· 8 years ago · Sep 10, 2017, 11:14 AM
1##########################################################################################
2Hostname preteen-art.info ISP Quasi Networks LTD. (AS29073)
3Continent Africa Flag
4SC
5Country Seychelles Country Code SC (SYC)
6Region Unknown Local time 10 Sep 2017 07:09 +04
7City Unknown Latitude -4.583
8IP Address 80.82.79.116 Longitude 55.667
9###########################################################################################
10preteen-art.info
11
12###########################################################################################
13
14whois preteen-art.info
15Domain Name: PRETEEN-ART.INFO
16Registry Domain ID: D503300000038978206-LRMS
17Registrar WHOIS Server:
18Registrar URL: http://www.ukraine.com.ua
19Updated Date: 2017-06-25T20:31:58Z
20Creation Date: 2017-04-26T17:20:10Z
21Registry Expiry Date: 2018-04-26T17:20:10Z
22Registrar Registration Expiration Date:
23Registrar: Hosting Ukraine LLC
24Registrar IANA ID: 2374
25Registrar Abuse Contact Email:
26Registrar Abuse Contact Phone:
27Reseller:
28Domain Status: ok https://icann.org/epp#ok
29Registry Registrant ID: C201778539-LRMS
30Registrant Name: Privacy Protection
31Registrant Organization:
32Registrant Street: PO Box 65
33Registrant City: Kiev
34Registrant State/Province:
35Registrant Postal Code: 04112
36Registrant Country: UA
37Registrant Phone: +380.443927433
38Registrant Phone Ext:
39Registrant Fax:
40Registrant Fax Ext:
41Registrant Email: abuse@ukraine.com.ua
42Registry Admin ID: C201778539-LRMS
43Admin Name: Privacy Protection
44Admin Organization:
45Admin Street: PO Box 65
46Admin City: Kiev
47Admin State/Province:
48Admin Postal Code: 04112
49Admin Country: UA
50Admin Phone: +380.443927433
51Admin Phone Ext:
52Admin Fax:
53Admin Fax Ext:
54Admin Email: abuse@ukraine.com.ua
55Registry Tech ID: C201778539-LRMS
56Tech Name: Privacy Protection
57Tech Organization:
58Tech Street: PO Box 65
59Tech City: Kiev
60Tech State/Province:
61Tech Postal Code: 04112
62Tech Country: UA
63Tech Phone: +380.443927433
64Tech Phone Ext:
65Tech Fax:
66Tech Fax Ext:
67Tech Email: abuse@ukraine.com.ua
68Registry Billing ID: C201778539-LRMS
69Billing Name: Privacy Protection
70Billing Organization:
71Billing Street: PO Box 65
72Billing City: Kiev
73Billing State/Province:
74Billing Postal Code: 04112
75Billing Country: UA
76Billing Phone: +380.443927433
77Billing Phone Ext:
78Billing Fax:
79Billing Fax Ext:
80Billing Email: abuse@ukraine.com.ua
81Name Server: PNS21.CLOUDNS.NET
82Name Server: PNS22.CLOUDNS.NET
83Name Server: PNS24.CLOUDNS.NET
84Name Server: PNS23.CLOUDNS.NET
85
86;preteen-art.info. IN ANY
87
88;; ANSWER SECTION:
89preteen-art.info. 54 IN A 80.82.79.116
90preteen-art.info. 1480 IN NS pns21.cloudns.net.
91preteen-art.info. 1480 IN NS pns24.cloudns.net.
92preteen-art.info. 1480 IN NS ns23.cloudns.net.
93preteen-art.info. 1480 IN NS ns24.cloudns.net.
94preteen-art.info. 1480 IN NS ns22.cloudns.net.
95preteen-art.info. 1480 IN NS ns21.cloudns.net.
96preteen-art.info. 1480 IN NS pns23.cloudns.net.
97preteen-art.info. 1480 IN NS pns22.cloudns.net.
98
99###########################################################################################
100
101Checking for HTTP-Loadbalancing [Date]: 03:33:33, 03:33:33, 03:33:34, 03:33:34, 03:33:35, 03:33:36, 03:33:36, 03:33:36, 03:33:37, 03:33:38, 03:33:38, 03:33:38, 03:33:38, 03:33:39, 03:33:39, 03:33:39, 03:33:40, 03:33:40, 03:33:40, 03:33:40, 03:33:41, 03:33:41, 03:33:41, 03:33:41, 03:33:42, 03:33:42, 03:33:43, 03:33:43, 03:33:44, 03:33:44, 03:33:45, 03:33:45, 03:33:45, 03:33:45, 03:33:46, 03:33:46, 03:33:46, 03:33:47, 03:33:47, 03:33:47, 03:33:47, 03:33:48, 03:33:48, 03:33:48, 03:33:48, 03:33:49, 03:33:49, 03:33:51, 03:33:54, 03:33:54,
102###########################################################################################
103
104nmap -PN -n -F -T4 -sV -A -oG temp.txt preteen-art.info
105
106Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-09 23:30 EDT
107Nmap scan report for preteen-art.info (80.82.79.116)
108Host is up (0.13s latency).
109Not shown: 89 closed ports
110PORT STATE SERVICE VERSION
11121/tcp open ftp vsftpd 3.0.2
11222/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
113| ssh-hostkey:
114| 1024 ab:16:56:89:21:7e:75:1c:77:f3:a2:7e:c2:f1:4c:09 (DSA)
115| 2048 22:f8:e3:f6:1a:1c:6a:99:09:6b:1e:7c:fd:30:e3:95 (RSA)
116|_ 256 a8:03:f4:96:36:d1:39:de:2e:4f:56:e9:0f:f3:63:56 (ECDSA)
11725/tcp filtered smtp
11853/tcp open domain
119| dns-nsid:
120|_ bind.version: 9.8.4-rpz2+rl005.12-P1
12180/tcp open http nginx
122|_http-server-header: nginx
123|_http-title: for virgin teen, girls small teen
124111/tcp open rpcbind 2-4 (RPC #100000)
125135/tcp filtered msrpc
126139/tcp filtered netbios-ssn
127445/tcp filtered microsoft-ds
128465/tcp filtered smtps
129587/tcp filtered submission
130Aggressive OS guesses: Linux 2.6.39 (95%), Linux 3.2 - 3.8 (94%), Linux 3.8 (94%), WatchGuard Fireware 11.8 (94%), Linux 3.1 - 3.2 (94%), Linux 3.5 (93%), Linux 2.6.32 - 2.6.39 (92%), Linux 3.0 - 3.2 (91%), Linux 2.6.32 - 3.0 (91%), Linux 2.6.32 (91%)
131No exact OS matches for host (test conditions non-ideal).
132Network Distance: 10 hops
133Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
134
135TRACEROUTE (using port 3389/tcp)
136HOP RTT ADDRESS
1371 156.95 ms 10.13.0.1
1382 ...
1393 156.99 ms 178.33.103.229
1404 ...
1415 157.02 ms 213.186.32.213
1426 ...
1437 157.09 ms 176.10.83.128
1448 157.05 ms 176.10.83.5
1459 ...
14610 157.11 ms 80.82.79.116
147
148OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
149Nmap done: 1 IP address (1 host up) scanned in 54.23 seconds
150
151###########################################################################################
152
153amap -i temp.txt
154amap v5.4 (www.thc.org/thc-amap) started at 2017-09-09 23:31:23 - APPLICATION MAPPING mode
155
156Protocol on 80.82.79.116:80/tcp matches http
157Protocol on 80.82.79.116:21/tcp matches ftp
158Protocol on 80.82.79.116:22/tcp matches ssh
159Protocol on 80.82.79.116:22/tcp matches ssh-openssh
160Protocol on 80.82.79.116:111/tcp matches rpc
161Protocol on 80.82.79.116:53/tcp matches dns
162Protocol on 80.82.79.116:111/tcp matches rpc-rpcbind-v4
163
164Unidentified ports: none.
165
166amap v5.4 finished at 2017-09-09 23:31:36
167
168###########################################################################################
169%
170inetnum: 80.82.79.0 - 80.82.79.255
171netname: SC-QUASI80
172descr: QUASI
173country: SC
174org: ORG-QNL3-RIPE
175admin-c: QNL1-RIPE
176tech-c: QNL1-RIPE
177status: ASSIGNED PA
178mnt-by: QUASINETWORKS-MNT
179mnt-lower: QUASINETWORKS-MNT
180mnt-routes: QUASINETWORKS-MNT
181created: 2010-08-25T21:29:49Z
182last-modified: 2016-01-23T23:04:27Z
183source: RIPE
184
185organisation: ORG-QNL3-RIPE
186org-name: Quasi Networks LTD.
187org-type: OTHER
188address: Suite 1, Second Floor
189address: Sound & Vision House, Francis Rachel Street
190address: Victoria, Mahe, SEYCHELLES
191remarks: *****************************************************************************
192remarks: IMPORTANT INFORMATION
193remarks: *****************************************************************************
194remarks: We are a high bandwidth network provider offering bandwidth solutions.
195remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
196remarks: Please only use abuse@quasinetworks.com for abuse reports.
197remarks: For all other requests, please see the details on our website.
198remarks: *****************************************************************************
199abuse-mailbox: abuse@quasinetworks.com
200abuse-c: AR34302-RIPE
201mnt-ref: QUASINETWORKS-MNT
202mnt-by: QUASINETWORKS-MNT
203created: 2015-11-08T22:25:26Z
204last-modified: 2015-11-27T09:37:50Z
205source: RIPE # Filtered
206
207role: Quasi Networks LTD
208address: Suite 1, Second Floor
209address: Sound & Vision House, Francis Rachel Street
210address: Victoria, Mahe, SEYCHELLES
211remarks: *****************************************************************************
212remarks: IMPORTANT INFORMATION
213remarks: *****************************************************************************
214remarks: We are a high bandwidth network provider offering bandwidth solutions.
215remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
216remarks: Please only use abuse@quasinetworks.com for abuse reports.
217remarks: For all other requests, please see the details on our website.
218remarks: *****************************************************************************
219abuse-mailbox: abuse@quasinetworks.com
220nic-hdl: QNL1-RIPE
221mnt-by: QUASINETWORKS-MNT
222created: 2015-11-07T22:43:04Z
223last-modified: 2015-11-07T23:04:49Z
224source: RIPE # Filtered
225
226% Information related to '80.82.79.0/24AS29073'
227
228route: 80.82.79.0/24
229descr: Quasi Networks LTD (IBC)
230origin: AS29073
231mnt-by: QUASINETWORKS-MNT
232created: 2010-08-25T21:31:02Z
233last-modified: 2016-01-23T23:04:45Z
234source: RIPE
235
236% This query was served by the RIPE Database Query Service version 1.89.2 (HEREFORD)
237
238###########################################################################################
239
240[i] Scanning Site: http://preteen-art.info
241
242
243
244B A S I C I N F O
245====================
246
247
248[+] Site Title: for virgin teen, girls small teen
249[+] IP address: 80.82.79.116
250[+] Web Server: nginx
251[+] CMS: Could Not Detect
252[+] Cloudflare: Not Detected
253[+] Robots File: Could NOT Find robots.txt!
254
255
256
257
258W H O I S L O O K U P
259========================
260
261 Domain Name: PRETEEN-ART.INFO
262Registry Domain ID: D503300000038978206-LRMS
263Registrar WHOIS Server:
264Registrar URL: http://www.ukraine.com.ua
265Updated Date: 2017-06-25T20:31:58Z
266Creation Date: 2017-04-26T17:20:10Z
267Registry Expiry Date: 2018-04-26T17:20:10Z
268Registrar Registration Expiration Date:
269Registrar: Hosting Ukraine LLC
270Registrar IANA ID: 2374
271Registrar Abuse Contact Email:
272Registrar Abuse Contact Phone:
273Reseller:
274Domain Status: ok https://icann.org/epp#ok
275Registry Registrant ID: C201778539-LRMS
276Registrant Name: Privacy Protection
277Registrant Organization:
278Registrant Street: PO Box 65
279Registrant City: Kiev
280Registrant State/Province:
281Registrant Postal Code: 04112
282Registrant Country: UA
283Registrant Phone: +380.443927433
284Registrant Phone Ext:
285Registrant Fax:
286Registrant Fax Ext:
287Registrant Email: abuse@ukraine.com.ua
288Registry Admin ID: C201778539-LRMS
289Admin Name: Privacy Protection
290Admin Organization:
291Admin Street: PO Box 65
292Admin City: Kiev
293Admin State/Province:
294Admin Postal Code: 04112
295Admin Country: UA
296Admin Phone: +380.443927433
297Admin Phone Ext:
298Admin Fax:
299Admin Fax Ext:
300Admin Email: abuse@ukraine.com.ua
301Registry Tech ID: C201778539-LRMS
302Tech Name: Privacy Protection
303Tech Organization:
304Tech Street: PO Box 65
305Tech City: Kiev
306Tech State/Province:
307Tech Postal Code: 04112
308Tech Country: UA
309Tech Phone: +380.443927433
310Tech Phone Ext:
311Tech Fax:
312Tech Fax Ext:
313Tech Email: abuse@ukraine.com.ua
314Registry Billing ID: C201778539-LRMS
315Billing Name: Privacy Protection
316Billing Organization:
317Billing Street: PO Box 65
318Billing City: Kiev
319Billing State/Province:
320Billing Postal Code: 04112
321Billing Country: UA
322Billing Phone: +380.443927433
323Billing Phone Ext:
324Billing Fax:
325Billing Fax Ext:
326Billing Email: abuse@ukraine.com.ua
327Name Server: PNS21.CLOUDNS.NET
328Name Server: PNS22.CLOUDNS.NET
329Name Server: PNS24.CLOUDNS.NET
330Name Server: PNS23.CLOUDNS.NET
331
332
333G E O I P L O O K U P
334=========================
335
336[i] IP Address: 80.82.79.116
337[i] Country: SC
338[i] State: N/A
339[i] City: N/A
340[i] Latitude: -4.583300
341[i] Longitude: 55.666698
342
343
344
345
346H T T P H E A D E R S
347=======================
348
349
350[i] HTTP/1.1 200 OK
351[i] Server: nginx
352[i] Date: Sun, 10 Sep 2017 03:33:20 GMT
353[i] Content-Type: text/html
354[i] Connection: close
355[i] Vary: Accept-Encoding
356[i] X-Powered-By: PHP/5.4.45-0+deb7u8
357[i] Set-Cookie: site_id=1; expires=Sun, 10-Sep-2017 15:33:20 GMT
358[i] Vary: Accept-Encoding
359
360
361
362
363D N S L O O K U P
364===================
365
366preteen-art.info. 56 IN A 80.82.79.116
367preteen-art.info. 3600 IN NS ns23.cloudns.net.
368preteen-art.info. 3600 IN NS ns22.cloudns.net.
369preteen-art.info. 3600 IN NS ns21.cloudns.net.
370preteen-art.info. 3600 IN NS pns23.cloudns.net.
371preteen-art.info. 3600 IN NS ns24.cloudns.net.
372preteen-art.info. 3600 IN NS pns22.cloudns.net.
373preteen-art.info. 3600 IN NS pns21.cloudns.net.
374preteen-art.info. 3600 IN NS pns24.cloudns.net.
375preteen-art.info. 3600 IN SOA ns21.cloudns.net. support.cloudns.net. 2017091018 7200 1800 1209600 3600
376
377
378
379
380S U B N E T C A L C U L A T I O N
381====================================
382
383Address = 80.82.79.116
384Network = 80.82.79.116 / 32
385Netmask = 255.255.255.255
386Broadcast = not needed on Point-to-Point links
387Wildcard Mask = 0.0.0.0
388Hosts Bits = 0
389Max. Hosts = 1 (2^0 - 0)
390Host Range = { 80.82.79.116 - 80.82.79.116 }
391
392
393
394N M A P P O R T S C A N
395============================
396
397
398Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 03:29 UTC
399Nmap scan report for preteen-art.info (80.82.79.116)
400Host is up (0.083s latency).
