Advertisement
Guest User

Anonymous Operation Israel JTSEC full recon 2018 #18

a guest
Apr 8th, 2018
415
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 38.31 KB | None | 0 0
  1. #######################################################################################################################################
  2. Hostname www.environment.gov.il ISP Tehila Project - Prime Minister Office's (AS8867)
  3. Continent Asia Flag
  4. IL
  5. Country Israel Country Code IL (ISR)
  6. Region 04 Local time 08 Apr 2018 00:38 IDT
  7. City Or Akiva Latitude 32.506
  8. IP Address 147.237.77.18 Longitude 34.921
  9. #######################################################################################################################################
  10. HostIP:147.237.77.18
  11. HostName:environment.gov.il
  12.  
  13. Gathered Inet-whois information for 147.237.77.18
  14. ---------------------------------------------------------------------------------------------------------------------------------------
  15.  
  16.  
  17. inetnum: 147.237.0.0 - 147.237.255.255
  18. netname: IL-GOVT-NET
  19. descr: Israeli Government Network
  20. country: IL
  21. admin-c: AT979-RIPE
  22. tech-c: TT441-RIPE
  23. status: LEGACY
  24. remarks: For information on "status:" attribute read https://www.ripe.net/data-tools/db/faq/faq-status-values-legacy-resources
  25. mnt-by: GOV-IL-DNS
  26. mnt-lower: GOV-IL-DNS
  27. mnt-routes: AS8867-MNT ANY
  28. mnt-routes: AS9116-MNT { 147.237.232.0/24^24-24 }
  29. created: 1970-01-01T00:00:00Z
  30. last-modified: 2015-05-05T01:38:51Z
  31. source: RIPE # Filtered
  32.  
  33. person: Admin Tehila
  34. address: Israel Ministry Of Finance
  35. address: 1 Netanel Lorech st
  36. address: Jerusalem Israel
  37. phone: +972 2 6664666
  38. fax-no: +972 2 6664650
  39. remarks: For ABUSE and security issues please contact
  40. remarks: email: abuse@tehila.gov.il
  41. remarks: or contact CERT.gov.il at report@CERT.gov.il
  42. nic-hdl: AT979-RIPE
  43. created: 2002-06-02T08:31:21Z
  44. last-modified: 2016-04-06T03:26:29Z
  45. mnt-by: RIPE-NCC-LOCKED-MNT
  46. source: RIPE # Filtered
  47.  
  48. person: Tech Tehila
  49. address: Israeli Ministry of Finance
  50. address: 1 Netanel Lorech st. , Jerusalem 91008, Israel
  51. phone: +972 2 6664666
  52. fax-no: +972 2 6664650
  53. remarks: For ABUSE and security issues please contact
  54. remarks: email: abuse@tehila.gov.il
  55. remarks: or contact CERT.gov.il at report@CERT.gov.il
  56. nic-hdl: TT441-RIPE
  57. created: 2002-06-02T08:31:22Z
  58. last-modified: 2016-04-06T03:26:28Z
  59. mnt-by: RIPE-NCC-LOCKED-MNT
  60. source: RIPE # Filtered
  61.  
  62. % Information related to '147.237.0.0/16AS8867'
  63.  
  64. route: 147.237.0.0/16
  65. descr: IL-GOVT-BLOCK
  66. origin: AS8867
  67. mnt-by: AS8867-MNT
  68. mnt-routes: AS8867-MNT ANY
  69. mnt-routes: AS9116-MNT { 147.237.232.0/24^24-24 }
  70. created: 1970-01-01T00:00:00Z
  71. last-modified: 2013-05-29T13:30:11Z
  72. source: RIPE
  73.  
  74. % This query was served by the RIPE Database Query Service version 1.91.1 (BLAARKOP)
  75.  
  76.  
  77.  
  78. Gathered Inic-whois information for environment.gov.il
  79. ---------------------------------------------------------------------------------------------------------------------------------------
  80. domain: environment.gov.il
  81.  
  82. descr: Tech Tehila
  83. descr: 1 Netanel Lorech st
  84. descr: Jerusalem
  85. descr: 91911
  86. descr: Israel
  87. e-mail: hostmaster AT tehila.gov.il
  88. admin-c: GV-TT3128-IL
  89. tech-c: GV-TT3128-IL
  90. zone-c: GV-TT3128-IL
  91. nserver: dns.gov.il
  92. nserver: dns3.gov.il
  93. validity: N/A
  94. DNSSEC: unsigned
  95. status: Transfer Allowed
  96. changed: domain-registrar AT isoc.org.il 20jV@11102F��7 �(Assign�%���ediV@)
  97. changed: domain-registrar AT isoc.org.il 20150121 (Changed)
  98. changed: domain-registrar AT isoc.org.il 20150122 (Changed)
  99.  
  100. person: Tech Tehila
  101. address: Prime minister office
  102. address: 1 Netanel Lorech st
  103. address: Jerusalem
  104. address: 91039
  105. address: Israel
  106. phone: +972 2 6664666
  107. fax-no: +972 2 6664650
  108. e-mail: Hostmaster AT tehila.gov.il
  109. nic-hdl: GV-TT3128-IL
  110. changed: Managing Registrar 20111027
  111. changed: Managing Registrar 20150122
  112.  
  113. registrar name: Israel Government
  114. registrar info:
  115.  
  116. % Rights to the data above are restricted by copyright.
  117.  
  118. Gathered Netcraft information for environment.gov.il
  119. ---------------------------------------------------------------------------------------------------------------------------------------
  120.  
  121. Retrieving Netcraft.com information for environment.gov.il
  122. Netcraft.com Information gathered
  123.  
  124. Gathered Subdomain information for environment.gov.il
  125. --------------------------------------------------------------------------------------------------------------------------------------
  126. Searching Google.com:80...
  127. HostName:www.environment.gov.il
  128. HostIP:147.237.77.18
  129. Searching Altavista.com:80...
  130. Found 1 possible subdomain(s) for host environment.gov.il, Searched 0 pages containing 0 results
  131.  
