Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- UNITED NATIONS (UN) - Primary Citrix Application Firewall Leaked
- (Robots/TLS-SSL Keys/AdminFolders and etc...)
- This Firewall Behind the Checkpoint Firewall..!!!
- The United Nations (UN) is an international organization whose stated aims are facilitating cooperation in international law, international security, economic development, social progress, human rights, and achievement of world peace. The UN was founded in 1945 after World War II to replace the League of Nations, to stop wars between countries, and to provide a platform for dialogue. It contains multiple subsidiary organizations to carry out its missions.
- http://www.un.org
- THIS ATTACK AGAINST THE DIRTIEST THINGS AGAINST THE SRI LANKA BY UN .........!!!!!
- EXCLUSIVE FROM - Anonymous Sri Lanka
- WWW.UN.ORG -----> Fuck3D and Bust3D
- Primary 157.150.34.32 Server Hacked and
- with Transferring (Data Leak)....!!
- Hail to Anonymous, Lulzsec and Operation Anti-Sec...
- 21/tcp open ftp syn-ack Check Point Firewall-1 ftpd
- | ftp-anon: Anonymous FTP login allowed (FTP code 200)
- | Can't get directory listing: Can't parse PASV response: "Access denied - wrong user name or password \
- |_aborted"
- | banner: 220 Check Point FireWall-1 Secure FTP server running on secper0
- |_1
- | ftp-brute:
- |_ ERROR: Login didn't return a proper response
- 22/tcp closed ssh reset
- 23/tcp filtered telnet no-response
- 25/tcp closed smtp reset
- 80/tcp open http-proxy syn-ack Citrix Application Firewall
- |_unusual-port: http-proxy unexpected on port tcp/80
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- | http-affiliate-id:
- |_ Google Analytics ID: UA-4803886-1
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-malware-host: Host appears to be clean
- |_http-apache-negotiation: mod_negotiation enabled.
- | http-methods: GET HEAD OPTIONS TRACE
- | Potentially risky methods: TRACE
- |_See http://nmap.org/nsedoc/scripts/http-methods.html
- | http-php-version: Logo query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- |_Credits query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- | http-robots.txt: 10 disallowed entries
- | /womenwatch/daw/conf/seforms/l123/d123
- | /wcm/administration/ /wcm/administrator/ /wcm/ajaxaction/
- |_/russian/news/mobile/ /common/ /temp/ /temp1/ /temp2/ /test/
- | http-headers:
- | Content-Type: text/html
- | Content-Length: -1
- | Date: Wed, 29 Feb 2012 09:20:24 GMT
- | Server: Apache/Not telling (Unix) AuthTDS/1.1
- |
- |_ (Request type: HEAD)
- |_http-date: Wed, 29 Feb 2012 09:20:34 GMT; +56s from local time.
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- |_http-favicon: Unknown favicon MD5: 7ECBB71944F5F183EEB12F80D55D861D
- |_http-userdir-enum: Didn't find any users!
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 110/tcp closed pop3 reset
- 139/tcp filtered netbios-ssn no-response
- 443/tcp open ssl/http-proxy syn-ack Citrix Application Firewall
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- |_unusual-port: http-proxy unexpected on port tcp/443
- | http-methods: GET HEAD OPTIONS TRACE
- | Potentially risky methods: TRACE
- |_See http://nmap.org/nsedoc/scripts/http-methods.html
- |_http-default-accounts: [ERROR] HTTP request table is empty. This should not happen since we at least made one request.
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-apache-negotiation: mod_negotiation enabled.
