Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #######################################################################################################################################
- =======================================================================================================================================
- Hostname fuhrernet.com ISP Comcast Cable Communications, LLC
- Continent North America Flag
- US
- Country United States Country Code US
- Region Pennsylvania Local time 28 Sep 2019 04:16 EDT
- City Levittown Postal Code 19056
- IP Address 68.81.58.227 Latitude 40.152
- Longitude -74.883
- =======================================================================================================================================
- #######################################################################################################################################
- > fuhrernet.com
- Server: 185.93.180.131
- Address: 185.93.180.131#53
- Non-authoritative answer:
- Name: fuhrernet.com
- Address: 68.81.58.227
- >
- #######################################################################################################################################
- Domain Name: FUHRERNET.COM
- Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: http://www.godaddy.com
- Updated Date: 2019-09-17T14:54:51Z
- Creation Date: 2017-11-06T18:02:49Z
- Registry Expiry Date: 2020-11-06T18:02:49Z
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: 480-624-2505
- Domain Status: ok https://icann.org/epp#ok
- Name Server: NS47.DOMAINCONTROL.COM
- Name Server: NS48.DOMAINCONTROL.COM
- DNSSEC: unsigned
- #######################################################################################################################################
- Domain Name: fuhrernet.com
- Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: http://www.godaddy.com
- Updated Date: 2017-11-06T18:02:49Z
- Creation Date: 2017-11-06T18:02:49Z
- Registrar Registration Expiration Date: 2020-11-06T18:02:49Z
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: +1.4806242505
- Domain Status: ok http://www.icann.org/epp#ok
- Registrant Organization: Fuhrernet
- Registrant State/Province: Pennsylvania
- Registrant Country: US
- Registrant Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
- Admin Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
- Tech Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
- Name Server: NS47.DOMAINCONTROL.COM
- Name Server: NS48.DOMAINCONTROL.COM
- DNSSEC: unsigned
- #######################################################################################################################################
- [+] Target : fuhrernet.com
- [+] IP Address : 68.81.58.227
- [+] Headers :
- [+] Date : Sat, 28 Sep 2019 08:23:29 GMT
- [+] Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- [+] X-Powered-By : PHP/7.1.1
- [+] Content-Length : 2626
- [+] Keep-Alive : timeout=5, max=100
- [+] Connection : Keep-Alive
- [+] Content-Type : text/html; charset=UTF-8
- [+] SSL Certificate Information :
- [+] commonName : localhost
- [+] commonName : localhost
- [+] Version : 1
- [+] Serial Number : B5C752C98781B503
- [+] Not Before : Nov 10 23:48:47 2009 GMT
- [+] Not After : Nov 8 23:48:47 2019 GMT
- [+] Whois Lookup :
- [+] NIR : None
- [+] ASN Registry : arin
- [+] ASN : 7922
- [+] ASN CIDR : 68.80.0.0/13
- [+] ASN Country Code : US
- [+] ASN Date : 2002-01-28
- [+] ASN Description : COMCAST-7922 - Comcast Cable Communications, LLC, US
- [+] cidr : 68.80.0.0/13
- [+] name : JUMPSTART-2
- [+] handle : NET-68-80-0-0-1
- [+] range : 68.80.0.0 - 68.87.255.255
- [+] description : Comcast Cable Communications, LLC
- [+] country : US
- [+] state : NJ
- [+] city : Mt Laurel
- [+] address : 1800 Bishops Gate Blvd
- [+] postal_code : 08054
- [+] emails : ['[email protected]', '[email protected]']
- [+] created : 2002-01-28
- [+] updated : 2016-08-31
- [+] Crawling Target...
- [+] Looking for robots.txt........[ Not Found ]
- [+] Looking for sitemap.xml.......[ Found ]
- [+] Extracting sitemap Links......[ 13 ]
- [+] Extracting CSS Links..........[ 9 ]
- [+] Extracting Javascript Links...[ 0 ]
- [+] Extracting Internal Links.....[ 0 ]
- [+] Extracting External Links.....[ 0 ]
- [+] Extracting Images.............[ 0 ]
- [+] Total Links Extracted : 22
- [+] Dumping Links in /opt/FinalRecon/dumps/fuhrernet.com.dump
- [+] Completed!
- #######################################################################################################################################
- [i] Scanning Site: http://fuhrernet.com
- B A S I C I N F O
- ====================
- [+] Site Title: Newsfeed
- [+] IP address: 68.81.58.227
- [+] Web Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- [+] CMS: Could Not Detect
- [+] Cloudflare: Not Detected
- [+] Robots File: Could NOT Find robots.txt!
- W H O I S L O O K U P
- ========================
- Domain Name: FUHRERNET.COM
- Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: http://www.godaddy.com
- Updated Date: 2019-09-17T14:54:51Z
- Creation Date: 2017-11-06T18:02:49Z
- Registry Expiry Date: 2020-11-06T18:02:49Z
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: 480-624-2505
- Domain Status: ok https://icann.org/epp#ok
- Name Server: NS47.DOMAINCONTROL.COM
- Name Server: NS48.DOMAINCONTROL.COM
- DNSSEC: unsigned
- URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
- >>> Last update of whois database: 2019-09-28T08:23:34Z <<<
- For more information on Whois status codes, please visit https://icann.org/epp
- The Registry database contains ONLY .COM, .NET, .EDU domains and
- Registrars.
- G E O I P L O O K U P
- =========================
- [i] IP Address: 68.81.58.227
- [i] Country: United States
- [i] State: Pennsylvania
- [i] City: Levittown
- [i] Latitude: 40.1519
- [i] Longitude: -74.8826
- H T T P H E A D E R S
- =======================
- [i] HTTP/1.1 200 OK
- [i] Date: Sat, 28 Sep 2019 08:23:50 GMT
- [i] Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- [i] X-Powered-By: PHP/7.1.1
- [i] Content-Length: 2626
- [i] Connection: close
- [i] Content-Type: text/html; charset=UTF-8
- D N S L O O K U P
- ===================
- fuhrernet.com. 599 IN A 68.81.58.227
- fuhrernet.com. 3599 IN NS ns47.domaincontrol.com.
- fuhrernet.com. 3599 IN NS ns48.domaincontrol.com.
- fuhrernet.com. 3599 IN SOA ns47.domaincontrol.com. dns.jomax.net. 2019091902 28800 7200 604800 600
- fuhrernet.com. 1799 IN MX 10 mx.yandex.net.
- fuhrernet.com. 3599 IN TXT "yandex-verification: d7cd81786b5817a7"
- fuhrernet.com. 3599 IN TXT "v=spf1 ip4: ip4: include:_spf.yandex.net ~all"
- S U B N E T C A L C U L A T I O N
- ====================================
- Address = 68.81.58.227
- Network = 68.81.58.227 / 32
- Netmask = 255.255.255.255
- Broadcast = not needed on Point-to-Point links
- Wildcard Mask = 0.0.0.0
- Hosts Bits = 0
- Max. Hosts = 1 (2^0 - 0)
- Host Range = { 68.81.58.227 - 68.81.58.227 }
- N M A P P O R T S C A N
- ============================
- Starting Nmap 7.70 ( https://nmap.org ) at 2019-09-28 08:23 UTC
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.030s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- PORT STATE SERVICE
- 21/tcp open ftp
- 22/tcp filtered ssh
- 23/tcp filtered telnet
- 80/tcp open http
- 110/tcp closed pop3
- 143/tcp closed imap
- 443/tcp open https
- 3389/tcp filtered ms-wbt-server
- Nmap done: 1 IP address (1 host up) scanned in 1.35 seconds
- #######################################################################################################################################
- [INFO] ------TARGET info------
- [*] TARGET: http://fuhrernet.com/login.php
- [*] TARGET IP: 68.81.58.227
- [INFO] NO load balancer detected for fuhrernet.com...
- [*] DNS servers: ns47.domaincontrol.com.
- [*] TARGET server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- [*] CC: US
- [*] Country: United States
- [*] RegionCode: PA
- [*] RegionName: Pennsylvania
- [*] City: Levittown
- [*] ASN: AS7922
- [*] BGP_PREFIX: 68.80.0.0/13
- [*] ISP: COMCAST-7922 - Comcast Cable Communications, LLC, US
- [INFO] DNS enumeration:
- [INFO] Possible abuse mails are:
- [INFO] NO PAC (Proxy Auto Configuration) file FOUND
- [INFO] Starting FUZZing in http://fuhrernet.com/FUzZzZzZzZz...
