Module 02 · Foundation
Networking & Linux Fluency
Become dangerous with the fundamentals: TCP/IP, DNS, HTTP, Linux processes, permissions, and shell pipelines. This module is what lets you understand tool output instead of memorizing flags.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Outcomes
- Read a packet path from client to service and predict what a scanner will see
- Use dig, curl, ss/netstat, tcpdump, and process tools confidently
- Navigate Linux permissions, users, services, and logs without a GUI
- Build shell pipelines to process recon and scan data reproducibly
- Intercept and reason about HTTP with a proxy as a microscope, not an autopilot
Lessons
TCP/IP mental model for attackers
Ports, handshakes, routing, firewalls, and what “open” really means from an operator’s network position.
Learning objectives
- Explain the TCP three-way handshake, teardown, and common socket states
- Differentiate host discovery, port scanning, and service identification
- Predict how drop vs reject firewalls change scan results
- Know when ICMP, ARP, and TCP probes apply (and when they lie)
- Read a Wireshark or tcpdump capture of your own scan and name each step
Deep teach-through
Layers as an operator language
You do not need academic OSI trivia; you need a working stack model. Link layer gets frames to neighbors (ARP on Ethernet). IP routes packets between networks. Transport (TCP/UDP) demultiplexes to ports. Application protocols (HTTP, SMB, DNS) ride above that. Every tool you use lives at one or more of these layers, and mis-layering is why beginners misread results.
An “open port” means a process is accepting connections on that transport endpoint from your vantage point — not that the service is vulnerable, not that the same port is open from the internet, and not that the banner is truthful. Always ask: open for whom, from where, with what middleboxes in the path?
IPv4 still dominates most labs and many enterprise estates; IPv6 is increasingly present and often under-monitored. Dual-stack hosts may expose different services on different families. Include both in mental models early so you do not invent a false sense of completeness from an IPv4-only scan.
TCP handshake, states, and what scanners exploit
TCP connects with SYN → SYN-ACK → ACK. Half-open behavior, RSTs, and silence are the raw signals behind SYN scans, connect scans, and filtered classifications. A listening socket that answers SYN-ACK is open from your perspective; a RST usually means closed; silence often means filtered (or loss, or rate limiting).
Common states you will see with ss or netstat: LISTEN (service waiting), ESTABLISHED (active session), TIME-WAIT (recently closed), SYN-RECV (half-open). Attackers abuse half-open floods in the real world; defenders watch for them. As a tester you use the same signals carefully and only with authorization.
UDP has no handshake. “Open|filtered” is common because lack of response is ambiguous. ICMP port unreachable can mean closed; silence might mean open, filtered, or dropped. Plan extra time and application-level probes (DNS query, SNMP, etc.) when UDP matters.
Host discovery vs port scanning
Host discovery answers “is anything here?” using ICMP echo, ARP (local segment), TCP SYN/ACK to common ports, or other probes. Port scanning assumes a host is worth deeper work and maps transport endpoints. Collapsing both into one loud -A against a /16 is how you miss hosts and annoy defenders.
On a local L2 segment, ARP-based discovery is often more reliable than ICMP. Across routed networks, ICMP may be blocked while TCP/80 and TCP/443 still answer. Professionals choose discovery based on network position and observed policy, not a single default template.
Only scan addresses you are authorized to touch. In labs, document the exact subnet. In client work, use the scope file as -iL input and treat discovery results that fall outside scope as inventory questions for the client, not free targets.
Firewalls, NAT, and relative truth
Scan results are always relative to your network position. A host “filtered” from the internet may be wide open on a VPN, partner link, or internal VLAN. Conversely, internal scans may show services that internet scanners never see. Report both the finding and the vantage point.
Drop vs reject changes what you observe. Drop (silent) produces filtered-looking results and slows scanners that wait for timeouts. Reject (RST or ICMP) fails fast. Stateful firewalls may allow established return traffic only; your outbound SYN from an unexpected source network can look very different from a user on the corporate LAN.
NAT and load balancers further distort the picture: one public IP may hide many backends; one backend may appear under many names. DNS, certificates, and HTTP Host headers become part of network truth, not just “application stuff.”