- |_http-malware-host: Host appears to be clean
- | http-headers:
- | Date: Wed, 29 Feb 2012 09:19:55 GMT
- | Server: Apache/Not telling (Unix) AuthTDS/1.1
- | Content-Type: text/html
- | Keep-Alive: timeout=5, max=96
- | Connection: Keep-Alive
- |
- |_ (Request type: HEAD)
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- | ssl-cert: Subject: commonName=*.un.org/organizationName=United Nations/stateOrProvinceName=New York/countryName=US/streetAddress=24-01 44th Road, 9th Floor/localityName=Long Island City/postalCode=11101-4605/organizationalUnitName=Comodo PremiumSSL Wildcard
- | Issuer: commonName=UTN-USERFirst-Hardware/organizationName=The USERTRUST Network/stateOrProvinceName=UT/countryName=US/localityName=Salt Lake City/organizationalUnitName=http://www.usertrust.com
- | Public Key type: rsa
- | Public Key bits: 2048
- | Not valid before: 2011-02-02 00:00:00
- | Not valid after: 2013-04-13 23:59:59
- | MD5: 7920 a56a 7a80 873f 2303 98fd 5711 4c72
- | SHA-1: 3829 64d1 30e8 d182 52e7 65b8 5c41 5de1 0470 a249
- | -----BEGIN CERTIFICATE-----
- | MIIGBzCCBO+gAwIBAgIQGSM5lIzygwVgvQZH7nphlDANBgkqhkiG9w0BAQUFADCB
- | lzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
- | Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExho
- | dHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xHzAdBgNVBAMTFlVUTi1VU0VSRmlyc3Qt
- | SGFyZHdhcmUwHhcNMTEwMjAyMDAwMDAwWhcNMTMwNDEzMjM1OTU5WjCCAQsxCzAJ
- | BgNVBAYTAlVTMRMwEQYDVQQREwoxMTEwMS00NjA1MREwDwYDVQQIEwhOZXcgWW9y
- | azEZMBcGA1UEBxMQTG9uZyBJc2xhbmQgQ2l0eTEjMCEGA1UECRMaMjQtMDEgNDR0
- | aCBSb2FkLCA5dGggRmxvb3IxFzAVBgNVBAoTDlVuaXRlZCBOYXRpb25zMQ0wCwYD
- | VQQLEwRPSUNUMTQwMgYDVQQLEytJc3N1ZWQgdGhyb3VnaCBVbml0ZWQgTmF0aW9u
- | cyBFLVBLSSBNYW5hZ2VyMSMwIQYDVQQLExpDb21vZG8gUHJlbWl1bVNTTCBXaWxk
- | Y2FyZDERMA8GA1UEAxQIKi51bi5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
- | ggEKAoIBAQCs1eE0bZ1LBeAYBybTC5K4D7p7jpOvfMqH8uWU5XUz5mD2t8ZuZ/gk
- | AL3Te23ev32e8bKPkSYym9VgLNZ5CQbh+DG4y6lQNY0kaokMRSYGMhQG8mdUEkcg
- | u4lvd3V1VZ6HeppcO7ufgn3RbpTSLcgKRlm9UABQmYxZ0nmwW6z9IeGgKPoHn+18
- | G8HgFuMx4N0+vAbPvuhrurzb3OfWFsj2qE0R3PHtbZ/4lUCB54SG7LtNfsDeqzhp
- | rlHoD6OB25V1/t5Mt4K38PRa1i52G6J+KcuexxslfS3Kv67eNFik6t3lR3MPDSGw
- | Vtw1ATyTNW5aHrkq84AbZAKzMi9O7HzxAgMBAAGjggHWMIIB0jAfBgNVHSMEGDAW
- | gBShcl8mGyiYQ5VdBzfVhZadS9LDRTAdBgNVHQ4EFgQUHdeek2FzeALWh9EDbE8s
- | xfGb4uQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYI
- | KwYBBQUHAwEGCCsGAQUFBwMCMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQMEMCsw
- | KQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNvbW9kby5jb20vQ1BTMHsGA1Ud
- | HwR0MHIwOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmly
- | c3QtSGFyZHdhcmUuY3JsMDagNKAyhjBodHRwOi8vY3JsLmNvbW9kby5uZXQvVVRO
- | LVVTRVJGaXJzdC1IYXJkd2FyZS5jcmwwcQYIKwYBBQUHAQEEZTBjMDsGCCsGAQUF
- | BzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNvbS9VVE5BZGRUcnVzdFNlcnZlckNB
- | LmNydDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2EuY29tMBsGA1Ud
- | EQQUMBKCCCoudW4ub3JnggZ1bi5vcmcwDQYJKoZIhvcNAQEFBQADggEBAG9ajQJE
- | fC4XCmsdUD0HQ+5PNO1YtusPQD9I7zOgf6c25TMeu7PCblYH7nZq5NiiglchRX6a
- | VowALfIqjXyEWTDlq94y7JKtv/B62GU1dX7lvNoPS80/e1MzZCzkGa1hHZjiQL7r
- | kFoSmHeRr8A+fIjJZ85o7x2Y6qZJcjQTtASRAMV4kZEqST+cnRF3Pz8WnGKlFwFn
- | aUXH/t/MDgQbpa0+tKIg8dAP3Tb43r4051Rius6zOhS5PYOmo4MsBiKOVXHZnT15
- | vHiNtnSrtsKkxE3xGI7d9x5CC/BLnp8edK5cneCK39+MZFmJmvMFxXwiaIDCiWGx
- | vhwke7E0HzImDls=
- |_-----END CERTIFICATE-----
- |_http-favicon: Unknown favicon MD5: 7ECBB71944F5F183EEB12F80D55D861D
- | http-robots.txt: 10 disallowed entries
- | /womenwatch/daw/conf/seforms/l123/d123
- | /wcm/administration/ /wcm/administrator/ /wcm/ajaxaction/
- |_/russian/news/mobile/ /common/ /temp/ /temp1/ /temp2/ /test/
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- | http-trace: TRACE is enabled
- | Headers:
- | Date: Wed, 29 Feb 2012 09:21:01 GMT
- | Server: Apache/Not telling (Unix) AuthTDS/1.1
- | Content-Type: message/http
- | Keep-Alive: timeout=5, max=38
- | Connection: Keep-Alive
- |_Transfer-Encoding: chunked
- | http-affiliate-id:
- |_ Google Analytics ID: UA-4803886-1
- |_http-date: Wed, 29 Feb 2012 09:21:05 GMT; +1m27s from local time.
