· 8 years ago · Aug 29, 2017, 06:40 AM
1http://8ch.net/younglove/res/13450.html
28ch.net
3
4
5 Domain Name: 8CH.NET
6 Registry Domain ID: 21069829_DOMAIN_NET-VRSN
7 Registrar WHOIS Server: whois.tucows.com
8 Registrar URL: http://www.tucowsdomains.com
9 Updated Date: 2017-01-31T05:07:26Z
10 Creation Date: 2000-03-01T17:04:24Z
11 Registry Expiry Date: 2018-03-01T17:04:24Z
12 Registrar: Tucows Domains Inc.
13 Registrar IANA ID: 69
14 Registrar Abuse Contact Email:
15 Registrar Abuse Contact Phone:
16 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
17 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
18 Name Server: BEN.NS.CLOUDFLARE.COM
19 Name Server: ISLA.NS.CLOUDFLARE.COM
20 DNSSEC: unsigned
21
22Domain Name: 8CH.NET
23Domain ID: 21069829_DOMAIN_NET-VRSN
24Registrar WHOIS Server: whois.tucows.com
25Registrar URL: http://tucowsdomains.com
26Updated Date: 2017-01-31T05:07:26Z
27Creation Date: 2000-03-01T17:04:24Z
28Registrar Registration Expiration Date: 2018-03-01T17:04:24Z
29Registrar: TUCOWS, INC.
30Registrar IANA ID: 69
31Registrar Abuse Contact Email: domainabuse@tucows.com
32Registrar Abuse Contact Phone: +1.4165350123
33Reseller: N.T.Technology inc.
34Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
35Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
36Registry Registrant ID:
37Registrant Name: Jim Watkins
38Registrant Organization: N.T.Technology, inc
39Registrant Street: 9120 Double Diamond Parkway Ste 5901
40Registrant City: Reno
41Registrant State/Province: Nevada
42Registrant Postal Code: 89521
43Registrant Country: US
44Registrant Phone: +1.4252593201
45Registrant Phone Ext:
46Registrant Fax: +1.4154620214
47Registrant Fax Ext:
48Registrant Email: domains@nttec.com
49Registry Admin ID:
50Admin Name: Jim Watkins
51Admin Organization: N.T.Technology, inc
52Admin Street: 9120 Double Diamond Parkway Ste 5901
53Admin City: Reno
54Admin State/Province: Nevada
55Admin Postal Code: 89521
56Admin Country: US
57Admin Phone: +1.4252593201
58Admin Phone Ext:
59Admin Fax: +1.4154620214
60Admin Fax Ext:
61Admin Email: domains@nttec.com
62Registry Tech ID:
63Tech Name: Jim Watkins
64Tech Organization: N.T.Technology, inc
65Tech Street: 9120 Double Diamond Parkway Ste 5901
66Tech City: Reno
67Tech State/Province: Nevada
68Tech Postal Code: 89521
69Tech Country: US
70Tech Phone: +1.4252593201
71Tech Phone Ext:
72Tech Fax: +1.4154620214
73Tech Fax Ext:
74Tech Email: domains@nttec.com
75Name Server: BEN.NS.CLOUDFLARE.COM
76Name Server: ISLA.NS.CLOUDFLARE.COM
77DNSSEC: unsigned
78
79
80
81 IN ANY
82
83;; ANSWER SECTION:
848ch.net. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
858ch.net. 52415 IN NS ben.ns.cloudflare.com.
868ch.net. 52415 IN NS isla.ns.cloudflare.com.
87
88;; Query time: 32 msec
89;; SERVER: 192.168.1.254#53(192.168.1.254)
90;; WHEN: Sun Aug 27 23:55:16 EDT 2017
91;; MSG SIZE rcvd: 148
92
93
94
95 traceroute -T -O info -i eth0 8ch.net
96traceroute to 8ch.net (104.20.43.57), 30 hops max, 60 byte packets
97 1 gateway (192.168.1.254) 0.462 ms 0.635 ms 0.903 ms
98 2 10.135.18.1 (10.135.18.1) 6.955 ms 7.604 ms 7.859 ms
99 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 29.938 ms 30.015 ms 30.045 ms
100 4 de-cix-new-york.as13335.net (206.130.10.31) 30.817 ms 30.977 ms 31.082 ms
101 5 104.20.43.57 (104.20.43.57) <syn,ack> 31.370 ms 31.492 ms 31.686 ms
102
103
104
105Host's addresses:
106__________________
107
1088ch.net. 202 IN A 104.20.44.57
1098ch.net. 202 IN A 104.20.43.57
110
111
112Name Servers:
113______________
114
115ben.ns.cloudflare.com. 50480 IN A 173.245.59.103
116isla.ns.cloudflare.com. 86400 IN A 173.245.58.119
117
118
119Mail (MX) Servers:
120___________________
121
122mail.nttec.com. 300 IN A 207.29.234.10
123
124
125
126
127Brute forcing with dns.txt:
128____________________________
129
130a.8ch.net. 300 IN A 104.20.44.57
131a.8ch.net. 300 IN A 104.20.43.57
132ads.8ch.net. 300 IN A 104.20.43.57
133ads.8ch.net. 300 IN A 104.20.44.57
134beta.8ch.net. 300 IN A 104.20.43.57
135beta.8ch.net. 300 IN A 104.20.44.57
136mail.8ch.net. 300 IN A 206.223.147.150
137www.8ch.net. 300 IN A 104.20.43.57
138www.8ch.net. 300 IN A 104.20.44.57
139
140
141
142
1438ch.net class C netranges:
144___________________________
145
146 104.20.43.0/24
147 104.20.44.0/24
148 206.223.147.0/24
149
150
151a.8ch.net
152IP address #1: 104.20.43.57
153IP address #2: 104.20.44.57
154
155beta.8ch.net
156IP address #1: 104.20.44.57
157IP address #2: 104.20.43.57
158
159h.8ch.net
160IP address #1: 104.20.44.57
161IP address #2: 104.20.43.57
162
163jp.8ch.net
164IP address #1: 104.20.44.57
165IP address #2: 104.20.43.57
166
167m.8ch.net
168IP address #1: 104.20.43.57
169IP address #2: 104.20.44.57
170
171mail.8ch.net
172IP address #1: 206.223.147.150
173
174media.8ch.net
175IP address #1: 104.20.43.57
176IP address #2: 104.20.44.57
177
178o.8ch.net
179IP address #1: 104.20.44.57
180IP address #2: 104.20.43.57
181
182ps.8ch.net
183IP address #1: 104.20.44.57
184IP address #2: 104.20.43.57
185
186v.8ch.net
187IP address #1: 104.20.44.57
188IP address #2: 104.20.43.57
189
190ws.8ch.net
191IP address #1: 104.20.44.57
192IP address #2: 104.20.43.57
193
194www.8ch.net
195IP address #1: 104.20.44.57
196IP address #2: 104.20.43.57
197
198
199
200WhatWeb report for http://8ch.net
201Status : 301 Moved Permanently
202Title : <None>
203IP : 104.20.44.57
204Country : UNITED STATES, US
205
206
207
208*******************************************************************
209* *
210* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
211* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
212* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
213* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
214* *
215* TheHarvester Ver. 2.7 *
216* Coded by Christian Martorella *
217* Edge-Security Research *
218* cmartorella@edge-security.com *
219*******************************************************************
220
221
222[-] Searching in Google:
223 Searching 0 results...
224 Searching 100 results...
225 Searching 200 results...
226 Searching 300 results...
227 Searching 400 results...
228 Searching 500 results...
229
230
231[+] Emails found:
232------------------
233admin@8ch.net
234dmca@8ch.net
235hachi@8ch.net
236
237[+] Hosts found in search engines:
238------------------------------------
239[-] Resolving hostnames IPs...
240104.20.44.57:banners.8ch.net
241104.20.43.57:beta.8ch.net
242104.20.44.57:kara.8ch.net
243104.20.44.57:media.8ch.net
244104.20.43.57:o.8ch.net
245104.20.43.57:sys.8ch.net
246104.20.43.57:www.8ch.net
247
248
249
250 ^ ^
251 _ __ _ ____ _ __ _ _ ____
252 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
253 | V V // o // _/ | V V // 0 // 0 // _/
254 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
255 <
256 ...'
257
258 WAFW00F - Web Application Firewall Detection Tool
259
260 By Sandro Gauci && Wendel G. Henrique
261
262Checking http://8ch.net
263The site http://8ch.net is behind a CloudFlare
264Number of requests: 1
265
266
267DNS Servers for 8ch.net:
268 ben.ns.cloudflare.com
269 isla.ns.cloudflare.com
270
271Trying zone transfer first...
272 Testing ben.ns.cloudflare.com
273 Request timed out or transfer not allowed.
274 Testing isla.ns.cloudflare.com
275 Request timed out or transfer not allowed.
276
277Unsuccessful in zone transfer (it was worth a shot)
278Okay, trying the good old fashioned way... brute force
279
280Checking for wildcard DNS...
281Nope. Good.
282Now performing 2280 test(s)...
283104.20.44.57 a.8ch.net
284104.20.43.57 a.8ch.net
285104.20.43.57 ads.8ch.net
286104.20.44.57 ads.8ch.net
287104.20.44.57 beta.8ch.net
288104.20.43.57 beta.8ch.net
289104.20.44.57 h.8ch.net
290104.20.43.57 h.8ch.net
291104.20.44.57 jp.8ch.net
292104.20.43.57 jp.8ch.net
293104.20.43.57 m.8ch.net
294104.20.44.57 m.8ch.net
295206.223.147.150 mail.8ch.net
296104.20.43.57 media.8ch.net
297104.20.44.57 media.8ch.net
298104.20.44.57 o.8ch.net
299104.20.43.57 o.8ch.net
300104.20.44.57 ps.8ch.net
301104.20.43.57 ps.8ch.net
302104.20.43.57 v.8ch.net
303104.20.44.57 v.8ch.net
304104.20.44.57 ws.8ch.net
305104.20.43.57 ws.8ch.net
306104.20.43.57 www.8ch.net
307104.20.44.57 www.8ch.net
308
309Subnets found (may want to probe here using nmap or unicornscan):
310 104.20.43.0-255 : 12 hostnames found.
311 104.20.44.0-255 : 12 hostnames found.
312 206.223.147.0-255 : 1 hostnames found.
313
314
315
316Checking for HTTP-Loadbalancing [Date]: 04:05:22, 04:05:22, 04:05:22, 04:05:22, 04:05:23, 04:05:23, 04:05:23, 04:05:23, 04:05:24, 04:05:24, 04:05:24, 04:05:24, 04:05:25, 04:05:25, 04:05:25, 04:05:25, 04:05:26, 04:05:26, 04:05:26, 04:05:26, 04:05:27, 04:05:27, 04:05:27, 04:05:28, 04:05:28, 04:05:28, 04:05:28, 04:05:29, 04:05:29, 04:05:29, 04:05:29, 04:05:30, 04:05:30, 04:05:30, 04:05:30, 04:05:31, 04:05:31, 04:05:31, 04:05:31, 04:05:32, 04:05:32, 04:05:32, 04:05:32, 04:05:33, 04:05:33, 04:05:33, 04:05:33, 04:05:34, 04:05:34, 04:05:34, NOT FOUND
317
318Checking for HTTP-Loadbalancing [Diff]: FOUND
319< Expires: Mon, 28 Aug 2017 04:05:49 GMT
320> Expires: Mon, 28 Aug 2017 04:05:50 GMT
321< CF-RAY: 3954649d525f1509-CDG
322> CF-RAY: 3954649f361c69ac-CDG
323
324
325
326
327B A S I C I N F O
328====================
329
330
331[+] Site Title: 8chan, the Darkest Reaches of the Internet
332[+] IP address: 104.20.44.57
333[+] Web Server: cloudflare-nginx
334[+] CMS: Could Not Detect
335[+] Cloudflare: Detected
336[+] Robots File: Could NOT Find robots.txt!
337
338
339
340
341W H O I S L O O K U P
342========================
343
344 Domain Name: 8CH.NET
345 Registry Domain ID: 21069829_DOMAIN_NET-VRSN
346 Registrar WHOIS Server: whois.tucows.com
347 Registrar URL: http://www.tucowsdomains.com
348 Updated Date: 2017-01-31T05:07:26Z
349 Creation Date: 2000-03-01T17:04:24Z
350 Registry Expiry Date: 2018-03-01T17:04:24Z
351 Registrar: Tucows Domains Inc.
352 Registrar IANA ID: 69
353 Registrar Abuse Contact Email:
354 Registrar Abuse Contact Phone:
355 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
356 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
357 Name Server: BEN.NS.CLOUDFLARE.COM
358 Name Server: ISLA.NS.CLOUDFLARE.COM
359
360
361G E O I P L O O K U P
362=========================
363
364[i] IP Address: 104.20.44.57
365[i] Country: US
366[i] State: California
367[i] City: San Francisco
368[i] Latitude: 37.769699
369[i] Longitude: -122.393303
370
371
372
373
374H T T P H E A D E R S
375=======================
376
377
378[i] HTTP/1.1 301 Moved Permanently
379[i] Date: Mon, 28 Aug 2017 03:56:07 GMT
380[i] Connection: close
381[i] Cache-Control: max-age=3600
382[i] Expires: Mon, 28 Aug 2017 04:56:07 GMT
383[i] Location: https://8ch.net/
384[i] Server: cloudflare-nginx
385[i] CF-RAY: 395456bfb27f68de-CDG
386[i] HTTP/1.1 301 Moved Permanently
387[i] Date: Mon, 28 Aug 2017 03:56:08 GMT
388[i] Content-Type: text/html
389[i] Connection: close
390[i] Set-Cookie: __cfduid=d5810dcf40006bc215ffa80e57d0af5301503892567; expires=Tue, 28-Aug-18 03:56:07 GMT; path=/; domain=.8ch.net; HttpOnly
391[i] Location: https://8ch.net/index.html
392[i] Expires: Sun, 27 Aug 2017 19:57:16 GMT
393[i] Cache-Control: no-cache
394[i] Access-Control-Allow-Origin: *
395[i] Server: cloudflare-nginx
396[i] CF-RAY: 395456c36ac21049-CDG
397[i] HTTP/1.1 200 OK
398[i] Date: Mon, 28 Aug 2017 03:56:08 GMT
399[i] Content-Type: text/html
400[i] Connection: close
401[i] Set-Cookie: __cfduid=df47fabf761b3cb7a3016fc5895cc60d41503892568; expires=Tue, 28-Aug-18 03:56:08 GMT; path=/; domain=.8ch.net; HttpOnly
402[i] Last-Modified: Mon, 28 Aug 2017 04:00:39 GMT
403[i] Accept-Ranges: bytes
404[i] Expires: Sun, 27 Aug 2017 19:57:17 GMT
405[i] Cache-Control: no-cache
406[i] Access-Control-Allow-Origin: *
407[i] Server: cloudflare-nginx
408[i] CF-RAY: 395456c9b8fb3bed-CDG
409
410
411
412
413D N S L O O K U P
414===================
415
4168ch.net. 294 IN A 104.20.43.57
4178ch.net. 294 IN A 104.20.44.57
4188ch.net. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
419
420
421
422
423S U B N E T C A L C U L A T I O N
424====================================
425
426Address = 104.20.43.57
427Network = 104.20.43.57 / 32
428Netmask = 255.255.255.255
429Broadcast = not needed on Point-to-Point links
430Wildcard Mask = 0.0.0.0
431Hosts Bits = 0
432Max. Hosts = 1 (2^0 - 0)
433Host Range = { 104.20.43.57 - 104.20.43.57 }
434
435
436
437N M A P P O R T S C A N
438============================
439
440
441Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 03:56 UTC
442Nmap scan report for 8ch.net (104.20.43.57)
443Host is up (0.0019s latency).
444Other addresses for 8ch.net (not scanned): 104.20.44.57
445PORT STATE SERVICE VERSION
44621/tcp filtered ftp
44722/tcp filtered ssh
44823/tcp filtered telnet
44925/tcp filtered smtp
45080/tcp open http Cloudflare nginx
451110/tcp filtered pop3
452143/tcp filtered imap
453443/tcp open ssl/http Cloudflare nginx
454445/tcp filtered microsoft-ds
4553389/tcp filtered ms-wbt-server
456
457
458
459S U B - D O M A I N F I N D E R
460==================================
461
462
463[i] Total Subdomains Found : 22
464
465[+] Subdomain: 8ch.net
466[-] IP: 104.20.43.57
467
468[+] Subdomain: 8ch.net
469[-] IP: 104.20.44.57
470
471[+] Subdomain: media2.8ch.net
472[-] IP: 104.20.43.57
473
474[+] Subdomain: media2.8ch.net
475[-] IP: 104.20.44.57
476
477[+] Subdomain: media.8ch.net
478[-] IP: 104.20.43.57
479
480[+] Subdomain: media.8ch.net
481[-] IP: 104.20.44.57
482
483[+] Subdomain: kara.8ch.net
484[-] IP: 104.20.43.57
485
486[+] Subdomain: kara.8ch.net
487[-] IP: 104.20.44.57
488
489[+] Subdomain: beta.8ch.net
490[-] IP: 104.20.43.57
491
492[+] Subdomain: beta.8ch.net
493[-] IP: 104.20.44.57
494
495[+] Subdomain: softserve.8ch.net
496[-] IP: 104.20.43.57
497
498[+] Subdomain: softserve.8ch.net
499[-] IP: 104.20.44.57
500
501[+] Subdomain: o.8ch.net
502[-] IP: 104.20.43.57
503
504[+] Subdomain: o.8ch.net
505[-] IP: 104.20.44.57
506
507[+] Subdomain: ads.8ch.net
508[-] IP: 104.20.43.57
509
510[+] Subdomain: ads.8ch.net
511[-] IP: 104.20.44.57
512
513[+] Subdomain: irclogs.8ch.net
514[-] IP: 104.20.43.57
515
516[+] Subdomain: irclogs.8ch.net
517[-] IP: 104.20.44.57
518
519[+] Subdomain: banners.8ch.net
520[-] IP: 104.20.43.57
521
522[+] Subdomain: banners.8ch.net
523[-] IP: 104.20.44.57
524
525[+] Subdomain: www.8ch.net
526[-] IP: 104.20.43.57
527
528[+] Subdomain: www.8ch.net
529[-] IP: 104.20.44.57
530
531
532
533
534
535R E V E R S E I P L O O K U P
536==================================
537
538
539[i] Total Sites Found On This Server : 2
540
541
542[#] banners.8ch.net
543[-] CMS: Could Not Detect
544
545[#] o.8ch.net,
546[-] CMS: Could Not Detect
547
548---------------------------------------------------------------------------
549+ Target IP: 104.20.43.57
550+ Target Hostname: 8ch.net
551+ Target Port: 80
552+ Start Time: 2017-08-28 00:11:43 (GMT-4)
553---------------------------------------------------------------------------
554+ Server: cloudflare-nginx
555+ The anti-clickjacking X-Frame-Options header is not present.
556+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
557+ Uncommon header 'cf-ray' found, with contents: 39546dbae6c668de-CDG
558+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
559+ Root page / redirects to: https://8ch.net/
560+ No CGI Directories found (use '-C all' to force check all possible dirs)
561+ Server banner has changed from 'cloudflare-nginx' to '-nginx' which may suggest a WAF, load balancer or proxy is in place
562+ 7445 requests: 0 error(s) and 4 item(s) reported on remote host
563+ End Time: 2017-08-28 00:28:27 (GMT-4) (1004 seconds)
564---------------------------------------------------------------------------
565#################################################################################
566magazine-fashion.com
567Hostname magazine-fashion.com ISP Hosting Operator eServer.ru Ltd. (AS42244)
568Continent Europe Flag
569RU
570Country Russian Federation Country Code RU (RUS)
571Region 48 Local time 28 Aug 2017 07:25 MSK
572Metropolis Unknown Postal Code 101194
573City Moscow Latitude 55.749
574IP Address 178.218.222.218 Longitude 37.618
575#################################################################################
576youngteenies.net
577
578
579 Domain Name: YOUNGTEENIES.NET
580 Registry Domain ID: 148289229_DOMAIN_NET-VRSN
581 Registrar WHOIS Server: whois.godaddy.com
582 Registrar URL: http://www.godaddy.com
583 Updated Date: 2016-03-31T17:31:21Z
584 Creation Date: 2005-03-28T06:39:14Z
585 Registry Expiry Date: 2018-03-28T05:39:14Z
586 Registrar: GoDaddy.com, LLC
587 Registrar IANA ID: 146
588 Registrar Abuse Contact Email: abuse@godaddy.com
589 Registrar Abuse Contact Phone: 480-624-2505
590 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
591 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
592 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
593 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
594 Name Server: NS1.M3XS.NET
595 Name Server: NS2.M3XS.NET
596 Name Server: NS3.M3XS.NET
597 Name Server: NS4.M3XS.NET
598
599Domain Name: YOUNGTEENIES.NET
600Registrar URL: http://www.godaddy.com
601Registrant Name: Elliot Deane
602Registrant Organization:
603Name Server: NS1.M3XS.NET
604Name Server: NS2.M3XS.NET
605Name Server: NS3.M3XS.NET
606Name Server: NS4.M3XS.NET
607DNSSEC: unsigned
608 IN ANY
609
610;; ANSWER SECTION:
611youngteenies.net. 3562 IN A 67.23.100.162
612youngteenies.net. 3562 IN NS ns1.m3xs.net.
613youngteenies.net. 3562 IN NS ns4.m3xs.net.
614youngteenies.net. 3562 IN NS ns2.m3xs.net.
615youngteenies.net. 3562 IN NS ns3.m3xs.net.
616
617;; Query time: 8 msec
618;; SERVER: 192.168.1.254#53(192.168.1.254)
619;; WHEN: Mon Aug 28 11:23:37 EDT 2017
620;; MSG SIZE rcvd: 138
621
622 traceroute -T -O info -i eth0 youngteenies.net
623traceroute to youngteenies.net (67.23.100.162), 30 hops max, 60 byte packets
624 1 gateway (192.168.1.254) 0.476 ms 0.660 ms 0.815 ms
625 2 10.135.18.1 (10.135.18.1) 11.253 ms 17.169 ms 20.367 ms
626 3 75.154.223.222 (75.154.223.222) 33.856 ms 34.052 ms 34.187 ms
627 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.647 ms 30.720 ms 31.325 ms
628 5 * * *
629 6 4.53.116.210 (4.53.116.210) 37.103 ms 34.432 ms 34.870 ms
630 7 yellow-bboi.bboi.net (66.216.1.218) 36.408 ms 36.634 ms 36.668 ms
631 8 67.23.113.49 (67.23.113.49) 36.578 ms 35.013 ms 35.569 ms
632 9 te2-2.NVARSX-AGA02.yellowfiber.net (67.23.112.186) 34.970 ms 35.073 ms 35.007 ms
63310 v3423.m3xs.net (67.23.100.162) <syn,ack> 35.251 ms 35.584 ms 35.690 ms
634
635
636__________________
637
638youngteenies.net. 3517 IN A 67.23.100.162
639
640
641Wildcard detection using: vltpltdyhhwt
642_______________________________________
643
644vltpltdyhhwt.youngteenies.net. 3600 IN A 67.23.100.162
645
646
647Name Servers:
648______________
649
650ns1.m3xs.net. 3600 IN A 67.23.100.5
651ns4.m3xs.net. 3600 IN A 65.175.104.4
652ns3.m3xs.net. 3600 IN A 216.177.153.200
653ns2.m3xs.net. 3600 IN A 184.175.106.2
654
655
656Mail (MX) Servers:
657___________________
658
659
660www.youngteenies.net. 3600 IN CNAME v3423.youngteenies.net.
661
662
663
664 67.23.100.0/24
665
666
667Performing reverse lookup on 256 ip addresses:
668_______________________________________________
669
670WhatWeb report for http://youngteenies.net
671Status : 200 OK
672Title : Young Teenies
673IP : 67.23.100.162
674Country : UNITED STATES, US
675
676Summary : SmartThumbs, Google-Analytics[UA-36820973-1], Script[text/javascript], HTTPServer[Apache], Apache
677
678Detected Plugins:
679[ Apache ]
680 The Apache HTTP Server Project is an effort to develop and
681 maintain an open-source HTTP server for modern operating
682 systems including UNIX and Windows NT. The goal of this
683 project is to provide a secure, efficient and extensible
684 server that provides HTTP services in sync with the current
685 HTTP standards.
686
687 Google Dorks: (3)
688 Website : http://httpd.apache.org/
689
690[ Google-Analytics ]
691 This plugin identifies the Google Analytics account.
692
693 Account : UA-36820973-1
694 Website : http://www.google.com/analytics/
695
696[ HTTPServer ]
697 HTTP server header string. This plugin also attempts to
698 identify the operating system from the server header.
699
700 String : Apache (from server string)
701
702[ Script ]
703 This plugin detects instances of script HTML elements and
704 returns the script language/type.
705
706 String : text/javascript
707
708[ SmartThumbs ]
709 SmartThumbs is a complete tgp script (thumbnail gallery
710 post management script), it makes your work easier and
711 faster by automating gallery preview and thumbnail
712 cropping. Productivity based thumbnail rotation makes your
713 productivity higher and brings fast traffic growth.
714
715 Website : http://www.smart-scripts.com/?action=smartthumbs
716
717HTTP Headers:
718 HTTP/1.1 200 OK
719 Date: Mon, 28 Aug 2017 15:26:51 GMT
720 Server: Apache
721 Accept-Ranges: bytes
722 Connection: close
723 Transfer-Encoding: chunked
724 Content-Type: text/html
725
726
727
728
729*******************************************************************
730* *
731* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
732* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
733* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
734* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
735* *
736* TheHarvester Ver. 2.7 *
737* Coded by Christian Martorella *
738* Edge-Security Research *
739* cmartorella@edge-security.com *
740*******************************************************************
741
742
743[-] Searching in Google:
744 Searching 0 results...
745 Searching 100 results...
746 Searching 200 results...
747 Searching 300 results...
748 Searching 400 results...
749 Searching 500 results...
750
751
752[+] Emails found:
753------------------
754info@youngteenies.net
755
756[+] Hosts found in search engines:
757------------------------------------
758[-] Resolving hostnames IPs...
75967.23.100.162:www.youngteenies.net
760
761
762
763 ^ ^
764 _ __ _ ____ _ __ _ _ ____
765 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
766 | V V // o // _/ | V V // 0 // 0 // _/
767 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
768 <
769 ...'
770
771 WAFW00F - Web Application Firewall Detection Tool
772
773 By Sandro Gauci && Wendel G. Henrique
774
775Checking http://youngteenies.net
776Generic Detection results:
777No WAF detected by the generic detection
778Number of requests: 13
779
780
781DNS Servers for youngteenies.net:
782 ns3.m3xs.net
783 ns1.m3xs.net
784 ns4.m3xs.net
785 ns2.m3xs.net
786
787Trying zone transfer first...
788 Testing ns3.m3xs.net
789 Request timed out or transfer not allowed.
790 Testing ns1.m3xs.net
791 Request timed out or transfer not allowed.
792 Testing ns4.m3xs.net
793 Request timed out or transfer not allowed.
794 Testing ns2.m3xs.net
795 Request timed out or transfer not allowed.
796
797Unsuccessful in zone transfer (it was worth a shot)
798Okay, trying the good old fashioned way... brute force
799
800Checking for wildcard DNS...
801 ** Found 99298572852.youngteenies.net at 67.23.100.162.
802 ** High probability of wildcard DNS.
803Now performing 2280 test(s)...
804
805Subnets found (may want to probe here using nmap or unicornscan):
806
807Done with Fierce scan: http://ha.ckers.org/fierce/
808Found 0 entries.
809
810Have a nice day.
811
812
813
814lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
815 Written by Stefan Behte (http://ge.mine.nu)
816 Proof-of-concept! Might give false positives.
817
818Checking for DNS-Loadbalancing: NOT FOUND
819Checking for HTTP-Loadbalancing [Server]:
820 Apache
821 NOT FOUND
822
823Checking for HTTP-Loadbalancing [Date]: 15:37:21, 15:37:22, 15:37:22, 15:37:23, 15:37:23, 15:37:23, 15:37:24, 15:37:24, 15:37:25, 15:37:25, 15:37:25, 15:37:26, 15:37:26, 15:37:27, 15:37:27, 15:37:27, 15:37:28, 15:37:28, 15:37:29, 15:37:29, 15:37:29, 15:37:30, 15:37:30, 15:37:31, 15:37:31, 15:37:31, 15:37:32, 15:37:32, 15:37:33, 15:37:33, 15:37:34, 15:37:34, 15:37:34, 15:37:35, 15:37:35, 15:37:36, 15:37:36, 15:37:36, 15:37:37, 15:37:37, 15:37:38, 15:37:38, 15:37:38, 15:37:39, 15:37:39, 15:37:40, 15:37:40, 15:37:40, 15:37:41, 15:37:41, NOT FOUND
824
825Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
826
827youngteenies.net does NOT use Load-balancing.
828
829
830
831Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
832
833 ----------------------------------------------------------
834| Scan Information |
835 ----------------------------------------------------------
836
837Mode ..................... VRFY
838Worker Processes ......... 5
839Usernames file ........... users.txt
840Target count ............. 1
841Username count ........... 494
842Target TCP port .......... 25
843Query timeout ............ 5 secs
844Target domain ............
845
846Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 11:46 EDT
847NSE: Loaded 146 scripts for scanning.
848NSE: Script Pre-scanning.
849Initiating NSE at 11:46
850Completed NSE at 11:46, 0.00s elapsed
851Initiating NSE at 11:46
852Completed NSE at 11:46, 0.00s elapsed
853Failed to resolve "youngteenies.net.txt".
854Initiating Parallel DNS resolution of 1 host. at 11:46
855Completed Parallel DNS resolution of 1 host. at 11:46, 0.37s elapsed
856Initiating SYN Stealth Scan at 11:46
857Scanning youngteenies.net (67.23.100.162) [100 ports]
858Discovered open port 21/tcp on 67.23.100.162
859Discovered open port 143/tcp on 67.23.100.162
860Discovered open port 80/tcp on 67.23.100.162
861Discovered open port 993/tcp on 67.23.100.162
862Discovered open port 995/tcp on 67.23.100.162
863Discovered open port 110/tcp on 67.23.100.162
864Discovered open port 443/tcp on 67.23.100.162
865Discovered open port 22/tcp on 67.23.100.162
866
867
868TRACEROUTE (using port 8080/tcp)
869HOP RTT ADDRESS
8701 110.15 ms 10.13.0.1
8712 ...
8723 110.74 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
8734 111.76 ms 10.95.33.8
8745 220.07 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
8756 220.06 ms ge-3-3-0.mpr1.lhr3.uk.above.net (195.66.236.76)
8767 220.10 ms ae6.mpr3.lhr3.uk.zip.zayo.com (64.125.21.21)
8778 220.14 ms ae27.cs1.lhr15.uk.eth.zayo.com (64.125.30.234)
8789 225.57 ms ae5.cs1.dca2.us.eth.zayo.com (64.125.29.131)
87910 220.18 ms ae0.cs2.dca2.us.eth.zayo.com (64.125.29.229)
88011 187.37 ms ae27.cr2.dca2.us.zip.zayo.com (64.125.30.249)
88112 213.54 ms ae15.er5.iad10.us.zip.zayo.com (64.125.31.42)
88213 213.55 ms 64.125.170.2.available.above.net (64.125.170.2)
88314 190.88 ms 67.23.108.66
88415 190.87 ms te2-1.rsx.a01.yellowfiber.net (67.23.107.234)
88516 188.26 ms v3423.m3xs.net (67.23.100.162)
886
887NSE: Script Post-scanning.
888Initiating NSE at 11:47
889Completed NSE at 11:47, 0.00s elapsed
890Initiating NSE at 11:47
891Completed NSE at 11:47, 0.00s elapsed
892Read data files from: /usr/bin/../share/nmap
893OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
894Nmap done: 1 IP address (1 host up) scanned in 100.41 seconds
895 Raw packets sent: 344 (17.132KB) | Rcvd: 56 (8.856KB)
896
897
898
899 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
900 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
901 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
902 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
903 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
904
905 _/ User-Agent Tester ↵
906 _/ AKA: Purple Pimp ↵
907 _/ ChrisJohnRiley ↵
908 _/ blog.c22.cc ↵
909
910 [>] Performing initial request and confirming stability
911 [>] Using User-Agent string Mozilla/5.0
912
913 [ ] URL (ENTERED): http://youngteenies.net
914 [ ] Response Code: 200 OK
915 [ ] Date: Mon, 28 Aug 2017 15:48:03 GMT
916 [ ] Server: Apache
917 [ ] Accept-Ranges: bytes
918 [ ] Connection: close
919 [ ] Transfer-Encoding: chunked
920 [ ] Content-Type: text/html
921 [ ] Data (MD5): 748e13150aa4852bd7116972ba2ce36c
922
923 [1] Pass
924 [2] Pass
925 [3] Pass
926
927 [>] URL appears stable. Beginning test
928
929 [>] Using DEFAULT User-Agent Strings
930
931 [>] Using Crazy User-Agent Strings
932 [>] Using Bot User-Agent Strings
933
934 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
935
936
937 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
938
939
940 [!] Data (MD5): b5258cd6caf0edd884dbde07304063d3
941
942
943 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
944
945
946 [!] Data (MD5): 8f078fed503d50199a2126c0c9d37725
947
948
949 [>] User-Agent String : TrackBack/1.02
950
951
952 [!] Data (MD5): e44b8a27fd2820e79489f5e14530eb80
953
954
955 [>] User-Agent String : wispr
956
957
958 [!] Data (MD5): 4cc16c9804abc8beddbbff1f97dd255c
959
960
961 [>] User-Agent String : EMPTY USER-AGENT STRING!
