JTSEC1333

Anonymous JTSEC #OpDomesticTerrorism Full Recon #3

Sep 28th, 2019
1,476
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 106.63 KB | None | 0 0
  1. #######################################################################################################################################
  2. =======================================================================================================================================
  3. Hostname fuhrernet.com ISP Comcast Cable Communications, LLC
  4. Continent North America Flag
  5. US
  6. Country United States Country Code US
  7. Region Pennsylvania Local time 28 Sep 2019 04:16 EDT
  8. City Levittown Postal Code 19056
  9. IP Address 68.81.58.227 Latitude 40.152
  10. Longitude -74.883
  11. =======================================================================================================================================
  12. #######################################################################################################################################
  13. > fuhrernet.com
  14. Server: 185.93.180.131
  15. Address: 185.93.180.131#53
  16.  
  17. Non-authoritative answer:
  18. Name: fuhrernet.com
  19. Address: 68.81.58.227
  20. >
  21. #######################################################################################################################################
  22. Domain Name: FUHRERNET.COM
  23. Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
  24. Registrar WHOIS Server: whois.godaddy.com
  25. Registrar URL: http://www.godaddy.com
  26. Updated Date: 2019-09-17T14:54:51Z
  27. Creation Date: 2017-11-06T18:02:49Z
  28. Registry Expiry Date: 2020-11-06T18:02:49Z
  29. Registrar: GoDaddy.com, LLC
  30. Registrar IANA ID: 146
  31. Registrar Abuse Contact Email: [email protected]
  32. Registrar Abuse Contact Phone: 480-624-2505
  33. Domain Status: ok https://icann.org/epp#ok
  34. Name Server: NS47.DOMAINCONTROL.COM
  35. Name Server: NS48.DOMAINCONTROL.COM
  36. DNSSEC: unsigned
  37. #######################################################################################################################################
  38. Domain Name: fuhrernet.com
  39. Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
  40. Registrar WHOIS Server: whois.godaddy.com
  41. Registrar URL: http://www.godaddy.com
  42. Updated Date: 2017-11-06T18:02:49Z
  43. Creation Date: 2017-11-06T18:02:49Z
  44. Registrar Registration Expiration Date: 2020-11-06T18:02:49Z
  45. Registrar: GoDaddy.com, LLC
  46. Registrar IANA ID: 146
  47. Registrar Abuse Contact Email: [email protected]
  48. Registrar Abuse Contact Phone: +1.4806242505
  49. Domain Status: ok http://www.icann.org/epp#ok
  50. Registrant Organization: Fuhrernet
  51. Registrant State/Province: Pennsylvania
  52. Registrant Country: US
  53. Registrant Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
  54. Admin Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
  55. Tech Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
  56. Name Server: NS47.DOMAINCONTROL.COM
  57. Name Server: NS48.DOMAINCONTROL.COM
  58. DNSSEC: unsigned
  59. #######################################################################################################################################
  60. [+] Target : fuhrernet.com
  61.  
  62. [+] IP Address : 68.81.58.227
  63.  
  64. [+] Headers :
  65.  
  66. [+] Date : Sat, 28 Sep 2019 08:23:29 GMT
  67. [+] Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  68. [+] X-Powered-By : PHP/7.1.1
  69. [+] Content-Length : 2626
  70. [+] Keep-Alive : timeout=5, max=100
  71. [+] Connection : Keep-Alive
  72. [+] Content-Type : text/html; charset=UTF-8
  73.  
  74. [+] SSL Certificate Information :
  75.  
  76. [+] commonName : localhost
  77. [+] commonName : localhost
  78. [+] Version : 1
  79. [+] Serial Number : B5C752C98781B503
  80. [+] Not Before : Nov 10 23:48:47 2009 GMT
  81. [+] Not After : Nov 8 23:48:47 2019 GMT
  82.  
  83. [+] Whois Lookup :
  84.  
  85. [+] NIR : None
  86. [+] ASN Registry : arin
  87. [+] ASN : 7922
  88. [+] ASN CIDR : 68.80.0.0/13
  89. [+] ASN Country Code : US
  90. [+] ASN Date : 2002-01-28
  91. [+] ASN Description : COMCAST-7922 - Comcast Cable Communications, LLC, US
  92. [+] cidr : 68.80.0.0/13
  93. [+] name : JUMPSTART-2
  94. [+] handle : NET-68-80-0-0-1
  95. [+] range : 68.80.0.0 - 68.87.255.255
  96. [+] description : Comcast Cable Communications, LLC
  97. [+] country : US
  98. [+] state : NJ
  99. [+] city : Mt Laurel
  100. [+] address : 1800 Bishops Gate Blvd
  101. [+] postal_code : 08054
  102. [+] created : 2002-01-28
  103. [+] updated : 2016-08-31
  104.  
  105. [+] Crawling Target...
  106.  
  107. [+] Looking for robots.txt........[ Not Found ]
  108. [+] Looking for sitemap.xml.......[ Found ]
  109. [+] Extracting sitemap Links......[ 13 ]
  110. [+] Extracting CSS Links..........[ 9 ]
  111. [+] Extracting Javascript Links...[ 0 ]
  112. [+] Extracting Internal Links.....[ 0 ]
  113. [+] Extracting External Links.....[ 0 ]
  114. [+] Extracting Images.............[ 0 ]
  115.  
  116. [+] Total Links Extracted : 22
  117.  
  118. [+] Dumping Links in /opt/FinalRecon/dumps/fuhrernet.com.dump
  119. [+] Completed!
  120. #######################################################################################################################################
  121. [i] Scanning Site: http://fuhrernet.com
  122.  
  123.  
  124.  
  125. B A S I C I N F O
  126. ====================
  127.  
  128.  
  129. [+] Site Title: Newsfeed
  130. [+] IP address: 68.81.58.227
  131. [+] Web Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  132. [+] CMS: Could Not Detect
  133. [+] Cloudflare: Not Detected
  134. [+] Robots File: Could NOT Find robots.txt!
  135.  
  136.  
  137.  
  138.  
  139. W H O I S L O O K U P
  140. ========================
  141.  
  142. Domain Name: FUHRERNET.COM
  143. Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
  144. Registrar WHOIS Server: whois.godaddy.com
  145. Registrar URL: http://www.godaddy.com
  146. Updated Date: 2019-09-17T14:54:51Z
  147. Creation Date: 2017-11-06T18:02:49Z
  148. Registry Expiry Date: 2020-11-06T18:02:49Z
  149. Registrar: GoDaddy.com, LLC
  150. Registrar IANA ID: 146
  151. Registrar Abuse Contact Email: [email protected]
  152. Registrar Abuse Contact Phone: 480-624-2505
  153. Domain Status: ok https://icann.org/epp#ok
  154. Name Server: NS47.DOMAINCONTROL.COM
  155. Name Server: NS48.DOMAINCONTROL.COM
  156. DNSSEC: unsigned
  157. URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
  158. >>> Last update of whois database: 2019-09-28T08:23:34Z <<<
  159.  
  160. For more information on Whois status codes, please visit https://icann.org/epp
  161.  
  162.  
  163.  
  164. The Registry database contains ONLY .COM, .NET, .EDU domains and
  165. Registrars.
  166.  
  167.  
  168.  
  169.  
  170. G E O I P L O O K U P
  171. =========================
  172.  
  173. [i] IP Address: 68.81.58.227
  174. [i] Country: United States
  175. [i] State: Pennsylvania
  176. [i] City: Levittown
  177. [i] Latitude: 40.1519
  178. [i] Longitude: -74.8826
  179.  
  180.  
  181.  
  182.  
  183. H T T P H E A D E R S
  184. =======================
  185.  
  186.  
  187. [i] HTTP/1.1 200 OK
  188. [i] Date: Sat, 28 Sep 2019 08:23:50 GMT
  189. [i] Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  190. [i] X-Powered-By: PHP/7.1.1
  191. [i] Content-Length: 2626
  192. [i] Connection: close
  193. [i] Content-Type: text/html; charset=UTF-8
  194.  
  195.  
  196.  
  197.  
  198. D N S L O O K U P
  199. ===================
  200.  
  201. fuhrernet.com. 599 IN A 68.81.58.227
  202. fuhrernet.com. 3599 IN NS ns47.domaincontrol.com.
  203. fuhrernet.com. 3599 IN NS ns48.domaincontrol.com.
  204. fuhrernet.com. 3599 IN SOA ns47.domaincontrol.com. dns.jomax.net. 2019091902 28800 7200 604800 600
  205. fuhrernet.com. 1799 IN MX 10 mx.yandex.net.
  206. fuhrernet.com. 3599 IN TXT "yandex-verification: d7cd81786b5817a7"
  207. fuhrernet.com. 3599 IN TXT "v=spf1 ip4: ip4: include:_spf.yandex.net ~all"
  208.  
  209.  
  210.  
  211.  
  212. S U B N E T C A L C U L A T I O N
  213. ====================================
  214.  
  215. Address = 68.81.58.227
  216. Network = 68.81.58.227 / 32
  217. Netmask = 255.255.255.255
  218. Broadcast = not needed on Point-to-Point links
  219. Wildcard Mask = 0.0.0.0
  220. Hosts Bits = 0
  221. Max. Hosts = 1 (2^0 - 0)
  222. Host Range = { 68.81.58.227 - 68.81.58.227 }
  223.  
  224.  
  225.  
  226. N M A P P O R T S C A N
  227. ============================
  228.  
  229. Starting Nmap 7.70 ( https://nmap.org ) at 2019-09-28 08:23 UTC
  230. Nmap scan report for fuhrernet.com (68.81.58.227)
  231. Host is up (0.030s latency).
  232. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  233.  
  234. PORT STATE SERVICE
  235. 21/tcp open ftp
  236. 22/tcp filtered ssh
  237. 23/tcp filtered telnet
  238. 80/tcp open http
  239. 110/tcp closed pop3
  240. 143/tcp closed imap
  241. 443/tcp open https
  242. 3389/tcp filtered ms-wbt-server
  243.  
  244. Nmap done: 1 IP address (1 host up) scanned in 1.35 seconds
  245. #######################################################################################################################################
  246. [INFO] ------TARGET info------
  247. [*] TARGET: http://fuhrernet.com/login.php
  248. [*] TARGET IP: 68.81.58.227
  249. [INFO] NO load balancer detected for fuhrernet.com...
  250. [*] DNS servers: ns47.domaincontrol.com.
  251. [*] TARGET server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  252. [*] CC: US
  253. [*] Country: United States
  254. [*] RegionCode: PA
  255. [*] RegionName: Pennsylvania
  256. [*] City: Levittown
  257. [*] ASN: AS7922
  258. [*] BGP_PREFIX: 68.80.0.0/13
  259. [*] ISP: COMCAST-7922 - Comcast Cable Communications, LLC, US
  260. [INFO] DNS enumeration:
  261. [INFO] Possible abuse mails are:
  262. [INFO] NO PAC (Proxy Auto Configuration) file FOUND
  263. [INFO] Starting FUZZing in http://fuhrernet.com/FUzZzZzZzZz...
  264. [INFO] Status code Folders
  265. [*] 200 http://fuhrernet.com/12
  266. [ALERT] Look in the source code. It may contain passwords
  267. [INFO] SAME content in http://fuhrernet.com/ AND http://68.81.58.227/
  268. [INFO] Links found from http://fuhrernet.com/login.php:
  269. [*] http://fuhrernet.com/create-account.php
  270. [*] http://fuhrernet.com/forgot-password.html
  271. [*] http://fuhrernet.com/forgot-username.html
  272. [INFO] Shodan detected the following opened ports on 68.81.58.227:
  273. [*] 1
  274. [*] 143
  275. [*] 2019
  276. [*] 21
  277. [*] 32
  278. [*] 3306
  279. [*] 4
  280. [*] 443
  281. [*] 62
  282. [*] 7
  283. [*] 80
  284. [*] 9000
  285. [*] 9001
  286. [*] 9675
  287. [INFO] ------VirusTotal SECTION------
  288. [INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
  289. [INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
  290. [INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
  291. [INFO] ------Alexa Rank SECTION------
  292. [INFO] Percent of Visitors Rank in Country:
  293. [INFO] Percent of Search Traffic:
  294. [INFO] Percent of Unique Visits:
  295. [INFO] Total Sites Linking In:
  296. [INFO] Useful links related to fuhrernet.com - 68.81.58.227:
  297. [*] https://www.virustotal.com/pt/ip-address/68.81.58.227/information/
  298. [*] https://www.hybrid-analysis.com/search?host=68.81.58.227
  299. [*] https://www.shodan.io/host/68.81.58.227
  300. [*] https://www.senderbase.org/lookup/?search_string=68.81.58.227
  301. [*] https://www.alienvault.com/open-threat-exchange/ip/68.81.58.227
  302. [*] http://pastebin.com/search?q=68.81.58.227
  303. [*] http://urlquery.net/search.php?q=68.81.58.227
  304. [*] http://www.alexa.com/siteinfo/fuhrernet.com
  305. [*] http://www.google.com/safebrowsing/diagnostic?site=fuhrernet.com
  306. [*] https://censys.io/ipv4/68.81.58.227
  307. [*] https://www.abuseipdb.com/check/68.81.58.227
  308. [*] https://urlscan.io/search/#68.81.58.227
  309. [*] https://github.com/search?q=68.81.58.227&type=Code
  310. [INFO] Useful links related to AS7922 - 68.80.0.0/13:
  311. [*] http://www.google.com/safebrowsing/diagnostic?site=AS:7922
  312. [*] https://www.senderbase.org/lookup/?search_string=68.80.0.0/13
  313. [*] http://bgp.he.net/AS7922
  314. [*] https://stat.ripe.net/AS7922
  315. [INFO] Date: 28/09/19 | Time: 04:28:11
  316. [INFO] Total time: 4 minute(s) and 17 second(s)
  317. #######################################################################################################################################
  318. [*] Load target domain: fuhrernet.com
  319. - starting scanning @ 2019-09-28 04:32:03
  320.  
