Networking From the Ground Up: Addresses, Ports, Protocols and the Rooms

The module that follows the command line in the Cyber Security 101 path, built for a beginner who can run commands but has no picture behind them. It covers the two-address system and why both are needed, the private ranges, reading slash notation and turning a prefix into a usable host count, the four-layer model, DHCP, ARP and NAT, ports with TCP against UDP and the three-way handshake, the difference between closed and filtered, DNS lookups and the records worth enumerating, what the TLS padlock does and does not prove, and the eight commands that open almost every networking room.

Subject: Cyber Security 101 · 62 slides · code lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. Networking, from the Ground Up

Title

Cyber Security 101, session 2

The module after the command line, and the one that unlocks every later room

2. What today gets you past

Objectives

Last session was about getting into files. This one is about the module that follows it, and it is the point where the rooms stop telling you which command to run and start assuming you already know what an address, a port and a handshake are. Everything after this in the path — scanning, exploitation, defensive security — is built on it.

  1. Explain why every machine has two addresses, and what each one is for
  2. Read a slash-notation address and say how many machines fit in the block
  3. Name what each of the four layers adds, and use that to place any protocol
  4. Describe how a machine gets an address, finds its neighbours, and reaches the outside
  5. Say what a port is, and tell TCP from UDP by what they promise
  6. Follow a DNS lookup end to end, and read the record types you will meet
  7. Say what the padlock does and does not prove
  8. Run the eight commands that appear in nearly every networking room, and read their output

TryHackMe, Cyber Security 101 path — the Networking module the Networking module

3. Part 1 — Why this is the next wall

Section

Orientation

4. What changes in these rooms

Concept

You said the hard part was not understanding a command but doing the specific thing being asked. The networking rooms sharpen that, because they ask for things that only make sense if you have a picture in your head.

What a command-line room asks
Find the flag in a file somewhere on the drive. The task is concrete, the answer is in a place, and the command either finds it or does not.
What a networking room asks
Which service is running on the target, and what version. There is no file to find. You have to know that services sit on ports, that a scanner asks each port in turn, and what an answer looks like.

So the goal today is not commands. It is the picture, with the commands hung off it — because once the picture is there, the commands are obvious and you can work out ones I never show you.

TryHackMe, Cyber Security 101 path — the Networking module the Networking module

5. Predict: what does a network actually move?

Prediction

Answer from first principles rather than from anything you have read.

Predict first

When you load a web page, what travels across the network?

  • The page, as one continuous stream
  • Many small packets, each independently addressed
  • A single file, compressed
  • A live connection with the server's disk

Correct: Many small packets, each independently addressed

Why: Everything is chopped into packets, each carrying its own addressing, each routed independently, and they can arrive out of order or not at all. Almost every idea in this module exists because of that one fact: addressing, ports, ordering, retransmission and the handshake are all consequences of packets being independent.

6. Part 2 — Addresses

Section

MAC and IP

7. Two addresses, two jobs

Concept

Every machine has at least two addresses and beginners routinely assume one is just an older version of the other. They do different jobs and both are needed on every single packet.

MAC address — a 48-bit identifier fixed to the network card, written as six pairs of hex digits, used only inside your local network

IP address — a 32-bit address in IPv4, written as four numbers, assigned by the network and used to route across the world

TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts

8. The building and the desk

Picture it

The analogy that makes the pair stop feeling redundant.

Figure (svg): Two panels comparing a MAC address burned into the network card with an IP address handed out by the network, framed as a name on a door and a postal address

A letter needs the postal address to cross the country and the name on the door to reach you once it arrives. Strip either one and the delivery fails, which is exactly why packets carry both.

9. Why does the MAC never leave?

Socratic

Think about what would have to be true for it to be useful further away.

Discussion prompt

Why is the MAC address useless for routing a packet across the internet?

Hint: Could a router anywhere in the world guess which way to send a MAC address?

Answer:

Because MAC addresses have no structure. They are assigned by manufacturers, so two machines on opposite sides of the world can have addresses that look adjacent and are unrelated.

