· 8 years ago · Dec 19, 2017, 03:04 AM
1#######################################################################################################################################
2Nom de l'hôte learn.nlpplus.co.il FAI 012 Smile Communications LTD. (AS9116)
3Continent Asie Drapeau
4IL
5Pays Israël Code du pays IL (ISR)
6Région Inconnu Heure locale 16 Dec 2017 07:17 IST
7Ville Inconnu Latitude 31.5
8Adresse IP 62.128.59.127 Longitude 34.75
9#######################################################################################################################################
10[i] Scanning Site: http://learn.nlpplus.co.il
11
12
13
14B A S I C I N F O
15====================
16
17
18[+] Site Title: NLP PLUS - WishList
19[+] IP address: 62.128.59.127
20[+] Web Server: Apache/6.6.6 mod_fcgid/2.3.9
21[+] CMS: WordPress
22[+] Cloudflare: Not Detected
23[+] Robots File: Found
24
25-------------[ contents ]----------------
26User-agent: *
27Disallow: /
28
29-----------[end of contents]-------------
30
31
32
33W H O I S L O O K U P
34========================
35
36
37% The data in the WHOIS database of the .il registry is provided
38% by ISOC-IL for information purposes, and to assist persons in
39% obtaining information about or related to a domain name
40% registration record. ISOC-IL does not guarantee its accuracy.
41% By submitting a WHOIS query, you agree that you will use this
42% Data only for lawful purposes and that, under no circumstances
43% will you use this Data to: (1) allow, enable, or otherwise
44% support the transmission of mass unsolicited, commercial
45% advertising or solicitations via e-mail (spam);
46% or (2) enable high volume, automated, electronic processes that
47% apply to ISOC-IL (or its systems).
48% ISOC-IL reserves the right to modify these terms at any time.
49% By submitting this query, you agree to abide by this policy.
50
51% No data was found to match the request criteria.
52
53
54% Rights to the data above are restricted by copyright.
55
56
57
58
59G E O I P L O O K U P
60=========================
61
62[i] IP Address: 62.128.59.127
63[i] Country: IL
64[i] State: HaMerkaz
65[i] City: Yavne
66[i] Latitude: 31.815599
67[i] Longitude: 34.720798
68
69
70
71
72H T T P H E A D E R S
73=======================
74
75
76[i] HTTP/1.0 200 OK
77[i] Date: Sat, 16 Dec 2017 05:48:23 GMT
78[i] Server: Apache/6.6.6 mod_fcgid/2.3.9
79[i] Link: <http://learn.nlpplus.co.il/wp-json/>; rel="https://api.w.org/"
80[i] Link: <http://learn.nlpplus.co.il/>; rel=shortlink
81[i] Vary: Accept-Encoding,User-Agent
82[i] Connection: close
83[i] Content-Type: text/html; charset=UTF-8
84
85
86
87
88D N S L O O K U P
89===================
90
91learn.nlpplus.co.il. 14399 IN SOA ns1.spd.co.il. hostmaster.learn.nlpplus.co.il. 2016060801 14400 3600 1209600 86400
92learn.nlpplus.co.il. 14399 IN NS ns2.spd.co.il.
93learn.nlpplus.co.il. 14399 IN NS ns1.spd.co.il.
94learn.nlpplus.co.il. 14399 IN A 62.128.59.127
95learn.nlpplus.co.il. 14399 IN MX 10 mailgw2.spd.co.il.
96learn.nlpplus.co.il. 14399 IN TXT "v=spf1 a mx ip4:62.128.59.127 ~all"
97
98
99
100
101S U B N E T C A L C U L A T I O N
102====================================
103
104Address = 62.128.59.127
105Network = 62.128.59.127 / 32
106Netmask = 255.255.255.255
107Broadcast = not needed on Point-to-Point links
108Wildcard Mask = 0.0.0.0
109Hosts Bits = 0
110Max. Hosts = 1 (2^0 - 0)
111Host Range = { 62.128.59.127 - 62.128.59.127 }
112
113
114
115N M A P P O R T S C A N
116============================
117
118
119Starting Nmap 7.01 ( https://nmap.org ) at 2017-12-16 05:48 UTC
120Nmap scan report for learn.nlpplus.co.il (62.128.59.127)
121Host is up (0.14s latency).
122rDNS record for 62.128.59.127: imarkvps2.spd.co.il
123PORT STATE SERVICE VERSION
12421/tcp open ftp ProFTPD
12522/tcp filtered ssh
12623/tcp closed telnet
12725/tcp open smtp Exim smtpd
12880/tcp open http Apache httpd 6.6.6 (mod_fcgid/2.3.9)
129110/tcp open pop3 Dovecot DirectAdmin pop3d
130143/tcp open imap Dovecot imapd
131443/tcp open ssl/http Apache httpd 6.6.6 (mod_fcgid/2.3.9)
132445/tcp closed microsoft-ds
1333389/tcp closed ms-wbt-server
134
135Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
136Nmap done: 1 IP address (1 host up) scanned in 16.29 seconds
137
138[!] IP Address : 62.128.59.127
139[!] Server: Apache/6.6.6 mod_fcgid/2.3.9
140[-] Clickjacking protection is not in place.
141[+] Operating System : Windows
142[!] learn.nlpplus.co.il doesn't seem to use a CMS
143[+] Honeypot Probabilty: 30%
144----------------------------------------
145[+] Robots.txt retrieved
146User-agent: *
147Disallow: /
148
149----------------------------------------
150PORT STATE SERVICE VERSION
15121/tcp open ftp ProFTPD
15222/tcp filtered ssh
15323/tcp closed telnet
15425/tcp open smtp Exim smtpd
15580/tcp open http Apache httpd 6.6.6 (mod_fcgid/2.3.9)
156110/tcp open pop3 Dovecot DirectAdmin pop3d
157143/tcp open imap Dovecot imapd
158443/tcp open ssl/http Apache httpd 6.6.6 (mod_fcgid/2.3.9)
159445/tcp closed microsoft-ds
1603389/tcp closed ms-wbt-server
161----------------------------------------
162
163[+] DNS Records
164ns2.spd.co.il. (80.179.148.8) AS9116 012 Smile Communications LTD. Israel
165ns1.spd.co.il. (212.199.164.175) AS9116 012 Smile Communications LTD. Israel
166
167[+] MX Records
16810 (192.116.71.71) AS9116 012 Smile Communications LTD. Israel
169
170[+] Host Records (A)
171learn.nlpplus.co.ilHTTP: (imarkvps2.spd.co.il) (62.128.59.127) AS9116 012 Smile Communications LTD. Israel
172
173[+] TXT Records
174"v=spf1 a mx ip4:62.128.59.127 ~all"
175
176[+] DNS Map: https://dnsdumpster.com/static/map/learn.nlpplus.co.il.png
177
178[>] Initiating 3 intel modules
179[>] Loading Alpha module (1/3)
180[>] Beta module deployed (2/3)
181[>] Gamma module initiated (3/3)
182No emails found
183No hosts found
184[+] Virtual hosts:
185-----------------
186[>] Crawling the target for fuzzable URLs
187[-] No fuzzable URLs found
188[+] URL: http://learn.nlpplus.co.il/
189[+] Started: Sat Dec 16 00:53:43 2017
190
191[+] robots.txt available under: 'http://learn.nlpplus.co.il/robots.txt'
192[!] The WordPress 'http://learn.nlpplus.co.il/readme.html' file exists exposing a version number
193[+] Interesting header: LINK: <http://learn.nlpplus.co.il/wp-json/>; rel="https://api.w.org/"
194[+] Interesting header: LINK: <http://learn.nlpplus.co.il/>; rel=shortlink
195[+] Interesting header: SERVER: Apache/6.6.6 mod_fcgid/2.3.9
196
197[+] WordPress version 4.5.12 (Released on 2017-11-29) identified from meta generator, links opml
198
199[+] WordPress theme in use: simplemag-child
200
201[+] Name: simplemag-child
202 | Location: http://learn.nlpplus.co.il/wp-content/themes/simplemag-child/
203 | Style URL: http://learn.nlpplus.co.il/wp-content/themes/simplemag-child/style.css
204 | Theme Name: SimpleMag
205 | Theme URI: http://themesindep.com/
206 | Description: Magazine theme for creative things
207 | Author: ThemesIndep
208 | Author URI: http://themesindep.com/
209
210[+] Detected parent theme: simplemag - v3.0.4
211
212[+] Name: simplemag - v3.0.4
213 | Location: http://learn.nlpplus.co.il/wp-content/themes/simplemag/
214 | Style URL: http://learn.nlpplus.co.il/wp-content/themes/simplemag/style.css
215 | Theme Name: SimpleMag
216 | Theme URI: http://themesindep.com/
217 | Description: Magazine theme for creative things
218 | Author: ThemesIndep
219 | Author URI: http://themesindep.com/
220
221[+] Enumerating plugins from passive detection ...
222 | 2 plugins found:
223
224[+] Name: contact-form-7 - v4.4.2
225 | Last updated: 2017-12-09T07:32:00.000Z
226 | Location: http://learn.nlpplus.co.il/wp-content/plugins/contact-form-7/
227 | Readme: http://learn.nlpplus.co.il/wp-content/plugins/contact-form-7/readme.txt
228[!] The version is out of date, the latest version is 4.9.2
229
230[+] Name: wordpress-seo - v3.2.5
231 | Last updated: 2017-12-05T11:24:00.000Z
232 | Location: http://learn.nlpplus.co.il/wp-content/plugins/wordpress-seo/
233 | Readme: http://learn.nlpplus.co.il/wp-content/plugins/wordpress-seo/readme.txt
234 | Changelog: http://learn.nlpplus.co.il/wp-content/plugins/wordpress-seo/changelog.txt
235[!] The version is out of date, the latest version is 5.9.1
236
237[!] Title: Yoast SEO <= 3.2.5 - Unspecified Cross-Site Scripting (XSS)
238 Reference: https://wpvulndb.com/vulnerabilities/8569
239 Reference: https://wordpress.org/plugins/wordpress-seo/changelog/
240[i] Fixed in: 3.3.0
241
242[!] Title: Yoast SEO <= 3.4.0 - Authenticated Stored Cross-Site Scripting (XSS)
243 Reference: https://wpvulndb.com/vulnerabilities/8583
244 Reference: https://plugins.trac.wordpress.org/changeset/1466243/wordpress-seo
245[i] Fixed in: 3.4.1
246
247[!] Title: Yoast SEO <= 5.7.1 - Unauthenticated Cross-Site Scripting (XSS)
248 Reference: https://wpvulndb.com/vulnerabilities/8960
249 Reference: https://plugins.trac.wordpress.org/changeset/1766831/wordpress-seo/trunk/admin/google_search_console/class-gsc-table.php
250 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16842
251[i] Fixed in: 5.8
252
253[+] Finished: Sat Dec 16 01:17:20 2017
254[+] Requests Done: 370
255[+] Memory used: 70.535 MB
256[+] Elapsed time: 00:23:36
257[92m + -- ----------------------------=[Running Nslookup]=------------------------ -- +[0m
258Server: 2001:568:ff09:10c::53
259Address: 2001:568:ff09:10c::53#53
260
261Non-authoritative answer:
262Name: learn.nlpplus.co.il
263Address: 62.128.59.127
264
265learn.nlpplus.co.il has address 62.128.59.127
266learn.nlpplus.co.il mail is handled by 10 mailgw2.spd.co.il.
267[92m + -- ----------------------------=[Checking OS Fingerprint]=----------------- -- +[0m
268
269Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor@o0o.nu, ofir@sys-security.com, meder@o0o.nu
270
271[+] Target is learn.nlpplus.co.il
272[+] Loading modules.
273[+] Following modules are loaded:
274[x] [1] ping:icmp_ping - ICMP echo discovery module
275[x] [2] ping:tcp_ping - TCP-based ping discovery module
276[x] [3] ping:udp_ping - UDP-based ping discovery module
277[x] [4] infogather:ttl_calc - TCP and UDP based TTL distance calculation
278[x] [5] infogather:portscan - TCP and UDP PortScanner
279[x] [6] fingerprint:icmp_echo - ICMP Echo request fingerprinting module
280[x] [7] fingerprint:icmp_tstamp - ICMP Timestamp request fingerprinting module
281[x] [8] fingerprint:icmp_amask - ICMP Address mask request fingerprinting module
282[x] [9] fingerprint:icmp_port_unreach - ICMP port unreachable fingerprinting module
283[x] [10] fingerprint:tcp_hshake - TCP Handshake fingerprinting module
284[x] [11] fingerprint:tcp_rst - TCP RST fingerprinting module
285[x] [12] fingerprint:smb - SMB fingerprinting module
286[x] [13] fingerprint:snmp - SNMPv2c fingerprinting module
287[+] 13 modules registered
288[+] Initializing scan engine
289[+] Running scan engine
290[-] ping:tcp_ping module: no closed/open TCP ports known on 62.128.59.127. Module test failed
291[-] ping:udp_ping module: no closed/open UDP ports known on 62.128.59.127. Module test failed
292[-] No distance calculation. 62.128.59.127 appears to be dead or no ports known
293[+] Host: 62.128.59.127 is up (Guess probability: 50%)
294[+] Target: 62.128.59.127 is alive. Round-Trip Time: 0.49971 sec
295[+] Selected safe Round-Trip Time value is: 0.99942 sec
296[-] fingerprint:tcp_hshake Module execution aborted (no open TCP ports known)
297[-] fingerprint:smb need either TCP port 139 or 445 to run
298[+] Primary guess:
299[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
300[+] Other guesses:
301[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
302[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
303[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
304[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
305[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
306[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
307[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
308[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
309[+] Host 62.128.59.127 Running OS: PÅ'ñU (Guess probability: 95%)
310[+] Cleaning up scan engine
311[+] Modules deinitialized
312[+] Execution completed.