401rDNS record for 80.82.79.116: no-reverse-dns-configured.com
402PORT STATE SERVICE VERSION
40321/tcp open ftp vsftpd 3.0.2
40422/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
40523/tcp closed telnet
40625/tcp closed smtp
40780/tcp open http nginx
408110/tcp closed pop3
409143/tcp closed imap
410443/tcp closed https
411445/tcp closed microsoft-ds
4123389/tcp closed ms-wbt-server
413Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
414
415Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
416Nmap done: 1 IP address (1 host up) scanned in 7.27 seconds
417
418
419
420S U B - D O M A I N F I N D E R
421==================================
422
423
424[i] Total Subdomains Found : 1
425
426[+] Subdomain: preteen-art.info
427[-] IP: 80.82.79.116
428[*] Performing TLD Brute force Enumeration against preteen-art.info
429[*] The operation could take up to: 00:01:07
430[*] A preteen-art.biz.af 5.45.75.45
431[*] CNAME preteen-art.biz.at free.biz.at
432[*] A free.biz.at 216.92.134.29
433[*] A preteen-art.org.aw 142.4.20.12
434[*] A preteen-art.co.ba 176.9.45.78
435[*] A preteen-art.com.ba 195.222.33.180
436[*] A preteen-art.com.be 95.173.170.166
437[*] A preteen-art.co.asia 91.195.240.135
438[*] A preteen-art.biz.by 71.18.52.2
439[*] A preteen-art.biz.bz 199.59.242.150
440[*] A preteen-art.com.cc 54.252.107.64
441[*] A preteen-art.net.cc 54.252.89.206
442[*] A preteen-art.co.cc 175.126.123.219
443[*] A preteen-art.org.ch 72.52.4.122
444[*] A preteen-art.co.cm 85.25.140.105
445[*] A preteen-art.net.cm 85.25.140.105
446[*] A preteen-art.biz.cl 185.53.178.8
447[*] A preteen-art.com.com 52.33.196.199
448[*] A preteen-art.com 167.114.156.214
449[*] A preteen-art.net.com 199.59.242.150
450[*] A preteen-art.co.com 173.192.115.17
451[*] A preteen-art.org.com 23.23.86.44
452[*] A preteen-art.biz.cr 72.52.4.122
453[*] CNAME preteen-art.biz.cm i.cns.cm
454[*] A i.cns.cm 118.184.56.30
455[*] A preteen-art.biz.cx 72.52.4.122
456[*] A preteen-art.net.cz 80.250.24.177
457[*] A preteen-art.de 212.227.111.250
458[*] A preteen-art.biz.cz 185.53.179.7
459[*] A preteen-art.com.cz 62.109.128.30
460[*] A preteen-art.com.de 50.56.68.37
461[*] CNAME preteen-art.co.de co.de
462[*] A co.de 144.76.162.245
463[*] CNAME preteen-art.org.de www.org.de
464[*] A www.org.de 78.47.128.8
465[*] A preteen-art.net.eu 78.46.90.98
466[*] A preteen-art.org.eu 78.46.90.98
467[*] A preteen-art.biz.fi 185.55.85.123
468[*] A preteen-art.fm 173.230.131.38
469[*] A preteen-art.biz.fm 173.230.131.38
470[*] A preteen-art.org.fr 149.202.133.35
471[*] A preteen-art.biz.gl 72.52.4.122
472[*] CNAME preteen-art.co.gp co.gp
473[*] A co.gp 144.76.162.245
474[*] A preteen-art.co.hn 208.100.40.203
475[*] CNAME preteen-art.net.hr net.hr
476[*] A net.hr 192.0.78.24
477[*] A net.hr 192.0.78.25
478[*] CNAME preteen-art.biz.hn parkmydomain.vhostgo.com
479[*] A parkmydomain.vhostgo.com 107.186.245.118
480[*] A preteen-art.co.ht 72.52.4.122
481[*] A preteen-art.info 89.248.166.21
482[*] A preteen-art.co.jobs 50.17.193.222
483[*] A preteen-art.com.jobs 50.19.241.165
484[*] A preteen-art.biz.jobs 50.19.241.165
485[*] A preteen-art.net.jobs 50.19.241.165
486[*] A preteen-art.org.jobs 50.19.241.165
487[*] A preteen-art.biz.ky 199.184.144.27
488[*] CNAME preteen-art.biz.li 712936.parkingcrew.net
489[*] A 712936.parkingcrew.net 185.53.179.29
490[*] A preteen-art.biz.lu 195.26.5.2
491[*] A preteen-art.biz.ly 64.136.20.39
492[*] A preteen-art.biz.md 72.52.4.122
493[*] A preteen-art.co.mk 87.76.31.211
494[*] A preteen-art.co.mobi 54.225.105.179
495[*] A preteen-art.biz.my 202.190.174.44
496[*] A preteen-art.co.net 188.166.216.219
497[*] A preteen-art.net.net 52.50.81.210
498[*] A preteen-art.net 45.33.9.234
499[*] A preteen-art.org.net 23.23.86.44
500[*] A preteen-art.co.nl 37.97.184.204
501[*] A preteen-art.com.nl 83.98.157.102
502[*] A preteen-art.net.nl 83.98.157.102
503[*] A preteen-art.co.nr 208.100.40.202
504[*] CNAME preteen-art.co.nu co.nu
505[*] A co.nu 144.76.162.245
506[*] CNAME preteen-art.com.nu com.nu
507[*] A com.nu 144.76.162.245
508[*] A preteen-art.net.nu 199.102.76.78
509[*] A preteen-art.org.nu 80.92.84.139
510[*] CNAME preteen-art.net.org pewtrusts.org
511[*] A pewtrusts.org 204.74.99.100
512[*] A preteen-art.com.org 23.23.86.44
513[*] A preteen-art.ph 45.79.222.138
514[*] A preteen-art.co.ph 45.79.222.138
515[*] A preteen-art.com.ph 45.79.222.138
516[*] A preteen-art.net.ph 45.79.222.138
517[*] A preteen-art.org.ph 45.79.222.138
518[*] A preteen-art.co.pl 212.91.6.55
519[*] A preteen-art.org.pm 208.73.211.177
520[*] A preteen-art.org.pm 208.73.210.202
521[*] A preteen-art.org.pm 208.73.211.165
522[*] A preteen-art.org.pm 208.73.210.217
523[*] A preteen-art.co.ps 66.96.132.56
524[*] CNAME preteen-art.biz.ps biz.ps
525[*] A biz.ps 144.76.162.245
526[*] A preteen-art.co.pt 194.107.127.52
527[*] A preteen-art.co.pw 141.8.226.59
528[*] A preteen-art.pw 141.8.226.58
529[*] A preteen-art.net.pw 141.8.226.59
530[*] A preteen-art.biz.pw 141.8.226.59
531[*] A preteen-art.org.pw 141.8.226.59
532[*] CNAME preteen-art.co.ro now.co.ro
533[*] A now.co.ro 185.27.255.9
534[*] A preteen-art.net.ro 69.64.52.127
535[*] A preteen-art.org.re 217.70.184.38
536[*] A preteen-art.com.ru 178.210.89.119
537[*] A preteen-art.biz.se 185.53.179.6
538[*] CNAME preteen-art.net.se 773147.parkingcrew.net
539[*] A 773147.parkingcrew.net 185.53.179.29
540[*] A preteen-art.co.sl 91.195.240.135
541[*] A preteen-art.com.sr 143.95.106.249
542[*] A preteen-art.biz.st 91.121.28.115
543[*] A preteen-art.co.su 72.52.4.122
544[*] A preteen-art.biz.tc 64.136.20.39
545[*] A preteen-art.biz.tf 85.236.153.18
546[*] A preteen-art.net.tf 188.40.70.27
547[*] A preteen-art.net.tf 188.40.117.12
548[*] A preteen-art.net.tf 188.40.70.29
549[*] A preteen-art.co.tl 208.100.40.202
550[*] A preteen-art.co.to 175.118.124.44
551[*] A preteen-art.co.tv 31.186.25.163
552[*] A preteen-art.biz.tv 72.52.4.122
553[*] A preteen-art.org.tv 72.52.4.122
554[*] CNAME preteen-art.biz.uz biz.uz
555[*] A biz.uz 144.76.162.245
556[*] A preteen-art.vg 88.198.29.97
557[*] A preteen-art.co.vg 88.198.29.97
558[*] A preteen-art.com.vg 88.198.29.97
559[*] A preteen-art.net.vg 68.178.254.180
560[*] A preteen-art.biz.vg 89.31.143.20
561[*] A preteen-art.ws 64.70.19.203
562[*] A preteen-art.com.ws 202.4.48.211
563[*] A preteen-art.net.ws 202.4.48.211
564[*] A preteen-art.org.ws 202.4.48.211
565[*] A preteen-art.biz.ws 184.168.221.104
566R E V E R S E I P L O O K U P
567==================================
568
569
570[i] Total Sites Found On This Server : 2
571
572
573[#] preteen-art.info
574[-] CMS: Could Not Detect
575
576[#] teendolls.online,
577[-] CMS: Could Not Detect
578preteen-art.info
579
580
581Domain Name: PRETEEN-ART.INFO
582Registry Domain ID: D503300000038978206-LRMS
583Registrar WHOIS Server:
584Registrar URL: http://www.ukraine.com.ua
585Updated Date: 2017-06-25T20:31:58Z
586Creation Date: 2017-04-26T17:20:10Z
587Registry Expiry Date: 2018-04-26T17:20:10Z
588Registrar Registration Expiration Date:
589Registrar: Hosting Ukraine LLC
590Registrar IANA ID: 2374
591Registrar Abuse Contact Email:
592Registrar Abuse Contact Phone:
593Reseller:
594Domain Status: ok https://icann.org/epp#ok
595Registry Registrant ID: C201778539-LRMS
596Registrant Name: Privacy Protection
597Registrant Organization:
598Registrant Street: PO Box 65
599Registrant City: Kiev
600Registrant State/Province:
601Registrant Postal Code: 04112
602Registrant Country: UA
603Registrant Phone: +380.443927433
604Registrant Phone Ext:
605Registrant Fax:
606Registrant Fax Ext:
607Registrant Email: abuse@ukraine.com.ua
608Registry Admin ID: C201778539-LRMS
609Admin Name: Privacy Protection
610Admin Organization:
611Admin Street: PO Box 65
612Admin City: Kiev
613Admin State/Province:
614Admin Postal Code: 04112
615Admin Country: UA
616Admin Phone: +380.443927433
617Admin Phone Ext:
618Admin Fax:
619Admin Fax Ext:
620Admin Email: abuse@ukraine.com.ua
621Registry Tech ID: C201778539-LRMS
622Tech Name: Privacy Protection
623Tech Organization:
624Tech Street: PO Box 65
625Tech City: Kiev
626Tech State/Province:
627Tech Postal Code: 04112
628Tech Country: UA
629Tech Phone: +380.443927433
630Tech Phone Ext:
631Tech Fax:
632Tech Fax Ext:
633Tech Email: abuse@ukraine.com.ua
634Registry Billing ID: C201778539-LRMS
635Billing Name: Privacy Protection
636Billing Organization:
637Billing Street: PO Box 65
638Billing City: Kiev
639Billing State/Province:
640Billing Postal Code: 04112
641Billing Country: UA
642Billing Phone: +380.443927433
643Billing Phone Ext:
644Billing Fax:
645Billing Fax Ext:
646Billing Email: abuse@ukraine.com.ua
647Name Server: PNS21.CLOUDNS.NET
648Name Server: PNS22.CLOUDNS.NET
649Name Server: PNS24.CLOUDNS.NET
650Name Server: PNS23.CLOUDNS.NET
651
652;preteen-art.info. IN ANY
653
654;; ANSWER SECTION:
655preteen-art.info. 56 IN A 80.82.79.116
656preteen-art.info. 1482 IN NS pns21.cloudns.net.
657preteen-art.info. 1482 IN NS ns21.cloudns.net.
658preteen-art.info. 1482 IN NS ns22.cloudns.net.
659preteen-art.info. 1482 IN NS pns24.cloudns.net.
660preteen-art.info. 1482 IN NS pns22.cloudns.net.
661preteen-art.info. 1482 IN NS ns23.cloudns.net.
662preteen-art.info. 1482 IN NS ns24.cloudns.net.
663preteen-art.info. 1482 IN NS pns23.cloudns.net.
664
665Host's addresses:
666__________________
667
668preteen-art.info. 45 IN A 80.82.79.116
669
670
671Wildcard detection using: dfzsoiabzgya
672_______________________________________
673
674dfzsoiabzgya.preteen-art.info. 60 IN A 80.82.79.116
675
676
677!!!!!!!!!!!!!!!!!!!!!!!!!!!!
678
679 Wildcards detected, all subdomains will point to the same IP address
680 Omitting results containing 80.82.79.116.
681 Maybe you are using OpenDNS servers.
682
683!!!!!!!!!!!!!!!!!!!!!!!!!!!!
684
685
686Name Servers:
687______________
688
689pns24.cloudns.net. 114834 IN A 185.136.99.96
690pns23.cloudns.net. 153160 IN A 185.136.98.96
691pns21.cloudns.net. 114834 IN A 185.136.96.96
692ns22.cloudns.net. 132523 IN A 108.59.2.202
693ns21.cloudns.net. 54205 IN A 109.201.133.61
694ns24.cloudns.net. 148264 IN A 46.165.221.164
695ns23.cloudns.net. 164590 IN A 79.137.84.65
696pns22.cloudns.net. 114833 IN A 185.136.97.96
697
698
699Mail (MX) Servers:
700___________________
701
702
703preteen-art.info class C netranges:
704____________________________________
705
706 80.82.79.0/24
707
708
709Performing reverse lookup on 256 ip addresses:
710_______________________________________________
711
712
7130 results out of 256 IP addresses.
714
715
716preteen-art.info ip blocks:
717____________________________
718
719
720 |\___ ns22.cloudns.net [preteen-art.info] (2604:9a00:2100:a006:0004:0000:0000:0001) Got authoritative answer
721 |\___ ns22.cloudns.net [preteen-art.info] (108.59.2.202) Got authoritative answer
722 |\___ ns23.cloudns.net [preteen-art.info] (2001:41d0:0401:3100:0000:0000:0000:5784) * * *
723 |\___ ns23.cloudns.net [preteen-art.info] (79.137.84.65) Got authoritative answer
724 |\___ pns24.cloudns.net [preteen-art.info] (2a06:fb00:0001:0000:0000:0000:0004:0096) Got authoritative answer
725 |\___ pns24.cloudns.net [preteen-art.info] (185.136.99.96) Got authoritative answer
726 |\___ pns22.cloudns.net [preteen-art.info] (2a06:fb00:0001:0000:0000:0000:0002:0096) Got authoritative answer
727 |\___ pns22.cloudns.net [preteen-art.info] (185.136.97.96) Got authoritative answer
728 |\___ pns21.cloudns.net [preteen-art.info] (2a06:fb00:0001:0000:0000:0000:0001:0096) Got authoritative answer
729 |\___ pns21.cloudns.net [preteen-art.info] (185.136.96.96) Got authoritative answer
730 |\___ ns21.cloudns.net [preteen-art.info] (109.201.133.61) Got authoritative answer
731 |\___ ns21.cloudns.net [preteen-art.info] (2a00:1768:1001:0009:0000:0000:0000:0021) Got authoritative answer
732 |\___ ns24.cloudns.net [preteen-art.info] (2a00:0c98:2030:a006:0002:0000:0000:0001) Got authoritative answer
733 |\___ ns24.cloudns.net [preteen-art.info] (46.165.221.164) Got authoritative answer
734 |\___ pns23.cloudns.net [preteen-art.info] (2a06:fb00:0001:0000:0000:0000:0003:0096) Got authoritative answer
735 \___ pns23.cloudns.net [preteen-art.info] (185.136.98.96) Got authoritative answer
736
737
738WhatWeb report for http://preteen-art.info
739Status : 200 OK
740Title : for virgin teen, girls small teen
741IP : 80.82.79.116
742Country : NETHERLANDS, NL
743
744Summary : X-Powered-By[PHP/5.4.45-0+deb7u8], HTTPServer[nginx], Cookies[site_id], PHP[5.4.45-0+deb7u8], nginx, Script[text/javascript]
745
746Detected Plugins:
747[ Cookies ]
748 Display the names of cookies in the HTTP headers. The
749 values are not returned to save on space.
750
751 String : site_id
752
753[ HTTPServer ]
754 HTTP server header string. This plugin also attempts to
755 identify the operating system from the server header.
756
757 String : nginx (from server string)
758
759[ PHP ]
760 PHP is a widely-used general-purpose scripting language
761 that is especially suited for Web development and can be
762 embedded into HTML. This plugin identifies PHP errors,
763 modules and versions and extracts the local file path and
764 username if present.
765
766 Version : 5.4.45-0+deb7u8
767 Google Dorks: (2)
768 Website : http://www.php.net/
769
770[ Script ]
771 This plugin detects instances of script HTML elements and
772 returns the script language/type.
773
774 String : text/javascript
775
776[ X-Powered-By ]
777 X-Powered-By HTTP header
778
779 String : PHP/5.4.45-0+deb7u8 (from x-powered-by string)
780
781[ nginx ]
782 Nginx (Engine-X) is a free, open-source, high-performance
783 HTTP server and reverse proxy, as well as an IMAP/POP3
784 proxy server.
785
786 Website : http://nginx.net/
787
788HTTP Headers:
789 HTTP/1.1 200 OK
790 Server: nginx
791 Date: Sun, 10 Sep 2017 03:38:56 GMT
792 Content-Type: text/html
793 Content-Length: 2909
794 Connection: close
795 X-Powered-By: PHP/5.4.45-0+deb7u8
796 Set-Cookie: site_id=1; expires=Sun, 10-Sep-2017 15:38:56 GMT
797 Vary: Accept-Encoding
798 Content-Encoding: gzip
799
800
801
802
803 ^ ^
804 _ __ _ ____ _ __ _ _ ____
805 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
806 | V V // o // _/ | V V // 0 // 0 // _/
807 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
808 <
809 ...'
810
811 WAFW00F - Web Application Firewall Detection Tool
812
813 By Sandro Gauci && Wendel G. Henrique
814
815Checking http://preteen-art.info
816Generic Detection results:
817No WAF detected by the generic detection
818Number of requests: 13
819
820
821DNS Servers for preteen-art.info:
822 pns21.cloudns.net
823 pns22.cloudns.net
824 ns22.cloudns.net
825 pns23.cloudns.net
826 ns21.cloudns.net
827 pns24.cloudns.net
828 ns23.cloudns.net
829 ns24.cloudns.net
830
831
832
833Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
834
835 ----------------------------------------------------------
836| Scan Information |
837 ----------------------------------------------------------
838
839Mode ..................... VRFY
840Worker Processes ......... 5
841Usernames file ........... users.txt
842Target count ............. 1
843Username count ........... 494
844Target TCP port .......... 25
845Query timeout ............ 5 secs
846Target domain ............
847
848######## Scan started at Sat Sep 9 23:42:55 2017 #########
849######## Scan completed at Sat Sep 9 23:51:10 2017 #########
8500 results.
851
852494 queries in 495 seconds (1.0 queries / sec)
853
854
855
856Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-09 23:51 EDT
857NSE: Loaded 146 scripts for scanning.
858NSE: Script Pre-scanning.
859Initiating NSE at 23:51
860Completed NSE at 23:51, 0.00s elapsed
861Initiating NSE at 23:51
862Completed NSE at 23:51, 0.00s elapsed
863Failed to resolve "preteen-art.info.txt".
864Initiating Parallel DNS resolution of 1 host. at 23:51
865Completed Parallel DNS resolution of 1 host. at 23:51, 0.59s elapsed
866Initiating SYN Stealth Scan at 23:51
867Scanning preteen-art.info (80.82.79.116) [100 ports]
868Discovered open port 53/tcp on 80.82.79.116
869Discovered open port 80/tcp on 80.82.79.116
870Discovered open port 21/tcp on 80.82.79.116
871Discovered open port 22/tcp on 80.82.79.116
872Discovered open port 111/tcp on 80.82.79.116
873Completed SYN Stealth Scan at 23:51, 3.63s elapsed (100 total ports)
874Initiating Service scan at 23:51
875Scanning 5 services on preteen-art.info (80.82.79.116)
876Completed Service scan at 23:51, 11.37s elapsed (5 services on 1 host)
877Initiating OS detection (try #1) against preteen-art.info (80.82.79.116)
878Retrying OS detection (try #2) against preteen-art.info (80.82.79.116)
879Initiating Traceroute at 23:51
880Completed Traceroute at 23:51, 3.01s elapsed
881Initiating Parallel DNS resolution of 7 hosts. at 23:51
882Completed Parallel DNS resolution of 7 hosts. at 23:51, 5.62s elapsed
883NSE: Script scanning 80.82.79.116.
884Initiating NSE at 23:51
885Completed NSE at 23:52, 32.19s elapsed
886Initiating NSE at 23:52
887Completed NSE at 23:52, 0.34s elapsed
888Nmap scan report for preteen-art.info (80.82.79.116)
889Host is up (0.18s latency).
890rDNS record for 80.82.79.116: no-reverse-dns-configured.com
891Not shown: 89 closed ports
892PORT STATE SERVICE VERSION
89321/tcp open ftp vsftpd 3.0.2
89422/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
895| ssh-hostkey:
896| 1024 ab:16:56:89:21:7e:75:1c:77:f3:a2:7e:c2:f1:4c:09 (DSA)
897| 2048 22:f8:e3:f6:1a:1c:6a:99:09:6b:1e:7c:fd:30:e3:95 (RSA)
898|_ 256 a8:03:f4:96:36:d1:39:de:2e:4f:56:e9:0f:f3:63:56 (ECDSA)
89925/tcp filtered smtp
90053/tcp open domain
901| dns-nsid:
902|_ bind.version: 9.8.4-rpz2+rl005.12-P1
90380/tcp open http nginx
904|_http-favicon: Unknown favicon MD5: E10A0146806273296BECCD951556D611
905| http-methods:
906|_ Supported Methods: GET HEAD POST
907|_http-server-header: nginx
908|_http-title: for virgin teen, girls small teen
909111/tcp open rpcbind 2-4 (RPC #100000)
910135/tcp filtered msrpc
911139/tcp filtered netbios-ssn
912445/tcp filtered microsoft-ds
913465/tcp filtered smtps
914587/tcp filtered submission
915Aggressive OS guesses: Linux 2.6.39 (96%), Linux 3.2 - 3.8 (95%), Linux 3.8 (95%), WatchGuard Fireware 11.8 (95%), Linux 3.1 - 3.2 (94%), Linux 3.5 (93%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.0 - 3.2 (92%), Linux 2.6.32 - 3.0 (92%), Linux 2.6.32 (91%)
916No exact OS matches for host (test conditions non-ideal).
917Uptime guess: 6.527 days (since Sun Sep 3 11:13:52 2017)
918Network Distance: 10 hops
919TCP Sequence Prediction: Difficulty=259 (Good luck!)
920IP ID Sequence Generation: All zeros
921Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
922
923TRACEROUTE (using port 8080/tcp)
924HOP RTT ADDRESS
9251 408.56 ms 10.13.0.1
9262 ...
9273 413.27 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
9284 424.32 ms 10.95.33.8
9295 424.36 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
9306 ...
9317 467.97 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
9328 467.84 ms 176.10.83.5
9339 ...
93410 467.90 ms no-reverse-dns-configured.com (80.82.79.116)
935
936
937
938
939 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
940 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
941 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
942 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
943 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
944
945 _/ User-Agent Tester ↵
946 _/ AKA: Purple Pimp ↵
947 _/ ChrisJohnRiley ↵
948 _/ blog.c22.cc ↵
949
950 [>] Performing initial request and confirming stability
951 [>] Using User-Agent string Mozilla/5.0
952
953 [ ] URL (ENTERED): http://preteen-art.info
954 [ ] Response Code: 200 OK
955 [ ] Server: nginx
956 [ ] Date: Sun, 10 Sep 2017 03:55:58 GMT
957 [ ] Content-Type: text/html
958 [ ] Transfer-Encoding: chunked
959 [ ] Connection: close
960 [ ] Vary: Accept-Encoding
961 [ ] X-Powered-By: PHP/5.4.45-0+deb7u8
962 [ ] Set-Cookie: site_id=1; expires=Sun, 10-Sep-2017 15:55:58 GMT
963 [ ] Vary: Accept-Encoding
964 [ ] Data (MD5): 96f209843590bb6aba7d59904bdc78f3
965
966 [1] Pass
967 [2] Pass
968 [3] Pass
969
970 [>] URL appears stable. Beginning test
971
972 [>] Using DEFAULT User-Agent Strings
973
974 [>] Using Crazy User-Agent Strings
975 [>] Using Bot User-Agent Strings
976
977 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
978
979
980 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
981
982
983 [!] Data (MD5): b1d179b8237ca36aceb474efec763bf3
984
985
986 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
987
988
989 [!] Data (MD5): 427377b3885c947fc95dfb6d2cfe7305
990
991
992 [>] User-Agent String : TrackBack/1.02
993
994
995 [!] Data (MD5): 088be84a7a168744c6a94445b5c2e50e
996
997
998 [>] User-Agent String : wispr
999
1000
1001 [!] Data (MD5): 70b62f4d7d5c0eb9b892494d1537c534
1002
1003
1004 [>] User-Agent String : EMPTY USER-AGENT STRING!
