Saturday, January 11, 2020
Net Sec
1. Name at least five applications and tools pre-loaded on the TargetWindows01 server desktop, and identify whether that application starts as a service on the system or must be run manually. WINDOWS APPLICATION LOADEDSTARTS AS SERVICE Y/N 1. tftpd32 Starts as a service 2. FileZilla Server Interface- The interface does not start as a service and must be ran manually 3. Wireshark ââ¬â Does not start as a service and must be ran manually 4. Nessus Server Manager ââ¬â Does not start as a service and must be ran manually 5. NetWitness Investigator ââ¬â Does not start as a service and must be ran manually 2.What was the allocated source IP host address for the TargetWindows01 server, TargetUbuntu01 server, and the IP default gateway router? TagetWindows01 Server- Source IP = 172. 30. 0. 8 TargetUbuntu01 Server ââ¬â Source IP = 172. 30. 0. 4 TargetUbuntu02 Server ââ¬â Source IP = 172. 30. 0. 9 The Default Gateway IP is = 172. 30. 0. 1 3. Did the targeted IP hosts respon d to the ICMP echo-request packet with an ICMP echo-reply packet when you initiated the ââ¬Å"pingâ⬠command at your DOS prompt? If yes, how many ICMP echo-request packets were sent back to the IP source? Yes, the targeted IP host responded back with 4 echo-replies. 4.If you ping the TargetWindows01 server and the UbuntuTarget01 server, which fields in the ICMP echo-request/echo-replies vary? The fields that vary is the Time To Live (TTL) fields. For the TargetUbuntu01 it's 64 and the TargetWindows01 is 128. 5. What is the command line syntax for running an ââ¬Å"Intense Scanâ⬠with Zenmap on a target subnet of 172. 30. 0. 0/24? The syntax for an Intense Scan in Zenmap is as followed: nmap -T4 -A -v -PE -PS22,25,80 -PA21,23,80,3389 172. 30. 0. 0/24 6. Name at least five different scans that may be performed from the Zenmap GUI. Document under what circumstances you would choose to run those particular scans.Intense Scan-Provides a very detailed information about ports an d protocols, Operating Systems, and Mac Addresses Internse Scan, all TCP ports ââ¬â Provide intense scan on all tcp ports 1-65535. Ping Scan-Provide basic information about availability and MAC addresses Quick Scan- Provides a fast scan limiting the number of TCP ports scanned only the top 100 most common TCP ports Regular Scan-This is the default scan by issuing TCP SYN scans for the most common 1000 TCP ports using pings for host detection. 7. How many different tests (i. e. , scripts) did your ââ¬Å"Intense Scanâ⬠definition perform?List them all after reviewing the scan report. The Intense Scan initiated 36 Scripts. The scripts can be found at http://nmap. org/nsedoc/ 8. Describe what each of these tests or scripts performs within the Zenmap GUI (Nmap) scan report. Below are each of the 36 scripts and a description of each, derived from http://nmap. org/nsedoc/. acarsd-info Retrieves information from a listening acarsd daemon. Acarsd decodes ACARS (Aircraft Communicati on Addressing and Reporting System) data in real time. The information retrieved by this script includes the daemon version, API version, administrator e-mail address and listening frequency. ddress-info Shows extra information about IPv6 addresses, such as embedded MAC or IPv4 addresses when available. afp-brute Performs password guessing against Apple Filing Protocol (AFP). afp-ls Attempts to get useful information about files from AFP volumes. The output is intended to resemble the output of ls. afp-path-vuln Detects the Mac OS X AFP directory traversal vulnerability, CVE-2010-0533. afp-serverinfo Shows AFP server information. This information includes the server's hostname, IPv4 and IPv6 addresses, and hardware type (for example Macmini or MacBookPro). fp-showmount Shows AFP shares and ACLs. ajp-auth Retrieves the authentication scheme and realm of an AJP service (Apache JServ Protocol) that requires authentication. ajp-brute Performs brute force passwords auditing against the A pache JServ protocol. The Apache JServ Protocol is commonly used by web servers to communicate with back-end Java application server containers. ajp-headers Performs a HEAD or GET request against either the root directory or any optional directory of an Apache JServ Protocol server and returns the server response headers. ajp-methodsDiscovers which options are supported by the AJP (Apache JServ Protocol) server by sending an OPTIONS request and lists potentially risky methods. ajp-request Requests a URI over the Apache JServ Protocol and displays the result (or stores it in a file). Different AJP methods such as; GET, HEAD, TRACE, PUT or DELETE may be used. amqp-info Gathers information (a list of all server properties) from an AMQP (advanced message queuing protocol) server. asn-query Maps IP addresses to autonomous system (AS) numbers. auth-owners Attempts to find the owner of an open TCP port by querying an auth daemon which must also be open on the target system.The auth service , also known as identd, normally runs on port 113. auth-spoof Checks for an identd (auth) server which is spoofing its replies. backorifice-brute Performs brute force password auditing against the BackOrifice service. The backorifice-brute. ports script argument is mandatory (it specifies ports to run the script against). backorifice-info Connects to a BackOrifice service and gathers information about the host and the BackOrifice service itself. banner A simple banner grabber which connects to an open TCP port and prints out anything sent by the listening service within five seconds. bitcoin-getaddrQueries a Bitcoin server for a list of known Bitcoin nodes bitcoin-info Extracts version and node information from a Bitcoin server bitcoinrpc-info Obtains information from a Bitcoin server by calling getinfo on its JSON-RPC interface. bittorrent-discovery Discovers bittorrent peers sharing a file based on a user-supplied torrent file or magnet link. Peers implement the Bittorrent protoco l and share the torrent, whereas the nodes (only shown if the include-nodes NSE argument is given) implement the DHT protocol and are used to track the peers. The sets of peers and nodes are not the same, but they usually intersect. bjnp-discoverRetrieves printer or scanner information from a remote device supporting the BJNP protocol. The protocol is known to be supported by network based Canon devices. broadcast-ataoe-discover Discovers servers supporting the ATA over Ethernet protocol. ATA over Ethernet is an ethernet protocol developed by the Brantley Coile Company and allows for simple, high-performance access to SATA drives over Ethernet. broadcast-avahi-dos Attempts to discover hosts in the local network using the DNS Service Discovery protocol and sends a NULL UDP packet to each host to test if it is vulnerable to the Avahi NULL UDP packet denial of service (CVE-2011-1002). roadcast-bjnp-discover Attempts to discover Canon devices (Printers/Scanners) supporting the BJNP prot ocol by sending BJNP Discover requests to the network broadcast address for both ports associated with the protocol. broadcast-db2-discover Attempts to discover DB2 servers on the network by sending a broadcast request to port 523/udp. broadcast-dhcp-discover Sends a DHCP request to the broadcast address (255. 255. 255. 255) and reports the results. The script uses a static MAC address (DE:AD:CO:DE:CA:FE) while doing so in order to prevent scope exhaustion. broadcast-dhcp6-discoverSends a DHCPv6 request (Solicit) to the DHCPv6 multicast address, parses the response, then extracts and prints the address along with any options returned by the server. broadcast-dns-service-discovery Attempts to discover hosts' services using the DNS Service Discovery protocol. It sends a multicast DNS-SD query and collects all the responses. broadcast-dropbox-listener Listens for the LAN sync information broadcasts that the Dropbox. com client broadcasts every 20 seconds, then prints all the discovered client IP addresses, port numbers, version numbers, display names, and more. broadcast-eigrp-discoveryPerforms network discovery and routing information gathering through Cisco's Enhanced Interior Gateway Routing Protocol (EIGRP). broadcast-igmp-discovery Discovers targets that have IGMP Multicast memberships and grabs interesting information. broadcast-listener Sniffs the network for incoming broadcast communication and attempts to decode the received packets. It supports protocols like CDP, HSRP, Spotify, DropBox, DHCP, ARP and a few more. See packetdecoders. lua for more information. broadcast-ms-sql-discover Discovers Microsoft SQL servers in the same broadcast domain. broadcast-netbios-master-browserAttempts to discover master browsers and the domains they manage. broadcast-networker-discover Discovers EMC Networker backup software servers on a LAN by sending a network broadcast query. broadcast-novell-locate Attempts to use the Service Location Protocol to discover Novell Net Ware Core Protocol (NCP) servers. broadcast-pc-anywhere Sends a special broadcast probe to discover PC-Anywhere hosts running on a LAN. broadcast-pc-duo Discovers PC-DUO remote control hosts and gateways running on a LAN by sending a special broadcast UDP probe. broadcast-pim-discovery Discovers routers that are running PIM (Protocol Independent Multicast). roadcast-ping Sends broadcast pings on a selected interface using raw ethernet packets and outputs the responding hosts' IP and MAC addresses or (if requested) adds them as targets. Root privileges on UNIX are required to run this script since it uses raw sockets. Most operating systems don't respond to broadcast-ping probes, but they can be configured to do so. broadcast-pppoe-discover Discovers PPPoE (Point-to-Point Protocol over Ethernet) servers using the PPPoE Discovery protocol (PPPoED). PPPoE is an ethernet based protocol so the script has to know what ethernet interface to use for discovery.If no interface is specified, r equests are sent out on all available interfaces. broadcast-rip-discover Discovers hosts and routing information from devices running RIPv2 on the LAN. It does so by sending a RIPv2 Request command and collects the responses from all devices responding to the request. broadcast-ripng-discover Discovers hosts and routing information from devices running RIPng on the LAN by sending a broadcast RIPng Request command and collecting any responses. broadcast-sybase-asa-discover Discovers Sybase Anywhere servers on the LAN by sending broadcast discovery messages. broadcast-tellstick-discoverDiscovers Telldus Technologies TellStickNet devices on the LAN. The Telldus TellStick is used to wirelessly control electric devices such as lights, dimmers and electric outlets. For more information: http://www. telldus. com/ broadcast-upnp-info Attempts to extract system information from the UPnP service by sending a multicast query, then collecting, parsing, and displaying all responses. broadcast-ve rsant-locate Discovers Versant object databases using the broadcast srvloc protocol. broadcast-wake-on-lan Wakes a remote system up from sleep by sending a Wake-On-Lan packet. broadcast-wpad-discoverRetrieves a list of proxy servers on a LAN using the Web Proxy Autodiscovery Protocol (WPAD). It implements both the DHCP and DNS methods of doing so and starts by querying DHCP to get the address. DHCP discovery requires nmap to be running in privileged mode and will be skipped when this is not the case. DNS discovery relies on the script being able to resolve the local domain either through a script argument or by attempting to reverse resolve the local IP. broadcast-wsdd-discover Uses a multicast query to discover devices supporting the Web Services Dynamic Discovery (WS-Discovery) protocol.It also attempts to locate any published Windows Communication Framework (WCF) web services (. NET 4. 