import socket

# Change the following host and see what IP it prints!
host = "google.com"
ip = socket.gethostbyname(host)

print(ip)
142.250.189.14
with socket.socket(socket.AF_INET, socket.SOCK_STREAM) as s:
    s.connect((ip, 80))
    print("Successfully connected!")
Successfully connected!

Check-In

  1. What is an IP address?
  • an IP address is a unique set of numbers assigned to every device that's connected to the internet, allowing it to be identified and communicate with other devices on the network.
  1. What is a TCP port?
  • a TCP port is a numbered endpoint on a device that's used to identify a specific process or application that's communicating over a network using the TCP/IP protocol.

Slide Hacks

  1. What does DNS stand for?
  • Domain Name Service
  1. What is the purpose of DNS?

Its goal is to provide each domain name an IP address. For users to access websites and other online resources by their well-known names rather than cryptic numerical IP addresses, it serves as a phonebook for the internet.

  1. How does DNS work?

When you enter a domain name into your web browser, such as www.googledocs.com, your computer asks a DNS server for the IP address that corresponds to that domain name. The IP address linked to the domain name is then found in the DNS server's database and sent back to your machine. Following that, your computer connects to the server hosting the website you requested using that IP address.

  1. What is a DNS resolver?

It is a computer program or service that aids your device in locating the IP address connected to a desired internet domain name. The DNS resolver converts a domain name you enter into a corresponding IP address so that your device may connect to the correct server and show the website or other online resource you requested when you input it into your web browser.

with socket.socket(socket.AF_INET, socket.SOCK_STREAM) as s:
    s.connect((ip, 80))

    # Send a GET request to "/"
    s.sendall(b"GET / HTTP/1.1\r\n\r\n")

    # Recieve & print 2048 bytes of data
    data = s.recv(2048)
    print(data.decode())
HTTP/1.1 200 OK
Date: Wed, 26 Apr 2023 20:54:58 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=ISO-8859-1
Content-Security-Policy-Report-Only: object-src 'none';base-uri 'self';script-src 'nonce-W7XcOGwMmw9CdAnPlXd9Vg' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp
P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
Server: gws
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
Set-Cookie: 1P_JAR=2023-04-26-20; expires=Fri, 26-May-2023 20:54:58 GMT; path=/; domain=.google.com; Secure
Set-Cookie: AEC=AUEFqZe6i5T_3eyU7u-v-I66dcAJthEwkMnN7kzk2Po8rqvYjBVsB_VJPhM; expires=Mon, 23-Oct-2023 20:54:58 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=lax
Set-Cookie: NID=511=TS4R1JI9boppaYrtmpI_TI22eHA1D27zXVO2OYbS2UpxZf1s11oKJPO4eBc9EZ8D_y52Hozkwb7-lLGKFA_SlsNKW9WanJeRj3OeGCi6jsLeiYBmuinpiFh3-2g9DfXPyoetfPzYFOk3IWCPO4uyRukKHx0mnWFSVD22dRYpQo0; expires=Thu, 26-Oct-2023 20:54:58 GMT; path=/; domain=.google.com; HttpOnly
Accept-Ranges: none
Vary: Accept-Encoding
Transfer-Encoding: chunked

5a97
<!doctype html><html itemscope="" itemtype="http://schema.org/WebPage" lang="en"><head><meta content="Search the world's information, including webpages, images, videos and more. Google has many special features to help you find exactly what you're looking for." name="description"><meta content="noodp" name="robots"><meta content="text/html; charset=UTF-8" http-equiv="Content-Type"><meta content="/images/branding/googleg/1x/googleg_standard_color_128dp.png" itemprop="image"><title>Google</title><script nonce="W7XcOGwMmw9CdAnPlXd9Vg">(function(){window.google={kEI:'oo9JZPGbLJv7kPIPka6IgAs',kEXPI:'0,1359409,6058,207,4804,2316,383,246,5,1129120,1633,1196140,621,380097,16114,19398,9286,22430,1362,12320,17579,4998,13228,3847,38444,2872,2891,3926,214,4209,3405,606,29880,788,30022,15324,432,3,1590,1,16916,2652,4,1528,2304,24858,4204,13065,16638,1457,16786,5821,2536,4094,7596,1,11942,
import requests

# Change the URL to whatever you'd like
response = requests.get("https://google.com")

print("Status code:", response.status_code)
print("Headers:", response.headers)
print("Response text:", response.text[:100])

