Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #######################################################################################################################################
- ======================================================================================================================================
- Hostname www.respectwashington.us ISP Hurricane Electric LLC
- Continent North America Flag
- US
- Country United States Country Code US
- Region Unknown Local time 22 Oct 2019 07:53 CDT
- City Unknown Postal Code Unknown
- IP Address 65.49.16.26 Latitude 37.751
- Longitude -97.822
- =======================================================================================================================================
- #######################################################################################################################################
- > www.respectwashington.us
- Server: 185.93.180.131
- Address: 185.93.180.131#53
- Non-authoritative answer:
- www.respectwashington.us canonical name = respectwashington.us.
- Name: respectwashington.us
- Address: 65.49.16.26
- >
- #######################################################################################################################################
- Domain Name: respectwashington.us
- Registry Domain ID: D16560512-US
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: whois.godaddy.com
- Updated Date: 2019-05-17T14:12:02Z
- Creation Date: 2008-05-12T19:02:13Z
- Registry Expiry Date: 2020-05-11T23:59:59Z
- Registrar: GoDaddy.com, Inc.
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: +1.4806242505
- Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
- Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
- Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
- Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
- Registry Registrant ID: C24033066-US
- Registrant Name: B. Keller
- Registrant Organization:
- Registrant Street: PO Box 3786
- Registrant Street:
- Registrant Street:
- Registrant City: Federal Way
- Registrant State/Province: Washington
- Registrant Postal Code: 98063-3786
- Registrant Country: US
- Registrant Phone: +1.2069353505
- Registrant Phone Ext:
- Registrant Fax:
- Registrant Fax Ext:
- Registrant Email: [email protected]
- Registrant Application Purpose: P3
- Registrant Nexus Category: C11
- Registry Admin ID: C24033071-US
- Admin Name: B. Keller
- Admin Organization:
- Admin Street: PO Box 3786
- Admin Street:
- Admin Street:
- Admin City: Federal Way
- Admin State/Province: Washington
- Admin Postal Code: 98063-3786
- Admin Country: US
- Admin Phone: +1.2069353505
- Admin Phone Ext:
- Admin Fax:
- Admin Fax Ext:
- Admin Email: [email protected]
- Admin Application Purpose: P3
- Admin Nexus Category: C11
- Registry Tech ID: C24033068-US
- Tech Name: B. Keller
- Tech Organization:
- Tech Street: PO Box 3786
- Tech Street:
- Tech Street:
- Tech City: Federal Way
- Tech State/Province: Washington
- Tech Postal Code: 98063-3786
- Tech Country: US
- Tech Phone: +1.2069353505
- Tech Phone Ext:
- Tech Fax:
- Tech Fax Ext:
- Tech Email: [email protected]
- Tech Application Purpose: P3
- Tech Nexus Category: C11
- Name Server: ns2.he.net
- Name Server: ns1.he.net
- DNSSEC: unsigned
- ######################################################################################################################################
- [+] Target : www.respectwashington.us
- [+] IP Address : 65.49.16.26
- [+] Headers :
- [+] Date : Tue, 22 Oct 2019 13:02:14 GMT
- [+] Server : Apache/2.4.18 (Ubuntu)
- [+] Last-Modified : Fri, 23 Feb 2018 15:15:28 GMT
- [+] ETag : "8956-565e2a1613be1-gzip"
- [+] Accept-Ranges : bytes
- [+] Vary : Accept-Encoding
- [+] Content-Encoding : gzip
- [+] Content-Length : 11076
- [+] Keep-Alive : timeout=5, max=100
- [+] Connection : Keep-Alive
- [+] Content-Type : text/html
- [+] SSL Certificate Information :
- [+] commonName : respectwashington.us
- [+] countryName : US
- [+] organizationName : Let's Encrypt
- [+] commonName : Let's Encrypt Authority X3
- [+] Version : 3
- [+] Serial Number : 0487DBDE45DC509FE9B4B360E72AAB131161
- [+] Not Before : Sep 23 10:50:34 2019 GMT
- [+] Not After : Dec 22 10:50:34 2019 GMT
- [+] OCSP : ('http://ocsp.int-x3.letsencrypt.org',)
- [+] subject Alt Name : (('DNS', 'keller4america.us'), ('DNS', 'mail.respectwashington.us'), ('DNS', 'respectwashington.us'), ('DNS', 'www.keller4america.us'), ('DNS', 'www.respectwashington.us'))
- [+] CA Issuers : ('http://cert.int-x3.letsencrypt.org/',)
- [+] Whois Lookup :
- [+] NIR : None
- [+] ASN Registry : arin
- [+] ASN : 6939
- [+] ASN CIDR : 65.49.0.0/17
- [+] ASN Country Code : US
- [+] ASN Date : 2007-10-04
- [+] ASN Description : HURRICANE - Hurricane Electric LLC, US
- [+] cidr : 65.49.0.0/17
- [+] name : HURRICANE-9
- [+] handle : NET-65-49-0-0-1
- [+] range : 65.49.0.0 - 65.49.127.255
- [+] description : Hurricane Electric LLC
- [+] country : US
- [+] state : CA
- [+] city : Fremont
- [+] address : 760 Mission Court
- [+] postal_code : 94539
- [+] emails : ['[email protected]', '[email protected]']
- [+] created : 2007-10-04
- [+] updated : 2012-02-24
- [+] Crawling Target...
- [+] Looking for robots.txt........[ Not Found ]
- [+] Looking for sitemap.xml.......[ Not Found ]
- [+] Extracting CSS Links..........[ 1 ]
- [+] Extracting Javascript Links...[ 0 ]
- [+] Extracting Internal Links.....[ 0 ]
- [+] Extracting External Links.....[ 10 ]
- [+] Extracting Images.............[ 3 ]
- [+] Total Links Extracted : 14
- [+] Dumping Links in /opt/FinalRecon/dumps/www.respectwashington.us.dump
- [+] Completed!
- ######################################################################################################################################
- [+] Starting At 2019-10-22 09:02:23.804210
- [+] Collecting Information On: http://www.respectwashington.us/
- [#] Status: 200
- --------------------------------------------------
- [#] Web Server Detected: Apache/2.4.18 (Ubuntu)
- [!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
- - Date: Tue, 22 Oct 2019 13:02:24 GMT
- - Server: Apache/2.4.18 (Ubuntu)
- - Last-Modified: Fri, 23 Feb 2018 15:15:28 GMT
- - ETag: "8956-565e2a1613be1-gzip"
- - Accept-Ranges: bytes
- - Vary: Accept-Encoding
- - Content-Encoding: gzip
- - Content-Length: 11076
- - Keep-Alive: timeout=5, max=100
- - Connection: Keep-Alive
- - Content-Type: text/html
- --------------------------------------------------
- [#] Finding Location..!
- [#] status: success
- [#] country: United States
- [#] countryCode: US
- [#] region: CA
- [#] regionName: California
- [#] city: Fremont
- [#] zip: 94539
- [#] lat: 37.4718
- [#] lon: -121.92
- [#] timezone: America/Los_Angeles
- [#] isp: Hurricane Electric LLC
- [#] org: Hurricane Electric
- [#] as: AS6939 Hurricane Electric LLC
- [#] query: 65.49.16.26
- --------------------------------------------------
- [x] Didn't Detect WAF Presence on: http://www.respectwashington.us/
- --------------------------------------------------
- [#] Starting Reverse DNS
- [-] Failed ! Fail
- --------------------------------------------------
- [!] Scanning Open Port
- [#] 80/tcp open http
- [#] 110/tcp open pop3
- [#] 143/tcp open imap
- [#] 443/tcp open https
- [#] 465/tcp open smtps
- [#] 587/tcp open submission
- [#] 993/tcp open imaps
- [#] 995/tcp open pop3s
- --------------------------------------------------
- [+] Collecting Information Disclosure!
- [#] Detecting sitemap.xml file
- [-] sitemap.xml file not Found!?
- [#] Detecting robots.txt file
- [-] robots.txt file not Found!?
- [#] Detecting GNU Mailman
- [-] GNU Mailman App Not Detected!?
- --------------------------------------------------
- [+] Crawling Url Parameter On: http://www.respectwashington.us/
- --------------------------------------------------
- [#] Searching Html Form !
- [-] No Html Form Found!?
- --------------------------------------------------
- [-] No DOM Paramter Found!?
- --------------------------------------------------
- [-] No internal Dynamic Parameter Found!?
- --------------------------------------------------
- [!] 4 External Dynamic Parameter Discovered
- [#] http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=75bce2e261405110VgnVCM1000004718190aRCRD&vgnextchannel=75bce2e261405110VgnVCM1000004718190aRCRD
- [#] http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=31b3ab0a43b5d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=db029c7755cb9010VgnVCM10000045f3d6a1RCRD
- [#] http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- [#] http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- --------------------------------------------------
- [!] 23 Internal links Discovered
- [+] http://www.respectwashington.us//rw-style.css
- [+] http://www.respectwashington.us//rwhome.html
- [+] http://www.respectwashington.us//whyweneed.html
- [+] http://www.respectwashington.us//petition.html
- [+] http://www.respectwashington.us//support.html
- [+] http://www.respectwashington.us//donate.html
- [+] http://www.respectwashington.us//testimonials.html
- [+] http://www.respectwashington.us//legal-action.html
- [+] http://www.respectwashington.us//volunteer.html
- [+] http://www.respectwashington.us//contact.html
- [+] http://www.respectwashington.us//Spokane Appellant Opening Brief.pdf
- [+] http://www.respectwashington.us//001 Gomez v Spokane Complaint.pdf
- [+] http://www.respectwashington.us//022 Gomez v Spokane Status Report.pdf
- [+] http://www.respectwashington.us//GomezSettlement SR 2018.pdf
- [+] http://www.respectwashington.us//001 Diaz-Garcia Rape INFORMATION.pdf
- [+] http://www.respectwashington.us//001 Diaz-Garcia Child Molest INFORMATION.pdf
- [+] http://www.respectwashington.us//DoC2014CrimeIllegals.pdf
- [+] http://www.respectwashington.us//DoJ Incarcerated Aliens 2017.pdf
- [+] http://www.respectwashington.us//BurienPolice2016Data.pdf
- [+] http://www.respectwashington.us//studies-and-reports/FAIRCostStudyWA2012.pdf
- [+] http://www.respectwashington.us//donate.html
- [+] http://www.respectwashington.us//Oregoneo0722.pdf
- [+] http://www.respectwashington.us//studies-and-reports/FAIRCostStudyWA2012.pdf
- --------------------------------------------------
- [!] 7 External links Discovered
- [#] http://komonews.com/news/local/charges-woman-bludgeoned-raped-at-burien-apartment-complex
- [#] http://www.kingcounty.gov/tools/inmate-lookup
- [#] http://www.foxnews.com/us/2017/08/02/dreamer-accused-brutally-raping-woman-in-washington.html
- [#] https://cis.org/Jessica-Vaughan-Discusses-Illegal-Aliens-Prisons
- [#] http://www.burienwa.gov/AgendaCenter/ViewFile/Agenda/_04242017-336
- [#] http://wei.secstate.wa.gov/osos/en/voterinformation/Pages/RegistertoVote.aspx
- [#] http://www.thesocialcontract.com/reports/eitc_2011apr/earned-income-tax-credit-2011apr.html
- --------------------------------------------------
- [#] Mapping Subdomain..
- [!] Found 1 Subdomain
- - respectwashington.us
- --------------------------------------------------
- [!] Done At 2019-10-22 09:02:39.319385
- #######################################################################################################################################
- [i] Scanning Site: http://www.respectwashington.us
- B A S I C I N F O
- ====================
- [+] Site Title: RespectWashington
- [+] IP address: 65.49.16.26
- [+] Web Server: Apache/2.4.18 (Ubuntu)
- [+] CMS: Could Not Detect
- [+] Cloudflare: Not Detected
- [+] Robots File: Could NOT Find robots.txt!
- W H O I S L O O K U P
- ========================
- Domain Name: respectwashington.us
- Registry Domain ID: D16560512-US
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: whois.godaddy.com
- Updated Date: 2019-05-17T14:12:02Z
- Creation Date: 2008-05-12T19:02:13Z
- Registry Expiry Date: 2020-05-11T23:59:59Z
- Registrar: GoDaddy.com, Inc.
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: +1.4806242505
- Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
- Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
- Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
- Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
- Registry Registrant ID: C24033066-US
- Registrant Name: B. Keller
- Registrant Organization:
- Registrant Street: PO Box 3786
- Registrant Street:
- Registrant Street:
- Registrant City: Federal Way
- Registrant State/Province: Washington
- Registrant Postal Code: 98063-3786
- Registrant Country: US
- Registrant Phone: +1.2069353505
- Registrant Phone Ext:
- Registrant Fax:
- Registrant Fax Ext:
- Registrant Email: [email protected]
- Registrant Application Purpose: P3
- Registrant Nexus Category: C11
- Registry Admin ID: C24033071-US
- Admin Name: B. Keller
- Admin Organization:
- Admin Street: PO Box 3786
- Admin Street:
- Admin Street:
- Admin City: Federal Way
- Admin State/Province: Washington
- Admin Postal Code: 98063-3786
- Admin Country: US
- Admin Phone: +1.2069353505
- Admin Phone Ext:
- Admin Fax:
- Admin Fax Ext:
- Admin Email: [email protected]
- Admin Application Purpose: P3
- Admin Nexus Category: C11
- Registry Tech ID: C24033068-US
- Tech Name: B. Keller
- Tech Organization:
- Tech Street: PO Box 3786
- Tech Street:
- Tech Street:
- Tech City: Federal Way
- Tech State/Province: Washington
- Tech Postal Code: 98063-3786
- Tech Country: US
- Tech Phone: +1.2069353505
- Tech Phone Ext:
- Tech Fax:
- Tech Fax Ext:
- Tech Email: [email protected]
- Tech Application Purpose: P3
- Tech Nexus Category: C11
- Name Server: ns2.he.net
- Name Server: ns1.he.net
- DNSSEC: unsigned
- URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
- >>> Last update of WHOIS database: 2019-10-22T13:02:47Z <<<
- For more information on Whois status codes, please visit https://icann.org/epp
- G E O I P L O O K U P
- =========================
- [i] IP Address: 65.49.16.26
- [i] Country: United States
- [i] State:
- [i] City:
- [i] Latitude: 37.751
- [i] Longitude: -97.822
- H T T P H E A D E R S
- =======================
- [i] HTTP/1.1 200 OK
- [i] Date: Tue, 22 Oct 2019 13:02:50 GMT
- [i] Server: Apache/2.4.18 (Ubuntu)
- [i] Last-Modified: Fri, 23 Feb 2018 15:15:28 GMT
- [i] ETag: "8956-565e2a1613be1"
- [i] Accept-Ranges: bytes
- [i] Content-Length: 35158
- [i] Vary: Accept-Encoding
- [i] Connection: close
- [i] Content-Type: text/html
- D N S L O O K U P
- ===================
- respectwashington.us. 21599 IN A 65.49.16.26
- respectwashington.us. 21599 IN NS ns2.he.net.
- respectwashington.us. 21599 IN NS ns5.he.net.
- respectwashington.us. 21599 IN NS ns3.he.net.
- respectwashington.us. 21599 IN NS ns1.he.net.
- respectwashington.us. 21599 IN NS ns4.he.net.
- respectwashington.us. 21599 IN SOA ns1.he.net. hostmaster.he.net. 200808098 10800 1800 604800 86400
- respectwashington.us. 21599 IN MX 1 respectwashington.us.
- S U B N E T C A L C U L A T I O N
- ====================================
- Address = 65.49.16.26
- Network = 65.49.16.26 / 32
- Netmask = 255.255.255.255
- Broadcast = not needed on Point-to-Point links
- Wildcard Mask = 0.0.0.0
- Hosts Bits = 0
- Max. Hosts = 1 (2^0 - 0)
- Host Range = { 65.49.16.26 - 65.49.16.26 }
- N M A P P O R T S C A N
- ============================
- Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-22 13:02 UTC
- Nmap scan report for respectwashington.us (65.49.16.26)
- Host is up (0.064s latency).
- PORT STATE SERVICE
- 21/tcp closed ftp
- 22/tcp closed ssh
- 23/tcp closed telnet
- 80/tcp open http
- 110/tcp open pop3
- 143/tcp open imap
- 443/tcp open https
- 3389/tcp closed ms-wbt-server
- Nmap done: 1 IP address (1 host up) scanned in 0.13 seconds
- #######################################################################################################################################
- [INFO] ------TARGET info------
- [*] TARGET: http://www.respectwashington.us/
- [*] TARGET IP: 65.49.16.26
- [INFO] NO load balancer detected for www.respectwashington.us...
- [*] DNS servers: respectwashington.us.
- [*] TARGET server: Apache/2.4.18 (Ubuntu)
- [*] CC: US
- [*] Country: United States
- [*] RegionCode: CA
- [*] RegionName: California
- [*] City: Fremont
- [*] ASN: AS6939
- [*] BGP_PREFIX: 65.49.0.0/17
- [*] ISP: HURRICANE - Hurricane Electric LLC, US
- [INFO] DNS enumeration:
- [*] ftp.respectwashington.us respectwashington.us. 65.49.16.26
- [*] mail.respectwashington.us respectwashington.us. 65.49.16.26
- [INFO] Possible abuse mails are:
- [INFO] NO PAC (Proxy Auto Configuration) file FOUND
- [INFO] Starting FUZZing in http://www.respectwashington.us/FUzZzZzZzZz...
- [INFO] Status code Folders
- [ALERT] Look in the source code. It may contain passwords
- [INFO] SAME content in http://www.respectwashington.us/ AND http://65.49.16.26/
- [INFO] Links found from http://www.respectwashington.us/:
- [*] http://komonews.com/news/local/charges-woman-bludgeoned-raped-at-burien-apartment-complex
- [*] https://cis.org/Jessica-Vaughan-Discusses-Illegal-Aliens-Prisons
- [*] http://wei.secstate.wa.gov/osos/en/voterinformation/Pages/RegistertoVote.aspx
- [*] http://www.burienwa.gov/AgendaCenter/ViewFile/Agenda/_04242017-336
- [*] http://www.foxnews.com/us/2017/08/02/dreamer-accused-brutally-raping-woman-in-washington.html
- [*] http://www.kingcounty.gov/tools/inmate-lookup
- [*] http://www.respectwashington.us/001 Diaz-Garcia Child Molest INFORMATION.pdf
- [*] http://www.respectwashington.us/001 Diaz-Garcia Rape INFORMATION.pdf
- [*] http://www.respectwashington.us/001 Gomez v Spokane Complaint.pdf
- [*] http://www.respectwashington.us/022 Gomez v Spokane Status Report.pdf
- [*] http://www.respectwashington.us/BurienPolice2016Data.pdf
- [*] http://www.respectwashington.us/contact.html
- [*] http://www.respectwashington.us/DoC2014CrimeIllegals.pdf
- [*] http://www.respectwashington.us/DoJ Incarcerated Aliens 2017.pdf
- [*] http://www.respectwashington.us/donate.html
- [*] http://www.respectwashington.us/GomezSettlement SR 2018.pdf
- [*] http://www.respectwashington.us/legal-action.html
- [*] http://www.respectwashington.us/Oregoneo0722.pdf
- [*] http://www.respectwashington.us/petition.html
- [*] http://www.respectwashington.us/rwhome.html
- [*] http://www.respectwashington.us/Spokane Appellant Opening Brief.pdf
- [*] http://www.respectwashington.us/studies-and-reports/FAIRCostStudyWA2012.pdf
- [*] http://www.respectwashington.us/support.html
- [*] http://www.respectwashington.us/testimonials.html
- [*] http://www.respectwashington.us/volunteer.html
- [*] http://www.respectwashington.us/whyweneed.html
- [*] http://www.thesocialcontract.com/reports/eitc_2011apr/earned-income-tax-credit-2011apr.html
- [*] http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=31b3ab0a43b5d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=db029c7755cb9010VgnVCM10000045f3d6a1RCRD
- [*] http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- [*] http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=75bce2e261405110VgnVCM1000004718190aRCRD&vgnextchannel=75bce2e261405110VgnVCM1000004718190aRCRD
- [INFO] Shodan detected the following opened ports on 65.49.16.26:
- [*] 1
- [*] 110
- [*] 143
- [*] 25
- [*] 4
- [*] 443
- [*] 465
- [*] 587
- [*] 80
- [*] 995
- [INFO] ------VirusTotal SECTION------
- [INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
- [INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
- [INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
- [INFO] ------Alexa Rank SECTION------
- [INFO] Percent of Visitors Rank in Country:
- [INFO] Percent of Search Traffic:
- [INFO] Percent of Unique Visits:
- [INFO] Total Sites Linking In:
- [*] Total Sites
- [INFO] Useful links related to www.respectwashington.us - 65.49.16.26:
- [*] https://www.virustotal.com/pt/ip-address/65.49.16.26/information/
- [*] https://www.hybrid-analysis.com/search?host=65.49.16.26
- [*] https://www.shodan.io/host/65.49.16.26
- [*] https://www.senderbase.org/lookup/?search_string=65.49.16.26
- [*] https://www.alienvault.com/open-threat-exchange/ip/65.49.16.26
- [*] http://pastebin.com/search?q=65.49.16.26
- [*] http://urlquery.net/search.php?q=65.49.16.26
- [*] http://www.alexa.com/siteinfo/www.respectwashington.us
- [*] http://www.google.com/safebrowsing/diagnostic?site=www.respectwashington.us
- [*] https://censys.io/ipv4/65.49.16.26
- [*] https://www.abuseipdb.com/check/65.49.16.26
- [*] https://urlscan.io/search/#65.49.16.26
- [*] https://github.com/search?q=65.49.16.26&type=Code
- [INFO] Useful links related to AS6939 - 65.49.0.0/17:
- [*] http://www.google.com/safebrowsing/diagnostic?site=AS:6939
- [*] https://www.senderbase.org/lookup/?search_string=65.49.0.0/17
- [*] http://bgp.he.net/AS6939
- [*] https://stat.ripe.net/AS6939
- [INFO] Date: 22/10/19 | Time: 09:04:07
- [INFO] Total time: 1 minute(s) and 21 second(s)
- ######################################################################################################################################
- Trying "respectwashington.us"
- ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46465
- ;; flags: qr rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 5, ADDITIONAL: 10
- ;; QUESTION SECTION:
- ;respectwashington.us. IN ANY
- ;; ANSWER SECTION:
- respectwashington.us. 43200 IN MX 1 respectwashington.us.
- respectwashington.us. 43200 IN SOA ns1.he.net. hostmaster.he.net. 200808098 10800 1800 604800 86400
- respectwashington.us. 43200 IN A 65.49.16.26
- respectwashington.us. 7200 IN NS ns1.he.net.
- respectwashington.us. 7200 IN NS ns5.he.net.
- respectwashington.us. 7200 IN NS ns2.he.net.
- respectwashington.us. 7200 IN NS ns4.he.net.
- respectwashington.us. 7200 IN NS ns3.he.net.
- ;; AUTHORITY SECTION:
- respectwashington.us. 7200 IN NS ns3.he.net.
- respectwashington.us. 7200 IN NS ns1.he.net.
- respectwashington.us. 7200 IN NS ns5.he.net.
- respectwashington.us. 7200 IN NS ns2.he.net.
- respectwashington.us. 7200 IN NS ns4.he.net.
- ;; ADDITIONAL SECTION:
- respectwashington.us. 43200 IN A 65.49.16.26
- ns2.he.net. 5670 IN A 216.218.131.2
- ns2.he.net. 5670 IN AAAA 2001:470:200::2
- ns5.he.net. 5670 IN A 216.66.80.18
- ns5.he.net. 5670 IN AAAA 2001:470:500::2
- ns3.he.net. 4649 IN A 216.218.132.2
- ns3.he.net. 5670 IN AAAA 2001:470:300::2
- ns1.he.net. 5670 IN A 216.218.130.2
- ns1.he.net. 5670 IN AAAA 2001:470:100::2
- ns4.he.net. 11042 IN A 216.66.1.2
- Received 491 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 101 ms
- #######################################################################################################################################
- ; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace respectwashington.us
- ;; global options: +cmd
- . 84866 IN NS j.root-servers.net.
- . 84866 IN NS c.root-servers.net.
- . 84866 IN NS i.root-servers.net.
- . 84866 IN NS g.root-servers.net.
- . 84866 IN NS b.root-servers.net.
- . 84866 IN NS k.root-servers.net.
- . 84866 IN NS m.root-servers.net.
- . 84866 IN NS f.root-servers.net.
- . 84866 IN NS e.root-servers.net.
- . 84866 IN NS l.root-servers.net.
- . 84866 IN NS d.root-servers.net.
- . 84866 IN NS h.root-servers.net.
- . 84866 IN NS a.root-servers.net.
- . 84866 IN RRSIG NS 8 0 518400 20191104050000 20191022040000 22545 . V7L2dB4F79xO9lx8hztPB86SYLY35tcInKqSk8aLbD8fvpqah4DWHoDe 2xbqt74EJPvBDnnxjmyB4tREMvAE2pcJYRcXgEXojn3yhrQSsQ3jFs5F PjYgRw0D2xB2yHw8rQ4l16CD7aEVgG+FefFGqt3W+daAM1PO+IYKW0wG ZlUdJNJSe51nOWemZldGoqlKha/wznCidzCCANqSG6ZPNuvTOgIFhRZB drsNOA4MFLWYNYyQpPWFiqtgkB5nZx3ACgXg/VY6Jy/blXbeM75bse+V 1878EtXXH4TdBRmzNhEyyy6uJa9iO9OjpIn2SDrdVRzSlWOKvOH+Pw8i KLe1JA==
- ;; Received 525 bytes from 185.93.180.131#53(185.93.180.131) in 272 ms
- us. 172800 IN NS a.cctld.us.
- us. 172800 IN NS b.cctld.us.
- us. 172800 IN NS c.cctld.us.
- us. 172800 IN NS e.cctld.us.
- us. 172800 IN NS f.cctld.us.
- us. 172800 IN NS k.cctld.us.
- us. 86400 IN DS 39361 8 1 09E0AF18E54225F87A3B10E95C9DA3F1E58E5B59
- us. 86400 IN DS 39361 8 2 415D8DAE2299D2C2DAB7458ED4C715268CD2EB3AE3C1C249FF1696BF 62112201
- us. 86400 IN RRSIG DS 8 1 86400 20191104050000 20191022040000 22545 . iwNdGw1iFmnlQhMmmiTvSmYrvodp8SP96yzRKIQIIGjHcoNjhjPyuCtK 0XV6r/hXQdDALEmrOYoXXm7bm4mxMUAPzELZx53gJqZnLuNSakJSSfSD v3+V7RkjAyDqsFbo8T8xqogYq5gdyfEgywvqM2AlTlCqLDKnq+PWGZSS hs5H2PRFMoBspEeeJDoX7OyaxmOqgZu7xntkkV3BLuj7TaasFeYF7+FH lLkiQIVpoQ7ZjP9V/EYYAEpD4yvfJFYEHEJ8tDQtrfQLuO8c9BrislHb 1N+yXPjCLmzI1qeyGZmCI4EPlzT6i35DOe4GK+NtnAabenxNxdG3+NOi BjnDYA==
- ;; Received 702 bytes from 192.5.5.241#53(f.root-servers.net) in 235 ms
- respectwashington.us. 7200 IN NS ns1.he.net.
- respectwashington.us. 7200 IN NS ns2.he.net.
- 04mlcpvb7mqd2gpuv2rh2rcgskp50v81.us. 86400 IN NSEC3 1 1 1 5BF34C13 056DH6NLLM6G7RO2Q55AA17ELRSE74UF NS SOA RRSIG DNSKEY NSEC3PARAM
- 04mlcpvb7mqd2gpuv2rh2rcgskp50v81.us. 86400 IN RRSIG NSEC3 8 2 86400 20191120004524 20191021004231 8985 us. HBYCNylHalmWp7B1QC9PEcoa0noKP+lJdunkL9MFmGqTB/V7U+R797ki NIFoLyjrlUpC8QXAEJJCUued6hPidMcp37LmEUOOg4J5KkgBR/q+f6A1 BwWRAhj+4HU1v6OXZPOPo2sP/lxYS4uDP+7Sfnps/rMRqXgsvVE/Z7Eu Ja4B/a8NF6KhwYfLftWfYlgiC3GBcEne+lFaWLFxl7W7Lw==
- sv29nkrum42r9gdc10fr6govqbv26ibh.us. 86400 IN NSEC3 1 1 1 5BF34C13 SVCMABQOVKNKUD1ODDO1FGH255K00IS1 NS DS RRSIG
- sv29nkrum42r9gdc10fr6govqbv26ibh.us. 86400 IN RRSIG NSEC3 8 2 86400 20191120032006 20191021022206 8985 us. i9QZRvSwQL+a4v7Ur23kXNeoalK80hyCJUyRlskjq75CPl343NoN5USk Hc/emaawPWw04sAw1LlxIOZZ4D0cI0TscpJY3voblXF9k9s4EseahHuw slUfO7MpsB2l5WlImpgbkySreSZGFzCAwOh3RZzMwNTzcvLmIe4YggDe PL2RkVfFIw9bH0iCyn7gnaRBmWksNjzFm78G/cuHaB3uvg==
- ;; Received 674 bytes from 156.154.125.70#53(b.cctld.us) in 238 ms
- respectwashington.us. 86400 IN A 65.49.16.26
- ;; Received 65 bytes from 216.218.130.2#53(ns1.he.net) in 299 ms
- #######################################################################################################################################
- [*] Performing General Enumeration of Domain: respectwashington.us
- [-] DNSSEC is not configured for respectwashington.us
- [*] SOA ns1.he.net 216.218.130.2
- [*] NS ns2.he.net 216.218.131.2
- [*] Bind Version for 216.218.131.2 Served by PowerDNS - https://www.powerdns.com/
- [*] NS ns2.he.net 2001:470:200::2
- [*] Bind Version for 2001:470:200::2 Served by PowerDNS - https://www.powerdns.com/
- [*] NS ns1.he.net 216.218.130.2
- [*] Bind Version for 216.218.130.2 Served by PowerDNS - https://www.powerdns.com/
- [*] NS ns1.he.net 2001:470:100::2
- [*] Bind Version for 2001:470:100::2 Served by PowerDNS - https://www.powerdns.com/
- [*] MX respectwashington.us 65.49.16.26
- [*] A respectwashington.us 65.49.16.26
- [*] Enumerating SRV Records
- [-] No SRV Records Found for respectwashington.us
- [+] 0 Records Found
- ######################################################################################################################################
- [*] Processing domain respectwashington.us
- [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
- [+] Getting nameservers
- 216.218.131.2 - ns2.he.net
- 216.218.130.2 - ns1.he.net
- [-] Zone transfer failed
- [+] MX records found, added to target list
- 1 respectwashington.us.
