JTSEC1333

Anonymous JTSEC #OpAssange Full Recon #19

Apr 29th, 2019
1,722
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 103.10 KB | None | 0 0
  1. #######################################################################################################################################
  2. =======================================================================================================================================
  3. Hostname www.inae.gob.ec ISP CORPORACION NACIONAL DE TELECOMUNICACIONES - CNT EP
  4. Continent South America Flag
  5. EC
  6. Country Ecuador Country Code EC
  7. Region Unknown Local time 29 Apr 2019 06:53 -05
  8. City Unknown Postal Code Unknown
  9. IP Address 190.214.11.74 Latitude -2
  10. Longitude -77.5
  11. =======================================================================================================================================
  12. #######################################################################################################################################
  13. > www.inae.gob.ec
  14. Server: 38.132.106.139
  15. Address: 38.132.106.139#53
  16.  
  17. Non-authoritative answer:
  18. Name: www.inae.gob.ec
  19. Address: 190.214.11.74
  20. >
  21. #######################################################################################################################################
  22. HostIP:190.214.11.74
  23. HostName:www.inae.gob.ec
  24.  
  25. Gathered Inet-whois information for 190.214.11.74
  26. ---------------------------------------------------------------------------------------------------------------------------------------
  27.  
  28.  
  29. inetnum: 189.0.0.0 - 192.5.27.255
  30. netname: NON-RIPE-NCC-MANAGED-ADDRESS-BLOCK
  31. descr: IPv4 address block not managed by the RIPE NCC
  32. remarks: ------------------------------------------------------
  33. remarks:
  34. remarks: For registration information,
  35. remarks: you can consult the following sources:
  36. remarks:
  37. remarks: IANA
  38. remarks: http://www.iana.org/assignments/ipv4-address-space
  39. remarks: http://www.iana.org/assignments/iana-ipv4-special-registry
  40. remarks: http://www.iana.org/assignments/ipv4-recovered-address-space
  41. remarks:
  42. remarks: AFRINIC (Africa)
  43. remarks: http://www.afrinic.net/ whois.afrinic.net
  44. remarks:
  45. remarks: APNIC (Asia Pacific)
  46. remarks: http://www.apnic.net/ whois.apnic.net
  47. remarks:
  48. remarks: ARIN (Northern America)
  49. remarks: http://www.arin.net/ whois.arin.net
  50. remarks:
  51. remarks: LACNIC (Latin America and the Carribean)
  52. remarks: http://www.lacnic.net/ whois.lacnic.net
  53. remarks:
  54. remarks: ------------------------------------------------------
  55. country: EU # Country is really world wide
  56. admin-c: IANA1-RIPE
  57. tech-c: IANA1-RIPE
  58. status: ALLOCATED UNSPECIFIED
  59. mnt-by: RIPE-NCC-HM-MNT
  60. created: 2019-01-07T10:49:25Z
  61. last-modified: 2019-01-07T10:49:25Z
  62. source: RIPE
  63.  
  64. role: Internet Assigned Numbers Authority
  65. address: see http://www.iana.org.
  66. admin-c: IANA1-RIPE
  67. tech-c: IANA1-RIPE
  68. nic-hdl: IANA1-RIPE
  69. remarks: For more information on IANA services
  70. remarks: go to IANA web site at http://www.iana.org.
  71. mnt-by: RIPE-NCC-MNT
  72. created: 1970-01-01T00:00:00Z
  73. last-modified: 2001-09-22T09:31:27Z
  74. source: RIPE # Filtered
  75.  
  76. % This query was served by the RIPE Database Query Service version 1.93.2 (HEREFORD)
  77.  
  78.  
  79.  
  80. Gathered Inic-whois information for inae.gob.ec
  81. ---------------------------------------------------------------------------------------------------------------------------------------
  82. Unable to connect: Socket Connect Error
  83. ERROR: Connection to InicWhois Server ec.whois-servers.net failed
  84.  
  85. Gathered Netcraft information for www.inae.gob.ec
  86. ---------------------------------------------------------------------------------------------------------------------------------------
  87.  
  88. Retrieving Netcraft.com information for www.inae.gob.ec
  89. Netcraft.com Information gathered
  90.  
  91. Gathered Subdomain information for inae.gob.ec
  92. ---------------------------------------------------------------------------------------------------------------------------------------
  93. Searching Google.com:80...
  94. HostName:www.inae.gob.ec
  95. HostIP:190.214.11.74
  96. Searching Altavista.com:80...
  97. Found 1 possible subdomain(s) for host inae.gob.ec, Searched 0 pages containing 0 results
  98.  
  99. Gathered E-Mail information for inae.gob.ec
  100. ---------------------------------------------------------------------------------------------------------------------------------------
  101. Searching Google.com:80...
  102. Searching Altavista.com:80...
  103. Found 0 E-Mail(s) for host inae.gob.ec, Searched 0 pages containing 0 results
  104.  
  105. Gathered TCP Port information for 190.214.11.74
  106. ---------------------------------------------------------------------------------------------------------------------------------------
  107.  
  108. Port State
  109.  
  110. 80/tcp open
  111.  
  112. Portscan Finished: Scanned 150 ports, 2 ports were in state closed
  113. #######################################################################################################################################
  114. [i] Scanning Site: http://www.inae.gob.ec
  115.  
  116.  
  117.  
  118. B A S I C I N F O
  119. =======================================================================================================================================
  120.  
  121.  
  122. [+] Site Title: Instituto Antártico Ecuatoriano – INAE
  123. [+] IP address: 190.214.11.74
  124. [+] Web Server: Could Not Detect
  125. [+] CMS: WordPress
  126. [+] Cloudflare: Not Detected
  127. [+] Robots File: Could NOT Find robots.txt!
  128.  
  129.  
  130. H T T P H E A D E R S
  131. =======================================================================================================================================
  132.  
  133.  
  134. [i] HTTP/1.1 200 OK
  135. [i] Date: Mon, 29 Apr 2019 12:48:37 GMT
  136. [i] X-Powered-By: PHP/5.4.16
  137. [i] X-UA-Compatible: IE=edge
  138. [i] Link: <http://www.inae.gob.ec/index.php/wp-json/>; rel="https://api.w.org/"
  139. [i] Link: <https://wp.me/P7hq3p-6>; rel=shortlink
  140. [i] Content-Type: text/html; charset=UTF-8
  141. [i] Connection: close
  142.  
  143.  
  144.  
  145.  
  146. D N S L O O K U P
  147. =======================================================================================================================================
  148.  
  149. inae.gob.ec. 7199 IN SOA root.andinanet.net. hostmaster.andinanet.net. 2018092401 14400 3600 604800 3600
  150. inae.gob.ec. 7199 IN NS pichincha.andinanet.net.
  151. inae.gob.ec. 7199 IN NS tungurahua.andinanet.net.
  152. inae.gob.ec. 7199 IN MX 10 mail.inae.gob.ec.
  153.  
  154.  
  155.  
  156.  
  157. S U B - D O M A I N F I N D E R
  158. =======================================================================================================================================
  159.  
  160.  
  161. [i] Total Subdomains Found : 1
  162.  
  163. [+] Subdomain: www.inae.gob.ec
  164. [-] IP: 190.214.11.74
  165. #######################################################################################################################################
  166. [?] Enter the target: example( http://domain.com )
  167. http://www.inae.gob.ec/
  168. [!] IP Address : 190.214.11.74
  169. [+] Operating System : CentOS
  170. [!] www.inae.gob.ec doesn't seem to use a CMS
  171. ---------------------------------------------------------------------------------------------------------------------------------------
  172. [~] Trying to gather whois information for www.inae.gob.ec
  173. [+] Whois information found
  174. [-] Unable to build response, visit https://who.is/whois/www.inae.gob.ec
  175. ---------------------------------------------------------------------------------------------------------------------------------------
  176. PORT STATE SERVICE
  177. 21/tcp filtered ftp
  178. 22/tcp filtered ssh
  179. 23/tcp filtered telnet
  180. 80/tcp open http
  181. 110/tcp filtered pop3
  182. 143/tcp filtered imap
  183. 443/tcp filtered https
  184. 3389/tcp filtered ms-wbt-server
  185. Nmap done: 1 IP address (1 host up) scanned in 2.36 seconds
  186. ---------------------------------------------------------------------------------------------------------------------------------------
  187. There was an error getting results
  188.  
  189. [-] DNS Records
  190. [>] Initiating 3 intel modules
  191. [>] Loading Alpha module (1/3)
  192. [>] Beta module deployed (2/3)
  193. [>] Gamma module initiated (3/3)
  194.  
  195.  
  196. [+] Emails found:
  197. ---------------------------------------------------------------------------------------------------------------------------------------
  198. No hosts found
  199. [+] Virtual hosts:
  200. ---------------------------------------------------------------------------------------------------------------------------------------
  201. #######################################################################################################################################
  202. =======================================================================================================================================
  203. | E-mails:
  204. | [+] E-mail Found: [email protected]
  205. | [+] E-mail Found: [email protected]
  206. | [+] E-mail Found: [email protected]
  207. | [+] E-mail Found: [email protected]
  208. | [+] E-mail Found: [email protected]
  209. | [+] E-mail Found: [email protected]
  210. | [+] E-mail Found: [email protected]
  211. | [+] E-mail Found: [email protected]
  212. | [+] E-mail Found: [email protected]
  213. | [+] E-mail Found: [email protected]
  214. | [+] E-mail Found: [email protected]
  215. | [+] E-mail Found: [email protected]
  216. | [+] E-mail Found: [email protected]
  217. | [+] E-mail Found: [email protected]
  218. | [+] E-mail Found: [email protected]
  219. | [+] E-mail Found: [email protected],
  220. | [+] E-mail Found: [email protected]
  221. | [+] E-mail Found: [email protected]
  222. | [+] E-mail Found: [email protected]
  223. | [+] E-mail Found: [email protected]
  224. | [+] E-mail Found: [email protected]
  225. | [+] E-mail Found: [email protected]
  226. | [+] E-mail Found: [email protected]
  227. | [+] E-mail Found: [email protected]
  228. | [+] E-mail Found: [email protected]
  229. | [+] E-mail Found: [email protected]
  230. | [+] E-mail Found: [email protected]
  231. | [+] E-mail Found: [email protected]
  232. | [+] E-mail Found: [email protected]
  233. | [+] E-mail Found: [email protected]
  234. | [+] E-mail Found: [email protected]
  235. | [+] E-mail Found: [email protected]
  236. | [+] E-mail Found: [email protected]
  237. | [+] E-mail Found: [email protected]
  238. | [+] E-mail Found: [email protected]
  239. | [+] E-mail Found: [email protected]
  240. | [+] E-mail Found: [email protected]
  241. | [+] E-mail Found: [email protected]
  242. | [+] E-mail Found: [email protected]
  243. | [+] E-mail Found: [email protected]
  244. | [+] E-mail Found: [email protected]
  245. | [+] E-mail Found: [email protected]
  246. | [+] E-mail Found: [email protected]
  247. | [+] E-mail Found: [email protected]
  248. | [+] E-mail Found: [email protected]
  249. | [+] E-mail Found: [email protected]
  250. | [+] E-mail Found: [email protected]
  251. | [+] E-mail Found: [email protected]
  252. | [+] E-mail Found: [email protected]
  253. | [+] E-mail Found: [email protected]
  254. | [+] E-mail Found: [email protected]
  255. | [+] E-mail Found: [email protected]
  256. | [+] E-mail Found: [email protected]
  257. | [+] E-mail Found: [email protected]
  258. | [+] E-mail Found: [email protected]
  259. | [+] E-mail Found: [email protected]
  260. | [+] E-mail Found: [email protected]
  261. | [+] E-mail Found: [email protected]
  262. | [+] E-mail Found: [email protected]
  263. | [+] E-mail Found: [email protected]
  264. | [+] E-mail Found: [email protected]
  265. | [+] E-mail Found: [email protected]
  266. | [+] E-mail Found: [email protected]
  267. | [+] E-mail Found: [email protected]
  268. | [+] E-mail Found: [email protected]
  269. | [+] E-mail Found: [email protected]
  270. | [+] E-mail Found: [email protected]
  271. | [+] E-mail Found: [email protected]
  272. | [+] E-mail Found: [email protected]
  273. | [+] E-mail Found: [email protected]
  274. | [+] E-mail Found: [email protected]
  275. | [+] E-mail Found: [email protected]
  276. | [+] E-mail Found: [email protected]
  277. | [+] E-mail Found: [email protected]
  278. | [+] E-mail Found: [email protected]
  279. | [+] E-mail Found: [email protected]
  280. | [+] E-mail Found: [email protected]
  281. | [+] E-mail Found: [email protected]
  282. | [+] E-mail Found: [email protected]
  283. | [+] E-mail Found: [email protected]
  284. | [+] E-mail Found: [email protected]
  285. | [+] E-mail Found: [email protected]
  286. | [+] E-mail Found: [email protected]
  287. | [+] E-mail Found: [email protected]
  288. | [+] E-mail Found: [email protected]
  289. | [+] E-mail Found: [email protected]
  290. | [+] E-mail Found: [email protected]
  291. | [+] E-mail Found: [email protected]
  292. | [+] E-mail Found: [email protected]
  293. | [+] E-mail Found: [email protected]
  294. | [+] E-mail Found: [email protected]
  295. | [+] E-mail Found: [email protected]
  296. | [+] E-mail Found: [email protected]
  297. | [+] E-mail Found: [email protected]
  298. | [+] E-mail Found: [email protected]
  299. | [+] E-mail Found: [email protected]
  300. | [+] E-mail Found: [email protected]
  301. | [+] E-mail Found: [email protected]
  302. | [+] E-mail Found: [email protected]
  303. | [+] E-mail Found: [email protected]
  304. | [+] E-mail Found: [email protected]
  305. | [+] E-mail Found: [email protected]
  306. | [+] E-mail Found: [email protected]
  307. | [+] E-mail Found: [email protected]
  308. | [+] E-mail Found: [email protected]
  309. | [+] E-mail Found: [email protected]
  310. | [+] E-mail Found: [email protected]
  311. | [+] E-mail Found: [email protected]
  312. =======================================================================================================================================
  313. | External hosts:
  314. | [+] External Host Found: http://wordpress.org
  315. | [+] External Host Found: https://www.ccamlr.org
  316. | [+] External Host Found: http://www.eltelegrafo.com.ec
  317. | [+] External Host Found: http://site.com
  318. | [+] External Host Found: https://www.ats.aq
  319. | [+] External Host Found: https://www.eluniverso.com
  320. | [+] External Host Found: https://twitter.com
  321. | [+] External Host Found: http://www.elcomercio.com
  322. | [+] External Host Found: https://es.unesco.org
  323. | [+] External Host Found: http://www.ilo.org
  324. | [+] External Host Found: https://www.researchgate.net
  325. | [+] External Host Found: https://www.facebook.com
  326. | [+] External Host Found: http://www.mysql.com
  327. | [+] External Host Found: https://i1.wp.com
  328. | [+] External Host Found: https://www.metaslider.com
  329. | [+] External Host Found: https://codex.wordpress.org
  330. | [+] External Host Found: http://www.socioempleo.gob.ec)
  331. | [+] External Host Found: https://www.publimetro.cl
  332. | [+] External Host Found: https://i0.wp.com
  333. | [+] External Host Found: http://planet.wordpress.org
  334. | [+] External Host Found: https://roundme.com
  335. | [+] External Host Found: http://www.subpesca.cl
  336. | [+] External Host Found: http://inae.gob.ec
  337. | [+] External Host Found: https://siteorigin.com
  338. | [+] External Host Found: https://wp.me
  339. | [+] External Host Found: https://wordpress.org
  340. | [+] External Host Found: http://codex.wordpress.org
  341. | [+] External Host Found: http://www.expreso.ec
  342. | [+] External Host Found: http://gmpg.org
  343. | [+] External Host Found: http://es.wikipedia.org
  344. | [+] External Host Found: http://www.biodiversity.aq
  345. | [+] External Host Found: http://www.wpcolumns.com
  346. | [+] External Host Found: https://github.com
  347. | [+] External Host Found: https://s0.wp.com
  348. | [+] External Host Found: https://secure.gravatar.com
  349. | [+] External Host Found: https://www.scar.org
  350. | [+] External Host Found: https://www.comnap.aq
  351. | [+] External Host Found: http://expreso.ec
  352. | [+] External Host Found: http://192.168.0.12
  353. | [+] External Host Found: https://themepoints.com
  354. | [+] External Host Found: http://www.persistenciathemovie.com
  355. | [+] External Host Found: http://www.scar.org
  356. | [+] External Host Found: https://scontent-lga3-1.xx.fbcdn.net
  357. | [+] External Host Found: http://httpd.apache.org
  358. | [+] External Host Found: https://www.lahora.com.ec
  359. | [+] External Host Found: http://es.forums.wordpress.org
  360. | [+] External Host Found: http://php.net
  361. | [+] External Host Found: https://lahora.com.ec
  362. | [+] External Host Found: http://comunidadplanetaazul.com
  363. =======================================================================================================================================
  364. #######################################################################################################################################
  365. ; <<>> DiG 9.11.5-P4-3-Debian <<>> inae.gob.ec
  366. ;; global options: +cmd
  367. ;; Got answer:
  368. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59663
  369. ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
  370.  