1005
1006
1007 [!] Data (MD5): 89069f1591f0c6e749fcca836c2fcb14
1008
1009
1010 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
1011
1012
1013 [!] Data (MD5): 16eb4f40d5e17e4b12c79fc8c9d43ba6
1014
1015
1016 [>] User-Agent String : Googlebot-Image/1.0
1017
1018
1019 [!] Data (MD5): 0965bc18cb2ac8d18d5d99764016903c
1020
1021
1022 [>] User-Agent String : Mediapartners-Google
1023
1024
1025 [!] Data (MD5): 7e34014131d2105ec31d3810dd6c7bfb
1026
1027
1028 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
1029
1030
1031 [!] Data (MD5): 41f61ece1c6010755324db743e6d16f3
1032
1033
1034 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
1035
1036
1037 [!] Data (MD5): 9da6e4cf49ae8eaf0d9e1a70d10635f5
1038
1039
1040 [>] User-Agent String : mmcrawler
1041
1042
1043 [!] Data (MD5): 966ce151ffd750c0390362d536387b23
1044
1045
1046 [>] Checks completed... try enabling VERBOSE mode for more detailed output
1047
1048 [>] That's all folks... Fo' Shizzle!
1049##############################################################################################
1050
1051Hostname nobare.com ISP Quasi Networks LTD. (AS29073)
1052Continent Africa Flag
1053SC
1054Country Seychelles Country Code SC (SYC)
1055Region Unknown Local time 10 Sep 2017 07:37 +04
1056City Unknown Latitude -4.583
1057IP Address 80.82.79.116 Longitude 55.667
1058#########################################################################################
1059nobare.com
1060
1061###########################################################################################
1062
1063whois nobare.com
1064 Domain Name: NOBARE.COM
1065 Registry Domain ID: 2000363694_DOMAIN_COM-VRSN
1066 Registrar WHOIS Server: whois.bizcn.com
1067 Registrar URL: http://www.bizcn.com
1068 Updated Date: 2017-04-28T08:16:12Z
1069 Creation Date: 2016-02-05T11:43:33Z
1070 Registry Expiry Date: 2018-02-05T11:43:33Z
1071 Registrar: Bizcn.com, Inc.
1072 Registrar IANA ID: 471
1073 Registrar Abuse Contact Email:
1074 Registrar Abuse Contact Phone:
1075 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
1076 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1077 Name Server: NS23.CLOUDNS.NET
1078 Name Server: PNS21.CLOUDNS.NET
1079 Name Server: PNS23.CLOUDNS.NET
1080 Name Server: PNS24.CLOUDNS.NET
1081 Name Server: PNS28.CLOUDNS.NET
1082 Name Server: PNS30.CLOUDNS.NET
1083
1084Domain name: nobare.com
1085Registry Domain ID: 2000363694_DOMAIN_COM-VRSN
1086Registrar WHOIS Server: whois.bizcn.com
1087Registrar URL: http://www.bizcn.com
1088Updated Date: 2017-02-02T23:00:03Z
1089Creation Date: 2016-02-05T11:43:33Z
1090Registrar Registration Expiration Date: 2018-02-05T11:43:33Z
1091Registrar: Bizcn.com,Inc.
1092Registrar IANA ID: 471
1093Registrar Abuse Contact Email: abuse@bizcn.com
1094Registrar Abuse Contact Phone: +86.5922577888
1095Reseller: Cnobin Technology HK Limited
1096Domain Status: clientDeleteProhibited (http://www.icann.org/epp#clientDeleteProhibited)
1097Domain Status: clientTransferProhibited (http://www.icann.org/epp#clientTransferProhibited)
1098Registry Registrant ID: Not Available From Registry
1099Registrant Name: Wuxi Yilian LLC
1100Registrant Organization: Wuxi Yilian LLC
1101Registrant Street: No.1001 Anling Road
1102Registrant City: Xiamen
1103Registrant State/Province: Fujian
1104Registrant Postal Code: 361008
1105Registrant Country: cn
1106Registrant Phone: +86.5922577888
1107Registrant Phone Ext:
1108Registrant Fax: +86.5922179606
1109Registrant Fax Ext:
1110Registrant Email: whoisprivacyprotect@whoisservices.cn
1111Registry Admin ID: Not Available From Registry
1112Admin Name: Wuxi Yilian LLC
1113Admin Organization: Wuxi Yilian LLC
1114Admin Street: No.1001 Anling Road
1115Admin City: Xiamen
1116Admin State/Province: Fujian
1117Admin Postal Code: 361008
1118Admin Country: cn
1119Admin Phone: +86.5922577888
1120Admin Phone Ext:
1121Admin Fax: +86.5922179606
1122Admin Fax Ext:
1123Admin Email: whoisprivacyprotect@whoisservices.cn
1124Registry Tech ID: Not Available From Registry
1125Tech Name: Wuxi Yilian LLC
1126Tech Organization: Wuxi Yilian LLC
1127Tech Street: No.1001 Anling Road
1128Tech City: Xiamen
1129Tech State/Province: Fujian
1130Tech Postal Code: 361008
1131Tech Country: cn
1132Tech Phone: +86.5922577888
1133Tech Phone Ext:
1134Tech Fax: +86.5922179606
1135Tech Fax Ext:
1136Tech Email: whoisprivacyprotect@whoisservices.cn
1137Name Server: pns23.cloudns.net
1138Name Server: pns24.cloudns.net
1139Name Server: pns21.cloudns.net
1140Name Server: pns28.cloudns.net
1141Name Server: pns30.cloudns.net
1142Name Server: ns23.cloudns.net
1143
1144###########################################################################################
1145IN ANY
1146
1147;; ANSWER SECTION:
1148nobare.com. 55 IN A 80.82.79.116
1149nobare.com. 3449 IN NS pns25.cloudns.net.
1150nobare.com. 3449 IN NS ns23.cloudns.net.
1151nobare.com. 3449 IN NS pns26.cloudns.net.
1152nobare.com. 3449 IN NS pns29.cloudns.net.
1153nobare.com. 3449 IN NS pns24.cloudns.net.
1154nobare.com. 3449 IN NS pns23.cloudns.net.
1155nobare.com. 3449 IN NS ns24.cloudns.net.
1156nobare.com. 3449 IN NS ns21.cloudns.net.
1157nobare.com. 3449 IN NS pns22.cloudns.net.
1158nobare.com. 3449 IN NS pns28.cloudns.net.
1159nobare.com. 3449 IN NS pns30.cloudns.net.
1160nobare.com. 3449 IN NS ns22.cloudns.net.
1161nobare.com. 3449 IN NS pns27.cloudns.net.
1162nobare.com. 3449 IN NS pns21.cloudns.net.
1163
1164PORT STATE SERVICE VERSION
116521/tcp open ftp vsftpd 3.0.2
116622/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
1167| ssh-hostkey:
1168| 1024 ab:16:56:89:21:7e:75:1c:77:f3:a2:7e:c2:f1:4c:09 (DSA)
1169| 2048 22:f8:e3:f6:1a:1c:6a:99:09:6b:1e:7c:fd:30:e3:95 (RSA)
1170|_ 256 a8:03:f4:96:36:d1:39:de:2e:4f:56:e9:0f:f3:63:56 (ECDSA)
117125/tcp filtered smtp
117226/tcp filtered rsftp
117353/tcp open domain
1174| dns-nsid:
1175|_ bind.version: 9.8.4-rpz2+rl005.12-P1
117680/tcp open http nginx
1177|_http-server-header: nginx
1178|_http-title: sexy teens, virgin mania, younger babes
1179111/tcp open rpcbind 2-4 (RPC #100000)
1180119/tcp filtered nntp
1181135/tcp filtered msrpc
1182139/tcp filtered netbios-ssn
1183445/tcp filtered microsoft-ds
1184465/tcp filtered smtps
1185587/tcp filtered submission
1186646/tcp filtered ldp
11871026/tcp filtered LSA-or-nterm
11881027/tcp filtered IIS
11892049/tcp filtered nfs
11902717/tcp filtered pn-requester
11913986/tcp filtered mapper-ws_ethd
11924899/tcp filtered radmin
11935060/tcp filtered sip
11945357/tcp filtered wsdapi
11955432/tcp filtered postgresql
11967070/tcp filtered realserver
11978009/tcp filtered ajp13
11988081/tcp filtered blackice-icecap
11999999/tcp filtered abyss
120049153/tcp filtered unknown
1201Aggressive OS guesses: Linux 2.6.39 (94%), Linux 3.2 - 3.8 (93%), Linux 3.8 (92%), WatchGuard Fireware 11.8 (92%), Linux 3.1 - 3.2 (92%), Linux 3.5 (91%), Linux 2.6.32 - 2.6.39 (91%), Linux 2.6.32 - 3.0 (90%), Linux 2.6.32 (89%), Linux 2.6.32 or 3.10 (89%)
1202No exact OS matches for host (test conditions non-ideal).
1203Network Distance: 10 hops
1204Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
1205
1206TRACEROUTE (using port 3389/tcp)
1207HOP RTT ADDRESS
12081 304.05 ms 10.13.0.1
12092 304.07 ms 37.187.24.252
12103 304.07 ms 178.33.103.229
12114 304.08 ms 10.95.33.8
12125 304.08 ms 213.186.32.213
12136 ...
12147 312.10 ms 176.10.83.128
12158 312.09 ms 176.10.83.5
12169 ...
121710 304.13 ms 80.82.79.116
1218
1219OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1220Nmap done: 1 IP address (1 host up) scanned in 67.48 seconds
1221
1222###########################################################################################
1223
1224amap -i temp.txt
1225amap v5.4 (www.thc.org/thc-amap) started at 2017-09-09 23:41:43 - APPLICATION MAPPING mode
1226
1227Protocol on 80.82.79.116:21/tcp matches ftp
1228Protocol on 80.82.79.116:22/tcp matches ssh
1229Protocol on 80.82.79.116:22/tcp matches ssh-openssh
1230Protocol on 80.82.79.116:80/tcp matches http
1231Protocol on 80.82.79.116:111/tcp matches rpc
1232Protocol on 80.82.79.116:53/tcp matches dns
1233Protocol on 80.82.79.116:111/tcp matches rpc-rpcbind-v4
1234
1235Unidentified ports: none.
1236
1237amap v5.4 finished at 2017-09-09 23:41:56
1238
1239###########################################################################################
1240
1241inetnum: 80.82.79.0 - 80.82.79.255
1242netname: SC-QUASI80
1243descr: QUASI
1244country: SC
1245org: ORG-QNL3-RIPE
1246admin-c: QNL1-RIPE
1247tech-c: QNL1-RIPE
1248status: ASSIGNED PA
1249mnt-by: QUASINETWORKS-MNT
1250mnt-lower: QUASINETWORKS-MNT
1251mnt-routes: QUASINETWORKS-MNT
1252created: 2010-08-25T21:29:49Z
1253last-modified: 2016-01-23T23:04:27Z
1254source: RIPE
1255
1256organisation: ORG-QNL3-RIPE
1257org-name: Quasi Networks LTD.
1258org-type: OTHER
1259address: Suite 1, Second Floor
1260address: Sound & Vision House, Francis Rachel Street
1261address: Victoria, Mahe, SEYCHELLES
1262remarks: *****************************************************************************
1263remarks: IMPORTANT INFORMATION
1264remarks: *****************************************************************************
1265remarks: We are a high bandwidth network provider offering bandwidth solutions.
1266remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
1267remarks: Please only use abuse@quasinetworks.com for abuse reports.
1268remarks: For all other requests, please see the details on our website.
1269remarks: *****************************************************************************
1270abuse-mailbox: abuse@quasinetworks.com
1271abuse-c: AR34302-RIPE
1272mnt-ref: QUASINETWORKS-MNT
1273mnt-by: QUASINETWORKS-MNT
1274created: 2015-11-08T22:25:26Z
1275last-modified: 2015-11-27T09:37:50Z
1276source: RIPE # Filtered
1277
1278role: Quasi Networks LTD
1279address: Suite 1, Second Floor
1280address: Sound & Vision House, Francis Rachel Street
1281address: Victoria, Mahe, SEYCHELLES
1282remarks: *****************************************************************************
1283remarks: IMPORTANT INFORMATION
1284remarks: *****************************************************************************
1285remarks: We are a high bandwidth network provider offering bandwidth solutions.
1286remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
1287remarks: Please only use abuse@quasinetworks.com for abuse reports.
1288remarks: For all other requests, please see the details on our website.
1289remarks: *****************************************************************************
1290abuse-mailbox: abuse@quasinetworks.com
1291nic-hdl: QNL1-RIPE
1292mnt-by: QUASINETWORKS-MNT
1293created: 2015-11-07T22:43:04Z
1294last-modified: 2015-11-07T23:04:49Z
1295source: RIPE # Filtered
1296
1297% Information related to '80.82.79.0/24AS29073'
1298
1299route: 80.82.79.0/24
1300descr: Quasi Networks LTD (IBC)
1301origin: AS29073
1302mnt-by: QUASINETWORKS-MNT
1303created: 2010-08-25T21:31:02Z
1304last-modified: 2016-01-23T23:04:45Z
1305source: RIPE
1306
1307% This query was served by the RIPE Database Query Service version 1.89.2 (BLAARKOP)
1308###########################################################################################
1309[i] Scanning Site: http://nobare.com
1310
1311
1312
1313B A S I C I N F O
1314====================
1315
1316
1317[+] Site Title: sexy teens, virgin mania, younger babes
1318[+] IP address: 80.82.79.116
1319[+] Web Server: nginx
1320[+] CMS: Could Not Detect
1321[+] Cloudflare: Not Detected
1322[+] Robots File: Could NOT Find robots.txt!
1323
1324
1325
1326
1327W H O I S L O O K U P
1328========================
1329
1330 Domain Name: NOBARE.COM
1331 Registry Domain ID: 2000363694_DOMAIN_COM-VRSN
1332 Registrar WHOIS Server: whois.bizcn.com
1333 Registrar URL: http://www.bizcn.com
1334 Updated Date: 2017-04-28T08:16:12Z
1335 Creation Date: 2016-02-05T11:43:33Z
1336 Registry Expiry Date: 2018-02-05T11:43:33Z
1337 Registrar: Bizcn.com, Inc.
1338 Registrar IANA ID: 471
1339 Registrar Abuse Contact Email:
1340 Registrar Abuse Contact Phone:
1341 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
1342 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1343 Name Server: NS23.CLOUDNS.NET
1344 Name Server: PNS21.CLOUDNS.NET
1345 Name Server: PNS23.CLOUDNS.NET
1346 Name Server: PNS24.CLOUDNS.NET
1347 Name Server: PNS28.CLOUDNS.NET
1348 Name Server: PNS30.CLOUDNS.NET
1349 DNSSEC: unsigned
1350
1351
1352
1353
1354G E O I P L O O K U P
1355=========================
1356
1357[i] IP Address: 80.82.79.116
1358[i] Country: SC
1359[i] State: N/A
1360[i] City: N/A
1361[i] Latitude: -4.583300
1362[i] Longitude: 55.666698
1363
1364
1365
1366
1367H T T P H E A D E R S
1368=======================
1369
1370
1371[i] HTTP/1.1 200 OK
1372[i] Server: nginx
1373[i] Date: Sun, 10 Sep 2017 03:43:24 GMT
1374[i] Content-Type: text/html
1375[i] Connection: close
1376[i] Vary: Accept-Encoding
1377[i] X-Powered-By: PHP/5.4.45-0+deb7u8
1378[i] Set-Cookie: teenporn=1; expires=Sun, 10-Sep-2017 15:43:24 GMT
1379[i] Vary: Accept-Encoding
1380
1381
1382
1383
1384D N S L O O K U P
1385===================
1386
1387nobare.com. 56 IN A 80.82.79.116
1388nobare.com. 3600 IN NS ns24.cloudns.net.
1389nobare.com. 3600 IN NS pns30.cloudns.net.
1390nobare.com. 3600 IN NS pns29.cloudns.net.
1391nobare.com. 3600 IN NS ns23.cloudns.net.
1392nobare.com. 3600 IN NS ns22.cloudns.net.
1393nobare.com. 3600 IN NS pns28.cloudns.net.
1394nobare.com. 3600 IN NS pns25.cloudns.net.
1395nobare.com. 3600 IN NS pns24.cloudns.net.
1396nobare.com. 3600 IN NS pns26.cloudns.net.
1397nobare.com. 3600 IN NS pns27.cloudns.net.
1398nobare.com. 3600 IN NS ns21.cloudns.net.
1399nobare.com. 3600 IN NS pns23.cloudns.net.
1400nobare.com. 3600 IN NS pns21.cloudns.net.
1401nobare.com. 3600 IN NS pns22.cloudns.net.
1402nobare.com. 3600 IN SOA ns21.cloudns.net. support.cloudns.net. 2017091012 7200 1800 1209600 3600
1403
1404
1405
1406
1407S U B N E T C A L C U L A T I O N
1408====================================
1409
1410Address = 80.82.79.116
1411Network = 80.82.79.116 / 32
1412Netmask = 255.255.255.255
1413Broadcast = not needed on Point-to-Point links
1414Wildcard Mask = 0.0.0.0
1415Hosts Bits = 0
1416Max. Hosts = 1 (2^0 - 0)
1417Host Range = { 80.82.79.116 - 80.82.79.116 }
1418
1419
1420
1421N M A P P O R T S C A N
1422============================
1423
1424
1425Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 03:39 UTC
1426Nmap scan report for nobare.com (80.82.79.116)
1427Host is up (0.083s latency).