- [*] Scanning respectwashington.us for A records
- 65.49.16.26 - respectwashington.us
- 65.49.16.26 - ftp.respectwashington.us
- 65.49.16.26 - mail.respectwashington.us
- 65.49.16.26 - www.respectwashington.us
- ######################################################################################################################################
- AVAILABLE PLUGINS
- -----------------
- CompressionPlugin
- OpenSslCipherSuitesPlugin
- HeartbleedPlugin
- RobotPlugin
- CertificateInfoPlugin
- FallbackScsvPlugin
- OpenSslCcsInjectionPlugin
- HttpHeadersPlugin
- SessionRenegotiationPlugin
- SessionResumptionPlugin
- EarlyDataPlugin
- CHECKING HOST(S) AVAILABILITY
- -----------------------------
- 65.49.16.26:443 => 65.49.16.26
- SCAN RESULTS FOR 65.49.16.26:443 - 65.49.16.26
- ----------------------------------------------
- * Deflate Compression:
- OK - Compression disabled
- * OpenSSL Heartbleed:
- OK - Not vulnerable to Heartbleed
- * Certificate Information:
- Content
- SHA1 Fingerprint: f98a5fd3ac3822786c2f81cf471ae5b94540febf
- Common Name: respectwashington.us
- Issuer: Let's Encrypt Authority X3
- Serial Number: 394679518299288580990689807411278660178273
- Not Before: 2019-09-23 10:50:34
- Not After: 2019-12-22 10:50:34
- Signature Algorithm: sha256
- Public Key Algorithm: RSA
- Key Size: 2048
- Exponent: 65537 (0x10001)
- DNS Subject Alternative Names: ['keller4america.us', 'mail.respectwashington.us', 'respectwashington.us', 'www.keller4america.us', 'www.respectwashington.us']
- Trust
- Hostname Validation: FAILED - Certificate does NOT match 65.49.16.26
- Android CA Store (9.0.0_r9): OK - Certificate is trusted
- Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
- Java CA Store (jdk-12.0.1): OK - Certificate is trusted
- Mozilla CA Store (2019-03-14): OK - Certificate is trusted
- Windows CA Store (2019-05-27): OK - Certificate is trusted
- Symantec 2018 Deprecation: WARNING: Certificate distrusted by Google and Mozilla on September 2018
- Received Chain: respectwashington.us --> Let's Encrypt Authority X3
- Verified Chain: respectwashington.us --> Let's Encrypt Authority X3 --> DST Root CA X3
- Received Chain Contains Anchor: OK - Anchor certificate not sent
- Received Chain Order: OK - Order is valid
- Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
- Extensions
- OCSP Must-Staple: NOT SUPPORTED - Extension not found
- Certificate Transparency: WARNING - Only 2 SCTs included but Google recommends 3 or more
- OCSP Stapling
- NOT SUPPORTED - Server did not send back an OCSP response
- * TLSV1_1 Cipher Suites:
- Forward Secrecy OK - Supported
- RC4 OK - Not Supported
- Preferred:
- None - Server followed client cipher suite preference.
- Accepted:
- TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- * TLSV1_2 Cipher Suites:
- Forward Secrecy OK - Supported
- RC4 OK - Not Supported
- Preferred:
- None - Server followed client cipher suite preference.
- Accepted:
- TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- * Downgrade Attacks:
- TLS_FALLBACK_SCSV: OK - Supported
- * OpenSSL CCS Injection:
- OK - Not vulnerable to OpenSSL CCS injection
- * SSLV3 Cipher Suites:
- Server rejected all cipher suites.
- * SSLV2 Cipher Suites:
- Server rejected all cipher suites.
- * TLSV1 Cipher Suites:
- Forward Secrecy OK - Supported
- RC4 OK - Not Supported
- Preferred:
- None - Server followed client cipher suite preference.
- Accepted:
- TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- * TLS 1.2 Session Resumption Support:
- With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
- With TLS Tickets: OK - Supported
- * Session Renegotiation:
- Client-initiated Renegotiation: OK - Rejected
- Secure Renegotiation: OK - Supported
- * TLSV1_3 Cipher Suites:
- Server rejected all cipher suites.
- * ROBOT Attack:
- OK - Not vulnerable
- SCAN COMPLETED IN 44.02 S
- -------------------------
- ######################################################################################################################################
- Domains still to check: 1
- Checking if the hostname respectwashington.us. given is in fact a domain...
- Analyzing domain: respectwashington.us.
- Checking NameServers using system default resolver...
- IP: 216.218.131.2 (United States)
- HostName: ns2.he.net Type: NS
- HostName: ns2.he.net Type: PTR
- IP: 216.218.130.2 (United States)
- HostName: ns1.he.net Type: NS
- HostName: ns1.he.net Type: PTR
- Checking MailServers using system default resolver...
- IP: 65.49.16.26 (United States)
- HostName: respectwashington.us Type: MX
- HostName: respectwashington.us Type: PTR
- Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
- No zone transfer found on nameserver 216.218.131.2
- No zone transfer found on nameserver 216.218.130.2
- Checking SPF record...
- No SPF record
- Checking 192 most common hostnames using system default resolver...
- IP: 65.49.16.26 (United States)
- HostName: respectwashington.us Type: MX
- HostName: respectwashington.us Type: PTR
- HostName: www.respectwashington.us. Type: A
- IP: 65.49.16.26 (United States)
- HostName: respectwashington.us Type: MX
- HostName: respectwashington.us Type: PTR
- HostName: www.respectwashington.us. Type: A
- HostName: ftp.respectwashington.us. Type: A
- IP: 65.49.16.26 (United States)
- HostName: respectwashington.us Type: MX
- HostName: respectwashington.us Type: PTR
- HostName: www.respectwashington.us. Type: A
- HostName: ftp.respectwashington.us. Type: A
- HostName: mail.respectwashington.us. Type: A
- Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
- Checking netblock 216.218.131.0
- Checking netblock 65.49.16.0
- Checking netblock 216.218.130.0
- Searching for respectwashington.us. emails in Google
- Checking 3 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
- Host 216.218.131.2 is up (echo-reply ttl 57)
- Host 65.49.16.26 is up (reset ttl 64)
- Host 216.218.130.2 is up (reset ttl 64)
- Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
- Scanning ip 216.218.131.2 (ns2.he.net (PTR)):
- 53/tcp open domain syn-ack ttl 57 PowerDNS 3.3 or later
- | dns-nsid:
- | NSID: ns2.he.net (6e73322e68652e6e6574)
- | id.server: ns2.he.net
- |_ bind.version: Served by PowerDNS - https://www.powerdns.com/
- Scanning ip 65.49.16.26 (mail.respectwashington.us.):
- 80/tcp open http syn-ack ttl 53 Apache httpd 2.4.18 ((Ubuntu))
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-server-header: Apache/2.4.18 (Ubuntu)
- |_http-title: RespectWashington
- 110/tcp open pop3 syn-ack ttl 53 Dovecot pop3d
- |_pop3-capabilities: TOP CAPA UIDL USER PIPELINING SASL(PLAIN LOGIN) RESP-CODES STLS AUTH-RESP-CODE
- |_ssl-date: TLS randomness does not represent time
- 143/tcp open imap syn-ack ttl 53 Dovecot imapd
- |_imap-capabilities: STARTTLS AUTH=PLAIN capabilities more listed IMAP4rev1 Pre-login LOGIN-REFERRALS SASL-IR OK post-login AUTH=LOGINA0001 IDLE have ENABLE ID LITERAL+
- |_ssl-date: TLS randomness does not represent time
- 443/tcp open ssl/http syn-ack ttl 53 Apache httpd 2.4.18
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-server-header: Apache/2.4.18 (Ubuntu)
- |_http-title: 400 Bad Request
- | ssl-cert: Subject: commonName=respectwashington.us
- | Subject Alternative Name: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
- | Public Key type: rsa
- | Public Key bits: 2048
- | Signature Algorithm: sha256WithRSAEncryption
- | Not valid before: 2019-09-23T10:50:34
- | Not valid after: 2019-12-22T10:50:34
- | MD5: 9c61 f3dc 6487 544c de9e 4197 e08a 5fa7
- |_SHA-1: f98a 5fd3 ac38 2278 6c2f 81cf 471a e5b9 4540 febf
- |_ssl-date: TLS randomness does not represent time
- | tls-alpn:
- |_ http/1.1
- 465/tcp open ssl/smtp syn-ack ttl 53 Postfix smtpd
- |_smtp-commands: Couldn't establish connection on port 465
- | ssl-cert: Subject: commonName=respectwashington.us
- | Subject Alternative Name: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
- | Public Key type: rsa
- | Public Key bits: 2048
- | Signature Algorithm: sha256WithRSAEncryption
- | Not valid before: 2019-09-23T10:50:34
- | Not valid after: 2019-12-22T10:50:34
- | MD5: 9c61 f3dc 6487 544c de9e 4197 e08a 5fa7
- |_SHA-1: f98a 5fd3 ac38 2278 6c2f 81cf 471a e5b9 4540 febf
- |_ssl-date: TLS randomness does not represent time
- 587/tcp open smtp syn-ack ttl 53 Postfix smtpd
- |_smtp-commands: respectwashington.us Hello nmap.scanme.org, STARTTLS, HELP,
- | ssl-cert: Subject: commonName=respectwashington.us
- | Subject Alternative Name: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
- | Public Key type: rsa
- | Public Key bits: 2048
- | Signature Algorithm: sha256WithRSAEncryption
- | Not valid before: 2019-09-23T10:50:34
- | Not valid after: 2019-12-22T10:50:34
- | MD5: 9c61 f3dc 6487 544c de9e 4197 e08a 5fa7
- |_SHA-1: f98a 5fd3 ac38 2278 6c2f 81cf 471a e5b9 4540 febf
- |_ssl-date: TLS randomness does not represent time
- 993/tcp open ssl/imaps? syn-ack ttl 53
- |_ssl-date: TLS randomness does not represent time
- 995/tcp open ssl/pop3s? syn-ack ttl 53
- |_ssl-date: TLS randomness does not represent time
- OS Info: Service Info: Hosts: www.respectwashington.us, respectwashington.us
- Scanning ip 216.218.130.2 (ns1.he.net (PTR)):
- 53/tcp open domain syn-ack ttl 57 PowerDNS 3.3 or later
- | dns-nsid:
- | NSID: ns1.he.net (6e73312e68652e6e6574)
- | id.server: ns1.he.net
- |_ bind.version: Served by PowerDNS - https://www.powerdns.com/
- WebCrawling domain's web servers... up to 50 max links.
- + URL to crawl: http://ftp.respectwashington.us.
- + Date: 2019-10-22
- + Crawling URL: http://ftp.respectwashington.us.:
- + Links:
- + Crawling http://ftp.respectwashington.us.
- + Crawling http://ftp.respectwashington.us./rwhome.html
- + Crawling http://ftp.respectwashington.us./whyweneed.html
- + Crawling http://ftp.respectwashington.us./petition.html
- + Crawling http://ftp.respectwashington.us./support.html
- + Crawling http://ftp.respectwashington.us./donate.html
- + Crawling http://ftp.respectwashington.us./testimonials.html
- + Crawling http://ftp.respectwashington.us./legal-action.html
- + Crawling http://ftp.respectwashington.us./volunteer.html
- + Crawling http://ftp.respectwashington.us./contact.html
- + Crawling http://ftp.respectwashington.us./MarchPetition (404 Not Found)
- + Crawling http://ftp.respectwashington.us./
- + Searching for directories...
- - Found: http://ftp.respectwashington.us./rw-images/
- - Found: http://ftp.respectwashington.us./studies-and-reports/
- - Found: http://ftp.respectwashington.us./legal-documents/
- + Searching open folders...
- - http://ftp.respectwashington.us./rw-images/ (403 Forbidden)
- - http://ftp.respectwashington.us./studies-and-reports/ (403 Forbidden)
- - http://ftp.respectwashington.us./legal-documents/ (403 Forbidden)
- + Crawl finished successfully.
- ----------------------------------------------------------------------
- Summary of http://http://ftp.respectwashington.us.
- ----------------------------------------------------------------------
- + Links crawled:
- - http://ftp.respectwashington.us.
- - http://ftp.respectwashington.us./
- - http://ftp.respectwashington.us./MarchPetition (404 Not Found)
- - http://ftp.respectwashington.us./contact.html
- - http://ftp.respectwashington.us./donate.html
- - http://ftp.respectwashington.us./legal-action.html
- - http://ftp.respectwashington.us./petition.html
- - http://ftp.respectwashington.us./rwhome.html
- - http://ftp.respectwashington.us./support.html
- - http://ftp.respectwashington.us./testimonials.html
- - http://ftp.respectwashington.us./volunteer.html
- - http://ftp.respectwashington.us./whyweneed.html
- Total links crawled: 12
- + Links to files found:
- - http://ftp.respectwashington.us./001 Diaz-Garcia Child Molest INFORMATION.pdf
- - http://ftp.respectwashington.us./001 Diaz-Garcia Rape INFORMATION.pdf
- - http://ftp.respectwashington.us./001 Gomez v Spokane Complaint.pdf
- - http://ftp.respectwashington.us./022 Gomez v Spokane Status Report.pdf
- - http://ftp.respectwashington.us./BurienPolice2016Data.pdf
- - http://ftp.respectwashington.us./CheckBackInMarch.pdf
- - http://ftp.respectwashington.us./DoC2014CrimeIllegals.jpg
- - http://ftp.respectwashington.us./DoC2014CrimeIllegals.pdf
- - http://ftp.respectwashington.us./DoJ Incarcerated Aliens 2017.pdf
- - http://ftp.respectwashington.us./FAIRWA2012.pdf
- - http://ftp.respectwashington.us./GomezSettlement SR 2018.pdf
- - http://ftp.respectwashington.us./Oregoneo0722.pdf
- - http://ftp.respectwashington.us./Spokane Appellant Opening Brief.pdf
- - http://ftp.respectwashington.us./how-to-ArmstrongV2.ppt
- - http://ftp.respectwashington.us./legal-documents/DECLARSTEPHENSAG4-18-11424.pdf
- - http://ftp.respectwashington.us./legal-documents/GAO2005-478.pdf
- - http://ftp.respectwashington.us./legal-documents/KingBRIEFOPToMSJApr18.pdf
- - http://ftp.respectwashington.us./legal-documents/KingDefenseFeb2011.pdf
- - http://ftp.respectwashington.us./legal-documents/KingDismissMSJMar2011.pdf
- - http://ftp.respectwashington.us./legal-documents/KingMSJDismissDeclMar2011.pdf
- - http://ftp.respectwashington.us./legal-documents/KingReplySupportDismissMSJApr25.pdf
- - http://ftp.respectwashington.us./legal-documents/ORDERGRANTINGKingMSJDis5-10-11.pdf
- - http://ftp.respectwashington.us./legal-documents/RingDeclareMar2011.pdf
- - http://ftp.respectwashington.us./legal-documents/RingMSJMar2011.pdf
- - http://ftp.respectwashington.us./legal-documents/RingOPToKingMSJDisApr18.pdf
- - http://ftp.respectwashington.us./legal-documents/RingPetitionNov2010.pdf
- - http://ftp.respectwashington.us./legal-documents/RingReplySupportMSjApr25.pdf
- - http://ftp.respectwashington.us./legal-documents/RingVRidgeMOTIONHEARING5-10-11.pdf
- - http://ftp.respectwashington.us./legal-documents/RingVRidgeOralArgs4-29-11.PDF
- - http://ftp.respectwashington.us./legal-documents/RingVRidgeOralDecTrans5-10-11.PDF
- - http://ftp.respectwashington.us./legal-documents/Ringhofer v Ridge 679708.wma
- - http://ftp.respectwashington.us./legal-documents/RinghoferPetitionReview2013.pdf
- - http://ftp.respectwashington.us./legal-documents/SpakovskyHeritage28.pdf
- - http://ftp.respectwashington.us./legal-documents/TexasHarrisCountyVoteID.pdf
- - http://ftp.respectwashington.us./legal-documents/USHouseAdmin2006Bettencourt.pdf
- - http://ftp.respectwashington.us./legal-documents/WSCADwyerOpinon12-10-12.pdf
- - http://ftp.respectwashington.us./legal-documents/WSSCAppealOpenBrief-Amended9-6-11.pdf
- - http://ftp.respectwashington.us./legal-documents/WSSCAppellantReplyBrief11-14-11.pdf
- - http://ftp.respectwashington.us./legal-documents/WSSCDirectReviewGrounds6-24-11.pdf
- - http://ftp.respectwashington.us./legal-documents/WSSCOrder88293-5RinghoferVRidge.pdf
- - http://ftp.respectwashington.us./legal-documents/WSSCRespondentBrief10-5-11.pdf
- - http://ftp.respectwashington.us./legal-documents/WSSCTransfer11-21-11.pdf
- - http://ftp.respectwashington.us./rw-images/header-blue-new.jpg
- - http://ftp.respectwashington.us./rw-images/keepLegal.gif
- - http://ftp.respectwashington.us./rw-style.css
- - http://ftp.respectwashington.us./studies-and-reports/11 03 08 FINAL whitepaper.pdf
- - http://ftp.respectwashington.us./studies-and-reports/2005DHSHAudit6534.pdf
- - http://ftp.respectwashington.us./studies-and-reports/BearStearnsUnderground.pdf
- - http://ftp.respectwashington.us./studies-and-reports/FAIRCostStudyWA2012.pdf
- - http://ftp.respectwashington.us./studies-and-reports/REAL ID Not National ID Card.pdf
- Total links to files: 50
- + Externals links found:
- - http://community.seattletimes.nwsource.com/archive/?date=20060718&slug=prisonbill18m
- - http://irli.org/
- - http://komonews.com/news/local/charges-woman-bludgeoned-raped-at-burien-apartment-complex
- - http://seattletimes.nwsource.com/html/localnews/2014429238_apwaxgrillegalimmigrantslicenses3rdldwritethru.html
- - http://seattletimes.nwsource.com/html/localnews/2014643197_wagetheft31m.html
- - http://wei.secstate.wa.gov/osos/en/voterinformation/Pages/RegistertoVote.aspx
- - http://www.alipac.us/
- - http://www.burienwa.gov/AgendaCenter/ViewFile/Agenda/_04242017-336
- - http://www.cis.org
- - http://www.fairus.org/site/PageServer
- - http://www.familysecuritymatters.org/
- - http://www.familysecuritymatters.org/publications/id.9984/pub_detail.asp
- - http://www.foxnews.com/us/2017/08/02/dreamer-accused-brutally-raping-woman-in-washington.html
- - http://www.heritage.org/
- - http://www.heritage.org/Research/HealthCare/wm1714.cfm
- - http://www.heritage.org/Research/Immigration/bg1936.cfm
- - http://www.heritage.org/Research/Immigration/lm25.cfm
- - http://www.heritage.org/Research/Immigration/tst052107a.cfm
- - http://www.ice.gov/worksite/
- - http://www.irli.org/
- - http://www.judicialwatch.org/wp-content/uploads/2014/02/Judicial-Watch-Special-Illegal-Immigration-Report.pdf
- - http://www.kingcounty.gov/tools/inmate-lookup
- - http://www.legion.org/documents/legion/pdf/illegalimmigration.pdf
- - http://www.manhattaninstitute.org/tools/topical_index.php?topic=49
- - http://www.minutemanhq.com/
- - http://www.numbersusa.org/
- - http://www.ojjpac.org/sanctuary.asp
- - http://www.oregonir.org/
- - http://www.securedbordersusa.com/
- - http://www.sos.wa.gov/elections/initiatives/Initiatives.aspx?y=2014&t=p
- - http://www.soundpolitics.com/
- - http://www.soundpolitics.com/voterlookup.html
- - http://www.thesocialcontract.com/
- - http://www.thesocialcontract.com/artman2/publish/tsc_18_2/index.shtml
- - http://www.thesocialcontract.com/events/press_conf_2009apr14.html
- - http://www.thesocialcontract.com/reports/eitc_2011apr/earned-income-tax-credit-2011apr.html
- - http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=31b3ab0a43b5d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=db029c7755cb9010VgnVCM10000045f3d6a1RCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=75bce2e261405110VgnVCM1000004718190aRCRD&vgnextchannel=75bce2e261405110VgnVCM1000004718190aRCRD
- - http://www.wfir.org/
- - http://www.wsp.wa.gov/crime/wanted.php
- - http://zip4.usps.com/zip4/welcome.jsp
- - https://cis.org/Jessica-Vaughan-Discusses-Illegal-Aliens-Prisons
- Total external links: 43
- + Email addresses found:
- Total email address found: 0
- + Directories found:
- - http://ftp.respectwashington.us./legal-documents/ (403 Forbidden)
- - http://ftp.respectwashington.us./rw-images/ (403 Forbidden)
- - http://ftp.respectwashington.us./studies-and-reports/ (403 Forbidden)
- Total directories: 3
- + Directory indexing found:
- Total directories with indexing: 0
- ----------------------------------------------------------------------
- + URL to crawl: http://www.respectwashington.us.
- + Date: 2019-10-22
- + Crawling URL: http://www.respectwashington.us.:
- + Links:
- + Crawling http://www.respectwashington.us.
- + Crawling http://www.respectwashington.us./rwhome.html
- + Crawling http://www.respectwashington.us./whyweneed.html
- + Crawling http://www.respectwashington.us./petition.html
- + Crawling http://www.respectwashington.us./support.html
- + Crawling http://www.respectwashington.us./donate.html
- + Crawling http://www.respectwashington.us./testimonials.html
- + Crawling http://www.respectwashington.us./legal-action.html
- + Crawling http://www.respectwashington.us./volunteer.html
- + Crawling http://www.respectwashington.us./contact.html
- + Crawling http://www.respectwashington.us./MarchPetition (404 Not Found)
- + Crawling http://www.respectwashington.us./
- + Searching for directories...
- - Found: http://www.respectwashington.us./rw-images/
- - Found: http://www.respectwashington.us./studies-and-reports/
- - Found: http://www.respectwashington.us./legal-documents/
- + Searching open folders...
- - http://www.respectwashington.us./rw-images/ (403 Forbidden)
- - http://www.respectwashington.us./studies-and-reports/ (403 Forbidden)
- - http://www.respectwashington.us./legal-documents/ (403 Forbidden)
- + Crawl finished successfully.
- ----------------------------------------------------------------------
- Summary of http://http://www.respectwashington.us.
- ----------------------------------------------------------------------
- + Links crawled:
- - http://www.respectwashington.us.
- - http://www.respectwashington.us./
- - http://www.respectwashington.us./MarchPetition (404 Not Found)
- - http://www.respectwashington.us./contact.html
- - http://www.respectwashington.us./donate.html
- - http://www.respectwashington.us./legal-action.html
- - http://www.respectwashington.us./petition.html
- - http://www.respectwashington.us./rwhome.html
- - http://www.respectwashington.us./support.html
- - http://www.respectwashington.us./testimonials.html
- - http://www.respectwashington.us./volunteer.html
- - http://www.respectwashington.us./whyweneed.html
- Total links crawled: 12
- + Links to files found:
- - http://www.respectwashington.us./001 Diaz-Garcia Child Molest INFORMATION.pdf
- - http://www.respectwashington.us./001 Diaz-Garcia Rape INFORMATION.pdf
- - http://www.respectwashington.us./001 Gomez v Spokane Complaint.pdf
- - http://www.respectwashington.us./022 Gomez v Spokane Status Report.pdf
- - http://www.respectwashington.us./BurienPolice2016Data.pdf
- - http://www.respectwashington.us./CheckBackInMarch.pdf
- - http://www.respectwashington.us./DoC2014CrimeIllegals.jpg
- - http://www.respectwashington.us./DoC2014CrimeIllegals.pdf
- - http://www.respectwashington.us./DoJ Incarcerated Aliens 2017.pdf
- - http://www.respectwashington.us./FAIRWA2012.pdf
- - http://www.respectwashington.us./GomezSettlement SR 2018.pdf
- - http://www.respectwashington.us./Oregoneo0722.pdf
- - http://www.respectwashington.us./Spokane Appellant Opening Brief.pdf
- - http://www.respectwashington.us./how-to-ArmstrongV2.ppt
- - http://www.respectwashington.us./legal-documents/DECLARSTEPHENSAG4-18-11424.pdf
- - http://www.respectwashington.us./legal-documents/GAO2005-478.pdf
- - http://www.respectwashington.us./legal-documents/KingBRIEFOPToMSJApr18.pdf
- - http://www.respectwashington.us./legal-documents/KingDefenseFeb2011.pdf
- - http://www.respectwashington.us./legal-documents/KingDismissMSJMar2011.pdf
- - http://www.respectwashington.us./legal-documents/KingMSJDismissDeclMar2011.pdf
- - http://www.respectwashington.us./legal-documents/KingReplySupportDismissMSJApr25.pdf
- - http://www.respectwashington.us./legal-documents/ORDERGRANTINGKingMSJDis5-10-11.pdf
- - http://www.respectwashington.us./legal-documents/RingDeclareMar2011.pdf
- - http://www.respectwashington.us./legal-documents/RingMSJMar2011.pdf
- - http://www.respectwashington.us./legal-documents/RingOPToKingMSJDisApr18.pdf
- - http://www.respectwashington.us./legal-documents/RingPetitionNov2010.pdf
- - http://www.respectwashington.us./legal-documents/RingReplySupportMSjApr25.pdf
- - http://www.respectwashington.us./legal-documents/RingVRidgeMOTIONHEARING5-10-11.pdf
- - http://www.respectwashington.us./legal-documents/RingVRidgeOralArgs4-29-11.PDF
- - http://www.respectwashington.us./legal-documents/RingVRidgeOralDecTrans5-10-11.PDF
- - http://www.respectwashington.us./legal-documents/Ringhofer v Ridge 679708.wma
- - http://www.respectwashington.us./legal-documents/RinghoferPetitionReview2013.pdf
- - http://www.respectwashington.us./legal-documents/SpakovskyHeritage28.pdf
- - http://www.respectwashington.us./legal-documents/TexasHarrisCountyVoteID.pdf
- - http://www.respectwashington.us./legal-documents/USHouseAdmin2006Bettencourt.pdf
- - http://www.respectwashington.us./legal-documents/WSCADwyerOpinon12-10-12.pdf
- - http://www.respectwashington.us./legal-documents/WSSCAppealOpenBrief-Amended9-6-11.pdf
- - http://www.respectwashington.us./legal-documents/WSSCAppellantReplyBrief11-14-11.pdf
- - http://www.respectwashington.us./legal-documents/WSSCDirectReviewGrounds6-24-11.pdf
- - http://www.respectwashington.us./legal-documents/WSSCOrder88293-5RinghoferVRidge.pdf
- - http://www.respectwashington.us./legal-documents/WSSCRespondentBrief10-5-11.pdf
- - http://www.respectwashington.us./legal-documents/WSSCTransfer11-21-11.pdf
- - http://www.respectwashington.us./rw-images/header-blue-new.jpg
- - http://www.respectwashington.us./rw-images/keepLegal.gif
- - http://www.respectwashington.us./rw-style.css
- - http://www.respectwashington.us./studies-and-reports/11 03 08 FINAL whitepaper.pdf
- - http://www.respectwashington.us./studies-and-reports/2005DHSHAudit6534.pdf
- - http://www.respectwashington.us./studies-and-reports/BearStearnsUnderground.pdf
- - http://www.respectwashington.us./studies-and-reports/FAIRCostStudyWA2012.pdf
- - http://www.respectwashington.us./studies-and-reports/REAL ID Not National ID Card.pdf
- Total links to files: 50
- + Externals links found:
- - http://community.seattletimes.nwsource.com/archive/?date=20060718&slug=prisonbill18m
- - http://irli.org/
- - http://komonews.com/news/local/charges-woman-bludgeoned-raped-at-burien-apartment-complex
- - http://seattletimes.nwsource.com/html/localnews/2014429238_apwaxgrillegalimmigrantslicenses3rdldwritethru.html
- - http://seattletimes.nwsource.com/html/localnews/2014643197_wagetheft31m.html
- - http://wei.secstate.wa.gov/osos/en/voterinformation/Pages/RegistertoVote.aspx
- - http://www.alipac.us/
- - http://www.burienwa.gov/AgendaCenter/ViewFile/Agenda/_04242017-336
- - http://www.cis.org
- - http://www.fairus.org/site/PageServer
- - http://www.familysecuritymatters.org/
- - http://www.familysecuritymatters.org/publications/id.9984/pub_detail.asp
- - http://www.foxnews.com/us/2017/08/02/dreamer-accused-brutally-raping-woman-in-washington.html
- - http://www.heritage.org/
- - http://www.heritage.org/Research/HealthCare/wm1714.cfm
- - http://www.heritage.org/Research/Immigration/bg1936.cfm
- - http://www.heritage.org/Research/Immigration/lm25.cfm
- - http://www.heritage.org/Research/Immigration/tst052107a.cfm
- - http://www.ice.gov/worksite/
- - http://www.irli.org/
- - http://www.judicialwatch.org/wp-content/uploads/2014/02/Judicial-Watch-Special-Illegal-Immigration-Report.pdf
- - http://www.kingcounty.gov/tools/inmate-lookup
- - http://www.legion.org/documents/legion/pdf/illegalimmigration.pdf
- - http://www.manhattaninstitute.org/tools/topical_index.php?topic=49
- - http://www.minutemanhq.com/
- - http://www.numbersusa.org/
- - http://www.ojjpac.org/sanctuary.asp
- - http://www.oregonir.org/
- - http://www.securedbordersusa.com/
- - http://www.sos.wa.gov/elections/initiatives/Initiatives.aspx?y=2014&t=p
- - http://www.soundpolitics.com/
- - http://www.soundpolitics.com/voterlookup.html
- - http://www.thesocialcontract.com/
- - http://www.thesocialcontract.com/artman2/publish/tsc_18_2/index.shtml
- - http://www.thesocialcontract.com/events/press_conf_2009apr14.html
- - http://www.thesocialcontract.com/reports/eitc_2011apr/earned-income-tax-credit-2011apr.html
- - http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=31b3ab0a43b5d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=db029c7755cb9010VgnVCM10000045f3d6a1RCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=75bce2e261405110VgnVCM1000004718190aRCRD&vgnextchannel=75bce2e261405110VgnVCM1000004718190aRCRD
- - http://www.wfir.org/
- - http://www.wsp.wa.gov/crime/wanted.php
- - http://zip4.usps.com/zip4/welcome.jsp
- - https://cis.org/Jessica-Vaughan-Discusses-Illegal-Aliens-Prisons
- Total external links: 43
- + Email addresses found:
- Total email address found: 0
- + Directories found:
- - http://www.respectwashington.us./legal-documents/ (403 Forbidden)
- - http://www.respectwashington.us./rw-images/ (403 Forbidden)
- - http://www.respectwashington.us./studies-and-reports/ (403 Forbidden)
- Total directories: 3
- + Directory indexing found:
- Total directories with indexing: 0
- ----------------------------------------------------------------------
- + URL to crawl: http://mail.respectwashington.us.
- + Date: 2019-10-22
- + Crawling URL: http://mail.respectwashington.us.:
- + Links:
- + Crawling http://mail.respectwashington.us.
- + Crawling http://mail.respectwashington.us./rwhome.html
- + Crawling http://mail.respectwashington.us./whyweneed.html
- + Crawling http://mail.respectwashington.us./petition.html
- + Crawling http://mail.respectwashington.us./support.html
- + Crawling http://mail.respectwashington.us./donate.html
- + Crawling http://mail.respectwashington.us./testimonials.html
- + Crawling http://mail.respectwashington.us./legal-action.html
- + Crawling http://mail.respectwashington.us./volunteer.html
- + Crawling http://mail.respectwashington.us./contact.html
- + Crawling http://mail.respectwashington.us./MarchPetition (404 Not Found)
- + Crawling http://mail.respectwashington.us./
- + Searching for directories...
- - Found: http://mail.respectwashington.us./rw-images/
- - Found: http://mail.respectwashington.us./studies-and-reports/
- - Found: http://mail.respectwashington.us./legal-documents/
- + Searching open folders...
- - http://mail.respectwashington.us./rw-images/ (403 Forbidden)
- - http://mail.respectwashington.us./studies-and-reports/ (403 Forbidden)
- - http://mail.respectwashington.us./legal-documents/ (403 Forbidden)
- + Crawl finished successfully.
- ----------------------------------------------------------------------
- Summary of http://http://mail.respectwashington.us.
- ----------------------------------------------------------------------
- + Links crawled:
- - http://mail.respectwashington.us.
