Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- UNITED NATIONS (UN) - Careers Web Server Data/Variable Disclos
- (TSL-SSL Keys/AdminFolders/Server Variables)
- The United Nations (UN) is an international organization whose stated aims are facilitating cooperation in international law, international security, economic development, social progress, human rights, and achievement of world peace. The UN was founded in 1945 after World War II to replace the League of Nations, to stop wars between countries, and to provide a platform for dialogue. It contains multiple subsidiary organizations to carry out its missions.
- http://www.un.org
- THIS ATTACK AGAINST THE DIRTIEST THINGS AGAINST THE SRI LANKA BY UN .........!!!!!
- EXCLUSIVE FROM - Anonymous Sri Lanka
- WWW.UN.ORG -----> Fuck3D and Bust3D
- Primary careers.un.org (157.150.34.31) Server Hacked and
- with Transferring (Data Leak)....!!
- Hail to Anonymous, Lulzsec and Operation Anti-Sec...
- 21/tcp filtered ftp no-response
- 22/tcp filtered ssh no-response
- 23/tcp filtered telnet no-response
- 25/tcp filtered smtp no-response
- 80/tcp open http? syn-ack
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | http-malware-host:
- |_ ERROR: Unknown pages return a 302 response; unable to check
- |_http-methods: No Allow or Public header in OPTIONS response (status code 307)
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- | http-title: Site doesn't have a title (text/html).
- |_Did not follow redirect to https://careers.un.org/
- | http-headers:
- | Content-Type: text/html
- | Content-Length: 88
- | Location: https://careers.un.org/
- | Cache-Control: private
- |
- |_ (Request type: GET)
- |_http-userdir-enum: Didn't find any users!
- |_http-wordpress-plugins: nothing found amongst the 100 most popular plugins, use --script-arg http-wordpress-plugins.search=<number|all> for deeper analysis)
- | http-vhosts:
- |_405 names had status 302
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 110/tcp filtered pop3 no-response
- 139/tcp filtered netbios-ssn no-response
- 443/tcp open ssl/http syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- |_http-date: Wed, 29 Feb 2012 08:51:18 GMT; +4s from local time.
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- | ssl-cert: Subject: commonName=*.un.org/organizationName=United Nations/stateOrProvinceName=New York/countryName=US/streetAddress=24-01 44th Road, 9th Floor/localityName=Long Island City/postalCode=11101-4605/organizationalUnitName=Comodo PremiumSSL Wildcard
- | Issuer: commonName=UTN-USERFirst-Hardware/organizationName=The USERTRUST Network/stateOrProvinceName=UT/countryName=US/localityName=Salt Lake City/organizationalUnitName=http://www.usertrust.com
- | Public Key type: rsa
- | Public Key bits: 2048
- | Not valid before: 2011-02-02 00:00:00
- | Not valid after: 2013-04-13 23:59:59
- | MD5: 7920 a56a 7a80 873f 2303 98fd 5711 4c72
- | SHA-1: 3829 64d1 30e8 d182 52e7 65b8 5c41 5de1 0470 a249
- | -----BEGIN CERTIFICATE-----
- | MIIGBzCCBO+gAwIBAgIQGSM5lIzygwVgvQZH7nphlDANBgkqhkiG9w0BAQUFADCB
- | lzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
- | Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExho
- | dHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xHzAdBgNVBAMTFlVUTi1VU0VSRmlyc3Qt