1428rDNS record for 80.82.79.116: no-reverse-dns-configured.com
1429PORT STATE SERVICE VERSION
143021/tcp open ftp vsftpd 3.0.2
143122/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
143223/tcp closed telnet
143325/tcp closed smtp
143480/tcp open http nginx
1435110/tcp closed pop3
1436143/tcp closed imap
1437443/tcp closed https
1438445/tcp closed microsoft-ds
14393389/tcp closed ms-wbt-server
1440
1441S U B - D O M A I N F I N D E R
1442==================================
1443
1444
1445[i] Total Subdomains Found : 1
1446
1447[+] Subdomain: nobare.com
1448[-] IP: 89.248.166.21
1449*] Performing TLD Brute force Enumeration against nobare.com
1450[*] The operation could take up to: 00:01:07
1451[*] A nobare.biz.af 5.45.75.45
1452[*] CNAME nobare.biz.at free.biz.at
1453[*] A free.biz.at 216.92.134.29
1454[*] A nobare.co.asia 91.195.240.135
1455[*] A nobare.org.aw 142.4.20.12
1456[*] A nobare.co.ba 176.9.45.78
1457[*] A nobare.com.ba 195.222.33.180
1458[*] A nobare.com.be 95.173.170.166
1459[*] A nobare.biz.by 71.18.52.2
1460[*] A nobare.biz.bz 199.59.242.150
1461[*] A nobare.net.cc 54.252.89.206
1462[*] A nobare.com.cc 54.252.107.64
1463[*] A nobare.co.cc 175.126.123.219
1464[*] A nobare.org.ch 72.52.4.122
1465[*] A nobare.co.cm 85.25.140.105
1466[*] A nobare.net.cm 85.25.140.105
1467[*] A nobare.biz.cl 185.53.178.8
1468[*] A nobare.com.com 52.33.196.199
1469[*] A nobare.net.com 199.59.242.150
1470[*] A nobare.org.com 23.23.86.44
1471[*] A nobare.co.com 173.192.115.17
1472[*] A nobare.com 89.248.166.21
1473[*] A nobare.biz.cr 72.52.4.122
1474[*] CNAME nobare.biz.cm i.cns.cm
1475[*] A i.cns.cm 118.184.56.30
1476[*] A nobare.biz.cx 72.52.4.122
1477[*] A nobare.biz.cz 185.53.179.7
1478[*] A nobare.com.cz 62.109.128.30
1479[*] A nobare.net.cz 80.250.24.177
1480[*] A nobare.com.de 50.56.68.37
1481[*] CNAME nobare.co.de co.de
1482[*] A co.de 144.76.162.245
1483[*] CNAME nobare.org.de www.org.de
1484[*] A www.org.de 78.47.128.8
1485[*] A nobare.net.eu 78.46.90.98
1486[*] A nobare.org.eu 78.46.90.98
1487[*] A nobare.biz.fi 185.55.85.123
1488[*] A nobare.fm 173.230.131.38
1489[*] A nobare.biz.fm 173.230.131.38
1490[*] A nobare.org.fr 149.202.133.35
1491[*] A nobare.biz.gl 72.52.4.122
1492[*] CNAME nobare.co.gp co.gp
1493[*] A co.gp 144.76.162.245
1494[*] A nobare.co.hn 208.100.40.203
1495[*] CNAME nobare.net.hr net.hr
1496[*] A net.hr 192.0.78.25
1497[*] A net.hr 192.0.78.24
1498[*] CNAME nobare.biz.hn parkmydomain.vhostgo.com
1499[*] A parkmydomain.vhostgo.com 107.186.245.118
1500[*] A nobare.co.ht 72.52.4.122
1501[*] A nobare.co.jobs 50.17.193.222
1502[*] A nobare.net.jobs 50.19.241.165
1503[*] A nobare.com.jobs 50.19.241.165
1504[*] A nobare.biz.jobs 50.19.241.165
1505[*] A nobare.org.jobs 50.19.241.165
1506[*] A nobare.biz.ky 199.184.144.27
1507[*] CNAME nobare.biz.li 712936.parkingcrew.net
1508[*] A 712936.parkingcrew.net 185.53.179.29
1509[*] A nobare.biz.lu 195.26.5.2
1510[*] A nobare.biz.ly 64.136.20.39
1511[*] A nobare.biz.md 72.52.4.122
1512[*] A nobare.co.mk 87.76.31.211
1513[*] A nobare.co.mobi 54.225.105.179
1514[*] A nobare.biz.my 202.190.174.44
1515[*] A nobare.co.net 188.166.216.219
1516[*] A nobare.net.net 52.50.81.210
1517[*] A nobare.org.net 23.23.86.44
1518[*] A nobare.co.nl 37.97.184.204
1519[*] A nobare.com.nl 83.98.157.102
1520[*] A nobare.net.nl 83.98.157.102
1521[*] A nobare.co.nr 208.100.40.202
1522[*] CNAME nobare.co.nu co.nu
1523[*] A co.nu 144.76.162.245
1524[*] CNAME nobare.com.nu com.nu
1525[*] A com.nu 144.76.162.245
1526[*] A nobare.org.nu 80.92.84.139
1527[*] A nobare.net.nu 199.102.76.78
1528[*] A nobare.org 50.63.202.5
1529[*] CNAME nobare.net.org pewtrusts.org
1530[*] A pewtrusts.org 204.74.99.100
1531[*] A nobare.com.org 23.23.86.44
1532[*] A nobare.ph 45.79.222.138
1533[*] A nobare.co.ph 45.79.222.138
1534[*] A nobare.com.ph 45.79.222.138
1535[*] A nobare.net.ph 45.79.222.138
1536[*] A nobare.org.ph 45.79.222.138
1537[*] A nobare.co.pl 212.91.6.55
1538[*] A nobare.org.pm 208.73.210.202
1539[*] A nobare.org.pm 208.73.211.177
1540[*] A nobare.org.pm 208.73.210.217
1541[*] A nobare.org.pm 208.73.211.165
1542[*] A nobare.co.ps 66.96.132.56
1543[*] CNAME nobare.biz.ps biz.ps
1544[*] A biz.ps 144.76.162.245
1545[*] A nobare.co.pt 194.107.127.52
1546[*] A nobare.co.pw 141.8.226.59
1547[*] A nobare.net.pw 141.8.226.59
1548[*] A nobare.pw 141.8.226.58
1549[*] A nobare.biz.pw 141.8.226.59
1550[*] A nobare.org.pw 141.8.226.59
1551[*] A nobare.org.re 217.70.184.38
1552[*] A nobare.net.ro 69.64.52.127
1553[*] CNAME nobare.co.ro now.co.ro
1554[*] A now.co.ro 185.27.255.9
1555[*] A nobare.com.ru 178.210.89.119
1556[*] A nobare.biz.se 185.53.179.6
1557[*] CNAME nobare.net.se 773147.parkingcrew.net
1558[*] A 773147.parkingcrew.net 185.53.179.29
1559[*] A nobare.co.sl 91.195.240.135
1560[*] A nobare.com.sr 143.95.106.249
1561[*] A nobare.biz.st 91.121.28.115
1562[*] A nobare.co.su 72.52.4.122
1563[*] A nobare.biz.tc 64.136.20.39
1564[*] A nobare.biz.tf 85.236.153.18
1565[*] A nobare.net.tf 188.40.70.27
1566[*] A nobare.net.tf 188.40.117.12
1567[*] A nobare.net.tf 188.40.70.29
1568[*] A nobare.co.tl 208.100.40.202
1569[*] A nobare.co.to 175.118.124.44
1570[*] A nobare.co.tv 31.186.25.163
1571[*] A nobare.biz.tv 72.52.4.122
1572[*] A nobare.org.tv 72.52.4.122
1573[*] CNAME nobare.biz.uz biz.uz
1574[*] A biz.uz 144.76.162.245
1575[*] A nobare.vg 88.198.29.97
1576[*] A nobare.co.vg 88.198.29.97
1577[*] A nobare.com.vg 88.198.29.97
1578[*] A nobare.net.vg 68.178.254.180
1579[*] A nobare.biz.vg 89.31.143.20
1580[*] A nobare.ws 64.70.19.203
1581[*] A nobare.com.ws 202.4.48.211
1582[*] A nobare.net.ws 202.4.48.211
1583[*] A nobare.biz.ws 184.168.221.104
1584[*] A nobare.org.ws 202.4.48.211
1585
1586R E V E R S E I P L O O K U P
1587==================================
1588
1589
1590[i] Total Sites Found On This Server : 3
1591
1592
1593[#] nobare.com
1594[-] CMS: Could Not Detect
1595
1596[#] preteen-art.info
1597[-] CMS: Could Not Detect
1598
1599[#] teendolls.online,
1600[-] CMS: Could Not Detect
1601nobare.com
1602
1603
1604 Domain Name: NOBARE.COM
1605 Registry Domain ID: 2000363694_DOMAIN_COM-VRSN
1606 Registrar WHOIS Server: whois.bizcn.com
1607 Registrar URL: http://www.bizcn.com
1608 Updated Date: 2017-04-28T08:16:12Z
1609 Creation Date: 2016-02-05T11:43:33Z
1610 Registry Expiry Date: 2018-02-05T11:43:33Z
1611 Registrar: Bizcn.com, Inc.
1612 Registrar IANA ID: 471
1613 Registrar Abuse Contact Email:
1614 Registrar Abuse Contact Phone:
1615 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
1616 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1617 Name Server: NS23.CLOUDNS.NET
1618 Name Server: PNS21.CLOUDNS.NET
1619 Name Server: PNS23.CLOUDNS.NET
1620 Name Server: PNS24.CLOUDNS.NET
1621 Name Server: PNS28.CLOUDNS.NET
1622 Name Server: PNS30.CLOUDNS.NET
1623
1624Domain name: nobare.com
1625Registry Domain ID: 2000363694_DOMAIN_COM-VRSN
1626Registrar WHOIS Server: whois.bizcn.com
1627Registrar URL: http://www.bizcn.com
1628Updated Date: 2017-02-02T23:00:03Z
1629Creation Date: 2016-02-05T11:43:33Z
1630Registrar Registration Expiration Date: 2018-02-05T11:43:33Z
1631Registrar: Bizcn.com,Inc.
1632Registrar IANA ID: 471
1633Registrar Abuse Contact Email: abuse@bizcn.com
1634Registrar Abuse Contact Phone: +86.5922577888
1635Reseller: Cnobin Technology HK Limited
1636Domain Status: clientDeleteProhibited (http://www.icann.org/epp#clientDeleteProhibited)
1637Domain Status: clientTransferProhibited (http://www.icann.org/epp#clientTransferProhibited)
1638Registry Registrant ID: Not Available From Registry
1639Registrant Name: Wuxi Yilian LLC
1640Registrant Organization: Wuxi Yilian LLC
1641Registrant Street: No.1001 Anling Road
1642Registrant City: Xiamen
1643Registrant State/Province: Fujian
1644Registrant Postal Code: 361008
1645Registrant Country: cn
1646Registrant Phone: +86.5922577888
1647Registrant Phone Ext:
1648Registrant Fax: +86.5922179606
1649Registrant Fax Ext:
1650Registrant Email: whoisprivacyprotect@whoisservices.cn
1651Registry Admin ID: Not Available From Registry
1652Admin Name: Wuxi Yilian LLC
1653Admin Organization: Wuxi Yilian LLC
1654Admin Street: No.1001 Anling Road
1655Admin City: Xiamen
1656Admin State/Province: Fujian
1657Admin Postal Code: 361008
1658Admin Country: cn
1659Admin Phone: +86.5922577888
1660Admin Phone Ext:
1661Admin Fax: +86.5922179606
1662Admin Fax Ext:
1663Admin Email: whoisprivacyprotect@whoisservices.cn
1664Registry Tech ID: Not Available From Registry
1665Tech Name: Wuxi Yilian LLC
1666Tech Organization: Wuxi Yilian LLC
1667Tech Street: No.1001 Anling Road
1668Tech City: Xiamen
1669Tech State/Province: Fujian
1670Tech Postal Code: 361008
1671Tech Country: cn
1672Tech Phone: +86.5922577888
1673Tech Phone Ext:
1674Tech Fax: +86.5922179606
1675Tech Fax Ext:
1676Tech Email: whoisprivacyprotect@whoisservices.cn
1677Name Server: pns23.cloudns.net
1678Name Server: pns24.cloudns.net
1679Name Server: pns21.cloudns.net
1680Name Server: pns28.cloudns.net
1681Name Server: pns30.cloudns.net
1682Name Server: ns23.cloudns.net
1683
1684;nobare.com. IN ANY
1685
1686;; ANSWER SECTION:
1687nobare.com. 47 IN A 80.82.79.116
1688nobare.com. 3441 IN NS pns26.cloudns.net.
1689nobare.com. 3441 IN NS ns23.cloudns.net.
1690nobare.com. 3441 IN NS pns24.cloudns.net.
1691nobare.com. 3441 IN NS ns21.cloudns.net.
1692nobare.com. 3441 IN NS pns27.cloudns.net.
1693nobare.com. 3441 IN NS pns28.cloudns.net.
1694nobare.com. 3441 IN NS pns29.cloudns.net.
1695nobare.com. 3441 IN NS pns23.cloudns.net.
1696nobare.com. 3441 IN NS pns25.cloudns.net.
1697nobare.com. 3441 IN NS pns30.cloudns.net.
1698nobare.com. 3441 IN NS pns22.cloudns.net.
1699nobare.com. 3441 IN NS ns24.cloudns.net.
1700nobare.com. 3441 IN NS ns22.cloudns.net.
1701nobare.com. 3441 IN NS pns21.cloudns.net.
1702
1703Host's addresses:
1704__________________
1705
1706nobare.com. 38 IN A 80.82.79.116
1707
1708
1709Wildcard detection using: kwvdrbpdyhgy
1710_______________________________________
1711
1712kwvdrbpdyhgy.nobare.com. 60 IN A 80.82.79.116
1713
1714
1715!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1716
1717 Wildcards detected, all subdomains will point to the same IP address
1718 Omitting results containing 80.82.79.116.
1719 Maybe you are using OpenDNS servers.
1720
1721!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1722
1723
1724Name Servers:
1725______________
1726
1727pns25.cloudns.net. 29821 IN A 185.136.96.96
1728ns23.cloudns.net. 163978 IN A 79.137.84.65
1729pns29.cloudns.net. 29821 IN A 185.136.96.96
1730pns21.cloudns.net. 114221 IN A 185.136.96.96
1731pns26.cloudns.net. 29821 IN A 185.136.97.96
1732ns22.cloudns.net. 131910 IN A 108.59.2.202
1733ns24.cloudns.net. 147651 IN A 46.165.221.164
1734pns24.cloudns.net. 114221 IN A 185.136.99.96
1735pns27.cloudns.net. 29821 IN A 185.136.98.96
1736pns22.cloudns.net. 114221 IN A 185.136.97.96
1737pns28.cloudns.net. 163978 IN A 185.136.99.96
1738pns30.cloudns.net. 121558 IN A 185.136.96.96
1739ns21.cloudns.net. 53592 IN A 109.201.133.61
1740pns23.cloudns.net. 152547 IN A 185.136.98.96
1741
1742
1743nobare.com class C netranges:
1744______________________________
1745
1746 80.82.79.0/24
1747
1748
1749Performing reverse lookup on 256 ip addresses:
1750_______________________________________________
1751
1752
17530 results out of 256 IP addresses.
1754
1755
1756nobare.com ip blocks:
1757______________________
1758
1759
1760done.
1761
1762
1763dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
1764
1765[+] warning: domain might use wildcards. 80.82.79.116 will be ignored from results
1766[+] searching (sub)domains for nobare.com using built-in wordlist
1767[+] using maximum random delay of 10 millisecond(s) between requests
1768
1769[+] 0 (sub)domains and 0 IP address(es) found
1770[+] completion time: 244 second(s)
1771
1772
1773Tracing to nobare.com[a] via 192.168.1.254, maximum of 3 retries
1774192.168.1.254 (192.168.1.254)
1775 |\___ ns21.cloudns.net [nobare.com] (2a00:1768:1001:0009:0000:0000:0000:0021) Got authoritative answer
1776 |\___ ns21.cloudns.net [nobare.com] (109.201.133.61) Got authoritative answer
1777 |\___ ns22.cloudns.net [nobare.com] (108.59.2.202) Got authoritative answer
1778 |\___ ns22.cloudns.net [nobare.com] (2604:9a00:2100:a006:0004:0000:0000:0001) Got authoritative answer
1779 |\___ pns23.cloudns.net [nobare.com] (185.136.98.96) Got authoritative answer
1780 |\___ pns23.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0003:0096) Got authoritative answer
1781 |\___ pns26.cloudns.net [nobare.com] (185.136.97.96) Got authoritative answer
1782 |\___ pns26.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0002:0096) Got authoritative answer
1783 |\___ ns23.cloudns.net [nobare.com] (79.137.84.65) Got authoritative answer
1784 |\___ ns23.cloudns.net [nobare.com] (2001:41d0:0401:3100:0000:0000:0000:5784) * * *
1785 |\___ pns22.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0002:0096) (cached)
1786 |\___ pns22.cloudns.net [nobare.com] (185.136.97.96) (cached)
1787 |\___ pns28.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0004:0096) Got authoritative answer
1788 |\___ pns28.cloudns.net [nobare.com] (185.136.99.96) Got authoritative answer
1789 |\___ pns25.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0001:0096) Got authoritative answer
1790 |\___ pns25.cloudns.net [nobare.com] (185.136.96.96) Got authoritative answer
1791 |\___ ns24.cloudns.net [nobare.com] (46.165.221.164) Got authoritative answer
1792 |\___ ns24.cloudns.net [nobare.com] (2a00:0c98:2030:a006:0002:0000:0000:0001) Got authoritative answer
1793 |\___ pns29.cloudns.net [nobare.com] (185.136.96.96) (cached)
1794 |\___ pns29.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0001:0096) (cached)
1795 |\___ pns30.cloudns.net [nobare.com] (185.136.96.96) (cached)
1796 |\___ pns30.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0001:0096) (cached)
1797 |\___ pns21.cloudns.net [nobare.com] (185.136.96.96) (cached)
1798 |\___ pns21.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0001:0096) (cached)
1799 |\___ pns27.cloudns.net [nobare.com] (185.136.98.96) (cached)
1800 \___ pns24.cloudns.net [nobare.com] (185.136.99.96) (cached)
1801 \___ pns24.cloudns.net [nobare.com] (2a06:fb00:0001:0000:0000:0000:0004:0096) (cached)
1802
1803
1804WhatWeb report for http://nobare.com
1805Status : 200 OK
1806Title : sexy teens, virgin mania, younger babes
1807IP : 80.82.79.116
1808Country : NETHERLANDS, NL
1809
1810Summary : X-Powered-By[PHP/5.4.45-0+deb7u8], HTTPServer[nginx], Cookies[teenporn], PHP[5.4.45-0+deb7u8], nginx, Script[text/javascript]
1811
1812Detected Plugins:
1813[ Cookies ]
1814 Display the names of cookies in the HTTP headers. The
1815 values are not returned to save on space.
1816
1817 String : teenporn
1818
1819[ HTTPServer ]
1820 HTTP server header string. This plugin also attempts to
1821 identify the operating system from the server header.
1822
1823 String : nginx (from server string)
1824
1825[ PHP ]
1826 PHP is a widely-used general-purpose scripting language
1827 that is especially suited for Web development and can be
1828 embedded into HTML. This plugin identifies PHP errors,
1829 modules and versions and extracts the local file path and
1830 username if present.
1831
1832 Version : 5.4.45-0+deb7u8
1833 Google Dorks: (2)
1834 Website : http://www.php.net/
1835
1836[ Script ]
1837 This plugin detects instances of script HTML elements and
1838 returns the script language/type.
1839
1840 String : text/javascript
1841
1842[ X-Powered-By ]
1843 X-Powered-By HTTP header
1844
1845 String : PHP/5.4.45-0+deb7u8 (from x-powered-by string)
1846
1847[ nginx ]
1848 Nginx (Engine-X) is a free, open-source, high-performance
1849 HTTP server and reverse proxy, as well as an IMAP/POP3
1850 proxy server.
1851
1852 Website : http://nginx.net/
1853
1854HTTP Headers:
1855 HTTP/1.1 200 OK
1856 Server: nginx
1857 Date: Sun, 10 Sep 2017 03:50:08 GMT
1858 Content-Type: text/html
1859 Content-Length: 2716
1860 Connection: close
1861 X-Powered-By: PHP/5.4.45-0+deb7u8
1862 Set-Cookie: teenporn=1; expires=Sun, 10-Sep-2017 15:50:08 GMT
1863 Vary: Accept-Encoding
1864 Content-Encoding: gzip
1865
1866
1867[+] Emails found:
1868------------------
1869contact@nobare.com
1870
1871[+] Hosts found in search engines:
1872------------------------------------
1873[-] Resolving hostnames IPs...
187480.82.79.116:www.nobare.com
1875
1876
1877
1878 ^ ^
1879 _ __ _ ____ _ __ _ _ ____
1880 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
1881 | V V // o // _/ | V V // 0 // 0 // _/
1882 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
1883 <
1884 ...'
1885
1886 WAFW00F - Web Application Firewall Detection Tool
1887
1888 By Sandro Gauci && Wendel G. Henrique
1889
1890Checking http://nobare.com
1891Generic Detection results:
1892No WAF detected by the generic detection
1893Number of requests: 13
1894
1895
1896DNS Servers for nobare.com:
1897 ns22.cloudns.net
1898 pns26.cloudns.net
1899 pns30.cloudns.net
1900 pns28.cloudns.net
1901 pns27.cloudns.net
1902 pns25.cloudns.net
1903 pns22.cloudns.net
1904 pns24.cloudns.net
1905 ns23.cloudns.net
1906 pns23.cloudns.net
1907 ns21.cloudns.net
1908 ns24.cloudns.net
1909 pns21.cloudns.net
1910 pns29.cloudns.net
1911
1912Trying zone transfer first...
