LynchOptre

#OpW.P.cz/ #GoC

Aug 18th, 2016
242
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 18.89 KB | None | 0 0
  1. Hello, all information under this is information about http://www.policie.cz/.
  2. ------------------------------------------------------------------------------
  3. 1. Private IP Disclosure > Attack: 10-22-23-24,(25) @InternalSystem.#Attacks^
  4. > CWE Id> 200
  5. > WASC Id> 13
  6. 2. Password Autocomplete in browser (3)> Heslo:</label>
  7. <input type="password" id="loginpass" style="width:150px; />
  8.  
  9. 3. Cross-Domain JavaScript Source File Inclusion> Paramater:>http://www.google-analytics.com/unrchin.js
  10. (Http://www.policie.cz/ are not the host over their own scripts)
  11.  
  12. 4. Cookie Set Without HttpOnly Flag> Parameter:> BF=1; path=/
  13.  
  14. 5. X-Frame-Options Header Not Set: (8250) That do not protect against ClickJacking Attack.
  15. Here is 10 of them>
  16. >http://www.policie.cz/-105-odst-3-zak-c-183-2006-sb-.aspx
  17. >http://www.policie.cz/-11-odst-3-pism-b-zak-c-111-1994-sb-.aspx
  18. >http://www.policie.cz/-122-odst-1-zak-c-183-2006-sb-.aspx
  19. >http://www.policie.cz/-124-odst-9-pism-e-zak-c-361-2000-sb.aspx
  20. >http://www.policie.cz/-15-odst-2-zak-c-13-1997-sb-.aspx
  21. >http://www.policie.cz/-16-odst-1-zak-c-13-1997-sb-.aspx
  22. >http://www.policie.cz/-15-zak-c-273-2008-sb-.aspx
  23. >http://www.policie.cz/-18c-odst-2-zak-c-111-1994-sb-.aspx
  24. >http://www.policie.cz/-29-odst-2-zak-c-13-1997-sb-.aspx
  25. >http://www.policie.cz/-37-odst-1-zak-c-13-1997-sb-.aspx
  26. 6. Web Browser XSS Protection Not enabled:> Enable>: X-XSS-Protection: 1; mode=block
  27. :> Disable> X-XSS-Protection: 0
  28. 7. X-Content-Type-Options Header Missing:> (8546)</>:; The Anti-MIME-Sniffing header X-Content-Type-Options was not set to 'nosniff'. This allows older versions of Internet Explorer and Chrome to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the declared content type. Current (early 2014) and legacy versions of Firefox will use the declared content type (if one is set), rather than performing MIME-sniffing.
  29.  
  30. 8. Other Information Such As Dic,Host,Server<ip Address>:/ External Hosts : Emails > and Etc.:>>> unexpected ACK for data ID 39f8e029080ccf5e1e2d611251143e3f from plugin testing... and too policie.cz
  31.  
