Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- UNITED NATIONS (UN) - Primary Check Point FireWall-1 Software Server Data Leaked
- (ROBOTS/ADMIN FOLDERS/SSL-TLS KEYS etc...)
- The United Nations (UN) is an international organization whose stated aims are facilitating cooperation in international law, international security, economic development, social progress, human rights, and achievement of world peace. The UN was founded in 1945 after World War II to replace the League of Nations, to stop wars between countries, and to provide a platform for dialogue. It contains multiple subsidiary organizations to carry out its missions.
- http://www.un.org
- THIS ATTACK AGAINST THE DIRTIEST THINGS AGAINST THE SRI LANKA BY UN .........!!!!!
- EXCLUSIVE FROM - Anonymous Sri Lanka
- WWW.UN.ORG -----> Fuck3D and Bust3D
- Primary 157.150.185.49 Server Hacked and
- with Transferring (Data Leak)....!!
- Hail to Anonymous, Lulzsec and Operation Anti-Sec...
- 21/tcp open ftp syn-ack Check Point Firewall-1 ftpd
- | banner: 220 Check Point FireWall-1 Secure FTP server running on secper0
- |_1
- | ftp-anon: Anonymous FTP login allowed (FTP code 200)
- | Can't get directory listing: Can't parse PASV response: "Access denied - wrong user name or password \
- |_aborted"
- | ftp-brute:
- |_ ERROR: Login didn't return a proper response
- 22/tcp closed ssh reset
- 23/tcp filtered telnet no-response
- 25/tcp closed smtp reset
- 80/tcp open http-proxy syn-ack Citrix Application Firewall
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- |_unusual-port: http-proxy unexpected on port tcp/80
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- |_http-apache-negotiation: mod_negotiation enabled.
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- |_http-malware-host: Host appears to be clean
- | http-headers:
- | Content-Type: text/html
- | Content-Length: -1
- | Date: Wed, 29 Feb 2012 10:08:21 GMT
- | Server: Apache/Not telling (Unix) AuthTDS/1.1
- |
- |_ (Request type: HEAD)
- |_http-date: Wed, 29 Feb 2012 10:08:26 GMT; +19s from local time.
- | http-affiliate-id:
- |_ Google Analytics ID: UA-4803886-1
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-favicon: Unknown favicon MD5: 7ECBB71944F5F183EEB12F80D55D861D
- | http-php-version: Logo query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- |_Credits query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- | http-robots.txt: 10 disallowed entries
- | /womenwatch/daw/conf/seforms/l123/d123
- | /wcm/administration/ /wcm/administrator/ /wcm/ajaxaction/
- |_/russian/news/mobile/ /common/ /temp/ /temp1/ /temp2/ /test/
- | http-methods: GET HEAD OPTIONS TRACE
- | Potentially risky methods: TRACE
- |_http-userdir-enum: Didn't find any users!
