JTSEC1333

Anonymous JTSEC #OpSudan Full Recon #59

Apr 23rd, 2019
912
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 115.46 KB | None | 0 0
  1. #######################################################################################################################################
  2. =======================================================================================================================================
  3. Hostname vtckosti.gov.sd ISP Hetzner Online GmbH
  4. Continent Europe Flag
  5. DE
  6. Country Germany Country Code DE
  7. Region Unknown Local time 23 Apr 2019 08:35 CEST
  8. City Unknown Postal Code Unknown
  9. IP Address 5.9.149.251 Latitude 51.299
  10. Longitude 9.491
  11. =======================================================================================================================================
  12. #######################################################################################################################################
  13. > vtckosti.gov.sd
  14. Server: 38.132.106.139
  15. Address: 38.132.106.139#53
  16.  
  17. Non-authoritative answer:
  18. Name: vtckosti.gov.sd
  19. Address: 5.9.149.251
  20. >
  21. #######################################################################################################################################
  22. HostIP:5.9.149.251
  23. HostName:vtckosti.gov.sd
  24.  
  25. Gathered Inet-whois information for 5.9.149.251
  26. ---------------------------------------------------------------------------------------------------------------------------------------
  27.  
  28.  
  29. inetnum: 5.9.149.224 - 5.9.149.255
  30. netname: HETZNER-fsn1-dc10
  31. descr: Hetzner Online GmbH
  32. descr: Datacenter fsn1-dc10
  33. country: DE
  34. admin-c: HOAC1-RIPE
  35. tech-c: HOAC1-RIPE
  36. status: ASSIGNED PA
  37. remarks: INFRA-AW
  38. mnt-by: HOS-GUN
  39. mnt-lower: HOS-GUN
  40. mnt-routes: HOS-GUN
  41. created: 2012-11-19T13:40:12Z
  42. last-modified: 2018-03-15T14:36:18Z
  43. source: RIPE
  44.  
  45. role: Hetzner Online GmbH - Contact Role
  46. address: Hetzner Online GmbH
  47. address: Industriestrasse 25
  48. address: D-91710 Gunzenhausen
  49. address: Germany
  50. phone: +49 9831 505-0
  51. fax-no: +49 9831 505-3
  52. abuse-mailbox: [email protected]
  53. remarks: *************************************************
  54. remarks: * For spam/abuse/security issues please contact *
  55. remarks: * [email protected], not this address. *
  56. remarks: * The contents of your abuse email will be *
  57. remarks: * forwarded directly on to our client for *
  58. remarks: * handling. *
  59. remarks: *************************************************
  60. remarks:
  61. remarks: *************************************************
  62. remarks: * Any questions on Peering please send to *
  63. remarks: * [email protected] *
  64. remarks: *************************************************
  65. org: ORG-HOA1-RIPE
  66. admin-c: MH375-RIPE
  67. tech-c: GM834-RIPE
  68. tech-c: SK2374-RIPE
  69. tech-c: TF2013-RIPE
  70. tech-c: MF1400-RIPE
  71. tech-c: SK8441-RIPE
  72. nic-hdl: HOAC1-RIPE
  73. mnt-by: HOS-GUN
  74. created: 2004-08-12T09:40:20Z
  75. last-modified: 2015-08-06T09:39:14Z
  76. source: RIPE # Filtered
  77.  
  78. % Information related to '5.9.0.0/16AS24940'
  79.  
  80. route: 5.9.0.0/16
  81. descr: HETZNER-RZ-FKS-BLK5
  82. origin: AS24940
  83. mnt-by: HOS-GUN
  84. created: 2012-04-26T10:30:12Z
  85. last-modified: 2012-04-26T10:30:12Z
  86. source: RIPE
  87.  
  88. % This query was served by the RIPE Database Query Service version 1.93.2 (BLAARKOP)
  89.  
  90.  
  91.  
  92. Retrieving Netcraft.com information for vtckosti.gov.sd
  93. Netcraft.com Information gathered
  94.  
  95. Gathered Subdomain information for vtckosti.gov.sd
  96. ---------------------------------------------------------------------------------------------------------------------------------------
  97. Searching Google.com:80...
  98. Searching Altavista.com:80...
  99. Found 0 possible subdomain(s) for host vtckosti.gov.sd, Searched 0 pages containing 0 results
  100.  
  101. Gathered E-Mail information for vtckosti.gov.sd
  102. ---------------------------------------------------------------------------------------------------------------------------------------
  103. Searching Google.com:80...
  104. Searching Altavista.com:80...
  105. Found 0 E-Mail(s) for host vtckosti.gov.sd, Searched 0 pages containing 0 results
  106.  
  107. Gathered TCP Port information for 5.9.149.251
  108. ---------------------------------------------------------------------------------------------------------------------------------------
  109.  
  110. Port State
  111.  
  112. 21/tcp open
  113. 53/tcp open
  114. 80/tcp open
  115. 110/tcp open
  116. 143/tcp open
  117.  
  118. Portscan Finished: Scanned 150 ports, 3 ports were in state closed
  119. #######################################################################################################################################
  120. [?] Enter the target: example( http://domain.com )
  121. http://vtckosti.gov.sd/
  122. [!] IP Address : 5.9.149.251
  123. [!] vtckosti.gov.sd doesn't seem to use a CMS
  124. [+] Honeypot Probabilty: 30%
  125. ---------------------------------------------------------------------------------------------------------------------------------------
  126. [~] Trying to gather whois information for vtckosti.gov.sd
  127. [+] Whois information found
  128. [-] Unable to build response, visit https://who.is/whois/vtckosti.gov.sd
  129. ---------------------------------------------------------------------------------------------------------------------------------------
  130. PORT STATE SERVICE
  131. 21/tcp open ftp
  132. 22/tcp filtered ssh
  133. 23/tcp filtered telnet
  134. 80/tcp open http
  135. 110/tcp open pop3
  136. 143/tcp open imap
  137. 443/tcp open https
  138. 3389/tcp filtered ms-wbt-server
  139. Nmap done: 1 IP address (1 host up) scanned in 1.68 seconds
  140. ---------------------------------------------------------------------------------------------------------------------------------------
  141.  
  142. [+] DNS Records
  143. ns8.mazinhost.net. (5.9.149.251) AS24940 Hetzner Online GmbH Germany
  144. ns2.mazinhost.com. (5.9.149.251) AS24940 Hetzner Online GmbH Germany
  145. ns1.mazinhost.com. (5.9.149.251) AS24940 Hetzner Online GmbH Germany
  146. ns7.mazinhost.net. (5.9.149.251) AS24940 Hetzner Online GmbH Germany
  147.  
  148. [+] MX Records
  149. 0 (5.9.149.251) AS24940 Hetzner Online GmbH Germany
  150.  
  151. [+] Host Records (A)
  152. vtckosti.gov.sdHTTP: (ns8.mazinhost.net) (5.9.149.251) AS24940 Hetzner Online GmbH Germany
  153.  
  154. [+] TXT Records
  155. "v=spf1 +a +mx +ip4:5.9.149.251 ~all"
  156.  
  157. [+] DNS Map: https://dnsdumpster.com/static/map/vtckosti.gov.sd.png
  158.  
  159. [>] Initiating 3 intel modules
  160. [>] Loading Alpha module (1/3)
  161. [>] Beta module deployed (2/3)
  162. [>] Gamma module initiated (3/3)
  163.  
  164.  
  165. [+] Emails found:
  166. ---------------------------------------------------------------------------------------------------------------------------------------
  167.  
  168. [+] Hosts found in search engines:
  169. ---------------------------------------------------------------------------------------------------------------------------------------
  170. [-] Resolving hostnames IPs...
  171. 5.9.149.251:www.vtckosti.gov.sd
  172. [+] Virtual hosts:
  173. ---------------------------------------------------------------------------------------------------------------------------------------
  174. 5.9.149.251 hseportal.net
  175. 5.9.149.251 qurtobasd.com
  176. 5.9.149.251 iskan.sd
  177. 5.9.149.251 ntechsd.com
  178. #######################################################################################################################################
  179. [i] Scanning Site: http://vtckosti.gov.sd
  180.  
  181.  
  182.  
  183. B A S I C I N F O
  184. =======================================================================================================================================
  185.  
  186.  
  187. [+] Site Title:
  188. [+] IP address: 5.9.149.251
  189. [+] Web Server: Could Not Detect
  190. [+] CMS: Could Not Detect
  191. [+] Cloudflare: Not Detected
  192. [+] Robots File: Could NOT Find robots.txt!
  193.  
  194.  
  195.  
  196.  
  197.  
  198.  
  199.  
  200. G E O I P L O O K U P
  201. =======================================================================================================================================
  202.  
  203. [i] IP Address: 5.9.149.251
  204. [i] Country: Germany
  205. [i] State:
  206. [i] City:
  207. [i] Latitude: 51.2993
  208. [i] Longitude: 9.491
  209.  
  210.  
  211.  
  212.  
  213. H T T P H E A D E R S
  214. =======================================================================================================================================
  215.  
  216.  
  217. [i] HTTP/1.1 200 OK
  218. [i] Date: Tue, 23 Apr 2019 07:10:44 GMT
  219. [i] X-Powered-By: PHP/7.3.1
  220. [i] X-UA-Compatible: IE=edge
  221. [i] Link: <http://vtckosti.gov.sd/index.php?rest_route=/>; rel="https://api.w.org/", <http://vtckosti.gov.sd/>; rel=shortlink
  222. [i] Content-Length: 233571
  223. [i] Content-Type: text/html; charset=UTF-8
  224. [i] Connection: close
  225.  
  226.  
  227.  
  228.  
  229. D N S L O O K U P
  230. =======================================================================================================================================
  231.  
  232. vtckosti.gov.sd. 14399 IN TXT "v=spf1 +a +mx +ip4:5.9.149.251 ~all"
  233. vtckosti.gov.sd. 21599 IN SOA ns7.mazinhost.net. info.mazinhost.com. 2017111403 3600 7200 1209600 86400
  234. vtckosti.gov.sd. 21599 IN NS ns2.mazinhost.com.
  235. vtckosti.gov.sd. 21599 IN NS ns7.mazinhost.net.
  236. vtckosti.gov.sd. 21599 IN NS ns1.mazinhost.com.
  237. vtckosti.gov.sd. 21599 IN NS ns8.mazinhost.net.
  238. vtckosti.gov.sd. 14399 IN A 5.9.149.251
  239. vtckosti.gov.sd. 14399 IN MX 0 vtckosti.gov.sd.
  240.  
  241.  
  242.  
  243.  
  244. S U B N E T C A L C U L A T I O N
  245. =======================================================================================================================================
  246.  
  247. Address = 5.9.149.251
  248. Network = 5.9.149.251 / 32
  249. Netmask = 255.255.255.255
  250. Broadcast = not needed on Point-to-Point links
  251. Wildcard Mask = 0.0.0.0
  252. Hosts Bits = 0
  253. Max. Hosts = 1 (2^0 - 0)
  254. Host Range = { 5.9.149.251 - 5.9.149.251 }
  255.  
  256.  
  257.  
  258. N M A P P O R T S C A N
  259. =======================================================================================================================================
  260.  
  261. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 07:10 UTC
  262. Nmap scan report for vtckosti.gov.sd (5.9.149.251)
  263. Host is up (0.082s latency).
  264. rDNS record for 5.9.149.251: ns8.mazinhost.net
  265.  
  266. PORT STATE SERVICE
  267. 21/tcp open ftp
  268. 22/tcp filtered ssh
  269. 23/tcp filtered telnet
  270. 80/tcp open http
  271. 110/tcp open pop3
  272. 143/tcp open imap
  273. 443/tcp open https
  274. 3389/tcp filtered ms-wbt-server
  275.  
  276. Nmap done: 1 IP address (1 host up) scanned in 1.93 seconds
  277. #######################################################################################################################################
  278. Enter Address Website = 5.9.149.251
  279.  
  280. Reversing IP With HackTarget '5.9.149.251'
  281. ---------------------------------------------------------------------------------------------------------------------------------------
  282.  
  283. [+] 5.9.149.251
  284. [+] abanostrading.com
  285. [+] abuamna.com
  286. [+] acdenorthafrica.org
  287. [+] advancedarrbian.com
  288. [+] africasoft.net
  289. [+] agropowergroup.com
  290. [+] ahmedsalihgroup.com
  291. [+] aihlawfirm.com
  292. [+] ajax-developer.com
  293. [+] akhhospital.com
  294. [+] akmal-sd.com
  295. [+] alfagroupsd.com
  296. [+] alfaisal-ft.com
  297. [+] alfuttiam-mining.com
  298. [+] alhaffary.com
  299. [+] alhasan-ic.com
  300. [+] alidros.com
  301. [+] aljazeera-agency.com
  302. [+] aljumhoria.net
  303. [+] alkhobaib.com
  304. [+] almamlaka-eng.com
  305. [+] alnasr-sd.com
  306. [+] alsahl-alakhdar.com
  307. [+] altasamoh.com
  308. [+] al-baylasan.com
  309. [+] amanabiz.com
  310. [+] amarouse.com
  311. [+] amazon4tech.com
  312. [+] ameeralata.com
  313. [+] ammtechsd.com
  314. [+] anniatour.com
  315. [+] api.filettoapp.com
  316. [+] api.tbeebk.com
  317. [+] apk.tbeebk.com
  318. [+] aptech-sudan.com
  319. [+] arkan-advanced.com
  320. [+] asap-travel.com
  321. [+] ataaat.com
  322. [+] autodiscover.amarouse.com
  323. [+] autodiscover.filettoapp.com
  324. [+] autodiscover.filetto.sd
  325. [+] autodiscover.gafe.gov.sd
  326. [+] autodiscover.hadeeltrading.com
  327. [+] autodiscover.layerone.com.sd
  328. [+] autodiscover.maallcomgroup.com
  329. [+] autodiscover.manahgsudan.com
  330. [+] autodiscover.manahg.edu.sd
  331. [+] autodiscover.mtowngroup.com
  332. [+] autodiscover.reddplussd.org
  333. [+] autodiscover.syaratti.com
  334. [+] autodiscover.tagheez.com
  335. [+] autodiscover.tbeebk.com
  336. [+] autodiscover.almamlaka-eng.com
  337. [+] autodiscover.medicorp-sd.com
  338. [+] autodiscover.trainsmart-sd.com
  339. [+] autodiscover.valerie-it.com
  340. [+] avinova.net
  341. [+] biolinemed.com
  342. [+] biznessmap.com
  343. [+] blackgoldlog.com
  344. [+] bluetree-sd.com
  345. [+] britishaccreditationsudan.org
  346. [+] burganengineering.com
  347. [+] cac-sa.com
  348. [+] castle-sd.com
  349. [+] chartersd.com
  350. [+] cic.edu.sd
  351. [+] clessies.com
  352. [+] clinic.tbeebk.com
  353. [+] conductorengineering.com
  354. [+] connectit-sd.com
  355. [+] control.tbeebk.com
  356. [+] copeninvestment.com
  357. [+] cpanel.amarouse.com
  358. [+] cpanel.copeninvestment.com
  359. [+] cpanel.filettoapp.com
  360. [+] cpanel.gafe.gov.sd
  361. [+] cpanel.hadeeltrading.com
  362. [+] cpanel.layerone.com.sd
  363. [+] cpanel.maallcomgroup.com
  364. [+] cpanel.manahgsudan.com
  365. [+] cpanel.manahg.edu.sd
  366. [+] cpanel.mazinhost.com
  367. [+] cpanel.mtowngroup.com
  368. [+] cpanel.reddplussd.org
  369. [+] cpanel.shahdtourismsudan.com
  370. [+] cpanel.syaratti.com
  371. [+] cpanel.tagheez.com
  372. [+] cpanel.tbeebk.com
  373. [+] cpanel.almamlaka-eng.com
  374. [+] cpanel.ihc-edu.com
  375. [+] cpanel.medicorp-sd.com
  376. [+] cpanel.trainsmart-sd.com
  377. [+] cpanel.valerie-it.com
  378. [+] csrtahmedgasim.com
  379. [+] damlakhi.com
  380. [+] daralhanan.org
  381. [+] dark-apple.com
  382. [+] dashboard.tbeebk.com
  383. [+] davinciclinics.com
  384. [+] dawadesigns.com
  385. [+] dc-808ba726616f.brqsms.com
  386. [+] dms-sd.com
  387. [+] doctors.tbeebk.com
  388. [+] download.tbeebk.com
  389. [+] drsatti.org
  390. [+] dynamic.express
  391. [+] ebsostech.com
  392. [+] elafsd.com
  393. [+] elbayti.com
  394. [+] elizdehar.com
  395. [+] elnafieconsultancy.com
  396. [+] elrmaya.com
  397. [+] enjazsd.com
  398. [+] enmaa-sd.com
  399. [+] env-neelain.org
  400. [+] eplservice.com
  401. [+] euphoric-sudan.com
  402. [+] fabienne-france.com
  403. [+] faimoninvest.com
  404. [+] familybank.sd
  405. [+] fast-factor.com
  406. [+] fbs-sd.com
  407. [+] filetto.sd
  408. [+] filettoapp.com
  409. [+] flyalsomor.com
  410. [+] foodnetsd.com
  411. [+] fpdo-sd.org
  412. [+] fstcafrica.com
  413. [+] gafe.com.gafe.gov.sd
  414. [+] gafe.gov.sd
  415. [+] gasmenz.com
  416. [+] geneva-international.com
  417. [+] genifa-cargo.com
  418. [+] georock-mining.com
  419. [+] gitafmb.com
  420. [+] goalmech.com
  421. [+] goldenlines24.com
  422. [+] gstc-sd.com
  423. [+] hadeeltrading.com
  424. [+] haggarforum.com
  425. [+] hakeim.com