- - http://mail.respectwashington.us./
- - http://mail.respectwashington.us./MarchPetition (404 Not Found)
- - http://mail.respectwashington.us./contact.html
- - http://mail.respectwashington.us./donate.html
- - http://mail.respectwashington.us./legal-action.html
- - http://mail.respectwashington.us./petition.html
- - http://mail.respectwashington.us./rwhome.html
- - http://mail.respectwashington.us./support.html
- - http://mail.respectwashington.us./testimonials.html
- - http://mail.respectwashington.us./volunteer.html
- - http://mail.respectwashington.us./whyweneed.html
- Total links crawled: 12
- + Links to files found:
- - http://mail.respectwashington.us./001 Diaz-Garcia Child Molest INFORMATION.pdf
- - http://mail.respectwashington.us./001 Diaz-Garcia Rape INFORMATION.pdf
- - http://mail.respectwashington.us./001 Gomez v Spokane Complaint.pdf
- - http://mail.respectwashington.us./022 Gomez v Spokane Status Report.pdf
- - http://mail.respectwashington.us./BurienPolice2016Data.pdf
- - http://mail.respectwashington.us./CheckBackInMarch.pdf
- - http://mail.respectwashington.us./DoC2014CrimeIllegals.jpg
- - http://mail.respectwashington.us./DoC2014CrimeIllegals.pdf
- - http://mail.respectwashington.us./DoJ Incarcerated Aliens 2017.pdf
- - http://mail.respectwashington.us./FAIRWA2012.pdf
- - http://mail.respectwashington.us./GomezSettlement SR 2018.pdf
- - http://mail.respectwashington.us./Oregoneo0722.pdf
- - http://mail.respectwashington.us./Spokane Appellant Opening Brief.pdf
- - http://mail.respectwashington.us./how-to-ArmstrongV2.ppt
- - http://mail.respectwashington.us./legal-documents/DECLARSTEPHENSAG4-18-11424.pdf
- - http://mail.respectwashington.us./legal-documents/GAO2005-478.pdf
- - http://mail.respectwashington.us./legal-documents/KingBRIEFOPToMSJApr18.pdf
- - http://mail.respectwashington.us./legal-documents/KingDefenseFeb2011.pdf
- - http://mail.respectwashington.us./legal-documents/KingDismissMSJMar2011.pdf
- - http://mail.respectwashington.us./legal-documents/KingMSJDismissDeclMar2011.pdf
- - http://mail.respectwashington.us./legal-documents/KingReplySupportDismissMSJApr25.pdf
- - http://mail.respectwashington.us./legal-documents/ORDERGRANTINGKingMSJDis5-10-11.pdf
- - http://mail.respectwashington.us./legal-documents/RingDeclareMar2011.pdf
- - http://mail.respectwashington.us./legal-documents/RingMSJMar2011.pdf
- - http://mail.respectwashington.us./legal-documents/RingOPToKingMSJDisApr18.pdf
- - http://mail.respectwashington.us./legal-documents/RingPetitionNov2010.pdf
- - http://mail.respectwashington.us./legal-documents/RingReplySupportMSjApr25.pdf
- - http://mail.respectwashington.us./legal-documents/RingVRidgeMOTIONHEARING5-10-11.pdf
- - http://mail.respectwashington.us./legal-documents/RingVRidgeOralArgs4-29-11.PDF
- - http://mail.respectwashington.us./legal-documents/RingVRidgeOralDecTrans5-10-11.PDF
- - http://mail.respectwashington.us./legal-documents/Ringhofer v Ridge 679708.wma
- - http://mail.respectwashington.us./legal-documents/RinghoferPetitionReview2013.pdf
- - http://mail.respectwashington.us./legal-documents/SpakovskyHeritage28.pdf
- - http://mail.respectwashington.us./legal-documents/TexasHarrisCountyVoteID.pdf
- - http://mail.respectwashington.us./legal-documents/USHouseAdmin2006Bettencourt.pdf
- - http://mail.respectwashington.us./legal-documents/WSCADwyerOpinon12-10-12.pdf
- - http://mail.respectwashington.us./legal-documents/WSSCAppealOpenBrief-Amended9-6-11.pdf
- - http://mail.respectwashington.us./legal-documents/WSSCAppellantReplyBrief11-14-11.pdf
- - http://mail.respectwashington.us./legal-documents/WSSCDirectReviewGrounds6-24-11.pdf
- - http://mail.respectwashington.us./legal-documents/WSSCOrder88293-5RinghoferVRidge.pdf
- - http://mail.respectwashington.us./legal-documents/WSSCRespondentBrief10-5-11.pdf
- - http://mail.respectwashington.us./legal-documents/WSSCTransfer11-21-11.pdf
- - http://mail.respectwashington.us./rw-images/header-blue-new.jpg
- - http://mail.respectwashington.us./rw-images/keepLegal.gif
- - http://mail.respectwashington.us./rw-style.css
- - http://mail.respectwashington.us./studies-and-reports/11 03 08 FINAL whitepaper.pdf
- - http://mail.respectwashington.us./studies-and-reports/2005DHSHAudit6534.pdf
- - http://mail.respectwashington.us./studies-and-reports/BearStearnsUnderground.pdf
- - http://mail.respectwashington.us./studies-and-reports/FAIRCostStudyWA2012.pdf
- - http://mail.respectwashington.us./studies-and-reports/REAL ID Not National ID Card.pdf
- Total links to files: 50
- + Externals links found:
- - http://community.seattletimes.nwsource.com/archive/?date=20060718&slug=prisonbill18m
- - http://irli.org/
- - http://komonews.com/news/local/charges-woman-bludgeoned-raped-at-burien-apartment-complex
- - http://seattletimes.nwsource.com/html/localnews/2014429238_apwaxgrillegalimmigrantslicenses3rdldwritethru.html
- - http://seattletimes.nwsource.com/html/localnews/2014643197_wagetheft31m.html
- - http://wei.secstate.wa.gov/osos/en/voterinformation/Pages/RegistertoVote.aspx
- - http://www.alipac.us/
- - http://www.burienwa.gov/AgendaCenter/ViewFile/Agenda/_04242017-336
- - http://www.cis.org
- - http://www.fairus.org/site/PageServer
- - http://www.familysecuritymatters.org/
- - http://www.familysecuritymatters.org/publications/id.9984/pub_detail.asp
- - http://www.foxnews.com/us/2017/08/02/dreamer-accused-brutally-raping-woman-in-washington.html
- - http://www.heritage.org/
- - http://www.heritage.org/Research/HealthCare/wm1714.cfm
- - http://www.heritage.org/Research/Immigration/bg1936.cfm
- - http://www.heritage.org/Research/Immigration/lm25.cfm
- - http://www.heritage.org/Research/Immigration/tst052107a.cfm
- - http://www.ice.gov/worksite/
- - http://www.irli.org/
- - http://www.judicialwatch.org/wp-content/uploads/2014/02/Judicial-Watch-Special-Illegal-Immigration-Report.pdf
- - http://www.kingcounty.gov/tools/inmate-lookup
- - http://www.legion.org/documents/legion/pdf/illegalimmigration.pdf
- - http://www.manhattaninstitute.org/tools/topical_index.php?topic=49
- - http://www.minutemanhq.com/
- - http://www.numbersusa.org/
- - http://www.ojjpac.org/sanctuary.asp
- - http://www.oregonir.org/
- - http://www.securedbordersusa.com/
- - http://www.sos.wa.gov/elections/initiatives/Initiatives.aspx?y=2014&t=p
- - http://www.soundpolitics.com/
- - http://www.soundpolitics.com/voterlookup.html
- - http://www.thesocialcontract.com/
- - http://www.thesocialcontract.com/artman2/publish/tsc_18_2/index.shtml
- - http://www.thesocialcontract.com/events/press_conf_2009apr14.html
- - http://www.thesocialcontract.com/reports/eitc_2011apr/earned-income-tax-credit-2011apr.html
- - http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=31b3ab0a43b5d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=db029c7755cb9010VgnVCM10000045f3d6a1RCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=75bce2e261405110VgnVCM1000004718190aRCRD&vgnextchannel=75bce2e261405110VgnVCM1000004718190aRCRD
- - http://www.wfir.org/
- - http://www.wsp.wa.gov/crime/wanted.php
- - http://zip4.usps.com/zip4/welcome.jsp
- - https://cis.org/Jessica-Vaughan-Discusses-Illegal-Aliens-Prisons
- Total external links: 43
- + Email addresses found:
- Total email address found: 0
- + Directories found:
- - http://mail.respectwashington.us./legal-documents/ (403 Forbidden)
- - http://mail.respectwashington.us./rw-images/ (403 Forbidden)
- - http://mail.respectwashington.us./studies-and-reports/ (403 Forbidden)
- Total directories: 3
- + Directory indexing found:
- Total directories with indexing: 0
- ----------------------------------------------------------------------
- + URL to crawl: http://respectwashington.us
- + Date: 2019-10-22
- + Crawling URL: http://respectwashington.us:
- + Links:
- + Crawling http://respectwashington.us
- + Crawling http://respectwashington.us/rwhome.html
- + Crawling http://respectwashington.us/whyweneed.html
- + Crawling http://respectwashington.us/petition.html
- + Crawling http://respectwashington.us/support.html
- + Crawling http://respectwashington.us/donate.html
- + Crawling http://respectwashington.us/testimonials.html
- + Crawling http://respectwashington.us/legal-action.html
- + Crawling http://respectwashington.us/volunteer.html
- + Crawling http://respectwashington.us/contact.html
- + Crawling http://respectwashington.us/MarchPetition (404 Not Found)
- + Crawling http://respectwashington.us/
- + Searching for directories...
- - Found: http://respectwashington.us/rw-images/
- - Found: http://respectwashington.us/studies-and-reports/
- - Found: http://respectwashington.us/legal-documents/
- + Searching open folders...
- - http://respectwashington.us/rw-images/ (403 Forbidden)
- - http://respectwashington.us/studies-and-reports/ (403 Forbidden)
- - http://respectwashington.us/legal-documents/ (403 Forbidden)
- + Crawl finished successfully.
- ----------------------------------------------------------------------
- Summary of http://http://respectwashington.us
- ----------------------------------------------------------------------
- + Links crawled:
- - http://respectwashington.us
- - http://respectwashington.us/
- - http://respectwashington.us/MarchPetition (404 Not Found)
- - http://respectwashington.us/contact.html
- - http://respectwashington.us/donate.html
- - http://respectwashington.us/legal-action.html
- - http://respectwashington.us/petition.html
- - http://respectwashington.us/rwhome.html
- - http://respectwashington.us/support.html
- - http://respectwashington.us/testimonials.html
- - http://respectwashington.us/volunteer.html
- - http://respectwashington.us/whyweneed.html
- Total links crawled: 12
- + Links to files found:
- - http://respectwashington.us/001 Diaz-Garcia Child Molest INFORMATION.pdf
- - http://respectwashington.us/001 Diaz-Garcia Rape INFORMATION.pdf
- - http://respectwashington.us/001 Gomez v Spokane Complaint.pdf
- - http://respectwashington.us/022 Gomez v Spokane Status Report.pdf
- - http://respectwashington.us/BurienPolice2016Data.pdf
- - http://respectwashington.us/CheckBackInMarch.pdf
- - http://respectwashington.us/DoC2014CrimeIllegals.jpg
- - http://respectwashington.us/DoC2014CrimeIllegals.pdf
- - http://respectwashington.us/DoJ Incarcerated Aliens 2017.pdf
- - http://respectwashington.us/FAIRWA2012.pdf
- - http://respectwashington.us/GomezSettlement SR 2018.pdf
- - http://respectwashington.us/Oregoneo0722.pdf
- - http://respectwashington.us/Spokane Appellant Opening Brief.pdf
- - http://respectwashington.us/how-to-ArmstrongV2.ppt
- - http://respectwashington.us/legal-documents/DECLARSTEPHENSAG4-18-11424.pdf
- - http://respectwashington.us/legal-documents/GAO2005-478.pdf
- - http://respectwashington.us/legal-documents/KingBRIEFOPToMSJApr18.pdf
- - http://respectwashington.us/legal-documents/KingDefenseFeb2011.pdf
- - http://respectwashington.us/legal-documents/KingDismissMSJMar2011.pdf
- - http://respectwashington.us/legal-documents/KingMSJDismissDeclMar2011.pdf
- - http://respectwashington.us/legal-documents/KingReplySupportDismissMSJApr25.pdf
- - http://respectwashington.us/legal-documents/ORDERGRANTINGKingMSJDis5-10-11.pdf
- - http://respectwashington.us/legal-documents/RingDeclareMar2011.pdf
- - http://respectwashington.us/legal-documents/RingMSJMar2011.pdf
- - http://respectwashington.us/legal-documents/RingOPToKingMSJDisApr18.pdf
- - http://respectwashington.us/legal-documents/RingPetitionNov2010.pdf
- - http://respectwashington.us/legal-documents/RingReplySupportMSjApr25.pdf
- - http://respectwashington.us/legal-documents/RingVRidgeMOTIONHEARING5-10-11.pdf
- - http://respectwashington.us/legal-documents/RingVRidgeOralArgs4-29-11.PDF
- - http://respectwashington.us/legal-documents/RingVRidgeOralDecTrans5-10-11.PDF
- - http://respectwashington.us/legal-documents/Ringhofer v Ridge 679708.wma
- - http://respectwashington.us/legal-documents/RinghoferPetitionReview2013.pdf
- - http://respectwashington.us/legal-documents/SpakovskyHeritage28.pdf
- - http://respectwashington.us/legal-documents/TexasHarrisCountyVoteID.pdf
- - http://respectwashington.us/legal-documents/USHouseAdmin2006Bettencourt.pdf
- - http://respectwashington.us/legal-documents/WSCADwyerOpinon12-10-12.pdf
- - http://respectwashington.us/legal-documents/WSSCAppealOpenBrief-Amended9-6-11.pdf
- - http://respectwashington.us/legal-documents/WSSCAppellantReplyBrief11-14-11.pdf
- - http://respectwashington.us/legal-documents/WSSCDirectReviewGrounds6-24-11.pdf
- - http://respectwashington.us/legal-documents/WSSCOrder88293-5RinghoferVRidge.pdf
- - http://respectwashington.us/legal-documents/WSSCRespondentBrief10-5-11.pdf
- - http://respectwashington.us/legal-documents/WSSCTransfer11-21-11.pdf
- - http://respectwashington.us/rw-images/header-blue-new.jpg
- - http://respectwashington.us/rw-images/keepLegal.gif
- - http://respectwashington.us/rw-style.css
- - http://respectwashington.us/studies-and-reports/11 03 08 FINAL whitepaper.pdf
- - http://respectwashington.us/studies-and-reports/2005DHSHAudit6534.pdf
- - http://respectwashington.us/studies-and-reports/BearStearnsUnderground.pdf
- - http://respectwashington.us/studies-and-reports/FAIRCostStudyWA2012.pdf
- - http://respectwashington.us/studies-and-reports/REAL ID Not National ID Card.pdf
- Total links to files: 50
- + Externals links found:
- - http://community.seattletimes.nwsource.com/archive/?date=20060718&slug=prisonbill18m
- - http://irli.org/
- - http://komonews.com/news/local/charges-woman-bludgeoned-raped-at-burien-apartment-complex
- - http://seattletimes.nwsource.com/html/localnews/2014429238_apwaxgrillegalimmigrantslicenses3rdldwritethru.html
- - http://seattletimes.nwsource.com/html/localnews/2014643197_wagetheft31m.html
- - http://wei.secstate.wa.gov/osos/en/voterinformation/Pages/RegistertoVote.aspx
- - http://www.alipac.us/
- - http://www.burienwa.gov/AgendaCenter/ViewFile/Agenda/_04242017-336
- - http://www.cis.org
- - http://www.fairus.org/site/PageServer
- - http://www.familysecuritymatters.org/
- - http://www.familysecuritymatters.org/publications/id.9984/pub_detail.asp
- - http://www.foxnews.com/us/2017/08/02/dreamer-accused-brutally-raping-woman-in-washington.html
- - http://www.heritage.org/
- - http://www.heritage.org/Research/HealthCare/wm1714.cfm
- - http://www.heritage.org/Research/Immigration/bg1936.cfm
- - http://www.heritage.org/Research/Immigration/lm25.cfm
- - http://www.heritage.org/Research/Immigration/tst052107a.cfm
- - http://www.ice.gov/worksite/
- - http://www.irli.org/
- - http://www.judicialwatch.org/wp-content/uploads/2014/02/Judicial-Watch-Special-Illegal-Immigration-Report.pdf
- - http://www.kingcounty.gov/tools/inmate-lookup
- - http://www.legion.org/documents/legion/pdf/illegalimmigration.pdf
- - http://www.manhattaninstitute.org/tools/topical_index.php?topic=49
- - http://www.minutemanhq.com/
- - http://www.numbersusa.org/
- - http://www.ojjpac.org/sanctuary.asp
- - http://www.oregonir.org/
- - http://www.securedbordersusa.com/
- - http://www.sos.wa.gov/elections/initiatives/Initiatives.aspx?y=2014&t=p
- - http://www.soundpolitics.com/
- - http://www.soundpolitics.com/voterlookup.html
- - http://www.thesocialcontract.com/
- - http://www.thesocialcontract.com/artman2/publish/tsc_18_2/index.shtml
- - http://www.thesocialcontract.com/events/press_conf_2009apr14.html
- - http://www.thesocialcontract.com/reports/eitc_2011apr/earned-income-tax-credit-2011apr.html
- - http://www.uscis.gov/portal/site/uscis/menuitem.5af9bb95919f35e66f614176543f6d1a/?vgnextoid=31b3ab0a43b5d010VgnVCM10000048f3d6a1RCRD&vgnextchannel=db029c7755cb9010VgnVCM10000045f3d6a1RCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=1721c2ec0c7c8110VgnVCM1000004718190aRCRD&vgnextchannel=1721c2ec0c7c8110VgnVCM1000004718190aRCRD
- - http://www.uscis.gov/portal/site/uscis/menuitem.eb1d4c2a3e5b9ac89243c6a7543f6d1a/?vgnextoid=75bce2e261405110VgnVCM1000004718190aRCRD&vgnextchannel=75bce2e261405110VgnVCM1000004718190aRCRD
- - http://www.wfir.org/
- - http://www.wsp.wa.gov/crime/wanted.php
- - http://zip4.usps.com/zip4/welcome.jsp
- - https://cis.org/Jessica-Vaughan-Discusses-Illegal-Aliens-Prisons
- Total external links: 43
- + Email addresses found:
- Total email address found: 1
- + Directories found:
- - http://respectwashington.us/legal-documents/ (403 Forbidden)
- - http://respectwashington.us/rw-images/ (403 Forbidden)
- - http://respectwashington.us/studies-and-reports/ (403 Forbidden)
- Total directories: 3
- + Directory indexing found:
- Total directories with indexing: 0
- ----------------------------------------------------------------------
- + URL to crawl: https://ftp.respectwashington.us.
- + Date: 2019-10-22
- + Crawling URL: https://ftp.respectwashington.us.:
- + Links:
- + Crawling https://ftp.respectwashington.us.
- + Searching for directories...
- + Searching open folders...
- + URL to crawl: https://www.respectwashington.us.
- + Date: 2019-10-22
- + Crawling URL: https://www.respectwashington.us.:
- + Links:
- + Crawling https://www.respectwashington.us.
- + Searching for directories...
- + Searching open folders...
- + URL to crawl: https://mail.respectwashington.us.
- + Date: 2019-10-22
- + Crawling URL: https://mail.respectwashington.us.:
- + Links:
- + Crawling https://mail.respectwashington.us.
- + Searching for directories...
- + Searching open folders...
- + URL to crawl: https://respectwashington.us
- + Date: 2019-10-22
- + Crawling URL: https://respectwashington.us:
- + Links:
- + Crawling https://respectwashington.us (403 Forbidden)
- + Searching for directories...
- + Searching open folders...
- --Finished--
- Summary information for domain respectwashington.us.
- -----------------------------------------
- Domain Specific Information:
- Email: [email protected]]
- Domain Ips Information:
- IP: 216.218.131.2
- HostName: ns2.he.net Type: NS
- HostName: ns2.he.net Type: PTR
- Country: United States
- Is Active: True (echo-reply ttl 57)
- Port: 53/tcp open domain syn-ack ttl 57 PowerDNS 3.3 or later
- Script Info: | dns-nsid:
- Script Info: | NSID: ns2.he.net (6e73322e68652e6e6574)
- Script Info: | id.server: ns2.he.net
- Script Info: |_ bind.version: Served by PowerDNS - https://www.powerdns.com/
- IP: 65.49.16.26
- HostName: respectwashington.us Type: MX
- HostName: respectwashington.us Type: PTR
- HostName: www.respectwashington.us. Type: A
- HostName: ftp.respectwashington.us. Type: A
- HostName: mail.respectwashington.us. Type: A
- Country: United States
- Is Active: True (reset ttl 64)
- Port: 80/tcp open http syn-ack ttl 53 Apache httpd 2.4.18 ((Ubuntu))
- Script Info: | http-methods:
- Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
- Script Info: |_http-server-header: Apache/2.4.18 (Ubuntu)
- Script Info: |_http-title: RespectWashington
- Port: 110/tcp open pop3 syn-ack ttl 53 Dovecot pop3d
- Script Info: |_pop3-capabilities: TOP CAPA UIDL USER PIPELINING SASL(PLAIN LOGIN) RESP-CODES STLS AUTH-RESP-CODE
- Script Info: |_ssl-date: TLS randomness does not represent time
- Port: 143/tcp open imap syn-ack ttl 53 Dovecot imapd
- Script Info: |_imap-capabilities: STARTTLS AUTH=PLAIN capabilities more listed IMAP4rev1 Pre-login LOGIN-REFERRALS SASL-IR OK post-login AUTH=LOGINA0001 IDLE have ENABLE ID LITERAL+
- Script Info: |_ssl-date: TLS randomness does not represent time
- Port: 443/tcp open ssl/http syn-ack ttl 53 Apache httpd 2.4.18
- Script Info: | http-methods:
- Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
- Script Info: |_http-server-header: Apache/2.4.18 (Ubuntu)
- Script Info: |_http-title: 400 Bad Request
- Script Info: | ssl-cert: Subject: commonName=respectwashington.us
- Script Info: | Subject Alternative Name: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
- Script Info: | Public Key type: rsa
- Script Info: | Public Key bits: 2048
- Script Info: | Signature Algorithm: sha256WithRSAEncryption
- Script Info: | Not valid before: 2019-09-23T10:50:34
- Script Info: | Not valid after: 2019-12-22T10:50:34
- Script Info: | MD5: 9c61 f3dc 6487 544c de9e 4197 e08a 5fa7
- Script Info: |_SHA-1: f98a 5fd3 ac38 2278 6c2f 81cf 471a e5b9 4540 febf
- Script Info: |_ssl-date: TLS randomness does not represent time
- Script Info: | tls-alpn:
- Script Info: |_ http/1.1
- Port: 465/tcp open ssl/smtp syn-ack ttl 53 Postfix smtpd
- Script Info: |_smtp-commands: Couldn't establish connection on port 465
- Script Info: | ssl-cert: Subject: commonName=respectwashington.us
- Script Info: | Subject Alternative Name: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
- Script Info: | Public Key type: rsa
- Script Info: | Public Key bits: 2048
- Script Info: | Signature Algorithm: sha256WithRSAEncryption
- Script Info: | Not valid before: 2019-09-23T10:50:34
- Script Info: | Not valid after: 2019-12-22T10:50:34
- Script Info: | MD5: 9c61 f3dc 6487 544c de9e 4197 e08a 5fa7
- Script Info: |_SHA-1: f98a 5fd3 ac38 2278 6c2f 81cf 471a e5b9 4540 febf
- Script Info: |_ssl-date: TLS randomness does not represent time
- Port: 587/tcp open smtp syn-ack ttl 53 Postfix smtpd
- Script Info: |_smtp-commands: respectwashington.us Hello nmap.scanme.org, STARTTLS, HELP,
- Script Info: | ssl-cert: Subject: commonName=respectwashington.us
- Script Info: | Subject Alternative Name: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
- Script Info: | Public Key type: rsa
- Script Info: | Public Key bits: 2048
- Script Info: | Signature Algorithm: sha256WithRSAEncryption
- Script Info: | Not valid before: 2019-09-23T10:50:34
- Script Info: | Not valid after: 2019-12-22T10:50:34
- Script Info: | MD5: 9c61 f3dc 6487 544c de9e 4197 e08a 5fa7
- Script Info: |_SHA-1: f98a 5fd3 ac38 2278 6c2f 81cf 471a e5b9 4540 febf
- Script Info: |_ssl-date: TLS randomness does not represent time
- Port: 993/tcp open ssl/imaps? syn-ack ttl 53
- Script Info: |_ssl-date: TLS randomness does not represent time
- Port: 995/tcp open ssl/pop3s? syn-ack ttl 53
- Script Info: |_ssl-date: TLS randomness does not represent time
- Os Info: Hosts: www.respectwashington.us, respectwashington.us
- IP: 216.218.130.2
- HostName: ns1.he.net Type: NS
- HostName: ns1.he.net Type: PTR
- Country: United States
- Is Active: True (reset ttl 64)
- Port: 53/tcp open domain syn-ack ttl 57 PowerDNS 3.3 or later
- Script Info: | dns-nsid:
- Script Info: | NSID: ns1.he.net (6e73312e68652e6e6574)
- Script Info: | id.server: ns1.he.net
- Script Info: |_ bind.version: Served by PowerDNS - https://www.powerdns.com/
- #######################################################################################################################################
- dnsenum VERSION:1.2.6
- ----- www.respectwashington.us -----
- Host's addresses:
- __________________
- respectwashington.us. 84126 IN A 65.49.16.26
- Name Servers:
- ______________
- ns2.he.net. 85380 IN A 216.218.131.2
- ns1.he.net. 84853 IN A 216.218.130.2
- Mail (MX) Servers:
- ___________________
- respectwashington.us. 84125 IN A 65.49.16.26
- Trying Zone Transfers and getting Bind Versions:
- _________________________________________________
- Trying Zone Transfer for www.respectwashington.us on ns2.he.net ...
- Trying Zone Transfer for www.respectwashington.us on ns1.he.net ...
- Brute forcing with /usr/share/dnsenum/dns.txt:
- _______________________________________________
- www.respectwashington.us class C netranges:
- ____________________________________________
- Performing reverse lookup on 0 ip addresses:
- _____________________________________________
- 0 results out of 0 IP addresses.
- www.respectwashington.us ip blocks:
- ____________________________________
- ######################################################################################################################################
- [3/100] http://www.respectwashington.us/BurienPolice2016Data.pdf
- [4/100] http://www.respectwashington.us/BurienPetition.pdf
- [5/100] http://www.respectwashington.us/FAIRWA2012.pdf
- [6/100] http://www.respectwashington.us/legal-documents/TexasHarrisCountyVoteID.pdf
- [x] Error in the parsing process
- [7/100] http://www.respectwashington.us/Oregoneo0722.pdf
- [8/100] http://www.respectwashington.us/legal-documents/RingMSJMar2011.pdf
- [x] Error in PDF metadata Creator
- [9/100] http://www.respectwashington.us/legal-documents/KingDismissMSJMar2011.pdf
- [x] Error in PDF metadata Creator
- [10/100] http://www.respectwashington.us/legal-documents/RingDeclareMar2011.pdf
- [x] Error in PDF metadata Creator
- [11/100] http://www.respectwashington.us/legal-documents/KingDefenseFeb2011.pdf
- [x] Error in PDF metadata Creator
- [12/100] http://www.respectwashington.us/legal-documents/SpakovskyHeritage28.pdf
- [13/100] http://www.respectwashington.us/legal-documents/USHouseAdmin2006Bettencourt.pdf
- [14/100] http://www.respectwashington.us/legal-documents/KingMSJDismissDeclMar2011.pdf
- [x] Error in PDF metadata Creator
- [15/100] http://www.respectwashington.us/legal-documents/RingPetitionNov2010.pdf
- [x] Error in PDF metadata Creator
- [16/100] http://www.respectwashington.us/legal-documents/GAO2005-478.pdf
- [17/100] http://www.respectwashington.us/legal-documents/KingReplySupportDismissMSJApr25.pdf
- [x] Error in PDF metadata Creator
- [18/100] http://www.respectwashington.us/studies-and-reports/BearStearnsUnderground.pdf
- [19/100] http://www.respectwashington.us/studies-and-reports/2005DHSHAudit6534.pdf
- [20/100] http://www.respectwashington.us/legal-documents/WSCADwyerOpinon12-10-12.pdf
- [21/100] http://www.respectwashington.us/legal-documents/WSSCDirectReviewGrounds6-24-11.pdf
- [22/100] http://www.respectwashington.us/GomezSettlement%2520SR%25202018.pdf
- [x] Error in the parsing process
- [23/100] http://www.respectwashington.us/legal-documents/WSSCTransfer11-21-11.pdf
- [x] Error in the parsing process
- [24/100] http://www.respectwashington.us/legal-documents/ORDERGRANTINGKingMSJDis5-10-11.pdf
- [x] Error in PDF metadata Creator
- [25/100] http://www.respectwashington.us/legal-documents/WSSCAppealOpenBrief-Amended9-6-11.pdf
- [26/100] http://www.respectwashington.us/legal-documents/DECLARSTEPHENSAG4-18-11424.pdf
- [x] Error in PDF metadata Creator
- [27/100] http://www.respectwashington.us/Spokane%2520Appellant%2520Opening%2520Brief.pdf
- [x] Error in the parsing process
- [28/100] http://www.respectwashington.us/DoJ%2520Incarcerated%2520Aliens%25202017.pdf
- [x] Error in the parsing process
- [29/100] http://www.respectwashington.us/001%2520Diaz-Garcia%2520Rape%2520INFORMATION.pdf
- [x] Error in the parsing process
- [30/100] http://www.respectwashington.us/DoC2014CrimeIllegals.pdf
- [31/100] http://www.respectwashington.us/001%2520Gomez%2520v%2520Spokane%2520Complaint.pdf
- -------------------------------------------------------------------------------------------------
- [+] List of users found:
- -------------------------------------------------------------------------------------------------
- Scott Greenberg
- buglassr
- Tax Office
- U.S. Government Accountability Office, http://www.gao.gov
- nlederer
- wallera
- [+] List of software found:
- -------------------------------------------------------------------------------------------------
- Adobe PDF Library 15.0
- Acrobat PDFMaker 15 for Word
- Adobe PDF Library 9.9
- Adobe InDesign CS5 (7.0)
- QuarkXPress(R) 8.16
- Adobe Acrobat 7.05 Paper Capture Plug-in
- Adobe Acrobat 7.05
- Acrobat Distiller 5.0 (Windows)
- FrameMaker 7.0
- Acrobat Distiller 6.0 (Windows)
- Acrobat PDFMaker 6.0 for Word
- Acrobat Distiller 5.0.5 (Windows)
- Acrobat PDFMaker 5.0 for Word
- activePDF Toolkit (www.activepdf.com)
- PScript5.dll Version 5.2
- Adobe PDF Scan Library 3.1
- ScandAll PRO V2.0.1
- Canon iR3245 PDF
- [+] List of paths and servers found:
- -------------------------------------------------------------------------------------------------
- [+] List of e-mails found:
- -------------------------------------------------------------------------------------------------
- merer@ki
- s@g
- l@k
- ######################################################################################################################################
- [*] Processing domain www.respectwashington.us
- [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
- [+] Getting nameservers
- 216.218.131.2 - ns2.he.net
- 216.218.130.2 - ns1.he.net
- [-] Zone transfer failed
- [+] MX records found, added to target list
- 1 respectwashington.us.
- [*] Scanning www.respectwashington.us for A records
- 65.49.16.26 - www.respectwashington.us
- ######################################################################################################################################
- Privileges have been dropped to "nobody:nogroup" for security reasons.
