Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # This paste its a simple display of 'ssl.rc' exploiter module (logfile)
- # and it will seach for heartbleed and poodle vulnerabilitys...
- # -----------------------------------------------------
- # 1º set scan (searching in WAN for port 443 SSL-HTTPS)
- # -----------------------------------------------------
- Nmap scan report for h2161561.stratoserver.net (81.169.188.156)
- Host is up, received user-set (0.072s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for a104-74-162-14.deploy.static.akamaitechnologies.com (104.74.162.14)
- Host is up, received user-set (0.31s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 12.68.90.116
- Host is up, received user-set (0.16s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for node-tst.pool-125-26.dynamic.totbb.net (125.26.150.221)
- Host is up, received user-set (0.33s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for www.NexQloud.com (207.192.165.180)
- Host is up, received user-set (0.060s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 87.116.3.182
- Host is up, received user-set (0.071s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 192-184-172-1.dsl.dynamic.sonic.net (192.184.172.1)
- Host is up, received user-set (0.21s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 104.194.3.72
- Host is up, received user-set (0.19s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for server-54-192-195-33.iad53.r.cloudfront.net (54.192.195.33)
- Host is up, received user-set (0.22s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 162-234-160-245.lightspeed.dybhfl.sbcglobal.net (162.234.160.245)
- Host is up, received user-set (0.18s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 205.193.192.33
- Host is up, received user-set (0.13s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for dhe-118-91-130-54.static.dhecyber.net.id (118.91.130.54)
- Host is up, received user-set (0.49s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for 63.237.180.19
- Host is up, received user-set (0.20s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for mail.ken.dk (77.243.39.210)
- Host is up, received user-set (0.077s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- Nmap scan report for bus219-062.gsb.columbia.edu (128.59.219.62)
- Host is up, received user-set (0.12s latency).
- PORT STATE SERVICE REASON
- 443/tcp open https syn-ack
- # -----------------------------------------------------
- # 2º step scans (scan for heartbleed)
- # -----------------------------------------------------
- # Nmap 6.46 scan initiated Sat May 2 04:24:55 2015 as: nmap -n -sS -Pn -oN /home/pedr0/RC-exploiter/logs/heartbleed.log --script ssl-ccs-injection.nse,ssl-heartbleed.nse --script-args vulns.showall -p 443 94.199.178.215 191.241.91.21 192.116.71.163 90.176.170.46
- Nmap scan report for 94.199.178.215
- Host is up (0.078s latency).
- PORT STATE SERVICE
- 443/tcp open https
- |_ssl-ccs-injection: ERROR: Script execution failed (use -d to debug)
- | ssl-heartbleed:
- | NOT VULNERABLE:
- | The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL/TLS encryption.
- | State: NOT VULNERABLE
- | References:
- | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
- | http://www.openssl.org/news/secadv_20140407.txt
- |_ http://cvedetails.com/cve/2014-0160/
- Nmap scan report for 191.241.91.21
- Host is up (0.35s latency).
- PORT STATE SERVICE
- 443/tcp open https
- |_ssl-ccs-injection: ERROR: Script execution failed (use -d to debug)
- | ssl-heartbleed:
- | NOT VULNERABLE:
- | The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL/TLS encryption.
- | State: NOT VULNERABLE
- | References:
- | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
- | http://www.openssl.org/news/secadv_20140407.txt
- |_ http://cvedetails.com/cve/2014-0160/
- Nmap scan report for 192.116.71.163
- Host is up (0.12s latency).
- PORT STATE SERVICE
- 443/tcp open https
- |_ssl-ccs-injection: ERROR: Script execution failed (use -d to debug)
- | ssl-heartbleed:
- | NOT VULNERABLE:
- | The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL/TLS encryption.
- | State: NOT VULNERABLE
- | References:
- | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
- | http://www.openssl.org/news/secadv_20140407.txt
- |_ http://cvedetails.com/cve/2014-0160/
- Nmap scan report for 90.176.170.46
- Host is up (0.088s latency).