DNS as the asset map; common protocols as attack surface
DNS turns human names into addresses and often leaks inventory through zone transfers (rare but high impact when allowed), subdomain naming patterns, and public records. Learn dig/nslookup for A/AAAA/MX/TXT/NS/CNAME and for tracing resolution paths. Broken or stale DNS is both an ops problem and a recon gift.
HTTP(S) dominates external attack surface. SMB and LDAP dominate many internal Windows estates. SSH, RDP, databases, and management interfaces matter when exposed. Your protocol priorities should follow engagement type (external web vs internal AD), not a generic port-order superstition.
Practice reading packets while you generate them. Capture an Nmap SYN scan and a curl to HTTPS. Identify Ethernet, IP, TCP, and — where not encrypted — application data. Encryption hides payloads but not the fact of connections, SNI in many setups, and timing. That dual view is what separates flag memorization from fluency.
Lab drills that build intuition
In your host-only lab, assign static IPs, run a simple listener (nc -lvnp 4444 or a web server), and scan it from the attacker VM. Change firewall rules on the target (iptables/nftables or host firewall) between drop and reject and re-scan. Record how Nmap classifications change.
Use tcpdump -i any -nn host TARGET and Wireshark display filters such as tcp.flags.syn==1 to isolate handshake behavior. Correlate ss -lntp on the target with what the scanner claims. When they disagree, you have found a middlebox, wrong interface, or wrong address family — a professional learning moment.
Build a one-page personal reference: discovery options by position, TCP vs UDP caveats, and “open/closed/filtered means…”. Update it after every lab surprise. This sheet will outlive any single tool version.
Key concepts
- Open port
- A transport endpoint accepting connections from your current vantage point — not a vulnerability by itself.
- Filtered
- Probes receive no useful response, often due to firewall drop, loss, or rate limiting.
- Host discovery
- Techniques to determine which addresses appear live before deep port scanning.
- Vantage point
- Your network position (internet, VPN, LAN segment) that shapes every scan result.
- Stateful firewall
- Device that tracks connection state and may allow return traffic only for approved sessions.
Common mistakes
- Treating “open” as “exploitable” without service context
- Running one aggressive scan template for every network position
- Ignoring IPv6 and secondary interfaces
- Believing ICMP silence means the host is down
- Scanning outside the written scope because a reverse DNS name “looked related”
- Never capturing packets, so tool flags remain superstition
Defender view
- Scan telemetry (source, rate, signature) is a primary detection signal — expect SOC visibility on production.
- Drop vs reject is a deliberate tradeoff between stealth of topology and scan speed for adversaries.
- Accurate asset inventory and least-exposed management planes shrink what external scanners can map.
Operator checklist
- Scope file lists every address/name I will touch
- I know whether I am on LAN, VPN, or internet path to the target
- I chose discovery method appropriate to that position
- I can explain open/closed/filtered for my last scan in plain language
- Raw scan output is saved with -oA or equivalent before I digress
Example commands & patterns
sudo tcpdump -i eth0 -nn host 192.168.56.10 and tcp
sudo nmap -sn 192.168.56.0/24 -oA scans/discover
sudo nmap -sS -p 22,80,443 192.168.56.10 -oA scans/top-check
dig +short example.com A
dig example.com ANY +noall +answer
ss -lntp
ip -br a
Practice drills
- Capture your own Nmap SYN scan in Wireshark and label SYN, SYN-ACK, and RST packets
- Map every device on your host-only lab with arp-scan and Nmap discovery; compare results
- On a lab target, toggle a firewall rule between drop and reject and re-run the same scan
- Use dig to resolve a domain you own and document A/AAAA/MX/NS/TXT records
- Write a half-page explanation of why a host might show “filtered” from home but “open” on VPN
Tools for this lesson
Next: Move to Linux daily-driver skills so you can own the attacker OS that generates these packets.
Linux as your daily operator OS
Filesystem, permissions, processes, services, logs, networking tools, and shell pipelines — the non-negotiable operator baseline.