  32. :>>>: ;J
  33. | Domain: http://www.policie.cz/
  34. | Server: MVCR
  35. | IP: 94.199.40.226
  36. ===================================================================================================
  37. |
  38. | Directory check:
  39. | [+] CODE: 200 URL: http://www.policie.cz/Javascript/
  40. | [+] CODE: 200 URL: http://www.policie.cz/aux/
  41. | [+] CODE: 200 URL: http://www.policie.cz/clientscript/
  42. | [+] CODE: 200 URL: http://www.policie.cz/ghostscript/
  43. | [+] CODE: 200 URL: http://www.policie.cz/javascript/
  44. | [+] CODE: 200 URL: http://www.policie.cz/jscript/
  45. | [+] CODE: 200 URL: http://www.policie.cz/istyles/
  46. | [+] CODE: 200 URL: http://www.policie.cz/kariera/
  47. | [+] CODE: 200 URL: http://www.policie.cz/kontakty/
  48. | [+] CODE: 200 URL: http://www.policie.cz/vbscript/
  49. | [+] CODE: 200 URL: http://www.policie.cz/webdesign/
  50. ===================================================================================================
  51. |
  52. | File check:
  53. | [+] CODE: 200 URL: http://www.policie.cz/default.aspx
  54. | [+] CODE: 200 URL: http://www.policie.cz/favicon.ico
  55. | [+] CODE: 200 URL: http://www.policie.cz/install/install.aspx
  56. | [+] CODE: 200 URL: http://www.policie.cz/junk.aspx
  57. | [+] CODE: 200 URL: http://www.policie.cz/lpt9
  58. | [+] CODE: 200 URL: http://www.policie.cz/maint.aspx
  59. | [+] CODE: 200 URL: http://www.policie.cz/maintenance.aspx
  60. | [+] CODE: 200 URL: http://www.policie.cz/login.aspx
  61. | [+] CODE: 200 URL: http://www.policie.cz/robots.txt
  62. | [+] CODE: 200 URL: http://www.policie.cz/trace.axd
  63. | [+] CODE: 200 URL: http://www.policie.cz/test.aspx
  64. | [+] CODE: 200 URL: http://www.policie.cz/test
  65. ===================================================================================================
  66. |
  67. | Check robots.txt:
  68. | [+] User-agent: *
  69. | [+] Disallow: /appEmpty.aspx
  70. | [+] Disallow: /req.aspx
  71. | [+] Disallow: /saveStats.aspx
  72.  
  73.  
  74. | E-mails:
  75. | [+] E-mail Found: uskpv.op.pamatky@pcr.cz
  76. | [+] E-mail Found: krpc.pio@pcr.cz
  77. | [+] E-mail Found: krpl.kr.tiskove@pcr.cz
  78. | [+] E-mail Found: muzeum@mvcr.cz
  79. | [+] E-mail Found: unitop@policie-sport.cz
  80. | [+] E-mail Found: epodatelna.policie@pcr.cz
  81. | [+] E-mail Found: pobyty@mvcr.cz
  82. | [+] E-mail Found: webmaster@pcr.cz
  83. | [+] E-mail Found: pio@policievysocina.cz
  84. | [+] E-mail Found: krpb.tisk@pcr.cz
  85. | [+] E-mail Found: krph.tisk@pcr.cz
  86. | [+] E-mail Found: krpa.tisk@pcr.cz
  87. | [+] E-mail Found: pp.tisk@pcr.cz
  88. | [+] E-mail Found: krpulk.kr.pio@pcr.cz
  89. | [+] E-mail Found: krps.kr.pio@pcr.cz
  90. | [+] E-mail Found: pp.oo.operacni@pcr.cz
  91. | [+] E-mail Found: pp.rscp.sekretariat@pcr.cz
  92. | [+] E-mail Found: ncoz.sekretariat@pcr.cz
  93. | [+] E-mail Found: ku@pcr.cz
  94. | [+] E-mail Found: ipacz@seznam.cz
  95. | [+] E-mail Found: krpe.tisk@pcr.cz
  96. | [+] E-mail Found: npc@pcr.cz
  97. | [+] E-mail Found: udv@pcr.cz
  98. | [+] E-mail Found: krpk@pcr.cz
  99. | [+] E-mail Found: krpp.tisk.plzen.kraj@pcr.cz
  100. | [+] E-mail Found: krpz.pio@pcr.cz
  101. | [+] E-mail Found: krpt.pio@pcr.cz
  102. | [+] E-mail Found: pp.ovk@pcr.cz
  103. | [+] E-mail Found: krpm.pio@pcr.cz
  104. |
  105.  
  106. |
  107. | External hosts:
  108. | [+] External Host Found: http://www.google-analytics.com
  109. | [+] External Host Found: http://www.eumostwanted.eu
  110. | [+] External Host Found: http://aplikace.policie.cz
  111. | [+] External Host Found: http://maps.google.cz
  112. | [+] External Host Found: http://www.ipacz.cz
  113. | [+] External Host Found: http://www.mvcr.cz
  114. | [+] External Host Found: http://www.brno-circuit.com
  115. | [+] External Host Found: http://aplikace.mvcr.cz
  116. | [+] External Host Found: http://www.muzeumpolicie.cz
  117. | [+] External Host Found: http://www.dpmb.cz
  118. | [+] External Host Found: http://pseud.policie.cz
  119.  