  132. Gathered E-Mail information for environment.gov.il
  133. --------------------------------------------------------------------------------------------------------------------------------------
  134. Searching Google.com:80...
  135. Searching Altavista.com:80...
  136. Found 0 E-Mail(s) for host environment.gov.il, Searched 0 pages containing 0 results
  137.  
  138. Gathered TCP Port information for 147.237.77.18
  139. ---------------------------------------------------------------------------------------------------------------------------------------
  140.  
  141. Port State
  142.  
  143.  
  144. Portscan Finished: Scanned 150 ports, 0 ports were in state closed
  145. #######################################################################################################################################
  146. [i] Scanning Site: http://environment.gov.il
  147.  
  148.  
  149.  
  150. B A S I C I N F O
  151. =======================================================================================================================================
  152.  
  153.  
  154. [+] Site Title:
  155. [+] IP address: 147.237.77.18
  156. [+] Web Server: Could Not Detect
  157. [+] CMS: Could Not Detect
  158. [+] Cloudflare: Not Detected
  159. [+] Robots File: Found
  160.  
  161. -------------[ contents ]----------------
  162. <html><body><script>document.cookie='ccccccc=f2f5ce66ccccccc_f2f5ce66; path=/';window.location.href=window.location.href;</script></body></html>
  163. -----------[end of contents]-------------
  164.  
  165.  
  166.  
  167. W H O I S L O O K U P
  168. ========================
  169.  
  170.  
  171. % The data in the WHOIS database of the .il registry is provided
  172. % by ISOC-IL for information purposes, and to assist persons in
  173. % obtaining information about or related to a domain name
  174. % registration record. ISOC-IL does not guarantee its accuracy.
  175. % By submitting a WHOIS query, you agree that you will use this
  176. % Data only for lawful purposes and that, under no circumstances
  177. % will you use this Data to: (1) allow, enable, or otherwise
  178. % support the transmission of mass unsolicited, commercial
  179. % advertising or solicitations via e-mail (spam);
  180. % or (2) enable high volume, automated, electronic processes that
  181. % apply to ISOC-IL (or its systems).
  182. % ISOC-IL reserves the right to modify these terms at any time.
  183. % By submitting this query, you agree to abide by this policy.
  184.  
  185. query: environment.gov.il
  186.  
  187. reg-name: environment
  188. domain: environment.gov.il
  189.  
  190. descr: Tech Tehila
  191. descr: 1 Netanel Lorech st
  192. descr: Jerusalem
  193. descr: 91911
  194. descr: Israel
  195. e-mail: hostmaster AT tehila.gov.il
  196. admin-c: GV-TT3128-IL
  197. tech-c: GV-TT3128-IL
  198. zone-c: GV-TT3128-IL
  199. nserver: dns.gov.il
  200. nserver: dns3.gov.il
  201. validity: N/A
  202. DNSSEC: unsigned
  203. status: Transfer Allowed
  204. changed: domain-registrar AT isoc.org.il 20111027 (Assigned)
  205. changed: domain-registrar AT isoc.org.il 20150121 (Changed)
  206. changed: domain-registrar AT isoc.org.il 20150122 (Changed)
  207.  
  208. person: Tech Tehila
  209. address: Prime minister office
  210. address: 1 Netanel Lorech st
  211. address: Jerusalem
  212. address: 91039
  213. address: Israel
  214. phone: +972 2 6664666
  215. fax-no: +972 2 6664650
  216. e-mail: Hostmaster AT tehila.gov.il
  217. nic-hdl: GV-TT3128-IL
  218. changed: Managing Registrar 20111027
  219. changed: Managing Registrar 20150122
  220.  
  221. registrar name: Israel Government
  222. registrar info:
  223.  
  224. % Rights to the data above are restricted by copyright.
  225.  
  226.  
  227.  
  228.  
  229. G E O I P L O O K U P
  230. =======================================================================================================================================
  231.  
  232. [i] IP Address: 147.237.77.18
  233. [i] Country: IL
  234. [i] State: N/A
  235. [i] City: N/A
  236. [i] Latitude: 31.500000
  237. [i] Longitude: 34.750000
  238.  
  239.  
  240.  
  241.  
  242. H T T P H E A D E R S
  243. ======================================================================================================================================
  244.  
  245.  
  246. [i] HTTP/1.0 200 OK
  247. [i] Expires: Sat, 6 May 1995 12:00:00 GMT
  248. [i] P3P: CP=NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM
  249. [i] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
  250. [i] Pragma: no-cache
  251. [i] Content-Length: 144
  252. [i] Connection: Close
  253.  
  254.  
  255.  
  256.  
  257. D N S L O O K U P
  258. ======================================================================================================================================
  259.  
  260. ;; Truncated, retrying in TCP mode.
  261. environment.gov.il. 3600 IN SOA dns.gov.il. hostmaster.tehila.gov.il. 2018010101 21600 3600 3628800 3600
  262. environment.gov.il. 600 IN MX 5 mail.tehila.gov.il.
  263. environment.gov.il. 3600 IN NS asia4.akam.net.
  264. environment.gov.il. 3600 IN NS eur6.akam.net.
  265. environment.gov.il. 3600 IN NS dns.gov.il.
  266. environment.gov.il. 3600 IN NS usw2.akam.net.
  267. environment.gov.il. 3600 IN NS asia3.akam.net.
  268. environment.gov.il. 3600 IN NS ns1-69.akam.net.
  269. environment.gov.il. 3600 IN NS eur2.akam.net.
  270. environment.gov.il. 3600 IN NS dns3.gov.il.
  271. environment.gov.il. 3600 IN NS ns1-111.akam.net.
  272. environment.gov.il. 3600 IN NS use4.akam.net.
  273. environment.gov.il. 3600 IN TXT "v=spf1 ip4:147.237.70.203 ip4:147.237.70.204 ip4:147.237.70.205 ip4:147.237.70.206 ~all"
  274. environment.gov.il. 3600 IN A 147.237.77.18
  275.  
