JTSEC1333

Anonymous JTSEC #OpDomesticTerrorism Full Recon #5

Oct 22nd, 2019
909
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 97.72 KB | None | 0 0
  1. #######################################################################################################################################
  2. =======================================================================================================================================
  3. Hostname fortressoffaith.com ISP Liquid Web, L.L.C
  4. Continent North America Flag
  5. US
  6. Country United States Country Code US
  7. Region Michigan Local time 22 Oct 2019 06:58 EDT
  8. City Lansing Postal Code 48917
  9. IP Address 72.52.244.17 Latitude 42.735
  10. Longitude -84.625
  11. ======================================================================================================================================
  12. #######################################################################################################################################
  13. > fortressoffaith.com
  14. Server: 185.93.180.131
  15. Address: 185.93.180.131#53
  16.  
  17. Non-authoritative answer:
  18. Name: fortressoffaith.com
  19. Address: 72.52.244.17
  20. >
  21. #######################################################################################################################################
  22. Domain Name: FORTRESSOFFAITH.COM
  23. Registry Domain ID: 1555724340_DOMAIN_COM-VRSN
  24. Registrar WHOIS Server: whois.domaindiscover.com
  25. Registrar URL: http://www.domaindiscover.com
  26. Updated Date: 2017-09-10T17:28:57Z
  27. Creation Date: 2009-05-14T22:06:41Z
  28. Registry Expiry Date: 2024-05-14T22:06:41Z
  29. Registrar: TierraNet Inc. d/b/a DomainDiscover
  30. Registrar IANA ID: 86
  31. Registrar Abuse Contact Email: [email protected]
  32. Registrar Abuse Contact Phone: 858-560-9416
  33. Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
  34. Name Server: NS1.BIGHORNHOSTING.COM
  35. Name Server: NS2.BIGHORNHOSTING.COM
  36. DNSSEC: unsigned
  37. #######################################################################################################################################
  38. Domain Name: FORTRESSOFFAITH.COM
  39. Registry Domain ID:
  40. Registrar WHOIS Server: whois.domaindiscover.com
  41. Registrar URL: https://www.tierra.net
  42. Updated Date: 2017-09-10T10:28:20Z
  43. Creation Date: 2009-05-14T15:06:40Z
  44. Registrar Registration Expiration Date: 2024-05-14T14:06:41Z
  45. Registrar: TIERRANET INC. DBA DOMAINDISCOVER
  46. Registrar IANA ID: 86
  47. Registrar Abuse Contact Email: [email protected]
  48. Registrar Abuse Contact Phone: +1.6193932105
  49. Reseller:
  50. Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
  51. Registry Registrant ID:
  52. Registrant Name: Tom Wallace
  53. Registrant Organization: Fortress of Faith
  54. Registrant Street: PO Box 30485
  55. Registrant City: Bellingham
  56. Registrant State/Province: WA
  57. Registrant Postal Code: 98228
  58. Registrant Country: US
  59. Registrant Phone: +1.3608205904
  60. Registrant Phone Ext:
  61. Registrant Fax:
  62. Registrant Fax Ext:
  63. Registrant Email: [email protected]
  64. Registry Admin ID:
  65. Admin Name: Tom Wallace
  66. Admin Organization: Fortress of Faith
  67. Admin Street: PO Box 30485
  68. Admin City: Bellingham
  69. Admin State/Province: WA
  70. Admin Postal Code: 98228
  71. Admin Country: US
  72. Admin Phone: +1.3608205904
  73. Admin Phone Ext:
  74. Admin Fax:
  75. Admin Fax Ext:
  76. Admin Email: [email protected]
  77. Registry Tech ID:
  78. Tech Name: Tom Wallace
  79. Tech Organization: Fortress of Faith
  80. Tech Street: PO Box 30485
  81. Tech City: Bellingham
  82. Tech State/Province: WA
  83. Tech Postal Code: 98228
  84. Tech Country: US
  85. Tech Phone: +1.3608205904
  86. Tech Phone Ext:
  87. Tech Fax:
  88. Tech Fax Ext:
  89. Tech Email: [email protected]
  90. Name Server: NS1.BIGHORNHOSTING.COM
  91. Name Server: NS2.BIGHORNHOSTING.COM
  92. DNSSEC:
  93. #######################################################################################################################################
  94. [+] Target : fortressoffaith.com
  95.  
  96. [+] IP Address : 72.52.244.17
  97.  
  98. [+] Headers :
  99.  
  100. [+] Connection : Keep-Alive
  101. [+] X-Powered-By : PHP/7.0.33
  102. [+] Access-Control-Allow-Origin : *
  103. [+] Expires : Thu, 19 Nov 1981 08:52:00 GMT
  104. [+] Cache-Control : no-store, no-cache, must-revalidate
  105. [+] Pragma : no-cache
  106. [+] Content-Type : text/html; charset=UTF-8
  107. [+] X-UA-Compatible : IE=edge
  108. [+] Link : <https://fortressoffaith.com/wp-json/>; rel="https://api.w.org/", <https://fortressoffaith.com/>; rel=shortlink
  109. [+] Etag : "7781-1571145912;gz"
  110. [+] X-LiteSpeed-Cache : hit
  111. [+] Transfer-Encoding : chunked
  112. [+] Content-Encoding : gzip
  113. [+] Vary : Accept-Encoding
  114. [+] Date : Tue, 22 Oct 2019 11:09:22 GMT
  115. [+] Server : LiteSpeed
  116. [+] Alt-Svc : quic=":443"; ma=2592000; v="39,43,46", h3-22=":443"; ma=2592000
  117.  
  118. [+] SSL Certificate Information :
  119.  
  120. [+] commonName : fortressoffaith.com
  121. [+] countryName : US
  122. [+] organizationName : Let's Encrypt
  123. [+] commonName : Let's Encrypt Authority X3
  124. [+] Version : 3
  125. [+] Serial Number : 0314BCBEF273AA2570B41FF74FF4483AB90A
  126. [+] Not Before : Sep 16 02:16:18 2019 GMT
  127. [+] Not After : Dec 15 02:16:18 2019 GMT
  128. [+] OCSP : ('http://ocsp.int-x3.letsencrypt.org',)
  129. [+] subject Alt Name : (('DNS', 'cpanel.fortressoffaith.com'), ('DNS', 'fortressoffaith.com'), ('DNS', 'mail.fortressoffaith.com'), ('DNS', 'webdisk.fortressoffaith.com'), ('DNS', 'webmail.fortressoffaith.com'), ('DNS', 'www.fortressoffaith.com'))
  130. [+] CA Issuers : ('http://cert.int-x3.letsencrypt.org/',)
  131.  
  132. [+] Whois Lookup :
  133.  
  134. [+] NIR : None
  135. [+] ASN Registry : arin
  136. [+] ASN : 32244
  137. [+] ASN CIDR : 72.52.128.0/17
  138. [+] ASN Country Code : US
  139. [+] ASN Date : 2006-08-03
  140. [+] ASN Description : LIQUIDWEB - Liquid Web, L.L.C, US
  141. [+] cidr : 72.52.128.0/17
  142. [+] name : LIQUIDWEB
  143. [+] handle : NET-72-52-128-0-1
  144. [+] range : 72.52.128.0 - 72.52.255.255
  145. [+] description : Liquid Web, L.L.C
  146. [+] country : US
  147. [+] state : MI
  148. [+] city : Lansing
  149. [+] address : 4210 Creyts Rd.
  150. [+] postal_code : 48917
  151. [+] created : 2006-08-03
  152. [+] updated : 2016-12-19
  153.  
  154. [+] Crawling Target...
  155.  
  156. [+] Looking for robots.txt........[ Found ]
  157. [+] Extracting robots Links.......[ 2 ]
  158. [+] Looking for sitemap.xml.......[ Not Found ]
  159. [+] Extracting CSS Links..........[ 18 ]
  160. [+] Extracting Javascript Links...[ 17 ]
  161. [+] Extracting Internal Links.....[ 20 ]
  162. [+] Extracting External Links.....[ 6 ]
  163. [+] Extracting Images.............[ 11 ]
  164.  
  165. [+] Total Links Extracted : 74
  166.  
  167. [+] Dumping Links in /opt/FinalRecon/dumps/fortressoffaith.com.dump
  168. [+] Completed!
  169. #######################################################################################################################################
  170. [+] Starting At 2019-10-22 07:11:48.884536
  171. [+] Collecting Information On: https://fortressoffaith.com/
  172. [#] Status: 200
  173. --------------------------------------------------
  174. [#] Web Server Detected: LiteSpeed
  175. [#] X-Powered-By: PHP/7.0.33
  176. [!] X-Frame-Options Headers not detect! target might be vulnerable Click Jacking
  177. [+] CORS Wildcard Detected !
  178. - Connection: Keep-Alive
  179. - X-Powered-By: PHP/7.0.33
  180. - Access-Control-Allow-Origin: *
  181. - Expires: Thu, 19 Nov 1981 08:52:00 GMT
  182. - Cache-Control: no-store, no-cache, must-revalidate
  183. - Pragma: no-cache
  184. - Content-Type: text/html; charset=UTF-8
  185. - X-UA-Compatible: IE=edge
  186. - Link: <https://fortressoffaith.com/wp-json/>; rel="https://api.w.org/", <https://fortressoffaith.com/>; rel=shortlink
  187. - Etag: "7781-1571145912;gz"
  188. - X-LiteSpeed-Cache: hit
  189. - Transfer-Encoding: chunked
  190. - Content-Encoding: gzip
  191. - Vary: Accept-Encoding
  192. - Date: Tue, 22 Oct 2019 11:11:49 GMT
  193. - Server: LiteSpeed
  194. - Alt-Svc: quic=":443"; ma=2592000; v="39,43,46", h3-22=":443"; ma=2592000
  195. --------------------------------------------------
  196. [#] Finding Location..!
  197. [#] status: success
  198. [#] country: United States
  199. [#] countryCode: US
  200. [#] region: MI
  201. [#] regionName: Michigan
  202. [#] city: Lansing
  203. [#] zip: 48917
  204. [#] lat: 42.6898
  205. [#] lon: -84.6427
  206. [#] timezone: America/Detroit
  207. [#] isp: Liquid Web, L.L.C
  208. [#] org: SourceDNS
  209. [#] as: AS32244 Liquid Web, L.L.C
  210. [#] query: 72.52.244.17
  211. --------------------------------------------------
  212. [x] Didn't Detect WAF Presence on: https://fortressoffaith.com/
  213. --------------------------------------------------
  214. [#] Starting Reverse DNS
  215. [-] Failed ! Fail
  216. --------------------------------------------------
  217. [!] Scanning Open Port
  218. [#] 21/tcp open ftp
  219. [#] 53/tcp open domain
  220. [#] 80/tcp open http
  221. [#] 110/tcp open pop3
  222. [#] 143/tcp open imap
  223. [#] 443/tcp open https
  224. [#] 465/tcp open smtps
  225. [#] 587/tcp open submission
  226. [#] 993/tcp open imaps
  227. [#] 995/tcp open pop3s
  228. [#] 2200/tcp open ici
  229. [#] 3306/tcp open mysql
  230. --------------------------------------------------
  231. [+] Collecting Information Disclosure!
  232. [#] Detecting sitemap.xml file
  233. [-] sitemap.xml file not Found!?
  234. [#] Detecting robots.txt file
  235. [!] robots.txt File Found: https://fortressoffaith.com//robots.txt
  236. [#] Detecting GNU Mailman
  237. [!] GNU Mailman App Detected: https://fortressoffaith.com//mailman/admin
  238. [!] version: 2.1.27
  239. --------------------------------------------------
  240. [+] Crawling Url Parameter On: https://fortressoffaith.com/
  241. --------------------------------------------------
  242. [#] Searching Html Form !
  243. [-] No Html Form Found!?
  244. --------------------------------------------------
  245. [!] Found 3 dom parameter
  246. [#] https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Ffortressoffaith.com%2F&#038;format=xml
  247. [#] https://fortressoffaith.com//#content
  248. [#] https://crm.fundly.com/6609/Pages/fundraising/#/5
  249. --------------------------------------------------
  250. [!] 3 Internal Dynamic Parameter Discovered
  251. [+] https://fortressoffaith.com/xmlrpc.php?rsd
  252. [+] https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Ffortressoffaith.com%2F
  253. [+] https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Ffortressoffaith.com%2F&#038;format=xml
  254. --------------------------------------------------
  255. [!] 1 External Dynamic Parameter Discovered
  256. [#] https://play.google.com/store/apps/details?id=com.mobincube.fortress_of_faith.sc_DWXU1A
  257. --------------------------------------------------
  258. [!] 32 Internal links Discovered
  259. [+] https://fortressoffaith.com/feed/
  260. [+] https://fortressoffaith.com/wp-includes/wlwmanifest.xml
  261. [+] https://fortressoffaith.com/
  262. [+] https://fortressoffaith.com/
  263. [+] https://fortressoffaith.com/
  264. [+] https://fortressoffaith.com/contact/
  265. [+] https://fortressoffaith.com/terms-conditions/
  266. [+] https://fortressoffaith.com/privacy-policy/
  267. [+] https://fortressoffaith.com/study/
  268. [+] https://fortressoffaith.com/daily-articles-2/
  269. [+] https://fortressoffaith.com/articles-by-category/
  270. [+] https://fortressoffaith.com/radio-2/
  271. [+] https://fortressoffaith.com/radio-2/
  272. [+] https://fortressoffaith.com/islam-the-religion/
  273. [+] https://fortressoffaith.com/islam-terrorism/
  274. [+] https://fortressoffaith.com/islam-in-proficy/
  275. [+] https://fortressoffaith.com/in-the-news/
  276. [+] https://fortressoffaith.com/muslims-the-people/
  277. [+] https://fortressoffaith.com/evangelizing-muslims/
  278. [+] https://fortressoffaith.com/apologetic-responses/
  279. [+] https://fortressoffaith.com/other-issues/
  280. [+] https://fortressoffaith.com/when-muslims-play-the-race-card/
  281. [+] https://fortressoffaith.com/when-muslims-play-the-race-card/
  282. [+] https://fortressoffaith.com/elementor-11586/
  283. [+] https://fortressoffaith.com/elementor-11586/
  284. [+] https://fortressoffaith.com/islam-and-pedophilia/
  285. [+] https://fortressoffaith.com/islam-and-pedophilia/
  286. [+] https://fortressoffaith.com/newsletter-subscribe/
  287. [+] https://fortressoffaith.com//" class=
  288. [+] https://fortressoffaith.com//" class=
  289. [+] https://fortressoffaith.com//" class=
  290. [+] https://fortressoffaith.com//" class=
  291. --------------------------------------------------
  292. [!] 4 External links Discovered
  293. [#] https://gmpg.org/xfn/11
  294. [#] https://crm.fundly.com/6609/Pages/fundraising/#/5
  295. [#] http://fortressoffaith.sermon.net/rss/main/audio
  296. [#] http://www.fortressoffaith.org/
  297. --------------------------------------------------
  298. [#] Mapping Subdomain..