  426. [+] halansudan.com
  427. [+] hardinfotech.com
  428. [+] hash.sd
  429. [+] hospital.tbeebk.com
  430. [+] hseportal.net
  431. [+] humansecurityinitiativesud.org
  432. [+] h-i-services.net
  433. [+] idexads.com
  434. [+] ihc-edu.com
  435. [+] ims-sd.com
  436. [+] iskan.sd
  437. [+] ittirad.com
  438. [+] kaffaa.net
  439. [+] kaizentechco.com
  440. [+] kaizentech-co.com
  441. [+] khalid-design.com
  442. [+] khandgawi.net
  443. [+] khoromernational.com
  444. [+] kibfsudan.gov.sd
  445. [+] kinzoco.com
  446. [+] kourbaj.com
  447. [+] krikab.com
  448. [+] layerone.com.sd
  449. [+] legendtornado.net
  450. [+] limaaviationgroup.com
  451. [+] linebaynoonah.com
  452. [+] lynx-ins.net
  453. [+] maallcomgroup.com
  454. [+] maksudan.com
  455. [+] maliktco.com
  456. [+] manahg.edu.sd
  457. [+] manahgsudan.com
  458. [+] manhttan-co.com
  459. [+] marij-sd.com
  460. [+] massaie.com
  461. [+] massajed.com
  462. [+] matabmedical.com
  463. [+] matrixco24.com
  464. [+] mazinhost.com
  465. [+] mazin-mazin.com
  466. [+] meastaralliance.com
  467. [+] medicorp-sd.com
  468. [+] member.snrec.sd
  469. [+] mepco-sd.com
  470. [+] mkmbhs.com
  471. [+] mmacpanel.neelain.edu.sd
  472. [+] mmmp1.neelaincourses.com
  473. [+] mnd-soft.com
  474. [+] molar.sd
  475. [+] monitor-is.com
  476. [+] mos5-tel.com
  477. [+] mosabfaisal.com
  478. [+] msd-oil.com
  479. [+] mtowngroup.com
  480. [+] myapp.tbeebk.com
  481. [+] myenginesd.com
  482. [+] myengine-sd.com
  483. [+] mykaf.com
  484. [+] nadaelazhar.org
  485. [+] nasmoltd.com
  486. [+] nawayipm.com
  487. [+] nbnstone.com
  488. [+] ndct24.com
  489. [+] neelain.edu.sd
  490. [+] neelaincourses.com
  491. [+] netrixti.com
  492. [+] nge.sd
  493. [+] nhegmedical.com
  494. [+] ns1.mazinhost.com
  495. [+] ns2.mazinhost.com
  496. [+] ns3.mazinhost.com
  497. [+] ns4.mazinhost.com
  498. [+] ns8.mazinhost.net
  499. [+] nubianstone.com
  500. [+] omdasalih.com
  501. [+] opticallightsd.com
  502. [+] ordercode.net
  503. [+] osama-consultancy.com
  504. [+] outlook.office.ittirad.com
  505. [+] pay.amarouse.com
  506. [+] pegasus-solutions.net
  507. [+] petrodaf.com
  508. [+] petronour.com
  509. [+] phc-ca.com
  510. [+] pmb-shaddad.com
  511. [+] prestige-sd.com
  512. [+] prettybase.com
  513. [+] primaveratc.com
  514. [+] prosudan.com
  515. [+] qalaa.net
  516. [+] qurtobasd.com
  517. [+] rahtak.sd
  518. [+] raidantravel1.com
  519. [+] ralldesing.com
  520. [+] rasmasd.com
  521. [+] rcdosd.org
  522. [+] reddplussd.org
  523. [+] remaxscientific.com
  524. [+] reyada.org
  525. [+] roadmap-group.net
  526. [+] safariflat.com
  527. [+] saffanacomplex.com
  528. [+] sahelsudan.org
  529. [+] salamall.com
  530. [+] samiagallabi.com
  531. [+] sanatechnology.ae
  532. [+] sapath.org
  533. [+] saudi-business.net
  534. [+] saudi-pos.com
  535. [+] sddeveloper.com
  536. [+] secs.org.sd
  537. [+] shahdtourismsudan.com
  538. [+] sheikhelsadig.com
  539. [+] sigmaelectric.net
  540. [+] smartvision-sd.com
  541. [+] smes-reg.net
  542. [+] snrec.sd
  543. [+] sonosudan.com
  544. [+] sounion.org
  545. [+] spectrapacks.com
  546. [+] sse-sudan.com
  547. [+] storesd.com
  548. [+] stream4cs.com
  549. [+] subulint.net
  550. [+] sudabase.com
  551. [+] sudafoam.com
  552. [+] sudandiy.com
  553. [+] sudaneselawfirm.com
  554. [+] sudani-business.com
  555. [+] sudansoe.org
  556. [+] syaratti.com
  557. [+] tadai.org
  558. [+] tagheez.com
  559. [+] tbeebk.com
  560. [+] tele-power.net
  561. [+] test.tbeebk.com
  562. [+] toams-sd.com
  563. [+] trainsmart-sd.com
  564. [+] tumbus-tours.com
  565. [+] twinsabujbal.com
  566. [+] uba-aviation.com
  567. [+] unorbit.com
  568. [+] valentina-sd.com
  569. [+] valerie-it.com
  570. [+] vitalmulti.com
  571. [+] webdisk.amarouse.com
  572. [+] webdisk.copeninvestment.com
  573. [+] webdisk.filettoapp.com
  574. [+] webdisk.filetto.sd
  575. [+] webdisk.gafe.gov.sd
  576. [+] webdisk.hadeeltrading.com
  577. [+] webdisk.layerone.com.sd
  578. [+] webdisk.manahgsudan.com
  579. [+] webdisk.manahg.edu.sd
  580. [+] webdisk.mtowngroup.com
  581. [+] webdisk.reddplussd.org
  582. [+] webdisk.shahdtourismsudan.com
  583. [+] webdisk.tagheez.com
  584. [+] webdisk.tbeebk.com
  585. [+] webdisk.almamlaka-eng.com
  586. [+] webdisk.ihc-edu.com
  587. [+] webdisk.medicorp-sd.com
  588. [+] webdisk.trainsmart-sd.com
  589. [+] webdisk.valerie-it.com
  590. [+] webmail.aihlawfirm.com
  591. [+] webmail.amarouse.com
  592. [+] webmail.copeninvestment.com
  593. [+] webmail.filettoapp.com
  594. [+] webmail.filetto.sd
  595. [+] webmail.gafe.gov.sd
  596. [+] webmail.hadeeltrading.com
  597. [+] webmail.layerone.com.sd
  598. [+] webmail.manahgsudan.com
  599. [+] webmail.manahg.edu.sd
  600. [+] webmail.mtowngroup.com
  601. [+] webmail.reddplussd.org
  602. [+] webmail.sahelsudan.org
  603. [+] webmail.shahdtourismsudan.com
  604. [+] webmail.tagheez.com
  605. [+] webmail.tbeebk.com
  606. [+] webmail.almamlaka-eng.com
  607. [+] webmail.fpdo-sd.org
  608. [+] webmail.ihc-edu.com
  609. [+] webmail.medicorp-sd.com
  610. [+] webmail.trainsmart-sd.com
  611. [+] webmail.valerie-it.com
  612. [+] workspace.amarouse.com
  613. [+] wsslni.com
  614. [+] www.api.filettoapp.com
  615. [+] www.api.tbeebk.com
  616. [+] www.clinic.tbeebk.com
  617. [+] www.control.tbeebk.com
  618. [+] www.c.amarouse.com
  619. [+] www.dashboard.tbeebk.com
  620. [+] www.doctors.tbeebk.com
  621. [+] www.download.tbeebk.com
  622. [+] www.gafe.com.gafe.gov.sd
  623. [+] www.hospital.tbeebk.com
  624. [+] www.myapp.tbeebk.com
  625. [+] www.pay.amarouse.com
  626. [+] www.test.tbeebk.com
  627. [+] www.workspace.amarouse.com
  628. [+] yas91n.com
  629. [+] yazansoft.com
  630. [+] zakat-ens.com
  631. [+] zoaltech.com
  632. [+] zoolsoftware.com
  633. #######################################################################################################################################
  634.  
  635. Reverse IP With YouGetSignal '5.9.149.251'
  636. ---------------------------------------------------------------------------------------------------------------------------------------
  637.  
  638. [*] IP: 5.9.149.251
  639. [*] Domain: 5.9.149.251
  640. [*] Total Domains: 71
  641.  
  642. [+] abumozanagt.sd
  643. [+] all.softportal.com
  644. [+] almohajreen.org
  645. [+] alsafwaa.edu.sd
  646. [+] articles.softportal.com
  647. [+] artmoney.softportal.com
  648. [+] autoelectodiagno.com
  649. [+] chemax.softportal.com
  650. [+] dle.softportal.com
  651. [+] download.softportal.com
  652. [+] elbayti.com
  653. [+] exinfo.gov.sd
  654. [+] file-subjects.com
  655. [+] gafe.gov.sd
  656. [+] games.softportal.com
  657. [+] haehd.org
  658. [+] haggarforum.com
  659. [+] hmwsudan.com
  660. [+] iskan.sd
  661. [+] k-lite.softportal.com
  662. [+] kaspersky.softportal.com
  663. [+] khandgawi.net
  664. [+] kibfsudan.gov.sd
  665. [+] kotc.edu.sd
  666. [+] m.softportal.com
  667. [+] makkawigroup.com
  668. [+] manahg.edu.sd
  669. [+] mazinhost.com
  670. [+] mepmentor.com
  671. [+] mgnetsd.com
  672. [+] mininfo.gov.sd
  673. [+] neelain.edu.sd
  674. [+] neelaincourses.com
  675. [+] news.softportal.com
  676. [+] nhegmedical.com
  677. [+] ns8.mazinhost.net
  678. [+] oiupharm.com
  679. [+] opera.softportal.com
  680. [+] pmb-shaddad.com
  681. [+] qip.softportal.com
  682. [+] rasmasd.com
  683. [+] rcdosd.org
  684. [+] reyada.org
  685. [+] rsailalnoor.com
  686. [+] salamall.com
  687. [+] sandoraa.com
  688. [+] sctdtraining.com
  689. [+] skype.softportal.com
  690. [+] snbc.gov.sd
  691. [+] softportal.com
  692. [+] sudabase.com
  693. [+] sudamall.sd
  694. [+] uba-aviation.com
  695. [+] vkontakte.softportal.com
  696. [+] vtckosti.gov.sd
  697. [+] wadgraino.net
  698. [+] www.alsalama.sd
  699. [+] www.elbayti.com
  700. [+] www.fatahosoft.com
  701. [+] www.ihubkhartoum.com
  702. [+] www.iskan.sd
  703. [+] www.manahg.edu.sd
  704. [+] www.monitor-is.com
  705. [+] www.neelain.edu.sd
  706. [+] www.pmb-shaddad.com
  707. [+] www.rsailalnoor.com
  708. [+] www.sahelsudan.org
  709. [+] www.sapath.org
  710. [+] www.softportal.com
  711. [+] www.visionaag.com
  712. [+] www.wadgraino.net
  713. #######################################################################################################################################
  714.  
  715. Geo IP Lookup '5.9.149.251'
  716. ---------------------------------------------------------------------------------------------------------------------------------------
  717.  
  718. [+] IP Address: 5.9.149.251
  719. [+] Country: Germany
  720. [+] State:
  721. [+] City:
  722. [+] Latitude: 51.2993
  723. [+] Longitude: 9.491
  724. #######################################################################################################################################
  725.  
  726. Show HTTP Header '5.9.149.251'
  727. ---------------------------------------------------------------------------------------------------------------------------------------
  728.  
  729. [+] HTTP/1.1 200 OK
  730. [+] Date: Tue, 23 Apr 2019 07:13:39 GMT
  731. [+] Server: Apache
  732. [+] Last-Modified: Tue, 07 Aug 2018 09:11:39 GMT
  733. [+] Accept-Ranges: bytes
  734. [+] Content-Length: 163
  735. [+] Content-Type: text/html
  736. #######################################################################################################################################
  737.  
  738. Port Scan '5.9.149.251'
  739. ---------------------------------------------------------------------------------------------------------------------------------------
  740.  
  741. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 07:13 UTC
  742. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  743. Host is up (0.083s latency).
  744.  
  745. PORT STATE SERVICE
  746. 21/tcp open ftp
  747. 22/tcp filtered ssh
  748. 23/tcp filtered telnet
  749. 80/tcp open http
  750. 110/tcp open pop3
  751. 143/tcp open imap
  752. 443/tcp open https
  753. 3389/tcp filtered ms-wbt-server
  754.  
  755. Nmap done: 1 IP address (1 host up) scanned in 1.50 seconds
  756. #######################################################################################################################################
  757.  
  758. Traceroute '5.9.149.251'
  759. ---------------------------------------------------------------------------------------------------------------------------------------
  760.  
  761. Start: 2019-04-23T07:13:45+0000
  762. HOST: web01 Loss% Snt Last Avg Best Wrst StDev
  763. 1.|-- 45.79.12.202 0.0% 3 0.8 1.2 0.8 1.6 0.4
  764. 2.|-- 45.79.12.6 0.0% 3 0.6 3.1 0.5 8.3 4.5
  765. 3.|-- dls-b22-link.telia.net 0.0% 3 1.7 1.4 0.9 1.7 0.5
  766. 4.|-- atl-b22-link.telia.net 0.0% 3 18.8 19.1 18.8 19.5 0.4
  767. 5.|-- ash-bb3-link.telia.net 0.0% 3 31.1 30.6 30.0 31.1 0.5
  768. 6.|-- prs-bb4-link.telia.net 0.0% 3 108.6 111.5 107.1 118.9 6.4
  769. 7.|-- ffm-bb4-link.telia.net 0.0% 3 119.7 119.8 119.7 119.9 0.1
  770. 8.|-- ffm-b4-link.telia.net 0.0% 3 129.1 131.0 129.1 134.8 3.3
  771. 9.|-- hetzner-ic-326013-ffm-b4.c.telia.net 0.0% 3 129.6 129.5 129.3 129.6 0.1
  772. 10.|-- core24.fsn1.hetzner.com 0.0% 3 134.5 134.4 134.2 134.5 0.2
  773. 11.|-- ex9k1.dc10.fsn1.hetzner.com 0.0% 3 135.2 135.0 134.9 135.2 0.2
  774. 12.|-- static.234.149.9.5.clients.your-server.de 0.0% 3 135.0 135.5 135.0 136.4 0.8
  775. 13.|-- ns8.mazinhost.net 0.0% 3 134.3 134.2 134.1 134.3 0.1
  776. #######################################################################################################################################
  777.  
  778. Ping '5.9.149.251'
  779. ---------------------------------------------------------------------------------------------------------------------------------------
  780.  
  781.  
  782. Starting Nping 0.7.70 ( https://nmap.org/nping ) at 2019-04-23 07:14 UTC
  783. SENT (0.0028s) ICMP [104.237.144.6 > 5.9.149.251 Echo request (type=8/code=0) id=35899 seq=1] IP [ttl=64 id=3868 iplen=28 ]
  784. RCVD (0.2038s) ICMP [5.9.149.251 > 104.237.144.6 Echo reply (type=0/code=0) id=35899 seq=1] IP [ttl=55 id=28169 iplen=28 ]
  785. SENT (1.0031s) ICMP [104.237.144.6 > 5.9.149.251 Echo request (type=8/code=0) id=35899 seq=3] IP [ttl=64 id=3868 iplen=28 ]
  786. RCVD (1.2230s) ICMP [5.9.149.251 > 104.237.144.6 Echo reply (type=0/code=0) id=35899 seq=3] IP [ttl=55 id=28170 iplen=28 ]
  787. SENT (2.0041s) ICMP [104.237.144.6 > 5.9.149.251 Echo request (type=8/code=0) id=35899 seq=3] IP [ttl=64 id=3868 iplen=28 ]
  788. RCVD (2.2430s) ICMP [5.9.149.251 > 104.237.144.6 Echo reply (type=0/code=0) id=35899 seq=3] IP [ttl=55 id=28171 iplen=28 ]
  789. SENT (3.0060s) ICMP [104.237.144.6 > 5.9.149.251 Echo request (type=8/code=0) id=35899 seq=4] IP [ttl=64 id=3868 iplen=28 ]
  790. RCVD (3.2630s) ICMP [5.9.149.251 > 104.237.144.6 Echo reply (type=0/code=0) id=35899 seq=4] IP [ttl=55 id=28172 iplen=28 ]
  791.  
  792. Max rtt: 257.076ms | Min rtt: 201.009ms | Avg rtt: 229.211ms
  793. Raw packets sent: 4 (112B) | Rcvd: 4 (184B) | Lost: 0 (0.00%)
  794. Nping done: 1 IP address pinged in 3.26 seconds
  795. #######################################################################################################################################
  796. ; <<>> DiG 9.11.5-P4-1-Debian <<>> vtckosti.gov.sd
  797. ;; global options: +cmd
  798. ;; Got answer:
  799. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 21737
  800. ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
  801.  
  802. ;; OPT PSEUDOSECTION:
  803. ; EDNS: version: 0, flags:; udp: 4096
  804. ;; QUESTION SECTION:
  805. ;vtckosti.gov.sd. IN A
  806.  
  807. ;; ANSWER SECTION:
  808. vtckosti.gov.sd. 11212 IN A 5.9.149.251
  809.  
  810. ;; Query time: 120 msec
  811. ;; SERVER: 185.93.180.131#53(185.93.180.131)
  812. ;; WHEN: mar avr 23 06:47:04 EDT 2019
  813. ;; MSG SIZE rcvd: 60
  814. #######################################################################################################################################
  815. ; <<>> DiG 9.11.5-P4-1-Debian <<>> +trace vtckosti.gov.sd
  816. ;; global options: +cmd
  817. . 82278 IN NS e.root-servers.net.
  818. . 82278 IN NS h.root-servers.net.
  819. . 82278 IN NS m.root-servers.net.
  820. . 82278 IN NS g.root-servers.net.
  821. . 82278 IN NS k.root-servers.net.
  822. . 82278 IN NS c.root-servers.net.
  823. . 82278 IN NS i.root-servers.net.
  824. . 82278 IN NS b.root-servers.net.
  825. . 82278 IN NS j.root-servers.net.
  826. . 82278 IN NS f.root-servers.net.
  827. . 82278 IN NS l.root-servers.net.
  828. . 82278 IN NS d.root-servers.net.
  829. . 82278 IN NS a.root-servers.net.
  830. . 82278 IN RRSIG NS 8 0 518400 20190506050000 20190423040000 25266 . KXjzmSf07KW0mvIPQIh6tgQ+zTmjRCDezLK3iAO+O7YcXMdwY7773kbL fvPTXTp+5imeLrMJHS6j+n99tmaTrDFW3dWQSdxHKcEFmAe7CmwEeQUb Jk0Sug6i1mx1/ql2t8xOD3Hv0NO7TYsZc69mzK15W+xn8RVViLo4hgHE MwjVl8Sm3S1z6KqZw0gJpO/GdO/Pt1r370Aw9p7hL71Z8mQyNWDsOr9M 24uWBq2UwZdpkx3OeE4Uhj2UCrHT8iFaT70iHrfrZgez1QURtkp4SUjr 1lAAKxlV3BFlAL4akM1OWVll8rpt4ZX1nuDNVvP8ND466m3maJoGAV9K D75L3w==
  831. ;; Received 525 bytes from 185.93.180.131#53(185.93.180.131) in 117 ms
  832.  
  833. sd. 172800 IN NS ans2.canar.sd.
  834. sd. 172800 IN NS ans1.canar.sd.
  835. sd. 172800 IN NS ns1.uaenic.ae.
  836. sd. 172800 IN NS sd.cctld.authdns.ripe.net.
  837. sd. 172800 IN NS ns2.uaenic.ae.
  838. sd. 172800 IN NS ans1.sis.sd.
  839. sd. 172800 IN NS ns-sd.afrinic.net.
  840. sd. 86400 IN NSEC se. NS RRSIG NSEC
  841. sd. 86400 IN RRSIG NSEC 8 1 86400 20190506050000 20190423040000 25266 . eH5pPCBMPKRyc4vv1/i90GH6j5i0L9wMWQ2K9HT0cRdnFrqHadF3gPCB YENOobZIvNtSSSXB/UKy2WGoeSbFBmDIkObYPmHEgAmC/hiX/LHgjOEm oVMnpqOACdUK8vXtcum2jSpa3tnrrhF7K9pOntHMx0S90kP70PZ4Xx9g ovIk0homGPg6x++HbnHJYFt1oJAx7Z7ScX5CpK0yCnDkRKxEMx2OhRRn 8ID1uQwz/S2cXSpN+CwtnPVA14Cre5DjYOxHyWIgAG87xZzWg0Md1YF6 3dek7TapvG4sm1k3LyRDPr3sxu6Hs0eJj7Hybbcr3uEzyFla9IqAuRxc vAc4NQ==
  842. ;; Received 702 bytes from 2001:503:ba3e::2:30#53(a.root-servers.net) in 51 ms
  843.  