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 110/tcp closed pop3 reset
- 139/tcp filtered netbios-ssn no-response
- 443/tcp open ssl/http-proxy syn-ack Citrix Application Firewall
- |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument)
- |_unusual-port: http-proxy unexpected on port tcp/443
- |_http-google-malware: [ERROR] No API key found. Update the variable APIKEY in http-google-malware or set it in the argument http-google-malware.api
- | http-brute:
- |_ ERROR: No path was specified (see http-brute.path)
- | http-grep:
- |_ ERROR: Argument http-grep.match was not set
- | http-affiliate-id:
- |_ Google Analytics ID: UA-4803886-1
- | ssl-cert: Subject: commonName=*.un.org/organizationName=United Nations/stateOrProvinceName=New York/countryName=US/streetAddress=24-01 44th Road, 9th Floor/localityName=Long Island City/postalCode=11101-4605/organizationalUnitName=Comodo PremiumSSL Wildcard
- | Issuer: commonName=UTN-USERFirst-Hardware/organizationName=The USERTRUST Network/stateOrProvinceName=UT/countryName=US/localityName=Salt Lake City/organizationalUnitName=http://www.usertrust.com
- | Public Key type: rsa
- | Public Key bits: 2048
- | Not valid before: 2011-02-02 00:00:00
- | Not valid after: 2013-04-13 23:59:59
- | MD5: 7920 a56a 7a80 873f 2303 98fd 5711 4c72
- | SHA-1: 3829 64d1 30e8 d182 52e7 65b8 5c41 5de1 0470 a249
- | -----BEGIN CERTIFICATE-----
- | MIIGBzCCBO+gAwIBAgIQGSM5lIzygwVgvQZH7nphlDANBgkqhkiG9w0BAQUFADCB
- | lzELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAlVUMRcwFQYDVQQHEw5TYWx0IExha2Ug
- | Q2l0eTEeMBwGA1UEChMVVGhlIFVTRVJUUlVTVCBOZXR3b3JrMSEwHwYDVQQLExho
- | dHRwOi8vd3d3LnVzZXJ0cnVzdC5jb20xHzAdBgNVBAMTFlVUTi1VU0VSRmlyc3Qt
- | SGFyZHdhcmUwHhcNMTEwMjAyMDAwMDAwWhcNMTMwNDEzMjM1OTU5WjCCAQsxCzAJ
- | BgNVBAYTAlVTMRMwEQYDVQQREwoxMTEwMS00NjA1MREwDwYDVQQIEwhOZXcgWW9y
- | azEZMBcGA1UEBxMQTG9uZyBJc2xhbmQgQ2l0eTEjMCEGA1UECRMaMjQtMDEgNDR0
- | aCBSb2FkLCA5dGggRmxvb3IxFzAVBgNVBAoTDlVuaXRlZCBOYXRpb25zMQ0wCwYD
- | VQQLEwRPSUNUMTQwMgYDVQQLEytJc3N1ZWQgdGhyb3VnaCBVbml0ZWQgTmF0aW9u
- | cyBFLVBLSSBNYW5hZ2VyMSMwIQYDVQQLExpDb21vZG8gUHJlbWl1bVNTTCBXaWxk
- | Y2FyZDERMA8GA1UEAxQIKi51bi5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
- | ggEKAoIBAQCs1eE0bZ1LBeAYBybTC5K4D7p7jpOvfMqH8uWU5XUz5mD2t8ZuZ/gk
- | AL3Te23ev32e8bKPkSYym9VgLNZ5CQbh+DG4y6lQNY0kaokMRSYGMhQG8mdUEkcg
- | u4lvd3V1VZ6HeppcO7ufgn3RbpTSLcgKRlm9UABQmYxZ0nmwW6z9IeGgKPoHn+18
- | G8HgFuMx4N0+vAbPvuhrurzb3OfWFsj2qE0R3PHtbZ/4lUCB54SG7LtNfsDeqzhp
- | rlHoD6OB25V1/t5Mt4K38PRa1i52G6J+KcuexxslfS3Kv67eNFik6t3lR3MPDSGw
- | Vtw1ATyTNW5aHrkq84AbZAKzMi9O7HzxAgMBAAGjggHWMIIB0jAfBgNVHSMEGDAW
- | gBShcl8mGyiYQ5VdBzfVhZadS9LDRTAdBgNVHQ4EFgQUHdeek2FzeALWh9EDbE8s
- | xfGb4uQwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYI
- | KwYBBQUHAwEGCCsGAQUFBwMCMEYGA1UdIAQ/MD0wOwYMKwYBBAGyMQECAQMEMCsw
- | KQYIKwYBBQUHAgEWHWh0dHBzOi8vc2VjdXJlLmNvbW9kby5jb20vQ1BTMHsGA1Ud
- | HwR0MHIwOKA2oDSGMmh0dHA6Ly9jcmwuY29tb2RvY2EuY29tL1VUTi1VU0VSRmly
- | c3QtSGFyZHdhcmUuY3JsMDagNKAyhjBodHRwOi8vY3JsLmNvbW9kby5uZXQvVVRO
