Posts

Showing posts with the label Network Security

Proxies and Pivoting Explained: Traffic Redirection for PenTest+

Proxies sit between a client and a destination, relaying traffic on the client's behalf. They appear on Network+ as infrastructure, on Security+ as a control, and on PenTest+ as a technique — and the exams expect you to recognise which role is in play. Forward and reverse proxies The distinction that comes up most. Forward proxy. Sits in front of clients and acts on their behalf. The destination sees the proxy's address, not the client's. Used for content filtering, caching, monitoring outbound traffic and enforcing acceptable use. A corporate secure web gateway is a forward proxy. Reverse proxy. Sits in front of servers and acts on their behalf. The client sees the proxy, not the server. Used for load balancing, TLS termination, caching and hiding internal architecture. A WAF typically operates as a reverse proxy. A memory aid: a forward proxy hides the client, a reverse proxy hides the server. Proxy types HTTP proxy understands HTTP and can inspect, cache and fi...

VTP: Centralised VLAN Management and the Revision Number Trap

VLAN Trunking Protocol propagates VLAN definitions between switches so a VLAN created on one appears on all of them. It saves configuration effort and it carries a failure mode severe enough that many organizations disable it entirely. Understanding why is more valuable than understanding the protocol. What it does Switches in the same VTP domain exchange advertisements over trunk links. Create a VLAN on one switch and the definition propagates, so every switch in the domain learns it without being configured individually. The three modes define behaviour. Server switches can create, modify and delete VLANs and propagate those changes. Client switches accept changes and cannot make them locally. Transparent switches maintain their own VLAN database independently, ignoring advertisements for their own purposes while still forwarding them to others. Note what VTP does not do: it propagates VLAN definitions , not port assignments. Which ports belong to which VLAN is always config...

Packet Crafting Explained: Protocol Testing and Detection for CySA+

Packet crafting means constructing network packets field by field rather than letting the operating system build them. Tools such as Scapy make it programmable. It matters on the exams for two reasons: it is how several attacks and tests work, and understanding it explains what defenders should be watching for. Why craft packets at all A normal application hands data to the operating system, which fills in the headers according to the rules. Crafting bypasses that, letting you set any field to any value — including combinations the standards do not permit. That has legitimate uses. Firewall rule verification : send traffic with specific characteristics and observe what gets through, which tests the rule set rather than trusting the configuration. Protocol stack testing , to see how a device handles malformed input. Detection validation , generating traffic that should trigger an IDS rule to confirm the rule works. Network troubleshooting , such as sending packets of a specific size ...

802.1Q VLAN Tagging: Trunks, Native VLANs and VLAN Hopping

A VLAN divides one physical switch into several logical broadcast domains. 802.1Q is the standard that lets those domains span multiple switches, by inserting a four-byte tag into the Ethernet frame that says which VLAN it belongs to. Almost everything interesting about VLAN security comes from the details of that tag and from one unfortunate exception to it. The tag The 802.1Q tag sits between the source MAC address and the EtherType field. Four bytes: a two-byte tag protocol identifier marking the frame as tagged, then three bits of priority for quality of service, one drop-eligible bit, and twelve bits of VLAN identifier. Twelve bits gives 4096 values, with 0 and 4095 reserved, so 4094 usable VLANs. That ceiling is the reason large multi-tenant data centers moved to overlays — the 24-bit identifier in VXLAN exists precisely because 4094 segments is not enough for a cloud provider. Because four bytes are added, the maximum frame grows to 1522 bytes. Switches handle this tr...

Spanning Tree Priority and Root Bridge Election: Controlling the Topology

Spanning tree prevents loops by electing one switch as the root bridge and blocking any port that would create a second path to it. Which switch wins that election determines the shape of the entire forwarding topology — and left to defaults, it is decided by an arbitrary tiebreaker that has nothing to do with your network design. The bridge ID Every switch advertises a bridge ID made of two parts: a 16-bit bridge priority and the switch's MAC address . The lowest bridge ID wins the election, priority compared first and MAC address used only as a tiebreaker. The default priority is 32768 on essentially every switch. When every switch shares that default, the priority comparison is a tie and the election falls entirely to the MAC address — meaning the oldest switch in the network usually wins, because manufacturers assign addresses roughly in sequence. That is frequently a small access switch in a closet rather than a core switch, and the resulting topology routes traffi...

DNS Filtering: Blocking Threats at the Resolver, and Its Limits

DNS filtering intercepts name resolution and refuses to answer for domains you do not want reached. It is the cheapest broad control in security: one change at the resolver protects every device and every application at once, with no agent to deploy and no traffic to inspect. Its limits are equally important, and they are what the exam tends to probe. Why the resolution step is a good place to intervene Almost every connection begins with a name lookup. Blocking the answer means the connection is never attempted — no packet leaves for the malicious host, no payload is fetched, no command channel opens. Because it operates before the connection, it protects protocols an HTTP proxy never sees, covers devices that cannot run an agent, and costs almost nothing in latency. It is also protocol-agnostic: the same block applies whether the application was going to use HTTP, a custom protocol, or a bare socket. What gets blocked Known malicious domains from threat intelligence feed...

