NMAP scanning will be good for teaching about ports/services, Network Packets, TCP flags, etc.
ARP poisoning, like I said, can teach about ARP, switched networks, packet sniffing, etc
DoS (SYN flood) could teach about the TCP connection queue and SYN cookies
IP Spoofing can teach about the three way handshake (ACK #'s, SYN #'s) and exploiting trust relationships.
This is a solid start and all of these things can be tested in a lab. NMAP scan a test box, ARP poison two communicating machines and sniff, SYN flood some test box ON THE LOCAL NETWORK, IP spoof some box running one of the r* services, etc.




Reply With Quote