· 8 years ago · Sep 02, 2017, 02:20 PM
1#######################################################################################################################################
2
3Hostname www.primejb.com ISP Cloudflare Inc (AS13335)
4Continent Unknown Flag Unknown
5Country Unknown Country Code Unknown
6Region Unknown Local time Unknown
7City Unknown Latitude Unknown
8IP Address 104.24.112.108 Longitude Unknown
9#######################################################################################################################################
10primejb.com
11
12
13 Domain Name: PRIMEJB.COM
14 Registry Domain ID: 1651285449_DOMAIN_COM-VRSN
15 Registrar WHOIS Server: whois.PublicDomainRegistry.com
16 Registrar URL: http://www.publicdomainregistry.com
17 Updated Date: 2015-05-04T05:59:29Z
18 Creation Date: 2011-04-16T19:41:13Z
19 Registry Expiry Date: 2019-04-16T19:41:13Z
20 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
21 Registrar IANA ID: 303
22 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
23 Registrar Abuse Contact Phone: +1.2013775952
24 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
25 Name Server: BOB.NS.CLOUDFLARE.COM
26 Name Server: KARINA.NS.CLOUDFLARE.COM
27 DNSSEC: unsigned
28
29Domain Name: PRIMEJB.COM
30Registry Domain ID: 1651285449_DOMAIN_COM-VRSN
31Registrar WHOIS Server: whois.publicdomainregistry.com
32Registrar URL: www.publicdomainregistry.com
33Updated Date: 2015-05-04T05:59:29Z
34Creation Date: 2011-04-16T19:41:13Z
35Registrar Registration Expiration Date: 2019-04-16T19:41:13Z
36Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
37Registrar IANA ID: 303
38Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
39Registry Registrant ID: Not Available From Registry
40Registrant Name: Domain Admin
41Registrant Organization: Privacy Protect, LLC (PrivacyProtect.org)
42Registrant Street: 10 Corporate Drive
43Registrant City: Burlington
44Registrant State/Province: MA
45Registrant Postal Code: 01803
46Registrant Country: US
47Registrant Phone: +1.8022274003
48Registrant Phone Ext:
49Registrant Fax:
50Registrant Fax Ext:
51Registrant Email: contact@privacyprotect.org
52Registry Admin ID: Not Available From Registry
53Admin Name: Domain Admin
54Admin Organization: Privacy Protect, LLC (PrivacyProtect.org)
55Admin Street: 10 Corporate Drive
56Admin City: Burlington
57Admin State/Province: MA
58Admin Postal Code: 01803
59Admin Country: US
60Admin Phone: +1.8022274003
61Admin Phone Ext:
62Admin Fax:
63Admin Fax Ext:
64Admin Email: contact@privacyprotect.org
65Registry Tech ID: Not Available From Registry
66Tech Name: Domain Admin
67Tech Organization: Privacy Protect, LLC (PrivacyProtect.org)
68Tech Street: 10 Corporate Drive
69Tech City: Burlington
70Tech State/Province: MA
71Tech Postal Code: 01803
72Tech Country: US
73Tech Phone: +1.8022274003
74Tech Phone Ext:
75Tech Fax:
76Tech Fax Ext:
77Tech Email: contact@privacyprotect.org
78Name Server: bob.ns.cloudflare.com
79Name Server: karina.ns.cloudflare.com
80DNSSEC:Unsigned
81Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
82Registrar Abuse Contact Phone: +1.2013775952
83
84
85
86; <<>> DiG 9.10.3-P4-Debian <<>> primejb.com any
87;; global options: +cmd
88;; Got answer:
89;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23540
90;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
91
92;; OPT PSEUDOSECTION:
93; EDNS: version: 0, flags:; udp: 4096
94;; QUESTION SECTION:
95;primejb.com. IN ANY
96
97;; ANSWER SECTION:
98primejb.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
99primejb.com. 92863 IN NS bob.ns.cloudflare.com.
100primejb.com. 92863 IN NS karina.ns.cloudflare.com.
101
102;; Query time: 33 msec
103;; SERVER: 192.168.1.254#53(192.168.1.254)
104;; WHEN: Wed Aug 30 17:51:28 EDT 2017
105;; MSG SIZE rcvd: 151
106
107
108
109;; Connection to 192.168.1.254#53(192.168.1.254) for primejb.com failed: connection refused.
110Host primejb.com not found: 9(NOTAUTH)
111; Transfer failed.
112
113
114Please type the name of your network interface Example: eth0
115eth0
116
117Running:
118 traceroute -T -O info -i eth0 primejb.com
119traceroute to primejb.com (104.24.112.108), 30 hops max, 60 byte packets
120 1 gateway (192.168.1.254) 0.483 ms 0.729 ms 0.904 ms
121 2 10.135.18.1 (10.135.18.1) 7.061 ms 8.176 ms 8.388 ms
122 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 29.721 ms 29.775 ms 30.000 ms
123 4 de-cix-new-york.as13335.net (206.130.10.31) 30.739 ms 30.874 ms 30.972 ms
124 5 104.24.112.108 (104.24.112.108) <syn,ack> 31.427 ms 31.153 ms 31.540 ms
125
126
127Smartmatch is experimental at /usr/bin/dnsenum line 698.
128Smartmatch is experimental at /usr/bin/dnsenum line 698.
129dnsenum VERSION:1.2.4
130Warning: can't load Net::Whois::IP module, whois queries disabled.
131
132----- primejb.com -----
133
134
135Host's addresses:
136__________________
137
138primejb.com. 300 IN A 104.24.113.108
139primejb.com. 300 IN A 104.24.112.108
140
141
142Name Servers:
143______________
144
145karina.ns.cloudflare.com. 48182 IN A 173.245.58.178
146bob.ns.cloudflare.com. 86400 IN A 173.245.59.104
147
148
149Mail (MX) Servers:
150___________________
151
152aspmx3.googlemail.com. 293 IN A 209.85.203.27
153alt1.aspmx.l.google.com. 126 IN A 64.233.190.26
154aspmx.l.google.com. 114 IN A 74.125.22.26
155aspmx2.googlemail.com. 293 IN A 64.233.190.27
156alt2.aspmx.l.google.com. 293 IN A 209.85.203.27
157
158
159
160dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
161
162[+] searching (sub)domains for primejb.com using built-in wordlist
163[+] using maximum random delay of 10 millisecond(s) between requests
164
165www.primejb.com
166IP address #1: 104.24.112.108
167IP address #2: 104.24.113.108
168
169[+] 1 (sub)domains and 2 IP address(es) found
170[+] completion time: 113 second(s)
171
172
173Tracing to primejb.com[a] via 192.168.1.254, maximum of 3 retries
174192.168.1.254 (192.168.1.254) Got answer
175
176
177WhatWeb report for http://primejb.com
178Status : 301 Moved Permanently
179Title : ,301 Moved Permanently
180IP : 104.24.112.108
181Country : UNITED STATES, US
182
183Summary : HTML5, CloudFlare, RedirectLocation[https://www.primejb.com/], HttpOnly[__cfduid], UncommonHeaders[x-content-type-options,cf-ray], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
184
185Detected Plugins:
186[ CloudFlare ]
187 CloudFlare is a content delivery network. Its features
188 include DDoS protection and Web Application Firewall
189 functionality
190
191 Google Dorks: (1)
192 Website : https://www.cloudflare.com/
193
194[ Cookies ]
195 Display the names of cookies in the HTTP headers. The
196 values are not returned to save on space.
197
198 String : __cfduid
199
200[ HTML5 ]
201 HTML version 5, detected by the doctype declaration
202
203
204[ HTTPServer ]
205 HTTP server header string. This plugin also attempts to
206 identify the operating system from the server header.
207
208 String : cloudflare-nginx (from server string)
209
210[ HttpOnly ]
211 If the HttpOnly flag is included in the HTTP set-cookie
212 response header and the browser supports it then the cookie
213 cannot be accessed through client side script - More Info:
214 http://en.wikipedia.org/wiki/HTTP_cookie
215
216 String : __cfduid
217
218[ RedirectLocation ]
219 HTTP Server string location. used with http-status 301 and
220 302
221
222 String : https://www.primejb.com/ (from location)
223
224[ UncommonHeaders ]
225 Uncommon HTTP server headers. The blacklist includes all
226 the standard headers and many non standard but common ones.
227 Interesting but fairly common headers should have their own
228 plugins, eg. x-powered-by, server and x-aspnet-version.
229 Info about headers can be found at www.http-stats.com
230
231 String : x-content-type-options,cf-ray (from headers)
232
233HTTP Headers:
234 HTTP/1.1 301 Moved Permanently
235 Date: Wed, 30 Aug 2017 21:53:42 GMT
236 Content-Type: text/html
237 Transfer-Encoding: chunked
238 Connection: close
239 Set-Cookie: __cfduid=d1a6decc309efa3e199dd4746ca41ca271504130022; expires=Thu, 30-Aug-18 21:53:42 GMT; path=/; domain=.primejb.com; HttpOnly
240 Accept-Ranges: bytes
241 Location: https://www.primejb.com/
242 X-Content-Type-Options: nosniff
243 Server: cloudflare-nginx
244 CF-RAY: 396afc00f2df184c-EWR
245
246WhatWeb report for https://www.primejb.com/
247Status : 200 OK
248Title : PrimeJailbait | The best jailbait and teen photo gallery on the net.
249IP : 104.24.112.108
250Country : UNITED STATES, US
251
252Summary : HTML5, Google-Analytics[UA-9558603-1], CloudFlare, Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], Script[text/javascript], PHP[5.4.31], X-XSS-Protection[1; mode=block], HttpOnly[__cfduid], X-Powered-By[PHP/5.4.31], UncommonHeaders[x-content-type-options,cf-ray], X-Frame-Options[SAMEORIGIN], HTTPServer[cloudflare-nginx], Frame, Cookies[PHPSESSID,__cfduid], JQuery
253
254Detected Plugins:
255[ CloudFlare ]
256 CloudFlare is a content delivery network. Its features
257 include DDoS protection and Web Application Firewall
258 functionality
259
260 Google Dorks: (1)
261 Website : https://www.cloudflare.com/
262
263[ Cookies ]
264 Display the names of cookies in the HTTP headers. The
265 values are not returned to save on space.
266
267 String : __cfduid
268 String : PHPSESSID
269
270[ Frame ]
271 This plugin detects instances of frame and iframe HTML
272 elements.
273
274
275[ Google-Analytics ]
276 This plugin identifies the Google Analytics account.
277
278 Account : UA-9558603-1
279 Website : http://www.google.com/analytics/
280
281[ HTML5 ]
282 HTML version 5, detected by the doctype declaration
283
284
285[ HTTPServer ]
286 HTTP server header string. This plugin also attempts to
287 identify the operating system from the server header.
288
289 String : cloudflare-nginx (from server string)
290
291[ HttpOnly ]
292 If the HttpOnly flag is included in the HTTP set-cookie
293 response header and the browser supports it then the cookie
294 cannot be accessed through client side script - More Info:
295 http://en.wikipedia.org/wiki/HTTP_cookie
296
297 String : __cfduid
298
299[ JQuery ]
300 A fast, concise, JavaScript that simplifies how to traverse
301 HTML documents, handle events, perform animations, and add
302 AJAX.
303
304 Website : http://jquery.com/
305
306[ PHP ]
307 PHP is a widely-used general-purpose scripting language
308 that is especially suited for Web development and can be
309 embedded into HTML. This plugin identifies PHP errors,
310 modules and versions and extracts the local file path and
311 username if present.
312
313 Version : 5.4.31
314 Google Dorks: (2)
315 Website : http://www.php.net/
316
317[ Script ]
318 This plugin detects instances of script HTML elements and
319 returns the script language/type.
320
321 String : text/javascript
322
323[ Strict-Transport-Security ]
324 Strict-Transport-Security is an HTTP header that restricts
325 a web browser from accessing a website without the security
326 of the HTTPS protocol.
327
328 String : max-age=15552000; includeSubDomains; preload
329
330[ UncommonHeaders ]
331 Uncommon HTTP server headers. The blacklist includes all
332 the standard headers and many non standard but common ones.
333 Interesting but fairly common headers should have their own
334 plugins, eg. x-powered-by, server and x-aspnet-version.
335 Info about headers can be found at www.http-stats.com
336
337 String : x-content-type-options,cf-ray (from headers)
338
339[ X-Frame-Options ]
340 This plugin retrieves the X-Frame-Options value from the
341 HTTP header. - More Info:
342 http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
343 aspx
344
345 String : SAMEORIGIN
346
347[ X-Powered-By ]
348 X-Powered-By HTTP header
349
350 String : PHP/5.4.31 (from x-powered-by string)
351
352[ X-XSS-Protection ]
353 This plugin retrieves the X-XSS-Protection value from the
354 HTTP header. - More Info:
355 http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
356 aspx
357
358 String : 1; mode=block
359
360HTTP Headers:
361 HTTP/1.1 200 OK
362 Date: Wed, 30 Aug 2017 21:53:43 GMT
363 Content-Type: text/html; charset=UTF-8
364 Transfer-Encoding: chunked
365 Connection: close
366 Set-Cookie: __cfduid=d4429c8c4757c15a9d74c1c4023efcf571504130022; expires=Thu, 30-Aug-18 21:53:42 GMT; path=/; domain=.primejb.com; HttpOnly
367 X-Powered-By: PHP/5.4.31
368 Set-Cookie: PHPSESSID=ede51257345d3eaa5b9b908315620c9a; path=/
369 Expires: Thu, 19 Nov 1981 08:52:00 GMT
370 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
371 Pragma: no-cache
372 X-Frame-Options: SAMEORIGIN
373 X-XSS-Protection: 1; mode=block
374 X-Content-Type-Options: nosniff
375 Vary: Accept-Encoding
376 Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
377 Server: cloudflare-nginx
378 CF-RAY: 396afc02edb61870-EWR
379 Content-Encoding: gzip
380
381
382
383
384 ^ ^
385 _ __ _ ____ _ __ _ _ ____
386 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
387 | V V // o // _/ | V V // 0 // 0 // _/
388 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
389 <
390 ...'
391
392 WAFW00F - Web Application Firewall Detection Tool
393
394 By Sandro Gauci && Wendel G. Henrique
395
396Checking http://primejb.com
397The site http://primejb.com is behind a CloudFlare
398Number of requests: 1
399
400
401DNS Servers for primejb.com:
402 bob.ns.cloudflare.com
403 karina.ns.cloudflare.com
404
405Trying zone transfer first...
406 Testing bob.ns.cloudflare.com
407 Request timed out or transfer not allowed.
408 Testing karina.ns.cloudflare.com
409 Request timed out or transfer not allowed.
410
411Unsuccessful in zone transfer (it was worth a shot)
412Okay, trying the good old fashioned way... brute force
413
414Checking for wildcard DNS...
415Nope. Good.
416Now performing 2280 test(s)...
417104.24.112.108 cdn.primejb.com
418104.24.113.108 cdn.primejb.com
419104.24.113.108 www.primejb.com
420104.24.112.108 www.primejb.com
421
422Subnets found (may want to probe here using nmap or unicornscan):
423 104.24.112.0-255 : 2 hostnames found.
424 104.24.113.0-255 : 2 hostnames found.
425
426Done with Fierce scan: http://ha.ckers.org/fierce/
427Found 4 entries.
428
429Have a nice day.
430
431
432
433lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
434 Written by Stefan Behte (http://ge.mine.nu)
435 Proof-of-concept! Might give false positives.
436
437Checking for DNS-Loadbalancing: FOUND
438primejb.com has address 104.24.112.108
439primejb.com has address 104.24.113.108
440
441Checking for HTTP-Loadbalancing [Server]:
442 cloudflare-nginx
443 NOT FOUND
444
445Checking for HTTP-Loadbalancing [Date]: 21:58:06, 21:58:06, 21:58:06, 21:58:06, 21:58:07, 21:58:07, 21:58:07, 21:58:07, 21:58:08, 21:58:08, 21:58:08, 21:58:09, 21:58:09, 21:58:09, 21:58:09, 21:58:10, 21:58:10, 21:58:10, 21:58:10, 21:58:11, 21:58:11, 21:58:11, 21:58:11, 21:58:12, 21:58:12, 21:58:12, 21:58:12, 21:58:13, 21:58:13, 21:58:13, 21:58:14, 21:58:14, 21:58:14, 21:58:14, 21:58:15, 21:58:15, 21:58:15, 21:58:15, 21:58:16, 21:58:16, 21:58:16, 21:58:16, 21:58:17, 21:58:17, 21:58:17, 21:58:17, 21:58:18, 21:58:18, 21:58:18, 21:58:19, NOT FOUND
446
447Checking for HTTP-Loadbalancing [Diff]: FOUND
448< CF-RAY: 396b02c261176938-CDG
449> CF-RAY: 396b02c3e78468fc-CDG
450
451primejb.com does Load-balancing. Found via Methods: DNS HTTP[Diff]
452
453
454
455Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
456
457 ----------------------------------------------------------
458| Scan Information |
459 ----------------------------------------------------------
460
461Mode ..................... VRFY
462Worker Processes ......... 5
463Usernames file ........... users.txt
464Target count ............. 1
465Username count ........... 494
466Target TCP port .......... 25
467Query timeout ............ 5 secs
468Target domain ............
469
470######## Scan started at Wed Aug 30 17:58:11 2017 #########
471######## Scan completed at Wed Aug 30 18:06:26 2017 #########
4720 results.
473
474494 queries in 495 seconds (1.0 queries / sec)
475
476
477
478Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-30 18:06 EDT
479NSE: Loaded 146 scripts for scanning.
480NSE: Script Pre-scanning.
481Initiating NSE at 18:06
482Completed NSE at 18:06, 0.00s elapsed
483Initiating NSE at 18:06
484Completed NSE at 18:06, 0.00s elapsed
485Failed to resolve "primejb.com.txt".
486Initiating Parallel DNS resolution of 1 host. at 18:06
487Completed Parallel DNS resolution of 1 host. at 18:06, 11.12s elapsed
488Initiating SYN Stealth Scan at 18:06
489Scanning primejb.com (104.24.113.108) [100 ports]
490Discovered open port 443/tcp on 104.24.113.108
491Discovered open port 8080/tcp on 104.24.113.108
492Discovered open port 80/tcp on 104.24.113.108
493Discovered open port 8443/tcp on 104.24.113.108
494Completed SYN Stealth Scan at 18:06, 3.54s elapsed (100 total ports)
495Initiating Service scan at 18:06
496Scanning 4 services on primejb.com (104.24.113.108)
497Completed Service scan at 18:06, 13.61s elapsed (4 services on 1 host)
498Initiating OS detection (try #1) against primejb.com (104.24.113.108)
499adjust_timeouts2: packet supposedly had rtt of -161355 microseconds. Ignoring time.
500adjust_timeouts2: packet supposedly had rtt of -161355 microseconds. Ignoring time.
501Retrying OS detection (try #2) against primejb.com (104.24.113.108)
502Initiating Traceroute at 18:07
503Completed Traceroute at 18:07, 3.01s elapsed
504Initiating Parallel DNS resolution of 7 hosts. at 18:07
505Completed Parallel DNS resolution of 7 hosts. at 18:07, 5.73s elapsed
506NSE: Script scanning 104.24.113.108.
507Initiating NSE at 18:07
508Completed NSE at 18:07, 22.27s elapsed
509Initiating NSE at 18:07
510Completed NSE at 18:07, 0.00s elapsed
511Nmap scan report for primejb.com (104.24.113.108)
512Host is up (0.12s latency).
513Other addresses for primejb.com (not scanned): 104.24.112.108
514Not shown: 96 filtered ports
515PORT STATE SERVICE VERSION
51680/tcp open http Cloudflare nginx
517| http-methods:
518|_ Supported Methods: GET HEAD OPTIONS
519|_http-server-header: cloudflare-nginx
520|_http-title: Did not follow redirect to https://www.primejb.com/
521443/tcp open ssl/http Cloudflare nginx
522| http-methods:
523|_ Supported Methods: GET POST OPTIONS
524|_http-title: 400 The plain HTTP request was sent to HTTPS port
525| ssl-cert: Subject: commonName=sni156912.cloudflaressl.com
526| Subject Alternative Name: DNS:sni156912.cloudflaressl.com, DNS:*.aioporn.com, DNS:*.bribeleg.xyz, DNS:*.btunai.com, DNS:*.btunai.stream, DNS:*.celayasznicolette.tk, DNS:*.cutestist.com, DNS:*.demoit.today, DNS:*.eastchinesehackensack.com, DNS:*.edmonsonegblythe.info, DNS:*.fanarmk.cf, DNS:*.fousoft.com, DNS:*.gfunction.com, DNS:*.primejb.com, DNS:*.quantumit.net.nz, DNS:*.saneyan.com, DNS:*.seginus.io, DNS:*.soft222.com, DNS:*.tiger-workshop.info, DNS:*.travelkingdom.com.hk, DNS:*.viviendaselarca.com.ar, DNS:*.wifecook.com, DNS:*.yijiule.com, DNS:*.youtube33.com, DNS:aioporn.com, DNS:bribeleg.xyz, DNS:btunai.com, DNS:btunai.stream, DNS:celayasznicolette.tk, DNS:cutestist.com, DNS:demoit.today, DNS:eastchinesehackensack.com, DNS:edmonsonegblythe.info, DNS:fanarmk.cf, DNS:fousoft.com, DNS:gfunction.com, DNS:primejb.com, DNS:quantumit.net.nz, DNS:saneyan.com, DNS:seginus.io, DNS:soft222.com, DNS:tiger-workshop.info, DNS:travelkingdom.com.hk, DNS:viviendaselarca.com.ar, DNS:wifecook.com, DNS:yijiule.com, DNS:youtube33.com
527| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
528| Public Key type: ec
529| Public Key bits: 256
530| Signature Algorithm: ecdsa-with-SHA256
531| Not valid before: 2017-08-08T00:00:00
532| Not valid after: 2018-02-14T23:59:59
533| MD5: f2f5 153c 3add 95af 249a 8eec a6ee 1895
534|_SHA-1: 77fb 72f2 764c 61ff 801b 3e60 fb5c 8686 9225 3005
5358080/tcp open http Cloudflare nginx
536| http-methods:
537|_ Supported Methods: POST
538|_http-server-header: cloudflare-nginx
539|_http-title: primejb.com | 521: Web server is down
5408443/tcp open ssl/http Cloudflare nginx
541| ssl-cert: Subject: commonName=sni156912.cloudflaressl.com
542| Subject Alternative Name: DNS:sni156912.cloudflaressl.com, DNS:*.aioporn.com, DNS:*.bribeleg.xyz, DNS:*.btunai.com, DNS:*.btunai.stream, DNS:*.celayasznicolette.tk, DNS:*.cutestist.com, DNS:*.demoit.today, DNS:*.eastchinesehackensack.com, DNS:*.edmonsonegblythe.info, DNS:*.fanarmk.cf, DNS:*.fousoft.com, DNS:*.gfunction.com, DNS:*.primejb.com, DNS:*.quantumit.net.nz, DNS:*.saneyan.com, DNS:*.seginus.io, DNS:*.soft222.com, DNS:*.tiger-workshop.info, DNS:*.travelkingdom.com.hk, DNS:*.viviendaselarca.com.ar, DNS:*.wifecook.com, DNS:*.yijiule.com, DNS:*.youtube33.com, DNS:aioporn.com, DNS:bribeleg.xyz, DNS:btunai.com, DNS:btunai.stream, DNS:celayasznicolette.tk, DNS:cutestist.com, DNS:demoit.today, DNS:eastchinesehackensack.com, DNS:edmonsonegblythe.info, DNS:fanarmk.cf, DNS:fousoft.com, DNS:gfunction.com, DNS:primejb.com, DNS:quantumit.net.nz, DNS:saneyan.com, DNS:seginus.io, DNS:soft222.com, DNS:tiger-workshop.info, DNS:travelkingdom.com.hk, DNS:viviendaselarca.com.ar, DNS:wifecook.com, DNS:yijiule.com, DNS:youtube33.com
543| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
544| Public Key type: ec
545| Public Key bits: 256
546| Signature Algorithm: ecdsa-with-SHA256
547| Not valid before: 2017-08-08T00:00:00
548| Not valid after: 2018-02-14T23:59:59
549| MD5: f2f5 153c 3add 95af 249a 8eec a6ee 1895
550|_SHA-1: 77fb 72f2 764c 61ff 801b 3e60 fb5c 8686 9225 3005
551Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
552Device type: general purpose
553Running (JUST GUESSING): Linux 3.X|2.6.X (88%)
554OS CPE: cpe:/o:linux:linux_kernel:3.18 cpe:/o:linux:linux_kernel:2.6
555Aggressive OS guesses: Linux 3.18 (88%), Linux 2.6.18 - 2.6.22 (86%)
556No exact OS matches for host (test conditions non-ideal).
557Network Distance: 8 hops
558TCP Sequence Prediction: Difficulty=261 (Good luck!)
559IP ID Sequence Generation: All zeros
560
561TRACEROUTE (using port 443/tcp)
562HOP RTT ADDRESS
5631 111.56 ms 10.13.0.1
5642 120.38 ms 37.187.24.252
5653 115.90 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
5664 ...
5675 132.34 ms be99-1106.gsw-1-a9.fr.eu (91.121.215.177)
5686 217.70 ms be99-2.th2-1-a9.fr.eu (37.187.36.214)
5697 217.76 ms equinix-paris.cloudflare.com (195.42.144.143)
5708 129.67 ms 104.24.113.108
571
572NSE: Script Post-scanning.
573Initiating NSE at 18:07
574Completed NSE at 18:07, 0.00s elapsed
575Initiating NSE at 18:07
576Completed NSE at 18:07, 0.00s elapsed
577Read data files from: /usr/bin/../share/nmap
578OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
579Nmap done: 1 IP address (1 host up) scanned in 68.83 seconds
580 Raw packets sent: 314 (18.952KB) | Rcvd: 117 (9.373KB)
581
582
583Error: can not open nmap file: primejb.com.txt
584
585
586httprint v0.301 (beta) - web server fingerprinting tool
587(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
588http://net-square.com/httprint/
589httprint@net-square.com
590
591Finger Printing on http://primejb.com:80/
592Finger Printing Completed on http://primejb.com:80/
593--------------------------------------------------
594Host: primejb.com
595Fingerprinting Error: Host/URL not found...
596
597--------------------------------------------------
598
599
600
601
602 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
603 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
604 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
605 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
606 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
607
608 _/ User-Agent Tester ↵
609 _/ AKA: Purple Pimp ↵
610 _/ ChrisJohnRiley ↵
611 _/ blog.c22.cc ↵
612
613 [>] Performing initial request and confirming stability
614 [>] Using User-Agent string Mozilla/5.0
615
616 [ ] URL (ENTERED): http://primejb.com
617 [!] URL (FINAL): https://www.primejb.com/
618 [!] Response Code: 301 Moved Permanently
619 [ ] Date: Wed, 30 Aug 2017 22:07:50 GMT
620 [ ] Content-Type: text/html; charset=UTF-8
621 [ ] Transfer-Encoding: chunked
622 [ ] Connection: close
623 [ ] Set-Cookie: __cfduid=d89381447c66fb9d72f2f471f151ec67f1504130869; expires=Thu, 30-Aug-18 22:07:49 GMT;
624 path=/; domain=.primejb.com; HttpOnly
625 [ ] X-Powered-By: PHP/5.4.31
626 [ ] Set-Cookie: PHPSESSID=e4928ff7ec138a40bfadd4f83d422d7f; path=/
627 [ ] Expires: Thu, 19 Nov 1981 08:52:00 GMT
628 [ ] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
629 [ ] Pragma: no-cache
630 [ ] X-Frame-Options: SAMEORIGIN
631 [ ] X-XSS-Protection: 1; mode=block
632 [ ] X-Content-Type-Options: nosniff
633 [ ] Vary: Accept-Encoding
634 [ ] Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
635 [ ] Server: cloudflare-nginx
636 [ ] CF-RAY: 396b10aeff083c6b-CDG
637 [ ] Data (MD5): 30f3ec6864d1caabf578704ee2c2e9b2
638
639 [1] Pass
640 [2] Pass
641 [3] Pass
642
643 [>] URL appears stable. Beginning test
644
645 [>] Using DEFAULT User-Agent Strings
646
647 [>] Using Crazy User-Agent Strings
648 [>] Using Bot User-Agent Strings
649
650 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
651
652
653 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
654
655
656 [!] CF-RAY: 396b1124fcd41565-CDG
657
658
659 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
660
661
662 [!] CF-RAY: 396b1138ce861073-CDG
663
664
665 [>] User-Agent String : TrackBack/1.02
666
667
668 [!] CF-RAY: 396b114caaa014eb-CDG
669
670
671 [>] User-Agent String : wispr
672
673
674 [!] CF-RAY: 396b116088ac3c71-CDG
675
676
677 [>] User-Agent String : EMPTY USER-AGENT STRING!
678
679
680 [!] CF-RAY: 396b11745b5514eb-CDG
681
682
683 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
684
685
686 [!] CF-RAY: 396b11885b3c6938-CDG
687
688
689 [>] User-Agent String : Googlebot-Image/1.0
690
691
692 [!] CF-RAY: 396b119c7a156962-CDG
693
694
695 [>] User-Agent String : Mediapartners-Google
696
697
698 [!] CF-RAY: 396b11b05ac86902-CDG
699
700
701 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
702
703
704 [!] CF-RAY: 396b11c3e8aa1067-CDG
705
706
707 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
708
709
710 [!] CF-RAY: 396b11d7ca44103d-CDG
711
712
713 [>] User-Agent String : mmcrawler
714
715
716 [!] CF-RAY: 396b11eb8a1d3c41-CDG
717
718
719 [>] That's all folks... Fo' Shizzle!
720
721
722
723
724 Enter your target IP : 104.24.112.108
725i] Scanning Site: https://primejb.com
726
727
728
729B A S I C I N F O
730=======================================================================================================================
731
732
733
734
735[+] Site Title: PrimeJailbait | The best jailbait and teen photo gallery on the net.
736[+] IP address: 104.24.112.108
737[+] Web Server: cloudflare-nginx
738[+] CMS: Could Not Detect
739[+] Cloudflare: Detected
740[+] Robots File: Could NOT Find robots.txt!
741
742
743
744
745W H O I S L O O K U P
746===========================================================================================================================
747
748
749
750 Domain Name: PRIMEJB.COM
751 Registry Domain ID: 1651285449_DOMAIN_COM-VRSN
752 Registrar WHOIS Server: whois.PublicDomainRegistry.com
753 Registrar URL: http://www.publicdomainregistry.com
754 Updated Date: 2015-05-04T05:59:29Z
755 Creation Date: 2011-04-16T19:41:13Z
756 Registry Expiry Date: 2019-04-16T19:41:13Z
757 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
758 Registrar IANA ID: 303
759 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
760 Registrar Abuse Contact Phone: +1.2013775952
761 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
762 Name Server: BOB.NS.CLOUDFLARE.COM
763 Name Server: KARINA.NS.CLOUDFLARE.COM
764 DNSSEC: unsigned
765 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
766>>> Last update of whois database: 2017-08-30T21:53:43Z <<<
767
768For more information on Whois status codes, please visit https://icann.org/epp
769
770
771
772The Registry database contains ONLY .COM, .NET, .EDU domains and
773Registrars.
774
775
776
777
778G E O I P L O O K U P
779============================================================================================================================
780
781
782
783[i] IP Address: 104.24.113.108
784[i] Country: US
785[i] State: California
786[i] City: San Francisco
787[i] Latitude: 37.769699
788[i] Longitude: -122.393303
789
790
791
792
793H T T P H E A D E R S
794==========================================================================================================================
795
796
797
798
799[i] HTTP/1.1 301 Moved Permanently
800[i] Date: Wed, 30 Aug 2017 21:53:57 GMT
801[i] Content-Type: text/html
802[i] Connection: close
803[i] Set-Cookie: __cfduid=d158968f920f733bcb1178015f3346d9a1504130037; expires=Thu, 30-Aug-18 21:53:57 GMT; path=/; domain=.primejb.com; HttpOnly
804[i] Accept-Ranges: bytes
805[i] Location: https://www.primejb.com/
806[i] Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
807[i] X-Content-Type-Options: nosniff
808[i] Server: cloudflare-nginx
809[i] CF-RAY: 396afc5e19fb21d4-EWR
810[i] HTTP/1.1 200 OK
811[i] Date: Wed, 30 Aug 2017 21:53:57 GMT
812[i] Content-Type: text/html; charset=UTF-8
813[i] Connection: close
814[i] Set-Cookie: __cfduid=df0cc5c5513ebfe65530a99ebf58a58901504130037; expires=Thu, 30-Aug-18 21:53:57 GMT; path=/; domain=.primejb.com; HttpOnly
815[i] X-Powered-By: PHP/5.4.31
816[i] Set-Cookie: PHPSESSID=a9c8afedc1f8b416154745ba27a59e07; path=/
817[i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
818[i] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
819[i] Pragma: no-cache
820[i] X-Frame-Options: SAMEORIGIN
821[i] X-XSS-Protection: 1; mode=block
822[i] X-Content-Type-Options: nosniff
823[i] Vary: Accept-Encoding
824[i] Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
825[i] Server: cloudflare-nginx
826[i] CF-RAY: 396afc5f98c5214a-EWR
827
828
829
830
831D N S L O O K U P
832======================================================================================================================
833
834
835
836primejb.com. 298 IN A 104.24.112.108
837primejb.com. 298 IN A 104.24.113.108
838primejb.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
839
840
841
842
843S U B N E T C A L C U L A T I O N
844=======================================================================================================================================
845
846
847
848Address = 104.24.112.108
849Network = 104.24.112.108 / 32
850Netmask = 255.255.255.255
851Broadcast = not needed on Point-to-Point links
852Wildcard Mask = 0.0.0.0
853Hosts Bits = 0
854Max. Hosts = 1 (2^0 - 0)
855Host Range = { 104.24.112.108 - 104.24.112.108 }
856
857
858
859N M A P P O R T S C A N
860===============================================================================================================================
861
862
863
864
865Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-30 21:53 UTC
866Nmap scan report for primejb.com (104.24.112.108)
867Host is up (0.0080s latency).
868Other addresses for primejb.com (not scanned): 104.24.113.108
869PORT STATE SERVICE VERSION
87021/tcp filtered ftp
87122/tcp filtered ssh
87223/tcp filtered telnet
87325/tcp filtered smtp
87480/tcp open http Cloudflare nginx
875110/tcp filtered pop3
876143/tcp filtered imap
877443/tcp open ssl/http Cloudflare nginx
878445/tcp filtered microsoft-ds
8793389/tcp filtered ms-wbt-server
880
881Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
882Nmap done: 1 IP address (1 host up) scanned in 13.92 seconds
883
884
885
886S U B - D O M A I N F I N D E R
887=====================================================================================================================================
888
889
890
891
892[i] Total Subdomains Found : 4
893
894[+] Subdomain: primejb.com
895[-] IP: 104.24.112.108
896
897[+] Subdomain: primejb.com
898[-] IP: 104.24.113.108
899
900[+] Subdomain: cdn.primejb.com
901[-] IP: 104.24.112.108
902
903[+] Subdomain: cdn.primejb.com
904[-] IP: 104.24.113.108
905---------------------------------------------------------------------------
906+ Target IP: 104.24.113.108
907+ Target Hostname: primejb.com
908+ Target Port: 80
909+ Start Time: 2017-08-30 17:54:54 (GMT-4)
910---------------------------------------------------------------------------
911+ Server: cloudflare-nginx
912+ The anti-clickjacking X-Frame-Options header is not present.
913+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
914+ Uncommon header 'cf-ray' found, with contents: 396afdf6a60769c4-CDG
915+ Root page / redirects to: https://www.primejb.com/
916+ Uncommon header 'cf-cache-status' found, with contents: MISS
917+ Server banner has changed from 'cloudflare-nginx' to '-nginx' which may suggest a WAF, load balancer or proxy is in place
918+ 8257 requests: 0 error(s) and 4 item(s) reported on remote host
919+ End Time: 2017-08-30 18:35:23 (GMT-4) (2429 seconds)
920--------------------------------------------------------------------------
921#######################################################################################################################################
922Hostname www.allyourpix.com ISP Unknown
923Continent Unknown Flag
924US
925Country United States Country Code US
926Region Unknown Local time 30 Aug 2017 17:20 CDT
927City Unknown Latitude 37.751
928IP Address (IPv6) 2400:cb00:2048:1::681c:525 Longitude -97.822
929#######################################################################################################################################
930allyourpix.com
931
932
933 Domain Name: ALLYOURPIX.COM
934 Registry Domain ID: 1552873964_DOMAIN_COM-VRSN
935 Registrar WHOIS Server: whois.PublicDomainRegistry.com
936 Registrar URL: http://www.publicdomainregistry.com
937 Updated Date: 2017-04-09T15:53:26Z
938 Creation Date: 2009-04-20T16:41:47Z
939 Registry Expiry Date: 2018-04-20T16:41:47Z
940 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
941 Registrar IANA ID: 303
942 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
943 Registrar Abuse Contact Phone: +1.2013775952
944 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
945 Name Server: FRANK.NS.CLOUDFLARE.COM
946 Name Server: MIKI.NS.CLOUDFLARE.COM
947
948Domain Name: ALLYOURPIX.COM
949Registry Domain ID: 1552873964_DOMAIN_COM-VRSN
950Registrar WHOIS Server: whois.publicdomainregistry.com
951Registrar URL: www.publicdomainregistry.com
952Updated Date: 2017-04-09T15:53:24Z
953Creation Date: 2009-04-20T16:41:47Z
954Registrar Registration Expiration Date: 2018-04-20T16:41:47Z
955Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
956Registrar IANA ID: 303
957Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
958Registry Registrant ID: Not Available From Registry
959Registrant Name: Domain Admin
960Registrant Organization: Privacy Protect, LLC (PrivacyProtect.org)
961Registrant Street: 10 Corporate Drive
962Registrant City: Burlington
963Registrant State/Province: MA
964Registrant Postal Code: 01803
965Registrant Country: US
966Registrant Phone: +1.8022274003
967Registrant Phone Ext:
968Registrant Fax:
969Registrant Fax Ext:
970Registrant Email: contact@privacyprotect.org
971Registry Admin ID: Not Available From Registry
972Admin Name: Domain Admin
973Admin Organization: Privacy Protect, LLC (PrivacyProtect.org)
974Admin Street: 10 Corporate Drive
975Admin City: Burlington
976Admin State/Province: MA
977Admin Postal Code: 01803
978Admin Country: US
979Admin Phone: +1.8022274003
980Admin Phone Ext:
981Admin Fax:
982Admin Fax Ext:
983Admin Email: contact@privacyprotect.org
984Registry Tech ID: Not Available From Registry
985Tech Name: Domain Admin
986Tech Organization: Privacy Protect, LLC (PrivacyProtect.org)
987Tech Street: 10 Corporate Drive
988Tech City: Burlington
989Tech State/Province: MA
990Tech Postal Code: 01803
991Tech Country: US
992Tech Phone: +1.8022274003
993Tech Phone Ext:
994Tech Fax:
995Tech Fax Ext:
996Tech Email: contact@privacyprotect.org
997Name Server: frank.ns.cloudflare.com
998Name Server: miki.ns.cloudflare.com
999DNSSEC:Unsigned
1000Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
1001Registrar Abuse Contact Phone: +1.2013775952
1002
1003
1004
1005; <<>> DiG 9.10.3-P4-Debian <<>> allyourpix.com any
1006;; global options: +cmd
1007;; Got answer:
1008;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 35549
1009;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
1010
1011;; OPT PSEUDOSECTION:
1012; EDNS: version: 0, flags:; udp: 4096
1013;; QUESTION SECTION:
1014;allyourpix.com. IN ANY
1015
1016;; ANSWER SECTION:
1017allyourpix.com. 3789 IN RRSIG HINFO 13 2 3789 20170831232216 20170829212216 35273 allyourpix.com. GVDZCE3yg25YvF2xJISokQMbrWCuPiD0Kt/CC2Hj7a234OJgBu9JS+7r DQtKFoXLWRoFrcxCC1EDxQze8BazxA==
1018allyourpix.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
1019allyourpix.com. 920 IN NS miki.ns.cloudflare.com.
1020allyourpix.com. 920 IN NS frank.ns.cloudflare.com.
1021
1022;; Query time: 32 msec
1023;; SERVER: 192.168.1.254#53(192.168.1.254)
1024;; WHEN: Wed Aug 30 18:22:08 EDT 2017
1025;; MSG SIZE rcvd: 264
1026
1027
1028
1029;; Connection to 192.168.1.254#53(192.168.1.254) for allyourpix.com failed: connection refused.
1030Host allyourpix.com not found: 9(NOTAUTH)
1031; Transfer failed.
1032
1033
1034Please type the name of your network interface Example: eth0
1035eth0
1036
1037Running:
1038 traceroute -T -O info -i eth0 allyourpix.com
1039traceroute to allyourpix.com (104.28.4.37), 30 hops max, 60 byte packets
1040 1 gateway (192.168.1.254) 0.583 ms 0.837 ms 0.983 ms
1041 2 10.135.18.1 (10.135.18.1) 17.045 ms 18.446 ms 18.671 ms
1042 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 30.234 ms 30.284 ms 30.313 ms
1043 4 de-cix-new-york.as13335.net (206.130.10.31) 31.864 ms 31.996 ms 32.415 ms
1044 5 104.28.4.37 (104.28.4.37) <syn,ack> 32.159 ms 32.529 ms 32.643 ms
1045
1046
1047Smartmatch is experimental at /usr/bin/dnsenum line 698.
1048Smartmatch is experimental at /usr/bin/dnsenum line 698.
1049dnsenum VERSION:1.2.4
1050Warning: can't load Net::Whois::IP module, whois queries disabled.
1051
1052----- allyourpix.com -----
1053
1054
1055Host's addresses:
1056__________________
1057
1058allyourpix.com. 294 IN A 104.28.5.37
1059allyourpix.com. 294 IN A 104.28.4.37
1060
1061
1062Name Servers:
1063______________
1064
1065miki.ns.cloudflare.com. 39599 IN A 173.245.58.202
1066frank.ns.cloudflare.com. 86400 IN A 173.245.59.166
1067
1068
1069Mail (MX) Servers:
1070___________________
1071
1072dc-a5b1a663b0e8.allyourpix.com. 300 IN A 216.86.147.186
1073nd(s) between requests
1074
1075ftp.allyourpix.com
1076IPv6 address #1: 2400:cb00:2048:1::681c:425
1077IPv6 address #2: 2400:cb00:2048:1::681c:525
1078
1079ftp.allyourpix.com
1080IP address #1: 104.28.5.37
1081IP address #2: 104.28.4.37
1082
1083localhost.allyourpix.com
1084IP address #1: 127.0.0.1
1085[+] warning: domain might be vulnerable to "same site" scripting (http://snipurl.com/etbcv)
1086
1087m.allyourpix.com
1088IPv6 address #1: 2400:cb00:2048:1::681c:525
1089IPv6 address #2: 2400:cb00:2048:1::681c:425
1090
1091m.allyourpix.com
1092IP address #1: 104.28.4.37
1093IP address #2: 104.28.5.37
1094
1095mail.allyourpix.com
1096IPv6 address #1: 2400:cb00:2048:1::681c:425
1097IPv6 address #2: 2400:cb00:2048:1::681c:525
1098
1099mail.allyourpix.com
1100IP address #1: 104.28.4.37
1101IP address #2: 104.28.5.37
1102
1103mobile.allyourpix.com
1104IPv6 address #1: 2400:cb00:2048:1::681c:425
1105IPv6 address #2: 2400:cb00:2048:1::681c:525
1106
1107mobile.allyourpix.com
1108IP address #1: 104.28.5.37
1109IP address #2: 104.28.4.37
1110
1111webmail.allyourpix.com
1112IPv6 address #1: 2400:cb00:2048:1::681c:425
1113IPv6 address #2: 2400:cb00:2048:1::681c:525
1114
1115webmail.allyourpix.com
1116IP address #1: 104.28.4.37
1117IP address #2: 104.28.5.37
1118
1119www.allyourpix.com
1120IPv6 address #1: 2400:cb00:2048:1::681c:525
1121IPv6 address #2: 2400:cb00:2048:1::681c:425
1122
1123www.allyourpix.com
1124IP address #1: 104.28.4.37
1125IP address #2: 104.28.5.37
1126
1127[+] 13 (sub)domains and 25 IP address(es) found
1128[+] completion time: 116 second(s)
1129
1130
1131Tracing to allyourpix.com[a] via 192.168.1.254, maximum of 3 retries
1132192.168.1.254 (192.168.1.254) Got answer
1133
1134
1135WhatWeb report for http://allyourpix.com
1136Status : 301 Moved Permanently
1137Title : 301 Moved Permanently
1138IP : 104.28.4.37
1139Country : UNITED STATES, US
1140
1141Summary : CloudFlare, Script, RedirectLocation[http://www.allyourpix.com/], HttpOnly[__cfduid], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
1142
1143Detected Plugins:
1144[ CloudFlare ]
1145 CloudFlare is a content delivery network. Its features
1146 include DDoS protection and Web Application Firewall
1147 functionality
1148
1149 Google Dorks: (1)
1150 Website : https://www.cloudflare.com/
1151
1152[ Cookies ]
1153 Display the names of cookies in the HTTP headers. The
1154 values are not returned to save on space.
1155
1156 String : __cfduid
1157
1158[ HTTPServer ]
1159 HTTP server header string. This plugin also attempts to
1160 identify the operating system from the server header.
1161
1162 String : cloudflare-nginx (from server string)
1163
1164[ HttpOnly ]
1165 If the HttpOnly flag is included in the HTTP set-cookie
1166 response header and the browser supports it then the cookie
1167 cannot be accessed through client side script - More Info:
1168 http://en.wikipedia.org/wiki/HTTP_cookie
1169
1170 String : __cfduid
1171
1172[ RedirectLocation ]
1173 HTTP Server string location. used with http-status 301 and
1174 302
1175
1176 String : http://www.allyourpix.com/ (from location)
1177
1178[ Script ]
1179 This plugin detects instances of script HTML elements and
1180 returns the script language/type.
1181
1182
1183[ UncommonHeaders ]
1184 Uncommon HTTP server headers. The blacklist includes all
1185 the standard headers and many non standard but common ones.
1186 Interesting but fairly common headers should have their own
1187 plugins, eg. x-powered-by, server and x-aspnet-version.
1188 Info about headers can be found at www.http-stats.com
1189
1190 String : cf-ray (from headers)
1191
1192HTTP Headers:
1193 HTTP/1.1 301 Moved Permanently
1194 Date: Wed, 30 Aug 2017 22:24:41 GMT
1195 Content-Type: text/html; charset=iso-8859-1
1196 Transfer-Encoding: chunked
1197 Connection: close
1198 Set-Cookie: __cfduid=d2c558bbe3328c52e3766b7aafbe1394a1504131881; expires=Thu, 30-Aug-18 22:24:41 GMT; path=/; domain=.allyourpix.com; HttpOnly
1199 Location: http://www.allyourpix.com/
1200 Server: cloudflare-nginx
1201 CF-RAY: 396b2963b0c66920-CDG
1202
1203WhatWeb report for http://www.allyourpix.com/
1204Status : 301 Moved Permanently
1205Title : <None>
1206IP : 104.28.4.37
1207Country : UNITED STATES, US
1208
1209Summary : CloudFlare, RedirectLocation[https://www.allyourpix.com/], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx]
1210
1211Detected Plugins:
1212[ CloudFlare ]
1213 CloudFlare is a content delivery network. Its features
1214 include DDoS protection and Web Application Firewall
1215 functionality
1216
1217 Google Dorks: (1)
1218 Website : https://www.cloudflare.com/
1219
1220[ HTTPServer ]
1221 HTTP server header string. This plugin also attempts to
1222 identify the operating system from the server header.
1223
1224 String : cloudflare-nginx (from server string)
1225
1226[ RedirectLocation ]
1227 HTTP Server string location. used with http-status 301 and
1228 302
1229
1230 String : https://www.allyourpix.com/ (from location)
1231
1232[ UncommonHeaders ]
1233 Uncommon HTTP server headers. The blacklist includes all
1234 the standard headers and many non standard but common ones.
1235 Interesting but fairly common headers should have their own
1236 plugins, eg. x-powered-by, server and x-aspnet-version.
1237 Info about headers can be found at www.http-stats.com
1238
1239 String : cf-ray (from headers)
1240
1241HTTP Headers:
1242 HTTP/1.1 301 Moved Permanently
1243 Date: Wed, 30 Aug 2017 22:24:42 GMT
1244 Transfer-Encoding: chunked
1245 Connection: close
1246 Cache-Control: max-age=3600
1247 Expires: Wed, 30 Aug 2017 23:24:42 GMT
1248 Location: https://www.allyourpix.com/
1249 Server: cloudflare-nginx
1250 CF-RAY: 396b2967168e1055-CDG
1251
1252WhatWeb report for https://www.allyourpix.com/
1253Status : 302 Found
1254Title : <None>
1255IP : 104.28.4.37
1256Country : UNITED STATES, US
1257
1258Summary : CloudFlare, RedirectLocation[http://www.allyourpix.com/index.php], HttpOnly[__cfduid], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
1259
1260Detected Plugins:
1261[ CloudFlare ]
1262 CloudFlare is a content delivery network. Its features
1263 include DDoS protection and Web Application Firewall
1264 functionality
1265
1266 Google Dorks: (1)
1267 Website : https://www.cloudflare.com/
1268
1269[ Cookies ]
1270 Display the names of cookies in the HTTP headers. The
1271 values are not returned to save on space.
1272
1273 String : __cfduid
1274
1275[ HTTPServer ]
1276 HTTP server header string. This plugin also attempts to
1277 identify the operating system from the server header.
1278
1279 String : cloudflare-nginx (from server string)
1280
1281[ HttpOnly ]
1282 If the HttpOnly flag is included in the HTTP set-cookie
1283 response header and the browser supports it then the cookie
1284 cannot be accessed through client side script - More Info:
1285 http://en.wikipedia.org/wiki/HTTP_cookie
1286
1287 String : __cfduid
1288
1289[ RedirectLocation ]
1290 HTTP Server string location. used with http-status 301 and
1291 302
1292
1293 String : http://www.allyourpix.com/index.php (from location)
1294
1295[ UncommonHeaders ]
1296 Uncommon HTTP server headers. The blacklist includes all
1297 the standard headers and many non standard but common ones.
1298 Interesting but fairly common headers should have their own
1299 plugins, eg. x-powered-by, server and x-aspnet-version.
1300 Info about headers can be found at www.http-stats.com
1301
1302 String : cf-ray (from headers)
1303
1304HTTP Headers:
1305 HTTP/1.1 302 Moved Temporarily
1306 Date: Wed, 30 Aug 2017 22:24:43 GMT
1307 Content-Type: text/html
1308 Transfer-Encoding: chunked
1309 Connection: close
1310 Set-Cookie: __cfduid=dd17454a41c0519e1f414c1c13bb394e61504131882; expires=Thu, 30-Aug-18 22:24:42 GMT; path=/; domain=.allyourpix.com; HttpOnly
1311 Location: http://www.allyourpix.com/index.php
1312 Server: cloudflare-nginx
1313 CF-RAY: 396b296b4873150f-CDG
1314
1315WhatWeb report for http://www.allyourpix.com/index.php
1316Status : 301 Moved Permanently
1317Title : <None>
1318IP : 104.28.4.37
1319Country : UNITED STATES, US
1320
1321Summary : CloudFlare, RedirectLocation[https://www.allyourpix.com/index.php], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx]
1322
1323Detected Plugins:
1324[ CloudFlare ]
1325 CloudFlare is a content delivery network. Its features
1326 include DDoS protection and Web Application Firewall
1327 functionality
1328
1329 Google Dorks: (1)
1330 Website : https://www.cloudflare.com/
1331
1332[ HTTPServer ]
1333 HTTP server header string. This plugin also attempts to
1334 identify the operating system from the server header.
1335
1336 String : cloudflare-nginx (from server string)
1337
1338[ RedirectLocation ]
1339 HTTP Server string location. used with http-status 301 and
1340 302
1341
1342 String : https://www.allyourpix.com/index.php (from location)
1343
1344[ UncommonHeaders ]
1345 Uncommon HTTP server headers. The blacklist includes all
1346 the standard headers and many non standard but common ones.
1347 Interesting but fairly common headers should have their own
1348 plugins, eg. x-powered-by, server and x-aspnet-version.