0 or later). broadcast-xdmcp-discover Discovers servers running the X Display Manager Control P rotocol (XDMCP) by sending a XDMCP broadcast request to the LAN. Display managers allowing access are marked using the keyword Willing in the result. cassandra-brute Performs brute force password auditing against the Cassandra database. cassandra-info Attempts to get basic info and server status from a Cassandra database. cccam-version Detects the CCcam service (software for sharing subscription TV among multiple receivers). itrix-brute-xml Attempts to guess valid credentials for the Citrix PN Web Agent XML Service. The XML service authenticates against the local Windows server or the Active Directory. citrix-enum-apps Extracts a list of published applications from the ICA Browser service. citrix-enum-apps-xml Extracts a list of applications, ACLs, and settings from the Citrix XML service. citrix-enum-servers Extracts a list of Citrix servers from the ICA Browser service. citrix-enum-servers-xml Extracts the name of the server farm and member servers from Citrix XML service. couchdb -databases Gets database tables from a CouchDB database. ouchdb-stats Gets database statistics from a CouchDB database. creds-summary Lists all discovered credentials (e. g. from brute force and default password checking scripts) at end of scan. cups-info Lists printers managed by the CUPS printing service. cups-queue-info Lists currently queued print jobs of the remote CUPS service grouped by printer. cvs-brute Performs brute force password auditing against CVS pserver authentication. cvs-brute-repository Attempts to guess the name of the CVS repositories hosted on the remote server. With knowledge of the correct repository name, usernames and passwords can be guessed. aap-get-library Retrieves a list of music from a DAAP server. The list includes artist names and album and song titles. daytime Retrieves the day and time from the Daytime service. db2-das-info Connects to the IBM DB2 Administration Server (DAS) on TCP or UDP port 523 and exports the server profile. No authentication is required for this request. db2-discover Attempts to discover DB2 servers on the network by querying open ibm-db2 UDP ports (normally port 523). dhcp-discover Sends a DHCPINFORM request to a host on UDP port 67 to obtain all the local configuration parameters without allocating a new address. ict-info Connects to a dictionary server using the DICT protocol, runs the SHOW SERVER command, and displays the result. The DICT protocol is defined in RFC 2229 and is a protocol which allows a client to query a dictionary server for definitions from a set of natural language dictionary databases. distcc-cve2004-2687 Detects and exploits a remote code execution vulnerability in the distributed compiler daemon distcc. The vulnerability was disclosed in 2002, but is still present in modern implementation due to poor configuration of the service. dns-blacklistChecks target IP addresses against multiple DNS anti-spam and open proxy blacklists and returns a list of services for which an IP has b een flagged. Checks may be limited by service category (eg: SPAM, PROXY) or to a specific service name. dns-brute Attempts to enumerate DNS hostnames by brute force guessing of common subdomains. dns-cache-snoop Performs DNS cache snooping against a DNS server. dns-check-zone Checks DNS zone configuration against best practices, including RFC 1912. The configuration checks are divided into categories which each have a number of different tests. dns-client-subnet-scanPerforms a domain lookup using the edns-client-subnet option which allows clients to specify the subnet that queries supposedly originate from. The script uses this option to supply a number of geographically distributed locations in an attempt to enumerate as many different address records as possible. The script also supports requests using a given subnet. dns-fuzz Launches a DNS fuzzing attack against DNS servers. dns-ip6-arpa-scan Performs a quick reverse DNS lookup of an IPv6 network using a technique which analyzes DNS server response codes to dramatically reduce the number of queries needed to enumerate large networks. ns-nsec-enum Enumerates DNS names using the DNSSEC NSEC-walking technique. dns-nsec3-enum Tries to enumerate domain names from the DNS server that supports DNSSEC NSEC3 records. dns-nsid Retrieves information from a DNS nameserver by requesting its nameserver ID (nsid) and asking for its id. server and version. bind values. This script performs the same queries as the following two dig commands: ââ¬â dig CH TXT bind. version @target ââ¬â dig +nsid CH TXT id. server @target dns-random-srcport Checks a DNS server for the predictable-port recursion vulnerability.Predictable source ports can make a DNS server vulnerable to cache poisoning attacks (see CVE-2008-1447). dns-random-txid Checks a DNS server for the predictable-TXID DNS recursion vulnerability. Predictable TXID values can make a DNS server vulnerable to cache poisoning attacks (see CVE-2008-1447). dns-recursion Checks if a DNS server allows queries for third-party names. It is expected that recursion will be enabled on your own internal nameservers. dns-service-discovery Attempts to discover target hosts' services using the DNS Service Discovery protocol. dns-srv-enum Enumerates various common service (SRV) records for a given domain name.The service records contain the hostname, port and priority of servers for a given service. The following services are enumerated by the script: ââ¬â Active Directory Global Catalog ââ¬â Exchange Autodiscovery ââ¬â Kerberos KDC Service ââ¬â Kerberos Passwd Change Service ââ¬â LDAP Servers ââ¬â SIP Servers ââ¬â XMPP S2S ââ¬â XMPP C2S dns-update Attempts to perform a dynamic DNS update without authentication. dns-zeustracker Checks if the target IP range is part of a Zeus botnet by querying ZTDNS @ abuse. ch. Please review the following information before you start to scan: https://zeustracker. abuse. ch/ztdns. php dns-zone-t ransferRequests a zone transfer (AXFR) from a DNS server. domcon-brute Performs brute force password auditing against the Lotus Domino Console. domcon-cmd Runs a console command on the Lotus Domino Console using the given authentication credentials (see also: domcon-brute) domino-enum-users Attempts to discover valid IBM Lotus Domino users and download their ID files by exploiting the CVE-2006-5835 vulnerability. dpap-brute Performs brute force password auditing against an iPhoto Library. drda-brute Performs password guessing against databases supporting the IBM DB2 protocol such as Informix, DB2 and Derby drda-infoAttempts to extract information from database servers supporting the DRDA protocol. The script sends a DRDA EXCSAT (exchange server attributes) command packet and parses the response. duplicates Attempts to discover multihomed systems by analysing and comparing information collected by other scripts. The information analyzed currently includes, SSL certificates, SSH host keys, MAC addresses, and Netbios server names. eap-info Enumerates the authentication methods offered by an EAP (Extensible Authentication Protocol) authenticator for a given identity or for the anonymous identity if no argument is passed. pmd-info Connects to Erlang Port Mapper Daemon (epmd) and retrieves a list of nodes with their respective port numbers. eppc-enum-processes Attempts to enumerate process info over the Apple Remote Event protocol. When accessing an application over the Apple Remote Event protocol the service responds with the uid and pid of the application, if it is running, prior to requesting authentication. finger Attempts to retrieve a list of usernames using the finger service. firewalk Tries to discover firewall rules using an IP TTL expiration technique known as firewalking. firewall-bypassDetects a vulnerability in netfilter and other firewalls that use helpers to dynamically open ports for protocols such as ftp and sip. flume-master-info Retrieves informat ion from Flume master HTTP pages. ftp-anon Checks if an FTP server allows anonymous logins. ftp-bounce Checks to see if an FTP server allows port scanning using the FTP bounce method. ftp-brute Performs brute force password auditing against FTP servers. ftp-libopie Checks if an FTPd is prone to CVE-2010-1938 (OPIE off-by-one stack overflow), a vulnerability discovered by Maksymilian Arciemowicz and Adam ââ¬Å"pi3â⬠Zabrocki. See the advisory at http://nmap. rg/r/fbsd-sa-opie. Be advised that, if launched against a vulnerable host, this script will crash the FTPd. ftp-proftpd-backdoor Tests for the presence of the ProFTPD 1. 3. 3c backdoor reported as OSVDB-ID 69562. This script attempts to exploit the backdoor using the innocuous id command by default, but that can be changed with the ftp-proftpd-backdoor. cmd script argument. ftp-vsftpd-backdoor Tests for the presence of the vsFTPd 2. 3. 4 backdoor reported on 2011-07-04 (CVE-2011-2523). This script attempts to exploit the ba ckdoor using the innocuous id command by default, but that can be changed with the exploit. md or ftp-vsftpd-backdoor. cmd script arguments. ftp-vuln-cve2010-4221 Checks for a stack-based buffer overflow in the ProFTPD server, version between 1. 3. 2rc3 and 1. 3. 3b. By sending a large number of TELNET_IAC escape sequence, the proftpd process miscalculates the buffer length, and a remote attacker will be able to corrupt the stack and execute arbitrary code within the context of the proftpd process (CVE-2010-4221). Authentication is not required to exploit this vulnerability. ganglia-info Retrieves system information (OS version, available memory, etc. from a listening Ganglia Monitoring Daemon or Ganglia Meta Daemon. giop-info Queries a CORBA naming server for a list of objects. gkrellm-info Queries a GKRellM service for monitoring information. A single round of collection is made, showing a snapshot of information at the time of the request. gopher-ls Lists files and directories at the root of a gopher service. gpsd-info Retrieves GPS time, coordinates and speed from the GPSD network daemon. hadoop-datanode-info Discovers information such as log directories from an Apache Hadoop DataNode HTTP status page. hadoop-jobtracker-infoRetrieves information from an Apache Hadoop JobTracker HTTP status page. hadoop-namenode-info Retrieves information from an Apache Hadoop NameNode HTTP status page. hadoop-secondary-namenode-info Retrieves information from an Apache Hadoop secondary NameNode HTTP status page. hadoop-tasktracker-info Retrieves information from an Apache Hadoop TaskTracker HTTP status page. hbase-master-info Retrieves information from an Apache HBase (Hadoop database) master HTTP status page. hbase-region-info Retrieves information from an Apache HBase (Hadoop database) region server HTTP status page. hddtemp-infoReads hard disk information (such as brand, model, and sometimes temperature) from a listening hddtemp service. hostmap-bfk Discovers hostnames that resolve to the target's IP address by querying the online database at http://www. bfk. de/bfk_dnslogger. html. hostmap-robtex Discovers hostnames that resolve to the target's IP address by querying the online Robtex service at http://ip. robtex. com/. http-affiliate-id Grabs affiliate network IDs (e. g. Google AdSense or Analytics, Amazon Associates, etc. ) from a web page. These can be used to identify pages with the same owner. http-apache-negotiationChecks if the target http server has mod_negotiation enabled. This feature can be leveraged to find hidden resources and spider a web site using fewer requests. http-auth Retrieves the authentication scheme and realm of a web service that requires authentication. http-auth-finder Spiders a web site to find web pages requiring form-based or HTTP-based authentication. The results are returned in a table with each url and the detected method. http-awstatstotals-exec Exploits a remote code execution vulnerability in Awstats Totals 1. 0 up to 1. 14 and possibly other products based on it (CVE: 2008-3922). ttp-axis2-dir-traversal Exploits a directory traversal vulnerability in Apache Axis2 version 1. 4. 