Networking Fundamentals
Almost every attack travels over the network, so understanding how machines communicate isn’t optional: it’s the substrate of recon, scanning, pivoting, and exfiltration. You don’t need to be a network engineer, but you do need to master the layered model, how packets are addressed and routed, and which protocols you’ll meet on each port.
The layered model
Section titled “The layered model”Two models, same idea (encapsulation: each layer wraps the one above):
- OSI (7 layers) — theoretical: Physical, Data Link, Network, Transport, Session, Presentation, Application.
- TCP/IP (4 layers) — practical: Link, Internet (IP), Transport (TCP/UDP), Application (HTTP, DNS…).
For a pentester, the ones that matter daily: Network (IP) = addressing and routing; Transport (TCP/UDP) = ports and reliability; Application = the service’s protocol.
IP addressing and subnetting
Section titled “IP addressing and subnetting”IPv4: 192.168.1.10 /24 -> network 192.168.1.0, hosts .1-.254, broadcast .255CIDR: /24 = 256 IPs, /16 = 65536, /30 = 4 (point-to-point links)Private (RFC1918): 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16Subnetting tells you what range to scan: a /24 is 254 hosts; a /16, 65k. IPv6 (fe80::/10 link-local) increasingly present and often unwatched (see mitm6 in AD).
TCP vs UDP and the three-way handshake
Section titled “TCP vs UDP and the three-way handshake”- TCP — connection-oriented, reliable. Handshake:
SYN → SYN-ACK → ACK. The basis of port scanning (a SYN-ACK = open port). - UDP — connectionless, no guarantees; faster and harder to scan (no response ≠ closed). DNS, SNMP, DHCP, VPN.
Useful TCP states: LISTEN (service waiting), ESTABLISHED (live connection)Key flags: SYN, ACK, FIN, RST (reset = closed), PSH, URGPorts and services you must recognize
Section titled “Ports and services you must recognize”21 FTP 22 SSH 23 Telnet 25 SMTP 53 DNS 80 HTTP110 POP3 111 RPC 135 MSRPC 139/445 SMB 143 IMAP 161 SNMP389 LDAP 443 HTTPS 636 LDAPS 1433 MSSQL 3306 MySQL 3389 RDP5432 PostgreSQL 5985/5986 WinRM 5900 VNC 8080 HTTP-altRecognizing a port is recognizing a surface: 445 = SMB (Windows/AD), 389 = LDAP (AD), 3389 = RDP, 5985 = WinRM.
Routing, NAT, and DNS
Section titled “Routing, NAT, and DNS”- Gateway/routing: how packets leave your subnet toward others (
ip route,route print). - NAT: translates private IPs to public; that’s why your internal
/24isn’t visible from outside (relevant for pivoting). - DNS: translates names to IPs; a key recon piece (see DNS Fundamentals). ARP: resolves IP↔MAC on the LAN (basis of MITM).
Basic tools
Section titled “Basic tools”ip a / ifconfig # interfaces and addressesip route / route print # routing tableping / traceroute # connectivity and hopsnslookup / dig # DNS queriesnetstat -ano / ss -tulpn # local ports and connectionsnmap # port/service scanning (see recon)tcpdump / wireshark # capture and analyze trafficWhy it matters in security
Section titled “Why it matters in security”Without this model you don’t understand what nmap does (SYN scan), why a firewall blocks, how you pivot from one subnet to another, or why you capture hashes at layer 2 (ARP/LLMNR). The network is the terrain; this is the map.
Mastery checklist
Section titled “Mastery checklist”- I understand encapsulation and the layers that matter (IP, TCP/UDP, Application)
- I can read CIDR notation and compute how many hosts a range has
- I can explain the TCP handshake and what each flag/state means
- I distinguish TCP from UDP and why UDP is harder to scan
- I recognize common ports/services from memory
- I understand routing, NAT, and ARP, and their relevance to pivoting/MITM
- I can use ip/ss/dig/tcpdump to inspect the network