  321. [+] Running & Checking source to be used
  322. ---------------------------------------------
  323.  
  324. ⍥ Shodan [ ✕ ]
  325. ⍥ Webarchive [ ✔ ]
  326. ⍥ Dnsdumpster [ ✔ ]
  327. ⍥ Certsh [ ✔ ]
  328. ⍥ Certspotter [ ✔ ]
  329. ⍥ Securitytrails [ ✕ ]
  330. ⍥ Threatminer [ ✔ ]
  331. ⍥ Riddler [ ✔ ]
  332. ⍥ Entrust [ ✔ ]
  333. ⍥ Bufferover [ ✔ ]
  334. ⍥ Censys [ ✕ ]
  335. ⍥ Threatcrowd [ ✔ ]
  336. ⍥ Hackertarget [ ✔ ]
  337. ⍥ Binaryedge [ ✕ ]
  338. ⍥ Virustotal [ ✕ ]
  339. ⍥ Findsubdomain [ ✔ ]
  340.  
  341. [+] Get & Count subdomain total From source
  342. ---------------------------------------------
  343.  
  344. ⍥ Hackertarget: Total Subdomain (1)
  345. ⍥ Findsubdomain: Total Subdomain (0)
  346. ⍥ Certspotter: Total Subdomain (0)
  347. ⍥ Threatminer: Total Subdomain (0)
  348. ⍥ Certsh: Total Subdomain (0)
  349. ⍥ BufferOver: Total Subdomain (0)
  350. ⍥ Entrust: Total Subdomain (0)
  351. ⍥ Threatcrowd: Total Subdomain (0)
  352. ⍥ Dnsdumpster: Total Subdomain (4)
  353. ⍥ Riddler: Total Subdomain (0)
  354. ⍥ Webarchive: Total Subdomain (1)
  355.  
  356. [+] Parsing & Sorting list Domain
  357. ---------------------------------------------
  358.  
  359. ⍥ Total [1]
  360.  
  361. - fuhrernet.com
  362.  
  363. ⍥ Total [1]
  364.  
  365. [+] Probe subdomain for working on http/https
  366. ---------------------------------------------
  367.  
  368. - http://fuhrernet.com
  369. - https://fuhrernet.com
  370.  
  371. ⍥ Total [2]
  372.  
  373.  
  374. [+] Check Live Host: Ping Sweep - ICMP PING
  375. ---------------------------------------------
  376.  
  377. ⍥ [LIVE] fuhrernet.com
  378.  
  379. [+] Check Resolving: Subdomains & Domains
  380. ---------------------------------------------
  381.  
  382. ⍥ Resolving domains to: 68.81.58.227
  383.  
  384. [+] Subdomain TakeOver - Check Possible Vulns
  385. ---------------------------------------------
  386.  
  387. ⍥ [FAILS] En: Unknown http://fuhrernet.com
  388. ⍥ [FAILS] En: Unknown https://fuhrernet.com
  389.  
  390. [+] Checks status code on port 80 and 443
  391. ---------------------------------------------
  392.  
  393. ⍥ [200] http://fuhrernet.com
  394. ⍥ [000] https://fuhrernet.com
  395.  
  396. [+] Web Screenshots: from domain list
  397. ---------------------------------------------
  398.  
  399. [+] 2 URLs to be screenshot
  400.  
  401. [+] 2 actual URLs screenshot
  402. [+] 0 error(s)
  403.  
  404. [+] Sud⍥my has been sucessfully completed
  405. ---------------------------------------------
  406.  
  407. ⍥ Location output:
  408. - output/09-28-2019/fuhrernet.com
  409. - output/09-28-2019/fuhrernet.com/report
  410. - output/09-28-2019/fuhrernet.com/screenshots
  411. #######################################################################################################################################
  412. [+] Starting At 2019-09-28 04:37:08.881372
  413. [+] Collecting Information On: http://fuhrernet.com/login.php
  414. [#] Status: 200
  415. --------------------------------------------------
  416. [#] Web Server Detected: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  417. [#] X-Powered-By: PHP/7.1.1
  418. [!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
  419. - Date: Sat, 28 Sep 2019 08:37:05 GMT
  420. - Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  421. - X-Powered-By: PHP/7.1.1
  422. - Content-Length: 6039
  423. - Keep-Alive: timeout=5, max=100
  424. - Connection: Keep-Alive
  425. - Content-Type: text/html; charset=UTF-8
  426. --------------------------------------------------
  427. [#] Finding Location..!
  428. [#] as: AS7922 Comcast Cable Communications, LLC
  429. [#] city: Levittown
  430. [#] country: United States
  431. [#] countryCode: US
  432. [#] isp: Comcast Cable Communications, LLC
  433. [#] lat: 40.1519
  434. [#] lon: -74.8826
  435. [#] org: Comcast Cable Communications, Inc.
  436. [#] query: 68.81.58.227
  437. [#] region: PA
  438. [#] regionName: Pennsylvania
  439. [#] status: success
  440. [#] timezone: America/New_York
  441. [#] zip: 19056
  442. --------------------------------------------------
  443. [x] Didn't Detect WAF Presence on: http://fuhrernet.com/login.php
  444. --------------------------------------------------
  445. [#] Starting Reverse DNS
  446. [!] Found 1 any Domain
  447. - fuhrernet.com
  448. --------------------------------------------------
  449. [!] Scanning Open Port
  450. [#] 21/tcp open ftp
  451. [#] 80/tcp open http
  452. [#] 85/tcp open mit-ml-dev
  453. [#] 443/tcp open https
  454. [#] 3306/tcp open mysql
  455. [#] 9001/tcp open tor-orport
  456. --------------------------------------------------
  457. [+] Collecting Information Disclosure!
  458. [#] Detecting sitemap.xml file
  459. [-] sitemap.xml file not Found!?
  460. [#] Detecting robots.txt file
  461. [-] robots.txt file not Found!?
  462. [#] Detecting GNU Mailman
  463. [-] GNU Mailman App Not Detected!?
  464. --------------------------------------------------
  465. [+] Crawling Url Parameter On: http://fuhrernet.com/login.php
  466. --------------------------------------------------
  467. [#] Searching Html Form !
  468. [+] Html Form Discovered
  469. [#] action: None
  470. [#] class: None
  471. [#] id: None
  472. [#] method: post
  473. --------------------------------------------------
  474. [-] No DOM Paramter Found!?
  475. --------------------------------------------------
  476. [-] No internal Dynamic Parameter Found!?
  477. --------------------------------------------------
  478. [-] No external Dynamic Paramter Found!?
  479. --------------------------------------------------
  480. [!] 13 Internal links Discovered
  481. [+] http://fuhrernet.com/login.php/assets/bootstrap/css/bootstrap.min.css
  482. [+] http://fuhrernet.com/login.php/assets/fonts/ionicons.min.css
  483. [+] http://fuhrernet.com/login.php/assets/css/Login-Form-Clean.css
  484. [+] http://fuhrernet.com/login.php/assets/css/styles.css
  485. [+] http://fuhrernet.com/login.php/assets/css/Profile-Card.css
  486. [+] http://fuhrernet.com/login.php/assets/css/untitled.css
  487. [+] http://fuhrernet.com/login.php/./apple-touch-icon.png
  488. [+] http://fuhrernet.com/login.php/./favicon-32x32.png
  489. [+] http://fuhrernet.com/login.php/./favicon-16x16.png
  490. [+] http://fuhrernet.com/login.php/./site.webmanifest
  491. [+] http://fuhrernet.com/login.php/./create-account.php
  492. [+] http://fuhrernet.com/login.php/./forgot-username.html
  493. [+] http://fuhrernet.com/login.php/./forgot-password.html
  494. --------------------------------------------------
  495. [!] 1 External links Discovered
  496. [#] https://cdnjs.cloudflare.com/ajax/libs/animate.css/3.5.2/animate.min.css
  497. --------------------------------------------------
  498. [#] Mapping Subdomain..
  499. [!] Found 1 Subdomain
  500. - fuhrernet.com
  501. --------------------------------------------------
  502. [!] Done At 2019-09-28 04:40:24.559313
  503. #######################################################################################################################################
  504.  
  505. Enter Address Website = fuhrernet.com
  506.  
  507.  
  508.  
  509. Reversing IP With HackTarget 'fuhrernet.com'
  510. -----------------------------------------------
  511.  
  512. [+] c-68-81-58-227.hsd1.pa.comcast.net
  513.  
  514.  
  515.  
  516. Reverse IP With YouGetSignal 'fuhrernet.com'
  517. -----------------------------------------------
  518.  
  519. [*] IP: 68.81.58.227
  520. [*] Domain: fuhrernet.com
  521. [*] Total Domains: 1
  522.  
  523. [+] fuhrernet.com
  524.  
  525.  
  526.  
  527. Geo IP Lookup 'fuhrernet.com'
  528. --------------------------------
  529.  
  530. [+] IP Address: 68.81.58.227
  531. [+] Country: United States
  532. [+] State: Pennsylvania
  533. [+] City: Levittown
  534. [+] Latitude: 40.1519
  535. [+] Longitude: -74.8826
  536.  
  537.  
  538.  
  539. Whois 'fuhrernet.com'
  540. ------------------------
  541.  
  542. [+] Domain Name: FUHRERNET.COM
  543. [+] Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
  544. [+] Registrar WHOIS Server: whois.godaddy.com
  545. [+] Registrar URL: http://www.godaddy.com
  546. [+] Updated Date: 2019-09-17T14:54:51Z
  547. [+] Creation Date: 2017-11-06T18:02:49Z
  548. [+] Registry Expiry Date: 2020-11-06T18:02:49Z
  549. [+] Registrar: GoDaddy.com, LLC
  550. [+] Registrar IANA ID: 146
  551. [+] Registrar Abuse Contact Email: [email protected]
  552. [+] Registrar Abuse Contact Phone: 480-624-2505
  553. [+] Domain Status: ok https://icann.org/epp#ok
  554. [+] Name Server: NS47.DOMAINCONTROL.COM
  555. [+] Name Server: NS48.DOMAINCONTROL.COM
  556. [+] DNSSEC: unsigned
  557. [+] URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
  558. [+] >>> Last update of whois database: 2019-09-28T08:36:22Z <<<
  559. [+] For more information on Whois status codes, please visit https://icann.org/epp
  560. [+] The Registry database contains ONLY .COM, .NET, .EDU domains and
  561. [+] Registrars.
  562.  
  563.  
  564.  
  565. Bypass Cloudflare 'fuhrernet.com'
  566. ------------------------------------
  567. [!] CloudFlare Bypass 68.81.58.227 | www.fuhrernet.com
  568.  
  569.  
  570. DNS Lookup 'fuhrernet.com'
  571. -----------------------------
  572.  
  573. [+] fuhrernet.com. 599 IN A 68.81.58.227
  574. [+] fuhrernet.com. 3599 IN NS ns47.domaincontrol.com.
  575. [+] fuhrernet.com. 3599 IN NS ns48.domaincontrol.com.
  576. [+] fuhrernet.com. 3599 IN SOA ns47.domaincontrol.com. dns.jomax.net. 2019091902 28800 7200 604800 600
  577. [+] fuhrernet.com. 1799 IN MX 10 mx.yandex.net.
  578. [+] fuhrernet.com. 3599 IN TXT "yandex-verification: d7cd81786b5817a7"
  579. [+] fuhrernet.com. 3599 IN TXT "v=spf1 ip4: ip4: include:_spf.yandex.net ~all"
  580.  
  581.  
  582.  
  583.  
  584. Show HTTP Header 'fuhrernet.com'
  585. -----------------------------------
  586.  
  587. [+] HTTP/1.1 200 OK
  588. [+] Date: Sat, 28 Sep 2019 08:36:54 GMT
  589. [+] Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  590. [+] X-Powered-By: PHP/7.1.1
  591. [+] Content-Type: text/html; charset=UTF-8
  592. [+]
  593.  
  594.  
  595.  
  596. Port Scan 'fuhrernet.com'
  597. ----------------------------
  598.  
  599. Starting Nmap 7.70 ( https://nmap.org ) at 2019-09-28 08:36 UTC
  600. Nmap scan report for fuhrernet.com (68.81.58.227)
  601. Host is up (0.024s latency).
  602. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  603.  
  604. PORT STATE SERVICE
  605. 21/tcp open ftp
  606. 22/tcp filtered ssh
  607. 23/tcp filtered telnet
  608. 80/tcp open http
  609. 110/tcp closed pop3
  610. 143/tcp closed imap
  611. 443/tcp open https
  612. 3389/tcp filtered ms-wbt-server
  613.  
