Network Analysis
ip
Bring interface up
sudo ip link set eth0 upDisplay the Routing Table
ip route showAdd a route
sudo ip route add 192.168.2.0/24 via 192.168.1.254Delete a Route
sudo ip route del 192.168.2.0/24Add a Default Gateway
sudo ip route add default via 192.168.1.1Use lft to trace hops in the network
sudo lft <IP:PORT>If you suspect that there is a
VMordockerbeing hosted in a different port you can uselftand check if there are differences in the results.
Find the processes associated with a port
lsof -i -n -P <port_number>Shows TCP open connections in the Listen state
lsof -wnP -iTCP -sTCP:LISTENListening ports & services
ss -tulnListening ports + PID
ss -tulnp | grep PIDTTL Values and OS Fingerprinting
The TTL value in the ping response is a starting value decremented by one for each hop the packet takes; Values differ between operating systems:
Linux/Unix->64Windows->128Cisco->255
ping -c 4 example.comIt sends
ICMP Echo Requestpackets to a target and waits forICMP Echo Replypackets in return.
Output Example
PING 192.168.1.1 (192.168.1.1) 56(84) bytes of data.
64 bytes from 192.168.1.1: icmp_seq=1 ttl=64 time=0.123 ms
64 bytes from 192.168.1.1: icmp_seq=2 ttl=64 time=0.120 ms
64 bytes from 192.168.1.1: icmp_seq=3 ttl=64 time=0.122 msTTL(Time to Live): The maximum number of hops a packet can traverse before being discarded.Time: The round-trip time (RTT) for the packet to reach the destination and return.
Last updated