  120. 9. From Web Browser XSS Protection Not Enabled: > : O
  121. *q. http://www.policie.cz/SCRIPT/ViewFile.aspx?docid=22149375
  122. W. http://www.policie.cz/SCRIPT/ViewImage.aspx?docid=21267725
  123. e. http://www.policie.cz/SCRIPT/ViewImage.aspx?docid=53738
  124.  
  125. 10. <script>alert("Message from Guardians Of The Cyber World");</script>
  126.  
  127. (Starting Nmap 6.47 ( http://nmap.org ) at 2016-08-18 15:48 CEST NSE: Loaded 240 scripts for scanning. NSE: Script Pre-scanning. Initiating NSE at 15:48 NSE: mtrace: A source IP must be provided through fromip argument. Completed NSE at 15:48, 10.88s elapsed Pre-scan script results: | broadcast-eigrp-discovery: |_ ERROR: Couldn't get an A.S value. | broadcast-igmp-discovery: | 192.168.91.1 | Interface: eth0 | Version: 2 | Group: 224.0.0.252 | Description: Link-local Multicast Name Resolution (rfc4795) | 192.168.91.1 | Interface: eth0 | Version: 2 | Group: 239.255.255.250 | Description: Organization-Local Scope (rfc2365) |_ Use the newtargets script-arg to add the results as targets | broadcast-ping: | IP: 192.168.91.2 MAC: 00:50:56:f1:7c:ed |_ Use --script-args=newtargets to add the results as targets | http-icloud-findmyiphone: |_ ERROR: No username or password was supplied | http-icloud-sendmsg: |_ ERROR: No username or password was supplied | targets-asn: |_ targets-asn.asn is a mandatory parameter Initiating Ping Scan at 15:48 Scanning 94.199.40.226 [7 ports] Completed Ping Scan at 15:48, 1.49s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 15:48 Completed Parallel DNS resolution of 1 host. at 15:48, 0.03s elapsed Initiating SYN Stealth Scan at 15:48 Scanning host-94-199-40-226.gov.cz (94.199.40.226) [1000 ports] Discovered open port 80/tcp on 94.199.40.226 SYN Stealth Scan Timing: About 39.05% done; ETC: 15:49 (0:00:48 remaining) SYN Stealth Scan Timing: About 40.15% done; ETC: 15:51 (0:01:31 remaining) SYN Stealth Scan Timing: About 41.25% done; ETC: 15:52 (0:02:10 remaining) SYN Stealth Scan Timing: About 42.35% done; ETC: 15:53 (0:02:46 remaining) Increasing send delay for 94.199.40.226 from 0 to 5 due to 11 out of 17 dropped probes since last increase. SYN Stealth Scan Timing: About 43.45% done; ETC: 15:54 (0:03:18 remaining) SYN Stealth Scan Timing: About 44.55% done; ETC: 15:55 (0:03:47 remaining) SYN Stealth Scan Timing: About 45.60% done; ETC: 15:56 (0:04:13 remaining) SYN Stealth Scan Timing: About 46.80% done; ETC: 15:57 (0:04:39 remaining) Increasing send delay for 94.199.40.226 from 5 to 10 due to 11 out of 11 dropped probes since last increase. SYN Stealth Scan Timing: About 48.20% done; ETC: 15:58 (0:05:05 remaining) SYN Stealth Scan Timing: About 50.15% done; ETC: 15:59 (0:05:36 remaining) SYN Stealth Scan Timing: About 53.05% done; ETC: 16:01 (0:06:11 remaining) SYN Stealth Scan Timing: About 61.05% done; ETC: 16:06 (0:06:51 remaining) adjust_timeouts2: packet supposedly had rtt of 9006656 microseconds. Ignoring time. adjust_timeouts2: packet supposedly had rtt of 9006656 microseconds. Ignoring time. SYN Stealth Scan Timing: About 46.97% done; ETC: 16:20 (0:17:01 remaining) Warning: 94.199.40.226 giving up on port because