Learning objectives
- Navigate the filesystem, readers, and editors without leaving the terminal
- Explain Linux permissions, ownership, SUID/SGID, and sudo at a working level
- Inspect processes, listening sockets, and systemd service state
- Transfer files multiple ways when labs break differently
- Build small bash pipelines (loops, grep, awk, jq) for recon and scan data
Deep teach-through
Shell fluency beats GUI dependency
Professional operators live in a shell on Linux (or WSL/remote SSH). You need comfortable navigation (cd, ls, find, locate), inspection (file, stat, less, head, tail -f), and editing (nano or vim basics). Muscle memory here multiplies every later module.
Know where things live: /etc for configuration, /var/log for logs, /proc and /sys for kernel-exported state, /home and /opt for user and third-party tools, /tmp for ephemeral scratch (and a place attackers abuse). On target systems later, the same map drives enumeration.
Use man pages and --help deliberately. Memorizing every flag is less valuable than knowing how to learn a flag under pressure. Keep a personal cheatsheet of the twenty commands you actually use weekly.
Users, groups, permissions, and privilege boundaries
Every file has owner user, group, and mode bits (rwx for user/group/other). Directories use execute to mean “traverse.” Misread permissions cause failed tools and missed privilege-escalation paths. Practice reading ls -l and interpreting numeric modes (e.g., 755, 640).
SUID/SGID binaries run with elevated identity — a classic privesc class when misconfigured. Linux capabilities fine-tune privileges beyond all-or-nothing root. You do not need full exploitation skill yet, but you must understand that “who runs this process” and “what file can it touch” are first-class questions.
sudo is policy, not magic. Read sudo -l in labs (authorized targets only) and understand that broad sudo ALL is high risk. On your attacker VM, use a normal user for daily work and escalate only when needed; operating as root for browser and notes is a bad habit.
Processes, services, and network listeners
ps, top/htop, and systemctl status tell you what is running. ss -lntp (or netstat) shows listening sockets and owning PIDs. Correlating a port to a binary is daily work in both offense and defense.
Logs matter: journalctl -u service, /var/log/auth.log or secure, application logs under /var/log. As an attacker in post-exploitation you will read them; as a careful lab operator you will watch them when something breaks.
Package managers (apt, dnf, pacman depending on distro) keep tools current. Prefer distro packages or documented install paths over random curl|bash from untrusted blogs. Pin versions when a lab requires reproducibility.
File transfer and remote interaction
Labs fail in different ways: no SCP, broken GUI, limited tools on target. Practice multiple transfer methods on systems you own: scp/sftp, python3 -m http.server, nc, curl/wget, base64 paste for small files. Knowing three paths prevents dead ends.
ssh is your remote shell; keys beat passwords. Understand ~/.ssh/config host aliases, StrictHostKeyChecking for labs vs production caution, and why agent forwarding can be dangerous on untrusted jumps.
netcat remains a Swiss army knife for listeners, simple transfers, and banner grabs. Prefer ncat or traditional nc consciously; flags differ across implementations. Document which binary your distro provides.
Pipelines: the operator’s data factory
Recon and scanning produce text. Experts pipe: sort -u, grep -E, cut, awk, sed, xargs, tee, and jq for JSON. Tools like anew help append only new lines to growing wordlists and host lists. Your goal is reproducible transforms, not one-off GUI clicks you cannot repeat in a report.
Write small bash loops for authorized lab ranges: while reading hosts from a file, run a safe check, tee results. Always test loops on one IP before launching against a list. A typo in a loop is how scope accidents happen.
OverTheWire Bandit (and similar wargames) compress months of shell pain into structured levels. If pipelines feel slow, invest evenings there before chasing exotic exploits. Shell skill compounds forever.
Operator hygiene on the attacker OS
Keep engagement directories clean, use version-controlled personal scripts carefully (no client data in public git), and separate tool configs from loot. Encrypt disks if the laptop leaves home.
Update consciously: full upgrades mid-engagement can break a working toolset; snapshot or note versions. In labs, rebuild from golden images when the attacker VM becomes a junk drawer.
Python and bash are enough to glue workflows. Learn to read simple scripts others publish before executing them. Treat unknown offensive scripts as untrusted code — because they are.
