Advertisement
Guest User

Untitled

a guest
Jun 16th, 2018
172
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 39.23 KB | None | 0 0
  1. Scanning 89 services on 19 hosts
  2. Service scan Timing: About 47.78% done; ETC: 08:23 (0:00:35 remaining)
  3. Completed Service scan at 08:24, 152.39s elapsed (90 services on 19 hosts)
  4. Initiating OS detection (try #1) against 19 hosts
  5. Retrying OS detection (try #2) against 6 hosts
  6. WARNING: OS didn't match until try #2
  7. NSE: Script scanning 19 hosts.
  8. Initiating NSE at 08:25
  9. Completed NSE at 08:27, 98.15s elapsed
  10. Nmap scan report for 1.1.0.100
  11. Host is up (0.00047s latency).
  12. Not shown: 980 closed ports
  13. PORT STATE SERVICE VERSION
  14. 53/tcp open domain Microsoft DNS
  15. 88/tcp open kerberos-sec Windows 2003 Kerberos (server time: 2018-06-16 15:20:52Z)
  16. 135/tcp open msrpc Microsoft Windows RPC
  17. 139/tcp open netbios-ssn
  18. 389/tcp open ldap
  19. 445/tcp open netbios-ssn
  20. 464/tcp open kpasswd5?
  21. 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
  22. 636/tcp open ldapssl?
  23. 3268/tcp open ldap
  24. 3269/tcp open globalcatLDAPssl?
  25. 3389/tcp open ms-wbt-server?
  26. 49152/tcp open msrpc Microsoft Windows RPC
  27. 49153/tcp open msrpc Microsoft Windows RPC
  28. 49154/tcp open msrpc Microsoft Windows RPC
  29. 49155/tcp open msrpc Microsoft Windows RPC
  30. 49157/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
  31. 49158/tcp open msrpc Microsoft Windows RPC
  32. 49159/tcp open msrpc Microsoft Windows RPC
  33. 49167/tcp open msrpc Microsoft Windows RPC
  34. MAC Address: E0:07:1B:FF:65:01 (Unknown)
  35. Device type: general purpose
  36. Running: Microsoft Windows 2012
  37. OS CPE: cpe:/o:microsoft:windows_server_2012
  38. OS details: Microsoft Windows Server 2012
  39. Uptime guess: 47.136 days (since Mon Apr 30 05:12:24 2018)
  40. Network Distance: 1 hop
  41. TCP Sequence Prediction: Difficulty=260 (Good luck!)
  42. IP ID Sequence Generation: Incremental
  43. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  44.  
  45. Host script results:
  46. | nbstat: NetBIOS name: ASSISI, NetBIOS user: <unknown>, NetBIOS MAC: e0:07:1b:ff:65:01 (unknown)
  47. | Names:
  48. | SFA<1c> Flags: <group><active>
  49. | ASSISI<00> Flags: <unique><active>
  50. | SFA<00> Flags: <group><active>
  51. | ASSISI<20> Flags: <unique><active>
  52. |_ SFA<1b> Flags: <unique><active>
  53. | smb-os-discovery:
  54. | OS: Windows Server 2012 R2 Standard 9600 (Windows Server 2012 R2 Standard 6.3)
  55. | OS CPE: cpe:/o:microsoft:windows_server_2012::-
  56. | Computer name: ASSISI
  57. | NetBIOS computer name: ASSISI
  58. | Domain name: sfa.com
  59. | Forest name: sfa.com
  60. | FQDN: ASSISI.sfa.com
  61. |_ System time: 2018-06-16T19:24:45+04:00
  62. | smb-security-mode:
  63. | Account that was used for smb scripts: guest
  64. | User-level authentication
  65. | SMB Security: Challenge/response passwords supported
  66. |_ Message signing required
  67. |_smbv2-enabled: Server supports SMBv2 protocol
  68.  
  69. TRACEROUTE
  70. HOP RTT ADDRESS
  71. 1 0.47 ms 1.1.0.100
  72.  
  73. Nmap scan report for 1.1.0.181
  74. Host is up (0.00030s latency).
  75. Not shown: 986 closed ports
  76. PORT STATE SERVICE VERSION
  77. 80/tcp open http Microsoft IIS httpd 10.0
  78. | http-methods: OPTIONS TRACE GET HEAD POST
  79. | Potentially risky methods: TRACE
  80. |_See http://nmap.org/nsedoc/scripts/http-methods.html
  81. |_http-title: Site doesn't have a title.
  82. 135/tcp filtered msrpc
  83. 139/tcp filtered netbios-ssn
  84. 445/tcp filtered microsoft-ds
  85. 1110/tcp filtered nfsd-status
  86. 1801/tcp open msmq?
  87. 2103/tcp open msrpc Microsoft Windows RPC
  88. 2105/tcp open msrpc Microsoft Windows RPC
  89. 2107/tcp open msrpc Microsoft Windows RPC
  90. 2869/tcp filtered icslap
  91. 3389/tcp filtered ms-wbt-server
  92. 5357/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
  93. |_http-methods: No Allow or Public header in OPTIONS response (status code 503)
  94. |_http-title: Service Unavailable
  95. 8000/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
  96. |_http-methods: No Allow or Public header in OPTIONS response (status code 404)
  97. |_http-title: Not Found
  98. 19780/tcp filtered unknown
  99. MAC Address: 00:26:55:47:C9:1C (Hewlett-Packard Company)
  100. Device type: general purpose
  101. Running (JUST GUESSING): Microsoft Windows 2008|7|Vista|2012|Longhorn|8.1 (96%)
  102. OS CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1 cpe:/o:microsoft:windows_7 cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows_vista::sp1 cpe:/o:microsoft:windows_vista::sp2 cpe:/o:microsoft:windows_server_2012 cpe:/o:microsoft:windows cpe:/o:microsoft:windows_8.1
  103. Aggressive OS guesses: Microsoft Windows Server 2008 R2 SP1 (96%), Microsoft Windows Server 2008 SP2 (94%), Microsoft Windows 7 or Windows Server 2008 (94%), Microsoft Windows 7 Professional (94%), Microsoft Windows 7 SP0 - SP1, Windows Server 2008 SP1, or Windows 8 (94%), Microsoft Windows 7 Ultimate (94%), Microsoft Windows 7 Ultimate Beta (build 7000) (94%), Microsoft Windows 7 SP 1 (94%), Microsoft Windows 8 (94%), Microsoft Windows Vista SP1 - SP2, Windows Server 2008 SP2, or Windows 7 (94%)
  104. No exact OS matches for host (test conditions non-ideal).
  105. Uptime guess: 2.994 days (since Wed Jun 13 08:36:06 2018)
  106. Network Distance: 1 hop
  107. TCP Sequence Prediction: Difficulty=259 (Good luck!)
  108. IP ID Sequence Generation: Incremental
  109. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  110.  