retransmission cap hit (6). SYN Stealth Scan Timing: About 56.34% done; ETC: 16:16 (0:12:04 remaining) SYN Stealth Scan Timing: About 75.00% done; ETC: 16:09 (0:05:21 remaining) SYN Stealth Scan Timing: About 88.60% done; ETC: 16:07 (0:02:08 remaining) RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 RTTVAR has grown to over 2.3 seconds, decreasing to 2.0 Completed SYN Stealth Scan at 16:07, 1131.09s elapsed (1000 total ports) Initiating UDP Scan at 16:07 Scanning host-94-199-40-226.gov.cz (94.199.40.226) [1000 ports] UDP Scan Timing: About 3.00% done; ETC: 16:24 (0:16:42 remaining) UDP Scan Timing: About 4.40% done; ETC: 16:30 (0:22:05 remaining) UDP Scan Timing: About 5.95% done; ETC: 16:32 (0:23:58 remaining) UDP Scan Timing: About 7.20% done; ETC: 16:35 (0:26:00 remaining) Increasing send delay for 94.199.40.226 from 0 to 50 due to 11 out of 20 dropped probes since last increase. Increasing send delay for 94.199.40.226 from 50 to 100 due to 11 out of 22 dropped probes since last increase. UDP Scan Timing: About 22.65% done; ETC: 16:39 (0:24:32 remaining) UDP Scan Timing: About 29.00% done; ETC: 16:39 (0:22:56 remaining) Increasing send delay for 94.199.40.226 from 100 to 200 due to 11 out of 20 dropped probes since last increase. UDP Scan Timing: About 35.10% done; ETC: 16:40 (0:21:16 remaining) Increasing send delay for 94.199.40.226 from 200 to 400 due to 11 out of 20 dropped probes since last increase. UDP Scan Timing: About 41.50% done; ETC: 16:40 (0:19:33 remaining) UDP Scan Timing: About 46.70% done; ETC: 16:40 (0:17:49 remaining) Increasing send delay for 94.199.40.226 from 400 to 800 due to 11 out of 19 dropped probes since last increase. UDP Scan Timing: About 52.45% done; ETC: 16:41 (0:16:06 remaining) Increasing send delay for 94.199.40.226 from 800 to 1000 due to 11 out of 21 dropped probes since last increase. UDP Scan Timing: About 58.05% done; ETC: 16:41 (0:14:24 remaining) UDP Scan Timing: About 63.75% done; ETC: 16:42 (0:12:40 remaining) UDP Scan Timing: About 69.35% done; ETC: 16:43 (0:10:55 remaining) UDP Scan Timing: About 74.70% done; ETC: 16:43 (0:09:07 remaining) UDP Scan Timing: About 79.95% done; ETC: 16:43 (0:07:18 remaining) UDP Scan Timing: About 85.10% done; ETC: 16:44 (0:05:28 remaining) UDP Scan Timing: About 90.20% done; ETC: 16:44 (0:03:37 remaining) UDP Scan Timing: About 95.40% done; ETC: 16:44 (0:01:43 remaining) Completed UDP Scan at 16:44, 2251.03s elapsed (1000 total ports) Initiating Service scan at 16:44 Scanning 1001 services on host-94-199-40-226.gov.cz (94.199.40.226) Service scan Timing: About 0.40% done Service scan Timing: About 3.10% done; ETC: 18:14 (1:26:34 remaining) Service scan Timing: About 6.09% done; ETC: 17:53 (1:03:57 remaining) Service scan Timing: About 9.09% done; ETC: 17:45 (0:55:20 remaining) Service scan Timing: About 12.09% done; ETC: 17:42 (0:50:11 remaining) Service scan Timing: About 15.08% done; ETC: 17:39 (0:46:38 remaining) Service scan Timing: About 18.08% done; ETC: 17:38 (0:43:48 remaining) Service scan Timing: About 23.88% done; ETC: 17:31 (0:35:30 remaining) Service scan Timing: About 24.08% done; ETC: 17:36 (0:39:13 remaining) Service