JTSEC1333

Anonymous JTSEC #OpSudan Full Recon #1

Sep 13th, 2019
1,358
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 225.78 KB | None | 0 0
  1. #######################################################################################################################################
  2. =======================================================================================================================================
  3. Hostname hcsp.gov.sd ISP Krystal Hosting Ltd
  4. Continent Europe Flag
  5. GB
  6. Country United Kingdom Country Code GB
  7. Region Unknown Local time 13 Sep 2019 14:55 BST
  8. City Unknown Postal Code Unknown
  9. IP Address 77.72.0.138 Latitude 51.496
  10. Longitude -0.122
  11. =======================================================================================================================================
  12. #######################################################################################################################################
  13. > hcsp.gov.sd
  14. Server: 38.132.106.139
  15. Address: 38.132.106.139#53
  16.  
  17. Non-authoritative answer:
  18. Name: hcsp.gov.sd
  19. Address: 77.72.0.138
  20. >
  21. #######################################################################################################################################
  22. [+] Target : hcsp.gov.sd
  23.  
  24. [+] IP Address : 77.72.0.138
  25.  
  26. [+] Headers :
  27.  
  28. [+] Cache-Control : private, no-cache, no-store, must-revalidate, max-age=0
  29. [+] Pragma : no-cache
  30. [+] Content-Type : text/html
  31. [+] Content-Length : 1139
  32. [+] Date : Fri, 13 Sep 2019 14:07:59 GMT
  33. [+] Server : LiteSpeed
  34. [+] Vary : User-Agent
  35. [+] Connection : Keep-Alive
  36.  
  37. [+] SSL Certificate Information :
  38.  
  39. [+] commonName : hcsp.gov.sd
  40. [+] countryName : US
  41. [+] organizationName : Let's Encrypt
  42. [+] commonName : Let's Encrypt Authority X3
  43. [+] Version : 3
  44. [+] Serial Number : 03615E55E0EA4385A6FBD457225E62CBB106
  45. [+] Not Before : Aug 21 09:17:32 2019 GMT
  46. [+] Not After : Nov 19 09:17:32 2019 GMT
  47. [+] OCSP : ('http://ocsp.int-x3.letsencrypt.org',)
  48. [+] subject Alt Name : (('DNS', 'hcsp.gov.sd'), ('DNS', 'www.hcsp.gov.sd'))
  49. [+] CA Issuers : ('http://cert.int-x3.letsencrypt.org/',)
  50.  
  51. [+] Whois Lookup :
  52.  
  53. [+] NIR : None
  54. [+] ASN Registry : ripencc
  55. [+] ASN : 12488
  56. [+] ASN CIDR : 77.72.0.0/21
  57. [+] ASN Country Code : GB
  58. [+] ASN Date : 2007-01-15
  59. [+] ASN Description : KRYSTAL, GR
  60. [+] cidr : 77.72.0.0/23
  61. [+] name : KRYSTAL
  62. [+] handle : KNOC3-RIPE
  63. [+] range : 77.72.0.0 - 77.72.1.255
  64. [+] description : Krystal Hosting
  65. [+] country : GB
  66. [+] state : None
  67. [+] city : None
  68. [+] address : Alta Vista, Hr Warberry Rd, Torquay, Devon, TQ1 1SD
  69. [+] postal_code : None
  70. [+] emails : None
  71. [+] created : 2007-03-16T13:09:35Z
  72. [+] updated : 2014-06-11T20:51:33Z
  73.  
  74. [+] Crawling Target...
  75.  
  76. [+] Looking for robots.txt........[ Found ]
  77. [+] Extracting robots Links.......[ 0 ]
  78. [+] Looking for sitemap.xml.......[ Found ]
  79. [+] Extracting sitemap Links......[ 0 ]
  80. [+] Extracting CSS Links..........[ 1 ]
  81. [+] Extracting Javascript Links...[ 1 ]
  82. [+] Extracting Internal Links.....[ 0 ]
  83. [+] Extracting External Links.....[ 0 ]
  84. [+] Extracting Images.............[ 0 ]
  85.  
  86. [+] Total Links Extracted : 2
  87.  
  88. [+] Dumping Links in /opt/FinalRecon/dumps/hcsp.gov.sd.dump
  89. [+] Completed!
  90. #######################################################################################################################################
  91.  
  92. [+] Starting At 2019-09-13 10:08:12.395237
  93. [+] Collecting Information On: https://hcsp.gov.sd/
  94. [#] Status: 200
  95. --------------------------------------------------
  96. [#] Web Server Detected: LiteSpeed
  97. [!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
  98. - Content-Type: text/html; charset=UTF-8
  99. - Content-Length: 822
  100. - Content-Encoding: gzip
  101. - Vary: Accept-Encoding,User-Agent
  102. - Date: Fri, 13 Sep 2019 14:08:05 GMT
  103. - Server: LiteSpeed
  104. - Alt-Svc: quic=":8887"; ma=2592000; v="35,39,43,44"
  105. - Connection: Keep-Alive
  106. --------------------------------------------------
  107. [#] Finding Location..!
  108. [#] as: AS12488 Krystal Hosting Ltd
  109. [#] city: Torquay
  110. [#] country: United Kingdom
  111. [#] countryCode: GB
  112. [#] isp: Krystal Hosting Ltd
  113. [#] lat: 50.4659
  114. [#] lon: -3.51632
  115. [#] org:
  116. [#] query: 77.72.0.138
  117. [#] region: ENG
  118. [#] regionName: England
  119. [#] status: success
  120. [#] timezone: Europe/London
  121. [#] zip: TQ2
  122. --------------------------------------------------
  123. [x] Didn't Detect WAF Presence on: https://hcsp.gov.sd/
  124. --------------------------------------------------
  125. [#] Starting Reverse DNS
  126. [!] Found 30 any Domain
  127. - aes.edu.sd
  128. - alsahafasd.com
  129. - artsbeat.blogs.nytimes.com
  130. - atsocialmedia.co.uk
  131. - cowdenbeathnews.com
  132. - crypto.moneyisinthelist.com
  133. - deliveringyourfuture.co.uk
  134. - faktor.life
  135. - foeaau.com
  136. - goansport.net
  137. - hcsp.gov.sd
  138. - honeyvilleresources.com
  139. - jcointoken.info
  140. - kambalgroup.com.sd
  141. - mis-hosting.org
  142. - ncmhp.gov.sd
  143. - ptwebs.com
  144. - sdmrc.co.uk
  145. - sudabest.net
  146. - sudanson.com
  147. - tanzaniawebexperts.com
  148. - the-sixteen.org.uk
  149. - tpsigns.co.uk
  150. - vremeplov.online
  151. - www.hcsp.gov.sd
  152. - www.notalone.org.sd
  153. - www.our-world.net
  154. - www.robloxhackforfree.com
  155. - www.rostrvm.com
  156. - xnovosti.com
  157. --------------------------------------------------
  158. [!] Scanning Open Port
  159. [#] 21/tcp open ftp
  160. [#] 22/tcp open ssh
  161. [#] 26/tcp open rsftp
  162. [#] 80/tcp open http
  163. [#] 110/tcp open pop3
  164. [#] 143/tcp open imap
  165. [#] 443/tcp open https
  166. [#] 587/tcp open submission
  167. [#] 3306/tcp open mysql
  168. --------------------------------------------------
  169. [+] Collecting Information Disclosure!
  170. [#] Detecting sitemap.xml file
  171. [!] sitemap.xml File Found: https://hcsp.gov.sd//sitemap.xml
  172. [#] Detecting robots.txt file
  173. [!] robots.txt File Found: https://hcsp.gov.sd//robots.txt
  174. [#] Detecting GNU Mailman
  175. [!] GNU Mailman App Detected: https://hcsp.gov.sd//mailman/admin
  176. [!] version: 2.1.27
  177. --------------------------------------------------
  178. [+] Crawling Url Parameter On: https://hcsp.gov.sd/
  179. --------------------------------------------------
  180. [#] Searching Html Form !
  181. [+] Html Form Discovered
  182. [#] action:
  183. [#] class: None
  184. [#] id: None
  185. [#] method: POST
  186. --------------------------------------------------
  187. [-] No DOM Paramter Found!?
  188. --------------------------------------------------
  189. [-] No internal Dynamic Parameter Found!?
  190. --------------------------------------------------
  191. [-] No external Dynamic Paramter Found!?
  192. --------------------------------------------------
  193. [-] No Internal Link Found!?
  194. --------------------------------------------------
  195. [-] No External Link Found!?
  196. --------------------------------------------------
  197. [#] Mapping Subdomain..
  198. [!] Found 1 Subdomain
  199. - hcsp.gov.sd
  200. --------------------------------------------------
  201. [!] Done At 2019-09-13 10:08:28.428112
  202. #######################################################################################################################################
  203. [i] Scanning Site: https://hcsp.gov.sd
  204.  
  205.  
  206.  
  207. B A S I C I N F O
  208. ====================
  209.  
  210.  
  211. [+] Site Title: Unauthorized Access
  212. [+] IP address: 77.72.0.138
  213. [+] Web Server: LiteSpeed
  214. [+] CMS: Could Not Detect
  215. [+] Cloudflare: Not Detected
  216. [+] Robots File: Found
  217.  
  218. -------------[ contents ]----------------
  219. <!doctype html>
  220. <html lang="en">
  221. <head>
  222. <title>Unauthorized Access</title>
  223. <meta charset="UTF-8">
  224. <script src="https://www.google.com/recaptcha/api.js" async defer></script>
  225. <link rel='stylesheet' href='https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.css'>
  226. </head>
  227. <body>
  228.  
  229. <div class="container-fluid">
  230. <div class="alert alert-warning"><h2>The firewall on this server is blocking your connection.</h2></div>
  231. <p>If you are the website owner you can log into your client area to find out why your IP address is being blocked.</p>
  232. <p>Your blocked IP address is: <b>176.113.74.28</b></p>
  233. <p>The hostname of this server is: <b>sulfur.cloudhosting.co.uk</b></p>
  234.  
  235. <br />
  236. <p>You can try to unblock yourself using ReCAPTCHA:</p>
  237.  
  238. <form action="" method="POST">
  239. <div class="row">
  240. <div class="col-md-4 col-md-offset-4">
  241. <div class="panel panel-default">
  242. <div class="panel-body">
  243. <div class="g-recaptcha" data-sitekey="6LejdkMUAAAAACWoEXveaAxFvpfYbLjmTwqCyjKE"></div>
  244. </div>
  245. <div class="panel-footer text-center">
  246. <button class='btn btn-primary' type="submit" name="submit">Unblock</button>
  247. </div>
  248. </div>
  249. </div>
  250. </div>
  251. </form>
  252.  
  253. <br />
  254.  
  255. <div class="alert alert-info">Please note: Not all unblock requests will be successful as it is dependent on how your IP address is being blocked. If the unblock fails you will need to contact the server owner or hosting provider for further information.</div>
  256. </div>
  257. </body>
  258. </html>
  259.  
  260. -----------[end of contents]-------------
  261.  
  262.  
  263.  
  264. W H O I S L O O K U P
  265. ========================
  266.  
  267. error check your api query
  268.  
  269.  
  270.  
  271. G E O I P L O O K U P
  272. =========================
  273.  
  274. [i] IP Address: 77.72.0.138
  275. [i] Country: United Kingdom
  276. [i] State:
  277. [i] City:
  278. [i] Latitude: 51.4964
  279. [i] Longitude: -0.1224
  280.  
  281.  
  282.  
  283.  
  284. H T T P H E A D E R S
  285. =======================
  286.  
  287.  
  288. [i] HTTP/1.0 200 OK
  289. [i] Content-Type: text/html; charset=UTF-8
  290. [i] Content-Length: 1493
  291. [i] Date: Fri, 13 Sep 2019 14:07:59 GMT
  292. [i] Server: LiteSpeed
  293. [i] Vary: User-Agent
  294. [i] Alt-Svc: quic=":8887"; ma=2592000; v="35,39,43,44"
  295. [i] Connection: close
  296.  
  297.  
  298.  
  299.  
  300. D N S L O O K U P
  301. ===================
  302.  
  303. hcsp.gov.sd. 14399 IN A 77.72.0.138
  304. hcsp.gov.sd. 21599 IN NS ns2.cloudhosting.co.uk.
  305. hcsp.gov.sd. 21599 IN NS ns1.cloudhosting.co.uk.
  306. hcsp.gov.sd. 21599 IN SOA ns1.cloudhosting.co.uk. admin.krystal.co.uk. 2017071310 3600 7200 1209600 86400
  307. hcsp.gov.sd. 3599 IN MX 20 mx2.cloudhosting.co.uk.
  308. hcsp.gov.sd. 3599 IN MX 10 mx1.cloudhosting.co.uk.
  309. hcsp.gov.sd. 14399 IN TXT "v=spf1 ip4:77.72.0.138 ip4:31.216.48.18 ip4:209.140.18.28 +a +mx +ip4:69.73.182.173 ?all"
  310.  
  311.  
  312.  
  313.  
  314. S U B N E T C A L C U L A T I O N
  315. ====================================
  316.  
  317. Address = 77.72.0.138
  318. Network = 77.72.0.138 / 32
  319. Netmask = 255.255.255.255
  320. Broadcast = not needed on Point-to-Point links
  321. Wildcard Mask = 0.0.0.0
  322. Hosts Bits = 0
  323. Max. Hosts = 1 (2^0 - 0)
  324. Host Range = { 77.72.0.138 - 77.72.0.138 }
  325.  
  326.  
  327.  
  328. N M A P P O R T S C A N
  329. ============================
  330.  
  331. Starting Nmap 7.70 ( https://nmap.org ) at 2019-09-13 14:08 UTC
  332. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  333. Host is up (0.079s latency).
  334. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  335.  
  336. PORT STATE SERVICE
  337. 21/tcp open ftp
  338. 22/tcp filtered ssh
  339. 23/tcp filtered telnet
  340. 80/tcp open http
  341. 110/tcp open pop3
  342. 143/tcp open imap
  343. 443/tcp open https
  344. 3389/tcp filtered ms-wbt-server
  345.  
  346. Nmap done: 1 IP address (1 host up) scanned in 2.01 seconds
  347.  
  348.  
  349. #######################################################################################################################################
  350. Trying "hcsp.gov.sd"
  351. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 11325
  352. ;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 2, ADDITIONAL: 2
  353.  
  354. ;; QUESTION SECTION:
  355. ;hcsp.gov.sd. IN ANY
  356.  
  357. ;; ANSWER SECTION:
  358. hcsp.gov.sd. 14400 IN TXT "v=spf1 ip4:77.72.0.138 ip4:31.216.48.18 ip4:209.140.18.28 +a +mx +ip4:69.73.182.173 ?all"
  359. hcsp.gov.sd. 3600 IN MX 10 mx1.cloudhosting.co.uk.
  360. hcsp.gov.sd. 3600 IN MX 20 mx2.cloudhosting.co.uk.
  361. hcsp.gov.sd. 43200 IN SOA ns1.cloudhosting.co.uk. admin.krystal.co.uk. 2017071310 3600 7200 1209600 86400
  362. hcsp.gov.sd. 14400 IN A 77.72.0.138
  363. hcsp.gov.sd. 14400 IN NS ns2.cloudhosting.co.uk.
  364. hcsp.gov.sd. 14400 IN NS ns1.cloudhosting.co.uk.
  365.  
  366. ;; AUTHORITY SECTION:
  367. hcsp.gov.sd. 14400 IN NS ns1.cloudhosting.co.uk.
  368. hcsp.gov.sd. 14400 IN NS ns2.cloudhosting.co.uk.
  369.  
  370. ;; ADDITIONAL SECTION:
  371. ns2.cloudhosting.co.uk. 36413 IN A 139.162.254.53
  372. ns1.cloudhosting.co.uk. 36413 IN A 77.72.0.13
  373.  
  374. Received 350 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 468 ms
  375. #######################################################################################################################################
  376.  
  377. ; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace hcsp.gov.sd
  378. ;; global options: +cmd
  379. . 81412 IN NS f.root-servers.net.
  380. . 81412 IN NS g.root-servers.net.
  381. . 81412 IN NS h.root-servers.net.
  382. . 81412 IN NS j.root-servers.net.
  383. . 81412 IN NS k.root-servers.net.
  384. . 81412 IN NS m.root-servers.net.
  385. . 81412 IN NS a.root-servers.net.
  386. . 81412 IN NS i.root-servers.net.
  387. . 81412 IN NS e.root-servers.net.
  388. . 81412 IN NS c.root-servers.net.
  389. . 81412 IN NS b.root-servers.net.
  390. . 81412 IN NS d.root-servers.net.
  391. . 81412 IN NS l.root-servers.net.
  392. . 81412 IN RRSIG NS 8 0 518400 20190926050000 20190913040000 59944 . EapAez+sQzkXnLpDiSfmjWxXJHgRKh8m0HbUT5qbKPYJD7U3wk2cLr9T rwZfVO8a8lyJCiYxzw5ytrSVECXKcQ9kvAVDjQ25Nmd35LGAckBd5Ids sexmr944gX+skSd6Dd3RvsXauGhfuNLH5C+Kx/SG4f3835e1Bq6POZsZ N98JlAtXnzovlsAzqUIV1WC7bvRpM5KKAH8QBqTwdTpZI+wPCtukOl4g 9vGtdRmAzoMpUuhAXkPCFt2Vd3tzXJuy+60FAY4BgTwCHyxzZxtk54Yy 9uDevwuzLywuSkuoD4Or1LiO1jUPblisng12sBQGV2t43kp7Qn7cpN00 N7y26Q==
  393. ;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 28 ms
  394.  
  395. sd. 172800 IN NS ans1.canar.sd.
  396. sd. 172800 IN NS ns2.uaenic.ae.
  397. sd. 172800 IN NS ans2.canar.sd.
  398. sd. 172800 IN NS ns-sd.afrinic.net.
  399. sd. 172800 IN NS sd.cctld.authdns.ripe.net.
  400. sd. 172800 IN NS ns1.uaenic.ae.
  401. sd. 172800 IN NS ans1.sis.sd.
  402. sd. 86400 IN NSEC se. NS RRSIG NSEC
  403. sd. 86400 IN RRSIG NSEC 8 1 86400 20190926050000 20190913040000 59944 . ZKos6Gf62cxqAFjrzXAHO8X8M/G7Q/LpjBFrYTBkLRlMVEpFAJjfBoJP h8EYeZOFRxareV09sSD7CH00khHR2y/6OXxPb9cDK7PPikmz8eJCCdnI BbHD+lg4YqePUkfzoocT20j5KKhKGJSZlcg28WhCYIUDdBzQYlaFYdMU X2quTEiXgpcx8znoulDWRdxmxdEnpp1PIOYgMuiYhZlkx0heO1jN9lZ+ UCB2zaOQv1Y3FjcRDRpMx7fMqGH0hPlepU8uhwOioeA256mx7t2SPdyY 8JwKxhChgwh9duplAxLlH7pckqA28Yu1011Cl8mtzVfBUWyoqT2ZT6Pz fHGEbQ==
  404. ;; Received 726 bytes from 2001:500:12::d0d#53(g.root-servers.net) in 60 ms
  405.  
  406. gov.sd. 14400 IN NS sd.cctld.authdns.ripe.net.
  407. gov.sd. 14400 IN NS ns1.uaenic.ae.
  408. gov.sd. 14400 IN NS ns2.uaenic.ae.
  409. gov.sd. 14400 IN NS ans1.sis.sd.
  410. gov.sd. 14400 IN NS ans1.canar.sd.
  411. gov.sd. 14400 IN NS ans2.canar.sd.
  412. gov.sd. 14400 IN NS ns-sd.afrinic.net.
  413. ;; Received 267 bytes from 2001:43f8:120::26#53(ns-sd.afrinic.net) in 262 ms
  414.  
  415. ;; Received 68 bytes from 213.42.0.226#53(ns1.uaenic.ae) in 217 ms
  416. #######################################################################################################################################
  417. [*] Performing General Enumeration of Domain: hcsp.gov.sd
  418. [-] DNSSEC is not configured for hcsp.gov.sd
  419. [*] SOA ns1.cloudhosting.co.uk 77.72.0.13
  420. [*] NS dns1.sudabest.net 77.72.0.13
  421. [*] Bind Version for 77.72.0.13 PowerDNS Authoritative Server 4.1.5 (built Nov 28 2018 11:44:40 by [email protected])
  422. [*] NS dns2.sudabest.net 139.162.254.53
  423. [*] Bind Version for 139.162.254.53
  424. [*] MX mx2.cloudhosting.co.uk 77.72.5.97
  425. [*] MX mx2.cloudhosting.co.uk 77.72.5.10
  426. [*] MX mx1.cloudhosting.co.uk 77.72.6.25
  427. [*] MX mx1.cloudhosting.co.uk 77.72.6.24
  428. [*] A hcsp.gov.sd 77.72.0.138
  429. [*] TXT hcsp.gov.sd v=spf1 ip4:77.72.0.138 ip4:31.216.48.18 ip4:209.140.18.28 +a +mx +ip4:69.73.182.173 ?all
  430. [*] Enumerating SRV Records
  431. [-] No SRV Records Found for hcsp.gov.sd
  432. [+] 0 Records Found
  433. #######################################################################################################################################
  434. [*] Processing domain hcsp.gov.sd
  435. [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  436. [+] Getting nameservers
  437. 77.72.0.13 - dns1.sudabest.net
  438. 139.162.254.53 - dns2.sudabest.net
  439. [-] Zone transfer failed
  440.  
  441. [+] TXT records found
  442. "v=spf1 ip4:77.72.0.138 ip4:31.216.48.18 ip4:209.140.18.28 +a +mx +ip4:69.73.182.173 ?all"
  443.  
  444. [+] MX records found, added to target list
  445. 20 mx2.cloudhosting.co.uk.
  446. 10 mx1.cloudhosting.co.uk.
  447.  
  448. [*] Scanning hcsp.gov.sd for A records
  449. 77.72.0.138 - hcsp.gov.sd
  450. 77.72.0.138 - cpanel.hcsp.gov.sd
  451. 77.72.0.138 - ftp.hcsp.gov.sd
  452. 127.0.0.1 - localhost.hcsp.gov.sd
  453. 77.72.0.138 - mail.hcsp.gov.sd
  454. 77.72.0.138 - webmail.hcsp.gov.sd
  455. 77.72.0.138 - webdisk.hcsp.gov.sd
  456. 77.72.0.138 - whm.hcsp.gov.sd
  457. 77.72.0.138 - www.hcsp.gov.sd
  458. #######################################################################################################################################
  459.  
  460. AVAILABLE PLUGINS
  461. -----------------
  462.  
  463. SessionRenegotiationPlugin
  464. OpenSslCcsInjectionPlugin
  465. SessionResumptionPlugin
  466. HttpHeadersPlugin
  467. EarlyDataPlugin
  468. CertificateInfoPlugin
  469. CompressionPlugin
  470. RobotPlugin
  471. OpenSslCipherSuitesPlugin
  472. HeartbleedPlugin
  473. FallbackScsvPlugin
  474.  
  475.  
  476.  
  477. CHECKING HOST(S) AVAILABILITY
  478. -----------------------------
  479.  
  480. 77.72.0.138:443 => 77.72.0.138
  481.  
  482.  
  483.  
  484.  
  485. SCAN RESULTS FOR 77.72.0.138:443 - 77.72.0.138
  486. ----------------------------------------------
  487.  
  488. * Downgrade Attacks:
  489. TLS_FALLBACK_SCSV: OK - Supported
  490.  
  491. * TLS 1.2 Session Resumption Support:
  492. With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
  493. With TLS Tickets: OK - Supported
  494.  
  495. * Session Renegotiation:
  496. Client-initiated Renegotiation: OK - Rejected
  497. Secure Renegotiation: OK - Supported
  498.  
  499. * OpenSSL CCS Injection:
  500. OK - Not vulnerable to OpenSSL CCS injection
  501.  
  502. * Certificate Information:
  503. Content
  504. SHA1 Fingerprint: b449e2508a8d9586e69b770b0ef8250e493e0b0f
  505. Common Name: *.cloudhosting.co.uk
  506. Issuer: COMODO RSA Domain Validation Secure Server CA
  507. Serial Number: 58203438259768559198525576048403348949
  508. Not Before: 2018-11-03 00:00:00
  509. Not After: 2020-11-02 23:59:59
  510. Signature Algorithm: sha256
  511. Public Key Algorithm: RSA
  512. Key Size: 2048
  513. Exponent: 65537 (0x10001)
  514. DNS Subject Alternative Names: ['*.cloudhosting.co.uk', 'cloudhosting.co.uk']
  515.  
  516. Trust
  517. Hostname Validation: FAILED - Certificate does NOT match 77.72.0.138
  518. Android CA Store (9.0.0_r9): OK - Certificate is trusted
  519. Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
  520. Java CA Store (jdk-12.0.1): OK - Certificate is trusted
  521. Mozilla CA Store (2019-03-14): OK - Certificate is trusted
  522. Windows CA Store (2019-05-27): OK - Certificate is trusted
  523. Symantec 2018 Deprecation: WARNING: Certificate distrusted by Google and Mozilla on September 2018
  524. Received Chain: *.cloudhosting.co.uk --> COMODO RSA Domain Validation Secure Server CA --> COMODO RSA Certification Authority
  525. Verified Chain: *.cloudhosting.co.uk --> COMODO RSA Domain Validation Secure Server CA --> COMODO RSA Certification Authority
  526. Received Chain Contains Anchor: OK - Anchor certificate not sent
  527. Received Chain Order: OK - Order is valid
  528. Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
  529.  
  530. Extensions
  531. OCSP Must-Staple: NOT SUPPORTED - Extension not found
  532. Certificate Transparency: OK - 3 SCTs included
  533.  
  534. OCSP Stapling
  535. NOT SUPPORTED - Server did not send back an OCSP response
  536.  
  537. * SSLV2 Cipher Suites:
  538. Server rejected all cipher suites.
  539.  
  540. * SSLV3 Cipher Suites:
  541. Server rejected all cipher suites.
  542. Undefined - An unexpected error happened:
  543. TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA timeout - timed out
  544.  
  545. * TLSV1 Cipher Suites:
  546. Forward Secrecy OK - Supported
  547. RC4 OK - Not Supported
  548.  
  549. Preferred:
  550. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  551. Accepted:
  552. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  553. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  554.  
  555. * Deflate Compression:
  556. OK - Compression disabled
  557.  
  558. * TLSV1_3 Cipher Suites:
  559. Forward Secrecy OK - Supported
  560. RC4 OK - Not Supported
  561.  
  562. Preferred:
  563. TLS_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  564. Accepted:
  565. TLS_CHACHA20_POLY1305_SHA256 256 bits HTTP 200 OK
  566. TLS_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  567. TLS_AES_128_GCM_SHA256 128 bits HTTP 200 OK
  568.  
  569. * ROBOT Attack:
  570. OK - Not vulnerable
  571.  
  572. * OpenSSL Heartbleed:
  573. OK - Not vulnerable to Heartbleed
  574.  
  575. * TLSV1_1 Cipher Suites:
  576. Forward Secrecy OK - Supported
  577. RC4 OK - Not Supported
  578.  
  579. Preferred:
  580. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  581. Accepted:
  582. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  583. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  584.  
  585. * TLSV1_2 Cipher Suites:
  586. Forward Secrecy OK - Supported
  587. RC4 OK - Not Supported
  588.  