  111. TRACEROUTE
  112. HOP RTT ADDRESS
  113. 1 0.30 ms 1.1.0.181
  114.  
  115. Nmap scan report for 1.1.0.189
  116. Host is up (0.00037s latency).
  117. Not shown: 986 closed ports
  118. PORT STATE SERVICE VERSION
  119. 135/tcp filtered msrpc
  120. 139/tcp filtered netbios-ssn
  121. 445/tcp filtered microsoft-ds
  122. 1110/tcp filtered nfsd-status
  123. 2869/tcp filtered icslap
  124. 3389/tcp filtered ms-wbt-server
  125. 7070/tcp open ssl/realserver?
  126. 19780/tcp filtered unknown
  127. 49152/tcp open msrpc Microsoft Windows RPC
  128. 49153/tcp open msrpc Microsoft Windows RPC
  129. 49154/tcp open msrpc Microsoft Windows RPC
  130. 49156/tcp open msrpc Microsoft Windows RPC
  131. 49159/tcp open msrpc Microsoft Windows RPC
  132. 49161/tcp open msrpc Microsoft Windows RPC
  133. MAC Address: 74:D4:35:C6:DB:93 (Giga-byte Technology Co.)
  134. Device type: general purpose
  135. Running: Microsoft Windows 2008
  136. OS CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1
  137. OS details: Microsoft Windows Server 2008 R2 SP1
  138. Uptime guess: 2.670 days (since Wed Jun 13 16:22:30 2018)
  139. Network Distance: 1 hop
  140. TCP Sequence Prediction: Difficulty=262 (Good luck!)
  141. IP ID Sequence Generation: Incremental
  142. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  143.  
  144. TRACEROUTE
  145. HOP RTT ADDRESS
  146. 1 0.37 ms 1.1.0.189
  147.  
  148. Nmap scan report for 1.1.0.198
  149. Host is up (0.00023s latency).
  150. Not shown: 997 closed ports
  151. PORT STATE SERVICE VERSION
  152. 135/tcp open msrpc Microsoft Windows RPC
  153. 139/tcp open netbios-ssn
  154. 445/tcp open microsoft-ds Microsoft Windows XP microsoft-ds
  155. MAC Address: 00:07:E9:86:EF:11 (Intel)
  156. Device type: general purpose
  157. Running: Microsoft Windows XP
  158. OS CPE: cpe:/o:microsoft:windows_xp::sp2 cpe:/o:microsoft:windows_xp::sp3
  159. OS details: Microsoft Windows XP SP2 or SP3
  160. Network Distance: 1 hop
  161. TCP Sequence Prediction: Difficulty=258 (Good luck!)
  162. IP ID Sequence Generation: Incremental
  163. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  164.  
  165. Host script results:
  166. | nbstat: NetBIOS name: CP, NetBIOS user: <unknown>, NetBIOS MAC: 00:07:e9:86:ef:11 (Intel)
  167. | Names:
  168. | CP<00> Flags: <unique><active>
  169. | MSHOME<00> Flags: <group><active>
  170. | CP<20> Flags: <unique><active>
  171. | MSHOME<1e> Flags: <group><active>
  172. | MSHOME<1d> Flags: <unique><active>
  173. |_ \x01\x02__MSBROWSE__\x02<01> Flags: <group><active>
  174. | smb-os-discovery:
  175. | OS: Windows XP (Windows 2000 LAN Manager)
  176. | OS CPE: cpe:/o:microsoft:windows_xp::-
  177. | Computer name: cp
  178. | NetBIOS computer name: CP
  179. | Workgroup: MSHOME
  180. |_ System time: 2018-06-16T19:33:39+04:00
  181. | smb-security-mode:
  182. | Account that was used for smb scripts: guest
  183. | User-level authentication
  184. | SMB Security: Challenge/response passwords supported
  185. |_ Message signing disabled (dangerous, but default)
  186. |_smbv2-enabled: Server doesn't support SMBv2 protocol
  187.  
  188. TRACEROUTE
  189. HOP RTT ADDRESS
  190. 1 0.23 ms 1.1.0.198
  191.  
  192. Nmap scan report for 1.1.0.200
  193. Host is up (0.00029s latency).
  194. Not shown: 991 closed ports
  195. PORT STATE SERVICE VERSION
  196. 21/tcp open ftp Ricoh Aficio MP C5502 ftpd 11.103
  197. | ftp-anon: Anonymous FTP login allowed (FTP code 230)
  198. | -r--r--r-- root root 200 Jan 1 01:08 help
  199. | -r--r--r-- root root 200 Jan 1 01:08 info
  200. | -r--r--r-- root root 200 Jan 1 01:08 prnlog
  201. | -r--r--r-- root root 200 Jan 1 01:08 stat
  202. |_-r--r--r-- root root 200 Jan 1 01:08 syslog
  203. 23/tcp open telnet Ricoh maintenance telnetd
  204. 80/tcp open ipp Web-Server httpd 3.0 (NRG copier or Ricoh Aficio printer http config)
  205. |_http-methods: No Allow or Public header in OPTIONS response (status code 501)
  206. |_http-title: Web Image Monitor
  207. 139/tcp open tcpwrapped
  208. 514/tcp open shell Ricoh rshd
  209. 515/tcp open printer lpd (error: Illegal service request)
  210. 631/tcp open ipp Web-Server httpd 3.0 (NRG copier or Ricoh Aficio printer http config)
  211. |_http-methods: No Allow or Public header in OPTIONS response (status code 404)
  212. |_http-title: 404 Not Found
  213. 7443/tcp open ssl/oracleas-https?
  214. |_ssl-date: 2018-06-16T18:27:09+00:00; +3h00m45s from local time.
  215. 9100/tcp open jetdirect?
  216. MAC Address: 00:26:73:5F:BC:26 (Ricoh Company)
  217. Aggressive OS guesses: NetBSD 2.1.0_STABLE or Ricoh C720S, 1107EX, MP 2550, or MP 7001 printer (96%), Apple Time Capsule NAS device (NetBSD 4.99) (95%), Apple AirPort Extreme WAP or Time Capsule NAS device (NetBSD 4.99), or QNX 6.5.0 (94%), Ricoh Aficio MP C6000 or GX3050N printer (93%), Ricoh Aficio MP C2550 printer (93%), Apple AirPort Extreme WAP (NetBSD 4.99) (93%), Panasonic DP-8045 printer (92%), Panasonic BB-HCM511A or BL-C140A Network Camera (92%), QNX 6.3 (92%), Apple Time Capsule NAS device (92%)
  218. No exact OS matches for host (test conditions non-ideal).
  219. Network Distance: 1 hop
  220. TCP Sequence Prediction: Difficulty=219 (Good luck!)
  221. IP ID Sequence Generation: Incremental
  222. Service Info: Devices: print server, printer
  223.  
  224. TRACEROUTE
  225. HOP RTT ADDRESS
  226. 1 0.29 ms 1.1.0.200
  227.  
  228. Nmap scan report for 1.1.0.201
  229. Host is up (0.00045s latency).
  230. Not shown: 992 closed ports
  231. PORT STATE SERVICE VERSION
  232. 135/tcp open msrpc Microsoft Windows RPC
  233. 139/tcp open netbios-ssn
  234. 445/tcp open netbios-ssn
  235. 49152/tcp open msrpc Microsoft Windows RPC
  236. 49153/tcp open msrpc Microsoft Windows RPC
  237. 49154/tcp open msrpc Microsoft Windows RPC
  238. 49156/tcp open msrpc Microsoft Windows RPC
  239. 49158/tcp open msrpc Microsoft Windows RPC
  240. MAC Address: 4C:CC:6A:B1:E0:00 (Unknown)
  241. Device type: general purpose
  242. Running (JUST GUESSING): Microsoft Windows 2008|7|2012|8.1|Vista|Longhorn (98%)
  243. OS CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1 cpe:/o:microsoft:windows_7::- cpe:/o:microsoft:windows_7::sp1 cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows_server_2012 cpe:/o:microsoft:windows_8.1 cpe:/o:microsoft:windows_vista cpe:/o:microsoft:windows
  244. Aggressive OS guesses: Microsoft Windows Server 2008 R2 SP1 (98%), Microsoft Windows Server 2008 SP2 (97%), Microsoft Windows 7 SP0 - SP1, Windows Server 2008 SP1, or Windows 8 (97%), Microsoft Windows 7 or Windows Server 2008 R2 (96%), Microsoft Windows 7 SP 1 (96%), Microsoft Windows 8 (96%), Microsoft Windows Server 2012 (95%), Windows 7 Professional SP1 (95%), Microsoft Windows 7 SP1 (95%), Microsoft Windows 7, Windows Server 2012, or Windows 8.1 Update 1 (94%)
  245. No exact OS matches for host (test conditions non-ideal).
  246. Uptime guess: 9.419 days (since Wed Jun 6 22:23:57 2018)
  247. Network Distance: 1 hop
  248. TCP Sequence Prediction: Difficulty=255 (Good luck!)
  249. IP ID Sequence Generation: Incremental
  250. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  251.  
  252. Host script results:
  253. | nbstat: NetBIOS name: CHURCH-SFC, NetBIOS user: <unknown>, NetBIOS MAC: 4c:cc:6a:b1:e0:00 (unknown)
  254. | Names:
  255. | CHURCH-SFC<00> Flags: <unique><active>
  256. | WORKGROUP<00> Flags: <group><active>
  257. | CHURCH-SFC<20> Flags: <unique><active>
  258. |_ WORKGROUP<1e> Flags: <group><active>
  259. | smb-os-discovery:
  260. | OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
  261. | OS CPE: cpe:/o:microsoft:windows_7::sp1:professional
  262. | Computer name: Church-SFC
  263. | NetBIOS computer name: CHURCH-SFC
  264. | Workgroup: WORKGROUP
  265. |_ System time: 2018-06-16T19:26:05+04:00
  266. | smb-security-mode:
  267. | Account that was used for smb scripts: guest
  268. | User-level authentication
  269. | SMB Security: Challenge/response passwords supported
  270. |_ Message signing disabled (dangerous, but default)
  271. |_smbv2-enabled: Server supports SMBv2 protocol
  272.  
  273. TRACEROUTE
  274. HOP RTT ADDRESS
  275. 1 0.45 ms 1.1.0.201
  276.  
  277. Nmap scan report for 1.1.0.206
  278. Host is up (0.00037s latency).
  279. Not shown: 997 closed ports
  280. PORT STATE SERVICE VERSION
  281. 22/tcp open ssh (protocol 2.0)
  282. |_ssh-hostkey:
  283. 53/tcp open domain
  284. 80/tcp open http?