IP addresses are handed out in blocks by location and network, so a router can look at the front of an address and know roughly which direction to send it without knowing the destination.

That is the whole reason for the split: MAC is a flat namespace and works only where everyone can shout to everyone; IP is a structured namespace and works at scale.

10. Private addresses, and why yours starts with 192.168

Concept

Three ranges are reserved for use inside private networks and are never routed on the public internet. You will see them constantly, and recognising them at a glance is genuinely useful in a room.

rangeslash notationwhere you meet it
10.0.0.0 to 10.255.255.25510.0.0.0/8large corporate networks, many lab VPNs
172.16.0.0 to 172.31.255.255172.16.0.0/12Docker's default, and mid-size networks
192.168.0.0 to 192.168.255.255192.168.0.0/16home routers, nearly every home lab
127.0.0.0 to 127.255.255.255127.0.0.0/8loopback — this machine, always

If a room gives you a target on one of these ranges, it is telling you the machine is on the same network you were placed in, not somewhere on the public internet.

RFC 1918, Address Allocation for Private Internets the reserved ranges

11. Sort these addresses

Definition probe

Recognising the range on sight saves you a lookup every time.

Sort into buckets

Public, private, or neither?

private
192.168.0.14; 10.10.55.3; 172.20.9.1
public
8.8.8.8; 203.0.113.7
loopback
127.0.0.1
priv
It falls inside one of the three reserved blocks, so it is only meaningful inside a local network and is never routed across the internet.
pub
It sits outside every reserved range, so it is routable and belongs to someone on the public internet. The second is a well-known public DNS resolver.
loop
Anything starting 127 refers to the machine you are typing on. It never reaches the network card at all, which is why it works with the cable unplugged.

12. Part 3 — Subnets

Section

Reading slash notation

13. What the number after the slash means

Concept

This is the piece of arithmetic that beginners skip and then hit repeatedly. It is genuinely simple once stated properly.

An IPv4 address is 32 bits. The number after the slash says how many of those bits identify the network. Whatever is left over identifies the machine.

\[ \text{host bits} = 32 - \text{prefix}, \qquad \text{addresses} = 2^{\,\text{host bits}} \]

Two of those addresses are always spoken for: the first names the network itself and the last is the broadcast address, so the usable count is two fewer than the total.

TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts, subnetting

14. A /24 against a /26

Picture it

The same starting address, cut two different ways.

Figure (svg): A wide bar representing a slash twenty-four block of 256 addresses above four narrower bars representing slash twenty-six blocks of 64 addresses each

A bigger prefix means fewer host bits, which means smaller blocks and more of them. That is the whole relationship, and it runs backwards from how people expect, which is why it is worth drawing once.

15. The pattern: prefix to block size in one step

Pattern

You do not need to convert to binary in a room. You need this table, and after a week you will not need the table either.

prefixhost bitsaddressesusablesubnet mask
/248256254255.255.255.0
/257128126255.255.255.128
/2666462255.255.255.192
/2753230255.255.255.224
/2841614255.255.255.240
/30242255.255.255.252

Read it as halving: every step up the prefix halves the block. Learn /24 and the doubling does the rest.

TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts

16. Worked example: which block is 192.168.1.100 in?

Worked example

The exact question a room will ask, done the way you should do it under time pressure.

Given the address 192.168.1.100 with a /26 prefix, find the network address, the broadcast address, and the usable range.

Figure (svg): A slash twenty-four bar above four slash twenty-six blocks, with the block containing address one hundred highlighted

Find the block size

Why: A /26 leaves six host bits, and two to the sixth is 64. So the blocks are 64 addresses wide.

Count blocks up to the address

Why: Blocks start at 0, 64, 128 and 192. The value 100 falls between 64 and 127.

Name the boundaries

Why: The first address in that block is the network address; the last is the broadcast.

roleaddresswhy
network192.168.1.64first address in the block, names the network
first usable192.168.1.65the one after the network address
last usable192.168.1.126the one before the broadcast
broadcast192.168.1.127last address in the block, reaches everyone

Verify: the arithmetic

Why: From 65 to 126 inclusive is 62 addresses, which matches the 62 usable the table predicts for a /26. If your count comes out at 64 you included the network and broadcast; if 63, you included one of them.

TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts, subnetting

17. Check: how many machines fit?

Check

Solve it on paper before you click.

Check your understanding

A room places you on 10.10.10.0/28. How many usable addresses does that network hold?

  • A. 16
  • B. 14 (correct)
  • C. 28
  • D. 254

Answer: B

Why: A /28 leaves four host bits, so the block holds two to the fourth, which is 16 addresses. Subtracting the network address and the broadcast address leaves 14 for actual machines.

Why A tempts people
That is the total size of the block. Two of those 16 can never be assigned to a machine, so the usable count is 14.
Why C tempts people
This reads the prefix as a count of hosts. The 28 is a count of network bits out of 32, not a number of machines.
Why D tempts people
That is the usable count for a /24. A /28 is four steps up from that, and each step halves the block.

18. Fill the middle: the block-size rule

Fill the middle

State it once in your own symbols and it stops needing the table.

Fill in the blanks

A /27 leaves 5 host bits, so the block holds 32 addresses and 30 are usable.

Why: Thirty-two total bits minus a prefix of 27 leaves five host bits. Two to the fifth is 32 addresses in the block, and removing the network and broadcast addresses leaves 30 that can be given to machines.

19. Part 4 — Layers

Section

The practical version

20. Four layers, not seven

Concept

You will meet the seven-layer OSI model and it is worth recognising, but the four-layer model is what actually maps onto the packets you will look at, so learn this one first.

The point of layers is not classification for its own sake. It is that each layer can be changed without touching the others — swapping Wi-Fi for a cable changes the bottom layer and nothing above it notices.

TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts, the models

21. What each layer adds

Picture it

Read it top to bottom: that is the order things get wrapped as a packet leaves your machine.

Figure (svg): Four nested horizontal bars labelled Application, Transport, Internet and Link, each wider than the one above, with example protocols beside each

When a room asks which layer something operates at, ask instead which question it answers. Which application? Which conversation? Which machine? Which cable?

22. Match the protocol to its layer

Matching

You do not memorise this. You reason it out from what each layer is responsible for.

Match the pairs

  • p1. HTTP
  • p2. TCP
  • p3. IP
  • p4. Ethernet
  • p5. DNS
  • q1. Application — what the data means
  • q2. Transport — which conversation, and is it reliable
  • q3. Internet — which machine, anywhere
  • q4. Link — which card on this cable

Why: HTTP and DNS both carry meaning that an application interprets, so both sit at the top. TCP is about the conversation rather than its content. IP is about reaching a machine. Ethernet is about the physical hop. Two protocols sharing a layer is normal — the layer is a job, not a slot.

23. Part 5 — Getting onto a network

Section

DHCP, ARP and NAT

24. How a machine gets an address

Concept

You plug in and it works, and it is worth knowing what happened, because when it does not work these are the four steps to check.

  1. Discover — the machine shouts to the whole local network asking whether any server hands out addresses
  2. Offer — a DHCP server replies with an address it is willing to lend
  3. Request — the machine says it will take that one
  4. Acknowledge — the server confirms, and adds the gateway and DNS server to the reply

That last point matters more than it looks. DHCP does not just give you an address; it tells you which machine is your way out and which machine answers name lookups. Almost everything you do afterwards depends on those two.

TryHackMe, Cyber Security 101 path — the Networking module Networking Essentials

25. ARP: the shout that finds a MAC

Picture it

You know the neighbour's IP. The packet cannot leave without their MAC. This is how the gap gets closed.

Figure (svg): One machine broadcasting a request to three others on the local network, with the matching machine replying

The reply is cached, which is why the first packet to a neighbour is slightly slower than the rest. It is also why ARP cache poisoning is a classic local-network attack — nothing in the protocol checks whether the answer is honest.

26. NAT: why your address is not the one the world sees

Picture it

The reason a private address can still browse the internet.