- PORT STATE SERVICE
- 443/tcp open https
- |_ssl-ccs-injection: ERROR: Script execution failed (use -d to debug)
- | ssl-heartbleed:
- | NOT VULNERABLE:
- | The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL/TLS encryption.
- | State: NOT VULNERABLE
- | References:
- | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
- | http://www.openssl.org/news/secadv_20140407.txt
- |_ http://cvedetails.com/cve/2014-0160/
- # Nmap done at Sat May 2 04:24:59 2015 -- 4 IP addresses (4 hosts up) scanned in 4.35 seconds
- # -----------------------------------------------------
- # 3º step scans (scan ssl related)
- # -----------------------------------------------------
- # Nmap 6.46 scan initiated Sat May 2 04:25:00 2015 as: nmap -T4 -sS -Pn -oN /home/pedr0/RC-exploiter/logs/[ssl]report.log --script ssl-poodle.nse,ssl-cert.nse,ssl-enum-ciphers.nse,dns-brute.nse,ip-geolocation-geoplugin.nse -p 443 94.199.178.215 191.241.91.21 192.116.71.163 90.176.170.46
- Nmap scan report for sinope.laxius.hu (94.199.178.215)
- Host is up (0.076s latency).
- PORT STATE SERVICE
- 443/tcp open https
- | ssl-cert: Subject: commonName=sinope.laxius.hu/organizationName=Bluecast Kft/stateOrProvinceName=Budapest/countryName=HU
- | Issuer: commonName=sinope.laxius.hu/organizationName=Bluecast Kft/stateOrProvinceName=Budapest/countryName=HU
- | Public Key type: rsa
- | Public Key bits: 2048
- | Not valid before: 2011-02-10T02:26:47+00:00
- | Not valid after: 2012-02-10T02:26:47+00:00
- | MD5: 1e66 4701 d51d 1246 13dc 7369 a558 e029
- |_SHA-1: 9614 7082 0b33 ebb5 8b45 9495 fe37 68ba ce5f 8fa9
- | ssl-enum-ciphers:
- | SSLv3:
- | ciphers:
- | TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - strong
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | compressors:
- | DEFLATE
- | NULL
- | TLSv1.0:
- | ciphers:
- | TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - strong
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | compressors:
- | DEFLATE
- | NULL
- |_ least strength: strong
- | ssl-poodle:
- | VULNERABLE:
- | SSL POODLE information leak
- | State: VULNERABLE
- | IDs: CVE:CVE-2014-3566 OSVDB:113251
- | Description:
- | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and
- | other products, uses nondeterministic CBC padding, which makes it easier
- | for man-in-the-middle attackers to obtain cleartext data via a
- | padding-oracle attack, aka the "POODLE" issue.
- | Disclosure date: 2014-10-14
- | Check results:
- | TLS_RSA_WITH_AES_128_CBC_SHA
- | References:
- | https://www.imperialviolet.org/2014/10/14/poodle.html
- | http://osvdb.org/113251
- | https://www.openssl.org/~bodo/ssl-poodle.pdf
- |_ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566
- Host script results:
- | dns-brute:
- | DNS Brute-force hostnames:
- | ns1.laxius.hu - 94.199.178.213
- | ns2.laxius.hu - 79.172.201.40
- | www.laxius.hu - 94.199.178.214
- | stage.laxius.hu - 94.199.178.214
- | admin.laxius.hu - 94.199.178.214
- | mail.laxius.hu - 94.199.178.183
- | backup.laxius.hu - 86.101.164.79
- |_ ftp.laxius.hu - 94.199.178.214
- | ip-geolocation-geoplugin:
- | 94.199.178.215
- | coordinates (lat,lon): 47,20
- |_ state: Unknown, Hungary
- Nmap scan report for 191-241-91-21.pequinet.net.br (191.241.91.21)
- Host is up (0.40s latency).
