What you're seeing in the
middle of the screen is details

30
00:01:53,940 --> 00:01:56,280
of the packet that's
highlighted in the upper part

31
00:01:56,280 --> 00:01:57,480
and then on the lower part

32
00:01:57,480 --> 00:01:59,880
of the screen what you're
seeing is the payload.

33
00:02:00,900 --> 00:02:03,360
So one things that we're
most interested here in is,

34
00:02:03,360 --> 00:02:05,700
is how are we communicating
in the browser?

35
00:02:05,700 --> 00:02:07,320
Are we communicating securely?

36
00:02:07,320 --> 00:02:09,330
Meaning are we using SSL

37
00:02:09,330 --> 00:02:12,690
or TLS both running on port 443?

38
00:02:12,690 --> 00:02:14,760
And which one are we using?

39
00:02:14,760 --> 00:02:16,470
SSL or TLS?

40
00:02:16,470 --> 00:02:19,230
And if we're using TLS, what version?

41
00:02:19,230 --> 00:02:21,810
So I'm just gonna apply a filter here.

42
00:02:21,810 --> 00:02:23,733
I'm gonna look for SSL.

43
00:02:24,600 --> 00:02:27,120
And interestingly enough,
what gets returned

44
00:02:27,120 --> 00:02:30,903
to me is a lot of TLS protocol packets.

45
00:02:32,010 --> 00:02:33,733
I'm move this down a little bit

46
00:02:33,733 --> 00:02:35,003
so you can see a little bit better here.

47
00:02:36,253 --> 00:02:39,660
So when I do my filter for SSL, again

48
00:02:39,660 --> 00:02:41,430
TLS is getting returned.

49
00:02:41,430 --> 00:02:42,933
And if I scroll down,

50
00:02:45,300 --> 00:02:49,290
what I'm seeing is actually no SSL

51
00:02:49,290 --> 00:02:51,870
and all of the connections were TLS.

52
00:02:51,870 --> 00:02:55,650
And you can see that some
of them are TLS version 1.2

53
00:02:55,650 --> 00:02:59,103
and some of them are TLS version 1.3.

54
00:03:00,420 --> 00:03:02,640
Again, I have a number
of different connections

55
00:03:02,640 --> 00:03:04,740
that are happening simultaneously.

56
00:03:04,740 --> 00:03:07,440
Some cases I'm connected
to the Turner Network

57
00:03:07,440 --> 00:03:09,960
and others to other content
that's being served up

58
00:03:09,960 --> 00:03:14,247
maybe video as well as the
initial connection to Google.

59
00:03:17,250 --> 00:03:20,970
We can see some Client
Hellos, we can see exchange

60
00:03:20,970 --> 00:03:25,920
of cipher information, see
exchange Server Hellos.

61
00:03:25,920 --> 00:03:29,280
So a lot that's going on
here in this TLS session.

62
00:03:29,280 --> 00:03:31,050
But really what I wanted to ensure was

63
00:03:31,050 --> 00:03:34,980
that my connections was using SSL or TLS

64
00:03:34,980 --> 00:03:37,737
and preferably not SSL and preferably TLS

65
00:03:37,737 --> 00:03:40,380
and TLS version 1.2 and above.

66
00:03:40,380 --> 00:03:43,950
And so we've gotten our assurance
from capturing the packets

67
00:03:43,950 --> 00:03:46,110
and being able to look specifically

68
00:03:46,110 --> 00:03:47,733
for the type of protocol.

69
00:03:49,200 --> 00:03:51,640
I am going to clear this now

70
00:03:54,960 --> 00:03:56,820
and I wanna show you something else.

71
00:03:56,820 --> 00:03:59,280
I wanna show you what an
insecure protocol looks

72
00:03:59,280 --> 00:04:01,740
like when you're doing a packet capture.

73
00:04:01,740 --> 00:04:05,280
So I am going to run FTP locally

74
00:04:05,280 --> 00:04:07,980
on my machine and do a login.

75
00:04:07,980 --> 00:04:12,780
Now, FTP in and of itself is
considered an insecure protocol

76
00:04:12,780 --> 00:04:15,210
because it's a clear text protocol.

77
00:04:15,210 --> 00:04:17,400
So what I'm gonna do is
I'm gonna start capturing

78
00:04:17,400 --> 00:04:18,780
with my loop back adapter.

79
00:04:18,780 --> 00:04:21,063
So that's looking just at my local system.

80
00:04:23,850 --> 00:04:26,560
And I'm gonna bring up a command prompt

81
00:04:29,730 --> 00:04:31,563
and I'm gonna start FTP.

82
00:04:33,810 --> 00:04:36,540
And I am gonna say, I open a session

83
00:04:36,540 --> 00:04:37,920
and I'm gonna open a session

84
00:04:37,920 --> 00:04:42,920
on my local host and it ask me to log in.