Figure (svg): Three private addresses feeding into a router which rewrites the source address to a single public address

The router keeps a table of which internal machine each conversation belongs to, so the replies get back to the right one. This is also why a machine behind NAT cannot simply be connected to from outside — there is no entry in the table until it starts the conversation.

27. Why can rooms reach you but the internet cannot?

Socratic

This explains a thing that puzzles almost everyone in their first few labs.

Discussion prompt

When a lab gives you a VPN and a 10.x address, why can the target machine reach you when the wider internet cannot?

Hint: What address does the target see when you connect, and can it route back to it?

Answer:

Because the VPN puts you inside the same private network as the target. From the target's point of view you are a neighbour on 10.x, not a stranger on the internet.

That matters for anything that asks the target to connect back to you — a reverse shell, a file transfer you host. It only works because you are inside, and your public address is irrelevant.

If you try the same thing from your home machine without the VPN, the callback has nowhere to land, because NAT has no entry for a conversation your machine did not start.

28. Part 6 — Ports and the handshake

Section

TCP against UDP

29. A port is which service, not which machine

Concept

The IP address gets a packet to the machine. The port says which program on that machine should receive it. Without ports, a machine could run exactly one network service.

port — a 16-bit number identifying one service on a machine, so a single address can host many services at once

Numbers up to 1023 are the well-known ports and are conventionally reserved for standard services. The convention is not enforced by anything — a web server can listen on 8080 or 31337, and in a CTF room it frequently does.

IANA Service Name and Transport Protocol Port Number Registry the port registry

30. One address, many doors

Picture it

The picture that makes port scanning make sense before you ever run a scanner.

Figure (svg): A building labelled with one IP address containing five numbered doors for SSH, DNS, HTTP, HTTPS and RDP

A port scan is knocking on every door in turn and writing down which ones answer. That is genuinely all it is, and the three answers you can get are the next thing worth knowing.

31. The ports worth knowing by heart

Concept

Roughly a dozen numbers cover most of what you meet. Seeing one in a scan should immediately suggest what to try next.

portservicewhat it suggests
21FTPfile transfer, often with anonymous login left on
22SSHremote shell, the usual way in if you find credentials
23Telnetremote shell with no encryption at all, a finding in itself
25SMTPmail sending
53DNSname lookups, sometimes zone transfers
80HTTPa website, unencrypted — always look at it
139 and 445SMBWindows file shares, a very common route in
443HTTPSthe same website, encrypted
3389RDPWindows remote desktop

IANA Service Name and Transport Protocol Port Number Registry assigned numbers

32. The three-way handshake

Picture it

What TCP does before any data moves, and what UDP skips.

Figure (svg): A sequence diagram between a client and a server showing SYN, SYN-ACK and ACK packets

Because a scanner can start this and watch what comes back, the handshake is also how port scanning works. A SYN that gets SYN-ACK means open; a SYN that gets a reset means closed; a SYN that gets nothing at all means a firewall ate it.

33. TCP against UDP

Comparison

One promises delivery and pays for it; the other promises nothing and is fast.

Comparison matrix

questionTCPUDP
is there a handshakeyes, three packets before any datano, it just sends
does it retransmit what is lostyesno, a lost packet is simply gone
does it keep the orderyes, it reassembles in sequenceno, packets can arrive shuffled
what uses itthe web, SSH, file transfer, emailDNS, video calls, most game traffic
why you would choose ityou cannot tolerate a missing bytea late packet is worse than a lost one

The choice is about what failure costs. Half a file is useless, so file transfer takes the overhead. Half a second of stale video is worse than a dropped frame, so calls do not.

34. Eliminate the wrong reading of a scan

Elimination

Your scan reports port 445 as filtered. Three of these conclusions are wrong.

Eliminate the wrong options

Which conclusion is actually supported?

  • s1. The service is definitely not running.
  • s2. Something is dropping the packets, so you learned nothing about the service itself.
  • s3. The port is closed.
  • s4. The machine is offline.