- | LVVTRVJGaXJzdC1IYXJkd2FyZS5jcmwwcQYIKwYBBQUHAQEEZTBjMDsGCCsGAQUF
- | BzAChi9odHRwOi8vY3J0LmNvbW9kb2NhLmNvbS9VVE5BZGRUcnVzdFNlcnZlckNB
- | LmNydDAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuY29tb2RvY2EuY29tMBsGA1Ud
- | EQQUMBKCCCoudW4ub3JnggZ1bi5vcmcwDQYJKoZIhvcNAQEFBQADggEBAG9ajQJE
- | fC4XCmsdUD0HQ+5PNO1YtusPQD9I7zOgf6c25TMeu7PCblYH7nZq5NiiglchRX6a
- | VowALfIqjXyEWTDlq94y7JKtv/B62GU1dX7lvNoPS80/e1MzZCzkGa1hHZjiQL7r
- | kFoSmHeRr8A+fIjJZ85o7x2Y6qZJcjQTtASRAMV4kZEqST+cnRF3Pz8WnGKlFwFn
- | aUXH/t/MDgQbpa0+tKIg8dAP3Tb43r4051Rius6zOhS5PYOmo4MsBiKOVXHZnT15
- | vHiNtnSrtsKkxE3xGI7d9x5CC/BLnp8edK5cneCK39+MZFmJmvMFxXwiaIDCiWGx
- | vhwke7E0HzImDls=
- |_-----END CERTIFICATE-----
- |_http-date: Wed, 29 Feb 2012 10:08:10 GMT; +2s from local time.
- | http-robots.txt: 10 disallowed entries
- | /womenwatch/daw/conf/seforms/l123/d123
- | /wcm/administration/ /wcm/administrator/ /wcm/ajaxaction/
- |_/russian/news/mobile/ /common/ /temp/ /temp1/ /temp2/ /test/
- |_http-iis-webdav-vuln: ERROR: This web server is not supported.
- |_http-apache-negotiation: mod_negotiation enabled.
- |_http-wordpress-enum: [Error] Wordpress installation was not found. We couldn't find wp-login.php
- | http-methods: GET HEAD OPTIONS TRACE
- | Potentially risky methods: TRACE
- | http-trace: TRACE is enabled
- | Headers:
- | Date: Wed, 29 Feb 2012 10:08:22 GMT
- | Server: Apache/Not telling (Unix) AuthTDS/1.1
- | Content-Type: message/http
- | Keep-Alive: timeout=5, max=67
- | Connection: Keep-Alive
- |_Transfer-Encoding: chunked
- |_http-favicon: Unknown favicon MD5: 7ECBB71944F5F183EEB12F80D55D861D
- | http-headers:
- | Date: Wed, 29 Feb 2012 10:08:28 GMT
- | Server: Apache/Not telling (Unix) AuthTDS/1.1
- | Content-Type: text/html
- | nnCoection: close
- |
- |_ (Request type: HEAD)
- |_http-malware-host: Host appears to be clean
- | http-php-version: Logo query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- |_Credits query returned unknown hash 4e6c537e157efab6c6f2a1ef0bd2f41e
- | http-form-brute:
- |_ ERROR: No passvar was specified (see http-form-brute.passvar)
- |_http-userdir-enum: Didn't find any users!
- | http-enum:
- | /maintenance/: Possible admin folder
- | /robots.txt: Robots file
- |_ /crossdomain.xml: Adobe Flash crossdomain policy
- | ssl-enum-ciphers:
- | SSLv3
- | Ciphers (3)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- | TLSv1.0
- | Ciphers (5)
- | TLS_RSA_WITH_3DES_EDE_CBC_SHA - strong
- | TLS_RSA_WITH_AES_128_CBC_SHA - strong
- | TLS_RSA_WITH_AES_256_CBC_SHA - unknown strength
- | TLS_RSA_WITH_RC4_128_MD5 - unknown strength
- | TLS_RSA_WITH_RC4_128_SHA - strong
- | Compressors (1)
- | NULL
- |_ Least strength = unknown strength
- | ssl-google-cert-catalog:
- |_ No DB entry
- | http-domino-enum-passwords:
- |_ ERROR: No valid credentials were found (see domino-enum-passwords.username and domino-enum-passwords.password)
- 445/tcp filtered microsoft-ds no-response
- 3389/tcp filtered ms-term-serv no-response
- TCP Sequence Prediction: Difficulty=257 (Good luck!)