1 by sending a specially crafted request to the parameter xsd (OSVDB-59001). By default it will try to retrieve the configuration file of the Axis2 service ââ¬Ë/conf/axis2. xml' using the path ââ¬Ë/axis2/services/' to return the username and password of the admin account. http-backup-finder Spiders a website and attempts to identify backup copies of discovered files. It does so by requesting a number of different combinations of the filename (eg. index. bak, index. html~, copy of index. html). http-barracuda-dir-traversalAttempts to retrieve the configuration settings from a Barracuda Networks Spam & Virus Firewall device using the directory traversal vulnerability described at http://seclists. org/fulldisclosure/2010/Oct/119. http-brute Performs brute force password auditing against http basic authenticatio n. http-cakephp-version Obtains the CakePHP version of a web application built with the CakePHP framework by fingerprinting default files shipped with the CakePHP framework. http-chrono Measures the time a website takes to deliver a web page and returns the maximum, minimum and average time it took to fetch a page. ttp-config-backup Checks for backups and swap files of common content management system and web server configuration files. http-cors Tests an http server for Cross-Origin Resource Sharing (CORS), a way for domains to explicitly opt in to having certain methods invoked by another domain. http-date Gets the date from HTTP-like services. Also prints how much the date differs from local time. Local time is the time the HTTP request was sent, so the difference includes at least the duration of one RTT. http-default-accounts Tests for access with default credentials used by a variety of web applications and devices. ttp-domino-enum-passwords Attempts to enumerate the hashed Do mino Internet Passwords that are (by default) accessible by all authenticated users. This script can also download any Domino ID Files attached to the Person document. http-drupal-enum-users Enumerates Drupal users by exploiting a an information disclosure vulnerability in Views, Drupal's most popular module. http-drupal-modules Enumerates the installed Drupal modules by using a list of known modules. http-email-harvest Spiders a web site and collects e-mail addresses. http-enum Enumerates directories used by popular web applications and servers. ttp-exif-spider Spiders a site's images looking for interesting exif data embedded in . jpg files. Displays the make and model of the camera, the date the photo was taken, and the embedded geotag information. http-favicon Gets the favicon (ââ¬Å"favorites iconâ⬠) from a web page and matches it against a database of the icons of known web applications. If there is a match, the name of the application is printed; otherwise the MD5 hash of the icon data is printed. http-form-brute Performs brute force password auditing against http form-based authentication. http-form-fuzzerPerforms a simple form fuzzing against forms found on websites. Tries strings and numbers of increasing length and attempts to determine if the fuzzing was successful. http-frontpage-login Checks whether target machines are vulnerable to anonymous Frontpage login. http-generator Displays the contents of the ââ¬Å"generatorâ⬠meta tag of a web page (default: /) if there is one. http-git Checks for a Git repository found in a website's document root /. git/) and retrieves as much repo information as possible, including language/framework, remotes, last commit message, and repository description. http-gitweb-projects-enumRetrieves a list of Git projects, owners and descriptions from a gitweb (web interface to the Git revision control system). http-google-malware Checks if hosts are on Google's blacklist of suspected malware and phishing serve rs. These lists are constantly updated and are part of Google's Safe Browsing service. http-grep Spiders a website and attempts to match all pages and urls against a given string. Matches are counted and grouped per url under which they were discovered. http-headers Performs a HEAD request for the root folder (ââ¬Å"/â⬠) of a web server and displays the HTTP headers returned. http-huawei-hg5xx-vulnDetects Huawei modems models HG530x, HG520x, HG510x (and possibly othersâ⬠¦ ) vulnerable to a remote credential and information disclosure vulnerability. It also extracts the PPPoE credentials and other interesting configuration values. http-icloud-findmyiphone Retrieves the locations of all ââ¬Å"Find my iPhoneâ⬠enabled iOS devices by querying the MobileMe web service (authentication required). http-icloud-sendmsg Sends a message to a iOS device through the Apple MobileMe web service. The device has to be registered with an Apple ID using the Find My Iphone application. h ttp-iis-webdav-vuln Checks for a vulnerability in IIS 5. /6. 0 that allows arbitrary users to access secured WebDAV folders by searching for a password-protected folder and attempting to access it. This vulnerability was patched in Microsoft Security Bulletin MS09-020, http://nmap. org/r/ms09-020. http-joomla-brute Performs brute force password auditing against Joomla web CMS installations. http-litespeed-sourcecode-download Exploits a null-byte poisoning vulnerability in Litespeed Web Servers 4. 0. x before 4. 0. 15 to retrieve the target script's source code by sending a HTTP request with a null byte followed by a . txt file extension (CVE-2010-2333). ttp-majordomo2-dir-traversal Exploits a directory traversal vulnerability existing in Majordomo2 to retrieve remote files. (CVE-2011-0049). http-malware-host Looks for signature of known server compromises. http-method-tamper Attempts to bypass password protected resources (HTTP 401 status) by performing HTTP verb tampering. If an ar ray of paths to check is not set, it will crawl the web server and perform the check against any password protected resource that it finds. http-methods Finds out what options are supported by an HTTP server by sending an OPTIONS request. Lists potentially risky methods.Optionally tests each method individually to see if they are subject to e. g. IP address restrictions. http-open-proxy Checks if an HTTP proxy is open. http-open-redirect Spiders a website and attempts to identify open redirects. Open redirects are handlers which commonly take a URL as a parameter and responds with a http redirect (3XX) to the target. Risks of open redirects are described at http://cwe. mitre. org/data/definitions/601. html. http-passwd Checks if a web server is vulnerable to directory traversal by attempting to retrieve /etc/passwd or oot. ini. http-php-version Attempts to retrieve the PHP version from a web server.PHP has a number of magic queries that return images or text that can vary with the PHP version. This script uses the following queries: /? =PHPE9568F36-D428-11d2-A769-00AA001ACF42: gets a GIF logo, which changes on April Fool's Day. /? =PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: gets an HTML credits page. http-phpself-xss Crawls a web server and attempts to find PHP files vulnerable to reflected cross site scripting via the variable $_SERVER[ââ¬Å"PHP_SELFâ⬠]. http-proxy-brute Performs brute force password guessing against HTTP proxy servers. http-put Uploads a local file to a remote web server using the HTTP PUT method.You must specify the filename and URL path with NSE arguments. http-qnap-nas-info Attempts to retrieve the model, firmware version, and enabled services from a QNAP Network Attached Storage (NAS) device. http-rfi-spider Crawls webservers in search of RFI (remote file inclusion) vulnerabilities. It tests every form field it finds and every parameter of a URL containing a query. http-robots. txt Checks for disallowed entries in /robots. txt on a web server. http-robtex-reverse-ip Obtains up to 100 forward DNS names for a target IP address by querying the Robtex service (http://www. robtex. com/ip/). http-robtex-shared-nsFinds up to 100 domain names which use the same name server as the target by querying the Robtex service at http://www. robtex. com/dns/. http-sitemap-generator Spiders a web server and displays its directory structure along with number and types of files in each folder. Note that files listed as having an ââ¬ËOther' extension are ones that have no extension or that are a root document. http-slowloris Tests a web server for vulnerability to the Slowloris DoS attack by launching a Slowloris attack. http-slowloris-check Tests a web server for vulnerability to the Slowloris DoS attack without actually launching a DoS attack. ttp-sql-injection Spiders an HTTP server looking for URLs containing queries vulnerable to an SQL injection attack. It also extracts forms from found websites and tries to identify field s that are vulnerable. http-title Shows the title of the default page of a web server. http-tplink-dir-traversal Exploits a directory traversal vulnerability existing in several TP-Link wireless routers. Attackers may exploit this vulnerability to read any of the configuration and password files remotely and without authentication. http-trace Sends an HTTP TRACE request and shows if the method TRACE is enabled.If debug is enabled, it returns the header fields that were modified in the response. http-traceroute Exploits the Max-Forwards HTTP header to detect the presence of reverse proxies. http-unsafe-output-escaping Spiders a website and attempts to identify output escaping problems where content is reflected back to the user. This script locates all parameters, ? x=foo&y=bar and checks if the values are reflected on the page. If they are indeed reflected, the script will try to insert ghz>hzxâ⬠zxc'xcv and check which (if any) characters were reflected back onto the page witho ut proper html escaping.This is an indication of potential XSS vulnerability. http-userdir-enum Attempts to enumerate valid usernames on web servers running with the mod_userdir module or similar enabled. http-vhosts Searches for web virtual hostnames by making a large number of HEAD requests against http servers using common hostnames. http-virustotal Checks whether a file has been determined as malware by Virustotal. Virustotal is a service that provides the capability to scan a file or check a checksum against a number of the major antivirus vendors.The script uses the public API which requires a valid API key and has a limit on 4 queries per minute. A key can be acquired by registering as a user on the virustotal web page: http://www. virustotal. com http-vlcstreamer-ls Connects to a VLC Streamer helper service and lists directory contents. The VLC Streamer helper service is used by the iOS VLC Streamer application to enable streaming of multimedia content from the remote server to the device. http-vmware-path-vuln Checks for a path-traversal vulnerability in VMWare ESX, ESXi, and Server (CVE-2009-3733). http-vuln-cve2009-3960Exploits cve-2009-3960 also known as Adobe XML External Entity Injection. http-vuln-cve2010-0738 Tests whether a JBoss target is vulnerable to jmx console authentication bypass (CVE-2010-0738). http-vuln-cve2010-2861 Executes a directory traversal attack against a ColdFusion server and tries to grab the password hash for the administrator user. It then uses the salt value (hidden in the web page) to create the SHA1 HMAC hash that the web server needs for authentication as admin. You can pass this value to the ColdFusion server as the admin without cracking the password hash. ttp-vuln-cve2011-3192 Detects a denial of service vulnerability in the way the Apache web server handles requests for multiple overlapping/simple ranges of a page. http-vuln-cve2011-3368 Tests for the CVE-2011-3368 (Reverse Proxy Bypass) vulnerability in Apache HT TP server's reverse proxy mode. The script will run 3 tests: o the loopback test, with 3 payloads to handle different rewrite rules o the internal hosts test. According to Contextis, we expect a delay before a server error. o The external website test. This does not mean that you can reach a LAN ip, but this is a relevant issue anyway. ttp-vuln-cve2012-1823 Detects PHP-CGI installations that are vulnerable to CVE-2012-1823, This critical vulnerability allows attackers to retrieve source code and execute code remotely. http-waf-detect Attempts to determine whether a web server is protected by an IPS (Intrusion Prevention System), IDS (Intrusion Detection System) or WAF (Web Application Firewall) by probing the web server with malicious payloads and detecting changes in the response code and body. http-waf-fingerprint Tries to detect the presence of a web application firewall and its type and version. http-wordpress-brute erforms brute force password auditing against WordPress CMS/blo g installations. http-wordpress-enum Enumerates usernames in WordPress blog/CMS installations by exploiting an information disclosure vulnerability existing in versions 2. 6, 3. 1, 3. 1. 1, 3. 1. 3 and 3. 