Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Channel4.COM - JOBS/WEB APPLICATION FIREWALL SERVER - Leaked..!!
- (ATTACK NON-INTRUSIVE) - WAF INFO/SSL-TLS/GOOGLE AND RESTRICTED INFO
- PROJECT DEDICATION: PROJECT SARADIYEL (http://en.wikipedia.org/wiki/Uthuwankande_Soora_Saradiyel)
- EXCLUSIVE FROM - Anonymous Sri Lanka
- WWW.CHANNEL4.COM -----> Servers Fuck3D and Bust3D
- Primary Server Data Leak with Transferring (Data Leak)....!!
- Hail to Anonymous, Lulzsec and Operation Anti-Sec...
- THIS ATTACK AGAINST THE DIRTIEST THINGS AGAINST THE SRI LANKA BY CHANNEL-4 .........!!!!!
- SERVER: jobs.channel4.com (89.234.58.1)
- 80/tcp open http syn-ack
- |
- |_http-title: Channel 4 : Current Vacancies - Current vacancies
- |_http-methods: No Allow or Public header in OPTIONS response (status code 404)
- | http-waf-detect: IDS/IPS/WAF detected:
- |_89.234.58.1:80/?p4yl04d3=<script>alert(document.cookie)</script>
- | http-headers:
- | Content-Type: text/html; charset=utf-8
- | Content-Length: 18654
- | Date: Fri, 16 Mar 2012 13:13:04 GMT
- | X-Powered-By: ASP.NET
- | Cache-Control: private
- |
- |_ (Request type: HEAD)
- |
- | http-affiliate-id:
- |_ Google Analytics ID: UA-3576948-15
- |
- | http-php-version: Logo query returned unknown hash 1e433f48854ee3ca587b7254c799d52f
- |_Credits query returned unknown hash 1e433f48854ee3ca587b7254c799d52f
- |
- | http-enum:
- | /robots.txt: Robots file
- |_ /Pages/Default.aspx: MS Sharepoint
- 443/tcp open https syn-ack
- |
- | ssl-cert: Subject:
- commonName=jobs.channel4.com/organizationName=jobs.channel4.com/countryName=GB/serialNumber=IfMGSkA28HJoRNYsKTX1zyYk80ekVsNr/organizational
- UnitName=Domain Control Validated - RapidSSL(R)
- | Issuer: commonName=RapidSSL CA/organizationName=GeoTrust, Inc./countryName=US
- | Public Key type: rsa
- | Public Key bits: 1024
- | Not valid before: 2011-12-28 22:43:47
- | Not valid after: 2013-01-30 02:10:53
- | MD5: fac6 a8a5 ac1c 1a18 245d cc1f 8d94 29c5
- | SHA-1: ca62 14fd da90 68d1 4d85 6571 3b7a 8831 5338 3cea
- | -----BEGIN CERTIFICATE-----
- | MIIEUDCCAzigAwIBAgIDBI+HMA0GCSqGSIb3DQEBBQUAMDwxCzAJBgNVBAYTAlVT
- | MRcwFQYDVQQKEw5HZW9UcnVzdCwgSW5jLjEUMBIGA1UEAxMLUmFwaWRTU0wgQ0Ew
- | HhcNMTExMjI4MjI0MzQ3WhcNMTMwMTMwMDIxMDUzWjCB6TEpMCcGA1UEBRMgSWZN
- | R1NrQTI4SEpvUk5Zc0tUWDF6eVlrODBla1ZzTnIxCzAJBgNVBAYTAkdCMRowGAYD
- | VQQKExFqb2JzLmNoYW5uZWw0LmNvbTETMBEGA1UECxMKR1QyMDQ3MjAwODExMC8G
- | A1UECxMoU2VlIHd3dy5yYXBpZHNzbC5jb20vcmVzb3VyY2VzL2NwcyAoYykxMTEv
- | MC0GA1UECxMmRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkIC0gUmFwaWRTU0woUikx
- | GjAYBgNVBAMTEWpvYnMuY2hhbm5lbDQuY29tMIGfMA0GCSqGSIb3DQEBAQUAA4GN
- | ADCBiQKBgQCv8gep1P8udICZVVPa/XWj1iuuUEyZPcgTkIkeRaxnrmAdSXtT9CEL
- | Djhco859SEzhU166KA290fmhRFZVJmKlzrQHFfzXzghx+/ZRC4hSdSe3Gt+dO3bt
- | 5eHPcMv6trFSSv6A08sYVPjJhPa21rDROZUbvfhfTONEvAFgnmddlQIDAQABo4IB