  589. Preferred:
  590. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
  591. Accepted:
  592. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  593. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  594. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
  595. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  596.  
  597.  
  598. SCAN COMPLETED IN 34.83 S
  599. -------------------------
  600. #######################################################################################################################################
  601. Domains still to check: 1
  602. Checking if the hostname hcsp.gov.sd. given is in fact a domain...
  603.  
  604. Analyzing domain: hcsp.gov.sd.
  605. Checking NameServers using system default resolver...
  606. IP: 77.72.0.13 (United Kingdom)
  607. HostName: dns1.sudabest.net Type: NS
  608. HostName: ns1.cloudhosting.co.uk Type: PTR
  609. IP: 139.162.254.53 (United States)
  610. HostName: dns2.sudabest.net Type: NS
  611. HostName: ns2.cloudhosting.co.uk Type: PTR
  612.  
  613. Checking MailServers using system default resolver...
  614. IP: 77.72.5.97 (United Kingdom)
  615. HostName: mx2.cloudhosting.co.uk Type: MX
  616. HostName: mx.strikemail.co.uk Type: PTR
  617. IP: 77.72.5.10 (United Kingdom)
  618. HostName: mx2.cloudhosting.co.uk Type: MX
  619. HostName: mx.strikemail.co.uk Type: PTR
  620. IP: 77.72.6.25 (United Kingdom)
  621. HostName: mx1.cloudhosting.co.uk Type: MX
  622. HostName: mx.strikemail.co.uk Type: PTR
  623. IP: 77.72.6.24 (United Kingdom)
  624. HostName: mx1.cloudhosting.co.uk Type: MX
  625. HostName: mx.strikemail.co.uk Type: PTR
  626.  
  627. Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
  628. No zone transfer found on nameserver 77.72.0.13
  629. No zone transfer found on nameserver 139.162.254.53
  630.  
  631. Checking SPF record...
  632. New IP found: 77.72.0.138
  633. New IP found: 31.216.48.18
  634. New IP found: 209.140.18.28
  635. New IP found: 69.73.182.173
  636.  
  637. Checking 192 most common hostnames using system default resolver...
  638. IP: 77.72.0.138 (United Kingdom)
  639. Type: SPF
  640. HostName: www.hcsp.gov.sd. Type: A
  641. HostName: sulfur.cloudhosting.co.uk Type: PTR
  642. IP: 77.72.0.138 (United Kingdom)
  643. Type: SPF
  644. HostName: www.hcsp.gov.sd. Type: A
  645. HostName: sulfur.cloudhosting.co.uk Type: PTR
  646. HostName: ftp.hcsp.gov.sd. Type: A
  647. IP: 77.72.0.138 (United Kingdom)
  648. Type: SPF
  649. HostName: www.hcsp.gov.sd. Type: A
  650. HostName: sulfur.cloudhosting.co.uk Type: PTR
  651. HostName: ftp.hcsp.gov.sd. Type: A
  652. HostName: mail.hcsp.gov.sd. Type: A
  653. IP: 77.72.0.138 (United Kingdom)
  654. Type: SPF
  655. HostName: www.hcsp.gov.sd. Type: A
  656. HostName: sulfur.cloudhosting.co.uk Type: PTR
  657. HostName: ftp.hcsp.gov.sd. Type: A
  658. HostName: mail.hcsp.gov.sd. Type: A
  659. HostName: webmail.hcsp.gov.sd. Type: A
  660.  
  661. Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
  662. Checking netblock 209.140.18.0
  663. Checking netblock 77.72.0.0
  664. Checking netblock 77.72.5.0
  665. Checking netblock 31.216.48.0
  666. Checking netblock 69.73.182.0
  667. Checking netblock 139.162.254.0
  668. Checking netblock 77.72.6.0
  669.  
  670. Searching for hcsp.gov.sd. emails in Google
  671.  
  672. Checking 10 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
  673. Host 209.140.18.28 is up (reset ttl 64)
  674. Host 77.72.0.13 is up (reset ttl 64)
  675. Host 77.72.5.10 is up (reset ttl 64)
  676. Host 77.72.0.138 is up (reset ttl 64)
  677. Host 31.216.48.18 is up (reset ttl 64)
  678. Host 69.73.182.173 is up (reset ttl 64)
  679. Host 77.72.5.97 is up (reset ttl 64)
  680. Host 139.162.254.53 is up (reset ttl 64)
  681. Host 77.72.6.25 is up (reset ttl 64)
  682. Host 77.72.6.24 is up (reset ttl 64)
  683.  
  684. Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
  685. Scanning ip 209.140.18.28 ():
  686. Scanning ip 77.72.0.13 (ns1.cloudhosting.co.uk (PTR)):
  687. 53/tcp open domain syn-ack ttl 50 PowerDNS Authoritative Server 4.1.5
  688. Device type: general purpose|storage-misc|media device|WAP
  689. Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (92%), HP embedded (85%), Infomir embedded (85%), Ubiquiti embedded (85%), Ubiquiti AirOS 5.X (85%)
  690. Scanning ip 77.72.5.10 (mx.strikemail.co.uk (PTR)):
  691. Scanning ip 77.72.0.138 (webmail.hcsp.gov.sd.):
  692. 21/tcp open ftp? syn-ack ttl 50
  693. | fingerprint-strings:
  694. | GenericLines, GetRequest, HTTPOptions, Help, NULL, RTSPRequest:
  695. | Your connection to this server has been blocked in this server's firewall.
  696. | need to contact the server owner or hosting provider for further information.
  697. | Your blocked IP address is: 176.113.74.28
  698. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  699. |_ftp-bounce: ERROR: Script execution failed (use -d to debug)
  700. 22/tcp open ssh? syn-ack ttl 50
  701. | fingerprint-strings:
  702. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  703. | Your connection to this server has been blocked in this server's firewall.
  704. | need to contact the server owner or hosting provider for further information.
  705. | Your blocked IP address is: 176.113.74.28
  706. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  707. 26/tcp open rsftp? syn-ack ttl 50
  708. | fingerprint-strings:
  709. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  710. | Your connection to this server has been blocked in this server's firewall.
  711. | need to contact the server owner or hosting provider for further information.
  712. | Your blocked IP address is: 176.113.74.28
  713. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  714. 80/tcp open http syn-ack ttl 50 LiteSpeed httpd
  715. | http-methods:
  716. |_ Supported Methods: GET HEAD POST OPTIONS
  717. |_http-server-header: LiteSpeed
  718. |_http-title: 403 Forbidden
  719. 110/tcp open pop3? syn-ack ttl 50
  720. | fingerprint-strings:
  721. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  722. | Your connection to this server has been blocked in this server's firewall.
  723. | need to contact the server owner or hosting provider for further information.
  724. | Your blocked IP address is: 176.113.74.28
  725. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  726. 143/tcp open imap? syn-ack ttl 50
  727. | fingerprint-strings:
  728. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  729. | Your connection to this server has been blocked in this server's firewall.
  730. | need to contact the server owner or hosting provider for further information.
  731. | Your blocked IP address is: 176.113.74.28
  732. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  733. |_imap-capabilities: CAPABILITY
  734. 443/tcp open ssl/http syn-ack ttl 50 LiteSpeed httpd
  735. | http-methods:
  736. |_ Supported Methods: GET HEAD POST OPTIONS
  737. |_http-server-header: LiteSpeed
  738. |_http-title: 403 Forbidden
  739. | ssl-cert: Subject: commonName=*.cloudhosting.co.uk
  740. | Subject Alternative Name: DNS:*.cloudhosting.co.uk, DNS:cloudhosting.co.uk
  741. | Issuer: commonName=COMODO RSA Domain Validation Secure Server CA/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
  742. | Public Key type: rsa
  743. | Public Key bits: 2048
  744. | Signature Algorithm: sha256WithRSAEncryption
  745. | Not valid before: 2018-11-03T00:00:00
  746. | Not valid after: 2020-11-02T23:59:59
  747. | MD5: 0c37 e699 94b4 d854 36dd 5f4f 5697 1434
  748. |_SHA-1: b449 e250 8a8d 9586 e69b 770b 0ef8 250e 493e 0b0f
  749. 587/tcp open submission? syn-ack ttl 50
  750. | fingerprint-strings:
  751. | GenericLines, GetRequest, HTTPOptions, Hello, Help, NULL:
  752. | Your connection to this server has been blocked in this server's firewall.
  753. | need to contact the server owner or hosting provider for further information.
  754. | Your blocked IP address is: 176.113.74.28
  755. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  756. | smtp-commands: SMTP: EHLO You need to contact the server owner or hosting provider for further information.\x0D
  757. | Your blocked IP address is: 176.113.74.28\x0D
  758. |_This server's hostname is: sulfur.cloudhosting.co.uk\x0D
  759. 3306/tcp open mysql? syn-ack ttl 50
  760. | fingerprint-strings:
  761. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  762. | Your connection to this server has been blocked in this server's firewall.
  763. | need to contact the server owner or hosting provider for further information.
  764. | Your blocked IP address is: 176.113.74.28
  765. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  766. |_mysql-info: ERROR: Script execution failed (use -d to debug)
  767. Scanning ip 31.216.48.18 ():
  768. Scanning ip 69.73.182.173 ():
  769. Scanning ip 77.72.5.97 (mx.strikemail.co.uk (PTR)):
  770. Scanning ip 139.162.254.53 (ns2.cloudhosting.co.uk (PTR)):
  771. 53/tcp open domain syn-ack ttl 52 (unknown banner: .Shall.we.play.a.game?)
  772. | dns-nsid:
  773. | NSID: ns2.cloudhosting.co.uk (6e73322e636c6f7564686f7374696e672e636f2e756b)
  774. |_ id.server: ns2.cloudhosting.co.uk
  775. | fingerprint-strings:
  776. | DNSVersionBindReqTCP:
  777. | version
  778. | bind
  779. | Shall
  780. | play
  781. |_ game?
  782. Scanning ip 77.72.6.25 (mx.strikemail.co.uk (PTR)):
  783. Scanning ip 77.72.6.24 (mx.strikemail.co.uk (PTR)):
  784. WebCrawling domain's web servers... up to 50 max links.
  785.  
  786. + URL to crawl: http://webmail.hcsp.gov.sd.
  787. + Date: 2019-09-13
  788.  
  789. + Crawling URL: http://webmail.hcsp.gov.sd.:
  790. + Links:
  791. + Crawling http://webmail.hcsp.gov.sd.
  792. + Searching for directories...
  793. + Searching open folders...
  794.  
  795.  
  796. + URL to crawl: http://www.hcsp.gov.sd.
  797. + Date: 2019-09-13
  798.  
  799. + Crawling URL: http://www.hcsp.gov.sd.:
  800. + Links:
  801. + Crawling http://www.hcsp.gov.sd.
  802. + Searching for directories...
  803. + Searching open folders...
  804.  
  805.  
  806. + URL to crawl: http://mail.hcsp.gov.sd.
  807. + Date: 2019-09-13
  808.  
  809. + Crawling URL: http://mail.hcsp.gov.sd.:
  810. + Links:
  811. + Crawling http://mail.hcsp.gov.sd.
  812. + Searching for directories...
  813. + Searching open folders...
  814.  
  815.  
  816. + URL to crawl: http://ftp.hcsp.gov.sd.
  817. + Date: 2019-09-13
  818.  
  819. + Crawling URL: http://ftp.hcsp.gov.sd.:
  820. + Links:
  821. + Crawling http://ftp.hcsp.gov.sd.
  822. + Searching for directories...
  823. + Searching open folders...
  824.  
  825.  
  826. + URL to crawl: https://webmail.hcsp.gov.sd.
  827. + Date: 2019-09-13
  828.  
  829. + Crawling URL: https://webmail.hcsp.gov.sd.:
  830. + Links:
  831. + Crawling https://webmail.hcsp.gov.sd.
  832. + Searching for directories...
  833. + Searching open folders...
  834.  
  835.  
  836. + URL to crawl: https://www.hcsp.gov.sd.
  837. + Date: 2019-09-13
  838.  
  839. + Crawling URL: https://www.hcsp.gov.sd.:
  840. + Links:
  841. + Crawling https://www.hcsp.gov.sd.
  842. + Searching for directories...
  843. + Searching open folders...
  844.  
  845.  
  846. + URL to crawl: https://mail.hcsp.gov.sd.
  847. + Date: 2019-09-13
  848.  
  849. + Crawling URL: https://mail.hcsp.gov.sd.:
  850. + Links:
  851. + Crawling https://mail.hcsp.gov.sd.
  852. + Searching for directories...
  853. + Searching open folders...
  854.  
  855.  
  856. + URL to crawl: https://ftp.hcsp.gov.sd.
  857. + Date: 2019-09-13
  858.  
  859. + Crawling URL: https://ftp.hcsp.gov.sd.:
  860. + Links:
  861. + Crawling https://ftp.hcsp.gov.sd.
  862. + Searching for directories...
  863. + Searching open folders...
  864.  
  865. --Finished--
  866. Summary information for domain hcsp.gov.sd.
  867. -----------------------------------------
  868. Domain Specific Information:
  869.  
  870. Domain Ips Information:
  871. IP: 209.140.18.28
  872. Type: SPF
  873. Is Active: True (reset ttl 64)
  874. IP: 77.72.0.13
  875. HostName: dns1.sudabest.net Type: NS
  876. HostName: ns1.cloudhosting.co.uk Type: PTR
  877. Country: United Kingdom
  878. Is Active: True (reset ttl 64)
  879. Port: 53/tcp open domain syn-ack ttl 50 PowerDNS Authoritative Server 4.1.5
  880. Script Info: Device type: general purpose|storage-misc|media device|WAP
  881. Script Info: Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (92%), HP embedded (85%), Infomir embedded (85%), Ubiquiti embedded (85%), Ubiquiti AirOS 5.X (85%)
  882. IP: 77.72.5.10
  883. HostName: mx2.cloudhosting.co.uk Type: MX
  884. HostName: mx.strikemail.co.uk Type: PTR
  885. Country: United Kingdom
  886. Is Active: True (reset ttl 64)
  887. IP: 77.72.0.138
  888. Type: SPF
  889. HostName: www.hcsp.gov.sd. Type: A
  890. HostName: sulfur.cloudhosting.co.uk Type: PTR
  891. HostName: ftp.hcsp.gov.sd. Type: A
  892. HostName: mail.hcsp.gov.sd. Type: A
  893. HostName: webmail.hcsp.gov.sd. Type: A
  894. Country: United Kingdom
  895. Is Active: True (reset ttl 64)
  896. Port: 21/tcp open ftp? syn-ack ttl 50
  897. Script Info: | fingerprint-strings:
  898. Script Info: | GenericLines, GetRequest, HTTPOptions, Help, NULL, RTSPRequest:
  899. Script Info: | Your connection to this server has been blocked in this server's firewall.
  900. Script Info: | need to contact the server owner or hosting provider for further information.
  901. Script Info: | Your blocked IP address is: 176.113.74.28
  902. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  903. Script Info: |_ftp-bounce: ERROR: Script execution failed (use -d to debug)
  904. Port: 22/tcp open ssh? syn-ack ttl 50
  905. Script Info: | fingerprint-strings:
  906. Script Info: | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  907. Script Info: | Your connection to this server has been blocked in this server's firewall.
  908. Script Info: | need to contact the server owner or hosting provider for further information.
  909. Script Info: | Your blocked IP address is: 176.113.74.28
  910. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  911. Port: 26/tcp open rsftp? syn-ack ttl 50
  912. Script Info: | fingerprint-strings:
  913. Script Info: | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  914. Script Info: | Your connection to this server has been blocked in this server's firewall.
  915. Script Info: | need to contact the server owner or hosting provider for further information.
  916. Script Info: | Your blocked IP address is: 176.113.74.28
  917. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  918. Port: 80/tcp open http syn-ack ttl 50 LiteSpeed httpd
  919. Script Info: | http-methods:
  920. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  921. Script Info: |_http-server-header: LiteSpeed
  922. Script Info: |_http-title: 403 Forbidden
  923. Port: 110/tcp open pop3? syn-ack ttl 50
  924. Script Info: | fingerprint-strings:
  925. Script Info: | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  926. Script Info: | Your connection to this server has been blocked in this server's firewall.
  927. Script Info: | need to contact the server owner or hosting provider for further information.
  928. Script Info: | Your blocked IP address is: 176.113.74.28
  929. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  930. Port: 143/tcp open imap? syn-ack ttl 50
  931. Script Info: | fingerprint-strings:
  932. Script Info: | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  933. Script Info: | Your connection to this server has been blocked in this server's firewall.
  934. Script Info: | need to contact the server owner or hosting provider for further information.
  935. Script Info: | Your blocked IP address is: 176.113.74.28
  936. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  937. Script Info: |_imap-capabilities: CAPABILITY
  938. Port: 443/tcp open ssl/http syn-ack ttl 50 LiteSpeed httpd
  939. Script Info: | http-methods:
  940. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  941. Script Info: |_http-server-header: LiteSpeed
  942. Script Info: |_http-title: 403 Forbidden
  943. Script Info: | ssl-cert: Subject: commonName=*.cloudhosting.co.uk
  944. Script Info: | Subject Alternative Name: DNS:*.cloudhosting.co.uk, DNS:cloudhosting.co.uk
  945. Script Info: | Issuer: commonName=COMODO RSA Domain Validation Secure Server CA/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
  946. Script Info: | Public Key type: rsa
  947. Script Info: | Public Key bits: 2048
  948. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  949. Script Info: | Not valid before: 2018-11-03T00:00:00
  950. Script Info: | Not valid after: 2020-11-02T23:59:59
  951. Script Info: | MD5: 0c37 e699 94b4 d854 36dd 5f4f 5697 1434
  952. Script Info: |_SHA-1: b449 e250 8a8d 9586 e69b 770b 0ef8 250e 493e 0b0f
  953. Port: 587/tcp open submission? syn-ack ttl 50
  954. Script Info: | fingerprint-strings:
  955. Script Info: | GenericLines, GetRequest, HTTPOptions, Hello, Help, NULL:
  956. Script Info: | Your connection to this server has been blocked in this server's firewall.
  957. Script Info: | need to contact the server owner or hosting provider for further information.
  958. Script Info: | Your blocked IP address is: 176.113.74.28
  959. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  960. Script Info: | smtp-commands: SMTP: EHLO You need to contact the server owner or hosting provider for further information.\x0D
  961. Script Info: | Your blocked IP address is: 176.113.74.28\x0D
  962. Script Info: |_This server's hostname is: sulfur.cloudhosting.co.uk\x0D
  963. Port: 3306/tcp open mysql? syn-ack ttl 50
  964. Script Info: | fingerprint-strings:
  965. Script Info: | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  966. Script Info: | Your connection to this server has been blocked in this server's firewall.
  967. Script Info: | need to contact the server owner or hosting provider for further information.
  968. Script Info: | Your blocked IP address is: 176.113.74.28
  969. Script Info: |_ This server's hostname is: sulfur.cloudhosting.co.uk
  970. Script Info: |_mysql-info: ERROR: Script execution failed (use -d to debug)
  971. IP: 31.216.48.18
  972. Type: SPF
  973. Is Active: True (reset ttl 64)
  974. IP: 69.73.182.173
  975. Type: SPF
  976. Is Active: True (reset ttl 64)
  977. IP: 77.72.5.97
  978. HostName: mx2.cloudhosting.co.uk Type: MX
  979. HostName: mx.strikemail.co.uk Type: PTR
  980. Country: United Kingdom
  981. Is Active: True (reset ttl 64)
  982. IP: 139.162.254.53
  983. HostName: dns2.sudabest.net Type: NS
  984. HostName: ns2.cloudhosting.co.uk Type: PTR
  985. Country: United States
  986. Is Active: True (reset ttl 64)
  987. Port: 53/tcp open domain syn-ack ttl 52 (unknown banner: .Shall.we.play.a.game?)
  988. Script Info: | dns-nsid:
  989. Script Info: | NSID: ns2.cloudhosting.co.uk (6e73322e636c6f7564686f7374696e672e636f2e756b)
  990. Script Info: |_ id.server: ns2.cloudhosting.co.uk
  991. Script Info: | fingerprint-strings:
  992. Script Info: | DNSVersionBindReqTCP:
  993. Script Info: | version
  994. Script Info: | bind
  995. Script Info: | Shall
  996. Script Info: | play
  997. Script Info: |_ game?
  998. IP: 77.72.6.25
  999. HostName: mx1.cloudhosting.co.uk Type: MX
  1000. HostName: mx.strikemail.co.uk Type: PTR
  1001. Country: United Kingdom
  1002. Is Active: True (reset ttl 64)
  1003. IP: 77.72.6.24
  1004. HostName: mx1.cloudhosting.co.uk Type: MX
  1005. HostName: mx.strikemail.co.uk Type: PTR
  1006. Country: United Kingdom
  1007. Is Active: True (reset ttl 64)
  1008. #######################################################################################################################################
  1009. dnsenum VERSION:1.2.4
  1010.  
  1011. ----- hcsp.gov.sd -----
  1012.  
  1013.  
  1014. Host's addresses:
  1015. __________________
  1016.  
  1017. hcsp.gov.sd. 12940 IN A 77.72.0.138
  1018.  
  1019.  
  1020. Name Servers:
  1021. ______________
  1022.  
  1023. dns2.sudabest.net. 84940 IN A 139.162.254.53
  1024. dns1.sudabest.net. 12940 IN A 77.72.0.13
  1025.  
  1026.  
  1027. Mail (MX) Servers:
  1028. ___________________
  1029.  
  1030. mx2.cloudhosting.co.uk. 46 IN A 77.72.5.97
  1031. mx2.cloudhosting.co.uk. 46 IN A 77.72.5.10
  1032. mx1.cloudhosting.co.uk. 46 IN A 77.72.6.25
  1033. mx1.cloudhosting.co.uk. 46 IN A 77.72.6.24
  1034.  
  1035.  
  1036. Trying Zone Transfers and getting Bind Versions:
  1037. _________________________________________________
  1038.  
  1039.  
  1040. Trying Zone Transfer for hcsp.gov.sd on dns2.sudabest.net ...
  1041.  
  1042. Trying Zone Transfer for hcsp.gov.sd on dns1.sudabest.net ...
  1043.  
  1044. brute force file not specified, bay.
  1045. #######################################################################################################################################
  1046. hcsp.gov.sd,77.72.0.138
  1047. www.hcsp.gov.sd,77.72.0.138
  1048. ftp.hcsp.gov.sd,77.72.0.138
  1049. mail.hcsp.gov.sd,77.72.0.138
  1050. webmail.hcsp.gov.sd,77.72.0.138
  1051. ######################################################################################################################################
  1052. ===============================================
  1053. -=Subfinder v1.1.3 github.com/subfinder/subfinder
  1054. ===============================================
  1055.  
  1056.  
  1057. Running Source: Ask
  1058. Running Source: Archive.is
  1059. Running Source: Baidu
  1060. Running Source: Bing
  1061. Running Source: CertDB
  1062. Running Source: CertificateTransparency
  1063. Running Source: Certspotter
  1064. Running Source: Commoncrawl
  1065. Running Source: Crt.sh
  1066. Running Source: Dnsdb
  1067. Running Source: DNSDumpster
  1068. Running Source: DNSTable
  1069. Running Source: Dogpile
  1070. Running Source: Exalead
  1071. Running Source: Findsubdomains
  1072. Running Source: Googleter
  1073. Running Source: Hackertarget
  1074. Running Source: Ipv4Info
  1075. Running Source: PTRArchive
  1076. Running Source: Sitedossier
  1077. Running Source: Threatcrowd
  1078. Running Source: ThreatMiner
  1079. Running Source: WaybackArchive
  1080. Running Source: Yahoo
  1081.  
  1082. Running enumeration on hcsp.gov.sd
  1083.  
  1084. waybackarchive: parse http://web.archive.org/cdx/search/cdx?url=*.hcsp.gov.sd/*&output=json&fl=original&collapse=urlkey&page=: net/url: invalid control character in URL
  1085.  
  1086.  
  1087. Starting Bruteforcing of hcsp.gov.sd with 9985 words
  1088.  
  1089. Total 10 Unique subdomains found for hcsp.gov.sd
  1090.  
  1091. .hcsp.gov.sd
  1092. cpanel.hcsp.gov.sd
  1093. ftp.hcsp.gov.sd
  1094. localhost.hcsp.gov.sd
  1095. mail.hcsp.gov.sd
  1096. webdisk.hcsp.gov.sd
  1097. webmail.hcsp.gov.sd
  1098. whm.hcsp.gov.sd
  1099. www.hcsp.gov.sd
  1100. www.hcsp.gov.sd
  1101. #######################################################################################################################################
  1102. [*] Found SPF record:
  1103. [*] v=spf1 ip4:77.72.0.138 ip4:31.216.48.18 ip4:209.140.18.28 +a +mx +ip4:69.73.182.173 ?all
  1104. [+] SPF record has no All string
  1105. [*] Checking SPF include mechanisms
  1106. [*] Include mechanisms are not strong
  1107. [*] No DMARC record found. Looking for organizational record
  1108. [+] No organizational DMARC record
  1109. [+] Spoofing possible for hcsp.gov.sd!
  1110. #######################################################################################################################################
  1111. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:30 EDT
  1112. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  1113. Host is up (0.11s latency).
  1114. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  1115. Not shown: 471 filtered ports, 3 closed ports
  1116. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  1117. PORT STATE SERVICE
  1118. 21/tcp open ftp
  1119. 22/tcp open ssh
  1120. 80/tcp open http
  1121. 110/tcp open pop3
  1122. 143/tcp open imap
  1123. 443/tcp open https
  1124. 587/tcp open submission
  1125. 3306/tcp open mysql
  1126. 8999/tcp open bctp
  1127.  
  1128. Nmap done: 1 IP address (1 host up) scanned in 5.95 seconds
  1129. #######################################################################################################################################
  1130. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:30 EDT
  1131. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  1132. Host is up (0.044s latency).
  1133. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  1134. Not shown: 2 filtered ports
  1135. PORT STATE SERVICE
  1136. 53/udp open|filtered domain
  1137. 67/udp open|filtered dhcps
  1138. 68/udp open|filtered dhcpc
  1139. 69/udp open|filtered tftp
  1140. 88/udp open|filtered kerberos-sec
  1141. 123/udp open|filtered ntp
  1142. 139/udp open|filtered netbios-ssn
  1143. 161/udp open|filtered snmp
  1144. 162/udp open|filtered snmptrap
  1145. 389/udp open|filtered ldap
  1146. 500/udp open|filtered isakmp
  1147. 520/udp open|filtered route
  1148. 2049/udp open|filtered nfs
  1149.  
  1150. Nmap done: 1 IP address (1 host up) scanned in 2.61 seconds
  1151. #######################################################################################################################################
  1152. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:30 EDT
  1153. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  1154. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  1155. NSE: [ftp-brute] passwords: Time limit 3m00s exceeded.
  1156. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  1157. Host is up (0.11s latency).
  1158. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  1159.  
  1160. PORT STATE SERVICE VERSION
  1161. 21/tcp open ftp?
  1162. | fingerprint-strings:
  1163. | GenericLines, GetRequest, HTTPOptions, Help, NULL, RTSPRequest:
  1164. | Your connection to this server has been blocked in this server's firewall.
  1165. | need to contact the server owner or hosting provider for further information.