  276.  
  277.  
  278.  
  279. S U B N E T C A L C U L A T I O N
  280. ======================================================================================================================================
  281.  
  282. Address = 147.237.77.18
  283. Network = 147.237.77.18 / 32
  284. Netmask = 255.255.255.255
  285. Broadcast = not needed on Point-to-Point links
  286. Wildcard Mask = 0.0.0.0
  287. Hosts Bits = 0
  288. Max. Hosts = 1 (2^0 - 0)
  289. Host Range = { 147.237.77.18 - 147.237.77.18 }
  290.  
  291.  
  292.  
  293. N M A P P O R T S C A N
  294. ======================================================================================================================================
  295.  
  296.  
  297. Starting Nmap 7.01 ( https://nmap.org ) at 2018-04-07 21:43 UTC
  298. Nmap scan report for environment.gov.il (147.237.77.18)
  299. Host is up (0.14s latency).
  300. PORT STATE SERVICE VERSION
  301. 21/tcp filtered ftp
  302. 22/tcp filtered ssh
  303. 23/tcp filtered telnet
  304. 25/tcp filtered smtp
  305. 80/tcp open http?
  306. 110/tcp filtered pop3
  307. 143/tcp filtered imap
  308. 443/tcp filtered https
  309. 445/tcp filtered microsoft-ds
  310. 3389/tcp filtered ms-wbt-server
  311. ######################################################################################################################################
  312. [!] IP Address : 147.237.77.18
  313. [!] environment.gov.il doesn't seem to use a CMS
  314. [+] Honeypot Probabilty: 0%
  315. ----------------------------------------
  316. [~] Trying to gather whois information for environment.gov.il
  317. [+] Whois information found
  318. Registrant Name : Tech Tehila
  319. Status : Transfer Allowed
  320. Dnssec : unsigned
  321. Expiration Date : N/A
  322. Domain Name : environment.gov.il
  323. Phone : +972 2 6664666
  324. Registrar : Israel Government
  325. Referral Url : None
  326. Name Servers : dns.gov.il, dns3.gov.il
  327. Emails : hostmaster@tehila.gov.il, Hostmaster@tehila.gov.il
  328. ----------------------------------------
  329. PORT STATE SERVICE VERSION
  330. 21/tcp filtered ftp
  331. 22/tcp filtered ssh
  332. 23/tcp filtered telnet
  333. 25/tcp filtered smtp
  334. 80/tcp open http?
  335. 110/tcp filtered pop3
  336. 143/tcp filtered imap
  337. 443/tcp filtered https
  338. 445/tcp filtered microsoft-ds
  339. 3389/tcp filtered ms-wbt-server
  340.  
  341.  
  342. [+] DNS Records
  343. ns1-111.akam.net. (193.108.91.111) AS21342 Akamai International B.V. Europe
  344. dns3.gov.il. (62.219.20.20) AS8551 Bezeq International Israel
  345. use4.akam.net. (23.211.133.65) AS21342 Akamai International B.V. Netherlands
  346. eur6.akam.net. (2.22.230.64) AS21342 Akamai International B.V. Spain
  347. dns.gov.il. (147.237.71.1) AS8867 Tehila Project - Prime Minister Office's Israel
  348. ns1-69.akam.net. (193.108.91.69) AS21342 Akamai International B.V. Europe
  349. usw2.akam.net. (184.26.161.64) AS21342 Akamai International B.V. United States
  350. asia3.akam.net. (23.211.61.64) AS21342 Akamai International B.V. Netherlands
  351. eur2.akam.net. (95.100.173.64) AS21342 Akamai International B.V. Europe
  352. asia4.akam.net. (184.85.248.64) AS21342 Akamai International B.V. Netherlands
  353.  
  354. [+] MX Records
  355. 5 (147.237.71.5) AS8867 Tehila Project - Prime Minister Office's Israel
  356.  
  357. [+] Host Records (A)
  358. www.environment.gov.il (147.237.77.18) AS8867 Tehila Project - Prime Minister Office's Israel
  359.  
  360. [+] TXT Records
  361. "v=spf1 ip4:147.237.70.203 ip4:147.237.70.204 ip4:147.237.70.205 ip4:147.237.70.206 ~all"
  362.  
  363. [+] DNS Map: https://dnsdumpster.com/static/map/environment.gov.il.png
  364.  
  365. [>] Initiating 3 intel modules
  366. [>] Loading Alpha module (1/3)
  367. [>] Beta module deployed (2/3)
  368. [>] Gamma module initiated (3/3)
  369.  
  370.  
  371. [+] Emails found:
  372. ---------------------------------------------------------------------------------------------------------------------------------------
  373. BaruchW@environment.gov.il
  374. Stelian@environment.gov.il
  375. alonz@environment.gov.il
  376. doar@environment.gov.il
  377. dover@environment.gov.il
  378. giliz@environment.gov.il
  379. hagaib@environment.gov.il
  380. iriss@environment.gov.il
  381. mankal@environment.gov.il
  382. miriamh@environment.gov.il
  383. ori@environment.gov.il
  384. pniot@environment.gov.il
  385. rayab@environment.gov.il
  386. ronene@environment.gov.il
  387. sar@environment.gov.il
  388. shulin@environment.gov.il
  389. victors@environment.gov.il
  390. yossi@environment.gov.il
  391.  
  392. [+] Hosts found in search engines:
  393. ------------------------------------
  394. [-] Resolving hostnames IPs...
  395. 147.237.77.18:WWW.environment.gov.il
  396. 147.237.77.18:www.environment.gov.il
  397. [+] Virtual hosts:
  398. -----------------
  399. 147.237.77.18 sviva.gov.il
  400. 147.237.77.18 www.sviva.gov.il
  401. #######################################################################################################################################
  402. Original* environment.gov.il 147.237.77.18 NS:asia3.akam.net MX:mail.tehila.gov.il
  403. #######################################################################################################################################
  404. [*] Processing domain environment.gov.il
  405. [+] Getting nameservers
  406. 184.85.248.64 - asia4.akam.net
  407. 2.22.230.64 - eur6.akam.net
  408. 147.237.71.1 - dns.gov.il
  409. 193.108.91.111 - ns1-111.akam.net
  410. 62.219.20.20 - dns3.gov.il
  411. 95.100.173.64 - eur2.akam.net
  412. 23.211.133.65 - use4.akam.net
  413. 184.26.161.64 - usw2.akam.net
  414. 23.211.61.64 - asia3.akam.net
  415. 193.108.91.69 - ns1-69.akam.net
  416. [-] Zone transfer failed
  417.  
  418. [+] TXT records found
  419. "v=spf1 ip4:147.237.70.203 ip4:147.237.70.204 ip4:147.237.70.205 ip4:147.237.70.206 ~all"
  420.  
  421. [+] MX records found, added to target list
  422. 5 mail.tehila.gov.il.
  423.  
  424. [*] Scanning environment.gov.il for A records
  425. 147.237.77.18 - environment.gov.il
  426. 147.237.77.18 - www.environment.gov.il
  427. ######################################################################################################################################
  428. Ip Address Status Type Domain Name Server
  429. ---------- ------ ---- ----------- ------
  430. 147.237.77.18 host www.environment.gov.il
  431. #######################################################################################################################################
  432. Server: 10.211.254.254
  433. Address: 10.211.254.254#53
  434.  
  435. Non-authoritative answer:
  436. Name: environment.gov.il
  437. Address: 147.237.77.18
  438.  
  439. environment.gov.il has address 147.237.77.18
  440. environment.gov.il mail is handled by 5 mail.tehila.gov.il.
  441. #######################################################################################################################################
  442. Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor@o0o.nu, ofir@sys-security.com, meder@o0o.nu
  443.  
  444. [+] Target is environment.gov.il
  445. [+] Loading modules.
  446. [+] Following modules are loaded:
  447. [x] [1] ping:icmp_ping - ICMP echo discovery module
  448. [x] [2] ping:tcp_ping - TCP-based ping discovery module
  449. [x] [3] ping:udp_ping - UDP-based ping discovery module
  450. [x] [4] infogather:ttl_calc - TCP and UDP based TTL distance calculation
  451. [x] [5] infogather:portscan - TCP and UDP PortScanner
  452. [x] [6] fingerprint:icmp_echo - ICMP Echo request fingerprinting module
  453. [x] [7] fingerprint:icmp_tstamp - ICMP Timestamp request fingerprinting module
  454. [x] [8] fingerprint:icmp_amask - ICMP Address mask request fingerprinting module
  455. [x] [9] fingerprint:icmp_port_unreach - ICMP port unreachable fingerprinting module
  456. [x] [10] fingerprint:tcp_hshake - TCP Handshake fingerprinting module
  457. [x] [11] fingerprint:tcp_rst - TCP RST fingerprinting module
  458. [x] [12] fingerprint:smb - SMB fingerprinting module
  459. [x] [13] fingerprint:snmp - SNMPv2c fingerprinting module
  460. [+] 13 modules registered
  461. [+] Initializing scan engine
  462. [+] Running scan engine
  463. [-] ping:tcp_ping module: no closed/open TCP ports known on 147.237.77.18. Module test failed
  464. [-] ping:udp_ping module: no closed/open UDP ports known on 147.237.77.18. Module test failed
  465. [-] No distance calculation. 147.237.77.18 appears to be dead or no ports known
  466. [+] Host: 147.237.77.18 is down (Guess probability: 0%)
  467. [+] Cleaning up scan engine
  468. [+] Modules deinitialized
  469. [+] Execution completed.
  470. #######################################################################################################################################
  471.  
  472. % The data in the WHOIS database of the .il registry is provided
  473. % by ISOC-IL for information purposes, and to assist persons in
  474. % obtaining information about or related to a domain name
  475. % registration record. ISOC-IL does not guarantee its accuracy.
  476. % By submitting a WHOIS query, you agree that you will use this
  477. % Data only for lawful purposes and that, under no circumstances
  478. % will you use this Data to: (1) allow, enable, or otherwise
  479. % support the transmission of mass unsolicited, commercial
  480. % advertising or solicitations via e-mail (spam);
  481. % or (2) enable high volume, automated, electronic processes that
  482. % apply to ISOC-IL (or its systems).
  483. % ISOC-IL reserves the right to modify these terms at any time.
  484. % By submitting this query, you agree to abide by this policy.
  485.  
  486. query: environment.gov.il
  487.  
  488. reg-name: environment
  489. domain: environment.gov.il
  490.  
  491. descr: Tech Tehila
  492. descr: 1 Netanel Lorech st
  493. descr: Jerusalem
  494. descr: 91911
  495. descr: Israel
  496. e-mail: hostmaster AT tehila.gov.il
  497. admin-c: GV-TT3128-IL
  498. tech-c: GV-TT3128-IL
  499. zone-c: GV-TT3128-IL
  500. nserver: dns.gov.il
  501. nserver: dns3.gov.il
  502. validity: N/A
  503. DNSSEC: unsigned
  504. status: Transfer Allowed
  505. changed: domain-registrar AT isoc.org.il 20111027 (Assigned)
  506. changed: domain-registrar AT isoc.org.il 20150121 (Changed)
  507. changed: domain-registrar AT isoc.org.il 20150122 (Changed)
  508.  
  509. person: Tech Tehila
  510. address: Prime minister office
  511. address: 1 Netanel Lorech st
  512. address: Jerusalem
  513. address: 91039
  514. address: Israel
  515. phone: +972 2 6664666
  516. fax-no: +972 2 6664650
  517. e-mail: Hostmaster AT tehila.gov.il
  518. nic-hdl: GV-TT3128-IL
  519. changed: Managing Registrar 20111027
  520. changed: Managing Registrar 20150122
  521.  