  614. Nmap done: 1 IP address (1 host up) scanned in 1.25 seconds
  615.  
  616.  
  617.  
  618.  
  619.  
  620. Traceroute 'fuhrernet.com'
  621. -----------------------------
  622.  
  623. Start: 2019-09-28T08:37:01+0000
  624. HOST: web01 Loss% Snt Last Avg Best Wrst StDev
  625. 1.|-- 45.79.12.201 0.0% 3 0.6 0.7 0.6 0.8 0.1
  626. 2.|-- 45.79.12.4 0.0% 3 20.9 7.4 0.6 20.9 11.7
  627. 3.|-- dls-b22-link.telia.net 0.0% 3 0.9 2.0 0.8 4.3 2.0
  628. 4.|-- dls-b21-link.telia.net 0.0% 3 1.5 3.1 1.5 5.6 2.2
  629. 5.|-- comcast-ic-318909-dls-b21.c.telia.net 0.0% 3 1.9 1.8 1.5 2.0 0.3
  630. 6.|-- be-12441-cr02.dallas.tx.ibone.comcast.net 0.0% 3 1.9 2.8 1.9 3.4 0.8
  631. 7.|-- be-12324-cr01.houston.tx.ibone.comcast.net 0.0% 3 8.1 8.3 8.1 8.4 0.2
  632. 8.|-- be-11423-cr02.56marietta.ga.ibone.comcast.net 0.0% 3 20.1 20.2 19.4 21.1 0.9
  633. 9.|-- be-1402-cs04.56marietta.ga.ibone.comcast.net 0.0% 3 19.4 19.8 19.4 20.0 0.3
  634. 10.|-- be-1411-cr11.56marietta.ga.ibone.comcast.net 0.0% 3 19.3 19.7 19.3 20.0 0.4
  635. 11.|-- be-301-cr11.ashburn.va.ibone.comcast.net 0.0% 3 35.5 35.5 35.5 35.6 0.1
  636. 12.|-- be-1411-cs04.ashburn.va.ibone.comcast.net 0.0% 3 35.5 35.6 35.5 35.7 0.1
  637. 13.|-- be-1402-cr02.ashburn.va.ibone.comcast.net 0.0% 3 30.2 30.7 30.2 31.1 0.4
  638. 14.|-- be-7922-ar03.newcastle.de.panjde.comcast.net 0.0% 3 34.6 33.7 33.2 34.6 0.7
  639. 15.|-- be-900-ar03.norristown.pa.panjde.comcast.net 0.0% 3 35.5 35.3 35.2 35.5 0.1
  640. 16.|-- 162.151.182.178 0.0% 3 39.2 39.1 39.1 39.2 0.1
  641. 17.|-- lag2-acr22.levittown.pa.panjde.comcast.net 0.0% 3 41.0 41.0 41.0 41.0 0.0
  642. 18.|-- c-68-81-58-227.hsd1.pa.comcast.net 0.0% 3 53.8 54.1 51.3 57.1 2.9
  643. #######################################################################################################################################
  644. Trying "fuhrernet.com"
  645. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5382
  646. ;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 2, ADDITIONAL: 4
  647.  
  648. ;; QUESTION SECTION:
  649. ;fuhrernet.com. IN ANY
  650.  
  651. ;; ANSWER SECTION:
  652. fuhrernet.com. 3600 IN TXT "v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all"
  653. fuhrernet.com. 3600 IN TXT "yandex-verification: d7cd81786b5817a7"
  654. fuhrernet.com. 1800 IN MX 10 mx.yandex.net.
  655. fuhrernet.com. 3600 IN SOA ns47.domaincontrol.com. dns.jomax.net. 2019091902 28800 7200 604800 600
  656. fuhrernet.com. 600 IN A 68.81.58.227
  657. fuhrernet.com. 3600 IN NS ns47.domaincontrol.com.
  658. fuhrernet.com. 3600 IN NS ns48.domaincontrol.com.
  659.  
  660. ;; AUTHORITY SECTION:
  661. fuhrernet.com. 3600 IN NS ns47.domaincontrol.com.
  662. fuhrernet.com. 3600 IN NS ns48.domaincontrol.com.
  663.  
  664. ;; ADDITIONAL SECTION:
  665. ns47.domaincontrol.com. 3039 IN A 97.74.103.24
  666. ns47.domaincontrol.com. 23226 IN AAAA 2603:5:2172::18
  667. ns48.domaincontrol.com. 21374 IN A 173.201.71.24
  668. ns48.domaincontrol.com. 10967 IN AAAA 2603:5:2272::18
  669.  
  670. Received 410 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 136 ms
  671. #######################################################################################################################################
  672. ; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace fuhrernet.com
  673. ;; global options: +cmd
  674. . 79757 IN NS k.root-servers.net.
  675. . 79757 IN NS b.root-servers.net.
  676. . 79757 IN NS h.root-servers.net.
  677. . 79757 IN NS g.root-servers.net.
  678. . 79757 IN NS j.root-servers.net.
  679. . 79757 IN NS e.root-servers.net.
  680. . 79757 IN NS f.root-servers.net.
  681. . 79757 IN NS m.root-servers.net.
  682. . 79757 IN NS d.root-servers.net.
  683. . 79757 IN NS l.root-servers.net.
  684. . 79757 IN NS c.root-servers.net.
  685. . 79757 IN NS i.root-servers.net.
  686. . 79757 IN NS a.root-servers.net.
  687. . 79757 IN RRSIG NS 8 0 518400 20191011050000 20190928040000 59944 . M2/pztQA5M3yKsxBHFunkxHu99aDaPjvo/OdBj24SIpGnsF32zMxTCD0 GaK2OztD+2eaqf3eENHJCQuwb2cFtsiLCbyx0d6kSmmIiJPw3mEZ+W1t tplJwghGtAmj0Fqtb2f7DtlcVUraowz2s6vfPuDlrLla0Nabij9WikwL TQGtdJ83LtV30Sl/cxglkKX892KyiVRIL463prTUdcP5VFk1836iPLYW HnPimmCcGxsEYkP+5+VCvZzKyCqkADZVrpBAirud20z7gdcL6MXZqzEX 4Kkv6sUi7jomDYbgHwlV+CFVLzDdTzsWbQBRVYrd0klVJC5gRtV6jf6M TQnMOQ==
  688. ;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 29 ms
  689.  
  690. com. 172800 IN NS i.gtld-servers.net.
  691. com. 172800 IN NS j.gtld-servers.net.
  692. com. 172800 IN NS e.gtld-servers.net.
  693. com. 172800 IN NS l.gtld-servers.net.
  694. com. 172800 IN NS m.gtld-servers.net.
  695. com. 172800 IN NS f.gtld-servers.net.
  696. com. 172800 IN NS h.gtld-servers.net.
  697. com. 172800 IN NS b.gtld-servers.net.
  698. com. 172800 IN NS d.gtld-servers.net.
  699. com. 172800 IN NS g.gtld-servers.net.
  700. com. 172800 IN NS c.gtld-servers.net.
  701. com. 172800 IN NS a.gtld-servers.net.
  702. com. 172800 IN NS k.gtld-servers.net.
  703. com. 86400 IN DS 30909 8 2 E2D3C916F6DEEAC73294E8268FB5885044A833FC5459588F4A9184CF C41A5766
  704. com. 86400 IN RRSIG DS 8 1 86400 20191011050000 20190928040000 59944 . h6+G+ESPE9Aa2qAQwbM53M14XGUz/j2SCYydXlhRZ+SHobuK9DqayXpY FFWWWKv0+qRzo1TduRVgqbtj0pYMX2jFfgoSNdpELPfVti+k704LO+D1 UTyhNh066JIFXd3bZPgZ7mlMI2PEWPAVl3l4XlxgMDzyGSEVQQGWuFwm IubH9k3Ud8jQPMZlMIkb9ET87BW0u6NR/HJKTyCnlBuMF9sr5mHkzFN4 jkESPG7//c84lv5JJNeyIUe7hY5z0sHUof6UeR7iDSQZdB4hjqyG2qN0 NumZbMgXCR9DJrVH7PvUrR7MEn29Rt7HLY5lxL48axCNAZWEUJvUgJ3M c49fDw==
  705. ;; Received 1173 bytes from 193.0.14.129#53(k.root-servers.net) in 81 ms
  706.  
  707. fuhrernet.com. 172800 IN NS ns47.domaincontrol.com.
  708. fuhrernet.com. 172800 IN NS ns48.domaincontrol.com.
  709. CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN NSEC3 1 1 0 - CK0Q1GIN43N1ARRC9OSM6QPQR81H5M9A NS SOA RRSIG DNSKEY NSEC3PARAM
  710. CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN RRSIG NSEC3 8 2 86400 20191002044638 20190925033638 17708 com. W1EdwlejJtzVVubIBRcoCicfmwD78yZE5RGrjWJc1enFUVYFadLsyHDm SdGwV9H5Izrr+dDFUqRrzw6AtZZD0agyG7oqP2066DddrgnwryHNTtkl 7TLBFPm/io9cRPiEANIyDLKqn7WbKDx+5BZ0Lys/HBUkXGkcVevSksfD /rk=
  711. 6RG8GQ3EJ5GEU55CNMDPQF4EN9E7SCFP.com. 86400 IN NSEC3 1 1 0 - 6RG8MMU5E2D4SMANA51JLH13O3PMDFVD NS DS RRSIG
  712. 6RG8GQ3EJ5GEU55CNMDPQF4EN9E7SCFP.com. 86400 IN RRSIG NSEC3 8 2 86400 20191002054536 20190925043536 17708 com. GI9DvwhtHQmOF+PC7BUPicV/1zc/W48kPFsFOjmKxRTv/EzXe16YZhcL kPKVxteUFNV40iWLpVYK7c8KhtG7hp5E1L+ntjsq/aujj/IEsXLssg/D fghuvhM8HamuUyW6zt8RevX19KjD9wCEbYG/AMlAilzLaGaxRYRgMePj rvM=
  713. ;; Received 667 bytes from 192.52.178.30#53(k.gtld-servers.net) in 59 ms
  714.  
  715. fuhrernet.com. 600 IN A 68.81.58.227
  716. fuhrernet.com. 3600 IN NS ns47.domaincontrol.com.
  717. fuhrernet.com. 3600 IN NS ns48.domaincontrol.com.
  718. ;; Received 110 bytes from 2603:5:2172::18#53(ns47.domaincontrol.com) in 33 ms
  719. #######################################################################################################################################
  720. [*] Performing General Enumeration of Domain: fuhrernet.com
  721. [-] DNSSEC is not configured for fuhrernet.com
  722. [*] SOA ns47.domaincontrol.com 97.74.103.24
  723. [*] NS ns48.domaincontrol.com 173.201.71.24
  724. [*] NS ns48.domaincontrol.com 2603:5:2272::18
  725. [*] NS ns47.domaincontrol.com 97.74.103.24
  726. [*] NS ns47.domaincontrol.com 2603:5:2172::18
  727. [*] MX mx.yandex.net 77.88.21.89
  728. [*] MX mx.yandex.net 213.180.193.89
  729. [*] MX mx.yandex.net 213.180.204.89
  730. [*] MX mx.yandex.net 93.158.134.89
  731. [*] MX mx.yandex.net 87.250.250.89
  732. [*] MX mx.yandex.net 2a02:6b8::89
  733. [*] A fuhrernet.com 68.81.58.227
  734. [*] TXT fuhrernet.com v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all
  735. [*] TXT fuhrernet.com yandex-verification: d7cd81786b5817a7
  736. [*] Enumerating SRV Records
  737. [-] No SRV Records Found for fuhrernet.com
  738. [+] 0 Records Found
  739. #######################################################################################################################################
  740. rocessing domain fuhrernet.com
  741. [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  742. [+] Getting nameservers
  743. 173.201.71.24 - ns48.domaincontrol.com
  744. 97.74.103.24 - ns47.domaincontrol.com
  745. [-] Zone transfer failed
  746.  
  747. [+] TXT records found
  748. "v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all"
  749. "yandex-verification: d7cd81786b5817a7"
  750.  
  751. [+] MX records found, added to target list
  752. 10 mx.yandex.net.
  753.  
  754. [*] Scanning fuhrernet.com for A records
  755. 68.81.58.227 - fuhrernet.com
  756. 68.81.58.227 - www.fuhrernet.com
  757. #######################################################################################################################################
  758.  
  759. AVAILABLE PLUGINS
  760. -----------------
  761.  
  762. SessionRenegotiationPlugin
  763. OpenSslCcsInjectionPlugin
  764. SessionResumptionPlugin
  765. HttpHeadersPlugin
  766. EarlyDataPlugin
  767. CertificateInfoPlugin
  768. CompressionPlugin
  769. RobotPlugin
  770. OpenSslCipherSuitesPlugin
  771. HeartbleedPlugin
  772. FallbackScsvPlugin
  773.  
  774.  
  775.  
  776. CHECKING HOST(S) AVAILABILITY
  777. -----------------------------
  778.  
  779. 68.81.58.227:443 => 68.81.58.227
  780.  
  781.  
  782.  
  783.  
  784. SCAN RESULTS FOR 68.81.58.227:443 - 68.81.58.227
  785. ------------------------------------------------
  786.  
