Linux Sysadmin · Lesson 2 · 25 min

Network & security tools

Lesson 1 got your server online. This one hands you the tools admins and security people use every day: fetch web pages from the terminal, test whether a port is open, see which program is using the network, watch packets fly by, and work with the encryption behind HTTPS.

You will learn

  • curl and wget: talk to websites from the terminal
  • nc, ss and lsof -i: is a port open, and who's using it?
  • tcpdump: watch network traffic, and the ethics of doing it
  • openssl and sha256sum: certificates, random secrets and checksums
  • iptables and nft: the firewall under firewalld and ufw
Hacking tools, used the right way

Every tool here can also be used to snoop or attack, which is why security people learn them. The rule is simple: only point them at machines and networks you own, or have written permission to test. Scanning or capturing on your school's network “just to see” can get you suspended, and in many countries it's illegal. Practice here, in a home lab, or in legal hacking games (CTFs).

curl and wget: the web without a browser

Rocky / RHEL
curl http://example.com       # print the page
curl -I https://example.com   # just the headers
sudo dnf install wget         # not on minimal installs
wget http://example.com       # download to a file

curl is always there. wget usually isn't.

Ubuntu / Debian
curl http://example.com
curl -I https://example.com
wget http://example.com       # already installed

Both are installed on Ubuntu Server.

Rule of thumb: curl shows things (and talks to web APIs), wget downloads files. Some handy extras: curl -O URL saves with the file's own name, curl -L follows redirects, and curl ifconfig.me tells you your public IP address.

Remember the red flag

curl https://some-site/install.sh | sudo bash runs a stranger's script as root without you reading it. Download it first (curl -O or wget), read it with less, and then decide (AI Basics, lesson 1).

Is that port open? nc, ss, lsof

Programs listen on numbered ports: SSH on 22, web on 80 and 443. When something “can't connect,” these tools tell you whether the problem is the program, the firewall or the network.

Rocky / RHEL
sudo dnf install nmap-ncat
nc -zv 192.168.1.50 22       # -z just test, -v tell me
ss -tlnp                     # what is listening here?
sudo lsof -i :22             # which program owns port 22?

Rocky's nc is Ncat, from the Nmap project.

Ubuntu / Debian
nc -zv 192.168.1.50 22       # preinstalled
ss -tlnp
sudo lsof -i :22

Ubuntu's nc is OpenBSD netcat. Same name, different program, with slightly different options and messages.

You see…It means…
Connected / succeeded!Something is listening and the firewall let you in.
Connection refusedYou reached the machine, but nothing is listening on that port. Is the service running?
Nothing, then timed outA firewall is silently dropping you, or the machine is unreachable.

tcpdump: watch the traffic

tcpdump prints every packet going in or out of a network card. It's how you prove what's actually being sent.

Rocky / RHEL
sudo dnf install tcpdump
sudo tcpdump -i enp0s3 -c 5 icmp      # 5 ping packets, then stop
sudo tcpdump -i enp0s3 port 80        # web traffic. Ctrl+C to stop
Ubuntu / Debian
sudo tcpdump -i enp0s3 -c 5 icmp      # preinstalled
sudo tcpdump -i enp0s3 port 80

It always needs sudo, because reading the network card is powerful: on plain HTTP (not HTTPS) you'd see the page contents, even passwords. That's the whole reason the web moved to HTTPS, and it's why the ethics rule above matters.

openssl: encryption toolbox

Same on both
openssl version                        # Rocky 9 and Ubuntu 24.04 both ship OpenSSL 3
openssl rand -base64 24                # a strong random password or secret
openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 30 -subj "/CN=myserver"
openssl x509 -in cert.pem -noout -subject -dates   # who is it for, and when does it expire?
openssl s_client -connect example.com:443 </dev/null   # look at a real website's certificate

The long req command makes a self-signed certificate: the kind of certificate HTTPS uses, but one only you vouch for, so browsers show a warning. Real websites get free trusted certificates from Let's Encrypt. Expired certificates are one of the most common reasons websites break, so checking -dates is a real admin skill.

Checksums: did the file change?

Same on both
sha256sum rocky.iso          # a fingerprint of the file
sha256sum -c SHA256SUMS      # check files against a list of fingerprints

Change a single letter and the fingerprint is completely different. Download sites publish checksums so you can prove your download wasn't damaged or tampered with.

The firewall underneath: iptables and nft

In Linux Basics, lesson 14 you used firewall-cmd on Rocky and ufw on Ubuntu. Both are friendly front ends. Underneath, the Linux kernel's firewall is nftables, and its old interface iptables still shows up in countless tutorials.

Rocky / RHEL
sudo nft list ruleset        # firewalld's real rules
sudo dnf install iptables-nft
sudo iptables -L -n          # the old view (mostly empty!)

firewalld keeps its rules in its own nftables table, so iptables -L doesn't show them.

Ubuntu / Debian
sudo iptables -L -n          # ufw's rules show up here
sudo nft list ruleset

ufw writes iptables rules, which modern Ubuntu quietly stores in nftables.

Pick one tool and stick with it

Adding rules with iptables by hand while firewalld or ufw is running is a recipe for confusion. They don't know about each other, and one can wipe the other's rules on reload. On these systems, manage the firewall with firewall-cmd or ufw, and use nft and iptables to look.

Try it: network investigator 🛰️

Quick check

1. nc -zv server 80 says “Connection refused.” What does that tell you?

2. A friend says “let's run tcpdump on the school Wi-Fi and see what people are doing.” Best response?

3. On Rocky, sudo iptables -L shows empty chains, but the firewall is definitely working. Why?

4. Your website suddenly shows a security warning in every browser. Which command helps you check the most common cause?

Finished the missions and the quiz? Mark it done to track your progress.