scan Timing: About 29.77% done; ETC: 17:31 (0:32:45 remaining) Service scan Timing: About 30.07% done; ETC: 17:35 (0:35:19 remaining) Service scan Timing: About 35.76% done; ETC: 17:31 (0:29:54 remaining) Service scan Timing: About 41.76% done; ETC: 17:31 (0:27:06 remaining) Service scan Timing: About 47.75% done; ETC: 17:31 (0:24:16 remaining) Service scan Timing: About 53.75% done; ETC: 17:31 (0:21:28 remaining) Service scan Timing: About 59.74% done; ETC: 17:31 (0:18:40 remaining) Service scan Timing: About 65.73% done; ETC: 17:31 (0:15:54 remaining) Service scan Timing: About 71.63% done; ETC: 17:31 (0:13:10 remaining) Service scan Timing: About 77.62% done; ETC: 17:31 (0:10:23 remaining) Service scan Timing: About 83.62% done; ETC: 17:31 (0:07:36 remaining) Service scan Timing: About 89.11% done; ETC: 17:31 (0:05:04 remaining) Service scan Timing: About 95.10% done; ETC: 17:31 (0:02:17 remaining) Completed Service scan at 17:31, 2817.27s elapsed (1001 services on 1 host) Initiating OS detection (try #1) against host-94-199-40-226.gov.cz (94.199.40.226) Initiating Traceroute at 17:32 Completed Traceroute at 17:32, 1.50s elapsed Initiating Parallel DNS resolution of 2 hosts. at 17:32 Completed Parallel DNS resolution of 2 hosts. at 17:32, 0.17s elapsed NSE: Script scanning 94.199.40.226. Initiating NSE at 17:32 NSE Timing: About 1.57% done; ETC: 18:05 (0:32:18 remaining) NSE Timing: About 3.94% done; ETC: 17:58 (0:24:48 remaining) NSE Timing: About 7.66% done; ETC: 17:53 (0:19:29 remaining) NSE Timing: About 9.18% done; ETC: 17:55 (0:20:56 remaining) NSE Timing: About 9.64% done; ETC: 18:00 (0:24:32 remaining) NSE Timing: About 13.45% done; ETC: 17:56 (0:20:22 remaining) NSE Timing: About 15.91% done; ETC: 17:58 (0:21:46 remaining) NSE Timing: About 19.55% done; ETC: 17:56 (0:19:13 remaining) NSE Timing: About 26.09% done; ETC: 17:56 (0:17:45 remaining) NSE Timing: About 32.27% done; ETC: 17:56 (0:16:18 remaining) NSE Timing: About 38.18% done; ETC: 17:57 (0:15:05 remaining) NSE Timing: About 44.00% done; ETC: 17:57 (0:13:46 remaining) NSE Timing: About 49.64% done; ETC: 17:57 (0:12:27 remaining) NSE Timing: About 54.55% done; ETC: 17:57 (0:11:11 remaining) NSE Timing: About 59.91% done; ETC: 17:57 (0:09:55 remaining) NSE Timing: About 65.73% done; ETC: 17:57 (0:08:30 remaining) NSE Timing: About 71.55% done; ETC: 17:57 (0:07:05 remaining) NSE Timing: About 77.45% done; ETC: 17:57 (0:05:37 remaining) NSE Timing: About 83.18% done; ETC: 17:57 (0:04:13 remaining) NSE Timing: About 88.73% done; ETC: 17:58 (0:02:50 remaining) NSE Timing: About 93.73% done; ETC: 17:57 (0:01:34 remaining) Completed NSE at 17:57, 1488.98s elapsed Initiating NSE at 17:57 NSE Timing: About 33.33% done; ETC: 17:59 (0:01:02 remaining) NSE Timing: About 66.67% done; ETC: 17:59 (0:00:30 remaining) Completed NSE at 17:59, 90.00s elapsed Nmap scan report for host-94-199-40-226.gov.cz (94.199.40.226) Host is up (0.54s latency). Not shown: 1000 open|filtered ports, 970 closed ports, 29 filtered ports PORT STATE SERVICE VERSION 80/tcp open http MVCR | http-comments-displayer: | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=host-94-199-40-226.gov.cz | | Path: http://host-94-199-40-226.gov.cz/ | Line number: 39 | Comment: |_ <!