- | SGFyZHdhcmUwHhcNMTEwMjAyMDAwMDAwWhcNMTMwNDEzMjM1OTU5WjCCAQsxCzAJ
- | BgNVBAYTAlVTMRMwEQYDVQQREwoxMTEwMS00NjA1MREwDwYDVQQIEwhOZXcgWW9y
- | azEZMBcGA1UEBxMQTG9uZyBJc2xhbmQgQ2l0eTEjMCEGA1UECRMaMjQtMDEgNDR0
- | aCBSb2FkLCA5dGggRmxvb3IxFzAVBgNVBAoTDlVuaXRlZCBOYXRpb25zMQ0wCwYD
- | VQQLEwRPSUNUMTQwMgYDVQQLEytJc3N1ZWQgdGhyb3VnaCBVbml0ZWQgTmF0aW9u
- | cyBFLVBLSSBNYW5hZ2VyMSMwIQYDVQQLExpDb21vZG8gUHJlbWl1bVNTTCBXaWxk
- | Y2FyZDERMA8GA1UEAxQIKi51bi5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
- | ggEKAoIBAQCs1eE0bZ1LBeAYBybTC5K4D7p7jpOvfMqH8uWU5XUz5mD2t8ZuZ/gk
- | AL3Te23ev32e8bKPkSYym9VgLNZ5CQbh+DG4y6lQNY0kaokMRSYGMhQG8mdUEkcg
- | u4lvd3V1VZ6HeppcO7ufgn3RbpTSLcgKRlm9UABQmYxZ0nmwW6z9IeGgKPoHn+18
- | G8HgFuMx4N0+vAbPvuhrurzb3OfWFsj2qE0R3PHtbZ/4lUCB54SG7LtNfsDeqzhp
- | rlHoD6OB25V1/t5Mt4K38PRa1i52G6J+KcuexxslfS3Kv67eNFik6t3lR3MPDSGw
- | Vtw1ATyTNW5aHrkq84AbZAKzMi9O7HzxAgMBAAGjggHWMIIB0jAfBgNVHSMEGDAW
- | gBShcl8mGyiYQ5VdBzfVhZadS9LDRTAdBgNVHQ4EFgQUHdeek2FzeALWh9EDbE8s
- | xfGb4uQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYI
- | KwYBBQUHAwEGCCsGAQUFBwMCMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQMEMCsw
- | KQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNvbW9kby5jb20vQ1BTMHsGA1Ud
- | HwR0MHIwOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmly
- | c3QtSGFyZHdhcmUuY3JsMDagNKAyhjBodHRwOi8vY3JsLmNvbW9kby5uZXQvVVRO
- | LVVTRVJGaXJzdC1IYXJkd2FyZS5jcmwwcQYIKwYBBQUHAQEEZTBjMDsGCCsGAQUF
- | BzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNvbS9VVE5BZGRUcnVzdFNlcnZlckNB
- | LmNydDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2EuY29tMBsGA1Ud
- | EQQUMBKCCCoudW4ub3JnggZ1bi5vcmcwDQYJKoZIhvcNAQEFBQADggEBAG9ajQJE
- | fC4XCmsdUD0HQ+5PNO1YtusPQD9I7zOgf6c25TMeu7PCblYH7nZq5NiiglchRX6a
- | VowALfIqjXyEWTDlq94y7JKtv/B62GU1dX7lvNoPS80/e1MzZCzkGa1hHZjiQL7r
- | kFoSmHeRr8A+fIjJZ85o7x2Y6qZJcjQTtASRAMV4kZEqST+cnRF3Pz8WnGKlFwFn
- | aUXH/t/MDgQbpa0+tKIg8dAP3Tb43r4051Rius6zOhS5PYOmo4MsBiKOVXHZnT15
- | vHiNtnSrtsKkxE3xGI7d9x5CC/BLnp8edK5cneCK39+MZFmJmvMFxXwiaIDCiWGx
- | vhwke7E0HzImDls=
- |_-----END CERTIFICATE-----
- | http-headers:
- | Cache-Control: no-cache
- | Content-Length: 448
- | Content-Type: text/html
- | Last-Modified: Thu, 30 Dec 2010 14:01:13 GMT
- | Accept-Ranges: bytes
- | ETag: "ac451e52aa8cb1:0"
- | X-Powered-By: ASP.NET
- | Date: Wed, 29 Feb 2012 08:51:23 GMT
- | Set-Cookie: NSC_q_m_nzdbsffst.vo.psh_ttm_mc_wjq=ffffffff9e9eb5e245525d5f4f58455e445a4a423660;expires=Wed, 29-Feb-2012 08:53:24 GMT;path=/;secure;httponly
- |
- |_ (Request type: HEAD)
- |_http-malware-host: Host appears to be clean
- |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
- |_http-title: UN Careers
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- | http-methods: OPTIONS TRACE GET HEAD POST
- | Potentially risky methods: TRACE
- | http-php-version: Logo query returned unknown hash aa30c8e81047a294cb857ba77f7dbac0
- |_Credits query returned unknown hash aa30c8e81047a294cb857ba77f7dbac0
- |_http-userdir-enum: Didn't find any users!
- | http-vuln-cve2011-3192:
- | VULNERABLE:
- | Apache byterange filter DoS
- | State: VULNERABLE
- | IDs: CVE:CVE-2011-3192 OSVDB:74721
- | Description:
- | The Apache web server is vulnerable to a denial of service attack when numerous
- | overlapping byte ranges are requested.