2-beta2 and possibly others. http-wordpress-plugins Tries to obtain a list of installed WordPress plugins by brute force testing for known plugins. iax2-brute Performs brute force password auditing against the Asterisk IAX2 protocol. Guessing fails when a large number of attempts is made due to the maxcallnumber limit (default 2048).In case your getting ââ¬Å"ERROR: Too many retries, aborted â⬠¦ â⬠after a while, this is most likely what's happening. In order to avoid this problem try: ââ¬â reducing the size of your dictionary ââ¬â use the brute delay option to introduce a delay between guesses ââ¬â split the guessing up in chunks and wait for a while between them iax2-version Detects the UDP IAX2 service. icap-info Tests a list of known ICAP service names and prints information about any it detects. The Internet Content Adaptation Protocol (ICAP) is used to extend transparent proxy servers and is generally used for content filtering and antivirus scanning. ke-version Get information from an IKE service. Tests the service with both Main and Aggressive Mode. Sends multiple transforms in a single request, so currently, only four packets are sent to the host. imap-brute Performs brute force password auditing against IMAP servers using either LOGIN, PLAIN, CRAM-MD5, DIGEST-MD5 or NTLM authentication. imap-capabilities Retrieves IMAP email server capabilities. informix-brute Performs brute force password auditing against IBM Informix Dynamic Server. informix-query Runs a query against IBM Informix Dynamic Server using the given authentication credentials (see also: informix-brute). nformix-tables Retrieves a list of tables and column definitions for each database on an Informix server. ip-forwarding Detects whether the remote device has ip fo rwarding or ââ¬Å"Internet connection sharingâ⬠enabled, by sending an ICMP echo request to a given target using the scanned host as default gateway. ip-geolocation-geobytes Tries to identify the physical location of an IP address using the Geobytes geolocation web service (http://www. geobytes. com/iplocator. htm). The limit of lookups using this service is 20 requests per hour. Once the limit is reached, an nmap. registry[ââ¬Å"ip-geolocation-geobytesâ⬠]. blocked oolean is set so no further requests are made during a scan. ip-geolocation-geoplugin Tries to identify the physical location of an IP address using the Geoplugin geolocation web service (http://www. geoplugin. com/). There is no limit on lookups using this service. ip-geolocation-ipinfodb Tries to identify the physical location of an IP address using the IPInfoDB geolocation web service (http://ipinfodb. com/ip_location_api. php). ip-geolocation-maxmind Tries to identify the physical location of an IP address using a Geolocation Maxmind database file (available from http://www. maxmind. com/app/ip-location).This script supports queries using all Maxmind databases that are supported by their API including the commercial ones. ipidseq Classifies a host's IP ID sequence (test for susceptibility to idle scan). ipv6-node-info Obtains hostnames, IPv4 and IPv6 addresses through IPv6 Node Information Queries. ipv6-ra-flood Generates a flood of Router Advertisements (RA) with random source MAC addresses and IPv6 prefixes. Computers, which have stateless autoconfiguration enabled by default (every major OS), will start to compute IPv6 suffix and update their routing table to reflect the accepted announcement.This will cause 100% CPU usage on Windows and platforms, preventing to process other application requests. irc-botnet-channels Checks an IRC server for channels that are commonly used by malicious botnets. irc-brute Performs brute force password auditing against IRC (Internet Relay Chat) serv ers. irc-info Gathers information from an IRC server. irc-sasl-brute Performs brute force password auditing against IRC (Internet Relay Chat) servers supporting SASL authentication. irc-unrealircd-backdoor Checks if an IRC server is backdoored by running a time-based command (ping) and checking how long it takes to respond. scsi-brute Performs brute force password auditing against iSCSI targets. iscsi-info Collects and displays information from remote iSCSI targets. isns-info Lists portals and iSCSI nodes registered with the Internet Storage Name Service (iSNS). jdwp-exec Attempts to exploit java's remote debugging port. When remote debugging port is left open, it is possible to inject java bytecode and achieve remote code execution. This script abuses this to inject and execute a Java class file that executes the supplied shell command and returns its output. jdwp-info Attempts to exploit java's remote debugging port.When remote debugging port is left open, it is possible to inject java bytecode and achieve remote code execution. This script injects and execute a Java class file that returns remote system information. jdwp-inject Attempts to exploit java's remote debugging port. When remote debugging port is left open, it is possible to inject java bytecode and achieve remote code execution. This script allows injection of arbitrary class files. jdwp-version Detects the Java Debug Wire Protocol. This protocol is used by Java programs to be debugged via the network.It should not be open to the public Internet, as it does not provide any security against malicious attackers who can inject their own bytecode into the debugged process. krb5-enum-users Discovers valid usernames by brute force querying likely usernames against a Kerberos service. When an invalid username is requested the server will responde using the Kerberos error code KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN, allowing us to determine that the user name was invalid. Valid user names will illicit either th e TGT in a AS-REP response or the error KRB5KDC_ERR_PREAUTH_REQUIRED, signaling that the user is required to perform pre authentication. dap-brute Attempts to brute-force LDAP authentication. By default it uses the built-in username and password lists. In order to use your own lists use the userdb and passdb script arguments. ldap-novell-getpass Universal Password enables advanced password policies, including extended characters in passwords, synchronization of passwords from eDirectory to other systems, and a single password for all access to eDirectory. ldap-rootdse Retrieves the LDAP root DSA-specific Entry (DSE) ldap-search Attempts to perform an LDAP search and returns all matches. lexmark-config Retrieves configuration information from a Lexmark S300-S400 printer. lmnr-resolve Resolves a hostname by using the LLMNR (Link-Local Multicast Name Resolution) protocol. lltd-discovery Uses the Microsoft LLTD protocol to discover hosts on a local network. maxdb-info Retrieves version and database information from a SAP Max DB database. mcafee-epo-agent Check if ePO agent is running on port 8081 or port identified as ePO Agent port. membase-brute Performs brute force password auditing against Couchbase Membase servers. membase-http-info Retrieves information (hostname, OS, uptime, etc. ) from the CouchBase Web Administration port. The information retrieved by this script does not require any credentials. emcached-info Retrieves information (including system architecture, process ID, and server time) from distributed memory object caching system memcached. metasploit-info Gathers info from the Metasploit rpc service. It requires a valid login pair. After authentication it tries to determine Metasploit version and deduce the OS type. Then it creates a new console and executes few commands to get additional info. References: * http://wiki. msgpack. org/display/MSGPACK/Format+specification * https://community. rapid7. com/docs/DOC-1516 Metasploit RPC API Guide metasp loit-msgrpc-brutePerforms brute force username and password auditing against Metasploit msgrpc interface. metasploit-xmlrpc-brute Performs brute force password auditing against a Metasploit RPC server using the XMLRPC protocol. mmouse-brute Performs brute force password auditing against the RPA Tech Mobile Mouse servers. mmouse-exec Connects to an RPA Tech Mobile Mouse server, starts an application and sends a sequence of keys to it. Any application that the user has access to can be started and the key sequence is sent to the application after it has been started. modbus-discover Enumerates SCADA Modbus slave ids (sids) and collects their device information. ongodb-brute Performs brute force password auditing against the MongoDB database. mongodb-databases Attempts to get a list of tables from a MongoDB database. mongodb-info Attempts to get build info and server status from a MongoDB database. mrinfo Queries targets for multicast routing information. ms-sql-brute Performs password guessing against Microsoft SQL Server (ms-sql). Works best in conjunction with the broadcast-ms-sql-discover script. ms-sql-config Queries Microsoft SQL Server (ms-sql) instances for a list of databases, linked servers, and configuration settings. ms-sql-dacQueries the Microsoft SQL Browser service for the DAC (Dedicated Admin Connection) port of a given (or all) SQL Server instance. The DAC port is used to connect to the database instance when normal connection attempts fail, for example, when server is hanging, out of memory or in other bad states. In addition, the DAC port provides an admin with access to system objects otherwise not accessible over normal connections. ms-sql-dump-hashes Dumps the password hashes from an MS-SQL server in a format suitable for cracking by tools such as John-the-ripper. In order to do so the user needs to have the appropriate DB privileges. s-sql-empty-password Attempts to authenticate to Microsoft SQL Servers using an empty password for the sysad min (sa) account. ms-sql-hasdbaccess Queries Microsoft SQL Server (ms-sql) instances for a list of databases a user has access to. ms-sql-info Attempts to determine configuration and version information for Microsoft SQL Server instances. ms-sql-query Runs a query against Microsoft SQL Server (ms-sql). ms-sql-tables Queries Microsoft SQL Server (ms-sql) for a list of tables per database. ms-sql-xp-cmdshell Attempts to run a command using the command shell of Microsoft SQL Server (ms-sql). msrpc-enumQueries an MSRPC endpoint mapper for a list of mapped services and displays the gathered information. mtrace Queries for the multicast path from a source to a destination host. murmur-version Detects the Murmur service (server for the Mumble voice communication client) version 1. 2. 0 and above. mysql-audit Audits MySQL database server security configuration against parts of the CIS MySQL v1. 0. 2 benchmark (the engine can be used for other MySQL audits by creating appropriate audit files ). mysql-brute Performs password guessing against MySQL. mysql-databases Attempts to list all databases on a MySQL server. mysql-dump-hashesDumps the password hashes from an MySQL server in a format suitable for cracking by tools such as John the Ripper. Appropriate DB privileges (root) are required. mysql-empty-password Checks for MySQL servers with an empty password for root or anonymous. mysql-enum Performs valid user enumeration against MySQL server. mysql-info Connects to a MySQL server and prints information such as the protocol and version numbers, thread ID, status, capabilities, and the password salt. mysql-query Runs a query against a MySQL database and returns the results as a table. mysql-users Attempts to list all users on a MySQL server. mysql-variablesAttempts to show all variables on a MySQL server. mysql-vuln-cve2012-2122 nat-pmp-info Get's the routers WAN IP using the NAT Port Mapping Protocol (NAT-PMP). The NAT-PMP protocol is supported by a broad range of routers including: ââ¬â Apple AirPort Express ââ¬â Apple AirPort Extreme ââ¬â Apple Time Capsule ââ¬â DD-WRT ââ¬â OpenWrt v8. 09 or higher, with MiniUPnP daemon ââ¬â pfSense v2. 0 ââ¬â Tarifa (firmware) (Linksys WRT54G/GL/GS) ââ¬â Tomato Firmware v1. 24 or higher. (Linksys WRT54G/GL/GS and many more) ââ¬â Peplink Balance nat-pmp-mapport Maps a WAN port on the router to a local port on the client using the NAT Port Mapping Protocol (NAT-PMP).It supports the following operations: o map ââ¬â maps a new external port on the router to an internal port of the requesting IP o unmap ââ¬â unmaps a previously mapped port for the requesting IP o unmapall ââ¬â unmaps all previously mapped ports for the requesting IP nbstat Attempts to retrieve the target's NetBIOS names and MAC address. ncp-enum-users Retrieves a list of all eDirectory users from the Novell NetWare Core Protocol (NCP) service. ncp-serverinfo Retrieves eDirectory server information (OS ve rsion, server name, mounts, etc. ) from the Novell NetWare Core Protocol (NCP) service. ndmp-fs-infoLists remote file systems by querying the remote device using the Network Data Management Protocol (ndmp). NDMP is a protocol intended to transport data between a NAS device and the backup device, removing the need for the data to pass through the backup server. The following products are known to support the protocol: Amanda Bacula CA Arcserve CommVault Simpana EMC Networker Hitachi Data Systems IBM Tivoli Quest Software Netvault Backup Symantec Netbackup Symantec Backup Exec ndmp-version Retrieves version information from the remote Network Data Management Protocol (ndmp) service.NDMP is a protocol intended to transport data between a NAS device and the backup device, removing the need for the data to pass through the backup server. The following products are known to support the protocol: Amanda Bacula CA Arcserve CommVault Simpana EMC Networker Hitachi Data Systems IBM Tivoli Ques t Software Netvault Backup Symantec Netbackup Symantec Backup Exec nessus-brute Performs brute force password auditing against a Nessus vulnerability scanning daemon using the NTP 1. 