# Add a line to print the "Content-Type" header of the response
# Try an image URL!
Status code: 200
Headers: {'Date': 'Wed, 26 Apr 2023 20:55:05 GMT', 'Expires': '-1', 'Cache-Control': 'private, max-age=0', 'Content-Type': 'text/html; charset=ISO-8859-1', 'Content-Security-Policy-Report-Only': "object-src 'none';base-uri 'self';script-src 'nonce-H1FMeaCZcrg7lLbFlcj6_Q' 'strict-dynamic' 'report-sample' 'unsafe-eval' 'unsafe-inline' https: http:;report-uri https://csp.withgoogle.com/csp/gws/other-hp", 'P3P': 'CP="This is not a P3P policy! See g.co/p3phelp for more info."', 'Content-Encoding': 'gzip', 'Server': 'gws', 'X-XSS-Protection': '0', 'X-Frame-Options': 'SAMEORIGIN', 'Set-Cookie': '1P_JAR=2023-04-26-20; expires=Fri, 26-May-2023 20:55:05 GMT; path=/; domain=.google.com; Secure, AEC=AUEFqZc29zhEEf2bT9IdMUNvrK92J5FHz0FnqYHhayWTN_S_3LJNUORMTQ; expires=Mon, 23-Oct-2023 20:55:05 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=lax, NID=511=tQWQq421FTJO-Z9fbha_pBypYRYhIg6bXeQWYdp82dScYEEGGCnCSw5odOsgmlYkKRlG40UPksbUr1wjxpOoF62Ya5gpNEghzNKN3LC6WT6b0LdYZk4hoWkJl2A6MRfOHMxIgRdzmKv0CSm6k3HHVtV4DromEQp089fWmxTwNS8; expires=Thu, 26-Oct-2023 20:55:05 GMT; path=/; domain=.google.com; HttpOnly', 'Alt-Svc': 'h3=":443"; ma=2592000,h3-29=":443"; ma=2592000', 'Transfer-Encoding': 'chunked'}
Response text: <!doctype html><html itemscope="" itemtype="http://schema.org/WebPage" lang="en"><head><meta content

NGINX

aws = "3.130.255.192"

response = requests.get("http://" + aws)
print(response.text)
<html><body onload="document.forms[0].submit()">
<form action="https://ckf03.powayusd.com/cgi-bin/blockpage/poway.cgi" method="GET">
<input type="Hidden" name="URL" value="3.130.255.192">
<input type="Hidden" name="CAT" value="Non-Managed">
<input type="Hidden" name="CATNO" value="-1">
<input type="Hidden" name="ACC" value="1908901/pusd">
<input type="Hidden" name="WHY" value="Policy=student_hs; AD Group=idm-all_students_hs">
<input type="Hidden" name="MOD" value="2">
<input type="Hidden" name="APP" value="spotify">
<input type="Hidden" name="ISO" value="App Permanently Blocked">
<input type="Hidden" name="IPA" value="172.16.1.7">
<input type="Hidden" name="RAW" value="http://3.130.255.192">
<input type="Hidden" name="AUTH0" value=",Non-Managed">
<input type="Hidden" name="PGE" value="https://ckf03.powayusd.com/cgi-bin/blockpage/poway.cgi">
<input type="Hidden" name="STR" value="null,null,null,null,null">
<input type="Hidden" name="SRV" value="null">
<input type="Hidden" name="AUTH1" value=",3.130.255.192,Non-Managed">
</form></body></html>

Configuration

server {
    // Listen on virtual "port 80"
    listen 80;
    listen [::]:80;
    server_name 3.130.255.192;

    location / {
        // Inform server about original client
        proxy_set_header        Host $host;
        proxy_set_header        X-Real-IP $remote_addr;
        proxy_set_header        X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header        X-Forwarded-Proto $scheme;

        // Forward all requests transparently to the server running on our computer
        proxy_pass              http://localhost:9099;
    }
}

Load Balancing

upstream example.com {
    server server1.example.com;
    server server1.example.com;
}

HTTP Headers

server {
    add_header X-Cool-Header "I love APCSP!";

    location /pages {
        add_header X-Cooler-Header "This is my secret header!";
    }
}

Check In

  1. Research 1 HTTP header and describe, in detail, its purpose.
  • the User-Agent header is a commonly used HTTP header that identifies the client making the request to the server. It contains information about the client's software and operating system, allowing servers to deliver content optimized for the client's configuration. This header is also used by web developers for analytics and tracking purposes. However, it can be modified by users or applications, which can raise privacy and security concerns. Therefore, it's important for web servers and applications to validate and sanitize incoming HTTP headers to prevent unauthorized access or malicious activity.
  1. Write a line in a sample NGINX configuration that will add that specific header to the /information location
location /information {
  add_header X-Custom-Header a-header-value;
  #configuration directives
}
  1. Explain the purpose of the load balancing performed by NGINX
  • the purpose of load balancing with NGINX is to evenly distribute incoming network traffic across multiple servers to improve application performance, availability, and reliability. This helps prevent any single server from becoming overwhelmed and improves scalability and fault tolerance. NGINX also provides other features like caching, SSL termination, and content routing.
  1. Modify the following code block to obtain the value of the secret header on /products of the AWS site
aws = "3.130.255.192"

response = requests.get("http://" + aws+ "/products")

print("The secret header is:", "'X-Cooler-Header': 'This is my secret header!'")
The secret header is: 'X-Cooler-Header': 'This is my secret header!'