Survives elimination: s2

Why: The three scan results mean three different things. Open means something answered and accepted. Closed means something answered and refused, which still proves the machine is alive and reachable. Filtered means nothing came back, so a firewall is between you and it and the state of the service is simply unknown. Treating filtered as closed is the most common misreading of a first scan.

35. Which protocol would you expect on which transport?

Discrimination

Reason from what failure costs rather than from memory.

Sort into buckets

TCP or UDP?

TCP
Downloading a file over HTTP; An SSH session; Sending email over SMTP
UDP
A DNS lookup; A live voice call; Streaming game position updates
tcp
A missing or reordered byte ruins the result. A file with a hole in it is corrupt, a shell that drops a keystroke is unusable, and an email missing a line is wrong. The handshake and retransmission are worth their cost.
udp
Speed matters more than completeness, and a late packet is worse than a lost one. A dropped audio frame is a click; a re-sent one arriving half a second late is worse. DNS goes further — the query is so small that asking again is cheaper than a handshake.

36. Estimate: how big is a full scan?

Estimation

Worth calibrating, because it explains why default scans are not exhaustive.

Predict first

How many TCP ports exist on a single machine?

  • 1,024
  • 10,000
  • 65,535
  • about a million

Correct: 65,535

Why: A port number is 16 bits, so there are 65,535 usable values. Scanners default to the roughly 1,000 most common precisely because checking all of them takes far longer — which is exactly why a room that hides a service on a high port is not caught by a default scan, and why the flag for all ports exists.

37. Push it: what happens when addresses run out?

Edge cases

A thirty-two-bit address space sounds enormous. Push on whether it is.

Discussion prompt

IPv4 has about four billion addresses and there are more connected devices than that. Why does the internet still work?

Hint: What is every home router already doing to your address?

Answer:

Largely because of NAT. An entire home or office sits behind one public address, so hundreds of devices consume one address between them rather than one each.

That is a workaround rather than a fix, and it has a cost: a machine behind NAT cannot be connected to from outside unless something is deliberately configured, which is why callbacks in labs need you inside the network.

The actual fix is IPv6, with 128-bit addresses — enough that every device can have a globally routable one and NAT becomes unnecessary. Adoption has been slow precisely because NAT worked well enough for long enough.

38. Part 7 — The core protocols

Section

DNS and the rest

39. DNS is the phone book, and the lookup is a chain

Concept

No human types an IP address, so before nearly every connection there is a lookup turning a name into an address. It is worth knowing the chain because it is a place things break and a place information leaks.

RFC 1035, Domain Names — Implementation and Specification the DNS specification

40. A lookup, hop by hop

Picture it

Five steps, and each answer is cached so the next lookup skips most of them.

Figure (svg): A five-step flow from the client asking a resolver, through root and top-level servers, to the authoritative server returning an address record

Caching is why the first visit to a site is slower than the second, and why a DNS change takes time to take effect everywhere — old answers are still sitting in caches until they expire.

41. The record types you will actually meet

Concept

A room asking you to enumerate DNS is asking you to look for these. Most are unremarkable; two of them regularly leak useful information.

recordwhat it holdswhy you care
Aan IPv4 address for a namethe basic lookup
AAAAan IPv6 addresssame job, longer addresses
CNAMEan alias pointing at another namereveals what a service is really hosted on
MXthe mail servers for a domainnames infrastructure you might not have found
TXTarbitrary textoften holds verification strings, sometimes far more
NSthe authoritative name serversthe start of enumerating a domain

RFC 1035, Domain Names — Implementation and Specification resource records

42. Worked example: look a name up by hand

Worked example

Two commands you will use in almost every room that touches a domain.

