Ethical Hacking and Network Defense, 3e, ISBN 9781285454610
Ch. 12 Solutions-1
Chapter 12 Solutions
Review Questions
1. Digital signatures are used to do which of the following?
2. What is the standard for PKI certificates?
3. List the three MIT professors who developed the RSA algorithm.
4. A hash value is a fixed-length string used to verify message integrity. True or False?
5. OpenPGP is focused on protecting which of the following?
6. Intruders can perform which kind of attack if they have possession of a company’s
password hash file?
7. Intercepting messages destined for another computer and sending back messages while
pretending to be the other computer is an example of what type of attack?
8. A certification authority (CA) issues private keys to recipients. True or False?
9. Write the equation to calculate how many keys are needed to have 20 people
communicate with symmetric keys.
10. Why did the NSA decide to drop support for DES?
11. Symmetric algorithms can be block ciphers or stream ciphers. True or False?
12. Which of the following describes a chosen-plaintext attack?
13. Two different messages producing the same hash value results in which of the following?
14. Which of the following is a program for extracting Windows password hash values?
15. Advanced Encryption Standard (AES) replaced DES with which algorithm?
Ethical Hacking and Network Defense, 3e, ISBN 9781285454610
Ch. 12 Solutions-2
16. What cryptographic devices were used during World War II? (Choose all that apply.)
17. Asymmetric cryptography systems are which of the following?
18. Diffie-Hellman is used to encrypt e-mail messages. True or False?
19. Hiding data in a photograph is an example of which of the following?
20. Which of the following is an asymmetric algorithm?
Activities
Activity 12-2
Step 2: CSS stands for “content scrambling system.”
Step 3: Yes, but the lawsuit against the programmer was dropped.
Activity 12-3
Answers to questions:
9000 certificates were signed with MD5.
200 Sony PlayStation 3s were used. The researchers spent $657 on certificates.
The researchers were able to sign arbitrary certificates and perform manin-the-middle
Case Projects
Case Project 12-1: Determining Possible Vulnerabilities of Microsoft CA
Root Server
Students should cite the report at www.microsoft.com/technet/security/advisory/961509.mspx,
which acknowledges the rogue CA experiment that generated an MD5 collision, or they can use
Case Project 12-2: Exploring Moral and Legal Issues
Answers can vary. The purpose of this project is to encourage students to use critical-thinking
skills in making decisions about moral and legal issues of software piracy, hacking passwords, and
so forth. There are no right or wrong answers. However, students at this level should be able to
Ethical Hacking and Network Defense, 3e, ISBN 9781285454610
Ch. 12 Solutions-3