  844. ;; Received 72 bytes from 213.42.0.226#53(ns1.uaenic.ae) in 236 ms
  845. #######################################################################################################################################
  846. [*] Performing General Enumeration of Domain: vtckosti.gov.sd
  847. [-] DNSSEC is not configured for vtckosti.gov.sd
  848. [*] SOA ns7.mazinhost.net 5.9.149.251
  849. [*] NS ns8.mazinhost.net 5.9.149.251
  850. [*] Bind Version for 5.9.149.251 9.8.2rc1-RedHat-9.8.2-0.62.rc1.el6_9.5
  851. [*] NS ns7.mazinhost.net 5.9.149.251
  852. [*] Bind Version for 5.9.149.251 9.8.2rc1-RedHat-9.8.2-0.62.rc1.el6_9.5
  853. [*] MX vtckosti.gov.sd 5.9.149.251
  854. [*] A vtckosti.gov.sd 5.9.149.251
  855. [*] TXT vtckosti.gov.sd v=spf1 +a +mx +ip4:5.9.149.251 ~all
  856. [*] Enumerating SRV Records
  857. [*] SRV _caldav._tcp.vtckosti.gov.sd ns8.mazinhost.net 5.9.149.251 2079 0
  858. [*] SRV _caldavs._tcp.vtckosti.gov.sd ns8.mazinhost.net 5.9.149.251 2080 0
  859. [*] SRV _carddavs._tcp.vtckosti.gov.sd ns8.mazinhost.net 5.9.149.251 2080 0
  860. [*] SRV _carddav._tcp.vtckosti.gov.sd ns8.mazinhost.net 5.9.149.251 2079 0
  861. [*] SRV _autodiscover._tcp.vtckosti.gov.sd cpanelemaildiscovery.cpanel.net 208.74.123.37 443 0
  862. [*] SRV _autodiscover._tcp.vtckosti.gov.sd cpanelemaildiscovery.cpanel.net 208.74.120.196 443 0
  863. [+] 6 Records Found
  864. #######################################################################################################################################
  865. [*] Processing domain vtckosti.gov.sd
  866. [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  867. [+] Getting nameservers
  868. 5.9.149.251 - ns8.mazinhost.net
  869. 5.9.149.251 - ns7.mazinhost.net
  870. [-] Zone transfer failed
  871.  
  872. [+] TXT records found
  873. "v=spf1 +a +mx +ip4:5.9.149.251 ~all"
  874.  
  875. [+] MX records found, added to target list
  876. 0 vtckosti.gov.sd.
  877.  
  878. [*] Scanning vtckosti.gov.sd for A records
  879. 5.9.149.251 - vtckosti.gov.sd
  880. 5.9.149.251 - autodiscover.vtckosti.gov.sd
  881. 5.9.149.251 - autoconfig.vtckosti.gov.sd
  882. 5.9.149.251 - cpanel.vtckosti.gov.sd
  883. 5.9.149.251 - ftp.vtckosti.gov.sd
  884. 5.9.149.251 - mail.vtckosti.gov.sd
  885. 5.9.149.251 - webdisk.vtckosti.gov.sd
  886. 5.9.149.251 - webmail.vtckosti.gov.sd
  887. 5.9.149.251 - whm.vtckosti.gov.sd
  888. 5.9.149.251 - www.vtckosti.gov.sd #######################################################################################################################################
  889. dnsenum VERSION:1.2.4
  890.  
  891. ----- vtckosti.gov.sd -----
  892.  
  893.  
  894. Host's addresses:
  895. __________________
  896.  
  897. vtckosti.gov.sd. 14400 IN A 5.9.149.251
  898.  
  899.  
  900. Name Servers:
  901. ______________
  902.  
  903. ns7.mazinhost.net. 9323 IN A 5.9.149.251
  904. ns8.mazinhost.net. 11093 IN A 5.9.149.251
  905. ns1.mazinhost.com. 300 IN A 5.9.149.251
  906. ns2.mazinhost.com. 300 IN A 5.9.149.251
  907.  
  908.  
  909. Mail (MX) Servers:
  910. ___________________
  911.  
  912. vtckosti.gov.sd. 14399 IN A 5.9.149.251
  913.  
  914.  
  915. Trying Zone Transfers and getting Bind Versions:
  916. _________________________________________________
  917.  
  918.  
  919. Trying Zone Transfer for vtckosti.gov.sd on ns7.mazinhost.net ...
  920.  
  921. Trying Zone Transfer for vtckosti.gov.sd on ns8.mazinhost.net ...
  922.  
  923. Trying Zone Transfer for vtckosti.gov.sd on ns1.mazinhost.com ...
  924.  
  925. Trying Zone Transfer for vtckosti.gov.sd on ns2.mazinhost.com ...
  926.  
  927. brute force file not specified, bay.
  928. #######################################################################################################################################
  929.  
  930. ____ _ _ _ _ _____
  931. / ___| _ _| |__ | (_)___| |_|___ / _ __
  932. \___ \| | | | '_ \| | / __| __| |_ \| '__|
  933. ___) | |_| | |_) | | \__ \ |_ ___) | |
  934. |____/ \__,_|_.__/|_|_|___/\__|____/|_|
  935.  
  936. # Coded By Ahmed Aboul-Ela - @aboul3la
  937.  
  938. [-] Enumerating subdomains now for vtckosti.gov.sd
  939. [-] verbosity is enabled, will show the subdomains results in realtime
  940. [-] Searching now in Baidu..
  941. [-] Searching now in Yahoo..
  942. [-] Searching now in Google..
  943. [-] Searching now in Bing..
  944. [-] Searching now in Ask..
  945. [-] Searching now in Netcraft..
  946. [-] Searching now in DNSdumpster..
  947. [-] Searching now in Virustotal..
  948. [-] Searching now in ThreatCrowd..
  949. [-] Searching now in SSL Certificates..
  950. [-] Searching now in PassiveDNS..
  951. Virustotal: www.vtckosti.gov.sd
  952. HTTPSConnectionPool(host='dnsdumpster.com', port=443): Read timed out. (read timeout=25)
  953. [-] Saving results to file: /usr/share/sniper/loot//domains/domains-vtckosti.gov.sd.txt
  954. [-] Total Unique Subdomains Found: 1
  955. www.vtckosti.gov.sd
  956. #######################################################################################################################################
  957. ===============================================
  958. -=Subfinder v1.1.3 github.com/subfinder/subfinder
  959. ===============================================
  960.  
  961.  
  962. Running Source: Ask
  963. Running Source: Archive.is
  964. Running Source: Baidu
  965. Running Source: Bing
  966. Running Source: CertDB
  967. Running Source: CertificateTransparency
  968. Running Source: Certspotter
  969. Running Source: Commoncrawl
  970. Running Source: Crt.sh
  971. Running Source: Dnsdb
  972. Running Source: DNSDumpster
  973. Running Source: DNSTable
  974. Running Source: Dogpile
  975. Running Source: Exalead
  976. Running Source: Findsubdomains
  977. Running Source: Googleter
  978. Running Source: Hackertarget
  979. Running Source: Ipv4Info
  980. Running Source: PTRArchive
  981. Running Source: Sitedossier
  982. Running Source: Threatcrowd
  983. Running Source: ThreatMiner
  984. Running Source: WaybackArchive
  985. Running Source: Yahoo
  986.  
  987. Running enumeration on vtckosti.gov.sd
  988.  
  989. dnsdb: Unexpected return status 503
  990.  
  991. ipv4info: <nil>
  992.  
  993. dogpile: Get https://www.dogpile.com/search/web?q=vtckosti.gov.sd&qsi=1: EOF
  994.  
  995. waybackarchive: parse http://web.archive.org/cdx/search/cdx?url=*.vtckosti.gov.sd/*&output=json&fl=original&collapse=urlkey&page=: net/url: invalid control character in URL
  996.  
  997. archiveis: Get https://archive.fo/*.vtckosti.gov.sd: http: server gave HTTP response to HTTPS client
  998.  
  999.  
  1000. Starting Bruteforcing of vtckosti.gov.sd with 9985 words
  1001.  
  1002. Total 9 Unique subdomains found for vtckosti.gov.sd
  1003.  
  1004. .vtckosti.gov.sd
  1005. autoconfig.vtckosti.gov.sd
  1006. autodiscover.vtckosti.gov.sd
  1007. ftp.vtckosti.gov.sd
  1008. mail.vtckosti.gov.sd
  1009. webdisk.vtckosti.gov.sd
  1010. webmail.vtckosti.gov.sd
  1011. whm.vtckosti.gov.sd
  1012. www.vtckosti.gov.sd
  1013. #######################################################################################################################################
  1014. [*] Processing domain vtckosti.gov.sd
  1015. [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  1016. [+] Getting nameservers
  1017. 5.9.149.251 - ns8.mazinhost.net
  1018. 5.9.149.251 - ns2.mazinhost.com
  1019. 5.9.149.251 - ns1.mazinhost.com
  1020. 5.9.149.251 - ns7.mazinhost.net
  1021. [-] Zone transfer failed
  1022.  
  1023. [+] TXT records found
  1024. "v=spf1 +a +mx +ip4:5.9.149.251 ~all"
  1025.  
  1026. [+] MX records found, added to target list
  1027. 0 vtckosti.gov.sd.
  1028.  
  1029. [*] Scanning vtckosti.gov.sd for A records
  1030. 5.9.149.251 - vtckosti.gov.sd
  1031. 5.9.149.251 - autodiscover.vtckosti.gov.sd
  1032. 5.9.149.251 - ftp.vtckosti.gov.sd
  1033. 5.9.149.251 - mail.vtckosti.gov.sd
  1034. 5.9.149.251 - webmail.vtckosti.gov.sd
  1035. 5.9.149.251 - www.vtckosti.gov.sd
  1036. #######################################################################################################################################
  1037. [*] Found SPF record:
  1038. [*] v=spf1 +a +mx +ip4:5.9.149.251 ~all
  1039. [*] SPF record contains an All item: ~all
  1040. [*] No DMARC record found. Looking for organizational record
  1041. [+] No organizational DMARC record
  1042. [+] Spoofing possible for vtckosti.gov.sd!
  1043. #######################################################################################################################################
  1044. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 03:56 EDT
  1045. Nmap scan report for vtckosti.gov.sd (5.9.149.251)
  1046. Host is up (0.13s latency).
  1047. rDNS record for 5.9.149.251: ns8.mazinhost.net
  1048. Not shown: 458 filtered ports, 9 closed ports
  1049. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  1050. PORT STATE SERVICE
  1051. 21/tcp open ftp
  1052. 53/tcp open domain
  1053. 80/tcp open http
  1054. 110/tcp open pop3
  1055. 143/tcp open imap
  1056. 443/tcp open https
  1057. 587/tcp open submission
  1058. 993/tcp open imaps
  1059. 995/tcp open pop3s
  1060. #######################################################################################################################################
  1061. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 03:56 EDT
  1062. Nmap scan report for vtckosti.gov.sd (5.9.149.251)
  1063. Host is up (0.12s latency).
  1064. rDNS record for 5.9.149.251: ns8.mazinhost.net
  1065. Not shown: 2 filtered ports
  1066. PORT STATE SERVICE
  1067. 53/udp open domain
  1068. 67/udp open|filtered dhcps
  1069. 68/udp open|filtered dhcpc
  1070. 69/udp open|filtered tftp
  1071. 88/udp open|filtered kerberos-sec
  1072. 123/udp open|filtered ntp
  1073. 139/udp open|filtered netbios-ssn
  1074. 161/udp open|filtered snmp
  1075. 162/udp open|filtered snmptrap
  1076. 389/udp open|filtered ldap
  1077. 520/udp open|filtered route
  1078. 2049/udp open|filtered nfs
  1079. #######################################################################################################################################
  1080. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 03:56 EDT
  1081. Nmap scan report for vtckosti.gov.sd (5.9.149.251)
  1082. Host is up (0.13s latency).
  1083. rDNS record for 5.9.149.251: ns8.mazinhost.net
  1084.  
  1085. PORT STATE SERVICE VERSION
  1086. 21/tcp open ftp Pure-FTPd
  1087. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1088. Device type: general purpose|firewall|storage-misc|VoIP phone
  1089. Running (JUST GUESSING): Linux 2.6.X|3.X (91%), WatchGuard Fireware 11.X (91%), Synology DiskStation Manager 5.X (90%), Grandstream embedded (85%)
  1090. OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.10 cpe:/o:watchguard:fireware:11.8 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/h:grandstream:gxv3275
  1091. Aggressive OS guesses: Linux 2.6.32 (91%), Linux 2.6.32 or 3.10 (91%), Linux 2.6.39 (91%), Linux 3.4 (91%), WatchGuard Fireware 11.8 (91%), Linux 3.1 - 3.2 (91%), Synology DiskStation Manager 5.1 (90%), Linux 3.10 (89%), Linux 2.6.32 - 2.6.39 (87%), Linux 2.6.18 - 2.6.22 (86%)
  1092. No exact OS matches for host (test conditions non-ideal).
  1093. Network Distance: 11 hops
  1094.  
  1095. TRACEROUTE (using port 21/tcp)
  1096. HOP RTT ADDRESS
  1097. 1 109.81 ms 10.252.200.1
  1098. 2 111.02 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1099. 3 119.62 ms te-5-13-0.bb1.par1.fr.m247.com (193.27.65.201)
  1100. 4 141.62 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1101. 5 119.67 ms 176.10.83.5
  1102. 6 120.44 ms amsix-gw.hetzner.de (80.249.209.55)
  1103. 7 122.45 ms core1.fra.hetzner.com (213.239.203.157)
  1104. 8 126.95 ms core24.fsn1.hetzner.com (213.239.229.78)
  1105. 9 126.94 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.50)
  1106. 10 126.97 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1107. 11 125.07 ms ns8.mazinhost.net (5.9.149.251)
  1108. #######################################################################################################################################
  1109. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 04:07 EDT
  1110. Nmap scan report for vtckosti.gov.sd (5.9.149.251)
  1111. Host is up (0.13s latency).
  1112. rDNS record for 5.9.149.251: ns8.mazinhost.net
  1113.  
  1114. PORT STATE SERVICE VERSION
  1115. 53/tcp open domain ISC BIND 9.8.2rc1 (RedHat Enterprise Linux 6)
  1116. |_dns-fuzz: Server didn't response to our probe, can't fuzz
  1117. | dns-nsec-enum:
  1118. |_ No NSEC records found
  1119. | dns-nsec3-enum:
  1120. |_ DNSSEC NSEC3 not supported
  1121. | dns-nsid:
  1122. |_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.62.rc1.el6_9.5
  1123. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1124. Device type: general purpose|firewall|storage-misc|VoIP phone
  1125. Running (JUST GUESSING): Linux 2.6.X|3.X (91%), WatchGuard Fireware 11.X (91%), Synology DiskStation Manager 5.X (90%), Grandstream embedded (85%)
  1126. OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.10 cpe:/o:watchguard:fireware:11.8 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/h:grandstream:gxv3275
  1127. Aggressive OS guesses: Linux 2.6.32 (91%), Linux 3.10 (91%), Linux 3.4 (91%), WatchGuard Fireware 11.8 (91%), Linux 3.1 - 3.2 (91%), Synology DiskStation Manager 5.1 (90%), Linux 2.6.32 or 3.10 (89%), Linux 2.6.39 (89%), Linux 2.6.32 - 2.6.39 (87%), Linux 2.6.18 - 2.6.22 (86%)
  1128. No exact OS matches for host (test conditions non-ideal).
  1129. Network Distance: 11 hops
  1130. Service Info: OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:6
  1131.  
  1132. Host script results:
  1133. | dns-brute:
  1134. |_ DNS Brute-force hostnames: No results.
  1135.  
  1136. TRACEROUTE (using port 53/tcp)
  1137. HOP RTT ADDRESS
  1138. 1 110.07 ms 10.252.200.1
  1139. 2 110.12 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1140. 3 138.74 ms te-5-13-0.bb1.par1.fr.m247.com (193.27.65.201)
  1141. 4 119.73 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1142. 5 119.79 ms 176.10.83.5
  1143. 6 121.49 ms amsix-gw.hetzner.de (80.249.209.55)
  1144. 7 122.53 ms core1.fra.hetzner.com (213.239.203.157)
  1145. 8 126.70 ms core23.fsn1.hetzner.com (213.239.203.154)
  1146. 9 126.76 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  1147. 10 126.84 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1148. 11 124.94 ms ns8.mazinhost.net (5.9.149.251)
  1149. #######################################################################################################################################
  1150.  
  1151. wig - WebApp Information Gatherer
  1152.  
  1153.  
  1154. Scanning http://vtckosti.gov.sd...
  1155. _______________________________ SITE INFO ________________________________
  1156. IP Title
  1157. 5.9.149.251 مركز التدريب المهني كوستي &#8211; مركز المهن الحياتية ف
  1158.  
  1159. ________________________________ VERSION _________________________________
  1160. Name Versions Type
  1161. WordPress 5.1.1 CMS
  1162. PHP 7.3.1 Platform
  1163.  
  1164. ______________________________ INTERESTING _______________________________
  1165. URL Note Type
  1166. /readme.html Readme file Interesting
  1167. /install.php Installation file Interesting
  1168. /test.php Test file Interesting
  1169. /test.htm Test file Interesting
  1170.  
  1171. _________________________________ TOOLS __________________________________
  1172. Name Link Software
  1173. wpscan https://github.com/wpscanteam/wpscan WordPress
  1174. CMSmap https://github.com/Dionach/CMSmap WordPress
  1175.  
  1176. __________________________________________________________________________
  1177. Time: 718.1 sec Urls: 326 Fingerprints: 40401
  1178. #######################################################################################################################################
  1179. HTTP/1.1 503 Service Unavailable
  1180. Mime-Version: 1.0
  1181. Date: Tue, 23 Apr 2019 08:22:23 GMT
  1182. Content-Type: text/html;charset=utf-8
  1183. Content-Length: 3549
  1184. X-Squid-Error: ERR_CONNECT_FAIL 110
  1185. Vary: Accept-Language
  1186. Content-Language: en
  1187. Connection: keep-alive
  1188.  
  1189. HTTP/1.1 503 Service Unavailable
  1190. Mime-Version: 1.0
  1191. Date: Tue, 23 Apr 2019 08:23:23 GMT
  1192. Content-Type: text/html;charset=utf-8
  1193. Content-Length: 3549
  1194. X-Squid-Error: ERR_CONNECT_FAIL 110
  1195. Vary: Accept-Language
  1196. Content-Language: en
  1197. Connection: keep-alive
  1198. #######################################################################################################################################
  1199. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 04:23 EDT
  1200. Nmap scan report for vtckosti.gov.sd (5.9.149.251)
  1201. Host is up (0.11s latency).
  1202. rDNS record for 5.9.149.251: ns8.mazinhost.net
  1203.  
  1204. PORT STATE SERVICE VERSION
  1205. 110/tcp open pop3 Dovecot pop3d
  1206. | pop3-brute:
  1207. | Accounts: No valid accounts found
  1208. | Statistics: Performed 45 guesses in 40 seconds, average tps: 1.1
  1209. |_ ERROR: Failed to connect.
  1210. |_pop3-capabilities: CAPA SASL(PLAIN LOGIN) RESP-CODES USER STLS TOP AUTH-RESP-CODE PIPELINING UIDL
  1211. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1212. Device type: general purpose|storage-misc|firewall|VoIP phone
  1213. Running (JUST GUESSING): Linux 2.6.X|3.X (91%), Synology DiskStation Manager 5.X (90%), WatchGuard Fireware 11.X (89%), Grandstream embedded (85%)
  1214. OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.10 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:watchguard:fireware:11.8 cpe:/h:grandstream:gxv3275
  1215. Aggressive OS guesses: Linux 2.6.32 (91%), Linux 2.6.39 (91%), Linux 3.10 (91%), Linux 3.4 (91%), Linux 3.1 - 3.2 (91%), Synology DiskStation Manager 5.1 (90%), Linux 2.6.32 or 3.10 (89%), WatchGuard Fireware 11.8 (89%), Linux 2.6.32 - 2.6.39 (87%), Linux 2.6.18 - 2.6.22 (86%)
  1216. No exact OS matches for host (test conditions non-ideal).
  1217. Network Distance: 1 hop
  1218.  
  1219. TRACEROUTE (using port 443/tcp)
  1220. HOP RTT ADDRESS
  1221. 1 109.27 ms ns8.mazinhost.net (5.9.149.251)
  1222. #######################################################################################################################################
  1223. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 04:49 EDT
  1224. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1225. Host is up (0.12s latency).
