JTSEC1333

Anonymous JTSEC #OpTurkey Full Recon `2

Oct 10th, 2019
746
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 318.31 KB | None | 0 0
  1. #######################################################################################################################################
  2. =======================================================================================================================================
  3. Hostname en.hmb.gov.tr ISP Turk Telekom
  4. Continent Asia Flag
  5. TR
  6. Country Turkey Country Code TR
  7. Region Unknown Local time 11 Oct 2019 06:19 +03
  8. City Unknown Postal Code Unknown
  9. IP Address 212.174.188.50 Latitude 41.021
  10. Longitude 28.995
  11. ======================================================================================================================================
  12. #######################################################################################################################################
  13. > en.hmb.gov.tr
  14. Server: 38.132.106.139
  15. Address: 38.132.106.139#53
  16.  
  17. Non-authoritative answer:
  18. Name: en.hmb.gov.tr
  19. Address: 212.174.188.50
  20. >
  21. #######################################################################################################################################
  22. [+] Target : en.hmb.gov.tr
  23.  
  24. [+] IP Address : 212.174.188.50
  25.  
  26. [+] Headers :
  27.  
  28. [+] Server : nginx
  29. [+] Date : Fri, 11 Oct 2019 03:26:41 GMT
  30. [+] Content-Type : text/html
  31. [+] Last-Modified : Mon, 07 Oct 2019 13:24:44 GMT
  32. [+] Transfer-Encoding : chunked
  33. [+] Connection : keep-alive
  34. [+] ETag : W/"5d9b3c9c-1837"
  35. [+] Content-Encoding : gzip
  36.  
  37. [+] SSL Certificate Information :
  38.  
  39. [+] countryName : TR
  40. [+] stateOrProvinceName : Ankara
  41. [+] localityName : Cankaya
  42. [+] organizationalUnitName : Bilgi Islem Dairesi
  43. [+] organizationName : Hazine ve Maliye Bakanligi
  44. [+] commonName : *.hmb.gov.tr
  45. [+] countryName : BE
  46. [+] organizationName : GlobalSign nv-sa
  47. [+] commonName : GlobalSign Organization Validation CA - SHA256 - G2
  48. [+] Version : 3
  49. [+] Serial Number : 7CA3923562E521E1BEDD787C
  50. [+] Not Before : Oct 5 16:39:41 2018 GMT
  51. [+] Not After : Oct 5 16:39:41 2020 GMT
  52. [+] OCSP : ('http://ocsp2.globalsign.com/gsorganizationvalsha2g2',)
  53. [+] subject Alt Name : (('DNS', '*.hmb.gov.tr'), ('DNS', 'hmb.gov.tr'))
  54. [+] CA Issuers : ('http://secure.globalsign.com/cacert/gsorganizationvalsha2g2r1.crt',)
  55. [+] CRL Distribution Points : ('http://crl.globalsign.com/gs/gsorganizationvalsha2g2.crl',)
  56.  
  57. [+] Whois Lookup :
  58.  
  59. [+] NIR : None
  60. [+] ASN Registry : ripencc
  61. [+] ASN : 9121
  62. [+] ASN CIDR : 212.174.128.0/17
  63. [+] ASN Country Code : TR
  64. [+] ASN Date : 1999-04-07
  65. [+] ASN Description : TTNET, TR
  66. [+] cidr : 212.174.188.0/24
  67. [+] name : MALIYE
  68. [+] handle : ED4533-RIPE
  69. [+] range : 212.174.188.0 - 212.174.188.255
  70. [+] description : MALIYE BAKANLIGI BILGI ISLEM DAIRESI BASKANLIGI
  71. [+] country : TR
  72. [+] state : None
  73. [+] city : None
  74. [+] address : Bilgi Islem Merkezi Kat:1 Dikmen/ANKARA
  75. [+] postal_code : None
  76. [+] emails : None
  77. [+] created : 1970-01-01T00:00:00Z
  78. [+] updated : 2017-10-02T09:00:57Z
  79.  
  80. [+] Crawling Target...
  81.  
  82. [+] Looking for robots.txt........[ Found ]
  83. [+] Extracting robots Links.......[ 1 ]
  84. [+] Looking for sitemap.xml.......[ Found ]
  85. [+] Extracting sitemap Links......[ 0 ]
  86. [+] Extracting CSS Links..........[ 2 ]
  87. [+] Extracting Javascript Links...[ 2 ]
  88. [+] Extracting Internal Links.....[ 0 ]
  89. [+] Extracting External Links.....[ 0 ]
  90. [+] Extracting Images.............[ 0 ]
  91.  
  92. [+] Total Links Extracted : 5
  93.  
  94. [+] Dumping Links in /opt/FinalRecon/dumps/en.hmb.gov.tr.dump
  95. [+] Completed!
  96. #######################################################################################################################################
  97. [+] Starting At 2019-10-10 23:27:29.368801
  98. [+] Collecting Information On: https://en.hmb.gov.tr/
  99. [#] Status: 200
  100. --------------------------------------------------
  101. [#] Web Server Detected: nginx
  102. [!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
  103. - Server: nginx
  104. - Date: Fri, 11 Oct 2019 03:26:50 GMT
  105. - Content-Type: text/html
  106. - Last-Modified: Mon, 07 Oct 2019 13:24:44 GMT
  107. - Transfer-Encoding: chunked
  108. - Connection: keep-alive
  109. - ETag: W/"5d9b3c9c-1837"
  110. - Content-Encoding: gzip
  111. --------------------------------------------------
  112. [#] Finding Location..!
  113. [#] as: AS9121 Turk Telekomunikasyon Anonim Sirketi
  114. [#] city: Ankara
  115. [#] country: Turkey
  116. [#] countryCode: TR
  117. [#] isp: TurkTelecom
  118. [#] lat: 39.9104
  119. [#] lon: 32.847
  120. [#] org:
  121. [#] query: 212.174.188.50
  122. [#] region: 06
  123. [#] regionName: Ankara
  124. [#] status: success
  125. [#] timezone: Europe/Istanbul
  126. [#] zip:
  127. --------------------------------------------------
  128. [x] Didn't Detect WAF Presence on: https://en.hmb.gov.tr/
  129. --------------------------------------------------
  130. [#] Starting Reverse DNS
  131. [!] Found 2 any Domain
  132. - hmb.gov.tr
  133. - muhasebat.hmb.gov.tr
  134. --------------------------------------------------
  135. [!] Scanning Open Port
  136. [#] 80/tcp open http
  137. [#] 443/tcp open https
  138. --------------------------------------------------
  139. [+] Collecting Information Disclosure!
  140. [#] Detecting sitemap.xml file
  141. [-] sitemap.xml file not Found!?
  142. [#] Detecting robots.txt file
  143. [!] robots.txt File Found: https://en.hmb.gov.tr//robots.txt
  144. [#] Detecting GNU Mailman
  145. [-] GNU Mailman App Not Detected!?
  146. --------------------------------------------------
  147. [+] Crawling Url Parameter On: https://en.hmb.gov.tr/
  148. --------------------------------------------------
  149. [#] Searching Html Form !
  150. [-] No Html Form Found!?
  151. --------------------------------------------------
  152. [-] No DOM Paramter Found!?
  153. --------------------------------------------------
  154. [-] No internal Dynamic Parameter Found!?
  155. --------------------------------------------------
  156. [!] 1 External Dynamic Parameter Discovered
  157. [#] https://fonts.googleapis.com/css?family=Open+Sans:300,400,500,700
  158. --------------------------------------------------
  159. [!] 29 Internal links Discovered
  160. [+] https://en.hmb.gov.tr///assets/vendor-2874a984551b4c780366c120d51dd084.css
  161. [+] https://en.hmb.gov.tr///assets/hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.css
  162. [+] https://en.hmb.gov.tr///favicon.ico
  163. [+] https://en.hmb.gov.tr///favicon-16x16.png
  164. [+] https://en.hmb.gov.tr///favicon-32x32.png
  165. [+] https://en.hmb.gov.tr///manifest.json
  166. [+] https://en.hmb.gov.tr///apple-touch-icon-57x57.png
  167. [+] https://en.hmb.gov.tr///apple-touch-icon-60x60.png
  168. [+] https://en.hmb.gov.tr///apple-touch-icon-72x72.png
  169. [+] https://en.hmb.gov.tr///apple-touch-icon-76x76.png
  170. [+] https://en.hmb.gov.tr///apple-touch-icon-114x114.png
  171. [+] https://en.hmb.gov.tr///apple-touch-icon-120x120.png
  172. [+] https://en.hmb.gov.tr///apple-touch-icon-144x144.png
  173. [+] https://en.hmb.gov.tr///apple-touch-icon-152x152.png
  174. [+] https://en.hmb.gov.tr///apple-touch-icon-167x167.png
  175. [+] https://en.hmb.gov.tr///apple-touch-icon-180x180.png
  176. [+] https://en.hmb.gov.tr///apple-touch-icon-1024x1024.png
  177. [+] https://en.hmb.gov.tr///apple-touch-startup-image-320x460.png
  178. [+] https://en.hmb.gov.tr///apple-touch-startup-image-640x920.png
  179. [+] https://en.hmb.gov.tr///apple-touch-startup-image-640x1096.png
  180. [+] https://en.hmb.gov.tr///apple-touch-startup-image-750x1294.png
  181. [+] https://en.hmb.gov.tr///apple-touch-startup-image-1182x2208.png
  182. [+] https://en.hmb.gov.tr///apple-touch-startup-image-1242x2148.png
  183. [+] https://en.hmb.gov.tr///apple-touch-startup-image-748x1024.png
  184. [+] https://en.hmb.gov.tr///apple-touch-startup-image-768x1004.png
  185. [+] https://en.hmb.gov.tr///apple-touch-startup-image-1496x2048.png
  186. [+] https://en.hmb.gov.tr///apple-touch-startup-image-1536x2008.png
  187. [+] https://en.hmb.gov.tr///coast-228x228.png
  188. [+] https://en.hmb.gov.tr///yandex-browser-manifest.json
  189. --------------------------------------------------
  190. [-] No External Link Found!?
  191. --------------------------------------------------
  192. [#] Mapping Subdomain..
  193. [!] Found 10 Subdomain
  194. - webmail.hmb.gov.tr
  195. - en.hmb.gov.tr
  196. - bkmybs.hmb.gov.tr
  197. - ms.hmb.gov.tr
  198. - muhasebat.hmb.gov.tr
  199. - www.hmb.gov.tr
  200. - mailgw01.hmb.gov.tr
  201. - mailgw02.hmb.gov.tr
  202. - mailgw03.hmb.gov.tr
  203. - mailgw04.hmb.gov.tr
  204. --------------------------------------------------
  205. [!] Done At 2019-10-10 23:28:16.979959
  206. #######################################################################################################################################
  207. [i] Scanning Site: https://en.hmb.gov.tr
  208.  
  209.  
  210.  
  211. B A S I C I N F O
  212. ====================
  213.  
  214.  
  215. [+] Site Title: T.C. Hazine ve Maliye Bakanlığı
  216. [+] IP address: 212.174.188.50
  217. [+] Web Server: nginx
  218. [+] CMS: Could Not Detect
  219. [+] Cloudflare: Not Detected
  220. [+] Robots File: Found
  221.  
  222. -------------[ contents ]----------------
  223. # http://www.robotstxt.org
  224. User-agent: *
  225. Disallow:
  226.  
  227. -----------[end of contents]-------------
  228.  
  229.  
  230.  
  231. W H O I S L O O K U P
  232. ========================
  233.  
  234. error check your api query
  235.  
  236.  
  237.  
  238. G E O I P L O O K U P
  239. =========================
  240.  
  241. [i] IP Address: 212.174.188.50
  242. [i] Country: Turkey
  243. [i] State: Istanbul
  244. [i] City: Bueyuekcekmece
  245. [i] Latitude: 41.0156
  246. [i] Longitude: 28.56
  247.  
  248.  
  249.  
  250.  
  251. H T T P H E A D E R S
  252. =======================
  253.  
  254.  
  255. [i] HTTP/1.1 200 OK
  256. [i] Server: nginx
  257. [i] Date: Fri, 11 Oct 2019 03:27:11 GMT
  258. [i] Content-Type: text/html
  259. [i] Content-Length: 6199
  260. [i] Last-Modified: Mon, 07 Oct 2019 13:24:44 GMT
  261. [i] Connection: close
  262. [i] ETag: "5d9b3c9c-1837"
  263. [i] Accept-Ranges: bytes
  264.  
  265.  
  266.  
  267.  
  268. D N S L O O K U P
  269. ===================
  270.  
  271. en.hmb.gov.tr. 3599 IN A 212.174.188.50
  272.  
  273.  
  274.  
  275.  
  276. S U B N E T C A L C U L A T I O N
  277. ====================================
  278.  
  279. Address = 212.174.188.50
  280. Network = 212.174.188.50 / 32
  281. Netmask = 255.255.255.255
  282. Broadcast = not needed on Point-to-Point links
  283. Wildcard Mask = 0.0.0.0
  284. Hosts Bits = 0
  285. Max. Hosts = 1 (2^0 - 0)
  286. Host Range = { 212.174.188.50 - 212.174.188.50 }
  287.  
  288.  
  289.  
  290. N M A P P O R T S C A N
  291. ============================
  292.  
  293. Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-11 03:27 UTC
  294. Nmap scan report for en.hmb.gov.tr (212.174.188.50)
  295. Host is up (0.13s latency).
  296.  
  297. PORT STATE SERVICE
  298. 21/tcp filtered ftp
  299. 22/tcp filtered ssh
  300. 23/tcp filtered telnet
  301. 80/tcp open http
  302. 110/tcp filtered pop3
  303. 143/tcp filtered imap
  304. 443/tcp open https
  305. 3389/tcp filtered ms-wbt-server
  306.  
  307. Nmap done: 1 IP address (1 host up) scanned in 19.07 seconds
  308.  
  309.  
  310. ########################################################################################################################################
  311. [INFO] ------TARGET info------
  312. [*] TARGET: https://en.hmb.gov.tr/
  313. [*] TARGET IP: 212.174.188.50
  314. [INFO] NO load balancer detected for en.hmb.gov.tr...
  315. [*] DNS servers: ns1.muhasebat.gov.tr.
  316. [*] TARGET server: nginx
  317. [*] CC: TR
  318. [*] Country: Turkey
  319. [*] RegionCode: 06
  320. [*] RegionName: Ankara
  321. [*] City: Ankara
  322. [*] ASN: AS9121
  323. [*] BGP_PREFIX: 212.174.0.0/15
  324. [*] ISP: TTNet Turk Telekomunikasyon Anonim Sirketi, TR
  325. [INFO] SSL/HTTPS certificate detected
  326. [*] Issuer: issuer=C = BE, O = GlobalSign nv-sa, CN = GlobalSign Organization Validation CA - SHA256 - G2
  327. [*] Subject: subject=C = TR, ST = Ankara, L = Cankaya, OU = Bilgi Islem Dairesi, O = Hazine ve Maliye Bakanligi, CN = *.hmb.gov.tr
  328. [INFO] DNS enumeration:
  329. [*] mail.hmb.gov.tr 212.174.188.10
  330. [*] ns1.hmb.gov.tr 212.174.189.24
  331. [*] ns2.hmb.gov.tr 212.174.189.29
  332. [*] vpn.hmb.gov.tr 212.174.189.60
  333. [*] webmail.hmb.gov.tr 212.174.188.9
  334. [INFO] Possible abuse mails are:
  335. [INFO] NO PAC (Proxy Auto Configuration) file FOUND
  336. [ALERT] robots.txt file FOUND in http://en.hmb.gov.tr/robots.txt
  337. [INFO] Checking for HTTP status codes recursively from http://en.hmb.gov.tr/robots.txt
  338. [INFO] Status code Folders
  339. [INFO] Starting FUZZing in http://en.hmb.gov.tr/FUzZzZzZzZz...
  340. [INFO] Status code Folders
  341. [*] 200 http://en.hmb.gov.tr/index
  342. [*] 200 http://en.hmb.gov.tr/download
  343. [*] 200 http://en.hmb.gov.tr/2006
  344. [*] 200 http://en.hmb.gov.tr/news
  345. [*] 200 http://en.hmb.gov.tr/crack
  346. [*] 200 http://en.hmb.gov.tr/serial
  347. [*] 200 http://en.hmb.gov.tr/warez
  348. [*] 200 http://en.hmb.gov.tr/full
  349. [*] 200 http://en.hmb.gov.tr/12
  350. [ALERT] Look in the source code. It may contain passwords
  351. [ALERT] Content in http://en.hmb.gov.tr/ AND http://www.en.hmb.gov.tr/ is different
  352. [INFO] MD5 for http://en.hmb.gov.tr/ is: b91692eed697bfce6e07bd7c3b7b7df1
  353. [INFO] MD5 for http://www.en.hmb.gov.tr/ is: d41d8cd98f00b204e9800998ecf8427e
  354. [INFO] http://en.hmb.gov.tr/ redirects to https://en.hmb.gov.tr/
  355. [INFO] http://www.en.hmb.gov.tr/ redirects to http://www.en.hmb.gov.tr/
  356. [INFO] SAME content in http://en.hmb.gov.tr/ AND http://212.174.188.50/
  357. [INFO] Links found from https://en.hmb.gov.tr/:
  358. [INFO] GOOGLE has 39,200,000 results (0.21 seconds) about http://en.hmb.gov.tr/
  359. [INFO] Shodan detected the following opened ports on 212.174.188.50:
  360. [*] 443
  361. [*] 80
  362. [INFO] ------VirusTotal SECTION------
  363. [INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
  364. [INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
  365. [INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
  366. [INFO] ------Alexa Rank SECTION------
  367. [INFO] Percent of Visitors Rank in Country:
  368. [INFO] Percent of Search Traffic:
  369. [INFO] Percent of Unique Visits:
  370. [INFO] Total Sites Linking In:
  371. [*] Total Sites
  372. [INFO] Useful links related to en.hmb.gov.tr - 212.174.188.50:
  373. [*] https://www.virustotal.com/pt/ip-address/212.174.188.50/information/
  374. [*] https://www.hybrid-analysis.com/search?host=212.174.188.50
  375. [*] https://www.shodan.io/host/212.174.188.50
  376. [*] https://www.senderbase.org/lookup/?search_string=212.174.188.50
  377. [*] https://www.alienvault.com/open-threat-exchange/ip/212.174.188.50
  378. [*] http://pastebin.com/search?q=212.174.188.50
  379. [*] http://urlquery.net/search.php?q=212.174.188.50
  380. [*] http://www.alexa.com/siteinfo/en.hmb.gov.tr
  381. [*] http://www.google.com/safebrowsing/diagnostic?site=en.hmb.gov.tr
  382. [*] https://censys.io/ipv4/212.174.188.50
  383. [*] https://www.abuseipdb.com/check/212.174.188.50
  384. [*] https://urlscan.io/search/#212.174.188.50
  385. [*] https://github.com/search?q=212.174.188.50&type=Code
  386. [INFO] Useful links related to AS9121 - 212.174.0.0/15:
  387. [*] http://www.google.com/safebrowsing/diagnostic?site=AS:9121
  388. [*] https://www.senderbase.org/lookup/?search_string=212.174.0.0/15
  389. [*] http://bgp.he.net/AS9121
  390. [*] https://stat.ripe.net/AS9121
  391. [INFO] Date: 10/10/19 | Time: 23:29:11
  392. [INFO] Total time: 1 minute(s) and 24 second(s)
  393. ########################################################################################################################################
  394. [*] Load target domain: en.hmb.gov.tr
  395. - starting scanning @ 2019-10-10 23:32:12
  396.  
  397. [+] Running & Checking source to be used
  398. ---------------------------------------------
  399.  
  400. ⍥ Shodan [ ✕ ]
  401. ⍥ Webarchive [ ✔ ]
  402. ⍥ Dnsdumpster [ ✔ ]
  403. ⍥ Binaryedge [ ✕ ]
  404. ⍥ Censys [ ✕ ]
  405. ⍥ Certspotter [ ✔ ]
  406. ⍥ Entrust [ ✔ ]
  407. ⍥ Threatcrowd [ ✔ ]
  408. ⍥ Certsh [ ✔ ]
  409. ⍥ Riddler [ ✔ ]
  410. ⍥ Threatminer [ ✔ ]
  411. ⍥ Virustotal [ ✕ ]
  412. ⍥ Bufferover [ ✔ ]
  413. ⍥ Hackertarget [ ✔ ]
  414. ⍥ Securitytrails [ ✕ ]
  415. ⍥ Findsubdomain [ ✔ ]
  416.  
  417. [+] Get & Count subdomain total From source
  418. ---------------------------------------------
  419.  
  420. ⍥ Hackertarget: Total Subdomain (1)
  421. ⍥ Findsubdomain: Total Subdomain (0)
  422. ⍥ Certspotter: Total Subdomain (0)
  423. ⍥ Threatminer: Total Subdomain (0)
  424. ⍥ Certsh: Total Subdomain (0)
  425. ⍥ BufferOver: Total Subdomain (0)
  426. ⍥ Entrust: Total Subdomain (0)
  427. ⍥ Threatcrowd: Total Subdomain (0)
  428. ⍥ Dnsdumpster: Total Subdomain (1)
  429. ⍥ Riddler: Total Subdomain (0)
  430. ⍥ Webarchive: Total Subdomain (1)
  431.  
  432. [+] Parsing & Sorting list Domain
  433. ---------------------------------------------
  434.  
  435. ⍥ Total [1]
  436.  
  437. - en.hmb.gov.tr
  438.  
  439. ⍥ Total [1]
  440.  
  441. [+] Probe subdomain for working on http/https
  442. ---------------------------------------------
  443.  
  444. - http://en.hmb.gov.tr
  445. - https://en.hmb.gov.tr
  446.  
  447. ⍥ Total [2]
  448.  
  449.  
  450. [+] Check Live Host: Ping Sweep - ICMP PING
  451. ---------------------------------------------
  452.  
  453. ⍥ [DEAD] en.hmb.gov.tr
  454.  
  455. [+] Check Resolving: Subdomains & Domains
  456. ---------------------------------------------
  457.  
  458. ⍥ Resolving domains to: 212.174.188.50
  459.  
  460. [+] Subdomain TakeOver - Check Possible Vulns
  461. ---------------------------------------------
  462.  
  463. ⍥ [FAILS] En: Unknown http://en.hmb.gov.tr
  464. ⍥ [FAILS] En: Unknown https://en.hmb.gov.tr
  465.  
  466. [+] Checks status code on port 80 and 443
  467. ---------------------------------------------
  468.  
  469. ⍥ [301] http://en.hmb.gov.tr
  470. ⍥ [200] https://en.hmb.gov.tr
  471.  
  472. [+] Web Screenshots: from domain list
  473. ---------------------------------------------
  474.  
  475. [+] 2 URLs to be screenshot
  476.  
  477. [+] 2 actual URLs screenshot
  478. [+] 0 error(s)
  479.  
  480. [+] Generate Reports: Make report into HTML
  481. ---------------------------------------------
  482.  
  483. ⍥ Make template for reports
  484. - output/10-10-2019/en.hmb.gov.tr/reports
  485.  
  486. ⍥ Successful Created ..
  487.  
  488. [+] Sud⍥my has been sucessfully completed
  489. ---------------------------------------------
  490.  
  491. ⍥ Location output:
  492. - output/10-10-2019/en.hmb.gov.tr
  493. - output/10-10-2019/en.hmb.gov.tr/report
  494. - output/10-10-2019/en.hmb.gov.tr/screenshots
  495.  
  496. #######################################################################################################################################
  497. Enter Address Website = en.hmb.gov.tr
  498.  
  499.  
  500.  
  501. Reversing IP With HackTarget 'en.hmb.gov.tr'
  502. -----------------------------------------------
  503.  
  504. [+] bahum.gov.tr
  505. [+] bkmybs.hmb.gov.tr
  506. [+] bumko.gov.tr
  507. [+] en.hmb.gov.tr
  508. [+] gep.gov.tr
  509. [+] hmb.gov.tr
  510. [+] icdenetim.gov.tr
  511. [+] kontrol.bumko.gov.tr
  512. [+] maliye-imid.gov.tr
  513. [+] maliye.gov.tr
  514. [+] ms.hmb.gov.tr
  515. [+] muhasebat.gov.tr
  516. [+] muhasebat.hmb.gov.tr
  517. [+] oib.gov.tr
  518. [+] pergen.gov.tr
  519. [+] sgb.gov.tr
  520. [+] sigortacilik.gov.tr
  521. [+] www.bahum.gov.tr
  522. [+] www.bumko.gov.tr
  523. [+] www.gep.gov.tr
  524. [+] www.hmb.gov.tr
  525. [+] www.icdenetim.gov.tr
  526. [+] www.maliye-imid.gov.tr
  527. [+] www.maliye.gov.tr
  528. [+] www.maliyekefalet.gov.tr
  529. [+] www.masak.gov.tr
  530. [+] www.muhasebat.gov.tr
  531. [+] www.oib.gov.tr
  532. [+] www.pergen.gov.tr
  533. [+] www.sgb.gov.tr
  534. [+] www.sigortacilik.gov.tr
  535. [+] www.vdk.gov.tr
  536.  
  537.  
  538.  
  539. Reverse IP With YouGetSignal 'en.hmb.gov.tr'
  540. -----------------------------------------------
  541.  
  542. [*] IP: 212.174.188.50
  543. [*] Domain: en.hmb.gov.tr
  544. [*] Total Domains: 3
  545.  
  546. [+] en.hmb.gov.tr
  547. [+] hmb.gov.tr
  548. [+] muhasebat.hmb.gov.tr
  549.  
  550.  
  551.  
  552. Geo IP Lookup 'en.hmb.gov.tr'
  553. --------------------------------
  554.  
  555. [+] IP Address: 212.174.188.50
  556. [+] Country: Turkey
  557. [+] State: Istanbul
  558. [+] City: Bueyuekcekmece
  559. [+] Latitude: 41.0156
  560. [+] Longitude: 28.56
  561.  
  562.  
  563.  
  564.  
  565. DNS Lookup 'en.hmb.gov.tr'
  566. -----------------------------
  567.  
  568. [+] en.hmb.gov.tr. 3599 IN A 212.174.188.50
  569.  
  570.  
  571.  
  572. Show HTTP Header 'en.hmb.gov.tr'
  573. -----------------------------------
  574.  
  575. [+] HTTP/1.1 301 Moved Permanently
  576. [+] Server: nginx
  577. [+] Date: Fri, 11 Oct 2019 03:30:00 GMT
  578. [+] Content-Type: text/html
  579. [+] Content-Length: 178
  580. [+] Connection: keep-alive
  581. [+] Location: https://en.hmb.gov.tr/
  582. [+]
  583.  
  584.  
  585.  
  586. Port Scan 'en.hmb.gov.tr'
  587. ----------------------------
  588.  
  589. Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-11 03:30 UTC
  590. Nmap scan report for en.hmb.gov.tr (212.174.188.50)
  591. Host is up (0.13s latency).
  592.  
  593. PORT STATE SERVICE
  594. 21/tcp filtered ftp
  595. 22/tcp filtered ssh
  596. 23/tcp filtered telnet
  597. 80/tcp open http
  598. 110/tcp filtered pop3
  599. 143/tcp filtered imap
  600. 443/tcp open https
  601. 3389/tcp filtered ms-wbt-server
  602.  
  603. Nmap done: 1 IP address (1 host up) scanned in 18.68 seconds
  604.  
  605.  
  606.  
  607.  
  608.  
  609. Robot.txt 'en.hmb.gov.tr'
  610. ----------------------------
  611.  
  612. # http://www.robotstxt.org
  613. User-agent: *
  614. Disallow:
  615.  
  616.  
  617.  
  618.  
  619. Traceroute 'en.hmb.gov.tr'
  620. -----------------------------
  621.  
  622. Start: 2019-10-11T03:31:06+0000
  623. HOST: web01 Loss% Snt Last Avg Best Wrst StDev
  624. 1.|-- 45.79.12.202 0.0% 3 0.7 0.6 0.6 0.7 0.0
  625. 2.|-- 45.79.12.2 0.0% 3 19.1 6.8 0.6 19.1 10.6
  626. 3.|-- 45.79.12.9 0.0% 3 0.5 10.1 0.5 23.8 12.1
  627. 4.|-- 199.245.16.65 0.0% 3 1.7 1.6 1.6 1.7 0.1
  628. 5.|-- ae-14.r22.dllstx09.us.bb.gin.ntt.net 0.0% 3 1.2 1.6 1.2 2.4 0.7
  629. 6.|-- ae-1.r22.asbnva02.us.bb.gin.ntt.net 0.0% 3 38.7 38.8 38.7 38.9 0.1
  630. 7.|-- ae-6.r25.frnkge08.de.bb.gin.ntt.net 0.0% 3 131.5 129.6 128.5 131.5 1.7
  631. 8.|-- ae-2.r01.frnkge13.de.bb.gin.ntt.net 0.0% 3 129.3 129.4 129.3 129.6 0.2
  632. 9.|-- nmf-0.r04.frnkge02.de.bb.gin.ntt.net 0.0% 3 127.9 128.0 127.9 128.0 0.0
  633. 10.|-- 06-ebgp-ulus1-k---301-fra-col-2.statik.turktelekom.com.tr 0.0% 3 171.8 168.9 167.4 171.8 2.5
  634. 11.|-- 212.156.117.186.29-gumushane-t3-1.25-erzurum-t2-1.statik.turktelekom.com.tr 0.0% 3 167.5 167.4 167.3 167.5 0.1
  635. 12.|-- 06-ulus-xrs-t2-1---06-ebgp-ulus1-k.statik.turktelekom.com.tr 0.0% 3 165.8 165.8 165.8 165.8 0.0
  636. 13.|-- 81.212.215.188.static.turktelekom.com.tr 0.0% 3 166.0 166.0 165.9 166.1 0.1
  637. 14.|-- mta4-v14.buaslanmis.com 0.0% 3 168.7 168.9 168.7 169.1 0.2
  638. 15.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
  639.  
  640.  
  641.  
  642. Page Admin Finder 'en.hmb.gov.tr'
  643. ------------------------------------
  644.  
  645.  
  646.  
  647. Avilable Links :
  648.  
  649. Find Page >> http://en.hmb.gov.tr/admin/
  650.  
  651. Find Page >> http://en.hmb.gov.tr/administrator/
  652.  
  653. Find Page >> http://en.hmb.gov.tr/admin1/
  654.  
  655. Find Page >> http://en.hmb.gov.tr/admin2/
  656.  
  657. Find Page >> http://en.hmb.gov.tr/admin3/
  658.  
  659. Find Page >> http://en.hmb.gov.tr/admin4/
  660.  
  661. Find Page >> http://en.hmb.gov.tr/admin5/
  662.  
  663. Find Page >> http://en.hmb.gov.tr/usuarios/
  664.  
  665. Find Page >> http://en.hmb.gov.tr/usuario/
  666.  
  667. Find Page >> http://en.hmb.gov.tr/moderator/
  668.  
  669. Find Page >> http://en.hmb.gov.tr/webadmin/
  670.  
  671. Find Page >> http://en.hmb.gov.tr/adminarea/
  672.  
  673. Find Page >> http://en.hmb.gov.tr/bb-admin/
  674.  
  675. Find Page >> http://en.hmb.gov.tr/adminLogin/
  676.  
  677. Find Page >> http://en.hmb.gov.tr/admin_area/
  678.  
  679. Find Page >> http://en.hmb.gov.tr/panel-administracion/
  680.  
  681. Find Page >> http://en.hmb.gov.tr/instadmin/
  682.  
  683. Find Page >> http://en.hmb.gov.tr/memberadmin/
  684.  
  685. Find Page >> http://en.hmb.gov.tr/administratorlogin/
  686.  
  687. Find Page >> http://en.hmb.gov.tr/adm/
  688.  
  689. Find Page >> http://en.hmb.gov.tr/siteadmin/login.html
  690.  
  691. Find Page >> http://en.hmb.gov.tr/admin/account.html
  692.  
  693. Find Page >> http://en.hmb.gov.tr/admin/index.html
  694.  
  695. Find Page >> http://en.hmb.gov.tr/admin/login.html
  696.  
  697. Find Page >> http://en.hmb.gov.tr/admin/admin.html
  698.  
  699. Find Page >> http://en.hmb.gov.tr/admin_area/login.html
  700.  
  701. Find Page >> http://en.hmb.gov.tr/admin_area/index.html
  702.  
  703. Find Page >> http://en.hmb.gov.tr/admincp/index.asp
  704.  
  705. Find Page >> http://en.hmb.gov.tr/admincp/login.asp
  706.  
  707. Find Page >> http://en.hmb.gov.tr/admincp/index.html
  708.  
  709. Find Page >> http://en.hmb.gov.tr/adminpanel.html
  710.  
  711. Find Page >> http://en.hmb.gov.tr/webadmin.html
  712.  
  713. Find Page >> http://en.hmb.gov.tr/webadmin/index.html
  714.  
  715. Find Page >> http://en.hmb.gov.tr/webadmin/admin.html
  716.  
  717. Find Page >> http://en.hmb.gov.tr/webadmin/login.html
  718.  
  719. Find Page >> http://en.hmb.gov.tr/admin/admin_login.html
  720.  
  721. Find Page >> http://en.hmb.gov.tr/admin_login.html
  722.  
  723. Find Page >> http://en.hmb.gov.tr/panel-administracion/login.html
  724.  
  725. Find Page >> http://en.hmb.gov.tr/admin_area/admin.html
  726.  
  727. Find Page >> http://en.hmb.gov.tr/bb-admin/index.html
  728.  
  729. Find Page >> http://en.hmb.gov.tr/bb-admin/login.html
  730.  
  731. Find Page >> http://en.hmb.gov.tr/bb-admin/admin.html
  732.  
  733. Find Page >> http://en.hmb.gov.tr/admin/home.html
  734.  
  735. Find Page >> http://en.hmb.gov.tr/pages/admin/admin-login.html
  736.  
  737. Find Page >> http://en.hmb.gov.tr/admin/admin-login.html
  738.  
  739. Find Page >> http://en.hmb.gov.tr/admin-login.html
  740.  
  741. Find Page >> http://en.hmb.gov.tr/admin/adminLogin.html
  742.  
  743. Find Page >> http://en.hmb.gov.tr/adminLogin.html
  744.  
  745. Find Page >> http://en.hmb.gov.tr/home.html
  746.  
  747. Find Page >> http://en.hmb.gov.tr/adminarea/index.html
  748.  
  749. Find Page >> http://en.hmb.gov.tr/adminarea/admin.html
  750.  
  751. Find Page >> http://en.hmb.gov.tr/admin/controlpanel.html
  752.  
  753. Find Page >> http://en.hmb.gov.tr/admin.html
  754.  
  755. Find Page >> http://en.hmb.gov.tr/admin/cp.html
  756.  
  757. Find Page >> http://en.hmb.gov.tr/cp.html
  758.  
  759. Find Page >> http://en.hmb.gov.tr/moderator.html
  760.  
  761. Find Page >> http://en.hmb.gov.tr/administrator/index.html
  762.  
  763. Find Page >> http://en.hmb.gov.tr/administrator/login.html
  764.  
  765. Find Page >> http://en.hmb.gov.tr/user.html
  766.  
  767. Find Page >> http://en.hmb.gov.tr/administrator/account.html
  768.  
  769. Find Page >> http://en.hmb.gov.tr/administrator.html
  770.  
  771. Find Page >> http://en.hmb.gov.tr/login.html
  772.  
  773. Find Page >> http://en.hmb.gov.tr/modelsearch/login.html
  774.  
  775. Find Page >> http://en.hmb.gov.tr/moderator/login.html
  776.  
  777. Find Page >> http://en.hmb.gov.tr/adminarea/login.html
  778.  
  779. Find Page >> http://en.hmb.gov.tr/panel-administracion/index.html
  780.  
  781. Find Page >> http://en.hmb.gov.tr/panel-administracion/admin.html
  782.  
  783. Find Page >> http://en.hmb.gov.tr/modelsearch/index.html
  784.  
  785. Find Page >> http://en.hmb.gov.tr/modelsearch/admin.html
  786.  
  787. Find Page >> http://en.hmb.gov.tr/admincontrol/login.html
  788.  
  789. Find Page >> http://en.hmb.gov.tr/adm/index.html
  790.  
  791. Find Page >> http://en.hmb.gov.tr/adm.html
  792.  
  793. Find Page >> http://en.hmb.gov.tr/moderator/admin.html
  794.  
  795. Find Page >> http://en.hmb.gov.tr/account.html
  796.  
  797. Find Page >> http://en.hmb.gov.tr/controlpanel.html
  798.  
  799. Find Page >> http://en.hmb.gov.tr/admincontrol.html
  800.  
  801. Find Page >> http://en.hmb.gov.tr/account.asp
  802.  
  803. Find Page >> http://en.hmb.gov.tr/admin/account.asp
  804.  
  805. Find Page >> http://en.hmb.gov.tr/admin/index.asp
  806.  
  807. Find Page >> http://en.hmb.gov.tr/admin/login.asp
  808.  
  809. Find Page >> http://en.hmb.gov.tr/admin/admin.asp
  810.  
  811. Find Page >> http://en.hmb.gov.tr/admin_area/admin.asp
  812.  
  813. Find Page >> http://en.hmb.gov.tr/admin_area/login.asp
  814.  
  815. Find Page >> http://en.hmb.gov.tr/admin_area/index.asp
  816.  
  817. Find Page >> http://en.hmb.gov.tr/bb-admin/index.asp
  818.  
  819. Find Page >> http://en.hmb.gov.tr/bb-admin/login.asp
  820.  
  821. Find Page >> http://en.hmb.gov.tr/bb-admin/admin.asp
  822.  
  823. Find Page >> http://en.hmb.gov.tr/admin/home.asp
  824.  
  825. Find Page >> http://en.hmb.gov.tr/admin/controlpanel.asp
  826.  
  827. Find Page >> http://en.hmb.gov.tr/admin.asp
  828.  
  829. Find Page >> http://en.hmb.gov.tr/pages/admin/admin-login.asp
  830.  
  831. Find Page >> http://en.hmb.gov.tr/admin/admin-login.asp
  832.  
  833. Find Page >> http://en.hmb.gov.tr/admin-login.asp
  834.  
  835. Find Page >> http://en.hmb.gov.tr/admin/cp.asp
  836.  
  837. Find Page >> http://en.hmb.gov.tr/cp.asp
  838.  
  839. Find Page >> http://en.hmb.gov.tr/administrator/account.asp
  840.  
  841. Find Page >> http://en.hmb.gov.tr/administrator.asp
  842.  
  843. Find Page >> http://en.hmb.gov.tr/acceso.asp
  844.  
  845. Find Page >> http://en.hmb.gov.tr/login.asp
  846.  
  847. Find Page >> http://en.hmb.gov.tr/modelsearch/login.asp
  848.  
  849. Find Page >> http://en.hmb.gov.tr/moderator.asp
  850.  
  851. Find Page >> http://en.hmb.gov.tr/moderator/login.asp
  852.  
  853. Find Page >> http://en.hmb.gov.tr/administrator/login.asp
  854.  
  855. Find Page >> http://en.hmb.gov.tr/moderator/admin.asp
  856.  
  857. Find Page >> http://en.hmb.gov.tr/controlpanel.asp
  858.  
  859. Find Page >> http://en.hmb.gov.tr/user.asp
  860.  
  861. Find Page >> http://en.hmb.gov.tr/admincontrol.asp
  862.  
  863. Find Page >> http://en.hmb.gov.tr/adminpanel.asp
  864.  
  865. Find Page >> http://en.hmb.gov.tr/webadmin.asp
  866.  
  867. Find Page >> http://en.hmb.gov.tr/webadmin/index.asp
  868.  
  869. Find Page >> http://en.hmb.gov.tr/webadmin/admin.asp
  870.  
  871. Find Page >> http://en.hmb.gov.tr/webadmin/login.asp
  872.  
  873. Find Page >> http://en.hmb.gov.tr/admin/admin_login.asp
  874.  
  875. Find Page >> http://en.hmb.gov.tr/admin_login.asp
  876.  
  877. Find Page >> http://en.hmb.gov.tr/panel-administracion/login.asp
  878.  
  879. Find Page >> http://en.hmb.gov.tr/adminLogin.asp
  880.  
  881. Find Page >> http://en.hmb.gov.tr/admin/adminLogin.asp
  882.  
  883. Find Page >> http://en.hmb.gov.tr/home.asp
  884.  
  885. Find Page >> http://en.hmb.gov.tr/adminarea/index.asp
  886.  
  887. Find Page >> http://en.hmb.gov.tr/adminarea/admin.asp
  888.  
  889. Find Page >> http://en.hmb.gov.tr/adminarea/login.asp
  890.  
  891. Find Page >> http://en.hmb.gov.tr/panel-administracion/index.asp
  892.  
  893. Find Page >> http://en.hmb.gov.tr/panel-administracion/admin.asp
  894.  
  895. Find Page >> http://en.hmb.gov.tr/modelsearch/index.asp
  896.  
  897. Find Page >> http://en.hmb.gov.tr/modelsearch/admin.asp
  898.  
  899. Find Page >> http://en.hmb.gov.tr/administrator/index.asp
  900.  
  901. Find Page >> http://en.hmb.gov.tr/admincontrol/login.asp
  902.  
  903. Find Page >> http://en.hmb.gov.tr/adm/admloginuser.asp
  904.  
  905. Find Page >> http://en.hmb.gov.tr/admloginuser.asp
  906.  
  907. Find Page >> http://en.hmb.gov.tr/admin2.asp
  908.  
  909. Find Page >> http://en.hmb.gov.tr/admin2/login.asp
  910.  
  911. Find Page >> http://en.hmb.gov.tr/admin2/index.asp
  912.  
  913. Find Page >> http://en.hmb.gov.tr/adm/index.asp
  914.  
  915. Find Page >> http://en.hmb.gov.tr/adm.asp
  916.  
  917. Find Page >> http://en.hmb.gov.tr/affiliate.asp
  918.  
  919. Find Page >> http://en.hmb.gov.tr/adm_auth.asp
  920.  
  921. Find Page >> http://en.hmb.gov.tr/memberadmin.asp
  922.  
  923. Find Page >> http://en.hmb.gov.tr/administratorlogin.asp
  924.  
  925. Find Page >> http://en.hmb.gov.tr/siteadmin/login.asp
  926.  
  927. Find Page >> http://en.hmb.gov.tr/siteadmin/index.asp
  928.  
  929. Find Page >> http://en.hmb.gov.tr/admin/account.cfm
  930.  
  931. Find Page >> http://en.hmb.gov.tr/admin/index.cfm
  932.  
  933. Find Page >> http://en.hmb.gov.tr/admin/login.cfm
  934.  
  935. Find Page >> http://en.hmb.gov.tr/admin/admin.cfm
  936.  
  937. Find Page >> http://en.hmb.gov.tr/admin_area/admin.cfm
  938.  
  939. Find Page >> http://en.hmb.gov.tr/admin_area/login.cfm
  940.  
  941. Find Page >> http://en.hmb.gov.tr/siteadmin/login.cfm
  942.  
  943. Find Page >> http://en.hmb.gov.tr/siteadmin/index.cfm
  944.  
  945. Find Page >> http://en.hmb.gov.tr/admin_area/index.cfm
  946.  
  947. Find Page >> http://en.hmb.gov.tr/bb-admin/index.cfm
  948.  
  949. Find Page >> http://en.hmb.gov.tr/bb-admin/login.cfm
  950.  
  951. Find Page >> http://en.hmb.gov.tr/bb-admin/admin.cfm
  952.  
  953. Find Page >> http://en.hmb.gov.tr/admin/home.cfm
  954.  
  955. Find Page >> http://en.hmb.gov.tr/admin/controlpanel.cfm
  956.  
  957. Find Page >> http://en.hmb.gov.tr/admin.cfm
  958.  
  959. Find Page >> http://en.hmb.gov.tr/admin/cp.cfm
  960.  
  961. Find Page >> http://en.hmb.gov.tr/cp.cfm
  962.  
  963. Find Page >> http://en.hmb.gov.tr/administrator/index.cfm
  964.  
  965. Find Page >> http://en.hmb.gov.tr/administrator/login.cfm
  966.  
  967. Find Page >> http://en.hmb.gov.tr/nsw/admin/login.cfm
  968.  
  969. Find Page >> http://en.hmb.gov.tr/webadmin/login.cfm
  970.  
  971. Find Page >> http://en.hmb.gov.tr/admin/admin_login.cfm
  972.  
  973. Find Page >> http://en.hmb.gov.tr/admin_login.cfm
  974.  