- [INFO] Status code Folders
- [*] 200 http://fuhrernet.com/12
- [ALERT] Look in the source code. It may contain passwords
- [INFO] SAME content in http://fuhrernet.com/ AND http://68.81.58.227/
- [INFO] Links found from http://fuhrernet.com/login.php:
- [*] http://fuhrernet.com/create-account.php
- [*] http://fuhrernet.com/forgot-password.html
- [*] http://fuhrernet.com/forgot-username.html
- [INFO] Shodan detected the following opened ports on 68.81.58.227:
- [*] 1
- [*] 143
- [*] 2019
- [*] 21
- [*] 32
- [*] 3306
- [*] 4
- [*] 443
- [*] 62
- [*] 7
- [*] 80
- [*] 9000
- [*] 9001
- [*] 9675
- [INFO] ------VirusTotal SECTION------
- [INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
- [INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
- [INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
- [INFO] ------Alexa Rank SECTION------
- [INFO] Percent of Visitors Rank in Country:
- [INFO] Percent of Search Traffic:
- [INFO] Percent of Unique Visits:
- [INFO] Total Sites Linking In:
- [INFO] Useful links related to fuhrernet.com - 68.81.58.227:
- [*] https://www.virustotal.com/pt/ip-address/68.81.58.227/information/
- [*] https://www.hybrid-analysis.com/search?host=68.81.58.227
- [*] https://www.shodan.io/host/68.81.58.227
- [*] https://www.senderbase.org/lookup/?search_string=68.81.58.227
- [*] https://www.alienvault.com/open-threat-exchange/ip/68.81.58.227
- [*] http://pastebin.com/search?q=68.81.58.227
- [*] http://urlquery.net/search.php?q=68.81.58.227
- [*] http://www.alexa.com/siteinfo/fuhrernet.com
- [*] http://www.google.com/safebrowsing/diagnostic?site=fuhrernet.com
- [*] https://censys.io/ipv4/68.81.58.227
- [*] https://www.abuseipdb.com/check/68.81.58.227
- [*] https://urlscan.io/search/#68.81.58.227
- [*] https://github.com/search?q=68.81.58.227&type=Code
- [INFO] Useful links related to AS7922 - 68.80.0.0/13:
- [*] http://www.google.com/safebrowsing/diagnostic?site=AS:7922
- [*] https://www.senderbase.org/lookup/?search_string=68.80.0.0/13
- [*] http://bgp.he.net/AS7922
- [*] https://stat.ripe.net/AS7922
- [INFO] Date: 28/09/19 | Time: 04:28:11
- [INFO] Total time: 4 minute(s) and 17 second(s)
- #######################################################################################################################################
- [*] Load target domain: fuhrernet.com
- - starting scanning @ 2019-09-28 04:32:03
- [+] Running & Checking source to be used
- ---------------------------------------------
- ⍥ Shodan [ ✕ ]
- ⍥ Webarchive [ ✔ ]
- ⍥ Dnsdumpster [ ✔ ]
- ⍥ Certsh [ ✔ ]
- ⍥ Certspotter [ ✔ ]
- ⍥ Securitytrails [ ✕ ]
- ⍥ Threatminer [ ✔ ]
- ⍥ Riddler [ ✔ ]
- ⍥ Entrust [ ✔ ]
- ⍥ Bufferover [ ✔ ]
- ⍥ Censys [ ✕ ]
- ⍥ Threatcrowd [ ✔ ]
- ⍥ Hackertarget [ ✔ ]
- ⍥ Binaryedge [ ✕ ]
- ⍥ Virustotal [ ✕ ]
- ⍥ Findsubdomain [ ✔ ]
- [+] Get & Count subdomain total From source
- ---------------------------------------------
- ⍥ Hackertarget: Total Subdomain (1)
- ⍥ Findsubdomain: Total Subdomain (0)
- ⍥ Certspotter: Total Subdomain (0)
- ⍥ Threatminer: Total Subdomain (0)
- ⍥ Certsh: Total Subdomain (0)
- ⍥ BufferOver: Total Subdomain (0)
- ⍥ Entrust: Total Subdomain (0)
- ⍥ Threatcrowd: Total Subdomain (0)
- ⍥ Dnsdumpster: Total Subdomain (4)
- ⍥ Riddler: Total Subdomain (0)
- ⍥ Webarchive: Total Subdomain (1)
- [+] Parsing & Sorting list Domain
- ---------------------------------------------
- ⍥ Total [1]
- - fuhrernet.com
- ⍥ Total [1]
- [+] Probe subdomain for working on http/https
- ---------------------------------------------
- - http://fuhrernet.com
- - https://fuhrernet.com
- ⍥ Total [2]
- [+] Check Live Host: Ping Sweep - ICMP PING
- ---------------------------------------------
- ⍥ [LIVE] fuhrernet.com
- [+] Check Resolving: Subdomains & Domains
- ---------------------------------------------
- ⍥ Resolving domains to: 68.81.58.227
- [+] Subdomain TakeOver - Check Possible Vulns
- ---------------------------------------------
- ⍥ [FAILS] En: Unknown http://fuhrernet.com
- ⍥ [FAILS] En: Unknown https://fuhrernet.com
- [+] Checks status code on port 80 and 443
- ---------------------------------------------
- ⍥ [200] http://fuhrernet.com
- ⍥ [000] https://fuhrernet.com
- [+] Web Screenshots: from domain list
- ---------------------------------------------
- [+] 2 URLs to be screenshot
- [+] 2 actual URLs screenshot
- [+] 0 error(s)
- [+] Sud⍥my has been sucessfully completed
- ---------------------------------------------
- ⍥ Location output:
- - output/09-28-2019/fuhrernet.com
- - output/09-28-2019/fuhrernet.com/report
- - output/09-28-2019/fuhrernet.com/screenshots
- #######################################################################################################################################
- [+] Starting At 2019-09-28 04:37:08.881372
- [+] Collecting Information On: http://fuhrernet.com/login.php
- [#] Status: 200
- --------------------------------------------------
- [#] Web Server Detected: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- [#] X-Powered-By: PHP/7.1.1
- [!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
- - Date: Sat, 28 Sep 2019 08:37:05 GMT
- - Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- - X-Powered-By: PHP/7.1.1
- - Content-Length: 6039
- - Keep-Alive: timeout=5, max=100
- - Connection: Keep-Alive
- - Content-Type: text/html; charset=UTF-8
- --------------------------------------------------
- [#] Finding Location..!
- [#] as: AS7922 Comcast Cable Communications, LLC
- [#] city: Levittown
- [#] country: United States
- [#] countryCode: US
- [#] isp: Comcast Cable Communications, LLC
- [#] lat: 40.1519
- [#] lon: -74.8826
- [#] org: Comcast Cable Communications, Inc.
- [#] query: 68.81.58.227
- [#] region: PA
- [#] regionName: Pennsylvania
- [#] status: success
- [#] timezone: America/New_York
- [#] zip: 19056
- --------------------------------------------------
- [x] Didn't Detect WAF Presence on: http://fuhrernet.com/login.php
- --------------------------------------------------
- [#] Starting Reverse DNS
- [!] Found 1 any Domain
- - fuhrernet.com
- --------------------------------------------------
- [!] Scanning Open Port
- [#] 21/tcp open ftp
- [#] 80/tcp open http
- [#] 85/tcp open mit-ml-dev
- [#] 443/tcp open https
- [#] 3306/tcp open mysql
- [#] 9001/tcp open tor-orport
- --------------------------------------------------
- [+] Collecting Information Disclosure!
- [#] Detecting sitemap.xml file
- [-] sitemap.xml file not Found!?
- [#] Detecting robots.txt file
- [-] robots.txt file not Found!?
- [#] Detecting GNU Mailman
- [-] GNU Mailman App Not Detected!?
- --------------------------------------------------
- [+] Crawling Url Parameter On: http://fuhrernet.com/login.php
- --------------------------------------------------
- [#] Searching Html Form !
- [+] Html Form Discovered
- [#] action: None
- [#] class: None
- [#] id: None
- [#] method: post
- --------------------------------------------------
- [-] No DOM Paramter Found!?
- --------------------------------------------------
- [-] No internal Dynamic Parameter Found!?
- --------------------------------------------------
- [-] No external Dynamic Paramter Found!?
- --------------------------------------------------
- [!] 13 Internal links Discovered
- [+] http://fuhrernet.com/login.php/assets/bootstrap/css/bootstrap.min.css
- [+] http://fuhrernet.com/login.php/assets/fonts/ionicons.min.css
- [+] http://fuhrernet.com/login.php/assets/css/Login-Form-Clean.css
- [+] http://fuhrernet.com/login.php/assets/css/styles.css
- [+] http://fuhrernet.com/login.php/assets/css/Profile-Card.css
- [+] http://fuhrernet.com/login.php/assets/css/untitled.css
- [+] http://fuhrernet.com/login.php/./apple-touch-icon.png
- [+] http://fuhrernet.com/login.php/./favicon-32x32.png
- [+] http://fuhrernet.com/login.php/./favicon-16x16.png
- [+] http://fuhrernet.com/login.php/./site.webmanifest
- [+] http://fuhrernet.com/login.php/./create-account.php
- [+] http://fuhrernet.com/login.php/./forgot-username.html
- [+] http://fuhrernet.com/login.php/./forgot-password.html
- --------------------------------------------------
- [!] 1 External links Discovered
- [#] https://cdnjs.cloudflare.com/ajax/libs/animate.css/3.5.2/animate.min.css
- --------------------------------------------------
- [#] Mapping Subdomain..
- [!] Found 1 Subdomain
- - fuhrernet.com
- --------------------------------------------------
- [!] Done At 2019-09-28 04:40:24.559313
- #######################################################################################################################################
- Enter Address Website = fuhrernet.com
- Reversing IP With HackTarget 'fuhrernet.com'
- -----------------------------------------------
- [+] c-68-81-58-227.hsd1.pa.comcast.net
- Reverse IP With YouGetSignal 'fuhrernet.com'
- -----------------------------------------------
- [*] IP: 68.81.58.227
- [*] Domain: fuhrernet.com
- [*] Total Domains: 1
- [+] fuhrernet.com
- Geo IP Lookup 'fuhrernet.com'
- --------------------------------
- [+] IP Address: 68.81.58.227
- [+] Country: United States
- [+] State: Pennsylvania
- [+] City: Levittown
- [+] Latitude: 40.1519
- [+] Longitude: -74.8826
- Whois 'fuhrernet.com'
- ------------------------
- [+] Domain Name: FUHRERNET.COM
- [+] Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
- [+] Registrar WHOIS Server: whois.godaddy.com
- [+] Registrar URL: http://www.godaddy.com
- [+] Updated Date: 2019-09-17T14:54:51Z
- [+] Creation Date: 2017-11-06T18:02:49Z
- [+] Registry Expiry Date: 2020-11-06T18:02:49Z
- [+] Registrar: GoDaddy.com, LLC
- [+] Registrar IANA ID: 146
- [+] Registrar Abuse Contact Email: [email protected]
- [+] Registrar Abuse Contact Phone: 480-624-2505
- [+] Domain Status: ok https://icann.org/epp#ok
- [+] Name Server: NS47.DOMAINCONTROL.COM
- [+] Name Server: NS48.DOMAINCONTROL.COM
- [+] DNSSEC: unsigned
- [+] URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
- [+] >>> Last update of whois database: 2019-09-28T08:36:22Z <<<
- [+] For more information on Whois status codes, please visit https://icann.org/epp
- [+] The Registry database contains ONLY .COM, .NET, .EDU domains and
- [+] Registrars.
- Bypass Cloudflare 'fuhrernet.com'
- ------------------------------------
- [!] CloudFlare Bypass 68.81.58.227 | www.fuhrernet.com
- DNS Lookup 'fuhrernet.com'
- -----------------------------
- [+] fuhrernet.com. 599 IN A 68.81.58.227
- [+] fuhrernet.com. 3599 IN NS ns47.domaincontrol.com.
- [+] fuhrernet.com. 3599 IN NS ns48.domaincontrol.com.
- [+] fuhrernet.com. 3599 IN SOA ns47.domaincontrol.com. dns.jomax.net. 2019091902 28800 7200 604800 600
- [+] fuhrernet.com. 1799 IN MX 10 mx.yandex.net.