  299. [!] Found 3 Subdomain
  300. - webdisk.fortressoffaith.com
  301. - cpanel.fortressoffaith.com
  302. - webmail.fortressoffaith.com
  303. --------------------------------------------------
  304. [!] Done At 2019-10-22 07:12:21.575711
  305. #######################################################################################################################################
  306. [i] Scanning Site: https://fortressoffaith.com
  307.  
  308.  
  309.  
  310. B A S I C I N F O
  311. ====================
  312.  
  313.  
  314. [+] Site Title: Fortress of Faith &#8211; Refuting Islam
  315. [+] IP address: 72.52.244.17
  316. [+] Web Server: LiteSpeed
  317. [+] CMS: WordPress
  318. [+] Cloudflare: Not Detected
  319. [+] Robots File: Found
  320.  
  321. -------------[ contents ]----------------
  322. User-agent: *
  323. Disallow: /wp-admin/
  324. Allow: /wp-admin/admin-ajax.php
  325.  
  326. -----------[end of contents]-------------
  327.  
  328.  
  329.  
  330. W H O I S L O O K U P
  331. ========================
  332.  
  333. Domain Name: FORTRESSOFFAITH.COM
  334. Registry Domain ID: 1555724340_DOMAIN_COM-VRSN
  335. Registrar WHOIS Server: whois.domaindiscover.com
  336. Registrar URL: http://www.domaindiscover.com
  337. Updated Date: 2017-09-10T17:28:57Z
  338. Creation Date: 2009-05-14T22:06:41Z
  339. Registry Expiry Date: 2024-05-14T22:06:41Z
  340. Registrar: TierraNet Inc. d/b/a DomainDiscover
  341. Registrar IANA ID: 86
  342. Registrar Abuse Contact Email: [email protected]
  343. Registrar Abuse Contact Phone: 858-560-9416
  344. Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
  345. Name Server: NS1.BIGHORNHOSTING.COM
  346. Name Server: NS2.BIGHORNHOSTING.COM
  347. DNSSEC: unsigned
  348. URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
  349. >>> Last update of whois database: 2019-10-22T11:12:52Z <<<
  350.  
  351. For more information on Whois status codes, please visit https://icann.org/epp
  352.  
  353.  
  354.  
  355. The Registry database contains ONLY .COM, .NET, .EDU domains and
  356. Registrars.
  357.  
  358.  
  359.  
  360.  
  361. G E O I P L O O K U P
  362. =========================
  363.  
  364. [i] IP Address: 72.52.244.17
  365. [i] Country: United States
  366. [i] State: Michigan
  367. [i] City: Lansing
  368. [i] Latitude: 42.7348
  369. [i] Longitude: -84.6245
  370.  
  371.  
  372.  
  373.  
  374. H T T P H E A D E R S
  375. =======================
  376.  
  377.  
  378. [i] HTTP/1.0 200 OK
  379. [i] Connection: close
  380. [i] X-Powered-By: PHP/7.0.33
  381. [i] Access-Control-Allow-Origin: *
  382. [i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
  383. [i] Cache-Control: no-store, no-cache, must-revalidate
  384. [i] Pragma: no-cache
  385. [i] Content-Type: text/html; charset=UTF-8
  386. [i] X-UA-Compatible: IE=edge
  387. [i] Link: <https://fortressoffaith.com/wp-json/>; rel="https://api.w.org/"
  388. [i] Link: <https://fortressoffaith.com/>; rel=shortlink
  389. [i] Etag: "7781-1571145912;;;"
  390. [i] X-LiteSpeed-Cache: hit
  391. [i] Date: Tue, 22 Oct 2019 11:13:07 GMT
  392. [i] Server: LiteSpeed
  393.  
  394.  
  395.  
  396.  
  397. D N S L O O K U P
  398. ===================
  399.  
  400. fortressoffaith.com. 14399 IN TXT "v=spf1 +a +mx +ip4:72.52.144.226 ~all"
  401. fortressoffaith.com. 21599 IN SOA ns1.bighornhosting.com. pierre.bighornhost.net. 2017071303 3600 7200 1209600 86400
  402. fortressoffaith.com. 21599 IN NS ns2.bighornhosting.com.
  403. fortressoffaith.com. 21599 IN NS ns1.bighornhosting.com.
  404. fortressoffaith.com. 14399 IN A 72.52.244.17
  405. fortressoffaith.com. 14399 IN MX 0 fortressoffaith.com.
  406.  
  407.  
  408.  
  409.  
  410. S U B N E T C A L C U L A T I O N
  411. ====================================
  412.  
  413. Address = 72.52.244.17
  414. Network = 72.52.244.17 / 32
  415. Netmask = 255.255.255.255
  416. Broadcast = not needed on Point-to-Point links
  417. Wildcard Mask = 0.0.0.0
  418. Hosts Bits = 0
  419. Max. Hosts = 1 (2^0 - 0)
  420. Host Range = { 72.52.244.17 - 72.52.244.17 }
  421.  
  422.  
  423.  
  424. N M A P P O R T S C A N
  425. ============================
  426.  
  427. Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-22 11:13 UTC
  428. Nmap scan report for fortressoffaith.com (72.52.244.17)
  429. Host is up (0.028s latency).
  430. rDNS record for 72.52.244.17: andrew.uswebhost.com
  431.  
  432. PORT STATE SERVICE
  433. 21/tcp open ftp
  434. 22/tcp closed ssh
  435. 23/tcp filtered telnet
  436. 80/tcp open http
  437. 110/tcp open pop3
  438. 143/tcp open imap
  439. 443/tcp open https
  440. 3389/tcp filtered ms-wbt-server
  441.  
  442. Nmap done: 1 IP address (1 host up) scanned in 1.28 seconds
  443.  
  444.  
  445.  
  446. S U B - D O M A I N F I N D E R
  447. ==================================
  448.  
  449.  
  450. [i] Total Subdomains Found : 2
  451.  
  452. [+] Subdomain: cpanel.fortressoffaith.com
  453. [-] IP: 72.52.244.17
  454.  
  455. [+] Subdomain: webmail.fortressoffaith.com
  456. [-] IP: 72.52.244.17
  457. #######################################################################################################################################
  458. Trying "fortressoffaith.com"
  459. ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18658
  460. ;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 2, ADDITIONAL: 3
  461.  
  462. ;; QUESTION SECTION:
  463. ;fortressoffaith.com. IN ANY
  464.  
  465. ;; ANSWER SECTION:
  466. fortressoffaith.com. 14400 IN MX 0 fortressoffaith.com.
  467. fortressoffaith.com. 14400 IN A 72.52.244.17
  468. fortressoffaith.com. 43200 IN SOA ns1.bighornhosting.com. pierre.bighornhost.net. 2017071303 3600 7200 1209600 86400
  469. fortressoffaith.com. 14400 IN TXT "v=spf1 +a +mx +ip4:72.52.144.226 ~all"
  470. fortressoffaith.com. 43200 IN NS ns2.bighornhosting.com.
  471. fortressoffaith.com. 43200 IN NS ns1.bighornhosting.com.
  472.  
  473. ;; AUTHORITY SECTION:
  474. fortressoffaith.com. 43200 IN NS ns2.bighornhosting.com.
  475. fortressoffaith.com. 43200 IN NS ns1.bighornhosting.com.
  476.  
  477. ;; ADDITIONAL SECTION:
  478. fortressoffaith.com. 14400 IN A 72.52.244.17
  479. ns2.bighornhosting.com. 43200 IN A 72.52.244.68
  480. ns1.bighornhosting.com. 43200 IN A 72.52.144.226
  481.  
  482. Received 304 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 88 ms
  483. ######################################################################################################################################
  484. ; <<>> DiG 9.11.5-P4-5.1+b1-Debian <<>> +trace fortressoffaith.com
  485. ;; global options: +cmd
  486. . 82914 IN NS j.root-servers.net.
  487. . 82914 IN NS f.root-servers.net.
  488. . 82914 IN NS k.root-servers.net.
  489. . 82914 IN NS h.root-servers.net.
  490. . 82914 IN NS d.root-servers.net.
  491. . 82914 IN NS c.root-servers.net.
  492. . 82914 IN NS e.root-servers.net.
  493. . 82914 IN NS m.root-servers.net.
  494. . 82914 IN NS g.root-servers.net.
  495. . 82914 IN NS l.root-servers.net.
  496. . 82914 IN NS i.root-servers.net.
  497. . 82914 IN NS b.root-servers.net.
  498. . 82914 IN NS a.root-servers.net.
  499. . 82914 IN RRSIG NS 8 0 518400 20191104050000 20191022040000 22545 . V7L2dB4F79xO9lx8hztPB86SYLY35tcInKqSk8aLbD8fvpqah4DWHoDe 2xbqt74EJPvBDnnxjmyB4tREMvAE2pcJYRcXgEXojn3yhrQSsQ3jFs5F PjYgRw0D2xB2yHw8rQ4l16CD7aEVgG+FefFGqt3W+daAM1PO+IYKW0wG ZlUdJNJSe51nOWemZldGoqlKha/wznCidzCCANqSG6ZPNuvTOgIFhRZB drsNOA4MFLWYNYyQpPWFiqtgkB5nZx3ACgXg/VY6Jy/blXbeM75bse+V 1878EtXXH4TdBRmzNhEyyy6uJa9iO9OjpIn2SDrdVRzSlWOKvOH+Pw8i KLe1JA==
  500. ;; Received 525 bytes from 185.93.180.131#53(185.93.180.131) in 107 ms
  501.  
  502. com. 172800 IN NS a.gtld-servers.net.
  503. com. 172800 IN NS b.gtld-servers.net.
  504. com. 172800 IN NS c.gtld-servers.net.
  505. com. 172800 IN NS d.gtld-servers.net.
  506. com. 172800 IN NS e.gtld-servers.net.
  507. com. 172800 IN NS f.gtld-servers.net.
  508. com. 172800 IN NS g.gtld-servers.net.
  509. com. 172800 IN NS h.gtld-servers.net.
  510. com. 172800 IN NS i.gtld-servers.net.
  511. com. 172800 IN NS j.gtld-servers.net.
  512. com. 172800 IN NS k.gtld-servers.net.
  513. com. 172800 IN NS l.gtld-servers.net.
  514. com. 172800 IN NS m.gtld-servers.net.
  515. com. 86400 IN DS 30909 8 2 E2D3C916F6DEEAC73294E8268FB5885044A833FC5459588F4A9184CF C41A5766
  516. com. 86400 IN RRSIG DS 8 1 86400 20191104050000 20191022040000 22545 . CPiZLu+5g2FPKEBREYZ3/y+dZsCiKF/jITgwc8/o4Qfj86LICQpXSO+D q9ePdIb+eIyR4VP0b5P58/c3QfEd+AkHbzRc59yPvptWoz8kTrffpWQU yY2Nz1WNkg6A1g1YhFFRkgr4gaUvWeMIWD10wB2gEqbxk/ZfVW3BNw3J BzQ6fu9EPG1sd2FopWsqCM285+ASZEUsCuJmGu+Q+yq6CaD/03g/suQE +gWd3debwSwxxOGYd0t2bFWGPZZYzhrfoXsbULy2iYlkrdlJJM0akfzU z8+XGGVA6LvANBExB6lFXR7zBE3gQukDGO6KNfSWwx3LoQH0W6EQLURq z3TVNg==
  517. ;; Received 1179 bytes from 2001:500:2d::d#53(d.root-servers.net) in 24 ms
  518.  
  519. fortressoffaith.com. 172800 IN NS ns1.bighornhosting.com.
  520. fortressoffaith.com. 172800 IN NS ns2.bighornhosting.com.
  521. CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN NSEC3 1 1 0 - CK0Q1GIN43N1ARRC9OSM6QPQR81H5M9A NS SOA RRSIG DNSKEY NSEC3PARAM
  522. CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN RRSIG NSEC3 8 2 86400 20191026044727 20191019033727 12163 com. L8X10nb9SRkzwcSf3SNTRa/24YQW0ay6SOzHltG4lknjnQgtMbu0/N3s LQH9wqc0SLy+qN+AYBKC8MtLicMWvYcx/SGRVlvfdgwcAR7wU7qxtJ8T vlfETNOWMGMwkPu//+yaJfWziWFnoLqnNeDcvlqnF0J3z0Ur89Bpb/NT Wng/L/BRj46mgZmQjllYzPHkR0cPAxYoFrLSCpal170H+g==
  523. FOGN3I94H2A9UGV5GFGT14N1QSTKOIUM.com. 86400 IN NSEC3 1 1 0 - FOGOAI8781JFAU7MD4IU4EB1VVESAI23 NS DS RRSIG
  524. FOGN3I94H2A9UGV5GFGT14N1QSTKOIUM.com. 86400 IN RRSIG NSEC3 8 2 86400 20191026052133 20191019041133 12163 com. lUrL25dru63cxGOk+vq82XgBUfPzLKjG4TgbL8GBYzu9azyvKT+gNLcm PUhd2X0c+TEtsMYV06L2EWIhAuj33N6rCHMGMNdn30oDk3Ds6WUSHZBw Pj+6ufMybBfqP8p/8UF/WrbcZjQsU/ix/F6vTY8H3HOtjqURILZifx6n dicy432cu5H4zeGX8eW5LXbUr5ToCOH5tMg5Mvo+/g1vgg==
  525. ;; Received 680 bytes from 2001:500:856e::30#53(d.gtld-servers.net) in 54 ms
  526.  
