You can run traceroute. Can you explain why it works?
Every networking tool is applied protocol semantics. It repurposes a field, or exploits a behavior the RFC either mandated or left undefined. Traceroute is the TTL field doing a second job. The nmap SYN, FIN, NULL, Xmas, and ACK scans are RFC 793's own mandated replies turned into a probe. The idle scan reads a stranger's IP ID counter. p0f fingerprints a host from the idiosyncrasies of its TCP options. The Kaminsky attack races sixteen bits of DNS entropy.
TCP/IP in Practice teaches the stack the way an engineer actually learns it: by understanding why each tool works, field by field, and then inverting every mechanism into a defense.
For each technique, the book shows the defensive inversion the protocol community actually shipped — SYN cookies, GTSM, RFC 6528 sequence numbers, source-port randomization, DNS 0x20 encoding, response-rate limiting, and uRPF — as one coherent family rather than a list of unrelated fixes.
Who it is for
Senior engineers and security practitioners who already use these tools and want to own the mechanism instead of memorizing the command. It assumes you know what an IP packet and a TCP handshake are. It does not assume you have ever opened Scapy.
Inside
"Sinopsis" puede pertenecer a otra edición de este libro.
Librería: California Books, Miami, FL, Estados Unidos de America
Condición: New. Print on Demand. Nº de ref. del artículo: I-9798170832286
Cantidad disponible: Más de 20 disponibles
Librería: PBShop.store UK, Fairford, GLOS, Reino Unido
PAP. Condición: New. New Book. Shipped from UK. Established seller since 2000. Nº de ref. del artículo: L2-9798170832286
Cantidad disponible: Más de 20 disponibles