The module that follows the command line in the Cyber Security 101 path, built for a beginner who can run commands but has no picture behind them. It covers the two-address system and why both are needed, the private ranges, reading slash notation and turning a prefix into a usable host count, the four-layer model, DHCP, ARP and NAT, ports with TCP against UDP and the three-way handshake, the difference between closed and filtered, DNS lookups and the records worth enumerating, what the TLS padlock does and does not prove, and the eight commands that open almost every networking room.
Subject: Cyber Security 101 · 62 slides · code lesson
Open the interactive version of this deck · Homework for this lesson
Title
Cyber Security 101, session 2
The module after the command line, and the one that unlocks every later room
Objectives
Last session was about getting into files. This one is about the module that follows it, and it is the point where the rooms stop telling you which command to run and start assuming you already know what an address, a port and a handshake are. Everything after this in the path — scanning, exploitation, defensive security — is built on it.
TryHackMe, Cyber Security 101 path — the Networking module the Networking module
Section
Orientation
Concept
You said the hard part was not understanding a command but doing the specific thing being asked. The networking rooms sharpen that, because they ask for things that only make sense if you have a picture in your head.
So the goal today is not commands. It is the picture, with the commands hung off it — because once the picture is there, the commands are obvious and you can work out ones I never show you.
TryHackMe, Cyber Security 101 path — the Networking module the Networking module
Prediction
Answer from first principles rather than from anything you have read.
Predict first
When you load a web page, what travels across the network?
Correct: Many small packets, each independently addressed
Why: Everything is chopped into packets, each carrying its own addressing, each routed independently, and they can arrive out of order or not at all. Almost every idea in this module exists because of that one fact: addressing, ports, ordering, retransmission and the handshake are all consequences of packets being independent.
Section
MAC and IP
Concept
Every machine has at least two addresses and beginners routinely assume one is just an older version of the other. They do different jobs and both are needed on every single packet.
MAC address — a 48-bit identifier fixed to the network card, written as six pairs of hex digits, used only inside your local network
IP address — a 32-bit address in IPv4, written as four numbers, assigned by the network and used to route across the world
TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts
Picture it
The analogy that makes the pair stop feeling redundant.
Figure (svg): Two panels comparing a MAC address burned into the network card with an IP address handed out by the network, framed as a name on a door and a postal address
A letter needs the postal address to cross the country and the name on the door to reach you once it arrives. Strip either one and the delivery fails, which is exactly why packets carry both.
Socratic
Think about what would have to be true for it to be useful further away.
Discussion prompt
Why is the MAC address useless for routing a packet across the internet?
Hint: Could a router anywhere in the world guess which way to send a MAC address?
Answer:
Because MAC addresses have no structure. They are assigned by manufacturers, so two machines on opposite sides of the world can have addresses that look adjacent and are unrelated.
IP addresses are handed out in blocks by location and network, so a router can look at the front of an address and know roughly which direction to send it without knowing the destination.
That is the whole reason for the split: MAC is a flat namespace and works only where everyone can shout to everyone; IP is a structured namespace and works at scale.
Concept
Three ranges are reserved for use inside private networks and are never routed on the public internet. You will see them constantly, and recognising them at a glance is genuinely useful in a room.
| range | slash notation | where you meet it |
|---|---|---|
| 10.0.0.0 to 10.255.255.255 | 10.0.0.0/8 | large corporate networks, many lab VPNs |
| 172.16.0.0 to 172.31.255.255 | 172.16.0.0/12 | Docker's default, and mid-size networks |
| 192.168.0.0 to 192.168.255.255 | 192.168.0.0/16 | home routers, nearly every home lab |
| 127.0.0.0 to 127.255.255.255 | 127.0.0.0/8 | loopback — this machine, always |
If a room gives you a target on one of these ranges, it is telling you the machine is on the same network you were placed in, not somewhere on the public internet.
RFC 1918, Address Allocation for Private Internets the reserved ranges
Definition probe
Recognising the range on sight saves you a lookup every time.
Sort into buckets
Public, private, or neither?
Section
Reading slash notation
Concept
This is the piece of arithmetic that beginners skip and then hit repeatedly. It is genuinely simple once stated properly.
