Every attack travels over a network. Understand the plumbing and half of “magic” exploits become obvious.
The OSI model is just packaging: your HTTP request gets wrapped in TCP, which gets wrapped in IP, which gets delivered by Ethernet/Wi-Fi. Each layer adds a header; the other side unwraps in reverse.
A three-way handshake (SYN → SYN-ACK → ACK) opens every TCP connection. A SYN scan sends only the first packet to see what answers — that’s why nmap -sS is called “half-open” scanning. When you understand wrapping, firewall rules (“block port 22 at L4”) stop being mystical.
An IP address finds a machine; a port finds the service on it. Memorize these cold:
Databases listening on public IPs are one of the most common real-world findings. The Service Bank on this site documents attack surfaces port-by-port — use it as your reference during scans.
DNS turns names into IPs through a resolver chain: your machine → recursive resolver → root → TLD (.com) → authoritative nameserver. Record types worth knowing:
Recon uses: enumerate subdomains (dig, wordlists, certificate transparency logs at crt.sh), spot dangling CNAMEs pointing at deprovisioned cloud services — that’s a subdomain takeover. Try dig any whoiskay.vercel.app on any domain and read the answers.
A request looks like:
GET /search?q=shoes HTTP/1.1 Host: shop.example.com Cookie: session=abc123 User-Agent: Mozilla/5.0 ...
Method + path + version, then headers. Responses mirror it: 200 OK, 301/302 redirect, 403 forbidden, 404 missing, 500 server exploded.
Key headers for hackers: Cookie (your identity — steal or manipulate), Authorization: Bearer (API tokens), Content-Type, Location (open redirects), security headers like CSP, HSTS, X-Frame-Options whose absence is a finding. Everything in the web-security module happens inside this simple text protocol — open DevTools → Network tab right now and read a real request. That tab is where web hackers live.