- [+] fuhrernet.com. 3599 IN TXT "yandex-verification: d7cd81786b5817a7"
- [+] fuhrernet.com. 3599 IN TXT "v=spf1 ip4: ip4: include:_spf.yandex.net ~all"
- Show HTTP Header 'fuhrernet.com'
- -----------------------------------
- [+] HTTP/1.1 200 OK
- [+] Date: Sat, 28 Sep 2019 08:36:54 GMT
- [+] Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- [+] X-Powered-By: PHP/7.1.1
- [+] Content-Type: text/html; charset=UTF-8
- [+]
- Port Scan 'fuhrernet.com'
- ----------------------------
- Starting Nmap 7.70 ( https://nmap.org ) at 2019-09-28 08:36 UTC
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.024s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- PORT STATE SERVICE
- 21/tcp open ftp
- 22/tcp filtered ssh
- 23/tcp filtered telnet
- 80/tcp open http
- 110/tcp closed pop3
- 143/tcp closed imap
- 443/tcp open https
- 3389/tcp filtered ms-wbt-server
- Nmap done: 1 IP address (1 host up) scanned in 1.25 seconds
- Traceroute 'fuhrernet.com'
- -----------------------------
- Start: 2019-09-28T08:37:01+0000
- HOST: web01 Loss% Snt Last Avg Best Wrst StDev
- 1.|-- 45.79.12.201 0.0% 3 0.6 0.7 0.6 0.8 0.1
- 2.|-- 45.79.12.4 0.0% 3 20.9 7.4 0.6 20.9 11.7
- 3.|-- dls-b22-link.telia.net 0.0% 3 0.9 2.0 0.8 4.3 2.0
- 4.|-- dls-b21-link.telia.net 0.0% 3 1.5 3.1 1.5 5.6 2.2
- 5.|-- comcast-ic-318909-dls-b21.c.telia.net 0.0% 3 1.9 1.8 1.5 2.0 0.3
- 6.|-- be-12441-cr02.dallas.tx.ibone.comcast.net 0.0% 3 1.9 2.8 1.9 3.4 0.8
- 7.|-- be-12324-cr01.houston.tx.ibone.comcast.net 0.0% 3 8.1 8.3 8.1 8.4 0.2
- 8.|-- be-11423-cr02.56marietta.ga.ibone.comcast.net 0.0% 3 20.1 20.2 19.4 21.1 0.9
- 9.|-- be-1402-cs04.56marietta.ga.ibone.comcast.net 0.0% 3 19.4 19.8 19.4 20.0 0.3
- 10.|-- be-1411-cr11.56marietta.ga.ibone.comcast.net 0.0% 3 19.3 19.7 19.3 20.0 0.4
- 11.|-- be-301-cr11.ashburn.va.ibone.comcast.net 0.0% 3 35.5 35.5 35.5 35.6 0.1
- 12.|-- be-1411-cs04.ashburn.va.ibone.comcast.net 0.0% 3 35.5 35.6 35.5 35.7 0.1
- 13.|-- be-1402-cr02.ashburn.va.ibone.comcast.net 0.0% 3 30.2 30.7 30.2 31.1 0.4
- 14.|-- be-7922-ar03.newcastle.de.panjde.comcast.net 0.0% 3 34.6 33.7 33.2 34.6 0.7
- 15.|-- be-900-ar03.norristown.pa.panjde.comcast.net 0.0% 3 35.5 35.3 35.2 35.5 0.1
- 16.|-- 162.151.182.178 0.0% 3 39.2 39.1 39.1 39.2 0.1
- 17.|-- lag2-acr22.levittown.pa.panjde.comcast.net 0.0% 3 41.0 41.0 41.0 41.0 0.0
- 18.|-- c-68-81-58-227.hsd1.pa.comcast.net 0.0% 3 53.8 54.1 51.3 57.1 2.9
- #######################################################################################################################################
- Trying "fuhrernet.com"
- ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5382
- ;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 2, ADDITIONAL: 4
- ;; QUESTION SECTION:
- ;fuhrernet.com. IN ANY
- ;; ANSWER SECTION:
- fuhrernet.com. 3600 IN TXT "v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all"
- fuhrernet.com. 3600 IN TXT "yandex-verification: d7cd81786b5817a7"
- fuhrernet.com. 1800 IN MX 10 mx.yandex.net.
- fuhrernet.com. 3600 IN SOA ns47.domaincontrol.com. dns.jomax.net. 2019091902 28800 7200 604800 600
- fuhrernet.com. 600 IN A 68.81.58.227
- fuhrernet.com. 3600 IN NS ns47.domaincontrol.com.
- fuhrernet.com. 3600 IN NS ns48.domaincontrol.com.
- ;; AUTHORITY SECTION:
- fuhrernet.com. 3600 IN NS ns47.domaincontrol.com.
- fuhrernet.com. 3600 IN NS ns48.domaincontrol.com.
- ;; ADDITIONAL SECTION:
- ns47.domaincontrol.com. 3039 IN A 97.74.103.24
- ns47.domaincontrol.com. 23226 IN AAAA 2603:5:2172::18
- ns48.domaincontrol.com. 21374 IN A 173.201.71.24
- ns48.domaincontrol.com. 10967 IN AAAA 2603:5:2272::18
- Received 410 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 136 ms
- #######################################################################################################################################
- ; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace fuhrernet.com
- ;; global options: +cmd
- . 79757 IN NS k.root-servers.net.
- . 79757 IN NS b.root-servers.net.
- . 79757 IN NS h.root-servers.net.
- . 79757 IN NS g.root-servers.net.
- . 79757 IN NS j.root-servers.net.
- . 79757 IN NS e.root-servers.net.
- . 79757 IN NS f.root-servers.net.
- . 79757 IN NS m.root-servers.net.
- . 79757 IN NS d.root-servers.net.
- . 79757 IN NS l.root-servers.net.
- . 79757 IN NS c.root-servers.net.
- . 79757 IN NS i.root-servers.net.
- . 79757 IN NS a.root-servers.net.
- . 79757 IN RRSIG NS 8 0 518400 20191011050000 20190928040000 59944 . M2/pztQA5M3yKsxBHFunkxHu99aDaPjvo/OdBj24SIpGnsF32zMxTCD0 GaK2OztD+2eaqf3eENHJCQuwb2cFtsiLCbyx0d6kSmmIiJPw3mEZ+W1t tplJwghGtAmj0Fqtb2f7DtlcVUraowz2s6vfPuDlrLla0Nabij9WikwL TQGtdJ83LtV30Sl/cxglkKX892KyiVRIL463prTUdcP5VFk1836iPLYW HnPimmCcGxsEYkP+5+VCvZzKyCqkADZVrpBAirud20z7gdcL6MXZqzEX 4Kkv6sUi7jomDYbgHwlV+CFVLzDdTzsWbQBRVYrd0klVJC5gRtV6jf6M TQnMOQ==
- ;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 29 ms
- com. 172800 IN NS i.gtld-servers.net.
- com. 172800 IN NS j.gtld-servers.net.
- com. 172800 IN NS e.gtld-servers.net.
- com. 172800 IN NS l.gtld-servers.net.
- com. 172800 IN NS m.gtld-servers.net.
- com. 172800 IN NS f.gtld-servers.net.
- com. 172800 IN NS h.gtld-servers.net.
- com. 172800 IN NS b.gtld-servers.net.
- com. 172800 IN NS d.gtld-servers.net.
- com. 172800 IN NS g.gtld-servers.net.
- com. 172800 IN NS c.gtld-servers.net.
- com. 172800 IN NS a.gtld-servers.net.
- com. 172800 IN NS k.gtld-servers.net.
- com. 86400 IN DS 30909 8 2 E2D3C916F6DEEAC73294E8268FB5885044A833FC5459588F4A9184CF C41A5766
- com. 86400 IN RRSIG DS 8 1 86400 20191011050000 20190928040000 59944 . h6+G+ESPE9Aa2qAQwbM53M14XGUz/j2SCYydXlhRZ+SHobuK9DqayXpY FFWWWKv0+qRzo1TduRVgqbtj0pYMX2jFfgoSNdpELPfVti+k704LO+D1 UTyhNh066JIFXd3bZPgZ7mlMI2PEWPAVl3l4XlxgMDzyGSEVQQGWuFwm IubH9k3Ud8jQPMZlMIkb9ET87BW0u6NR/HJKTyCnlBuMF9sr5mHkzFN4 jkESPG7//c84lv5JJNeyIUe7hY5z0sHUof6UeR7iDSQZdB4hjqyG2qN0 NumZbMgXCR9DJrVH7PvUrR7MEn29Rt7HLY5lxL48axCNAZWEUJvUgJ3M c49fDw==
- ;; Received 1173 bytes from 193.0.14.129#53(k.root-servers.net) in 81 ms
- fuhrernet.com. 172800 IN NS ns47.domaincontrol.com.
- fuhrernet.com. 172800 IN NS ns48.domaincontrol.com.
- CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN NSEC3 1 1 0 - CK0Q1GIN43N1ARRC9OSM6QPQR81H5M9A NS SOA RRSIG DNSKEY NSEC3PARAM
- CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN RRSIG NSEC3 8 2 86400 20191002044638 20190925033638 17708 com. W1EdwlejJtzVVubIBRcoCicfmwD78yZE5RGrjWJc1enFUVYFadLsyHDm SdGwV9H5Izrr+dDFUqRrzw6AtZZD0agyG7oqP2066DddrgnwryHNTtkl 7TLBFPm/io9cRPiEANIyDLKqn7WbKDx+5BZ0Lys/HBUkXGkcVevSksfD /rk=
- 6RG8GQ3EJ5GEU55CNMDPQF4EN9E7SCFP.com. 86400 IN NSEC3 1 1 0 - 6RG8MMU5E2D4SMANA51JLH13O3PMDFVD NS DS RRSIG
- 6RG8GQ3EJ5GEU55CNMDPQF4EN9E7SCFP.com. 86400 IN RRSIG NSEC3 8 2 86400 20191002054536 20190925043536 17708 com. GI9DvwhtHQmOF+PC7BUPicV/1zc/W48kPFsFOjmKxRTv/EzXe16YZhcL kPKVxteUFNV40iWLpVYK7c8KhtG7hp5E1L+ntjsq/aujj/IEsXLssg/D fghuvhM8HamuUyW6zt8RevX19KjD9wCEbYG/AMlAilzLaGaxRYRgMePj rvM=
- ;; Received 667 bytes from 192.52.178.30#53(k.gtld-servers.net) in 59 ms
- fuhrernet.com. 600 IN A 68.81.58.227
- fuhrernet.com. 3600 IN NS ns47.domaincontrol.com.
- fuhrernet.com. 3600 IN NS ns48.domaincontrol.com.
- ;; Received 110 bytes from 2603:5:2172::18#53(ns47.domaincontrol.com) in 33 ms
- #######################################################################################################################################
- [*] Performing General Enumeration of Domain: fuhrernet.com
- [-] DNSSEC is not configured for fuhrernet.com
- [*] SOA ns47.domaincontrol.com 97.74.103.24
- [*] NS ns48.domaincontrol.com 173.201.71.24
- [*] NS ns48.domaincontrol.com 2603:5:2272::18
- [*] NS ns47.domaincontrol.com 97.74.103.24
- [*] NS ns47.domaincontrol.com 2603:5:2172::18
- [*] MX mx.yandex.net 77.88.21.89
- [*] MX mx.yandex.net 213.180.193.89
- [*] MX mx.yandex.net 213.180.204.89
- [*] MX mx.yandex.net 93.158.134.89
- [*] MX mx.yandex.net 87.250.250.89
- [*] MX mx.yandex.net 2a02:6b8::89
- [*] A fuhrernet.com 68.81.58.227
- [*] TXT fuhrernet.com v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all
- [*] TXT fuhrernet.com yandex-verification: d7cd81786b5817a7
- [*] Enumerating SRV Records
- [-] No SRV Records Found for fuhrernet.com
- [+] 0 Records Found
- #######################################################################################################################################
- rocessing domain fuhrernet.com
- [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
- [+] Getting nameservers
- 173.201.71.24 - ns48.domaincontrol.com
- 97.74.103.24 - ns47.domaincontrol.com
- [-] Zone transfer failed
- [+] TXT records found
- "v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all"
- "yandex-verification: d7cd81786b5817a7"
- [+] MX records found, added to target list
- 10 mx.yandex.net.