- PORT STATE SERVICE
- 443/tcp open https
- | ssl-cert: Subject: commonName=UBNT/organizationName=Ubiquiti Networks Inc./stateOrProvinceName=CA/countryName=US
- | Issuer: commonName=UBNT/organizationName=Ubiquiti Networks Inc./stateOrProvinceName=CA/countryName=US
- | Public Key type: rsa
- | Public Key bits: 1024
- | Not valid before: 2011-06-02T07:35:02+00:00
- | Not valid after: 2020-01-01T08:35:02+00:00
- | MD5: 6863 bbff 0501 4b31 193a c2d5 f0c7 5dc6
- |_SHA-1: eb54 c44a 32a6 4497 d892 6ff8 7ba7 08f9 6fb0 bff3
- | ssl-enum-ciphers:
- | SSLv3:
- | ciphers:
- | TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - strong
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | compressors:
- | NULL
- | TLSv1.0:
- | ciphers:
- | TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - strong
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | compressors:
- | NULL
- |_ least strength: strong
- |_ssl-poodle: ERROR: Script execution failed (use -d to debug)
- Host script results:
- | dns-brute:
- | DNS Brute-force hostnames:
- | ns1.pequinet.net.br - 191.241.88.69
- |_ ns2.pequinet.net.br - 191.241.88.70
- | ip-geolocation-geoplugin:
- | 191.241.91.21
- | coordinates (lat,lon): -10,-55
- |_ state: Unknown, Brazil
- Nmap scan report for fish.spd.co.il (192.116.71.163)
- Host is up (0.12s latency).
- PORT STATE SERVICE
- 443/tcp open https
- Host script results:
- | dns-brute:
- | DNS Brute-force hostnames:
- | devel.spd.co.il - 80.179.148.11
- | ads.spd.co.il - 80.178.250.110
- | alerts.spd.co.il - 80.179.148.241
- | dns.spd.co.il - 212.199.164.176
- | mysql.spd.co.il - 212.199.163.164
- | apache.spd.co.il - 212.199.163.165
- | test.spd.co.il - 62.128.51.141
- | id.spd.co.il - 212.199.125.110
- | images.spd.co.il - 192.116.109.20
- | ns.spd.co.il - 212.199.164.175
- | mail.spd.co.il - 62.128.51.251
- | mirror.spd.co.il - 212.199.164.166
- | monitor.spd.co.il - 80.179.148.11
- | ns1.spd.co.il - 212.199.164.175
- | ns2.spd.co.il - 80.179.148.8
- | ns3.spd.co.il - 37.58.74.30
- | pbx.spd.co.il - 62.128.59.129
- | secure.spd.co.il - 192.116.109.192
- | smtp.spd.co.il - 80.179.55.190
- | squid.spd.co.il - 212.199.163.170
- | vpn.spd.co.il - 62.128.59.133
- | ssl.spd.co.il - 192.116.109.20
- | whois.spd.co.il - 192.116.109.20
- | wiki.spd.co.il - 80.178.250.103
- |_ www.spd.co.il - 192.230.82.105
- | ip-geolocation-geoplugin:
- | 192.116.71.163
- | coordinates (lat,lon): 31.5,34.75
- |_ state: Unknown, Israel
- Nmap scan report for 46-170-176-90.vybezek.net (90.176.170.46)
- Host is up (0.078s latency).