  285. |_http-generator: ERROR: Script execution failed (use -d to debug)
  286. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  287. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:73:d5:33&t=1529162767&url=http://1.1.0.206%2f
  288. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  289. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B42%P=arm-unknown-linux-gnueabih
  290. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\xb0\xbfm\xa8\xd
  291. SF:8\?VRMx\x99\x0f\xb1\xd6N\xc7\0\0\0mcurve25519-sha256@libssh\.org,diffie
  292. SF:-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.ucc\.a
  293. SF:sn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x1
  294. SF:5aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sha1,h
  295. SF:mac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\x9e:\x079
  296. SF:0\xb4\x81r\xe7_>");
  297. MAC Address: F0:9F:C2:73:D5:33 (Unknown)
  298. Device type: general purpose
  299. Running: Linux 2.6.X|3.X
  300. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  301. OS details: Linux 2.6.32 - 3.10
  302. Uptime guess: 11.186 days (since Tue Jun 5 03:59:54 2018)
  303. Network Distance: 1 hop
  304. TCP Sequence Prediction: Difficulty=248 (Good luck!)
  305. IP ID Sequence Generation: All zeros
  306.  
  307. TRACEROUTE
  308. HOP RTT ADDRESS
  309. 1 0.37 ms 1.1.0.206
  310.  
  311. Nmap scan report for 1.1.0.207
  312. Host is up (0.00038s latency).
  313. Not shown: 997 closed ports
  314. PORT STATE SERVICE VERSION
  315. 22/tcp open ssh (protocol 2.0)
  316. |_ssh-hostkey:
  317. 53/tcp open domain
  318. 80/tcp open http?
  319. |_http-generator: ERROR: Script execution failed (use -d to debug)
  320. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  321. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=80:2a:a8:89:59:40&t=1529162758&url=http://1.1.0.207%2f
  322. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  323. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B44%P=arm-unknown-linux-gnueabih
  324. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\xb3\x94\xb8\xa6
  325. SF:>Z\xcd\xcc\xfc\x83l!7\x8e\xf0\xa4\0\0\0mcurve25519-sha256@libssh\.org,d
  326. SF:iffie-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.u
  327. SF:cc\.asn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0
  328. SF:\0\x15aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-s
  329. SF:ha1,hmac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\x1cY
  330. SF:\xe4\x89\xd5\xec\t\x14u\xb4\[");
  331. MAC Address: 80:2A:A8:89:59:40 (Unknown)
  332. Device type: general purpose
  333. Running: Linux 2.6.X|3.X
  334. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  335. OS details: Linux 2.6.32 - 3.10
  336. Uptime guess: 3.125 days (since Wed Jun 13 05:27:41 2018)
  337. Network Distance: 1 hop
  338. TCP Sequence Prediction: Difficulty=252 (Good luck!)
  339. IP ID Sequence Generation: All zeros
  340.  
  341. TRACEROUTE
  342. HOP RTT ADDRESS
  343. 1 0.38 ms 1.1.0.207
  344.  
  345. Nmap scan report for 1.1.0.210
  346. Host is up (0.00036s latency).
  347. Not shown: 997 closed ports
  348. PORT STATE SERVICE VERSION
  349. 22/tcp open ssh (protocol 2.0)
  350. |_ssh-hostkey:
  351. 53/tcp open domain
  352. 80/tcp open http?
  353. |_http-generator: ERROR: Script execution failed (use -d to debug)
  354. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  355. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:a3:96:98&t=1529162760&url=http://1.1.0.210%2f
  356. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  357. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B48%P=arm-unknown-linux-gnueabih
  358. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\xec\x9aI0\xe7cP
  359. SF:\xf5\xc0\x1e\x0e\x03\*\^5\xc2\0\0\0mcurve25519-sha256@libssh\.org,diffi
  360. SF:e-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.ucc\.
  361. SF:asn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x
  362. SF:15aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sha1,
  363. SF:hmac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\x8f\xe1\
  364. SF:xec~\xbfH<\?\n\xa0\x19");
  365. MAC Address: F0:9F:C2:A3:96:98 (Unknown)
  366. Device type: general purpose
  367. Running: Linux 2.6.X|3.X
  368. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  369. OS details: Linux 2.6.32 - 3.10
  370. Uptime guess: 11.186 days (since Tue Jun 5 03:59:53 2018)
  371. Network Distance: 1 hop
  372. TCP Sequence Prediction: Difficulty=254 (Good luck!)
  373. IP ID Sequence Generation: All zeros
  374.  
  375. TRACEROUTE
  376. HOP RTT ADDRESS
  377. 1 0.36 ms 1.1.0.210
  378.  
  379. Nmap scan report for 1.1.0.211
  380. Host is up (0.00034s latency).
  381. Not shown: 997 closed ports
  382. PORT STATE SERVICE VERSION
  383. 22/tcp open ssh (protocol 2.0)
  384. |_ssh-hostkey:
  385. 53/tcp open domain
  386. 80/tcp open http?
  387. |_http-generator: ERROR: Script execution failed (use -d to debug)
  388. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  389. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:a3:81:36&t=1529162757&url=http://1.1.0.211%2f
  390. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  391. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B4A%P=arm-unknown-linux-gnueabih
  392. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\xa0W\xcc\xe2\+e
  393. SF:bS\xc6\xab\xf4\]\xa1\xd2\xcf\xab\0\0\0mcurve25519-sha256@libssh\.org,di
  394. SF:ffie-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.uc
  395. SF:c\.asn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\
  396. SF:0\x15aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sh
  397. SF:a1,hmac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0wl{O\x
  398. SF:ca\xce\x8e\x98\xa6\xa0%");
  399. MAC Address: F0:9F:C2:A3:81:36 (Unknown)
  400. Device type: general purpose
  401. Running: Linux 2.6.X|3.X
  402. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  403. OS details: Linux 2.6.32 - 3.10
  404. Uptime guess: 11.186 days (since Tue Jun 5 03:59:55 2018)
  405. Network Distance: 1 hop
  406. TCP Sequence Prediction: Difficulty=252 (Good luck!)
  407. IP ID Sequence Generation: All zeros
  408.  
  409. TRACEROUTE
  410. HOP RTT ADDRESS
  411. 1 0.34 ms 1.1.0.211
  412.  
  413. Nmap scan report for 1.1.0.212
  414. Host is up (0.00040s latency).
  415. Not shown: 997 closed ports
  416. PORT STATE SERVICE VERSION
  417. 22/tcp open ssh (protocol 2.0)
  418. |_ssh-hostkey:
  419. 53/tcp open domain
  420. 80/tcp open http?