  1226. Not shown: 454 filtered ports, 14 closed ports
  1227. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  1228. PORT STATE SERVICE
  1229. 21/tcp open ftp
  1230. 53/tcp open domain
  1231. 80/tcp open http
  1232. 143/tcp open imap
  1233. 443/tcp open https
  1234. 465/tcp open smtps
  1235. 587/tcp open submission
  1236. 993/tcp open imaps
  1237. #######################################################################################################################################
  1238. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 04:49 EDT
  1239. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1240. Host is up (0.11s latency).
  1241. Not shown: 2 filtered ports
  1242. PORT STATE SERVICE
  1243. 53/udp open domain
  1244. 67/udp open|filtered dhcps
  1245. 68/udp open|filtered dhcpc
  1246. 69/udp open|filtered tftp
  1247. 88/udp open|filtered kerberos-sec
  1248. 123/udp open|filtered ntp
  1249. 139/udp open|filtered netbios-ssn
  1250. 161/udp open|filtered snmp
  1251. 162/udp open|filtered snmptrap
  1252. 389/udp open|filtered ldap
  1253. 520/udp open|filtered route
  1254. 2049/udp open|filtered nfs
  1255. #######################################################################################################################################
  1256. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 04:49 EDT
  1257. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1258. Host is up (0.13s latency).
  1259.  
  1260. PORT STATE SERVICE VERSION
  1261. 21/tcp open ftp Pure-FTPd
  1262. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1263. Device type: general purpose|storage-misc|firewall
  1264. Running (JUST GUESSING): Linux 2.6.X|3.X (91%), Synology DiskStation Manager 5.X (90%), WatchGuard Fireware 11.X (89%)
  1265. OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.10 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:watchguard:fireware:11.8
  1266. Aggressive OS guesses: Linux 2.6.32 or 3.10 (91%), Synology DiskStation Manager 5.1 (90%), Linux 2.6.32 (89%), Linux 2.6.39 (89%), WatchGuard Fireware 11.8 (89%), Linux 3.1 - 3.2 (89%), Linux 3.10 (88%), Linux 3.4 (88%), Linux 2.6.32 - 2.6.39 (87%), Linux 2.6.18 - 2.6.22 (86%)
  1267. No exact OS matches for host (test conditions non-ideal).
  1268. Network Distance: 11 hops
  1269.  
  1270. TRACEROUTE (using port 21/tcp)
  1271. HOP RTT ADDRESS
  1272. 1 114.34 ms 10.252.200.1
  1273. 2 115.25 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1274. 3 125.09 ms te-2-9-0.bb1.par1.fr.m247.com (185.206.226.108)
  1275. 4 161.31 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1276. 5 123.90 ms 176.10.83.5
  1277. 6 123.96 ms amsix-gw.hetzner.de (80.249.209.55)
  1278. 7 120.72 ms core1.fra.hetzner.com (213.239.203.157)
  1279. 8 125.20 ms core24.fsn1.hetzner.com (213.239.229.78)
  1280. 9 125.24 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  1281. 10 125.33 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1282. 11 125.83 ms ns8.mazinhost.net (5.9.149.251)
  1283. #######################################################################################################################################
  1284. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 05:01 EDT
  1285. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1286. Host is up (0.13s latency).
  1287.  
  1288. PORT STATE SERVICE VERSION
  1289. 53/tcp open domain ISC BIND 9.8.2rc1 (RedHat Enterprise Linux 6)
  1290. |_dns-fuzz: Server didn't response to our probe, can't fuzz
  1291. | dns-nsec-enum:
  1292. |_ No NSEC records found
  1293. | dns-nsec3-enum:
  1294. |_ DNSSEC NSEC3 not supported
  1295. | dns-nsid:
  1296. |_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.62.rc1.el6_9.5
  1297. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  1298. Aggressive OS guesses: Linux 2.6.32 (92%), Linux 2.6.32 or 3.10 (92%), WatchGuard Fireware 11.8 (92%), Synology DiskStation Manager 5.1 (92%), Linux 2.6.39 (91%), Linux 3.4 (91%), Linux 3.1 - 3.2 (91%), Linux 2.6.18 - 2.6.22 (90%), Linux 3.10 (90%), Linux 2.6.32 - 2.6.39 (89%)
  1299. No exact OS matches for host (test conditions non-ideal).
  1300. Network Distance: 11 hops
  1301. Service Info: OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:6
  1302.  
  1303. Host script results:
  1304. | dns-brute:
  1305. | DNS Brute-force hostnames:
  1306. | www.mazinhost.net - 162.251.82.251
  1307. | ns1.mazinhost.net - 95.216.109.43
  1308. | ns2.mazinhost.net - 95.216.109.43
  1309. | ns3.mazinhost.net - 95.216.109.43
  1310. | smtp.mazinhost.net - 208.91.198.143
  1311. | smtp.mazinhost.net - 208.91.199.223
  1312. | smtp.mazinhost.net - 208.91.199.224
  1313. |_ smtp.mazinhost.net - 208.91.199.225
  1314.  
  1315. TRACEROUTE (using port 53/tcp)
  1316. HOP RTT ADDRESS
  1317. 1 116.07 ms 10.252.200.1
  1318. 2 116.12 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1319. 3 155.36 ms vlan2907.bb1.par1.fr.m247.com (212.103.51.185)
  1320. 4 168.08 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1321. 5 125.56 ms 176.10.83.5
  1322. 6 121.50 ms amsix-gw.hetzner.de (80.249.209.55)
  1323. 7 123.55 ms core1.fra.hetzner.com (213.239.203.157)
  1324. 8 128.14 ms core23.fsn1.hetzner.com (213.239.203.154)
  1325. 9 128.22 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.50)
  1326. 10 128.24 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1327. 11 130.26 ms ns8.mazinhost.net (5.9.149.251)
  1328. #######################################################################################################################################
  1329. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 05:02 EDT
  1330. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1331. Host is up (0.13s latency).
  1332.  
  1333. PORT STATE SERVICE VERSION
  1334. 67/udp open|filtered dhcps
  1335. |_dhcp-discover: ERROR: Script execution failed (use -d to debug)
  1336. Too many fingerprints match this host to give specific OS details
  1337. Network Distance: 11 hops
  1338.  
  1339. TRACEROUTE (using proto 1/icmp)
  1340. HOP RTT ADDRESS
  1341. 1 113.83 ms 10.252.200.1
  1342. 2 113.87 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1343. 3 118.00 ms te-2-13-0.bb1.par1.fr.m247.com (212.103.51.189)
  1344. 4 151.89 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1345. 5 117.99 ms 176.10.83.5
  1346. 6 118.04 ms amsix-gw.hetzner.de (80.249.209.55)
  1347. 7 121.46 ms core4.fra.hetzner.com (213.239.252.45)
  1348. 8 128.09 ms core24.fsn1.hetzner.com (213.239.203.150)
  1349. 9 126.15 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  1350. 10 126.25 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1351. 11 126.22 ms ns8.mazinhost.net (5.9.149.251)
  1352. #######################################################################################################################################
  1353. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 05:03 EDT
  1354. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1355. Host is up (0.13s latency).
  1356.  
  1357. PORT STATE SERVICE VERSION
  1358. 68/udp open|filtered dhcpc
  1359. Too many fingerprints match this host to give specific OS details
  1360. Network Distance: 11 hops
  1361.  
  1362. TRACEROUTE (using proto 1/icmp)
  1363. HOP RTT ADDRESS
  1364. 1 109.51 ms 10.252.200.1
  1365. 2 109.71 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1366. 3 119.10 ms te-2-13-0.bb1.par1.fr.m247.com (212.103.51.189)
  1367. 4 119.11 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1368. 5 119.08 ms 176.10.83.5
  1369. 6 119.92 ms amsix-gw.hetzner.de (80.249.209.55)
  1370. 7 122.55 ms core4.fra.hetzner.com (213.239.252.45)
  1371. 8 127.14 ms core24.fsn1.hetzner.com (213.239.203.150)
  1372. 9 127.12 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  1373. 10 127.19 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1374. 11 125.55 ms ns8.mazinhost.net (5.9.149.251)
  1375. #######################################################################################################################################
  1376. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 05:05 EDT
  1377. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1378. Host is up (0.13s latency).
  1379.  
  1380. PORT STATE SERVICE VERSION
  1381. 69/udp open|filtered tftp
  1382. Too many fingerprints match this host to give specific OS details
  1383. Network Distance: 11 hops
  1384.  
  1385. TRACEROUTE (using proto 1/icmp)
  1386. HOP RTT ADDRESS
  1387. 1 108.15 ms 10.252.200.1
  1388. 2 108.34 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1389. 3 118.00 ms te-2-13-0.bb1.par1.fr.m247.com (212.103.51.189)
  1390. 4 156.39 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1391. 5 117.99 ms 176.10.83.5
  1392. 6 118.00 ms amsix-gw.hetzner.de (80.249.209.55)
  1393. 7 120.90 ms core4.fra.hetzner.com (213.239.252.45)
  1394. 8 125.78 ms core24.fsn1.hetzner.com (213.239.203.150)
  1395. 9 125.77 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  1396. 10 125.82 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1397. 11 126.23 ms ns8.mazinhost.net (5.9.149.251)
  1398. #######################################################################################################################################
  1399. HTTP/1.1 200 OK
  1400. Date: Tue, 23 Apr 2019 09:38:02 GMT
  1401. Last-Modified: Tue, 07 Aug 2018 09:11:39 GMT
  1402. Accept-Ranges: bytes
  1403. Content-Length: 163
  1404. Content-Type: text/html
  1405. Connection: keep-alive
  1406.  
  1407. HTTP/1.1 200 OK
  1408. Date: Tue, 23 Apr 2019 09:38:02 GMT
  1409. Last-Modified: Tue, 07 Aug 2018 09:11:39 GMT
  1410. Accept-Ranges: bytes
  1411. Content-Length: 163
  1412. Content-Type: text/html
  1413. Connection: keep-alive
  1414. #######################################################################################################################################
  1415. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 05:38 EDT
  1416. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1417. Host is up (0.13s latency).
  1418.  
  1419. PORT STATE SERVICE VERSION
  1420. 123/udp open|filtered ntp
  1421. Too many fingerprints match this host to give specific OS details
  1422. Network Distance: 11 hops
  1423.  
  1424. TRACEROUTE (using proto 1/icmp)
  1425. HOP RTT ADDRESS
  1426. 1 111.37 ms 10.252.200.1
  1427. 2 113.11 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  1428. 3 122.93 ms te-2-13-0.bb1.par1.fr.m247.com (212.103.51.189)
  1429. 4 122.92 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  1430. 5 121.23 ms 176.10.83.5
  1431. 6 122.90 ms amsix-gw.hetzner.de (80.249.209.55)
  1432. 7 146.31 ms core4.fra.hetzner.com (213.239.252.45)
  1433. 8 127.10 ms core24.fsn1.hetzner.com (213.239.203.150)
  1434. 9 127.13 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  1435. 10 127.18 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  1436. 11 125.27 ms ns8.mazinhost.net (5.9.149.251)
  1437. #######################################################################################################################################
  1438. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 05:48 EDT
  1439. NSE: Loaded 148 scripts for scanning.
  1440. NSE: Script Pre-scanning.
  1441. NSE: Starting runlevel 1 (of 2) scan.
  1442. Initiating NSE at 05:48
  1443. Completed NSE at 05:48, 0.00s elapsed
  1444. NSE: Starting runlevel 2 (of 2) scan.
  1445. Initiating NSE at 05:48
  1446. Completed NSE at 05:48, 0.00s elapsed
  1447. Initiating Ping Scan at 05:48
  1448. Scanning 5.9.149.251 [4 ports]
  1449. Completed Ping Scan at 05:48, 0.15s elapsed (1 total hosts)
  1450. Initiating Parallel DNS resolution of 1 host. at 05:48
  1451. Completed Parallel DNS resolution of 1 host. at 05:48, 0.03s elapsed
  1452. Initiating Connect Scan at 05:48
  1453. Scanning ns8.mazinhost.net (5.9.149.251) [65535 ports]
  1454. Discovered open port 587/tcp on 5.9.149.251
  1455. Discovered open port 143/tcp on 5.9.149.251
  1456. Discovered open port 110/tcp on 5.9.149.251
  1457. Discovered open port 995/tcp on 5.9.149.251
  1458. Discovered open port 993/tcp on 5.9.149.251
  1459. Discovered open port 53/tcp on 5.9.149.251
  1460. Discovered open port 80/tcp on 5.9.149.251
  1461. Discovered open port 443/tcp on 5.9.149.251
  1462. Discovered open port 21/tcp on 5.9.149.251
  1463. Increasing send delay for 5.9.149.251 from 0 to 5 due to max_successful_tryno increase to 5
  1464. Connect Scan Timing: About 0.35% done
  1465. Connect Scan Timing: About 0.55% done
  1466. Increasing send delay for 5.9.149.251 from 5 to 10 due to max_successful_tryno increase to 6
  1467. Warning: 5.9.149.251 giving up on port because retransmission cap hit (6).
  1468. Connect Scan Timing: About 1.00% done
  1469. Connect Scan Timing: About 1.60% done; ETC: 07:54 (2:03:59 remaining)
  1470. Connect Scan Timing: About 2.16% done; ETC: 07:44 (1:53:58 remaining)
  1471. Connect Scan Timing: About 2.89% done; ETC: 07:39 (1:48:00 remaining)
  1472. Connect Scan Timing: About 3.55% done; ETC: 07:34 (1:42:25 remaining)
  1473. Connect Scan Timing: About 5.06% done; ETC: 07:30 (1:36:52 remaining)
  1474. Connect Scan Timing: About 7.54% done; ETC: 07:27 (1:31:37 remaining)
  1475. Connect Scan Timing: About 10.04% done; ETC: 07:24 (1:26:38 remaining)
  1476. Discovered open port 2087/tcp on 5.9.149.251
  1477. Connect Scan Timing: About 13.46% done; ETC: 07:22 (1:21:44 remaining)
  1478. Connect Scan Timing: About 18.06% done; ETC: 07:22 (1:16:59 remaining)
  1479. Connect Scan Timing: About 22.39% done; ETC: 07:21 (1:12:10 remaining)
  1480. Discovered open port 2083/tcp on 5.9.149.251
  1481. Connect Scan Timing: About 27.08% done; ETC: 07:20 (1:07:30 remaining)
  1482. Connect Scan Timing: About 31.91% done; ETC: 07:20 (1:02:52 remaining)
  1483. Connect Scan Timing: About 37.02% done; ETC: 07:20 (0:58:12 remaining)
  1484. Connect Scan Timing: About 41.73% done; ETC: 07:20 (0:53:34 remaining)
  1485. Connect Scan Timing: About 46.57% done; ETC: 07:19 (0:48:58 remaining)
  1486. Connect Scan Timing: About 51.49% done; ETC: 07:19 (0:44:21 remaining)
  1487. Connect Scan Timing: About 56.53% done; ETC: 07:19 (0:39:46 remaining)
  1488. Discovered open port 2096/tcp on 5.9.149.251
  1489. Connect Scan Timing: About 61.40% done; ETC: 07:19 (0:35:11 remaining)
  1490. Connect Scan Timing: About 66.32% done; ETC: 07:18 (0:30:35 remaining)
  1491. Discovered open port 2095/tcp on 5.9.149.251
  1492. Connect Scan Timing: About 71.20% done; ETC: 07:18 (0:26:02 remaining)
  1493. Discovered open port 2082/tcp on 5.9.149.251
  1494. Connect Scan Timing: About 76.12% done; ETC: 07:18 (0:21:29 remaining)
  1495. Connect Scan Timing: About 81.09% done; ETC: 07:17 (0:16:57 remaining)
  1496. Connect Scan Timing: About 86.05% done; ETC: 07:17 (0:12:27 remaining)
  1497. Connect Scan Timing: About 91.05% done; ETC: 07:17 (0:07:58 remaining)
  1498. Discovered open port 2077/tcp on 5.9.149.251
  1499. Connect Scan Timing: About 96.08% done; ETC: 07:16 (0:03:29 remaining)
  1500. Discovered open port 465/tcp on 5.9.149.251
  1501. Completed Connect Scan at 07:18, 5415.07s elapsed (65535 total ports)
  1502. Initiating Service scan at 07:18
  1503. Scanning 16 services on ns8.mazinhost.net (5.9.149.251)
  1504. Service scan Timing: About 68.75% done; ETC: 07:21 (0:01:07 remaining)
  1505. Completed Service scan at 07:20, 155.87s elapsed (16 services on 1 host)
  1506. Initiating OS detection (try #1) against ns8.mazinhost.net (5.9.149.251)
  1507. Retrying OS detection (try #2) against ns8.mazinhost.net (5.9.149.251)
  1508. Initiating Traceroute at 07:21
  1509. Completed Traceroute at 07:21, 0.25s elapsed
  1510. Initiating Parallel DNS resolution of 11 hosts. at 07:21
  1511. Completed Parallel DNS resolution of 11 hosts. at 07:21, 0.37s elapsed
  1512. NSE: Script scanning 5.9.149.251.
  1513. NSE: Starting runlevel 1 (of 2) scan.
  1514. Initiating NSE at 07:21
  1515. NSE Timing: About 99.17% done; ETC: 07:21 (0:00:00 remaining)
  1516. NSE Timing: About 99.31% done; ETC: 07:22 (0:00:00 remaining)
  1517. NSE Timing: About 99.35% done; ETC: 07:22 (0:00:01 remaining)
  1518. NSE Timing: About 99.40% done; ETC: 07:23 (0:00:01 remaining)
  1519. NSE Timing: About 99.86% done; ETC: 07:23 (0:00:00 remaining)
  1520. NSE Timing: About 99.91% done; ETC: 07:24 (0:00:00 remaining)
  1521. NSE Timing: About 99.95% done; ETC: 07:24 (0:00:00 remaining)
  1522. Completed NSE at 07:24, 230.61s elapsed
  1523. NSE: Starting runlevel 2 (of 2) scan.
  1524. Initiating NSE at 07:24
  1525. Completed NSE at 07:24, 1.15s elapsed
  1526. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  1527. Host is up, received syn-ack ttl 64 (0.13s latency).