MAC Flooding: Turning a Switch Into a Hub, and How Port Security Stops It

A switch forwards a frame to one port instead of all of them because it has learned which MAC address lives where. That knowledge is held in a finite table, and MAC flooding fills the table with fabricated entries until the switch can no longer learn anything real — at which point it falls back to flooding, and every device on the segment sees traffic that was not for it. How the CAM table works When a frame arrives, the switch records its source MAC address against the ingress port. When a frame needs forwarding, it looks up the destination: a known address goes out one port, an unknown address is flooded out every port in the VLAN. That flooding behaviour is not a bug — it is how the switch discovers where a silent device is. Entries age out after a few minutes so the table tracks devices that move. The table is fixed in size, typically thousands to tens of thousands of entries depending on the hardware. An access switch at the low end of that range can be filled quic...

ARP Spoofing: How a Stateless Protocol Becomes a Machine-in-the-Middle

ARP resolves an IP address to a MAC address so a frame can be delivered on the local segment. It was designed for cooperative networks and includes no authentication whatsoever — a host accepts whatever answer arrives, and in many implementations accepts answers to questions it never asked. That is the entire vulnerability. How the protocol works, and where it fails A host needing to reach an IP address on its own subnet broadcasts an ARP request: who has this address? The owner replies with its MAC address, and the requester caches the mapping for a few minutes. Three properties make this exploitable. There is no way to verify that a reply came from the rightful owner. Many implementations accept gratuitous ARP — an unsolicited announcement — and update the cache from it. And a later reply simply overwrites an earlier one, so the attacker who speaks last wins. An attacker therefore sends continuous forged replies telling the victim that the gateway's IP address ...

LLDP and CDP: Neighbour Discovery, and What It Tells an Attacker

Link Layer Discovery Protocol lets a device tell its directly connected neighbours what it is. Switches, routers, phones and access points advertise their identity, capabilities and port details, and each builds a picture of what is on the other end of every cable. It is genuinely useful and it is an information disclosure waiting to happen on the wrong port. What gets advertised LLDP frames are sent periodically to a reserved multicast address and are not forwarded by switches, so they reach only the directly connected device. Each frame carries a set of typed fields. Mandatory: the chassis identifier, the port identifier, and a time-to-live after which the neighbour entry expires. Optional and commonly enabled: the system name, a system description including the software version, the port description, the device's capabilities and which are enabled, the management address, and the VLAN identifier. That optional set is the security problem. A device advertising its model, it...

Exposed Remote Access: Why SSH and RDP on the Internet Get Compromised

Internet-facing remote access services are one of the two leading initial access vectors in real incidents, alongside phishing. The reason is unglamorous: a management service reachable from anywhere is continuously attacked by automated tooling, and it only has to be wrong once. What actually happens to an exposed service Put an SSH or RDP service on a public address and authentication attempts begin within minutes — not because anyone targeted you, but because internet-wide scanning identifies every listening service continuously, and lists of responsive hosts are traded and reused. The discovery side of this is covered under internet-wide scanning . The attempts are automated and patient. Common usernames paired with common passwords, credentials from breach dumps, and default vendor account names, delivered slowly enough from enough distinct addresses that per-source rate limits never trigger. Success comes from a small number of predictable weaknesses: a default or uncha...

BPDU Guard, Root Guard and Loop Guard: Hardening Switch Access Ports

Spanning tree keeps a switched network loop-free by trusting the information switches exchange. The guard features exist because that trust extends to any device on any port, including a consumer switch a user plugged in and a laptop running attack tooling. Each guard defends a different assumption, and applying the right one to the right port type is what the exam tests. BPDU Guard An access port connects an end host. An end host has no business participating in spanning tree, so a bridge protocol data unit arriving on such a port means something other than a host is attached. BPDU Guard shuts the port down immediately — into err-disabled state — the moment any BPDU is received. Not a lower priority BPDU, not a superior one: any. It pairs with PortFast, which skips the listening and learning states so a host gets a working link in a second rather than thirty. PortFast alone is dangerous, because a port that forwards immediately will forward a loop immediately if someon...

Secure Web Gateway: Inline Web Filtering, TLS Inspection and SASE

A secure web gateway sits inline between users and the internet, inspecting outbound web traffic and enforcing policy on it. Every request passes through, is evaluated, and is allowed, blocked, or modified. The direction is the thing to fix in your head: an SWG protects users going out; a WAF protects applications coming in . Confusing the two is the single most common mistake on this topic. What it enforces URL and category filtering is the visible layer — blocking gambling, malware distribution, or newly registered domains by category rather than by maintaining a list by hand. Reputation scoring adds judgment about domains that have no category yet, which is where a lot of phishing infrastructure lives. Malware inspection scans downloads, often detonating unknown files in a sandbox before releasing them. Application control distinguishes between services at a finer grain than a domain: permitting a sanctioned file sharing tenant while blocking personal accounts on the same p...