  1166. | Your blocked IP address is: 176.113.74.28
  1167. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  1168. |_ftp-bounce: ERROR: Script execution failed (use -d to debug)
  1169. | ftp-brute:
  1170. | Accounts: No valid accounts found
  1171. |_ Statistics: Performed 1690 guesses in 182 seconds, average tps: 9.3
  1172. |_ftp-libopie: ERROR: Script execution failed (use -d to debug)
  1173. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
  1174. SF-Port21-TCP:V=7.80%I=7%D=9/13%Time=5D7BA810%P=x86_64-pc-linux-gnu%r(NULL
  1175. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  1176. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  1177. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  1178. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  1179. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  1180. SF:hosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20t
  1181. SF:his\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fi
  1182. SF:rewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20o
  1183. SF:r\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20
  1184. SF:blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's
  1185. SF:\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(Help,100,"Y
  1186. SF:our\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocked\x20
  1187. SF:in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact\x2
  1188. SF:0the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20further\
  1189. SF:x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.113
  1190. SF:\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhosting
  1191. SF:\.co\.uk\r\n")%r(GetRequest,100,"Your\x20connection\x20to\x20this\x20se
  1192. SF:rver\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall\.\
  1193. SF:r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20host
  1194. SF:ing\x20provider\x20for\x20further\x20information\.\r\nYour\x20blocked\x
  1195. SF:20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20hostn
  1196. SF:ame\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(HTTPOptions,100,"You
  1197. SF:r\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocked\x20in
  1198. SF:\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact\x20t
  1199. SF:he\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20further\x2
  1200. SF:0information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.113\.
  1201. SF:74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhosting\.
  1202. SF:co\.uk\r\n")%r(RTSPRequest,100,"Your\x20connection\x20to\x20this\x20ser
  1203. SF:ver\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall\.\r
  1204. SF:\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20hosti
  1205. SF:ng\x20provider\x20for\x20further\x20information\.\r\nYour\x20blocked\x2
  1206. SF:0IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20hostna
  1207. SF:me\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  1208. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1209. Device type: general purpose|specialized|storage-misc
  1210. Running (JUST GUESSING): Linux 3.X|4.X (91%), Crestron 2-Series (87%), HP embedded (85%)
  1211. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3
  1212. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), Linux 3.18 (91%), Linux 3.2 - 4.9 (91%), Crestron XPanel control system (87%), Linux 3.16 (86%), HP P2000 G3 NAS device (85%)
  1213. No exact OS matches for host (test conditions non-ideal).
  1214. Network Distance: 15 hops
  1215.  
  1216. TRACEROUTE (using port 21/tcp)
  1217. HOP RTT ADDRESS
  1218. 1 54.73 ms 10.244.204.1
  1219. 2 54.79 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1220. 3 54.80 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  1221. 4 54.79 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  1222. 5 54.78 ms motl-b1-link.telia.net (62.115.162.41)
  1223. 6 54.83 ms nyk-bb4-link.telia.net (62.115.134.52)
  1224. 7 54.86 ms ash-bb4-link.telia.net (62.115.136.201)
  1225. 8 74.04 ms ash-b1-link.telia.net (62.115.143.121)
  1226. 9 74.02 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  1227. 10 33.51 ms ash-eqx-02gw.voxility.net (5.254.81.133)
  1228. 11 183.02 ms ash-eqx-01c.voxility.net (5.254.81.22)
  1229. 12 ...
  1230. 13 137.35 ms lon-tel-01c.voxility.net (5.254.112.185)
  1231. 14 ...
  1232. 15 115.84 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  1233. #######################################################################################################################################
  1234. USER_FILE => /usr/share/brutex/wordlists/simple-users.txt
  1235. RHOSTS => hcsp.gov.sd
  1236. RHOST => hcsp.gov.sd
  1237. [*] 77.72.0.138:22 - SSH - Using malformed packet technique
  1238. [*] 77.72.0.138:22 - SSH - Starting scan
  1239. [-] 77.72.0.138:22 - SSH - User 'admin' not found
  1240. [-] 77.72.0.138:22 - SSH - User 'administrator' not found
  1241. [-] 77.72.0.138:22 - SSH - User 'anonymous' not found
  1242. [-] 77.72.0.138:22 - SSH - User 'backup' not found
  1243. [-] 77.72.0.138:22 - SSH - User 'bee' not found
  1244. [-] 77.72.0.138:22 - SSH - User 'ftp' not found
  1245. [-] 77.72.0.138:22 - SSH - User 'guest' not found
  1246. [-] 77.72.0.138:22 - SSH - User 'GUEST' not found
  1247. [-] 77.72.0.138:22 - SSH - User 'info' not found
  1248. [-] 77.72.0.138:22 - SSH - User 'mail' not found
  1249. [-] 77.72.0.138:22 - SSH - User 'mailadmin' not found
  1250. [-] 77.72.0.138:22 - SSH - User 'msfadmin' not found
  1251. [-] 77.72.0.138:22 - SSH - User 'mysql' not found
  1252. [-] 77.72.0.138:22 - SSH - User 'nobody' not found
  1253. [-] 77.72.0.138:22 - SSH - User 'oracle' not found
  1254. [-] 77.72.0.138:22 - SSH - User 'owaspbwa' not found
  1255. [-] 77.72.0.138:22 - SSH - User 'postfix' not found
  1256. [-] 77.72.0.138:22 - SSH - User 'postgres' not found
  1257. [-] 77.72.0.138:22 - SSH - User 'private' not found
  1258. [-] 77.72.0.138:22 - SSH - User 'proftpd' not found
  1259. [-] 77.72.0.138:22 - SSH - User 'public' not found
  1260. [-] 77.72.0.138:22 - SSH - User 'root' not found
  1261. [-] 77.72.0.138:22 - SSH - User 'superadmin' not found
  1262. [-] 77.72.0.138:22 - SSH - User 'support' not found
  1263. [-] 77.72.0.138:22 - SSH - User 'sys' not found
  1264. [-] 77.72.0.138:22 - SSH - User 'system' not found
  1265. [-] 77.72.0.138:22 - SSH - User 'systemadmin' not found
  1266. [-] 77.72.0.138:22 - SSH - User 'systemadministrator' not found
  1267. [-] 77.72.0.138:22 - SSH - User 'test' not found
  1268. [-] 77.72.0.138:22 - SSH - User 'tomcat' not found
  1269. [-] 77.72.0.138:22 - SSH - User 'user' not found
  1270. [-] 77.72.0.138:22 - SSH - User 'webmaster' not found
  1271. [-] 77.72.0.138:22 - SSH - User 'www-data' not found
  1272. [-] 77.72.0.138:22 - SSH - User 'Fortimanager_Access' not found
  1273. [*] Scanned 1 of 1 hosts (100% complete)
  1274. [*] Auxiliary module execution completed
  1275. #######################################################################################################################################
  1276. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:35 EDT
  1277. NSE: Loaded 164 scripts for scanning.
  1278. NSE: Script Pre-scanning.
  1279. Initiating NSE at 10:35
  1280. Completed NSE at 10:35, 0.00s elapsed
  1281. Initiating NSE at 10:35
  1282. Completed NSE at 10:35, 0.00s elapsed
  1283. Initiating Parallel DNS resolution of 1 host. at 10:35
  1284. Completed Parallel DNS resolution of 1 host. at 10:35, 0.02s elapsed
  1285. Initiating SYN Stealth Scan at 10:35
  1286. Scanning hcsp.gov.sd (77.72.0.138) [1 port]
  1287. Discovered open port 80/tcp on 77.72.0.138
  1288. Completed SYN Stealth Scan at 10:35, 0.15s elapsed (1 total ports)
  1289. Initiating Service scan at 10:35
  1290. Scanning 1 service on hcsp.gov.sd (77.72.0.138)
  1291. Completed Service scan at 10:35, 6.23s elapsed (1 service on 1 host)
  1292. Initiating OS detection (try #1) against hcsp.gov.sd (77.72.0.138)
  1293. Retrying OS detection (try #2) against hcsp.gov.sd (77.72.0.138)
  1294. Initiating Traceroute at 10:35
  1295. Completed Traceroute at 10:35, 3.11s elapsed
  1296. Initiating Parallel DNS resolution of 12 hosts. at 10:35
  1297. Completed Parallel DNS resolution of 12 hosts. at 10:35, 0.20s elapsed
  1298. NSE: Script scanning 77.72.0.138.
  1299. Initiating NSE at 10:35
  1300. Completed NSE at 10:36, 41.48s elapsed
  1301. Initiating NSE at 10:36
  1302. Completed NSE at 10:36, 0.59s elapsed
  1303. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  1304. Host is up (0.11s latency).
  1305. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  1306.  
  1307. PORT STATE SERVICE VERSION
  1308. 80/tcp open http LiteSpeed httpd
  1309. | http-brute:
  1310. |_ Path "/" does not require authentication
  1311. |_http-chrono: Request times for /; avg: 395.03ms; min: 354.66ms; max: 433.53ms
  1312. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  1313. |_http-date: Fri, 13 Sep 2019 14:35:54 GMT; -8s from local time.
  1314. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  1315. |_http-dombased-xss: Couldn't find any DOM based XSS.
  1316. | http-errors:
  1317. | Spidering limited to: maxpagecount=40; withinhost=hcsp.gov.sd
  1318. | Found the following error pages:
  1319. |
  1320. | Error Code: 403
  1321. |_ http://hcsp.gov.sd:80/
  1322. |_http-feed: Couldn't find any feeds.
  1323. |_http-fetch: Please enter the complete path of the directory to save data in.
  1324. | http-headers:
  1325. | Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
  1326. | Pragma: no-cache
  1327. | Content-Type: text/html
  1328. | Content-Length: 1139
  1329. | Date: Fri, 13 Sep 2019 14:35:57 GMT
  1330. | Server: LiteSpeed
  1331. | Vary: User-Agent
  1332. | Connection: close
  1333. |
  1334. |_ (Request type: GET)
  1335. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  1336. |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
  1337. | http-methods:
  1338. |_ Supported Methods: GET HEAD
  1339. |_http-mobileversion-checker: No mobile version detected.
  1340. |_http-security-headers:
  1341. |_http-server-header: LiteSpeed
  1342. | http-sitemap-generator:
  1343. | Directory structure:
  1344. | Longest directory structure:
  1345. | Depth: 0
  1346. | Dir: /
  1347. | Total files found (by extension):
  1348. |_
  1349. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  1350. |_http-title: 403 Forbidden
  1351. |_http-userdir-enum: Potential Users: root, admin, administrator, webadmin, sysadmin, netadmin, guest, user, web, test
  1352. | http-vhosts:
  1353. | 46 names had status ERROR
  1354. |_81 names had status 403
  1355. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
  1356. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  1357. |_http-xssed: No previously reported XSS vuln.
  1358. |_vulscan: ERROR: Script execution failed (use -d to debug)
  1359. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1360. Device type: general purpose|specialized|storage-misc
  1361. Running (JUST GUESSING): Linux 3.X|4.X (91%), Crestron 2-Series (87%), HP embedded (85%), Oracle VM Server 3.X (85%)
  1362. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3 cpe:/o:oracle:vm_server:3.4.2 cpe:/o:linux:linux_kernel:4.1
  1363. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), Linux 3.2 - 4.9 (91%), Linux 3.18 (89%), Crestron XPanel control system (87%), Linux 3.16 (86%), HP P2000 G3 NAS device (85%), Oracle VM Server 3.4.2 (Linux 4.1) (85%)
  1364. No exact OS matches for host (test conditions non-ideal).
  1365. Uptime guess: 27.430 days (since Sat Aug 17 00:17:25 2019)
  1366. Network Distance: 15 hops
  1367. TCP Sequence Prediction: Difficulty=261 (Good luck!)
  1368. IP ID Sequence Generation: All zeros
  1369.  
  1370. TRACEROUTE (using port 80/tcp)
  1371. HOP RTT ADDRESS
  1372. 1 95.92 ms 10.244.204.1
  1373. 2 95.97 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1374. 3 96.00 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  1375. 4 95.98 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  1376. 5 96.02 ms motl-b1-link.telia.net (62.115.162.41)
  1377. 6 ...
  1378. 7 65.02 ms ash-bb3-link.telia.net (62.115.141.244)
  1379. 8 96.08 ms ash-b1-link.telia.net (213.155.136.39)
  1380. 9 96.11 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  1381. 10 33.38 ms ash-eqx-02gw.voxility.net (5.254.81.133)
  1382. 11 75.23 ms ash-eqx-01c.voxility.net (5.254.81.22)
  1383. 12 ...
  1384. 13 151.55 ms lon-tel-01c.voxility.net (5.254.112.185)
  1385. 14 ...
  1386. 15 103.47 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  1387.  
  1388. NSE: Script Post-scanning.
  1389. Initiating NSE at 10:36
  1390. Completed NSE at 10:36, 0.00s elapsed
  1391. Initiating NSE at 10:36
  1392. Completed NSE at 10:36, 0.00s elapsed
  1393. #######################################################################################################################################
  1394. HTTP/1.1 200 OK
  1395. Content-Type: text/html; charset=UTF-8
  1396. Date: Fri, 13 Sep 2019 14:37:40 GMT
  1397. Server: LiteSpeed
  1398. Vary: User-Agent
  1399. Connection: Keep-Alive
  1400.  
  1401. HTTP/1.1 200 OK
  1402. Content-Type: text/html; charset=UTF-8
  1403. Date: Fri, 13 Sep 2019 14:37:41 GMT
  1404. Server: LiteSpeed
  1405. Vary: User-Agent
  1406. Connection: Keep-Alive
  1407. ######################################################################################################################################
  1408. ------------------------------------------------------------------------------------------------------------------------
  1409.  
  1410. [ ! ] Starting SCANNER INURLBR 2.1 at [13-09-2019 10:38:09]
  1411. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  1412. It is the end user's responsibility to obey all applicable local, state and federal laws.
  1413. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  1414.  
  1415. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/hcsp.gov.sd/output/inurlbr-hcsp.gov.sd ]
  1416. [ INFO ][ DORK ]::[ site:hcsp.gov.sd ]
  1417. [ INFO ][ SEARCHING ]:: {
  1418. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.cm ]
  1419.  
  1420. [ INFO ][ SEARCHING ]::
  1421. -[:::]
  1422. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  1423.  
  1424. [ INFO ][ SEARCHING ]::
  1425. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1426. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.cf ID: 007843865286850066037:3ajwn2jlweq ]
  1427.  
  1428. [ INFO ][ SEARCHING ]::
  1429. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1430.  
  1431. [ INFO ][ TOTAL FOUND VALUES ]:: [ 100 ]
  1432.  
  1433.  
  1434. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1435. |_[ + ] [ 0 / 100 ]-[10:38:21] [ - ]
  1436. |_[ + ] Target:: [ https://hcsp.gov.sd/ ]
  1437. |_[ + ] Exploit::
  1438. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1439. |_[ + ] More details:: / - / , ISP:
  1440. |_[ + ] Found:: UNIDENTIFIED
  1441.  
  1442. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1443. |_[ + ] [ 1 / 100 ]-[10:38:22] [ - ]
  1444. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/ ]
  1445. |_[ + ] Exploit::
  1446. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1447. |_[ + ] More details:: / - / , ISP:
  1448. |_[ + ] Found:: UNIDENTIFIED
  1449.  
  1450. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1451. |_[ + ] [ 2 / 100 ]-[10:38:23] [ - ]
  1452. |_[ + ] Target:: [ https://hcsp.gov.sd/2069/ ]
  1453. |_[ + ] Exploit::
  1454. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1455. |_[ + ] More details:: / - / , ISP:
  1456. |_[ + ] Found:: UNIDENTIFIED
  1457.  
  1458. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1459. |_[ + ] [ 3 / 100 ]-[10:38:24] [ - ]
  1460. |_[ + ] Target:: [ https://hcsp.gov.sd/2062/ ]
  1461. |_[ + ] Exploit::
  1462. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1463. |_[ + ] More details:: / - / , ISP:
  1464. |_[ + ] Found:: UNIDENTIFIED
  1465.  
  1466. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1467. |_[ + ] [ 4 / 100 ]-[10:38:24] [ - ]
  1468. |_[ + ] Target:: [ http://hcsp.gov.sd/activities/ ]
  1469. |_[ + ] Exploit::
  1470. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1471. |_[ + ] More details:: / - / , ISP:
  1472. |_[ + ] Found:: UNIDENTIFIED
  1473.  
  1474. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1475. |_[ + ] [ 5 / 100 ]-[10:38:25] [ - ]
  1476. |_[ + ] Target:: [ http://hcsp.gov.sd/النشأة/ ]
  1477. |_[ + ] Exploit::
  1478. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1479. |_[ + ] More details:: / - / , ISP:
  1480. |_[ + ] Found:: UNIDENTIFIED
  1481.  
  1482. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1483. |_[ + ] [ 6 / 100 ]-[10:38:26] [ - ]
  1484. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1195/ ]
  1485. |_[ + ] Exploit::
  1486. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1487. |_[ + ] More details:: / - / , ISP:
  1488. |_[ + ] Found:: UNIDENTIFIED
  1489.  
  1490. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1491. |_[ + ] [ 7 / 100 ]-[10:38:26] [ - ]
  1492. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_5942/ ]
  1493. |_[ + ] Exploit::
  1494. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1495. |_[ + ] More details:: / - / , ISP:
  1496. |_[ + ] Found:: UNIDENTIFIED
  1497.  
  1498. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1499. |_[ + ] [ 8 / 100 ]-[10:38:27] [ - ]
  1500. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6310/ ]
  1501. |_[ + ] Exploit::
  1502. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1503. |_[ + ] More details:: / - / , ISP:
  1504. |_[ + ] Found:: UNIDENTIFIED
  1505.  
  1506. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1507. |_[ + ] [ 9 / 100 ]-[10:38:28] [ - ]
  1508. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_0784/ ]
  1509. |_[ + ] Exploit::
  1510. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1511. |_[ + ] More details:: / - / , ISP:
  1512. |_[ + ] Found:: UNIDENTIFIED
  1513.  
  1514. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1515. |_[ + ] [ 10 / 100 ]-[10:38:28] [ - ]
  1516. |_[ + ] Target:: [ http://hcsp.gov.sd/_dsc1253/ ]
  1517. |_[ + ] Exploit::
  1518. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1519. |_[ + ] More details:: / - / , ISP:
  1520. |_[ + ] Found:: UNIDENTIFIED
  1521.  
  1522. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1523. |_[ + ] [ 11 / 100 ]-[10:38:29] [ - ]
  1524. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_0714/ ]
  1525. |_[ + ] Exploit::
  1526. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1527. |_[ + ] More details:: / - / , ISP:
  1528. |_[ + ] Found:: UNIDENTIFIED
  1529.  
  1530. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1531. |_[ + ] [ 12 / 100 ]-[10:38:30] [ - ]
  1532. |_[ + ] Target:: [ https://hcsp.gov.sd/شه/ ]
  1533. |_[ + ] Exploit::
  1534. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1535. |_[ + ] More details:: / - / , ISP:
  1536. |_[ + ] Found:: UNIDENTIFIED
  1537.  
  1538. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1539. |_[ + ] [ 13 / 100 ]-[10:38:30] [ - ]
  1540. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6289/ ]
  1541. |_[ + ] Exploit::
  1542. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1543. |_[ + ] More details:: / - / , ISP:
  1544. |_[ + ] Found:: UNIDENTIFIED
  1545.  
  1546. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1547. |_[ + ] [ 14 / 100 ]-[10:38:31] [ - ]
  1548. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1106/ ]
  1549. |_[ + ] Exploit::
  1550. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1551. |_[ + ] More details:: / - / , ISP:
  1552. |_[ + ] Found:: UNIDENTIFIED
  1553.  
  1554. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1555. |_[ + ] [ 15 / 100 ]-[10:38:32] [ - ]
  1556. |_[ + ] Target:: [ http://hcsp.gov.sd/657/ ]
  1557. |_[ + ] Exploit::
  1558. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1559. |_[ + ] More details:: / - / , ISP:
  1560. |_[ + ] Found:: UNIDENTIFIED
  1561.  
  1562. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1563. |_[ + ] [ 16 / 100 ]-[10:38:32] [ - ]
  1564. |_[ + ] Target:: [ http://hcsp.gov.sd/إستمارة_رقم2/ ]
  1565. |_[ + ] Exploit::
  1566. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1567. |_[ + ] More details:: / - / , ISP:
  1568. |_[ + ] Found:: UNIDENTIFIED
  1569.  
  1570. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1571. |_[ + ] [ 17 / 100 ]-[10:38:33] [ - ]
  1572. |_[ + ] Target:: [ https://hcsp.gov.sd/2490/ ]
  1573. |_[ + ] Exploit::
  1574. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1575. |_[ + ] More details:: / - / , ISP:
  1576. |_[ + ] Found:: UNIDENTIFIED
  1577.  
  1578. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1579. |_[ + ] [ 18 / 100 ]-[10:38:34] [ - ]
  1580. |_[ + ] Target:: [ http://hcsp.gov.sd/تــــــهــــنــــــــــــــئـــة/ ]
  1581. |_[ + ] Exploit::
  1582. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1583. |_[ + ] More details:: / - / , ISP:
  1584. |_[ + ] Found:: UNIDENTIFIED
  1585.  
  1586. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1587. |_[ + ] [ 19 / 100 ]-[10:38:34] [ - ]
  1588. |_[ + ] Target:: [ http://hcsp.gov.sd/5/ ]
  1589. |_[ + ] Exploit::
  1590. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1591. |_[ + ] More details:: / - / , ISP:
  1592. |_[ + ] Found:: UNIDENTIFIED
  1593.  
  1594. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1595. |_[ + ] [ 20 / 100 ]-[10:38:35] [ - ]
  1596. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_0715/ ]
  1597. |_[ + ] Exploit::
  1598. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1599. |_[ + ] More details:: / - / , ISP:
  1600. |_[ + ] Found:: UNIDENTIFIED
  1601.  
  1602. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1603. |_[ + ] [ 21 / 100 ]-[10:38:35] [ - ]
  1604. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1061/ ]
  1605. |_[ + ] Exploit::
  1606. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1607. |_[ + ] More details:: / - / , ISP:
  1608. |_[ + ] Found:: UNIDENTIFIED
  1609.  
  1610. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1611. |_[ + ] [ 22 / 100 ]-[10:38:36] [ - ]
  1612. |_[ + ] Target:: [ http://hcsp.gov.sd/tur_5313/ ]
  1613. |_[ + ] Exploit::
  1614. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1615. |_[ + ] More details:: / - / , ISP:
  1616. |_[ + ] Found:: UNIDENTIFIED
  1617.  
  1618. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1619. |_[ + ] [ 23 / 100 ]-[10:38:37] [ - ]
  1620. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6377/ ]
  1621. |_[ + ] Exploit::
  1622. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1623. |_[ + ] More details:: / - / , ISP:
  1624. |_[ + ] Found:: UNIDENTIFIED
  1625.  
  1626. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1627. |_[ + ] [ 24 / 100 ]-[10:38:37] [ - ]
  1628. |_[ + ] Target:: [ https://hcsp.gov.sd/الرؤيا/ ]
  1629. |_[ + ] Exploit::
  1630. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1631. |_[ + ] More details:: / - / , ISP:
  1632. |_[ + ] Found:: UNIDENTIFIED
  1633.  
  1634. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1635. |_[ + ] [ 25 / 100 ]-[10:38:38] [ - ]
  1636. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_5954/ ]
  1637. |_[ + ] Exploit::
  1638. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1639. |_[ + ] More details:: / - / , ISP:
  1640. |_[ + ] Found:: UNIDENTIFIED
  1641.  
  1642. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1643. |_[ + ] [ 26 / 100 ]-[10:38:39] [ - ]
  1644. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6298/ ]
  1645. |_[ + ] Exploit::
  1646. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1647. |_[ + ] More details:: / - / , ISP:
  1648. |_[ + ] Found:: UNIDENTIFIED
  1649.  
  1650. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1651. |_[ + ] [ 27 / 100 ]-[10:38:39] [ - ]
  1652. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1174/ ]
  1653. |_[ + ] Exploit::
  1654. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1655. |_[ + ] More details:: / - / , ISP:
  1656. |_[ + ] Found:: UNIDENTIFIED
  1657.  
  1658. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1659. |_[ + ] [ 28 / 100 ]-[10:38:40] [ - ]
  1660. |_[ + ] Target:: [ http://hcsp.gov.sd/إستمارة_رقم1/ ]
  1661. |_[ + ] Exploit::
  1662. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1663. |_[ + ] More details:: / - / , ISP:
  1664. |_[ + ] Found:: UNIDENTIFIED
  1665.  
  1666. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1667. |_[ + ] [ 29 / 100 ]-[10:38:41] [ - ]
  1668. |_[ + ] Target:: [ http://hcsp.gov.sd/img_7649/ ]
  1669. |_[ + ] Exploit::
  1670. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1671. |_[ + ] More details:: / - / , ISP:
  1672. |_[ + ] Found:: UNIDENTIFIED
  1673.  
  1674. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1675. |_[ + ] [ 30 / 100 ]-[10:38:41] [ - ]
  1676. |_[ + ] Target:: [ http://hcsp.gov.sd/الاستثمار/ ]
  1677. |_[ + ] Exploit::
  1678. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1679. |_[ + ] More details:: / - / , ISP:
  1680. |_[ + ] Found:: UNIDENTIFIED
  1681.  
  1682. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1683. |_[ + ] [ 31 / 100 ]-[10:38:42] [ - ]
  1684. |_[ + ] Target:: [ http://hcsp.gov.sd/media/ ]
  1685. |_[ + ] Exploit::
  1686. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1687. |_[ + ] More details:: / - / , ISP:
  1688. |_[ + ] Found:: UNIDENTIFIED
  1689.  
  1690. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1691. |_[ + ] [ 32 / 100 ]-[10:38:43] [ - ]
  1692. |_[ + ] Target:: [ http://hcsp.gov.sd/عن-الخرطوم/ ]
  1693. |_[ + ] Exploit::
  1694. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1695. |_[ + ] More details:: / - / , ISP:
  1696. |_[ + ] Found:: UNIDENTIFIED
  1697.  
  1698. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1699. |_[ + ] [ 33 / 100 ]-[10:38:43] [ - ]
  1700. |_[ + ] Target:: [ http://hcsp.gov.sd/عن-السودان/ ]
  1701. |_[ + ] Exploit::
  1702. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1703. |_[ + ] More details:: / - / , ISP:
  1704. |_[ + ] Found:: UNIDENTIFIED
  1705.  
  1706. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1707. |_[ + ] [ 34 / 100 ]-[10:38:44] [ - ]
  1708. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/library/ ]
  1709. |_[ + ] Exploit::
  1710. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1711. |_[ + ] More details:: / - / , ISP:
  1712. |_[ + ] Found:: UNIDENTIFIED
  1713.  
  1714. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1715. |_[ + ] [ 35 / 100 ]-[10:38:45] [ - ]
  1716. |_[ + ] Target:: [ http://hcsp.gov.sd/5858-2/ ]
  1717. |_[ + ] Exploit::
  1718. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1719. |_[ + ] More details:: / - / , ISP:
  1720. |_[ + ] Found:: UNIDENTIFIED
  1721.  
  1722. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1723. |_[ + ] [ 36 / 100 ]-[10:38:45] [ - ]
  1724. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/courses/ ]
  1725. |_[ + ] Exploit::
  1726. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1727. |_[ + ] More details:: / - / , ISP:
  1728. |_[ + ] Found:: UNIDENTIFIED
  1729.  
  1730. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1731. |_[ + ] [ 37 / 100 ]-[10:38:46] [ - ]
  1732. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/ ]
  1733. |_[ + ] Exploit::
  1734. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1735. |_[ + ] More details:: / - / , ISP:
  1736. |_[ + ] Found:: UNIDENTIFIED
  1737.  
  1738. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1739. |_[ + ] [ 38 / 100 ]-[10:38:47] [ - ]
  1740. |_[ + ] Target:: [ https://hcsp.gov.sd/5701-2/ ]
  1741. |_[ + ] Exploit::
  1742. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1743. |_[ + ] More details:: / - / , ISP:
  1744. |_[ + ] Found:: UNIDENTIFIED
  1745.  
  1746. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1747. |_[ + ] [ 39 / 100 ]-[10:38:48] [ - ]
  1748. |_[ + ] Target:: [ http://hcsp.gov.sd/4-2/ ]
  1749. |_[ + ] Exploit::
  1750. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1751. |_[ + ] More details:: / - / , ISP:
  1752. |_[ + ] Found:: UNIDENTIFIED
  1753.  
  1754. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1755. |_[ + ] [ 40 / 100 ]-[10:38:48] [ - ]
  1756. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/researches/ ]
  1757. |_[ + ] Exploit::
  1758. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1759. |_[ + ] More details:: / - / , ISP:
  1760. |_[ + ] Found:: UNIDENTIFIED
  1761.  
  1762. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1763. |_[ + ] [ 41 / 100 ]-[10:38:49] [ - ]
  1764. |_[ + ] Target:: [ http://hcsp.gov.sd/6-2/ ]
  1765. |_[ + ] Exploit::
  1766. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1767. |_[ + ] More details:: / - / , ISP:
  1768. |_[ + ] Found:: UNIDENTIFIED
  1769.  
  1770. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1771. |_[ + ] [ 42 / 100 ]-[10:38:50] [ - ]
  1772. |_[ + ] Target:: [ http://hcsp.gov.sd/الخطة-الاستراتيجية/ ]
  1773. |_[ + ] Exploit::
  1774. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1775. |_[ + ] More details:: / - / , ISP:
  1776. |_[ + ] Found:: UNIDENTIFIED
  1777.  
  1778. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1779. |_[ + ] [ 43 / 100 ]-[10:38:50] [ - ]
  1780. |_[ + ] Target:: [ http://hcsp.gov.sd/إتصل-بنا/ ]
  1781. |_[ + ] Exploit::
  1782. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1783. |_[ + ] More details:: / - / , ISP:
  1784. |_[ + ] Found:: UNIDENTIFIED
  1785.  
  1786. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1787. |_[ + ] [ 44 / 100 ]-[10:38:51] [ - ]
  1788. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_6500/ ]
  1789. |_[ + ] Exploit::
  1790. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1791. |_[ + ] More details:: / - / , ISP:
  1792. |_[ + ] Found:: UNIDENTIFIED
  1793.  
  1794. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1795. |_[ + ] [ 45 / 100 ]-[10:38:52] [ - ]
  1796. |_[ + ] Target:: [ http://hcsp.gov.sd/3-6/ ]
  1797. |_[ + ] Exploit::
  1798. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1799. |_[ + ] More details:: / - / , ISP:
  1800. |_[ + ] Found:: UNIDENTIFIED
  1801.  
  1802. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1803. |_[ + ] [ 46 / 100 ]-[10:38:52] [ - ]
  1804. |_[ + ] Target:: [ https://hcsp.gov.sd/دليل-المجلس/ ]
  1805. |_[ + ] Exploit::
  1806. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1807. |_[ + ] More details:: / - / , ISP:
  1808. |_[ + ] Found:: UNIDENTIFIED
  1809.  
  1810. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1811. |_[ + ] [ 47 / 100 ]-[10:38:53] [ - ]
  1812. |_[ + ] Target:: [ http://hcsp.gov.sd/5855-2/ ]
  1813. |_[ + ] Exploit::
  1814. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1815. |_[ + ] More details:: / - / , ISP:
  1816. |_[ + ] Found:: UNIDENTIFIED
  1817.  
  1818. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1819. |_[ + ] [ 48 / 100 ]-[10:38:54] [ - ]
  1820. |_[ + ] Target:: [ http://hcsp.gov.sd/2-5/ ]
  1821. |_[ + ] Exploit::
  1822. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1823. |_[ + ] More details:: / - / , ISP:
  1824. |_[ + ] Found:: UNIDENTIFIED
  1825.  
  1826. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1827. |_[ + ] [ 49 / 100 ]-[10:38:54] [ - ]
  1828. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_0097/ ]
  1829. |_[ + ] Exploit::
  1830. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1831. |_[ + ] More details:: / - / , ISP:
  1832. |_[ + ] Found:: UNIDENTIFIED
  1833.  
  1834. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1835. |_[ + ] [ 50 / 100 ]-[10:38:55] [ - ]
  1836. |_[ + ] Target:: [ http://hcsp.gov.sd/1582/dsc_0072/ ]
  1837. |_[ + ] Exploit::
  1838. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1839. |_[ + ] More details:: / - / , ISP:
  1840. |_[ + ] Found:: UNIDENTIFIED
  1841.  
  1842. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1843. |_[ + ] [ 51 / 100 ]-[10:38:56] [ - ]
  1844. |_[ + ] Target:: [ http://hcsp.gov.sd/5023-2/ ]
  1845. |_[ + ] Exploit::
  1846. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1847. |_[ + ] More details:: / - / , ISP:
  1848. |_[ + ] Found:: UNIDENTIFIED
  1849.  
  1850. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1851. |_[ + ] [ 52 / 100 ]-[10:38:56] [ - ]
  1852. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_4063/ ]
  1853. |_[ + ] Exploit::
  1854. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1855. |_[ + ] More details:: / - / , ISP:
  1856. |_[ + ] Found:: UNIDENTIFIED
  1857.  
  1858. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1859. |_[ + ] [ 53 / 100 ]-[10:38:57] [ - ]
  1860. |_[ + ] Target:: [ http://hcsp.gov.sd/تحليل-السياسات/ ]
  1861. |_[ + ] Exploit::
  1862. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1863. |_[ + ] More details:: / - / , ISP:
  1864. |_[ + ] Found:: UNIDENTIFIED
  1865.  
  1866. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1867. |_[ + ] [ 54 / 100 ]-[10:38:57] [ - ]
  1868. |_[ + ] Target:: [ http://hcsp.gov.sd/2-13/ ]
  1869. |_[ + ] Exploit::
  1870. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1871. |_[ + ] More details:: / - / , ISP:
  1872. |_[ + ] Found:: UNIDENTIFIED
  1873.  
  1874. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1875. |_[ + ] [ 55 / 100 ]-[10:38:58] [ - ]
  1876. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_5994/ ]
  1877. |_[ + ] Exploit::
  1878. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1879. |_[ + ] More details:: / - / , ISP:
  1880. |_[ + ] Found:: UNIDENTIFIED
  1881.  
  1882. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1883. |_[ + ] [ 56 / 100 ]-[10:38:59] [ - ]
  1884. |_[ + ] Target:: [ http://hcsp.gov.sd/مجلة-الاستراتيجي/ ]
  1885. |_[ + ] Exploit::
  1886. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1887. |_[ + ] More details:: / - / , ISP:
  1888. |_[ + ] Found:: UNIDENTIFIED
  1889.  
  1890. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1891. |_[ + ] [ 57 / 100 ]-[10:39:00] [ - ]
  1892. |_[ + ] Target:: [ https://hcsp.gov.sd/المكتبة-التفاعيلة33/ ]
  1893. |_[ + ] Exploit::
  1894. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1895. |_[ + ] More details:: / - / , ISP:
  1896. |_[ + ] Found:: UNIDENTIFIED
  1897.  
  1898. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1899. |_[ + ] [ 58 / 100 ]-[10:39:00] [ - ]
  1900. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_6513/ ]
  1901. |_[ + ] Exploit::
  1902. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1903. |_[ + ] More details:: / - / , ISP:
  1904. |_[ + ] Found:: UNIDENTIFIED
  1905.  
  1906. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1907. |_[ + ] [ 59 / 100 ]-[10:39:01] [ - ]
  1908. |_[ + ] Target:: [ http://hcsp.gov.sd/5-8/ ]
  1909. |_[ + ] Exploit::
  1910. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1911. |_[ + ] More details:: / - / , ISP:
  1912. |_[ + ] Found:: UNIDENTIFIED
  1913.  
  1914. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1915. |_[ + ] [ 60 / 100 ]-[10:39:02] [ - ]
  1916. |_[ + ] Target:: [ http://hcsp.gov.sd/رؤية-الولاية/ ]
  1917. |_[ + ] Exploit::
  1918. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1919. |_[ + ] More details:: / - / , ISP:
  1920. |_[ + ] Found:: UNIDENTIFIED
  1921.  
  1922. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1923. |_[ + ] [ 61 / 100 ]-[10:39:02] [ - ]
  1924. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_5984/ ]
  1925. |_[ + ] Exploit::
  1926. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1927. |_[ + ] More details:: / - / , ISP:
  1928. |_[ + ] Found:: UNIDENTIFIED
  1929.  
  1930. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1931. |_[ + ] [ 62 / 100 ]-[10:39:03] [ - ]
  1932. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_0035/ ]
  1933. |_[ + ] Exploit::
  1934. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1935. |_[ + ] More details:: / - / , ISP:
  1936. |_[ + ] Found:: UNIDENTIFIED
  1937.  
  1938. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1939. |_[ + ] [ 63 / 100 ]-[10:39:03] [ - ]
  1940. |_[ + ] Target:: [ http://hcsp.gov.sd/علم-الإجتماع/ ]
  1941. |_[ + ] Exploit::
  1942. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1943. |_[ + ] More details:: / - / , ISP:
  1944. |_[ + ] Found:: UNIDENTIFIED
  1945.  
  1946. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1947. |_[ + ] [ 64 / 100 ]-[10:39:04] [ - ]
  1948. |_[ + ] Target:: [ https://hcsp.gov.sd/التقارير-الاستراتيجية/ ]
  1949. |_[ + ] Exploit::
  1950. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1951. |_[ + ] More details:: / - / , ISP:
  1952. |_[ + ] Found:: UNIDENTIFIED
  1953.  
  1954. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1955. |_[ + ] [ 65 / 100 ]-[10:39:05] [ - ]
  1956. |_[ + ] Target:: [ http://hcsp.gov.sd/media/album/ ]
  1957. |_[ + ] Exploit::
  1958. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1959. |_[ + ] More details:: / - / , ISP:
  1960. |_[ + ] Found:: UNIDENTIFIED
  1961.  
  1962. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1963. |_[ + ] [ 66 / 100 ]-[10:39:06] [ - ]
  1964. |_[ + ] Target:: [ https://hcsp.gov.sd/magazine/ ]
  1965. |_[ + ] Exploit::
  1966. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1967. |_[ + ] More details:: / - / , ISP:
  1968. |_[ + ] Found:: UNIDENTIFIED
  1969.  
  1970. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1971. |_[ + ] [ 67 / 100 ]-[10:39:06] [ - ]
  1972. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/الخطة-الإستراتيجية/ ]
  1973. |_[ + ] Exploit::
  1974. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  1975. |_[ + ] More details:: / - / , ISP:
  1976. |_[ + ] Found:: UNIDENTIFIED
  1977.  
  1978. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1979. |_[ + ] [ 68 / 100 ]-[10:39:07] [ - ]
  1980. |_[ + ] Target:: [ https://hcsp.gov.sd/محلية-كرري-ت/ ]
  1981. |_[ + ] Exploit::
  1982. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1983. |_[ + ] More details:: / - / , ISP:
  1984. |_[ + ] Found:: UNIDENTIFIED
  1985.  
  1986. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1987. |_[ + ] [ 69 / 100 ]-[10:39:08] [ - ]
  1988. |_[ + ] Target:: [ https://hcsp.gov.sd/مسابقة-تصميم-شعار/ ]
  1989. |_[ + ] Exploit::
  1990. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1991. |_[ + ] More details:: / - / , ISP:
  1992. |_[ + ] Found:: UNIDENTIFIED
  1993.  
  1994. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1995. |_[ + ] [ 70 / 100 ]-[10:39:09] [ - ]
  1996. |_[ + ] Target:: [ https://hcsp.gov.sd/en/ ]
  1997. |_[ + ] Exploit::
  1998. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  1999. |_[ + ] More details:: / - / , ISP:
  2000. |_[ + ] Found:: UNIDENTIFIED
  2001.  
  2002. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2003. |_[ + ] [ 71 / 100 ]-[10:39:09] [ - ]
  2004. |_[ + ] Target:: [ http://hcsp.gov.sd/روابط-ذات-صلة/ ]
  2005. |_[ + ] Exploit::
  2006. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2007. |_[ + ] More details:: / - / , ISP:
  2008. |_[ + ] Found:: UNIDENTIFIED
  2009.  
  2010. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2011. |_[ + ] [ 72 / 100 ]-[10:39:10] [ - ]
  2012. |_[ + ] Target:: [ http://hcsp.gov.sd/منظومة-القيم-والمرتكزات/ ]
  2013. |_[ + ] Exploit::
  2014. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2015. |_[ + ] More details:: / - / , ISP:
  2016. |_[ + ] Found:: UNIDENTIFIED
  2017.  
  2018. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2019. |_[ + ] [ 73 / 100 ]-[10:39:11] [ - ]
  2020. |_[ + ] Target:: [ http://hcsp.gov.sd/مؤتمر-الخدمه-الوطنية/ ]
  2021. |_[ + ] Exploit::
  2022. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2023. |_[ + ] More details:: / - / , ISP:
  2024. |_[ + ] Found:: UNIDENTIFIED
  2025.  
  2026. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2027. |_[ + ] [ 74 / 100 ]-[10:39:11] [ - ]
  2028. |_[ + ] Target:: [ https://hcsp.gov.sd/الاطفال-فاقدى-السند/ ]
  2029. |_[ + ] Exploit::
  2030. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2031. |_[ + ] More details:: / - / , ISP:
  2032. |_[ + ] Found:: UNIDENTIFIED
  2033.  
  2034. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2035. |_[ + ] [ 75 / 100 ]-[10:39:12] [ - ]
  2036. |_[ + ] Target:: [ http://hcsp.gov.sd/مكتبة-الصور-2/ ]
  2037. |_[ + ] Exploit::
  2038. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2039. |_[ + ] More details:: / - / , ISP:
  2040. |_[ + ] Found:: UNIDENTIFIED
  2041.  
  2042. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2043. |_[ + ] [ 76 / 100 ]-[10:39:13] [ - ]
  2044. |_[ + ] Target:: [ http://hcsp.gov.sd/زيارة-الوزير-للمحليات/ ]
  2045. |_[ + ] Exploit::
  2046. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2047. |_[ + ] More details:: / - / , ISP:
  2048. |_[ + ] Found:: UNIDENTIFIED
  2049.  
  2050. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2051. |_[ + ] [ 77 / 100 ]-[10:39:13] [ - ]
  2052. |_[ + ] Target:: [ http://hcsp.gov.sd/المكتبة-التفاعيلة33/الكتب/ ]
  2053. |_[ + ] Exploit::
  2054. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2055. |_[ + ] More details:: / - / , ISP:
  2056. |_[ + ] Found:: UNIDENTIFIED
  2057.  
  2058. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2059. |_[ + ] [ 78 / 100 ]-[10:39:14] [ - ]
  2060. |_[ + ] Target:: [ http://hcsp.gov.sd/التخطيط-الإستراتيجي-السياسي/ ]
  2061. |_[ + ] Exploit::
  2062. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2063. |_[ + ] More details:: / - / , ISP:
  2064. |_[ + ] Found:: UNIDENTIFIED
  2065.  
  2066. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2067. |_[ + ] [ 79 / 100 ]-[10:39:15] [ - ]
  2068. |_[ + ] Target:: [ http://hcsp.gov.sd/عن-السودان/tur_5309/ ]
  2069. |_[ + ] Exploit::
  2070. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2071. |_[ + ] More details:: / - / , ISP:
  2072. |_[ + ] Found:: UNIDENTIFIED
  2073.  
  2074. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2075. |_[ + ] [ 80 / 100 ]-[10:39:15] [ - ]
  2076. |_[ + ] Target:: [ http://hcsp.gov.sd/imagesgallery/ورشة-التعليم/ ]
  2077. |_[ + ] Exploit::
  2078. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2079. |_[ + ] More details:: / - / , ISP:
  2080. |_[ + ] Found:: UNIDENTIFIED
  2081.  
  2082. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2083. |_[ + ] [ 81 / 100 ]-[10:39:16] [ - ]
  2084. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_6470-2/ ]
  2085. |_[ + ] Exploit::
  2086. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2087. |_[ + ] More details:: / - / , ISP:
  2088. |_[ + ] Found:: UNIDENTIFIED
  2089.  
  2090. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2091. |_[ + ] [ 82 / 100 ]-[10:39:17] [ - ]
  2092. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/courses/page/5/ ]
  2093. |_[ + ] Exploit::
  2094. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2095. |_[ + ] More details:: / - / , ISP:
  2096. |_[ + ] Found:: UNIDENTIFIED
  2097.  
  2098. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2099. |_[ + ] [ 83 / 100 ]-[10:39:17] [ - ]
  2100. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/45/ ]
  2101. |_[ + ] Exploit::
  2102. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2103. |_[ + ] More details:: / - / , ISP:
  2104. |_[ + ] Found:: UNIDENTIFIED
  2105.  
  2106. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2107. |_[ + ] [ 84 / 100 ]-[10:39:18] [ - ]
  2108. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/48/ ]
  2109. |_[ + ] Exploit::
  2110. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2111. |_[ + ] More details:: / - / , ISP:
  2112. |_[ + ] Found:: UNIDENTIFIED
  2113.  
  2114. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2115. |_[ + ] [ 85 / 100 ]-[10:39:19] [ - ]
  2116. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/47/ ]
  2117. |_[ + ] Exploit::
  2118. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2119. |_[ + ] More details:: / - / , ISP:
  2120. |_[ + ] Found:: UNIDENTIFIED
  2121.  
  2122. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2123. |_[ + ] [ 86 / 100 ]-[10:39:20] [ - ]
  2124. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/108/ ]
  2125. |_[ + ] Exploit::
  2126. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2127. |_[ + ] More details:: / - / , ISP:
  2128. |_[ + ] Found:: UNIDENTIFIED
  2129.  
  2130. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2131. |_[ + ] [ 87 / 100 ]-[10:39:20] [ - ]
  2132. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/92/ ]
  2133. |_[ + ] Exploit::
  2134. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2135. |_[ + ] More details:: / - / , ISP:
  2136. |_[ + ] Found:: UNIDENTIFIED
  2137.  
  2138. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2139. |_[ + ] [ 88 / 100 ]-[10:39:21] [ - ]
  2140. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/researches/دراسات-إقتصادية/ ]
  2141. |_[ + ] Exploit::
  2142. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2143. |_[ + ] More details:: / - / , ISP:
  2144. |_[ + ] Found:: UNIDENTIFIED
  2145.  
  2146. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2147. |_[ + ] [ 89 / 100 ]-[10:39:22] [ - ]
  2148. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/60/ ]
  2149. |_[ + ] Exploit::
  2150. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2151. |_[ + ] More details:: / - / , ISP:
  2152. |_[ + ] Found:: UNIDENTIFIED
  2153.  
  2154. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2155. |_[ + ] [ 90 / 100 ]-[10:39:23] [ - ]
  2156. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/8/ ]
  2157. |_[ + ] Exploit::
  2158. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2159. |_[ + ] More details:: / - / , ISP:
  2160. |_[ + ] Found:: UNIDENTIFIED
  2161.  
  2162. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2163. |_[ + ] [ 91 / 100 ]-[10:39:23] [ - ]
  2164. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/111/ ]
  2165. |_[ + ] Exploit::
  2166. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2167. |_[ + ] More details:: / - / , ISP:
  2168. |_[ + ] Found:: UNIDENTIFIED
  2169.  
  2170. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2171. |_[ + ] [ 92 / 100 ]-[10:39:24] [ - ]
  2172. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/78/ ]
  2173. |_[ + ] Exploit::
  2174. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2175. |_[ + ] More details:: / - / , ISP:
  2176. |_[ + ] Found:: UNIDENTIFIED
  2177.  
  2178. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2179. |_[ + ] [ 93 / 100 ]-[10:39:24] [ - ]
  2180. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/researches/page/4/ ]
  2181. |_[ + ] Exploit::
  2182. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2183. |_[ + ] More details:: / - / , ISP:
  2184. |_[ + ] Found:: UNIDENTIFIED
  2185.  
  2186. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2187. |_[ + ] [ 94 / 100 ]-[10:39:25] [ - ]
  2188. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/20/ ]
  2189. |_[ + ] Exploit::
  2190. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2191. |_[ + ] More details:: / - / , ISP:
  2192. |_[ + ] Found:: UNIDENTIFIED
  2193.  
  2194. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2195. |_[ + ] [ 95 / 100 ]-[10:39:26] [ - ]
  2196. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/21/ ]
  2197. |_[ + ] Exploit::
  2198. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2199. |_[ + ] More details:: / - / , ISP:
  2200. |_[ + ] Found:: UNIDENTIFIED
  2201.  
  2202. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2203. |_[ + ] [ 96 / 100 ]-[10:39:26] [ - ]
  2204. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/100/ ]
  2205. |_[ + ] Exploit::
  2206. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2207. |_[ + ] More details:: / - / , ISP:
  2208. |_[ + ] Found:: UNIDENTIFIED
  2209.  
  2210. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2211. |_[ + ] [ 97 / 100 ]-[10:39:27] [ - ]
  2212. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/7/ ]
  2213. |_[ + ] Exploit::
  2214. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2215. |_[ + ] More details:: / - / , ISP:
  2216. |_[ + ] Found:: UNIDENTIFIED
  2217.  
  2218. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2219. |_[ + ] [ 98 / 100 ]-[10:39:27] [ - ]
  2220. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/6/ ]
  2221. |_[ + ] Exploit::
  2222. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2223. |_[ + ] More details:: / - / , ISP:
  2224. |_[ + ] Found:: UNIDENTIFIED
  2225.  
  2226. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2227. |_[ + ] [ 99 / 100 ]-[10:39:28] [ - ]
  2228. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/26/ ]
  2229. |_[ + ] Exploit::
  2230. |_[ + ] Information Server:: HTTP/2 403 , , IP:77.72.0.138:443
  2231. |_[ + ] More details:: / - / , ISP:
  2232. |_[ + ] Found:: UNIDENTIFIED
  2233.  
  2234. [ INFO ] [ Shutting down ]
  2235. [ INFO ] [ End of process INURLBR at [13-09-2019 10:39:28]
  2236. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  2237. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/hcsp.gov.sd/output/inurlbr-hcsp.gov.sd ]
  2238. |_________________________________________________________________________________________
  2239.  
  2240. \_________________________________________________________________________________________/
  2241. #######################################################################################################################################
  2242. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:39 EDT
  2243. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  2244. Host is up (0.12s latency).
  2245. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  2246.  
  2247. PORT STATE SERVICE VERSION
  2248. 110/tcp open pop3?
  2249. | fingerprint-strings:
  2250. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  2251. | Your connection to this server has been blocked in this server's firewall.
  2252. | need to contact the server owner or hosting provider for further information.
  2253. | Your blocked IP address is: 176.113.74.28
  2254. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  2255. | pop3-brute:
  2256. | Accounts: No valid accounts found
  2257. | Statistics: Performed 5 guesses in 1 seconds, average tps: 5.0
  2258. |_ ERROR: Failed to make a pop-connection.
  2259. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
  2260. SF-Port110-TCP:V=7.80%I=7%D=9/13%Time=5D7BAA24%P=x86_64-pc-linux-gnu%r(NUL
  2261. SF:L,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  2262. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  2263. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  2264. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  2265. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  2266. SF:dhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20
  2267. SF:this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20f
  2268. SF:irewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20
  2269. SF:or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x2
  2270. SF:0blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server'
  2271. SF:s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest
  2272. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  2273. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  2274. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  2275. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  2276. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  2277. SF:hosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20th
  2278. SF:is\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fir
  2279. SF:ewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or
  2280. SF:\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20b
  2281. SF:locked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\
  2282. SF:x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,
  2283. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  2284. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  2285. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  2286. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  2287. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  2288. SF:osting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x
  2289. SF:20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewal
  2290. SF:l\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20
  2291. SF:hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20block
  2292. SF:ed\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20h
  2293. SF:ostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  2294. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  2295. Device type: general purpose|specialized|storage-misc
  2296. Running (JUST GUESSING): Linux 3.X|4.X (91%), Crestron 2-Series (87%), HP embedded (85%)
  2297. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3
  2298. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), Linux 3.2 - 4.9 (91%), Linux 3.18 (89%), Crestron XPanel control system (87%), Linux 3.16 (86%), HP P2000 G3 NAS device (85%)
  2299. No exact OS matches for host (test conditions non-ideal).
  2300. Network Distance: 15 hops
  2301.  
  2302. TRACEROUTE (using port 443/tcp)
  2303. HOP RTT ADDRESS
  2304. 1 59.99 ms 10.244.204.1
  2305. 2 82.11 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  2306. 3 82.15 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  2307. 4 82.15 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  2308. 5 82.15 ms motl-b1-link.telia.net (62.115.162.41)
  2309. 6 82.18 ms nyk-bb4-link.telia.net (62.115.134.52)
  2310. 7 82.21 ms ash-bb3-link.telia.net (62.115.141.244)
  2311. 8 82.21 ms ash-b1-link.telia.net (62.115.143.79)
  2312. 9 82.22 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  2313. 10 34.46 ms ash-eqx-01gw.voxility.net (5.254.81.129)
  2314. 11 64.44 ms ash-eqx-01c.voxility.net (37.221.173.74)
  2315. 12 ...
  2316. 13 138.06 ms lon-tel-01c.voxility.net (5.254.112.185)
  2317. 14 ...
  2318. 15 116.56 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  2319. #######################################################################################################################################
  2320. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:39 EDT
  2321. NSE: Loaded 164 scripts for scanning.
  2322. NSE: Script Pre-scanning.
  2323. Initiating NSE at 10:39
  2324. Completed NSE at 10:39, 0.00s elapsed
  2325. Initiating NSE at 10:39
  2326. Completed NSE at 10:39, 0.00s elapsed
  2327. Initiating Parallel DNS resolution of 1 host. at 10:39
  2328. Completed Parallel DNS resolution of 1 host. at 10:39, 0.03s elapsed
  2329. Initiating SYN Stealth Scan at 10:39
  2330. Scanning hcsp.gov.sd (77.72.0.138) [1 port]
  2331. Discovered open port 443/tcp on 77.72.0.138
  2332. Completed SYN Stealth Scan at 10:39, 0.14s elapsed (1 total ports)
  2333. Initiating Service scan at 10:39
  2334. Scanning 1 service on hcsp.gov.sd (77.72.0.138)
  2335. Completed Service scan at 10:40, 12.72s elapsed (1 service on 1 host)
  2336. Initiating OS detection (try #1) against hcsp.gov.sd (77.72.0.138)
  2337. Retrying OS detection (try #2) against hcsp.gov.sd (77.72.0.138)
  2338. Initiating Traceroute at 10:40
  2339. Completed Traceroute at 10:40, 3.09s elapsed
  2340. Initiating Parallel DNS resolution of 13 hosts. at 10:40
  2341. Completed Parallel DNS resolution of 13 hosts. at 10:40, 0.16s elapsed
  2342. NSE: Script scanning 77.72.0.138.
  2343. Initiating NSE at 10:40
  2344. Completed NSE at 10:41, 71.79s elapsed
  2345. Initiating NSE at 10:41
  2346. Completed NSE at 10:41, 1.18s elapsed
  2347. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  2348. Host is up (0.11s latency).