  787. * Downgrade Attacks:
  788. TLS_FALLBACK_SCSV: OK - Supported
  789.  
  790. * TLS 1.2 Session Resumption Support:
  791. With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
  792. With TLS Tickets: OK - Supported
  793.  
  794. * Certificate Information:
  795. Content
  796. SHA1 Fingerprint: b0238c547a905bfa119c4e8baccaeacf36491ff6
  797. Common Name: localhost
  798. Issuer: localhost
  799. Serial Number: 13098529066745705731
  800. Not Before: 2009-11-10 23:48:47
  801. Not After: 2019-11-08 23:48:47
  802. Signature Algorithm: sha1
  803. Public Key Algorithm: RSA
  804. Key Size: 1024
  805. Exponent: 65537 (0x10001)
  806. DNS Subject Alternative Names: []
  807.  
  808. Trust
  809. Hostname Validation: FAILED - Certificate does NOT match 68.81.58.227
  810. Android CA Store (9.0.0_r9): FAILED - Certificate is NOT Trusted: self signed certificate
  811. Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):FAILED - Certificate is NOT Trusted: self signed certificate
  812. Java CA Store (jdk-12.0.1): FAILED - Certificate is NOT Trusted: self signed certificate
  813. Mozilla CA Store (2019-03-14): FAILED - Certificate is NOT Trusted: self signed certificate
  814. Windows CA Store (2019-05-27): FAILED - Certificate is NOT Trusted: self signed certificate
  815. Symantec 2018 Deprecation: OK - Not a Symantec-issued certificate
  816. Received Chain: localhost
  817. Verified Chain: ERROR - Could not build verified chain (certificate untrusted?)
  818. Received Chain Contains Anchor: ERROR - Could not build verified chain (certificate untrusted?)
  819. Received Chain Order: OK - Order is valid
  820. Verified Chain contains SHA1: ERROR - Could not build verified chain (certificate untrusted?)
  821.  
  822. Extensions
  823. OCSP Must-Staple: NOT SUPPORTED - Extension not found
  824. Certificate Transparency: NOT SUPPORTED - Extension not found
  825.  
  826. OCSP Stapling
  827. NOT SUPPORTED - Server did not send back an OCSP response
  828.  
  829. * SSLV3 Cipher Suites:
  830. Server rejected all cipher suites.
  831.  
  832. * OpenSSL CCS Injection:
  833. OK - Not vulnerable to OpenSSL CCS injection
  834.  
  835. * SSLV2 Cipher Suites:
  836. Server rejected all cipher suites.
  837.  
  838. * Session Renegotiation:
  839. Client-initiated Renegotiation: OK - Rejected
  840. Secure Renegotiation: OK - Supported
  841.  
  842. * TLSV1_3 Cipher Suites:
  843. Server rejected all cipher suites.
  844.  
  845. * Deflate Compression:
  846. OK - Compression disabled
  847.  
  848. * TLSV1 Cipher Suites:
  849. Forward Secrecy OK - Supported
  850. RC4 OK - Not Supported
  851.  
  852. Preferred:
  853. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  854. Accepted:
  855. TLS_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
  856. TLS_RSA_WITH_IDEA_CBC_SHA 128 bits HTTP 200 OK
  857. TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
  858. TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
  859. TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  860. TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  861. TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  862. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  863. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  864. TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  865. TLS_DHE_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
  866. TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
  867. TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
  868. TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  869. TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  870. TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  871.  
  872. * TLSV1_1 Cipher Suites:
  873. Forward Secrecy OK - Supported
  874. RC4 OK - Not Supported
  875.  
  876. Preferred:
  877. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  878. Accepted:
  879. TLS_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
  880. TLS_RSA_WITH_IDEA_CBC_SHA 128 bits HTTP 200 OK
  881. TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
  882. TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
  883. TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  884. TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  885. TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  886. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  887. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  888. TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  889. TLS_DHE_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
  890. TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
  891. TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
  892. TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  893. TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  894. TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  895.  
  896. * TLSV1_2 Cipher Suites:
  897. Forward Secrecy OK - Supported
  898. RC4 OK - Not Supported
  899.  
  900. Preferred:
  901. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  902. Accepted:
  903. TLS_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
  904. TLS_RSA_WITH_IDEA_CBC_SHA 128 bits HTTP 200 OK
  905. TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
  906. TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
  907. TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  908. TLS_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
  909. TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  910. TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
  911. TLS_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
  912. TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  913. TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  914. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  915. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 200 OK
  916. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  917. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
  918. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
  919. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  920. TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  921. TLS_DHE_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
  922. TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
  923. TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
  924. TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
  925. TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
  926. TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
  927. TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
  928. TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
  929. TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
  930. TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  931. TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
  932.  
  933. * OpenSSL Heartbleed:
  934. OK - Not vulnerable to Heartbleed
  935.  
  936. * ROBOT Attack:
  937. OK - Not vulnerable
  938.  
  939.  
  940. SCAN COMPLETED IN 24.24 S
  941. -------------------------
  942. #######################################################################################################################################
  943.  
  944. Domains still to check: 1
  945. Checking if the hostname fuhrernet.com. given is in fact a domain...
  946.  
  947. Analyzing domain: fuhrernet.com.
  948. Checking NameServers using system default resolver...
  949. IP: 173.201.71.24 (United States)
  950. HostName: ns48.domaincontrol.com Type: NS
  951. HostName: ns48.domaincontrol.com Type: PTR
  952. IP: 97.74.103.24 (United States)
  953. HostName: ns47.domaincontrol.com Type: NS
  954. HostName: ns47.domaincontrol.com Type: PTR
  955.  
  956. Checking MailServers using system default resolver...
  957. IP: 87.250.250.89 (Russian Federation)
  958. HostName: mx.yandex.net Type: MX
  959. HostName: mx.yandex.ru Type: PTR
  960. IP: 213.180.204.89 (Russian Federation)
  961. HostName: mx.yandex.net Type: MX
  962. HostName: mx.yandex.ru Type: PTR
  963. IP: 77.88.21.89 (Russian Federation)
  964. HostName: mx.yandex.net Type: MX
  965. HostName: mx.yandex.ru Type: PTR
  966. IP: 213.180.193.89 (Russian Federation)
  967. HostName: mx.yandex.net Type: MX
  968. HostName: mx.yandex.ru Type: PTR
  969. IP: 93.158.134.89 (Russian Federation)
  970. HostName: mx.yandex.net Type: MX
  971. HostName: mx.yandex.ru Type: PTR
  972.  
  973. Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
  974. No zone transfer found on nameserver 97.74.103.24
  975. No zone transfer found on nameserver 173.201.71.24
  976.  
  977. Checking SPF record...
  978. New IP found: <IP-1>
  979. New IP found: <IP-2>
  980.  
  981. Checking SPF record...
  982.  
  983. Checking 192 most common hostnames using system default resolver...
  984. IP: 68.81.58.227 (United States)
  985. HostName: www.fuhrernet.com. Type: A
  986.  
  987. Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
  988. Checking netblock 68.81.58.0
  989. Checking netblock 97.74.103.0
  990. Checking netblock 93.158.134.0
  991. Checking netblock 213.180.193.0
  992. Checking netblock 173.201.71.0
  993. Checking netblock 77.88.21.0
  994. Checking netblock 87.250.250.0
  995. Checking netblock 0
  996. Checking netblock 213.180.204.0
  997.  
  998. Searching for fuhrernet.com. emails in Google
  999.  
  1000. Checking 10 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
  1001. Host 68.81.58.227 is up (echo-reply ttl 49)
  1002. Host 97.74.103.24 is up (reset ttl 64)
  1003. Host 93.158.134.89 is up (reset ttl 64)
  1004. Host 213.180.193.89 is up (reset ttl 64)
  1005. Host 173.201.71.24 is up (echo-reply ttl 56)
  1006. Host 77.88.21.89 is up (reset ttl 64)
  1007. Host 87.250.250.89 is up (reset ttl 64)
  1008. Failed to resolve "<IP-2>".
  1009. WARNING: No targets were specified, so 0 hosts scanned.
  1010. Host <IP-2> is down
  1011. Failed to resolve "<IP-1>".
  1012. WARNING: No targets were specified, so 0 hosts scanned.
  1013. Host <IP-1> is down
  1014. Host 213.180.204.89 is up (reset ttl 64)
  1015.  
  1016. Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
  1017. Scanning ip 68.81.58.227 (www.fuhrernet.com.):
  1018. adjust_timeouts2: packet supposedly had rtt of -57270 microseconds. Ignoring time.
  1019. adjust_timeouts2: packet supposedly had rtt of -57270 microseconds. Ignoring time.
  1020. adjust_timeouts2: packet supposedly had rtt of -91548 microseconds. Ignoring time.
  1021. adjust_timeouts2: packet supposedly had rtt of -91548 microseconds. Ignoring time.
  1022. 21/tcp open tcpwrapped syn-ack ttl 112
  1023. | ftp-syst:
  1024. |_ SYST: UNIX emulated by FileZilla
  1025. 80/tcp open tcpwrapped syn-ack ttl 112
  1026. |_http-favicon: Unknown favicon MD5: DB329B3B28D2D0EFB3462491F591D883
  1027. | http-methods:
  1028. |_ Supported Methods: GET HEAD POST OPTIONS
  1029. |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1030. |_http-title: Newsfeed
  1031. 443/tcp open tcpwrapped syn-ack ttl 112
  1032. | http-methods:
  1033. |_ Supported Methods: GET HEAD POST OPTIONS
  1034. |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1035. |_http-title: Bad request!
  1036. | ssl-cert: Subject: commonName=localhost
  1037. | Issuer: commonName=localhost
  1038. | Public Key type: rsa
  1039. | Public Key bits: 1024
  1040. | Signature Algorithm: sha1WithRSAEncryption
  1041. | Not valid before: 2009-11-10T23:48:47
  1042. | Not valid after: 2019-11-08T23:48:47
  1043. | MD5: a0a4 4cc9 9e84 b26f 9e63 9f9e d229 dee0
  1044. |_SHA-1: b023 8c54 7a90 5bfa 119c 4e8b acca eacf 3649 1ff6
  1045. |_ssl-date: TLS randomness does not represent time
  1046. | tls-alpn:
  1047. |_ http/1.1
  1048. 3306/tcp open tcpwrapped syn-ack ttl 112
  1049. Device type: general purpose|WAP
  1050. Scanning ip 97.74.103.24 (ns47.domaincontrol.com (PTR)):
  1051. 53/tcp open tcpwrapped syn-ack ttl 52
  1052. Scanning ip 93.158.134.89 (mx.yandex.ru (PTR)):
  1053. Scanning ip 213.180.193.89 (mx.yandex.ru (PTR)):
  1054. Scanning ip 173.201.71.24 (ns48.domaincontrol.com (PTR)):
  1055. 53/tcp open tcpwrapped syn-ack ttl 56
  1056. Scanning ip 77.88.21.89 (mx.yandex.ru (PTR)):
  1057. Scanning ip 87.250.250.89 (mx.yandex.ru (PTR)):
  1058. Scanning ip 213.180.204.89 (mx.yandex.ru (PTR)):
  1059. WebCrawling domain's web servers... up to 50 max links.
  1060. --Finished--
  1061. Summary information for domain fuhrernet.com.
  1062. -----------------------------------------
  1063.  
  1064. Domain Ips Information:
  1065. IP: 68.81.58.227
  1066. HostName: www.fuhrernet.com. Type: A
  1067. Country: United States
  1068. Is Active: True (echo-reply ttl 49)
  1069. Port: 21/tcp open tcpwrapped syn-ack ttl 112
  1070. Script Info: | ftp-syst:
  1071. Script Info: |_ SYST: UNIX emulated by FileZilla
  1072. Port: 80/tcp open tcpwrapped syn-ack ttl 112
  1073. Script Info: |_http-favicon: Unknown favicon MD5: DB329B3B28D2D0EFB3462491F591D883
  1074. Script Info: | http-methods:
  1075. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1076. Script Info: |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1077. Script Info: |_http-title: Newsfeed
  1078. Port: 443/tcp open tcpwrapped syn-ack ttl 112
  1079. Script Info: | http-methods:
  1080. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1081. Script Info: |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1082. Script Info: |_http-title: Bad request!