An IPv4 address is 32 bits. The number after the slash says how many of those bits identify the network. Whatever is left over identifies the machine.
\[ \text{host bits} = 32 - \text{prefix}, \qquad \text{addresses} = 2^{\,\text{host bits}} \]
Two of those addresses are always spoken for: the first names the network itself and the last is the broadcast address, so the usable count is two fewer than the total.
TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts, subnetting
Picture it
The same starting address, cut two different ways.
Figure (svg): A wide bar representing a slash twenty-four block of 256 addresses above four narrower bars representing slash twenty-six blocks of 64 addresses each
A bigger prefix means fewer host bits, which means smaller blocks and more of them. That is the whole relationship, and it runs backwards from how people expect, which is why it is worth drawing once.
Pattern
You do not need to convert to binary in a room. You need this table, and after a week you will not need the table either.
| prefix | host bits | addresses | usable | subnet mask |
|---|---|---|---|---|
| /24 | 8 | 256 | 254 | 255.255.255.0 |
| /25 | 7 | 128 | 126 | 255.255.255.128 |
| /26 | 6 | 64 | 62 | 255.255.255.192 |
| /27 | 5 | 32 | 30 | 255.255.255.224 |
| /28 | 4 | 16 | 14 | 255.255.255.240 |
| /30 | 2 | 4 | 2 | 255.255.255.252 |
Read it as halving: every step up the prefix halves the block. Learn /24 and the doubling does the rest.
TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts
Worked example
The exact question a room will ask, done the way you should do it under time pressure.
Given the address 192.168.1.100 with a /26 prefix, find the network address, the broadcast address, and the usable range.
Figure (svg): A slash twenty-four bar above four slash twenty-six blocks, with the block containing address one hundred highlighted
Find the block size
Why: A /26 leaves six host bits, and two to the sixth is 64. So the blocks are 64 addresses wide.
Count blocks up to the address
Why: Blocks start at 0, 64, 128 and 192. The value 100 falls between 64 and 127.
Name the boundaries
Why: The first address in that block is the network address; the last is the broadcast.
| role | address | why |
|---|---|---|
| network | 192.168.1.64 | first address in the block, names the network |
| first usable | 192.168.1.65 | the one after the network address |
| last usable | 192.168.1.126 | the one before the broadcast |
| broadcast | 192.168.1.127 | last address in the block, reaches everyone |
Verify: the arithmetic
Why: From 65 to 126 inclusive is 62 addresses, which matches the 62 usable the table predicts for a /26. If your count comes out at 64 you included the network and broadcast; if 63, you included one of them.
TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts, subnetting
Check
Solve it on paper before you click.
Check your understanding
A room places you on 10.10.10.0/28. How many usable addresses does that network hold?
Answer: B
Why: A /28 leaves four host bits, so the block holds two to the fourth, which is 16 addresses. Subtracting the network address and the broadcast address leaves 14 for actual machines.
Fill the middle
State it once in your own symbols and it stops needing the table.
Fill in the blanks
A /27 leaves 5 host bits, so the block holds 32 addresses and 30 are usable.
Why: Thirty-two total bits minus a prefix of 27 leaves five host bits. Two to the fifth is 32 addresses in the block, and removing the network and broadcast addresses leaves 30 that can be given to machines.
Section
The practical version
Concept
You will meet the seven-layer OSI model and it is worth recognising, but the four-layer model is what actually maps onto the packets you will look at, so learn this one first.
The point of layers is not classification for its own sake. It is that each layer can be changed without touching the others — swapping Wi-Fi for a cable changes the bottom layer and nothing above it notices.
TryHackMe, Cyber Security 101 path — the Networking module Networking Concepts, the models
Picture it
Read it top to bottom: that is the order things get wrapped as a packet leaves your machine.
Figure (svg): Four nested horizontal bars labelled Application, Transport, Internet and Link, each wider than the one above, with example protocols beside each
When a room asks which layer something operates at, ask instead which question it answers. Which application? Which conversation? Which machine? Which cable?
Matching
You do not memorise this. You reason it out from what each layer is responsible for.
Match the pairs
Why: HTTP and DNS both carry meaning that an application interprets, so both sit at the top. TCP is about the conversation rather than its content. IP is about reaching a machine. Ethernet is about the physical hop. Two protocols sharing a layer is normal — the layer is a job, not a slot.
Section
DHCP, ARP and NAT
Concept
You plug in and it works, and it is worth knowing what happened, because when it does not work these are the four steps to check.