  2349. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  2350.  
  2351. PORT STATE SERVICE VERSION
  2352. 443/tcp open ssl/http LiteSpeed httpd
  2353. | http-brute:
  2354. |_ Path "/" does not require authentication
  2355. |_http-chrono: Request times for /; avg: 1096.17ms; min: 682.35ms; max: 1724.74ms
  2356. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  2357. |_http-date: Fri, 13 Sep 2019 14:40:14 GMT; -8s from local time.
  2358. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  2359. |_http-dombased-xss: Couldn't find any DOM based XSS.
  2360. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  2361. | http-errors:
  2362. | Spidering limited to: maxpagecount=40; withinhost=hcsp.gov.sd
  2363. | Found the following error pages:
  2364. |
  2365. | Error Code: 403
  2366. |_ http://hcsp.gov.sd:443/
  2367. |_http-feed: Couldn't find any feeds.
  2368. |_http-fetch: Please enter the complete path of the directory to save data in.
  2369. | http-headers:
  2370. | Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
  2371. | Pragma: no-cache
  2372. | Content-Type: text/html
  2373. | Content-Length: 1139
  2374. | Date: Fri, 13 Sep 2019 14:40:33 GMT
  2375. | Server: LiteSpeed
  2376. | Vary: User-Agent
  2377. | Alt-Svc: quic=":8887"; ma=2592000; v="35,39,43,44"
  2378. | Connection: close
  2379. |
  2380. |_ (Request type: GET)
  2381. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  2382. |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
  2383. | http-methods:
  2384. |_ Supported Methods: GET HEAD POST OPTIONS
  2385. |_http-mobileversion-checker: No mobile version detected.
  2386. |_http-passwd: ERROR: Script execution failed (use -d to debug)
  2387. | http-security-headers:
  2388. | Strict_Transport_Security:
  2389. |_ HSTS not configured in HTTPS Server
  2390. |_http-server-header: LiteSpeed
  2391. | http-sitemap-generator:
  2392. | Directory structure:
  2393. | Longest directory structure:
  2394. | Depth: 0
  2395. | Dir: /
  2396. | Total files found (by extension):
  2397. |_
  2398. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  2399. |_http-title: 403 Forbidden
  2400. |_http-traceroute: ERROR: Script execution failed (use -d to debug)
  2401. |_http-userdir-enum: Potential Users: root, admin, administrator, webadmin, sysadmin, netadmin, guest, user, web, test
  2402. | http-vhosts:
  2403. | 65 names had status 403
  2404. | 19 names had status ERROR
  2405. |_43 names had status 301
  2406. |_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
  2407. | http-waf-detect: IDS/IPS/WAF detected:
  2408. |_hcsp.gov.sd:443/?p4yl04d3=<script>alert(document.cookie)</script>
  2409. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
  2410. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  2411. |_http-xssed: No previously reported XSS vuln.
  2412. |_vulscan: ERROR: Script execution failed (use -d to debug)
  2413. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  2414. Device type: general purpose|specialized|storage-misc
  2415. Running (JUST GUESSING): Linux 3.X|4.X (91%), Crestron 2-Series (87%), HP embedded (85%), Oracle VM Server 3.X (85%)
  2416. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3 cpe:/o:oracle:vm_server:3.4.2 cpe:/o:linux:linux_kernel:4.1
  2417. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), Linux 3.18 (91%), Linux 3.2 - 4.9 (91%), Crestron XPanel control system (87%), Linux 3.16 (86%), HP P2000 G3 NAS device (85%), Oracle VM Server 3.4.2 (Linux 4.1) (85%)
  2418. No exact OS matches for host (test conditions non-ideal).
  2419. Uptime guess: 27.433 days (since Sat Aug 17 00:17:25 2019)
  2420. Network Distance: 15 hops
  2421. TCP Sequence Prediction: Difficulty=259 (Good luck!)
  2422. IP ID Sequence Generation: All zeros
  2423.  
  2424. TRACEROUTE (using port 443/tcp)
  2425. HOP RTT ADDRESS
  2426. 1 58.11 ms 10.244.204.1
  2427. 2 79.17 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  2428. 3 79.20 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  2429. 4 79.18 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  2430. 5 79.15 ms motl-b1-link.telia.net (62.115.162.41)
  2431. 6 79.25 ms nyk-bb4-link.telia.net (62.115.134.52)
  2432. 7 79.33 ms ash-bb3-link.telia.net (62.115.141.244)
  2433. 8 79.33 ms ash-b1-link.telia.net (213.155.136.39)
  2434. 9 79.41 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  2435. 10 37.46 ms ash-eqx-01gw.voxility.net (5.254.81.129)
  2436. 11 58.05 ms ash-eqx-01c.voxility.net (37.221.173.74)
  2437. 12 ...
  2438. 13 139.56 ms lon-tel-01c.voxility.net (5.254.112.185)
  2439. 14 ...
  2440. 15 120.10 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  2441.  
  2442. NSE: Script Post-scanning.
  2443. Initiating NSE at 10:41
  2444. Completed NSE at 10:41, 0.00s elapsed
  2445. Initiating NSE at 10:41
  2446. Completed NSE at 10:41, 0.00s elapsed
  2447. #######################################################################################################################################
  2448. HTTP/2 200
  2449. content-type: text/html; charset=UTF-8
  2450. date: Fri, 13 Sep 2019 14:43:49 GMT
  2451. server: LiteSpeed
  2452. vary: User-Agent
  2453. alt-svc: quic=":8887"; ma=2592000; v="35,39,43,44"
  2454.  
  2455. HTTP/1.1 200 OK
  2456. Content-Type: text/html; charset=UTF-8
  2457. Date: Fri, 13 Sep 2019 14:43:49 GMT
  2458. Server: LiteSpeed
  2459. Vary: User-Agent
  2460. Alt-Svc: quic=":8887"; ma=2592000; v="35,39,43,44"
  2461. Connection: Keep-Alive
  2462. #######################################################################################################################################
  2463. Version: 1.11.13-static
  2464. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  2465.  
  2466. Connected to 77.72.0.138
  2467.  
  2468. Testing SSL server hcsp.gov.sd on port 443 using SNI name hcsp.gov.sd
  2469.  
  2470. TLS Fallback SCSV:
  2471. Server supports TLS Fallback SCSV
  2472.  
  2473. TLS renegotiation:
  2474. Secure session renegotiation supported
  2475.  
  2476. TLS Compression:
  2477. Compression disabled
  2478.  
  2479. Heartbleed:
  2480. TLS 1.2 not vulnerable to heartbleed
  2481. TLS 1.1 not vulnerable to heartbleed
  2482. TLS 1.0 not vulnerable to heartbleed
  2483.  
  2484. Supported Server Cipher(s):
  2485. Preferred TLSv1.2 128 bits ECDHE-RSA-AES128-GCM-SHA256 Curve P-256 DHE 256
  2486. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
  2487. Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  2488. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  2489. Preferred TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  2490. Accepted TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  2491. Preferred TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  2492. Accepted TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  2493.  
  2494. SSL Certificate:
  2495. Signature Algorithm: sha256WithRSAEncryption
  2496. RSA Key Strength: 2048
  2497.  
  2498. Subject: hcsp.gov.sd
  2499. Altnames: DNS:hcsp.gov.sd, DNS:www.hcsp.gov.sd
  2500. Issuer: Let's Encrypt Authority X3
  2501.  
  2502. Not valid before: Aug 21 09:17:32 2019 GMT
  2503. Not valid after: Nov 19 09:17:32 2019 GMT
  2504. #######################################################################################################################################
  2505. ------------------------------------------------------------------------------------------------------------------------
  2506.  
  2507. [ ! ] Starting SCANNER INURLBR 2.1 at [13-09-2019 10:44:29]
  2508. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  2509. It is the end user's responsibility to obey all applicable local, state and federal laws.
  2510. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  2511.  
  2512. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/hcsp.gov.sd/output/inurlbr-hcsp.gov.sd ]
  2513. [ INFO ][ DORK ]::[ site:hcsp.gov.sd ]
  2514. [ INFO ][ SEARCHING ]:: {
  2515. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.com.ng ]
  2516.  
  2517. [ INFO ][ SEARCHING ]::
  2518. -[:::]
  2519. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  2520.  
  2521. [ INFO ][ SEARCHING ]::
  2522. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  2523. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.cz ID: 006688160405527839966:yhpefuwybre ]
  2524.  
  2525. [ INFO ][ SEARCHING ]::
  2526. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  2527.  
  2528. [ INFO ][ TOTAL FOUND VALUES ]:: [ 100 ]
  2529.  
  2530.  
  2531. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2532. |_[ + ] [ 0 / 100 ]-[10:44:41] [ - ]
  2533. |_[ + ] Target:: [ https://hcsp.gov.sd/ ]
  2534. |_[ + ] Exploit::
  2535. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2536. |_[ + ] More details:: / - / , ISP:
  2537. |_[ + ] Found:: UNIDENTIFIED
  2538.  
  2539. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2540. |_[ + ] [ 1 / 100 ]-[10:44:42] [ - ]
  2541. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/ ]
  2542. |_[ + ] Exploit::
  2543. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2544. |_[ + ] More details:: / - / , ISP:
  2545. |_[ + ] Found:: UNIDENTIFIED
  2546.  
  2547. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2548. |_[ + ] [ 2 / 100 ]-[10:44:43] [ - ]
  2549. |_[ + ] Target:: [ https://hcsp.gov.sd/2069/ ]
  2550. |_[ + ] Exploit::
  2551. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2552. |_[ + ] More details:: / - / , ISP:
  2553. |_[ + ] Found:: UNIDENTIFIED
  2554.  
  2555. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2556. |_[ + ] [ 3 / 100 ]-[10:44:44] [ - ]
  2557. |_[ + ] Target:: [ https://hcsp.gov.sd/2062/ ]
  2558. |_[ + ] Exploit::
  2559. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2560. |_[ + ] More details:: / - / , ISP:
  2561. |_[ + ] Found:: UNIDENTIFIED
  2562.  
  2563. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2564. |_[ + ] [ 4 / 100 ]-[10:44:44] [ - ]
  2565. |_[ + ] Target:: [ http://hcsp.gov.sd/activities/ ]
  2566. |_[ + ] Exploit::
  2567. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2568. |_[ + ] More details:: / - / , ISP:
  2569. |_[ + ] Found:: UNIDENTIFIED
  2570.  
  2571. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2572. |_[ + ] [ 5 / 100 ]-[10:44:45] [ - ]
  2573. |_[ + ] Target:: [ http://hcsp.gov.sd/النشأة/ ]
  2574. |_[ + ] Exploit::
  2575. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2576. |_[ + ] More details:: / - / , ISP:
  2577. |_[ + ] Found:: UNIDENTIFIED
  2578.  
  2579. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2580. |_[ + ] [ 6 / 100 ]-[10:44:46] [ - ]
  2581. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1195/ ]
  2582. |_[ + ] Exploit::
  2583. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2584. |_[ + ] More details:: / - / , ISP:
  2585. |_[ + ] Found:: UNIDENTIFIED
  2586.  
  2587. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2588. |_[ + ] [ 7 / 100 ]-[10:44:46] [ - ]
  2589. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_5942/ ]
  2590. |_[ + ] Exploit::
  2591. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2592. |_[ + ] More details:: / - / , ISP:
  2593. |_[ + ] Found:: UNIDENTIFIED
  2594.  
  2595. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2596. |_[ + ] [ 8 / 100 ]-[10:44:47] [ - ]
  2597. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6310/ ]
  2598. |_[ + ] Exploit::
  2599. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2600. |_[ + ] More details:: / - / , ISP:
  2601. |_[ + ] Found:: UNIDENTIFIED
  2602.  
  2603. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2604. |_[ + ] [ 9 / 100 ]-[10:44:48] [ - ]
  2605. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_0784/ ]
  2606. |_[ + ] Exploit::
  2607. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2608. |_[ + ] More details:: / - / , ISP:
  2609. |_[ + ] Found:: UNIDENTIFIED
  2610.  
  2611. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2612. |_[ + ] [ 10 / 100 ]-[10:44:48] [ - ]
  2613. |_[ + ] Target:: [ http://hcsp.gov.sd/_dsc1253/ ]
  2614. |_[ + ] Exploit::
  2615. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2616. |_[ + ] More details:: / - / , ISP:
  2617. |_[ + ] Found:: UNIDENTIFIED
  2618.  
  2619. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2620. |_[ + ] [ 11 / 100 ]-[10:44:49] [ - ]
  2621. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_0714/ ]
  2622. |_[ + ] Exploit::
  2623. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2624. |_[ + ] More details:: / - / , ISP:
  2625. |_[ + ] Found:: UNIDENTIFIED
  2626.  
  2627. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2628. |_[ + ] [ 12 / 100 ]-[10:44:50] [ - ]
  2629. |_[ + ] Target:: [ https://hcsp.gov.sd/شه/ ]
  2630. |_[ + ] Exploit::
  2631. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2632. |_[ + ] More details:: / - / , ISP:
  2633. |_[ + ] Found:: UNIDENTIFIED
  2634.  
  2635. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2636. |_[ + ] [ 13 / 100 ]-[10:44:50] [ - ]
  2637. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6289/ ]
  2638. |_[ + ] Exploit::
  2639. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2640. |_[ + ] More details:: / - / , ISP:
  2641. |_[ + ] Found:: UNIDENTIFIED
  2642.  
  2643. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2644. |_[ + ] [ 14 / 100 ]-[10:44:51] [ - ]
  2645. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1106/ ]
  2646. |_[ + ] Exploit::
  2647. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2648. |_[ + ] More details:: / - / , ISP:
  2649. |_[ + ] Found:: UNIDENTIFIED
  2650.  
  2651. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2652. |_[ + ] [ 15 / 100 ]-[10:44:52] [ - ]
  2653. |_[ + ] Target:: [ http://hcsp.gov.sd/657/ ]
  2654. |_[ + ] Exploit::
  2655. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2656. |_[ + ] More details:: / - / , ISP:
  2657. |_[ + ] Found:: UNIDENTIFIED
  2658.  
  2659. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2660. |_[ + ] [ 16 / 100 ]-[10:44:52] [ - ]
  2661. |_[ + ] Target:: [ http://hcsp.gov.sd/إستمارة_رقم2/ ]
  2662. |_[ + ] Exploit::
  2663. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2664. |_[ + ] More details:: / - / , ISP:
  2665. |_[ + ] Found:: UNIDENTIFIED
  2666.  
  2667. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2668. |_[ + ] [ 17 / 100 ]-[10:44:53] [ - ]
  2669. |_[ + ] Target:: [ https://hcsp.gov.sd/2490/ ]
  2670. |_[ + ] Exploit::
  2671. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2672. |_[ + ] More details:: / - / , ISP:
  2673. |_[ + ] Found:: UNIDENTIFIED
  2674.  
  2675. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2676. |_[ + ] [ 18 / 100 ]-[10:44:54] [ - ]
  2677. |_[ + ] Target:: [ http://hcsp.gov.sd/تــــــهــــنــــــــــــــئـــة/ ]
  2678. |_[ + ] Exploit::
  2679. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2680. |_[ + ] More details:: / - / , ISP:
  2681. |_[ + ] Found:: UNIDENTIFIED
  2682.  
  2683. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2684. |_[ + ] [ 19 / 100 ]-[10:44:54] [ - ]
  2685. |_[ + ] Target:: [ http://hcsp.gov.sd/5/ ]
  2686. |_[ + ] Exploit::
  2687. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2688. |_[ + ] More details:: / - / , ISP:
  2689. |_[ + ] Found:: UNIDENTIFIED
  2690.  
  2691. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2692. |_[ + ] [ 20 / 100 ]-[10:44:55] [ - ]
  2693. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_0715/ ]
  2694. |_[ + ] Exploit::
  2695. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2696. |_[ + ] More details:: / - / , ISP:
  2697. |_[ + ] Found:: UNIDENTIFIED
  2698.  
  2699. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2700. |_[ + ] [ 21 / 100 ]-[10:44:55] [ - ]
  2701. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1061/ ]
  2702. |_[ + ] Exploit::
  2703. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2704. |_[ + ] More details:: / - / , ISP:
  2705. |_[ + ] Found:: UNIDENTIFIED
  2706.  
  2707. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2708. |_[ + ] [ 22 / 100 ]-[10:44:56] [ - ]
  2709. |_[ + ] Target:: [ http://hcsp.gov.sd/tur_5313/ ]
  2710. |_[ + ] Exploit::
  2711. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2712. |_[ + ] More details:: / - / , ISP:
  2713. |_[ + ] Found:: UNIDENTIFIED
  2714.  
  2715. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2716. |_[ + ] [ 23 / 100 ]-[10:44:57] [ - ]
  2717. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6377/ ]
  2718. |_[ + ] Exploit::
  2719. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2720. |_[ + ] More details:: / - / , ISP:
  2721. |_[ + ] Found:: UNIDENTIFIED
  2722.  
  2723. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2724. |_[ + ] [ 24 / 100 ]-[10:44:58] [ - ]
  2725. |_[ + ] Target:: [ https://hcsp.gov.sd/الرؤيا/ ]
  2726. |_[ + ] Exploit::
  2727. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2728. |_[ + ] More details:: / - / , ISP:
  2729. |_[ + ] Found:: UNIDENTIFIED
  2730.  
  2731. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2732. |_[ + ] [ 25 / 100 ]-[10:44:58] [ - ]
  2733. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_5954/ ]
  2734. |_[ + ] Exploit::
  2735. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2736. |_[ + ] More details:: / - / , ISP:
  2737. |_[ + ] Found:: UNIDENTIFIED
  2738.  
  2739. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2740. |_[ + ] [ 26 / 100 ]-[10:44:59] [ - ]
  2741. |_[ + ] Target:: [ http://hcsp.gov.sd/_fre6298/ ]
  2742. |_[ + ] Exploit::
  2743. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2744. |_[ + ] More details:: / - / , ISP:
  2745. |_[ + ] Found:: UNIDENTIFIED
  2746.  
  2747. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2748. |_[ + ] [ 27 / 100 ]-[10:45:00] [ - ]
  2749. |_[ + ] Target:: [ http://hcsp.gov.sd/dsc_1174/ ]
  2750. |_[ + ] Exploit::
  2751. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2752. |_[ + ] More details:: / - / , ISP:
  2753. |_[ + ] Found:: UNIDENTIFIED
  2754.  
  2755. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2756. |_[ + ] [ 28 / 100 ]-[10:45:00] [ - ]
  2757. |_[ + ] Target:: [ http://hcsp.gov.sd/إستمارة_رقم1/ ]
  2758. |_[ + ] Exploit::
  2759. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2760. |_[ + ] More details:: / - / , ISP:
  2761. |_[ + ] Found:: UNIDENTIFIED
  2762.  
  2763. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2764. |_[ + ] [ 29 / 100 ]-[10:45:01] [ - ]
  2765. |_[ + ] Target:: [ http://hcsp.gov.sd/img_7649/ ]
  2766. |_[ + ] Exploit::
  2767. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2768. |_[ + ] More details:: / - / , ISP:
  2769. |_[ + ] Found:: UNIDENTIFIED
  2770.  
  2771. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2772. |_[ + ] [ 30 / 100 ]-[10:45:01] [ - ]
  2773. |_[ + ] Target:: [ http://hcsp.gov.sd/الاستثمار/ ]
  2774. |_[ + ] Exploit::
  2775. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2776. |_[ + ] More details:: / - / , ISP:
  2777. |_[ + ] Found:: UNIDENTIFIED
  2778.  
  2779. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2780. |_[ + ] [ 31 / 100 ]-[10:45:02] [ - ]
  2781. |_[ + ] Target:: [ http://hcsp.gov.sd/media/ ]
  2782. |_[ + ] Exploit::
  2783. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2784. |_[ + ] More details:: / - / , ISP:
  2785. |_[ + ] Found:: UNIDENTIFIED
  2786.  
  2787. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2788. |_[ + ] [ 32 / 100 ]-[10:45:03] [ - ]
  2789. |_[ + ] Target:: [ http://hcsp.gov.sd/عن-الخرطوم/ ]
  2790. |_[ + ] Exploit::
  2791. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2792. |_[ + ] More details:: / - / , ISP:
  2793. |_[ + ] Found:: UNIDENTIFIED
  2794.  
  2795. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2796. |_[ + ] [ 33 / 100 ]-[10:45:03] [ - ]
  2797. |_[ + ] Target:: [ http://hcsp.gov.sd/عن-السودان/ ]
  2798. |_[ + ] Exploit::
  2799. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2800. |_[ + ] More details:: / - / , ISP:
  2801. |_[ + ] Found:: UNIDENTIFIED
  2802.  
  2803. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2804. |_[ + ] [ 34 / 100 ]-[10:45:04] [ - ]
  2805. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/library/ ]
  2806. |_[ + ] Exploit::
  2807. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2808. |_[ + ] More details:: / - / , ISP:
  2809. |_[ + ] Found:: UNIDENTIFIED
  2810.  
  2811. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2812. |_[ + ] [ 35 / 100 ]-[10:45:05] [ - ]
  2813. |_[ + ] Target:: [ http://hcsp.gov.sd/5858-2/ ]
  2814. |_[ + ] Exploit::
  2815. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2816. |_[ + ] More details:: / - / , ISP:
  2817. |_[ + ] Found:: UNIDENTIFIED
  2818.  
  2819. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2820. |_[ + ] [ 36 / 100 ]-[10:45:05] [ - ]
  2821. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/courses/ ]
  2822. |_[ + ] Exploit::
  2823. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2824. |_[ + ] More details:: / - / , ISP:
  2825. |_[ + ] Found:: UNIDENTIFIED
  2826.  
  2827. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2828. |_[ + ] [ 37 / 100 ]-[10:45:06] [ - ]
  2829. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/ ]
  2830. |_[ + ] Exploit::
  2831. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2832. |_[ + ] More details:: / - / , ISP:
  2833. |_[ + ] Found:: UNIDENTIFIED
  2834.  
  2835. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2836. |_[ + ] [ 38 / 100 ]-[10:45:07] [ - ]
  2837. |_[ + ] Target:: [ https://hcsp.gov.sd/5701-2/ ]
  2838. |_[ + ] Exploit::
  2839. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2840. |_[ + ] More details:: / - / , ISP:
  2841. |_[ + ] Found:: UNIDENTIFIED
  2842.  
  2843. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2844. |_[ + ] [ 39 / 100 ]-[10:45:08] [ - ]
  2845. |_[ + ] Target:: [ http://hcsp.gov.sd/4-2/ ]
  2846. |_[ + ] Exploit::
  2847. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2848. |_[ + ] More details:: / - / , ISP:
  2849. |_[ + ] Found:: UNIDENTIFIED
  2850.  
  2851. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2852. |_[ + ] [ 40 / 100 ]-[10:45:08] [ - ]
  2853. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/researches/ ]
  2854. |_[ + ] Exploit::
  2855. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2856. |_[ + ] More details:: / - / , ISP:
  2857. |_[ + ] Found:: UNIDENTIFIED
  2858.  
  2859. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2860. |_[ + ] [ 41 / 100 ]-[10:45:09] [ - ]
  2861. |_[ + ] Target:: [ http://hcsp.gov.sd/6-2/ ]
  2862. |_[ + ] Exploit::
  2863. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2864. |_[ + ] More details:: / - / , ISP:
  2865. |_[ + ] Found:: UNIDENTIFIED
  2866.  
  2867. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2868. |_[ + ] [ 42 / 100 ]-[10:45:10] [ - ]
  2869. |_[ + ] Target:: [ http://hcsp.gov.sd/الخطة-الاستراتيجية/ ]
  2870. |_[ + ] Exploit::
  2871. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2872. |_[ + ] More details:: / - / , ISP:
  2873. |_[ + ] Found:: UNIDENTIFIED
  2874.  
  2875. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2876. |_[ + ] [ 43 / 100 ]-[10:45:11] [ - ]
  2877. |_[ + ] Target:: [ http://hcsp.gov.sd/إتصل-بنا/ ]
  2878. |_[ + ] Exploit::
  2879. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2880. |_[ + ] More details:: / - / , ISP:
  2881. |_[ + ] Found:: UNIDENTIFIED
  2882.  
  2883. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2884. |_[ + ] [ 44 / 100 ]-[10:45:11] [ - ]
  2885. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_6500/ ]
  2886. |_[ + ] Exploit::
  2887. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2888. |_[ + ] More details:: / - / , ISP:
  2889. |_[ + ] Found:: UNIDENTIFIED
  2890.  
  2891. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2892. |_[ + ] [ 45 / 100 ]-[10:45:12] [ - ]
  2893. |_[ + ] Target:: [ http://hcsp.gov.sd/3-6/ ]
  2894. |_[ + ] Exploit::
  2895. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2896. |_[ + ] More details:: / - / , ISP:
  2897. |_[ + ] Found:: UNIDENTIFIED
  2898.  
  2899. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2900. |_[ + ] [ 46 / 100 ]-[10:45:13] [ - ]
  2901. |_[ + ] Target:: [ https://hcsp.gov.sd/دليل-المجلس/ ]
  2902. |_[ + ] Exploit::
  2903. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2904. |_[ + ] More details:: / - / , ISP:
  2905. |_[ + ] Found:: UNIDENTIFIED
  2906.  
  2907. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2908. |_[ + ] [ 47 / 100 ]-[10:45:13] [ - ]
  2909. |_[ + ] Target:: [ http://hcsp.gov.sd/5855-2/ ]
  2910. |_[ + ] Exploit::
  2911. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2912. |_[ + ] More details:: / - / , ISP:
  2913. |_[ + ] Found:: UNIDENTIFIED
  2914.  
  2915. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2916. |_[ + ] [ 48 / 100 ]-[10:45:14] [ - ]
  2917. |_[ + ] Target:: [ http://hcsp.gov.sd/2-5/ ]
  2918. |_[ + ] Exploit::
  2919. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2920. |_[ + ] More details:: / - / , ISP:
  2921. |_[ + ] Found:: UNIDENTIFIED
  2922.  
  2923. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2924. |_[ + ] [ 49 / 100 ]-[10:45:15] [ - ]
  2925. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_0097/ ]
  2926. |_[ + ] Exploit::
  2927. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2928. |_[ + ] More details:: / - / , ISP:
  2929. |_[ + ] Found:: UNIDENTIFIED
  2930.  
  2931. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2932. |_[ + ] [ 50 / 100 ]-[10:45:15] [ - ]
  2933. |_[ + ] Target:: [ http://hcsp.gov.sd/1582/dsc_0072/ ]
  2934. |_[ + ] Exploit::
  2935. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2936. |_[ + ] More details:: / - / , ISP:
  2937. |_[ + ] Found:: UNIDENTIFIED
  2938.  
  2939. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2940. |_[ + ] [ 51 / 100 ]-[10:45:16] [ - ]
  2941. |_[ + ] Target:: [ http://hcsp.gov.sd/5023-2/ ]
  2942. |_[ + ] Exploit::
  2943. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2944. |_[ + ] More details:: / - / , ISP:
  2945. |_[ + ] Found:: UNIDENTIFIED
  2946.  