- Processed queries: 0
- Received packets: 0
- Progress: 0.00% (00 h 00 min 00 sec / 00 h 00 min 00 sec)
- Current incoming rate: 0 pps, average: 0 pps
- Current success rate: 0 pps, average: 0 pps
- Finished total: 0, success: 0 (0.00%)
- Mismatched domains: 0 (0.00%), IDs: 0 (0.00%)
- Failures: 0: 0.00%, 1: 0.00%, 2: 0.00%, 3: 0.00%, 4: 0.00%, 5: 0.00%, 6: 0.00%, 7: 0.00%, 8: 0.00%, 9: 0.00%, 10: 0.00%, 11: 0.00%, 12: 0.00%, 13: 0.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 0 ( 0.00%) | 0 ( 0.00%)
- NXDOMAIN: | 0 ( 0.00%) | 0 ( 0.00%)
- SERVFAIL: | 0 ( 0.00%) | 0 ( 0.00%)
- REFUSED: | 0 ( 0.00%) | 0 ( 0.00%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 318
- Progress: 100.00% (00 h 00 min 01 sec / 00 h 00 min 01 sec)
- Current incoming rate: 317 pps, average: 317 pps
- Current success rate: 233 pps, average: 233 pps
- Finished total: 234, success: 234 (100.00%)
- Mismatched domains: 0 (0.00%), IDs: 0 (0.00%)
- Failures: 0: 35.04%, 1: 750.43%, 2: 34.62%, 3: 0.00%, 4: 0.00%, 5: 0.00%, 6: 0.00%, 7: 0.00%, 8: 0.00%, 9: 0.00%, 10: 0.00%, 11: 0.00%, 12: 0.00%, 13: 0.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 23 ( 9.83%) | 23 ( 7.30%)
- NXDOMAIN: | 202 ( 86.32%) | 202 ( 64.13%)
- SERVFAIL: | 9 ( 3.85%) | 9 ( 2.86%)
- REFUSED: | 0 ( 0.00%) | 81 ( 25.71%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 702
- Progress: 100.00% (00 h 00 min 02 sec / 00 h 00 min 02 sec)
- Current incoming rate: 383 pps, average: 350 pps
- Current success rate: 279 pps, average: 256 pps
- Finished total: 514, success: 514 (100.00%)
- Mismatched domains: 0 (0.00%), IDs: 0 (0.00%)
- Failures: 0: 15.95%, 1: 29.57%, 2: 26.46%, 3: 265.56%, 4: 35.80%, 5: 0.00%, 6: 0.00%, 7: 0.00%, 8: 0.00%, 9: 0.00%, 10: 0.00%, 11: 0.00%, 12: 0.00%, 13: 0.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 46 ( 8.95%) | 46 ( 6.59%)
- NXDOMAIN: | 449 ( 87.35%) | 449 ( 64.33%)
- SERVFAIL: | 19 ( 3.70%) | 19 ( 2.72%)
- REFUSED: | 0 ( 0.00%) | 184 ( 26.36%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 1083
- Progress: 100.00% (00 h 00 min 03 sec / 00 h 00 min 03 sec)
- Current incoming rate: 380 pps, average: 360 pps
- Current success rate: 264 pps, average: 259 pps
- Finished total: 779, success: 779 (100.00%)
- Mismatched domains: 0 (0.00%), IDs: 0 (0.00%)
- Failures: 0: 10.53%, 1: 19.51%, 2: 17.46%, 3: 18.49%, 4: 18.23%, 5: 124.52%, 6: 37.61%, 7: 0.00%, 8: 0.00%, 9: 0.00%, 10: 0.00%, 11: 0.00%, 12: 0.00%, 13: 0.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 63 ( 8.09%) | 63 ( 5.86%)
- NXDOMAIN: | 687 ( 88.19%) | 687 ( 63.91%)
- SERVFAIL: | 29 ( 3.72%) | 29 ( 2.70%)
- REFUSED: | 0 ( 0.00%) | 296 ( 27.53%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 1477
- Progress: 100.00% (00 h 00 min 04 sec / 00 h 00 min 04 sec)
- Current incoming rate: 393 pps, average: 368 pps
- Current success rate: 227 pps, average: 251 pps
- Finished total: 1007, success: 1007 (100.00%)
- Mismatched domains: 77 (5.25%), IDs: 0 (0.00%)
- Failures: 0: 8.14%, 1: 15.09%, 2: 13.51%, 3: 14.30%, 4: 14.10%, 5: 12.71%, 6: 13.41%, 7: 65.34%, 8: 32.97%, 9: 0.99%, 10: 0.00%, 11: 0.00%, 12: 0.00%, 13: 0.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 85 ( 8.44%) | 93 ( 6.34%)
- NXDOMAIN: | 888 ( 88.18%) | 936 ( 63.85%)
- SERVFAIL: | 34 ( 3.38%) | 35 ( 2.39%)
- REFUSED: | 0 ( 0.00%) | 402 ( 27.42%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 1862
- Progress: 100.00% (00 h 00 min 05 sec / 00 h 00 min 05 sec)
- Current incoming rate: 384 pps, average: 371 pps
- Current success rate: 152 pps, average: 231 pps
- Finished total: 1160, success: 1160 (100.00%)
- Mismatched domains: 269 (14.53%), IDs: 0 (0.00%)
- Failures: 0: 7.07%, 1: 13.10%, 2: 11.72%, 3: 12.41%, 4: 12.24%, 5: 11.03%, 6: 11.64%, 7: 6.47%, 8: 5.86%, 9: 45.95%, 10: 26.64%, 11: 1.29%, 12: 0.00%, 13: 0.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 101 ( 8.71%) | 124 ( 6.70%)
- NXDOMAIN: | 1021 ( 88.02%) | 1201 ( 64.88%)
- SERVFAIL: | 38 ( 3.28%) | 43 ( 2.32%)
- REFUSED: | 0 ( 0.00%) | 483 ( 26.09%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 2267
- Progress: 100.00% (00 h 00 min 06 sec / 00 h 00 min 06 sec)
- Current incoming rate: 404 pps, average: 377 pps
- Current success rate: 141 pps, average: 216 pps
- Finished total: 1302, success: 1302 (100.00%)
- Mismatched domains: 464 (20.59%), IDs: 0 (0.00%)
- Failures: 0: 6.30%, 1: 11.67%, 2: 10.45%, 3: 11.06%, 4: 10.91%, 5: 9.83%, 6: 10.37%, 7: 5.76%, 8: 5.22%, 9: 6.30%, 10: 5.38%, 11: 30.49%, 12: 21.66%, 13: 2.00%, 14: 0.00%, 15: 0.00%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 111 ( 8.53%) | 148 ( 6.57%)
- NXDOMAIN: | 1149 ( 88.25%) | 1449 ( 64.29%)
- SERVFAIL: | 42 ( 3.23%) | 54 ( 2.40%)
- REFUSED: | 0 ( 0.00%) | 603 ( 26.75%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 2686
- Progress: 100.00% (00 h 00 min 07 sec / 00 h 00 min 07 sec)
- Current incoming rate: 418 pps, average: 383 pps
- Current success rate: 168 pps, average: 209 pps
- Finished total: 1471, success: 1471 (100.00%)
- Mismatched domains: 678 (25.38%), IDs: 0 (0.00%)
- Failures: 0: 5.57%, 1: 10.33%, 2: 9.25%, 3: 9.79%, 4: 9.65%, 5: 8.70%, 6: 9.18%, 7: 5.10%, 8: 4.62%, 9: 5.57%, 10: 4.76%, 11: 5.37%, 12: 4.55%, 13: 20.46%, 14: 15.43%, 15: 2.11%, 16: 0.00%, 17: 0.00%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 125 ( 8.50%) | 174 ( 6.51%)
- NXDOMAIN: | 1296 ( 88.10%) | 1735 ( 64.96%)
- SERVFAIL: | 50 ( 3.40%) | 70 ( 2.62%)
- REFUSED: | 0 ( 0.00%) | 692 ( 25.91%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 3091
- Progress: 100.00% (00 h 00 min 08 sec / 00 h 00 min 08 sec)
- Current incoming rate: 404 pps, average: 385 pps
- Current success rate: 76 pps, average: 193 pps
- Finished total: 1548, success: 1548 (100.00%)
- Mismatched domains: 971 (31.63%), IDs: 0 (0.00%)
- Failures: 0: 5.30%, 1: 9.82%, 2: 8.79%, 3: 9.30%, 4: 9.17%, 5: 8.27%, 6: 8.72%, 7: 4.84%, 8: 4.39%, 9: 5.30%, 10: 4.52%, 11: 5.10%, 12: 4.33%, 13: 5.75%, 14: 3.29%, 15: 12.14%, 16: 12.40%, 17: 2.52%, 18: 0.00%, 19: 0.00%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 129 ( 8.33%) | 189 ( 6.16%)
- NXDOMAIN: | 1368 ( 88.37%) | 1999 ( 65.11%)
- SERVFAIL: | 51 ( 3.29%) | 79 ( 2.57%)
- REFUSED: | 0 ( 0.00%) | 803 ( 26.16%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 3499
- Progress: 100.00% (00 h 00 min 09 sec / 00 h 00 min 09 sec)
- Current incoming rate: 407 pps, average: 388 pps
- Current success rate: 95 pps, average: 182 pps
- Finished total: 1644, success: 1644 (100.00%)
- Mismatched domains: 1251 (36.03%), IDs: 0 (0.00%)
- Failures: 0: 4.99%, 1: 9.25%, 2: 8.27%, 3: 8.76%, 4: 8.64%, 5: 7.79%, 6: 8.21%, 7: 4.56%, 8: 4.14%, 9: 4.99%, 10: 4.26%, 11: 4.81%, 12: 4.08%, 13: 5.41%, 14: 3.10%, 15: 2.31%, 16: 2.74%, 17: 8.21%, 18: 10.10%, 19: 2.13%, 20: 0.00%, 21: 0.00%, 22: 0.00%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 141 ( 8.58%) | 225 ( 6.48%)
- NXDOMAIN: | 1450 ( 88.20%) | 2256 ( 64.98%)
- SERVFAIL: | 53 ( 3.22%) | 89 ( 2.56%)
- REFUSED: | 0 ( 0.00%) | 902 ( 25.98%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 3874
- Progress: 100.00% (00 h 00 min 10 sec / 00 h 00 min 10 sec)
- Current incoming rate: 374 pps, average: 386 pps
- Current success rate: 71 pps, average: 171 pps
- Finished total: 1716, success: 1716 (100.00%)
- Mismatched domains: 1535 (39.92%), IDs: 0 (0.00%)
- Failures: 0: 4.78%, 1: 8.86%, 2: 7.93%, 3: 8.39%, 4: 8.28%, 5: 7.46%, 6: 7.87%, 7: 4.37%, 8: 3.96%, 9: 4.78%, 10: 4.08%, 11: 4.60%, 12: 3.90%, 13: 5.19%, 14: 2.97%, 15: 2.21%, 16: 2.62%, 17: 2.56%, 18: 2.33%, 19: 6.06%, 20: 6.70%, 21: 1.86%, 22: 0.06%, 23: 0.00%, 24: 0.00%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 147 ( 8.57%) | 249 ( 6.48%)
- NXDOMAIN: | 1514 ( 88.23%) | 2512 ( 65.33%)
- SERVFAIL: | 55 ( 3.21%) | 97 ( 2.52%)
- REFUSED: | 0 ( 0.00%) | 987 ( 25.67%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 4284
- Progress: 100.00% (00 h 00 min 11 sec / 00 h 00 min 11 sec)
- Current incoming rate: 409 pps, average: 388 pps
- Current success rate: 38 pps, average: 159 pps
- Finished total: 1755, success: 1755 (100.00%)
- Mismatched domains: 1890 (44.44%), IDs: 0 (0.00%)
- Failures: 0: 4.67%, 1: 8.66%, 2: 7.75%, 3: 8.21%, 4: 8.09%, 5: 7.29%, 6: 7.69%, 7: 4.27%, 8: 3.87%, 9: 4.67%, 10: 3.99%, 11: 4.50%, 12: 3.82%, 13: 5.07%, 14: 2.91%, 15: 2.17%, 16: 2.56%, 17: 2.51%, 18: 2.28%, 19: 1.94%, 20: 1.08%, 21: 5.07%, 22: 5.01%, 23: 0.97%, 24: 0.28%, 25: 0.00%, 26: 0.00%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 150 ( 8.55%) | 277 ( 6.51%)
- NXDOMAIN: | 1550 ( 88.32%) | 2773 ( 65.20%)
- SERVFAIL: | 55 ( 3.13%) | 109 ( 2.56%)
- REFUSED: | 0 ( 0.00%) | 1094 ( 25.72%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 4689
- Progress: 100.00% (00 h 00 min 12 sec / 00 h 00 min 12 sec)
- Current incoming rate: 404 pps, average: 390 pps
- Current success rate: 18 pps, average: 147 pps
- Finished total: 1774, success: 1774 (100.00%)
- Mismatched domains: 2264 (48.64%), IDs: 0 (0.00%)
- Failures: 0: 4.62%, 1: 8.57%, 2: 7.67%, 3: 8.12%, 4: 8.00%, 5: 7.22%, 6: 7.61%, 7: 4.23%, 8: 3.83%, 9: 4.62%, 10: 3.95%, 11: 4.45%, 12: 3.78%, 13: 5.02%, 14: 2.87%, 15: 2.14%, 16: 2.54%, 17: 2.48%, 18: 2.25%, 19: 1.92%, 20: 1.07%, 21: 1.18%, 22: 0.90%, 23: 4.17%, 24: 4.11%, 25: 0.73%, 26: 0.11%, 27: 0.00%, 28: 0.00%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 150 ( 8.46%) | 296 ( 6.36%)
- NXDOMAIN: | 1568 ( 88.39%) | 3036 ( 65.22%)
- SERVFAIL: | 56 ( 3.16%) | 118 ( 2.53%)
- REFUSED: | 0 ( 0.00%) | 1205 ( 25.89%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 5068
- Progress: 100.00% (00 h 00 min 13 sec / 00 h 00 min 13 sec)
- Current incoming rate: 378 pps, average: 389 pps
- Current success rate: 12 pps, average: 137 pps
- Finished total: 1787, success: 1787 (100.00%)
- Mismatched domains: 2622 (52.14%), IDs: 0 (0.00%)
- Failures: 0: 4.59%, 1: 8.51%, 2: 7.61%, 3: 8.06%, 4: 7.95%, 5: 7.16%, 6: 7.55%, 7: 4.20%, 8: 3.81%, 9: 4.59%, 10: 3.92%, 11: 4.42%, 12: 3.75%, 13: 4.98%, 14: 2.85%, 15: 2.13%, 16: 2.52%, 17: 2.46%, 18: 2.24%, 19: 1.90%, 20: 1.06%, 21: 1.18%, 22: 0.90%, 23: 0.45%, 24: 0.56%, 25: 4.09%, 26: 3.30%, 27: 0.56%, 28: 0.11%, 29: 0.00%, 30: 0.00%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 150 ( 8.39%) | 317 ( 6.30%)
- NXDOMAIN: | 1580 ( 88.42%) | 3286 ( 65.34%)
- SERVFAIL: | 57 ( 3.19%) | 128 ( 2.55%)
- REFUSED: | 0 ( 0.00%) | 1298 ( 25.81%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 5481
- Progress: 100.00% (00 h 00 min 14 sec / 00 h 00 min 14 sec)
- Current incoming rate: 412 pps, average: 390 pps
- Current success rate: 20 pps, average: 128 pps
- Finished total: 1808, success: 1808 (100.00%)
- Mismatched domains: 3006 (55.27%), IDs: 0 (0.00%)
- Failures: 0: 4.54%, 1: 8.41%, 2: 7.52%, 3: 7.96%, 4: 7.85%, 5: 7.08%, 6: 7.47%, 7: 4.15%, 8: 3.76%, 9: 4.54%, 10: 3.87%, 11: 4.37%, 12: 3.71%, 13: 4.92%, 14: 2.82%, 15: 2.10%, 16: 2.49%, 17: 2.43%, 18: 2.21%, 19: 1.88%, 20: 1.05%, 21: 1.16%, 22: 0.88%, 23: 0.44%, 24: 0.55%, 25: 0.44%, 26: 0.50%, 27: 4.31%, 28: 2.10%, 29: 0.50%, 30: 0.11%, 31: 0.00%, 32: 0.00%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 151 ( 8.35%) | 347 ( 6.38%)
- NXDOMAIN: | 1600 ( 88.50%) | 3545 ( 65.18%)
- SERVFAIL: | 57 ( 3.15%) | 135 ( 2.48%)
- REFUSED: | 0 ( 0.00%) | 1412 ( 25.96%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 5885
- Progress: 100.00% (00 h 00 min 15 sec / 00 h 00 min 15 sec)
- Current incoming rate: 403 pps, average: 391 pps
- Current success rate: 26 pps, average: 122 pps
- Finished total: 1835, success: 1835 (100.00%)
- Mismatched domains: 3365 (57.62%), IDs: 0 (0.00%)
- Failures: 0: 4.47%, 1: 8.28%, 2: 7.41%, 3: 7.85%, 4: 7.74%, 5: 6.98%, 6: 7.36%, 7: 4.09%, 8: 3.71%, 9: 4.47%, 10: 3.81%, 11: 4.31%, 12: 3.65%, 13: 4.85%, 14: 2.78%, 15: 2.07%, 16: 2.45%, 17: 2.40%, 18: 2.18%, 19: 1.85%, 20: 1.04%, 21: 1.14%, 22: 0.87%, 23: 0.44%, 24: 0.54%, 25: 0.44%, 26: 0.49%, 27: 0.71%, 28: 0.60%, 29: 3.38%, 30: 1.69%, 31: 0.44%, 32: 0.11%, 33: 0.00%, 34: 0.00%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 153 ( 8.34%) | 368 ( 6.30%)
- NXDOMAIN: | 1625 ( 88.56%) | 3800 ( 65.07%)
- SERVFAIL: | 57 ( 3.11%) | 147 ( 2.52%)
- REFUSED: | 0 ( 0.00%) | 1525 ( 26.11%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 6277
- Progress: 100.00% (00 h 00 min 16 sec / 00 h 00 min 16 sec)
- Current incoming rate: 391 pps, average: 391 pps
- Current success rate: 24 pps, average: 116 pps
- Finished total: 1860, success: 1860 (100.00%)
- Mismatched domains: 3716 (59.65%), IDs: 0 (0.00%)
- Failures: 0: 4.41%, 1: 8.17%, 2: 7.31%, 3: 7.74%, 4: 7.63%, 5: 6.88%, 6: 7.26%, 7: 4.03%, 8: 3.66%, 9: 4.41%, 10: 3.76%, 11: 4.25%, 12: 3.60%, 13: 4.78%, 14: 2.74%, 15: 2.04%, 16: 2.42%, 17: 2.37%, 18: 2.15%, 19: 1.83%, 20: 1.02%, 21: 1.13%, 22: 0.86%, 23: 0.43%, 24: 0.54%, 25: 0.43%, 26: 0.48%, 27: 0.70%, 28: 0.59%, 29: 0.59%, 30: 0.70%, 31: 2.53%, 32: 1.29%, 33: 0.38%, 34: 0.05%, 35: 0.00%, 36: 0.00%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 153 ( 8.23%) | 391 ( 6.28%)
- NXDOMAIN: | 1648 ( 88.60%) | 4046 ( 64.94%)
- SERVFAIL: | 59 ( 3.17%) | 158 ( 2.54%)
- REFUSED: | 0 ( 0.00%) | 1635 ( 26.24%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 6681
- Progress: 100.00% (00 h 00 min 17 sec / 00 h 00 min 17 sec)
- Current incoming rate: 403 pps, average: 392 pps
- Current success rate: 37 pps, average: 111 pps
- Finished total: 1898, success: 1898 (100.00%)
- Mismatched domains: 4058 (61.17%), IDs: 0 (0.00%)
- Failures: 0: 4.32%, 1: 8.01%, 2: 7.17%, 3: 7.59%, 4: 7.48%, 5: 6.74%, 6: 7.11%, 7: 3.95%, 8: 3.58%, 9: 4.32%, 10: 3.69%, 11: 4.16%, 12: 3.53%, 13: 4.69%, 14: 2.69%, 15: 2.00%, 16: 2.37%, 17: 2.32%, 18: 2.11%, 19: 1.79%, 20: 1.00%, 21: 1.11%, 22: 0.84%, 23: 0.42%, 24: 0.53%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.58%, 29: 0.58%, 30: 0.68%, 31: 0.53%, 32: 1.21%, 33: 1.37%, 34: 0.68%, 35: 0.32%, 36: 0.05%, 37: 0.00%, 38: 0.00%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 157 ( 8.27%) | 409 ( 6.17%)
- NXDOMAIN: | 1682 ( 88.62%) | 4295 ( 64.74%)
- SERVFAIL: | 59 ( 3.11%) | 165 ( 2.49%)
- REFUSED: | 0 ( 0.00%) | 1765 ( 26.61%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 7075
- Progress: 100.00% (00 h 00 min 18 sec / 00 h 00 min 18 sec)
- Current incoming rate: 393 pps, average: 392 pps
- Current success rate: 15 pps, average: 106 pps
- Finished total: 1914, success: 1914 (100.00%)
- Mismatched domains: 4430 (63.05%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.94%, 2: 7.11%, 3: 7.52%, 4: 7.42%, 5: 6.69%, 6: 7.05%, 7: 3.92%, 8: 3.55%, 9: 4.28%, 10: 3.66%, 11: 4.13%, 12: 3.50%, 13: 4.65%, 14: 2.66%, 15: 1.99%, 16: 2.35%, 17: 2.30%, 18: 2.09%, 19: 1.78%, 20: 0.99%, 21: 1.10%, 22: 0.84%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.10%, 34: 0.68%, 35: 0.26%, 36: 0.16%, 37: 0.10%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 157 ( 8.20%) | 432 ( 6.15%)
- NXDOMAIN: | 1697 ( 88.66%) | 4556 ( 64.84%)
- SERVFAIL: | 60 ( 3.13%) | 173 ( 2.46%)
- REFUSED: | 0 ( 0.00%) | 1865 ( 26.54%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 7474
- Progress: 100.00% (00 h 00 min 19 sec / 00 h 00 min 19 sec)
- Current incoming rate: 398 pps, average: 392 pps
- Current success rate: 2 pps, average: 100 pps
- Finished total: 1917, success: 1917 (100.00%)
- Mismatched domains: 4819 (64.95%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.93%, 2: 7.09%, 3: 7.51%, 4: 7.41%, 5: 6.68%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.50%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.30%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.10%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.10%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.10%, 38: 0.10%, 39: 0.00%, 40: 0.05%, 41: 0.00%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 453 ( 6.11%)
- NXDOMAIN: | 1699 ( 88.63%) | 4799 ( 64.69%)
- SERVFAIL: | 60 ( 3.13%) | 185 ( 2.49%)
- REFUSED: | 0 ( 0.00%) | 1982 ( 26.72%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 7863
- Progress: 100.00% (00 h 00 min 20 sec / 00 h 00 min 20 sec)
- Current incoming rate: 388 pps, average: 392 pps
- Current success rate: 0 pps, average: 95 pps
- Finished total: 1918, success: 1918 (100.00%)
- Mismatched domains: 5206 (66.68%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.92%, 2: 7.09%, 3: 7.51%, 4: 7.40%, 5: 6.67%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.29%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.05%, 40: 0.00%, 41: 0.05%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 477 ( 6.11%)
- NXDOMAIN: | 1700 ( 88.63%) | 5061 ( 64.83%)
- SERVFAIL: | 60 ( 3.13%) | 195 ( 2.50%)
- REFUSED: | 0 ( 0.00%) | 2074 ( 26.57%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 8056
- Progress: 100.00% (00 h 00 min 21 sec / 00 h 00 min 21 sec)
- Current incoming rate: 192 pps, average: 382 pps
- Current success rate: 0 pps, average: 91 pps
- Finished total: 1918, success: 1918 (100.00%)
- Mismatched domains: 5399 (67.49%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.92%, 2: 7.09%, 3: 7.51%, 4: 7.40%, 5: 6.67%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.29%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.10%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 486 ( 6.07%)
- NXDOMAIN: | 1700 ( 88.63%) | 5202 ( 65.03%)
- SERVFAIL: | 60 ( 3.13%) | 201 ( 2.51%)
- REFUSED: | 0 ( 0.00%) | 2111 ( 26.39%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 8071
- Progress: 100.00% (00 h 00 min 22 sec / 00 h 00 min 22 sec)
- Current incoming rate: 14 pps, average: 366 pps
- Current success rate: 0 pps, average: 87 pps
- Finished total: 1918, success: 1918 (100.00%)
- Mismatched domains: 5414 (67.55%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.92%, 2: 7.09%, 3: 7.51%, 4: 7.40%, 5: 6.67%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.29%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.05%, 42: 0.00%, 43: 0.05%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 486 ( 6.06%)
- NXDOMAIN: | 1700 ( 88.63%) | 5212 ( 65.03%)
- SERVFAIL: | 60 ( 3.13%) | 203 ( 2.53%)
- REFUSED: | 0 ( 0.00%) | 2114 ( 26.38%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 8077
- Progress: 100.00% (00 h 00 min 23 sec / 00 h 00 min 23 sec)
- Current incoming rate: 5 pps, average: 350 pps
- Current success rate: 0 pps, average: 83 pps
- Finished total: 1918, success: 1918 (100.00%)
- Mismatched domains: 5420 (67.57%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.92%, 2: 7.09%, 3: 7.51%, 4: 7.40%, 5: 6.67%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.29%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.05%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.05%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 486 ( 6.06%)
- NXDOMAIN: | 1700 ( 88.63%) | 5214 ( 65.00%)
- SERVFAIL: | 60 ( 3.13%) | 204 ( 2.54%)
- REFUSED: | 0 ( 0.00%) | 2117 ( 26.39%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 8088
- Progress: 100.00% (00 h 00 min 24 sec / 00 h 00 min 24 sec)
- Current incoming rate: 10 pps, average: 336 pps
- Current success rate: 0 pps, average: 79 pps
- Finished total: 1918, success: 1918 (100.00%)
- Mismatched domains: 5431 (67.62%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.92%, 2: 7.09%, 3: 7.51%, 4: 7.40%, 5: 6.67%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.29%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.05%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.05%, 48: 0.00%, 49: 0.00%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 486 ( 6.05%)
- NXDOMAIN: | 1700 ( 88.63%) | 5220 ( 64.99%)
- SERVFAIL: | 60 ( 3.13%) | 208 ( 2.59%)
- REFUSED: | 0 ( 0.00%) | 2118 ( 26.37%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 8095
- Progress: 100.00% (00 h 00 min 25 sec / 00 h 00 min 25 sec)
- Current incoming rate: 6 pps, average: 323 pps
- Current success rate: 0 pps, average: 76 pps
- Finished total: 1918, success: 1918 (100.00%)
- Mismatched domains: 5438 (67.65%), IDs: 0 (0.00%)
- Failures: 0: 4.28%, 1: 7.92%, 2: 7.09%, 3: 7.51%, 4: 7.40%, 5: 6.67%, 6: 7.04%, 7: 3.91%, 8: 3.55%, 9: 4.28%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.35%, 17: 2.29%, 18: 2.09%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.05%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.05%, 50: 0.00%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 486 ( 6.05%)
- NXDOMAIN: | 1700 ( 88.63%) | 5226 ( 65.01%)
- SERVFAIL: | 60 ( 3.13%) | 209 ( 2.60%)
- REFUSED: | 0 ( 0.00%) | 2118 ( 26.35%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- Processed queries: 1919
- Received packets: 8096
- Progress: 100.00% (00 h 00 min 25 sec / 00 h 00 min 25 sec)
- Current incoming rate: 17 pps, average: 322 pps
- Current success rate: 0 pps, average: 76 pps
- Finished total: 1919, success: 1918 (99.95%)
- Mismatched domains: 5439 (67.65%), IDs: 0 (0.00%)
- Failures: 0: 4.27%, 1: 7.92%, 2: 7.09%, 3: 7.50%, 4: 7.40%, 5: 6.67%, 6: 7.03%, 7: 3.91%, 8: 3.54%, 9: 4.27%, 10: 3.65%, 11: 4.12%, 12: 3.49%, 13: 4.64%, 14: 2.66%, 15: 1.98%, 16: 2.34%, 17: 2.29%, 18: 2.08%, 19: 1.77%, 20: 0.99%, 21: 1.09%, 22: 0.83%, 23: 0.42%, 24: 0.52%, 25: 0.42%, 26: 0.47%, 27: 0.68%, 28: 0.57%, 29: 0.57%, 30: 0.68%, 31: 0.52%, 32: 1.20%, 33: 1.09%, 34: 0.68%, 35: 0.21%, 36: 0.16%, 37: 0.05%, 38: 0.10%, 39: 0.00%, 40: 0.00%, 41: 0.05%, 42: 0.00%, 43: 0.00%, 44: 0.00%, 45: 0.00%, 46: 0.00%, 47: 0.00%, 48: 0.00%, 49: 0.00%, 50: 0.05%,
- Response: | Success: | Total:
- OK: | 158 ( 8.24%) | 486 ( 6.04%)
- NXDOMAIN: | 1700 ( 88.63%) | 5226 ( 65.00%)
- SERVFAIL: | 60 ( 3.13%) | 210 ( 2.61%)
- REFUSED: | 0 ( 0.00%) | 2118 ( 26.34%)
- FORMERR: | 0 ( 0.00%) | 0 ( 0.00%)
- www.respectwashington.us
- respectwashington.us.
- ######################################################################################################################################
- [+] www.respectwashington.us has no SPF record!
- [*] No DMARC record found. Looking for organizational record
- [+] No organizational DMARC record
- [+] Spoofing possible for www.respectwashington.us!
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:57 EDT
- Nmap scan report for www.respectwashington.us (65.49.16.26)
- Host is up (0.79s latency).
- rDNS record for 65.49.16.26: respectwashington.us
- Not shown: 992 closed ports
- PORT STATE SERVICE
- 80/tcp open http
- 110/tcp open pop3
- 143/tcp open imap
- 443/tcp open https
- 465/tcp open smtps
- 587/tcp open submission
- 993/tcp open imaps
- 995/tcp open pop3s
- Nmap done: 1 IP address (1 host up) scanned in 3.83 seconds
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:57 EDT
- Nmap scan report for www.respectwashington.us (65.49.16.26)
- Host is up (0.28s latency).
- rDNS record for 65.49.16.26: respectwashington.us
- Not shown: 12 closed ports, 2 filtered ports
- PORT STATE SERVICE
- 2049/udp open|filtered nfs
- Nmap done: 1 IP address (1 host up) scanned in 7.48 seconds
- ######################################################################################################################################
- HTTP/1.1 200 OK
- Date: Tue, 22 Oct 2019 13:57:25 GMT
- Server: Apache/2.4.18 (Ubuntu)
- Last-Modified: Fri, 23 Feb 2018 15:15:28 GMT
- ETag: "8956-565e2a1613be1"
- Accept-Ranges: bytes
- Content-Length: 35158
- Vary: Accept-Encoding
- Content-Type: text/html
- Allow: GET,HEAD,POST,OPTIONS
- ######################################################################################################################################
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Top Nav XXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!--Second row-->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX End Top Nav XXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX About the legislation XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Cost of the legislation XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXX Quote from WA Sate Constitution XXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXX "Keep it Legal" logo XXXXXXXXXXXXXXXXX-->
- <!-- XXXXXXXXXXXXXXXXXX End "Keep it Legal" logo XXXXXXXXXXXXXXXXX-->
- ######################################################################################################################################
- http://www.w3.org/1999/xhtml
- text/css
- -//W3C//DTD XHTML 1.0 Transitional//EN
- #######################################################################################################################################
- http://www.respectwashington.us [200 OK] Apache[2.4.18], Country[UNITED STATES][US], Email[[email protected]], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[65.49.16.26], Title[RespectWashington]
- #######################################################################################################################################
- wig - WebApp Information Gatherer
- Scanning http://www.respectwashington.us...