That last point matters more than it looks. DHCP does not just give you an address; it tells you which machine is your way out and which machine answers name lookups. Almost everything you do afterwards depends on those two.
TryHackMe, Cyber Security 101 path — the Networking module Networking Essentials
Picture it
You know the neighbour's IP. The packet cannot leave without their MAC. This is how the gap gets closed.
Figure (svg): One machine broadcasting a request to three others on the local network, with the matching machine replying
The reply is cached, which is why the first packet to a neighbour is slightly slower than the rest. It is also why ARP cache poisoning is a classic local-network attack — nothing in the protocol checks whether the answer is honest.
Picture it
The reason a private address can still browse the internet.
Figure (svg): Three private addresses feeding into a router which rewrites the source address to a single public address
The router keeps a table of which internal machine each conversation belongs to, so the replies get back to the right one. This is also why a machine behind NAT cannot simply be connected to from outside — there is no entry in the table until it starts the conversation.
Socratic
This explains a thing that puzzles almost everyone in their first few labs.
Discussion prompt
When a lab gives you a VPN and a 10.x address, why can the target machine reach you when the wider internet cannot?
Hint: What address does the target see when you connect, and can it route back to it?
Answer:
Because the VPN puts you inside the same private network as the target. From the target's point of view you are a neighbour on 10.x, not a stranger on the internet.
That matters for anything that asks the target to connect back to you — a reverse shell, a file transfer you host. It only works because you are inside, and your public address is irrelevant.
If you try the same thing from your home machine without the VPN, the callback has nowhere to land, because NAT has no entry for a conversation your machine did not start.
Section
TCP against UDP
Concept
The IP address gets a packet to the machine. The port says which program on that machine should receive it. Without ports, a machine could run exactly one network service.
port — a 16-bit number identifying one service on a machine, so a single address can host many services at once
Numbers up to 1023 are the well-known ports and are conventionally reserved for standard services. The convention is not enforced by anything — a web server can listen on 8080 or 31337, and in a CTF room it frequently does.
IANA Service Name and Transport Protocol Port Number Registry the port registry
Picture it
The picture that makes port scanning make sense before you ever run a scanner.
Figure (svg): A building labelled with one IP address containing five numbered doors for SSH, DNS, HTTP, HTTPS and RDP
A port scan is knocking on every door in turn and writing down which ones answer. That is genuinely all it is, and the three answers you can get are the next thing worth knowing.
Concept
Roughly a dozen numbers cover most of what you meet. Seeing one in a scan should immediately suggest what to try next.
| port | service | what it suggests |
|---|---|---|
| 21 | FTP | file transfer, often with anonymous login left on |
| 22 | SSH | remote shell, the usual way in if you find credentials |
| 23 | Telnet | remote shell with no encryption at all, a finding in itself |
| 25 | SMTP | mail sending |
| 53 | DNS | name lookups, sometimes zone transfers |
| 80 | HTTP | a website, unencrypted — always look at it |
| 139 and 445 | SMB | Windows file shares, a very common route in |
| 443 | HTTPS | the same website, encrypted |
| 3389 | RDP | Windows remote desktop |
IANA Service Name and Transport Protocol Port Number Registry assigned numbers
Picture it
What TCP does before any data moves, and what UDP skips.
Figure (svg): A sequence diagram between a client and a server showing SYN, SYN-ACK and ACK packets
Because a scanner can start this and watch what comes back, the handshake is also how port scanning works. A SYN that gets SYN-ACK means open; a SYN that gets a reset means closed; a SYN that gets nothing at all means a firewall ate it.
Comparison
One promises delivery and pays for it; the other promises nothing and is fast.
Comparison matrix
| question | TCP | UDP |
|---|---|---|
| is there a handshake | yes, three packets before any data | no, it just sends |
| does it retransmit what is lost | yes | no, a lost packet is simply gone |
| does it keep the order | yes, it reassembles in sequence | no, packets can arrive shuffled |
| what uses it | the web, SSH, file transfer, email | DNS, video calls, most game traffic |
| why you would choose it | you cannot tolerate a missing byte | a late packet is worse than a lost one |
The choice is about what failure costs. Half a file is useless, so file transfer takes the overhead. Half a second of stale video is worse than a dropped frame, so calls do not.