  1528. Scanned at 2019-04-23 05:48:05 EDT for 5808s
  1529. Not shown: 61615 filtered ports, 3904 closed ports
  1530. Reason: 61615 no-responses and 3904 conn-refused
  1531. PORT STATE SERVICE REASON VERSION
  1532. 21/tcp open ftp syn-ack Pure-FTPd
  1533. | ssl-cert: Subject: commonName=ns8.mazinhost.net/organizationalUnitName=PositiveSSL
  1534. | Subject Alternative Name: DNS:ns8.mazinhost.net, DNS:www.ns8.mazinhost.net
  1535. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US/localityName=Houston
  1536. | Public Key type: rsa
  1537. | Public Key bits: 2048
  1538. | Signature Algorithm: sha256WithRSAEncryption
  1539. | Not valid before: 2018-05-19T00:00:00
  1540. | Not valid after: 2019-05-19T23:59:59
  1541. | MD5: ebe8 f669 2a41 00c3 49f7 f4d6 605d b865
  1542. | SHA-1: 42f1 0588 6bff d05d 2be7 f17f ec1d f54d 10ca 9a97
  1543. | -----BEGIN CERTIFICATE-----
  1544. | MIIGMDCCBRigAwIBAgIQA20Akq/R8L9AhfPMDTevZzANBgkqhkiG9w0BAQsFADBy
  1545. | MQswCQYDVQQGEwJVUzELMAkGA1UECBMCVFgxEDAOBgNVBAcTB0hvdXN0b24xFTAT
  1546. | BgNVBAoTDGNQYW5lbCwgSW5jLjEtMCsGA1UEAxMkY1BhbmVsLCBJbmMuIENlcnRp
  1547. | ZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MDUxOTAwMDAwMFoXDTE5MDUxOTIzNTk1
  1548. | OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQL
  1549. | EwtQb3NpdGl2ZVNTTDEaMBgGA1UEAxMRbnM4Lm1hemluaG9zdC5uZXQwggEiMA0G
  1550. | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTqGFb4g3zsnUiltRO7hvcqefawU/E
  1551. | kbZDDRzv+fC7o9CtmVwnHn4JMBcZccLFkwq33DGK5wP1gHLuU1LHHmxIqjsKCvfT
  1552. | L5iPNqq2QJWVB6VX+0ABIVUqEq1Qk8rX9xnoVw4Vrcf261aHcaMlSKxAqyekay4p
  1553. | azkjinolw0jUEOlM6iEqF62+hBnivrW/NoNxDq7/rRu5HDvHsVa2BOIz9btr3WQN
  1554. | S0vg6hWn9doMX/IRWUx6Ka2aq6w9lv14WXjfxAjDFx8EgmomwpVWbonn3IfPY4rl
  1555. | BdNmiajIk0lmoYoJoOg8s7GHw3pSXmmLnUy4y4v+gjag6g/F7m9Z0MNfAgMBAAGj
  1556. | ggLdMIIC2TAfBgNVHSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4E
  1557. | FgQUC6DptCTqii1lrU89VEly8dWbjgowDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
  1558. | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCME8GA1UdIARIMEYw
  1559. | OgYLKwYBBAGyMQECAjQwKzApBggrBgEFBQcCARYdaHR0cHM6Ly9zZWN1cmUuY29t
  1560. | b2RvLmNvbS9DUFMwCAYGZ4EMAQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9j
  1561. | cmwuY29tb2RvY2EuY29tL2NQYW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHku
  1562. | Y3JsMH0GCCsGAQUFBwEBBHEwbzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21v
  1563. | ZG9jYS5jb20vY1BhbmVsSW5jQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYI
  1564. | KwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAzBgNVHREELDAqghFu
  1565. | czgubWF6aW5ob3N0Lm5ldIIVd3d3Lm5zOC5tYXppbmhvc3QubmV0MIIBBQYKKwYB
  1566. | BAHWeQIEAgSB9gSB8wDxAHcA7ku9t3XOYLrhQmkfq+GeZqMPfl+wctiDAMR7iXqo
  1567. | /csAAAFjeKxlDAAABAMASDBGAiEAqXtMvgZ9tg9Q3gTvmCDrPrOjfLlSZlPENlBl
  1568. | Q8oWEjwCIQCvubT7Fgh4tR2a64m0ff+Qfmgln5G85eo0R/A7JtdHxwB2AHR+2oMx
  1569. | rTMQkSGcziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABY3isZxQAAAQDAEcwRQIgMhVw
  1570. | fjcqeSqm6O64dSjRtzhuJWnOBH927oo6bn2Dx+oCIQCgJarwU54PMCFEWdzhqOHV
  1571. | lmYmuA7X1pBAvPqBUblgiTANBgkqhkiG9w0BAQsFAAOCAQEAKB3KYSjdcG9GfCV1
  1572. | CjHAYbUhvQCZFl2HdUrDVdWGVDjKwlQu6dJpWtsbWjeW7th7D0lpTRcK3kD1011F
  1573. | MVG2EDhwzy+Cg2hiGrpgHG+regMKK4LYdXdayypzF3uGcgs1bjc5l3j1Nd+vVO6Q
  1574. | 4++bqrsRz+TfoDcuMfKh2jO8/IiJrVRykOJYp+TSvzdy5eI/JNW3KDkMC7v/klVo
  1575. | s7JU46rxZSURXjX8a4PonnBxYpJZf+eyuLa9vduB575jIeLAHE8wLjU1ItDLBSBB
  1576. | MAxhbvNLZ2v7qvGs5FWd38xJ0cenlst0WMVXqK/ZDBwfW42EvZveqek2KNo/lKHH
  1577. | Az7cAg==
  1578. |_-----END CERTIFICATE-----
  1579. |_ssl-date: 2019-04-23T11:21:00+00:00; -4s from scanner time.
  1580. 53/tcp open domain syn-ack ISC BIND 9.8.2rc1 (RedHat Enterprise Linux 6)
  1581. | dns-nsid:
  1582. |_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.62.rc1.el6_9.5
  1583. 80/tcp open http-proxy syn-ack Squid http proxy
  1584. |_http-open-proxy: Proxy might be redirecting requests
  1585. |_http-title: 403 Forbidden
  1586. 110/tcp open pop3 syn-ack Dovecot pop3d
  1587. |_pop3-capabilities: SASL(PLAIN LOGIN) STLS TOP AUTH-RESP-CODE USER PIPELINING CAPA RESP-CODES UIDL
  1588. |_ssl-date: 2019-04-23T11:21:00+00:00; -5s from scanner time.
  1589. 143/tcp open imap syn-ack Dovecot imapd
  1590. |_imap-capabilities: OK IMAP4rev1 AUTH=PLAIN NAMESPACE LITERAL+ AUTH=LOGINA0001 Pre-login ENABLE ID have capabilities more STARTTLS IDLE listed LOGIN-REFERRALS post-login SASL-IR
  1591. |_ssl-date: 2019-04-23T11:20:57+00:00; -5s from scanner time.
  1592. 443/tcp open ssl/http syn-ack Apache httpd
  1593. |_http-server-header: Apache
  1594. |_http-title: 403 Forbidden
  1595. 465/tcp open ssl/smtp syn-ack Exim smtpd 4.89_1
  1596. | smtp-commands: ns8.mazinhost.net Hello ns8.mazinhost.net [185.189.113.228], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
  1597. |_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1598. | ssl-cert: Subject: commonName=ns8.mazinhost.net/organizationalUnitName=PositiveSSL
  1599. | Subject Alternative Name: DNS:ns8.mazinhost.net, DNS:www.ns8.mazinhost.net
  1600. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US/localityName=Houston
  1601. | Public Key type: rsa
  1602. | Public Key bits: 2048
  1603. | Signature Algorithm: sha256WithRSAEncryption
  1604. | Not valid before: 2018-05-19T00:00:00
  1605. | Not valid after: 2019-05-19T23:59:59
  1606. | MD5: ebe8 f669 2a41 00c3 49f7 f4d6 605d b865
  1607. | SHA-1: 42f1 0588 6bff d05d 2be7 f17f ec1d f54d 10ca 9a97
  1608. | -----BEGIN CERTIFICATE-----
  1609. | MIIGMDCCBRigAwIBAgIQA20Akq/R8L9AhfPMDTevZzANBgkqhkiG9w0BAQsFADBy
  1610. | MQswCQYDVQQGEwJVUzELMAkGA1UECBMCVFgxEDAOBgNVBAcTB0hvdXN0b24xFTAT
  1611. | BgNVBAoTDGNQYW5lbCwgSW5jLjEtMCsGA1UEAxMkY1BhbmVsLCBJbmMuIENlcnRp
  1612. | ZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MDUxOTAwMDAwMFoXDTE5MDUxOTIzNTk1
  1613. | OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQL
  1614. | EwtQb3NpdGl2ZVNTTDEaMBgGA1UEAxMRbnM4Lm1hemluaG9zdC5uZXQwggEiMA0G
  1615. | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTqGFb4g3zsnUiltRO7hvcqefawU/E
  1616. | kbZDDRzv+fC7o9CtmVwnHn4JMBcZccLFkwq33DGK5wP1gHLuU1LHHmxIqjsKCvfT
  1617. | L5iPNqq2QJWVB6VX+0ABIVUqEq1Qk8rX9xnoVw4Vrcf261aHcaMlSKxAqyekay4p
  1618. | azkjinolw0jUEOlM6iEqF62+hBnivrW/NoNxDq7/rRu5HDvHsVa2BOIz9btr3WQN
  1619. | S0vg6hWn9doMX/IRWUx6Ka2aq6w9lv14WXjfxAjDFx8EgmomwpVWbonn3IfPY4rl
  1620. | BdNmiajIk0lmoYoJoOg8s7GHw3pSXmmLnUy4y4v+gjag6g/F7m9Z0MNfAgMBAAGj
  1621. | ggLdMIIC2TAfBgNVHSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4E
  1622. | FgQUC6DptCTqii1lrU89VEly8dWbjgowDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
  1623. | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCME8GA1UdIARIMEYw
  1624. | OgYLKwYBBAGyMQECAjQwKzApBggrBgEFBQcCARYdaHR0cHM6Ly9zZWN1cmUuY29t
  1625. | b2RvLmNvbS9DUFMwCAYGZ4EMAQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9j
  1626. | cmwuY29tb2RvY2EuY29tL2NQYW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHku
  1627. | Y3JsMH0GCCsGAQUFBwEBBHEwbzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21v
  1628. | ZG9jYS5jb20vY1BhbmVsSW5jQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYI
  1629. | KwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAzBgNVHREELDAqghFu
  1630. | czgubWF6aW5ob3N0Lm5ldIIVd3d3Lm5zOC5tYXppbmhvc3QubmV0MIIBBQYKKwYB
  1631. | BAHWeQIEAgSB9gSB8wDxAHcA7ku9t3XOYLrhQmkfq+GeZqMPfl+wctiDAMR7iXqo
  1632. | /csAAAFjeKxlDAAABAMASDBGAiEAqXtMvgZ9tg9Q3gTvmCDrPrOjfLlSZlPENlBl
  1633. | Q8oWEjwCIQCvubT7Fgh4tR2a64m0ff+Qfmgln5G85eo0R/A7JtdHxwB2AHR+2oMx
  1634. | rTMQkSGcziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABY3isZxQAAAQDAEcwRQIgMhVw
  1635. | fjcqeSqm6O64dSjRtzhuJWnOBH927oo6bn2Dx+oCIQCgJarwU54PMCFEWdzhqOHV
  1636. | lmYmuA7X1pBAvPqBUblgiTANBgkqhkiG9w0BAQsFAAOCAQEAKB3KYSjdcG9GfCV1
  1637. | CjHAYbUhvQCZFl2HdUrDVdWGVDjKwlQu6dJpWtsbWjeW7th7D0lpTRcK3kD1011F
  1638. | MVG2EDhwzy+Cg2hiGrpgHG+regMKK4LYdXdayypzF3uGcgs1bjc5l3j1Nd+vVO6Q
  1639. | 4++bqrsRz+TfoDcuMfKh2jO8/IiJrVRykOJYp+TSvzdy5eI/JNW3KDkMC7v/klVo
  1640. | s7JU46rxZSURXjX8a4PonnBxYpJZf+eyuLa9vduB575jIeLAHE8wLjU1ItDLBSBB
  1641. | MAxhbvNLZ2v7qvGs5FWd38xJ0cenlst0WMVXqK/ZDBwfW42EvZveqek2KNo/lKHH
  1642. | Az7cAg==
  1643. |_-----END CERTIFICATE-----
  1644. |_ssl-date: 2019-04-23T11:20:59+00:00; -5s from scanner time.
  1645. 587/tcp open smtp syn-ack Exim smtpd 4.89_1
  1646. | smtp-commands: ns8.mazinhost.net Hello ns8.mazinhost.net [185.189.113.228], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, STARTTLS, HELP,
  1647. |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1648. | ssl-cert: Subject: commonName=ns8.mazinhost.net/organizationalUnitName=PositiveSSL
  1649. | Subject Alternative Name: DNS:ns8.mazinhost.net, DNS:www.ns8.mazinhost.net
  1650. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US/localityName=Houston
  1651. | Public Key type: rsa
  1652. | Public Key bits: 2048
  1653. | Signature Algorithm: sha256WithRSAEncryption
  1654. | Not valid before: 2018-05-19T00:00:00
  1655. | Not valid after: 2019-05-19T23:59:59
  1656. | MD5: ebe8 f669 2a41 00c3 49f7 f4d6 605d b865
  1657. | SHA-1: 42f1 0588 6bff d05d 2be7 f17f ec1d f54d 10ca 9a97
  1658. | -----BEGIN CERTIFICATE-----
  1659. | MIIGMDCCBRigAwIBAgIQA20Akq/R8L9AhfPMDTevZzANBgkqhkiG9w0BAQsFADBy
  1660. | MQswCQYDVQQGEwJVUzELMAkGA1UECBMCVFgxEDAOBgNVBAcTB0hvdXN0b24xFTAT
  1661. | BgNVBAoTDGNQYW5lbCwgSW5jLjEtMCsGA1UEAxMkY1BhbmVsLCBJbmMuIENlcnRp
  1662. | ZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MDUxOTAwMDAwMFoXDTE5MDUxOTIzNTk1
  1663. | OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQL
  1664. | EwtQb3NpdGl2ZVNTTDEaMBgGA1UEAxMRbnM4Lm1hemluaG9zdC5uZXQwggEiMA0G
  1665. | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTqGFb4g3zsnUiltRO7hvcqefawU/E
  1666. | kbZDDRzv+fC7o9CtmVwnHn4JMBcZccLFkwq33DGK5wP1gHLuU1LHHmxIqjsKCvfT
  1667. | L5iPNqq2QJWVB6VX+0ABIVUqEq1Qk8rX9xnoVw4Vrcf261aHcaMlSKxAqyekay4p
  1668. | azkjinolw0jUEOlM6iEqF62+hBnivrW/NoNxDq7/rRu5HDvHsVa2BOIz9btr3WQN
  1669. | S0vg6hWn9doMX/IRWUx6Ka2aq6w9lv14WXjfxAjDFx8EgmomwpVWbonn3IfPY4rl
  1670. | BdNmiajIk0lmoYoJoOg8s7GHw3pSXmmLnUy4y4v+gjag6g/F7m9Z0MNfAgMBAAGj
  1671. | ggLdMIIC2TAfBgNVHSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4E
  1672. | FgQUC6DptCTqii1lrU89VEly8dWbjgowDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
  1673. | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCME8GA1UdIARIMEYw
  1674. | OgYLKwYBBAGyMQECAjQwKzApBggrBgEFBQcCARYdaHR0cHM6Ly9zZWN1cmUuY29t
  1675. | b2RvLmNvbS9DUFMwCAYGZ4EMAQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9j
  1676. | cmwuY29tb2RvY2EuY29tL2NQYW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHku
  1677. | Y3JsMH0GCCsGAQUFBwEBBHEwbzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21v
  1678. | ZG9jYS5jb20vY1BhbmVsSW5jQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYI
  1679. | KwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAzBgNVHREELDAqghFu
  1680. | czgubWF6aW5ob3N0Lm5ldIIVd3d3Lm5zOC5tYXppbmhvc3QubmV0MIIBBQYKKwYB
  1681. | BAHWeQIEAgSB9gSB8wDxAHcA7ku9t3XOYLrhQmkfq+GeZqMPfl+wctiDAMR7iXqo
  1682. | /csAAAFjeKxlDAAABAMASDBGAiEAqXtMvgZ9tg9Q3gTvmCDrPrOjfLlSZlPENlBl
  1683. | Q8oWEjwCIQCvubT7Fgh4tR2a64m0ff+Qfmgln5G85eo0R/A7JtdHxwB2AHR+2oMx
  1684. | rTMQkSGcziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABY3isZxQAAAQDAEcwRQIgMhVw
  1685. | fjcqeSqm6O64dSjRtzhuJWnOBH927oo6bn2Dx+oCIQCgJarwU54PMCFEWdzhqOHV
  1686. | lmYmuA7X1pBAvPqBUblgiTANBgkqhkiG9w0BAQsFAAOCAQEAKB3KYSjdcG9GfCV1
  1687. | CjHAYbUhvQCZFl2HdUrDVdWGVDjKwlQu6dJpWtsbWjeW7th7D0lpTRcK3kD1011F
  1688. | MVG2EDhwzy+Cg2hiGrpgHG+regMKK4LYdXdayypzF3uGcgs1bjc5l3j1Nd+vVO6Q
  1689. | 4++bqrsRz+TfoDcuMfKh2jO8/IiJrVRykOJYp+TSvzdy5eI/JNW3KDkMC7v/klVo
  1690. | s7JU46rxZSURXjX8a4PonnBxYpJZf+eyuLa9vduB575jIeLAHE8wLjU1ItDLBSBB
  1691. | MAxhbvNLZ2v7qvGs5FWd38xJ0cenlst0WMVXqK/ZDBwfW42EvZveqek2KNo/lKHH
  1692. | Az7cAg==
  1693. |_-----END CERTIFICATE-----
  1694. |_ssl-date: 2019-04-23T11:20:59+00:00; -5s from scanner time.
  1695. 993/tcp open ssl/imaps? syn-ack
  1696. |_ssl-date: 2019-04-23T11:20:57+00:00; -5s from scanner time.
  1697. 995/tcp open ssl/pop3s? syn-ack
  1698. |_ssl-date: 2019-04-23T11:20:57+00:00; -5s from scanner time.