- _________________ SITE INFO __________________
- IP Title
- 65.49.16.26 RespectWashington
- __________________ VERSION ___________________
- Name Versions Type
- Apache 2.4.18 Platform
- Ubuntu 16.04 OS
- ______________________________________________
- Time: 90.4 sec Urls: 813 Fingerprints: 40401
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:59 EDT
- NSE: Loaded 163 scripts for scanning.
- NSE: Script Pre-scanning.
- Initiating NSE at 09:59
- Completed NSE at 09:59, 0.00s elapsed
- Initiating NSE at 09:59
- Completed NSE at 09:59, 0.00s elapsed
- Initiating Parallel DNS resolution of 1 host. at 09:59
- Completed Parallel DNS resolution of 1 host. at 09:59, 0.03s elapsed
- Initiating SYN Stealth Scan at 09:59
- Scanning www.respectwashington.us (65.49.16.26) [1 port]
- Discovered open port 80/tcp on 65.49.16.26
- Completed SYN Stealth Scan at 09:59, 0.27s elapsed (1 total ports)
- Initiating Service scan at 09:59
- Scanning 1 service on www.respectwashington.us (65.49.16.26)
- Completed Service scan at 09:59, 6.49s elapsed (1 service on 1 host)
- Initiating OS detection (try #1) against www.respectwashington.us (65.49.16.26)
- Retrying OS detection (try #2) against www.respectwashington.us (65.49.16.26)
- Initiating Traceroute at 09:59
- Completed Traceroute at 09:59, 1.32s elapsed
- Initiating Parallel DNS resolution of 11 hosts. at 09:59
- Completed Parallel DNS resolution of 11 hosts. at 09:59, 0.24s elapsed
- NSE: Script scanning 65.49.16.26.
- Initiating NSE at 09:59
- Completed NSE at 10:01, 95.87s elapsed
- Initiating NSE at 10:01
- Completed NSE at 10:01, 1.45s elapsed
- Nmap scan report for www.respectwashington.us (65.49.16.26)
- Host is up (0.30s latency).
- rDNS record for 65.49.16.26: respectwashington.us
- PORT STATE SERVICE VERSION
- 80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
- | http-brute:
- |_ Path "/" does not require authentication
- |_http-chrono: Request times for /; avg: 1578.32ms; min: 1423.87ms; max: 1782.78ms
- | http-csrf:
- | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=www.respectwashington.us
- | Found the following possible CSRF vulnerabilities:
- |
- | Path: http://www.respectwashington.us:80/donate.html
- | Form id:
- |_ Form action: https://www.paypal.com/cgi-bin/webscr
- |_http-date: Tue, 22 Oct 2019 13:59:46 GMT; -1s from local time.
- |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
- |_http-dombased-xss: Couldn't find any DOM based XSS.
- |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
- | http-errors:
- | Spidering limited to: maxpagecount=40; withinhost=www.respectwashington.us
- | Found the following error pages:
- |
- | Error Code: 404
- |_ http://www.respectwashington.us:80/MarchPetition
- |_http-exif-spider: ERROR: Script execution failed (use -d to debug)
- |_http-feed: Couldn't find any feeds.
- |_http-fetch: Please enter the complete path of the directory to save data in.
- | http-fileupload-exploiter:
- |
- | Couldn't find a file-type field.
- |
- |_ Couldn't find a file-type field.
- | http-grep:
- | (1) http://www.respectwashington.us:80/:
- | (1) email:
- | (1) http://www.respectwashington.us:80/volunteer.html:
- | (1) email:
- | (1) http://www.respectwashington.us:80/donate.html:
- | (1) email:
- | (1) http://www.respectwashington.us:80/petition.html:
- | (1) email:
- | (356) http://www.respectwashington.us:80/support.html:
- | (356) email:
- |_ + [email protected]
- | http-headers:
- | Date: Tue, 22 Oct 2019 13:59:43 GMT
- | Server: Apache/2.4.18 (Ubuntu)
- | Last-Modified: Fri, 23 Feb 2018 15:15:28 GMT
- | ETag: "8956-565e2a1613be1"
- | Accept-Ranges: bytes
- | Content-Length: 35158
- | Vary: Accept-Encoding
- | Connection: close
- | Content-Type: text/html
- |
- |_ (Request type: HEAD)
- |_http-jsonp-detection: Couldn't find any JSONP endpoints.
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-mobileversion-checker: No mobile version detected.
- | http-php-version: Logo query returned unknown hash 70292b41bac2f29a9009dbd6b677a696
- |_Credits query returned unknown hash 70292b41bac2f29a9009dbd6b677a696
- |_http-security-headers:
- |_http-server-header: Apache/2.4.18 (Ubuntu)
- | http-sitemap-generator:
- | Directory structure:
- | /
- | Other: 1; css: 1; html: 9; jpg: 1; pdf: 6
- | /rw-images/
- | jpg: 1
- | Longest directory structure:
- | Depth: 1
- | Dir: /rw-images/
- | Total files found (by extension):
- |_ Other: 1; css: 1; html: 9; jpg: 2; pdf: 6
- |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
- |_http-title: RespectWashington
- | http-vhosts:
- |_127 names had status 200
- |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
- |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-xssed: No previously reported XSS vuln.
- | vulners:
- | cpe:/a:apache:http_server:2.4.18:
- | CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
- | CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
- | CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
- | CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
- | CVE-2019-0211 7.2 https://vulners.com/cve/CVE-2019-0211
- | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
- | CVE-2017-15715 6.8 https://vulners.com/cve/CVE-2017-15715
- | CVE-2019-10082 6.4 https://vulners.com/cve/CVE-2019-10082
- | CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
- | CVE-2019-10098 5.8 https://vulners.com/cve/CVE-2019-10098
- | CVE-2019-0220 5.0 https://vulners.com/cve/CVE-2019-0220
- | CVE-2019-0196 5.0 https://vulners.com/cve/CVE-2019-0196
- | CVE-2018-17199 5.0 https://vulners.com/cve/CVE-2018-17199
- | CVE-2018-1333 5.0 https://vulners.com/cve/CVE-2018-1333
- | CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
- | CVE-2017-15710 5.0 https://vulners.com/cve/CVE-2017-15710
- | CVE-2016-8743 5.0 https://vulners.com/cve/CVE-2016-8743
- | CVE-2016-8740 5.0 https://vulners.com/cve/CVE-2016-8740
- | CVE-2016-4979 5.0 https://vulners.com/cve/CVE-2016-4979
- | CVE-2019-0197 4.9 https://vulners.com/cve/CVE-2019-0197
- | CVE-2019-10092 4.3 https://vulners.com/cve/CVE-2019-10092
- | CVE-2018-11763 4.3 https://vulners.com/cve/CVE-2018-11763
- | CVE-2016-4975 4.3 https://vulners.com/cve/CVE-2016-4975
- | CVE-2016-1546 4.3 https://vulners.com/cve/CVE-2016-1546
- | CVE-2018-1283 3.5 https://vulners.com/cve/CVE-2018-1283
- |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
- | vulscan: VulDB - https://vuldb.com:
- | [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
- | [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
- | [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
- | [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
- | [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
- | [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
- | [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
- | [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
- | [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
- | [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
- | [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
- | [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
- | [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
- | [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
- | [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
- | [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
- | [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
- | [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
- | [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
- | [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
- | [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
- | [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
- | [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
- | [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
- | [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
- | [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
- | [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
- | [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
- | [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
- | [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
- | [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
- | [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
- | [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
- | [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
- | [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
- | [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
- | [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
- | [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
- | [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
- | [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
- | [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
- | [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
- | [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
- | [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
- | [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
- | [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
- | [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
- | [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
- | [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
- | [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
- | [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
- | [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
- | [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
- | [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
- | [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
- | [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
- | [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
- | [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
- | [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
- | [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
- | [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
- | [15177] PHP Apache 2 Local Denial of Service Vulnerability
- | [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
- | [5816] Apache 2 mod_dav Denial Of Service Vulnerability
- | [5486] Apache 2.0 CGI Path Disclosure Vulnerability
- | [5485] Apache 2.0 Path Disclosure Vulnerability
- | [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
- | [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
- | [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
- | [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [75211] Debian GNU/Linux apache 2 cross-site scripting
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
- | [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
- | [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
- | [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
- | [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
- | [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
- | [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
- | [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
- | [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
- | [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
- | [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
- | [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
- | [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
- | [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
- | [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
- | [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
- | [21719] Apache 2.0 Path Disclosure Vulnerability
- | [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
- | [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
- | [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
- | [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
- | [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
- | [17691] Apache Struts < 2.2.0 - Remote Command Execution
- | [15319] Apache 2.2 (Windows) Local Denial of Service
- | [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
- | [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
- | [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
- | [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
- | [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
- | [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
- | [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
- | [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
- | [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
- | [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
- | [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
- | [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
- | [9] Apache HTTP Server 2.x Memory Leak Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [855524] Solaris Update for Apache 2 120544-14
- | [855077] Solaris Update for Apache 2 120543-14
- | [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
- | [72626] Debian Security Advisory DSA 2579-1 (apache2)
- | [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
- | [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
- | [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
- | [71256] Debian Security Advisory DSA 2452-1 (apache2)
- | [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
- | [70724] Debian Security Advisory DSA 2405-1 (apache2)
- | [70235] Debian Security Advisory DSA 2298-2 (apache2)
- | [70233] Debian Security Advisory DSA 2298-1 (apache2)
- | [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
- | [69338] Debian Security Advisory DSA 2202-1 (apache2)
- | [65131] SLES9: Security update for Apache 2 oes/CORE
- | [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
- | [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
- | [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
- | [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
- | [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
- | [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
- | [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
- | [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
- | [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
- | [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
- | [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
- | [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
- | [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
- | [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
- | [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
- | [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
- | [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
- | [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
- | [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
- | [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
- | [11092] Apache 2.0.39 Win32 directory traversal
- | [66081] SLES11: Security update for Apache 2
- | [66074] SLES10: Security update for Apache 2
- | [66070] SLES9: Security update for Apache 2
- | [65893] SLES10: Security update for Apache 2
- | [65888] SLES10: Security update for Apache 2
- | [65510] SLES9: Security update for Apache 2
- | [65249] SLES9: Security update for Apache 2
- | [65230] SLES9: Security update for Apache 2
- | [65228] SLES9: Security update for Apache 2
- | [65207] SLES9: Security update for Apache 2
- | [65136] SLES9: Security update for Apache 2
- | [65017] SLES9: Security update for Apache 2
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
- | [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
- | [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
- | [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
- | [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
- |
- | OSVDB - http://www.osvdb.org:
- | [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
- |_
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Aggressive OS guesses: Linux 3.18 (99%), Linux 2.6.35 (98%), Tandberg VCS video conferencing system (98%), Synology DiskStation Manager 5.1 (98%), Linux 3.10 - 3.12 (98%), Linux 4.4 (98%), Linux 2.6.32 (97%), Linux 2.6.32 or 3.10 (97%), Linux 2.6.39 (97%), Linux 3.10 (97%)
- No exact OS matches for host (test conditions non-ideal).
- Uptime guess: 40.651 days (since Wed Sep 11 18:23:43 2019)
- Network Distance: 11 hops
- TCP Sequence Prediction: Difficulty=262 (Good luck!)
- IP ID Sequence Generation: All zeros
- TRACEROUTE (using port 80/tcp)
- HOP RTT ADDRESS
- 1 193.79 ms 10.252.204.1
- 2 336.66 ms 45.131.4.3
- 3 336.62 ms 109.236.95.228
- 4 336.70 ms 109.236.95.167
- 5 336.72 ms amsix-200gbps.core1.ams1.he.net (80.249.209.150)
- 6 336.75 ms 100ge16-1.core1.lon2.he.net (72.52.92.213)
- 7 336.79 ms 100ge13-2.core1.nyc4.he.net (72.52.92.166)
- 8 436.58 ms 100ge8-1.core1.sjc2.he.net (184.105.81.218)
- 9 308.61 ms 100ge13-2.core1.sjc1.he.net (184.105.65.113)
- 10 436.64 ms e0-50.core4.fmt1.he.net (184.105.65.214)
- 11 236.08 ms respectwashington.us (65.49.16.26)
- NSE: Script Post-scanning.
- Initiating NSE at 10:01
- Completed NSE at 10:01, 0.00s elapsed
- Initiating NSE at 10:01
- Completed NSE at 10:01, 0.00s elapsed
- ######################################################################################################################################
- ------------------------------------------------------------------------------------------------------------------------
- [ ! ] Starting SCANNER INURLBR 2.1 at [22-10-2019 10:01:37]
- [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
- It is the end user's responsibility to obey all applicable local, state and federal laws.
- Developers assume no liability and are not responsible for any misuse or damage caused by this program
- [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/www.respectwashington.us/output/inurlbr-www.respectwashington.us ]
- [ INFO ][ DORK ]::[ site:www.respectwashington.us ]
- [ INFO ][ SEARCHING ]:: {
- [ INFO ][ ENGINE ]::[ GOOGLE - www.google.dm ]
- [ INFO ][ SEARCHING ]::
- -[:::]
- [ INFO ][ ENGINE ]::[ GOOGLE API ]
- [ INFO ][ SEARCHING ]::
- -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
- [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.dz ID: 006748068166572874491:55ez0c3j3ey ]
- [ INFO ][ SEARCHING ]::
- -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
- [ INFO ][ TOTAL FOUND VALUES ]:: [ 42 ]
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 0 / 42 ]-[10:01:57] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/ ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 1 / 42 ]-[10:02:00] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/petition.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 2 / 42 ]-[10:02:02] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/support.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 3 / 42 ]-[10:02:04] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/testimonials.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 4 / 42 ]-[10:02:06] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/whyweneed.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 5 / 42 ]-[10:02:08] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/volunteer.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 6 / 42 ]-[10:02:10] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/donate.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 7 / 42 ]-[10:02:11] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/contact.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 8 / 42 ]-[10:02:14] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-action.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 9 / 42 ]-[10:02:19] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/BurienPolice2016Data.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 10 / 42 ]-[10:02:23] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/BurienPetition.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 11 / 42 ]-[10:02:28] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/FAIRWA2012.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 12 / 42 ]-[10:02:31] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/TexasHarrisCountyVoteID.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 13 / 42 ]-[10:02:34] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/Oregoneo0722.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 14 / 42 ]-[10:02:40] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/RingMSJMar2011.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 15 / 42 ]-[10:02:46] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/KingDismissMSJMar2011.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 16 / 42 ]-[10:02:51] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/RingDeclareMar2011.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 17 / 42 ]-[10:02:57] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/KingDefenseFeb2011.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 18 / 42 ]-[10:03:03] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/SpakovskyHeritage28.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 19 / 42 ]-[10:03:05] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/USHouseAdmin2006Bettencourt.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 20 / 42 ]-[10:03:11] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/KingMSJDismissDeclMar2011.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 21 / 42 ]-[10:03:17] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/RingPetitionNov2010.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 22 / 42 ]-[10:03:23] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/GAO2005-478.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 23 / 42 ]-[10:03:28] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/KingReplySupportDismissMSJApr25.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 24 / 42 ]-[10:03:32] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/studies-and-reports/BearStearnsUnderground.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 25 / 42 ]-[10:03:37] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/studies-and-reports/2005DHSHAudit6534.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 26 / 42 ]-[10:03:42] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/WSCADwyerOpinon12-10-12.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 27 / 42 ]-[10:03:47] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/WSSCDirectReviewGrounds6-24-11.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 28 / 42 ]-[10:03:49] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/GomezSettlement SR 2018.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 29 / 42 ]-[10:03:52] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/WSSCTransfer11-21-11.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 30 / 42 ]-[10:03:54] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/ORDERGRANTINGKingMSJDis5-10-11.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 31 / 42 ]-[10:04:00] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/WSSCAppealOpenBrief-Amended9-6-11.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 32 / 42 ]-[10:04:04] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/legal-documents/DECLARSTEPHENSAG4-18-11424.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 33 / 42 ]-[10:04:06] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/Spokane Appellant Opening Brief.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 34 / 42 ]-[10:04:08] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/DoJ Incarcerated Aliens 2017.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 35 / 42 ]-[10:04:09] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/001 Diaz-Garcia Rape INFORMATION.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 36 / 42 ]-[10:04:12] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/DoC2014CrimeIllegals.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 37 / 42 ]-[10:04:14] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/001 Gomez v Spokane Complaint.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 38 / 42 ]-[10:04:15] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/001 Diaz-Garcia Child Molest INFORMATION.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 39 / 42 ]-[10:04:17] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/022 Gomez v Spokane Status Report.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 40 / 42 ]-[10:04:19] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/studies-and-reports/11 03 08 FINAL whitepaper.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 41 / 42 ]-[10:04:21] [ - ]
- |_[ + ] Target:: [ http://www.respectwashington.us/studies-and-reports/REAL ID Not National ID Card.pdf ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 400 Bad Request, Server: Apache/2.4.18 (Ubuntu) , IP:65.49.16.26:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- [ INFO ] [ Shutting down ]
- [ INFO ] [ End of process INURLBR at [22-10-2019 10:04:21]
- [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
- [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/www.respectwashington.us/output/inurlbr-www.respectwashington.us ]
- |_________________________________________________________________________________________
- \_________________________________________________________________________________________/
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 10:04 EDT
- Nmap scan report for www.respectwashington.us (65.49.16.26)
- Host is up (0.32s latency).
- rDNS record for 65.49.16.26: respectwashington.us
- PORT STATE SERVICE VERSION
- 110/tcp open pop3 Dovecot pop3d
- | pop3-brute:
- | Accounts: No valid accounts found
- | Statistics: Performed 45 guesses in 35 seconds, average tps: 1.3
- |_ ERROR: Failed to connect.
- |_pop3-capabilities: STLS AUTH-RESP-CODE SASL(PLAIN LOGIN) TOP CAPA UIDL RESP-CODES USER PIPELINING
- | vulscan: VulDB - https://vuldb.com:
- | [139289] cPanel up to 68.0.14 dovecot-xaps-plugin Format privilege escalation
- | [134480] Dovecot up to 2.3.5.2 Submission-Login Crash denial of service
- | [134479] Dovecot up to 2.3.5.2 IMAP Server Crash denial of service
- | [134024] Dovecot up to 2.3.5.1 JSON Encoder Username Crash denial of service
- | [132543] Dovecot up to 2.2.36.0/2.3.4.0 Certificate Impersonation weak authentication
- | [119762] Dovecot up to 2.2.28 dict Authentication var_expand() denial of service
- | [114012] Dovecot up to 2.2.33 TLS SNI Restart denial of service
- | [114009] Dovecot SMTP Delivery Email Message Out-of-Bounds memory corruption
- | [112447] Dovecot up to 2.2.33/2.3.0 SASL Auth Memory Leak denial of service
- | [106837] Dovecot up to 2.2.16 ssl-proxy-openssl.c ssl-proxy-opensslc denial of service
- | [97052] Dovecot up to 2.2.26 auth-policy Unset Crash denial of service
- | [69835] Dovecot 2.2.0/2.2.1 denial of service
- | [13348] Dovecot up to 1.2.15/2.1.15 IMAP4/POP3 SSL/TLS Handshake denial of service
- | [65684] Dovecot up to 2.2.6 unknown vulnerability
- | [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer privilege escalation
- | [63692] Dovecot up to 2.0.15 spoofing
- | [7062] Dovecot 2.1.10 mail-search.c denial of service
- | [57517] Dovecot up to 2.0.12 Login directory traversal
- | [57516] Dovecot up to 2.0.12 Access Restriction directory traversal
- | [57515] Dovecot up to 2.0.12 Crash denial of service
- | [54944] Dovecot up to 1.2.14 denial of service
- | [54943] Dovecot up to 1.2.14 Access Restriction Symlink privilege escalation
- | [54942] Dovecot up to 2.0.4 Access Restriction denial of service
- | [54941] Dovecot up to 2.0.4 Access Restriction unknown vulnerability
- | [54840] Dovecot up to 1.2.12 AGate unknown vulnerability
- | [53277] Dovecot up to 1.2.10 denial of service
- | [50082] Dovecot up to 1.1.6 Stack-based memory corruption
- | [45256] Dovecot up to 1.1.5 directory traversal
- | [44846] Dovecot 1.1.4/1.1.5 IMAP Client Crash denial of service
- | [44546] Dovecot up to 1.0.x Access Restriction unknown vulnerability
- | [44545] Dovecot up to 1.0.x Access Restriction unknown vulnerability
- | [41430] Dovecot 1.0.12/1.1 Locking unknown vulnerability
- | [40356] Dovecot 1.0.9 Cache unknown vulnerability
- | [38222] Dovecot 1.0.2 directory traversal
- | [36376] Dovecot up to 1.0.x directory traversal
- | [33332] Timo Sirainen Dovecot up to 1.0test53 Off-By-One memory corruption
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
- | [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
- | [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
- | [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
- | [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
- | [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
- | [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
- | [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
- | [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
- | [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
- | [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
- | [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
- | [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
- | [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
- | [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
- | [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
- | [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
- | [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
- | [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
- | [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
- | [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
- | [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
- | [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
- | [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
- | [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
- | [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
- | [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
- | [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
- | [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
- | [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
- | [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
- | [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
- | [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
- | [CVE-2002-0925] Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
- | [CVE-2001-0143] vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
- | [CVE-2000-1197] POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
- | [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [103201] Dovecot CVE-2017-14461 Out-Of-Bounds Read Information Disclosure Vulnerability
- | [97536] Dovecot CVE-2017-2669 Denial of Service Vulnerability
- | [94639] Dovecot Auth Component CVE-2016-8652 Denial of Service Vulnerability
- | [91175] Dovecot CVE-2016-4982 Local Information Disclosure Vulnerability
- | [84736] Dovecot CVE-2008-4870 Local Security Vulnerability
- | [74335] Dovecot 'ssl-proxy-openssl.c' Remote Denial of Service Vulnerability
- | [67306] Dovecot Denial of Service Vulnerability
- | [67219] akpop3d 'pszQuery' Remote Memory Corruption Vulnerability
- | [63367] Dovecot Checkpassword Authentication Protocol Local Authentication Bypass Vulnerability
- | [61763] RETIRED: Dovecot 'LIST' Command Denial of Service Vulnerability
- | [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
- | [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
- | [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
- | [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
- | [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
- | [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
- | [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
- | [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
- | [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
- | [39838] tpop3d Remote Denial of Service Vulnerability
- | [39258] Dovecot Service Control Access List Security Bypass Vulnerability
- | [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
- | [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
- | [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
- | [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
- | [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
- | [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
- | [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
- | [27093] Dovecot Authentication Cache Security Bypass Vulnerability
- | [25182] Dovecot ACL Plugin Security Bypass Vulnerability
- | [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
- | [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
- | [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
- | [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
- | [17961] Dovecot Remote Information Disclosure Vulnerability
- | [16672] Dovecot Double Free Denial of Service Vulnerability
- | [8495] akpop3d User Name SQL Injection Vulnerability
- | [8473] Vpop3d Remote Denial Of Service Vulnerability
- | [3990] ZPop3D Bad Login Logging Failure Vulnerability
- | [2781] DynFX MailServer POP3d Denial of Service Vulnerability
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [86382] Dovecot POP3 Service denial of service
- | [84396] Dovecot IMAP APPEND denial of service
- | [80453] Dovecot mail-search.c denial of service
- | [71354] Dovecot SSL Common Name (CN) weak security
- | [67675] Dovecot script-login security bypass
- | [67674] Dovecot script-login directory traversal
- | [67589] Dovecot header name denial of service
- | [63267] Apple Mac OS X Dovecot information disclosure
- | [62340] Dovecot mailbox security bypass
- | [62339] Dovecot IMAP or POP3 denial of service
- | [62256] Dovecot mailbox security bypass
- | [62255] Dovecot ACL entry security bypass
- | [60639] Dovecot ACL plugin weak security
- | [57267] Apple Mac OS X Dovecot Kerberos security bypass
- | [56763] Dovecot header denial of service
- | [54363] Dovecot base_dir privilege escalation
- | [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
- | [46323] Dovecot dovecot.conf information disclosure
- | [46227] Dovecot message parsing denial of service
- | [45669] Dovecot ACL mailbox security bypass
- | [45667] Dovecot ACL plugin rights security bypass
- | [41085] Dovecot TAB characters authentication bypass
- | [41009] Dovecot mail_extra_groups option unauthorized access
- | [39342] Dovecot LDAP auth cache configuration security bypass
- | [35767] Dovecot ACL plugin security bypass
- | [34082] Dovecot mbox-storage.c directory traversal
- | [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
- | [26578] Cyrus IMAP pop3d buffer overflow
- | [26536] Dovecot IMAP LIST information disclosure
- | [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
- | [24709] Dovecot APPEND command denial of service
- | [13018] akpop3d authentication code SQL injection
- | [7345] Slackware Linux imapd and ipop3d core dump
- | [6269] imap, ipop2d and ipop3d buffer overflows
- | [5923] Linuxconf vpop3d symbolic link
- | [4918] IPOP3D, Buffer overflow attack
- | [1560] IPOP3D, user login successful
- | [1559] IPOP3D user login to remote host successful
- | [1525] IPOP3D, user logout
- | [1524] IPOP3D, user auto-logout
- | [1523] IPOP3D, user login failure
- | [1522] IPOP3D, brute force attack
- | [1521] IPOP3D, user kiss of death logout
- | [418] pop3d mktemp creates insecure temporary files
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
- | [23053] Vpop3d Remote Denial of Service Vulnerability
- | [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
- | [11893] tPop3d 1.5.3 DoS
- | [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 - Remote Email Disclosure Exploit
- | [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
- | [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
- | [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
- | [901025] Dovecot Version Detection
- | [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
- | [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
- | [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
- | [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
- | [870607] RedHat Update for dovecot RHSA-2011:0600-01
- | [870471] RedHat Update for dovecot RHSA-2011:1187-01
- | [870153] RedHat Update for dovecot RHSA-2008:0297-02
- | [863272] Fedora Update for dovecot FEDORA-2011-7612
- | [863115] Fedora Update for dovecot FEDORA-2011-7258
- | [861525] Fedora Update for dovecot FEDORA-2007-664
- | [861394] Fedora Update for dovecot FEDORA-2007-493
- | [861333] Fedora Update for dovecot FEDORA-2007-1485
- | [860845] Fedora Update for dovecot FEDORA-2008-9202
- | [860663] Fedora Update for dovecot FEDORA-2008-2475
- | [860169] Fedora Update for dovecot FEDORA-2008-2464
- | [860089] Fedora Update for dovecot FEDORA-2008-9232
- | [840950] Ubuntu Update for dovecot USN-1295-1
- | [840668] Ubuntu Update for dovecot USN-1143-1
- | [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
- | [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
- | [840290] Ubuntu Update for dovecot vulnerability USN-567-1
- | [840234] Ubuntu Update for dovecot vulnerability USN-666-1
- | [840072] Ubuntu Update for dovecot vulnerability USN-487-1
- | [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
- | [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
- | [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
- | [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
- | [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
- | [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
- | [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
- | [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
- | [70259] FreeBSD Ports: dovecot
- | [69959] Debian Security Advisory DSA 2252-1 (dovecot)
- | [66522] FreeBSD Ports: dovecot
- | [65010] Ubuntu USN-838-1 (dovecot)
- | [64978] Debian Security Advisory DSA 1892-1 (dovecot)
- | [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
- | [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
- | [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
- | [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
- | [62854] FreeBSD Ports: dovecot-managesieve
- | [61916] FreeBSD Ports: dovecot
- | [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
- | [60568] Debian Security Advisory DSA 1516-1 (dovecot)
- | [60528] FreeBSD Ports: dovecot
- | [60134] Debian Security Advisory DSA 1457-1 (dovecot)
- | [60089] FreeBSD Ports: dovecot
- | [58578] Debian Security Advisory DSA 1359-1 (dovecot)
- | [56834] Debian Security Advisory DSA 1080-1 (dovecot)
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
- | [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
- | [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
- |
- | OSVDB - http://www.osvdb.org:
- | [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
- | [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
- | [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
- | [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
- | [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
- | [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
- | [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
- | [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
- | [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
- | [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
- | [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
- | [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
- | [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
- | [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
- | [66113] Dovecot Mail Root Directory Creation Permission Weakness
- | [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
- | [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
- | [66110] Dovecot Multiple Unspecified Buffer Overflows
- | [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
- | [64783] Dovecot E-mail Message Header Unspecified DoS
- | [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
- | [62796] Dovecot mbox Format Email Header Handling DoS
- | [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
- | [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
- | [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
- | [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
- | [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
- | [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
- | [49098] Dovecot ACL Plugin Negative Access Rights Bypass
- | [43137] Dovecot mail_extra_groups Symlink File Manipulation
- | [42979] Dovecot passdbs Argument Injection Authentication Bypass
- | [39876] Dovecot LDAP Auth Cache Security Bypass
- | [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
- | [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
- | [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
- | [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
- | [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
- | [23281] Dovecot imap/pop3-login dovecot-auth DoS
- | [23280] Dovecot Malformed APPEND Command DoS
- | [14459] mmmail mmpop3d USER Command mmsyslog Function Format String
- | [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
- | [5857] Linux pop3d Arbitrary Mail File Access
- | [2471] akpop3d username SQL Injection
- |_
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Aggressive OS guesses: Linux 4.4 (99%), Linux 3.18 (99%), Linux 2.6.32 (98%), Linux 2.6.32 or 3.10 (98%), Linux 2.6.35 (98%), Linux 3.10 (98%), Linux 3.4 (98%), Linux 3.5 (98%), Linux 3.7 (98%), Linux 4.2 (98%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 11 hops
- TRACEROUTE (using port 110/tcp)
- HOP RTT ADDRESS
- 1 292.61 ms 10.252.204.1
- 2 244.39 ms 45.131.4.2
- 3 145.10 ms 109.236.95.224
- 4 244.45 ms 109.236.95.173
- 5 244.48 ms amsix-200gbps.core1.ams1.he.net (80.249.209.150)
- 6 244.51 ms 100ge16-1.core1.lon2.he.net (72.52.92.213)
- 7 244.54 ms 100ge13-2.core1.nyc4.he.net (72.52.92.166)
- 8 344.30 ms 100ge8-1.core1.sjc2.he.net (184.105.81.218)
- 9 344.33 ms 100ge13-2.core1.sjc1.he.net (184.105.65.113)
- 10 344.30 ms e0-50.core4.fmt1.he.net (184.105.65.214)
- 11 344.32 ms respectwashington.us (65.49.16.26)
- #######################################################################################################################################
- https://www.respectwashington.us [403 Forbidden] Apache[2.4.18], Country[UNITED STATES][US], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[65.49.16.26], Title[403 Forbidden]
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:05 EDT
- Nmap scan report for respectwashington.us (65.49.16.26)
- Host is up (0.65s latency).
- Not shown: 992 closed ports
- PORT STATE SERVICE
- 80/tcp open http
- 110/tcp open pop3
- 143/tcp open imap
- 443/tcp open https
- 465/tcp open smtps
- 587/tcp open submission
- 993/tcp open imaps
- 995/tcp open pop3s
- Nmap done: 1 IP address (1 host up) scanned in 3.63 seconds
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:05 EDT
- Nmap scan report for respectwashington.us (65.49.16.26)
- Host is up (0.33s latency).
