Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- OHCHR.COM (Human Rights Commission) MAIL/WAF and RSA LEAK ..!!
- (ATTACK NON-INTRUSIVE)
- PROJECT DEDICATION: PROJECT SARADIYEL (http://en.wikipedia.org/wiki/Uthuwankande_Soora_Saradiyel)
- EXCLUSIVE FROM - Anonymous Sri Lanka
- WWW.OHCHR.COM -----> Servers Fuck3D and Bust3D
- Primary Server Data Leak with Transferring (Data Leak)....!!
- Hail to Anonymous, Lulzsec and Operation Anti-Sec...
- THIS ATTACK AGAINST THE DIRTIEST THINGS AGAINST THE SRI LANKA BY HUMAN RIGHTS COMMISSION ....!!!!!
- webmail.ohchr.org (193.194.138.188)
- 80/tcp open http syn-ack
- |
- | http-waf-detect: IDS/IPS/WAF detected:
- |_webmail.ohchr.org:80/?p4yl04d3=<script>alert(document.cookie)</script>
- | http-headers:
- | Content-Length: 0
- | Location: https://webmail.ohchr.org/
- |
- |
- | ssl-cert: Subject: commonName=webmail.ohchr.org/organizationName=International Computing Centre/stateOrProvinceName=Geneva/countryName=CH/streetAddress=Palais des Nations/localityName=Geneva/postalCode=1211/organizationalUnitName=InstantSSL
- | Issuer: commonName=COMODO High-Assurance Secure Server CA/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB/localityName=Salford
- | Public Key type: rsa
- | Public Key bits: 2048
- | Not valid before: 2012-02-22 00:00:00
- | Not valid after: 2013-04-09 23:59:59
- | MD5: 4bf0 10ab 22fb d81c 9af7 b1d4 e1c8 94c1
- | SHA-1: 5c4f 18b6 9a04 e3d8 151a 3037 69f6 2d01 7f0c 66c7
- | -----BEGIN CERTIFICATE-----
- | MIIF5TCCBM2gAwIBAgIRAI6wwjoVSm2ynLRYr1rRC08wDQYJKoZIhvcNAQEFBQAw
- | gYkxCzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAO
- | BgNVBAcTB1NhbGZvcmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMS8wLQYD
- | VQQDEyZDT01PRE8gSGlnaC1Bc3N1cmFuY2UgU2VjdXJlIFNlcnZlciBDQTAeFw0x
- | MjAyMjIwMDAwMDBaFw0xMzA0MDkyMzU5NTlaMIH7MQswCQYDVQQGEwJDSDENMAsG
- | A1UEERMEMTIxMTEPMA0GA1UECBMGR2VuZXZhMQ8wDQYDVQQHEwZHZW5ldmExGzAZ
- | BgNVBAkTElBhbGFpcyBkZXMgTmF0aW9uczEnMCUGA1UEChMeSW50ZXJuYXRpb25h
- | bCBDb21wdXRpbmcgQ2VudHJlMUQwQgYDVQQLEztJc3N1ZWQgdGhyb3VnaCBJbnRl
- | cm5hdGlvbmFsIENvbXB1dGluZyBDZW50cmUgRS1QS0kgTWFuYWdlcjETMBEGA1UE
- | CxMKSW5zdGFudFNTTDEaMBgGA1UEAxMRd2VibWFpbC5vaGNoci5vcmcwggEiMA0G
- | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDI4bJ4yAVAXhAlZpOJtlh7tbxrY7t6
- | wyJV+BYOlaAywJa1Y1gDJRZ0pScGH/tu76jdAZc3wBDp84KeZzyehhlI87UNAaK4
- | 3POZbWCRI4zF6whURL28l5TfpzUSvSaLX9ZrW3eK4KDXubWriXKKrzpZuWiCGiUL
- | cIckJkD7I++xbUtHs/5dgka+xuUJg28tbn+QzzfnCp7RcaKmXNxAJgqe6AkdHVxu
- | RXRdjWk4jTqj7twzcGyvv5QqfHSfmFOP3DeB5GH/814J2ssmHPvcg0Qm/C02/NsF
- | UIblz1ICMyjCb4zlrqWIfKVdaD2We6DjetHPXwlBXSo8sOD4LukOhGNNAgMBAAGj
- | ggHSMIIBzjAfBgNVHSMEGDAWgBQ/1bXQ1kR5UEoXo5uMSty4sCJkazAdBgNVHQ4E
- | FgQUyv8XSVUNTrEmxBIwuJwjpb7jH/swDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
- | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMEYGA1UdIAQ/MD0w
- | OwYMKwYBBAGyMQECAQMEMCswKQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNv
- | bW9kby5jb20vQ1BTME8GA1UdHwRIMEYwRKBCoECGPmh0dHA6Ly9jcmwuY29tb2Rv
- | Y2EuY29tL0NPTU9ET0hpZ2gtQXNzdXJhbmNlU2VjdXJlU2VydmVyQ0EuY3JsMIGA
- | BggrBgEFBQcBAQR0MHIwSgYIKwYBBQUHMAKGPmh0dHA6Ly9jcnQuY29tb2RvY2Eu
- | Y29tL0NPTU9ET0hpZ2gtQXNzdXJhbmNlU2VjdXJlU2VydmVyQ0EuY3J0MCQGCCsG
- | AQUFBzABhhhodHRwOi8vb2NzcC5jb21vZG9jYS5jb20wMwYDVR0RBCwwKoIRd2Vi