313[92m + -- ----------------------------=[Gathering Whois Info]=-------------------- -- +[0m
314
315% The data in the WHOIS database of the .il registry is provided
316% by ISOC-IL for information purposes, and to assist persons in
317% obtaining information about or related to a domain name
318% registration record. ISOC-IL does not guarantee its accuracy.
319% By submitting a WHOIS query, you agree that you will use this
320% Data only for lawful purposes and that, under no circumstances
321% will you use this Data to: (1) allow, enable, or otherwise
322% support the transmission of mass unsolicited, commercial
323% advertising or solicitations via e-mail (spam);
324% or (2) enable high volume, automated, electronic processes that
325% apply to ISOC-IL (or its systems).
326% ISOC-IL reserves the right to modify these terms at any time.
327% By submitting this query, you agree to abide by this policy.
328
329% No data was found to match the request criteria.
330
331
332% Rights to the data above are restricted by copyright.
333[92m + -- ----------------------------=[Gathering OSINT Info]=-------------------- -- +[0m
334
335*******************************************************************
336* *
337* | |_| |__ ___ /\ /\__ _ _ ____ _____ ___| |_ ___ _ __ *
338* | __| '_ \ / _ \ / /_/ / _` | '__\ \ / / _ \/ __| __/ _ \ '__| *
339* | |_| | | | __/ / __ / (_| | | \ V / __/\__ \ || __/ | *
340* \__|_| |_|\___| \/ /_/ \__,_|_| \_/ \___||___/\__\___|_| *
341* *
342* TheHarvester Ver. 2.7 *
343* Coded by Christian Martorella *
344* Edge-Security Research *
345* cmartorella@edge-security.com *
346*******************************************************************
347
348
349Full harvest..
350[-] Searching in Google..
351 Searching 0 results...
352 Searching 100 results...
353 Searching 200 results...
354[-] Searching in PGP Key server..
355[-] Searching in Bing..
356 Searching 50 results...
357
358******************************************************
359* /\/\ ___| |_ __ _ __ _ ___ ___ / _(_) | *
360* / \ / _ \ __/ _` |/ _` |/ _ \ / _ \| |_| | | *
361* / /\/\ \ __/ || (_| | (_| | (_) | (_) | _| | | *
362* \/ \/\___|\__\__,_|\__, |\___/ \___/|_| |_|_| *
363* |___/ *
364* Metagoofil Ver 2.2 *
365* Christian Martorella *
366* Edge-Security.com *
367* cmartorella_at_edge-security.com *
368******************************************************
369
370[-] Starting online search...
371
372[-] Searching for doc files, with a limit of 200
373 Searching 100 results...
374 Searching 200 results...
375Results: 0 files found
376Starting to download 50 of them:
377----------------------------------------
378
379
380[-] Searching for pdf files, with a limit of 200
381 Searching 100 results...
382 Searching 200 results...
383Results: 0 files found
384Starting to download 50 of them:
385----------------------------------------
386
387
388[-] Searching for xls files, with a limit of 200
389 Searching 100 results...
390 Searching 200 results...
391Results: 0 files found
392Starting to download 50 of them:
393----------------------------------------
394
395
396[-] Searching for csv files, with a limit of 200
397 Searching 100 results...
398 Searching 200 results...
399Results: 0 files found
400Starting to download 50 of them:
401----------------------------------------
402
403
404[-] Searching for txt files, with a limit of 200
405 Searching 100 results...
406 Searching 200 results...
407Results: 0 files found
408Starting to download 50 of them:
409----------------------------------------
410
411processing
412user
413email
414
415[+] List of users found:
416--------------------------
417
418[+] List of software found:
419-----------------------------
420
421[+] List of paths and servers found:
422---------------------------------------
423
424[+] List of e-mails found:
425----------------------------
426[92m + -- ----------------------------=[Gathering DNS Info]=---------------------- -- +[0m
427
428; <<>> DiG 9.11.2-4-Debian <<>> -x learn.nlpplus.co.il
429;; global options: +cmd
430;; Got answer:
431;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 60816
432;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
433
434;; OPT PSEUDOSECTION:
435; EDNS: version: 0, flags:; udp: 4096
436;; QUESTION SECTION:
437;il.co.nlpplus.learn.in-addr.arpa. IN PTR
438
439;; AUTHORITY SECTION:
440in-addr.arpa. 3600 IN SOA b.in-addr-servers.arpa. nstld.iana.org. 2017102477 1800 900 604800 3600
441
442;; Query time: 391 msec
443;; SERVER: 2001:568:ff09:10c::53#53(2001:568:ff09:10c::53)
444;; WHEN: Sat Dec 16 00:51:23 EST 2017
445;; MSG SIZE rcvd: 129
446
447dnsenum VERSION:1.2.4
448[1;34m
449----- learn.nlpplus.co.il -----
450[0m[1;31m
451
452Host's addresses:
453__________________
454
455[0mlearn.nlpplus.co.il. 12360 IN A 62.128.59.127
456[1;31m
457
458Name Servers:
459______________
460
461[0mns2.spd.co.il. 36331 IN A 80.179.148.8
462ns1.spd.co.il. 1924 IN A 212.199.164.175
463[1;31m
464
465Mail (MX) Servers:
466___________________
467
468[0mmailgw2.spd.co.il. 38400 IN A 192.116.71.71
469[1;31m
470
471Trying Zone Transfers and getting Bind Versions:
472_________________________________________________
473
474[0m
475Trying Zone Transfer for learn.nlpplus.co.il on ns2.spd.co.il ...
476
477Trying Zone Transfer for learn.nlpplus.co.il on ns1.spd.co.il ...
478
479brute force file not specified, bay.
480[92m + -- ----------------------------=[Gathering DNS Subdomains]=---------------- -- +[0m
481[91m
482 ____ _ _ _ _ _____
483 / ___| _ _| |__ | (_)___| |_|___ / _ __
484 \___ \| | | | '_ \| | / __| __| |_ \| '__|
485 ___) | |_| | |_) | | \__ \ |_ ___) | |
486 |____/ \__,_|_.__/|_|_|___/\__|____/|_|[0m[93m
487
488 # Coded By Ahmed Aboul-Ela - @aboul3la
489
490[94m[-] Enumerating subdomains now for learn.nlpplus.co.il[0m
491[93m[-] verbosity is enabled, will show the subdomains results in realtime[0m
492[92m[-] Searching now in Baidu..[0m
493[92m[-] Searching now in Yahoo..[0m
494[92m[-] Searching now in Google..[0m
495[92m[-] Searching now in Bing..[0m
496[92m[-] Searching now in Ask..[0m
497[92m[-] Searching now in Netcraft..[0m
498[92m[-] Searching now in DNSdumpster..[0m
499[92m[-] Searching now in Virustotal..[0m
500[92m[-] Searching now in ThreatCrowd..[0m
501[92m[-] Searching now in SSL Certificates..[0m
502[92m[-] Searching now in PassiveDNS..[0m
503
504[91m ╔â•Â╗╩â•Â╗╔╩╗╔â•Â╗╩╩[0m
505[91m ║ ╠╩╠║ ╚â•Â╗╠â•Â╣[0m
506[91m ╚â•Ââ•Â╩╚╠╩o╚â•Ââ•Â╩ ╩[0m
507[91m + -- ----------------------------=[Gathering Certificate Subdomains]=-------- -- +[0m
508[94m
509[91m [+] Domains saved to: /usr/share/sniper/loot/domains/domains-learn.nlpplus.co.il-full.txt
510[0m
511[92m + -- ----------------------------=[Checking for Sub-Domain Hijacking]=------- -- +[0m
512[92m + -- ----------------------------=[Checking Email Security]=----------------- -- +[0m
513
514[92m + -- ----------------------------=[Pinging host]=---------------------------- -- +[0m
515PING learn.nlpplus.co.il (62.128.59.127) 56(84) bytes of data.
51664 bytes from imarkvps2.spd.co.il (62.128.59.127): icmp_seq=1 ttl=53 time=682 ms
517
518--- learn.nlpplus.co.il ping statistics ---
5191 packets transmitted, 1 received, 0% packet loss, time 0ms
520rtt min/avg/max/mdev = 682.158/682.158/682.158/0.000 ms
521
522[92m + -- ----------------------------=[Running TCP port scan]=------------------- -- +[0m
523
524Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-16 00:53 EST
525Warning: 62.128.59.127 giving up on port because retransmission cap hit (2).
526Nmap scan report for learn.nlpplus.co.il (62.128.59.127)
527Host is up (0.29s latency).
528rDNS record for 62.128.59.127: imarkvps2.spd.co.il
529Not shown: 397 closed ports, 66 filtered ports
530Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
531PORT STATE SERVICE
53221/tcp open ftp
53353/tcp open domain
53480/tcp open http
535110/tcp open pop3
536143/tcp open imap
537443/tcp open https
538993/tcp open imaps
539995/tcp open pop3s
5402222/tcp open EtherNetIP-1
5415353/tcp open mdns
542
543Nmap done: 1 IP address (1 host up) scanned in 17.78 seconds
544
545[92m + -- ----------------------------=[Running Intrusive Scans]=----------------- -- +[0m
546[93m + -- --=[Port 21 opened... running tests...[0m
547
548Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-16 00:53 EST
549Nmap scan report for learn.nlpplus.co.il (62.128.59.127)
550Host is up (0.92s latency).
551rDNS record for 62.128.59.127: imarkvps2.spd.co.il
552
553PORT STATE SERVICE VERSION
55421/tcp filtered ftp
555Too many fingerprints match this host to give specific OS details
556Network Distance: 14 hops
557
558TRACEROUTE (using proto 1/icmp)
559HOP RTT ADDRESS
5601 913.15 ms 10.13.0.1
5612 916.68 ms 37.187.24.253
5623 919.57 ms 10.50.225.61
5634 606.99 ms 10.17.129.46
5645 603.52 ms 10.73.0.52
5656 ...
5667 614.28 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
5678 620.02 ms be100-2.ldn-5-a9.uk.eu (213.251.130.122)
5689 610.53 ms edge.lon-01012.net.il (195.66.225.114)
56910 626.02 ms EDGE-LON-MX-01-ae0-102.ip4.012.net.il (80.179.165.105)
57011 ...
57112 643.53 ms 82.102.132.157
57213 636.81 ms 62.128.59.2.static.hosting.spd.co.il (62.128.59.2)
57314 920.15 ms imarkvps2.spd.co.il (62.128.59.127)
574
575OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
576Nmap done: 1 IP address (1 host up) scanned in 27.38 seconds
577[0m[36m[1m[37m
578 . .
579 .
580
581 [34mdBBBBBBb dBBBP dBBBBBBP dBBBBBb [37m. o
582 [34m ' dB' BBP
583 dB'dB'dB' dBBP dBP dBP BB
584 dB'dB'dB' dBP dBP dBP BB
585 dB'dB'dB' dBBBBP dBP dBBBBBBB
586
587 [31mdBBBBBP [34mdBBBBBb dBP dBBBBP dBP dBBBBBBP
588 [37m. [36m. [34mdB' dBP dB'.BP
589 [36m| [31mdBP[34m dBBBB' dBP dB'.BP dBP dBP
590 [36m--o-- [31mdBP[34m dBP dBP dB'.BP dBP dBP
591 [36m| [31mdBBBBP[34m dBP dBBBBP dBBBBP dBP dBP[37m
592
593 .
594 .
595 o [32mTo boldly go where no
596 shell has gone before
597[0m
598
599 =[ [33mmetasploit v4.16.22-dev[0m ]
600+ -- --=[ 1707 exploits - 970 auxiliary - 299 post ]
601+ -- --=[ 503 payloads - 40 encoders - 10 nops ]
602+ -- --=[ Free Metasploit Pro trial: http://r-7.co/trymsp ]
603
604[0m[0mRHOST => learn.nlpplus.co.il
605[0mRHOSTS => learn.nlpplus.co.il
606[0m[1m[34m[*][0m learn.nlpplus.co.il:21 - Banner: 220 FTP Server
607[1m[34m[*][0m learn.nlpplus.co.il:21 - USER: 331 Password required for fRUnS:)
608[1m[34m[*][0m Exploit completed, but no session was created.