962
963
964 [!] Data (MD5): 8db13c0a543585bbba56c159a391ba7a
965
966
967 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
968
969
970 [!] Data (MD5): 8972171c5937545e5a366da418417fcb
971
972
973 [>] User-Agent String : Googlebot-Image/1.0
974
975
976 [!] Data (MD5): 2d4cf0f26ed8f5645434cf7118d5a47b
977
978
979 [>] User-Agent String : Mediapartners-Google
980
981
982 [!] Data (MD5): fcbab140a76ee76a26a181eb34210841
983
984
985 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
986
987
988 [!] Data (MD5): 15e519c8b2133f585ba57026c3fca859
989
990
991 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
992
993
994 [!] Data (MD5): aa818df1e9a10986c8371293c39a357e
995
996
997 [>] User-Agent String : mmcrawler
998
999
1000 [!] Data (MD5): 9ed475fb5200a5326d58a897897673f0
1001
1002
1003 [>] Checks completed... try enabling VERBOSE mode for more detailed output
1004
1005 [>] That's all folks... Fo' Shizzle!
1006
1007
1008
1009
1010 Enter your target IP : 178.218.222.218
1011
1012 obtention site Joomla ...
1013
1014
1015
1016
1017 obtention site Wordpress ...
1018
1019https://0.r.bat.bing.com
1020https://1871817.r.bat.bing.com
1021https://37001174.r.bat.bing.com
1022[i] Scanning Site: http://youngteenies.net
1023
1024
1025
1026B A S I C I N F O
1027====================
1028
1029
1030[+] Site Title: Young Teenies
1031[+] IP address: 67.23.100.162
1032[+] Web Server: Apache
1033[+] CMS: Could Not Detect
1034[+] Cloudflare: Not Detected
1035[+] Robots File: Could NOT Find robots.txt!
1036
1037
1038
1039
1040W H O I S L O O K U P
1041========================
1042
1043 Domain Name: YOUNGTEENIES.NET
1044 Registry Domain ID: 148289229_DOMAIN_NET-VRSN
1045 Registrar WHOIS Server: whois.godaddy.com
1046 Registrar URL: http://www.godaddy.com
1047 Updated Date: 2016-03-31T17:31:21Z
1048 Creation Date: 2005-03-28T06:39:14Z
1049 Registry Expiry Date: 2018-03-28T05:39:14Z
1050 Registrar: GoDaddy.com, LLC
1051 Registrar IANA ID: 146
1052 Registrar Abuse Contact Email: abuse@godaddy.com
1053 Registrar Abuse Contact Phone: 480-624-2505
1054 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
1055 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
1056 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1057 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
1058 Name Server: NS1.M3XS.NET
1059 Name Server: NS2.M3XS.NET
1060 Name Server: NS3.M3XS.NET
1061 Name Server: NS4.M3XS.NET
1062 DNSSEC: unsigned
1063
1064G E O I P L O O K U P
1065=========================
1066
1067[i] IP Address: 67.23.100.162
1068[i] Country: US
1069[i] State: Virginia
1070[i] City: Reston
1071[i] Latitude: 38.931099
1072[i] Longitude: -77.348900
1073
1074
1075
1076
1077H T T P H E A D E R S
1078=======================
1079
1080
1081[i] HTTP/1.1 200 OK
1082[i] Date: Mon, 28 Aug 2017 15:23:19 GMT
1083[i] Server: Apache
1084[i] Accept-Ranges: bytes
1085[i] Connection: close
1086[i] Content-Type: text/html
1087
1088
1089
1090
1091D N S L O O K U P
1092===================
1093
1094youngteenies.net. 3594 IN A 67.23.100.162
1095youngteenies.net. 3600 IN NS ns2.m3xs.net.
1096youngteenies.net. 3600 IN NS ns1.m3xs.net.
1097youngteenies.net. 3600 IN NS ns3.m3xs.net.
1098youngteenies.net. 3600 IN NS ns4.m3xs.net.
1099youngteenies.net. 3600 IN SOA ns1.m3xs.net. dns.m3xs.net. 2013121001 3600 1800 1209600 3600
1100youngteenies.net. 3600 IN MX 30 v3423.m3xs.net.
1101
1102
1103
1104
1105S U B N E T C A L C U L A T I O N
1106====================================
1107
1108Address = 67.23.100.162
1109Network = 67.23.100.162 / 32
1110Netmask = 255.255.255.255
1111Broadcast = not needed on Point-to-Point links
1112Wildcard Mask = 0.0.0.0
1113Hosts Bits = 0
1114Max. Hosts = 1 (2^0 - 0)
1115Host Range = { 67.23.100.162 - 67.23.100.162 }
1116
1117
1118
1119N M A P P O R T S C A N
1120============================
1121
1122
1123Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 15:23 UTC
1124Nmap scan report for youngteenies.net (67.23.100.162)
1125Host is up (0.0031s latency).
1126rDNS record for 67.23.100.162: v3423.m3xs.net
1127PORT STATE SERVICE VERSION
112821/tcp open ftp Pure-FTPd
112922/tcp open ssh OpenSSH 5.3 (protocol 2.0)
113023/tcp filtered telnet
113125/tcp open smtp Sendmail 8.14.4/8.13.8
113280/tcp open http Apache httpd (PHP 5.6.31)
1133110/tcp open pop3 Dovecot pop3d
1134143/tcp open imap Dovecot imapd
1135443/tcp open ssl/http Apache httpd (PHP 5.6.31)
1136445/tcp filtered microsoft-ds
11373389/tcp filtered ms-wbt-server
1138Service Info: OS: Unix
1139
1140
1141
1142S U B - D O M A I N F I N D E R
1143==================================
1144
1145
1146[i] Total Subdomains Found : 2
1147
1148[+] Subdomain: youngteenies.net
1149[-] IP: 67.23.100.162
1150
1151[+] Subdomain: v3423.youngteenies.net
1152[-] IP: 67.23.100.162
1153
1154
1155
1156---------------------------------------------------------------------------
1157+ Target IP: 67.23.100.162
1158+ Target Hostname: YOUNGTEENIES.NET
1159+ Target Port: 80
1160+ Start Time: 2017-08-28 12:35:22 (GMT-4)
1161---------------------------------------------------------------------------
1162+ Server: Apache
1163+ The anti-clickjacking X-Frame-Options header is not present.
1164+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
1165+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
1166+ ERROR: Error limit (20) reached for host, giving up. Last error:
1167+ Scan terminated: 0 error(s) and 3 item(s) reported on remote host
1168+ End Time: 2017-08-28 12:36:14 (GMT-4) (52 seconds)
1169---------------------------------------------------------------------------
1170#################################################################################
1171- Hostname www.teen-home-tube.com ISP Quasi Networks LTD. (AS29073)
1172Continent Africa Flag
1173SC
1174Country Seychelles Country Code SC (SYC)
1175Region Unknown Local time 28 Aug 2017 21:09 +04
1176City Unknown Latitude -4.583
1177IP Address 80.82.77.146 Longitude 55.667
1178#################################################################################
1179teen-home-tube.com
1180
1181
1182 Domain Name: TEEN-HOME-TUBE.COM
1183 Registry Domain ID: 2128898120_DOMAIN_COM-VRSN
1184 Registrar WHOIS Server: whois.PublicDomainRegistry.com
1185 Registrar URL: http://www.publicdomainregistry.com
1186 Updated Date: 2017-05-29T13:30:40Z
1187 Creation Date: 2017-05-29T13:29:27Z
1188 Registry Expiry Date: 2018-05-29T13:29:27Z
1189 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
1190 Registrar IANA ID: 303
1191 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
1192 Registrar Abuse Contact Phone: +1.2013775952
1193 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1194 Name Server: NS1.MYGIRLSSEX.COM
1195 Name Server: NS2.MYGIRLSSEX.COM
1196
1197Domain Name: TEEN-HOME-TUBE.COM
1198Registry Domain ID: 2128898120_DOMAIN_COM-VRSN
1199Registrar WHOIS Server: whois.publicdomainregistry.com
1200Registrar URL: www.publicdomainregistry.com
1201Updated Date: 2017-07-29T02:17:27Z
1202Creation Date: 2017-05-29T13:29:27Z
1203Registrar Registration Expiration Date: 2018-05-29T13:29:27Z
1204Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
1205Registrar IANA ID: 303
1206Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1207Registry Registrant ID: Not Available From Registry
1208Registrant Name: dmitry
1209Registrant Organization:
1210Registrant Street: ketcherskaya
1211Registrant City: moscow
1212Registrant State/Province: Moscow
1213Registrant Postal Code: 117422
1214Registrant Country: RU
1215Registrant Phone: +7.9281262378
1216Registrant Phone Ext:
1217Registrant Fax:
1218Registrant Fax Ext:
1219Registrant Email: carterserv@safe-mail.net
1220Registry Admin ID: Not Available From Registry
1221Admin Name: dmitry
1222Admin Organization:
1223Admin Street: ketcherskaya
1224Admin City: moscow
1225Admin State/Province: Moscow
1226Admin Postal Code: 117422
1227Admin Country: RU
1228Admin Phone: +7.9281262378
1229Admin Phone Ext:
1230Admin Fax:
1231Admin Fax Ext:
1232Admin Email: carterserv@safe-mail.net
1233Registry Tech ID: Not Available From Registry
1234Tech Name: dmitry
1235Tech Organization:
1236Tech Street: ketcherskaya
1237Tech City: moscow
1238Tech State/Province: Moscow
1239Tech Postal Code: 117422
1240Tech Country: RU
1241Tech Phone: +7.9281262378
1242Tech Phone Ext:
1243Tech Fax:
1244Tech Fax Ext:
1245Tech Email: carterserv@safe-mail.net
1246Name Server: ns1.mygirlssex.com
1247Name Server: ns2.mygirlssex.com
1248
1249
1250
1251;; OPT PSEUDOSECTION:
1252; EDNS: version: 0, flags:; udp: 4096
1253;; QUESTION SECTION:
1254;teen-home-tube.com. IN ANY
1255
1256;; ANSWER SECTION:
1257teen-home-tube.com. 14364 IN A 80.82.77.146
1258teen-home-tube.com. 14364 IN NS ns1.mygirlssex.com.
1259teen-home-tube.com. 14364 IN NS ns2.mygirlssex.com.
1260
1261;; Query time: 8 msec
1262;; SERVER: 192.168.1.254#53(192.168.1.254)
1263;; WHEN: Mon Aug 28 12:38:15 EDT 2017
1264;; MSG SIZE rcvd: 110
1265
1266Running:
1267 traceroute -T -O info -i eth0 teen-home-tube.com
1268traceroute to teen-home-tube.com (80.82.77.146), 30 hops max, 60 byte packets
1269 1 gateway (192.168.1.254) 0.411 ms 0.587 ms 0.824 ms
1270 2 10.135.18.1 (10.135.18.1) 8.007 ms 9.392 ms 16.439 ms
1271 3 75.154.223.222 (75.154.223.222) 29.467 ms 29.625 ms 29.763 ms
1272 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.363 ms 30.563 ms 30.795 ms
1273 5 ae-239-3615.edge6.Amsterdam1.Level3.net (4.69.162.250) 104.694 ms 104.764 ms 104.831 ms
1274 6 * * *
1275 7 * * *
1276 8 80.82.77.146 (80.82.77.146) <syn,ack> 103.419 ms 103.327 ms 103.819 ms
1277
1278
1279
1280Host's addresses:
1281__________________
1282
1283teen-home-tube.com. 14295 IN A 80.82.77.146
1284
1285
1286Name Servers:
1287______________
1288
1289ns2.mygirlssex.com. 14400 IN A 80.82.77.146
1290ns1.mygirlssex.com. 14400 IN A 80.82.77.146
1291
1292
1293Mail (MX) Servers:
1294___________________
1295
1296mail.teen-home-tube.com. 14400 IN A 80.82.77.146
1297
1298
1299Brute forcing with dns.txt:
1300____________________________
1301
1302ftp.teen-home-tube.com. 14400 IN A 80.82.77.146
1303mail.teen-home-tube.com. 14381 IN A 80.82.77.146
1304pop.teen-home-tube.com. 14400 IN A 80.82.77.146
1305www.teen-home-tube.com. 14262 IN A 80.82.77.146
1306
1307______________________________________
1308
1309 80.82.77.0/24
1310
1311
1312Performing reverse lookup on 256 ip addresses:
1313_______________________________________________
1314
1315
13160 results out of 256 IP addresses.
1317
1318
1319teen-home-tube.com ip blocks:
1320______________________________
1321
1322
1323ftp.teen-home-tube.com
1324IP address #1: 80.82.77.146
1325
1326mail.teen-home-tube.com
1327IP address #1: 80.82.77.146
1328
1329pop.teen-home-tube.com
1330IP address #1: 80.82.77.146
1331
1332www.teen-home-tube.com
1333IP address #1: 80.82.77.146
1334
1335[+] 4 (sub)domains and 4 IP address(es) found
1336[+] completion time: 147 second(s)
1337
1338
1339Tracing to teen-home-tube.com[a] via 192.168.1.254, maximum of 3 retries
1340192.168.1.254 (192.168.1.254) Got answer
1341
1342
1343WhatWeb report for http://teen-home-tube.com
1344Status : 301 Moved Permanently
1345Title : 301 Moved Permanently
1346IP : 80.82.77.146
1347Country : NETHERLANDS, NL
1348
1349Summary : nginx, RedirectLocation[http://www.teen-home-tube.com/], HTTPServer[nginx]
1350
1351Detected Plugins:
1352[ HTTPServer ]
1353 HTTP server header string. This plugin also attempts to
1354 identify the operating system from the server header.
1355
1356 String : nginx (from server string)
1357
1358[ RedirectLocation ]
1359 HTTP Server string location. used with http-status 301 and
1360 302
1361
1362 String : http://www.teen-home-tube.com/ (from location)
1363
1364[ nginx ]
1365 Nginx (Engine-X) is a free, open-source, high-performance
1366 HTTP server and reverse proxy, as well as an IMAP/POP3
1367 proxy server.
1368
1369 Website : http://nginx.net/
1370
1371HTTP Headers:
1372 HTTP/1.1 301 Moved Permanently
1373 Server: nginx
1374 Date: Mon, 28 Aug 2017 16:42:55 GMT
1375 Content-Type: text/html; charset=iso-8859-1
1376 Content-Length: 322
1377 Connection: close
1378 Location: http://www.teen-home-tube.com/
1379
1380WhatWeb report for http://www.teen-home-tube.com/
1381Status : 200 OK
1382Title : Home teen porn tube videos naked teen girls.
1383IP : 80.82.77.146
1384Country : NETHERLANDS, NL
1385
1386Summary : HTML5, nginx, Script[text/Javascript,text/javascript], PHP[5.4.45], X-Powered-By[PHP/5.4.45], HTTPServer[nginx]
1387
1388Detected Plugins:
1389[ HTML5 ]
1390 HTML version 5, detected by the doctype declaration
1391
1392
1393[ HTTPServer ]
1394 HTTP server header string. This plugin also attempts to
1395 identify the operating system from the server header.
1396
1397 String : nginx (from server string)
1398
1399[ PHP ]
1400 PHP is a widely-used general-purpose scripting language
1401 that is especially suited for Web development and can be
1402 embedded into HTML. This plugin identifies PHP errors,
1403 modules and versions and extracts the local file path and
1404 username if present.
1405
1406 Version : 5.4.45
1407 Google Dorks: (2)
1408 Website : http://www.php.net/
1409
1410[ Script ]
1411 This plugin detects instances of script HTML elements and
1412 returns the script language/type.
1413
1414 String : text/Javascript,text/javascript
1415
1416[ X-Powered-By ]
1417 X-Powered-By HTTP header
1418
1419 String : PHP/5.4.45 (from x-powered-by string)
1420
1421[ nginx ]
1422 Nginx (Engine-X) is a free, open-source, high-performance
1423 HTTP server and reverse proxy, as well as an IMAP/POP3
1424 proxy server.
1425
1426 Website : http://nginx.net/
1427
1428HTTP Headers:
1429 HTTP/1.1 200 OK
1430 Server: nginx
1431 Date: Mon, 28 Aug 2017 16:42:55 GMT
1432 Content-Type: text/html; charset=UTF-8
1433 Transfer-Encoding: chunked
1434 Connection: close
1435 X-Powered-By: PHP/5.4.45
1436 Content-Encoding: gzip
1437
1438
1439
1440
1441*******************************************************************
1442* *
1443* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
1444* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
1445* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
1446* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
1447* *
1448* TheHarvester Ver. 2.7 *
1449* Coded by Christian Martorella *
1450* Edge-Security Research *
1451* cmartorella@edge-security.com *
1452*******************************************************************
1453
1454
1455[-] Searching in Google:
1456 Searching 0 results...
1457 Searching 100 results...
1458 Searching 200 results...
1459 Searching 300 results...
1460 Searching 400 results...
1461 Searching 500 results...
1462
1463
1464[+] Emails found:
1465------------------
1466No emails found
1467
1468[+] Hosts found in search engines:
1469------------------------------------
1470[-] Resolving hostnames IPs...
147180.82.77.146:www.teen-home-tube.com
1472
1473
1474
1475 ^ ^
1476 _ __ _ ____ _ __ _ _ ____
1477 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
1478 | V V // o // _/ | V V // 0 // 0 // _/
1479 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
1480 <
1481 ...'
1482
1483 WAFW00F - Web Application Firewall Detection Tool
1484
1485 By Sandro Gauci && Wendel G. Henrique
1486
1487Checking http://teen-home-tube.com
1488Generic Detection results:
1489No WAF detected by the generic detection
1490Number of requests: 13
1491
1492
1493DNS Servers for teen-home-tube.com:
1494 ns2.mygirlssex.com
1495 ns1.mygirlssex.com
1496
1497Trying zone transfer first...
1498 Testing ns2.mygirlssex.com
1499 Request timed out or transfer not allowed.
1500 Testing ns1.mygirlssex.com
1501 Request timed out or transfer not allowed.
1502
1503Unsuccessful in zone transfer (it was worth a shot)
1504Okay, trying the good old fashioned way... brute force
1505
1506Checking for wildcard DNS...
1507Nope. Good.
1508Now performing 2280 test(s)...
150980.82.77.146 ftp.teen-home-tube.com
151080.82.77.146 mail.teen-home-tube.com
151180.82.77.146 pop.teen-home-tube.com
151280.82.77.146 www.teen-home-tube.com
1513
1514
1515 5.79.70.7
1516Checking for HTTP-Loadbalancing [Date]: 16:48:08, 16:48:08, 16:48:08, 16:48:08, 16:48:09, 16:48:09, 16:48:09, 16:48:10, 16:48:10, 16:48:10, 16:48:10, 16:48:11, 16:48:11, 16:48:11, 16:48:11, 16:48:12, 16:48:12, 16:48:12, 16:48:12, 16:48:13, 16:48:13, 16:48:13, 16:48:14, 16:48:14, 16:48:14, 16:48:14, 16:48:15, 16:48:15, 16:48:15, 16:48:15, 16:48:16, 16:48:16, 16:48:16, 16:48:16, 16:48:17, 16:48:17, 16:48:17, 16:48:18, 16:48:18, 16:48:18, 16:48:18, 16:48:19, 16:48:19, 16:48:19, 16:48:19, 16:48:20, 16:48:20, 16:48:20, 16:48:20, 16:48:21, NOT FOUND
1517
1518Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
1519
1520teen-home-tube.com does NOT use Load-balancing.
1521
1522
1523
1524Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
1525
1526 ----------------------------------------------------------
1527| Scan Information |
1528 ----------------------------------------------------------
1529
1530Mode ..................... VRFY
1531Worker Processes ......... 5
1532Usernames file ........... users.txt
1533Target count ............. 1
1534Username count ........... 494
1535Target TCP port .......... 25
1536Query timeout ............ 5 secs
1537Target domain ............
1538
1539Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 12:56 EDT
1540NSE: Loaded 146 scripts for scanning.
1541NSE: Script Pre-scanning.
1542Initiating NSE at 12:56
1543Completed NSE at 12:56, 0.00s elapsed
1544Initiating NSE at 12:56
1545Completed NSE at 12:56, 0.00s elapsed
1546Failed to resolve "teen-home-tube.com.txt".
1547Initiating Parallel DNS resolution of 1 host. at 12:56
1548Completed Parallel DNS resolution of 1 host. at 12:56, 0.45s elapsed
1549Initiating SYN Stealth Scan at 12:56
1550Scanning teen-home-tube.com (80.82.77.146) [100 ports]
1551Discovered open port 80/tcp on 80.82.77.146
1552Discovered open port 53/tcp on 80.82.77.146
1553Discovered open port 8080/tcp on 80.82.77.146
1554Discovered open port 21/tcp on 80.82.77.146
1555Completed SYN Stealth Scan at 12:56, 2.97s elapsed (100 total ports)
1556Initiating Service scan at 12:56
1557Scanning 4 services on teen-home-tube.com (80.82.77.146)
1558Completed Service scan at 12:56, 6.36s elapsed (4 services on 1 host)
1559Initiating OS detection (try #1) against teen-home-tube.com (80.82.77.146)
1560Retrying OS detection (try #2) against teen-home-tube.com (80.82.77.146)
1561Initiating Traceroute at 12:57
1562Completed Traceroute at 12:57, 3.13s elapsed
1563Initiating Parallel DNS resolution of 7 hosts. at 12:57
1564Completed Parallel DNS resolution of 7 hosts. at 12:57, 5.64s elapsed
1565NSE: Script scanning 80.82.77.146.
1566Initiating NSE at 12:57
1567Completed NSE at 12:57, 8.89s elapsed
1568Initiating NSE at 12:57
1569Completed NSE at 12:57, 0.00s elapsed
1570Nmap scan report for teen-home-tube.com (80.82.77.146)
1571Host is up (0.13s latency).
1572Not shown: 94 filtered ports
1573PORT STATE SERVICE VERSION
157421/tcp open ftp vsftpd 2.2.2
157553/tcp open domain ISC BIND get lost
1576| dns-nsid:
1577|_ bind.version: get lost
157880/tcp open http nginx
1579|_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E
1580| http-methods:
1581|_ Supported Methods: GET HEAD POST OPTIONS
1582|_http-server-header: nginx
1583|_http-title: Did not follow redirect to http://www.teen-home-tube.com/
158481/tcp closed hosts2-ns
1585443/tcp closed https
15868080/tcp open http Apache httpd 2.2.15 ((CentOS))
1587| http-methods:
1588|_ Supported Methods: GET HEAD POST OPTIONS
1589|_http-open-proxy: Proxy might be redirecting requests
1590|_http-server-header: Apache/2.2.15 (CentOS)
1591|_http-title: Did not follow redirect to http://www.teen-home-tube.com/
1592Aggressive OS guesses: Linux 2.6.32 (90%), Linux 2.6.32 or 3.10 (90%), Linux 2.6.39 (90%), IPCop 2 firewall (Linux 3.4) (90%), Linux 3.2 (90%), Linux 3.2 - 3.8 (90%), Linux 3.4 (90%), Linux 3.6 (90%), Linux 3.8 (90%), Synology DiskStation Manager 5.1 (90%)
1593No exact OS matches for host (test conditions non-ideal).
1594Network Distance: 12 hops
1595Service Info: OS: Unix
1596
1597TRACEROUTE (using port 443/tcp)
1598HOP RTT ADDRESS
15991 110.21 ms 10.13.0.1
16002 ...
16013 110.24 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
16024 ...
16035 119.04 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
16046 119.54 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
16057 ...
16068 124.56 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
16079 120.33 ms 176.10.83.119
160810 ... 11
160912 215.30 ms 80.82.77.146
1610
1611NSE: Script Post-scanning.
1612Initiating NSE at 12:57
1613Completed NSE at 12:57, 0.00s elapsed
1614Initiating NSE at 12:57
1615Completed NSE at 12:57, 0.00s elapsed
1616Read data files from: /usr/bin/../share/nmap
1617OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1618Nmap done: 1 IP address (1 host up) scanned in 34.18 seconds
1619 Raw packets sent: 353 (20.344KB) | Rcvd: 35 (2.584KB)
1620
1621
1622Error: can not open nmap file: teen-home-tube.com.txt
1623
1624-
1625
1626
1627
1628
1629 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
1630 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
1631 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
1632 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
1633 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
1634
1635 _/ User-Agent Tester ↵
1636 _/ AKA: Purple Pimp ↵
1637 _/ ChrisJohnRiley ↵
1638 _/ blog.c22.cc ↵
1639
1640 [>] Performing initial request and confirming stability
1641 [>] Using User-Agent string Mozilla/5.0
1642
1643 [ ] URL (ENTERED): http://teen-home-tube.com
1644 [!] URL (FINAL): http://www.teen-home-tube.com/
1645 [!] Response Code: 301 Moved Permanently
1646 [ ] Server: nginx
1647 [ ] Date: Mon, 28 Aug 2017 16:57:33 GMT
1648 [ ] Content-Type: text/html; charset=UTF-8
1649 [ ] Transfer-Encoding: chunked
1650 [ ] Connection: close
1651 [ ] X-Powered-By: PHP/5.4.45
1652 [ ] Data (MD5): 0e17abdfbd992a5b49819e4d8fb27b21
1653
1654 [1] Pass
1655 [2] Pass
1656 [3] Pass
1657
1658
1659 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
1660
1661
1662 [!] Data (MD5): f5d36908db23e640f9ac209480f75cc8
1663
1664
1665 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
1666
1667
1668 [!] Data (MD5): 1d4f2e75967258b3858734eb3a7b822d
1669
1670
1671 [>] User-Agent String : TrackBack/1.02
1672
1673
1674 [!] Data (MD5): 0e634a327a14af7bd218c11ba2396e18
1675
1676
1677 [>] User-Agent String : wispr
1678
1679
1680 [!] Data (MD5): 71a685ec2465c1d5fb15d10cadf0faf5
1681
1682
1683 [>] User-Agent String : EMPTY USER-AGENT STRING!
1684
1685
1686 [!] Data (MD5): 2930fe5b9610db3295112550679335e4
1687
1688
1689 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
1690
1691
1692 [!] Data (MD5): 03d52fc2205d03c62e78582fdf738ed4
1693
1694
1695 [>] User-Agent String : Googlebot-Image/1.0
1696
1697
1698 [!] Data (MD5): 9c535fb24a8ef4d078f915259016bed3
1699
1700
1701 [>] User-Agent String : Mediapartners-Google
1702
1703
1704 [!] Data (MD5): 83a5af2dfdad3c973add733b87be4e34
1705
1706
1707 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
1708
1709
1710 [!] Data (MD5): e405f2476ffab74b2f4b2b91a6f35cf2
1711
1712
1713 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
1714
1715
1716 [!] Data (MD5): 7d4e5696a96c646cdb86f613d515d76c
1717
1718
1719 [>] User-Agent String : mmcrawler
1720
1721
1722 [!] Data (MD5): 2ecbaa40cd1425027dab24cb02ed1b5b
1723
1724
1725 [>] Checks completed... try enabling VERBOSE mode for more detailed output
1726
1727 [>] That's all folks... Fo' Shizzle!
1728[i] Scanning Site: http://teen-home-tube.com
1729
1730
1731
1732B A S I C I N F O
1733====================
1734
1735
1736[+] Site Title: Home teen porn tube videos naked teen girls.
1737[+] IP address: 80.82.77.146
1738[+] Web Server: nginx
1739[+] CMS: Could Not Detect
1740[+] Cloudflare: Not Detected
1741[+] Robots File: Found
1742
1743-------------[ contents ]----------------
1744# vestacp autogenerated robots.txt
1745User-agent: *
1746Crawl-delay: 10
1747
1748-----------[end of contents]-------------
1749
1750
1751
1752W H O I S L O O K U P
1753========================
1754
1755 Domain Name: TEEN-HOME-TUBE.COM
1756 Registry Domain ID: 2128898120_DOMAIN_COM-VRSN
1757 Registrar WHOIS Server: whois.PublicDomainRegistry.com
1758 Registrar URL: http://www.publicdomainregistry.com
1759 Updated Date: 2017-05-29T13:30:40Z
1760 Creation Date: 2017-05-29T13:29:27Z
1761 Registry Expiry Date: 2018-05-29T13:29:27Z
1762 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
1763 Registrar IANA ID: 303
1764 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
1765 Registrar Abuse Contact Phone: +1.2013775952
1766 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1767 Name Server: NS1.MYGIRLSSEX.COM
1768 Name Server: NS2.MYGIRLSSEX.COM
1769
1770
1771
1772
1773G E O I P L O O K U P
1774=========================
1775
1776[i] IP Address: 80.82.77.146
1777[i] Country: SC
1778[i] State: N/A
1779[i] City: N/A
1780[i] Latitude: -4.583300
1781[i] Longitude: 55.666698
1782
1783
1784
1785
1786H T T P H E A D E R S
1787=======================
1788
1789
1790[i] HTTP/1.1 301 Moved Permanently
1791[i] Server: nginx
1792[i] Date: Mon, 28 Aug 2017 16:38:07 GMT
1793[i] Content-Type: text/html; charset=iso-8859-1
1794[i] Content-Length: 322
1795[i] Connection: close
1796[i] Location: http://www.teen-home-tube.com/
1797[i] HTTP/1.1 200 OK
1798[i] Server: nginx
1799[i] Date: Mon, 28 Aug 2017 16:38:07 GMT
1800[i] Content-Type: text/html; charset=UTF-8
1801[i] Connection: close
1802[i] X-Powered-By: PHP/5.4.45
1803
1804
1805
1806
1807D N S L O O K U P
1808===================
1809
1810teen-home-tube.com. 14394 IN A 80.82.77.146
1811teen-home-tube.com. 14399 IN NS ns1.mygirlssex.com.
1812teen-home-tube.com. 14399 IN NS ns2.mygirlssex.com.
1813teen-home-tube.com. 14399 IN SOA ns1.mygirlssex.com. root.teen-home-tube.com. 2017052901 7200 3600 1209600 180
1814teen-home-tube.com. 14399 IN MX 10 mail.teen-home-tube.com.
1815teen-home-tube.com. 14399 IN TXT "v=spf1 a mx ip4:80.82.77.146 ?all"
1816
1817
1818
1819
1820S U B N E T C A L C U L A T I O N
1821====================================
1822
1823Address = 80.82.77.146
1824Network = 80.82.77.146 / 32
1825Netmask = 255.255.255.255
1826Broadcast = not needed on Point-to-Point links
1827Wildcard Mask = 0.0.0.0
1828Hosts Bits = 0
1829Max. Hosts = 1 (2^0 - 0)
1830Host Range = { 80.82.77.146 - 80.82.77.146 }
1831
1832
1833
1834N M A P P O R T S C A N
1835============================
1836
1837
1838Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 16:38 UTC
1839Nmap scan report for teen-home-tube.com (80.82.77.146)
1840Host is up (0.082s latency).
1841PORT STATE SERVICE VERSION
184221/tcp open ftp vsftpd 2.2.2
184322/tcp filtered ssh
184423/tcp filtered telnet
184525/tcp open smtp Exim smtpd 4.89
184680/tcp open http nginx
1847110/tcp filtered pop3
1848143/tcp filtered imap
1849443/tcp closed https
1850445/tcp filtered microsoft-ds
18513389/tcp filtered ms-wbt-server
1852
1853
1854S U B - D O M A I N F I N D E R
1855==================================
1856
1857
1858[i] Total Subdomains Found : 1
1859
1860[+] Subdomain: teen-home-tube.com
1861[-] IP: 80.82.77.146
1862
1863
1864
1865
1866
1867R E V E R S E I P L O O K U P
1868==================================
1869
1870
1871[i] Total Sites Found On This Server : 4
1872
1873
1874[#] babegirlsex.com,1,crazynudeteens.com
1875[-] CMS: Could Not Detect
1876
1877[#] teen-home-tube.com
1878[-] CMS: Could Not Detect
1879
1880[#] www.girlspornvids.com,1,www.sexpornteenage.com,1,www.teenamatureporn.com,1,www.teencutiespics.com
1881[-] CMS: Could Not Detect
1882
1883[#] www.teensexvidoe.com,1,www.xxlpornoteen.com,1
1884[-] CMS: Could Not Detect
1885
1886
1887
1888---------------------------------------------------------------------------
1889+ Target IP: 80.82.77.146
1890+ Target Hostname: teen-home-tube.com
1891+ Target Port: 80
1892+ Start Time: 2017-08-28 14:02:44 (GMT-4)
1893---------------------------------------------------------------------------
1894+ Server: nginx
1895+ The anti-clickjacking X-Frame-Options header is not present.
1896+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
1897+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
1898+ ERROR: Error limit (20) reached for host, giving up. Last error:
1899+ Scan terminated: 9 error(s) and 3 item(s) reported on remote host
1900+ End Time: 2017-08-28 14:16:58 (GMT-4) (854 seconds)
1901---------------------------------------------------------------------------
1902+ 1 host(s) tested
1903###################################################################################
1904Hostname dirtyteenpics.com ISP LeaseWeb Netherlands B.V. (AS60781)
1905Continent Europe Flag
1906NL
1907Country Netherlands Country Code NL (NLD)
1908Region Unknown Local time 28 Aug 2017 21:39 CEST
1909City Unknown Latitude 52.382
1910IP Address 95.211.210.42 Longitude 4.899
1911#######################################################################################
1912dirtyteenpics.com
1913
1914
1915 Domain Name: DIRTYTEENPICS.COM
1916 Registry Domain ID: 2066597385_DOMAIN_COM-VRSN
1917 Registrar WHOIS Server: whois.name.com
1918 Registrar URL: http://www.name.com
1919 Updated Date: 2016-10-16T16:47:03Z
1920 Creation Date: 2016-10-16T12:14:33Z
1921 Registry Expiry Date: 2017-10-16T12:14:33Z
1922 Registrar: Name.com, Inc.
1923 Registrar IANA ID: 625
1924 Registrar Abuse Contact Email: abuse@name.com
1925 Registrar Abuse Contact Phone: 7202492374
1926 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1927 Name Server: NS1.BESTMATURESTORE.COM
1928 Name Server: NS2.BESTMATURESTORE.COM
1929
1930Domain Name: DIRTYTEENPICS.COM
1931Registry Domain ID: 2066597385_DOMAIN_COM-VRSN
1932Registrar WHOIS Server: whois.name.com
1933Registrar URL: http://www.name.com
1934Updated Date: 2016-10-16T16:47:03Z
1935Creation Date: 2016-10-16T12:14:33Z
1936Registrar Registration Expiration Date: 2017-10-16T12:14:33Z
1937Registrar: Name.com, Inc.
1938Registrar IANA ID: 625
1939Reseller:
1940Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
1941Registry Registrant ID: Not Available From Registry
1942Registrant Name: Whois Agent
1943Registrant Organization: Domain Protection Services, Inc.
1944Registrant Street: PO Box 1769
1945Registrant City: Denver
1946Registrant State/Province: CO
1947Registrant Postal Code: 80201
1948Registrant Country: US
1949Registrant Phone: +1.7208009072
1950Registrant Fax: +1.7209758725
1951Registrant Email: dirtyteenpics.com@protecteddomainservices.com
1952Registry Admin ID: Not Available From Registry
1953Admin Name: Whois Agent
1954Admin Organization: Domain Protection Services, Inc.
1955Admin Street: PO Box 1769
1956Admin City: Denver
1957Admin State/Province: CO
1958Admin Postal Code: 80201
1959Admin Country: US
1960Admin Phone: +1.7208009072
1961Admin Fax: +1.7209758725
1962Admin Email: dirtyteenpics.com@protecteddomainservices.com
1963Registry Tech ID: Not Available From Registry
1964Tech Name: Whois Agent
1965Tech Organization: Domain Protection Services, Inc.
1966Tech Street: PO Box 1769
1967Tech City: Denver
1968Tech State/Province: CO
1969Tech Postal Code: 80201
1970Tech Country: US
1971Tech Phone: +1.7208009072
1972Tech Fax: +1.7209758725
1973Tech Email: dirtyteenpics.com@protecteddomainservices.com
1974Name Server: ns1.bestmaturestore.com
1975Name Server: ns2.bestmaturestore.com
1976DNSSEC: unSigned
1977Registrar Abuse Contact Email: abuse@name.com
1978Registrar Abuse Contact Phone: +1.7203101849
1979URL of the ICANN WHOIS Data Problem Reporting System: http://
1980
1981;dirtyteenpics.com. IN ANY
1982
1983;; ANSWER SECTION:
1984dirtyteenpics.com. 10800 IN MX 10 mx1.dirtyteenpics.com.
1985dirtyteenpics.com. 10800 IN SOA ns1.bestmaturestore.com. root.bestmaturestore.com. 2016101612 10800 3600 604800 3600
1986dirtyteenpics.com. 10800 IN A 95.211.210.42
1987dirtyteenpics.com. 10800 IN NS ns2.bestmaturestore.com.
1988dirtyteenpics.com. 10800 IN NS ns1.bestmaturestore.com.
1989
1990;; Query time: 127 msec
1991;; SERVER: 192.168.1.254#53(192.168.1.254)
1992;; WHEN: Mon Aug 28 14:02:35 EDT 2017
1993;; MSG SIZE rcvd: 175
1994
1995
1996
1997
1998
1999Running:
2000 traceroute -T -O info -i eth0 dirtyteenpics.com
2001traceroute to dirtyteenpics.com (95.211.210.42), 30 hops max, 60 byte packets
2002 1 gateway (192.168.1.254) 0.509 ms 0.696 ms 0.855 ms
2003 2 10.135.18.1 (10.135.18.1) 6.764 ms 7.158 ms 7.226 ms
2004 3 75.154.223.209 (75.154.223.209) 32.180 ms 32.260 ms 32.468 ms
2005 4 chi-ms1.us.leaseweb.NET (206.223.119.148) 58.509 ms * *
2006 5 * * *
2007 6 * * *
2008 7 * * *
2009 8 95.211.210.42 (95.211.210.42) <syn,ack> 126.030 ms 125.474 ms 125.675 ms
2010
2011
2012----- dirtyteenpics.com -----
2013
2014
2015Host's addresses:
2016__________________
2017
2018dirtyteenpics.com. 10783 IN A 95.211.210.42
2019
2020
2021Name Servers:
2022______________
2023
2024ns1.bestmaturestore.com. 10800 IN A 95.211.210.42
2025ns2.bestmaturestore.com. 10800 IN A 95.211.210.42
2026
2027
2028Mail (MX) Servers:
2029___________________
2030
2031mx1.dirtyteenpics.com. 10800 IN A 95.211.210.42
2032
2033
2034
2035Google Results:
2036________________
2037
2038 perhaps Google is blocking our queries.
2039 Check manually.
2040
2041
2042Brute forcing with dns.txt:
2043____________________________
2044
2045mx1.dirtyteenpics.com. 10767 IN A 95.211.210.42
2046ns1.dirtyteenpics.com. 10800 IN A 95.211.210.42
2047ns2.dirtyteenpics.com. 10800 IN A 95.211.210.42
2048www.dirtyteenpics.com. 10800 IN A 95.211.210.42
2049
2050
2051dirtyteenpics.com class C netranges:
2052_____________________________________
2053
2054 95.211.210.0/24
2055
2056
2057Performing reverse lookup on 256 ip addresses:
2058_______________________________________________
2059
2060
20610 results out of 256 IP addresses.
2062
2063
2064dirtyteenpics.com ip blocks:
2065_____________________________
2066
2067
2068
2069mx1.dirtyteenpics.com
2070IP address #1: 95.211.210.42
2071
2072ns1.dirtyteenpics.com
2073IP address #1: 95.211.210.42
2074
2075ns2.dirtyteenpics.com
2076IP address #1: 95.211.210.42
2077
2078www.dirtyteenpics.com
2079IP address #1: 95.211.210.42
2080
2081WhatWeb report for http://dirtyteenpics.com
2082Status : 200 OK
2083Title : Dirty Teen Pics - Picture Galleries
2084IP : 95.211.210.42
2085Country : NETHERLANDS, NL
2086
2087Summary : nginx[1.6.2], Script[text/javascript], HTTPServer[nginx/1.6.2], Frame
2088
2089Detected Plugins:
2090[ Frame ]
2091 This plugin detects instances of frame and iframe HTML
2092 elements.
2093
2094
2095[ HTTPServer ]
2096 HTTP server header string. This plugin also attempts to
2097 identify the operating system from the server header.
2098
2099 String : nginx/1.6.2 (from server string)
2100
2101[ Script ]
2102 This plugin detects instances of script HTML elements and
2103 returns the script language/type.
2104
2105 String : text/javascript
2106
2107[ nginx ]
2108 Nginx (Engine-X) is a free, open-source, high-performance
2109 HTTP server and reverse proxy, as well as an IMAP/POP3
2110 proxy server.
2111
2112 Version : 1.6.2
2113 Website : http://nginx.net/
2114
2115HTTP Headers:
2116 HTTP/1.1 200 OK
2117 Server: nginx/1.6.2
2118 Date: Mon, 28 Aug 2017 18:13:00 GMT
2119 Content-Type: text/html; charset=UTF-8
2120 Content-Length: 10811
2121 Connection: close
2122 Vary: Accept-Encoding
2123 Content-Encoding: gzip
2124
2125
2126
2127
2128*******************************************************************
2129* *
2130* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
2131* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
2132* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
2133* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
2134* *
2135* TheHarvester Ver. 2.7 *
2136* Coded by Christian Martorella *
2137* Edge-Security Research *
2138* cmartorella@edge-security.com *
2139*******************************************************************
2140
2141
2142[-] Searching in Google:
2143 Searching 0 results...
2144 Searching 100 results...
2145 Searching 200 results...
2146 Searching 300 results...
2147 Searching 400 results...
2148 Searching 500 results...
2149
2150
2151[+] Emails found:
2152------------------
2153No emails found
2154
2155[+] Hosts found in search engines:
2156------------------------------------
2157[-] Resolving hostnames IPs...
215895.211.210.42:www.dirtyteenpics.com
2159
2160
2161
2162 ^ ^
2163 _ __ _ ____ _ __ _ _ ____
2164 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2165 | V V // o // _/ | V V // 0 // 0 // _/
2166 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2167 <
2168 ...'
2169
2170 WAFW00F - Web Application Firewall Detection Tool
2171
2172 By Sandro Gauci && Wendel G. Henrique
2173
2174Checking http://dirtyteenpics.com
2175ERROR:root:Site http://dirtyteenpics.com appears to be down
2176
2177
2178DNS Servers for dirtyteenpics.com:
2179 ns1.bestmaturestore.com
2180 ns2.bestmaturestore.com
2181
2182Trying zone transfer first...
2183 Testing ns1.bestmaturestore.com
2184 Request timed out or transfer not allowed.
2185 Testing ns2.bestmaturestore.com
2186 Request timed out or transfer not allowed.
2187
2188Unsuccessful in zone transfer (it was worth a shot)
2189Okay, trying the good old fashioned way... brute force
2190
2191Checking for wildcard DNS...
2192Nope. Good.
2193Now performing 2280 test(s)...
219495.211.210.42 ns1.dirtyteenpics.com
219595.211.210.42 ns2.dirtyteenpics.com
219695.211.210.42 www.dirtyteenpics.com
2197
2198Subnets found (may want to probe here using nmap or unicornscan):
2199 95.211.210.0-255 : 3 hostnames found.
2200
2201
2202Checking for HTTP-Loadbalancing [Date]: 18:36:34, 18:36:34, 18:36:34, 18:36:34, 18:36:35, 18:36:35, 18:36:35, 18:36:35, 18:36:36, 18:36:36, 18:36:36, 18:36:36, 18:36:37, 18:36:37, 18:36:37, 18:36:38, 18:36:38, 18:36:38, 18:36:38, 18:36:39, 18:36:39, 18:36:39, 18:36:39, 18:36:40, 18:36:40, 18:36:40, 18:36:40, 18:36:41, 18:36:41, 18:36:41, 18:36:42, 18:36:42, 18:36:42, 18:36:42, 18:36:43, 18:36:43, 18:36:43, 18:36:43, 18:36:44, 18:36:44, 18:36:44, 18:36:44, 18:36:45, 18:36:45, 18:36:45, 18:36:45, 18:36:46, 18:36:46, 18:36:46, 18:36:46, NOT FOUND
2203
2204Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2205
2206dirtyteenpics.com does NOT use Load-balancing.
2207
2208
2209
2210Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2211
2212 ----------------------------------------------------------
2213| Scan Information |
2214 ----------------------------------------------------------
2215
2216Mode ..................... VRFY
2217Worker Processes ......... 5
2218Usernames file ........... users.txt
2219Target count ............. 1
2220Username count ........... 494
2221Target TCP port .......... 25
2222Query timeout ............ 5 secs
2223Target domain ............
2224
2225
2226Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 14:46 EDT
2227NSE: Loaded 146 scripts for scanning.
2228NSE: Script Pre-scanning.
2229Initiating NSE at 14:46
2230Completed NSE at 14:46, 0.00s elapsed
2231Initiating NSE at 14:46
2232Completed NSE at 14:46, 0.00s elapsed
2233Failed to resolve "dirtyteenpics.com.txt".
2234Initiating Parallel DNS resolution of 1 host. at 14:46
2235Completed Parallel DNS resolution of 1 host. at 14:46, 0.63s elapsed
2236Initiating SYN Stealth Scan at 14:46
2237Scanning dirtyteenpics.com (95.211.210.42) [100 ports]
2238Discovered open port 21/tcp on 95.211.210.42
2239Discovered open port 53/tcp on 95.211.210.42
2240Discovered open port 80/tcp on 95.211.210.42
2241Discovered open port 111/tcp on 95.211.210.42
2242Discovered open port 22/tcp on 95.211.210.42
2243Completed SYN Stealth Scan at 14:46, 3.65s elapsed (100 total ports)
2244Initiating Service scan at 14:46
2245Scanning 5 services on dirtyteenpics.com (95.211.210.42)
2246Completed Service scan at 14:46, 11.37s elapsed (5 services on 1 host)
2247Initiating OS detection (try #1) against dirtyteenpics.com (95.211.210.42)
2248Retrying OS detection (try #2) against dirtyteenpics.com (95.211.210.42)
2249Initiating Traceroute at 14:46
2250Completed Traceroute at 14:46, 3.00s elapsed
2251Initiating Parallel DNS resolution of 5 hosts. at 14:46
2252Completed Parallel DNS resolution of 5 hosts. at 14:46, 5.61s elapsed
2253NSE: Script scanning 95.211.210.42.
2254Initiating NSE at 14:46
2255Completed NSE at 14:47, 49.06s elapsed
2256Initiating NSE at 14:47
2257Completed NSE at 14:47, 0.46s elapsed
2258Nmap scan report for dirtyteenpics.com (95.211.210.42)
2259Host is up (0.14s latency).
2260Not shown: 89 closed ports
2261PORT STATE SERVICE VERSION
226221/tcp open ftp vsftpd 3.0.2
226322/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u2 (protocol 2.0)
2264| ssh-hostkey:
2265| 1024 9e:06:13:c8:ac:c9:74:b1:b8:c8:0c:a6:6d:e1:8e:7f (DSA)
2266| 2048 bd:aa:d5:69:04:2e:f1:bb:8b:df:6d:5d:41:50:b4:71 (RSA)
2267|_ 256 70:84:aa:f8:3e:01:9a:b7:18:e4:85:c7:33:75:dc:84 (ECDSA)
226825/tcp filtered smtp
226953/tcp open domain
2270| dns-nsid:
2271|_ bind.version: 9.9.5-9+deb8u3-Debian
227280/tcp open http nginx 1.6.2
2273|_http-server-header: nginx/1.6.2
2274|_http-title: Dirty Teen Pics - Picture Galleries
2275111/tcp open rpcbind 2-4 (RPC #100000)
2276| rpcinfo:
2277| program version port/proto service
2278| 100000 2,3,4 111/tcp rpcbind
2279| 100000 2,3,4 111/udp rpcbind
2280| 100024 1 43171/tcp status
2281|_ 100024 1 59632/udp status
2282135/tcp filtered msrpc
2283139/tcp filtered netbios-ssn
2284445/tcp filtered microsoft-ds
2285465/tcp filtered smtps
2286587/tcp filtered submission
2287Aggressive OS guesses: Linux 2.6.39 (95%), Linux 2.6.23 (94%), Linux 2.6.32 (94%), Linux 2.6.32 or 3.10 (94%), Linux 3.2 (94%), Linux 3.2 - 3.8 (94%), Linux 3.4 (94%), Linux 3.8 (94%), Synology DiskStation Manager 5.1 (94%), WatchGuard Fireware 11.8 (94%)
2288No exact OS matches for host (test conditions non-ideal).
2289Network Distance: 9 hops
2290Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
2291
2292TRACEROUTE (using port 1720/tcp)
2293HOP RTT ADDRESS
22941 110.55 ms 10.13.0.1
22952 110.38 ms 37.187.24.252
22963 110.59 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
22974 ...
22985 116.80 ms be100-1112.ams-5-a9.nl.eu (213.251.128.67)
22996 ... 8
23009 115.86 ms 95.211.210.42
2301
2302NSE: Script Post-scanning.
2303Initiating NSE at 14:47
2304Completed NSE at 14:47, 0.00s elapsed
2305Initiating NSE at 14:47
2306Completed NSE at 14:47, 0.00s elapsed
2307Read data files from: /usr/bin/../share/nmap
2308OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2309Nmap done: 1 IP address (1 host up) scanned in 81.08 seconds
2310 Raw packets sent: 309 (16.336KB) | Rcvd: 169 (8.076KB)
2311
2312
2313Error: can not open nmap file: dirtyteenpics.com.txt
2314
2315
2316httprint v0.301 (beta) - web server fingerprinting tool
2317(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
2318http://net-square.com/httprint/
2319httprint@net-square.com
2320
2321
2322
2323 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
2324 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2325 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
2326 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2327 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
2328
2329 _/ User-Agent Tester ↵
2330 _/ AKA: Purple Pimp ↵
2331 _/ ChrisJohnRiley ↵
2332 _/ blog.c22.cc ↵
2333
2334 [>] Performing initial request and confirming stability
2335 [>] Using User-Agent string Mozilla/5.0
2336
2337 [ ] URL (ENTERED): http://dirtyteenpics.com
2338 [ ] Response Code: 200 OK
2339 [ ] Server: nginx/1.6.2
2340 [ ] Date: Mon, 28 Aug 2017 18:46:41 GMT
2341 [ ] Content-Type: text/html; charset=UTF-8
2342 [ ] Transfer-Encoding: chunked
2343 [ ] Connection: close
2344 [ ] Vary: Accept-Encoding
2345 [ ] Data (MD5): 0e6dd7ef34aaf80edc70c15de2a41af0
2346
2347 [1] Pass
2348 [2] Pass
2349 [3] Pass
2350
2351 [>] URL appears stable. Beginning test
2352
2353 [>] Using DEFAULT User-Agent Strings
2354
2355 [>] Using Crazy User-Agent Strings
2356 [>] Using Bot User-Agent Strings
2357
2358 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
2359
2360
2361 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
2362
2363
2364 [!] Data (MD5): a3d76d5ed4007b7f2fc0802b993c1858
2365
2366
2367 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
2368
2369
2370 [!] Data (MD5): 529da3d3ddce890fc3a64d846143687b
2371
2372
2373 [>] User-Agent String : TrackBack/1.02
2374
2375
2376 [!] Data (MD5): 70770fb6e36ad75f01158193d9656d6f
2377
2378
2379 [>] User-Agent String : wispr
2380
2381
2382 [!] Data (MD5): e8f1def8d393aba4500ce9ef29d20086
2383
2384
2385 [>] User-Agent String : EMPTY USER-AGENT STRING!
2386
2387
2388 [!] Data (MD5): 2f597e1a7aa59c57b67b4c0b9b9f374a
2389
2390
2391 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
2392
2393
2394 [!] Data (MD5): 1939902ca96de97a6f7234d302c35649
2395
2396
2397 [>] User-Agent String : Googlebot-Image/1.0
2398
2399
2400 [!] Data (MD5): 5a5fcd94c3c9fdcae856d959edc51e03
2401
2402
2403 [>] User-Agent String : Mediapartners-Google
2404
2405
2406 [!] Data (MD5): b99e7085c61f62f05621298ca6988756
2407
2408
2409 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
2410
2411
2412 [!] Data (MD5): 8a264fcd72da31773d881530af034403
2413
2414
2415 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
2416
2417
2418 [!] Data (MD5): a02ff12dc2b48b574ad51cb0fe02c435
2419
2420
2421 [>] User-Agent String : mmcrawler
2422
2423
2424 [!] Data (MD5): a07918a6b5f0c5d93fb1fd592bb4ee25
2425
2426
2427 [>] Checks completed... try enabling VERBOSE mode for more detailed output
2428
2429 [>] That's all folks... Fo' Shizzle!
2430
2431
2432
2433
2434 Enter your target IP : 80.82.77.146
2435
2436 obtention site Joomla ...
2437
2438
2439
2440
2441
2442B A S I C I N F O
2443====================
2444
2445
2446[+] Site Title: Dirty Teen Pics - Picture Galleries
2447[+] IP address: 95.211.210.42
2448[+] Web Server: nginx/1.6.2
2449[+] CMS: Could Not Detect
2450[+] Cloudflare: Not Detected
2451[+] Robots File: Could NOT Find robots.txt!
2452
2453
2454
2455
2456W H O I S L O O K U P
2457========================
2458
2459 Domain Name: DIRTYTEENPICS.COM
2460 Registry Domain ID: 2066597385_DOMAIN_COM-VRSN
2461 Registrar WHOIS Server: whois.name.com
2462 Registrar URL: http://www.name.com
2463 Updated Date: 2016-10-16T16:47:03Z
2464 Creation Date: 2016-10-16T12:14:33Z
2465 Registry Expiry Date: 2017-10-16T12:14:33Z
2466 Registrar: Name.com, Inc.
2467 Registrar IANA ID: 625
2468 Registrar Abuse Contact Email: abuse@name.com
2469 Registrar Abuse Contact Phone: 7202492374
2470 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2471 Name Server: NS1.BESTMATURESTORE.COM
2472 Name Server: NS2.BESTMATURESTORE.COM
2473 DNSSEC: unsigned
2474 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
2475>
2476
2477
2478G E O I P L O O K U P
2479=========================
2480
2481[i] IP Address: 95.211.210.42
2482[i] Country: NL
2483[i] State: N/A
2484[i] City: N/A
2485[i] Latitude: 52.382401
2486[i] Longitude: 4.899500
2487
2488
2489
2490
2491H T T P H E A D E R S
2492=======================
2493
2494
2495[i] HTTP/1.1 200 OK
2496[i] Server: nginx/1.6.2
2497[i] Date: Mon, 28 Aug 2017 18:09:37 GMT
2498[i] Content-Type: text/html; charset=UTF-8
2499[i] Connection: close
2500[i] Vary: Accept-Encoding
2501
2502
2503
2504
2505D N S L O O K U P
2506===================
2507
2508dirtyteenpics.com. 10695 IN A 95.211.210.42
2509dirtyteenpics.com. 10800 IN NS ns2.bestmaturestore.com.
2510dirtyteenpics.com. 10800 IN NS ns1.bestmaturestore.com.
2511dirtyteenpics.com. 10800 IN SOA ns1.bestmaturestore.com. root.bestmaturestore.com. 2016101612 10800 3600 604800 3600
2512dirtyteenpics.com. 10800 IN MX 10 mx1.dirtyteenpics.com.
2513
2514
2515
2516
2517S U B N E T C A L C U L A T I O N
2518====================================
2519
2520Address = 95.211.210.42
2521Network = 95.211.210.42 / 32
2522Netmask = 255.255.255.255
2523Broadcast = not needed on Point-to-Point links
2524Wildcard Mask = 0.0.0.0
2525Hosts Bits = 0
2526Max. Hosts = 1 (2^0 - 0)
2527Host Range = { 95.211.210.42 - 95.211.210.42 }
2528
2529
2530
2531N M A P P O R T S C A N
2532============================
2533
2534
2535Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 18:11 UTC
2536Nmap scan report for dirtyteenpics.com (95.211.210.42)
2537Host is up (0.048s latency).
2538PORT STATE SERVICE VERSION
253921/tcp open ftp vsftpd 3.0.2
254022/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u2 (protocol 2.0)
254123/tcp closed telnet
254225/tcp closed smtp
254380/tcp open http nginx 1.6.2
2544110/tcp closed pop3
2545143/tcp closed imap
2546443/tcp closed https
2547445/tcp filtered microsoft-ds
25483389/tcp closed ms-wbt-server
2549Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
2550
2551Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2552Nmap done: 1 IP address (1 host up) scanned in 8.75 seconds
2553
2554
2555
2556S U B - D O M A I N F I N D E R
2557==================================
2558
2559
2560[i] Total Subdomains Found : 2
2561
2562[+] Subdomain: dirtyteenpics.com
2563[-] IP: 95.211.210.42
2564
2565[+] Subdomain: mx1.dirtyteenpics.com
2566[-] IP: 95.211.210.42
2567
2568
2569Crawling Types & Descriptions:
2570---------------------------------------------------------------------------
2571+ Target IP: 95.211.210.42
2572+ Target Hostname: dirtyteenpics.com
2573+ Target Port: 80
2574+ Start Time: 2017-08-28 15:46:29 (GMT-4)
2575---------------------------------------------------------------------------
2576+ Server: nginx/1.6.2
2577+ The anti-clickjacking X-Frame-Options header is not present.
2578+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
2579+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
2580+ Uncommon header 'tcn' found, with contents: list
2581+ Apache mod_negotiation is enabled with MultiViews, which allows attackers to easily brute force file names. See http://www.wisec.it/sectou.php?id=4698ebdc59d15. The following alternatives for 'index' were found: index.php
2582+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
2583+ DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
2584+ OSVDB-561: /server-status: This reveals Apache information. Comment out appropriate line in the Apache conf file or restrict access to allowed sources.
2585+ Server leaks inodes via ETags, header found with file /icons/README, fields: 0x13f4 0x438c034968a80
2586+ OSVDB-3233: /icons/README: Apache default file found.
2587+ /server-status: Apache server-status interface found (pass protected)
2588+ 8258 requests: 1 error(s) and 11 item(s) reported on remote host
2589+ End Time: 2017-08-28 16:28:34 (GMT-4) (2525 seconds)
2590
2591################################################################################
2592Hostname lovnymph.com ISP Unknown
2593Continent Unknown Flag
2594US
2595Country United States Country Code US
2596Region Unknown Local time 28 Aug 2017 15:31 CDT
2597City Unknown Latitude 37.751
2598IP Address (IPv6) 2400:cb00:2048:1::681c:7bf Longitude -97.822
2599#################################################################################
2600lovnymph.com
2601ovnymph.com
2602
2603
2604 Domain Name: LOVNYMPH.COM
2605 Registry Domain ID: 1982561072_DOMAIN_COM-VRSN
2606 Registrar WHOIS Server: whois.internet.bs
2607 Registrar URL: http://www.internet.bs
2608 Updated Date: 2017-06-15T20:13:15Z
2609 Creation Date: 2015-11-20T11:10:36Z
2610 Registry Expiry Date: 2017-11-20T11:10:36Z
2611 Registrar: Internet Domain Service BS Corp
2612 Registrar IANA ID: 2487
2613 Registrar Abuse Contact Email:
2614 Registrar Abuse Contact Phone:
2615 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2616 Name Server: NS-CANADA.TOPDNS.COM
2617 Name Server: NS-UK.TOPDNS.COM
2618 Name Server: NS-USA.TOPDNS.COM
2619
2620Domain Name: LOVNYMPH.COM
2621Registry Domain ID: 1982561072_DOMAIN_COM-VRSN
2622Registrar WHOIS Server: whois.internet.bs
2623Registrar URL: http://www.internetbs.net
2624Updated Date: 2017-06-15T20:13:15Z
2625Creation Date: 2015-11-20T11:10:36Z
2626Registrar Registration Expiration Date: 2017-11-20T11:10:36Z
2627Registrar: Internet Domain Service BS Corp.
2628Registrar IANA ID: 2487
2629Registrar Abuse Contact Email: abuse@internet.bs
2630Registrar Abuse Contact Phone: +1.5167401179
2631Reseller:
2632Domain Status: clientTransferProhibited - http://www.icann.org/epp#clientTransferProhibited
2633Registry Registrant ID:
2634Registrant Name: Domain Admin
2635Registrant Organization: Whois Privacy Corp.
2636Registrant Street: Ocean Centre, Montagu Foreshore, East Bay Street
2637Registrant City: Nassau
2638Registrant State/Province: New Providence
2639Registrant Postal Code:
2640Registrant Country: BS
2641Registrant Phone: +1.5163872248
2642Registrant Phone Ext:
2643Registrant Fax:
2644Registrant Fax Ext:
2645Registrant Email: lovnymph.com-owner-juiw@customers.whoisprivacycorp.com
2646Registry Admin ID:
2647Admin Name: Domain Admin
2648Admin Organization: Whois Privacy Corp.
2649Admin Street: Ocean Centre, Montagu Foreshore, East Bay Street
2650Admin City: Nassau
2651Admin State/Province: New Providence
2652Admin Postal Code:
2653Admin Country: BS
2654Admin Phone: +1.5163872248
2655Admin Phone Ext:
2656Admin Fax:
2657Admin Fax Ext:
2658Admin Email: lovnymph.com-admin-yqnp@customers.whoisprivacycorp.com
2659Registry Tech ID:
2660Tech Name: Domain Admin
2661Tech Organization: Whois Privacy Corp.
2662Tech Street: Ocean Centre, Montagu Foreshore, East Bay Street
2663Tech City: Nassau
2664Tech State/Province: New Providence
2665Tech Postal Code:
2666Tech Country: BS
2667Tech Phone: +1.5163872248
2668Tech Phone Ext:
2669Tech Fax:
2670Tech Fax Ext:
2671Tech Email: lovnymph.com-tech-zsp0@customers.whoisprivacycorp.com
2672Name Server: ns-canada.topdns.com
2673Name Server: ns-uk.topdns.com
2674Name Server: ns-usa.topdns.com
2675DNSSEC: unsigned
2676URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
2677>>> Last update of WHOIS database: 2017-08-28T19:46:47Z <<<
2678
2679
2680
2681;; OPT PSEUDOSECTION:
2682; EDNS: version: 0, flags:; udp: 4096
2683;; QUESTION SECTION:
2684;lovnymph.com. IN ANY
2685
2686;; ANSWER SECTION:
2687lovnymph.com. 3600 IN A 5.79.70.7
2688lovnymph.com. 7200 IN SOA bob.ns.cloudflare.com. hostmaster.topdns.com. 2017071800 43200 900 1209600 3600
2689lovnymph.com. 3600 IN NS bob.ns.cloudflare.com.
2690lovnymph.com. 3600 IN NS reza.ns.cloudflare.com.
2691
2692;; Query time: 32 msec
2693;; SERVER: 192.168.1.254#53(192.168.1.254)
2694;; WHEN: Mon Aug 28 15:48:05 EDT 2017
2695;; MSG SIZE rcvd: 162
2696
2697Running:
2698 traceroute -T -O info -i eth0 lovnymph.com
2699traceroute to lovnymph.com (5.79.70.7), 30 hops max, 60 byte packets
2700 1 gateway (192.168.1.254) 0.544 ms 0.730 ms 0.893 ms
2701 2 10.135.18.1 (10.135.18.1) 7.330 ms 7.523 ms 7.965 ms
2702 3 75.154.223.209 (75.154.223.209) 32.370 ms 32.417 ms 32.475 ms
2703 4 * * *
2704 5 * * *
2705 6 * * *
2706 7 * * *
2707 8 po-1001.ce01.ams-01.nl.leaseweb.net (5.79.79.239) 128.655 ms po-1004.ce02.ams-01.nl.leaseweb.net (37.48.95.203) 127.721 ms po-1004.ce01.ams-01.nl.leaseweb.net (37.48.95.199) 127.985 ms
2708 9 5.79.78.212 (5.79.78.212) 120.189 ms 119.930 ms 5.79.78.213 (5.79.78.213) 128.181 ms
270910 lw1745.ua-hosting.company (5.79.70.7) <syn,ack> 120.271 ms 120.200 ms 127.898 ms
2710
2711Host's addresses:
2712__________________
2713
2714lovnymph.com. 3536 IN A 5.79.70.7
2715
2716
2717Name Servers:
2718______________
2719
2720reza.ns.cloudflare.com. 59753 IN A 173.245.58.217
2721bob.ns.cloudflare.com. 62904 IN A 173.245.59.104
2722
2723
2724
2725
2726Brute forcing with dns.txt:
2727____________________________
2728
2729www.lovnymph.com. 300 IN A 104.28.6.191
2730www.lovnymph.com. 300 IN A 104.28.7.191
2731
2732________________________________
2733
2734 5.79.70.0/24
2735 104.28.6.0/24
2736 104.28.7.0/24
2737
2738www.lovnymph.com
2739IPv6 address #1: 2400:cb00:2048:1::681c:6bf
2740IPv6 address #2: 2400:cb00:2048:1::681c:7bf
2741
2742www.lovnymph.com
2743IP address #1: 104.28.7.191
2744IP address #2: 104.28.6.191
2745
2746[+] 2 (sub)domains and 4 IP address(es) found
2747[+] completion time: 111 second(s)
2748
2749
2750Tracing to lovnymph.com[a] via 192.168.1.254, maximum of 3 retries
2751192.168.1.254 (192.168.1.254) Got answer
2752
2753
2754WhatWeb report for http://lovnymph.com
2755Status : 200 OK
2756Title : LoveNymphets
2757IP : 5.79.70.7
2758Country : NETHERLANDS, NL
2759
2760Summary : HTML5, Google-Analytics[Universal][UA-71325180-1], X-UA-Compatible[IE=Edge], PasswordField[password], Script[text/javascript], PHP[5.4.45], HttpOnly[xf_session], X-Powered-By[PHP/5.4.45], X-Frame-Options[SAMEORIGIN], XenForo, HTTPServer[Apache/2.2.22 (@RELEASE@)], Apache[2.2.22], Open-Graph-Protocol[website], Cookies[xf_session], JQuery[1.11.0], probably WordPress
2761
2762Detected Plugins:
2763[ Apache ]
2764 The Apache HTTP Server Project is an effort to develop and
2765 maintain an open-source HTTP server for modern operating
2766 systems including UNIX and Windows NT. The goal of this
2767 project is to provide a secure, efficient and extensible
2768 server that provides HTTP services in sync with the current
2769 HTTP standards.
2770
2771 Version : 2.2.22 (from HTTP Server Header)
2772 Google Dorks: (3)
2773 Website : http://httpd.apache.org/
2774
2775[ Cookies ]
2776 Display the names of cookies in the HTTP headers. The
2777 values are not returned to save on space.
2778
2779 String : xf_session
2780
2781[ Google-Analytics ]
2782 This plugin identifies the Google Analytics account.
2783
2784 Version : Universal
2785 Account : UA-71325180-1
2786 Website : http://www.google.com/analytics/
2787
2788[ HTML5 ]
2789 HTML version 5, detected by the doctype declaration
2790
2791
2792[ HTTPServer ]
2793 HTTP server header string. This plugin also attempts to
2794 identify the operating system from the server header.
2795
2796 String : Apache/2.2.22 (@RELEASE@) (from server string)
2797
2798[ HttpOnly ]
2799 If the HttpOnly flag is included in the HTTP set-cookie
2800 response header and the browser supports it then the cookie
2801 cannot be accessed through client side script - More Info:
2802 http://en.wikipedia.org/wiki/HTTP_cookie
2803
2804 String : xf_session
2805
2806[ JQuery ]
2807 A fast, concise, JavaScript that simplifies how to traverse
2808 HTML documents, handle events, perform animations, and add
2809 AJAX.
2810
2811 Version : 1.11.0
2812 Website : http://jquery.com/
2813
2814[ Open-Graph-Protocol ]
2815 The Open Graph protocol enables you to integrate your Web
2816 pages into the social graph. It is currently designed for
2817 Web pages representing profiles of real-world things .
2818 things like movies, sports teams, celebrities, and
2819 restaurants. Including Open Graph tags on your Web page,
2820 makes your page equivalent to a Facebook Page.
2821
2822 Version : website
2823
2824[ PHP ]
2825 PHP is a widely-used general-purpose scripting language
2826 that is especially suited for Web development and can be
2827 embedded into HTML. This plugin identifies PHP errors,
2828 modules and versions and extracts the local file path and
2829 username if present.
2830
2831 Version : 5.4.45
2832 Google Dorks: (2)
2833 Website : http://www.php.net/
2834
2835[ PasswordField ]
2836 find password fields
2837
2838 String : password (from field name)
2839
2840[ Script ]
2841 This plugin detects instances of script HTML elements and
2842 returns the script language/type.
2843
2844 String : text/javascript
2845
2846[ WordPress ]
2847 WordPress is an opensource blogging system commonly used as
2848 a CMS.
2849
2850 Certainty : probably
2851 Aggressive function available (check plugin file or details).
2852 Google Dorks: (1)
2853 Website : http://www.wordpress.org/
2854
2855[ X-Frame-Options ]
2856 This plugin retrieves the X-Frame-Options value from the
2857 HTTP header. - More Info:
2858 http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
2859 aspx
2860
2861 String : SAMEORIGIN
2862
2863[ X-Powered-By ]
2864 X-Powered-By HTTP header
2865
2866 String : PHP/5.4.45 (from x-powered-by string)
2867
2868[ X-UA-Compatible ]
2869 This plugin retrieves the X-UA-Compatible value from the
2870 HTTP header and meta http-equiv tag. - More Info:
2871 http://msdn.microsoft.com/en-us/library/cc817574.aspx
2872
2873 String : IE=Edge
2874
2875[ XenForo ]
2876 XenForo is a commercial Internet forum software written in
2877 the PHP programming language using the Zend Framework.
2878
2879 Google Dorks: (1)
2880 Website : http://xenforo.com/
2881
2882HTTP Headers:
2883 HTTP/1.1 200 OK
2884 Date: Mon, 28 Aug 2017 19:52:00 GMT
2885 Server: Apache/2.2.22 (@RELEASE@)
2886 X-Powered-By: PHP/5.4.45
2887 Expires: Thu, 19 Nov 1981 08:52:00 GMT
2888 Cache-control: private, max-age=0
2889 Set-Cookie: xf_session=aff76cccb03d94b9b4d5503c8b74df64; path=/; httponly
2890 X-Frame-Options: SAMEORIGIN
2891 Last-Modified: Mon, 28 Aug 2017 19:52:01 GMT
2892 Content-Encoding: gzip
2893 Vary: Accept-Encoding
2894 Content-Length: 15378
2895 Connection: close
2896 Content-Type: text/html; charset=UTF-8
2897
2898
2899
2900
2901*******************************************************************
2902* *
2903* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
2904* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
2905* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
2906* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
2907* *
2908* TheHarvester Ver. 2.7 *
2909* Coded by Christian Martorella *
2910* Edge-Security Research *
2911* cmartorella@edge-security.com *
2912*******************************************************************
2913
2914
2915[-] Searching in Google:
2916 Searching 0 results...
2917 Searching 100 results...
2918 Searching 200 results...
2919 Searching 300 results...
2920 Searching 400 results...
2921 Searching 500 results...
2922
2923
2924[+] Emails found:
2925------------------
2926No emails found
2927
2928[+] Hosts found in search engines:
2929------------------------------------
2930[-] Resolving hostnames IPs...
2931104.28.6.191:www.lovnymph.com
2932
2933
2934
2935 ^ ^
2936 _ __ _ ____ _ __ _ _ ____
2937 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2938 | V V // o // _/ | V V // 0 // 0 // _/
2939 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2940 <
2941 ...'
2942
2943 WAFW00F - Web Application Firewall Detection Tool
2944
2945 By Sandro Gauci && Wendel G. Henrique
2946
2947Checking http://lovnymph.com
2948The site http://lovnymph.com is behind a CloudFlare
2949Number of requests: 1
2950
2951
2952DNS Servers for lovnymph.com:
2953 bob.ns.cloudflare.com
2954 reza.ns.cloudflare.com
2955
2956Trying zone transfer first...
2957 Testing bob.ns.cloudflare.com
2958 Request timed out or transfer not allowed.
2959 Testing reza.ns.cloudflare.com
2960 Request timed out or transfer not allowed.
2961
2962Unsuccessful in zone transfer (it was worth a shot)
2963Okay, trying the good old fashioned way... brute force
2964
2965Checking for wildcard DNS...
2966Nope. Good.
2967Now performing 2280 test(s)...
2968104.28.6.191 www.lovnymph.com
2969104.28.7.191 www.lovnymph.com
2970
2971Subnets found (may want to probe here using nmap or unicornscan):
2972 104.28.6.0-255 : 1 hostnames found.
2973 104.28.7.0-255 : 1 hostnames found.
2974
2975Done with Fierce scan: http://ha.ckers.org/fierce/
2976Found 2 entries.
2977
2978Have a nice day.
2979
2980Checking for HTTP-Loadbalancing [Date]: 20:04:30, 20:04:30, 20:04:31, 20:04:31, 20:04:31, 20:04:32, 20:04:32, 20:04:33, 20:04:33, 20:04:33, 20:04:34, 20:04:34, 20:04:34, 20:04:34, 20:04:35, 20:04:35, 20:04:35, 20:04:35, 20:04:36, 20:04:36, 20:04:36, 20:04:37, 20:04:37, 20:04:37, 20:04:37, 20:04:38, 20:04:38, 20:04:38, 20:04:38, 20:04:39, 20:04:39, 20:04:39, 20:04:40, 20:04:40, 20:04:40, 20:04:40, 20:04:41, 20:04:41, 20:04:41, 20:04:42, 20:04:42, 20:04:42, 20:04:42, 20:04:43, 20:04:43, 20:04:43, 20:04:43, 20:04:44, 20:04:44, 20:04:44, NOT FOUND
2981
2982Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2983
2984lovnymph.com does NOT use Load-balancing.
2985
2986
2987
2988Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2989
2990 ----------------------------------------------------------
2991| Scan Information |
2992 ----------------------------------------------------------
2993
2994Mode ..................... VRFY
2995Worker Processes ......... 5
2996Usernames file ........... users.txt
2997Target count ............. 1
2998Username count ........... 494
2999Target TCP port .......... 25
3000Query timeout ............ 5 secs
3001Target domain ............
3002
3003
3004
3005Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 16:13 EDT
3006NSE: Loaded 146 scripts for scanning.
3007NSE: Script Pre-scanning.
3008Initiating NSE at 16:13
3009Completed NSE at 16:13, 0.00s elapsed
3010Initiating NSE at 16:13
3011Completed NSE at 16:13, 0.00s elapsed
3012Failed to resolve "lovnymph.com.txt".
3013Initiating Parallel DNS resolution of 1 host. at 16:13
3014Completed Parallel DNS resolution of 1 host. at 16:13, 0.56s elapsed
3015Initiating SYN Stealth Scan at 16:13
3016Scanning lovnymph.com (5.79.70.7) [100 ports]
3017Discovered open port 143/tcp on 5.79.70.7
3018Discovered open port 53/tcp on 5.79.70.7
3019Discovered open port 995/tcp on 5.79.70.7
3020Discovered open port 22/tcp on 5.79.70.7
3021Discovered open port 21/tcp on 5.79.70.7
3022Increasing send delay for 5.79.70.7 from 0 to 5 due to 13 out of 31 dropped probes since last increase.
3023Discovered open port 993/tcp on 5.79.70.7
3024Discovered open port 80/tcp on 5.79.70.7
3025Discovered open port 110/tcp on 5.79.70.7
3026Completed SYN Stealth Scan at 16:13, 24.05s elapsed (100 total ports)
3027Initiating Service scan at 16:13
3028Scanning 8 services on lovnymph.com (5.79.70.7)
3029Service scan Timing: About 62.50% done; ETC: 16:16 (0:01:13 remaining)
3030Service scan Timing: About 75.00% done; ETC: 16:17 (0:00:55 remaining)
3031Completed Service scan at 16:16, 177.32s elapsed (8 services on 1 host)
3032Initiating OS detection (try #1) against lovnymph.com (5.79.70.7)
3033Retrying OS detection (try #2) against lovnymph.com (5.79.70.7)
3034Initiating Traceroute at 16:17
3035Completed Traceroute at 16:17, 4.86s elapsed
3036Initiating Parallel DNS resolution of 9 hosts. at 16:17
3037Completed Parallel DNS resolution of 9 hosts. at 16:17, 5.65s elapsed
3038NSE: Script scanning 5.79.70.7.
3039Initiating NSE at 16:17
3040Completed NSE at 16:19, 102.93s elapsed
3041Initiating NSE at 16:19
3042Completed NSE at 16:19, 3.36s elapsed
3043Nmap scan report for lovnymph.com (5.79.70.7)
3044Host is up (1.7s latency).
3045Other addresses for lovnymph.com (not scanned): 2400:cb00:2048:1::681c:6bf 2400:cb00:2048:1::681c:7bf
3046rDNS record for 5.79.70.7: lw1745.ua-hosting.company
3047Not shown: 86 closed ports
3048PORT STATE SERVICE VERSION
304921/tcp open ftp ProFTPD or KnFTPD
305022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
3051| ssh-hostkey:
3052| 1024 5b:ba:0a:da:22:cb:0c:52:27:66:3b:9d:dd:96:38:50 (DSA)
3053|_ 2048 a3:b7:93:06:e1:5c:b6:6f:7f:e5:d4:90:2a:82:fb:87 (RSA)
305425/tcp filtered smtp
305553/tcp open domain?
305680/tcp open ssl/http Apache/2.2.22 (@RELEASE@)
3057|_http-favicon: Unknown favicon MD5: 242C0C45C4B3089A50CCFD0C36834ACC
3058| http-methods:
3059|_ Supported Methods: OPTIONS
3060|_http-server-header: Apache/2.2.22 (@RELEASE@)
3061|_http-title: LoveNymphets
3062110/tcp open pop3 Dovecot pop3d
3063|_pop3-capabilities: CAPA RESP-CODES SASL(PLAIN LOGIN DIGEST-MD5 CRAM-MD5) STLS UIDL USER PIPELINING TOP
3064135/tcp filtered msrpc
3065139/tcp filtered netbios-ssn
3066143/tcp open imap Dovecot imapd
3067|_imap-capabilities: STARTTLS IDLE AUTH=LOGIN Capability IMAP4rev1 completed LOGIN-REFERRALS LITERAL+ AUTH=PLAIN ID OK ENABLE SASL-IR AUTH=DIGEST-MD5 AUTH=CRAM-MD5A0001
3068|_ssl-date: 2017-08-28T20:18:12+00:00; +2s from scanner time.
3069445/tcp filtered microsoft-ds
3070465/tcp filtered smtps
3071587/tcp filtered submission
3072993/tcp open imaps?
3073| ssl-cert: Subject: commonName=lw1745.ua-hosting.company/organizationName=XX/stateOrProvinceName=XX/countryName=XX
3074| Issuer: commonName=lw1745.ua-hosting.company/organizationName=XX/stateOrProvinceName=XX/countryName=XX
3075| Public Key type: rsa
3076| Public Key bits: 1024
3077| Signature Algorithm: sha1WithRSAEncryption
3078| Not valid before: 2017-07-13T07:47:49
3079| Not valid after: 2027-07-11T07:47:49
3080| MD5: ea18 5156 b24b 7edf a495 b0b9 29d7 ad44
3081|_SHA-1: 5d7e e299 6164 051e 0800 e8c1 de94 45f7 9208 6837
3082995/tcp open pop3s?
3083| ssl-cert: Subject: commonName=lw1745.ua-hosting.company/organizationName=XX/stateOrProvinceName=XX/countryName=XX
3084| Issuer: commonName=lw1745.ua-hosting.company/organizationName=XX/stateOrProvinceName=XX/countryName=XX
3085| Public Key type: rsa
3086| Public Key bits: 1024
3087| Signature Algorithm: sha1WithRSAEncryption
3088| Not valid before: 2017-07-13T07:47:49
3089| Not valid after: 2027-07-11T07:47:49
3090| MD5: ea18 5156 b24b 7edf a495 b0b9 29d7 ad44
3091|_SHA-1: 5d7e e299 6164 051e 0800 e8c1 de94 45f7 9208 6837
3092Aggressive OS guesses: Linux 2.6.32 (94%), Linux 2.6.32 or 3.10 (94%), WatchGuard Fireware 11.8 (94%), Linux 2.6.39 (94%), Synology DiskStation Manager 5.1 (93%), Linux 3.10 (93%), Linux 3.4 (93%), Linux 3.1 - 3.2 (92%), Linux 2.6.32 - 2.6.39 (92%), Linux 3.2 - 3.8 (90%)
3093No exact OS matches for host (test conditions non-ideal).
3094Uptime guess: 46.540 days (since Thu Jul 13 03:21:16 2017)
3095Network Distance: 12 hops
3096TCP Sequence Prediction: Difficulty=260 (Good luck!)
3097IP ID Sequence Generation: All zeros
3098Service Info: OS: Unix
3099
3100Host script results:
3101|_clock-skew: mean: 1s, deviation: 0s, median: 1s
3102
3103TRACEROUTE (using port 111/tcp)
3104HOP RTT ADDRESS
31051 839.27 ms 10.13.0.1
31062 832.56 ms 37.187.24.252
31073 2732.97 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
31084 2737.25 ms 10.95.33.8
31095 2835.61 ms be100-1108.ams-1-a9.nl.eu (213.186.32.211)
31106 2825.39 ms be100-2.ams-5-a9.nl.eu (94.23.122.229)
31117 ... 9
311210 2825.39 ms po-1001.ce01.ams-01.nl.leaseweb.net (5.79.79.239)
311311 2825.38 ms 5.79.78.212
311412 2733.32 ms lw1745.ua-hosting.company (5.79.70.7)
3115
3116
3117
3118 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
3119 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3120 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
3121 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3122 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
3123
3124 _/ User-Agent Tester ↵
3125 _/ AKA: Purple Pimp ↵
3126 _/ ChrisJohnRiley ↵
3127 _/ blog.c22.cc ↵
3128
3129 [>] Performing initial request and confirming stability
3130 [>] Using User-Agent string Mozilla/5.0
3131
3132 [ ] URL (ENTERED): http://lovnymph.com
3133 [ ] Response Code: 200 OK
3134 [ ] Date: Mon, 28 Aug 2017 20:19:26 GMT
3135 [ ] Content-Type: text/html; charset=UTF-8
3136 [ ] Transfer-Encoding: chunked
3137 [ ] Connection: close
3138 [ ] Set-Cookie: __cfduid=dcee5b4c082a7204a9f62710b20bae5811503951566; expires=Tue, 28-Aug-18 20:19:26 GMT;
3139 path=/; domain=.lovnymph.com; HttpOnly
3140 [ ] X-Powered-By: PHP/5.4.45
3141 [ ] Expires: Thu, 19 Nov 1981 08:52:00 GMT
3142 [ ] Cache-control: private, max-age=0
3143 [ ] Set-Cookie: xf_session=942f26f49ef7e36c96cb1c176b219274; path=/; httponly
3144 [ ] X-Frame-Options: SAMEORIGIN
3145 [ ] Last-Modified: Mon, 28 Aug 2017 20:19:26 GMT
3146 [ ] Vary: Accept-Encoding
3147 [ ] Server: cloudflare-nginx
3148 [ ] CF-RAY: 3959f729279321da-EWR
3149 [ ] Data (MD5): 5a18f25af2da544e1baeade1d261d80f
3150
3151 [1] Pass
3152 [2] Pass
3153 [3] Pass
3154
3155 [>] URL appears stable. Beginning test
3156
3157 [>] Using DEFAULT User-Agent Strings
3158
3159 [>] Using Crazy User-Agent Strings
3160 [>] Using Bot User-Agent Strings
3161
3162 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
3163
3164
3165 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
3166
3167
3168 [!] Last-Modified: Mon, 28 Aug 2017 20:19:34 GMT
3169 [!] CF-RAY: 3959f75de1862192-EWR
3170
3171
3172 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
3173
3174
3175 [!] Last-Modified: Mon, 28 Aug 2017 20:19:35 GMT
3176 [!] CF-RAY: 3959f760f026187c-EWR
3177 [*] HTTPError: HTTP Error 403: Forbidden
3178
3179
3180.
3181
3182http://sexxxgirls.xyz
3183https://0.r.bat.bing.com
3184https://139092434.r.bat.bing.com
3185https://140111099.r.bat.bing.com
3186https://152013951.r.bat.bing.com
3187https://1871817.r.bat.bing.com
3188https://1871821.r.bat.bing.com
3189https://2847011.r.bat.bing.com
3190Please press ENTER to return to the menu
3191[+] Scanning Begins ...
3192[i] Scanning Site: http://lovnymph.com
3193
3194
3195
3196B A S I C I N F O
3197====================
3198
3199
3200[+] Site Title: LoveNymphets
3201[+] IP address: 5.79.70.7
3202[+] Web Server: cloudflare-nginx
3203[+] CMS: WordPress
3204[+] Cloudflare: Not Detected
3205[+] Robots File: Could NOT Find robots.txt!
3206
3207
3208
3209
3210W H O I S L O O K U P
3211========================
3212
3213 Domain Name: LOVNYMPH.COM
3214 Registry Domain ID: 1982561072_DOMAIN_COM-VRSN
3215 Registrar WHOIS Server: whois.internet.bs
3216 Registrar URL: http://www.internet.bs
3217 Updated Date: 2017-06-15T20:13:15Z
3218 Creation Date: 2015-11-20T11:10:36Z
3219 Registry Expiry Date: 2017-11-20T11:10:36Z
3220 Registrar: Internet Domain Service BS Corp
3221 Registrar IANA ID: 2487
3222 Registrar Abuse Contact Email:
3223 Registrar Abuse Contact Phone:
3224 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3225 Name Server: NS-CANADA.TOPDNS.COM
3226 Name Server: NS-UK.TOPDNS.COM
3227 Name Server: NS-USA.TOPDNS.COM
3228 DNSSEC: unsigned
3229
3230
3231
3232
3233G E O I P L O O K U P
3234=========================
3235
3236[i] IP Address: 5.79.70.7
3237[i] Country: NL
3238[i] State: N/A
3239[i] City: N/A
3240[i] Latitude: 52.382401
3241[i] Longitude: 4.899500
3242
3243
3244
3245
3246H T T P H E A D E R S
3247=======================
3248
3249
3250[i] HTTP/1.1 200 OK
3251[i] Date: Mon, 28 Aug 2017 19:49:14 GMT
3252[i] Content-Type: text/html; charset=UTF-8
3253[i] Connection: close
3254[i] Set-Cookie: __cfduid=d3f4f958bb66d1c5f714d7d7b4b980b321503949753; expires=Tue, 28-Aug-18 19:49:13 GMT; path=/; domain=.lovnymph.com; HttpOnly
3255[i] X-Powered-By: PHP/5.4.45
3256[i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
3257[i] Cache-control: private, max-age=0
3258[i] Set-Cookie: xf_session=d5f85c205721d8fd82268321f57ad506; path=/; httponly
3259[i] X-Frame-Options: SAMEORIGIN
3260[i] Last-Modified: Mon, 28 Aug 2017 19:49:14 GMT
3261[i] Vary: Accept-Encoding
3262[i] Server: cloudflare-nginx
3263[i] CF-RAY: 3959cae8474f2138-EWR
3264
3265
3266
3267
3268D N S L O O K U P
3269===================
3270
3271lovnymph.com. 3582 IN A 5.79.70.7
3272lovnymph.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
3273
3274
3275
3276
3277S U B N E T C A L C U L A T I O N
3278====================================
3279
3280Address = 5.79.70.7
3281Network = 5.79.70.7 / 32
3282Netmask = 255.255.255.255
3283Broadcast = not needed on Point-to-Point links
3284Wildcard Mask = 0.0.0.0
3285Hosts Bits = 0
3286Max. Hosts = 1 (2^0 - 0)
3287Host Range = { 5.79.70.7 - 5.79.70.7 }
3288
3289
3290
3291N M A P P O R T S C A N
3292============================
3293
3294
3295Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 19:49 UTC
3296Nmap scan report for lovnymph.com (5.79.70.7)
3297Host is up (0.11s latency).
3298rDNS record for 5.79.70.7: lw1745.ua-hosting.company
3299PORT STATE SERVICE VERSION
330021/tcp open ftp ProFTPD or KnFTPD
330122/tcp open ssh OpenSSH 5.3 (protocol 2.0)
330223/tcp closed telnet
330325/tcp open smtp Exim smtpd 4.84_2
330480/tcp open http Apache httpd 2.2.22
3305110/tcp open pop3 Dovecot pop3d
3306143/tcp open imap Dovecot imapd
3307443/tcp closed https
3308445/tcp filtered microsoft-ds
33093389/tcp closed ms-wbt-server
3310Service Info: Host: candydoll.lovenimphets.com; OS: Unix
3311
3312
3313S U B - D O M A I N F I N D E R
3314==================================
3315
3316
3317[i] Total Subdomains Found : 2
3318
3319[+] Subdomain: lovnymph.com
3320[-] IP: 5.79.70.7
3321
3322[+] Subdomain: www.lovnymph.com
3323[-] IP: 5.79.70.7
3324
3325
3326
3327---------------------------------------------------------------------------
3328+ Target IP: 5.79.70.7
3329+ Target Hostname: lovnymph.com
3330+ Target Port: 80
3331+ Start Time: 2017-08-28 17:17:23 (GMT-4)
3332---------------------------------------------------------------------------
3333+ Server: Apache/2.2.22 (@RELEASE@)
3334+ Retrieved x-powered-by header: PHP/5.4.45
3335+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
3336+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
3337+ Apache/2.2.22 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
3338+ Server leaks inodes via ETags, header found with file /favicon.ico, inode: 921778, size: 1150, mtime: Wed Mar 15 07:03:36 2017
3339+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
3340+ DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
3341+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
3342+ /help/: Help directory should not be accessible
3343+ OSVDB-29786: /admin.php?en_log_id=0&action=config: EasyNews from http://www.webrc.ca version 4.3 allows remote admin access. This PHP file should be protected.
3344+ OSVDB-29786: /admin.php?en_log_id=0&action=users: EasyNews from http://www.webrc.ca version 4.3 allows remote admin access. This PHP file should be protected.
3345+ OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3346+ OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3347+ OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3348+ OSVDB-3092: /admin.php: This might be interesting...
3349+ OSVDB-3092: /data/: This might be interesting...
3350+ OSVDB-3092: /login/: This might be interesting...
3351+ Uncommon header 'x-ob_mode' found, with contents: 0
3352+ OSVDB-3092: /register/: This might be interesting...
3353+ OSVDB-3268: /icons/: Directory indexing found.
3354+ OSVDB-3233: /icons/README: Apache default file found.
3355+ /htaccess.txt: Default Joomla! htaccess.txt file found. This should be removed or renamed.
3356+ /wordpress/: A Wordpress installation was found.
3357+ /phpmyadmin/: phpMyAdmin directory found
3358+ /portal/changelog: Vignette richtext HTML editor changelog found.
3359+ 8784 requests: 5 error(s) and 25 item(s) reported on remote host
3360+ End Time: 2017-08-28 21:12:34 (GMT-4) (14111 seconds)
3361---------------------------------------------------------------------------
3362
3363[#] lovnymph.com
3364[-] CMS: WordPress
3365
3366[#] sexxxgirls.xyz,1,www.softerotic.org,
3367[-] CMS: Could Not Detect
3368---------------------------------------------------------------------------
3369+ Target IP: 5.79.70.7
3370+ Target Hostname: lovnymph.com
3371+ Target Port: 80
3372+ Start Time: 2017-08-28 17:17:23 (GMT-4)
3373---------------------------------------------------------------------------
3374+ Server: Apache/2.2.22 (@RELEASE@)
3375+ Retrieved x-powered-by header: PHP/5.4.45
3376+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
3377+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
3378+ Apache/2.2.22 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
3379+ Server leaks inodes via ETags, header found with file /favicon.ico, inode: 921778, size: 1150, mtime: Wed Mar 15 07:03:36 2017
3380+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
3381+ DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
3382+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
3383+ /help/: Help directory should not be accessible
3384+ OSVDB-29786: /admin.php?en_log_id=0&action=config: EasyNews from http://www.webrc.ca version 4.3 allows remote admin access. This PHP file should be protected.
3385+ OSVDB-29786: /admin.php?en_log_id=0&action=users: EasyNews from http://www.webrc.ca version 4.3 allows remote admin access. This PHP file should be protected.
3386+ OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3387+ OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3388+ OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
3389+ OSVDB-3092: /admin.php: This might be interesting...
3390+ OSVDB-3092: /data/: This might be interesting...
3391+ OSVDB-3092: /login/: This might be interesting...
3392+ Uncommon header 'x-ob_mode' found, with contents: 0
3393+ OSVDB-3092: /register/: This might be interesting...
3394+ OSVDB-3268: /icons/: Directory indexing found.
3395+ OSVDB-3233: /icons/README: Apache default file found.
3396+ /htaccess.txt: Default Joomla! htaccess.txt file found. This should be removed or renamed.
3397+ /wordpress/: A Wordpress installation was found.
3398+ /phpmyadmin/: phpMyAdmin directory found
3399+ /portal/changelog: Vignette richtext HTML editor changelog found.
3400+ 8784 requests: 5 error(s) and 25 item(s) reported on remote host
3401+ End Time: 2017-08-28 21:12:34 (GMT-4) (14111 seconds)
3402---------------------------------------------------------------------------
3403#################################################################################
3404Hostname youngandsexy.nnfree.com ISP Webair Internet Development Company Inc. (AS27257)
3405Continent North America Flag
3406US
3407Country United States Country Code US (USA)
3408Region NY Local time 28 Aug 2017 18:43 EDT
3409Metropolis* New York Postal Code 11530
3410City Garden City Latitude 40.728
3411IP Address 174.137.171.36 Longitude -73.634
3412#################################################################################
3413youngandsexy.nnfree.com
3414
3415
3416
3417;; ANSWER SECTION:
3418youngandsexy.nnfree.com. 43200 IN A 174.137.171.36
3419
3420;; Query time: 65 msec
3421;; SERVER: 192.168.1.254#53(192.168.1.254)
3422;; WHEN: Mon Aug 28 17:32:47 EDT 2017
3423;; MSG SIZE rcvd: 68
3424
3425
3426
3427Running:
3428 traceroute -T -O info -i eth0 youngandsexy.nnfree.com
3429traceroute to youngandsexy.nnfree.com (174.137.171.36), 30 hops max, 60 byte packets
3430 1 gateway (192.168.1.254) 0.441 ms 0.604 ms 0.752 ms
3431 2 10.135.18.1 (10.135.18.1) 7.207 ms 7.545 ms 8.288 ms
3432 3 75.154.223.222 (75.154.223.222) 29.607 ms 29.645 ms 29.696 ms
3433 4 ix-xe-1-0-1-0.tcore1.N75-New-York.as6453.net (66.110.96.1) 29.892 ms 30.325 ms 30.470 ms
3434 5 ae-8.r07.nycmny01.us.bb.gin.ntt.net (129.250.9.113) 31.039 ms 32.370 ms 31.893 ms
3435 6 * * *
3436 7 csc180.gsc.webair.net (173.239.0.26) 30.133 ms 30.272 ms 30.434 ms
3437 8 dsd180.gsc.webair.net (173.239.38.134) 30.348 ms dsc180.gsc.webair.net (173.239.38.130) 29.886 ms dsd180.gsc.webair.net (173.239.38.134) 29.848 ms
3438 9 horngf.webair.com (174.137.171.36) <syn,ack> 29.568 ms 29.642 ms 29.909 ms
3439
3440
3441----- youngandsexy.nnfree.com -----
3442
3443
3444Host's addresses:
3445__________________
3446
3447youngandsexy.nnfree.com. 43032 IN A 174.137.171.36
3448
3449
3450Name Servers:
3451______________
3452
3453 youngandsexy.nnfree.com NS record query failed: NOERROR
3454
3455
3456dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
3457
3458[+] searching (sub)domains for youngandsexy.nnfree.com using built-in wordlist
3459[+] using maximum random delay of 10 millisecond(s) between requests
3460
3461[+] 0 (sub)domains and 0 IP address(es) found
3462[+] completion time: 82 second(s)
3463
3464
3465Tracing to youngandsexy.nnfree.com[a] via 192.168.1.254, maximum of 3 retries
3466192.168.1.254 (192.168.1.254) Got answer
3467
3468
3469WhatWeb report for http://youngandsexy.nnfree.com
3470Status : 200 OK
3471Title : Welcome to Innocents and Virgins +18yo
3472IP : 174.137.171.36
3473Country : UNITED STATES, US
3474
3475Summary : Script[text/javascript], PHP[5.6.17], X-Powered-By[PHP/5.6.17], HTTPServer[CentOS][Apache/2.2.15 (CentOS)], Apache[2.2.15], Email[webmaster.mati@gmail.com], Cookies[sloth_cc,sloth_nosend,sloth_ref,sloth_sc,sloth_src]
3476
3477Detected Plugins:
3478[ Apache ]
3479 The Apache HTTP Server Project is an effort to develop and
3480 maintain an open-source HTTP server for modern operating
3481 systems including UNIX and Windows NT. The goal of this
3482 project is to provide a secure, efficient and extensible
3483 server that provides HTTP services in sync with the current
3484 HTTP standards.
3485
3486 Version : 2.2.15 (from HTTP Server Header)
3487 Google Dorks: (3)
3488 Website : http://httpd.apache.org/
3489
3490[ Cookies ]
3491 Display the names of cookies in the HTTP headers. The
3492 values are not returned to save on space.
3493
3494 String : sloth_src
3495 String : sloth_cc
3496 String : sloth_sc
3497 String : sloth_ref
3498 String : sloth_nosend
3499
3500[ Email ]
3501 Extract email addresses. Find valid email address and
3502 syntactically invalid email addresses from mailto: link
3503 tags. We match syntactically invalid links containing
3504 mailto: to catch anti-spam email addresses, eg. bob at
3505 gmail.com. This uses the simplified email regular
3506 expression from
3507 http://www.regular-expressions.info/email.html for valid
3508 email address matching.
3509
3510 String : webmaster.mati@gmail.com
3511 String : webmaster.mati@gmail.com
3512
3513[ HTTPServer ]
3514 HTTP server header string. This plugin also attempts to
3515 identify the operating system from the server header.
3516
3517 OS : CentOS
3518 String : Apache/2.2.15 (CentOS) (from server string)
3519
3520[ PHP ]
3521 PHP is a widely-used general-purpose scripting language
3522 that is especially suited for Web development and can be
3523 embedded into HTML. This plugin identifies PHP errors,
3524 modules and versions and extracts the local file path and
3525 username if present.
3526
3527 Version : 5.6.17
3528 Google Dorks: (2)
3529 Website : http://www.php.net/
3530
3531[ Script ]
3532 This plugin detects instances of script HTML elements and
3533 returns the script language/type.
3534
3535 String : text/javascript
3536
3537[ X-Powered-By ]
3538 X-Powered-By HTTP header
3539
3540 String : PHP/5.6.17 (from x-powered-by string)
3541
3542HTTP Headers:
3543 HTTP/1.1 200 OK
3544 Date: Mon, 28 Aug 2017 21:37:04 GMT
3545 Server: Apache/2.2.15 (CentOS)
3546 X-Powered-By: PHP/5.6.17
3547 Set-Cookie: sloth_src=noref; expires=Wed, 30-Aug-2017 21:37:04 GMT; Max-Age=172800; path=/
3548 Set-Cookie: sloth_cc=0; expires=Wed, 30-Aug-2017 21:37:04 GMT; Max-Age=172800; path=/
3549 Set-Cookie: sloth_sc=0; expires=Wed, 30-Aug-2017 21:37:04 GMT; Max-Age=172800; path=/
3550 Set-Cookie: sloth_ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
3551 Set-Cookie: sloth_nosend=59a48d00%253A00%253ATnoref%253A; expires=Wed, 30-Aug-2017 21:37:04 GMT; Max-Age=172800; path=/
3552 Connection: close
3553 Transfer-Encoding: chunked
3554 Content-Type: text/html; charset=UTF-8
3555
3556.
3557
3558
3559
3560 ^ ^
3561 _ __ _ ____ _ __ _ _ ____
3562 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
3563 | V V // o // _/ | V V // 0 // 0 // _/
3564 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
3565 <
3566 ...'
3567
3568 WAFW00F - Web Application Firewall Detection Tool
3569
3570 By Sandro Gauci && Wendel G. Henrique
3571
3572Checking http://youngandsexy.nnfree.com
3573Generic Detection results:
3574No WAF detected by the generic detection
3575Number of requests: 13
3576
3577
3578
3579T
3580
3581lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
3582 Written by Stefan Behte (http://ge.mine.nu)
3583 Proof-of-concept! Might give false positives.
3584
3585Checking for DNS-Loadbalancing: NOT FOUND
3586Checking for HTTP-Loadbalancing [Server]:
3587 Apache/2.2.15 (CentOS)
3588 NOT FOUND
3589
3590Checking for HTTP-Loadbalancing [Date]: 21:38:35, 21:38:36, 21:38:38, 21:38:39, 21:38:40, 21:38:41, 21:38:42, 21:38:44, 21:38:45, 21:38:45, 21:38:47, 21:38:47, 21:38:49, 21:38:55, 21:38:58, 21:39:00, 21:39:03, 21:39:03, 21:39:05, 21:39:05, 21:39:05, 21:39:06, 21:39:07, 21:39:08, 21:39:10, 21:39:11, 21:39:11, 21:39:13, 21:39:13, 21:39:14, 21:39:15, 21:39:16, 21:39:18, 21:39:18, 21:39:19, 21:39:20, 21:39:21, 21:39:22, 21:39:22, 21:39:22, 21:39:23, 21:39:24, 21:39:27, 21:39:29, 21:39:32, 21:39:34, 21:39:36, 21:39:39, 21:39:40, 21:39:40, NOT FOUND
3591
3592Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
3593
3594youngandsexy.nnfree.com does NOT use Load-balancing.
3595
3596
3597
3598Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
3599
3600 ----------------------------------------------------------
3601| Scan Information |
3602 ----------------------------------------------------------
3603
3604Mode ..................... VRFY
3605Worker Processes ......... 5
3606Usernames file ........... users.txt
3607Target count ............. 1
3608Username count ........... 494
3609Target TCP port .......... 25
3610Query timeout ............ 5 secs
3611Target domain ............
3612
3613
3614
3615Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 17:48 EDT
3616NSE: Loaded 146 scripts for scanning.
3617NSE: Script Pre-scanning.
3618Initiating NSE at 17:48
3619Completed NSE at 17:48, 0.00s elapsed
3620Initiating NSE at 17:48
3621Completed NSE at 17:48, 0.00s elapsed
3622Failed to resolve "youngandsexy.nnfree.com.txt".
3623Initiating Parallel DNS resolution of 1 host. at 17:48
3624Completed Parallel DNS resolution of 1 host. at 17:48, 0.47s elapsed
3625Initiating SYN Stealth Scan at 17:48
3626Scanning youngandsexy.nnfree.com (174.137.171.36) [100 ports]
3627Discovered open port 3306/tcp on 174.137.171.36
3628Discovered open port 80/tcp on 174.137.171.36
3629Discovered open port 111/tcp on 174.137.171.36
3630Discovered open port 443/tcp on 174.137.171.36
3631Discovered open port 22/tcp on 174.137.171.36
3632Discovered open port 21/tcp on 174.137.171.36
3633Discovered open port 5666/tcp on 174.137.171.36
3634Increasing send delay for 174.137.171.36 from 0 to 5 due to 57 out of 142 dropped probes since last increase.
3635Completed SYN Stealth Scan at 17:48, 4.95s elapsed (100 total ports)
3636Initiating Service scan at 17:48
3637Scanning 7 services on youngandsexy.nnfree.com (174.137.171.36)
3638Completed Service scan at 17:48, 15.92s elapsed (7 services on 1 host)
3639Initiating OS detection (try #1) against youngandsexy.nnfree.com (174.137.171.36)
3640Initiating Traceroute at 17:49
3641Completed Traceroute at 17:49, 3.00s elapsed
3642Initiating Parallel DNS resolution of 10 hosts. at 17:49
3643Completed Parallel DNS resolution of 10 hosts. at 17:49, 5.80s elapsed
3644NSE: Script scanning 174.137.171.36.
3645Initiating NSE at 17:49
3646Completed NSE at 17:49, 32.58s elapsed
3647Initiating NSE at 17:49
3648Completed NSE at 17:49, 0.49s elapsed
3649Nmap scan report for youngandsexy.nnfree.com (174.137.171.36)
3650Host is up (0.18s latency).
3651rDNS record for 174.137.171.36: horngf.webair.com
3652Not shown: 86 closed ports
3653PORT STATE SERVICE VERSION
365421/tcp open ftp NcFTPd
365522/tcp open ssh OpenSSH 5.3 (protocol 2.0)
3656| ssh-hostkey:
3657| 1024 e7:0e:c0:9a:41:2d:af:0d:23:25:8d:31:03:02:1b:d9 (DSA)
3658|_ 2048 cd:30:da:c0:dc:31:6f:57:5f:56:68:11:d7:1a:ef:94 (RSA)
365925/tcp filtered smtp
366080/tcp open http Apache httpd 2.2.15 ((CentOS))
3661|_http-title: Welcome to Innocents and Virgins +18yo
3662111/tcp open rpcbind 2-4 (RPC #100000)
3663135/tcp filtered msrpc
3664139/tcp filtered netbios-ssn
3665443/tcp open ssl/http Apache httpd 2.2.15 ((CentOS))
3666| ssl-cert: Subject: commonName=horngf1/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
3667| Issuer: commonName=horngf1/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=--
3668| Public Key type: rsa
3669| Public Key bits: 2048
3670| Signature Algorithm: sha256WithRSAEncryption
3671| Not valid before: 2016-01-26T00:01:29
3672| Not valid after: 2017-01-25T00:01:29
3673| MD5: fcb7 8838 4bc5 0433 5707 8a9f 9bc5 cb33
3674|_SHA-1: bf75 8466 c6bb 671d 2716 d50d 0178 c7ab aeec 7d09
3675|_ssl-date: 2017-08-28T21:49:17+00:00; +4s from scanner time.
3676445/tcp filtered microsoft-ds
3677465/tcp filtered smtps
3678587/tcp filtered submission
36793306/tcp open mysql MySQL 5.6.28-76.1-log
36805666/tcp open tcpwrapped
368149152/tcp filtered unknown
3682Device type: general purpose
3683Running: Linux 2.6.X
3684OS CPE: cpe:/o:linux:linux_kernel:2.6.39
3685OS details: Linux 2.6.39
3686Uptime guess: 20.408 days (since Tue Aug 8 08:01:43 2017)
3687Network Distance: 12 hops
3688TCP Sequence Prediction: Difficulty=257 (Good luck!)
3689IP ID Sequence Generation: All zeros
3690Service Info: OS: Unix
3691
3692Host script results:
3693|_clock-skew: mean: 3s, deviation: 0s, median: 3s
3694
3695TRACEROUTE (using port 110/tcp)
3696HOP RTT ADDRESS
36971 109.61 ms 10.13.0.1
36982 110.04 ms 37.187.24.252
36993 1.06 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
37004 ...
37015 5.76 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
37026 11.75 ms be100-1295.nwk-1-a9.nj.us (192.99.146.127)
37037 ...
37048 17.74 ms be6.nyk-5-6k.ny.us (178.32.135.58)
37059 29.75 ms nyiix.NYC2.webair.net (198.32.160.100)
370610 23.55 ms csc180.gsc.webair.net (173.239.0.26)
370711 70.25 ms dsd180.gsc.webair.net (173.239.38.134)
370812 21.23 ms horngf.webair.com (174.137.171.36)
3709
3710NSE: Script Post-scanning.
3711Initiating NSE at 17:49
3712Completed NSE at 17:49, 0.00s elapsed
3713Initiating NSE at 17:49
3714Completed NSE at 17:49, 0.00s elapsed
3715Read data files from: /usr/bin/../share/nmap
3716OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
3717Nmap done: 1 IP address (1 host up) scanned in 67.03 seconds
3718 Raw packets sent: 234 (11.692KB) | Rcvd: 228 (13.577KB)
3719
3720
3721
3722
3723
3724 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
3725 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3726 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
3727 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3728 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
3729
3730 _/ User-Agent Tester ↵
3731 _/ AKA: Purple Pimp ↵
3732 _/ ChrisJohnRiley ↵
3733 _/ blog.c22.cc ↵
3734
3735 [>] Performing initial request and confirming stability
3736 [>] Using User-Agent string Mozilla/5.0
3737
3738 [ ] URL (ENTERED): http://youngandsexy.nnfree.com
3739 [ ] Response Code: 200 OK
3740 [ ] Date: Mon, 28 Aug 2017 21:49:57 GMT
3741 [ ] Server: Apache/2.2.15 (CentOS)
3742 [ ] X-Powered-By: PHP/5.6.17
3743 [ ] Set-Cookie: sloth_src=noref; expires=Wed, 30-Aug-2017 21:49:57 GMT; Max-Age=172800; path=/
3744 [ ] Set-Cookie: sloth_cc=0; expires=Wed, 30-Aug-2017 21:49:57 GMT; Max-Age=172800; path=/
3745 [ ] Set-Cookie: sloth_sc=0; expires=Wed, 30-Aug-2017 21:49:57 GMT; Max-Age=172800; path=/
3746 [ ] Set-Cookie: sloth_ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
3747 [ ] Set-Cookie: sloth_nosend=59a49005%253A00%253ATnoref%253A; expires=Wed, 30-Aug-2017 21:49:57 GMT; Max-
3748 Age=172800; path=/
3749 [ ] Connection: close
3750 [ ] Transfer-Encoding: chunked
3751 [ ] Content-Type: text/html; charset=UTF-8
3752 [ ] Data (MD5): 49d9d14d84a9b23ff7cffedf08cadc9b
3753
3754 [1] Pass
3755 [2] Pass
3756 [3] Pass
3757
3758 [>] URL appears stable. Beginning test
3759
3760 [>] Using DEFAULT User-Agent Strings
3761
3762 [>] Using Crazy User-Agent Strings
3763 [>] Using Bot User-Agent Strings
3764
3765 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
3766
3767
3768 [>] Checks completed... try enabling VERBOSE mode for more detailed output
3769
3770 [>] That's all folks... Fo' Shizzle!
3771
3772
3773
3774
3775 Enter your target IP : 174.137.171.36
3776
3777
3778[i] Scanning Site: http://youngandsexy.nnfree.com
3779
3780
3781
3782B A S I C I N F O
3783====================
3784
3785<
3786[+] Site Title: Welcome to Innocents and Virgins +18yo
3787[+] IP address: 174.137.171.36
3788[+] Web Server: Apache/2.2.15 (CentOS)
3789[+] CMS: Could Not Detect
3790[+] Cloudflare: Not Detected
3791[+] Robots File: Could NOT Find robots.txt!
3792
3793
3794
3795
3796
3797
3798
3799G E O I P L O O K U P
3800=========================
3801
3802[i] IP Address: 174.137.171.36
3803[i] Country: US
3804[i] State: New York
3805[i] City: Garden City
3806[i] Latitude: 40.727600
3807[i] Longitude: -73.634399
3808
3809
3810
3811
3812H T T P H E A D E R S
3813=======================
3814
3815
3816[i] HTTP/1.1 200 OK
3817[i] Date: Mon, 28 Aug 2017 21:34:35 GMT
3818[i] Server: Apache/2.2.15 (CentOS)
3819[i] X-Powered-By: PHP/5.6.17
3820[i] Set-Cookie: sloth_src=noref; expires=Wed, 30-Aug-2017 21:34:35 GMT; Max-Age=172800; path=/
3821[i] Set-Cookie: sloth_cc=0; expires=Wed, 30-Aug-2017 21:34:35 GMT; Max-Age=172800; path=/
3822[i] Set-Cookie: sloth_sc=0; expires=Wed, 30-Aug-2017 21:34:35 GMT; Max-Age=172800; path=/
3823[i] Set-Cookie: sloth_ref=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
3824[i] Set-Cookie: sloth_nosend=59a48c6b%253A00%253ATnoref%253A; expires=Wed, 30-Aug-2017 21:34:35 GMT; Max-Age=172800; path=/
3825[i] Connection: close
3826[i] Content-Type: text/html; charset=UTF-8
3827
3828
3829
3830
3831D N S L O O K U P
3832===================
3833
3834youngandsexy.nnfree.com. 43189 IN A 174.137.171.36
3835
3836
3837
3838
3839S U B N E T C A L C U L A T I O N
3840====================================
3841
3842Address = 174.137.171.36
3843Network = 174.137.171.36 / 32
3844Netmask = 255.255.255.255
3845Broadcast = not needed on Point-to-Point links
3846Wildcard Mask = 0.0.0.0
3847Hosts Bits = 0
3848Max. Hosts = 1 (2^0 - 0)
3849Host Range = { 174.137.171.36 - 174.137.171.36 }
3850
3851
3852
3853N M A P P O R T S C A N
3854============================
3855
3856
3857Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 21:34 UTC
3858Nmap scan report for youngandsexy.nnfree.com (174.137.171.36)
3859Host is up (0.0082s latency).
3860rDNS record for 174.137.171.36: horngf.webair.com
3861PORT STATE SERVICE VERSION
386221/tcp open ftp NcFTPd
386322/tcp open ssh OpenSSH 5.3 (protocol 2.0)
386423/tcp closed telnet
386525/tcp closed smtp
386680/tcp open http Apache httpd 2.2.15 ((CentOS))
3867110/tcp closed pop3
3868143/tcp closed imap
3869443/tcp open ssl/http Apache httpd 2.2.15 ((CentOS))
3870445/tcp filtered microsoft-ds
38713389/tcp closed ms-wbt-server
3872
3873
3874S U B - D O M A I N F I N D E R
3875==================================
3876
3877
3878[i] Total Subdomains Found : 1
3879
3880[+] Subdomain: youngandsexy.nnfree.com
3881[-] IP: 174.137.171.36
3882---------------------------------------------------------------------------
3883+ Target IP: 174.137.171.36
3884+ Target Hostname: youngandsexy.nnfree.com
3885+ Target Port: 80
3886+ Start Time: 2017-08-28 18:49:25 (GMT-4)
3887---------------------------------------------------------------------------
3888+ Server: Apache/2.2.15 (CentOS)
3889+ Cookie sloth_src created without the httponly flag
3890+ Cookie sloth_cc created without the httponly flag
3891+ Cookie sloth_sc created without the httponly flag
3892+ Cookie sloth_ref created without the httponly flag
3893+ Cookie sloth_nosend created without the httponly flag
3894+ Retrieved x-powered-by header: PHP/5.6.17
3895+ The anti-clickjacking X-Frame-Options header is not present.
3896+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
3897+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
3898+ Apache/2.2.15 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
3899+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
3900+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
3901+ ERROR: Error limit (20) reached for host, giving up. Last error:
3902+ Scan terminated: 0 error(s) and 12 item(s) reported on remote host
3903+ End Time: 2017-08-28 19:01:46 (GMT-4) (741 seconds)
3904---------------------------------------------------------------------------
3905
3906#################################################################################
3907Hostname www.youngshoolgirls.net ISP Quasi Networks LTD. (AS29073)
3908Continent Africa Flag
3909SC
3910Country Seychelles Country Code SC (SYC)
3911Region Unknown Local time 29 Aug 2017 03:06 +04
3912City Unknown Latitude -4.583
3913IP Address 93.174.91.159 Longitude 55.667
3914##################################################################################
3915youngshoolgirls.net
3916
3917
3918 Domain Name: YOUNGSHOOLGIRLS.NET
3919 Registry Domain ID: 1777282519_DOMAIN_NET-VRSN
3920 Registrar WHOIS Server: whois.registrationtek.com
3921 Registrar URL: http://www.RegistrationTek.com
3922 Updated Date: 2017-04-18T18:48:00Z
3923 Creation Date: 2013-01-30T14:29:16Z
3924 Registry Expiry Date: 2018-01-30T14:29:16Z
3925 Registrar: Registration Technologies, Inc.
3926 Registrar IANA ID: 321
3927 Registrar Abuse Contact Email:
3928 Registrar Abuse Contact Phone:
3929 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3930 Name Server: DNS1.REGISTRATIONTEK.COM
3931 Name Server: DNS2.REGISTRATIONTEK.COM
3932 Name Server: DNS3.REGISTRATIONTEK.COM
3933 Name Server: DNS4.REGISTRATIONTEK.COM
3934
3935Domain Name: youngshoolgirls.net
3936Registry Domain ID: 1777282519_DOMAIN_NET-VRSN
3937Registrar WHOIS Server: whois.registrationtek.com
3938Registrar URL: https://www.registrationtek.com/whois-i/regtek_whois.php
3939Updated Date: 2017-04-18T18:48:00Z
3940Creation Date: 2013-01-30T14:29:16Z
3941Registrar Registration Expiration Date: 2018-01-30T14:29:16Z
3942Registrar: Registration Technologies, Inc.
3943Registrar IANA ID: 321
3944Registrar Abuse Contact Email: illegal@registrationtek.com
3945Registrar Abuse Contact Phone: +1.4016482137
3946Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3947Registry Registrant ID:
3948Registrant Name:
3949Registrant Organization: Registration Technologies, Inc.
3950Registrant Street: PMB: 43423, 400 Putnam Pike, STE D203
3951Registrant City: Smithfield
3952Registrant State/Province: RI
3953Registrant Postal Code: 02917-2442
3954Registrant Country: US
3955Registrant Phone: +1.4016480147
3956Registrant Phone Ext:
3957Registrant Fax:
3958Registrant Fax Ext:
3959Registrant Email: NOSPAM-43423@RTWhoisEnvoy.net
3960Registry Admin ID:
3961Admin Name:
3962Admin Organization: Registration Technologies, Inc.
3963Admin Street: PMB: 43423, 400 Putnam Pike, STE D203
3964Admin City: Smithfield
3965Admin State/Province: RI
3966Admin Postal Code: 02917-2442
3967Admin Country: US
3968Admin Phone: +1.4016480147
3969Admin Phone Ext:
3970Admin Fax:
3971Admin Fax Ext:
3972Admin Email: NOSPAM-43423@RTWhoisEnvoy.net
3973Registry Tech ID:
3974Tech Name:
3975Tech Organization: Registration Technologies, Inc.
3976Tech Street: PMB: 43423, 400 Putnam Pike, STE D203
3977Tech City: Smithfield
3978Tech State/Province: RI
3979Tech Postal Code: 02917-2442
3980Tech Country: US
3981Tech Phone: +1.4016480147
3982Tech Phone Ext:
3983Tech Fax:
3984Tech Fax Ext:
3985Tech Email: NOSPAM-43423@RTWhoisEnvoy.net
3986Name Server: DNS1.REGISTRATIONTEK.COM
3987Name Server: DNS2.REGISTRATIONTEK.COM
3988Name Server: DNS3.REGISTRATIONTEK.COM
3989Name Server: DNS4.REGISTRATIONTEK.COM
3990
3991
3992 IN ANY
3993
3994;; ANSWER SECTION:
3995youngshoolgirls.net. 7200 IN TXT "Web: www.RegistrationTek.com"
3996youngshoolgirls.net. 7200 IN TXT "Email: support@RegistrationTek.com"
3997youngshoolgirls.net. 7200 IN TXT "Free DNS from Registration Technologies, Inc., an ICANN accredited registrar!"
3998youngshoolgirls.net. 7200 IN SOA dns1.registrationtek.com. support.registrationtek.com. 1492539453 3600 600 1209600 3600
3999youngshoolgirls.net. 600 IN A 93.174.91.159
4000youngshoolgirls.net. 7200 IN NS dns3.registrationtek.com.
4001youngshoolgirls.net. 7200 IN NS dns4.registrationtek.com.
4002youngshoolgirls.net. 7200 IN NS dns2.registrationtek.com.
4003youngshoolgirls.net. 7200 IN NS dns1.registrationtek.com.
4004
4005;; Query time: 98 msec
4006;; SERVER: 192.168.1.254#53(192.168.1.254)
4007;; WHEN: Mon Aug 28 19:07:30 EDT 2017
4008;; MSG SIZE rcvd: 381
4009
4010
4011Running:
4012 traceroute -T -O info -i eth0 youngshoolgirls.net
4013traceroute to youngshoolgirls.net (93.174.91.159), 30 hops max, 60 byte packets
4014 1 gateway (192.168.1.254) 0.472 ms 0.723 ms 0.939 ms
4015 2 10.135.18.1 (10.135.18.1) 8.275 ms 10.677 ms 16.746 ms
4016 3 75.154.223.222 (75.154.223.222) 29.824 ms 30.154 ms 30.281 ms
4017 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 33.777 ms 33.869 ms 33.909 ms
4018 5 ae-239-3615.edge6.Amsterdam1.Level3.net (4.69.162.250) 104.761 ms ae-240-3616.edge6.Amsterdam1.Level3.net (4.69.162.254) 104.827 ms 104.891 ms
4019 6 * * *
4020 7 no-reverse-dns-configured.com (93.174.91.159) <syn,ack> 103.473 ms 103.526 ms 104.053 ms
4021
4022
4023
4024----- youngshoolgirls.net -----
4025
4026
4027Host's addresses:
4028__________________
4029
4030youngshoolgirls.net. 558 IN A 93.174.91.159
4031
4032
4033Name Servers:
4034______________
4035
4036dns1.registrationtek.com. 7200 IN A 72.46.65.111
4037dns2.registrationtek.com. 7200 IN A 107.150.4.135
4038dns3.registrationtek.com. 7200 IN A 185.122.59.99
4039dns4.registrationtek.com. 7200 IN A 193.70.95.140
4040
4041
4042Mail (MX) Servers:
4043___________________
4044
4045
4046
4047
4048Brute forcing with dns.txt:
4049____________________________
4050
4051www.youngshoolgirls.net. 437 IN A 93.174.91.159
4052
4053youngshoolgirls.net class C netranges:
4054_______________________________________
4055
4056 93.174.91.0/24
4057
4058
4059Performing reverse lookup on 256 ip addresses:
4060_______________________________________________
4061
4062
4063www.youngshoolgirls.net
4064IP address #1: 93.174.91.159
4065
4066[+] 1 (sub)domains and 1 IP address(es) found
4067[+] completion time: 100 second(s)
4068
4069
4070Tracing to youngshoolgirls.net[a] via 192.168.1.254, maximum of 3 retries
4071192.168.1.254 (192.168.1.254) Got answer
4072
4073
4074WhatWeb report for http://youngshoolgirls.net
4075Status : 200 OK
4076Title : hot teen modelses, freennpics catalog freennpics, amateur teens with
4077IP : 93.174.91.159
4078Country : NETHERLANDS, NL
4079
4080Summary : nginx, Script[text/javascript], PHP[5.4.45-0+deb7u8], X-Powered-By[PHP/5.4.45-0+deb7u8], HTTPServer[nginx], Cookies[teenporn]
4081
4082Detected Plugins:
4083[ Cookies ]
4084 Display the names of cookies in the HTTP headers. The
4085 values are not returned to save on space.
4086
4087 String : teenporn
4088
4089[ HTTPServer ]
4090 HTTP server header string. This plugin also attempts to
4091 identify the operating system from the server header.
4092
4093 String : nginx (from server string)
4094
4095[ PHP ]
4096 PHP is a widely-used general-purpose scripting language
4097 that is especially suited for Web development and can be
4098 embedded into HTML. This plugin identifies PHP errors,
4099 modules and versions and extracts the local file path and
4100 username if present.
4101
4102 Version : 5.4.45-0+deb7u8
4103 Google Dorks: (2)
4104 Website : http://www.php.net/
4105
4106[ Script ]
4107 This plugin detects instances of script HTML elements and
4108 returns the script language/type.
4109
4110 String : text/javascript
4111
4112[ X-Powered-By ]
4113 X-Powered-By HTTP header
4114
4115 String : PHP/5.4.45-0+deb7u8 (from x-powered-by string)
4116
4117[ nginx ]
4118 Nginx (Engine-X) is a free, open-source, high-performance
4119 HTTP server and reverse proxy, as well as an IMAP/POP3
4120 proxy server.
4121
4122 Website : http://nginx.net/
4123
4124HTTP Headers:
4125 HTTP/1.1 200 OK
4126 Server: nginx
4127 Date: Mon, 28 Aug 2017 23:14:30 GMT
4128 Content-Type: text/html
4129 Content-Length: 2536
4130 Connection: close
4131 X-Powered-By: PHP/5.4.45-0+deb7u8
4132 Set-Cookie: teenporn=1; expires=Tue, 29-Aug-2017 11:14:30 GMT
4133 Vary: Accept-Encoding
4134 Content-Encoding: gzip
4135
4136
4137
4138
4139*******************************************************************
4140* *
4141* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
4142* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
4143* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
4144* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
4145* *
4146* TheHarvester Ver. 2.7 *
4147* Coded by Christian Martorella *
4148* Edge-Security Research *
4149* cmartorella@edge-security.com *
4150*******************************************************************
4151
4152
4153[-] Searching in Google:
4154 Searching 0 results...
4155 Searching 100 results...
4156 Searching 200 results...
4157 Searching 300 results...
4158 Searching 400 results...
4159 Searching 500 results...
4160
4161------------------------------------
4162[-] Resolving hostnames IPs...
416393.174.91.159:www.youngshoolgirls.net
4164
4165
4166
4167 ^ ^
4168 _ __ _ ____ _ __ _ _ ____
4169 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
4170 | V V // o // _/ | V V // 0 // 0 // _/
4171 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
4172 <
4173 ...'
4174
4175 WAFW00F - Web Application Firewall Detection Tool
4176
4177 By Sandro Gauci && Wendel G. Henrique
4178
4179Checking http://youngshoolgirls.net
4180Generic Detection results:
4181No WAF detected by the generic detection
4182Number of requests: 13
4183
4184
4185DNS Servers for youngshoolgirls.net:
4186 dns4.registrationtek.com
4187 dns2.registrationtek.com
4188 dns1.registrationtek.com
4189 dns3.registrationtek.com
4190
4191Trying zone transfer first...
4192 Testing dns4.registrationtek.com
4193 Request timed out or transfer not allowed.
4194 Testing dns2.registrationtek.com
4195 Request timed out or transfer not allowed.
4196 Testing dns1.registrationtek.com
4197 Request timed out or transfer not allowed.
4198 Testing dns3.registrationtek.com
4199 Request timed out or transfer not allowed.
4200
4201Unsuccessful in zone transfer (it was worth a shot)
4202Okay, trying the good old fashioned way... brute force
4203
4204Checking for wildcard DNS...
4205Nope. Good.
4206Now performing 2280 test(s)...
420793.174.91.159 img.youngshoolgirls.net
420893.174.91.159 www.youngshoolgirls.net
4209
4210Subnets found (may want to probe here using nmap or unicornscan):
4211 93.174.91.0-255 : 2 hostnames found.
4212
4213Checking for HTTP-Loadbalancing [Date]: 23:31:16, 23:31:16, 23:31:17, 23:31:18, 23:31:18, 23:31:19, 23:31:20, 23:31:21, 23:31:22, 23:31:23, 23:31:24, 23:31:25, 23:31:25, 23:31:26, 23:31:27, 23:31:28, 23:31:28, 23:31:29, 23:31:30, 23:31:30, 23:31:31, 23:31:32, 23:31:33, 23:31:33, 23:31:33, 23:31:35, 23:31:35, 23:31:36, 23:31:37, 23:31:37, 23:31:38, 23:31:39, 23:31:40, 23:31:41, 23:31:41, 23:31:42, 23:31:43, 23:31:43, 23:31:44, 23:31:45, 23:31:46, 23:31:47, 23:31:47, 23:31:49, 23:31:49, 23:31:50, 23:31:50, 23:31:51, 23:31:52, 23:31:53, NOT FOUND
4214
4215Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
4216
4217youngshoolgirls.net does NOT use Load-balancing.
4218
4219
4220
4221Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
4222
4223 ----------------------------------------------------------
4224| Scan Information |
4225 ----------------------------------------------------------
4226
4227Mode ..................... VRFY
4228Worker Processes ......... 5
4229Usernames file ........... users.txt
4230Target count ............. 1
4231Username count ........... 494
4232Target TCP port .......... 25
4233Query timeout ............ 5 secs
4234Target domain ............
4235
4236
4237
4238Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 19:37 EDT
4239NSE: Loaded 146 scripts for scanning.
4240NSE: Script Pre-scanning.
4241Initiating NSE at 19:37
4242Completed NSE at 19:37, 0.00s elapsed
4243Initiating NSE at 19:37
4244Completed NSE at 19:37, 0.00s elapsed
4245Failed to resolve "youngshoolgirls.net.txt".
4246Initiating Parallel DNS resolution of 1 host. at 19:37
4247Completed Parallel DNS resolution of 1 host. at 19:37, 0.59s elapsed
4248Initiating SYN Stealth Scan at 19:37
4249Scanning youngshoolgirls.net (93.174.91.159) [100 ports]
4250Discovered open port 80/tcp on 93.174.91.159
4251Discovered open port 21/tcp on 93.174.91.159
4252Discovered open port 53/tcp on 93.174.91.159
4253Discovered open port 111/tcp on 93.174.91.159
4254Discovered open port 22/tcp on 93.174.91.159
4255Increasing send delay for 93.174.91.159 from 0 to 5 due to 55 out of 136 dropped probes since last increase.
4256Completed SYN Stealth Scan at 19:37, 3.16s elapsed (100 total ports)
4257Initiating Service scan at 19:37
4258Scanning 5 services on youngshoolgirls.net (93.174.91.159)
4259Completed Service scan at 19:37, 12.01s elapsed (5 services on 1 host)
4260Initiating OS detection (try #1) against youngshoolgirls.net (93.174.91.159)
4261Retrying OS detection (try #2) against youngshoolgirls.net (93.174.91.159)
4262Initiating Traceroute at 19:37
4263Completed Traceroute at 19:37, 3.01s elapsed
4264Initiating Parallel DNS resolution of 9 hosts. at 19:37
4265Completed Parallel DNS resolution of 9 hosts. at 19:37, 5.62s elapsed
4266NSE: Script scanning 93.174.91.159.
4267Initiating NSE at 19:37
4268Completed NSE at 19:38, 30.10s elapsed
4269Initiating NSE at 19:38
4270Completed NSE at 19:38, 1.04s elapsed
4271Nmap scan report for youngshoolgirls.net (93.174.91.159)
4272Host is up (0.15s latency).
4273rDNS record for 93.174.91.159: no-reverse-dns-configured.com
4274Not shown: 89 closed ports
4275PORT STATE SERVICE VERSION
427621/tcp open ftp vsftpd 3.0.2
427722/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
4278| ssh-hostkey:
4279| 1024 ab:16:56:89:21:7e:75:1c:77:f3:a2:7e:c2:f1:4c:09 (DSA)
4280| 2048 22:f8:e3:f6:1a:1c:6a:99:09:6b:1e:7c:fd:30:e3:95 (RSA)
4281|_ 256 a8:03:f4:96:36:d1:39:de:2e:4f:56:e9:0f:f3:63:56 (ECDSA)
428225/tcp filtered smtp
428353/tcp open domain
4284| dns-nsid:
4285|_ bind.version: 9.8.4-rpz2+rl005.12-P1
428680/tcp open http nginx
4287|_http-favicon: Unknown favicon MD5: 3E2272E8CFA7751167C26CBCD2824670
4288| http-methods:
4289|_ Supported Methods: HEAD OPTIONS
4290|_http-server-header: nginx
4291|_http-title: hot teen modelses, freennpics catalog freennpics, amateur t...
4292111/tcp open rpcbind 2-4 (RPC #100000)
4293135/tcp filtered msrpc
4294139/tcp filtered netbios-ssn
4295445/tcp filtered microsoft-ds
4296465/tcp filtered smtps
4297587/tcp filtered submission
4298Aggressive OS guesses: Linux 2.6.39 (96%), Linux 3.2 - 3.8 (95%), Linux 3.8 (95%), WatchGuard Fireware 11.8 (95%), Linux 3.1 - 3.2 (94%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.5 (92%), Linux 3.0 - 3.2 (92%), Linux 2.6.32 (91%), Linux 3.0 (91%)
4299No exact OS matches for host (test conditions non-ideal).
4300Uptime guess: 3.570 days (since Fri Aug 25 05:57:42 2017)
4301Network Distance: 11 hops
4302TCP Sequence Prediction: Difficulty=261 (Good luck!)
4303IP ID Sequence Generation: All zeros
4304Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
4305
4306TRACEROUTE (using port 554/tcp)
4307HOP RTT ADDRESS
43081 109.50 ms 10.13.0.1
43092 110.93 ms 37.187.24.252
43103 110.48 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
43114 111.73 ms 10.95.33.10
43125 119.47 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
43136 119.50 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
43147 ...
43158 124.57 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
43169 120.76 ms 176.10.83.5
431710 ...
431811 120.78 ms no-reverse-dns-configured.com (93.174.91.159)
4319
4320NSE: Script Post-scanning.
4321Initiating NSE at 19:38
4322Completed NSE at 19:38, 0.00s elapsed
4323Initiating NSE at 19:38
4324Completed NSE at 19:38, 0.00s elapsed
4325Read data files from: /usr/bin/../share/nmap
4326OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4327Nmap done: 1 IP address (1 host up) scanned in 76.04 seconds
4328 Raw packets sent: 308 (17.474KB) | Rcvd: 295 (18.210KB)
4329
4330
4331
4332
4333 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
4334 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4335 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
4336 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4337 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
4338
4339 _/ User-Agent Tester ↵
4340 _/ AKA: Purple Pimp ↵
4341 _/ ChrisJohnRiley ↵
4342 _/ blog.c22.cc ↵
4343
4344 [>] Performing initial request and confirming stability
4345 [>] Using User-Agent string Mozilla/5.0
4346
4347 [ ] URL (ENTERED): http://youngshoolgirls.net
4348 [ ] Response Code: 200 OK
4349 [ ] Server: nginx
4350 [ ] Date: Mon, 28 Aug 2017 23:42:05 GMT
4351 [ ] Content-Type: text/html
4352 [ ] Transfer-Encoding: chunked
4353 [ ] Connection: close
4354 [ ] Vary: Accept-Encoding
4355 [ ] X-Powered-By: PHP/5.4.45-0+deb7u8
4356 [ ] Set-Cookie: teenporn=1; expires=Tue, 29-Aug-2017 11:42:05 GMT
4357 [ ] Vary: Accept-Encoding
4358 [ ] Data (MD5): d087363820931560fa0f39e322947f64
4359
4360 [1] Pass
4361 [2] Pass
4362 [3] Pass
4363
4364 [>] URL appears stable. Beginning test
4365
4366 [>] Using DEFAULT User-Agent Strings
4367
4368 [>] Using Crazy User-Agent Strings
4369 [>] Using Bot User-Agent Strings
4370
4371 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
4372
4373
4374 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
4375
4376
4377 [!] Data (MD5): ec78a617a7a81824718bbdc834cfd13e
4378
4379
4380 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
4381
4382
4383 [!] Data (MD5): 1a1e6d3790029b07282e838b97497df1
4384
4385
4386 [>] User-Agent String : TrackBack/1.02
4387
4388
4389 [!] Data (MD5): f82668c61b3410523619073e6fa2493d
4390
4391
4392 [>] User-Agent String : wispr
4393
4394
4395 [!] Data (MD5): b706d2f032518b062318fd89fc90288f
4396
4397
4398 [>] User-Agent String : EMPTY USER-AGENT STRING!
4399
4400
4401 [!] Data (MD5): 94e8596f71841c544c921c001e26fd6a
4402
4403
4404 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
4405
4406
4407 [!] Data (MD5): f995b233a8507a3dc2b69149b185c1e5
4408
4409
4410 [>] User-Agent String : Googlebot-Image/1.0
4411
4412
4413 [!] Data (MD5): 48d9fb4136b1a8810b1d06f1fcdfe256
4414
4415
4416 [>] User-Agent String : Mediapartners-Google
4417
4418
4419 [!] Data (MD5): d008c7debf441a194aa2b2907d97f3dd
4420
4421
4422 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
4423
4424
4425 [!] Data (MD5): 2f68d1f048be4f3dbd93fe6476baa755
4426
4427
4428 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
4429
4430
4431 [!] Data (MD5): 6401e04250c7d360d22b456a686d1afa
4432
4433
4434 [>] User-Agent String : mmcrawler
4435
4436
4437 [!] Data (MD5): 52f168642a668011230a532e10cfef67
4438
4439
4440 [>] Checks completed... try enabling VERBOSE mode for more detailed output
4441
4442 [>] That's all folks... Fo' Shizzle!
4443
4444
4445
4446
4447B A S I C I N F O
4448====================
4449
4450
4451[+] Site Title: hot teen modelses, freennpics catalog freennpics, amateur teens with
4452[+] IP address: 93.174.91.159
4453[+] Web Server: nginx
4454[+] CMS: Could Not Detect
4455[+] Cloudflare: Not Detected
4456[+] Robots File: Could NOT Find robots.txt!
4457
4458
4459
4460
4461W H O I S L O O K U P
4462========================
4463
4464 Domain Name: YOUNGSHOOLGIRLS.NET
4465 Registry Domain ID: 1777282519_DOMAIN_NET-VRSN
4466 Registrar WHOIS Server: whois.registrationtek.com
4467 Registrar URL: http://www.RegistrationTek.com
4468 Updated Date: 2017-04-18T18:48:00Z
4469 Creation Date: 2013-01-30T14:29:16Z
4470 Registry Expiry Date: 2018-01-30T14:29:16Z
4471 Registrar: Registration Technologies, Inc.
4472 Registrar IANA ID: 321
4473 Registrar Abuse Contact Email:
4474 Registrar Abuse Contact Phone:
4475 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4476 Name Server: DNS1.REGISTRATIONTEK.COM
4477 Name Server: DNS2.REGISTRATIONTEK.COM
4478 Name Server: DNS3.REGISTRATIONTEK.COM
4479 Name Server: DNS4.REGISTRATIONTEK.COM
4480
4481
4482
4483
4484
4485G E O I P L O O K U P
4486=========================
4487
4488[i] IP Address: 93.174.91.159
4489[i] Country: SC
4490[i] State: N/A
4491[i] City: N/A
4492[i] Latitude: -4.583300
4493[i] Longitude: 55.666698
4494
4495
4496
4497
4498H T T P H E A D E R S
4499=======================
4500
4501
4502[i] HTTP/1.1 200 OK
4503[i] Server: nginx
4504[i] Date: Mon, 28 Aug 2017 23:12:35 GMT
4505[i] Content-Type: text/html
4506[i] Connection: close
4507[i] Vary: Accept-Encoding
4508[i] X-Powered-By: PHP/5.4.45-0+deb7u8
4509[i] Set-Cookie: teenporn=1; expires=Tue, 29-Aug-2017 11:12:35 GMT
4510[i] Vary: Accept-Encoding
4511
4512
4513
4514
4515D N S L O O K U P
4516===================
4517
4518youngshoolgirls.net. 588 IN A 93.174.91.159
4519youngshoolgirls.net. 7200 IN NS dns1.registrationtek.com.
4520youngshoolgirls.net. 7200 IN NS dns2.registrationtek.com.
4521youngshoolgirls.net. 7200 IN NS dns3.registrationtek.com.
4522youngshoolgirls.net. 7200 IN NS dns4.registrationtek.com.
4523youngshoolgirls.net. 7200 IN SOA dns1.registrationtek.com. support.registrationtek.com. 1492539453 3600 600 1209600 3600
4524youngshoolgirls.net. 7200 IN TXT "Free DNS from Registration Technologies, Inc., an ICANN accredited registrar!"
4525youngshoolgirls.net. 7200 IN TXT "Web: www.RegistrationTek.com"
4526youngshoolgirls.net. 7200 IN TXT "Email: support@RegistrationTek.com"
4527
4528
4529
4530
4531S U B N E T C A L C U L A T I O N
4532====================================
4533
4534Address = 93.174.91.159
4535Network = 93.174.91.159 / 32
4536Netmask = 255.255.255.255
4537Broadcast = not needed on Point-to-Point links
4538Wildcard Mask = 0.0.0.0
4539Hosts Bits = 0
4540Max. Hosts = 1 (2^0 - 0)
4541Host Range = { 93.174.91.159 - 93.174.91.159 }
4542
4543
4544
4545N M A P P O R T S C A N
4546============================
4547
4548
4549Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-28 23:09 UTC
4550Nmap scan report for youngshoolgirls.net (93.174.91.159)
4551Host is up (0.083s latency).
4552rDNS record for 93.174.91.159: no-reverse-dns-configured.com
4553PORT STATE SERVICE VERSION
455421/tcp open ftp vsftpd 3.0.2
455522/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
455623/tcp closed telnet
455725/tcp closed smtp
455880/tcp open http nginx
4559110/tcp closed pop3
4560143/tcp closed imap
4561443/tcp closed https
4562445/tcp closed microsoft-ds
45633389/tcp closed ms-wbt-server
4564Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
4565
4566Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4567Nmap done: 1 IP address (1 host up) scanned in 7.23 seconds
4568
4569
4570
4571S U B - D O M A I N F I N D E R
4572==================================
4573
4574
4575[i] Total Subdomains Found : 1
4576
4577[+] Subdomain: youngshoolgirls.net
4578[-] IP: 93.174.91.159
4579---------------------------------------------------------------------------
4580+ Target IP: 93.174.91.159
4581+ Target Hostname: youngshoolgirls.net
4582+ Target Port: 80
4583+ Start Time: 2017-08-28 20:17:37 (GMT-4)
4584---------------------------------------------------------------------------
4585+ Server: nginx
4586+ Cookie teenporn created without the httponly flag
4587+ Retrieved x-powered-by header: PHP/5.4.45-0+deb7u8
4588+ The anti-clickjacking X-Frame-Options header is not present.
4589+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
4590+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
4591+ No CGI Directories found (use '-C all' to force check all possible dirs)
4592+ Server leaks inodes via ETags, header found with file /favicon.ico, fields: 0x52e0c2d6 0x1f6
4593+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
4594+ DEBUG HTTP verb may show server debugging information. See http://msdn.microsoft.com/en-us/library/e8z01xdh%28VS.80%29.aspx for details.
4595+ OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
4596+ OSVDB-12184: /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
4597+ OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
4598+ OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
4599+ OSVDB-3233: /icons/README: Apache default file found.
4600+ Cookie progress created without the httponly flag
4601+ Cookie fav created without the httponly flag
4602+ 7458 requests: 12 error(s) and 15 item(s) reported on remote host
4603+ End Time: 2017-08-28 21:35:31 (GMT-4) (4674 seconds)
4604---------------------------------------------------------------------------
4605##############################################################################
4606Hostname www.18kitties.com ISP OVH S (AS16276)
4607Continent North America Flag
4608CA
4609Country Canada Country Code CA (CAN)
4610Region QC Local time 28 Aug 2017 20:19 EDT
4611Metropolis Unknown Postal Code h3a 2n4
4612City Montr�al Latitude 45.504
4613IP Address 192.99.40.174 Longitude -73.575
4614#############################################################################
461518kitties.com
4616
4617
4618 Domain Name: 18KITTIES.COM
4619 Registry Domain ID: 1418736341_DOMAIN_COM-VRSN
4620 Registrar WHOIS Server: whois.moniker.com
4621 Registrar URL: http://www.moniker.com
4622 Updated Date: 2017-02-26T02:54:45Z
4623 Creation Date: 2008-03-09T22:00:21Z
4624 Registry Expiry Date: 2018-03-09T22:00:21Z
4625 Registrar: Moniker Online Services LLC
4626 Registrar IANA ID: 228
4627 Registrar Abuse Contact Email: abuse@moniker.com
4628 Registrar Abuse Contact Phone: +49.68949396850
4629 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
4630 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4631 Name Server: NS1.COOLSEXHOST.COM
4632 Name Server: NS2.COOLSEXHOST.COM
4633
4634Domain Name: 18kitties.com
4635Registry Domain ID: 1418736341_DOMAIN_COM-VRSN
4636Registrar WHOIS Server: whois.moniker.com
4637Registrar URL: http://www.moniker.com
4638Updated Date: 2017-02-26T02:54:45.0Z
4639Creation Date: 2008-03-09T22:00:21.0Z
4640Registrar Registration Expiration Date: 2018-03-09T22:00:21.0Z
4641Registrar: Moniker Online Services LLC
4642Registrar IANA ID: 228
4643Registrar Abuse Contact Email: abuse@moniker.com
4644Registrar Abuse Contact Phone: +1.9546071294
4645Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
4646Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4647Registry Registrant ID: Not Available From Registry
4648Registrant Name: Moniker Privacy Services
4649Registrant Organization: Moniker Privacy Services
4650Registrant Street: 2320 NE 9th St, Second Floor
4651Registrant City: Fort Lauderdale
4652Registrant State/Province: FL
4653Registrant Postal Code: 33304
4654Registrant Country: US
4655Registrant Phone: +1.8006886311
4656Registrant Phone Ext:
4657Registrant Fax: +1.9545859186
4658Registrant Fax Ext:
4659Registrant Email: f25d3a725a6df4c6976909f8b475a065346958f3fd965740e86beac58e72edf0@18kitties.com.whoisproxy.org
4660Registry Admin ID: Not Available From Registry
4661Admin Name: Moniker Privacy Services
4662Admin Organization: Moniker Privacy Services
4663Admin Street: 2320 NE 9th St, Second Floor
4664Admin City: Fort Lauderdale
4665Admin State/Province: FL
4666Admin Postal Code: 33304
4667Admin Country: US
4668Admin Phone: +1.8006886311
4669Admin Phone Ext:
4670Admin Fax: +1.9545859186
4671Admin Fax Ext:
4672Admin Email: f25d3a725a6df4c6976909f8b475a065346958f3fd965740e86beac58e72edf0@18kitties.com.whoisproxy.org
4673Registry Tech ID: Not Available From Registry
4674Tech Name: Moniker Privacy Services
4675Tech Organization: Moniker Privacy Services
4676Tech Street: 2320 NE 9th St, Second Floor
4677Tech City: Fort Lauderdale
4678Tech Postal Code: 33304
4679Tech State/Province: FL
4680Tech Country: US
4681Tech Phone: +1.8006886311
4682Tech Phone Ext:
4683Tech Fax: +1.9545859186
4684Tech Fax Ext:
4685Tech Email: f25d3a725a6df4c6976909f8b475a065346958f3fd965740e86beac58e72edf0@18kitties.com.whoisproxy.org
4686Registry Billing ID: Not Available From Registry
4687Billing Name: Moniker Privacy Services
4688Billing Organization: Moniker Privacy Services
4689Billing Street: 2320 NE 9th St, Second Floor
4690Billing City: Fort Lauderdale
4691Billing State/Province: FL
4692Billing Postal Code: 33304
4693Billing Country: US
4694Billing Phone: +1.8006886311
4695Billing Phone Ext:
4696Billing Fax: +1.9545859186
4697Billing Fax Ext:
4698Billing Email: f25d3a725a6df4c6976909f8b475a065346958f3fd965740e86beac58e72edf0@18kitties.com.whoisproxy.org
4699Name Server: ns1.coolsexhost.com
4700Name Server: ns2.coolsexhost.com
4701DNSSEC: unsigned
4702Whoisprivacy: 4
4703U
47041) allow, enable, or otherwise support the transmission of mass
4705 unsolicited, commercial advertising or solicitations via E-mail
4706 (spam) or
47072) enable high volume, automated, electronic processes that apply
4708 to this WHOIS server.
4709These terms may be changed without prior notice.
4710By submitting this query, you agree to abide by this policy.
4711 IN ANY
4712
4713;; ANSWER SECTION:
471418kitties.com. 30 IN MX 10 mail.18kitties.com.
471518kitties.com. 30 IN SOA ns1.coolsexhost.com. hostmaster.coolsexhost.com. 2017012301 10800 3600 3600000 30
471618kitties.com. 30 IN A 192.99.40.174
471718kitties.com. 30 IN NS ns1.coolsexhost.com.
471818kitties.com. 30 IN NS ns2.coolsexhost.com.
4719
4720;; Query time: 121 msec
4721;; SERVER: 192.168.1.254#53(192.168.1.254)
4722;; WHEN: Mon Aug 28 20:15:14 EDT 2017
4723;; MSG SIZE rcvd: 174
4724
4725
4726
4727Running:
4728 traceroute -T -O info -i eth0 18kitties.com
4729traceroute to 18kitties.com (192.99.40.174), 30 hops max, 60 byte packets
4730 1 gateway (192.168.1.254) 0.488 ms 0.740 ms 0.927 ms
4731 2 10.135.18.1 (10.135.18.1) 10.068 ms 12.108 ms 18.988 ms
4732 3 75.154.223.209 (75.154.223.209) 32.211 ms 32.370 ms 32.441 ms
4733 4 * * *
4734 5 192.99.146.140 (192.99.146.140) 36.398 ms * *
4735 6 * * *
4736 7 po7.bhs-s3-6k.qc.ca (198.27.73.142) 31.730 ms po7.bhs-s4-6k.qc.ca (198.27.73.146) 31.632 ms po7.bhs-s3-6k.qc.ca (198.27.73.142) 32.128 ms
4737 8 ns7000270.ip-192-99-40.net (192.99.40.174) <syn,ack> 31.949 ms 31.347 ms 31.362 ms
4738
4739----- 18kitties.com -----
4740
4741
4742Host's addresses:
4743__________________
4744
474518kitties.com. 29 IN A 192.99.40.174
4746
4747
4748Name Servers:
4749______________
4750
4751ns2.coolsexhost.com. 30 IN A 192.99.40.174
4752ns1.coolsexhost.com. 30 IN A 192.99.40.174
4753
4754
4755Mail (MX) Servers:
4756___________________
4757
4758mail.18kitties.com. 30 IN A 88.85.84.37
4759
4760Google Results:
4761________________
4762
4763www.18kitties.com. 30 IN A 192.99.40.174
4764
4765
4766Brute forcing with dns.txt:
4767____________________________
4768
4769ftp.18kitties.com. 30 IN CNAME www.18kitties.com.
4770www.18kitties.com. 26 IN A 192.99.40.174
4771mail.18kitties.com. 13 IN A 88.85.84.37
4772
477318kitties.com class C netranges:
4774_________________________________
4775
4776 88.85.84.0/24
4777 192.99.40.0/24
4778
4779
4780Performing reverse lookup on 512 ip addresses:
4781_______________________________________________
4782
4783
47840 results out of 512 IP addresses.
4785
4786
478718kitties.com ip blocks:
4788_________________________
4789
4790
4791done.
4792
4793
4794dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
4795
4796[+] searching (sub)domains for 18kitties.com using built-in wordlist
4797[+] using maximum random delay of 10 millisecond(s) between requests
4798
4799ftp.18kitties.com
4800IP address #1: 192.99.40.174
4801
4802mail.18kitties.com
4803IP address #1: 88.85.84.37
4804
4805www.18kitties.com
4806IP address #1: 192.99.40.174
4807
4808[+] 3 (sub)domains and 3 IP address(es) found
4809[+] completion time: 100 second(s)
4810
4811
4812Tracing to 18kitties.com[a] via 192.168.1.254, maximum of 3 retries
4813192.168.1.254 (192.168.1.254) Got answer
4814
4815
4816WhatWeb report for http://18kitties.com
4817Status : 301 Moved Permanently
4818Title : 301 Moved Permanently
4819IP : 192.99.40.174
4820Country : CANADA, CA
4821
4822Summary : nginx, RedirectLocation[http://www.18kitties.com/], HTTPServer[nginx]
4823
4824Detected Plugins:
4825[ HTTPServer ]
4826 HTTP server header string. This plugin also attempts to
4827 identify the operating system from the server header.
4828
4829 String : nginx (from server string)
4830
4831[ RedirectLocation ]
4832 HTTP Server string location. used with http-status 301 and
4833 302
4834
4835 String : http://www.18kitties.com/ (from location)
4836
4837[ nginx ]
4838 Nginx (Engine-X) is a free, open-source, high-performance
4839 HTTP server and reverse proxy, as well as an IMAP/POP3
4840 proxy server.
4841
4842 Website : http://nginx.net/
4843
4844HTTP Headers:
4845 HTTP/1.1 301 Moved Permanently
4846 Server: nginx
4847 Date: Tue, 29 Aug 2017 00:22:13 GMT
4848 Content-Type: text/html; charset=iso-8859-1
4849 Content-Length: 233
4850 Connection: close
4851 Location: http://www.18kitties.com/
4852
4853WhatWeb report for http://www.18kitties.com/
4854Status : 200 OK
4855Title : Teen Erotica : Amour Angels, Nude Girl
4856IP : 192.99.40.174
4857Country : CANADA, CA
4858
4859Summary : nginx, Script[javascript,text/javascript], HTTPServer[nginx], JQuery
4860
4861Detected Plugins:
4862[ HTTPServer ]
4863 HTTP server header string. This plugin also attempts to
4864 identify the operating system from the server header.
4865
4866 String : nginx (from server string)
4867
4868[ JQuery ]
4869 A fast, concise, JavaScript that simplifies how to traverse
4870 HTML documents, handle events, perform animations, and add
4871 AJAX.
4872
4873 Website : http://jquery.com/
4874
4875[ Script ]
4876 This plugin detects instances of script HTML elements and
4877 returns the script language/type.
4878
4879 String : javascript,text/javascript
4880
4881[ nginx ]
4882 Nginx (Engine-X) is a free, open-source, high-performance
4883 HTTP server and reverse proxy, as well as an IMAP/POP3
4884 proxy server.
4885
4886 Website : http://nginx.net/
4887
4888HTTP Headers:
4889 HTTP/1.1 200 OK
4890 Server: nginx
4891 Date: Tue, 29 Aug 2017 00:22:15 GMT
4892 Content-Type: text/html
4893 Transfer-Encoding: chunked
4894 Connection: close
4895 Accept-Ranges: bytes
4896
4897
4898
4899
4900*******************************************************************
4901* *
4902* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
4903* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
4904* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
4905* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
4906* *
4907* TheHarvester Ver. 2.7 *
4908* Coded by Christian Martorella *
4909* Edge-Security Research *
4910* cmartorella@edge-security.com *
4911*******************************************************************
4912
4913
4914[-] Searching in Google:
4915 Searching 0 results...
4916 Searching 100 results...
4917 Searching 200 results...
4918 Searching 300 results...
4919 Searching 400 results...
4920 Searching 500 results...
4921
4922
4923[+] Emails found:
4924------------------
4925No emails found
4926
4927[+] Hosts found in search engines:
4928------------------------------------
4929[-] Resolving hostnames IPs...
4930192.99.40.174:www.18kitties.com
4931
4932
4933
4934 ^ ^
4935 _ __ _ ____ _ __ _ _ ____
4936 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
4937 | V V // o // _/ | V V // 0 // 0 // _/
4938 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
4939 <
4940 ...'
4941
4942 WAFW00F - Web Application Firewall Detection Tool
4943
4944 By Sandro Gauci && Wendel G. Henrique
4945
4946Checking http://18kitties.com
4947Generic Detection results:
4948No WAF detected by the generic detection
4949Number of requests: 13
4950
4951
4952DNS Servers for 18kitties.com:
4953 ns2.coolsexhost.com
4954 ns1.coolsexhost.com
4955
4956Trying zone transfer first...
4957 Testing ns2.coolsexhost.com
4958 Request timed out or transfer not allowed.
4959 Testing ns1.coolsexhost.com
4960 Request timed out or transfer not allowed.
4961
4962Unsuccessful in zone transfer (it was worth a shot)
4963Okay, trying the good old fashioned way... brute force
4964
4965Checking for wildcard DNS...
4966Nope. Good.
4967Now performing 2280 test(s)...
4968192.99.40.174 ftp.18kitties.com
496988.85.84.37 mail.18kitties.com
4970192.99.40.174 www.18kitties.com
4971
4972Subnets found (may want to probe here using nmap or unicornscan):
4973 192.99.40.0-255 : 2 hostnames found.
4974 88.85.84.0-255 : 1 hostnames found.
4975
4976Done with Fierce scan: http://ha.ckers.org/fierce/
4977Found 3 entries.
4978
4979Have a nice day.
4980
4981
4982
4983
4984Checking for HTTP-Loadbalancing [Date]: 01:04:00, 01:04:04, 01:04:08, 01:04:13, 01:04:14, 01:04:15, 01:04:16, 01:04:18, 01:04:24, 01:04:26, 01:04:28, 01:04:29, 01:04:31, 01:04:35, 01:04:40, 01:04:41, 01:04:42, 01:04:44, 01:04:48, 01:04:53, 01:04:55, 01:04:57, 01:04:59, 01:05:04, 01:05:10, 01:05:10, 01:05:12, 01:05:13, 01:05:14, 01:05:15, 01:05:17, 01:05:18, 01:05:19, 01:05:21, 01:05:22, 01:05:24, 01:05:26, 01:05:28, 01:05:30, 01:05:31, 01:05:32, 01:05:34, 01:05:36, 01:05:39, 01:05:42, 01:05:43, 01:05:44, 01:05:48, 01:05:53, 01:05:54, NOT FOUND
4985
4986Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
4987
498818kitties.com does NOT use Load-balancing.
4989
4990
4991
4992Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
4993
4994 ----------------------------------------------------------
4995| Scan Information |
4996 ----------------------------------------------------------
4997
4998Mode ..................... VRFY
4999Worker Processes ......... 5
5000Usernames file ........... users.txt
5001Target count ............. 1
5002Username count ........... 494
5003Target TCP port .......... 25
5004Query timeout ............ 5 secs
5005Target domain ............
5006
5007
5008Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-28 21:15 EDT
5009NSE: Loaded 146 scripts for scanning.
5010NSE: Script Pre-scanning.
5011Initiating NSE at 21:15
5012Completed NSE at 21:15, 0.00s elapsed
5013Initiating NSE at 21:15
5014Completed NSE at 21:15, 0.00s elapsed
5015Failed to resolve "18kitties.com.txt".
5016Initiating Parallel DNS resolution of 1 host. at 21:15
5017Completed Parallel DNS resolution of 1 host. at 21:15, 0.54s elapsed
5018Initiating SYN Stealth Scan at 21:15
5019Scanning 18kitties.com (192.99.40.174) [100 ports]
5020Discovered open port 21/tcp on 192.99.40.174
5021Discovered open port 22/tcp on 192.99.40.174
5022Discovered open port 80/tcp on 192.99.40.174
5023Discovered open port 53/tcp on 192.99.40.174
5024Discovered open port 5666/tcp on 192.99.40.174
5025Completed SYN Stealth Scan at 21:15, 3.94s elapsed (100 total ports)
5026Initiating Service scan at 21:15
5027Scanning 5 services on 18kitties.com (192.99.40.174)
5028Completed Service scan at 21:15, 11.60s elapsed (5 services on 1 host)
5029Initiating OS detection (try #1) against 18kitties.com (192.99.40.174)
5030Retrying OS detection (try #2) against 18kitties.com (192.99.40.174)
5031adjust_timeouts2: packet supposedly had rtt of -161964 microseconds. Ignoring time.
5032adjust_timeouts2: packet supposedly had rtt of -161964 microseconds. Ignoring time.
5033Initiating Traceroute at 21:16
5034Completed Traceroute at 21:16, 0.23s elapsed
5035Initiating Parallel DNS resolution of 7 hosts. at 21:16
5036Completed Parallel DNS resolution of 7 hosts. at 21:16, 5.51s elapsed
5037NSE: Script scanning 192.99.40.174.
5038Initiating NSE at 21:16
5039Completed NSE at 21:16, 9.54s elapsed
5040Initiating NSE at 21:16
5041Completed NSE at 21:16, 0.00s elapsed
5042Nmap scan report for 18kitties.com (192.99.40.174)
5043Host is up (0.18s latency).
5044rDNS record for 192.99.40.174: ns7000270.ip-192-99-40.net
5045Not shown: 95 filtered ports
5046PORT STATE SERVICE VERSION
504721/tcp open ftp ProFTPD
504822/tcp open ssh OpenSSH 7.2 (FreeBSD 20160310; protocol 2.0)
5049| ssh-hostkey:
5050| 2048 1e:92:a6:77:68:a4:44:c6:92:e2:f1:41:c1:31:4c:ce (RSA)
5051| 256 92:1e:30:b8:76:09:37:ce:9e:e8:a8:5d:d3:21:e9:9b (ECDSA)
5052|_ 256 86:67:c2:e7:e6:36:09:4c:d7:57:d9:55:68:6a:0f:28 (EdDSA)
505353/tcp open domain ISC BIND djbdns
5054| dns-nsid:
5055|_ bind.version: djbdns
505680/tcp open http nginx
5057| http-methods:
5058|_ Supported Methods: GET HEAD POST OPTIONS
5059|_http-server-header: nginx
5060|_http-title: Did not follow redirect to http://www.18kitties.com/
50615666/tcp open tcpwrapped
5062Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
5063OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
5064No OS matches for host
5065Uptime guess: 0.000 days (since Mon Aug 28 21:16:00 2017)
5066Network Distance: 7 hops
5067TCP Sequence Prediction: Difficulty=262 (Good luck!)
5068IP ID Sequence Generation: All zeros
5069Service Info: Host: Microsoft; OS: FreeBSD; CPE: cpe:/o:freebsd:freebsd
5070
5071TRACEROUTE (using port 21/tcp)
5072HOP RTT ADDRESS
50731 110.51 ms 10.13.0.1
50742 110.54 ms 37.187.24.252
50753 110.54 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
50764 111.81 ms vl1247.rbx-g1-a75.fr.eu (37.187.231.234)
50775 190.00 ms vl1304.bhs-g1-a75.qc.ca (213.186.32.249)
50786 219.99 ms po5.bhs-s4-6k.qc.ca (198.27.73.144)
50797 189.81 ms ns7000270.ip-192-99-40.net (192.99.40.174)
5080
5081NSE: Script Post-scanning.
5082Initiating NSE at 21:16
5083Completed NSE at 21:16, 0.00s elapsed
5084Initiating NSE at 21:16
5085Completed NSE at 21:16, 0.00s elapsed
5086Read data files from: /usr/bin/../share/nmap
5087OS and Service detection performed. Please report any incorrect results at
5088
5089httprint v0.301 (beta) - web server fingerprinting tool
5090(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
5091http://net-square.com/httprint/
5092httprint@net-square.com
5093
5094Finger Printing on http://18kitties.com:80/
5095Finger Printing Completed on http://18kitties.com:80/
5096--------------------------------------------------
5097Host: 18kitties.com
5098Fingerprinting Error: Host/URL not found...
5099
5100--------------------------------------------------
5101
5102
5103
5104
5105 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
5106 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5107 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
5108 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5109 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
5110
5111 _/ User-Agent Tester ↵
5112 _/ AKA: Purple Pimp ↵
5113 _/ ChrisJohnRiley ↵
5114 _/ blog.c22.cc ↵
5115
5116 [>] Performing initial request and confirming stability
5117 [>] Using User-Agent string Mozilla/5.0
5118
5119 [ ] URL (ENTERED): http://18kitties.com
5120 [!] URL (FINAL): http://www.18kitties.com/
5121 [!] Response Code: 301 Moved Permanently
5122 [ ] Server: nginx
5123 [ ] Date: Tue, 29 Aug 2017 01:16:34 GMT
5124 [ ] Content-Type: text/html
5125 [ ] Transfer-Encoding: chunked
5126 [ ] Connection: close
5127 [ ] Accept-Ranges: bytes
5128 [ ] Data (MD5): e6a4b8375790740d18a63f7b561e12c8
5129
5130 [1] Pass
5131 [2] Pass
5132 [3] Pass
5133
5134 [>] URL appears stable. Beginning test
5135
5136 [>] Using DEFAULT User-Agent Strings
5137
5138 [>] Using Crazy User-Agent Strings
5139 [>] Using Bot User-Agent Strings
5140
5141 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
5142
5143
5144 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
5145
5146
5147 [!] Data (MD5): 5c9d2d94e82e2e0ec3fca9192933252b
5148
5149
5150 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
5151
5152
5153 [!] Data (MD5): b754dcecc54be6f1257636eed8d20d36
5154
5155
5156 [>] User-Agent String : TrackBack/1.02
5157
5158
5159 [!] Data (MD5): 07ebd2e17beb0b6163d5fa9856f47ae3
5160
5161
5162 [>] User-Agent String : wispr
5163
5164
5165 [!] Data (MD5): 846ad99ff1fe9058e99b5ee761f208ff
5166
5167
5168 [>] User-Agent String : EMPTY USER-AGENT STRING!
5169
5170
5171 [!] Data (MD5): c5a9a9de25484e6662ab8d4b4ee13e5a
5172
5173
5174 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
5175
5176
5177 [!] Data (MD5): 1f6715aa3636f7e87b1a238e08f83232
5178
5179
5180 [>] User-Agent String : Googlebot-Image/1.0
5181
5182
5183 [!] Data (MD5): 6e01fd0bc97e8e3982a368d865db7bfb
5184
5185
5186 [>] User-Agent String : Mediapartners-Google
5187
5188
5189 [!] Data (MD5): faec4ee0ca76fbadc46a27878afa0165
5190
5191
5192 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
5193
5194
5195 [!] Data (MD5): efcc70f30a88ae3f5cc0d7998704f031
5196
5197
5198 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
5199
5200
5201 [!] Data (MD5): 7589475ccd0d94a946e83f3a3813fdb5
5202
5203
5204 [>] User-Agent String : mmcrawler
5205
5206
5207 [!] Data (MD5): bae5da1bf31d4d765337da1852942678
5208
5209
5210 [>] Checks completed... try enabling VERBOSE mode for more detailed output
5211
5212 [>] That's all folks... Fo' Shizzle!
5213
5214
5215
5216
5217 Enter your target IP : 192.99.40.174
5218
5219 obtention site Joomla ...
5220
5221
5222
5223
5224 obtention site Wordpress ...
5225
5226https://0.r.bat.bing.com
5227https://1871817.r.bat.bing.com
5228i] Scanning Site: http://18kitties.com
5229
5230
5231
5232B A S I C I N F O
5233====================
5234
5235
5236[+] Site Title: Teen Erotica : Amour Angels, Nude Girl
5237[+] IP address: 192.99.40.174
5238[+] Web Server: nginx
5239[+] CMS: Could Not Detect
5240[+] Cloudflare: Not Detected
5241[+] Robots File: Could NOT Find robots.txt!
5242
5243
5244
5245
5246W H O I S L O O K U P
5247========================
5248
5249 Domain Name: 18KITTIES.COM
5250 Registry Domain ID: 1418736341_DOMAIN_COM-VRSN
5251 Registrar WHOIS Server: whois.moniker.com
5252 Registrar URL: http://www.moniker.com
5253 Updated Date: 2017-02-26T02:54:45Z
5254 Creation Date: 2008-03-09T22:00:21Z
5255 Registry Expiry Date: 2018-03-09T22:00:21Z
5256 Registrar: Moniker Online Services LLC
5257 Registrar IANA ID: 228
5258 Registrar Abuse Contact Email: abuse@moniker.com
5259 Registrar Abuse Contact Phone: +49.68949396850
5260 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
5261 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5262 Name Server: NS1.COOLSEXHOST.COM
5263 Name Server: NS2.COOLSEXHOST.COM
5264
5265
5266
5267
5268G E O I P L O O K U P
5269=========================
5270
5271[i] IP Address: 192.99.40.174
5272[i] Country: CA
5273[i] State: Quebec
5274[i] City: Montral
5275[i] Latitude: 45.504002
5276[i] Longitude: -73.574699
5277
5278
5279
5280
5281H T T P H E A D E R S
5282=======================
5283
5284
5285[i] HTTP/1.1 301 Moved Permanently
5286[i] Server: nginx
5287[i] Date: Tue, 29 Aug 2017 00:19:55 GMT
5288[i] Content-Type: text/html; charset=iso-8859-1
5289[i] Content-Length: 233
5290[i] Connection: close
5291[i] Location: http://www.18kitties.com/
5292[i] HTTP/1.1 200 OK
5293[i] Server: nginx
5294[i] Date: Tue, 29 Aug 2017 00:19:57 GMT
5295[i] Content-Type: text/html
5296[i] Connection: close
5297[i] Accept-Ranges: bytes
5298
5299
5300
5301
5302D N S L O O K U P
5303===================
5304
530518kitties.com. 18 IN A 192.99.40.174
530618kitties.com. 30 IN NS ns2.coolsexhost.com.
530718kitties.com. 30 IN NS ns1.coolsexhost.com.
530818kitties.com. 30 IN SOA ns1.coolsexhost.com. hostmaster.coolsexhost.com. 2017012301 10800 3600 3600000 30
530918kitties.com. 30 IN MX 10 mail.18kitties.com.
5310
5311
5312
5313
5314S U B N E T C A L C U L A T I O N
5315====================================
5316
5317Address = 192.99.40.174
5318Network = 192.99.40.174 / 32
5319Netmask = 255.255.255.255
5320Broadcast = not needed on Point-to-Point links
5321Wildcard Mask = 0.0.0.0
5322Hosts Bits = 0
5323Max. Hosts = 1 (2^0 - 0)
5324Host Range = { 192.99.40.174 - 192.99.40.174 }
5325
5326
5327
5328N M A P P O R T S C A N
5329============================
5330
5331
5332Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 00:20 UTC
5333Nmap scan report for 18kitties.com (192.99.40.174)
5334Host is up (0.016s latency).
5335rDNS record for 192.99.40.174: ns7000270.ip-192-99-40.net
5336PORT STATE SERVICE VERSION
533721/tcp open ftp ProFTPD 1.2.10
533822/tcp open ssh OpenSSH 7.2 (FreeBSD 20160310; protocol 2.0)
533923/tcp filtered telnet
534025/tcp filtered smtp
534180/tcp open http nginx
5342110/tcp filtered pop3
5343143/tcp filtered imap
5344443/tcp filtered https
5345445/tcp filtered microsoft-ds
53463389/tcp filtered ms-wbt-server
5347
5348
5349
5350S U B - D O M A I N F I N D E R
5351==================================
5352
5353
5354[i] Total Subdomains Found : 3
5355
5356[+] Subdomain: 18kitties.com
5357[-] IP: 192.99.40.174
5358
5359[+] Subdomain: mail.18kitties.com
5360[-] IP: 88.85.84.37
5361
5362[+] Subdomain: www.18kitties.com
5363[-] IP: 192.99.40.174
5364
5365
5366
5367
5368
5369R E V E R S E I P L O O K U P
5370==================================
5371
5372
5373[i] Total Sites Found On This Server : 4
5374
5375
5376[#] hosted.amourangels.com
5377[-] CMS: Could Not Detect
5378
5379[#] hosted.showybeauty.com
5380[-] CMS: Could Not Detect
5381
5382[#] teenpornstorage.biz,1,www.artnudegalleries.com
5383[-] CMS: Could Not Detect
5384
5385[#] www.teenporngallery.net,1
5386[-] CMS: Could Not Detect
5387---------------------------------------------------------------------------
5388+ Target IP: 192.99.40.174
5389+ Target Hostname: 18kitties.com
5390+ Target Port: 80
5391+ Start Time: 2017-08-28 22:20:27 (GMT-4)
5392---------------------------------------------------------------------------
5393+ Server: nginx
5394+ The anti-clickjacking X-Frame-Options header is not present.
5395+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
5396+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
5397+ Root page / redirects to: http://www.18kitties.com/
5398+ 8256 requests: 0 error(s) and 3 item(s) reported on remote host
5399+ End Time: 2017-08-28 22:54:11 (GMT-4) (2024 seconds)
5400---------------------------------------------------------------------------
5401################################################################################
5402http://www.teenflavour.com/
5403 Hostname www.teenflavour.com ISP DataWeb Global Group B.V. (AS39572)
5404Continent North America Flag
5405US
5406Country United States Country Code US (USA)
5407Region VA Local time 28 Aug 2017 22:36 EDT
5408Metropolis* Washington Postal Code 20147
5409City Ashburn Latitude 39.018
5410IP Address 213.174.158.127 Longitude -77.539
5411##############################################################################
5412teenflavour.com
5413
5414
5415 Domain Name: TEENFLAVOUR.COM
5416 Registry Domain ID: 1402607651_DOMAIN_COM-VRSN
5417 Registrar WHOIS Server: whois.evonames.com
5418 Registrar URL: http://www.danesconames.com
5419 Updated Date: 2017-01-04T12:20:54Z
5420 Creation Date: 2008-02-14T05:42:14Z
5421 Registry Expiry Date: 2018-02-14T05:42:14Z
5422 Registrar: Danesco Trading Ltd.
5423 Registrar IANA ID: 1418
5424 Registrar Abuse Contact Email:
5425 Registrar Abuse Contact Phone:
5426 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
5427 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5428 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
5429 Name Server: NS5.PUBLIC-NS.COM
5430 Name Server: NS6.PUBLIC-NS.COM
5431
5432
5433Domain Name: TEENFLAVOUR.COM
5434Registry Domain ID:
5435Registrar WHOIS Server: whois.evonames.com
5436Registrar URL: https://evonames.com/
5437Updated Date: 2017-03-17 16:06:22.530903
5438Creation Date: 2008-02-14
5439Registrar Registration Expiration Date: 2018-02-14
5440Registrar: DANESCO TRADING LTD
5441Registrar IANA ID: 1418
5442Registrar Abuse Contact Email: abuse@evonames.com
5443Registrar Abuse Contact Phone: +357.95713635
5444Reseller: AHnames.com https://www.AHnames.com/
5445Domain Status: clientUpdateProhibited
5446Domain Status: clientDeleteProhibited
5447Domain Status: clientTransferProhibited
5448Registry Registrant ID: MR_2627861WP
5449Registrant Name: WhoisProtectService.net
5450Registrant Organization: PROTECTSERVICE, LTD.
5451Registrant Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
5452Registrant City: Limassol
5453Registrant State/Province:
5454Registrant Postal Code: 3025
5455Registrant Country: Cyprus
5456Registrant Phone: +357.95713635
5457Registrant Phone Ext:
5458Registrant Fax:
5459Registrant Fax Ext:
5460Registrant Email: teenflavour.com@whoisprotectservice.net
5461Registry Admin ID: MR_2627861WP
5462Admin Name: WhoisProtectService.net
5463Admin Organization: PROTECTSERVICE, LTD.
5464Admin Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
5465Admin City: Limassol
5466Admin State/Province:
5467Admin Postal Code: 3025
5468Admin Country: Cyprus
5469Admin Phone: +357.95713635
5470Admin Phone Ext:
5471Admin Fax:
5472Admin Fax Ext:
5473Admin Email: teenflavour.com@whoisprotectservice.net
5474Registry Tech ID: MR_2627861WP
5475Tech Name: WhoisProtectService.net
5476Tech Organization: PROTECTSERVICE, LTD.
5477Tech Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
5478Tech City: Limassol
5479Tech State/Province:
5480Tech Postal Code: 3025
5481Tech Country: Cyprus
5482Tech Phone: +357.95713635
5483Tech Phone Ext:
5484Tech Fax:
5485Tech Fax Ext:
5486Tech Email: teenflavour.com@whoisprotectservice.net
5487Registry Billing ID: MR_2627861WP
5488Billing Name: WhoisProtectService.net
5489Billing Organization: PROTECTSERVICE, LTD.
5490Billing Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
5491Billing City: Limassol
5492Billing State/Province:
5493Billing Postal Code: 3025
5494Billing Country: Cyprus
5495Billing Phone: +357.95713635
5496Billing Phone Ext:
5497Billing Fax:
5498Billing Fax Ext:
5499Billing Email: teenflavour.com@whoisprotectservice.net
5500Name Server: NS5.PUBLIC-NS.COM
5501Name Server: NS6.PUBLIC-NS.COM
5502DNSSEC: unsigned
5503URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
5504>>> Last update of WHOIS database: 2017-08-18 20:45:37 <<<
5505
5506Abuse email: abuse@ahnames.com
5507
5508
5509
5510
5511; <<>> DiG 9.10.3-P4-Debian <<>> teenflavour.com any
5512;; global options: +cmd
5513;; Got answer:
5514;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59531
5515;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1
5516
5517;; OPT PSEUDOSECTION:
5518; EDNS: version: 0, flags:; udp: 4096
5519;; QUESTION SECTION:
5520;teenflavour.com. IN ANY
5521
5522;; ANSWER SECTION:
5523teenflavour.com. 1200 IN A 213.174.158.127
5524teenflavour.com. 1200 IN MX 10 mail.teenflavour.com.
5525teenflavour.com. 1200 IN MX 20 mail2.teenflavour.com.
5526teenflavour.com. 1200 IN SOA ns6.public-ns.com. admin.teenflavour.com. 1399054271 21600 3600 691200 38400
5527teenflavour.com. 1200 IN NS ns5.public-ns.com.
5528teenflavour.com. 1200 IN NS ns6.public-ns.com.
5529
5530;; Query time: 38 msec
5531;; SERVER: 192.168.1.254#53(192.168.1.254)
5532;; WHEN: Tue Aug 29 00:39:40 EDT 2017
5533;; MSG SIZE rcvd: 191
5534
5535
5536
5537;; Connection to 192.168.1.254#53(192.168.1.254) for teenflavour.com failed: connection refused.
5538Host teenflavour.com not found: 9(NOTAUTH)
5539; Transfer failed.
5540
5541
5542Please type the name of your network interface Example: eth0
5543eth0
5544
5545Running:
5546 traceroute -T -O info -i eth0 teenflavour.com
5547traceroute to teenflavour.com (213.174.158.127), 30 hops max, 60 byte packets
5548 1 gateway (192.168.1.254) 0.532 ms 0.718 ms 0.880 ms
5549 2 10.135.18.1 (10.135.18.1) 14.735 ms 20.701 ms 21.531 ms
5550 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 30.877 ms 31.218 ms 31.334 ms
5551 4 * * *
5552 5 * * *
5553 6 ah.101.eq.ash.va.us.iptp.net (98.158.98.238) 38.155 ms 35.214 ms 35.179 ms
5554 7 213.174.158.127 (213.174.158.127) <syn,ack> 35.977 ms 35.569 ms 35.982 ms
5555
5556
5557Smartmatch is experimental at /usr/bin/dnsenum line 698.
5558Smartmatch is experimental at /usr/bin/dnsenum line 698.
5559dnsenum VERSION:1.2.4
5560Warning: can't load Net::Whois::IP module, whois queries disabled.
5561
5562----- teenflavour.com -----
5563
5564
5565Host's addresses:
5566__________________
5567
5568teenflavour.com. 1185 IN A 213.174.158.127
5569
5570
5571Name Servers:
5572______________
5573
5574ns5.public-ns.com. 1200 IN A 213.174.157.35
5575ns6.public-ns.com. 1200 IN A 88.208.29.10
5576
5577
5578Mail (MX) Servers:
5579___________________
5580
5581mail2.teenflavour.com. 1200 IN A 88.208.36.36
5582mail.teenflavour.com. 1200 IN A 213.174.151.151
5583
5584
5585
5586
5587 ---- Google search page: 1 ----
5588
5589 www
5590
5591
5592Google Results:
5593________________
5594
5595www.teenflavour.com. 1200 IN A 213.174.158.127
5596
5597
5598Brute forcing with dns.txt:
5599____________________________
5600
5601mail.teenflavour.com. 1191 IN A 213.174.151.151
5602mail2.teenflavour.com. 1191 IN A 88.208.36.36
5603
5604
5605Performing recursion:
5606______________________
5607
5608
5609 ---- Checking subdomains NS records ----
5610
5611 Can't perform recursion no NS records.
5612
5613
5614teenflavour.com class C netranges:
5615___________________________________
5616
5617 88.208.36.0/24
5618 213.174.151.0/24
5619 213.174.158.0/24
5620
5621
5622Performing reverse lookup on 768 ip addresses:
5623_______________________________________________
5624i] Scanning Site: http://teenflavour.com
5625
5626
5627
5628B A S I C I N F O
5629====================
5630
5631
5632[+] Site Title: Young Models @ Teen Flavour
5633[+] IP address: 213.174.158.127
5634[+] Web Server: nginx/1.4.2
5635[+] CMS: Could Not Detect
5636[+] Cloudflare: Not Detected
5637[+] Robots File: Found
5638
5639-------------[ contents ]----------------
5640User-agent: *
5641Disallow: /trade.php
5642Disallow: /galleries/
5643-----------[end of contents]-------------
5644
5645
5646
5647W H O I S L O O K U P
5648========================
5649
5650 Domain Name: TEENFLAVOUR.COM
5651 Registry Domain ID: 1402607651_DOMAIN_COM-VRSN
5652 Registrar WHOIS Server: whois.evonames.com
5653 Registrar URL: http://www.danesconames.com
5654 Updated Date: 2017-01-04T12:20:54Z
5655 Creation Date: 2008-02-14T05:42:14Z
5656 Registry Expiry Date: 2018-02-14T05:42:14Z
5657 Registrar: Danesco Trading Ltd.
5658 Registrar IANA ID: 1418
5659 Registrar Abuse Contact Email:
5660 Registrar Abuse Contact Phone:
5661 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
5662 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5663 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
5664 Name Server: NS5.PUBLIC-NS.COM
5665 Name Server: NS6.PUBLIC-NS.COM
5666 DNSSEC: unsigned
5667
5668
5669
5670
5671
5672G E O I P L O O K U P
5673=========================
5674
5675[i] IP Address: 213.174.158.127
5676[i] Country: US
5677[i] State: Virginia
5678[i] City: Ashburn
5679[i] Latitude: 39.018002
5680[i] Longitude: -77.539001
5681
5682
5683
5684
5685H T T P H E A D E R S
5686=======================
5687
5688
5689[i] HTTP/1.1 301 Moved Permanently
5690[i] Server: nginx/1.4.2
5691[i] Date: Tue, 29 Aug 2017 04:42:17 GMT
5692[i] Content-Type: text/html; charset=iso-8859-1
5693[i] Content-Length: 365
5694[i] Connection: close
5695[i] Location: http://www.teenflavour.com/
5696[i] Vary: Accept-Encoding
5697[i] Expires: Thu, 28 Sep 2017 04:42:17 GMT
5698[i] Cache-Control: max-age=2592000
5699[i] HTTP/1.1 200 OK
5700[i] Server: nginx/1.4.2
5701[i] Date: Tue, 29 Aug 2017 04:42:17 GMT
5702[i] Content-Type: text/html
5703[i] Connection: close
5704[i] Vary: Accept-Encoding
5705[i] X-Powered-By: PHP/5.4.43
5706[i] Vary: Accept-Encoding
5707[i] Expires: Thu, 28 Sep 2017 04:42:17 GMT
5708[i] Cache-Control: max-age=2592000
5709
5710
5711
5712
5713D N S L O O K U P
5714===================
5715
5716teenflavour.com. 1198 IN A 213.174.158.127
5717teenflavour.com. 1200 IN NS ns6.public-ns.com.
5718teenflavour.com. 1200 IN NS ns5.public-ns.com.
5719teenflavour.com. 1200 IN SOA ns6.public-ns.com. admin.teenflavour.com. 1399054271 21600 3600 691200 38400
5720teenflavour.com. 1200 IN MX 10 mail.teenflavour.com.
5721teenflavour.com. 1200 IN MX 20 mail2.teenflavour.com.
5722
5723
5724
5725
5726S U B N E T C A L C U L A T I O N
5727====================================
5728
5729Address = 213.174.158.127
5730Network = 213.174.158.127 / 32
5731Netmask = 255.255.255.255
5732Broadcast = not needed on Point-to-Point links
5733Wildcard Mask = 0.0.0.0
5734Hosts Bits = 0
5735Max. Hosts = 1 (2^0 - 0)
5736Host Range = { 213.174.158.127 - 213.174.158.127 }
5737
5738
5739
5740N M A P P O R T S C A N
5741============================
5742
5743
5744Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 04:42 UTC
5745Nmap scan report for teenflavour.com (213.174.158.127)
5746Host is up (0.027s latency).
5747PORT STATE SERVICE VERSION
574821/tcp open ftp OpenBSD ftpd
574922/tcp open ssh OpenSSH 5.8p2_hpn13v11 (FreeBSD 20110503; protocol 2.0)
575023/tcp filtered telnet
575125/tcp filtered smtp
575280/tcp open http nginx 1.4.2
5753110/tcp filtered pop3
5754143/tcp filtered imap
5755443/tcp filtered https
5756445/tcp filtered microsoft-ds
57573389/tcp filtered ms-wbt-server
5758Service Info: Host: DS2187; OS: FreeBSD; CPE: cpe:/o:freebsd:freebsd
5759
5760Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5761Nmap done: 1 IP address (1 host up) scanned in 8.26 seconds
5762
5763
5764
5765S U B - D O M A I N F I N D E R
5766==================================
5767
5768
5769[i] Total Subdomains Found : 4
5770
5771[+] Subdomain: teenflavour.com
5772[-] IP: 213.174.158.127
5773
5774[+] Subdomain: mail2.teenflavour.com
5775[-] IP: 88.208.36.36
5776
5777[+] Subdomain: mail.teenflavour.com
5778[-] IP: 213.174.151.151
5779
5780[+] Subdomain: www.teenflavour.com
5781[-] IP: 213.174.158.127
5782
5783
5784
5785
5786
5787R E V E R S E I P L O O K U P
5788==================================
5789
5790
5791[i] Total Sites Found On This Server : 48
5792
5793
5794[#] closenet.org
5795[-] CMS: Could Not Detect
5796
5797[#] domoteens.com
5798[-] CMS: Could Not Detect
5799
5800[#] innocent-tiny-vaginas.net,1,itinyteens.com
5801[-] CMS: Could Not Detect
5802
5803[#] petite-virgin-teens.net
5804[-] CMS: Could Not Detect
5805
5806[#] teenflavour.com
5807[-] CMS: Could Not Detect
5808
5809[#] teenzaza.com
5810[-] CMS: Could Not Detect
5811
5812[#] www.100teenthumbs.com
5813[-] CMS: Could Not Detect
5814
5815[#] www.allteennudes.com
5816[-] CMS: Could Not Detect
5817
5818[#] www.alluringbikinibabes.com
5819[-] CMS: Could Not Detect
5820
5821[#] www.baldyoungpussy.com,1,www.bbwporngalleries.com,1,www.beautiesonboard.com
5822[-] CMS: Could Not Detect
5823
5824[#] www.big-tits-beauties.net,1,www.bigtittedwomen.net
5825[-] CMS: Could Not Detect
5826
5827[#] www.blackzandu.com
5828[-] CMS: Could Not Detect
5829
5830[#] www.cartoonpornhq.com,1,www.cartoonsexhq.com,1,www.cutennteens.com
5831[-] CMS: Could Not Detect
5832
5833[#] www.domoteens.com
5834[-] CMS: Could Not Detect
5835
5836[#] www.gaypornclub.net,1,www.gethairygirls.com
5837[-] CMS: Could Not Detect
5838
5839[#] www.gethairypussy.com,1,www.gethotmoms.com
5840[-] CMS: Could Not Detect
5841
5842[#] www.getshemales.com
5843[-] CMS: Could Not Detect
5844
5845[#] www.girlsbushes.com
5846[-] CMS: Could Not Detect
5847
5848[#] www.hqhairypussy.com,1,www.ihairyvagina.com,1,www.ihavehairybush.com
5849[-] CMS: Could Not Detect
5850
5851[#] www.ilovehairycunts.com,1,www.iloveporncomics.com,1,www.ilovesexyteens.com,1,www.inakedteens.com
5852[-] CMS: Could Not Detect
5853
5854[#] www.iseeknewteens.com
5855[-] CMS: Could Not Detect
5856
5857[#] www.itinyteens.com
5858[-] CMS: Could Not Detect
5859
5860[#] www.juicyxvideos.com
5861[-] CMS: Could Not Detect
5862
5863[#] www.justbigtit.com
5864[-] CMS: Could Not Detect
5865
5866[#] www.latteintero.com
5867[-] CMS: Could Not Detect
5868
5869[#] www.mintladies.com
5870[-] CMS: Could Not Detect
5871
5872[#] www.mintteens.com
5873[-] CMS: Could Not Detect
5874
5875[#] www.niceteenmodels.com
5876[-] CMS: Could Not Detect
5877
5878[#] www.nubilegirlsvideos.com
5879[-] CMS: Could Not Detect
5880
5881[#] www.nudeskinnyteens.com
5882[-] CMS: Could Not Detect
5883
5884[#] www.oggylist.com
5885[-] CMS: Could Not Detect
5886
5887[#] www.onlyhairybeaver.com
5888[-] CMS: Could Not Detect
5889
5890[#] www.prettynubiles.com
5891[-] CMS: Could Not Detect
5892
5893[#] www.smallteenpussy.com,1,www.smallteentits.net,1,www.softcore-girls.com,1,www.sugarmolly.com
5894[-] CMS: Could Not Detect
5895
5896[#] www.teen-sex-clips.net,1,www.teenflavour.com
5897[-] CMS: Could Not Detect
5898
5899[#] www.teenkey.com
5900[-] CMS: Could Not Detect
5901
5902[#] www.teenmarker.com
5903[-] CMS: Could Not Detect
5904
5905[#] www.teenorange.com
5906[-] CMS: Could Not Detect
5907
5908[#] www.teensexhq.com,1,www.teensinmicrobikini.com
5909[-] CMS: Could Not Detect
5910
5911[#] www.teentray.com
5912[-] CMS: Could Not Detect
5913
5914[#] www.teenzaza.com
5915[-] CMS: Could Not Detect
5916
5917[#] www.tinyjugs.com
5918[-] CMS: Could Not Detect
5919
5920[#] www.unozomer.com
5921[-] CMS: Could Not Detect
5922
5923[#] www.xhairywomen.com
5924[-] CMS: Could Not Detect
5925
5926[#] www.xmaturegalleries.com
5927[-] CMS: Could Not Detect
5928
5929[#] www.xtightteenies.com
5930[-] CMS: Could Not Detect
5931
5932[#] www.youngporntgp.com,1,www.zulateens.com
5933[-] CMS: Could Not Detect
5934
5935[#] young-russian-virgins.net,
5936[-] CMS: Could Not Detect
5937
5938
5939
5940
5941 [+] URL(s) With Parameter(s):220
5942
5943
5944
5945C R A W L E R
5946=============
5947
5948
5949Crawling Types & Descriptions:
5950---------------------------------------------------------------------------
5951+ Target IP: 213.174.158.127
5952+ Target Hostname: teenflavour.com
5953+ Target Port: 80
5954+ Start Time: 2017-08-29 00:42:24 (GMT-4)
5955---------------------------------------------------------------------------
5956+ Server: nginx/1.4.2
5957+ The anti-clickjacking X-Frame-Options header is not present.
5958+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
5959+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
5960+ Root page / redirects to: http://www.teenflavour.com/
5961+ No CGI Directories found (use '-C all' to force check all possible dirs)
5962+ Server leaks inodes via ETags, header found with file /robots.txt, fields: 0x4f870609 0x38
5963+ "robots.txt" contains 2 entries which should be manually viewed.
5964+ ERROR: Error limit (20) reached for host, giving up. Last error: error reading HTTP response
5965+ Scan terminated: 20 error(s) and 5 item(s) reported on remote host
5966+ End Time: 2017-08-29 00:54:17 (GMT-4) (713 seconds)
5967---------------------------------------------------------------------------
5968###########################################################################################
5969Hostname teenjuniors.com ISP LeaseWeb Netherlands B.V. (AS60781)
5970Continent Europe Flag
5971NL
5972Country Netherlands Country Code NL (NLD)
5973Region Unknown Local time 29 Aug 2017 07:14 CEST
5974City Unknown Latitude 52.382
5975IP Address 95.211.5.91 Longitude 4.899
5976#######################################################################################
5977teenjuniors.com
5978teenjuniors.com
5979
5980
5981 Domain Name: TEENJUNIORS.COM
5982 Registry Domain ID: 1495083595_DOMAIN_COM-VRSN
5983 Registrar WHOIS Server: whois.godaddy.com
5984 Registrar URL: http://www.godaddy.com
5985 Updated Date: 2017-06-17T10:21:56Z
5986 Creation Date: 2008-06-16T17:51:19Z
5987 Registry Expiry Date: 2018-06-16T17:51:19Z
5988 Registrar: GoDaddy.com, LLC
5989 Registrar IANA ID: 146
5990 Registrar Abuse Contact Email: abuse@godaddy.com
5991 Registrar Abuse Contact Phone: 480-624-2505
5992 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
5993 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
5994 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5995 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
5996 Name Server: NS09.DOMAINCONTROL.COM
5997 Name Server: NS10.DOMAINCONTROL.COM
5998
5999Domain Name: TEENJUNIORS.COM
6000Registrar URL: http://www.godaddy.com
6001Registrant Name: Registration Private
6002Registrant Organization: Domains By Proxy, LLC
6003Name Server: NS09.DOMAINCONTROL.COM
6004Name Server: NS10.DOMAINCONTROL.COM
6005 IN ANY
6006
6007;; ANSWER SECTION:
6008teenjuniors.com. 1703 IN A 95.211.5.91
6009teenjuniors.com. 3503 IN NS ns09.domaincontrol.com.
6010teenjuniors.com. 3503 IN NS ns10.domaincontrol.com.
6011
6012;; Query time: 8 msec
6013;; SERVER: 192.168.1.254#53(192.168.1.254)
6014;; WHEN: Tue Aug 29 01:15:18 EDT 2017
6015;; MSG SIZE rcvd: 112
6016
6017
6018
6019;; Connection to 192.168.1.254#53(192.168.1.254) for teenjuniors.com failed: connection refused.
6020Host teenjuniors.com not found: 9(NOTAUTH)
6021; Transfer failed.
6022
6023
6024Please type the name of your network interface Example: eth0
6025eth0
6026
6027Running:
6028 traceroute -T -O info -i eth0 teenjuniors.com
6029traceroute to teenjuniors.com (95.211.5.91), 30 hops max, 60 byte packets
6030 1 gateway (192.168.1.254) 0.508 ms 0.634 ms 0.908 ms
6031 2 10.135.18.1 (10.135.18.1) 18.643 ms 19.173 ms 28.199 ms
6032 3 75.154.223.209 (75.154.223.209) 32.039 ms 32.102 ms 32.123 ms
6033 4 * * *
6034 5 * * *
6035 6 * * *
6036 7 * * *
6037 8 91.kaasserver.com (95.211.5.91) <syn,ack> 125.690 ms 126.055 ms 124.538 ms
6038
6039
6040Smartmatch is experimental at /usr/bin/dnsenum line 698.
6041Smartmatch is experimental at /usr/bin/dnsenum line 698.
6042dnsenum VERSION:1.2.4
6043Warning: can't load Net::Whois::IP module, whois queries disabled.
6044
6045----- teenjuniors.com -----
6046
6047
6048Host's addresses:
6049__________________
6050
6051teenjuniors.com. 1681 IN A 95.211.5.91
6052
6053
6054Wildcard detection using: dgwkoeqgigov
6055_______________________________________
6056
6057dgwkoeqgigov.teenjuniors.com. 1800 IN A 95.211.5.91
6058
6059
6060Name Servers:
6061______________
6062
6063ns09.domaincontrol.com. 172800 IN A 216.69.185.5
6064ns10.domaincontrol.com. 172800 IN A 208.109.255.5
6065
6066
6067Mail (MX) Servers:
6068___________________
6069
6070www.teenjuniors.com. 1680 IN CNAME teenjuniors.com.
6071
6072
6073Brute forcing with dns.txt:
6074____________________________
6075
6076e.teenjuniors.com. 3600 IN CNAME email.secureserver.net.
6077email.secureserver.net. 60 IN A 173.201.193.133
6078email.secureserver.net. 60 IN A 97.74.135.55
6079email.secureserver.net. 60 IN A 173.201.193.5
6080email.secureserver.net. 60 IN A 97.74.135.45
6081email.secureserver.net. 60 IN A 173.201.192.148
6082email.secureserver.net. 60 IN A 173.201.192.133
6083email.secureserver.net. 60 IN A 72.167.218.173
6084email.secureserver.net. 60 IN A 173.201.193.148
6085email.secureserver.net. 60 IN A 97.74.135.133
6086email.secureserver.net. 60 IN A 173.201.192.20
6087email.secureserver.net. 60 IN A 173.201.193.20
6088email.secureserver.net. 60 IN A 97.74.135.148
6089email.secureserver.net. 60 IN A 72.167.218.45
6090email.secureserver.net. 60 IN A 173.201.192.5
6091email.secureserver.net. 60 IN A 72.167.218.55
6092email.secureserver.net. 60 IN A 72.167.218.183
6093ftp.teenjuniors.com. 3600 IN CNAME teenjuniors.com.
6094mail.teenjuniors.com. 3600 IN CNAME pop.secureserver.net.
6095pop.secureserver.net. 9 IN A 173.201.193.200
6096pop.secureserver.net. 9 IN A 97.74.135.111
6097pop.secureserver.net. 9 IN A 97.74.135.218
6098pop.secureserver.net. 9 IN A 68.178.252.115
6099pop.secureserver.net. 9 IN A 45.40.130.44
6100pop.teenjuniors.com. 3600 IN CNAME pop.secureserver.net.
6101pop.secureserver.net. 6 IN A 97.74.135.111
6102pop.secureserver.net. 6 IN A 97.74.135.218
6103pop.secureserver.net. 6 IN A 68.178.252.115
6104pop.secureserver.net. 6 IN A 45.40.130.44
6105pop.secureserver.net. 6 IN A 173.201.193.200
6106smtp.teenjuniors.com. 3600 IN CNAME smtp.secureserver.net.
6107smtp.secureserver.net. 60 IN A 72.167.238.29
6108smtp.secureserver.net. 60 IN A 68.178.213.37
6109smtp.secureserver.net. 60 IN A 68.178.213.203
6110webmail.teenjuniors.com. 3600 IN CNAME webmail.secureserver.net.
6111webmail.secureserver.net. 3600 IN CNAME email.secureserver.net.
6112email.secureserver.net. 51 IN A 97.74.135.55
6113email.secureserver.net. 51 IN A 173.201.193.5
6114email.secureserver.net. 51 IN A 97.74.135.45
6115email.secureserver.net. 51 IN A 173.201.192.148
6116email.secureserver.net. 51 IN A 173.201.192.133
6117email.secureserver.net. 51 IN A 72.167.218.173
6118email.secureserver.net. 51 IN A 173.201.193.148
6119email.secureserver.net. 51 IN A 97.74.135.133
6120email.secureserver.net. 51 IN A 173.201.192.20
6121email.secureserver.net. 51 IN A 173.201.193.20
6122email.secureserver.net. 51 IN A 97.74.135.148
6123email.secureserver.net. 51 IN A 72.167.218.45
6124email.secureserver.net. 51 IN A 173.201.192.5
6125email.secureserver.net. 51 IN A 72.167.218.55
6126email.secureserver.net. 51 IN A 72.167.218.183
6127email.secureserver.net. 51 IN A 173.201.193.133
6128
6129
6130Performing recursion:
6131______________________
6132
6133
6134 ---- Checking subdomains NS records ----
6135teenjuniors.com. 3466 IN NS ns09.domaincontrol.com.
6136teenjuniors.com. 3466 IN NS ns10.domaincontrol.com.
6137teenjuniors.com. 3466 IN NS ns09.domaincontrol.com.
6138teenjuniors.com. 3466 IN NS ns10.domaincontrol.com.
6139
6140e.teenjuniors.com
6141IP address #1: 173.201.193.5
6142IP address #2: 97.74.135.45
6143IP address #3: 173.201.192.148
6144IP address #4: 173.201.192.133
6145IP address #5: 72.167.218.173
6146IP address #6: 173.201.193.148
6147IP address #7: 97.74.135.133
6148IP address #8: 173.201.192.20
6149IP address #9: 173.201.193.20
6150IP address #10: 97.74.135.148
6151IP address #11: 72.167.218.45
6152IP address #12: 173.201.192.5
6153IP address #13: 72.167.218.55
6154IP address #14: 72.167.218.183
6155IP address #15: 173.201.193.133
6156IP address #16: 97.74.135.55
6157
6158email.teenjuniors.com
6159IP address #1: 97.74.135.45
6160IP address #2: 173.201.192.148
6161IP address #3: 173.201.192.133
6162IP address #4: 72.167.218.173
6163IP address #5: 173.201.193.148
6164IP address #6: 97.74.135.133
6165IP address #7: 173.201.192.20
6166IP address #8: 173.201.193.20
6167IP address #9: 97.74.135.148
6168IP address #10: 72.167.218.45
6169IP address #11: 173.201.192.5
6170IP address #12: 72.167.218.55
6171IP address #13: 72.167.218.183
6172IP address #14: 173.201.193.133
6173IP address #15: 97.74.135.55
6174IP address #16: 173.201.193.5
6175
6176imap.teenjuniors.com
6177IP address #1: 97.74.135.69
6178IP address #2: 68.178.252.221
6179IP address #3: 173.201.193.71
6180IP address #4: 72.167.218.187
6181IP address #5: 45.40.130.32
6182IP address #6: 72.167.218.82
6183IP address #7: 97.74.135.193
6184IP address #8: 68.178.252.71
6185IP address #9: 173.201.193.226
6186IP address #10: 173.201.192.71
6187IP address #11: 68.178.252.222
6188
6189mail.teenjuniors.com
6190IP address #1: 97.74.135.218
6191IP address #2: 173.201.193.200
6192IP address #3: 45.40.130.44
6193IP address #4: 68.178.252.115
6194IP address #5: 97.74.135.111
6195
6196pop.teenjuniors.com
6197IP address #1: 68.178.252.115
6198IP address #2: 97.74.135.111
6199IP address #3: 97.74.135.218
6200IP address #4: 173.201.193.200
6201IP address #5: 45.40.130.44
6202
6203smtp.teenjuniors.com
6204IP address #1: 68.178.213.37
6205IP address #2: 68.178.213.203
6206IP address #3: 72.167.238.29
6207
6208webmail.teenjuniors.com
6209IP address #1: 72.167.218.173
6210IP address #2: 173.201.193.20
6211IP address #3: 97.74.135.133
6212IP address #4: 173.201.193.5
6213IP address #5: 72.167.218.183
6214IP address #6: 173.201.192.133
6215IP address #7: 72.167.218.45
6216IP address #8: 173.201.192.5
6217IP address #9: 173.201.193.148
6218IP address #10: 173.201.193.133
6219IP address #11: 173.201.192.148
6220IP address #12: 97.74.135.148
6221IP address #13: 173.201.192.20
6222IP address #14: 97.74.135.45
6223IP address #15: 97.74.135.55
6224IP address #16: 72.167.218.55
6225
6226WhatWeb report for http://teenjuniors.com
6227Status : 200 OK
6228Title : TeenJuniors.com :: welcome to the Juniors index ::
6229IP : 95.211.5.91
6230Country : NETHERLANDS, NL
6231
6232Summary : Meta-Author[teenjuniors.com], Script[onlineusr,text/javascript], PHP[5.2.4-2ubuntu5.26], X-Powered-By[PHP/5.2.4-2ubuntu5.26], HTTPServer[Apache], Apache
6233
6234Detected Plugins:
6235[ Apache ]
6236 The Apache HTTP Server Project is an effort to develop and
6237 maintain an open-source HTTP server for modern operating
6238 systems including UNIX and Windows NT. The goal of this
6239 project is to provide a secure, efficient and extensible
6240 server that provides HTTP services in sync with the current
6241 HTTP standards.
6242
6243 Google Dorks: (3)
6244 Website : http://httpd.apache.org/
6245
6246[ HTTPServer ]
6247 HTTP server header string. This plugin also attempts to
6248 identify the operating system from the server header.
6249
6250 String : Apache (from server string)
6251
6252[ Meta-Author ]
6253 This plugin retrieves the author name from the meta name
6254 tag - info:
6255 http://www.webmarketingnow.com/tips/meta-tags-uncovered.html
6256 #author
6257
6258 String : teenjuniors.com
6259
6260[ PHP ]
6261 PHP is a widely-used general-purpose scripting language
6262 that is especially suited for Web development and can be
6263 embedded into HTML. This plugin identifies PHP errors,
6264 modules and versions and extracts the local file path and
6265 username if present.
6266
6267 Version : 5.2.4-2ubuntu5.26
6268 Google Dorks: (2)
6269 Website : http://www.php.net/
6270
6271[ Script ]
6272 This plugin detects instances of script HTML elements and
6273 returns the script language/type.
6274
6275 String : onlineusr,text/javascript
6276
6277[ X-Powered-By ]
6278 X-Powered-By HTTP header
6279
6280 String : PHP/5.2.4-2ubuntu5.26 (from x-powered-by string)
6281
6282HTTP Headers:
6283 HTTP/1.1 200 OK
6284 Date: Tue, 29 Aug 2017 05:18:09 GMT
6285 Server: Apache
6286 X-Powered-By: PHP/5.2.4-2ubuntu5.26
6287 Connection: close
6288 Transfer-Encoding: chunked
6289 Content-Type: text/html
6290
6291
6292
6293
6294*******************************************************************
6295* *
6296* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
6297* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
6298* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
6299* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
6300* *
6301* TheHarvester Ver. 2.7 *
6302* Coded by Christian Martorella *
6303* Edge-Security Research *
6304* cmartorella@edge-security.com *
6305*******************************************************************
6306
6307
6308[-] Searching in Google:
6309 Searching 0 results...
6310 Searching 100 results...
6311 Searching 200 results...
6312 Searching 300 results...
6313 Searching 400 results...
6314 Searching 500 results...
6315
6316
6317[+] Emails found:
6318------------------
6319No emails found
6320
6321[+] Hosts found in search engines:
6322------------------------------------
6323[-] Resolving hostnames IPs...
632495.211.5.91:253Dwww.teenjuniors.com
632595.211.5.91:www.teenjuniors.com
6326
6327
6328
6329 ^ ^
6330 _ __ _ ____ _ __ _ _ ____
6331 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
6332 | V V // o // _/ | V V // 0 // 0 // _/
6333 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
6334 <
6335 ...'
6336
6337 WAFW00F - Web Application Firewall Detection Tool
6338
6339 By Sandro Gauci && Wendel G. Henrique
6340
6341Checking http://teenjuniors.com
6342Generic Detection results:
6343No WAF detected by the generic detection
6344Number of requests: 13
6345
6346
6347DNS Servers for teenjuniors.com:
6348 ns10.domaincontrol.com
6349 ns09.domaincontrol.com
6350
6351Trying zone transfer first...
6352 Testing ns10.domaincontrol.com
6353 Request timed out or transfer not allowed.
6354 Testing ns09.domaincontrol.com
6355 Request timed out or transfer not allowed.
6356
6357Unsuccessful in zone transfer (it was worth a shot)
6358Okay, trying the good old fashioned way... brute force
6359
6360Checking for wildcard DNS...
6361 ** Found 98891010212.teenjuniors.com at 95.211.5.91.
6362 ** High probability of wildcard DNS.
6363Now performing 2280 test(s)...
6364
6365Subnets found (may want to probe here using nmap or unicornscan):
6366
6367Done with Fierce scan: http://ha.ckers.org/fierce/
6368Found 0 entries.
6369
6370Have a nice day.
6371
6372
6373
6374lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
6375 Written by Stefan Behte (http://ge.mine.nu)
6376 Proof-of-concept! Might give false positives.
6377
6378Checking for DNS-Loadbalancing: NOT FOUND
6379Checking for HTTP-Loadbalancing [Server]:
6380 Apache
6381 NOT FOUND
6382
6383Checking for HTTP-Loadbalancing [Date]: 05:30:07, 05:30:07, 05:30:07, 05:30:08, 05:30:08, 05:30:08, 05:30:08, 05:30:09, 05:30:09, 05:30:09, 05:30:09, 05:30:10, 05:30:10, 05:30:10, 05:30:10, 05:30:11, 05:30:11, 05:30:11, 05:30:11, 05:30:12, 05:30:12, 05:30:12, 05:30:12, 05:30:13, 05:30:13, 05:30:13, 05:30:13, 05:30:14, 05:30:14, 05:30:14, 05:30:15, 05:30:15, 05:30:15, 05:30:15, 05:30:16, 05:30:16, 05:30:16, 05:30:16, 05:30:17, 05:30:17, 05:30:17, 05:30:17, 05:30:18, 05:30:18, 05:30:18, 05:30:18, 05:30:19, 05:30:19, 05:30:19, 05:30:19, NOT FOUND
6384
6385Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
6386
6387teenjuniors.com does NOT use Load-balancing.
6388
6389
6390
6391Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
6392
6393 ----------------------------------------------------------
6394| Scan Information |
6395 ----------------------------------------------------------
6396
6397Mode ..................... VRFY
6398Worker Processes ......... 5
6399Usernames file ........... users.txt
6400Target count ............. 1
6401Username count ........... 494
6402Target TCP port .......... 25
6403Query timeout ............ 5 secs
6404Target domain ............
6405
6406######## Scan started at Tue Aug 29 01:30:41 2017 #########
6407######## Scan completed at Tue Aug 29 01:38:57 2017 #########
64080 results.
6409
6410494 queries in 496 seconds (1.0 queries / sec)
6411
6412
6413
6414Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 01:38 EDT
6415NSE: Loaded 146 scripts for scanning.
6416NSE: Script Pre-scanning.
6417Initiating NSE at 01:38
6418Completed NSE at 01:38, 0.00s elapsed
6419Initiating NSE at 01:38
6420Completed NSE at 01:38, 0.00s elapsed
6421Failed to resolve "teenjuniors.com.txt".
6422Initiating Parallel DNS resolution of 1 host. at 01:38
6423Completed Parallel DNS resolution of 1 host. at 01:38, 0.53s elapsed
6424Initiating SYN Stealth Scan at 01:38
6425Scanning teenjuniors.com (95.211.5.91) [100 ports]
6426Discovered open port 80/tcp on 95.211.5.91
6427Increasing send delay for 95.211.5.91 from 0 to 5 due to 35 out of 86 dropped probes since last increase.
6428Completed SYN Stealth Scan at 01:39, 6.38s elapsed (100 total ports)
6429Initiating Service scan at 01:39
6430Scanning 1 service on teenjuniors.com (95.211.5.91)
6431Completed Service scan at 01:39, 7.76s elapsed (1 service on 1 host)
6432Initiating OS detection (try #1) against teenjuniors.com (95.211.5.91)
6433Retrying OS detection (try #2) against teenjuniors.com (95.211.5.91)
6434Initiating Traceroute at 01:39
6435Completed Traceroute at 01:39, 3.01s elapsed
6436Initiating Parallel DNS resolution of 7 hosts. at 01:39
6437Completed Parallel DNS resolution of 7 hosts. at 01:39, 5.78s elapsed
6438NSE: Script scanning 95.211.5.91.
6439Initiating NSE at 01:39
6440Completed NSE at 01:41, 127.99s elapsed
6441Initiating NSE at 01:41
6442Completed NSE at 01:41, 0.00s elapsed
6443Nmap scan report for teenjuniors.com (95.211.5.91)
6444Host is up (0.67s latency).
6445rDNS record for 95.211.5.91: 91.kaasserver.com
6446Not shown: 93 closed ports
6447PORT STATE SERVICE VERSION
644825/tcp filtered smtp
644980/tcp open http Apache httpd
6450|_http-favicon: Unknown favicon MD5: 47DF85411621AD2B7F7E79D429AFE43A
6451| http-methods:
6452|_ Supported Methods: GET HEAD POST OPTIONS
6453|_http-server-header: Apache
6454|_http-title: TeenJuniors.com :: welcome to the Juniors index ::
6455135/tcp filtered msrpc
6456139/tcp filtered netbios-ssn
6457445/tcp filtered microsoft-ds
6458465/tcp filtered smtps
6459587/tcp filtered submission
6460Aggressive OS guesses: Kyocera CopyStar CS 255 printer (99%), Kyocera CopyStar CS-2560 printer (99%), AXIS 205 Network Camera, Buffalo TeraStation NAS device, Linksys WAP54G WAP, or Sony SNC-RZ50N network camera (98%), Sun Integrated Lights-Out Manager (98%), Dell Integrated Remote Access Controller (iDRAC9) (98%), Linux 2.6.22 (98%), AVM FRITZ!Box FON WLAN 7170 WAP (97%), Dell Integrated Remote Access Controller (iDRAC) (97%), Dell Remote Access Controller 5/I (DRAC 5/I) (97%), Extreme Networks ExtremeXOS 12.5.4 (97%)
6461No exact OS matches for host (test conditions non-ideal).
6462Uptime guess: 411.361 days (since Wed Jul 13 17:02:05 2016)
6463Network Distance: 10 hops
6464TCP Sequence Prediction: Difficulty=264 (Good luck!)
6465IP ID Sequence Generation: All zeros
6466
6467TRACEROUTE (using port 443/tcp)
6468HOP RTT ADDRESS
64691 491.07 ms 10.13.0.1
64702 513.29 ms 37.187.24.252
64713 495.68 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
64724 513.34 ms 10.95.33.8
64735 605.32 ms be100-1108.ams-1-a9.nl.eu (213.186.32.211)
64746 606.24 ms be100-2.ams-5-a9.nl.eu (94.23.122.229)
64757 ... 9
647610 605.13 ms 91.kaasserver.com (95.211.5.91)
6477
6478NSE: Script Post-scanning.
6479Initiating NSE at 01:41
6480Completed NSE at 01:41, 0.00s elapsed
6481Initiating NSE at 01:41
6482Completed NSE at 01:41, 0.00s elapsed
6483Read data files from: /usr/bin/../share/nmap
6484OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6485Nmap done: 1 IP address (1 host up) scanned in 179.52 seconds
6486 Raw packets sent: 285 (16.920KB) | Rcvd: 623 (436.398KB)
6487
6488
6489Error: can not open nmap file: teenjuniors.com.txt
6490
6491
6492httprint v0.301 (beta) - web server fingerprinting tool
6493(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
6494http://net-square.com/httprint/
6495httprint@net-square.com
6496
6497Finger Printing on http://teenjuniors.com:80/
6498Finger Printing Completed on http://teenjuniors.com:80/
6499--------------------------------------------------
6500Host: teenjuniors.com
6501Fingerprinting Error: Host/URL not found...
6502
6503--------------------------------------------------
6504
6505
6506
6507
6508 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
6509 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6510 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
6511 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6512 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
6513
6514 _/ User-Agent Tester ↵
6515 _/ AKA: Purple Pimp ↵
6516 _/ ChrisJohnRiley ↵
6517 _/ blog.c22.cc ↵
6518
6519 [>] Performing initial request and confirming stability
6520 [>] Using User-Agent string Mozilla/5.0
6521
6522 [ ] URL (ENTERED): http://teenjuniors.com
6523 [ ] Response Code: 200 OK
6524 [ ] Date: Tue, 29 Aug 2017 05:42:10 GMT
6525 [ ] Server: Apache
6526 [ ] X-Powered-By: PHP/5.2.4-2ubuntu5.26
6527 [ ] Connection: close
6528 [ ] Transfer-Encoding: chunked
6529 [ ] Content-Type: text/html
6530 [ ] Data (MD5): fa850ce4c5ca4ce9ca901e774c442647
6531
6532 [1] Pass
6533 [2] Pass
6534 [3] Pass
6535
6536 [>] URL appears stable. Beginning test
6537
6538 [>] Using DEFAULT User-Agent Strings
6539
6540 [>] Using Crazy User-Agent Strings
6541 [>] Using Bot User-Agent Strings
6542
6543 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
6544
6545
6546 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
6547
6548
6549 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6550
6551
6552 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
6553
6554
6555 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6556
6557
6558 [>] User-Agent String : TrackBack/1.02
6559
6560
6561 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6562
6563
6564 [>] User-Agent String : wispr
6565
6566
6567 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6568
6569
6570 [>] User-Agent String : EMPTY USER-AGENT STRING!
6571
6572
6573 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6574
6575
6576 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
6577
6578
6579 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6580
6581
6582 [>] User-Agent String : Googlebot-Image/1.0
6583
6584
6585 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6586
6587
6588 [>] User-Agent String : Mediapartners-Google
6589
6590
6591 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6592
6593
6594 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
6595
6596
6597 [!] Data (MD5): 6dd2a337113a68dbe3355b457f34f1fa
6598
6599
6600 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
6601
6602
6603 [!] Data (MD5): b467f61ed38e6e70ec3dd818734e3d39
6604
6605
6606 [>] User-Agent String : mmcrawler
6607
6608
6609 [!] Data (MD5): b467f61ed38e6e70ec3dd818734e3d39
6610
6611
6612 [>] Checks completed... try enabling VERBOSE mode for more detailed output
6613
6614 [>] That's all folks... Fo' Shizzle!
6615[i] Scanning Site: http://teenjuniors.com
6616
6617
6618
6619B A S I C I N F O
6620====================
6621
6622
6623[+] Site Title: TeenJuniors.com :: welcome to the Juniors index ::
6624[+] IP address: 95.211.5.91
6625[+] Web Server: Apache
6626[+] CMS: Could Not Detect
6627[+] Cloudflare: Not Detected
6628[+] Robots File: Found
6629
6630-------------[ contents ]----------------
6631User-Agent: *
6632Allow: /
6633-----------[end of contents]-------------
6634
6635
6636
6637W H O I S L O O K U P
6638========================
6639
6640 Domain Name: TEENJUNIORS.COM
6641 Registry Domain ID: 1495083595_DOMAIN_COM-VRSN
6642 Registrar WHOIS Server: whois.godaddy.com
6643 Registrar URL: http://www.godaddy.com
6644 Updated Date: 2017-06-17T10:21:56Z
6645 Creation Date: 2008-06-16T17:51:19Z
6646 Registry Expiry Date: 2018-06-16T17:51:19Z
6647 Registrar: GoDaddy.com, LLC
6648 Registrar IANA ID: 146
6649 Registrar Abuse Contact Email: abuse@godaddy.com
6650 Registrar Abuse Contact Phone: 480-624-2505
6651 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
6652 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
6653 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6654 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
6655 Name Server: NS09.DOMAINCONTROL.COM
6656 Name Server: NS10.DOMAINCONTROL.COM
6657
6658
6659G E O I P L O O K U P
6660=========================
6661
6662[i] IP Address: 95.211.5.91
6663[i] Country: NL
6664[i] State: N/A
6665[i] City: N/A
6666[i] Latitude: 52.382401
6667[i] Longitude: 4.899500
6668
6669
6670
6671
6672H T T P H E A D E R S
6673=======================
6674
6675
6676[i] HTTP/1.1 200 OK
6677[i] Date: Tue, 29 Aug 2017 05:18:47 GMT
6678[i] Server: Apache
6679[i] X-Powered-By: PHP/5.2.4-2ubuntu5.26
6680[i] Connection: close
6681[i] Content-Type: text/html
6682
6683
6684
6685
6686D N S L O O K U P
6687===================
6688
6689teenjuniors.com. 1781 IN A 95.211.5.91
6690teenjuniors.com. 3600 IN NS ns09.domaincontrol.com.
6691teenjuniors.com. 3600 IN NS ns10.domaincontrol.com.
6692teenjuniors.com. 3600 IN SOA ns09.domaincontrol.com. dns.jomax.net. 2016050200 28800 7200 604800 3600
6693teenjuniors.com. 1800 IN MX 0 91.kaasserver.com.
6694
6695
6696
6697
6698S U B N E T C A L C U L A T I O N
6699====================================
6700
6701Address = 95.211.5.91
6702Network = 95.211.5.91 / 32
6703Netmask = 255.255.255.255
6704Broadcast = not needed on Point-to-Point links
6705Wildcard Mask = 0.0.0.0
6706Hosts Bits = 0
6707Max. Hosts = 1 (2^0 - 0)
6708Host Range = { 95.211.5.91 - 95.211.5.91 }
6709
6710
6711
6712N M A P P O R T S C A N
6713============================
6714
6715
6716Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 05:18 UTC
6717Nmap scan report for teenjuniors.com (95.211.5.91)
6718Host is up (0.11s latency).
6719rDNS record for 95.211.5.91: 91.kaasserver.com
6720PORT STATE SERVICE VERSION
672121/tcp closed ftp
672222/tcp closed ssh
672323/tcp closed telnet
672425/tcp open smtp Postfix smtpd
672580/tcp open http Apache httpd
6726110/tcp closed pop3
6727143/tcp closed imap
6728443/tcp closed https
6729445/tcp filtered microsoft-ds
67303389/tcp closed ms-wbt-server
6731Service Info: Host: mx01.kaasserver.com
6732
6733Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6734Nmap done: 1 IP address (1 host up) scanned in 8.41 seconds
6735
6736
6737
6738S U B - D O M A I N F I N D E R
6739==================================
6740
6741
6742[i] Total Subdomains Found : 2
6743
6744[+] Subdomain: teenjuniors.com
6745[-] IP: 95.211.5.91
6746
6747[+] Subdomain: www.teenjuniors.comwww.teenjuniors.com
6748[-] IP: 95.211.5.91
6749
6750
6751
6752
6753
6754R E V E R S E I P L O O K U P
6755==================================
6756
6757
6758[i] Total Sites Found On This Server : 78
6759
6760
6761[#] 91.kaasserver.com
6762[-] CMS: Could Not Detect
6763
6764[#] amateur.nextdoorteen18.net
6765[-] CMS: Could Not Detect
6766
6767[#] carina.girly-shoot.com
6768[-] CMS: Could Not Detect
6769
6770[#] chloe.nextdoorteen18.net
6771[-] CMS: Could Not Detect
6772
6773[#] daphne.youngamateur18.com
6774[-] CMS: Could Not Detect
6775
6776[#] eileen.girly-shoot.com
6777[-] CMS: Could Not Detect
6778
6779[#] elena.nextdoorteen18.net
6780[-] CMS: Could Not Detect
6781
6782[#] eva.girly-shoot.com
6783[-] CMS: Could Not Detect
6784
6785[#] evita.girly-shoot.com
6786[-] CMS: Could Not Detect
6787
6788[#] evita.nextdoorteen18.net
6789[-] CMS: Could Not Detect
6790
6791[#] evita.toptinygirls.com
6792[-] CMS: Could Not Detect
6793
6794[#] fee.nextdoorteen18.net
6795[-] CMS: Could Not Detect
6796
6797[#] fhg.247teencash.net
6798[-] CMS: Could Not Detect
6799
6800[#] fiona.girly-shoot.com
6801[-] CMS: Could Not Detect
6802
6803[#] girly-center.com
6804[-] CMS: Could Not Detect
6805
6806[#] girly-shoot.com
6807[-] CMS: Could Not Detect
6808
6809[#] girlytop.com
6810[-] CMS: Could Not Detect
6811
6812[#] image-ressource.com
6813[-] CMS: Could Not Detect
6814
6815[#] indira.girly-shoot.com
6816[-] CMS: Could Not Detect
6817
6818[#] janina.girly-shoot.com
6819[-] CMS: Could Not Detect
6820
6821[#] jenny.girly-shoot.com
6822[-] CMS: Could Not Detect
6823
6824[#] kaasserver.com
6825[-] CMS: Could Not Detect
6826
6827[#] kira.nextdoorteen18.net
6828[-] CMS: Could Not Detect
6829
6830[#] liane.girly-shoot.com
6831[-] CMS: Could Not Detect
6832
6833[#] liane.nextdoorteen18.net
6834[-] CMS: Could Not Detect
6835
6836[#] lilli.youngamateur18.com
6837[-] CMS: Could Not Detect
6838
6839[#] lisa.girly-shoot.com
6840[-] CMS: Could Not Detect
6841
6842[#] manja.girly-shoot.com
6843[-] CMS: Could Not Detect
6844
6845[#] marina.girly-shoot.com
6846[-] CMS: Could Not Detect
6847
6848[#] master-shoot.com
6849[-] CMS: Could Not Detect
6850
6851[#] masterpass.youngamateur18.com
6852[-] CMS: Could Not Detect
6853
6854[#] melissa.youngamateur18.com
6855[-] CMS: Could Not Detect
6856
6857[#] nadja.girly-shoot.com
6858[-] CMS: Could Not Detect
6859
6860[#] nelly.girly-shoot.com
6861[-] CMS: Could Not Detect
6862
6863[#] newsletter.nextdoorteen18.net
6864[-] CMS: Could Not Detect
6865
6866[#] nextdoorteen18.net
6867[-] CMS: Could Not Detect
6868
6869[#] nnjuniors.net
6870[-] CMS: Could Not Detect
6871
6872[#] potd.247teencash.net
6873[-] CMS: Could Not Detect
6874
6875[#] potd.image-ressource.com
6876[-] CMS: Could Not Detect
6877
6878[#] private-model.net
6879[-] CMS: Could Not Detect
6880
6881[#] pvc.nextdoorteen18.net
6882[-] CMS: Could Not Detect
6883
6884[#] samantha.youngamateur18.com
6885[-] CMS: Could Not Detect
6886
6887[#] sandy.girly-shoot.com
6888[-] CMS: Could Not Detect
6889
6890[#] sarah.girly-shoot.com
6891[-] CMS: Could Not Detect
6892
6893[#] sarina.girly-shoot.com
6894[-] CMS: Could Not Detect
6895
6896[#] sasha.girly-shoot.com
6897[-] CMS: Could Not Detect
6898
6899[#] shirley.youngamateur18.com
6900[-] CMS: Could Not Detect
6901
6902[#] sophie.nextdoorteen18.net
6903[-] CMS: Could Not Detect
6904
6905[#] support.247teencash.net
6906[-] CMS: Could Not Detect
6907
6908[#] teen-tickets.com
6909[-] CMS: Could Not Detect
6910
6911[#] teenjuniors.com
6912[-] CMS: Could Not Detect
6913
6914[#] tonja.girly-shoot.com
6915[-] CMS: Could Not Detect
6916
6917[#] toptinygirls.com
6918[-] CMS: Could Not Detect
6919
6920[#] uk2serve.com
6921[-] CMS: Could Not Detect
6922
6923[#] uk2serve.net
6924[-] CMS: Could Not Detect
6925
6926[#] veronique.youngamateur18.com
6927[-] CMS: Could Not Detect
6928
6929[#] wild-tatjana.com
6930[-] CMS: Could Not Detect
6931
6932[#] www.247teencash.net
6933[-] CMS: Could Not Detect
6934
6935[#] www.girly-center.com
6936[-] CMS: Could Not Detect
6937
6938[#] www.girly-shoot.com
6939[-] CMS: Could Not Detect
6940
6941[#] www.girlytop.com
6942[-] CMS: Could Not Detect
6943
6944[#] www.master-shoot.com
6945[-] CMS: Could Not Detect
6946
6947[#] www.nnjuniors.net
6948[-] CMS: Could Not Detect
6949
6950[#] www.northerntool.com
6951[-] CMS: Could Not Detect
6952
6953[#] www.private-model.net
6954[-] CMS: Could Not Detect
6955
6956[#] www.teen-tickets.com
6957[-] CMS: Could Not Detect
6958
6959[#] www.teenjuniors.com
6960[-] CMS: Could Not Detect
6961
6962[#] www.toptinygirls.com
6963[-] CMS: Could Not Detect
6964
6965[#] www.youngbodylist.com
6966[-] CMS: Could Not Detect
6967
6968[#] www.zora-shoot.com
6969[-] CMS: Could Not Detect
6970
6971[#] young.toptinygirls.com
6972[-] CMS: Could Not Detect
6973
6974[#] youngamateur18.com
6975[-] CMS: Could Not Detect
6976
6977[#] youngbodylist.com
6978[-] CMS: Could Not Detect
6979
6980[#] zarina.girly-shoot.com
6981[-] CMS: Could Not Detect
6982
6983[#] zoe.girly-shoot.com
6984[-] CMS: Could Not Detect
6985
6986[#] zoe.nextdoorteen18.net
6987[-] CMS: Could Not Detect
6988
6989[#] zora-shoot.com
6990[-] CMS: Could Not Detect
6991
6992[#] zora.girly-shoot.com,
6993[-] CMS: Could Not Detect
6994---------------------------------------------------------------------------
6995+ Target IP: 95.211.5.91
6996+ Target Hostname: teenjuniors.com
6997+ Target Port: 80
6998+ Start Time: 2017-08-29 01:18:10 (GMT-4)
6999---------------------------------------------------------------------------
7000+ Server: Apache
7001+ Retrieved x-powered-by header: PHP/5.2.4-2ubuntu5.26
7002+ The anti-clickjacking X-Frame-Options header is not present.
7003+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
7004+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
7005+ Server leaks inodes via ETags, header found with file /robots.txt, inode: 2952797935, size: 22, mtime: Mon Nov 3 18:00:00 2008
7006+ "robots.txt" contains 1 entry which should be manually viewed.
7007+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
7008+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
7009+ OSVDB-3092: /sitemap.xml: This gives a nice listing of the site content.
7010+ OSVDB-12184: /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
7011+ OSVDB-12184: /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
7012+ OSVDB-12184: /?=PHPE9568F34-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
7013+ OSVDB-12184: /?=PHPE9568F35-D428-11d2-A769-00AA001ACF42: PHP reveals potentially sensitive information via certain HTTP requests that contain specific QUERY strings.
7014+ OSVDB-3268: /icons/: Directory indexing found.
7015+ OSVDB-3233: /icons/README: Apache default file found.
7016+ 8257 requests: 0 error(s) and 15 item(s) reported on remote host
7017+ End Time: 2017-08-29 02:27:53 (GMT-4) (4183 seconds)
7018##############################################################################################################################################################################################################################################################################