2 protocol. nessus-xmlrpc-brute Performs brute force password auditing against a Nessus vulnerability scanning daemon using the XMLRPC protocol. etbus-auth-bypass Checks if a NetBus server is vulnerable to an authentication bypass vulnerability which allows full access without knowing the password. netbus-brute Performs brute force password auditing against the Netbus backdoor (ââ¬Å"remote administrationâ⬠) service. netbus-info Opens a connection to a NetBus server and extracts information about the host and the NetBus service itself. netbus-version Extends version detection to detect NetBuster, a honeypot service that mimes NetBus. nexpose-brute Performs brute force password auditing against a Nexpose vulnerability scanner using the API 1. 1.By default it only tries three guesses per username to avoid target account lockout. nfs-ls Attempts to get useful information about files from NFS exports. The output is intended to resemble the output of ls. nfs-showmount Shows NFS exports, like the showmount -e command. nfs-statfs Retrieves disk space statistics and information from a remote NFS share. The output is intended to resemble the output of df. nping-brute Performs brute force password auditing against an Nping Echo service. nrpe-enum Queries Nagios Remote Plugin Executor (NRPE) daemons to obtain information such as load averages, process counts, logged in user information, etc. tp-info Gets the time and configuration variables from an NTP server. We send two requests: a time request and a ââ¬Å"read variablesâ⬠(opcode 2) control message. Without verbosity, the script shows the time and the value of the version, processor, system, refid, and stratum variables. With verbosity, all variables are shown. ntp-monlist Obtains and prints an NTP server's monitor data. omp2- brute Performs brute force password auditing against the OpenVAS manager using OMPv2. omp2-enum-targets Attempts to retrieve the list of target systems and networks from an OpenVAS Manager server. openlookup-infoParses and displays the banner information of an OpenLookup (network key-value store) server. openvas-otp-brute Performs brute force password auditing against a OpenVAS vulnerability scanner daemon using the OTP 1. 0 protocol. oracle-brute Performs brute force password auditing against Oracle servers. oracle-brute-stealth Exploits the CVE-2012-3137 vulnerability, a weakness in Oracle's O5LOGIN authentication scheme. The vulnerability exists in Oracle 11g R1/R2 and allows linking the session key to a password hash. When initiating an authentication attempt as a valid user the server will respond with a session key and salt.Once received the script will disconnect the connection thereby not recording the login attempt. The session key and salt can then be used to brute force t he users password. oracle-enum-users Attempts to enumerate valid Oracle user names against unpatched Oracle 11g servers (this bug was fixed in Oracle's October 2009 Critical Patch Update). oracle-sid-brute Guesses Oracle instance/SID names against the TNS-listener. ovs-agent-version Detects the version of an Oracle Virtual Server Agent by fingerprinting responses to an HTTP GET request and an XML-RPC method call. p2p-conficker Checks if a host is infected with Conficker.C or higher, based on Conficker's peer to peer communication. path-mtu Performs simple Path MTU Discovery to target hosts. pcanywhere-brute Performs brute force password auditing against the pcAnywhere remote access protocol. pgsql-brute Performs password guessing against PostgreSQL. pjl-ready-message Retrieves or sets the ready message on printers that support the Printer Job Language. This includes most PostScript printers that listen on port 9100. Without an argument, displays the current ready message. With the p jl_ready_message script argument, displays the old ready message and changes it to the message given. op3-brute Tries to log into a POP3 account by guessing usernames and passwords. pop3-capabilities Retrieves POP3 email server capabilities. pptp-version Attempts to extract system information from the point-to-point tunneling protocol (PPTP) service. qscan Repeatedly probe open and/or closed ports on a host to obtain a series of round-trip time values for each port. These values are used to group collections of ports which are statistically different from other groups. Ports being in different groups (or ââ¬Å"familiesâ⬠) may be due to network mechanisms such as port forwarding to machines behind a NAT. quake3-infoExtracts information from a Quake3 game server and other games which use the same protocol. quake3-master-getservers Queries Quake3-style master servers for game servers (many games other than Quake 3 use this same protocol). rdp-enum-encryption Determines which Secu rity layer and Encryption level is supported by the RDP service. It does so by cycling through all existing protocols and ciphers. When run in debug mode, the script also returns the protocols and ciphers that fail and any errors that were reported. rdp-vuln-ms12-020 Checks if a machine is vulnerable to MS12-020 RDP vulnerability. realvnc-auth-bypassChecks if a VNC server is vulnerable to the RealVNC authentication bypass (CVE-2006-2369). redis-brute Performs brute force passwords auditing against a Redis key-value store. redis-info Retrieves information (such as version number and architecture) from a Redis key-value store. resolveall Resolves hostnames and adds every address (IPv4 or IPv6, depending on Nmap mode) to Nmap's target list. This differs from Nmap's normal host resolution process, which only scans the first address (A or AAAA record) returned for each host name. reverse-index Creates a reverse index at the end of scan output showing which hosts run a particular service. This is in addition to Nmap's normal output listing the services on each host. rexec-brute Performs brute force password auditing against the classic UNIX rexec (remote exec) service. riak-http-info Retrieves information (such as node name and architecture) from a Basho Riak distributed database using the HTTP protocol. rlogin-brute Performs brute force password auditing against the classic UNIX rlogin (remote login) service. This script must be run in privileged mode on UNIX because it must bind to a low source port number. rmi-dumpregistry Connects to a remote RMI registry and attempts to dump all of its objects. mi-vuln-classloader Tests whether Java rmiregistry allows class loading. The default configuration of rmiregistry allows loading classes from remote URLs, which can lead to remote code execution. The vendor (Oracle/Sun) classifies this as a design feature. rpc-grind Fingerprints the target RPC port to extract the target service, RPC number and version. rpcap-brute Perform s brute force password auditing against the WinPcap Remote Capture Daemon (rpcap). rpcap-info Connects to the rpcap service (provides remote sniffing capabilities through WinPcap) and retrieves interface information.The service can either be setup to require authentication or not and also supports IP restrictions. rpcinfo Connects to portmapper and fetches a list of all registered programs. It then prints out a table including (for each program) the RPC program number, supported version numbers, port number and protocol, and program name. rsync-brute Performs brute force password auditing against the rsync remote file syncing protocol. rsync-list-modules Lists modules available for rsync (remote file sync) synchronization. rtsp-methods Determines which methods are supported by the RTSP (real time streaming protocol) server. tsp-url-brute Attempts to enumerate RTSP media URLS by testing for common paths on devices such as surveillance IP cameras. samba-vuln-cve-2012-1182 Checks if ta rget machines are vulnerable to the Samba heap overflow vulnerability CVE-2012-1182. servicetags Attempts to extract system information (OS, hardware, etc. ) from the Sun Service Tags service agent (UDP port 6481). sip-brute Performs brute force password auditing against Session Initiation Protocol (SIP ââ¬â http://en. wikipedia. org/wiki/Session_Initiation_Protocol) accounts. This protocol is most commonly associated with VoIP sessions. ip-call-spoof Spoofs a call to a SIP phone and detects the action taken by the target (busy, declined, hung up, etc. ) sip-enum-users Enumerates a SIP server's valid extensions (users). sip-methods Enumerates a SIP Server's allowed methods (INVITE, OPTIONS, SUBSCRIBE, etc. ) skypev2-version Detects the Skype version 2 service. smb-brute Attempts to guess username/password combinations over SMB, storing discovered combinations for use in other scripts. Every attempt will be made to get a valid list of users and to verify each username before actu ally using them.When a username is discovered, besides being printed, it is also saved in the Nmap registry so other Nmap scripts can use it. That means that if you're going to run smb-brute. nse, you should run other smb scripts you want. This checks passwords in a case-insensitive way, determining case after a password is found, for Windows versions before Vista. smb-check-vulns Checks for vulnerabilities: MS08-067, a Windows RPC vulnerability Conficker, an infection by the Conficker worm Unnamed regsvc DoS, a denial-of-service vulnerability I accidentally found in Windows 2000 SMBv2 exploit (CVE-2009-3103, Microsoft Security Advisory 75497) MS06-025, a Windows Ras RPC service vulnerability MS07-029, a Windows Dns Server RPC service vulnerability smb-enum-domains Attempts to enumerate domains on a system, along with their policies. This generally requires credentials, except against Windows 2000. In addition to the actual domain, the ââ¬Å"Builtinâ⬠domain is generally displ ayed. Windows returns this in the list of domains, but its policies don't appear to be used anywhere. smb-enum-groups Obtains a list of groups from the remote Windows system, as well as a list of the group's users. This works similarly to enum. exe with the /G switch. smb-enum-processesPulls a list of processes from the remote server over SMB. This will determine all running processes, their process IDs, and their parent processes. It is done by querying the remote registry service, which is disabled by default on Vista; on all other Windows versions, it requires Administrator privileges. smb-enum-sessions Enumerates the users logged into a system either locally or through an SMB share. The local users can be logged on either physically on the machine, or through a terminal services session. Connections to a SMB share are, for example, people connected to fileshares or making RPC calls.Nmap's connection will also show up, and is generally identified by the one that connected ââ¬Å" 0 seconds agoâ⬠. smb-enum-shares Attempts to list shares using the srvsvc. NetShareEnumAll MSRPC function and retrieve more information about them using srvsvc. NetShareGetInfo. If access to those functions is denied, a list of common share names are checked. smb-enum-users Attempts to enumerate the users on a remote Windows system, with as much information as possible, through two different techniques (both over MSRPC, which uses port 445 or 139; see smb. lua). The goal of this script is to iscover all user accounts that exist on a remote system. This can be helpful for administration, by seeing who has an account on a server, or for penetration testing or network footprinting, by determining which accounts exist on a system. smb-flood Exhausts a remote SMB server's connection limit by by opening as many connections as we can. Most implementations of SMB have a hard global limit of 11 connections for user accounts and 10 connections for anonymous. Once that limit is reached, f urther connections are denied. This script exploits that limit by taking up all the connections and holding them. smb-lsAttempts to retrieve useful information about files shared on SMB volumes. The output is intended to resemble the output of the UNIX ls command. smb-mbenum Queries information managed by the Windows Master Browser. smb-os-discovery Attempts to determine the operating system, computer name, domain, workgroup, and current time over the SMB protocol (ports 445 or 139). This is done by starting a session with the anonymous account (or with a proper user account, if one is given; it likely doesn't make a difference); in response to a session starting, the server will send back all this information. smb-print-text
Friday, January 3, 2020
Marxism As A Conflict Theory - 1273 Words
ââ¬Å"Marxism is a conflict theory based on the idea that society is in conflict with each other; the conflict is between the rich and the poorâ⬠(ââ¬Å"A Brief Introduction to Marxismâ⬠). The basic tenets of Marxââ¬â¢s theory rest on the conflict between the different classes of society of which, Marx states that ââ¬Å"the ideas of the ruling class are in every epoch the ruling ideas: i.e.,the class which is the ruling material force of society is at the same time its ruling intellectual force. The class which has the means for material production at its disposal have control at the same time over the means of material production, so that ...generally speaking, the ideas of those who lack the means of mental and [material] production are subject to itâ⬠(Marxâ⬠¦show more contentâ⬠¦The tenets of Marxism as defined by Marx and Althusser provide a unique lens through which the reader can view Joseph Conradââ¬â¢s Heart of Darkness. Conradââ¬â¢s novel la portrays the historical era of Imperialism, when European countries, Great Britain included, were laying claim to parts of the African continent for its riches in natural resources. The idea that ââ¬Å"Imperialism was the highest stage of capitalismâ⬠, expressed by Vladimir Lenin, a proponent of Marxism, adds an important layer to a study of the novella using Marxist theory (Marxism: Essential Writings). A look at one small scene from Section III of the novel, in which the young Russian speaks about Kurtz to Marlowe, blatantly illustrates the treatment of the workforce by the ruling class: He had, as he informed me proudly, managed to nurse Kurtz through two illnesses (he alluded to it as you would to some risky feat), but as a rule Kurtz wandered alone, far in the depths of the forest. Very often coming to this station, I had to wait days and days before he would turn up, he said. Ah, it was worth waiting for!--sometimes. What was he doing? exploring or what? I asked. Oh yes, of course; he had discovered lots of villages, a lake too--he did not know exactly in what direction; it was dangerous to inquire too much--but mostly his expeditions had been for ivory. But heShow MoreRelatedMarxism : A Structural Conflict Theory1718 Words à |à 7 Pages Marxism is a macro, structural conflict theory that denotes Marxists belief that the ruling class (bourgeoisie) exploits the working class (proletariat) for means of labour, as the bourgeois own the factors of production. Marx called the resulting situation alienation, and he said that when the workers repossessed the object at which they produced through the division of labour, alienation would be overcome and class divisions would cease. This is the apparent class struggle that plays a centralRead More Marxism and Labour Theory - The Conflicts between Employee and Employer3044 Words à |à 13 PagesMarxism and Labour Theory - The Conflicts between Employee and Employer 1. Introduction 1.1 Overview on the essay topic To organisations, employees (labours) are wonderful resources, because they are compact and multi-purpose, capable of simple manual tasks or dealing with complicated machines, most importantly, they are the profit maker for their employers. However, there is always a problem between employees and employer. Any attempt to manager in a humane way, by consensus, is doomed to failureRead MoreAssess the Usefulness of Marxism and Other Conflict Theories of Our Understanding of Society.2104 Words à |à 9 PagesAssess the usefulness of Marxism and other conflict theories of our understanding of society. Marxism is a useful conflict theory in helping us to understand why there was obedience, particularly in the past in society. Marx was seen as an economic determinist, as he believed that the functioning and running of society was based upon the economy. Because of this, Marx says that is why there was a divide between the proletariat (working class who have only their skills to sell) and the bourgeoisieRead MoreTheories Of Marxist Theory And Conflict Theory1066 Words à |à 5 PagesMany theories have interrelated theories and derive from one another. Marxist theory has connection with labeling theory and conflict theory. Marxist theory and conflict theory explains law and criminal justice but does not oversee multi-groups conflict of society (Akers 2017). Marxist theory is a sociological model which is based on conflict of classes (Akers 2017). Marx viewed the industrial society or capitalist society from a macro point of view. Marxism is also a conflict theory, believing thatRead MoreFunctionalism and Marxism: Sociological Perspectives Essay670 Words à |à 3 PagesSociological Concepts and Perspectives: Functionalism and Marxism In this essay I am going to compare and contrast Functionalism and Marxism. They are both sociological perspectives which have theories about society and the people that live within it. They attempt to explain how society influences people, and similarly how people influence society. However, the two perspectives are clearly different. Functionalism is a macro system theory which sees society as a mega structure of linked social institutionsRead MoreConflict Theory Essay1066 Words à |à 5 PagesConflict theory is a rather ambiguous theoretical example in sociological thinking. This theory was born in the 1950s by many sociologists like Lewis Coser and Ralf Dahrendorf. These sociologists and many others joined terms such as, phenomena of power, interests, coercion, and conflict to form this theory. In other words, Conflict theory is mainly about power divisions and class struggle lead to conflict. This theory plays an important role when it comes to sociological studies, since it provesRead MoreOutline and Assess Marxist Explanations of the Causes of Crime719 Words à |à 3 PagesMarxist explanations of the causes of crime (50 marks) It is to a large extent that Marxism is a useful theory in explaining the causes of crime. This is because it highlights the inequalities in society and how the ruling class owns the means of production. This fails to show reasons why not everyone is facing status frustration and lower income turn to crime. One way in which Marxism is a useful theory for explaining the causes of crime is the concept of capitalism, criminogenic capitalismRead MoreKarl Marx And The Communist Manifesto Essay1691 Words à |à 7 Pages(1820-1895), founded the Marxist Theory. Both men were philosophers, however were referred to as revolutionaries. ââ¬ËThe Communist Manifestoââ¬â¢, was written collaboratively by both Marx and Engels, as they explored the argument that ââ¬Å"history and progress can be seen dialectically as societies shift from one mode of production to anotherâ⬠. This will be argued through a contextual account of Marxism, its development, critiques, and both the dependency theory and critical theory. Marx closely analysed theRead Moreââ¬Å¡Ãâà ²Marxism Is No Longer Relevant to Our Understanding of Crime Deviance in Societyââ¬Å¡Ãâà ´1269 Words à |à 6 Pagesact seen as ââ¬Ëabnormalââ¬â¢ and going against the norms values o f Society, such as cross-dressing etc. Marx developed the idea of Marxism (a conflict theory between Upper and Lower social classes) in the 18th Century, when social classes were very clearly defined- the ââ¬ËBourgeoisââ¬â¢ and the ââ¬ËProletariatââ¬â¢. For this very reason, what is known as ââ¬ËTraditional Marxismââ¬â¢ is now quite evidently outdated, mainly due to the emergence of the ââ¬ËMiddle Classââ¬â¢ throughout the 20th Century and the ââ¬ËDigital Revolutionââ¬â¢Read MoreWhy Has Marxism Been Neglected For International Relations?977 Words à |à 4 PagesWhy has Marxism been neglected in International Relations? One of the major reasons why Marxism has generally been neglected in International Relations is due to the scarcity of Marxist writing that is specifically focused on this subject. However, it can be argued that due to this paucity of material, Marxist theory has nothing of substantial value to offer with regards to international relations. Non- Marxists argue that the concepts in Marxââ¬â¢s analysis of capitalist production; class, labor, exchange
Thursday, December 26, 2019
The War Of The European Powers - 1605 Words
Over the years America has gotten involved with many other countries. Countries where we have spread our beliefs and democracy. In doing so we have created many allies as well as enemies. Many people tend to disagree on when and where we get involved with foreign affairs. The US was very politically isolated from the world through the 19th century and into the 20th. This isolationist view of the 19th century can be seen through 1823 Monroe doctrine, In the wars of the European powers, in matters relating to themselves, we have never taken part, nor does it comport with our policy, so to do. Germanyââ¬â¢s submarine warfare and Zimmermanââ¬â¢s note shifted our view and got us involved in WWI. (ââ¬Å"U-S-History.comâ⬠) Today USA is a world super power and not nearly as isolated as we used to be. A foreign issue becomes an American issue when it threatens our security. This can be seen through the Cold War, global wars, cyber warfare, and terrorism. All of these issues show w hen we should get involved in the past and present. Firstly, the Cold War threatened our safety and security after WWII. After WWII the US finally thought they had peace at last. Meanwhile across the Atlantic, the rise of the ââ¬Å"Iron Curtainâ⬠was underway. The Iron Curtain is defined as, ââ¬Å"the ideological conflict and physical boundary dividing Europe into two separate areas from the end of World War II in 1945 until the end of the Cold War in 1991.â⬠(ââ¬Å"AmericanHistoryUSA.comâ⬠) Communist Russia continued to gain powerShow MoreRelatedA Comparison of World War I and World War II Essay examples527 Words à |à 3 PagesA Comparison of World War I and World War II World War I and World War II, while started by much of the same worldwide tensions, had drastically different results because of the much more destructive nature of World War II. Both world wars were started, ultimately, by nationalismRead MoreEurope s Influence On Western Europe1355 Words à |à 6 PagesWorld Wars, shared the same history. In another perspective, it was also sometimes referring to a region where countries shared the same value: capitalism and democracy. Throughout the history, because of difference events, the position of Western Europe in the world has also changed. Before 1914, due to the rapid development of the Enlightenment ideas and the industrialization in Britain and France, the world major powers centrally seated in Western Europe. However, as the Western European countriesRead MoreCauses of First World War Essay940 Words à |à 4 PagesIntroduction The First World War started in 1914 and lasted for four years to end in 1918 when Germany, Russia, Austria-Hungary and Ottoman empires were defeated (Havers 7). There have been a number of causes identified to have led to the war but most of them are not as straightforward as many would think. In essence, the root causes of the war are deeper than most abstract reasons many authors have identified in the past. However, this does not mean that there was no trail of events which directlyRead MoreThe Colonization Of Europeans Into The North America1555 Words à |à 7 PagesNew World. The colonization of Europeans into the North America had considerable impacts on the Native American lives. European empire at the time, such as the French, England and Spanish empires, often fought against each other for power and control. After the European tried to colonized, the Native American suddenly found themselves dealing with European power politics. The arrival of Europeans into the New World meant new political relationships for both the European and the Native Americans. EachRead MoreDefensive Foreign Policies865 Words à |à 4 Pagesforeign policy was primarily acts of neutrality and refusal to be involved with European affairs that came out of a defensive reaction to perceived threats from Europe. Two of these policies in include Washingtonââ¬â¢s Proclamation of Neutrality and the Monroe Doctrine. Both of these policies expressed the neutrality of the United States in European affairs and helped the new country to develop without the constant threat of war. President George Washington issued the Proclamation of Neutrality in 1793Read MoreWas the Outbreak of General War in 1914 Inevitable After the Assassination of Arch Duke Franz Ferdinand?1705 Words à |à 7 Pagesof general war in 1914 inevitable after the assassination of Arch Duke Franz Ferdinand? Various different factors led to the outbreak of the first World War- a war which incorporated all human, economic and military resources available to achieve total victory over the enemy. Roughly, the causes can be classified into long term (Franco-Prussian War, Imperialism, Alliance System, Anglo- German Naval Arms Race, etc.), short term (Morrocan Crisis, Agadir Crisis, Bosnian Crisis, Balkan Wars) and theRead MoreHow Isolationism Is A Part Of American Policy1602 Words à |à 7 PagesAddress in 1796 and lasting to the end of World War II. Factors like thousands of miles of sea between the US and Europe, fear of entangling alliances and a desire to remain autonomous contributed to the overall isolationist sentiment of many Americans. In addition, nativist sentiment has been present throughout American history as a product of isolationism and, among other factors, wage depression and fear of criminal behavior. During World War I, European countries were not only fighting with each otherRead MoreThe Greatest Single Cause Of The War Essay1741 Words à |à 7 Pagesââ¬ËThe greatest single cause of the war was the system of secret alliances which developed.