Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

A security analyst is reviewing packet captures for a specific server that is suspected of containing malware and discovers the following packets 138-23.45.201 73.252.34.101 TOP

image text in transcribed
A security analyst is reviewing packet captures for a specific server that is suspected of containing malware and discovers the following packets 138-23.45.201 73.252.34.101 TOP 56712dna (53) (syN) seq o Win 4128 Len o MBS-1460 73.252.34.101 138.23.45.201 TCP dna (53) -> 56712 tsen, ACSI seqe Ack#1 win-4128 Len-o 138.23.45.201 73.252.34.101 TCP 567 12-> dns(53) [ACK] 3eq-1 Ack 1 win-4128 Len#0 73.252.34.101 138.23.45.201 33H Server1 Protocol (33H-2.0-ciaco-i.25) :38.23.45.201 73.252.34.101 83H c1ient: Protocol (338-1.99-cisco-1.25) 73.252.34.101 138.23.45.201 sav2 Server: Key Exchange Init 103.34.243.12 73.252.34.101 TCP 62014Etp (21) (8YN) Seqo Win 65535 Len- 73.252.34.101 103.34.243.12 Tep ftp (21) -> 62014 [STH, ACK] 3eq#0 Ack#1 win-S792 lento 03.34.243.12 73.252.34.101 CP 62014 -Etp (21) (ACK) Seql Ack 1 win 65535 en-o 73.252.34.101 103.34.243.12 FT Response: 220 PEOFTPD 1.3.0a server 03.34.243.12 73.252.34.101 FTP Request: USER Etp 73.252.34.102 103.34.243.12 FE Response: 331 Anonymous login ok, send your complete email address s your password 103.34.243.12 73.252.34.101 FEP Request: PAss ftp 73.252.34.101 103.34.243.12 rp Reaponse : 230 Anonymous access granted, ceateictions apply. win-57 92 Len-O MSgz1460 8ACK FERF TSTalag 3 5 172 936 Taecr-22 16538 ws-64 TCP 8080-> 57678 sw, ACK] .q#0 Ack-1 73.252.34.101 202.53.245.78 73.252.24.101 Tep 57678-> 80eo tacr] seri Ack-1 win-saae ten-O Traja22 16S 43 TIeer.8 35172,36 202.53.245.78 73.252.34.101 HTEP GET images/layout/1ogo.pg H/ 202.53.2457e 73.252.34.101 TCP 5767e-> eoe0 [ACK] 8eq-13S Ack"2897 wia#1 1648 Which of the following traffic patterns or data would be MOST concerning to the secunity 202.53.245.78 H72P/1. Len#0 TSval-22165e ?secr63S1729E Ports used for SMTP traffic from 73 252 34 101 B Unencrypted password sent from 103 34 243 12 C Anonymous access granted by 103 34 243 12 Pornt used or HTTPta2053 245 78

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Professional SQL Server 2000 Database Design

Authors: Louis Davidson

1st Edition

1861004761, 978-1861004765

More Books

Students also viewed these Databases questions

Question

2. Do you find change a. invigorating? b. stressful? _______

Answered: 1 week ago

Question

10. Are you a. a leader? b. a follower? _______

Answered: 1 week ago