- |_http-userdir-enum: Didn't find any users!
- | http-php-version: Logo query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- |_Credits query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- | ssl-enum-ciphers:
- | SSLv3
- | Ciphers (3)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- | TLSv1.0
- | Ciphers (5)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - unknown strength
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- |_ Least strength = unknown strength
- | ssl-google-cert-catalog:
- |_ No DB entry
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 445/tcp filtered microsoft-ds no-response
- 3389/tcp filtered ms-term-serv no-response
- Network Distance: 2 hops
- TCP Sequence Prediction: Difficulty=261
- IP ID Sequence Generation: Incremental
- Service Info: Device: firewall
- Host script results:
- | dns-blacklist:
- | PROXY
- | dnsbl.ahbl.org - FAIL
- | socks.dnsbl.sorbs.net - FAIL
- | http.dnsbl.sorbs.net - FAIL
- | misc.dnsbl.sorbs.net - FAIL
- | dnsbl.tornevall.org - FAIL
- | SPAM
- | dnsbl.ahbl.org - FAIL
- | dnsbl.inps.de - FAIL
- | bl.nszones.com - FAIL
- | l2.apews.org - FAIL
- | list.quorum.to - FAIL
- | all.spamrats.com - FAIL
- | bl.spamcop.net - FAIL
- | spam.dnsbl.sorbs.net - FAIL
- |_ sbl.spamhaus.org - FAIL
- |_dns-brute: Can't guess domain of "157.150.34.32"; use dns-brute.domain script argument.
- | dns-zeustracker:
- |_ ERROR: DNS Query failed
- |_asn-query: No Servers
- |_path-mtu: PMTU == 1500
- | firewalk:
- | HOP HOST PROTOCOL BLOCKED PORTS
- |_1 127.0.0.1 tcp 23,139,445,3389
- |_whois: See the result for 157.150.185.0.
- |_ipidseq: Unknown [used port 21]
- | ip-geolocation-geoplugin:
- | 157.150.34.32
- | coordinates (lat,lon): 40.752799987793,-73.972503662109
- |_ state: New York, United States
- | ip-geolocation-geobytes:
- | 157.150.34.32
- | coordinates (lat,lon): 40.7488,-73.9846
- |_ city: New York, New York, United States
- |_hostmap: Error: found no hostnames but not the marker for "no hostnames found" (pattern error?)
- | qscan:
- | PORT FAMILY MEAN (us) STDDEV LOSS (%)
- | 21 0 370251.10 16504.59 0.0%
- | 22 1 2194909.70 76813.97 0.0%
- | 80 0 391551.70 74399.35 0.0%
- |_443 0 397059.20 90980.39 0.0%
- New targets in the scanned cache: 0, pending ones: 0.
- Post-scan script results:
- | http-affiliate-id: Possible related sites
- | Google Analytics ID: UA-4803886-1 used by:
- | 157.150.34.32:80/
- | 157.150.34.32:443/
- | 157.150.185.49:443/
- |_ 157.150.185.49:80/
- | reverse-index:
- | 21/tcp: 157.150.185.49, 157.150.34.32
- | 80/tcp: 157.150.185.49, 157.150.34.32
- |_ 443/tcp: 157.150.185.49, 157.150.34.32
RAW Paste Data