ââ¬â¢ How far do you agree with this interpretation on what caused World War One. The first world war between the triple entente and the triple alliance is said to be the first modern war. A previously unseen number of human lives were lost on both sides and because of this when the war ended it came to be known as ââ¬Ëthe war to end all warsââ¬â¢ ââ¬â as said by the former president of the United States Woodrow Wilson.Read MoreWas World War 1 Inevitable?1737 Words à |à 7 PagesThe First World War has established an unforgettable memoir in the history books. World War 1 was a massacre of human life and an important event that determined the present state of the modern world. Yes, World War 1 was inevitable. The foundation of the causes of World War 1 can be traced back to several factors that were building up international tension to the ultimate result of war. In the 1900s, the European countries were extremely competitive in extending their influence around the worldRead MoreEssay on 1890 Europe As An Area of Growing Tension1326 Words à |à 6 Pag esAlliance, through wars and turbulence in Europe the eventual outcome was the outbreak of the first world war. The western powers expanded colonies. However, national rivalries gradually grew and alliance camps emerged. Economic competition and arms race also became intense. The Balkans became a hotpot of western intervention, as the Ottoman Empire declined. Finally war broke out in 1914, a war which was unexpectedly disastrous and destructive in scale. The war was caused by
Tuesday, December 17, 2019
English Paper - 1090 Words
Introduction: Dead manââ¬â¢s shoes written by David Evans; David was born and raised in South Africa, but after 5 years in prison for anti-apartheid activities, he moved from his hometown. The story is about recently widow Anne Bezuidenhout. Her husband of many years Piet Bezuidenhout had broken his neck at the Pampoenfontein gymkhana and was now dead. Anne was pleasant-faced with wide green eyes and had a flickering, charming and tantalizing smile. Most important, Anne was rich. She had ten thousand morgen fully paid for, fruitful lands and all the right equipment. Not to mention the hills well grassed to feed sheep and cattle even in bad times, the money that everyone knew was piling up in the bank, the brand new Saab cabriolet, theâ⬠¦show more contentâ⬠¦But Anne did not listen; she had Sam to protect her. A few months later Anne changed her mind and invited all 7 suitors back to her farm, but Anne wasnââ¬â¢t as expected waiting for them at the front porch. Only the sight of a pair muddy brown shoeââ¬â¢s met their eyes. The end of the story resembles Cinderella a lot. All of the suitors had to try on the pair of brown shoes, and the one who could fill t hem out would get Anne and all of her wealth. After none of the 7 suitors fitted the shoes, Sam is asked to try, and he slides into them, as if they were his own. Although Nelson Mandela recently had been elected as President of South Africa, there were still some significant differences between blacks and whites at the time this story was written. Therefore the suitors were quite shocked. Sam was just a Negro and not a good match for a woman like Anne. A few days later the teacher visited his shoemaker Josiah Meintjies to get a pair of boots repaired and he then shared the ââ¬Å"Cinderellaâ⬠story. ââ¬Å"Bad it might have been, but it was no miracle that those shoes fitted, because I made them for Sam Pitso. I made them in return for six pairs, which had belonged to the late Mr. Bezuidenheit and were to narrow for Samâ⬠. They had all been duped, but by who? One must take for granted that Anne has had a hand in. She had of course been able to recognize her deceased husbandââ¬â¢s shoes and must have known that the muddy brown pair did not ever belong toShow MoreRelatedPersonal Reflection Paper On English1015 Words à |à 5 Pages Reflection Paper English has never been my strong suit. I always hated English simply, because I never concerned myself as a writer. I always stuck to the bare minimum and was pleased to know that I passed. I honestly never tried hard in English because I never felt good enough. I did not see myself as a confident writer and I am not sure I ever will. Since, being enrolled in English 201, it supplied some challenges that I was not ready for and felt unsuited for. Along the way, I learnRead MoreEnglish Paper3249 Words à |à 13 PagesEnglish unit 4 17. Write answers in paragraphs in response to two of the following questions. Each answer should be approximately 200 words. Support your answer with specific references to Still Stands the House. Organize your ideas to express them clearly and coherently. a) The house is a dominant symbol that looms over Still Stands the House as if it were a character itself. What does the house symbolize? Support your answer with two references to the play. b) This play has several strong themesRead MoreGrammar Narrative Paper : English Language1131 Words à |à 5 PagesGrammar Narrative Paper As being the first Canadian-born daughter to my parents who have immigrated from India, I have encountered a lot of hardships towards my journey in learning the English language. Since childhood I have always been a quiet girl, who was always to shy to express what her thoughts had to share. I would never raise my hand in class to answer questions I knew answers of, nor be the first to talk in a conversation. Rather, I would convince myself that it was right to not talkRead MoreEnglish Paper1184 Words à |à 5 PagesEnglish 101 ââ¬Å"Dreams Converted to Realityâ⬠In ââ¬Å"The Symbolic Language of Dreamsâ⬠, Stephen King speaks in depth about his writing process. King has written over fifty novels and sold over three hundred and fifty thousand copies worldwide. Most of us cringe at the thought of re-living some of our worst nightmares, but thatââ¬â¢s not the case for novelist Stephen King. He uses his dreams and nightmares to sculpt his stories to his liking. King believes that dreams are the way our minds translateRead MoreEnglish Paper998 Words à |à 4 PagesAnalysis of the Missionaries Coming to Nigeria In the book Things Fall Apart, the author Chinua Achebe gives the reader a privileged insight into the life of the Ibo civilization. Morals and beliefs of the Ibo people were major factors that were pointed throughout the book in many ways. The Ibo civilization is very rich in tradition, culture, and religion before the missionaries came to convert them to Christianity. The missionaries overlooked these features, and compared them as savages. TheyRead MoreEnglish Paper1099 Words à |à 5 PagesIntroduction: Dead manââ¬â¢s shoes written by David Evans; David was born and raised in South Africa, but after 5 years in prison for anti-apartheid activities, he moved from his hometown. The story is about recently widow Anne Bezuidenhout. Her husband of many years Piet Bezuidenhout had broken his neck at the Pampoenfontein gymkhana and was now dead. Anne was pleasant-faced with wide green eyes and had a flickering, charming and tantalizing smile. Most important, Anne was rich. She had ten thousandRead MoreReaction Paper to Comprehension-Based Approach in English Language Teaching978 Words à |à 4 PagesCarlos Hilado Memorial State College Graduate School Talisay City, Negros Occidental, Philippines Subject : Current Trends in Teaching English Instructor: Mrs. Liezl May C. Tortogo Student: Adoracion Aileen Ayn E. Hilado Reaction to Comprehension Based Approach in Teaching Language A. Summary of Comprehension Based Approach The Comprehension Approach refers to several methodologies of language learning that emphasize understanding of language rather than speaking. It is a pedagogical/instructiveRead MoreReflection Paper In English1063 Words à |à 5 PagesEnglish is a terrible subject. We learn it the day we start school in kindergarten and all the way till the end of high school and possibly college. English composition is a completely unavoidable subject and not everyone likes learning about things such as grammar, writing, and reading comprehension. It is one of those subjects that many students just want to get it over with as quickly as possible. On the other hand, students need to realize the English composition classes offer a lot more benefitsRead MoreReflection Paper In English937 Words à |à 4 Pagesmuch as my brain capacity can endure is my ultimate goal in life. School is not just a chore, it is a necessity to further me into the future. English class, specifically the writing portio n has evolved my understanding of persuasive literature and how to explain my thoughts on paper for an audience to understand. Throughout the first semester of KCC English I have improved my essays from small to large mistakes. Overlooking my first draft of the Cause and Effect, I have realized I am growing as aRead MoreEnglish Reflection Paper1293 Words à |à 6 PagesSpeech. The English language has been hard for me to grasp. It still is today, in many ways. Of course, I have grown to love it and accept it, even indulge, in the challenge it presents. This did not come naturally, though. As a young child, I had a speech impediment. It was hard for me to make myself understood, even less so through my writing. Not only was it hard for me to write, but also to read. As a result, from the time I was four years old to the time I was nine years old, I worked with speech
Monday, December 9, 2019
Be true to thyself Essay Example For Students
Be true to thyself Essay ââ¬Å"I was looking for myself and asking everyone except myself questions which I, and only I, could answer.â⬠-The Invisible ManBe True to ThyselfMany people travel through life on a constant search on who there are and how they fit into this world. Some maneuver through situations and issues that they are faced with never being true to themselves, but more so modeling the behaviors of others. It is not until one defines their self-image, obtain a healthy amount of self-esteem, and confidence can they execute decisions concerning their lives. Until then, their actions are merely mimics or derivatives of the thoughts or beliefs of another. In Ralph Ellisonââ¬â¢s novel Invisible Man, the nameless protagonist does not possess a definite sense of self, which results in his living his life for others. Primarily, the invisible man emulates his life after other people. The first example of this is how he behaves like his grandfather. On his deathbed the invisible manââ¬â¢s grandfather tells him to ââ¬Å"to keep up the good fightâ⬠(Ellison16). Following this he was always doing what was right and was ââ¬Å"considered an example of desired conductââ¬âjust as his grandfather had beenâ⬠(Ellison 17). Once the invisible man goes off to college he begins to act in a manner to please Mr. Norton. Not only does Mr. Norton not identify with the invisible man racially, he views blacks as ââ¬Å"a mark on the scoreboard of his achievementâ⬠(Ellison 95). Despite these two facts the invisible man allows himself to be a ââ¬Å"do boyâ⬠by chauffeuring Mr. Norton to slave quarters. It is here that the protagonist can truly be identified as someone that is not in touch with himself because he sacrifices his education for a man that is not concerned about him or his race. Dr. Bledsoe tries to drive this concept into the invisible man when he tells him that ââ¬Å"the white folks tell everybody what to thinkâ⬠(Ellison 143). Dr. Bledsoe expels the invisible man from school, hoping that he will learn how to survive and develop an identity that suits him. After being expelled from school, the invisible man begins a journey to make a living for himself. He ends up in New York where he is introduced to ââ¬Å"The Brotherhoodâ⬠. ââ¬Å"The Brotherhoodâ⬠quickly gives him a place to live, a job with a reasonable salary, and petty cash to spend on clothing. He adopts their ideologies, mimics their way of life, and indulges himself in their literature. After going through a rigorous tutorial program the invisible man emerges brainwashed and still lacking an identity. Never making his own decisions, the invisible man becomes ââ¬Å"chief spokesman of the Harlem Districtâ⬠(Ellison 359) and finally begins to promote the ideas of ââ¬Å"The Bro therhoodâ⬠to the people of Harlem. Not knowing that ââ¬Å"The Brotherhoodâ⬠is using him to entice the people into following their doctrine and adopting their philosophies. He never decided where he would go or what cause he would speak against. He became a pawn for ââ¬Å"The Brotherhoodâ⬠. To them he was not an individual, but an inanimate object. Eventually the invisible man grows tired of ââ¬Å"The Brotherhoodâ⬠and their mannerisms. However, instead of trying to work on developing an identity, the invisible man begins to impersonate ââ¬Å"Rine the runner and Rine the gambler and Rine the briber and Rine the lover and Rinehart the Reverendâ⬠(Ellison 498). Wearing a large hat and glasses tinted a dark green, he moves about the street with greetings of ââ¬Å"Hey now!