  527. fortressoffaith.com. 14400 IN A 72.52.244.17
  528. fortressoffaith.com. 86400 IN NS ns2.bighornhosting.com.
  529. fortressoffaith.com. 86400 IN NS ns1.bighornhosting.com.
  530. ;; Received 175 bytes from 72.52.144.226#53(ns1.bighornhosting.com) in 325 ms
  531. ######################################################################################################################################
  532. [*] Performing General Enumeration of Domain: fortressoffaith.com
  533. [-] DNSSEC is not configured for fortressoffaith.com
  534. [*] SOA ns1.bighornhosting.com 72.52.144.226
  535. [*] NS ns2.bighornhosting.com 72.52.244.68
  536. [*] Bind Version for 72.52.244.68 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  537. [*] NS ns1.bighornhosting.com 72.52.144.226
  538. [*] Bind Version for 72.52.144.226 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  539. [*] MX fortressoffaith.com 72.52.244.17
  540. [*] A fortressoffaith.com 72.52.244.17
  541. [*] TXT fortressoffaith.com v=spf1 +a +mx +ip4:72.52.144.226 ~all
  542. [*] Enumerating SRV Records
  543. [-] No SRV Records Found for fortressoffaith.com
  544. [+] 0 Records Found
  545. ######################################################################################################################################
  546. [*] Processing domain fortressoffaith.com
  547. [*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
  548. [+] Getting nameservers
  549. 72.52.244.68 - ns2.bighornhosting.com
  550. 72.52.144.226 - ns1.bighornhosting.com
  551. [-] Zone transfer failed
  552.  
  553. [+] TXT records found
  554. "v=spf1 +a +mx +ip4:72.52.144.226 ~all"
  555.  
  556. [+] MX records found, added to target list
  557. 0 fortressoffaith.com.
  558.  
  559. [*] Scanning fortressoffaith.com for A records
  560. 72.52.244.17 - fortressoffaith.com
  561. 72.52.244.17 - cpanel.fortressoffaith.com
  562. 72.52.144.226 - ftp.fortressoffaith.com
  563. 72.52.244.17 - mail.fortressoffaith.com
  564. 72.52.244.17 - webdisk.fortressoffaith.com
  565. 72.52.244.17 - webmail.fortressoffaith.com
  566. 72.52.244.17 - whm.fortressoffaith.com
  567. 72.52.244.17 - www.fortressoffaith.com
  568. #######################################################################################################################################
  569.  
  570. Domains still to check: 1
  571. Checking if the hostname fortressoffaith.com. given is in fact a domain...
  572.  
  573. Analyzing domain: fortressoffaith.com.
  574. Checking NameServers using system default resolver...
  575. IP: 72.52.244.68 (United States)
  576. HostName: ns2.bighornhosting.com Type: NS
  577. HostName: andrew.uswebhost.com Type: PTR
  578. IP: 72.52.144.226 (United States)
  579. HostName: ns1.bighornhosting.com Type: NS
  580. HostName: andrew.uswebhost.com Type: PTR
  581.  
  582. Checking MailServers using system default resolver...
  583. IP: 72.52.244.17 (United States)
  584. HostName: fortressoffaith.com Type: MX
  585. HostName: andrew.uswebhost.com Type: PTR
  586.  
  587. Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
  588. No zone transfer found on nameserver 72.52.144.226
  589. No zone transfer found on nameserver 72.52.244.68
  590.  
  591. Checking SPF record...
  592.  
  593. Checking 192 most common hostnames using system default resolver...
  594. IP: 72.52.244.17 (United States)
  595. HostName: fortressoffaith.com Type: MX
  596. HostName: andrew.uswebhost.com Type: PTR
  597. HostName: www.fortressoffaith.com. Type: A
  598. IP: 72.52.144.226 (United States)
  599. HostName: ns1.bighornhosting.com Type: NS
  600. HostName: andrew.uswebhost.com Type: PTR
  601. Type: SPF
  602. HostName: ftp.fortressoffaith.com. Type: A
  603. IP: 72.52.244.17 (United States)
  604. HostName: fortressoffaith.com Type: MX
  605. HostName: andrew.uswebhost.com Type: PTR
  606. HostName: www.fortressoffaith.com. Type: A
  607. HostName: mail.fortressoffaith.com. Type: A
  608. IP: 72.52.244.17 (United States)
  609. HostName: fortressoffaith.com Type: MX
  610. HostName: andrew.uswebhost.com Type: PTR
  611. HostName: www.fortressoffaith.com. Type: A
  612. HostName: mail.fortressoffaith.com. Type: A
  613. HostName: webmail.fortressoffaith.com. Type: A
  614.  
  615. Checking with nmap the reverse DNS hostnames of every <ip>/24 netblock using system default resolver...
  616. Checking netblock 72.52.144.0
  617. Checking netblock 72.52.244.0
  618.  
  619. Searching for fortressoffaith.com. emails in Google
  620.  
  621. Checking 3 active hosts using nmap... (nmap -sn -n -v -PP -PM -PS80,25 -PA -PY -PU53,40125 -PE --reason <ip> -oA <output_directory>/nmap/<ip>.sn)
  622. Host 72.52.144.226 is up (echo-reply ttl 56)
  623. Host 72.52.244.68 is up (reset ttl 64)
  624. Host 72.52.244.17 is up (reset ttl 64)
  625.  
  626. Checking ports on every active host using nmap... (nmap -O --reason --webxml --traceroute -sS -sV -sC -Pn -n -v -F <ip> -oA <output_directory>/nmap/<ip>)
  627. Scanning ip 72.52.144.226 (ftp.fortressoffaith.com.):
  628. NSOCK ERROR [56.2870s] mksock_bind_addr(): Bind to 0.0.0.0:22 failed (IOD #121): Address already in use (98)
  629. 21/tcp open ftp syn-ack ttl 56 Pure-FTPd
  630. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  631. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  632. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  633. | Public Key type: rsa
  634. | Public Key bits: 2048
  635. | Signature Algorithm: sha256WithRSAEncryption
  636. | Not valid before: 2019-04-22T00:00:00
  637. | Not valid after: 2020-04-21T23:59:59
  638. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  639. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  640. |_ssl-date: TLS randomness does not represent time
  641. 53/tcp open domain syn-ack ttl 56 ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  642. | dns-nsid:
  643. |_ bind.version: 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  644. 80/tcp open http syn-ack ttl 56 LiteSpeed httpd
  645. | http-methods:
  646. |_ Supported Methods: OPTIONS HEAD GET POST
  647. |_http-server-header: LiteSpeed
  648. |_http-title: Site doesn't have a title (text/html).
  649. 110/tcp open pop3 syn-ack ttl 56 Dovecot pop3d
  650. |_pop3-capabilities: USER PIPELINING CAPA RESP-CODES TOP SASL(PLAIN LOGIN) STLS AUTH-RESP-CODE UIDL
  651. |_ssl-date: TLS randomness does not represent time
  652. 143/tcp open imap syn-ack ttl 56 Dovecot imapd
  653. |_imap-capabilities: STARTTLS AUTH=PLAIN SASL-IR NAMESPACE capabilities IMAP4rev1 post-login Pre-login more have ID AUTH=LOGINA0001 listed IDLE ENABLE LOGIN-REFERRALS LITERAL+ OK
  654. |_ssl-date: TLS randomness does not represent time
  655. 443/tcp open ssl/http syn-ack ttl 56 LiteSpeed httpd
  656. | http-methods:
  657. |_ Supported Methods: OPTIONS HEAD GET POST
  658. |_http-server-header: LiteSpeed
  659. |_http-title: Site doesn't have a title (text/html).
  660. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  661. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  662. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  663. | Public Key type: rsa
  664. | Public Key bits: 2048
  665. | Signature Algorithm: sha256WithRSAEncryption
  666. | Not valid before: 2017-06-09T00:00:00
  667. | Not valid after: 2018-06-09T23:59:59
  668. | MD5: 8e4f acd9 49e8 1ce2 6852 8d9d e6af a499
  669. |_SHA-1: 25ae d633 8140 a626 8fa9 c672 a9aa 164a 3cd3 1156
  670. |_ssl-date: 2019-10-22T11:31:31+00:00; -1s from scanner time.
  671. | tls-alpn:
  672. | h2
  673. | spdy/3
  674. | spdy/2
  675. |_ http/1.1
  676. 465/tcp open ssl/smtp syn-ack ttl 56 Exim smtpd 4.92
  677. |_smtp-commands: Couldn't establish connection on port 465
  678. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  679. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  680. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  681. | Public Key type: rsa
  682. | Public Key bits: 2048
  683. | Signature Algorithm: sha256WithRSAEncryption
  684. | Not valid before: 2019-04-22T00:00:00
  685. | Not valid after: 2020-04-21T23:59:59
  686. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  687. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  688. |_ssl-date: TLS randomness does not represent time
  689. 587/tcp open smtp syn-ack ttl 56 Exim smtpd 4.92
  690. | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
  691. |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  692. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  693. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  694. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  695. | Public Key type: rsa
  696. | Public Key bits: 2048
  697. | Signature Algorithm: sha256WithRSAEncryption
  698. | Not valid before: 2019-04-22T00:00:00
  699. | Not valid after: 2020-04-21T23:59:59
  700. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  701. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  702. |_ssl-date: TLS randomness does not represent time
  703. 993/tcp open ssl/imaps? syn-ack ttl 56
  704. |_ssl-date: TLS randomness does not represent time
  705. 995/tcp open ssl/pop3s? syn-ack ttl 56
  706. |_ssl-date: TLS randomness does not represent time
  707. 3306/tcp open mysql syn-ack ttl 56 MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  708. | mysql-info:
  709. | Protocol: 10
  710. | Version: 5.5.5-10.2.27-MariaDB-cll-lve
  711. | Thread ID: 57087
  712. | Capabilities flags: 63486
  713. | Some Capabilities: LongColumnFlag, ODBCClient, ConnectWithDatabase, FoundRows, Speaks41ProtocolOld, SupportsTransactions, IgnoreSigpipes, InteractiveClient, Speaks41ProtocolNew, IgnoreSpaceBeforeParenthesis, DontAllowDatabaseTableColumn, SupportsCompression, SupportsLoadDataLocal, Support41Auth, SupportsMultipleStatments, SupportsMultipleResults, SupportsAuthPlugins
  714. | Status: Autocommit
  715. | Salt: fUY?k#ga/e1b{fkgBT`f
  716. |_ Auth Plugin Name: mysql_native_password
  717. Device type: general purpose|WAP|storage-misc|firewall|proxy server|broadband router
  718. Running (JUST GUESSING): FreeBSD 6.X (92%), Linux 3.X|4.X|2.6.X (88%), Dell embedded (85%), Cisco embedded (85%), Riverbed embedded (85%), Zhone embedded (85%)
  719. OS Info: Service Info: Host: andrew.uswebhost.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  720. |_clock-skew: -1s
  721. Scanning ip 72.52.244.68 (andrew.uswebhost.com (PTR)):
  722. 21/tcp open ftp syn-ack ttl 56 Pure-FTPd
  723. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  724. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  725. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  726. | Public Key type: rsa
  727. | Public Key bits: 2048
  728. | Signature Algorithm: sha256WithRSAEncryption
  729. | Not valid before: 2019-04-22T00:00:00
  730. | Not valid after: 2020-04-21T23:59:59
  731. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  732. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  733. |_ssl-date: TLS randomness does not represent time
  734. 53/tcp open domain syn-ack ttl 56 ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  735. | dns-nsid:
  736. |_ bind.version: 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  737. 80/tcp open http syn-ack ttl 56 LiteSpeed httpd
  738. | http-methods:
  739. |_ Supported Methods: OPTIONS HEAD GET POST
  740. |_http-server-header: LiteSpeed
  741. |_http-title: Site doesn't have a title (text/html).
  742. 110/tcp open pop3 syn-ack ttl 56 Dovecot pop3d
  743. |_pop3-capabilities: STLS AUTH-RESP-CODE TOP PIPELINING UIDL USER RESP-CODES CAPA SASL(PLAIN LOGIN)
  744. |_ssl-date: TLS randomness does not represent time
  745. 143/tcp open imap syn-ack ttl 56 Dovecot imapd
  746. |_imap-capabilities: ID LITERAL+ listed IMAP4rev1 IDLE NAMESPACE LOGIN-REFERRALS post-login Pre-login OK ENABLE have more capabilities STARTTLS SASL-IR AUTH=LOGINA0001 AUTH=PLAIN
  747. |_ssl-date: TLS randomness does not represent time
  748. 443/tcp open ssl/http syn-ack ttl 56 LiteSpeed httpd
  749. | http-methods:
  750. |_ Supported Methods: OPTIONS HEAD GET POST
  751. |_http-server-header: LiteSpeed
  752. |_http-title: Site doesn't have a title (text/html).
  753. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  754. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  755. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  756. | Public Key type: rsa
  757. | Public Key bits: 2048
  758. | Signature Algorithm: sha256WithRSAEncryption
  759. | Not valid before: 2019-04-22T00:00:00
  760. | Not valid after: 2020-04-21T23:59:59
  761. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  762. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  763. |_ssl-date: 2019-10-22T11:34:39+00:00; -1s from scanner time.