# the quick one, on any system
nslookup tryhackme.com

# the detailed one, on Linux — ask for one record type at a time
dig tryhackme.com A +short
dig tryhackme.com MX +short
dig tryhackme.com TXT +short

Figure (svg): A terminal panel showing nslookup output with the answering server, the non-authoritative note and the resolved address highlighted separately

Read the output in three parts

Why: Which server answered you, which question was asked, and the answer section itself.

what you seewhat it meanswhat to do next
a Server linewhich resolver answerednote it — in a lab it may be the target
Non-authoritative answerthis came from a cache, not the sourcefine for an address, not for enumeration
an A recordthe address the name resolves toscan it
no answer at allthe name does not exist, or the resolver is blockedtry a different resolver before concluding

Verify: against a name you know

Why: Run it on a name you are certain exists before trusting a negative result on one you are unsure about. A blocked resolver and a nonexistent name look almost identical, and telling them apart saves a lot of wasted effort.

RFC 1035, Domain Names — Implementation and Specification queries and responses

43. Find the error: reading a scan result

Error analysis

A beginner writes this conclusion into their notes after a scan.

Annotate

On: \( \text{port } 80 \text{ open} \;\Rightarrow\; \text{the site is insecure} \)

  • Port 80 being open means an unencrypted web service is listening. It does not by itself say anything about the security of the application on it.
  • Many sites listen on 80 purely to redirect to 443, which is normal and correct rather than a finding.
  • The finding worth writing down is narrower and more useful: traffic to this port is unencrypted, so check whether anything sensitive is served or accepted over it rather than redirected.

Precision in notes is a real skill in these rooms. Write down what you observed and what it permits you to conclude, and keep those two lines separate.

44. Part 8 — Secure protocols

Section

What the padlock proves

45. Encryption and identity are two separate things

Concept

TLS does two jobs at once and beginners routinely collapse them into one, which leads to a genuinely dangerous misunderstanding.

Encryption
Nobody in the middle can read the traffic. This says nothing whatever about who is on the other end.
Identity
A certificate signed by an authority your machine trusts asserts that the server really is the name it claims. This is what stops encryption being pointless.

A phishing site can hold a perfectly valid certificate for its own name and serve you over a flawless encrypted connection. The padlock proves the connection is private and that the name matches the certificate. It proves nothing about whether the name is one you should trust.

RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3 TLS 1.3

46. The handshake behind the padlock

Picture it

Five steps, and they happen after the TCP handshake and before the first byte of the page.

Figure (svg): Five sequential steps labelled ClientHello, ServerHello, Certificate, Key exchange and Finished, each with a plain-language description

Worth noticing that the certificate arrives in step three, before any of your data is sent. That ordering is the point: you verify who you are talking to before you say anything.

47. Two truths and a lie about HTTPS

Two truths and a lie

Two of these are safe to say in a report. One is the sentence that gets people phished.

Eliminate the wrong options

Cross out the false statement.

  • h1. The traffic cannot be read by someone on the same Wi-Fi.
  • h2. The server's name matches a certificate a trusted authority signed.
  • h3. The site is safe and run by a legitimate organisation.

Survives elimination: h3

Why: Certificates are free and automated, so anyone can get a valid one for a domain they control, including an attacker who registered a lookalike name an hour ago. The padlock is a statement about the connection, not about the organisation behind it. Reading it as a safety badge is precisely the assumption phishing relies on.

48. The insecure protocol and its replacement

Comparison

Most of the older protocols have a direct modern equivalent, and finding the old one in a scan is itself a finding.

Comparison matrix

oldportmodern replacement
Telnet, plaintext shell23SSH on 22
FTP, plaintext transfer21SFTP or SCP, both over SSH on 22
HTTP, plaintext web80HTTPS on 443
SMTP without encryption25SMTP with STARTTLS, or on 587

In a room, spotting the left-hand column is often the whole point of the scan. Credentials sent over any of them can simply be read off the wire.