  522. registrar name: Israel Government
  523. registrar info:
  524.  
  525. % Rights to the data above are restricted by copyright.
  526. ######################################################################################################################################
  527.  
  528. ; <<>> DiG 9.11.3-1-Debian <<>> -x environment.gov.il
  529. ;; global options: +cmd
  530. ;; Got answer:
  531. ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 49597
  532. ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
  533.  
  534. ;; OPT PSEUDOSECTION:
  535. ; EDNS: version: 0, flags:; udp: 4096
  536. ;; QUESTION SECTION:
  537. ;il.gov.environment.in-addr.arpa. IN PTR
  538.  
  539. ;; AUTHORITY SECTION:
  540. in-addr.arpa. 3600 IN SOA b.in-addr-servers.arpa. nstld.iana.org. 2018013344 1800 900 604800 3600
  541.  
  542. ;; Query time: 558 msec
  543. ;; SERVER: 10.211.254.254#53(10.211.254.254)
  544. ;; WHEN: Sat Apr 07 18:07:15 EDT 2018
  545. ;; MSG SIZE rcvd: 128
  546.  
  547. dnsenum VERSION:1.2.4
  548.  
  549. ----- environment.gov.il -----
  550.  
  551.  
  552. Host's addresses:
  553. __________________
  554.  
  555. environment.gov.il. 3585 IN A 147.237.77.18
  556.  
  557.  
  558. Name Servers:
  559. ______________
  560.  
  561. asia4.akam.net. 89909 IN A 184.85.248.64
  562. usw2.akam.net. 85717 IN A 184.26.161.64
  563. asia3.akam.net. 86416 IN A 23.211.61.64
  564. ns1-69.akam.net. 89923 IN A 193.108.91.69
  565. eur6.akam.net. 89909 IN A 2.22.230.64
  566. dns.gov.il. 510 IN A 147.237.71.1
  567. ns1-111.akam.net. 89936 IN A 193.108.91.111
  568. eur2.akam.net. 83758 IN A 95.100.173.64
  569. dns3.gov.il. 600 IN A 62.219.20.20
  570. use4.akam.net. 89964 IN A 23.211.133.65
  571.  
  572.  
  573. Mail (MX) Servers:
  574. ___________________
  575.  
  576. mail.tehila.gov.il. 600 IN A 147.237.71.7
  577. mail.tehila.gov.il. 600 IN A 147.237.71.6
  578. mail.tehila.gov.il. 600 IN A 147.237.71.4
  579. mail.tehila.gov.il. 600 IN A 147.237.71.5
  580.  
  581.  
  582. Trying Zone Transfers and getting Bind Versions:
  583. _________________________________________________
  584.  
  585.  
  586. Trying Zone Transfer for environment.gov.il on asia4.akam.net ...
  587.  
  588. Trying Zone Transfer for environment.gov.il on usw2.akam.net ...
  589.  
  590. Trying Zone Transfer for environment.gov.il on asia3.akam.net ...
  591.  
  592. Trying Zone Transfer for environment.gov.il on ns1-69.akam.net ...
  593.  
  594. Trying Zone Transfer for environment.gov.il on eur6.akam.net ...
  595.  
  596. Trying Zone Transfer for environment.gov.il on dns.gov.il ...
  597.  
  598. Trying Zone Transfer for environment.gov.il on ns1-111.akam.net ...
  599.  
  600. Trying Zone Transfer for environment.gov.il on eur2.akam.net ...
  601.  
  602. Trying Zone Transfer for environment.gov.il on dns3.gov.il ...
  603.  
  604. Trying Zone Transfer for environment.gov.il on use4.akam.net ...
  605.  
  606. brute force file not specified, bay.
  607. #######################################################################################################################################
  608. [-] Enumerating subdomains now for environment.gov.il
  609. [-] verbosity is enabled, will show the subdomains results in realtime
  610. [-] Searching now in Baidu..
  611. [-] Searching now in Yahoo..
  612. [-] Searching now in Google..
  613. [-] Searching now in Bing..
  614. [-] Searching now in Ask..
  615. [-] Searching now in Netcraft..
  616. [-] Searching now in DNSdumpster..
  617. [-] Searching now in Virustotal..
  618. [-] Searching now in ThreatCrowd..
  619. [-] Searching now in SSL Certificates..
  620. [-] Searching now in PassiveDNS..
  621. HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /en/domain/environment.gov.il/information/ (Caused by NewConnectionError('<urllib3.connection.VerifiedHTTPSConnection object at 0x7f77aef38710>: Failed to establish a new connection: [Errno -2] Name or service not known',))
  622. HTTPSConnectionPool(host='searchdns.netcraft.com', port=443): Max retries exceeded with url: /?restriction=site+ends+with&host=example.com (Caused by NewConnectionError('<urllib3.connection.VerifiedHTTPSConnection object at 0x7f77aef38750>: Failed to establish a new connection: [Errno -2] Name or service not known',))
  623. DNSdumpster: www.environment.gov.il
  624. Yahoo: www.environment.gov.il
  625. [-] Saving results to file: /usr/share/sniper/loot/environment.gov.il/domains/domains-environment.gov.il.txt
  626. [-] Total Unique Subdomains Found: 1
  627. www.environment.gov.il
  628.  
  629. ######################################################################################################################################
  630. __
  631. ____ _____ ___ ______ _/ /_____ ____ ___
  632. / __ `/ __ `/ / / / __ `/ __/ __ \/ __ \/ _ \
  633. / /_/ / /_/ / /_/ / /_/ / /_/ /_/ / / / / __/
  634. \__,_/\__, /\__,_/\__,_/\__/\____/_/ /_/\___/
  635. /_/ discover v0.5.0 - by @michenriksen
  636.  
  637. Identifying nameservers for environment.gov.il... Done
  638. Using nameservers:
  639.  
