You can run traceroute. Can you explain why it works?
Every networking tool is applied protocol semantics. It repurposes a field, or exploits a behavior the RFC either mandated or left undefined. Traceroute is the TTL field doing a second job. The nmap SYN, FIN, NULL, Xmas, and ACK scans are RFC 793's own mandated replies turned into a probe. The idle scan reads a stranger's IP ID counter. p0f fingerprints a host from the idiosyncrasies of its TCP options. The Kaminsky attack races sixteen bits of DNS entropy.
TCP/IP in Practice teaches the stack the way an engineer actually learns it: by understanding why each tool works, field by field, and then inverting every mechanism into a defense.
For each technique, the book shows the defensive inversion the protocol community actually shipped — SYN cookies, GTSM, RFC 6528 sequence numbers, source-port randomization, DNS 0x20 encoding, response-rate limiting, and uRPF — as one coherent family rather than a list of unrelated fixes.
Who it is for
Senior engineers and security practitioners who already use these tools and want to own the mechanism instead of memorizing the command. It assumes you know what an IP packet and a TCP handshake are. It does not assume you have ever opened Scapy.
Inside
Les informations fournies dans la section « Synopsis » peuvent faire référence à une autre édition de ce titre.
Vendeur : California Books, Miami, FL, Etats-Unis
Etat : New. Print on Demand. N° de réf. du vendeur I-9798170832286
Quantité disponible : Plus de 20 disponibles
Vendeur : PBShop.store UK, Fairford, GLOS, Royaume-Uni
PAP. Etat : New. New Book. Shipped from UK. Established seller since 2000. N° de réf. du vendeur L2-9798170832286
Quantité disponible : Plus de 20 disponibles