609[0m[0m[1m[33m[!][0m You are binding to a loopback address by setting LHOST to 127.0.0.1. Did you want ReverseListenerBindAddress?
610[1m[34m[*][0m Started reverse TCP double handler on 127.0.0.1:4444
611[1m[34m[*][0m learn.nlpplus.co.il:21 - Sending Backdoor Command
612[1m[31m[-][0m learn.nlpplus.co.il:21 - Not backdoored
613[1m[34m[*][0m Exploit completed, but no session was created.
614[0m[91m + -- --=[Port 22 closed... skipping.[0m
615[91m + -- --=[Port 23 closed... skipping.[0m
616[91m + -- --=[Port 25 closed... skipping.[0m
617[93m + -- --=[Port 53 opened... running tests...[0m
618
619Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-16 00:59 EST
620Nmap scan report for learn.nlpplus.co.il (62.128.59.127)
621Host is up (0.26s latency).
622rDNS record for 62.128.59.127: imarkvps2.spd.co.il
623
624PORT STATE SERVICE VERSION
62553/udp open domain ISC BIND 6.6.6
626|_dns-cache-snoop: 0 of 100 tested domains are cached.
627|_dns-fuzz: Server didn't response to our probe, can't fuzz
628| dns-nsec-enum:
629|_ No NSEC records found
630| dns-nsec3-enum:
631|_ DNSSEC NSEC3 not supported
632| dns-nsid:
633|_ bind.version: 6.6.6
634Too many fingerprints match this host to give specific OS details
635Network Distance: 14 hops
636
637Host script results:
638| dns-brute:
639| DNS Brute-force hostnames:
640| www.nlpplus.co.il - 62.128.59.127
641| mail.nlpplus.co.il - 62.128.59.127
642| ftp.nlpplus.co.il - 62.128.59.127
643|_ smtp.nlpplus.co.il - 62.128.59.127
644
645TRACEROUTE (using proto 1/icmp)
646HOP RTT ADDRESS
6471 881.59 ms 10.13.0.1
6482 888.31 ms 37.187.24.253
6493 799.35 ms 10.50.225.61
6504 802.89 ms 10.17.129.46
6515 795.90 ms 10.73.0.52
6526 ...
6537 810.12 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
6548 826.64 ms be100-2.ldn-5-a9.uk.eu (213.251.130.122)
6559 806.39 ms edge.lon-01012.net.il (195.66.225.114)
65610 815.77 ms EDGE-LON-MX-01-ae0-102.ip4.012.net.il (80.179.165.105)
65711 703.46 ms EDGE-LON-MX-02-so-4-1-0-0.ip4.012.net.il (80.179.165.25)
65812 ...
65913 885.11 ms 62.128.59.2.static.hosting.spd.co.il (62.128.59.2)
66014 888.65 ms imarkvps2.spd.co.il (62.128.59.127)
661
662OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
663Nmap done: 1 IP address (1 host up) scanned in 119.19 seconds
664[91m + -- --=[Port 79 closed... skipping.[0m
665[93m + -- --=[Port 80 opened... running tests...[0m
666[92m + -- ----------------------------=[Checking for WAF]=------------------------ -- +[0m
667
668 ^ ^
669 _ __ _ ____ _ __ _ _ ____
670 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
671 | V V // o // _/ | V V // 0 // 0 // _/
672 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
673 <
674 ...'
675
676 WAFW00F - Web Application Firewall Detection Tool
677
678 By Sandro Gauci && Wendel G. Henrique
679
680Checking http://learn.nlpplus.co.il
681Generic Detection results:
682The site http://learn.nlpplus.co.il seems to be behind a WAF or some sort of security solution
683Reason: The server returned a different response code when a string trigged the blacklist.
684Normal response code is "404", while the response code to an attack is "302"
685Number of requests: 12
686
687[92m + -- ----------------------------=[Gathering HTTP Info]=--------------------- -- +[0m
688[1m[34mhttp://learn.nlpplus.co.il[0m [200 OK] [1m[37mApache[0m[[1m[32m6.6.6[0m][[1m[31mmod_fcgid/2.3.9[0m], [1m[37mCountry[0m[[37mISRAEL[0m][[1m[31mIL[0m], [1m[37mGoogle-Analytics[0m[[1m[32mUniversal[0m][[1m[36mUA-63152966-2[0m], [1m[37mHTML5[0m, [1m[37mHTTPServer[0m[[1m[36mApache/6.6.6 mod_fcgid/2.3.9[0m], [1m[37mIP[0m[[37m62.128.59.127[0m], [1m[37mJQuery[0m[[1m[32m1.12.4[0m], [1m[37mMetaGenerator[0m[[37mWordPress 4.5.12[0m], [1m[37mOpen-Graph-Protocol[0m[[1m[32mwebsite[0m], [1m[37mPasswordField[0m[[37mpwd[0m], [1m[37mPoweredBy[0m[[37mWordPress[0m], [1m[37mScript[0m[[37mapplication/ld+json,text/javascript[0m], [1m[37mTitle[0m[[1m[33mNLP PLUS - WishList[0m], [1m[37mUncommonHeaders[0m[[37mlink[0m], [1m[37mWordPress[0m[[1m[32m4.5.12[0m], [1m[37mX-UA-Compatible[0m[[37mIE=edge[0m]
689
690[94m __ ______ _____ [0m
691[94m \ \/ / ___|_ _|[0m
692[94m \ /\___ \ | | [0m
693[94m / \ ___) || | [0m
694[94m /_/\_|____/ |_| [0m
695
696[94m+ -- --=[Cross-Site Tracer v1.3 by 1N3 @ CrowdShield[0m
697[94m+ -- --=[Target: learn.nlpplus.co.il:80[0m
698
699[92m + -- ----------------------------=[Checking HTTP Headers]=------------------- -- +[0m
700[94m+ -- --=[Checking if X-Content options are enabled on learn.nlpplus.co.il...[0m [93m
701
702[94m+ -- --=[Checking if X-Frame options are enabled on learn.nlpplus.co.il...[0m [93m
703
704[94m+ -- --=[Checking if X-XSS-Protection header is enabled on learn.nlpplus.co.il...[0m [93m
705
706[94m+ -- --=[Checking HTTP methods on learn.nlpplus.co.il...[0m [93m
707
708[94m+ -- --=[Checking if TRACE method is enabled on learn.nlpplus.co.il...[0m [93m
709
710[94m+ -- --=[Checking for META tags on learn.nlpplus.co.il...[0m [93m
711<meta property="og:title" content="NLP PLUS - WishList" />
712<meta property="og:url" content="http://learn.nlpplus.co.il/" />
713<meta property="og:site_name" content="WishList" />
714<meta name="twitter:card" content="summary" />
715<meta name="twitter:title" content="NLP PLUS - WishList" />
716<meta name="generator" content="WordPress 4.5.12" />
717.tagline,.sub-title,.menu a,.widget_pages,.widget_categories,.entry-meta,.entry-note,.read-more,#submit,.single .entry-content > p:first-of-type:first-letter,input#s, .widget_ti-about-site p,.comments .vcard, #respond label,.copyright, #wp-calendar tbody,.latest-reviews i,.score-box .total {
718h1, h2, h3, h4, h5, h6, .main-menu a, .secondary-menu a, .widget_pages, .widget_categories, .widget_nav_menu, .tagline, .sub-title, .entry-meta, .entry-note, .read-more, #submit, .ltr .single .entry-content > p:first-of-type:first-letter, input#s, .single-author-box .vcard, .comment-author, .comment-meta, .comment-reply-link, #respond label, .copyright, #wp-calendar tbody, .latest-reviews i, .score-box .total{
719h1, h2, h3, h4, h5, h6, .main-menu a, .secondary-menu a, .widget_pages, .widget_categories, .widget_nav_menu, .tagline, .sub-title, .entry-meta, .entry-note, .read-more, #submit, .ltr .single .entry-content > p:first-of-type:first-letter, input#s, .single-author-box .vcard, .comment-author, .comment-meta, .comment-reply-link, #respond label, .copyright, #wp-calendar tbody, .latest-reviews i, .score-box .total {
720<style type="text/css" title="dynamic-css" class="options-output">h1, h2, h3, h4, h5, h6, .main-menu a, .secondary-menu a, .widget_pages, .widget_categories, .widget_nav_menu, .tagline, .sub-title, .entry-meta, .entry-note, .read-more, #submit, .ltr .single .entry-content > p:first-of-type:first-letter, input#s, .single-author-box .vcard, .comment-author, .comment-meta, .comment-reply-link, #respond label, .copyright, #wp-calendar tbody, .latest-reviews i, .score-box .total{font-family:Oswald;font-weight:700;font-style:normal;}.title-with-sep, .title-with-bg, .classic-layout .entry-title, .posts-slider .entry-title{font-size:48px;}.main-menu > ul > li{font-size:48px;}body{font-family:Lato;font-weight:normal;font-style:normal;font-size:18px;}body, .site-content, .layout-full .title-with-sep .title, .layout-full .title-with-sep .entry-title{background-color:#7bc145;}.entry-image, .paging-navigation .current, .link-pages span, .score-line span, .entry-breakdown .item .score-line, .widget_ti_most_commented span, .all-news-link .read-more{background-color:#05ba38;}.paging-navigation .current, .widget span i, .score-line span i, .all-news-link .read-more{color:#000000;}#masthead, .main-menu-fixed{background-color:transparent;}.top-strip, .secondary-menu .sub-menu, .top-strip #searchform input[type="text"], .top-strip .social li ul{background-color:#f2f2f2;}.secondary-menu a{color:#ffffff;}.secondary-menu a:hover{color:#cccccc;}.secondary-menu li, .top-strip #searchform input[type="text"]{border-color:#333333;}.top-strip .social li a{color:#8c919b;}.main-menu,.sticky-active .main-menu-fixed{background-color:#ffffff;}.main-menu > ul > li > a{color:#000000;}.main-menu > ul > li > a:hover{color:#000000;}.main-menu > ul > li:after{color:#eeeeee;}.main-menu{border-top:1px solid #000;}.main-menu{border-bottom:3px solid #dbdbdb;}.main-menu .sub-menu,.main-menu .sub-menu-two-columns .sub-menu:before{background-color:#2b75bf;}.sub-links li a{color:#000000;}.sub-links li a:hover{color:#ffcc0d;}.main-menu .sub-menu .sub-links a:after{background-color:#1e1e1e;}.main-menu .sub-menu:after{background-color:#242628;}.sub-posts li a{color:#000000;}.sub-posts li a:hover{color:#ffcc0d;}.modern .content-over-image figure:before{background-color:#000000;}.sidebar{border-top:1px solid #000;border-bottom:1px solid #000;border-left:1px solid #000;border-right:1px solid #000;}.slide-dock{background-color:#ffffff;}.slide-dock h3, .slide-dock a, .slide-dock p{color:#8091e5;}.footer-sidebar, .widget_ti_most_commented li a{background-color:#242628;}.footer-sidebar .widget h3{color:#ffcc0d;}.footer-sidebar{color:#8c919b;}.footer-sidebar .widget a{color:#8c919b;}.footer-sidebar .widget a:hover{color:#ffcc0d;}.widget-area-2, .widget-area-3, .footer-sidebar .widget{border-top:1px dotted #585b61;border-bottom:1px dotted #585b61;border-left:1px dotted #585b61;border-right:1px dotted #585b61;}.copyright{background-color:#8091e5;}.copyright, .copyright a{color:#000000;}</style>
721
722[94m+ -- --=[Checking for open proxy on learn.nlpplus.co.il...[0m [93m
723
724[94m+ -- --=[Enumerating software on learn.nlpplus.co.il...[0m [93m
725Server: Apache/6.6.6 mod_fcgid/2.3.9
726
727[94m+ -- --=[Checking if Strict-Transport-Security is enabled on learn.nlpplus.co.il...[0m [93m
728
729[94m+ -- --=[Checking for Flash cross-domain policy on learn.nlpplus.co.il...[0m [93m
730<script type='text/javascript' src='http://learn.nlpplus.co.il/wp-content/themes/simplemag/js/jquery.assets.js?ver=1.0'></script>
731<script type='text/javascript' src='http://learn.nlpplus.co.il/wp-content/themes/simplemag/js/jquery.custom.js?ver=1.0'></script>
732<script type='text/javascript' src='http://learn.nlpplus.co.il/wp-includes/js/wp-embed.min.js?ver=4.5.12'></script>
733
734<script type='text/javascript'>
735 jQuery(function($) {
736 });
737 </script>
738</body>
739</html>
740[94m+ -- --=[Checking for Silverlight cross-domain policy on learn.nlpplus.co.il...[0m [93m
741<script type='text/javascript' src='http://learn.nlpplus.co.il/wp-content/themes/simplemag/js/jquery.assets.js?ver=1.0'></script>
742<script type='text/javascript' src='http://learn.nlpplus.co.il/wp-content/themes/simplemag/js/jquery.custom.js?ver=1.0'></script>
743<script type='text/javascript' src='http://learn.nlpplus.co.il/wp-includes/js/wp-embed.min.js?ver=4.5.12'></script>
744
745<script type='text/javascript'>
746 jQuery(function($) {
747 });
748 </script>
749</body>
750</html>
751[94m+ -- --=[Checking for HTML5 cross-origin resource sharing on learn.nlpplus.co.il...[0m [93m
752
753[94m+ -- --=[Retrieving robots.txt on learn.nlpplus.co.il...[0m [93m
754User-agent: *
755Disallow: /
756
757[94m+ -- --=[Retrieving sitemap.xml on learn.nlpplus.co.il...[0m [93m
758
759[94m+ -- --=[Checking cookie attributes on learn.nlpplus.co.il...[0m [93m
760
761[94m+ -- --=[Checking for ASP.NET Detailed Errors on learn.nlpplus.co.il...[0m [93m
762<body class="rtl error404" itemscope itemtype="http://schema.org/WebPage">
763 <article id="post-0" class="post error404 not-found">
764 <img src="http://learn.nlpplus.co.il/wp-content/themes/simplemag/images/error-page.png" alt="Ooops! That page can not be found" width="402" height="402" />
765 </article><!-- #post-0 .post .error404 .not-found -->
766<body class="rtl error404" itemscope itemtype="http://schema.org/WebPage">
767 <article id="post-0" class="post error404 not-found">
768 <img src="http://learn.nlpplus.co.il/wp-content/themes/simplemag/images/error-page.png" alt="Ooops! That page can not be found" width="402" height="402" />
769 </article><!-- #post-0 .post .error404 .not-found -->
770
771[0m
772[92m + -- ----------------------------=[Running Web Vulnerability Scan]=---------- -- +[0m
773- Nikto v2.1.6
774---------------------------------------------------------------------------
775+ Target IP: 62.128.59.127
776+ Target Hostname: learn.nlpplus.co.il
777+ Target Port: 80
778+ Start Time: 2017-12-16 01:08:48 (GMT-5)
779---------------------------------------------------------------------------
780+ Server: Apache/6.6.6 mod_fcgid/2.3.9
781+ The anti-clickjacking X-Frame-Options header is not present.