  640. - 2.22.230.64
  641. - 193.108.91.69
  642. - 193.108.91.111
  643. - 147.237.71.1
  644. - 95.100.173.64
  645. - 62.219.20.20
  646. - 23.211.61.64
  647. - 184.26.161.64
  648. - 23.211.133.65
  649. - 184.85.248.64
  650.  
  651. Checking for wildcard DNS... Done
  652.  
  653. Running collector: Certificate Search... Error
  654. -> Failed to open TCP connection to crt.sh:443 (getaddrinfo: Name or service not known)
  655. Running collector: Google Transparency Report... Done (0 hosts)
  656. Running collector: Shodan... Skipped
  657. -> Key 'shodan' has not been set
  658. Running collector: Dictionary... Done (27 hosts)
  659. Running collector: PassiveTotal... Skipped
  660. -> Key 'passivetotal_key' has not been set
  661. Running collector: DNSDB... Done (1 host)
  662. Running collector: Threat Crowd... Done (0 hosts)
  663. Running collector: VirusTotal... Skipped
  664. -> Key 'virustotal' has not been set
  665. Running collector: Riddler... Skipped
  666. -> Key 'riddler_username' has not been set
  667. Running collector: Netcraft... Done (0 hosts)
  668. Running collector: PTRArchive... Error
  669. -> PTRArchive returned unexpected response code: 502
  670. Running collector: Wayback Machine... Timed out
  671. Running collector: HackerTarget... Done (1 host)
  672. Running collector: Censys... Skipped
  673. -> Key 'censys_secret' has not been set
  674. Running collector: PublicWWW... Done (1 host)
  675.  
  676. Resolving 30 unique hosts...
  677. 147.237.77.18 .environment.gov.il
  678. 147.237.77.18 environment.gov.il
  679. 147.237.77.18 www.environment.gov.il
  680.  
  681. Found subnets:
  682.  
  683. - 147.237.77.0-255 : 3 hosts
  684.  
  685. Wrote 3 hosts to:
  686.  
  687. - file:///root/aquatone/environment.gov.il/hosts.txt
  688. - file:///root/aquatone/environment.gov.il/hosts.json
  689. __
  690. ____ _____ ___ ______ _/ /_____ ____ ___
  691. / __ `/ __ `/ / / / __ `/ __/ __ \/ __ \/ _ \
  692. / /_/ / /_/ / /_/ / /_/ / /_/ /_/ / / / / __/
  693. \__,_/\__, /\__,_/\__,_/\__/\____/_/ /_/\___/
  694. /_/ takeover v0.5.0 - by @michenriksen
  695.  
  696. Loaded 3 hosts from /root/aquatone/environment.gov.il/hosts.json
  697. Loaded 25 domain takeover detectors
  698.  
  699. Identifying nameservers for environment.gov.il... Done
  700. Using nameservers:
  701.  
  702. - 95.100.173.64
  703. - 184.26.161.64
  704. - 193.108.91.111
  705. - 184.85.248.64
  706. - 2.22.230.64
  707. - 23.211.133.65
  708. - 147.237.71.1
  709. - 62.219.20.20
  710. - 193.108.91.69
  711. - 23.211.61.64
  712.  
  713. Checking hosts for domain takeover vulnerabilities...
  714.  
  715. Finished checking hosts:
  716.  
  717. - Vulnerable : 0
  718. - Not Vulnerable : 3
  719.  
  720. Wrote 0 potential subdomain takeovers to:
  721.  
  722. - file:///root/aquatone/environment.gov.il/takeovers.json
  723.  
  724. __
  725. ____ _____ ___ ______ _/ /_____ ____ ___
  726. / __ `/ __ `/ / / / __ `/ __/ __ \/ __ \/ _ \
  727. / /_/ / /_/ / /_/ / /_/ / /_/ /_/ / / / / __/
  728. \__,_/\__, /\__,_/\__,_/\__/\____/_/ /_/\___/
  729. /_/ scan v0.5.0 - by @michenriksen
  730.  
  731. Loaded 3 hosts from /root/aquatone/environment.gov.il/hosts.json
  732.  
  733. Probing 2 ports...
  734. 80/tcp 147.237.77.18 .environment.gov.il, environment.gov.il, www.environment.gov.il
  735.  
  736. Wrote open ports to file:///root/aquatone/environment.gov.il/open_ports.txt
  737. Wrote URLs to file:///root/aquatone/environment.gov.il/urls.txt
  738. __
  739. ____ _____ ___ ______ _/ /_____ ____ ___
  740. / __ `/ __ `/ / / / __ `/ __/ __ \/ __ \/ _ \
  741. / /_/ / /_/ / /_/ / /_/ / /_/ /_/ / / / / __/
  742. \__,_/\__, /\__,_/\__,_/\__/\____/_/ /_/\___/
  743. /_/ gather v0.5.0 - by @michenriksen
  744.  
  745. Processing 3 pages...
  746. Failed: http://147.237.77.18/ (.environment.gov.il) - Timeout
  747. Failed: http://147.237.77.18/ (environment.gov.il) - Timeout
  748. Failed: http://147.237.77.18/ (www.environment.gov.il) - Timeout
  749.  
  750. Finished processing pages:
  751.  
  752. - Successful : 0
  753. - Failed : 3
  754.  
  755. Generating report...done
  756. Report pages generated:
  757.  
  758. #######################################################################################################################################
  759.  
  760.  
  761. [+] Emails found:
  762. ------------------
  763. BaruchW@environment.gov.il
  764. Stelian@environment.gov.il
  765. doar@environment.gov.il
  766. dover@environment.gov.il
  767. giliz@environment.gov.il
  768. hagaib@environment.gov.il
  769. iriss@environment.gov.il
  770. mankal@environment.gov.il
  771. miriamh@environment.gov.il
  772. ori@environment.gov.il
  773. pniot@environment.gov.il
  774. rayab@environment.gov.il
  775. ronene@environment.gov.il
  776. sar@environment.gov.il
  777. shulin@environment.gov.il
  778. victors@environment.gov.il
  779. yossi@environment.gov.il
  780.  