- IP ID Sequence Generation: Incremental
- Service Info: Device: firewall
- Host script results:
- | dns-blacklist:
- | PROXY
- | dnsbl.ahbl.org - FAIL
- | socks.dnsbl.sorbs.net - FAIL
- | http.dnsbl.sorbs.net - FAIL
- | misc.dnsbl.sorbs.net - FAIL
- | dnsbl.tornevall.org - FAIL
- | SPAM
- | dnsbl.ahbl.org - FAIL
- | dnsbl.inps.de - FAIL
- | bl.nszones.com - FAIL
- | l2.apews.org - FAIL
- | list.quorum.to - FAIL
- | all.spamrats.com - FAIL
- | bl.spamcop.net - FAIL
- | spam.dnsbl.sorbs.net - FAIL
- |_ sbl.spamhaus.org - FAIL
- |_dns-brute: Can't guess domain of "157.150.185.49"; use dns-brute.domain script argument.
- |_asn-query: No Servers
- | dns-zeustracker:
- |_ ERROR: DNS Query failed
- |_path-mtu: PMTU == 1500
- | firewalk:
- | HOP HOST PROTOCOL BLOCKED PORTS
- |_1 192.168.140.2 tcp 23,139,445,3389
- |_ipidseq: Unknown [used port 21]
- | ip-geolocation-geobytes:
- | 157.150.185.49
- | coordinates (lat,lon): 40.7488,-73.9846
- |_ city: New York, New York, United States
- |_hostmap: Error: found no hostnames but not the marker for "no hostnames found" (pattern error?)
- | whois: Record found at whois.arin.net
- | netrange: 157.150.0.0 - 157.150.255.255
- | netname: UN-NET
- | orgname: United Nations
- | orgid: UNITED-2
- | country: US stateprov: NY
- |
- | orgtechname: Debargue, Olivier
- |_orgtechemail: debargue@un.org
- | ip-geolocation-geoplugin:
- | 157.150.185.49
- | coordinates (lat,lon): 40.752799987793,-73.972503662109
- |_ state: New York, United States
- | qscan:
- | PORT FAMILY MEAN (us) STDDEV LOSS (%)
- | 21 0 401651.10 42709.10 0.0%
- | 22 1 2156255.30 98053.60 0.0%
- | 80 0 390357.60 38856.76 0.0%
- |_443 2 366864.30 18420.75 0.0%
- New targets in the scanned cache: 0, pending ones: 0.
- NSE: Script Post-scanning.
- NSE: Starting runlevel 1 (of 4) scan.
- NSE: Starting 'http-affiliate-id' (thread: 0xb878360).
- NSE: Starting 'reverse-index' (thread: 0xb91a108).
- Initiating NSE at 05:47
- NSE: Finished 'http-affiliate-id' (thread: 0xb878360).
- NSE: Finished 'reverse-index' (thread: 0xb91a108).
- Completed NSE at 05:47, 0.00s elapsed
- NSE: Starting runlevel 2 (of 4) scan.
- NSE: Starting runlevel 3 (of 4) scan.
- NSE: Starting runlevel 4 (of 4) scan.
- Post-scan script results:
- | http-affiliate-id: Possible related sites
- | Google Analytics ID: UA-4803886-1 used by:
- | 157.150.185.49:443/
- |_ 157.150.185.49:80/
- | reverse-index:
- | 21/tcp: 157.150.185.49
- | 80/tcp: 157.150.185.49
- |_ 443/tcp: 157.150.185.49
RAW Paste Data