Elimination
Your scan reports port 445 as filtered. Three of these conclusions are wrong.
Eliminate the wrong options
Which conclusion is actually supported?
Survives elimination: s2
Why: The three scan results mean three different things. Open means something answered and accepted. Closed means something answered and refused, which still proves the machine is alive and reachable. Filtered means nothing came back, so a firewall is between you and it and the state of the service is simply unknown. Treating filtered as closed is the most common misreading of a first scan.
Discrimination
Reason from what failure costs rather than from memory.
Sort into buckets
TCP or UDP?
Estimation
Worth calibrating, because it explains why default scans are not exhaustive.
Predict first
How many TCP ports exist on a single machine?
Correct: 65,535
Why: A port number is 16 bits, so there are 65,535 usable values. Scanners default to the roughly 1,000 most common precisely because checking all of them takes far longer — which is exactly why a room that hides a service on a high port is not caught by a default scan, and why the flag for all ports exists.
Edge cases
A thirty-two-bit address space sounds enormous. Push on whether it is.
Discussion prompt
IPv4 has about four billion addresses and there are more connected devices than that. Why does the internet still work?
Hint: What is every home router already doing to your address?
Answer:
Largely because of NAT. An entire home or office sits behind one public address, so hundreds of devices consume one address between them rather than one each.
That is a workaround rather than a fix, and it has a cost: a machine behind NAT cannot be connected to from outside unless something is deliberately configured, which is why callbacks in labs need you inside the network.
The actual fix is IPv6, with 128-bit addresses — enough that every device can have a globally routable one and NAT becomes unnecessary. Adoption has been slow precisely because NAT worked well enough for long enough.
Section
DNS and the rest
Concept
No human types an IP address, so before nearly every connection there is a lookup turning a name into an address. It is worth knowing the chain because it is a place things break and a place information leaks.
RFC 1035, Domain Names — Implementation and Specification the DNS specification
Picture it
Five steps, and each answer is cached so the next lookup skips most of them.
Figure (svg): A five-step flow from the client asking a resolver, through root and top-level servers, to the authoritative server returning an address record
Caching is why the first visit to a site is slower than the second, and why a DNS change takes time to take effect everywhere — old answers are still sitting in caches until they expire.
Concept
A room asking you to enumerate DNS is asking you to look for these. Most are unremarkable; two of them regularly leak useful information.
| record | what it holds | why you care |
|---|---|---|
| A | an IPv4 address for a name | the basic lookup |
| AAAA | an IPv6 address | same job, longer addresses |
| CNAME | an alias pointing at another name | reveals what a service is really hosted on |
| MX | the mail servers for a domain | names infrastructure you might not have found |
| TXT | arbitrary text | often holds verification strings, sometimes far more |
| NS | the authoritative name servers | the start of enumerating a domain |
RFC 1035, Domain Names — Implementation and Specification resource records
Worked example
Two commands you will use in almost every room that touches a domain.
# the quick one, on any system
nslookup tryhackme.com
# the detailed one, on Linux — ask for one record type at a time
dig tryhackme.com A +short
dig tryhackme.com MX +short
dig tryhackme.com TXT +shortFigure (svg): A terminal panel showing nslookup output with the answering server, the non-authoritative note and the resolved address highlighted separately
Read the output in three parts
Why: Which server answered you, which question was asked, and the answer section itself.
| what you see | what it means | what to do next |
|---|---|---|
| a Server line | which resolver answered | note it — in a lab it may be the target |
| Non-authoritative answer | this came from a cache, not the source | fine for an address, not for enumeration |
| an A record | the address the name resolves to | scan it |
| no answer at all | the name does not exist, or the resolver is blocked | try a different resolver before concluding |
Verify: against a name you know
Why: Run it on a name you are certain exists before trusting a negative result on one you are unsure about. A blocked resolver and a nonexistent name look almost identical, and telling them apart saves a lot of wasted effort.
RFC 1035, Domain Names — Implementation and Specification queries and responses
Error analysis
A beginner writes this conclusion into their notes after a scan.
Annotate
On: \( \text{port } 80 \text{ open} \;\Rightarrow\; \text{the site is insecure} \)
Precision in notes is a real skill in these rooms. Write down what you observed and what it permits you to conclude, and keep those two lines separate.