1913 Testing ns22.cloudns.net
1914 Request timed out or transfer not allowed.
1915 Testing pns26.cloudns.net
1916 Request timed out or transfer not allowed.
1917 Testing pns30.cloudns.net
1918 Request timed out or transfer not allowed.
1919 Testing pns28.cloudns.net
1920 Request timed out or transfer not allowed.
1921 Testing pns27.cloudns.net
1922 Request timed out or transfer not allowed.
1923 Testing pns25.cloudns.net
1924 Request timed out or transfer not allowed.
1925 Testing pns22.cloudns.net
1926 Request timed out or transfer not allowed.
1927 Testing pns24.cloudns.net
1928 Request timed out or transfer not allowed.
1929 Testing ns23.cloudns.net
1930 Request timed out or transfer not allowed.
1931 Testing pns23.cloudns.net
1932 Request timed out or transfer not allowed.
1933 Testing ns21.cloudns.net
1934 Request timed out or transfer not allowed.
1935 Testing ns24.cloudns.net
1936 Request timed out or transfer not allowed.
1937 Testing pns21.cloudns.net
1938 Request timed out or transfer not allowed.
1939 Testing pns29.cloudns.net
1940 Request timed out or transfer not allowed.
1941
1942Unsuccessful in zone transfer (it was worth a shot)
1943Okay, trying the good old fashioned way... brute force
1944
1945Checking for wildcard DNS...
1946 ** Found 93089228133.nobare.com at 80.82.79.116.
1947 ** High probability of wildcard DNS.
1948Now performing 2280 test(s)...
194993.174.91.159 voyager.nobare.com
195093.174.91.159 vpn.nobare.com
195193.174.91.159 vpn0.nobare.com
195293.174.91.159 vpn01.nobare.com
195393.174.91.159 vpn02.nobare.com
195493.174.91.159 vpn1.nobare.com
195593.174.91.159 vpn2.nobare.com
195693.174.91.159 vsnl.nobare.com
195793.174.91.159 vt.nobare.com
195893.174.91.159 vu.nobare.com
195993.174.91.159 w.nobare.com
196093.174.91.159 w1.nobare.com
196193.174.91.159 w2.nobare.com
196293.174.91.159 w3.nobare.com
196393.174.91.159 wa.nobare.com
196493.174.91.159 wais.nobare.com
196593.174.91.159 wakwak.nobare.com
196693.174.91.159 wallet.nobare.com
196793.174.91.159 wam.nobare.com
196893.174.91.159 wan.nobare.com
196993.174.91.159 wap.nobare.com
197093.174.91.159 war.nobare.com
197193.174.91.159 warehouse.nobare.com
197293.174.91.159 washington.nobare.com
197393.174.91.159 water.nobare.com
197493.174.91.159 wc3.nobare.com
197593.174.91.159 web.nobare.com
197693.174.91.159 webaccess.nobare.com
197793.174.91.159 webadmin.nobare.com
197893.174.91.159 webalizer.nobare.com
197993.174.91.159 webboard.nobare.com
198093.174.91.159 webcache.nobare.com
198193.174.91.159 webcam.nobare.com
198293.174.91.159 webcast.nobare.com
198393.174.91.159 webdev.nobare.com
198493.174.91.159 webdocs.nobare.com
198593.174.91.159 webfarm.nobare.com
198693.174.91.159 webhelp.nobare.com
198793.174.91.159 weblib.nobare.com
198893.174.91.159 weblogic.nobare.com
198993.174.91.159 webmail.nobare.com
199093.174.91.159 webmaster.nobare.com
199193.174.91.159 webproxy.nobare.com
199293.174.91.159 webring.nobare.com
199393.174.91.159 webs.nobare.com
199493.174.91.159 webserv.nobare.com
199593.174.91.159 webserver.nobare.com
199693.174.91.159 webservices.nobare.com
199793.174.91.159 website.nobare.com
199893.174.91.159 websites.nobare.com
199993.174.91.159 websphere.nobare.com
200093.174.91.159 websrv.nobare.com
200193.174.91.159 websrvr.nobare.com
200293.174.91.159 webstats.nobare.com
200393.174.91.159 webstore.nobare.com
200493.174.91.159 websvr.nobare.com
200593.174.91.159 webtrends.nobare.com
200693.174.91.159 welcome.nobare.com
200793.174.91.159 west.nobare.com
200893.174.91.159 westnet.nobare.com
200993.174.91.159 westvirginia.nobare.com
201093.174.91.159 wf.nobare.com
201193.174.91.159 whiskey.nobare.com
201293.174.91.159 white.nobare.com
201393.174.91.159 whois.nobare.com
201493.174.91.159 wi.nobare.com
201593.174.91.159 wichita.nobare.com
201693.174.91.159 wiki.nobare.com
201793.174.91.159 wililiam.nobare.com
201893.174.91.159 wimax-client.nobare.com
201993.174.91.159 win.nobare.com
202093.174.91.159 win01.nobare.com
202193.174.91.159 win02.nobare.com
202293.174.91.159 win1.nobare.com
202393.174.91.159 win2.nobare.com
202493.174.91.159 win2000.nobare.com
202593.174.91.159 win2003.nobare.com
202693.174.91.159 win2k.nobare.com
202793.174.91.159 win2k3.nobare.com
202893.174.91.159 windows.nobare.com
202993.174.91.159 windows01.nobare.com
203093.174.91.159 windows02.nobare.com
203193.174.91.159 windows1.nobare.com
203293.174.91.159 windows2.nobare.com
203393.174.91.159 windows2000.nobare.com
203493.174.91.159 windows2003.nobare.com
203593.174.91.159 windowsxp.nobare.com
203693.174.91.159 wingate.nobare.com
203793.174.91.159 winnt.nobare.com
203893.174.91.159 winproxy.nobare.com
203993.174.91.159 wins.nobare.com
204093.174.91.159 winserve.nobare.com
204193.174.91.159 winxp.nobare.com
204293.174.91.159 wire.nobare.com
204393.174.91.159 wireless.nobare.com
204493.174.91.159 wisconsin.nobare.com
204593.174.91.159 wlan.nobare.com
204693.174.91.159 wlfrct.nobare.com
204793.174.91.159 woh.nobare.com
204893.174.91.159 wood.nobare.com
204993.174.91.159 wordpress.nobare.com
205093.174.91.159 work.nobare.com
205193.174.91.159 world.nobare.com
205293.174.91.159 wotnoh.nobare.com
205393.174.91.159 write.nobare.com
205493.174.91.159 ws.nobare.com
205593.174.91.159 ws1.nobare.com
205693.174.91.159 ws10.nobare.com
205793.174.91.159 ws11.nobare.com
205893.174.91.159 ws12.nobare.com
205993.174.91.159 ws13.nobare.com
206093.174.91.159 ws2.nobare.com
206193.174.91.159 ws3.nobare.com
206293.174.91.159 ws4.nobare.com
206393.174.91.159 ws5.nobare.com
206493.174.91.159 ws6.nobare.com
206593.174.91.159 ws7.nobare.com
206693.174.91.159 ws8.nobare.com
206793.174.91.159 ws9.nobare.com
206893.174.91.159 wusage.nobare.com
206993.174.91.159 wv.nobare.com
207093.174.91.159 ww.nobare.com
207193.174.91.159 www.nobare.com
207293.174.91.159 www-.nobare.com
207393.174.91.159 www-01.nobare.com
207493.174.91.159 www-02.nobare.com
207593.174.91.159 www-1.nobare.com
207693.174.91.159 www-2.nobare.com
207793.174.91.159 www-int.nobare.com
207893.174.91.159 www0.nobare.com
207993.174.91.159 www01.nobare.com
208093.174.91.159 www02.nobare.com
208193.174.91.159 www1.nobare.com
208293.174.91.159 www2.nobare.com
208393.174.91.159 www3.nobare.com
208493.174.91.159 www_.nobare.com
208593.174.91.159 wwwchat.nobare.com
208693.174.91.159 wwwdev.nobare.com
208793.174.91.159 wwwmail.nobare.com
208893.174.91.159 wy.nobare.com
208993.174.91.159 wyoming.nobare.com
209093.174.91.159 x.nobare.com
209193.174.91.159 x-ray.nobare.com
209293.174.91.159 xdsl.nobare.com
209393.174.91.159 xi.nobare.com
209493.174.91.159 xlogan.nobare.com
209593.174.91.159 xmail.nobare.com
209693.174.91.159 xml.nobare.com
209793.174.91.159 xp.nobare.com
209893.174.91.159 xr.nobare.com
209993.174.91.159 y.nobare.com
210093.174.91.159 y12.nobare.com
210193.174.91.159 yankee.nobare.com
210293.174.91.159 ye.nobare.com
210393.174.91.159 yellow.nobare.com
210493.174.91.159 yokohama.nobare.com
210593.174.91.159 young.nobare.com
210693.174.91.159 yournet.nobare.com
210793.174.91.159 yt.nobare.com
210893.174.91.159 yu.nobare.com
210993.174.91.159 z.nobare.com
211093.174.91.159 z-log.nobare.com
211193.174.91.159 za.nobare.com
211293.174.91.159 zaq.nobare.com
211393.174.91.159 zebra.nobare.com
211493.174.91.159 zera.nobare.com
211593.174.91.159 zeus.nobare.com
211693.174.91.159 zlog.nobare.com
211793.174.91.159 zm.nobare.com
211893.174.91.159 zulu.nobare.com
211993.174.91.159 zw.nobare.com
212093.174.91.159 zz.nobare.com
2121
2122
2123
2124Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2125
2126 ----------------------------------------------------------
2127| Scan Information |
2128 ----------------------------------------------------------
2129
2130Mode ..................... VRFY
2131Worker Processes ......... 5
2132Usernames file ........... users.txt
2133Target count ............. 1
2134Username count ........... 494
2135Target TCP port .......... 25
2136Query timeout ............ 5 secs
2137Target domain ............
2138
2139######## Scan started at Sat Sep 9 23:58:42 2017 #########
2140######## Scan completed at Sun Sep 10 00:06:57 2017 #########
21410 results.
2142
2143494 queries in 495 seconds (1.0 queries / sec)
2144
2145
2146
2147Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:06 EDT
2148NSE: Loaded 146 scripts for scanning.
2149NSE: Script Pre-scanning.
2150Initiating NSE at 00:06
2151Completed NSE at 00:06, 0.00s elapsed
2152Initiating NSE at 00:06
2153Completed NSE at 00:06, 0.00s elapsed
2154Failed to resolve "nobare.com.txt".
2155Initiating Parallel DNS resolution of 1 host. at 00:06
2156Completed Parallel DNS resolution of 1 host. at 00:06, 0.53s elapsed
2157Initiating SYN Stealth Scan at 00:06
2158Scanning nobare.com (93.174.91.159) [100 ports]
2159Discovered open port 80/tcp on 93.174.91.159
2160Discovered open port 22/tcp on 93.174.91.159
2161Discovered open port 111/tcp on 93.174.91.159
2162Discovered open port 21/tcp on 93.174.91.159
2163Increasing send delay for 93.174.91.159 from 0 to 5 due to 11 out of 27 dropped probes since last increase.
2164Discovered open port 53/tcp on 93.174.91.159
2165Completed SYN Stealth Scan at 00:07, 5.91s elapsed (100 total ports)
2166Initiating Service scan at 00:07
2167Scanning 5 services on nobare.com (93.174.91.159)
2168Completed Service scan at 00:07, 16.24s elapsed (5 services on 1 host)
2169Initiating OS detection (try #1) against nobare.com (93.174.91.159)
2170Retrying OS detection (try #2) against nobare.com (93.174.91.159)
2171Initiating Traceroute at 00:07
2172Completed Traceroute at 00:07, 4.49s elapsed
2173Initiating Parallel DNS resolution of 8 hosts. at 00:07
2174Completed Parallel DNS resolution of 8 hosts. at 00:07, 5.51s elapsed
2175NSE: Script scanning 93.174.91.159.
2176Initiating NSE at 00:07
2177Completed NSE at 00:08, 49.03s elapsed
2178Initiating NSE at 00:08
2179Completed NSE at 00:08, 2.84s elapsed
2180Nmap scan report for nobare.com (93.174.91.159)
2181Host is up (0.27s latency).
2182rDNS record for 93.174.91.159: no-reverse-dns-configured.com
2183Not shown: 89 closed ports
2184PORT STATE SERVICE VERSION
218521/tcp open ftp vsftpd 3.0.2
218622/tcp open ssh OpenSSH 6.0p1 Debian 4+deb7u6 (protocol 2.0)
2187| ssh-hostkey:
2188| 1024 ab:16:56:89:21:7e:75:1c:77:f3:a2:7e:c2:f1:4c:09 (DSA)
2189| 2048 22:f8:e3:f6:1a:1c:6a:99:09:6b:1e:7c:fd:30:e3:95 (RSA)
2190|_ 256 a8:03:f4:96:36:d1:39:de:2e:4f:56:e9:0f:f3:63:56 (ECDSA)
219125/tcp filtered smtp
219253/tcp open domain
2193| dns-nsid:
2194|_ bind.version: 9.8.4-rpz2+rl005.12-P1
219580/tcp open http nginx
2196|_http-favicon: Unknown favicon MD5: 5E0F89CEACB1E8F4725C059E968988B0
2197| http-methods:
2198|_ Supported Methods: HEAD POST OPTIONS
2199111/tcp open rpcbind 2-4 (RPC #100000)
2200135/tcp filtered msrpc
2201139/tcp filtered netbios-ssn
2202445/tcp filtered microsoft-ds
2203465/tcp filtered smtps
2204587/tcp filtered submission
2205Aggressive OS guesses: Linux 2.6.39 (96%), Linux 3.2 - 3.8 (95%), Linux 3.8 (95%), WatchGuard Fireware 11.8 (95%), Linux 3.1 - 3.2 (94%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.5 (92%), Linux 3.0 - 3.2 (92%), Linux 2.6.32 - 3.0 (92%), Linux 2.6.32 (91%)
2206No exact OS matches for host (test conditions non-ideal).
2207Uptime guess: 6.486 days (since Sun Sep 3 12:28:34 2017)
2208Network Distance: 11 hops
2209TCP Sequence Prediction: Difficulty=260 (Good luck!)
2210IP ID Sequence Generation: All zeros
2211Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
2212
2213TRACEROUTE (using port 199/tcp)
2214HOP RTT ADDRESS
22151 444.40 ms 10.13.0.1
22162 1151.13 ms 37.187.24.252
22173 1029.42 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
22184 ...
22195 1121.44 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
22206 1127.44 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
22217 ...
22228 1140.52 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
22239 1136.57 ms 176.10.83.5
222410 ...
222511 1134.06 ms no-reverse-dns-configured.com (93.174.91.159)
2226
2227
2228
2229 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
2230 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2231 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
2232 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2233 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
2234
2235 _/ User-Agent Tester ↵
2236 _/ AKA: Purple Pimp ↵
2237 _/ ChrisJohnRiley ↵
2238 _/ blog.c22.cc ↵
2239
2240 [>] Performing initial request and confirming stability
2241 [>] Using User-Agent string Mozilla/5.0
2242
2243 [ ] URL (ENTERED): http://nobare.com
2244 [ ] Response Code: 200 OK
2245 [ ] Server: nginx
2246 [ ] Date: Sun, 10 Sep 2017 04:12:16 GMT
2247 [ ] Content-Type: text/html
2248 [ ] Transfer-Encoding: chunked
2249 [ ] Connection: close
2250 [ ] Vary: Accept-Encoding
2251 [ ] X-Powered-By: PHP/5.4.45-0+deb7u8
2252 [ ] Set-Cookie: teenporn=1; expires=Sun, 10-Sep-2017 16:12:16 GMT
2253 [ ] Vary: Accept-Encoding
2254 [ ] Data (MD5): db7e76ed01e0a53e6b3f8c21869acd63
2255
2256 [1] Pass
2257 [2] Pass
2258 [3] Pass
2259
2260 [>] URL appears stable. Beginning test
2261
2262 [>] Using DEFAULT User-Agent Strings
2263
2264 [>] Using Crazy User-Agent Strings
2265 [>] Using Bot User-Agent Strings
2266
2267 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
2268
2269
2270 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
2271
2272
2273 [!] Data (MD5): c8a9ce34a8f3efca33c148c4fca54d4b
2274
2275
2276 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
2277
2278
2279 [!] Data (MD5): f46bbb168f3f487911b670a7db31ced8
2280
2281
2282 [>] User-Agent String : TrackBack/1.02
2283
2284
2285 [!] Data (MD5): 2d09febc78aecd391698aa78c5be4d25
2286
2287
2288 [>] User-Agent String : wispr
2289
2290
2291 [!] Data (MD5): 1645f9eecda60e0f67a99a14f3379c70
2292
2293
2294 [>] User-Agent String : EMPTY USER-AGENT STRING!
2295
2296
2297 [!] Data (MD5): dea00ec7d5865f323226e06d187184d5
2298
2299
2300 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
2301
2302
2303 [!] Data (MD5): 198732d017f517405afaf2de5ea84d93
2304
2305
2306 [>] User-Agent String : Googlebot-Image/1.0
2307
2308
2309 [!] Data (MD5): 466fc9cd061938aa7efcd0fb854d6a4f
2310
2311
2312 [>] User-Agent String : Mediapartners-Google
2313
2314
2315 [!] Data (MD5): fbb42438cba29961c91caf27b29b31d3
2316
2317
2318 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
2319
2320
2321 [!] Data (MD5): 4f208acbcb3b44ef2294e5360e4d9893
2322
2323
2324 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
2325
2326
2327 [!] Data (MD5): 948563ad0757150bc9597e67d7dff3e7
2328
2329
2330 [>] User-Agent String : mmcrawler
2331
2332
2333 [!] Data (MD5): bab8041c358c7f9c9c9639ed53b73344
2334
2335
2336 [>] Checks completed... try enabling VERBOSE mode for more detailed output
2337
2338 [>] That's all folks... Fo' Shizzle!
2339
2340########################################################################################
2341Hostname 1000models.net ISP Lucky Net Ltd (AS3254)
2342Continent Europe Flag
2343UA
2344Country Ukraine Country Code UA (UKR)
2345Region Unknown Local time 10 Sep 2017 06:41 EEST
2346City Unknown Latitude 50.45
2347IP Address 91.219.29.120 Longitude 30.523
2348##########################################################################################
23491000models.net
2350
2351###########################################################################################
2352
2353whois 1000models.net
2354 Domain Name: 1000MODELS.NET
2355 Registry Domain ID: 2060561760_DOMAIN_NET-VRSN
2356 Registrar WHOIS Server: whois.joker.com
2357 Registrar URL: http://www.joker.com
2358 Updated Date: 2017-09-02T13:39:27Z
2359 Creation Date: 2016-09-20T06:54:17Z
2360 Registry Expiry Date: 2018-09-20T06:54:17Z
2361 Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
2362 Registrar IANA ID: 113
2363 Registrar Abuse Contact Email: abuse@joker.com
2364 Registrar Abuse Contact Phone: +49.21186767447
2365 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2366 Name Server: NS1.EUROGLOBALHOST.COM
2367 Name Server: NS2.EUROGLOBALHOST.COM
2368
2369Domain Name: 1000models.net
2370Registry Domain ID: 2060561760_DOMAIN_NET-VRSN
2371Registrar WHOIS Server: whois.joker.com
2372Registrar URL: http://joker.com/
2373Updated Date: 2017-09-02T13:39:27Z
2374Creation Date: 2016-09-20T06:54:17Z
2375Registrar Registration Expiration Date: 2018-09-20T06:54:17Z
2376Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
2377Registrar IANA ID: 113
2378Registrar Abuse Contact Email: abuse@joker.com
2379Registrar Abuse Contact Phone: +49.21186767447
2380Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2381Registry Registrant ID:
2382Registrant Name: Rene Elizabeth Figueiredo
2383Registrant Street: 170 Riverview dr.
2384Registrant City: Fort Bragg
2385Registrant State/Province: CA
2386Registrant Postal Code: 95437
2387Registrant Country: US
2388Registrant Phone: +1.7079644761
2389Registrant Email: e.efigueiredo@aol.com
2390Registry Admin ID:
2391Admin Name: Rene Elizabeth Figueiredo
2392Admin Street: 170 Riverview dr.
