@Ipoint.) If you can get the source code and check it, so much the better! 1 vhow to verify the vulnerability  in the absense of source code  (if an attack program is required, you may euse pseudocode to describe the attack program). Be very detailed here; what would correct behavior hbe, and what would erroneous behavior be? If you did this in the previous assignment, you may repeat it @\here, but please be sure that any competent programmer could reproduce what you plan to do. !* leffects of exploiting the vulnerability; would you gain access? would you simply deny service or affect the @response speed? !+ hdisruptions caused by exploiting the vulnerability: would you interfere with normal use of the network? jCould you accidentally (or intentionally) interrupt or disrupt others use of the network, or others sys@tems? - uIf possible, check to see if the vulnerability exists.  Act ethically if disruptions could occur other than to zthe users of pacific-hts, dont launch the attack!!!   (If your attack could disrupt the network, please wait ... "ewe will have a Windows 2000 system set up in the security lab next week, on a network you can use to mlaunch attacks. FW,e HUV ;.HUV 3Ge HUV ;05+HUV 22l H$ ;1H$ 5Ge H$ ;33H$ 44l HHˆ;4HHˆƒ*m337 ` Homework 3 G `2Due Date : June 1, 2000 Points : 200 H` ![ y( 10 points ) In a book on UNIX system security, one author states that the reason there has not been a computer nvirus on UNIX systems other than in the laboratory is because viruses require binary compatibility across sys@otems; that is, the machine languages of the two systems must be compatible. Is he right? Justify your answer. !/ ( 20 points ) An  iteration attack  on the RSA cipher is one in which repeated encipherings of the ciphertext produce the plaintext. Consider the ciphertext  C  = 3,  n  = 55, and  e  = 17. Please show that this message can be bro@Lken with the iteration attack. !% ( 100 points ) This continues our penetration testing of  pacific-hts . In the last exercise you hypothesized flaws in @Fthe systems networking implementation. Now it is time to test them! !& nIn each of your three vulnerability descriptions was a short item about how to test for the vulnerability (at @fleast, there was  supposed  to be!) Expand each of these into a full description, as follows: '` your name; (`server with the vulnerability; a uhow to verify the vulnerability  if you have source code . What would you look for? You are free to describe csome hypothetical code. For example, if a buffer overflow might occur on input, you would say somenthing like look for the input functions, and see if they (1) respect buffer boundaries or (2) if they are in ia loop that does not check bounds. (The idea here is if you acquire source code, youll have a starting account to make this security tool as useful as possible? Discuss attacks and countermeasures. !% ( 100 points ) This continues our penetration testing of  pacific-hts . In the last exercise you hypothesized flaws in @Fthe systems networking implementation. Now it is time to test them! !& nIn each of your three vulnerability descriptions was a short item about how to test for the vulnerability (at @fleast, there was  supposed  to be!) Expand each of these into a full description, as follows: '` your name; (`server with the vulnerability; a uhow to verify the vulnerability  if you have source code . What would you look for? You are free to describe csome hypothetical code. For example, if a buffer overflow might occur on input, you would say somenthing like look for the input functions, and see if they (1) respect buffer boundaries or (2) if they are in ia loop that does not check bounds. (The idea here is if you acquire source code, youll have a starting (The idea here is if you acquire source code, youll have a starting HHˆ;6HHˆ 66 l}H HD!CH FAG3e }H HDN:H FOG4e C:Subscript }H HD9GH FOG5eEM d;;<@H$ ;<;>H$ == l H$ ;=;H$ <Wl4May 18, 2000ECS 253 Spring 2000Page 1  HUV ;>;<@HUV ?? l HUV ;?;HUV >Wl?Last modified at  12:14 am on Thursday, May 18, 2000  HHˆ;@;>HHˆAA l HHˆ;A;HHˆ@W` }?^H =x 1C?^H  FW-e¢ }^H =z B^^H  FW.a d=~EEd=Dd FF l d=Dd& (EzJ9CFILORUwtX[^adgjmpsy| % ).1^[XURO}H HD:HH FOG6eN }H HDGIH FOG7eN }H HDHH FOG8e }H HD~KH FPG9e C:subscript }H HDJLH FPG:eEM }H HDKMH FPG;eN }H HDLNH FPG<eN }H HDM9H FPG=e }¦? @c TP¦?  BWie }?¦H @e OQ?¦H  BWje... }¦H @g P¦H  BWke }š? @i WSš?  GWle }?šH @k RT?šH  GWme- }šH @m SOšH  GWne }Ž? @o ZVŽ?  HWoe }?ŽH @q UW?ŽH  HWpe-- }ŽH @s VRŽH  HWqe }‚? @u ]Y‚?  IWre }?‚H @w XZ?‚H  IWse° }‚H @y YU‚H  IWte }v? @{ `\v?  JWue }?vH @} []?vH  JWve® }vH @ \XvH  JWwe }j? @ C_j?  