  1083. Script Info: | ssl-cert: Subject: commonName=localhost
  1084. Script Info: | Issuer: commonName=localhost
  1085. Script Info: | Public Key type: rsa
  1086. Script Info: | Public Key bits: 1024
  1087. Script Info: | Signature Algorithm: sha1WithRSAEncryption
  1088. Script Info: | Not valid before: 2009-11-10T23:48:47
  1089. Script Info: | Not valid after: 2019-11-08T23:48:47
  1090. Script Info: | MD5: a0a4 4cc9 9e84 b26f 9e63 9f9e d229 dee0
  1091. Script Info: |_SHA-1: b023 8c54 7a90 5bfa 119c 4e8b acca eacf 3649 1ff6
  1092. Script Info: |_ssl-date: TLS randomness does not represent time
  1093. Script Info: | tls-alpn:
  1094. Script Info: |_ http/1.1
  1095. Port: 3306/tcp open tcpwrapped syn-ack ttl 112
  1096. Script Info: Device type: general purpose|WAP
  1097. IP: 97.74.103.24
  1098. HostName: ns47.domaincontrol.com Type: NS
  1099. HostName: ns47.domaincontrol.com Type: PTR
  1100. Country: United States
  1101. Is Active: True (reset ttl 64)
  1102. Port: 53/tcp open tcpwrapped syn-ack ttl 52
  1103. IP: 93.158.134.89
  1104. HostName: mx.yandex.net Type: MX
  1105. HostName: mx.yandex.ru Type: PTR
  1106. Country: Russian Federation
  1107. Is Active: True (reset ttl 64)
  1108. IP: 213.180.193.89
  1109. HostName: mx.yandex.net Type: MX
  1110. HostName: mx.yandex.ru Type: PTR
  1111. Country: Russian Federation
  1112. Is Active: True (reset ttl 64)
  1113. IP: 173.201.71.24
  1114. HostName: ns48.domaincontrol.com Type: NS
  1115. HostName: ns48.domaincontrol.com Type: PTR
  1116. Country: United States
  1117. Is Active: True (echo-reply ttl 56)
  1118. Port: 53/tcp open tcpwrapped syn-ack ttl 56
  1119. IP: 77.88.21.89
  1120. HostName: mx.yandex.net Type: MX
  1121. HostName: mx.yandex.ru Type: PTR
  1122. Country: Russian Federation
  1123. Is Active: True (reset ttl 64)
  1124. IP: 87.250.250.89
  1125. HostName: mx.yandex.net Type: MX
  1126. HostName: mx.yandex.ru Type: PTR
  1127. Country: Russian Federation
  1128. Is Active: True (reset ttl 64)
  1129. IP: <IP-2>
  1130. Type: SPF
  1131. Is Active: False
  1132. IP: <IP-1>
  1133. Type: SPF
  1134. Is Active: False
  1135. IP: 213.180.204.89
  1136. HostName: mx.yandex.net Type: MX
  1137. HostName: mx.yandex.ru Type: PTR
  1138. Country: Russian Federation
  1139. Is Active: True (reset ttl 64)
  1140. #######################################################################################################################################
  1141. dnsenum VERSION:1.2.4
  1142.  
  1143. ----- fuhrernet.com -----
  1144.  
  1145.  
  1146. Host's addresses:
  1147. __________________
  1148.  
  1149. fuhrernet.com. 340 IN A 68.81.58.227
  1150.  
  1151.  
  1152. Name Servers:
  1153. ______________
  1154.  
  1155. ns47.domaincontrol.com. 86004 IN A 97.74.103.24
  1156. ns48.domaincontrol.com. 86028 IN A 173.201.71.24
  1157.  
  1158.  
  1159. Mail (MX) Servers:
  1160. ___________________
  1161.  
  1162. mx.yandex.net. 554 IN A 87.250.250.89
  1163. mx.yandex.net. 554 IN A 213.180.204.89
  1164. mx.yandex.net. 554 IN A 77.88.21.89
  1165. mx.yandex.net. 554 IN A 213.180.193.89
  1166. mx.yandex.net. 554 IN A 93.158.134.89
  1167.  
  1168.  
  1169. Trying Zone Transfers and getting Bind Versions:
  1170. _________________________________________________
  1171.  
  1172.  
  1173. Trying Zone Transfer for fuhrernet.com on ns47.domaincontrol.com ...
  1174.  
  1175. Trying Zone Transfer for fuhrernet.com on ns48.domaincontrol.com ...
  1176.  
  1177. brute force file not specified, bay.
  1178. #######################################################################################################################################
  1179. Domain Name: FUHRERNET.COM
  1180. Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
  1181. Registrar WHOIS Server: whois.godaddy.com
  1182. Registrar URL: http://www.godaddy.com
  1183. Updated Date: 2019-09-17T14:54:51Z
  1184. Creation Date: 2017-11-06T18:02:49Z
  1185. Registry Expiry Date: 2020-11-06T18:02:49Z
  1186. Registrar: GoDaddy.com, LLC
  1187. Registrar IANA ID: 146
  1188. Registrar Abuse Contact Email: [email protected]
  1189. Registrar Abuse Contact Phone: 480-624-2505
  1190. Domain Status: ok https://icann.org/epp#ok
  1191. Name Server: NS47.DOMAINCONTROL.COM
  1192. Name Server: NS48.DOMAINCONTROL.COM
  1193. DNSSEC: unsigned
  1194. #######################################################################################################################################
  1195. Domain Name: fuhrernet.com
  1196. Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
  1197. Registrar WHOIS Server: whois.godaddy.com
  1198. Registrar URL: http://www.godaddy.com
  1199. Updated Date: 2017-11-06T18:02:49Z
  1200. Creation Date: 2017-11-06T18:02:49Z
  1201. Registrar Registration Expiration Date: 2020-11-06T18:02:49Z
  1202. Registrar: GoDaddy.com, LLC
  1203. Registrar IANA ID: 146
  1204. Registrar Abuse Contact Email: [email protected]
  1205. Registrar Abuse Contact Phone: +1.4806242505
  1206. Domain Status: ok http://www.icann.org/epp#ok
  1207. Registrant Organization: Fuhrernet
  1208. Registrant State/Province: Pennsylvania
  1209. Registrant Country: US
  1210. Registrant Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
  1211. Admin Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
  1212. Tech Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
  1213. Name Server: NS47.DOMAINCONTROL.COM
  1214. Name Server: NS48.DOMAINCONTROL.COM
  1215. DNSSEC: unsigned
  1216. #######################################################################################################################################
  1217. [*] Processing domain fuhrernet.com
  1218. [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  1219. [+] Getting nameservers
  1220. 173.201.71.24 - ns48.domaincontrol.com
  1221. 97.74.103.24 - ns47.domaincontrol.com
  1222. [-] Zone transfer failed
  1223.  
  1224. [+] TXT records found
  1225. "v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all"
  1226. "yandex-verification: d7cd81786b5817a7"
  1227.  
  1228. [+] MX records found, added to target list
  1229. 10 mx.yandex.net.
  1230.  
  1231. [*] Scanning fuhrernet.com for A records
  1232. 68.81.58.227 - fuhrernet.com
  1233. 68.81.58.227 - www.fuhrernet.com
  1234. #######################################################################################################################################
  1235. [*] Found SPF record:
  1236. [*] v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all
  1237. [*] SPF record contains an All item: ~all
  1238. [*] No DMARC record found. Looking for organizational record
  1239. [+] No organizational DMARC record
  1240. [+] Spoofing possible for fuhrernet.com!
  1241. ######################################################################################################################################
  1242. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:54 EDT
  1243. Nmap scan report for fuhrernet.com (68.81.58.227)
  1244. Host is up (0.086s latency).
  1245. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  1246. Not shown: 473 filtered ports, 6 closed ports
  1247. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  1248. PORT STATE SERVICE
  1249. 21/tcp open ftp
  1250. 80/tcp open http
  1251. 443/tcp open https
  1252. 3306/tcp open mysql
  1253.  
  1254. Nmap done: 1 IP address (1 host up) scanned in 94.47 seconds
  1255. #######################################################################################################################################
  1256. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:55 EDT
  1257. Nmap scan report for fuhrernet.com (68.81.58.227)
  1258. Host is up (0.075s latency).
  1259. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  1260. Not shown: 2 filtered ports
  1261. PORT STATE SERVICE
  1262. 53/udp open|filtered domain
  1263. 67/udp open|filtered dhcps
  1264. 68/udp open|filtered dhcpc
  1265. 69/udp open|filtered tftp
  1266. 88/udp open|filtered kerberos-sec
  1267. 123/udp open|filtered ntp
  1268. 139/udp open|filtered netbios-ssn
  1269. 161/udp open|filtered snmp
  1270. 162/udp open|filtered snmptrap
  1271. 389/udp open|filtered ldap
  1272. 500/udp open|filtered isakmp
  1273. 520/udp open|filtered route
  1274. 2049/udp open|filtered nfs
  1275.  
  1276. Nmap done: 1 IP address (1 host up) scanned in 2.60 seconds
  1277. ######################################################################################################################################
  1278. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:56 EDT
  1279. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  1280. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  1281. NSE: [ftp-brute] passwords: Time limit 3m00s exceeded.
  1282. Nmap scan report for fuhrernet.com (68.81.58.227)
  1283. Host is up (0.079s latency).
  1284. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  1285.  
  1286. PORT STATE SERVICE VERSION
  1287. 21/tcp open ftp FileZilla ftpd 0.9.41 beta
  1288. | ftp-brute:
  1289. | Accounts: No valid accounts found
  1290. |_ Statistics: Performed 2331 guesses in 266 seconds, average tps: 7.9
  1291. | ftp-syst:
  1292. |_ SYST: UNIX emulated by FileZilla
  1293. |_vulscan: ERROR: Script execution failed (use -d to debug)
  1294. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1295. Device type: specialized|general purpose
  1296. Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (87%)
  1297. OS CPE: cpe:/o:freebsd:freebsd:6.2
  1298. Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (87%)
  1299. No exact OS matches for host (test conditions non-ideal).
  1300. Network Distance: 20 hops
  1301. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  1302.  
  1303. TRACEROUTE (using port 21/tcp)
  1304. HOP RTT ADDRESS
  1305. 1 99.30 ms 10.244.204.1
  1306. 2 99.36 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1307. 3 99.34 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  1308. 4 99.34 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  1309. 5 99.34 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  1310. 6 99.36 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  1311. 7 99.36 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  1312. 8 99.38 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  1313. 9 99.39 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  1314. 10 28.53 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
  1315. 11 89.59 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  1316. 12 39.20 ms 66.110.96.130
  1317. 13 39.21 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  1318. 14 39.20 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  1319. 15 39.21 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  1320. 16 39.20 ms 68.86.211.122
  1321. 17 39.19 ms 162.151.182.174
  1322. 18 39.21 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  1323. 19 ...
  1324. 20 59.05 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1325. #######################################################################################################################################
  1326. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 05:01 EDT
  1327. NSE: Loaded 164 scripts for scanning.
  1328. NSE: Script Pre-scanning.
  1329. Initiating NSE at 05:01
  1330. Completed NSE at 05:01, 0.00s elapsed
  1331. Initiating NSE at 05:01
  1332. Completed NSE at 05:01, 0.00s elapsed
  1333. Initiating Parallel DNS resolution of 1 host. at 05:01
  1334. Completed Parallel DNS resolution of 1 host. at 05:01, 0.02s elapsed
  1335. Initiating SYN Stealth Scan at 05:01
  1336. Scanning fuhrernet.com (68.81.58.227) [1 port]
  1337. Discovered open port 80/tcp on 68.81.58.227
  1338. Completed SYN Stealth Scan at 05:01, 0.12s elapsed (1 total ports)
  1339. Initiating Service scan at 05:01
  1340. Scanning 1 service on fuhrernet.com (68.81.58.227)
  1341. Completed Service scan at 05:01, 6.11s elapsed (1 service on 1 host)
  1342. Initiating OS detection (try #1) against fuhrernet.com (68.81.58.227)
  1343. Retrying OS detection (try #2) against fuhrernet.com (68.81.58.227)
  1344. Initiating Traceroute at 05:02
  1345. Completed Traceroute at 05:02, 3.06s elapsed
  1346. Initiating Parallel DNS resolution of 19 hosts. at 05:02
  1347. Completed Parallel DNS resolution of 19 hosts. at 05:02, 0.28s elapsed
  1348. NSE: Script scanning 68.81.58.227.
  1349. Initiating NSE at 05:02
  1350. Completed NSE at 05:02, 46.72s elapsed
  1351. Initiating NSE at 05:02
  1352. Completed NSE at 05:02, 0.99s elapsed
  1353. Nmap scan report for fuhrernet.com (68.81.58.227)
  1354. Host is up (0.12s latency).
  1355. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  1356.  
  1357. PORT STATE SERVICE VERSION
  1358. 80/tcp open http Apache httpd 2.4.25 ((Win32) OpenSSL/1.0.2j PHP/7.1.1)
  1359. | http-brute:
  1360. |_ Path "/" does not require authentication
  1361. |_http-chrono: Request times for /; avg: 631.71ms; min: 466.84ms; max: 786.86ms
  1362. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  1363. |_http-date: Sat, 28 Sep 2019 09:02:07 GMT; -5s from local time.
  1364. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  1365. |_http-dombased-xss: Couldn't find any DOM based XSS.
  1366. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  1367. |_http-errors: Couldn't find any error pages.
  1368. |_http-feed: Couldn't find any feeds.
  1369. |_http-fetch: Please enter the complete path of the directory to save data in.
  1370. | http-headers:
  1371. | Date: Sat, 28 Sep 2019 09:02:03 GMT
  1372. | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1373. | X-Powered-By: PHP/7.1.1
  1374. | Connection: close
  1375. | Content-Type: text/html; charset=UTF-8
  1376. |
  1377. |_ (Request type: HEAD)
  1378. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  1379. |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
  1380. | http-methods:
  1381. |_ Supported Methods: GET HEAD POST OPTIONS
  1382. |_http-mobileversion-checker: No mobile version detected.