-- Ochrana proti spamu na adminovu adresu --> |_http-date: Thu, 18 Aug 2016 15:57:11 GMT; +24m11s from local time. |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api | http-grep: |_ ERROR: Argument http-grep.match was not set | http-headers: | Date: Thu, 18 Aug 2016 15:57:12 GMT | Server: MVCR | Last-Modified: Thu, 27 Sep 2012 09:10:36 GMT | ETag: "20218-a83-4caab4fed1b00" | Accept-Ranges: bytes | Content-Length: 2691 | Connection: close | Content-Type: text/html; charset=UTF-8 | |_ (Request type: GET) | http-methods: GET HEAD POST OPTIONS TRACE | Potentially risky methods: TRACE |_See http://nmap.org/nsedoc/scripts/http-methods.html |_http-mobileversion-checker: No mobile version detected. |_http-referer-checker: Couldn't find any cross-domain scripts. | http-server-header: Software version grabbed from Server header. | Consider submitting a service fingerprint. |_Run with --script-args http-server-header.skip |_http-title: Chyba: Po\xC5\xBEadovan\xC3\xA1 str\xC3\xA1nka nen\xC3\xAD dostupn\xC3\xA1 |_http-trace: TRACE is enabled | http-traceroute: |_ Possible reverse proxy detected. | http-useragent-tester: | | Allowed User Agents: | libwww | lwp-trivial | libcurl-agent/1.0 | PHP/ | Python-urllib/2.5 | GT::WWW | Snoopy | MFC_Tear_Sample | HTTP::Lite | PHPCrawl | URI::Fetch | Zend_Http_Client | http client | PECL::HTTP | Wget/1.13.4 (linux-gnu) | WWW-Mechanize/1.34 |_ |_http-xssed: No previously reported XSS vuln. Device type: general purpose Running: Microsoft Windows 7|XP OS CPE: cpe:/o:microsoft:windows_7:::enterprise cpe:/o:microsoft:windows_xp::sp3 OS details: Microsoft Windows 7 Enterprise, Microsoft Windows XP SP3 Network Distance: 2 hops IP ID Sequence Generation: Incremental Host script results: | asn-query: | BGP: 94.199.40.0/21 | Country: CZ | Origin AS: 48298 - GOVCZ , CZ |_ Peer AS: 21142 | firewalk: | HOP HOST PROTOCOL BLOCKED PORTS | 1 192.168.91.2 tcp 100,880,981,1041,1071,1145,1198,1236,2126,2382 |_ udp 2-3,7,9,13,17,19-22 |_hostmap-robtex: ERROR: Script execution failed (use -d to debug) | ip-geolocation-geoplugin: | 94.199.40.226 | coordinates (lat,lon): 50.0833,14.4667 |_ state: Hlavn&iacute; Mesto Praha, Czech Republic |_ip-geolocation-maxmind: ERROR: Script execution failed (use -d to debug) |_ipidseq: Incremental! |_path-mtu: PMTU == 1500 | qscan: | PORT FAMILY MEAN (us) STDDEV LOSS (%) | 1 0 1301791.10 248436.06 0.0% |_80 1 27614.90 15847.31 0.0% | traceroute-geolocation: | HOP RTT ADDRESS GEOLOCATION | 1 0.36 192.168.91.2 - ,- |_ 2 482.62 host-94-199-40-226.gov.cz (94.199.40.226) 50,14 Czech Republic (Hlavn&iacute; Mesto Praha) |_whois-domain: You should provide a domain name. |_whois-ip: ERROR: Script execution failed (use -d to debug) TRACEROUTE (using port 427/tcp) HOP RTT ADDRESS 1 0.36 ms 192.168.91.2 2 482.62 ms host-94-199-40-226.gov.cz (94.199.40.226) NSE: Script Post-scanning. Read data files from: /usr/bin/../share/nmap OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 7856.27 seconds Raw packets sent: 6114 (241.962KB) | Rcvd: 1238 (49.720KB) )
Add Comment
Please, Sign In to add comment