  421. |_http-generator: ERROR: Script execution failed (use -d to debug)
  422. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  423. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:a3:96:e8&t=1529162758&url=http://1.1.0.212%2f
  424. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  425. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B4E%P=arm-unknown-linux-gnueabih
  426. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\xa1\xc9\x87=6%\
  427. SF:x07Ezy\x80U\[\"\xc9\x89\0\0\0mcurve25519-sha256@libssh\.org,diffie-hell
  428. SF:man-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.ucc\.asn\.a
  429. SF:u\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x15aes1
  430. SF:28-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sha1,hmac-m
  431. SF:d5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0C\x12\xcb\x18\x
  432. SF:b6\xbf\]Z\xd9\xa8\x0e");
  433. MAC Address: F0:9F:C2:A3:96:E8 (Unknown)
  434. Device type: general purpose
  435. Running: Linux 2.6.X|3.X
  436. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  437. OS details: Linux 2.6.32 - 3.10
  438. Uptime guess: 11.186 days (since Tue Jun 5 03:59:56 2018)
  439. Network Distance: 1 hop
  440. TCP Sequence Prediction: Difficulty=262 (Good luck!)
  441. IP ID Sequence Generation: All zeros
  442.  
  443. TRACEROUTE
  444. HOP RTT ADDRESS
  445. 1 0.40 ms 1.1.0.212
  446.  
  447. Nmap scan report for 1.1.0.215
  448. Host is up (0.020s latency).
  449. Not shown: 549 filtered ports, 450 closed ports
  450. PORT STATE SERVICE VERSION
  451. 5357/tcp open wsdapi?
  452. MAC Address: B8:81:98:13:C5:7C (Unknown)
  453. OS fingerprint not ideal because: maxTimingRatio (1.818000e+00) is greater than 1.4
  454. No OS matches for host
  455. Network Distance: 1 hop
  456.  
  457. TRACEROUTE
  458. HOP RTT ADDRESS
  459. 1 20.49 ms 1.1.0.215
  460.  
  461. Nmap scan report for 1.1.0.241
  462. Host is up (0.0019s latency).
  463. Not shown: 998 filtered ports
  464. PORT STATE SERVICE VERSION
  465. 80/tcp open http ViewSonic PJD6521 projector http config
  466. | http-auth:
  467. | HTTP/1.1 401 Unauthorized
  468. |_ Basic realm=Protected
  469. |_http-methods: No Allow or Public header in OPTIONS response (status code 501)
  470. |_http-title: Site doesn't have a title.
  471. 8000/tcp open http-alt?
  472. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  473. SF-Port8000-TCP:V=6.47%I=7%D=6/16%Time=5B252B51%P=arm-unknown-linux-gnueab
  474. SF:ihf%r(NULL,A4,"\x02\xaaV\0W\0\x1b\0\x12\x06\x10\x13\x17\r\0\x19\x001\x0
  475. SF:2\x04\x0eh\0\0\0Z\0\x00251226\xad\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x0
  476. SF:5\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\
  477. SF:n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03\x02\xaaV\0\0\0\x1b\0\x12\
  478. SF:x06\x10\x13\x17\x0f\0\x19\x001\x02\0\x0eh\0\0\0Z\0\x00251226\xfc\x03\x0
  479. SF:2\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x0
  480. SF:3\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd
  481. SF:7\x03")%r(GenericLines,F6,"\x02\xaaV\0W\0\x1b\0\x12\x06\x10\x13\x17\r\0
  482. SF:\x19\x001\x02\x04\x0eh\0\0\0Z\0\x00251226\xad\x03\x02\xaaS\0\x01\0\x0e\
  483. SF:0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03\x02\xaaS\0\x01\0\
  484. SF:x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03\x02\xaaV\0\0\
  485. SF:0\x1b\0\x12\x06\x10\x13\x17\x0f\0\x19\x001\x02\0\x0eh\0\0\0Z\0\x0025122
  486. SF:6\xfc\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x0
  487. SF:1\x01\xd7\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x0
  488. SF:1\x01\x01\xd7\x03\x02\xaaV\0\0\0\x1b\0\x12\x06\x10\x13\x17\x14\0\x19\x0
  489. SF:01\x02\0\x0eh\0\0\0Z\0\x00251226\xe7\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n
  490. SF:\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03\x02\xaaS\0\x01\0\x0e\0@h\x
  491. SF:01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03")%r(GetRequest,52,"\x0
  492. SF:2\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x0
  493. SF:3\x02\xaaV\0\0\0\x1b\0\x12\x06\x10\x13\x17\x19\0\x19\x001\x02\0\x0eh\0\
  494. SF:0\0Z\0\x00251226\xea\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05
  495. SF:\x12\x01\x01\x01\x01\xd7\x03")%r(X11Probe,8D,"\x02\xaaV\0\0\0\x1b\0\x12
  496. SF:\x06\x10\x13\x17\x1c\0\x19\x001\x02\0\x0eh\0\0\0Z\0\x00251226\xef\x03\x
  497. SF:02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x
  498. SF:03\x02\xaaV\0\0\0\x1b\0\x12\x06\x10\x13\x17\x1e\0\x19\x001\x02\0\x0eh\0
  499. SF:\0\0Z\0\x00251226\xed\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x0
  500. SF:5\x12\x01\x01\x01\x01\xd7\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x1
  501. SF:9\x05\x12\x01\x01\x01\x01\xd7\x03")%r(FourOhFourRequest,52,"\x02\xaaS\0
  502. SF:\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x01\x01\x01\xd7\x03\x02\xa
  503. SF:aV\0\0\0\x1b\0\x12\x06\x10\x13\x17#\0\x19\x001\x02\0\x0eh\0\0\0Z\0\x002
  504. SF:51226\xd0\x03\x02\xaaS\0\x01\0\x0e\0@h\x01\n\x05\x0b\x19\x05\x12\x01\x0
  505. SF:1\x01\x01\xd7\x03");
  506. MAC Address: 00:04:A3:F7:00:F1 (Microchip Technology)
  507. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  508. Device type: printer
  509. Running (JUST GUESSING): Ricoh embedded (85%)
  510. OS CPE: cpe:/h:ricoh:aficio_sp_c210sf
  511. Aggressive OS guesses: Ricoh Aficio SP C210SF printer (85%)
  512. No exact OS matches for host (test conditions non-ideal).
  513. Network Distance: 1 hop
  514. TCP Sequence Prediction: Difficulty=255 (Good luck!)
  515. IP ID Sequence Generation: Incremental
  516. Service Info: Device: media device; CPE: cpe:/h:viewsonic:pjd6521
  517.  