1349 Info about headers can be found at www.http-stats.com
1350
1351 String : cf-ray (from headers)
1352
1353HTTP Headers:
1354 HTTP/1.1 301 Moved Permanently
1355 Date: Wed, 30 Aug 2017 22:24:43 GMT
1356 Transfer-Encoding: chunked
1357 Connection: close
1358 Cache-Control: max-age=3600
1359 Expires: Wed, 30 Aug 2017 23:24:43 GMT
1360 Location: https://www.allyourpix.com/index.php
1361 Server: cloudflare-nginx
1362 CF-RAY: 396b296eb3323c89-CDG
1363
1364WhatWeb report for https://www.allyourpix.com/index.php
1365Status : 200 OK
1366Title : AllYourPix.com Adult Video And Picture Gallery - FREE HOME MADE MOBILE AND TUBE PORN VIDEOS.
1367IP : 104.28.4.37
1368Country : UNITED STATES, US
1369
1370Summary : CloudFlare, Script[text/javascript], HttpOnly[__cfduid], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Frame, Cookies[CSS,LANG,PHPSESSID,__cfduid], JQuery[1.3.2]
1371
1372Detected Plugins:
1373[ CloudFlare ]
1374 CloudFlare is a content delivery network. Its features
1375 include DDoS protection and Web Application Firewall
1376 functionality
1377
1378 Google Dorks: (1)
1379 Website : https://www.cloudflare.com/
1380
1381[ Cookies ]
1382 Display the names of cookies in the HTTP headers. The
1383 values are not returned to save on space.
1384
1385 String : __cfduid
1386 String : PHPSESSID
1387 String : CSS
1388 String : LANG
1389
1390[ Frame ]
1391 This plugin detects instances of frame and iframe HTML
1392 elements.
1393
1394
1395[ HTTPServer ]
1396 HTTP server header string. This plugin also attempts to
1397 identify the operating system from the server header.
1398
1399 String : cloudflare-nginx (from server string)
1400
1401[ HttpOnly ]
1402 If the HttpOnly flag is included in the HTTP set-cookie
1403 response header and the browser supports it then the cookie
1404 cannot be accessed through client side script - More Info:
1405 http://en.wikipedia.org/wiki/HTTP_cookie
1406
1407 String : __cfduid
1408
1409[ JQuery ]
1410 A fast, concise, JavaScript that simplifies how to traverse
1411 HTML documents, handle events, perform animations, and add
1412 AJAX.
1413
1414 Version : 1.3.2
1415 Website : http://jquery.com/
1416
1417[ Script ]
1418 This plugin detects instances of script HTML elements and
1419 returns the script language/type.
1420
1421 String : text/javascript
1422
1423[ UncommonHeaders ]
1424 Uncommon HTTP server headers. The blacklist includes all
1425 the standard headers and many non standard but common ones.
1426 Interesting but fairly common headers should have their own
1427 plugins, eg. x-powered-by, server and x-aspnet-version.
1428 Info about headers can be found at www.http-stats.com
1429
1430 String : cf-ray (from headers)
1431
1432HTTP Headers:
1433 HTTP/1.1 200 OK
1434 Date: Wed, 30 Aug 2017 22:24:44 GMT
1435 Content-Type: text/html
1436 Transfer-Encoding: chunked
1437 Connection: close
1438 Set-Cookie: __cfduid=d07b5b186e87838de2938bbe434c998ba1504131883; expires=Thu, 30-Aug-18 22:24:43 GMT; path=/; domain=.allyourpix.com; HttpOnly
1439 Expires: Thu, 19 Nov 1981 08:52:00 GMT
1440 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
1441 Pragma: no-cache
1442 Set-Cookie: PHPSESSID=a138f135258460d2d59bd4ea0da5f9a4; path=/
1443 Set-Cookie: CSS=black; expires=Fri, 29-Sep-2017 22:26:08 GMT
1444 Set-Cookie: LANG=en; expires=Fri, 29-Sep-2017 22:26:08 GMT
1445 Server: cloudflare-nginx
1446 CF-RAY: 396b2972ecbe150f-CDG
1447 Content-Encoding: gzip
1448
1449
1450
1451 ^ ^
1452 _ __ _ ____ _ __ _ _ ____
1453 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
1454 | V V // o // _/ | V V // 0 // 0 // _/
1455 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
1456 <
1457 ...'
1458
1459 WAFW00F - Web Application Firewall Detection Tool
1460
1461 By Sandro Gauci && Wendel G. Henrique
1462
1463Checking http://allyourpix.com
1464The site http://allyourpix.com is behind a CloudFlare
1465Number of requests: 1
1466
1467
1468DNS Servers for allyourpix.com:
1469 miki.ns.cloudflare.com
1470 frank.ns.cloudflare.com
1471
1472Trying zone transfer first...
1473 Testing miki.ns.cloudflare.com
1474 Request timed out or transfer not allowed.
1475 Testing frank.ns.cloudflare.com
1476 Request timed out or transfer not allowed.
1477
1478Unsuccessful in zone transfer (it was worth a shot)
1479Okay, trying the good old fashioned way... brute force
1480
1481Checking for wildcard DNS...
1482Nope. Good.
1483Now performing 2280 test(s)...
1484104.28.4.37 ftp.allyourpix.com
1485104.28.5.37 ftp.allyourpix.com
1486127.0.0.1 localhost.allyourpix.com
1487104.28.4.37 m.allyourpix.com
1488104.28.5.37 m.allyourpix.com
1489104.28.4.37 mail.allyourpix.com
1490104.28.5.37 mail.allyourpix.com
1491104.28.4.37 mobile.allyourpix.com
1492104.28.5.37 mobile.allyourpix.com
1493104.28.4.37 video.allyourpix.com
1494104.28.5.37 video.allyourpix.com
1495104.28.4.37 webmail.allyourpix.com
1496104.28.5.37 webmail.allyourpix.com
1497104.28.5.37 www.allyourpix.com
1498104.28.4.37 www.allyourpix.com
1499
1500Subnets found (may want to probe here using nmap or unicornscan):
1501 104.28.4.0-255 : 7 hostnames found.
1502 104.28.5.0-255 : 7 hostnames found.
1503 127.0.0.0-255 : 1 hostnames found.
1504
1505Done with Fierce scan: http://ha.ckers.org/fierce/
1506Found 15 entries.
1507
1508Have a nice day.
1509
1510
1511
1512lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
1513 Written by Stefan Behte (http://ge.mine.nu)
1514 Proof-of-concept! Might give false positives.
1515
1516Checking for DNS-Loadbalancing: FOUND
1517allyourpix.com has address 104.28.5.37
1518allyourpix.com has address 104.28.4.37
1519
1520Checking for HTTP-Loadbalancing [Server]:
1521 cloudflare-nginx
1522 NOT FOUND
1523
1524Checking for HTTP-Loadbalancing [Date]: 22:30:59, 22:31:00, 22:31:00, 22:31:00, 22:31:00, 22:31:01, 22:31:01, 22:31:01, 22:31:01, 22:31:02, 22:31:02, 22:31:02, 22:31:02, 22:31:03, 22:31:03, 22:31:03, 22:31:03, 22:31:04, 22:31:04, 22:31:04, 22:31:04, 22:31:05, 22:31:05, 22:31:05, 22:31:05, 22:31:06, 22:31:06, 22:31:06, 22:31:06, 22:31:07, 22:31:07, 22:31:07, 22:31:08, 22:31:08, 22:31:08, 22:31:08, 22:31:09, 22:31:09, 22:31:09, 22:31:09, 22:31:10, 22:31:10, 22:31:10, 22:31:10, 22:31:11, 22:31:11, 22:31:11, 22:31:11, 22:31:12, 22:31:12, NOT FOUND
1525
1526Checking for HTTP-Loadbalancing [Diff]: FOUND
1527< CF-RAY: 396b32eff397691a-CDG
1528> CF-RAY: 396b32f2370e3c29-CDG
1529
1530allyourpix.com does Load-balancing. Found via Methods: DNS HTTP[Diff]
1531
1532
1533
1534Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
1535
1536 ----------------------------------------------------------
1537| Scan Information |
1538 ----------------------------------------------------------
1539
1540Mode ..................... VRFY
1541Worker Processes ......... 5
1542Usernames file ........... users.txt
1543Target count ............. 1
1544Username count ........... 494
1545Target TCP port .......... 25
1546Query timeout ............ 5 secs
1547Target domain ............
1548
1549######## Scan started at Wed Aug 30 18:31:04 2017 #########
1550######## Scan completed at Wed Aug 30 18:39:19 2017 #########
15510 results.
1552
1553494 queries in 495 seconds (1.0 queries / sec)
1554
1555
1556
1557Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-30 18:39 EDT
1558NSE: Loaded 146 scripts for scanning.
1559NSE: Script Pre-scanning.
1560Initiating NSE at 18:39
1561Completed NSE at 18:39, 0.00s elapsed
1562Initiating NSE at 18:39
1563Completed NSE at 18:39, 0.00s elapsed
1564Failed to resolve "allyourpix.com.txt".
1565Initiating Parallel DNS resolution of 1 host. at 18:39
1566Completed Parallel DNS resolution of 1 host. at 18:39, 11.12s elapsed
1567Initiating SYN Stealth Scan at 18:39
1568Scanning allyourpix.com (104.28.4.37) [100 ports]
1569Discovered open port 8080/tcp on 104.28.4.37
1570Discovered open port 80/tcp on 104.28.4.37
1571Discovered open port 443/tcp on 104.28.4.37
1572Discovered open port 8443/tcp on 104.28.4.37
1573Completed SYN Stealth Scan at 18:39, 3.41s elapsed (100 total ports)
1574Initiating Service scan at 18:39
1575Scanning 4 services on allyourpix.com (104.28.4.37)
1576Completed Service scan at 18:39, 13.41s elapsed (4 services on 1 host)
1577Initiating OS detection (try #1) against allyourpix.com (104.28.4.37)
1578adjust_timeouts2: packet supposedly had rtt of -161432 microseconds. Ignoring time.
1579adjust_timeouts2: packet supposedly had rtt of -161432 microseconds. Ignoring time.
1580Retrying OS detection (try #2) against allyourpix.com (104.28.4.37)
1581Initiating Traceroute at 18:39
1582Completed Traceroute at 18:39, 3.01s elapsed
1583Initiating Parallel DNS resolution of 7 hosts. at 18:39
1584Completed Parallel DNS resolution of 7 hosts. at 18:40, 5.72s elapsed
1585NSE: Script scanning 104.28.4.37.
1586Initiating NSE at 18:40
1587Completed NSE at 18:40, 23.71s elapsed
1588Initiating NSE at 18:40
1589Completed NSE at 18:40, 0.00s elapsed
1590Nmap scan report for allyourpix.com (104.28.4.37)
1591Host is up (0.11s latency).
1592Other addresses for allyourpix.com (not scanned): 2400:cb00:2048:1::681c:425 2400:cb00:2048:1::681c:525 104.28.5.37
1593Not shown: 96 filtered ports
1594PORT STATE SERVICE VERSION
159580/tcp open http Cloudflare nginx
1596| http-methods:
1597|_ Supported Methods: GET HEAD POST OPTIONS
1598|_http-server-header: cloudflare-nginx
1599|_http-title: Did not follow redirect to http://www.allyourpix.com/
1600443/tcp open ssl/http Cloudflare nginx
1601| http-methods:
1602|_ Supported Methods: POST
1603|_http-title: 400 The plain HTTP request was sent to HTTPS port
1604| ssl-cert: Subject: commonName=sni74562.cloudflaressl.com
1605| Subject Alternative Name: DNS:sni74562.cloudflaressl.com, DNS:*.allyourpix.com, DNS:*.csgonecro.net, DNS:*.escuelabiblicamundial.net, DNS:*.esperanzavivaebm.org, DNS:*.freemetaltake.com, DNS:*.grantgu.us, DNS:*.hilarykillam.ca, DNS:*.kfktuhvpmtbvacp.ga, DNS:*.kouhari.loan, DNS:*.limitedquantitychristmastoys.com, DNS:*.mdsdnr.ru, DNS:*.nkchaussures.eu, DNS:*.nmaxshop.com, DNS:*.perfectrolex.co.uk, DNS:*.perfectwatch2u.co.uk, DNS:*.quirs1974.tk, DNS:*.restaurantcoverings.com, DNS:*.sell-gtbbax.cf, DNS:*.sharejesusnow.net, DNS:*.theasdanceacademy.com, DNS:*.yeezymall.co.uk, DNS:*.youtubetoon.com, DNS:allyourpix.com, DNS:csgonecro.net, DNS:escuelabiblicamundial.net, DNS:esperanzavivaebm.org, DNS:freemetaltake.com, DNS:grantgu.us, DNS:hilarykillam.ca, DNS:kfktuhvpmtbvacp.ga, DNS:kouhari.loan, DNS:limitedquantitychristmastoys.com, DNS:mdsdnr.ru, DNS:nkchaussures.eu, DNS:nmaxshop.com, DNS:perfectrolex.co.uk, DNS:perfectwatch2u.co.uk, DNS:quirs1974.tk, DNS:restaurantcoverings.com, DNS:sell-gtbbax.cf, DNS:sharejesusnow.net, DNS:theasdanceacademy.com, DNS:yeezymall.co.uk, DNS:youtubetoon.com
1606| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
1607| Public Key type: ec
1608| Public Key bits: 256
1609| Signature Algorithm: ecdsa-with-SHA256
1610| Not valid before: 2017-08-11T00:00:00
1611| Not valid after: 2018-02-17T23:59:59
1612| MD5: c0a9 1b23 62ac 03bb 1ad1 5ae3 06d3 f78d
1613|_SHA-1: 91a8 a91d 94ac e361 4105 b7bf 134a 53ab 995e b182
16148080/tcp open http Cloudflare nginx
1615| http-methods:
1616|_ Supported Methods: GET
1617|_http-title: allyourpix.com | 521: Web server is down
16188443/tcp open ssl/http Cloudflare nginx
1619| http-methods:
1620|_ Supported Methods: GET POST OPTIONS
1621| ssl-cert: Subject: commonName=sni74562.cloudflaressl.com
1622| Subject Alternative Name: DNS:sni74562.cloudflaressl.com, DNS:*.allyourpix.com, DNS:*.csgonecro.net, DNS:*.escuelabiblicamundial.net, DNS:*.esperanzavivaebm.org, DNS:*.freemetaltake.com, DNS:*.grantgu.us, DNS:*.hilarykillam.ca, DNS:*.kfktuhvpmtbvacp.ga, DNS:*.kouhari.loan, DNS:*.limitedquantitychristmastoys.com, DNS:*.mdsdnr.ru, DNS:*.nkchaussures.eu, DNS:*.nmaxshop.com, DNS:*.perfectrolex.co.uk, DNS:*.perfectwatch2u.co.uk, DNS:*.quirs1974.tk, DNS:*.restaurantcoverings.com, DNS:*.sell-gtbbax.cf, DNS:*.sharejesusnow.net, DNS:*.theasdanceacademy.com, DNS:*.yeezymall.co.uk, DNS:*.youtubetoon.com, DNS:allyourpix.com, DNS:csgonecro.net, DNS:escuelabiblicamundial.net, DNS:esperanzavivaebm.org, DNS:freemetaltake.com, DNS:grantgu.us, DNS:hilarykillam.ca, DNS:kfktuhvpmtbvacp.ga, DNS:kouhari.loan, DNS:limitedquantitychristmastoys.com, DNS:mdsdnr.ru, DNS:nkchaussures.eu, DNS:nmaxshop.com, DNS:perfectrolex.co.uk, DNS:perfectwatch2u.co.uk, DNS:quirs1974.tk, DNS:restaurantcoverings.com, DNS:sell-gtbbax.cf, DNS:sharejesusnow.net, DNS:theasdanceacademy.com, DNS:yeezymall.co.uk, DNS:youtubetoon.com
1623| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
1624| Public Key type: ec
1625| Public Key bits: 256
1626| Signature Algorithm: ecdsa-with-SHA256
1627| Not valid before: 2017-08-11T00:00:00
1628| Not valid after: 2018-02-17T23:59:59
1629| MD5: c0a9 1b23 62ac 03bb 1ad1 5ae3 06d3 f78d
1630|_SHA-1: 91a8 a91d 94ac e361 4105 b7bf 134a 53ab 995e b182
1631Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
1632Device type: general purpose
1633Running (JUST GUESSING): Linux 3.X|2.6.X (88%)
1634OS CPE: cpe:/o:linux:linux_kernel:3.18 cpe:/o:linux:linux_kernel:2.6
1635Aggressive OS guesses: Linux 3.18 (88%), Linux 2.6.18 - 2.6.22 (86%)
1636No exact OS matches for host (test conditions non-ideal).
1637Network Distance: 8 hops
1638TCP Sequence Prediction: Difficulty=263 (Good luck!)
1639IP ID Sequence Generation: All zeros
1640
1641TRACEROUTE (using port 8080/tcp)
1642HOP RTT ADDRESS
16431 110.08 ms 10.13.0.1
16442 111.75 ms 37.187.24.252
16453 110.14 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
16464 ...
16475 114.78 ms be99-1106.gsw-1-a9.fr.eu (91.121.215.177)
16486 219.68 ms be99-2.th2-1-a9.fr.eu (37.187.36.214)
16497 219.75 ms cloudflare.par.franceix.net (37.49.237.49)
16508 115.15 ms 104.28.4.37
1651
1652NSE: Script Post-scanning.
1653Initiating NSE at 18:40
1654Completed NSE at 18:40, 0.00s elapsed
1655Initiating NSE at 18:40
1656Completed NSE at 18:40, 0.00s elapsed
1657Read data files from: /usr/bin/../share/nmap
1658OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1659Nmap done: 1 IP address (1 host up) scanned in 68.70 seconds
1660 Raw packets sent: 313 (18.908KB) | Rcvd: 62 (4.808KB)
1661
1662
1663Error: can not open nmap file: allyourpix.com.txt
1664
1665
1666httprint v0.301 (beta) - web server fingerprinting tool
1667(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
1668http://net-square.com/httprint/
1669httprint@net-square.com
1670
1671Finger Printing on http://allyourpix.com:80/
1672Finger Printing Completed on http://allyourpix.com:80/
1673--------------------------------------------------
1674Host: allyourpix.com
1675Fingerprinting Error: Host/URL not found...
1676
1677--------------------------------------------------
1678
1679
1680
1681
1682 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
1683 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
1684 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
1685 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
1686 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
1687
1688 _/ User-Agent Tester ↵
1689 _/ AKA: Purple Pimp ↵
1690 _/ ChrisJohnRiley ↵
1691 _/ blog.c22.cc ↵
1692
1693 [>] Performing initial request and confirming stability
1694 [>] Using User-Agent string Mozilla/5.0
1695
1696 [ ] URL (ENTERED): http://allyourpix.com
1697 [!] URL (FINAL): https://www.allyourpix.com/index.php
1698 [!] Response Code: 301 Moved Permanently
1699 [ ] Date: Wed, 30 Aug 2017 22:40:42 GMT
1700 [ ] Content-Type: text/html
1701 [ ] Transfer-Encoding: chunked
1702 [ ] Connection: close
1703 [ ] Set-Cookie: __cfduid=d12194178e7c25c868e0f6f78fcc4d4c61504132842; expires=Thu, 30-Aug-18 22:40:42 GMT;
1704 path=/; domain=.allyourpix.com; HttpOnly
1705 [ ] Expires: Thu, 19 Nov 1981 08:52:00 GMT
1706 [ ] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
1707 [ ] Pragma: no-cache
1708 [ ] Set-Cookie: PHPSESSID=4842890008c85b3396138280d142274e; path=/
1709 [ ] Set-Cookie: CSS=black; expires=Fri, 29-Sep-2017 22:42:06 GMT
1710 [ ] Set-Cookie: LANG=en; expires=Fri, 29-Sep-2017 22:42:06 GMT
1711 [ ] Server: cloudflare-nginx
1712 [ ] CF-RAY: 396b40d9fd3021d4-EWR
1713 [ ] Data (MD5): d66f0d21fa568961061189c6149be091
1714
1715 [1] Pass
1716 [2] Pass
1717 [3] Pass
1718
1719 [>] URL appears stable. Beginning test
1720
1721 [>] Using DEFAULT User-Agent Strings
1722
1723 [>] Using Crazy User-Agent Strings
1724 [>] Using Bot User-Agent Strings
1725
1726 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
1727
1728
1729 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
1730
1731
1732 [!] CF-RAY: 396b41271eb221f8-EWR
1733
1734
1735 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
1736
1737
1738 [!] CF-RAY: 396b413079dc46ec-EWR
1739 [*] HTTPError: HTTP Error 403: Forbidden
1740
1741
1742 Enter your target IP : 104.28.5.37
1743[i] Scanning Site: https://allyourpix.com
1744
1745
1746
1747B A S I C I N F O
1748=======================================================================================================================
1749
1750
1751
1752
1753[+] Site Title: AllYourPix.com Adult Video And Picture Gallery - FREE HOME MADE MOBILE AND TUBE PORN VIDEOS.
1754[+] IP address: 104.28.4.37
1755[+] Web Server: cloudflare-nginx
1756[+] CMS: Could Not Detect
1757[+] Cloudflare: Detected
1758[+] Robots File: Could NOT Find robots.txt!
1759
1760
1761
1762
1763W H O I S L O O K U P
1764===========================================================================================================================
1765
1766
1767
1768 Domain Name: ALLYOURPIX.COM
1769 Registry Domain ID: 1552873964_DOMAIN_COM-VRSN
1770 Registrar WHOIS Server: whois.PublicDomainRegistry.com
1771 Registrar URL: http://www.publicdomainregistry.com
1772 Updated Date: 2017-04-09T15:53:26Z
1773 Creation Date: 2009-04-20T16:41:47Z
1774 Registry Expiry Date: 2018-04-20T16:41:47Z
1775 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
1776 Registrar IANA ID: 303
1777 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
1778 Registrar Abuse Contact Phone: +1.2013775952
1779 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1780
1781
1782
1783
1784G E O I P L O O K U P
1785============================================================================================================================
1786
1787
1788
1789[i] IP Address: 104.28.5.37
1790[i] Country: US
1791[i] State: California
1792[i] City: San Francisco
1793[i] Latitude: 37.769699
1794[i] Longitude: -122.393303
1795
1796
1797
1798
1799H T T P H E A D E R S
1800==========================================================================================================================
1801
1802
1803
1804
1805[i] HTTP/1.1 301 Moved Permanently
1806[i] Date: Wed, 30 Aug 2017 22:23:44 GMT
1807[i] Content-Type: text/html; charset=iso-8859-1
1808[i] Connection: close
1809[i] Set-Cookie: __cfduid=dd2bdbff311cf7cda6b958e80f09b8dc51504131824; expires=Thu, 30-Aug-18 22:23:44 GMT; path=/; domain=.allyourpix.com; HttpOnly
1810[i] Location: http://www.allyourpix.com/
1811[i] Server: cloudflare-nginx
1812[i] CF-RAY: 396b27fc78321870-EWR
1813[i] HTTP/1.1 301 Moved Permanently
1814[i] Date: Wed, 30 Aug 2017 22:23:44 GMT
1815[i] Connection: close
1816[i] Cache-Control: max-age=3600
1817[i] Expires: Wed, 30 Aug 2017 23:23:44 GMT
1818[i] Location: https://www.allyourpix.com/
1819[i] Server: cloudflare-nginx
1820[i] CF-RAY: 396b27fda78f2216-EWR
1821[i] HTTP/1.1 302 Moved Temporarily
1822[i] Date: Wed, 30 Aug 2017 22:23:44 GMT
1823[i] Content-Type: text/html
1824[i] Connection: close
1825[i] Set-Cookie: __cfduid=dbebefaa12608fa7b096e0b3ebb24bef01504131824; expires=Thu, 30-Aug-18 22:23:44 GMT; path=/; domain=.allyourpix.com; HttpOnly
1826[i] Location: http://www.allyourpix.com/index.php
1827[i] Server: cloudflare-nginx
1828[i] CF-RAY: 396b27fea9f621d4-EWR
1829[i] HTTP/1.1 301 Moved Permanently
1830[i] Date: Wed, 30 Aug 2017 22:23:44 GMT
1831[i] Connection: close
1832[i] Cache-Control: max-age=3600
1833[i] Expires: Wed, 30 Aug 2017 23:23:44 GMT
1834[i] Location: https://www.allyourpix.com/index.php
1835[i] Server: cloudflare-nginx
1836[i] CF-RAY: 396b280011cf4740-EWR
1837[i] HTTP/1.1 200 OK
1838[i] Date: Wed, 30 Aug 2017 22:23:45 GMT
1839[i] Content-Type: text/html
1840[i] Connection: close
1841[i] Set-Cookie: __cfduid=d272ec6dff1a2f22821e317a4849565201504131824; expires=Thu, 30-Aug-18 22:23:44 GMT; path=/; domain=.allyourpix.com; HttpOnly
1842[i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
1843[i] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
1844[i] Pragma: no-cache
1845[i] Set-Cookie: PHPSESSID=2ec6cf53e6255a3ef3e9192cb39460c8; path=/
1846[i] Set-Cookie: CSS=black; expires=Fri, 29-Sep-2017 22:25:08 GMT
1847[i] Set-Cookie: LANG=en; expires=Fri, 29-Sep-2017 22:25:08 GMT
1848[i] Server: cloudflare-nginx
1849[i] CF-RAY: 396b28012de9471c-EWR
1850
1851
1852
1853
1854D N S L O O K U P
1855======================================================================================================================
1856
1857
1858
1859allyourpix.com. 295 IN A 104.28.4.37
1860allyourpix.com. 295 IN A 104.28.5.37
1861allyourpix.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
1862allyourpix.com. 295 IN AAAA 2400:cb00:2048:1::681c:525
1863allyourpix.com. 295 IN AAAA 2400:cb00:2048:1::681c:425
1864
1865
1866
1867
1868S U B N E T C A L C U L A T I O N
1869=======================================================================================================================================
1870
1871
1872
1873Address = 2400:cb00:2048:1::681c:425
1874Network = 2400:cb00:2048:1::681c:425 / 128
1875Netmask = ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff
1876Wildcard Mask = ::
1877Hosts Bits = 0
1878Max. Hosts = 0 (2^0 - 1)
1879Host Range = { 2400:cb00:2048:1::681c:426 - 2400:cb00:2048:1::681c:425 }
1880
1881
1882
1883N M A P P O R T S C A N
1884===============================================================================================================================
1885
1886
1887
1888
1889Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-30 22:23 UTC
1890Nmap scan report for allyourpix.com (104.28.4.37)
1891Host is up (0.0019s latency).
1892Other addresses for allyourpix.com (not scanned): 104.28.5.37 2400:cb00:2048:1::681c:425 2400:cb00:2048:1::681c:525
1893PORT STATE SERVICE VERSION
189421/tcp filtered ftp
189522/tcp filtered ssh
189623/tcp filtered telnet
189725/tcp filtered smtp
189880/tcp open http Cloudflare nginx
1899110/tcp filtered pop3
1900143/tcp filtered imap
1901443/tcp open ssl/http Cloudflare nginx
1902445/tcp filtered microsoft-ds
19033389/tcp filtered ms-wbt-server
1904
1905
1906
1907S U B - D O M A I N F I N D E R
1908=====================================================================================================================================
1909
1910
1911
1912
1913[i] Total Subdomains Found : 4
1914
1915[+] Subdomain: allyourpix.com
1916[-] IP: 104.28.5.37
1917
1918[+] Subdomain: allyourpix.com
1919[-] IP: 104.28.4.37
1920
1921[+] Subdomain: www.allyourpix.com
1922[-] IP: 104.28.4.37
1923
1924[+] Subdomain: www.allyourpix.com
1925[-] IP: 104.28.5.37
1926
1927
1928
1929
1930
1931R E V E R S E I P L O O K U P
1932=====================================================================================================================================
1933
1934
1935
1936
1937[i] Total Sites Found On This Server : 29
1938
1939
1940[#] basic.my
1941[-] CMS: WordPress
1942
1943[#] basilicoshb.com
1944[-] CMS: Could Not Detect
1945
1946[#] bladesofteal.com
1947[-] CMS: WordPress
1948
1949[#] canli-radyo.biz
1950[-] CMS: WordPress
1951
1952[#] cryptolife.net
1953[-] CMS: WordPress
1954
1955[#] dailycurrant.com
1956[-] CMS: Could Not Detect
1957
1958[#] dev.cryptolife.net
1959[-] CMS: WordPress
1960
1961[#] finestmanvan.co.uk
1962[-] CMS: Could Not Detect
1963
1964[#] gall.dcinside.com
1965[-] CMS: Could Not Detect
1966
1967[#] hawar.cn
1968[-] CMS: Could Not Detect
1969
1970[#] jstore.co
1971[-] CMS: Could Not Detect
1972
1973[#] reddirtramblings.com
1974[-] CMS: WordPress
1975
1976[#] smigroups.com
1977[-] CMS: WordPress
1978
1979[#] springrank.com
1980[-] CMS: Could Not Detect
1981
1982[#] travesti.asia
1983[-] CMS: WordPress
1984
1985
1986
1987[#] www.custommealplansinlosangelesca.com
1988[-] CMS: WordPress
1989
1990[#] www.dinamani.com
1991[-] CMS: Could Not Detect
1992
1993[#] www.esainfo.ca
1994[-] CMS: WordPress
1995
1996[#] www.gdaf.org
1997[-] CMS: WordPress
1998
1999[#] www.humboldtjustice.com
2000[-] CMS: WordPress
2001
2002[#] www.tandcstaff.com
2003[-] CMS: WordPress
2004---------------------------------------------------------------------------
2005+ Target IP: 104.28.5.37
2006+ Target Hostname: 104.28.5.37
2007+ Target Port: 80
2008+ Start Time: 2017-08-30 19:36:45 (GMT-4)
2009---------------------------------------------------------------------------
2010+ Server: cloudflare-nginx
2011+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
2012+ Uncommon header 'cf-ray' found, with contents: 396b932ad1983bf3-CDG
2013+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
2014+ All CGI directories 'found', use '-C none' to test none
2015+ Server banner has changed from 'cloudflare-nginx' to '-nginx' which may suggest a WAF, load balancer or proxy is in place
2016+ ERROR: Error limit (20) reached for host, giving up. Last error:
2017+ Scan terminated: 3 error(s) and 3 item(s) reported on remote host
2018+ End Time: 2017-08-30 21:42:11 (GMT-4) (7526 seconds)
2019---------------------------------------------------------------------------
2020#######################################################################################################################################
2021Hostname youngandsexy.nnfree.com ISP Webair Internet Development Company Inc. (AS27257)
2022Continent North America Flag
2023US
2024Country United States Country Code US (USA)
2025Region NY Local time 30 Aug 2017 19:39 EDT
2026Metropolis* New York Postal Code 11530
2027City Garden City Latitude 40.728
2028IP Address 174.137.171.36 Longitude -73.634
2029########################################################################################################################################
2030youngandsexy.nnfree.com
2031
2032
2033; <<>> DiG 9.10.3-P4-Debian <<>> youngandsexy.nnfree.com any
2034;; global options: +cmd
2035;; Got answer:
2036;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 3934
2037;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
2038
2039;; OPT PSEUDOSECTION:
2040; EDNS: version: 0, flags:; udp: 4096
2041;; QUESTION SECTION:
2042;youngandsexy.nnfree.com. IN ANY
2043
2044;; ANSWER SECTION:
2045youngandsexy.nnfree.com. 7369 IN A 174.137.171.36
2046
2047;; Query time: 8 msec
2048;; SERVER: 192.168.1.254#53(192.168.1.254)
2049;; WHEN: Wed Aug 30 19:39:45 EDT 2017
2050;; MSG SIZE rcvd: 68
2051
2052
2053
2054;; Connection to 192.168.1.254#53(192.168.1.254) for youngandsexy.nnfree.com failed: connection refused.
2055Host youngandsexy.nnfree.com not found: 9(NOTAUTH)
2056; Transfer failed.
2057
2058
2059Please type the name of your network interface Example: eth0
2060eth0
2061
2062Running:
2063 traceroute -T -O info -i eth0 youngandsexy.nnfree.com
2064traceroute to youngandsexy.nnfree.com (174.137.171.36), 30 hops max, 60 byte packets
2065 1 gateway (192.168.1.254) 0.469 ms 0.743 ms 0.912 ms
2066 2 10.135.18.1 (10.135.18.1) 12.421 ms 16.715 ms 17.635 ms
2067 3 75.154.223.222 (75.154.223.222) 29.672 ms 29.849 ms 29.944 ms
2068 4 ix-xe-1-0-1-0.tcore1.N75-New-York.as6453.net (66.110.96.1) 30.090 ms 30.423 ms 30.578 ms
2069 5 ae-8.r07.nycmny01.us.bb.gin.ntt.net (129.250.9.113) 30.994 ms 30.882 ms 30.989 ms
2070 6 * * *
2071 7 csc180.gsc.webair.net (173.239.0.26) 30.307 ms 29.974 ms 30.000 ms
2072 8 dsc180.gsc.webair.net (173.239.38.130) 29.817 ms 30.073 ms dsd180.gsc.webair.net (173.239.38.134) 30.816 ms
2073 9 horngf.webair.com (174.137.171.36) <syn,ack> 30.933 ms 31.327 ms 31.476 ms
2074
2075
2076Smartmatch is experimental at /usr/bin/dnsenum line 698.
2077Smartmatch is experimental at /usr/bin/dnsenum line 698.
2078dnsenum VERSION:1.2.4
2079Warning: can't load Net::Whois::IP module, whois queries disabled.
2080
2081----- youngandsexy.nnfree.com -----
2082
2083
2084Host's addresses:
2085__________________
2086
2087youngandsexy.nnfree.com. 7317 IN A 174.137.171.36
2088
2089
2090Name Servers:
2091______________
2092
2093 youngandsexy.nnfree.com NS record query failed: NOERROR
2094
2095
2096
2097WhatWeb report for http://youngandsexy.nnfree.com
2098Status : 200 OK
2099Title : Welcome to Innocents and Virgins +18yo
2100IP : 174.137.171.36
2101Country : UNITED STATES, US
2102
2103Summary : Script[text/javascript], PHP[5.6.17], X-Powered-By[PHP/5.6.17], HTTPServer[CentOS][Apache/2.2.15 (CentOS)], Apache[2.2.15], Email[webmaster.mati@gmail.com], Cookies[sloth_cc,sloth_nosend,sloth_ref,sloth_sc,sloth_src]
2104
2105Detected Plugins:
2106[ Apache ]
2107 The Apache HTTP Server Project is an effort to develop and
2108 maintain an open-source HTTP server for modern operating
2109 systems including UNIX and Windows NT. The goal of this
2110 project is to provide a secure, efficient and extensible
2111 server that provides HTTP services in sync with the current
2112 HTTP standards.
2113
2114 Version : 2.2.15 (from HTTP Server Header)
2115 Google Dorks: (3)
2116 Website : http://httpd.apache.org/
2117
2118[ Cookies ]
2119 Display the names of cookies in the HTTP headers. The
2120 values are not returned to save on space.
2121
2122 String : sloth_src
2123 String : sloth_cc
2124 String : sloth_sc
2125 String : sloth_ref
2126 String : sloth_nosend
2127
2128[ Email ]
2129 Extract email addresses. Find valid email address and
2130 syntactically invalid email addresses from mailto: link
2131 tags. We match syntactically invalid links containing
2132 mailto: to catch anti-spam email addresses, eg. bob at
2133 gmail.com. This uses the simplified email regular
2134 expression from
2135 http://www.regular-expressions.info/email.html for valid
2136 email address matching.
2137
2138 String : webmaster.mati@gmail.com
2139 String : webmaster.mati@gmail.com
2140
2141[ HTTPServer ]
2142 HTTP server header string. This plugin also attempts to
2143 identify the operating system from the server header.
2144
2145 OS : CentOS
2146 String : Apache/2.2.15 (CentOS) (from server string)
2147
2148[ PHP ]
2149 PHP is a widely-used general-purpose scripting language
2150 that is especially suited for Web development and can be
2151 embedded into HTML. This plugin identifies PHP errors,
2152 modules and versions and extracts the local file path and
2153 username if present.
2154
2155 Version : 5.6.17
2156 Google Dorks: (2)
2157 Website : http://www.php.net/
2158
2159[ Script ]
2160 This plugin detects instances of script HTML elements and
2161 returns the script language/type.
2162
2163 String : text/javascript
2164
2165[ X-Powered-By ]
2166 X-Powered-By HTTP header
2167
2168 String : PHP/5.6.17 (from x-powered-by string)
2169
2170HTTP Headers:
2171 HTTP/1.1 200 OK
2172 Date: Wed, 30 Aug 2017 23:42:09 GMT
2173 Server: Apache/2.2.15 (CentOS)
2174 X-Powered-By: PHP/5.6.17
2175 Set-Cookie: sloth_src=noref; expires=Fri, 01-Sep-2017 23:42:09 GMT; Max-Age=172800; path=/
2176 Set-Cookie: sloth_cc=0; expires=Fri, 01-Sep-2017 23:42:09 GMT; Max-Age=172800; path=/
2177 Set-Cookie: sloth_sc=0; expires=Fri, 01-Sep-2017 23:42:09 GMT; Max-Age=172800; path=/
2178 Set-Cookie: sloth_ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
2179 Set-Cookie: sloth_nosend=59a74d51%253A00%253ATnoref%253A; expires=Fri, 01-Sep-2017 23:42:09 GMT; Max-Age=172800; path=/
2180 Connection: close
2181 Transfer-Encoding: chunked
2182 Content-Type: text/html; charset=UTF-8
2183
2184
2185
2186
2187
2188 ^ ^
2189 _ __ _ ____ _ __ _ _ ____
2190 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2191 | V V // o // _/ | V V // 0 // 0 // _/
2192 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2193 <
2194 ...'
2195
2196 WAFW00F - Web Application Firewall Detection Tool
2197
2198 By Sandro Gauci && Wendel G. Henrique
2199
2200Checking http://youngandsexy.nnfree.com
2201Generic Detection results:
2202No WAF detected by the generic detection
2203Number of requests: 13
2204
2205
2206
2207Trying zone transfer first...
2208
2209Unsuccessful in zone transfer (it was worth a shot)
2210Okay, trying the good old fashioned way... brute force
2211
2212Checking for wildcard DNS...
2213Nope. Good.
2214Now performing 2280 test(s)...
2215
2216Subnets found (may want to probe here using nmap or unicornscan):
2217
2218Done with Fierce scan: http://ha.ckers.org/fierce/
2219Found 0 entries.
2220
2221Have a nice day.
2222
2223
2224
2225lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
2226 Written by Stefan Behte (http://ge.mine.nu)
2227 Proof-of-concept! Might give false positives.
2228
2229Checking for DNS-Loadbalancing: NOT FOUND
2230Checking for HTTP-Loadbalancing [Server]:
2231 Apache/2.2.15 (CentOS)
2232 NOT FOUND
2233
2234Checking for HTTP-Loadbalancing [Date]: 23:43:14, 23:43:14, 23:43:15, 23:43:15, 23:43:16, 23:43:16, 23:43:17, 23:43:18, 23:43:18, 23:43:18, 23:43:19, 23:43:19, 23:43:20, 23:43:21, 23:43:21, 23:43:22, 23:43:23, 23:43:23, 23:43:24, 23:43:24, 23:43:25, 23:43:25, 23:43:26, 23:43:26, 23:43:28, 23:43:28, 23:43:29, 23:43:29, 23:43:30, 23:43:30, 23:43:31, 23:43:31, 23:43:32, 23:43:32, 23:43:33, 23:43:33, 23:43:34, 23:43:34, 23:43:35, 23:43:35, 23:43:36, 23:43:36, 23:43:37, 23:43:37, 23:43:38, 23:43:39, 23:43:40, 23:43:45, 23:43:48, 23:43:49, NOT FOUND
2235
2236Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2237
2238youngandsexy.nnfree.com does NOT use Load-balancing.
2239
2240
2241
2242Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2243
2244 ----------------------------------------------------------
2245| Scan Information |
2246 ----------------------------------------------------------
2247
2248Mode ..................... VRFY
2249Worker Processes ......... 5
2250Usernames file ........... users.txt
2251Target count ............. 1
2252Username count ........... 494
2253Target TCP port .......... 25
2254Query timeout ............ 5 secs
2255Target domain ............
2256
2257######## Scan started at Wed Aug 30 19:44:07 2017 #########
2258######## Scan completed at Wed Aug 30 19:52:22 2017 #########
22590 results.
2260
2261494 queries in 495 seconds (1.0 queries / sec)
2262
2263
2264
2265Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-30 19:52 EDT
2266NSE: Loaded 146 scripts for scanning.
2267NSE: Script Pre-scanning.
2268Initiating NSE at 19:52
2269Completed NSE at 19:52, 0.00s elapsed
2270Initiating NSE at 19:52
2271Completed NSE at 19:52, 0.00s elapsed
2272Failed to resolve "youngandsexy.nnfree.com.txt".
2273Initiating Parallel DNS resolution of 1 host. at 19:52
2274Completed Parallel DNS resolution of 1 host. at 19:52, 0.46s elapsed
2275Initiating SYN Stealth Scan at 19:52
2276Scanning youngandsexy.nnfree.com (174.137.171.36) [100 ports]
2277Discovered open port 3306/tcp on 174.137.171.36
2278Discovered open port 22/tcp on 174.137.171.36
2279Discovered open port 21/tcp on 174.137.171.36
2280Discovered open port 80/tcp on 174.137.171.36
2281Discovered open port 111/tcp on 174.137.171.36
2282Discovered open port 443/tcp on 174.137.171.36
2283Discovered open port 5666/tcp on 174.137.171.36
2284Completed SYN Stealth Scan at 19:52, 3.98s elapsed (100 total ports)
2285Initiating Service scan at 19:52
2286Scanning 7 services on youngandsexy.nnfree.com (174.137.171.36)
2287Completed Service scan at 19:52, 14.28s elapsed (7 services on 1 host)
2288Initiating OS detection (try #1) against youngandsexy.nnfree.com (174.137.171.36)
2289Initiating Traceroute at 19:52
2290Completed Traceroute at 19:52, 3.13s elapsed
2291Initiating Parallel DNS resolution of 10 hosts. at 19:52
2292Completed Parallel DNS resolution of 10 hosts. at 19:52, 5.51s elapsed
2293NSE: Script scanning 174.137.171.36.
2294Initiating NSE at 19:52
2295Completed NSE at 19:53, 44.85s elapsed
2296Initiating NSE at 19:53
2297Completed NSE at 19:53, 0.56s elapsed
2298Nmap scan report for youngandsexy.nnfree.com (174.137.171.36)
2299Host is up (0.28s latency).
2300rDNS record for 174.137.171.36: horngf.webair.com
2301Not shown: 86 closed ports
2302PORT STATE SERVICE VERSION
230321/tcp open ftp NcFTPd
230422/tcp open ssh OpenSSH 5.3 (protocol 2.0)
2305| ssh-hostkey:
2306| 1024 e7:0e:c0:9a:41:2d:af:0d:23:25:8d:31:03:02:1b:d9 (DSA)
2307|_ 2048 cd:30:da:c0:dc:31:6f:57:5f:56:68:11:d7:1a:ef:94 (RSA)
230825/tcp filtered smtp
230980/tcp open http Apache httpd 2.2.15 ((CentOS))
2310|_http-server-header: Apache/2.2.15 (CentOS)
2311|_http-title: Welcome to Innocents and Virgins +18yo
2312111/tcp open rpcbind 2-4 (RPC #100000)
2313135/tcp filtered msrpc
2314139/tcp filtered netbios-ssn
2315443/tcp open ssl/http Apache httpd 2.2.15 ((CentOS))
2316| ssl-cert: Subject: commonName=horngf1/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
2317| Issuer: commonName=horngf1/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
2318| Public Key type: rsa
2319| Public Key bits: 2048
2320| Signature Algorithm: sha256WithRSAEncryption
2321| Not valid before: 2016-01-26T00:01:29
2322| Not valid after: 2017-01-25T00:01:29
2323| MD5: fcb7 8838 4bc5 0433 5707 8a9f 9bc5 cb33
2324|_SHA-1: bf75 8466 c6bb 671d 2716 d50d 0178 c7ab aeec 7d09
2325|_ssl-date: 2017-08-30T23:53:10+00:00; +7s from scanner time.
2326445/tcp filtered microsoft-ds
2327465/tcp filtered smtps
2328587/tcp filtered submission
23293306/tcp open mysql MySQL 5.6.28-76.1-log
2330| mysql-info:
2331| Protocol: 10
2332| Version: 5.6.28-76.1-log
2333| Thread ID: 45245
2334| Capabilities flags: 63487
2335| Some Capabilities: Support41Auth, LongColumnFlag, Speaks41ProtocolOld, SupportsTransactions, IgnoreSigpipes, InteractiveClient, SupportsCompression, ConnectWithDatabase, SupportsLoadDataLocal, FoundRows, LongPassword, DontAllowDatabaseTableColumn, ODBCClient, IgnoreSpaceBeforeParenthesis, Speaks41ProtocolNew, SupportsAuthPlugins, SupportsMultipleResults, SupportsMultipleStatments
2336| Status: Autocommit
2337| Salt: t7T}<Rh3e"xW,qw"A^8;
2338|_ Auth Plugin Name: 88
23395666/tcp open tcpwrapped
234049152/tcp filtered unknown
2341Device type: general purpose
2342Running: Linux 2.6.X
2343OS CPE: cpe:/o:linux:linux_kernel:2.6.39
2344OS details: Linux 2.6.39
2345Uptime guess: 22.494 days (since Tue Aug 8 08:01:41 2017)
2346Network Distance: 12 hops
2347TCP Sequence Prediction: Difficulty=257 (Good luck!)
2348IP ID Sequence Generation: All zeros
2349Service Info: OS: Unix
2350
2351Host script results:
2352|_clock-skew: mean: 6s, deviation: 0s, median: 6s
2353
2354TRACEROUTE (using port 993/tcp)
2355HOP RTT ADDRESS
23561 278.93 ms 10.13.0.1
23572 ...
23583 110.32 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
23594 112.00 ms 10.95.33.8
23605 113.71 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
23616 180.32 ms be100-1295.nwk-1-a9.nj.us (192.99.146.127)
23627 ...
23638 180.43 ms be6.nyk-5-6k.ny.us (178.32.135.58)
23649 212.80 ms nyiix.NYC2.webair.net (198.32.160.100)
236510 212.77 ms csc180.gsc.webair.net (173.239.0.26)
236611 212.71 ms dsc180.gsc.webair.net (173.239.38.130)
236712 180.87 ms horngf.webair.com (174.137.171.36)
2368
2369NSE: Script Post-scanning.
2370Initiating NSE at 19:53
2371Completed NSE at 19:53, 0.00s elapsed
2372Initiating NSE at 19:53
2373Completed NSE at 19:53, 0.00s elapsed
2374Read data files from: /usr/bin/../share/nmap
2375OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2376Nmap done: 1 IP address (1 host up) scanned in 77.24 seconds
2377 Raw packets sent: 207 (10.062KB) | Rcvd: 234 (16.052KB)
2378
2379
2380Error: can not open nmap file: youngandsexy.nnfree.com.txt
2381
2382
2383httprint v0.301 (beta) - web server fingerprinting tool
2384(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
2385http://net-square.com/httprint/
2386httprint@net-square.com
2387
2388Finger Printing on http://youngandsexy.nnfree.com:80/
2389Finger Printing Completed on http://youngandsexy.nnfree.com:80/
2390--------------------------------------------------
2391Host: youngandsexy.nnfree.com
2392Fingerprinting Error: Host/URL not found...
2393
2394--------------------------------------------------
2395
2396
2397
2398
2399 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
2400 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2401 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
2402 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2403 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
2404
2405 _/ User-Agent Tester ↵
2406 _/ AKA: Purple Pimp ↵
2407 _/ ChrisJohnRiley ↵
2408 _/ blog.c22.cc ↵
2409
2410 [>] Performing initial request and confirming stability
2411 [>] Using User-Agent string Mozilla/5.0
2412
2413 [ ] URL (ENTERED): http://youngandsexy.nnfree.com
2414 [ ] Response Code: 200 OK
2415 [ ] Date: Wed, 30 Aug 2017 23:53:53 GMT
2416 [ ] Server: Apache/2.2.15 (CentOS)
2417 [ ] X-Powered-By: PHP/5.6.17
2418 [ ] Set-Cookie: sloth_src=noref; expires=Fri, 01-Sep-2017 23:53:53 GMT; Max-Age=172800; path=/
2419 [ ] Set-Cookie: sloth_cc=0; expires=Fri, 01-Sep-2017 23:53:53 GMT; Max-Age=172800; path=/
2420 [ ] Set-Cookie: sloth_sc=0; expires=Fri, 01-Sep-2017 23:53:53 GMT; Max-Age=172800; path=/
2421 [ ] Set-Cookie: sloth_ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
2422 [ ] Set-Cookie: sloth_nosend=59a75011%253A00%253ATnoref%253A; expires=Fri, 01-Sep-2017 23:53:53 GMT; Max-
2423 Age=172800; path=/
2424 [ ] Connection: close
2425 [ ] Transfer-Encoding: chunked
2426 [ ] Content-Type: text/html; charset=UTF-8
2427 [ ] Data (MD5): 49d9d14d84a9b23ff7cffedf08cadc9b
2428
2429 [1] Pass
2430 [2] Pass
2431 [3] Pass
2432
2433 [>] URL appears stable. Beginning test
2434
2435 [>] Using DEFAULT User-Agent Strings
2436
2437 [>] Using Crazy User-Agent Strings
2438 [>] Using Bot User-Agent Strings
2439
2440 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
2441
2442
2443 [>] Checks completed... try enabling VERBOSE mode for more detailed output
2444
2445 [>] That's all folks... Fo' Shizzle!
2446i] Scanning Site: http://youngandsexy.nnfree.com
2447
2448
2449
2450B A S I C I N F O
2451=======================================================================================================================
2452
2453
2454
2455
2456[+] Site Title: Welcome to Innocents and Virgins +18yo
2457[+] IP address: 174.137.171.36
2458[+] Web Server: Apache/2.2.15 (CentOS)
2459[+] CMS: Could Not Detect
2460[+] Cloudflare: Not Detected
2461[+] Robots File: Could NOT Find robots.txt!
2462
2463
2464
2465
2466G E O I P L O O K U P
2467============================================================================================================================
2468
2469
2470
2471[i] IP Address: 174.137.171.36
2472[i] Country: US
2473[i] State: New York
2474[i] City: Garden City
2475[i] Latitude: 40.727600
2476[i] Longitude: -73.634399
2477
2478
2479
2480
2481H T T P H E A D E R S
2482==========================================================================================================================
2483
2484
2485
2486
2487[i] HTTP/1.1 200 OK
2488[i] Date: Wed, 30 Aug 2017 23:40:51 GMT
2489[i] Server: Apache/2.2.15 (CentOS)
2490[i] X-Powered-By: PHP/5.6.17
2491[i] Set-Cookie: sloth_src=noref; expires=Fri, 01-Sep-2017 23:40:51 GMT; Max-Age=172800; path=/
2492[i] Set-Cookie: sloth_cc=0; expires=Fri, 01-Sep-2017 23:40:51 GMT; Max-Age=172800; path=/
2493[i] Set-Cookie: sloth_sc=0; expires=Fri, 01-Sep-2017 23:40:51 GMT; Max-Age=172800; path=/
2494[i] Set-Cookie: sloth_ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
2495[i] Set-Cookie: sloth_nosend=59a74d03%253A00%253ATnoref%253A; expires=Fri, 01-Sep-2017 23:40:51 GMT; Max-Age=172800; path=/
2496[i] Connection: close
2497[i] Content-Type: text/html; charset=UTF-8
2498
2499
2500
2501
2502D N S L O O K U P
2503======================================================================================================================
2504
2505
2506
2507youngandsexy.nnfree.com. 43195 IN A 174.137.171.36
2508
2509
2510
2511
2512S U B N E T C A L C U L A T I O N
2513=======================================================================================================================================
2514
2515
2516
2517Address = 174.137.171.36
2518Network = 174.137.171.36 / 32
2519Netmask = 255.255.255.255
2520Broadcast = not needed on Point-to-Point links
2521Wildcard Mask = 0.0.0.0
2522Hosts Bits = 0
2523Max. Hosts = 1 (2^0 - 0)
2524Host Range = { 174.137.171.36 - 174.137.171.36 }
2525
2526
2527
2528N M A P P O R T S C A N
2529===============================================================================================================================
2530
2531
2532
2533
2534Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-30 23:40 UTC
2535Nmap scan report for youngandsexy.nnfree.com (174.137.171.36)
2536Host is up (0.0081s latency).