  371. ;; OPT PSEUDOSECTION:
  372. ; EDNS: version: 0, flags:; udp: 4096
  373. ;; QUESTION SECTION:
  374. ;inae.gob.ec. IN A
  375.  
  376. ;; AUTHORITY SECTION:
  377. inae.gob.ec. 3600 IN SOA root.andinanet.net. hostmaster.andinanet.net. 2018092401 14400 3600 604800 3600
  378.  
  379. ;; Query time: 65 msec
  380. ;; SERVER: 38.132.106.139#53(38.132.106.139)
  381. ;; WHEN: lun avr 29 10:32:11 EDT 2019
  382. ;; MSG SIZE rcvd: 105
  383. #######################################################################################################################################
  384. ; <<>> DiG 9.11.5-P4-3-Debian <<>> +trace inae.gob.ec
  385. ;; global options: +cmd
  386. . 83086 IN NS k.root-servers.net.
  387. . 83086 IN NS h.root-servers.net.
  388. . 83086 IN NS i.root-servers.net.
  389. . 83086 IN NS a.root-servers.net.
  390. . 83086 IN NS m.root-servers.net.
  391. . 83086 IN NS d.root-servers.net.
  392. . 83086 IN NS g.root-servers.net.
  393. . 83086 IN NS c.root-servers.net.
  394. . 83086 IN NS l.root-servers.net.
  395. . 83086 IN NS j.root-servers.net.
  396. . 83086 IN NS b.root-servers.net.
  397. . 83086 IN NS e.root-servers.net.
  398. . 83086 IN NS f.root-servers.net.
  399. . 83086 IN RRSIG NS 8 0 518400 20190512050000 20190429040000 25266 . bQWAaqwMGyuKJ43sy8YDogYmQbm0CPjSlIxhdSa5QhQXjWArYKeHpS/F oaoDGBoDxxTkNKDqhFp5NWZikNXGfzDr6VdYnWoRzhscK7gMC0UFdiLf HelwaJ8agLehlq9Hp6mX2AVUdTd0UfZcRioI3OS6azSMGEocNI96T4+9 AJ633UU62cSMEzxE/t+5U6p2Vc/JDwg4Ji9n9mPNJSN3oeBlyB4MXfLz 0/GpNbEagyWJOhWzpRyo4/DOTFxG8tyrnZWYLe88f8Brkdxm0AFg7xAh E55hO+57oGciCR0xffYvtJMX/oPll1Qa6tlGBBIZXtKwSsiktKA115Mw w6mLWQ==
  400. ;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 31 ms
  401.  
  402. ec. 172800 IN NS sns-pb.isc.org.
  403. ec. 172800 IN NS a.lactld.org.
  404. ec. 172800 IN NS n3.dns.ec.
  405. ec. 172800 IN NS n2.nic.ec.
  406. ec. 86400 IN NSEC eco. NS RRSIG NSEC
  407. ec. 86400 IN RRSIG NSEC 8 1 86400 20190512050000 20190429040000 25266 . AAKUGZvhFeyG7SUGomscjoUOE5zx2Ho+5hKKtKKq3PGxYrBYYB6zh93H 7C1zZdGvz4sr4PDcUVw9XrGTYK/E5nAphwuwTZvQA46Q6XBObaRm8n7a uSucjLzbzdCEi1q2BQKi/cWej6gJ3dpQ8UGwFxbofckxXRm8uRAEUgG2 o2S5BMIMl2lUDpFua1aRw6h4cN2TlCs0kgxWwP+LKWqvsgEby35m/a/p sqJ6jq2Y3Krj+w7857+uKFm7p9yJ7M1Zif+U3SitFPpAB7zBLSP+YtwI PE4l11/1coj+pVQn/M1G1IK0vBZ6ItdAGr74iTx6s5bGHLWWz8Mi0Oo9 dwrNNQ==
  408. ;; Received 649 bytes from 192.33.4.12#53(c.root-servers.net) in 29 ms
  409.  
  410. inae.gob.ec. 129600 IN NS pichincha.andinanet.net.
  411. inae.gob.ec. 129600 IN NS tungurahua.andinanet.net.
  412. ;; Received 130 bytes from 2001:500:2e::1#53(sns-pb.isc.org) in 98 ms
  413.  
  414. inae.gob.ec. 3600 IN SOA root.andinanet.net. hostmaster.andinanet.net. 2018092401 14400 3600 604800 3600
  415. ;; Received 105 bytes from 200.107.10.110#53(pichincha.andinanet.net) in 74 ms
  416. #######################################################################################################################################
  417. [*] Performing General Enumeration of Domain: inae.gob.ec
  418. [-] DNSSEC is not configured for inae.gob.ec
  419. [-] Error while resolving SOA record.
  420. [-] Error while resolving SOA record.
  421. [*] NS tungurahua.andinanet.net 200.107.10.110
  422. [*] Bind Version for 200.107.10.110 3.2.2
  423. [*] NS tungurahua.andinanet.net 2800:370:10::110
  424. [*] Bind Version for 2800:370:10::110 3.2.2
  425. [*] NS pichincha.andinanet.net 200.107.10.110
  426. [*] Bind Version for 200.107.10.110 3.2.2
  427. [*] NS pichincha.andinanet.net 2800:370:10::110
  428. [*] Bind Version for 2800:370:10::110 3.2.2
  429. [*] MX mail.inae.gob.ec 190.214.11.76
  430. [*] Enumerating SRV Records
  431. [-] No SRV Records Found for inae.gob.ec
  432. [+] 0 Records Found
  433. #######################################################################################################################################
  434. [*] Processing domain inae.gob.ec
  435. [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  436. [+] Getting nameservers
  437. 200.107.10.110 - tungurahua.andinanet.net
  438. 200.107.10.110 - pichincha.andinanet.net
  439. [-] Zone transfer failed
  440.  
  441. [+] MX records found, added to target list
  442. 10 mail.inae.gob.ec.
  443.  
  444. [*] Scanning inae.gob.ec for A records
  445. 190.214.11.76 - mail.inae.gob.ec
  446. 190.214.11.74 - www.inae.gob.ec
  447. #######################################################################################################################################
  448. Ip Address Status Type Domain Name Server
  449. ---------- ------ ---- ----------- ------
  450. 190.214.11.76 host mail.inae.gob.ec
  451. 190.214.11.74 200 host www.inae.gob.ec Apache/2.4.6 (CentOS) PHP/5.4.16
  452. #######################################################################################################################################
  453. [+] Testing domain
  454. www.inae.gob.ec 190.214.11.74
  455. [+] Dns resolving
  456. No address associated with hostname inae.gob.ec
  457. [+] Testing wildcard
  458. Ok, no wildcard found.
  459.  
  460. [+] Scanning for subdomain on inae.gob.ec
  461. [!] Wordlist not specified. I scannig with my internal wordlist...
  462. Estimated time about 57.68 seconds
  463.  
  464. Subdomain Ip address Name server
  465.  
  466. mail.inae.gob.ec 190.214.11.76 76.11.214.190.static.anycast.cnt-grms.ec
  467. www.inae.gob.ec 190.214.11.74 74.11.214.190.static.anycast.cnt-grms.ec
  468.  
  469. #######################################################################################################################################
  470. ---------------------------------------------------------------------------------------------------------------------------------------
  471. + Target IP: 190.214.11.74
  472. + Target Hostname: www.inae.gob.ec
  473. + Target Port: 80
  474. + Start Time: 2019-04-29 09:24:52 (GMT-4)
  475. ---------------------------------------------------------------------------------------------------------------------------------------
  476. + Server: No banner retrieved
  477. + Retrieved x-powered-by header: PHP/5.4.16
  478. + The anti-clickjacking X-Frame-Options header is not present.
  479. + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
  480. + Uncommon header 'link' found, with multiple values: (<http://www.inae.gob.ec/index.php/wp-json/>; rel="https://api.w.org/",<https://wp.me/P7hq3p-6>; rel=shortlink,)
  481. + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
  482. + Server banner has changed from '' to 'Apache/2.4.6 (CentOS) PHP/5.4.16' which may suggest a WAF, load balancer or proxy is in place
  483. + Web Server returns a valid response with junk HTTP methods, this may cause false positives.
  484. + DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
  485. + OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
  486. + OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  487. + OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  488. + OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  489. + OSVDB-3268: /icons/: Directory indexing found.
  490. + OSVDB-3233: /icons/README: Apache default file found.
  491. + /wp-content/plugins/akismet/readme.txt: The WordPress Akismet plugin 'Tested up to' version usually matches the WordPress version
  492. + /wp-links-opml.php: This WordPress script reveals the installed version.
  493. + OSVDB-3092: /license.txt: License file found may identify site software.
  494. + /: A Wordpress installation was found.
  495. + Cookie wordpress_test_cookie created without the httponly flag
  496. + OSVDB-3268: /wp-content/uploads/: Directory indexing found.
  497. + /wp-content/uploads/: Wordpress uploads directory is browsable. This may reveal sensitive information
  498. + 26589 requests: 0 error(s) and 20 item(s) reported on remote host
  499. + End Time: 2019-04-29 10:48:09 (GMT-4) (4997 seconds)
  500. ---------------------------------------------------------------------------------------------------------------------------------------
  501. #######################################################################################################################################
  502. dnsenum VERSION:1.2.4
  503.  
  504. ----- www.inae.gob.ec -----
  505.  
  506.  
  507. Host's addresses:
  508. __________________
  509.  
  510. www.inae.gob.ec. 7200 IN A 190.214.11.74
  511.  
  512.  
  513. Name Servers:
  514. ______________
  515. #######################################################################################################################################
  516. ===============================================
  517. -=Subfinder v1.1.3 github.com/subfinder/subfinder
  518. ===============================================
  519.  
  520.  
  521. Running Source: Ask
  522. Running Source: Archive.is
  523. Running Source: Baidu
  524. Running Source: Bing
  525. Running Source: CertDB
  526. Running Source: CertificateTransparency
  527. Running Source: Certspotter
  528. Running Source: Commoncrawl
  529. Running Source: Crt.sh
  530. Running Source: Dnsdb
  531. Running Source: DNSDumpster
  532. Running Source: DNSTable
  533. Running Source: Dogpile
  534. Running Source: Exalead
  535. Running Source: Findsubdomains
  536. Running Source: Googleter
  537. Running Source: Hackertarget
  538. Running Source: Ipv4Info
  539. Running Source: PTRArchive
  540. Running Source: Sitedossier
  541. Running Source: Threatcrowd
  542. Running Source: ThreatMiner
  543. Running Source: WaybackArchive
  544. Running Source: Yahoo
  545.  
  546. Running enumeration on www.inae.gob.ec
  547.  
  548. dnsdb: Unexpected return status 503
  549.  
  550. waybackarchive: parse http://web.archive.org/cdx/search/cdx?url=*.www.inae.gob.ec/*&output=json&fl=original&collapse=urlkey&page=: net/url: invalid control character in URL
  551.  
  552. dogpile: Get https://www.dogpile.com/search/web?q=www.inae.gob.ec&qsi=1: EOF
  553.  
  554.  
  555. Starting Bruteforcing of www.inae.gob.ec with 9985 words
  556.  
  557. Total 1 Unique subdomains found for www.inae.gob.ec
  558.  
  559. .www.inae.gob.ec
  560. #######################################################################################################################################
  561. [*] Processing domain www.inae.gob.ec
  562. [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  563. [+] Getting nameservers
  564. [-] Getting nameservers failed
  565. [-] Zone transfer failed
  566.  
  567. [*] Scanning www.inae.gob.ec for A records
  568. 190.214.11.74 - www.inae.gob.ec
  569. #######################################################################################################################################
  570. [+] www.inae.gob.ec has no SPF record!
  571. [*] No DMARC record found. Looking for organizational record
  572. [+] No organizational DMARC record
  573. [+] Spoofing possible for www.inae.gob.ec!
  574. #######################################################################################################################################
  575. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 09:34 EDT
  576. Nmap scan report for www.inae.gob.ec (190.214.11.74)
  577. Host is up (0.068s latency).
  578. rDNS record for 190.214.11.74: 74.11.214.190.static.anycast.cnt-grms.ec
  579. Not shown: 472 filtered ports, 3 closed ports
  580. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  581. PORT STATE SERVICE
  582. 80/tcp open http
  583. #######################################################################################################################################
  584. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 09:34 EDT
  585. Nmap scan report for www.inae.gob.ec (190.214.11.74)
  586. Host is up (0.025s latency).
  587. rDNS record for 190.214.11.74: 74.11.214.190.static.anycast.cnt-grms.ec
  588. Not shown: 2 filtered ports
  589. PORT STATE SERVICE
  590. 53/udp open|filtered domain
  591. 67/udp open|filtered dhcps
  592. 68/udp open|filtered dhcpc
  593. 69/udp open|filtered tftp
  594. 88/udp open|filtered kerberos-sec
  595. 123/udp open|filtered ntp
  596. 139/udp open|filtered netbios-ssn
  597. 161/udp open|filtered snmp
  598. 162/udp open|filtered snmptrap
  599. 389/udp open|filtered ldap
  600. 520/udp open|filtered route
  601. 2049/udp open|filtered nfs
  602. #######################################################################################################################################
  603. http://www.inae.gob.ec/wp-content/themes/twentyten/languages/twentyten.pot ERROR: Timed out execution expired
  604. http://www.inae.gob.ec [200 OK] Apache[2.4.6], Country[ECUADOR][EC], Email[[email protected]], Frame, HTML5, HTTPServer[CentOS][Apache/2.4.6 (CentOS) PHP/5.4.16], IP[190.214.11.74], JQuery[1.12.4], MetaGenerator[WordPress 4.7.3], Open-Graph-Protocol[website], PHP[5.4.16], PoweredBy[Shareaholic], Script[text/javascript], Title[Instituto Antártico Ecuatoriano &#8211; INAE], UncommonHeaders[link], WordPress[4.7,4.7.3], X-Powered-By[PHP/5.4.16], X-UA-Compatible[IE=10,IE=edge], YouTube
  605. #######################################################################################################################################
  606.  
  607. wig - WebApp Information Gatherer
  608.  
  609.  
  610. Scanning http://www.inae.gob.ec...
  611. _______________________________ SITE INFO ________________________________
  612. IP Title
  613. 190.214.11.74 Instituto Antártico Ecuatoriano &#8211; INAE
  614.  
  615. ________________________________ VERSION _________________________________
  616. Name Versions Type
  617. WordPress 4.7 CMS
  618. Apache 2.4.6 Platform
  619. PHP 5.4.16 Platform
  620. CentOS 7-1511 | 7.0-1406 | 7.1-1503 OS
  621.  
  622. ______________________________ INTERESTING _______________________________
  623. URL Note Type
  624. /readme.html Wordpress readme Interesting
  625. /readme.html Readme file Interesting
  626.  
  627. _________________________________ TOOLS __________________________________
  628. Name Link Software
  629. wpscan https://github.com/wpscanteam/wpscan WordPress
  630. CMSmap https://github.com/Dionach/CMSmap WordPress
  631.  
  632. __________________________________________________________________________
  633. Time: 420.1 sec Urls: 824 Fingerprints: 40401
  634. #######################################################################################################################################
  635. HTTP/1.1 200 OK
  636. Date: Mon, 29 Apr 2019 13:42:47 GMT
  637. Server: Apache/2.4.6 (CentOS) PHP/5.4.16
  638. X-Powered-By: PHP/5.4.16
  639. X-UA-Compatible: IE=edge
  640. Link: <http://www.inae.gob.ec/index.php/wp-json/>; rel="https://api.w.org/"
  641. Link: <https://wp.me/P7hq3p-6>; rel=shortlink
  642. Content-Type: text/html; charset=UTF-8
  643.  
  644. HTTP/1.1 200 OK
  645. Date: Mon, 29 Apr 2019 13:42:50 GMT
  646. Server: Apache/2.4.6 (CentOS) PHP/5.4.16
  647. X-Powered-By: PHP/5.4.16
  648. X-UA-Compatible: IE=edge
  649. Link: <http://www.inae.gob.ec/index.php/wp-json/>; rel="https://api.w.org/"
  650. Link: <https://wp.me/P7hq3p-6>; rel=shortlink
  651. Content-Type: text/html; charset=UTF-8
  652. #######################################################################################################################################
  653. jQuery Migrate
  654. Apache 2.4.6
  655. Twitter
  656. WordPress 4.7.3
  657. jQuery 1.12.4
  658. PHP 5.4.16
  659. YouTube
  660. CentOS
  661. WordPress
  662. X-UA-Compatible: IE=edge
  663. #######################################################################################################################################
  664. --------------------------------------------------------
  665. <<<Yasuo discovered following vulnerable applications>>>
  666. --------------------------------------------------------
  667. +------------+-------------------------------------+--------------------------------------------------+----------+----------+
  668. | App Name | URL to Application | Potential Exploit | Username | Password |
  669. +------------+-------------------------------------+--------------------------------------------------+----------+----------+
  670. | phpMyAdmin | http://190.214.11.74:80/phpmyadmin/ | ./exploits/multi/http/phpmyadmin_preg_replace.rb | | |
  671. +------------+-------------------------------------+--------------------------------------------------+----------+----------+
  672. #######################################################################################################################################
  673. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:07 EDT
  674. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  675. Host is up (0.11s latency).
  676. Not shown: 472 filtered ports, 3 closed ports
  677. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  678. PORT STATE SERVICE
  679. 80/tcp open http
  680. #######################################################################################################################################
  681. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:07 EDT
  682. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  683. Host is up (0.021s latency).
  684. Not shown: 2 filtered ports
  685. PORT STATE SERVICE
  686. 53/udp open|filtered domain
  687. 67/udp open|filtered dhcps
  688. 68/udp open|filtered dhcpc
  689. 69/udp open|filtered tftp
  690. 88/udp open|filtered kerberos-sec
  691. 123/udp open|filtered ntp
  692. 139/udp open|filtered netbios-ssn
  693. 161/udp open|filtered snmp
  694. 162/udp open|filtered snmptrap
  695. 389/udp open|filtered ldap
  696. 520/udp open|filtered route
  697. 2049/udp open|filtered nfs
  698. #######################################################################################################################################
  699. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:07 EDT
  700. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  701. Host is up (0.14s latency).
  702.  
  703. PORT STATE SERVICE VERSION
  704. 67/udp open|filtered dhcps
  705. |_dhcp-discover: ERROR: Script execution failed (use -d to debug)
  706. Too many fingerprints match this host to give specific OS details
  707. Network Distance: 13 hops
  708.  
  709. TRACEROUTE (using proto 1/icmp)
  710. HOP RTT ADDRESS
  711. 1 24.82 ms 10.247.200.1
  712. 2 25.17 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  713. 3 46.60 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  714. 4 24.85 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  715. 5 24.99 ms motl-b1-link.telia.net (62.115.162.41)
  716. 6 ...
  717. 7 35.28 ms nyk-b6-link.telia.net (62.115.125.63)
  718. 8 37.28 ms corporacionnacional-ic-326985-nyk-b6.c.telia.net (213.248.91.41)
  719. 9 ...
  720. 10 142.48 ms 190.152.253.154
  721. 11 ... 12
  722. 13 137.84 ms 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  723. #######################################################################################################################################
  724. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:09 EDT
  725. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  726. Host is up (0.14s latency).
  727.  
  728. PORT STATE SERVICE VERSION
  729. 68/udp open|filtered dhcpc
  730. Too many fingerprints match this host to give specific OS details
  731. Network Distance: 13 hops
  732.  
  733. TRACEROUTE (using proto 1/icmp)
  734. HOP RTT ADDRESS
  735. 1 961.47 ms 10.247.200.1
  736. 2 964.59 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  737. 3 969.26 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  738. 4 962.11 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  739. 5 965.02 ms motl-b1-link.telia.net (62.115.162.41)
  740. 6 ...
  741. 7 969.10 ms nyk-b6-link.telia.net (62.115.125.63)
  742. 8 969.23 ms corporacionnacional-ic-326985-nyk-b6.c.telia.net (213.248.91.41)
  743. 9 ...
  744. 10 1073.80 ms 190.152.253.154
  745. 11 ... 12
  746. 13 140.98 ms 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  747. #######################################################################################################################################
  748. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:11 EDT
  749. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  750. Host is up (0.14s latency).
  751.  
  752. PORT STATE SERVICE VERSION
  753. 69/udp open|filtered tftp
  754. Too many fingerprints match this host to give specific OS details
  755. Network Distance: 13 hops
  756.  
  757. TRACEROUTE (using proto 1/icmp)
  758. HOP RTT ADDRESS
  759. 1 27.33 ms 10.247.200.1
  760. 2 22.19 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  761. 3 43.33 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  762. 4 22.16 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  763. 5 22.19 ms motl-b1-link.telia.net (62.115.162.41)
  764. 6 ...
  765. 7 32.74 ms nyk-b6-link.telia.net (62.115.125.63)
  766. 8 34.35 ms corporacionnacional-ic-326985-nyk-b6.c.telia.net (213.248.91.41)
  767. 9 ...
  768. 10 139.84 ms 190.152.253.154
  769. 11 ... 12
  770. 13 138.62 ms 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  771. #######################################################################################################################################
  772. http://190.214.11.74 [301 Moved Permanently] Apache[2.4.6], Country[ECUADOR][EC], HTTPServer[CentOS][Apache/2.4.6 (CentOS) PHP/5.4.16], IP[190.214.11.74], PHP[5.4.16], RedirectLocation[http://www.inae.gob.ec/], X-Powered-By[PHP/5.4.16], X-UA-Compatible[IE=edge]
  773. http://www.inae.gob.ec/ [200 OK] Apache[2.4.6], Country[ECUADOR][EC], Email[[email protected]], Frame, HTML5, HTTPServer[CentOS][Apache/2.4.6 (CentOS) PHP/5.4.16], IP[190.214.11.74], JQuery[1.12.4], MetaGenerator[WordPress 4.7.3], Open-Graph-Protocol[website], PHP[5.4.16], PoweredBy[Shareaholic], Script[text/javascript], Title[Instituto Antártico Ecuatoriano &#8211; INAE], UncommonHeaders[link], WordPress[4.7,4.7.3], X-Powered-By[PHP/5.4.16], X-UA-Compatible[IE=10,IE=edge], YouTube
  774. #######################################################################################################################################
  775.  
  776. wig - WebApp Information Gatherer
  777.  
  778.  
  779. Scanning http://www.inae.gob.ec...
  780. ______________________________ SITE INFO _______________________________
  781. IP Title
  782. 190.214.11.74 Instituto Antártico Ecuatoriano &#8211; INAE
  783.  
  784. _______________________________ VERSION ________________________________
  785. Name Versions Type
  786. WordPress 4.7 CMS
  787. Apache 2.4.6 Platform
  788. PHP 5.4.16 Platform
  789. CentOS 7-1511 | 7.0-1406 | 7.1-1503 OS
  790.  
  791. _____________________________ INTERESTING ______________________________
  792. URL Note Type
  793. /readme.html Wordpress readme Interesting
  794. /readme.html Readme file Interesting
  795.  
  796. ________________________________ TOOLS _________________________________
  797. Name Link Software
  798. wpscan https://github.com/wpscanteam/wpscan WordPress
  799. CMSmap https://github.com/Dionach/CMSmap WordPress
  800.  
  801. ________________________________________________________________________
  802. Time: 3.3 sec Urls: 826 Fingerprints: 40401
  803. #######################################################################################################################################
  804. HTTP/1.1 301 Moved Permanently
  805. Date: Mon, 29 Apr 2019 14:14:02 GMT
  806. Server: Apache/2.4.6 (CentOS) PHP/5.4.16
  807. X-Powered-By: PHP/5.4.16
  808. X-UA-Compatible: IE=edge
  809. Location: http://www.inae.gob.ec/
  810. Content-Type: text/html; charset=UTF-8
  811.  
  812. HTTP/1.1 301 Moved Permanently
  813. Date: Mon, 29 Apr 2019 14:14:03 GMT
  814. Server: Apache/2.4.6 (CentOS) PHP/5.4.16
  815. X-Powered-By: PHP/5.4.16
  816. X-UA-Compatible: IE=edge
  817. Location: http://www.inae.gob.ec/
  818. Content-Type: text/html; charset=UTF-8
  819.  
  820. HTTP/1.1 200 OK
  821. Date: Mon, 29 Apr 2019 14:14:03 GMT
  822. Server: Apache/2.4.6 (CentOS) PHP/5.4.16
  823. X-Powered-By: PHP/5.4.16
  824. X-UA-Compatible: IE=edge
  825. Link: <http://www.inae.gob.ec/index.php/wp-json/>; rel="https://api.w.org/"
  826. Link: <https://wp.me/P7hq3p-6>; rel=shortlink
  827. Content-Type: text/html; charset=UTF-8
  828. #######################################################################################################################################
  829. jQuery Migrate
  830. Apache 2.4.6
  831. Twitter
  832. WordPress 4.7.3
  833. jQuery 1.12.4
  834. PHP 5.4.16
  835. YouTube
  836. CentOS
  837. WordPress
  838. X-UA-Compatible: IE=edge
  839. #######################################################################################################################################
  840. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:14 EDT
  841. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  842. Host is up (0.14s latency).
  843.  
  844. PORT STATE SERVICE VERSION
  845. 123/udp open|filtered ntp
  846. Too many fingerprints match this host to give specific OS details
  847. Network Distance: 13 hops
  848.  
  849. TRACEROUTE (using proto 1/icmp)
  850. HOP RTT ADDRESS
  851. 1 27.79 ms 10.247.200.1
  852. 2 51.58 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  853. 3 39.58 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  854. 4 27.87 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  855. 5 27.93 ms motl-b1-link.telia.net (62.115.162.41)
  856. 6 ...
  857. 7 38.19 ms nyk-b6-link.telia.net (62.115.125.63)
  858. 8 40.06 ms corporacionnacional-ic-326985-nyk-b6.c.telia.net (213.248.91.41)
  859. 9 ...
  860. 10 138.97 ms 190.152.253.154
  861. 11 ... 12
  862. 13 138.09 ms 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  863. #######################################################################################################################################
  864. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:16 EDT
  865. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  866. Host is up (0.14s latency).
  867.  
  868. PORT STATE SERVICE VERSION
  869. 161/tcp filtered snmp
  870. 161/udp open|filtered snmp
  871. Too many fingerprints match this host to give specific OS details
  872. Network Distance: 13 hops
  873.  
  874. TRACEROUTE (using proto 1/icmp)
  875. HOP RTT ADDRESS
  876. 1 21.32 ms 10.247.200.1
  877. 2 21.71 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  878. 3 32.65 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  879. 4 21.46 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  880. 5 21.49 ms motl-b1-link.telia.net (62.115.162.41)
  881. 6 ...
  882. 7 31.79 ms nyk-b6-link.telia.net (62.115.125.63)
  883. 8 33.59 ms corporacionnacional-ic-326985-nyk-b6.c.telia.net (213.248.91.41)
  884. 9 ...
  885. 10 139.11 ms 190.152.253.154
  886. 11 ... 12
  887. 13 139.92 ms 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  888. #######################################################################################################################################
  889. --------------------------------------------------------
  890. <<<Yasuo discovered following vulnerable applications>>>
  891. --------------------------------------------------------
  892. +------------+-------------------------------------+--------------------------------------------------+----------+----------+
  893. | App Name | URL to Application | Potential Exploit | Username | Password |
  894. +------------+-------------------------------------+--------------------------------------------------+----------+----------+
  895. | phpMyAdmin | http://190.214.11.74:80/phpmyadmin/ | ./exploits/multi/http/phpmyadmin_preg_replace.rb | | |
  896. +------------+-------------------------------------+--------------------------------------------------+----------+----------+
  897. #######################################################################################################################################
  898. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:19 EDT
  899. NSE: Loaded 148 scripts for scanning.
  900. NSE: Script Pre-scanning.
  901. NSE: Starting runlevel 1 (of 2) scan.
  902. Initiating NSE at 10:19
  903. Completed NSE at 10:19, 0.00s elapsed
  904. NSE: Starting runlevel 2 (of 2) scan.
  905. Initiating NSE at 10:19
  906. Completed NSE at 10:19, 0.00s elapsed
  907. Initiating Ping Scan at 10:19
  908. Scanning 190.214.11.74 [4 ports]
  909. Completed Ping Scan at 10:19, 0.17s elapsed (1 total hosts)
  910. Initiating Parallel DNS resolution of 1 host. at 10:19
  911. Completed Parallel DNS resolution of 1 host. at 10:19, 0.03s elapsed
  912. Initiating Connect Scan at 10:19
  913. Scanning 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74) [65535 ports]
  914. Discovered open port 80/tcp on 190.214.11.74
  915. Connect Scan Timing: About 7.34% done; ETC: 10:26 (0:06:32 remaining)
  916. Connect Scan Timing: About 34.38% done; ETC: 10:22 (0:01:56 remaining)
  917. Completed Connect Scan at 10:20, 104.46s elapsed (65535 total ports)
  918. Initiating Service scan at 10:20
  919. Scanning 1 service on 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  920. Completed Service scan at 10:21, 7.14s elapsed (1 service on 1 host)
  921. Initiating OS detection (try #1) against 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  922. Retrying OS detection (try #2) against 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  923. Initiating Traceroute at 10:21
  924. Completed Traceroute at 10:21, 3.04s elapsed
  925. Initiating Parallel DNS resolution of 10 hosts. at 10:21
  926. Completed Parallel DNS resolution of 10 hosts. at 10:21, 0.38s elapsed
  927. NSE: Script scanning 190.214.11.74.
  928. NSE: Starting runlevel 1 (of 2) scan.
  929. Initiating NSE at 10:21
  930. Completed NSE at 10:21, 14.26s elapsed
  931. NSE: Starting runlevel 2 (of 2) scan.
  932. Initiating NSE at 10:21
  933. Completed NSE at 10:21, 0.00s elapsed
  934. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  935. Host is up, received echo-reply ttl 52 (0.11s latency).
  936. Scanned at 2019-04-29 10:19:08 EDT for 135s
  937. Not shown: 65531 filtered ports
  938. Reason: 65531 no-responses
  939. PORT STATE SERVICE REASON VERSION
  940. 25/tcp closed smtp conn-refused
  941. 80/tcp open http syn-ack Apache httpd 2.4.6 ((CentOS) PHP/5.4.16)
  942. | http-methods:
  943. |_ Supported Methods: GET HEAD POST OPTIONS
  944. |_http-server-header: Apache/2.4.6 (CentOS) PHP/5.4.16
  945. |_http-title: Did not follow redirect to http://www.inae.gob.ec/
  946. 139/tcp closed netbios-ssn conn-refused
  947. 445/tcp closed microsoft-ds conn-refused
  948. OS fingerprint not ideal because: Didn't receive UDP response. Please try again with -sSU
  949. Aggressive OS guesses: Linux 3.10 - 4.11 (92%), HP P2000 G3 NAS device (91%), Linux 3.2 - 4.9 (91%), Linux 3.16 - 4.6 (90%), Linux 2.6.32 (90%), Linux 2.6.32 - 3.1 (90%), Ubiquiti AirMax NanoStation WAP (Linux 2.6.32) (90%), Linux 3.7 (90%), Ubiquiti AirOS 5.5.9 (90%), Linux 4.4 (90%)
  950. No exact OS matches for host (test conditions non-ideal).
  951. TCP/IP fingerprint:
  952. SCAN(V=7.70%E=4%D=4/29%OT=80%CT=25%CU=%PV=N%DS=13%DC=T%G=N%TM=5CC70863%P=x86_64-pc-linux-gnu)
  953. SEQ(SP=105%GCD=1%ISR=108%TI=Z%CI=Z%II=I%TS=A)
  954. OPS(O1=M44FST11NW7%O2=M44FST11NW7%O3=M44FNNT11NW7%O4=M44FST11NW7%O5=M44FST11NW7%O6=M44FST11)
  955. WIN(W1=7120%W2=7120%W3=7120%W4=7120%W5=7120%W6=7120)
  956. ECN(R=Y%DF=Y%TG=40%W=7210%O=M44FNNSNW7%CC=Y%Q=)
  957. T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
  958. T2(R=N)
  959. T3(R=N)
  960. T4(R=Y%DF=Y%TG=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
  961. T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
  962. T6(R=Y%DF=Y%TG=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
  963. T7(R=N)
  964. U1(R=N)
  965. IE(R=Y%DFI=N%TG=40%CD=S)
  966.  
  967. Uptime guess: 0.961 days (since Sun Apr 28 11:17:38 2019)
  968. Network Distance: 13 hops
  969. TCP Sequence Prediction: Difficulty=261 (Good luck!)
  970. IP ID Sequence Generation: All zeros
  971.  
  972. TRACEROUTE (using proto 1/icmp)
  973. HOP RTT ADDRESS
  974. 1 27.13 ms 10.247.200.1
  975. 2 27.38 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  976. 3 43.86 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  977. 4 27.37 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  978. 5 21.65 ms motl-b1-link.telia.net (62.115.162.41)
  979. 6 33.66 ms nyk-bb3-link.telia.net (62.115.137.142)
  980. 7 32.29 ms nyk-b6-link.telia.net (62.115.125.63)
  981. 8 33.73 ms corporacionnacional-ic-326985-nyk-b6.c.telia.net (213.248.91.41)
  982. 9 ...
  983. 10 139.54 ms 190.152.253.154
  984. 11 ... 12
  985. 13 138.26 ms 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  986.  
  987. NSE: Script Post-scanning.
  988. NSE: Starting runlevel 1 (of 2) scan.
  989. Initiating NSE at 10:21
  990. Completed NSE at 10:21, 0.00s elapsed
  991. NSE: Starting runlevel 2 (of 2) scan.
  992. Initiating NSE at 10:21
  993. Completed NSE at 10:21, 0.00s elapsed
  994. Read data files from: /usr/bin/../share/nmap
  995. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  996. Nmap done: 1 IP address (1 host up) scanned in 135.81 seconds
  997. Raw packets sent: 85 (6.736KB) | Rcvd: 111 (24.961KB)
  998. #######################################################################################################################################
  999. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-29 10:21 EDT
  1000. NSE: Loaded 148 scripts for scanning.
  1001. NSE: Script Pre-scanning.
  1002. Initiating NSE at 10:21
  1003. Completed NSE at 10:21, 0.00s elapsed
  1004. Initiating NSE at 10:21
  1005. Completed NSE at 10:21, 0.00s elapsed
  1006. Initiating Parallel DNS resolution of 1 host. at 10:21
  1007. Completed Parallel DNS resolution of 1 host. at 10:21, 0.03s elapsed
  1008. Initiating UDP Scan at 10:21
  1009. Scanning 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74) [14 ports]
  1010. Completed UDP Scan at 10:21, 1.26s elapsed (14 total ports)
  1011. Initiating Service scan at 10:21
  1012. Scanning 12 services on 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  1013. Service scan Timing: About 8.33% done; ETC: 10:41 (0:17:58 remaining)
  1014. Completed Service scan at 10:23, 102.59s elapsed (12 services on 1 host)
  1015. Initiating OS detection (try #1) against 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  1016. Retrying OS detection (try #2) against 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  1017. Initiating Traceroute at 10:23
  1018. Completed Traceroute at 10:23, 7.10s elapsed
  1019. Initiating Parallel DNS resolution of 1 host. at 10:23
  1020. Completed Parallel DNS resolution of 1 host. at 10:23, 0.01s elapsed
  1021. NSE: Script scanning 190.214.11.74.
  1022. Initiating NSE at 10:23
  1023. Completed NSE at 10:23, 20.36s elapsed
  1024. Initiating NSE at 10:23
  1025. Completed NSE at 10:23, 1.02s elapsed
  1026. Nmap scan report for 74.11.214.190.static.anycast.cnt-grms.ec (190.214.11.74)
  1027. Host is up (0.025s latency).
  1028.  
  1029. PORT STATE SERVICE VERSION
  1030. 53/udp open|filtered domain
  1031. 67/udp open|filtered dhcps
  1032. 68/udp open|filtered dhcpc
  1033. 69/udp open|filtered tftp
  1034. 88/udp open|filtered kerberos-sec
  1035. 123/udp open|filtered ntp
  1036. 137/udp filtered netbios-ns
  1037. 138/udp filtered netbios-dgm
  1038. 139/udp open|filtered netbios-ssn
  1039. 161/udp open|filtered snmp
  1040. 162/udp open|filtered snmptrap
  1041. 389/udp open|filtered ldap
  1042. 520/udp open|filtered route
  1043. 2049/udp open|filtered nfs
  1044. Too many fingerprints match this host to give specific OS details
  1045.  
  1046. TRACEROUTE (using port 137/udp)
  1047. HOP RTT ADDRESS
  1048. 1 ... 3
  1049. 4 20.02 ms 10.247.200.1
  1050. 5 26.21 ms 10.247.200.1
  1051. 6 26.20 ms 10.247.200.1
  1052. 7 26.19 ms 10.247.200.1
  1053. 8 26.18 ms 10.247.200.1
  1054. 9 26.19 ms 10.247.200.1
  1055. 10 26.19 ms 10.247.200.1
  1056. 11 ... 15
  1057. 16 21.91 ms 10.247.200.1
  1058. 17 ... 18
  1059. 19 19.85 ms 10.247.200.1
  1060. 20 20.82 ms 10.247.200.1
  1061. 21 21.12 ms 10.247.200.1
  1062. 22 ... 29
  1063. 30 19.91 ms 10.247.200.1
  1064.  
  1065. NSE: Script Post-scanning.
  1066. Initiating NSE at 10:23
  1067. Completed NSE at 10:23, 0.00s elapsed
  1068. Initiating NSE at 10:23
  1069. Completed NSE at 10:23, 0.00s elapsed
  1070. Read data files from: /usr/bin/../share/nmap
  1071. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  1072. Nmap done: 1 IP address (1 host up) scanned in 135.49 seconds
  1073. Raw packets sent: 147 (13.614KB) | Rcvd: 117 (21.802KB)
  1074. #######################################################################################################################################
  1075. [+] URL: http://www.inae.gob.ec/
  1076. [+] Started: Mon Apr 29 07:56:57 2019
  1077.  
  1078. Interesting Finding(s):
  1079.  
  1080. [+] http://www.inae.gob.ec/
  1081. | Interesting Entries:
  1082. | - X-Powered-By: PHP/5.4.16
  1083. | - X-UA-Compatible: IE=edge
  1084. | Found By: Headers (Passive Detection)
  1085. | Confidence: 100%
  1086.  
  1087. [+] http://www.inae.gob.ec/xmlrpc.php
  1088. | Found By: Link Tag (Passive Detection)
  1089. | Confidence: 100%
  1090. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  1091. | References:
  1092. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1093. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1094. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1095. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1096. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1097.  
  1098. [+] http://www.inae.gob.ec/readme.html
  1099. | Found By: Direct Access (Aggressive Detection)
  1100. | Confidence: 100%
  1101.  
  1102. [+] Registration is enabled: http://www.inae.gob.ec/wp-login.php?action=register
  1103. | Found By: Direct Access (Aggressive Detection)
  1104. | Confidence: 100%
  1105.  
  1106. [+] Upload directory has listing enabled: http://www.inae.gob.ec/wp-content/uploads/
  1107. | Found By: Direct Access (Aggressive Detection)
  1108. | Confidence: 100%
  1109.  
  1110. [+] http://www.inae.gob.ec/wp-cron.php
  1111. | Found By: Direct Access (Aggressive Detection)
  1112. | Confidence: 60%
  1113. | References:
  1114. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1115. | - https://github.com/wpscanteam/wpscan/issues/1299
  1116.  
  1117. [+] WordPress version 4.7.3 identified (Insecure, released on 2017-03-06).
  1118. | Detected By: Rss Generator (Passive Detection)
  1119. | - http://www.inae.gob.ec/index.php/feed/, <generator>https://wordpress.org/?v=4.7.3</generator>
  1120. | - http://www.inae.gob.ec/index.php/comments/feed/, <generator>https://wordpress.org/?v=4.7.3</generator>
  1121. |
  1122. | [!] 34 vulnerabilities identified:
  1123. |
  1124. | [!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
  1125. | References:
  1126. | - https://wpvulndb.com/vulnerabilities/8807
  1127. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
  1128. | - https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
  1129. | - http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
  1130. | - https://core.trac.wordpress.org/ticket/25239
  1131. |
  1132. | [!] Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
  1133. | Fixed in: 4.7.5
  1134. | References:
  1135. | - https://wpvulndb.com/vulnerabilities/8815
  1136. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
  1137. | - https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
  1138. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1139. |
  1140. | [!] Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
  1141. | Fixed in: 4.7.5
  1142. | References:
  1143. | - https://wpvulndb.com/vulnerabilities/8816
  1144. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
  1145. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1146. | - https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
  1147. |
  1148. | [!] Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
  1149. | Fixed in: 4.7.5
  1150. | References:
  1151. | - https://wpvulndb.com/vulnerabilities/8817
  1152. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
  1153. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1154. | - https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
  1155. |
  1156. | [!] Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
  1157. | Fixed in: 4.7.5
  1158. | References:
  1159. | - https://wpvulndb.com/vulnerabilities/8818
  1160. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
  1161. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1162. | - https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
  1163. | - https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
  1164. |
  1165. | [!] Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
  1166. | Fixed in: 4.7.5
  1167. | References:
  1168. | - https://wpvulndb.com/vulnerabilities/8819
  1169. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
  1170. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1171. | - https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
  1172. | - https://hackerone.com/reports/203515
  1173. | - https://hackerone.com/reports/203515
  1174. |
  1175. | [!] Title: WordPress 3.4.0-4.7.4 - Customizer XSS & CSRF
  1176. | Fixed in: 4.7.5
  1177. | References:
  1178. | - https://wpvulndb.com/vulnerabilities/8820
  1179. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
  1180. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1181. | - https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
  1182. |
  1183. | [!] Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
  1184. | Fixed in: 4.7.6
  1185. | References:
  1186. | - https://wpvulndb.com/vulnerabilities/8905
  1187. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1188. | - https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  1189. | - https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
  1190. |
  1191. | [!] Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
  1192. | Fixed in: 4.7.5
  1193. | References:
  1194. | - https://wpvulndb.com/vulnerabilities/8906
  1195. | - https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
  1196. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1197. | - https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  1198. | - https://wpvulndb.com/vulnerabilities/8905
  1199. |
  1200. | [!] Title: WordPress 2.9.2-4.8.1 - Open Redirect
  1201. | Fixed in: 4.7.6
  1202. | References:
  1203. | - https://wpvulndb.com/vulnerabilities/8910
  1204. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
  1205. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1206. | - https://core.trac.wordpress.org/changeset/41398
  1207. |
  1208. | [!] Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
  1209. | Fixed in: 4.7.6
  1210. | References:
  1211. | - https://wpvulndb.com/vulnerabilities/8911
  1212. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
  1213. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1214. | - https://core.trac.wordpress.org/changeset/41457
  1215. |
  1216. | [!] Title: WordPress 4.4-4.8.1 - Path Traversal in Customizer
  1217. | Fixed in: 4.7.6
  1218. | References:
  1219. | - https://wpvulndb.com/vulnerabilities/8912
  1220. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14722
  1221. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1222. | - https://core.trac.wordpress.org/changeset/41397
  1223. |
  1224. | [!] Title: WordPress 4.4-4.8.1 - Cross-Site Scripting (XSS) in oEmbed
  1225. | Fixed in: 4.7.6
  1226. | References:
  1227. | - https://wpvulndb.com/vulnerabilities/8913
  1228. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14724
  1229. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1230. | - https://core.trac.wordpress.org/changeset/41448
  1231. |
  1232. | [!] Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
  1233. | Fixed in: 4.7.6
  1234. | References:
  1235. | - https://wpvulndb.com/vulnerabilities/8914
  1236. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
  1237. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1238. | - https://core.trac.wordpress.org/changeset/41395
  1239. | - https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
  1240. |
  1241. | [!] Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
  1242. | Fixed in: 4.7.7
  1243. | References:
  1244. | - https://wpvulndb.com/vulnerabilities/8941
  1245. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
  1246. | - https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
  1247. | - https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
  1248. | - https://twitter.com/ircmaxell/status/923662170092638208
  1249. | - https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
  1250. |
  1251. | [!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
  1252. | Fixed in: 4.7.8
  1253. | References:
  1254. | - https://wpvulndb.com/vulnerabilities/8966
  1255. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
  1256. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1257. | - https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
  1258. |
  1259. | [!] Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
  1260. | Fixed in: 4.7.8
  1261. | References:
  1262. | - https://wpvulndb.com/vulnerabilities/8967
  1263. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
  1264. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1265. | - https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
  1266. |
  1267. | [!] Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
  1268. | Fixed in: 4.7.8
  1269. | References:
  1270. | - https://wpvulndb.com/vulnerabilities/8968
  1271. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
  1272. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1273. | - https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
  1274. |
  1275. | [!] Title: WordPress 3.7-4.9 - 'newbloguser' Key Weak Hashing
  1276. | Fixed in: 4.7.8
  1277. | References:
  1278. | - https://wpvulndb.com/vulnerabilities/8969
  1279. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
  1280. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1281. | - https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
  1282. |
  1283. | [!] Title: WordPress 3.7-4.9.1 - MediaElement Cross-Site Scripting (XSS)
  1284. | Fixed in: 4.7.9
  1285. | References:
  1286. | - https://wpvulndb.com/vulnerabilities/9006
  1287. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5776
  1288. | - https://github.com/WordPress/WordPress/commit/3fe9cb61ee71fcfadb5e002399296fcc1198d850
  1289. | - https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/
  1290. | - https://core.trac.wordpress.org/ticket/42720
  1291. |
  1292. | [!] Title: WordPress <= 4.9.4 - Application Denial of Service (DoS) (unpatched)
  1293. | References:
  1294. | - https://wpvulndb.com/vulnerabilities/9021
  1295. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6389
  1296. | - https://baraktawily.blogspot.fr/2018/02/how-to-dos-29-of-world-wide-websites.html
  1297. | - https://github.com/quitten/doser.py
  1298. | - https://thehackernews.com/2018/02/wordpress-dos-exploit.html
  1299. |
  1300. | [!] Title: WordPress 3.7-4.9.4 - Remove localhost Default
  1301. | Fixed in: 4.7.10
  1302. | References:
  1303. | - https://wpvulndb.com/vulnerabilities/9053
  1304. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10101
  1305. | - https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
  1306. | - https://github.com/WordPress/WordPress/commit/804363859602d4050d9a38a21f5a65d9aec18216
  1307. |
  1308. | [!] Title: WordPress 3.7-4.9.4 - Use Safe Redirect for Login
  1309. | Fixed in: 4.7.10
  1310. | References:
  1311. | - https://wpvulndb.com/vulnerabilities/9054
  1312. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10100
  1313. | - https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
  1314. | - https://github.com/WordPress/WordPress/commit/14bc2c0a6fde0da04b47130707e01df850eedc7e
  1315. |
  1316. | [!] Title: WordPress 3.7-4.9.4 - Escape Version in Generator Tag
  1317. | Fixed in: 4.7.10
  1318. | References:
  1319. | - https://wpvulndb.com/vulnerabilities/9055
  1320. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10102
  1321. | - https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
  1322. | - https://github.com/WordPress/WordPress/commit/31a4369366d6b8ce30045d4c838de2412c77850d
  1323. |
  1324. | [!] Title: WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion
  1325. | Fixed in: 4.7.11
  1326. | References:
  1327. | - https://wpvulndb.com/vulnerabilities/9100
  1328. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12895
  1329. | - https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
  1330. | - http://blog.vulnspy.com/2018/06/27/Wordpress-4-9-6-Arbitrary-File-Delection-Vulnerbility-Exploit/
  1331. | - https://github.com/WordPress/WordPress/commit/c9dce0606b0d7e6f494d4abe7b193ac046a322cd
  1332. | - https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance-release/
  1333. | - https://www.wordfence.com/blog/2018/07/details-of-an-additional-file-deletion-vulnerability-patched-in-wordpress-4-9-7/
  1334. |
  1335. | [!] Title: WordPress <= 5.0 - Authenticated File Delete
  1336. | Fixed in: 4.7.12
  1337. | References:
  1338. | - https://wpvulndb.com/vulnerabilities/9169
  1339. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20147
  1340. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1341. |
  1342. | [!] Title: WordPress <= 5.0 - Authenticated Post Type Bypass
  1343. | Fixed in: 4.7.12
  1344. | References:
  1345. | - https://wpvulndb.com/vulnerabilities/9170
  1346. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20152
  1347. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1348. | - https://blog.ripstech.com/2018/wordpress-post-type-privilege-escalation/
  1349. |
  1350. | [!] Title: WordPress <= 5.0 - PHP Object Injection via Meta Data
  1351. | Fixed in: 4.7.12
  1352. | References:
  1353. | - https://wpvulndb.com/vulnerabilities/9171
  1354. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20148
  1355. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1356. |
  1357. | [!] Title: WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS)
  1358. | Fixed in: 4.7.12
  1359. | References:
  1360. | - https://wpvulndb.com/vulnerabilities/9172
  1361. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20153
  1362. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1363. |
  1364. | [!] Title: WordPress <= 5.0 - Cross-Site Scripting (XSS) that could affect plugins
  1365. | Fixed in: 4.7.12
  1366. | References:
  1367. | - https://wpvulndb.com/vulnerabilities/9173
  1368. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20150
  1369. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1370. | - https://github.com/WordPress/WordPress/commit/fb3c6ea0618fcb9a51d4f2c1940e9efcd4a2d460
  1371. |
  1372. | [!] Title: WordPress <= 5.0 - User Activation Screen Search Engine Indexing
  1373. | Fixed in: 4.7.12
  1374. | References:
  1375. | - https://wpvulndb.com/vulnerabilities/9174
  1376. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20151
  1377. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1378. |
  1379. | [!] Title: WordPress <= 5.0 - File Upload to XSS on Apache Web Servers
  1380. | Fixed in: 4.7.12
  1381. | References:
  1382. | - https://wpvulndb.com/vulnerabilities/9175
  1383. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20149
  1384. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1385. | - https://github.com/WordPress/WordPress/commit/246a70bdbfac3bd45ff71c7941deef1bb206b19a
  1386. |
  1387. | [!] Title: WordPress 3.7-5.0 (except 4.9.9) - Authenticated Code Execution
  1388. | Fixed in: 5.0.1
  1389. | References:
  1390. | - https://wpvulndb.com/vulnerabilities/9222
  1391. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8942
  1392. | - https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/
  1393. |
  1394. | [!] Title: WordPress 3.9-5.1 - Comment Cross-Site Scripting (XSS)
  1395. | Fixed in: 4.7.13
  1396. | References:
  1397. | - https://wpvulndb.com/vulnerabilities/9230
  1398. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9787
  1399. | - https://github.com/WordPress/WordPress/commit/0292de60ec78c5a44956765189403654fe4d080b
  1400. | - https://wordpress.org/news/2019/03/wordpress-5-1-1-security-and-maintenance-release/
  1401. | - https://blog.ripstech.com/2019/wordpress-csrf-to-rce/
  1402.  
  1403. [+] WordPress theme in use: vantage
  1404. | Location: http://www.inae.gob.ec/wp-content/themes/vantage/
  1405. | Last Updated: 2019-04-22T00:00:00.000Z
  1406. | Readme: http://www.inae.gob.ec/wp-content/themes/vantage/readme.txt
  1407. | [!] The version is out of date, the latest version is 1.10.1
  1408. | Style URL: http://www.inae.gob.ec/wp-content/themes/vantage/style.css?ver=1.7.8
  1409. | Style Name: Vantage
  1410. | Style URI: https://siteorigin.com/theme/vantage/
  1411. | Description: Vantage is a flexible multipurpose theme. Its strength lies in its tight integration with some power...
  1412. | Author: SiteOrigin
  1413. | Author URI: https://siteorigin.com/
  1414. |
  1415. | Detected By: Css Style (Passive Detection)
  1416. |
  1417. | Version: 1.7.8 (80% confidence)
  1418. | Detected By: Style (Passive Detection)
  1419. | - http://www.inae.gob.ec/wp-content/themes/vantage/style.css?ver=1.7.8, Match: 'Version: 1.7.8'
  1420.  
  1421. [+] Enumerating All Plugins (via Passive Methods)
  1422. [+] Checking Plugin Versions (via Passive and Aggressive Methods)
  1423.  
  1424. [i] Plugin(s) Identified:
  1425.  
  1426. [+] accordions-wp
  1427. | Location: http://www.inae.gob.ec/wp-content/plugins/accordions-wp/
  1428. | Latest Version: 2.4 (up to date)
  1429. | Last Updated: 2018-08-13T12:06:00.000Z
  1430. |
  1431. | Detected By: Urls In Homepage (Passive Detection)
  1432. |
  1433. | Version: 2.4 (100% confidence)
  1434. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1435. | - http://www.inae.gob.ec/wp-content/plugins/accordions-wp/readme.txt
  1436. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  1437. | - http://www.inae.gob.ec/wp-content/plugins/accordions-wp/readme.txt
  1438.  
  1439. [+] advanced-wp-columns
  1440. | Location: http://www.inae.gob.ec/wp-content/plugins/advanced-wp-columns/
  1441. | Last Updated: 2015-12-28T03:37:00.000Z
  1442. | [!] The version is out of date, the latest version is 2.0.6
  1443. |
  1444. | Detected By: Urls In Homepage (Passive Detection)
  1445. |
  1446. | Version: 2.0 (80% confidence)
  1447. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1448. | - http://www.inae.gob.ec/wp-content/plugins/advanced-wp-columns/readme.txt
  1449.  
  1450. [+] arconix-shortcodes
  1451. | Location: http://www.inae.gob.ec/wp-content/plugins/arconix-shortcodes/
  1452. | Last Updated: 2018-12-14T06:30:00.000Z
  1453. | [!] The version is out of date, the latest version is 2.1.6
  1454. |
  1455. | Detected By: Urls In Homepage (Passive Detection)
  1456. |
  1457. | Version: 2.0.4 (100% confidence)
  1458. | Detected By: Query Parameter (Passive Detection)
  1459. | - http://www.inae.gob.ec/wp-content/plugins/arconix-shortcodes/includes/css/arconix-shortcodes.min.css?ver=2.0.4
  1460. | Confirmed By:
  1461. | Readme - Stable Tag (Aggressive Detection)
  1462. | - http://www.inae.gob.ec/wp-content/plugins/arconix-shortcodes/readme.txt
  1463. | Readme - ChangeLog Section (Aggressive Detection)
  1464. | - http://www.inae.gob.ec/wp-content/plugins/arconix-shortcodes/readme.txt
  1465.  
  1466. [+] fuse-social-floating-sidebar
  1467. | Location: http://www.inae.gob.ec/wp-content/plugins/fuse-social-floating-sidebar/
  1468. | Last Updated: 2019-03-09T11:43:00.000Z
  1469. | [!] The version is out of date, the latest version is 4.0
  1470. |
  1471. | Detected By: Urls In Homepage (Passive Detection)
  1472. |
  1473. | Version: 2.0 (80% confidence)
  1474. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1475. | - http://www.inae.gob.ec/wp-content/plugins/fuse-social-floating-sidebar/readme.txt
  1476.  
  1477. [+] imagemapper
  1478. | Location: http://www.inae.gob.ec/wp-content/plugins/imagemapper/
  1479. | Latest Version: 1.2.6 (up to date)
  1480. | Last Updated: 2016-04-20T09:52:00.000Z
  1481. |
  1482. | Detected By: Urls In Homepage (Passive Detection)
  1483. |
  1484. | Version: 1.2.6 (100% confidence)
  1485. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1486. | - http://www.inae.gob.ec/wp-content/plugins/imagemapper/readme.txt
  1487. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  1488. | - http://www.inae.gob.ec/wp-content/plugins/imagemapper/readme.txt
  1489.  
  1490. [+] jetpack
  1491. | Location: http://www.inae.gob.ec/wp-content/plugins/jetpack/
  1492. | Last Updated: 2019-04-04T21:00:00.000Z
  1493. | [!] The version is out of date, the latest version is 7.2.1
  1494. |
  1495. | Detected By: Urls In Homepage (Passive Detection)
  1496. |
  1497. | [!] 1 vulnerability identified:
  1498. |
  1499. | [!] Title: Jetpack <= 6.4.2 - Authenticated Stored Cross-Site Scripting (XSS)
  1500. | Fixed in: 6.5
  1501. | References:
  1502. | - https://wpvulndb.com/vulnerabilities/9168
  1503. | - https://www.ripstech.com/php-security-calendar-2018/#day-11
  1504. |
  1505. | Version: 6.3.3 (100% confidence)
  1506. | Detected By: Query Parameter (Passive Detection)
  1507. | - http://www.inae.gob.ec/wp-content/plugins/jetpack/css/jetpack.css?ver=6.3.3
  1508. | Confirmed By:
  1509. | Readme - Stable Tag (Aggressive Detection)
  1510. | - http://www.inae.gob.ec/wp-content/plugins/jetpack/readme.txt
  1511. | Readme - ChangeLog Section (Aggressive Detection)
  1512. | - http://www.inae.gob.ec/wp-content/plugins/jetpack/readme.txt
  1513.  
  1514. [+] jquery-mega-menu
  1515. | Location: http://www.inae.gob.ec/wp-content/plugins/jquery-mega-menu/
  1516. | Latest Version: 1.3.10 (up to date)
  1517. | Last Updated: 2012-11-02T16:20:00.000Z
  1518. |
  1519. | Detected By: Urls In Homepage (Passive Detection)
  1520. |
  1521. | [!] 1 vulnerability identified:
  1522. |
  1523. | [!] Title: jQuery Mega Menu 1.0 - Local File Inclusion
  1524. | References:
  1525. | - https://wpvulndb.com/vulnerabilities/6417
  1526. | - https://www.exploit-db.com/exploits/16250/
  1527. |
  1528. | Version: 1.3.10 (100% confidence)
  1529. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1530. | - http://www.inae.gob.ec/wp-content/plugins/jquery-mega-menu/readme.txt
  1531. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  1532. | - http://www.inae.gob.ec/wp-content/plugins/jquery-mega-menu/readme.txt
  1533.  
  1534. [+] ml-slider
  1535. | Location: http://www.inae.gob.ec/wp-content/plugins/ml-slider/
  1536. | Last Updated: 2019-03-25T15:15:00.000Z
  1537. | [!] The version is out of date, the latest version is 3.12.1
  1538. |
  1539. | Detected By: Urls In Homepage (Passive Detection)
  1540. |
  1541. | Version: 3.10.0 (80% confidence)
  1542. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1543. | - http://www.inae.gob.ec/wp-content/plugins/ml-slider/readme.txt
  1544.  
  1545. [+] shareaholic
  1546. | Location: http://www.inae.gob.ec/wp-content/plugins/shareaholic/
  1547. | Last Updated: 2019-04-18T22:46:00.000Z
  1548. | [!] The version is out of date, the latest version is 8.12.4
  1549. |
  1550. | Detected By: Meta Tag (Passive Detection)
  1551. |
  1552. | Version: 8.0.1 (100% confidence)
  1553. | Detected By: Meta Tag (Passive Detection)
  1554. | - http://www.inae.gob.ec/, Match: '8.0.1'
  1555. | Confirmed By:
  1556. | Readme - Stable Tag (Aggressive Detection)
  1557. | - http://www.inae.gob.ec/wp-content/plugins/shareaholic/readme.txt
  1558. | Readme - ChangeLog Section (Aggressive Detection)
  1559. | - http://www.inae.gob.ec/wp-content/plugins/shareaholic/readme.txt
  1560.  
  1561. [+] siteorigin-panels
  1562. | Location: http://www.inae.gob.ec/wp-content/plugins/siteorigin-panels/
  1563. | Last Updated: 2019-04-06T00:55:00.000Z
  1564. | [!] The version is out of date, the latest version is 2.10.5
  1565. |
  1566. | Detected By: Urls In Homepage (Passive Detection)
  1567. |
  1568. | Version: 2.7.2 (100% confidence)
  1569. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1570. | - http://www.inae.gob.ec/wp-content/plugins/siteorigin-panels/readme.txt
  1571. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  1572. | - http://www.inae.gob.ec/wp-content/plugins/siteorigin-panels/readme.txt
  1573.  
  1574. [+] so-widgets-bundle
  1575. | Location: http://www.inae.gob.ec/wp-content/plugins/so-widgets-bundle/
  1576. | Last Updated: 2019-03-27T20:27:00.000Z
  1577. | [!] The version is out of date, the latest version is 1.15.4
  1578. |
  1579. | Detected By: Urls In Homepage (Passive Detection)
  1580. |
  1581. | Version: 1.9.2 (80% confidence)
  1582. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1583. | - http://www.inae.gob.ec/wp-content/plugins/so-widgets-bundle/readme.txt
  1584.  
  1585. [+] wp-publication-archive
  1586. | Location: http://www.inae.gob.ec/wp-content/plugins/wp-publication-archive/
  1587. | Latest Version: 3.0.1 (up to date)
  1588. | Last Updated: 2013-07-25T18:04:00.000Z
  1589. |
  1590. | Detected By: Urls In Homepage (Passive Detection)
  1591. |
  1592. | Version: 3.0.1 (80% confidence)
  1593. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1594. | - http://www.inae.gob.ec/wp-content/plugins/wp-publication-archive/readme.txt
  1595.  
  1596. [+] Enumerating Config Backups (via Passive and Aggressive Methods)
  1597. Checking Config Backups - Time: 00:00:02 <=============> (21 / 21) 100.00% Time: 00:00:02
  1598.  
  1599. [i] No Config Backups Found.
  1600.  
  1601.  
  1602. [+] Finished: Mon Apr 29 07:57:20 2019
  1603. [+] Requests Done: 73
  1604. [+] Cached Requests: 5
  1605. [+] Data Sent: 14.342 KB
  1606. [+] Data Received: 525.88 KB
  1607. [+] Memory used: 170.77 MB
  1608. [+] Elapsed time: 00:00:22
  1609. #######################################################################################################################################
  1610. [+] URL: http://www.inae.gob.ec/
  1611. [+] Started: Mon Apr 29 07:56:59 2019
  1612.  
  1613. Interesting Finding(s):
  1614.  
  1615. [+] http://www.inae.gob.ec/
  1616. | Interesting Entries:
  1617. | - X-Powered-By: PHP/5.4.16
  1618. | - X-UA-Compatible: IE=edge
  1619. | Found By: Headers (Passive Detection)
  1620. | Confidence: 100%
  1621.  
  1622. [+] http://www.inae.gob.ec/xmlrpc.php
  1623. | Found By: Link Tag (Passive Detection)
  1624. | Confidence: 100%
  1625. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  1626. | References:
  1627. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1628. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1629. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1630. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1631. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1632.  
  1633. [+] http://www.inae.gob.ec/readme.html
  1634. | Found By: Direct Access (Aggressive Detection)
  1635. | Confidence: 100%
  1636.  
  1637. [+] Registration is enabled: http://www.inae.gob.ec/wp-login.php?action=register
  1638. | Found By: Direct Access (Aggressive Detection)
  1639. | Confidence: 100%
  1640.  
  1641. [+] Upload directory has listing enabled: http://www.inae.gob.ec/wp-content/uploads/
  1642. | Found By: Direct Access (Aggressive Detection)
  1643. | Confidence: 100%
  1644.  
  1645. [+] http://www.inae.gob.ec/wp-cron.php
  1646. | Found By: Direct Access (Aggressive Detection)
  1647. | Confidence: 60%
  1648. | References:
  1649. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1650. | - https://github.com/wpscanteam/wpscan/issues/1299
  1651.  
  1652. [+] WordPress version 4.7.3 identified (Insecure, released on 2017-03-06).
  1653. | Detected By: Rss Generator (Passive Detection)
  1654. | - http://www.inae.gob.ec/index.php/feed/, <generator>https://wordpress.org/?v=4.7.3</generator>
  1655. | - http://www.inae.gob.ec/index.php/comments/feed/, <generator>https://wordpress.org/?v=4.7.3</generator>
  1656. |
  1657. | [!] 34 vulnerabilities identified:
  1658. |
  1659. | [!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
  1660. | References:
  1661. | - https://wpvulndb.com/vulnerabilities/8807
  1662. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
  1663. | - https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
  1664. | - http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
  1665. | - https://core.trac.wordpress.org/ticket/25239
  1666. |
  1667. | [!] Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
  1668. | Fixed in: 4.7.5
  1669. | References:
  1670. | - https://wpvulndb.com/vulnerabilities/8815
  1671. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
  1672. | - https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
  1673. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1674. |
  1675. | [!] Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
  1676. | Fixed in: 4.7.5
  1677. | References:
  1678. | - https://wpvulndb.com/vulnerabilities/8816
  1679. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
  1680. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1681. | - https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
  1682. |
  1683. | [!] Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
  1684. | Fixed in: 4.7.5
  1685. | References:
  1686. | - https://wpvulndb.com/vulnerabilities/8817
  1687. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
  1688. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1689. | - https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
  1690. |
  1691. | [!] Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
  1692. | Fixed in: 4.7.5
  1693. | References:
  1694. | - https://wpvulndb.com/vulnerabilities/8818
  1695. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
  1696. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1697. | - https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
  1698. | - https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
  1699. |
  1700. | [!] Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
  1701. | Fixed in: 4.7.5
  1702. | References:
  1703. | - https://wpvulndb.com/vulnerabilities/8819
  1704. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
  1705. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1706. | - https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
  1707. | - https://hackerone.com/reports/203515
  1708. | - https://hackerone.com/reports/203515
  1709. |
  1710. | [!] Title: WordPress 3.4.0-4.7.4 - Customizer XSS & CSRF
  1711. | Fixed in: 4.7.5
  1712. | References:
  1713. | - https://wpvulndb.com/vulnerabilities/8820
  1714. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
  1715. | - https://wordpress.org/news/2017/05/wordpress-4-7-5/
  1716. | - https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
  1717. |
  1718. | [!] Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
  1719. | Fixed in: 4.7.6
  1720. | References:
  1721. | - https://wpvulndb.com/vulnerabilities/8905
  1722. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1723. | - https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  1724. | - https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
  1725. |
  1726. | [!] Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
  1727. | Fixed in: 4.7.5
  1728. | References:
  1729. | - https://wpvulndb.com/vulnerabilities/8906
  1730. | - https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
  1731. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1732. | - https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
  1733. | - https://wpvulndb.com/vulnerabilities/8905
  1734. |
  1735. | [!] Title: WordPress 2.9.2-4.8.1 - Open Redirect
  1736. | Fixed in: 4.7.6
  1737. | References:
  1738. | - https://wpvulndb.com/vulnerabilities/8910
  1739. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
  1740. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1741. | - https://core.trac.wordpress.org/changeset/41398
  1742. |
  1743. | [!] Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
  1744. | Fixed in: 4.7.6
  1745. | References:
  1746. | - https://wpvulndb.com/vulnerabilities/8911
  1747. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
  1748. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1749. | - https://core.trac.wordpress.org/changeset/41457
  1750. |
  1751. | [!] Title: WordPress 4.4-4.8.1 - Path Traversal in Customizer
  1752. | Fixed in: 4.7.6
  1753. | References:
  1754. | - https://wpvulndb.com/vulnerabilities/8912
  1755. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14722
  1756. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1757. | - https://core.trac.wordpress.org/changeset/41397
  1758. |
  1759. | [!] Title: WordPress 4.4-4.8.1 - Cross-Site Scripting (XSS) in oEmbed
  1760. | Fixed in: 4.7.6
  1761. | References:
  1762. | - https://wpvulndb.com/vulnerabilities/8913
  1763. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14724
  1764. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1765. | - https://core.trac.wordpress.org/changeset/41448
  1766. |
  1767. | [!] Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
  1768. | Fixed in: 4.7.6
  1769. | References:
  1770. | - https://wpvulndb.com/vulnerabilities/8914
  1771. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
  1772. | - https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
  1773. | - https://core.trac.wordpress.org/changeset/41395
  1774. | - https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
  1775. |
  1776. | [!] Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
  1777. | Fixed in: 4.7.7
  1778. | References:
  1779. | - https://wpvulndb.com/vulnerabilities/8941
  1780. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
  1781. | - https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
  1782. | - https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
  1783. | - https://twitter.com/ircmaxell/status/923662170092638208
  1784. | - https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
  1785. |
  1786. | [!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
  1787. | Fixed in: 4.7.8
  1788. | References:
  1789. | - https://wpvulndb.com/vulnerabilities/8966
  1790. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
  1791. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1792. | - https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
  1793. |
  1794. | [!] Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
  1795. | Fixed in: 4.7.8
  1796. | References:
  1797. | - https://wpvulndb.com/vulnerabilities/8967
  1798. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
  1799. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1800. | - https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
  1801. |
  1802. | [!] Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
  1803. | Fixed in: 4.7.8
  1804. | References:
  1805. | - https://wpvulndb.com/vulnerabilities/8968
  1806. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
  1807. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1808. | - https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
  1809. |
  1810. | [!] Title: WordPress 3.7-4.9 - 'newbloguser' Key Weak Hashing
  1811. | Fixed in: 4.7.8
  1812. | References:
  1813. | - https://wpvulndb.com/vulnerabilities/8969
  1814. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
  1815. | - https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
  1816. | - https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
  1817. |
  1818. | [!] Title: WordPress 3.7-4.9.1 - MediaElement Cross-Site Scripting (XSS)
  1819. | Fixed in: 4.7.9
  1820. | References:
  1821. | - https://wpvulndb.com/vulnerabilities/9006
  1822. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5776
  1823. | - https://github.com/WordPress/WordPress/commit/3fe9cb61ee71fcfadb5e002399296fcc1198d850
  1824. | - https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/
  1825. | - https://core.trac.wordpress.org/ticket/42720
  1826. |
  1827. | [!] Title: WordPress <= 4.9.4 - Application Denial of Service (DoS) (unpatched)
  1828. | References:
  1829. | - https://wpvulndb.com/vulnerabilities/9021
  1830. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6389
  1831. | - https://baraktawily.blogspot.fr/2018/02/how-to-dos-29-of-world-wide-websites.html
  1832. | - https://github.com/quitten/doser.py
  1833. | - https://thehackernews.com/2018/02/wordpress-dos-exploit.html
  1834. |
  1835. | [!] Title: WordPress 3.7-4.9.4 - Remove localhost Default
  1836. | Fixed in: 4.7.10
  1837. | References:
  1838. | - https://wpvulndb.com/vulnerabilities/9053
  1839. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10101
  1840. | - https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
  1841. | - https://github.com/WordPress/WordPress/commit/804363859602d4050d9a38a21f5a65d9aec18216
  1842. |
  1843. | [!] Title: WordPress 3.7-4.9.4 - Use Safe Redirect for Login
  1844. | Fixed in: 4.7.10
  1845. | References:
  1846. | - https://wpvulndb.com/vulnerabilities/9054
  1847. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10100
  1848. | - https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
  1849. | - https://github.com/WordPress/WordPress/commit/14bc2c0a6fde0da04b47130707e01df850eedc7e
  1850. |
  1851. | [!] Title: WordPress 3.7-4.9.4 - Escape Version in Generator Tag
  1852. | Fixed in: 4.7.10
  1853. | References:
  1854. | - https://wpvulndb.com/vulnerabilities/9055
  1855. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10102
  1856. | - https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release/
  1857. | - https://github.com/WordPress/WordPress/commit/31a4369366d6b8ce30045d4c838de2412c77850d
  1858. |
  1859. | [!] Title: WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion
  1860. | Fixed in: 4.7.11
  1861. | References:
  1862. | - https://wpvulndb.com/vulnerabilities/9100
  1863. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12895
  1864. | - https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
  1865. | - http://blog.vulnspy.com/2018/06/27/Wordpress-4-9-6-Arbitrary-File-Delection-Vulnerbility-Exploit/
  1866. | - https://github.com/WordPress/WordPress/commit/c9dce0606b0d7e6f494d4abe7b193ac046a322cd
  1867. | - https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance-release/
  1868. | - https://www.wordfence.com/blog/2018/07/details-of-an-additional-file-deletion-vulnerability-patched-in-wordpress-4-9-7/
  1869. |
  1870. | [!] Title: WordPress <= 5.0 - Authenticated File Delete
  1871. | Fixed in: 4.7.12
  1872. | References:
  1873. | - https://wpvulndb.com/vulnerabilities/9169
  1874. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20147
  1875. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1876. |
  1877. | [!] Title: WordPress <= 5.0 - Authenticated Post Type Bypass
  1878. | Fixed in: 4.7.12
  1879. | References:
  1880. | - https://wpvulndb.com/vulnerabilities/9170
  1881. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20152
  1882. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1883. | - https://blog.ripstech.com/2018/wordpress-post-type-privilege-escalation/
  1884. |
  1885. | [!] Title: WordPress <= 5.0 - PHP Object Injection via Meta Data
  1886. | Fixed in: 4.7.12
  1887. | References:
  1888. | - https://wpvulndb.com/vulnerabilities/9171
  1889. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20148
  1890. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1891. |
  1892. | [!] Title: WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS)
  1893. | Fixed in: 4.7.12
  1894. | References:
  1895. | - https://wpvulndb.com/vulnerabilities/9172
  1896. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20153
  1897. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1898. |
  1899. | [!] Title: WordPress <= 5.0 - Cross-Site Scripting (XSS) that could affect plugins
  1900. | Fixed in: 4.7.12
  1901. | References:
  1902. | - https://wpvulndb.com/vulnerabilities/9173
  1903. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20150
  1904. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1905. | - https://github.com/WordPress/WordPress/commit/fb3c6ea0618fcb9a51d4f2c1940e9efcd4a2d460
  1906. |
  1907. | [!] Title: WordPress <= 5.0 - User Activation Screen Search Engine Indexing
  1908. | Fixed in: 4.7.12
  1909. | References:
  1910. | - https://wpvulndb.com/vulnerabilities/9174
  1911. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20151
  1912. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1913. |
  1914. | [!] Title: WordPress <= 5.0 - File Upload to XSS on Apache Web Servers
  1915. | Fixed in: 4.7.12
  1916. | References:
  1917. | - https://wpvulndb.com/vulnerabilities/9175
  1918. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20149
  1919. | - https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
  1920. | - https://github.com/WordPress/WordPress/commit/246a70bdbfac3bd45ff71c7941deef1bb206b19a
  1921. |
  1922. | [!] Title: WordPress 3.7-5.0 (except 4.9.9) - Authenticated Code Execution
  1923. | Fixed in: 5.0.1
  1924. | References:
  1925. | - https://wpvulndb.com/vulnerabilities/9222
  1926. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8942
  1927. | - https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/
  1928. |
  1929. | [!] Title: WordPress 3.9-5.1 - Comment Cross-Site Scripting (XSS)
  1930. | Fixed in: 4.7.13
  1931. | References:
  1932. | - https://wpvulndb.com/vulnerabilities/9230
  1933. | - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9787
  1934. | - https://github.com/WordPress/WordPress/commit/0292de60ec78c5a44956765189403654fe4d080b
  1935. | - https://wordpress.org/news/2019/03/wordpress-5-1-1-security-and-maintenance-release/
  1936. | - https://blog.ripstech.com/2019/wordpress-csrf-to-rce/
  1937.  
  1938. [+] WordPress theme in use: vantage
  1939. | Location: http://www.inae.gob.ec/wp-content/themes/vantage/
  1940. | Last Updated: 2019-04-22T00:00:00.000Z
  1941. | Readme: http://www.inae.gob.ec/wp-content/themes/vantage/readme.txt
  1942. | [!] The version is out of date, the latest version is 1.10.1
  1943. | Style URL: http://www.inae.gob.ec/wp-content/themes/vantage/style.css?ver=1.7.8
  1944. | Style Name: Vantage
  1945. | Style URI: https://siteorigin.com/theme/vantage/
  1946. | Description: Vantage is a flexible multipurpose theme. Its strength lies in its tight integration with some power...