- | bWFpbC5vaGNoci5vcmeCFXd3dy53ZWJtYWlsLm9oY2hyLm9yZzANBgkqhkiG9w0B
- | AQUFAAOCAQEAuoNFHDR/XfAGQiSu1ig6smCcqPTK+ZSGexWMpgygtjCjzyFVSKgN
- | QEYari/BCxw8LCLsQPLCLxsqnKulhFjSA5aIBPZqgQ9+FZz2ONVTw0PzsitSTWsH
- | h6x+7F4MbvCwXRpMKmvmMMzAW6H26Kyq4iDGINJ+gtRkb1OP8hUvv46QfiRJ/LdW
- | 53yGvKt2lpB4D5r9yE4Yz/Hcb1jCtaA+78xvSkPsopysXIeky2dWgw9f0+anFFRE
- | hhYjZTHa20pbyPISANQBQvCYOTmdQgavJhrZfyLYjTxTaSu9tA79gMkijXH2dtQF
- | 2rmXrlE8mgyisN/LFS76a3E4G4NCWPSvbg==
- |_-----END CERTIFICATE-----
- |
- | http-robots.txt: 1 disallowed entry
- |_/
- | http-title: OHCHR Web Mail Access
- |_Requested resource was https://webmail.ohchr.org/dana-na/auth/url_4/welcome.cgi
- |
- | http-headers:
- | Location: https://webmail.ohchr.org/dana-na/auth/url_4/welcome.cgi
- | Content-Type: text/html; charset=utf-8
- | Set-Cookie: DSSIGNIN=url_4; path=/dana-na/; expires=Thu, 31-Dec-2037 00:00:00 GMT; secure
- | Set-Cookie: DSIVS=; path=/; expires=Thu, 01 Jan 1970 22:00:00 GMT; secure
- | Set-Cookie: DSSignInURL=/; path=/; secure
- | Connection: close
- |
- |_ (Request type: GET)
- |_http-userdir-enum: Didn't find any users!
- | ssl-enum-ciphers:
- | SSLv3
- | Ciphers (9)
- | TLS_RSA_EXPORT_WITH_DES40_CBC_SHA - unknown strength
- | TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 - unknown strength
- | TLS_RSA_EXPORT_WITH_RC4_40_MD5 - unknown strength
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - unknown strength
- | TLS_RSA_WITH_DES_CBC_SHA - unknown strength
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- | TLSv1.0
- | Ciphers (9)
- | TLS_RSA_EXPORT_WITH_DES40_CBC_SHA - unknown strength
- | TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 - unknown strength
- | TLS_RSA_EXPORT_WITH_RC4_40_MD5 - unknown strength
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - unknown strength
- | TLS_RSA_WITH_DES_CBC_SHA - unknown strength
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- |_ Least strength = unknown strength
- | http-vhosts:
- |_405 names had status 302
- | http-enum:
- |_ /robots.txt: Robots file
- Host script results:
- | unusual-port:
- |_ WARNING: this script depends on Nmap's service/version detection (-sV)
- |_path-mtu: PMTU == 1500
- | ip-geolocation-geobytes:
- | 193.194.138.188 (webmail.ohchr.org)
- | coordinates (lat,lon): 46.2,6.167
- |_ city: Geneva, Geneve, Switzerland
- | ip-geolocation-geoplugin:
- | 193.194.138.188 (webmail.ohchr.org)
- | coordinates (lat,lon): 46.200000762939,6.166699886322
- |_ state: 7, Switzerland
- | asn-query:
- | BGP: 193.194.138.0/24 | Country: CH
- | Origin AS: 8659 - AS8659 United Nations International Computing Centre
- |_ Peer AS: 3549 8220
- | whois: Record found at whois.ripe.net
- | inetnum: 193.194.138.0 - 193.194.139.255
- | netname: UNICC
- | descr: United Nations International Computing Center
- | country: CH
- | person: Roberto Kuroiwa
- |_email: callcentre@unicc.org
- |_ipidseq: Unknown [used port 80]
- | dns-brute:
- | DNS Brute-force hostnames
- | www.ohchr.org - 193.194.138.68
- | mail.ohchr.org - 193.194.138.188
- | intranet.ohchr.org - 193.194.138.111
- | smtp.ohchr.org - 193.194.138.188
- | ftp.ohchr.org - 192.91.247.98
- | ap.ohchr.org - 193.194.138.185
- |_ info.ohchr.org - 193.194.138.183
- | qscan:
- | PORT FAMILY MEAN (us) STDDEV LOSS (%)
- | 80 0 390517.00 10508.25 0.0%
- |_443 0 395191.30 14500.48 0.0%
RAW Paste Data