  781. [+] Hosts found in search engines:
  782. ------------------------------------
  783. [-] Resolving hostnames IPs...
  784. 147.237.77.18:www.environment.gov.il
  785. [+] Virtual hosts:
  786. ==================
  787. 147.237.77.18 sviva.gov.il
  788. 147.237.77.18 www.sviva.gov.il
  789.  
  790. ######################################################################################################################################
  791. Starting Nmap 7.70 ( https://nmap.org ) at 2018-04-07 18:16 EDT
  792. Nmap scan report for environment.gov.il (147.237.77.18)
  793. Host is up.
  794.  
  795. PORT STATE SERVICE
  796. 53/udp open|filtered domain
  797. 67/udp open|filtered dhcps
  798. 68/udp open|filtered dhcpc
  799. 69/udp open|filtered tftp
  800. 88/udp open|filtered kerberos-sec
  801. 123/udp open|filtered ntp
  802. 137/udp open|filtered netbios-ns
  803. 138/udp open|filtered netbios-dgm
  804. 139/udp open|filtered netbios-ssn
  805. 161/udp open|filtered snmp
  806. 162/udp open|filtered snmptrap
  807. 389/udp open|filtered ldap
  808. 520/udp open|filtered route
  809. 2049/udp open|filtered nfs
  810.  
  811. ######################################################################################################################################
  812. Hostname www.itrade.gov.il ISP 013 NetVision Ltd (AS1680)
  813. Continent Asia Flag
  814. IL
  815. Country Israel Country Code IL (ISR)
  816. Region Unknown Local time 08 Apr 2018 02:08 IDT
  817. City Unknown Latitude 31.5
  818. IP Address 185.162.127.53 Longitude 34.75
  819. ######################################################################################################################################
  820.  
  821. HostIP:107.178.254.36
  822. HostName:itrade.gov.il
  823.  
  824. Gathered Inet-whois information for 107.178.254.36
  825. ---------------------------------------------------------------------------------------------------------------------------------------
  826.  
  827.  
  828. inetnum: 107.161.176.0 - 107.181.127.255
  829. netname: NON-RIPE-NCC-MANAGED-ADDRESS-BLOCK
  830. descr: IPv4 address block not managed by the RIPE NCC
  831. remarks: ------------------------------------------------------
  832. remarks:
  833. remarks: You can find the whois server to query, or the
  834. remarks: IANA registry to query on this web page:
  835. remarks: http://www.iana.org/assignments/ipv4-address-space
  836. remarks:
  837. remarks: You can access databases of other RIRs at:
  838. remarks:
  839. remarks: AFRINIC (Africa)
  840. remarks: http://www.afrinic.net/ whois.afrinic.net
  841. remarks:
  842. remarks: APNIC (Asia Pacific)
  843. remarks: http://www.apnic.net/ whois.apnic.net
  844. remarks:
  845. remarks: ARIN (Northern America)
  846. remarks: http://www.arin.net/ whois.arin.net
  847. remarks:
  848. remarks: LACNIC (Latin America and the Carribean)
  849. remarks: http://www.lacnic.net/ whois.lacnic.net
  850. remarks:
  851. remarks: IANA IPV4 Recovered Address Space
  852. remarks: http://www.iana.org/assignments/ipv4-recovered-address-space/ipv4-recovered-address-space.xhtml
  853. remarks:
  854. remarks: ------------------------------------------------------
  855. country: EU # Country is really world wide
  856. admin-c: IANA1-RIPE
  857. tech-c: IANA1-RIPE
  858. status: ALLOCATED UNSPECIFIED
  859. mnt-by: RIPE-NCC-HM-MNT
  860. mnt-lower: RIPE-NCC-HM-MNT
  861. mnt-routes: RIPE-NCC-RPSL-MNT
  862. created: 2016-07-21T14:34:45Z
  863. last-modified: 2016-07-21T14:34:45Z
  864. source: RIPE
  865.  
  866. role: Internet Assigned Numbers Authority
  867. address: see http://www.iana.org.
  868. admin-c: IANA1-RIPE
  869. tech-c: IANA1-RIPE
  870. nic-hdl: IANA1-RIPE
  871. remarks: For more information on IANA services
  872. remarks: go to IANA web site at http://www.iana.org.
  873. mnt-by: RIPE-NCC-MNT
  874. created: 1970-01-01T00:00:00Z
  875. last-modified: 2001-09-22T09:31:27Z
  876. source: RIPE # Filtered
  877.  
  878. % This query was served by the RIPE Database Query Service version 1.91.1 (WAGYU)
  879.  
  880.  
  881.  
  882. Gathered Inic-whois information for itrade.gov.il
  883. ---------------------------------
  884. ERROR: Unable to locate Name Whois data on itrade.gov.il
  885.  
  886. Gathered Netcraft information for itrade.gov.il
  887. ---------------------------------
  888.  
  889. Retrieving Netcraft.com information for itrade.gov.il
  890. Netcraft.com Information gathered
  891.  
  892. Gathered Subdomain information for itrade.gov.il
  893. ---------------------------------
  894. Searching Google.com:80...
  895. HostName:www.itrade.gov.il
  896. HostIP:185.241.4.166
  897. Searching Altavista.com:80...
  898. Found 1 possible subdomain(s) for host itrade.gov.il, Searched 0 pages containing 0 results
  899.  
  900. Gathered E-Mail information for itrade.gov.il
  901. ---------------------------------
  902. Searching Google.com:80...
  903. Searching Altavista.com:80...
  904. Found 0 E-Mail(s) for host itrade.gov.il, Searched 0 pages containing 0 results
  905.  
  906. Gathered TCP Port information for 107.178.254.36
  907. ---------------------------------
  908.  
  909. Port State
  910.  
  911. 43/tcp open
  912. 80/tcp open
  913. 110/tcp open
  914. 143/tcp open
  915.  
