Networking & ports
TL;DR
Nearly everything you test sits on TCP/IP. Hosts have IP addresses, services listen on numbered ports, and traffic moves over TCP (reliable) or UDP (fire-and-forget). Get comfortable with that and the rest makes sense.
What it is
Networking is how machines find and talk to each other. A host is reached by its IP address; a service on that host is reached at a port. “Open a connection to 10.0.0.5 on port 443” is the whole idea in one line.
How it works
Ports run 0–65535, and the well-known ones tell you what’s likely listening. TCP sets up a connection (the three-way handshake) and guarantees delivery; UDP just sends and hopes, which is why it’s used for fast, loss-tolerant things like DNS.
| Port | Service |
|---|---|
| 22 | SSH |
| 80 / 443 | HTTP / HTTPS |
| 53 | DNS |
| 445 | SMB |
| 3389 | RDP |
| 389 / 636 | LDAP / LDAPS |
Why it matters for testing
The first thing most tests do is map this: which hosts are up, which ports are open, and what’s listening. That’s what Nmap is for, and it’s the picture everything else builds on.