← Indietro
EsameEsame completoTesto d’esame

02 07 15

Esame completo di Computer Security per il corso di Computer Engineering presso Politecnico di Milano. Materiale proveniente dall’archivio storico Studwiz e classificato per la consultazione online.

Computer SecurityEsame completo

Informazioni sul documento

Cosa trovi in questo materiale

Esame completo di Computer Security per il corso di Computer Engineering presso Politecnico di Milano. Materiale proveniente dall’archivio storico Studwiz e classificato per la consultazione online.

Qualità dell’importazione: il testo è stato estratto direttamente dal documento originale.

Contenuti estratti dal documento

Passaggi rappresentativi riconosciuti nelle diverse parti del materiale. Il testo completo resta presente nella pagina per la ricerca, mentre l’anteprima compatta rende più semplice la lettura.

Pagina 1

Computer Security Exam July 2, 2015 First name: ________________________ Last name: ________________________ Matricola: ________________________ Signature: ________________________ Challenges? [ ] (Y) [ ] (N) Exam points: __________________________ Instructions ● The exam is composed of 7 pages. ● Just as a cross check, tell us whether you have completed the homeworks, by putting an "X" mark appropriately. ● The exam is "closed books". Please put away in a non-suspicious place (i.e. not below the desk) any notes, books, or similar. You will be expelled if, at any time, you do not follow this rule. ● You are not allowed to communicate with other students, and you will be expelled from the exam if you do. ● Shut down and store electronic devices. They will be subject to inspection if found and you may be expelled if you are found using one. ● Please answer within the allowed space. Schemes are good, short answers are recommended. ● You can write in pen or pencil, any color, but avoid writing in red. ● No extra paper is allowed. ● The ​answers should be written exclusively in the space provided​ below each questions. Question 1 (4 points) 1. Explain why the Initial Sequence Number (ISN) in a TCP connection should be random. Because if an attacker could guess it, she could blindly (i.e. without sniffing or being physically a MITM) complete a three-way handshake, effectively spoofing the IP address of a third party. 2. Which of the following TCP stacks is more vulnerable to the above attack, and why (in brief)? The most vulnerable stack is the one at the top-right. The second most vulnerable one is the one at the top-left. The reason is that the ISNs are distributed around few points. Question 2 (5 points) A web page contains the following code: //get the username from the…

Anteprima

Prima pagina del documento.

Prima pagina: 02 07 15