- PORT STATE SERVICE
- 443/tcp open https
- | ssl-cert: Subject: commonName=Spravce/organizationName=ZSSluknov/stateOrProvinceName=Some-State/countryName=CZ
- | Issuer: commonName=Spravce/organizationName=ZSSluknov/stateOrProvinceName=Some-State/countryName=CZ
- | Public Key type: rsa
- | Public Key bits: 1024
- | Not valid before: 2011-02-04T09:47:50+00:00
- | Not valid after: 2013-01-24T09:47:50+00:00
- | MD5: bb3f 65a4 d18d 4875 6219 4fe6 e914 e9e1
- |_SHA-1: 025b 70e3 90c4 f202 f7ac e95a dc7b 943d 72de 2684
- | ssl-enum-ciphers:
- | SSLv3:
- | ciphers:
- | TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA - weak
- | TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_DES_CBC_SHA - weak
- | TLS_RSA_EXPORT_WITH_DES40_CBC_SHA - weak
- | TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 - weak
- | TLS_RSA_EXPORT_WITH_RC4_40_MD5 - weak
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong
- | TLS_RSA_WITH_CAMELLIA_256_CBC_SHA - strong
- | TLS_RSA_WITH_DES_CBC_SHA - weak
- | TLS_RSA_WITH_RC4_128_MD5 - strong
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | compressors:
- | NULL
- | TLSv1.0:
- | ciphers:
- | TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA - weak
- | TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA - strong
- | TLS_DHE_RSA_WITH_DES_CBC_SHA - weak
- | TLS_RSA_EXPORT_WITH_DES40_CBC_SHA - weak
- | TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 - weak
- | TLS_RSA_EXPORT_WITH_RC4_40_MD5 - weak
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - strong
- | TLS_RSA_WITH_CAMELLIA_128_CBC_SHA - strong
- | TLS_RSA_WITH_CAMELLIA_256_CBC_SHA - strong
- | TLS_RSA_WITH_DES_CBC_SHA - weak
- | TLS_RSA_WITH_RC4_128_MD5 - strong
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | compressors:
- | NULL
- |_ least strength: weak
- | ssl-poodle:
- | VULNERABLE:
- | SSL POODLE information leak
- | State: VULNERABLE
- | IDs: CVE:CVE-2014-3566 OSVDB:113251
- | Description:
- | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and
- | other products, uses nondeterministic CBC padding, which makes it easier
- | for man-in-the-middle attackers to obtain cleartext data via a
- | padding-oracle attack, aka the "POODLE" issue.
- | Disclosure date: 2014-10-14
- | Check results:
- | TLS_RSA_WITH_AES_128_CBC_SHA
- | References:
- | https://www.imperialviolet.org/2014/10/14/poodle.html
- | http://osvdb.org/113251
- | https://www.openssl.org/~bodo/ssl-poodle.pdf
- |_ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566
- Host script results:
- | dns-brute:
- | DNS Brute-force hostnames:
- | mx.vybezek.net - 86.63.210.53
- | ns.vybezek.net - 86.63.210.2
- | ns1.vybezek.net - 86.63.210.2
- | test.vybezek.net - 86.63.210.3
- | ns2.vybezek.net - 86.63.210.4
- | intranet.vybezek.net - 86.63.210.6
- | mail.vybezek.net - 86.63.210.52
- | mail.vybezek.net - 86.63.210.4
- | mail2.vybezek.net - 86.63.210.40
- | www.vybezek.net - 86.63.210.3
- | mail3.vybezek.net - 86.63.210.40
- | sip.vybezek.net - 213.168.162.150
- | smtp.vybezek.net - 86.63.210.40
- | ftp.vybezek.net - 86.63.210.3
- | gw.vybezek.net - 86.63.210.1
- |_ db.vybezek.net - 86.63.210.7
- | ip-geolocation-geoplugin:
- | 90.176.170.46
- | coordinates (lat,lon): 49.75,15.5
- |_ state: Unknown, Czech Republic
- # Nmap done at Sat May 2 04:25:35 2015 -- 4 IP addresses (4 hosts up) scanned in 35.00 seconds
- # -----------------------------------------------------
- # 4º step scans (scan/brute-force-exploit) using
- # metasploit auxiliary modules
- # -----------------------------------------------------
- soon will be printed ...
Advertisement
Add Comment
Please, Sign In to add comment