Network & security tools
Lesson 1 got your server online. This one hands you the tools admins and security people use every day: fetch web pages from the terminal, test whether a port is open, see which program is using the network, watch packets fly by, and work with the encryption behind HTTPS.
You will learn
curlandwget: talk to websites from the terminalnc,ssandlsof -i: is a port open, and who's using it?tcpdump: watch network traffic, and the ethics of doing itopensslandsha256sum: certificates, random secrets and checksumsiptablesandnft: the firewall under firewalld and ufw
Every tool here can also be used to snoop or attack, which is why security people learn them. The rule is simple: only point them at machines and networks you own, or have written permission to test. Scanning or capturing on your school's network “just to see” can get you suspended, and in many countries it's illegal. Practice here, in a home lab, or in legal hacking games (CTFs).
curl and wget: the web without a browser
curl http://example.com # print the page curl -I https://example.com # just the headers sudo dnf install wget # not on minimal installs wget http://example.com # download to a file
curl is always there. wget usually isn't.
curl http://example.com
curl -I https://example.com
wget http://example.com # already installed
Both are installed on Ubuntu Server.
Rule of thumb: curl shows things (and talks to web APIs), wget downloads files. Some handy extras: curl -O URL saves with the file's own name, curl -L follows redirects, and curl ifconfig.me tells you your public IP address.
curl https://some-site/install.sh | sudo bash runs a stranger's script as root without you reading it. Download it first (curl -O or wget), read it with less, and then decide (AI Basics, lesson 1).
Is that port open? nc, ss, lsof
Programs listen on numbered ports: SSH on 22, web on 80 and 443. When something “can't connect,” these tools tell you whether the problem is the program, the firewall or the network.
sudo dnf install nmap-ncat nc -zv 192.168.1.50 22 # -z just test, -v tell me ss -tlnp # what is listening here? sudo lsof -i :22 # which program owns port 22?
Rocky's nc is Ncat, from the Nmap project.
nc -zv 192.168.1.50 22 # preinstalled
ss -tlnp
sudo lsof -i :22
Ubuntu's nc is OpenBSD netcat. Same name, different program, with slightly different options and messages.
| You see… | It means… |
|---|---|
Connected / succeeded! | Something is listening and the firewall let you in. |
Connection refused | You reached the machine, but nothing is listening on that port. Is the service running? |
Nothing, then timed out | A firewall is silently dropping you, or the machine is unreachable. |
tcpdump: watch the traffic
tcpdump prints every packet going in or out of a network card. It's how you prove what's actually being sent.
sudo dnf install tcpdump sudo tcpdump -i enp0s3 -c 5 icmp # 5 ping packets, then stop sudo tcpdump -i enp0s3 port 80 # web traffic. Ctrl+C to stop
sudo tcpdump -i enp0s3 -c 5 icmp # preinstalled
sudo tcpdump -i enp0s3 port 80It always needs sudo, because reading the network card is powerful: on plain HTTP (not HTTPS) you'd see the page contents, even passwords. That's the whole reason the web moved to HTTPS, and it's why the ethics rule above matters.
openssl: encryption toolbox
openssl version # Rocky 9 and Ubuntu 24.04 both ship OpenSSL 3 openssl rand -base64 24 # a strong random password or secret openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 30 -subj "/CN=myserver" openssl x509 -in cert.pem -noout -subject -dates # who is it for, and when does it expire? openssl s_client -connect example.com:443 </dev/null # look at a real website's certificate
The long req command makes a self-signed certificate: the kind of certificate HTTPS uses, but one only you vouch for, so browsers show a warning. Real websites get free trusted certificates from Let's Encrypt. Expired certificates are one of the most common reasons websites break, so checking -dates is a real admin skill.
Checksums: did the file change?
sha256sum rocky.iso # a fingerprint of the file sha256sum -c SHA256SUMS # check files against a list of fingerprints
Change a single letter and the fingerprint is completely different. Download sites publish checksums so you can prove your download wasn't damaged or tampered with.
The firewall underneath: iptables and nft
In Linux Basics, lesson 14 you used firewall-cmd on Rocky and ufw on Ubuntu. Both are friendly front ends. Underneath, the Linux kernel's firewall is nftables, and its old interface iptables still shows up in countless tutorials.
sudo nft list ruleset # firewalld's real rules sudo dnf install iptables-nft sudo iptables -L -n # the old view (mostly empty!)
firewalld keeps its rules in its own nftables table, so iptables -L doesn't show them.
sudo iptables -L -n # ufw's rules show up here
sudo nft list ruleset
ufw writes iptables rules, which modern Ubuntu quietly stores in nftables.
Adding rules with iptables by hand while firewalld or ufw is running is a recipe for confusion. They don't know about each other, and one can wipe the other's rules on reload. On these systems, manage the firewall with firewall-cmd or ufw, and use nft and iptables to look.
Try it: network investigator 🛰️
Quick check
1. nc -zv server 80 says “Connection refused.” What does that tell you?
✓ “Refused” is an answer from the machine. Firewalls usually just drop you, which looks like a timeout.
2. A friend says “let's run tcpdump on the school Wi-Fi and see what people are doing.” Best response?
✓ Good security people get permission first. Always.
3. On Rocky, sudo iptables -L shows empty chains, but the firewall is definitely working. Why?
✓ Different tools, same kernel firewall underneath.
4. Your website suddenly shows a security warning in every browser. Which command helps you check the most common cause?
✓ Expired certificates break websites all the time, even at big companies.