- | LzCCASswHwYDVR0jBBgwFoAUa2k9ahhCSt2PAmU5/TUkhniRFjAwDgYDVR0PAQH/
- | BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAcBgNVHREEFTAT
- | ghFqb2JzLmNoYW5uZWw0LmNvbTBDBgNVHR8EPDA6MDigNqA0hjJodHRwOi8vcmFw
- | aWRzc2wtY3JsLmdlb3RydXN0LmNvbS9jcmxzL3JhcGlkc3NsLmNybDAdBgNVHQ4E
- | FgQUsOujljuC33BYvs/Bxa84UzpNjYowDAYDVR0TAQH/BAIwADBJBggrBgEFBQcB
- | AQQ9MDswOQYIKwYBBQUHMAKGLWh0dHA6Ly9yYXBpZHNzbC1haWEuZ2VvdHJ1c3Qu
- | Y29tL3JhcGlkc3NsLmNydDANBgkqhkiG9w0BAQUFAAOCAQEAQzbr54qDiLaXJl3n
- | m70yNI2CDZEZJ154BUXWKPvcFtirKN2hjGvbGbJ2ix08UUAqIHA7AVVb4tZAQDtd
- | pHmVXlTSf3SB6k0UnQYJ/rIFsx+ov1uBuGG/sbIgrgygE9VEgF1ARIAn/YueT75C
- | iH2P+Dp+iZwE+oS0zPp0spjhI7PxLAVfqD6i4NOO0KgzcEscGFIqJ8rpWzQI6vfH
- | nvq5C6LlbI81BX53r6ZQIDIFl1FeUcb0phYdzMlT05DX//+dh/bz7cVMbzjdaLbW
- | b0ds2VnJZn0AODsx02D6olGkUCk0orzX+w6LepB6DJFUe2uUhgnyESbvYYcpn9wd
- | PhY4Pg==
- |_-----END CERTIFICATE-----
- |
- |_/
- | http-php-version: Logo query returned unknown hash 3864edfa2124069a3c041227ec03efb9
- |_Credits query returned unknown hash dee0feda8b227569785b8302208e646a
- |
- | http-title: Object moved
- |_Did not follow redirect to http://89.234.58.1/Default.aspx
- |
- | http-waf-detect: IDS/IPS/WAF detected:
- |_89.234.58.1:443/?p4yl04d3=<script>alert(document.cookie)</script>
- | http-headers:
- | Cache-Control: private
- | Content-Length: 148
- | Content-Type: text/html; charset=utf-8
- | Location: http://89.234.58.1/Default.aspx
- | X-Powered-By: ASP.NET
- | Date: Fri, 16 Mar 2012 13:13:28 GMT
- | Connection: close
- |
- |_ (Request type: GET)
- |
- | ssl-enum-ciphers:
- | SSLv3
- | Ciphers (3)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- | TLSv1.0
- | Ciphers (3)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- |_ Least strength = unknown strength
- | http-enum:
- | /admin/: Possible admin folder
- | /admin/login.aspx: Possible admin folder
- | /Admin/: Possible admin folder
- |_ /robots.txt: Robots file
- Host script results:
- |
- |_path-mtu: PMTU == 1500
- | asn-query:
- | BGP: 89.234.0.0/18 | Country: GB
- | Origin AS: 15395 - UK Rackspace
- |_ Peer AS: 174 3257 3356 6461 6939 8928
- | whois: Record found at whois.ripe.net
- | inetnum: 89.234.0.0 - 89.234.63.255
- | netname: UK-RACKSPACE-20060517
- | descr: Rackspace.com
- | country: GB
- | orgname: Rackspace.com
- | organisation: ORG-RA33-RIPE
- | email: hostmaster@rackspace.com
- | role: Rackspace Managed Hosting Contact Role
- | email: hostmaster@rackspace.com
- | person: Dennis Boline
- |_email: db-ripe@rackspace.com
- | ip-geolocation-geobytes:
- | 89.234.58.1
- | coordinates (lat,lon): 41.865,-87.6718
- |_ city: Chicago, Illinois, United States
- |_ipidseq: Random Positive Increments [used port 80]
- | qscan:
- | PORT FAMILY MEAN (us) STDDEV LOSS (%)
- | 80 0 409138.10 67959.95 0.0%
- |_443 0 405567.20 35504.22 0.0%
RAW Paste Data