2393Admin City: Fort Bragg
2394Admin State/Province: CA
2395Admin Postal Code: 95437
2396Admin Country: US
2397Admin Phone: +1.7079644761
2398Admin Email: e.efigueiredo@aol.com
2399Registry Tech ID:
2400Tech Name: Rene Elizabeth Figueiredo
2401Tech Street: 170 Riverview dr.
2402Tech City: Fort Bragg
2403Tech State/Province: CA
2404Tech Postal Code: 95437
2405Tech Country: US
2406Tech Phone: +1.7079644761
2407Tech Email: e.efigueiredo@aol.com
2408Name Server: ns1.euroglobalhost.com
2409Name Server: ns2.euroglobalhost.com
2410
2411###########################################################################################
2412
2413;1000models.net. IN ANY
2414
2415;; ANSWER SECTION:
24161000models.net. 14399 IN MX 10 mail.1000models.net.
24171000models.net. 11054 IN A 91.219.29.120
24181000models.net. 11054 IN NS ns1.euroglobalhost.com.
24191000models.net. 11054 IN NS ns2.euroglobalhost.com.
2420
2421PORT STATE SERVICE VERSION
242222/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
2423| ssh-hostkey:
2424| 2048 2b:d0:38:0e:ca:11:3f:76:6c:5b:84:c1:e6:f2:1b:6c (RSA)
2425| 256 2b:b6:42:1b:ac:af:99:36:a4:f0:7b:89:17:bb:ec:81 (ECDSA)
2426|_ 256 88:ff:8e:62:bc:e6:75:1c:c0:06:72:75:e6:c4:66:57 (EdDSA)
242725/tcp filtered smtp
242880/tcp open http nginx 1.10.2
2429|_http-server-header: nginx/1.10.2
2430|_http-title: sexy pictures non-nude
2431135/tcp filtered msrpc
2432139/tcp filtered netbios-ssn
2433445/tcp filtered microsoft-ds
2434465/tcp filtered smtps
2435587/tcp filtered submission
2436Aggressive OS guesses: Linux 4.4 (95%), Linux 3.10 - 3.12 (94%), Linux 4.0 (92%), Linux 3.10 (92%), Linux 3.11 - 4.1 (91%), Linux 2.6.32 (91%), Linux 3.4 (91%), Linux 3.5 (91%), Linux 4.2 (91%), Synology DiskStation Manager 5.1 (91%)
2437No exact OS matches for host (test conditions non-ideal).
2438Network Distance: 12 hops
2439
2440TRACEROUTE (using port 21/tcp)
2441HOP RTT ADDRESS
24421 35.64 ms 10.13.0.1
24432 ...
24443 870.56 ms 178.33.103.229
24454 ...
24465 875.01 ms 213.186.32.211
24476 47.12 ms 91.121.215.191
24487 ...
24498 63.30 ms 87.245.233.213
24509 56.38 ms 87.245.237.118
245110 52.90 ms 195.177.68.94
245211 60.10 ms 193.193.193.45
245312 269.30 ms 91.219.29.120
2454
2455OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2456Nmap done: 1 IP address (1 host up) scanned in 86.67 seconds
2457
2458###########################################################################################
2459
2460amap -i temp.txt
2461amap v5.4 (www.thc.org/thc-amap) started at 2017-09-09 23:55:45 - APPLICATION MAPPING mode
2462
2463Protocol on 91.219.29.120:80/tcp matches http
2464Protocol on 91.219.29.120:22/tcp matches ssh
2465Protocol on 91.219.29.120:22/tcp matches ssh-openssh
2466Protocol on 91.219.29.120:80/tcp matches http-apache-2
2467this connect
2468this connect
2469
2470inetnum: 91.219.28.0 - 91.219.31.255
2471netname: UKRSERVERS-NET
2472country: UA
2473org: ORG-FKAV1-RIPE
2474admin-c: KCH78-RIPE
2475tech-c: KCH78-RIPE
2476status: ASSIGNED PI
2477mnt-by: RIPE-NCC-END-MNT
2478mnt-by: UADOMEN-MNT
2479mnt-routes: UADOMEN-MNT
2480mnt-routes: DATAHARBOUR-MNT
2481mnt-domains: UADOMEN-MNT
2482created: 2010-09-06T11:31:55Z
2483last-modified: 2017-01-31T08:48:17Z
2484source: RIPE
2485sponsoring-org: ORG-SL452-RIPE
2486
2487organisation: ORG-FKAV1-RIPE
2488org-name: FLP Kochenov Aleksej Vladislavovich
2489org-type: OTHER
2490address: 38, Danilevskogo Str., Kharkov
2491address: Kharkov, Ukraine
2492phone: +38.0443039163
2493fax-no: +38.0577209170
2494abuse-c: AR18187-RIPE
2495admin-c: KCH78-RIPE
2496tech-c: KCH78-RIPE
2497mnt-ref: UADOMEN-MNT
2498mnt-ref: SINARO
2499abuse-mailbox: hostmaster@uadomen.com
2500mnt-by: UADOMEN-MNT
2501created: 2009-02-13T16:33:48Z
2502last-modified: 2017-01-20T20:50:23Z
2503source: RIPE # Filtered
2504
2505person: Aleksej V. Kochenov
2506address: 8, Donvar Zapolskogo Str.,
2507address: Kiev, Ukraine
2508phone: +38.0443039163
2509fax-no: +38.0577209170
2510nic-hdl: KCH78-RIPE
2511abuse-mailbox: support@uadomen.com
2512mnt-by: UADOMEN-MNT
2513created: 2009-02-13T13:13:18Z
2514last-modified: 2015-05-28T18:26:23Z
2515source: RIPE # Filtered
2516
2517% Information related to '91.219.29.0/24AS3254'
2518
2519route: 91.219.29.0/24
2520descr: AGGREGATE BLOCK FOR LuckyNet Datacenter
2521origin: AS3254
2522mnt-by: AS3254-MNT
2523created: 2011-03-23T09:12:24Z
2524last-modified: 2011-03-23T09:12:24Z
2525source: RIPE
2526
2527% This query was served by the RIPE Database Query Service version 1.89.2 (BLAARKOP)
2528
2529###########################################################################################
2530[i] Scanning Site: http://1000models.net
2531
2532
2533
2534B A S I C I N F O
2535====================
2536
2537
2538[+] Site Title: sexy pictures non-nude
2539[+] IP address: 91.219.29.120
2540[+] Web Server: nginx/1.10.2
2541[+] CMS: Could Not Detect
2542[+] Cloudflare: Not Detected
2543[+] Robots File: Found
2544
2545-------------[ contents ]----------------
2546User-agent: *
2547Disallow:
2548Host: 1000models.net
2549Sitemap: http://1000models.net/sitemap.xml
2550-----------[end of contents]-------------
2551
2552
2553
2554W H O I S L O O K U P
2555========================
2556
2557 Domain Name: 1000MODELS.NET
2558 Registry Domain ID: 2060561760_DOMAIN_NET-VRSN
2559 Registrar WHOIS Server: whois.joker.com
2560 Registrar URL: http://www.joker.com
2561 Updated Date: 2017-09-02T13:39:27Z
2562 Creation Date: 2016-09-20T06:54:17Z
2563 Registry Expiry Date: 2018-09-20T06:54:17Z
2564 Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
2565 Registrar IANA ID: 113
2566 Registrar Abuse Contact Email: abuse@joker.com
2567 Registrar Abuse Contact Phone: +49.21186767447
2568 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2569 Name Server: NS1.EUROGLOBALHOST.COM
2570 Name Server: NS2.EUROGLOBALHOST.COM
2571 DNSSEC: unsigned
2572
2573
2574
2575
2576
2577G E O I P L O O K U P
2578=========================
2579
2580[i] IP Address: 91.219.29.120
2581[i] Country: UA
2582[i] State: N/A
2583[i] City: N/A
2584[i] Latitude: 50.450001
2585[i] Longitude: 30.523300
2586
2587
2588
2589
2590H T T P H E A D E R S
2591=======================
2592
2593
2594[i] HTTP/1.1 200 OK
2595[i] Server: nginx/1.10.2
2596[i] Date: Sun, 10 Sep 2017 03:49:29 GMT
2597[i] Content-Type: text/html; charset=utf-8
2598[i] Connection: close
2599[i] Accept-Ranges: bytes
2600[i] Vary: Accept-Encoding,User-Agent
2601
2602
2603
2604
2605D N S L O O K U P
2606===================
2607
26081000models.net. 14393 IN A 91.219.29.120
26091000models.net. 14400 IN NS ns2.euroglobalhost.com.
26101000models.net. 14400 IN NS ns1.euroglobalhost.com.
26111000models.net. 14400 IN SOA ns1.euroglobalhost.com. hostmaster.1000models.net. 2017031402 14400 3600 1209600 86400
26121000models.net. 14400 IN MX 10 mail.1000models.net.
26131000models.net. 14400 IN TXT "v=spf1 a mx ip4:80.82.64.110 ~all"
2614
2615
2616
2617
2618S U B N E T C A L C U L A T I O N
2619====================================
2620
2621Address = 91.219.29.120
2622Network = 91.219.29.120 / 32
2623Netmask = 255.255.255.255
2624Broadcast = not needed on Point-to-Point links
2625Wildcard Mask = 0.0.0.0
2626Hosts Bits = 0
2627Max. Hosts = 1 (2^0 - 0)
2628Host Range = { 91.219.29.120 - 91.219.29.120 }
2629
2630
2631
2632N M A P P O R T S C A N
2633============================
2634
2635
2636Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 03:51 UTC
2637Nmap scan report for 1000models.net (91.219.29.120)
2638Host is up (0.12s latency).
2639rDNS record for 91.219.29.120: 120.29.219.91.colo.ukrservers.com
2640PORT STATE SERVICE VERSION
264121/tcp closed ftp
264222/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
264323/tcp closed telnet
264425/tcp closed smtp
264580/tcp open http nginx 1.10.2
2646110/tcp closed pop3
2647143/tcp closed imap
2648443/tcp closed https
2649445/tcp closed microsoft-ds
26503389/tcp closed ms-wbt-server
2651
2652S U B - D O M A I N F I N D E R
2653==================================
2654
2655
2656[i] Total Subdomains Found : 2
2657
2658[+] Subdomain: 1000models.net
2659[-] IP: 91.219.29.120
2660
2661[+] Subdomain: mail.1000models.net
2662[-] IP: 80.82.64.193
26631000models.net
2664
2665
2666 Domain Name: 1000MODELS.NET
2667 Registry Domain ID: 2060561760_DOMAIN_NET-VRSN
2668 Registrar WHOIS Server: whois.joker.com
2669 Registrar URL: http://www.joker.com
2670 Updated Date: 2017-09-02T13:39:27Z
2671 Creation Date: 2016-09-20T06:54:17Z
2672 Registry Expiry Date: 2018-09-20T06:54:17Z
2673 Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
2674 Registrar IANA ID: 113
2675 Registrar Abuse Contact Email: abuse@joker.com
2676 Registrar Abuse Contact Phone: +49.21186767447
2677 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2678 Name Server: NS1.EUROGLOBALHOST.COM
2679 Name Server: NS2.EUROGLOBALHOST.COM
2680
2681Domain Name: 1000models.net
2682Registry Domain ID: 2060561760_DOMAIN_NET-VRSN
2683Registrar WHOIS Server: whois.joker.com
2684Registrar URL: http://joker.com/
2685Updated Date: 2017-09-02T13:39:27Z
2686Creation Date: 2016-09-20T06:54:17Z
2687Registrar Registration Expiration Date: 2018-09-20T06:54:17Z
2688Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
2689Registrar IANA ID: 113
2690Registrar Abuse Contact Email: abuse@joker.com
2691Registrar Abuse Contact Phone: +49.21186767447
2692Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2693Registry Registrant ID:
2694Registrant Name: Rene Elizabeth Figueiredo
2695Registrant Street: 170 Riverview dr.
2696Registrant City: Fort Bragg
2697Registrant State/Province: CA
2698Registrant Postal Code: 95437
2699Registrant Country: US
2700Registrant Phone: +1.7079644761
2701Registrant Email: e.efigueiredo@aol.com
2702Registry Admin ID:
2703Admin Name: Rene Elizabeth Figueiredo
2704Admin Street: 170 Riverview dr.
2705Admin City: Fort Bragg
2706Admin State/Province: CA
2707Admin Postal Code: 95437
2708Admin Country: US
2709Admin Phone: +1.7079644761
2710Admin Email: e.efigueiredo@aol.com
2711Registry Tech ID:
2712Tech Name: Rene Elizabeth Figueiredo
2713Tech Street: 170 Riverview dr.
2714Tech City: Fort Bragg
2715Tech State/Province: CA
2716Tech Postal Code: 95437
2717Tech Country: US
2718Tech Phone: +1.7079644761
2719Tech Email: e.efigueiredo@aol.com
2720Name Server: ns1.euroglobalhost.com
2721Name Server: ns2.euroglobalhost.com
2722
2723----- 1000models.net -----
2724
2725
2726Host's addresses:
2727__________________
2728
27291000models.net. 11055 IN A 91.219.29.120
2730
2731
2732Name Servers:
2733______________
2734
2735
2736
2737Mail (MX) Servers:
2738___________________
2739
2740mail.1000models.net. 14400 IN A 80.82.64.193
2741
2742
2743Brute forcing with dns.txt:
2744____________________________
2745
2746ftp.1000models.net. 14400 IN A 80.82.64.193
2747mail.1000models.net. 14379 IN A 80.82.64.193
2748pop.1000models.net. 14400 IN A 80.82.64.193
2749smtp.1000models.net. 14400 IN A 80.82.64.193
2750www.1000models.net. 14400 IN A 91.219.29.120
2751
2752
2753dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
2754
2755[+] searching (sub)domains for 1000models.net using built-in wordlist
2756[+] using maximum random delay of 10 millisecond(s) between requests
2757
2758ftp.1000models.net
2759IP address #1: 80.82.64.193
2760
2761localhost.1000models.net
2762IPv6 address #1: ::1
2763
2764localhost.1000models.net
2765IP address #1: 127.0.0.1
2766[+] warning: domain might be vulnerable to "same site" scripting (http://snipurl.com/etbcv)
2767
2768mail.1000models.net
2769IP address #1: 80.82.64.193
2770
2771pop.1000models.net
2772IP address #1: 80.82.64.193
2773
2774smtp.1000models.net
2775IP address #1: 80.82.64.193
2776
2777www.1000models.net
2778IP address #1: 91.219.29.120
2779
2780[+] 7 (sub)domains and 7 IP address(es) found
2781[+] completion time: 158 second(s)
2782
2783
2784Tracing to 1000models.net[a] via 192.168.1.254, maximum of 3 retries
2785192.168.1.254 (192.168.1.254) Got answer
2786
2787
2788WhatWeb report for http://1000models.net
2789Status : 200 OK
2790Title : sexy pictures non-nude
2791IP : 91.219.29.120
2792Country : UKRAINE, UA
2793
2794Summary : HTTPServer[nginx/1.10.2], nginx[1.10.2], Script[text/javascript], AddThis
2795
2796Detected Plugins:
2797[ AddThis ]
2798 AddThis is a free way to boost traffic back to your site by
2799 making it easier for visitors to share your content.
2800
2801 Website : http://www.addthis.com/
2802
2803[ HTTPServer ]
2804 HTTP server header string. This plugin also attempts to
2805 identify the operating system from the server header.
2806
2807 String : nginx/1.10.2 (from server string)
2808
2809[ Script ]
2810 This plugin detects instances of script HTML elements and
2811 returns the script language/type.
2812
2813 String : text/javascript
2814
2815[ nginx ]
2816 Nginx (Engine-X) is a free, open-source, high-performance
2817 HTTP server and reverse proxy, as well as an IMAP/POP3
2818 proxy server.
2819
2820 Version : 1.10.2
2821 Website : http://nginx.net/
2822
2823HTTP Headers:
2824 HTTP/1.1 200 OK
2825 Server: nginx/1.10.2
2826 Date: Sun, 10 Sep 2017 03:52:03 GMT
2827 Content-Type: text/html; charset=utf-8
2828 Content-Length: 8937
2829 Connection: close
2830 Accept-Ranges: bytes
2831 Vary: Accept-Encoding,User-Agent
2832 Content-Encoding: gzip
2833
2834
2835
2836[+] Hosts found in search engines:
2837------------------------------------
2838[-] Resolving hostnames IPs...
283991.219.29.120:Www.1000models.net
284080.82.64.193:mail.1000models.net
284191.219.29.120:www.1000models.net
2842
2843
2844
2845 ^ ^
2846 _ __ _ ____ _ __ _ _ ____
2847 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2848 | V V // o // _/ | V V // 0 // 0 // _/
2849 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2850 <
2851 ...'
2852
2853 WAFW00F - Web Application Firewall Detection Tool
2854
2855 By Sandro Gauci && Wendel G. Henrique
2856
2857Checking http://1000models.net
2858Generic Detection results:
2859No WAF detected by the generic detection
2860Number of requests: 13
2861
2862
2863DNS Servers for 1000models.net:
2864 ns1.euroglobalhost.com
2865 ns2.euroglobalhost.com
2866
2867
28681000models.net does NOT use Load-balancing.
2869
2870
2871
2872Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2873
2874 ----------------------------------------------------------
2875| Scan Information |
2876 ----------------------------------------------------------
2877
2878Mode ..................... VRFY
2879Worker Processes ......... 5
2880Usernames file ........... users.txt
2881Target count ............. 1
2882Username count ........... 494
2883Target TCP port .......... 25
2884Query timeout ............ 5 secs
2885Target domain ............
2886
2887######## Scan started at Sat Sep 9 23:57:07 2017 #########
2888######## Scan completed at Sun Sep 10 00:05:22 2017 #########
28890 results.
2890
2891494 queries in 495 seconds (1.0 queries / sec)
2892
2893
2894
2895Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:05 EDT
2896NSE: Loaded 146 scripts for scanning.
2897NSE: Script Pre-scanning.
2898Initiating NSE at 00:05
2899Completed NSE at 00:05, 0.00s elapsed
2900Initiating NSE at 00:05
2901Completed NSE at 00:05, 0.00s elapsed
2902Failed to resolve "1000models.net.txt".
2903Initiating Parallel DNS resolution of 1 host. at 00:05
2904Completed Parallel DNS resolution of 1 host. at 00:05, 1.21s elapsed
2905Initiating SYN Stealth Scan at 00:05
2906Scanning 1000models.net (91.219.29.120) [100 ports]
2907Discovered open port 22/tcp on 91.219.29.120
2908Discovered open port 80/tcp on 91.219.29.120
2909Increasing send delay for 91.219.29.120 from 0 to 5 due to 11 out of 22 dropped probes since last increase.
2910Increasing send delay for 91.219.29.120 from 5 to 10 due to 50 out of 124 dropped probes since last increase.
2911Completed SYN Stealth Scan at 00:05, 8.39s elapsed (100 total ports)
2912Initiating Service scan at 00:05
2913Scanning 2 services on 1000models.net (91.219.29.120)
2914Completed Service scan at 00:05, 7.48s elapsed (2 services on 1 host)
2915Initiating OS detection (try #1) against 1000models.net (91.219.29.120)
2916Retrying OS detection (try #2) against 1000models.net (91.219.29.120)
2917adjust_timeouts2: packet supposedly had rtt of -109425 microseconds. Ignoring time.
2918adjust_timeouts2: packet supposedly had rtt of -109425 microseconds. Ignoring time.
2919Initiating Traceroute at 00:05
2920Completed Traceroute at 00:05, 3.02s elapsed
2921Initiating Parallel DNS resolution of 11 hosts. at 00:05
2922Completed Parallel DNS resolution of 11 hosts. at 00:05, 5.62s elapsed
2923NSE: Script scanning 91.219.29.120.
2924Initiating NSE at 00:05
2925Completed NSE at 00:06, 22.50s elapsed
2926Initiating NSE at 00:06
2927Completed NSE at 00:06, 0.00s elapsed
2928Nmap scan report for 1000models.net (91.219.29.120)
2929Host is up (0.16s latency).