â⬠(Ellison 485) and ââ¬Å"daddy-oâ⬠(Ellison 484). He immerses himself into a youthful lifestyle with no prior knowledge of how it operates. His resemblance to Rinehart is advant ageous because it allows him to travel safely from place to place while in hiding from ââ¬Å"ââ¬Å"The Brotherhoodâ⬠â⬠. The invisible man moves through his life never really living for himself but for others. In addition, to adopting the behaviors expected of him, he also adopts the personalities of others. Both of these practices strengthen the idea that he is invisible ââ¬Å"simply because people refuse to seeâ⬠(Ellison 3) him because there really is not a concrete personality to see. Though the invisible man lives a life of emulation for some time, he eventually retreats from others to discover his identity. The invisible manââ¬â¢s first step to living a personally fulfilling life was realizing that his ââ¬Å"future lies chiefly in his own handsâ⬠(Vanzant 1/15). Consequently, if he does not know what to identify himself with he will not control his future. To have an established identity oneââ¬â¢s self-image, self-esteem and confidence must be asses sed and developed. Secondly he learns that ââ¬Å"identification with an organization or a cause is no substitute for self-realizationâ⬠(Vanzant4/29). He realizes that his relationship to ââ¬Å"The Brotherhoodâ⬠and his role in their activities was insignificant. He excepts the fact that he was not really a part of the group, but more so someone that ran errands. In addition, the invisible man discovers ââ¬Å"In the solitude of your mind are the answers to all your questions about life. You must take the time to ask and listenâ⬠(Vanzant 1/17). This is seen when he says ââ¬Å"I was looking for myself and asking everyone except myself questions which I, and only I, could answer.â⬠(Ellison 15). Taking time to think about morals, values and basic characteristics can prove useful in determining the qualities, which a person would like to exemplify. Knowing what he stands for will allow him to make better judgments in the future. In due time, he will begin to make judgments based on what his morals, ideas, and values reflect. ââ¬Å"Nothing can dim the light which shines from withinâ⬠(Vanzant 2/5), when you have a positive self-image you exude a confidence that surpasses even the most negative comments and corrupted situations. The invisible man begins to look at himself positivelyââ¬Å"We must not wish to be anything but what we, are and to be that perfectlyâ⬠(Vanzant 1/7). When we are satisfied with whom we are then we can begin to accomplish things. As the invisible manââ¬â¢s self-esteem increases so does his self-confidence. When someone begins to construct who they are they must realize that ââ¬Å"If you have no confidence in self, you are twice defeated in the race of life. With no confidence, you have won even before you have startedâ⬠(Vanzant 2/7). The invisible man develops a self-definition, which makes him ââ¬Å"visibleâ⬠to others. .u37c94fc5816380735f9fd64fdee14c5c , .u37c94fc5816380735f9fd64fdee14c5c .postImageUrl , .u37c94fc5816380735f9fd64fdee14c5c .centered-text-area { min-height: 80px; position: relative; } .u37c94fc5816380735f9fd64fdee14c5c , .u37c94fc5816380735f9fd64fdee14c5c:hover , .u37c94fc5816380735f9fd64fdee14c5c:visited , .u37c94fc5816380735f9fd64fdee14c5c:active { border:0!important; } .u37c94fc5816380735f9fd64fdee14c5c .clearfix:after { content: ""; display: table; clear: both; } .u37c94fc5816380735f9fd64fdee14c5c { display: block; transition: background-color 250ms; webkit-transition: background-color 250ms; width: 100%; opacity: 1; transition: opacity 250ms; webkit-transition: opacity 250ms; background-color: #95A5A6; } .u37c94fc5816380735f9fd64fdee14c5c:active , .u37c94fc5816380735f9fd64fdee14c5c:hover { opacity: 1; transition: opacity 250ms; webkit-transition: opacity 250ms; background-color: #2C3E50; } .u37c94fc5816380735f9fd64fdee14c5c .centered-text-area { width: 100%; position: relative ; } .u37c94fc5816380735f9fd64fdee14c5c .ctaText { border-bottom: 0 solid #fff; color: #2980B9; font-size: 16px; font-weight: bold; margin: 0; padding: 0; text-decoration: underline; } .u37c94fc5816380735f9fd64fdee14c5c .postTitle { color: #FFFFFF; font-size: 16px; font-weight: 600; margin: 0; padding: 0; width: 100%; } .u37c94fc5816380735f9fd64fdee14c5c .ctaButton { background-color: #7F8C8D!important; color: #2980B9; border: none; border-radius: 3px; box-shadow: none; font-size: 14px; font-weight: bold; line-height: 26px; moz-border-radius: 3px; text-align: center; text-decoration: none; text-shadow: none; width: 80px; min-height: 80px; background: url(https://artscolumbia.org/wp-content/plugins/intelly-related-posts/assets/images/simple-arrow.png)no-repeat; position: absolute; right: 0; top: 0; } .u37c94fc5816380735f9fd64fdee14c5c:hover .ctaButton { background-color: #34495E!important; } .u37c94fc5816380735f9fd64fdee14c5c .centered-text { display: table; height: 80px; padding-left : 18px; top: 0; } .u37c94fc5816380735f9fd64fdee14c5c .u37c94fc5816380735f9fd64fdee14c5c-content { display: table-cell; margin: 0; padding: 0; padding-right: 108px; position: relative; vertical-align: middle; width: 100%; } .u37c94fc5816380735f9fd64fdee14c5c:after { content: ""; display: block; clear: both; } READ: Star Traveling To The Millennium EssayFurthermore, retreating underground was the best decision the invisible man made. Underground is where he finally realizes that he has no identity ââ¬Å"is the way it has always beenâ⬠(Ellison 566) and that his life was merely a farce. He realizes that other people controlled his whole life: from his grandfatherââ¬â¢s death; to driving Mr. Norton; to being expelled from college by Dr. Bledsoe; to being a member of ââ¬Å" ââ¬Å"The Brotherhoodâ⬠. He understands that he was never given a chance to think for himself and develop an identity befitting him: My problem was that I always tried to go in everyoneââ¬â¢s way bu t my own. I have also been called one thing and then another while no one really wished to hear what I called myself. So after many years of trying to adopt the opinion of others I finally rebelled. (Ellison 573)After years and years of portraying others thoughts and beliefs he accepts ââ¬Å"That I am nobody but myself.â⬠(Ellison 15). It took him years to understand that some people live their whole life never knowing who they are and he was one of those people. Happy and content with his subterraneous lifestyle the invisible man begins to live a life true to himself. Invisible Man is a dynamic novel that many people can relate to today. Myriads of people are on a continuous search for their identity and purpose. This process has been conquered by some; however, many never discover or develop to their full potential. The lesson of this novel, however, is that seeking a strong self-definition is essential, while keeping in mind to not let outside agents determine that definition. This novel is one that I would recommend to all of my friends because while following the path that the invisible man takes to self-discover, I realized that many of us are on the same trail of discovery. Invisible Man highlights and emphasizes the significance in having a strong self-identity to live a productive and satisfying life.
Monday, December 2, 2019
Street Art
Street Art- Visual Arts Essay The visual arts are created based on ones influences and inspirations that surround them. Its a form of expression for most artists as this is how they communicate feelings without directly speaking them. Some artists practice is so powerful, it shapes and effects significant events in society. This is achieved by inspiring the audience who may change their mind about a certain issue or encourage the audience to embrace and support a significant issue/event/cause. Well renowned artists, Barbara Kruger and Jean-Michel Basque, are prime examples of artists whos practices in the visual arts have either shaped or been heaped by certain events throughout their life, Whether it be in their private lives or events occurring publicly that has an impact on a majority of people. The Barbara Kruger is an American conceptual/pop artist whose works focus mainly on feminism and the social and political stance of things. We will write a custom essay on Street Art- Visual Arts specifically for you for only $16.38 $13.9/page Order now She takes images from the mass media and pastes big, bold extracts over them such as aphorisms, questions and slogans, both meaningful and eye catching. Her images sometimes make you look twice to try and fully interpret what the text may mean as opposed to the picture and what she is trying to convey to the audience. Gougers artworks have definitely been shaped by events that have taken place and by the ways to elite back in the day, when females had a lot of restriction. Kruger being a feminist has always been against that and this is what inspires her to produce such truthful and powerful images. She has produced several artworks that are inspired by natural life experiences that every human shares and in life such as love (everybody can relate and this has been a prime factor influence that shape how many artists work, its inspiring, confusing, good and bad) as well as the problems of co-existence. These are uncontrollable in nature, they just occur. Other controlled experiences and ways of life are that Of consumerism, conformity and the female condition back in those days. These are all present in Think like us, look like us, Your body is a battleground, and love for sale by Barbara Kruger. Barbara Krueger artworks are created to either agree or oppose the way people think life should be and the rules that must be abided by. On the other hand Jean-Michel Bassists work deals with a completely different art scene but has had a great impact on society and events as does Barbara Gougers, He was a gritty, street-smart graffiti artist before his drug overdose, who focused on suggestive dichotomies such as wealth versus poverty, integration versus segregation and inner versus outer experience. His art practice was shaped by the traumatic events he went through as a child growing up, including having abusive parents and a suicidal mother, which then lead him to a troubled adulthood as well. He expresses this tonally in his works, however. Although his art career was brief, Jean-Michel Basque has been credited with bringing the African-American and Latino experience in the elite art world. He didnt want the black people and white people to be separated because of their color. He expresses his views on how the blacks were seen by painting El Grand Speculator (History of Black People). It was executed at the height of his artistic maturity before the urban energy on the streets of new York had been distorted by the artworks success and stardom. Its inspired by the Obvious events that took place in the asss towards the black people. The racism and criticism. These vents shaped his way of thinking and therefore hue also shaped his take on art and the artworks he makes. The events that a person experiences in their life can be enough to change them and for the artists, this may have an impact on their practices in the visual arts but it is not always a bad thing. From creating inspirational yet truthful art, sometimes that art may shape the events instead, it may shape the outside world. And how people view certain aspects of life, There is a lot that can change how an artist expresses themselves but then again there is a lot their art can change.
Subscribe to:
Posts (Atom)