Section
What the padlock proves
Concept
TLS does two jobs at once and beginners routinely collapse them into one, which leads to a genuinely dangerous misunderstanding.
A phishing site can hold a perfectly valid certificate for its own name and serve you over a flawless encrypted connection. The padlock proves the connection is private and that the name matches the certificate. It proves nothing about whether the name is one you should trust.
RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3 TLS 1.3
Picture it
Five steps, and they happen after the TCP handshake and before the first byte of the page.
Figure (svg): Five sequential steps labelled ClientHello, ServerHello, Certificate, Key exchange and Finished, each with a plain-language description
Worth noticing that the certificate arrives in step three, before any of your data is sent. That ordering is the point: you verify who you are talking to before you say anything.
Two truths and a lie
Two of these are safe to say in a report. One is the sentence that gets people phished.
Eliminate the wrong options
Cross out the false statement.
Survives elimination: h3
Why: Certificates are free and automated, so anyone can get a valid one for a domain they control, including an attacker who registered a lookalike name an hour ago. The padlock is a statement about the connection, not about the organisation behind it. Reading it as a safety badge is precisely the assumption phishing relies on.
Comparison
Most of the older protocols have a direct modern equivalent, and finding the old one in a scan is itself a finding.
Comparison matrix
| old | port | modern replacement |
|---|---|---|
| Telnet, plaintext shell | 23 | SSH on 22 |
| FTP, plaintext transfer | 21 | SFTP or SCP, both over SSH on 22 |
| HTTP, plaintext web | 80 | HTTPS on 443 |
| SMTP without encryption | 25 | SMTP with STARTTLS, or on 587 |
In a room, spotting the left-hand column is often the whole point of the scan. Credentials sent over any of them can simply be read off the wire.
Section
What to run in a room
Concept
These appear again and again. Learn what each one answers rather than its flags, and you can look the flags up.
| question | Linux | Windows |
|---|---|---|
| what is my address | ip a | ipconfig |
| can I reach that machine | ping | ping |
| what is the path there | traceroute | tracert |
| what does this name resolve to | dig or nslookup | nslookup |
| what is listening on my machine | ss -tulpn | netstat -ano |
| who are my neighbours | arp -a | arp -a |
| what is open on the target | nmap | nmap |
| what is my way out | ip route | route print |
TryHackMe, Cyber Security 101 path — the Networking module Networking Essentials
Worked example
A repeatable opening sequence. Run these before you think about the task, because they tell you where you are.
ip a # my address and which interface the VPN gave me
ip route # my gateway - the way out of this network
ping -c 3 10.10.x.x # is the target actually up
nmap -sV -T4 10.10.x.x # which ports answer, and what is running on themRead each answer before running the next
Why: Each command narrows what the next one should be. Running all four blind wastes the information.
| command | what you are looking for | what it changes |
|---|---|---|
| ip a | the tun0 interface and its address | confirms the VPN is up at all |
| ip route | the default gateway | tells you the shape of the network you are in |
| ping | replies, and the time they take | up or down, before you waste a scan |
| nmap -sV | open ports and service versions | decides everything you do next |
Verify: that the first command worked before trusting the last
Why: If there is no tun interface, you are not on the lab network and every later result is meaningless. More than one wasted hour has been spent scanning from outside the VPN.
TryHackMe, Cyber Security 101 path — the Networking module Networking Essentials
Picture it
The cleverest small trick in networking, and it makes TTL make sense.
Figure (svg): Four hops with increasing TTL values, each router reporting a time-exceeded message back to the sender
Every packet carries a time-to-live that each router decrements. Send one with a TTL of one and the first router kills it and reports back. Send one with a TTL of two and the second does. Collect the reports and you have the path.
Trap
You ping the target and get nothing back.
Write it off as offline
Why: Move on, or spend twenty minutes trying to fix the VPN that is working perfectly.
Miss the machine entirely
Why: The box was up the whole time and the room is unfinishable until you come back to it.
You ping the target and get nothing back.
Remember what ping actually uses
Why: It sends an ICMP echo request, and plenty of hosts — Windows by default — simply do not answer those.
Ask a different question
Why: Scan a port instead. In nmap the flag that skips the ping check entirely is the one to reach for, and a machine that answers on 445 is very obviously up whatever it thinks of your ping.
Check
Solve it on paper before you click.
