Task 8 →NULL, FIN, Xmas


Firewall Evasion

Microsoft Windows

Task 9 → ICMP Network Scanning

nmap -sn

Task 10 → Working With The NSE



Task 11 → Overview

in this DOC you can see it take arg call maxlist


Task 12 → Searching for script

If you run the above command you will get a list like this and highlighted one is the OS discovery.


This is how you can see the scorce code of smb-os-discovery.nse
first you need to type locate smb-os-discovery.nse and copy that location and use cat <file_location> the you will be able to get this

So answer is smb-brute

Task 13 →Firewall Evasion


— data-length

To find this you can type man nmap and go to Firewall evasion tab and you can see this to your self.

Task 14 → Practical


you can see 999 are open and filtered

no response

If you run this above command you will be able see there are 5 ports are open


this is how you have to use scripts in Nmap so in the result you can see anonymous login is allowed now lets try to login

This is how you have to log in to the FTP session