  764. | tls-alpn:
  765. | h2
  766. | spdy/3
  767. | spdy/2
  768. |_ http/1.1
  769. 465/tcp open ssl/smtp syn-ack ttl 56 Exim smtpd 4.92
  770. | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
  771. |_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  772. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  773. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  774. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  775. | Public Key type: rsa
  776. | Public Key bits: 2048
  777. | Signature Algorithm: sha256WithRSAEncryption
  778. | Not valid before: 2019-04-22T00:00:00
  779. | Not valid after: 2020-04-21T23:59:59
  780. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  781. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  782. |_ssl-date: TLS randomness does not represent time
  783. 587/tcp open smtp syn-ack ttl 56 Exim smtpd 4.92
  784. | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
  785. |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  786. | ssl-cert: Subject: commonName=andrew.uswebhost.com
  787. | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  788. | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  789. | Public Key type: rsa
  790. | Public Key bits: 2048
  791. | Signature Algorithm: sha256WithRSAEncryption
  792. | Not valid before: 2019-04-22T00:00:00
  793. | Not valid after: 2020-04-21T23:59:59
  794. | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  795. |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  796. |_ssl-date: TLS randomness does not represent time
  797. 993/tcp open ssl/imaps? syn-ack ttl 56
  798. |_ssl-date: TLS randomness does not represent time
  799. 995/tcp open ssl/pop3s? syn-ack ttl 56
  800. |_ssl-date: TLS randomness does not represent time
  801. 3306/tcp open mysql syn-ack ttl 56 MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  802. | mysql-info:
  803. | Protocol: 10
  804. | Version: 5.5.5-10.2.27-MariaDB-cll-lve
  805. | Thread ID: 58267
  806. | Capabilities flags: 63486
  807. | Some Capabilities: SupportsCompression, FoundRows, InteractiveClient, IgnoreSpaceBeforeParenthesis, IgnoreSigpipes, SupportsLoadDataLocal, Support41Auth, LongColumnFlag, DontAllowDatabaseTableColumn, ConnectWithDatabase, Speaks41ProtocolOld, SupportsTransactions, ODBCClient, Speaks41ProtocolNew, SupportsMultipleStatments, SupportsAuthPlugins, SupportsMultipleResults
  808. | Status: Autocommit
  809. | Salt: v5@!$2nT:dkjUHK}VvoL
  810. |_ Auth Plugin Name: mysql_native_password
  811. OS Info: Service Info: Host: andrew.uswebhost.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  812. |_clock-skew: -1s
  813. Scanning ip 72.52.244.17 (webmail.fortressoffaith.com.):
  814. 21/tcp open ftp syn-ack ttl 56 Pure-FTPd
  815. 53/tcp open domain syn-ack ttl 56 ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  816. | dns-nsid:
  817. |_ bind.version: 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  818. 80/tcp open http syn-ack ttl 56 LiteSpeed httpd
  819. | http-methods:
  820. |_ Supported Methods: OPTIONS HEAD GET POST
  821. |_http-title: Site doesn't have a title (text/html).
  822. 110/tcp open pop3 syn-ack ttl 56 Dovecot pop3d
  823. 143/tcp open imap syn-ack ttl 56 Dovecot imapd
  824. |_imap-capabilities: LOGIN-REFERRALS STARTTLS SASL-IR AUTH=LOGINA0001 post-login NAMESPACE have AUTH=PLAIN ID ENABLE OK IMAP4rev1 more IDLE listed capabilities Pre-login LITERAL+
  825. 443/tcp open ssl/http syn-ack ttl 56 LiteSpeed httpd
  826. | http-cookie-flags:
  827. | /:
  828. | PHPSESSID:
  829. |_ httponly flag not set
  830. |_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E
  831. | http-robots.txt: 1 disallowed entry
  832. |_/wp-admin/
  833. |_http-title: Did not follow redirect to https://bighornhosting.com/
  834. | ssl-cert: Subject: commonName=bighornhosting.com
  835. | Subject Alternative Name: DNS:bighornhosting.com, DNS:cpanel.bighornhosting.com, DNS:mail.bighornhosting.com, DNS:webdisk.bighornhosting.com, DNS:webmail.bighornhosting.com, DNS:whm.bighornhosting.com, DNS:www.bighornhosting.com
  836. | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
  837. | Public Key type: rsa
  838. | Public Key bits: 2048
  839. | Signature Algorithm: sha256WithRSAEncryption
  840. | Not valid before: 2019-09-18T02:08:45
  841. | Not valid after: 2019-12-17T02:08:45
  842. | MD5: d01a 9027 47d9 e638 609d 2c22 c3c4 722c
  843. |_SHA-1: b6a1 69c7 f8fc 7d21 9237 3776 009f 080c 07f2 1ebf
  844. 465/tcp open ssl/smtp syn-ack ttl 56 Exim smtpd 4.92
  845. | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
  846. |_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  847. 587/tcp open smtp syn-ack ttl 56 Exim smtpd 4.92
  848. | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
  849. |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  850. 993/tcp open ssl/imaps? syn-ack ttl 56
  851. 995/tcp open ssl/pop3s? syn-ack ttl 56
  852. 3306/tcp open mysql syn-ack ttl 56 MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  853. | mysql-info:
  854. | Protocol: 10
  855. | Version: 5.5.5-10.2.27-MariaDB-cll-lve
  856. | Thread ID: 59305
  857. | Capabilities flags: 63486
  858. | Some Capabilities: Support41Auth, Speaks41ProtocolOld, SupportsTransactions, IgnoreSpaceBeforeParenthesis, DontAllowDatabaseTableColumn, IgnoreSigpipes, InteractiveClient, Speaks41ProtocolNew, SupportsCompression, ODBCClient, SupportsLoadDataLocal, ConnectWithDatabase, FoundRows, LongColumnFlag, SupportsAuthPlugins, SupportsMultipleResults, SupportsMultipleStatments
  859. | Status: Autocommit
  860. | Salt: By\Am&nz:SoVC*HmkT?~
  861. |_ Auth Plugin Name: mysql_native_password
  862. Device type: general purpose|storage-misc|firewall|webcam
  863. Running (JUST GUESSING): Linux 4.X|3.X|2.6.X (93%), Synology DiskStation Manager 5.X (87%), FreeBSD 6.X (86%), WatchGuard Fireware 11.X (86%), Tandberg embedded (86%)
  864. OS Info: Service Info: Host: andrew.uswebhost.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  865. WebCrawling domain's web servers... up to 50 max links.
  866.  
  867. + URL to crawl: http://ns1.bighornhosting.com
  868. + Date: 2019-10-22
  869.  
  870. + Crawling URL: http://ns1.bighornhosting.com:
  871. + Links:
  872. + Crawling http://ns1.bighornhosting.com (timed out)
  873. + Searching for directories...
  874. + Searching open folders...
  875.  
  876.  
  877. + URL to crawl: http://ftp.fortressoffaith.com.
  878. + Date: 2019-10-22
  879.  
  880. + Crawling URL: http://ftp.fortressoffaith.com.:
  881. + Links:
  882. + Crawling http://ftp.fortressoffaith.com. (timed out)
  883. + Searching for directories...
  884. + Searching open folders...
  885.  
  886.  
  887. + URL to crawl: https://ns1.bighornhosting.com
  888. + Date: 2019-10-22
  889.  
  890. + Crawling URL: https://ns1.bighornhosting.com:
  891. + Links:
  892. + Crawling https://ns1.bighornhosting.com (timed out)
  893. + Searching for directories...
  894. + Searching open folders...
  895.  
  896.  
  897. + URL to crawl: https://ftp.fortressoffaith.com.
  898. + Date: 2019-10-22
  899.  
  900. + Crawling URL: https://ftp.fortressoffaith.com.:
  901. + Links:
  902. + Crawling https://ftp.fortressoffaith.com. (timed out)
  903. + Searching for directories...
  904. + Searching open folders...
  905.  
  906.  
  907. + URL to crawl: http://ns2.bighornhosting.com
  908. + Date: 2019-10-22
  909.  
  910. + Crawling URL: http://ns2.bighornhosting.com:
  911. + Links:
  912. + Crawling http://ns2.bighornhosting.com (timed out)
  913. + Searching for directories...
  914. + Searching open folders...
  915.  
  916.  
  917. + URL to crawl: https://ns2.bighornhosting.com
  918. + Date: 2019-10-22
  919.  
  920. + Crawling URL: https://ns2.bighornhosting.com:
  921. + Links:
  922. + Crawling https://ns2.bighornhosting.com (timed out)
  923. + Searching for directories...
  924. + Searching open folders...
  925.  
  926.  
  927. + URL to crawl: http://www.fortressoffaith.com.
  928. + Date: 2019-10-22
  929.  
  930. + Crawling URL: http://www.fortressoffaith.com.:
  931. + Links:
  932. + Crawling http://www.fortressoffaith.com. (timed out)
  933. + Searching for directories...
  934. + Searching open folders...
  935.  
  936.  
  937. + URL to crawl: http://mail.fortressoffaith.com.
  938. + Date: 2019-10-22
  939.  
  940. + Crawling URL: http://mail.fortressoffaith.com.:
  941. + Links:
  942. + Crawling http://mail.fortressoffaith.com. (timed out)
  943. + Searching for directories...
  944. + Searching open folders...
  945.  
  946.  
  947. + URL to crawl: http://fortressoffaith.com
  948. + Date: 2019-10-22
  949.  
  950. + Crawling URL: http://fortressoffaith.com:
  951. + Links:
  952. + Crawling http://fortressoffaith.com (timed out)
  953. + Searching for directories...
  954. + Searching open folders...
  955.  
  956.  
  957. + URL to crawl: http://webmail.fortressoffaith.com.
  958. + Date: 2019-10-22
  959.  
  960. + Crawling URL: http://webmail.fortressoffaith.com.:
  961. + Links:
  962. + Crawling http://webmail.fortressoffaith.com. (timed out)
  963. + Searching for directories...
  964. + Searching open folders...
  965.  
  966.  
  967. + URL to crawl: https://www.fortressoffaith.com.
  968. + Date: 2019-10-22
  969.  
  970. + Crawling URL: https://www.fortressoffaith.com.:
  971. + Links:
  972. + Crawling https://www.fortressoffaith.com. (timed out)
  973. + Searching for directories...
  974. + Searching open folders...
  975.  
  976.  
  977. + URL to crawl: https://mail.fortressoffaith.com.
  978. + Date: 2019-10-22
  979.  
  980. + Crawling URL: https://mail.fortressoffaith.com.:
  981. + Links:
  982. + Crawling https://mail.fortressoffaith.com. (timed out)
  983. + Searching for directories...
  984. + Searching open folders...
  985.  
  986.  
  987. + URL to crawl: https://fortressoffaith.com
  988. + Date: 2019-10-22
  989.  
  990. + Crawling URL: https://fortressoffaith.com:
  991. + Links:
  992. + Crawling https://fortressoffaith.com (timed out)
  993. + Searching for directories...
  994. + Searching open folders...
  995.  
  996.  
  997. + URL to crawl: https://webmail.fortressoffaith.com.
  998. + Date: 2019-10-22
  999.  
  1000. + Crawling URL: https://webmail.fortressoffaith.com.:
  1001. + Links:
  1002. + Crawling https://webmail.fortressoffaith.com. (timed out)
  1003. + Searching for directories...
  1004. + Searching open folders...
  1005.  
  1006. --Finished--
  1007. Summary information for domain fortressoffaith.com.
  1008. -----------------------------------------
  1009.  
  1010. Domain Ips Information:
  1011. IP: 72.52.144.226
  1012. HostName: ns1.bighornhosting.com Type: NS
  1013. HostName: andrew.uswebhost.com Type: PTR
  1014. Type: SPF
  1015. HostName: ftp.fortressoffaith.com. Type: A
  1016. Country: United States
  1017. Is Active: True (echo-reply ttl 56)
  1018. Port: 21/tcp open ftp syn-ack ttl 56 Pure-FTPd
  1019. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1020. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1021. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1022. Script Info: | Public Key type: rsa
  1023. Script Info: | Public Key bits: 2048
  1024. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1025. Script Info: | Not valid before: 2019-04-22T00:00:00
  1026. Script Info: | Not valid after: 2020-04-21T23:59:59
  1027. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1028. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1029. Script Info: |_ssl-date: TLS randomness does not represent time
  1030. Port: 53/tcp open domain syn-ack ttl 56 ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  1031. Script Info: | dns-nsid:
  1032. Script Info: |_ bind.version: 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  1033. Port: 80/tcp open http syn-ack ttl 56 LiteSpeed httpd
  1034. Script Info: | http-methods:
  1035. Script Info: |_ Supported Methods: OPTIONS HEAD GET POST
  1036. Script Info: |_http-server-header: LiteSpeed
  1037. Script Info: |_http-title: Site doesn't have a title (text/html).
  1038. Port: 110/tcp open pop3 syn-ack ttl 56 Dovecot pop3d
  1039. Script Info: |_pop3-capabilities: USER PIPELINING CAPA RESP-CODES TOP SASL(PLAIN LOGIN) STLS AUTH-RESP-CODE UIDL
  1040. Script Info: |_ssl-date: TLS randomness does not represent time
  1041. Port: 143/tcp open imap syn-ack ttl 56 Dovecot imapd
  1042. Script Info: |_imap-capabilities: STARTTLS AUTH=PLAIN SASL-IR NAMESPACE capabilities IMAP4rev1 post-login Pre-login more have ID AUTH=LOGINA0001 listed IDLE ENABLE LOGIN-REFERRALS LITERAL+ OK
  1043. Script Info: |_ssl-date: TLS randomness does not represent time
  1044. Port: 443/tcp open ssl/http syn-ack ttl 56 LiteSpeed httpd
  1045. Script Info: | http-methods:
  1046. Script Info: |_ Supported Methods: OPTIONS HEAD GET POST
  1047. Script Info: |_http-server-header: LiteSpeed
  1048. Script Info: |_http-title: Site doesn't have a title (text/html).
  1049. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1050. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1051. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1052. Script Info: | Public Key type: rsa
  1053. Script Info: | Public Key bits: 2048
  1054. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1055. Script Info: | Not valid before: 2017-06-09T00:00:00