- Not shown: 12 closed ports, 2 filtered ports
- PORT STATE SERVICE
- 2049/udp open|filtered nfs
- Nmap done: 1 IP address (1 host up) scanned in 8.51 seconds
- #######################################################################################################################################
- HTTP/1.1 200 OK
- Date: Tue, 22 Oct 2019 13:05:33 GMT
- Server: Apache/2.4.18 (Ubuntu)
- Vary: Host,Accept-Encoding
- Last-Modified: Fri, 23 Feb 2018 15:15:28 GMT
- ETag: "8956-565e2a1613be1"
- Accept-Ranges: bytes
- Content-Length: 35158
- Content-Type: text/html
- Allow: GET,HEAD,POST,OPTIONS
- #######################################################################################################################################
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Top Nav XXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!--Second row-->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX End Top Nav XXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX About the legislation XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX Cost of the legislation XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXX Quote from WA Sate Constitution XXXXXXXXXXXXXXXXXXXXXXXXXXX -->
- <!-- XXXXXXXXXXXXXXXXXXXX "Keep it Legal" logo XXXXXXXXXXXXXXXXX-->
- <!-- XXXXXXXXXXXXXXXXXX End "Keep it Legal" logo XXXXXXXXXXXXXXXXX-->
- #######################################################################################################################################
- http://www.w3.org/1999/xhtml
- text/css
- -//W3C//DTD XHTML 1.0 Transitional//EN
- ######################################################################################################################################
- http://65.49.16.26 [200 OK] Apache[2.4.18], Country[UNITED STATES][US], Email[[email protected]], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[65.49.16.26], Title[RespectWashington]
- ######################################################################################################################################
- wig - WebApp Information Gatherer
- Scanning http://65.49.16.26...
- _________________ SITE INFO __________________
- IP Title
- 65.49.16.26 RespectWashington
- __________________ VERSION ___________________
- Name Versions Type
- Apache 2.4.18 Platform
- Ubuntu 16.04 OS
- ______________________________________________
- Time: 53.8 sec Urls: 603 Fingerprints: 40401
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:07 EDT
- Nmap scan report for respectwashington.us (65.49.16.26)
- Host is up (0.34s latency).
- PORT STATE SERVICE VERSION
- 110/tcp open pop3 Dovecot pop3d
- | pop3-brute:
- | Accounts: No valid accounts found
- | Statistics: Performed 55 guesses in 49 seconds, average tps: 1.0
- |_ ERROR: Failed to connect.
- |_pop3-capabilities: TOP CAPA PIPELINING RESP-CODES STLS SASL(PLAIN LOGIN) AUTH-RESP-CODE UIDL USER
- | vulscan: VulDB - https://vuldb.com:
- | [139289] cPanel up to 68.0.14 dovecot-xaps-plugin Format privilege escalation
- | [134480] Dovecot up to 2.3.5.2 Submission-Login Crash denial of service
- | [134479] Dovecot up to 2.3.5.2 IMAP Server Crash denial of service
- | [134024] Dovecot up to 2.3.5.1 JSON Encoder Username Crash denial of service
- | [132543] Dovecot up to 2.2.36.0/2.3.4.0 Certificate Impersonation weak authentication
- | [119762] Dovecot up to 2.2.28 dict Authentication var_expand() denial of service
- | [114012] Dovecot up to 2.2.33 TLS SNI Restart denial of service
- | [114009] Dovecot SMTP Delivery Email Message Out-of-Bounds memory corruption
- | [112447] Dovecot up to 2.2.33/2.3.0 SASL Auth Memory Leak denial of service
- | [106837] Dovecot up to 2.2.16 ssl-proxy-openssl.c ssl-proxy-opensslc denial of service
- | [97052] Dovecot up to 2.2.26 auth-policy Unset Crash denial of service
- | [69835] Dovecot 2.2.0/2.2.1 denial of service
- | [13348] Dovecot up to 1.2.15/2.1.15 IMAP4/POP3 SSL/TLS Handshake denial of service
- | [65684] Dovecot up to 2.2.6 unknown vulnerability
- | [9807] Dovecot up to 1.2.7 on Exim Input Sanitizer privilege escalation
- | [63692] Dovecot up to 2.0.15 spoofing
- | [7062] Dovecot 2.1.10 mail-search.c denial of service
- | [57517] Dovecot up to 2.0.12 Login directory traversal
- | [57516] Dovecot up to 2.0.12 Access Restriction directory traversal
- | [57515] Dovecot up to 2.0.12 Crash denial of service
- | [54944] Dovecot up to 1.2.14 denial of service
- | [54943] Dovecot up to 1.2.14 Access Restriction Symlink privilege escalation
- | [54942] Dovecot up to 2.0.4 Access Restriction denial of service
- | [54941] Dovecot up to 2.0.4 Access Restriction unknown vulnerability
- | [54840] Dovecot up to 1.2.12 AGate unknown vulnerability
- | [53277] Dovecot up to 1.2.10 denial of service
- | [50082] Dovecot up to 1.1.6 Stack-based memory corruption
- | [45256] Dovecot up to 1.1.5 directory traversal
- | [44846] Dovecot 1.1.4/1.1.5 IMAP Client Crash denial of service
- | [44546] Dovecot up to 1.0.x Access Restriction unknown vulnerability
- | [44545] Dovecot up to 1.0.x Access Restriction unknown vulnerability
- | [41430] Dovecot 1.0.12/1.1 Locking unknown vulnerability
- | [40356] Dovecot 1.0.9 Cache unknown vulnerability
- | [38222] Dovecot 1.0.2 directory traversal
- | [36376] Dovecot up to 1.0.x directory traversal
- | [33332] Timo Sirainen Dovecot up to 1.0test53 Off-By-One memory corruption
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2011-4318] Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.
- | [CVE-2011-2167] script-login in Dovecot 2.0.x before 2.0.13 does not follow the chroot configuration setting, which might allow remote authenticated users to conduct directory traversal attacks by leveraging a script.
- | [CVE-2011-2166] script-login in Dovecot 2.0.x before 2.0.13 does not follow the user and group configuration settings, which might allow remote authenticated users to bypass intended access restrictions by leveraging a script.
- | [CVE-2011-1929] lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.
- | [CVE-2010-4011] Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."
- | [CVE-2010-3780] Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.
- | [CVE-2010-3779] Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.
- | [CVE-2010-3707] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
- | [CVE-2010-3706] plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.
- | [CVE-2010-3304] The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote attackers to read mailboxes that have unintended weak ACLs.
- | [CVE-2010-0745] Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.
- | [CVE-2010-0535] Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending and receiving e-mail, which allows remote authenticated users to bypass intended access restrictions via unspecified vectors.
- | [CVE-2010-0433] The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.
- | [CVE-2009-3897] Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.
- | [CVE-2009-3235] Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
- | [CVE-2009-2632] Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
- | [CVE-2008-5301] Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.
- | [CVE-2008-4907] The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows remote attackers to cause a denial of service (persistent crash) via an email with a malformed From address, which triggers an assertion error, aka "invalid message address parsing bug."
- | [CVE-2008-4870] dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.
- | [CVE-2008-4578] The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.
- | [CVE-2008-4577] The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
- | [CVE-2008-1218] Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a password containing TAB characters, which are treated as argument delimiters that enable the skip_password_check field to be specified.
- | [CVE-2008-1199] Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other users, or modify files or directories that are writable by group, via a symlink attack.
- | [CVE-2007-6598] Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.
- | [CVE-2007-5794] Race condition in nss_ldap, when used in applications that are linked against the pthread library and fork after a call to nss_ldap, might send user data to the wrong process because of improper handling of the LDAP connection. NOTE: this issue was originally reported for Dovecot with the wrong mailboxes being returned, but other applications might also be affected.
- | [CVE-2007-4211] The ACL plugin in Dovecot before 1.0.3 allows remote authenticated users with the insert right to save certain flags via a (1) COPY or (2) APPEND command.
- | [CVE-2007-2231] Directory traversal vulnerability in index/mbox/mbox-storage.c in Dovecot before 1.0.rc29, when using the zlib plugin, allows remote attackers to read arbitrary gzipped (.gz) mailboxes (mbox files) via a .. (dot dot) sequence in the mailbox name.
- | [CVE-2007-2173] Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
- | [CVE-2007-0618] Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."
- | [CVE-2006-5973] Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used and mmap_disable is set to "yes," allows remote authenticated IMAP or POP3 users to cause a denial of service (crash) via unspecified vectors involving the cache file.
- | [CVE-2006-2502] Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.
- | [CVE-2006-2414] Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.
- | [CVE-2006-0730] Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.
- | [CVE-2002-0925] Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
- | [CVE-2001-0143] vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
- | [CVE-2000-1197] POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
- | [CVE-1999-1445] Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [103201] Dovecot CVE-2017-14461 Out-Of-Bounds Read Information Disclosure Vulnerability
- | [97536] Dovecot CVE-2017-2669 Denial of Service Vulnerability
- | [94639] Dovecot Auth Component CVE-2016-8652 Denial of Service Vulnerability
- | [91175] Dovecot CVE-2016-4982 Local Information Disclosure Vulnerability
- | [84736] Dovecot CVE-2008-4870 Local Security Vulnerability
- | [74335] Dovecot 'ssl-proxy-openssl.c' Remote Denial of Service Vulnerability
- | [67306] Dovecot Denial of Service Vulnerability
- | [67219] akpop3d 'pszQuery' Remote Memory Corruption Vulnerability
- | [63367] Dovecot Checkpassword Authentication Protocol Local Authentication Bypass Vulnerability
- | [61763] RETIRED: Dovecot 'LIST' Command Denial of Service Vulnerability
- | [60465] Exim for Dovecot 'use_shell' Remote Command Execution Vulnerability
- | [60052] Dovecot 'APPEND' Parameter Denial of Service Vulnerability
- | [56759] RETIRED: Dovecot 'mail-search.c' Denial of Service Vulnerability
- | [50709] Dovecot SSL Certificate 'Common Name' Field Validation Security Bypass Vulnerability
- | [48003] Dovecot 'script-login' Multiple Security Bypass Vulnerabilities
- | [47930] Dovecot Header Name NULL Character Denial of Service Vulnerability
- | [44874] Apple Mac OS X Dovecot (CVE-2010-4011) Memory Corruption Vulnerability
- | [43690] Dovecot Access Control List (ACL) Multiple Remote Vulnerabilities
- | [41964] Dovecot Access Control List (ACL) Plugin Security Bypass Weakness
- | [39838] tpop3d Remote Denial of Service Vulnerability
- | [39258] Dovecot Service Control Access List Security Bypass Vulnerability
- | [37084] Dovecot Insecure 'base_dir' Permissions Local Privilege Escalation Vulnerability
- | [36377] Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
- | [32582] Dovecot ManageSieve Service '.sieve' Files Directory Traversal Vulnerability
- | [31997] Dovecot Invalid Message Address Parsing Denial of Service Vulnerability
- | [31587] Dovecot ACL Plugin Multiple Security Bypass Vulnerabilities
- | [28181] Dovecot 'Tab' Character Password Check Security Bypass Vulnerability
- | [28092] Dovecot 'mail_extra_groups' Insecure Settings Local Unauthorized Access Vulnerability
- | [27093] Dovecot Authentication Cache Security Bypass Vulnerability
- | [25182] Dovecot ACL Plugin Security Bypass Vulnerability
- | [23552] Dovecot Zlib Plugin Remote Information Disclosure Vulnerability
- | [22262] IBM AIX Pop3D/Pop3DS/IMapD/IMapDS Authentication Bypass Vulnerability
- | [21183] Dovecot IMAP Server Mapped Pages Off-By-One Buffer Overflow Vulnerability
- | [18056] Cyrus IMAPD POP3D Remote Buffer Overflow Vulnerability
- | [17961] Dovecot Remote Information Disclosure Vulnerability
- | [16672] Dovecot Double Free Denial of Service Vulnerability
- | [8495] akpop3d User Name SQL Injection Vulnerability
- | [8473] Vpop3d Remote Denial Of Service Vulnerability
- | [3990] ZPop3D Bad Login Logging Failure Vulnerability
- | [2781] DynFX MailServer POP3d Denial of Service Vulnerability
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [86382] Dovecot POP3 Service denial of service
- | [84396] Dovecot IMAP APPEND denial of service
- | [80453] Dovecot mail-search.c denial of service
- | [71354] Dovecot SSL Common Name (CN) weak security
- | [67675] Dovecot script-login security bypass
- | [67674] Dovecot script-login directory traversal
- | [67589] Dovecot header name denial of service
- | [63267] Apple Mac OS X Dovecot information disclosure
- | [62340] Dovecot mailbox security bypass
- | [62339] Dovecot IMAP or POP3 denial of service
- | [62256] Dovecot mailbox security bypass
- | [62255] Dovecot ACL entry security bypass
- | [60639] Dovecot ACL plugin weak security
- | [57267] Apple Mac OS X Dovecot Kerberos security bypass
- | [56763] Dovecot header denial of service
- | [54363] Dovecot base_dir privilege escalation
- | [53248] CMU Sieve plugin for Dovecot unspecified buffer overflow
- | [46323] Dovecot dovecot.conf information disclosure
- | [46227] Dovecot message parsing denial of service
- | [45669] Dovecot ACL mailbox security bypass
- | [45667] Dovecot ACL plugin rights security bypass
- | [41085] Dovecot TAB characters authentication bypass
- | [41009] Dovecot mail_extra_groups option unauthorized access
- | [39342] Dovecot LDAP auth cache configuration security bypass
- | [35767] Dovecot ACL plugin security bypass
- | [34082] Dovecot mbox-storage.c directory traversal
- | [30433] Dovecot IMAP/POP3 server dovecot.index.cache buffer overflow
- | [26578] Cyrus IMAP pop3d buffer overflow
- | [26536] Dovecot IMAP LIST information disclosure
- | [24710] Dovecot dovecot-auth and imap/pop3-login denial of service
- | [24709] Dovecot APPEND command denial of service
- | [13018] akpop3d authentication code SQL injection
- | [7345] Slackware Linux imapd and ipop3d core dump
- | [6269] imap, ipop2d and ipop3d buffer overflows
- | [5923] Linuxconf vpop3d symbolic link
- | [4918] IPOP3D, Buffer overflow attack
- | [1560] IPOP3D, user login successful
- | [1559] IPOP3D user login to remote host successful
- | [1525] IPOP3D, user logout
- | [1524] IPOP3D, user auto-logout
- | [1523] IPOP3D, user login failure
- | [1522] IPOP3D, brute force attack
- | [1521] IPOP3D, user kiss of death logout
- | [418] pop3d mktemp creates insecure temporary files
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [25297] Dovecot with Exim sender_address Parameter - Remote Command Execution
- | [23053] Vpop3d Remote Denial of Service Vulnerability
- | [16836] Cyrus IMAPD pop3d popsubfolders USER Buffer Overflow
- | [11893] tPop3d 1.5.3 DoS
- | [5257] Dovecot IMAP 1.0.10 <= 1.1rc2 - Remote Email Disclosure Exploit
- | [2185] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (3)
- | [2053] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit (2)
- | [1813] Cyrus IMAPD 2.3.2 (pop3d) Remote Buffer Overflow Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [901026] Dovecot Sieve Plugin Multiple Buffer Overflow Vulnerabilities
- | [901025] Dovecot Version Detection
- | [881402] CentOS Update for dovecot CESA-2011:1187 centos5 x86_64
- | [881358] CentOS Update for dovecot CESA-2011:1187 centos4 x86_64
- | [880980] CentOS Update for dovecot CESA-2011:1187 centos5 i386
- | [880967] CentOS Update for dovecot CESA-2011:1187 centos4 i386
- | [870607] RedHat Update for dovecot RHSA-2011:0600-01
- | [870471] RedHat Update for dovecot RHSA-2011:1187-01
- | [870153] RedHat Update for dovecot RHSA-2008:0297-02
- | [863272] Fedora Update for dovecot FEDORA-2011-7612
- | [863115] Fedora Update for dovecot FEDORA-2011-7258
- | [861525] Fedora Update for dovecot FEDORA-2007-664
- | [861394] Fedora Update for dovecot FEDORA-2007-493
- | [861333] Fedora Update for dovecot FEDORA-2007-1485
- | [860845] Fedora Update for dovecot FEDORA-2008-9202
- | [860663] Fedora Update for dovecot FEDORA-2008-2475
- | [860169] Fedora Update for dovecot FEDORA-2008-2464
- | [860089] Fedora Update for dovecot FEDORA-2008-9232
- | [840950] Ubuntu Update for dovecot USN-1295-1
- | [840668] Ubuntu Update for dovecot USN-1143-1
- | [840583] Ubuntu Update for dovecot vulnerabilities USN-1059-1
- | [840335] Ubuntu Update for dovecot vulnerabilities USN-593-1
- | [840290] Ubuntu Update for dovecot vulnerability USN-567-1
- | [840234] Ubuntu Update for dovecot vulnerability USN-666-1
- | [840072] Ubuntu Update for dovecot vulnerability USN-487-1
- | [831405] Mandriva Update for dovecot MDVSA-2011:101 (dovecot)
- | [831230] Mandriva Update for dovecot MDVSA-2010:217 (dovecot)
- | [831197] Mandriva Update for dovecot MDVSA-2010:196 (dovecot)
- | [831054] Mandriva Update for dovecot MDVSA-2010:104 (dovecot)
- | [830496] Mandriva Update for dovecot MDVSA-2008:232 (dovecot)
- | [801055] Dovecot 'base_dir' Insecure Permissions Security Bypass Vulnerability
- | [800030] Dovecot ACL Plugin Security Bypass Vulnerabilities
- | [70767] Gentoo Security Advisory GLSA 201110-04 (Dovecot)
- | [70259] FreeBSD Ports: dovecot
- | [69959] Debian Security Advisory DSA 2252-1 (dovecot)
- | [66522] FreeBSD Ports: dovecot
- | [65010] Ubuntu USN-838-1 (dovecot)
- | [64978] Debian Security Advisory DSA 1892-1 (dovecot)
- | [64953] Mandrake Security Advisory MDVSA-2009:242-1 (dovecot)
- | [64952] Mandrake Security Advisory MDVSA-2009:242 (dovecot)
- | [64861] Fedora Core 10 FEDORA-2009-9559 (dovecot)
- | [62965] Gentoo Security Advisory GLSA 200812-16 (dovecot)
- | [62854] FreeBSD Ports: dovecot-managesieve
- | [61916] FreeBSD Ports: dovecot
- | [60588] Gentoo Security Advisory GLSA 200803-25 (dovecot)
- | [60568] Debian Security Advisory DSA 1516-1 (dovecot)
- | [60528] FreeBSD Ports: dovecot
- | [60134] Debian Security Advisory DSA 1457-1 (dovecot)
- | [60089] FreeBSD Ports: dovecot
- | [58578] Debian Security Advisory DSA 1359-1 (dovecot)
- | [56834] Debian Security Advisory DSA 1080-1 (dovecot)
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1028585] Dovecot APPEND Parameter Processing Flaw Lets Remote Authenticated Users Deny Service
- | [1024740] Mac OS X Server Dovecot Memory Aliasing Bug May Cause Mail to Be Delivered to the Wrong User
- | [1017288] Dovecot POP3/IMAP Cache File Buffer Overflow May Let Remote Users Execute Arbitrary Code
- |
- | OSVDB - http://www.osvdb.org:
- | [96172] Dovecot POP3 Service Terminated LIST Command Remote DoS
- | [93525] Dovecot IMAP APPEND Command Malformed Parameter Parsing Remote DoS
- | [93004] Dovecot with Exim sender_address Parameter Remote Command Execution
- | [88058] Dovecot lib-storage/mail-search.c Multiple Keyword Search Handling Remote DoS
- | [77185] Dovecot SSL Certificate Common Name Field MitM Spoofing Weakness
- | [74515] Dovecot script-login chroot Configuration Setting Traversal Arbitrary File Access
- | [74514] Dovecot script-login User / Group Configuration Settings Remote Access Restriction Bypass
- | [72495] Dovecot lib-mail/message-header-parser.c Mail Header Name NULL Character Handling Remote DoS
- | [69260] Apple Mac OS X Server Dovecot Memory Aliasing Mail Delivery Issue
- | [68516] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition User Private Namespace Mailbox Access Restriction Remote Bypass
- | [68515] Dovecot plugins/acl/acl-backend-vfile.c ACL Permission Addition Specific Entry Order Mailbox Access Restriction Remote Bypass
- | [68513] Dovecot Non-public Namespace Mailbox ACL Manipulation Access Restriction Remote Bypass
- | [68512] Dovecot IMAP / POP3 Session Disconnect Master Process Outage Remote DoS
- | [66625] Dovecot ACL Plugin INBOX ACL Copying Weakness Restriction Bypass
- | [66113] Dovecot Mail Root Directory Creation Permission Weakness
- | [66112] Dovecot Installation base_dir Parent Directory Permission Weakness
- | [66111] Dovecot SEARCH Functionality str_find_init() Function Overflow
- | [66110] Dovecot Multiple Unspecified Buffer Overflows
- | [66108] Dovecot Malformed Message Body Processing Unspecified Functions Remote DoS
- | [64783] Dovecot E-mail Message Header Unspecified DoS
- | [63372] Apple Mac OS X Dovecot Kerberos Authentication SACL Restriction Bypass
- | [62796] Dovecot mbox Format Email Header Handling DoS
- | [60316] Dovecot base_dir Directory Permission Weakness Local Privilege Escalation
- | [58103] Dovecot CMU Sieve Plugin Script Handling Multiple Overflows
- | [50253] Dovecot dovecot.conf Permission Weakness Local ssl_key_password Parameter Disclosure
- | [49918] Dovecot ManageSieve Script Name Handling Traversal Arbitrary File Manipulation
- | [49429] Dovecot Message Parsing Feature Crafted Email Header Handling Remote DoS
- | [49099] Dovecot ACL Plugin k Right Mailbox Creation Restriction Bypass
- | [49098] Dovecot ACL Plugin Negative Access Rights Bypass
- | [43137] Dovecot mail_extra_groups Symlink File Manipulation
- | [42979] Dovecot passdbs Argument Injection Authentication Bypass
- | [39876] Dovecot LDAP Auth Cache Security Bypass
- | [39386] Dovecot ACL Plugin Insert Right APPEND / COPY Command Unauthorized Flag Manipulation
- | [35489] Dovecot index/mbox/mbox-storage.c Traversal Arbitrary Gzip File Access
- | [30524] Dovecot IMAP/POP3 Server dovecot.index.cache Handling Overflow
- | [25853] Cyrus IMAPD pop3d USER Command Remote Overflow
- | [25727] Dovecot Multiple Command Traversal Arbitrary Directory Listing
- | [23281] Dovecot imap/pop3-login dovecot-auth DoS
- | [23280] Dovecot Malformed APPEND Command DoS
- | [14459] mmmail mmpop3d USER Command mmsyslog Function Format String
- | [12033] Slackware Linux imapd/ipop3d Malformed USER/PASS Sequence DoS
- | [5857] Linux pop3d Arbitrary Mail File Access
- | [2471] akpop3d username SQL Injection
- |_
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Aggressive OS guesses: Linux 3.10 - 3.12 (99%), Linux 4.4 (99%), Linux 3.18 (99%), Linux 2.6.32 (98%), Linux 2.6.35 (98%), Linux 2.6.39 (98%), Linux 3.10 (98%), Linux 3.4 (98%), Linux 3.5 (98%), Linux 3.7 (98%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 11 hops
- TRACEROUTE (using port 110/tcp)
- HOP RTT ADDRESS
- 1 240.15 ms 10.252.204.1
- 2 716.83 ms 45.131.4.2
- 3 201.33 ms 109.236.95.226
- 4 300.79 ms 109.236.95.106
- 5 300.84 ms amsix-200gbps.core1.ams1.he.net (80.249.209.150)
- 6 300.87 ms 100ge16-1.core1.lon2.he.net (72.52.92.213)
- 7 300.94 ms 100ge13-2.core1.nyc4.he.net (72.52.92.166)
- 8 442.90 ms 100ge8-1.core1.sjc2.he.net (184.105.81.218)
- 9 442.94 ms 100ge13-2.core1.sjc1.he.net (184.105.65.113)
- 10 442.94 ms e0-50.core4.fmt1.he.net (184.105.65.214)
- 11 300.99 ms respectwashington.us (65.49.16.26)
- #######################################################################################################################################
- https://65.49.16.26 [200 OK] Apache[2.4.18], Country[UNITED STATES][US], Email[[email protected]], HTTPServer[Ubuntu Linux][Apache/2.4.18 (Ubuntu)], IP[65.49.16.26], Title[RespectWashington]
- ######################################################################################################################################
- Version: 1.11.13-static
- OpenSSL 1.0.2-chacha (1.0.2g-dev)
- Connected to 65.49.16.26
- Testing SSL server 65.49.16.26 on port 443 using SNI name 65.49.16.26
- TLS Fallback SCSV:
- Server supports TLS Fallback SCSV
- TLS renegotiation:
- Secure session renegotiation supported
- TLS Compression:
- Compression disabled
- Heartbleed:
- TLS 1.2 not vulnerable to heartbleed
- TLS 1.1 not vulnerable to heartbleed
- TLS 1.0 not vulnerable to heartbleed
- Supported Server Cipher(s):
- Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
- Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
- Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384 DHE 2048 bits
- Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA256 DHE 2048 bits
- Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
- Accepted TLSv1.2 256 bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
- Accepted TLSv1.2 256 bits AES256-GCM-SHA384
- Accepted TLSv1.2 256 bits AES256-SHA256
- Accepted TLSv1.2 256 bits AES256-SHA
- Accepted TLSv1.2 256 bits CAMELLIA256-SHA
- Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-GCM-SHA256 Curve P-256 DHE 256
- Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
- Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256 DHE 2048 bits
- Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA256 DHE 2048 bits
- Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
- Accepted TLSv1.2 128 bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
- Accepted TLSv1.2 128 bits AES128-GCM-SHA256
- Accepted TLSv1.2 128 bits AES128-SHA256
- Accepted TLSv1.2 128 bits AES128-SHA
- Accepted TLSv1.2 128 bits CAMELLIA128-SHA
- Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
- Accepted TLSv1.1 256 bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
- Accepted TLSv1.1 256 bits AES256-SHA
- Accepted TLSv1.1 256 bits CAMELLIA256-SHA
- Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
- Accepted TLSv1.1 128 bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
- Accepted TLSv1.1 128 bits AES128-SHA
- Accepted TLSv1.1 128 bits CAMELLIA128-SHA
- Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
- Accepted TLSv1.0 256 bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
- Accepted TLSv1.0 256 bits AES256-SHA
- Accepted TLSv1.0 256 bits CAMELLIA256-SHA
- Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
- Accepted TLSv1.0 128 bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
- Accepted TLSv1.0 128 bits AES128-SHA
- Accepted TLSv1.0 128 bits CAMELLIA128-SHA
- SSL Certificate:
- Signature Algorithm: sha256WithRSAEncryption
- RSA Key Strength: 2048
- Subject: respectwashington.us
- Altnames: DNS:keller4america.us, DNS:mail.respectwashington.us, DNS:respectwashington.us, DNS:www.keller4america.us, DNS:www.respectwashington.us
- Issuer: Let's Encrypt Authority X3
- Not valid before: Sep 23 10:50:34 2019 GMT
- Not valid after: Dec 22 10:50:34 2019 GMT
- #######################################################################################################################################
- --------------------------------------------------------
- <<<Yasuo discovered following vulnerable applications>>>
- --------------------------------------------------------
- +-----------------+-----------------------------------+--------------------------------------------------+-----------+-----------+
- | App Name | URL to Application | Potential Exploit | Username | Password |
- +-----------------+-----------------------------------+--------------------------------------------------+-----------+-----------+
- | phpMyAdmin | http://65.49.16.26:80/phpmyadmin/ | ./exploits/multi/http/phpmyadmin_preg_replace.rb | Not Found | Not Found |
- | Linksys WRT54GL | https://65.49.16.26:443/apply.cgi | ./auxiliary/admin/http/linksys_wrt54gl_exec.rb | Not Found | Not Found |
- +-----------------+-----------------------------------+--------------------------------------------------+-----------+-----------+
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:15 EDT
- NSE: Loaded 47 scripts for scanning.
- NSE: Script Pre-scanning.
- Initiating NSE at 09:15
- Completed NSE at 09:15, 0.00s elapsed
- Initiating NSE at 09:15
- Completed NSE at 09:15, 0.00s elapsed
- Initiating Ping Scan at 09:15
- Scanning 65.49.16.26 [4 ports]
- Completed Ping Scan at 09:15, 0.28s elapsed (1 total hosts)
- Initiating Parallel DNS resolution of 1 host. at 09:15
- Completed Parallel DNS resolution of 1 host. at 09:15, 0.02s elapsed
- Initiating SYN Stealth Scan at 09:15
- Scanning respectwashington.us (65.49.16.26) [65535 ports]
- Discovered open port 587/tcp on 65.49.16.26
- Discovered open port 80/tcp on 65.49.16.26
- Discovered open port 443/tcp on 65.49.16.26
- SYN Stealth Scan Timing: About 1.26% done; ETC: 09:56 (0:40:25 remaining)
- SYN Stealth Scan Timing: About 2.12% done; ETC: 10:03 (0:47:00 remaining)
- SYN Stealth Scan Timing: About 4.01% done; ETC: 09:53 (0:36:18 remaining)
- SYN Stealth Scan Timing: About 12.48% done; ETC: 09:31 (0:14:09 remaining)
- SYN Stealth Scan Timing: About 30.58% done; ETC: 09:34 (0:13:19 remaining)
- Discovered open port 47025/tcp on 65.49.16.26
- SYN Stealth Scan Timing: About 39.08% done; ETC: 09:36 (0:12:20 remaining)
- SYN Stealth Scan Timing: About 45.45% done; ETC: 09:36 (0:11:18 remaining)
- Discovered open port 465/tcp on 65.49.16.26
- Discovered open port 36095/tcp on 65.49.16.26
- SYN Stealth Scan Timing: About 51.03% done; ETC: 09:36 (0:10:14 remaining)
- SYN Stealth Scan Timing: About 56.26% done; ETC: 09:36 (0:09:09 remaining)
- Discovered open port 34816/tcp on 65.49.16.26
- SYN Stealth Scan Timing: About 61.93% done; ETC: 09:37 (0:08:06 remaining)
- SYN Stealth Scan Timing: About 67.62% done; ETC: 09:37 (0:07:00 remaining)
- SYN Stealth Scan Timing: About 72.45% done; ETC: 09:37 (0:05:54 remaining)
- SYN Stealth Scan Timing: About 78.10% done; ETC: 09:37 (0:04:47 remaining)
- Discovered open port 35643/tcp on 65.49.16.26
- SYN Stealth Scan Timing: About 83.63% done; ETC: 09:37 (0:03:37 remaining)
- SYN Stealth Scan Timing: About 88.83% done; ETC: 09:38 (0:02:31 remaining)
- SYN Stealth Scan Timing: About 93.91% done; ETC: 09:38 (0:01:23 remaining)
- Completed SYN Stealth Scan at 09:38, 1391.51s elapsed (65535 total ports)
- Initiating Service scan at 09:38
- Scanning 8 services on respectwashington.us (65.49.16.26)
- Completed Service scan at 09:39, 22.62s elapsed (8 services on 1 host)
- Initiating OS detection (try #1) against respectwashington.us (65.49.16.26)
- Retrying OS detection (try #2) against respectwashington.us (65.49.16.26)
- Initiating Traceroute at 09:39
- Completed Traceroute at 09:39, 0.45s elapsed
- Initiating Parallel DNS resolution of 11 hosts. at 09:39
- Completed Parallel DNS resolution of 11 hosts. at 09:39, 0.30s elapsed
- NSE: Script scanning 65.49.16.26.
- Initiating NSE at 09:39
- Completed NSE at 09:39, 14.11s elapsed
- Initiating NSE at 09:39
- Completed NSE at 09:39, 2.73s elapsed
- Nmap scan report for respectwashington.us (65.49.16.26)
- Host is up (0.34s latency).