782+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
783+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
784+ Root page / redirects to: http://abuse.spd.co.il
785+ No CGI Directories found (use '-C all' to force check all possible dirs)
786+ Uncommon header 'link' found, with contents: <http://learn.nlpplus.co.il/wp-json/>; rel="https://api.w.org/"
787+ Scan terminated: 0 error(s) and 4 item(s) reported on remote host
788+ End Time: 2017-12-16 01:14:01 (GMT-5) (313 seconds)
789---------------------------------------------------------------------------
790+ 1 host(s) tested
791
792
793 *********************************************************************
794 Portions of the server's headers (Apache/6.6.6) are not in
795 the Nikto database or are newer than the known string. Would you like
796 to submit this information (*no server specific data*) to CIRT.net
797 for a Nikto update (or you may email to sullo@cirt.net) (y/n)?
798+ The anti-clickjacking X-Frame-Options header is not present.
799+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
800+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
801+ ERROR 302: Update failed, please notify sullo@cirt.net of this code.
802[92m + -- ----------------------------=[Saving Web Screenshots]=------------------ -- +[0m
803[91m[+][0m Screenshot saved to /usr/share/sniper/loot/screenshots/learn.nlpplus.co.il-port80.jpg
804[92m + -- ----------------------------=[Running Google Hacking Queries]=--------------------- -- +[0m
805[92m + -- ----------------------------=[Running InUrlBR OSINT Queries]=---------- -- +[0m
806
807[1;35m _____ [1;37m .701F. .iBR. .7CL. .70BR. .7BR. .7BR'''Cq. .70BR. [0;31m.1BR'''Yp, .8BR'''Cq.
808[1;35m (_____)[1;37m 01 01N. C 01 C 01 .01. 01 [1;31m 01 Yb 01 .01.
809[1;35m (() ())[1;37m 01 C YCb C 01 C 01 ,C9 01 [0;31m 01 dP 01 ,C9
810[1;35m \ / [1;37m 01 C .CN. C 01 C 0101dC9 01 [1;31m 01'''bg. 0101dC9
811[1;35m \ / [1;37m 01 C .01.C 01 C 01 YC. 01 , [0;31m 01 .Y 01 YC.
812[1;35m /=\ [1;37m 01 C Y01 YC. ,C 01 .Cb. 01 ,C [1;31m 01 ,9 01 .Cb.
813[1;35m [___] [1;37m .J01L. .JCL. YC .b0101d'. .J01L. .J01. .J01010101C [0;31m.J0101Cd9 .J01L. .J01./ [1;37m2.1
814
815[1;37m__[ ! ] Neither war between hackers, nor peace for the system.
816[1;37m__[ ! ] [02;31mhttp://blog.inurl.com.br
817[1;37m__[ ! ] [02;31mhttp://fb.com/InurlBrasil
818[1;37m__[ ! ] [02;31mhttp://twitter.com/@googleinurl[0m
819[1;37m__[ ! ] [02;31mhttp://github.com/googleinurl[0m
820[1;37m__[ ! ] [02;31mCurrent PHP version::[ [1;37m7.0.26-1 [02;31m][0m
821[1;37m__[ ! ] [02;31mCurrent script owner::[ [1;37mroot [02;31m][0m
822[1;37m__[ ! ] [02;31mCurrent uname::[ [1;37mLinux Kali 4.14.0-kali1-amd64 #1 SMP Debian 4.14.2-1kali1 (2017-12-04) x86_64 [02;31m][0m
823[1;37m__[ ! ] [02;31mCurrent pwd::[ [1;37m/usr/share/sniper [02;31m][0m
824[1;37m__[ ! ] [1;33mHelp: php inurlbr.php --help[0m
825[1;37m------------------------------------------------------------------------------------------------------------------------[0m
826
827[1;37m[ ! ] Starting SCANNER INURLBR 2.1 at [16-12-2017 01:21:25][0;37m
828[ ! ] legal disclaimer: Usage of INURLBR for attacking targets without prior mutual consent is illegal.
829It is the end user's responsibility to obey all applicable local, state and federal laws.
830Developers assume no liability and are not responsible for any misuse or damage caused by this program[0m
831
832[1;37m[ INFO ][02;31m[ OUTPUT FILE ]::[1;37m [ /usr/share/sniper/output/inurlbr-learn.nlpplus.co.il.txt ][0m
833[1;37m[ INFO ][0m[02;31m[ DORK ]::[1;37m[ site:learn.nlpplus.co.il ]
834[1;37m[ INFO ][0m[02;31m[ SEARCHING ]:: [1;37m{[0m
835[1;37m[ INFO ][0m[02;31m[ ENGINE ]::[1;37m[ GOOGLE - www.google.at ][0m
836
837[1;37m[ INFO ][0m[02;31m[ SEARCHING ]:: [0m
838[1;37m-[02;31m[[0;31m:::[02;31m][0m
839[1;37m[ INFO ][0m[02;31m[ ENGINE ]::[1;37m[ GOOGLE API ][0m
840
841[1;37m[ INFO ][0m[02;31m[ SEARCHING ]:: [0m
842[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m
843[1;37m[ INFO ][0m[02;31m[ ENGINE ]::[1;37m[ GOOGLE_GENERIC_RANDOM - www.google.lv ID: 003917828085772992913:gmoeray5sa8 ][0m
844
845[1;37m[ INFO ][0m[02;31m[ SEARCHING ]:: [0m
846[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m[1;37m-[02;31m[[0;31m:::[02;31m][0m
847
848[1;37m[ INFO ][0;31m[ TOTAL FOUND VALUES ]::[1;37m [ 0 ][0m
849[1;37m[ INFO ][1;33m Not a satisfactory result was found![0m
850
851
852[1;37m[ INFO ] [ Shutting down ][0m
853[1;37m[ INFO ] [ End of process INURLBR at [16-12-2017 01:23:15][0m
854[1;37m[ INFO ] [0m[02;31m[ TOTAL FILTERED VALUES ]::[1;37m [ 0 ][0m
855[1;37m[ INFO ] [02;31m[ OUTPUT FILE ]::[1;37m [ /usr/share/sniper/output/inurlbr-learn.nlpplus.co.il.txt ][0m
856[1;37m|_________________________________________________________________________________________[0m
857
858[1;37m\_________________________________________________________________________________________/[0m
859
860[93m + -- --=[Port 110 opened... running tests...[0m
861
862Starting Nmap 7.60 ( https://nmap.org ) at 2017-12-16 01:23 EST
863Nmap scan report for learn.nlpplus.co.il (62.128.59.127)
864Host is up (0.21s latency).
865rDNS record for 62.128.59.127: imarkvps2.spd.co.il
866
867PORT STATE SERVICE VERSION
868110/tcp open pop3 Dovecot DirectAdmin pop3d
869| pop3-brute:
870| Accounts: No valid accounts found
871| Statistics: Performed 115 guesses in 101 seconds, average tps: 1.1
872|_ ERROR: Failed to connect.
873|_pop3-capabilities: UIDL USER RESP-CODES CAPA TOP AUTH-RESP-CODE STLS SASL(PLAIN) PIPELINING
874Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
875Aggressive OS guesses: Linux 2.6.39 (95%), Linux 3.10 - 3.12 (94%), Linux 4.4 (94%), Linux 2.6.18 - 2.6.22 (94%), Linux 4.0 (92%), Linux 2.6.18 (91%), Linux 3.10 (91%), Linux 3.10 - 4.8 (90%), Linux 3.11 - 4.1 (90%), Linux 3.18 (90%)
876No exact OS matches for host (test conditions non-ideal).
877Network Distance: 12 hops
878
879TRACEROUTE (using port 110/tcp)
880HOP RTT ADDRESS
8811 984.88 ms 10.13.0.1
8822 989.40 ms 37.187.24.253
8833 224.18 ms 10.50.225.61
8844 224.21 ms 10.17.129.42
8855 224.17 ms 10.73.0.50
8866 224.24 ms 10.95.33.10
8877 224.28 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
8888 224.27 ms 195.66.226.60
8899 224.34 ms EDGE-LON-MX-02-so-4-1-0-0.ip4.012.net.il (80.179.165.25)
89010 ...
89111 224.38 ms 82.102.132.157
89212 224.38 ms imarkvps2.spd.co.il (62.128.59.127)
893
894OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
895Nmap done: 1 IP address (1 host up) scanned in 131.64 seconds
896[91m + -- --=[Port 111 closed... skipping.[0m
897[91m + -- --=[Port 135 closed... skipping.[0m
898[91m + -- --=[Port 139 closed... skipping.[0m
899[91m + -- --=[Port 161 closed... skipping.[0m
900[91m + -- --=[Port 162 closed... skipping.[0m
901[91m + -- --=[Port 389 closed... skipping.[0m
902[93m + -- --=[Port 443 opened... running tests...[0m
903[92m + -- ----------------------------=[Checking for WAF]=------------------------ -- +[0m
904
905 ^ ^
906 _ __ _ ____ _ __ _ _ ____
907 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
908 | V V // o // _/ | V V // 0 // 0 // _/
909 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
910 <
911 ...'
912
913 WAFW00F - Web Application Firewall Detection Tool
914
915 By Sandro Gauci && Wendel G. Henrique
916
917Checking https://learn.nlpplus.co.il
918
919[92m + -- ----------------------------=[Checking Cloudflare]=--------------------- -- +[0m
920 ____ _ _ _____ _ _
921 / ___| | ___ _ _ __| | ___|_ _(_) |
922 | | | |/ _ \| | | |/ _` | |_ / _` | | |
923 | |___| | (_) | |_| | (_| | _| (_| | | |
924 \____|_|\___/ \__,_|\__,_|_| \__,_|_|_|
925 v1.0.1 by m0rtem
926
927
928[01:25:39] Initializing CloudFail - the date is: 16/12/2017
929[01:25:39] Fetching initial information from: learn.nlpplus.co.il...
930[01:25:39] No ipout file found, fetching data
931[01:25:39] Just checking for updates, please wait...
932[01:25:39] Updating CloudFlare subnet...
933[01:25:47] Updating Crimeflare database...
934[02:02:37] ipout file created
935[02:02:45] Server IP: 62.128.59.127
936[02:02:45] Testing if learn.nlpplus.co.il is on the Cloudflare network...
937[02:02:45] learn.nlpplus.co.il is not part of the Cloudflare network, quitting...