  1056. Script Info: | Not valid after: 2018-06-09T23:59:59
  1057. Script Info: | MD5: 8e4f acd9 49e8 1ce2 6852 8d9d e6af a499
  1058. Script Info: |_SHA-1: 25ae d633 8140 a626 8fa9 c672 a9aa 164a 3cd3 1156
  1059. Script Info: |_ssl-date: 2019-10-22T11:31:31+00:00; -1s from scanner time.
  1060. Script Info: | tls-alpn:
  1061. Script Info: | h2
  1062. Script Info: | spdy/3
  1063. Script Info: | spdy/2
  1064. Script Info: |_ http/1.1
  1065. Port: 465/tcp open ssl/smtp syn-ack ttl 56 Exim smtpd 4.92
  1066. Script Info: |_smtp-commands: Couldn't establish connection on port 465
  1067. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1068. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1069. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1070. Script Info: | Public Key type: rsa
  1071. Script Info: | Public Key bits: 2048
  1072. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1073. Script Info: | Not valid before: 2019-04-22T00:00:00
  1074. Script Info: | Not valid after: 2020-04-21T23:59:59
  1075. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1076. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1077. Script Info: |_ssl-date: TLS randomness does not represent time
  1078. Port: 587/tcp open smtp syn-ack ttl 56 Exim smtpd 4.92
  1079. Script Info: | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
  1080. Script Info: |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1081. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1082. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1083. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1084. Script Info: | Public Key type: rsa
  1085. Script Info: | Public Key bits: 2048
  1086. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1087. Script Info: | Not valid before: 2019-04-22T00:00:00
  1088. Script Info: | Not valid after: 2020-04-21T23:59:59
  1089. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1090. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1091. Script Info: |_ssl-date: TLS randomness does not represent time
  1092. Port: 993/tcp open ssl/imaps? syn-ack ttl 56
  1093. Script Info: |_ssl-date: TLS randomness does not represent time
  1094. Port: 995/tcp open ssl/pop3s? syn-ack ttl 56
  1095. Script Info: |_ssl-date: TLS randomness does not represent time
  1096. Port: 3306/tcp open mysql syn-ack ttl 56 MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  1097. Script Info: | mysql-info:
  1098. Script Info: | Protocol: 10
  1099. Script Info: | Version: 5.5.5-10.2.27-MariaDB-cll-lve
  1100. Script Info: | Thread ID: 57087
  1101. Script Info: | Capabilities flags: 63486
  1102. Script Info: | Some Capabilities: LongColumnFlag, ODBCClient, ConnectWithDatabase, FoundRows, Speaks41ProtocolOld, SupportsTransactions, IgnoreSigpipes, InteractiveClient, Speaks41ProtocolNew, IgnoreSpaceBeforeParenthesis, DontAllowDatabaseTableColumn, SupportsCompression, SupportsLoadDataLocal, Support41Auth, SupportsMultipleStatments, SupportsMultipleResults, SupportsAuthPlugins
  1103. Script Info: | Status: Autocommit
  1104. Script Info: | Salt: fUY?k#ga/e1b{fkgBT`f
  1105. Script Info: |_ Auth Plugin Name: mysql_native_password
  1106. Script Info: Device type: general purpose|WAP|storage-misc|firewall|proxy server|broadband router
  1107. Script Info: Running (JUST GUESSING): FreeBSD 6.X (92%), Linux 3.X|4.X|2.6.X (88%), Dell embedded (85%), Cisco embedded (85%), Riverbed embedded (85%), Zhone embedded (85%)
  1108. Os Info: Host: andrew.uswebhost.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  1109. Script Info: |_clock-skew: -1s
  1110. IP: 72.52.244.68
  1111. HostName: ns2.bighornhosting.com Type: NS
  1112. HostName: andrew.uswebhost.com Type: PTR
  1113. Country: United States
  1114. Is Active: True (reset ttl 64)
  1115. Port: 21/tcp open ftp syn-ack ttl 56 Pure-FTPd
  1116. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1117. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1118. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1119. Script Info: | Public Key type: rsa
  1120. Script Info: | Public Key bits: 2048
  1121. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1122. Script Info: | Not valid before: 2019-04-22T00:00:00
  1123. Script Info: | Not valid after: 2020-04-21T23:59:59
  1124. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1125. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1126. Script Info: |_ssl-date: TLS randomness does not represent time
  1127. Port: 53/tcp open domain syn-ack ttl 56 ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  1128. Script Info: | dns-nsid:
  1129. Script Info: |_ bind.version: 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  1130. Port: 80/tcp open http syn-ack ttl 56 LiteSpeed httpd
  1131. Script Info: | http-methods:
  1132. Script Info: |_ Supported Methods: OPTIONS HEAD GET POST
  1133. Script Info: |_http-server-header: LiteSpeed
  1134. Script Info: |_http-title: Site doesn't have a title (text/html).
  1135. Port: 110/tcp open pop3 syn-ack ttl 56 Dovecot pop3d
  1136. Script Info: |_pop3-capabilities: STLS AUTH-RESP-CODE TOP PIPELINING UIDL USER RESP-CODES CAPA SASL(PLAIN LOGIN)
  1137. Script Info: |_ssl-date: TLS randomness does not represent time
  1138. Port: 143/tcp open imap syn-ack ttl 56 Dovecot imapd
  1139. Script Info: |_imap-capabilities: ID LITERAL+ listed IMAP4rev1 IDLE NAMESPACE LOGIN-REFERRALS post-login Pre-login OK ENABLE have more capabilities STARTTLS SASL-IR AUTH=LOGINA0001 AUTH=PLAIN
  1140. Script Info: |_ssl-date: TLS randomness does not represent time
  1141. Port: 443/tcp open ssl/http syn-ack ttl 56 LiteSpeed httpd
  1142. Script Info: | http-methods:
  1143. Script Info: |_ Supported Methods: OPTIONS HEAD GET POST
  1144. Script Info: |_http-server-header: LiteSpeed
  1145. Script Info: |_http-title: Site doesn't have a title (text/html).
  1146. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1147. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1148. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1149. Script Info: | Public Key type: rsa
  1150. Script Info: | Public Key bits: 2048
  1151. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1152. Script Info: | Not valid before: 2019-04-22T00:00:00
  1153. Script Info: | Not valid after: 2020-04-21T23:59:59
  1154. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1155. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1156. Script Info: |_ssl-date: 2019-10-22T11:34:39+00:00; -1s from scanner time.
  1157. Script Info: | tls-alpn:
  1158. Script Info: | h2
  1159. Script Info: | spdy/3
  1160. Script Info: | spdy/2
  1161. Script Info: |_ http/1.1
  1162. Port: 465/tcp open ssl/smtp syn-ack ttl 56 Exim smtpd 4.92
  1163. Script Info: | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
  1164. Script Info: |_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1165. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1166. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1167. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1168. Script Info: | Public Key type: rsa
  1169. Script Info: | Public Key bits: 2048
  1170. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1171. Script Info: | Not valid before: 2019-04-22T00:00:00
  1172. Script Info: | Not valid after: 2020-04-21T23:59:59
  1173. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1174. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1175. Script Info: |_ssl-date: TLS randomness does not represent time
  1176. Port: 587/tcp open smtp syn-ack ttl 56 Exim smtpd 4.92
  1177. Script Info: | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
  1178. Script Info: |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1179. Script Info: | ssl-cert: Subject: commonName=andrew.uswebhost.com
  1180. Script Info: | Subject Alternative Name: DNS:andrew.uswebhost.com, DNS:www.andrew.uswebhost.com
  1181. Script Info: | Issuer: commonName=cPanel, Inc. Certification Authority/organizationName=cPanel, Inc./stateOrProvinceName=TX/countryName=US
  1182. Script Info: | Public Key type: rsa
  1183. Script Info: | Public Key bits: 2048
  1184. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1185. Script Info: | Not valid before: 2019-04-22T00:00:00
  1186. Script Info: | Not valid after: 2020-04-21T23:59:59
  1187. Script Info: | MD5: 3aea ca91 d196 86ca 0a14 cb01 f4e7 ab54
  1188. Script Info: |_SHA-1: 9e8f 8e39 347d 195f 5283 099c cde1 1eb8 1f5f 5ada
  1189. Script Info: |_ssl-date: TLS randomness does not represent time
  1190. Port: 993/tcp open ssl/imaps? syn-ack ttl 56
  1191. Script Info: |_ssl-date: TLS randomness does not represent time
  1192. Port: 995/tcp open ssl/pop3s? syn-ack ttl 56
  1193. Script Info: |_ssl-date: TLS randomness does not represent time
  1194. Port: 3306/tcp open mysql syn-ack ttl 56 MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  1195. Script Info: | mysql-info:
  1196. Script Info: | Protocol: 10
  1197. Script Info: | Version: 5.5.5-10.2.27-MariaDB-cll-lve
  1198. Script Info: | Thread ID: 58267
  1199. Script Info: | Capabilities flags: 63486
  1200. Script Info: | Some Capabilities: SupportsCompression, FoundRows, InteractiveClient, IgnoreSpaceBeforeParenthesis, IgnoreSigpipes, SupportsLoadDataLocal, Support41Auth, LongColumnFlag, DontAllowDatabaseTableColumn, ConnectWithDatabase, Speaks41ProtocolOld, SupportsTransactions, ODBCClient, Speaks41ProtocolNew, SupportsMultipleStatments, SupportsAuthPlugins, SupportsMultipleResults
  1201. Script Info: | Status: Autocommit
  1202. Script Info: | Salt: v5@!$2nT:dkjUHK}VvoL
  1203. Script Info: |_ Auth Plugin Name: mysql_native_password
  1204. Os Info: Host: andrew.uswebhost.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  1205. Script Info: |_clock-skew: -1s
  1206. IP: 72.52.244.17
  1207. HostName: fortressoffaith.com Type: MX
  1208. HostName: andrew.uswebhost.com Type: PTR
  1209. HostName: www.fortressoffaith.com. Type: A
  1210. HostName: mail.fortressoffaith.com. Type: A
  1211. HostName: webmail.fortressoffaith.com. Type: A
  1212. Country: United States
  1213. Is Active: True (reset ttl 64)
  1214. Port: 21/tcp open ftp syn-ack ttl 56 Pure-FTPd
  1215. Port: 53/tcp open domain syn-ack ttl 56 ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  1216. Script Info: | dns-nsid:
  1217. Script Info: |_ bind.version: 9.11.4-P2-RedHat-9.11.4-9.P2.el7
  1218. Port: 80/tcp open http syn-ack ttl 56 LiteSpeed httpd
  1219. Script Info: | http-methods:
  1220. Script Info: |_ Supported Methods: OPTIONS HEAD GET POST
  1221. Script Info: |_http-title: Site doesn't have a title (text/html).
  1222. Port: 110/tcp open pop3 syn-ack ttl 56 Dovecot pop3d
  1223. Port: 143/tcp open imap syn-ack ttl 56 Dovecot imapd
  1224. Script Info: |_imap-capabilities: LOGIN-REFERRALS STARTTLS SASL-IR AUTH=LOGINA0001 post-login NAMESPACE have AUTH=PLAIN ID ENABLE OK IMAP4rev1 more IDLE listed capabilities Pre-login LITERAL+
  1225. Port: 443/tcp open ssl/http syn-ack ttl 56 LiteSpeed httpd
  1226. Script Info: | http-cookie-flags:
  1227. Script Info: | /:
  1228. Script Info: | PHPSESSID:
  1229. Script Info: |_ httponly flag not set
  1230. Script Info: |_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E
  1231. Script Info: | http-robots.txt: 1 disallowed entry
  1232. Script Info: |_/wp-admin/
  1233. Script Info: |_http-title: Did not follow redirect to https://bighornhosting.com/
  1234. Script Info: | ssl-cert: Subject: commonName=bighornhosting.com
  1235. Script Info: | Subject Alternative Name: DNS:bighornhosting.com, DNS:cpanel.bighornhosting.com, DNS:mail.bighornhosting.com, DNS:webdisk.bighornhosting.com, DNS:webmail.bighornhosting.com, DNS:whm.bighornhosting.com, DNS:www.bighornhosting.com
  1236. Script Info: | Issuer: commonName=Let's Encrypt Authority X3/organizationName=Let's Encrypt/countryName=US
  1237. Script Info: | Public Key type: rsa
  1238. Script Info: | Public Key bits: 2048
  1239. Script Info: | Signature Algorithm: sha256WithRSAEncryption
  1240. Script Info: | Not valid before: 2019-09-18T02:08:45
  1241. Script Info: | Not valid after: 2019-12-17T02:08:45
  1242. Script Info: | MD5: d01a 9027 47d9 e638 609d 2c22 c3c4 722c
  1243. Script Info: |_SHA-1: b6a1 69c7 f8fc 7d21 9237 3776 009f 080c 07f2 1ebf
  1244. Port: 465/tcp open ssl/smtp syn-ack ttl 56 Exim smtpd 4.92
  1245. Script Info: | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
  1246. Script Info: |_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1247. Port: 587/tcp open smtp syn-ack ttl 56 Exim smtpd 4.92
  1248. Script Info: | smtp-commands: andrew.uswebhost.com Hello nmap.scanme.org [45.131.4.11], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
  1249. Script Info: |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
  1250. Port: 993/tcp open ssl/imaps? syn-ack ttl 56
  1251. Port: 995/tcp open ssl/pop3s? syn-ack ttl 56
  1252. Port: 3306/tcp open mysql syn-ack ttl 56 MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  1253. Script Info: | mysql-info:
  1254. Script Info: | Protocol: 10
  1255. Script Info: | Version: 5.5.5-10.2.27-MariaDB-cll-lve
  1256. Script Info: | Thread ID: 59305
  1257. Script Info: | Capabilities flags: 63486
  1258. Script Info: | Some Capabilities: Support41Auth, Speaks41ProtocolOld, SupportsTransactions, IgnoreSpaceBeforeParenthesis, DontAllowDatabaseTableColumn, IgnoreSigpipes, InteractiveClient, Speaks41ProtocolNew, SupportsCompression, ODBCClient, SupportsLoadDataLocal, ConnectWithDatabase, FoundRows, LongColumnFlag, SupportsAuthPlugins, SupportsMultipleResults, SupportsMultipleStatments
  1259. Script Info: | Status: Autocommit
  1260. Script Info: | Salt: By\Am&nz:SoVC*HmkT?~
  1261. Script Info: |_ Auth Plugin Name: mysql_native_password
  1262. Script Info: Device type: general purpose|storage-misc|firewall|webcam
  1263. Script Info: Running (JUST GUESSING): Linux 4.X|3.X|2.6.X (93%), Synology DiskStation Manager 5.X (87%), FreeBSD 6.X (86%), WatchGuard Fireware 11.X (86%), Tandberg embedded (86%)
  1264. Os Info: Host: andrew.uswebhost.com; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  1265. #######################################################################################################################################
  1266. ----- fortressoffaith.com -----
  1267.  
  1268.  
  1269. Host's addresses:
  1270. __________________
  1271.  
  1272. fortressoffaith.com. 11399 IN A 72.52.244.17
  1273.  
  1274.  
  1275. Name Servers:
  1276. ______________
  1277.  
  1278. ns2.bighornhosting.com. 83399 IN A 72.52.244.68
  1279. ns1.bighornhosting.com. 84553 IN A 72.52.144.226
  1280.  
  1281.  
  1282. Mail (MX) Servers:
  1283. ___________________
  1284.  
  1285. fortressoffaith.com. 11398 IN A 72.52.244.17
  1286.  
  1287. _______________________________________________
  1288.  
  1289. ftp.fortressoffaith.com. 12507 IN A 72.52.144.226
  1290. mail.fortressoffaith.com. 12494 IN CNAME fortressoffaith.com.
  1291. fortressoffaith.com. 12549 IN A 72.52.244.17
  1292. webmail.fortressoffaith.com. 12459 IN A 72.52.244.17
  1293. www.fortressoffaith.com. 12502 IN CNAME fortressoffaith.com.
  1294. fortressoffaith.com. 12502 IN A 72.52.244.17
  1295.  
  1296.  
  1297. Launching Whois Queries:
  1298. _________________________
  1299.  
  1300. whois ip result: 72.52.144.0 -> 72.52.128.0/17
  1301.  
  1302. #######################################################################################################################################
  1303. AVAILABLE PLUGINS
  1304. -----------------
  1305.  
  1306. CompressionPlugin
  1307. OpenSslCipherSuitesPlugin
  1308. HeartbleedPlugin
  1309. RobotPlugin
  1310. CertificateInfoPlugin
  1311. FallbackScsvPlugin
  1312. OpenSslCcsInjectionPlugin
  1313. HttpHeadersPlugin
  1314. SessionRenegotiationPlugin
  1315. SessionResumptionPlugin
  1316. EarlyDataPlugin
  1317.  
  1318.  
  1319.  
  1320. CHECKING HOST(S) AVAILABILITY
  1321. -----------------------------
  1322.  
  1323. 72.52.244.17:443 => 72.52.244.17
  1324.  
  1325.  
  1326.  
  1327.  
  1328. SCAN RESULTS FOR 72.52.244.17:443 - 72.52.244.17
  1329. ------------------------------------------------
  1330.  
  1331. * Deflate Compression:
  1332. OK - Compression disabled
  1333.  
  1334. * OpenSSL Heartbleed:
  1335. OK - Not vulnerable to Heartbleed
  1336.  
  1337. * Certificate Information:
  1338. Content
  1339. SHA1 Fingerprint: b6a169c7f8fc7d2192373776009f080c07f21ebf
  1340. Common Name: bighornhosting.com
  1341. Issuer: Let's Encrypt Authority X3
  1342. Serial Number: 272989317180563932023806509179710043591674
  1343. Not Before: 2019-09-18 02:08:45
  1344. Not After: 2019-12-17 02:08:45
  1345. Signature Algorithm: sha256
  1346. Public Key Algorithm: RSA
  1347. Key Size: 2048
  1348. Exponent: 65537 (0x10001)
  1349. DNS Subject Alternative Names: ['bighornhosting.com', 'cpanel.bighornhosting.com', 'mail.bighornhosting.com', 'webdisk.bighornhosting.com', 'webmail.bighornhosting.com', 'whm.bighornhosting.com', 'www.bighornhosting.com']
  1350.  
  1351. Trust
  1352. Hostname Validation: FAILED - Certificate does NOT match 72.52.244.17
  1353. Android CA Store (9.0.0_r9): OK - Certificate is trusted
  1354. Apple CA Store (iOS 12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
  1355. Java CA Store (jdk-12.0.1): OK - Certificate is trusted
  1356. Mozilla CA Store (2019-03-14): OK - Certificate is trusted
  1357. Windows CA Store (2019-05-27): OK - Certificate is trusted
  1358. Symantec 2018 Deprecation: WARNING: Certificate distrusted by Google and Mozilla on September 2018
  1359. Received Chain: bighornhosting.com --> Let's Encrypt Authority X3
  1360. Verified Chain: bighornhosting.com --> Let's Encrypt Authority X3 --> DST Root CA X3
  1361. Received Chain Contains Anchor: OK - Anchor certificate not sent
  1362. Received Chain Order: OK - Order is valid
  1363. Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
  1364.  
  1365. Extensions
  1366. OCSP Must-Staple: NOT SUPPORTED - Extension not found
  1367. Certificate Transparency: WARNING - Only 2 SCTs included but Google recommends 3 or more
  1368.  
  1369. OCSP Stapling
  1370. OCSP Response Status: successful
  1371. Validation w/ Mozilla Store: OK - Response is trusted
  1372. Responder Id: C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
  1373. Cert Status: good
  1374. Cert Serial Number: 03223E560BAB9BF324451A91529F013413FA
  1375. This Update: Oct 21 03:00:00 2019 GMT
  1376. Next Update: Oct 28 03:00:00 2019 GMT
  1377.  
  1378. * TLSV1_1 Cipher Suites:
  1379. Server rejected all cipher suites.
  1380.  
  1381. * TLSV1 Cipher Suites:
  1382. Server rejected all cipher suites.
  1383.  
  1384. * Downgrade Attacks:
  1385. TLS_FALLBACK_SCSV: OK - Supported
  1386.  
  1387. * OpenSSL CCS Injection:
  1388. OK - Not vulnerable to OpenSSL CCS injection
  1389.  
  1390. * SSLV3 Cipher Suites:
  1391. Server rejected all cipher suites.
  1392.  
  1393. * SSLV2 Cipher Suites:
  1394. Server rejected all cipher suites.
  1395.  
  1396. * TLS 1.2 Session Resumption Support:
  1397. With Session IDs: PARTIALLY SUPPORTED (4 successful, 1 failed, 0 errors, 5 total attempts).
  1398. With TLS Tickets: OK - Supported
  1399.  
  1400. * TLSV1_2 Cipher Suites:
  1401. Forward Secrecy OK - Supported
  1402. RC4 OK - Not Supported
  1403.  
  1404. Preferred:
  1405. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1406. Accepted:
  1407. TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1408. TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1409. TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1410. TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1411. TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1412. TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 256 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1413. TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1414. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1415. TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1416. TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 301 Moved Permanently - https://bighornhosting.com/
  1417.  
  1418. * TLSV1_3 Cipher Suites:
  1419. Server rejected all cipher suites.
  1420.  
  1421. * Session Renegotiation:
  1422. Client-initiated Renegotiation: OK - Rejected
  1423. Secure Renegotiation: OK - Supported
  1424.  
  1425. * ROBOT Attack:
  1426. OK - Not vulnerable
  1427.  
  1428.  
  1429. SCAN COMPLETED IN 37.66 S
  1430. -------------------------
  1431. #######################################################################################################################################
  1432. adding 72.52.244.17/32 mode `TCPscan' ports `7,9,11,13,18,19,21-23,25,37,39,42,49,50,53,65,67-70,79-81,88,98,100,105-107,109-111,113,118,119,123,129,135,137-139,143,150,161-164,174,177-179,191,199-202,204,206,209,210,213,220,345,346,347,369-372,389,406,407,422,443-445,487,500,512-514,517,518,520,525,533,538,548,554,563,587,610-612,631-634,636,642,653,655,657,666,706,750-752,765,779,808,873,901,923,941,946,992-995,1001,1023-1030,1080,1210,1214,1234,1241,1334,1349,1352,1423-1425,1433,1434,1524,1525,1645,1646,1649,1701,1718,1719,1720,1723,1755,1812,1813,2048-2050,2101-2104,2140,2150,2233,2323,2345,2401,2430,2431,2432,2433,2583,2628,2776,2777,2988,2989,3050,3130,3150,3232,3306,3389,3456,3493,3542-3545,3632,3690,3801,4000,4400,4321,4567,4899,5002,5136-5139,5150,5151,5222,5269,5308,5354,5355,5422-5425,5432,5503,5555,5556,5678,6000-6007,6346,6347,6543,6544,6789,6838,6666-6670,7000-7009,7028,7100,7983,8079-8082,8088,8787,8879,9090,9101-9103,9325,9359,10000,10026,10027,10067,10080,10081,10167,10498,11201,15345,17001-17003,18753,20011,20012,21554,22273,26274,27374,27444,27573,31335-31338,31787,31789,31790,31791,32668,32767-32780,33390,47262,49301,54320,54321,57341,58008,58009,58666,59211,60000,60006,61000,61348,61466,61603,63485,63808,63809,64429,65000,65506,65530-65535' pps 300
  1433. using interface(s) eth0
  1434. added module payload for port 5060 proto 17
  1435. added module payload for port 1900 proto 17
  1436. added module payload for port 53 proto 17
  1437. added module payload for port 80 proto 6
  1438. added module payload for port 80 proto 6
  1439. added module payload for port 518 proto 17
  1440. scaning 1.00e+00 total hosts with 3.38e+02 total packets, should take a little longer than 8 Seconds
  1441. drone type Unknown on fd 4 is version 1.1
  1442. drone type Unknown on fd 3 is version 1.1
  1443. added module payload for port 5060 proto 17
  1444. added module payload for port 1900 proto 17
  1445. added module payload for port 53 proto 17
  1446. added module payload for port 80 proto 6
  1447. added module payload for port 80 proto 6
  1448. added module payload for port 518 proto 17
  1449. scan iteration 1 out of 1
  1450. using pcap filter: `dst 192.168.0.52 and ! src 192.168.0.52 and (tcp)'
  1451. using TSC delay
  1452. sender statistics 299.8 pps with 338 packets sent total
  1453. listener statistics 94 packets recieved 0 packets droped and 0 interface drops
  1454. #######################################################################################################################################
  1455. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 07:54 EDT
  1456. Nmap scan report for andrew.uswebhost.com (72.52.244.17)
  1457. Host is up (0.14s latency).
  1458. Not shown: 2 filtered ports
  1459. PORT STATE SERVICE
  1460. 53/udp open domain
  1461. 67/udp open|filtered dhcps
  1462. 68/udp open|filtered dhcpc
  1463. 69/udp open|filtered tftp
  1464. 88/udp open|filtered kerberos-sec
  1465. 123/udp open|filtered ntp
  1466. 139/udp open|filtered netbios-ssn
  1467. 161/udp open|filtered snmp
  1468. 162/udp open|filtered snmptrap
  1469. 389/udp open|filtered ldap
  1470. 500/udp open|filtered isakmp
  1471. 520/udp open|filtered route
  1472. 2049/udp open|filtered nfs
  1473.  
  1474. Nmap done: 1 IP address (1 host up) scanned in 2.56 seconds
  1475. ######################################################################################################################################
  1476. Starting Nmap 7.80 ( https://nmap.org ) at 2019-10-22 07:31 EDT
  1477. Nmap scan report for andrew.uswebhost.com (72.52.244.17)
  1478. Host is up (0.32s latency).
  1479. Not shown: 928 filtered ports, 60 closed ports
  1480. PORT STATE SERVICE VERSION
  1481. 21/tcp open ftp Pure-FTPd
  1482. 53/tcp open domain ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
  1483. 80/tcp open http LiteSpeed httpd
  1484. 110/tcp open pop3 Dovecot pop3d
  1485. 143/tcp open imap Dovecot imapd
  1486. 443/tcp open ssl/http LiteSpeed httpd
  1487. 465/tcp open ssl/smtp Exim smtpd 4.92
  1488. 587/tcp open smtp Exim smtpd 4.92
  1489. 993/tcp open ssl/imaps?
  1490. 995/tcp open ssl/pop3s?
  1491. 2200/tcp open ssh OpenSSH 7.4 (protocol 2.0)
  1492. 3306/tcp open mysql MySQL 5.5.5-10.2.27-MariaDB-cll-lve
  1493. Service Info: OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
  1494. #######################################################################################################################################
  1495. https://fortressoffaith.com/ [200 OK] Country[UNITED STATES][US], Google-Analytics[Universal][UA-113358977-1], HTML5, HTTPServer[LiteSpeed], IP[72.52.244.17], JQuery, LiteSpeed, MetaGenerator[WordPress 5.2.4], PHP[7.0.33], Script[text/javascript], Title[Fortress of Faith &#8211; Refuting Islam], UncommonHeaders[access-control-allow-origin,link,x-litespeed-cache,alt-svc], WordPress[5.2.4], X-Powered-By[PHP/7.0.33], X-UA-Compatible[IE=edge]
  1496. #######################################################################################################################################
  1497. [+] URL: https://fortressoffaith.com/
  1498. [+] Started: Tue Oct 22 07:04:11 2019
  1499.  
  1500. Interesting Finding(s):
  1501.  
  1502. [+] https://fortressoffaith.com/
  1503. | Interesting Entries:
  1504. | - x-powered-by: PHP/7.0.33
  1505. | - access-control-allow-origin: *
  1506. | - x-ua-compatible: IE=edge
  1507. | - x-litespeed-cache: hit
  1508. | - server: LiteSpeed
  1509. | - alt-svc: quic=":443"; ma=2592000; v="39,43,46", h3-22=":443"; ma=2592000
  1510. | Found By: Headers (Passive Detection)
  1511. | Confidence: 100%
  1512.  
  1513. [+] https://fortressoffaith.com/robots.txt
  1514. | Interesting Entries:
  1515. | - /wp-admin/
  1516. | - /wp-admin/admin-ajax.php
  1517. | Found By: Robots Txt (Aggressive Detection)
  1518. | Confidence: 100%
  1519.  
  1520. [+] https://fortressoffaith.com/xmlrpc.php
  1521. | Found By: Direct Access (Aggressive Detection)
  1522. | Confidence: 100%
  1523. | References:
  1524. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1525. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1526. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1527. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1528. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1529.  
  1530. [+] https://fortressoffaith.com/readme.html
  1531. | Found By: Direct Access (Aggressive Detection)
  1532. | Confidence: 100%
  1533.  
  1534. [+] This site has 'Must Use Plugins': https://fortressoffaith.com/wp-content/mu-plugins/
  1535. | Found By: Direct Access (Aggressive Detection)
  1536. | Confidence: 80%
  1537. | Reference: http://codex.wordpress.org/Must_Use_Plugins
  1538.  
  1539. [+] Upload directory has listing enabled: https://fortressoffaith.com/wp-content/uploads/
  1540. | Found By: Direct Access (Aggressive Detection)
  1541. | Confidence: 100%
  1542.  
  1543. [+] https://fortressoffaith.com/wp-cron.php
  1544. | Found By: Direct Access (Aggressive Detection)
  1545. | Confidence: 60%
  1546. | References:
  1547. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1548. | - https://github.com/wpscanteam/wpscan/issues/1299
  1549.  
  1550. [+] WordPress version 5.2.4 identified (Latest, released on 2019-10-14).
  1551. | Detected By: Emoji Settings (Passive Detection)
  1552. | - https://fortressoffaith.com/, Match: 'wp-includes\/js\/wp-emoji-release.min.js?ver=5.2.4'
  1553. | Confirmed By: Meta Generator (Passive Detection)
  1554. | - https://fortressoffaith.com/, Match: 'WordPress 5.2.4'
  1555.  
  1556. [+] WordPress theme in use: generatepress
  1557. | Location: https://fortressoffaith.com/wp-content/themes/generatepress/
  1558. | Latest Version: 2.3.2 (up to date)
  1559. | Last Updated: 2019-06-25T00:00:00.000Z
  1560. | Readme: https://fortressoffaith.com/wp-content/themes/generatepress/readme.txt
  1561. | Style URL: https://fortressoffaith.com/wp-content/themes/generatepress/style.css
  1562. | Style Name: GeneratePress
  1563. | Style URI: https://generatepress.com
  1564. | Description: GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performanc...
  1565. | Author: Tom Usborne
  1566. | Author URI: https://tomusborne.com
  1567. |
  1568. | Detected By: Urls In Homepage (Passive Detection)
  1569. |
  1570. | Version: 2.3.2 (80% confidence)
  1571. | Detected By: Style (Passive Detection)
  1572. | - https://fortressoffaith.com/wp-content/themes/generatepress/style.css, Match: 'Version: 2.3.2'
  1573.  
  1574. [+] Enumerating All Plugins (via Passive Methods)
  1575. [+] Checking Plugin Versions (via Passive and Aggressive Methods)
  1576.  
  1577. [i] Plugin(s) Identified:
  1578.  
  1579. [+] cuepro
  1580. | Location: https://fortressoffaith.com/wp-content/plugins/cuepro/
  1581. |
  1582. | Detected By: Urls In Homepage (Passive Detection)
  1583. |
  1584. | The version could not be determined.
  1585.  
  1586. [+] elementor
  1587. | Location: https://fortressoffaith.com/wp-content/plugins/elementor/
  1588. | Latest Version: 2.7.4 (up to date)
  1589. | Last Updated: 2019-10-06T13:05:00.000Z
  1590. |
  1591. | Detected By: Urls In Homepage (Passive Detection)
  1592. |
  1593. | Version: 2.7.4 (100% confidence)
  1594. | Detected By: Query Parameter (Passive Detection)
  1595. | - https://fortressoffaith.com/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=2.7.4
  1596. | - https://fortressoffaith.com/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=2.7.4
  1597. | Confirmed By: Readme - Stable Tag (Aggressive Detection)
  1598. | - https://fortressoffaith.com/wp-content/plugins/elementor/readme.txt
  1599.  
  1600. [+] elementor-pro
  1601. | Location: https://fortressoffaith.com/wp-content/plugins/elementor-pro/
  1602. |
  1603. | Detected By: Urls In Homepage (Passive Detection)
  1604. |
  1605. | The version could not be determined.
  1606.  
  1607. [+] feedburner-alternative-and-rss-redirect
  1608. | Location: https://fortressoffaith.com/wp-content/plugins/feedburner-alternative-and-rss-redirect/
  1609. | Latest Version: 2.3 (up to date)
  1610. | Last Updated: 2019-10-02T13:01:00.000Z
  1611. |
  1612. | Detected By: Urls In Homepage (Passive Detection)
  1613. |
  1614. | Version: 2.3 (100% confidence)
  1615. | Detected By: Readme - Stable Tag (Aggressive Detection)
  1616. | - https://fortressoffaith.com/wp-content/plugins/feedburner-alternative-and-rss-redirect/readme.txt
  1617. | Confirmed By: Readme - ChangeLog Section (Aggressive Detection)
  1618. | - https://fortressoffaith.com/wp-content/plugins/feedburner-alternative-and-rss-redirect/readme.txt
  1619.  
  1620. [+] maticpress-client
  1621. | Location: https://fortressoffaith.com/wp-content/plugins/maticpress-client/
  1622. |
  1623. | Detected By: Urls In Homepage (Passive Detection)
  1624. |
  1625. | The version could not be determined.
  1626.  
  1627. [+] Enumerating Config Backups (via Passive and Aggressive Methods)
  1628. Checking Config Backups - Time: 00:00:12 <=============> (21 / 21) 100.00% Time: 00:00:12
  1629.  
  1630. [i] No Config Backups Found.
  1631.  
  1632. [!] No WPVulnDB API Token given, as a result vulnerability data has not been output.
  1633. [!] You can get a free API token with 50 daily requests by registering at https://wpvulndb.com/users/sign_up.
  1634.  
  1635. [+] Finished: Tue Oct 22 07:05:12 2019
  1636. [+] Requests Done: 70
  1637. [+] Cached Requests: 6
  1638. [+] Data Sent: 19.748 KB
  1639. [+] Data Received: 467.155 KB
  1640. [+] Memory used: 133.723 MB
  1641. [+] Elapsed time: 00:01:01
  1642. #######################################################################################################################################
  1643. [+] URL: https://fortressoffaith.com/
  1644. [+] Started: Tue Oct 22 07:04:14 2019
  1645.  
  1646. Interesting Finding(s):
  1647.  
  1648. [+] https://fortressoffaith.com/
  1649. | Interesting Entries:
  1650. | - x-powered-by: PHP/7.0.33
  1651. | - access-control-allow-origin: *
  1652. | - x-ua-compatible: IE=edge
  1653. | - x-litespeed-cache: hit
  1654. | - server: LiteSpeed
  1655. | - alt-svc: quic=":443"; ma=2592000; v="39,43,46", h3-22=":443"; ma=2592000
  1656. | Found By: Headers (Passive Detection)
  1657. | Confidence: 100%
  1658.  
  1659. [+] https://fortressoffaith.com/robots.txt
  1660. | Interesting Entries:
  1661. | - /wp-admin/
  1662. | - /wp-admin/admin-ajax.php
  1663. | Found By: Robots Txt (Aggressive Detection)
  1664. | Confidence: 100%
  1665.  
  1666. [+] https://fortressoffaith.com/xmlrpc.php
  1667. | Found By: Direct Access (Aggressive Detection)
  1668. | Confidence: 100%
  1669. | References:
  1670. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1671. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1672. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1673. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1674. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1675.  
  1676. [+] https://fortressoffaith.com/readme.html
  1677. | Found By: Direct Access (Aggressive Detection)
  1678. | Confidence: 100%
  1679.  
  1680. [+] This site has 'Must Use Plugins': https://fortressoffaith.com/wp-content/mu-plugins/
  1681. | Found By: Direct Access (Aggressive Detection)
  1682. | Confidence: 80%
  1683. | Reference: http://codex.wordpress.org/Must_Use_Plugins
  1684.  
  1685. [+] Upload directory has listing enabled: https://fortressoffaith.com/wp-content/uploads/
  1686. | Found By: Direct Access (Aggressive Detection)
  1687. | Confidence: 100%
  1688.  
  1689. [+] https://fortressoffaith.com/wp-cron.php
  1690. | Found By: Direct Access (Aggressive Detection)
  1691. | Confidence: 60%
  1692. | References:
  1693. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1694. | - https://github.com/wpscanteam/wpscan/issues/1299
  1695.  
  1696. [+] WordPress version 5.2.4 identified (Latest, released on 2019-10-14).
  1697. | Detected By: Emoji Settings (Passive Detection)
  1698. | - https://fortressoffaith.com/, Match: 'wp-includes\/js\/wp-emoji-release.min.js?ver=5.2.4'
  1699. | Confirmed By: Meta Generator (Passive Detection)
  1700. | - https://fortressoffaith.com/, Match: 'WordPress 5.2.4'
  1701.  
  1702. [+] WordPress theme in use: generatepress
  1703. | Location: https://fortressoffaith.com/wp-content/themes/generatepress/
  1704. | Latest Version: 2.3.2 (up to date)
  1705. | Last Updated: 2019-06-25T00:00:00.000Z
  1706. | Readme: https://fortressoffaith.com/wp-content/themes/generatepress/readme.txt
  1707. | Style URL: https://fortressoffaith.com/wp-content/themes/generatepress/style.css
  1708. | Style Name: GeneratePress
  1709. | Style URI: https://generatepress.com
  1710. | Description: GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performanc...
  1711. | Author: Tom Usborne
  1712. | Author URI: https://tomusborne.com
  1713. |
  1714. | Detected By: Urls In Homepage (Passive Detection)
  1715. |
  1716. | Version: 2.3.2 (80% confidence)
  1717. | Detected By: Style (Passive Detection)
  1718. | - https://fortressoffaith.com/wp-content/themes/generatepress/style.css, Match: 'Version: 2.3.2'
  1719.  
  1720. [+] Enumerating Users (via Passive and Aggressive Methods)
  1721. Brute Forcing Author IDs - Time: 00:00:07 <==> (10 / 10) 100.00% Time: 00:00:07
  1722.  
  1723. [i] User(s) Identified:
  1724.  
  1725. [+] pcoovert
  1726. | Detected By: Wp Json Api (Aggressive Detection)
  1727. | - https://fortressoffaith.com/wp-json/wp/v2/users/?per_page=100&page=1
  1728. | Confirmed By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1729.  
  1730. [+] admin
  1731. | Detected By: Wp Json Api (Aggressive Detection)
  1732. | - https://fortressoffaith.com/wp-json/wp/v2/users/?per_page=100&page=1
  1733. | Confirmed By:
  1734. | Oembed API - Author URL (Aggressive Detection)
  1735. | - https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https://fortressoffaith.com/&format=json
  1736. | Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1737.  
  1738. [+] josh
  1739. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1740.  
  1741. [!] No WPVulnDB API Token given, as a result vulnerability data has not been output.
  1742. [!] You can get a free API token with 50 daily requests by registering at https://wpvulndb.com/users/sign_up.
  1743.  
  1744. [+] Finished: Tue Oct 22 07:05:05 2019
  1745. [+] Requests Done: 40
  1746. [+] Cached Requests: 19
  1747. [+] Data Sent: 13.985 KB
  1748. [+] Data Received: 321.54 KB
  1749. [+] Memory used: 114.797 MB
  1750. [+] Elapsed time: 00:00:51
  1751. #######################################################################################################################################
  1752. [+] URL: https://fortressoffaith.com/
  1753. [+] Started: Tue Oct 22 07:07:05 2019
  1754.  
  1755. Interesting Finding(s):
  1756.  
  1757. [+] https://fortressoffaith.com/
  1758. | Interesting Entries:
  1759. | - x-powered-by: PHP/7.0.33
  1760. | - access-control-allow-origin: *
  1761. | - x-ua-compatible: IE=edge
  1762. | - x-litespeed-cache: hit
  1763. | - server: LiteSpeed
  1764. | - alt-svc: quic=":443"; ma=2592000; v="39,43,46", h3-22=":443"; ma=2592000
  1765. | Found By: Headers (Passive Detection)
  1766. | Confidence: 100%
  1767.  
  1768. [+] https://fortressoffaith.com/robots.txt
  1769. | Interesting Entries:
  1770. | - /wp-admin/
  1771. | - /wp-admin/admin-ajax.php
  1772. | Found By: Robots Txt (Aggressive Detection)
  1773. | Confidence: 100%
  1774.  
  1775. [+] https://fortressoffaith.com/xmlrpc.php
  1776. | Found By: Direct Access (Aggressive Detection)
  1777. | Confidence: 100%
  1778. | References:
  1779. | - http://codex.wordpress.org/XML-RPC_Pingback_API
  1780. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner
  1781. | - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos
  1782. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login
  1783. | - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access
  1784.  
  1785. [+] https://fortressoffaith.com/readme.html
  1786. | Found By: Direct Access (Aggressive Detection)
  1787. | Confidence: 100%
  1788.  
  1789. [+] This site has 'Must Use Plugins': https://fortressoffaith.com/wp-content/mu-plugins/
  1790. | Found By: Direct Access (Aggressive Detection)
  1791. | Confidence: 80%
  1792. | Reference: http://codex.wordpress.org/Must_Use_Plugins
  1793.  
  1794. [+] Upload directory has listing enabled: https://fortressoffaith.com/wp-content/uploads/
  1795. | Found By: Direct Access (Aggressive Detection)
  1796. | Confidence: 100%
  1797.  
  1798. [+] https://fortressoffaith.com/wp-cron.php
  1799. | Found By: Direct Access (Aggressive Detection)
  1800. | Confidence: 60%
  1801. | References:
  1802. | - https://www.iplocation.net/defend-wordpress-from-ddos
  1803. | - https://github.com/wpscanteam/wpscan/issues/1299
  1804.  
  1805. [+] WordPress version 5.2.4 identified (Latest, released on 2019-10-14).
  1806. | Detected By: Emoji Settings (Passive Detection)
  1807. | - https://fortressoffaith.com/, Match: 'wp-includes\/js\/wp-emoji-release.min.js?ver=5.2.4'
  1808. | Confirmed By: Meta Generator (Passive Detection)
  1809. | - https://fortressoffaith.com/, Match: 'WordPress 5.2.4'
  1810.  
  1811. [+] WordPress theme in use: generatepress
  1812. | Location: https://fortressoffaith.com/wp-content/themes/generatepress/
  1813. | Latest Version: 2.3.2 (up to date)
  1814. | Last Updated: 2019-06-25T00:00:00.000Z
  1815. | Readme: https://fortressoffaith.com/wp-content/themes/generatepress/readme.txt
  1816. | Style URL: https://fortressoffaith.com/wp-content/themes/generatepress/style.css
  1817. | Style Name: GeneratePress
  1818. | Style URI: https://generatepress.com
  1819. | Description: GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performanc...
  1820. | Author: Tom Usborne
  1821. | Author URI: https://tomusborne.com
  1822. |
  1823. | Detected By: Urls In Homepage (Passive Detection)
  1824. |
  1825. | Version: 2.3.2 (80% confidence)
  1826. | Detected By: Style (Passive Detection)
  1827. | - https://fortressoffaith.com/wp-content/themes/generatepress/style.css, Match: 'Version: 2.3.2'
  1828.  
  1829. [+] Enumerating Users (via Passive and Aggressive Methods)
  1830. Brute Forcing Author IDs - Time: 00:00:02 <============> (10 / 10) 100.00% Time: 00:00:02
  1831.  
  1832. [i] User(s) Identified:
  1833.  
  1834. [+] pcoovert
  1835. | Detected By: Wp Json Api (Aggressive Detection)
  1836. | - https://fortressoffaith.com/wp-json/wp/v2/users/?per_page=100&page=1
  1837. | Confirmed By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1838.  
  1839. [+] admin
  1840. | Detected By: Wp Json Api (Aggressive Detection)
  1841. | - https://fortressoffaith.com/wp-json/wp/v2/users/?per_page=100&page=1
  1842. | Confirmed By:
  1843. | Oembed API - Author URL (Aggressive Detection)
  1844. | - https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https://fortressoffaith.com/&format=json
  1845. | Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1846.  
  1847. [+] josh
  1848. | Detected By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)
  1849.  
  1850. [!] No WPVulnDB API Token given, as a result vulnerability data has not been output.
  1851. [!] You can get a free API token with 50 daily requests by registering at https://wpvulndb.com/users/sign_up.
  1852.  
  1853. [+] Finished: Tue Oct 22 07:07:14 2019
  1854. [+] Requests Done: 16
  1855. [+] Cached Requests: 43
  1856. [+] Data Sent: 4.43 KB
  1857. [+] Data Received: 50.064 KB
  1858. [+] Memory used: 113.871 MB
  1859. [+] Elapsed time: 00:00:09
  1860. #######################################################################################################################################
  1861. [INFO] ------TARGET info------
  1862. [*] TARGET: https://fortressoffaith.com/
  1863. [*] TARGET IP: 72.52.244.17
  1864. [INFO] NO load balancer detected for fortressoffaith.com...
  1865. [*] DNS servers: ns1.bighornhosting.com.
  1866. [*] TARGET server: LiteSpeed
  1867. [*] CC: US
  1868. [*] Country: United States
  1869. [*] RegionCode: MI
  1870. [*] RegionName: Michigan
  1871. [*] City: Lansing
  1872. [*] ASN: AS32244
  1873. [*] BGP_PREFIX: 72.52.128.0/17
  1874. [*] ISP: LIQUIDWEB - Liquid Web, L.L.C, US
  1875. [INFO] SSL/HTTPS certificate detected
  1876. [*] Issuer: issuer=C = US, O = Let's Encrypt, CN = Let's Encrypt Authority X3
  1877. [*] Subject: subject=CN = fortressoffaith.com
  1878. [ALERT] Let's Encrypt is commonly used for Phishing
  1879. [INFO] DNS enumeration:
  1880. [*] ftp.fortressoffaith.com 72.52.144.226
  1881. [*] mail.fortressoffaith.com fortressoffaith.com. 72.52.244.17
  1882. [*] webmail.fortressoffaith.com 72.52.244.17
  1883. [INFO] Possible abuse mails are:
  1884. [INFO] NO PAC (Proxy Auto Configuration) file FOUND
  1885. [ALERT] robots.txt file FOUND in http://fortressoffaith.com/robots.txt
  1886. [INFO] Checking for HTTP status codes recursively from http://fortressoffaith.com/robots.txt
  1887. [INFO] Status code Folders
  1888. [*] 200 http://fortressoffaith.com/wp-admin/
  1889. [INFO] Starting FUZZing in http://fortressoffaith.com/FUzZzZzZzZz...
  1890. [INFO] Status code Folders
  1891. [*] 200 http://fortressoffaith.com/news
  1892. [ALERT] Look in the source code. It may contain passwords
  1893. [INFO] Links found from https://fortressoffaith.com/ http://72.52.244.17/:
  1894. [*] http://72.52.244.17/cgi-sys/defaultwebpage.cgi
  1895. [*] http://fortressoffaith.sermon.net/21099434
  1896. [*] http://fortressoffaith.sermon.net/21099740
  1897. [*] http://fortressoffaith.sermon.net/rss/main/audio
  1898. [*] https://crm.fundly.com/6609/Pages/fundraising/#/5
  1899. [*] https://fortressoffaith.com/
  1900. [*] https://fortressoffaith.com/apologetic-responses/
  1901. [*] https://fortressoffaith.com/articles-by-category/
  1902. [*] https://fortressoffaith.com/contact/
  1903. [*] https://fortressoffaith.com/#content
  1904. [*] https://fortressoffaith.com/daily-articles-2/
  1905. [*] https://fortressoffaith.com/elementor-11586/
  1906. [*] https://fortressoffaith.com/evangelizing-muslims/
  1907. [*] https://fortressoffaith.com/feed/
  1908. [*] https://fortressoffaith.com/in-the-news/
  1909. [*] https://fortressoffaith.com/islam-and-pedophilia/
  1910. [*] https://fortressoffaith.com/islam-in-proficy/
  1911. [*] https://fortressoffaith.com/islam-terrorism/
  1912. [*] https://fortressoffaith.com/islam-the-religion/
  1913. [*] https://fortressoffaith.com/muslims-the-people/
  1914. [*] https://fortressoffaith.com/newsletter-subscribe/
  1915. [*] https://fortressoffaith.com/other-issues/
  1916. [*] https://fortressoffaith.com/privacy-policy/
  1917. [*] https://fortressoffaith.com/radio-2/
  1918. [*] https://fortressoffaith.com/study/
  1919. [*] https://fortressoffaith.com/terms-conditions/
  1920. [*] https://fortressoffaith.com/when-muslims-play-the-race-card/
  1921. [*] https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https://fortressoffaith.com/
  1922. [*] https://fortressoffaith.com/wp-json/oembed/1.0/embed?url=https://fortressoffaith.com/&format=xml
  1923. [*] https://play.google.com/store/apps/details?id=com.mobincube.fortress_of_faith.sc_DWXU1A
  1924. [*] http://www.fortressoffaith.org/
  1925. [INFO] GOOGLE has 294,000 results (0.20 seconds) about http://fortressoffaith.com/
  1926. [INFO] Shodan detected the following opened ports on 72.52.244.17:
  1927. [*] 1
  1928. [*] 110
  1929. [*] 143
  1930. [*] 2082
  1931. [*] 2083
  1932. [*] 2086
  1933. [*] 2087
  1934. [*] 21
  1935. [*] 3306
  1936. [*] 4
  1937. [*] 443
  1938. [*] 53
  1939. [*] 587
  1940. [*] 80
  1941. [*] 993
  1942. [*] 995
  1943. [INFO] ------VirusTotal SECTION------
  1944. [INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
  1945. [INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
  1946. [INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
  1947. [INFO] ------Alexa Rank SECTION------
  1948. [INFO] Percent of Visitors Rank in Country:
  1949. [INFO] Percent of Search Traffic:
  1950. [INFO] Percent of Unique Visits:
  1951. [INFO] Total Sites Linking In:
  1952. [*] Total Sites
  1953. [INFO] Useful links related to fortressoffaith.com - 72.52.244.17:
  1954. [*] https://www.virustotal.com/pt/ip-address/72.52.244.17/information/
  1955. [*] https://www.hybrid-analysis.com/search?host=72.52.244.17
  1956. [*] https://www.shodan.io/host/72.52.244.17
  1957. [*] https://www.senderbase.org/lookup/?search_string=72.52.244.17
  1958. [*] https://www.alienvault.com/open-threat-exchange/ip/72.52.244.17
  1959. [*] http://pastebin.com/search?q=72.52.244.17
  1960. [*] http://urlquery.net/search.php?q=72.52.244.17
  1961. [*] http://www.alexa.com/siteinfo/fortressoffaith.com
  1962. [*] http://www.google.com/safebrowsing/diagnostic?site=fortressoffaith.com
  1963. [*] https://censys.io/ipv4/72.52.244.17
  1964. [*] https://www.abuseipdb.com/check/72.52.244.17
  1965. [*] https://urlscan.io/search/#72.52.244.17
  1966. [*] https://github.com/search?q=72.52.244.17&type=Code
  1967. [INFO] Useful links related to AS32244 - 72.52.128.0/17:
  1968. [*] http://www.google.com/safebrowsing/diagnostic?site=AS:32244
  1969. [*] https://www.senderbase.org/lookup/?search_string=72.52.128.0/17
  1970. [*] http://bgp.he.net/AS32244
  1971. [*] https://stat.ripe.net/AS32244
  1972. [INFO] Date: 22/10/19 | Time: 07:09:58
  1973. [INFO] Total time: 1 minute(s) and 56 second(s)
  1974. #######################################################################################################################################
  1975. [-] Target: https://fortressoffaith.com (72.52.244.17)
  1976. [I] Server: LiteSpeed
  1977. [I] X-Powered-By: PHP/7.0.33
  1978. [L] X-Frame-Options: Not Enforced
  1979. [I] Strict-Transport-Security: Not Enforced
  1980. [I] X-Content-Security-Policy: Not Enforced
  1981. [I] X-Content-Type-Options: Not Enforced
  1982. [L] Robots.txt Found: https://fortressoffaith.com/robots.txt
  1983. [I] CMS Detection: WordPress
  1984. [I] Wordpress Version: 5.2.4
  1985. [I] Wordpress Theme: generatepress
  1986. [-] WordPress usernames identified:
  1987. [M] Josh Rodriguez
  1988. [M] Pierre Coovert
  1989. [M] Tom Wallace
  1990. [M] admin
  1991. [M] josh
  1992. [M] pcoovert
  1993. [M] XML-RPC services are enabled
  1994. [M] Website vulnerable to XML-RPC Brute Force Vulnerability
  1995. [I] Autocomplete Off Not Found: https://fortressoffaith.com/wp-login.php
  1996. [-] Default WordPress Files:
  1997. [I] https://fortressoffaith.com/license.txt
  1998. [I] https://fortressoffaith.com/readme.html
  1999. [I] https://fortressoffaith.com/wp-content/themes/twentynineteen/readme.txt
  2000. [I] https://fortressoffaith.com/wp-includes/ID3/license.commercial.txt
  2001. [I] https://fortressoffaith.com/wp-includes/ID3/license.txt
  2002. [I] https://fortressoffaith.com/wp-includes/ID3/readme.txt
  2003. [I] https://fortressoffaith.com/wp-includes/images/crystal/license.txt
  2004. [I] https://fortressoffaith.com/wp-includes/js/plupload/license.txt
  2005. [I] https://fortressoffaith.com/wp-includes/js/swfupload/license.txt
  2006. [I] https://fortressoffaith.com/wp-includes/js/tinymce/license.txt
  2007. [-] Searching Wordpress Plugins ...
  2008. [I] advanced-uploader v3.2
  2009. [M] EDB-ID: 38867 "WordPress Plugin Advanced uploader 2.10 - Multiple Vulnerabilities"
  2010. [I] cuepro
  2011. [I] elementor v2.7.4
  2012. [I] elementor-pro
  2013. [I] feed
  2014. [M] EDB-ID: 38624 "WordPress Plugin WP Feed - 'nid' SQL Injection"
  2015. [I] feedburner-alternative-and-rss-redirect v2.3
  2016. [I] maticpress-client
  2017. [I] woocommerce v3.4.0
  2018. [M] EDB-ID: 43196 "WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal"
  2019. [I] Checking for Directory Listing Enabled ...
  2020. [L] https://fortressoffaith.com/wp-admin/css
  2021. [L] https://fortressoffaith.com/wp-admin/images
  2022. [L] https://fortressoffaith.com/wp-admin/includes
  2023. [L] https://fortressoffaith.com/wp-admin/js
  2024. [L] https://fortressoffaith.com/wp-admin/maint
  2025. [L] https://fortressoffaith.com/wp-includes
  2026. [L] https://fortressoffaith.com/wp-includes/ID3
  2027. [L] https://fortressoffaith.com/wp-includes/IXR
  2028. [L] https://fortressoffaith.com/wp-includes/Requests
  2029. [L] https://fortressoffaith.com/wp-includes/SimplePie
  2030. [L] https://fortressoffaith.com/wp-includes/Text
  2031. [L] https://fortressoffaith.com/wp-includes/blocks
  2032. [L] https://fortressoffaith.com/wp-includes/certificates
  2033. [L] https://fortressoffaith.com/wp-includes/css
  2034. [L] https://fortressoffaith.com/wp-includes/customize
  2035. [L] https://fortressoffaith.com/wp-includes/fonts
  2036. [L] https://fortressoffaith.com/wp-includes/images
  2037. [L] https://fortressoffaith.com/wp-includes/js
  2038. [L] https://fortressoffaith.com/wp-includes/pomo
  2039. [L] https://fortressoffaith.com/wp-includes/random_compat
  2040. [L] https://fortressoffaith.com/wp-includes/rest-api
  2041. [L] https://fortressoffaith.com/wp-includes/sodium_compat
  2042. [L] https://fortressoffaith.com/wp-includes/theme-compat
  2043. [L] https://fortressoffaith.com/wp-includes/widgets
  2044. [L] https://fortressoffaith.com/wp-content/plugins/advanced-uploader
  2045. [L] https://fortressoffaith.com/wp-content/plugins/cuepro
  2046. [L] https://fortressoffaith.com/wp-content/plugins/elementor
  2047. [L] https://fortressoffaith.com/wp-content/plugins/elementor-pro
  2048. [L] https://fortressoffaith.com/wp-content/plugins/feedburner-alternative-and-rss-redirect
  2049. [L] https://fortressoffaith.com/wp-content/plugins/woocommerce
  2050. [-] Date & Time: 22/10/2019 07:26:10
  2051. [-] Completed in: 0:21:46
  2052. #######################################################################################################################################
  2053. Anonymous JTSEC #OpDomesticTerrorism Full Recon #5
Advertisement
Add Comment
Please, Sign In to add comment