49. Part 9 — The commands

Section

What to run in a room

50. Eight commands cover almost everything

Concept

These appear again and again. Learn what each one answers rather than its flags, and you can look the flags up.

questionLinuxWindows
what is my addressip aipconfig
can I reach that machinepingping
what is the path theretraceroutetracert
what does this name resolve todig or nslookupnslookup
what is listening on my machiness -tulpnnetstat -ano
who are my neighboursarp -aarp -a
what is open on the targetnmapnmap
what is my way outip routeroute print

TryHackMe, Cyber Security 101 path — the Networking module Networking Essentials

51. Worked example: the first four minutes in a networking room

Worked example

A repeatable opening sequence. Run these before you think about the task, because they tell you where you are.

ip a                    # my address and which interface the VPN gave me
ip route                # my gateway - the way out of this network
ping -c 3 10.10.x.x     # is the target actually up
nmap -sV -T4 10.10.x.x  # which ports answer, and what is running on them

Read each answer before running the next

Why: Each command narrows what the next one should be. Running all four blind wastes the information.

commandwhat you are looking forwhat it changes
ip athe tun0 interface and its addressconfirms the VPN is up at all
ip routethe default gatewaytells you the shape of the network you are in
pingreplies, and the time they takeup or down, before you waste a scan
nmap -sVopen ports and service versionsdecides everything you do next

Verify: that the first command worked before trusting the last

Why: If there is no tun interface, you are not on the lab network and every later result is meaningless. More than one wasted hour has been spent scanning from outside the VPN.

TryHackMe, Cyber Security 101 path — the Networking module Networking Essentials

52. What traceroute is really doing

Picture it

The cleverest small trick in networking, and it makes TTL make sense.

Figure (svg): Four hops with increasing TTL values, each router reporting a time-exceeded message back to the sender

Every packet carries a time-to-live that each router decrements. Send one with a TTL of one and the first router kills it and reports back. Send one with a TTL of two and the second does. Collect the reports and you have the path.

53. Trap: concluding the host is down because ping fails

Trap

The trap

You ping the target and get nothing back.

Write it off as offline

Why: Move on, or spend twenty minutes trying to fix the VPN that is working perfectly.

Miss the machine entirely

Why: The box was up the whole time and the room is unfinishable until you come back to it.

The fix

You ping the target and get nothing back.

Remember what ping actually uses

Why: It sends an ICMP echo request, and plenty of hosts — Windows by default — simply do not answer those.

Ask a different question

Why: Scan a port instead. In nmap the flag that skips the ping check entirely is the one to reach for, and a machine that answers on 445 is very obviously up whatever it thinks of your ping.

54. Check: pick the right tool

Check

Solve it on paper before you click.

Check your understanding

You can reach the target by IP but a hostname the room gave you does not work. What is the first thing to check?

  • A. The target is down.
  • B. Name resolution — the machine cannot turn that name into an address. (correct)
  • C. The port is filtered.
  • D. The VPN has dropped.

Answer: B

Why: Reaching it by IP proves the network path, the VPN and the host are all fine. The only thing the hostname adds is a lookup, so that is the step that failed. Many rooms expect you to add the name to your hosts file yourself, precisely so you meet this.

Why A tempts people
It cannot be — you just reached it by IP. That success rules the whole possibility out.
Why C tempts people
Filtering is per port and would affect the IP just as much as the name. The IP worked, so this is not it.
Why D tempts people
Also ruled out by the IP working. If the VPN were down, neither route would reach the machine.

55. Part 10 — Consolidation

Section

Making it stick

56. Order the packet's journey

Ranking

You type an address and press enter. Put what happens in order.

Put in order

  1. DNS turns the name into an IP address
  2. The machine checks whether that IP is on its own network
  3. ARP finds the MAC of the gateway, since it is not
  4. The TCP three-way handshake opens the connection
  5. The TLS handshake agrees keys and checks the certificate
  6. The HTTP request is finally sent

Why: Nothing can happen before the name becomes an address. Then the routing decision comes before the addressing one — you only ARP for the gateway once you know the destination is elsewhere. TCP opens the pipe, TLS secures it, and only then does the actual request go. Six steps before one byte of your request leaves, and every one of them is a place a room can break on purpose.

57. Explain the two-address system

Explain it to yourself

If you can say this cleanly, most of the module has landed.

Discussion prompt

In your own words, why does a packet need both a MAC address and an IP address?

Hint: Which of the two changes as the packet crosses each router?

