{"id":420,"date":"2018-07-13T12:09:38","date_gmt":"2018-07-13T12:09:38","guid":{"rendered":"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=420"},"modified":"2019-05-16T09:20:02","modified_gmt":"2019-05-16T09:20:02","slug":"open-source-security-tools","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/chapter\/open-source-security-tools\/","title":{"rendered":"Open Source Security Tools"},"content":{"raw":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/on3k_Oxemq4\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n&nbsp;\r\n\r\n<strong>Need for Network Security<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Day by day, network security is becoming important. New ways of hack attacks are being revealed with the development of complex computer systems. Most of the users now-a-days use Internet. With the increasing usage of Internet, the systems and networks are becoming more vulnerable. In this module, we will learn the followings:<\/p>\r\n&nbsp;\r\n\r\na) Scan a system for vulnerable services\r\n\r\nb) Protect a system using firewall\r\n\r\nc) Protect the data using OpenSSL tool\r\n\r\n&nbsp;\r\n\r\n<strong>Overview of Port-Scanning<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Services like HTTP, FTP, TELNET etc. utilize well-known port numbers according to the conventions. Applications like TELNET are too old and they do not provide secure ways of communications. SSH is a utility to replace TELNET and is being used in most of the remote login sessions. Imagine if a network administrator has left the TELNET services open which was supposed to be closed, in that case any hacker can know that the vulnerable service is running on port no. 23. He can further device methods to hack the system and acquire data or control of the server. Port scanning utilities can help the network administrator to identify the unwanted services that are still running and he can immediately stop or suspend those services. Port scanning utilities are also helpful to hackers as they can use such utilities to scan computer systems or networks for vulnerable services.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">A widely known port scanning utility called \u201cnmap\u201d has gained popularity since years. A dedicated website is present to download the nmap utility and has many resources for the learners to learn nmap and experiment with the tool. Nmap can be downloaded from <a href=\"http:\/\/www.insecure.org\/\">www.insecure.org <\/a>website. In this section, let us learn few basic commands of nmap and will try to scan our server to identify vulnerable services.<\/p>\r\n&nbsp;\r\n\r\n<strong>Overview of nmap<\/strong>\r\n\r\n&nbsp;\r\n\r\nNMAP is an abbreviation of network mapper, It is used to scan ports on a machine (local or remote)\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">It discovers hosts and services on a network and can be used to discover OS and some software\/services on remote systems. NMAP is licensed under GNU GPL v2. It was initially released in 1997. Nmap can be ported to Linux, Windows, Solaris, BSD variants. It is written in C, C++ and Python. There is a GUI equivalent for nmap utility known as Zenmap.<\/p>\r\n&nbsp;\r\n\r\n<strong>Installation and use of nmap<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Binaries of nmap is available on website that can be used to download and install the software on Windows or Linux system. However, the source code of nmap is available on website insecure.org. We can download the source code and compile the source (using make) to generate executable binary file. The steps required to generate binary are:<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-421 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2.png\" alt=\"\" width=\"630\" height=\"114\" \/><\/p>\r\n<img class=\"alignnone size-full wp-image-422 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1.png\" alt=\"\" width=\"672\" height=\"471\" \/><img class=\"alignnone size-full wp-image-423 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1.png\" alt=\"\" width=\"678\" height=\"186\" \/>\r\n<p style=\"text-align: justify;\">Let us see an example of the output derived by using nmap command. Suppose, we want to scan the port of localhost system, the nmap command with its output is listed as follows:<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-424 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1.png\" alt=\"\" width=\"648\" height=\"233\" \/><\/p>\r\n<p style=\"text-align: justify;\">From the above output, we can come to the conclusion that the services identified by port numbers 21, 22, 23, 25 and 111 are open on the system. So, the network administrator has to take precautions of closing these ports or securing them if they are being used by clients or other applications. In the extra reading notes, we more examples have been included.<\/p>\r\n&nbsp;\r\n\r\n<strong>Overview of Firewall<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">A firewall is a network security system used to secure a host or a network. It has predetermined security rules. It is responsible to continuously monitor the outgoing and incoming network traffic. Firewall also controls the network traffic as specified in the set of rules. Firewall helps to secure a single system or an entire network. It works like a barrier between a trusted internal network and untrusted outside network, such as the Internet.