  975. Find Page >> http://en.hmb.gov.tr/administrator/account.cfm
  976.  
  977. Find Page >> http://en.hmb.gov.tr/administrator.cfm
  978.  
  979. Find Page >> http://en.hmb.gov.tr/pages/admin/admin-login.cfm
  980.  
  981. Find Page >> http://en.hmb.gov.tr/admin/admin-login.cfm
  982.  
  983. Find Page >> http://en.hmb.gov.tr/admin-login.cfm
  984.  
  985. Find Page >> http://en.hmb.gov.tr/login.cfm
  986.  
  987. Find Page >> http://en.hmb.gov.tr/modelsearch/login.cfm
  988.  
  989. Find Page >> http://en.hmb.gov.tr/moderator.cfm
  990.  
  991. Find Page >> http://en.hmb.gov.tr/moderator/login.cfm
  992.  
  993. Find Page >> http://en.hmb.gov.tr/moderator/admin.cfm
  994.  
  995. Find Page >> http://en.hmb.gov.tr/account.cfm
  996.  
  997. Find Page >> http://en.hmb.gov.tr/controlpanel.cfm
  998.  
  999. Find Page >> http://en.hmb.gov.tr/admincontrol.cfm
  1000.  
  1001. Find Page >> http://en.hmb.gov.tr/acceso.cfm
  1002.  
  1003. Find Page >> http://en.hmb.gov.tr/rcjakar/admin/login.cfm
  1004.  
  1005. Find Page >> http://en.hmb.gov.tr/webadmin.cfm
  1006.  
  1007. Find Page >> http://en.hmb.gov.tr/webadmin/index.cfm
  1008.  
  1009. Find Page >> http://en.hmb.gov.tr/webadmin/admin.cfm
  1010.  
  1011. Find Page >> http://en.hmb.gov.tr/adminpanel.cfm
  1012.  
  1013. Find Page >> http://en.hmb.gov.tr/user.cfm
  1014.  
  1015. Find Page >> http://en.hmb.gov.tr/panel-administracion/login.cfm
  1016.  
  1017. Find Page >> http://en.hmb.gov.tr/wp-login.cfm
  1018.  
  1019. Find Page >> http://en.hmb.gov.tr/adminLogin.cfm
  1020.  
  1021. Find Page >> http://en.hmb.gov.tr/admin/adminLogin.cfm
  1022.  
  1023. Find Page >> http://en.hmb.gov.tr/home.cfm
  1024.  
  1025. Find Page >> http://en.hmb.gov.tr/adminarea/index.cfm
  1026.  
  1027. Find Page >> http://en.hmb.gov.tr/adminarea/admin.cfm
  1028.  
  1029. Find Page >> http://en.hmb.gov.tr/adminarea/login.cfm
  1030.  
  1031. Find Page >> http://en.hmb.gov.tr/panel-administracion/index.cfm
  1032.  
  1033. Find Page >> http://en.hmb.gov.tr/panel-administracion/admin.cfm
  1034.  
  1035. Find Page >> http://en.hmb.gov.tr/modelsearch/index.cfm
  1036.  
  1037. Find Page >> http://en.hmb.gov.tr/modelsearch/admin.cfm
  1038.  
  1039. Find Page >> http://en.hmb.gov.tr/admincontrol/login.cfm
  1040.  
  1041. Find Page >> http://en.hmb.gov.tr/adm/admloginuser.cfm
  1042.  
  1043. Find Page >> http://en.hmb.gov.tr/admloginuser.cfm
  1044.  
  1045. Find Page >> http://en.hmb.gov.tr/admin2.cfm
  1046.  
  1047. Find Page >> http://en.hmb.gov.tr/admin2/login.cfm
  1048.  
  1049. Find Page >> http://en.hmb.gov.tr/admin2/index.cfm
  1050.  
  1051. Find Page >> http://en.hmb.gov.tr/usuarios/login.cfm
  1052.  
  1053. Find Page >> http://en.hmb.gov.tr/adm/index.cfm
  1054.  
  1055. Find Page >> http://en.hmb.gov.tr/adm.cfm
  1056.  
  1057. Find Page >> http://en.hmb.gov.tr/affiliate.cfm
  1058.  
  1059. Find Page >> http://en.hmb.gov.tr/adm_auth.cfm
  1060.  
  1061. Find Page >> http://en.hmb.gov.tr/memberadmin.cfm
  1062.  
  1063. Find Page >> http://en.hmb.gov.tr/administratorlogin.cfm
  1064.  
  1065. Find Page >> http://en.hmb.gov.tr/admin/account.js
  1066.  
  1067. Find Page >> http://en.hmb.gov.tr/admin/index.js
  1068.  
  1069. Find Page >> http://en.hmb.gov.tr/admin/login.js
  1070.  
  1071. Find Page >> http://en.hmb.gov.tr/admin/admin.js
  1072.  
  1073. Find Page >> http://en.hmb.gov.tr/admin_area/admin.js
  1074.  
  1075. Find Page >> http://en.hmb.gov.tr/admin_area/login.js
  1076.  
  1077. Find Page >> http://en.hmb.gov.tr/siteadmin/login.js
  1078.  
  1079. Find Page >> http://en.hmb.gov.tr/siteadmin/index.js
  1080.  
  1081. Find Page >> http://en.hmb.gov.tr/admin_area/index.js
  1082.  
  1083. Find Page >> http://en.hmb.gov.tr/bb-admin/index.js
  1084.  
  1085. Find Page >> http://en.hmb.gov.tr/bb-admin/login.js
  1086.  
  1087. Find Page >> http://en.hmb.gov.tr/bb-admin/admin.js
  1088.  
  1089. Find Page >> http://en.hmb.gov.tr/admin/home.js
  1090.  
  1091. Find Page >> http://en.hmb.gov.tr/admin/controlpanel.js
  1092.  
  1093. Find Page >> http://en.hmb.gov.tr/admin.js
  1094.  
  1095. Find Page >> http://en.hmb.gov.tr/admin/cp.js
  1096.  
  1097. Find Page >> http://en.hmb.gov.tr/cp.js
  1098.  
  1099. Find Page >> http://en.hmb.gov.tr/administrator/index.js
  1100.  
  1101. Find Page >> http://en.hmb.gov.tr/administrator/login.js
  1102.  
  1103. Find Page >> http://en.hmb.gov.tr/nsw/admin/login.js
  1104.  
  1105. Find Page >> http://en.hmb.gov.tr/webadmin/login.js
  1106.  
  1107. Find Page >> http://en.hmb.gov.tr/admin/admin_login.js
  1108.  
  1109. Find Page >> http://en.hmb.gov.tr/admin_login.js
  1110.  
  1111. Find Page >> http://en.hmb.gov.tr/administrator/account.js
  1112.  
  1113. Find Page >> http://en.hmb.gov.tr/administrator.js
  1114.  
  1115. Find Page >> http://en.hmb.gov.tr/pages/admin/admin-login.js
  1116.  
  1117. Find Page >> http://en.hmb.gov.tr/admin/admin-login.js
  1118.  
  1119. Find Page >> http://en.hmb.gov.tr/admin-login.js
  1120.  
  1121. Find Page >> http://en.hmb.gov.tr/login.js
  1122.  
  1123. Find Page >> http://en.hmb.gov.tr/modelsearch/login.js
  1124.  
  1125. Find Page >> http://en.hmb.gov.tr/moderator.js
  1126.  
  1127. Find Page >> http://en.hmb.gov.tr/moderator/login.js
  1128.  
  1129. Find Page >> http://en.hmb.gov.tr/moderator/admin.js
  1130.  
  1131. Find Page >> http://en.hmb.gov.tr/account.js
  1132.  
  1133. Find Page >> http://en.hmb.gov.tr/controlpanel.js
  1134.  
  1135. Find Page >> http://en.hmb.gov.tr/admincontrol.js
  1136.  
  1137. Find Page >> http://en.hmb.gov.tr/rcjakar/admin/login.js
  1138.  
  1139. Find Page >> http://en.hmb.gov.tr/webadmin.js
  1140.  
  1141. Find Page >> http://en.hmb.gov.tr/webadmin/index.js
  1142.  
  1143. Find Page >> http://en.hmb.gov.tr/acceso.js
  1144.  
  1145. Find Page >> http://en.hmb.gov.tr/webadmin/admin.js
  1146.  
  1147. Find Page >> http://en.hmb.gov.tr/adminpanel.js
  1148.  
  1149. Find Page >> http://en.hmb.gov.tr/user.js
  1150.  
  1151. Find Page >> http://en.hmb.gov.tr/panel-administracion/login.js
  1152.  
  1153. Find Page >> http://en.hmb.gov.tr/wp-login.js
  1154.  
  1155. Find Page >> http://en.hmb.gov.tr/adminLogin.js
  1156.  
  1157. Find Page >> http://en.hmb.gov.tr/admin/adminLogin.js
  1158.  
  1159. Find Page >> http://en.hmb.gov.tr/home.js
  1160.  
  1161. Find Page >> http://en.hmb.gov.tr/adminarea/index.js
  1162.  
  1163. Find Page >> http://en.hmb.gov.tr/adminarea/admin.js
  1164.  
  1165. Find Page >> http://en.hmb.gov.tr/adminarea/login.js
  1166.  
  1167. Find Page >> http://en.hmb.gov.tr/panel-administracion/index.js
  1168.  
  1169. Find Page >> http://en.hmb.gov.tr/panel-administracion/admin.js
  1170.  
  1171. Find Page >> http://en.hmb.gov.tr/modelsearch/index.js
  1172.  
  1173. Find Page >> http://en.hmb.gov.tr/modelsearch/admin.js
  1174.  
  1175. Find Page >> http://en.hmb.gov.tr/admincontrol/login.js
  1176.  
  1177. Find Page >> http://en.hmb.gov.tr/adm/admloginuser.js
  1178.  
  1179. Find Page >> http://en.hmb.gov.tr/admloginuser.js
  1180.  
  1181. Find Page >> http://en.hmb.gov.tr/admin2.js
  1182.  
  1183. Find Page >> http://en.hmb.gov.tr/admin2/login.js
  1184.  
  1185. Find Page >> http://en.hmb.gov.tr/admin2/index.js
  1186.  
  1187. Find Page >> http://en.hmb.gov.tr/usuarios/login.js
  1188.  
  1189. Find Page >> http://en.hmb.gov.tr/adm/index.js
  1190.  
  1191. Find Page >> http://en.hmb.gov.tr/adm.js
  1192.  
  1193. Find Page >> http://en.hmb.gov.tr/affiliate.js
  1194.  
  1195. Find Page >> http://en.hmb.gov.tr/adm_auth.js
  1196.  
  1197. Find Page >> http://en.hmb.gov.tr/memberadmin.js
  1198.  
  1199. Find Page >> http://en.hmb.gov.tr/administratorlogin.js
  1200.  
  1201. Find Page >> http://en.hmb.gov.tr/admin/account.cgi
  1202.  
  1203. Find Page >> http://en.hmb.gov.tr/admin/index.cgi
  1204.  
  1205. Find Page >> http://en.hmb.gov.tr/admin/login.cgi
  1206.  
  1207. Find Page >> http://en.hmb.gov.tr/admin/admin.cgi
  1208.  
  1209. Find Page >> http://en.hmb.gov.tr/admin_area/admin.cgi
  1210.  
  1211. Find Page >> http://en.hmb.gov.tr/admin_area/login.cgi
  1212.  
  1213. Find Page >> http://en.hmb.gov.tr/siteadmin/login.cgi
  1214.  
  1215. Find Page >> http://en.hmb.gov.tr/siteadmin/index.cgi
  1216.  
  1217. Find Page >> http://en.hmb.gov.tr/admin_area/index.cgi
  1218.  
  1219. Find Page >> http://en.hmb.gov.tr/bb-admin/index.cgi
  1220.  
  1221. Find Page >> http://en.hmb.gov.tr/bb-admin/login.cgi
  1222.  
  1223. Find Page >> http://en.hmb.gov.tr/bb-admin/admin.cgi
  1224.  
  1225. Find Page >> http://en.hmb.gov.tr/admin/home.cgi
  1226.  
  1227. Find Page >> http://en.hmb.gov.tr/admin/controlpanel.cgi
  1228.  
  1229. Find Page >> http://en.hmb.gov.tr/admin.cgi
  1230.  
  1231. Find Page >> http://en.hmb.gov.tr/admin/cp.cgi
  1232.  
  1233. Find Page >> http://en.hmb.gov.tr/cp.cgi
  1234.  
  1235. Find Page >> http://en.hmb.gov.tr/administrator/index.cgi
  1236.  
  1237. Find Page >> http://en.hmb.gov.tr/administrator/login.cgi
  1238.  
  1239. Find Page >> http://en.hmb.gov.tr/nsw/admin/login.cgi
  1240.  
  1241. Find Page >> http://en.hmb.gov.tr/webadmin/login.cgi
  1242.  
  1243. Find Page >> http://en.hmb.gov.tr/admin/admin_login.cgi
  1244.  
  1245. Find Page >> http://en.hmb.gov.tr/admin_login.cgi
  1246.  
  1247. Find Page >> http://en.hmb.gov.tr/administrator/account.cgi
  1248.  
  1249. Find Page >> http://en.hmb.gov.tr/administrator.cgi
  1250.  
  1251. Find Page >> http://en.hmb.gov.tr/pages/admin/admin-login.cgi
  1252.  
  1253. Find Page >> http://en.hmb.gov.tr/admin/admin-login.cgi
  1254.  
  1255. Find Page >> http://en.hmb.gov.tr/admin-login.cgi
  1256.  
  1257. Find Page >> http://en.hmb.gov.tr/login.cgi
  1258.  
  1259. Find Page >> http://en.hmb.gov.tr/modelsearch/login.cgi
  1260.  
  1261. Find Page >> http://en.hmb.gov.tr/moderator.cgi
  1262.  
  1263. Find Page >> http://en.hmb.gov.tr/moderator/login.cgi
  1264.  
  1265. Find Page >> http://en.hmb.gov.tr/moderator/admin.cgi
  1266.  
  1267. Find Page >> http://en.hmb.gov.tr/account.cgi
  1268.  
  1269. Find Page >> http://en.hmb.gov.tr/controlpanel.cgi
  1270.  
  1271. Find Page >> http://en.hmb.gov.tr/admincontrol.cgi
  1272.  
  1273. Find Page >> http://en.hmb.gov.tr/rcjakar/admin/login.cgi
  1274.  
  1275. Find Page >> http://en.hmb.gov.tr/webadmin.cgi
  1276.  
  1277. Find Page >> http://en.hmb.gov.tr/webadmin/index.cgi
  1278.  
  1279. Find Page >> http://en.hmb.gov.tr/acceso.cgi
  1280.  
  1281. Find Page >> http://en.hmb.gov.tr/webadmin/admin.cgi
  1282.  
  1283. Find Page >> http://en.hmb.gov.tr/adminpanel.cgi
  1284.  
  1285. Find Page >> http://en.hmb.gov.tr/user.cgi
  1286.  
  1287. Find Page >> http://en.hmb.gov.tr/panel-administracion/login.cgi
  1288.  
  1289. Find Page >> http://en.hmb.gov.tr/wp-login.cgi
  1290.  
  1291. Find Page >> http://en.hmb.gov.tr/adminLogin.cgi
  1292.  
  1293. Find Page >> http://en.hmb.gov.tr/admin/adminLogin.cgi
  1294.  
  1295. Find Page >> http://en.hmb.gov.tr/home.cgi
  1296.  
  1297. Find Page >> http://en.hmb.gov.tr/adminarea/index.cgi
  1298.  
  1299. Find Page >> http://en.hmb.gov.tr/adminarea/admin.cgi
  1300.  
  1301. Find Page >> http://en.hmb.gov.tr/adminarea/login.cgi
  1302.  
  1303. Find Page >> http://en.hmb.gov.tr/panel-administracion/index.cgi
  1304.  
  1305. Find Page >> http://en.hmb.gov.tr/panel-administracion/admin.cgi
  1306.  
  1307. Find Page >> http://en.hmb.gov.tr/modelsearch/index.cgi
  1308.  
  1309. Find Page >> http://en.hmb.gov.tr/modelsearch/admin.cgi
  1310.  
  1311. Find Page >> http://en.hmb.gov.tr/admincontrol/login.cgi
  1312.  
  1313. Find Page >> http://en.hmb.gov.tr/adm/admloginuser.cgi
  1314.  
  1315. Find Page >> http://en.hmb.gov.tr/admloginuser.cgi
  1316.  
  1317. Find Page >> http://en.hmb.gov.tr/admin2.cgi
  1318.  
  1319. Find Page >> http://en.hmb.gov.tr/admin2/login.cgi
  1320.  
  1321. Find Page >> http://en.hmb.gov.tr/admin2/index.cgi
  1322.  
  1323. Find Page >> http://en.hmb.gov.tr/usuarios/login.cgi
  1324.  
  1325. Find Page >> http://en.hmb.gov.tr/adm/index.cgi
  1326.  
  1327. Find Page >> http://en.hmb.gov.tr/adm.cgi
  1328.  
  1329. Find Page >> http://en.hmb.gov.tr/affiliate.cgi
  1330.  
  1331. Find Page >> http://en.hmb.gov.tr/adm_auth.cgi
  1332.  
  1333. Find Page >> http://en.hmb.gov.tr/memberadmin.cgi
  1334.  
  1335. Find Page >> http://en.hmb.gov.tr/administratorlogin.cgi
  1336.  
  1337. Find Page >> http://en.hmb.gov.tr/admin_panel/
  1338.  
  1339. Find Page >> http://en.hmb.gov.tr/admin_panel.html
  1340.  
  1341. Find Page >> http://en.hmb.gov.tr/adm_cp/
  1342. #######################################################################################################################################
  1343. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 21194
  1344. ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
  1345.  
  1346. ;; QUESTION SECTION:
  1347. ;en.hmb.gov.tr. IN ANY
  1348.  
  1349. ;; ANSWER SECTION:
  1350. en.hmb.gov.tr. 3600 IN A 212.174.188.50
  1351.  
  1352. ;; AUTHORITY SECTION:
  1353. hmb.gov.tr. 43200 IN NS ns3.muhasebat.gov.tr.
  1354. hmb.gov.tr. 43200 IN NS ns1.muhasebat.gov.tr.
  1355.  
  1356. ;; ADDITIONAL SECTION:
  1357. ns1.muhasebat.gov.tr. 42687 IN A 212.174.189.29
  1358. ns3.muhasebat.gov.tr. 42687 IN A 212.174.189.24
  1359.  
  1360. Received 125 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 2018 ms
  1361. ########################################################################################################################################
  1362. ; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace en.hmb.gov.tr
  1363. ;; global options: +cmd
  1364. . 83966 IN NS g.root-servers.net.
  1365. . 83966 IN NS d.root-servers.net.
  1366. . 83966 IN NS m.root-servers.net.
  1367. . 83966 IN NS a.root-servers.net
  1368. . 83966 IN NS e.root-servers.net.
  1369. . 83966 IN NS f.root-servers.net.
  1370. . 83966 IN NS h.root-servers.net.
  1371. . 83966 IN NS c.root-servers.net.
  1372. . 83966 IN NS b.root-servers.net.
  1373. . 83966 IN NS j.root-servers.net.
  1374. . 83966 IN NS i.root-servers.net.
  1375. . 83966 IN NS l.root-servers.net.
  1376. . 83966 IN NS k.root-servers.net.
  1377. . 83966 IN RRSIG NS 8 0 518400 20191023170000 20191010160000 22545 . sEqYXFvUPcMu1T90AWfMc9qC/3fzkIedU3tYYDMot3m/lnLto9+0avlp /lCjgGxVVDcqxCehNod58TxBmBPW//h7GiD2FfhhSrpu+/Q8j4Uvmzq/ DoD0REnDIcvYTb0sZCQQAW0Bsv8E3zEtq4CO5Vwpfwy20hRTO1Es9ikW l7JiKMGF+/S6R0rCs8dQ3UzUOTuZyiEoaGBZm7Un93TyKeiBpBjTj24y 6x3qER2gvv+K4tetnPWNsTe7tBlrtjf3SNz2oi6SP+zmYFAU5S1gkg78 blwGR5zH/vC8OBQBeLq0as1qiTpAaTBJETFIJu4vlEYWIzZ4TkYZk4Vg yhrvig==
  1378. ;; Received 525 bytes from 38.132.106.139#53(38.132.106.139) in 85 ms
  1379.  
  1380. tr. 172800 IN NS ns21.nic.tr.
  1381. tr. 172800 IN NS ns22.nic.tr.
  1382. tr. 172800 IN NS ns31.nic.tr.
  1383. tr. 172800 IN NS ns41.nic.tr.
  1384. tr. 172800 IN NS ns42.nic.tr.
  1385. tr. 172800 IN NS ns91.nic.tr.
  1386. tr. 172800 IN NS ns92.nic.tr.
  1387. tr. 86400 IN NSEC trade. NS RRSIG NSEC
  1388. tr. 86400 IN RRSIG NSEC 8 1 86400 20191023170000 20191010160000 22545 . ddnGvTsodXTqQJRNwE83h9HHh09rMdMIH9ON15qEihMkD7GLAKoBAddI mTUH02iuXHqrXREzVYkhg58QIOGTAnIn1ybT4yvtjrOZLtHLk8fbLcry 1nveOQ+MII6Yy4eJxV4MbdsvP0WfSSNxWF65oBEXNPK7VN8iRc1dq3gV MKMOdTQSaQQr6zevrk8u2oIqTnVhitKB25P2v+aNDYo9dZ8CBhcCOB1K N29O8J8s4WwEeAWu13NSDk030akz0GogeiquZ+QexLv6OHrKcF3JaaEW sfLhRGYdyRuHZfc4j7Rt4Nzb94AX8xs376UBur1Le/7tYxw8lpg4aNsE x5OKRw==
  1389. ;; Received 717 bytes from 2001:503:ba3e::2:30#53(a.root-servers.net) in 42 ms
  1390.  
  1391. hmb.gov.tr. 43200 IN NS ns1.muhasebat.gov.tr.
  1392. hmb.gov.tr. 43200 IN NS ns3.muhasebat.gov.tr.
  1393. ;; Received 120 bytes from 31.210.155.2#53(ns31.nic.tr) in 207 ms
  1394.  
  1395. ;; Received 54 bytes from 212.174.189.29#53(ns1.muhasebat.gov.tr) in 207 ms
  1396. #######################################################################################################################################
  1397.  
  1398. AVAILABLE PLUGINS
  1399. -----------------
  1400.  
  1401. SessionRenegotiationPlugin
  1402. EarlyDataPlugin
  1403. HttpHeadersPlugin
  1404. CertificateInfoPlugin
  1405. OpenSslCipherSuitesPlugin
  1406. HeartbleedPlugin
  1407. RobotPlugin
  1408. OpenSslCcsInjectionPlugin
  1409. CompressionPlugin
  1410. FallbackScsvPlugin
  1411. SessionResumptionPlugin
  1412.  
  1413.  
  1414.  
  1415. CHECKING HOST(S) AVAILABILITY
  1416. -----------------------------
  1417.  
  1418. 212.174.188.50:443 => 212.174.188.50
  1419.  
  1420.  
  1421.  
  1422.  
  1423. SCAN RESULTS FOR 212.174.188.50:443 - 212.174.188.50
  1424. ----------------------------------------------------
  1425.  
  1426. * Downgrade Attacks:
  1427. TLS_FALLBACK_SCSV: OK - Supported
  1428.  
  1429. * SSLV2 Cipher Suites:
  1430. Server rejected all cipher suites.
  1431.  
  1432. * Deflate Compression:
  1433. OK - Compression disabled
  1434.  
  1435. * Session Renegotiation:
  1436. Client-initiated Renegotiation: OK - Rejected
  1437. Secure Renegotiation: OK - Supported
  1438.  
  1439. * TLSV1_3 Cipher Suites:
  1440. Forward Secrecy OK - Supported
  1441. RC4 OK - Not Supported
  1442.  
  1443. Preferred:
  1444. TLS_AES_256_GCM_SHA384 256 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1445. Accepted:
  1446. TLS_CHACHA20_POLY1305_SHA256 256 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1447. TLS_AES_256_GCM_SHA384 256 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1448. TLS_AES_128_GCM_SHA256 128 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1449.  
  1450. * ROBOT Attack:
  1451. OK - Not vulnerable
  1452.  
  1453. * OpenSSL Heartbleed:
  1454. OK - Not vulnerable to Heartbleed
  1455.  
  1456. * TLSV1_1 Cipher Suites:
  1457. Server rejected all cipher suites.
  1458.  
  1459. * TLSV1 Cipher Suites:
  1460. Server rejected all cipher suites.
  1461.  
  1462. * Certificate Information:
  1463. Content
  1464. SHA1 Fingerprint: 97a7ad852f9fe53dbae797aabdeef469cbd38cef
  1465. Common Name: *.hmb.gov.tr
  1466. Issuer: GlobalSign Organization Validation CA - SHA256 - G2
  1467. Serial Number: 38573886576754047190994614396
  1468. Not Before: 2018-10-05 16:39:41
  1469. Not After: 2020-10-05 16:39:41
  1470. Signature Algorithm: sha256
  1471. Public Key Algorithm: RSA
  1472. Key Size: 2048
  1473. Exponent: 65537 (0x10001)
  1474. DNS Subject Alternative Names: ['*.hmb.gov.tr', 'hmb.gov.tr']
  1475.  
  1476. Trust
  1477. Hostname Validation: FAILED - Certificate does NOT match 212.174.188.50
  1478. Android CA Store (9.0.0_r9): OK - Certificate is trusted
  1479. Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
  1480. Java CA Store (jdk-12.0.1): OK - Certificate is trusted
  1481. Mozilla CA Store (2019-03-14): OK - Certificate is trusted
  1482. Windows CA Store (2019-05-27): OK - Certificate is trusted
  1483. Symantec 2018 Deprecation: WARNING: Certificate distrusted by Google and Mozilla on September 2018
  1484. Received Chain: *.hmb.gov.tr --> GlobalSign Organization Validation CA - SHA256 - G2
  1485. Verified Chain: *.hmb.gov.tr --> GlobalSign Organization Validation CA - SHA256 - G2 --> GlobalSign
  1486. Received Chain Contains Anchor: OK - Anchor certificate not sent
  1487. Received Chain Order: OK - Order is valid
  1488. Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
  1489.  
  1490. Extensions
  1491. OCSP Must-Staple: NOT SUPPORTED - Extension not found
  1492. Certificate Transparency: OK - 3 SCTs included
  1493.  
  1494. OCSP Stapling
  1495. NOT SUPPORTED - Server did not send back an OCSP response
  1496.  
  1497. * TLS 1.2 Session Resumption Support:
  1498. With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
  1499. With TLS Tickets: NOT SUPPORTED - TLS ticket not assigned.
  1500.  
  1501. * OpenSSL CCS Injection:
  1502. OK - Not vulnerable to OpenSSL CCS injection
  1503.  
  1504. * TLSV1_2 Cipher Suites:
  1505. Forward Secrecy OK - Supported
  1506. RC4 OK - Not Supported
  1507.  
  1508. Preferred:
  1509. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1510. Accepted:
  1511. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1512. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 301 Moved Permanently - https://www.hmb.gov.tr
  1513.  
  1514. * SSLV3 Cipher Suites:
  1515. Server rejected all cipher suites.
  1516.  
  1517.  
  1518. SCAN COMPLETED IN 16.00 S
  1519. -------------------------
  1520. #######################################################################################################################################
  1521.  
  1522. Domains still to check: 1
  1523. Checking if the hostname hmb.gov.tr. given is in fact a domain...
  1524.  
  1525. Analyzing domain: hmb.gov.tr.
  1526. Checking NameServers using system default resolver...
  1527. IP: 212.174.189.24 (Turkey)
  1528. HostName: ns3.muhasebat.gov.tr Type: NS
  1529. HostName: 212.174.189.24.static.ttnet.com.tr Type: PTR
  1530. IP: 212.174.189.29 (Turkey)
  1531. HostName: ns1.muhasebat.gov.tr Type: NS
  1532. HostName: 212.174.189.29.static.ttnet.com.tr Type: PTR
  1533.  
  1534. Checking MailServers using system default resolver...
  1535. IP: 212.174.188.11 (Turkey)
  1536. HostName: mailgw01.hmb.gov.tr Type: MX
  1537. HostName: mailgw01.maliye.gov.tr Type: PTR
  1538. IP: 212.174.188.13 (Turkey)
  1539. HostName: mailgw03.hmb.gov.tr Type: MX
  1540. HostName: mailgw03.hmb.gov.tr Type: PTR
  1541. IP: 212.174.188.12 (Turkey)
  1542. HostName: mailgw02.hmb.gov.tr Type: MX
  1543. HostName: mailgw02.maliye.gov.tr Type: PTR
  1544.  
  1545. Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
  1546. No zone transfer found on nameserver 212.174.189.24
  1547. No zone transfer found on nameserver 212.174.189.29
  1548.  
  1549. Checking SPF record...
  1550. New hostname found: mailgw01
  1551. New hostname found: mailgw02
  1552. New hostname found: mailgw03
  1553. New hostname found: mailgw04
  1554.  
  1555. Checking 196 most common hostnames using system default resolver...
  1556. IP: 212.174.188.50 (Turkey)
  1557. HostName: www.hmb.gov.tr. Type: A
  1558. IP: 212.174.188.10 (Turkey)
  1559. HostName: mail.hmb.gov.tr. Type: A
  1560. IP: 212.174.189.24 (Turkey)
  1561. HostName: ns3.muhasebat.gov.tr Type: NS
  1562. HostName: 212.174.189.24.static.ttnet.com.tr Type: PTR
  1563. HostName: ns1.hmb.gov.tr. Type: A
  1564. IP: 212.174.189.29 (Turkey)
  1565. HostName: ns1.muhasebat.gov.tr Type: NS
  1566. HostName: 212.174.189.29.static.ttnet.com.tr Type: PTR
  1567. HostName: ns2.hmb.gov.tr. Type: A
  1568. IP: 212.174.188.9 (Turkey)
  1569. HostName: webmail.hmb.gov.tr. Type: A
  1570. IP: 212.174.188.11 (Turkey)
  1571. HostName: mailgw01.hmb.gov.tr Type: MX
  1572. HostName: mailgw01.maliye.gov.tr Type: PTR
  1573. HostName: mailgw01.hmb.gov.tr. Type: A
  1574. IP: 212.174.188.12 (Turkey)
  1575. HostName: mailgw02.hmb.gov.tr Type: MX
  1576. HostName: mailgw02.maliye.gov.tr Type: PTR
  1577. HostName: mailgw02.hmb.gov.tr. Type: A
  1578. IP: 212.174.188.13 (Turkey)
  1579. HostName: mailgw03.hmb.gov.tr Type: MX
  1580. HostName: mailgw03.hmb.gov.tr Type: PTR
  1581. HostName: mailgw03.hmb.gov.tr. Type: A
  1582. IP: 212.174.188.15 (Turkey)
  1583. HostName: mailgw04.hmb.gov.tr. Type: A
  1584.  
  1585. Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
  1586. Checking netblock 212.174.188.0
  1587. Checking netblock 212.174.189.0
  1588.  
  1589. Searching for hmb.gov.tr. emails in Google
  1590.  
  1591. Checking 9 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
  1592. Host 212.174.188.9 is up (reset ttl 64)
  1593. Host 212.174.188.12 is up (reset ttl 64)
  1594. Host 212.174.188.11 is up (reset ttl 64)
  1595. Host 212.174.188.10 is up (reset ttl 64)
  1596. Host 212.174.188.13 is up (reset ttl 64)
  1597. Host 212.174.189.24 is up (reset ttl 64)
  1598. Host 212.174.188.15 is up (reset ttl 64)
  1599. Host 212.174.188.50 is up (reset ttl 64)
  1600. Host 212.174.189.29 is up (reset ttl 64)
  1601.  
  1602. Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
  1603. Scanning ip 212.174.188.9 (webmail.hmb.gov.tr.):
  1604. 80/tcp open http-proxy syn-ack ttl 234 F5 BIG-IP load balancer http proxy
  1605. | http-methods:
  1606. |_ Supported Methods: GET HEAD POST OPTIONS
  1607. |_http-server-header: BigIP
  1608. |_http-title: Did not follow redirect to https://212.174.188.9/
  1609. |_https-redirect: ERROR: Script execution failed (use -d to debug)
  1610. 443/tcp open ssl/https? syn-ack ttl 234
  1611. |_http-favicon: Unknown favicon MD5: 486373B021971D0A95AF04C811799E21
  1612. | ssl-cert: Subject: commonName=*.hmb.gov.tr/organizationName=Hazine ve Maliye Bakanligi/stateOrProvinceName=Ankara/countryName=TR
  1613. | Subject Alternative Name: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  1614. | Issuer: commonName=GlobalSign Organization Validation CA - SHA256 - G2/organizationName=GlobalSign nv-sa/countryName=BE
  1615. | Public Key type: rsa
  1616. | Public Key bits: 2048
  1617. | Signature Algorithm: sha256WithRSAEncryption
  1618. | Not valid before: 2018-10-05T16:39:41
  1619. | Not valid after: 2020-10-05T16:39:41
  1620. | MD5: d9a6 828e 3cb7 f9b5 8a71 1d50 fb89 5033
  1621. |_SHA-1: 97a7 ad85 2f9f e53d bae7 97aa bdee f469 cbd3 8cef
  1622. |_ssl-date: TLS randomness does not represent time
  1623. Device type: general purpose|WAP
  1624. OS Info: Service Info: Device: load balancer
  1625. Scanning ip 212.174.188.12 (mailgw02.hmb.gov.tr.):
  1626. Scanning ip 212.174.188.11 (mailgw01.hmb.gov.tr.):
  1627. 80/tcp open http syn-ack ttl 107 Microsoft IIS httpd 7.5
  1628. | http-methods:
  1629. |_ Supported Methods: GET HEAD POST OPTIONS
  1630. |_http-server-header: Microsoft-IIS/7.5
  1631. |_http-title: Did not follow redirect to https://mail.muhasebat.gov.tr/owa
  1632. 443/tcp open ssl/https? syn-ack ttl 107
  1633. |_ssl-date: 2019-10-11T03:47:25+00:00; -2m03s from scanner time.
  1634. Device type: general purpose|WAP
  1635. Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 7|2008|2012|Vista (86%)
  1636. OS Info: Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  1637. |_clock-skew: -2m03s
  1638. Scanning ip 212.174.188.10 (mail.hmb.gov.tr.):
  1639. 80/tcp open http-proxy syn-ack ttl 234 F5 BIG-IP load balancer http proxy
  1640. | http-methods:
  1641. |_ Supported Methods: GET HEAD POST OPTIONS
  1642. |_http-server-header: BigIP
  1643. |_http-title: Did not follow redirect to https://212.174.188.10/
  1644. |_https-redirect: ERROR: Script execution failed (use -d to debug)
  1645. 443/tcp open ssl/http-proxy syn-ack ttl 234 F5 BIG-IP load balancer http proxy
  1646. | http-methods:
  1647. |_ Supported Methods: GET HEAD POST OPTIONS
  1648. |_http-server-header: BigIP
  1649. | ssl-cert: Subject: commonName=*.hmb.gov.tr/organizationName=Hazine ve Maliye Bakanligi/stateOrProvinceName=Ankara/countryName=TR
  1650. | Subject Alternative Name: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  1651. | Issuer: commonName=GlobalSign Organization Validation CA - SHA256 - G2/organizationName=GlobalSign nv-sa/countryName=BE
  1652. | Public Key type: rsa
  1653. | Public Key bits: 2048
  1654. | Signature Algorithm: sha256WithRSAEncryption
  1655. | Not valid before: 2018-10-05T16:39:41
  1656. | Not valid after: 2020-10-05T16:39:41
  1657. | MD5: d9a6 828e 3cb7 f9b5 8a71 1d50 fb89 5033
  1658. |_SHA-1: 97a7 ad85 2f9f e53d bae7 97aa bdee f469 cbd3 8cef
  1659. |_ssl-date: TLS randomness does not represent time
  1660. Device type: general purpose|WAP
  1661. OS Info: Service Info: Device: load balancer
  1662. Scanning ip 212.174.188.13 (mailgw03.hmb.gov.tr.):
  1663. Scanning ip 212.174.189.24 (ns1.hmb.gov.tr.):
  1664. 53/tcp open domain syn-ack ttl 108 Microsoft DNS 6.1.7601 (1DB15EC5) (Windows Server 2008 R2 SP1)
  1665. | dns-nsid:
  1666. |_ bind.version: Microsoft DNS 6.1.7601 (1DB15EC5)
  1667. Device type: general purpose|WAP
  1668. Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 7|2008|2012|Vista (88%)
  1669. OS Info: Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1
  1670. Scanning ip 212.174.188.15 (mailgw04.hmb.gov.tr.):
  1671. Scanning ip 212.174.188.50 (www.hmb.gov.tr.):
  1672. 80/tcp open http syn-ack ttl 41 nginx
  1673. | http-methods:
  1674. |_ Supported Methods: GET HEAD POST OPTIONS
  1675. |_http-title: Did not follow redirect to https://www.hmb.gov.tr
  1676. 443/tcp open ssl/http syn-ack ttl 41 nginx
  1677. | http-methods:
  1678. |_ Supported Methods: GET HEAD POST OPTIONS
  1679. |_http-title: Did not follow redirect to https://www.hmb.gov.tr
  1680. | ssl-cert: Subject: commonName=*.hmb.gov.tr/organizationName=Hazine ve Maliye Bakanligi/stateOrProvinceName=Ankara/countryName=TR
  1681. | Subject Alternative Name: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  1682. | Issuer: commonName=GlobalSign Organization Validation CA - SHA256 - G2/organizationName=GlobalSign nv-sa/countryName=BE
  1683. | Public Key type: rsa
  1684. | Public Key bits: 2048
  1685. | Signature Algorithm: sha256WithRSAEncryption
  1686. | Not valid before: 2018-10-05T16:39:41
  1687. | Not valid after: 2020-10-05T16:39:41
  1688. | MD5: d9a6 828e 3cb7 f9b5 8a71 1d50 fb89 5033
  1689. |_SHA-1: 97a7 ad85 2f9f e53d bae7 97aa bdee f469 cbd3 8cef
  1690. Running (JUST GUESSING): Linux 3.X|2.6.X|4.X (92%)
  1691. Scanning ip 212.174.189.29 (ns2.hmb.gov.tr.):
  1692. 53/tcp open domain syn-ack ttl 108 Microsoft DNS 6.1.7601 (1DB15F75) (Windows Server 2008 R2 SP1)
  1693. | dns-nsid:
  1694. |_ bind.version: Microsoft DNS 6.1.7601 (1DB15F75)
  1695. OS Info: Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1
  1696. WebCrawling domain's web servers... up to 50 max links.
  1697.  
  1698. + URL to crawl: http://webmail.hmb.gov.tr.
  1699. + Date: 2019-10-10
  1700.  
  1701. + Crawling URL: http://webmail.hmb.gov.tr.:
  1702. + Links:
  1703. + Crawling http://webmail.hmb.gov.tr.
  1704. + Searching for directories...
  1705. + Searching open folders...
  1706.  
  1707.  
  1708. + URL to crawl: http://mailgw01.hmb.gov.tr.
  1709. + Date: 2019-10-10
  1710.  
  1711. + Crawling URL: http://mailgw01.hmb.gov.tr.:
  1712. + Links:
  1713. + Crawling http://mailgw01.hmb.gov.tr. (400 Bad Request)
  1714. + Searching for directories...
  1715. + Searching open folders...
  1716.  
  1717.  
  1718. + URL to crawl: http://mailgw01.hmb.gov.tr
  1719. + Date: 2019-10-10
  1720.  
  1721. + Crawling URL: http://mailgw01.hmb.gov.tr:
  1722. + Links:
  1723. + Crawling http://mailgw01.hmb.gov.tr ([SSL: UNSUPPORTED_PROTOCOL] unsupported protocol (_ssl.c:727))
  1724. + Searching for directories...
  1725. + Searching open folders...
  1726.  
  1727.  
  1728. + URL to crawl: http://mail.hmb.gov.tr.
  1729. + Date: 2019-10-10
  1730.  
  1731. + Crawling URL: http://mail.hmb.gov.tr.:
  1732. + Links:
  1733. + Crawling http://mail.hmb.gov.tr.
  1734. + Searching for directories...
  1735. + Searching open folders...
  1736.  
  1737.  
  1738. + URL to crawl: http://mail.hmb.gov.tr.:443
  1739. + Date: 2019-10-10
  1740.  
  1741. + Crawling URL: http://mail.hmb.gov.tr.:443:
  1742. + Links:
  1743. + Crawling http://mail.hmb.gov.tr.:443
  1744. + Searching for directories...
  1745. + Searching open folders...
  1746.  
  1747.  
  1748. + URL to crawl: http://www.hmb.gov.tr.
  1749. + Date: 2019-10-10
  1750.  
  1751. + Crawling URL: http://www.hmb.gov.tr.:
  1752. + Links:
  1753. + Crawling http://www.hmb.gov.tr.
  1754. + Crawling http://www.hmb.gov.tr./manifest.json (File! Not crawling it.)
  1755. + Crawling http://www.hmb.gov.tr./yandex-browser-manifest.json (File! Not crawling it.)
  1756. + Searching for directories...
  1757. - Found: http://www.hmb.gov.tr./assets/
  1758. + Searching open folders...
  1759. - http://www.hmb.gov.tr./assets/ (403 Forbidden)
  1760.  
  1761.  
  1762. + URL to crawl: https://www.hmb.gov.tr.
  1763. + Date: 2019-10-10
  1764.  
  1765. + Crawling URL: https://www.hmb.gov.tr.:
  1766. + Links:
  1767. + Crawling https://www.hmb.gov.tr.
  1768. + Searching for directories...
  1769. + Searching open folders...
  1770.  
  1771. --Finished--
  1772. Summary information for domain hmb.gov.tr.
  1773. -----------------------------------------
  1774. Domain Specific Information:
  1775.  
  1776. Domain Ips Information:
  1777. IP: 212.174.188.9
  1778. HostName: webmail.hmb.gov.tr. Type: A
  1779. Country: Turkey
  1780. Is Active: True (reset ttl 64)
  1781. Port: 80/tcp open http-proxy syn-ack ttl 234 F5 BIG-IP load balancer http proxy
  1782. Script Info: | http-methods:
  1783. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1784. Script Info: |_http-server-header: BigIP
  1785. Script Info: |_http-title: Did not follow redirect to https://212.174.188.9/
  1786. Script Info: |_https-redirect: ERROR: Script execution failed (use -d to debug)
  1787. Port: 443/tcp open ssl/https? syn-ack ttl 234
  1788. Script Info: |_http-favicon: Unknown favicon MD5: 486373B021971D0A95AF04C811799E21
  1789. Script Info: | ssl-cert: Subject: commonName=*.hmb.gov.tr/organizationName=Hazine ve Maliye Bakanligi/stateOrProvinceName=Ankara/countryName=TR
  1790. Script Info: | Subject Alternative Name: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  1791. Script Info: | Issuer: commonName=GlobalSign Organization Validation CA - SHA256 - G2/organizationName=GlobalSign nv-sa/countryName=BE
  1792. Script Info: | Public Key type: rsa
  1793. Script Info: | Public Key bits: 2048
  1794. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1795. Script Info: | Not valid before: 2018-10-05T16:39:41
  1796. Script Info: | Not valid after: 2020-10-05T16:39:41
  1797. Script Info: | MD5: d9a6 828e 3cb7 f9b5 8a71 1d50 fb89 5033
  1798. Script Info: |_SHA-1: 97a7 ad85 2f9f e53d bae7 97aa bdee f469 cbd3 8cef
  1799. Script Info: |_ssl-date: TLS randomness does not represent time
  1800. Script Info: Device type: general purpose|WAP
  1801. Os Info: Device: load balancer
  1802. IP: 212.174.188.12
  1803. HostName: mailgw02.hmb.gov.tr Type: MX
  1804. HostName: mailgw02.maliye.gov.tr Type: PTR
  1805. HostName: mailgw02.hmb.gov.tr. Type: A
  1806. Country: Turkey
  1807. Is Active: True (reset ttl 64)
  1808. IP: 212.174.188.11
  1809. HostName: mailgw01.hmb.gov.tr Type: MX
  1810. HostName: mailgw01.maliye.gov.tr Type: PTR
  1811. HostName: mailgw01.hmb.gov.tr. Type: A
  1812. Country: Turkey
  1813. Is Active: True (reset ttl 64)
  1814. Port: 80/tcp open http syn-ack ttl 107 Microsoft IIS httpd 7.5
  1815. Script Info: | http-methods:
  1816. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1817. Script Info: |_http-server-header: Microsoft-IIS/7.5
  1818. Script Info: |_http-title: Did not follow redirect to https://mail.muhasebat.gov.tr/owa
  1819. Port: 443/tcp open ssl/https? syn-ack ttl 107
  1820. Script Info: |_ssl-date: 2019-10-11T03:47:25+00:00; -2m03s from scanner time.
  1821. Script Info: Device type: general purpose|WAP
  1822. Script Info: Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 7|2008|2012|Vista (86%)
  1823. Os Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  1824. Script Info: |_clock-skew: -2m03s
  1825. IP: 212.174.188.10
  1826. HostName: mail.hmb.gov.tr. Type: A
  1827. Country: Turkey
  1828. Is Active: True (reset ttl 64)
  1829. Port: 80/tcp open http-proxy syn-ack ttl 234 F5 BIG-IP load balancer http proxy
  1830. Script Info: | http-methods:
  1831. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1832. Script Info: |_http-server-header: BigIP
  1833. Script Info: |_http-title: Did not follow redirect to https://212.174.188.10/
  1834. Script Info: |_https-redirect: ERROR: Script execution failed (use -d to debug)
  1835. Port: 443/tcp open ssl/http-proxy syn-ack ttl 234 F5 BIG-IP load balancer http proxy
  1836. Script Info: | http-methods:
  1837. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1838. Script Info: |_http-server-header: BigIP
  1839. Script Info: | ssl-cert: Subject: commonName=*.hmb.gov.tr/organizationName=Hazine ve Maliye Bakanligi/stateOrProvinceName=Ankara/countryName=TR
  1840. Script Info: | Subject Alternative Name: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  1841. Script Info: | Issuer: commonName=GlobalSign Organization Validation CA - SHA256 - G2/organizationName=GlobalSign nv-sa/countryName=BE
  1842. Script Info: | Public Key type: rsa
  1843. Script Info: | Public Key bits: 2048
  1844. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1845. Script Info: | Not valid before: 2018-10-05T16:39:41
  1846. Script Info: | Not valid after: 2020-10-05T16:39:41
  1847. Script Info: | MD5: d9a6 828e 3cb7 f9b5 8a71 1d50 fb89 5033
  1848. Script Info: |_SHA-1: 97a7 ad85 2f9f e53d bae7 97aa bdee f469 cbd3 8cef
  1849. Script Info: |_ssl-date: TLS randomness does not represent time
  1850. Script Info: Device type: general purpose|WAP
  1851. Os Info: Device: load balancer
  1852. IP: 212.174.188.13
  1853. HostName: mailgw03.hmb.gov.tr Type: MX
  1854. HostName: mailgw03.hmb.gov.tr Type: PTR
  1855. HostName: mailgw03.hmb.gov.tr. Type: A
  1856. Country: Turkey
  1857. Is Active: True (reset ttl 64)
  1858. IP: 212.174.189.24
  1859. HostName: ns3.muhasebat.gov.tr Type: NS
  1860. HostName: 212.174.189.24.static.ttnet.com.tr Type: PTR
  1861. HostName: ns1.hmb.gov.tr. Type: A
  1862. Country: Turkey
  1863. Is Active: True (reset ttl 64)
  1864. Port: 53/tcp open domain syn-ack ttl 108 Microsoft DNS 6.1.7601 (1DB15EC5) (Windows Server 2008 R2 SP1)
  1865. Script Info: | dns-nsid:
  1866. Script Info: |_ bind.version: Microsoft DNS 6.1.7601 (1DB15EC5)
  1867. Script Info: Device type: general purpose|WAP
  1868. Script Info: Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 7|2008|2012|Vista (88%)
  1869. Os Info: OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1
  1870. IP: 212.174.188.15
  1871. HostName: mailgw04.hmb.gov.tr. Type: A
  1872. Country: Turkey
  1873. Is Active: True (reset ttl 64)
  1874. IP: 212.174.188.50
  1875. HostName: www.hmb.gov.tr. Type: A
  1876. Country: Turkey
  1877. Is Active: True (reset ttl 64)
  1878. Port: 80/tcp open http syn-ack ttl 41 nginx
  1879. Script Info: | http-methods:
  1880. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1881. Script Info: |_http-title: Did not follow redirect to https://www.hmb.gov.tr
  1882. Port: 443/tcp open ssl/http syn-ack ttl 41 nginx
  1883. Script Info: | http-methods:
  1884. Script Info: |_ Supported Methods: GET HEAD POST OPTIONS
  1885. Script Info: |_http-title: Did not follow redirect to https://www.hmb.gov.tr
  1886. Script Info: | ssl-cert: Subject: commonName=*.hmb.gov.tr/organizationName=Hazine ve Maliye Bakanligi/stateOrProvinceName=Ankara/countryName=TR
  1887. Script Info: | Subject Alternative Name: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  1888. Script Info: | Issuer: commonName=GlobalSign Organization Validation CA - SHA256 - G2/organizationName=GlobalSign nv-sa/countryName=BE
  1889. Script Info: | Public Key type: rsa
  1890. Script Info: | Public Key bits: 2048
  1891. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1892. Script Info: | Not valid before: 2018-10-05T16:39:41
  1893. Script Info: | Not valid after: 2020-10-05T16:39:41
  1894. Script Info: | MD5: d9a6 828e 3cb7 f9b5 8a71 1d50 fb89 5033
  1895. Script Info: |_SHA-1: 97a7 ad85 2f9f e53d bae7 97aa bdee f469 cbd3 8cef
  1896. Script Info: Running (JUST GUESSING): Linux 3.X|2.6.X|4.X (92%)
  1897. IP: 212.174.189.29
  1898. HostName: ns1.muhasebat.gov.tr Type: NS
  1899. HostName: 212.174.189.29.static.ttnet.com.tr Type: PTR
  1900. HostName: ns2.hmb.gov.tr. Type: A
  1901. Country: Turkey
  1902. Is Active: True (reset ttl 64)
  1903. Port: 53/tcp open domain syn-ack ttl 108 Microsoft DNS 6.1.7601 (1DB15F75) (Windows Server 2008 R2 SP1)
  1904. Script Info: | dns-nsid:
  1905. Script Info: |_ bind.version: Microsoft DNS 6.1.7601 (1DB15F75)
  1906. Os Info: OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1
  1907. #######################################################################################################################################
  1908. dnsenum VERSION:1.2.4
  1909.  
  1910. ----- en.hmb.gov.tr -----
  1911.  
  1912.  
  1913. Host's addresses:
  1914. __________________
  1915.  
  1916. en.hmb.gov.tr. 1568 IN A 212.174.188.50
  1917.  
  1918.  
  1919. Name Servers:
  1920. ______________
  1921.  
  1922. #######################################################################################################################################
  1923. [+] en.hmb.gov.tr has no SPF record!
  1924. [*] No DMARC record found. Looking for organizational record
  1925. [*] Found organizational DMARC record:
  1926. [*] v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected];
  1927. [*] No explicit organizational subdomain policy. Defaulting to organizational policy
  1928. [+] DMARC policy set to none
  1929. [+] Spoofing possible for en.hmb.gov.tr!
  1930. ######################################################################################################################################
  1931. INFO[0000] Starting to process queue....
  1932. INFO[0000] Starting to process permutations....
  1933. INFO[0001] FORBIDDEN http://hmb-staging.s3.amazonaws.com (http://hmb.gov.tr)
  1934. INFO[0001] FORBIDDEN http://hmb.s3.amazonaws.com (http://hmb.gov.tr)
  1935. #######################################################################################################################################
  1936. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-10 23:59 EDT
  1937. Nmap scan report for en.hmb.gov.tr (212.174.188.50)
  1938. Host is up (0.18s latency).
  1939. Not shown: 995 filtered ports, 3 closed ports
  1940. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  1941. PORT STATE SERVICE
  1942. 80/tcp open http
  1943. 443/tcp open https
  1944.  
  1945. Nmap done: 1 IP address (1 host up) scanned in 34.32 seconds
  1946. #######################################################################################################################################
  1947.  
  1948. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-11 00:00 EDT
  1949. Nmap scan report for en.hmb.gov.tr (212.174.188.50)
  1950. Host is up (0.060s latency).
  1951. Not shown: 2 filtered ports
  1952. PORT STATE SERVICE
  1953. 53/udp open|filtered domain
  1954. 67/udp open|filtered dhcps
  1955. 68/udp open|filtered dhcpc
  1956. 69/udp open|filtered tftp
  1957. 88/udp open|filtered kerberos-sec
  1958. 123/udp open|filtered ntp
  1959. 139/udp open|filtered netbios-ssn
  1960. 161/udp open|filtered snmp
  1961. 162/udp open|filtered snmptrap
  1962. 389/udp open|filtered ldap
  1963. 500/udp open|filtered isakmp
  1964. 520/udp open|filtered route
  1965. 2049/udp open|filtered nfs
  1966.  
  1967. Nmap done: 1 IP address (1 host up) scanned in 14.14 seconds
  1968. #######################################################################################################################################
  1969. HTTP/1.1 301 Moved Permanently
  1970. Server: nginx
  1971. Date: Fri, 11 Oct 2019 03:59:38 GMT
  1972. Content-Type: text/html
  1973. Content-Length: 178
  1974. Connection: keep-alive
  1975. Location: https://en.hmb.gov.tr/
  1976. #######################################################################################################################################
  1977. http://en.hmb.gov.tr [301 Moved Permanently] Country[TURKEY][TR], HTTPServer[nginx], IP[212.174.188.50], RedirectLocation[https://en.hmb.gov.tr/], Title[301 Moved Permanently], nginx
  1978. https://en.hmb.gov.tr/ [200 OK] Country[TURKEY][TR], HTML5, HTTPServer[nginx], IP[212.174.188.50], Script, Title[T.C. Hazine ve Maliye Bakanlığı], X-UA-Compatible[IE=edge], nginx
  1979. #######################################################################################################################################
  1980. wig - WebApp Information Gatherer
  1981.  
  1982.  
  1983. Scanning https://en.hmb.gov.tr...
  1984. _____________________ SITE INFO ______________________
  1985. IP Title
  1986. 212.174.188.50 T.C. Hazine ve Maliye Bakanlığı
  1987.  
  1988. ______________________ VERSION _______________________
  1989. Name Versions Type
  1990. nginx Platform
  1991.  
  1992. ____________________ INTERESTING _____________________
  1993. URL Note Type
  1994. /robots.txt robots.txt index Interesting
  1995.  
  1996. ______________________________________________________
  1997. Time: 150.3 sec Urls: 629 Fingerprints: 40401
  1998. ######################################################################################################################################
  1999. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-11 00:03 EDT
  2000. NSE: Loaded 163 scripts for scanning.
  2001. NSE: Script Pre-scanning.
  2002. Initiating NSE at 00:03
  2003. Completed NSE at 00:03, 0.00s elapsed
  2004. Initiating NSE at 00:03
  2005. Completed NSE at 00:03, 0.00s elapsed
  2006. Initiating Parallel DNS resolution of 1 host. at 00:03
  2007. Completed Parallel DNS resolution of 1 host. at 00:03, 11.86s elapsed
  2008. Initiating SYN Stealth Scan at 00:03
  2009. Scanning en.hmb.gov.tr (212.174.188.50) [1 port]
  2010. Discovered open port 80/tcp on 212.174.188.50
  2011. Completed SYN Stealth Scan at 00:03, 0.28s elapsed (1 total ports)
  2012. Initiating Service scan at 00:03
  2013. Scanning 1 service on en.hmb.gov.tr (212.174.188.50)
  2014. Completed Service scan at 00:03, 6.42s elapsed (1 service on 1 host)
  2015. Initiating OS detection (try #1) against en.hmb.gov.tr (212.174.188.50)
  2016. Retrying OS detection (try #2) against en.hmb.gov.tr (212.174.188.50)
  2017. Initiating Traceroute at 00:03
  2018. Completed Traceroute at 00:03, 3.10s elapsed
  2019. Initiating Parallel DNS resolution of 16 hosts. at 00:03
  2020. Completed Parallel DNS resolution of 16 hosts. at 00:03, 10.38s elapsed
  2021. NSE: Script scanning 212.174.188.50.
  2022. Initiating NSE at 00:03
  2023. Completed NSE at 00:04, 50.46s elapsed
  2024. Initiating NSE at 00:04
  2025. Completed NSE at 00:04, 0.96s elapsed
  2026. Nmap scan report for en.hmb.gov.tr (212.174.188.50)
  2027. Host is up (0.22s latency).
  2028.  
  2029. PORT STATE SERVICE VERSION
  2030. 80/tcp open http nginx
  2031. | http-brute:
  2032. |_ Path "/" does not require authentication
  2033. |_http-chrono: Request times for /; avg: 599.75ms; min: 512.83ms; max: 664.12ms
  2034. | http-cross-domain-policy:
  2035. | VULNERABLE:
  2036. | Cross-domain and Client Access policies.
  2037. | State: LIKELY VULNERABLE
  2038. | A cross-domain policy file specifies the permissions that a web client such as Java, Adobe Flash, Adobe Reader,
  2039. | etc. use to access data across different domains. A client acces policy file is similar to cross-domain policy
  2040. | but is used for M$ Silverlight applications. Overly permissive configurations enables Cross-site Request
  2041. | Forgery attacks, and may allow third parties to access sensitive data meant for the user.
  2042. | Check results:
  2043. | /crossdomain.xml:
  2044. | <?xml version="1.0"?>
  2045. | <!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
  2046. | <cross-domain-policy>
  2047. | <!-- Read this: www.adobe.com/devnet/articles/crossdomain_policy_file_spec.html -->
  2048. |
  2049. | <!-- Most restrictive policy: -->
  2050. | <site-control permitted-cross-domain-policies="none"/>
  2051. |
  2052. | <!-- Least restrictive policy: -->
  2053. | <site-control permitted-cross-domain-policies="all"/>
  2054. | <allow-access-from domain="*.hmb.gov.tr" to-ports="*" secure="false"/>
  2055. | <allow-http-request-headers-from domain="*.hmb.gov.tr" headers="*" secure="false"/>
  2056. |
  2057. | </cross-domain-policy>
  2058. |
  2059. | Extra information:
  2060. | Trusted domains:gov.tr
  2061. | Use the script argument 'domain-lookup' to find trusted domains available for purchase
  2062. | References:
  2063. | http://gursevkalra.blogspot.com/2013/08/bypassing-same-origin-policy-with-flash.html
  2064. | https://www.adobe.com/devnet-docs/acrobatetk/tools/AppSec/CrossDomain_PolicyFile_Specification.pdf
  2065. | https://www.adobe.com/devnet/articles/crossdomain_policy_file_spec.html
  2066. | http://sethsec.blogspot.com/2014/03/exploiting-misconfigured-crossdomainxml.html
  2067. | http://acunetix.com/vulnerabilities/web/insecure-clientaccesspolicy-xml-file
  2068. |_ https://www.owasp.org/index.php/Test_RIA_cross_domain_policy_%28OTG-CONFIG-008%29
  2069. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  2070. |_http-date: Fri, 11 Oct 2019 04:03:13 GMT; -40s from local time.
  2071. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  2072. |_http-dombased-xss: Couldn't find any DOM based XSS.
  2073. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  2074. |_http-errors: Couldn't find any error pages.
  2075. |_http-feed: Couldn't find any feeds.
  2076. |_http-fetch: Please enter the complete path of the directory to save data in.
  2077. | http-headers:
  2078. | Server: nginx
  2079. | Date: Fri, 11 Oct 2019 04:03:16 GMT
  2080. | Content-Type: text/html
  2081. | Content-Length: 178
  2082. | Connection: close
  2083. | Location: https://en.hmb.gov.tr/
  2084. |
  2085. |_ (Request type: GET)
  2086. | http-internal-ip-disclosure:
  2087. |_ Internal IP Leaked: 10.128.10.36
  2088. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  2089. | http-methods:
  2090. |_ Supported Methods: GET HEAD POST OPTIONS
  2091. |_http-mobileversion-checker: No mobile version detected.
  2092. |_http-passwd: ERROR: Script execution failed (use -d to debug)
  2093. |_http-security-headers:
  2094. | http-sitemap-generator:
  2095. | Directory structure:
  2096. | Longest directory structure:
  2097. | Depth: 0
  2098. | Dir: /
  2099. | Total files found (by extension):
  2100. |_
  2101. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  2102. |_http-title: Did not follow redirect to https://en.hmb.gov.tr/
  2103. | http-vhosts:
  2104. | 125 names had status 200
  2105. | www.hmb.gov.tr : 301 -> https://www.hmb.gov.tr/
  2106. |_en.hmb.gov.tr : 301 -> https://en.hmb.gov.tr/
  2107. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
  2108. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  2109. |_http-xssed: No previously reported XSS vuln.
  2110. | vulscan: VulDB - https://vuldb.com:
  2111. | [133852] Sangfor Sundray WLAN Controller up to 3.7.4.2 Cookie Header nginx_webconsole.php Code Execution
  2112. | [132132] SoftNAS Cloud 4.2.0/4.2.1 Nginx privilege escalation
  2113. | [131858] Puppet Discovery up to 1.3.x Nginx Container weak authentication
  2114. | [130644] Nginx Unit up to 1.7.0 Router Process Request Heap-based memory corruption
  2115. | [127759] VeryNginx 0.3.3 Web Application Firewall privilege escalation
  2116. | [126525] nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
  2117. | [126524] nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
  2118. | [126523] nginx up to 1.14.0/1.15.5 HTTP2 Memory Consumption denial of service
  2119. | [119845] Pivotal Operations Manager up to 2.0.13/2.1.5 Nginx privilege escalation
  2120. | [114368] SuSE Portus 2.3 Nginx Certificate weak authentication
  2121. | [103517] nginx up to 1.13.2 Range Filter Request Integer Overflow memory corruption
  2122. | [89849] nginx RFC 3875 Namespace Conflict Environment Variable Open Redirect
  2123. | [87719] nginx up to 1.11.0 ngx_files.c ngx_chain_to_iovec denial of service
  2124. | [80760] nginx 0.6.18/1.9.9 DNS CNAME Record Crash denial of service
  2125. | [80759] nginx 0.6.18/1.9.9 DNS CNAME Record Use-After-Free denial of service
  2126. | [80758] nginx 0.6.18/1.9.9 DNS UDP Packet Crash denial of service
  2127. | [67677] nginx up to 1.7.3 SSL weak authentication
  2128. | [67296] nginx up to 1.7.3 SMTP Proxy ngx_mail_smtp_starttls privilege escalation
  2129. | [12822] nginx up to 1.5.11 SPDY SPDY Request Heap-based memory corruption
  2130. | [12824] nginx 1.5.10 on 32-bit SPDY memory corruption
  2131. | [11237] nginx up to 1.5.6 URI String Bypass privilege escalation
  2132. | [65364] nginx up to 1.1.13 Default Configuration information disclosure
  2133. | [8671] nginx up to 1.4 proxy_pass denial of service
  2134. | [8618] nginx 1.3.9/1.4.0 http/ngx_http_parse.c ngx_http_parse_chunked() memory corruption
  2135. | [7247] nginx 1.2.6 Proxy Function spoofing
  2136. | [61434] nginx 1.2.0/1.3.0 on Windows Access Restriction privilege escalation
  2137. | [5293] nginx up to 1.1.18 ngx_http_mp4_module MP4 File memory corruption
  2138. | [4843] nginx up to 1.0.13/1.1.16 HTTP Header Response Parser ngx_http_parse.c information disclosure
  2139. | [59645] nginx up to 0.8.9 Heap-based memory corruption
  2140. | [53592] nginx 0.8.36 memory corruption
  2141. | [53590] nginx up to 0.8.9 unknown vulnerability
  2142. | [51533] nginx 0.7.64 Terminal privilege escalation
  2143. | [50905] nginx up to 0.8.9 directory traversal
  2144. | [50903] nginx up to 0.8.10 NULL Pointer Dereference denial of service
  2145. | [50043] nginx up to 0.8.10 memory corruption
  2146. |
  2147. | MITRE CVE - https://cve.mitre.org:
  2148. | [CVE-2013-2070] http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
  2149. | [CVE-2013-2028] The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
  2150. | [CVE-2012-3380] Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
  2151. | [CVE-2012-2089] Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
  2152. | [CVE-2012-1180] Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
  2153. | [CVE-2011-4963] nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
  2154. | [CVE-2011-4315] Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
  2155. | [CVE-2010-2266] nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
  2156. | [CVE-2010-2263] nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
  2157. | [CVE-2009-4487] nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
  2158. | [CVE-2009-3898] Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
  2159. | [CVE-2009-3896] src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.
  2160. | [CVE-2009-2629] Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
  2161. |
  2162. | SecurityFocus - https://www.securityfocus.com/bid/:
  2163. | [99534] Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
  2164. | [93903] Nginx CVE-2016-1247 Remote Privilege Escalation Vulnerability
  2165. | [91819] Nginx CVE-2016-1000105 Security Bypass Vulnerability
  2166. | [90967] nginx CVE-2016-4450 Denial of Service Vulnerability
  2167. | [82230] nginx Multiple Denial of Service Vulnerabilities
  2168. | [78928] Nginx CVE-2010-2266 Denial-Of-Service Vulnerability
  2169. | [70025] nginx CVE-2014-3616 SSL Session Fixation Vulnerability
  2170. | [69111] nginx SMTP Proxy Remote Command Injection Vulnerability
  2171. | [67507] nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
  2172. | [66537] nginx SPDY Implementation Heap Based Buffer Overflow Vulnerability
  2173. | [63814] nginx CVE-2013-4547 URI Processing Security Bypass Vulnerability
  2174. | [59824] Nginx CVE-2013-2070 Remote Security Vulnerability
  2175. | [59699] nginx 'ngx_http_parse.c' Stack Buffer Overflow Vulnerability
  2176. | [59496] nginx 'ngx_http_close_connection()' Remote Integer Overflow Vulnerability
  2177. | [59323] nginx NULL-Byte Arbitrary Code Execution Vulnerability
  2178. | [58105] Nginx 'access.log' Insecure File Permissions Vulnerability
  2179. | [57139] nginx CVE-2011-4968 Man in The Middle Vulnerability
  2180. | [55920] nginx CVE-2011-4963 Security Bypass Vulnerability
  2181. | [54331] Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
  2182. | [52999] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  2183. | [52578] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  2184. | [50710] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  2185. | [40760] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  2186. | [40434] nginx Space String Remote Source Code Disclosure Vulnerability
  2187. | [40420] nginx Directory Traversal Vulnerability
  2188. | [37711] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  2189. | [36839] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  2190. | [36490] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  2191. | [36438] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  2192. | [36384] nginx HTTP Request Remote Buffer Overflow Vulnerability
  2193. |
  2194. | IBM X-Force - https://exchange.xforce.ibmcloud.com:
  2195. | [84623] Phusion Passenger gem for Ruby with nginx configuration insecure permissions
  2196. | [84172] nginx denial of service
  2197. | [84048] nginx buffer overflow
  2198. | [83923] nginx ngx_http_close_connection() integer overflow
  2199. | [83688] nginx null byte code execution
  2200. | [83103] Naxsi module for Nginx naxsi_unescape_uri() function security bypass
  2201. | [82319] nginx access.log information disclosure
  2202. | [80952] nginx SSL spoofing
  2203. | [77244] nginx and Microsoft Windows request security bypass
  2204. | [76778] Naxsi module for Nginx nx_extract.py directory traversal
  2205. | [74831] nginx ngx_http_mp4_module.c buffer overflow
  2206. | [74191] nginx ngx_cpystrn() information disclosure
  2207. | [74045] nginx header response information disclosure
  2208. | [71355] nginx ngx_resolver_copy() buffer overflow
  2209. | [59370] nginx characters denial of service
  2210. | [59369] nginx DATA source code disclosure
  2211. | [59047] nginx space source code disclosure
  2212. | [58966] nginx unspecified directory traversal
  2213. | [54025] nginx ngx_http_parse.c denial of service
  2214. | [53431] nginx WebDAV component directory traversal
  2215. | [53328] Nginx CRC-32 cached domain name spoofing
  2216. | [53250] Nginx ngx_http_parse_complex_uri() function code execution
  2217. |
  2218. | Exploit-DB - https://www.exploit-db.com:
  2219. | [26737] nginx 1.3.9/1.4.0 x86 Brute Force Remote Exploit
  2220. | [25775] Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow
  2221. | [25499] nginx 1.3.9-1.4.0 DoS PoC
  2222. | [24967] nginx 0.6.x Arbitrary Code Execution NullByte Injection
  2223. | [14830] nginx 0.6.38 - Heap Corruption Exploit
  2224. | [13822] Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability
  2225. | [13818] Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities
  2226. | [12804] nginx [engine x] http server <= 0.6.36 Path Draversal
  2227. | [9901] nginx 0.7.0-0.7.61, 0.6.0-0.6.38, 0.5.0-0.5.37, 0.4.0-0.4.14 PoC
  2228. | [9829] nginx 0.7.61 WebDAV directory traversal
  2229. |
  2230. | OpenVAS (Nessus) - http://www.openvas.org:
  2231. | [864418] Fedora Update for nginx FEDORA-2012-3846
  2232. | [864310] Fedora Update for nginx FEDORA-2012-6238
  2233. | [864209] Fedora Update for nginx FEDORA-2012-6411
  2234. | [864204] Fedora Update for nginx FEDORA-2012-6371
  2235. | [864121] Fedora Update for nginx FEDORA-2012-4006
  2236. | [864115] Fedora Update for nginx FEDORA-2012-3991
  2237. | [864065] Fedora Update for nginx FEDORA-2011-16075
  2238. | [863654] Fedora Update for nginx FEDORA-2011-16110
  2239. | [861232] Fedora Update for nginx FEDORA-2007-1158
  2240. | [850180] SuSE Update for nginx openSUSE-SU-2012:0237-1 (nginx)
  2241. | [831680] Mandriva Update for nginx MDVSA-2012:043 (nginx)
  2242. | [802045] 64-bit Debian Linux Rootkit with nginx Doing iFrame Injection
  2243. | [801636] nginx HTTP Request Remote Buffer Overflow Vulnerability
  2244. | [103470] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  2245. | [103469] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  2246. | [103344] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  2247. | [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  2248. | [100659] nginx Directory Traversal Vulnerability
  2249. | [100658] nginx Space String Remote Source Code Disclosure Vulnerability
  2250. | [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  2251. | [100321] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  2252. | [100277] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  2253. | [100276] nginx HTTP Request Remote Buffer Overflow Vulnerability
  2254. | [100275] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  2255. | [71574] Gentoo Security Advisory GLSA 201206-07 (nginx)
  2256. | [71308] Gentoo Security Advisory GLSA 201203-22 (nginx)
  2257. | [71297] FreeBSD Ports: nginx
  2258. | [71276] FreeBSD Ports: nginx
  2259. | [71239] Debian Security Advisory DSA 2434-1 (nginx)
  2260. | [66451] Fedora Core 11 FEDORA-2009-12782 (nginx)
  2261. | [66450] Fedora Core 10 FEDORA-2009-12775 (nginx)
  2262. | [66449] Fedora Core 12 FEDORA-2009-12750 (nginx)
  2263. | [64924] Gentoo Security Advisory GLSA 200909-18 (nginx)
  2264. | [64912] Fedora Core 10 FEDORA-2009-9652 (nginx)
  2265. | [64911] Fedora Core 11 FEDORA-2009-9630 (nginx)
  2266. | [64894] FreeBSD Ports: nginx
  2267. | [64869] Debian Security Advisory DSA 1884-1 (nginx)
  2268. |
  2269. | SecurityTracker - https://www.securitytracker.com:
  2270. | [1028544] nginx Bug Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
  2271. | [1028519] nginx Stack Overflow Lets Remote Users Execute Arbitrary Code
  2272. | [1026924] nginx Buffer Overflow in ngx_http_mp4_module Lets Remote Users Execute Arbitrary Code
  2273. | [1026827] nginx HTTP Response Processing Lets Remote Users Obtain Portions of Memory Contents
  2274. |
  2275. | OSVDB - http://www.osvdb.org:
  2276. | [94864] cPnginx Plugin for cPanel nginx Configuration Manipulation Arbitrary File Access
  2277. | [93282] nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
  2278. | [93037] nginx /http/ngx_http_parse.c Worker Process Crafted Request Handling Remote Overflow
  2279. | [92796] nginx ngx_http_close_connection Function Crafted r-&gt
  2280. | [92634] nginx ngx_http_request.h zero_in_uri URL Null Byte Handling Remote Code Execution
  2281. | [90518] nginx Log Directory Permission Weakness Local Information Disclosure
  2282. | [88910] nginx Proxy Functionality SSL Certificate Validation MitM Spoofing Weakness
  2283. | [84339] nginx/Windows Multiple Request Sequence Parsing Arbitrary File Access
  2284. | [83617] Naxsi Module for Nginx naxsi-ui/ nx_extract.py Traversal Arbitrary File Access
  2285. | [81339] nginx ngx_http_mp4_module Module Atom MP4 File Handling Remote Overflow
  2286. | [80124] nginx HTTP Header Response Parsing Freed Memory Information Disclosure
  2287. | [77184] nginx ngx_resolver.c ngx_resolver_copy() Function DNS Response Parsing Remote Overflow
  2288. | [65531] nginx on Windows URI ::$DATA Append Arbitrary File Access
  2289. | [65530] nginx Encoded Traversal Sequence Memory Corruption Remote DoS
  2290. | [65294] nginx on Windows Encoded Space Request Remote Source Disclosure
  2291. | [63136] nginx on Windows 8.3 Filename Alias Request Access Rules / Authentication Bypass
  2292. | [62617] nginx Internal DNS Cache Poisoning Weakness
  2293. | [61779] nginx HTTP Request Escape Sequence Terminal Command Injection
  2294. | [59278] nginx src/http/ngx_http_parse.c ngx_http_process_request_headers() Function URL Handling NULL Dereference DoS
  2295. | [58328] nginx WebDAV Multiple Method Traversal Arbitrary File Write
  2296. | [58128] nginx ngx_http_parse_complex_uri() Function Underflow
  2297. | [44447] nginx (engine x) msie_refresh Directive Unspecified XSS
  2298. | [44446] nginx (engine x) ssl_verify_client Directive HTTP/0.9 Protocol Bypass
  2299. | [44445] nginx (engine x) ngx_http_realip_module satisfy_any Directive Unspecified Access Bypass
  2300. | [44444] nginx (engine x) X-Accel-Redirect Header Unspecified Traversal
  2301. | [44443] nginx (engine x) rtsig Method Signal Queue Overflow
  2302. | [44442] nginx (engine x) Worker Process Millisecond Timers Unspecified Overflow
  2303. |_
  2304. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  2305. Device type: general purpose
  2306. Running (JUST GUESSING): Linux 3.X|2.6.X|4.X (98%)
  2307. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:4.0
  2308. Aggressive OS guesses: Linux 3.10 - 3.12 (98%), Linux 2.6.32 (90%), Linux 3.10 - 3.16 (90%), Linux 4.0 (90%), Linux 4.4 (89%), Linux 3.10 (88%)
  2309. No exact OS matches for host (test conditions non-ideal).
  2310. Uptime guess: 11.868 days (since Sun Sep 29 03:14:49 2019)
  2311. Network Distance: 25 hops
  2312. TCP Sequence Prediction: Difficulty=263 (Good luck!)
  2313. IP ID Sequence Generation: All zeros
  2314.  
  2315. TRACEROUTE (using port 80/tcp)
  2316. HOP RTT ADDRESS
  2317. 1 56.55 ms 10.249.204.1
  2318. 2 86.95 ms 104.245.145.161
  2319. 3 87.08 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
  2320. 4 87.06 ms te0-0-0-1.agr13.yyz02.atlas.cogentco.com (154.24.54.37)
  2321. 5 87.04 ms te0-9-0-9.ccr32.yyz02.atlas.cogentco.com (154.54.43.153)
  2322. 6 87.15 ms be2994.ccr22.cle04.atlas.cogentco.com (154.54.31.233)
  2323. 7 87.19 ms be2718.ccr42.ord01.atlas.cogentco.com (154.54.7.129)
  2324. 8 87.29 ms be2766.ccr41.ord03.atlas.cogentco.com (154.54.46.178)
  2325. 9 87.25 ms ae-11.r08.chcgil09.us.bb.gin.ntt.net (129.250.9.121)
  2326. 10 87.34 ms ae-0.r20.chcgil09.us.bb.gin.ntt.net (129.250.2.191)
  2327. 11 82.60 ms ae-0.r25.nycmny01.us.bb.gin.ntt.net (129.250.2.167)
  2328. 12 219.03 ms ae-9.r24.frnkge08.de.bb.gin.ntt.net (129.250.2.5)
  2329. 13 187.16 ms ae-1.r01.frnkge13.de.bb.gin.ntt.net (129.250.2.85)
  2330. 14 ... 18
  2331. 19 249.06 ms mta4-v14.buaslanmis.com (212.174.117.78)
  2332. 20 249.10 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  2333. 21 244.98 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  2334. 22 207.76 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  2335. 23 214.44 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  2336. 24 257.95 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  2337. 25 227.69 ms 212.174.188.50
  2338.  
  2339. NSE: Script Post-scanning.
  2340. Initiating NSE at 00:04
  2341. Completed NSE at 00:04, 0.00s elapsed
  2342. Initiating NSE at 00:04
  2343. Completed NSE at 00:04, 0.00s elapsed
  2344. Read data files from: /usr/bin/../share/nmap
  2345. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  2346. Nmap done: 1 IP address (1 host up) scanned in 90.51 seconds
  2347. Raw packets sent: 125 (10.636KB) | Rcvd: 51 (3.630KB)
  2348. ######################################################################################################################################
  2349. ------------------------------------------------------------------------------------------------------------------------
  2350.  
  2351. [ ! ] Starting SCANNER INURLBR 2.1 at [11-10-2019 00:04:59]
  2352. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  2353. It is the end user's responsibility to obey all applicable local, state and federal laws.
  2354. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  2355.  
  2356. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/en.hmb.gov.tr/output/inurlbr-en.hmb.gov.tr ]
  2357. [ INFO ][ DORK ]::[ site:en.hmb.gov.tr ]
  2358. [ INFO ][ SEARCHING ]:: {
  2359. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.gr ]
  2360.  
  2361. [ INFO ][ SEARCHING ]::
  2362. -[:::]
  2363. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  2364.  
  2365. [ INFO ][ SEARCHING ]::
  2366. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  2367. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.co.ck ID: 006688160405527839966:yhpefuwybre ]
  2368.  
  2369. [ INFO ][ SEARCHING ]::
  2370. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  2371.  
  2372. [ INFO ][ TOTAL FOUND VALUES ]:: [ 100 ]
  2373.  
  2374.  
  2375. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2376. |_[ + ] [ 0 / 100 ]-[00:05:14] [ - ]
  2377. |_[ + ] Target:: [ https://en.hmb.gov.tr/ ]
  2378. |_[ + ] Exploit::
  2379. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2380. |_[ + ] More details:: / - / , ISP:
  2381. |_[ + ] Found:: UNIDENTIFIED
  2382.  
  2383. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2384. |_[ + ] [ 1 / 100 ]-[00:05:16] [ - ]
  2385. |_[ + ] Target:: [ https://en.hmb.gov.tr/awards ]
  2386. |_[ + ] Exploit::
  2387. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2388. |_[ + ] More details:: / - / , ISP:
  2389. |_[ + ] Found:: UNIDENTIFIED
  2390.  
  2391. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2392. |_[ + ] [ 2 / 100 ]-[00:05:17] [ - ]
  2393. |_[ + ] Target:: [ https://en.hmb.gov.tr/contact ]
  2394. |_[ + ] Exploit::
  2395. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2396. |_[ + ] More details:: / - / , ISP:
  2397. |_[ + ] Found:: UNIDENTIFIED
  2398.  
  2399. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2400. |_[ + ] [ 3 / 100 ]-[00:05:19] [ - ]
  2401. |_[ + ] Target:: [ https://en.hmb.gov.tr/municipalities ]
  2402. |_[ + ] Exploit::
  2403. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2404. |_[ + ] More details:: / - / , ISP:
  2405. |_[ + ] Found:: UNIDENTIFIED
  2406.  
  2407. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2408. |_[ + ] [ 4 / 100 ]-[00:05:21] [ - ]
  2409. |_[ + ] Target:: [ https://en.hmb.gov.tr/departments ]
  2410. |_[ + ] Exploit::
  2411. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2412. |_[ + ] More details:: / - / , ISP:
  2413. |_[ + ] Found:: UNIDENTIFIED
  2414.  
  2415. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2416. |_[ + ] [ 5 / 100 ]-[00:05:22] [ - ]
  2417. |_[ + ] Target:: [ https://en.hmb.gov.tr/disclaimer ]
  2418. |_[ + ] Exploit::
  2419. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2420. |_[ + ] More details:: / - / , ISP:
  2421. |_[ + ] Found:: UNIDENTIFIED
  2422.  
  2423. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2424. |_[ + ] [ 6 / 100 ]-[00:05:24] [ - ]
  2425. |_[ + ] Target:: [ https://en.hmb.gov.tr/insurance ]
  2426. |_[ + ] Exploit::
  2427. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2428. |_[ + ] More details:: / - / , ISP:
  2429. |_[ + ] Found:: UNIDENTIFIED
  2430.  
  2431. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2432. |_[ + ] [ 7 / 100 ]-[00:05:25] [ - ]
  2433. |_[ + ] Target:: [ https://en.hmb.gov.tr/mtp ]
  2434. |_[ + ] Exploit::
  2435. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2436. |_[ + ] More details:: / - / , ISP:
  2437. |_[ + ] Found:: UNIDENTIFIED
  2438.  
  2439. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2440. |_[ + ] [ 8 / 100 ]-[00:05:27] [ - ]
  2441. |_[ + ] Target:: [ https://en.hmb.gov.tr/minister ]
  2442. |_[ + ] Exploit::
  2443. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2444. |_[ + ] More details:: / - / , ISP:
  2445. |_[ + ] Found:: UNIDENTIFIED
  2446.  
  2447. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2448. |_[ + ] [ 9 / 100 ]-[00:05:28] [ - ]
  2449. |_[ + ] Target:: [ https://en.hmb.gov.tr/links ]
  2450. |_[ + ] Exploit::
  2451. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2452. |_[ + ] More details:: / - / , ISP:
  2453. |_[ + ] Found:: UNIDENTIFIED
  2454.  
  2455. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2456. |_[ + ] [ 10 / 100 ]-[00:05:30] [ - ]
  2457. |_[ + ] Target:: [ https://en.hmb.gov.tr/exchange ]
  2458. |_[ + ] Exploit::
  2459. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2460. |_[ + ] More details:: / - / , ISP:
  2461. |_[ + ] Found:: UNIDENTIFIED
  2462.  
  2463. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2464. |_[ + ] [ 11 / 100 ]-[00:05:32] [ - ]
  2465. |_[ + ] Target:: [ https://en.hmb.gov.tr/foreign-offices ]
  2466. |_[ + ] Exploit::
  2467. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2468. |_[ + ] More details:: / - / , ISP:
  2469. |_[ + ] Found:: UNIDENTIFIED
  2470.  
  2471. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2472. |_[ + ] [ 12 / 100 ]-[00:05:33] [ - ]
  2473. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-newsletter ]
  2474. |_[ + ] Exploit::
  2475. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2476. |_[ + ] More details:: / - / , ISP:
  2477. |_[ + ] Found:: UNIDENTIFIED
  2478.  
  2479. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2480. |_[ + ] [ 13 / 100 ]-[00:05:35] [ - ]
  2481. |_[ + ] Target:: [ https://en.hmb.gov.tr/public-finance ]
  2482. |_[ + ] Exploit::
  2483. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2484. |_[ + ] More details:: / - / , ISP:
  2485. |_[ + ] Found:: UNIDENTIFIED
  2486.  
  2487. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2488. |_[ + ] [ 14 / 100 ]-[00:05:36] [ - ]
  2489. |_[ + ] Target:: [ https://en.hmb.gov.tr/imf-relations ]
  2490. |_[ + ] Exploit::
  2491. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2492. |_[ + ] More details:: / - / , ISP:
  2493. |_[ + ] Found:: UNIDENTIFIED
  2494.  
  2495. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2496. |_[ + ] [ 15 / 100 ]-[00:05:37] [ - ]
  2497. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-books ]
  2498. |_[ + ] Exploit::
  2499. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2500. |_[ + ] More details:: / - / , ISP:
  2501. |_[ + ] Found:: UNIDENTIFIED
  2502.  
  2503. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2504. |_[ + ] [ 16 / 100 ]-[00:05:39] [ - ]
  2505. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-typologies ]
  2506. |_[ + ] Exploit::
  2507. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2508. |_[ + ] More details:: / - / , ISP:
  2509. |_[ + ] Found:: UNIDENTIFIED
  2510.  
  2511. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2512. |_[ + ] [ 17 / 100 ]-[00:05:41] [ - ]
  2513. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-sanctions ]
  2514. |_[ + ] Exploit::
  2515. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2516. |_[ + ] More details:: / - / , ISP:
  2517. |_[ + ] Found:: UNIDENTIFIED
  2518.  
  2519. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2520. |_[ + ] [ 18 / 100 ]-[00:05:42] [ - ]
  2521. |_[ + ] Target:: [ https://en.hmb.gov.tr/central-government ]
  2522. |_[ + ] Exploit::
  2523. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2524. |_[ + ] More details:: / - / , ISP:
  2525. |_[ + ] Found:: UNIDENTIFIED
  2526.  
  2527. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2528. |_[ + ] [ 19 / 100 ]-[00:05:44] [ - ]
  2529. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-guidelines ]
  2530. |_[ + ] Exploit::
  2531. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2532. |_[ + ] More details:: / - / , ISP:
  2533. |_[ + ] Found:: UNIDENTIFIED
  2534.  
  2535. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2536. |_[ + ] [ 20 / 100 ]-[00:05:45] [ - ]
  2537. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-announcements ]
  2538. |_[ + ] Exploit::
  2539. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2540. |_[ + ] More details:: / - / , ISP:
  2541. |_[ + ] Found:: UNIDENTIFIED
  2542.  
  2543. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2544. |_[ + ] [ 21 / 100 ]-[00:05:47] [ - ]
  2545. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-subscription ]
  2546. |_[ + ] Exploit::
  2547. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2548. |_[ + ] More details:: / - / , ISP:
  2549. |_[ + ] Found:: UNIDENTIFIED
  2550.  
  2551. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2552. |_[ + ] [ 22 / 100 ]-[00:05:48] [ - ]
  2553. |_[ + ] Target:: [ https://en.hmb.gov.tr/insurance-reports ]
  2554. |_[ + ] Exploit::
  2555. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2556. |_[ + ] More details:: / - / , ISP:
  2557. |_[ + ] Found:: UNIDENTIFIED
  2558.  
  2559. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2560. |_[ + ] [ 23 / 100 ]-[00:05:50] [ - ]
  2561. |_[ + ] Target:: [ https://en.hmb.gov.tr/treasury-law ]
  2562. |_[ + ] Exploit::
  2563. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2564. |_[ + ] More details:: / - / , ISP:
  2565. |_[ + ] Found:: UNIDENTIFIED
  2566.  
  2567. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2568. |_[ + ] [ 24 / 100 ]-[00:05:51] [ - ]
  2569. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-presentation ]
  2570. |_[ + ] Exploit::
  2571. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2572. |_[ + ] More details:: / - / , ISP:
  2573. |_[ + ] Found:: UNIDENTIFIED
  2574.  
  2575. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2576. |_[ + ] [ 25 / 100 ]-[00:05:53] [ - ]
  2577. |_[ + ] Target:: [ https://en.hmb.gov.tr/economic-indicators ]
  2578. |_[ + ] Exploit::
  2579. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2580. |_[ + ] More details:: / - / , ISP:
  2581. |_[ + ] Found:: UNIDENTIFIED
  2582.  
  2583. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2584. |_[ + ] [ 26 / 100 ]-[00:05:54] [ - ]
  2585. |_[ + ] Target:: [ https://en.hmb.gov.tr/credit-ratings ]
  2586. |_[ + ] Exploit::
  2587. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2588. |_[ + ] More details:: / - / , ISP:
  2589. |_[ + ] Found:: UNIDENTIFIED
  2590.  
  2591. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2592. |_[ + ] [ 27 / 100 ]-[00:05:56] [ - ]
  2593. |_[ + ] Target:: [ https://en.hmb.gov.tr/general-government ]
  2594. |_[ + ] Exploit::
  2595. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2596. |_[ + ] More details:: / - / , ISP:
  2597. |_[ + ] Found:: UNIDENTIFIED
  2598.  
  2599. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2600. |_[ + ] [ 28 / 100 ]-[00:05:58] [ - ]
  2601. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-contacts ]
  2602. |_[ + ] Exploit::
  2603. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2604. |_[ + ] More details:: / - / , ISP:
  2605. |_[ + ] Found:: UNIDENTIFIED
  2606.  
  2607. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2608. |_[ + ] [ 29 / 100 ]-[00:05:59] [ - ]
  2609. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-dictionary ]
  2610. |_[ + ] Exploit::
  2611. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2612. |_[ + ] More details:: / - / , ISP:
  2613. |_[ + ] Found:: UNIDENTIFIED
  2614.  
  2615. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2616. |_[ + ] [ 30 / 100 ]-[00:06:01] [ - ]
  2617. |_[ + ] Target:: [ https://en.hmb.gov.tr/local-government ]
  2618. |_[ + ] Exploit::
  2619. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2620. |_[ + ] More details:: / - / , ISP:
  2621. |_[ + ] Found:: UNIDENTIFIED
  2622.  
  2623. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2624. |_[ + ] [ 31 / 100 ]-[00:06:02] [ - ]
  2625. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-history ]
  2626. |_[ + ] Exploit::
  2627. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2628. |_[ + ] More details:: / - / , ISP:
  2629. |_[ + ] Found:: UNIDENTIFIED
  2630.  
  2631. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2632. |_[ + ] [ 32 / 100 ]-[00:06:04] [ - ]
  2633. |_[ + ] Target:: [ https://en.hmb.gov.tr/contact-us ]
  2634. |_[ + ] Exploit::
  2635. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2636. |_[ + ] More details:: / - / , ISP:
  2637. |_[ + ] Found:: UNIDENTIFIED
  2638.  
  2639. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2640. |_[ + ] [ 33 / 100 ]-[00:06:05] [ - ]
  2641. |_[ + ] Target:: [ https://en.hmb.gov.tr/sec-registrations ]
  2642. |_[ + ] Exploit::
  2643. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2644. |_[ + ] More details:: / - / , ISP:
  2645. |_[ + ] Found:: UNIDENTIFIED
  2646.  
  2647. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2648. |_[ + ] [ 34 / 100 ]-[00:06:07] [ - ]
  2649. |_[ + ] Target:: [ https://en.hmb.gov.tr/secondary-legislation ]
  2650. |_[ + ] Exploit::
  2651. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2652. |_[ + ] More details:: / - / , ISP:
  2653. |_[ + ] Found:: UNIDENTIFIED
  2654.  
  2655. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2656. |_[ + ] [ 35 / 100 ]-[00:06:08] [ - ]
  2657. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-str ]
  2658. |_[ + ] Exploit::
  2659. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2660. |_[ + ] More details:: / - / , ISP:
  2661. |_[ + ] Found:: UNIDENTIFIED
  2662.  
  2663. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2664. |_[ + ] [ 36 / 100 ]-[00:06:10] [ - ]
  2665. |_[ + ] Target:: [ https://en.hmb.gov.tr/insurance-legislation ]
  2666. |_[ + ] Exploit::
  2667. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2668. |_[ + ] More details:: / - / , ISP:
  2669. |_[ + ] Found:: UNIDENTIFIED
  2670.  
  2671. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2672. |_[ + ] [ 37 / 100 ]-[00:06:11] [ - ]
  2673. |_[ + ] Target:: [ https://en.hmb.gov.tr/metropolitan-municipalities ]
  2674. |_[ + ] Exploit::
  2675. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2676. |_[ + ] More details:: / - / , ISP:
  2677. |_[ + ] Found:: UNIDENTIFIED
  2678.  
  2679. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2680. |_[ + ] [ 38 / 100 ]-[00:06:13] [ - ]
  2681. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-projects ]
  2682. |_[ + ] Exploit::
  2683. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2684. |_[ + ] More details:: / - / , ISP:
  2685. |_[ + ] Found:: UNIDENTIFIED
  2686.  
  2687. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2688. |_[ + ] [ 39 / 100 ]-[00:06:14] [ - ]
  2689. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-chronology ]
  2690. |_[ + ] Exploit::
  2691. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2692. |_[ + ] More details:: / - / , ISP:
  2693. |_[ + ] Found:: UNIDENTIFIED
  2694.  
  2695. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2696. |_[ + ] [ 40 / 100 ]-[00:06:16] [ - ]
  2697. |_[ + ] Target:: [ https://en.hmb.gov.tr/iacb-projects ]
  2698. |_[ + ] Exploit::
  2699. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2700. |_[ + ] More details:: / - / , ISP:
  2701. |_[ + ] Found:: UNIDENTIFIED
  2702.  
  2703. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2704. |_[ + ] [ 41 / 100 ]-[00:06:17] [ - ]
  2705. |_[ + ] Target:: [ https://en.hmb.gov.tr/exchange-legislation ]
  2706. |_[ + ] Exploit::
  2707. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2708. |_[ + ] More details:: / - / , ISP:
  2709. |_[ + ] Found:: UNIDENTIFIED
  2710.  
  2711. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2712. |_[ + ] [ 42 / 100 ]-[00:06:19] [ - ]
  2713. |_[ + ] Target:: [ https://en.hmb.gov.tr/bulent-aksu ]
  2714. |_[ + ] Exploit::
  2715. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2716. |_[ + ] More details:: / - / , ISP:
  2717. |_[ + ] Found:: UNIDENTIFIED
  2718.  
  2719. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2720. |_[ + ] [ 43 / 100 ]-[00:06:21] [ - ]
  2721. |_[ + ] Target:: [ https://en.hmb.gov.tr/development-agencies ]
  2722. |_[ + ] Exploit::
  2723. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2724. |_[ + ] More details:: / - / , ISP:
  2725. |_[ + ] Found:: UNIDENTIFIED
  2726.  
  2727. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2728. |_[ + ] [ 44 / 100 ]-[00:06:22] [ - ]
  2729. |_[ + ] Target:: [ https://en.hmb.gov.tr/extrabudegetary-funds ]
  2730. |_[ + ] Exploit::
  2731. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2732. |_[ + ] More details:: / - / , ISP:
  2733. |_[ + ] Found:: UNIDENTIFIED
  2734.  
  2735. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2736. |_[ + ] [ 45 / 100 ]-[00:06:24] [ - ]
  2737. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-tasks ]
  2738. |_[ + ] Exploit::
  2739. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2740. |_[ + ] More details:: / - / , ISP:
  2741. |_[ + ] Found:: UNIDENTIFIED
  2742.  
  2743. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2744. |_[ + ] [ 46 / 100 ]-[00:06:25] [ - ]
  2745. |_[ + ] Target:: [ https://en.hmb.gov.tr/iacb-publications ]
  2746. |_[ + ] Exploit::
  2747. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2748. |_[ + ] More details:: / - / , ISP:
  2749. |_[ + ] Found:: UNIDENTIFIED
  2750.  
  2751. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2752. |_[ + ] [ 47 / 100 ]-[00:06:27] [ - ]
  2753. |_[ + ] Target:: [ https://en.hmb.gov.tr/social-facilities ]
  2754. |_[ + ] Exploit::
  2755. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2756. |_[ + ] More details:: / - / , ISP:
  2757. |_[ + ] Found:: UNIDENTIFIED
  2758.  
  2759. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2760. |_[ + ] [ 48 / 100 ]-[00:06:28] [ - ]
  2761. |_[ + ] Target:: [ https://en.hmb.gov.tr/national-standarts ]
  2762. |_[ + ] Exploit::
  2763. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2764. |_[ + ] More details:: / - / , ISP:
  2765. |_[ + ] Found:: UNIDENTIFIED
  2766.  
  2767. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2768. |_[ + ] [ 49 / 100 ]-[00:06:30] [ - ]
  2769. |_[ + ] Target:: [ https://en.hmb.gov.tr/primary-legislation ]
  2770. |_[ + ] Exploit::
  2771. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2772. |_[ + ] More details:: / - / , ISP:
  2773. |_[ + ] Found:: UNIDENTIFIED
  2774.  
  2775. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2776. |_[ + ] [ 50 / 100 ]-[00:06:31] [ - ]
  2777. |_[ + ] Target:: [ https://en.hmb.gov.tr/investors-guides ]
  2778. |_[ + ] Exploit::
  2779. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2780. |_[ + ] More details:: / - / , ISP:
  2781. |_[ + ] Found:: UNIDENTIFIED
  2782.  
  2783. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2784. |_[ + ] [ 51 / 100 ]-[00:06:33] [ - ]
  2785. |_[ + ] Target:: [ https://en.hmb.gov.tr/tertiary-legislation ]
  2786. |_[ + ] Exploit::
  2787. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2788. |_[ + ] More details:: / - / , ISP:
  2789. |_[ + ] Found:: UNIDENTIFIED
  2790.  
  2791. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2792. |_[ + ] [ 52 / 100 ]-[00:06:35] [ - ]
  2793. |_[ + ] Target:: [ https://en.hmb.gov.tr/revolving-funds ]
  2794. |_[ + ] Exploit::
  2795. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2796. |_[ + ] More details:: / - / , ISP:
  2797. |_[ + ] Found:: UNIDENTIFIED
  2798.  
  2799. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2800. |_[ + ] [ 53 / 100 ]-[00:06:36] [ - ]
  2801. |_[ + ] Target:: [ https://en.hmb.gov.tr/debt-indicators ]
  2802. |_[ + ] Exploit::
  2803. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2804. |_[ + ] More details:: / - / , ISP:
  2805. |_[ + ] Found:: UNIDENTIFIED
  2806.  
  2807. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2808. |_[ + ] [ 54 / 100 ]-[00:06:37] [ - ]
  2809. |_[ + ] Target:: [ https://en.hmb.gov.tr/osman-dincbas ]
  2810. |_[ + ] Exploit::
  2811. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2812. |_[ + ] More details:: / - / , ISP:
  2813. |_[ + ] Found:: UNIDENTIFIED
  2814.  
  2815. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2816. |_[ + ] [ 55 / 100 ]-[00:06:39] [ - ]
  2817. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-communication ]
  2818. |_[ + ] Exploit::
  2819. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2820. |_[ + ] More details:: / - / , ISP:
  2821. |_[ + ] Found:: UNIDENTIFIED
  2822.  
  2823. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2824. |_[ + ] [ 56 / 100 ]-[00:06:41] [ - ]
  2825. |_[ + ] Target:: [ https://en.hmb.gov.tr/wb-relations ]
  2826. |_[ + ] Exploit::
  2827. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2828. |_[ + ] More details:: / - / , ISP:
  2829. |_[ + ] Found:: UNIDENTIFIED
  2830.  
  2831. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2832. |_[ + ] [ 57 / 100 ]-[00:06:42] [ - ]
  2833. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/growth ]
  2834. |_[ + ] Exploit::
  2835. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2836. |_[ + ] More details:: / - / , ISP:
  2837. |_[ + ] Found:: UNIDENTIFIED
  2838.  
  2839. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2840. |_[ + ] [ 58 / 100 ]-[00:06:44] [ - ]
  2841. |_[ + ] Target:: [ https://en.hmb.gov.tr/international-relations ]
  2842. |_[ + ] Exploit::
  2843. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2844. |_[ + ] More details:: / - / , ISP:
  2845. |_[ + ] Found:: UNIDENTIFIED
  2846.  
  2847. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2848. |_[ + ] [ 59 / 100 ]-[00:06:45] [ - ]
  2849. |_[ + ] Target:: [ https://en.hmb.gov.tr/coordination-board ]
  2850. |_[ + ] Exploit::
  2851. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2852. |_[ + ] More details:: / - / , ISP:
  2853. |_[ + ] Found:: UNIDENTIFIED
  2854.  
  2855. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2856. |_[ + ] [ 60 / 100 ]-[00:06:47] [ - ]
  2857. |_[ + ] Target:: [ https://en.hmb.gov.tr/iacb-legislations ]
  2858. |_[ + ] Exploit::
  2859. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2860. |_[ + ] More details:: / - / , ISP:
  2861. |_[ + ] Found:: UNIDENTIFIED
  2862.  
  2863. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2864. |_[ + ] [ 61 / 100 ]-[00:06:48] [ - ]
  2865. |_[ + ] Target:: [ https://en.hmb.gov.tr/provincial-special-administrations ]
  2866. |_[ + ] Exploit::
  2867. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2868. |_[ + ] More details:: / - / , ISP:
  2869. |_[ + ] Found:: UNIDENTIFIED
  2870.  
  2871. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2872. |_[ + ] [ 62 / 100 ]-[00:06:50] [ - ]
  2873. |_[ + ] Target:: [ https://en.hmb.gov.tr/conference-and-seminars ]
  2874. |_[ + ] Exploit::
  2875. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2876. |_[ + ] More details:: / - / , ISP:
  2877. |_[ + ] Found:: UNIDENTIFIED
  2878.  
  2879. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2880. |_[ + ] [ 63 / 100 ]-[00:06:51] [ - ]
  2881. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-obliged-parties ]
  2882. |_[ + ] Exploit::
  2883. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2884. |_[ + ] More details:: / - / , ISP:
  2885. |_[ + ] Found:: UNIDENTIFIED
  2886.  
  2887. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2888. |_[ + ] [ 64 / 100 ]-[00:06:53] [ - ]
  2889. |_[ + ] Target:: [ https://en.hmb.gov.tr/investor-relations-office ]
  2890. |_[ + ] Exploit::
  2891. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2892. |_[ + ] More details:: / - / , ISP:
  2893. |_[ + ] Found:: UNIDENTIFIED
  2894.  
  2895. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2896. |_[ + ] [ 65 / 100 ]-[00:06:54] [ - ]
  2897. |_[ + ] Target:: [ https://en.hmb.gov.tr/general-budget-institutions ]
  2898. |_[ + ] Exploit::
  2899. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2900. |_[ + ] More details:: / - / , ISP:
  2901. |_[ + ] Found:: UNIDENTIFIED
  2902.  
  2903. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2904. |_[ + ] [ 66 / 100 ]-[00:06:56] [ - ]
  2905. |_[ + ] Target:: [ https://en.hmb.gov.tr/twinning-project-2 ]
  2906. |_[ + ] Exploit::
  2907. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2908. |_[ + ] More details:: / - / , ISP:
  2909. |_[ + ] Found:: UNIDENTIFIED
  2910.  
  2911. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2912. |_[ + ] [ 67 / 100 ]-[00:06:57] [ - ]
  2913. |_[ + ] Target:: [ https://en.hmb.gov.tr/data-release-calendar ]
  2914. |_[ + ] Exploit::
  2915. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2916. |_[ + ] More details:: / - / , ISP:
  2917. |_[ + ] Found:: UNIDENTIFIED
  2918.  
  2919. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2920. |_[ + ] [ 68 / 100 ]-[00:06:59] [ - ]
  2921. |_[ + ] Target:: [ https://en.hmb.gov.tr/social-security-institutions ]
  2922. |_[ + ] Exploit::
  2923. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2924. |_[ + ] More details:: / - / , ISP:
  2925. |_[ + ] Found:: UNIDENTIFIED
  2926.  
  2927. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2928. |_[ + ] [ 69 / 100 ]-[00:07:01] [ - ]
  2929. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-duties-powers ]
  2930. |_[ + ] Exploit::
  2931. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2932. |_[ + ] More details:: / - / , ISP:
  2933. |_[ + ] Found:: UNIDENTIFIED
  2934.  
  2935. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2936. |_[ + ] [ 70 / 100 ]-[00:07:02] [ - ]
  2937. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-activity-reports ]
  2938. |_[ + ] Exploit::
  2939. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2940. |_[ + ] More details:: / - / , ISP:
  2941. |_[ + ] Found:: UNIDENTIFIED
  2942.  
  2943. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2944. |_[ + ] [ 71 / 100 ]-[00:07:03] [ - ]
  2945. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-national-legistation ]
  2946. |_[ + ] Exploit::
  2947. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2948. |_[ + ] More details:: / - / , ISP:
  2949. |_[ + ] Found:: UNIDENTIFIED
  2950.  
  2951. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2952. |_[ + ] [ 72 / 100 ]-[00:07:05] [ - ]
  2953. |_[ + ] Target:: [ https://en.hmb.gov.tr/confidentiality-of-reporting ]
  2954. |_[ + ] Exploit::
  2955. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2956. |_[ + ] More details:: / - / , ISP:
  2957. |_[ + ] Found:: UNIDENTIFIED
  2958.  
  2959. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2960. |_[ + ] [ 73 / 100 ]-[00:07:06] [ - ]
  2961. |_[ + ] Target:: [ https://en.hmb.gov.tr/about-public-finance ]
  2962. |_[ + ] Exploit::
  2963. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2964. |_[ + ] More details:: / - / , ISP:
  2965. |_[ + ] Found:: UNIDENTIFIED
  2966.  
  2967. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2968. |_[ + ] [ 74 / 100 ]-[00:07:08] [ - ]
  2969. |_[ + ] Target:: [ https://en.hmb.gov.tr/special-budget-institutions ]
  2970. |_[ + ] Exploit::
  2971. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2972. |_[ + ] More details:: / - / , ISP:
  2973. |_[ + ] Found:: UNIDENTIFIED
  2974.  
  2975. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2976. |_[ + ] [ 75 / 100 ]-[00:07:10] [ - ]
  2977. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-main-indicator ]
  2978. |_[ + ] Exploit::
  2979. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2980. |_[ + ] More details:: / - / , ISP:
  2981. |_[ + ] Found:: UNIDENTIFIED
  2982.  
  2983. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2984. |_[ + ] [ 76 / 100 ]-[00:07:11] [ - ]
  2985. |_[ + ] Target:: [ https://en.hmb.gov.tr/presentations-conference-calls ]
  2986. |_[ + ] Exploit::
  2987. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2988. |_[ + ] More details:: / - / , ISP:
  2989. |_[ + ] Found:: UNIDENTIFIED
  2990.  
  2991. _[ - ]::--------------------------------------------------------------------------------------------------------------
  2992. |_[ + ] [ 77 / 100 ]-[00:07:13] [ - ]
  2993. |_[ + ] Target:: [ https://en.hmb.gov.tr/information-for-investors ]
  2994. |_[ + ] Exploit::
  2995. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  2996. |_[ + ] More details:: / - / , ISP:
  2997. |_[ + ] Found:: UNIDENTIFIED
  2998.  
  2999. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3000. |_[ + ] [ 78 / 100 ]-[00:07:14] [ - ]
  3001. |_[ + ] Target:: [ https://en.hmb.gov.tr/frequently-asked-questions ]
  3002. |_[ + ] Exploit::
  3003. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3004. |_[ + ] More details:: / - / , ISP:
  3005. |_[ + ] Found:: UNIDENTIFIED
  3006.  
  3007. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3008. |_[ + ] [ 79 / 100 ]-[00:07:16] [ - ]
  3009. |_[ + ] Target:: [ https://en.hmb.gov.tr/suspicious-transactions-types ]
  3010. |_[ + ] Exploit::
  3011. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3012. |_[ + ] More details:: / - / , ISP:
  3013. |_[ + ] Found:: UNIDENTIFIED
  3014.  
  3015. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3016. |_[ + ] [ 80 / 100 ]-[00:07:17] [ - ]
  3017. |_[ + ] Target:: [ https://en.hmb.gov.tr/investor-protection-measures ]
  3018. |_[ + ] Exploit::
  3019. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3020. |_[ + ] More details:: / - / , ISP:
  3021. |_[ + ] Found:: UNIDENTIFIED
  3022.  
  3023. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3024. |_[ + ] [ 81 / 100 ]-[00:07:19] [ - ]
  3025. |_[ + ] Target:: [ https://en.hmb.gov.tr/government-finance-statistics ]
  3026. |_[ + ] Exploit::
  3027. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3028. |_[ + ] More details:: / - / , ISP:
  3029. |_[ + ] Found:: UNIDENTIFIED
  3030.  
  3031. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3032. |_[ + ] [ 82 / 100 ]-[00:07:21] [ - ]
  3033. |_[ + ] Target:: [ https://en.hmb.gov.tr/it-modernization-program ]
  3034. |_[ + ] Exploit::
  3035. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3036. |_[ + ] More details:: / - / , ISP:
  3037. |_[ + ] Found:: UNIDENTIFIED
  3038.  
  3039. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3040. |_[ + ] [ 83 / 100 ]-[00:07:22] [ - ]
  3041. |_[ + ] Target:: [ https://en.hmb.gov.tr/local-government-unions ]
  3042. |_[ + ] Exploit::
  3043. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3044. |_[ + ] More details:: / - / , ISP:
  3045. |_[ + ] Found:: UNIDENTIFIED
  3046.  
  3047. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3048. |_[ + ] [ 84 / 100 ]-[00:07:24] [ - ]
  3049. |_[ + ] Target:: [ https://en.hmb.gov.tr/primary-dealership-system ]
  3050. |_[ + ] Exploit::
  3051. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3052. |_[ + ] More details:: / - / , ISP:
  3053. |_[ + ] Found:: UNIDENTIFIED
  3054.  
  3055. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3056. |_[ + ] [ 85 / 100 ]-[00:07:26] [ - ]
  3057. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/duty-losses ]
  3058. |_[ + ] Exploit::
  3059. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3060. |_[ + ] More details:: / - / , ISP:
  3061. |_[ + ] Found:: UNIDENTIFIED
  3062.  
  3063. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3064. |_[ + ] [ 86 / 100 ]-[00:07:27] [ - ]
  3065. |_[ + ] Target:: [ https://en.hmb.gov.tr/state-owned-enterprises ]
  3066. |_[ + ] Exploit::
  3067. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3068. |_[ + ] More details:: / - / , ISP:
  3069. |_[ + ] Found:: UNIDENTIFIED
  3070.  
  3071. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3072. |_[ + ] [ 87 / 100 ]-[00:07:29] [ - ]
  3073. |_[ + ] Target:: [ https://en.hmb.gov.tr/extrabudegetary-other-institutions ]
  3074. |_[ + ] Exploit::
  3075. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3076. |_[ + ] More details:: / - / , ISP:
  3077. |_[ + ] Found:: UNIDENTIFIED
  3078.  
  3079. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3080. |_[ + ] [ 88 / 100 ]-[00:07:30] [ - ]
  3081. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/press-statement ]
  3082. |_[ + ] Exploit::
  3083. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3084. |_[ + ] More details:: / - / , ISP:
  3085. |_[ + ] Found:: UNIDENTIFIED
  3086.  
  3087. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3088. |_[ + ] [ 89 / 100 ]-[00:07:32] [ - ]
  3089. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-vision-mission ]
  3090. |_[ + ] Exploit::
  3091. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3092. |_[ + ] More details:: / - / , ISP:
  3093. |_[ + ] Found:: UNIDENTIFIED
  3094.  
  3095. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3096. |_[ + ] [ 90 / 100 ]-[00:07:33] [ - ]
  3097. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/2017-financing_program ]
  3098. |_[ + ] Exploit::
  3099. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3100. |_[ + ] More details:: / - / , ISP:
  3101. |_[ + ] Found:: UNIDENTIFIED
  3102.  
  3103. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3104. |_[ + ] [ 91 / 100 ]-[00:07:35] [ - ]
  3105. |_[ + ] Target:: [ https://en.hmb.gov.tr/internal-control-standarts ]
  3106. |_[ + ] Exploit::
  3107. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3108. |_[ + ] More details:: / - / , ISP:
  3109. |_[ + ] Found:: UNIDENTIFIED
  3110.  
  3111. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3112. |_[ + ] [ 92 / 100 ]-[00:07:36] [ - ]
  3113. |_[ + ] Target:: [ https://en.hmb.gov.tr/internal-audit-standarts ]
  3114. |_[ + ] Exploit::
  3115. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3116. |_[ + ] More details:: / - / , ISP:
  3117. |_[ + ] Found:: UNIDENTIFIED
  3118.  
  3119. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3120. |_[ + ] [ 93 / 100 ]-[00:07:38] [ - ]
  3121. |_[ + ] Target:: [ https://en.hmb.gov.tr/en-US/Mainpage ]
  3122. |_[ + ] Exploit::
  3123. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3124. |_[ + ] More details:: / - / , ISP:
  3125. |_[ + ] Found:: UNIDENTIFIED
  3126.  
  3127. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3128. |_[ + ] [ 94 / 100 ]-[00:07:40] [ - ]
  3129. |_[ + ] Target:: [ https://en.hmb.gov.tr/phd-nureddin-nebati ]
  3130. |_[ + ] Exploit::
  3131. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3132. |_[ + ] More details:: / - / , ISP:
  3133. |_[ + ] Found:: UNIDENTIFIED
  3134.  
  3135. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3136. |_[ + ] [ 95 / 100 ]-[00:07:41] [ - ]
  3137. |_[ + ] Target:: [ https://en.hmb.gov.tr/debt-management-legislation ]
  3138. |_[ + ] Exploit::
  3139. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3140. |_[ + ] More details:: / - / , ISP:
  3141. |_[ + ] Found:: UNIDENTIFIED
  3142.  
  3143. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3144. |_[ + ] [ 96 / 100 ]-[00:07:43] [ - ]
  3145. |_[ + ] Target:: [ https://en.hmb.gov.tr/world-bank-projects ]
  3146. |_[ + ] Exploit::
  3147. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3148. |_[ + ] More details:: / - / , ISP:
  3149. |_[ + ] Found:: UNIDENTIFIED
  3150.  
  3151. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3152. |_[ + ] [ 97 / 100 ]-[00:07:44] [ - ]
  3153. |_[ + ] Target:: [ https://en.hmb.gov.tr/business-angel-scheme ]
  3154. |_[ + ] Exploit::
  3155. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3156. |_[ + ] More details:: / - / , ISP:
  3157. |_[ + ] Found:: UNIDENTIFIED
  3158.  
  3159. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3160. |_[ + ] [ 98 / 100 ]-[00:07:46] [ - ]
  3161. |_[ + ] Target:: [ https://en.hmb.gov.tr/turkish-economy ]
  3162. |_[ + ] Exploit::
  3163. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3164. |_[ + ] More details:: / - / , ISP:
  3165. |_[ + ] Found:: UNIDENTIFIED
  3166.  
  3167. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3168. |_[ + ] [ 99 / 100 ]-[00:07:47] [ - ]
  3169. |_[ + ] Target:: [ https://en.hmb.gov.tr/experience-sharing-program ]
  3170. |_[ + ] Exploit::
  3171. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3172. |_[ + ] More details:: / - / , ISP:
  3173. |_[ + ] Found:: UNIDENTIFIED
  3174.  
  3175. [ INFO ] [ Shutting down ]
  3176. [ INFO ] [ End of process INURLBR at [11-10-2019 00:07:47]
  3177. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  3178. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/en.hmb.gov.tr/output/inurlbr-en.hmb.gov.tr ]
  3179. #######################################################################################################################################
  3180. HTTP/1.1 200 OK
  3181. Server: nginx
  3182. Date: Fri, 11 Oct 2019 04:07:12 GMT
  3183. Content-Type: text/html
  3184. Content-Length: 6199
  3185. Last-Modified: Mon, 07 Oct 2019 13:24:44 GMT
  3186. Connection: keep-alive
  3187. ETag: "5d9b3c9c-1837"
  3188. Accept-Ranges: bytes
  3189. #######################################################################################################################################
  3190.  
  3191. wig - WebApp Information Gatherer
  3192.  
  3193.  
  3194. Scanning https://en.hmb.gov.tr...
  3195. ____________________ SITE INFO _____________________
  3196. IP Title
  3197. 212.174.188.50 T.C. Hazine ve Maliye Bakanlığı
  3198.  
  3199. _____________________ VERSION ______________________
  3200. Name Versions Type
  3201. nginx Platform
  3202.  
  3203. ___________________ INTERESTING ____________________
  3204. URL Note Type
  3205. /robots.txt robots.txt index Interesting
  3206.  
  3207. ____________________________________________________
  3208. Time: 1.7 sec Urls: 629 Fingerprints: 40401
  3209. #######################################################################################################################################
  3210. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-11 00:08 EDT
  3211. NSE: Loaded 163 scripts for scanning.
  3212. NSE: Script Pre-scanning.
  3213. Initiating NSE at 00:08
  3214. Completed NSE at 00:08, 0.00s elapsed
  3215. Initiating NSE at 00:08
  3216. Completed NSE at 00:08, 0.00s elapsed
  3217. Initiating Parallel DNS resolution of 1 host. at 00:08
  3218. Completed Parallel DNS resolution of 1 host. at 00:08, 10.38s elapsed
  3219. Initiating SYN Stealth Scan at 00:08
  3220. Scanning en.hmb.gov.tr (212.174.188.50) [1 port]
  3221. Discovered open port 443/tcp on 212.174.188.50
  3222. Completed SYN Stealth Scan at 00:08, 0.25s elapsed (1 total ports)
  3223. Initiating Service scan at 00:08
  3224. Scanning 1 service on en.hmb.gov.tr (212.174.188.50)
  3225. Completed Service scan at 00:08, 13.45s elapsed (1 service on 1 host)
  3226. Initiating OS detection (try #1) against en.hmb.gov.tr (212.174.188.50)
  3227. Initiating Traceroute at 00:08
  3228. Completed Traceroute at 00:08, 0.60s elapsed
  3229. Initiating Parallel DNS resolution of 21 hosts. at 00:08
  3230. Completed Parallel DNS resolution of 21 hosts. at 00:08, 6.22s elapsed
  3231. NSE: Script scanning 212.174.188.50.
  3232. Initiating NSE at 00:08
  3233. Completed NSE at 00:13, 293.70s elapsed
  3234. Initiating NSE at 00:13
  3235. Completed NSE at 00:13, 2.53s elapsed
  3236. Nmap scan report for en.hmb.gov.tr (212.174.188.50)
  3237. Host is up (0.22s latency).
  3238.  
  3239. PORT STATE SERVICE VERSION
  3240. 443/tcp open ssl/http nginx
  3241. | http-backup-finder:
  3242. | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=en.hmb.gov.tr
  3243. | https://en.hmb.gov.tr:443/assets/vendor-762733947933133dc078a17ae6569f64.bak
  3244. | https://en.hmb.gov.tr:443/assets/vendor-762733947933133dc078a17ae6569f64.js~
  3245. | https://en.hmb.gov.tr:443/assets/vendor-762733947933133dc078a17ae6569f64 copy.js
  3246. | https://en.hmb.gov.tr:443/assets/Copy of vendor-762733947933133dc078a17ae6569f64.js
  3247. | https://en.hmb.gov.tr:443/assets/Copy (2) of vendor-762733947933133dc078a17ae6569f64.js
  3248. | https://en.hmb.gov.tr:443/assets/vendor-762733947933133dc078a17ae6569f64.js.1
  3249. | https://en.hmb.gov.tr:443/assets/vendor-762733947933133dc078a17ae6569f64.js.~1~
  3250. | https://en.hmb.gov.tr:443/assets/hmb-frontend-ec89b55213b506c267824d367414b1c1.bak
  3251. | https://en.hmb.gov.tr:443/assets/hmb-frontend-ec89b55213b506c267824d367414b1c1.js~
  3252. | https://en.hmb.gov.tr:443/assets/hmb-frontend-ec89b55213b506c267824d367414b1c1 copy.js
  3253. | https://en.hmb.gov.tr:443/assets/Copy of hmb-frontend-ec89b55213b506c267824d367414b1c1.js
  3254. | https://en.hmb.gov.tr:443/assets/Copy (2) of hmb-frontend-ec89b55213b506c267824d367414b1c1.js
  3255. | https://en.hmb.gov.tr:443/assets/hmb-frontend-ec89b55213b506c267824d367414b1c1.js.1
  3256. | https://en.hmb.gov.tr:443/assets/hmb-frontend-ec89b55213b506c267824d367414b1c1.js.~1~
  3257. | https://en.hmb.gov.tr:443/yandex-browser-manifest.bak
  3258. | https://en.hmb.gov.tr:443/yandex-browser-manifest.json~
  3259. | https://en.hmb.gov.tr:443/yandex-browser-manifest copy.json
  3260. | https://en.hmb.gov.tr:443/Copy of yandex-browser-manifest.json
  3261. | https://en.hmb.gov.tr:443/Copy (2) of yandex-browser-manifest.json
  3262. | https://en.hmb.gov.tr:443/yandex-browser-manifest.json.1
  3263. | https://en.hmb.gov.tr:443/yandex-browser-manifest.json.~1~
  3264. | https://en.hmb.gov.tr:443/manifest.bak
  3265. | https://en.hmb.gov.tr:443/manifest.json~
  3266. | https://en.hmb.gov.tr:443/manifest copy.json
  3267. | https://en.hmb.gov.tr:443/Copy of manifest.json
  3268. | https://en.hmb.gov.tr:443/Copy (2) of manifest.json
  3269. | https://en.hmb.gov.tr:443/manifest.json.1
  3270. | https://en.hmb.gov.tr:443/manifest.json.~1~
  3271. | https://en.hmb.gov.tr:443/assets/hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.bak
  3272. | https://en.hmb.gov.tr:443/assets/hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.css~
  3273. | https://en.hmb.gov.tr:443/assets/hmb-frontend-2c611e0d3ec71128aed8724251b0a93a copy.css
  3274. | https://en.hmb.gov.tr:443/assets/Copy of hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.css
  3275. | https://en.hmb.gov.tr:443/assets/Copy (2) of hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.css
  3276. | https://en.hmb.gov.tr:443/assets/hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.css.1
  3277. | https://en.hmb.gov.tr:443/assets/hmb-frontend-2c611e0d3ec71128aed8724251b0a93a.css.~1~
  3278. | https://en.hmb.gov.tr:443/assets/vendor-2874a984551b4c780366c120d51dd084.bak
  3279. | https://en.hmb.gov.tr:443/assets/vendor-2874a984551b4c780366c120d51dd084.css~
  3280. | https://en.hmb.gov.tr:443/assets/vendor-2874a984551b4c780366c120d51dd084 copy.css
  3281. | https://en.hmb.gov.tr:443/assets/Copy of vendor-2874a984551b4c780366c120d51dd084.css
  3282. | https://en.hmb.gov.tr:443/assets/Copy (2) of vendor-2874a984551b4c780366c120d51dd084.css
  3283. | https://en.hmb.gov.tr:443/assets/vendor-2874a984551b4c780366c120d51dd084.css.1
  3284. | https://en.hmb.gov.tr:443/assets/vendor-2874a984551b4c780366c120d51dd084.css.~1~
  3285. | https://en.hmb.gov.tr:443/favicon.bak
  3286. | https://en.hmb.gov.tr:443/favicon.ico~
  3287. | https://en.hmb.gov.tr:443/favicon copy.ico
  3288. | https://en.hmb.gov.tr:443/Copy of favicon.ico
  3289. | https://en.hmb.gov.tr:443/Copy (2) of favicon.ico
  3290. | https://en.hmb.gov.tr:443/favicon.ico.1
  3291. |_ https://en.hmb.gov.tr:443/favicon.ico.~1~
  3292. | http-brute:
  3293. |_ Path "/" does not require authentication
  3294. | http-cakephp-version: Version of codebase: 1.3.x
  3295. | Version of icons: 1.3.x
  3296. |_Default stylesheet has an unknown hash: b91692eed697bfce6e07bd7c3b7b7df1
  3297. |_http-chrono: Request times for /; avg: 1197.10ms; min: 1143.56ms; max: 1268.02ms
  3298. |_http-config-backup: ERROR: Script execution failed (use -d to debug)
  3299. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  3300. |_http-date: Fri, 11 Oct 2019 04:08:09 GMT; -40s from local time.
  3301. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  3302. |_http-dombased-xss: Couldn't find any DOM based XSS.
  3303. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  3304. |_http-errors: Couldn't find any error pages.
  3305. |_http-feed: Couldn't find any feeds.
  3306. |_http-fetch: Please enter the complete path of the directory to save data in.
  3307. | http-headers:
  3308. | Server: nginx
  3309. | Date: Fri, 11 Oct 2019 04:08:15 GMT
  3310. | Content-Type: text/html
  3311. | Content-Length: 6199
  3312. | Last-Modified: Mon, 07 Oct 2019 13:24:44 GMT
  3313. | Connection: close
  3314. | ETag: "5d9b3c9c-1837"
  3315. | Accept-Ranges: bytes
  3316. |
  3317. |_ (Request type: HEAD)
  3318. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  3319. |_http-majordomo2-dir-traversal: ERROR: Script execution failed (use -d to debug)
  3320. | http-methods:
  3321. |_ Supported Methods: GET HEAD
  3322. |_http-mobileversion-checker: No mobile version detected.
  3323. | http-php-version: Logo query returned unknown hash b91692eed697bfce6e07bd7c3b7b7df1
  3324. |_Credits query returned unknown hash b91692eed697bfce6e07bd7c3b7b7df1
  3325. | http-security-headers:
  3326. | Strict_Transport_Security:
  3327. |_ HSTS not configured in HTTPS Server
  3328. | http-sitemap-generator:
  3329. | Directory structure:
  3330. | /
  3331. | Other: 1; json: 1; png: 15
  3332. | /assets/
  3333. | css: 1; js: 2
  3334. | Longest directory structure:
  3335. | Depth: 1
  3336. | Dir: /assets/
  3337. | Total files found (by extension):
  3338. |_ Other: 1; css: 1; js: 2; json: 1; png: 15
  3339. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  3340. |_http-title: 400 The plain HTTP request was sent to HTTPS port
  3341. |_http-trane-info: Problem with XML parsing of /evox/about
  3342. |_http-userdir-enum: Potential Users: root, admin, administrator, webadmin, sysadmin, netadmin, guest, user, web, test
  3343. | http-vhosts:
  3344. |_127 names had status 200
  3345. | http-vuln-cve2010-0738:
  3346. |_ /jmx-console/: Authentication was not required
  3347. | http-vuln-cve2011-3192:
  3348. | VULNERABLE:
  3349. | Apache byterange filter DoS
  3350. | State: VULNERABLE
  3351. | IDs: BID:49303 CVE:CVE-2011-3192
  3352. | The Apache web server is vulnerable to a denial of service attack when numerous
  3353. | overlapping byte ranges are requested.
  3354. | Disclosure date: 2011-08-19
  3355. | References:
  3356. | https://seclists.org/fulldisclosure/2011/Aug/175
  3357. | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192
  3358. | https://www.tenable.com/plugins/nessus/55976
  3359. |_ https://www.securityfocus.com/bid/49303
  3360. |_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
  3361. | http-wordpress-enum:
  3362. | Search limited to top 100 themes/plugins
  3363. | plugins
  3364. | akismet
  3365. | contact-form-7
  3366. | wordpress-seo
  3367. | jetpack
  3368. | all-in-one-seo-pack
  3369. | wordfence
  3370. | woocommerce
  3371. | google-sitemap-generator
  3372. | wordpress-importer
  3373. | nextgen-gallery
  3374. | google-analytics-for-wordpress
  3375. | wp-super-cache
  3376. | tinymce-advanced
  3377. | wptouch
  3378. | better-wp-security
  3379. | siteorigin-panels
  3380. | updraftplus
  3381. | w3-total-cache
  3382. | google-analytics-dashboard-for-wp
  3383. | wp-pagenavi
  3384. | si-contact-form
  3385. | advanced-custom-fields
  3386. | mailchimp-for-wp
  3387. | the-events-calendar
  3388. | add-to-any
  3389. | duplicator
  3390. | wysija-newsletters
  3391. | ninja-forms
  3392. | wp-smushit
  3393. | buddypress
  3394. | ewww-image-optimizer
  3395. | so-widgets-bundle
  3396. | really-simple-captcha
  3397. | ml-slider
  3398. | black-studio-tinymce-widget
  3399. | photo-gallery
  3400. | broken-link-checker
  3401. | regenerate-thumbnails
  3402. | google-analyticator
  3403. | redirection
  3404. | captcha
  3405. | duplicate-post
  3406. | breadcrumb-navxt
  3407. | backwpup
  3408. | user-role-editor
  3409. | yet-another-related-posts-plugin
  3410. | contact-form-plugin
  3411. | newsletter
  3412. | bbpress
  3413. | all-in-one-wp-security-and-firewall
  3414. | disable-comments
  3415. | social-networks-auto-poster-facebook-twitter-g
  3416. | wp-optimize
  3417. | addthis
  3418. | wp-statistics
  3419. | wp-e-commerce
  3420. | all-in-one-wp-migration
  3421. | backupwordpress
  3422. | si-captcha-for-wordpress
  3423. | wp-slimstat
  3424. | wp-google-maps
  3425. | wp-spamshield
  3426. | wp-maintenance-mode
  3427. | googleanalytics
  3428. | worker
  3429. | yith-woocommerce-wishlist
  3430. | wp-multibyte-patch
  3431. | wp-to-twitter
  3432. | image-widget
  3433. | wp-db-backup
  3434. | shortcodes-ultimate
  3435. | ultimate-tinymce
  3436. | share-this
  3437. | disqus-comment-system
  3438. | gallery-bank
  3439. | types
  3440. | wp-polls
  3441. | custom-post-type-ui
  3442. | shareaholic
  3443. | polylang
  3444. | post-types-order
  3445. | gtranslate
  3446. | bulletproof-security
  3447. | wp-fastest-cache
  3448. | facebook
  3449. | sociable
  3450. | iwp-client
  3451. | nextgen-facebook
  3452. | seo-ultimate
  3453. | wp-postviews
  3454. | formidable
  3455. | squirrly-seo
  3456. | wp-mail-smtp
  3457. | tablepress
  3458. | redux-framework
  3459. | page-links-to
  3460. | youtube-embed-plus
  3461. | contact-bank
  3462. | maintenance
  3463. | wp-retina-2x
  3464. | themes
  3465. | twentyeleven
  3466. | twentytwelve
  3467. | twentyten
  3468. | twentythirteen
  3469. | twentyfourteen
  3470. | twentyfifteen
  3471. | responsive
  3472. | customizr
  3473. | zerif-lite
  3474. | virtue
  3475. | storefront
  3476. | atahualpa
  3477. | twentysixteen
  3478. | vantage
  3479. | hueman
  3480. | spacious
  3481. | evolve
  3482. | colorway
  3483. | graphene
  3484. | sydney
  3485. | ifeature
  3486. | mh-magazine-lite
  3487. | generatepress
  3488. | mantra
  3489. | omega
  3490. | onetone
  3491. | coraline
  3492. | pinboard
  3493. | thematic
  3494. | sparkling
  3495. | catch-box
  3496. | make
  3497. | colormag
  3498. | enigma
  3499. | custom-community
  3500. | mystique
  3501. | alexandria
  3502. | delicate
  3503. | lightword
  3504. | attitude
  3505. | inove
  3506. | magazine-basic
  3507. | raindrops
  3508. | minamaze
  3509. | zbench
  3510. | point
  3511. | eclipse
  3512. | portfolio-press
  3513. | twentyseventeen
  3514. | travelify
  3515. | swift-basic
  3516. | iconic-one
  3517. | arcade-basic
  3518. | bouquet
  3519. | pixel
  3520. | sliding-door
  3521. | pilcrow
  3522. | simple-catch
  3523. | tempera
  3524. | destro
  3525. | p2
  3526. | sunspot
  3527. | sundance
  3528. | dusk-to-dawn
  3529. | onepress
  3530. | moesia
  3531. | dynamic-news-lite
  3532. | parabola
  3533. | parament
  3534. | dazzling
  3535. | accesspress-lite
  3536. | optimizer
  3537. | one-page
  3538. | chaostheory
  3539. | business-lite
  3540. | duster
  3541. | constructor
  3542. | nirvana
  3543. | sixteen
  3544. | esquire
  3545. | beach
  3546. | next-saturday
  3547. | flat
  3548. | hatch
  3549. | minimatica
  3550. | radiate
  3551. | accelerate
  3552. | oxygen
  3553. | accesspress-parallax
  3554. | swift
  3555. | spun
  3556. | wp-creativix
  3557. | suevafree
  3558. | hemingway
  3559. | pink-touch-2
  3560. | motion
  3561. | fruitful
  3562. | steira
  3563. | news
  3564. |_ llorix-one-lite
  3565. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  3566. |_http-xssed: No previously reported XSS vuln.
  3567. | vulscan: VulDB - https://vuldb.com:
  3568. | [133852] Sangfor Sundray WLAN Controller up to 3.7.4.2 Cookie Header nginx_webconsole.php Code Execution
  3569. | [132132] SoftNAS Cloud 4.2.0/4.2.1 Nginx privilege escalation
  3570. | [131858] Puppet Discovery up to 1.3.x Nginx Container weak authentication
  3571. | [130644] Nginx Unit up to 1.7.0 Router Process Request Heap-based memory corruption
  3572. | [127759] VeryNginx 0.3.3 Web Application Firewall privilege escalation
  3573. | [126525] nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
  3574. | [126524] nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
  3575. | [126523] nginx up to 1.14.0/1.15.5 HTTP2 Memory Consumption denial of service
  3576. | [119845] Pivotal Operations Manager up to 2.0.13/2.1.5 Nginx privilege escalation
  3577. | [114368] SuSE Portus 2.3 Nginx Certificate weak authentication
  3578. | [103517] nginx up to 1.13.2 Range Filter Request Integer Overflow memory corruption
  3579. | [89849] nginx RFC 3875 Namespace Conflict Environment Variable Open Redirect
  3580. | [87719] nginx up to 1.11.0 ngx_files.c ngx_chain_to_iovec denial of service
  3581. | [80760] nginx 0.6.18/1.9.9 DNS CNAME Record Crash denial of service
  3582. | [80759] nginx 0.6.18/1.9.9 DNS CNAME Record Use-After-Free denial of service
  3583. | [80758] nginx 0.6.18/1.9.9 DNS UDP Packet Crash denial of service
  3584. | [67677] nginx up to 1.7.3 SSL weak authentication
  3585. | [67296] nginx up to 1.7.3 SMTP Proxy ngx_mail_smtp_starttls privilege escalation
  3586. | [12822] nginx up to 1.5.11 SPDY SPDY Request Heap-based memory corruption
  3587. | [12824] nginx 1.5.10 on 32-bit SPDY memory corruption
  3588. | [11237] nginx up to 1.5.6 URI String Bypass privilege escalation
  3589. | [65364] nginx up to 1.1.13 Default Configuration information disclosure
  3590. | [8671] nginx up to 1.4 proxy_pass denial of service
  3591. | [8618] nginx 1.3.9/1.4.0 http/ngx_http_parse.c ngx_http_parse_chunked() memory corruption
  3592. | [7247] nginx 1.2.6 Proxy Function spoofing
  3593. | [61434] nginx 1.2.0/1.3.0 on Windows Access Restriction privilege escalation
  3594. | [5293] nginx up to 1.1.18 ngx_http_mp4_module MP4 File memory corruption
  3595. | [4843] nginx up to 1.0.13/1.1.16 HTTP Header Response Parser ngx_http_parse.c information disclosure
  3596. | [59645] nginx up to 0.8.9 Heap-based memory corruption
  3597. | [53592] nginx 0.8.36 memory corruption
  3598. | [53590] nginx up to 0.8.9 unknown vulnerability
  3599. | [51533] nginx 0.7.64 Terminal privilege escalation
  3600. | [50905] nginx up to 0.8.9 directory traversal
  3601. | [50903] nginx up to 0.8.10 NULL Pointer Dereference denial of service
  3602. | [50043] nginx up to 0.8.10 memory corruption
  3603. |
  3604. | MITRE CVE - https://cve.mitre.org:
  3605. | [CVE-2013-2070] http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
  3606. | [CVE-2013-2028] The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
  3607. | [CVE-2012-3380] Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
  3608. | [CVE-2012-2089] Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
  3609. | [CVE-2012-1180] Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
  3610. | [CVE-2011-4963] nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
  3611. | [CVE-2011-4315] Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
  3612. | [CVE-2010-2266] nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
  3613. | [CVE-2010-2263] nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
  3614. | [CVE-2009-4487] nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
  3615. | [CVE-2009-3898] Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
  3616. | [CVE-2009-3896] src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.
  3617. | [CVE-2009-2629] Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
  3618. |
  3619. | SecurityFocus - https://www.securityfocus.com/bid/:
  3620. | [99534] Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
  3621. | [93903] Nginx CVE-2016-1247 Remote Privilege Escalation Vulnerability
  3622. | [91819] Nginx CVE-2016-1000105 Security Bypass Vulnerability
  3623. | [90967] nginx CVE-2016-4450 Denial of Service Vulnerability
  3624. | [82230] nginx Multiple Denial of Service Vulnerabilities
  3625. | [78928] Nginx CVE-2010-2266 Denial-Of-Service Vulnerability
  3626. | [70025] nginx CVE-2014-3616 SSL Session Fixation Vulnerability
  3627. | [69111] nginx SMTP Proxy Remote Command Injection Vulnerability
  3628. | [67507] nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
  3629. | [66537] nginx SPDY Implementation Heap Based Buffer Overflow Vulnerability
  3630. | [63814] nginx CVE-2013-4547 URI Processing Security Bypass Vulnerability
  3631. | [59824] Nginx CVE-2013-2070 Remote Security Vulnerability
  3632. | [59699] nginx 'ngx_http_parse.c' Stack Buffer Overflow Vulnerability
  3633. | [59496] nginx 'ngx_http_close_connection()' Remote Integer Overflow Vulnerability
  3634. | [59323] nginx NULL-Byte Arbitrary Code Execution Vulnerability
  3635. | [58105] Nginx 'access.log' Insecure File Permissions Vulnerability
  3636. | [57139] nginx CVE-2011-4968 Man in The Middle Vulnerability
  3637. | [55920] nginx CVE-2011-4963 Security Bypass Vulnerability
  3638. | [54331] Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
  3639. | [52999] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  3640. | [52578] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  3641. | [50710] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  3642. | [40760] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  3643. | [40434] nginx Space String Remote Source Code Disclosure Vulnerability
  3644. | [40420] nginx Directory Traversal Vulnerability
  3645. | [37711] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  3646. | [36839] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  3647. | [36490] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  3648. | [36438] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  3649. | [36384] nginx HTTP Request Remote Buffer Overflow Vulnerability
  3650. |
  3651. | IBM X-Force - https://exchange.xforce.ibmcloud.com:
  3652. | [84623] Phusion Passenger gem for Ruby with nginx configuration insecure permissions
  3653. | [84172] nginx denial of service
  3654. | [84048] nginx buffer overflow
  3655. | [83923] nginx ngx_http_close_connection() integer overflow
  3656. | [83688] nginx null byte code execution
  3657. | [83103] Naxsi module for Nginx naxsi_unescape_uri() function security bypass
  3658. | [82319] nginx access.log information disclosure
  3659. | [80952] nginx SSL spoofing
  3660. | [77244] nginx and Microsoft Windows request security bypass
  3661. | [76778] Naxsi module for Nginx nx_extract.py directory traversal
  3662. | [74831] nginx ngx_http_mp4_module.c buffer overflow
  3663. | [74191] nginx ngx_cpystrn() information disclosure
  3664. | [74045] nginx header response information disclosure
  3665. | [71355] nginx ngx_resolver_copy() buffer overflow
  3666. | [59370] nginx characters denial of service
  3667. | [59369] nginx DATA source code disclosure
  3668. | [59047] nginx space source code disclosure
  3669. | [58966] nginx unspecified directory traversal
  3670. | [54025] nginx ngx_http_parse.c denial of service
  3671. | [53431] nginx WebDAV component directory traversal
  3672. | [53328] Nginx CRC-32 cached domain name spoofing
  3673. | [53250] Nginx ngx_http_parse_complex_uri() function code execution
  3674. |
  3675. | Exploit-DB - https://www.exploit-db.com:
  3676. | [26737] nginx 1.3.9/1.4.0 x86 Brute Force Remote Exploit
  3677. | [25775] Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow
  3678. | [25499] nginx 1.3.9-1.4.0 DoS PoC
  3679. | [24967] nginx 0.6.x Arbitrary Code Execution NullByte Injection
  3680. | [14830] nginx 0.6.38 - Heap Corruption Exploit
  3681. | [13822] Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability
  3682. | [13818] Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities
  3683. | [12804] nginx [engine x] http server <= 0.6.36 Path Draversal
  3684. | [9901] nginx 0.7.0-0.7.61, 0.6.0-0.6.38, 0.5.0-0.5.37, 0.4.0-0.4.14 PoC
  3685. | [9829] nginx 0.7.61 WebDAV directory traversal
  3686. |
  3687. | OpenVAS (Nessus) - http://www.openvas.org:
  3688. | [864418] Fedora Update for nginx FEDORA-2012-3846
  3689. | [864310] Fedora Update for nginx FEDORA-2012-6238
  3690. | [864209] Fedora Update for nginx FEDORA-2012-6411
  3691. | [864204] Fedora Update for nginx FEDORA-2012-6371
  3692. | [864121] Fedora Update for nginx FEDORA-2012-4006
  3693. | [864115] Fedora Update for nginx FEDORA-2012-3991
  3694. | [864065] Fedora Update for nginx FEDORA-2011-16075
  3695. | [863654] Fedora Update for nginx FEDORA-2011-16110
  3696. | [861232] Fedora Update for nginx FEDORA-2007-1158
  3697. | [850180] SuSE Update for nginx openSUSE-SU-2012:0237-1 (nginx)
  3698. | [831680] Mandriva Update for nginx MDVSA-2012:043 (nginx)
  3699. | [802045] 64-bit Debian Linux Rootkit with nginx Doing iFrame Injection
  3700. | [801636] nginx HTTP Request Remote Buffer Overflow Vulnerability
  3701. | [103470] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  3702. | [103469] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  3703. | [103344] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  3704. | [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  3705. | [100659] nginx Directory Traversal Vulnerability
  3706. | [100658] nginx Space String Remote Source Code Disclosure Vulnerability
  3707. | [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  3708. | [100321] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  3709. | [100277] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  3710. | [100276] nginx HTTP Request Remote Buffer Overflow Vulnerability
  3711. | [100275] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  3712. | [71574] Gentoo Security Advisory GLSA 201206-07 (nginx)
  3713. | [71308] Gentoo Security Advisory GLSA 201203-22 (nginx)
  3714. | [71297] FreeBSD Ports: nginx
  3715. | [71276] FreeBSD Ports: nginx
  3716. | [71239] Debian Security Advisory DSA 2434-1 (nginx)
  3717. | [66451] Fedora Core 11 FEDORA-2009-12782 (nginx)
  3718. | [66450] Fedora Core 10 FEDORA-2009-12775 (nginx)
  3719. | [66449] Fedora Core 12 FEDORA-2009-12750 (nginx)
  3720. | [64924] Gentoo Security Advisory GLSA 200909-18 (nginx)
  3721. | [64912] Fedora Core 10 FEDORA-2009-9652 (nginx)
  3722. | [64911] Fedora Core 11 FEDORA-2009-9630 (nginx)
  3723. | [64894] FreeBSD Ports: nginx
  3724. | [64869] Debian Security Advisory DSA 1884-1 (nginx)
  3725. |
  3726. | SecurityTracker - https://www.securitytracker.com:
  3727. | [1028544] nginx Bug Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
  3728. | [1028519] nginx Stack Overflow Lets Remote Users Execute Arbitrary Code
  3729. | [1026924] nginx Buffer Overflow in ngx_http_mp4_module Lets Remote Users Execute Arbitrary Code
  3730. | [1026827] nginx HTTP Response Processing Lets Remote Users Obtain Portions of Memory Contents
  3731. |
  3732. | OSVDB - http://www.osvdb.org:
  3733. | [94864] cPnginx Plugin for cPanel nginx Configuration Manipulation Arbitrary File Access
  3734. | [93282] nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
  3735. | [93037] nginx /http/ngx_http_parse.c Worker Process Crafted Request Handling Remote Overflow
  3736. | [92796] nginx ngx_http_close_connection Function Crafted r-&gt
  3737. | [92634] nginx ngx_http_request.h zero_in_uri URL Null Byte Handling Remote Code Execution
  3738. | [90518] nginx Log Directory Permission Weakness Local Information Disclosure
  3739. | [88910] nginx Proxy Functionality SSL Certificate Validation MitM Spoofing Weakness
  3740. | [84339] nginx/Windows Multiple Request Sequence Parsing Arbitrary File Access
  3741. | [83617] Naxsi Module for Nginx naxsi-ui/ nx_extract.py Traversal Arbitrary File Access
  3742. | [81339] nginx ngx_http_mp4_module Module Atom MP4 File Handling Remote Overflow
  3743. | [80124] nginx HTTP Header Response Parsing Freed Memory Information Disclosure
  3744. | [77184] nginx ngx_resolver.c ngx_resolver_copy() Function DNS Response Parsing Remote Overflow
  3745. | [65531] nginx on Windows URI ::$DATA Append Arbitrary File Access
  3746. | [65530] nginx Encoded Traversal Sequence Memory Corruption Remote DoS
  3747. | [65294] nginx on Windows Encoded Space Request Remote Source Disclosure
  3748. | [63136] nginx on Windows 8.3 Filename Alias Request Access Rules / Authentication Bypass
  3749. | [62617] nginx Internal DNS Cache Poisoning Weakness
  3750. | [61779] nginx HTTP Request Escape Sequence Terminal Command Injection
  3751. | [59278] nginx src/http/ngx_http_parse.c ngx_http_process_request_headers() Function URL Handling NULL Dereference DoS
  3752. | [58328] nginx WebDAV Multiple Method Traversal Arbitrary File Write
  3753. | [58128] nginx ngx_http_parse_complex_uri() Function Underflow
  3754. | [44447] nginx (engine x) msie_refresh Directive Unspecified XSS
  3755. | [44446] nginx (engine x) ssl_verify_client Directive HTTP/0.9 Protocol Bypass
  3756. | [44445] nginx (engine x) ngx_http_realip_module satisfy_any Directive Unspecified Access Bypass
  3757. | [44444] nginx (engine x) X-Accel-Redirect Header Unspecified Traversal
  3758. | [44443] nginx (engine x) rtsig Method Signal Queue Overflow
  3759. | [44442] nginx (engine x) Worker Process Millisecond Timers Unspecified Overflow
  3760. |_
  3761. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  3762. Device type: general purpose
  3763. Running: Linux 3.X
  3764. OS CPE: cpe:/o:linux:linux_kernel:3
  3765. OS details: Linux 3.10 - 3.12
  3766. Uptime guess: 11.874 days (since Sun Sep 29 03:14:49 2019)
  3767. Network Distance: 24 hops
  3768. TCP Sequence Prediction: Difficulty=254 (Good luck!)
  3769. IP ID Sequence Generation: All zeros
  3770.  
  3771. TRACEROUTE (using port 443/tcp)
  3772. HOP RTT ADDRESS
  3773. 1 56.19 ms 10.249.204.1
  3774. 2 86.01 ms 104.245.145.161
  3775. 3 85.95 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
  3776. 4 86.01 ms te0-0-0-1.agr13.yyz02.atlas.cogentco.com (154.24.54.37)
  3777. 5 86.05 ms te0-9-0-9.ccr32.yyz02.atlas.cogentco.com (154.54.43.153)
  3778. 6 86.10 ms be2994.ccr22.cle04.atlas.cogentco.com (154.54.31.233)
  3779. 7 86.13 ms be2717.ccr41.ord01.atlas.cogentco.com (154.54.6.221)
  3780. 8 86.16 ms be2765.ccr41.ord03.atlas.cogentco.com (154.54.45.18)
  3781. 9 86.19 ms ae-11.r08.chcgil09.us.bb.gin.ntt.net (129.250.9.121)
  3782. 10 86.25 ms ae-0.r21.chcgil09.us.bb.gin.ntt.net (129.250.2.205)
  3783. 11 80.78 ms ae-1.r23.asbnva02.us.bb.gin.ntt.net (129.250.2.138)
  3784. 12 254.70 ms ae-2.r25.amstnl02.nl.bb.gin.ntt.net (129.250.6.163)
  3785. 13 254.59 ms ae-5.r02.amstnl02.nl.bb.gin.ntt.net (129.250.2.179)
  3786. 14 180.70 ms ae-0.turk-telekom.amstnl02.nl.bb.gin.ntt.net (81.20.64.102)
  3787. 15 254.63 ms 06-ebgp-ulus1-k---302-ams-col-3.statik.turktelekom.com.tr (212.156.102.114)
  3788. 16 254.74 ms 212.156.117.186.29-gumushane-t3-1.25-erzurum-t2-1.statik.turktelekom.com.tr (212.156.117.186)
  3789. 17 254.70 ms 06-ulus-xrs-t2-1---06-ebgp-ulus1-k.statik.turktelekom.com.tr (81.212.197.36)
  3790. 18 254.64 ms 81.212.215.188.static.turktelekom.com.tr (81.212.215.188)
  3791. 19 254.59 ms mta4-v14.buaslanmis.com (212.174.117.78)
  3792. 20 254.63 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  3793. 21 258.51 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  3794. 22 226.66 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  3795. 23 233.72 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  3796. 24 233.59 ms 212.174.188.50
  3797.  
  3798. NSE: Script Post-scanning.
  3799. Initiating NSE at 00:13
  3800. Completed NSE at 00:13, 0.00s elapsed
  3801. Initiating NSE at 00:13
  3802. Completed NSE at 00:13, 0.00s elapsed
  3803. Read data files from: /usr/bin/../share/nmap
  3804. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  3805. Nmap done: 1 IP address (1 host up) scanned in 330.78 seconds
  3806. #######################################################################################################################################
  3807. Version: 1.11.13-static
  3808. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  3809.  
  3810. Connected to 212.174.188.50
  3811.  
  3812. Testing SSL server en.hmb.gov.tr on port 443 using SNI name en.hmb.gov.tr
  3813.  
  3814. TLS Fallback SCSV:
  3815. Server supports TLS Fallback SCSV
  3816.  
  3817. TLS renegotiation:
  3818. Session renegotiation not supported
  3819.  
  3820. TLS Compression:
  3821. Compression disabled
  3822.  
  3823. Heartbleed:
  3824. TLS 1.2 not vulnerable to heartbleed
  3825. TLS 1.1 not vulnerable to heartbleed
  3826. TLS 1.0 not vulnerable to heartbleed
  3827.  
  3828. Supported Server Cipher(s):
  3829. Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-384 DHE 384
  3830. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-384 DHE 384
  3831.  
  3832. SSL Certificate:
  3833. Signature Algorithm: sha256WithRSAEncryption
  3834. RSA Key Strength: 2048
  3835.  
  3836. Subject: *.hmb.gov.tr
  3837. Altnames: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  3838. Issuer: GlobalSign Organization Validation CA - SHA256 - G2
  3839.  
  3840. Not valid before: Oct 5 16:39:41 2018 GMT
  3841. Not valid after: Oct 5 16:39:41 2020 GMT
  3842. #######################################################################################################################################
  3843. ------------------------------------------------------------------------------------------------------------------------
  3844.  
  3845. [ ! ] Starting SCANNER INURLBR 2.1 at [11-10-2019 00:14:19]
  3846. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  3847. It is the end user's responsibility to obey all applicable local, state and federal laws.
  3848. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  3849.  
  3850. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/en.hmb.gov.tr/output/inurlbr-en.hmb.gov.tr ]
  3851. [ INFO ][ DORK ]::[ site:en.hmb.gov.tr ]
  3852. [ INFO ][ SEARCHING ]:: {
  3853. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.ro ]
  3854.  
  3855. [ INFO ][ SEARCHING ]::
  3856. -[:::]
  3857. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  3858.  
  3859. [ INFO ][ SEARCHING ]::
  3860. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  3861. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.co.mz ID: 010479943387663786936:wjwf2xkhfmq ]
  3862.  
  3863. [ INFO ][ SEARCHING ]::
  3864. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  3865.  
  3866. [ INFO ][ TOTAL FOUND VALUES ]:: [ 100 ]
  3867.  
  3868.  
  3869. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3870. |_[ + ] [ 0 / 100 ]-[00:14:33] [ - ]
  3871. |_[ + ] Target:: [ https://en.hmb.gov.tr/ ]
  3872. |_[ + ] Exploit::
  3873. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3874. |_[ + ] More details:: / - / , ISP:
  3875. |_[ + ] Found:: UNIDENTIFIED
  3876.  
  3877. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3878. |_[ + ] [ 1 / 100 ]-[00:14:35] [ - ]
  3879. |_[ + ] Target:: [ https://en.hmb.gov.tr/awards ]
  3880. |_[ + ] Exploit::
  3881. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3882. |_[ + ] More details:: / - / , ISP:
  3883. |_[ + ] Found:: UNIDENTIFIED
  3884.  
  3885. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3886. |_[ + ] [ 2 / 100 ]-[00:14:36] [ - ]
  3887. |_[ + ] Target:: [ https://en.hmb.gov.tr/contact ]
  3888. |_[ + ] Exploit::
  3889. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3890. |_[ + ] More details:: / - / , ISP:
  3891. |_[ + ] Found:: UNIDENTIFIED
  3892.  
  3893. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3894. |_[ + ] [ 3 / 100 ]-[00:14:38] [ - ]
  3895. |_[ + ] Target:: [ https://en.hmb.gov.tr/municipalities ]
  3896. |_[ + ] Exploit::
  3897. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3898. |_[ + ] More details:: / - / , ISP:
  3899. |_[ + ] Found:: UNIDENTIFIED
  3900.  
  3901. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3902. |_[ + ] [ 4 / 100 ]-[00:14:39] [ - ]
  3903. |_[ + ] Target:: [ https://en.hmb.gov.tr/departments ]
  3904. |_[ + ] Exploit::
  3905. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3906. |_[ + ] More details:: / - / , ISP:
  3907. |_[ + ] Found:: UNIDENTIFIED
  3908.  
  3909. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3910. |_[ + ] [ 5 / 100 ]-[00:14:41] [ - ]
  3911. |_[ + ] Target:: [ https://en.hmb.gov.tr/disclaimer ]
  3912. |_[ + ] Exploit::
  3913. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3914. |_[ + ] More details:: / - / , ISP:
  3915. |_[ + ] Found:: UNIDENTIFIED
  3916.  
  3917. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3918. |_[ + ] [ 6 / 100 ]-[00:14:42] [ - ]
  3919. |_[ + ] Target:: [ https://en.hmb.gov.tr/insurance ]
  3920. |_[ + ] Exploit::
  3921. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3922. |_[ + ] More details:: / - / , ISP:
  3923. |_[ + ] Found:: UNIDENTIFIED
  3924.  
  3925. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3926. |_[ + ] [ 7 / 100 ]-[00:14:43] [ - ]
  3927. |_[ + ] Target:: [ https://en.hmb.gov.tr/mtp ]
  3928. |_[ + ] Exploit::
  3929. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3930. |_[ + ] More details:: / - / , ISP:
  3931. |_[ + ] Found:: UNIDENTIFIED
  3932.  
  3933. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3934. |_[ + ] [ 8 / 100 ]-[00:14:45] [ - ]
  3935. |_[ + ] Target:: [ https://en.hmb.gov.tr/minister ]
  3936. |_[ + ] Exploit::
  3937. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3938. |_[ + ] More details:: / - / , ISP:
  3939. |_[ + ] Found:: UNIDENTIFIED
  3940.  
  3941. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3942. |_[ + ] [ 9 / 100 ]-[00:14:46] [ - ]
  3943. |_[ + ] Target:: [ https://en.hmb.gov.tr/links ]
  3944. |_[ + ] Exploit::
  3945. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3946. |_[ + ] More details:: / - / , ISP:
  3947. |_[ + ] Found:: UNIDENTIFIED
  3948.  
  3949. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3950. |_[ + ] [ 10 / 100 ]-[00:14:48] [ - ]
  3951. |_[ + ] Target:: [ https://en.hmb.gov.tr/exchange ]
  3952. |_[ + ] Exploit::
  3953. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3954. |_[ + ] More details:: / - / , ISP:
  3955. |_[ + ] Found:: UNIDENTIFIED
  3956.  
  3957. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3958. |_[ + ] [ 11 / 100 ]-[00:14:49] [ - ]
  3959. |_[ + ] Target:: [ https://en.hmb.gov.tr/foreign-offices ]
  3960. |_[ + ] Exploit::
  3961. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3962. |_[ + ] More details:: / - / , ISP:
  3963. |_[ + ] Found:: UNIDENTIFIED
  3964.  
  3965. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3966. |_[ + ] [ 12 / 100 ]-[00:14:51] [ - ]
  3967. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-newsletter ]
  3968. |_[ + ] Exploit::
  3969. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3970. |_[ + ] More details:: / - / , ISP:
  3971. |_[ + ] Found:: UNIDENTIFIED
  3972.  
  3973. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3974. |_[ + ] [ 13 / 100 ]-[00:14:52] [ - ]
  3975. |_[ + ] Target:: [ https://en.hmb.gov.tr/public-finance ]
  3976. |_[ + ] Exploit::
  3977. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3978. |_[ + ] More details:: / - / , ISP:
  3979. |_[ + ] Found:: UNIDENTIFIED
  3980.  
  3981. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3982. |_[ + ] [ 14 / 100 ]-[00:14:54] [ - ]
  3983. |_[ + ] Target:: [ https://en.hmb.gov.tr/imf-relations ]
  3984. |_[ + ] Exploit::
  3985. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3986. |_[ + ] More details:: / - / , ISP:
  3987. |_[ + ] Found:: UNIDENTIFIED
  3988.  
  3989. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3990. |_[ + ] [ 15 / 100 ]-[00:14:55] [ - ]
  3991. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-typologies ]
  3992. |_[ + ] Exploit::
  3993. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  3994. |_[ + ] More details:: / - / , ISP:
  3995. |_[ + ] Found:: UNIDENTIFIED
  3996.  
  3997. _[ - ]::--------------------------------------------------------------------------------------------------------------
  3998. |_[ + ] [ 16 / 100 ]-[00:14:57] [ - ]
  3999. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-sanctions ]
  4000. |_[ + ] Exploit::
  4001. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4002. |_[ + ] More details:: / - / , ISP:
  4003. |_[ + ] Found:: UNIDENTIFIED
  4004.  
  4005. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4006. |_[ + ] [ 17 / 100 ]-[00:14:58] [ - ]
  4007. |_[ + ] Target:: [ https://en.hmb.gov.tr/central-government ]
  4008. |_[ + ] Exploit::
  4009. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4010. |_[ + ] More details:: / - / , ISP:
  4011. |_[ + ] Found:: UNIDENTIFIED
  4012.  
  4013. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4014. |_[ + ] [ 18 / 100 ]-[00:15:00] [ - ]
  4015. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-guidelines ]
  4016. |_[ + ] Exploit::
  4017. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4018. |_[ + ] More details:: / - / , ISP:
  4019. |_[ + ] Found:: UNIDENTIFIED
  4020.  
  4021. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4022. |_[ + ] [ 19 / 100 ]-[00:15:01] [ - ]
  4023. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-announcements ]
  4024. |_[ + ] Exploit::
  4025. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4026. |_[ + ] More details:: / - / , ISP:
  4027. |_[ + ] Found:: UNIDENTIFIED
  4028.  
  4029. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4030. |_[ + ] [ 20 / 100 ]-[00:15:03] [ - ]
  4031. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-subscription ]
  4032. |_[ + ] Exploit::
  4033. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4034. |_[ + ] More details:: / - / , ISP:
  4035. |_[ + ] Found:: UNIDENTIFIED
  4036.  
  4037. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4038. |_[ + ] [ 21 / 100 ]-[00:15:04] [ - ]
  4039. |_[ + ] Target:: [ https://en.hmb.gov.tr/insurance-reports ]
  4040. |_[ + ] Exploit::
  4041. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4042. |_[ + ] More details:: / - / , ISP:
  4043. |_[ + ] Found:: UNIDENTIFIED
  4044.  
  4045. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4046. |_[ + ] [ 22 / 100 ]-[00:15:06] [ - ]
  4047. |_[ + ] Target:: [ https://en.hmb.gov.tr/treasury-law ]
  4048. |_[ + ] Exploit::
  4049. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4050. |_[ + ] More details:: / - / , ISP:
  4051. |_[ + ] Found:: UNIDENTIFIED
  4052.  
  4053. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4054. |_[ + ] [ 23 / 100 ]-[00:15:07] [ - ]
  4055. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-presentation ]
  4056. |_[ + ] Exploit::
  4057. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4058. |_[ + ] More details:: / - / , ISP:
  4059. |_[ + ] Found:: UNIDENTIFIED
  4060.  
  4061. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4062. |_[ + ] [ 24 / 100 ]-[00:15:09] [ - ]
  4063. |_[ + ] Target:: [ https://en.hmb.gov.tr/economic-indicators ]
  4064. |_[ + ] Exploit::
  4065. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4066. |_[ + ] More details:: / - / , ISP:
  4067. |_[ + ] Found:: UNIDENTIFIED
  4068.  
  4069. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4070. |_[ + ] [ 25 / 100 ]-[00:15:10] [ - ]
  4071. |_[ + ] Target:: [ https://en.hmb.gov.tr/credit-ratings ]
  4072. |_[ + ] Exploit::
  4073. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4074. |_[ + ] More details:: / - / , ISP:
  4075. |_[ + ] Found:: UNIDENTIFIED
  4076.  
  4077. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4078. |_[ + ] [ 26 / 100 ]-[00:15:11] [ - ]
  4079. |_[ + ] Target:: [ https://en.hmb.gov.tr/general-government ]
  4080. |_[ + ] Exploit::
  4081. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4082. |_[ + ] More details:: / - / , ISP:
  4083. |_[ + ] Found:: UNIDENTIFIED
  4084.  
  4085. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4086. |_[ + ] [ 27 / 100 ]-[00:15:13] [ - ]
  4087. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-contacts ]
  4088. |_[ + ] Exploit::
  4089. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4090. |_[ + ] More details:: / - / , ISP:
  4091. |_[ + ] Found:: UNIDENTIFIED
  4092.  
  4093. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4094. |_[ + ] [ 28 / 100 ]-[00:15:14] [ - ]
  4095. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-dictionary ]
  4096. |_[ + ] Exploit::
  4097. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4098. |_[ + ] More details:: / - / , ISP:
  4099. |_[ + ] Found:: UNIDENTIFIED
  4100.  
  4101. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4102. |_[ + ] [ 29 / 100 ]-[00:15:16] [ - ]
  4103. |_[ + ] Target:: [ https://en.hmb.gov.tr/local-government ]
  4104. |_[ + ] Exploit::
  4105. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4106. |_[ + ] More details:: / - / , ISP:
  4107. |_[ + ] Found:: UNIDENTIFIED
  4108.  
  4109. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4110. |_[ + ] [ 30 / 100 ]-[00:15:18] [ - ]
  4111. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-history ]
  4112. |_[ + ] Exploit::
  4113. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4114. |_[ + ] More details:: / - / , ISP:
  4115. |_[ + ] Found:: UNIDENTIFIED
  4116.  
  4117. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4118. |_[ + ] [ 31 / 100 ]-[00:15:19] [ - ]
  4119. |_[ + ] Target:: [ https://en.hmb.gov.tr/contact-us ]
  4120. |_[ + ] Exploit::
  4121. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4122. |_[ + ] More details:: / - / , ISP:
  4123. |_[ + ] Found:: UNIDENTIFIED
  4124.  
  4125. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4126. |_[ + ] [ 32 / 100 ]-[00:15:21] [ - ]
  4127. |_[ + ] Target:: [ https://en.hmb.gov.tr/sec-registrations ]
  4128. |_[ + ] Exploit::
  4129. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4130. |_[ + ] More details:: / - / , ISP:
  4131. |_[ + ] Found:: UNIDENTIFIED
  4132.  
  4133. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4134. |_[ + ] [ 33 / 100 ]-[00:15:22] [ - ]
  4135. |_[ + ] Target:: [ https://en.hmb.gov.tr/secondary-legislation ]
  4136. |_[ + ] Exploit::
  4137. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4138. |_[ + ] More details:: / - / , ISP:
  4139. |_[ + ] Found:: UNIDENTIFIED
  4140.  
  4141. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4142. |_[ + ] [ 34 / 100 ]-[00:15:24] [ - ]
  4143. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-str ]
  4144. |_[ + ] Exploit::
  4145. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4146. |_[ + ] More details:: / - / , ISP:
  4147. |_[ + ] Found:: UNIDENTIFIED
  4148.  
  4149. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4150. |_[ + ] [ 35 / 100 ]-[00:15:25] [ - ]
  4151. |_[ + ] Target:: [ https://en.hmb.gov.tr/insurance-legislation ]
  4152. |_[ + ] Exploit::
  4153. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4154. |_[ + ] More details:: / - / , ISP:
  4155. |_[ + ] Found:: UNIDENTIFIED
  4156.  
  4157. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4158. |_[ + ] [ 36 / 100 ]-[00:15:27] [ - ]
  4159. |_[ + ] Target:: [ https://en.hmb.gov.tr/metropolitan-municipalities ]
  4160. |_[ + ] Exploit::
  4161. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4162. |_[ + ] More details:: / - / , ISP:
  4163. |_[ + ] Found:: UNIDENTIFIED
  4164.  
  4165. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4166. |_[ + ] [ 37 / 100 ]-[00:15:28] [ - ]
  4167. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-projects ]
  4168. |_[ + ] Exploit::
  4169. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4170. |_[ + ] More details:: / - / , ISP:
  4171. |_[ + ] Found:: UNIDENTIFIED
  4172.  
  4173. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4174. |_[ + ] [ 38 / 100 ]-[00:15:30] [ - ]
  4175. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-chronology ]
  4176. |_[ + ] Exploit::
  4177. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4178. |_[ + ] More details:: / - / , ISP:
  4179. |_[ + ] Found:: UNIDENTIFIED
  4180.  
  4181. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4182. |_[ + ] [ 39 / 100 ]-[00:15:31] [ - ]
  4183. |_[ + ] Target:: [ https://en.hmb.gov.tr/iacb-projects ]
  4184. |_[ + ] Exploit::
  4185. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4186. |_[ + ] More details:: / - / , ISP:
  4187. |_[ + ] Found:: UNIDENTIFIED
  4188.  
  4189. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4190. |_[ + ] [ 40 / 100 ]-[00:15:33] [ - ]
  4191. |_[ + ] Target:: [ https://en.hmb.gov.tr/exchange-legislation ]
  4192. |_[ + ] Exploit::
  4193. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4194. |_[ + ] More details:: / - / , ISP:
  4195. |_[ + ] Found:: UNIDENTIFIED
  4196.  
  4197. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4198. |_[ + ] [ 41 / 100 ]-[00:15:34] [ - ]
  4199. |_[ + ] Target:: [ https://en.hmb.gov.tr/bulent-aksu ]
  4200. |_[ + ] Exploit::
  4201. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4202. |_[ + ] More details:: / - / , ISP:
  4203. |_[ + ] Found:: UNIDENTIFIED
  4204.  
  4205. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4206. |_[ + ] [ 42 / 100 ]-[00:15:36] [ - ]
  4207. |_[ + ] Target:: [ https://en.hmb.gov.tr/development-agencies ]
  4208. |_[ + ] Exploit::
  4209. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4210. |_[ + ] More details:: / - / , ISP:
  4211. |_[ + ] Found:: UNIDENTIFIED
  4212.  
  4213. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4214. |_[ + ] [ 43 / 100 ]-[00:15:37] [ - ]
  4215. |_[ + ] Target:: [ https://en.hmb.gov.tr/extrabudegetary-funds ]
  4216. |_[ + ] Exploit::
  4217. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4218. |_[ + ] More details:: / - / , ISP:
  4219. |_[ + ] Found:: UNIDENTIFIED
  4220.  
  4221. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4222. |_[ + ] [ 44 / 100 ]-[00:15:39] [ - ]
  4223. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-tasks ]
  4224. |_[ + ] Exploit::
  4225. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4226. |_[ + ] More details:: / - / , ISP:
  4227. |_[ + ] Found:: UNIDENTIFIED
  4228.  
  4229. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4230. |_[ + ] [ 45 / 100 ]-[00:15:40] [ - ]
  4231. |_[ + ] Target:: [ https://en.hmb.gov.tr/iacb-publications ]
  4232. |_[ + ] Exploit::
  4233. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4234. |_[ + ] More details:: / - / , ISP:
  4235. |_[ + ] Found:: UNIDENTIFIED
  4236.  
  4237. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4238. |_[ + ] [ 46 / 100 ]-[00:15:42] [ - ]
  4239. |_[ + ] Target:: [ https://en.hmb.gov.tr/social-facilities ]
  4240. |_[ + ] Exploit::
  4241. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4242. |_[ + ] More details:: / - / , ISP:
  4243. |_[ + ] Found:: UNIDENTIFIED
  4244.  
  4245. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4246. |_[ + ] [ 47 / 100 ]-[00:15:43] [ - ]
  4247. |_[ + ] Target:: [ https://en.hmb.gov.tr/national-standarts ]
  4248. |_[ + ] Exploit::
  4249. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4250. |_[ + ] More details:: / - / , ISP:
  4251. |_[ + ] Found:: UNIDENTIFIED
  4252.  
  4253. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4254. |_[ + ] [ 48 / 100 ]-[00:15:45] [ - ]
  4255. |_[ + ] Target:: [ https://en.hmb.gov.tr/primary-legislation ]
  4256. |_[ + ] Exploit::
  4257. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4258. |_[ + ] More details:: / - / , ISP:
  4259. |_[ + ] Found:: UNIDENTIFIED
  4260.  
  4261. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4262. |_[ + ] [ 49 / 100 ]-[00:15:47] [ - ]
  4263. |_[ + ] Target:: [ https://en.hmb.gov.tr/investors-guides ]
  4264. |_[ + ] Exploit::
  4265. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4266. |_[ + ] More details:: / - / , ISP:
  4267. |_[ + ] Found:: UNIDENTIFIED
  4268.  
  4269. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4270. |_[ + ] [ 50 / 100 ]-[00:15:48] [ - ]
  4271. |_[ + ] Target:: [ https://en.hmb.gov.tr/tertiary-legislation ]
  4272. |_[ + ] Exploit::
  4273. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4274. |_[ + ] More details:: / - / , ISP:
  4275. |_[ + ] Found:: UNIDENTIFIED
  4276.  
  4277. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4278. |_[ + ] [ 51 / 100 ]-[00:15:50] [ - ]
  4279. |_[ + ] Target:: [ https://en.hmb.gov.tr/revolving-funds ]
  4280. |_[ + ] Exploit::
  4281. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4282. |_[ + ] More details:: / - / , ISP:
  4283. |_[ + ] Found:: UNIDENTIFIED
  4284.  
  4285. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4286. |_[ + ] [ 52 / 100 ]-[00:15:51] [ - ]
  4287. |_[ + ] Target:: [ https://en.hmb.gov.tr/osman-dincbas ]
  4288. |_[ + ] Exploit::
  4289. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4290. |_[ + ] More details:: / - / , ISP:
  4291. |_[ + ] Found:: UNIDENTIFIED
  4292.  
  4293. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4294. |_[ + ] [ 53 / 100 ]-[00:15:53] [ - ]
  4295. |_[ + ] Target:: [ https://en.hmb.gov.tr/control-communication ]
  4296. |_[ + ] Exploit::
  4297. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4298. |_[ + ] More details:: / - / , ISP:
  4299. |_[ + ] Found:: UNIDENTIFIED
  4300.  
  4301. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4302. |_[ + ] [ 54 / 100 ]-[00:15:54] [ - ]
  4303. |_[ + ] Target:: [ https://en.hmb.gov.tr/wb-relations ]
  4304. |_[ + ] Exploit::
  4305. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4306. |_[ + ] More details:: / - / , ISP:
  4307. |_[ + ] Found:: UNIDENTIFIED
  4308.  
  4309. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4310. |_[ + ] [ 55 / 100 ]-[00:15:56] [ - ]
  4311. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/growth ]
  4312. |_[ + ] Exploit::
  4313. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4314. |_[ + ] More details:: / - / , ISP:
  4315. |_[ + ] Found:: UNIDENTIFIED
  4316.  
  4317. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4318. |_[ + ] [ 56 / 100 ]-[00:15:57] [ - ]
  4319. |_[ + ] Target:: [ https://en.hmb.gov.tr/international-relations ]
  4320. |_[ + ] Exploit::
  4321. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4322. |_[ + ] More details:: / - / , ISP:
  4323. |_[ + ] Found:: UNIDENTIFIED
  4324.  
  4325. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4326. |_[ + ] [ 57 / 100 ]-[00:15:59] [ - ]
  4327. |_[ + ] Target:: [ https://en.hmb.gov.tr/debt-indicators ]
  4328. |_[ + ] Exploit::
  4329. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4330. |_[ + ] More details:: / - / , ISP:
  4331. |_[ + ] Found:: UNIDENTIFIED
  4332.  
  4333. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4334. |_[ + ] [ 58 / 100 ]-[00:16:00] [ - ]
  4335. |_[ + ] Target:: [ https://en.hmb.gov.tr/coordination-board ]
  4336. |_[ + ] Exploit::
  4337. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4338. |_[ + ] More details:: / - / , ISP:
  4339. |_[ + ] Found:: UNIDENTIFIED
  4340.  
  4341. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4342. |_[ + ] [ 59 / 100 ]-[00:16:02] [ - ]
  4343. |_[ + ] Target:: [ https://en.hmb.gov.tr/iacb-legislations ]
  4344. |_[ + ] Exploit::
  4345. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4346. |_[ + ] More details:: / - / , ISP:
  4347. |_[ + ] Found:: UNIDENTIFIED
  4348.  
  4349. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4350. |_[ + ] [ 60 / 100 ]-[00:16:03] [ - ]
  4351. |_[ + ] Target:: [ https://en.hmb.gov.tr/provincial-special-administrations ]
  4352. |_[ + ] Exploit::
  4353. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4354. |_[ + ] More details:: / - / , ISP:
  4355. |_[ + ] Found:: UNIDENTIFIED
  4356.  
  4357. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4358. |_[ + ] [ 61 / 100 ]-[00:16:04] [ - ]
  4359. |_[ + ] Target:: [ https://en.hmb.gov.tr/conference-and-seminars ]
  4360. |_[ + ] Exploit::
  4361. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4362. |_[ + ] More details:: / - / , ISP:
  4363. |_[ + ] Found:: UNIDENTIFIED
  4364.  
  4365. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4366. |_[ + ] [ 62 / 100 ]-[00:16:06] [ - ]
  4367. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-obliged-parties ]
  4368. |_[ + ] Exploit::
  4369. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4370. |_[ + ] More details:: / - / , ISP:
  4371. |_[ + ] Found:: UNIDENTIFIED
  4372.  
  4373. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4374. |_[ + ] [ 63 / 100 ]-[00:16:07] [ - ]
  4375. |_[ + ] Target:: [ https://en.hmb.gov.tr/investor-relations-office ]
  4376. |_[ + ] Exploit::
  4377. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4378. |_[ + ] More details:: / - / , ISP:
  4379. |_[ + ] Found:: UNIDENTIFIED
  4380.  
  4381. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4382. |_[ + ] [ 64 / 100 ]-[00:16:09] [ - ]
  4383. |_[ + ] Target:: [ https://en.hmb.gov.tr/general-budget-institutions ]
  4384. |_[ + ] Exploit::
  4385. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4386. |_[ + ] More details:: / - / , ISP:
  4387. |_[ + ] Found:: UNIDENTIFIED
  4388.  
  4389. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4390. |_[ + ] [ 65 / 100 ]-[00:16:10] [ - ]
  4391. |_[ + ] Target:: [ https://en.hmb.gov.tr/twinning-project-2 ]
  4392. |_[ + ] Exploit::
  4393. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4394. |_[ + ] More details:: / - / , ISP:
  4395. |_[ + ] Found:: UNIDENTIFIED
  4396.  
  4397. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4398. |_[ + ] [ 66 / 100 ]-[00:16:12] [ - ]
  4399. |_[ + ] Target:: [ https://en.hmb.gov.tr/data-release-calendar ]
  4400. |_[ + ] Exploit::
  4401. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4402. |_[ + ] More details:: / - / , ISP:
  4403. |_[ + ] Found:: UNIDENTIFIED
  4404.  
  4405. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4406. |_[ + ] [ 67 / 100 ]-[00:16:13] [ - ]
  4407. |_[ + ] Target:: [ https://en.hmb.gov.tr/social-security-institutions ]
  4408. |_[ + ] Exploit::
  4409. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4410. |_[ + ] More details:: / - / , ISP:
  4411. |_[ + ] Found:: UNIDENTIFIED
  4412.  
  4413. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4414. |_[ + ] [ 68 / 100 ]-[00:16:15] [ - ]
  4415. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-duties-powers ]
  4416. |_[ + ] Exploit::
  4417. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4418. |_[ + ] More details:: / - / , ISP:
  4419. |_[ + ] Found:: UNIDENTIFIED
  4420.  
  4421. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4422. |_[ + ] [ 69 / 100 ]-[00:16:16] [ - ]
  4423. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-activity-reports ]
  4424. |_[ + ] Exploit::
  4425. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4426. |_[ + ] More details:: / - / , ISP:
  4427. |_[ + ] Found:: UNIDENTIFIED
  4428.  
  4429. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4430. |_[ + ] [ 70 / 100 ]-[00:16:18] [ - ]
  4431. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-national-legistation ]
  4432. |_[ + ] Exploit::
  4433. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4434. |_[ + ] More details:: / - / , ISP:
  4435. |_[ + ] Found:: UNIDENTIFIED
  4436.  
  4437. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4438. |_[ + ] [ 71 / 100 ]-[00:16:20] [ - ]
  4439. |_[ + ] Target:: [ https://en.hmb.gov.tr/confidentiality-of-reporting ]
  4440. |_[ + ] Exploit::
  4441. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4442. |_[ + ] More details:: / - / , ISP:
  4443. |_[ + ] Found:: UNIDENTIFIED
  4444.  
  4445. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4446. |_[ + ] [ 72 / 100 ]-[00:16:21] [ - ]
  4447. |_[ + ] Target:: [ https://en.hmb.gov.tr/about-public-finance ]
  4448. |_[ + ] Exploit::
  4449. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4450. |_[ + ] More details:: / - / , ISP:
  4451. |_[ + ] Found:: UNIDENTIFIED
  4452.  
  4453. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4454. |_[ + ] [ 73 / 100 ]-[00:16:23] [ - ]
  4455. |_[ + ] Target:: [ https://en.hmb.gov.tr/special-budget-institutions ]
  4456. |_[ + ] Exploit::
  4457. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4458. |_[ + ] More details:: / - / , ISP:
  4459. |_[ + ] Found:: UNIDENTIFIED
  4460.  
  4461. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4462. |_[ + ] [ 74 / 100 ]-[00:16:24] [ - ]
  4463. |_[ + ] Target:: [ https://en.hmb.gov.tr/iro-main-indicator ]
  4464. |_[ + ] Exploit::
  4465. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4466. |_[ + ] More details:: / - / , ISP:
  4467. |_[ + ] Found:: UNIDENTIFIED
  4468.  
  4469. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4470. |_[ + ] [ 75 / 100 ]-[00:16:25] [ - ]
  4471. |_[ + ] Target:: [ https://en.hmb.gov.tr/information-for-investors ]
  4472. |_[ + ] Exploit::
  4473. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4474. |_[ + ] More details:: / - / , ISP:
  4475. |_[ + ] Found:: UNIDENTIFIED
  4476.  
  4477. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4478. |_[ + ] [ 76 / 100 ]-[00:16:27] [ - ]
  4479. |_[ + ] Target:: [ https://en.hmb.gov.tr/frequently-asked-questions ]
  4480. |_[ + ] Exploit::
  4481. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4482. |_[ + ] More details:: / - / , ISP:
  4483. |_[ + ] Found:: UNIDENTIFIED
  4484.  
  4485. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4486. |_[ + ] [ 77 / 100 ]-[00:16:29] [ - ]
  4487. |_[ + ] Target:: [ https://en.hmb.gov.tr/suspicious-transactions-types ]
  4488. |_[ + ] Exploit::
  4489. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4490. |_[ + ] More details:: / - / , ISP:
  4491. |_[ + ] Found:: UNIDENTIFIED
  4492.  
  4493. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4494. |_[ + ] [ 78 / 100 ]-[00:16:30] [ - ]
  4495. |_[ + ] Target:: [ https://en.hmb.gov.tr/investor-protection-measures ]
  4496. |_[ + ] Exploit::
  4497. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4498. |_[ + ] More details:: / - / , ISP:
  4499. |_[ + ] Found:: UNIDENTIFIED
  4500.  
  4501. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4502. |_[ + ] [ 79 / 100 ]-[00:16:32] [ - ]
  4503. |_[ + ] Target:: [ https://en.hmb.gov.tr/government-finance-statistics ]
  4504. |_[ + ] Exploit::
  4505. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4506. |_[ + ] More details:: / - / , ISP:
  4507. |_[ + ] Found:: UNIDENTIFIED
  4508.  
  4509. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4510. |_[ + ] [ 80 / 100 ]-[00:16:33] [ - ]
  4511. |_[ + ] Target:: [ https://en.hmb.gov.tr/it-modernization-program ]
  4512. |_[ + ] Exploit::
  4513. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4514. |_[ + ] More details:: / - / , ISP:
  4515. |_[ + ] Found:: UNIDENTIFIED
  4516.  
  4517. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4518. |_[ + ] [ 81 / 100 ]-[00:16:35] [ - ]
  4519. |_[ + ] Target:: [ https://en.hmb.gov.tr/local-government-unions ]
  4520. |_[ + ] Exploit::
  4521. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4522. |_[ + ] More details:: / - / , ISP:
  4523. |_[ + ] Found:: UNIDENTIFIED
  4524.  
  4525. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4526. |_[ + ] [ 82 / 100 ]-[00:16:36] [ - ]
  4527. |_[ + ] Target:: [ https://en.hmb.gov.tr/primary-dealership-system ]
  4528. |_[ + ] Exploit::
  4529. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4530. |_[ + ] More details:: / - / , ISP:
  4531. |_[ + ] Found:: UNIDENTIFIED
  4532.  
  4533. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4534. |_[ + ] [ 83 / 100 ]-[00:16:38] [ - ]
  4535. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/duty-losses ]
  4536. |_[ + ] Exploit::
  4537. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4538. |_[ + ] More details:: / - / , ISP:
  4539. |_[ + ] Found:: UNIDENTIFIED
  4540.  
  4541. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4542. |_[ + ] [ 84 / 100 ]-[00:16:39] [ - ]
  4543. |_[ + ] Target:: [ https://en.hmb.gov.tr/state-owned-enterprises ]
  4544. |_[ + ] Exploit::
  4545. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4546. |_[ + ] More details:: / - / , ISP:
  4547. |_[ + ] Found:: UNIDENTIFIED
  4548.  
  4549. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4550. |_[ + ] [ 85 / 100 ]-[00:16:41] [ - ]
  4551. |_[ + ] Target:: [ https://en.hmb.gov.tr/extrabudegetary-other-institutions ]
  4552. |_[ + ] Exploit::
  4553. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4554. |_[ + ] More details:: / - / , ISP:
  4555. |_[ + ] Found:: UNIDENTIFIED
  4556.  
  4557. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4558. |_[ + ] [ 86 / 100 ]-[00:16:42] [ - ]
  4559. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/press-statement ]
  4560. |_[ + ] Exploit::
  4561. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4562. |_[ + ] More details:: / - / , ISP:
  4563. |_[ + ] Found:: UNIDENTIFIED
  4564.  
  4565. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4566. |_[ + ] [ 87 / 100 ]-[00:16:44] [ - ]
  4567. |_[ + ] Target:: [ https://en.hmb.gov.tr/fcib-vision-mission ]
  4568. |_[ + ] Exploit::
  4569. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4570. |_[ + ] More details:: / - / , ISP:
  4571. |_[ + ] Found:: UNIDENTIFIED
  4572.  
  4573. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4574. |_[ + ] [ 88 / 100 ]-[00:16:45] [ - ]
  4575. |_[ + ] Target:: [ https://en.hmb.gov.tr/duyuru/2017-financing_program ]
  4576. |_[ + ] Exploit::
  4577. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4578. |_[ + ] More details:: / - / , ISP:
  4579. |_[ + ] Found:: UNIDENTIFIED
  4580.  
  4581. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4582. |_[ + ] [ 89 / 100 ]-[00:16:47] [ - ]
  4583. |_[ + ] Target:: [ https://en.hmb.gov.tr/internal-control-standarts ]
  4584. |_[ + ] Exploit::
  4585. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4586. |_[ + ] More details:: / - / , ISP:
  4587. |_[ + ] Found:: UNIDENTIFIED
  4588.  
  4589. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4590. |_[ + ] [ 90 / 100 ]-[00:16:48] [ - ]
  4591. |_[ + ] Target:: [ https://en.hmb.gov.tr/internal-audit-standarts ]
  4592. |_[ + ] Exploit::
  4593. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4594. |_[ + ] More details:: / - / , ISP:
  4595. |_[ + ] Found:: UNIDENTIFIED
  4596.  
  4597. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4598. |_[ + ] [ 91 / 100 ]-[00:16:50] [ - ]
  4599. |_[ + ] Target:: [ https://en.hmb.gov.tr/en-US/Mainpage ]
  4600. |_[ + ] Exploit::
  4601. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4602. |_[ + ] More details:: / - / , ISP:
  4603. |_[ + ] Found:: UNIDENTIFIED
  4604.  
  4605. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4606. |_[ + ] [ 92 / 100 ]-[00:16:51] [ - ]
  4607. |_[ + ] Target:: [ https://en.hmb.gov.tr/phd-nureddin-nebati ]
  4608. |_[ + ] Exploit::
  4609. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4610. |_[ + ] More details:: / - / , ISP:
  4611. |_[ + ] Found:: UNIDENTIFIED
  4612.  
  4613. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4614. |_[ + ] [ 93 / 100 ]-[00:16:53] [ - ]
  4615. |_[ + ] Target:: [ https://en.hmb.gov.tr/debt-management-legislation ]
  4616. |_[ + ] Exploit::
  4617. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4618. |_[ + ] More details:: / - / , ISP:
  4619. |_[ + ] Found:: UNIDENTIFIED
  4620.  
  4621. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4622. |_[ + ] [ 94 / 100 ]-[00:16:54] [ - ]
  4623. |_[ + ] Target:: [ https://en.hmb.gov.tr/world-bank-projects ]
  4624. |_[ + ] Exploit::
  4625. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4626. |_[ + ] More details:: / - / , ISP:
  4627. |_[ + ] Found:: UNIDENTIFIED
  4628.  
  4629. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4630. |_[ + ] [ 95 / 100 ]-[00:16:56] [ - ]
  4631. |_[ + ] Target:: [ https://en.hmb.gov.tr/business-angel-scheme ]
  4632. |_[ + ] Exploit::
  4633. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4634. |_[ + ] More details:: / - / , ISP:
  4635. |_[ + ] Found:: UNIDENTIFIED
  4636.  
  4637. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4638. |_[ + ] [ 96 / 100 ]-[00:16:57] [ - ]
  4639. |_[ + ] Target:: [ https://en.hmb.gov.tr/turkish-economy ]
  4640. |_[ + ] Exploit::
  4641. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4642. |_[ + ] More details:: / - / , ISP:
  4643. |_[ + ] Found:: UNIDENTIFIED
  4644.  
  4645. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4646. |_[ + ] [ 97 / 100 ]-[00:16:59] [ - ]
  4647. |_[ + ] Target:: [ https://en.hmb.gov.tr/experience-sharing-program ]
  4648. |_[ + ] Exploit::
  4649. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4650. |_[ + ] More details:: / - / , ISP:
  4651. |_[ + ] Found:: UNIDENTIFIED
  4652.  
  4653. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4654. |_[ + ] [ 98 / 100 ]-[00:17:00] [ - ]
  4655. |_[ + ] Target:: [ https://en.hmb.gov.tr/public-debt-management-reports ]
  4656. |_[ + ] Exploit::
  4657. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4658. |_[ + ] More details:: / - / , ISP:
  4659. |_[ + ] Found:: UNIDENTIFIED
  4660.  
  4661. _[ - ]::--------------------------------------------------------------------------------------------------------------
  4662. |_[ + ] [ 99 / 100 ]-[00:17:02] [ - ]
  4663. |_[ + ] Target:: [ https://en.hmb.gov.tr/foreign-economic-relations-legislation ]
  4664. |_[ + ] Exploit::
  4665. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: nginx , IP:212.174.188.50:443
  4666. |_[ + ] More details:: / - / , ISP:
  4667. |_[ + ] Found:: UNIDENTIFIED
  4668.  
  4669. [ INFO ] [ Shutting down ]
  4670. [ INFO ] [ End of process INURLBR at [11-10-2019 00:17:02]
  4671. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  4672. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/loot/workspace/en.hmb.gov.tr/output/inurlbr-en.hmb.gov.tr ]
  4673. |_________________________________________________________________________________________
  4674.  
  4675. \_________________________________________________________________________________________/
  4676. #######################################################################################################################################
  4677. --------------------------------------------------------
  4678. <<<Yasuo discovered following vulnerable applications>>>
  4679. --------------------------------------------------------
  4680. +-------------------+-----------------------------------------+-----------------------------------------------------+----------+----------+
  4681. | App Name | URL to Application | Potential Exploit | Username | Password |
  4682. +-------------------+-----------------------------------------+-----------------------------------------------------+----------+----------+
  4683. | JBoss jmx-console | https://212.174.188.50:443/jmx-console/ | ./exploit/multi/http/jboss_deploymentfilerepository | None | None |
  4684. +-------------------+-----------------------------------------+-----------------------------------------------------+----------+----------+
  4685. #######################################################################################################################################
  4686. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-10 23:35 EDT
  4687. Stats: 0:00:00 elapsed; 0 hosts completed (0 up), 0 undergoing Host Discovery
  4688. Parallel DNS resolution of 1 host. Timing: About 0.00% done
  4689. Nmap scan report for 212.174.188.50
  4690. Host is up (0.16s latency).
  4691. Not shown: 995 filtered ports, 3 closed ports
  4692. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  4693. PORT STATE SERVICE
  4694. 80/tcp open http
  4695. 443/tcp open https
  4696.  
  4697. Nmap done: 1 IP address (1 host up) scanned in 25.45 seconds
  4698. #######################################################################################################################################
  4699. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-10 23:35 EDT
  4700. Nmap scan report for 212.174.188.50
  4701. Host is up (0.097s latency).
  4702. Not shown: 2 filtered ports
  4703. PORT STATE SERVICE
  4704. 53/udp open|filtered domain
  4705. 67/udp open|filtered dhcps
  4706. 68/udp open|filtered dhcpc
  4707. 69/udp open|filtered tftp
  4708. 88/udp open|filtered kerberos-sec
  4709. 123/udp open|filtered ntp
  4710. 139/udp open|filtered netbios-ssn
  4711. 161/udp open|filtered snmp
  4712. 162/udp open|filtered snmptrap
  4713. 389/udp open|filtered ldap
  4714. 500/udp open|filtered isakmp
  4715. 520/udp open|filtered route
  4716. 2049/udp open|filtered nfs
  4717.  
  4718. Nmap done: 1 IP address (1 host up) scanned in 13.21 seconds
  4719.  
  4720. #######################################################################################################################################
  4721. HTTP/1.1 301 Moved Permanently
  4722. Server: nginx
  4723. Date: Fri, 11 Oct 2019 03:35:03 GMT
  4724. Content-Type: text/html
  4725. Content-Length: 178
  4726. Connection: keep-alive
  4727. Location: https://www.hmb.gov.tr
  4728. #######################################################################################################################################
  4729. http://212.174.188.50 [301 Moved Permanently] Country[TURKEY][TR], HTTPServer[nginx], IP[212.174.188.50], RedirectLocation[https://www.hmb.gov.tr], Title[301 Moved Permanently], nginx
  4730. https://www.hmb.gov.tr [200 OK] Country[TURKEY][TR], HTML5, HTTPServer[nginx], IP[212.174.188.50], Script, Title[T.C. Hazine ve Maliye Bakanlığı], X-UA-Compatible[IE=edge], nginx
  4731. ######################################################################################################################################
  4732. wig - WebApp Information Gatherer
  4733.  
  4734.  
  4735. Scanning https://www.hmb.gov.tr...
  4736. _____________________ SITE INFO ______________________
  4737. IP Title
  4738. 212.174.188.50 T.C. Hazine ve Maliye Bakanlığı
  4739.  
  4740. ______________________ VERSION _______________________
  4741. Name Versions Type
  4742. nginx Platform
  4743.  
  4744. ____________________ INTERESTING _____________________
  4745. URL Note Type
  4746. /robots.txt robots.txt index Interesting
  4747.  
  4748. ______________________________________________________
  4749. Time: 146.9 sec Urls: 629 Fingerprints: 40401
  4750. #######################################################################################################################################
  4751. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-10 23:38 EDT
  4752. NSE: Loaded 163 scripts for scanning.
  4753. NSE: Script Pre-scanning.
  4754. Initiating NSE at 23:38
  4755. Completed NSE at 23:38, 0.00s elapsed
  4756. Initiating NSE at 23:38
  4757. Completed NSE at 23:38, 0.00s elapsed
  4758. Initiating Parallel DNS resolution of 1 host. at 23:38
  4759. Completed Parallel DNS resolution of 1 host. at 23:38, 10.30s elapsed
  4760. Initiating SYN Stealth Scan at 23:38
  4761. Scanning 212.174.188.50 [1 port]
  4762. Discovered open port 80/tcp on 212.174.188.50
  4763. Completed SYN Stealth Scan at 23:38, 0.25s elapsed (1 total ports)
  4764. Initiating Service scan at 23:38
  4765. Scanning 1 service on 212.174.188.50
  4766. Completed Service scan at 23:38, 6.44s elapsed (1 service on 1 host)
  4767. Initiating OS detection (try #1) against 212.174.188.50
  4768. Retrying OS detection (try #2) against 212.174.188.50
  4769. Initiating Traceroute at 23:38
  4770. Completed Traceroute at 23:38, 3.10s elapsed
  4771. Initiating Parallel DNS resolution of 16 hosts. at 23:38
  4772. Completed Parallel DNS resolution of 16 hosts. at 23:39, 6.19s elapsed
  4773. NSE: Script scanning 212.174.188.50.
  4774. Initiating NSE at 23:39
  4775. Completed NSE at 23:39, 49.20s elapsed
  4776. Initiating NSE at 23:39
  4777. Completed NSE at 23:39, 1.08s elapsed
  4778. Nmap scan report for 212.174.188.50
  4779. Host is up (0.21s latency).
  4780.  
  4781. PORT STATE SERVICE VERSION
  4782. 80/tcp open http nginx
  4783. | http-brute:
  4784. |_ Path "/" does not require authentication
  4785. |_http-chrono: ERROR: Script execution failed (use -d to debug)
  4786. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  4787. |_http-date: Fri, 11 Oct 2019 03:38:30 GMT; -40s from local time.
  4788. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  4789. |_http-dombased-xss: Couldn't find any DOM based XSS.
  4790. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  4791. |_http-errors: Couldn't find any error pages.
  4792. |_http-feed: Couldn't find any feeds.
  4793. |_http-fetch: Please enter the complete path of the directory to save data in.
  4794. | http-headers:
  4795. | Server: nginx
  4796. | Date: Fri, 11 Oct 2019 03:38:34 GMT
  4797. | Content-Type: text/html
  4798. | Content-Length: 178
  4799. | Connection: close
  4800. | Location: https://www.hmb.gov.tr
  4801. |
  4802. |_ (Request type: GET)
  4803. | http-internal-ip-disclosure:
  4804. |_ Internal IP Leaked: 10.128.10.36
  4805. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  4806. | http-methods:
  4807. |_ Supported Methods: GET HEAD POST OPTIONS
  4808. |_http-mobileversion-checker: No mobile version detected.
  4809. |_http-passwd: ERROR: Script execution failed (use -d to debug)
  4810. |_http-security-headers:
  4811. | http-sitemap-generator:
  4812. | Directory structure:
  4813. | Longest directory structure:
  4814. | Depth: 0
  4815. | Dir: /
  4816. | Total files found (by extension):
  4817. |_
  4818. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  4819. |_http-title: Did not follow redirect to https://www.hmb.gov.tr
  4820. | http-vhosts:
  4821. |_127 names had status 200
  4822. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
  4823. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  4824. |_http-xssed: No previously reported XSS vuln.
  4825. | vulscan: VulDB - https://vuldb.com:
  4826. | [133852] Sangfor Sundray WLAN Controller up to 3.7.4.2 Cookie Header nginx_webconsole.php Code Execution
  4827. | [132132] SoftNAS Cloud 4.2.0/4.2.1 Nginx privilege escalation
  4828. | [131858] Puppet Discovery up to 1.3.x Nginx Container weak authentication
  4829. | [130644] Nginx Unit up to 1.7.0 Router Process Request Heap-based memory corruption
  4830. | [127759] VeryNginx 0.3.3 Web Application Firewall privilege escalation
  4831. | [126525] nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
  4832. | [126524] nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
  4833. | [126523] nginx up to 1.14.0/1.15.5 HTTP2 Memory Consumption denial of service
  4834. | [119845] Pivotal Operations Manager up to 2.0.13/2.1.5 Nginx privilege escalation
  4835. | [114368] SuSE Portus 2.3 Nginx Certificate weak authentication
  4836. | [103517] nginx up to 1.13.2 Range Filter Request Integer Overflow memory corruption
  4837. | [89849] nginx RFC 3875 Namespace Conflict Environment Variable Open Redirect
  4838. | [87719] nginx up to 1.11.0 ngx_files.c ngx_chain_to_iovec denial of service
  4839. | [80760] nginx 0.6.18/1.9.9 DNS CNAME Record Crash denial of service
  4840. | [80759] nginx 0.6.18/1.9.9 DNS CNAME Record Use-After-Free denial of service
  4841. | [80758] nginx 0.6.18/1.9.9 DNS UDP Packet Crash denial of service
  4842. | [67677] nginx up to 1.7.3 SSL weak authentication
  4843. | [67296] nginx up to 1.7.3 SMTP Proxy ngx_mail_smtp_starttls privilege escalation
  4844. | [12822] nginx up to 1.5.11 SPDY SPDY Request Heap-based memory corruption
  4845. | [12824] nginx 1.5.10 on 32-bit SPDY memory corruption
  4846. | [11237] nginx up to 1.5.6 URI String Bypass privilege escalation
  4847. | [65364] nginx up to 1.1.13 Default Configuration information disclosure
  4848. | [8671] nginx up to 1.4 proxy_pass denial of service
  4849. | [8618] nginx 1.3.9/1.4.0 http/ngx_http_parse.c ngx_http_parse_chunked() memory corruption
  4850. | [7247] nginx 1.2.6 Proxy Function spoofing
  4851. | [61434] nginx 1.2.0/1.3.0 on Windows Access Restriction privilege escalation
  4852. | [5293] nginx up to 1.1.18 ngx_http_mp4_module MP4 File memory corruption
  4853. | [4843] nginx up to 1.0.13/1.1.16 HTTP Header Response Parser ngx_http_parse.c information disclosure
  4854. | [59645] nginx up to 0.8.9 Heap-based memory corruption
  4855. | [53592] nginx 0.8.36 memory corruption
  4856. | [53590] nginx up to 0.8.9 unknown vulnerability
  4857. | [51533] nginx 0.7.64 Terminal privilege escalation
  4858. | [50905] nginx up to 0.8.9 directory traversal
  4859. | [50903] nginx up to 0.8.10 NULL Pointer Dereference denial of service
  4860. | [50043] nginx up to 0.8.10 memory corruption
  4861. |
  4862. | MITRE CVE - https://cve.mitre.org:
  4863. | [CVE-2013-2070] http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
  4864. | [CVE-2013-2028] The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
  4865. | [CVE-2012-3380] Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
  4866. | [CVE-2012-2089] Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
  4867. | [CVE-2012-1180] Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
  4868. | [CVE-2011-4963] nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
  4869. | [CVE-2011-4315] Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
  4870. | [CVE-2010-2266] nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
  4871. | [CVE-2010-2263] nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
  4872. | [CVE-2009-4487] nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
  4873. | [CVE-2009-3898] Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
  4874. | [CVE-2009-3896] src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.
  4875. | [CVE-2009-2629] Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
  4876. |
  4877. | SecurityFocus - https://www.securityfocus.com/bid/:
  4878. | [99534] Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
  4879. | [93903] Nginx CVE-2016-1247 Remote Privilege Escalation Vulnerability
  4880. | [91819] Nginx CVE-2016-1000105 Security Bypass Vulnerability
  4881. | [90967] nginx CVE-2016-4450 Denial of Service Vulnerability
  4882. | [82230] nginx Multiple Denial of Service Vulnerabilities
  4883. | [78928] Nginx CVE-2010-2266 Denial-Of-Service Vulnerability
  4884. | [70025] nginx CVE-2014-3616 SSL Session Fixation Vulnerability
  4885. | [69111] nginx SMTP Proxy Remote Command Injection Vulnerability
  4886. | [67507] nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
  4887. | [66537] nginx SPDY Implementation Heap Based Buffer Overflow Vulnerability
  4888. | [63814] nginx CVE-2013-4547 URI Processing Security Bypass Vulnerability
  4889. | [59824] Nginx CVE-2013-2070 Remote Security Vulnerability
  4890. | [59699] nginx 'ngx_http_parse.c' Stack Buffer Overflow Vulnerability
  4891. | [59496] nginx 'ngx_http_close_connection()' Remote Integer Overflow Vulnerability
  4892. | [59323] nginx NULL-Byte Arbitrary Code Execution Vulnerability
  4893. | [58105] Nginx 'access.log' Insecure File Permissions Vulnerability
  4894. | [57139] nginx CVE-2011-4968 Man in The Middle Vulnerability
  4895. | [55920] nginx CVE-2011-4963 Security Bypass Vulnerability
  4896. | [54331] Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
  4897. | [52999] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  4898. | [52578] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  4899. | [50710] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  4900. | [40760] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  4901. | [40434] nginx Space String Remote Source Code Disclosure Vulnerability
  4902. | [40420] nginx Directory Traversal Vulnerability
  4903. | [37711] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  4904. | [36839] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  4905. | [36490] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  4906. | [36438] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  4907. | [36384] nginx HTTP Request Remote Buffer Overflow Vulnerability
  4908. |
  4909. | IBM X-Force - https://exchange.xforce.ibmcloud.com:
  4910. | [84623] Phusion Passenger gem for Ruby with nginx configuration insecure permissions
  4911. | [84172] nginx denial of service
  4912. | [84048] nginx buffer overflow
  4913. | [83923] nginx ngx_http_close_connection() integer overflow
  4914. | [83688] nginx null byte code execution
  4915. | [83103] Naxsi module for Nginx naxsi_unescape_uri() function security bypass
  4916. | [82319] nginx access.log information disclosure
  4917. | [80952] nginx SSL spoofing
  4918. | [77244] nginx and Microsoft Windows request security bypass
  4919. | [76778] Naxsi module for Nginx nx_extract.py directory traversal
  4920. | [74831] nginx ngx_http_mp4_module.c buffer overflow
  4921. | [74191] nginx ngx_cpystrn() information disclosure
  4922. | [74045] nginx header response information disclosure
  4923. | [71355] nginx ngx_resolver_copy() buffer overflow
  4924. | [59370] nginx characters denial of service
  4925. | [59369] nginx DATA source code disclosure
  4926. | [59047] nginx space source code disclosure
  4927. | [58966] nginx unspecified directory traversal
  4928. | [54025] nginx ngx_http_parse.c denial of service
  4929. | [53431] nginx WebDAV component directory traversal
  4930. | [53328] Nginx CRC-32 cached domain name spoofing
  4931. | [53250] Nginx ngx_http_parse_complex_uri() function code execution
  4932. |
  4933. | Exploit-DB - https://www.exploit-db.com:
  4934. | [26737] nginx 1.3.9/1.4.0 x86 Brute Force Remote Exploit
  4935. | [25775] Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow
  4936. | [25499] nginx 1.3.9-1.4.0 DoS PoC
  4937. | [24967] nginx 0.6.x Arbitrary Code Execution NullByte Injection
  4938. | [14830] nginx 0.6.38 - Heap Corruption Exploit
  4939. | [13822] Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability
  4940. | [13818] Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities
  4941. | [12804] nginx [engine x] http server <= 0.6.36 Path Draversal
  4942. | [9901] nginx 0.7.0-0.7.61, 0.6.0-0.6.38, 0.5.0-0.5.37, 0.4.0-0.4.14 PoC
  4943. | [9829] nginx 0.7.61 WebDAV directory traversal
  4944. |
  4945. | OpenVAS (Nessus) - http://www.openvas.org:
  4946. | [864418] Fedora Update for nginx FEDORA-2012-3846
  4947. | [864310] Fedora Update for nginx FEDORA-2012-6238
  4948. | [864209] Fedora Update for nginx FEDORA-2012-6411
  4949. | [864204] Fedora Update for nginx FEDORA-2012-6371
  4950. | [864121] Fedora Update for nginx FEDORA-2012-4006
  4951. | [864115] Fedora Update for nginx FEDORA-2012-3991
  4952. | [864065] Fedora Update for nginx FEDORA-2011-16075
  4953. | [863654] Fedora Update for nginx FEDORA-2011-16110
  4954. | [861232] Fedora Update for nginx FEDORA-2007-1158
  4955. | [850180] SuSE Update for nginx openSUSE-SU-2012:0237-1 (nginx)
  4956. | [831680] Mandriva Update for nginx MDVSA-2012:043 (nginx)
  4957. | [802045] 64-bit Debian Linux Rootkit with nginx Doing iFrame Injection
  4958. | [801636] nginx HTTP Request Remote Buffer Overflow Vulnerability
  4959. | [103470] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  4960. | [103469] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  4961. | [103344] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  4962. | [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  4963. | [100659] nginx Directory Traversal Vulnerability
  4964. | [100658] nginx Space String Remote Source Code Disclosure Vulnerability
  4965. | [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  4966. | [100321] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  4967. | [100277] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  4968. | [100276] nginx HTTP Request Remote Buffer Overflow Vulnerability
  4969. | [100275] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  4970. | [71574] Gentoo Security Advisory GLSA 201206-07 (nginx)
  4971. | [71308] Gentoo Security Advisory GLSA 201203-22 (nginx)
  4972. | [71297] FreeBSD Ports: nginx
  4973. | [71276] FreeBSD Ports: nginx
  4974. | [71239] Debian Security Advisory DSA 2434-1 (nginx)
  4975. | [66451] Fedora Core 11 FEDORA-2009-12782 (nginx)
  4976. | [66450] Fedora Core 10 FEDORA-2009-12775 (nginx)
  4977. | [66449] Fedora Core 12 FEDORA-2009-12750 (nginx)
  4978. | [64924] Gentoo Security Advisory GLSA 200909-18 (nginx)
  4979. | [64912] Fedora Core 10 FEDORA-2009-9652 (nginx)
  4980. | [64911] Fedora Core 11 FEDORA-2009-9630 (nginx)
  4981. | [64894] FreeBSD Ports: nginx
  4982. | [64869] Debian Security Advisory DSA 1884-1 (nginx)
  4983. |
  4984. | SecurityTracker - https://www.securitytracker.com:
  4985. | [1028544] nginx Bug Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
  4986. | [1028519] nginx Stack Overflow Lets Remote Users Execute Arbitrary Code
  4987. | [1026924] nginx Buffer Overflow in ngx_http_mp4_module Lets Remote Users Execute Arbitrary Code
  4988. | [1026827] nginx HTTP Response Processing Lets Remote Users Obtain Portions of Memory Contents
  4989. |
  4990. | OSVDB - http://www.osvdb.org:
  4991. | [94864] cPnginx Plugin for cPanel nginx Configuration Manipulation Arbitrary File Access
  4992. | [93282] nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
  4993. | [93037] nginx /http/ngx_http_parse.c Worker Process Crafted Request Handling Remote Overflow
  4994. | [92796] nginx ngx_http_close_connection Function Crafted r-&gt
  4995. | [92634] nginx ngx_http_request.h zero_in_uri URL Null Byte Handling Remote Code Execution
  4996. | [90518] nginx Log Directory Permission Weakness Local Information Disclosure
  4997. | [88910] nginx Proxy Functionality SSL Certificate Validation MitM Spoofing Weakness
  4998. | [84339] nginx/Windows Multiple Request Sequence Parsing Arbitrary File Access
  4999. | [83617] Naxsi Module for Nginx naxsi-ui/ nx_extract.py Traversal Arbitrary File Access
  5000. | [81339] nginx ngx_http_mp4_module Module Atom MP4 File Handling Remote Overflow
  5001. | [80124] nginx HTTP Header Response Parsing Freed Memory Information Disclosure
  5002. | [77184] nginx ngx_resolver.c ngx_resolver_copy() Function DNS Response Parsing Remote Overflow
  5003. | [65531] nginx on Windows URI ::$DATA Append Arbitrary File Access
  5004. | [65530] nginx Encoded Traversal Sequence Memory Corruption Remote DoS
  5005. | [65294] nginx on Windows Encoded Space Request Remote Source Disclosure
  5006. | [63136] nginx on Windows 8.3 Filename Alias Request Access Rules / Authentication Bypass
  5007. | [62617] nginx Internal DNS Cache Poisoning Weakness
  5008. | [61779] nginx HTTP Request Escape Sequence Terminal Command Injection
  5009. | [59278] nginx src/http/ngx_http_parse.c ngx_http_process_request_headers() Function URL Handling NULL Dereference DoS
  5010. | [58328] nginx WebDAV Multiple Method Traversal Arbitrary File Write
  5011. | [58128] nginx ngx_http_parse_complex_uri() Function Underflow
  5012. | [44447] nginx (engine x) msie_refresh Directive Unspecified XSS
  5013. | [44446] nginx (engine x) ssl_verify_client Directive HTTP/0.9 Protocol Bypass
  5014. | [44445] nginx (engine x) ngx_http_realip_module satisfy_any Directive Unspecified Access Bypass
  5015. | [44444] nginx (engine x) X-Accel-Redirect Header Unspecified Traversal
  5016. | [44443] nginx (engine x) rtsig Method Signal Queue Overflow
  5017. | [44442] nginx (engine x) Worker Process Millisecond Timers Unspecified Overflow
  5018. |_
  5019. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  5020. Device type: general purpose
  5021. Running (JUST GUESSING): Linux 3.X|2.6.X|4.X (98%)
  5022. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:4.0
  5023. Aggressive OS guesses: Linux 3.10 - 3.12 (98%), Linux 2.6.32 (90%), Linux 3.10 - 3.16 (90%), Linux 4.0 (90%), Linux 4.4 (89%), Linux 3.10 (88%)
  5024. No exact OS matches for host (test conditions non-ideal).
  5025. Uptime guess: 11.851 days (since Sun Sep 29 03:14:49 2019)
  5026. Network Distance: 24 hops
  5027. TCP Sequence Prediction: Difficulty=263 (Good luck!)
  5028. IP ID Sequence Generation: All zeros
  5029.  
  5030. TRACEROUTE (using port 80/tcp)
  5031. HOP RTT ADDRESS
  5032. 1 81.50 ms 10.249.204.1
  5033. 2 81.56 ms 104.245.145.161
  5034. 3 81.59 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
  5035. 4 81.61 ms te0-0-0-1.agr14.yyz02.atlas.cogentco.com (154.24.54.41)
  5036. 5 81.64 ms te0-9-1-9.ccr31.yyz02.atlas.cogentco.com (154.54.43.161)
  5037. 6 81.67 ms be2993.ccr21.cle04.atlas.cogentco.com (154.54.31.225)
  5038. 7 81.73 ms be2717.ccr41.ord01.atlas.cogentco.com (154.54.6.221)
  5039. 8 81.73 ms be2765.ccr41.ord03.atlas.cogentco.com (154.54.45.18)
  5040. 9 81.72 ms ae-11.r08.chcgil09.us.bb.gin.ntt.net (129.250.9.121)
  5041. 10 81.79 ms ae-0.r20.chcgil09.us.bb.gin.ntt.net (129.250.2.191)
  5042. 11 111.67 ms ae-0.r25.nycmny01.us.bb.gin.ntt.net (129.250.2.167)
  5043. 12 171.08 ms ae-9.r24.frnkge08.de.bb.gin.ntt.net (129.250.2.5)
  5044. 13 171.02 ms ae-1.r01.frnkge13.de.bb.gin.ntt.net (129.250.2.85)
  5045. 14 ... 19
  5046. 20 230.77 ms mta4-v14.buaslanmis.com (212.174.117.78)
  5047. 21 203.76 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  5048. 22 215.47 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  5049. 23 215.40 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  5050. 24 217.68 ms 212.174.188.50
  5051.  
  5052. NSE: Script Post-scanning.
  5053. Initiating NSE at 23:39
  5054. Completed NSE at 23:39, 0.00s elapsed
  5055. Initiating NSE at 23:39
  5056. Completed NSE at 23:39, 0.00s elapsed
  5057. Read data files from: /usr/bin/../share/nmap
  5058. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  5059. Nmap done: 1 IP address (1 host up) scanned in 83.39 seconds
  5060. ######################################################################################################################################
  5061. https://212.174.188.50 [301 Moved Permanently] Country[TURKEY][TR], HTTPServer[nginx], IP[212.174.188.50], RedirectLocation[https://www.hmb.gov.tr], Title[301 Moved Permanently], nginx
  5062. https://www.hmb.gov.tr [200 OK] Country[TURKEY][TR], HTML5, HTTPServer[nginx], IP[212.174.188.50], Script, Title[T.C. Hazine ve Maliye Bakanlığı], X-UA-Compatible[IE=edge], nginx
  5063. ######################################################################################################################################
  5064. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-10 23:40 EDT
  5065. NSE: Loaded 163 scripts for scanning.
  5066. NSE: Script Pre-scanning.
  5067. Initiating NSE at 23:40
  5068. Completed NSE at 23:40, 0.00s elapsed
  5069. Initiating NSE at 23:40
  5070. Completed NSE at 23:40, 0.00s elapsed
  5071. Initiating Parallel DNS resolution of 1 host. at 23:40
  5072. Completed Parallel DNS resolution of 1 host. at 23:40, 10.33s elapsed
  5073. Initiating SYN Stealth Scan at 23:40
  5074. Scanning 212.174.188.50 [1 port]
  5075. Discovered open port 443/tcp on 212.174.188.50
  5076. Completed SYN Stealth Scan at 23:40, 0.27s elapsed (1 total ports)
  5077. Initiating Service scan at 23:40
  5078. Scanning 1 service on 212.174.188.50
  5079. Completed Service scan at 23:40, 13.35s elapsed (1 service on 1 host)
  5080. Initiating OS detection (try #1) against 212.174.188.50
  5081. Initiating Traceroute at 23:40
  5082. Completed Traceroute at 23:40, 0.55s elapsed
  5083. Initiating Parallel DNS resolution of 22 hosts. at 23:40
  5084. Completed Parallel DNS resolution of 22 hosts. at 23:40, 10.37s elapsed
  5085. NSE: Script scanning 212.174.188.50.
  5086. Initiating NSE at 23:40
  5087. Completed NSE at 23:45, 271.09s elapsed
  5088. Initiating NSE at 23:45
  5089. Completed NSE at 23:45, 2.30s elapsed
  5090. Nmap scan report for 212.174.188.50
  5091. Host is up (0.22s latency).
  5092.  
  5093. PORT STATE SERVICE VERSION
  5094. 443/tcp open ssl/http nginx
  5095. | http-brute:
  5096. |_ Path "/" does not require authentication
  5097. |_http-chrono: ERROR: Script execution failed (use -d to debug)
  5098. |_http-csrf: Couldn't find any CSRF vulnerabilities.
  5099. |_http-date: Fri, 11 Oct 2019 03:40:30 GMT; -40s from local time.
  5100. | http-default-accounts:
  5101. | [Arris 2307] at /logo_t.gif
  5102. |_ <blank>:<blank>
  5103. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
  5104. |_http-dombased-xss: Couldn't find any DOM based XSS.
  5105. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
  5106. |_http-errors: Couldn't find any error pages.
  5107. |_http-feed: Couldn't find any feeds.
  5108. |_http-fetch: Please enter the complete path of the directory to save data in.
  5109. | http-headers:
  5110. | Server: nginx
  5111. | Date: Fri, 11 Oct 2019 03:40:34 GMT
  5112. | Content-Type: text/html
  5113. | Content-Length: 178
  5114. | Connection: close
  5115. | Location: https://www.hmb.gov.tr
  5116. |
  5117. |_ (Request type: GET)
  5118. |_http-jsonp-detection: Couldn't find any JSONP endpoints.
  5119. | http-methods:
  5120. |_ Supported Methods: GET HEAD POST OPTIONS
  5121. |_http-mobileversion-checker: No mobile version detected.
  5122. |_http-passwd: ERROR: Script execution failed (use -d to debug)
  5123. | http-security-headers:
  5124. | Strict_Transport_Security:
  5125. |_ HSTS not configured in HTTPS Server
  5126. | http-sitemap-generator:
  5127. | Directory structure:
  5128. | Longest directory structure:
  5129. | Depth: 0
  5130. | Dir: /
  5131. | Total files found (by extension):
  5132. |_
  5133. |_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
  5134. |_http-title: Did not follow redirect to https://www.hmb.gov.tr
  5135. | http-traceroute:
  5136. | HTML title
  5137. | Hop #1: 400 The plain HTTP request was sent to HTTPS port
  5138. | Hop #2: 301 Moved Permanently
  5139. | Hop #3: 301 Moved Permanently
  5140. | Status Code
  5141. | Hop #1: 400
  5142. | Hop #2: 301
  5143. | Hop #3: 301
  5144. | content-length
  5145. | Hop #1: 264
  5146. | Hop #2: 178
  5147. | Hop #3: 178
  5148. | location
  5149. | Hop #1
  5150. | Hop #2: https://www.hmb.gov.tr
  5151. |_ Hop #3: https://www.hmb.gov.tr
  5152. |_http-userdir-enum: Potential Users: root, admin, administrator, webadmin, sysadmin, netadmin, guest, user, web, test
  5153. | http-vhosts:
  5154. | 125 names had status 200
  5155. | sip : 400
  5156. |_administration : 400
  5157. | http-wordpress-enum:
  5158. | Search limited to top 100 themes/plugins
  5159. | plugins
  5160. | akismet
  5161. | contact-form-7
  5162. | wordpress-seo
  5163. | jetpack
  5164. | all-in-one-seo-pack
  5165. | wordfence
  5166. | woocommerce
  5167. | google-sitemap-generator
  5168. | wordpress-importer
  5169. | nextgen-gallery
  5170. | google-analytics-for-wordpress
  5171. | wp-super-cache
  5172. | tinymce-advanced
  5173. | wptouch
  5174. | better-wp-security
  5175. | siteorigin-panels
  5176. | updraftplus
  5177. | w3-total-cache
  5178. | google-analytics-dashboard-for-wp
  5179. | wp-pagenavi
  5180. | si-contact-form
  5181. | advanced-custom-fields
  5182. | mailchimp-for-wp
  5183. | the-events-calendar
  5184. | add-to-any
  5185. | duplicator
  5186. | wysija-newsletters
  5187. | ninja-forms
  5188. | wp-smushit
  5189. | buddypress
  5190. | ewww-image-optimizer
  5191. | so-widgets-bundle
  5192. | really-simple-captcha
  5193. | ml-slider
  5194. | black-studio-tinymce-widget
  5195. | photo-gallery
  5196. | broken-link-checker
  5197. | regenerate-thumbnails
  5198. | google-analyticator
  5199. | redirection
  5200. | captcha
  5201. | duplicate-post
  5202. | breadcrumb-navxt
  5203. | backwpup
  5204. | user-role-editor
  5205. | yet-another-related-posts-plugin
  5206. | contact-form-plugin
  5207. | newsletter
  5208. | bbpress
  5209. | all-in-one-wp-security-and-firewall
  5210. | disable-comments
  5211. | social-networks-auto-poster-facebook-twitter-g
  5212. | wp-optimize
  5213. | addthis
  5214. | wp-statistics
  5215. | wp-e-commerce
  5216. | all-in-one-wp-migration
  5217. | backupwordpress
  5218. | si-captcha-for-wordpress
  5219. | wp-slimstat
  5220. | wp-google-maps
  5221. | wp-spamshield
  5222. | wp-maintenance-mode
  5223. | googleanalytics
  5224. | worker
  5225. | yith-woocommerce-wishlist
  5226. | wp-multibyte-patch
  5227. | wp-to-twitter
  5228. | image-widget
  5229. | wp-db-backup
  5230. | shortcodes-ultimate
  5231. | ultimate-tinymce
  5232. | share-this
  5233. | disqus-comment-system
  5234. | gallery-bank
  5235. | types
  5236. | wp-polls
  5237. | custom-post-type-ui
  5238. | shareaholic
  5239. | polylang
  5240. | post-types-order
  5241. | gtranslate
  5242. | bulletproof-security
  5243. | wp-fastest-cache
  5244. | facebook
  5245. | sociable
  5246. | iwp-client
  5247. | nextgen-facebook
  5248. | seo-ultimate
  5249. | wp-postviews
  5250. | formidable
  5251. | squirrly-seo
  5252. | wp-mail-smtp
  5253. | tablepress
  5254. | redux-framework
  5255. | page-links-to
  5256. | youtube-embed-plus
  5257. | contact-bank
  5258. | maintenance
  5259. | wp-retina-2x
  5260. | themes
  5261. | twentyeleven
  5262. | twentytwelve
  5263. | twentyten
  5264. | twentythirteen
  5265. | twentyfourteen
  5266. | twentyfifteen
  5267. | responsive
  5268. | customizr
  5269. | zerif-lite
  5270. | virtue
  5271. | storefront
  5272. | atahualpa
  5273. | twentysixteen
  5274. | vantage
  5275. | hueman
  5276. | spacious
  5277. | evolve
  5278. | colorway
  5279. | graphene
  5280. | sydney
  5281. | ifeature
  5282. | mh-magazine-lite
  5283. | generatepress
  5284. | mantra
  5285. | omega
  5286. | onetone
  5287. | coraline
  5288. | pinboard
  5289. | thematic
  5290. | sparkling
  5291. | catch-box
  5292. | make
  5293. | colormag
  5294. | enigma
  5295. | custom-community
  5296. | mystique
  5297. | alexandria
  5298. | delicate
  5299. | lightword
  5300. | attitude
  5301. | inove
  5302. | magazine-basic
  5303. | raindrops
  5304. | minamaze
  5305. | zbench
  5306. | point
  5307. | eclipse
  5308. | portfolio-press
  5309. | twentyseventeen
  5310. | travelify
  5311. | swift-basic
  5312. | iconic-one
  5313. | arcade-basic
  5314. | bouquet
  5315. | pixel
  5316. | sliding-door
  5317. | pilcrow
  5318. | simple-catch
  5319. | tempera
  5320. | destro
  5321. | p2
  5322. | sunspot
  5323. | sundance
  5324. | dusk-to-dawn
  5325. | onepress
  5326. | moesia
  5327. | dynamic-news-lite
  5328. | parabola
  5329. | parament
  5330. | dazzling
  5331. | accesspress-lite
  5332. | optimizer
  5333. | one-page
  5334. | chaostheory
  5335. | business-lite
  5336. | duster
  5337. | constructor
  5338. | nirvana
  5339. | sixteen
  5340. | esquire
  5341. | beach
  5342. | next-saturday
  5343. | flat
  5344. | hatch
  5345. | minimatica
  5346. | radiate
  5347. | accelerate
  5348. | oxygen
  5349. | accesspress-parallax
  5350. | swift
  5351. | spun
  5352. | wp-creativix
  5353. | suevafree
  5354. | hemingway
  5355. | pink-touch-2
  5356. | motion
  5357. | fruitful
  5358. | steira
  5359. | news
  5360. |_ llorix-one-lite
  5361. |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
  5362. |_http-xssed: No previously reported XSS vuln.
  5363. | vulscan: VulDB - https://vuldb.com:
  5364. | [133852] Sangfor Sundray WLAN Controller up to 3.7.4.2 Cookie Header nginx_webconsole.php Code Execution
  5365. | [132132] SoftNAS Cloud 4.2.0/4.2.1 Nginx privilege escalation
  5366. | [131858] Puppet Discovery up to 1.3.x Nginx Container weak authentication
  5367. | [130644] Nginx Unit up to 1.7.0 Router Process Request Heap-based memory corruption
  5368. | [127759] VeryNginx 0.3.3 Web Application Firewall privilege escalation
  5369. | [126525] nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
  5370. | [126524] nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
  5371. | [126523] nginx up to 1.14.0/1.15.5 HTTP2 Memory Consumption denial of service
  5372. | [119845] Pivotal Operations Manager up to 2.0.13/2.1.5 Nginx privilege escalation
  5373. | [114368] SuSE Portus 2.3 Nginx Certificate weak authentication
  5374. | [103517] nginx up to 1.13.2 Range Filter Request Integer Overflow memory corruption
  5375. | [89849] nginx RFC 3875 Namespace Conflict Environment Variable Open Redirect
  5376. | [87719] nginx up to 1.11.0 ngx_files.c ngx_chain_to_iovec denial of service
  5377. | [80760] nginx 0.6.18/1.9.9 DNS CNAME Record Crash denial of service
  5378. | [80759] nginx 0.6.18/1.9.9 DNS CNAME Record Use-After-Free denial of service
  5379. | [80758] nginx 0.6.18/1.9.9 DNS UDP Packet Crash denial of service
  5380. | [67677] nginx up to 1.7.3 SSL weak authentication
  5381. | [67296] nginx up to 1.7.3 SMTP Proxy ngx_mail_smtp_starttls privilege escalation
  5382. | [12822] nginx up to 1.5.11 SPDY SPDY Request Heap-based memory corruption
  5383. | [12824] nginx 1.5.10 on 32-bit SPDY memory corruption
  5384. | [11237] nginx up to 1.5.6 URI String Bypass privilege escalation
  5385. | [65364] nginx up to 1.1.13 Default Configuration information disclosure
  5386. | [8671] nginx up to 1.4 proxy_pass denial of service
  5387. | [8618] nginx 1.3.9/1.4.0 http/ngx_http_parse.c ngx_http_parse_chunked() memory corruption
  5388. | [7247] nginx 1.2.6 Proxy Function spoofing
  5389. | [61434] nginx 1.2.0/1.3.0 on Windows Access Restriction privilege escalation
  5390. | [5293] nginx up to 1.1.18 ngx_http_mp4_module MP4 File memory corruption
  5391. | [4843] nginx up to 1.0.13/1.1.16 HTTP Header Response Parser ngx_http_parse.c information disclosure
  5392. | [59645] nginx up to 0.8.9 Heap-based memory corruption
  5393. | [53592] nginx 0.8.36 memory corruption
  5394. | [53590] nginx up to 0.8.9 unknown vulnerability
  5395. | [51533] nginx 0.7.64 Terminal privilege escalation
  5396. | [50905] nginx up to 0.8.9 directory traversal
  5397. | [50903] nginx up to 0.8.10 NULL Pointer Dereference denial of service
  5398. | [50043] nginx up to 0.8.10 memory corruption
  5399. |
  5400. | MITRE CVE - https://cve.mitre.org:
  5401. | [CVE-2013-2070] http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
  5402. | [CVE-2013-2028] The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
  5403. | [CVE-2012-3380] Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
  5404. | [CVE-2012-2089] Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
  5405. | [CVE-2012-1180] Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
  5406. | [CVE-2011-4963] nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
  5407. | [CVE-2011-4315] Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
  5408. | [CVE-2010-2266] nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
  5409. | [CVE-2010-2263] nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
  5410. | [CVE-2009-4487] nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
  5411. | [CVE-2009-3898] Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
  5412. | [CVE-2009-3896] src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.
  5413. | [CVE-2009-2629] Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
  5414. |
  5415. | SecurityFocus - https://www.securityfocus.com/bid/:
  5416. | [99534] Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
  5417. | [93903] Nginx CVE-2016-1247 Remote Privilege Escalation Vulnerability
  5418. | [91819] Nginx CVE-2016-1000105 Security Bypass Vulnerability
  5419. | [90967] nginx CVE-2016-4450 Denial of Service Vulnerability
  5420. | [82230] nginx Multiple Denial of Service Vulnerabilities
  5421. | [78928] Nginx CVE-2010-2266 Denial-Of-Service Vulnerability
  5422. | [70025] nginx CVE-2014-3616 SSL Session Fixation Vulnerability
  5423. | [69111] nginx SMTP Proxy Remote Command Injection Vulnerability
  5424. | [67507] nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
  5425. | [66537] nginx SPDY Implementation Heap Based Buffer Overflow Vulnerability
  5426. | [63814] nginx CVE-2013-4547 URI Processing Security Bypass Vulnerability
  5427. | [59824] Nginx CVE-2013-2070 Remote Security Vulnerability
  5428. | [59699] nginx 'ngx_http_parse.c' Stack Buffer Overflow Vulnerability
  5429. | [59496] nginx 'ngx_http_close_connection()' Remote Integer Overflow Vulnerability
  5430. | [59323] nginx NULL-Byte Arbitrary Code Execution Vulnerability
  5431. | [58105] Nginx 'access.log' Insecure File Permissions Vulnerability
  5432. | [57139] nginx CVE-2011-4968 Man in The Middle Vulnerability
  5433. | [55920] nginx CVE-2011-4963 Security Bypass Vulnerability
  5434. | [54331] Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
  5435. | [52999] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  5436. | [52578] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  5437. | [50710] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  5438. | [40760] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  5439. | [40434] nginx Space String Remote Source Code Disclosure Vulnerability
  5440. | [40420] nginx Directory Traversal Vulnerability
  5441. | [37711] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  5442. | [36839] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  5443. | [36490] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  5444. | [36438] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  5445. | [36384] nginx HTTP Request Remote Buffer Overflow Vulnerability
  5446. |
  5447. | IBM X-Force - https://exchange.xforce.ibmcloud.com:
  5448. | [84623] Phusion Passenger gem for Ruby with nginx configuration insecure permissions
  5449. | [84172] nginx denial of service
  5450. | [84048] nginx buffer overflow
  5451. | [83923] nginx ngx_http_close_connection() integer overflow
  5452. | [83688] nginx null byte code execution
  5453. | [83103] Naxsi module for Nginx naxsi_unescape_uri() function security bypass
  5454. | [82319] nginx access.log information disclosure
  5455. | [80952] nginx SSL spoofing
  5456. | [77244] nginx and Microsoft Windows request security bypass
  5457. | [76778] Naxsi module for Nginx nx_extract.py directory traversal
  5458. | [74831] nginx ngx_http_mp4_module.c buffer overflow
  5459. | [74191] nginx ngx_cpystrn() information disclosure
  5460. | [74045] nginx header response information disclosure
  5461. | [71355] nginx ngx_resolver_copy() buffer overflow
  5462. | [59370] nginx characters denial of service
  5463. | [59369] nginx DATA source code disclosure
  5464. | [59047] nginx space source code disclosure
  5465. | [58966] nginx unspecified directory traversal
  5466. | [54025] nginx ngx_http_parse.c denial of service
  5467. | [53431] nginx WebDAV component directory traversal
  5468. | [53328] Nginx CRC-32 cached domain name spoofing
  5469. | [53250] Nginx ngx_http_parse_complex_uri() function code execution
  5470. |
  5471. | Exploit-DB - https://www.exploit-db.com:
  5472. | [26737] nginx 1.3.9/1.4.0 x86 Brute Force Remote Exploit
  5473. | [25775] Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow
  5474. | [25499] nginx 1.3.9-1.4.0 DoS PoC
  5475. | [24967] nginx 0.6.x Arbitrary Code Execution NullByte Injection
  5476. | [14830] nginx 0.6.38 - Heap Corruption Exploit
  5477. | [13822] Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability
  5478. | [13818] Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities
  5479. | [12804] nginx [engine x] http server <= 0.6.36 Path Draversal
  5480. | [9901] nginx 0.7.0-0.7.61, 0.6.0-0.6.38, 0.5.0-0.5.37, 0.4.0-0.4.14 PoC
  5481. | [9829] nginx 0.7.61 WebDAV directory traversal
  5482. |
  5483. | OpenVAS (Nessus) - http://www.openvas.org:
  5484. | [864418] Fedora Update for nginx FEDORA-2012-3846
  5485. | [864310] Fedora Update for nginx FEDORA-2012-6238
  5486. | [864209] Fedora Update for nginx FEDORA-2012-6411
  5487. | [864204] Fedora Update for nginx FEDORA-2012-6371
  5488. | [864121] Fedora Update for nginx FEDORA-2012-4006
  5489. | [864115] Fedora Update for nginx FEDORA-2012-3991
  5490. | [864065] Fedora Update for nginx FEDORA-2011-16075
  5491. | [863654] Fedora Update for nginx FEDORA-2011-16110
  5492. | [861232] Fedora Update for nginx FEDORA-2007-1158
  5493. | [850180] SuSE Update for nginx openSUSE-SU-2012:0237-1 (nginx)
  5494. | [831680] Mandriva Update for nginx MDVSA-2012:043 (nginx)
  5495. | [802045] 64-bit Debian Linux Rootkit with nginx Doing iFrame Injection
  5496. | [801636] nginx HTTP Request Remote Buffer Overflow Vulnerability
  5497. | [103470] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  5498. | [103469] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  5499. | [103344] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  5500. | [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  5501. | [100659] nginx Directory Traversal Vulnerability
  5502. | [100658] nginx Space String Remote Source Code Disclosure Vulnerability
  5503. | [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  5504. | [100321] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  5505. | [100277] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  5506. | [100276] nginx HTTP Request Remote Buffer Overflow Vulnerability
  5507. | [100275] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  5508. | [71574] Gentoo Security Advisory GLSA 201206-07 (nginx)
  5509. | [71308] Gentoo Security Advisory GLSA 201203-22 (nginx)
  5510. | [71297] FreeBSD Ports: nginx
  5511. | [71276] FreeBSD Ports: nginx
  5512. | [71239] Debian Security Advisory DSA 2434-1 (nginx)
  5513. | [66451] Fedora Core 11 FEDORA-2009-12782 (nginx)
  5514. | [66450] Fedora Core 10 FEDORA-2009-12775 (nginx)
  5515. | [66449] Fedora Core 12 FEDORA-2009-12750 (nginx)
  5516. | [64924] Gentoo Security Advisory GLSA 200909-18 (nginx)
  5517. | [64912] Fedora Core 10 FEDORA-2009-9652 (nginx)
  5518. | [64911] Fedora Core 11 FEDORA-2009-9630 (nginx)
  5519. | [64894] FreeBSD Ports: nginx
  5520. | [64869] Debian Security Advisory DSA 1884-1 (nginx)
  5521. |
  5522. | SecurityTracker - https://www.securitytracker.com:
  5523. | [1028544] nginx Bug Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
  5524. | [1028519] nginx Stack Overflow Lets Remote Users Execute Arbitrary Code
  5525. | [1026924] nginx Buffer Overflow in ngx_http_mp4_module Lets Remote Users Execute Arbitrary Code
  5526. | [1026827] nginx HTTP Response Processing Lets Remote Users Obtain Portions of Memory Contents
  5527. |
  5528. | OSVDB - http://www.osvdb.org:
  5529. | [94864] cPnginx Plugin for cPanel nginx Configuration Manipulation Arbitrary File Access
  5530. | [93282] nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
  5531. | [93037] nginx /http/ngx_http_parse.c Worker Process Crafted Request Handling Remote Overflow
  5532. | [92796] nginx ngx_http_close_connection Function Crafted r-&gt
  5533. | [92634] nginx ngx_http_request.h zero_in_uri URL Null Byte Handling Remote Code Execution
  5534. | [90518] nginx Log Directory Permission Weakness Local Information Disclosure
  5535. | [88910] nginx Proxy Functionality SSL Certificate Validation MitM Spoofing Weakness
  5536. | [84339] nginx/Windows Multiple Request Sequence Parsing Arbitrary File Access
  5537. | [83617] Naxsi Module for Nginx naxsi-ui/ nx_extract.py Traversal Arbitrary File Access
  5538. | [81339] nginx ngx_http_mp4_module Module Atom MP4 File Handling Remote Overflow
  5539. | [80124] nginx HTTP Header Response Parsing Freed Memory Information Disclosure
  5540. | [77184] nginx ngx_resolver.c ngx_resolver_copy() Function DNS Response Parsing Remote Overflow
  5541. | [65531] nginx on Windows URI ::$DATA Append Arbitrary File Access
  5542. | [65530] nginx Encoded Traversal Sequence Memory Corruption Remote DoS
  5543. | [65294] nginx on Windows Encoded Space Request Remote Source Disclosure
  5544. | [63136] nginx on Windows 8.3 Filename Alias Request Access Rules / Authentication Bypass
  5545. | [62617] nginx Internal DNS Cache Poisoning Weakness
  5546. | [61779] nginx HTTP Request Escape Sequence Terminal Command Injection
  5547. | [59278] nginx src/http/ngx_http_parse.c ngx_http_process_request_headers() Function URL Handling NULL Dereference DoS
  5548. | [58328] nginx WebDAV Multiple Method Traversal Arbitrary File Write
  5549. | [58128] nginx ngx_http_parse_complex_uri() Function Underflow
  5550. | [44447] nginx (engine x) msie_refresh Directive Unspecified XSS
  5551. | [44446] nginx (engine x) ssl_verify_client Directive HTTP/0.9 Protocol Bypass
  5552. | [44445] nginx (engine x) ngx_http_realip_module satisfy_any Directive Unspecified Access Bypass
  5553. | [44444] nginx (engine x) X-Accel-Redirect Header Unspecified Traversal
  5554. | [44443] nginx (engine x) rtsig Method Signal Queue Overflow
  5555. | [44442] nginx (engine x) Worker Process Millisecond Timers Unspecified Overflow
  5556. |_
  5557. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  5558. Device type: general purpose
  5559. Running: Linux 3.X
  5560. OS CPE: cpe:/o:linux:linux_kernel:3
  5561. OS details: Linux 3.10 - 3.12
  5562. Uptime guess: 11.855 days (since Sun Sep 29 03:14:49 2019)
  5563. Network Distance: 24 hops
  5564. TCP Sequence Prediction: Difficulty=263 (Good luck!)
  5565. IP ID Sequence Generation: All zeros
  5566.  
  5567. TRACEROUTE (using port 443/tcp)
  5568. HOP RTT ADDRESS
  5569. 1 97.07 ms 10.249.204.1
  5570. 2 132.90 ms 104.245.145.161
  5571. 3 132.98 ms te0-0-2-1.225.nr11.b010988-1.yyz02.atlas.cogentco.com (38.104.156.9)
  5572. 4 133.00 ms te0-0-0-1.agr14.yyz02.atlas.cogentco.com (154.24.54.41)
  5573. 5 132.98 ms te0-9-1-9.ccr32.yyz02.atlas.cogentco.com (154.54.43.169)
  5574. 6 133.04 ms be2994.ccr22.cle04.atlas.cogentco.com (154.54.31.233)
  5575. 7 133.07 ms be2718.ccr42.ord01.atlas.cogentco.com (154.54.7.129)
  5576. 8 133.12 ms be2766.ccr41.ord03.atlas.cogentco.com (154.54.46.178)
  5577. 9 133.11 ms ae-11.r08.chcgil09.us.bb.gin.ntt.net (129.250.9.121)
  5578. 10 133.18 ms ae-0.r20.chcgil09.us.bb.gin.ntt.net (129.250.2.191)
  5579. 11 70.53 ms ae-0.r25.nycmny01.us.bb.gin.ntt.net (129.250.2.167)
  5580. 12 188.25 ms ae-9.r24.frnkge08.de.bb.gin.ntt.net (129.250.2.5)
  5581. 13 188.23 ms ae-1.r01.frnkge13.de.bb.gin.ntt.net (129.250.2.85)
  5582. 14 188.23 ms nmf-0.r04.frnkge02.de.bb.gin.ntt.net (213.198.52.90)
  5583. 15 219.82 ms 34-acibadem-xrs-t2-1---301-fra-col-2.statik.turktelekom.com.tr (212.156.101.65)
  5584. 16 219.77 ms 212.156.120.184.static.turktelekom.com.tr (212.156.120.184)
  5585. 17 219.80 ms 00-gayrettepe-xrs-t2-1---00-ebgp-gayrettepe-k.statik.turktelekom.com.tr (81.212.201.194)
  5586. 18 219.82 ms 06-ulus-xrs-t2-1---34-acibadem-xrs-t2-1.statik.turktelekom.com.tr (195.175.166.207)
  5587. 19 219.79 ms 81.212.215.188.static.turktelekom.com.tr (81.212.215.188)
  5588. 20 219.77 ms mta4-v14.buaslanmis.com (212.174.117.78)
  5589. 21 287.18 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  5590. 22 207.71 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  5591. 23 207.77 ms 212.175.34.34.static.ttnet.com.tr (212.175.34.34)
  5592. 24 207.72 ms 212.174.188.50
  5593.  
  5594. NSE: Script Post-scanning.
  5595. Initiating NSE at 23:45
  5596. Completed NSE at 23:45, 0.00s elapsed
  5597. Initiating NSE at 23:45
  5598. Completed NSE at 23:45, 0.00s elapsed
  5599. Read data files from: /usr/bin/../share/nmap
  5600. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  5601. Nmap done: 1 IP address (1 host up) scanned in 312.06 seconds
  5602. #######################################################################################################################################
  5603. Version: 1.11.13-static
  5604. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  5605.  
  5606. Connected to 212.174.188.50
  5607.  
  5608. Testing SSL server 212.174.188.50 on port 443 using SNI name 212.174.188.50
  5609.  
  5610. TLS Fallback SCSV:
  5611. Server supports TLS Fallback SCSV
  5612.  
  5613. TLS renegotiation:
  5614. Session renegotiation not supported
  5615.  
  5616. TLS Compression:
  5617. Compression disabled
  5618.  
  5619. Heartbleed:
  5620. TLS 1.2 not vulnerable to heartbleed
  5621. TLS 1.1 not vulnerable to heartbleed
  5622. TLS 1.0 not vulnerable to heartbleed
  5623.  
  5624. Supported Server Cipher(s):
  5625. Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384 Curve P-384 DHE 384
  5626. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-384 DHE 384
  5627.  
  5628. SSL Certificate:
  5629. Signature Algorithm: sha256WithRSAEncryption
  5630. RSA Key Strength: 2048
  5631.  
  5632. Subject: *.hmb.gov.tr
  5633. Altnames: DNS:*.hmb.gov.tr, DNS:hmb.gov.tr
  5634. Issuer: GlobalSign Organization Validation CA - SHA256 - G2
  5635.  
  5636. Not valid before: Oct 5 16:39:41 2018 GMT
  5637. Not valid after: Oct 5 16:39:41 2020 GMT
  5638. #######################################################################################################################################
  5639. <<<Yasuo discovered following vulnerable applications>>>
  5640. --------------------------------------------------------
  5641. +-------------------+-----------------------------------------+-----------------------------------------------------+----------+----------+
  5642. | App Name | URL to Application | Potential Exploit | Username | Password |
  5643. +-------------------+-----------------------------------------+-----------------------------------------------------+----------+----------+
  5644. | JBoss jmx-console | https://212.174.188.50:443/jmx-console/ | ./exploit/multi/http/jboss_deploymentfilerepository | None | None |
  5645. +-------------------+-----------------------------------------+-----------------------------------------------------+----------+----------+
  5646. #######################################################################################################################################
  5647. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-10 23:48 EDT
  5648. NSE: Loaded 47 scripts for scanning.
  5649. NSE: Script Pre-scanning.
  5650. Initiating NSE at 23:49
  5651. Completed NSE at 23:49, 0.00s elapsed
  5652. Initiating NSE at 23:49
  5653. Completed NSE at 23:49, 0.00s elapsed
  5654. Initiating Ping Scan at 23:49
  5655. Scanning 212.174.188.50 [4 ports]
  5656. Completed Ping Scan at 23:49, 0.24s elapsed (1 total hosts)
  5657. Initiating Parallel DNS resolution of 1 host. at 23:49
  5658. Completed Parallel DNS resolution of 1 host. at 23:49, 10.36s elapsed
  5659. Initiating SYN Stealth Scan at 23:49
  5660. Scanning 212.174.188.50 [65535 ports]
  5661. Discovered open port 80/tcp on 212.174.188.50
  5662. Discovered open port 443/tcp on 212.174.188.50
  5663. SYN Stealth Scan Timing: About 2.31% done; ETC: 00:11 (0:21:49 remaining)
  5664. SYN Stealth Scan Timing: About 13.48% done; ETC: 23:56 (0:06:32 remaining)
  5665. Discovered open port 18825/tcp on 212.174.188.50
  5666. Discovered open port 33789/tcp on 212.174.188.50
  5667. Discovered open port 53123/tcp on 212.174.188.50
  5668. Discovered open port 27429/tcp on 212.174.188.50
  5669. Discovered open port 7462/tcp on 212.174.188.50
  5670. Discovered open port 32803/tcp on 212.174.188.50
  5671. Discovered open port 32726/tcp on 212.174.188.50
  5672. Discovered open port 33688/tcp on 212.174.188.50
  5673. Discovered open port 46995/tcp on 212.174.188.50
  5674. Discovered open port 49097/tcp on 212.174.188.50
  5675. Discovered open port 30369/tcp on 212.174.188.50
  5676. Discovered open port 49693/tcp on 212.174.188.50
  5677. Discovered open port 59083/tcp on 212.174.188.50
  5678. Discovered open port 61861/tcp on 212.174.188.50
  5679. Discovered open port 45695/tcp on 212.174.188.50
  5680. Discovered open port 43401/tcp on 212.174.188.50
  5681. Discovered open port 20457/tcp on 212.174.188.50
  5682. Discovered open port 32876/tcp on 212.174.188.50
  5683. Discovered open port 15557/tcp on 212.174.188.50
  5684. Discovered open port 39006/tcp on 212.174.188.50
  5685. Discovered open port 11086/tcp on 212.174.188.50
  5686. Discovered open port 52299/tcp on 212.174.188.50
  5687. Discovered open port 15670/tcp on 212.174.188.50
  5688. Discovered open port 48932/tcp on 212.174.188.50
  5689. Discovered open port 18985/tcp on 212.174.188.50
  5690. Discovered open port 54484/tcp on 212.174.188.50
  5691. Discovered open port 1996/tcp on 212.174.188.50
  5692. Discovered open port 28728/tcp on 212.174.188.50
  5693. Discovered open port 15601/tcp on 212.174.188.50
  5694. Discovered open port 14878/tcp on 212.174.188.50
  5695. Discovered open port 10785/tcp on 212.174.188.50
  5696. Discovered open port 1012/tcp on 212.174.188.50
  5697. Discovered open port 7019/tcp on 212.174.188.50
  5698. Discovered open port 60345/tcp on 212.174.188.50
  5699. Discovered open port 50714/tcp on 212.174.188.50
  5700. Discovered open port 35234/tcp on 212.174.188.50
  5701. Discovered open port 24946/tcp on 212.174.188.50
  5702. Discovered open port 47415/tcp on 212.174.188.50
  5703. Discovered open port 46391/tcp on 212.174.188.50
  5704. Discovered open port 35974/tcp on 212.174.188.50
  5705. Discovered open port 23516/tcp on 212.174.188.50
  5706. Discovered open port 41424/tcp on 212.174.188.50
  5707. Discovered open port 2663/tcp on 212.174.188.50
  5708. Discovered open port 38957/tcp on 212.174.188.50
  5709. Discovered open port 47796/tcp on 212.174.188.50
  5710. Discovered open port 56976/tcp on 212.174.188.50
  5711. Discovered open port 47766/tcp on 212.174.188.50
  5712. Discovered open port 25365/tcp on 212.174.188.50
  5713. Increasing send delay for 212.174.188.50 from 0 to 5 due to 32 out of 106 dropped probes since last increase.
  5714. Discovered open port 45430/tcp on 212.174.188.50
  5715. Discovered open port 21697/tcp on 212.174.188.50
  5716. Discovered open port 64833/tcp on 212.174.188.50
  5717. Discovered open port 7220/tcp on 212.174.188.50
  5718. Discovered open port 64396/tcp on 212.174.188.50
  5719. Discovered open port 61166/tcp on 212.174.188.50
  5720. Discovered open port 30285/tcp on 212.174.188.50
  5721. Discovered open port 29674/tcp on 212.174.188.50
  5722. Discovered open port 26048/tcp on 212.174.188.50
  5723. Discovered open port 38397/tcp on 212.174.188.50
  5724. Discovered open port 44428/tcp on 212.174.188.50
  5725. Discovered open port 49996/tcp on 212.174.188.50
  5726. Discovered open port 46979/tcp on 212.174.188.50
  5727. Discovered open port 63352/tcp on 212.174.188.50
  5728. Discovered open port 27991/tcp on 212.174.188.50
  5729. Discovered open port 14570/tcp on 212.174.188.50
  5730. Discovered open port 41727/tcp on 212.174.188.50
  5731. Discovered open port 46427/tcp on 212.174.188.50
  5732. Discovered open port 36363/tcp on 212.174.188.50
  5733. Discovered open port 35394/tcp on 212.174.188.50
  5734. Discovered open port 15044/tcp on 212.174.188.50
  5735. Discovered open port 42400/tcp on 212.174.188.50
  5736. Discovered open port 36130/tcp on 212.174.188.50
  5737. Discovered open port 13412/tcp on 212.174.188.50
  5738. Discovered open port 18372/tcp on 212.174.188.50
  5739. Discovered open port 60595/tcp on 212.174.188.50
  5740. Discovered open port 32835/tcp on 212.174.188.50
  5741. Discovered open port 58529/tcp on 212.174.188.50
  5742. Discovered open port 6830/tcp on 212.174.188.50
  5743. Discovered open port 18497/tcp on 212.174.188.50
  5744. Discovered open port 36382/tcp on 212.174.188.50
  5745. Discovered open port 7048/tcp on 212.174.188.50
  5746. Discovered open port 36436/tcp on 212.174.188.50
  5747. Discovered open port 65116/tcp on 212.174.188.50
  5748. Discovered open port 54461/tcp on 212.174.188.50
  5749. Discovered open port 59477/tcp on 212.174.188.50
  5750. Discovered open port 22743/tcp on 212.174.188.50
  5751. Discovered open port 13728/tcp on 212.174.188.50
  5752. Discovered open port 45764/tcp on 212.174.188.50
  5753. Discovered open port 48954/tcp on 212.174.188.50
  5754. Discovered open port 53801/tcp on 212.174.188.50
  5755. Discovered open port 36515/tcp on 212.174.188.50
  5756. Discovered open port 14339/tcp on 212.174.188.50
  5757. Discovered open port 11494/tcp on 212.174.188.50
  5758. Discovered open port 24618/tcp on 212.174.188.50
  5759. Discovered open port 23170/tcp on 212.174.188.50
  5760. Discovered open port 27110/tcp on 212.174.188.50
  5761. Discovered open port 33437/tcp on 212.174.188.50
  5762. Discovered open port 9177/tcp on 212.174.188.50
  5763. Discovered open port 26346/tcp on 212.174.188.50
  5764. Discovered open port 64592/tcp on 212.174.188.50
  5765. Discovered open port 4884/tcp on 212.174.188.50
  5766. Discovered open port 42870/tcp on 212.174.188.50
  5767. Discovered open port 60686/tcp on 212.174.188.50
  5768. Discovered open port 4300/tcp on 212.174.188.50
  5769. Discovered open port 64752/tcp on 212.174.188.50
  5770. Discovered open port 61904/tcp on 212.174.188.50
  5771. Discovered open port 32719/tcp on 212.174.188.50
  5772. Discovered open port 49622/tcp on 212.174.188.50
  5773. Discovered open port 22019/tcp on 212.174.188.50
  5774. Discovered open port 48008/tcp on 212.174.188.50
  5775. Discovered open port 61161/tcp on 212.174.188.50
  5776. Discovered open port 58350/tcp on 212.174.188.50
  5777. Discovered open port 45874/tcp on 212.174.188.50
  5778. Discovered open port 18982/tcp on 212.174.188.50
  5779. Discovered open port 28970/tcp on 212.174.188.50
  5780. Discovered open port 45305/tcp on 212.174.188.50
  5781. Discovered open port 33107/tcp on 212.174.188.50
  5782. Discovered open port 19885/tcp on 212.174.188.50
  5783. Discovered open port 61830/tcp on 212.174.188.50
  5784. Discovered open port 47227/tcp on 212.174.188.50
  5785. Discovered open port 49013/tcp on 212.174.188.50
  5786. Discovered open port 45313/tcp on 212.174.188.50
  5787. Discovered open port 32942/tcp on 212.174.188.50
  5788. Discovered open port 29097/tcp on 212.174.188.50
  5789. Discovered open port 17984/tcp on 212.174.188.50
  5790. Discovered open port 37813/tcp on 212.174.188.50
  5791. Discovered open port 45795/tcp on 212.174.188.50
  5792. Discovered open port 55788/tcp on 212.174.188.50
  5793. Discovered open port 46707/tcp on 212.174.188.50
  5794. Discovered open port 48194/tcp on 212.174.188.50
  5795. Discovered open port 63785/tcp on 212.174.188.50
  5796. Discovered open port 14725/tcp on 212.174.188.50
  5797. Discovered open port 11958/tcp on 212.174.188.50
  5798. Discovered open port 22672/tcp on 212.174.188.50
  5799. Discovered open port 64707/tcp on 212.174.188.50
  5800. Discovered open port 26586/tcp on 212.174.188.50
  5801. Discovered open port 44838/tcp on 212.174.188.50
  5802. Discovered open port 23731/tcp on 212.174.188.50
  5803. Discovered open port 30034/tcp on 212.174.188.50
  5804. Discovered open port 60146/tcp on 212.174.188.50
  5805. Discovered open port 46449/tcp on 212.174.188.50
  5806. Discovered open port 19566/tcp on 212.174.188.50
  5807. Discovered open port 39062/tcp on 212.174.188.50
  5808. Discovered open port 61557/tcp on 212.174.188.50
  5809. Discovered open port 145/tcp on 212.174.188.50
  5810. Discovered open port 50111/tcp on 212.174.188.50
  5811. SYN Stealth Scan Timing: About 17.80% done; ETC: 23:57 (0:07:00 remaining)
  5812. SYN Stealth Scan Timing: About 20.00% done; ETC: 23:59 (0:08:04 remaining)
  5813. SYN Stealth Scan Timing: About 22.21% done; ETC: 00:00 (0:08:49 remaining)
  5814. SYN Stealth Scan Timing: About 24.86% done; ETC: 00:01 (0:09:25 remaining)
  5815. SYN Stealth Scan Timing: About 28.57% done; ETC: 00:03 (0:10:03 remaining)
  5816. SYN Stealth Scan Timing: About 46.35% done; ETC: 00:06 (0:09:20 remaining)
  5817. SYN Stealth Scan Timing: About 53.23% done; ETC: 00:07 (0:08:27 remaining)
  5818. SYN Stealth Scan Timing: About 59.42% done; ETC: 00:07 (0:07:31 remaining)
  5819. SYN Stealth Scan Timing: About 65.25% done; ETC: 00:08 (0:06:35 remaining)
  5820. SYN Stealth Scan Timing: About 70.90% done; ETC: 00:08 (0:05:37 remaining)
  5821. SYN Stealth Scan Timing: About 76.36% done; ETC: 00:08 (0:04:37 remaining)
  5822. SYN Stealth Scan Timing: About 81.66% done; ETC: 00:08 (0:03:37 remaining)
  5823. SYN Stealth Scan Timing: About 86.91% done; ETC: 00:09 (0:02:37 remaining)
  5824. SYN Stealth Scan Timing: About 92.08% done; ETC: 00:09 (0:01:36 remaining)
  5825. SYN Stealth Scan Timing: About 97.12% done; ETC: 00:09 (0:00:35 remaining)
  5826. Completed SYN Stealth Scan at 00:09, 1220.59s elapsed (65535 total ports)
  5827. Initiating Service scan at 00:09
  5828. Scanning 147 services on 212.174.188.50
  5829. Completed Service scan at 00:10, 40.02s elapsed (147 services on 1 host)
  5830. Initiating OS detection (try #1) against 212.174.188.50
  5831. Retrying OS detection (try #2) against 212.174.188.50
  5832. Initiating Traceroute at 00:10
  5833. Completed Traceroute at 00:10, 0.13s elapsed
  5834. Initiating Parallel DNS resolution of 2 hosts. at 00:10
  5835. Completed Parallel DNS resolution of 2 hosts. at 00:10, 6.08s elapsed
  5836. NSE: Script scanning 212.174.188.50.
  5837. Initiating NSE at 00:10
  5838. Completed NSE at 00:10, 12.95s elapsed
  5839. Initiating NSE at 00:10
  5840. Completed NSE at 00:10, 2.46s elapsed
  5841. Nmap scan report for 212.174.188.50
  5842. Host is up (0.100s latency).
  5843. Not shown: 65385 filtered ports
  5844. PORT STATE SERVICE VERSION
  5845. 25/tcp closed smtp
  5846. 80/tcp open http nginx
  5847. | vulscan: VulDB - https://vuldb.com:
  5848. | [133852] Sangfor Sundray WLAN Controller up to 3.7.4.2 Cookie Header nginx_webconsole.php Code Execution
  5849. | [132132] SoftNAS Cloud 4.2.0/4.2.1 Nginx privilege escalation
  5850. | [131858] Puppet Discovery up to 1.3.x Nginx Container weak authentication
  5851. | [130644] Nginx Unit up to 1.7.0 Router Process Request Heap-based memory corruption
  5852. | [127759] VeryNginx 0.3.3 Web Application Firewall privilege escalation
  5853. | [126525] nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
  5854. | [126524] nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
  5855. | [126523] nginx up to 1.14.0/1.15.5 HTTP2 Memory Consumption denial of service
  5856. | [119845] Pivotal Operations Manager up to 2.0.13/2.1.5 Nginx privilege escalation
  5857. | [114368] SuSE Portus 2.3 Nginx Certificate weak authentication
  5858. | [103517] nginx up to 1.13.2 Range Filter Request Integer Overflow memory corruption
  5859. | [89849] nginx RFC 3875 Namespace Conflict Environment Variable Open Redirect
  5860. | [87719] nginx up to 1.11.0 ngx_files.c ngx_chain_to_iovec denial of service
  5861. | [80760] nginx 0.6.18/1.9.9 DNS CNAME Record Crash denial of service
  5862. | [80759] nginx 0.6.18/1.9.9 DNS CNAME Record Use-After-Free denial of service
  5863. | [80758] nginx 0.6.18/1.9.9 DNS UDP Packet Crash denial of service
  5864. | [67677] nginx up to 1.7.3 SSL weak authentication
  5865. | [67296] nginx up to 1.7.3 SMTP Proxy ngx_mail_smtp_starttls privilege escalation
  5866. | [12822] nginx up to 1.5.11 SPDY SPDY Request Heap-based memory corruption
  5867. | [12824] nginx 1.5.10 on 32-bit SPDY memory corruption
  5868. | [11237] nginx up to 1.5.6 URI String Bypass privilege escalation
  5869. | [65364] nginx up to 1.1.13 Default Configuration information disclosure
  5870. | [8671] nginx up to 1.4 proxy_pass denial of service
  5871. | [8618] nginx 1.3.9/1.4.0 http/ngx_http_parse.c ngx_http_parse_chunked() memory corruption
  5872. | [7247] nginx 1.2.6 Proxy Function spoofing
  5873. | [61434] nginx 1.2.0/1.3.0 on Windows Access Restriction privilege escalation
  5874. | [5293] nginx up to 1.1.18 ngx_http_mp4_module MP4 File memory corruption
  5875. | [4843] nginx up to 1.0.13/1.1.16 HTTP Header Response Parser ngx_http_parse.c information disclosure
  5876. | [59645] nginx up to 0.8.9 Heap-based memory corruption
  5877. | [53592] nginx 0.8.36 memory corruption
  5878. | [53590] nginx up to 0.8.9 unknown vulnerability
  5879. | [51533] nginx 0.7.64 Terminal privilege escalation
  5880. | [50905] nginx up to 0.8.9 directory traversal
  5881. | [50903] nginx up to 0.8.10 NULL Pointer Dereference denial of service
  5882. | [50043] nginx up to 0.8.10 memory corruption
  5883. |
  5884. | MITRE CVE - https://cve.mitre.org:
  5885. | [CVE-2013-2070] http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
  5886. | [CVE-2013-2028] The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
  5887. | [CVE-2012-3380] Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
  5888. | [CVE-2012-2089] Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
  5889. | [CVE-2012-1180] Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
  5890. | [CVE-2011-4963] nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
  5891. | [CVE-2011-4315] Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
  5892. | [CVE-2010-2266] nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
  5893. | [CVE-2010-2263] nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
  5894. | [CVE-2009-4487] nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
  5895. | [CVE-2009-3898] Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
  5896. | [CVE-2009-3896] src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.
  5897. | [CVE-2009-2629] Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
  5898. |
  5899. | SecurityFocus - https://www.securityfocus.com/bid/:
  5900. | [99534] Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
  5901. | [93903] Nginx CVE-2016-1247 Remote Privilege Escalation Vulnerability
  5902. | [91819] Nginx CVE-2016-1000105 Security Bypass Vulnerability
  5903. | [90967] nginx CVE-2016-4450 Denial of Service Vulnerability
  5904. | [82230] nginx Multiple Denial of Service Vulnerabilities
  5905. | [78928] Nginx CVE-2010-2266 Denial-Of-Service Vulnerability
  5906. | [70025] nginx CVE-2014-3616 SSL Session Fixation Vulnerability
  5907. | [69111] nginx SMTP Proxy Remote Command Injection Vulnerability
  5908. | [67507] nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
  5909. | [66537] nginx SPDY Implementation Heap Based Buffer Overflow Vulnerability
  5910. | [63814] nginx CVE-2013-4547 URI Processing Security Bypass Vulnerability
  5911. | [59824] Nginx CVE-2013-2070 Remote Security Vulnerability
  5912. | [59699] nginx 'ngx_http_parse.c' Stack Buffer Overflow Vulnerability
  5913. | [59496] nginx 'ngx_http_close_connection()' Remote Integer Overflow Vulnerability
  5914. | [59323] nginx NULL-Byte Arbitrary Code Execution Vulnerability
  5915. | [58105] Nginx 'access.log' Insecure File Permissions Vulnerability
  5916. | [57139] nginx CVE-2011-4968 Man in The Middle Vulnerability
  5917. | [55920] nginx CVE-2011-4963 Security Bypass Vulnerability
  5918. | [54331] Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
  5919. | [52999] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  5920. | [52578] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  5921. | [50710] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  5922. | [40760] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  5923. | [40434] nginx Space String Remote Source Code Disclosure Vulnerability
  5924. | [40420] nginx Directory Traversal Vulnerability
  5925. | [37711] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  5926. | [36839] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  5927. | [36490] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  5928. | [36438] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  5929. | [36384] nginx HTTP Request Remote Buffer Overflow Vulnerability
  5930. |
  5931. | IBM X-Force - https://exchange.xforce.ibmcloud.com:
  5932. | [84623] Phusion Passenger gem for Ruby with nginx configuration insecure permissions
  5933. | [84172] nginx denial of service
  5934. | [84048] nginx buffer overflow
  5935. | [83923] nginx ngx_http_close_connection() integer overflow
  5936. | [83688] nginx null byte code execution
  5937. | [83103] Naxsi module for Nginx naxsi_unescape_uri() function security bypass
  5938. | [82319] nginx access.log information disclosure
  5939. | [80952] nginx SSL spoofing
  5940. | [77244] nginx and Microsoft Windows request security bypass
  5941. | [76778] Naxsi module for Nginx nx_extract.py directory traversal
  5942. | [74831] nginx ngx_http_mp4_module.c buffer overflow
  5943. | [74191] nginx ngx_cpystrn() information disclosure
  5944. | [74045] nginx header response information disclosure
  5945. | [71355] nginx ngx_resolver_copy() buffer overflow
  5946. | [59370] nginx characters denial of service
  5947. | [59369] nginx DATA source code disclosure
  5948. | [59047] nginx space source code disclosure
  5949. | [58966] nginx unspecified directory traversal
  5950. | [54025] nginx ngx_http_parse.c denial of service
  5951. | [53431] nginx WebDAV component directory traversal
  5952. | [53328] Nginx CRC-32 cached domain name spoofing
  5953. | [53250] Nginx ngx_http_parse_complex_uri() function code execution
  5954. |
  5955. | Exploit-DB - https://www.exploit-db.com:
  5956. | [26737] nginx 1.3.9/1.4.0 x86 Brute Force Remote Exploit
  5957. | [25775] Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow
  5958. | [25499] nginx 1.3.9-1.4.0 DoS PoC
  5959. | [24967] nginx 0.6.x Arbitrary Code Execution NullByte Injection
  5960. | [14830] nginx 0.6.38 - Heap Corruption Exploit
  5961. | [13822] Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability
  5962. | [13818] Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities
  5963. | [12804] nginx [engine x] http server <= 0.6.36 Path Draversal
  5964. | [9901] nginx 0.7.0-0.7.61, 0.6.0-0.6.38, 0.5.0-0.5.37, 0.4.0-0.4.14 PoC
  5965. | [9829] nginx 0.7.61 WebDAV directory traversal
  5966. |
  5967. | OpenVAS (Nessus) - http://www.openvas.org:
  5968. | [864418] Fedora Update for nginx FEDORA-2012-3846
  5969. | [864310] Fedora Update for nginx FEDORA-2012-6238
  5970. | [864209] Fedora Update for nginx FEDORA-2012-6411
  5971. | [864204] Fedora Update for nginx FEDORA-2012-6371
  5972. | [864121] Fedora Update for nginx FEDORA-2012-4006
  5973. | [864115] Fedora Update for nginx FEDORA-2012-3991
  5974. | [864065] Fedora Update for nginx FEDORA-2011-16075
  5975. | [863654] Fedora Update for nginx FEDORA-2011-16110
  5976. | [861232] Fedora Update for nginx FEDORA-2007-1158
  5977. | [850180] SuSE Update for nginx openSUSE-SU-2012:0237-1 (nginx)
  5978. | [831680] Mandriva Update for nginx MDVSA-2012:043 (nginx)
  5979. | [802045] 64-bit Debian Linux Rootkit with nginx Doing iFrame Injection
  5980. | [801636] nginx HTTP Request Remote Buffer Overflow Vulnerability
  5981. | [103470] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  5982. | [103469] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  5983. | [103344] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  5984. | [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  5985. | [100659] nginx Directory Traversal Vulnerability
  5986. | [100658] nginx Space String Remote Source Code Disclosure Vulnerability
  5987. | [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  5988. | [100321] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  5989. | [100277] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  5990. | [100276] nginx HTTP Request Remote Buffer Overflow Vulnerability
  5991. | [100275] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  5992. | [71574] Gentoo Security Advisory GLSA 201206-07 (nginx)
  5993. | [71308] Gentoo Security Advisory GLSA 201203-22 (nginx)
  5994. | [71297] FreeBSD Ports: nginx
  5995. | [71276] FreeBSD Ports: nginx
  5996. | [71239] Debian Security Advisory DSA 2434-1 (nginx)
  5997. | [66451] Fedora Core 11 FEDORA-2009-12782 (nginx)
  5998. | [66450] Fedora Core 10 FEDORA-2009-12775 (nginx)
  5999. | [66449] Fedora Core 12 FEDORA-2009-12750 (nginx)
  6000. | [64924] Gentoo Security Advisory GLSA 200909-18 (nginx)
  6001. | [64912] Fedora Core 10 FEDORA-2009-9652 (nginx)
  6002. | [64911] Fedora Core 11 FEDORA-2009-9630 (nginx)
  6003. | [64894] FreeBSD Ports: nginx
  6004. | [64869] Debian Security Advisory DSA 1884-1 (nginx)
  6005. |
  6006. | SecurityTracker - https://www.securitytracker.com:
  6007. | [1028544] nginx Bug Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
  6008. | [1028519] nginx Stack Overflow Lets Remote Users Execute Arbitrary Code
  6009. | [1026924] nginx Buffer Overflow in ngx_http_mp4_module Lets Remote Users Execute Arbitrary Code
  6010. | [1026827] nginx HTTP Response Processing Lets Remote Users Obtain Portions of Memory Contents
  6011. |
  6012. | OSVDB - http://www.osvdb.org:
  6013. | [94864] cPnginx Plugin for cPanel nginx Configuration Manipulation Arbitrary File Access
  6014. | [93282] nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
  6015. | [93037] nginx /http/ngx_http_parse.c Worker Process Crafted Request Handling Remote Overflow
  6016. | [92796] nginx ngx_http_close_connection Function Crafted r-&gt
  6017. | [92634] nginx ngx_http_request.h zero_in_uri URL Null Byte Handling Remote Code Execution
  6018. | [90518] nginx Log Directory Permission Weakness Local Information Disclosure
  6019. | [88910] nginx Proxy Functionality SSL Certificate Validation MitM Spoofing Weakness
  6020. | [84339] nginx/Windows Multiple Request Sequence Parsing Arbitrary File Access
  6021. | [83617] Naxsi Module for Nginx naxsi-ui/ nx_extract.py Traversal Arbitrary File Access
  6022. | [81339] nginx ngx_http_mp4_module Module Atom MP4 File Handling Remote Overflow
  6023. | [80124] nginx HTTP Header Response Parsing Freed Memory Information Disclosure
  6024. | [77184] nginx ngx_resolver.c ngx_resolver_copy() Function DNS Response Parsing Remote Overflow
  6025. | [65531] nginx on Windows URI ::$DATA Append Arbitrary File Access
  6026. | [65530] nginx Encoded Traversal Sequence Memory Corruption Remote DoS
  6027. | [65294] nginx on Windows Encoded Space Request Remote Source Disclosure
  6028. | [63136] nginx on Windows 8.3 Filename Alias Request Access Rules / Authentication Bypass
  6029. | [62617] nginx Internal DNS Cache Poisoning Weakness
  6030. | [61779] nginx HTTP Request Escape Sequence Terminal Command Injection
  6031. | [59278] nginx src/http/ngx_http_parse.c ngx_http_process_request_headers() Function URL Handling NULL Dereference DoS
  6032. | [58328] nginx WebDAV Multiple Method Traversal Arbitrary File Write
  6033. | [58128] nginx ngx_http_parse_complex_uri() Function Underflow
  6034. | [44447] nginx (engine x) msie_refresh Directive Unspecified XSS
  6035. | [44446] nginx (engine x) ssl_verify_client Directive HTTP/0.9 Protocol Bypass
  6036. | [44445] nginx (engine x) ngx_http_realip_module satisfy_any Directive Unspecified Access Bypass
  6037. | [44444] nginx (engine x) X-Accel-Redirect Header Unspecified Traversal
  6038. | [44443] nginx (engine x) rtsig Method Signal Queue Overflow
  6039. | [44442] nginx (engine x) Worker Process Millisecond Timers Unspecified Overflow
  6040. |_
  6041. 139/tcp closed netbios-ssn
  6042. 145/tcp open tcpwrapped
  6043. 443/tcp open ssl/http nginx
  6044. | vulscan: VulDB - https://vuldb.com:
  6045. | [133852] Sangfor Sundray WLAN Controller up to 3.7.4.2 Cookie Header nginx_webconsole.php Code Execution
  6046. | [132132] SoftNAS Cloud 4.2.0/4.2.1 Nginx privilege escalation
  6047. | [131858] Puppet Discovery up to 1.3.x Nginx Container weak authentication
  6048. | [130644] Nginx Unit up to 1.7.0 Router Process Request Heap-based memory corruption
  6049. | [127759] VeryNginx 0.3.3 Web Application Firewall privilege escalation
  6050. | [126525] nginx up to 1.14.0/1.15.5 ngx_http_mp4_module Loop denial of service
  6051. | [126524] nginx up to 1.14.0/1.15.5 HTTP2 CPU Exhaustion denial of service
  6052. | [126523] nginx up to 1.14.0/1.15.5 HTTP2 Memory Consumption denial of service
  6053. | [119845] Pivotal Operations Manager up to 2.0.13/2.1.5 Nginx privilege escalation
  6054. | [114368] SuSE Portus 2.3 Nginx Certificate weak authentication
  6055. | [103517] nginx up to 1.13.2 Range Filter Request Integer Overflow memory corruption
  6056. | [89849] nginx RFC 3875 Namespace Conflict Environment Variable Open Redirect
  6057. | [87719] nginx up to 1.11.0 ngx_files.c ngx_chain_to_iovec denial of service
  6058. | [80760] nginx 0.6.18/1.9.9 DNS CNAME Record Crash denial of service
  6059. | [80759] nginx 0.6.18/1.9.9 DNS CNAME Record Use-After-Free denial of service
  6060. | [80758] nginx 0.6.18/1.9.9 DNS UDP Packet Crash denial of service
  6061. | [67677] nginx up to 1.7.3 SSL weak authentication
  6062. | [67296] nginx up to 1.7.3 SMTP Proxy ngx_mail_smtp_starttls privilege escalation
  6063. | [12822] nginx up to 1.5.11 SPDY SPDY Request Heap-based memory corruption
  6064. | [12824] nginx 1.5.10 on 32-bit SPDY memory corruption
  6065. | [11237] nginx up to 1.5.6 URI String Bypass privilege escalation
  6066. | [65364] nginx up to 1.1.13 Default Configuration information disclosure
  6067. | [8671] nginx up to 1.4 proxy_pass denial of service
  6068. | [8618] nginx 1.3.9/1.4.0 http/ngx_http_parse.c ngx_http_parse_chunked() memory corruption
  6069. | [7247] nginx 1.2.6 Proxy Function spoofing
  6070. | [61434] nginx 1.2.0/1.3.0 on Windows Access Restriction privilege escalation
  6071. | [5293] nginx up to 1.1.18 ngx_http_mp4_module MP4 File memory corruption
  6072. | [4843] nginx up to 1.0.13/1.1.16 HTTP Header Response Parser ngx_http_parse.c information disclosure
  6073. | [59645] nginx up to 0.8.9 Heap-based memory corruption
  6074. | [53592] nginx 0.8.36 memory corruption
  6075. | [53590] nginx up to 0.8.9 unknown vulnerability
  6076. | [51533] nginx 0.7.64 Terminal privilege escalation
  6077. | [50905] nginx up to 0.8.9 directory traversal
  6078. | [50903] nginx up to 0.8.10 NULL Pointer Dereference denial of service
  6079. | [50043] nginx up to 0.8.10 memory corruption
  6080. |
  6081. | MITRE CVE - https://cve.mitre.org:
  6082. | [CVE-2013-2070] http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
  6083. | [CVE-2013-2028] The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
  6084. | [CVE-2012-3380] Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
  6085. | [CVE-2012-2089] Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.
  6086. | [CVE-2012-1180] Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
  6087. | [CVE-2011-4963] nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.
  6088. | [CVE-2011-4315] Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
  6089. | [CVE-2010-2266] nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
  6090. | [CVE-2010-2263] nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.
  6091. | [CVE-2009-4487] nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
  6092. | [CVE-2009-3898] Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.
  6093. | [CVE-2009-3896] src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.
  6094. | [CVE-2009-2629] Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
  6095. |
  6096. | SecurityFocus - https://www.securityfocus.com/bid/:
  6097. | [99534] Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
  6098. | [93903] Nginx CVE-2016-1247 Remote Privilege Escalation Vulnerability
  6099. | [91819] Nginx CVE-2016-1000105 Security Bypass Vulnerability
  6100. | [90967] nginx CVE-2016-4450 Denial of Service Vulnerability
  6101. | [82230] nginx Multiple Denial of Service Vulnerabilities
  6102. | [78928] Nginx CVE-2010-2266 Denial-Of-Service Vulnerability
  6103. | [70025] nginx CVE-2014-3616 SSL Session Fixation Vulnerability
  6104. | [69111] nginx SMTP Proxy Remote Command Injection Vulnerability
  6105. | [67507] nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
  6106. | [66537] nginx SPDY Implementation Heap Based Buffer Overflow Vulnerability
  6107. | [63814] nginx CVE-2013-4547 URI Processing Security Bypass Vulnerability
  6108. | [59824] Nginx CVE-2013-2070 Remote Security Vulnerability
  6109. | [59699] nginx 'ngx_http_parse.c' Stack Buffer Overflow Vulnerability
  6110. | [59496] nginx 'ngx_http_close_connection()' Remote Integer Overflow Vulnerability
  6111. | [59323] nginx NULL-Byte Arbitrary Code Execution Vulnerability
  6112. | [58105] Nginx 'access.log' Insecure File Permissions Vulnerability
  6113. | [57139] nginx CVE-2011-4968 Man in The Middle Vulnerability
  6114. | [55920] nginx CVE-2011-4963 Security Bypass Vulnerability
  6115. | [54331] Nginx Naxsi Module 'nx_extract.py' Script Remote File Disclosure Vulnerability
  6116. | [52999] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  6117. | [52578] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  6118. | [50710] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  6119. | [40760] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  6120. | [40434] nginx Space String Remote Source Code Disclosure Vulnerability
  6121. | [40420] nginx Directory Traversal Vulnerability
  6122. | [37711] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  6123. | [36839] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  6124. | [36490] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  6125. | [36438] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  6126. | [36384] nginx HTTP Request Remote Buffer Overflow Vulnerability
  6127. |
  6128. | IBM X-Force - https://exchange.xforce.ibmcloud.com:
  6129. | [84623] Phusion Passenger gem for Ruby with nginx configuration insecure permissions
  6130. | [84172] nginx denial of service
  6131. | [84048] nginx buffer overflow
  6132. | [83923] nginx ngx_http_close_connection() integer overflow
  6133. | [83688] nginx null byte code execution
  6134. | [83103] Naxsi module for Nginx naxsi_unescape_uri() function security bypass
  6135. | [82319] nginx access.log information disclosure
  6136. | [80952] nginx SSL spoofing
  6137. | [77244] nginx and Microsoft Windows request security bypass
  6138. | [76778] Naxsi module for Nginx nx_extract.py directory traversal
  6139. | [74831] nginx ngx_http_mp4_module.c buffer overflow
  6140. | [74191] nginx ngx_cpystrn() information disclosure
  6141. | [74045] nginx header response information disclosure
  6142. | [71355] nginx ngx_resolver_copy() buffer overflow
  6143. | [59370] nginx characters denial of service
  6144. | [59369] nginx DATA source code disclosure
  6145. | [59047] nginx space source code disclosure
  6146. | [58966] nginx unspecified directory traversal
  6147. | [54025] nginx ngx_http_parse.c denial of service
  6148. | [53431] nginx WebDAV component directory traversal
  6149. | [53328] Nginx CRC-32 cached domain name spoofing
  6150. | [53250] Nginx ngx_http_parse_complex_uri() function code execution
  6151. |
  6152. | Exploit-DB - https://www.exploit-db.com:
  6153. | [26737] nginx 1.3.9/1.4.0 x86 Brute Force Remote Exploit
  6154. | [25775] Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow
  6155. | [25499] nginx 1.3.9-1.4.0 DoS PoC
  6156. | [24967] nginx 0.6.x Arbitrary Code Execution NullByte Injection
  6157. | [14830] nginx 0.6.38 - Heap Corruption Exploit
  6158. | [13822] Nginx <= 0.7.65 / 0.8.39 (dev) Source Disclosure / Download Vulnerability
  6159. | [13818] Nginx 0.8.36 Source Disclosure and DoS Vulnerabilities
  6160. | [12804] nginx [engine x] http server <= 0.6.36 Path Draversal
  6161. | [9901] nginx 0.7.0-0.7.61, 0.6.0-0.6.38, 0.5.0-0.5.37, 0.4.0-0.4.14 PoC
  6162. | [9829] nginx 0.7.61 WebDAV directory traversal
  6163. |
  6164. | OpenVAS (Nessus) - http://www.openvas.org:
  6165. | [864418] Fedora Update for nginx FEDORA-2012-3846
  6166. | [864310] Fedora Update for nginx FEDORA-2012-6238
  6167. | [864209] Fedora Update for nginx FEDORA-2012-6411
  6168. | [864204] Fedora Update for nginx FEDORA-2012-6371
  6169. | [864121] Fedora Update for nginx FEDORA-2012-4006
  6170. | [864115] Fedora Update for nginx FEDORA-2012-3991
  6171. | [864065] Fedora Update for nginx FEDORA-2011-16075
  6172. | [863654] Fedora Update for nginx FEDORA-2011-16110
  6173. | [861232] Fedora Update for nginx FEDORA-2007-1158
  6174. | [850180] SuSE Update for nginx openSUSE-SU-2012:0237-1 (nginx)
  6175. | [831680] Mandriva Update for nginx MDVSA-2012:043 (nginx)
  6176. | [802045] 64-bit Debian Linux Rootkit with nginx Doing iFrame Injection
  6177. | [801636] nginx HTTP Request Remote Buffer Overflow Vulnerability
  6178. | [103470] nginx 'ngx_http_mp4_module.c' Buffer Overflow Vulnerability
  6179. | [103469] nginx 'ngx_cpystrn()' Information Disclosure Vulnerability
  6180. | [103344] nginx DNS Resolver Remote Heap Buffer Overflow Vulnerability
  6181. | [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
  6182. | [100659] nginx Directory Traversal Vulnerability
  6183. | [100658] nginx Space String Remote Source Code Disclosure Vulnerability
  6184. | [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
  6185. | [100321] nginx 'ngx_http_process_request_headers()' Remote Buffer Overflow Vulnerability
  6186. | [100277] nginx Proxy DNS Cache Domain Spoofing Vulnerability
  6187. | [100276] nginx HTTP Request Remote Buffer Overflow Vulnerability
  6188. | [100275] nginx WebDAV Multiple Directory Traversal Vulnerabilities
  6189. | [71574] Gentoo Security Advisory GLSA 201206-07 (nginx)
  6190. | [71308] Gentoo Security Advisory GLSA 201203-22 (nginx)
  6191. | [71297] FreeBSD Ports: nginx
  6192. | [71276] FreeBSD Ports: nginx
  6193. | [71239] Debian Security Advisory DSA 2434-1 (nginx)
  6194. | [66451] Fedora Core 11 FEDORA-2009-12782 (nginx)
  6195. | [66450] Fedora Core 10 FEDORA-2009-12775 (nginx)
  6196. | [66449] Fedora Core 12 FEDORA-2009-12750 (nginx)
  6197. | [64924] Gentoo Security Advisory GLSA 200909-18 (nginx)
  6198. | [64912] Fedora Core 10 FEDORA-2009-9652 (nginx)
  6199. | [64911] Fedora Core 11 FEDORA-2009-9630 (nginx)
  6200. | [64894] FreeBSD Ports: nginx
  6201. | [64869] Debian Security Advisory DSA 1884-1 (nginx)
  6202. |
  6203. | SecurityTracker - https://www.securitytracker.com:
  6204. | [1028544] nginx Bug Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
  6205. | [1028519] nginx Stack Overflow Lets Remote Users Execute Arbitrary Code
  6206. | [1026924] nginx Buffer Overflow in ngx_http_mp4_module Lets Remote Users Execute Arbitrary Code
  6207. | [1026827] nginx HTTP Response Processing Lets Remote Users Obtain Portions of Memory Contents
  6208. |
  6209. | OSVDB - http://www.osvdb.org:
  6210. | [94864] cPnginx Plugin for cPanel nginx Configuration Manipulation Arbitrary File Access
  6211. | [93282] nginx proxy_pass Crafted Upstream Proxied Server Response Handling Worker Process Memory Disclosure
  6212. | [93037] nginx /http/ngx_http_parse.c Worker Process Crafted Request Handling Remote Overflow
  6213. | [92796] nginx ngx_http_close_connection Function Crafted r-&gt
  6214. | [92634] nginx ngx_http_request.h zero_in_uri URL Null Byte Handling Remote Code Execution
  6215. | [90518] nginx Log Directory Permission Weakness Local Information Disclosure
  6216. | [88910] nginx Proxy Functionality SSL Certificate Validation MitM Spoofing Weakness
  6217. | [84339] nginx/Windows Multiple Request Sequence Parsing Arbitrary File Access
  6218. | [83617] Naxsi Module for Nginx naxsi-ui/ nx_extract.py Traversal Arbitrary File Access
  6219. | [81339] nginx ngx_http_mp4_module Module Atom MP4 File Handling Remote Overflow
  6220. | [80124] nginx HTTP Header Response Parsing Freed Memory Information Disclosure
  6221. | [77184] nginx ngx_resolver.c ngx_resolver_copy() Function DNS Response Parsing Remote Overflow
  6222. | [65531] nginx on Windows URI ::$DATA Append Arbitrary File Access
  6223. | [65530] nginx Encoded Traversal Sequence Memory Corruption Remote DoS
  6224. | [65294] nginx on Windows Encoded Space Request Remote Source Disclosure
  6225. | [63136] nginx on Windows 8.3 Filename Alias Request Access Rules / Authentication Bypass
  6226. | [62617] nginx Internal DNS Cache Poisoning Weakness
  6227. | [61779] nginx HTTP Request Escape Sequence Terminal Command Injection
  6228. | [59278] nginx src/http/ngx_http_parse.c ngx_http_process_request_headers() Function URL Handling NULL Dereference DoS
  6229. | [58328] nginx WebDAV Multiple Method Traversal Arbitrary File Write
  6230. | [58128] nginx ngx_http_parse_complex_uri() Function Underflow
  6231. | [44447] nginx (engine x) msie_refresh Directive Unspecified XSS
  6232. | [44446] nginx (engine x) ssl_verify_client Directive HTTP/0.9 Protocol Bypass
  6233. | [44445] nginx (engine x) ngx_http_realip_module satisfy_any Directive Unspecified Access Bypass
  6234. | [44444] nginx (engine x) X-Accel-Redirect Header Unspecified Traversal
  6235. | [44443] nginx (engine x) rtsig Method Signal Queue Overflow
  6236. | [44442] nginx (engine x) Worker Process Millisecond Timers Unspecified Overflow
  6237. |_
  6238. 445/tcp closed microsoft-ds
  6239. 1012/tcp open tcpwrapped
  6240. 1996/tcp open tcpwrapped
  6241. 2663/tcp open tcpwrapped
  6242. 4300/tcp open tcpwrapped
  6243. 4884/tcp open tcpwrapped
  6244. 6830/tcp open tcpwrapped
  6245. 7019/tcp open tcpwrapped
  6246. 7048/tcp open tcpwrapped
  6247. 7220/tcp open tcpwrapped
  6248. 7462/tcp open tcpwrapped
  6249. 9177/tcp open tcpwrapped
  6250. 10785/tcp open tcpwrapped
  6251. 11086/tcp open tcpwrapped
  6252. 11494/tcp open tcpwrapped
  6253. 11958/tcp open tcpwrapped
  6254. 13412/tcp open tcpwrapped
  6255. 13728/tcp open tcpwrapped
  6256. 14339/tcp open tcpwrapped
  6257. 14570/tcp open tcpwrapped
  6258. 14725/tcp open tcpwrapped
  6259. 14878/tcp open tcpwrapped
  6260. 15044/tcp open tcpwrapped
  6261. 15557/tcp open tcpwrapped
  6262. 15601/tcp open tcpwrapped
  6263. 15670/tcp open tcpwrapped
  6264. 17984/tcp open tcpwrapped
  6265. 18372/tcp open tcpwrapped
  6266. 18497/tcp open tcpwrapped
  6267. 18825/tcp open tcpwrapped
  6268. 18982/tcp open tcpwrapped
  6269. 18985/tcp open tcpwrapped
  6270. 19566/tcp open tcpwrapped
  6271. 19885/tcp open tcpwrapped
  6272. 20457/tcp open tcpwrapped
  6273. 21697/tcp open tcpwrapped
  6274. 22019/tcp open tcpwrapped
  6275. 22672/tcp open tcpwrapped
  6276. 22743/tcp open tcpwrapped
  6277. 23170/tcp open tcpwrapped
  6278. 23516/tcp open tcpwrapped
  6279. 23731/tcp open tcpwrapped
  6280. 24618/tcp open tcpwrapped
  6281. 24946/tcp open tcpwrapped
  6282. 25365/tcp open tcpwrapped
  6283. 26048/tcp open tcpwrapped
  6284. 26346/tcp open tcpwrapped
  6285. 26586/tcp open tcpwrapped
  6286. 27110/tcp open tcpwrapped
  6287. 27429/tcp open tcpwrapped
  6288. 27991/tcp open tcpwrapped
  6289. 28728/tcp open tcpwrapped
  6290. 28970/tcp open tcpwrapped
  6291. 29097/tcp open tcpwrapped
  6292. 29674/tcp open tcpwrapped
  6293. 30034/tcp open tcpwrapped
  6294. 30285/tcp open tcpwrapped
  6295. 30369/tcp open tcpwrapped
  6296. 32719/tcp open tcpwrapped
  6297. 32726/tcp open tcpwrapped
  6298. 32803/tcp open tcpwrapped
  6299. 32835/tcp open tcpwrapped
  6300. 32876/tcp open tcpwrapped
  6301. 32942/tcp open tcpwrapped
  6302. 33107/tcp open tcpwrapped
  6303. 33437/tcp open tcpwrapped
  6304. 33688/tcp open tcpwrapped
  6305. 33789/tcp open tcpwrapped
  6306. 35234/tcp open tcpwrapped
  6307. 35394/tcp open tcpwrapped
  6308. 35974/tcp open tcpwrapped
  6309. 36130/tcp open tcpwrapped
  6310. 36363/tcp open tcpwrapped
  6311. 36382/tcp open tcpwrapped
  6312. 36436/tcp open tcpwrapped
  6313. 36515/tcp open tcpwrapped
  6314. 37813/tcp open tcpwrapped
  6315. 38397/tcp open tcpwrapped
  6316. 38957/tcp open tcpwrapped
  6317. 39006/tcp open tcpwrapped
  6318. 39062/tcp open tcpwrapped
  6319. 41424/tcp open tcpwrapped
  6320. 41727/tcp open tcpwrapped
  6321. 42400/tcp open tcpwrapped
  6322. 42870/tcp open tcpwrapped
  6323. 43401/tcp open tcpwrapped
  6324. 44428/tcp open tcpwrapped
  6325. 44838/tcp open tcpwrapped
  6326. 45305/tcp open tcpwrapped
  6327. 45313/tcp open tcpwrapped
  6328. 45430/tcp open tcpwrapped
  6329. 45695/tcp open tcpwrapped
  6330. 45764/tcp open tcpwrapped
  6331. 45795/tcp open tcpwrapped
  6332. 45874/tcp open tcpwrapped
  6333. 46391/tcp open tcpwrapped
  6334. 46427/tcp open tcpwrapped
  6335. 46449/tcp open tcpwrapped
  6336. 46707/tcp open tcpwrapped
  6337. 46979/tcp open tcpwrapped
  6338. 46995/tcp open tcpwrapped
  6339. 47227/tcp open tcpwrapped
  6340. 47415/tcp open tcpwrapped
  6341. 47766/tcp open tcpwrapped
  6342. 47796/tcp open tcpwrapped
  6343. 48008/tcp open tcpwrapped
  6344. 48194/tcp open tcpwrapped
  6345. 48932/tcp open tcpwrapped
  6346. 48954/tcp open tcpwrapped
  6347. 49013/tcp open tcpwrapped
  6348. 49097/tcp open tcpwrapped
  6349. 49622/tcp open tcpwrapped
  6350. 49693/tcp open tcpwrapped
  6351. 49996/tcp open tcpwrapped
  6352. 50111/tcp open tcpwrapped
  6353. 50714/tcp open tcpwrapped
  6354. 52299/tcp open tcpwrapped
  6355. 53123/tcp open tcpwrapped
  6356. 53801/tcp open tcpwrapped
  6357. 54461/tcp open tcpwrapped
  6358. 54484/tcp open tcpwrapped
  6359. 55788/tcp open tcpwrapped
  6360. 56976/tcp open tcpwrapped
  6361. 58350/tcp open tcpwrapped
  6362. 58529/tcp open tcpwrapped
  6363. 59083/tcp open tcpwrapped
  6364. 59477/tcp open tcpwrapped
  6365. 60146/tcp open tcpwrapped
  6366. 60345/tcp open tcpwrapped
  6367. 60595/tcp open tcpwrapped
  6368. 60686/tcp open tcpwrapped
  6369. 61161/tcp open tcpwrapped
  6370. 61166/tcp open tcpwrapped
  6371. 61557/tcp open tcpwrapped
  6372. 61830/tcp open tcpwrapped
  6373. 61861/tcp open tcpwrapped
  6374. 61904/tcp open tcpwrapped
  6375. 63352/tcp open tcpwrapped
  6376. 63785/tcp open tcpwrapped
  6377. 64396/tcp open tcpwrapped
  6378. 64592/tcp open tcpwrapped
  6379. 64707/tcp open tcpwrapped
  6380. 64752/tcp open tcpwrapped
  6381. 64833/tcp open tcpwrapped
  6382. 65116/tcp open tcpwrapped
  6383. Device type: general purpose
  6384. Running (JUST GUESSING): Linux 3.X|2.6.X|4.X (94%)
  6385. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:4.4
  6386. Aggressive OS guesses: Linux 3.10 - 3.12 (94%), Linux 2.6.18 - 2.6.22 (91%), Linux 2.6.32 - 3.1 (89%), Linux 2.6.32 (88%), Linux 4.4 (86%), Linux 3.10 (86%), Linux 3.10 - 3.16 (86%), Linux 3.10 - 4.11 (85%), Linux 3.5 (85%), Linux 4.0 (85%)
  6387. No exact OS matches for host (test conditions non-ideal).
  6388. Uptime guess: 11.872 days (since Sun Sep 29 03:14:49 2019)
  6389. Network Distance: 2 hops
  6390. TCP Sequence Prediction: Difficulty=259 (Good luck!)
  6391. IP ID Sequence Generation: All zeros
  6392.  
  6393. TRACEROUTE (using port 445/tcp)
  6394. HOP RTT ADDRESS
  6395. 1 115.68 ms 10.249.204.1
  6396. 2 115.66 ms 212.174.188.50
  6397.  
  6398. NSE: Script Post-scanning.
  6399. Initiating NSE at 00:10
  6400. Completed NSE at 00:10, 0.00s elapsed
  6401. Initiating NSE at 00:10
  6402. Completed NSE at 00:10, 0.00s elapsed
  6403. Read data files from: /usr/bin/../share/nmap
  6404. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  6405. Nmap done: 1 IP address (1 host up) scanned in 1300.30 seconds
  6406. Raw packets sent: 262906 (11.573MB) | Rcvd: 34214 (6.175MB)
  6407. #######################################################################################################################################
  6408. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-11 00:10 EDT
  6409. NSE: Loaded 47 scripts for scanning.
  6410. NSE: Script Pre-scanning.
  6411. Initiating NSE at 00:10
  6412. Completed NSE at 00:10, 0.00s elapsed
  6413. Initiating NSE at 00:10
  6414. Completed NSE at 00:10, 0.00s elapsed
  6415. Initiating Parallel DNS resolution of 1 host. at 00:10
  6416. Completed Parallel DNS resolution of 1 host. at 00:10, 10.44s elapsed
  6417. Initiating UDP Scan at 00:10
  6418. Scanning 212.174.188.50 [15 ports]
  6419. Completed UDP Scan at 00:10, 2.08s elapsed (15 total ports)
  6420. Initiating Service scan at 00:10
  6421. Scanning 13 services on 212.174.188.50
  6422. Service scan Timing: About 7.69% done; ETC: 00:31 (0:19:24 remaining)
  6423. Completed Service scan at 00:12, 102.58s elapsed (13 services on 1 host)
  6424. Initiating OS detection (try #1) against 212.174.188.50
  6425. Retrying OS detection (try #2) against 212.174.188.50
  6426. Initiating Traceroute at 00:12
  6427. Completed Traceroute at 00:12, 7.07s elapsed
  6428. Initiating Parallel DNS resolution of 1 host. at 00:12
  6429. Completed Parallel DNS resolution of 1 host. at 00:12, 0.00s elapsed
  6430. NSE: Script scanning 212.174.188.50.
  6431. Initiating NSE at 00:12
  6432. Completed NSE at 00:12, 7.14s elapsed
  6433. Initiating NSE at 00:12
  6434. Completed NSE at 00:12, 1.01s elapsed
  6435. Nmap scan report for 212.174.188.50
  6436. Host is up (0.060s latency).
  6437.  
  6438. PORT STATE SERVICE VERSION
  6439. 53/udp open|filtered domain
  6440. 67/udp open|filtered dhcps
  6441. 68/udp open|filtered dhcpc
  6442. 69/udp open|filtered tftp
  6443. 88/udp open|filtered kerberos-sec
  6444. 123/udp open|filtered ntp
  6445. 137/udp filtered netbios-ns
  6446. 138/udp filtered netbios-dgm
  6447. 139/udp open|filtered netbios-ssn
  6448. 161/udp open|filtered snmp
  6449. 162/udp open|filtered snmptrap
  6450. 389/udp open|filtered ldap
  6451. 500/udp open|filtered isakmp
  6452. |_ike-version: ERROR: Script execution failed (use -d to debug)
  6453. 520/udp open|filtered route
  6454. 2049/udp open|filtered nfs
  6455. Too many fingerprints match this host to give specific OS details
  6456.  
  6457. TRACEROUTE (using port 138/udp)
  6458. HOP RTT ADDRESS
  6459. 1 38.17 ms 10.249.204.1
  6460. 2 ... 3
  6461. 4 33.52 ms 10.249.204.1
  6462. 5 121.15 ms 10.249.204.1
  6463. 6 121.15 ms 10.249.204.1
  6464. 7 121.15 ms 10.249.204.1
  6465. 8 121.14 ms 10.249.204.1
  6466. 9 121.13 ms 10.249.204.1
  6467. 10 45.15 ms 10.249.204.1
  6468. 11 ... 18
  6469. 19 91.58 ms 10.249.204.1
  6470. 20 36.04 ms 10.249.204.1
  6471. 21 ... 28
  6472. 29 74.28 ms 10.249.204.1
  6473. 30 32.07 ms 10.249.204.1
  6474.  
  6475. NSE: Script Post-scanning.
  6476. Initiating NSE at 00:12
  6477. Completed NSE at 00:12, 0.00s elapsed
  6478. Initiating NSE at 00:12
  6479. Completed NSE at 00:12, 0.00s elapsed
  6480. Read data files from: /usr/bin/../share/nmap
  6481. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  6482. Nmap done: 1 IP address (1 host up) scanned in 134.14 seconds
  6483. Raw packets sent: 149 (10.404KB) | Rcvd: 228 (54.772KB)
  6484. #######################################################################################################################################
  6485. Hosts
  6486. =====
  6487.  
  6488. address mac name os_name os_flavor os_sp purpose info comments
  6489. ------- --- ---- ------- --------- ----- ------- ---- --------
  6490. 212.174.188.50 Linux 3.X server
  6491.  
  6492. Services
  6493. ========
  6494.  
  6495. host port proto name state info
  6496. ---- ---- ----- ---- ----- ----
  6497. 212.174.188.50 25 tcp smtp closed
  6498. 212.174.188.50 53 udp domain unknown
  6499. 212.174.188.50 67 udp dhcps unknown
  6500. 212.174.188.50 68 udp dhcpc unknown
  6501. 212.174.188.50 69 udp tftp unknown
  6502. 212.174.188.50 80 tcp http open nginx
  6503. 212.174.188.50 88 udp kerberos-sec unknown
  6504. 212.174.188.50 123 udp ntp unknown
  6505. 212.174.188.50 137 udp netbios-ns filtered
  6506. 212.174.188.50 138 udp netbios-dgm filtered
  6507. 212.174.188.50 139 tcp netbios-ssn closed
  6508. 212.174.188.50 139 udp netbios-ssn unknown
  6509. 212.174.188.50 145 tcp tcpwrapped open
  6510. 212.174.188.50 161 udp snmp unknown
  6511. 212.174.188.50 162 udp snmptrap unknown
  6512. 212.174.188.50 389 udp ldap unknown
  6513. 212.174.188.50 443 tcp ssl/http open nginx
  6514. 212.174.188.50 445 tcp microsoft-ds closed
  6515. 212.174.188.50 500 udp isakmp unknown
  6516. 212.174.188.50 520 udp route unknown
  6517. 212.174.188.50 1012 tcp tcpwrapped open
  6518. 212.174.188.50 1996 tcp tcpwrapped open
  6519. 212.174.188.50 2049 udp nfs unknown
  6520. 212.174.188.50 2663 tcp tcpwrapped open
  6521. 212.174.188.50 4300 tcp tcpwrapped open
  6522. 212.174.188.50 4884 tcp tcpwrapped open
  6523. 212.174.188.50 6830 tcp tcpwrapped open
  6524. 212.174.188.50 7019 tcp tcpwrapped open
  6525. 212.174.188.50 7048 tcp tcpwrapped open
  6526. 212.174.188.50 7220 tcp tcpwrapped open
  6527. 212.174.188.50 7462 tcp tcpwrapped open
  6528. 212.174.188.50 9177 tcp tcpwrapped open
  6529. 212.174.188.50 10785 tcp tcpwrapped open
  6530. 212.174.188.50 11086 tcp tcpwrapped open
  6531. 212.174.188.50 11494 tcp tcpwrapped open
  6532. 212.174.188.50 11958 tcp tcpwrapped open
  6533. 212.174.188.50 13412 tcp tcpwrapped open
  6534. 212.174.188.50 13728 tcp tcpwrapped open
  6535. 212.174.188.50 14339 tcp tcpwrapped open
  6536. 212.174.188.50 14570 tcp tcpwrapped open
  6537. 212.174.188.50 14725 tcp tcpwrapped open
  6538. 212.174.188.50 14878 tcp tcpwrapped open
  6539. 212.174.188.50 15044 tcp tcpwrapped open
  6540. 212.174.188.50 15557 tcp tcpwrapped open
  6541. 212.174.188.50 15601 tcp tcpwrapped open
  6542. 212.174.188.50 15670 tcp tcpwrapped open
  6543. 212.174.188.50 17984 tcp tcpwrapped open
  6544. 212.174.188.50 18372 tcp tcpwrapped open
  6545. 212.174.188.50 18497 tcp tcpwrapped open
  6546. 212.174.188.50 18825 tcp tcpwrapped open
  6547. 212.174.188.50 18982 tcp tcpwrapped open
  6548. 212.174.188.50 18985 tcp tcpwrapped open
  6549. 212.174.188.50 19566 tcp tcpwrapped open
  6550. 212.174.188.50 19885 tcp tcpwrapped open
  6551. 212.174.188.50 20457 tcp tcpwrapped open
  6552. 212.174.188.50 21697 tcp tcpwrapped open
  6553. 212.174.188.50 22019 tcp tcpwrapped open
  6554. 212.174.188.50 22672 tcp tcpwrapped open
  6555. 212.174.188.50 22743 tcp tcpwrapped open
  6556. 212.174.188.50 23170 tcp tcpwrapped open
  6557. 212.174.188.50 23516 tcp tcpwrapped open
  6558. 212.174.188.50 23731 tcp tcpwrapped open
  6559. 212.174.188.50 24618 tcp tcpwrapped open
  6560. 212.174.188.50 24946 tcp tcpwrapped open
  6561. 212.174.188.50 25365 tcp tcpwrapped open
  6562. 212.174.188.50 26048 tcp tcpwrapped open
  6563. 212.174.188.50 26346 tcp tcpwrapped open
  6564. 212.174.188.50 26586 tcp tcpwrapped open
  6565. 212.174.188.50 27110 tcp tcpwrapped open
  6566. 212.174.188.50 27429 tcp tcpwrapped open
  6567. 212.174.188.50 27991 tcp tcpwrapped open
  6568. 212.174.188.50 28728 tcp tcpwrapped open
  6569. 212.174.188.50 28970 tcp tcpwrapped open
  6570. 212.174.188.50 29097 tcp tcpwrapped open
  6571. 212.174.188.50 29674 tcp tcpwrapped open
  6572. 212.174.188.50 30034 tcp tcpwrapped open
  6573. 212.174.188.50 30285 tcp tcpwrapped open
  6574. 212.174.188.50 30369 tcp tcpwrapped open
  6575. 212.174.188.50 32719 tcp tcpwrapped open
  6576. 212.174.188.50 32726 tcp tcpwrapped open
  6577. 212.174.188.50 32803 tcp tcpwrapped open
  6578. 212.174.188.50 32835 tcp tcpwrapped open
  6579. 212.174.188.50 32876 tcp tcpwrapped open
  6580. 212.174.188.50 32942 tcp tcpwrapped open
  6581. 212.174.188.50 33107 tcp tcpwrapped open
  6582. 212.174.188.50 33437 tcp tcpwrapped open
  6583. 212.174.188.50 33688 tcp tcpwrapped open
  6584. 212.174.188.50 33789 tcp tcpwrapped open
  6585. 212.174.188.50 35234 tcp tcpwrapped open
  6586. 212.174.188.50 35394 tcp tcpwrapped open
  6587. 212.174.188.50 35974 tcp tcpwrapped open
  6588. 212.174.188.50 36130 tcp tcpwrapped open
  6589. 212.174.188.50 36363 tcp tcpwrapped open
  6590. 212.174.188.50 36382 tcp tcpwrapped open
  6591. 212.174.188.50 36436 tcp tcpwrapped open
  6592. 212.174.188.50 36515 tcp tcpwrapped open
  6593. 212.174.188.50 37813 tcp tcpwrapped open
  6594. 212.174.188.50 38397 tcp tcpwrapped open
  6595. 212.174.188.50 38957 tcp tcpwrapped open
  6596. 212.174.188.50 39006 tcp tcpwrapped open
  6597. 212.174.188.50 39062 tcp tcpwrapped open
  6598. 212.174.188.50 41424 tcp tcpwrapped open
  6599. 212.174.188.50 41727 tcp tcpwrapped open
  6600. 212.174.188.50 42400 tcp tcpwrapped open
  6601. 212.174.188.50 42870 tcp tcpwrapped open
  6602. 212.174.188.50 43401 tcp tcpwrapped open
  6603. 212.174.188.50 44428 tcp tcpwrapped open
  6604. 212.174.188.50 44838 tcp tcpwrapped open
  6605. 212.174.188.50 45305 tcp tcpwrapped open
  6606. 212.174.188.50 45313 tcp tcpwrapped open
  6607. 212.174.188.50 45430 tcp tcpwrapped open
  6608. 212.174.188.50 45695 tcp tcpwrapped open
  6609. 212.174.188.50 45764 tcp tcpwrapped open
  6610. 212.174.188.50 45795 tcp tcpwrapped open
  6611. 212.174.188.50 45874 tcp tcpwrapped open
  6612. 212.174.188.50 46391 tcp tcpwrapped open
  6613. 212.174.188.50 46427 tcp tcpwrapped open
  6614. 212.174.188.50 46449 tcp tcpwrapped open
  6615. 212.174.188.50 46707 tcp tcpwrapped open
  6616. 212.174.188.50 46979 tcp tcpwrapped open
  6617. 212.174.188.50 46995 tcp tcpwrapped open
  6618. 212.174.188.50 47227 tcp tcpwrapped open
  6619. 212.174.188.50 47415 tcp tcpwrapped open
  6620. 212.174.188.50 47766 tcp tcpwrapped open
  6621. 212.174.188.50 47796 tcp tcpwrapped open
  6622. 212.174.188.50 48008 tcp tcpwrapped open
  6623. 212.174.188.50 48194 tcp tcpwrapped open
  6624. 212.174.188.50 48932 tcp tcpwrapped open
  6625. 212.174.188.50 48954 tcp tcpwrapped open
  6626. 212.174.188.50 49013 tcp tcpwrapped open
  6627. 212.174.188.50 49097 tcp tcpwrapped open
  6628. 212.174.188.50 49622 tcp tcpwrapped open
  6629. 212.174.188.50 49693 tcp tcpwrapped open
  6630. 212.174.188.50 49996 tcp tcpwrapped open
  6631. 212.174.188.50 50111 tcp tcpwrapped open
  6632. 212.174.188.50 50714 tcp tcpwrapped open
  6633. 212.174.188.50 52299 tcp tcpwrapped open
  6634. 212.174.188.50 53123 tcp tcpwrapped open
  6635. 212.174.188.50 53801 tcp tcpwrapped open
  6636. 212.174.188.50 54461 tcp tcpwrapped open
  6637. 212.174.188.50 54484 tcp tcpwrapped open
  6638. 212.174.188.50 55788 tcp tcpwrapped open
  6639. 212.174.188.50 56976 tcp tcpwrapped open
  6640. 212.174.188.50 58350 tcp tcpwrapped open
  6641. 212.174.188.50 58529 tcp tcpwrapped open
  6642. 212.174.188.50 59083 tcp tcpwrapped open
  6643. 212.174.188.50 59477 tcp tcpwrapped open
  6644. 212.174.188.50 60146 tcp tcpwrapped open
  6645. 212.174.188.50 60345 tcp tcpwrapped open
  6646. 212.174.188.50 60595 tcp tcpwrapped open
  6647. 212.174.188.50 60686 tcp tcpwrapped open
  6648. 212.174.188.50 61161 tcp tcpwrapped open
  6649. 212.174.188.50 61166 tcp tcpwrapped open
  6650. 212.174.188.50 61557 tcp tcpwrapped open
  6651. 212.174.188.50 61830 tcp tcpwrapped open
  6652. 212.174.188.50 61861 tcp tcpwrapped open
  6653. 212.174.188.50 61904 tcp tcpwrapped open
  6654. 212.174.188.50 63352 tcp tcpwrapped open
  6655. 212.174.188.50 63785 tcp tcpwrapped open
  6656. 212.174.188.50 64396 tcp tcpwrapped open
  6657. 212.174.188.50 64592 tcp tcpwrapped open
  6658. 212.174.188.50 64707 tcp tcpwrapped open
  6659. 212.174.188.50 64752 tcp tcpwrapped open
  6660. 212.174.188.50 64833 tcp tcpwrapped open
  6661. 212.174.188.50 65116 tcp tcpwrapped open
  6662. #######################################################################################################################################
  6663. Anonymous JTSEC #OpTurkey Full Recon 2
Advertisement
Add Comment
Please, Sign In to add comment