Networking & ports

beginnerFoundations

TL;DR

Nearly everything you test sits on TCP/IP. Hosts have IP addresses, services listen on numbered ports, and traffic moves over TCP (reliable) or UDP (fire-and-forget). Get comfortable with that and the rest makes sense.

What it is

Networking is how machines find and talk to each other. A host is reached by its IP address; a service on that host is reached at a port. “Open a connection to 10.0.0.5 on port 443” is the whole idea in one line.

How it works

Ports run 0–65535, and the well-known ones tell you what’s likely listening. TCP sets up a connection (the three-way handshake) and guarantees delivery; UDP just sends and hopes, which is why it’s used for fast, loss-tolerant things like DNS.

PortService
22SSH
80 / 443HTTP / HTTPS
53DNS
445SMB
3389RDP
389 / 636LDAP / LDAPS

Why it matters for testing

The first thing most tests do is map this: which hosts are up, which ports are open, and what’s listening. That’s what Nmap is for, and it’s the picture everything else builds on.

← Back to Foundations