Networking Deeper: Services, Protocols, and the Attack Surface
CAP, ACID vs BASE, latency numbers, back-of-envelope estimation, single points of failure — the vocabulary every system designer thinks in.
Core Philosophy: A computer connected to a network is not one target — it is a collection of doors, each one a service listening on a port. Both attacking and defending begin with the same question: “What doors exist, and which are open?” The sum of all those doors is called the attack surface. Security, in large part, is the discipline of knowing your attack surface and keeping it as small as possible.
Part 1: The Problem
In section 0.1 you learned that a port identifies a program on a machine. Now we make that operational. Before anyone can attack a system — and before anyone can defend it — they need a map: which services are running, on which ports, speaking which protocols, exposed to whom.
A defender who doesn’t know their own attack surface cannot protect it. An attacker who maps it well is halfway to a breach. This section is about seeing the surface.
Part 2: The Concept — Services Listen on Ports
A service is a program that sits running, waiting for network connections on a particular port. It “listens.”
ONE SERVER
┌─────────────────────────┐
│ Web service → port 80, 443
│ SSH service → port 22
│ Database → port 3306
│ Mail service → port 25
└─────────────────────────┘
Each is a separate "door."
Each listening service is an independent way in. If the web service is flawless but the database is exposed with a default password, the attacker simply uses the database door. A system is only as secure as its weakest service.
Part 3: Common Services You’ll Meet Constantly
| Port | Service | What it is | Why an attacker cares |
|---|---|---|---|
| 22 | SSH | Encrypted remote login | Full control of the box if cracked |
| 80 / 443 | HTTP / HTTPS | Web servers | The huge web-app attack surface |
| 21 | FTP | Old file transfer | Often allows anonymous access |
| 25 / 587 | SMTP | Sending mail | Spam relay, info leaks |
| 53 | DNS | Name resolution | Spoofing, info gathering |
| 3306 | MySQL | Database | Direct access to all the data |
| 3389 | RDP | Windows remote desktop | Full graphical control of a Windows box |
| 445 | SMB | Windows file sharing | Historically a major breach vector |
You don’t memorize this table — you’ll absorb it through use. Keep it on your Tools & Reference Cheatsheet page.
Part 4: Client–Server, and Why “Listening” Matters
Every network interaction has two roles:
- A server listens on a port, waiting.
- A client initiates a connection to that port.
Your browser is a client. A web server listens. Your SSH program is a client; an SSH service listens.
The security-relevant insight: only listening services can be attacked over the network. A program that isn’t listening on any port presents no network door. This leads straight to a core defensive move — turn off and remove services you don’t need. Every service you shut down is a door that no longer exists. (You’ll do exactly this in Phase 4’s hardening pages.)
Part 5: Firewalls, NAT, and VPNs — The Gatekeepers
Three pieces of technology sit between services and the open internet. Know what each does.
Firewall — the bouncer. A firewall is a set of rules deciding which connections are allowed. “Allow incoming on 443, block everything else incoming.” It doesn’t fix a vulnerable service; it controls who can reach the door at all.
Internet ──► ┌──────────┐ ──► Services
│ FIREWALL │
│ rules │ blocks anything
└──────────┘ not explicitly allowed
NAT — the shared mailbox.Network Address Translation lets many devices on a home or office network share one public IP address. A side effect: devices behind NAT aren’t directly reachable from the internet by default — a small, accidental layer of protection. It’s why your laptop at home isn’t directly exposed, but a cloud server is.
VPN — the private tunnel. A Virtual Private Network creates an encrypted tunnel between you and another network, so you appear to be “inside” it. Security uses VPNs two ways: defensively (employees safely reach internal systems) and, in this curriculum, to legally connect into hacking-practice lab networks — many training platforms require a VPN connection to reach their deliberately vulnerable machines.
Part 6: Attack Surface — The Idea That Ties It Together
Your attack surface is the total set of points where an attacker could try to get in:
- Every open port and listening service.
- Every web page, form, input field, and API endpoint.
- Every user account.
- Every piece of software, each with its own possible flaws.
Two principles flow from this, and they run through the entire curriculum:
- Attackers enumerate the attack surface. “Reconnaissance” (Phase 2.1) and “scanning” (Phase 3.1) are exactly this — mapping every door before trying any.
- Defenders minimize the attack surface. “Attack surface reduction” — closing unused ports, removing unused software, disabling unused accounts — is one of the highest-value defensive activities. Fewer doors, fewer ways in. This is the heart of Phase 4’s hardening.
BIG attack surface SMALL attack surface
(many doors open) (only what's needed)
┌─┬─┬─┬─┬─┬─┬─┐ ┌─┬───────────┬─┐
│D│D│D│D│D│D│D│ │D│ │D│
└─┴─┴─┴─┴─┴─┴─┘ └─┴───────────┴─┘
easy to attack hard to attack
📓 Key Terms
| Term | Plain meaning |
|---|---|
| Service | A program listening on a port for network connections. |
| Listening | A service actively waiting for connections on a port. |
| Client / Server | The side that initiates / the side that listens. |
| Firewall | Rules controlling which network connections are allowed. |
| NAT | Lets many devices share one public IP; incidentally hides them. |
| VPN | An encrypted tunnel making you appear inside another network. |
| Attack surface | The total set of points an attacker could try to exploit. |
| Attack surface reduction | Closing/removing unneeded services, accounts, software. |
🧪 Hands-On Lab
⚠️ Legal note: In this lab you scan only your own machine (localhost/127.0.0.1). Scanning machines you don’t own can be illegal even if you cause no harm. Section 1.0 covers the rules in full; the habit starts here.
Task 1 — Install Nmap. Nmap is the standard port-scanning tool. Install it (sudo apt install nmap on Ubuntu, or download from nmap.org).
Task 2 — Scan your own machine.
nmap localhost
Nmap reports which ports are open on your own computer and guesses the service behind each. This is your machine’s attack surface, made visible.
Task 3 — A more detailed scan.
nmap -sV localhost
The -sV flag asks Nmap to identify each service’s version. Versions matter enormously later — a specific version often maps to specific known vulnerabilities.
Task 4 — Reflect on each open door. For every open port, ask: “Do I know what this is? Do I actually need it running?” That single question, asked about a real server, is attack-surface reduction.
Task 5 — Inspect your firewall.
- Linux:
sudo ufw status - Windows: open “Windows Defender Firewall”
See which rules currently exist. Don’t change anything yet — just observe what’s already guarding your doors.
⚠️ Common Mistakes
- Scanning machines you don’t own. Even a “harmless” scan of someone else’s system can be an offense. Only
localhostand machines you own or are explicitly authorized to test. - Assuming a closed port is safe forever. Software updates, new installs, and config changes open ports over time. Attack surface is not static — it must be re-checked.
- Thinking a firewall fixes a vulnerable service. A firewall controls reachability, not soundness. A reachable, vulnerable service behind an “allow” rule is still vulnerable.
- Ignoring the boring services. People obsess over the web service and forget the exposed database or old FTP server. Attackers go for the forgotten door.
✅ Recap & What’s Next
- A networked machine is a set of services listening on ports — each one a separate door.
- Firewalls, NAT, and VPNs control who can reach those doors; they don’t make the doors themselves sound.
- Attack surface is the sum of all doors; attackers map it, defenders shrink it — a theme for the whole curriculum.
Next (0.5): You can’t practice attacks on the real internet — that’s illegal. So we build your own private, legal, isolated lab: an attacker machine and a victim machine, safely sealed off from everything else.
⁂ Back to all modules