  1383. | http-php-version: Logo query returned unknown hash 493264b1ea71e8083a6356206999ff80
  1384. | Credits query returned unknown hash 493264b1ea71e8083a6356206999ff80
  1385. |_Version from header x-powered-by: PHP/7.1.1
  1386. |_http-security-headers:
  1387. |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1388. | http-sitemap-generator:
  1389. | Directory structure:
  1390. | /
  1391. | Other: 1; png: 3; webmanifest: 1
  1392. | /assets/bootstrap/css/
  1393. | css: 1
  1394. | /assets/css/
  1395. | css: 6
  1396. | /assets/fonts/
  1397. | css: 1
  1398. | Longest directory structure:
  1399. | Depth: 3
  1400. | Dir: /assets/bootstrap/css/
  1401. | Total files found (by extension):
  1402. |_ Other: 1; css: 8; png: 3; webmanifest: 1
  1403. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  1404. |_http-title: Newsfeed
  1405. | http-trace: TRACE is enabled
  1406. | Headers:
  1407. | Date: Sat, 28 Sep 2019 09:02:02 GMT
  1408. | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1409. | Connection: close
  1410. | Transfer-Encoding: chunked
  1411. |_Content-Type: message/http
  1412. | http-vhosts:
  1413. |_127 names had status 200
  1414. | http-vuln-cve2010-0738:
  1415. |_ /jmx-console/: Authentication was not required
  1416. |_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
  1417. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
  1418. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  1419. |_http-xssed: No previously reported XSS vuln.
  1420. | vulners:
  1421. | cpe:/a:apache:http_server:2.4.25:
  1422. | CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
  1423. | CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
  1424. | CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
  1425. | CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
  1426. | CVE-2019-0211 7.2 https://vulners.com/cve/CVE-2019-0211
  1427. | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
  1428. | CVE-2017-15715 6.8 https://vulners.com/cve/CVE-2017-15715
  1429. | CVE-2019-10082 6.4 https://vulners.com/cve/CVE-2019-10082
  1430. | CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
  1431. | CVE-2019-10098 5.8 https://vulners.com/cve/CVE-2019-10098
  1432. | CVE-2019-10081 5.0 https://vulners.com/cve/CVE-2019-10081
  1433. | CVE-2019-0220 5.0 https://vulners.com/cve/CVE-2019-0220
  1434. | CVE-2019-0196 5.0 https://vulners.com/cve/CVE-2019-0196
  1435. | CVE-2018-17199 5.0 https://vulners.com/cve/CVE-2018-17199
  1436. | CVE-2018-1333 5.0 https://vulners.com/cve/CVE-2018-1333
  1437. | CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
  1438. | CVE-2017-7659 5.0 https://vulners.com/cve/CVE-2017-7659
  1439. | CVE-2017-15710 5.0 https://vulners.com/cve/CVE-2017-15710
  1440. | CVE-2019-0197 4.9 https://vulners.com/cve/CVE-2019-0197
  1441. | CVE-2019-10092 4.3 https://vulners.com/cve/CVE-2019-10092
  1442. | CVE-2018-11763 4.3 https://vulners.com/cve/CVE-2018-11763
  1443. |_ CVE-2018-1283 3.5 https://vulners.com/cve/CVE-2018-1283
  1444. |_vulscan: ERROR: Script execution failed (use -d to debug)
  1445. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1446. Device type: general purpose|specialized
  1447. Running (JUST GUESSING): FreeBSD 6.X (87%), AVtech embedded (85%)
  1448. OS CPE: cpe:/o:freebsd:freebsd:6.2
  1449. Aggressive OS guesses: FreeBSD 6.2-RELEASE (87%), AVtech Room Alert 26W environmental monitor (85%)
  1450. No exact OS matches for host (test conditions non-ideal).
  1451. Network Distance: 20 hops
  1452. TCP Sequence Prediction: Difficulty=261 (Good luck!)
  1453. IP ID Sequence Generation: Incremental
  1454.  
  1455. TRACEROUTE (using port 80/tcp)
  1456. HOP RTT ADDRESS
  1457. 1 49.76 ms 10.244.204.1
  1458. 2 49.85 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1459. 3 49.89 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  1460. 4 49.85 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  1461. 5 49.87 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  1462. 6 50.00 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  1463. 7 49.94 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  1464. 8 49.99 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  1465. 9 49.98 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  1466. 10 30.01 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
  1467. 11 47.74 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  1468. 12 58.68 ms 66.110.96.138
  1469. 13 79.05 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  1470. 14 78.96 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  1471. 15 79.07 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  1472. 16 79.03 ms 68.86.211.122
  1473. 17 78.98 ms 162.151.182.174
  1474. 18 79.07 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  1475. 19 ...
  1476. 20 105.13 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1477.  
  1478. NSE: Script Post-scanning.
  1479. Initiating NSE at 05:02
  1480. Completed NSE at 05:02, 0.00s elapsed
  1481. Initiating NSE at 05:02
  1482. Completed NSE at 05:02, 0.00s elapsed
  1483. #######################################################################################################################################
  1484. http://fuhrernet.com [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], Meta-Refresh-Redirect[./login.php], Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], Script, Title[Newsfeed], X-Powered-By[PHP/7.1.1]
  1485. http://fuhrernet.com/login.php [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], JQuery, Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], PasswordField[password], Script[text/javascript], Title[Login to Führernet], X-Powered-By[PHP/7.1.1]
  1486. #######################################################################################################################################
  1487.  
  1488. wig - WebApp Information Gatherer
  1489.  
  1490.  
  1491. Scanning http://fuhrernet.com...
  1492. ____________________ SITE INFO ____________________
  1493. IP Title
  1494. 68.81.58.227 Newsfeed
  1495.  
  1496. _____________________ VERSION _____________________
  1497. Name Versions Type
  1498. Apache 2.4.25 Platform
  1499. PHP 7.1.1 Platform
  1500. openssl 1.0.2j Platform
  1501. FreeBSD 10 | 11 OS
  1502. openSUSE tumbleweed OS
  1503.  
  1504. ___________________ INTERESTING ___________________
  1505. URL Note Type
  1506. /test.html Test file Interesting
  1507. /login.php Login Page Interesting
  1508. /phpinfo.php PHP info file Interesting
  1509. /test/ Test directory Interesting
  1510.  
  1511. ___________________________________________________
  1512. Time: 60.2 sec Urls: 846 Fingerprints: 40401
  1513. #######################################################################################################################################
  1514. HTTP/1.1 200 OK
  1515. Date: Sat, 28 Sep 2019 09:04:00 GMT
  1516. Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1517. X-Powered-By: PHP/7.1.1
  1518. Content-Type: text/html; charset=UTF-8
  1519.  
  1520. HTTP/1.1 200 OK
  1521. Date: Sat, 28 Sep 2019 09:04:00 GMT
  1522. Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1523. X-Powered-By: PHP/7.1.1
  1524. Content-Type: text/html; charset=UTF-8
  1525. ######################################################################################################################################
  1526. ------------------------------------------------------------------------------------------------------------------------
  1527.  
  1528. [ ! ] Starting SCANNER INURLBR 2.1 at [28-09-2019 05:04:26]
  1529. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  1530. It is the end user's responsibility to obey all applicable local, state and federal laws.
  1531. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  1532.  
  1533. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
  1534. [ INFO ][ DORK ]::[ site:fuhrernet.com ]
  1535. [ INFO ][ SEARCHING ]:: {
  1536. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.nu ]
  1537.  
  1538. [ INFO ][ SEARCHING ]::
  1539. -[:::]
  1540. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  1541.  
  1542. [ INFO ][ SEARCHING ]::
  1543. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1544. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.mv ID: 012873187529719969291:yexdhbzntue ]
  1545.  
  1546. [ INFO ][ SEARCHING ]::
  1547. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1548.  
  1549. [ INFO ][ TOTAL FOUND VALUES ]:: [ 4 ]
  1550.  
  1551.  
  1552. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1553. |_[ + ] [ 0 / 4 ]-[05:04:41] [ - ]
  1554. |_[ + ] Target:: [ http://fuhrernet.com/ ]
  1555. |_[ + ] Exploit::
  1556. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
  1557. |_[ + ] More details:: / - / , ISP:
  1558. |_[ + ] Found:: UNIDENTIFIED
  1559.  
  1560. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1561. |_[ + ] [ 1 / 4 ]-[05:04:42] [ - ]
  1562. |_[ + ] Target:: [ http://fuhrernet.com/forgot-username.html ]
  1563. |_[ + ] Exploit::
  1564. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
  1565. |_[ + ] More details:: / - / , ISP:
  1566. |_[ + ] Found:: UNIDENTIFIED
  1567.  
  1568. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1569. |_[ + ] [ 2 / 4 ]-[05:04:43] [ - ]
  1570. |_[ + ] Target:: [ http://www.fuhrernet.com/forgot-password.html ]
  1571. |_[ + ] Exploit::
  1572. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
  1573. |_[ + ] More details:: / - / , ISP:
  1574. |_[ + ] Found:: UNIDENTIFIED
  1575.  
  1576. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1577. |_[ + ] [ 3 / 4 ]-[05:04:44] [ - ]
  1578. |_[ + ] Target:: [ http://www.fuhrernet.com/create-account.php ]
  1579. |_[ + ] Exploit::
  1580. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
  1581. |_[ + ] More details:: / - / , ISP:
  1582. |_[ + ] Found:: UNIDENTIFIED
  1583.  
  1584. [ INFO ] [ Shutting down ]
  1585. [ INFO ] [ End of process INURLBR at [28-09-2019 05:04:44]
  1586. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  1587. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
  1588. |_________________________________________________________________________________________
  1589.  
  1590. \_________________________________________________________________________________________/
  1591. #######################################################################################################################################
  1592. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 05:04 EDT
  1593. NSE: Loaded 164 scripts for scanning.
  1594. NSE: Script Pre-scanning.
  1595. Initiating NSE at 05:04
  1596. Completed NSE at 05:04, 0.00s elapsed
  1597. Initiating NSE at 05:04
  1598. Completed NSE at 05:04, 0.00s elapsed
  1599. Initiating Parallel DNS resolution of 1 host. at 05:04
  1600. Completed Parallel DNS resolution of 1 host. at 05:04, 0.02s elapsed
  1601. Initiating SYN Stealth Scan at 05:04
  1602. Scanning fuhrernet.com (68.81.58.227) [1 port]
  1603. Completed SYN Stealth Scan at 05:04, 0.54s elapsed (1 total ports)
  1604. Initiating Service scan at 05:04
  1605. Initiating OS detection (try #1) against fuhrernet.com (68.81.58.227)
  1606. Retrying OS detection (try #2) against fuhrernet.com (68.81.58.227)
  1607. Initiating Traceroute at 05:04
  1608. Completed Traceroute at 05:04, 0.13s elapsed
  1609. Initiating Parallel DNS resolution of 19 hosts. at 05:04
  1610. Completed Parallel DNS resolution of 19 hosts. at 05:04, 0.15s elapsed
  1611. NSE: Script scanning 68.81.58.227.
  1612. Initiating NSE at 05:04
  1613. Completed NSE at 05:04, 0.22s elapsed
  1614. Initiating NSE at 05:04
  1615. Completed NSE at 05:04, 0.00s elapsed
  1616. Nmap scan report for fuhrernet.com (68.81.58.227)
  1617. Host is up (0.048s latency).
  1618. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  1619.  
  1620. PORT STATE SERVICE VERSION
  1621. 443/tcp filtered https
  1622. Too many fingerprints match this host to give specific OS details
  1623. Network Distance: 19 hops
  1624.  
  1625. TRACEROUTE (using proto 1/icmp)
  1626. HOP RTT ADDRESS
  1627. 1 49.76 ms 10.244.204.1
  1628. 2 49.81 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1629. 3 69.35 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  1630. 4 49.83 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  1631. 5 49.85 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  1632. 6 49.87 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  1633. 7 49.88 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  1634. 8 49.90 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  1635. 9 49.91 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  1636. 10 28.97 ms if-ae-7-2.tcore1.nto-new-york.as6453.net (63.243.128.25)
  1637. 11 59.56 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  1638. 12 59.29 ms 66.110.96.146
  1639. 13 59.33 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  1640. 14 59.29 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  1641. 15 59.32 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  1642. 16 59.34 ms 68.86.211.122
  1643. 17 59.29 ms 162.151.182.174
  1644. 18 59.32 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  1645. 19 78.99 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1646.  
  1647. NSE: Script Post-scanning.
  1648. Initiating NSE at 05:04
  1649. Completed NSE at 05:04, 0.00s elapsed
  1650. Initiating NSE at 05:04
  1651. Completed NSE at 05:04, 0.00s elapsed
  1652. #######################################################################################################################################
  1653. Version: 1.11.13-static
  1654. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  1655.  
  1656. Connected to 68.81.58.227
  1657.  
  1658. Testing SSL server fuhrernet.com on port 443 using SNI name fuhrernet.com
  1659.  
  1660. TLS Fallback SCSV:
  1661. Server supports TLS Fallback SCSV
  1662.  
  1663. TLS renegotiation:
  1664. Secure session renegotiation supported
  1665.  
  1666. TLS Compression:
  1667. Compression disabled
  1668.  
  1669. Heartbleed:
  1670. TLS 1.2 not vulnerable to heartbleed
  1671. TLS 1.1 not vulnerable to heartbleed
  1672. TLS 1.0 not vulnerable to heartbleed
  1673.  