  518. TRACEROUTE
  519. HOP RTT ADDRESS
  520. 1 1.87 ms 1.1.0.241
  521.  
  522. Nmap scan report for 1.1.0.244
  523. Host is up (0.00038s latency).
  524. Not shown: 997 closed ports
  525. PORT STATE SERVICE VERSION
  526. 22/tcp open ssh (protocol 2.0)
  527. |_ssh-hostkey:
  528. 53/tcp open domain
  529. 80/tcp open http?
  530. |_http-generator: ERROR: Script execution failed (use -d to debug)
  531. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  532. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:73:d3:ff&t=1529162759&url=http://1.1.0.244%2f
  533. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  534. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B53%P=arm-unknown-linux-gnueabih
  535. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\xaa\x11\x9c\xb1
  536. SF:\$\x02X\x96R\xb2\x14\x1bb\xec\x96\xc1\0\0\0mcurve25519-sha256@libssh\.o
  537. SF:rg,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@mat
  538. SF:t\.ucc\.asn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr
  539. SF:\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hm
  540. SF:ac-sha1,hmac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0v
  541. SF:>\x99\x0f\x9f\x85\x95\x0f\xa2\xce\r");
  542. MAC Address: F0:9F:C2:73:D3:FF (Unknown)
  543. Device type: general purpose
  544. Running: Linux 2.6.X|3.X
  545. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  546. OS details: Linux 2.6.32 - 3.10
  547. Uptime guess: 69.688 days (since Sat Apr 7 15:56:35 2018)
  548. Network Distance: 1 hop
  549. TCP Sequence Prediction: Difficulty=260 (Good luck!)
  550. IP ID Sequence Generation: All zeros
  551.  
  552. TRACEROUTE
  553. HOP RTT ADDRESS
  554. 1 0.38 ms 1.1.0.244
  555.  
  556. Nmap scan report for 1.1.0.248
  557. Host is up (0.00039s latency).
  558. Not shown: 997 closed ports
  559. PORT STATE SERVICE VERSION
  560. 22/tcp open ssh (protocol 2.0)
  561. |_ssh-hostkey:
  562. 53/tcp open domain
  563. 80/tcp open http?
  564. |_http-generator: ERROR: Script execution failed (use -d to debug)
  565. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  566. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=80:2a:a8:46:d0:58&t=1529162768&url=http://1.1.0.248%2f
  567. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  568. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B56%P=arm-unknown-linux-gnueabih
  569. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\^\x11\x84\xea\x
  570. SF:87\x8c\x8c\xe7<5\xe1\xc7\xa2\xa3c\x80\0\0\0mcurve25519-sha256@libssh\.o
  571. SF:rg,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@mat
  572. SF:t\.ucc\.asn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr
  573. SF:\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hm
  574. SF:ac-sha1,hmac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\
  575. SF:x92U\xdemTH#\xba\xee\xd6\xa6");
  576. MAC Address: 80:2A:A8:46:D0:58 (Unknown)
  577. Device type: general purpose
  578. Running: Linux 2.6.X|3.X
  579. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  580. OS details: Linux 2.6.32 - 3.10
  581. Uptime guess: 3.125 days (since Wed Jun 13 05:27:40 2018)
  582. Network Distance: 1 hop
  583. TCP Sequence Prediction: Difficulty=254 (Good luck!)
  584. IP ID Sequence Generation: All zeros
  585.  
  586. TRACEROUTE
  587. HOP RTT ADDRESS
  588. 1 0.39 ms 1.1.0.248
  589.  
  590. Nmap scan report for 1.1.0.250
  591. Host is up (0.00042s latency).
  592. Not shown: 997 closed ports
  593. PORT STATE SERVICE VERSION
  594. 22/tcp open ssh (protocol 2.0)
  595. |_ssh-hostkey:
  596. 53/tcp open domain
  597. 80/tcp open http?
  598. |_http-generator: ERROR: Script execution failed (use -d to debug)
  599. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  600. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=80:2a:a8:c0:83:1b&t=1529162769&url=http://1.1.0.250%2f
  601. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  602. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B59%P=arm-unknown-linux-gnueabih
  603. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14-\x84t\x18to\x8b
  604. SF:U9\xec\x17N\.\xa9\\l\0\0\0mcurve25519-sha256@libssh\.org,diffie-hellman
  605. SF:-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.ucc\.asn\.au\0
  606. SF:\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x15aes128-
  607. SF:ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sha1,hmac-md5\
  608. SF:0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\xde\xb4\xb6\xfcS\
  609. SF:xaf\x11\xdep3\xf0");
  610. MAC Address: 80:2A:A8:C0:83:1B (Unknown)
  611. Device type: general purpose
  612. Running: Linux 2.6.X|3.X
  613. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  614. OS details: Linux 2.6.32 - 3.10
  615. Uptime guess: 50.846 days (since Thu Apr 26 12:09:56 2018)
  616. Network Distance: 1 hop
  617. TCP Sequence Prediction: Difficulty=250 (Good luck!)
  618. IP ID Sequence Generation: All zeros
  619.  
  620. TRACEROUTE
  621. HOP RTT ADDRESS
  622. 1 0.41 ms 1.1.0.250
  623.  