85
00:04:43,830 --> 00:04:45,990
I'm gonna log in as anonymous

86
00:04:45,990 --> 00:04:47,730
and it says anonymous access allowed.

87
00:04:47,730 --> 00:04:49,642
And it's gonna suggest I send my identity

88
00:04:49,642 --> 00:04:52,170
my email name as a password.

89
00:04:52,170 --> 00:04:55,593
I'll just use sari@sari.com.

90
00:04:56,880 --> 00:04:59,340
And there's an issue, it's
not allowing me to log in.

91
00:04:59,340 --> 00:05:01,980
That's really irrelevant
because what I wanna show you

92
00:05:01,980 --> 00:05:05,160
is that all of that login
information was captured

93
00:05:05,160 --> 00:05:07,950
and will be viewable in clear text.

94
00:05:07,950 --> 00:05:10,690
So I am going to just
close out this session

95
00:05:11,760 --> 00:05:14,220
and now we're gonna come
back into our packet capture.

96
00:05:14,220 --> 00:05:16,890
I'm gonna clear the filter
because nothing I did was SSL

97
00:05:16,890 --> 00:05:20,853
and our filter is still asking
just to show SSL traffic.

98
00:05:22,230 --> 00:05:25,980
All right, so now we have all
the packets we just captured

99
00:05:25,980 --> 00:05:29,340
during the local host session.

100
00:05:29,340 --> 00:05:33,213
And what I'm gonna do now is
apply another filter to FTP.

101
00:05:35,310 --> 00:05:36,810
And I wanna call your attention

102
00:05:36,810 --> 00:05:38,430
to the right hand side of the screen.

103
00:05:38,430 --> 00:05:42,240
You can see that I started
the Microsoft FTP service.

104
00:05:42,240 --> 00:05:44,310
You can see the command was successful.

105
00:05:44,310 --> 00:05:47,010
You can see where it says user right here.

106
00:05:47,010 --> 00:05:51,150
That user logged in with the
credentials of anonymous.

107
00:05:51,150 --> 00:05:52,470
Then the message that came back

108
00:05:52,470 --> 00:05:54,990
that said anonymous access was allowed.

109
00:05:54,990 --> 00:05:58,080
Then the password, which
I use sari@sari.com.

110
00:05:58,080 --> 00:05:59,910
And then there was that
error message that we saw

111
00:05:59,910 --> 00:06:03,898
that the user couldn't log
in and then the quick command

112
00:06:03,898 --> 00:06:07,710
and then the FTP service
shutting down and saying goodbye.

113
00:06:07,710 --> 00:06:10,260
The key here is in this insecure protocol,

114
00:06:10,260 --> 00:06:13,500
this clear text protocol
we could see everything

115
00:06:13,500 --> 00:06:14,340
that happened.

116
00:06:14,340 --> 00:06:17,490
When we were looking at
the SSL or TLS connections,

117
00:06:17,490 --> 00:06:22,350
we weren't getting that clear
view right into the payload,

118
00:06:22,350 --> 00:06:25,053
the data that was being
transmitted back and forth.

119
00:06:26,070 --> 00:06:27,660
So I've done all this with Wireshark.

120
00:06:27,660 --> 00:06:29,880
This was just a really,
really brief overview

121
00:06:29,880 --> 00:06:32,940
and introduction to Wireshark
if you haven't seen it before.

122
00:06:32,940 --> 00:06:36,141
I think it's an absolutely
critical skill to have

123
00:06:36,141 --> 00:06:40,020
to be able to capture
traffic and to analyze that.

124
00:06:40,020 --> 00:06:43,530
So if you aren't familiar
with using a tool similar

125
00:06:43,530 --> 00:06:45,480
to Wireshark or using Wireshark,

126
00:06:45,480 --> 00:06:47,970
I would strongly suggest
that you download it

127
00:06:47,970 --> 00:06:49,823
and just start working with it.

128
00:06:49,823 --> 00:06:53,430
Once you have it installed
and again, it's free.

129
00:06:53,430 --> 00:06:55,980
There's a really good help section.

130
00:06:55,980 --> 00:06:58,140
You can get to their website,
you can ask questions.

131
00:06:58,140 --> 00:07:00,120
There's FAQs, there's sample captures

132
00:07:00,120 --> 00:07:01,470
there's a really good wiki.

133
00:07:02,430 --> 00:07:05,527
Again, knowing this is good for the exam,

134
00:07:05,527 --> 00:07:08,070
but it's really, really essential

135
00:07:08,070 --> 00:07:11,871
for every cybersecurity
professional to be able

136
00:07:11,871 --> 00:07:14,460
to do this kind of work regardless

137
00:07:14,460 --> 00:07:16,980
of what your specialty area is.

138
00:07:16,980 --> 00:07:18,960
And that's a closer look

139
00:07:18,960 --> 00:07:23,103
at packet capture and in
insecure and secure protocols.
