Tuesday, February 28, 2017

Feb 28 2017 - What Are We Doing In Class Today?

Entrance Ticket - (15 min) Write Code, Save Lives - find out more... This started as a Google Summer of Code event with openMSR

https://opensource.googleblog.com/2011/12/students-write-code-and-save-lives-with.html
 and
http://openmrs.org/

Write a 50-100 words about openMSR
  1. What is openMSR?
  2. How to get involved in a project like this?  
  3. If you wanted to work on a openMSR project, how would you apply?
  4. How would Cyber Security be important to openMRS
  5. For 10 points Extra Credit - Can you find any other programs, where you can code to save lives and help people?

Class Agenda:

Raspberry PI Instructables class

Please sign up for the Instructables Raspberry PI class found:


https://www.instructables.com/class/Raspberry-Pi-Class/?utm_medium=search%2F

This is a 10 lesson class.  I want you to go through this class self paced.  You will have all week to complete it.  You will not actually be building all the hardware, but you will want to review all lessons to be able to answers the questions.  Turn your answers in to Jupiter.

Lesson 1
  1. Who is the creator or the Push_Reset?
  2. What is the end goal of this Instructables project?
  3. What is a Raspberry PI?
  4. What are the main "flavors" of the RPi family?
  5. Who Created the Raspberry PI?
  6. Why is it called a Raspberry PI?
  7. What Assumptions are made about you, the student?
Lesson 2
  1. What is a Pi Hat?
  2. What Pi Hat is recommended?
  3. What size monitor is required?
Lesson 3
  1. How many GPIO does a RPI have?
  2. List all the "input" & "output" ports
  3. Is a wireless mouse & Keyboard recommended? if so , why?
  4. What does NOOBS stand for?
  5. What is the recommended method to setup your keyboard preferences?
  6. If you want to change the Mouse and Keyboard settings, where do you do it?
  7. Who is the Japanese sci-fi illustrations artist mentioned
Lesson 4 (part 1)
  1. What does an OS do?
  2. What are the 2 ways to get around in the Raspberry PI software?
  3. _____________ are found on the Tool bar?
  4. Does the RPi have a on/of switch?
  5. Is it OK to just pull the power plug to turn off your RPI?
  6. what is the recommended way to turn off the RPi?  
  7. At the command prompt when you see $ what that mean?  What does it mean when you see # at the command prompt?
  8. What is "scrot"?
  9. What is "sudo" used for?
  10. What cool jewelry is Lara wearing?  would you get one?
Lesson 4 (part 2)
    Watch the TED talk (20 min).  What did you learn, that you did not know before?
    1. Who Created Linux?
    2. Why did he create Linux?
    3. How long has he been working on it?
    4. What school did his "friend" who introduced him to "open Sourced community" come from? 
    5. What was Linus Torvalds biggest worry about what would happen to his Linux project?
    6. When he was 21, and people started looking at his code, what did he think was an amazing revelation?
    7. Does Linus "love" other people?
    8. Did his Linux project just "take off" at some point?
    9. How was Linus involved in "GIT" and why did he work on it?  and did people "love it"?  
    10. What was the tool he used before "GIT"? Did he like it? - CVS... No, he hated it
    11. What did his Sister say about him? - His biggest exceptional quality was that "he would not let go"
    12. What did Linus say about other peoples feelings?
    13. What doe the work he used mean?
    14. What would happen if Linux had to design a pretty UI (User Interface)?.
    Lesson 5
    1.  What does "apt-get update" command do?
    2. If you tried to run it, do it work?  What did you need to change?
    3. How do you get an install install with out continuing to ask yes/no to continue?
    4. How do you remove an application?  What is the command?  
    5. Create a short text file.  turn it in with these answers. (hint, you should be able to save a file to you google drive, or even log in to Jupiter)
    6. While We will not be using a camera right now (because we don't have any), what is another shell script you can write?  Create a simple shell script.  It could be something simple, like get the current time, and print some thing every minute...
    7. How do you find other packaged that might exist? How do you search?
    8. What command do you use to see if a specific package exists?
    9. How do you find any dependencies that package might have?  What is that command?
    Lesson 6
    1.  What is this lesson about?
    2. How do you tell the RPi to play sound from the Audio Jack?
    3. Were you able to install mpg321?
    4. Where you able to play an mp3 file?
    5. Using pygame.mixer, can you play a sound file?
    6. Using pygame.movie can you play a movie?
    SonicPI
    1. Work through the SonicPI tutorial.
    2. Play a "song" with at least 4 notes
    3. Create and play a sign wave
    4. Create a new "song"
    Lesson 7
    1. Turn in a python3 script that you wrote as part of working through Lesson 7
    Lesson 8
    1.  We will do Lesson 8 as a class lab... so you can skip this or not... if you are ahead, you can work through this lab, or wait for when we do this as a class... you choose.
    Lesson 9
    1.  We will do Lesson 9 as a class lab... so you can skip this or not... if you are ahead, you can work through this lab, or wait for when we do this as a class... you choose.
    Lesson 10
    1. We may do something here... but tell me what type of booth you would build.