938[92m + -- ----------------------------=[Gathering HTTP Info]=--------------------- -- +[0m
939[1m[34mhttps://learn.nlpplus.co.il[0m [302 Found] [1m[37mApache[0m[[1m[32m6.6.6[0m][[1m[31mmod_fcgid/2.3.9[0m], [1m[37mCountry[0m[[37mISRAEL[0m][[1m[31mIL[0m], [1m[37mHTTPServer[0m[[1m[36mApache/6.6.6 mod_fcgid/2.3.9[0m], [1m[37mIP[0m[[37m62.128.59.127[0m], [1m[37mRedirectLocation[0m[[37mhttp://learn.nlpplus.co.il:2222[0m]
940[1m[34mhttp://learn.nlpplus.co.il:2222[0m [200 OK] [1m[37mCookies[0m[[37msession[0m], [1m[37mCountry[0m[[37mISRAEL[0m][[1m[31mIL[0m], [1m[37mDirectAdmin[0m[[1m[32m1.51.3[0m], [1m[37mHTTPServer[0m[[1m[36mDirectAdmin Daemon v1.51.3 Registered to sPD[0m], [1m[37mHttpOnly[0m[[37msession[0m], [1m[37mIP[0m[[37m62.128.59.127[0m], [1m[37mScript[0m[[37mJavaScript[0m], [1m[37mTitle[0m[[1m[33mDirectAdmin Login[0m], [1m[37mUncommonHeaders[0m[[37mx-directadmin[0m]
941
942[92m + -- ----------------------------=[Gathering SSL/TLS Info]=------------------ -- +[0m
943
944
945
946 AVAILABLE PLUGINS
947 -----------------
948
949 PluginOpenSSLCipherSuites
950 PluginCertInfo
951 PluginCompression
952 PluginChromeSha1Deprecation
953 PluginHSTS
954 PluginSessionResumption
955 PluginSessionRenegotiation
956 PluginHeartbleed
957
958
959
960 CHECKING HOST(S) AVAILABILITY
961 -----------------------------
962
963 learn.nlpplus.co.il:443 => 62.128.59.127:443
964
965
966
967 SCAN RESULTS FOR LEARN.NLPPLUS.CO.IL:443 - 62.128.59.127:443
968 ------------------------------------------------------------
969
970 * Deflate Compression:
971 OK - Compression disabled
972
973 * Session Renegotiation:
974 Client-initiated Renegotiations: OK - Rejected
975 Secure Renegotiation: OK - Supported
976
977 * Certificate - Content:
978 SHA1 Fingerprint: bd1c430430b4002b94f18a8b381905e293e60c55
979 Common Name: localhost
980 Issuer: localhost
981 Serial Number: F6CAA3FFE039B31C
982 Not Before: Apr 5 20:21:32 2015 GMT
983 Not After: Aug 20 20:21:32 2042 GMT
984 Signature Algorithm: sha1WithRSAEncryption
985 Public Key Algorithm: rsaEncryption
986 Key Size: 2048 bit
987 Exponent: 65537 (0x10001)
988
989 * Certificate - Trust:
990 Hostname Validation: FAILED - Certificate does NOT match learn.nlpplus.co.il
991 Google CA Store (09/2015): FAILED - Certificate is NOT Trusted: self signed certificate
992 Java 6 CA Store (Update 65): FAILED - Certificate is NOT Trusted: self signed certificate
993 Microsoft CA Store (09/2015): FAILED - Certificate is NOT Trusted: self signed certificate
994 Mozilla NSS CA Store (09/2015): FAILED - Certificate is NOT Trusted: self signed certificate
995 Apple CA Store (OS X 10.10.5): FAILED - Certificate is NOT Trusted: self signed certificate
996 Certificate Chain Received: ['localhost']
997
998 * Certificate - OCSP Stapling:
999 NOT SUPPORTED - Server did not send back an OCSP response.
1000
1001 * Session Resumption:
1002 With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
1003 With TLS Session Tickets: OK - Supported
1004
1005 * SSLV2 Cipher Suites:
1006 Server rejected all cipher suites.
1007
1008 * SSLV3 Cipher Suites:
1009 Server rejected all cipher suites.
1010
1011
1012
1013 SCAN COMPLETED IN 13.58 S
1014 -------------------------
1015Version: [32m1.11.10-static[0m
1016OpenSSL 1.0.2-chacha (1.0.2g-dev)
1017[0m
1018Testing SSL server [32mlearn.nlpplus.co.il[0m on port [32m443[0m using SNI name [32mlearn.nlpplus.co.il[0m
1019
1020 [1;34mTLS Fallback SCSV:[0m
1021Server [32msupports[0m TLS Fallback SCSV
1022
1023 [1;34mTLS renegotiation:[0m
1024[32mSecure[0m session renegotiation supported
1025
1026 [1;34mTLS Compression:[0m
1027Compression [32mdisabled[0m
1028
1029 [1;34mHeartbleed:[0m
1030TLS 1.2 [32mnot vulnerable[0m to heartbleed
1031TLS 1.1 [32mnot vulnerable[0m to heartbleed
1032TLS 1.0 [32mnot vulnerable[0m to heartbleed
1033
1034 [1;34mSupported Server Cipher(s):[0m
1035[32mPreferred[0m TLSv1.2 [32m256[0m bits [32mECDHE-RSA-AES256-GCM-SHA384 [0m Curve P-256 DHE 256
1036Accepted TLSv1.2 [32m256[0m bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
1037Accepted TLSv1.2 [32m256[0m bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
1038Accepted TLSv1.2 [32m256[0m bits [32mDHE-RSA-AES256-GCM-SHA384 [0m DHE 2048 bits
1039Accepted TLSv1.2 [32m256[0m bits DHE-RSA-AES256-SHA256 DHE 2048 bits
1040Accepted TLSv1.2 [32m256[0m bits DHE-RSA-AES256-SHA DHE 2048 bits
1041Accepted TLSv1.2 [32m256[0m bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
1042Accepted TLSv1.2 [32m256[0m bits AES256-GCM-SHA384
1043Accepted TLSv1.2 [32m256[0m bits AES256-SHA256
1044Accepted TLSv1.2 [32m256[0m bits AES256-SHA
1045Accepted TLSv1.2 [32m256[0m bits CAMELLIA256-SHA
1046Accepted TLSv1.2 [32m128[0m bits [32mECDHE-RSA-AES128-GCM-SHA256 [0m Curve P-256 DHE 256
1047Accepted TLSv1.2 [32m128[0m bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
1048Accepted TLSv1.2 [32m128[0m bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
1049Accepted TLSv1.2 [32m128[0m bits [32mDHE-RSA-AES128-GCM-SHA256 [0m DHE 2048 bits
1050Accepted TLSv1.2 [32m128[0m bits DHE-RSA-AES128-SHA256 DHE 2048 bits
1051Accepted TLSv1.2 [32m128[0m bits DHE-RSA-AES128-SHA DHE 2048 bits
1052Accepted TLSv1.2 [32m128[0m bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
1053Accepted TLSv1.2 [32m128[0m bits AES128-GCM-SHA256
1054Accepted TLSv1.2 [32m128[0m bits AES128-SHA256
1055Accepted TLSv1.2 [32m128[0m bits AES128-SHA
1056Accepted TLSv1.2 [32m128[0m bits CAMELLIA128-SHA
1057Accepted TLSv1.2 [32m112[0m bits [33mECDHE-RSA-DES-CBC3-SHA [0m Curve P-256 DHE 256
1058Accepted TLSv1.2 [32m112[0m bits [33mEDH-RSA-DES-CBC3-SHA [0m DHE 2048 bits
1059Accepted TLSv1.2 [32m112[0m bits [33mDES-CBC3-SHA [0m
1060[32mPreferred[0m TLSv1.1 [32m256[0m bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
1061Accepted TLSv1.1 [32m256[0m bits DHE-RSA-AES256-SHA DHE 2048 bits
1062Accepted TLSv1.1 [32m256[0m bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
1063Accepted TLSv1.1 [32m256[0m bits AES256-SHA
1064Accepted TLSv1.1 [32m256[0m bits CAMELLIA256-SHA
1065Accepted TLSv1.1 [32m128[0m bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
1066Accepted TLSv1.1 [32m128[0m bits DHE-RSA-AES128-SHA DHE 2048 bits
1067Accepted TLSv1.1 [32m128[0m bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
1068Accepted TLSv1.1 [32m128[0m bits AES128-SHA
1069Accepted TLSv1.1 [32m128[0m bits CAMELLIA128-SHA
1070Accepted TLSv1.1 [32m112[0m bits [33mECDHE-RSA-DES-CBC3-SHA [0m Curve P-256 DHE 256
1071Accepted TLSv1.1 [32m112[0m bits [33mEDH-RSA-DES-CBC3-SHA [0m DHE 2048 bits
1072Accepted TLSv1.1 [32m112[0m bits [33mDES-CBC3-SHA [0m
1073[32mPreferred[0m [33mTLSv1.0[0m [32m256[0m bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
1074Accepted [33mTLSv1.0[0m [32m256[0m bits DHE-RSA-AES256-SHA DHE 2048 bits
1075Accepted [33mTLSv1.0[0m [32m256[0m bits DHE-RSA-CAMELLIA256-SHA DHE 2048 bits
1076Accepted [33mTLSv1.0[0m [32m256[0m bits AES256-SHA
1077Accepted [33mTLSv1.0[0m [32m256[0m bits CAMELLIA256-SHA
1078Accepted [33mTLSv1.0[0m [32m128[0m bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
1079Accepted [33mTLSv1.0[0m [32m128[0m bits DHE-RSA-AES128-SHA DHE 2048 bits
1080Accepted [33mTLSv1.0[0m [32m128[0m bits DHE-RSA-CAMELLIA128-SHA DHE 2048 bits
1081Accepted [33mTLSv1.0[0m [32m128[0m bits AES128-SHA
1082Accepted [33mTLSv1.0[0m [32m128[0m bits CAMELLIA128-SHA
1083Accepted [33mTLSv1.0[0m [32m112[0m bits [33mECDHE-RSA-DES-CBC3-SHA [0m Curve P-256 DHE 256
1084Accepted [33mTLSv1.0[0m [32m112[0m bits [33mEDH-RSA-DES-CBC3-SHA [0m DHE 2048 bits
1085Accepted [33mTLSv1.0[0m [32m112[0m bits [33mDES-CBC3-SHA [0m
1086
1087 [1;34mSSL Certificate:[0m
1088Signature Algorithm: [31msha1WithRSAEncryption[0m
1089RSA Key Strength: 2048
1090
1091Subject: localhost
1092Issuer: [31mlocalhost[0m
1093
1094Not valid before: [32mApr 5 20:21:32 2015 GMT[0m
1095Not valid after: [32mAug 20 20:21:32 2042 GMT[0m
1096[1m
1097###########################################################
1098 testssl 2.9dev from [m[1mhttps://testssl.sh/dev/[m
1099[1m
1100 This program is free software. Distribution and
1101 modification under GPLv2 permitted.
1102 USAGE w/o ANY WARRANTY. USE IT AT YOUR OWN RISK!
1103
1104 Please file bugs @ [m[1mhttps://testssl.sh/bugs/[m
1105[1m
1106###########################################################[m
1107
1108 Using "OpenSSL 1.0.2-chacha (1.0.2i-dev)" [~183 ciphers]
1109 on Kali:/usr/share/sniper/plugins/testssl.sh/bin/openssl.Linux.x86_64
1110 (built: "Jun 22 19:32:29 2016", platform: "linux-x86_64")
1111
1112
1113[7m Start 2017-12-16 02:04:44 -->> 62.128.59.127:443 (learn.nlpplus.co.il) <<--[m
1114
1115 rDNS (62.128.59.127): imarkvps2.spd.co.il.