- Not shown: 65522 closed ports
- PORT STATE SERVICE VERSION
- 80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
- |_http-server-header: Apache/2.4.18 (Ubuntu)
- | vulners:
- | cpe:/a:apache:http_server:2.4.18:
- | CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
- | CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
- | CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
- | CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
- | CVE-2019-0211 7.2 https://vulners.com/cve/CVE-2019-0211
- | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
- | CVE-2017-15715 6.8 https://vulners.com/cve/CVE-2017-15715
- | CVE-2019-10082 6.4 https://vulners.com/cve/CVE-2019-10082
- | CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
- | CVE-2019-10098 5.8 https://vulners.com/cve/CVE-2019-10098
- | CVE-2019-0220 5.0 https://vulners.com/cve/CVE-2019-0220
- | CVE-2019-0196 5.0 https://vulners.com/cve/CVE-2019-0196
- | CVE-2018-17199 5.0 https://vulners.com/cve/CVE-2018-17199
- | CVE-2018-1333 5.0 https://vulners.com/cve/CVE-2018-1333
- | CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
- | CVE-2017-15710 5.0 https://vulners.com/cve/CVE-2017-15710
- | CVE-2016-8743 5.0 https://vulners.com/cve/CVE-2016-8743
- | CVE-2016-8740 5.0 https://vulners.com/cve/CVE-2016-8740
- | CVE-2016-4979 5.0 https://vulners.com/cve/CVE-2016-4979
- | CVE-2019-0197 4.9 https://vulners.com/cve/CVE-2019-0197
- | CVE-2019-10092 4.3 https://vulners.com/cve/CVE-2019-10092
- | CVE-2018-11763 4.3 https://vulners.com/cve/CVE-2018-11763
- | CVE-2016-4975 4.3 https://vulners.com/cve/CVE-2016-4975
- | CVE-2016-1546 4.3 https://vulners.com/cve/CVE-2016-1546
- | CVE-2018-1283 3.5 https://vulners.com/cve/CVE-2018-1283
- |_ CVE-2016-8612 3.3 https://vulners.com/cve/CVE-2016-8612
- | vulscan: VulDB - https://vuldb.com:
- | [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
- | [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
- | [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
- | [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
- | [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
- | [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
- | [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
- | [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
- | [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
- | [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
- | [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
- | [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
- | [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
- | [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
- | [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
- | [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
- | [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
- | [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
- | [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
- | [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
- | [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
- | [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
- | [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
- | [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
- | [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
- | [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
- | [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
- | [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
- | [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
- | [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
- | [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
- | [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
- | [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
- | [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
- | [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
- | [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
- | [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
- | [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
- | [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
- | [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
- | [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
- | [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
- | [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
- | [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
- | [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
- | [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
- | [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
- | [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
- | [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
- | [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
- | [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
- | [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
- | [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
- | [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
- | [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
- | [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
- | [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
- | [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
- | [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
- | [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
- | [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
- | [15177] PHP Apache 2 Local Denial of Service Vulnerability
- | [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
- | [5816] Apache 2 mod_dav Denial Of Service Vulnerability
- | [5486] Apache 2.0 CGI Path Disclosure Vulnerability
- | [5485] Apache 2.0 Path Disclosure Vulnerability
- | [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
- | [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
- | [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
- | [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [75211] Debian GNU/Linux apache 2 cross-site scripting
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
- | [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
- | [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
- | [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
- | [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
- | [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
- | [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
- | [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
- | [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
- | [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
- | [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
- | [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
- | [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
- | [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
- | [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
- | [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
- | [21719] Apache 2.0 Path Disclosure Vulnerability
- | [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
- | [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
- | [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
- | [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
- | [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
- | [17691] Apache Struts < 2.2.0 - Remote Command Execution
- | [15319] Apache 2.2 (Windows) Local Denial of Service
- | [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
- | [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
- | [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
- | [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
- | [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
- | [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
- | [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
- | [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
- | [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
- | [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
- | [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
- | [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
- | [9] Apache HTTP Server 2.x Memory Leak Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [855524] Solaris Update for Apache 2 120544-14
- | [855077] Solaris Update for Apache 2 120543-14
- | [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
- | [72626] Debian Security Advisory DSA 2579-1 (apache2)
- | [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
- | [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
- | [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
- | [71256] Debian Security Advisory DSA 2452-1 (apache2)
- | [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
- | [70724] Debian Security Advisory DSA 2405-1 (apache2)
- | [70235] Debian Security Advisory DSA 2298-2 (apache2)
- | [70233] Debian Security Advisory DSA 2298-1 (apache2)
- | [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
- | [69338] Debian Security Advisory DSA 2202-1 (apache2)
- | [65131] SLES9: Security update for Apache 2 oes/CORE
- | [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
- | [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
- | [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
- | [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
- | [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
- | [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
- | [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
- | [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
- | [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
- | [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
- | [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
- | [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
- | [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
- | [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
- | [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
- | [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
- | [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
- | [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
- | [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
- | [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
- | [11092] Apache 2.0.39 Win32 directory traversal
- | [66081] SLES11: Security update for Apache 2
- | [66074] SLES10: Security update for Apache 2
- | [66070] SLES9: Security update for Apache 2
- | [65893] SLES10: Security update for Apache 2
- | [65888] SLES10: Security update for Apache 2
- | [65510] SLES9: Security update for Apache 2
- | [65249] SLES9: Security update for Apache 2
- | [65230] SLES9: Security update for Apache 2
- | [65228] SLES9: Security update for Apache 2
- | [65207] SLES9: Security update for Apache 2
- | [65136] SLES9: Security update for Apache 2
- | [65017] SLES9: Security update for Apache 2
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
- | [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
- | [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
- | [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
- | [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
- |
- | OSVDB - http://www.osvdb.org:
- | [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
- |_
- 110/tcp filtered pop3
- 143/tcp filtered imap
- 443/tcp open ssl/http Apache httpd 2.4.18
- |_http-server-header: Apache/2.4.18 (Ubuntu)
- | vulners:
- | Apache httpd 2.4.18:
- | HTTPD:F564BBA32AA088833DA032B7EB77CA29 7.5 https://vulners.com/httpd/HTTPD:F564BBA32AA088833DA032B7EB77CA29
- | HTTPD:E74D6161229FA3D00A1783E6C3426C5D 7.5 https://vulners.com/httpd/HTTPD:E74D6161229FA3D00A1783E6C3426C5D
- | HTTPD:C7D2DA1ACB016A5220CA8E74647BED26 7.5 https://vulners.com/httpd/HTTPD:C7D2DA1ACB016A5220CA8E74647BED26
- | HTTPD:8F00FB1DD7567228376803FEDB0EC3B6 7.5 https://vulners.com/httpd/HTTPD:8F00FB1DD7567228376803FEDB0EC3B6
- | HTTPD:7EEE138FD834328B3FC98E4B7FCAD266 7.5 https://vulners.com/httpd/HTTPD:7EEE138FD834328B3FC98E4B7FCAD266
- | HTTPD:24E96D438275A8177C289509C796525C 7.5 https://vulners.com/httpd/HTTPD:24E96D438275A8177C289509C796525C
- | HTTPD:237FAB5DE739A612077A245192137A48 7.5 https://vulners.com/httpd/HTTPD:237FAB5DE739A612077A245192137A48
- | HTTPD:143F3A43D871E3AFFF956DB1049A6A2A 7.5 https://vulners.com/httpd/HTTPD:143F3A43D871E3AFFF956DB1049A6A2A
- | HTTPD:0C6EE30D77005EBF2B39E351B1F3E2C4 7.5 https://vulners.com/httpd/HTTPD:0C6EE30D77005EBF2B39E351B1F3E2C4
- | HTTPD:FC354B921BA807DFCACD7CD3C1D02FF9 7.2 https://vulners.com/httpd/HTTPD:FC354B921BA807DFCACD7CD3C1D02FF9
- | HTTPD:9CDB89FBD1162B1E462FDF5BEA375759 6.8 https://vulners.com/httpd/HTTPD:9CDB89FBD1162B1E462FDF5BEA375759
- | HTTPD:13B5FCC9676077F8FD08063C83511140 6.8 https://vulners.com/httpd/HTTPD:13B5FCC9676077F8FD08063C83511140
- | HTTPD:B057D0A07B0AC97248CE6210E08ACAF7 6.4 https://vulners.com/httpd/HTTPD:B057D0A07B0AC97248CE6210E08ACAF7
- | HTTPD:99188FFDCAF9C4932D00C218A2E58EC7 6.4 https://vulners.com/httpd/HTTPD:99188FFDCAF9C4932D00C218A2E58EC7
- | HTTPD:531CF2A74E1A5A02A1D6AE2505AD586F 6.4 https://vulners.com/httpd/HTTPD:531CF2A74E1A5A02A1D6AE2505AD586F
- | HTTPD:1696C4DDCBC58CE20005FCB002958C09 6.0 https://vulners.com/httpd/HTTPD:1696C4DDCBC58CE20005FCB002958C09
- | HTTPD:01BB9C701A4D4302EF59FA7EA89D9115 5.8 https://vulners.com/httpd/HTTPD:01BB9C701A4D4302EF59FA7EA89D9115
- | HTTPD:F292DF1CEE1729E4240D1D62A10F5D32 5.1 https://vulners.com/httpd/HTTPD:F292DF1CEE1729E4240D1D62A10F5D32
- | HTTPD:CE14FA5A5B1A2BE3A35EA809C9D8CFF7 5.1 https://vulners.com/httpd/HTTPD:CE14FA5A5B1A2BE3A35EA809C9D8CFF7
- | HTTPD:79096CA36FAE041205EFAB66A6D4EF4B 5.1 https://vulners.com/httpd/HTTPD:79096CA36FAE041205EFAB66A6D4EF4B
- | HTTPD:E91F31FD116386F2922B3EDA4BE3899B 5.0 https://vulners.com/httpd/HTTPD:E91F31FD116386F2922B3EDA4BE3899B
- | HTTPD:E05CACB9D575871BA1E3088D02930266 5.0 https://vulners.com/httpd/HTTPD:E05CACB9D575871BA1E3088D02930266
- | HTTPD:D7BF4648C333C0F770A30DEB0A23601C 5.0 https://vulners.com/httpd/HTTPD:D7BF4648C333C0F770A30DEB0A23601C
- | HTTPD:D5609C15618DCADFDAD5AD396F2B83D7 5.0 https://vulners.com/httpd/HTTPD:D5609C15618DCADFDAD5AD396F2B83D7
- | HTTPD:D5091608B1DC5DB5CABE405261B7658E 5.0 https://vulners.com/httpd/HTTPD:D5091608B1DC5DB5CABE405261B7658E
- | HTTPD:D26626D944F16D90B877FB157E4A128F 5.0 https://vulners.com/httpd/HTTPD:D26626D944F16D90B877FB157E4A128F
- | HTTPD:D0D55654F7429E8A4965CBBE30779CD6 5.0 https://vulners.com/httpd/HTTPD:D0D55654F7429E8A4965CBBE30779CD6
- | HTTPD:C191D6FAD0C97D0A2E0A2A9F7BFE6B38 5.0 https://vulners.com/httpd/HTTPD:C191D6FAD0C97D0A2E0A2A9F7BFE6B38
- | HTTPD:BD5F2FE0FF24D28F3450C11422A68AC8 5.0 https://vulners.com/httpd/HTTPD:BD5F2FE0FF24D28F3450C11422A68AC8
- | HTTPD:B2B68FFCE0FB45D09BE91EE9ECBA07F6 5.0 https://vulners.com/httpd/HTTPD:B2B68FFCE0FB45D09BE91EE9ECBA07F6
- | HTTPD:A5459AF02C9EC35CE80EA173C36C3F47 5.0 https://vulners.com/httpd/HTTPD:A5459AF02C9EC35CE80EA173C36C3F47
- | HTTPD:824D39D8A30F1234C966CBDA41E1C446 5.0 https://vulners.com/httpd/HTTPD:824D39D8A30F1234C966CBDA41E1C446
- | HTTPD:73656ED41609146303D488C86337BC2D 5.0 https://vulners.com/httpd/HTTPD:73656ED41609146303D488C86337BC2D
- | HTTPD:6CAC4F8B58BB2BE168795A6BA0CA26A1 5.0 https://vulners.com/httpd/HTTPD:6CAC4F8B58BB2BE168795A6BA0CA26A1
- | HTTPD:5D6E315A1B98558C0DF8CBE51264FBA5 5.0 https://vulners.com/httpd/HTTPD:5D6E315A1B98558C0DF8CBE51264FBA5
- | HTTPD:4EC9662496A151DDE6D030D9127572E7 5.0 https://vulners.com/httpd/HTTPD:4EC9662496A151DDE6D030D9127572E7
- | HTTPD:42FA2547862AB3B3F5E7F776E2D90614 5.0 https://vulners.com/httpd/HTTPD:42FA2547862AB3B3F5E7F776E2D90614
- | HTTPD:3647863A8E4AE972669D5EE60974E777 5.0 https://vulners.com/httpd/HTTPD:3647863A8E4AE972669D5EE60974E777
- | HTTPD:18105DABC6D0ADE97D12B90F63EAE025 5.0 https://vulners.com/httpd/HTTPD:18105DABC6D0ADE97D12B90F63EAE025
- | HTTPD:174A0D44882BCA7E2F229BC91D6D5A09 5.0 https://vulners.com/httpd/HTTPD:174A0D44882BCA7E2F229BC91D6D5A09
- | HTTPD:04C30566E99EFB3C0D60F08EE2524591 5.0 https://vulners.com/httpd/HTTPD:04C30566E99EFB3C0D60F08EE2524591
- | HTTPD:F4FBBB7467F08F96828B98E753E5FE7D 4.3 https://vulners.com/httpd/HTTPD:F4FBBB7467F08F96828B98E753E5FE7D
- | HTTPD:D94ACD37B5627A621B2D592BD44873F2 4.3 https://vulners.com/httpd/HTTPD:D94ACD37B5627A621B2D592BD44873F2
- | HTTPD:D26FFC4C8AA598C5F130A0223836644E 4.3 https://vulners.com/httpd/HTTPD:D26FFC4C8AA598C5F130A0223836644E
- | HTTPD:A5773ECB3CB67826707B252F21BB80BB 4.3 https://vulners.com/httpd/HTTPD:A5773ECB3CB67826707B252F21BB80BB
- | HTTPD:86C509FC37A85DC3C01E3CE10402C6DC 4.3 https://vulners.com/httpd/HTTPD:86C509FC37A85DC3C01E3CE10402C6DC
- | HTTPD:714A18409AEB3B8362DC4FA2B923CA7A 4.3 https://vulners.com/httpd/HTTPD:714A18409AEB3B8362DC4FA2B923CA7A
- | HTTPD:43E63F90DCA6F418ACF2327C4F88C3D8 4.3 https://vulners.com/httpd/HTTPD:43E63F90DCA6F418ACF2327C4F88C3D8
- | HTTPD:2E568217BC35E0AA91DF49E7CE65CA67 3.5 https://vulners.com/httpd/HTTPD:2E568217BC35E0AA91DF49E7CE65CA67
- | HTTPD:B6CF5630624F83951A477D36DC8FD634 0.0 https://vulners.com/httpd/HTTPD:B6CF5630624F83951A477D36DC8FD634
- | HTTPD:94C27BCF50CA81A222019B9F06735AA1 0.0 https://vulners.com/httpd/HTTPD:94C27BCF50CA81A222019B9F06735AA1
- | HTTPD:914D0BB6DF64CDA58BDF1461563DCBC2 0.0 https://vulners.com/httpd/HTTPD:914D0BB6DF64CDA58BDF1461563DCBC2
- | HTTPD:7ED2E94FC8175AF57B0B84C966E78986 0.0 https://vulners.com/httpd/HTTPD:7ED2E94FC8175AF57B0B84C966E78986
- | HTTPD:55F8C86BB4FE80544B301C6F772E1F21 0.0 https://vulners.com/httpd/HTTPD:55F8C86BB4FE80544B301C6F772E1F21
- | HTTPD:53F7D531D201D0209EE31F3FA8829F5B 0.0 https://vulners.com/httpd/HTTPD:53F7D531D201D0209EE31F3FA8829F5B
- |_ HTTPD:21A860C56B7B6A55960FB17E72B7E4B4 0.0 https://vulners.com/httpd/HTTPD:21A860C56B7B6A55960FB17E72B7E4B4
- | vulscan: VulDB - https://vuldb.com:
- | [88747] Apache HTTP Server 2.4.17/2.4.18 mod_http2 denial of service
- | [76731] Apache HTTP Server 2.4.12 ErrorDocument 400 Crash denial of service
- | [74367] Apache HTTP Server up to 2.4.12 mod_lua lua_request.c wsupgrade denial of service
- | [68575] Apache HTTP Server up to 2.4.10 LuaAuthzProvider mod_lua.c privilege escalation
- | [68435] Apache HTTP Server 2.4.10 mod_proxy_fcgi.c handle_headers denial of service
- | [13300] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi setuid privilege escalation
- | [13299] Apache HTTP Server 2.4.1/2.4.2 mod_wsgi Content-Type Header information disclosure
- | [136374] Apache HTTP Server up to 2.4.38 Slash Regular Expression unknown vulnerability
- | [136373] Apache HTTP Server 2.4.34/2.4.35/2.4.36/2.4.37/2.4.38 HTTP2 Request Crash denial of service
- | [136372] Apache HTTP Server up to 2.4.38 HTTP2 Request unknown vulnerability
- | [133112] Apache HTTP Server up to 2.4.38 mod_auth_digest race condition privilege escalation
- | [133111] Apache HTTP Server 2.4.37/2.4.38 mod_ssl Bypass privilege escalation
- | [130341] Apache HTTP Server 2.4.37 mod_ssl Loop denial of service
- | [130330] Apache HTTP Server up to 2.4.37 mod_session Expired privilege escalation
- | [130329] Apache HTTP Server 2.4.37 mod_http2 Slowloris denial of service
- | [124447] Apache HTTP Server up to 2.4.34 SETTINGS Frame denial of service
- | [121910] Apache HTTP Server 2.4.33 mod_md HTTP Requests denial of service
- | [122569] Apache HTTP Server up to 2.4.33 HTTP2 Request denial of service
- | [115061] Apache HTTP Server up to 2.4.29 HTTP Digest Authentication Challenge HTTP Requests Replay privilege escalation
- | [115060] Apache HTTP Server up to 2.4.29 mod_cache_socache Request Header Crash denial of service
- | [115059] Apache HTTP Server up to 2.4.29 HTTP2 NULL Pointer Dereference denial of service
- | [115058] Apache HTTP Server up to 2.4.29 HTTP Header Crash denial of service
- | [115057] Apache HTTP Server up to 2.4.29 mod_session Variable Name Cache privilege escalation
- | [115039] Apache HTTP Server up to 2.4.29 FilesMatch File Upload privilege escalation
- | [114258] Apache HTTP Server up to 2.4.22 mod_cluster Segmentation Fault denial of service
- | [104986] Apache CXF 2.4.5/2.5.1 WS-SP UsernameToken Policy SOAP Request weak authentication
- | [103521] Apache HTTP Server 2.4.26 HTTP2 Free memory corruption
- | [94627] Apache HTTP Server up to 2.4.24 mod_auth_digest Crash denial of service
- | [94626] Apache HTTP Server up to 2.4.24 mod_session_crypto Padding weak encryption
- | [94625] Apache HTTP Server up to 2.4.24 Response Split privilege escalation
- | [93958] Apache HTTP Server up to 2.4.23 mod_http2 h2_stream.c denial of service
- | [89669] Apache HTTP Server up to 2.4.23 RFC 3875 Namespace Conflict Environment Variable Open Redirect
- | [88667] Apache HTTP Server up to 2.4.20 mod_http2 Certificate weak authentication
- | [77083] Apache Groovy up to 2.4.3 MethodClosure.java MethodClosure memory corruption
- | [76733] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 ap_some_auth_required unknown vulnerability
- | [76732] Apache HTTP Server 2.4.7/2.4.8/2.4.9/2.4.10/2.4.12 Request apr_brigade_flatten privilege escalation
- | [73106] Apache Hadoop up to 2.4.0 Symlink privilege escalation
- | [67183] Apache HTTP Server up to 2.4.9 mod_proxy denial of service
- | [67180] Apache HTTP Server up to 2.4.9 WinNT MPM Memory Leak denial of service
- | [67185] Apache HTTP Server up to 2.4.9 mod_status Heap-Based memory corruption
- | [67184] Apache HTTP Server 2.4.5/2.4.6 mod_cache NULL Pointer Dereference denial of service
- | [67182] Apache HTTP Server up to 2.4.9 mod_deflate Memory Consumption denial of service
- | [67181] Apache HTTP Server up to 2.4.9 mod_cgid denial of service
- | [12667] Apache HTTP Server 2.4.7 mod_log_config.c log_cookie denial of service
- | [9683] Apache HTTP Server 2.4.5 mod_session_dbd denial of service
- | [7202] Apache HTTP Server 2.4.2 on Oracle Solaris ld_library_path cross site scripting
- | [62417] Apache CXF 2.4.7/2.4.8/2.5.3/2.5.4/2.6.1 spoofing
- | [6092] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_ajp.c information disclosure
- | [6090] Apache HTTP Server 2.4.0/2.4.1/2.4.2 mod_proxy_http.c information disclosure
- | [9673] Apache HTTP Server up to 2.4.4 mod_dav mod_dav.c Request denial of service
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2013-2249] mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.
- | [CVE-2012-4558] Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
- | [CVE-2012-3502] The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.
- | [CVE-2012-3499] Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
- | [CVE-2012-3451] Apache CXF before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to execute unintended web-service operations by sending a header with a SOAP Action String that is inconsistent with the message body.
- | [CVE-2012-2687] Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
- | [CVE-2012-2379] Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.
- | [CVE-2012-2378] Apache CXF 2.4.5 through 2.4.7, 2.5.1 through 2.5.3, and 2.6.x before 2.6.1, does not properly enforce child policies of a WS-SecurityPolicy 1.1 SupportingToken policy on the client side, which allows remote attackers to bypass the (1) AlgorithmSuite, (2) SignedParts, (3) SignedElements, (4) EncryptedParts, and (5) EncryptedElements policies.
- | [CVE-2012-0883] envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
- | [CVE-2011-2516] Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [42102] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
- | [27237] Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 'mod_status' Cross-Site Scripting Vulnerability
- | [15413] PHP Apache 2 Virtual() Safe_Mode and Open_Basedir Restriction Bypass Vulnerability
- | [15177] PHP Apache 2 Local Denial of Service Vulnerability
- | [6065] Apache 2 WebDAV CGI POST Request Information Disclosure Vulnerability
- | [5816] Apache 2 mod_dav Denial Of Service Vulnerability
- | [5486] Apache 2.0 CGI Path Disclosure Vulnerability
- | [5485] Apache 2.0 Path Disclosure Vulnerability
- | [5434] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
- | [5256] Apache httpd 2.0 CGI Error Path Disclosure Vulnerability
- | [4057] Apache 2 for Windows OPTIONS request Path Disclosure Vulnerability
- | [4056] Apache 2 for Windows php.exe Path Disclosure Vulnerability
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [75211] Debian GNU/Linux apache 2 cross-site scripting
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [31052] Apache <= 2.2.6 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
- | [30901] Apache HTTP Server 2.2.6 Windows Share PHP File Extension Mapping Information Disclosure Vulnerability
- | [30835] Apache HTTP Server <= 2.2.4 413 Error HTTP Request Method Cross-Site Scripting Weakness
- | [28424] Apache 2.x HTTP Server Arbitrary HTTP Request Headers Security Weakness
- | [28365] Apache 2.2.2 CGI Script Source Code Information Disclosure Vulnerability
- | [27915] Apache James 2.2 SMTP Denial of Service Vulnerability
- | [27135] Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
- | [26710] Apache CXF prior to 2.5.10, 2.6.7 and 2.7.4 - Denial of Service
- | [24590] Apache 2.0.x mod_ssl Remote Denial of Service Vulnerability
- | [23581] Apache 2.0.4x mod_perl Module File Descriptor Leakage Vulnerability
- | [23482] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (2)
- | [23481] Apache 2.0.4x mod_php Module File Descriptor Leakage Vulnerability (1)
- | [23296] Red Hat Apache 2.0.40 Directory Index Default Configuration Error
- | [23282] apache cocoon 2.14/2.2 - Directory Traversal vulnerability
- | [22191] Apache Web Server 2.0.x MS-DOS Device Name Denial of Service Vulnerability
- | [21854] Apache 2.0.39/40 Oversized STDERR Buffer Denial of Service Vulnerability
- | [21719] Apache 2.0 Path Disclosure Vulnerability
- | [21697] Apache 2.0 Encoded Backslash Directory Traversal Vulnerability
- | [20272] Apache 1.2.5/1.3.1,UnityMail 2.0 MIME Header DoS Vulnerability
- | [19828] Cobalt RaQ 2.0/3.0 Apache .htaccess Disclosure Vulnerability
- | [18984] Apache Struts <= 2.2.1.1 - Remote Command Execution
- | [18329] Apache Struts2 <= 2.3.1 - Multiple Vulnerabilities
- | [17691] Apache Struts < 2.2.0 - Remote Command Execution
- | [15319] Apache 2.2 (Windows) Local Denial of Service
- | [14617] Apache JackRabbit 2.0.0 webapp XPath Injection
- | [11650] Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit
- | [8458] Apache Geronimo <= 2.1.3 - Multiple Directory Traversal Vulnerabilities
- | [5330] Apache 2.0 mod_jk2 2.0.2 - Remote Buffer Overflow Exploit (win32)
- | [3996] Apache 2.0.58 mod_rewrite Remote Overflow Exploit (win2k3)
- | [2237] Apache < 1.3.37, 2.0.59, 2.2.3 (mod_rewrite) Remote Overflow PoC
- | [1056] Apache <= 2.0.49 Arbitrary Long HTTP Headers Denial of Service
- | [855] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit
- | [132] Apache 1.3.x - 2.0.48 - mod_userdir Remote Users Disclosure Exploit
- | [38] Apache <= 2.0.45 APR Remote Exploit -Apache-Knacker.pl
- | [34] Webfroot Shoutbox < 2.32 (Apache) Remote Exploit
- | [11] Apache <= 2.0.44 Linux Remote Denial of Service Exploit
- | [9] Apache HTTP Server 2.x Memory Leak Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [855524] Solaris Update for Apache 2 120544-14
- | [855077] Solaris Update for Apache 2 120543-14
- | [100858] Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability
- | [72626] Debian Security Advisory DSA 2579-1 (apache2)
- | [71551] Gentoo Security Advisory GLSA 201206-25 (apache)
- | [71550] Gentoo Security Advisory GLSA 201206-24 (apache tomcat)
- | [71485] Debian Security Advisory DSA 2506-1 (libapache-mod-security)
- | [71256] Debian Security Advisory DSA 2452-1 (apache2)
- | [71238] Debian Security Advisory DSA 2436-1 (libapache2-mod-fcgid)
- | [70724] Debian Security Advisory DSA 2405-1 (apache2)
- | [70235] Debian Security Advisory DSA 2298-2 (apache2)
- | [70233] Debian Security Advisory DSA 2298-1 (apache2)
- | [69988] Debian Security Advisory DSA 2279-1 (libapache2-mod-authnz-external)
- | [69338] Debian Security Advisory DSA 2202-1 (apache2)
- | [65131] SLES9: Security update for Apache 2 oes/CORE
- | [64426] Gentoo Security Advisory GLSA 200907-04 (apache)
- | [61381] Gentoo Security Advisory GLSA 200807-06 (apache)
- | [60582] Gentoo Security Advisory GLSA 200803-19 (apache)
- | [58745] Gentoo Security Advisory GLSA 200711-06 (apache)
- | [57851] Gentoo Security Advisory GLSA 200608-01 (apache)
- | [56246] Gentoo Security Advisory GLSA 200602-03 (Apache)
- | [55392] Gentoo Security Advisory GLSA 200509-12 (Apache)
- | [55129] Gentoo Security Advisory GLSA 200508-15 (apache)
- | [54739] Gentoo Security Advisory GLSA 200411-18 (apache)
- | [54724] Gentoo Security Advisory GLSA 200411-03 (apache)
- | [54712] Gentoo Security Advisory GLSA 200410-21 (apache)
- | [54689] Gentoo Security Advisory GLSA 200409-33 (net=www/apache)
- | [54677] Gentoo Security Advisory GLSA 200409-21 (apache)
- | [54610] Gentoo Security Advisory GLSA 200407-03 (Apache)
- | [54601] Gentoo Security Advisory GLSA 200406-16 (Apache)
- | [54590] Gentoo Security Advisory GLSA 200406-05 (Apache)
- | [54582] Gentoo Security Advisory GLSA 200405-22 (Apache)
- | [54529] Gentoo Security Advisory GLSA 200403-04 (Apache)
- | [54499] Gentoo Security Advisory GLSA 200310-04 (Apache)
- | [54498] Gentoo Security Advisory GLSA 200310-03 (Apache)
- | [11092] Apache 2.0.39 Win32 directory traversal
- | [66081] SLES11: Security update for Apache 2
- | [66074] SLES10: Security update for Apache 2
- | [66070] SLES9: Security update for Apache 2
- | [65893] SLES10: Security update for Apache 2
- | [65888] SLES10: Security update for Apache 2
- | [65510] SLES9: Security update for Apache 2
- | [65249] SLES9: Security update for Apache 2
- | [65230] SLES9: Security update for Apache 2
- | [65228] SLES9: Security update for Apache 2
- | [65207] SLES9: Security update for Apache 2
- | [65136] SLES9: Security update for Apache 2
- | [65017] SLES9: Security update for Apache 2
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1008196] Apache 2.x on Windows May Return Unexpected Files For URLs Ending With Certain Characters
- | [1007143] Apache 2.0 Web Server May Use a Weaker Encryption Implementation Than Specified in Some Cases
- | [1006444] Apache 2.0 Web Server Line Feed Buffer Allocation Flaw Lets Remote Users Deny Service
- | [1005963] Apache Web Server 2.x Windows Device Access Flaw Lets Remote Users Crash the Server or Possibly Execute Arbitrary Code
- | [1004770] Apache 2.x Web Server ap_log_rerror() Function May Disclose Full Installation Path to Remote Users
- |
- | OSVDB - http://www.osvdb.org:
- | [20897] PHP w/ Apache 2 SAPI virtual() Function Unspecified INI Setting Disclosure
- |_
- 465/tcp open ssl/smtp Postfix smtpd
- | vulscan: VulDB - https://vuldb.com:
- | [108975] Apple macOS up to 10.13.1 Postfix unknown vulnerability
- | [98314] PostfixAdmin up to 3.0.1 AliasHandler delete.php gen_show_status denial of service
- | [71720] Postfix up to 2.3.0 backup.php pacrypt sql injection
- | [12746] Postfix Admin 2.3.6 functions.inc.php sql injection
- | [57422] Postfix memory corruption
- | [56843] Postfix up to 2.7.2 Cleartext weak encryption
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2013-2852] Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
- | [CVE-2011-1720] The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
- | [CVE-2011-0411] The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
- | [CVE-2010-0230] SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
- | [CVE-2009-2939] The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
- | [CVE-2008-4977] ** DISPUTED ** postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it."
- | [CVE-2008-3889] Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.
- | [CVE-2008-3646] The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.
- | [CVE-2008-2937] Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.
- | [CVE-2008-2936] Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
- | [CVE-2007-3791] Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.
- | [CVE-2006-0213] Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
- | [CVE-2005-1127] Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.
- | [CVE-2005-0337] Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
- | [CVE-2004-1113] SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.
- | [CVE-2004-1088] Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
- | [CVE-2004-0925] Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
- | [CVE-2003-0540] The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
- | [CVE-2003-0468] Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.