  2947. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2948. |_[ + ] [ 52 / 100 ]-[10:45:17] [ - ]
  2949. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_4063/ ]
  2950. |_[ + ] Exploit::
  2951. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2952. |_[ + ] More details:: / - / , ISP:
  2953. |_[ + ] Found:: UNIDENTIFIED
  2954.  
  2955. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2956. |_[ + ] [ 53 / 100 ]-[10:45:17] [ - ]
  2957. |_[ + ] Target:: [ http://hcsp.gov.sd/تحليل-السياسات/ ]
  2958. |_[ + ] Exploit::
  2959. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2960. |_[ + ] More details:: / - / , ISP:
  2961. |_[ + ] Found:: UNIDENTIFIED
  2962.  
  2963. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2964. |_[ + ] [ 54 / 100 ]-[10:45:18] [ - ]
  2965. |_[ + ] Target:: [ http://hcsp.gov.sd/2-13/ ]
  2966. |_[ + ] Exploit::
  2967. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2968. |_[ + ] More details:: / - / , ISP:
  2969. |_[ + ] Found:: UNIDENTIFIED
  2970.  
  2971. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2972. |_[ + ] [ 55 / 100 ]-[10:45:18] [ - ]
  2973. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_5994/ ]
  2974. |_[ + ] Exploit::
  2975. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2976. |_[ + ] More details:: / - / , ISP:
  2977. |_[ + ] Found:: UNIDENTIFIED
  2978.  
  2979. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2980. |_[ + ] [ 56 / 100 ]-[10:45:19] [ - ]
  2981. |_[ + ] Target:: [ http://hcsp.gov.sd/مجلة-الاستراتيجي/ ]
  2982. |_[ + ] Exploit::
  2983. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  2984. |_[ + ] More details:: / - / , ISP:
  2985. |_[ + ] Found:: UNIDENTIFIED
  2986.  
  2987. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2988. |_[ + ] [ 57 / 100 ]-[10:45:20] [ - ]
  2989. |_[ + ] Target:: [ https://hcsp.gov.sd/المكتبة-التفاعيلة33/ ]
  2990. |_[ + ] Exploit::
  2991. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  2992. |_[ + ] More details:: / - / , ISP:
  2993. |_[ + ] Found:: UNIDENTIFIED
  2994.  
  2995. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2996. |_[ + ] [ 58 / 100 ]-[10:45:20] [ - ]
  2997. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_6513/ ]
  2998. |_[ + ] Exploit::
  2999. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3000. |_[ + ] More details:: / - / , ISP:
  3001. |_[ + ] Found:: UNIDENTIFIED
  3002.  
  3003. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3004. |_[ + ] [ 59 / 100 ]-[10:45:21] [ - ]
  3005. |_[ + ] Target:: [ http://hcsp.gov.sd/5-8/ ]
  3006. |_[ + ] Exploit::
  3007. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3008. |_[ + ] More details:: / - / , ISP:
  3009. |_[ + ] Found:: UNIDENTIFIED
  3010.  
  3011. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3012. |_[ + ] [ 60 / 100 ]-[10:45:22] [ - ]
  3013. |_[ + ] Target:: [ http://hcsp.gov.sd/رؤية-الولاية/ ]
  3014. |_[ + ] Exploit::
  3015. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3016. |_[ + ] More details:: / - / , ISP:
  3017. |_[ + ] Found:: UNIDENTIFIED
  3018.  
  3019. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3020. |_[ + ] [ 61 / 100 ]-[10:45:22] [ - ]
  3021. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_5984/ ]
  3022. |_[ + ] Exploit::
  3023. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3024. |_[ + ] More details:: / - / , ISP:
  3025. |_[ + ] Found:: UNIDENTIFIED
  3026.  
  3027. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3028. |_[ + ] [ 62 / 100 ]-[10:45:23] [ - ]
  3029. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_0035/ ]
  3030. |_[ + ] Exploit::
  3031. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3032. |_[ + ] More details:: / - / , ISP:
  3033. |_[ + ] Found:: UNIDENTIFIED
  3034.  
  3035. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3036. |_[ + ] [ 63 / 100 ]-[10:45:23] [ - ]
  3037. |_[ + ] Target:: [ http://hcsp.gov.sd/علم-الإجتماع/ ]
  3038. |_[ + ] Exploit::
  3039. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3040. |_[ + ] More details:: / - / , ISP:
  3041. |_[ + ] Found:: UNIDENTIFIED
  3042.  
  3043. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3044. |_[ + ] [ 64 / 100 ]-[10:45:24] [ - ]
  3045. |_[ + ] Target:: [ https://hcsp.gov.sd/التقارير-الاستراتيجية/ ]
  3046. |_[ + ] Exploit::
  3047. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3048. |_[ + ] More details:: / - / , ISP:
  3049. |_[ + ] Found:: UNIDENTIFIED
  3050.  
  3051. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3052. |_[ + ] [ 65 / 100 ]-[10:45:25] [ - ]
  3053. |_[ + ] Target:: [ http://hcsp.gov.sd/media/album/ ]
  3054. |_[ + ] Exploit::
  3055. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3056. |_[ + ] More details:: / - / , ISP:
  3057. |_[ + ] Found:: UNIDENTIFIED
  3058.  
  3059. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3060. |_[ + ] [ 66 / 100 ]-[10:45:26] [ - ]
  3061. |_[ + ] Target:: [ https://hcsp.gov.sd/magazine/ ]
  3062. |_[ + ] Exploit::
  3063. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3064. |_[ + ] More details:: / - / , ISP:
  3065. |_[ + ] Found:: UNIDENTIFIED
  3066.  
  3067. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3068. |_[ + ] [ 67 / 100 ]-[10:45:26] [ - ]
  3069. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/الخطة-الإستراتيجية/ ]
  3070. |_[ + ] Exploit::
  3071. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3072. |_[ + ] More details:: / - / , ISP:
  3073. |_[ + ] Found:: UNIDENTIFIED
  3074.  
  3075. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3076. |_[ + ] [ 68 / 100 ]-[10:45:27] [ - ]
  3077. |_[ + ] Target:: [ https://hcsp.gov.sd/محلية-كرري-ت/ ]
  3078. |_[ + ] Exploit::
  3079. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3080. |_[ + ] More details:: / - / , ISP:
  3081. |_[ + ] Found:: UNIDENTIFIED
  3082.  
  3083. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3084. |_[ + ] [ 69 / 100 ]-[10:45:28] [ - ]
  3085. |_[ + ] Target:: [ https://hcsp.gov.sd/مسابقة-تصميم-شعار/ ]
  3086. |_[ + ] Exploit::
  3087. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3088. |_[ + ] More details:: / - / , ISP:
  3089. |_[ + ] Found:: UNIDENTIFIED
  3090.  
  3091. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3092. |_[ + ] [ 70 / 100 ]-[10:45:29] [ - ]
  3093. |_[ + ] Target:: [ https://hcsp.gov.sd/en/ ]
  3094. |_[ + ] Exploit::
  3095. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3096. |_[ + ] More details:: / - / , ISP:
  3097. |_[ + ] Found:: UNIDENTIFIED
  3098.  
  3099. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3100. |_[ + ] [ 71 / 100 ]-[10:45:30] [ - ]
  3101. |_[ + ] Target:: [ http://hcsp.gov.sd/روابط-ذات-صلة/ ]
  3102. |_[ + ] Exploit::
  3103. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3104. |_[ + ] More details:: / - / , ISP:
  3105. |_[ + ] Found:: UNIDENTIFIED
  3106.  
  3107. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3108. |_[ + ] [ 72 / 100 ]-[10:45:30] [ - ]
  3109. |_[ + ] Target:: [ http://hcsp.gov.sd/منظومة-القيم-والمرتكزات/ ]
  3110. |_[ + ] Exploit::
  3111. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3112. |_[ + ] More details:: / - / , ISP:
  3113. |_[ + ] Found:: UNIDENTIFIED
  3114.  
  3115. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3116. |_[ + ] [ 73 / 100 ]-[10:45:31] [ - ]
  3117. |_[ + ] Target:: [ http://hcsp.gov.sd/مؤتمر-الخدمه-الوطنية/ ]
  3118. |_[ + ] Exploit::
  3119. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3120. |_[ + ] More details:: / - / , ISP:
  3121. |_[ + ] Found:: UNIDENTIFIED
  3122.  
  3123. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3124. |_[ + ] [ 74 / 100 ]-[10:45:32] [ - ]
  3125. |_[ + ] Target:: [ https://hcsp.gov.sd/الاطفال-فاقدى-السند/ ]
  3126. |_[ + ] Exploit::
  3127. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3128. |_[ + ] More details:: / - / , ISP:
  3129. |_[ + ] Found:: UNIDENTIFIED
  3130.  
  3131. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3132. |_[ + ] [ 75 / 100 ]-[10:45:32] [ - ]
  3133. |_[ + ] Target:: [ http://hcsp.gov.sd/مكتبة-الصور-2/ ]
  3134. |_[ + ] Exploit::
  3135. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3136. |_[ + ] More details:: / - / , ISP:
  3137. |_[ + ] Found:: UNIDENTIFIED
  3138.  
  3139. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3140. |_[ + ] [ 76 / 100 ]-[10:45:33] [ - ]
  3141. |_[ + ] Target:: [ http://hcsp.gov.sd/زيارة-الوزير-للمحليات/ ]
  3142. |_[ + ] Exploit::
  3143. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3144. |_[ + ] More details:: / - / , ISP:
  3145. |_[ + ] Found:: UNIDENTIFIED
  3146.  
  3147. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3148. |_[ + ] [ 77 / 100 ]-[10:45:33] [ - ]
  3149. |_[ + ] Target:: [ http://hcsp.gov.sd/المكتبة-التفاعيلة33/الكتب/ ]
  3150. |_[ + ] Exploit::
  3151. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3152. |_[ + ] More details:: / - / , ISP:
  3153. |_[ + ] Found:: UNIDENTIFIED
  3154.  
  3155. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3156. |_[ + ] [ 78 / 100 ]-[10:45:34] [ - ]
  3157. |_[ + ] Target:: [ http://hcsp.gov.sd/التخطيط-الإستراتيجي-السياسي/ ]
  3158. |_[ + ] Exploit::
  3159. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3160. |_[ + ] More details:: / - / , ISP:
  3161. |_[ + ] Found:: UNIDENTIFIED
  3162.  
  3163. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3164. |_[ + ] [ 79 / 100 ]-[10:45:35] [ - ]
  3165. |_[ + ] Target:: [ http://hcsp.gov.sd/عن-السودان/tur_5309/ ]
  3166. |_[ + ] Exploit::
  3167. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3168. |_[ + ] More details:: / - / , ISP:
  3169. |_[ + ] Found:: UNIDENTIFIED
  3170.  
  3171. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3172. |_[ + ] [ 80 / 100 ]-[10:45:35] [ - ]
  3173. |_[ + ] Target:: [ http://hcsp.gov.sd/imagesgallery/ورشة-التعليم/ ]
  3174. |_[ + ] Exploit::
  3175. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3176. |_[ + ] More details:: / - / , ISP:
  3177. |_[ + ] Found:: UNIDENTIFIED
  3178.  
  3179. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3180. |_[ + ] [ 81 / 100 ]-[10:45:36] [ - ]
  3181. |_[ + ] Target:: [ http://hcsp.gov.sd/gellery/dsc_6470-2/ ]
  3182. |_[ + ] Exploit::
  3183. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3184. |_[ + ] More details:: / - / , ISP:
  3185. |_[ + ] Found:: UNIDENTIFIED
  3186.  
  3187. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3188. |_[ + ] [ 82 / 100 ]-[10:45:37] [ - ]
  3189. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/courses/page/5/ ]
  3190. |_[ + ] Exploit::
  3191. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3192. |_[ + ] More details:: / - / , ISP:
  3193. |_[ + ] Found:: UNIDENTIFIED
  3194.  
  3195. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3196. |_[ + ] [ 83 / 100 ]-[10:45:38] [ - ]
  3197. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/45/ ]
  3198. |_[ + ] Exploit::
  3199. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3200. |_[ + ] More details:: / - / , ISP:
  3201. |_[ + ] Found:: UNIDENTIFIED
  3202.  
  3203. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3204. |_[ + ] [ 84 / 100 ]-[10:45:39] [ - ]
  3205. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/48/ ]
  3206. |_[ + ] Exploit::
  3207. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3208. |_[ + ] More details:: / - / , ISP:
  3209. |_[ + ] Found:: UNIDENTIFIED
  3210.  
  3211. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3212. |_[ + ] [ 85 / 100 ]-[10:45:39] [ - ]
  3213. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/47/ ]
  3214. |_[ + ] Exploit::
  3215. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3216. |_[ + ] More details:: / - / , ISP:
  3217. |_[ + ] Found:: UNIDENTIFIED
  3218.  
  3219. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3220. |_[ + ] [ 86 / 100 ]-[10:45:40] [ - ]
  3221. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/108/ ]
  3222. |_[ + ] Exploit::
  3223. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3224. |_[ + ] More details:: / - / , ISP:
  3225. |_[ + ] Found:: UNIDENTIFIED
  3226.  
  3227. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3228. |_[ + ] [ 87 / 100 ]-[10:45:41] [ - ]
  3229. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/92/ ]
  3230. |_[ + ] Exploit::
  3231. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3232. |_[ + ] More details:: / - / , ISP:
  3233. |_[ + ] Found:: UNIDENTIFIED
  3234.  
  3235. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3236. |_[ + ] [ 88 / 100 ]-[10:45:41] [ - ]
  3237. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/researches/دراسات-إقتصادية/ ]
  3238. |_[ + ] Exploit::
  3239. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3240. |_[ + ] More details:: / - / , ISP:
  3241. |_[ + ] Found:: UNIDENTIFIED
  3242.  
  3243. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3244. |_[ + ] [ 89 / 100 ]-[10:45:42] [ - ]
  3245. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/60/ ]
  3246. |_[ + ] Exploit::
  3247. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3248. |_[ + ] More details:: / - / , ISP:
  3249. |_[ + ] Found:: UNIDENTIFIED
  3250.  
  3251. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3252. |_[ + ] [ 90 / 100 ]-[10:45:43] [ - ]
  3253. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/8/ ]
  3254. |_[ + ] Exploit::
  3255. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3256. |_[ + ] More details:: / - / , ISP:
  3257. |_[ + ] Found:: UNIDENTIFIED
  3258.  
  3259. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3260. |_[ + ] [ 91 / 100 ]-[10:45:44] [ - ]
  3261. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/111/ ]
  3262. |_[ + ] Exploit::
  3263. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3264. |_[ + ] More details:: / - / , ISP:
  3265. |_[ + ] Found:: UNIDENTIFIED
  3266.  
  3267. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3268. |_[ + ] [ 92 / 100 ]-[10:45:44] [ - ]
  3269. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/78/ ]
  3270. |_[ + ] Exploit::
  3271. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3272. |_[ + ] More details:: / - / , ISP:
  3273. |_[ + ] Found:: UNIDENTIFIED
  3274.  
  3275. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3276. |_[ + ] [ 93 / 100 ]-[10:45:45] [ - ]
  3277. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/researches/page/4/ ]
  3278. |_[ + ] Exploit::
  3279. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3280. |_[ + ] More details:: / - / , ISP:
  3281. |_[ + ] Found:: UNIDENTIFIED
  3282.  
  3283. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3284. |_[ + ] [ 94 / 100 ]-[10:45:46] [ - ]
  3285. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/20/ ]
  3286. |_[ + ] Exploit::
  3287. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3288. |_[ + ] More details:: / - / , ISP:
  3289. |_[ + ] Found:: UNIDENTIFIED
  3290.  
  3291. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3292. |_[ + ] [ 95 / 100 ]-[10:45:46] [ - ]
  3293. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/21/ ]
  3294. |_[ + ] Exploit::
  3295. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3296. |_[ + ] More details:: / - / , ISP:
  3297. |_[ + ] Found:: UNIDENTIFIED
  3298.  
  3299. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3300. |_[ + ] [ 96 / 100 ]-[10:45:47] [ - ]
  3301. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/100/ ]
  3302. |_[ + ] Exploit::
  3303. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3304. |_[ + ] More details:: / - / , ISP:
  3305. |_[ + ] Found:: UNIDENTIFIED
  3306.  
  3307. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3308. |_[ + ] [ 97 / 100 ]-[10:45:48] [ - ]
  3309. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/7/ ]
  3310. |_[ + ] Exploit::
  3311. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3312. |_[ + ] More details:: / - / , ISP:
  3313. |_[ + ] Found:: UNIDENTIFIED
  3314.  
  3315. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3316. |_[ + ] [ 98 / 100 ]-[10:45:48] [ - ]
  3317. |_[ + ] Target:: [ http://hcsp.gov.sd/topics/news/page/6/ ]
  3318. |_[ + ] Exploit::
  3319. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:80
  3320. |_[ + ] More details:: / - / , ISP:
  3321. |_[ + ] Found:: UNIDENTIFIED
  3322.  
  3323. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3324. |_[ + ] [ 99 / 100 ]-[10:45:49] [ - ]
  3325. |_[ + ] Target:: [ https://hcsp.gov.sd/topics/news/page/26/ ]
  3326. |_[ + ] Exploit::
  3327. |_[ + ] Information Server:: HTTP/1.1 403 Forbidden, Server: LiteSpeed , IP:77.72.0.138:443
  3328. |_[ + ] More details:: / - / , ISP:
  3329. |_[ + ] Found:: UNIDENTIFIED
  3330.  
  3331. [ INFO ] [ Shutting down ]
  3332. [ INFO ] [ End of process INURLBR at [13-09-2019 10:45:49]
  3333. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  3334. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/hcsp.gov.sd/output/inurlbr-hcsp.gov.sd ]
  3335. |_________________________________________________________________________________________
  3336.  
  3337. \_________________________________________________________________________________________/
  3338. #######################################################################################################################################
  3339. tee: /usr/share/sniper/loot/workspace/hcsp.gov.sd/output/nmap-hcsp.gov.sd-port3306.txt: Aucun fichier ou dossier de ce type
  3340. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:45 EDT
  3341. Nmap scan report for hcsp.gov.sd (77.72.0.138)
  3342. Host is up (0.15s latency).
  3343. rDNS record for 77.72.0.138: sulfur.cloudhosting.co.uk
  3344.  
  3345. PORT STATE SERVICE VERSION
  3346. 3306/tcp open mysql?
  3347. | fingerprint-strings:
  3348. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3349. | Your connection to this server has been blocked in this server's firewall.
  3350. | need to contact the server owner or hosting provider for further information.
  3351. | Your blocked IP address is: 176.113.74.28
  3352. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3353. | mysql-brute:
  3354. | Accounts: No valid accounts found
  3355. | Statistics: Performed 0 guesses in 1 seconds, average tps: 0.0
  3356. |_ ERROR: The service seems to have failed or is heavily firewalled...
  3357. |_mysql-empty-password: ERROR: Script execution failed (use -d to debug)
  3358. | mysql-enum:
  3359. | Accounts: No valid accounts found
  3360. | Statistics: Performed 0 guesses in 1 seconds, average tps: 0.0
  3361. |_ ERROR: The service seems to have failed or is heavily firewalled...
  3362. |_mysql-info: ERROR: Script execution failed (use -d to debug)
  3363. |_mysql-vuln-cve2012-2122: ERROR: Script execution failed (use -d to debug)
  3364. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
  3365. SF-Port3306-TCP:V=7.80%I=7%D=9/13%Time=5D7BABA1%P=x86_64-pc-linux-gnu%r(NU
  3366. SF:LL,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bl
  3367. SF:ocked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20c
  3368. SF:ontact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x2
  3369. SF:0further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2
  3370. SF:0176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clo
  3371. SF:udhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x2
  3372. SF:0this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20
  3373. SF:firewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x2
  3374. SF:0or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x
  3375. SF:20blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server
  3376. SF:'s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetReques
  3377. SF:t,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3378. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3379. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3380. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3381. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3382. SF:dhosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20t
  3383. SF:his\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fi
  3384. SF:rewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20o
  3385. SF:r\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20
  3386. SF:blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's
  3387. SF:\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest
  3388. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3389. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3390. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3391. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3392. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3393. SF:hosting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\
  3394. SF:x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewa
  3395. SF:ll\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x2
  3396. SF:0hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20bloc
  3397. SF:ked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20
  3398. SF:hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3399. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  3400. Device type: general purpose|specialized|storage-misc
  3401. Running (JUST GUESSING): Linux 3.X|4.X (91%), Crestron 2-Series (87%), HP embedded (85%)
  3402. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3
  3403. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), Linux 3.2 - 4.9 (91%), Linux 3.18 (89%), Crestron XPanel control system (87%), Linux 3.16 (86%), HP P2000 G3 NAS device (85%)
  3404. No exact OS matches for host (test conditions non-ideal).
  3405. Network Distance: 15 hops
  3406.  
  3407. TRACEROUTE (using port 3306/tcp)
  3408. HOP RTT ADDRESS
  3409. 1 103.23 ms 10.244.204.1
  3410. 2 103.28 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  3411. 3 103.29 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  3412. 4 103.28 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  3413. 5 103.29 ms motl-b1-link.telia.net (62.115.162.41)
  3414. 6 103.33 ms nyk-bb4-link.telia.net (62.115.134.52)
  3415. 7 103.35 ms ash-bb3-link.telia.net (62.115.141.244)
  3416. 8 103.36 ms ash-b1-link.telia.net (62.115.143.79)
  3417. 9 103.36 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  3418. 10 37.61 ms ash-eqx-01gw.voxility.net (5.254.81.129)
  3419. 11 88.82 ms ash-eqx-01c.voxility.net (37.221.173.74)
  3420. 12 ...
  3421. 13 197.73 ms lon-tel-01c.voxility.net (5.254.112.185)
  3422. 14 ...
  3423. 15 197.63 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  3424. ######################################################################################################################################
  3425. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:13 EDT
  3426. Nmap scan report for sulfur.cloudhosting.co.uk (77.72.0.138)
  3427. Host is up (0.11s latency).
  3428. Not shown: 470 filtered ports, 5 closed ports
  3429. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  3430. PORT STATE SERVICE
  3431. 21/tcp open ftp
  3432. 110/tcp open pop3
  3433. 143/tcp open imap
  3434. 465/tcp open smtps
  3435. 587/tcp open submission
  3436. 993/tcp open imaps
  3437. 995/tcp open pop3s
  3438. 8999/tcp open bctp
  3439.  
  3440. Nmap done: 1 IP address (1 host up) scanned in 5.82 seconds
  3441. #######################################################################################################################################
  3442. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:13 EDT
  3443. Nmap scan report for sulfur.cloudhosting.co.uk (77.72.0.138)
  3444. Host is up (0.067s latency).
  3445. Not shown: 3 closed ports, 2 filtered ports
  3446. PORT STATE SERVICE
  3447. 67/udp open|filtered dhcps
  3448. 68/udp open|filtered dhcpc
  3449. 69/udp open|filtered tftp
  3450. 88/udp open|filtered kerberos-sec
  3451. 123/udp open|filtered ntp
  3452. 139/udp open|filtered netbios-ssn
  3453. 389/udp open|filtered ldap
  3454. 500/udp open|filtered isakmp
  3455. 520/udp open|filtered route
  3456. 2049/udp open|filtered nfs
  3457.  
  3458. Nmap done: 1 IP address (1 host up) scanned in 1.80 seconds
  3459. #######################################################################################################################################
  3460. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:13 EDT
  3461. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  3462. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  3463. NSE: [ftp-brute] passwords: Time limit 3m00s exceeded.
  3464. Nmap scan report for sulfur.cloudhosting.co.uk (77.72.0.138)
  3465. Host is up (0.12s latency).
  3466.  
  3467. PORT STATE SERVICE VERSION
  3468. 21/tcp open ftp Pure-FTPd
  3469. |_ftp-bounce: ERROR: Script execution failed (use -d to debug)
  3470. | ftp-brute:
  3471. | Accounts: No valid accounts found
  3472. |_ Statistics: Performed 1717 guesses in 182 seconds, average tps: 9.4
  3473. |_ftp-libopie: ERROR: Script execution failed (use -d to debug)
  3474. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3475. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  3476. Device type: general purpose
  3477. Running (JUST GUESSING): Linux 3.X|4.X|2.6.X (91%)
  3478. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4.4 cpe:/o:linux:linux_kernel:2.6
  3479. Aggressive OS guesses: Linux 3.10 - 3.12 (91%), Linux 4.4 (91%), Linux 4.9 (91%), Linux 2.6.18 - 2.6.22 (86%), Linux 3.10 (86%), Linux 3.10 - 3.16 (86%), Linux 4.0 (86%), Linux 3.10 - 4.11 (85%), Linux 3.11 - 4.1 (85%), Linux 3.18 (85%)
  3480. No exact OS matches for host (test conditions non-ideal).
  3481. Network Distance: 15 hops
  3482.  
  3483. TRACEROUTE (using port 21/tcp)
  3484. HOP RTT ADDRESS
  3485. 1 55.44 ms 10.244.204.1
  3486. 2 55.50 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  3487. 3 55.52 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  3488. 4 55.49 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  3489. 5 55.51 ms motl-b1-link.telia.net (62.115.162.41)
  3490. 6 ...
  3491. 7 81.48 ms ash-bb4-link.telia.net (62.115.136.201)
  3492. 8 81.53 ms ash-b1-link.telia.net (62.115.143.79)
  3493. 9 81.53 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  3494. 10 35.22 ms ash-eqx-02gw.voxility.net (5.254.81.133)
  3495. 11 61.86 ms ash-eqx-01c.voxility.net (5.254.81.22)
  3496. 12 ...
  3497. 13 144.91 ms lon-tel-01c.voxility.net (5.254.112.185)
  3498. 14 ...
  3499. 15 144.84 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  3500. #######################################################################################################################################
  3501. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:17 EDT
  3502. Nmap scan report for sulfur.cloudhosting.co.uk (77.72.0.138)
  3503. Host is up (0.13s latency).
  3504.  
  3505. PORT STATE SERVICE VERSION
  3506. 110/tcp open pop3?
  3507. | fingerprint-strings:
  3508. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3509. | Your connection to this server has been blocked in this server's firewall.
  3510. | need to contact the server owner or hosting provider for further information.
  3511. | Your blocked IP address is: 176.113.74.28
  3512. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3513. | pop3-brute:
  3514. | Accounts: No valid accounts found
  3515. | Statistics: Performed 5 guesses in 1 seconds, average tps: 5.0
  3516. |_ ERROR: Failed to make a pop-connection.
