n3cr0 secure shell v2.0.26
initializing encrypted connection...
loading cyber warfare modules...
red team: READY
blue team: READY
purple team: READY
HTB integration: ONLINE
access granted. welcome, operator.

Security Fundamentals

The building blocks. If you skip these, everything else falls apart. Read this page, understand it, then come back when you forget something.

The CIA Triad

Three properties that security protects:

Every security control maps back to at least one of these. Every attack violates at least one.

Beyond CIA

The triad is the minimum. More complete frameworks add:

Attack Types

Malware

Software designed to cause harm. Major categories:

Social Engineering

Attacking the human, not the machine:

Web Attacks

Network Attacks

Authentication and Authorization

Authentication Factors

Something you know, something you have, something you are:

Password Security

Authorization Models

Cryptography Basics

Symmetric Encryption

Same key for encryption and decryption. Fast. Good for bulk data.

Problem: key distribution. How do you share the key securely with the other party?

Asymmetric Encryption

Key pair: public key encrypts, private key decrypts. Solves key distribution.

Problem: slow. Used to exchange a symmetric key, then symmetric encryption does the bulk work.

Hashing

One-way function. You cannot reverse a hash to get the original input. Used for integrity verification and password storage.

Digital Signatures

Sign with private key, verify with public key. Proves the message came from you and was not tampered with. Used in TLS certificates, code signing, PGP email.

Networking Fundamentals

OSI Model

Layer Name Examples
7. Application User-facing protocols HTTP, DNS, SSH, FTP, SMTP
6. Presentation Data format, encryption TLS, JPEG, ASCII
5. Session Manage sessions Sockets, RPC
4. Transport Reliable delivery TCP, UDP
3. Network Routing between networks IP, ICMP
2. Data Link Frame delivery on local network Ethernet, ARP, MAC addresses
1. Physical Electrical signals Cables, radio, fiber

In practice, most security work happens at layers 3-7. You rarely deal with physical or data link layer attacks unless you are doing physical pentesting or WiFi hacking.

TCP vs UDP

Common Ports

Protocol Port Transport Use
HTTP 80 TCP Web traffic
HTTPS 443 TCP Encrypted web traffic
SSH 22 TCP Remote shell
FTP 21 TCP File transfer control
FTP-DATA 20 TCP File transfer data
SMB 445 TCP Windows file sharing
RDP 3389 TCP Windows remote desktop
DNS 53 UDP/TCP Name resolution
SMTP 25 TCP Email sending
SMTPS 465 TCP Encrypted email sending
POP3 110 TCP Email receiving
IMAP 143 TCP Email receiving
MySQL 3306 TCP MySQL database
PostgreSQL 5432 TCP PostgreSQL database
Redis 6379 TCP In-memory cache
WinRM 5985/5986 TCP Windows remote management
SNMP 161 UDP Network management
NTP 123 UDP Time synchronization
LDAP 389 TCP Directory services
LDAPS 636 TCP Encrypted directory services
Kerberos 88 TCP Windows authentication
NetBIOS 137-139 TCP/UDP Legacy Windows name resolution

Key Security Principles

Defense in Depth

Multiple layers of security. If one fails, the next catches it. Firewall + patching + MFA + logging + backups. No single control is perfect.

Least Privilege

Give users and systems the minimum access they need to do their job. Nothing more. A web server does not need root. A marketing intern does not need Domain Admin.

Zero Trust

"Never trust, always verify." Do not assume traffic inside the network is safe. Authenticate and authorize every request, regardless of source. The old "castle and moat" model assumed the perimeter was secure and everything inside was trusted. Zero trust rejects that assumption.

Separation of Duties

No single person should have enough authority to both initiate and approve a critical action. The person who writes the check should not be the person who signs it.

Fail Secure

When a system fails, it should fail in a secure state. Default deny, not default allow. If the firewall crashes, block all traffic, not allow all traffic.