  1674. Supported Server Cipher(s):
  1675. Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
  1676. Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  1677. Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
  1678. Accepted TLSv1.1 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
  1679. Accepted TLSv1.1 256 bits AES256-SHA
  1680. Accepted TLSv1.1 256 bits CAMELLIA256-SHA
  1681. Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  1682. Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
  1683. Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  1684. Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
  1685. Accepted TLSv1.0 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
  1686. Accepted TLSv1.0 256 bits AES256-SHA
  1687. Accepted TLSv1.0 256 bits CAMELLIA256-SHA
  1688. Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  1689. Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
  1690. Accepted TLSv1.0 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
  1691. Accepted TLSv1.0 128 bits AES128-SHA
  1692. Accepted TLSv1.0 128 bits CAMELLIA128-SHA
  1693. Accepted TLSv1.0 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
  1694. Accepted TLSv1.0 128 bits SEED-SHA
  1695. Accepted TLSv1.0 128 bits IDEA-CBC-SHA
  1696. Accepted TLSv1.0 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
  1697. Accepted TLSv1.0 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
  1698. Accepted TLSv1.0 112 bits DES-CBC3-SHA
  1699.  
  1700. SSL Certificate:
  1701. Signature Algorithm: sha1WithRSAEncryption
  1702. RSA Key Strength: 1024
  1703.  
  1704. Subject: localhost
  1705. Issuer: localhost
  1706.  
  1707. Not valid before: Nov 10 23:48:47 2009 GMT
  1708. Not valid after: Nov 8 23:48:47 2019 GMT
  1709. ######################################################################################################################################
  1710. ------------------------------------------------------------------------------------------------------------------------
  1711.  
  1712. [ ! ] Starting SCANNER INURLBR 2.1 at [28-09-2019 05:09:05]
  1713. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  1714. It is the end user's responsibility to obey all applicable local, state and federal laws.
  1715. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  1716.  
  1717. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
  1718. [ INFO ][ DORK ]::[ site:fuhrernet.com ]
  1719. [ INFO ][ SEARCHING ]:: {
  1720. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.cv ]
  1721.  
  1722. [ INFO ][ SEARCHING ]::
  1723. -[:::]
  1724. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  1725.  
  1726. [ INFO ][ SEARCHING ]::
  1727. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1728. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.ro ID: 010479943387663786936:wjwf2xkhfmq ]
  1729.  
  1730. [ INFO ][ SEARCHING ]::
  1731. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1732.  
  1733. [ INFO ][ TOTAL FOUND VALUES ]:: [ 4 ]
  1734.  
  1735.  
  1736. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1737. |_[ + ] [ 0 / 4 ]-[05:09:18] [ - ]
  1738. |_[ + ] Target:: [ http://fuhrernet.com/ ]
  1739. |_[ + ] Exploit::
  1740. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
  1741. |_[ + ] More details:: / - / , ISP:
  1742. |_[ + ] Found:: UNIDENTIFIED
  1743.  
  1744. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1745. |_[ + ] [ 1 / 4 ]-[05:09:18] [ - ]
  1746. |_[ + ] Target:: [ http://fuhrernet.com/forgot-username.html ]
  1747. |_[ + ] Exploit::
  1748. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
  1749. |_[ + ] More details:: / - / , ISP:
  1750. |_[ + ] Found:: UNIDENTIFIED
  1751.  
  1752. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1753. |_[ + ] [ 2 / 4 ]-[05:09:19] [ - ]
  1754. |_[ + ] Target:: [ http://www.fuhrernet.com/forgot-password.html ]
  1755. |_[ + ] Exploit::
  1756. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
  1757. |_[ + ] More details:: / - / , ISP:
  1758. |_[ + ] Found:: UNIDENTIFIED
  1759.  
  1760. _[ - ]::--------------------------------------------------------------------------------------------------------------
  1761. |_[ + ] [ 3 / 4 ]-[05:09:20] [ - ]
  1762. |_[ + ] Target:: [ http://www.fuhrernet.com/create-account.php ]
  1763. |_[ + ] Exploit::
  1764. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
  1765. |_[ + ] More details:: / - / , ISP:
  1766. |_[ + ] Found:: UNIDENTIFIED
  1767.  
  1768. [ INFO ] [ Shutting down ]
  1769. [ INFO ] [ End of process INURLBR at [28-09-2019 05:09:20]
  1770. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  1771. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
  1772. |_________________________________________________________________________________________
  1773.  
  1774. \_________________________________________________________________________________________/
  1775. #######################################################################################################################################
  1776. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 05:09 EDT
  1777. Nmap scan report for fuhrernet.com (68.81.58.227)
  1778. Host is up (0.16s latency).
  1779. rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
  1780.  
  1781. PORT STATE SERVICE VERSION
  1782. 3306/tcp open mysql MariaDB (unauthorized)
  1783. | mysql-brute:
  1784. | Accounts: No valid accounts found
  1785. |_ Statistics: Performed 42 guesses in 112 seconds, average tps: 0.4
  1786. |_mysql-empty-password: Host '176.113.74.60' is not allowed to connect to this MariaDB server
  1787. | mysql-enum:
  1788. | Accounts: No valid accounts found
  1789. |_ Statistics: Performed 5 guesses in 9 seconds, average tps: 0.6
  1790. |_mysql-vuln-cve2012-2122: ERROR: Script execution failed (use -d to debug)
  1791. |_vulscan: ERROR: Script execution failed (use -d to debug)
  1792. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1793. Device type: specialized|general purpose
  1794. Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (85%)
  1795. OS CPE: cpe:/o:freebsd:freebsd:6.2
  1796. Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (85%)
  1797. No exact OS matches for host (test conditions non-ideal).
  1798. Network Distance: 20 hops
  1799.  
  1800. TRACEROUTE (using port 3306/tcp)
  1801. HOP RTT ADDRESS
  1802. 1 39.72 ms 10.244.204.1
  1803. 2 39.81 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1804. 3 39.87 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  1805. 4 39.86 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  1806. 5 39.83 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  1807. 6 40.05 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  1808. 7 39.96 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  1809. 8 40.00 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  1810. 9 40.08 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  1811. 10 40.10 ms if-ae-7-2.tcore1.nto-new-york.as6453.net (63.243.128.25)
  1812. 11 89.63 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  1813. 12 150.76 ms 66.110.96.138
  1814. 13 150.83 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  1815. 14 150.78 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  1816. 15 150.81 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  1817. 16 150.77 ms 68.86.211.122
  1818. 17 150.72 ms 162.151.182.174
  1819. 18 150.78 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  1820. 19 ...
  1821. 20 150.77 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1822.  
  1823. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  1824. Nmap done: 1 IP address (1 host up) scanned in 122.77 seconds
  1825. #######################################################################################################################################
  1826. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:44 EDT
  1827. Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1828. Host is up (0.059s latency).
  1829. Not shown: 473 filtered ports, 6 closed ports
  1830. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  1831. PORT STATE SERVICE
  1832. 21/tcp open ftp
  1833. 80/tcp open http
  1834. 443/tcp open https
  1835. 3306/tcp open mysql
  1836.  
  1837. Nmap done: 1 IP address (1 host up) scanned in 61.34 seconds
  1838. #######################################################################################################################################
  1839. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:45 EDT
  1840. Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1841. Host is up (0.036s latency).
  1842. Not shown: 2 filtered ports
  1843. PORT STATE SERVICE
  1844. 53/udp open|filtered domain
  1845. 67/udp open|filtered dhcps
  1846. 68/udp open|filtered dhcpc
  1847. 69/udp open|filtered tftp
  1848. 88/udp open|filtered kerberos-sec
  1849. 123/udp open|filtered ntp
  1850. 139/udp open|filtered netbios-ssn
  1851. 161/udp open|filtered snmp
  1852. 162/udp open|filtered snmptrap
  1853. 389/udp open|filtered ldap
  1854. 500/udp open|filtered isakmp
  1855. 520/udp open|filtered route
  1856. 2049/udp open|filtered nfs
  1857.  
  1858. Nmap done: 1 IP address (1 host up) scanned in 1.78 seconds
  1859. #######################################################################################################################################
  1860. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:45 EDT
  1861. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  1862. NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
  1863. NSE: [ftp-brute] passwords: Time limit 3m00s exceeded.
  1864. Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1865. Host is up (0.085s latency).
  1866.  
  1867. PORT STATE SERVICE VERSION
  1868. 21/tcp open ftp FileZilla ftpd 0.9.41 beta
  1869. | ftp-brute:
  1870. | Accounts: No valid accounts found
  1871. |_ Statistics: Performed 247 guesses in 181 seconds, average tps: 1.6
  1872. | ftp-syst:
  1873. |_ SYST: UNIX emulated by FileZilla
  1874. |_vulscan: ERROR: Script execution failed (use -d to debug)
  1875. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1876. Device type: specialized|general purpose
  1877. Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (87%)
  1878. OS CPE: cpe:/o:freebsd:freebsd:6.2
  1879. Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (87%)
  1880. No exact OS matches for host (test conditions non-ideal).
  1881. Network Distance: 20 hops
  1882. Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  1883.  
  1884. TRACEROUTE (using port 21/tcp)
  1885. HOP RTT ADDRESS
  1886. 1 31.52 ms 10.244.204.1
  1887. 2 61.24 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  1888. 3 61.37 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  1889. 4 61.22 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  1890. 5 61.29 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  1891. 6 61.39 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  1892. 7 61.35 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  1893. 8 61.45 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  1894. 9 61.37 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  1895. 10 61.47 ms if-ae-7-2.tcore1.nto-new-york.as6453.net (63.243.128.25)
  1896. 11 50.11 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  1897. 12 40.11 ms 66.110.96.150
  1898. 13 59.79 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  1899. 14 59.81 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  1900. 15 59.82 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  1901. 16 59.81 ms 68.86.211.122
  1902. 17 59.80 ms 162.151.182.174
  1903. 18 59.81 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  1904. 19 ...
  1905. 20 79.65 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1906. #######################################################################################################################################
  1907. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:49 EDT
  1908. NSE: Loaded 164 scripts for scanning.
  1909. NSE: Script Pre-scanning.
  1910. Initiating NSE at 04:49
  1911. Completed NSE at 04:49, 0.00s elapsed
  1912. Initiating NSE at 04:49
  1913. Completed NSE at 04:49, 0.00s elapsed
  1914. Initiating Parallel DNS resolution of 1 host. at 04:49
  1915. Completed Parallel DNS resolution of 1 host. at 04:49, 0.03s elapsed
  1916. Initiating SYN Stealth Scan at 04:49
  1917. Scanning c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227) [1 port]
  1918. Discovered open port 80/tcp on 68.81.58.227
  1919. Completed SYN Stealth Scan at 04:49, 0.10s elapsed (1 total ports)
  1920. Initiating Service scan at 04:49
  1921. Scanning 1 service on c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1922. Completed Service scan at 04:49, 6.11s elapsed (1 service on 1 host)
  1923. Initiating OS detection (try #1) against c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1924. Retrying OS detection (try #2) against c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1925. Initiating Traceroute at 04:49
  1926. Completed Traceroute at 04:49, 3.09s elapsed
  1927. Initiating Parallel DNS resolution of 19 hosts. at 04:49
  1928. Completed Parallel DNS resolution of 19 hosts. at 04:49, 0.27s elapsed
  1929. NSE: Script scanning 68.81.58.227.
  1930. Initiating NSE at 04:49
  1931. Completed NSE at 04:49, 26.57s elapsed
  1932. Initiating NSE at 04:49
  1933. Completed NSE at 04:49, 0.39s elapsed
  1934. Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  1935. Host is up (0.091s latency).
  1936.  
  1937. PORT STATE SERVICE VERSION
  1938. 80/tcp open http Apache httpd 2.4.25 ((Win32) OpenSSL/1.0.2j PHP/7.1.1)
  1939. | http-brute:
  1940. |_ Path "/" does not require authentication
  1941. |_http-chrono: Request times for /; avg: 432.70ms; min: 312.10ms; max: 583.81ms
  1942. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  1943. |_http-date: Sat, 28 Sep 2019 08:49:28 GMT; -5s from local time.
  1944. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  1945. |_http-dombased-xss: Couldn't find any DOM based XSS.
  1946. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  1947. |_http-errors: Couldn't find any error pages.
  1948. |_http-feed: Couldn't find any feeds.
  1949. |_http-fetch: Please enter the complete path of the directory to save data in.
  1950. | http-headers:
  1951. | Date: Sat, 28 Sep 2019 08:49:26 GMT
  1952. | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1953. | X-Powered-By: PHP/7.1.1
  1954. | Connection: close
  1955. | Content-Type: text/html; charset=UTF-8
  1956. |
  1957. |_ (Request type: HEAD)
  1958. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  1959. |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
  1960. | http-methods:
  1961. |_ Supported Methods: GET HEAD POST OPTIONS
  1962. |_http-mobileversion-checker: No mobile version detected.