Check your understanding
You can reach the target by IP but a hostname the room gave you does not work. What is the first thing to check?
Answer: B
Why: Reaching it by IP proves the network path, the VPN and the host are all fine. The only thing the hostname adds is a lookup, so that is the step that failed. Many rooms expect you to add the name to your hosts file yourself, precisely so you meet this.
Section
Making it stick
Ranking
You type an address and press enter. Put what happens in order.
Put in order
Why: Nothing can happen before the name becomes an address. Then the routing decision comes before the addressing one — you only ARP for the gateway once you know the destination is elsewhere. TCP opens the pipe, TLS secures it, and only then does the actual request go. Six steps before one byte of your request leaves, and every one of them is a place a room can break on purpose.
Explain it to yourself
If you can say this cleanly, most of the module has landed.
Discussion prompt
In your own words, why does a packet need both a MAC address and an IP address?
Hint: Which of the two changes as the packet crosses each router?
Answer:
The IP address identifies the destination machine anywhere in the world, and it is structured so routers can forward toward it without knowing exactly where it is.
The MAC address identifies the next physical device on this particular cable or wireless link, and it changes at every hop.
So the IP stays the same the whole journey and the MAC is rewritten at each step. One is the destination, the other is the next move toward it.
Real world
Worth grounding, because these are the same skills your work network runs on.
Discussion prompt
Your home Wi-Fi says connected but nothing loads. Using only today's material, what do you check and in what order?
Hint: Work outwards: yourself, then your gateway, then the world, then names.
Answer:
Do you have an address at all? If it starts 169.254 then DHCP never answered and you have no usable address, which is a different problem from having no internet.
Can you reach the gateway? If not, the problem is between you and the router. If yes, the router is fine and the problem is further out.
Can you reach a public IP directly but not a name? Then everything works except DNS, which is the single most common cause of the site cannot be reached.
That is three checks that split the possibilities roughly in half each time, and it is exactly the sequence you would run against a lab target.
Warm-up
Close the deck. This is the check on whether today stuck.
Discussion prompt
From memory: the two addresses and their jobs; the three private ranges; the usable count in a /26; the three TCP handshake packets; what filtered means; what port 445 suggests; what the padlock proves; and what traceroute exploits.
Hint: Two addresses, three ranges, one count, three packets, one word, one service, one limit, one field.
Answer:
MAC for the local hop, IP for routing across the world.
Ten dot anything, 172.16 through 172.31, and 192.168 dot anything.
Sixty-two, because a /26 leaves six host bits giving 64 addresses, minus the network and broadcast.
SYN, SYN-ACK, ACK.
No answer came back, so a firewall is in the way and the service state is unknown — which is not the same as closed.
SMB, meaning Windows file sharing, and a very common way into a machine.
That the connection is encrypted and the name matches the certificate. Nothing about whether the site is trustworthy.
The time-to-live field, by sending packets designed to expire one hop further along each time.
Connect it up
Twenty minutes on this beats another hour of reading, and it is the artefact to bring next session.
Draw it
Draw your machine on the left and a web server on the right, with a router between them. Label your machine with both its addresses. Then draw the six steps of loading a page in order, and beside each write the one command you would run to check that step is working.
Any step where you cannot name the command is the part to practise before the next room.
Exit ticket
This decides what I prepare, so pick the one you would actually open tonight.
Predict first
Where does the next session go?
Correct: Whichever you pick is what I will prepare.
Why: The last option is worth taking seriously even though it looks like the least structured. Watching how you open an unfamiliar room shows me which of these ideas is actually missing far faster than any question I could write, and it is usually not the one a student expects.
Recap
Last session was about getting into files. This one was about the picture underneath every room from here on.
| you need | the command | the thing to look for |
|---|---|---|
| my address | ip a | the tun interface, proving the VPN is up |
| my way out | ip route | the default gateway |
| is it alive | ping, then a port scan | no reply does not mean down |
| what is running | nmap -sV | versions, which decide the next step |
| name to address | dig or nslookup | the answer section, and who answered |
| my neighbours | arp -a | the cached MAC of the gateway |
TryHackMe, Cyber Security 101 path — the Networking module the Networking module — every section above maps onto one of its rooms
Want this taught 1-on-1? Alexander tutors Cyber Security 101 — $55/session, free consultation.