    Other Instructables:

    Monday, February 27, 2017

    Feb 27 2017 - What Are We Doing In Class Today?

    Entrance Ticket - (15 min) Hacker Shows How Easy It Is To Hack People While Walking Around in Public
    Write a 50-100 words about how to protect your devices in Public

    Class Agenda:

    • HUB?
    • Take a break for about 10 min, AND CLEAN UP THE ROOM SOME... ALL THE PAPERS AT YOUR DESK, TOOLS, WIRES, ETC...

    Wednesday, February 15, 2017

    Feb 16 2017 - What Are We Doing In Class Today?

    Entrance Ticket - Cyber Security Current Event  - 30 min   See the Rubric for full points.  I will be looking for bullets, relevant graphics, etc...

    Class Agenda:

    • (30 min) Entry Ticket - 30 min  Work on your Presentations
    • (20 Min) 2 Students should then volunteer to present no more than 10 each... you can have the class evaluate the presentation in a class discussion .  They can open their presentation on the PC on my desk and project it on the screen.  5-6 min each - 5 points Extra Credit for Volunteers
    • (30 min) WireShark -
      • Start Watching (on your own computer with Headphones)  https://www.youtube.com/watch?v=vUdOxcRJgME   
      •  Answer these Questions
        • What is this class designed to do? What is the Authors goals?
        • Is the class targeted at Beginners or Advanced Users?
        • For Whom is Wireshark a must have?
        • What is his IP address?
        • What type of IP address types do business vs personal users have (Static vs Dynamic?
        • is data over port 443 encrypted or not?
        • What does DNS servers do?
        • when he talks about the NMAP and the port Service State, what is the state of his port 631 and what does he say about that?
        • What does he say is a "burnt in Hardware Address"
      • You can skip the Install section
    • (30 min) Python- Programming for Everybody (Getting Started with Python) -Class Resources  
    Here is an example of my code:

    def stripEmail():
        fhand = open('mbox.txt')
        countEmail = 0
        for line in fhand:
            countEmail = countEmail + 1
            line = line.rstrip()
            if '@' in line :
                setOfSubStrings = (line.split(sep=' '))
             # print(setOfSubStrings)
             # print()
             for email in setOfSubStrings :
                 if '@' in email :
                     print(email)
        print(countEmail)

    You still need to figure out how to strip stuff like "<" and ">" and even some ":" and "~"

    wagnermr@iupui.edu
    cwen@iupui.edu
    postmaster@collab.sakaiproject.org
    200801032122.m03LMFo4005148@nakamura.uits.iupui.edu
    source@collab.sakaiproject.org
    source@collab.sakaiproject.org
    source@collab.sakaiproject.org
    apache@localhost)       <--- This one is also not an email.... so there is still some more work
    source@collab.sakaiproject.org
    cwen@iupui.edu
    source@collab.sakaiproject.org
    cwen@iupui.edu
    cwen@iupui.edu
    wagnermr@iupui.edu
    1909
    • Take a break for about 10 min, AND CLEAN UP THE ROOM SOME... ALL THE PAPERS AT YOUR DESK, TOOLS, WIRES, ETC...