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">In linux, <strong>iptables<\/strong> is a command line firewall that allows administrators and system engineers to manage outgoing and incoming traffic via a set of configurable rules. iptables uses a set of tables which have chains that contain set of built-in or user defined rules. System administrator can properly filter the network traffic of his system\/ network using firewalls.<\/p>\r\n&nbsp;\r\n\r\n<strong>Managing the firewall<\/strong>\r\n\r\n&nbsp;\r\n\r\nThe following is command to start or stop firewall in old RedHat based systems.\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\"><img class=\"size-full wp-image-425 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3.png\" alt=\"\" width=\"580\" height=\"66\" \/><\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">In modern RedHat based systems (RedHat 7 onwards), firewalld tool is used to manage firewalls. It is a dynamic firewall manager. The command used to enable or disable a firewall is:<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Before we understand how to modify the rules of a firewall, let us understand the basic keywords associated with iptables. iptables uses three different chains: input, forward, and output. The significance of these chains are as follows:<\/p>\r\n\r\n<ul>\r\n \t<li>Input chain is used to control the behaviour for all incoming connections.<\/li>\r\n \t<li>Output chain is used for outgoing connections.<\/li>\r\n \t<li>Forward chain is used when routers forward packets.<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify;\">While configuring the policies for iptables, we also use keywords like accept, drop and reject.The significance of each keyword is as shown below:<\/p>\r\n\r\n<ul>\r\n \t<li>Accept is used to allow the connection.<\/li>\r\n \t<li>Drop is used to drop the connection and no further action is taken.<\/li>\r\n \t<li>Reject signifies that don\u2019t allow the connection but send back an error.<\/li>\r\n<\/ul>\r\n<p style=\"text-align: justify;\">Let us understand few commands that are helpful to modify the rules of firewall in Linux. The following command can be used to display the existing rules of a firewall<\/p>\r\n<img class=\"alignnone size-full wp-image-426 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4.png\" alt=\"\" width=\"606\" height=\"244\" \/>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">As seen in the above output, there are no rules set for Forwarding and Output policy. However, the Input policy allows accepting of incoming connections for specific protocol and port numbers. Now, let us try to understand how the policies can be modified.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">In the following example, the firewall blocks packets arriving from a particular IP while in another case, the firewall blocks all packets that arrive from a particular IP address (say x.x.x.x) for the connections using tcp protocol. To unblock particular IP address for incoming connections, we use the -D option<\/p>\r\n&nbsp;\r\n\r\n<img class=\"alignnone size-full wp-image-427 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2.png\" alt=\"\" width=\"601\" height=\"116\" \/>\r\n<p style=\"text-align: justify;\">The iptables command can also be used to block or unblock specific port numbers for protocol tcp. In the following example, value of '22' and \u201823\u2019 represents port numbers.<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-428 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2.png\" alt=\"\" width=\"590\" height=\"90\" \/><\/p>\r\n&nbsp;\r\n\r\n<strong>Overview of Cryptography<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Linux provides a variety of open source tools for cryptography. In this section, we will review openssl tool that can be used to encrypt a file or decrypt a file using algorithms like DES, AES, RSA etc. Openssl utility supports various algorithms of cryptography including symmetric and asymmetric key cryptography. The following command can be used to list the version of openssl tool:<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-429 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2.png\" alt=\"\" width=\"587\" height=\"117\" \/><\/p>\r\nFollowing commands list the commands supported by openssl and also lists the cryptography algorithms that are supported by openssl\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-430 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1.png\" alt=\"\" width=\"590\" height=\"75\" \/><\/p>\r\n<p style=\"text-align: justify;\">Now, let us see how we can encrypt and decrypt text using openssl utility. In the following command, we are encrypting a file plain.txt using AES algorithm and CBC mode. To decrypt the file, we use '-d' option with openssl command.