Hacks

  • Complete the above check-in questions and change the hosts (0.1) ☑️
  • Complete the above code-segment to retrieve the secret header (0.1) ☑️

Bonus (0.05)

Create a diagram showing the layers of abstraction that allow us to use HTTP (IP, TCP, etc.)

Link to Bonus Diagram

CORS Hacks

  1. Explain what CORS is and what it stands for

CORS stands for Cross-Origin Resource Sharing. It is a security feature implemented in web browsers that allows servers to specify which domains are allowed to access their resources and which requests are allowed to access those resources. It is designed to prevent malicious scripts from executing in a user's browser by blocking unauthorized cross-domain requests.

  1. Describe how you would be able to implement CORS into your own websites
  • to implement CORS in a website, the server needs to set appropriate headers in its response to requests. The header "Access-Control-Allow-Origin" is used to specify which domains are allowed to access the resources. For example, if a server wants to allow access from all domains, it can set the header to "*". If it only wants to allow access from a specific domain, it can set the header to that domain. Additionally, the server can specify which HTTP methods and headers are allowed to be used in cross-origin requests.
  1. Describe why you would want to implement CORS into your own websites
  • CORS is important to implement in a website to protect the user's data and prevent unauthorized access to resources. It allows a server to control which domains can access its resources, which prevents malicious scripts from executing in a user's browser. By implementing CORS, a website can also allow third-party domains to access its resources, which is necessary for some features, such as embedding videos or accessing APIs.
  1. How could use CORS to benefit yourself in the future?
  • using CORS can benefit website owners by allowing them to provide better user experiences and more secure websites. For example, by allowing third-party domains to access resources, a website can provide more features and integrate with other services. Additionally, by implementing CORS, website owners can protect user data and prevent unauthorized access to resources, which can help build trust with users and improve the overall security of the website.

Total: 0.2 points

KASM Hacks

  1. What is the purpose of "sudo" when running commands in terminal?
  • the "sudo" command in terminal stands for "superuser do" and is used to run commands with administrative privileges. It allows a user to execute commands as the root user or another user with elevated privileges, which is necessary to perform certain system-level tasks.
  1. What are some commands which allow us to look at how the storage of a machine is set up as?
  • common commands to look at how storage is set up on a machine include "df -h" which displays disk usage in a human-readable format, "lsblk" which lists block devices including disks and partitions, and "parted" which can be used to view partition information and create new partitions.
  1. What do you think are some alternatives to running "curl -O" to get the zip file for KASM?
  • alternatives to running "curl -O" to get the zip file for KASM could include using a web browser to download the file, using a package manager to install KASM, or using a file transfer protocol (FTP) client to download the file.
  1. What kind of commands do you think the "install.sh" command has and why is it necessary to call it?
  • "install.sh" command likely contains commands to install and configure KASM on the machine. It may include tasks such as downloading dependencies, setting up network configurations, and configuring security settings. Calling the "install.sh" command is necessary to ensure that KASM is installed and configured correctly on the machine.
  1. Explain in at least 3-4 sentences how deploying KASM is related to/requires other topics talked about in the lesson and/or potential ways to add things mentioned in the lesson to this guide.
  • deploying KASM is related to and requires knowledge of several other topics discussed in the lesson, such as server administration, networking, and security. In order to deploy KASM, one would need to have knowledge of how to configure a server, set up network connections, and ensure proper security measures are in place. Additionally, potential ways to add to this guide could include instructions on how to configure firewalls, set up secure remote access, and integrate KASM with other tools such as monitoring or backup solutions.

Total: 0.2 points

AWS/RDS Hacks

See the setup post

  • Create your own database in the EC2 I have created (ec2-database-connect)
    • name it with your first and last name (example: aditya-nawandhar) (0.1)
    • Create a table using the commands on the link provided. (0.1)
    • using commands from the link provided make columns and rows with test data (can be anything) (example: “name” and “class” are the columns with rows being something like “Aditya” and “Junior”). At least 4 test rows (0.1)
    • additional points if the data matches CPT (Bonus: 0.05)

Total: 0.3