    Tuesday, February 14, 2017

    Feb 14 2017 - What Are We Doing In Class Today?

    Entrance Ticket - Jupiter or Python Games / Code - 20 min


    Jupiter:  Turn in 2 jupiter assignments or Turning an update that is different from yesterday of what you did.  If you played a Game, submit screen shots, if you wrote code, submit a file.py file

    Grades are Due!!!!!!!!!!!!!!!!!!!!!!!! So Please turn in missing assignments.  I will only accept any late work until the end of class on Tuesday.

    Class Agenda:

    Wireshark Lab #6 - HTTP Authentication

    HTTP Authentication
    Finally, let’s try visiting a web site that is password-protected and examine the sequence of HTTP message exchanged for such a site. The URL http://www.steamclown.org//cyberSecuritySVCTE/wireshark/auth/wireshark_lab_006.htm is password protected. The username is “Zim” (without the quotes), and the password is “learn” (again, without the quotes). So let’s access this “secure”
    password-protected site. Do the following:
    • Make sure your browser’s cache is cleared, and close down your browser. Then, start up your browser
    • Start up the Wireshark packet sniffer
    • Enter the following URL into your browser http://www.steamclown.org//cyberSecuritySVCTE/wireshark/auth/wireshark_lab_006.htm 
    • Type the requested user name and password into the pop up box
    • Stop Wireshark packet capture, and enter “http” in the display-filter-specification window, so that only captured HTTP messages will be displayed later in the packet-listing window.

    Now let’s examine the Wireshark output. You might want to first read up on HTTP
    authentication by reviewing the easy-to-read material on “HTTP Access Authentication
    Framework” at http://frontier.userland.com/stories/storyReader$2159

    Answer the following questions:
    1. What is the server’s response (status code and phrase) in response to the initial HTTP GET message from your browser?
    2. When your browser’s sends the HTTP GET message for the second time, what new field is included in the HTTP GET message
    The username (Zim) and password (learn) that you entered are not encoded. this is because the web site does not have base64 encoding.  Now if you re-run  the steps, but use the following link: http://gaia.cs.umass.edu/wireshark-labs/protected_pages/HTTP-wireshark-file5.html with the username is “wireshark-students” (without the quotes), and the password is “network” (again, without the quotes).

    • Make sure your browser’s cache is cleared, and close down your browser. Then, start up your browser
    • Start up the Wireshark packet sniffer
    • Enter the following URL into your browser http://gaia.cs.umass.edu/wireshark-labs/protected_pages/HTTP-wireshark-file5.html
    • Type the requested user name and password into the pop up box
    • Stop Wireshark packet capture, and enter “http” in the display-filter-specification window, so that only captured HTTP messages will be displayed later in the packet-listing window.

    Now answer the following questions again:
    1. What is the server’s response (status code and phrase) in response to the initial HTTP GET message from your browser?
    2. When your browser’s sends the HTTP GET message for the second time, what new field is included in the HTTP GET message

    The username (wireshark-students) and password (network) that you entered are encoded in the string of characters (d2lyZXNoYXJrLXN0dWRlbnRzOm5ldHdvcms=) following the “Authorization:  Basic” header in the client’s HTTP GET message. While it  may appear that your username and password are encrypted, they are simply encoded in a format known as Base64 format. The username and password are not encrypted! To see this, go to http://www.motobit.com/util/base64-decoder-encoder.asp and enter the base64-encoded string d2lyZXNoYXJrLXN0dWRlbnRz and decode. Voila! You have translated from Base64 encoding to ASCII encoding, and thus should see your username! To view the password, enter the remainder of the string Om5ldHdvcms= and press decode. Since anyone can download a tool like Wireshark and sniff packets (not just their own) passing by their network adaptor, and anyone can translate from Base64 to ASCII (you just did it!), it should be clear to you that simple passwords on WWW sites are not secure unless additional measures are taken.

    Fear not! As we will see later there are ways to make WWW access more secure.
    However, we’ll clearly need something that goes beyond the basic HTTP authentication
    framework!