1116 Service detected: HTTP
1117
1118
1119[1m[4m Testing protocols [m[4mvia sockets except SPDY+HTTP2 [m
1120
1121[1m SSLv2 [m[1;32mnot offered (OK)[m
1122[1m SSLv3 [m[1;32mnot offered (OK)[m
1123[1m TLS 1 [moffered
1124[1m TLS 1.1 [moffered
1125[1m TLS 1.2 [m[1;32moffered (OK)[m
1126[1m TLS 1.3 [mnot offered
1127[1m SPDY/NPN [mnot offered
1128[1m HTTP2/ALPN [mnot offered
1129
1130[1m[4m Testing ~standard cipher categories [m
1131
1132[1m NULL ciphers (no encryption) [m[1;32mnot offered (OK)[m
1133[1m Anonymous NULL Ciphers (no authentication) [m[1;32mnot offered (OK)[m
1134[1m Export ciphers (w/o ADH+NULL) [m[1;32mnot offered (OK)[m
1135[1m LOW: 64 Bit + DES encryption (w/o export) [m[1;32mnot offered (OK)[m
1136[1m Weak 128 Bit ciphers (SEED, IDEA, RC[2,4]) [m[0;32mnot offered (OK)[m
1137[1m Triple DES Ciphers (Medium) [m[0;33moffered[m
1138[1m High encryption (AES+Camellia, no AEAD) [m[0;32moffered (OK)[m
1139[1m Strong encryption (AEAD ciphers) [m[1;32moffered (OK)[m
1140
1141
1142[1m[4m Testing robust (perfect) forward secrecy[m[4m, (P)FS -- omitting Null Authentication/Encryption, 3DES, RC4 [m
1143
1144[0;32m PFS is offered (OK)[m ECDHE-RSA-AES256-GCM-SHA384
1145 ECDHE-RSA-AES256-SHA384 ECDHE-RSA-AES256-SHA
1146 DHE-RSA-AES256-GCM-SHA384 DHE-RSA-AES256-SHA256
1147 DHE-RSA-AES256-SHA DHE-RSA-CAMELLIA256-SHA
1148 ECDHE-RSA-AES128-GCM-SHA256
1149 ECDHE-RSA-AES128-SHA256 ECDHE-RSA-AES128-SHA
1150 DHE-RSA-AES128-GCM-SHA256 DHE-RSA-AES128-SHA256
1151 DHE-RSA-AES128-SHA DHE-RSA-CAMELLIA128-SHA
1152[1m Elliptic curves offered: [m[0;32mprime256v1[m [0;32msecp384r1[m [0;32msecp521r1[m
1153
1154
1155[1m[4m Testing server preferences [m
1156
1157[1m Has server cipher order? [m[1;32myes (OK)[m
1158[1m Negotiated protocol [m[1;32mTLSv1.2[m
1159[1m Negotiated cipher [m[1;33mECDHE-RSA-AES256-GCM-SHA384[m, [0;32m256 bit ECDH (P-256)[m
1160[1m Cipher order[m
1161 TLSv1: ECDHE-RSA-AES256-SHA DHE-RSA-AES256-SHA DHE-RSA-CAMELLIA256-SHA
1162 AES256-SHA CAMELLIA256-SHA ECDHE-RSA-AES128-SHA
1163 DHE-RSA-AES128-SHA DHE-RSA-CAMELLIA128-SHA AES128-SHA
1164 CAMELLIA128-SHA ECDHE-RSA-DES-CBC3-SHA EDH-RSA-DES-CBC3-SHA
1165 DES-CBC3-SHA
1166 TLSv1.1: ECDHE-RSA-AES256-SHA DHE-RSA-AES256-SHA DHE-RSA-CAMELLIA256-SHA
1167 AES256-SHA CAMELLIA256-SHA ECDHE-RSA-AES128-SHA
1168 DHE-RSA-AES128-SHA DHE-RSA-CAMELLIA128-SHA AES128-SHA
1169 CAMELLIA128-SHA ECDHE-RSA-DES-CBC3-SHA EDH-RSA-DES-CBC3-SHA
1170 DES-CBC3-SHA
1171 TLSv1.2: ECDHE-RSA-AES256-GCM-SHA384 ECDHE-RSA-AES256-SHA384
1172 ECDHE-RSA-AES256-SHA DHE-RSA-AES256-GCM-SHA384
1173 DHE-RSA-AES256-SHA256 DHE-RSA-AES256-SHA DHE-RSA-CAMELLIA256-SHA
1174 AES256-GCM-SHA384 AES256-SHA256 AES256-SHA CAMELLIA256-SHA
1175 ECDHE-RSA-AES128-GCM-SHA256 ECDHE-RSA-AES128-SHA256
1176 ECDHE-RSA-AES128-SHA DHE-RSA-AES128-GCM-SHA256
1177 DHE-RSA-AES128-SHA256 DHE-RSA-AES128-SHA DHE-RSA-CAMELLIA128-SHA
1178 AES128-GCM-SHA256 AES128-SHA256 AES128-SHA CAMELLIA128-SHA
1179 ECDHE-RSA-DES-CBC3-SHA EDH-RSA-DES-CBC3-SHA DES-CBC3-SHA
1180
1181
1182[1m[4m Testing server defaults (Server Hello) [m
1183
1184[1m TLS extensions (standard) [m"renegotiation info/#65281"
1185 "EC point formats/#11" "session ticket/#35"
1186 "heartbeat/#15"
1187[1m Session Ticket RFC 5077 hint [m300 seconds, session tickets keys seems to be rotated < daily
1188[1m SSL Session ID support [myes
1189[1m Session Resumption [mTickets: yes, ID: yes
1190[1m TLS clock skew[m -1 sec from localtime
1191[1m Signature Algorithm [m[0;33mSHA1 with RSA[m -- besides: users will receive a [0;31mstrong browser WARNING[m
1192[1m Server key size [mRSA 2048 bits
1193[1m Fingerprint / Serial [mSHA1 BD1C430430B4002B94F18A8B381905E293E60C55 / F6CAA3FFE039B31C
1194 SHA256 E1AD3736360DAB3DAE6D74FDB9E01E75102E133DECE7EA30FC63FF1DEC2E00BD
1195[1m Common Name (CN) [m[3mlocalhost[m
1196[1m subjectAltName (SAN) [m[0;31mmissing (NOT ok)[m -- Browsers are complaining
1197[1m Issuer [m[1;31mself-signed (NOT ok)[m
1198[1m Trust (hostname) [m[0;31mcertificate does not match supplied URI[m (same w/o SNI)
1199[1m Chain of trust[m [1;31mNOT ok[m (self signed)
1200[1m EV cert[m (experimental) no
1201[1m Certificate Expiration [m[0;32m9013 >= 60 days[m (2015-04-05 16:21 --> 2042-08-20 16:21 -0400)
1202[1m # of certificates provided[m 1
1203[1m Certificate Revocation List [m[0;31mNOT ok --[m neither CRL nor OCSP URI provided
1204[1m OCSP URI [m--
1205[1m OCSP stapling [mnot offered
1206[1m OCSP must staple [mno
1207[1m DNS CAA RR[m (experimental) [1;33mnot offered[m
1208[1m Certificate Transparency [mno
1209
1210
1211[1m[4m Testing HTTP header response @ "/" [m
1212
1213[1m HTTP Status Code [m 302 Found, redirecting to "http://learn.nlpplus.co.il:2222"[0;31m -- Redirect to insecure URL (NOT ok)[m
1214[1m HTTP clock skew [m0 sec from localtime
1215[1m Strict Transport Security [m--
1216[1m Public Key Pinning [m--
1217[1m Server banner [mApache/[33m6(B[m.[33m6(B[m.[33m6(B[m mod_fcgid/[33m2(B[m.[33m3(B[m.[33m9(B[m
1218[1m Application banner [m--
1219[1m Cookie(s) [m(none issued at "/") -- maybe better try target URL of 30x
1220[1m Security headers [m[0;33m--[m
1221[1m Reverse Proxy banner [m--
1222
1223
1224[1m[4m Testing vulnerabilities [m
1225
1226[1m Heartbleed[m (CVE-2014-0160) [1;32mnot vulnerable (OK)[m, timed out
1227[1m CCS[m (CVE-2014-0224) [1;32mnot vulnerable (OK)[m
1228[1m Ticketbleed[m (CVE-2016-9244), experiment. [1;32mnot vulnerable (OK)[m, memory fragments do not differ
1229[1m ROBOT [m[1;32mnot vulnerable (OK)[m
1230[1m Secure Renegotiation [m(CVE-2009-3555) [1;32mnot vulnerable (OK)[m
1231[1m Secure Client-Initiated Renegotiation [m[0;32mnot vulnerable (OK)[m
1232[1m CRIME, TLS [m(CVE-2012-4929) [0;32mnot vulnerable (OK)[m
1233[1m BREACH[m (CVE-2013-3587) [1;32mno HTTP compression (OK) [m - only supplied "/" tested
1234[1m POODLE, SSL[m (CVE-2014-3566) [1;32mnot vulnerable (OK)[m
1235[1m TLS_FALLBACK_SCSV[m (RFC 7507) [0;32mDowngrade attack prevention supported (OK)[m
1236[1m SWEET32[m (CVE-2016-2183, CVE-2016-6329) [1;33mVULNERABLE[m, uses 64 bit block ciphers
1237[1m FREAK[m (CVE-2015-0204) [1;32mnot vulnerable (OK)[m
1238[1m DROWN[m (CVE-2016-0800, CVE-2016-0703) [1;32mnot vulnerable on this host and port (OK)[m
1239 make sure you don't use this certificate elsewhere with SSLv2 enabled services
1240 https://censys.io/ipv4?q=E1AD3736360DAB3DAE6D74FDB9E01E75102E133DECE7EA30FC63FF1DEC2E00BD could help you to find out
1241[1m LOGJAM[m (CVE-2015-4000), experimental [1;33mCommon prime with 2048 bits detected: [m[3mRFC3526/Oakley Group 14[m,
1242 but no DH EXPORT ciphers
1243[1m BEAST[m (CVE-2011-3389) TLS1: [1;33mECDHE-RSA-AES256-SHA
1244 DHE-RSA-AES256-SHA
1245 DHE-RSA-CAMELLIA256-SHA
1246 AES256-SHA CAMELLIA256-SHA
1247 ECDHE-RSA-AES128-SHA
1248 DHE-RSA-AES128-SHA
1249 DHE-RSA-CAMELLIA128-SHA
1250 AES128-SHA CAMELLIA128-SHA
1251 ECDHE-RSA-DES-CBC3-SHA
1252 EDH-RSA-DES-CBC3-SHA
1253 DES-CBC3-SHA [m
1254 [1;33mVULNERABLE[m -- but also supports higher protocols (possible mitigation): TLSv1.1 TLSv1.2
1255[1m LUCKY13[m (CVE-2013-0169), experimental potentially [1;33mVULNERABLE[m, uses cipher block chaining (CBC) ciphers with TLS
1256[1m RC4[m (CVE-2013-2566, CVE-2015-2808) [0;32mno RC4 ciphers detected (OK)[m
1257
1258
1259[1m[4m Testing 364 ciphers via OpenSSL plus sockets against the server, ordered by encryption strength [m
1260
1261Hexcode Cipher Suite Name (OpenSSL) KeyExch. Encryption Bits Cipher Suite Name (RFC)
1262-----------------------------------------------------------------------------------------------------------------------------
1263 xc030 ECDHE-RSA-AES256-GCM-SHA384 ECDH[0;32m 256[m AESGCM 256 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
1264 xc028 ECDHE-RSA-AES256-SHA384 ECDH[0;32m 256[m AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
1265 xc014 ECDHE-RSA-AES256-SHA ECDH[0;32m 256[m AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
1266 x9f DHE-RSA-AES256-GCM-SHA384 DH[0;32m 2048[m AESGCM 256 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
1267 x6b DHE-RSA-AES256-SHA256 DH[0;32m 2048[m AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA256
1268 x39 DHE-RSA-AES256-SHA DH[0;32m 2048[m AES 256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA
1269 x88 DHE-RSA-CAMELLIA256-SHA DH[0;32m 2048[m Camellia 256 TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA
1270 x9d AES256-GCM-SHA384 RSA AESGCM 256 TLS_RSA_WITH_AES_256_GCM_SHA384
1271 x3d AES256-SHA256 RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA256
1272 x35 AES256-SHA RSA AES 256 TLS_RSA_WITH_AES_256_CBC_SHA
1273 x84 CAMELLIA256-SHA RSA Camellia 256 TLS_RSA_WITH_CAMELLIA_256_CBC_SHA
1274 xc02f ECDHE-RSA-AES128-GCM-SHA256 ECDH[0;32m 256[m AESGCM 128 TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
1275 xc027 ECDHE-RSA-AES128-SHA256 ECDH[0;32m 256[m AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
1276 xc013 ECDHE-RSA-AES128-SHA ECDH[0;32m 256[m AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
1277 x9e DHE-RSA-AES128-GCM-SHA256 DH[0;32m 2048[m AESGCM 128 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
1278 x67 DHE-RSA-AES128-SHA256 DH[0;32m 2048[m AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA256
1279 x33 DHE-RSA-AES128-SHA DH[0;32m 2048[m AES 128 TLS_DHE_RSA_WITH_AES_128_CBC_SHA
1280 x45 DHE-RSA-CAMELLIA128-SHA DH[0;32m 2048[m Camellia 128 TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA
1281 x9c AES128-GCM-SHA256 RSA AESGCM 128 TLS_RSA_WITH_AES_128_GCM_SHA256
1282 x3c AES128-SHA256 RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA256
1283 x2f AES128-SHA RSA AES 128 TLS_RSA_WITH_AES_128_CBC_SHA
1284 x41 CAMELLIA128-SHA RSA Camellia 128 TLS_RSA_WITH_CAMELLIA_128_CBC_SHA
1285 xc012 ECDHE-RSA-DES-CBC3-SHA ECDH[0;32m 256[m 3DES 168 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA
1286 x16 EDH-RSA-DES-CBC3-SHA DH[0;32m 2048[m 3DES 168 TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA
1287 x0a DES-CBC3-SHA RSA 3DES 168 TLS_RSA_WITH_3DES_EDE_CBC_SHA
1288
1289
1290[1m[4m Running client simulations via sockets [m
1291
1292 Android 2.3.7 TLSv1.0 DHE-RSA-AES128-SHA, [0;32m2048 bit DH[m
1293 Android 4.1.1 TLSv1.0 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1294 Android 4.3 TLSv1.0 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1295 Android 4.4.2 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1296 Android 5.0.0 TLSv1.2 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1297 Android 6.0 TLSv1.2 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1298 Android 7.0 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1299 Chrome 51 Win 7 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1300 Chrome 57 Win 7 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1301 Firefox 49 Win 7 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1302 Firefox 53 Win 7 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1303 IE 6 XP No connection
1304 IE 7 Vista TLSv1.0 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1305 IE 8 XP TLSv1.0 DES-CBC3-SHA
1306 IE 8 Win 7 TLSv1.0 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1307 IE 11 Win 7 TLSv1.2 ECDHE-RSA-AES256-SHA384, [0;32m256 bit ECDH (P-256)[m
1308 IE 11 Win 8.1 TLSv1.2 ECDHE-RSA-AES256-SHA384, [0;32m256 bit ECDH (P-256)[m
1309 IE 11 Win Phone 8.1 Update TLSv1.2 ECDHE-RSA-AES256-SHA384, [0;32m256 bit ECDH (P-256)[m
1310 IE 11 Win 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1311 Edge 13 Win 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1312 Edge 13 Win Phone 10 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1313 Opera 17 Win 7 TLSv1.2 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1314 Safari 5.1.9 OS X 10.6.8 TLSv1.0 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1315 Safari 7 iOS 7.1 TLSv1.2 ECDHE-RSA-AES256-SHA384, [0;32m256 bit ECDH (P-256)[m
1316 Safari 9 OS X 10.11 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1317 Safari 10 OS X 10.12 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1318 Apple ATS 9 iOS 9 TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1319 Tor 17.0.9 Win 7 TLSv1.0 ECDHE-RSA-AES256-SHA, [0;32m256 bit ECDH (P-256)[m
1320 Java 6u45 No connection
1321 Java 7u25 TLSv1.0 ECDHE-RSA-AES128-SHA, [0;32m256 bit ECDH (P-256)[m
1322 Java 8u31 TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, [0;32m256 bit ECDH (P-256)[m
1323 OpenSSL 1.0.1l TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1324 OpenSSL 1.0.2e TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, [0;32m256 bit ECDH (P-256)[m
1325
1326[7m Done 2017-12-16 02:09:52 [ 320s] -->> 62.128.59.127:443 (learn.nlpplus.co.il) <<--[m
1327#######################################################################################################################################
1328Nom de l'hôte www.flybox.co.il FAI Inconnu
1329Continent Inconnu Drapeau
1330US
1331Pays Etats-Unis d'Amérique Code du pays US
1332Région Inconnu Heure locale 16 Dec 2017 01:25 CST
1333Ville Inconnu Latitude 37.751
1334Adresse IP (IPv6) 2400:cb00:2048:1::681f:4bef Longitude -97.822
1335######################################################################################################################################
1336[i] Scanning Site: https://flybox.co.il
1337
1338
1339
1340B A S I C I N F O
1341====================
1342
1343
1344[+] Site Title: Flybox - ×טרקציה במרכז לכל המשפחה והחברי×! ×ž× ×”×¨×ª רוח ×”×’×™×¢×” לישר×ל
1345[+] IP address: 104.31.74.239
1346[+] Web Server: cloudflare-nginx
1347[+] CMS: WordPress
1348[+] Cloudflare: Detected
1349[+] Robots File: Found
1350
1351-------------[ contents ]----------------
1352User-agent: *
1353Disallow: /wp-admin/
1354Allow: /wp-admin/admin-ajax.php
1355
1356-----------[end of contents]-------------
1357
1358
1359
1360W H O I S L O O K U P
1361========================
1362
1363
1364% The data in the WHOIS database of the .il registry is provided
1365% by ISOC-IL for information purposes, and to assist persons in
1366% obtaining information about or related to a domain name
1367% registration record. ISOC-IL does not guarantee its accuracy.
1368% By submitting a WHOIS query, you agree that you will use this
1369% Data only for lawful purposes and that, under no circumstances
1370% will you use this Data to: (1) allow, enable, or otherwise
1371% support the transmission of mass unsolicited, commercial
1372% advertising or solicitations via e-mail (spam);
1373% or (2) enable high volume, automated, electronic processes that
1374% apply to ISOC-IL (or its systems).
1375% ISOC-IL reserves the right to modify these terms at any time.
1376% By submitting this query, you agree to abide by this policy.
1377
1378query: flybox.co.il
1379
1380reg-name: flybox
1381domain: flybox.co.il
1382
1383descr: Ofer Bar
1384descr: Kibutz Hulda
1385descr: Kibutz Hulda
1386descr: 11111
1387descr: Israel
1388phone: +972 54 3035371
1389fax-no: +972 9 9574370
1390admin-c: IS-OB5539-IL
1391tech-c: IS-ID1078-IL
1392zone-c: IS-ID1078-IL
1393nserver: athena.ns.cloudflare.com
1394nserver: vin.ns.cloudflare.com
1395validity: 04-09-2019
1396DNSSEC: unsigned
1397status: Transfer Locked
1398changed: domain-registrar AT isoc.org.il 20130904 (Assigned)
1399changed: domain-registrar AT isoc.org.il 20161012 (Changed)
1400
1401person: Ofer Bar
1402address: Ofer Bar
1403address: Kibutz Hulda
1404address: Kibutz Hulda
1405address: 11111
1406address: Israel
1407phone: +972 54 3035371
1408fax-no: +972 9 9574370
1409e-mail: tsahye AT gmail.com
1410nic-hdl: IS-OB5539-IL
1411changed: domain-registrar AT isoc.org.il 20130904
1412changed: Managing Registrar 20150805
1413
1414person: Interspace Domreg
1415address: Interspace Ltd.
1416address: P.O.Box 8723
1417address: Netanya
1418address: 42505
1419address: Israel
1420phone: +972 73 2224444
1421fax-no: +972 73 2224440
1422e-mail: domreg AT interspace.net
1423nic-hdl: IS-ID1078-IL
1424changed: Managing Registrar 20070110
1425changed: Managing Registrar 20070319
1426changed: Managing Registrar 20070909
1427changed: Managing Registrar 20090514
1428changed: Managing Registrar 20110720
1429changed: Managing Registrar 20110720
1430changed: Managing Registrar 20110721
1431changed: Managing Registrar 20111128
1432changed: Managing Registrar 20111128
1433changed: Managing Registrar 20130924
1434changed: Managing Registrar 20130924
1435changed: Managing Registrar 20130924
1436changed: Managing Registrar 20130924
1437changed: Managing Registrar 20130924
1438changed: Managing Registrar 20170518
1439changed: Managing Registrar 20170716
1440
1441registrar name: InterSpace Ltd
1442registrar info: http://www.internic.co.il
1443
1444% Rights to the data above are restricted by copyright.
1445
1446
1447
1448
1449G E O I P L O O K U P
1450=========================
1451
1452[i] IP Address: 104.31.74.239
1453[i] Country: US
1454[i] State: N/A
1455[i] City: N/A
1456[i] Latitude: 37.750999
1457[i] Longitude: -97.821999
1458
1459
1460
1461
1462H T T P H E A D E R S
1463=======================
1464
1465
1466[i] HTTP/1.1 301 Moved Permanently
1467[i] Date: Sat, 16 Dec 2017 07:31:11 GMT
1468[i] Content-Type: text/html; charset=UTF-8
1469[i] Connection: close
1470[i] Set-Cookie: __cfduid=d2385da995b22eac5d4292d307299d4011513409470; expires=Sun, 16-Dec-18 07:31:10 GMT; path=/; domain=.flybox.co.il; HttpOnly
1471[i] X-Powered-By: PHP/7.0.13
1472[i] Set-Cookie: PHPSESSID=2b4m80ba749cm5tvkv4qn8fbb6; expires=Wed, 30-Aug-2023 15:27:22 GMT; Max-Age=180000000; path=/
1473[i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
1474[i] Cache-Control: no-store, no-cache, must-revalidate
1475[i] Pragma: no-cache
1476[i] Set-Cookie: qtrans_front_language=he; expires=Sun, 16-Dec-2018 07:27:22 GMT; Max-Age=31536000; path=/
1477[i] Location: https://www.flybox.co.il/
1478[i] Server: cloudflare-nginx
1479[i] CF-RAY: 3cdff104d959220a-EWR
1480[i] HTTP/1.1 200 OK
1481[i] Date: Sat, 16 Dec 2017 07:31:20 GMT
1482[i] Content-Type: text/html; charset=UTF-8
1483[i] Connection: close
1484[i] Set-Cookie: __cfduid=de3ef7a4e858facf92c4b5d3a60eb030d1513409479; expires=Sun, 16-Dec-18 07:31:19 GMT; path=/; domain=.flybox.co.il; HttpOnly
1485[i] X-Powered-By: PHP/7.0.13
1486[i] Set-Cookie: PHPSESSID=t2nkia7h4tmv10qesqqj9c6lq6; expires=Wed, 30-Aug-2023 15:27:31 GMT; Max-Age=180000000; path=/
1487[i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
1488[i] Cache-Control: no-store, no-cache, must-revalidate
1489[i] Pragma: no-cache
1490[i] Set-Cookie: qtrans_front_language=he; expires=Sun, 16-Dec-2018 07:27:31 GMT; Max-Age=31536000; path=/
1491[i] Link: <https://www.flybox.co.il/wp-json/>; rel="https://api.w.org/"
1492[i] Link: <https://www.flybox.co.il/>; rel=shortlink
1493[i] Access-Control-Allow-Origin: *
1494[i] Server: cloudflare-nginx
1495[i] CF-RAY: 3cdff13d59bc0ee5-EWR
1496
1497
1498
1499
1500D N S L O O K U P
1501===================
1502
1503flybox.co.il. 3788 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
1504
1505
1506
1507
1508S U B N E T C A L C U L A T I O N
1509====================================
1510
1511Address = 2400:cb00:2048:1::681f:4bef
1512Network = 2400:cb00:2048:1::681f:4bef / 128
1513Netmask = ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff
1514Wildcard Mask = ::
1515Hosts Bits = 0
1516Max. Hosts = 0 (2^0 - 1)
1517Host Range = { 2400:cb00:2048:1::681f:4bf0 - 2400:cb00:2048:1::681f:4bef }
1518
1519
1520
1521N M A P P O R T S C A N
1522============================
1523
1524
1525Starting Nmap 7.01 ( https://nmap.org ) at 2017-12-16 07:31 UTC
1526Nmap scan report for flybox.co.il (104.31.75.239)
1527Host is up (0.0020s latency).
1528Other addresses for flybox.co.il (not scanned): 104.31.74.239 2400:cb00:2048:1::681f:4bef 2400:cb00:2048:1::681f:4aef
1529PORT STATE SERVICE VERSION
153021/tcp filtered ftp
153122/tcp filtered ssh
153223/tcp filtered telnet
153325/tcp filtered smtp
153480/tcp open http Cloudflare nginx
1535110/tcp filtered pop3
1536143/tcp filtered imap
1537443/tcp open ssl/http Cloudflare nginx
1538445/tcp filtered microsoft-ds
15393389/tcp filtered ms-wbt-server
1540
1541Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1542Nmap done: 1 IP address (1 host up) scanned in 13.87 seconds
1543
1544
1545
1546DNS Status:
1547A | 104.31.75.239
1548A | 104.31.74.239
1549NS | athena.ns.cloudflare.com
1550NS | vin.ns.cloudflare.com
1551MX | aspmx.l.google.com
1552MX | aspmx3.googlemail.com
1553MX | alt2.aspmx.l.google.com
1554MX | aspmx2.googlemail.com
1555MX | alt1.aspmx.l.google.com
1556Subdomain Bruteforce:
1557www.flybox.co.il | 104.31.75.239
1558ftp.flybox.co.il | 104.31.75.239
1559api.flybox.co.il | 104.31.74.239
1560No results found for SRV Bruteforce
1561No results found for Crimeflare DB
1562Domain History
1563104.31.75.239
1564104.31.74.239
1565[!] IP Address : 104.31.74.239
1566[-] Cloudflare detected
1567[!] Powered By: PHP/7.0.13
1568[-] Clickjacking protection is not in place.
1569[!] CMS Detected : WordPress
1570[?] Would you like to use WPScan? [Y/n] y
1571_______________________________________________________________
1572 __ _______ _____
1573 \ \ / / __ \ / ____|
1574 \ \ /\ / /| |__) | (___ ___ __ _ _ __ ®
1575 \ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \
1576 \ /\ / | | ____) | (__| (_| | | | |
1577 \/ \/ |_| |_____/ \___|\__,_|_| |_|
1578
1579 WordPress Security Scanner by the WPScan Team
1580 Version 2.9.3
1581 Sponsored by Sucuri - https://sucuri.net
1582 @_WPScan_, @ethicalhack3r, @erwan_lr, pvdl, @_FireFart_
1583_______________________________________________________________
1584
1585[i] The remote host tried to redirect to: https://www.flybox.co.il/
1586[?] Do you want follow the redirection ? [Y]es [N]o [A]bort, default: [N]N
1587[+] URL: http://www.flybox.co.il/
1588[+] Started: Sat Dec 16 02:51:36 2017
1589
1590[+] Interesting header: CF-RAY: 3ce00f8004711840-EWR
1591[+] Interesting header: SERVER: cloudflare-nginx
1592[+] XML-RPC Interface available under: http://www.flybox.co.il/xmlrpc.php
1593
1594[+] WordPress version 4.5.6 (Released on 2017-01-26) identified from meta generator, links opml
1595[!] 22 vulnerabilities identified from the version number
1596
1597[!] Title: WordPress 3.6.0-4.7.2 - Authenticated Cross-Site Scripting (XSS) via Media File Metadata
1598 Reference: https://wpvulndb.com/vulnerabilities/8765
1599 Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
1600 Reference: https://github.com/WordPress/WordPress/commit/28f838ca3ee205b6f39cd2bf23eb4e5f52796bd7
1601 Reference: https://sumofpwn.nl/advisory/2016/wordpress_audio_playlist_functionality_is_affected_by_cross_site_scripting.html
1602 Reference: http://seclists.org/oss-sec/2017/q1/563
1603 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6814
1604[i] Fixed in: 4.5.7
1605
1606[!] Title: WordPress 2.8.1-4.7.2 - Control Characters in Redirect URL Validation
1607 Reference: https://wpvulndb.com/vulnerabilities/8766
1608 Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
1609 Reference: https://github.com/WordPress/WordPress/commit/288cd469396cfe7055972b457eb589cea51ce40e
1610 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6815
1611[i] Fixed in: 4.5.7
1612
1613[!] Title: WordPress 4.0-4.7.2 - Authenticated Stored Cross-Site Scripting (XSS) in YouTube URL Embeds
1614 Reference: https://wpvulndb.com/vulnerabilities/8768
1615 Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
1616 Reference: https://github.com/WordPress/WordPress/commit/419c8d97ce8df7d5004ee0b566bc5e095f0a6ca8
1617 Reference: https://blog.sucuri.net/2017/03/stored-xss-in-wordpress-core.html
1618 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6817
1619[i] Fixed in: 4.5.7
1620
1621[!] Title: WordPress 4.2-4.7.2 - Press This CSRF DoS
1622 Reference: https://wpvulndb.com/vulnerabilities/8770
1623 Reference: https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
1624 Reference: https://github.com/WordPress/WordPress/commit/263831a72d08556bc2f3a328673d95301a152829
1625 Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_press_this_function_allows_dos.html
1626 Reference: http://seclists.org/oss-sec/2017/q1/562
1627 Reference: https://hackerone.com/reports/153093
1628 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6819
1629[i] Fixed in: 4.5.7
1630
1631[!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
1632 Reference: https://wpvulndb.com/vulnerabilities/8807
1633 Reference: https://exploitbox.io/vuln/WordPress-Exploit-4-7-Unauth-Password-Reset-0day-CVE-2017-8295.html
1634 Reference: http://blog.dewhurstsecurity.com/2017/05/04/exploitbox-wordpress-security-advisories.html
1635 Reference: https://core.trac.wordpress.org/ticket/25239
1636 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8295
1637
1638[!] Title: WordPress 2.7.0-4.7.4 - Insufficient Redirect Validation
1639 Reference: https://wpvulndb.com/vulnerabilities/8815
1640 Reference: https://github.com/WordPress/WordPress/commit/76d77e927bb4d0f87c7262a50e28d84e01fd2b11
1641 Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
1642 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9066
1643[i] Fixed in: 4.5.9
1644
1645[!] Title: WordPress 2.5.0-4.7.4 - Post Meta Data Values Improper Handling in XML-RPC
1646 Reference: https://wpvulndb.com/vulnerabilities/8816
1647 Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
1648 Reference: https://github.com/WordPress/WordPress/commit/3d95e3ae816f4d7c638f40d3e936a4be19724381
1649 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9062
1650[i] Fixed in: 4.5.9
1651
1652[!] Title: WordPress 3.4.0-4.7.4 - XML-RPC Post Meta Data Lack of Capability Checks
1653 Reference: https://wpvulndb.com/vulnerabilities/8817
1654 Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
1655 Reference: https://github.com/WordPress/WordPress/commit/e88a48a066ab2200ce3091b131d43e2fab2460a4
1656 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9065
1657[i] Fixed in: 4.5.9
1658
1659[!] Title: WordPress 2.5.0-4.7.4 - Filesystem Credentials Dialog CSRF
1660 Reference: https://wpvulndb.com/vulnerabilities/8818
1661 Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
1662 Reference: https://github.com/WordPress/WordPress/commit/38347d7c580be4cdd8476e4bbc653d5c79ed9b67
1663 Reference: https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_wordpress_connection_information.html
1664 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9064
1665[i] Fixed in: 4.5.9
1666
1667[!] Title: WordPress 3.3-4.7.4 - Large File Upload Error XSS
1668 Reference: https://wpvulndb.com/vulnerabilities/8819
1669 Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
1670 Reference: https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6
1671 Reference: https://hackerone.com/reports/203515
1672 Reference: https://hackerone.com/reports/203515
1673 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9061
1674[i] Fixed in: 4.5.9
1675
1676[!] Title: WordPress 3.4.0-4.7.4 - Customizer XSS & CSRF
1677 Reference: https://wpvulndb.com/vulnerabilities/8820
1678 Reference: https://wordpress.org/news/2017/05/wordpress-4-7-5/
1679 Reference: https://github.com/WordPress/WordPress/commit/3d10fef22d788f29aed745b0f5ff6f6baea69af3
1680 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9063
1681[i] Fixed in: 4.5.9
1682
1683[!] Title: WordPress 2.3.0-4.8.1 - $wpdb->prepare() potential SQL Injection
1684 Reference: https://wpvulndb.com/vulnerabilities/8905
1685 Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
1686 Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
1687 Reference: https://github.com/WordPress/WordPress/commit/fc930d3daed1c3acef010d04acc2c5de93cd18ec
1688[i] Fixed in: 4.5.10
1689
1690[!] Title: WordPress 2.3.0-4.7.4 - Authenticated SQL injection
1691 Reference: https://wpvulndb.com/vulnerabilities/8906
1692 Reference: https://medium.com/websec/wordpress-sqli-bbb2afcc8e94
1693 Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
1694 Reference: https://github.com/WordPress/WordPress/commit/70b21279098fc973eae803693c0705a548128e48
1695 Reference: https://wpvulndb.com/vulnerabilities/8905
1696[i] Fixed in: 4.7.5
1697
1698[!] Title: WordPress 2.9.2-4.8.1 - Open Redirect
1699 Reference: https://wpvulndb.com/vulnerabilities/8910
1700 Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
1701 Reference: https://core.trac.wordpress.org/changeset/41398
1702 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14725
1703[i] Fixed in: 4.5.10
1704
1705[!] Title: WordPress 3.0-4.8.1 - Path Traversal in Unzipping
1706 Reference: https://wpvulndb.com/vulnerabilities/8911
1707 Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
1708 Reference: https://core.trac.wordpress.org/changeset/41457
1709 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14719
1710[i] Fixed in: 4.5.10
1711
1712[!] Title: WordPress 4.4-4.8.1 - Cross-Site Scripting (XSS) in oEmbed
1713 Reference: https://wpvulndb.com/vulnerabilities/8913
1714 Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
1715 Reference: https://core.trac.wordpress.org/changeset/41448
1716 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14724
1717[i] Fixed in: 4.5.10
1718
1719[!] Title: WordPress 4.2.3-4.8.1 - Authenticated Cross-Site Scripting (XSS) in Visual Editor
1720 Reference: https://wpvulndb.com/vulnerabilities/8914
1721 Reference: https://wordpress.org/news/2017/09/wordpress-4-8-2-security-and-maintenance-release/
1722 Reference: https://core.trac.wordpress.org/changeset/41395
1723 Reference: https://blog.sucuri.net/2017/09/stored-cross-site-scripting-vulnerability-in-wordpress-4-8-1.html
1724 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14726
1725[i] Fixed in: 4.5.10
1726
1727[!] Title: WordPress <= 4.8.2 - $wpdb->prepare() Weakness
1728 Reference: https://wpvulndb.com/vulnerabilities/8941
1729 Reference: https://wordpress.org/news/2017/10/wordpress-4-8-3-security-release/
1730 Reference: https://github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167d
1731 Reference: https://twitter.com/ircmaxell/status/923662170092638208
1732 Reference: https://blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.html
1733 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16510
1734[i] Fixed in: 4.5.11
1735
1736[!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
1737 Reference: https://wpvulndb.com/vulnerabilities/8966
1738 Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
1739 Reference: https://github.com/WordPress/WordPress/commit/67d03a98c2cae5f41843c897f206adde299b0509
1740 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17092
1741[i] Fixed in: 4.5.12
1742
1743[!] Title: WordPress 1.5.0-4.9 - RSS and Atom Feed Escaping
1744 Reference: https://wpvulndb.com/vulnerabilities/8967
1745 Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
1746 Reference: https://github.com/WordPress/WordPress/commit/f1de7e42df29395c3314bf85bff3d1f4f90541de
1747 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17094
1748[i] Fixed in: 4.5.12
1749
1750[!] Title: WordPress 4.3.0-4.9 - HTML Language Attribute Escaping
1751 Reference: https://wpvulndb.com/vulnerabilities/8968
1752 Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
1753 Reference: https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43da6c09a
1754 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17093
1755[i] Fixed in: 4.5.12
1756
1757[!] Title: WordPress 3.7-4.9 - 'newbloguser' Key Weak Hashing
1758 Reference: https://wpvulndb.com/vulnerabilities/8969
1759 Reference: https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
1760 Reference: https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c
1761 Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17091
1762[i] Fixed in: 4.5.12
1763
1764[+] WordPress theme in use: blue-summit-wp-bootstrap
1765
1766[+] Name: blue-summit-wp-bootstrap
1767 | Location: http://www.flybox.co.il/wp-content/themes/blue-summit-wp-bootstrap/
1768 | Style URL: http://www.flybox.co.il/wp-content/themes/blue-summit-wp-bootstrap/style.css
1769 | Referenced style.css: https://www.flybox.co.il/wp-content/themes/blue-summit-wp-bootstrap/style.css
1770
1771[+] Enumerating plugins from passive detection ...
1772[+] No plugins found
1773
1774[+] Finished: Sat Dec 16 02:53:53 2017
1775[+] Requests Done: 356
1776[+] Memory used: 39.465 MB
1777[+] Elapsed time: 00:02:17
1778[+] Honeypot Probabilty: 30%
1779----------------------------------------
1780[+] Robots.txt retrieved
1781User-agent: *
1782Disallow: /wp-admin/
1783Allow: /wp-admin/admin-ajax.php
1784
1785----------------------------------------
1786PORT STATE SERVICE VERSION
178721/tcp filtered ftp
178822/tcp filtered ssh
178923/tcp filtered telnet
179025/tcp filtered smtp
179180/tcp open http Cloudflare nginx
1792110/tcp filtered pop3
1793143/tcp filtered imap
1794443/tcp open ssl/https?
1795445/tcp filtered microsoft-ds
17963389/tcp filtered ms-wbt-server
1797----------------------------------------
1798
1799[+] DNS Records
1800
1801[+] Host Records (A)
1802www.flybox.co.ilHTTP: (104.31.75.239) AS13335 Cloudflare Inc
1803
1804[+] TXT Records
1805
1806[+] DNS Map: https://dnsdumpster.com/static/map/www.flybox.co.il.png
1807
1808[>] Initiating 3 intel modules
1809[>] Loading Alpha module (1/3)
1810[>] Beta module deployed (2/3)
1811[>] Gamma module initiated (3/3)
1812No emails found
1813No hosts found
1814[+] Virtual hosts:
1815-----------------
1816[>] Crawling the target for fuzzable URLs
1817[+] Found 4 fuzzable URLs
1818https://www.flybox.co.il//selected-package/?packageid=1
1819[>] Using SQLMap api to check for SQL injection vulnerabilities. Don't
1820 worry we are using an online service and it doesn't depend on your internet connection.
1821 This scan will take 2-3 minutes.
1822[-] None of parameters is vulnerable to SQL injection
1823[+] These are the URLs having parameters:
1824https://www.flybox.co.il//selected-package/?packageid=1
1825https://www.flybox.co.il//selected-package/?packageid=1
1826https://www.flybox.co.il//selected-package/?packageid=1
1827https://www.flybox.co.il//selected-package/?packageid=1
1828#######################################################################################################################################