  3517. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
  3518. SF-Port110-TCP:V=7.80%I=7%D=9/13%Time=5D7BA508%P=x86_64-pc-linux-gnu%r(NUL
  3519. SF:L,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3520. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3521. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3522. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3523. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3524. SF:dhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20
  3525. SF:this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20f
  3526. SF:irewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20
  3527. SF:or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x2
  3528. SF:0blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server'
  3529. SF:s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest
  3530. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3531. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3532. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3533. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3534. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3535. SF:hosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20th
  3536. SF:is\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fir
  3537. SF:ewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or
  3538. SF:\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20b
  3539. SF:locked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\
  3540. SF:x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,
  3541. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  3542. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  3543. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  3544. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  3545. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  3546. SF:osting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x
  3547. SF:20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewal
  3548. SF:l\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20
  3549. SF:hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20block
  3550. SF:ed\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20h
  3551. SF:ostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3552. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  3553. Device type: general purpose|specialized|storage-misc
  3554. Running (JUST GUESSING): Linux 3.X|4.X (91%), Crestron 2-Series (87%), HP embedded (85%), Oracle VM Server 3.X (85%)
  3555. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3 cpe:/o:oracle:vm_server:3.4.2 cpe:/o:linux:linux_kernel:4.1
  3556. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), Linux 3.2 - 4.9 (91%), Linux 3.18 (89%), Crestron XPanel control system (87%), Linux 3.16 (86%), HP P2000 G3 NAS device (85%), Oracle VM Server 3.4.2 (Linux 4.1) (85%)
  3557. No exact OS matches for host (test conditions non-ideal).
  3558. Network Distance: 15 hops
  3559.  
  3560. TRACEROUTE (using port 80/tcp)
  3561. HOP RTT ADDRESS
  3562. 1 28.89 ms 10.244.204.1
  3563. 2 69.49 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  3564. 3 50.15 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  3565. 4 50.10 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  3566. 5 50.13 ms motl-b1-link.telia.net (62.115.162.41)
  3567. 6 50.17 ms nyk-bb4-link.telia.net (62.115.134.52)
  3568. 7 50.21 ms ash-bb3-link.telia.net (62.115.141.244)
  3569. 8 50.19 ms ash-b1-link.telia.net (213.155.136.39)
  3570. 9 50.20 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  3571. 10 50.24 ms ash-eqx-02gw.voxility.net (5.254.81.133)
  3572. 11 211.54 ms ash-eqx-01c.voxility.net (5.254.81.22)
  3573. 12 ...
  3574. 13 144.38 ms lon-tel-01c.voxility.net (5.254.112.185)
  3575. 14 144.40 ms 185.5.172.166
  3576. 15 144.33 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  3577. #######################################################################################################################################
  3578. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:18 EDT
  3579. NSE: Loaded 47 scripts for scanning.
  3580. NSE: Script Pre-scanning.
  3581. Initiating NSE at 10:18
  3582. Completed NSE at 10:18, 0.00s elapsed
  3583. Initiating NSE at 10:18
  3584. Completed NSE at 10:18, 0.00s elapsed
  3585. Initiating Ping Scan at 10:18
  3586. Scanning 77.72.0.138 [4 ports]
  3587. Completed Ping Scan at 10:18, 0.20s elapsed (1 total hosts)
  3588. Initiating Parallel DNS resolution of 1 host. at 10:18
  3589. Completed Parallel DNS resolution of 1 host. at 10:18, 0.03s elapsed
  3590. Initiating SYN Stealth Scan at 10:18
  3591. Scanning sulfur.cloudhosting.co.uk (77.72.0.138) [65535 ports]
  3592. Discovered open port 80/tcp on 77.72.0.138
  3593. Discovered open port 22/tcp on 77.72.0.138
  3594. Discovered open port 587/tcp on 77.72.0.138
  3595. Discovered open port 110/tcp on 77.72.0.138
  3596. Discovered open port 143/tcp on 77.72.0.138
  3597. Discovered open port 443/tcp on 77.72.0.138
  3598. Discovered open port 3306/tcp on 77.72.0.138
  3599. Discovered open port 21/tcp on 77.72.0.138
  3600. Discovered open port 2083/tcp on 77.72.0.138
  3601. SYN Stealth Scan Timing: About 10.32% done; ETC: 10:23 (0:04:29 remaining)
  3602. Discovered open port 8998/tcp on 77.72.0.138
  3603. SYN Stealth Scan Timing: About 22.13% done; ETC: 10:23 (0:03:35 remaining)
  3604. SYN Stealth Scan Timing: About 36.59% done; ETC: 10:23 (0:02:38 remaining)
  3605. Discovered open port 26/tcp on 77.72.0.138
  3606. Discovered open port 2095/tcp on 77.72.0.138
  3607. Discovered open port 2086/tcp on 77.72.0.138
  3608. Discovered open port 8887/tcp on 77.72.0.138
  3609. SYN Stealth Scan Timing: About 59.47% done; ETC: 10:22 (0:01:22 remaining)
  3610. SYN Stealth Scan Timing: About 72.75% done; ETC: 10:22 (0:00:57 remaining)
  3611. Discovered open port 525/tcp on 77.72.0.138
  3612. Discovered open port 2096/tcp on 77.72.0.138
  3613. SYN Stealth Scan Timing: About 84.79% done; ETC: 10:22 (0:00:32 remaining)
  3614. Discovered open port 2082/tcp on 77.72.0.138
  3615. Discovered open port 8999/tcp on 77.72.0.138
  3616. Discovered open port 2087/tcp on 77.72.0.138
  3617. Completed SYN Stealth Scan at 10:22, 224.05s elapsed (65535 total ports)
  3618. Initiating Service scan at 10:22
  3619. Scanning 19 services on sulfur.cloudhosting.co.uk (77.72.0.138)
  3620. Completed Service scan at 10:23, 35.27s elapsed (19 services on 1 host)
  3621. Initiating OS detection (try #1) against sulfur.cloudhosting.co.uk (77.72.0.138)
  3622. Retrying OS detection (try #2) against sulfur.cloudhosting.co.uk (77.72.0.138)
  3623. Initiating Traceroute at 10:23
  3624. Completed Traceroute at 10:23, 3.06s elapsed
  3625. Initiating Parallel DNS resolution of 14 hosts. at 10:23
  3626. Completed Parallel DNS resolution of 14 hosts. at 10:23, 0.27s elapsed
  3627. NSE: Script scanning 77.72.0.138.
  3628. Initiating NSE at 10:23
  3629. Completed NSE at 10:23, 3.00s elapsed
  3630. Initiating NSE at 10:23
  3631. Completed NSE at 10:23, 1.22s elapsed
  3632. Nmap scan report for sulfur.cloudhosting.co.uk (77.72.0.138)
  3633. Host is up (0.12s latency).
  3634. Not shown: 65513 filtered ports
  3635. PORT STATE SERVICE VERSION
  3636. 21/tcp open ftp?
  3637. | fingerprint-strings:
  3638. | GenericLines, GetRequest, HTTPOptions, Help, NULL, RTSPRequest:
  3639. | Your connection to this server has been blocked in this server's firewall.
  3640. | need to contact the server owner or hosting provider for further information.
  3641. | Your blocked IP address is: 176.113.74.28
  3642. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3643. 22/tcp open ssh?
  3644. | fingerprint-strings:
  3645. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3646. | Your connection to this server has been blocked in this server's firewall.
  3647. | need to contact the server owner or hosting provider for further information.
  3648. | Your blocked IP address is: 176.113.74.28
  3649. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3650. 25/tcp closed smtp
  3651. 26/tcp open rsftp?
  3652. | fingerprint-strings:
  3653. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3654. | Your connection to this server has been blocked in this server's firewall.
  3655. | need to contact the server owner or hosting provider for further information.
  3656. | Your blocked IP address is: 176.113.74.28
  3657. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3658. 80/tcp open http LiteSpeed httpd
  3659. |_http-server-header: LiteSpeed
  3660. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3661. 110/tcp open pop3?
  3662. | fingerprint-strings:
  3663. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3664. | Your connection to this server has been blocked in this server's firewall.
  3665. | need to contact the server owner or hosting provider for further information.
  3666. | Your blocked IP address is: 176.113.74.28
  3667. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3668. 139/tcp closed netbios-ssn
  3669. 143/tcp open imap?
  3670. | fingerprint-strings:
  3671. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3672. | Your connection to this server has been blocked in this server's firewall.
  3673. | need to contact the server owner or hosting provider for further information.
  3674. | Your blocked IP address is: 176.113.74.28
  3675. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3676. 443/tcp open ssl/http LiteSpeed httpd
  3677. |_http-server-header: LiteSpeed
  3678. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3679. 445/tcp closed microsoft-ds
  3680. 525/tcp open timed?
  3681. | fingerprint-strings:
  3682. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3683. | Your connection to this server has been blocked in this server's firewall.
  3684. | need to contact the server owner or hosting provider for further information.
  3685. | Your blocked IP address is: 176.113.74.28
  3686. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3687. 587/tcp open submission?
  3688. | fingerprint-strings:
  3689. | GenericLines, GetRequest, HTTPOptions, Hello, Help, NULL:
  3690. | Your connection to this server has been blocked in this server's firewall.
  3691. | need to contact the server owner or hosting provider for further information.
  3692. | Your blocked IP address is: 176.113.74.28
  3693. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3694. 2082/tcp open http LiteSpeed httpd
  3695. |_http-server-header: LiteSpeed
  3696. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3697. 2083/tcp open ssl/http LiteSpeed httpd
  3698. |_http-server-header: LiteSpeed
  3699. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3700. 2086/tcp open http LiteSpeed httpd
  3701. |_http-server-header: LiteSpeed
  3702. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3703. 2087/tcp open ssl/http LiteSpeed httpd
  3704. |_http-server-header: LiteSpeed
  3705. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3706. 2095/tcp open http LiteSpeed httpd
  3707. |_http-server-header: LiteSpeed
  3708. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3709. 2096/tcp open ssl/http LiteSpeed httpd
  3710. |_http-server-header: LiteSpeed
  3711. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3712. 3306/tcp open mysql?
  3713. | fingerprint-strings:
  3714. | GenericLines, GetRequest, HTTPOptions, NULL, RPCCheck, RTSPRequest:
  3715. | Your connection to this server has been blocked in this server's firewall.
  3716. | need to contact the server owner or hosting provider for further information.
  3717. | Your blocked IP address is: 176.113.74.28
  3718. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3719. 8887/tcp open ssl/http LiteSpeed httpd
  3720. |_http-server-header: LiteSpeed
  3721. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3722. 8998/tcp open http LiteSpeed httpd
  3723. |_http-server-header: LiteSpeed
  3724. |_vulscan: ERROR: Script execution failed (use -d to debug)
  3725. 8999/tcp open bctp?
  3726. | fingerprint-strings:
  3727. | GenericLines, GetRequest, HTTPOptions, JavaRMI, NULL, RTSPRequest:
  3728. | Your connection to this server has been blocked in this server's firewall.
  3729. | need to contact the server owner or hosting provider for further information.
  3730. | Your blocked IP address is: 176.113.74.28
  3731. |_ This server's hostname is: sulfur.cloudhosting.co.uk
  3732. 9 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service :
  3733. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3734. SF-Port21-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NULL
  3735. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3736. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3737. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3738. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3739. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3740. SF:hosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20t
  3741. SF:his\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fi
  3742. SF:rewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20o
  3743. SF:r\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20
  3744. SF:blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's
  3745. SF:\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(Help,100,"Y
  3746. SF:our\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocked\x20
  3747. SF:in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact\x2
  3748. SF:0the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20further\
  3749. SF:x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.113
  3750. SF:\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhosting
  3751. SF:\.co\.uk\r\n")%r(GetRequest,100,"Your\x20connection\x20to\x20this\x20se
  3752. SF:rver\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall\.\
  3753. SF:r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20host
  3754. SF:ing\x20provider\x20for\x20further\x20information\.\r\nYour\x20blocked\x
  3755. SF:20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20hostn
  3756. SF:ame\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(HTTPOptions,100,"You
  3757. SF:r\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocked\x20in
  3758. SF:\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact\x20t
  3759. SF:he\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20further\x2
  3760. SF:0information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.113\.
  3761. SF:74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhosting\.
  3762. SF:co\.uk\r\n")%r(RTSPRequest,100,"Your\x20connection\x20to\x20this\x20ser
  3763. SF:ver\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall\.\r
  3764. SF:\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20hosti
  3765. SF:ng\x20provider\x20for\x20further\x20information\.\r\nYour\x20blocked\x2
  3766. SF:0IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20hostna
  3767. SF:me\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3768. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3769. SF-Port22-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NULL
  3770. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3771. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3772. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3773. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3774. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3775. SF:hosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20t
  3776. SF:his\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fi
  3777. SF:rewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20o
  3778. SF:r\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20
  3779. SF:blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's
  3780. SF:\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest,
  3781. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  3782. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  3783. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  3784. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  3785. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  3786. SF:osting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20thi
  3787. SF:s\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fire
  3788. SF:wall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\
  3789. SF:x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20bl
  3790. SF:ocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x
  3791. SF:20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,1
  3792. SF:00,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocke
  3793. SF:d\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20conta
  3794. SF:ct\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fur
  3795. SF:ther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176
  3796. SF:\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudho
  3797. SF:sting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x2
  3798. SF:0server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall
  3799. SF:\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20h
  3800. SF:osting\x20provider\x20for\x20further\x20information\.\r\nYour\x20blocke
  3801. SF:d\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20ho
  3802. SF:stname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3803. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3804. SF-Port26-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NULL
  3805. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3806. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3807. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3808. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3809. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3810. SF:hosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20t
  3811. SF:his\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fi
  3812. SF:rewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20o
  3813. SF:r\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20
  3814. SF:blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's
  3815. SF:\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest,
  3816. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  3817. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  3818. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  3819. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  3820. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  3821. SF:osting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20thi
  3822. SF:s\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fire
  3823. SF:wall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\
  3824. SF:x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20bl
  3825. SF:ocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x
  3826. SF:20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,1
  3827. SF:00,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocke
  3828. SF:d\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20conta
  3829. SF:ct\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fur
  3830. SF:ther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176
  3831. SF:\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudho
  3832. SF:sting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x2
  3833. SF:0server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall
  3834. SF:\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20h
  3835. SF:osting\x20provider\x20for\x20further\x20information\.\r\nYour\x20blocke
  3836. SF:d\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20ho
  3837. SF:stname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3838. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3839. SF-Port110-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NUL
  3840. SF:L,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3841. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3842. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3843. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3844. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3845. SF:dhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20
  3846. SF:this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20f
  3847. SF:irewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20
  3848. SF:or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x2
  3849. SF:0blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server'
  3850. SF:s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest
  3851. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3852. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3853. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3854. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3855. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3856. SF:hosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20th
  3857. SF:is\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fir
  3858. SF:ewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or
  3859. SF:\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20b
  3860. SF:locked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\
  3861. SF:x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,
  3862. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  3863. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  3864. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  3865. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  3866. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  3867. SF:osting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x
  3868. SF:20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewal
  3869. SF:l\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20
  3870. SF:hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20block
  3871. SF:ed\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20h
  3872. SF:ostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3873. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3874. SF-Port143-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NUL
  3875. SF:L,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3876. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3877. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3878. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3879. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3880. SF:dhosting\.co\.uk\r\n")%r(GetRequest,100,"Your\x20connection\x20to\x20th
  3881. SF:is\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fir
  3882. SF:ewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or
  3883. SF:\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20b
  3884. SF:locked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\
  3885. SF:x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GenericLines
  3886. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3887. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3888. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3889. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3890. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3891. SF:hosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20th
  3892. SF:is\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fir
  3893. SF:ewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or
  3894. SF:\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20b
  3895. SF:locked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\
  3896. SF:x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,
  3897. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  3898. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  3899. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  3900. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  3901. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  3902. SF:osting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x
  3903. SF:20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewal
  3904. SF:l\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20
  3905. SF:hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20block
  3906. SF:ed\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20h
  3907. SF:ostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3908. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3909. SF-Port525-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NUL
  3910. SF:L,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3911. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3912. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3913. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3914. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3915. SF:dhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20
  3916. SF:this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20f
  3917. SF:irewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20
  3918. SF:or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x2
  3919. SF:0blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server'
  3920. SF:s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest
  3921. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  3922. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  3923. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  3924. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  3925. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  3926. SF:hosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20th
  3927. SF:is\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fir
  3928. SF:ewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or
  3929. SF:\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20b
  3930. SF:locked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\
  3931. SF:x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest,
  3932. SF:100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20block
  3933. SF:ed\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20cont
  3934. SF:act\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fu
  3935. SF:rther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2017
  3936. SF:6\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudh
  3937. SF:osting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\x
  3938. SF:20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewal
  3939. SF:l\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20
  3940. SF:hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20block
  3941. SF:ed\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20h
  3942. SF:ostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3943. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3944. SF-Port587-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NUL
  3945. SF:L,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3946. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3947. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3948. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3949. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3950. SF:dhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x20
  3951. SF:this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20f
  3952. SF:irewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20
  3953. SF:or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x2
  3954. SF:0blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server'
  3955. SF:s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(Hello,100,
  3956. SF:"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocked\x
  3957. SF:20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact\
  3958. SF:x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20furthe
  3959. SF:r\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.1
  3960. SF:13\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhosti
  3961. SF:ng\.co\.uk\r\n")%r(Help,100,"Your\x20connection\x20to\x20this\x20server
  3962. SF:\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall\.\r\nY
  3963. SF:ou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20hosting\
  3964. SF:x20provider\x20for\x20further\x20information\.\r\nYour\x20blocked\x20IP
  3965. SF:\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20hostname\
  3966. SF:x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetRequest,100,"Your\x20
  3967. SF:connection\x20to\x20this\x20server\x20has\x20been\x20blocked\x20in\x20t
  3968. SF:his\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact\x20the\x2
  3969. SF:0server\x20owner\x20or\x20hosting\x20provider\x20for\x20further\x20info
  3970. SF:rmation\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.113\.74\.2
  3971. SF:8\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.u
  3972. SF:k\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20this\x20server\x
  3973. SF:20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewall\.\r\nYou
  3974. SF:\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20hosting\x2
  3975. SF:0provider\x20for\x20further\x20information\.\r\nYour\x20blocked\x20IP\x
  3976. SF:20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20hostname\x2
  3977. SF:0is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  3978. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  3979. SF-Port3306-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NU
  3980. SF:LL,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bl
  3981. SF:ocked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20c
  3982. SF:ontact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x2
  3983. SF:0further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2
  3984. SF:0176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clo
  3985. SF:udhosting\.co\.uk\r\n")%r(GenericLines,100,"Your\x20connection\x20to\x2
  3986. SF:0this\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20
  3987. SF:firewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x2
  3988. SF:0or\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x
  3989. SF:20blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server
  3990. SF:'s\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GetReques
  3991. SF:t,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blo
  3992. SF:cked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20co
  3993. SF:ntact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20
  3994. SF:further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20
  3995. SF:176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clou
  3996. SF:dhosting\.co\.uk\r\n")%r(HTTPOptions,100,"Your\x20connection\x20to\x20t
  3997. SF:his\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20fi
  3998. SF:rewall\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20o
  3999. SF:r\x20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20
  4000. SF:blocked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's
  4001. SF:\x20hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(RTSPRequest
  4002. SF:,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bloc
  4003. SF:ked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20con
  4004. SF:tact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20f
  4005. SF:urther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x201
  4006. SF:76\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloud
  4007. SF:hosting\.co\.uk\r\n")%r(RPCCheck,100,"Your\x20connection\x20to\x20this\
  4008. SF:x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewa
  4009. SF:ll\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x2
  4010. SF:0hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20bloc
  4011. SF:ked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20
  4012. SF:hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  4013. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  4014. SF-Port8999-TCP:V=7.80%I=7%D=9/13%Time=5D7BA62D%P=x86_64-pc-linux-gnu%r(NU
  4015. SF:LL,100,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20bl
  4016. SF:ocked\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20c
  4017. SF:ontact\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x2
  4018. SF:0further\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x2
  4019. SF:0176\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.clo
  4020. SF:udhosting\.co\.uk\r\n")%r(JavaRMI,100,"Your\x20connection\x20to\x20this
  4021. SF:\x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firew
  4022. SF:all\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x
  4023. SF:20hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20blo
  4024. SF:cked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x2
  4025. SF:0hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(GenericLines,1
  4026. SF:00,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocke
  4027. SF:d\x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20conta
  4028. SF:ct\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20fur
  4029. SF:ther\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176
  4030. SF:\.113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudho
  4031. SF:sting\.co\.uk\r\n")%r(GetRequest,100,"Your\x20connection\x20to\x20this\
  4032. SF:x20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewa
  4033. SF:ll\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x2
  4034. SF:0hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20bloc
  4035. SF:ked\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20
  4036. SF:hostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n")%r(HTTPOptions,100
  4037. SF:,"Your\x20connection\x20to\x20this\x20server\x20has\x20been\x20blocked\
  4038. SF:x20in\x20this\x20server's\x20firewall\.\r\nYou\x20need\x20to\x20contact
  4039. SF:\x20the\x20server\x20owner\x20or\x20hosting\x20provider\x20for\x20furth
  4040. SF:er\x20information\.\r\nYour\x20blocked\x20IP\x20address\x20is:\x20176\.
  4041. SF:113\.74\.28\r\nThis\x20server's\x20hostname\x20is:\x20sulfur\.cloudhost
  4042. SF:ing\.co\.uk\r\n")%r(RTSPRequest,100,"Your\x20connection\x20to\x20this\x
  4043. SF:20server\x20has\x20been\x20blocked\x20in\x20this\x20server's\x20firewal
  4044. SF:l\.\r\nYou\x20need\x20to\x20contact\x20the\x20server\x20owner\x20or\x20
  4045. SF:hosting\x20provider\x20for\x20further\x20information\.\r\nYour\x20block
  4046. SF:ed\x20IP\x20address\x20is:\x20176\.113\.74\.28\r\nThis\x20server's\x20h
  4047. SF:ostname\x20is:\x20sulfur\.cloudhosting\.co\.uk\r\n");
  4048. Aggressive OS guesses: Linux 3.10 - 4.11 (91%), HP P2000 G3 NAS device (90%), Linux 3.2 - 4.9 (90%), Linux 3.18 (89%), Linux 3.16 - 4.6 (89%), Linux 4.4 (89%), Linux 2.6.32 (89%), Linux 2.6.32 - 3.1 (89%), Ubiquiti AirMax NanoStation WAP (Linux 2.6.32) (89%), Linux 3.7 (89%)
  4049. No exact OS matches for host (test conditions non-ideal).
  4050. Uptime guess: 27.421 days (since Sat Aug 17 00:17:25 2019)
  4051. Network Distance: 15 hops
  4052. TCP Sequence Prediction: Difficulty=261 (Good luck!)
  4053. IP ID Sequence Generation: All zeros
  4054.  
  4055. TRACEROUTE (using port 80/tcp)
  4056. HOP RTT ADDRESS
  4057. 1 46.51 ms 10.244.204.1
  4058. 2 46.61 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  4059. 3 76.53 ms xe-0-0-1-0.agg2.qc1.ca.m247.com (37.120.128.166)
  4060. 4 46.56 ms vlan304.as032.buc.ro.m247.com (77.243.185.226)
  4061. 5 46.55 ms motl-b1-link.telia.net (62.115.162.41)
  4062. 6 46.60 ms nyk-bb4-link.telia.net (62.115.134.52)
  4063. 7 71.38 ms ash-bb3-link.telia.net (62.115.141.244)
  4064. 8 46.62 ms ash-b1-link.telia.net (213.155.136.39)
  4065. 9 46.65 ms voxility-ic-311384-ash-b3.c.telia.net (62.115.55.66)
  4066. 10 46.67 ms ash-eqx-01gw.voxility.net (5.254.81.129)
  4067. 11 69.41 ms ash-eqx-01c.voxility.net (37.221.173.74)
  4068. 12 ...
  4069. 13 149.46 ms lon-tel-01c.voxility.net (5.254.112.185)
  4070. 14 149.49 ms 185.5.172.166
  4071. 15 149.44 ms sulfur.cloudhosting.co.uk (77.72.0.138)
  4072.  
  4073. NSE: Script Post-scanning.
  4074. Initiating NSE at 10:23
  4075. Completed NSE at 10:23, 0.00s elapsed
  4076. Initiating NSE at 10:23
  4077. Completed NSE at 10:23, 0.00s elapsed
  4078. #######################################################################################################################################
  4079. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-13 10:23 EDT
  4080. NSE: Loaded 47 scripts for scanning.
  4081. NSE: Script Pre-scanning.
  4082. Initiating NSE at 10:23
  4083. Completed NSE at 10:23, 0.00s elapsed
  4084. Initiating NSE at 10:23
  4085. Completed NSE at 10:23, 0.00s elapsed
  4086. Initiating Parallel DNS resolution of 1 host. at 10:23
  4087. Completed Parallel DNS resolution of 1 host. at 10:23, 0.03s elapsed
  4088. Initiating UDP Scan at 10:23
  4089. Scanning sulfur.cloudhosting.co.uk (77.72.0.138) [15 ports]
  4090. Completed UDP Scan at 10:23, 2.38s elapsed (15 total ports)
  4091. Initiating Service scan at 10:23
  4092. Scanning 13 services on sulfur.cloudhosting.co.uk (77.72.0.138)
  4093. Service scan Timing: About 7.69% done; ETC: 10:44 (0:19:36 remaining)
  4094. Completed Service scan at 10:25, 102.58s elapsed (13 services on 1 host)
  4095. Initiating OS detection (try #1) against sulfur.cloudhosting.co.uk (77.72.0.138)
  4096. Retrying OS detection (try #2) against sulfur.cloudhosting.co.uk (77.72.0.138)
  4097. Initiating Traceroute at 10:25
  4098. Completed Traceroute at 10:25, 7.05s elapsed
  4099. Initiating Parallel DNS resolution of 1 host. at 10:25
  4100. Completed Parallel DNS resolution of 1 host. at 10:25, 0.00s elapsed
  4101. NSE: Script scanning 77.72.0.138.
  4102. Initiating NSE at 10:25
  4103. Completed NSE at 10:25, 7.12s elapsed
  4104. Initiating NSE at 10:25
  4105. Completed NSE at 10:25, 1.01s elapsed
  4106. Nmap scan report for sulfur.cloudhosting.co.uk (77.72.0.138)
  4107. Host is up (0.080s latency).
  4108.  
  4109. PORT STATE SERVICE VERSION
  4110. 53/udp open|filtered domain
  4111. 67/udp open|filtered dhcps
  4112. 68/udp open|filtered dhcpc
  4113. 69/udp open|filtered tftp
  4114. 88/udp open|filtered kerberos-sec
  4115. 123/udp open|filtered ntp
  4116. 137/udp filtered netbios-ns
  4117. 138/udp filtered netbios-dgm
  4118. 139/udp open|filtered netbios-ssn
  4119. 161/udp open|filtered snmp
  4120. 162/udp open|filtered snmptrap
  4121. 389/udp open|filtered ldap
  4122. 500/udp open|filtered isakmp
  4123. |_ike-version: ERROR: Script execution failed (use -d to debug)
  4124. 520/udp open|filtered route
  4125. 2049/udp open|filtered nfs
  4126. Too many fingerprints match this host to give specific OS details
  4127.  
  4128. TRACEROUTE (using port 137/udp)
  4129. HOP RTT ADDRESS
  4130. 1 20.16 ms 10.244.204.1
  4131. 2 ... 3
  4132. 4 19.94 ms 10.244.204.1
  4133. 5 60.59 ms 10.244.204.1
  4134. 6 60.59 ms 10.244.204.1
  4135. 7 60.58 ms 10.244.204.1
  4136. 8 60.54 ms 10.244.204.1
  4137. 9 41.28 ms 10.244.204.1
  4138. 10 20.50 ms 10.244.204.1
  4139. 11 ... 18
  4140. 19 21.33 ms 10.244.204.1
  4141. 20 20.83 ms 10.244.204.1
  4142. 21 ... 27
  4143. 28 19.99 ms 10.244.204.1
  4144. 29 ...