- | [CVE-2001-0894] Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to email the postmaster when SMTP errors cause the session to terminate, allows remote attackers to cause a denial of service (memory exhaustion) by generating a large number of SMTP errors, which forces the SMTP session log to grow too large.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [96142] PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
- | [90814] Postfix Admin Multiple Cross Site Request Forgery Vulnerabilities
- | [67250] Postfix Arbitrary Content Security Bypass Vulnerability
- | [66455] Postfix Admin 'functions.inc.php' SQL Injection Vulnerability
- | [65184] Fail2ban Postfix Filter Remote Denial of Service Vulnerability
- | [51680] Postfix Admin Multiple SQL Injection and Cross Site Scripting Vulnerabilities
- | [47778] Postfix SMTP Server Cyrus SASL Support Memory Corruption Vulnerability
- | [36469] Debian and Ubuntu Postfix Insecure Temporary File Creation Vulnerability
- | [31721] Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
- | [30977] Postfix 'epoll' Linux Event Handler Local Denial of Service Vulnerability
- | [30691] Postfix Local Information Disclosure and Local Privilege Escalation Vulnerabilities
- | [13133] Salim Gasmi GLD Postfix Greylisting Daemon Format String Vulnerability
- | [13129] Salim Gasmi GLD Postfix Greylisting Daemon Buffer Overflow Vulnerability
- | [12445] Postfix IPv6 Unauthorized Mail Relay Vulnerability
- | [11898] SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
- | [11633] SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
- | [11323] Apple Mac OS X Postfix Release SMTPD AUTH Username Denial Of Service Vulnerability
- | [8362] Postfix SMTP Malformed E-mail Envelope Address Denial of Service Vulnerability
- | [8361] Postfix Connection Proxying Vulnerability
- | [8333] Multiple Postfix Denial of Service Vulnerabilities
- | [3638] SuSEConfig.postfix chroot Local DoS Attack Vulnerability
- | [3637] SuSEConfig.postfix chroot File Ownership Vulnerability
- | [3544] Postfix SMTP Log Denial Of Service Vulnerability
- | [1428] cyrus With postfix and Procmail Remote Shell Expansion Vulnerabilities
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [72752] Postfix Admin multiple parameters SQL injection
- | [72751] PostfixAdmin multiple parameters cross-site scripting
- | [67359] Postfix Cyrus SASL library in the SMTP server code execution
- | [55970] SUSE Linux Enterprise postfix security bypass
- | [53425] Postfix in Debian and Ubuntu pid symlink
- | [45876] Apple Mac OS X Postfix configuration file weak security
- | [44865] Postfix file descriptor denial of service
- | [44461] Postfix email information disclosure
- | [44460] Postfix symlink code execution
- | [22655] RHSA-2005:152 updates for postfix not installed
- | [19218] Postfix IPv6 mail relay
- | [18435] SQLgrey Postfix greylisting service SQL injection
- | [18353] Postfix CRAM-MD5 authentication replay attack
- | [17998] SQLgrey Postfix greylisting service SQL injection
- | [17595] Apple Mac OS postfix SMTPD AUTH denial of service
- | [12816] Postfix MAIL FROM or RCPT TO denial of service
- | [12815] Postfix could be used as a distributed denial of service tool
- | [7568] Postfix SMTP log denial of service
- | [4905] Cyrus with postfix and procmail integration could allow remote command execution
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [25392] Salim Gasmi GLD 1.x Postfix Greylisting Daemon Buffer Overflow Vulnerability
- | [22982] Postfix 1.1.x Denial of Service Vulnerabilities (2)
- | [22981] Postfix 1.1.x Denial of Service Vulnerabilities (1)
- | [16841] GLD (Greylisting Daemon) Postfix Buffer Overflow
- | [10023] Salim Gasmi GLD 1.0 - 1.4 Postfix Greylisting Buffer Overflow
- | [6472] Postfix < 2.4.9, 2.5.5, 2.6-20080902 - (.forward) Local DoS Exploit
- | [6337] Postfix <= 2.6-20080814 - (symlink) Local Privilege Escalation Exploit
- | [934] gld 1.4 (Postfix Greylisting Daemon) Remote Format String Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [902517] Postfix SMTP Server Cyrus SASL Support Memory Corruption Vulnerability
- | [881389] CentOS Update for postfix CESA-2011:0422 centos5 x86_64
- | [881293] CentOS Update for postfix CESA-2011:0843 centos4 x86_64
- | [881278] CentOS Update for postfix CESA-2011:0422 centos4 x86_64
- | [881267] CentOS Update for postfix CESA-2011:0843 centos5 x86_64
- | [880520] CentOS Update for postfix CESA-2011:0422 centos5 i386
- | [880509] CentOS Update for postfix CESA-2011:0843 centos5 i386
- | [880488] CentOS Update for postfix CESA-2011:0843 centos4 i386
- | [880485] CentOS Update for postfix CESA-2011:0422 centos4 i386
- | [880268] CentOS Update for postfix CESA-2008:0839 centos3 i386
- | [880023] CentOS Update for postfix CESA-2008:0839 centos3 x86_64
- | [870658] RedHat Update for postfix RHSA-2011:0423-01
- | [870440] RedHat Update for postfix RHSA-2011:0843-01
- | [870418] RedHat Update for postfix RHSA-2011:0422-01
- | [870021] RedHat Update for postfix RHSA-2008:0839-01
- | [863100] Fedora Update for postfix FEDORA-2011-6777
- | [863097] Fedora Update for postfix FEDORA-2011-6771
- | [862950] Fedora Update for postfix FEDORA-2011-3394
- | [862938] Fedora Update for postfix FEDORA-2011-3355
- | [860510] Fedora Update for postfix FEDORA-2008-8593
- | [860419] Fedora Update for postfix FEDORA-2008-8595
- | [850126] SuSE Update for postfix SUSE-SA:2010:011
- | [850031] SuSE Update for postfix SUSE-SA:2008:040
- | [840658] Ubuntu Update for postfix USN-1131-1
- | [840648] Ubuntu Update for postfix USN-1113-1
- | [840227] Ubuntu Update for postfix vulnerabilities USN-642-1
- | [840190] Ubuntu Update for postfix vulnerability USN-636-1
- | [831400] Mandriva Update for postfix MDVSA-2011:090 (postfix)
- | [830713] Mandriva Update for postfix MDVSA-2008:171 (postfix)
- | [830635] Mandriva Update for postfix MDVSA-2008:190 (postfix)
- | [830075] Mandriva Update for postfix MDKA-2007:079 (postfix)
- | [72452] Gentoo Security Advisory GLSA 201209-18 (postfixadmin)
- | [71559] Gentoo Security Advisory GLSA 201206-33 (Postfix)
- | [70744] FreeBSD Ports: postfixadmin
- | [69770] FreeBSD Ports: postfix, postfix-base
- | [69733] Debian Security Advisory DSA 2233-1 (postfix)
- | [69363] FreeBSD Ports: postfix, postfix-base
- | [66394] Mandriva Security Advisory MDVSA-2009:224-1 (postfix)
- | [65957] SLES10: Security update for Postfix
- | [65911] SLES10: Security update for Postfix
- | [65353] SLES9: Security update for Postfix
- | [65350] SLES9: Security update for postfix
- | [64696] Mandrake Security Advisory MDVSA-2009:224 (postfix)
- | [61646] Gentoo Security Advisory GLSA 200809-09 (postfix)
- | [61445] Gentoo Security Advisory GLSA 200808-12 (postfix)
- | [61435] Debian Security Advisory DSA 1629-2 (postfix)
- | [61434] Debian Security Advisory DSA 1629-1 (postfix)
- | [60836] FreeBSD Ports: postfix-policyd-weight
- | [58580] Debian Security Advisory DSA 1361-1 (postfix-policyd)
- | [53833] Debian Security Advisory DSA 093-1 (postfix)
- | [53652] Debian Security Advisory DSA 363-1 (postfix)
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1025521] Postfix SASL Authentication Heap Overflow Lets Remote Users Deny Service
- | [1025179] Postfix Plaintext to TLS Switching Error Lets Remote Users Inject Plaintext Commands
- | [1020800] Postfix Linux epoll File Descriptor Leak Lets Local Users Deny Service
- | [1020700] Postfix Symlink Dereference Bug Lets Local Users Gain Elevated Privileges
- | [1012395] Postfix CRAM-MD5 Replay Attack May Let Remote Users Send Mail
- | [1011532] Postfix Buffer Error May Prevent Remote Users from Being Able to Authenticate Using SMTPD AUTH
- | [1007382] Postfix Bounce Messages Let Remote Users Scan for Open Ports on Other Hosts
- | [1007381] Postfix Address Resolver Parsing Bug Lets Remote Users Hang the System
- | [1002756] Postfix Mail Server Can Be Crashed By Remote Users Initiating Unsuccessful Sessions
- |
- | OSVDB - http://www.osvdb.org:
- | [94034] Linux Kernel Broadcom B43 Wireless Driver b43_request_firmware Function fwpostfix modprobe Parameter Format String Local Privilege Escalation
- | [78567] Postfix Admin backup.php Unspecified SQL Injection
- | [78566] Postfix Admin functions.inc.php pacrypt() Function Unspecified SQL Injection
- | [78565] Postfix Admin create-domain.php Unspecified SQL Injection
- | [78564] Postfix Admin Unspecified XSS
- | [78563] Postfix Admin edit-alias.php Unspecified XSS
- | [78562] Postfix Admin create-alias.php Unspecified XSS
- | [78561] Postfix Admin create-domain.php Unspecified XSS
- | [78560] Postfix Admin templates/edit-vacation.php domain Parameter XSS
- | [78559] Postfix Admin templates/menu.php domain Parameter XSS
- | [72259] Postfix SMTP Cyrus SASL Authentication Context Data Reuse Memory Corruption
- | [71021] Postfix STARTTLS Arbitrary Plaintext Command Injection
- | [68340] Artica postfix.events.php Unrestricted Access Information Disclosure
- | [61983] SUSE Linux postfix Network Interface Remote Access Restriction Bypass
- | [58325] Debian GNU/Linux postfix postfix.postinst Symlink Arbitrary File Overwrite
- | [49634] Postfix postfix_groups.pl Multiple Temporary File Symlink Arbitrary File Overwrite
- | [48973] Apple Mac OS X Postfix Network Access Configuration Weakness
- | [48108] Postfix epoll File Descriptor Leak Local DoS
- | [47659] Postfix Cross-user Filename Local Mail Interception
- | [47658] Postfix Hardlink to Symlink Mailspool Arbitrary Content Append
- | [43888] policyd-weight for Postfix Socket Handling Unspecified Arbitrary File Manipulation
- | [38091] policyd for Postfix sockets.c read_w() Function SMTP Command Remote Overflow
- | [22381] Kolab Server Secure SMTP postfix.log Authentication Credential Disclosure
- | [13470] Postfix IPv6 Patch if_inet6 Failure Arbitrary Mail Relay
- | [12339] SQLgrey Postfix greylisting service Unspecified SQL Injection
- | [12200] Apple Mac OS X Postfix CRAM-MD5 Replay Credentials
- | [11571] SQLgrey Postfix greylisting Email Address SQL Injection
- | [10545] Postfix Multiple Mail Header SMTP listener DoS
- | [10544] Postfix Malformed Envelope Address nqmgr DoS
- | [10500] Apple Mac OS X Postfix SMTPD AUTH Username Overflow DoS
- | [6551] Postfix Bounce Scan / Packet Amplification DDoS
- | [1991] Postfix SMTP Log DoS
- |_
- 587/tcp open smtp Postfix smtpd
- | vulscan: VulDB - https://vuldb.com:
- | [108975] Apple macOS up to 10.13.1 Postfix unknown vulnerability
- | [98314] PostfixAdmin up to 3.0.1 AliasHandler delete.php gen_show_status denial of service
- | [71720] Postfix up to 2.3.0 backup.php pacrypt sql injection
- | [12746] Postfix Admin 2.3.6 functions.inc.php sql injection
- | [57422] Postfix memory corruption
- | [56843] Postfix up to 2.7.2 Cleartext weak encryption
- |
- | MITRE CVE - https://cve.mitre.org:
- | [CVE-2013-2852] Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.
- | [CVE-2011-1720] The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.
- | [CVE-2011-0411] The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.
- | [CVE-2010-0230] SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
- | [CVE-2009-2939] The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
- | [CVE-2008-4977] ** DISPUTED ** postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability, stating "This is not a real issue ... users would have to edit a script under /usr/lib to enable it."
- | [CVE-2008-3889] Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.
- | [CVE-2008-3646] The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.
- | [CVE-2008-2937] Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.
- | [CVE-2008-2936] Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script.
- | [CVE-2007-3791] Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.
- | [CVE-2006-0213] Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges.
- | [CVE-2005-1127] Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.
- | [CVE-2005-0337] Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
- | [CVE-2004-1113] SQL injection vulnerability in SQLgrey Postfix greylisting service before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) sender or (2) recipient e-mail addresses.
- | [CVE-2004-1088] Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
- | [CVE-2004-0925] Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
- | [CVE-2003-0540] The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
- | [CVE-2003-0468] Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.
- | [CVE-2001-0894] Vulnerability in Postfix SMTP server before 20010228-pl07, when configured to email the postmaster when SMTP errors cause the session to terminate, allows remote attackers to cause a denial of service (memory exhaustion) by generating a large number of SMTP errors, which forces the SMTP session log to grow too large.
- |
- | SecurityFocus - https://www.securityfocus.com/bid/:
- | [96142] PostfixAdmin CVE-2017-5930 Session Management Security Bypass Vulnerability
- | [90814] Postfix Admin Multiple Cross Site Request Forgery Vulnerabilities
- | [67250] Postfix Arbitrary Content Security Bypass Vulnerability
- | [66455] Postfix Admin 'functions.inc.php' SQL Injection Vulnerability
- | [65184] Fail2ban Postfix Filter Remote Denial of Service Vulnerability
- | [51680] Postfix Admin Multiple SQL Injection and Cross Site Scripting Vulnerabilities
- | [47778] Postfix SMTP Server Cyrus SASL Support Memory Corruption Vulnerability
- | [36469] Debian and Ubuntu Postfix Insecure Temporary File Creation Vulnerability
- | [31721] Apple Mac OS X 10.5 Postfix Security Bypass Vulnerability
- | [30977] Postfix 'epoll' Linux Event Handler Local Denial of Service Vulnerability
- | [30691] Postfix Local Information Disclosure and Local Privilege Escalation Vulnerabilities
- | [13133] Salim Gasmi GLD Postfix Greylisting Daemon Format String Vulnerability
- | [13129] Salim Gasmi GLD Postfix Greylisting Daemon Buffer Overflow Vulnerability
- | [12445] Postfix IPv6 Unauthorized Mail Relay Vulnerability
- | [11898] SQLgrey Postfix Greylisting Service Unspecified SQL Injection Vulnerability
- | [11633] SQLgrey Postfix Greylisting Service SQL Injection Vulnerability
- | [11323] Apple Mac OS X Postfix Release SMTPD AUTH Username Denial Of Service Vulnerability
- | [8362] Postfix SMTP Malformed E-mail Envelope Address Denial of Service Vulnerability
- | [8361] Postfix Connection Proxying Vulnerability
- | [8333] Multiple Postfix Denial of Service Vulnerabilities
- | [3638] SuSEConfig.postfix chroot Local DoS Attack Vulnerability
- | [3637] SuSEConfig.postfix chroot File Ownership Vulnerability
- | [3544] Postfix SMTP Log Denial Of Service Vulnerability
- | [1428] cyrus With postfix and Procmail Remote Shell Expansion Vulnerabilities
- |
- | IBM X-Force - https://exchange.xforce.ibmcloud.com:
- | [72752] Postfix Admin multiple parameters SQL injection
- | [72751] PostfixAdmin multiple parameters cross-site scripting
- | [67359] Postfix Cyrus SASL library in the SMTP server code execution
- | [55970] SUSE Linux Enterprise postfix security bypass
- | [53425] Postfix in Debian and Ubuntu pid symlink
- | [45876] Apple Mac OS X Postfix configuration file weak security
- | [44865] Postfix file descriptor denial of service
- | [44461] Postfix email information disclosure
- | [44460] Postfix symlink code execution
- | [22655] RHSA-2005:152 updates for postfix not installed
- | [19218] Postfix IPv6 mail relay
- | [18435] SQLgrey Postfix greylisting service SQL injection
- | [18353] Postfix CRAM-MD5 authentication replay attack
- | [17998] SQLgrey Postfix greylisting service SQL injection
- | [17595] Apple Mac OS postfix SMTPD AUTH denial of service
- | [12816] Postfix MAIL FROM or RCPT TO denial of service
- | [12815] Postfix could be used as a distributed denial of service tool
- | [7568] Postfix SMTP log denial of service
- | [4905] Cyrus with postfix and procmail integration could allow remote command execution
- |
- | Exploit-DB - https://www.exploit-db.com:
- | [25392] Salim Gasmi GLD 1.x Postfix Greylisting Daemon Buffer Overflow Vulnerability
- | [22982] Postfix 1.1.x Denial of Service Vulnerabilities (2)
- | [22981] Postfix 1.1.x Denial of Service Vulnerabilities (1)
- | [16841] GLD (Greylisting Daemon) Postfix Buffer Overflow
- | [10023] Salim Gasmi GLD 1.0 - 1.4 Postfix Greylisting Buffer Overflow
- | [6472] Postfix < 2.4.9, 2.5.5, 2.6-20080902 - (.forward) Local DoS Exploit
- | [6337] Postfix <= 2.6-20080814 - (symlink) Local Privilege Escalation Exploit
- | [934] gld 1.4 (Postfix Greylisting Daemon) Remote Format String Exploit
- |
- | OpenVAS (Nessus) - http://www.openvas.org:
- | [902517] Postfix SMTP Server Cyrus SASL Support Memory Corruption Vulnerability
- | [881389] CentOS Update for postfix CESA-2011:0422 centos5 x86_64
- | [881293] CentOS Update for postfix CESA-2011:0843 centos4 x86_64
- | [881278] CentOS Update for postfix CESA-2011:0422 centos4 x86_64
- | [881267] CentOS Update for postfix CESA-2011:0843 centos5 x86_64
- | [880520] CentOS Update for postfix CESA-2011:0422 centos5 i386
- | [880509] CentOS Update for postfix CESA-2011:0843 centos5 i386
- | [880488] CentOS Update for postfix CESA-2011:0843 centos4 i386
- | [880485] CentOS Update for postfix CESA-2011:0422 centos4 i386
- | [880268] CentOS Update for postfix CESA-2008:0839 centos3 i386
- | [880023] CentOS Update for postfix CESA-2008:0839 centos3 x86_64
- | [870658] RedHat Update for postfix RHSA-2011:0423-01
- | [870440] RedHat Update for postfix RHSA-2011:0843-01
- | [870418] RedHat Update for postfix RHSA-2011:0422-01
- | [870021] RedHat Update for postfix RHSA-2008:0839-01
- | [863100] Fedora Update for postfix FEDORA-2011-6777
- | [863097] Fedora Update for postfix FEDORA-2011-6771
- | [862950] Fedora Update for postfix FEDORA-2011-3394
- | [862938] Fedora Update for postfix FEDORA-2011-3355
- | [860510] Fedora Update for postfix FEDORA-2008-8593
- | [860419] Fedora Update for postfix FEDORA-2008-8595
- | [850126] SuSE Update for postfix SUSE-SA:2010:011
- | [850031] SuSE Update for postfix SUSE-SA:2008:040
- | [840658] Ubuntu Update for postfix USN-1131-1
- | [840648] Ubuntu Update for postfix USN-1113-1
- | [840227] Ubuntu Update for postfix vulnerabilities USN-642-1
- | [840190] Ubuntu Update for postfix vulnerability USN-636-1
- | [831400] Mandriva Update for postfix MDVSA-2011:090 (postfix)
- | [830713] Mandriva Update for postfix MDVSA-2008:171 (postfix)
- | [830635] Mandriva Update for postfix MDVSA-2008:190 (postfix)
- | [830075] Mandriva Update for postfix MDKA-2007:079 (postfix)
- | [72452] Gentoo Security Advisory GLSA 201209-18 (postfixadmin)
- | [71559] Gentoo Security Advisory GLSA 201206-33 (Postfix)
- | [70744] FreeBSD Ports: postfixadmin
- | [69770] FreeBSD Ports: postfix, postfix-base
- | [69733] Debian Security Advisory DSA 2233-1 (postfix)
- | [69363] FreeBSD Ports: postfix, postfix-base
- | [66394] Mandriva Security Advisory MDVSA-2009:224-1 (postfix)
- | [65957] SLES10: Security update for Postfix
- | [65911] SLES10: Security update for Postfix
- | [65353] SLES9: Security update for Postfix
- | [65350] SLES9: Security update for postfix
- | [64696] Mandrake Security Advisory MDVSA-2009:224 (postfix)
- | [61646] Gentoo Security Advisory GLSA 200809-09 (postfix)
- | [61445] Gentoo Security Advisory GLSA 200808-12 (postfix)
- | [61435] Debian Security Advisory DSA 1629-2 (postfix)
- | [61434] Debian Security Advisory DSA 1629-1 (postfix)
- | [60836] FreeBSD Ports: postfix-policyd-weight
- | [58580] Debian Security Advisory DSA 1361-1 (postfix-policyd)
- | [53833] Debian Security Advisory DSA 093-1 (postfix)
- | [53652] Debian Security Advisory DSA 363-1 (postfix)
- |
- | SecurityTracker - https://www.securitytracker.com:
- | [1025521] Postfix SASL Authentication Heap Overflow Lets Remote Users Deny Service
- | [1025179] Postfix Plaintext to TLS Switching Error Lets Remote Users Inject Plaintext Commands
- | [1020800] Postfix Linux epoll File Descriptor Leak Lets Local Users Deny Service
- | [1020700] Postfix Symlink Dereference Bug Lets Local Users Gain Elevated Privileges
- | [1012395] Postfix CRAM-MD5 Replay Attack May Let Remote Users Send Mail
- | [1011532] Postfix Buffer Error May Prevent Remote Users from Being Able to Authenticate Using SMTPD AUTH
- | [1007382] Postfix Bounce Messages Let Remote Users Scan for Open Ports on Other Hosts
- | [1007381] Postfix Address Resolver Parsing Bug Lets Remote Users Hang the System
- | [1002756] Postfix Mail Server Can Be Crashed By Remote Users Initiating Unsuccessful Sessions
- |
- | OSVDB - http://www.osvdb.org:
- | [94034] Linux Kernel Broadcom B43 Wireless Driver b43_request_firmware Function fwpostfix modprobe Parameter Format String Local Privilege Escalation
- | [78567] Postfix Admin backup.php Unspecified SQL Injection
- | [78566] Postfix Admin functions.inc.php pacrypt() Function Unspecified SQL Injection
- | [78565] Postfix Admin create-domain.php Unspecified SQL Injection
- | [78564] Postfix Admin Unspecified XSS
- | [78563] Postfix Admin edit-alias.php Unspecified XSS
- | [78562] Postfix Admin create-alias.php Unspecified XSS
- | [78561] Postfix Admin create-domain.php Unspecified XSS
- | [78560] Postfix Admin templates/edit-vacation.php domain Parameter XSS
- | [78559] Postfix Admin templates/menu.php domain Parameter XSS
- | [72259] Postfix SMTP Cyrus SASL Authentication Context Data Reuse Memory Corruption
- | [71021] Postfix STARTTLS Arbitrary Plaintext Command Injection
- | [68340] Artica postfix.events.php Unrestricted Access Information Disclosure
- | [61983] SUSE Linux postfix Network Interface Remote Access Restriction Bypass
- | [58325] Debian GNU/Linux postfix postfix.postinst Symlink Arbitrary File Overwrite
- | [49634] Postfix postfix_groups.pl Multiple Temporary File Symlink Arbitrary File Overwrite
- | [48973] Apple Mac OS X Postfix Network Access Configuration Weakness
- | [48108] Postfix epoll File Descriptor Leak Local DoS
- | [47659] Postfix Cross-user Filename Local Mail Interception
- | [47658] Postfix Hardlink to Symlink Mailspool Arbitrary Content Append
- | [43888] policyd-weight for Postfix Socket Handling Unspecified Arbitrary File Manipulation
- | [38091] policyd for Postfix sockets.c read_w() Function SMTP Command Remote Overflow
- | [22381] Kolab Server Secure SMTP postfix.log Authentication Credential Disclosure
- | [13470] Postfix IPv6 Patch if_inet6 Failure Arbitrary Mail Relay
- | [12339] SQLgrey Postfix greylisting service Unspecified SQL Injection
- | [12200] Apple Mac OS X Postfix CRAM-MD5 Replay Credentials
- | [11571] SQLgrey Postfix greylisting Email Address SQL Injection
- | [10545] Postfix Multiple Mail Header SMTP listener DoS
- | [10544] Postfix Malformed Envelope Address nqmgr DoS
- | [10500] Apple Mac OS X Postfix SMTPD AUTH Username Overflow DoS
- | [6551] Postfix Bounce Scan / Packet Amplification DDoS
- | [1991] Postfix SMTP Log DoS
- |_
- 993/tcp filtered imaps
- 995/tcp filtered pop3s
- 5355/tcp filtered llmnr
- 34816/tcp open mountd 1-3 (RPC #100005)
- 35643/tcp open nlockmgr 1-4 (RPC #100021)
- 36095/tcp open mountd 1-3 (RPC #100005)
- 47025/tcp open mountd 1-3 (RPC #100005)
- Aggressive OS guesses: Linux 4.4 (95%), Android 5.0.1 (94%), Linux 2.6.32 (94%), Linux 2.6.35 (94%), Linux 3.10 (94%), Linux 3.4 (94%), Linux 3.5 (94%), Linux 4.2 (94%), Synology DiskStation Manager 5.1 (94%), WatchGuard Fireware 11.8 (94%)
- No exact OS matches for host (test conditions non-ideal).
- Uptime guess: 40.636 days (since Wed Sep 11 18:23:44 2019)
- Network Distance: 11 hops
- TCP Sequence Prediction: Difficulty=261 (Good luck!)
- IP ID Sequence Generation: All zeros
- Service Info: Host: www.respectwashington.us
- TRACEROUTE (using port 554/tcp)
- HOP RTT ADDRESS
- 1 199.21 ms 10.252.204.1
- 2 341.72 ms 45.131.4.3
- 3 341.68 ms 109.236.95.226
- 4 341.76 ms 109.236.95.167
- 5 341.79 ms amsix-200gbps.core1.ams1.he.net (80.249.209.150)
- 6 341.82 ms 100ge16-1.core1.lon2.he.net (72.52.92.213)
- 7 341.86 ms 100ge13-2.core1.nyc4.he.net (72.52.92.166)
- 8 442.40 ms 100ge8-1.core1.sjc2.he.net (184.105.81.218)
- 9 442.44 ms 10ge4-4.core1.sjc1.he.net (72.52.92.117)
- 10 442.47 ms e0-50.core4.fmt1.he.net (184.105.65.214)
- 11 238.68 ms respectwashington.us (65.49.16.26)
- NSE: Script Post-scanning.
- Initiating NSE at 09:39
- Completed NSE at 09:39, 0.00s elapsed
- Initiating NSE at 09:39
- Completed NSE at 09:39, 0.00s elapsed
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 09:39 EDT
- NSE: Loaded 47 scripts for scanning.
- NSE: Script Pre-scanning.
- Initiating NSE at 09:39
- Completed NSE at 09:39, 0.00s elapsed
- Initiating NSE at 09:39
- Completed NSE at 09:39, 0.00s elapsed
- Initiating Parallel DNS resolution of 1 host. at 09:39
- Completed Parallel DNS resolution of 1 host. at 09:39, 0.02s elapsed
- Initiating UDP Scan at 09:39
- Scanning respectwashington.us (65.49.16.26) [15 ports]
- Completed UDP Scan at 09:39, 7.92s elapsed (15 total ports)
- Initiating Service scan at 09:39
- Scanning 1 service on respectwashington.us (65.49.16.26)
- Completed Service scan at 09:41, 97.59s elapsed (1 service on 1 host)
- Initiating OS detection (try #1) against respectwashington.us (65.49.16.26)
- Retrying OS detection (try #2) against respectwashington.us (65.49.16.26)
- Initiating Traceroute at 09:41
- Completed Traceroute at 09:41, 7.37s elapsed
- Initiating Parallel DNS resolution of 1 host. at 09:41
- Completed Parallel DNS resolution of 1 host. at 09:41, 0.00s elapsed
- NSE: Script scanning 65.49.16.26.
- Initiating NSE at 09:41
- Completed NSE at 09:41, 0.01s elapsed
- Initiating NSE at 09:41
- Completed NSE at 09:41, 1.64s elapsed
- Nmap scan report for respectwashington.us (65.49.16.26)
- Host is up (0.36s latency).
- PORT STATE SERVICE VERSION
- 53/udp closed domain
- 67/udp closed dhcps
- 68/udp closed dhcpc
- 69/udp closed tftp
- 88/udp closed kerberos-sec
- 123/udp closed ntp
- 137/udp filtered netbios-ns
- 138/udp filtered netbios-dgm
- 139/udp closed netbios-ssn
- 161/udp closed snmp
- 162/udp closed snmptrap
- 389/udp closed ldap
- 500/udp closed isakmp
- 520/udp closed route
- 2049/udp open|filtered nfs
- Too many fingerprints match this host to give specific OS details
- Network Distance: 11 hops
- TRACEROUTE (using port 137/udp)
- HOP RTT ADDRESS
- 1 ...
- 2 140.84 ms 10.252.204.1
- 3 ... 4
- 5 206.21 ms 10.252.204.1
- 6 221.54 ms 10.252.204.1
- 7 221.54 ms 10.252.204.1
- 8 221.53 ms 10.252.204.1
- 9 221.53 ms 10.252.204.1
- 10 221.50 ms 10.252.204.1
- 11 121.94 ms 10.252.204.1
- 12 ... 18
- 19 199.13 ms 10.252.204.1
- 20 141.69 ms 10.252.204.1
- 21 130.79 ms 10.252.204.1
- 22 ... 27
- 28 163.61 ms 10.252.204.1
- 29 ...
- 30 127.01 ms 10.252.204.1
- NSE: Script Post-scanning.
- Initiating NSE at 09:41
- Completed NSE at 09:41, 0.00s elapsed
- Initiating NSE at 09:41
- Completed NSE at 09:41, 0.00s elapsed
- ######################################################################################################################################
- Hosts
- =====
- address mac name os_name os_flavor os_sp purpose info comments
- ------- --- ---- ------- --------- ----- ------- ---- --------
- 65.49.16.26 respectwashington.us Linux 4.X server
- Services
- ========
- host port proto name state info
- ---- ---- ----- ---- ----- ----
- 65.49.16.26 53 udp domain closed
- 65.49.16.26 67 udp dhcps closed
- 65.49.16.26 68 udp dhcpc closed
- 65.49.16.26 69 udp tftp closed
- 65.49.16.26 80 tcp http open Apache httpd 2.4.18 (Ubuntu)
- 65.49.16.26 88 udp kerberos-sec closed
- 65.49.16.26 110 tcp pop3 filtered
- 65.49.16.26 123 udp ntp closed
- 65.49.16.26 137 udp netbios-ns filtered
- 65.49.16.26 138 udp netbios-dgm filtered
- 65.49.16.26 139 udp netbios-ssn closed
- 65.49.16.26 143 tcp imap filtered
- 65.49.16.26 161 udp snmp closed
- 65.49.16.26 162 udp snmptrap closed
- 65.49.16.26 389 udp ldap closed
- 65.49.16.26 443 tcp ssl/http open Apache httpd 2.4.18
- 65.49.16.26 465 tcp ssl/smtp open Postfix smtpd
- 65.49.16.26 500 udp isakmp closed
- 65.49.16.26 520 udp route closed
- 65.49.16.26 587 tcp smtp open Postfix smtpd
- 65.49.16.26 993 tcp imaps filtered
- 65.49.16.26 995 tcp pop3s filtered
- 65.49.16.26 2049 udp nfs unknown
- 65.49.16.26 5355 tcp llmnr filtered
- 65.49.16.26 34816 tcp mountd open 1-3 RPC #100005
- 65.49.16.26 35643 tcp nlockmgr open 1-4 RPC #100021
- 65.49.16.26 36095 tcp mountd open 1-3 RPC #100005
- 65.49.16.26 47025 tcp mountd open 1-3 RPC #100005
- #######################################################################################################################################
- Anonymous JTSEC #OpDomesticTerrorism Full Recon #6
Advertisement
Add Comment
Please, Sign In to add comment