Key concepts
- SUID
- Binary flag that runs a program with the file owner’s privileges, often root — high value in privesc review.
- Listening socket
- Local endpoint accepting connections; map with ss/netstat and match to a process.
- Pipeline
- Chaining commands so stdout of one becomes stdin of the next for data transformation.
- Least privilege
- Operating and configuring access with only the rights needed for the task.
- systemd unit
- Service/timer definition managed by systemd; common way services start on modern Linux.
Common mistakes
- Living as root on the attacker VM for convenience
- Only knowing one file-transfer method
- Running unreviewed curl|bash installers for offensive tools
- Building bash loops against full lists without a single-host dry run
- Ignoring logs when a service “just doesn’t work”
- Skipping Bandit/shell practice and hitting a wall on every box
Defender view
- Process ancestry, unexpected listeners, and sudo abuse are core detection and hardening themes.
- File integrity and permission audits catch many “it was world-writable” incidents before attackers do.
- Centralized logging turns operator mistakes and real attacks into reconstructable timelines.
Operator checklist
- I can find which process owns a listening port
- I can explain permissions on a sensitive file from ls -l alone
- I have at least three file-transfer options tested in the lab
- My engagement folder structure exists before the first scan
- I dry-run any loop or scripted scan on one in-scope host first
Example commands & patterns
ss -lntp
ps auxf | less
find / -perm -4000 -type f 2>/dev/null | head
systemctl status ssh
journalctl -u ssh -n 50 --no-pager
python3 -m http.server 8000 --bind 127.0.0.1
while read -r ip; do nc -zv -w 2 "$ip" 22; done < hosts.txt
cat hosts.txt | sort -u | tee hosts.uniq.txt
Practice drills
- Complete OverTheWire Bandit levels 0–10 minimum (stretch to 15+)
- Write a bash loop that runs a safe Nmap scan against a list of lab IPs and tees output
- On your attacker VM, map every listening port to a process and document it
- Transfer a file between two lab VMs using three different methods
- Parse a JSON tool output with jq and produce a clean list of hostnames or URLs
Tools for this lesson
Next: Deepen HTTP fluency next — most external engagements live in requests and responses.
HTTP, browsers, and proxies
Requests, responses, cookies, auth headers, TLS basics, and intercepting proxies as instruments of understanding.
Learning objectives
- Manually craft and explain every part of an HTTP request and response
- Configure Burp or ZAP with a browser and intercept traffic safely in a lab
- Explain cookies, sessions, and common token patterns (including JWT at a high level)
- Use Repeater-style workflows to test one hypothesis at a time
- Recognize status codes, redirects, caching, and CORS as daily vocabulary
Deep teach-through
HTTP as a readable protocol
An HTTP request has a method and path (and optional query string), headers, and sometimes a body. A response has a status code, headers, and body. If you cannot draw that on a whiteboard, web testing will feel like magic no matter how many scanner plugins you install.
Methods carry intent: GET for retrieval (should be safe/idempotent in well-behaved apps), POST for actions and bodies, PUT/PATCH/DELETE in APIs, OPTIONS for CORS preflight. Real apps misuse methods; do not assume compliance — observe behavior.
Headers are a goldmine: Host, User-Agent, Cookie, Authorization, Content-Type, Origin, Referer, X-Forwarded-For (sometimes trusted naively). Learn to read them before you automate changing them.
TLS, Host headers, and virtual hosting
HTTPS encrypts HTTP over TLS. As a tester you still see endpoints, certificates, redirects, and often SNI. Certificate names feed recon; weak TLS configs can be findings; mixed content and cookie Secure flags matter.
Virtual hosts mean one IP can serve many sites. The Host header (and SNI) selects which site you hit. Content discovery and routing bugs often depend on sending the right Host value. Your mental model must include name-based routing, not only IP:port.
Use curl -v and curl -k carefully in labs. Verbose mode teaches handshake and header flow. In professional work, respect scope and avoid needless certificate validation bypasses against production without reason.