  4145. 30 20.12 ms 10.244.204.1
  4146.  
  4147. NSE: Script Post-scanning.
  4148. Initiating NSE at 10:25
  4149. Completed NSE at 10:25, 0.00s elapsed
  4150. Initiating NSE at 10:25
  4151. Completed NSE at 10:25, 0.00s elapsed
  4152. #######################################################################################################################################
  4153. Hosts
  4154. =====
  4155.  
  4156. address mac name os_name os_flavor os_sp purpose info comments
  4157. ------- --- ---- ------- --------- ----- ------- ---- --------
  4158. 77.72.0.138 sulfur.cloudhosting.co.uk Linux 3.X server
  4159.  
  4160. Services
  4161. ========
  4162.  
  4163. host port proto name state info
  4164. ---- ---- ----- ---- ----- ----
  4165. 77.72.0.138 21 tcp ftp open
  4166. 77.72.0.138 22 tcp ssh open
  4167. 77.72.0.138 25 tcp smtp closed
  4168. 77.72.0.138 26 tcp rsftp open
  4169. 77.72.0.138 53 udp domain unknown
  4170. 77.72.0.138 67 udp dhcps unknown
  4171. 77.72.0.138 68 udp dhcpc unknown
  4172. 77.72.0.138 69 udp tftp unknown
  4173. 77.72.0.138 80 tcp http open LiteSpeed httpd
  4174. 77.72.0.138 88 udp kerberos-sec unknown
  4175. 77.72.0.138 110 tcp pop3 open
  4176. 77.72.0.138 123 udp ntp unknown
  4177. 77.72.0.138 137 udp netbios-ns filtered
  4178. 77.72.0.138 138 udp netbios-dgm filtered
  4179. 77.72.0.138 139 tcp netbios-ssn closed
  4180. 77.72.0.138 139 udp netbios-ssn unknown
  4181. 77.72.0.138 143 tcp imap open
  4182. 77.72.0.138 161 udp snmp unknown
  4183. 77.72.0.138 162 udp snmptrap unknown
  4184. 77.72.0.138 389 udp ldap unknown
  4185. 77.72.0.138 443 tcp ssl/http open LiteSpeed httpd
  4186. 77.72.0.138 445 tcp microsoft-ds closed
  4187. 77.72.0.138 500 udp isakmp unknown
  4188. 77.72.0.138 520 udp route unknown
  4189. 77.72.0.138 525 tcp timed open
  4190. 77.72.0.138 587 tcp submission open
  4191. 77.72.0.138 2049 udp nfs unknown
  4192. 77.72.0.138 2082 tcp http open LiteSpeed httpd
  4193. 77.72.0.138 2083 tcp ssl/http open LiteSpeed httpd
  4194. 77.72.0.138 2086 tcp http open LiteSpeed httpd
  4195. 77.72.0.138 2087 tcp ssl/http open LiteSpeed httpd
  4196. 77.72.0.138 2095 tcp http open LiteSpeed httpd
  4197. 77.72.0.138 2096 tcp ssl/http open LiteSpeed httpd
  4198. 77.72.0.138 3306 tcp mysql open
  4199. 77.72.0.138 8887 tcp ssl/http open LiteSpeed httpd
  4200. 77.72.0.138 8998 tcp http open LiteSpeed httpd
  4201. 77.72.0.138 8999 tcp bctp open
  4202. ######################################################################################################################################
  4203. [+] URL: https://hcsp.gov.sd/
  4204. [+] Started: Fri Sep 13 09:58:47 2019
  4205.  
  4206. Interesting Finding(s):
  4207.  
  4208. [+] https://hcsp.gov.sd/
  4209. | Interesting Entries:
  4210. | - server: LiteSpeed
  4211. | - alt-svc: quic=":443"; ma=2592000; v="35,39,43,44"
  4212. | Found By: Headers (Passive Detection)
  4213. | Confidence: 100%
  4214.  
  4215. [+] https://hcsp.gov.sd/robots.txt
  4216. | Interesting Entries:
  4217. | - /wp-admin/
  4218. | - /wp-admin/admin-ajax.php
  4219. | Found By: Robots Txt (Aggressive Detection)
  4220. | Confidence: 100%
  4221.  
  4222. [+] https://hcsp.gov.sd/xmlrpc.php
  4223. | Found By: Link Tag (Passive Detection)
  4224. | Confidence: 100%
  4225. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  4226. | References:
  4227. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  4228. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  4229. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  4230. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  4231. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  4232.  
  4233. [+] https://hcsp.gov.sd/readme.html
  4234. | Found By: Direct Access (Aggressive Detection)
  4235. | Confidence: 100%
  4236.  
  4237. [+] This site seems to be a multisite
  4238. | Found By: Direct Access (Aggressive Detection)
  4239. | Confidence: 100%
  4240. | Reference: http://codex.wordpress.org/Glossary#Multisite
  4241.  
  4242. [+] https://hcsp.gov.sd/wp-cron.php
  4243. | Found By: Direct Access (Aggressive Detection)
  4244. | Confidence: 60%
  4245. | References:
  4246. | - https://www.iplocation.net/defend-wordpress-from-ddos
  4247. | - https://github.com/wpscanteam/wpscan/issues/1299
  4248.  
  4249. [+] WordPress version 4.7.14 identified (Latest, released on 2019-09-05).
  4250. | Detected By: Query Parameter In Install Page (Aggressive Detection)
  4251. | - https://hcsp.gov.sd/wp-includes/css/buttons.min.css?ver=4.7.14
  4252. | - https://hcsp.gov.sd/wp-admin/css/install.min.css?ver=4.7.14
  4253. | - https://hcsp.gov.sd/wp-includes/css/dashicons.min.css?ver=4.7.14
  4254. | Confirmed By: Query Parameter In Upgrade Page (Aggressive Detection)
  4255. | - https://hcsp.gov.sd/wp-includes/css/buttons.min.css?ver=4.7.14
  4256. | - https://hcsp.gov.sd/wp-admin/css/install.min.css?ver=4.7.14
  4257.  
  4258. [+] WordPress theme in use: hcsp
  4259. | Location: https://hcsp.gov.sd/wp-content/themes/hcsp/
  4260. | Style URL: https://hcsp.gov.sd/wp-content/themes/hcsp/style.css
  4261. | Style Name: HCSP
  4262. | Style URI: http://fabric.sd
  4263. | Description: A custom website template....
  4264. | Author: fabric
  4265. | Author URI: http://fabric.sd
  4266. |
  4267. | Detected By: Css Style (Passive Detection)
  4268. | Confirmed By: Urls In Homepage (Passive Detection)
  4269. |
  4270. | Version: 1.0 (80% confidence)
  4271. | Detected By: Style (Passive Detection)
  4272. | - https://hcsp.gov.sd/wp-content/themes/hcsp/style.css, Match: 'Version: 1.0'
  4273.  
  4274. [+] Enumerating All Plugins (via Passive Methods)
  4275. [+] Checking Plugin Versions (via Passive and Aggressive Methods)
  4276.  
  4277. [i] Plugin(s) Identified:
  4278.  
  4279. [+] mechanic-visitor-counter
  4280. | Location: https://hcsp.gov.sd/wp-content/plugins/mechanic-visitor-counter/
  4281. | Last Updated: 2016-12-28T11:49:00.000Z
  4282. | [!] The version is out of date, the latest version is 3.2.2
  4283. |
  4284. | Detected By: Urls In Homepage (Passive Detection)
  4285. |
  4286. | Version: 3.1 (80% confidence)
  4287. | Detected By: Readme - Stable Tag (Aggressive Detection)
  4288. | - https://hcsp.gov.sd/wp-content/plugins/mechanic-visitor-counter/readme.txt
  4289.  
  4290. [+] pointelle-slider
  4291. | Location: https://hcsp.gov.sd/wp-content/plugins/pointelle-slider/
  4292. |
  4293. | Detected By: Urls In Homepage (Passive Detection)
  4294. |
  4295. | The version could not be determined.
  4296.  
  4297. [+] Enumerating Config Backups (via Passive and Aggressive Methods)
  4298. Checking Config Backups - Time: 00:00:01 <=============> (21 / 21) 100.00% Time: 00:00:01
  4299.  
  4300. [i] No Config Backups Found.
  4301.  
  4302.  
  4303. [+] Finished: Fri Sep 13 09:59:00 2019
  4304. [+] Requests Done: 82
  4305. [+] Cached Requests: 7
  4306. [+] Data Sent: 14.675 KB
  4307. [+] Data Received: 24.567 MB
  4308. [+] Memory used: 211.598 MB
  4309. [+] Elapsed time: 00:00:12
  4310. #######################################################################################################################################
  4311. [+] URL: https://hcsp.gov.sd/
  4312. [+] Started: Fri Sep 13 09:58:52 2019
  4313.  
  4314. Interesting Finding(s):
  4315.  
  4316. [+] https://hcsp.gov.sd/
  4317. | Interesting Entries:
  4318. | - server: LiteSpeed
  4319. | - alt-svc: quic=":443"; ma=2592000; v="35,39,43,44"
  4320. | Found By: Headers (Passive Detection)
  4321. | Confidence: 100%
  4322.  
  4323. [+] https://hcsp.gov.sd/robots.txt
  4324. | Interesting Entries:
  4325. | - /wp-admin/
  4326. | - /wp-admin/admin-ajax.php
  4327. | Found By: Robots Txt (Aggressive Detection)
  4328. | Confidence: 100%
  4329.  
  4330. [+] https://hcsp.gov.sd/xmlrpc.php
  4331. | Found By: Link Tag (Passive Detection)
  4332. | Confidence: 100%
  4333. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  4334. | References:
  4335. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  4336. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  4337. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  4338. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  4339. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  4340.  
  4341. [+] https://hcsp.gov.sd/readme.html
  4342. | Found By: Direct Access (Aggressive Detection)
  4343. | Confidence: 100%
  4344.  
  4345. [+] This site seems to be a multisite
  4346. | Found By: Direct Access (Aggressive Detection)
  4347. | Confidence: 100%
  4348. | Reference: http://codex.wordpress.org/Glossary#Multisite
  4349.  
  4350. [+] https://hcsp.gov.sd/wp-cron.php
  4351. | Found By: Direct Access (Aggressive Detection)
  4352. | Confidence: 60%
  4353. | References:
  4354. | - https://www.iplocation.net/defend-wordpress-from-ddos
  4355. | - https://github.com/wpscanteam/wpscan/issues/1299
  4356.  
  4357. [+] WordPress version 4.7.14 identified (Latest, released on 2019-09-05).
  4358. | Detected By: Query Parameter In Install Page (Aggressive Detection)
  4359. | - https://hcsp.gov.sd/wp-includes/css/buttons.min.css?ver=4.7.14
  4360. | - https://hcsp.gov.sd/wp-admin/css/install.min.css?ver=4.7.14
  4361. | - https://hcsp.gov.sd/wp-includes/css/dashicons.min.css?ver=4.7.14
  4362. | Confirmed By: Query Parameter In Upgrade Page (Aggressive Detection)
  4363. | - https://hcsp.gov.sd/wp-includes/css/buttons.min.css?ver=4.7.14
  4364. | - https://hcsp.gov.sd/wp-admin/css/install.min.css?ver=4.7.14
  4365.  
  4366. [+] WordPress theme in use: hcsp
  4367. | Location: https://hcsp.gov.sd/wp-content/themes/hcsp/
  4368. | Style URL: https://hcsp.gov.sd/wp-content/themes/hcsp/style.css
  4369. | Style Name: HCSP
  4370. | Style URI: http://fabric.sd
  4371. | Description: A custom website template....
  4372. | Author: fabric
  4373. | Author URI: http://fabric.sd
  4374. |
  4375. | Detected By: Css Style (Passive Detection)
  4376. | Confirmed By: Urls In Homepage (Passive Detection)
  4377. |
  4378. | Version: 1.0 (80% confidence)
  4379. | Detected By: Style (Passive Detection)
  4380. | - https://hcsp.gov.sd/wp-content/themes/hcsp/style.css, Match: 'Version: 1.0'
  4381.  
  4382. [+] Enumerating Users (via Passive and Aggressive Methods)
  4383. Brute Forcing Author IDs - Time: 00:00:05 <==> (10 / 10) 100.00% Time: 00:00:05
  4384.  
  4385. [i] User(s) Identified:
  4386.  
  4387. [+] hcsp_admin
  4388. | Detected By: Rss Generator (Aggressive Detection)
  4389. | Confirmed By:
  4390. | Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4391. | Login Error Messages (Aggressive Detection)
  4392.  
  4393. [+] user2
  4394. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4395. | Confirmed By: Login Error Messages (Aggressive Detection)
  4396.  
  4397. [+] tarig3
  4398. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4399. | Confirmed By: Login Error Messages (Aggressive Detection)
  4400.  
  4401. [+] miqdad
  4402. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4403. | Confirmed By: Login Error Messages (Aggressive Detection)
  4404.  
  4405.  
  4406. [+] Finished: Fri Sep 13 09:59:05 2019
  4407. [+] Requests Done: 37
  4408. [+] Cached Requests: 35
  4409. [+] Data Sent: 7.775 KB
  4410. [+] Data Received: 281.508 KB
  4411. [+] Memory used: 102.426 MB
  4412. [+] Elapsed time: 00:00:13
  4413. #######################################################################################################################################
  4414. [+] URL: https://hcsp.gov.sd/
  4415. [+] Started: Fri Sep 13 10:01:18 2019
  4416.  
  4417. Interesting Finding(s):
  4418.  
  4419. [+] https://hcsp.gov.sd/
  4420. | Interesting Entries:
  4421. | - server: LiteSpeed
  4422. | - alt-svc: quic=":443"; ma=2592000; v="35,39,43,44"
  4423. | Found By: Headers (Passive Detection)
  4424. | Confidence: 100%
  4425.  
  4426. [+] https://hcsp.gov.sd/robots.txt
  4427. | Interesting Entries:
  4428. | - /wp-admin/
  4429. | - /wp-admin/admin-ajax.php
  4430. | Found By: Robots Txt (Aggressive Detection)
  4431. | Confidence: 100%
  4432.  
  4433. [+] https://hcsp.gov.sd/xmlrpc.php
  4434. | Found By: Link Tag (Passive Detection)
  4435. | Confidence: 30%
  4436. | References:
  4437. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  4438. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  4439. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  4440. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  4441. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  4442.  
  4443. [+] https://hcsp.gov.sd/readme.html
  4444. | Found By: Direct Access (Aggressive Detection)
  4445. | Confidence: 100%
  4446.  
  4447. [+] This site seems to be a multisite
  4448. | Found By: Direct Access (Aggressive Detection)
  4449. | Confidence: 100%
  4450. | Reference: http://codex.wordpress.org/Glossary#Multisite
  4451.  
  4452. [+] https://hcsp.gov.sd/wp-cron.php
  4453. | Found By: Direct Access (Aggressive Detection)
  4454. | Confidence: 60%
  4455. | References:
  4456. | - https://www.iplocation.net/defend-wordpress-from-ddos
  4457. | - https://github.com/wpscanteam/wpscan/issues/1299
  4458.  
  4459. [+] WordPress version 4.7.14 identified (Latest, released on 2019-09-05).
  4460. | Detected By: Query Parameter In Install Page (Aggressive Detection)
  4461. | - https://hcsp.gov.sd/wp-includes/css/buttons.min.css?ver=4.7.14
  4462. | - https://hcsp.gov.sd/wp-admin/css/install.min.css?ver=4.7.14
  4463. | - https://hcsp.gov.sd/wp-includes/css/dashicons.min.css?ver=4.7.14
  4464. | Confirmed By: Query Parameter In Upgrade Page (Aggressive Detection)
  4465. | - https://hcsp.gov.sd/wp-includes/css/buttons.min.css?ver=4.7.14
  4466. | - https://hcsp.gov.sd/wp-admin/css/install.min.css?ver=4.7.14
  4467.  
  4468. [+] WordPress theme in use: hcsp
  4469. | Location: https://hcsp.gov.sd/wp-content/themes/hcsp/
  4470. | Style URL: https://hcsp.gov.sd/wp-content/themes/hcsp/style.css
  4471. | Style Name: HCSP
  4472. | Style URI: http://fabric.sd
  4473. | Description: A custom website template....
  4474. | Author: fabric
  4475. | Author URI: http://fabric.sd
  4476. |
  4477. | Detected By: Css Style (Passive Detection)
  4478. | Confirmed By: Urls In Homepage (Passive Detection)
  4479. |
  4480. | Version: 1.0 (80% confidence)
  4481. | Detected By: Style (Passive Detection)
  4482. | - https://hcsp.gov.sd/wp-content/themes/hcsp/style.css, Match: 'Version: 1.0'
  4483.  
  4484. [+] Enumerating Users (via Passive and Aggressive Methods)
  4485. Brute Forcing Author IDs - Time: 00:00:06 <============> (10 / 10) 100.00% Time: 00:00:06
  4486.  
  4487. [i] User(s) Identified:
  4488.  
  4489. [+] hcsp_admin
  4490. | Detected By: Rss Generator (Aggressive Detection)
  4491. | Confirmed By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4492.  
  4493. [+] user2
  4494. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4495.  
  4496. [+] tarig3
  4497. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4498.  
  4499. [+] miqdad
  4500. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  4501.  
  4502.  
  4503. [+] Finished: Fri Sep 13 10:01:33 2019
  4504. [+] Requests Done: 20
  4505. [+] Cached Requests: 55
  4506. [+] Data Sent: 4.333 KB
  4507. [+] Data Received: 18.609 KB
  4508. [+] Memory used: 101.738 MB
  4509. [+] Elapsed time: 00:00:15
  4510. #######################################################################################################################################
  4511. [INFO] ------TARGET info------
  4512. [*] TARGET: https://hcsp.gov.sd/
  4513. [*] TARGET IP: 77.72.0.138
  4514. [INFO] NO load balancer detected for hcsp.gov.sd...
  4515. [*] DNS servers: ns1.cloudhosting.co.uk.
  4516. [*] TARGET server: LiteSpeed
  4517. [*] CC: hcsp.gov.sd
  4518. [*] Country: invalid query
  4519. [*] RegionCode:
  4520. [*] RegionName:
  4521. [*] City:
  4522. [*] ASN: AS12488
  4523. [*] BGP_PREFIX: 77.72.0.0/21
  4524. [*] ISP: KRYSTAL Krystal Hosting Ltd, GR
  4525. [INFO] SSL/HTTPS certificate detected
  4526. [*] Issuer: issuer=C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
  4527. [*] Subject: subject=CN = hcsp.gov.sd
  4528. [ALERT] Let's Encrypt is commonly used for Phishing
  4529. [INFO] DNS enumeration:
  4530. [*] ftp.hcsp.gov.sd 77.72.0.138
  4531. [*] mail.hcsp.gov.sd hcsp.gov.sd. 77.72.0.138
  4532. [*] webmail.hcsp.gov.sd 77.72.0.138
  4533. [INFO] Possible abuse mails are:
  4534. [INFO] NO PAC (Proxy Auto Configuration) file FOUND
  4535. [ALERT] robots.txt file FOUND in http://hcsp.gov.sd/robots.txt
  4536. [INFO] Checking for HTTP status codes recursively from http://hcsp.gov.sd/robots.txt
  4537. [INFO] Status code Folders
  4538. [INFO] Starting FUZZing in http://hcsp.gov.sd/FUzZzZzZzZz...
  4539. [INFO] Status code Folders
  4540. [*] 200 http://hcsp.gov.sd/index
  4541. [*] 200 http://hcsp.gov.sd/images
  4542. [*] 200 http://hcsp.gov.sd/download
  4543. [*] 200 http://hcsp.gov.sd/2006
  4544. [*] 200 http://hcsp.gov.sd/news
  4545. [*] 200 http://hcsp.gov.sd/crack
  4546. [*] 200 http://hcsp.gov.sd/serial
  4547. [*] 200 http://hcsp.gov.sd/warez
  4548. [*] 200 http://hcsp.gov.sd/full
  4549. [*] 200 http://hcsp.gov.sd/12
  4550. [ALERT] Look in the source code. It may contain passwords
  4551. [INFO] SAME content in http://hcsp.gov.sd/ AND http://77.72.0.138/
  4552. [INFO] Links found from https://hcsp.gov.sd/:
  4553. [INFO] Shodan detected the following opened ports on 77.72.0.138:
  4554. [*] 2086
  4555. [*] 2087
  4556. [*] 2095
  4557. [*] 2096
  4558. [*] 21
  4559. [*] 443
  4560. [*] 465
  4561. [*] 80
  4562. [*] 995
  4563. [INFO] ------VirusTotal SECTION------
  4564. [INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
  4565. [INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
  4566. [INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
  4567. [INFO] ------Alexa Rank SECTION------
  4568. [INFO] Percent of Visitors Rank in Country:
  4569. [INFO] Percent of Search Traffic:
  4570. [INFO] Percent of Unique Visits:
  4571. [INFO] Total Sites Linking In:
  4572. [*] Total Sites
  4573. [INFO] Useful links related to hcsp.gov.sd - 77.72.0.138:
  4574. [*] https://www.virustotal.com/pt/ip-address/77.72.0.138/information/
  4575. [*] https://www.hybrid-analysis.com/search?host=77.72.0.138
  4576. [*] https://www.shodan.io/host/77.72.0.138
  4577. [*] https://www.senderbase.org/lookup/?search_string=77.72.0.138
  4578. [*] https://www.alienvault.com/open-threat-exchange/ip/77.72.0.138
  4579. [*] http://pastebin.com/search?q=77.72.0.138
  4580. [*] http://urlquery.net/search.php?q=77.72.0.138
  4581. [*] http://www.alexa.com/siteinfo/hcsp.gov.sd
  4582. [*] http://www.google.com/safebrowsing/diagnostic?site=hcsp.gov.sd
  4583. [*] https://censys.io/ipv4/77.72.0.138
  4584. [*] https://www.abuseipdb.com/check/77.72.0.138
  4585. [*] https://urlscan.io/search/#77.72.0.138
  4586. [*] https://github.com/search?q=77.72.0.138&type=Code
  4587. [INFO] Useful links related to AS12488 - 77.72.0.0/21:
  4588. [*] http://www.google.com/safebrowsing/diagnostic?site=AS:12488
  4589. [*] https://www.senderbase.org/lookup/?search_string=77.72.0.0/21
  4590. [*] http://bgp.he.net/AS12488
  4591. [*] https://stat.ripe.net/AS12488
  4592. [INFO] Date: 13/09/19 | Time: 10:02:32
  4593. [INFO] Total time: 0 minute(s) and 44 second(s)
  4594. #######################################################################################################################################
  4595. [*] Load target domain: hcsp.gov.sd
  4596. - starting scanning @ 2019-09-13 10:03:57
  4597.  
  4598. [+] Running & Checking source to be used
  4599. ---------------------------------------------
  4600.  
  4601. ⍥ Shodan [ ✕ ]
  4602. ⍥ Webarchive [ ✔ ]
  4603. ⍥ Dnsdumpster [ ✔ ]
  4604. ⍥ Certspotter [ ✔ ]
  4605. ⍥ Bufferover [ ✔ ]
  4606. ⍥ Riddler [ ✔ ]
  4607. ⍥ Hackertarget [ ✔ ]
  4608. ⍥ Censys [ ✕ ]
  4609. ⍥ Binaryedge [ ✕ ]
  4610. ⍥ Threatminer [ ✔ ]
  4611. ⍥ Entrust [ ✔ ]
  4612. ⍥ Securitytrails [ ✕ ]
  4613. ⍥ Certsh [ ✔ ]
  4614. ⍥ Threatcrowd [ ✔ ]
  4615. ⍥ Virustotal [ ✕ ]
  4616. ⍥ Findsubdomain [ ✔ ]
  4617.  
  4618. [+] Get & Count subdomain total From source
  4619. ---------------------------------------------
  4620.  
  4621. ⍥ Hackertarget: Total Subdomain (1)
  4622. ⍥ Findsubdomain: Total Subdomain (1)
  4623. ⍥ Certspotter: Total Subdomain (2)
  4624. ⍥ Threatminer: Total Subdomain (0)
  4625. ⍥ Certsh: Total Subdomain (1)
  4626. ⍥ BufferOver: Total Subdomain (1)
  4627. ⍥ Entrust: Total Subdomain (1)
  4628. ⍥ Threatcrowd: Total Subdomain (0)
  4629. ⍥ Dnsdumpster: Total Subdomain (5)
  4630. ⍥ Riddler: Total Subdomain (1)
  4631. ⍥ Webarchive: Total Subdomain (1)
  4632.  
  4633. [+] Parsing & Sorting list Domain
  4634. ---------------------------------------------
  4635.  
  4636. ⍥ Total [2]
  4637.  
  4638. - hcsp.gov.sd
  4639. - www.hcsp.gov.sd
  4640.  
  4641. ⍥ Total [2]
  4642.  
  4643. [+] Probe subdomain for working on http/https
  4644. ---------------------------------------------
  4645.  
  4646. - http://www.hcsp.gov.sd
  4647. - http://hcsp.gov.sd
  4648. - https://hcsp.gov.sd
  4649. - https://www.hcsp.gov.sd
  4650.  
  4651. ⍥ Total [4]
  4652.  
  4653.  
  4654. [+] Check Live Host: Ping Sweep - ICMP PING
  4655. ---------------------------------------------
  4656.  
  4657. ⍥ [DEAD] hcsp.gov.sd
  4658. ⍥ [DEAD] www.hcsp.gov.sd
  4659.  
  4660. [+] Check Resolving: Subdomains & Domains
  4661. ---------------------------------------------
  4662.  
  4663. ⍥ Resolving domains to: 77.72.0.138
  4664. ⍥ Resolving domains to: 77.72.0.138
  4665.  
  4666. [+] Subdomain TakeOver - Check Possible Vulns
  4667. ---------------------------------------------
  4668.  
  4669. ⍥ [FAILS] En: Unknown http://hcsp.gov.sd
  4670. ⍥ [FAILS] En: Unknown http://www.hcsp.gov.sd
  4671. ⍥ [FAILS] En: Unknown https://hcsp.gov.sd
  4672. ⍥ [FAILS] En: Unknown https://www.hcsp.gov.sd
  4673.  
  4674. [+] Checks status code on port 80 and 443
  4675. ---------------------------------------------
  4676.  
  4677. ⍥ [200] http://hcsp.gov.sd
  4678. ⍥ [200] http://www.hcsp.gov.sd
  4679. ⍥ [200] https://hcsp.gov.sd
  4680. ⍥ [200] https://www.hcsp.gov.sd
  4681.  
  4682. [+] Web Screenshots: from domain list
  4683. ---------------------------------------------
  4684.  
  4685. [+] 4 URLs to be screenshot
  4686.  
  4687. [+] 4 actual URLs screenshot
  4688. [+] 0 error(s)
  4689.  
  4690. [+] Sud⍥my has been sucessfully completed
  4691. ---------------------------------------------
  4692.  
  4693. ⍥ Location output:
  4694. - output/09-13-2019/hcsp.gov.sd
  4695. - output/09-13-2019/hcsp.gov.sd/report
  4696. - output/09-13-2019/hcsp.gov.sd/screenshots
  4697. #######################################################################################################################################
  4698. Anonymous JTSEC #OpSudan Full Recon #1
Advertisement
Add Comment
Please, Sign In to add comment