  624. Nmap scan report for 1.1.0.251
  625. Host is up (0.00041s latency).
  626. Not shown: 997 closed ports
  627. PORT STATE SERVICE VERSION
  628. 22/tcp open ssh (protocol 2.0)
  629. |_ssh-hostkey:
  630. 53/tcp open domain
  631. 80/tcp open http?
  632. |_http-generator: ERROR: Script execution failed (use -d to debug)
  633. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  634. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:73:d4:99&t=1529162780&url=http://1.1.0.251%2f
  635. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  636. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B5C%P=arm-unknown-linux-gnueabih
  637. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\x91O\x14\xe1Z\x
  638. SF:f3\x9a\x12k\x19\x9a\xff\xa2\xdf\|\x83\0\0\0mcurve25519-sha256@libssh\.o
  639. SF:rg,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@mat
  640. SF:t\.ucc\.asn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr
  641. SF:\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hm
  642. SF:ac-sha1,hmac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\
  643. SF:x07\xffB\xc4\x16\x9f\xa2\x0b%\xd8\xc7");
  644. MAC Address: F0:9F:C2:73:D4:99 (Unknown)
  645. Device type: general purpose
  646. Running: Linux 2.6.X|3.X
  647. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  648. OS details: Linux 2.6.32 - 3.10
  649. Uptime guess: 3.125 days (since Wed Jun 13 05:27:40 2018)
  650. Network Distance: 1 hop
  651. TCP Sequence Prediction: Difficulty=251 (Good luck!)
  652. IP ID Sequence Generation: All zeros
  653.  
  654. TRACEROUTE
  655. HOP RTT ADDRESS
  656. 1 0.41 ms 1.1.0.251
  657.  
  658. Nmap scan report for 1.1.0.253
  659. Host is up (0.00041s latency).
  660. Not shown: 997 closed ports
  661. PORT STATE SERVICE VERSION
  662. 22/tcp open ssh (protocol 2.0)
  663. |_ssh-hostkey:
  664. 53/tcp open domain
  665. 80/tcp open http?
  666. |_http-generator: ERROR: Script execution failed (use -d to debug)
  667. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  668. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=80:2a:a8:c6:e6:cd&t=1529162759&url=http://1.1.0.253%2f
  669. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  670. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B5F%P=arm-unknown-linux-gnueabih
  671. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14\x9c\x0cG\|O\x99
  672. SF:UZc\xf6\xb2\x03L\xfcq\x0f\0\0\0mcurve25519-sha256@libssh\.org,diffie-he
  673. SF:llman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.ucc\.asn\
  674. SF:.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x15ae
  675. SF:s128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sha1,hmac
  676. SF:-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0l\x8f\x14\xa1
  677. SF:\xc4\xbc\xaf\xdf\xbd\xf4\xfb");
  678. MAC Address: 80:2A:A8:C6:E6:CD (Unknown)
  679. Device type: general purpose
  680. Running: Linux 2.6.X|3.X
  681. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  682. OS details: Linux 2.6.32 - 3.10
  683. Uptime guess: 3.125 days (since Wed Jun 13 05:27:40 2018)
  684. Network Distance: 1 hop
  685. TCP Sequence Prediction: Difficulty=253 (Good luck!)
  686. IP ID Sequence Generation: All zeros
  687.  
  688. TRACEROUTE
  689. HOP RTT ADDRESS
  690. 1 0.41 ms 1.1.0.253
  691.  
  692. Nmap scan report for 1.1.0.254
  693. Host is up (0.00044s latency).
  694. Not shown: 997 closed ports
  695. PORT STATE SERVICE VERSION
  696. 22/tcp open ssh (protocol 2.0)
  697. |_ssh-hostkey:
  698. 53/tcp open domain
  699. 80/tcp open http?
  700. |_http-generator: ERROR: Script execution failed (use -d to debug)
  701. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  702. |_http-title: Did not follow redirect to http://1.1.0.180:8880/guest/s/default/?id=78:8a:20:46:6b:c5&ap=f0:9f:c2:73:d5:40&t=1529162770&url=http://1.1.0.254%2f
  703. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  704. SF-Port22-TCP:V=6.47%I=7%D=6/16%Time=5B252B62%P=arm-unknown-linux-gnueabih
  705. SF:f%r(NULL,132,"SSH-2\.0-dropbear\r\n\0\0\x01\x1c\x0b\x14i\xe2d_\xb65#\xb
  706. SF:f\xdf\xb0\r\x97\x92~\xed\xa8\0\0\0mcurve25519-sha256@libssh\.org,diffie
  707. SF:-hellman-group14-sha1,diffie-hellman-group1-sha1,kexguess2@matt\.ucc\.a
  708. SF:sn\.au\0\0\0\x0fssh-rsa,ssh-dss\0\0\0\x15aes128-ctr,aes256-ctr\0\0\0\x1
  709. SF:5aes128-ctr,aes256-ctr\0\0\0\x12hmac-sha1,hmac-md5\0\0\0\x12hmac-sha1,h
  710. SF:mac-md5\0\0\0\x04none\0\0\0\x04none\0\0\0\0\0\0\0\0\0\0\0\0\0\xb0\xf2\0
  711. SF:P~;\xcf\x17\xc3\xad\x86");
  712. MAC Address: F0:9F:C2:73:D5:40 (Unknown)
  713. Device type: general purpose
  714. Running: Linux 2.6.X|3.X
  715. OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3
  716. OS details: Linux 2.6.32 - 3.10
  717. Uptime guess: 3.125 days (since Wed Jun 13 05:27:40 2018)
  718. Network Distance: 1 hop
  719. TCP Sequence Prediction: Difficulty=251 (Good luck!)
  720. IP ID Sequence Generation: All zeros
  721.  
  722. TRACEROUTE
  723. HOP RTT ADDRESS
  724. 1 0.44 ms 1.1.0.254
  725.  