2537rDNS record for 174.137.171.36: horngf.webair.com
2538PORT STATE SERVICE VERSION
253921/tcp open ftp NcFTPd
254022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
254123/tcp closed telnet
254225/tcp closed smtp
254380/tcp open http Apache httpd 2.2.15 ((CentOS))
2544110/tcp closed pop3
2545143/tcp closed imap
2546443/tcp open ssl/http Apache httpd 2.2.15 ((CentOS))
2547445/tcp filtered microsoft-ds
25483389/tcp closed ms-wbt-server
2549
2550
2551
2552S U B - D O M A I N F I N D E R
2553=====================================================================================================================================
2554
2555
2556
2557
2558[i] Total Subdomains Found : 1
2559
2560[+] Subdomain: youngandsexy.nnfree.com
2561[-] IP: 174.137.171.36
2562
2563
2564
2565
2566
2567 [+] URL(s) With Parameter(s):156
2568--------------------------------------------------------------------------
2569+ Target IP: 174.137.171.36
2570+ Target Hostname: 174.137.171.36
2571+ Target Port: 80
2572+ Start Time: 2017-08-30 19:41:33 (GMT-4)
2573---------------------------------------------------------------------------
2574+ Server: Apache/2.2.15 (CentOS)
2575+ Retrieved x-powered-by header: PHP/5.6.17
2576+ The anti-clickjacking X-Frame-Options header is not present.
2577+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
2578+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
2579+ Apache/2.2.15 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
2580+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
2581+ DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
2582+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
2583+ ERROR: Error limit (20) reached for host, giving up. Last error:
2584+ Scan terminated: 0 error(s) and 8 item(s) reported on remote host
2585+ End Time: 2017-08-30 19:49:38 (GMT-4) (485 seconds)
2586---------------------------------------------------------------------------
2587+ 1 host(s) tested
2588########################################################################################################################################
2589
2590Hostname teenjuniors.com ISP LeaseWeb Netherlands B.V. (AS60781)
2591Continent Europe Flag
2592NL
2593Country Netherlands Country Code NL (NLD)
2594Region Unknown Local time 31 Aug 2017 02:49 CEST
2595City Unknown Latitude 52.382
2596IP Address 95.211.5.91 Longitude 4.899
2597#######################################################################################################################################
2598teenjuniors.com
2599
2600
2601 Domain Name: TEENJUNIORS.COM
2602 Registry Domain ID: 1495083595_DOMAIN_COM-VRSN
2603 Registrar WHOIS Server: whois.godaddy.com
2604 Registrar URL: http://www.godaddy.com
2605 Updated Date: 2017-06-17T10:21:56Z
2606 Creation Date: 2008-06-16T17:51:19Z
2607 Registry Expiry Date: 2018-06-16T17:51:19Z
2608 Registrar: GoDaddy.com, LLC
2609 Registrar IANA ID: 146
2610 Registrar Abuse Contact Email: abuse@godaddy.com
2611 Registrar Abuse Contact Phone: 480-624-2505
2612 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
2613 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
2614 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2615 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
2616 Name Server: NS09.DOMAINCONTROL.COM
2617 Name Server: NS10.DOMAINCONTROL.COM
2618
2619Domain Name: TEENJUNIORS.COM
2620Registrar URL: http://www.godaddy.com
2621Registrant Name: Registration Private
2622Registrant Organization: Domains By Proxy, LLC
2623Name Server: NS09.DOMAINCONTROL.COM
2624Name Server: NS10.DOMAINCONTROL.COM
2625
2626; <<>> DiG 9.10.3-P4-Debian <<>> teenjuniors.com any
2627;; global options: +cmd
2628;; Got answer:
2629;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15335
2630;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
2631
2632;; OPT PSEUDOSECTION:
2633; EDNS: version: 0, flags:; udp: 4096
2634;; QUESTION SECTION:
2635;teenjuniors.com. IN ANY
2636
2637;; ANSWER SECTION:
2638teenjuniors.com. 1670 IN A 95.211.5.91
2639teenjuniors.com. 3470 IN NS ns09.domaincontrol.com.
2640teenjuniors.com. 3470 IN NS ns10.domaincontrol.com.
2641
2642;; Query time: 8 msec
2643;; SERVER: 192.168.1.254#53(192.168.1.254)
2644;; WHEN: Wed Aug 30 20:50:22 EDT 2017
2645;; MSG SIZE rcvd: 112
2646
2647
2648
2649
2650Running:
2651 traceroute -T -O info -i eth0 teenjuniors.com
2652traceroute to teenjuniors.com (95.211.5.91), 30 hops max, 60 byte packets
2653 1 gateway (192.168.1.254) 0.452 ms 0.621 ms 0.843 ms
2654 2 10.135.18.1 (10.135.18.1) 15.174 ms 16.865 ms 20.449 ms
2655 3 75.154.223.209 (75.154.223.209) 32.275 ms 32.304 ms 32.333 ms
2656 4 * * *
2657 5 * * *
2658 6 * * *
2659 7 * * *
2660 8 91.kaasserver.com (95.211.5.91) <syn,ack> 133.418 ms 132.544 ms 134.202 ms
2661
2662
2663
2664
2665Host's addresses:
2666__________________
2667
2668teenjuniors.com. 1621 IN A 95.211.5.91
2669
2670
2671Wildcard detection using: bzpotrxpfchc
2672_______________________________________
2673
2674bzpotrxpfchc.teenjuniors.com. 1800 IN A 95.211.5.91
2675
2676
2677!!!!!!!!!!!!!!!!!!!!!!!!!!!!
2678
2679 Wildcards detected, all subdomains will point to the same IP address
2680 Omitting results containing 95.211.5.91.
2681 Maybe you are using OpenDNS servers.
2682
2683!!!!!!!!!!!!!!!!!!!!!!!!!!!!
2684
2685
2686Name Servers:
2687______________
2688
2689ns10.domaincontrol.com. 15885 IN A 208.109.255.5
2690ns09.domaincontrol.com. 15885 IN A 216.69.185.5
2691
2692
2693Mail (MX) Servers:
2694___________________
2695
2696
2697
2698www.teenjuniors.com. 1618 IN CNAME teenjuniors.com.
2699
2700
2701Brute forcing with dns.txt:
2702____________________________
2703
2704e.teenjuniors.com. 3600 IN CNAME email.secureserver.net.
2705email.secureserver.net. 60 IN A 173.201.192.133
2706email.secureserver.net. 60 IN A 173.201.193.5
2707email.secureserver.net. 60 IN A 97.74.135.55
2708email.secureserver.net. 60 IN A 173.201.192.20
2709email.secureserver.net. 60 IN A 97.74.135.148
2710email.secureserver.net. 60 IN A 97.74.135.45
2711email.secureserver.net. 60 IN A 72.167.218.45
2712email.secureserver.net. 60 IN A 72.167.218.173
2713email.secureserver.net. 60 IN A 72.167.218.55
2714email.secureserver.net. 60 IN A 173.201.192.148
2715email.secureserver.net. 60 IN A 173.201.192.5
2716email.secureserver.net. 60 IN A 173.201.193.133
2717email.secureserver.net. 60 IN A 97.74.135.133
2718email.secureserver.net. 60 IN A 173.201.193.20
2719email.secureserver.net. 60 IN A 72.167.218.183
2720email.secureserver.net. 60 IN A 173.201.193.148
2721ftp.teenjuniors.com. 3600 IN CNAME teenjuniors.com.
2722mail.teenjuniors.com. 3600 IN CNAME pop.secureserver.net.
2723pop.secureserver.net. 43 IN A 45.40.130.44
2724pop.secureserver.net. 43 IN A 173.201.193.200
2725pop.secureserver.net. 43 IN A 68.178.252.115
2726pop.secureserver.net. 43 IN A 97.74.135.111
2727pop.secureserver.net. 43 IN A 97.74.135.218
2728pop.teenjuniors.com. 3600 IN CNAME pop.secureserver.net.
2729pop.secureserver.net. 40 IN A 173.201.193.200
2730pop.secureserver.net. 40 IN A 68.178.252.115
2731pop.secureserver.net. 40 IN A 97.74.135.111
2732pop.secureserver.net. 40 IN A 97.74.135.218
2733pop.secureserver.net. 40 IN A 45.40.130.44
2734smtp.teenjuniors.com. 3600 IN CNAME smtp.secureserver.net.
2735smtp.secureserver.net. 60 IN A 68.178.213.37
2736smtp.secureserver.net. 60 IN A 68.178.213.203
2737smtp.secureserver.net. 60 IN A 72.167.238.29
2738webmail.teenjuniors.com. 3600 IN CNAME webmail.secureserver.net.
2739webmail.secureserver.net. 3600 IN CNAME email.secureserver.net.
2740email.secureserver.net. 51 IN A 173.201.193.5
2741email.secureserver.net. 51 IN A 97.74.135.55
2742email.secureserver.net. 51 IN A 173.201.192.20
2743email.secureserver.net. 51 IN A 97.74.135.148
2744email.secureserver.net. 51 IN A 97.74.135.45
2745email.secureserver.net. 51 IN A 72.167.218.45
2746email.secureserver.net. 51 IN A 72.167.218.173
2747email.secureserver.net. 51 IN A 72.167.218.55
2748email.secureserver.net. 51 IN A 173.201.192.148
2749email.secureserver.net. 51 IN A 173.201.192.5
2750email.secureserver.net. 51 IN A 173.201.193.133
2751email.secureserver.net. 51 IN A 97.74.135.133
2752email.secureserver.net. 51 IN A 173.201.193.20
2753email.secureserver.net. 51 IN A 72.167.218.183
2754email.secureserver.net. 51 IN A 173.201.193.148
2755email.secureserver.net. 51 IN A 173.201.192.133
2756
2757
2758Performing recursion:
2759______________________
2760
2761
2762 ---- Checking subdomains NS records ----
2763teenjuniors.com. 3404 IN NS ns09.domaincontrol.com.
2764teenjuniors.com. 3404 IN NS ns10.domaincontrol.com.
2765teenjuniors.com. 3404 IN NS ns09.domaincontrol.com.
2766teenjuniors.com. 3404 IN NS ns10.domaincontrol.com.
2767
2768 Can't perform recursion no NS records.
2769
2770
2771teenjuniors.com class C netranges:
2772___________________________________
2773
2774 95.211.5.0/24
2775
2776
2777e.teenjuniors.com
2778IP address #1: 97.74.135.55
2779IP address #2: 173.201.192.20
2780IP address #3: 97.74.135.148
2781IP address #4: 97.74.135.45
2782IP address #5: 72.167.218.45
2783IP address #6: 72.167.218.173
2784IP address #7: 72.167.218.55
2785IP address #8: 173.201.192.148
2786IP address #9: 173.201.192.5
2787IP address #10: 173.201.193.133
2788IP address #11: 97.74.135.133
2789IP address #12: 173.201.193.20
2790IP address #13: 72.167.218.183
2791IP address #14: 173.201.193.148
2792IP address #15: 173.201.192.133
2793IP address #16: 173.201.193.5
2794
2795email.teenjuniors.com
2796IP address #1: 173.201.192.20
2797IP address #2: 97.74.135.148
2798IP address #3: 97.74.135.45
2799IP address #4: 72.167.218.45
2800IP address #5: 72.167.218.173
2801IP address #6: 72.167.218.55
2802IP address #7: 173.201.192.148
2803IP address #8: 173.201.192.5
2804IP address #9: 173.201.193.133
2805IP address #10: 97.74.135.133
2806IP address #11: 173.201.193.20
2807IP address #12: 72.167.218.183
2808IP address #13: 173.201.193.148
2809IP address #14: 173.201.192.133
2810IP address #15: 173.201.193.5
2811IP address #16: 97.74.135.55
2812
2813imap.teenjuniors.com
2814IP address #1: 68.178.252.71
2815IP address #2: 72.167.218.187
2816IP address #3: 72.167.218.82
2817IP address #4: 97.74.135.193
2818IP address #5: 97.74.135.69
2819IP address #6: 173.201.192.71
2820IP address #7: 173.201.193.226
2821IP address #8: 173.201.193.71
2822IP address #9: 45.40.130.32
2823IP address #10: 68.178.252.221
2824IP address #11: 68.178.252.222
2825
2826mail.teenjuniors.com
2827IP address #1: 97.74.135.111
2828IP address #2: 173.201.193.200
2829IP address #3: 68.178.252.115
2830IP address #4: 45.40.130.44
2831IP address #5: 97.74.135.218
2832
2833pop.teenjuniors.com
2834IP address #1: 173.201.193.200
2835IP address #2: 68.178.252.115
2836IP address #3: 45.40.130.44
2837IP address #4: 97.74.135.218
2838IP address #5: 97.74.135.111
2839
2840smtp.teenjuniors.com
2841IP address #1: 72.167.238.29
2842IP address #2: 68.178.213.203
2843IP address #3: 68.178.213.37
2844
2845webmail.teenjuniors.com
2846IP address #1: 173.201.193.5
2847IP address #2: 173.201.193.148
2848IP address #3: 97.74.135.133
2849IP address #4: 72.167.218.45
2850IP address #5: 97.74.135.45
2851IP address #6: 173.201.192.20
2852IP address #7: 173.201.192.133
2853IP address #8: 173.201.193.133
2854IP address #9: 173.201.192.5
2855IP address #10: 72.167.218.55
2856IP address #11: 173.201.193.20
2857IP address #12: 97.74.135.55
2858IP address #13: 173.201.192.148
2859IP address #14: 72.167.218.173
2860IP address #15: 97.74.135.148
2861IP address #16: 72.167.218.183
2862
2863[+] 7 (sub)domains and 72 IP address(es) found
2864[+] completion time: 116 second(s)
2865
2866
2867Tracing to teenjuniors.com[a] via 192.168.1.254, maximum of 3 retries
2868192.168.1.254 (192.168.1.254) Got answer
2869
2870
2871WhatWeb report for http://teenjuniors.com
2872Status : 200 OK
2873Title : TeenJuniors.com :: welcome to the Juniors index ::
2874IP : 95.211.5.91
2875Country : NETHERLANDS, NL
2876
2877Summary : Meta-Author[teenjuniors.com], Script[onlineusr,text/javascript], PHP[5.2.4-2ubuntu5.26], X-Powered-By[PHP/5.2.4-2ubuntu5.26], HTTPServer[Apache], Apache
2878
2879Detected Plugins:
2880[ Apache ]
2881 The Apache HTTP Server Project is an effort to develop and
2882 maintain an open-source HTTP server for modern operating
2883 systems including UNIX and Windows NT. The goal of this
2884 project is to provide a secure, efficient and extensible
2885 server that provides HTTP services in sync with the current
2886 HTTP standards.
2887
2888 Google Dorks: (3)
2889 Website : http://httpd.apache.org/
2890
2891[ HTTPServer ]
2892 HTTP server header string. This plugin also attempts to
2893 identify the operating system from the server header.
2894
2895 String : Apache (from server string)
2896
2897[ Meta-Author ]
2898 This plugin retrieves the author name from the meta name
2899 tag - info:
2900 http://www.webmarketingnow.com/tips/meta-tags-uncovered.html
2901 #author
2902
2903 String : teenjuniors.com
2904
2905[ PHP ]
2906 PHP is a widely-used general-purpose scripting language
2907 that is especially suited for Web development and can be
2908 embedded into HTML. This plugin identifies PHP errors,
2909 modules and versions and extracts the local file path and
2910 username if present.
2911
2912 Version : 5.2.4-2ubuntu5.26
2913 Google Dorks: (2)
2914 Website : http://www.php.net/
2915
2916[ Script ]
2917 This plugin detects instances of script HTML elements and
2918 returns the script language/type.
2919
2920 String : onlineusr,text/javascript
2921
2922[ X-Powered-By ]
2923 X-Powered-By HTTP header
2924
2925 String : PHP/5.2.4-2ubuntu5.26 (from x-powered-by string)
2926
2927HTTP Headers:
2928 HTTP/1.1 200 OK
2929 Date: Thu, 31 Aug 2017 00:53:56 GMT
2930 Server: Apache
2931 X-Powered-By: PHP/5.2.4-2ubuntu5.26
2932 Connection: close
2933 Transfer-Encoding: chunked
2934 Content-Type: text/html
2935
2936
2937
2938
2939
2940 ^ ^
2941 _ __ _ ____ _ __ _ _ ____
2942 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2943 | V V // o // _/ | V V // 0 // 0 // _/
2944 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2945 <
2946 ...'
2947
2948 WAFW00F - Web Application Firewall Detection Tool
2949
2950 By Sandro Gauci && Wendel G. Henrique
2951
2952Checking http://teenjuniors.com
2953Generic Detection results:
2954The site http://teenjuniors.com seems to be behind a WAF or some sort of security solution
2955Reason: Blocking is being done at connection/packet level.
2956Number of requests: 12
2957
2958
2959DNS Servers for teenjuniors.com:
2960 ns09.domaincontrol.com
2961 ns10.domaincontrol.com
2962
2963Trying zone transfer first...
2964 Testing ns09.domaincontrol.com
2965 Request timed out or transfer not allowed.
2966 Testing ns10.domaincontrol.com
2967 Request timed out or transfer not allowed.
2968
2969Unsuccessful in zone transfer (it was worth a shot)
2970Okay, trying the good old fashioned way... brute force
2971
2972Checking for wildcard DNS...
2973 ** Found 96870623776.teenjuniors.com at 95.211.5.91.
2974 ** High probability of wildcard DNS.
2975Now performing 2280 test(s)...
2976
2977Subnets found (may want to probe here using nmap or unicornscan):
2978
2979Done with Fierce scan: http://ha.ckers.org/fierce/
2980Found 0 entries.
2981
2982Have a nice day.
2983
2984
2985
2986Checking for HTTP-Loadbalancing [Date]: 01:08:49, 01:08:50, 01:08:50, 01:08:51, 01:08:51, 01:08:52, 01:08:52, 01:08:52, 01:08:53, 01:08:53, 01:08:54, 01:08:54, 01:08:54, 01:08:55, 01:08:55, 01:08:56, 01:08:56, 01:08:57, 01:08:57, 01:08:57, 01:08:58, 01:08:58, 01:08:59, 01:08:59, 01:08:59, 01:09:00, 01:09:00, 01:09:01, 01:09:01, 01:09:01, 01:09:02, 01:09:02, 01:09:03, 01:09:03, 01:09:03, 01:09:04, 01:09:04, 01:09:05, 01:09:05, 01:09:06, 01:09:06, 01:09:06, 01:09:07, 01:09:07, 01:09:08, 01:09:08, 01:09:08, 01:09:09, 01:09:09, 01:09:10, NOT FOUND
2987
2988Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2989
2990teenjuniors.com does NOT use Load-balancing.
2991
2992
2993
2994Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2995
2996 ----------------------------------------------------------
2997| Scan Information |
2998 ----------------------------------------------------------
2999
3000Mode ..................... VRFY
3001Worker Processes ......... 5
3002Usernames file ........... users.txt
3003Target count ............. 1
3004Username count ........... 494
3005Target TCP port .......... 25
3006Query timeout ............ 5 secs
3007Target domain ............
3008
3009######## Scan started at Wed Aug 30 21:09:22 2017 #########
3010######## Scan completed at Wed Aug 30 21:17:37 2017 #########
30110 results.
3012
3013494 queries in 495 seconds (1.0 queries / sec)
3014
3015
3016
3017Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-30 21:17 EDT
3018NSE: Loaded 146 scripts for scanning.
3019NSE: Script Pre-scanning.
3020Initiating NSE at 21:17
3021Completed NSE at 21:17, 0.00s elapsed
3022Initiating NSE at 21:17
3023Completed NSE at 21:17, 0.00s elapsed
3024Failed to resolve "teenjuniors.com.txt".
3025Initiating Parallel DNS resolution of 1 host. at 21:17
3026Completed Parallel DNS resolution of 1 host. at 21:17, 0.55s elapsed
3027Initiating SYN Stealth Scan at 21:17
3028Scanning teenjuniors.com (95.211.5.91) [100 ports]
3029Discovered open port 80/tcp on 95.211.5.91
3030Completed SYN Stealth Scan at 21:17, 4.51s elapsed (100 total ports)
3031Initiating Service scan at 21:17
3032Scanning 1 service on teenjuniors.com (95.211.5.91)
3033Completed Service scan at 21:17, 11.05s elapsed (1 service on 1 host)
3034Initiating OS detection (try #1) against teenjuniors.com (95.211.5.91)
3035Retrying OS detection (try #2) against teenjuniors.com (95.211.5.91)
3036adjust_timeouts2: packet supposedly had rtt of -328496 microseconds. Ignoring time.
3037adjust_timeouts2: packet supposedly had rtt of -328496 microseconds. Ignoring time.
3038Initiating Traceroute at 21:18
3039Completed Traceroute at 21:18, 3.04s elapsed
3040Initiating Parallel DNS resolution of 5 hosts. at 21:18
3041Completed Parallel DNS resolution of 5 hosts. at 21:18, 5.62s elapsed
3042NSE: Script scanning 95.211.5.91.
3043Initiating NSE at 21:18
3044Completed NSE at 21:20, 128.84s elapsed
3045Initiating NSE at 21:20
3046Completed NSE at 21:20, 0.00s elapsed
3047Nmap scan report for teenjuniors.com (95.211.5.91)
3048Host is up (0.88s latency).
3049rDNS record for 95.211.5.91: 91.kaasserver.com
3050Not shown: 93 closed ports
3051PORT STATE SERVICE VERSION
305225/tcp filtered smtp
305380/tcp open http Apache httpd
3054| http-methods:
3055|_ Supported Methods: GET HEAD
3056|_http-server-header: Apache
3057|_http-title: TeenJuniors.com :: welcome to the Juniors index ::
3058135/tcp filtered msrpc
3059139/tcp filtered netbios-ssn
3060445/tcp filtered microsoft-ds
3061465/tcp filtered smtps
3062587/tcp filtered submission
3063Aggressive OS guesses: Kyocera CopyStar CS 255 printer (99%), Kyocera CopyStar CS-2560 printer (99%), AXIS 205 Network Camera, Buffalo TeraStation NAS device, Linksys WAP54G WAP, or Sony SNC-RZ50N network camera (98%), Sun Integrated Lights-Out Manager (98%), Dell Integrated Remote Access Controller (iDRAC9) (98%), Linux 2.6.22 (98%), AVM FRITZ!Box FON WLAN 7170 WAP (97%), Dell Integrated Remote Access Controller (iDRAC) (97%), Dell Remote Access Controller 5/I (DRAC 5/I) (97%), Extreme Networks ExtremeXOS 12.5.4 (97%)
3064No exact OS matches for host (test conditions non-ideal).
3065Uptime guess: 413.180 days (since Wed Jul 13 17:02:03 2016)
3066Network Distance: 10 hops
3067TCP Sequence Prediction: Difficulty=260 (Good luck!)
3068IP ID Sequence Generation: All zeros
3069
3070TRACEROUTE (using port 8080/tcp)
3071HOP RTT ADDRESS
30721 1008.08 ms 10.13.0.1
30732 ...
30743 1012.45 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
30754 1016.91 ms 10.95.33.8
30765 1025.41 ms be100-1108.ams-1-a9.nl.eu (213.186.32.211)
30776 ... 9
307810 1023.27 ms 91.kaasserver.com (95.211.5.91)
3079
3080--------------------------------------------------
3081
3082
3083
3084
3085 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
3086 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3087 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
3088 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3089 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
3090
3091 _/ User-Agent Tester ↵
3092 _/ AKA: Purple Pimp ↵
3093 _/ ChrisJohnRiley ↵
3094 _/ blog.c22.cc ↵
3095
3096 [>] Performing initial request and confirming stability
3097 [>] Using User-Agent string Mozilla/5.0
3098
3099 [ ] URL (ENTERED): http://teenjuniors.com
3100 [ ] Response Code: 200 OK
3101 [ ] Date: Thu, 31 Aug 2017 01:21:04 GMT
3102 [ ] Server: Apache
3103 [ ] X-Powered-By: PHP/5.2.4-2ubuntu5.26
3104 [ ] Connection: close
3105 [ ] Transfer-Encoding: chunked
3106 [ ] Content-Type: text/html
3107 [ ] Data (MD5): 22a66f218f834ec734802a1e4cc9dc03
3108
3109 [1] Pass
3110 [2] Pass
3111 [3] Pass
3112
3113 [>] URL appears stable. Beginning test
3114
3115 [>] Using DEFAULT User-Agent Strings
3116
3117 [>] Using Crazy User-Agent Strings
3118 [>] Using Bot User-Agent Strings
3119
3120 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
3121
3122
3123 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
3124
3125
3126 [!] Data (MD5): 16f403d8c639d1a8ea52c7ad2a3cffff
3127
3128
3129 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
3130
3131
3132 [!] Data (MD5): 16f403d8c639d1a8ea52c7ad2a3cffff
3133
3134
3135 [>] User-Agent String : TrackBack/1.02
3136
3137
3138 [!] Data (MD5): 16f403d8c639d1a8ea52c7ad2a3cffff
3139
3140
3141 [>] User-Agent String : wispr
3142
3143
3144 [!] Data (MD5): 16f403d8c639d1a8ea52c7ad2a3cffff
3145
3146
3147 [>] User-Agent String : EMPTY USER-AGENT STRING!
3148
3149
3150 [!] Data (MD5): 16f403d8c639d1a8ea52c7ad2a3cffff
3151
3152
3153 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
3154
3155
3156 [!] Data (MD5): 16f403d8c639d1a8ea52c7ad2a3cffff
3157
3158
3159 [>] User-Agent String : Googlebot-Image/1.0
3160
3161
3162 [!] Data (MD5): a7fbdbb38afad077ce448551192c470d
3163
3164
3165 [>] User-Agent String : Mediapartners-Google
3166
3167
3168 [!] Data (MD5): a7fbdbb38afad077ce448551192c470d
3169
3170
3171 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
3172
3173
3174 [!] Data (MD5): a7fbdbb38afad077ce448551192c470d
3175
3176
3177 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
3178
3179
3180 [!] Data (MD5): a7fbdbb38afad077ce448551192c470d
3181
3182
3183 [>] User-Agent String : mmcrawler
3184
3185
3186 [!] Data (MD5): a7fbdbb38afad077ce448551192c470d
3187
3188
3189 [>] Checks completed... try enabling VERBOSE mode for more detailed output
3190
3191 [>] That's all folks... Fo' Shizzle!
3192
3193[i] Scanning Site: http://teenjuniors.com
3194
3195
3196
3197B A S I C I N F O
3198=======================================================================================================================
3199
3200
3201
3202
3203[+] Site Title: TeenJuniors.com :: welcome to the Juniors index ::
3204[+] IP address: 95.211.5.91
3205[+] Web Server: Apache
3206[+] CMS: Could Not Detect
3207[+] Cloudflare: Not Detected
3208[+] Robots File: Found
3209
3210-------------[ contents ]----------------
3211User-Agent: *
3212Allow: /
3213-----------[end of contents]-------------
3214
3215
3216
3217W H O I S L O O K U P
3218===========================================================================================================================
3219
3220
3221
3222 Domain Name: TEENJUNIORS.COM
3223 Registry Domain ID: 1495083595_DOMAIN_COM-VRSN
3224 Registrar WHOIS Server: whois.godaddy.com
3225 Registrar URL: http://www.godaddy.com
3226 Updated Date: 2017-06-17T10:21:56Z
3227 Creation Date: 2008-06-16T17:51:19Z
3228 Registry Expiry Date: 2018-06-16T17:51:19Z
3229 Registrar: GoDaddy.com, LLC
3230 Registrar IANA ID: 146
3231 Registrar Abuse Contact Email: abuse@godaddy.com
3232 Registrar Abuse Contact Phone: 480-624-2505
3233 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
3234 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
3235 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3236 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
3237 Name Server: NS09.DOMAINCONTROL.COM
3238 Name Server: NS10.DOMAINCONTROL.COM
3239
3240
3241
3242G E O I P L O O K U P
3243=========================
3244
3245[i] IP Address: 95.211.5.91
3246[i] Country: NL
3247[i] State: N/A
3248[i] City: N/A
3249[i] Latitude: 52.382401
3250[i] Longitude: 4.899500
3251
3252
3253
3254
3255[i] HTTP/1.1 200 OK
3256[i] Date: Thu, 31 Aug 2017 00:51:35 GMT
3257[i] Server: Apache
3258[i] X-Powered-By: PHP/5.2.4-2ubuntu5.26
3259[i] Connection: close
3260[i] Content-Type: text/html
3261
3262
3263
3264
3265D N S L O O K U P
3266======================================================================================================================
3267
3268
3269
3270teenjuniors.com. 1796 IN A 95.211.5.91
3271teenjuniors.com. 3600 IN NS ns09.domaincontrol.com.
3272teenjuniors.com. 3600 IN NS ns10.domaincontrol.com.
3273teenjuniors.com. 3600 IN SOA ns09.domaincontrol.com. dns.jomax.net. 2016050200 28800 7200 604800 3600
3274teenjuniors.com. 1800 IN MX 0 91.kaasserver.com.
3275
3276
3277
3278
3279S U B N E T C A L C U L A T I O N
3280=======================================================================================================================================
3281
3282
3283
3284Address = 95.211.5.91
3285Network = 95.211.5.91 / 32
3286Netmask = 255.255.255.255
3287Broadcast = not needed on Point-to-Point links
3288Wildcard Mask = 0.0.0.0
3289Hosts Bits = 0
3290Max. Hosts = 1 (2^0 - 0)
3291Host Range = { 95.211.5.91 - 95.211.5.91 }
3292
3293
3294
3295N M A P P O R T S C A N
3296===============================================================================================================================
3297
3298
3299
3300
3301Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 00:51 UTC
3302Nmap scan report for teenjuniors.com (95.211.5.91)
3303Host is up (0.11s latency).
3304rDNS record for 95.211.5.91: 91.kaasserver.com
3305PORT STATE SERVICE VERSION
330621/tcp closed ftp
330722/tcp closed ssh
330823/tcp closed telnet
330925/tcp open smtp Postfix smtpd
331080/tcp open http Apache httpd
3311110/tcp closed pop3
3312143/tcp closed imap
3313443/tcp closed https
3314445/tcp filtered microsoft-ds
33153389/tcp closed ms-wbt-server
3316
3317S U B - D O M A I N F I N D E R
3318=====================================================================================================================================
3319
3320
3321
3322
3323[i] Total Subdomains Found : 2
3324
3325[+] Subdomain: teenjuniors.com
3326[-] IP: 95.211.5.91
3327
3328[+] Subdomain: www.teenjuniors.comwww.teenjuniors.com
3329[-] IP: 95.211.5.91
3330
3331
3332
3333
3334
3335
3336--------------------------------------------------------------------------
3337+ Target IP: 95.211.5.91
3338+ Target Hostname: teenjuniors.com
3339+ Target Port: 80
3340+ Start Time: 2017-08-30 20:51:36 (GMT-4)
3341---------------------------------------------------------------------------
3342+ Server: Apache
3343+ Retrieved x-powered-by header: PHP/5.2.4-2ubuntu5.26
3344+ The anti-clickjacking X-Frame-Options header is not present.
3345+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
3346+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
3347+ Server leaks inodes via ETags, header found with file /robots.txt, inode: 2952797935, size: 22, mtime: Mon Nov 3 18:00:00 2008
3348+ "robots.txt" contains 1 entry which should be manually viewed.
3349+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
3350+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
3351+ OSVDB-3092: /sitemap.xml: This gives a nice listing of the site content.
3352+ OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3353+ OSVDB-12184: /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3354+ OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3355+ OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3356+ OSVDB-3268: /icons/: Directory indexing found.
3357+ OSVDB-3233: /icons/README: Apache default file found.
3358+ 8256 requests: 1 error(s) and 15 item(s) reported on remote host
3359+ End Time: 2017-08-30 22:09:14 (GMT-4) (4658 seconds)
3360---------------------------------------------------------------------------
3361+ 1 host(s) tested
3362#######################################################################################################################################
3363http://teen-gate.com/
3364 Hostname teen-gate.com ISP LeaseWeb Netherlands B.V. (AS60781)
3365Continent Europe Flag
3366NL
3367Country Netherlands Country Code NL (NLD)
3368Region Unknown Local time 31 Aug 2017 07:04 CEST
3369City Unknown Latitude 52.382
3370IP Address 37.48.84.238 Longitude 4.899
3371#######################################################################################################################################
3372teen-gate.com
3373
3374
3375 Domain Name: TEEN-GATE.COM
3376 Registry Domain ID: 1529098515_DOMAIN_COM-VRSN
3377 Registrar WHOIS Server: whois.psi-usa.info
3378 Registrar URL: http://www.psi-usa.info
3379 Updated Date: 2017-01-09T10:12:48Z
3380 Creation Date: 2008-11-18T16:49:03Z
3381 Registry Expiry Date: 2017-11-18T16:49:03Z
3382 Registrar: PSI-USA, Inc. dba Domain Robot
3383 Registrar IANA ID: 151
3384 Registrar Abuse Contact Email: domain-abuse@psi-usa.info
3385 Registrar Abuse Contact Phone: +49.94159559482
3386 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3387 Name Server: A.NS14.NET
3388 Name Server: B.NS14.NET
3389 Name Server: C.NS14.NET
3390 Name Server: D.NS14.NET
3391
3392Domain Name: teen-gate.com
3393Registry Domain ID: 1529098515_DOMAIN_COM-VRSN
3394Registrar WHOIS Server: whois.psi-usa.info
3395Registrar URL: http://www.psi-usa.info
3396Updated Date: 2017-01-09T10:13:00Z
3397Creation Date: 2008-11-18T16:49:03Z
3398Registrar Registration Expiration Date: 2017-11-18T16:49:04Z
3399Registrar: PSI-USA, Inc. dba Domain Robot
3400Registrar IANA ID: 151
3401Registrar Abuse Contact Email: domain-abuse@psi-usa.info
3402Registrar Abuse Contact Phone: +49.94159559482
3403Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
3404Registry Registrant ID:
3405Registrant Name: Svetlana Ovchinkina
3406Registrant Organization:
3407Registrant Street: Pr. Sisova Nr. 32
3408Registrant City: St. Petersburg
3409Registrant State/Province: RU
3410Registrant Postal Code: 197349
3411Registrant Country: RU
3412Registrant Phone: +79.215971697
3413Registrant Phone Ext:
3414Registrant Fax: +79.215971697
3415Registrant Fax Ext:
3416Registrant Email: info@so-models.com
3417Registry Admin ID:
3418Admin Name: Svetlana Ovchinkina
3419Admin Organization:
3420Admin Street: Pr. Sisova Nr. 32
3421Admin City: St. Petersburg
3422Admin State/Province: RU
3423Admin Postal Code: 197349
3424Admin Country: RU
3425Admin Phone: +79.215971697
3426Admin Phone Ext:
3427Admin Fax: +79.215971697
3428Admin Fax Ext:
3429Admin Email: info@so-models.com
3430Registry Tech ID:
3431Tech Name: Svetlana Ovchinkina
3432Tech Organization:
3433Tech Street: Pr. Sisova Nr. 32
3434Tech City: St. Petersburg
3435Tech State/Province: RU
3436Tech Postal Code: 197349
3437Tech Country: RU
3438Tech Phone: +79.215971697
3439Tech Phone Ext:
3440Tech Fax: +79.215971697
3441Tech Fax Ext:
3442Tech Email: info@so-models.com
3443Name Server: a.ns14.net
3444Name Server: b.ns14.net
3445Name Server: c.ns14.net
3446Name Server: d.ns14.net
3447 IN ANY
3448
3449;; ANSWER SECTION:
3450teen-gate.com. 86400 IN MX 100 mail.teen-gate.com.
3451teen-gate.com. 86400 IN SOA a.ns14.net. info.fit-4.net. 2017010901 43200 7200 1209600 86400
3452teen-gate.com. 3427 IN A 37.48.84.238
3453teen-gate.com. 86400 IN NS a.ns14.net.
3454teen-gate.com. 86400 IN NS d.ns14.net.
3455teen-gate.com. 86400 IN NS b.ns14.net.
3456teen-gate.com. 86400 IN NS c.ns14.net.
3457
3458;; Query time: 329 msec
3459;; SERVER: 192.168.1.254#53(192.168.1.254)
3460;; WHEN: Thu Aug 31 01:06:34 EDT 2017
3461;; MSG SIZE rcvd: 198
3462
3463
3464
3465Running:
3466 traceroute -T -O info -i eth0 teen-gate.com
3467traceroute to teen-gate.com (37.48.84.238), 30 hops max, 60 byte packets
3468 1 gateway (192.168.1.254) 0.518 ms 0.800 ms 0.967 ms
3469 2 10.135.18.1 (10.135.18.1) 7.227 ms 7.430 ms 7.838 ms
3470 3 75.154.223.209 (75.154.223.209) 32.694 ms 32.753 ms 32.811 ms
3471 4 chi-ms1.us.leaseweb.NET (206.223.119.148) 58.849 ms * *
3472 5 * * *
3473 6 * * *
3474 7 * * *
3475 8 po-1003.ce02.ams-01.nl.leaseweb.net (37.48.95.201) 120.339 ms po-1002.ce02.ams-01.nl.leaseweb.net (37.48.95.195) 127.607 ms po-1001.ce01.ams-01.nl.leaseweb.net (5.79.79.239) 127.643 ms
3476 9 5.79.78.213 (5.79.78.213) 128.384 ms 128.231 ms 128.373 ms
347710 37.48.84.238 (37.48.84.238) <syn,ack> 128.157 ms 120.677 ms 128.475 ms
3478
3479
3480----- teen-gate.com -----
3481
3482
3483Host's addresses:
3484__________________
3485
3486teen-gate.com. 3352 IN A 37.48.84.238
3487
3488
3489Wildcard detection using: fnszuazmccge
3490_______________________________________
3491
3492fnszuazmccge.teen-gate.com. 86400 IN A 37.48.84.238
3493
3494
3495
3496
3497Name Servers:
3498______________
3499
3500d.ns14.net. 31256 IN A 74.208.254.254
3501a.ns14.net. 103152 IN A 62.116.131.31
3502c.ns14.net. 138819 IN A 195.34.161.195
3503b.ns14.net. 47008 IN A 83.169.55.5
3504b.ns14.net. 47008 IN A 217.160.113.32
3505
3506
3507Mail (MX) Servers:
3508___________________
3509
3510mail.teen-gate.com. 86400 IN A 82.199.141.21
3511
3512
3513Brute forcing with dns.txt:
3514____________________________
3515
3516mail.teen-gate.com. 86382 IN A 82.199.141.21
3517
3518
3519Performing recursion:
3520______________________
3521
3522
3523 ---- Checking subdomains NS records ----
3524
3525 Can't perform recursion no NS records.
3526
3527
3528teen-gate.com class C netranges:
3529_________________________________
3530
3531 37.48.84.0/24
3532 82.199.141.0/24
3533
3534
3535Performing reverse lookup on 512 ip addresses:
3536_______________________________________________
3537
3538
35390 results out of 512 IP addresses.
3540
3541
3542teen-gate.com ip blocks:
3543_________________________
3544
3545
3546done.
3547
3548
3549dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
3550
3551[+] warning: domain might use wildcards. 37.48.84.238 will be ignored from results
3552[+] searching (sub)domains for teen-gate.com using built-in wordlist
3553[+] using maximum random delay of 10 millisecond(s) between requests
3554
3555mail.teen-gate.com
3556IP address #1: 82.199.141.21
3557
3558[+] 1 (sub)domains and 1 IP address(es) found
3559[+] completion time: 171 second(s)
3560
3561
3562Tracing to teen-gate.com[a] via 192.168.1.254, maximum of 3 retries
3563192.168.1.254 (192.168.1.254) Got answer
3564
3565
3566WhatWeb report for http://teen-gate.com
3567Status : 200 OK
3568Title : Teen-Gate - The Gate to Meet Cute & Sexy Teen Models all over the Planet
3569IP : 37.48.84.238
3570Country : NETHERLANDS, NL
3571
3572Summary : Script[javascript>,text/javascript], AddThis, X-Powered-By[PleskLin], HTTPServer[Apache], Apache, Frame, Email[webmaster@teen-gate.com], JQuery[3.1.1], Plesk[Lin]
3573
3574Detected Plugins:
3575[ AddThis ]
3576 AddThis is a free way to boost traffic back to your site by
3577 making it easier for visitors to share your content.
3578
3579 Website : http://www.addthis.com/
3580
3581[ Apache ]
3582 The Apache HTTP Server Project is an effort to develop and
3583 maintain an open-source HTTP server for modern operating
3584 systems including UNIX and Windows NT. The goal of this
3585 project is to provide a secure, efficient and extensible
3586 server that provides HTTP services in sync with the current
3587 HTTP standards.
3588
3589 Google Dorks: (3)
3590 Website : http://httpd.apache.org/
3591
3592[ Email ]
3593 Extract email addresses. Find valid email address and
3594 syntactically invalid email addresses from mailto: link
3595 tags. We match syntactically invalid links containing
3596 mailto: to catch anti-spam email addresses, eg. bob at
3597 gmail.com. This uses the simplified email regular
3598 expression from
3599 http://www.regular-expressions.info/email.html for valid
3600 email address matching.
3601
3602 String : webmaster@teen-gate.com
3603
3604[ Frame ]
3605 This plugin detects instances of frame and iframe HTML
3606 elements.
3607
3608
3609[ HTTPServer ]
3610 HTTP server header string. This plugin also attempts to
3611 identify the operating system from the server header.
3612
3613 String : Apache (from server string)
3614
3615[ JQuery ]
3616 A fast, concise, JavaScript that simplifies how to traverse
3617 HTML documents, handle events, perform animations, and add
3618 AJAX.
3619
3620 Version : 3.1.1
3621 Website : http://jquery.com/
3622
3623[ Plesk ]
3624 Plesk is a web control panel
3625
3626 String : Lin
3627 Google Dorks: (1)
3628 Website : http://www.parallels.com/products/plesk/
3629
3630[ Script ]
3631 This plugin detects instances of script HTML elements and
3632 returns the script language/type.
3633
3634 String : javascript>,text/javascript
3635
3636[ X-Powered-By ]
3637 X-Powered-By HTTP header
3638
3639 String : PleskLin (from x-powered-by string)
3640
3641HTTP Headers:
3642 HTTP/1.1 200 OK
3643 Date: Thu, 31 Aug 2017 05:10:44 GMT
3644 Server: Apache
3645 X-Powered-By: PleskLin
3646 Vary: Accept-Encoding
3647 Content-Encoding: gzip
3648 Connection: close
3649 Transfer-Encoding: chunked
3650 Content-Type: text/html
3651
3652
3653
3654[+] Hosts found in search engines:
3655------------------------------------
3656[-] Resolving hostnames IPs...
365737.48.84.238:253Dwww.teen-gate.com
365837.48.84.238:www.teen-gate.com
3659
3660
3661
3662 ^ ^
3663 _ __ _ ____ _ __ _ _ ____
3664 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
3665 | V V // o // _/ | V V // 0 // 0 // _/
3666 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
3667 <
3668 ...'
3669
3670 WAFW00F - Web Application Firewall Detection Tool
3671
3672 By Sandro Gauci && Wendel G. Henrique
3673
3674Checking http://teen-gate.com
3675Generic Detection results:
3676No WAF detected by the generic detection
3677Number of requests: 13
3678
3679
3680DNS Servers for teen-gate.com:
3681 a.ns14.net
3682 b.ns14.net
3683 d.ns14.net
3684 c.ns14.net
3685
3686Trying zone transfer first...
3687 Testing a.ns14.net
3688 Request timed out or transfer not allowed.
3689 Testing b.ns14.net
3690 Request timed out or transfer not allowed.
3691 Testing d.ns14.net
3692 Request timed out or transfer not allowed.
3693 Testing c.ns14.net
3694 Request timed out or transfer not allowed.
3695
3696Unsuccessful in zone transfer (it was worth a shot)
3697Okay, trying the good old fashioned way... brute force
3698
3699Checking for wildcard DNS...
3700 ** Found 99511443143.teen-gate.com at 37.48.84.238.
3701 ** High probability of wildcard DNS.
3702Now performing 2280 test(s)...
370382.199.141.21 mail.teen-gate.com
3704
3705Subnets found (may want to probe here using nmap or unicornscan):
3706 82.199.141.0-255 : 1 hostnames found.
3707
3708Done with Fierce scan: http://ha.ckers.org/fierce/
3709Found 1 entries.
3710
3711Have a nice day.
3712
3713
3714
3715lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
3716 Written by Stefan Behte (http://ge.mine.nu)
3717 Proof-of-concept! Might give false positives.
3718
3719Checking for DNS-Loadbalancing: NOT FOUND
3720Checking for HTTP-Loadbalancing [Server]:
3721 Apache
3722 NOT FOUND
3723
3724Checking for HTTP-Loadbalancing [Date]: 05:17:36, 05:17:37, 05:17:37, 05:17:37, 05:17:38, 05:17:38, 05:17:38, 05:17:39, 05:17:39, 05:17:40, 05:17:40, 05:17:40, 05:17:41, 05:17:41, 05:17:41, 05:17:42, 05:17:42, 05:17:42, 05:17:43, 05:17:44, 05:17:46, 05:17:46, 05:17:46, 05:17:46, 05:17:47, 05:17:47, 05:17:47, 05:17:47, 05:17:48, 05:17:48, 05:17:48, 05:17:48, 05:17:49, 05:17:49, 05:17:49, 05:17:50, 05:17:50, 05:17:50, 05:17:50, 05:17:51, 05:17:51, 05:17:51, 05:17:51, 05:17:52, 05:17:52, 05:17:52, 05:17:52, 05:17:53, 05:17:53, 05:17:54, NOT FOUND
3725
3726Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
3727
3728teen-gate.com does NOT use Load-balancing.
3729
3730
3731
3732Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
3733
3734 ----------------------------------------------------------
3735| Scan Information |
3736 ----------------------------------------------------------
3737
3738Mode ..................... VRFY
3739Worker Processes ......... 5
3740Usernames file ........... users.txt
3741Target count ............. 1
3742Username count ........... 494
3743Target TCP port .......... 25
3744Query timeout ............ 5 secs
3745Target domain ............
3746
3747######## Scan started at Thu Aug 31 01:19:09 2017 #########
3748######## Scan completed at Thu Aug 31 01:27:27 2017 #########
37490 results.
3750
3751494 queries in 498 seconds (1.0 queries / sec)
3752
3753
3754
3755Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-31 01:27 EDT
3756NSE: Loaded 146 scripts for scanning.
3757NSE: Script Pre-scanning.
3758Initiating NSE at 01:27
3759Completed NSE at 01:27, 0.00s elapsed
3760Initiating NSE at 01:27
3761Completed NSE at 01:27, 0.00s elapsed
3762Failed to resolve "teen-gate.com.txt".
3763Initiating Parallel DNS resolution of 1 host. at 01:27
3764Completed Parallel DNS resolution of 1 host. at 01:27, 0.42s elapsed
3765Initiating SYN Stealth Scan at 01:27
3766Scanning teen-gate.com (37.48.84.238) [100 ports]
3767Discovered open port 995/tcp on 37.48.84.238
3768Discovered open port 3306/tcp on 37.48.84.238
3769Discovered open port 80/tcp on 37.48.84.238
3770Discovered open port 22/tcp on 37.48.84.238
3771Discovered open port 143/tcp on 37.48.84.238
3772Discovered open port 993/tcp on 37.48.84.238
3773Discovered open port 110/tcp on 37.48.84.238
3774Discovered open port 443/tcp on 37.48.84.238
3775Discovered open port 21/tcp on 37.48.84.238
3776Discovered open port 106/tcp on 37.48.84.238
3777Discovered open port 8443/tcp on 37.48.84.238
3778Completed SYN Stealth Scan at 01:27, 3.66s elapsed (100 total ports)
3779Initiating Service scan at 01:27
3780Scanning 11 services on teen-gate.com (37.48.84.238)
3781Completed Service scan at 01:27, 20.60s elapsed (11 services on 1 host)
3782Initiating OS detection (try #1) against teen-gate.com (37.48.84.238)
3783adjust_timeouts2: packet supposedly had rtt of -128553 microseconds. Ignoring time.
3784adjust_timeouts2: packet supposedly had rtt of -128553 microseconds. Ignoring time.
3785Retrying OS detection (try #2) against teen-gate.com (37.48.84.238)
3786Initiating Traceroute at 01:28
3787Completed Traceroute at 01:28, 3.03s elapsed
3788Initiating Parallel DNS resolution of 7 hosts. at 01:28
3789Completed Parallel DNS resolution of 7 hosts. at 01:28, 5.86s elapsed
3790NSE: Script scanning 37.48.84.238.
3791Initiating NSE at 01:28
3792Completed NSE at 01:30, 147.19s elapsed
3793Initiating NSE at 01:30
3794Completed NSE at 01:30, 0.26s elapsed
3795Nmap scan report for teen-gate.com (37.48.84.238)
3796Host is up (0.13s latency).
3797Not shown: 83 closed ports
3798PORT STATE SERVICE VERSION
379921/tcp open ftp ProFTPD 1.3.5b
3800| ssl-cert: Subject: commonName=Parallels Panel/organizationName=Parallels/stateOrProvinceName=Virginia/countryName=US
3801| Issuer: commonName=Parallels Panel/organizationName=Parallels/stateOrProvinceName=Virginia/countryName=US
3802| Public Key type: rsa
3803| Public Key bits: 2048
3804| Signature Algorithm: sha1WithRSAEncryption
3805| Not valid before: 2014-06-12T12:49:42
3806| Not valid after: 2015-06-12T12:49:42
3807| MD5: 185b 4c32 fda5 47d1 a8de 6bcb f31a db0b
3808|_SHA-1: 36d7 343d 4f4b b422 873b 0227 fa41 0d77 18f0 a729
380922/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u1 (protocol 2.0)
3810| ssh-hostkey:
3811| 1024 c9:43:76:45:2e:82:60:51:89:40:a7:79:4e:c5:23:52 (DSA)
3812| 2048 35:dd:3b:0d:45:54:6a:45:54:d7:27:57:e2:ff:bb:e7 (RSA)
3813|_ 256 3b:9e:a9:29:89:98:6e:c2:91:84:ba:a0:c1:a6:2d:d2 (ECDSA)
381425/tcp filtered smtp
381580/tcp open http Apache httpd (PleskLin)
3816|_http-title: Teen-Gate - The Gate to Meet Cute & Sexy Teen Models all over ...
3817106/tcp open pop3pw poppassd
3818110/tcp open pop3 Courier pop3d
3819135/tcp filtered msrpc
3820139/tcp filtered netbios-ssn
3821143/tcp open imap Courier Imapd (released 2015)
3822443/tcp open ssl/http Apache httpd
3823| ssl-cert: Subject: commonName=Parallels Panel/organizationName=Parallels/stateOrProvinceName=Virginia/countryName=US
3824| Issuer: commonName=Parallels Panel/organizationName=Parallels/stateOrProvinceName=Virginia/countryName=US
3825| Public Key type: rsa
3826| Public Key bits: 2048
3827| Signature Algorithm: sha1WithRSAEncryption
3828| Not valid before: 2014-06-12T12:49:42
3829| Not valid after: 2015-06-12T12:49:42
3830| MD5: 185b 4c32 fda5 47d1 a8de 6bcb f31a db0b
3831|_SHA-1: 36d7 343d 4f4b b422 873b 0227 fa41 0d77 18f0 a729
3832|_ssl-date: 2017-08-31T05:27:19+00:00; -1m04s from scanner time.
3833445/tcp filtered microsoft-ds
3834465/tcp filtered smtps
3835587/tcp filtered submission
3836993/tcp open ssl/imaps?
3837|_ssl-date: 2017-08-31T05:27:12+00:00; -1m06s from scanner time.
3838995/tcp open ssl/pop3s?
3839|_ssl-date: 2017-08-31T05:27:12+00:00; -1m06s from scanner time.