  916. Portscan Finished: Scanned 150 ports, 0 ports were in state closed
  917. #######################################################################################################################################
  918. [i] Scanning Site: http://itrade.gov.il
  919.  
  920.  
  921.  
  922. B A S I C I N F O
  923. ====================
  924.  
  925.  
  926. [+] Site Title:
  927. [+] IP address: 107.178.254.36
  928. [+] Web Server: nginx
  929. [+] CMS: Could Not Detect
  930. [+] Cloudflare: Not Detected
  931. [+] Robots File: Could NOT Find robots.txt!
  932.  
  933.  
  934.  
  935.  
  936. W H O I S L O O K U P
  937. ========================
  938.  
  939.  
  940. % The data in the WHOIS database of the .il registry is provided
  941. % by ISOC-IL for information purposes, and to assist persons in
  942. % obtaining information about or related to a domain name
  943. % registration record. ISOC-IL does not guarantee its accuracy.
  944. % By submitting a WHOIS query, you agree that you will use this
  945. % Data only for lawful purposes and that, under no circumstances
  946. % will you use this Data to: (1) allow, enable, or otherwise
  947. % support the transmission of mass unsolicited, commercial
  948. % advertising or solicitations via e-mail (spam);
  949. % or (2) enable high volume, automated, electronic processes that
  950. % apply to ISOC-IL (or its systems).
  951. % ISOC-IL reserves the right to modify these terms at any time.
  952. % By submitting this query, you agree to abide by this policy.
  953.  
  954. % No data was found to match the request criteria.
  955.  
  956.  
  957. % Rights to the data above are restricted by copyright.
  958.  
  959.  
  960.  
  961.  
  962. G E O I P L O O K U P
  963. =========================
  964.  
  965. [i] IP Address: 107.178.254.36
  966. [i] Country: US
  967. [i] State: California
  968. [i] City: Mountain View
  969. [i] Latitude: 37.419201
  970. [i] Longitude: -122.057404
  971.  
  972.  
  973.  
  974.  
  975. H T T P H E A D E R S
  976. =======================
  977.  
  978.  
  979. [i] HTTP/1.0 301 Moved Permanently
  980. [i] Server: nginx
  981. [i] Date: Sun, 08 Apr 2018 00:56:38 GMT
  982. [i] Content-Type: text/html
  983. [i] Content-Length: 178
  984. [i] Location: http://www.itrade.gov.il/
  985. [i] Via: 1.1 google
  986. [i] HTTP/1.1 200 OK
  987. [i] Server: Reblaze Secure Web Gateway
  988. [i] Date: Sun, 08 Apr 2018 00:56:39 GMT
  989. [i] Content-Type: text/html; charset=utf-8
  990. [i] Content-Length: 86405
  991. [i] Connection: close
  992. [i] Vary: Accept-Encoding
  993. [i] expires: Thu, 01 Jan 1970 00:01:48 GMT
  994. [i] Cache-Control: no-cache, private, no-transform, no-store
  995. [i] Pragma: no-cache
  996. [i] P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
  997.  
  998.  
  999.  
  1000.  
  1001. D N S L O O K U P
  1002. ===================
  1003.  
  1004. ;; Truncated, retrying in TCP mode.
  1005. itrade.gov.il. 600 IN A 107.178.254.36
  1006.  
  1007.  
  1008.  
  1009.  
  1010. S U B N E T C A L C U L A T I O N
  1011. ====================================
  1012.  
  1013. Address = 107.178.254.36
  1014. Network = 107.178.254.36 / 32
  1015. Netmask = 255.255.255.255
  1016. Broadcast = not needed on Point-to-Point links
  1017. Wildcard Mask = 0.0.0.0
  1018. Hosts Bits = 0
  1019. Max. Hosts = 1 (2^0 - 0)
  1020. Host Range = { 107.178.254.36 - 107.178.254.36 }
  1021.  
  1022.  
  1023.  
  1024. N M A P P O R T S C A N
  1025. ============================
  1026.  
  1027.  
  1028. Starting Nmap 7.01 ( https://nmap.org ) at 2018-04-08 00:56 UTC
  1029. Nmap scan report for itrade.gov.il (107.178.254.36)
  1030. Host is up (0.0021s latency).
  1031. rDNS record for 107.178.254.36: 36.254.178.107.bc.googleusercontent.com
  1032. PORT STATE SERVICE VERSION
  1033. 21/tcp filtered ftp
  1034. 22/tcp filtered ssh
  1035. 23/tcp filtered telnet
  1036. 25/tcp open tcpwrapped
  1037. 80/tcp open http nginx
  1038. 110/tcp open tcpwrapped
  1039. 143/tcp open tcpwrapped
  1040. 443/tcp open tcpwrapped
  1041. 445/tcp filtered microsoft-ds
  1042. 3389/tcp open tcpwrapped
  1043.  
  1044. Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  1045. Nmap done: 1 IP address (1 host up) scanned in 8.46 seconds
  1046. ######################################################################################################################################
  1047. Original* itrade.gov.il 107.178.254.36
  1048. #####################################################################################################################################
  1049. [*] Processing domain itrade.gov.il
  1050. [+] Getting nameservers
  1051. [-] Getting nameservers failed
  1052. [-] Zone transfer failed
  1053.  
  1054. [*] Scanning itrade.gov.il for A records
  1055. 107.178.254.36 - itrade.gov.il
  1056. 185.241.6.89 - www.itrade.gov.il
  1057. #######################################################################################################################################
  1058. Ip Address Status Type Domain Name Server
  1059. ---------- ------ ---- ----------- ------
  1060. 185.241.6.243 200 alias www.itrade.gov.il Reblaze Secure Web Gateway
  1061. 185.241.6.243 200 alias itrade-gov-il.cloudwm-waf.com Reblaze Secure Web Gateway
  1062. 185.241.6.243 200 host geo.cloudwm-waf.com Reblaze Secure Web Gateway
  1063. #######################################################################################################################################
  1064. Anonymous Operation Israel JTSEC full recon 2018 #18
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement