all modules module 02 · beginner

Networking for Hackers

Every attack travels over a network. Understand the plumbing and half of “magic” exploits become obvious.

01How data actually moves~5 min

The OSI model is just packaging: your HTTP request gets wrapped in TCP, which gets wrapped in IP, which gets delivered by Ethernet/Wi-Fi. Each layer adds a header; the other side unwraps in reverse.

  • L4 (TCP/UDP): TCP = reliable, ordered (web, SSH). UDP = fast, no guarantees (DNS queries, games).
  • L3 (IP): addressing and routing between networks.
  • L2: MAC addresses, delivery inside one network segment.

A three-way handshake (SYN → SYN-ACK → ACK) opens every TCP connection. A SYN scan sends only the first packet to see what answers — that’s why nmap -sS is called “half-open” scanning. When you understand wrapping, firewall rules (“block port 22 at L4”) stop being mystical.

02IPs, ports & the services you must know~5 min

An IP address finds a machine; a port finds the service on it. Memorize these cold:

  • 21 FTP · 22 SSH/SFTP · 23 Telnet (plaintext, red flag)
  • 25/587 SMTP mail · 53 DNS · 80/443 HTTP/HTTPS
  • 445 SMB (Windows file sharing — EternalBlue territory) · 3389 RDP
  • 3306 MySQL · 5432 PostgreSQL · 6379 Redis · 27017 MongoDB

Databases listening on public IPs are one of the most common real-world findings. The Service Bank on this site documents attack surfaces port-by-port — use it as your reference during scans.

03DNS: the internet’s phone book (and recon goldmine)~5 min

DNS turns names into IPs through a resolver chain: your machine → recursive resolver → root → TLD (.com) → authoritative nameserver. Record types worth knowing:

  • A / AAAA — name to IPv4/IPv6
  • CNAME — alias to another name (subdomain takeovers live here!)
  • MX — mail servers (reveals email provider)
  • TXT — free-form text: SPF, DKIM, domain verification tokens
  • NS — who runs DNS itself

Recon uses: enumerate subdomains (dig, wordlists, certificate transparency logs at crt.sh), spot dangling CNAMEs pointing at deprovisioned cloud services — that’s a subdomain takeover. Try dig any whoiskay.vercel.app on any domain and read the answers.

04HTTP anatomy: requests, headers & status codes~6 min

A request looks like:

GET /search?q=shoes HTTP/1.1
Host: shop.example.com
Cookie: session=abc123
User-Agent: Mozilla/5.0 ...

Method + path + version, then headers. Responses mirror it: 200 OK, 301/302 redirect, 403 forbidden, 404 missing, 500 server exploded.

Key headers for hackers: Cookie (your identity — steal or manipulate), Authorization: Bearer (API tokens), Content-Type, Location (open redirects), security headers like CSP, HSTS, X-Frame-Options whose absence is a finding. Everything in the web-security module happens inside this simple text protocol — open DevTools → Network tab right now and read a real request. That tab is where web hackers live.