2930rDNS record for 91.219.29.120: 120.29.219.91.colo.ukrservers.com
2931Not shown: 92 closed ports
2932PORT STATE SERVICE VERSION
293322/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
2934| ssh-hostkey:
2935| 2048 2b:d0:38:0e:ca:11:3f:76:6c:5b:84:c1:e6:f2:1b:6c (RSA)
2936| 256 2b:b6:42:1b:ac:af:99:36:a4:f0:7b:89:17:bb:ec:81 (ECDSA)
2937|_ 256 88:ff:8e:62:bc:e6:75:1c:c0:06:72:75:e6:c4:66:57 (EdDSA)
293825/tcp filtered smtp
293980/tcp open http nginx 1.10.2
2940| http-methods:
2941|_ Supported Methods: OPTIONS GET HEAD POST
2942|_http-server-header: nginx/1.10.2
2943|_http-title: sexy pictures non-nude
2944135/tcp filtered msrpc
2945139/tcp filtered netbios-ssn
2946445/tcp filtered microsoft-ds
2947465/tcp filtered smtps
2948587/tcp filtered submission
2949Aggressive OS guesses: Linux 3.10 - 3.12 (94%), Linux 4.4 (94%), Linux 4.0 (92%), Linux 3.11 - 4.1 (91%), Linux 3.10 (91%), Linux 2.6.32 (91%), Linux 3.4 (91%), Linux 3.5 (91%), Linux 4.2 (91%), Synology DiskStation Manager 5.1 (91%)
2950No exact OS matches for host (test conditions non-ideal).
2951Uptime guess: 30.315 days (since Thu Aug 10 16:33:08 2017)
2952Network Distance: 12 hops
2953TCP Sequence Prediction: Difficulty=264 (Good luck!)
2954IP ID Sequence Generation: All zeros
2955
2956TRACEROUTE (using port 111/tcp)
2957HOP RTT ADDRESS
29581 109.85 ms 10.13.0.1
29592 156.23 ms 37.187.24.252
29603 110.62 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
29614 111.40 ms 10.95.33.8
29625 116.92 ms be100-1108.ams-1-a9.nl.eu (213.186.32.211)
29636 139.50 ms be100-1166.var-5-a9.pl.eu (91.121.215.191)
29647 ...
29658 152.44 ms ae0-1.RT1.NTL.KIV.UA.retn.net (87.245.233.213)
29669 152.49 ms GW-Fiberax.retn.net (87.245.237.118)
296710 152.49 ms 195.177.68.94
296811 152.54 ms runa.lucky.net (193.193.193.45)
296912 152.02 ms 120.29.219.91.colo.ukrservers.com (91.219.29.120)
2970
2971
2972
2973 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
2974 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2975 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
2976 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2977 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
2978
2979 _/ User-Agent Tester ↵
2980 _/ AKA: Purple Pimp ↵
2981 _/ ChrisJohnRiley ↵
2982 _/ blog.c22.cc ↵
2983
2984 [>] Performing initial request and confirming stability
2985 [>] Using User-Agent string Mozilla/5.0
2986
2987 [ ] URL (ENTERED): http://1000models.net
2988 [ ] Response Code: 200 OK
2989 [ ] Server: nginx/1.10.2
2990 [ ] Date: Sun, 10 Sep 2017 04:04:54 GMT
2991 [ ] Content-Type: text/html; charset=utf-8
2992 [ ] Transfer-Encoding: chunked
2993 [ ] Connection: close
2994 [ ] Accept-Ranges: bytes
2995 [ ] Vary: Accept-Encoding,User-Agent
2996 [ ] Data (MD5): aec933bd8740ac19a1d822d362c01628
2997
2998 [1] Pass
2999 [2] Pass
3000 [3] Pass
3001
3002 [>] URL appears stable. Beginning test
3003
3004 [>] Using DEFAULT User-Agent Strings
3005
3006 [>] Using Crazy User-Agent Strings
3007 [>] Using Bot User-Agent Strings
3008
3009 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
3010
3011
3012 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
3013
3014
3015 [!] Data (MD5): 94b5aa8ae42cce18e0d08cd217bb7ac1
3016
3017
3018 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
3019
3020
3021 [!] Data (MD5): 005802b73182dac4bb822ddecbf47cbb
3022
3023
3024 [>] User-Agent String : TrackBack/1.02
3025
3026
3027 [!] Data (MD5): 93d0d7881b8ed977cca8186050a6b710
3028
3029
3030 [>] User-Agent String : wispr
3031
3032
3033 [!] Data (MD5): dc867703bdc22144b641cce9f39f5272
3034
3035
3036 [>] User-Agent String : EMPTY USER-AGENT STRING!
3037
3038
3039 [!] Data (MD5): 89a7b8bcf601221d6e97e4c82ba98979
3040
3041
3042 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
3043
3044
3045 [!] Data (MD5): 5f3f43876e2706f52cd4f79c6234cfa4
3046
3047
3048 [>] User-Agent String : Googlebot-Image/1.0
3049
3050
3051 [!] Data (MD5): 19304c0b1089862733166bbe69e9f0be
3052
3053
3054 [>] User-Agent String : Mediapartners-Google
3055
3056
3057 [!] Data (MD5): c5ab794a89f9259346eec32d51678b7c
3058
3059
3060 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
3061
3062
3063 [!] Data (MD5): 3926c8f7615fc49a7b11fd148fe9716c
3064
3065
3066 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
3067
3068
3069 [!] Data (MD5): 9577fbda3cc4a74573802b867c6118a3
3070
3071
3072 [>] User-Agent String : mmcrawler
3073
3074
3075 [!] Data (MD5): b19b9e9aaf08c83e176a4e812cfa57ef
3076
3077
3078 [>] Checks completed... try enabling VERBOSE mode for more detailed output
3079
3080 [>] That's all folks... Fo' Shizzle!
3081##########################################################################################
3082Hostname dolce-forum.info ISP FOP Sedinkin Olexandr Valeriyovuch (AS56485)
3083Continent Europe Flag
3084UA
3085Country Ukraine Country Code UA (UKR)
3086Region Unknown Local time 10 Sep 2017 07:09 EEST
3087City Unknown Latitude 50.45
3088IP Address 176.114.5.138 Longitude 30.523
3089##########################################################################################
3090dolce-forum.info
3091
3092###########################################################################################
3093
3094whois dolce-forum.info
3095Domain Name: DOLCE-FORUM.INFO
3096Registry Domain ID: D48040481-LRMS
3097Registrar WHOIS Server:
3098Registrar URL: http://www.joker.com
3099Updated Date: 2017-09-02T13:39:31Z
3100Creation Date: 2012-10-10T11:42:24Z
3101Registry Expiry Date: 2018-10-10T11:42:24Z
3102Registrar Registration Expiration Date:
3103Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
3104Registrar IANA ID: 113
3105Registrar Abuse Contact Email:
3106Registrar Abuse Contact Phone:
3107Reseller:
3108Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3109Registry Registrant ID: C134259982-LRMS
3110Registrant Name: Rene Elizabeth Figueiredo
3111Registrant Organization:
3112Registrant Street: 170 Riverview dr.
3113Registrant City: Fort Bragg
3114Registrant State/Province: CA
3115Registrant Postal Code: 95437
3116Registrant Country: US
3117Registrant Phone: +1.7079644761
3118Registrant Phone Ext:
3119Registrant Fax:
3120Registrant Fax Ext:
3121Registrant Email: e.efigueiredo@aol.com
3122Registry Admin ID: C134259848-LRMS
3123Admin Name: Rene Elizabeth Figueiredo
3124Admin Organization:
3125Admin Street: 170 Riverview dr.
3126Admin City: Fort Bragg
3127Admin State/Province: CA
3128Admin Postal Code: 95437
3129Admin Country: US
3130Admin Phone: +1.7079644761
3131Admin Phone Ext:
3132Admin Fax:
3133Admin Fax Ext:
3134Admin Email: e.efigueiredo@aol.com
3135Registry Tech ID: C134259848-LRMS
3136Tech Name: Rene Elizabeth Figueiredo
3137Tech Organization:
3138Tech Street: 170 Riverview dr.
3139Tech City: Fort Bragg
3140Tech State/Province: CA
3141Tech Postal Code: 95437
3142Tech Country: US
3143Tech Phone: +1.7079644761
3144Tech Phone Ext:
3145Tech Fax:
3146Tech Fax Ext:
3147Tech Email: e.efigueiredo@aol.com
3148Registry Billing ID: C134259848-LRMS
3149Billing Name: Rene Elizabeth Figueiredo
3150Billing Organization:
3151Billing Street: 170 Riverview dr.
3152Billing City: Fort Bragg
3153Billing State/Province: CA
3154Billing Postal Code: 95437
3155Billing Country: US
3156Billing Phone: +1.7079644761
3157Billing Phone Ext:
3158Billing Fax:
3159Billing Fax Ext:
3160Billing Email: e.efigueiredo@aol.com
3161Name Server: NS1.GEOSCALING.COM
3162Name Server: NS2.GEOSCALING.COM
3163Name Server: NS3.GEOSCALING.COM
3164Name Server: NS4.GEOSCALING.COM
3165
3166###########################################################################################
3167
3168dig dolce-forum.info any
3169
3170; <<>> DiG 9.10.3-P4-Debian <<>> dolce-forum.info any
3171;; global options: +cmd
3172;; Got answer:
3173;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5798
3174;; flags: qr rd ra; QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1
3175
3176;; OPT PSEUDOSECTION:
3177; EDNS: version: 0, flags:; udp: 4096
3178;; QUESTION SECTION:
3179;dolce-forum.info. IN ANY
3180
3181;; ANSWER SECTION:
3182dolce-forum.info. 7198 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
3183dolce-forum.info. 286 IN A 176.114.5.138
3184dolce-forum.info. 7198 IN NS ns3.geoscaling.com.
3185dolce-forum.info. 7198 IN NS ns2.geoscaling.com.
3186dolce-forum.info. 7198 IN NS ns1.geoscaling.com.
3187dolce-forum.info. 7198 IN NS ns5.geoscaling.com.
3188
3189
3190Checking for HTTP-Loadbalancing [Diff]: FOUND
3191< Date: Sun, 10 Sep 2017 04:17:14 GMT
3192< Content-Type: text/html
3193< Connection: close
3194< Accept-Ranges: bytes
3195< Vary: Accept-Encoding,User-Agent
3196<
3197< HTTP/1.1 200 OK
3198< Server: nginx/1.10.2
3199< Date: Sun, 10 Sep 2017 04:17:15 GMT
3200< Content-Type: text/html
3201< Connection: close
3202< Accept-Ranges: bytes
3203< Vary: Accept-Encoding,User-Agent
3204<
3205< HTTP/1.1 200 OK
3206< Server: nginx/1.10.2
3207< Date: Sun, 10 Sep 2017 04:17:16 GMT
3208< Content-Type: text/html
3209< Connection: close
3210< Accept-Ranges: bytes
3211< Vary: Accept-Encoding,User-Agent
3212<
3213< HTTP/1.1 200 OK
3214< Server: nginx/1.10.2
3215< Date: Sun, 10 Sep 2017 04:17:17 GMT
3216< Content-Type: text/html
3217< Connection: close
3218< Accept-Ranges: bytes
3219< Vary: Accept-Encoding,User-Agent
3220<
3221< HTTP/1.1 200 OK
3222< Server: nginx/1.10.2
3223< Date: Sun, 10 Sep 2017 04:17:22 GMT
3224< Content-Type: text/html
3225< Connection: close
3226< Accept-Ranges: bytes
3227< Vary: Accept-Encoding,User-Agent
3228<
3229< HTTP/1.1 200 OK
3230< Server: nginx/1.10.2
3231< Date: Sun, 10 Sep 2017 04:17:26 GMT
3232< Content-Type: text/html
3233< Connection: close
3234< Accept-Ranges: bytes
3235< Vary: Accept-Encoding,User-Agent
3236<
3237< HTTP/1.1 200 OK
3238< Server: nginx/1.10.2
3239< Date: Sun, 10 Sep 2017 04:17:28 GMT
3240< Content-Type: text/html
3241< Connection: close
3242< Accept-Ranges: bytes
3243< Vary: Accept-Encoding,User-Agent
3244<
3245< HTTP/1.1 200 OK
3246< Server: nginx/1.10.2
3247< Date: Sun, 10 Sep 2017 04:17:29 GMT
3248< Content-Type: text/html
3249< Connection: close
3250< Accept-Ranges: bytes
3251< Vary: Accept-Encoding,User-Agent
3252<
3253< HTTP/1.1 200 OK
3254< Server: nginx/1.10.2
3255< Date: Sun, 10 Sep 2017 04:17:30 GMT
3256< Content-Type: text/html
3257< Connection: close
3258< Accept-Ranges: bytes
3259< Vary: Accept-Encoding,User-Agent
3260<
3261< HTTP/1.1 200 OK
3262< Server: nginx/1.10.2
3263< Date: Sun, 10 Sep 2017 04:17:34 GMT
3264< Content-Type: text/html
3265< Connection: close
3266< Accept-Ranges: bytes
3267< Vary: Accept-Encoding,User-Agent
3268<
3269< HTTP/1.1 200 OK
3270< Server: nginx/1.10.2
3271< Date: Sun, 10 Sep 2017 04:17:37 GMT
3272< Content-Type: text/html
3273< Connection: close
3274< Accept-Ranges: bytes
3275< Vary: Accept-Encoding,User-Agent
3276<
3277< HTTP/1.1 200 OK
3278< Server: nginx/1.10.2
3279< Date: Sun, 10 Sep 2017 04:17:37 GMT
3280< Content-Type: text/html
3281< Connection: close
3282< Accept-Ranges: bytes
3283< Vary: Accept-Encoding,User-Agent
3284<
3285< HTTP/1.1 200 OK
3286< Server: nginx/1.10.2
3287< Date: Sun, 10 Sep 2017 04:17:38 GMT
3288
3289dolce-forum.info does Load-balancing. Found via Methods: HTTP[Diff]
3290
3291###########################################################################################
3292
3293nmap -PN -n -F -T4 -sV -A -oG temp.txt dolce-forum.info
3294
3295Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:17 EDT
3296Nmap scan report for dolce-forum.info (176.114.5.138)
3297Host is up (1.0s latency).
3298Not shown: 90 closed ports
3299PORT STATE SERVICE VERSION
330022/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
3301| ssh-hostkey:
3302| 2048 ce:2f:35:6c:4b:09:dd:5d:5e:b0:68:98:78:a2:65:0b (RSA)
3303| 256 f3:f4:05:37:96:9f:1a:8f:31:5d:18:69:f8:35:f7:a7 (ECDSA)
3304|_ 256 6a:f4:e1:4d:5e:9f:93:e3:e5:2f:cb:13:91:00:f6:ae (EdDSA)
330525/tcp filtered smtp
330653/tcp filtered domain
330780/tcp open http nginx 1.10.2
3308|_http-server-header: nginx/1.10.2
3309|_http-title: Site doesn't have a title (text/html).
3310111/tcp open rpcbind 2-4 (RPC #100000)
3311| rpcinfo:
3312| program version port/proto service
3313| 100000 2,3,4 111/tcp rpcbind
3314|_ 100000 2,3,4 111/udp rpcbind
3315135/tcp filtered msrpc
3316139/tcp filtered netbios-ssn
3317445/tcp filtered microsoft-ds
3318465/tcp filtered smtps
3319587/tcp filtered submission
3320Aggressive OS guesses: Linux 4.4 (94%), Linux 3.10 - 3.12 (93%), Linux 4.0 (92%), Linux 3.11 - 4.1 (91%), Linux 3.10 (91%), Linux 2.6.32 (91%), Linux 3.4 (91%), Linux 3.5 (91%), Linux 4.2 (91%), Synology DiskStation Manager 5.1 (91%)
3321No exact OS matches for host (test conditions non-ideal).
3322Network Distance: 10 hops
3323
3324TRACEROUTE (using port 8080/tcp)
3325HOP RTT ADDRESS
33261 836.76 ms 10.13.0.1
33272 928.90 ms 37.187.24.252
33283 840.89 ms 178.33.103.229
33294 ...
33305 845.78 ms 213.186.32.213
33316 912.99 ms 91.121.215.191
33327 928.92 ms 193.25.180.159
33338 950.45 ms 91.196.149.36
33349 919.23 ms 91.196.149.36
333510 950.38 ms 176.114.5.138
3336
3337OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
3338Nmap done: 1 IP address (1 host up) scanned in 105.75 seconds
3339
3340###########################################################################################
3341
3342amap -i temp.txt
3343amap v5.4 (www.thc.org/thc-amap) started at 2017-09-10 00:19:24 - APPLICATION MAPPING mode
3344
3345Protocol on 176.114.5.138:22/tcp matches ssh
3346Protocol on 176.114.5.138:22/tcp matches ssh-openssh
3347Protocol on 176.114.5.138:80/tcp matches http
3348Protocol on 176.114.5.138:111/tcp matches rpc
3349Protocol on 176.114.5.138:111/tcp matches rpc-rpcbind-v4
3350
3351inetnum: 176.114.0.0 - 176.114.15.255
3352netname: THEHOST-NETWORK-3
3353country: UA
3354org: ORG-FSOV1-RIPE
3355admin-c: SA7501-RIPE
3356tech-c: SA7501-RIPE
3357status: ASSIGNED PI
3358mnt-by: RIPE-NCC-END-MNT
3359mnt-by: THEHOST-MNT
3360mnt-routes: THEHOST-MNT
3361mnt-domains: THEHOST-MNT
3362created: 2012-04-10T13:34:51Z
3363last-modified: 2017-05-11T09:51:38Z
3364source: RIPE
3365sponsoring-org: ORG-ML410-RIPE
3366
3367organisation: ORG-FSOV1-RIPE
3368org-name: FOP Sedinkin Olexandr Valeriyovuch
3369org-type: other
3370address: 08154, Ukraine, Boyarka, Belogorodskaya str., 11a
3371abuse-c: AR19055-RIPE
3372abuse-mailbox: abuse@thehost.ua
3373remarks: -----------------------------------------------------
3374remarks: Hosting Provider TheHost
3375remarks: -----------------------------------------------------
3376remarks: For abuse/spam issues contact abuse@thehost.ua
3377remarks: For general/sales questions contact info@thehost.ua
3378remarks: For technical support contact support@thehost.ua
3379remarks: -----------------------------------------------------
3380phone: +380 44 222-9-888
3381phone: +7 499 403-36-28
3382fax-no: +380 44 222-9-888 ext. 4
3383admin-c: SA7501-RIPE
3384mnt-ref: THEHOST-MNT
3385mnt-by: THEHOST-MNT
3386created: 2011-03-01T10:48:14Z
3387last-modified: 2015-11-29T21:16:15Z
3388source: RIPE # Filtered
3389
3390person: Sedinkin Alexander
3391address: Ukraine, Boyarka, Belogorodskaya str., 11a
3392phone: +380 44 222-9-888 ext. 213
3393address: UKRAINE
3394nic-hdl: SA7501-RIPE
3395mnt-by: THEHOST-MNT
3396created: 2011-03-01T10:36:18Z
3397last-modified: 2017-05-03T11:09:44Z
3398source: RIPE # Filtered
3399
3400% Information related to '176.114.4.0/22AS56485'
3401
3402route: 176.114.4.0/22
3403descr: FOP Sedinkin Olexandr Valeriyovuch
3404origin: AS56485
3405mnt-by: THEHOST-MNT
3406created: 2014-04-26T22:56:24Z
3407last-modified: 2014-04-26T22:56:24Z
3408source: RIPE
3409
3410% This query was served by the RIPE Database Query Service version 1.89.2 (WAGYU)
3411###########################################################################################
3412i] Scanning Site: http://dolce-forum.info
3413
3414
3415
3416B A S I C I N F O
3417====================
3418
3419
3420[+] Site Title: Dolce Nonude Models Forum - View Topic - <FolderName>
3421[+] IP address: 176.114.5.138
3422[+] Web Server: nginx/1.10.2
3423[+] CMS: Could Not Detect
3424[+] Cloudflare: Not Detected
3425[+] Robots File: Found
3426
3427-------------[ contents ]----------------
3428User-agent: *
3429Disallow:
3430sitemap: http://dolce-forum.info/sitemap.xml
3431-----------[end of contents]-------------
3432
3433
3434
3435W H O I S L O O K U P
3436========================
3437
3438 Domain Name: DOLCE-FORUM.INFO
3439Registry Domain ID: D48040481-LRMS
3440Registrar WHOIS Server:
3441Registrar URL: http://www.joker.com
3442Updated Date: 2017-09-02T13:39:31Z
3443Creation Date: 2012-10-10T11:42:24Z
3444Registry Expiry Date: 2018-10-10T11:42:24Z
3445Registrar Registration Expiration Date:
3446Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
3447Registrar IANA ID: 113
3448Registrar Abuse Contact Email:
3449Registrar Abuse Contact Phone:
3450Reseller:
3451Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3452Registry Registrant ID: C134259982-LRMS
3453Registrant Name: Rene Elizabeth Figueiredo
3454Registrant Organization:
3455Registrant Street: 170 Riverview dr.
