Network Commands
The Network Toolbox
When something is wrong on a machine or a network, a handful of commands answer most questions: Is it reachable? What is it listening on? Who is it talking to? What does the web server say about itself? You will use these daily as a security analyst.
ping: Is It Reachable?
ping -c 4 google.com
ping sends ICMP echo requests and measures the reply time. It tells you the host is alive, the latency, and the packet loss. Many firewalls block ICMP, so no reply does not always mean down.
traceroute: Where Does the Traffic Go?
traceroute scanme.nmap.org
traceroute uses the TTL trick from the networking module. It sends packets with TTL 1, 2, 3, and so on, and each router that drops one reveals itself. You see every hop and its delay. A sudden jump (for example from 14 ms to 98 ms) shows where the traffic crosses an ocean, such as from Lagos to a European exchange. Unexpected hops can indicate a routing problem or a redirect.
ss and netstat: What Is Listening?
ss -tulnp # TCP + UDP, listening, numeric, with process
netstat -tulnp # older tool, similar output
Flags: t TCP, u UDP, l listening, n numbers not names, p show the process.
tcp LISTEN 0.0.0.0:22 sshd (expected)
tcp LISTEN 127.0.0.1:3306 mysqld (local only: good)
tcp LISTEN 0.0.0.0:4444 nc (why?)
Notice the address. 127.0.0.1 means only this machine can connect. 0.0.0.0 means every network interface, so anyone who can reach the server can connect. A database on 0.0.0.0 is a finding. Use ss -tunap to also see established connections and spot a strange outbound one.
curl and wget: Talk to Web Servers
curl http://target.lab # fetch the page
curl -I http://target.lab # headers only
wget http://target.lab/file.zip # download a file
curl -I is a security favourite. Read the headers:
Server: Apache/2.2.8 (Ubuntu) DAV/2 <- exact version leaks
X-Powered-By: PHP/5.2.4 <- exact version leaks
(missing) Strict-Transport-Security
(missing) X-Frame-Options
(missing) Content-Security-Policy
Old version numbers help an attacker pick an exploit, and missing headers are quick findings for a report. In Module 4 you will learn what these headers do.
Careful: never run
curl ... | bashon a script you have not read. Attackers use that pattern to install malware.
Putting It Together: A Quick Triage
Suppose a colleague says a server "feels suspicious". A sensible first five minutes:
ss -tulnp: what is listening, and is it expected?ps aux: any unexpected processes?pingandtraceroute: is the network path sane?curl -Ion your own web service: what does it reveal?- Compare everything against what should be there (a baseline).
Finding a difference between "expected" and "actual" is the core skill of both defenders and penetration testers.
A Nigerian and Global View
Whether you support a bank's internal apps in Lagos, a telecom in Accra or a SaaS startup in Berlin, these same commands work on every Linux server and cloud instance. Being fluent with them makes you faster in interviews, in incident response and in bug-bounty work.
Try It in the Lab: Network Reconnaissance
You are cleared to assess the staging server target.lab (192.168.56.101) on the lab network. Complete the mission in the simulated terminal on the right:
ifconfig(orip a): what is this machine's IP address and subnet?ping -c 3 target.lab: is the target up? How fast does it answer?traceroute scanme.nmap.org: count the hops. Which one looks like the Lagos internet exchange, and where does the latency jump?netstat -tulnp(orss -tulnp): which ports is your machine listening on, and which process owns each one? One of them should not be there.curl: fetchhttp://target.lab/robots.txtand follow it to the page the admins tried to hide.
Bonus: dig target.lab to see how the name resolves. Also run curl -I http://target.lab and list the headers that leak software versions.
Everything here is simulated and safe. Only run scans and fetches against systems you own or are allowed to test.
Try it yourself
Key Takeaways
- ping tests reachability and latency, but many firewalls block ICMP, so no reply does not always mean the host is down.
- traceroute uses increasing TTL values to reveal each hop, which helps you find where delay or odd routing appears.
- ss -tulnp (or netstat) shows listening ports and their processes. 0.0.0.0 means exposed on all interfaces and 127.0.0.1 means local only.
- curl -I reveals server and framework versions and missing security headers such as HSTS, X-Frame-Options and CSP.
- Compare what is running and listening with what should be there. Never pipe curl into bash without reading the script.
Quick Quiz
1.What does an address of 0.0.0.0:3306 in ss -tulnp output tell you about a MySQL server?
2.Which command shows only the HTTP response headers of a website?
3.How does traceroute discover each router on the path to a host?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx