Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- UNITED NATIONS (UN) - Lotus Domino Web-Mail Server Data Leaked
- The United Nations (UN) is an international organization whose stated aims are facilitating cooperation in international law, international security, economic development, social progress, human rights, and achievement of world peace. The UN was founded in 1945 after World War II to replace the League of Nations, to stop wars between countries, and to provide a platform for dialogue. It contains multiple subsidiary organizations to carry out its missions.
- http://www.un.org
- THIS ATTACK AGAINST THE DIRTIEST THINGS AGAINST THE SRI LANKA BY UN .........!!!!!
- EXCLUSIVE FROM - Anonymous Sri Lanka
- WWW.UN.ORG -----> Fuck3D and Bust3D
- Primary webmaildr.un.org (157.150.34.43) Server Hacked and
- with Transferring (Data Leak)....!!
- Hail to Anonymous, Lulzsec and Operation Anti-Sec...
- 21/tcp closed ftp reset
- 22/tcp closed ssh reset
- 23/tcp filtered telnet no-response
- 25/tcp closed smtp reset
- 80/tcp open http? syn-ack
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- | http-malware-host:
- |_ ERROR: Unknown pages return a 302 response; unable to check
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- | http-title: Site doesn't have a title (text/html).
- |_Did not follow redirect to https://webmail.un.org/
- |_http-methods: No Allow or Public header in OPTIONS response (status code 307)
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-headers: ERROR: Header request didn't return a proper header
- |_http-userdir-enum: Didn't find any users!
- |_http-wordpress-plugins: nothing found amongst the 100 most popular plugins, use --script-arg http-wordpress-plugins.search=<number|all> for deeper analysis)
- | http-vhosts:
- |_405 names had status 302
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 110/tcp closed pop3 reset
- 139/tcp filtered netbios-ssn no-response
- 443/tcp open ssl/http syn-ack Lotus Domino httpd
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | ssl-cert: Subject: commonName=*.un.org/organizationName=United Nations/stateOrProvinceName=New York/countryName=US/streetAddress=24-01 44th Road, 9th Floor/localityName=Long Island City/postalCode=11101-4605/organizationalUnitName=Comodo PremiumSSL Wildcard
- | Issuer: commonName=UTN-USERFirst-Hardware/organizationName=The USERTRUST Network/stateOrProvinceName=UT/countryName=US/localityName=Salt Lake City/organizationalUnitName=http://www.usertrust.com
- | Public Key type: rsa
- | Public Key bits: 2048
- | Not valid before: 2011-02-02 00:00:00
- | Not valid after: 2013-04-13 23:59:59
- | MD5: 7920 a56a 7a80 873f 2303 98fd 5711 4c72
- | SHA-1: 3829 64d1 30e8 d182 52e7 65b8 5c41 5de1 0470 a249
- | -----BEGIN CERTIFICATE-----
- | MIIGBzCCBO+gAwIBAgIQGSM5lIzygwVgvQZH7nphlDANBgkqhkiG9w0BAQUFADCB
- | lzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
- | Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExho
- | dHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xHzAdBgNVBAMTFlVUTi1VU0VSRmlyc3Qt
- | SGFyZHdhcmUwHhcNMTEwMjAyMDAwMDAwWhcNMTMwNDEzMjM1OTU5WjCCAQsxCzAJ
- | BgNVBAYTAlVTMRMwEQYDVQQREwoxMTEwMS00NjA1MREwDwYDVQQIEwhOZXcgWW9y
- | azEZMBcGA1UEBxMQTG9uZyBJc2xhbmQgQ2l0eTEjMCEGA1UECRMaMjQtMDEgNDR0
- | aCBSb2FkLCA5dGggRmxvb3IxFzAVBgNVBAoTDlVuaXRlZCBOYXRpb25zMQ0wCwYD
- | VQQLEwRPSUNUMTQwMgYDVQQLEytJc3N1ZWQgdGhyb3VnaCBVbml0ZWQgTmF0aW9u
- | cyBFLVBLSSBNYW5hZ2VyMSMwIQYDVQQLExpDb21vZG8gUHJlbWl1bVNTTCBXaWxk
- | Y2FyZDERMA8GA1UEAxQIKi51bi5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
- | ggEKAoIBAQCs1eE0bZ1LBeAYBybTC5K4D7p7jpOvfMqH8uWU5XUz5mD2t8ZuZ/gk
- | AL3Te23ev32e8bKPkSYym9VgLNZ5CQbh+DG4y6lQNY0kaokMRSYGMhQG8mdUEkcg
- | u4lvd3V1VZ6HeppcO7ufgn3RbpTSLcgKRlm9UABQmYxZ0nmwW6z9IeGgKPoHn+18
- | G8HgFuMx4N0+vAbPvuhrurzb3OfWFsj2qE0R3PHtbZ/4lUCB54SG7LtNfsDeqzhp
- | rlHoD6OB25V1/t5Mt4K38PRa1i52G6J+KcuexxslfS3Kv67eNFik6t3lR3MPDSGw
- | Vtw1ATyTNW5aHrkq84AbZAKzMi9O7HzxAgMBAAGjggHWMIIB0jAfBgNVHSMEGDAW
- | gBShcl8mGyiYQ5VdBzfVhZadS9LDRTAdBgNVHQ4EFgQUHdeek2FzeALWh9EDbE8s
- | xfGb4uQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYI
- | KwYBBQUHAwEGCCsGAQUFBwMCMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQMEMCsw
- | KQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNvbW9kby5jb20vQ1BTMHsGA1Ud
- | HwR0MHIwOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmly
- | c3QtSGFyZHdhcmUuY3JsMDagNKAyhjBodHRwOi8vY3JsLmNvbW9kby5uZXQvVVRO
- | LVVTRVJGaXJzdC1IYXJkd2FyZS5jcmwwcQYIKwYBBQUHAQEEZTBjMDsGCCsGAQUF
- | BzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNvbS9VVE5BZGRUcnVzdFNlcnZlckNB
- | LmNydDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2EuY29tMBsGA1Ud
- | EQQUMBKCCCoudW4ub3JnggZ1bi5vcmcwDQYJKoZIhvcNAQEFBQADggEBAG9ajQJE
- | fC4XCmsdUD0HQ+5PNO1YtusPQD9I7zOgf6c25TMeu7PCblYH7nZq5NiiglchRX6a
- | VowALfIqjXyEWTDlq94y7JKtv/B62GU1dX7lvNoPS80/e1MzZCzkGa1hHZjiQL7r
- | kFoSmHeRr8A+fIjJZ85o7x2Y6qZJcjQTtASRAMV4kZEqST+cnRF3Pz8WnGKlFwFn
- | aUXH/t/MDgQbpa0+tKIg8dAP3Tb43r4051Rius6zOhS5PYOmo4MsBiKOVXHZnT15
- | vHiNtnSrtsKkxE3xGI7d9x5CC/BLnp8edK5cneCK39+MZFmJmvMFxXwiaIDCiWGx
- | vhwke7E0HzImDls=
- |_-----END CERTIFICATE-----
- | http-trace: TRACE is enabled
- | Headers:
- | Server: Lotus-Domino
- | Date: Wed, 29 Feb 2012 10:04:30 GMT
- | Pragma: no-cache
- | Cache-Control: no-cache
- | Expires: Wed, 29 Feb 2012 10:04:30 GMT
- | Content-Type: message/http
- |_Content-Length: 204
- |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-date: Wed, 29 Feb 2012 10:04:33 GMT; +5s from local time.
- |_http-malware-host: Host appears to be clean
- |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- | http-title: Site doesn't have a title (text/html; charset=UTF-8).
- |_Requested resource was http://157.150.34.43/mailjump.nsf
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-favicon: IBM Lotus Notes Collaboration Software
- | http-headers:
- | Server: Lotus-Domino
- | Date: Wed, 29 Feb 2012 10:04:47 GMT
- | Connection: close
- | Location: mailjump.nsf
- |
- |_ (Request type: GET)
- |_http-userdir-enum: Didn't find any users!
- |_http-wordpress-plugins: nothing found amongst the 100 most popular plugins, use --script-arg http-wordpress-plugins.search=<number|all> for deeper analysis)
- | ssl-enum-ciphers:
- | SSLv3
- | Ciphers (3)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- | TLSv1.0
- | Ciphers (5)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - unknown strength
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- |_ Least strength = unknown strength
- | http-vhosts:
- |_405 names had status 302
- | http-enum:
- | /homepage.nsf/homePage.gif?OpenImageResource: Lotus Domino
- | /icons/ecblank.gif: Lotus Domino
- | /admin4.nsf: Lotus Domino
- | /agentrunner.nsf: Lotus Domino
- | /busytime.nsf: Lotus Domino
- | /catalog.nsf: Lotus Domino
- | /certlog.nsf: Lotus Domino
- | /certsrv.nsf: Lotus Domino
- | /doladmin.nsf: Lotus Domino
- | /domcfg.nsf: Lotus Domino
- | /domlog.nsf: Lotus Domino
- | /events4.nsf: Lotus Domino
- | /homepage.nsf: Lotus Domino
- | /log.nsf: Lotus Domino
- | /mail1.box: Lotus Domino
- | /mail2.box: Lotus Domino
- | /names.nsf: Lotus Domino
- | /reports.nsf: Lotus Domino
- | /webadmin.nsf: Lotus Domino
- |_ /icons/ecblank.gif: Lotus Domino
- | ssl-google-cert-catalog:
- |_ No DB entry
- | http-domino-enum-passwords:
- |_ ERROR: No credentials supplied (see domino-enum-passwords.username and domino-enum-passwords.password)
- 445/tcp filtered microsoft-ds no-response
- 3389/tcp filtered ms-term-serv no-response
- Host script results:
- | dns-blacklist:
- | PROXY
- | dnsbl.ahbl.org - FAIL
- | socks.dnsbl.sorbs.net - FAIL
- | http.dnsbl.sorbs.net - FAIL
- | misc.dnsbl.sorbs.net - FAIL
- | dnsbl.tornevall.org - FAIL
- | SPAM
- | dnsbl.ahbl.org - FAIL
- | dnsbl.inps.de - FAIL
- | bl.nszones.com - FAIL
- | l2.apews.org - FAIL
- | list.quorum.to - FAIL
- | all.spamrats.com - FAIL
- | bl.spamcop.net - FAIL
- | spam.dnsbl.sorbs.net - FAIL
- |_ sbl.spamhaus.org - FAIL
- | dns-zeustracker:
- |_ ERROR: DNS Query failed
- |_asn-query: No Servers
- |_whois: See the result for 157.150.185.55.
- |_path-mtu: PMTU == 1500
- | ip-geolocation-geoplugin:
- | 157.150.34.43
- | coordinates (lat,lon): 40.752799987793,-73.972503662109
- |_ state: New York, United States
- | firewalk:
- | HOP HOST PROTOCOL BLOCKED PORTS
- |_1 127.0.0.1 tcp 23,139,445,3389
- | ip-geolocation-geobytes:
- | 157.150.34.43
- | coordinates (lat,lon): 40.7488,-73.9846
- |_ city: New York, New York, United States
- |_ipidseq: Unknown [used port 80]
- | qscan:
- | PORT FAMILY MEAN (us) STDDEV LOSS (%)
- | 21 0 2207039.30 141741.93 0.0%
- | 80 1 401146.80 46385.79 0.0%
- |_443 1 376206.90 23007.01 0.0%
- TRACEROUTE (using port 22/tcp)
- HOP RTT ADDRESS
- 1 0.24 ms 192.168.140.2
- 2 32.85 ms webmaildr.un.org (157.150.34.43)
- Final times for host: srtt: 379122 rttvar: 464954 to: 1250000
- New targets in the scanned cache: 0, pending ones: 0.
- NSE: Script Post-scanning.
- NSE: Starting runlevel 1 (of 4) scan.
- NSE: Starting 'reverse-index' (thread: 0xa9b0798).
- Initiating NSE at 05:35
- NSE: Finished 'reverse-index' (thread: 0xa9b0798).
- Completed NSE at 05:35, 0.00s elapsed
- NSE: Starting runlevel 2 (of 4) scan.
- NSE: Starting runlevel 3 (of 4) scan.
- NSE: Starting runlevel 4 (of 4) scan.
- Post-scan script results:
- | reverse-index:
- | 80/tcp: 157.150.185.55, 157.150.34.43
- |_ 443/tcp: 157.150.185.55, 157.150.34.43
- Read from /usr/local/bin/../share/nmap: nmap-os-db nmap-payloads nmap-protocols nmap-rpc nmap-service-probes nmap-services.
- OS and Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .
- Nmap done: 8 IP addresses (8 hosts up) scanned in 4582.56 seconds
- Raw packets sent: 3689 (178.378KB) | Rcvd: 2061 (145.558KB)
RAW Paste Data