Sessions, cookies, and tokens
Most apps track logged-in state with cookies or bearer tokens. Cookie flags (HttpOnly, Secure, SameSite) and scope (Domain/Path) affect theft and CSRF risk. Session fixation, weak session IDs, and missing invalidation on logout are classic issues.
JWT and similar tokens appear in Authorization headers or cookies. At this stage, understand structure (header.payload.signature), that payloads are readable (Base64), and that “algorithm none” and weak secrets are classes you will test later — not that you should attack random sites.
Authorization is not authentication. Logging in as user A and accessing user B’s object (IDOR) is often higher real-world impact than a flashy XSS on a marketing page. Train yourself to watch object IDs and role boundaries early.
Intercepting proxies as microscopes
Burp Suite, OWASP ZAP, mitmproxy, and similar tools sit between browser and server. You configure the browser (or system) proxy, trust the lab CA, and intercept. The goal is visibility and controlled modification — not blind autopilot scanning on day one.
Repeater (or equivalent) is where understanding happens: send one request, change one variable, observe. Intruder/fuzzing comes after you have a hypothesis. History and site maps become part of your evidence pack — export them into engagement folders.
Scope the proxy to in-lab or in-engagement hosts so you do not accidentally send personal traffic through an intercepting stack or attack the wrong host. Disable intercept when navigating complex flows so you do not fight your own tool.
Status codes, caching, CORS, and daily signals
Status codes tell stories: 401 vs 403, 302 login redirects, 500 stack traces, 200 on “not found” soft pages that break content discovery filters. Never trust a single code without body context.
Caching and CDNs can serve different content by cookie, country, or header. CORS policy governs browser cross-origin reads; misconfiguration can leak authenticated responses to evil origins. You will test these deeply in web modules — learn the vocabulary now.
Postman and curl remain valuable for API work without a full browser. Build a small collection of lab API calls with saved tokens. Prefer replaying captured legitimate requests over inventing shapes that the app never uses.
Key concepts
- Intercepting proxy
- Tool that terminates and reveals HTTP(S) between client and server for inspection and modification.
- Virtual host
- Name-based site selection on a shared IP, driven by Host header and often TLS SNI.
- Session
- Server-side (or token-carried) state binding a client to an authenticated identity across requests.
- Authorization header
- HTTP header commonly carrying credentials or bearer tokens for API and app auth.
- Same-origin policy
- Browser rule restricting how documents from one origin read another — foundational to web security.
Common mistakes
- Running automated scanners before understanding a single login request
- Trusting personal browser profile + proxy CA for banking and lab mixed together
- Ignoring Host header and testing only by IP
- Changing five parameters at once in Repeater and learning nothing
- Treating 403 as uninteresting without checking alternate paths or methods
- Exporting full HTTP histories with session tokens into unsecured chat apps
Defender view
- Security headers, cookie flags, and centralized authn reduce entire classes of bugs.
- WAF and gateway logs show probing patterns; professional testers coordinate noisy tests.
- TLS and certificate hygiene protect users in transit; broken lab CAs must never ship to production trust stores.
Operator checklist
- I can draw a request/response and label method, path, headers, body, status
- Proxy is scoped to lab or authorized hosts only
- I captured a clean login and one authenticated page in history
- I replayed one request in Repeater with a single intentional change
- Evidence exports are stored in the engagement folder, not random screenshots only
Example commands & patterns
curl -v http://127.0.0.1:3000/
curl -k -v https://192.168.56.10/
curl -X POST http://127.0.0.1:3000/login -H 'Content-Type: application/x-www-form-urlencoded' -d 'user=admin&pass=admin'
# Configure browser proxy 127.0.0.1:8080 → Burp/ZAP; install lab CA
mitmproxy -p 8080
Practice drills
- Intercept a login to DVWA or Juice Shop and replay it in Repeater with one modified field
- Change a cookie or parameter and document authorization behavior before vs after
- Use curl -v to fetch the same page as the browser and compare headers
- Map every cookie set during login; note flags and scope
- Export a small HTTP history subset as evidence for a mock finding draft
Tools for this lesson
Next: With packets, shell, and HTTP under control, begin Module 3: quiet reconnaissance and OSINT.