Answer:

The IP address identifies the destination machine anywhere in the world, and it is structured so routers can forward toward it without knowing exactly where it is.

The MAC address identifies the next physical device on this particular cable or wireless link, and it changes at every hop.

So the IP stays the same the whole journey and the MAC is rewritten at each step. One is the destination, the other is the next move toward it.

58. Where this shows up outside a room

Real world

Worth grounding, because these are the same skills your work network runs on.

Discussion prompt

Your home Wi-Fi says connected but nothing loads. Using only today's material, what do you check and in what order?

Hint: Work outwards: yourself, then your gateway, then the world, then names.

Answer:

Do you have an address at all? If it starts 169.254 then DHCP never answered and you have no usable address, which is a different problem from having no internet.

Can you reach the gateway? If not, the problem is between you and the router. If yes, the router is fine and the problem is further out.

Can you reach a public IP directly but not a name? Then everything works except DNS, which is the single most common cause of the site cannot be reached.

That is three checks that split the possibilities roughly in half each time, and it is exactly the sequence you would run against a lab target.

59. Retrieval: eight answers, no notes

Warm-up

Close the deck. This is the check on whether today stuck.

Discussion prompt

From memory: the two addresses and their jobs; the three private ranges; the usable count in a /26; the three TCP handshake packets; what filtered means; what port 445 suggests; what the padlock proves; and what traceroute exploits.

Hint: Two addresses, three ranges, one count, three packets, one word, one service, one limit, one field.

Answer:

MAC for the local hop, IP for routing across the world.

Ten dot anything, 172.16 through 172.31, and 192.168 dot anything.

Sixty-two, because a /26 leaves six host bits giving 64 addresses, minus the network and broadcast.

SYN, SYN-ACK, ACK.

No answer came back, so a firewall is in the way and the service state is unknown — which is not the same as closed.

SMB, meaning Windows file sharing, and a very common way into a machine.

That the connection is encrypted and the name matches the certificate. Nothing about whether the site is trustworthy.

The time-to-live field, by sending packets designed to expire one hop further along each time.

60. Draw the journey on one page

Connect it up

Twenty minutes on this beats another hour of reading, and it is the artefact to bring next session.

Draw it

Draw your machine on the left and a web server on the right, with a router between them. Label your machine with both its addresses. Then draw the six steps of loading a page in order, and beside each write the one command you would run to check that step is working.

Any step where you cannot name the command is the part to practise before the next room.

61. Exit ticket: which room next?

Exit ticket

This decides what I prepare, so pick the one you would actually open tonight.

Predict first

Where does the next session go?

  • More networking — putting this to work in Wireshark and reading real packets
  • Nmap properly: scan types, service detection and reading the output
  • The Cryptography module, which comes next in the path
  • Back to the command line, because that still feels shaky
  • Straight into a full room, with me watching how you approach it

Correct: Whichever you pick is what I will prepare.

Why: The last option is worth taking seriously even though it looks like the least structured. Watching how you open an unfamiliar room shows me which of these ideas is actually missing far faster than any question I could write, and it is usually not the one a student expects.

62. What you can do now

Recap

Last session was about getting into files. This one was about the picture underneath every room from here on.

you needthe commandthe thing to look for
my addressip athe tun interface, proving the VPN is up
my way outip routethe default gateway
is it aliveping, then a port scanno reply does not mean down
what is runningnmap -sVversions, which decide the next step
name to addressdig or nslookupthe answer section, and who answered
my neighboursarp -athe cached MAC of the gateway

TryHackMe, Cyber Security 101 path — the Networking module the Networking module — every section above maps onto one of its rooms

Sources

  1. TryHackMe, Cyber Security 101 path — the Networking module
  2. RFC 1918, Address Allocation for Private Internets
  3. RFC 793, Transmission Control Protocol (the three-way handshake)
  4. RFC 1035, Domain Names — Implementation and Specification
  5. IANA Service Name and Transport Protocol Port Number Registry
  6. RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3

Want this taught 1-on-1? Alexander tutors Cyber Security 101 — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108