  726. Initiating SYN Stealth Scan at 08:27
  727. Scanning 1.1.0.180 [1000 ports]
  728. Discovered open port 443/tcp on 1.1.0.180
  729. Discovered open port 22/tcp on 1.1.0.180
  730. Discovered open port 80/tcp on 1.1.0.180
  731. Discovered open port 8080/tcp on 1.1.0.180
  732. Discovered open port 6789/tcp on 1.1.0.180
  733. Discovered open port 8443/tcp on 1.1.0.180
  734. Completed SYN Stealth Scan at 08:27, 9.35s elapsed (1000 total ports)
  735. Initiating Service scan at 08:27
  736. Scanning 6 services on 1.1.0.180
  737. Completed Service scan at 08:29, 131.14s elapsed (6 services on 1 host)
  738. Initiating OS detection (try #1) against 1.1.0.180
  739. NSE: Script scanning 1.1.0.180.
  740. Initiating NSE at 08:30
  741. Completed NSE at 08:30, 30.16s elapsed
  742. Nmap scan report for 1.1.0.180
  743. Host is up (0.00014s latency).
  744. Not shown: 994 closed ports
  745. PORT STATE SERVICE VERSION
  746. 22/tcp open ssh OpenSSH 6.7p1 Debian 5+deb8u4 (protocol 2.0)
  747. |_ssh-hostkey: ERROR: Script execution failed (use -d to debug)
  748. 80/tcp open http nginx
  749. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  750. |_http-title: Did not follow redirect to https://1.1.0.180/
  751. 443/tcp open http nginx
  752. |_http-methods: No Allow or Public header in OPTIONS response (status code 400)
  753. |_http-title: 400 The plain HTTP request was sent to HTTPS port
  754. | ssl-cert: Subject: stateOrProvinceName=CA/countryName=US
  755. | Issuer: stateOrProvinceName=CA/countryName=US
  756. | Public Key type: rsa
  757. | Public Key bits: 2048
  758. | Not valid before: 2018-06-05T11:11:51+00:00
  759. | Not valid after: 2028-06-05T11:11:51+00:00
  760. | MD5: bc3a 7d0d c4fd 3137 ddab 0d8d 95b6 3796
  761. |_SHA-1: 185b e657 763e ee8a c1da 207d fd79 0737 5729 faa6
  762. |_ssl-date: ERROR: Script execution failed (use -d to debug)
  763. | tls-nextprotoneg:
  764. |_ http/1.1
  765. 6789/tcp open ibm-db2-admin?
  766. 8080/tcp open tcpwrapped
  767. |_http-generator: ERROR: Script execution failed (use -d to debug)
  768. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  769. |_http-open-proxy: Proxy might be redirecting requests
  770. |_http-title: Did not follow redirect to https://1.1.0.180:8443/manage
  771. 8443/tcp open https-alt?
  772. | ssl-cert: Subject: stateOrProvinceName=CA/countryName=US
  773. | Issuer: stateOrProvinceName=CA/countryName=US
  774. | Public Key type: rsa
  775. | Public Key bits: 2048
  776. | Not valid before: 2018-06-05T11:11:51+00:00
  777. | Not valid after: 2028-06-05T11:11:51+00:00
  778. | MD5: bc3a 7d0d c4fd 3137 ddab 0d8d 95b6 3796
  779. |_SHA-1: 185b e657 763e ee8a c1da 207d fd79 0737 5729 faa6
  780. 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
  781. SF-Port8443-TCP:V=6.47%I=7%D=6/16%Time=5B252C76%P=arm-unknown-linux-gnueab
  782. SF:ihf%r(NULL,7,"\x15\x03\x03\0\x02\x02\n")%r(GetRequest,7,"\x15\x03\x03\0
  783. SF:\x02\x02\n")%r(HTTPOptions,7,"\x15\x03\x03\0\x02\x02\n")%r(RTSPRequest,
  784. SF:7,"\x15\x03\x03\0\x02\x02\n")%r(RPCCheck,7,"\x15\x03\x03\0\x02\x02\n")%
  785. SF:r(DNSVersionBindReq,7,"\x15\x03\x03\0\x02\x02\n")%r(DNSStatusRequest,7,
  786. SF:"\x15\x03\x03\0\x02\x02\n")%r(Help,7,"\x15\x03\x03\0\x02\x02\n")%r(SSLS
  787. SF:essionReq,7,"\x15\x03\x03\0\x02\x02\(")%r(Kerberos,7,"\x15\x03\x03\0\x0
  788. SF:2\x02\n")%r(SMBProgNeg,7,"\x15\x03\x03\0\x02\x02\n")%r(X11Probe,7,"\x15
  789. SF:\x03\x03\0\x02\x02\n")%r(FourOhFourRequest,7,"\x15\x03\x03\0\x02\x02\n"
  790. SF:)%r(LPDString,7,"\x15\x03\x03\0\x02\x02\n")%r(LDAPBindReq,7,"\x15\x03\x
  791. SF:03\0\x02\x02\n")%r(SIPOptions,7,"\x15\x03\x03\0\x02\x02\n")%r(LANDesk-R
  792. SF:C,7,"\x15\x03\x03\0\x02\x02\n")%r(TerminalServer,7,"\x15\x03\x03\0\x02\
  793. SF:x02\n")%r(NCP,7,"\x15\x03\x03\0\x02\x02\n")%r(NotesRPC,7,"\x15\x03\x03\
  794. SF:0\x02\x02\n")%r(WMSRequest,7,"\x15\x03\x03\0\x02\x02\n")%r(oracle-tns,7
  795. SF:,"\x15\x03\x03\0\x02\x02\n")%r(afp,7,"\x15\x03\x03\0\x02\x02\n")%r(kumo
  796. SF:-server,7,"\x15\x03\x03\0\x02\x02\n");
  797. Device type: general purpose
  798. Running: Linux 3.X
  799. OS CPE: cpe:/o:linux:linux_kernel:3
  800. OS details: Linux 3.7 - 3.15
  801. Uptime guess: 11.135 days (since Tue Jun 5 05:16:38 2018)
  802. Network Distance: 0 hops
  803. TCP Sequence Prediction: Difficulty=255 (Good luck!)
  804. IP ID Sequence Generation: All zeros
  805. Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement