JTSEC1333

Anonymous JTSEC #OpSudan Full Recon #65

May 1st, 2019
819
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 70.02 KB | None | 0 0
  1. #######################################################################################################################################
  2. ======================================================================================================================================
  3. Hostname mininfo.gov.sd ISP Online S.a.s.
  4. Continent Europe Flag
  5. FR
  6. Country France Country Code FR
  7. Region Vendée Local time 01 May 2019 21:35 CEST
  8. City Chavagnes-en-Paillers Postal Code 85250
  9. IP Address 212.83.140.187 Latitude 46.892
  10. Longitude -1.252
  11.  
  12. =======================================================================================================================================
  13. #######################################################################################################################################
  14. > mininfo.gov.sd
  15. Server: 38.132.106.139
  16. Address: 38.132.106.139#53
  17.  
  18. Non-authoritative answer:
  19. Name: mininfo.gov.sd
  20. Address: 212.83.140.187
  21. >
  22. #######################################################################################################################################
  23. HostIP:212.83.140.187
  24. HostName:mininfo.gov.sd
  25.  
  26. Gathered Inet-whois information for 212.83.140.187
  27. ---------------------------------------------------------------------------------------------------------------------------------------
  28.  
  29.  
  30. inetnum: 212.83.128.0 - 212.83.143.255
  31. org: ORG-ONLI1-RIPE
  32. netname: Online
  33. descr: Online SAS - Dedibox
  34. country: FR
  35. admin-c: TTFR1-RIPE
  36. tech-c: TTFR1-RIPE
  37. status: ASSIGNED PA
  38. mnt-by: MNT-TISCALIFR
  39. mnt-by: MNT-TISCALIFR-B2B
  40. created: 2016-02-23T12:28:33Z
  41. last-modified: 2016-02-23T16:51:16Z
  42. source: RIPE
  43.  
  44. organisation: ORG-ONLI1-RIPE
  45. mnt-ref: MNT-TISCALIFR-B2B
  46. org-name: ONLINE SAS
  47. org-type: OTHER
  48. address: 8 rue de la ville l'eveque 75008 PARIS
  49. abuse-c: AR32851-RIPE
  50. mnt-ref: ONLINESAS-MNT
  51. mnt-by: ONLINESAS-MNT
  52. created: 2015-07-10T15:20:41Z
  53. last-modified: 2017-10-30T14:40:53Z
  54. source: RIPE # Filtered
  55.  
  56. role: Tiscali Telecom France Registry
  57. remarks: now known as Online S.A.S. / Iliad-Entreprises
  58. address: 8 rue de la ville l'�v�que
  59. address: 75008 Paris
  60. address: France
  61. abuse-mailbox: [email protected]
  62. admin-c: IENT-RIPE
  63. tech-c: IENT-RIPE
  64. tech-c: NR1053-RIPE
  65. nic-hdl: TTFR1-RIPE
  66. mnt-by: MNT-TISCALIFR
  67. created: 2002-09-24T14:16:42Z
  68. last-modified: 2012-11-05T16:08:46Z
  69. source: RIPE # Filtered
  70.  
  71. % Information related to '212.83.128.0/19AS12876'
  72.  
  73. route: 212.83.128.0/19
  74. descr: Online SAS
  75. descr: Paris, France
  76. origin: AS12876
  77. mnt-by: MNT-TISCALIFR
  78. created: 2013-08-02T09:07:45Z
  79. last-modified: 2013-08-02T09:07:45Z
  80. source: RIPE
  81.  
  82. % This query was served by the RIPE Database Query Service version 1.93.2 (WAGYU)
  83.  
  84.  
  85.  
  86. Gathered Inic-whois information for mininfo.gov.sd
  87. ---------------------------------------------------------------------------------------------------------------------------------------
  88. Error: Unable to connect - Invalid Host
  89. ERROR: Connection to InicWhois Server sd.whois-servers.net failed
  90. close error
  91.  
  92. Gathered Netcraft information for mininfo.gov.sd
  93. ---------------------------------------------------------------------------------------------------------------------------------------
  94.  
  95. Retrieving Netcraft.com information for mininfo.gov.sd
  96. Netcraft.com Information gathered
  97.  
  98. Gathered Subdomain information for mininfo.gov.sd
  99. ---------------------------------------------------------------------------------------------------------------------------------------
  100. Searching Google.com:80...
  101. Searching Altavista.com:80...
  102. Found 0 possible subdomain(s) for host mininfo.gov.sd, Searched 0 pages containing 0 results
  103.  
  104. Gathered E-Mail information for mininfo.gov.sd
  105. ---------------------------------------------------------------------------------------------------------------------------------------
  106. Searching Google.com:80...
  107. Searching Altavista.com:80...
  108. Found 0 E-Mail(s) for host mininfo.gov.sd, Searched 0 pages containing 0 results
  109.  
  110. Gathered TCP Port information for 212.83.140.187
  111. ---------------------------------------------------------------------------------------------------------------------------------------
  112.  
  113. Port State
  114.  
  115. 21/tcp open
  116. 22/tcp open
  117. 53/tcp open
  118. 80/tcp open
  119. 143/tcp open
  120.  
  121. Portscan Finished: Scanned 150 ports, 3 ports were in state closed
  122. #######################################################################################################################################
  123. [i] Scanning Site: http://mininfo.gov.sd
  124.  
  125.  
  126.  
  127. B A S I C I N F O
  128. =======================================================================================================================================
  129.  
  130.  
  131. [+] Site Title: وزارة الإعلام | جمهورية السودان
  132. [+] IP address: 212.83.140.187
  133. [+] Web Server: Could Not Detect
  134. [+] CMS: WordPress
  135. [+] Cloudflare: Not Detected
  136. [+] Robots File: Found
  137.  
  138. -------------[ contents ]----------------
  139. User-agent: *
  140.  
  141. -----------[end of contents]-------------
  142.  
  143.  
  144.  
  145.  
  146.  
  147. G E O I P L O O K U P
  148. =======================================================================================================================================
  149.  
  150. [i] IP Address: 212.83.140.187
  151. [i] Country: France
  152. [i] State: Vendee
  153. [i] City: Chavagnes-en-Paillers
  154. [i] Latitude: 46.8917
  155. [i] Longitude: -1.2521
  156.  
  157.  
  158.  
  159.  
  160. H T T P H E A D E R S
  161. =======================================================================================================================================
  162.  
  163.  
  164. [i] HTTP/1.1 200 OK
  165. [i] Date: Wed, 01 May 2019 20:22:39 GMT
  166. [i] Last-Modified: Wed, 01 May 2019 05:31:04 GMT
  167. [i] Accept-Ranges: bytes
  168. [i] Vary: Accept-Encoding
  169. [i] Cache-Control: max-age=0, no-cache, no-store, must-revalidate
  170. [i] Pragma: no-cache
  171. [i] Expires: Mon, 29 Oct 1923 20:30:00 GMT
  172. [i] Content-Type: text/html; charset=UTF-8
  173. [i] Connection: close
  174.  
  175.  
  176.  
  177.  
  178. D N S L O O K U P
  179. =======================================================================================================================================
  180.  
  181. mininfo.gov.sd. 3599 IN MX 10 mail.mininfo.gov.sd.
  182. mininfo.gov.sd. 3599 IN NS ns51.mazinhost.net.
  183. mininfo.gov.sd. 3599 IN NS ns52.mazinhost.net.
  184. mininfo.gov.sd. 3599 IN TXT "v=spf1 mx a ~all"
  185. mininfo.gov.sd. 3599 IN A 212.83.140.187
  186. mininfo.gov.sd. 3599 IN SOA ns51.mazinhost.net. info.mazinhost.com. 2018041903 7200 540 604800 3600
  187.  
  188.  
  189.  
  190.  
  191. S U B N E T C A L C U L A T I O N
  192. =======================================================================================================================================
  193.  
  194. Address = 212.83.140.187
  195. Network = 212.83.140.187 / 32
  196. Netmask = 255.255.255.255
  197. Broadcast = not needed on Point-to-Point links
  198. Wildcard Mask = 0.0.0.0
  199. Hosts Bits = 0
  200. Max. Hosts = 1 (2^0 - 0)
  201. Host Range = { 212.83.140.187 - 212.83.140.187 }
  202.  
  203.  
  204.  
  205. N M A P P O R T S C A N
  206. =======================================================================================================================================
  207.  
  208. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 20:22 UTC
  209. Nmap scan report for mininfo.gov.sd (212.83.140.187)
  210. Host is up (0.074s latency).
  211. rDNS record for 212.83.140.187: ns51.mazinhost.net
  212.  
  213. PORT STATE SERVICE
  214. 21/tcp open ftp
  215. 22/tcp open ssh
  216. 23/tcp filtered telnet
  217. 80/tcp open http
  218. 110/tcp open pop3
  219. 143/tcp open imap
  220. 443/tcp open https
  221. 3389/tcp filtered ms-wbt-server
  222.  
  223. Nmap done: 1 IP address (1 host up) scanned in 1.35 seconds
  224.  
  225.  
  226.  
  227. S U B - D O M A I N F I N D E R
  228. =======================================================================================================================================
  229.  
  230.  
  231. [i] Total Subdomains Found : 1
  232.  
  233. [+] Subdomain: mail.mininfo.gov.sd
  234. [-] IP: 212.83.140.187
  235. #######################################################################################################################################
  236. [?] Enter the target: example( http://domain.com )
  237. http://mininfo.gov.sd/
  238. [!] IP Address : 212.83.140.187
  239. [+] Operating System : Ubuntu"
  240.  
  241. [!] mininfo.gov.sd doesn't seem to use a CMS
  242. [+] Honeypot Probabilty: 30%
  243. ---------------------------------------------------------------------------------------------------------------------------------------
  244. [~] Trying to gather whois information for mininfo.gov.sd
  245. [+] Whois information found
  246. [-] Unable to build response, visit https://who.is/whois/mininfo.gov.sd
  247. ---------------------------------------------------------------------------------------------------------------------------------------
  248. PORT STATE SERVICE
  249. 21/tcp open ftp
  250. 22/tcp open ssh
  251. 23/tcp filtered telnet
  252. 80/tcp open http
  253. 110/tcp open pop3
  254. 143/tcp open imap
  255. 443/tcp open https
  256. 3389/tcp filtered ms-wbt-server
  257. Nmap done: 1 IP address (1 host up) scanned in 1.37 seconds
  258. ---------------------------------------------------------------------------------------------------------------------------------------
  259.  
  260. [+] DNS Records
  261. ns51.mazinhost.net. (212.83.140.187) AS12876 Online S.a.s. France
  262. ns52.mazinhost.net. (212.83.140.187) AS12876 Online S.a.s. France
  263.  
  264. [+] MX Records
  265. 10 (212.83.140.187) AS12876 Online S.a.s. France
  266.  
  267. [+] Host Records (A)
  268. mininfo.gov.sdHTTP: (ns51.mazinhost.net) (212.83.140.187) AS12876 Online S.a.s. France
  269. mail.mininfo.gov.sdHTTP: (ns51.mazinhost.net) (212.83.140.187) AS12876 Online S.a.s. France
  270.  
  271. [+] TXT Records
  272. "v=spf1 mx a ~all"
  273.  
  274. [+] DNS Map: https://dnsdumpster.com/static/map/mininfo.gov.sd.png
  275.  
  276. [>] Initiating 3 intel modules
  277. [>] Loading Alpha module (1/3)
  278. [>] Beta module deployed (2/3)
  279. [>] Gamma module initiated (3/3)
  280.  
  281.  
  282. [+] Emails found:
  283. ---------------------------------------------------------------------------------------------------------------------------------------
  284.  
  285. [+] Hosts found in search engines:
  286. ---------------------------------------------------------------------------------------------------------------------------------------
  287. [-] Resolving hostnames IPs...
  288. 212.83.140.187:www.mininfo.gov.sd
  289. [+] Virtual hosts:
  290. ---------------------------------------------------------------------------------------------------------------------------------------
  291. #######################################################################################################################################
  292. Enter Address Website = mininfo.gov.sd
  293.  
  294. Reversing IP With HackTarget 'mininfo.gov.sd'
  295. ---------------------------------------------------------------------------------------------------------------------------------------
  296.  
  297. [+] elbadri.org
  298. [+] mail.mininfo.gov.sd
  299. [+] mininfo.gov.sd
  300. [+] ns51.mazinhost.net
  301. [+] ns52.mazinhost.net
  302. [+] ns516.mazinhost.net
  303. [+] ns517.mazinhost.net
  304. #######################################################################################################################################
  305.  
  306. Reverse IP With YouGetSignal 'mininfo.gov.sd'
  307. ---------------------------------------------------------------------------------------------------------------------------------------
  308.  
  309. [*] IP: 212.83.140.187
  310. [*] Domain: mininfo.gov.sd
  311. [*] Total Domains: 3
  312.  
  313. [+] mininfo.gov.sd
  314. [+] pharmacyalberta.com
  315. [+] www.mininfo.gov.sd
  316. #######################################################################################################################################
  317.  
  318. Geo IP Lookup 'mininfo.gov.sd'
  319. ---------------------------------------------------------------------------------------------------------------------------------------
  320.  
  321. [+] IP Address: 212.83.140.187
  322. [+] Country: France
  323. [+] State: Vendee
  324. [+] City: Chavagnes-en-Paillers
  325. [+] Latitude: 46.8917
  326. [+] Longitude: -1.2521
  327. #######################################################################################################################################
  328.  
  329. Bypass Cloudflare 'mininfo.gov.sd'
  330. ---------------------------------------------------------------------------------------------------------------------------------------
  331.  
  332. [!] CloudFlare Bypass 212.83.140.187 | webmail.mininfo.gov.sd
  333. [!] CloudFlare Bypass 212.83.140.187 | mail.mininfo.gov.sd
  334. [!] CloudFlare Bypass 212.83.140.187 | www.mininfo.gov.sd
  335. #######################################################################################################################################
  336.  
  337. DNS Lookup 'mininfo.gov.sd'
  338. ---------------------------------------------------------------------------------------------------------------------------------------
  339.  
  340. [+] mininfo.gov.sd. 3599 IN MX 10 mail.mininfo.gov.sd.
  341. [+] mininfo.gov.sd. 3599 IN NS ns52.mazinhost.net.
  342. [+] mininfo.gov.sd. 3599 IN NS ns51.mazinhost.net.
  343. [+] mininfo.gov.sd. 3599 IN TXT "v=spf1 mx a ~all"
  344. [+] mininfo.gov.sd. 3599 IN A 212.83.140.187
  345. [+] mininfo.gov.sd. 3599 IN SOA ns51.mazinhost.net. info.mazinhost.com. 2018041903 7200 540 604800 3600
  346. #######################################################################################################################################
  347.  
  348. Show HTTP Header 'mininfo.gov.sd'
  349. ---------------------------------------------------------------------------------------------------------------------------------------
  350.  
  351. [+] HTTP/1.1 200 OK
  352. [+] Date: Wed, 01 May 2019 20:22:21 GMT
  353. [+] Server: Apache/2.4.18 (Ubuntu)
  354. [+] Last-Modified: Wed, 01 May 2019 05:31:04 GMT
  355. [+] Accept-Ranges: bytes
  356. [+] Content-Length: 263075
  357. [+] Vary: Accept-Encoding
  358. [+] Cache-Control: max-age=0, no-cache, no-store, must-revalidate
  359. [+] Pragma: no-cache
  360. [+] Expires: Mon, 29 Oct 1923 20:30:00 GMT
  361. [+] Content-Type: text/html; charset=UTF-8
  362. #######################################################################################################################################
  363.  
  364. Port Scan 'mininfo.gov.sd'
  365. ---------------------------------------------------------------------------------------------------------------------------------------
  366.  
  367. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 20:22 UTC
  368. Nmap scan report for mininfo.gov.sd (212.83.140.187)
  369. Host is up (0.074s latency).
  370. rDNS record for 212.83.140.187: ns51.mazinhost.net
  371.  
  372. PORT STATE SERVICE
  373. 21/tcp open ftp
  374. 22/tcp open ssh
  375. 23/tcp filtered telnet
  376. 80/tcp open http
  377. 110/tcp open pop3
  378. 143/tcp open imap
  379. 443/tcp open https
  380. 3389/tcp filtered ms-wbt-server
  381.  
  382. Nmap done: 1 IP address (1 host up) scanned in 1.72 seconds
  383. #######################################################################################################################################
  384.  
  385. Traceroute 'mininfo.gov.sd'
  386. ---------------------------------------------------------------------------------------------------------------------------------------
  387.  
  388. Start: 2019-05-01T20:22:30+0000
  389. HOST: web01 Loss% Snt Last Avg Best Wrst StDev
  390. 1.|-- 45.79.12.202 0.0% 3 0.8 1.1 0.8 1.5 0.4
  391. 2.|-- 45.79.12.6 0.0% 3 0.5 2.0 0.5 4.7 2.3
  392. 3.|-- 45.79.12.8 0.0% 3 0.6 0.7 0.5 0.8 0.1
  393. 4.|-- hu0-7-0-7.ccr41.dfw03.atlas.cogentco.com 0.0% 3 1.2 1.5 1.2 1.8 0.3
  394. 5.|-- be2763.ccr31.dfw01.atlas.cogentco.com 0.0% 3 1.6 1.8 1.6 2.2 0.3
  395. 6.|-- be2441.ccr41.iah01.atlas.cogentco.com 0.0% 3 7.6 7.2 6.9 7.6 0.4
  396. 7.|-- be2687.ccr41.atl01.atlas.cogentco.com 0.0% 3 20.9 21.2 20.9 21.6 0.3
  397. 8.|-- be2112.ccr41.dca01.atlas.cogentco.com 0.0% 3 32.1 32.1 32.1 32.2 0.0
  398. 9.|-- be2806.ccr41.jfk02.atlas.cogentco.com 0.0% 3 38.0 38.1 38.0 38.2 0.1
  399. 10.|-- be3627.ccr41.par01.atlas.cogentco.com 0.0% 3 110.8 114.4 110.8 121.0 5.7
  400. 11.|-- be3183.ccr31.par04.atlas.cogentco.com 0.0% 3 111.2 111.1 111.0 111.2 0.2
  401. 12.|-- be3750.rcr21.b022890-0.par04.atlas.cogentco.com 0.0% 3 113.9 116.1 112.9 121.5 4.7
  402. 13.|-- online.demarc.cogentco.com 0.0% 3 112.0 111.8 111.6 112.0 0.2
  403. 14.|-- pni-th2-a9k1.th2.poneytelecom.eu 0.0% 3 113.3 113.9 113.1 115.2 1.1
  404. 15.|-- 195.154.2.145 0.0% 3 111.4 111.2 110.9 111.4 0.3
  405. 16.|-- ns51.mazinhost.net 0.0% 3 113.0 113.2 113.0 113.3 0.2
  406. #######################################################################################################################################
  407.  
  408. Ping 'mininfo.gov.sd'
  409. ---------------------------------------------------------------------------------------------------------------------------------------
  410.  
  411.  
  412. Starting Nping 0.7.70 ( https://nmap.org/nping ) at 2019-05-01 20:23 UTC
  413. SENT (0.2808s) ICMP [104.237.144.6 > 212.83.140.187 Echo request (type=8/code=0) id=31026 seq=1] IP [ttl=64 id=14946 iplen=28 ]
  414. RCVD (0.4826s) ICMP [212.83.140.187 > 104.237.144.6 Echo reply (type=0/code=0) id=31026 seq=1] IP [ttl=54 id=36499 iplen=28 ]
  415. SENT (1.2816s) ICMP [104.237.144.6 > 212.83.140.187 Echo request (type=8/code=0) id=31026 seq=2] IP [ttl=64 id=14946 iplen=28 ]
  416. RCVD (1.5022s) ICMP [212.83.140.187 > 104.237.144.6 Echo reply (type=0/code=0) id=31026 seq=2] IP [ttl=54 id=36565 iplen=28 ]
  417. SENT (2.2843s) ICMP [104.237.144.6 > 212.83.140.187 Echo request (type=8/code=0) id=31026 seq=3] IP [ttl=64 id=14946 iplen=28 ]
  418. RCVD (2.5223s) ICMP [212.83.140.187 > 104.237.144.6 Echo reply (type=0/code=0) id=31026 seq=3] IP [ttl=54 id=36667 iplen=28 ]
  419. SENT (3.2866s) ICMP [104.237.144.6 > 212.83.140.187 Echo request (type=8/code=0) id=31026 seq=4] IP [ttl=64 id=14946 iplen=28 ]
  420. RCVD (3.5425s) ICMP [212.83.140.187 > 104.237.144.6 Echo reply (type=0/code=0) id=31026 seq=4] IP [ttl=54 id=36738 iplen=28 ]
  421.  
  422. Max rtt: 255.888ms | Min rtt: 201.807ms | Avg rtt: 228.959ms
  423. Raw packets sent: 4 (112B) | Rcvd: 4 (184B) | Lost: 0 (0.00%)
  424. Nping done: 1 IP address pinged in 3.54 seconds
  425. #######################################################################################################################################
  426. ; <<>> DiG 9.11.5-P4-3-Debian <<>> mininfo.gov.sd
  427. ;; global options: +cmd
  428. ;; Got answer:
  429. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 14332
  430. ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
  431.  
  432. ;; OPT PSEUDOSECTION:
  433. ; EDNS: version: 0, flags:; udp: 4096
  434. ;; QUESTION SECTION:
  435. ;mininfo.gov.sd. IN A
  436.  
  437. ;; ANSWER SECTION:
  438. mininfo.gov.sd. 1323 IN A 212.83.140.187
  439.  
  440. ;; Query time: 222 msec
  441. ;; SERVER: 185.93.180.131#53(185.93.180.131)
  442. ;; WHEN: mer mai 01 22:54:58 EDT 2019
  443. ;; MSG SIZE rcvd: 59
  444. #######################################################################################################################################
  445. ; <<>> DiG 9.11.5-P4-3-Debian <<>> +trace mininfo.gov.sd
  446. ;; global options: +cmd
  447. . 81897 IN NS a.root-servers.net.
  448. . 81897 IN NS k.root-servers.net.
  449. . 81897 IN NS f.root-servers.net.
  450. . 81897 IN NS d.root-servers.net.
  451. . 81897 IN NS g.root-servers.net.
  452. . 81897 IN NS h.root-servers.net.
  453. . 81897 IN NS c.root-servers.net.
  454. . 81897 IN NS b.root-servers.net.
  455. . 81897 IN NS m.root-servers.net.
  456. . 81897 IN NS j.root-servers.net.
  457. . 81897 IN NS e.root-servers.net.
  458. . 81897 IN NS i.root-servers.net.
  459. . 81897 IN NS l.root-servers.net.
  460. . 81897 IN RRSIG NS 8 0 518400 20190514170000 20190501160000 25266 . w4ssTvTC9iBkFkqxTfOYUUzNPGYa6X8OafW9aSqZemGH5DXIrB7qHOf2 5wje3SBrkIEEbDa6EfNdcwIzMOf5XhhuwfM5dnO8tKSfnKpasFHMrBHG S3ugP+fPEGuIWtol0nyjdVqcbbDtlWWLBSX6KJs/no3vGbzlAbLZJap4 0XaRFnoWJLz0kDceA8QXeuuh//zpeHCHyzv/OJ8lmPSdBeRUmMLm/Kab Lm4zG+UJSYH3HCLkUNAvDylul5uUoue3jiZTKjwK+MxjdqUQa/FyPXow gN8goiu8cUKc6OAUnWn0dV6T/cDZC5Lj0O/Oaj+9rV7nGNTETqNwhcQt JWHhqw==
  461. ;; Received 525 bytes from 185.93.180.131#53(185.93.180.131) in 218 ms
  462.  
  463. sd. 172800 IN NS sd.cctld.authdns.ripe.net.
  464. sd. 172800 IN NS ns1.uaenic.ae.
  465. sd. 172800 IN NS ns2.uaenic.ae.
  466. sd. 172800 IN NS ans1.sis.sd.
  467. sd. 172800 IN NS ans1.canar.sd.
  468. sd. 172800 IN NS ans2.canar.sd.
  469. sd. 172800 IN NS ns-sd.afrinic.net.
  470. sd. 86400 IN NSEC se. NS RRSIG NSEC
  471. sd. 86400 IN RRSIG NSEC 8 1 86400 20190514170000 20190501160000 25266 . RvWMl899QG/w8chpHW82ngDehj9ubgmK53QxZzcDub+gqGYHTtZSY67i Cv7IAvZb3XIHN+lbYe3c+nl3mIEzL1iSlDhtYmJtI6Z3abJBSu6S6ILk RHn3xyixJO9YMgXwGCn/TehgPbCqBE+NlI5GC9saGA5sa2UPvyMqLMTB reU28UtE5UzyyyNHGmuB0Ft6eONuuHrFfFuAAOFGyKTS9smX3kmyu78q P2Ys7Xxp2pnPefEQa54S8ZJ9tVFjoQw+VPvPQDF5IbmWUoGm6mcJj6pW CRm0JuA/UjZ2JS9HGwL64HzuZpy+M4LbCclsYG0uE9ugv0D9YPLkExN1 IpuUUg==
  472. ;; Received 701 bytes from 2001:500:2f::f#53(f.root-servers.net) in 28 ms
  473.  
  474. ;; Received 71 bytes from 195.229.0.186#53(ns2.uaenic.ae) in 423 ms
  475. #######################################################################################################################################
  476. [*] Performing General Enumeration of Domain: mininfo.gov.sd
  477. [-] DNSSEC is not configured for mininfo.gov.sd
  478. [*] SOA ns51.mazinhost.net 212.83.140.187
  479. [*] NS ns52.mazinhost.net 212.83.140.187
  480. [*] NS ns51.mazinhost.net 212.83.140.187
  481. [*] MX mail.mininfo.gov.sd 212.83.140.187
  482. [*] A mininfo.gov.sd 212.83.140.187
  483. [*] TXT mininfo.gov.sd v=spf1 mx a ~all
  484. [*] Enumerating SRV Records
  485. [-] No SRV Records Found for mininfo.gov.sd
  486. [+] 0 Records Found
  487. #######################################################################################################################################
  488. [*] Processing domain mininfo.gov.sd
  489. [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  490. [+] Getting nameservers
  491. 212.83.140.187 - ns52.mazinhost.net
  492. 212.83.140.187 - ns51.mazinhost.net
  493. [-] Zone transfer failed
  494.  
  495. [+] TXT records found
  496. "v=spf1 mx a ~all"
  497.  
  498. [+] MX records found, added to target list
  499. 10 mail.mininfo.gov.sd.
  500.  
  501. [*] Scanning mininfo.gov.sd for A records
  502. 212.83.140.187 - mininfo.gov.sd
  503. 212.83.140.187 - mail.mininfo.gov.sd
  504. 212.83.140.187 - webmail.mininfo.gov.sd
  505. 212.83.140.187 - www.mininfo.gov.sd
  506. #######################################################################################################################################
  507. [+] Testing domain
  508. www.mininfo.gov.sd 212.83.140.187
  509. [+] Dns resolving
  510. Domain name Ip address Name server
  511. mininfo.gov.sd 212.83.140.187 ns51.mazinhost.net
  512. Found 1 host(s) for mininfo.gov.sd
  513. [+] Testing wildcard
  514. Ok, no wildcard found.
  515.  
  516. [+] Scanning for subdomain on mininfo.gov.sd
  517. [!] Wordlist not specified. I scannig with my internal wordlist...
  518. Estimated time about 259.36 seconds
  519.  
  520. Subdomain Ip address Name server
  521.  
  522. mail.mininfo.gov.sd 212.83.140.187 ns51.mazinhost.net
  523. webmail.mininfo.gov.sd 212.83.140.187 ns51.mazinhost.net
  524. www.mininfo.gov.sd 212.83.140.187 ns51.mazinhost.net
  525. #######################################################################################################################################
  526. dnsenum VERSION:1.2.4
  527.  
  528. ----- mininfo.gov.sd -----
  529.  
  530.  
  531. Host's addresses:
  532. __________________
  533.  
  534. mininfo.gov.sd. 3600 IN A 212.83.140.187
  535.  
  536.  
  537. Name Servers:
  538. ______________
  539.  
  540. ns52.mazinhost.net. 14398 IN A 212.83.140.187
  541. ns51.mazinhost.net. 14399 IN A 212.83.140.187
  542.  
  543.  
  544. Mail (MX) Servers:
  545. ___________________
  546.  
  547. mail.mininfo.gov.sd. 3599 IN A 212.83.140.187
  548.  
  549.  
  550. Trying Zone Transfers and getting Bind Versions:
  551. _________________________________________________
  552.  
  553.  
  554. Trying Zone Transfer for mininfo.gov.sd on ns52.mazinhost.net ...
  555.  
  556. Trying Zone Transfer for mininfo.gov.sd on ns51.mazinhost.net ...
  557.  
  558. brute force file not specified, bay.
  559. #######################################################################################################################################
  560.  
  561. ____ _ _ _ _ _____
  562. / ___| _ _| |__ | (_)___| |_|___ / _ __
  563. \___ \| | | | '_ \| | / __| __| |_ \| '__|
  564. ___) | |_| | |_) | | \__ \ |_ ___) | |
  565. |____/ \__,_|_.__/|_|_|___/\__|____/|_|
  566.  
  567. # Coded By Ahmed Aboul-Ela - @aboul3la
  568.  
  569. [-] Enumerating subdomains now for mininfo.gov.sd
  570. [-] verbosity is enabled, will show the subdomains results in realtime
  571. [-] Searching now in Baidu..
  572. [-] Searching now in Yahoo..
  573. [-] Searching now in Google..
  574. [-] Searching now in Bing..
  575. [-] Searching now in Ask..
  576. [-] Searching now in Netcraft..
  577. [-] Searching now in DNSdumpster..
  578. [-] Searching now in Virustotal..
  579. [-] Searching now in ThreatCrowd..
  580. [-] Searching now in SSL Certificates..
  581. [-] Searching now in PassiveDNS..
  582. Virustotal: www.mininfo.gov.sd
  583. DNSdumpster: mail.mininfo.gov.sd
  584. [-] Saving results to file: /usr/share/sniper/loot//domains/domains-mininfo.gov.sd.txt
  585. [-] Total Unique Subdomains Found: 2
  586. www.mininfo.gov.sd
  587. mail.mininfo.gov.sd
  588. #######################################################################################################################################
  589. ===============================================
  590. -=Subfinder v1.1.3 github.com/subfinder/subfinder
  591. ===============================================
  592.  
  593.  
  594. Running Source: Ask
  595. Running Source: Archive.is
  596. Running Source: Baidu
  597. Running Source: Bing
  598. Running Source: CertDB
  599. Running Source: CertificateTransparency
  600. Running Source: Certspotter
  601. Running Source: Commoncrawl
  602. Running Source: Crt.sh
  603. Running Source: Dnsdb
  604. Running Source: DNSDumpster
  605. Running Source: DNSTable
  606. Running Source: Dogpile
  607. Running Source: Exalead
  608. Running Source: Findsubdomains
  609. Running Source: Googleter
  610. Running Source: Hackertarget
  611. Running Source: Ipv4Info
  612. Running Source: PTRArchive
  613. Running Source: Sitedossier
  614. Running Source: Threatcrowd
  615. Running Source: ThreatMiner
  616. Running Source: WaybackArchive
  617. Running Source: Yahoo
  618.  
  619. Running enumeration on mininfo.gov.sd
  620.  
  621. dnsdb: Unexpected return status 503
  622.  
  623. waybackarchive: parse http://web.archive.org/cdx/search/cdx?url=*.mininfo.gov.sd/*&output=json&fl=original&collapse=urlkey&page=: net/url: invalid control character in URL
  624.  
  625. dogpile: Get https://www.dogpile.com/search/web?q=mininfo.gov.sd&qsi=1: EOF
  626.  
  627. baidu: Get https://www.baidu.com/s?rn=100&pn=0&wd=site%3Amininfo.gov.sd&oq=site%3Amininfo.gov.sd: net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
  628.  
  629.  
  630. Starting Bruteforcing of mininfo.gov.sd with 9985 words
  631.  
  632. Total 6 Unique subdomains found for mininfo.gov.sd
  633.  
  634. .mininfo.gov.sd
  635. mail.mininfo.gov.sd
  636. mail.mininfo.gov.sd
  637. webmail.mininfo.gov.sd
  638. www.mininfo.gov.sd
  639. www.mininfo.gov.sd
  640. #######################################################################################################################################
  641. [*] Processing domain mininfo.gov.sd
  642. [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  643. [+] Getting nameservers
  644. 212.83.140.187 - ns52.mazinhost.net
  645. 212.83.140.187 - ns51.mazinhost.net
  646. [-] Zone transfer failed
  647.  
  648. [+] TXT records found
  649. "v=spf1 mx a ~all"
  650.  
  651. [+] MX records found, added to target list
  652. 10 mail.mininfo.gov.sd.
  653.  
  654. [*] Scanning mininfo.gov.sd for A records
  655. 212.83.140.187 - mininfo.gov.sd
  656. 212.83.140.187 - mail.mininfo.gov.sd
  657. 212.83.140.187 - webmail.mininfo.gov.sd
  658. 212.83.140.187 - www.mininfo.gov.sd
  659. #######################################################################################################################################
  660. mail.mininfo.gov.sd
  661. www.mininfo.gov.sd
  662. #######################################################################################################################################
  663. [*] Found SPF record:
  664. [*] v=spf1 mx a ~all
  665. [*] SPF record contains an All item: ~all
  666. [*] No DMARC record found. Looking for organizational record
  667. [+] No organizational DMARC record
  668. [+] Spoofing possible for mininfo.gov.sd!
  669. #######################################################################################################################################
  670. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 22:31 EDT
  671. Nmap scan report for mininfo.gov.sd (212.83.140.187)
  672. Host is up (0.17s latency).
  673. rDNS record for 212.83.140.187: ns51.mazinhost.net
  674. Not shown: 2 filtered ports
  675. PORT STATE SERVICE
  676. 53/udp open|filtered domain
  677. 67/udp open|filtered dhcps
  678. 68/udp open|filtered dhcpc
  679. 69/udp open|filtered tftp
  680. 88/udp open|filtered kerberos-sec
  681. 123/udp open|filtered ntp
  682. 139/udp open|filtered netbios-ssn
  683. 161/udp open|filtered snmp
  684. 162/udp open|filtered snmptrap
  685. 389/udp open|filtered ldap
  686. 520/udp open|filtered route
  687. 2049/udp open|filtered nfs
  688.  
  689. Nmap done: 1 IP address (1 host up) scanned in 2.89 seconds
  690. #######################################################################################################################################
  691. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:10 EDT
  692. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  693. Host is up (0.23s latency).
  694. Not shown: 461 filtered ports, 3 closed ports
  695. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  696. PORT STATE SERVICE
  697. 21/tcp open ftp
  698. 22/tcp open ssh
  699. 53/tcp open domain
  700. 80/tcp open http
  701. 110/tcp open pop3
  702. 143/tcp open imap
  703. 443/tcp open https
  704. 465/tcp open smtps
  705. 587/tcp open submission
  706. 993/tcp open imaps
  707. 995/tcp open pop3s
  708. 8080/tcp open http-proxy
  709. #######################################################################################################################################
  710. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:10 EDT
  711. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  712. Host is up (0.18s latency).
  713. Not shown: 2 filtered ports
  714. PORT STATE SERVICE
  715. 53/udp open domain
  716. 67/udp open|filtered dhcps
  717. 68/udp open|filtered dhcpc
  718. 69/udp open|filtered tftp
  719. 88/udp open|filtered kerberos-sec
  720. 123/udp open|filtered ntp
  721. 139/udp open|filtered netbios-ssn
  722. 161/udp open|filtered snmp
  723. 162/udp open|filtered snmptrap
  724. 389/udp open|filtered ldap
  725. 520/udp open|filtered route
  726. 2049/udp open|filtered nfs
  727. #######################################################################################################################################
  728. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:10 EDT
  729. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  730. Host is up (0.24s latency).
  731.  
  732. PORT STATE SERVICE VERSION
  733. 21/tcp open ftp Pure-FTPd
  734. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  735. Device type: general purpose
  736. Running (JUST GUESSING): Linux 3.X|4.X|2.6.X (91%)
  737. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:2.6
  738. Aggressive OS guesses: Linux 3.11 - 4.1 (91%), Linux 4.4 (91%), Linux 3.2.0 (90%), Linux 3.16 (89%), Linux 3.13 (88%), Linux 2.6.18 - 2.6.22 (86%), Linux 3.10 - 3.16 (86%), Linux 3.10 - 3.12 (85%), Linux 3.10 - 4.11 (85%), Linux 3.12 (85%)
  739. No exact OS matches for host (test conditions non-ideal).
  740. Network Distance: 11 hops
  741.  
  742. TRACEROUTE (using port 21/tcp)
  743. HOP RTT ADDRESS
  744. 1 170.35 ms 10.251.200.1
  745. 2 172.10 ms 213.184.122.97
  746. 3 170.71 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  747. 4 170.94 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  748. 5 220.72 ms bzq-114-65-1.cust.bezeqint.net (192.114.65.1)
  749. 6 218.35 ms bzq-161-218.pop.bezeqint.net (212.179.161.218)
  750. 7 242.17 ms 80.249.212.93
  751. 8 245.16 ms 51.158.8.185
  752. 9 255.59 ms 195.154.2.103
  753. 10 247.89 ms 51.158.8.185
  754. 11 242.22 ms ns51.mazinhost.net (212.83.140.187)
  755. #######################################################################################################################################
  756. # general
  757. (gen) banner: SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.4
  758. (gen) software: OpenSSH 7.2p2
  759. (gen) compatibility: OpenSSH 7.2+, Dropbear SSH 2013.62+
  760. (gen) compression: enabled ([email protected])
  761.  
  762. # key exchange algorithms
  763. (kex) [email protected] -- [info] available since OpenSSH 6.5, Dropbear SSH 2013.62
  764. (kex) ecdh-sha2-nistp256 -- [fail] using weak elliptic curves
  765. `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
  766. (kex) ecdh-sha2-nistp384 -- [fail] using weak elliptic curves
  767. `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
  768. (kex) ecdh-sha2-nistp521 -- [fail] using weak elliptic curves
  769. `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
  770. (kex) diffie-hellman-group-exchange-sha256 -- [warn] using custom size modulus (possibly weak)
  771. `- [info] available since OpenSSH 4.4
  772. (kex) diffie-hellman-group14-sha1 -- [warn] using weak hashing algorithm
  773. `- [info] available since OpenSSH 3.9, Dropbear SSH 0.53
  774.  
  775. # host-key algorithms
  776. (key) ssh-rsa -- [info] available since OpenSSH 2.5.0, Dropbear SSH 0.28
  777. (key) rsa-sha2-512 -- [info] available since OpenSSH 7.2
  778. (key) rsa-sha2-256 -- [info] available since OpenSSH 7.2
  779. (key) ecdsa-sha2-nistp256 -- [fail] using weak elliptic curves
  780. `- [warn] using weak random number generator could reveal the key
  781. `- [info] available since OpenSSH 5.7, Dropbear SSH 2013.62
  782. (key) ssh-ed25519 -- [info] available since OpenSSH 6.5
  783.  
  784. # encryption algorithms (ciphers)
  785. (enc) [email protected] -- [info] available since OpenSSH 6.5
  786. `- [info] default cipher since OpenSSH 6.9.
  787. (enc) aes128-ctr -- [info] available since OpenSSH 3.7, Dropbear SSH 0.52
  788. (enc) aes192-ctr -- [info] available since OpenSSH 3.7
  789. (enc) aes256-ctr -- [info] available since OpenSSH 3.7, Dropbear SSH 0.52
  790. (enc) [email protected] -- [info] available since OpenSSH 6.2
  791. (enc) [email protected] -- [info] available since OpenSSH 6.2
  792.  
  793. # message authentication code algorithms
  794. (mac) [email protected] -- [warn] using small 64-bit tag size
  795. `- [info] available since OpenSSH 6.2
  796. (mac) [email protected] -- [info] available since OpenSSH 6.2
  797. (mac) [email protected] -- [info] available since OpenSSH 6.2
  798. (mac) [email protected] -- [info] available since OpenSSH 6.2
  799. (mac) [email protected] -- [warn] using weak hashing algorithm
  800. `- [info] available since OpenSSH 6.2
  801. (mac) [email protected] -- [warn] using encrypt-and-MAC mode
  802. `- [warn] using small 64-bit tag size
  803. `- [info] available since OpenSSH 4.7
  804. (mac) [email protected] -- [warn] using encrypt-and-MAC mode
  805. `- [info] available since OpenSSH 6.2
  806. (mac) hmac-sha2-256 -- [warn] using encrypt-and-MAC mode
  807. `- [info] available since OpenSSH 5.9, Dropbear SSH 2013.56
  808. (mac) hmac-sha2-512 -- [warn] using encrypt-and-MAC mode
  809. `- [info] available since OpenSSH 5.9, Dropbear SSH 2013.56
  810. (mac) hmac-sha1 -- [warn] using encrypt-and-MAC mode
  811. `- [warn] using weak hashing algorithm
  812. `- [info] available since OpenSSH 2.1.0, Dropbear SSH 0.28
  813.  
  814. # algorithm recommendations (for OpenSSH 7.2)
  815. (rec) -ecdh-sha2-nistp521 -- kex algorithm to remove
  816. (rec) -ecdh-sha2-nistp384 -- kex algorithm to remove
  817. (rec) -ecdh-sha2-nistp256 -- kex algorithm to remove
  818. (rec) -diffie-hellman-group14-sha1 -- kex algorithm to remove
  819. (rec) -ecdsa-sha2-nistp256 -- key algorithm to remove
  820. (rec) -hmac-sha2-512 -- mac algorithm to remove
  821. (rec) [email protected] -- mac algorithm to remove
  822. (rec) -hmac-sha2-256 -- mac algorithm to remove
  823. (rec) [email protected] -- mac algorithm to remove
  824. (rec) -hmac-sha1 -- mac algorithm to remove
  825. (rec) [email protected] -- mac algorithm to remove
  826. (rec) [email protected] -- mac algorithm to remove
  827. #######################################################################################################################################
  828. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:21 EDT
  829. NSE: [ssh-run] Failed to specify credentials and command to run.
  830. NSE: [ssh-brute] Trying username/password pair: root:root
  831. NSE: [ssh-brute] Trying username/password pair: admin:admin
  832. NSE: [ssh-brute] Trying username/password pair: administrator:administrator
  833. NSE: [ssh-brute] Trying username/password pair: webadmin:webadmin
  834. NSE: [ssh-brute] Trying username/password pair: sysadmin:sysadmin
  835. NSE: [ssh-brute] Trying username/password pair: netadmin:netadmin
  836. NSE: [ssh-brute] Trying username/password pair: guest:guest
  837. NSE: [ssh-brute] Trying username/password pair: user:user
  838. NSE: [ssh-brute] Trying username/password pair: web:web
  839. NSE: [ssh-brute] Trying username/password pair: test:test
  840. NSE: [ssh-brute] Trying username/password pair: root:
  841. NSE: [ssh-brute] Trying username/password pair: admin:
  842. NSE: [ssh-brute] Trying username/password pair: administrator:
  843. NSE: [ssh-brute] Trying username/password pair: webadmin:
  844. NSE: [ssh-brute] Trying username/password pair: sysadmin:
  845. NSE: [ssh-brute] Trying username/password pair: netadmin:
  846. NSE: [ssh-brute] Trying username/password pair: guest:
  847. NSE: [ssh-brute] Trying username/password pair: user:
  848. NSE: [ssh-brute] Trying username/password pair: web:
  849. NSE: [ssh-brute] Trying username/password pair: test:
  850. NSE: [ssh-brute] Trying username/password pair: root:123456
  851. NSE: [ssh-brute] Trying username/password pair: admin:123456
  852. NSE: [ssh-brute] Trying username/password pair: administrator:123456
  853. NSE: [ssh-brute] Trying username/password pair: webadmin:123456
  854. NSE: [ssh-brute] Trying username/password pair: sysadmin:123456
  855. NSE: [ssh-brute] Trying username/password pair: netadmin:123456
  856. NSE: [ssh-brute] Trying username/password pair: guest:123456
  857. NSE: [ssh-brute] Trying username/password pair: user:123456
  858. NSE: [ssh-brute] Trying username/password pair: web:123456
  859. NSE: [ssh-brute] Trying username/password pair: test:123456
  860. NSE: [ssh-brute] Trying username/password pair: root:12345
  861. NSE: [ssh-brute] Trying username/password pair: admin:12345
  862. NSE: [ssh-brute] Trying username/password pair: administrator:12345
  863. NSE: [ssh-brute] Trying username/password pair: webadmin:12345
  864. NSE: [ssh-brute] Trying username/password pair: sysadmin:12345
  865. NSE: [ssh-brute] Trying username/password pair: netadmin:12345
  866. NSE: [ssh-brute] Trying username/password pair: guest:12345
  867. NSE: [ssh-brute] Trying username/password pair: user:12345
  868. NSE: [ssh-brute] Trying username/password pair: web:12345
  869. NSE: [ssh-brute] Trying username/password pair: test:12345
  870. NSE: [ssh-brute] Trying username/password pair: root:123456789
  871. NSE: [ssh-brute] Trying username/password pair: admin:123456789
  872. NSE: [ssh-brute] Trying username/password pair: administrator:123456789
  873. NSE: [ssh-brute] Trying username/password pair: webadmin:123456789
  874. NSE: [ssh-brute] Trying username/password pair: sysadmin:123456789
  875. NSE: [ssh-brute] Trying username/password pair: netadmin:123456789
  876. NSE: [ssh-brute] Trying username/password pair: guest:123456789
  877. NSE: [ssh-brute] Trying username/password pair: user:123456789
  878. NSE: [ssh-brute] Trying username/password pair: web:123456789
  879. NSE: [ssh-brute] Trying username/password pair: test:123456789
  880. NSE: [ssh-brute] Trying username/password pair: root:password
  881. NSE: [ssh-brute] Trying username/password pair: admin:password
  882. NSE: [ssh-brute] Trying username/password pair: administrator:password
  883. NSE: [ssh-brute] Trying username/password pair: webadmin:password
  884. NSE: [ssh-brute] Trying username/password pair: sysadmin:password
  885. NSE: [ssh-brute] Trying username/password pair: netadmin:password
  886. NSE: [ssh-brute] Trying username/password pair: guest:password
  887. NSE: [ssh-brute] Trying username/password pair: user:password
  888. NSE: [ssh-brute] Trying username/password pair: web:password
  889. NSE: [ssh-brute] Trying username/password pair: test:password
  890. NSE: [ssh-brute] Trying username/password pair: root:iloveyou
  891. NSE: [ssh-brute] Trying username/password pair: admin:iloveyou
  892. NSE: [ssh-brute] Trying username/password pair: administrator:iloveyou
  893. NSE: [ssh-brute] Trying username/password pair: webadmin:iloveyou
  894. NSE: [ssh-brute] Trying username/password pair: sysadmin:iloveyou
  895. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  896. Host is up (0.24s latency).
  897.  
  898. PORT STATE SERVICE VERSION
  899. 22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.4 (Ubuntu Linux; protocol 2.0)
  900. | ssh-auth-methods:
  901. | Supported authentication methods:
  902. | publickey
  903. |_ password
  904. | ssh-hostkey:
  905. | 2048 af:4b:11:25:a5:bb:ab:68:84:95:0d:08:c2:07:2c:b9 (RSA)
  906. | 256 d1:31:9e:37:4b:70:f9:16:1e:e6:49:68:2d:d8:c8:bf (ECDSA)
  907. |_ 256 fc:ca:4c:d1:7c:1a:80:3c:17:66:4f:bc:ff:73:32:fd (ED25519)
  908. | ssh-publickey-acceptance:
  909. |_ Accepted Public Keys: No public keys accepted
  910. |_ssh-run: Failed to specify credentials and command to run.
  911. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  912. Device type: general purpose
  913. Running (JUST GUESSING): Linux 3.X|4.X|2.6.X (91%)
  914. OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:2.6
  915. Aggressive OS guesses: Linux 3.11 - 4.1 (91%), Linux 4.4 (91%), Linux 3.2.0 (90%), Linux 3.16 (89%), Linux 3.13 (88%), Linux 2.6.18 - 2.6.22 (86%), Linux 3.10 - 3.12 (85%), Linux 3.10 - 4.11 (85%), Linux 3.12 (85%), Linux 3.13 or 4.2 (85%)
  916. No exact OS matches for host (test conditions non-ideal).
  917. Network Distance: 11 hops
  918. Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
  919.  
  920. TRACEROUTE (using port 22/tcp)
  921. HOP RTT ADDRESS
  922. 1 173.95 ms 10.251.200.1
  923. 2 174.94 ms 213.184.122.97
  924. 3 173.98 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  925. 4 176.56 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  926. 5 225.59 ms bzq-179-124-153.cust.bezeqint.net (212.179.124.153)
  927. 6 217.37 ms bzq-179-124-34.cust.bezeqint.net (212.179.124.34)
  928. 7 239.59 ms 195.154.2.103
  929. 8 241.59 ms 195.154.2.103
  930. 9 243.56 ms 195.154.2.103
  931. 10 243.62 ms 49e-s202b-1-dc2-a9k1.dc2.poneytelecom.eu (195.154.1.29)
  932. 11 241.86 ms ns51.mazinhost.net (212.83.140.187)
  933. #######################################################################################################################################
  934. USER_FILE => /usr/share/brutex/wordlists/simple-users.txt
  935. RHOSTS => 212.83.140.187
  936. RHOST => 212.83.140.187
  937. [*] 212.83.140.187:22 - SSH - Using malformed packet technique
  938. [*] 212.83.140.187:22 - SSH - Starting scan
  939. [-] 212.83.140.187:22 - SSH - User 'admin' on could not connect
  940. [-] 212.83.140.187:22 - SSH - User 'administrator' on could not connect
  941. [-] 212.83.140.187:22 - SSH - User 'anonymous' on could not connect
  942. [-] 212.83.140.187:22 - SSH - User 'backup' on could not connect
  943. [-] 212.83.140.187:22 - SSH - User 'bee' on could not connect
  944. [-] 212.83.140.187:22 - SSH - User 'ftp' on could not connect
  945. [-] 212.83.140.187:22 - SSH - User 'guest' on could not connect
  946. [-] 212.83.140.187:22 - SSH - User 'GUEST' on could not connect
  947. [-] 212.83.140.187:22 - SSH - User 'info' on could not connect
  948. [-] 212.83.140.187:22 - SSH - User 'mail' on could not connect
  949. [-] 212.83.140.187:22 - SSH - User 'mailadmin' on could not connect
  950. [-] 212.83.140.187:22 - SSH - User 'msfadmin' on could not connect
  951. [-] 212.83.140.187:22 - SSH - User 'mysql' on could not connect
  952. [-] 212.83.140.187:22 - SSH - User 'nobody' on could not connect
  953. [-] 212.83.140.187:22 - SSH - User 'oracle' on could not connect
  954. [-] 212.83.140.187:22 - SSH - User 'owaspbwa' on could not connect
  955. [-] 212.83.140.187:22 - SSH - User 'postfix' on could not connect
  956. [-] 212.83.140.187:22 - SSH - User 'postgres' on could not connect
  957. [-] 212.83.140.187:22 - SSH - User 'private' on could not connect
  958. [-] 212.83.140.187:22 - SSH - User 'proftpd' on could not connect
  959. [-] 212.83.140.187:22 - SSH - User 'public' on could not connect
  960. [-] 212.83.140.187:22 - SSH - User 'root' on could not connect
  961. [-] 212.83.140.187:22 - SSH - User 'superadmin' on could not connect
  962. [-] 212.83.140.187:22 - SSH - User 'support' on could not connect
  963. [-] 212.83.140.187:22 - SSH - User 'sys' on could not connect
  964. [-] 212.83.140.187:22 - SSH - User 'system' on could not connect
  965. [-] 212.83.140.187:22 - SSH - User 'systemadmin' on could not connect
  966. [-] 212.83.140.187:22 - SSH - User 'systemadministrator' on could not connect
  967. [-] 212.83.140.187:22 - SSH - User 'test' on could not connect
  968. [-] 212.83.140.187:22 - SSH - User 'tomcat' on could not connect
  969. [-] 212.83.140.187:22 - SSH - User 'user' on could not connect
  970. [-] 212.83.140.187:22 - SSH - User 'webmaster' on could not connect
  971. [-] 212.83.140.187:22 - SSH - User 'www-data' on could not connect
  972. [-] 212.83.140.187:22 - SSH - User 'Fortimanager_Access' on could not connect
  973. [*] Scanned 1 of 1 hosts (100% complete)
  974. [*] Auxiliary module execution completed
  975. #######################################################################################################################################
  976. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:52 EDT
  977. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  978. Host is up.
  979.  
  980. PORT STATE SERVICE VERSION
  981. 53/tcp filtered domain
  982. Too many fingerprints match this host to give specific OS details
  983.  
  984. Host script results:
  985. | dns-brute:
  986. | DNS Brute-force hostnames:
  987. | www.mazinhost.net - 162.251.82.251
  988. | ns1.mazinhost.net - 95.216.109.43
  989. | ns2.mazinhost.net - 95.216.109.43
  990. | ns3.mazinhost.net - 95.216.109.43
  991. | smtp.mazinhost.net - 208.91.198.143
  992. | smtp.mazinhost.net - 208.91.199.223
  993. | smtp.mazinhost.net - 208.91.199.224
  994. |_ smtp.mazinhost.net - 208.91.199.225
  995.  
  996. TRACEROUTE (using proto 1/icmp)
  997. HOP RTT ADDRESS
  998. 1 167.60 ms 10.251.200.1
  999. 2 168.57 ms 213.184.122.97
  1000. 3 167.65 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  1001. 4 168.02 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  1002. 5 217.45 ms bzq-179-124-190.cust.bezeqint.net (212.179.124.190)
  1003. 6 228.10 ms 80.249.212.93
  1004. 7 242.26 ms 195.154.2.103
  1005. 8 243.84 ms 51.158.8.185
  1006. 9 241.46 ms 195.154.2.145
  1007. 10 ... 30
  1008. #######################################################################################################################################
  1009. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:52 EDT
  1010. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  1011. Host is up.
  1012.  
  1013. PORT STATE SERVICE VERSION
  1014. 67/udp open|filtered dhcps
  1015. |_dhcp-discover: ERROR: Script execution failed (use -d to debug)
  1016. Too many fingerprints match this host to give specific OS details
  1017.  
  1018. TRACEROUTE (using proto 1/icmp)
  1019. HOP RTT ADDRESS
  1020. 1 169.35 ms 10.251.200.1
  1021. 2 171.00 ms 213.184.122.97
  1022. 3 170.86 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  1023. 4 170.92 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  1024. 5 219.26 ms bzq-179-124-190.cust.bezeqint.net (212.179.124.190)
  1025. 6 228.64 ms 80.249.212.93
  1026. 7 243.03 ms 195.154.2.103
  1027. 8 244.25 ms 51.158.8.185
  1028. 9 241.89 ms 195.154.2.145
  1029. 10 ... 30
  1030. #######################################################################################################################################
  1031. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:54 EDT
  1032. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  1033. Host is up.
  1034.  
  1035. PORT STATE SERVICE VERSION
  1036. 68/udp open|filtered dhcpc
  1037. Too many fingerprints match this host to give specific OS details
  1038.  
  1039. TRACEROUTE (using proto 1/icmp)
  1040. HOP RTT ADDRESS
  1041. 1 172.86 ms 10.251.200.1
  1042. 2 174.04 ms 213.184.122.97
  1043. 3 167.87 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  1044. 4 168.09 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  1045. 5 217.90 ms bzq-179-124-190.cust.bezeqint.net (212.179.124.190)
  1046. 6 228.73 ms 80.249.212.93
  1047. 7 242.92 ms 195.154.2.103
  1048. 8 244.14 ms 51.158.8.185
  1049. 9 241.50 ms 195.154.2.145
  1050. 10 ... 30
  1051. #######################################################################################################################################
  1052. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 18:56 EDT
  1053. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  1054. Host is up.
  1055.  
  1056. PORT STATE SERVICE VERSION
  1057. 69/udp open|filtered tftp
  1058. Too many fingerprints match this host to give specific OS details
  1059.  
  1060. TRACEROUTE (using proto 1/icmp)
  1061. HOP RTT ADDRESS
  1062. 1 168.89 ms 10.251.200.1
  1063. 2 170.10 ms 213.184.122.97
  1064. 3 168.93 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  1065. 4 169.13 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  1066. 5 219.17 ms bzq-179-124-190.cust.bezeqint.net (212.179.124.190)
  1067. 6 229.40 ms 80.249.212.93
  1068. 7 243.39 ms 195.154.2.103
  1069. 8 244.78 ms 51.158.8.185
  1070. 9 242.62 ms 195.154.2.145
  1071. 10 ... 30
  1072. #######################################################################################################################################
  1073. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 19:02 EDT
  1074. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  1075. Host is up.
  1076.  
  1077. PORT STATE SERVICE VERSION
  1078. 123/udp open|filtered ntp
  1079. Too many fingerprints match this host to give specific OS details
  1080.  
  1081. TRACEROUTE (using proto 1/icmp)
  1082. HOP RTT ADDRESS
  1083. 1 167.24 ms 10.251.200.1
  1084. 2 168.25 ms 213.184.122.97
  1085. 3 167.29 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
  1086. 4 167.63 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
  1087. 5 217.46 ms bzq-179-124-190.cust.bezeqint.net (212.179.124.190)
  1088. 6 227.88 ms 80.249.212.93
  1089. 7 242.27 ms 195.154.2.103
  1090. 8 243.66 ms 51.158.8.185
  1091. 9 241.11 ms 195.154.2.145
  1092. 10 ... 30
  1093. #######################################################################################################################################
  1094. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 19:10 EDT
  1095. NSE: Loaded 148 scripts for scanning.
  1096. NSE: Script Pre-scanning.
  1097. NSE: Starting runlevel 1 (of 2) scan.
  1098. Initiating NSE at 19:10
  1099. Completed NSE at 19:10, 0.00s elapsed
  1100. NSE: Starting runlevel 2 (of 2) scan.
  1101. Initiating NSE at 19:10
  1102. Completed NSE at 19:10, 0.00s elapsed
  1103. Initiating Ping Scan at 19:10
  1104. Scanning 212.83.140.187 [4 ports]
  1105. Completed Ping Scan at 19:10, 2.04s elapsed (1 total hosts)
  1106. Nmap scan report for 212.83.140.187 [host down, received no-response]
  1107. NSE: Script Post-scanning.
  1108. NSE: Starting runlevel 1 (of 2) scan.
  1109. Initiating NSE at 19:10
  1110. Completed NSE at 19:10, 0.00s elapsed
  1111. NSE: Starting runlevel 2 (of 2) scan.
  1112. Initiating NSE at 19:10
  1113. Completed NSE at 19:10, 0.00s elapsed
  1114. Read data files from: /usr/bin/../share/nmap
  1115. Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
  1116. Nmap done: 1 IP address (0 hosts up) scanned in 2.51 seconds
  1117. Raw packets sent: 8 (304B) | Rcvd: 0 (0B)
  1118. #######################################################################################################################################
  1119. Starting Nmap 7.70 ( https://nmap.org ) at 2019-05-01 19:10 EDT
  1120. NSE: Loaded 148 scripts for scanning.
  1121. NSE: Script Pre-scanning.
  1122. Initiating NSE at 19:10
  1123. Completed NSE at 19:10, 0.00s elapsed
  1124. Initiating NSE at 19:10
  1125. Completed NSE at 19:10, 0.00s elapsed
  1126. Initiating Parallel DNS resolution of 1 host. at 19:10
  1127. Completed Parallel DNS resolution of 1 host. at 19:10, 0.03s elapsed
  1128. Initiating UDP Scan at 19:10
  1129. Scanning ns51.mazinhost.net (212.83.140.187) [14 ports]
  1130. Completed UDP Scan at 19:10, 2.58s elapsed (14 total ports)
  1131. Initiating Service scan at 19:10
  1132. Scanning 12 services on ns51.mazinhost.net (212.83.140.187)
  1133. Service scan Timing: About 8.33% done; ETC: 19:30 (0:17:58 remaining)
  1134. Completed Service scan at 19:12, 102.59s elapsed (12 services on 1 host)
  1135. Initiating OS detection (try #1) against ns51.mazinhost.net (212.83.140.187)
  1136. Retrying OS detection (try #2) against ns51.mazinhost.net (212.83.140.187)
  1137. Initiating Traceroute at 19:12
  1138. Completed Traceroute at 19:12, 7.22s elapsed
  1139. Initiating Parallel DNS resolution of 1 host. at 19:12
  1140. Completed Parallel DNS resolution of 1 host. at 19:12, 0.01s elapsed
  1141. NSE: Script scanning 212.83.140.187.
  1142. Initiating NSE at 19:12
  1143. Completed NSE at 19:12, 20.37s elapsed
  1144. Initiating NSE at 19:12
  1145. Completed NSE at 19:12, 1.32s elapsed
  1146. Nmap scan report for ns51.mazinhost.net (212.83.140.187)
  1147. Host is up (0.17s latency).
  1148.  
  1149. PORT STATE SERVICE VERSION
  1150. 53/udp open|filtered domain
  1151. 67/udp open|filtered dhcps
  1152. 68/udp open|filtered dhcpc
  1153. 69/udp open|filtered tftp
  1154. 88/udp open|filtered kerberos-sec
  1155. 123/udp open|filtered ntp
  1156. 137/udp filtered netbios-ns
  1157. 138/udp filtered netbios-dgm
  1158. 139/udp open|filtered netbios-ssn
  1159. 161/udp open|filtered snmp
  1160. 162/udp open|filtered snmptrap
  1161. 389/udp open|filtered ldap
  1162. 520/udp open|filtered route
  1163. 2049/udp open|filtered nfs
  1164. Too many fingerprints match this host to give specific OS details
  1165.  
  1166. TRACEROUTE (using port 137/udp)
  1167. HOP RTT ADDRESS
  1168. 1 167.91 ms 10.251.200.1
  1169. 2 ... 3
  1170. 4 167.58 ms 10.251.200.1
  1171. 5 167.87 ms 10.251.200.1
  1172. 6 167.86 ms 10.251.200.1
  1173. 7 167.85 ms 10.251.200.1
  1174. 8 167.84 ms 10.251.200.1
  1175. 9 167.84 ms 10.251.200.1
  1176. 10 167.86 ms 10.251.200.1
  1177. 11 ... 18
  1178. 19 167.19 ms 10.251.200.1
  1179. 20 167.29 ms 10.251.200.1
  1180. 21 166.74 ms 10.251.200.1
  1181. 22 ... 29
  1182. 30 168.18 ms 10.251.200.1
  1183.  
  1184. NSE: Script Post-scanning.
  1185. Initiating NSE at 19:12
  1186. Completed NSE at 19:12, 0.00s elapsed
  1187. Initiating NSE at 19:12
  1188. Completed NSE at 19:12, 0.00s elapsed
  1189. Read data files from: /usr/bin/../share/nmap
  1190. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  1191. Nmap done: 1 IP address (1 host up) scanned in 140.69 seconds
  1192. Raw packets sent: 148 (13.692KB) | Rcvd: 21 (2.284KB)
  1193. #######################################################################################################################################
  1194. [+] URL: http://mininfo.gov.sd/
  1195. [+] Started: Wed May 1 15:38:35 2019
  1196.  
  1197. Interesting Finding(s):
  1198.  
  1199. [+] http://mininfo.gov.sd/robots.txt
  1200. | Found By: Robots Txt (Aggressive Detection)
  1201. | Confidence: 100%
  1202.  
  1203. [+] http://mininfo.gov.sd/xmlrpc.php
  1204. | Found By: Link Tag (Passive Detection)
  1205. | Confidence: 100%
  1206. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  1207. | References:
  1208. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1209. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1210. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1211. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1212. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1213.  
  1214. [+] http://mininfo.gov.sd/wp-cron.php
  1215. | Found By: Direct Access (Aggressive Detection)
  1216. | Confidence: 60%
  1217. | References:
  1218. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1219. | - https://github.com/wpscanteam/wpscan/issues/1299
  1220.  
  1221. Fingerprinting the version - Time: 00:01:25 <=========> (346 / 346) 100.00% Time: 00:01:25
  1222. [+] WordPress version 5.1.1 identified (Latest, released on 2019-03-13).
  1223. | Detected By: Query Parameter In Install Page (Aggressive Detection)
  1224. | - http://mininfo.gov.sd/wp-includes/css/dashicons.min.css?ver=5.1.1
  1225. | Confirmed By: Unique Fingerprinting (Aggressive Detection)
  1226. | - http://mininfo.gov.sd/wp-admin/js/widgets/custom-html-widgets.js md5sum is 0c079b9a73b9cfc434e2188b5b9a2ce8
  1227.  
  1228. [+] WordPress theme in use: alyoum2
  1229. | Location: http://mininfo.gov.sd/wp-content/themes/alyoum2/
  1230. | [!] An error log file has been found: http://mininfo.gov.sd/wp-content/themes/alyoum2/error_log
  1231. | Style URL: http://mininfo.gov.sd/wp-content/themes/alyoum2/style.css
  1232. | Style Name: AlYoum Premium Blog/Magazine WordPress Theme
  1233. | Style URI: http://themeforest.net/user/Code125?ref=code125
  1234. | Description: AlYoum Premium Magazine & Blog WordPress Theme available on themeforest with many features and optio...
  1235. | Author: Code125
  1236. | Author URI: http://www.code125.com
  1237. |
  1238. | Detected By: Urls In Homepage (Passive Detection)
  1239. |
  1240. | Version: 5.9.2 (80% confidence)
  1241. | Detected By: Style (Passive Detection)
  1242. | - http://mininfo.gov.sd/wp-content/themes/alyoum2/style.css, Match: 'Version: 5.9.2'
  1243.  
  1244. [+] Enumerating All Plugins (via Passive Methods)
  1245. [+] Checking Plugin Versions (via Passive and Aggressive Methods)
  1246.  
  1247. [i] Plugin(s) Identified:
  1248.  
  1249. [+] gs-logo-slider
  1250. | Location: http://mininfo.gov.sd/wp-content/plugins/gs-logo-slider/
  1251. | Last Updated: 2019-01-17T11:16:00.000Z
  1252. | [!] The version is out of date, the latest version is 1.8.2
  1253. |
  1254. | Detected By: Urls In Homepage (Passive Detection)
  1255. |
  1256. | Version: 1.8.1 (100% confidence)
  1257. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1258. | - http://mininfo.gov.sd/wp-content/plugins/gs-logo-slider/readme.txt
  1259. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  1260. | - http://mininfo.gov.sd/wp-content/plugins/gs-logo-slider/readme.txt
  1261.  
  1262. [+] revslider
  1263. | Location: http://mininfo.gov.sd/wp-content/plugins/revslider/
  1264. |
  1265. | Detected By: Meta Generator (Passive Detection)
  1266. |
  1267. | Version: 5.3.0.2 (100% confidence)
  1268. | Detected By: Meta Generator (Passive Detection)
  1269. | - http://mininfo.gov.sd/, Match: 'Powered by Slider Revolution 5.3.0.2'
  1270. | Confirmed By: Release Log (Aggressive Detection)
  1271. | - http://mininfo.gov.sd/wp-content/plugins/revslider/release_log.html, Match: 'Version 5.3.0.2 StarPath (26th October 2016)'
  1272.  
  1273. [+] sitepress-multilingual-cms
  1274. | Location: http://mininfo.gov.sd/wp-content/plugins/sitepress-multilingual-cms/
  1275. | Latest Version: 2.0.4.1 (up to date)
  1276. | Last Updated: 2011-06-05T13:40:00.000Z
  1277. |
  1278. | Detected By: Urls In Homepage (Passive Detection)
  1279. | Confirmed By: Meta Generator (Passive Detection)
  1280. |
  1281. | Version: 4.1.3 (60% confidence)
  1282. | Detected By: Meta Generator (Passive Detection)
  1283. | - http://mininfo.gov.sd/, Match: 'WPML ver:4.1.3 stt'
  1284.  
  1285. [+] xt-visitor-counter
  1286. | Location: http://mininfo.gov.sd/wp-content/plugins/xt-visitor-counter/
  1287. | Latest Version: 1.4.1
  1288. | Last Updated: 2018-10-18T08:31:00.000Z
  1289. |
  1290. | Detected By: Urls In Homepage (Passive Detection)
  1291. |
  1292. | The version could not be determined.
  1293.  
  1294. [+] Enumerating Config Backups (via Passive and Aggressive Methods)
  1295. Checking Config Backups - Time: 00:00:01 <=============> (21 / 21) 100.00% Time: 00:00:01
  1296.  
  1297. [i] No Config Backups Found.
  1298.  
  1299.  
  1300. [+] Finished: Wed May 1 15:55:00 2019
  1301. [+] Requests Done: 250
  1302. [+] Cached Requests: 7
  1303. [+] Data Sent: 50.873 KB
  1304. [+] Data Received: 20.745 MB
  1305. [+] Memory used: 173.645 MB
  1306. [+] Elapsed time: 00:16:25
  1307. #######################################################################################################################################
  1308. [+] URL: http://mininfo.gov.sd/
  1309. [+] Started: Wed May 1 15:38:35 2019
  1310.  
  1311. Interesting Finding(s):
  1312.  
  1313. [+] http://mininfo.gov.sd/robots.txt
  1314. | Found By: Robots Txt (Aggressive Detection)
  1315. | Confidence: 100%
  1316.  
  1317. [+] http://mininfo.gov.sd/xmlrpc.php
  1318. | Found By: Link Tag (Passive Detection)
  1319. | Confidence: 100%
  1320. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  1321. | References:
  1322. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1323. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1324. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1325. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1326. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1327.  
  1328. [+] http://mininfo.gov.sd/wp-cron.php
  1329. | Found By: Direct Access (Aggressive Detection)
  1330. | Confidence: 60%
  1331. | References:
  1332. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1333. | - https://github.com/wpscanteam/wpscan/issues/1299
  1334.  
  1335. Fingerprinting the version - Time: 00:01:26 <> (346 / 346) 100.00% Time: 00:01:26
  1336. [+] WordPress version 5.1.1 identified (Latest, released on 2019-03-13).
  1337. | Detected By: Query Parameter In Install Page (Aggressive Detection)
  1338. | - http://mininfo.gov.sd/wp-includes/css/dashicons.min.css?ver=5.1.1
  1339. | Confirmed By: Unique Fingerprinting (Aggressive Detection)
  1340. | - http://mininfo.gov.sd/wp-admin/js/widgets/custom-html-widgets.js md5sum is 0c079b9a73b9cfc434e2188b5b9a2ce8
  1341.  
  1342. [+] WordPress theme in use: alyoum2
  1343. | Location: http://mininfo.gov.sd/wp-content/themes/alyoum2/
  1344. | [!] An error log file has been found: http://mininfo.gov.sd/wp-content/themes/alyoum2/error_log
  1345. | Style URL: http://mininfo.gov.sd/wp-content/themes/alyoum2/style.css
  1346. | Style Name: AlYoum Premium Blog/Magazine WordPress Theme
  1347. | Style URI: http://themeforest.net/user/Code125?ref=code125
  1348. | Description: AlYoum Premium Magazine & Blog WordPress Theme available on themeforest with many features and optio...
  1349. | Author: Code125
  1350. | Author URI: http://www.code125.com
  1351. |
  1352. | Detected By: Urls In Homepage (Passive Detection)
  1353. |
  1354. | Version: 5.9.2 (80% confidence)
  1355. | Detected By: Style (Passive Detection)
  1356. | - http://mininfo.gov.sd/wp-content/themes/alyoum2/style.css, Match: 'Version: 5.9.2'
  1357.  
  1358. [+] Enumerating Users (via Passive and Aggressive Methods)
  1359. Brute Forcing Author IDs - Time: 00:00:10 <==> (10 / 10) 100.00% Time: 00:00:10
  1360.  
  1361. [i] User(s) Identified:
  1362.  
  1363. [+] mazin
  1364. | Detected By: Author Posts - Author Pattern (Passive Detection)
  1365.  
  1366. [+] edit-min-sd
  1367. | Detected By: Author Posts - Author Pattern (Passive Detection)
  1368.  
  1369.  
  1370. [+] Finished: Wed May 1 15:53:47 2019
  1371. [+] Requests Done: 149
  1372. [+] Cached Requests: 81
  1373. [+] Data Sent: 30.478 KB
  1374. [+] Data Received: 1.25 MB
  1375. [+] Memory used: 88.637 MB
  1376. [+] Elapsed time: 00:15:11
  1377. #######################################################################################################################################
  1378. [+] URL: http://mininfo.gov.sd/
  1379. [+] Started: Wed May 1 15:57:27 2019
  1380.  
  1381. Interesting Finding(s):
  1382.  
  1383. [+] http://mininfo.gov.sd/robots.txt
  1384. | Found By: Robots Txt (Aggressive Detection)
  1385. | Confidence: 100%
  1386.  
  1387. [+] http://mininfo.gov.sd/xmlrpc.php
  1388. | Found By: Link Tag (Passive Detection)
  1389. | Confidence: 30%
  1390. | References:
  1391. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1392. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1393. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1394. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1395. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1396.  
  1397. [+] http://mininfo.gov.sd/wp-cron.php
  1398. | Found By: Direct Access (Aggressive Detection)
  1399. | Confidence: 60%
  1400. | References:
  1401. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1402. | - https://github.com/wpscanteam/wpscan/issues/1299
  1403.  
  1404. Fingerprinting the version - Time: 00:00:36 <=========> (346 / 346) 100.00% Time: 00:00:36
  1405. [+] WordPress version 5.1.1 identified (Latest, released on 2019-03-13).
  1406. | Detected By: Query Parameter In Install Page (Aggressive Detection)
  1407. | - http://mininfo.gov.sd/wp-includes/css/dashicons.min.css?ver=5.1.1
  1408. | Confirmed By: Unique Fingerprinting (Aggressive Detection)
  1409. | - http://mininfo.gov.sd/wp-admin/js/widgets/custom-html-widgets.js md5sum is 0c079b9a73b9cfc434e2188b5b9a2ce8
  1410.  
  1411. [+] WordPress theme in use: alyoum2
  1412. | Location: http://mininfo.gov.sd/wp-content/themes/alyoum2/
  1413. | [!] An error log file has been found: http://mininfo.gov.sd/wp-content/themes/alyoum2/error_log
  1414. | Style URL: http://mininfo.gov.sd/wp-content/themes/alyoum2/style.css
  1415. | Style Name: AlYoum Premium Blog/Magazine WordPress Theme
  1416. | Style URI: http://themeforest.net/user/Code125?ref=code125
  1417. | Description: AlYoum Premium Magazine & Blog WordPress Theme available on themeforest with many features and optio...
  1418. | Author: Code125
  1419. | Author URI: http://www.code125.com
  1420. |
  1421. | Detected By: Urls In Homepage (Passive Detection)
  1422. |
  1423. | Version: 5.9.2 (80% confidence)
  1424. | Detected By: Style (Passive Detection)
  1425. | - http://mininfo.gov.sd/wp-content/themes/alyoum2/style.css, Match: 'Version: 5.9.2'
  1426.  
  1427. [+] Enumerating Users (via Passive and Aggressive Methods)
  1428. Brute Forcing Author IDs - Time: 00:00:03 <============> (10 / 10) 100.00% Time: 00:00:03
  1429.  
  1430. [i] User(s) Identified:
  1431.  
  1432. [+] mazin
  1433. | Detected By: Author Posts - Author Pattern (Passive Detection)
  1434.  
  1435. [+] edit-min-sd
  1436. | Detected By: Author Posts - Author Pattern (Passive Detection)
  1437.  
  1438.  
  1439. [+] Finished: Wed May 1 16:12:22 2019
  1440. [+] Requests Done: 214
  1441. [+] Cached Requests: 7
  1442. [+] Data Sent: 44.524 KB
  1443. [+] Data Received: 4.377 MB
  1444. [+] Memory used: 89.316 MB
  1445. [+] Elapsed time: 00:14:55
  1446. #######################################################################################################################################
  1447. [-] Date & Time: 01/05/2019 15:38:19
  1448. [I] Threads: 5
  1449. [-] Target: http://mininfo.gov.sd (212.83.140.187)
  1450. [M] Website Not in HTTPS: http://mininfo.gov.sd
  1451. [L] X-Frame-Options: Not Enforced
  1452. [I] Strict-Transport-Security: Not Enforced
  1453. [I] X-Content-Security-Policy: Not Enforced
  1454. [I] X-Content-Type-Options: Not Enforced
  1455. [L] Robots.txt Found: http://mininfo.gov.sd/robots.txt
  1456. [I] CMS Detection: WordPress
  1457. [I] Wordpress Theme: alyoum2
  1458. [-] WordPress usernames identified:
  1459. [M] وزارة الإعلام
  1460. [M] XML-RPC services are enabled
  1461. [I] Autocomplete Off Not Found: http://mininfo.gov.sd/wp-login.php
  1462. [-] Default WordPress Files:
  1463. [I] http://mininfo.gov.sd/license.txt
  1464. [I] http://mininfo.gov.sd/wp-content/themes/twentyfifteen/genericons/COPYING.txt
  1465. [I] http://mininfo.gov.sd/wp-content/themes/twentyfifteen/genericons/LICENSE.txt
  1466. [I] http://mininfo.gov.sd/wp-content/themes/twentyfifteen/readme.txt
  1467. [I] http://mininfo.gov.sd/wp-content/themes/twentynineteen/readme.txt
  1468. [I] http://mininfo.gov.sd/wp-content/themes/twentyseventeen/README.txt
  1469. [I] http://mininfo.gov.sd/wp-content/themes/twentysixteen/genericons/COPYING.txt
  1470. [I] http://mininfo.gov.sd/wp-content/themes/twentysixteen/genericons/LICENSE.txt
  1471. [I] http://mininfo.gov.sd/wp-content/themes/twentysixteen/readme.txt
  1472. [I] http://mininfo.gov.sd/wp-includes/ID3/license.commercial.txt
  1473. [I] http://mininfo.gov.sd/wp-includes/ID3/license.txt
  1474. [I] http://mininfo.gov.sd/wp-includes/ID3/readme.txt
  1475. [I] http://mininfo.gov.sd/wp-includes/images/crystal/license.txt
  1476. [I] http://mininfo.gov.sd/wp-includes/js/plupload/license.txt
  1477. [I] http://mininfo.gov.sd/wp-includes/js/swfupload/license.txt
  1478. [I] http://mininfo.gov.sd/wp-includes/js/tinymce/license.txt
  1479. [-] Searching Wordpress Plugins ...
  1480. [I] "+plugin+"
  1481. [I] $plugin
  1482. [I] Enigma2.php?boarddir=http:
  1483. [I] adrotate
  1484. [M] EDB-ID: 17888 "WordPress Plugin AdRotate 3.6.5 - SQL Injection"
  1485. [M] EDB-ID: 18114 "WordPress Plugin AdRotate 3.6.6 - SQL Injection"
  1486. [M] EDB-ID: 31834 "WordPress Plugin AdRotate 3.9.4 - 'clicktracker.ph?track' SQL Injection"
  1487. [I] ads-box
  1488. [M] EDB-ID: 38060 "WordPress Plugin Ads Box - 'count' SQL Injection"
  1489. [I] all-in-one-wp-security-and-firewall
  1490. [M] EDB-ID: 34854 "WordPress Plugin All In One WP Security & Firewall 3.8.3 - Persistent Cross-Site Scripting"
  1491. [I] feed
  1492. [M] EDB-ID: 38624 "WordPress Plugin WP Feed - 'nid' SQL Injection"
  1493. [I] firestats
  1494. [M] EDB-ID: 14308 "WordPress Plugin Firestats - Remote Configuration File Download"
  1495. [M] EDB-ID: 33367 "WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabilities (1)"
  1496. [M] EDB-ID: 33368 "WordPress Plugin Firestats 1.0.2 - Multiple Cross-Site Scripting / Authentication Bypass Vulnerabilities (2)"
  1497. [I] gs-logo-slider v1.8.1
  1498. [I] revslider
  1499. [I] simple-ads-manager
  1500. [M] EDB-ID: 36613 "WordPress Plugin Simple Ads Manager - Multiple SQL Injections"
  1501. [M] EDB-ID: 36614 "WordPress Plugin Simple Ads Manager 2.5.94 - Arbitrary File Upload"
  1502. [M] EDB-ID: 36615 "WordPress Plugin Simple Ads Manager - Information Disclosure"
  1503. [M] EDB-ID: 39133 "WordPress Plugin Simple Ads Manager 2.9.4.116 - SQL Injection"
  1504. [I] sitepress-multilingual-cms
  1505. [I] wp-bannerize
  1506. [M] EDB-ID: 17764 "WordPress Plugin Bannerize 2.8.6 - SQL Injection"
  1507. [M] EDB-ID: 17906 "WordPress Plugin Bannerize 2.8.7 - SQL Injection"
  1508. [M] EDB-ID: 36193 "WordPress Plugin WP Bannerize 2.8.7 - 'ajax_sorter.php' SQL Injection"
  1509. [I] xt-visitor-counter
  1510. [I] Checking for Directory Listing Enabled ...
  1511. [-] Date & Time: 01/05/2019 16:05:08
  1512. [-] Completed in: 0:26:49
  1513. ######################################################################################################################################
  1514. --------------------------------------------------------------------------------------------------------------------------------------
  1515. + Target IP: 212.83.140.187
  1516. + Target Hostname: mininfo.gov.sd
  1517. + Target Port: 80
  1518. + Start Time: 2019-05-01 16:39:01 (GMT-4)
  1519. ---------------------------------------------------------------------------------------------------------------------------------------
  1520. + Server: No banner retrieved
  1521. + The anti-clickjacking X-Frame-Options header is not present.
  1522. + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
  1523. + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
  1524. + Uncommon header 'x-squid-error' found, with contents: ERR_INVALID_URL 0
  1525. + ERROR: Error limit (20) reached for host, giving up. Last error: error reading HTTP response
  1526. + Scan terminated: 20 error(s) and 4 item(s) reported on remote host
  1527. + End Time: 2019-05-01 16:48:27 (GMT-4) (566 seconds)
  1528. ---------------------------------------------------------------------------------------------------------------------------------------
  1529. #######################################################################################################################################
  1530. Anonymous JTSEC #OpSudan Full Recon #65
Advertisement
Add Comment
Please, Sign In to add comment