- | Disclosure date: 2011-08-19
- | References:
- | http://seclists.org/fulldisclosure/2011/Aug/175
- | http://nessus.org/plugins/index.php?view=single&id=55976
- | http://osvdb.org/74721
- |_ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192
- |_http-wordpress-plugins: nothing found amongst the 100 most popular plugins, use --script-arg http-wordpress-plugins.search=<number|all> for deeper analysis)
- | http-email-harvest:
- | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=careers.un.org
- |_ thangpdtt@gmail.com
- | http-unsafe-output-escaping:
- | Characters ['] reflected in parameter viewtype at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=205
- | Characters ['] reflected in parameter PID at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=205
- | Characters ['] reflected in parameter viewtype at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=188
- | Characters ['] reflected in parameter PID at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=188
- | Characters ['] reflected in parameter viewtype at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=181
- | Characters ['] reflected in parameter PID at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=181
- | Characters ['] reflected in parameter viewtype at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=136
- | Characters ['] reflected in parameter PID at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=136
- | Characters ['] reflected in parameter viewtype at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=201
- | Characters ['] reflected in parameter PID at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=201
- | Characters ['] reflected in parameter viewtype at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=165
- |_ Characters ['] reflected in parameter PID at https://careers.un.org/lbw/home.aspx?viewtype=VP&PID=165
- | ssl-enum-ciphers:
- | SSLv3
- | Ciphers (3)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- | TLSv1.0
- | Ciphers (5)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - unknown strength
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- |_ Least strength = unknown strength
- | http-enum:
- | /login.aspx: Possible admin folder
- | /home.aspx: Possible admin folder
- | /rss.aspx: RSS or Atom feed
- |_ /login/: Login page
- | http-vhosts:
- |_405 names had status 200
- | ssl-google-cert-catalog:
- |_ No DB entry
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 445/tcp filtered microsoft-ds no-response
- 3389/tcp filtered ms-term-serv no-response
- Host script results:
- | dns-blacklist:
- | PROXY
- | dnsbl.ahbl.org - FAIL
- | socks.dnsbl.sorbs.net - FAIL
- | http.dnsbl.sorbs.net - FAIL
- | misc.dnsbl.sorbs.net - FAIL
- | dnsbl.tornevall.org - FAIL
- | SPAM
- | dnsbl.ahbl.org - FAIL
- | dnsbl.inps.de - FAIL
- | bl.nszones.com - FAIL
- | l2.apews.org - FAIL
- | list.quorum.to - FAIL
- | all.spamrats.com - FAIL
- | bl.spamcop.net - FAIL
- | spam.dnsbl.sorbs.net - FAIL
- |_ sbl.spamhaus.org - FAIL
- |_asn-query: No Servers
- | dns-zeustracker:
- |_ ERROR: DNS Query failed
- |_path-mtu: PMTU == 1500
- | dns-brute:
- | DNS Brute-force hostnames
- |_ No results.
- |_hostmap: Error: found no hostnames but not the marker for "no hostnames found" (pattern error?)
- | ip-geolocation-geobytes:
- | 157.150.195.212 (careers.un.org)
- | coordinates (lat,lon): 40.7488,-73.9846
- |_ city: New York, New York, United States
- | firewalk:
- | HOP HOST PROTOCOL BLOCKED PORTS
- |_1 192.168.140.2 tcp 21-23,25,110,139,445,3389
- | ip-geolocation-geoplugin:
- | 157.150.195.212 (careers.un.org)
- | coordinates (lat,lon): 40.752799987793,-73.972503662109
- |_ state: New York, United States
- | whois: Record found at whois.arin.net
- | netrange: 157.150.0.0 - 157.150.255.255
- | netname: UN-NET
- | orgname: United Nations
- | orgid: UNITED-2
- | country: US stateprov: NY
- |
- | orgtechname: Linehan, Andrew John
- |_orgtechemail: linehan@un.org
- |_ipidseq: Random Positive Increments [used port 80]
- | qscan:
- | PORT FAMILY MEAN (us) STDDEV LOSS (%)
- | 80 0 389239.00 38695.70 0.0%
- |_443 0 385803.40 34701.11 0.0%
- TRACEROUTE (using port 443/tcp)
- HOP RTT ADDRESS
- 1 0.57 ms 192.168.140.2
- 2 357.84 ms secnet158.un.org (157.150.195.212)
- Final times for host: srtt: 345936 rttvar: 50458 to: 547768
- New targets in the scanned cache: 0, pending ones: 0.
- Post-scan script results:
- | reverse-index:
- | 80/tcp: 157.150.195.212
- |_ 443/tcp: 157.150.195.212
RAW Paste Data