<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-431 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2.png\" alt=\"\" width=\"597\" height=\"130\" \/><\/p>\r\n<p style=\"text-align: justify;\">Openssl can also be used to encrypt or decrypt using Assymetric key cryptography. However, while using assymetric key, we need to ensure that first we generate the private keys and public keys. The following commands illustrates generation of private key of 1024 bits and subsequently we are generating public key. The keys are stored in .pem files.<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-432 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1.png\" alt=\"\" width=\"613\" height=\"92\" \/><\/p>\r\n<p style=\"text-align: justify;\">Once the keys are generated, we can encrypt or decrypt files by applying these keys. In the following example, we take plain.txt file and encrypt into encrypt.txt file. In the second example, we decrypt the encrypt.txt file into decrypted.txt file. It must be noted that the content of decrypted.txt file and plain.txt file will be same.<\/p>\r\n<p style=\"text-align: center;\"><img class=\"size-full wp-image-433 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1.png\" alt=\"\" width=\"604\" height=\"131\" \/><\/p>\r\n<p style=\"text-align: justify;\">OpenSSL supports many ciphers which can be explored from the manual. OpenSSL tool has many other features to generate checksum using various message digest algorithms. Extensive study of functionalities of the utilities discusses in this module is not in the scope.<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify;\">Let us summarize the key concepts covered in this module<\/p>\r\n\r\n<ul>\r\n \t<li style=\"text-align: justify;\">Portscanning utility nmap and its application<\/li>\r\n \t<li style=\"text-align: justify;\">Managing linux firewall using iptables command<\/li>\r\n \t<li style=\"text-align: justify;\">Generating cipher text using OpenSSL toolkit<\/li>\r\n<\/ul>\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on Open Source Security Tools<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/on3k_Oxemq4\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<strong>References for Open Source Security Tools:<\/strong>\r\n<ol>\r\n \t<li style=\"text-align: justify;\">Daniel J. Barrett, Richard E. Silverman, and Robert G. Byrnes. 2003. <em>Linux security<\/em> <em>cookbook<\/em>, O\u2019Reilly.<\/li>\r\n \t<li style=\"text-align: justify;\">Paulino Calderon. <em>Nmap\u202f: network exploration and security auditing cookbook\u202f: a<\/em> <em>complete guide to mastering Nmap and its scripting engine, covering practical tasks for penetration testers and system administrators<\/em>,<\/li>\r\n \t<li style=\"text-align: justify;\">Rob. Flickenger. 2003. <em>Linux server hacks<\/em>, O\u2019Reilly.<\/li>\r\n \t<li style=\"text-align: justify;\">Gordon Fyodor. Lyon. 2008. <em>Nmap network scanning\u202f: official Nmap project guide to<\/em> <em>network discovery and security scanning<\/em>, Insecure.Com, LLC.<\/li>\r\n \t<li style=\"text-align: justify;\">Nicholas. Marsh. 2015. <em>Nmap 6 cookbook\u202f: the fat-free guide to network scanning<\/em>, CreateSpace.<\/li>\r\n \t<li style=\"text-align: justify;\">Angela. Orebaugh and Becky. Pinkard. 2008. <em>Nmap in the enterprise\u202f: your guide to<\/em> <em>network scanning<\/em>, Syngress Pub.<\/li>\r\n \t<li style=\"text-align: justify;\">Paulino Calderon. Pale. 2015. <em>Mastering the Nmap Scripting Engine.<\/em>, Packt Publishing.<\/li>\r\n \t<li style=\"text-align: justify;\">Paulino Calderon. Pale. 2012. <em>Nmap 6\u202f: network exploration and security auditing\u00a0<\/em><em style=\"text-align: initial; font-size: 1em;\">Cookbook<\/em><span style=\"text-align: initial; font-size: 1em;\">, Packt Pub.<\/span><\/li>\r\n \t<li style=\"text-align: justify;\">Gregor N. Purdy. 2004. <em>Linux iptables\u202f: pocket reference<\/em>, O\u2019Reilly Media.<\/li>\r\n \t<li style=\"text-align: justify;\">Michael. Rash. 2007. <em>Linux firewalls\u202f: attack detection and response with iptables,<\/em> <em>psad, and fwsnort<\/em>, No Starch Press.<\/li>\r\n \t<li style=\"text-align: justify;\">David Shaw. <em>Nmap essentials\u202f:<\/em> <em>harness the power of Nmap, the most versatile<\/em> <em>network port scanner on the planet, to secure large scale networks<\/em>,<\/li>\r\n \t<li style=\"text-align: justify;\">J. Viega, M. Messier, and P. Chandra. 2002. <em>Network Security with OpenSSL:<\/em> <em>Cryptography for Secure Communications<\/em>,<\/li>\r\n \t<li style=\"text-align: justify;\">John. Viega, Matt. Messier, and Pravir. Chandra. 2002. <em>Network security with<\/em> <em>OpenSSL<\/em>, O\u2019Reilly.<\/li>\r\n \t<li style=\"text-align: justify;\">Anon. Insecure.Org - Nmap Free Security Scanner, Tools &amp;amp; Hacking resources. Retrieved March 20, 2017 from http:\/\/insecure.org\/<\/li>\r\n \t<li style=\"text-align: justify;\">Anon. OpenSSL Manual. Retrieved March 20, 2017 from https:\/\/www.openssl.org\/docs\/man1.1.1\/man1\/<\/li>\r\n \t<li style=\"text-align: justify;\">Anon. OpenSSL Website. Retrieved March 20, 2017 from https:\/\/www.openssl.org\/<\/li>\r\n<\/ol>","rendered":"<div><span style=\"float: right;\"><a href=\"https:\/\/youtu.be\/on3k_Oxemq4\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Need for Network Security<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Day by day, network security is becoming important. New ways of hack attacks are being revealed with the development of complex computer systems. Most of the users now-a-days use Internet. With the increasing usage of Internet, the systems and networks are becoming more vulnerable. In this module, we will learn the followings:<\/p>\n<p>&nbsp;<\/p>\n<p>a) Scan a system for vulnerable services<\/p>\n<p>b) Protect a system using firewall<\/p>\n<p>c) Protect the data using OpenSSL tool<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Overview of Port-Scanning<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Services like HTTP, FTP, TELNET etc. utilize well-known port numbers according to the conventions. Applications like TELNET are too old and they do not provide secure ways of communications. SSH is a utility to replace TELNET and is being used in most of the remote login sessions. Imagine if a network administrator has left the TELNET services open which was supposed to be closed, in that case any hacker can know that the vulnerable service is running on port no. 23. He can further device methods to hack the system and acquire data or control of the server. Port scanning utilities can help the network administrator to identify the unwanted services that are still running and he can immediately stop or suspend those services. Port scanning utilities are also helpful to hackers as they can use such utilities to scan computer systems or networks for vulnerable services.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">A widely known port scanning utility called \u201cnmap\u201d has gained popularity since years. A dedicated website is present to download the nmap utility and has many resources for the learners to learn nmap and experiment with the tool. Nmap can be downloaded from <a href=\"http:\/\/www.insecure.org\/\">www.insecure.org <\/a>website. In this section, let us learn few basic commands of nmap and will try to scan our server to identify vulnerable services.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Overview of nmap<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>NMAP is an abbreviation of network mapper, It is used to scan ports on a machine (local or remote)<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">It discovers hosts and services on a network and can be used to discover OS and some software\/services on remote systems. NMAP is licensed under GNU GPL v2. It was initially released in 1997. Nmap can be ported to Linux, Windows, Solaris, BSD variants. It is written in C, C++ and Python. There is a GUI equivalent for nmap utility known as Zenmap.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Installation and use of nmap<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Binaries of nmap is available on website that can be used to download and install the software on Windows or Linux system. However, the source code of nmap is available on website insecure.org. We can download the source code and compile the source (using make) to generate executable binary file. The steps required to generate binary are:<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-421 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2.png\" alt=\"\" width=\"630\" height=\"114\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2.png 630w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2-300x54.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2-65x12.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2-225x41.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/4-2-350x63.png 350w\" sizes=\"auto, (max-width: 630px) 100vw, 630px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-422 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1.png\" alt=\"\" width=\"672\" height=\"471\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1.png 672w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1-300x210.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1-65x46.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1-225x158.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/5-1-350x245.png 350w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-423 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1.png\" alt=\"\" width=\"678\" height=\"186\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1.png 678w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1-300x82.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1-65x18.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1-225x62.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/6-1-350x96.png 350w\" sizes=\"auto, (max-width: 678px) 100vw, 678px\" \/><\/p>\n<p style=\"text-align: justify;\">Let us see an example of the output derived by using nmap command. Suppose, we want to scan the port of localhost system, the nmap command with its output is listed as follows:<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-424 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1.png\" alt=\"\" width=\"648\" height=\"233\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1.png 648w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1-300x108.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1-65x23.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1-225x81.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/7-1-350x126.png 350w\" sizes=\"auto, (max-width: 648px) 100vw, 648px\" \/><\/p>\n<p style=\"text-align: justify;\">From the above output, we can come to the conclusion that the services identified by port numbers 21, 22, 23, 25 and 111 are open on the system. So, the network administrator has to take precautions of closing these ports or securing them if they are being used by clients or other applications. In the extra reading notes, we more examples have been included.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Overview of Firewall<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">A firewall is a network security system used to secure a host or a network. It has predetermined security rules. It is responsible to continuously monitor the outgoing and incoming network traffic. Firewall also controls the network traffic as specified in the set of rules. Firewall helps to secure a single system or an entire network. It works like a barrier between a trusted internal network and untrusted outside network, such as the Internet.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">In linux, <strong>iptables<\/strong> is a command line firewall that allows administrators and system engineers to manage outgoing and incoming traffic via a set of configurable rules. iptables uses a set of tables which have chains that contain set of built-in or user defined rules. System administrator can properly filter the network traffic of his system\/ network using firewalls.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Managing the firewall<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>The following is command to start or stop firewall in old RedHat based systems.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-425 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3.png\" alt=\"\" width=\"580\" height=\"66\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3.png 580w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3-300x34.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3-65x7.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3-225x26.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-3-350x40.png 350w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">In modern RedHat based systems (RedHat 7 onwards), firewalld tool is used to manage firewalls. It is a dynamic firewall manager. The command used to enable or disable a firewall is:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Before we understand how to modify the rules of a firewall, let us understand the basic keywords associated with iptables. iptables uses three different chains: input, forward, and output. The significance of these chains are as follows:<\/p>\n<ul>\n<li>Input chain is used to control the behaviour for all incoming connections.<\/li>\n<li>Output chain is used for outgoing connections.<\/li>\n<li>Forward chain is used when routers forward packets.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">While configuring the policies for iptables, we also use keywords like accept, drop and reject.The significance of each keyword is as shown below:<\/p>\n<ul>\n<li>Accept is used to allow the connection.<\/li>\n<li>Drop is used to drop the connection and no further action is taken.<\/li>\n<li>Reject signifies that don\u2019t allow the connection but send back an error.<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Let us understand few commands that are helpful to modify the rules of firewall in Linux. The following command can be used to display the existing rules of a firewall<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-426 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4.png\" alt=\"\" width=\"606\" height=\"244\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4.png 606w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4-300x121.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4-65x26.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4-225x91.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/8-4-350x141.png 350w\" sizes=\"auto, (max-width: 606px) 100vw, 606px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">As seen in the above output, there are no rules set for Forwarding and Output policy. However, the Input policy allows accepting of incoming connections for specific protocol and port numbers. Now, let us try to understand how the policies can be modified.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">In the following example, the firewall blocks packets arriving from a particular IP while in another case, the firewall blocks all packets that arrive from a particular IP address (say x.x.x.x) for the connections using tcp protocol. To unblock particular IP address for incoming connections, we use the -D option<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-427 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2.png\" alt=\"\" width=\"601\" height=\"116\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2.png 601w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2-300x58.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2-65x13.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2-225x43.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/9-2-350x68.png 350w\" sizes=\"auto, (max-width: 601px) 100vw, 601px\" \/><\/p>\n<p style=\"text-align: justify;\">The iptables command can also be used to block or unblock specific port numbers for protocol tcp. In the following example, value of &#8217;22&#8217; and \u201823\u2019 represents port numbers.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-428 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2.png\" alt=\"\" width=\"590\" height=\"90\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2.png 590w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2-300x46.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2-65x10.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2-225x34.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/10-2-350x53.png 350w\" sizes=\"auto, (max-width: 590px) 100vw, 590px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Overview of Cryptography<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Linux provides a variety of open source tools for cryptography. In this section, we will review openssl tool that can be used to encrypt a file or decrypt a file using algorithms like DES, AES, RSA etc. Openssl utility supports various algorithms of cryptography including symmetric and asymmetric key cryptography. The following command can be used to list the version of openssl tool:<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-429 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2.png\" alt=\"\" width=\"587\" height=\"117\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2.png 587w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2-300x60.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2-65x13.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2-225x45.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/11-2-350x70.png 350w\" sizes=\"auto, (max-width: 587px) 100vw, 587px\" \/><\/p>\n<p>Following commands list the commands supported by openssl and also lists the cryptography algorithms that are supported by openssl<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-430 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1.png\" alt=\"\" width=\"590\" height=\"75\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1.png 590w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1-300x38.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1-65x8.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1-225x29.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/12-1-350x44.png 350w\" sizes=\"auto, (max-width: 590px) 100vw, 590px\" \/><\/p>\n<p style=\"text-align: justify;\">Now, let us see how we can encrypt and decrypt text using openssl utility. In the following command, we are encrypting a file plain.txt using AES algorithm and CBC mode. To decrypt the file, we use &#8216;-d&#8217; option with openssl command.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-431 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2.png\" alt=\"\" width=\"597\" height=\"130\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2.png 597w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2-300x65.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2-65x14.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2-225x49.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/13-2-350x76.png 350w\" sizes=\"auto, (max-width: 597px) 100vw, 597px\" \/><\/p>\n<p style=\"text-align: justify;\">Openssl can also be used to encrypt or decrypt using Assymetric key cryptography. However, while using assymetric key, we need to ensure that first we generate the private keys and public keys. The following commands illustrates generation of private key of 1024 bits and subsequently we are generating public key. The keys are stored in .pem files.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-432 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1.png\" alt=\"\" width=\"613\" height=\"92\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1.png 613w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1-300x45.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1-65x10.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1-225x34.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/14-1-350x53.png 350w\" sizes=\"auto, (max-width: 613px) 100vw, 613px\" \/><\/p>\n<p style=\"text-align: justify;\">Once the keys are generated, we can encrypt or decrypt files by applying these keys. In the following example, we take plain.txt file and encrypt into encrypt.txt file. In the second example, we decrypt the encrypt.txt file into decrypted.txt file. It must be noted that the content of decrypted.txt file and plain.txt file will be same.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-433 aligncenter\" src=\"http:\/\/itp7.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1.png\" alt=\"\" width=\"604\" height=\"131\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1.png 604w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1-300x65.png 300w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1-65x14.png 65w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1-225x49.png 225w, https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-content\/uploads\/sites\/30\/2018\/07\/15-1-350x76.png 350w\" sizes=\"auto, (max-width: 604px) 100vw, 604px\" \/><\/p>\n<p style=\"text-align: justify;\">OpenSSL supports many ciphers which can be explored from the manual. OpenSSL tool has many other features to generate checksum using various message digest algorithms. Extensive study of functionalities of the utilities discusses in this module is not in the scope.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify;\">Let us summarize the key concepts covered in this module<\/p>\n<ul>\n<li style=\"text-align: justify;\">Portscanning utility nmap and its application<\/li>\n<li style=\"text-align: justify;\">Managing linux firewall using iptables command<\/li>\n<li style=\"text-align: justify;\">Generating cipher text using OpenSSL toolkit<\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on Open Source Security Tools<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/on3k_Oxemq4\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>References for Open Source Security Tools:<\/strong><\/p>\n<ol>\n<li style=\"text-align: justify;\">Daniel J. Barrett, Richard E. Silverman, and Robert G. Byrnes. 2003. <em>Linux security<\/em> <em>cookbook<\/em>, O\u2019Reilly.<\/li>\n<li style=\"text-align: justify;\">Paulino Calderon. <em>Nmap\u202f: network exploration and security auditing cookbook\u202f: a<\/em> <em>complete guide to mastering Nmap and its scripting engine, covering practical tasks for penetration testers and system administrators<\/em>,<\/li>\n<li style=\"text-align: justify;\">Rob. Flickenger. 2003. <em>Linux server hacks<\/em>, O\u2019Reilly.<\/li>\n<li style=\"text-align: justify;\">Gordon Fyodor. Lyon. 2008. <em>Nmap network scanning\u202f: official Nmap project guide to<\/em> <em>network discovery and security scanning<\/em>, Insecure.Com, LLC.<\/li>\n<li style=\"text-align: justify;\">Nicholas. Marsh. 2015. <em>Nmap 6 cookbook\u202f: the fat-free guide to network scanning<\/em>, CreateSpace.<\/li>\n<li style=\"text-align: justify;\">Angela. Orebaugh and Becky. Pinkard. 2008. <em>Nmap in the enterprise\u202f: your guide to<\/em> <em>network scanning<\/em>, Syngress Pub.<\/li>\n<li style=\"text-align: justify;\">Paulino Calderon. Pale. 2015. <em>Mastering the Nmap Scripting Engine.<\/em>, Packt Publishing.<\/li>\n<li style=\"text-align: justify;\">Paulino Calderon. Pale. 2012. <em>Nmap 6\u202f: network exploration and security auditing\u00a0<\/em><em style=\"text-align: initial; font-size: 1em;\">Cookbook<\/em><span style=\"text-align: initial; font-size: 1em;\">, Packt Pub.<\/span><\/li>\n<li style=\"text-align: justify;\">Gregor N. Purdy. 2004. <em>Linux iptables\u202f: pocket reference<\/em>, O\u2019Reilly Media.<\/li>\n<li style=\"text-align: justify;\">Michael. Rash. 2007. <em>Linux firewalls\u202f: attack detection and response with iptables,<\/em> <em>psad, and fwsnort<\/em>, No Starch Press.<\/li>\n<li style=\"text-align: justify;\">David Shaw. <em>Nmap essentials\u202f:<\/em> <em>harness the power of Nmap, the most versatile<\/em> <em>network port scanner on the planet, to secure large scale networks<\/em>,<\/li>\n<li style=\"text-align: justify;\">J. Viega, M. Messier, and P. Chandra. 2002. <em>Network Security with OpenSSL:<\/em> <em>Cryptography for Secure Communications<\/em>,<\/li>\n<li style=\"text-align: justify;\">John. Viega, Matt. Messier, and Pravir. Chandra. 2002. <em>Network security with<\/em> <em>OpenSSL<\/em>, O\u2019Reilly.<\/li>\n<li style=\"text-align: justify;\">Anon. Insecure.Org &#8211; Nmap Free Security Scanner, Tools &amp;amp; Hacking resources. Retrieved March 20, 2017 from http:\/\/insecure.org\/<\/li>\n<li style=\"text-align: justify;\">Anon. OpenSSL Manual. Retrieved March 20, 2017 from https:\/\/www.openssl.org\/docs\/man1.1.1\/man1\/<\/li>\n<li style=\"text-align: justify;\">Anon. OpenSSL Website. Retrieved March 20, 2017 from https:\/\/www.openssl.org\/<\/li>\n<\/ol>\n","protected":false},"author":4,"menu_order":30,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":["mr-hardik-joshi"],"pb_section_license":""},"chapter-type":[],"contributor":[58],"license":[],"class_list":["post-420","chapter","type-chapter","status-publish","hentry","contributor-mr-hardik-joshi"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/chapters\/420","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/wp\/v2\/users\/4"}],"version-history":[{"count":5,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/chapters\/420\/revisions"}],"predecessor-version":[{"id":719,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/chapters\/420\/revisions\/719"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/chapters\/420\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/wp\/v2\/media?parent=420"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/pressbooks\/v2\/chapter-type?post=420"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/wp\/v2\/contributor?post=420"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/itp7\/wp-json\/wp\/v2\/license?post=420"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}