- [*] Scanning fuhrernet.com for A records
- 68.81.58.227 - fuhrernet.com
- 68.81.58.227 - www.fuhrernet.com
- #######################################################################################################################################
- AVAILABLE PLUGINS
- -----------------
- SessionRenegotiationPlugin
- OpenSslCcsInjectionPlugin
- SessionResumptionPlugin
- HttpHeadersPlugin
- EarlyDataPlugin
- CertificateInfoPlugin
- CompressionPlugin
- RobotPlugin
- OpenSslCipherSuitesPlugin
- HeartbleedPlugin
- FallbackScsvPlugin
- CHECKING HOST(S) AVAILABILITY
- -----------------------------
- 68.81.58.227:443 => 68.81.58.227
- SCAN RESULTS FOR 68.81.58.227:443 - 68.81.58.227
- ------------------------------------------------
- * Downgrade Attacks:
- TLS_FALLBACK_SCSV: OK - Supported
- * TLS 1.2 Session Resumption Support:
- With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
- With TLS Tickets: OK - Supported
- * Certificate Information:
- Content
- SHA1 Fingerprint: b0238c547a905bfa119c4e8baccaeacf36491ff6
- Common Name: localhost
- Issuer: localhost
- Serial Number: 13098529066745705731
- Not Before: 2009-11-10 23:48:47
- Not After: 2019-11-08 23:48:47
- Signature Algorithm: sha1
- Public Key Algorithm: RSA
- Key Size: 1024
- Exponent: 65537 (0x10001)
- DNS Subject Alternative Names: []
- Trust
- Hostname Validation: FAILED - Certificate does NOT match 68.81.58.227
- Android CA Store (9.0.0_r9): FAILED - Certificate is NOT Trusted: self signed certificate
- Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):FAILED - Certificate is NOT Trusted: self signed certificate
- Java CA Store (jdk-12.0.1): FAILED - Certificate is NOT Trusted: self signed certificate
- Mozilla CA Store (2019-03-14): FAILED - Certificate is NOT Trusted: self signed certificate
- Windows CA Store (2019-05-27): FAILED - Certificate is NOT Trusted: self signed certificate
- Symantec 2018 Deprecation: OK - Not a Symantec-issued certificate
- Received Chain: localhost
- Verified Chain: ERROR - Could not build verified chain (certificate untrusted?)
- Received Chain Contains Anchor: ERROR - Could not build verified chain (certificate untrusted?)
- Received Chain Order: OK - Order is valid
- Verified Chain contains SHA1: ERROR - Could not build verified chain (certificate untrusted?)
- Extensions
- OCSP Must-Staple: NOT SUPPORTED - Extension not found
- Certificate Transparency: NOT SUPPORTED - Extension not found
- OCSP Stapling
- NOT SUPPORTED - Server did not send back an OCSP response
- * SSLV3 Cipher Suites:
- Server rejected all cipher suites.
- * OpenSSL CCS Injection:
- OK - Not vulnerable to OpenSSL CCS injection
- * SSLV2 Cipher Suites:
- Server rejected all cipher suites.
- * Session Renegotiation:
- Client-initiated Renegotiation: OK - Rejected
- Secure Renegotiation: OK - Supported
- * TLSV1_3 Cipher Suites:
- Server rejected all cipher suites.
- * Deflate Compression:
- OK - Compression disabled
- * TLSV1 Cipher Suites:
- Forward Secrecy OK - Supported
- RC4 OK - Not Supported
- Preferred:
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- Accepted:
- TLS_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_IDEA_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- * TLSV1_1 Cipher Suites:
- Forward Secrecy OK - Supported
- RC4 OK - Not Supported
- Preferred:
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- Accepted:
- TLS_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_IDEA_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- * TLSV1_2 Cipher Suites:
- Forward Secrecy OK - Supported
- RC4 OK - Not Supported
- Preferred:
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- Accepted:
- TLS_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_IDEA_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
- TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_SEED_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
- * OpenSSL Heartbleed:
- OK - Not vulnerable to Heartbleed
- * ROBOT Attack:
- OK - Not vulnerable
- SCAN COMPLETED IN 24.24 S
- -------------------------
- #######################################################################################################################################
- Domains still to check: 1
- Checking if the hostname fuhrernet.com. given is in fact a domain...
- Analyzing domain: fuhrernet.com.
- Checking NameServers using system default resolver...
- IP: 173.201.71.24 (United States)
- HostName: ns48.domaincontrol.com Type: NS
- HostName: ns48.domaincontrol.com Type: PTR
- IP: 97.74.103.24 (United States)
- HostName: ns47.domaincontrol.com Type: NS
- HostName: ns47.domaincontrol.com Type: PTR
- Checking MailServers using system default resolver...
- IP: 87.250.250.89 (Russian Federation)
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- IP: 213.180.204.89 (Russian Federation)
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- IP: 77.88.21.89 (Russian Federation)
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- IP: 213.180.193.89 (Russian Federation)
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- IP: 93.158.134.89 (Russian Federation)
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
- No zone transfer found on nameserver 97.74.103.24
- No zone transfer found on nameserver 173.201.71.24
- Checking SPF record...
- New IP found: <IP-1>
- New IP found: <IP-2>
- Checking SPF record...
- Checking 192 most common hostnames using system default resolver...
- IP: 68.81.58.227 (United States)
- HostName: www.fuhrernet.com. Type: A
- Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
- Checking netblock 68.81.58.0
- Checking netblock 97.74.103.0
- Checking netblock 93.158.134.0
- Checking netblock 213.180.193.0
- Checking netblock 173.201.71.0
- Checking netblock 77.88.21.0
- Checking netblock 87.250.250.0
- Checking netblock 0
- Checking netblock 213.180.204.0
- Searching for fuhrernet.com. emails in Google
- Checking 10 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
- Host 68.81.58.227 is up (echo-reply ttl 49)
- Host 97.74.103.24 is up (reset ttl 64)
- Host 93.158.134.89 is up (reset ttl 64)
- Host 213.180.193.89 is up (reset ttl 64)
- Host 173.201.71.24 is up (echo-reply ttl 56)
- Host 77.88.21.89 is up (reset ttl 64)
- Host 87.250.250.89 is up (reset ttl 64)
- Failed to resolve "<IP-2>".
- WARNING: No targets were specified, so 0 hosts scanned.
- Host <IP-2> is down
- Failed to resolve "<IP-1>".
- WARNING: No targets were specified, so 0 hosts scanned.
- Host <IP-1> is down
- Host 213.180.204.89 is up (reset ttl 64)
- Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
- Scanning ip 68.81.58.227 (www.fuhrernet.com.):
- adjust_timeouts2: packet supposedly had rtt of -57270 microseconds. Ignoring time.
- adjust_timeouts2: packet supposedly had rtt of -57270 microseconds. Ignoring time.
- adjust_timeouts2: packet supposedly had rtt of -91548 microseconds. Ignoring time.
- adjust_timeouts2: packet supposedly had rtt of -91548 microseconds. Ignoring time.
- 21/tcp open tcpwrapped syn-ack ttl 112
- | ftp-syst:
- |_ SYST: UNIX emulated by FileZilla
- 80/tcp open tcpwrapped syn-ack ttl 112
- |_http-favicon: Unknown favicon MD5: DB329B3B28D2D0EFB3462491F591D883
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- |_http-title: Newsfeed
- 443/tcp open tcpwrapped syn-ack ttl 112
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- |_http-title: Bad request!
- | ssl-cert: Subject: commonName=localhost
- | Issuer: commonName=localhost
- | Public Key type: rsa
- | Public Key bits: 1024
- | Signature Algorithm: sha1WithRSAEncryption
- | Not valid before: 2009-11-10T23:48:47
- | Not valid after: 2019-11-08T23:48:47
- | MD5: a0a4 4cc9 9e84 b26f 9e63 9f9e d229 dee0
- |_SHA-1: b023 8c54 7a90 5bfa 119c 4e8b acca eacf 3649 1ff6
- |_ssl-date: TLS randomness does not represent time
- | tls-alpn:
- |_ http/1.1
- 3306/tcp open tcpwrapped syn-ack ttl 112
- Device type: general purpose|WAP
- Scanning ip 97.74.103.24 (ns47.domaincontrol.com (PTR)):
- 53/tcp open tcpwrapped syn-ack ttl 52
- Scanning ip 93.158.134.89 (mx.yandex.ru (PTR)):
- Scanning ip 213.180.193.89 (mx.yandex.ru (PTR)):
- Scanning ip 173.201.71.24 (ns48.domaincontrol.com (PTR)):
- 53/tcp open tcpwrapped syn-ack ttl 56
- Scanning ip 77.88.21.89 (mx.yandex.ru (PTR)):
- Scanning ip 87.250.250.89 (mx.yandex.ru (PTR)):
- Scanning ip 213.180.204.89 (mx.yandex.ru (PTR)):
- WebCrawling domain's web servers... up to 50 max links.
- --Finished--
- Summary information for domain fuhrernet.com.
- -----------------------------------------
- Domain Ips Information:
- IP: 68.81.58.227
- HostName: www.fuhrernet.com. Type: A
- Country: United States
- Is Active: True (echo-reply ttl 49)
- Port: 21/tcp open tcpwrapped syn-ack ttl 112
- Script Info: | ftp-syst:
- Script Info: |_ SYST: UNIX emulated by FileZilla
- Port: 80/tcp open tcpwrapped syn-ack ttl 112
- Script Info: |_http-favicon: Unknown favicon MD5: DB329B3B28D2D0EFB3462491F591D883
- Script Info: | http-methods:
- Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
- Script Info: |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- Script Info: |_http-title: Newsfeed
- Port: 443/tcp open tcpwrapped syn-ack ttl 112
- Script Info: | http-methods:
- Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
- Script Info: |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- Script Info: |_http-title: Bad request!
- Script Info: | ssl-cert: Subject: commonName=localhost
- Script Info: | Issuer: commonName=localhost
- Script Info: | Public Key type: rsa
- Script Info: | Public Key bits: 1024
- Script Info: | Signature Algorithm: sha1WithRSAEncryption
- Script Info: | Not valid before: 2009-11-10T23:48:47
- Script Info: | Not valid after: 2019-11-08T23:48:47
- Script Info: | MD5: a0a4 4cc9 9e84 b26f 9e63 9f9e d229 dee0
- Script Info: |_SHA-1: b023 8c54 7a90 5bfa 119c 4e8b acca eacf 3649 1ff6
- Script Info: |_ssl-date: TLS randomness does not represent time
- Script Info: | tls-alpn:
- Script Info: |_ http/1.1
- Port: 3306/tcp open tcpwrapped syn-ack ttl 112
- Script Info: Device type: general purpose|WAP
- IP: 97.74.103.24
- HostName: ns47.domaincontrol.com Type: NS
- HostName: ns47.domaincontrol.com Type: PTR
- Country: United States
- Is Active: True (reset ttl 64)
- Port: 53/tcp open tcpwrapped syn-ack ttl 52
- IP: 93.158.134.89
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- Country: Russian Federation
- Is Active: True (reset ttl 64)
- IP: 213.180.193.89
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- Country: Russian Federation
- Is Active: True (reset ttl 64)
- IP: 173.201.71.24
- HostName: ns48.domaincontrol.com Type: NS
- HostName: ns48.domaincontrol.com Type: PTR
- Country: United States
- Is Active: True (echo-reply ttl 56)
- Port: 53/tcp open tcpwrapped syn-ack ttl 56
- IP: 77.88.21.89
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- Country: Russian Federation
- Is Active: True (reset ttl 64)
- IP: 87.250.250.89
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- Country: Russian Federation
- Is Active: True (reset ttl 64)
- IP: <IP-2>
- Type: SPF
- Is Active: False
- IP: <IP-1>
- Type: SPF
- Is Active: False
- IP: 213.180.204.89
- HostName: mx.yandex.net Type: MX
- HostName: mx.yandex.ru Type: PTR
- Country: Russian Federation
- Is Active: True (reset ttl 64)
- #######################################################################################################################################
- dnsenum VERSION:1.2.4
- ----- fuhrernet.com -----
- Host's addresses:
- __________________
- fuhrernet.com. 340 IN A 68.81.58.227
- Name Servers:
- ______________
- ns47.domaincontrol.com. 86004 IN A 97.74.103.24
- ns48.domaincontrol.com. 86028 IN A 173.201.71.24
- Mail (MX) Servers:
- ___________________
- mx.yandex.net. 554 IN A 87.250.250.89
- mx.yandex.net. 554 IN A 213.180.204.89
- mx.yandex.net. 554 IN A 77.88.21.89
- mx.yandex.net. 554 IN A 213.180.193.89
- mx.yandex.net. 554 IN A 93.158.134.89
- Trying Zone Transfers and getting Bind Versions:
- _________________________________________________
- Trying Zone Transfer for fuhrernet.com on ns47.domaincontrol.com ...
- Trying Zone Transfer for fuhrernet.com on ns48.domaincontrol.com ...
- brute force file not specified, bay.
- #######################################################################################################################################
- Domain Name: FUHRERNET.COM
- Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: http://www.godaddy.com
- Updated Date: 2019-09-17T14:54:51Z
- Creation Date: 2017-11-06T18:02:49Z
- Registry Expiry Date: 2020-11-06T18:02:49Z
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: 480-624-2505
- Domain Status: ok https://icann.org/epp#ok
- Name Server: NS47.DOMAINCONTROL.COM
- Name Server: NS48.DOMAINCONTROL.COM
- DNSSEC: unsigned
- #######################################################################################################################################
- Domain Name: fuhrernet.com
- Registry Domain ID: 2183865559_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: http://www.godaddy.com
- Updated Date: 2017-11-06T18:02:49Z
- Creation Date: 2017-11-06T18:02:49Z
- Registrar Registration Expiration Date: 2020-11-06T18:02:49Z
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: [email protected]
- Registrar Abuse Contact Phone: +1.4806242505
- Domain Status: ok http://www.icann.org/epp#ok
- Registrant Organization: Fuhrernet
- Registrant State/Province: Pennsylvania
- Registrant Country: US
- Registrant Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
- Admin Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
- Tech Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=fuhrernet.com
- Name Server: NS47.DOMAINCONTROL.COM
- Name Server: NS48.DOMAINCONTROL.COM
- DNSSEC: unsigned
- #######################################################################################################################################
- [*] Processing domain fuhrernet.com
- [*] Using system resolvers ['38.132.106.139', '194.187.251.67', '185.93.180.131', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
- [+] Getting nameservers
- 173.201.71.24 - ns48.domaincontrol.com
- 97.74.103.24 - ns47.domaincontrol.com
- [-] Zone transfer failed
- [+] TXT records found
- "v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all"
- "yandex-verification: d7cd81786b5817a7"
- [+] MX records found, added to target list
- 10 mx.yandex.net.
- [*] Scanning fuhrernet.com for A records
- 68.81.58.227 - fuhrernet.com
- 68.81.58.227 - www.fuhrernet.com
- #######################################################################################################################################
- [*] Found SPF record:
- [*] v=spf1 ip4:<IP-1> ip4:<IP-2> include:_spf.yandex.net ~all
- [*] SPF record contains an All item: ~all
- [*] No DMARC record found. Looking for organizational record
- [+] No organizational DMARC record
- [+] Spoofing possible for fuhrernet.com!
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:54 EDT
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.086s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- Not shown: 473 filtered ports, 6 closed ports
- Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
- PORT STATE SERVICE
- 21/tcp open ftp
- 80/tcp open http
- 443/tcp open https
- 3306/tcp open mysql
- Nmap done: 1 IP address (1 host up) scanned in 94.47 seconds
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:55 EDT
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.075s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- Not shown: 2 filtered ports
- PORT STATE SERVICE
- 53/udp open|filtered domain
- 67/udp open|filtered dhcps
- 68/udp open|filtered dhcpc
- 69/udp open|filtered tftp
- 88/udp open|filtered kerberos-sec
- 123/udp open|filtered ntp
- 139/udp open|filtered netbios-ssn
- 161/udp open|filtered snmp
- 162/udp open|filtered snmptrap
- 389/udp open|filtered ldap
- 500/udp open|filtered isakmp
- 520/udp open|filtered route
- 2049/udp open|filtered nfs
- Nmap done: 1 IP address (1 host up) scanned in 2.60 seconds
- ######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:56 EDT
- NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
- NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
- NSE: [ftp-brute] passwords: Time limit 3m00s exceeded.
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.079s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- PORT STATE SERVICE VERSION
- 21/tcp open ftp FileZilla ftpd 0.9.41 beta
- | ftp-brute:
- | Accounts: No valid accounts found
- |_ Statistics: Performed 2331 guesses in 266 seconds, average tps: 7.9
- | ftp-syst:
- |_ SYST: UNIX emulated by FileZilla
- |_vulscan: ERROR: Script execution failed (use -d to debug)
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Device type: specialized|general purpose
- Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (87%)
- OS CPE: cpe:/o:freebsd:freebsd:6.2
- Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (87%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 20 hops
- Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
- TRACEROUTE (using port 21/tcp)
- HOP RTT ADDRESS
- 1 99.30 ms 10.244.204.1
- 2 99.36 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 99.34 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 99.34 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 99.34 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 99.36 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 99.36 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 99.38 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 99.39 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 28.53 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
- 11 89.59 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 39.20 ms 66.110.96.130
- 13 39.21 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 39.20 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 39.21 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 39.20 ms 68.86.211.122
- 17 39.19 ms 162.151.182.174
- 18 39.21 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 ...
- 20 59.05 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 05:01 EDT
- NSE: Loaded 164 scripts for scanning.
- NSE: Script Pre-scanning.
- Initiating NSE at 05:01
- Completed NSE at 05:01, 0.00s elapsed
- Initiating NSE at 05:01
- Completed NSE at 05:01, 0.00s elapsed
- Initiating Parallel DNS resolution of 1 host. at 05:01
- Completed Parallel DNS resolution of 1 host. at 05:01, 0.02s elapsed
- Initiating SYN Stealth Scan at 05:01
- Scanning fuhrernet.com (68.81.58.227) [1 port]
- Discovered open port 80/tcp on 68.81.58.227
- Completed SYN Stealth Scan at 05:01, 0.12s elapsed (1 total ports)
- Initiating Service scan at 05:01
- Scanning 1 service on fuhrernet.com (68.81.58.227)
- Completed Service scan at 05:01, 6.11s elapsed (1 service on 1 host)
- Initiating OS detection (try #1) against fuhrernet.com (68.81.58.227)
- Retrying OS detection (try #2) against fuhrernet.com (68.81.58.227)
- Initiating Traceroute at 05:02
- Completed Traceroute at 05:02, 3.06s elapsed
- Initiating Parallel DNS resolution of 19 hosts. at 05:02
- Completed Parallel DNS resolution of 19 hosts. at 05:02, 0.28s elapsed
- NSE: Script scanning 68.81.58.227.
- Initiating NSE at 05:02
- Completed NSE at 05:02, 46.72s elapsed
- Initiating NSE at 05:02
- Completed NSE at 05:02, 0.99s elapsed
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.12s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- PORT STATE SERVICE VERSION
- 80/tcp open http Apache httpd 2.4.25 ((Win32) OpenSSL/1.0.2j PHP/7.1.1)
- | http-brute:
- |_ Path "/" does not require authentication
- |_http-chrono: Request times for /; avg: 631.71ms; min: 466.84ms; max: 786.86ms
- |_http-csrf: Couldn't find any CSRF vulnerabilities.
- |_http-date: Sat, 28 Sep 2019 09:02:07 GMT; -5s from local time.
- |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
- |_http-dombased-xss: Couldn't find any DOM based XSS.
- |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
- |_http-errors: Couldn't find any error pages.
- |_http-feed: Couldn't find any feeds.
- |_http-fetch: Please enter the complete path of the directory to save data in.
- | http-headers:
- | Date: Sat, 28 Sep 2019 09:02:03 GMT
- | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- | X-Powered-By: PHP/7.1.1
- | Connection: close
- | Content-Type: text/html; charset=UTF-8
- |
- |_ (Request type: HEAD)
- |_http-jsonp-detection: Couldn't find any JSONP endpoints.
- |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-mobileversion-checker: No mobile version detected.
- | http-php-version: Logo query returned unknown hash 493264b1ea71e8083a6356206999ff80
- | Credits query returned unknown hash 493264b1ea71e8083a6356206999ff80
- |_Version from header x-powered-by: PHP/7.1.1
- |_http-security-headers:
- |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- | http-sitemap-generator:
- | Directory structure:
- | /
- | Other: 1; png: 3; webmanifest: 1
- | /assets/bootstrap/css/
- | css: 1
- | /assets/css/
- | css: 6
- | /assets/fonts/
- | css: 1
- | Longest directory structure:
- | Depth: 3
- | Dir: /assets/bootstrap/css/
- | Total files found (by extension):
- |_ Other: 1; css: 8; png: 3; webmanifest: 1
- |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
- |_http-title: Newsfeed
- | http-trace: TRACE is enabled
- | Headers:
- | Date: Sat, 28 Sep 2019 09:02:02 GMT
- | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- | Connection: close
- | Transfer-Encoding: chunked
- |_Content-Type: message/http
- | http-vhosts:
- |_127 names had status 200
- | http-vuln-cve2010-0738:
- |_ /jmx-console/: Authentication was not required
- |_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
- |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
- |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-xssed: No previously reported XSS vuln.