  1947. | Author: SiteOrigin
  1948. | Author URI: https://siteorigin.com/
  1949. |
  1950. | Detected By: Css Style (Passive Detection)
  1951. |
  1952. | Version: 1.7.8 (80% confidence)
  1953. | Detected By: Style (Passive Detection)
  1954. | - http://www.inae.gob.ec/wp-content/themes/vantage/style.css?ver=1.7.8, Match: 'Version: 1.7.8'
  1955.  
  1956. [+] Enumerating Users (via Passive and Aggressive Methods)
  1957. Brute Forcing Author IDs - Time: 00:00:12 <==> (10 / 10) 100.00% Time: 00:00:12
  1958.  
  1959. [i] User(s) Identified:
  1960.  
  1961. [+] inae_web2
  1962. | Detected By: Rss Generator (Passive Detection)
  1963. | Confirmed By:
  1964. | Wp Json Api (Aggressive Detection)
  1965. | - http://www.inae.gob.ec/index.php/wp-json/wp/v2/users/?per_page=100&page=1
  1966. | Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1967.  
  1968. [+] inae_web
  1969. | Detected By: Wp Json Api (Aggressive Detection)
  1970. | - http://www.inae.gob.ec/index.php/wp-json/wp/v2/users/?per_page=100&page=1
  1971. | Confirmed By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1972.  
  1973. [+] administrador
  1974. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1975.  
  1976. [+] alejandro3438
  1977. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1978.  
  1979. [+] roughmountpaddzuara
  1980. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1981.  
  1982. [+] stephany9922
  1983. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1984.  
  1985. [+] tahliaoram8
  1986. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1987.  
  1988. [+] robertomarconi6
  1989. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1990.  
  1991. [+] moselemmone96
  1992. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1993.  
  1994. [+] lanbraley6
  1995. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1996.  
  1997.  
  1998. [+] Finished: Mon Apr 29 07:57:40 2019
  1999. [+] Requests Done: 54
  2000. [+] Cached Requests: 17
  2001. [+] Data Sent: 11.645 KB
  2002. [+] Data Received: 936.63 KB
  2003. [+] Memory used: 112.148 MB
  2004. [+] Elapsed time: 00:00:41
  2005. #######################################################################################################################################
  2006. [-] Date & Time: 29/04/2019 07:56:54
  2007. [I] Threads: 5
  2008. [-] Target: http://www.inae.gob.ec (190.214.11.74)
  2009. [M] Website Not in HTTPS: http://www.inae.gob.ec
  2010. [I] X-Powered-By: PHP/5.4.16
  2011. [L] X-Frame-Options: Not Enforced
  2012. [I] Strict-Transport-Security: Not Enforced
  2013. [I] X-Content-Security-Policy: Not Enforced
  2014. [I] X-Content-Type-Options: Not Enforced
  2015. [L] No Robots.txt Found
  2016. [I] CMS Detection: WordPress
  2017. [I] Wordpress Version: 4.7
  2018. [M] EDB-ID: 46511 "WordPress Core 5.0 - Remote Code Execution"
  2019. [M] EDB-ID: 46662 "WordPress 5.0.0 - Crop-image Shell Upload (Metasploit)"
  2020. [M] EDB-ID: 44949 "WordPress Core < 4.9.6 - (Authenticated) Arbitrary File Deletion"
  2021. [M] EDB-ID: 41963 "WordPress < 4.7.4 - Unauthorized Password Reset"
  2022. [M] EDB-ID: 41497 "WordPress < 4.7.1 - Username Enumeration"
  2023. [M] EDB-ID: 41223 "WordPress 4.7.0/4.7.1 - Content Injection (Python)"
  2024. [M] EDB-ID: 41224 "WordPress 4.7.0/4.7.1 - Content Injection (Ruby)"
  2025. [I] Wordpress Theme: vantage
  2026. [M] EDB-ID: 8820 "amember 3.1.7 - Cross-Site Scripting / SQL Injection / HTML Injection"
  2027. [-] WordPress usernames identified:
  2028. [M] administrador
  2029. [M] alejandro3438
  2030. [M] archiedalyell4
  2031. [M] augustbeaman3
  2032. [M] bynfrancesca
  2033. [M] claytonmackellar
  2034. [M] conniea4166
  2035. [M] dalearmijo5
  2036. [M] deandregandy
  2037. [M] denesemann962
  2038. [M] derrickrae
  2039. [M] doloreshays9
  2040. [M] elbertforan39
  2041. [M] gwendolynwarburt
  2042. [M] haydenrickett0
  2043. [M] heath876729327
  2044. [M] henryi735389
  2045. [M] inae_web
  2046. [M] inae_web2
  2047. [M] irvinbrooks
  2048. [M] isabellamackey5
  2049. [M] jamikajemison
  2050. [M] juniors6224
  2051. [M] katricevasey789
  2052. [M] lakeisha89x
  2053. [M] lanbraley6
  2054. [M] lavondac58
  2055. [M] lawerenceboudrea
  2056. [M] ldtlynne656
  2057. [M] maddisongoshorn
  2058. [M] margaretteholtzm
  2059. [M] maydrummond535
  2060. [M] michelinecheyne
  2061. [M] mohammadnorthern
  2062. [M] moselemmone96
  2063. [M] nadinemoultrie
  2064. [M] nicholasstobie
  2065. [M] noe88t3433
  2066. [M] philip0620
  2067. [M] rachelnorris8
  2068. [M] remonakenney24
  2069. [M] rheamincey7434
  2070. [M] rickeydrayton24
  2071. [M] robertomarconi6
  2072. [M] roughmountpaddzuara
  2073. [M] stephany9922
  2074. [M] stormylaws5023
  2075. [M] tahliaoram8
  2076. [M] tonjahirschfeld
  2077. [M] XML-RPC services are enabled
  2078. [M] Website vulnerable to XML-RPC Brute Force Vulnerability
  2079. [I] Autocomplete Off Not Found: http://www.inae.gob.ec/wp-login.php
  2080. [-] Default WordPress Files:
  2081. [I] http://www.inae.gob.ec/license.txt
  2082. [I] http://www.inae.gob.ec/readme.html
  2083. [I] http://www.inae.gob.ec/wp-content/themes/twentyfifteen/genericons/COPYING.txt
  2084. [I] http://www.inae.gob.ec/wp-content/themes/twentyfifteen/genericons/LICENSE.txt
  2085. [I] http://www.inae.gob.ec/wp-content/themes/twentyfifteen/readme.txt
  2086. [I] http://www.inae.gob.ec/wp-content/themes/twentyseventeen/README.txt
  2087. [I] http://www.inae.gob.ec/wp-content/themes/twentysixteen/genericons/COPYING.txt
  2088. [I] http://www.inae.gob.ec/wp-content/themes/twentysixteen/genericons/LICENSE.txt
  2089. [I] http://www.inae.gob.ec/wp-content/themes/twentysixteen/readme.txt
  2090. [I] http://www.inae.gob.ec/wp-includes/ID3/license.commercial.txt
  2091. [I] http://www.inae.gob.ec/wp-includes/ID3/license.txt
  2092. [I] http://www.inae.gob.ec/wp-includes/ID3/readme.txt
  2093. [I] http://www.inae.gob.ec/wp-includes/images/crystal/license.txt
  2094. [I] http://www.inae.gob.ec/wp-includes/js/plupload/license.txt
  2095. [I] http://www.inae.gob.ec/wp-includes/js/swfupload/license.txt
  2096. [I] http://www.inae.gob.ec/wp-includes/js/tinymce/license.txt
  2097. [-] Searching Wordpress Plugins ...
  2098. [I] accordions-wp v2.4
  2099. [I] adrotate
  2100. [M] EDB-ID: 17888 "WordPress Plugin AdRotate 3.6.5 - SQL Injection"
  2101. [M] EDB-ID: 18114 "WordPress Plugin AdRotate 3.6.6 - SQL Injection"
  2102. [M] EDB-ID: 31834 "WordPress Plugin AdRotate 3.9.4 - 'clicktracker.ph?track' SQL Injection"
  2103. [I] ads-box
  2104. [M] EDB-ID: 38060 "WordPress Plugin Ads Box - 'count' SQL Injection"
  2105. [I] advanced-wp-columns
  2106. [I] akismet v4.0.8
  2107. [M] EDB-ID: 37826 "WordPress 3.4.2 - Multiple Path Disclosure Vulnerabilities"
  2108. [M] EDB-ID: 37902 "WordPress Plugin Akismet - Multiple Cross-Site Scripting Vulnerabilities"
  2109. [I] arconix-shortcodes v2.0.4
  2110. [I] firestats
  2111. [M] EDB-ID: 14308 "WordPress Plugin Firestats - Remote Configuration File Download"
  2112. [M] EDB-ID: 33367 "WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabilities (1)"
  2113. [M] EDB-ID: 33368 "WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabilities (2)"
  2114. [I] fuse-social-floating-sidebar v2.0
  2115. [I] imagemapper v1.2.6
  2116. [I] jetpack v6.3.3
  2117. [M] EDB-ID: 18126 "WordPress Plugin jetpack - 'sharedaddy.php' ID SQL Injection"
  2118. [I] jquery-mega-menu v1.3.10
  2119. [M] EDB-ID: 16250 "WordPress Plugin jQuery Mega Menu 1.0 - Local File Inclusion"
  2120. [I] ml-slider v3.10.0
  2121. [I] simple-ads-manager
  2122. [M] EDB-ID: 36613 "WordPress Plugin Simple Ads Manager - Multiple SQL Injections"
  2123. [M] EDB-ID: 36614 "WordPress Plugin Simple Ads Manager 2.5.94 - Arbitrary File Upload"
  2124. [M] EDB-ID: 36615 "WordPress Plugin Simple Ads Manager - Information Disclosure"
  2125. [M] EDB-ID: 39133 "WordPress Plugin Simple Ads Manager 2.9.4.116 - SQL Injection"
  2126. [I] siteorigin-panels v2.7.2
  2127. [I] so-widgets-bundle v1.9.2
  2128. [I] wp-bannerize
  2129. [M] EDB-ID: 17764 "WordPress Plugin Bannerize 2.8.6 - SQL Injection"
  2130. [M] EDB-ID: 17906 "WordPress Plugin Bannerize 2.8.7 - SQL Injection"
  2131. [M] EDB-ID: 36193 "WordPress Plugin WP Bannerize 2.8.7 - 'ajax_sorter.php' SQL Injection"
  2132. [I] wp-publication-archive v3.0.1
  2133. [M] EDB-ID: 35263 "WordPress Plugin WP Publication Archive 2.0.1 - 'file' Information Disclosure"
  2134. [I] Checking for Directory Listing Enabled ...
  2135. [L] http://www.inae.gob.ec/wp-admin/css
  2136. [L] http://www.inae.gob.ec/wp-admin/images
  2137. [L] http://www.inae.gob.ec/wp-admin/includes
  2138. [L] http://www.inae.gob.ec/wp-admin/js
  2139. [L] http://www.inae.gob.ec/wp-admin/maint
  2140. [L] http://www.inae.gob.ec/wp-includes
  2141. [L] http://www.inae.gob.ec/wp-includes/ID3
  2142. [L] http://www.inae.gob.ec/wp-includes/IXR
  2143. [L] http://www.inae.gob.ec/wp-includes/Requests
  2144. [L] http://www.inae.gob.ec/wp-includes/SimplePie
  2145. [L] http://www.inae.gob.ec/wp-includes/Text
  2146. [L] http://www.inae.gob.ec/wp-includes/certificates
  2147. [L] http://www.inae.gob.ec/wp-includes/css
  2148. [L] http://www.inae.gob.ec/wp-includes/customize
  2149. [L] http://www.inae.gob.ec/wp-includes/fonts
  2150. [L] http://www.inae.gob.ec/wp-includes/images
  2151. [L] http://www.inae.gob.ec/wp-includes/js
  2152. [L] http://www.inae.gob.ec/wp-includes/pomo
  2153. [L] http://www.inae.gob.ec/wp-includes/random_compat
  2154. [L] http://www.inae.gob.ec/wp-includes/rest-api
  2155. [L] http://www.inae.gob.ec/wp-includes/theme-compat
  2156. [L] http://www.inae.gob.ec/wp-includes/widgets
  2157. [L] http://www.inae.gob.ec/wp-content/plugins/accordions-wp
  2158. [L] http://www.inae.gob.ec/wp-content/plugins/advanced-wp-columns
  2159. [L] http://www.inae.gob.ec/wp-content/plugins/arconix-shortcodes
  2160. [L] http://www.inae.gob.ec/wp-content/plugins/fuse-social-floating-sidebar
  2161. [L] http://www.inae.gob.ec/wp-content/plugins/imagemapper
  2162. [L] http://www.inae.gob.ec/wp-content/plugins/jetpack
  2163. [L] http://www.inae.gob.ec/wp-content/plugins/jquery-mega-menu
  2164. [L] http://www.inae.gob.ec/wp-content/plugins/ml-slider
  2165. [L] http://www.inae.gob.ec/wp-content/plugins/siteorigin-panels
  2166. [L] http://www.inae.gob.ec/wp-content/plugins/so-widgets-bundle
  2167. [L] http://www.inae.gob.ec/wp-content/plugins/wp-publication-archive
  2168. [-] Date & Time: 29/04/2019 08:21:22
  2169. [-] Completed in: 0:24:27
  2170. #######################################################################################################################################
  2171. Anonymous JTSEC #OpAssange Full Recon #19
Advertisement
Add Comment
Please, Sign In to add comment