  1699. 2077/tcp open tsrmagt? syn-ack
  1700. | fingerprint-strings:
  1701. | SIPOptions:
  1702. | HTTP/1.1 200 OK
  1703. | Date: Tue, 23 Apr 2019 11:19:53 GMT
  1704. | Server: cPanel
  1705. | Persistent-Auth: false
  1706. | Host: ns8.mazinhost.net:2077
  1707. | Cache-Control: no-cache, no-store, must-revalidate, private
  1708. | Connection: Keep-Alive
  1709. | Vary: Accept-Encoding
  1710. | Allow: GET, PUT, DELETE, PROPPATCH, COPY, PROPFIND, LOCK, OPTIONS, MKCOL, HEAD, UNLOCK, POST, MOVE
  1711. | Content-Length: 0
  1712. | Content-Type: text/plain
  1713. | Expires: Fri, 01 Jan 1990 00:00:00 GMT
  1714. | DAV: 1, 2
  1715. | Keep-Alive: timeout=15, max=96
  1716. |_ MS-Author-Via: DAV
  1717. 2082/tcp open infowave? syn-ack
  1718. | fingerprint-strings:
  1719. | SIPOptions:
  1720. | HTTP/1.0 401 Access Denied
  1721. | Connection: close
  1722. | Content-Type: text/html; charset="utf-8"
  1723. | Date: Tue, 23 Apr 2019 11:19:53 GMT
  1724. | Cache-Control: no-cache, no-store, must-revalidate, private
  1725. | Pragma: no-cache
  1726. | WWW-Authenticate: Basic realm="cPanel"
  1727. | Set-Cookie: cprelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2082
  1728. | Set-Cookie: cpsession=%3aM3T9cwg9l8gihkOD%2cf903463095077d06f6c76b06c1f2f6d1; HttpOnly; path=/; port=2082
  1729. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2082
  1730. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2082
  1731. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2082
  1732. |_ Set-Cookie: horde_secret_key=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-J
  1733. 2083/tcp open ssl/radsec? syn-ack
  1734. | fingerprint-strings:
  1735. | GetRequest:
  1736. | HTTP/1.0 401 Access Denied
  1737. | Connection: close
  1738. | Content-Type: text/html; charset="utf-8"
  1739. | Date: Tue, 23 Apr 2019 11:18:45 GMT
  1740. | Cache-Control: no-cache, no-store, must-revalidate, private
  1741. | Pragma: no-cache
  1742. | WWW-Authenticate: Basic realm="cPanel"
  1743. | Set-Cookie: cprelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1744. | Set-Cookie: cpsession=%3aZtlIwIbfjGuzk_np%2cf7b3043fe5c7b5f94c4a652512b7d89f; HttpOnly; path=/; port=2083; secure
  1745. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1746. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1747. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1748. | Set-Cookie: horde_secret_key=expired; HttpOnly; doma
  1749. | HTTPOptions:
  1750. | HTTP/1.0 401 Access Denied
  1751. | Connection: close
  1752. | Content-Type: text/html; charset="utf-8"
  1753. | Date: Tue, 23 Apr 2019 11:18:46 GMT
  1754. | Cache-Control: no-cache, no-store, must-revalidate, private
  1755. | Pragma: no-cache
  1756. | WWW-Authenticate: Basic realm="cPanel"
  1757. | Set-Cookie: cprelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1758. | Set-Cookie: cpsession=%3aO7q17tD6XYxuSOVr%2c67d1bf02408f4fe4b1a9be18c9e4a2c9; HttpOnly; path=/; port=2083; secure
  1759. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1760. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1761. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2083; secure
  1762. |_ Set-Cookie: horde_secret_key=expired; HttpOnly; doma
  1763. | ssl-cert: Subject: commonName=ns8.mazinhost.net/organizationalUnitName=PositiveSSL
  1764. | Subject Alternative Name: DNS:ns8.mazinhost.net, DNS:www.ns8.mazinhost.net
  1765. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US/localityName=Houston
  1766. | Public Key type: rsa
  1767. | Public Key bits: 2048
  1768. | Signature Algorithm: sha256WithRSAEncryption
  1769. | Not valid before: 2018-05-19T00:00:00
  1770. | Not valid after: 2019-05-19T23:59:59
  1771. | MD5: ebe8 f669 2a41 00c3 49f7 f4d6 605d b865
  1772. | SHA-1: 42f1 0588 6bff d05d 2be7 f17f ec1d f54d 10ca 9a97
  1773. | -----BEGIN CERTIFICATE-----
  1774. | MIIGMDCCBRigAwIBAgIQA20Akq/R8L9AhfPMDTevZzANBgkqhkiG9w0BAQsFADBy
  1775. | MQswCQYDVQQGEwJVUzELMAkGA1UECBMCVFgxEDAOBgNVBAcTB0hvdXN0b24xFTAT
  1776. | BgNVBAoTDGNQYW5lbCwgSW5jLjEtMCsGA1UEAxMkY1BhbmVsLCBJbmMuIENlcnRp
  1777. | ZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MDUxOTAwMDAwMFoXDTE5MDUxOTIzNTk1
  1778. | OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQL
  1779. | EwtQb3NpdGl2ZVNTTDEaMBgGA1UEAxMRbnM4Lm1hemluaG9zdC5uZXQwggEiMA0G
  1780. | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTqGFb4g3zsnUiltRO7hvcqefawU/E
  1781. | kbZDDRzv+fC7o9CtmVwnHn4JMBcZccLFkwq33DGK5wP1gHLuU1LHHmxIqjsKCvfT
  1782. | L5iPNqq2QJWVB6VX+0ABIVUqEq1Qk8rX9xnoVw4Vrcf261aHcaMlSKxAqyekay4p
  1783. | azkjinolw0jUEOlM6iEqF62+hBnivrW/NoNxDq7/rRu5HDvHsVa2BOIz9btr3WQN
  1784. | S0vg6hWn9doMX/IRWUx6Ka2aq6w9lv14WXjfxAjDFx8EgmomwpVWbonn3IfPY4rl
  1785. | BdNmiajIk0lmoYoJoOg8s7GHw3pSXmmLnUy4y4v+gjag6g/F7m9Z0MNfAgMBAAGj
  1786. | ggLdMIIC2TAfBgNVHSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4E
  1787. | FgQUC6DptCTqii1lrU89VEly8dWbjgowDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
  1788. | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCME8GA1UdIARIMEYw
  1789. | OgYLKwYBBAGyMQECAjQwKzApBggrBgEFBQcCARYdaHR0cHM6Ly9zZWN1cmUuY29t
  1790. | b2RvLmNvbS9DUFMwCAYGZ4EMAQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9j
  1791. | cmwuY29tb2RvY2EuY29tL2NQYW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHku
  1792. | Y3JsMH0GCCsGAQUFBwEBBHEwbzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21v
  1793. | ZG9jYS5jb20vY1BhbmVsSW5jQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYI
  1794. | KwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAzBgNVHREELDAqghFu
  1795. | czgubWF6aW5ob3N0Lm5ldIIVd3d3Lm5zOC5tYXppbmhvc3QubmV0MIIBBQYKKwYB
  1796. | BAHWeQIEAgSB9gSB8wDxAHcA7ku9t3XOYLrhQmkfq+GeZqMPfl+wctiDAMR7iXqo
  1797. | /csAAAFjeKxlDAAABAMASDBGAiEAqXtMvgZ9tg9Q3gTvmCDrPrOjfLlSZlPENlBl
  1798. | Q8oWEjwCIQCvubT7Fgh4tR2a64m0ff+Qfmgln5G85eo0R/A7JtdHxwB2AHR+2oMx
  1799. | rTMQkSGcziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABY3isZxQAAAQDAEcwRQIgMhVw
  1800. | fjcqeSqm6O64dSjRtzhuJWnOBH927oo6bn2Dx+oCIQCgJarwU54PMCFEWdzhqOHV
  1801. | lmYmuA7X1pBAvPqBUblgiTANBgkqhkiG9w0BAQsFAAOCAQEAKB3KYSjdcG9GfCV1
  1802. | CjHAYbUhvQCZFl2HdUrDVdWGVDjKwlQu6dJpWtsbWjeW7th7D0lpTRcK3kD1011F
  1803. | MVG2EDhwzy+Cg2hiGrpgHG+regMKK4LYdXdayypzF3uGcgs1bjc5l3j1Nd+vVO6Q
  1804. | 4++bqrsRz+TfoDcuMfKh2jO8/IiJrVRykOJYp+TSvzdy5eI/JNW3KDkMC7v/klVo
  1805. | s7JU46rxZSURXjX8a4PonnBxYpJZf+eyuLa9vduB575jIeLAHE8wLjU1ItDLBSBB
  1806. | MAxhbvNLZ2v7qvGs5FWd38xJ0cenlst0WMVXqK/ZDBwfW42EvZveqek2KNo/lKHH
  1807. | Az7cAg==
  1808. |_-----END CERTIFICATE-----
  1809. |_ssl-date: 2019-04-23T11:20:58+00:00; -5s from scanner time.
  1810. 2087/tcp open ssl/eli? syn-ack
  1811. | fingerprint-strings:
  1812. | GetRequest:
  1813. | HTTP/1.0 401 Access Denied
  1814. | Connection: close
  1815. | Content-Type: text/html; charset="utf-8"
  1816. | Date: Tue, 23 Apr 2019 11:18:45 GMT
  1817. | Cache-Control: no-cache, no-store, must-revalidate, private
  1818. | Pragma: no-cache
  1819. | WWW-Authenticate: Basic realm="Web Host Manager"
  1820. | Set-Cookie: whostmgrrelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1821. | Set-Cookie: whostmgrsession=%3aU3OAHj5GowCtSXss%2c3570e2bb40fb00ba49201bc325d4280f; HttpOnly; path=/; port=2087; secure
  1822. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1823. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1824. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1825. | Set-Cookie: horde_secret_key=e
  1826. | HTTPOptions:
  1827. | HTTP/1.0 401 Access Denied
  1828. | Connection: close
  1829. | Content-Type: text/html; charset="utf-8"
  1830. | Date: Tue, 23 Apr 2019 11:18:46 GMT
  1831. | Cache-Control: no-cache, no-store, must-revalidate, private
  1832. | Pragma: no-cache
  1833. | WWW-Authenticate: Basic realm="Web Host Manager"
  1834. | Set-Cookie: whostmgrrelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1835. | Set-Cookie: whostmgrsession=%3aVvWYjMt5zOAddbhV%2c7261bee0be4d37621fffc0bbe9d91dfa; HttpOnly; path=/; port=2087; secure
  1836. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1837. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1838. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2087; secure
  1839. |_ Set-Cookie: horde_secret_key=e
  1840. | ssl-cert: Subject: commonName=ns8.mazinhost.net/organizationalUnitName=PositiveSSL
  1841. | Subject Alternative Name: DNS:ns8.mazinhost.net, DNS:www.ns8.mazinhost.net
  1842. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US/localityName=Houston
  1843. | Public Key type: rsa
  1844. | Public Key bits: 2048
  1845. | Signature Algorithm: sha256WithRSAEncryption
  1846. | Not valid before: 2018-05-19T00:00:00
  1847. | Not valid after: 2019-05-19T23:59:59
  1848. | MD5: ebe8 f669 2a41 00c3 49f7 f4d6 605d b865
  1849. | SHA-1: 42f1 0588 6bff d05d 2be7 f17f ec1d f54d 10ca 9a97
  1850. | -----BEGIN CERTIFICATE-----
  1851. | MIIGMDCCBRigAwIBAgIQA20Akq/R8L9AhfPMDTevZzANBgkqhkiG9w0BAQsFADBy
  1852. | MQswCQYDVQQGEwJVUzELMAkGA1UECBMCVFgxEDAOBgNVBAcTB0hvdXN0b24xFTAT
  1853. | BgNVBAoTDGNQYW5lbCwgSW5jLjEtMCsGA1UEAxMkY1BhbmVsLCBJbmMuIENlcnRp
  1854. | ZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MDUxOTAwMDAwMFoXDTE5MDUxOTIzNTk1
  1855. | OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQL
  1856. | EwtQb3NpdGl2ZVNTTDEaMBgGA1UEAxMRbnM4Lm1hemluaG9zdC5uZXQwggEiMA0G
  1857. | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTqGFb4g3zsnUiltRO7hvcqefawU/E
  1858. | kbZDDRzv+fC7o9CtmVwnHn4JMBcZccLFkwq33DGK5wP1gHLuU1LHHmxIqjsKCvfT
  1859. | L5iPNqq2QJWVB6VX+0ABIVUqEq1Qk8rX9xnoVw4Vrcf261aHcaMlSKxAqyekay4p
  1860. | azkjinolw0jUEOlM6iEqF62+hBnivrW/NoNxDq7/rRu5HDvHsVa2BOIz9btr3WQN
  1861. | S0vg6hWn9doMX/IRWUx6Ka2aq6w9lv14WXjfxAjDFx8EgmomwpVWbonn3IfPY4rl
  1862. | BdNmiajIk0lmoYoJoOg8s7GHw3pSXmmLnUy4y4v+gjag6g/F7m9Z0MNfAgMBAAGj
  1863. | ggLdMIIC2TAfBgNVHSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4E
  1864. | FgQUC6DptCTqii1lrU89VEly8dWbjgowDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
  1865. | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCME8GA1UdIARIMEYw
  1866. | OgYLKwYBBAGyMQECAjQwKzApBggrBgEFBQcCARYdaHR0cHM6Ly9zZWN1cmUuY29t
  1867. | b2RvLmNvbS9DUFMwCAYGZ4EMAQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9j
  1868. | cmwuY29tb2RvY2EuY29tL2NQYW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHku
  1869. | Y3JsMH0GCCsGAQUFBwEBBHEwbzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21v
  1870. | ZG9jYS5jb20vY1BhbmVsSW5jQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYI
  1871. | KwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAzBgNVHREELDAqghFu
  1872. | czgubWF6aW5ob3N0Lm5ldIIVd3d3Lm5zOC5tYXppbmhvc3QubmV0MIIBBQYKKwYB
  1873. | BAHWeQIEAgSB9gSB8wDxAHcA7ku9t3XOYLrhQmkfq+GeZqMPfl+wctiDAMR7iXqo
  1874. | /csAAAFjeKxlDAAABAMASDBGAiEAqXtMvgZ9tg9Q3gTvmCDrPrOjfLlSZlPENlBl
  1875. | Q8oWEjwCIQCvubT7Fgh4tR2a64m0ff+Qfmgln5G85eo0R/A7JtdHxwB2AHR+2oMx
  1876. | rTMQkSGcziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABY3isZxQAAAQDAEcwRQIgMhVw
  1877. | fjcqeSqm6O64dSjRtzhuJWnOBH927oo6bn2Dx+oCIQCgJarwU54PMCFEWdzhqOHV
  1878. | lmYmuA7X1pBAvPqBUblgiTANBgkqhkiG9w0BAQsFAAOCAQEAKB3KYSjdcG9GfCV1
  1879. | CjHAYbUhvQCZFl2HdUrDVdWGVDjKwlQu6dJpWtsbWjeW7th7D0lpTRcK3kD1011F
  1880. | MVG2EDhwzy+Cg2hiGrpgHG+regMKK4LYdXdayypzF3uGcgs1bjc5l3j1Nd+vVO6Q
  1881. | 4++bqrsRz+TfoDcuMfKh2jO8/IiJrVRykOJYp+TSvzdy5eI/JNW3KDkMC7v/klVo
  1882. | s7JU46rxZSURXjX8a4PonnBxYpJZf+eyuLa9vduB575jIeLAHE8wLjU1ItDLBSBB
  1883. | MAxhbvNLZ2v7qvGs5FWd38xJ0cenlst0WMVXqK/ZDBwfW42EvZveqek2KNo/lKHH
  1884. | Az7cAg==
  1885. |_-----END CERTIFICATE-----
  1886. |_ssl-date: 2019-04-23T11:21:00+00:00; -5s from scanner time.
  1887. 2095/tcp open nbx-ser? syn-ack
  1888. | fingerprint-strings:
  1889. | SIPOptions:
  1890. | HTTP/1.0 401 Access Denied
  1891. | Connection: close
  1892. | Content-Type: text/html; charset="utf-8"
  1893. | Date: Tue, 23 Apr 2019 11:19:53 GMT
  1894. | Cache-Control: no-cache, no-store, must-revalidate, private
  1895. | Pragma: no-cache
  1896. | WWW-Authenticate: Basic realm="WebMail"
  1897. | Set-Cookie: webmailrelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2095
  1898. | Set-Cookie: webmailsession=%3a6BsQnTTAQthEBooz%2cc00209fae915dd5925ada0de198c6aa1; HttpOnly; path=/; port=2095
  1899. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2095
  1900. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2095
  1901. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2095
  1902. |_ Set-Cookie: horde_secret_key=expired; HttpOnly; domain=.ns8.mazinhost.net; expire
  1903. 2096/tcp open ssl/nbx-dir? syn-ack
  1904. | fingerprint-strings:
  1905. | GetRequest:
  1906. | HTTP/1.0 401 Access Denied
  1907. | Connection: close
  1908. | Content-Type: text/html; charset="utf-8"
  1909. | Date: Tue, 23 Apr 2019 11:18:45 GMT
  1910. | Cache-Control: no-cache, no-store, must-revalidate, private
  1911. | Pragma: no-cache
  1912. | WWW-Authenticate: Basic realm="WebMail"
  1913. | Set-Cookie: webmailrelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1914. | Set-Cookie: webmailsession=%3aOlsEefWvomVPQwH3%2cf8ec47567b7719589f5553206ea05a9a; HttpOnly; path=/; port=2096; secure
  1915. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1916. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1917. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1918. | Set-Cookie: horde_secret_key=expired; Htt
  1919. | HTTPOptions:
  1920. | HTTP/1.0 401 Access Denied
  1921. | Connection: close
  1922. | Content-Type: text/html; charset="utf-8"
  1923. | Date: Tue, 23 Apr 2019 11:18:46 GMT
  1924. | Cache-Control: no-cache, no-store, must-revalidate, private
  1925. | Pragma: no-cache
  1926. | WWW-Authenticate: Basic realm="WebMail"
  1927. | Set-Cookie: webmailrelogin=no; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1928. | Set-Cookie: webmailsession=%3avl5HQIzhK8D46szZ%2cb5abf756778552a64816ed2ef45c0ee1; HttpOnly; path=/; port=2096; secure
  1929. | Set-Cookie: roundcube_sessid=expired; HttpOnly; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1930. | Set-Cookie: roundcube_sessauth=expired; HttpOnly; domain=ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1931. | Set-Cookie: Horde=expired; HttpOnly; domain=.ns8.mazinhost.net; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; port=2096; secure
  1932. |_ Set-Cookie: horde_secret_key=expired; Htt
  1933. | ssl-cert: Subject: commonName=ns8.mazinhost.net/organizationalUnitName=PositiveSSL
  1934. | Subject Alternative Name: DNS:ns8.mazinhost.net, DNS:www.ns8.mazinhost.net
  1935. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US/localityName=Houston
  1936. | Public Key type: rsa
  1937. | Public Key bits: 2048
  1938. | Signature Algorithm: sha256WithRSAEncryption
  1939. | Not valid before: 2018-05-19T00:00:00
  1940. | Not valid after: 2019-05-19T23:59:59
  1941. | MD5: ebe8 f669 2a41 00c3 49f7 f4d6 605d b865
  1942. | SHA-1: 42f1 0588 6bff d05d 2be7 f17f ec1d f54d 10ca 9a97
  1943. | -----BEGIN CERTIFICATE-----
  1944. | MIIGMDCCBRigAwIBAgIQA20Akq/R8L9AhfPMDTevZzANBgkqhkiG9w0BAQsFADBy
  1945. | MQswCQYDVQQGEwJVUzELMAkGA1UECBMCVFgxEDAOBgNVBAcTB0hvdXN0b24xFTAT
  1946. | BgNVBAoTDGNQYW5lbCwgSW5jLjEtMCsGA1UEAxMkY1BhbmVsLCBJbmMuIENlcnRp
  1947. | ZmljYXRpb24gQXV0aG9yaXR5MB4XDTE4MDUxOTAwMDAwMFoXDTE5MDUxOTIzNTk1
  1948. | OVowVTEhMB8GA1UECxMYRG9tYWluIENvbnRyb2wgVmFsaWRhdGVkMRQwEgYDVQQL
  1949. | EwtQb3NpdGl2ZVNTTDEaMBgGA1UEAxMRbnM4Lm1hemluaG9zdC5uZXQwggEiMA0G
  1950. | CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTqGFb4g3zsnUiltRO7hvcqefawU/E
  1951. | kbZDDRzv+fC7o9CtmVwnHn4JMBcZccLFkwq33DGK5wP1gHLuU1LHHmxIqjsKCvfT
  1952. | L5iPNqq2QJWVB6VX+0ABIVUqEq1Qk8rX9xnoVw4Vrcf261aHcaMlSKxAqyekay4p
  1953. | azkjinolw0jUEOlM6iEqF62+hBnivrW/NoNxDq7/rRu5HDvHsVa2BOIz9btr3WQN
  1954. | S0vg6hWn9doMX/IRWUx6Ka2aq6w9lv14WXjfxAjDFx8EgmomwpVWbonn3IfPY4rl
  1955. | BdNmiajIk0lmoYoJoOg8s7GHw3pSXmmLnUy4y4v+gjag6g/F7m9Z0MNfAgMBAAGj
  1956. | ggLdMIIC2TAfBgNVHSMEGDAWgBR+A1plQWunfgrhuJ0I6h2OHWrHZTAdBgNVHQ4E
  1957. | FgQUC6DptCTqii1lrU89VEly8dWbjgowDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB
  1958. | /wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCME8GA1UdIARIMEYw
  1959. | OgYLKwYBBAGyMQECAjQwKzApBggrBgEFBQcCARYdaHR0cHM6Ly9zZWN1cmUuY29t
  1960. | b2RvLmNvbS9DUFMwCAYGZ4EMAQIBMEwGA1UdHwRFMEMwQaA/oD2GO2h0dHA6Ly9j
  1961. | cmwuY29tb2RvY2EuY29tL2NQYW5lbEluY0NlcnRpZmljYXRpb25BdXRob3JpdHku
  1962. | Y3JsMH0GCCsGAQUFBwEBBHEwbzBHBggrBgEFBQcwAoY7aHR0cDovL2NydC5jb21v
  1963. | ZG9jYS5jb20vY1BhbmVsSW5jQ2VydGlmaWNhdGlvbkF1dGhvcml0eS5jcnQwJAYI
  1964. | KwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmNvbW9kb2NhLmNvbTAzBgNVHREELDAqghFu
  1965. | czgubWF6aW5ob3N0Lm5ldIIVd3d3Lm5zOC5tYXppbmhvc3QubmV0MIIBBQYKKwYB
  1966. | BAHWeQIEAgSB9gSB8wDxAHcA7ku9t3XOYLrhQmkfq+GeZqMPfl+wctiDAMR7iXqo
  1967. | /csAAAFjeKxlDAAABAMASDBGAiEAqXtMvgZ9tg9Q3gTvmCDrPrOjfLlSZlPENlBl
  1968. | Q8oWEjwCIQCvubT7Fgh4tR2a64m0ff+Qfmgln5G85eo0R/A7JtdHxwB2AHR+2oMx
  1969. | rTMQkSGcziVPQnDCv/1eQiAIxjc1eeYQe8xWAAABY3isZxQAAAQDAEcwRQIgMhVw
  1970. | fjcqeSqm6O64dSjRtzhuJWnOBH927oo6bn2Dx+oCIQCgJarwU54PMCFEWdzhqOHV
  1971. | lmYmuA7X1pBAvPqBUblgiTANBgkqhkiG9w0BAQsFAAOCAQEAKB3KYSjdcG9GfCV1
  1972. | CjHAYbUhvQCZFl2HdUrDVdWGVDjKwlQu6dJpWtsbWjeW7th7D0lpTRcK3kD1011F
  1973. | MVG2EDhwzy+Cg2hiGrpgHG+regMKK4LYdXdayypzF3uGcgs1bjc5l3j1Nd+vVO6Q
  1974. | 4++bqrsRz+TfoDcuMfKh2jO8/IiJrVRykOJYp+TSvzdy5eI/JNW3KDkMC7v/klVo
  1975. | s7JU46rxZSURXjX8a4PonnBxYpJZf+eyuLa9vduB575jIeLAHE8wLjU1ItDLBSBB
  1976. | MAxhbvNLZ2v7qvGs5FWd38xJ0cenlst0WMVXqK/ZDBwfW42EvZveqek2KNo/lKHH
  1977. | Az7cAg==
  1978. |_-----END CERTIFICATE-----
  1979. |_ssl-date: 2019-04-23T11:20:57+00:00; -5s from scanner time.
  1980. 6 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service :
  1981. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  1982. SF-Port2077-TCP:V=7.70%I=7%D=4/23%Time=5CBEF4E5%P=x86_64-pc-linux-gnu%r(SI
  1983. SF:POptions,1E2,"HTTP/1\.1\x20200\x20OK\r\nDate:\x20Tue,\x2023\x20Apr\x202
  1984. SF:019\x2011:19:53\x20GMT\r\nServer:\x20cPanel\r\nPersistent-Auth:\x20fals
  1985. SF:e\r\nHost:\x20ns8\.mazinhost\.net:2077\r\nCache-Control:\x20no-cache,\x
  1986. SF:20no-store,\x20must-revalidate,\x20private\r\nConnection:\x20Keep-Alive
  1987. SF:\r\nVary:\x20Accept-Encoding\r\nAllow:\x20GET,\x20PUT,\x20DELETE,\x20PR
  1988. SF:OPPATCH,\x20COPY,\x20PROPFIND,\x20LOCK,\x20OPTIONS,\x20MKCOL,\x20HEAD,\
  1989. SF:x20UNLOCK,\x20POST,\x20MOVE\r\nContent-Length:\x200\r\nContent-Type:\x2
  1990. SF:0text/plain\r\nExpires:\x20Fri,\x2001\x20Jan\x201990\x2000:00:00\x20GMT
  1991. SF:\r\nDAV:\x201,\x202\r\nKeep-Alive:\x20timeout=15,\x20max=96\r\nMS-Autho
  1992. SF:r-Via:\x20DAV\r\n\r\n");
  1993. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  1994. SF-Port2082-TCP:V=7.70%I=7%D=4/23%Time=5CBEF4DE%P=x86_64-pc-linux-gnu%r(SI
  1995. SF:POptions,2A9E,"HTTP/1\.0\x20401\x20Access\x20Denied\r\nConnection:\x20c
  1996. SF:lose\r\nContent-Type:\x20text/html;\x20charset=\"utf-8\"\r\nDate:\x20Tu
  1997. SF:e,\x2023\x20Apr\x202019\x2011:19:53\x20GMT\r\nCache-Control:\x20no-cach
  1998. SF:e,\x20no-store,\x20must-revalidate,\x20private\r\nPragma:\x20no-cache\r
  1999. SF:\nWWW-Authenticate:\x20Basic\x20realm=\"cPanel\"\r\nSet-Cookie:\x20cpre
  2000. SF:login=no;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GM
  2001. SF:T;\x20path=/;\x20port=2082\r\nSet-Cookie:\x20cpsession=%3aM3T9cwg9l8gih
  2002. SF:kOD%2cf903463095077d06f6c76b06c1f2f6d1;\x20HttpOnly;\x20path=/;\x20port
  2003. SF:=2082\r\nSet-Cookie:\x20roundcube_sessid=expired;\x20HttpOnly;\x20expir
  2004. SF:es=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2082\r\nS
  2005. SF:et-Cookie:\x20roundcube_sessauth=expired;\x20HttpOnly;\x20domain=ns8\.m
  2006. SF:azinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20pa
  2007. SF:th=/;\x20port=2082\r\nSet-Cookie:\x20Horde=expired;\x20HttpOnly;\x20dom
  2008. SF:ain=\.ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x
  2009. SF:20GMT;\x20path=/;\x20port=2082\r\nSet-Cookie:\x20horde_secret_key=expir
  2010. SF:ed;\x20HttpOnly;\x20domain=\.ns8\.mazinhost\.net;\x20expires=Thu,\x2001
  2011. SF:-J");
  2012. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  2013. SF-Port2083-TCP:V=7.70%T=SSL%I=7%D=4/23%Time=5CBEF49A%P=x86_64-pc-linux-gn
  2014. SF:u%r(GetRequest,4000,"HTTP/1\.0\x20401\x20Access\x20Denied\r\nConnection
  2015. SF::\x20close\r\nContent-Type:\x20text/html;\x20charset=\"utf-8\"\r\nDate:
  2016. SF:\x20Tue,\x2023\x20Apr\x202019\x2011:18:45\x20GMT\r\nCache-Control:\x20n
  2017. SF:o-cache,\x20no-store,\x20must-revalidate,\x20private\r\nPragma:\x20no-c
  2018. SF:ache\r\nWWW-Authenticate:\x20Basic\x20realm=\"cPanel\"\r\nSet-Cookie:\x
  2019. SF:20cprelogin=no;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01
  2020. SF:\x20GMT;\x20path=/;\x20port=2083;\x20secure\r\nSet-Cookie:\x20cpsession
  2021. SF:=%3aZtlIwIbfjGuzk_np%2cf7b3043fe5c7b5f94c4a652512b7d89f;\x20HttpOnly;\x
  2022. SF:20path=/;\x20port=2083;\x20secure\r\nSet-Cookie:\x20roundcube_sessid=ex
  2023. SF:pired;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\
  2024. SF:x20path=/;\x20port=2083;\x20secure\r\nSet-Cookie:\x20roundcube_sessauth
  2025. SF:=expired;\x20HttpOnly;\x20domain=ns8\.mazinhost\.net;\x20expires=Thu,\x
  2026. SF:2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2083;\x20secure\r\
  2027. SF:nSet-Cookie:\x20Horde=expired;\x20HttpOnly;\x20domain=\.ns8\.mazinhost\
  2028. SF:.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20
  2029. SF:port=2083;\x20secure\r\nSet-Cookie:\x20horde_secret_key=expired;\x20Htt
  2030. SF:pOnly;\x20doma")%r(HTTPOptions,4000,"HTTP/1\.0\x20401\x20Access\x20Deni
  2031. SF:ed\r\nConnection:\x20close\r\nContent-Type:\x20text/html;\x20charset=\"
  2032. SF:utf-8\"\r\nDate:\x20Tue,\x2023\x20Apr\x202019\x2011:18:46\x20GMT\r\nCac
  2033. SF:he-Control:\x20no-cache,\x20no-store,\x20must-revalidate,\x20private\r\
  2034. SF:nPragma:\x20no-cache\r\nWWW-Authenticate:\x20Basic\x20realm=\"cPanel\"\
  2035. SF:r\nSet-Cookie:\x20cprelogin=no;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-
  2036. SF:1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2083;\x20secure\r\nSet-Cook
  2037. SF:ie:\x20cpsession=%3aO7q17tD6XYxuSOVr%2c67d1bf02408f4fe4b1a9be18c9e4a2c9
  2038. SF:;\x20HttpOnly;\x20path=/;\x20port=2083;\x20secure\r\nSet-Cookie:\x20rou
  2039. SF:ndcube_sessid=expired;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x200
  2040. SF:0:00:01\x20GMT;\x20path=/;\x20port=2083;\x20secure\r\nSet-Cookie:\x20ro
  2041. SF:undcube_sessauth=expired;\x20HttpOnly;\x20domain=ns8\.mazinhost\.net;\x
  2042. SF:20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=20
  2043. SF:83;\x20secure\r\nSet-Cookie:\x20Horde=expired;\x20HttpOnly;\x20domain=\
  2044. SF:.ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT
  2045. SF:;\x20path=/;\x20port=2083;\x20secure\r\nSet-Cookie:\x20horde_secret_key
  2046. SF:=expired;\x20HttpOnly;\x20doma");
  2047. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  2048. SF-Port2087-TCP:V=7.70%T=SSL%I=7%D=4/23%Time=5CBEF49A%P=x86_64-pc-linux-gn
  2049. SF:u%r(GetRequest,4000,"HTTP/1\.0\x20401\x20Access\x20Denied\r\nConnection
  2050. SF::\x20close\r\nContent-Type:\x20text/html;\x20charset=\"utf-8\"\r\nDate:
  2051. SF:\x20Tue,\x2023\x20Apr\x202019\x2011:18:45\x20GMT\r\nCache-Control:\x20n
  2052. SF:o-cache,\x20no-store,\x20must-revalidate,\x20private\r\nPragma:\x20no-c
  2053. SF:ache\r\nWWW-Authenticate:\x20Basic\x20realm=\"Web\x20Host\x20Manager\"\
  2054. SF:r\nSet-Cookie:\x20whostmgrrelogin=no;\x20HttpOnly;\x20expires=Thu,\x200
  2055. SF:1-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2087;\x20secure\r\nSe
  2056. SF:t-Cookie:\x20whostmgrsession=%3aU3OAHj5GowCtSXss%2c3570e2bb40fb00ba4920
  2057. SF:1bc325d4280f;\x20HttpOnly;\x20path=/;\x20port=2087;\x20secure\r\nSet-Co
  2058. SF:okie:\x20roundcube_sessid=expired;\x20HttpOnly;\x20expires=Thu,\x2001-J
  2059. SF:an-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2087;\x20secure\r\nSet-C
  2060. SF:ookie:\x20roundcube_sessauth=expired;\x20HttpOnly;\x20domain=ns8\.mazin
  2061. SF:host\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/
  2062. SF:;\x20port=2087;\x20secure\r\nSet-Cookie:\x20Horde=expired;\x20HttpOnly;
  2063. SF:\x20domain=\.ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:
  2064. SF:00:01\x20GMT;\x20path=/;\x20port=2087;\x20secure\r\nSet-Cookie:\x20hord
  2065. SF:e_secret_key=e")%r(HTTPOptions,4000,"HTTP/1\.0\x20401\x20Access\x20Deni
  2066. SF:ed\r\nConnection:\x20close\r\nContent-Type:\x20text/html;\x20charset=\"
  2067. SF:utf-8\"\r\nDate:\x20Tue,\x2023\x20Apr\x202019\x2011:18:46\x20GMT\r\nCac
  2068. SF:he-Control:\x20no-cache,\x20no-store,\x20must-revalidate,\x20private\r\
  2069. SF:nPragma:\x20no-cache\r\nWWW-Authenticate:\x20Basic\x20realm=\"Web\x20Ho
  2070. SF:st\x20Manager\"\r\nSet-Cookie:\x20whostmgrrelogin=no;\x20HttpOnly;\x20e
  2071. SF:xpires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2087;
  2072. SF:\x20secure\r\nSet-Cookie:\x20whostmgrsession=%3aVvWYjMt5zOAddbhV%2c7261
  2073. SF:bee0be4d37621fffc0bbe9d91dfa;\x20HttpOnly;\x20path=/;\x20port=2087;\x20
  2074. SF:secure\r\nSet-Cookie:\x20roundcube_sessid=expired;\x20HttpOnly;\x20expi
  2075. SF:res=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2087;\x2
  2076. SF:0secure\r\nSet-Cookie:\x20roundcube_sessauth=expired;\x20HttpOnly;\x20d
  2077. SF:omain=ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x
  2078. SF:20GMT;\x20path=/;\x20port=2087;\x20secure\r\nSet-Cookie:\x20Horde=expir
  2079. SF:ed;\x20HttpOnly;\x20domain=\.ns8\.mazinhost\.net;\x20expires=Thu,\x2001
  2080. SF:-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2087;\x20secure\r\nSet
  2081. SF:-Cookie:\x20horde_secret_key=e");
  2082. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  2083. SF-Port2095-TCP:V=7.70%I=7%D=4/23%Time=5CBEF4DE%P=x86_64-pc-linux-gnu%r(SI
  2084. SF:POptions,2A9E,"HTTP/1\.0\x20401\x20Access\x20Denied\r\nConnection:\x20c
  2085. SF:lose\r\nContent-Type:\x20text/html;\x20charset=\"utf-8\"\r\nDate:\x20Tu
  2086. SF:e,\x2023\x20Apr\x202019\x2011:19:53\x20GMT\r\nCache-Control:\x20no-cach
  2087. SF:e,\x20no-store,\x20must-revalidate,\x20private\r\nPragma:\x20no-cache\r
  2088. SF:\nWWW-Authenticate:\x20Basic\x20realm=\"WebMail\"\r\nSet-Cookie:\x20web
  2089. SF:mailrelogin=no;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01
  2090. SF:\x20GMT;\x20path=/;\x20port=2095\r\nSet-Cookie:\x20webmailsession=%3a6B
  2091. SF:sQnTTAQthEBooz%2cc00209fae915dd5925ada0de198c6aa1;\x20HttpOnly;\x20path
  2092. SF:=/;\x20port=2095\r\nSet-Cookie:\x20roundcube_sessid=expired;\x20HttpOnl
  2093. SF:y;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20por
  2094. SF:t=2095\r\nSet-Cookie:\x20roundcube_sessauth=expired;\x20HttpOnly;\x20do
  2095. SF:main=ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x2
  2096. SF:0GMT;\x20path=/;\x20port=2095\r\nSet-Cookie:\x20Horde=expired;\x20HttpO
  2097. SF:nly;\x20domain=\.ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2
  2098. SF:000:00:01\x20GMT;\x20path=/;\x20port=2095\r\nSet-Cookie:\x20horde_secre
  2099. SF:t_key=expired;\x20HttpOnly;\x20domain=\.ns8\.mazinhost\.net;\x20expire"
  2100. SF:);
  2101. ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)==============
  2102. SF-Port2096-TCP:V=7.70%T=SSL%I=7%D=4/23%Time=5CBEF49A%P=x86_64-pc-linux-gn
  2103. SF:u%r(GetRequest,4000,"HTTP/1\.0\x20401\x20Access\x20Denied\r\nConnection
  2104. SF::\x20close\r\nContent-Type:\x20text/html;\x20charset=\"utf-8\"\r\nDate:
  2105. SF:\x20Tue,\x2023\x20Apr\x202019\x2011:18:45\x20GMT\r\nCache-Control:\x20n
  2106. SF:o-cache,\x20no-store,\x20must-revalidate,\x20private\r\nPragma:\x20no-c
  2107. SF:ache\r\nWWW-Authenticate:\x20Basic\x20realm=\"WebMail\"\r\nSet-Cookie:\
  2108. SF:x20webmailrelogin=no;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x2000
  2109. SF::00:01\x20GMT;\x20path=/;\x20port=2096;\x20secure\r\nSet-Cookie:\x20web
  2110. SF:mailsession=%3aOlsEefWvomVPQwH3%2cf8ec47567b7719589f5553206ea05a9a;\x20
  2111. SF:HttpOnly;\x20path=/;\x20port=2096;\x20secure\r\nSet-Cookie:\x20roundcub
  2112. SF:e_sessid=expired;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1970\x2000:00:
  2113. SF:01\x20GMT;\x20path=/;\x20port=2096;\x20secure\r\nSet-Cookie:\x20roundcu
  2114. SF:be_sessauth=expired;\x20HttpOnly;\x20domain=ns8\.mazinhost\.net;\x20exp
  2115. SF:ires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2096;\x
  2116. SF:20secure\r\nSet-Cookie:\x20Horde=expired;\x20HttpOnly;\x20domain=\.ns8\
  2117. SF:.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20
  2118. SF:path=/;\x20port=2096;\x20secure\r\nSet-Cookie:\x20horde_secret_key=expi
  2119. SF:red;\x20Htt")%r(HTTPOptions,4000,"HTTP/1\.0\x20401\x20Access\x20Denied\
  2120. SF:r\nConnection:\x20close\r\nContent-Type:\x20text/html;\x20charset=\"utf
  2121. SF:-8\"\r\nDate:\x20Tue,\x2023\x20Apr\x202019\x2011:18:46\x20GMT\r\nCache-
  2122. SF:Control:\x20no-cache,\x20no-store,\x20must-revalidate,\x20private\r\nPr
  2123. SF:agma:\x20no-cache\r\nWWW-Authenticate:\x20Basic\x20realm=\"WebMail\"\r\
  2124. SF:nSet-Cookie:\x20webmailrelogin=no;\x20HttpOnly;\x20expires=Thu,\x2001-J
  2125. SF:an-1970\x2000:00:01\x20GMT;\x20path=/;\x20port=2096;\x20secure\r\nSet-C
  2126. SF:ookie:\x20webmailsession=%3avl5HQIzhK8D46szZ%2cb5abf756778552a64816ed2e
  2127. SF:f45c0ee1;\x20HttpOnly;\x20path=/;\x20port=2096;\x20secure\r\nSet-Cookie
  2128. SF::\x20roundcube_sessid=expired;\x20HttpOnly;\x20expires=Thu,\x2001-Jan-1
  2129. SF:970\x2000:00:01\x20GMT;\x20path=/;\x20port=2096;\x20secure\r\nSet-Cooki
  2130. SF:e:\x20roundcube_sessauth=expired;\x20HttpOnly;\x20domain=ns8\.mazinhost
  2131. SF:\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:01\x20GMT;\x20path=/;\x2
  2132. SF:0port=2096;\x20secure\r\nSet-Cookie:\x20Horde=expired;\x20HttpOnly;\x20
  2133. SF:domain=\.ns8\.mazinhost\.net;\x20expires=Thu,\x2001-Jan-1970\x2000:00:0
  2134. SF:1\x20GMT;\x20path=/;\x20port=2096;\x20secure\r\nSet-Cookie:\x20horde_se
  2135. SF:cret_key=expired;\x20Htt");
  2136. OS fingerprint not ideal because: Didn't receive UDP response. Please try again with -sSU
  2137. Aggressive OS guesses: Linux 2.6.32 (93%), Linux 2.6.32 or 3.10 (93%), Synology DiskStation Manager 5.1 (92%), WatchGuard Fireware 11.8 (92%), Linux 3.10 (91%), Linux 2.6.39 (90%), Linux 3.4 (90%), Linux 2.6.32 - 2.6.39 (90%), Linux 3.1 - 3.2 (89%), Linux 3.2 - 3.8 (88%)
  2138. No exact OS matches for host (test conditions non-ideal).
  2139. TCP/IP fingerprint:
  2140. SCAN(V=7.70%E=4%D=4/23%OT=21%CT=20%CU=%PV=N%DS=11%DC=T%G=N%TM=5CBEF605%P=x86_64-pc-linux-gnu)
  2141. SEQ(SP=FA%GCD=1%ISR=107%TI=Z%II=I%TS=A)
  2142. OPS(O1=M44FST11NW7%O2=M44FST11NW7%O3=M44FNNT11NW7%O4=M44FST11NW7%O5=M44FST11NW7%O6=M44FST11)
  2143. WIN(W1=3890%W2=3890%W3=3890%W4=3890%W5=3890%W6=3890)
  2144. ECN(R=Y%DF=Y%TG=40%W=3908%O=M44FNNSNW7%CC=Y%Q=)
  2145. T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
  2146. T2(R=N)
  2147. T3(R=N)
  2148. T4(R=N)
  2149. T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
  2150. T6(R=N)
  2151. T7(R=N)
  2152. U1(R=N)
  2153. IE(R=Y%DFI=N%TG=40%CD=S)
  2154.  
  2155. Uptime guess: 0.427 days (since Mon Apr 22 21:10:13 2019)
  2156. Network Distance: 11 hops
  2157. TCP Sequence Prediction: Difficulty=250 (Good luck!)
  2158. IP ID Sequence Generation: All zeros
  2159. Service Info: OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:6
  2160.  
  2161. Host script results:
  2162. |_clock-skew: mean: -4s, deviation: 0s, median: -5s
  2163.  
  2164. TRACEROUTE (using proto 1/icmp)
  2165. HOP RTT ADDRESS
  2166. 1 114.21 ms 10.252.200.1
  2167. 2 117.49 ms vlan200.bb1.par1.fr.m247.com (185.94.189.129)
  2168. 3 123.82 ms te-2-13-0.bb1.par1.fr.m247.com (212.103.51.189)
  2169. 4 123.85 ms te-1-2-2-0.bb1.ams2.nl.m247.com (82.102.29.40)
  2170. 5 123.78 ms 176.10.83.5
  2171. 6 124.22 ms amsix-gw.hetzner.de (80.249.209.55)
  2172. 7 121.20 ms core4.fra.hetzner.com (213.239.252.45)
  2173. 8 127.99 ms core24.fsn1.hetzner.com (213.239.203.150)
  2174. 9 125.59 ms ex9k1.dc10.fsn1.hetzner.com (213.239.229.54)
  2175. 10 125.71 ms static.234.149.9.5.clients.your-server.de (5.9.149.234)
  2176. 11 125.84 ms ns8.mazinhost.net (5.9.149.251)
  2177.  
  2178. NSE: Script Post-scanning.
  2179. NSE: Starting runlevel 1 (of 2) scan.
  2180. Initiating NSE at 07:24
  2181. Completed NSE at 07:24, 0.00s elapsed
  2182. NSE: Starting runlevel 2 (of 2) scan.
  2183. Initiating NSE at 07:24
  2184. Completed NSE at 07:24, 0.00s elapsed
  2185. Read data files from: /usr/bin/../share/nmap
  2186. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  2187. Nmap done: 1 IP address (1 host up) scanned in 5808.25 seconds
  2188. Raw packets sent: 92 (7.316KB) | Rcvd: 36 (2.906KB)
  2189. #######################################################################################################################################
  2190. Starting Nmap 7.70 ( https://nmap.org ) at 2019-04-23 07:24 EDT
  2191. NSE: Loaded 148 scripts for scanning.
  2192. NSE: Script Pre-scanning.
  2193. Initiating NSE at 07:24
  2194. Completed NSE at 07:24, 0.00s elapsed
  2195. Initiating NSE at 07:24
  2196. Completed NSE at 07:24, 0.00s elapsed
  2197. Initiating Parallel DNS resolution of 1 host. at 07:24
  2198. Completed Parallel DNS resolution of 1 host. at 07:24, 0.03s elapsed
  2199. Initiating UDP Scan at 07:24
  2200. Scanning ns8.mazinhost.net (5.9.149.251) [14 ports]
  2201. Discovered open port 53/udp on 5.9.149.251
  2202. Completed UDP Scan at 07:24, 1.96s elapsed (14 total ports)
  2203. Initiating Service scan at 07:24
  2204. Scanning 12 services on ns8.mazinhost.net (5.9.149.251)
  2205. Service scan Timing: About 16.67% done; ETC: 07:34 (0:08:05 remaining)
  2206. Completed Service scan at 07:26, 102.58s elapsed (12 services on 1 host)
  2207. Initiating OS detection (try #1) against ns8.mazinhost.net (5.9.149.251)
  2208. Retrying OS detection (try #2) against ns8.mazinhost.net (5.9.149.251)
  2209. Initiating Traceroute at 07:26
  2210. Completed Traceroute at 07:26, 7.15s elapsed
  2211. Initiating Parallel DNS resolution of 1 host. at 07:26
  2212. Completed Parallel DNS resolution of 1 host. at 07:26, 0.01s elapsed
  2213. NSE: Script scanning 5.9.149.251.
  2214. Initiating NSE at 07:26
  2215. Completed NSE at 07:27, 20.30s elapsed
  2216. Initiating NSE at 07:27
  2217. Completed NSE at 07:27, 1.03s elapsed
  2218. Nmap scan report for ns8.mazinhost.net (5.9.149.251)
  2219. Host is up (0.12s latency).
  2220.  
  2221. PORT STATE SERVICE VERSION
  2222. 53/udp open domain ISC BIND 9.8.2rc1 (RedHat Enterprise Linux 6)
  2223. | dns-nsid:
  2224. |_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.62.rc1.el6_9.5
  2225. 67/udp open|filtered dhcps
  2226. 68/udp open|filtered dhcpc
  2227. 69/udp open|filtered tftp
  2228. 88/udp open|filtered kerberos-sec
  2229. 123/udp open|filtered ntp
  2230. 137/udp filtered netbios-ns
  2231. 138/udp filtered netbios-dgm
  2232. 139/udp open|filtered netbios-ssn
  2233. 161/udp open|filtered snmp
  2234. 162/udp open|filtered snmptrap
  2235. 389/udp open|filtered ldap
  2236. 520/udp open|filtered route
  2237. 2049/udp open|filtered nfs
  2238. Too many fingerprints match this host to give specific OS details
  2239. Service Info: OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:6
  2240.  
  2241. TRACEROUTE (using port 137/udp)
  2242. HOP RTT ADDRESS
  2243. 1 108.15 ms 10.252.200.1
  2244. 2 ... 3
  2245. 4 108.14 ms 10.252.200.1
  2246. 5 109.95 ms 10.252.200.1
  2247. 6 109.94 ms 10.252.200.1
  2248. 7 109.92 ms 10.252.200.1
  2249. 8 109.91 ms 10.252.200.1
  2250. 9 109.90 ms 10.252.200.1
  2251. 10 109.92 ms 10.252.200.1
  2252. 11 ... 18
  2253. 19 109.12 ms 10.252.200.1
  2254. 20 109.35 ms 10.252.200.1
  2255. 21 ... 28
  2256. 29 109.68 ms 10.252.200.1
  2257. 30 108.04 ms 10.252.200.1
  2258.  
  2259. NSE: Script Post-scanning.
  2260. Initiating NSE at 07:27
  2261. Completed NSE at 07:27, 0.00s elapsed
  2262. Initiating NSE at 07:27
  2263. Completed NSE at 07:27, 0.00s elapsed
  2264. Read data files from: /usr/bin/../share/nmap
  2265. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  2266. Nmap done: 1 IP address (1 host up) scanned in 136.92 seconds
  2267. Raw packets sent: 131 (11.438KB) | Rcvd: 43 (4.422KB)
  2268. #######################################################################################################################################
  2269. [+] URL: http://vtckosti.gov.sd/
  2270. [+] Started: Tue Apr 23 02:39:22 2019
  2271.  
  2272. Interesting Finding(s):
  2273.  
  2274. [+] http://vtckosti.gov.sd/
  2275. | Interesting Entries:
  2276. | - X-Powered-By: PHP/7.3.1
  2277. | - X-UA-Compatible: IE=edge
  2278. | Found By: Headers (Passive Detection)
  2279. | Confidence: 100%
  2280.  
  2281. [+] http://vtckosti.gov.sd/xmlrpc.php
  2282. | Found By: Link Tag (Passive Detection)
  2283. | Confidence: 100%
  2284. | Confirmed By: Direct Access (Aggressive Detection), 100% confidence
  2285. | References:
  2286. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  2287. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  2288. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  2289. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  2290. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  2291.  
  2292. [+] http://vtckosti.gov.sd/readme.html
  2293. | Found By: Direct Access (Aggressive Detection)
  2294. | Confidence: 100%
  2295.  
  2296. [+] Registration is enabled: http://vtckosti.gov.sd/wp-login.php?action=register
  2297. | Found By: Direct Access (Aggressive Detection)
  2298. | Confidence: 100%
  2299.  
  2300. [+] http://vtckosti.gov.sd/wp-cron.php
  2301. | Found By: Direct Access (Aggressive Detection)
  2302. | Confidence: 60%
  2303. | References:
  2304. | - https://www.iplocation.net/defend-wordpress-from-ddos
  2305. | - https://github.com/wpscanteam/wpscan/issues/1299
  2306.  
  2307. [+] WordPress version 5.1.1 identified (Latest, released on 2019-03-13).
  2308. | Detected By: Rss Generator (Passive Detection)
  2309. | - http://vtckosti.gov.sd/?feed=rss2, <generator>https://wordpress.org/?v=5.1.1</generator>
  2310. | - http://vtckosti.gov.sd/?feed=comments-rss2, <generator>https://wordpress.org/?v=5.1.1</generator>
  2311.  
  2312. [+] WordPress theme in use: jannah
  2313. | Location: http://vtckosti.gov.sd/wp-content/themes/jannah/
  2314. | Style URL: http://vtckosti.gov.sd/wp-content/themes/jannah/style.css
  2315. | Style Name: Jannah
  2316. | Style URI: http://jannah.tielabs.com/
  2317. | Description: Beautiful, Powerful & Flexible WordPress Theme for News, Magazine and Blog websites....
  2318. | Author: TieLabs
  2319. | Author URI: https://tielabs.com/
  2320. |
  2321. | Detected By: Urls In Homepage (Passive Detection)
  2322. |
  2323. | Version: 2.0.4 (80% confidence)
  2324. | Detected By: Style (Passive Detection)
  2325. | - http://vtckosti.gov.sd/wp-content/themes/jannah/style.css, Match: 'Version: 2.0.4'
  2326.  
  2327. [+] Enumerating All Plugins (via Passive Methods)
  2328. [+] Checking Plugin Versions (via Passive and Aggressive Methods)
  2329.  
  2330. [i] Plugin(s) Identified:
  2331.  
  2332. [+] contact-form-7
  2333. | Location: http://vtckosti.gov.sd/wp-content/plugins/contact-form-7/
  2334. | Latest Version: 5.1.1 (up to date)
  2335. | Last Updated: 2018-12-18T18:05:00.000Z
  2336. |
  2337. | Detected By: Urls In Homepage (Passive Detection)
  2338. |
  2339. | Version: 5.1.1 (100% confidence)
  2340. | Detected By: Readme - Stable Tag (Aggressive Detection)
  2341. | - http://vtckosti.gov.sd/wp-content/plugins/contact-form-7/readme.txt
  2342. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  2343. | - http://vtckosti.gov.sd/wp-content/plugins/contact-form-7/readme.txt
  2344.  
  2345. [+] gtranslate
  2346. | Location: http://vtckosti.gov.sd/wp-content/plugins/gtranslate/
  2347. | Latest Version: 2.8.46 (up to date)
  2348. | Last Updated: 2019-03-02T09:44:00.000Z
  2349. |
  2350. | Detected By: Urls In Homepage (Passive Detection)
  2351. |
  2352. | Version: 2.8.46 (100% confidence)
  2353. | Detected By: Readme - Stable Tag (Aggressive Detection)
  2354. | - http://vtckosti.gov.sd/wp-content/plugins/gtranslate/readme.txt
  2355. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  2356. | - http://vtckosti.gov.sd/wp-content/plugins/gtranslate/readme.txt
  2357.  
  2358. [+] instanow
  2359. | Location: http://vtckosti.gov.sd/wp-content/plugins/instanow/
  2360. |
  2361. | Detected By: Urls In Homepage (Passive Detection)
  2362. |
  2363. | The version could not be determined.
  2364.  
  2365. [+] js_composer
  2366. | Location: http://vtckosti.gov.sd/wp-content/plugins/js_composer/
  2367. |
  2368. | Detected By: Urls In Homepage (Passive Detection)
  2369. | Confirmed By: Body Tag (Passive Detection)
  2370. |
  2371. | Version: 5.7 (60% confidence)
  2372. | Detected By: Body Tag (Passive Detection)
  2373. | - http://vtckosti.gov.sd/, Match: 'js-comp-ver-5.7'
  2374.  
  2375. [+] mailpoet
  2376. | Location: http://vtckosti.gov.sd/wp-content/plugins/mailpoet/
  2377. | Last Updated: 2019-04-16T07:53:00.000Z
  2378. | [!] The version is out of date, the latest version is 3.23.2
  2379. |
  2380. | Detected By: Urls In Homepage (Passive Detection)
  2381. |
  2382. | Version: 3.22.0 (80% confidence)
  2383. | Detected By: Readme - Stable Tag (Aggressive Detection)
  2384. | - http://vtckosti.gov.sd/wp-content/plugins/mailpoet/readme.txt
  2385.  
  2386. [+] mechanic-visitor-counter
  2387. | Location: http://vtckosti.gov.sd/wp-content/plugins/mechanic-visitor-counter/
  2388. | Last Updated: 2016-12-28T11:49:00.000Z
  2389. | [!] The version is out of date, the latest version is 3.2.2
  2390. |
  2391. | Detected By: Urls In Homepage (Passive Detection)
  2392. |
  2393. | Version: 3.1 (80% confidence)
  2394. | Detected By: Readme - Stable Tag (Aggressive Detection)
  2395. | - http://vtckosti.gov.sd/wp-content/plugins/mechanic-visitor-counter/readme.txt
  2396.  
  2397. [+] photo-gallery
  2398. | Location: http://vtckosti.gov.sd/wp-content/plugins/photo-gallery/
  2399. | Last Updated: 2019-04-22T13:24:00.000Z
  2400. | [!] The version is out of date, the latest version is 1.5.21
  2401. |
  2402. | Detected By: Urls In Homepage (Passive Detection)
  2403. |
  2404. | Version: 1.5.20 (100% confidence)
  2405. | Detected By: Readme - Stable Tag (Aggressive Detection)
  2406. | - http://vtckosti.gov.sd/wp-content/plugins/photo-gallery/readme.txt
  2407. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  2408. | - http://vtckosti.gov.sd/wp-content/plugins/photo-gallery/readme.txt
  2409.  
  2410. [+] taqyeem-buttons
  2411. | Location: http://vtckosti.gov.sd/wp-content/plugins/taqyeem-buttons/
  2412. |
  2413. | Detected By: Urls In Homepage (Passive Detection)
  2414. |
  2415. | The version could not be determined.
  2416.  
  2417. [+] traffic-counter-widget
  2418. | Location: http://vtckosti.gov.sd/wp-content/plugins/traffic-counter-widget/
  2419. | Latest Version: 2.1.2 (up to date)
  2420. | Last Updated: 2012-12-15T18:41:00.000Z
  2421. |
  2422. | Detected By: Urls In Homepage (Passive Detection)
  2423. |
  2424. | Version: 2.1.2 (80% confidence)
  2425. | Detected By: Readme - Stable Tag (Aggressive Detection)
  2426. | - http://vtckosti.gov.sd/wp-content/plugins/traffic-counter-widget/readme.txt
  2427.  
  2428. [+] wp-statistics
  2429. | Location: http://vtckosti.gov.sd/wp-content/plugins/wp-statistics/
  2430. | Last Updated: 2019-04-13T12:28:00.000Z
  2431. | [!] The version is out of date, the latest version is 12.6.3
  2432. |
  2433. | Detected By: Comment (Passive Detection)
  2434. |
  2435. | Version: 12.6.1 (100% confidence)
  2436. | Detected By: Comment (Passive Detection)
  2437. | - http://vtckosti.gov.sd/, Match: 'Analytics by WP-Statistics v12.6.1'
  2438. | Confirmed By:
  2439. | Readme - Stable Tag (Aggressive Detection)
  2440. | - http://vtckosti.gov.sd/wp-content/plugins/wp-statistics/readme.txt
  2441. | Readme - ChangeLog Section (Aggressive Detection)
  2442. | - http://vtckosti.gov.sd/wp-content/plugins/wp-statistics/readme.txt
  2443.  
  2444. [+] Enumerating Config Backups (via Passive and Aggressive Methods)
  2445. Checking Config Backups - Time: 00:00:01 <===> (21 / 21) 100.00% Time: 00:00:01
  2446.  
  2447. [i] No Config Backups Found.
  2448.  
  2449.  
  2450. [+] Finished: Tue Apr 23 02:40:38 2019
  2451. [+] Requests Done: 81
  2452. [+] Cached Requests: 5
  2453. [+] Data Sent: 23.907 KB
  2454. [+] Data Received: 645.756 KB
  2455. [+] Memory used: 192.227 MB
  2456. [+] Elapsed time: 00:01:15
  2457. #######################################################################################################################################
  2458. --------------------------------------------------------------------------------------------------------------------------------------
  2459. + Target IP: 5.9.149.251
  2460. + Target Hostname: vtckosti.gov.sd
  2461. + Target Port: 80
  2462. + Start Time: 2019-04-23 03:23:39 (GMT-4)
  2463. ---------------------------------------------------------------------------------------------------------------------------------------
  2464. + Server: No banner retrieved
  2465. + The anti-clickjacking X-Frame-Options header is not present.
  2466. + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
  2467. + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
  2468. + ERROR: Error limit (20) reached for host, giving up. Last error: error reading HTTP response
  2469. + Scan terminated: 20 error(s) and 3 item(s) reported on remote host
  2470. + End Time: 2019-04-23 03:30:26 (GMT-4) (407 seconds)
  2471. ---------------------------------------------------------------------------------------------------------------------------------------
  2472. ######################################################################################################################################
  2473. ---------------------------------------------------------------------------------------------------------------------------------------
  2474. + Target IP: 5.9.149.251
  2475. + Target Hostname: 5.9.149.251
  2476. + Target Port: 443
  2477. ---------------------------------------------------------------------------------------------------------------------------------------
  2478. + SSL Info: Subject: /CN=aau.edu.sd
  2479. Ciphers: ECDHE-RSA-AES256-GCM-SHA384
  2480. Issuer: /CN=aau.edu.sd
  2481. + Start Time: 2019-04-23 03:24:35 (GMT-4)
  2482. ---------------------------------------------------------------------------------------------------------------------------------------
  2483. + Server: Apache
  2484. + The anti-clickjacking X-Frame-Options header is not present.
  2485. + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
  2486. + The site uses SSL and the Strict-Transport-Security HTTP header is not defined.
  2487. + The site uses SSL and Expect-CT header is not present.
  2488. + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
  2489. + ERROR: Error limit (20) reached for host, giving up. Last error: opening stream: can't connect: Connect failed: ; Connection timed out at /var/lib/nikto/plugins/LW2.pm line 5157.
  2490. : Connection timed out
  2491. + Scan terminated: 20 error(s) and 5 item(s) reported on remote host
  2492. + End Time: 2019-04-23 03:31:21 (GMT-4) (406 seconds)
  2493. ---------------------------------------------------------------------------------------------------------------------------------------
  2494. #######################################################################################################################################
  2495. Anonymous JTSEC #OpSudan Full Recon #59
Advertisement
Add Comment
Please, Sign In to add comment