38403306/tcp open mysql MySQL 5.5.53-0+deb7u1
3841| mysql-info:
3842| Protocol: 10
3843| Version: 5.5.53-0+deb7u1
3844| Thread ID: 19035781
3845| Capabilities flags: 63487
3846| Some Capabilities: LongPassword, IgnoreSpaceBeforeParenthesis, SupportsTransactions, FoundRows, Speaks41ProtocolOld, SupportsCompression, LongColumnFlag, ODBCClient, DontAllowDatabaseTableColumn, IgnoreSigpipes, ConnectWithDatabase, Speaks41ProtocolNew, Support41Auth, SupportsLoadDataLocal, InteractiveClient, SupportsMultipleStatments, SupportsMultipleResults, SupportsAuthPlugins
3847| Status: Autocommit
3848| Salt: 6IN,0Ll[b\&Flnd-P-/A
3849|_ Auth Plugin Name: 88
38508443/tcp open ssl/http nginx
3851| ssl-cert: Subject: commonName=Parallels Panel/organizationName=Parallels/stateOrProvinceName=Virginia/countryName=US
3852| Issuer: commonName=Parallels Panel/organizationName=Parallels/stateOrProvinceName=Virginia/countryName=US
3853| Public Key type: rsa
3854| Public Key bits: 2048
3855| Signature Algorithm: sha1WithRSAEncryption
3856| Not valid before: 2014-06-12T12:49:42
3857| Not valid after: 2015-06-12T12:49:42
3858| MD5: 185b 4c32 fda5 47d1 a8de 6bcb f31a db0b
3859|_SHA-1: 36d7 343d 4f4b b422 873b 0227 fa41 0d77 18f0 a729
3860|_ssl-date: 2017-08-31T05:27:26+00:00; -1m04s from scanner time.
3861| tls-nextprotoneg:
3862| spdy/3.1
3863|_ http/1.1
3864Aggressive OS guesses: Linux 3.2 - 3.8 (95%), Linux 3.8 (95%), WatchGuard Fireware 11.8 (95%), Linux 3.5 (93%), Linux 3.1 - 3.2 (93%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.0 - 3.2 (92%), Linux 2.6.32 (91%), Linux 2.6.32 or 3.10 (91%), Linux 3.0 (91%)
3865No exact OS matches for host (test conditions non-ideal).
3866Uptime guess: 173.504 days (since Fri Mar 10 12:24:51 2017)
3867Network Distance: 11 hops
3868TCP Sequence Prediction: Difficulty=260 (Good luck!)
3869IP ID Sequence Generation: All zeros
3870Service Info: Hosts: localhost.localdomain, default-37_48_84_238; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
3871
3872Host script results:
3873|_clock-skew: mean: -1m05s, deviation: 1s, median: -1m06s
3874
3875TRACEROUTE (using port 113/tcp)
3876HOP RTT ADDRESS
38771 110.05 ms 10.13.0.1
38782 112.01 ms 37.187.24.252
38793 110.76 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
38804 ...
38815 220.41 ms be100-1112.ams-5-a9.nl.eu (213.251.128.67)
38826 ... 8
38839 220.58 ms po-1002.ce01.ams-01.nl.leaseweb.net (37.48.95.193)
388410 116.99 ms 5.79.78.212
388511 116.33 ms 37.48.84.238
3886
3887
3888
3889 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
3890 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3891 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
3892 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3893 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
3894
3895 _/ User-Agent Tester ↵
3896 _/ AKA: Purple Pimp ↵
3897 _/ ChrisJohnRiley ↵
3898 _/ blog.c22.cc ↵
3899
3900 [>] Performing initial request and confirming stability
3901 [>] Using User-Agent string Mozilla/5.0
3902
3903 [ ] URL (ENTERED): http://teen-gate.com
3904 [ ] Response Code: 200 OK
3905 [ ] Date: Thu, 31 Aug 2017 05:29:39 GMT
3906 [ ] Server: Apache
3907 [ ] X-Powered-By: PleskLin
3908 [ ] Vary: Accept-Encoding
3909 [ ] Connection: close
3910 [ ] Transfer-Encoding: chunked
3911 [ ] Content-Type: text/html
3912 [ ] Data (MD5): 1fe8c9b204ccdaf71d66a892e2963b5b
3913
3914 [1] Pass
3915 [2] Pass
3916 [3] Pass
3917
3918 [>] URL appears stable. Beginning test
3919
3920 [>] Using DEFAULT User-Agent Strings
3921
3922 [>] Using Crazy User-Agent Strings
3923 [>] Using Bot User-Agent Strings
3924
3925 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
3926
3927
3928 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
3929
3930
3931 [!] Data (MD5): cbedd9c9e12bf294286c82b353753926
3932
3933
3934 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
3935
3936
3937 [!] Data (MD5): 8c98f56aaf290f64d809dc8eafa8b15a
3938
3939
3940 [>] User-Agent String : TrackBack/1.02
3941
3942
3943 [!] Data (MD5): 7512091a76f9c352a66e6464fa2110ea
3944
3945
3946 [>] User-Agent String : wispr
3947
3948
3949 [!] Data (MD5): dc3fc6afa29dbcd53be98dcf7c377359
3950
3951
3952 [>] User-Agent String : EMPTY USER-AGENT STRING!
3953
3954
3955 [!] Data (MD5): fab9e5cd927ac307dde6b2e9a6fb29cd
3956
3957
3958 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
3959
3960
3961 [!] Data (MD5): a51428131363655bdbe6a23e4866fa81
3962
3963
3964 [>] User-Agent String : Googlebot-Image/1.0
3965
3966
3967 [!] Data (MD5): b63a41625979bb03dd959ebc558eeca7
3968
3969
3970 [>] User-Agent String : Mediapartners-Google
3971
3972
3973 [!] Data (MD5): 2cf744a5516401337980e2f1dbeb7c41
3974
3975
3976 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
3977
3978
3979 [!] Data (MD5): 183865cdb59833c14ad19fdcecd364ce
3980
3981
3982 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
3983
3984
3985 [!] Data (MD5): df9314adb12336f9bcaa5a9834345a55
3986
3987
3988 [>] User-Agent String : mmcrawler
3989
3990
3991 [!] Data (MD5): 5ce1f425d005ca93bd564ad323ee1846
3992
3993
3994 [>] Checks completed... try enabling VERBOSE mode for more detailed output
3995
3996 [>] That's all folks... Fo' Shizzle!
3997i] Scanning Site: http://teen-gate.com
3998
3999
4000
4001B A S I C I N F O
4002=======================================================================================================================
4003
4004
4005
4006
4007[+] Site Title: Teen-Gate - The Gate to Meet Cute & Sexy Teen Models all over the Planet
4008[+] IP address: 37.48.84.238
4009[+] Web Server: Apache
4010[+] CMS: Could Not Detect
4011[+] Cloudflare: Not Detected
4012[+] Robots File: Found
4013
4014-------------[ contents ]----------------
4015User-Agent: *
4016Allow: /
4017
4018
4019-----------[end of contents]-------------
4020
4021
4022
4023W H O I S L O O K U P
4024===========================================================================================================================
4025
4026
4027
4028 Domain Name: TEEN-GATE.COM
4029 Registry Domain ID: 1529098515_DOMAIN_COM-VRSN
4030 Registrar WHOIS Server: whois.psi-usa.info
4031 Registrar URL: http://www.psi-usa.info
4032 Updated Date: 2017-01-09T10:12:48Z
4033 Creation Date: 2008-11-18T16:49:03Z
4034 Registry Expiry Date: 2017-11-18T16:49:03Z
4035 Registrar: PSI-USA, Inc. dba Domain Robot
4036 Registrar IANA ID: 151
4037 Registrar Abuse Contact Email: domain-abuse@psi-usa.info
4038 Registrar Abuse Contact Phone: +49.94159559482
4039 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4040 Name Server: A.NS14.NET
4041 Name Server: B.NS14.NET
4042 Name Server: C.NS14.NET
4043 Name Server: D.NS14.NET
4044
4045
4046
4047
4048G E O I P L O O K U P
4049============================================================================================================================
4050
4051
4052
4053[i] IP Address: 37.48.84.238
4054[i] Country: NL
4055[i] State: N/A
4056[i] City: N/A
4057[i] Latitude: 52.382401
4058[i] Longitude: 4.899500
4059
4060
4061
4062
4063H T T P H E A D E R S
4064==========================================================================================================================
4065
4066
4067
4068
4069[i] HTTP/1.1 200 OK
4070[i] Date: Thu, 31 Aug 2017 05:06:14 GMT
4071[i] Server: Apache
4072[i] X-Powered-By: PleskLin
4073[i] Vary: Accept-Encoding
4074[i] Connection: close
4075[i] Content-Type: text/html
4076
4077
4078
4079
4080D N S L O O K U P
4081======================================================================================================================
4082
4083
4084
4085teen-gate.com. 3596 IN A 37.48.84.238
4086teen-gate.com. 86400 IN NS c.ns14.net.
4087teen-gate.com. 86400 IN NS d.ns14.net.
4088teen-gate.com. 86400 IN NS a.ns14.net.
4089teen-gate.com. 86400 IN NS b.ns14.net.
4090teen-gate.com. 86400 IN SOA a.ns14.net. info.fit-4.net. 2017010901 43200 7200 1209600 86400
4091teen-gate.com. 86400 IN MX 100 mail.teen-gate.com.
4092
4093
4094
4095
4096S U B N E T C A L C U L A T I O N
4097=======================================================================================================================================
4098
4099
4100
4101Address = 37.48.84.238
4102Network = 37.48.84.238 / 32
4103Netmask = 255.255.255.255
4104Broadcast = not needed on Point-to-Point links
4105Wildcard Mask = 0.0.0.0
4106Hosts Bits = 0
4107Max. Hosts = 1 (2^0 - 0)
4108Host Range = { 37.48.84.238 - 37.48.84.238 }
4109
4110
4111
4112N M A P P O R T S C A N
4113===============================================================================================================================
4114
4115
4116
4117
4118Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 05:07 UTC
4119Nmap scan report for teen-gate.com (37.48.84.238)
4120Host is up (0.11s latency).
4121PORT STATE SERVICE VERSION
412221/tcp open ftp ProFTPD 1.3.5b
412322/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u1 (protocol 2.0)
412423/tcp closed telnet
412525/tcp open smtp Postfix smtpd
412680/tcp open http Apache httpd (PleskLin)
4127110/tcp open pop3 Courier pop3d
4128143/tcp open imap Courier Imapd (released 2015)
4129443/tcp open ssl/http Apache httpd
4130445/tcp filtered microsoft-ds
41313389/tcp closed ms-wbt-server
4132
4133S U B - D O M A I N F I N D E R
4134=====================================================================================================================================
4135
4136
4137
4138
4139[i] Total Subdomains Found : 3
4140
4141[+] Subdomain: teen-gate.com
4142[-] IP: 37.48.84.238
4143
4144[+] Subdomain: mail.teen-gate.com
4145[-] IP: 82.199.141.21
4146
4147[+] Subdomain: www.teen-gate.com
4148[-] IP: 37.48.84.238
4149
4150
4151
4152
4153
4154R E V E R S E I P L O O K U P
4155=====================================================================================================================================
4156
4157
4158
4159
4160[i] Total Sites Found On This Server : 1
4161
4162
4163[#] www.sweet-nadja.com,
4164[-] CMS: Could Not Detect
4165
4166
4167---------------------------------------------------------------------------
4168+ Target IP: 37.48.84.238
4169+ Target Hostname: 37.48.84.238
4170+ Target Port: 80
4171+ Start Time: 2017-08-31 01:08:38 (GMT-4)
4172---------------------------------------------------------------------------
4173+ Server: Apache
4174+ Retrieved x-powered-by header: PleskLin
4175+ Server leaks inodes via ETags, header found with file /, inode: 259487, size: 7153, mtime: Wed Jan 4 09:26:08 2017
4176+ The anti-clickjacking X-Frame-Options header is not present.
4177+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
4178+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
4179+ Allowed HTTP Methods: OPTIONS, GET, HEAD, POST
4180+ OSVDB-3233: /icons/README: Apache default file found.
4181+ 8347 requests: 0 error(s) and 7 item(s) reported on remote host
4182+ End Time: 2017-08-31 01:27:28 (GMT-4) (1130 seconds)
4183---------------------------------------------------------------------------
4184#######################################################################################################################################
4185 Hostname www.a-teenz.com ISP GleSYS Internet Services AB (AS43948)
4186Continent Europe Flag
4187SE
4188Country Sweden Country Code SE (SWE)
4189Region 06 Local time 31 Aug 2017 07:50 CEST
4190Metropolis Unknown Postal Code 311 01
4191City Falkenberg Latitude 56.898
4192IP Address 31.192.226.138 Longitude 12.502
4193#######################################################################################################################################
4194Enter the target EG. domain.org
4195www.a-teenz.com
4196
4197
4198
4199
4200; <<>> DiG 9.10.3-P4-Debian <<>> www.a-teenz.com any
4201;; global options: +cmd
4202;; Got answer:
4203;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 38407
4204;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
4205
4206;; OPT PSEUDOSECTION:
4207; EDNS: version: 0, flags:; udp: 4096
4208;; QUESTION SECTION:
4209;www.a-teenz.com. IN ANY
4210
4211;; ANSWER SECTION:
4212www.a-teenz.com. 1642 IN A 31.192.226.138
4213
4214;; Query time: 9 msec
4215;; SERVER: 192.168.1.254#53(192.168.1.254)
4216;; WHEN: Thu Aug 31 01:51:52 EDT 2017
4217;; MSG SIZE rcvd: 60
4218
4219
4220
4221;; Connection to 192.168.1.254#53(192.168.1.254) for www.a-teenz.com failed: connection refused.
4222Host www.a-teenz.com not found: 9(NOTAUTH)
4223; Transfer failed.
4224
4225
4226Please type the name of your network interface Example: eth0
4227eht0
4228
4229Running:
4230 traceroute -T -O info -i eht0 www.a-teenz.com
4231
4232setsockopt SO_BINDTODEVICE: Aucun périphérique de ce type
4233
4234
4235Smartmatch is experimental at /usr/bin/dnsenum line 698.
4236Smartmatch is experimental at /usr/bin/dnsenum line 698.
4237dnsenum VERSION:1.2.4
4238Warning: can't load Net::Whois::IP module, whois queries disabled.
4239
4240----- www.a-teenz.com -----
4241
4242
4243Host's addresses:
4244__________________
4245
4246www.a-teenz.com. 1592 IN A 31.192.226.138
4247
4248
4249Name Servers:
4250______________
4251
4252 www.a-teenz.com NS record query failed: NOERROR
4253
4254
4255dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
4256
4257[+] searching (sub)domains for www.a-teenz.com using built-in wordlist
4258[+] using maximum random delay of 10 millisecond(s) between requests
4259
4260[+] 0 (sub)domains and 0 IP address(es) found
4261[+] completion time: 117 second(s)
4262
4263
4264Tracing to www.a-teenz.com[a] via 192.168.1.254, maximum of 3 retries
4265192.168.1.254 (192.168.1.254) Got answer
4266
4267
4268WhatWeb report for http://www.a-teenz.com
4269Status : 200 OK
4270Title : Free Nude Sexy Teen Girls and Free Amateur Teen Videos
4271IP : 31.192.226.138
4272Country : SWEDEN, SE
4273
4274Summary : HTML5, Google-Analytics[UA-13127408-8], Script[text/javascript], X-Frame-Options[SAMEORIGIN], HTTPServer[Debian Linux][Apache/2.2.16 (Debian)], Apache[2.2.16]
4275
4276Detected Plugins:
4277[ Apache ]
4278 The Apache HTTP Server Project is an effort to develop and
4279 maintain an open-source HTTP server for modern operating
4280 systems including UNIX and Windows NT. The goal of this
4281 project is to provide a secure, efficient and extensible
4282 server that provides HTTP services in sync with the current
4283 HTTP standards.
4284
4285 Version : 2.2.16 (from HTTP Server Header)
4286 Google Dorks: (3)
4287 Website : http://httpd.apache.org/
4288
4289[ Google-Analytics ]
4290 This plugin identifies the Google Analytics account.
4291
4292 Account : UA-13127408-8
4293 Website : http://www.google.com/analytics/
4294
4295[ HTML5 ]
4296 HTML version 5, detected by the doctype declaration
4297
4298
4299[ HTTPServer ]
4300 HTTP server header string. This plugin also attempts to
4301 identify the operating system from the server header.
4302
4303 OS : Debian Linux
4304 String : Apache/2.2.16 (Debian) (from server string)
4305
4306[ Script ]
4307 This plugin detects instances of script HTML elements and
4308 returns the script language/type.
4309
4310 String : text/javascript
4311
4312[ X-Frame-Options ]
4313 This plugin retrieves the X-Frame-Options value from the
4314 HTTP header. - More Info:
4315 http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
4316 aspx
4317
4318 String : SAMEORIGIN
4319
4320HTTP Headers:
4321 HTTP/1.1 200 OK
4322 Date: Thu, 31 Aug 2017 05:54:49 GMT
4323 Server: Apache/2.2.16 (Debian)
4324 Accept-Ranges: bytes
4325 Vary: Accept-Encoding
4326 Content-Encoding: gzip
4327 X-Frame-Options: SAMEORIGIN
4328 Content-Length: 10757
4329 Connection: close
4330 Content-Type: text/html
4331
4332
4333 ^ ^
4334 _ __ _ ____ _ __ _ _ ____
4335 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
4336 | V V // o // _/ | V V // 0 // 0 // _/
4337 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
4338 <
4339 ...'
4340
4341 WAFW00F - Web Application Firewall Detection Tool
4342
4343 By Sandro Gauci && Wendel G. Henrique
4344
4345Checking http://www.a-teenz.com
4346Generic Detection results:
4347No WAF detected by the generic detection
4348Number of requests: 13
4349
4350
4351
4352Trying zone transfer first...
4353
4354Unsuccessful in zone transfer (it was worth a shot)
4355Okay, trying the good old fashioned way... brute force
4356
4357Checking for wildcard DNS...
4358Nope. Good.
4359Now performing 2280 test(s)...
4360
4361Subnets found (may want to probe here using nmap or unicornscan):
4362
4363Done with Fierce scan: http://ha.ckers.org/fierce/
4364Found 0 entries.
4365
4366Have a nice day.
4367
4368
4369
4370lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
4371 Written by Stefan Behte (http://ge.mine.nu)
4372 Proof-of-concept! Might give false positives.
4373
4374Checking for DNS-Loadbalancing: NOT FOUND
4375Checking for HTTP-Loadbalancing [Server]:
4376 Apache/2.2.16 (Debian)
4377 NOT FOUND
4378
4379Checking for HTTP-Loadbalancing [Date]: 05:55:28, 05:55:28, 05:55:28, 05:55:29, 05:55:29, 05:55:29, 05:55:30, 05:55:30, 05:55:30, 05:55:31, 05:55:31, 05:55:31, 05:55:32, 05:55:32, 05:55:32, 05:55:33, 05:55:33, 05:55:34, 05:55:34, 05:55:35, 05:55:35, 05:55:35, 05:55:36, 05:55:36, 05:55:36, 05:55:37, 05:55:37, 05:55:37, 05:55:38, 05:55:38, 05:55:38, 05:55:39, 05:55:39, 05:55:39, 05:55:40, 05:55:40, 05:55:40, 05:55:41, 05:55:41, 05:55:41, 05:55:42, 05:55:42, 05:55:42, 05:55:43, 05:55:43, 05:55:43, 05:55:44, 05:55:44, 05:55:44, 05:55:45, NOT FOUND
4380
4381Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
4382
4383www.a-teenz.com does NOT use Load-balancing.
4384
4385
4386
4387Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
4388
4389 ----------------------------------------------------------
4390| Scan Information |
4391 ----------------------------------------------------------
4392
4393Mode ..................... VRFY
4394Worker Processes ......... 5
4395Usernames file ........... users.txt
4396Target count ............. 1
4397Username count ........... 494
4398Target TCP port .......... 25
4399Query timeout ............ 5 secs
4400Target domain ............
4401
4402######## Scan started at Thu Aug 31 01:55:53 2017 #########
4403######## Scan completed at Thu Aug 31 02:04:08 2017 #########
44040 results.
4405
4406494 queries in 495 seconds (1.0 queries / sec)
4407
4408
4409
4410Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-31 02:04 EDT
4411NSE: Loaded 146 scripts for scanning.
4412NSE: Script Pre-scanning.
4413Initiating NSE at 02:04
4414Completed NSE at 02:04, 0.00s elapsed
4415Initiating NSE at 02:04
4416Completed NSE at 02:04, 0.00s elapsed
4417Failed to resolve "www.a-teenz.com.txt".
4418Initiating Parallel DNS resolution of 1 host. at 02:04
4419Completed Parallel DNS resolution of 1 host. at 02:04, 0.70s elapsed
4420Initiating SYN Stealth Scan at 02:04
4421Scanning www.a-teenz.com (31.192.226.138) [100 ports]
4422Discovered open port 53/tcp on 31.192.226.138
4423Discovered open port 80/tcp on 31.192.226.138
4424Discovered open port 443/tcp on 31.192.226.138
4425Completed SYN Stealth Scan at 02:04, 3.12s elapsed (100 total ports)
4426Initiating Service scan at 02:04
4427Scanning 3 services on www.a-teenz.com (31.192.226.138)
4428Completed Service scan at 02:04, 6.42s elapsed (3 services on 1 host)
4429Initiating OS detection (try #1) against www.a-teenz.com (31.192.226.138)
4430adjust_timeouts2: packet supposedly had rtt of -166871 microseconds. Ignoring time.
4431adjust_timeouts2: packet supposedly had rtt of -166871 microseconds. Ignoring time.
4432adjust_timeouts2: packet supposedly had rtt of -138137 microseconds. Ignoring time.
4433adjust_timeouts2: packet supposedly had rtt of -138137 microseconds. Ignoring time.
4434Retrying OS detection (try #2) against www.a-teenz.com (31.192.226.138)
4435adjust_timeouts2: packet supposedly had rtt of -136561 microseconds. Ignoring time.
4436adjust_timeouts2: packet supposedly had rtt of -136561 microseconds. Ignoring time.
4437Initiating Traceroute at 02:04
4438Completed Traceroute at 02:04, 3.00s elapsed
4439Initiating Parallel DNS resolution of 11 hosts. at 02:04
4440Completed Parallel DNS resolution of 11 hosts. at 02:04, 5.86s elapsed
4441NSE: Script scanning 31.192.226.138.
4442Initiating NSE at 02:04
4443Completed NSE at 02:05, 60.02s elapsed
4444Initiating NSE at 02:05
4445Completed NSE at 02:05, 0.00s elapsed
4446Nmap scan report for www.a-teenz.com (31.192.226.138)
4447Host is up (0.17s latency).
4448rDNS record for 31.192.226.138: 31-192-226-138-static.serverhotell.net
4449Not shown: 91 closed ports
4450PORT STATE SERVICE VERSION
445125/tcp filtered smtp
445253/tcp open domain ISC BIND 9.7.3
4453| dns-nsid:
4454|_ bind.version: 9.7.3
445580/tcp open http Apache httpd 2.2.16
4456| http-methods:
4457|_ Supported Methods: HEAD POST OPTIONS
4458| http-robots.txt: 20 disallowed entries (15 shown)
4459| / /atc/ /awastats-icon/ /awastatsicons/ /font/
4460| /galleries/make/ /galleries/femalebeauty/ /icon/ /php/ /phpmyadmin/
4461|_/stats/ /te/ /update/ /*.gif$ /*.jpg$
4462|_http-title: Free Nude Sexy Teen Girls and Free Amateur Teen Videos
4463135/tcp filtered msrpc
4464139/tcp filtered netbios-ssn
4465443/tcp open http Apache httpd 2.2.16
4466| http-methods:
4467|_ Supported Methods: GET HEAD POST OPTIONS
4468|_http-server-header: Apache/2.2.16 (Debian)
4469|_http-title: 404 Not Found
4470445/tcp filtered microsoft-ds
4471465/tcp filtered smtps
4472587/tcp filtered submission
4473Aggressive OS guesses: Linux 2.6.39 (99%), Linux 2.6.32 (95%), Linux 2.6.32 or 3.10 (95%), WatchGuard Fireware 11.8 (95%), Synology DiskStation Manager 5.1 (94%), Linux 3.10 (94%), Linux 3.4 (94%), Linux 3.1 - 3.2 (93%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.2 - 3.8 (91%)
4474No exact OS matches for host (test conditions non-ideal).
4475Uptime guess: 2.918 days (since Mon Aug 28 04:04:17 2017)
4476Network Distance: 12 hops
4477TCP Sequence Prediction: Difficulty=259 (Good luck!)
4478IP ID Sequence Generation: All zeros
4479Service Info: Host: a-teenz.com
4480
4481TRACEROUTE (using port 995/tcp)
4482HOP RTT ADDRESS
44831 110.00 ms 10.13.0.1
44842 110.26 ms 37.187.24.252
44853 110.80 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
44864 ...
44875 119.97 ms be100-1112.ams-5-a9.nl.eu (213.251.128.67)
44886 120.04 ms 20ge-amsix.ams1.nl.portlane.net (80.249.209.25)
44897 190.50 ms te-0-3-0-2.cr1.sto1.se.portlane.net (80.67.4.178)
44908 190.43 ms po-6.vbdc-cr1.glesys.net (193.108.196.44)
44919 190.64 ms te-6-4.fbg-cr1.glesys.net (46.21.96.129)
449210 190.72 ms te-1-1.fbg-pe2.glesys.net (193.108.196.87)
449311 190.72 ms 91.228.193.180
449412 190.70 ms 31-192-226-138-static.serverhotell.net (31.192.226.138)
4495
4496NSE: Script Post-scanning.
4497Initiating NSE at 02:05
4498Completed NSE at 02:05, 0.00s elapsed
4499Initiating NSE at 02:05
4500Completed NSE at 02:05, 0.00s elapsed
4501Read data files from: /usr/bin/../share/nmap
4502OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4503Nmap done: 1 IP address (1 host up) scanned in 87.62 seconds
4504 Raw packets sent: 242 (12.952KB) | Rcvd: 443 (73.207KB)
4505
4506
4507Error: can not open nmap file: www.a-teenz.com.txt
4508
4509
4510httprint v0.301 (beta) - web server fingerprinting tool
4511(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
4512http://net-square.com/httprint/
4513httprint@net-square.com
4514
4515Finger Printing on http://www.a-teenz.com:80/
4516Finger Printing Completed on http://www.a-teenz.com:80/
4517--------------------------------------------------
4518Host: www.a-teenz.com
4519Fingerprinting Error: Host/URL not found...
4520
4521--------------------------------------------------
4522
4523
4524
4525
4526 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
4527 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4528 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
4529 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4530 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
4531
4532 _/ User-Agent Tester ↵
4533 _/ AKA: Purple Pimp ↵
4534 _/ ChrisJohnRiley ↵
4535 _/ blog.c22.cc ↵
4536
4537 [>] Performing initial request and confirming stability
4538 [>] Using User-Agent string Mozilla/5.0
4539
4540 [ ] URL (ENTERED): http://www.a-teenz.com
4541 [ ] Response Code: 200 OK
4542 [ ] Date: Thu, 31 Aug 2017 06:05:49 GMT
4543 [ ] Server: Apache/2.2.16 (Debian)
4544 [ ] Accept-Ranges: bytes
4545 [ ] Vary: Accept-Encoding
4546 [ ] X-Frame-Options: SAMEORIGIN
4547 [ ] Connection: close
4548 [ ] Transfer-Encoding: chunked
4549 [ ] Content-Type: text/html
4550 [ ] Data (MD5): ed7d1080b3c8d68b8eaeeeb4310dc3f1
4551
4552 [1] Pass
4553 [2] Pass
4554 [3] Pass
4555
4556 [>] URL appears stable. Beginning test
4557
4558 [>] Using DEFAULT User-Agent Strings
4559
4560 [>] Using Crazy User-Agent Strings
4561 [>] Using Bot User-Agent Strings
4562
4563 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
4564
4565
4566 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
4567
4568
4569 [!] Data (MD5): 882a1f4ebc3bee3b5c7f49e2d059a0fe
4570
4571
4572 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
4573
4574
4575 [!] Data (MD5): 882a1f4ebc3bee3b5c7f49e2d059a0fe
4576
4577
4578 [>] User-Agent String : TrackBack/1.02
4579
4580
4581 [!] Data (MD5): 882a1f4ebc3bee3b5c7f49e2d059a0fe
4582
4583
4584B A S I C I N F O
4585=======================================================================================================================
4586
4587
4588
4589
4590[+] Site Title:
4591[+] IP address: 31.192.226.138
4592[+] Web Server: Apache/2.2.16 (Debian)
4593[+] CMS: Could Not Detect
4594[+] Cloudflare: Not Detected
4595[+] Robots File: Could NOT Find robots.txt!
4596
4597
4598
4599
4600W H O I S L O O K U P
4601===========================================================================================================================
4602
4603
4604
4605 Domain Name: A-TEENZ.COM
4606 Registry Domain ID: 1630831954_DOMAIN_COM-VRSN
4607 Registrar WHOIS Server: whois.enom.com
4608 Registrar URL: http://www.enom.com
4609 Updated Date: 2016-07-25T14:59:06Z
4610 Creation Date: 2010-12-17T21:50:46Z
4611 Registry Expiry Date: 2018-12-17T21:50:46Z
4612 Registrar: eNom, Inc.
4613 Registrar IANA ID: 48
4614 Registrar Abuse Contact Email:
4615 Registrar Abuse Contact Phone:
4616 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4617 Name Server: DNS1.REGISTRAR-SERVERS.COM
4618 Name Server: DNS2.REGISTRAR-SERVERS.COM
4619
4620
4621
4622
4623
4624G E O I P L O O K U P
4625============================================================================================================================
4626
4627
4628
4629[i] IP Address: 31.192.226.138
4630[i] Country: SE
4631[i] State: Hallands Lan
4632[i] City: Falkenberg
4633[i] Latitude: 56.898102
4634[i] Longitude: 12.501900
4635
4636
4637
4638
4639H T T P H E A D E R S
4640==========================================================================================================================
4641
4642
4643
4644
4645[i] HTTP/1.1 403 Forbidden
4646[i] Date: Thu, 31 Aug 2017 05:52:47 GMT
4647[i] Server: Apache/2.2.16 (Debian)
4648[i] Vary: Accept-Encoding
4649[i] Content-Length: 283
4650[i] Connection: close
4651[i] Content-Type: text/html; charset=iso-8859-1
4652
4653
4654
4655
4656D N S L O O K U P
4657======================================================================================================================
4658
4659
4660
4661a-teenz.com. 1799 IN A 31.192.226.138
4662a-teenz.com. 1800 IN NS dns1.registrar-servers.com.
4663a-teenz.com. 1800 IN NS dns3.registrar-servers.com.
4664a-teenz.com. 1800 IN NS dns5.registrar-servers.com.
4665a-teenz.com. 1800 IN NS dns2.registrar-servers.com.
4666a-teenz.com. 1800 IN NS dns4.registrar-servers.com.
4667a-teenz.com. 3601 IN SOA dns1.registrar-servers.com,. hostmaster.registrar-servers.com,. 2015072303 43200 3600 604800 3601
4668a-teenz.com. 1800 IN MX 10 wm.a-teenz.com.
4669
4670
4671
4672
4673S U B N E T C A L C U L A T I O N
4674=======================================================================================================================================
4675
4676
4677
4678Address = 31.192.226.138
4679Network = 31.192.226.138 / 32
4680Netmask = 255.255.255.255
4681Broadcast = not needed on Point-to-Point links
4682Wildcard Mask = 0.0.0.0
4683Hosts Bits = 0
4684Max. Hosts = 1 (2^0 - 0)
4685Host Range = { 31.192.226.138 - 31.192.226.138 }
4686
4687
4688
4689N M A P P O R T S C A N
4690===============================================================================================================================
4691
4692
4693
4694
4695Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 05:52 UTC
4696Nmap scan report for a-teenz.com (31.192.226.138)
4697Host is up (0.091s latency).
4698rDNS record for 31.192.226.138: 31-192-226-138-static.serverhotell.net
4699PORT STATE SERVICE VERSION
470021/tcp closed ftp
470122/tcp closed ssh
470223/tcp closed telnet
470325/tcp closed smtp
470480/tcp open http Apache httpd 2.2.16
4705110/tcp closed pop3
4706143/tcp closed imap
4707443/tcp open http Apache httpd 2.2.16
4708445/tcp closed microsoft-ds
47093389/tcp closed ms-wbt-server
4710
4711
4712S U B - D O M A I N F I N D E R
4713=====================================================================================================================================
4714
4715
4716
4717
4718[i] Total Subdomains Found : 3
4719
4720[+] Subdomain: a-teenz.com
4721[-] IP: 31.192.226.138
4722
4723[+] Subdomain: m.a-teenz.com
4724[-] IP: 192.64.119.191
4725
4726[+] Subdomain: www.a-teenz.com
4727[-] IP: 31.192.226.138
4728
4729
4730
4731
4732
4733
4734Crawling Types & Descriptions:
4735---------------------------------------------------------------------------
4736+ Target IP: 31.192.226.138
4737+ Target Hostname: 31.192.226.138
4738+ Target Port: 80
4739+ Start Time: 2017-08-31 01:53:58 (GMT-4)
4740---------------------------------------------------------------------------
4741+ Server: Apache/2.2.16 (Debian)
4742+ The anti-clickjacking X-Frame-Options header is not present.
4743+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
4744+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
4745+ Root page / redirects to: http://www.a-teenz.com/
4746+ Apache/2.2.16 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
4747+ Server leaks inodes via ETags, header found with file /manual/, inode: 120485518, size: 520, mtime: Sun Apr 1 02:40:25 2012
4748+ OSVDB-3092: /manual/: Web server manual found.
4749+ OSVDB-3268: /icons/: Directory indexing found.
4750+ OSVDB-3268: /manual/images/: Directory indexing found.
4751+ OSVDB-3233: /icons/README: Apache default file found.
4752+ 8649 requests: 0 error(s) and 9 item(s) reported on remote host
4753+ End Time: 2017-08-31 02:17:32 (GMT-4) (1414 seconds)
4754---------------------------------------------------------------------------
4755#######################################################################################################################################
4756Hostname www.nn-show-pics.com ISP Tele Asia Limited (AS133398)
4757Continent Europe Flag
4758LT
4759Country Lithuania Country Code LT (LTU)
4760Region 57 Local time 31 Aug 2017 10:05 EEST
4761Metropolis Unknown Postal Code 44001
4762City Kaunas Latitude 54.9
4763IP Address 45.123.190.121 Longitude 23.9
4764#######################################################################################################################################
4765nn-show-pics.com
4766
4767
4768 Domain Name: NN-SHOW-PICS.COM
4769 Registry Domain ID: 1709702231_DOMAIN_COM-VRSN
4770 Registrar WHOIS Server: whois.nic.ru
4771 Registrar URL: http://nic.ru
4772 Updated Date: 2017-06-01T19:25:21Z
4773 Creation Date: 2012-03-29T01:44:16Z
4774 Registry Expiry Date: 2018-03-29T01:44:16Z
4775 Registrar: Regional Network Information Center, JSC dba RU-CENTER
4776 Registrar IANA ID: 463
4777 Registrar Abuse Contact Email: tld-abuse@nic.ru
4778 Registrar Abuse Contact Phone: +7 (495) 994-46-01
4779 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4780 Name Server: NS1.GEOSCALING.COM
4781 Name Server: NS2.GEOSCALING.COM
4782 Name Server: NS3.GEOSCALING.COM
4783 Name Server: NS4.GEOSCALING.COM
4784 Name Server: NS5.GEOSCALING.COM
4785
4786Domain Name: NN-SHOW-PICS.COM
4787Registry Domain ID: 1709702231_DOMAIN_COM-VRSN
4788Registrar WHOIS Server: whois.nic.ru
4789Registrar URL: http://www.nic.ru
4790Creation Date: 2012-03-29T01:44:16Z
4791Registrar Registration Expiration Date: 2018-03-28T21:00:00Z
4792Registrar: Regional Network Information Center, JSC dba RU-CENTER
4793Registrar IANA ID: 463
4794Registrar Abuse Contact Email: tld-abuse@nic.ru
4795Registrar Abuse Contact Phone: +7.4959944601
4796Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4797Registry Registrant ID:
4798Registrant Name: dmytro cimbalo
4799Registrant Organization: dmytro cimbalo
4800Registrant Street: Kommunarov, 268
4801Registrant City: kishinev
4802Registrant Postal Code: 222
4803Registrant Country: MD
4804Registrant Phone: +373.22574084
4805Registrant Phone Ext:
4806Registrant Email: dmytrocimbalo@mail.ru
4807Registry Admin ID:
4808Admin Name: dmytro cimbalo
4809Admin Organization: dmytro cimbalo
4810Admin Street: Kommunarov, 268
4811Admin City: kishinev
4812Admin Postal Code: 222
4813Admin Country: MD
4814Admin Phone: +373.22574084
4815Admin Phone Ext:
4816Admin Email: dmytrocimbalo@mail.ru
4817Registry Tech ID:
4818Tech Name: dmytro cimbalo
4819Tech Organization: dmytro cimbalo
4820Tech Street: Kommunarov, 268
4821Tech City: kishinev
4822Tech Postal Code: 222
4823Tech Country: MD
4824Tech Phone: +373.22574084
4825Tech Phone Ext:
4826Tech Email: dmytrocimbalo@mail.ru
4827Name Server: ns1.geoscaling.com
4828Name Server: ns2.geoscaling.com
4829Name Server: ns3.geoscaling.com
4830Name Server: ns4.geoscaling.com
4831Name Server: ns5.geoscaling.com
4832
4833
4834Running:
4835 traceroute -T -O info -i eth0 nn-show-pics.com
4836traceroute to nn-show-pics.com (45.123.190.121), 30 hops max, 60 byte packets
4837 1 gateway (192.168.1.254) 0.451 ms 0.631 ms 0.902 ms
4838 2 10.135.18.1 (10.135.18.1) 12.779 ms 14.150 ms 18.075 ms
4839 3 CHCNIL23BR01.bb.telus.com (154.11.11.121) 32.167 ms 32.234 ms 32.283 ms
4840 4 VANCBC01GR01.bb.telus.com (154.11.10.25) 33.366 ms 33.507 ms 33.648 ms
4841 5 TenGE0-0-0-7.br02.frf06.pccwbtn.net (63.218.232.45) 131.465 ms 121.320 ms TenGE0-0-0-23.br02.frf06.pccwbtn.net (63.218.232.61) 118.982 ms
4842 6 63-218-233-6.static.pccwglobal.net (63.218.233.6) 120.943 ms 129.405 ms 118.564 ms
4843 7 mskn06.mskn202.transtelecom.net (188.43.9.190) 163.236 ms 166.711 ms 204.692 ms
4844 8 * * *
4845 9 * * *
484610 * * *
484711 ddos-guard.net (185.129.101.85) 176.634 ms 165.761 ms 163.966 ms
484812 eesmaarasti.net (45.123.190.121) <syn,ack> 188.847 ms 188.906 ms 201.112 ms
4849
4850
4851
4852
4853Host's addresses:
4854__________________
4855
4856nn-show-pics.com. 84 IN A 45.123.190.121
4857
4858
4859Name Servers:
4860______________
4861
4862ns2.geoscaling.com. 300 IN A 91.121.64.153
4863ns5.geoscaling.com. 300 IN A 91.121.64.153
4864ns1.geoscaling.com. 300 IN A 91.121.64.153
4865ns3.geoscaling.com. 300 IN A 91.121.64.153
4866
4867Brute forcing with dns.txt:
4868____________________________
4869
4870www.nn-show-pics.com. 300 IN CNAME nn-show-pics.com.
4871nn-show-pics.com. 300 IN A 45.123.190.121
4872
4873
4874Performing recursion:
4875______________________
4876
4877
4878 ---- Checking subdomains NS records ----
4879nn-show-pics.com. 6949 IN NS ns5.geoscaling.com.
4880nn-show-pics.com. 6949 IN NS ns3.geoscaling.com.
4881nn-show-pics.com. 6949 IN NS ns1.geoscaling.com.
4882nn-show-pics.com. 6949 IN NS ns2.geoscaling.com.
4883
4884 Can't perform recursion no NS records.
4885
4886
4887nn-show-pics.com class C netranges:
4888____________________________________
4889
4890 45.123.190.0/24
4891
4892
4893www.nn-show-pics.com
4894IP address #1: 45.123.190.121
4895
4896[+] 1 (sub)domains and 1 IP address(es) found
4897[+] completion time: 160 second(s)
4898
4899
4900Tracing to nn-show-pics.com[a] via 192.168.1.254, maximum of 3 retries
4901192.168.1.254 (192.168.1.254) Got answer
4902
4903
4904WhatWeb report for http://nn-show-pics.com
4905Status : 200 OK
4906Title : Angel BBS| Nymphets | Underage girls | no nudes BBS
4907IP : <Unknown>
4908Country : <Unknown>
4909
4910Summary : nginx[1.10.2], Script[text/Javascript,text/javascript], HTTPServer[nginx/1.10.2]
4911
4912Detected Plugins:
4913[ HTTPServer ]
4914 HTTP server header string. This plugin also attempts to
4915 identify the operating system from the server header.
4916
4917 String : nginx/1.10.2 (from server string)
4918
4919[ Script ]
4920 This plugin detects instances of script HTML elements and
4921 returns the script language/type.
4922
4923 String : text/Javascript,text/javascript
4924
4925[ nginx ]
4926 Nginx (Engine-X) is a free, open-source, high-performance
4927 HTTP server and reverse proxy, as well as an IMAP/POP3
4928 proxy server.
4929
4930 Version : 1.10.2
4931 Website : http://nginx.net/
4932
4933HTTP Headers:
4934 HTTP/1.1 200 OK
4935 Server: nginx/1.10.2
4936 Date: Thu, 31 Aug 2017 04:16:02 GMT
4937 Content-Type: text/html
4938 Content-Length: 7859
4939 Connection: close
4940 Accept-Ranges: bytes
4941 Vary: Accept-Encoding,User-Agent
4942 Content-Encoding: gzip
4943
4944
4945[+] Hosts found in search engines:
4946------------------------------------
4947[-] Resolving hostnames IPs...
494845.123.190.121:www.nn-show-pics.com
4949
4950
4951
4952 ^ ^
4953 _ __ _ ____ _ __ _ _ ____
4954 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
4955 | V V // o // _/ | V V // 0 // 0 // _/
4956 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
4957 <
4958 ...'
4959
4960 WAFW00F - Web Application Firewall Detection Tool
4961
4962 By Sandro Gauci && Wendel G. Henrique
4963
4964Checking http://nn-show-pics.com
4965Generic Detection results:
4966No WAF detected by the generic detection
4967Number of requests: 13
4968
4969
4970DNS Servers for nn-show-pics.com:
4971 ns5.geoscaling.com
4972 ns2.geoscaling.com
4973 ns1.geoscaling.com
4974 ns3.geoscaling.com
4975
4976Trying zone transfer first...
4977 Testing ns5.geoscaling.com
4978 Request timed out or transfer not allowed.
4979 Testing ns2.geoscaling.com
4980 Request timed out or transfer not allowed.
4981 Testing ns1.geoscaling.com
4982 Request timed out or transfer not allowed.
4983 Testing ns3.geoscaling.com
4984 Request timed out or transfer not allowed.
4985
4986Unsuccessful in zone transfer (it was worth a shot)
4987Okay, trying the good old fashioned way... brute force
4988
4989Checking for wildcard DNS...
4990Nope. Good.
4991Now performing 2280 test(s)...
499245.123.190.121 www.nn-show-pics.com
4993
4994Subnets found (may want to probe here using nmap or unicornscan):
4995 45.123.190.0-255 : 1 hostnames found.
4996
4997
4998Checking for HTTP-Loadbalancing [Date]: 04:21:52, 04:21:53, 04:21:53, 04:21:54, 04:21:54, 04:21:55, 04:21:56, 04:21:56, 04:21:57, 04:21:57, 04:21:58, 04:21:59, 04:21:59, 04:22:00, 04:22:00, 04:22:01, 04:22:01, 04:22:03, 04:22:04, 04:22:05, 04:22:05, 04:22:06, 04:22:06, 04:22:07, 04:22:08, 04:22:08, 04:22:09, 04:22:10, 04:22:11, 04:22:11, 04:22:12, 04:22:13, 04:22:14, 04:22:15, 04:22:16, 04:22:17, 04:22:17, 04:22:19, 04:22:20, 04:22:20, 04:22:22, 04:22:23, 04:22:24, 04:22:24, 04:22:25, 04:22:27, 04:22:29, 04:22:30, 04:22:32, 04:22:33, NOT FOUND
4999
5000Checking for HTTP-Loadbalancing [Diff]: FOUND
5001< HTTP/1.1 400 Bad Request
5002> HTTP/1.1 502 Bad Gateway
5003< Content-Type: text/html; charset=iso-8859-1
5004> Content-Type: text/html
5005> Content-Length: 173
5006
5007nn-show-pics.com does Load-balancing. Found via Methods: HTTP[Diff]
5008
5009
5010
5011Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
5012
5013 ----------------------------------------------------------
5014| Scan Information |
5015 ----------------------------------------------------------
5016
5017Mode ..................... VRFY
5018Worker Processes ......... 5
5019Usernames file ........... users.txt
5020Target count ............. 1
5021Username count ........... 494
5022Target TCP port .......... 25
5023Query timeout ............ 5 secs
5024Target domain ............
5025
5026######## Scan started at Thu Aug 31 03:23:22 2017 #########
5027######## Scan completed at Thu Aug 31 03:31:37 2017 #########
50280 results.
5029
5030494 queries in 495 seconds (1.0 queries / sec)
5031
5032
5033
5034Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-31 03:31 EDT
5035NSE: Loaded 146 scripts for scanning.
5036NSE: Script Pre-scanning.
5037Initiating NSE at 03:31
5038Completed NSE at 03:31, 0.00s elapsed
5039Initiating NSE at 03:31
5040Completed NSE at 03:31, 0.00s elapsed
5041Failed to resolve "nn-show-pics.com.txt".
5042Initiating Parallel DNS resolution of 1 host. at 03:31
5043Completed Parallel DNS resolution of 1 host. at 03:31, 0.93s elapsed
5044Initiating SYN Stealth Scan at 03:31
5045Scanning nn-show-pics.com (45.123.190.121) [100 ports]
5046Discovered open port 22/tcp on 45.123.190.121
5047Discovered open port 80/tcp on 45.123.190.121
5048Completed SYN Stealth Scan at 03:31, 4.30s elapsed (100 total ports)
5049Initiating Service scan at 03:31
5050Scanning 2 services on nn-show-pics.com (45.123.190.121)
5051Completed Service scan at 03:31, 6.57s elapsed (2 services on 1 host)
5052Initiating OS detection (try #1) against nn-show-pics.com (45.123.190.121)
5053Retrying OS detection (try #2) against nn-show-pics.com (45.123.190.121)
5054adjust_timeouts2: packet supposedly had rtt of -106978 microseconds. Ignoring time.
5055adjust_timeouts2: packet supposedly had rtt of -106978 microseconds. Ignoring time.
5056Initiating Traceroute at 03:31
5057Completed Traceroute at 03:31, 3.02s elapsed
5058Initiating Parallel DNS resolution of 9 hosts. at 03:31
5059Completed Parallel DNS resolution of 9 hosts. at 03:32, 5.51s elapsed
5060NSE: Script scanning 45.123.190.121.
5061Initiating NSE at 03:32
5062Completed NSE at 03:32, 35.47s elapsed
5063Initiating NSE at 03:32
5064Completed NSE at 03:32, 0.00s elapsed
5065Nmap scan report for nn-show-pics.com (45.123.190.121)
5066Host is up (0.18s latency).
5067rDNS record for 45.123.190.121: eesmaarasti.net
5068Not shown: 92 closed ports
5069PORT STATE SERVICE VERSION
507022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
5071| ssh-hostkey:
5072| 1024 56:1f:ed:a4:fc:ae:23:e0:3b:37:8e:46:4a:f2:aa:e3 (DSA)
5073|_ 2048 d0:4f:06:cf:bd:fa:97:a5:6e:da:5d:cd:41:00:cd:c2 (RSA)
507425/tcp filtered smtp
507580/tcp open http nginx 1.10.2
5076| http-methods:
5077|_ Supported Methods: POST OPTIONS HEAD GET
5078|_http-server-header: nginx/1.10.2
5079|_http-title: Angel BBS| Nymphets | Underage girls | no nudes BBS
5080135/tcp filtered msrpc
5081139/tcp filtered netbios-ssn
5082445/tcp filtered microsoft-ds
5083465/tcp filtered smtps
5084587/tcp filtered submission
5085Aggressive OS guesses: Linux 2.6.39 (95%), Linux 2.6.32 (95%), Linux 3.4 (95%), WatchGuard Fireware 11.8 (95%), Synology DiskStation Manager 5.1 (94%), Linux 3.10 (94%), Linux 3.1 - 3.2 (94%), Linux 2.6.32 or 3.10 (94%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.2 - 3.8 (91%)
5086No exact OS matches for host (test conditions non-ideal).
5087Uptime guess: 9.888 days (since Mon Aug 21 06:13:59 2017)
5088Network Distance: 12 hops
5089TCP Sequence Prediction: Difficulty=256 (Good luck!)
5090IP ID Sequence Generation: All zeros
5091
5092TRACEROUTE (using port 53/tcp)
5093HOP RTT ADDRESS
50941 109.42 ms 10.13.0.1
50952 110.55 ms 37.187.24.252
50963 110.51 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
50974 219.92 ms 10.95.33.8
50985 119.06 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
50996 220.03 ms be100-1166.var-5-a9.pl.eu (91.121.215.191)
51007 220.09 ms vl2.var-6-a72.pl.eu (91.121.215.209)
51018 ... 10
510211 220.21 ms ddos-guard.net (185.129.101.85)
510312 202.17 ms eesmaarasti.net (45.123.190.121)
5104
5105NSE: Script Post-scanning.
5106Initiating NSE at 03:32
5107Completed NSE at 03:32, 0.00s elapsed
5108Initiating NSE at 03:32
5109Completed NSE at 03:32, 0.00s elapsed
5110Read data files from: /usr/bin/../share/nmap
5111OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5112Nmap done: 1 IP address (1 host up) scanned in 62.53 seconds
5113 Raw packets sent: 232 (12.108KB) | Rcvd: 238 (20.584KB)
5114
5115
5116Error: can not open nmap file: nn-show-pics.com.txt
5117
5118
5119httprint v0.301 (beta) - web server fingerprinting tool
5120(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
5121http://net-square.com/httprint/
5122httprint@net-square.com
5123
5124Finger Printing on http://nn-show-pics.com:80/
5125Finger Printing Completed on http://nn-show-pics.com:80/
5126--------------------------------------------------
5127Host: nn-show-pics.com
5128Fingerprinting Error: Host/URL not found...
5129
5130--------------------------------------------------
5131
5132
5133
5134
5135 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
5136 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5137 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
5138 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5139 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
5140
5141 _/ User-Agent Tester ↵
5142 _/ AKA: Purple Pimp ↵
5143 _/ ChrisJohnRiley ↵
5144 _/ blog.c22.cc ↵
5145
5146 [>] Performing initial request and confirming stability
5147 [>] Using User-Agent string Mozilla/5.0
5148
5149 [ ] URL (ENTERED): http://nn-show-pics.com
5150 [ ] Response Code: 200 OK
5151 [ ] Server: nginx/1.10.2
5152 [ ] Date: Thu, 31 Aug 2017 04:33:06 GMT
5153 [ ] Content-Type: text/html
5154 [ ] Transfer-Encoding: chunked
5155 [ ] Connection: close
5156 [ ] Accept-Ranges: bytes
5157 [ ] Vary: Accept-Encoding,User-Agent
5158 [ ] Data (MD5): 04ed8714126193d0d9a93b11a49edf4a
5159
5160 [1] Pass
5161 [2] Pass
5162 [3] Pass
5163
5164 [>] URL appears stable. Beginning test
5165
5166 [>] Using DEFAULT User-Agent Strings
5167
5168 [>] Using Crazy User-Agent Strings
5169 [>] Using Bot User-Agent Strings
5170
5171 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
5172
5173
5174 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
5175
5176
5177 [!] Data (MD5): 4a9a20678a05538fc31d343555967d8c
5178
5179
5180 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
5181
5182
5183 [!] Data (MD5): 152d7c44a61b4aa4bcd96fc696a93f59
5184
5185
5186 [>] User-Agent String : TrackBack/1.02
5187
5188
5189 [!] Data (MD5): 8269337126534cb9e9efdf3a05003f2b
5190
5191
5192 [>] User-Agent String : wispr
5193
5194
5195 [!] Data (MD5): e631c2af0c32458a7b220116a33a00ce
5196
5197
5198 [>] User-Agent String : EMPTY USER-AGENT STRING!
5199
5200
5201 [!] Data (MD5): c720e99bdbd2308bb9dd9eb6156d39bd
5202
5203
5204 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
5205
5206
5207 [!] Data (MD5): a4a9a6934380f9a67bf0f81ce5700cca
5208
5209
5210 [>] User-Agent String : Googlebot-Image/1.0
5211
5212
5213 [!] Data (MD5): a5a1757c7cb56aebf928fd8465666a4e
5214
5215
5216 [>] User-Agent String : Mediapartners-Google
5217
5218
5219 [!] Data (MD5): 72e8c884b672b49238c58f66b15a0f22
5220
5221
5222 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
5223
5224
5225 [!] Data (MD5): 72e76889307c31a33bc8b4eb206e916a
5226
5227
5228 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
5229
5230
5231 [!] Data (MD5): 094cf14c6fe4b249ec51ed01f8e6b45c
5232
5233
5234 [>] User-Agent String : mmcrawler
5235
5236
5237 [!] Data (MD5): 73d6ae48594a75734cc7846837cfe22e
5238
5239
5240 [>] Checks completed... try enabling VERBOSE mode for more detailed output
5241
5242 [>] That's all folks... Fo' Shizzle!
5243i] Scanning Site: http://nn-show-pics.com
5244
5245
5246
5247B A S I C I N F O
5248=======================================================================================================================
5249
5250
5251
5252
5253[+] Site Title: Angel BBS| Nymphets | Underage girls | no nudes BBS
5254[+] IP address: 45.123.190.121
5255[+] Web Server: nginx/1.10.2
5256[+] CMS: Could Not Detect
5257[+] Cloudflare: Not Detected
5258[+] Robots File: Could NOT Find robots.txt!
5259
5260
5261
5262
5263W H O I S L O O K U P
5264===========================================================================================================================
5265
5266
5267
5268 Domain Name: NN-SHOW-PICS.COM
5269 Registry Domain ID: 1709702231_DOMAIN_COM-VRSN
5270 Registrar WHOIS Server: whois.nic.ru
5271 Registrar URL: http://nic.ru
5272 Updated Date: 2017-06-01T19:25:21Z
5273 Creation Date: 2012-03-29T01:44:16Z
5274 Registry Expiry Date: 2018-03-29T01:44:16Z
5275 Registrar: Regional Network Information Center, JSC dba RU-CENTER
5276 Registrar IANA ID: 463
5277 Registrar Abuse Contact Email: tld-abuse@nic.ru
5278 Registrar Abuse Contact Phone: +7 (495) 994-46-01
5279 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5280 Name Server: NS1.GEOSCALING.COM
5281 Name Server: NS2.GEOSCALING.COM
5282 Name Server: NS3.GEOSCALING.COM
5283 Name Server: NS4.GEOSCALING.COM
5284 Name Server: NS5.GEOSCALING.COM
5285
5286
5287
5288
5289G E O I P L O O K U P
5290============================================================================================================================
5291
5292
5293
5294[i] IP Address: 45.123.190.121
5295[i] Country: LT
5296[i] State: Kauno Apskritis
5297[i] City: Kaunas
5298[i] Latitude: 54.900002
5299[i] Longitude: 23.900000
5300
5301
5302
5303
5304H T T P H E A D E R S
5305==========================================================================================================================
5306
5307
5308
5309
5310[i] HTTP/1.1 200 OK
5311[i] Server: nginx/1.10.2
5312[i] Date: Thu, 31 Aug 2017 04:09:12 GMT
5313[i] Content-Type: text/html
5314[i] Connection: close
5315[i] Accept-Ranges: bytes
5316[i] Vary: Accept-Encoding,User-Agent
5317
5318
5319S U B N E T C A L C U L A T I O N
5320=======================================================================================================================================
5321
5322
5323
5324Address = 45.123.190.121
5325Network = 45.123.190.121 / 32
5326Netmask = 255.255.255.255
5327Broadcast = not needed on Point-to-Point links
5328Wildcard Mask = 0.0.0.0
5329Hosts Bits = 0
5330Max. Hosts = 1 (2^0 - 0)
5331Host Range = { 45.123.190.121 - 45.123.190.121 }
5332
5333
5334
5335N M A P P O R T S C A N
5336===============================================================================================================================
5337
5338
5339
5340
5341Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 07:09 UTC
5342Nmap scan report for nn-show-pics.com (45.123.190.121)
5343Host is up (0.16s latency).
5344rDNS record for 45.123.190.121: eesmaarasti.net
5345PORT STATE SERVICE VERSION
534621/tcp closed ftp
534722/tcp open ssh OpenSSH 5.3 (protocol 2.0)
534823/tcp closed telnet
534925/tcp closed smtp
535080/tcp open http nginx 1.10.2
5351110/tcp closed pop3
5352143/tcp closed imap
5353443/tcp closed https
5354445/tcp closed microsoft-ds
53553389/tcp closed ms-wbt-server
5356
5357
5358S U B - D O M A I N F I N D E R
5359=====================================================================================================================================
5360
5361
5362
5363
5364[i] Total Subdomains Found : 1
5365
5366[+] Subdomain: nn-show-pics.com
5367[-] IP: 185.151.245.9
5368
5369
5370
5371
5372--------------------------------------------------------------------------
5373+ Target IP: 45.123.190.121
5374+ Target Hostname: 45.123.190.121
5375+ Target Port: 80
5376+ Start Time: 2017-08-31 03:10:08 (GMT-4)
5377---------------------------------------------------------------------------
5378+ Server: nginx/1.10.2
5379+ Server leaks inodes via ETags, header found with file /, fields: 0x2c 0x5578fffb0f6bc
5380+ The anti-clickjacking X-Frame-Options header is not present.
5381+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
5382+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
5383+ Allowed HTTP Methods: POST, OPTIONS, HEAD, GET
5384+ Retrieved x-powered-by header: PHP/5.4.45
5385+ Uncommon header 'x-dns-prefetch-control' found, with contents: off
5386+ Uncommon header 'x-robots-tag' found, with contents: noindex, nofollow
5387+ Uncommon header 'x-ob_mode' found, with contents: 1
5388+ OSVDB-3092: /phpMyAdmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
5389+ OSVDB-3092: /phpmyadmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
5390+ OSVDB-3092: /pma/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
5391+ Cookie SQMSESSID created without the httponly flag
5392+ OSVDB-3093: /squirrelmail/src/read_body.php: SquirrelMail found
5393+ OSVDB-3268: /icons/: Directory indexing found.
5394+ ERROR: Error limit (20) reached for host, giving up. Last error:
5395+ Scan terminated: 2 error(s) and 15 item(s) reported on remote host
5396+ End Time: 2017-08-31 03:54:03 (GMT-4) (2635 seconds)
5397---------------------------------------------------------------------------
5398#######################################################################################################################################
5399Hostname www.bad-young-girls.com ISP WZ Communications Inc. (AS40824)
5400Continent North America Flag
5401US
5402Country United States Country Code US (USA)
5403Region FL Local time 31 Aug 2017 03:45 EDT
5404Metropolis* Miami-Ft. Lauderdale Postal Code 33301
5405City Fort Lauderdale Latitude 26.121
5406IP Address 204.155.148.235 Longitude -80.127
5407######################################################################################################################################
5408bad-young-girls.com
5409
5410
5411 Domain Name: BAD-YOUNG-GIRLS.COM
5412 Registry Domain ID: 1579842676_DOMAIN_COM-VRSN
5413 Registrar WHOIS Server: whois.enom.com
5414 Registrar URL: http://www.enom.com
5415 Updated Date: 2016-12-09T13:58:09Z
5416 Creation Date: 2009-12-24T11:30:15Z
5417 Registry Expiry Date: 2017-12-24T11:30:15Z
5418 Registrar: eNom, Inc.
5419 Registrar IANA ID: 48
5420 Registrar Abuse Contact Email:
5421 Registrar Abuse Contact Phone:
5422 Domain Status: ok https://icann.org/epp#ok
5423 Name Server: NS-E.EST-HOST.COM
5424 Name Server: NS-F.EST-HOST.COM
5425 Name Server: NS2-E.EST-HOST.COM
5426 Name Server: NS2-F.EST-HOST.COM
5427
5428Domain Name: BAD-YOUNG-GIRLS.COM
5429Registry Domain ID: 1579842676_DOMAIN_COM-VRSN
5430Registrar WHOIS Server: whois.enom.com
5431Registrar URL: www.enom.com
5432Updated Date: 2016-11-25T05:43:57.00Z
5433Creation Date: 2009-12-24T11:30:00.00Z
5434Registrar Registration Expiration Date: 2017-12-24T11:30:15.00Z
5435Registrar: ENOM, INC.
5436Registrar IANA ID: 48
5437Reseller: NAMECHEAP.COM
5438Domain Status: ok https://www.icann.org/epp#ok
5439Registry Registrant ID:
5440Registrant Name: JAMES NEIL
5441Registrant Organization: EST HOLDING CORP.
5442Registrant Street: 39 CARLISLE LANE
5443Registrant City: SAVANNAH
5444Registrant State/Province: GA
5445Registrant Postal Code: 31419
5446Registrant Country: US
5447Registrant Phone: +1.7029531854
5448Registrant Phone Ext:
5449Registrant Fax: +1.7029531854
5450Registrant Fax Ext:
5451Registrant Email: WEBMASTER@SM-RGS.COM
5452Registry Admin ID:
5453Admin Name: JAMES NEIL
5454Admin Organization: EST HOLDING CORP.
5455Admin Street: 39 CARLISLE LANE
5456Admin City: SAVANNAH
5457Admin State/Province: GA
5458Admin Postal Code: 31419
5459Admin Country: US
5460Admin Phone: +1.7029531854
5461Admin Phone Ext:
5462Admin Fax: +1.7029531854
5463Admin Fax Ext:
5464Admin Email: WEBMASTER@SM-RGS.COM
5465Registry Tech ID:
5466Tech Name: JAMES NEIL
5467Tech Organization: EST HOLDING CORP.
5468Tech Street: 39 CARLISLE LANE
5469Tech City: SAVANNAH
5470Tech State/Province: GA
5471Tech Postal Code: 31419
5472Tech Country: US
5473Tech Phone: +1.7029531854
5474Tech Phone Ext:
5475Tech Fax: +1.7029531854
5476Tech Fax Ext:
5477Tech Email: WEBMASTER@SM-RGS.COM
5478Name Server: NS-E.EST-HOST.COM
5479Name Server: NS-F.EST-HOST.COM
5480Name Server: NS2-E.EST-HOST.COM
5481Name Server: NS2-F.EST-HOST.COM
5482DNSSEC: unSigned
5483Registrar Abuse Contact Email: abuse@enom.com
5484Registrar Abuse Contact Phone: +1.4252982646
5485
5486; <<>> DiG 9.10.3-P4-Debian <<>> bad-young-girls.com any
5487;; global options: +cmd
5488;; Got answer:
5489;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1549
5490;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
5491
5492;; OPT PSEUDOSECTION:
5493; EDNS: version: 0, flags:; udp: 4096
5494;; QUESTION SECTION:
5495;bad-young-girls.com. IN ANY
5496
5497;; ANSWER SECTION:
5498bad-young-girls.com. 3361 IN A 204.155.148.235
5499bad-young-girls.com. 3361 IN NS ns2-e.est-host.com.
5500bad-young-girls.com. 3361 IN NS ns-f.est-host.com.
5501bad-young-girls.com. 3361 IN NS ns2-f.est-host.com.
5502bad-young-girls.com. 3361 IN NS ns-e.est-host.com.
5503
5504;; Query time: 8 msec
5505;; SERVER: 192.168.1.254#53(192.168.1.254)
5506;; WHEN: Thu Aug 31 03:48:14 EDT 2017
5507;; MSG SIZE rcvd: 151
5508
5509
5510
5511;; Connection to 192.168.1.254#53(192.168.1.254) for bad-young-girls.com failed: connection refused.
5512Host bad-young-girls.com not found: 9(NOTAUTH)
5513; Transfer failed.
5514
5515
5516Please type the name of your network interface Example: eth0
5517eth0
5518
5519Running:
5520 traceroute -T -O info -i eth0 bad-young-girls.com
5521traceroute to bad-young-girls.com (204.155.148.235), 30 hops max, 60 byte packets
5522 1 gateway (192.168.1.254) 0.552 ms 0.719 ms 0.870 ms
5523 2 10.135.18.1 (10.135.18.1) 7.248 ms 8.147 ms 8.208 ms
5524 3 75.154.223.222 (75.154.223.222) 29.920 ms 30.024 ms 30.063 ms
5525 4 Global-Reach.plalca01gr00.bb.telus.com (154.11.3.138) 30.420 ms 30.589 ms 30.846 ms
5526 5 hu-1-3-0-3-cr02.newyork.ny.ibone.comcast.net (68.86.83.101) 31.476 ms hu-1-3-0-8-cr02.newyork.ny.ibone.comcast.net (68.86.84.241) 33.490 ms hu-1-3-0-3-cr02.newyork.ny.ibone.comcast.net (68.86.83.101) 33.557 ms
5527 6 be-10203-cr01.newark.nj.ibone.comcast.net (68.86.85.185) 33.621 ms 30.903 ms 30.937 ms
5528 7 be-10102-cr02.ashburn.va.ibone.comcast.net (68.86.85.161) 35.296 ms 34.630 ms 34.726 ms
5529 8 be-10114-cr02.56marietta.ga.ibone.comcast.net (68.86.85.10) 48.726 ms 49.301 ms 48.663 ms
5530 9 be-11424-cr02.dallas.tx.ibone.comcast.net (68.86.85.22) 69.200 ms 69.246 ms 69.279 ms
553110 be-12441-pe01.1950stemmons.tx.ibone.comcast.net (68.86.89.206) 67.723 ms 68.938 ms 68.999 ms
553211 50.248.119.34 (50.248.119.34) 61.465 ms 50.248.117.158 (50.248.117.158) 61.642 ms 50.248.119.34 (50.248.119.34) 61.284 ms
553312 204.155.148.235 (204.155.148.235) <syn,ack> 60.857 ms 60.938 ms 61.077 ms
5534
5535----- bad-young-girls.com -----
5536
5537
5538Host's addresses:
5539__________________
5540
5541bad-young-girls.com. 3346 IN A 204.155.148.235
5542
5543
5544Name Servers:
5545______________
5546
5547ns2-f.est-host.com. 3600 IN A 204.155.148.232
5548ns-f.est-host.com. 3600 IN A 204.155.144.130
5549ns2-e.est-host.com. 3600 IN A 204.155.148.232
5550ns-e.est-host.com. 3600 IN A 204.155.144.130
5551
5552
5553Mail (MX) Servers:
5554___________________
5555
5556
5557www.bad-young-girls.com. 3319 IN CNAME bad-young-girls.com.
5558bad-young-girls.com. 3319 IN A 204.155.148.235
5559www2.bad-young-girls.com. 3600 IN A 204.155.148.235
5560
5561
5562Performing recursion:
5563______________________
5564
5565
5566 ---- Checking subdomains NS records ----
5567bad-young-girls.com. 3318 IN NS ns2-f.est-host.com.
5568bad-young-girls.com. 3318 IN NS ns2-e.est-host.com.
5569bad-young-girls.com. 3318 IN NS ns-e.est-host.com.
5570bad-young-girls.com. 3318 IN NS ns-f.est-host.com.
5571
5572 Can't perform recursion no NS records.
5573
5574
5575bad-young-girls.com class C netranges:
5576_______________________________________
5577
5578 204.155.148.0/24
5579
5580
5581Performing reverse lookup on 256 ip addresses:
5582_______________________________________________
5583
5584
55850 results out of 256 IP addresses.
5586
5587
5588bad-young-girls.com ip blocks:
5589_______________________________
5590
5591
5592done.
5593
5594
5595dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
5596
5597[+] searching (sub)domains for bad-young-girls.com using built-in wordlist
5598[+] using maximum random delay of 10 millisecond(s) between requests
5599
5600www.bad-young-girls.com
5601IP address #1: 204.155.148.235
5602
5603www2.bad-young-girls.com
5604IP address #1: 204.155.148.235
5605
5606[+] 2 (sub)domains and 2 IP address(es) found
5607[+] completion time: 116 second(s)
5608
5609
5610Tracing to bad-young-girls.com[a] via 192.168.1.254, maximum of 3 retries
5611192.168.1.254 (192.168.1.254) Got answer
5612
5613
5614WhatWeb report for http://bad-young-girls.com
5615Status : 302 Found
5616Title : 302 Found
5617IP : 204.155.148.235
5618Country : UNITED STATES, US
5619
5620Summary : Perl[5.18.2], RedirectLocation[http://bad-young-girls.com/index.htm?FabzNDfQqD1i5Mbbbnxo], HTTPServer[FreeBSD][Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2], Apache[2.2.26][mod_perl/2.0.8,mod_ssl/2.2.26], OpenSSL[1.0.1f], Cookies[bothub_id,bothub_ip_addr,bothub_sec_code]
5621
5622Detected Plugins:
5623[ Apache ]
5624 The Apache HTTP Server Project is an effort to develop and
5625 maintain an open-source HTTP server for modern operating
5626 systems including UNIX and Windows NT. The goal of this
5627 project is to provide a secure, efficient and extensible
5628 server that provides HTTP services in sync with the current
5629 HTTP standards.
5630
5631 Version : 2.2.26 (from HTTP Server Header)
5632 Module : mod_perl/2.0.8,mod_ssl/2.2.26
5633 Google Dorks: (3)
5634 Website : http://httpd.apache.org/
5635
5636[ Cookies ]
5637 Display the names of cookies in the HTTP headers. The
5638 values are not returned to save on space.
5639
5640 String : bothub_ip_addr
5641 String : bothub_id
5642 String : bothub_sec_code
5643
5644[ HTTPServer ]
5645 HTTP server header string. This plugin also attempts to
5646 identify the operating system from the server header.
5647
5648 OS : FreeBSD
5649 String : Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2 (from server string)
5650
5651[ OpenSSL ]
5652 The OpenSSL Project is a collaborative effort to develop a
5653 robust, commercial-grade, full-featured, and Open Source
5654 toolkit implementing the Secure Sockets Layer (SSL v2/v3)
5655 and Transport Layer Security (TLS v1) protocols as well as
5656 a full-strength general purpose cryptography library.
5657
5658 Version : 1.0.1f
5659 Website : http://www.openssl.org/
5660
5661[ Perl ]
5662 Perl is a highly capable, feature-rich programming language
5663 with over 22 years of development.
5664
5665 Version : 5.18.2
5666 Website : http://www.perl.org/
5667
5668[ RedirectLocation ]
5669 HTTP Server string location. used with http-status 301 and
5670 302
5671
5672 String : http://bad-young-girls.com/index.htm?FabzNDfQqD1i5Mbbbnxo (from location)
5673
5674HTTP Headers:
5675 HTTP/1.1 302 Found
5676 Date: Thu, 31 Aug 2017 07:52:10 GMT
5677 Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
5678 Set-Cookie: bothub_ip_addr=87.98.166.29; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
5679 Set-Cookie: bothub_id=10527371654219340833; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
5680 Set-Cookie: bothub_sec_code=FabzNDfQqD1i5Mbbbnxo; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
5681 Location: http://bad-young-girls.com/index.htm?FabzNDfQqD1i5Mbbbnxo
5682 Content-Length: 241
5683 Connection: close
5684 Content-Type: text/html; charset=iso-8859-1
5685
5686WhatWeb report for http://bad-young-girls.com/index.htm?FabzNDfQqD1i5Mbbbnxo
5687Status : 200 OK
5688Title : BAD Young Girls - Sexy teen models - page 1
5689IP : 204.155.148.235
5690Country : UNITED STATES, US
5691
5692Summary : HTML5, Perl[5.18.2], Script[text/javascript], HTTPServer[FreeBSD][Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2], Apache[2.2.26][mod_perl/2.0.8,mod_ssl/2.2.26], OpenSSL[1.0.1f], Cookies[bothub_id,bothub_ip_addr,bothub_sec_code]
5693
5694Detected Plugins:
5695[ Apache ]
5696 The Apache HTTP Server Project is an effort to develop and
5697 maintain an open-source HTTP server for modern operating
5698 systems including UNIX and Windows NT. The goal of this
5699 project is to provide a secure, efficient and extensible
5700 server that provides HTTP services in sync with the current
5701 HTTP standards.
5702
5703 Version : 2.2.26 (from HTTP Server Header)
5704 Module : mod_perl/2.0.8,mod_ssl/2.2.26
5705 Google Dorks: (3)
5706 Website : http://httpd.apache.org/
5707
5708[ Cookies ]
5709 Display the names of cookies in the HTTP headers. The
5710 values are not returned to save on space.
5711
5712 String : bothub_ip_addr
5713 String : bothub_id
5714 String : bothub_sec_code
5715
5716[ HTML5 ]
5717 HTML version 5, detected by the doctype declaration
5718
5719
5720[ HTTPServer ]
5721 HTTP server header string. This plugin also attempts to
5722 identify the operating system from the server header.
5723
5724 OS : FreeBSD
5725 String : Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2 (from server string)
5726
5727[ OpenSSL ]
5728 The OpenSSL Project is a collaborative effort to develop a
5729 robust, commercial-grade, full-featured, and Open Source
5730 toolkit implementing the Secure Sockets Layer (SSL v2/v3)
5731 and Transport Layer Security (TLS v1) protocols as well as
5732 a full-strength general purpose cryptography library.
5733
5734 Version : 1.0.1f
5735 Website : http://www.openssl.org/
5736
5737[ Perl ]
5738 Perl is a highly capable, feature-rich programming language
5739 with over 22 years of development.
5740
5741 Version : 5.18.2
5742 Website : http://www.perl.org/
5743
5744[ Script ]
5745 This plugin detects instances of script HTML elements and
5746 returns the script language/type.
5747
5748 String : text/javascript
5749
5750HTTP Headers:
5751 HTTP/1.1 200 OK
5752 Date: Thu, 31 Aug 2017 07:52:11 GMT
5753 Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
5754 Accept-Ranges: bytes
5755 Set-Cookie: bothub_ip_addr=87.98.166.29; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
5756 Set-Cookie: bothub_id=11527833959518963155; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
5757 Set-Cookie: bothub_sec_code=FabzNDfQqD1i5Mbbbnxo; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
5758 Content-Length: 104840
5759 Last-Modified: Thu, 31 Aug 2017 07:52:11 GMT
5760 Connection: close
5761 Content-Type: text/html; charset=iso-8859-2
5762
5763
5764
5765 ^ ^
5766 _ __ _ ____ _ __ _ _ ____
5767 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
5768 | V V // o // _/ | V V // 0 // 0 // _/
5769 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
5770 <
5771 ...'
5772
5773 WAFW00F - Web Application Firewall Detection Tool
5774
5775 By Sandro Gauci && Wendel G. Henrique
5776
5777Checking http://bad-young-girls.com
5778Generic Detection results:
5779No WAF detected by the generic detection
5780Number of requests: 14
5781
5782
5783DNS Servers for bad-young-girls.com:
5784 ns-f.est-host.com
5785 ns2-e.est-host.com
5786 ns2-f.est-host.com
5787 ns-e.est-host.com
5788
5789Trying zone transfer first...
5790 Testing ns-f.est-host.com
5791 Request timed out or transfer not allowed.
5792 Testing ns2-e.est-host.com
5793 Request timed out or transfer not allowed.
5794 Testing ns2-f.est-host.com
5795 Request timed out or transfer not allowed.
5796 Testing ns-e.est-host.com
5797 Request timed out or transfer not allowed.
5798
5799Unsuccessful in zone transfer (it was worth a shot)
5800Okay, trying the good old fashioned way... brute force
5801
5802Checking for wildcard DNS...
5803Nope. Good.
5804Now performing 2280 test(s)...
5805204.155.148.235 www.bad-young-girls.com
5806204.155.148.235 www2.bad-young-girls.com
5807
5808Subnets found (may want to probe here using nmap or unicornscan):
5809 204.155.148.0-255 : 2 hostnames found.
5810
5811Done with Fierce scan: http://ha.ckers.org/fierce/
5812Found 2 entries.
5813
5814Have a nice day.
5815
5816
5817
5818lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
5819 Written by Stefan Behte (http://ge.mine.nu)
5820 Proof-of-concept! Might give false positives.
5821
5822Checking for DNS-Loadbalancing: NOT FOUND
5823Checking for HTTP-Loadbalancing [Server]:
5824 Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
5825 NOT FOUND
5826
5827Checking for HTTP-Loadbalancing [Date]: 08:07:22, 08:07:22, 08:07:30, 08:07:31, 08:07:31, 08:07:32, 08:07:33, 08:07:34, 08:07:36, 08:07:38, 08:07:39, 08:07:39, 08:07:40, 08:07:40, 08:07:41, 08:07:41, 08:07:42, 08:07:44, 08:07:46, 08:07:49, 08:07:49, 08:07:50, 08:07:50, 08:07:51, 08:07:51, 08:07:52, 08:07:53, 08:07:54, 08:07:56, 08:07:58, 08:07:59, 08:07:59, 08:08:00, 08:08:00, 08:08:01, 08:08:01, 08:08:01, 08:08:02, 08:08:02, 08:08:03, 08:08:03, 08:08:04, 08:08:04, 08:08:05, 08:08:05, 08:08:06, 08:08:06, 08:08:07, 08:08:07, 08:08:07, NOT FOUND
5828
5829Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
5830
5831bad-young-girls.com does NOT use Load-balancing.
5832
5833
5834
5835Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
5836
5837 ----------------------------------------------------------
5838| Scan Information |
5839 ----------------------------------------------------------
5840
5841Mode ..................... VRFY
5842Worker Processes ......... 5
5843Usernames file ........... users.txt
5844Target count ............. 1
5845Username count ........... 494
5846Target TCP port .......... 25
5847Query timeout ............ 5 secs
5848Target domain ............
5849
5850######## Scan started at Thu Aug 31 04:08:27 2017 #########
5851######## Scan completed at Thu Aug 31 04:16:42 2017 #########
58520 results.
5853
5854494 queries in 495 seconds (1.0 queries / sec)
5855
5856
5857
5858Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-31 04:16 EDT
5859NSE: Loaded 146 scripts for scanning.
5860NSE: Script Pre-scanning.
5861Initiating NSE at 04:16
5862Completed NSE at 04:16, 0.00s elapsed
5863Initiating NSE at 04:16
5864Completed NSE at 04:16, 0.00s elapsed
5865Failed to resolve "bad-young-girls.com.txt".
5866Initiating Parallel DNS resolution of 1 host. at 04:16
5867Completed Parallel DNS resolution of 1 host. at 04:16, 0.51s elapsed
5868Initiating SYN Stealth Scan at 04:16
5869Scanning bad-young-girls.com (204.155.148.235) [100 ports]
5870Discovered open port 80/tcp on 204.155.148.235
5871Completed SYN Stealth Scan at 04:16, 7.05s elapsed (100 total ports)
5872Initiating Service scan at 04:16
5873Scanning 1 service on bad-young-girls.com (204.155.148.235)
5874Completed Service scan at 04:16, 6.45s elapsed (1 service on 1 host)
5875Initiating OS detection (try #1) against bad-young-girls.com (204.155.148.235)
5876adjust_timeouts2: packet supposedly had rtt of -92268 microseconds. Ignoring time.
5877adjust_timeouts2: packet supposedly had rtt of -92268 microseconds. Ignoring time.
5878Retrying OS detection (try #2) against bad-young-girls.com (204.155.148.235)
5879WARNING: OS didn't match until try #2
5880Initiating Traceroute at 04:17
5881Completed Traceroute at 04:17, 3.03s elapsed
5882Initiating Parallel DNS resolution of 9 hosts. at 04:17
5883Completed Parallel DNS resolution of 9 hosts. at 04:17, 6.78s elapsed
5884NSE: Script scanning 204.155.148.235.
5885Initiating NSE at 04:17
5886Completed NSE at 04:17, 17.61s elapsed
5887Initiating NSE at 04:17
5888Completed NSE at 04:17, 0.00s elapsed
5889Nmap scan report for bad-young-girls.com (204.155.148.235)
5890Host is up (0.22s latency).
5891Not shown: 99 filtered ports
5892PORT STATE SERVICE VERSION
589380/tcp open http Apache httpd 2.2.26 ((FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2)
5894|_http-favicon: Unknown favicon MD5: F571DC1B075269131B64AFF24DB2673E
5895| http-methods:
5896|_ Supported Methods: GET HEAD POST OPTIONS
5897| http-robots.txt: 4 disallowed entries
5898|_/adver /adver2 /js /scripts
5899|_http-server-header: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
5900| http-title: BAD Young Girls - Sexy teen models - page 1
5901|_Requested resource was http://bad-young-girls.com/index.htm?oiYpplmMnp5ie9lk22K7
5902Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
5903Device type: specialized|WAP|general purpose|router
5904Running: AVtech embedded, Linux 2.4.X|2.6.X|3.X, MikroTik RouterOS 6.X
5905OS CPE: cpe:/o:linux:linux_kernel:2.4.20 cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:3.2.0 cpe:/o:mikrotik:routeros:6.15
5906OS details: AVtech Room Alert 26W environmental monitor, Tomato 1.27 - 1.28 (Linux 2.4.20), Linux 2.6.18 - 2.6.22, Linux 3.2.0, MikroTik RouterOS 6.15 (Linux 3.3.5)
5907Network Distance: 10 hops
5908
5909TRACEROUTE (using port 80/tcp)
5910HOP RTT ADDRESS
59111 109.86 ms 10.13.0.1
59122 110.54 ms 37.187.24.252
59133 110.54 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
59144 ...
59155 113.81 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
59166 182.65 ms be100-1298.nwk-5-a9.nj.us (192.99.146.133)
59177 181.70 ms paix.ny.us.iptransit.com (198.32.118.43)
59188 216.17 ms te5-3.r1.dal.iptransit.com (204.26.60.58)
59199 220.20 ms 199.59.204.2
592010 217.58 ms 204.155.148.235
5921
5922NSE: Script Post-scanning.
5923Initiating NSE at 04:17
5924Completed NSE at 04:17, 0.00s elapsed
5925Initiating NSE at 04:17
5926Completed NSE at 04:17, 0.00s elapsed
5927Read data files from: /usr/bin/../share/nmap
5928OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5929Nmap done: 1 IP address (1 host up) scanned in 54.35 seconds
5930 Raw packets sent: 331 (20.052KB) | Rcvd: 49 (2.816KB)
5931
5932
5933Error: can not open nmap file: bad-young-girls.com.txt
5934
5935
5936httprint v0.301 (beta) - web server fingerprinting tool
5937(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
5938http://net-square.com/httprint/
5939httprint@net-square.com
5940
5941Finger Printing on http://bad-young-girls.com:80/
5942Finger Printing Completed on http://bad-young-girls.com:80/
5943--------------------------------------------------
5944Host: bad-young-girls.com
5945Fingerprinting Error: Host/URL not found...
5946
5947--------------------------------------------------
5948
5949
5950
5951
5952 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
5953 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5954 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
5955 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5956 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
5957
5958 _/ User-Agent Tester ↵
5959 _/ AKA: Purple Pimp ↵
5960 _/ ChrisJohnRiley ↵
5961 _/ blog.c22.cc ↵
5962
5963 [>] Performing initial request and confirming stability
5964 [>] Using User-Agent string Mozilla/5.0
5965
5966 [ ] URL (ENTERED): http://bad-young-girls.com
5967 [!] URL (FINAL): http://bad-young-girls.com/index.htm?oiYpplmMnp5ie9lk22K7
5968 [!] Response Code: 302 Found
5969 [ ] Date: Thu, 31 Aug 2017 08:17:46 GMT
5970 [ ] Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
5971 [ ] Accept-Ranges: bytes
5972 [ ] Set-Cookie: bothub_id=46178746661843621817; domain=bad-young-girls.com; path=/; expires=Sun,
5973 1-Jan-2900 00:00:00 GMT
5974 [ ] Set-Cookie: bothub_sec_code=oiYpplmMnp5ie9lk22K7; domain=bad-young-girls.com; path=/; expires=Sun,
5975 1-Jan-2900 00:00:00 GMT
5976 [ ] Set-Cookie: bothub_ip_addr=87.98.166.29; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900
5977 00:00:00 GMT
5978 [ ] Content-Length: 104840
5979 [ ] Last-Modified: Thu, 31 Aug 2017 08:17:46 GMT
5980 [ ] Connection: close
5981 [ ] Content-Type: text/html; charset=iso-8859-2
5982 [ ] Data (MD5): af0375932025f384b3381cc90b7bf8c4
5983
5984 [1] Pass
5985 [2] Pass
5986 [3] Pass
5987
5988 [>] URL appears stable. Beginning test
5989
5990 [>] Using DEFAULT User-Agent Strings
5991
5992 [>] Using Crazy User-Agent Strings
5993 [>] Using Bot User-Agent Strings
5994
5995 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
5996
5997
5998 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
5999
6000
6001 [!] Last-Modified: Thu, 31 Aug 2017 08:18:26 GMT
6002
6003
6004 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
6005
6006
6007 [!] Last-Modified: Thu, 31 Aug 2017 08:18:42 GMT
6008
6009
6010 [>] User-Agent String : TrackBack/1.02
6011
6012
6013 [!] Last-Modified: Thu, 31 Aug 2017 08:18:50 GMT
6014
6015
6016 [>] User-Agent String : wispr
6017
6018
6019 [!] Last-Modified: Thu, 31 Aug 2017 08:18:58 GMT
6020
6021
6022 [>] User-Agent String : EMPTY USER-AGENT STRING!
6023
6024
6025 [!] Last-Modified: Thu, 31 Aug 2017 08:19:07 GMT
6026
6027
6028 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
6029
6030
6031 [!] Last-Modified: Thu, 31 Aug 2017 08:19:16 GMT
6032
6033
6034 [>] User-Agent String : Googlebot-Image/1.0
6035
6036
6037 [!] Last-Modified: Thu, 31 Aug 2017 08:19:23 GMT
6038
6039
6040 [>] User-Agent String : Mediapartners-Google
6041
6042
6043 [!] Last-Modified: Thu, 31 Aug 2017 08:19:31 GMT
6044
6045
6046 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
6047
6048
6049 [!] Last-Modified: Thu, 31 Aug 2017 08:19:40 GMT
6050
6051
6052 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
6053
6054
6055 [!] Last-Modified: Thu, 31 Aug 2017 08:19:48 GMT
6056
6057
6058 [>] User-Agent String : mmcrawler
6059
6060
6061 [!] Last-Modified: Thu, 31 Aug 2017 08:19:57 GMT
6062
6063
6064 [>] That's all folks... Fo' Shizzle!
6065[i] Scanning Site: http://bad-young-girls.com
6066
6067
6068
6069B A S I C I N F O
6070=======================================================================================================================
6071
6072
6073
6074
6075[+] Site Title: BAD Young Girls - Sexy teen models - page 1
6076[+] IP address: 204.155.148.235
6077[+] Web Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
6078[+] CMS: Could Not Detect
6079[+] Cloudflare: Not Detected
6080[+] Robots File: Found
6081
6082-------------[ contents ]----------------
6083User-agent: *
6084Disallow: /adver
6085Disallow: /adver2
6086Disallow: /js
6087Disallow: /scripts
6088
6089Sitemap: http://www.bad-young-girls.com/sitemap.xml
6090
6091-----------[end of contents]-------------
6092
6093
6094
6095W H O I S L O O K U P
6096===========================================================================================================================
6097
6098
6099
6100 Domain Name: BAD-YOUNG-GIRLS.COM
6101 Registry Domain ID: 1579842676_DOMAIN_COM-VRSN
6102 Registrar WHOIS Server: whois.enom.com
6103 Registrar URL: http://www.enom.com
6104 Updated Date: 2016-12-09T13:58:09Z
6105 Creation Date: 2009-12-24T11:30:15Z
6106 Registry Expiry Date: 2017-12-24T11:30:15Z
6107 Registrar: eNom, Inc.
6108 Registrar IANA ID: 48
6109 Registrar Abuse Contact Email:
6110 Registrar Abuse Contact Phone:
6111 Domain Status: ok https://icann.org/epp#ok
6112 Name Server: NS-E.EST-HOST.COM
6113 Name Server: NS-F.EST-HOST.COM
6114 Name Server: NS2-E.EST-HOST.COM
6115 Name Server: NS2-F.EST-HOST.COM
6116
6117
6118
6119
6120G E O I P L O O K U P
6121============================================================================================================================
6122
6123
6124
6125[i] IP Address: 204.155.148.235
6126[i] Country: US
6127[i] State: Florida
6128[i] City: Fort Lauderdale
6129[i] Latitude: 26.120899
6130[i] Longitude: -80.127296
6131
6132
6133
6134
6135H T T P H E A D E R S
6136==========================================================================================================================
6137
6138
6139
6140
6141[i] HTTP/1.1 302 Found
6142[i] Date: Thu, 31 Aug 2017 07:50:15 GMT
6143[i] Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
6144[i] Set-Cookie: bothub_ip_addr=87.98.166.29; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
6145[i] Set-Cookie: bothub_sec_code=FabzNDfQqD1i5Mbbbnxo; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
6146[i] Set-Cookie: bothub_id=15507267373946482535; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
6147[i] Location: http://bad-young-girls.com/index.htm?FabzNDfQqD1i5Mbbbnxo
6148[i] Content-Length: 241
6149[i] Connection: close
6150[i] Content-Type: text/html; charset=iso-8859-1
6151[i] HTTP/1.1 200 OK
6152[i] Date: Thu, 31 Aug 2017 07:50:16 GMT
6153[i] Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
6154[i] Accept-Ranges: bytes
6155[i] Set-Cookie: bothub_id=16507213418691295273; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
6156[i] Set-Cookie: bothub_ip_addr=87.98.166.29; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
6157[i] Set-Cookie: bothub_sec_code=FabzNDfQqD1i5Mbbbnxo; domain=bad-young-girls.com; path=/; expires=Sun, 1-Jan-2900 00:00:00 GMT
6158[i] Content-Length: 104840
6159[i] Last-Modified: Thu, 31 Aug 2017 07:50:16 GMT
6160[i] Connection: close
6161[i] Content-Type: text/html; charset=iso-8859-2
6162
6163
6164
6165
6166D N S L O O K U P
6167======================================================================================================================
6168
6169
6170
6171bad-young-girls.com. 3593 IN A 204.155.148.235
6172bad-young-girls.com. 3600 IN NS ns2-f.est-host.com.
6173bad-young-girls.com. 3600 IN NS ns-e.est-host.com.
6174bad-young-girls.com. 3600 IN NS ns2-e.est-host.com.
6175bad-young-girls.com. 3600 IN NS ns-f.est-host.com.
6176bad-young-girls.com. 3600 IN SOA ns-e.est-host.com. webmaster.est-host.com. 20140310 3600 900 3600000 3600
6177
6178
6179
6180
6181S U B N E T C A L C U L A T I O N
6182=======================================================================================================================================
6183
6184
6185
6186Address = 204.155.148.235
6187Network = 204.155.148.235 / 32
6188Netmask = 255.255.255.255
6189Broadcast = not needed on Point-to-Point links
6190Wildcard Mask = 0.0.0.0
6191Hosts Bits = 0
6192Max. Hosts = 1 (2^0 - 0)
6193Host Range = { 204.155.148.235 - 204.155.148.235 }
6194
6195
6196
6197N M A P P O R T S C A N
6198===============================================================================================================================
6199
6200
6201
6202
6203Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 07:50 UTC
6204Nmap scan report for bad-young-girls.com (204.155.148.235)
6205Host is up (0.040s latency).
6206PORT STATE SERVICE VERSION
620721/tcp filtered ftp
620822/tcp filtered ssh
620923/tcp filtered telnet
621025/tcp filtered smtp
621180/tcp open http Apache httpd 2.2.26 ((FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2)
6212110/tcp filtered pop3
6213143/tcp filtered imap
6214443/tcp filtered https
6215445/tcp filtered microsoft-ds
62163389/tcp filtered ms-wbt-server
6217
6218S U B - D O M A I N F I N D E R
6219=====================================================================================================================================
6220
6221
6222
6223
6224[i] Total Subdomains Found : 1
6225
6226[+] Subdomain: bad-young-girls.com
6227[-] IP: 204.155.148.235
6228
6229
6230
6231
6232---------------------------------------------------------------------------
6233+ Target IP: 204.155.148.235
6234+ Target Hostname: 204.155.148.235
6235+ Target Port: 80
6236+ Start Time: 2017-08-31 07:59:29 (GMT-4)
6237---------------------------------------------------------------------------
6238+ Server: Apache/2.2.26 (FreeBSD) mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2
6239+ Server leaks inodes via ETags, header found with file /, inode: 29774977, size: 4, mtime: Mon Mar 24 09:29:25 2014
6240+ The anti-clickjacking X-Frame-Options header is not present.
6241+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
6242+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
6243+ Apache mod_negotiation is enabled with MultiViews, which allows attackers to easily brute force file names. See http://www.wisec.it/sectou.php?id=4698ebdc59d15. The following alternatives for 'index' were found: HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var, HTTP_NOT_FOUND.html.var
6244+ mod_ssl/2.2.26 appears to be outdated (current is at least 2.8.31) (may depend on server version)
6245+ OpenSSL/1.0.1f appears to be outdated (current is at least 1.0.1j). OpenSSL 1.0.0o and 0.9.8zc are also current.
6246+ Apache/2.2.26 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
6247+ Allowed HTTP Methods: OPTIONS, GET, HEAD, POST, TRACE
6248+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
6249+ mod_ssl/2.2.26 OpenSSL/1.0.1f mod_perl/2.0.8 Perl/v5.18.2 - mod_ssl 2.8.7 and lower are vulnerable to a remote buffer overflow which may allow a remote shell. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0082, OSVDB-756.
6250+ OSVDB-3268: /icons/: Directory indexing found.
6251+ OSVDB-3233: /icons/README: Apache default file found.
6252+ 8362 requests: 0 error(s) and 13 item(s) reported on remote host
6253+ End Time: 2017-08-31 08:41:00 (GMT-4) (2491 seconds)
6254##########################################################################################
6255Hostname www.mintteens.com ISP DataWeb Global Group B.V. (AS39572)
6256Continent North America Flag
6257US
6258Country United States Country Code US (USA)
6259Region VA Local time 31 Aug 2017 04:29 EDT
6260Metropolis* Washington Postal Code 20147
6261City Ashburn Latitude 39.018
6262IP Address 213.174.158.127 Longitude -77.539
6263##########################################################################################
6264mintteens.com
6265
6266
6267 Domain Name: MINTTEENS.COM
6268 Registry Domain ID: 1366588757_DOMAIN_COM-VRSN
6269 Registrar WHOIS Server: whois.evonames.com
6270 Registrar URL: http://www.danesconames.com
6271 Updated Date: 2016-09-28T17:14:00Z
6272 Creation Date: 2007-12-29T21:35:33Z
6273 Registry Expiry Date: 2017-12-29T21:35:33Z
6274 Registrar: Danesco Trading Ltd.
6275 Registrar IANA ID: 1418
6276 Registrar Abuse Contact Email:
6277 Registrar Abuse Contact Phone:
6278 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
6279 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6280 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
6281 Name Server: NS5.PUBLIC-NS.COM
6282 Name Server: NS6.PUBLIC-NS.COM
6283
6284Domain Name: MINTTEENS.COM
6285Registry Domain ID:
6286Registrar WHOIS Server: whois.evonames.com
6287Registrar URL: https://evonames.com/
6288Updated Date: 2017-03-17 17:15:10.526972
6289Creation Date: 2007-12-29
6290Registrar Registration Expiration Date: 2017-12-29
6291Registrar: DANESCO TRADING LTD
6292Registrar IANA ID: 1418
6293Registrar Abuse Contact Email: abuse@evonames.com
6294Registrar Abuse Contact Phone: +357.95713635
6295Reseller: AHnames.com https://www.AHnames.com/
6296Domain Status: clientUpdateProhibited
6297Domain Status: clientDeleteProhibited
6298Domain Status: clientTransferProhibited
6299Registry Registrant ID: MR_2462006WP
6300Registrant Name: WhoisProtectService.net
6301Registrant Organization: PROTECTSERVICE, LTD.
6302Registrant Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
6303Registrant City: Limassol
6304Registrant State/Province:
6305Registrant Postal Code: 3025
6306Registrant Country: Cyprus
6307Registrant Phone: +357.95713635
6308Registrant Phone Ext:
6309Registrant Fax:
6310Registrant Fax Ext:
6311Registrant Email: mintteens.com@whoisprotectservice.net
6312Registry Admin ID: MR_2462006WP
6313Admin Name: WhoisProtectService.net
6314Admin Organization: PROTECTSERVICE, LTD.
6315Admin Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
6316Admin City: Limassol
6317Admin State/Province:
6318Admin Postal Code: 3025
6319Admin Country: Cyprus
6320Admin Phone: +357.95713635
6321Admin Phone Ext:
6322Admin Fax:
6323Admin Fax Ext:
6324Admin Email: mintteens.com@whoisprotectservice.net
6325Registry Tech ID: MR_2462006WP
6326Tech Name: WhoisProtectService.net
6327Tech Organization: PROTECTSERVICE, LTD.
6328Tech Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
6329Tech City: Limassol
6330Tech State/Province:
6331Tech Postal Code: 3025
6332Tech Country: Cyprus
6333Tech Phone: +357.95713635
6334Tech Phone Ext:
6335Tech Fax:
6336Tech Fax Ext:
6337Tech Email: mintteens.com@whoisprotectservice.net
6338Registry Billing ID: MR_2462006WP
6339Billing Name: WhoisProtectService.net
6340Billing Organization: PROTECTSERVICE, LTD.
6341Billing Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
6342Billing City: Limassol
6343Billing State/Province:
6344Billing Postal Code: 3025
6345Billing Country: Cyprus
6346Billing Phone: +357.95713635
6347Billing Phone Ext:
6348Billing Fax:
6349Billing Fax Ext:
6350Billing Email: mintteens.com@whoisprotectservice.net
6351Name Server: NS5.PUBLIC-NS.COM
6352Name Server: NS6.PUBLIC-NS.COM
6353DNSSEC: unsigned
6354URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
6355>>> Last update of WHOIS database: 2017-08-19 05:45:36 <<<
6356
6357Abuse email: abuse@ahnames.com
6358
6359
6360
6361
6362; <<>> DiG 9.10.3-P4-Debian <<>> mintteens.com any
6363;; global options: +cmd
6364;; Got answer:
6365;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59094
6366;; flags: qr rd ra; QUERY: 1, ANSWER: 8, AUTHORITY: 0, ADDITIONAL: 1
6367
6368;; OPT PSEUDOSECTION:
6369; EDNS: version: 0, flags:; udp: 4096
6370;; QUESTION SECTION:
6371;mintteens.com. IN ANY
6372
6373;; ANSWER SECTION:
6374mintteens.com. 1200 IN A 213.174.158.127
6375mintteens.com. 1200 IN MX 20 mail2.mintteens.com.
6376mintteens.com. 1200 IN MX 10 mail.mintteens.com.
6377mintteens.com. 1200 IN SOA ns1.ah-dns.com. admin.mintteens.com. 1399054237 21600 3600 691200 38400
6378mintteens.com. 1200 IN NS ns5.public-ns.com.
6379mintteens.com. 1200 IN NS ns1.ah-dns.com.
6380mintteens.com. 1200 IN NS ns6.public-ns.com.
6381mintteens.com. 1200 IN NS ns2.ah-dns.com.
6382
6383;; Query time: 72 msec
6384;; SERVER: 192.168.1.254#53(192.168.1.254)
6385;; WHEN: Thu Aug 31 08:00:17 EDT 2017
6386;; MSG SIZE rcvd: 232
6387
6388
6389
6390Running:
6391 traceroute -T -O info -i eth0 mintteens.com
6392traceroute to mintteens.com (213.174.158.127), 30 hops max, 60 byte packets
6393 1 gateway (192.168.1.254) 0.560 ms 0.873 ms 1.047 ms
6394 2 10.135.18.1 (10.135.18.1) 7.225 ms 8.112 ms 18.743 ms
6395 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 29.910 ms 30.065 ms 30.122 ms
6396 4 * * *
6397 5 * * *
6398 6 ah.101.eq.ash.va.us.iptp.net (98.158.98.238) 37.804 ms 35.481 ms 35.435 ms
6399 7 213.174.158.127 (213.174.158.127) <syn,ack> 36.150 ms 35.878 ms 36.313 ms
6400
6401
6402Smartmatch is experimental at /usr/bin/dnsenum line 698.
6403Smartmatch is experimental at /usr/bin/dnsenum line 698.
6404dnsenum VERSION:1.2.4
6405Warning: can't load Net::Whois::IP module, whois queries disabled.
6406
6407----- mintteens.com -----
6408
6409
6410Host's addresses:
6411__________________
6412
6413mintteens.com. 1192 IN A 213.174.158.127
6414
6415
6416Name Servers:
6417______________
6418
6419ns5.public-ns.com. 1200 IN A 213.174.157.35
6420ns6.public-ns.com. 1200 IN A 88.208.29.10
6421ns1.ah-dns.com. 1200 IN A 88.208.5.3
6422ns2.ah-dns.com. 1200 IN A 192.243.50.242
6423
6424
6425Mail (MX) Servers:
6426___________________
6427
6428mail.mintteens.com. 1200 IN A 213.174.151.151
6429mail2.mintteens.com. 1200 IN A 88.208.36.36
6430
6431
6432
6433Google Results:
6434________________
6435
6436www.mintteens.com. 1200 IN A 213.174.158.127
6437
6438
6439Brute forcing with dns.txt:
6440____________________________
6441
6442mail.mintteens.com. 1180 IN A 213.174.151.151
6443mail2.mintteens.com. 1180 IN A 88.208.36.36
6444
6445
6446
6447mintteens.com class C netranges:
6448_________________________________
6449
6450 88.208.36.0/24
6451 213.174.151.0/24
6452 213.174.158.0/24
6453
6454[i] Scanning Site: http://mintteens.com
6455
6456
6457
6458B A S I C I N F O
6459=======================================================================================================================
6460
6461
6462
6463
6464[+] Site Title: Young Teens - naked teen models
6465[+] IP address: 213.174.158.127
6466[+] Web Server: nginx/1.4.2
6467[+] CMS: Could Not Detect
6468[+] Cloudflare: Not Detected
6469[+] Robots File: Found
6470
6471-------------[ contents ]----------------
6472User-agent: *
6473Disallow:
6474-----------[end of contents]-------------
6475
6476
6477
6478W H O I S L O O K U P
6479===========================================================================================================================
6480
6481
6482
6483 Domain Name: MINTTEENS.COM
6484 Registry Domain ID: 1366588757_DOMAIN_COM-VRSN
6485 Registrar WHOIS Server: whois.evonames.com
6486 Registrar URL: http://www.danesconames.com
6487 Updated Date: 2016-09-28T17:14:00Z
6488 Creation Date: 2007-12-29T21:35:33Z
6489 Registry Expiry Date: 2017-12-29T21:35:33Z
6490 Registrar: Danesco Trading Ltd.
6491 Registrar IANA ID: 1418
6492 Registrar Abuse Contact Email:
6493 Registrar Abuse Contact Phone:
6494 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
6495 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6496 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
6497 Name Server: NS5.PUBLIC-NS.COM
6498 Name Server: NS6.PUBLIC-NS.COM
6499 DNSSEC: unsigned
6500 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
6501>>> Last update of whois database: 2017-08-31T12:03:10Z <<<
6502
6503For more information on Whois status codes, please visit https://icann.org/epp
6504
6505
6506
6507The Registry database contains ONLY .COM, .NET, .EDU domains and
6508Registrars.
6509
6510
6511
6512
6513G E O I P L O O K U P
6514============================================================================================================================
6515
6516
6517
6518[i] IP Address: 213.174.158.127
6519[i] Country: US
6520[i] State: Virginia
6521[i] City: Ashburn
6522[i] Latitude: 39.018002
6523[i] Longitude: -77.539001
6524
6525
6526
6527
6528H T T P H E A D E R S
6529==========================================================================================================================
6530
6531
6532
6533
6534[i] HTTP/1.1 301 Moved Permanently
6535[i] Server: nginx/1.4.2
6536[i] Date: Thu, 31 Aug 2017 12:03:23 GMT
6537[i] Content-Type: text/html; charset=iso-8859-1
6538[i] Content-Length: 361
6539[i] Connection: close
6540[i] Location: http://www.mintteens.com/
6541[i] Vary: Accept-Encoding
6542[i] Expires: Sat, 30 Sep 2017 12:03:23 GMT
6543[i] Cache-Control: max-age=2592000
6544[i] HTTP/1.1 200 OK
6545[i] Server: nginx/1.4.2
6546[i] Date: Thu, 31 Aug 2017 12:03:24 GMT
6547[i] Content-Type: text/html
6548[i] Connection: close
6549[i] Vary: Accept-Encoding
6550[i] X-Powered-By: PHP/5.4.43
6551[i] Vary: Accept-Encoding
6552[i] Expires: Sat, 30 Sep 2017 12:03:24 GMT
6553[i] Cache-Control: max-age=2592000
6554
6555
6556
6557
6558D N S L O O K U P
6559======================================================================================================================
6560
6561
6562mintteens.com. 1195 IN A 213.174.158.127
6563mintteens.com. 1200 IN NS ns1.ah-dns.com.
6564mintteens.com. 1200 IN NS ns2.ah-dns.com.
6565mintteens.com. 1200 IN NS ns5.public-ns.com.
6566mintteens.com. 1200 IN NS ns6.public-ns.com.
6567mintteens.com. 1200 IN SOA ns1.ah-dns.com. admin.mintteens.com. 1399054237 21600 3600 691200 38400
6568mintteens.com. 1200 IN MX 10 mail.mintteens.com.
6569mintteens.com. 1200 IN MX 20 mail2.mintteens.com.
6570
6571
6572
6573
6574S U B N E T C A L C U L A T I O N
6575=======================================================================================================================================
6576
6577
6578
6579Address = 213.174.158.127
6580Network = 213.174.158.127 / 32
6581Netmask = 255.255.255.255
6582Broadcast = not needed on Point-to-Point links
6583Wildcard Mask = 0.0.0.0
6584Hosts Bits = 0
6585Max. Hosts = 1 (2^0 - 0)
6586Host Range = { 213.174.158.127 - 213.174.158.127 }
6587
6588
6589
6590N M A P P O R T S C A N
6591===============================================================================================================================
6592
6593
6594
6595
6596Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 12:03 UTC
6597Nmap scan report for mintteens.com (213.174.158.127)
6598Host is up (0.017s latency).
6599PORT STATE SERVICE VERSION
660021/tcp open ftp OpenBSD ftpd
660122/tcp open ssh OpenSSH 5.8p2_hpn13v11 (FreeBSD 20110503; protocol 2.0)
660223/tcp filtered telnet
660325/tcp filtered smtp
660480/tcp open http nginx 1.4.2
6605110/tcp filtered pop3
6606143/tcp filtered imap
6607443/tcp filtered https
6608445/tcp filtered microsoft-ds
66093389/tcp filtered ms-wbt-server
6610Service Info: Host: DS2187; OS: FreeBSD; CPE: cpe:/o:freebsd:freebsd
6611
6612Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6613Nmap done: 1 IP address (1 host up) scanned in 8.26 seconds
6614
6615
6616
6617S U B - D O M A I N F I N D E R
6618=====================================================================================================================================
6619
6620
6621
6622
6623[i] Total Subdomains Found : 4
6624
6625[+] Subdomain: mintteens.com
6626[-] IP: 213.174.158.127
6627
6628[+] Subdomain: mail2.mintteens.com
6629[-] IP: 88.208.36.36
6630
6631[+] Subdomain: mail.mintteens.com
6632[-] IP: 213.174.151.151
6633
6634[+] Subdomain: www.mintteens.com
6635[-] IP: 213.174.158.127
6636- Nikto v2.1.6
6637---------------------------------------------------------------------------
6638+ Target IP: 213.174.158.127
6639+ Target Hostname: 213.174.158.127
6640+ Target Port: 80
6641+ Start Time: 2017-08-31 08:28:46 (GMT-4)
6642---------------------------------------------------------------------------
6643+ Server: nginx/1.4.2
6644+ Server leaks inodes via ETags, header found with file /, inode: 21909892, size: 7662, mtime: Sat Mar 25 14:37:12 2017
6645+ The anti-clickjacking X-Frame-Options header is not present.
6646+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
6647+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
6648+ No CGI Directories found (use '-C all' to force check all possible dirs)
6649+ Allowed HTTP Methods: GET, HEAD, POST, OPTIONS, TRACE
6650+ OSVDB-3092: /test.html: This might be interesting...
6651+ ERROR: Error limit (20) reached for host, giving up. Last error: error reading HTTP response
6652+ Scan terminated: 20 error(s) and 6 item(s) reported on remote host
6653+ End Time: 2017-08-31 09:03:30 (GMT-4) (2084 seconds)
6654#######################################################################################################################################
6655Hostname www.toptinygirls.com ISP LeaseWeb Netherlands B.V. (AS60781)
6656Continent Europe Flag
6657NL
6658Country Netherlands Country Code NL (NLD)
6659Region Unknown Local time 31 Aug 2017 14:30 CEST
6660City Unknown Latitude 52.382
6661IP Address 95.211.5.91 Longitude 4.899
6662######################################################################################################################################
6663toptinygirls.com
6664
6665
6666 Domain Name: TOPTINYGIRLS.COM
6667 Registry Domain ID: 1496685204_DOMAIN_COM-VRSN
6668 Registrar WHOIS Server: whois.godaddy.com
6669 Registrar URL: http://www.godaddy.com
6670 Updated Date: 2017-06-19T11:44:31Z
6671 Creation Date: 2008-06-18T22:58:21Z
6672 Registry Expiry Date: 2018-06-18T22:58:21Z
6673 Registrar: GoDaddy.com, LLC
6674 Registrar IANA ID: 146
6675 Registrar Abuse Contact Email: abuse@godaddy.com
6676 Registrar Abuse Contact Phone: 480-624-2505
6677 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
6678 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
6679 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6680 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
6681 Name Server: NS09.DOMAINCONTROL.COM
6682 Name Server: NS10.DOMAINCONTROL.COM
6683
6684Domain Name: TOPTINYGIRLS.COM
6685Registrar URL: http://www.godaddy.com
6686Registrant Name: Registration Private
6687Registrant Organization: Domains By Proxy, LLC
6688Name Server: NS09.DOMAINCONTROL.COM
6689Name Server: NS10.DOMAINCONTROL.COM
6690 IN ANY
6691
6692;; ANSWER SECTION:
6693toptinygirls.com. 12 IN A 95.211.5.91
6694toptinygirls.com. 1812 IN NS ns09.domaincontrol.com.
6695toptinygirls.com. 1812 IN NS ns10.domaincontrol.com.
6696
6697;; Query time: 8 msec
6698;; SERVER: 192.168.1.254#53(192.168.1.254)
6699;; WHEN: Thu Aug 31 08:50:42 EDT 2017
6700;; MSG SIZE rcvd: 113
6701
6702
6703
6704;; Connection to 192.168.1.254#53(192.168.1.254) for toptinygirls.com failed: connection refused.
6705Host toptinygirls.com not found: 9(NOTAUTH)
6706; Transfer failed.
6707
6708
6709Please type the name of your network interface Example: eth0
6710eth0
6711
6712Running:
6713 traceroute -T -O info -i eth0 toptinygirls.com
6714traceroute to toptinygirls.com (95.211.5.91), 30 hops max, 60 byte packets
6715 1 gateway (192.168.1.254) 0.535 ms 0.719 ms 0.876 ms
6716 2 10.135.18.1 (10.135.18.1) 7.271 ms 7.562 ms 7.774 ms
6717 3 75.154.223.209 (75.154.223.209) 32.332 ms 32.510 ms 32.643 ms
6718 4 * * *
6719 5 * * *
6720 6 * * *
6721 7 * * *
6722 8 91.kaasserver.com (95.211.5.91) <syn,ack> 124.107 ms 123.505 ms 122.124 ms
6723
6724
6725Smartmatch is experimental at /usr/bin/dnsenum line 698.
6726Smartmatch is experimental at /usr/bin/dnsenum line 698.
6727dnsenum VERSION:1.2.4
6728Warning: can't load Net::Whois::IP module, whois queries disabled.
6729
6730----- toptinygirls.com -----
6731
6732
6733Host's addresses:
6734__________________
6735
6736toptinygirls.com. 1800 IN A 95.211.5.91
6737
6738
6739Wildcard detection using: dthaiqiyapmb
6740_______________________________________
6741
6742dthaiqiyapmb.toptinygirls.com. 1800 IN A 95.211.5.91
6743
6744
6745
6746Name Servers:
6747______________
6748
6749ns09.domaincontrol.com. 92208 IN A 216.69.185.5
6750ns10.domaincontrol.com. 92208 IN A 208.109.255.5
6751
6752
6753Mail (MX) Servers:
6754___________________
6755
6756
6757
6758
6759
6760Brute forcing with dns.txt:
6761____________________________
6762
6763e.toptinygirls.com. 3600 IN CNAME email.secureserver.net.
6764email.secureserver.net. 60 IN A 72.167.218.173
6765email.secureserver.net. 60 IN A 72.167.218.183
6766email.secureserver.net. 60 IN A 72.167.218.45
6767email.secureserver.net. 60 IN A 72.167.218.55
6768email.secureserver.net. 60 IN A 97.74.135.133
6769email.secureserver.net. 60 IN A 97.74.135.148
6770email.secureserver.net. 60 IN A 97.74.135.45
6771email.secureserver.net. 60 IN A 97.74.135.55
6772email.secureserver.net. 60 IN A 173.201.192.133
6773email.secureserver.net. 60 IN A 173.201.192.148
6774email.secureserver.net. 60 IN A 173.201.192.20
6775email.secureserver.net. 60 IN A 173.201.192.5
6776email.secureserver.net. 60 IN A 173.201.193.133
6777email.secureserver.net. 60 IN A 173.201.193.148
6778email.secureserver.net. 60 IN A 173.201.193.20
6779email.secureserver.net. 60 IN A 173.201.193.5
6780ftp.toptinygirls.com. 3600 IN CNAME toptinygirls.com.
6781mail.toptinygirls.com. 3600 IN CNAME pop.secureserver.net.
6782pop.secureserver.net. 24 IN A 68.178.252.115
6783pop.secureserver.net. 24 IN A 45.40.130.44
6784pop.secureserver.net. 24 IN A 173.201.193.200
6785pop.secureserver.net. 24 IN A 97.74.135.218
6786pop.secureserver.net. 24 IN A 97.74.135.111
6787pop.toptinygirls.com. 3600 IN CNAME pop.secureserver.net.
6788pop.secureserver.net. 22 IN A 45.40.130.44
6789pop.secureserver.net. 22 IN A 173.201.193.200
6790pop.secureserver.net. 22 IN A 97.74.135.218
6791pop.secureserver.net. 22 IN A 97.74.135.111
6792pop.secureserver.net. 22 IN A 68.178.252.115
6793smtp.toptinygirls.com. 3600 IN CNAME smtp.secureserver.net.
6794smtp.secureserver.net. 60 IN A 68.178.213.203
6795smtp.secureserver.net. 60 IN A 68.178.213.37
6796smtp.secureserver.net. 60 IN A 72.167.238.29
6797webmail.toptinygirls.com. 3600 IN CNAME webmail.secureserver.net.
6798webmail.secureserver.net. 3600 IN CNAME email.secureserver.net.
6799email.secureserver.net. 51 IN A 72.167.218.183
6800email.secureserver.net. 51 IN A 72.167.218.45
6801email.secureserver.net. 51 IN A 72.167.218.55
6802email.secureserver.net. 51 IN A 97.74.135.133
6803email.secureserver.net. 51 IN A 97.74.135.148
6804email.secureserver.net. 51 IN A 97.74.135.45
6805email.secureserver.net. 51 IN A 97.74.135.55
6806email.secureserver.net. 51 IN A 173.201.192.133
6807email.secureserver.net. 51 IN A 173.201.192.148
6808email.secureserver.net. 51 IN A 173.201.192.20
6809email.secureserver.net. 51 IN A 173.201.192.5
6810email.secureserver.net. 51 IN A 173.201.193.133
6811email.secureserver.net. 51 IN A 173.201.193.148
6812email.secureserver.net. 51 IN A 173.201.193.20
6813email.secureserver.net. 51 IN A 173.201.193.5
6814email.secureserver.net. 51 IN A 72.167.218.173
6815www.toptinygirls.com. 1800 IN CNAME toptinygirls.com.
6816
6817
6818Performing recursion:
6819______________________
6820
6821
6822 ---- Checking subdomains NS records ----
6823toptinygirls.com. 1784 IN NS ns09.domaincontrol.com.
6824toptinygirls.com. 1784 IN NS ns10.domaincontrol.com.
6825toptinygirls.com. 1784 IN NS ns09.domaincontrol.com.
6826toptinygirls.com. 1784 IN NS ns10.domaincontrol.com.
6827
6828 Can't perform recursion no NS records.
6829
6830
6831toptinygirls.com class C netranges:
6832____________________________________
6833
6834 95.211.5.0/24
6835
6836
6837Performing reverse lookup on 256 ip addresses:
6838_______________________________________________
6839
6840
68410 results out of 256 IP addresses.
6842
6843e.toptinygirls.com
6844IP address #1: 72.167.218.45
6845IP address #2: 72.167.218.55
6846IP address #3: 97.74.135.133
6847IP address #4: 97.74.135.148
6848IP address #5: 97.74.135.45
6849IP address #6: 97.74.135.55
6850IP address #7: 173.201.192.133
6851IP address #8: 173.201.192.148
6852IP address #9: 173.201.192.20
6853IP address #10: 173.201.192.5
6854IP address #11: 173.201.193.133
6855IP address #12: 173.201.193.148
6856IP address #13: 173.201.193.20
6857IP address #14: 173.201.193.5
6858IP address #15: 72.167.218.173
6859IP address #16: 72.167.218.183
6860
6861email.toptinygirls.com
6862IP address #1: 72.167.218.55
6863IP address #2: 97.74.135.133
6864IP address #3: 97.74.135.148
6865IP address #4: 97.74.135.45
6866IP address #5: 97.74.135.55
6867IP address #6: 173.201.192.133
6868IP address #7: 173.201.192.148
6869IP address #8: 173.201.192.20
6870IP address #9: 173.201.192.5
6871IP address #10: 173.201.193.133
6872IP address #11: 173.201.193.148
6873IP address #12: 173.201.193.20
6874IP address #13: 173.201.193.5
6875IP address #14: 72.167.218.173
6876IP address #15: 72.167.218.183
6877IP address #16: 72.167.218.45
6878
6879mail.toptinygirls.com
6880IP address #1: 97.74.135.218
6881IP address #2: 173.201.193.200
6882IP address #3: 45.40.130.44
6883IP address #4: 68.178.252.115
6884IP address #5: 97.74.135.111
6885
6886pop.toptinygirls.com
6887IP address #1: 68.178.252.115
6888IP address #2: 97.74.135.111
6889IP address #3: 97.74.135.218
6890IP address #4: 173.201.193.200
6891IP address #5: 45.40.130.44
6892
6893smtp.toptinygirls.com
6894IP address #1: 72.167.238.29
6895IP address #2: 68.178.213.37
6896IP address #3: 68.178.213.203
6897
6898webmail.toptinygirls.com
6899IP address #1: 173.201.193.133
6900IP address #2: 97.74.135.133
6901IP address #3: 72.167.218.45
6902IP address #4: 173.201.192.148
6903IP address #5: 97.74.135.148
6904IP address #6: 173.201.192.133
6905IP address #7: 72.167.218.173
6906IP address #8: 97.74.135.55
6907IP address #9: 173.201.193.148
6908IP address #10: 173.201.192.5
6909IP address #11: 173.201.192.20
6910IP address #12: 72.167.218.55
6911IP address #13: 97.74.135.45
6912IP address #14: 173.201.193.5
6913IP address #15: 173.201.193.20
6914IP address #16: 72.167.218.183
6915
6916[+] 6 (sub)domains and 61 IP address(es) found
6917[+] completion time: 116 second(s)
6918
6919
6920Tracing to toptinygirls.com[a] via 192.168.1.254, maximum of 3 retries
6921192.168.1.254 (192.168.1.254) Got answer
6922
6923
6924WhatWeb report for http://toptinygirls.com
6925Status : 200 OK
6926Title : TopTinyGirls.com :: your teen resource ...
6927IP : 95.211.5.91
6928Country : NETHERLANDS, NL
6929
6930Summary : Meta-Author[toptinygirls.com], Script[text/javascript], PHP[5.2.4-2ubuntu5.26], X-Powered-By[PHP/5.2.4-2ubuntu5.26], HTTPServer[Apache], Apache
6931
6932Detected Plugins:
6933[ Apache ]
6934 The Apache HTTP Server Project is an effort to develop and
6935 maintain an open-source HTTP server for modern operating
6936 systems including UNIX and Windows NT. The goal of this
6937 project is to provide a secure, efficient and extensible
6938 server that provides HTTP services in sync with the current
6939 HTTP standards.
6940
6941 Google Dorks: (3)
6942 Website : http://httpd.apache.org/
6943
6944[ HTTPServer ]
6945 HTTP server header string. This plugin also attempts to
6946 identify the operating system from the server header.
6947
6948 String : Apache (from server string)
6949
6950[ Meta-Author ]
6951 This plugin retrieves the author name from the meta name
6952 tag - info:
6953 http://www.webmarketingnow.com/tips/meta-tags-uncovered.html
6954 #author
6955
6956 String : toptinygirls.com
6957
6958[ PHP ]
6959 PHP is a widely-used general-purpose scripting language
6960 that is especially suited for Web development and can be
6961 embedded into HTML. This plugin identifies PHP errors,
6962 modules and versions and extracts the local file path and
6963 username if present.
6964
6965 Version : 5.2.4-2ubuntu5.26
6966 Google Dorks: (2)
6967 Website : http://www.php.net/
6968
6969[ Script ]
6970 This plugin detects instances of script HTML elements and
6971 returns the script language/type.
6972
6973 String : text/javascript
6974
6975[ X-Powered-By ]
6976 X-Powered-By HTTP header
6977
6978 String : PHP/5.2.4-2ubuntu5.26 (from x-powered-by string)
6979
6980HTTP Headers:
6981 HTTP/1.1 200 OK
6982 Date: Thu, 31 Aug 2017 12:53:24 GMT
6983 Server: Apache
6984 X-Powered-By: PHP/5.2.4-2ubuntu5.26
6985 Connection: close
6986 Transfer-Encoding: chunked
6987 Content-Type: text/html
6988
6989
6990[+] Hosts found in search engines:
6991------------------------------------
6992[-] Resolving hostnames IPs...
699395.211.5.91:young.toptinygirls.com
6994
6995
6996
6997 ^ ^
6998 _ __ _ ____ _ __ _ _ ____
6999 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
7000 | V V // o // _/ | V V // 0 // 0 // _/
7001 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
7002 <
7003 ...'
7004
7005 WAFW00F - Web Application Firewall Detection Tool
7006
7007 By Sandro Gauci && Wendel G. Henrique
7008
7009Checking http://toptinygirls.com
7010Generic Detection results:
7011No WAF detected by the generic detection
7012Number of requests: 13
7013
7014
7015DNS Servers for toptinygirls.com:
7016 ns10.domaincontrol.com
7017 ns09.domaincontrol.com
7018
7019Trying zone transfer first...
7020 Testing ns10.domaincontrol.com
7021 Request timed out or transfer not allowed.
7022 Testing ns09.domaincontrol.com
7023 Request timed out or transfer not allowed.
7024
7025Unsuccessful in zone transfer (it was worth a shot)
7026Okay, trying the good old fashioned way... brute force
7027
7028Checking for wildcard DNS...
7029 ** Found 92000387981.toptinygirls.com at 95.211.5.91.
7030 ** High probability of wildcard DNS.
7031Now performing 2280 test(s)...
7032
7033Subnets found (may want to probe here using nmap or unicornscan):
7034
7035Done with Fierce scan: http://ha.ckers.org/fierce/
7036Found 0 entries.
7037
7038Have a nice day.
7039
7040
7041
7042lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
7043 Written by Stefan Behte (http://ge.mine.nu)
7044 Proof-of-concept! Might give false positives.
7045
7046Checking for DNS-Loadbalancing: NOT FOUND
7047Checking for HTTP-Loadbalancing [Server]:
7048 Apache
7049 NOT FOUND
7050
7051Checking for HTTP-Loadbalancing [Date]: 13:00:14, 13:00:14, 13:00:14, 13:00:15, 13:00:15, 13:00:15, 13:00:15, 13:00:16, 13:00:16, 13:00:16, 13:00:16, 13:00:17, 13:00:17, 13:00:17, 13:00:17, 13:00:18, 13:00:18, 13:00:18, 13:00:19, 13:00:19, 13:00:19, 13:00:19, 13:00:20, 13:00:20, 13:00:20, 13:00:20, 13:00:21, 13:00:21, 13:00:21, 13:00:21, 13:00:22, 13:00:22, 13:00:22, 13:00:22, 13:00:23, 13:00:23, 13:00:23, 13:00:23, 13:00:24, 13:00:24, 13:00:24, 13:00:24, 13:00:25, 13:00:25, 13:00:25, 13:00:26, 13:00:26, 13:00:26, 13:00:27, 13:00:27, NOT FOUND
7052
7053Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
7054
7055toptinygirls.com does NOT use Load-balancing.
7056
7057
7058
7059Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
7060
7061 ----------------------------------------------------------
7062| Scan Information |
7063 ----------------------------------------------------------
7064
7065Mode ..................... VRFY
7066Worker Processes ......... 5
7067Usernames file ........... users.txt
7068Target count ............. 1
7069Username count ........... 494
7070Target TCP port .......... 25
7071Query timeout ............ 5 secs
7072Target domain ............
7073
7074######## Scan started at Thu Aug 31 09:00:31 2017 #########
7075######## Scan completed at Thu Aug 31 09:08:46 2017 #########
70760 results.
7077
7078494 queries in 495 seconds (1.0 queries / sec)
7079
7080
7081
7082Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-31 09:08 EDT
7083NSE: Loaded 146 scripts for scanning.
7084NSE: Script Pre-scanning.
7085Initiating NSE at 09:08
7086Completed NSE at 09:08, 0.00s elapsed
7087Initiating NSE at 09:08
7088Completed NSE at 09:08, 0.00s elapsed
7089Failed to resolve "toptinygirls.com.txt".
7090Initiating Parallel DNS resolution of 1 host. at 09:08
7091Completed Parallel DNS resolution of 1 host. at 09:08, 0.56s elapsed
7092Initiating SYN Stealth Scan at 09:08
7093Scanning toptinygirls.com (95.211.5.91) [100 ports]
7094Discovered open port 80/tcp on 95.211.5.91
7095Completed SYN Stealth Scan at 09:08, 5.95s elapsed (100 total ports)
7096Initiating Service scan at 09:08
7097Scanning 1 service on toptinygirls.com (95.211.5.91)
7098Completed Service scan at 09:09, 6.24s elapsed (1 service on 1 host)
7099Initiating OS detection (try #1) against toptinygirls.com (95.211.5.91)
7100adjust_timeouts2: packet supposedly had rtt of -86620 microseconds. Ignoring time.
7101adjust_timeouts2: packet supposedly had rtt of -86620 microseconds. Ignoring time.
7102adjust_timeouts2: packet supposedly had rtt of -86084 microseconds. Ignoring time.
7103adjust_timeouts2: packet supposedly had rtt of -86084 microseconds. Ignoring time.
7104Retrying OS detection (try #2) against toptinygirls.com (95.211.5.91)
7105Initiating Traceroute at 09:09
7106Completed Traceroute at 09:09, 3.01s elapsed
7107Initiating Parallel DNS resolution of 5 hosts. at 09:09
7108Completed Parallel DNS resolution of 5 hosts. at 09:09, 5.51s elapsed
7109NSE: Script scanning 95.211.5.91.
7110Initiating NSE at 09:09
7111Completed NSE at 09:10, 55.13s elapsed
7112Initiating NSE at 09:10
7113Completed NSE at 09:10, 0.00s elapsed
7114Nmap scan report for toptinygirls.com (95.211.5.91)
7115Host is up (0.12s latency).
7116rDNS record for 95.211.5.91: 91.kaasserver.com
7117Not shown: 93 closed ports
7118PORT STATE SERVICE VERSION
711925/tcp filtered smtp
712080/tcp open http Apache httpd
7121| http-methods:
7122|_ Supported Methods: GET
7123|_http-server-header: Apache
7124|_http-title: TopTinyGirls.com :: your teen resource ...
7125135/tcp filtered msrpc
7126139/tcp filtered netbios-ssn
7127445/tcp filtered microsoft-ds
7128465/tcp filtered smtps
7129587/tcp filtered submission
7130Aggressive OS guesses: Sun Integrated Lights-Out Manager (98%), Kyocera CopyStar CS 255 printer (98%), Kyocera CopyStar CS-2560 printer (98%), Linux 2.6.22 (98%), AXIS 205 Network Camera, Buffalo TeraStation NAS device, Linksys WAP54G WAP, or Sony SNC-RZ50N network camera (97%), Dell Remote Access Controller (DRAC 6) (97%), AVM FRITZ!Box FON WLAN 7170 WAP (97%), Dell Integrated Remote Access Controller (iDRAC) (97%), Dell Integrated Remote Access Controller (iDRAC9) (97%), Dell Remote Access Controller 5/I (DRAC 5/I) (97%)
7131No exact OS matches for host (test conditions non-ideal).
7132Uptime guess: 413.672 days (since Wed Jul 13 17:02:02 2016)
7133Network Distance: 10 hops
7134TCP Sequence Prediction: Difficulty=247 (Good luck!)
7135IP ID Sequence Generation: All zeros
7136
7137TRACEROUTE (using port 443/tcp)
7138HOP RTT ADDRESS
71391 110.41 ms 10.13.0.1
71402 ...
71413 110.48 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
71424 ...
71435 116.69 ms be100-1108.ams-1-a9.nl.eu (213.186.32.211)
71446 117.23 ms be100-2.ams-5-a9.nl.eu (94.23.122.229)
71457 ... 9
714610 116.59 ms 91.kaasserver.com (95.211.5.91)
7147
7148NSE: Script Post-scanning.
7149Initiating NSE at 09:10
7150Completed NSE at 09:10, 0.00s elapsed
7151Initiating NSE at 09:10
7152Completed NSE at 09:10, 0.00s elapsed
7153Read data files from: /usr/bin/../share/nmap
7154OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7155Nmap done: 1 IP address (1 host up) scanned in 82.99 seconds
7156 Raw packets sent: 276 (15.834KB) | Rcvd: 188 (10.814KB)
7157
7158
7159Error: can not open nmap file: toptinygirls.com.txt
7160
7161
7162httprint v0.301 (beta) - web server fingerprinting tool
7163(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
7164http://net-square.com/httprint/
7165httprint@net-square.com
7166
7167Finger Printing on http://toptinygirls.com:80/
7168Finger Printing Completed on http://toptinygirls.com:80/
7169--------------------------------------------------
7170Host: toptinygirls.com
7171Fingerprinting Error: Host/URL not found...
7172
7173--------------------------------------------------
7174
7175
7176
7177
7178 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
7179 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
7180 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
7181 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
7182 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
7183
7184 _/ User-Agent Tester ↵
7185 _/ AKA: Purple Pimp ↵
7186 _/ ChrisJohnRiley ↵
7187 _/ blog.c22.cc ↵
7188
7189 [>] Performing initial request and confirming stability
7190 [>] Using User-Agent string Mozilla/5.0
7191
7192 [ ] URL (ENTERED): http://toptinygirls.com
7193 [ ] Response Code: 200 OK
7194 [ ] Date: Thu, 31 Aug 2017 13:10:23 GMT
7195 [ ] Server: Apache
7196 [ ] X-Powered-By: PHP/5.2.4-2ubuntu5.26
7197 [ ] Connection: close
7198 [ ] Transfer-Encoding: chunked
7199 [ ] Content-Type: text/html
7200 [ ] Data (MD5): de136e21a2f226c370f2d15cfc1d07dc
7201
7202 [1] Pass
7203 [2] Pass
7204 [3] Pass
7205
7206 [>] URL appears stable. Beginning test
7207
7208 [>] Using DEFAULT User-Agent Strings
7209
7210 [>] Using Crazy User-Agent Strings
7211 [>] Using Bot User-Agent Strings
7212
7213 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
7214
7215
7216 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
7217
7218
7219 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7220
7221
7222 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
7223
7224
7225 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7226
7227
7228 [>] User-Agent String : TrackBack/1.02
7229
7230
7231 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7232
7233
7234 [>] User-Agent String : wispr
7235
7236
7237 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7238
7239
7240 [>] User-Agent String : EMPTY USER-AGENT STRING!
7241
7242
7243 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7244
7245
7246 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
7247
7248
7249 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7250
7251
7252 [>] User-Agent String : Googlebot-Image/1.0
7253
7254
7255 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7256
7257
7258 [>] User-Agent String : Mediapartners-Google
7259
7260
7261 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7262
7263
7264 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
7265
7266
7267 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7268
7269
7270 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
7271
7272
7273 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7274
7275
7276 [>] User-Agent String : mmcrawler
7277
7278
7279 [!] Data (MD5): 748b524894bf89241a929880e5e9281a
7280
7281
7282 [>] Checks completed... try enabling VERBOSE mode for more detailed output
7283
7284 [>] That's all folks... Fo' Shizzle!
7285[i] Scanning Site: http://toptinygirls.com
7286
7287
7288
7289B A S I C I N F O
7290=======================================================================================================================
7291
7292
7293
7294
7295[+] Site Title: TopTinyGirls.com :: your teen resource ...
7296[+] IP address: 95.211.5.91
7297[+] Web Server: Apache
7298[+] CMS: Could Not Detect
7299[+] Cloudflare: Not Detected
7300[+] Robots File: Found
7301
7302-------------[ contents ]----------------
7303User-Agent: *
7304Allow:
7305
7306
7307-----------[end of contents]-------------
7308
7309
7310
7311W H O I S L O O K U P
7312===========================================================================================================================
7313
7314
7315
7316 Domain Name: TOPTINYGIRLS.COM
7317 Registry Domain ID: 1496685204_DOMAIN_COM-VRSN
7318 Registrar WHOIS Server: whois.godaddy.com
7319 Registrar URL: http://www.godaddy.com
7320 Updated Date: 2017-06-19T11:44:31Z
7321 Creation Date: 2008-06-18T22:58:21Z
7322 Registry Expiry Date: 2018-06-18T22:58:21Z
7323 Registrar: GoDaddy.com, LLC
7324 Registrar IANA ID: 146
7325 Registrar Abuse Contact Email: abuse@godaddy.com
7326 Registrar Abuse Contact Phone: 480-624-2505
7327 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
7328 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
7329 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7330 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
7331 Name Server: NS09.DOMAINCONTROL.COM
7332 Name Server: NS10.DOMAINCONTROL.COM
7333
7334
7335G E O I P L O O K U P
7336============================================================================================================================
7337
7338
7339
7340[i] IP Address: 95.211.5.91
7341[i] Country: NL
7342[i] State: N/A
7343[i] City: N/A
7344[i] Latitude: 52.382401
7345[i] Longitude: 4.899500
7346
7347
7348
7349
7350H T T P H E A D E R S
7351==========================================================================================================================
7352
7353
7354
7355
7356[i] HTTP/1.1 200 OK
7357[i] Date: Thu, 31 Aug 2017 12:52:28 GMT
7358[i] Server: Apache
7359[i] X-Powered-By: PHP/5.2.4-2ubuntu5.26
7360[i] Connection: close
7361[i] Content-Type: text/html
7362
7363
7364
7365
7366D N S L O O K U P
7367======================================================================================================================
7368
7369
7370
7371toptinygirls.com. 1796 IN A 95.211.5.91
7372toptinygirls.com. 3600 IN NS ns09.domaincontrol.com.
7373toptinygirls.com. 3600 IN NS ns10.domaincontrol.com.
7374toptinygirls.com. 3600 IN SOA ns09.domaincontrol.com. dns.jomax.net. 2016050200 28800 7200 604800 3600
7375toptinygirls.com. 1800 IN MX 0 91.kaasserver.com.
7376
7377
7378
7379
7380S U B N E T C A L C U L A T I O N
7381=======================================================================================================================================
7382
7383
7384
7385Address = 95.211.5.91
7386Network = 95.211.5.91 / 32
7387Netmask = 255.255.255.255
7388Broadcast = not needed on Point-to-Point links
7389Wildcard Mask = 0.0.0.0
7390Hosts Bits = 0
7391Max. Hosts = 1 (2^0 - 0)
7392Host Range = { 95.211.5.91 - 95.211.5.91 }
7393
7394
7395
7396N M A P P O R T S C A N
7397===============================================================================================================================
7398
7399
7400
7401
7402Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 12:52 UTC
7403Nmap scan report for toptinygirls.com (95.211.5.91)
7404Host is up (0.11s latency).
7405rDNS record for 95.211.5.91: 91.kaasserver.com
7406PORT STATE SERVICE VERSION
740721/tcp closed ftp
740822/tcp closed ssh
740923/tcp closed telnet
741025/tcp open smtp Postfix smtpd
741180/tcp open http Apache httpd
7412110/tcp closed pop3
7413143/tcp closed imap
7414443/tcp closed https
7415445/tcp filtered microsoft-ds
74163389/tcp closed ms-wbt-server
7417Service Info: Host: mx01.kaasserver.com
7418
7419Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7420Nmap done: 1 IP address (1 host up) scanned in 8.22 seconds
7421
7422
7423
7424S U B - D O M A I N F I N D E R
7425=====================================================================================================================================
7426
7427
7428
7429
7430[i] Total Subdomains Found : 1
7431
7432[+] Subdomain: toptinygirls.com
7433[-] IP: 95.211.5.91
7434
7435
7436---------------------------------------------------------------------------
7437+ Target IP: 95.211.5.91
7438+ Target Hostname: 95.211.5.91
7439+ Target Port: 80
7440+ Start Time: 2017-09-01 21:53:41 (GMT-4)
7441---------------------------------------------------------------------------
7442+ Server: Apache
7443+ The anti-clickjacking X-Frame-Options header is not present.
7444+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
7445+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
7446+ All CGI directories 'found', use '-C none' to test none
7447+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
7448+ OSVDB-3268: /icons/: Directory indexing found.
7449+ Server leaks inodes via ETags, header found with file /icons/README, inode: 29604597, size: 5108, mtime: Tue Aug 28 06:48:10 2007
7450+ OSVDB-3233: /icons/README: Apache default file found.
7451+ 26186 requests: 0 error(s) and 7 item(s) reported on remote host
7452+ End Time: 2017-09-01 23:37:59 (GMT-4) (6258 seconds)
7453
7454#######################################################################################################################################
7455
7456Hostname www.nnhoney.com ISP Unknown
7457Continent Unknown Flag
7458US
7459Country United States Country Code US
7460Region Unknown Local time 31 Aug 2017 08:26 CDT
7461City Unknown Latitude 37.751
7462IP Address (IPv6) 2400:cb00:2048:1::6812:24c4 Longitude -97.822
7463#####################################################################################################################################
7464nnhoney.com
7465
7466
7467 Domain Name: NNHONEY.COM
7468 Registry Domain ID: 144391280_DOMAIN_COM-VRSN
7469 Registrar WHOIS Server: whois.enom.com
7470 Registrar URL: http://www.enom.com
7471 Updated Date: 2017-07-14T16:54:03Z
7472 Creation Date: 2005-02-28T15:40:53Z
7473 Registry Expiry Date: 2018-02-28T15:40:53Z
7474 Registrar: eNom, Inc.
7475 Registrar IANA ID: 48
7476 Registrar Abuse Contact Email:
7477 Registrar Abuse Contact Phone:
7478 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7479 Name Server: IAN.NS.CLOUDFLARE.COM
7480 Name Server: POLA.NS.CLOUDFLARE.COM
7481
7482Domain Name: NNHONEY.COM
7483Registry Domain ID: 144391280_DOMAIN_COM-VRSN
7484Registrar WHOIS Server: whois.enom.com
7485Registrar URL: www.enom.com
7486Updated Date: 2014-01-28T00:38:53.00Z
7487Creation Date: 2005-02-28T15:40:00.00Z
7488Registrar Registration Expiration Date: 2018-02-28T15:40:53.00Z
7489Registrar: ENOM, INC.
7490Registrar IANA ID: 48
7491Reseller: NAMECHEAP.COM
7492Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
7493Registry Registrant ID:
7494Registrant Name: WHOISGUARD PROTECTED
7495Registrant Organization: WHOISGUARD, INC.
7496Registrant Street: P.O. BOX 0823-03411
7497Registrant City: PANAMA
7498Registrant State/Province: PANAMA
7499Registrant Postal Code:
7500Registrant Country: PA
7501Registrant Phone: +507.8365503
7502Registrant Phone Ext:
7503Registrant Fax: +51.17057182
7504Registrant Fax Ext:
7505Registrant Email: 8744BA8A894748FC9BEC2D501C931A60.PROTECT@WHOISGUARD.COM
7506Registry Admin ID:
7507Admin Name: WHOISGUARD PROTECTED
7508Admin Organization: WHOISGUARD, INC.
7509Admin Street: P.O. BOX 0823-03411
7510Admin City: PANAMA
7511Admin State/Province: PANAMA
7512Admin Postal Code:
7513Admin Country: PA
7514Admin Phone: +507.8365503
7515Admin Phone Ext:
7516Admin Fax: +51.17057182
7517Admin Fax Ext:
7518Admin Email: 8744BA8A894748FC9BEC2D501C931A60.PROTECT@WHOISGUARD.COM
7519Registry Tech ID:
7520Tech Name: WHOISGUARD PROTECTED
7521Tech Organization: WHOISGUARD, INC.
7522Tech Street: P.O. BOX 0823-03411
7523Tech City: PANAMA
7524Tech State/Province: PANAMA
7525Tech Postal Code:
7526Tech Country: PA
7527Tech Phone: +507.8365503
7528Tech Phone Ext:
7529Tech Fax: +51.17057182
7530Tech Fax Ext:
7531Tech Email: 8744BA8A894748FC9BEC2D501C931A60.PROTECT@WHOISGUARD.COM
7532Name Server: IAN.NS.CLOUDFLARE.COM
7533Name Server: POLA.NS.CLOUDFLARE.COM
7534DNSSEC: unSigned
7535Registrar Abuse Contact Email: abuse@enom.com
7536
7537;; OPT PSEUDOSECTION:
7538; EDNS: version: 0, flags:; udp: 4096
7539;; QUESTION SECTION:
7540;nnhoney.com. IN ANY
7541
7542;; ANSWER SECTION:
7543nnhoney.com. 259 IN A 104.18.36.196
7544nnhoney.com. 259 IN A 104.18.37.196
7545nnhoney.com. 259 IN AAAA 2400:cb00:2048:1::6812:24c4
7546nnhoney.com. 259 IN AAAA 2400:cb00:2048:1::6812:25c4
7547nnhoney.com. 76136 IN NS ian.ns.cloudflare.com.
7548nnhoney.com. 76136 IN NS pola.ns.cloudflare.com.
7549
7550;; Query time: 9 msec
7551;; SERVER: 192.168.1.254#53(192.168.1.254)
7552;; WHEN: Thu Aug 31 12:18:54 EDT 2017
7553;; MSG SIZE rcvd: 179
7554
7555
7556
7557;; Connection to 192.168.1.254#53(192.168.1.254) for nnhoney.com failed: connection refused.
7558Host nnhoney.com not found: 9(NOTAUTH)
7559; Transfer failed.
7560
7561
7562Please type the name of your network interface Example: eth0
7563eth0
7564
7565Running:
7566 traceroute -T -O info -i eth0 nnhoney.com
7567traceroute to nnhoney.com (104.18.37.196), 30 hops max, 60 byte packets
7568 1 gateway (192.168.1.254) 0.456 ms 0.620 ms 0.788 ms
7569 2 10.135.18.1 (10.135.18.1) 8.076 ms 12.452 ms *
7570 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 29.650 ms 29.915 ms 29.963 ms
7571 4 de-cix-new-york.as13335.net (206.130.10.31) 30.385 ms 31.101 ms 31.172 ms
7572 5 104.18.37.196 (104.18.37.196) <syn,ack> 31.447 ms 31.312 ms 31.759 ms
7573
7574
7575Host's addresses:
7576__________________
7577
7578nnhoney.com. 201 IN A 104.18.36.196
7579nnhoney.com. 201 IN A 104.18.37.196
7580
7581
7582Name Servers:
7583______________
7584
7585ian.ns.cloudflare.com. 24845 IN A 173.245.59.118
7586pola.ns.cloudflare.com. 4565 IN A 173.245.58.214
7587
7588
7589ftp.nnhoney.com
7590IPv6 address #1: 2400:cb00:2048:1::6812:24c4
7591IPv6 address #2: 2400:cb00:2048:1::6812:25c4
7592
7593ftp.nnhoney.com
7594IP address #1: 104.18.36.196
7595IP address #2: 104.18.37.196
7596
7597mail.nnhoney.com
7598IPv6 address #1: 2400:cb00:2048:1::6812:25c4
7599IPv6 address #2: 2400:cb00:2048:1::6812:24c4
7600
7601mail.nnhoney.com
7602IP address #1: 104.18.36.196
7603IP address #2: 104.18.37.196
7604
7605mysql.nnhoney.com
7606IPv6 address #1: 2400:cb00:2048:1::6812:24c4
7607IPv6 address #2: 2400:cb00:2048:1::6812:25c4
7608
7609mysql.nnhoney.com
7610IP address #1: 104.18.37.196
7611IP address #2: 104.18.36.196
7612
7613webmail.nnhoney.com
7614IPv6 address #1: 2400:cb00:2048:1::6812:24c4
7615IPv6 address #2: 2400:cb00:2048:1::6812:25c4
7616
7617webmail.nnhoney.com
7618IP address #1: 104.18.37.196
7619IP address #2: 104.18.36.196
7620
7621www.nnhoney.com
7622IPv6 address #1: 2400:cb00:2048:1::6812:24c4
7623IPv6 address #2: 2400:cb00:2048:1::6812:25c4
7624
7625www.nnhoney.com
7626IP address #1: 104.18.37.196
7627IP address #2: 104.18.36.196
7628
7629[+] 10 (sub)domains and 20 IP address(es) found
7630[+] completion time: 113 second(s)
7631
7632
7633Tracing to nnhoney.com[a] via 192.168.1.254, maximum of 3 retries
7634192.168.1.254 (192.168.1.254) Got answer
7635
7636
7637WhatWeb report for http://nnhoney.com
7638Status : 301 Moved Permanently
7639Title : <None>
7640IP : 104.18.37.196
7641Country : UNITED STATES, US
7642
7643Summary : CloudFlare, RedirectLocation[https://nnhoney.com/], HttpOnly[__cfduid], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
7644
7645Detected Plugins:
7646[ CloudFlare ]
7647 CloudFlare is a content delivery network. Its features
7648 include DDoS protection and Web Application Firewall
7649 functionality
7650
7651 Google Dorks: (1)
7652 Website : https://www.cloudflare.com/
7653
7654[ Cookies ]
7655 Display the names of cookies in the HTTP headers. The
7656 values are not returned to save on space.
7657
7658 String : __cfduid
7659
7660[ HTTPServer ]
7661 HTTP server header string. This plugin also attempts to
7662 identify the operating system from the server header.
7663
7664 String : cloudflare-nginx (from server string)
7665
7666[ HttpOnly ]
7667 If the HttpOnly flag is included in the HTTP set-cookie
7668 response header and the browser supports it then the cookie
7669 cannot be accessed through client side script - More Info:
7670 http://en.wikipedia.org/wiki/HTTP_cookie
7671
7672 String : __cfduid
7673
7674[ RedirectLocation ]
7675 HTTP Server string location. used with http-status 301 and
7676 302
7677
7678 String : https://nnhoney.com/ (from location)
7679
7680[ UncommonHeaders ]
7681 Uncommon HTTP server headers. The blacklist includes all
7682 the standard headers and many non standard but common ones.
7683 Interesting but fairly common headers should have their own
7684 plugins, eg. x-powered-by, server and x-aspnet-version.
7685 Info about headers can be found at www.http-stats.com
7686
7687 String : cf-ray (from headers)
7688
7689HTTP Headers:
7690 HTTP/1.1 301 Moved Permanently
7691 Date: Thu, 31 Aug 2017 16:21:57 GMT
7692 Content-Type: text/html; charset=UTF-8
7693 Transfer-Encoding: chunked
7694 Connection: close
7695 Set-Cookie: __cfduid=d6e6ba99380ff87463148203280c6ab741504196516; expires=Fri, 31-Aug-18 16:21:56 GMT; path=/; domain=.nnhoney.com; HttpOnly
7696 Location: https://nnhoney.com/
7697 Server: cloudflare-nginx
7698 CF-RAY: 39715366a52c694a-CDG
7699
7700WhatWeb report for https://nnhoney.com/
7701Status : 301 Moved Permanently
7702Title : <None>
7703IP : 104.18.37.196
7704Country : UNITED STATES, US
7705
7706Summary : CloudFlare, RedirectLocation[https://www.nnhoney.com/], HttpOnly[__cfduid], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
7707
7708Detected Plugins:
7709[ CloudFlare ]
7710 CloudFlare is a content delivery network. Its features
7711 include DDoS protection and Web Application Firewall
7712 functionality
7713
7714 Google Dorks: (1)
7715 Website : https://www.cloudflare.com/
7716
7717[ Cookies ]
7718 Display the names of cookies in the HTTP headers. The
7719 values are not returned to save on space.
7720
7721 String : __cfduid
7722
7723[ HTTPServer ]
7724 HTTP server header string. This plugin also attempts to
7725 identify the operating system from the server header.
7726
7727 String : cloudflare-nginx (from server string)
7728
7729[ HttpOnly ]
7730 If the HttpOnly flag is included in the HTTP set-cookie
7731 response header and the browser supports it then the cookie
7732 cannot be accessed through client side script - More Info:
7733 http://en.wikipedia.org/wiki/HTTP_cookie
7734
7735 String : __cfduid
7736
7737[ RedirectLocation ]
7738 HTTP Server string location. used with http-status 301 and
7739 302
7740
7741 String : https://www.nnhoney.com/ (from location)
7742
7743[ UncommonHeaders ]
7744 Uncommon HTTP server headers. The blacklist includes all
7745 the standard headers and many non standard but common ones.
7746 Interesting but fairly common headers should have their own
7747 plugins, eg. x-powered-by, server and x-aspnet-version.
7748 Info about headers can be found at www.http-stats.com
7749
7750 String : cf-ray (from headers)
7751
7752HTTP Headers:
7753 HTTP/1.1 301 Moved Permanently
7754 Date: Thu, 31 Aug 2017 16:21:58 GMT
7755 Content-Type: text/html; charset=UTF-8
7756 Transfer-Encoding: chunked
7757 Connection: close
7758 Set-Cookie: __cfduid=d7323957424c296d5854a14b83d5a566d1504196518; expires=Fri, 31-Aug-18 16:21:58 GMT; path=/; domain=.nnhoney.com; HttpOnly
7759 Location: https://www.nnhoney.com/
7760 Server: cloudflare-nginx
7761 CF-RAY: 3971536ec9310920-CDG
7762
7763WhatWeb report for https://www.nnhoney.com/
7764Status : 200 OK
7765Title : NN Honey - NN Teens Are The Best Teens
7766IP : 104.18.37.196
7767Country : UNITED STATES, US
7768
7769Summary : HTML5, CloudFlare, Script[application/ld+json,text/javascript], MetaGenerator[WordPress 4.8.1], HttpOnly[__cfduid], UncommonHeaders[link,cf-ray], HTTPServer[cloudflare-nginx], Open-Graph-Protocol[website], Cookies[__cfduid], JQuery[1.12.4], WordPress[4.8.1]
7770
7771Detected Plugins:
7772[ CloudFlare ]
7773 CloudFlare is a content delivery network. Its features
7774 include DDoS protection and Web Application Firewall
7775 functionality
7776
7777 Google Dorks: (1)
7778 Website : https://www.cloudflare.com/
7779
7780[ Cookies ]
7781 Display the names of cookies in the HTTP headers. The
7782 values are not returned to save on space.
7783
7784 String : __cfduid
7785
7786[ HTML5 ]
7787 HTML version 5, detected by the doctype declaration
7788
7789
7790[ HTTPServer ]
7791 HTTP server header string. This plugin also attempts to
7792 identify the operating system from the server header.
7793
7794 String : cloudflare-nginx (from server string)
7795
7796[ HttpOnly ]
7797 If the HttpOnly flag is included in the HTTP set-cookie
7798 response header and the browser supports it then the cookie
7799 cannot be accessed through client side script - More Info:
7800 http://en.wikipedia.org/wiki/HTTP_cookie
7801
7802 String : __cfduid
7803
7804[ JQuery ]
7805 A fast, concise, JavaScript that simplifies how to traverse
7806 HTML documents, handle events, perform animations, and add
7807 AJAX.
7808
7809 Version : 1.12.4
7810 Website : http://jquery.com/
7811
7812[ MetaGenerator ]
7813 This plugin identifies meta generator tags and extracts its
7814 value.
7815
7816 String : WordPress 4.8.1
7817
7818[ Open-Graph-Protocol ]
7819 The Open Graph protocol enables you to integrate your Web
7820 pages into the social graph. It is currently designed for
7821 Web pages representing profiles of real-world things .
7822 things like movies, sports teams, celebrities, and
7823 restaurants. Including Open Graph tags on your Web page,
7824 makes your page equivalent to a Facebook Page.
7825
7826 Version : website
7827
7828[ Script ]
7829 This plugin detects instances of script HTML elements and
7830 returns the script language/type.
7831
7832 String : application/ld+json,text/javascript
7833
7834[ UncommonHeaders ]
7835 Uncommon HTTP server headers. The blacklist includes all
7836 the standard headers and many non standard but common ones.
7837 Interesting but fairly common headers should have their own
7838 plugins, eg. x-powered-by, server and x-aspnet-version.
7839 Info about headers can be found at www.http-stats.com
7840
7841 String : link,cf-ray (from headers)
7842
7843[ WordPress ]
7844 WordPress is an opensource blogging system commonly used as
7845 a CMS.
7846
7847 Version : 4.8.1
7848 Aggressive function available (check plugin file or details).
7849 Google Dorks: (1)
7850 Website : http://www.wordpress.org/
7851
7852HTTP Headers:
7853 HTTP/1.1 200 OK
7854 Date: Thu, 31 Aug 2017 16:22:00 GMT
7855 Content-Type: text/html; charset=UTF-8
7856 Transfer-Encoding: chunked
7857 Connection: close
7858 Set-Cookie: __cfduid=d9760187b3d0ddcc366d1dedb260e49621504196519; expires=Fri, 31-Aug-18 16:21:59 GMT; path=/; domain=.nnhoney.com; HttpOnly
7859 Link: <https://www.nnhoney.com/wp-json/>; rel="https://api.w.org/"
7860 Server: cloudflare-nginx
7861 CF-RAY: 39715377cfbd691a-CDG
7862 Content-Encoding: gzip
7863
7864
7865
7866
7867[+] Hosts found in search engines:
7868------------------------------------
7869[-] Resolving hostnames IPs...
7870104.18.36.196:www.nnhoney.com
7871
7872
7873
7874 ^ ^
7875 _ __ _ ____ _ __ _ _ ____
7876 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
7877 | V V // o // _/ | V V // 0 // 0 // _/
7878 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
7879 <
7880 ...'
7881
7882 WAFW00F - Web Application Firewall Detection Tool
7883
7884 By Sandro Gauci && Wendel G. Henrique
7885
7886Checking http://nnhoney.com
7887The site http://nnhoney.com is behind a CloudFlare
7888Number of requests: 1
7889
7890
7891DNS Servers for nnhoney.com:
7892 ian.ns.cloudflare.com
7893 pola.ns.cloudflare.com
7894
7895Trying zone transfer first...
7896 Testing ian.ns.cloudflare.com
7897 Request timed out or transfer not allowed.
7898 Testing pola.ns.cloudflare.com
7899 Request timed out or transfer not allowed.
7900
7901Unsuccessful in zone transfer (it was worth a shot)
7902Okay, trying the good old fashioned way... brute force
7903
7904Checking for wildcard DNS...
7905Nope. Good.
7906Now performing 2280 test(s)...
7907104.18.37.196 ftp.nnhoney.com
7908104.18.36.196 ftp.nnhoney.com
7909104.18.36.196 mail.nnhoney.com
7910104.18.37.196 mail.nnhoney.com
7911104.18.36.196 mysql.nnhoney.com
7912104.18.37.196 mysql.nnhoney.com
7913104.18.37.196 webmail.nnhoney.com
7914104.18.36.196 webmail.nnhoney.com
7915104.18.36.196 www.nnhoney.com
7916104.18.37.196 www.nnhoney.com
7917
7918Subnets found (may want to probe here using nmap or unicornscan):
7919 104.18.36.0-255 : 5 hostnames found.
7920 104.18.37.0-255 : 5 hostnames found.
7921
7922Done with Fierce scan: http://ha.ckers.org/fierce/
7923Found 10 entries.
7924
7925Have a nice day.
7926
7927
7928
7929lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
7930 Written by Stefan Behte (http://ge.mine.nu)
7931 Proof-of-concept! Might give false positives.
7932
7933Checking for DNS-Loadbalancing: FOUND
7934nnhoney.com has address 104.18.37.196
7935nnhoney.com has address 104.18.36.196
7936
7937Checking for HTTP-Loadbalancing [Server]:
7938 cloudflare-nginx
7939 NOT FOUND
7940
7941Checking for HTTP-Loadbalancing [Date]: 16:27:32, 16:27:32, 16:27:33, 16:27:33, 16:27:33, 16:27:34, 16:27:34, 16:27:34, 16:27:34, 16:27:35, 16:27:35, 16:27:35, 16:27:35, 16:27:36, 16:27:36, 16:27:36, 16:27:36, 16:27:37, 16:27:37, 16:27:37, 16:27:38, 16:27:38, 16:27:38, 16:27:38, 16:27:39, 16:27:39, 16:27:39, 16:27:40, 16:27:40, 16:27:40, 16:27:40, 16:27:41, 16:27:41, 16:27:41, 16:27:41, 16:27:42, 16:27:42, 16:27:42, 16:27:43, 16:27:43, 16:27:43, 16:27:43, 16:27:44, 16:27:44, 16:27:44, 16:27:44, 16:27:45, 16:27:45, 16:27:45, 16:27:46, NOT FOUND
7942
7943Checking for HTTP-Loadbalancing [Diff]: FOUND
7944< CF-RAY: 39715bee94313c23-CDG
7945> CF-RAY: 39715bf0247a3c29-CDG
7946
7947nnhoney.com does Load-balancing. Found via Methods: DNS HTTP[Diff]
7948
7949
7950
7951Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
7952
7953 ----------------------------------------------------------
7954| Scan Information |
7955 ----------------------------------------------------------
7956
7957Mode ..................... VRFY
7958Worker Processes ......... 5
7959Usernames file ........... users.txt
7960Target count ............. 1
7961Username count ........... 494
7962Target TCP port .......... 25
7963Query timeout ............ 5 secs
7964Target domain ............
7965
7966######## Scan started at Thu Aug 31 12:27:37 2017 #########
7967######## Scan completed at Thu Aug 31 12:35:52 2017 #########
79680 results.
7969
7970494 queries in 495 seconds (1.0 queries / sec)
7971
7972
7973
7974Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-31 12:35 EDT
7975NSE: Loaded 146 scripts for scanning.
7976NSE: Script Pre-scanning.
7977Initiating NSE at 12:35
7978Completed NSE at 12:35, 0.00s elapsed
7979Initiating NSE at 12:35
7980Completed NSE at 12:35, 0.00s elapsed
7981Failed to resolve "nnhoney.com.txt".
7982Initiating Parallel DNS resolution of 1 host. at 12:35
7983Completed Parallel DNS resolution of 1 host. at 12:36, 11.11s elapsed
7984Initiating SYN Stealth Scan at 12:36
7985Scanning nnhoney.com (104.18.37.196) [100 ports]
7986Discovered open port 443/tcp on 104.18.37.196
7987Discovered open port 80/tcp on 104.18.37.196
7988Discovered open port 8080/tcp on 104.18.37.196
7989Discovered open port 8443/tcp on 104.18.37.196
7990Completed SYN Stealth Scan at 12:36, 3.59s elapsed (100 total ports)
7991Initiating Service scan at 12:36
7992Scanning 4 services on nnhoney.com (104.18.37.196)
7993Completed Service scan at 12:36, 13.59s elapsed (4 services on 1 host)
7994Initiating OS detection (try #1) against nnhoney.com (104.18.37.196)
7995Retrying OS detection (try #2) against nnhoney.com (104.18.37.196)
7996Initiating Traceroute at 12:36
7997Completed Traceroute at 12:36, 0.16s elapsed
7998Initiating Parallel DNS resolution of 7 hosts. at 12:36
7999Completed Parallel DNS resolution of 7 hosts. at 12:36, 5.72s elapsed
8000NSE: Script scanning 104.18.37.196.
8001Initiating NSE at 12:36
8002Completed NSE at 12:36, 25.97s elapsed
8003Initiating NSE at 12:36
8004Completed NSE at 12:36, 0.01s elapsed
8005Nmap scan report for nnhoney.com (104.18.37.196)
8006Host is up (0.12s latency).
8007Other addresses for nnhoney.com (not scanned): 2400:cb00:2048:1::6812:24c4 2400:cb00:2048:1::6812:25c4 104.18.36.196
8008Not shown: 96 filtered ports
8009PORT STATE SERVICE VERSION
801080/tcp open http Cloudflare nginx
8011| http-methods:
8012|_ Supported Methods: GET HEAD POST OPTIONS
8013|_http-server-header: cloudflare-nginx
8014|_http-title: Did not follow redirect to https://nnhoney.com/
8015443/tcp open ssl/http Cloudflare nginx
8016| ssl-cert: Subject: commonName=sni171563.cloudflaressl.com
8017| Subject Alternative Name: DNS:sni171563.cloudflaressl.com, DNS:*.acreativecouple.com, DNS:*.agedbeauty.net, DNS:*.babshopjd.gq, DNS:*.discountefhotdshop.ga, DNS:*.echtgeschickt.faith, DNS:*.femdompleasures.com, DNS:*.fuckyeahcosplay.com, DNS:*.fuckyeahcurvygirls.com, DNS:*.fuckyeahfitgirls.com, DNS:*.getsugarinstant.com, DNS:*.igenesisscimedpro.com, DNS:*.jina0mr.cf, DNS:*.joyofincest.com, DNS:*.justsexyteengirls.com, DNS:*.lilithmedia.com, DNS:*.m7likcmidou.gq, DNS:*.nnhoney.com, DNS:*.pricegfsalehotbest.cf, DNS:*.primetush.com, DNS:*.purennmodels.com, DNS:*.servicecenterrijscholen.nl, DNS:*.survivalnation.org, DNS:*.tscraze.com, DNS:acreativecouple.com, DNS:agedbeauty.net, DNS:babshopjd.gq, DNS:discountefhotdshop.ga, DNS:echtgeschickt.faith, DNS:femdompleasures.com, DNS:fuckyeahcosplay.com, DNS:fuckyeahcurvygirls.com, DNS:fuckyeahfitgirls.com, DNS:getsugarinstant.com, DNS:igenesisscimedpro.com, DNS:jina0mr.cf, DNS:joyofincest.com, DNS:justsexyteengirls.com, DNS:lilithmedia.com, DNS:m7likcmidou.gq, DNS:nnhoney.com, DNS:pricegfsalehotbest.cf, DNS:primetush.com, DNS:purennmodels.com, DNS:servicecenterrijscholen.nl, DNS:survivalnation.org, DNS:tscraze.com
8018| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
8019| Public Key type: ec
8020| Public Key bits: 256
8021| Signature Algorithm: ecdsa-with-SHA256
8022| Not valid before: 2017-08-10T00:00:00
8023| Not valid after: 2018-02-16T23:59:59
8024| MD5: 918e 8e0e 2484 7955 c0a6 ebbe 23a9 2853
8025|_SHA-1: 5594 de17 f43d 25de 0369 6aed 0da2 c78b fdcc 09ee
80268080/tcp open http Cloudflare nginx
8027|_http-server-header: cloudflare-nginx
8028|_http-title: nnhoney.com | 521: Web server is down
80298443/tcp open ssl/http Cloudflare nginx
8030| ssl-cert: Subject: commonName=sni171563.cloudflaressl.com
8031| Subject Alternative Name: DNS:sni171563.cloudflaressl.com, DNS:*.acreativecouple.com, DNS:*.agedbeauty.net, DNS:*.babshopjd.gq, DNS:*.discountefhotdshop.ga, DNS:*.echtgeschickt.faith, DNS:*.femdompleasures.com, DNS:*.fuckyeahcosplay.com, DNS:*.fuckyeahcurvygirls.com, DNS:*.fuckyeahfitgirls.com, DNS:*.getsugarinstant.com, DNS:*.igenesisscimedpro.com, DNS:*.jina0mr.cf, DNS:*.joyofincest.com, DNS:*.justsexyteengirls.com, DNS:*.lilithmedia.com, DNS:*.m7likcmidou.gq, DNS:*.nnhoney.com, DNS:*.pricegfsalehotbest.cf, DNS:*.primetush.com, DNS:*.purennmodels.com, DNS:*.servicecenterrijscholen.nl, DNS:*.survivalnation.org, DNS:*.tscraze.com, DNS:acreativecouple.com, DNS:agedbeauty.net, DNS:babshopjd.gq, DNS:discountefhotdshop.ga, DNS:echtgeschickt.faith, DNS:femdompleasures.com, DNS:fuckyeahcosplay.com, DNS:fuckyeahcurvygirls.com, DNS:fuckyeahfitgirls.com, DNS:getsugarinstant.com, DNS:igenesisscimedpro.com, DNS:jina0mr.cf, DNS:joyofincest.com, DNS:justsexyteengirls.com, DNS:lilithmedia.com, DNS:m7likcmidou.gq, DNS:nnhoney.com, DNS:pricegfsalehotbest.cf, DNS:primetush.com, DNS:purennmodels.com, DNS:servicecenterrijscholen.nl, DNS:survivalnation.org, DNS:tscraze.com
8032| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
8033| Public Key type: ec
8034| Public Key bits: 256
8035| Signature Algorithm: ecdsa-with-SHA256
8036| Not valid before: 2017-08-10T00:00:00
8037| Not valid after: 2018-02-16T23:59:59
8038| MD5: 918e 8e0e 2484 7955 c0a6 ebbe 23a9 2853
8039|_SHA-1: 5594 de17 f43d 25de 0369 6aed 0da2 c78b fdcc 09ee
8040Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
8041Device type: general purpose
8042Running (JUST GUESSING): Linux 3.X|2.6.X (88%)
8043OS CPE: cpe:/o:linux:linux_kernel:3.18 cpe:/o:linux:linux_kernel:2.6
8044Aggressive OS guesses: Linux 3.18 (88%), Linux 2.6.18 - 2.6.22 (86%)
8045No exact OS matches for host (test conditions non-ideal).
8046Network Distance: 7 hops
8047TCP Sequence Prediction: Difficulty=260 (Good luck!)
8048IP ID Sequence Generation: All zeros
8049
8050TRACEROUTE (using port 443/tcp)
8051HOP RTT ADDRESS
80521 110.35 ms 10.13.0.1
80532 153.99 ms 37.187.24.252
80543 138.29 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
80554 138.36 ms 10.95.33.10
80565 138.60 ms be99-1110.th2-1-a9.fr.eu (213.186.32.215)
80576 138.64 ms equinix-paris.cloudflare.com (195.42.144.143)
80587 138.59 ms 104.18.37.196
8059
8060NSE: Script Post-scanning.
8061Initiating NSE at 12:36
8062Completed NSE at 12:36, 0.00s elapsed
8063Initiating NSE at 12:36
8064Completed NSE at 12:36, 0.00s elapsed
8065Read data files from: /usr/bin/../share/nmap
8066OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
8067Nmap done: 1 IP address (1 host up) scanned in 65.66 seconds
8068 Raw packets sent: 301 (18.452KB) | Rcvd: 56 (4.716KB)
8069
8070
8071Error: can not open nmap file: nnhoney.com.txt
8072
8073
8074httprint v0.301 (beta) - web server fingerprinting tool
8075(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
8076http://net-square.com/httprint/
8077httprint@net-square.com
8078
8079Finger Printing on http://nnhoney.com:80/
8080Finger Printing Completed on http://nnhoney.com:80/
8081--------------------------------------------------
8082Host: nnhoney.com
8083Fingerprinting Error: Host/URL not found...
8084
8085--------------------------------------------------
8086
8087
8088
8089
8090 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
8091 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
8092 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
8093 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
8094 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
8095
8096 _/ User-Agent Tester ↵
8097 _/ AKA: Purple Pimp ↵
8098 _/ ChrisJohnRiley ↵
8099 _/ blog.c22.cc ↵
8100
8101 [>] Performing initial request and confirming stability
8102 [>] Using User-Agent string Mozilla/5.0
8103
8104 [ ] URL (ENTERED): http://nnhoney.com
8105 [!] URL (FINAL): https://www.nnhoney.com/
8106 [!] Response Code: 301 Moved Permanently
8107 [ ] Date: Thu, 31 Aug 2017 16:37:14 GMT
8108 [ ] Content-Type: text/html; charset=UTF-8
8109 [ ] Transfer-Encoding: chunked
8110 [ ] Connection: close
8111 [ ] Set-Cookie: __cfduid=d7d53805d7ad7ce99a90f6ab9815cc9f21504197433; expires=Fri, 31-Aug-18 16:37:13 GMT;
8112 path=/; domain=.nnhoney.com; HttpOnly
8113 [ ] Link: <https://www.nnhoney.com/wp-json/>; rel="https://api.w.org/"
8114 [ ] Server: cloudflare-nginx
8115 [ ] CF-RAY: 397169c9ea0a21e6-EWR
8116 [ ] Data (MD5): 80a35e117387803f2783ca4b3edf83fa
8117
8118 [1] Pass
8119 [2] Pass
8120 [3] Pass
8121
8122 [>] URL appears stable. Beginning test
8123
8124 [>] Using DEFAULT User-Agent Strings
8125
8126 [>] Using Crazy User-Agent Strings
8127 [>] Using Bot User-Agent Strings
8128
8129 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
8130
8131
8132 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
8133
8134
8135 [!] CF-RAY: 39716a3d9f21076d-EWR
8136
8137
8138 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
8139
8140
8141 [!] CF-RAY: 39716a4c79bd2210-EWR
8142 [*] HTTPError: HTTP Error 403: Forbidden
8143[i] Scanning Site: http://nnhoney.com
8144
8145
8146
8147B A S I C I N F O
8148=======================================================================================================================
8149
8150
8151
8152
8153[+] Site Title: NN Honey - NN Teens Are The Best Teens
8154[+] IP address: 104.18.37.196
8155[+] Web Server: cloudflare-nginx
8156[+] CMS: WordPress
8157[+] Cloudflare: Detected
8158[+] Robots File: Could NOT Find robots.txt!
8159
8160
8161
8162
8163W H O I S L O O K U P
8164===========================================================================================================================
8165
8166
8167
8168 Domain Name: NNHONEY.COM
8169 Registry Domain ID: 144391280_DOMAIN_COM-VRSN
8170 Registrar WHOIS Server: whois.enom.com
8171 Registrar URL: http://www.enom.com
8172 Updated Date: 2017-07-14T16:54:03Z
8173 Creation Date: 2005-02-28T15:40:53Z
8174 Registry Expiry Date: 2018-02-28T15:40:53Z
8175 Registrar: eNom, Inc.
8176 Registrar IANA ID: 48
8177 Registrar Abuse Contact Email:
8178 Registrar Abuse Contact Phone:
8179 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
8180 Name Server: IAN.NS.CLOUDFLARE.COM
8181 Name Server: POLA.NS.CLOUDFLARE.COM
8182 DNSSEC: unsigned
8183 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
8184>
8185G E O I P L O O K U P
8186============================================================================================================================
8187
8188
8189
8190[i] IP Address: 104.18.37.196
8191[i] Country: US
8192[i] State: California
8193[i] City: San Francisco
8194[i] Latitude: 37.769699
8195[i] Longitude: -122.393303
8196
8197
8198
8199
8200H T T P H E A D E R S
8201==========================================================================================================================
8202
8203
8204
8205
8206[i] HTTP/1.1 301 Moved Permanently
8207[i] Date: Thu, 31 Aug 2017 16:19:53 GMT
8208[i] Content-Type: text/html; charset=UTF-8
8209[i] Connection: close
8210[i] Set-Cookie: __cfduid=db3848e4c4f8e5a45330ed3618347ce9c1504196393; expires=Fri, 31-Aug-18 16:19:53 GMT; path=/; domain=.nnhoney.com; HttpOnly
8211[i] Location: https://nnhoney.com/
8212[i] Server: cloudflare-nginx
8213[i] CF-RAY: 39715060d68e46fe-EWR
8214[i] HTTP/1.1 301 Moved Permanently
8215[i] Date: Thu, 31 Aug 2017 16:19:54 GMT
8216[i] Content-Type: text/html; charset=UTF-8
8217[i] Connection: close
8218[i] Set-Cookie: __cfduid=df4fc2f5c8c20ec6be9055fc867bf95581504196393; expires=Fri, 31-Aug-18 16:19:53 GMT; path=/; domain=.nnhoney.com; HttpOnly
8219[i] Location: https://www.nnhoney.com/
8220[i] Server: cloudflare-nginx
8221[i] CF-RAY: 397150653c981864-EWR
8222[i] HTTP/1.1 200 OK
8223[i] Date: Thu, 31 Aug 2017 16:19:55 GMT
8224[i] Content-Type: text/html; charset=UTF-8
8225[i] Connection: close
8226[i] Set-Cookie: __cfduid=d66e59fb702c8388a1e078780ee0599b31504196394; expires=Fri, 31-Aug-18 16:19:54 GMT; path=/; domain=.nnhoney.com; HttpOnly
8227[i] Link: <https://www.nnhoney.com/wp-json/>; rel="https://api.w.org/"
8228[i] Server: cloudflare-nginx
8229[i] CF-RAY: 3971506a7d9446fe-EWR
8230
8231
8232
8233
8234D N S L O O K U P
8235======================================================================================================================
8236
8237
8238
8239nnhoney.com. 292 IN A 104.18.36.196
8240nnhoney.com. 292 IN A 104.18.37.196
8241nnhoney.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
8242nnhoney.com. 292 IN AAAA 2400:cb00:2048:1::6812:24c4
8243nnhoney.com. 292 IN AAAA 2400:cb00:2048:1::6812:25c4
8244
8245
8246
8247
8248S U B N E T C A L C U L A T I O N
8249=======================================================================================================================================
8250
8251
8252
8253Address = 2400:cb00:2048:1::6812:25c4
8254Network = 2400:cb00:2048:1::6812:25c4 / 128
8255Netmask = ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff
8256Wildcard Mask = ::
8257Hosts Bits = 0
8258Max. Hosts = 0 (2^0 - 1)
8259Host Range = { 2400:cb00:2048:1::6812:25c5 - 2400:cb00:2048:1::6812:25c4 }
8260
8261
8262
8263N M A P P O R T S C A N
8264===============================================================================================================================
8265
8266
8267
8268
8269Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-31 16:19 UTC
8270Nmap scan report for nnhoney.com (104.18.36.196)
8271Host is up (0.0076s latency).
8272Other addresses for nnhoney.com (not scanned): 104.18.37.196 2400:cb00:2048:1::6812:25c4 2400:cb00:2048:1::6812:24c4
8273PORT STATE SERVICE VERSION
827421/tcp filtered ftp
827522/tcp filtered ssh
827623/tcp filtered telnet
827725/tcp filtered smtp
827880/tcp open http Cloudflare nginx
8279110/tcp filtered pop3
8280143/tcp filtered imap
8281443/tcp open ssl/http Cloudflare nginx
8282445/tcp filtered microsoft-ds
82833389/tcp filtered ms-wbt-server
8284
8285Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
8286Nmap done: 1 IP address (1 host up) scanned in 13.88 seconds
8287
8288
8289
8290S U B - D O M A I N F I N D E R
8291=====================================================================================================================================
8292
8293
8294
8295
8296[i] Total Subdomains Found : 2
8297
8298[+] Subdomain: nnhoney.com
8299[-] IP: 104.18.36.196
8300
8301[+] Subdomain: nnhoney.com
8302[-] IP: 104.18.37.196
8303
8304
8305R E V E R S E I P L O O K U P
8306=====================================================================================================================================
8307
8308
8309
8310
8311[i] Total Sites Found On This Server : 4
8312
8313
8314[#] nnhoney.com
8315[-] CMS: WordPress
8316
8317[#] www.chefsresource.com
8318[-] CMS: Could Not Detect
8319
8320[#] www.nnhoney.com
8321[-] CMS: WordPress
8322
8323[#] www.urbanitsolutions.co.uk,
8324[-] CMS: Could Not Detect
8325Nikto v2.1.6
8326---------------------------------------------------------------------------
8327+ Target IP: 104.18.37.196
8328+ Target Hostname: 104.18.37.196
8329+ Target Port: 80
8330+ Start Time: 2017-08-31 16:12:16 (GMT-4)
8331---------------------------------------------------------------------------
8332+ Server: cloudflare-nginx
8333+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
8334+ Uncommon header 'cf-ray' found, with contents: 3972a50be77469b2-CDG
8335+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
8336+ All CGI directories 'found', use '-C none' to test none
8337+ Server banner has changed from 'cloudflare-nginx' to '-nginx' which may suggest a WAF, load balancer or proxy is in place
8338+ ERROR: Error limit (20) reached for host, giving up. Last error: error reading HTTP response
8339+ Scan terminated: 6 error(s) and 3 item(s) reported on remote host
8340+ End Time: 2017-08-31 16:53:51 (GMT-4) (2495 seconds)
8341---------------------------------------------------------------------------
8342#######################################################################################################################################
8343Hostname www.teeniesugar.com ISP Omnis Network, LLC (AS19237)
8344Continent North America Flag
8345US
8346Country United States Country Code US (USA)
8347Region CA Local time 01 Sep 2017 21:13 PDT
8348Metropolis* Los Angeles Postal Code 90503
8349City Torrance Latitude 33.836
8350IP Address 216.17.111.213 Longitude -118.341
8351######################################################################################################################################
8352eeniesugar.com
8353
8354
8355 Domain Name: TEENIESUGAR.COM
8356 Registry Domain ID: 1483149175_DOMAIN_COM-VRSN
8357 Registrar WHOIS Server: whois.godaddy.com
8358 Registrar URL: http://www.godaddy.com
8359 Updated Date: 2017-05-27T21:21:04Z
8360 Creation Date: 2008-05-30T09:59:22Z
8361 Registry Expiry Date: 2018-05-30T09:59:22Z
8362 Registrar: GoDaddy.com, LLC
8363 Registrar IANA ID: 146
8364 Registrar Abuse Contact Email: abuse@godaddy.com
8365 Registrar Abuse Contact Phone: 480-624-2505
8366 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
8367 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
8368 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
8369 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
8370
8371Domain Name: TEENIESUGAR.COM
8372Registrar URL: http://www.godaddy.com
8373Registrant Name: Andreas O
8374Registrant Organization:
8375Name Server: NS1.AMERINOC.COM
8376Name Server: NS2.AMERINOC.COM
8377
8378
8379
8380
8381; <<>> DiG 9.10.3-P4-Debian <<>> teeniesugar.com any
8382;; global options: +cmd
8383;; Got answer:
8384;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37492
8385;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
8386
8387;; OPT PSEUDOSECTION:
8388; EDNS: version: 0, flags:; udp: 4096
8389;; QUESTION SECTION:
8390;teeniesugar.com. IN ANY
8391
8392;; ANSWER SECTION:
8393teeniesugar.com. 14400 IN MX 10 mail.teeniesugar.com.
8394teeniesugar.com. 86400 IN SOA primary.guardeddns.net. dns-admin.guardeddns.net. 102 28800 450 1209600 900
8395teeniesugar.com. 11582 IN A 216.17.111.213
8396teeniesugar.com. 14400 IN NS ns1.amerinoc.com.
8397teeniesugar.com. 14400 IN NS ns2.amerinoc.com.
8398
8399;; Query time: 97 msec
8400;; SERVER: 192.168.1.254#53(192.168.1.254)
8401;; WHEN: Sat Sep 02 00:14:03 EDT 2017
8402;; MSG SIZE rcvd: 194
8403
8404
8405
8406;; Connection to 192.168.1.254#53(192.168.1.254) for teeniesugar.com failed: connection refused.
8407Host teeniesugar.com not found: 9(NOTAUTH)
8408; Transfer failed.
8409
8410
8411Please type the name of your network interface Example: eth0
8412eth0
8413
8414Running:
8415 traceroute -T -O info -i eth0 teeniesugar.com
8416traceroute to teeniesugar.com (216.17.111.213), 30 hops max, 60 byte packets
8417 1 gateway (192.168.1.254) 0.638 ms 0.884 ms 1.173 ms
8418 2 10.135.18.1 (10.135.18.1) 7.567 ms 8.006 ms 8.184 ms
8419 3 75.154.223.222 (75.154.223.222) 30.088 ms 30.121 ms 30.368 ms
8420 4 v704.core1.nyc4.he.net (209.51.184.241) 30.539 ms 30.654 ms 35.074 ms
8421 5 100ge8-2.core1.ash1.he.net (184.105.223.165) 35.846 ms 35.937 ms 35.964 ms
8422 6 100ge8-2.core1.atl1.he.net (184.105.213.69) 57.893 ms 45.822 ms 45.701 ms
8423 7 100ge12-1.core1.dal1.he.net (184.105.81.170) 77.794 ms 77.673 ms 77.760 ms
8424 8 100ge4-2.core1.phx2.he.net (184.105.81.173) 88.263 ms 88.557 ms 88.741 ms
8425 9 omnis-network-llc.10gigabitethernet1-1-21.switch3.phx2.he.net (65.49.80.230) 86.420 ms 86.420 ms 86.445 ms
842610 barney.phatservers.com (216.17.111.213) <syn,ack> 92.234 ms 92.455 ms 92.998 ms
8427
8428
8429Smartmatch is experimental at /usr/bin/dnsenum line 698.
8430Smartmatch is experimental at /usr/bin/dnsenum line 698.
8431dnsenum VERSION:1.2.4
8432Warning: can't load Net::Whois::IP module, whois queries disabled.
8433
8434----- teeniesugar.com -----
8435
8436
8437Host's addresses:
8438__________________
8439
8440teeniesugar.com. 11574 IN A 216.17.111.213
8441
8442
8443Name Servers:
8444______________
8445
8446ns1.amerinoc.com. 360 IN A 216.239.128.2
8447ns2.amerinoc.com. 360 IN A 204.10.136.2
8448
8449
8450Mail (MX) Servers:
8451___________________
8452
8453mail.teeniesugar.com. 14400 IN A 216.17.111.213
8454
8455
8456
8457
8458Google Results:
8459________________
8460
8461www.teeniesugar.com. 6213 IN A 216.17.111.213
8462
8463
8464Brute forcing with dns.txt:
8465____________________________
8466
8467ftp.teeniesugar.com. 14400 IN CNAME www.teeniesugar.com.
8468www.teeniesugar.com. 6203 IN A 216.17.111.213
8469mail.teeniesugar.com. 14382 IN A 216.17.111.213
8470
8471
8472Performing recursion:
8473______________________
8474
8475
8476 ---- Checking subdomains NS records ----
8477
8478 Can't perform recursion no NS records.
8479
8480
8481teeniesugar.com class C netranges:
8482___________________________________
8483
8484 216.17.111.0/24
8485
8486
8487Performing reverse lookup on 256 ip addresses:
8488_______________________________________________
8489
8490
84910 results out of 256 IP addresses.
8492
8493
8494teeniesugar.com ip blocks:
8495___________________________
8496
8497
8498done.
8499
8500
8501dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
8502
8503[+] searching (sub)domains for teeniesugar.com using built-in wordlist
8504[+] using maximum random delay of 10 millisecond(s) between requests
8505
8506ftp.teeniesugar.com
8507IP address #1: 216.17.111.213
8508
8509mail.teeniesugar.com
8510IP address #1: 216.17.111.213
8511
8512www.teeniesugar.com
8513IP address #1: 216.17.111.213
8514
8515[+] 3 (sub)domains and 3 IP address(es) found
8516[+] completion time: 135 second(s)
8517
8518
8519Tracing to teeniesugar.com[a] via 192.168.1.254, maximum of 3 retries
8520192.168.1.254 (192.168.1.254) Got answer
8521
8522
8523WhatWeb report for http://teeniesugar.com
8524Status : 301 Moved Permanently
8525Title : 301 Moved Permanently
8526IP : 216.17.111.213
8527Country : UNITED STATES, US
8528
8529Summary : RedirectLocation[http://www.teeniesugar.com/], HTTPServer[Apache/2], Apache[2]
8530
8531Detected Plugins:
8532[ Apache ]
8533 The Apache HTTP Server Project is an effort to develop and
8534 maintain an open-source HTTP server for modern operating
8535 systems including UNIX and Windows NT. The goal of this
8536 project is to provide a secure, efficient and extensible
8537 server that provides HTTP services in sync with the current
8538 HTTP standards.
8539
8540 Version : 2 (from HTTP Server Header)
8541 Google Dorks: (3)
8542 Website : http://httpd.apache.org/
8543
8544[ HTTPServer ]
8545 HTTP server header string. This plugin also attempts to
8546 identify the operating system from the server header.
8547
8548 String : Apache/2 (from server string)
8549
8550[ RedirectLocation ]
8551 HTTP Server string location. used with http-status 301 and
8552 302
8553
8554 String : http://www.teeniesugar.com/ (from location)
8555
8556HTTP Headers:
8557 HTTP/1.1 301 Moved Permanently
8558 Date: Sat, 02 Sep 2017 04:01:49 GMT
8559 Server: Apache/2
8560 Location: http://www.teeniesugar.com/
8561 Content-Length: 235
8562 Connection: close
8563 Content-Type: text/html; charset=iso-8859-1
8564
8565WhatWeb report for http://www.teeniesugar.com/
8566Status : 200 OK
8567Title : Teenie Sugar - Free Teen Galleries
8568IP : 216.17.111.213
8569Country : UNITED STATES, US
8570
8571Summary : Google-Analytics[UA-3884674-15], Script[text/javascript], PHP[5.6.22], X-Powered-By[PHP/5.6.22], HTTPServer[Apache/2], Apache[2], Frame, JQuery[1.3.2]
8572
8573Detected Plugins:
8574[ Apache ]
8575 The Apache HTTP Server Project is an effort to develop and
8576 maintain an open-source HTTP server for modern operating
8577 systems including UNIX and Windows NT. The goal of this
8578 project is to provide a secure, efficient and extensible
8579 server that provides HTTP services in sync with the current
8580 HTTP standards.
8581
8582 Version : 2 (from HTTP Server Header)
8583 Google Dorks: (3)
8584 Website : http://httpd.apache.org/
8585
8586[ Frame ]
8587 This plugin detects instances of frame and iframe HTML
8588 elements.
8589
8590
8591[ Google-Analytics ]
8592 This plugin identifies the Google Analytics account.
8593
8594 Account : UA-3884674-15
8595 Website : http://www.google.com/analytics/
8596
8597[ HTTPServer ]
8598 HTTP server header string. This plugin also attempts to
8599 identify the operating system from the server header.
8600
8601 String : Apache/2 (from server string)
8602
8603[ JQuery ]
8604 A fast, concise, JavaScript that simplifies how to traverse
8605 HTML documents, handle events, perform animations, and add
8606 AJAX.
8607
8608 Version : 1.3.2
8609 Website : http://jquery.com/
8610
8611[ PHP ]
8612 PHP is a widely-used general-purpose scripting language
8613 that is especially suited for Web development and can be
8614 embedded into HTML. This plugin identifies PHP errors,
8615 modules and versions and extracts the local file path and
8616 username if present.
8617
8618 Version : 5.6.22
8619 Google Dorks: (2)
8620 Website : http://www.php.net/
8621
8622[ Script ]
8623 This plugin detects instances of script HTML elements and
8624 returns the script language/type.
8625
8626 String : text/javascript
8627
8628[ X-Powered-By ]
8629 X-Powered-By HTTP header
8630
8631 String : PHP/5.6.22 (from x-powered-by string)
8632
8633HTTP Headers:
8634 HTTP/1.1 200 OK
8635 Date: Sat, 02 Sep 2017 04:01:51 GMT
8636 Server: Apache/2
8637 X-Powered-By: PHP/5.6.22
8638 Vary: Accept-Encoding,User-Agent
8639 Content-Encoding: gzip
8640 Content-Length: 11496
8641 Connection: close
8642 Content-Type: text/html; charset=UTF-8
8643
8644
8645[-] Resolving hostnames IPs...
8646216.17.111.213:www.teeniesugar.com
8647
8648
8649
8650 ^ ^
8651 _ __ _ ____ _ __ _ _ ____
8652 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
8653 | V V // o // _/ | V V // 0 // 0 // _/
8654 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
8655 <
8656 ...'
8657
8658 WAFW00F - Web Application Firewall Detection Tool
8659
8660 By Sandro Gauci && Wendel G. Henrique
8661
8662Checking http://teeniesugar.com
8663Generic Detection results:
8664No WAF detected by the generic detection
8665Number of requests: 13
8666
8667
8668DNS Servers for teeniesugar.com:
8669 ns1.amerinoc.com
8670 ns2.amerinoc.com
8671
8672Trying zone transfer first...
8673 Testing ns1.amerinoc.com
8674 Request timed out or transfer not allowed.
8675 Testing ns2.amerinoc.com
8676 Request timed out or transfer not allowed.
8677
8678Unsuccessful in zone transfer (it was worth a shot)
8679Okay, trying the good old fashioned way... brute force
8680
8681Checking for wildcard DNS...
8682Nope. Good.
8683Now performing 2280 test(s)...
8684216.17.111.213 ftp.teeniesugar.com
8685216.17.111.213 mail.teeniesugar.com
8686216.17.111.213 www.teeniesugar.com
8687
8688Subnets found (may want to probe here using nmap or unicornscan):
8689 216.17.111.0-255 : 3 hostnames found.
8690
8691Done with Fierce scan: http://ha.ckers.org/fierce/
8692Found 3 entries.
8693
8694Have a nice day.
8695
8696
8697
8698lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
8699 Written by Stefan Behte (http://ge.mine.nu)
8700 Proof-of-concept! Might give false positives.
8701
8702Checking for DNS-Loadbalancing: NOT FOUND
8703Checking for HTTP-Loadbalancing [Server]:
8704 Apache/2
8705 NOT FOUND
8706
8707Checking for HTTP-Loadbalancing [Date]: 04:17:24, 04:17:28, 04:17:30, 04:17:31, 04:17:32, 04:17:32, 04:17:33, 04:17:35, 04:17:36, 04:17:36, 04:17:37, 04:17:37, 04:17:38, 04:17:39, 04:17:41, 04:17:41, 04:17:42, 04:17:42, 04:17:43, 04:17:46, 04:17:50, 04:17:51, 04:17:51, 04:17:52, 04:17:52, 04:17:55, 04:17:55, 04:17:56, 04:17:56, 04:17:57, 04:17:58, 04:18:01, 04:18:02, 04:18:02, 04:18:03, 04:18:03, 04:18:06, 04:18:11, 04:18:11, 04:18:12, 04:18:13, 04:18:13, 04:18:15, 04:18:19, 04:18:21, 04:18:22, 04:18:22, 04:18:23, 04:18:23, 04:18:24, NOT FOUND
8708
8709Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
8710
8711teeniesugar.com does NOT use Load-balancing.
8712
8713
8714
8715Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
8716
8717 ----------------------------------------------------------
8718| Scan Information |
8719 ----------------------------------------------------------
8720
8721Mode ..................... VRFY
8722Worker Processes ......... 5
8723Usernames file ........... users.txt
8724Target count ............. 1
8725Username count ........... 494
8726Target TCP port .......... 25
8727Query timeout ............ 5 secs
8728Target domain ............
8729
8730######## Scan started at Sat Sep 2 00:34:10 2017 #########
8731######## Scan completed at Sat Sep 2 00:42:25 2017 #########
87320 results.
8733
8734494 queries in 495 seconds (1.0 queries / sec)
8735
8736
8737
8738Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-02 00:42 EDT
8739NSE: Loaded 146 scripts for scanning.
8740NSE: Script Pre-scanning.
8741Initiating NSE at 00:42
8742Completed NSE at 00:42, 0.00s elapsed
8743Initiating NSE at 00:42
8744Completed NSE at 00:42, 0.00s elapsed
8745Failed to resolve "teeniesugar.com.txt".
8746Initiating Parallel DNS resolution of 1 host. at 00:42
8747Completed Parallel DNS resolution of 1 host. at 00:42, 0.49s elapsed
8748Initiating SYN Stealth Scan at 00:42
8749Scanning teeniesugar.com (216.17.111.213) [100 ports]
8750Discovered open port 21/tcp on 216.17.111.213
8751Discovered open port 993/tcp on 216.17.111.213
8752Discovered open port 143/tcp on 216.17.111.213
8753Discovered open port 53/tcp on 216.17.111.213
8754Discovered open port 80/tcp on 216.17.111.213
8755Discovered open port 443/tcp on 216.17.111.213
8756Discovered open port 995/tcp on 216.17.111.213
8757Discovered open port 110/tcp on 216.17.111.213
8758Completed SYN Stealth Scan at 00:42, 2.62s elapsed (100 total ports)
8759Initiating Service scan at 00:42
8760Scanning 8 services on teeniesugar.com (216.17.111.213)
8761Completed Service scan at 00:43, 43.38s elapsed (8 services on 1 host)
8762Initiating OS detection (try #1) against teeniesugar.com (216.17.111.213)
8763Retrying OS detection (try #2) against teeniesugar.com (216.17.111.213)
8764adjust_timeouts2: packet supposedly had rtt of -109896 microseconds. Ignoring time.
8765adjust_timeouts2: packet supposedly had rtt of -109896 microseconds. Ignoring time.
8766adjust_timeouts2: packet supposedly had rtt of -109891 microseconds. Ignoring time.
8767adjust_timeouts2: packet supposedly had rtt of -109891 microseconds. Ignoring time.
8768adjust_timeouts2: packet supposedly had rtt of -108467 microseconds. Ignoring time.
8769adjust_timeouts2: packet supposedly had rtt of -108467 microseconds. Ignoring time.
8770adjust_timeouts2: packet supposedly had rtt of -146463 microseconds. Ignoring time.
8771adjust_timeouts2: packet supposedly had rtt of -146463 microseconds. Ignoring time.
8772Initiating Traceroute at 00:43
8773Completed Traceroute at 00:43, 3.21s elapsed
8774Initiating Parallel DNS resolution of 14 hosts. at 00:43
8775Completed Parallel DNS resolution of 14 hosts. at 00:43, 6.44s elapsed
8776NSE: Script scanning 216.17.111.213.
8777Initiating NSE at 00:43
8778Completed NSE at 00:47, 264.25s elapsed
8779Initiating NSE at 00:47
8780Completed NSE at 00:47, 0.52s elapsed
8781Nmap scan report for teeniesugar.com (216.17.111.213)
8782Host is up (0.26s latency).
8783rDNS record for 216.17.111.213: barney.phatservers.com
8784Not shown: 85 closed ports
8785PORT STATE SERVICE VERSION
878621/tcp open ftp ProFTPD 1.3.5b
8787|_ssl-date: 2017-09-02T04:28:20+00:00; -15m20s from scanner time.
878822/tcp filtered ssh
878925/tcp filtered smtp
879053/tcp open domain ISC BIND 9.9.5
8791| dns-nsid:
8792|_ bind.version: 9.9.5
879380/tcp open ssl/http Apache/2
8794| http-methods:
8795|_ Supported Methods: GET HEAD POST OPTIONS
8796|_http-server-header: Apache/2
8797|_http-title: Did not follow redirect to http://www.teeniesugar.com:80/
8798110/tcp open pop3 Dovecot DirectAdmin pop3d
8799|_pop3-capabilities: TOP UIDL USER PIPELINING SASL(PLAIN) STLS CAPA AUTH-RESP-CODE RESP-CODES
8800|_ssl-date: 2017-09-02T04:28:14+00:00; -15m20s from scanner time.
8801135/tcp filtered msrpc
8802139/tcp filtered netbios-ssn
8803143/tcp open imap Dovecot imapd
8804|_imap-capabilities: ENABLE OK listed LITERAL+ IDLE more Pre-login post-login SASL-IR capabilities have AUTH=PLAINA0001 IMAP4rev1 STARTTLS ID LOGIN-REFERRALS
8805|_ssl-date: 2017-09-02T04:28:22+00:00; -15m20s from scanner time.
8806443/tcp open ssl/https?
8807|_ssl-date: 2017-09-02T04:28:12+00:00; -15m20s from scanner time.
8808445/tcp filtered microsoft-ds
8809465/tcp filtered smtps
8810587/tcp filtered submission
8811993/tcp open ssl/imaps?
8812|_ssl-date: 2017-09-02T04:28:12+00:00; -15m20s from scanner time.
8813995/tcp open ssl/pop3s?
8814|_ssl-date: 2017-09-02T04:28:15+00:00; -15m20s from scanner time.
8815Aggressive OS guesses: FreeBSD 7.0-RELEASE (95%), FreeBSD 7.1-PRERELEASE 7.2-STABLE (95%), FreeBSD 9.0-RELEASE - 10.3-RELEASE (95%), FreeBSD 8.1-RELEASE (94%), FreeBSD 8.2-RELEASE (94%), FreeBSD 8.0-RELEASE (94%), FreeBSD 10.2-RELEASE (NAS4Free) (93%), FreeBSD 9.0-RELEASE (92%), FreeBSD 7.0-RELEASE - 9.0-RELEASE (92%), FreeBSD 7.1-RELEASE (92%)
8816No exact OS matches for host (test conditions non-ideal).
8817Uptime guess: 0.003 days (since Sat Sep 2 00:43:15 2017)
8818Network Distance: 15 hops
8819TCP Sequence Prediction: Difficulty=249 (Good luck!)
8820IP ID Sequence Generation: Busy server or unknown class
8821Service Info: OS: Unix
8822
8823Host script results:
8824|_clock-skew: mean: -15m20s, deviation: 0s, median: -15m20s
8825
8826TRACEROUTE (using port 3306/tcp)
8827HOP RTT ADDRESS
88281 110.27 ms 10.13.0.1
88292 ...
88303 110.52 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
88314 111.59 ms 10.95.33.10
88325 113.35 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
88336 182.86 ms be100-1298.nwk-5-a9.nj.us (192.99.146.133)
88347 181.17 ms be100-2.nwk-1-a9.nj.us (178.32.135.218)
88358 181.88 ms 10ge3-9.core1.nyc6.he.net (206.130.10.8)
88369 182.83 ms 100ge13-1.core1.nyc4.he.net (184.105.64.177)
883710 186.36 ms 100ge8-2.core1.ash1.he.net (184.105.223.165)
883811 196.97 ms 100ge8-2.core1.atl1.he.net (184.105.213.69)
883912 292.27 ms 100ge12-1.core1.dal1.he.net (184.105.81.170)
884013 292.31 ms 100ge4-2.core1.phx2.he.net (184.105.81.173)
884114 292.25 ms omnis-network-llc.10gigabitethernet1-1-21.switch3.phx2.he.net (65.49.80.230)
884215 292.33 ms barney.phatservers.com (216.17.111.213)
8843
8844NSE: Script Post-scanning.
8845Initiating NSE at 00:47
8846Completed NSE at 00:47, 0.00s elapsed
8847Initiating NSE at 00:47
8848Completed NSE at 00:47, 0.00s elapsed
8849Read data files from: /usr/bin/../share/nmap
8850OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
8851Nmap done: 1 IP address (1 host up) scanned in 330.34 seconds
8852 Raw packets sent: 195 (11.074KB) | Rcvd: 155 (8.718KB)
8853
8854
8855Error: can not open nmap file: teeniesugar.com.txt
8856
8857
8858httprint v0.301 (beta) - web server fingerprinting tool
8859(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
8860http://net-square.com/httprint/
8861httprint@net-square.com
8862
8863Finger Printing on http://teeniesugar.com:80/
8864Finger Printing Completed on http://teeniesugar.com:80/
8865--------------------------------------------------
8866Host: teeniesugar.com
8867Fingerprinting Error: Host/URL not found...
8868
8869--------------------------------------------------
8870
8871
8872
8873
8874 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
8875 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
8876 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
8877 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
8878 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
8879
8880 _/ User-Agent Tester ↵
8881 _/ AKA: Purple Pimp ↵
8882 _/ ChrisJohnRiley ↵
8883 _/ blog.c22.cc ↵
8884
8885 [>] Performing initial request and confirming stability
8886 [>] Using User-Agent string Mozilla/5.0
8887
8888 [ ] URL (ENTERED): http://teeniesugar.com
8889 [!] URL (FINAL): http://www.teeniesugar.com/
8890 [!] Response Code: 301 Moved Permanently
8891 [ ] Date: Sat, 02 Sep 2017 04:32:42 GMT
8892 [ ] Server: Apache/2
8893 [ ] X-Powered-By: PHP/5.6.22
8894 [ ] Vary: Accept-Encoding,User-Agent
8895 [ ] Connection: close
8896 [ ] Transfer-Encoding: chunked
8897 [ ] Content-Type: text/html; charset=UTF-8
8898 [ ] Data (MD5): 8a71f98449ba036fd52893349c266823
8899
8900 [1] Pass
8901 [2] Pass
8902 [3] Pass
8903
8904 [>] URL appears stable. Beginning test
8905
8906 [>] Using DEFAULT User-Agent Strings
8907
8908 [>] Using Crazy User-Agent Strings
8909 [>] Using Bot User-Agent Strings
8910
8911 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
8912
8913
8914 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
8915
8916
8917 [!] Data (MD5): 3ed6ad4ca5dd5fafc7173da4bdf3cb50
8918
8919
8920 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
8921
8922
8923 [!] Data (MD5): e4f6f1a71271d1d4ca21e3e88e092862
8924
8925
8926 [>] User-Agent String : TrackBack/1.02
8927
8928
8929 [!] Data (MD5): 612f5040860254eb0c58cea98c8152d2
8930
8931
8932 [>] User-Agent String : wispr
8933
8934
8935 [!] Data (MD5): 022fd32c0e5fc724d095c2e98770e6f0
8936
8937
8938 [>] User-Agent String : EMPTY USER-AGENT STRING!
8939
8940
8941 [!] Data (MD5): a3b94f9266be1b6b742634d66605e6b4
8942
8943
8944 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
8945
8946
8947 [!] Data (MD5): 332f86b9616c9461b2a5eb2f8ea6e19f
8948
8949
8950 [>] User-Agent String : Googlebot-Image/1.0
8951
8952
8953 [!] Data (MD5): 43573f5007561fe10ae12c9ea156dcad
8954
8955
8956 [>] User-Agent String : Mediapartners-Google
8957
8958
8959 [!] Data (MD5): 0f9cc905b51bfe7a049fd2d8e8163ce7
8960
8961
8962 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
8963
8964
8965 [!] Data (MD5): a0ef8d148a459b841a0d4f8a8436a880
8966
8967
8968 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
8969
8970
8971 [!] Data (MD5): 78234234a8b0873cf18c45f512ffc5ea
8972
8973
8974 [>] User-Agent String : mmcrawler
8975
8976
8977 [!] Data (MD5): cdc2987dc1c280c8a3f1982aaed663db
8978
8979
8980 [>] Checks completed... try enabling VERBOSE mode for more detailed output
8981
8982 [>] That's all folks... Fo' Shizzle!
8983
8984i] Scanning Site: http://teeniesugar.com
8985
8986
8987
8988B A S I C I N F O
8989=======================================================================================================================
8990
8991
8992
8993
8994[+] Site Title: Teenie Sugar - Free Teen Galleries
8995[+] IP address: 216.17.111.213
8996[+] Web Server: Apache/2
8997[+] CMS: Could Not Detect
8998[+] Cloudflare: Not Detected
8999[+] Robots File: Could NOT Find robots.txt!
9000
9001
9002
9003
9004W H O I S L O O K U P
9005===========================================================================================================================
9006
9007
9008
9009 Domain Name: TEENIESUGAR.COM
9010 Registry Domain ID: 1483149175_DOMAIN_COM-VRSN
9011 Registrar WHOIS Server: whois.godaddy.com
9012 Registrar URL: http://www.godaddy.com
9013 Updated Date: 2017-05-27T21:21:04Z
9014 Creation Date: 2008-05-30T09:59:22Z
9015 Registry Expiry Date: 2018-05-30T09:59:22Z
9016 Registrar: GoDaddy.com, LLC
9017 Registrar IANA ID: 146
9018 Registrar Abuse Contact Email: abuse@godaddy.com
9019 Registrar Abuse Contact Phone: 480-624-2505
9020 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
9021 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
9022 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
9023 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
9024 Name Server: NS1.AMERINOC.COM
9025 Name Server: NS2.AMERINOC.COM
9026 DNSSEC: unsigned
9027 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
9028>>> Last update of whois database: 2017-09-02T04:15:57Z <<<
9029
9030For more information on Whois status codes, please visit https://icann.org/epp
9031
9032
9033
9034The Registry database contains ONLY .COM, .NET, .EDU domains and
9035Registrars.
9036
9037
9038
9039
9040G E O I P L O O K U P
9041============================================================================================================================
9042
9043
9044
9045[i] IP Address: 216.17.111.213
9046[i] Country: US
9047[i] State: California
9048[i] City: Torrance
9049[i] Latitude: 33.835899
9050[i] Longitude: -118.340599
9051
9052
9053
9054
9055H T T P H E A D E R S
9056==========================================================================================================================
9057
9058
9059
9060
9061[i] HTTP/1.1 301 Moved Permanently
9062[i] Date: Sat, 02 Sep 2017 04:00:43 GMT
9063[i] Server: Apache/2
9064[i] Location: http://www.teeniesugar.com/
9065[i] Content-Length: 235
9066[i] Connection: close
9067[i] Content-Type: text/html; charset=iso-8859-1
9068[i] HTTP/1.1 200 OK
9069[i] Date: Sat, 02 Sep 2017 04:00:44 GMT
9070[i] Server: Apache/2
9071[i] X-Powered-By: PHP/5.6.22
9072[i] Vary: Accept-Encoding,User-Agent
9073[i] Connection: close
9074[i] Content-Type: text/html; charset=UTF-8
9075
9076
9077
9078
9079D N S L O O K U P
9080======================================================================================================================
9081
9082
9083
9084teeniesugar.com. 14394 IN A 216.17.111.213
9085teeniesugar.com. 14399 IN NS ns1.amerinoc.com.
9086teeniesugar.com. 14399 IN NS ns2.amerinoc.com.
9087teeniesugar.com. 86399 IN SOA primary.guardeddns.net. dns-admin.guardeddns.net. 102 28800 450 1209600 900
9088teeniesugar.com. 14399 IN MX 10 mail.teeniesugar.com.
9089
9090
9091
9092
9093S U B N E T C A L C U L A T I O N
9094=======================================================================================================================================
9095
9096
9097
9098Address = 216.17.111.213
9099Network = 216.17.111.213 / 32
9100Netmask = 255.255.255.255
9101Broadcast = not needed on Point-to-Point links
9102Wildcard Mask = 0.0.0.0
9103Hosts Bits = 0
9104Max. Hosts = 1 (2^0 - 0)
9105Host Range = { 216.17.111.213 - 216.17.111.213 }
9106
9107
9108
9109N M A P P O R T S C A N
9110===============================================================================================================================
9111
9112
9113
9114
9115PORT STATE SERVICE VERSION
911621/tcp open ftp ProFTPD 1.3.5b
911722/tcp filtered ssh
911823/tcp closed telnet
911925/tcp open smtp Exim smtpd 4.87
912080/tcp open http?
9121110/tcp open pop3 Dovecot DirectAdmin pop3d
9122143/tcp open imap Dovecot imapd
9123443/tcp open ssl/https?
9124445/tcp closed microsoft-ds
91253389/tcp closed ms-wbt-server
9126
9127
9128S U B - D O M A I N F I N D E R
9129=====================================================================================================================================
9130
9131
9132
9133
9134[i] Total Subdomains Found : 3
9135
9136[+] Subdomain: teeniesugar.com
9137[-] IP: 216.17.111.213
9138
9139[+] Subdomain: mail.teeniesugar.com
9140[-] IP: 216.17.111.213
9141
9142[+] Subdomain: www.teeniesugar.com
9143[-] IP: 216.17.111.213
9144--------------------------------------------------------------------------
9145+ Target IP: 216.17.111.213
9146+ Target Hostname: 216.17.111.213
9147+ Target Port: 80
9148+ Start Time: 2017-09-02 01:13:57 (GMT-4)
9149---------------------------------------------------------------------------
9150+ Server: Apache/2
9151+ Server leaks inodes via ETags, header found with file /, fields: 0xf4 0x5000ef275871d
9152+ The anti-clickjacking X-Frame-Options header is not present.
9153+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
9154+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
9155+ No CGI Directories found (use '-C all' to force check all possible dirs)
9156+ Apache/2 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
9157+ Allowed HTTP Methods: OPTIONS, GET, HEAD, POST
9158+ Retrieved x-powered-by header: PHP/5.6.22
9159+ Uncommon header 'x-robots-tag' found, with contents: noindex, nofollow
9160+ Uncommon header 'x-ob_mode' found, with contents: 1
9161+ Uncommon header 'x-permitted-cross-domain-policies' found, with contents: none
9162+ OSVDB-3092: /phpMyAdmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
9163+ OSVDB-3092: /phpmyadmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
9164+ OSVDB-3092: /pma/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
9165+ Cookie SQMSESSID created without the httponly flag
9166+ OSVDB-3093: /squirrelmail/src/read_body.php: SquirrelMail found
9167+ OSVDB-3093: /webmail/src/read_body.php: SquirrelMail found
9168+ OSVDB-3268: /icons/: Directory indexing found.
9169+ OSVDB-3233: /icons/README: Apache default file found.
9170+ /webmail/src/configtest.php: Squirrelmail configuration test may reveal version and system info.
9171+ 7687 requests: 0 error(s) and 19 item(s) reported on remote host
9172+ End Time: 2017-09-02 01:47:56 (GMT-4) (2039 seconds)
9173---------------------------------------------------------------------------
9174######################################################################################################################################
9175Hostname www.trydaddy.com ISP Leaseweb USA, Inc. (AS30633)
9176Continent North America Flag
9177US
9178Country United States Country Code US (USA)
9179Region DE Local time 02 Sep 2017 07:59 EDT
9180Metropolis Unknown Postal Code Unknown
9181City Unknown Latitude 39.673
9182IP Address 108.59.1.220 Longitude -75.705
9183#######################################################################################################################################
9184trydaddy.com
9185
9186
9187 Domain Name: TRYDADDY.COM
9188 Registry Domain ID: 1222341695_DOMAIN_COM-VRSN
9189 Registrar WHOIS Server: whois.PublicDomainRegistry.com
9190 Registrar URL: http://www.publicdomainregistry.com
9191 Updated Date: 2016-08-23T15:59:28Z
9192 Creation Date: 2007-09-17T12:55:51Z
9193 Registry Expiry Date: 2017-09-17T12:55:51Z
9194 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
9195 Registrar IANA ID: 303
9196 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
9197 Registrar Abuse Contact Phone: +1.2013775952
9198 Domain Status: ok https://icann.org/epp#ok
9199 Name Server: NS1.OLDMANWISH.COM
9200 Name Server: NS2.OLDMANWISH.COM
9201
9202Domain Name: TRYDADDY.COM
9203Registry Domain ID: 1222341695_DOMAIN_COM-VRSN
9204Registrar WHOIS Server: whois.publicdomainregistry.com
9205Registrar URL: www.publicdomainregistry.com
9206Updated Date: 2016-08-23T15:59:35Z
9207Creation Date: 2007-09-17T12:55:51Z
9208Registrar Registration Expiration Date: 2017-09-17T12:55:51Z
9209Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
9210Registrar IANA ID: 303
9211Domain Status: OK https://icann.org/epp#OK
9212Registry Registrant ID: Not Available From Registry
9213Registrant Name: Jason
9214Registrant Organization: XxX
9215Registrant Street: XXX
9216Registrant City: Krasnodar
9217Registrant State/Province: Krasnodarskiy kray
9218Registrant Postal Code: 434564
9219Registrant Country: RU
9220Registrant Phone: +001.44567788989
9221Registrant Phone Ext:
9222Registrant Fax:
9223Registrant Fax Ext:
9224Registrant Email: admin@uniformgirl.net
9225Registry Admin ID: Not Available From Registry
9226Admin Name: Jason
9227Admin Organization: XxX
9228Admin Street: XXX
9229Admin City: Krasnodar
9230Admin State/Province: Krasnodarskiy kray
9231Admin Postal Code: 434564
9232Admin Country: RU
9233Admin Phone: +001.44567788989
9234Admin Phone Ext:
9235Admin Fax:
9236Admin Fax Ext:
9237Admin Email: admin@uniformgirl.net
9238Registry Tech ID: Not Available From Registry
9239Tech Name: Jason
9240Tech Organization: XxX
9241Tech Street: XXX
9242Tech City: Krasnodar
9243Tech State/Province: Krasnodarskiy kray
9244Tech Postal Code: 434564
9245Tech Country: RU
9246Tech Phone: +001.44567788989
9247Tech Phone Ext:
9248Tech Fax:
9249Tech Fax Ext:
9250Tech Email: admin@uniformgirl.net
9251Name Server: ns1.oldmanwish.com
9252Name Server: ns2.oldmanwish.com
9253DNSSEC:Unsigned
9254Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
9255Registrar Abuse Contact Phone: +1.2013775952
9256
9257
9258; <<>> DiG 9.10.3-P4-Debian <<>> trydaddy.com any
9259;; global options: +cmd
9260;; Got answer:
9261;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59181
9262;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
9263
9264;; OPT PSEUDOSECTION:
9265; EDNS: version: 0, flags:; udp: 4096
9266;; QUESTION SECTION:
9267;trydaddy.com. IN ANY
9268
9269;; ANSWER SECTION:
9270trydaddy.com. 38193 IN NS lcwmlm431.amhost.net.
9271
9272;; Query time: 8 msec
9273;; SERVER: 192.168.1.254#53(192.168.1.254)
9274;; WHEN: Sat Sep 02 08:02:00 EDT 2017
9275;; MSG SIZE rcvd: 75
9276
9277
9278
9279;; Connection to 192.168.1.254#53(192.168.1.254) for trydaddy.com failed: connection refused.
9280Host trydaddy.com not found: 9(NOTAUTH)
9281; Transfer failed.
9282
9283
9284Please type the name of your network interface Example: eth0
9285eth0
9286
9287Running:
9288 traceroute -T -O info -i eth0 trydaddy.com
9289trydaddy.com: Nom ou service inconnu
9290Cannot handle "host" cmdline arg `trydaddy.com' on position 1 (argc 6)
9291
9292
9293Smartmatch is experimental at /usr/bin/dnsenum line 698.
9294Smartmatch is experimental at /usr/bin/dnsenum line 698.
9295dnsenum VERSION:1.2.4
9296Warning: can't load Net::Whois::IP module, whois queries disabled.
9297
9298
9299
9300
9301Google Results:
9302________________
9303
9304www.trydaddy.com. 38172 IN A 108.59.1.220
9305
9306
9307Brute forcing with dns.txt:
9308____________________________
9309
9310
9311
9312Performing recursion:
9313______________________
9314
9315
9316 ---- Checking subdomains NS records ----
9317
9318 Can't perform recursion no NS records.
9319
9320
9321trydaddy.com class C netranges:
9322________________________________
9323
9324 108.59.1.0/24
9325
9326[i] Scanning Site: http://trydaddy.com
9327
9328
9329
9330B A S I C I N F O
9331=======================================================================================================================
9332
9333
9334
9335
9336[+] Site Title: TryDaddy.com - Dirty Dad and young girls
9337[+] IP address: 108.59.1.220
9338[+] Web Server: nginx/1.9.5
9339[+] CMS: Could Not Detect
9340[+] Cloudflare: Not Detected
9341[+] Robots File: Could NOT Find robots.txt!
9342
9343
9344
9345
9346W H O I S L O O K U P
9347===========================================================================================================================
9348
9349
9350
9351 Domain Name: TRYDADDY.COM
9352 Registry Domain ID: 1222341695_DOMAIN_COM-VRSN
9353 Registrar WHOIS Server: whois.PublicDomainRegistry.com
9354 Registrar URL: http://www.publicdomainregistry.com
9355 Updated Date: 2016-08-23T15:59:28Z
9356 Creation Date: 2007-09-17T12:55:51Z
9357 Registry Expiry Date: 2017-09-17T12:55:51Z
9358 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
9359 Registrar IANA ID: 303
9360 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
9361 Registrar Abuse Contact Phone: +1.2013775952
9362 Domain Status: ok https://icann.org/epp#ok
9363 Name Server: NS1.OLDMANWISH.COM
9364 Name Server: NS2.OLDMANWISH.COM
9365 DNSSEC: unsigned
9366 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
9367>>> Last update of whois database: 2017-09-02T12:04:58Z <<<
9368
9369For more information on Whois status codes, please visit https://icann.org/epp
9370
9371
9372
9373The Registry database contains ONLY .COM, .NET, .EDU domains and
9374Registrars.
9375
9376
9377
9378
9379G E O I P L O O K U P
9380============================================================================================================================
9381
9382
9383
9384[i] IP Address: 108.59.1.220
9385[i] Country: US
9386[i] State: Delaware
9387[i] City: N/A
9388[i] Latitude: 39.673401
9389[i] Longitude: -75.705200
9390
9391
9392
9393
9394
9395
9396S U B N E T C A L C U L A T I O N
9397=======================================================================================================================================
9398
9399
9400
9401Address = 108.59.1.220
9402Network = 108.59.1.220 / 32
9403Netmask = 255.255.255.255
9404Broadcast = not needed on Point-to-Point links
9405Wildcard Mask = 0.0.0.0
9406Hosts Bits = 0
9407Max. Hosts = 1 (2^0 - 0)
9408Host Range = { 108.59.1.220 - 108.59.1.220 }
9409
9410
9411
9412N M A P P O R T S C A N
9413===============================================================================================================================
9414
9415
9416
9417Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-02 12:05 UTC
9418Nmap scan report for trydaddy.com (108.59.1.220)
9419Host is up (0.056s latency).
9420PORT STATE SERVICE VERSION
942121/tcp open ftp ProFTPD or KnFTPD
942222/tcp open ssh OpenSSH 5.3 (protocol 2.0)
942323/tcp closed telnet
942425/tcp open smtp Postfix smtpd
942580/tcp open http nginx 1.9.5
9426110/tcp open pop3 Dovecot pop3d
9427143/tcp open imap Dovecot imapd
9428443/tcp closed https
9429445/tcp filtered microsoft-ds
94303389/tcp closed ms-wbt-server
9431Service Info: Host: lcwmlm431.amhost.net; OS: Unix
9432
9433Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
9434Nmap done: 1 IP address (1 host up) scanned in 8.35 seconds
9435
9436
9437
9438S U B - D O M A I N F I N D E R
9439=====================================================================================================================================
9440
9441
9442
9443
9444[i] Total Subdomains Found : 3
9445
9446[+] Subdomain: trydaddy.com
9447[-] IP: 108.59.1.220
9448
9449[+] Subdomain: mail.trydaddy.com
9450[-] IP: 108.59.1.220
9451
9452[+] Subdomain: www.trydaddy.com
9453[-] IP: 108.59.1.220
9454
9455
9456
9457
9458
9459R E V E R S E I P L O O K U P
9460=====================================================================================================================================
9461
9462
9463
9464
9465[i] Total Sites Found On This Server : 4
9466
9467
9468[#] trydaddy.com
9469[-] CMS: Could Not Detect
9470
9471[#] www.atlasphones.com
9472[-] CMS: Could Not Detect
9473
9474[#] www.nylonx.net
9475[-] CMS: Could Not Detect
9476
9477[#] www.santaclarasystems.com,
9478[-] CMS: Could Not Detect
9479
9480
9481
9482
9483
9484
9485Crawling Types & Descriptions:
9486---------------------------------------------------------------------------
9487+ Target IP: 108.59.1.220
9488+ Target Hostname: 108.59.1.220
9489+ Target Port: 80
9490+ Start Time: 2017-09-02 08:18:56 (GMT-4)
9491---------------------------------------------------------------------------
9492+ Server: nginx/1.9.5
9493+ Server leaks inodes via ETags, header found with file /, inode: 48359890, size: 3199, mtime: Fri Aug 4 08:10:07 2017
9494+ The anti-clickjacking X-Frame-Options header is not present.
9495+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
9496+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
9497+ Allowed HTTP Methods: GET, HEAD, POST, OPTIONS, TRACE
9498+ OSVDB-3092: /members/: This might be interesting...
9499+ OSVDB-3268: /icons/: Directory indexing found.
9500+ OSVDB-3233: /icons/README: Apache default file found.
9501+ 9308 requests: 0 error(s) and 8 item(s) reported on remote host
9502+ End Time: 2017-09-02 08:50:11 (GMT-4) (1875 seconds)
9503---------------------------------------------------------------------------
9504######################################################################################################################################
9505
9506Hostname girlloverforum.net ISP Unknown
9507Continent Unknown Flag
9508US
9509Country United States Country Code US
9510Region Unknown Local time 02 Sep 2017 08:06 CDT
9511City Unknown Latitude 37.751
9512IP Address (IPv6) 2400:cb00:2048:1::681f:4e48 Longitude -97.822
9513
9514#####################################################################################################################################
9515girlloverforum.net
9516
9517
9518 Domain Name: GIRLLOVERFORUM.NET
9519 Registry Domain ID: 124719553_DOMAIN_NET-VRSN
9520 Registrar WHOIS Server: whois.domrobot.com
9521 Registrar URL: http://www.inwx.com
9522 Updated Date: 2017-02-27T05:16:04Z
9523 Creation Date: 2004-07-13T18:35:06Z
9524 Registry Expiry Date: 2018-07-13T18:35:06Z
9525 Registrar: INWX GmbH & Co. KG
9526 Registrar IANA ID: 1420
9527 Registrar Abuse Contact Email:
9528 Registrar Abuse Contact Phone:
9529 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
9530 Name Server: ELLE.NS.CLOUDFLARE.COM
9531 Name Server: MAREK.NS.CLOUDFLARE.COM
9532 DNSSEC: unsigned
9533 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
9534
9535Domain Name: girlloverforum.net
9536Internationalized Domain Name: girlloverforum.net
9537Registry Domain ID: 124719553_DOMAIN_NET-VRSN
9538Registrar WHOIS Server: whois.domrobot.com
9539Registrar URL: http://www.whois.domrobot.com
9540Updated Date: 2017-02-27T05:17:04Z
9541Creation Date: 2004-07-13T18:35:06Z
9542Registrar Registration Expiration Date: 2018-07-13T18:35:06Z
9543Registrar: INWX GmbH & Co. KG
9544Registrar IANA ID: 1420
9545Registrar Abuse Contact Email: abuse@domrobot.com
9546Registrar Abuse Contact Phone: +49.30983212112
9547Reseller: INWX GmbH & Co. KG
9548Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
9549Registry Registrant ID: Not Available From Registry
9550Registrant Name: FlokiNET WhoisProtection
9551Registrant Organization: FlokiNET ehf
9552Registrant Street: P.O. Box No 4
9553Registrant City: Reykjavik
9554Registrant State/Province:
9555Registrant Postal Code: 121
9556Registrant Country: IS
9557Registrant Phone: +354.4150300
9558Registrant Phone Ext:
9559Registrant Fax: +354.4150309
9560Registrant Fax Ext:
9561Registrant Email: abuse@flokinet.is
9562Registry Admin ID: Not Available From Registry
9563Admin Name: FlokiNET WhoisProtection
9564Admin Organization: FlokiNET ehf
9565Admin Street: P.O. Box No 4
9566Admin City: Reykjavik
9567Admin State/Province:
9568Admin Postal Code: 121
9569Admin Country: IS
9570Admin Phone: +354.4150300
9571Admin Phone Ext:
9572Admin Fax: +354.4150309
9573Admin Fax Ext:
9574Admin Email: abuse@flokinet.is
9575Registry Tech ID: Not Available From Registry
9576Tech Name: FlokiNET WhoisProtection
9577Tech Organization: FlokiNET ehf
9578Tech Street: P.O. Box No 4
9579Tech City: Reykjavik
9580Tech State/Province:
9581Tech Postal Code: 121
9582Tech Country: IS
9583Tech Phone: +354.4150300
9584Tech Phone Ext:
9585Tech Fax: +354.4150309
9586Tech Fax Ext:
9587Tech Email: abuse@flokinet.is
9588Registry Billing ID: Not Available From Registry
9589Billing Name: FlokiNET WhoisProtection
9590Billing Organization: FlokiNET ehf
9591Billing Street: P.O. Box No 4
9592Billing City: Reykjavik
9593Billing State/Province:
9594Billing Postal Code: 121
9595Billing Country: IS
9596Billing Phone: +354.4150300
9597Billing Phone Ext:
9598Billing Fax: +354.4150309
9599Billing Fax Ext:
9600Billing Email: abuse@flokinet.is
9601Name Server: marek.ns.cloudflare.com
9602Name Server: elle.ns.cloudflare.com
9603DNSSEC: unsigned
9604URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
9605>>> Last update of WHOIS database: 2017-09-02T13:07:47Z <<<
9606
9607For more information on Whois status codes, please visit https://icann.org/epp
9608
9609Terms of Use: This data is provided by INWX GmbH & Co. KG
9610for information purposes, and to assist persons obtaining information
9611about or related to domain name registration records.
9612INWX GmbH & Co. KG does not guarantee its accuracy.
9613By submitting a WHOIS query, you agree that you will use this data
9614only for lawful purposes and that, under no circumstances, you will
9615use this data to
96161) allow, enable, or otherwise support the transmission of mass
9617 unsolicited, commercial advertising or solicitations via E-mail
9618 (spam); or
96192) enable high volume, automated, electronic processes that apply
9620 to this WHOIS server.
9621These terms may be changed without prior notice.
9622By submitting this query, you agree to abide by this policy.
9623
9624Please register your domains at
9625http://www.inwx.de
9626
9627
9628
9629; <<>> DiG 9.10.3-P4-Debian <<>> girlloverforum.net any
9630;; global options: +cmd
9631;; Got answer:
9632;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 15880
9633;; flags: qr rd ra; QUERY: 1, ANSWER: 7, AUTHORITY: 0, ADDITIONAL: 1
9634
9635;; OPT PSEUDOSECTION:
9636; EDNS: version: 0, flags:; udp: 4096
9637;; QUESTION SECTION:
9638;girlloverforum.net. IN ANY
9639
9640;; ANSWER SECTION:
9641girlloverforum.net. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
9642girlloverforum.net. 235 IN AAAA 2400:cb00:2048:1::681f:4f48
9643girlloverforum.net. 235 IN AAAA 2400:cb00:2048:1::681f:4e48
9644girlloverforum.net. 235 IN A 104.31.79.72
9645girlloverforum.net. 235 IN A 104.31.78.72
9646girlloverforum.net. 169918 IN NS marek.ns.cloudflare.com.
9647girlloverforum.net. 169918 IN NS elle.ns.cloudflare.com.
9648
9649;; Query time: 33 msec
9650;; SERVER: 192.168.1.254#53(192.168.1.254)
9651;; WHEN: Sat Sep 02 09:07:38 EDT 2017
9652;; MSG SIZE rcvd: 249
9653
9654
9655
9656;; Connection to 192.168.1.254#53(192.168.1.254) for girlloverforum.net failed: connection refused.
9657Host girlloverforum.net not found: 9(NOTAUTH)
9658; Transfer failed.
9659
9660
9661Please type the name of your network interface Example: eth0
9662eth0
9663
9664Running:
9665 traceroute -T -O info -i eth0 girlloverforum.net
9666traceroute to girlloverforum.net (104.31.78.72), 30 hops max, 60 byte packets
9667 1 gateway (192.168.1.254) 0.572 ms 0.854 ms 1.077 ms
9668 2 10.135.18.1 (10.135.18.1) 8.605 ms 10.467 ms 18.516 ms
9669 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 32.080 ms 32.212 ms 32.327 ms
9670 4 de-cix-new-york.as13335.net (206.130.10.31) 30.947 ms 31.015 ms 31.282 ms
9671 5 104.31.78.72 (104.31.78.72) <syn,ack> 31.124 ms 31.435 ms 31.728 ms
9672
9673
9674Smartmatch is experimental at /usr/bin/dnsenum line 698.
9675Smartmatch is experimental at /usr/bin/dnsenum line 698.
9676dnsenum VERSION:1.2.4
9677Warning: can't load Net::Whois::IP module, whois queries disabled.
9678
9679----- girlloverforum.net -----
9680
9681
9682Host's addresses:
9683__________________
9684
9685girlloverforum.net. 221 IN A 104.31.79.72
9686girlloverforum.net. 221 IN A 104.31.78.72
9687
9688
9689Name Servers:
9690______________
9691
9692elle.ns.cloudflare.com. 4054 IN A 173.245.58.110
9693marek.ns.cloudflare.com. 7045 IN A 173.245.59.202
9694
9695
9696Mail (MX) Servers:
9697___________________
9698
9699
9700
9701
9702
9703Google Results:
9704________________
9705
9706www.girlloverforum.net. 300 IN A 104.31.78.72
9707www.girlloverforum.net. 300 IN A 104.31.79.72
9708
9709
9710Brute forcing with dns.txt:
9711____________________________
9712
9713webmail.girlloverforum.net. 300 IN A 5.254.96.71
9714
9715
9716Performing recursion:
9717______________________
9718
9719
9720 ---- Checking subdomains NS records ----
9721
9722 Can't perform recursion no NS records.
9723
9724
9725girlloverforum.net class C netranges:
9726______________________________________
9727
9728 5.254.96.0/24
9729 104.31.78.0/24
9730 104.31.79.0/24
9731
9732
9733Performing reverse lookup on 768 ip addresses:
9734_______________________________________________
9735
9736
97370 results out of 768 IP addresses.
9738
9739
9740girlloverforum.net ip blocks:
9741______________________________
9742
9743
9744done.
9745
9746
9747dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
9748
9749[+] searching (sub)domains for girlloverforum.net using built-in wordlist
9750[+] using maximum random delay of 10 millisecond(s) between requests
9751
9752cpanel.girlloverforum.net
9753IP address #1: 5.254.96.71
9754
9755webmail.girlloverforum.net
9756IP address #1: 5.254.96.71
9757
9758www.girlloverforum.net
9759IPv6 address #1: 2400:cb00:2048:1::681f:4f48
9760IPv6 address #2: 2400:cb00:2048:1::681f:4e48
9761
9762www.girlloverforum.net
9763IP address #1: 104.31.79.72
9764IP address #2: 104.31.78.72
9765
9766[+] 4 (sub)domains and 6 IP address(es) found
9767[+] completion time: 109 second(s)
9768
9769
9770Tracing to girlloverforum.net[a] via 192.168.1.254, maximum of 3 retries
9771192.168.1.254 (192.168.1.254) Got answer
9772
9773
9774WhatWeb report for http://girlloverforum.net
9775Status : 200 OK
9776Title : <None>
9777IP : 104.31.78.72
9778Country : UNITED STATES, US
9779
9780Summary : CloudFlare, PHP[5.3.3], HttpOnly[__cfduid], X-Powered-By[PHP/5.3.3], UncommonHeaders[cf-ray], Meta-Refresh-Redirect[./forum/portal.php], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
9781
9782Detected Plugins:
9783[ CloudFlare ]
9784 CloudFlare is a content delivery network. Its features
9785 include DDoS protection and Web Application Firewall
9786 functionality
9787
9788 Google Dorks: (1)
9789 Website : https://www.cloudflare.com/
9790
9791[ Cookies ]
9792 Display the names of cookies in the HTTP headers. The
9793 values are not returned to save on space.
9794
9795 String : __cfduid
9796
9797[ HTTPServer ]
9798 HTTP server header string. This plugin also attempts to
9799 identify the operating system from the server header.
9800
9801 String : cloudflare-nginx (from server string)
9802
9803[ HttpOnly ]
9804 If the HttpOnly flag is included in the HTTP set-cookie
9805 response header and the browser supports it then the cookie
9806 cannot be accessed through client side script - More Info:
9807 http://en.wikipedia.org/wiki/HTTP_cookie
9808
9809 String : __cfduid
9810
9811[ Meta-Refresh-Redirect ]
9812 Meta refresh tag is a deprecated URL element that can be
9813 used to optionally wait x seconds before reloading the
9814 current page or loading a new page. More info:
9815 https://secure.wikimedia.org/wikipedia/en/wiki/Meta_refresh
9816
9817 String : ./forum/portal.php
9818
9819[ PHP ]
9820 PHP is a widely-used general-purpose scripting language
9821 that is especially suited for Web development and can be
9822 embedded into HTML. This plugin identifies PHP errors,
9823 modules and versions and extracts the local file path and
9824 username if present.
9825
9826 Version : 5.3.3
9827 Google Dorks: (2)
9828 Website : http://www.php.net/
9829
9830[ UncommonHeaders ]
9831 Uncommon HTTP server headers. The blacklist includes all
9832 the standard headers and many non standard but common ones.
9833 Interesting but fairly common headers should have their own
9834 plugins, eg. x-powered-by, server and x-aspnet-version.
9835 Info about headers can be found at www.http-stats.com
9836
9837 String : cf-ray (from headers)
9838
9839[ X-Powered-By ]
9840 X-Powered-By HTTP header
9841
9842 String : PHP/5.3.3 (from x-powered-by string)
9843
9844HTTP Headers:
9845 HTTP/1.1 200 OK
9846 Date: Sat, 02 Sep 2017 13:10:30 GMT
9847 Content-Type: text/html; charset=UTF-8
9848 Transfer-Encoding: chunked
9849 Connection: close
9850 Set-Cookie: __cfduid=d636521989e3c9770b19ebb69f23055a11504357830; expires=Sun, 02-Sep-18 13:10:30 GMT; path=/; domain=.girlloverforum.net; HttpOnly
9851 X-Powered-By: PHP/5.3.3
9852 Server: cloudflare-nginx
9853 CF-RAY: 3980b5b821f469be-CDG
9854 Content-Encoding: gzip
9855
9856WhatWeb report for http://girlloverforum.net/forum/portal.php
9857Status : 301 Moved Permanently
9858Title : <None>
9859IP : 104.31.78.72
9860Country : UNITED STATES, US
9861
9862Summary : CloudFlare, RedirectLocation[https://girlloverforum.net/forum/portal.php], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx]
9863
9864Detected Plugins:
9865[ CloudFlare ]
9866 CloudFlare is a content delivery network. Its features
9867 include DDoS protection and Web Application Firewall
9868 functionality
9869
9870 Google Dorks: (1)
9871 Website : https://www.cloudflare.com/
9872
9873[ HTTPServer ]
9874 HTTP server header string. This plugin also attempts to
9875 identify the operating system from the server header.
9876
9877 String : cloudflare-nginx (from server string)
9878
9879[ RedirectLocation ]
9880 HTTP Server string location. used with http-status 301 and
9881 302
9882
9883 String : https://girlloverforum.net/forum/portal.php (from location)
9884
9885[ UncommonHeaders ]
9886 Uncommon HTTP server headers. The blacklist includes all
9887 the standard headers and many non standard but common ones.
9888 Interesting but fairly common headers should have their own
9889 plugins, eg. x-powered-by, server and x-aspnet-version.
9890 Info about headers can be found at www.http-stats.com
9891
9892 String : cf-ray (from headers)
9893
9894HTTP Headers:
9895 HTTP/1.1 301 Moved Permanently
9896 Date: Sat, 02 Sep 2017 13:10:30 GMT
9897 Transfer-Encoding: chunked
9898 Connection: close
9899 Cache-Control: max-age=3600
9900 Expires: Sat, 02 Sep 2017 14:10:30 GMT
9901 Location: https://girlloverforum.net/forum/portal.php
9902 Server: cloudflare-nginx
9903 CF-RAY: 3980b5ba742d695c-CDG
9904
9905WhatWeb report for https://girlloverforum.net/forum/portal.php
9906Status : 200 OK
9907Title : Portal • Girllover Forum ~ Girlloverforum ~ GL Forum ~ Girl Lover ~ Girllove ~ Mädchen ~ Liebe
9908IP : 104.31.78.72
9909Country : UNITED STATES, US
9910
9911Summary : CloudFlare, X-UA-Compatible[IE=EmulateIE7], Script[text/javascript], PHP[5.3.3], HttpOnly[__cfduid], X-Powered-By[PHP/5.3.3], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Cookies[__cfduid]
9912
9913Detected Plugins:
9914[ CloudFlare ]
9915 CloudFlare is a content delivery network. Its features
9916 include DDoS protection and Web Application Firewall
9917 functionality
9918
9919 Google Dorks: (1)
9920 Website : https://www.cloudflare.com/
9921
9922[ Cookies ]
9923 Display the names of cookies in the HTTP headers. The
9924 values are not returned to save on space.
9925
9926 String : __cfduid
9927
9928[ HTTPServer ]
9929 HTTP server header string. This plugin also attempts to
9930 identify the operating system from the server header.
9931
9932 String : cloudflare-nginx (from server string)
9933
9934[ HttpOnly ]
9935 If the HttpOnly flag is included in the HTTP set-cookie
9936 response header and the browser supports it then the cookie
9937 cannot be accessed through client side script - More Info:
9938 http://en.wikipedia.org/wiki/HTTP_cookie
9939
9940 String : __cfduid
9941
9942[ PHP ]
9943 PHP is a widely-used general-purpose scripting language
9944 that is especially suited for Web development and can be
9945 embedded into HTML. This plugin identifies PHP errors,
9946 modules and versions and extracts the local file path and
9947 username if present.
9948
9949 Version : 5.3.3
9950 Google Dorks: (2)
9951 Website : http://www.php.net/
9952
9953[ Script ]
9954 This plugin detects instances of script HTML elements and
9955 returns the script language/type.
9956
9957 String : text/javascript
9958
9959[ UncommonHeaders ]
9960 Uncommon HTTP server headers. The blacklist includes all
9961 the standard headers and many non standard but common ones.
9962 Interesting but fairly common headers should have their own
9963 plugins, eg. x-powered-by, server and x-aspnet-version.
9964 Info about headers can be found at www.http-stats.com
9965
9966 String : cf-ray (from headers)
9967
9968[ X-Powered-By ]
9969 X-Powered-By HTTP header
9970
9971 String : PHP/5.3.3 (from x-powered-by string)
9972
9973[ X-UA-Compatible ]
9974 This plugin retrieves the X-UA-Compatible value from the
9975 HTTP header and meta http-equiv tag. - More Info:
9976 http://msdn.microsoft.com/en-us/library/cc817574.aspx
9977
9978 String : IE=EmulateIE7
9979
9980HTTP Headers:
9981 HTTP/1.1 200 OK
9982 Date: Sat, 02 Sep 2017 13:10:31 GMT
9983 Content-Type: text/html; charset=UTF-8
9984 Transfer-Encoding: chunked
9985 Connection: close
9986 Set-Cookie: __cfduid=dbdbf83a1f19853b353e12bb52404eb251504357831; expires=Sun, 02-Sep-18 13:10:31 GMT; path=/; domain=.girlloverforum.net; HttpOnly
9987 X-Powered-By: PHP/5.3.3
9988 Server: cloudflare-nginx
9989 CF-RAY: 3980b5c00f47692c-CDG
9990 Content-Encoding: gzip
9991
9992
9993[+] Hosts found in search engines:
9994------------------------------------
9995[-] Resolving hostnames IPs...
9996104.31.78.72:www.girlloverforum.net
9997
9998
9999
10000 ^ ^
10001 _ __ _ ____ _ __ _ _ ____
10002 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
10003 | V V // o // _/ | V V // 0 // 0 // _/
10004 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
10005 <
10006 ...'
10007
10008 WAFW00F - Web Application Firewall Detection Tool
10009
10010 By Sandro Gauci && Wendel G. Henrique
10011
10012Checking http://girlloverforum.net
10013The site http://girlloverforum.net is behind a CloudFlare
10014Number of requests: 1
10015
10016
10017DNS Servers for girlloverforum.net:
10018 elle.ns.cloudflare.com
10019 marek.ns.cloudflare.com
10020
10021Trying zone transfer first...
10022 Testing elle.ns.cloudflare.com
10023 Request timed out or transfer not allowed.
10024 Testing marek.ns.cloudflare.com
10025 Request timed out or transfer not allowed.
10026
10027Unsuccessful in zone transfer (it was worth a shot)
10028Okay, trying the good old fashioned way... brute force
10029
10030Checking for wildcard DNS...
10031Nope. Good.
10032Now performing 2280 test(s)...
100335.254.96.71 webmail.girlloverforum.net
10034104.31.78.72 www.girlloverforum.net
10035104.31.79.72 www.girlloverforum.net
10036
10037Subnets found (may want to probe here using nmap or unicornscan):
10038 104.31.78.0-255 : 1 hostnames found.
10039 104.31.79.0-255 : 1 hostnames found.
10040 5.254.96.0-255 : 1 hostnames found.
10041
10042Done with Fierce scan: http://ha.ckers.org/fierce/
10043Found 3 entries.
10044
10045Have a nice day.
10046
10047
10048
10049lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
10050 Written by Stefan Behte (http://ge.mine.nu)
10051 Proof-of-concept! Might give false positives.
10052
10053Checking for DNS-Loadbalancing: FOUND
10054girlloverforum.net has address 104.31.78.72
10055girlloverforum.net has address 104.31.79.72
10056
10057Checking for HTTP-Loadbalancing [Server]:
10058 cloudflare-nginx
10059 NOT FOUND
10060
10061Checking for HTTP-Loadbalancing [Date]: 13:15:46, 13:15:46, 13:15:47, 13:15:47, 13:15:47, 13:15:47, 13:15:48, 13:15:48, 13:15:48, 13:15:48, 13:15:49, 13:15:49, 13:15:49, 13:15:50, 13:15:50, 13:15:50, 13:15:50, 13:15:51, 13:15:51, 13:15:51, 13:15:51, 13:15:52, 13:15:52, 13:15:52, 13:15:52, 13:15:53, 13:15:53, 13:15:53, 13:15:53, 13:15:54, 13:15:54, 13:15:54, 13:15:54, 13:15:55, 13:15:55, 13:15:55, 13:15:55, 13:15:56, 13:15:56, 13:15:56, 13:15:56, 13:15:57, 13:15:57, 13:15:57, 13:15:57, 13:15:58, 13:15:58, 13:15:58, 13:15:58, 13:15:59, NOT FOUND
10062
10063Checking for HTTP-Loadbalancing [Diff]: FOUND
10064< CF-RAY: 3980bdc0866e3c35-CDG
10065> CF-RAY: 3980bdc2059c3c2f-CDG
10066
10067girlloverforum.net does Load-balancing. Found via Methods: DNS HTTP[Diff]
10068
10069
10070
10071Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
10072
10073 ----------------------------------------------------------
10074| Scan Information |
10075 ----------------------------------------------------------
10076
10077Mode ..................... VRFY
10078Worker Processes ......... 5
10079Usernames file ........... users.txt
10080Target count ............. 1
10081Username count ........... 494
10082Target TCP port .......... 25
10083Query timeout ............ 5 secs
10084Target domain ............
10085
10086######## Scan started at Sat Sep 2 09:15:50 2017 #########
10087######## Scan completed at Sat Sep 2 09:24:05 2017 #########
100880 results.
10089
10090494 queries in 495 seconds (1.0 queries / sec)
10091
10092
10093
10094Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-02 09:24 EDT
10095NSE: Loaded 146 scripts for scanning.
10096NSE: Script Pre-scanning.
10097Initiating NSE at 09:24
10098Completed NSE at 09:24, 0.00s elapsed
10099Initiating NSE at 09:24
10100Completed NSE at 09:24, 0.00s elapsed
10101Failed to resolve "girlloverforum.net.txt".
10102Initiating Parallel DNS resolution of 1 host. at 09:24
10103Completed Parallel DNS resolution of 1 host. at 09:24, 11.12s elapsed
10104Initiating SYN Stealth Scan at 09:24
10105Scanning girlloverforum.net (104.31.78.72) [100 ports]
10106Discovered open port 443/tcp on 104.31.78.72
10107Discovered open port 80/tcp on 104.31.78.72
10108Discovered open port 8080/tcp on 104.31.78.72
10109Discovered open port 8443/tcp on 104.31.78.72
10110Completed SYN Stealth Scan at 09:24, 3.51s elapsed (100 total ports)
10111Initiating Service scan at 09:24
10112Scanning 4 services on girlloverforum.net (104.31.78.72)
10113Completed Service scan at 09:24, 13.38s elapsed (4 services on 1 host)
10114Initiating OS detection (try #1) against girlloverforum.net (104.31.78.72)
10115adjust_timeouts2: packet supposedly had rtt of -78094 microseconds. Ignoring time.
10116adjust_timeouts2: packet supposedly had rtt of -78094 microseconds. Ignoring time.
10117Retrying OS detection (try #2) against girlloverforum.net (104.31.78.72)
10118Initiating Traceroute at 09:24
10119Completed Traceroute at 09:24, 3.01s elapsed
10120Initiating Parallel DNS resolution of 6 hosts. at 09:24
10121Completed Parallel DNS resolution of 6 hosts. at 09:24, 11.12s elapsed
10122NSE: Script scanning 104.31.78.72.
10123Initiating NSE at 09:24
10124Completed NSE at 09:25, 21.77s elapsed
10125Initiating NSE at 09:25
10126Completed NSE at 09:25, 0.00s elapsed
10127Nmap scan report for girlloverforum.net (104.31.78.72)
10128Host is up (0.15s latency).
10129Other addresses for girlloverforum.net (not scanned): 2400:cb00:2048:1::681f:4e48 2400:cb00:2048:1::681f:4f48 104.31.79.72
10130Not shown: 96 filtered ports
10131PORT STATE SERVICE VERSION
1013280/tcp open http Cloudflare nginx
10133| http-methods:
10134|_ Supported Methods: POST OPTIONS
10135|_http-title: Site doesn't have a title (text/html; charset=UTF-8).
10136443/tcp open ssl/http Cloudflare nginx
10137| http-methods:
10138|_ Supported Methods: HEAD POST OPTIONS
10139|_http-title: 400 The plain HTTP request was sent to HTTPS port
10140| ssl-cert: Subject: commonName=sni225278.cloudflaressl.com
10141| Subject Alternative Name: DNS:sni225278.cloudflaressl.com, DNS:*.alexshephard.com, DNS:*.barcatalk.com, DNS:*.catlatigo.gq, DNS:*.codevalve.com, DNS:*.combinationfiles.com, DNS:*.cowpawg.gq, DNS:*.girlloverforum.info, DNS:*.girlloverforum.net, DNS:*.johnlovell.site, DNS:*.mexoduhy.ru, DNS:*.mountainwhale.com, DNS:*.nutmobcap.gq, DNS:*.nutomenta.gq, DNS:*.questfestival.net, DNS:*.shopconsole2017.ga, DNS:*.studioscapela.com, DNS:*.tonhexers.gq, DNS:*.tonlayk.ml, DNS:*.tulsawomenshealthcare.com, DNS:*.ukelahoma.com, DNS:*.venturenorthproductions.com, DNS:*.yfuli.cc, DNS:alexshephard.com, DNS:barcatalk.com, DNS:catlatigo.gq, DNS:codevalve.com, DNS:combinationfiles.com, DNS:cowpawg.gq, DNS:girlloverforum.info, DNS:girlloverforum.net, DNS:johnlovell.site, DNS:mexoduhy.ru, DNS:mountainwhale.com, DNS:nutmobcap.gq, DNS:nutomenta.gq, DNS:questfestival.net, DNS:shopconsole2017.ga, DNS:studioscapela.com, DNS:tonhexers.gq, DNS:tonlayk.ml, DNS:tulsawomenshealthcare.com, DNS:ukelahoma.com, DNS:venturenorthproductions.com, DNS:yfuli.cc
10142| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
10143| Public Key type: ec
10144| Public Key bits: 256
10145| Signature Algorithm: ecdsa-with-SHA256
10146| Not valid before: 2017-08-23T00:00:00
10147| Not valid after: 2018-03-01T23:59:59
10148| MD5: 4d46 ca42 a559 93a0 7421 119e c786 973c
10149|_SHA-1: 1b8e 44c4 0240 fe0e 9502 3f26 e6a5 178d 8517 88aa
101508080/tcp open http Cloudflare nginx
10151| http-methods:
10152|_ Supported Methods: OPTIONS
10153|_http-server-header: cloudflare-nginx
10154|_http-title: girlloverforum.net | 521: Web server is down
101558443/tcp open ssl/http Cloudflare nginx
10156|_http-server-header: cloudflare-nginx
10157| ssl-cert: Subject: commonName=sni225278.cloudflaressl.com
10158| Subject Alternative Name: DNS:sni225278.cloudflaressl.com, DNS:*.alexshephard.com, DNS:*.barcatalk.com, DNS:*.catlatigo.gq, DNS:*.codevalve.com, DNS:*.combinationfiles.com, DNS:*.cowpawg.gq, DNS:*.girlloverforum.info, DNS:*.girlloverforum.net, DNS:*.johnlovell.site, DNS:*.mexoduhy.ru, DNS:*.mountainwhale.com, DNS:*.nutmobcap.gq, DNS:*.nutomenta.gq, DNS:*.questfestival.net, DNS:*.shopconsole2017.ga, DNS:*.studioscapela.com, DNS:*.tonhexers.gq, DNS:*.tonlayk.ml, DNS:*.tulsawomenshealthcare.com, DNS:*.ukelahoma.com, DNS:*.venturenorthproductions.com, DNS:*.yfuli.cc, DNS:alexshephard.com, DNS:barcatalk.com, DNS:catlatigo.gq, DNS:codevalve.com, DNS:combinationfiles.com, DNS:cowpawg.gq, DNS:girlloverforum.info, DNS:girlloverforum.net, DNS:johnlovell.site, DNS:mexoduhy.ru, DNS:mountainwhale.com, DNS:nutmobcap.gq, DNS:nutomenta.gq, DNS:questfestival.net, DNS:shopconsole2017.ga, DNS:studioscapela.com, DNS:tonhexers.gq, DNS:tonlayk.ml, DNS:tulsawomenshealthcare.com, DNS:ukelahoma.com, DNS:venturenorthproductions.com, DNS:yfuli.cc
10159| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
10160| Public Key type: ec
10161| Public Key bits: 256
10162| Signature Algorithm: ecdsa-with-SHA256
10163| Not valid before: 2017-08-23T00:00:00
10164| Not valid after: 2018-03-01T23:59:59
10165| MD5: 4d46 ca42 a559 93a0 7421 119e c786 973c
10166|_SHA-1: 1b8e 44c4 0240 fe0e 9502 3f26 e6a5 178d 8517 88aa
10167Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
10168Device type: general purpose
10169Running (JUST GUESSING): Linux 3.X|2.6.X (88%)
10170OS CPE: cpe:/o:linux:linux_kernel:3.18 cpe:/o:linux:linux_kernel:2.6
10171Aggressive OS guesses: Linux 3.18 (88%), Linux 2.6.18 - 2.6.22 (86%)
10172No exact OS matches for host (test conditions non-ideal).
10173Network Distance: 7 hops
10174TCP Sequence Prediction: Difficulty=262 (Good luck!)
10175IP ID Sequence Generation: All zeros
10176
10177TRACEROUTE (using port 443/tcp)
10178HOP RTT ADDRESS
101791 110.32 ms 10.13.0.1
101802 ...
101813 110.72 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
101824 112.21 ms 10.95.33.10
101835 220.86 ms be99-1110.th2-1-a9.fr.eu (213.186.32.215)
101846 220.85 ms equinix-paris.cloudflare.com (195.42.144.143)
101857 220.83 ms 104.31.78.72
10186
10187NSE: Script Post-scanning.
10188Initiating NSE at 09:25
10189Completed NSE at 09:25, 0.00s elapsed
10190Initiating NSE at 09:25
10191Completed NSE at 09:25, 0.00s elapsed
10192Read data files from: /usr/bin/../share/nmap
10193OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
10194Nmap done: 1 IP address (1 host up) scanned in 71.98 seconds
10195 Raw packets sent: 309 (18.318KB) | Rcvd: 60 (4.262KB)
10196
10197
10198Error: can not open nmap file: girlloverforum.net.txt
10199
10200
10201httprint v0.301 (beta) - web server fingerprinting tool
10202(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
10203http://net-square.com/httprint/
10204httprint@net-square.com
10205
10206Finger Printing on http://girlloverforum.net:80/
10207Finger Printing Completed on http://girlloverforum.net:80/
10208--------------------------------------------------
10209Host: girlloverforum.net
10210Fingerprinting Error: Host/URL not found...
10211
10212--------------------------------------------------
10213
10214
10215
10216
10217 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
10218 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
10219 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
10220 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
10221 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
10222
10223 _/ User-Agent Tester ↵
10224 _/ AKA: Purple Pimp ↵
10225 _/ ChrisJohnRiley ↵
10226 _/ blog.c22.cc ↵
10227
10228 [>] Performing initial request and confirming stability
10229 [>] Using User-Agent string Mozilla/5.0
10230
10231 [ ] URL (ENTERED): http://girlloverforum.net
10232 [ ] Response Code: 200 OK
10233 [ ] Date: Sat, 02 Sep 2017 13:25:32 GMT
10234 [ ] Content-Type: text/html; charset=UTF-8
10235 [ ] Content-Length: 69
10236 [ ] Connection: close
10237 [ ] Set-Cookie: __cfduid=d061b7a19e75dac415249784bbdc79e351504358732; expires=Sun, 02-Sep-18 13:25:32 GMT;
10238 path=/; domain=.girlloverforum.net; HttpOnly
10239 [ ] X-Powered-By: PHP/5.3.3
10240 [ ] Server: cloudflare-nginx
10241 [ ] CF-RAY: 3980cbbd93f92204-EWR
10242 [ ] Data (MD5): 0ab8445f7a3d698f2539f793811a023b
10243
10244 [1] Pass
10245 [2] Pass
10246 [3] Pass
10247
10248 [>] URL appears stable. Beginning test
10249
10250 [>] Using DEFAULT User-Agent Strings
10251
10252 [>] Using Crazy User-Agent Strings
10253 [>] Using Bot User-Agent Strings
10254
10255 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
10256
10257
10258 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
10259
10260
10261 [!] CF-RAY: 3980cbe972b8215c-EWR
10262
10263
10264 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
10265
10266
10267 [!] CF-RAY: 3980cbeb05dd0785-EWR
10268 [*] HTTPError: HTTP Error 403: Forbidden
10269[i] Scanning Site: https://girlloverforum.net
10270
10271
10272
10273B A S I C I N F O
10274=======================================================================================================================
10275
10276
10277
10278
10279[+] Site Title:
10280[+] IP address: 104.31.78.72
10281[+] Web Server: cloudflare-nginx
10282[+] CMS: Could Not Detect
10283[+] Cloudflare: Detected
10284[+] Robots File: Found
10285
10286-------------[ contents ]----------------
10287User-agent: Mozilla/5.0 (compatible; CaronteBot/1.0; +http://carontevaha5x626.onion/bot.html)
10288Disallow: /
10289
10290-----------[end of contents]-------------
10291
10292
10293
10294W H O I S L O O K U P
10295===========================================================================================================================
10296
10297
10298
10299 Domain Name: GIRLLOVERFORUM.NET
10300 Registry Domain ID: 124719553_DOMAIN_NET-VRSN
10301 Registrar WHOIS Server: whois.domrobot.com
10302 Registrar URL: http://www.inwx.com
10303 Updated Date: 2017-02-27T05:16:04Z
10304 Creation Date: 2004-07-13T18:35:06Z
10305 Registry Expiry Date: 2018-07-13T18:35:06Z
10306 Registrar: INWX GmbH & Co. KG
10307 Registrar IANA ID: 1420
10308 Registrar Abuse Contact Email:
10309 Registrar Abuse Contact Phone:
10310 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
10311 Name Server: ELLE.NS.CLOUDFLARE.COM
10312 Name Server: MAREK.NS.CLOUDFLARE.COM
10313 DNSSEC: unsigned
10314 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
10315>>> Last update of whois database: 2017-09-02T13:08:32Z <<<
10316
10317For more information on Whois status codes, please visit https://icann.org/epp
10318
10319
10320
10321The Registry database contains ONLY .COM, .NET, .EDU domains and
10322Registrars.
10323
10324
10325
10326
10327G E O I P L O O K U P
10328============================================================================================================================
10329
10330
10331
10332[i] IP Address: 104.31.79.72
10333[i] Country: US
10334[i] State: California
10335[i] City: San Francisco
10336[i] Latitude: 37.769699
10337[i] Longitude: -122.393303
10338
10339
10340
10341
10342H T T P H E A D E R S
10343==========================================================================================================================
10344
10345
10346
10347
10348[i] HTTP/1.1 200 OK
10349[i] Date: Sat, 02 Sep 2017 13:08:42 GMT
10350[i] Content-Type: text/html; charset=UTF-8
10351[i] Content-Length: 69
10352[i] Connection: close
10353[i] Set-Cookie: __cfduid=d1984910ab17bd4e50d160b4433e3b2641504357722; expires=Sun, 02-Sep-18 13:08:42 GMT; path=/; domain=.girlloverforum.net; HttpOnly
10354[i] X-Powered-By: PHP/5.3.3
10355[i] Server: cloudflare-nginx
10356[i] CF-RAY: 3980b314cced1852-EWR
10357
10358
10359
10360
10361D N S L O O K U P
10362======================================================================================================================
10363
10364
10365
10366girlloverforum.net. 296 IN A 104.31.78.72
10367girlloverforum.net. 296 IN A 104.31.79.72
10368girlloverforum.net. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
10369girlloverforum.net. 296 IN AAAA 2400:cb00:2048:1::681f:4f48
10370girlloverforum.net. 296 IN AAAA 2400:cb00:2048:1::681f:4e48
10371
10372
10373
10374
10375S U B N E T C A L C U L A T I O N
10376=======================================================================================================================================
10377
10378
10379
10380Address = 2400:cb00:2048:1::681f:4e48
10381Network = 2400:cb00:2048:1::681f:4e48 / 128
10382Netmask = ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff
10383Wildcard Mask = ::
10384Hosts Bits = 0
10385Max. Hosts = 0 (2^0 - 1)
10386Host Range = { 2400:cb00:2048:1::681f:4e49 - 2400:cb00:2048:1::681f:4e48 }
10387
10388
10389
10390N M A P P O R T S C A N
10391===============================================================================================================================
10392
10393
10394
10395
10396Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-02 13:08 UTC
10397Nmap scan report for girlloverforum.net (104.31.78.72)
10398Host is up (0.0018s latency).
10399Other addresses for girlloverforum.net (not scanned): 104.31.79.72 2400:cb00:2048:1::681f:4e48 2400:cb00:2048:1::681f:4f48
10400PORT STATE SERVICE VERSION
1040121/tcp filtered ftp
1040222/tcp filtered ssh
1040323/tcp filtered telnet
1040425/tcp filtered smtp
1040580/tcp open http Cloudflare nginx
10406110/tcp filtered pop3
10407143/tcp filtered imap
10408443/tcp open ssl/http Cloudflare nginx
10409445/tcp filtered microsoft-ds
104103389/tcp filtered ms-wbt-server
10411
10412Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
10413Nmap done: 1 IP address (1 host up) scanned in 13.83 seconds
10414
10415
10416
10417S U B - D O M A I N F I N D E R
10418=====================================================================================================================================
10419
10420
10421
10422
10423[i] Total Subdomains Found : 4
10424
10425[+] Subdomain: girlloverforum.net
10426[-] IP: 104.31.78.72
10427
10428[+] Subdomain: girlloverforum.net
10429[-] IP: 104.31.79.72
10430
10431[+] Subdomain: www.girlloverforum.net
10432[-] IP: 104.31.78.72
10433
10434[+] Subdomain: www.girlloverforum.net
10435[-] IP: 104.31.79.72
10436
10437
10438
10439
10440
10441R E V E R S E I P L O O K U P
10442=======================================================================================================================================
10443
10444
10445[i] Total Sites Found On This Server : 4
10446
10447
10448[#] girlloverforum.net
10449[-] CMS: Could Not Detect
10450
10451[#] hdcineblog01.com
10452[-] CMS: Could Not Detect
10453
10454[#] www.professionalmassageerie.com
10455[-] CMS: WordPress
10456
10457[#] www.wffservices.com,
10458[-] CMS: Could Not Detect
10459##############################################################################################################################################################################################################################################################################
10460 - OPDeathEathers Anonymous full Recon JTSEC #17-