  1963. | http-php-version: Logo query returned unknown hash 493264b1ea71e8083a6356206999ff80
  1964. | Credits query returned unknown hash 493264b1ea71e8083a6356206999ff80
  1965. |_Version from header x-powered-by: PHP/7.1.1
  1966. |_http-security-headers:
  1967. |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1968. | http-sitemap-generator:
  1969. | Directory structure:
  1970. | /
  1971. | Other: 1; png: 3; webmanifest: 1
  1972. | /assets/bootstrap/css/
  1973. | css: 1
  1974. | /assets/css/
  1975. | css: 6
  1976. | /assets/fonts/
  1977. | css: 1
  1978. | Longest directory structure:
  1979. | Depth: 3
  1980. | Dir: /assets/bootstrap/css/
  1981. | Total files found (by extension):
  1982. |_ Other: 1; css: 8; png: 3; webmanifest: 1
  1983. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  1984. |_http-title: Newsfeed
  1985. | http-trace: TRACE is enabled
  1986. | Headers:
  1987. | Date: Sat, 28 Sep 2019 08:49:29 GMT
  1988. | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  1989. | Connection: close
  1990. | Transfer-Encoding: chunked
  1991. |_Content-Type: message/http
  1992. | http-vhosts:
  1993. |_127 names had status 200
  1994. | http-vuln-cve2010-0738:
  1995. |_ /jmx-console/: Authentication was not required
  1996. |_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
  1997. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
  1998. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  1999. |_http-xssed: No previously reported XSS vuln.
  2000. | vulners:
  2001. | cpe:/a:apache:http_server:2.4.25:
  2002. | CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
  2003. | CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
  2004. | CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
  2005. | CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
  2006. | CVE-2019-0211 7.2 https://vulners.com/cve/CVE-2019-0211
  2007. | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
  2008. | CVE-2017-15715 6.8 https://vulners.com/cve/CVE-2017-15715
  2009. | CVE-2019-10082 6.4 https://vulners.com/cve/CVE-2019-10082
  2010. | CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
  2011. | CVE-2019-10098 5.8 https://vulners.com/cve/CVE-2019-10098
  2012. | CVE-2019-10081 5.0 https://vulners.com/cve/CVE-2019-10081
  2013. | CVE-2019-0220 5.0 https://vulners.com/cve/CVE-2019-0220
  2014. | CVE-2019-0196 5.0 https://vulners.com/cve/CVE-2019-0196
  2015. | CVE-2018-17199 5.0 https://vulners.com/cve/CVE-2018-17199
  2016. | CVE-2018-1333 5.0 https://vulners.com/cve/CVE-2018-1333
  2017. | CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
  2018. | CVE-2017-7659 5.0 https://vulners.com/cve/CVE-2017-7659
  2019. | CVE-2017-15710 5.0 https://vulners.com/cve/CVE-2017-15710
  2020. | CVE-2019-0197 4.9 https://vulners.com/cve/CVE-2019-0197
  2021. | CVE-2019-10092 4.3 https://vulners.com/cve/CVE-2019-10092
  2022. | CVE-2018-11763 4.3 https://vulners.com/cve/CVE-2018-11763
  2023. |_ CVE-2018-1283 3.5 https://vulners.com/cve/CVE-2018-1283
  2024. |_vulscan: ERROR: Script execution failed (use -d to debug)
  2025. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  2026. Device type: specialized|general purpose
  2027. Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (87%)
  2028. OS CPE: cpe:/o:freebsd:freebsd:6.2
  2029. Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (87%)
  2030. No exact OS matches for host (test conditions non-ideal).
  2031. Network Distance: 20 hops
  2032. TCP Sequence Prediction: Difficulty=258 (Good luck!)
  2033. IP ID Sequence Generation: Incremental
  2034.  
  2035. TRACEROUTE (using port 80/tcp)
  2036. HOP RTT ADDRESS
  2037. 1 51.19 ms 10.244.204.1
  2038. 2 71.05 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  2039. 3 71.06 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  2040. 4 71.04 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  2041. 5 71.06 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  2042. 6 71.11 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  2043. 7 71.11 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  2044. 8 71.15 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  2045. 9 71.14 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  2046. 10 29.99 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
  2047. 11 60.35 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  2048. 12 50.40 ms 66.110.96.146
  2049. 13 49.87 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  2050. 14 49.88 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  2051. 15 49.90 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  2052. 16 49.91 ms 68.86.211.122
  2053. 17 49.88 ms 162.151.182.174
  2054. 18 49.92 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  2055. 19 ...
  2056. 20 69.70 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  2057.  
  2058. NSE: Script Post-scanning.
  2059. Initiating NSE at 04:49
  2060. Completed NSE at 04:49, 0.00s elapsed
  2061. Initiating NSE at 04:49
  2062. Completed NSE at 04:49, 0.00s elapsed
  2063. #######################################################################################################################################
  2064. http://68.81.58.227 [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], Meta-Refresh-Redirect[./login.php], Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], Script, Title[Newsfeed], X-Powered-By[PHP/7.1.1]
  2065. http://68.81.58.227/login.php [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], JQuery, Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], PasswordField[password], Script[text/javascript], Title[Login to Führernet], X-Powered-By[PHP/7.1.1]
  2066. #######################################################################################################################################
  2067.  
  2068. wig - WebApp Information Gatherer
  2069.  
  2070.  
  2071. Scanning http://68.81.58.227...
  2072. ____________________ SITE INFO ____________________
  2073. IP Title
  2074. 68.81.58.227 Newsfeed
  2075.  
  2076. _____________________ VERSION _____________________
  2077. Name Versions Type
  2078. Apache 2.4.25 Platform
  2079. PHP 7.1.1 Platform
  2080. openssl 1.0.2j Platform
  2081. FreeBSD 10 | 11 OS
  2082. openSUSE tumbleweed OS
  2083.  
  2084. ___________________ INTERESTING ___________________
  2085. URL Note Type
  2086. /test.html Test file Interesting
  2087. /login.php Login Page Interesting
  2088. /phpinfo.php PHP info file Interesting
  2089. /test/ Test directory Interesting
  2090.  
  2091. ___________________________________________________
  2092. Time: 29.6 sec Urls: 846 Fingerprints: 40401
  2093. #######################################################################################################################################
  2094. HTTP/1.1 200 OK
  2095. Date: Sat, 28 Sep 2019 08:50:27 GMT
  2096. Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  2097. X-Powered-By: PHP/7.1.1
  2098. Content-Type: text/html; charset=UTF-8
  2099.  
  2100. HTTP/1.1 200 OK
  2101. Date: Sat, 28 Sep 2019 08:50:27 GMT
  2102. Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
  2103. X-Powered-By: PHP/7.1.1
  2104. Content-Type: text/html; charset=UTF-8
  2105. #######################################################################################################################################
  2106. https://68.81.58.227 [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], Meta-Refresh-Redirect[./login.php], Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], Script, Title[Newsfeed], X-Powered-By[PHP/7.1.1]
  2107. https://68.81.58.227/login.php [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], JQuery, Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], PasswordField[password], Script[text/javascript], Title[Login to Führernet], X-Powered-By[PHP/7.1.1]
  2108. #######################################################################################################################################
  2109. Version: 1.11.13-static
  2110. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  2111.  
  2112. Connected to 68.81.58.227
  2113.  
  2114. Testing SSL server 68.81.58.227 on port 443 using SNI name 68.81.58.227
  2115.  
  2116. TLS Fallback SCSV:
  2117. Server supports TLS Fallback SCSV
  2118.  
  2119. TLS renegotiation:
  2120. Secure session renegotiation supported
  2121.  
  2122. TLS Compression:
  2123. Compression disabled
  2124.  
  2125. Heartbleed:
  2126. TLS 1.2 not vulnerable to heartbleed
  2127. TLS 1.1 not vulnerable to heartbleed
  2128. TLS 1.0 not vulnerable to heartbleed
  2129.  
  2130. Supported Server Cipher(s):
  2131. Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
  2132. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
  2133. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  2134. Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384 DHE 1024 bits
  2135. Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA256 DHE 1024 bits
  2136. Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
  2137. Accepted TLSv1.2 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
  2138. Accepted TLSv1.2 256 bits AES256-GCM-SHA384
  2139. Accepted TLSv1.2 256 bits AES256-SHA256
  2140. Accepted TLSv1.2 256 bits AES256-SHA
  2141. Accepted TLSv1.2 256 bits CAMELLIA256-SHA
  2142. Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-GCM-SHA256 Curve P-256 DHE 256
  2143. Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
  2144. Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  2145. Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256 DHE 1024 bits
  2146. Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA256 DHE 1024 bits
  2147. Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
  2148. Accepted TLSv1.2 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
  2149. Accepted TLSv1.2 128 bits AES128-GCM-SHA256
  2150. Accepted TLSv1.2 128 bits AES128-SHA256
  2151. Accepted TLSv1.2 128 bits AES128-SHA
  2152. Accepted TLSv1.2 128 bits CAMELLIA128-SHA
  2153. Accepted TLSv1.2 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
  2154. Accepted TLSv1.2 128 bits SEED-SHA
  2155. Accepted TLSv1.2 128 bits IDEA-CBC-SHA
  2156. Accepted TLSv1.2 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
  2157. Accepted TLSv1.2 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
  2158. Accepted TLSv1.2 112 bits DES-CBC3-SHA
  2159. Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  2160. Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
  2161. Accepted TLSv1.1 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
  2162. Accepted TLSv1.1 256 bits AES256-SHA
  2163. Accepted TLSv1.1 256 bits CAMELLIA256-SHA
  2164. Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  2165. Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
  2166. Accepted TLSv1.1 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
  2167. Accepted TLSv1.1 128 bits AES128-SHA
  2168. Accepted TLSv1.1 128 bits CAMELLIA128-SHA
  2169. Accepted TLSv1.1 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
  2170. Accepted TLSv1.1 128 bits SEED-SHA
  2171. Accepted TLSv1.1 128 bits IDEA-CBC-SHA
  2172. Accepted TLSv1.1 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
  2173. Accepted TLSv1.1 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
  2174. Accepted TLSv1.1 112 bits DES-CBC3-SHA
  2175. Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  2176. Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
  2177. Accepted TLSv1.0 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
  2178. Accepted TLSv1.0 256 bits AES256-SHA
  2179. Accepted TLSv1.0 256 bits CAMELLIA256-SHA
  2180. Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  2181. Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
  2182. Accepted TLSv1.0 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
  2183. Accepted TLSv1.0 128 bits AES128-SHA
  2184. Accepted TLSv1.0 128 bits CAMELLIA128-SHA
  2185. Accepted TLSv1.0 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
  2186. Accepted TLSv1.0 128 bits SEED-SHA
  2187. Accepted TLSv1.0 128 bits IDEA-CBC-SHA
  2188. Accepted TLSv1.0 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
  2189. Accepted TLSv1.0 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
  2190. Accepted TLSv1.0 112 bits DES-CBC3-SHA
  2191.  
  2192. SSL Certificate:
  2193. Signature Algorithm: sha1WithRSAEncryption
  2194. RSA Key Strength: 1024
  2195.  
  2196. Subject: localhost
  2197. Issuer: localhost
  2198.  
  2199. Not valid before: Nov 10 23:48:47 2009 GMT
  2200. Not valid after: Nov 8 23:48:47 2019 GMT
  2201. #######################################################################################################################################
  2202. Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:51 EDT
  2203. Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  2204. Host is up (0.077s latency).
  2205.  
  2206. PORT STATE SERVICE VERSION
  2207. 3306/tcp open mysql MariaDB (unauthorized)
  2208. | mysql-brute:
  2209. | Accounts: No valid accounts found
  2210. |_ Statistics: Performed 9415 guesses in 244 seconds, average tps: 60.1
  2211. |_mysql-empty-password: Host '176.113.74.60' is not allowed to connect to this MariaDB server
  2212. | mysql-enum:
  2213. | Accounts: No valid accounts found
  2214. |_ Statistics: Performed 10 guesses in 1 seconds, average tps: 10.0
  2215. |_mysql-vuln-cve2012-2122: ERROR: Script execution failed (use -d to debug)
  2216. |_vulscan: ERROR: Script execution failed (use -d to debug)
  2217. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  2218. Device type: general purpose|router
  2219. Running (JUST GUESSING): FreeBSD 6.X (87%), Linksys embedded (86%)
  2220. OS CPE: cpe:/o:freebsd:freebsd:6.2
  2221. Aggressive OS guesses: FreeBSD 6.2-RELEASE (87%), Linksys BEFSR41 EtherFast router (86%)
  2222. No exact OS matches for host (test conditions non-ideal).
  2223. Network Distance: 20 hops
  2224.  
  2225. TRACEROUTE (using port 3306/tcp)
  2226. HOP RTT ADDRESS
  2227. 1 49.43 ms 10.244.204.1
  2228. 2 69.07 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
  2229. 3 69.10 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
  2230. 4 69.04 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
  2231. 5 69.08 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
  2232. 6 69.17 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
  2233. 7 69.16 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
  2234. 8 69.20 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
  2235. 9 69.16 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
  2236. 10 29.39 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
  2237. 11 58.46 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
  2238. 12 58.44 ms 66.110.96.150
  2239. 13 58.31 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
  2240. 14 58.31 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
  2241. 15 58.28 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
  2242. 16 58.31 ms 68.86.211.122
  2243. 17 58.19 ms 162.151.182.174
  2244. 18 58.31 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
  2245. 19 ...
  2246. 20 78.05 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
  2247. #######################################################################################################################################
  2248. Anonymous JTSEC #OpDomesticTerrorism Full Recon #3
Advertisement
Add Comment
Please, Sign In to add comment