- | vulners:
- | cpe:/a:apache:http_server:2.4.25:
- | CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
- | CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
- | CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
- | CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
- | CVE-2019-0211 7.2 https://vulners.com/cve/CVE-2019-0211
- | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
- | CVE-2017-15715 6.8 https://vulners.com/cve/CVE-2017-15715
- | CVE-2019-10082 6.4 https://vulners.com/cve/CVE-2019-10082
- | CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
- | CVE-2019-10098 5.8 https://vulners.com/cve/CVE-2019-10098
- | CVE-2019-10081 5.0 https://vulners.com/cve/CVE-2019-10081
- | CVE-2019-0220 5.0 https://vulners.com/cve/CVE-2019-0220
- | CVE-2019-0196 5.0 https://vulners.com/cve/CVE-2019-0196
- | CVE-2018-17199 5.0 https://vulners.com/cve/CVE-2018-17199
- | CVE-2018-1333 5.0 https://vulners.com/cve/CVE-2018-1333
- | CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
- | CVE-2017-7659 5.0 https://vulners.com/cve/CVE-2017-7659
- | CVE-2017-15710 5.0 https://vulners.com/cve/CVE-2017-15710
- | CVE-2019-0197 4.9 https://vulners.com/cve/CVE-2019-0197
- | CVE-2019-10092 4.3 https://vulners.com/cve/CVE-2019-10092
- | CVE-2018-11763 4.3 https://vulners.com/cve/CVE-2018-11763
- |_ CVE-2018-1283 3.5 https://vulners.com/cve/CVE-2018-1283
- |_vulscan: ERROR: Script execution failed (use -d to debug)
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Device type: general purpose|specialized
- Running (JUST GUESSING): FreeBSD 6.X (87%), AVtech embedded (85%)
- OS CPE: cpe:/o:freebsd:freebsd:6.2
- Aggressive OS guesses: FreeBSD 6.2-RELEASE (87%), AVtech Room Alert 26W environmental monitor (85%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 20 hops
- TCP Sequence Prediction: Difficulty=261 (Good luck!)
- IP ID Sequence Generation: Incremental
- TRACEROUTE (using port 80/tcp)
- HOP RTT ADDRESS
- 1 49.76 ms 10.244.204.1
- 2 49.85 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 49.89 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 49.85 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 49.87 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 50.00 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 49.94 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 49.99 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 49.98 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 30.01 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
- 11 47.74 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 58.68 ms 66.110.96.138
- 13 79.05 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 78.96 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 79.07 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 79.03 ms 68.86.211.122
- 17 78.98 ms 162.151.182.174
- 18 79.07 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 ...
- 20 105.13 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- NSE: Script Post-scanning.
- Initiating NSE at 05:02
- Completed NSE at 05:02, 0.00s elapsed
- Initiating NSE at 05:02
- Completed NSE at 05:02, 0.00s elapsed
- #######################################################################################################################################
- http://fuhrernet.com [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], Meta-Refresh-Redirect[./login.php], Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], Script, Title[Newsfeed], X-Powered-By[PHP/7.1.1]
- http://fuhrernet.com/login.php [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], JQuery, Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], PasswordField[password], Script[text/javascript], Title[Login to Führernet], X-Powered-By[PHP/7.1.1]
- #######################################################################################################################################
- wig - WebApp Information Gatherer
- Scanning http://fuhrernet.com...
- ____________________ SITE INFO ____________________
- IP Title
- 68.81.58.227 Newsfeed
- _____________________ VERSION _____________________
- Name Versions Type
- Apache 2.4.25 Platform
- PHP 7.1.1 Platform
- openssl 1.0.2j Platform
- FreeBSD 10 | 11 OS
- openSUSE tumbleweed OS
- ___________________ INTERESTING ___________________
- URL Note Type
- /test.html Test file Interesting
- /login.php Login Page Interesting
- /phpinfo.php PHP info file Interesting
- /test/ Test directory Interesting
- ___________________________________________________
- Time: 60.2 sec Urls: 846 Fingerprints: 40401
- #######################################################################################################################################
- HTTP/1.1 200 OK
- Date: Sat, 28 Sep 2019 09:04:00 GMT
- Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- X-Powered-By: PHP/7.1.1
- Content-Type: text/html; charset=UTF-8
- HTTP/1.1 200 OK
- Date: Sat, 28 Sep 2019 09:04:00 GMT
- Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- X-Powered-By: PHP/7.1.1
- Content-Type: text/html; charset=UTF-8
- ######################################################################################################################################
- ------------------------------------------------------------------------------------------------------------------------
- [ ! ] Starting SCANNER INURLBR 2.1 at [28-09-2019 05:04:26]
- [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
- It is the end user's responsibility to obey all applicable local, state and federal laws.
- Developers assume no liability and are not responsible for any misuse or damage caused by this program
- [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
- [ INFO ][ DORK ]::[ site:fuhrernet.com ]
- [ INFO ][ SEARCHING ]:: {
- [ INFO ][ ENGINE ]::[ GOOGLE - www.google.nu ]
- [ INFO ][ SEARCHING ]::
- -[:::]
- [ INFO ][ ENGINE ]::[ GOOGLE API ]
- [ INFO ][ SEARCHING ]::
- -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
- [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.mv ID: 012873187529719969291:yexdhbzntue ]
- [ INFO ][ SEARCHING ]::
- -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
- [ INFO ][ TOTAL FOUND VALUES ]:: [ 4 ]
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 0 / 4 ]-[05:04:41] [ - ]
- |_[ + ] Target:: [ http://fuhrernet.com/ ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 1 / 4 ]-[05:04:42] [ - ]
- |_[ + ] Target:: [ http://fuhrernet.com/forgot-username.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 2 / 4 ]-[05:04:43] [ - ]
- |_[ + ] Target:: [ http://www.fuhrernet.com/forgot-password.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 3 / 4 ]-[05:04:44] [ - ]
- |_[ + ] Target:: [ http://www.fuhrernet.com/create-account.php ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- [ INFO ] [ Shutting down ]
- [ INFO ] [ End of process INURLBR at [28-09-2019 05:04:44]
- [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
- [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
- |_________________________________________________________________________________________
- \_________________________________________________________________________________________/
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 05:04 EDT
- NSE: Loaded 164 scripts for scanning.
- NSE: Script Pre-scanning.
- Initiating NSE at 05:04
- Completed NSE at 05:04, 0.00s elapsed
- Initiating NSE at 05:04
- Completed NSE at 05:04, 0.00s elapsed
- Initiating Parallel DNS resolution of 1 host. at 05:04
- Completed Parallel DNS resolution of 1 host. at 05:04, 0.02s elapsed
- Initiating SYN Stealth Scan at 05:04
- Scanning fuhrernet.com (68.81.58.227) [1 port]
- Completed SYN Stealth Scan at 05:04, 0.54s elapsed (1 total ports)
- Initiating Service scan at 05:04
- Initiating OS detection (try #1) against fuhrernet.com (68.81.58.227)
- Retrying OS detection (try #2) against fuhrernet.com (68.81.58.227)
- Initiating Traceroute at 05:04
- Completed Traceroute at 05:04, 0.13s elapsed
- Initiating Parallel DNS resolution of 19 hosts. at 05:04
- Completed Parallel DNS resolution of 19 hosts. at 05:04, 0.15s elapsed
- NSE: Script scanning 68.81.58.227.
- Initiating NSE at 05:04
- Completed NSE at 05:04, 0.22s elapsed
- Initiating NSE at 05:04
- Completed NSE at 05:04, 0.00s elapsed
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.048s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- PORT STATE SERVICE VERSION
- 443/tcp filtered https
- Too many fingerprints match this host to give specific OS details
- Network Distance: 19 hops
- TRACEROUTE (using proto 1/icmp)
- HOP RTT ADDRESS
- 1 49.76 ms 10.244.204.1
- 2 49.81 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 69.35 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 49.83 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 49.85 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 49.87 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 49.88 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 49.90 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 49.91 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 28.97 ms if-ae-7-2.tcore1.nto-new-york.as6453.net (63.243.128.25)
- 11 59.56 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 59.29 ms 66.110.96.146
- 13 59.33 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 59.29 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 59.32 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 59.34 ms 68.86.211.122
- 17 59.29 ms 162.151.182.174
- 18 59.32 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 78.99 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- NSE: Script Post-scanning.
- Initiating NSE at 05:04
- Completed NSE at 05:04, 0.00s elapsed
- Initiating NSE at 05:04
- Completed NSE at 05:04, 0.00s elapsed
- #######################################################################################################################################
- Version: 1.11.13-static
- OpenSSL 1.0.2-chacha (1.0.2g-dev)
- Connected to 68.81.58.227
- Testing SSL server fuhrernet.com on port 443 using SNI name fuhrernet.com
- TLS Fallback SCSV:
- Server supports TLS Fallback SCSV
- TLS renegotiation:
- Secure session renegotiation supported
- TLS Compression:
- Compression disabled
- Heartbleed:
- TLS 1.2 not vulnerable to heartbleed
- TLS 1.1 not vulnerable to heartbleed
- TLS 1.0 not vulnerable to heartbleed
- Supported Server Cipher(s):
- Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
- Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
- Accepted TLSv1.1 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
- Accepted TLSv1.1 256 bits AES256-SHA
- Accepted TLSv1.1 256 bits CAMELLIA256-SHA
- Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
- Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
- Accepted TLSv1.0 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
- Accepted TLSv1.0 256 bits AES256-SHA
- Accepted TLSv1.0 256 bits CAMELLIA256-SHA
- Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
- Accepted TLSv1.0 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
- Accepted TLSv1.0 128 bits AES128-SHA
- Accepted TLSv1.0 128 bits CAMELLIA128-SHA
- Accepted TLSv1.0 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
- Accepted TLSv1.0 128 bits SEED-SHA
- Accepted TLSv1.0 128 bits IDEA-CBC-SHA
- Accepted TLSv1.0 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
- Accepted TLSv1.0 112 bits DES-CBC3-SHA
- SSL Certificate:
- Signature Algorithm: sha1WithRSAEncryption
- RSA Key Strength: 1024
- Subject: localhost
- Issuer: localhost
- Not valid before: Nov 10 23:48:47 2009 GMT
- Not valid after: Nov 8 23:48:47 2019 GMT
- ######################################################################################################################################
- ------------------------------------------------------------------------------------------------------------------------
- [ ! ] Starting SCANNER INURLBR 2.1 at [28-09-2019 05:09:05]
- [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
- It is the end user's responsibility to obey all applicable local, state and federal laws.
- Developers assume no liability and are not responsible for any misuse or damage caused by this program
- [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
- [ INFO ][ DORK ]::[ site:fuhrernet.com ]
- [ INFO ][ SEARCHING ]:: {
- [ INFO ][ ENGINE ]::[ GOOGLE - www.google.cv ]
- [ INFO ][ SEARCHING ]::
- -[:::]
- [ INFO ][ ENGINE ]::[ GOOGLE API ]
- [ INFO ][ SEARCHING ]::
- -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
- [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.ro ID: 010479943387663786936:wjwf2xkhfmq ]
- [ INFO ][ SEARCHING ]::
- -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
- [ INFO ][ TOTAL FOUND VALUES ]:: [ 4 ]
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 0 / 4 ]-[05:09:18] [ - ]
- |_[ + ] Target:: [ http://fuhrernet.com/ ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 1 / 4 ]-[05:09:18] [ - ]
- |_[ + ] Target:: [ http://fuhrernet.com/forgot-username.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 2 / 4 ]-[05:09:19] [ - ]
- |_[ + ] Target:: [ http://www.fuhrernet.com/forgot-password.html ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 , IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- _[ - ]::--------------------------------------------------------------------------------------------------------------
- |_[ + ] [ 3 / 4 ]-[05:09:20] [ - ]
- |_[ + ] Target:: [ http://www.fuhrernet.com/create-account.php ]
- |_[ + ] Exploit::
- |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1 X-Powered-By: PHP/7.1.1, IP:68.81.58.227:80
- |_[ + ] More details:: / - / , ISP:
- |_[ + ] Found:: UNIDENTIFIED
- [ INFO ] [ Shutting down ]
- [ INFO ] [ End of process INURLBR at [28-09-2019 05:09:20]
- [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
- [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/fuhrernet.com/output/inurlbr-fuhrernet.com ]
- |_________________________________________________________________________________________
- \_________________________________________________________________________________________/
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 05:09 EDT
- Nmap scan report for fuhrernet.com (68.81.58.227)
- Host is up (0.16s latency).
- rDNS record for 68.81.58.227: c-68-81-58-227.hsd1.pa.comcast.net
- PORT STATE SERVICE VERSION
- 3306/tcp open mysql MariaDB (unauthorized)
- | mysql-brute:
- | Accounts: No valid accounts found
- |_ Statistics: Performed 42 guesses in 112 seconds, average tps: 0.4
- |_mysql-empty-password: Host '176.113.74.60' is not allowed to connect to this MariaDB server
- | mysql-enum:
- | Accounts: No valid accounts found
- |_ Statistics: Performed 5 guesses in 9 seconds, average tps: 0.6
- |_mysql-vuln-cve2012-2122: ERROR: Script execution failed (use -d to debug)
- |_vulscan: ERROR: Script execution failed (use -d to debug)
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Device type: specialized|general purpose
- Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (85%)
- OS CPE: cpe:/o:freebsd:freebsd:6.2
- Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (85%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 20 hops
- TRACEROUTE (using port 3306/tcp)
- HOP RTT ADDRESS
- 1 39.72 ms 10.244.204.1
- 2 39.81 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 39.87 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 39.86 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 39.83 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 40.05 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 39.96 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 40.00 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 40.08 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 40.10 ms if-ae-7-2.tcore1.nto-new-york.as6453.net (63.243.128.25)
- 11 89.63 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 150.76 ms 66.110.96.138
- 13 150.83 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 150.78 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 150.81 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 150.77 ms 68.86.211.122
- 17 150.72 ms 162.151.182.174
- 18 150.78 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 ...
- 20 150.77 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
- Nmap done: 1 IP address (1 host up) scanned in 122.77 seconds
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:44 EDT
- Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Host is up (0.059s latency).
- Not shown: 473 filtered ports, 6 closed ports
- Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
- PORT STATE SERVICE
- 21/tcp open ftp
- 80/tcp open http
- 443/tcp open https
- 3306/tcp open mysql
- Nmap done: 1 IP address (1 host up) scanned in 61.34 seconds
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:45 EDT
- Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Host is up (0.036s latency).
- Not shown: 2 filtered ports
- PORT STATE SERVICE
- 53/udp open|filtered domain
- 67/udp open|filtered dhcps
- 68/udp open|filtered dhcpc
- 69/udp open|filtered tftp
- 88/udp open|filtered kerberos-sec
- 123/udp open|filtered ntp
- 139/udp open|filtered netbios-ssn
- 161/udp open|filtered snmp
- 162/udp open|filtered snmptrap
- 389/udp open|filtered ldap
- 500/udp open|filtered isakmp
- 520/udp open|filtered route
- 2049/udp open|filtered nfs
- Nmap done: 1 IP address (1 host up) scanned in 1.78 seconds
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:45 EDT
- NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
- NSE: [ftp-brute] usernames: Time limit 3m00s exceeded.
- NSE: [ftp-brute] passwords: Time limit 3m00s exceeded.
- Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Host is up (0.085s latency).
- PORT STATE SERVICE VERSION
- 21/tcp open ftp FileZilla ftpd 0.9.41 beta
- | ftp-brute:
- | Accounts: No valid accounts found
- |_ Statistics: Performed 247 guesses in 181 seconds, average tps: 1.6
- | ftp-syst:
- |_ SYST: UNIX emulated by FileZilla
- |_vulscan: ERROR: Script execution failed (use -d to debug)
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Device type: specialized|general purpose
- Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (87%)
- OS CPE: cpe:/o:freebsd:freebsd:6.2
- Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (87%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 20 hops
- Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
- TRACEROUTE (using port 21/tcp)
- HOP RTT ADDRESS
- 1 31.52 ms 10.244.204.1
- 2 61.24 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 61.37 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 61.22 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 61.29 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 61.39 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 61.35 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 61.45 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 61.37 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 61.47 ms if-ae-7-2.tcore1.nto-new-york.as6453.net (63.243.128.25)
- 11 50.11 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 40.11 ms 66.110.96.150
- 13 59.79 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 59.81 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 59.82 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 59.81 ms 68.86.211.122
- 17 59.80 ms 162.151.182.174
- 18 59.81 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 ...
- 20 79.65 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:49 EDT
- NSE: Loaded 164 scripts for scanning.
- NSE: Script Pre-scanning.
- Initiating NSE at 04:49
- Completed NSE at 04:49, 0.00s elapsed
- Initiating NSE at 04:49
- Completed NSE at 04:49, 0.00s elapsed
- Initiating Parallel DNS resolution of 1 host. at 04:49
- Completed Parallel DNS resolution of 1 host. at 04:49, 0.03s elapsed
- Initiating SYN Stealth Scan at 04:49
- Scanning c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227) [1 port]
- Discovered open port 80/tcp on 68.81.58.227
- Completed SYN Stealth Scan at 04:49, 0.10s elapsed (1 total ports)
- Initiating Service scan at 04:49
- Scanning 1 service on c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Completed Service scan at 04:49, 6.11s elapsed (1 service on 1 host)
- Initiating OS detection (try #1) against c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Retrying OS detection (try #2) against c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Initiating Traceroute at 04:49
- Completed Traceroute at 04:49, 3.09s elapsed
- Initiating Parallel DNS resolution of 19 hosts. at 04:49
- Completed Parallel DNS resolution of 19 hosts. at 04:49, 0.27s elapsed
- NSE: Script scanning 68.81.58.227.
- Initiating NSE at 04:49
- Completed NSE at 04:49, 26.57s elapsed
- Initiating NSE at 04:49
- Completed NSE at 04:49, 0.39s elapsed
- Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Host is up (0.091s latency).
- PORT STATE SERVICE VERSION
- 80/tcp open http Apache httpd 2.4.25 ((Win32) OpenSSL/1.0.2j PHP/7.1.1)
- | http-brute:
- |_ Path "/" does not require authentication
- |_http-chrono: Request times for /; avg: 432.70ms; min: 312.10ms; max: 583.81ms
- |_http-csrf: Couldn't find any CSRF vulnerabilities.
- |_http-date: Sat, 28 Sep 2019 08:49:28 GMT; -5s from local time.
- |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
- |_http-dombased-xss: Couldn't find any DOM based XSS.
- |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
- |_http-errors: Couldn't find any error pages.
- |_http-feed: Couldn't find any feeds.
- |_http-fetch: Please enter the complete path of the directory to save data in.
- | http-headers:
- | Date: Sat, 28 Sep 2019 08:49:26 GMT
- | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- | X-Powered-By: PHP/7.1.1
- | Connection: close
- | Content-Type: text/html; charset=UTF-8
- |
- |_ (Request type: HEAD)
- |_http-jsonp-detection: Couldn't find any JSONP endpoints.
- |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
- | http-methods:
- |_ Supported Methods: GET HEAD POST OPTIONS
- |_http-mobileversion-checker: No mobile version detected.
- | http-php-version: Logo query returned unknown hash 493264b1ea71e8083a6356206999ff80
- | Credits query returned unknown hash 493264b1ea71e8083a6356206999ff80
- |_Version from header x-powered-by: PHP/7.1.1
- |_http-security-headers:
- |_http-server-header: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- | http-sitemap-generator:
- | Directory structure:
- | /
- | Other: 1; png: 3; webmanifest: 1
- | /assets/bootstrap/css/
- | css: 1
- | /assets/css/
- | css: 6
- | /assets/fonts/
- | css: 1
- | Longest directory structure:
- | Depth: 3
- | Dir: /assets/bootstrap/css/
- | Total files found (by extension):
- |_ Other: 1; css: 8; png: 3; webmanifest: 1
- |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
- |_http-title: Newsfeed
- | http-trace: TRACE is enabled
- | Headers:
- | Date: Sat, 28 Sep 2019 08:49:29 GMT
- | Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- | Connection: close
- | Transfer-Encoding: chunked
- |_Content-Type: message/http
- | http-vhosts:
- |_127 names had status 200
- | http-vuln-cve2010-0738:
- |_ /jmx-console/: Authentication was not required
- |_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
- |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
- |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-xssed: No previously reported XSS vuln.
- | vulners:
- | cpe:/a:apache:http_server:2.4.25:
- | CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
- | CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
- | CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
- | CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
- | CVE-2019-0211 7.2 https://vulners.com/cve/CVE-2019-0211
- | CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
- | CVE-2017-15715 6.8 https://vulners.com/cve/CVE-2017-15715
- | CVE-2019-10082 6.4 https://vulners.com/cve/CVE-2019-10082
- | CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
- | CVE-2019-10098 5.8 https://vulners.com/cve/CVE-2019-10098
- | CVE-2019-10081 5.0 https://vulners.com/cve/CVE-2019-10081
- | CVE-2019-0220 5.0 https://vulners.com/cve/CVE-2019-0220
- | CVE-2019-0196 5.0 https://vulners.com/cve/CVE-2019-0196
- | CVE-2018-17199 5.0 https://vulners.com/cve/CVE-2018-17199
- | CVE-2018-1333 5.0 https://vulners.com/cve/CVE-2018-1333
- | CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
- | CVE-2017-7659 5.0 https://vulners.com/cve/CVE-2017-7659
- | CVE-2017-15710 5.0 https://vulners.com/cve/CVE-2017-15710
- | CVE-2019-0197 4.9 https://vulners.com/cve/CVE-2019-0197
- | CVE-2019-10092 4.3 https://vulners.com/cve/CVE-2019-10092
- | CVE-2018-11763 4.3 https://vulners.com/cve/CVE-2018-11763
- |_ CVE-2018-1283 3.5 https://vulners.com/cve/CVE-2018-1283
- |_vulscan: ERROR: Script execution failed (use -d to debug)
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Device type: specialized|general purpose
- Running (JUST GUESSING): AVtech embedded (87%), FreeBSD 6.X (87%)
- OS CPE: cpe:/o:freebsd:freebsd:6.2
- Aggressive OS guesses: AVtech Room Alert 26W environmental monitor (87%), FreeBSD 6.2-RELEASE (87%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 20 hops
- TCP Sequence Prediction: Difficulty=258 (Good luck!)
- IP ID Sequence Generation: Incremental
- TRACEROUTE (using port 80/tcp)
- HOP RTT ADDRESS
- 1 51.19 ms 10.244.204.1
- 2 71.05 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 71.06 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 71.04 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 71.06 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 71.11 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 71.11 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 71.15 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 71.14 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 29.99 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
- 11 60.35 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 50.40 ms 66.110.96.146
- 13 49.87 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 49.88 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 49.90 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 49.91 ms 68.86.211.122
- 17 49.88 ms 162.151.182.174
- 18 49.92 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 ...
- 20 69.70 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- NSE: Script Post-scanning.
- Initiating NSE at 04:49
- Completed NSE at 04:49, 0.00s elapsed
- Initiating NSE at 04:49
- Completed NSE at 04:49, 0.00s elapsed
- #######################################################################################################################################
- http://68.81.58.227 [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], Meta-Refresh-Redirect[./login.php], Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], Script, Title[Newsfeed], X-Powered-By[PHP/7.1.1]
- http://68.81.58.227/login.php [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], JQuery, Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], PasswordField[password], Script[text/javascript], Title[Login to Führernet], X-Powered-By[PHP/7.1.1]
- #######################################################################################################################################
- wig - WebApp Information Gatherer
- Scanning http://68.81.58.227...
- ____________________ SITE INFO ____________________
- IP Title
- 68.81.58.227 Newsfeed
- _____________________ VERSION _____________________
- Name Versions Type
- Apache 2.4.25 Platform
- PHP 7.1.1 Platform
- openssl 1.0.2j Platform
- FreeBSD 10 | 11 OS
- openSUSE tumbleweed OS
- ___________________ INTERESTING ___________________
- URL Note Type
- /test.html Test file Interesting
- /login.php Login Page Interesting
- /phpinfo.php PHP info file Interesting
- /test/ Test directory Interesting
- ___________________________________________________
- Time: 29.6 sec Urls: 846 Fingerprints: 40401
- #######################################################################################################################################
- HTTP/1.1 200 OK
- Date: Sat, 28 Sep 2019 08:50:27 GMT
- Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- X-Powered-By: PHP/7.1.1
- Content-Type: text/html; charset=UTF-8
- HTTP/1.1 200 OK
- Date: Sat, 28 Sep 2019 08:50:27 GMT
- Server: Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1
- X-Powered-By: PHP/7.1.1
- Content-Type: text/html; charset=UTF-8
- #######################################################################################################################################
- https://68.81.58.227 [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], Meta-Refresh-Redirect[./login.php], Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], Script, Title[Newsfeed], X-Powered-By[PHP/7.1.1]
- https://68.81.58.227/login.php [200 OK] Apache[2.4.25], Country[UNITED STATES][US], HTML5, HTTPServer[Windows (32 bit)][Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/7.1.1], IP[68.81.58.227], JQuery, Open-Graph-Protocol[website], OpenSSL[1.0.2j], PHP[7.1.1], PasswordField[password], Script[text/javascript], Title[Login to Führernet], X-Powered-By[PHP/7.1.1]
- #######################################################################################################################################
- Version: 1.11.13-static
- OpenSSL 1.0.2-chacha (1.0.2g-dev)
- Connected to 68.81.58.227
- Testing SSL server 68.81.58.227 on port 443 using SNI name 68.81.58.227
- TLS Fallback SCSV:
- Server supports TLS Fallback SCSV
- TLS renegotiation:
- Secure session renegotiation supported
- TLS Compression:
- Compression disabled
- Heartbleed:
- TLS 1.2 not vulnerable to heartbleed
- TLS 1.1 not vulnerable to heartbleed
- TLS 1.0 not vulnerable to heartbleed
- Supported Server Cipher(s):
- Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-256 DHE 256
- Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
- Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384 DHE 1024 bits
- Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA256 DHE 1024 bits
- Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
- Accepted TLSv1.2 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
- Accepted TLSv1.2 256 bits AES256-GCM-SHA384
- Accepted TLSv1.2 256 bits AES256-SHA256
- Accepted TLSv1.2 256 bits AES256-SHA
- Accepted TLSv1.2 256 bits CAMELLIA256-SHA
- Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-GCM-SHA256 Curve P-256 DHE 256
- Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
- Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256 DHE 1024 bits
- Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA256 DHE 1024 bits
- Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
- Accepted TLSv1.2 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
- Accepted TLSv1.2 128 bits AES128-GCM-SHA256
- Accepted TLSv1.2 128 bits AES128-SHA256
- Accepted TLSv1.2 128 bits AES128-SHA
- Accepted TLSv1.2 128 bits CAMELLIA128-SHA
- Accepted TLSv1.2 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
- Accepted TLSv1.2 128 bits SEED-SHA
- Accepted TLSv1.2 128 bits IDEA-CBC-SHA
- Accepted TLSv1.2 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
- Accepted TLSv1.2 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
- Accepted TLSv1.2 112 bits DES-CBC3-SHA
- Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
- Accepted TLSv1.1 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
- Accepted TLSv1.1 256 bits AES256-SHA
- Accepted TLSv1.1 256 bits CAMELLIA256-SHA
- Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
- Accepted TLSv1.1 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
- Accepted TLSv1.1 128 bits AES128-SHA
- Accepted TLSv1.1 128 bits CAMELLIA128-SHA
- Accepted TLSv1.1 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
- Accepted TLSv1.1 128 bits SEED-SHA
- Accepted TLSv1.1 128 bits IDEA-CBC-SHA
- Accepted TLSv1.1 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
- Accepted TLSv1.1 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
- Accepted TLSv1.1 112 bits DES-CBC3-SHA
- Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
- Accepted TLSv1.0 256 bits DHE-RSA-CAMELLIA256-SHA DHE 1024 bits
- Accepted TLSv1.0 256 bits AES256-SHA
- Accepted TLSv1.0 256 bits CAMELLIA256-SHA
- Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
- Accepted TLSv1.0 128 bits DHE-RSA-CAMELLIA128-SHA DHE 1024 bits
- Accepted TLSv1.0 128 bits AES128-SHA
- Accepted TLSv1.0 128 bits CAMELLIA128-SHA
- Accepted TLSv1.0 128 bits DHE-RSA-SEED-SHA DHE 1024 bits
- Accepted TLSv1.0 128 bits SEED-SHA
- Accepted TLSv1.0 128 bits IDEA-CBC-SHA
- Accepted TLSv1.0 112 bits ECDHE-RSA-DES-CBC3-SHA Curve P-256 DHE 256
- Accepted TLSv1.0 112 bits EDH-RSA-DES-CBC3-SHA DHE 1024 bits
- Accepted TLSv1.0 112 bits DES-CBC3-SHA
- SSL Certificate:
- Signature Algorithm: sha1WithRSAEncryption
- RSA Key Strength: 1024
- Subject: localhost
- Issuer: localhost
- Not valid before: Nov 10 23:48:47 2009 GMT
- Not valid after: Nov 8 23:48:47 2019 GMT
- #######################################################################################################################################
- Starting Nmap 7.80 ( https://nmap.org ) at 2019-09-28 04:51 EDT
- Nmap scan report for c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- Host is up (0.077s latency).
- PORT STATE SERVICE VERSION
- 3306/tcp open mysql MariaDB (unauthorized)
- | mysql-brute:
- | Accounts: No valid accounts found
- |_ Statistics: Performed 9415 guesses in 244 seconds, average tps: 60.1
- |_mysql-empty-password: Host '176.113.74.60' is not allowed to connect to this MariaDB server
- | mysql-enum:
- | Accounts: No valid accounts found
- |_ Statistics: Performed 10 guesses in 1 seconds, average tps: 10.0
- |_mysql-vuln-cve2012-2122: ERROR: Script execution failed (use -d to debug)
- |_vulscan: ERROR: Script execution failed (use -d to debug)
- Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
- Device type: general purpose|router
- Running (JUST GUESSING): FreeBSD 6.X (87%), Linksys embedded (86%)
- OS CPE: cpe:/o:freebsd:freebsd:6.2
- Aggressive OS guesses: FreeBSD 6.2-RELEASE (87%), Linksys BEFSR41 EtherFast router (86%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 20 hops
- TRACEROUTE (using port 3306/tcp)
- HOP RTT ADDRESS
- 1 49.43 ms 10.244.204.1
- 2 69.07 ms vlan102.as02.qc1.ca.m247.com (176.113.74.17)
- 3 69.10 ms irb-0.agg1.qc1.ca.m247.com (37.120.128.168)
- 4 69.04 ms te-1-5-2-0.bb1.fra2.de.m247.com (82.102.29.44)
- 5 69.08 ms ix-xe-11-1-1-0.tcore1.w6c-montreal.as6453.net (66.198.96.98)
- 6 69.17 ms if-ae-12-2.tcore1.mtt-montreal.as6453.net (64.86.31.26)
- 7 69.16 ms if-ae-0-2.tcore2.mtt-montreal.as6453.net (216.6.115.90)
- 8 69.20 ms if-ae-5-2.tcore2.n0v-new-york.as6453.net (64.86.226.58)
- 9 69.16 ms if-ae-2-2.tcore1.n0v-new-york.as6453.net (216.6.90.21)
- 10 29.39 ms if-ae-7-5.tcore1.nto-new-york.as6453.net (63.243.128.141)
- 11 58.46 ms if-ae-9-2.tcore1.n75-new-york.as6453.net (63.243.128.122)
- 12 58.44 ms 66.110.96.150
- 13 58.31 ms be-10390-cr02.newyork.ny.ibone.comcast.net (68.86.83.89)
- 14 58.31 ms be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185)
- 15 58.28 ms be-7922-ar03.ivyland.pa.panjde.comcast.net (68.86.93.174)
- 16 58.31 ms 68.86.211.122
- 17 58.19 ms 162.151.182.174
- 18 58.31 ms lag1-acr22.levittown.pa.panjde.comcast.net (68.85.78.58)
- 19 ...
- 20 78.05 ms c-68-81-58-227.hsd1.pa.comcast.net (68.81.58.227)
- #######################################################################################################################################
- Anonymous JTSEC #OpDomesticTerrorism Full Recon #3
Advertisement
Add Comment
Please, Sign In to add comment