3456Registrant City: Fort Bragg
3457Registrant State/Province: CA
3458Registrant Postal Code: 95437
3459Registrant Country: US
3460Registrant Phone: +1.7079644761
3461Registrant Phone Ext:
3462Registrant Fax:
3463Registrant Fax Ext:
3464Registrant Email: e.efigueiredo@aol.com
3465Registry Admin ID: C134259848-LRMS
3466Admin Name: Rene Elizabeth Figueiredo
3467Admin Organization:
3468Admin Street: 170 Riverview dr.
3469Admin City: Fort Bragg
3470Admin State/Province: CA
3471Admin Postal Code: 95437
3472Admin Country: US
3473Admin Phone: +1.7079644761
3474Admin Phone Ext:
3475Admin Fax:
3476Admin Fax Ext:
3477Admin Email: e.efigueiredo@aol.com
3478Registry Tech ID: C134259848-LRMS
3479Tech Name: Rene Elizabeth Figueiredo
3480Tech Organization:
3481Tech Street: 170 Riverview dr.
3482Tech City: Fort Bragg
3483Tech State/Province: CA
3484Tech Postal Code: 95437
3485Tech Country: US
3486Tech Phone: +1.7079644761
3487Tech Phone Ext:
3488Tech Fax:
3489Tech Fax Ext:
3490Tech Email: e.efigueiredo@aol.com
3491Registry Billing ID: C134259848-LRMS
3492Billing Name: Rene Elizabeth Figueiredo
3493Billing Organization:
3494Billing Street: 170 Riverview dr.
3495Billing City: Fort Bragg
3496Billing State/Province: CA
3497Billing Postal Code: 95437
3498Billing Country: US
3499Billing Phone: +1.7079644761
3500Billing Phone Ext:
3501Billing Fax:
3502Billing Fax Ext:
3503Billing Email: e.efigueiredo@aol.com
3504
3505
3506G E O I P L O O K U P
3507=========================
3508
3509[i] IP Address: 176.114.5.138
3510[i] Country: UA
3511[i] State: N/A
3512[i] City: N/A
3513[i] Latitude: 50.450001
3514[i] Longitude: 30.523300
3515
3516
3517
3518
3519H T T P H E A D E R S
3520=======================
3521
3522
3523[i] HTTP/1.1 200 OK
3524[i] Server: nginx/1.10.2
3525[i] Date: Sun, 10 Sep 2017 04:15:09 GMT
3526[i] Content-Type: text/html
3527[i] Connection: close
3528[i] Accept-Ranges: bytes
3529[i] Vary: Accept-Encoding,User-Agent
3530
3531
3532
3533
3534D N S L O O K U P
3535===================
3536
3537dolce-forum.info. 295 IN A 176.114.5.138
3538dolce-forum.info. 7200 IN NS ns1.geoscaling.com.
3539dolce-forum.info. 7200 IN NS ns5.geoscaling.com.
3540dolce-forum.info. 7200 IN NS ns3.geoscaling.com.
3541dolce-forum.info. 7200 IN NS ns2.geoscaling.com.
3542dolce-forum.info. 7200 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
3543
3544
3545
3546
3547S U B N E T C A L C U L A T I O N
3548====================================
3549
3550Address = 176.114.5.138
3551Network = 176.114.5.138 / 32
3552Netmask = 255.255.255.255
3553Broadcast = not needed on Point-to-Point links
3554Wildcard Mask = 0.0.0.0
3555Hosts Bits = 0
3556Max. Hosts = 1 (2^0 - 0)
3557Host Range = { 176.114.5.138 - 176.114.5.138 }
3558
3559
3560
3561N M A P P O R T S C A N
3562============================
3563
3564
3565Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 04:15 UTC
3566Nmap scan report for dolce-forum.info (176.114.5.138)
3567Host is up (0.12s latency).
3568rDNS record for 176.114.5.138: myserver.org
3569PORT STATE SERVICE VERSION
357021/tcp closed ftp
357122/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
357223/tcp closed telnet
357325/tcp closed smtp
357480/tcp open http nginx 1.10.2
3575110/tcp closed pop3
3576143/tcp closed imap
3577443/tcp closed https
3578445/tcp filtered microsoft-ds
35793389/tcp closed ms-wbt-server
3580
3581Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
3582Nmap done: 1 IP address (1 host up) scanned in 8.99 seconds
3583
3584
3585
3586S U B - D O M A I N F I N D E R
3587==================================
3588
3589
3590[i] Total Subdomains Found : 2
3591
3592[+] Subdomain: dolce-forum.info
3593[-] IP: 176.114.5.138
3594
3595[+] Subdomain: www.dolce-forum.info
3596[-] IP: 176.114.5.138
3597
3598dolce-forum.info
3599[*] Performing TLD Brute force Enumeration against dolce-forum.info
3600[*] The operation could take up to: 00:01:07
3601[*] A dolce-forum.biz.af 5.45.75.45
3602[*] CNAME dolce-forum.biz.at free.biz.at
3603[*] A free.biz.at 216.92.134.29
3604[*] A dolce-forum.co.asia 91.195.240.135
3605[*] A dolce-forum.org.aw 142.4.20.12
3606[*] A dolce-forum.co.ba 176.9.45.78
3607[*] A dolce-forum.com.ba 195.222.33.180
3608[*] A dolce-forum.com.be 95.173.170.166
3609[*] A dolce-forum.biz.by 71.18.52.2
3610[*] A dolce-forum.biz.bz 199.59.242.150
3611[*] A dolce-forum.com.cc 54.252.107.64
3612[*] A dolce-forum.net.cc 54.252.89.206
3613[*] A dolce-forum.co.cc 175.126.123.219
3614[*] A dolce-forum.org.ch 72.52.4.122
3615[*] A dolce-forum.co.cm 85.25.140.105
3616[*] A dolce-forum.net.cm 85.25.140.105
3617[*] A dolce-forum.biz.cl 185.53.178.8
3618[*] A dolce-forum.com.com 52.33.196.199
3619[*] A dolce-forum.net.com 199.59.242.150
3620[*] A dolce-forum.co.com 173.192.115.17
3621[*] A dolce-forum.org.com 23.23.86.44
3622[*] A dolce-forum.biz.cr 72.52.4.122
3623[*] CNAME dolce-forum.biz.cm i.cns.cm
3624[*] A i.cns.cm 118.184.56.30
3625[*] A dolce-forum.biz.cx 72.52.4.122
3626[*] A dolce-forum.biz.cz 185.53.179.7
3627[*] A dolce-forum.net.cz 80.250.24.177
3628[*] A dolce-forum.com.cz 62.109.128.30
3629[*] CNAME dolce-forum.co.de co.de
3630[*] A co.de 144.76.162.245
3631[*] A dolce-forum.com.de 50.56.68.37
3632[*] CNAME dolce-forum.org.de www.org.de
3633[*] A www.org.de 78.47.128.8
3634[*] A dolce-forum.net.eu 78.46.90.98
3635[*] A dolce-forum.org.eu 78.46.90.98
3636[*] A dolce-forum.biz.fi 185.55.85.123
3637[*] A dolce-forum.fm 173.230.131.38
3638[*] A dolce-forum.biz.fm 173.230.131.38
3639[*] A dolce-forum.org.fr 149.202.133.35
3640[*] A dolce-forum.biz.gl 72.52.4.122
3641[*] CNAME dolce-forum.co.gp co.gp
3642[*] A co.gp 144.76.162.245
3643[*] A dolce-forum.co.hn 208.100.40.203
3644[*] CNAME dolce-forum.net.hr net.hr
3645[*] A net.hr 192.0.78.24
3646[*] A net.hr 192.0.78.25
3647[*] CNAME dolce-forum.biz.hn parkmydomain.vhostgo.com
3648[*] A parkmydomain.vhostgo.com 107.186.245.118
3649[*] A dolce-forum.co.ht 72.52.4.122
3650[*] A dolce-forum.info 176.114.5.138
3651[*] A dolce-forum.com.jobs 50.19.241.165
3652[*] A dolce-forum.co.jobs 50.17.193.222
3653[*] A dolce-forum.net.jobs 50.19.241.165
3654[*] A dolce-forum.biz.jobs 50.19.241.165
3655[*] A dolce-forum.org.jobs 50.19.241.165
3656[*] A dolce-forum.biz.ky 199.184.144.27
3657[*] CNAME dolce-forum.biz.li 712936.parkingcrew.net
3658[*] A 712936.parkingcrew.net 185.53.179.29
3659[*] A dolce-forum.biz.lu 195.26.5.2
3660[*] A dolce-forum.biz.ly 64.136.20.39
3661[*] A dolce-forum.biz.md 72.52.4.122
3662[*] A dolce-forum.co.mk 87.76.31.211
3663[*] A dolce-forum.co.mobi 54.225.105.179
3664[*] A dolce-forum.biz.my 202.190.174.44
3665[*] A dolce-forum.co.net 188.166.216.219
3666[*] A dolce-forum.net.net 52.50.81.210
3667[*] A dolce-forum.org.net 23.23.86.44
3668[*] A dolce-forum.co.nl 37.97.184.204
3669[*] A dolce-forum.com.nl 83.98.157.102
3670[*] A dolce-forum.net.nl 83.98.157.102
3671[*] A dolce-forum.co.nr 208.100.40.202
3672[*] CNAME dolce-forum.co.nu co.nu
3673[*] A co.nu 144.76.162.245
3674[*] CNAME dolce-forum.com.nu com.nu
3675[*] A com.nu 144.76.162.245
3676[*] A dolce-forum.net.nu 199.102.76.78
3677[*] A dolce-forum.org.nu 80.92.84.139
3678[*] CNAME dolce-forum.net.org pewtrusts.org
3679[*] A pewtrusts.org 204.74.99.100
3680[*] A dolce-forum.com.org 23.23.86.44
3681[*] A dolce-forum.ph 45.79.222.138
3682[*] A dolce-forum.co.ph 45.79.222.138
3683[*] A dolce-forum.com.ph 45.79.222.138
3684[*] A dolce-forum.net.ph 45.79.222.138
3685[*] A dolce-forum.org.ph 45.79.222.138
3686[*] A dolce-forum.co.pl 212.91.6.55
3687[*] A dolce-forum.org.pm 208.73.211.165
3688[*] A dolce-forum.org.pm 208.73.210.217
3689[*] A dolce-forum.org.pm 208.73.211.177
3690[*] A dolce-forum.org.pm 208.73.210.202
3691[*] A dolce-forum.co.ps 66.96.132.56
3692[*] CNAME dolce-forum.biz.ps biz.ps
3693[*] A biz.ps 144.76.162.245
3694[*] A dolce-forum.co.pt 194.107.127.52
3695[*] A dolce-forum.co.pw 141.8.226.59
3696[*] A dolce-forum.pw 141.8.226.58
3697[*] A dolce-forum.net.pw 141.8.226.59
3698[*] A dolce-forum.biz.pw 141.8.226.59
3699[*] A dolce-forum.org.pw 141.8.226.59
3700[*] A dolce-forum.net.ro 69.64.52.127
3701[*] CNAME dolce-forum.co.ro now.co.ro
3702[*] A now.co.ro 185.27.255.9
3703[*] A dolce-forum.org.re 217.70.184.38
3704[*] A dolce-forum.com.ru 178.210.89.119
3705[*] A dolce-forum.biz.se 185.53.179.6
3706[*] CNAME dolce-forum.net.se 773147.parkingcrew.net
3707[*] A 773147.parkingcrew.net 185.53.179.29
3708[*] A dolce-forum.co.sl 91.195.240.135
3709[*] A dolce-forum.com.sr 143.95.106.249
3710[*] A dolce-forum.biz.st 91.121.28.115
3711[*] A dolce-forum.co.su 72.52.4.122
3712[*] A dolce-forum.biz.tc 64.136.20.39
3713[*] A dolce-forum.biz.tf 85.236.153.18
3714[*] A dolce-forum.net.tf 188.40.70.27
3715[*] A dolce-forum.net.tf 188.40.70.29
3716[*] A dolce-forum.net.tf 188.40.117.12
3717[*] A dolce-forum.co.tl 208.100.40.202
3718[*] A dolce-forum.co.to 175.118.124.44
3719[*] A dolce-forum.co.tv 31.186.25.163
3720[*] A dolce-forum.biz.tv 72.52.4.122
3721[*] A dolce-forum.org.tv 72.52.4.122
3722[*] CNAME dolce-forum.biz.uz biz.uz
3723[*] A biz.uz 144.76.162.245
3724[*] A dolce-forum.vg 88.198.29.97
3725[*] A dolce-forum.co.vg 88.198.29.97
3726[*] A dolce-forum.com.vg 88.198.29.97
3727[*] A dolce-forum.net.vg 68.178.254.180
3728[*] A dolce-forum.biz.vg 89.31.143.20
3729[*] A dolce-forum.ws 64.70.19.203
3730[*] A dolce-forum.com.ws 202.4.48.211
3731[*] A dolce-forum.net.ws 202.4.48.211
3732[*] A dolce-forum.biz.ws 184.168.221.104
3733[*] A dolce-forum.org.ws 202.4.48.211
3734Domain Name: DOLCE-FORUM.INFO
3735Registry Domain ID: D48040481-LRMS
3736Registrar WHOIS Server:
3737Registrar URL: http://www.joker.com
3738Updated Date: 2017-09-02T13:39:31Z
3739Creation Date: 2012-10-10T11:42:24Z
3740Registry Expiry Date: 2018-10-10T11:42:24Z
3741Registrar Registration Expiration Date:
3742Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
3743Registrar IANA ID: 113
3744Registrar Abuse Contact Email:
3745Registrar Abuse Contact Phone:
3746Reseller:
3747Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3748Registry Registrant ID: C134259982-LRMS
3749Registrant Name: Rene Elizabeth Figueiredo
3750Registrant Organization:
3751Registrant Street: 170 Riverview dr.
3752Registrant City: Fort Bragg
3753Registrant State/Province: CA
3754Registrant Postal Code: 95437
3755Registrant Country: US
3756Registrant Phone: +1.7079644761
3757Registrant Phone Ext:
3758Registrant Fax:
3759Registrant Fax Ext:
3760Registrant Email: e.efigueiredo@aol.com
3761Registry Admin ID: C134259848-LRMS
3762Admin Name: Rene Elizabeth Figueiredo
3763Admin Organization:
3764Admin Street: 170 Riverview dr.
3765Admin City: Fort Bragg
3766Admin State/Province: CA
3767Admin Postal Code: 95437
3768Admin Country: US
3769Admin Phone: +1.7079644761
3770Admin Phone Ext:
3771Admin Fax:
3772Admin Fax Ext:
3773Admin Email: e.efigueiredo@aol.com
3774Registry Tech ID: C134259848-LRMS
3775Tech Name: Rene Elizabeth Figueiredo
3776Tech Organization:
3777Tech Street: 170 Riverview dr.
3778Tech City: Fort Bragg
3779Tech State/Province: CA
3780Tech Postal Code: 95437
3781Tech Country: US
3782Tech Phone: +1.7079644761
3783Tech Phone Ext:
3784Tech Fax:
3785Tech Fax Ext:
3786Tech Email: e.efigueiredo@aol.com
3787Registry Billing ID: C134259848-LRMS
3788Billing Name: Rene Elizabeth Figueiredo
3789Billing Organization:
3790Billing Street: 170 Riverview dr.
3791Billing City: Fort Bragg
3792Billing State/Province: CA
3793Billing Postal Code: 95437
3794Billing Country: US
3795Billing Phone: +1.7079644761
3796Billing Phone Ext:
3797Billing Fax:
3798Billing Fax Ext:
3799Billing Email: e.efigueiredo@aol.com
3800Name Server: NS1.GEOSCALING.COM
3801Name Server: NS2.GEOSCALING.COM
3802Name Server: NS3.GEOSCALING.COM
3803Name Server: NS4.GEOSCALING.COM
3804
3805;dolce-forum.info. IN ANY
3806
3807;; ANSWER SECTION:
3808dolce-forum.info. 7200 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
3809dolce-forum.info. 288 IN A 176.114.5.138
3810dolce-forum.info. 7200 IN NS ns2.geoscaling.com.
3811dolce-forum.info. 7200 IN NS ns1.geoscaling.com.
3812dolce-forum.info. 7200 IN NS ns3.geoscaling.com.
3813dolce-forum.info. 7200 IN NS ns5.geoscaling.com.
3814
3815;; Query time: 114 msec
3816;; SERVER: 192.168.1.254#53(192.168.1.254)
3817;; WHEN: Sun Sep 10 00:14:56 EDT 2017
3818;; MSG SIZE rcvd: 191
3819
3820
3821----- dolce-forum.info -----
3822
3823
3824Host's addresses:
3825__________________
3826
3827dolce-forum.info. 277 IN A 176.114.5.138
3828
3829
3830Name Servers:
3831______________
3832
3833ns3.geoscaling.com. 300 IN A 91.121.64.153
3834ns2.geoscaling.com. 300 IN A 91.121.64.153
3835ns5.geoscaling.com. 300 IN A 91.121.64.153
3836ns1.geoscaling.com. 300 IN A 91.121.64.153
3837
3838
3839Mail (MX) Servers:
3840___________________
3841
3842
3843
3844
3845Brute forcing with dns.txt:
3846____________________________
3847
3848www.dolce-forum.info. 300 IN A 176.114.5.138
3849
3850
3851Performing recursion:
3852______________________
3853
3854
3855 ---- Checking subdomains NS records ----
3856
3857 Can't perform recursion no NS records.
3858
3859
3860dolce-forum.info class C netranges:
3861____________________________________
3862
3863 176.114.5.0/24
3864
3865
3866
3867WhatWeb report for http://dolce-forum.info
3868Status : 200 OK
3869Title : <None>
3870IP : 176.114.5.138
3871Country : UKRAINE, UA
3872
3873Summary : HTTPServer[nginx/1.10.2], Meta-Author[http://dolce-forum.info,www.dolce-forum.info], nginx[1.10.2], Script[text/javascript], AddThis
3874
3875Detected Plugins:
3876[ AddThis ]
3877 AddThis is a free way to boost traffic back to your site by
3878 making it easier for visitors to share your content.
3879
3880 Website : http://www.addthis.com/
3881
3882[ HTTPServer ]
3883 HTTP server header string. This plugin also attempts to
3884 identify the operating system from the server header.
3885
3886 String : nginx/1.10.2 (from server string)
3887
3888[ Meta-Author ]
3889 This plugin retrieves the author name from the meta name
3890 tag - info:
3891 http://www.webmarketingnow.com/tips/meta-tags-uncovered.html
3892 #author
3893
3894 String : http://dolce-forum.info,www.dolce-forum.info
3895
3896[ Script ]
3897 This plugin detects instances of script HTML elements and
3898 returns the script language/type.
3899
3900 String : text/javascript
3901
3902[ nginx ]
3903 Nginx (Engine-X) is a free, open-source, high-performance
3904 HTTP server and reverse proxy, as well as an IMAP/POP3
3905 proxy server.
3906
3907 Version : 1.10.2
3908 Website : http://nginx.net/
3909
3910HTTP Headers:
3911 HTTP/1.1 200 OK
3912 Server: nginx/1.10.2
3913 Date: Sun, 10 Sep 2017 04:20:17 GMT
3914 Content-Type: text/html
3915 Content-Length: 7901
3916 Connection: close
3917 Accept-Ranges: bytes
3918 Vary: Accept-Encoding,User-Agent
3919 Content-Encoding: gzip
3920
3921
3922
3923
3924[+] Hosts found in search engines:
3925------------------------------------
3926[-] Resolving hostnames IPs...
3927176.114.5.138:www.dolce-forum.info
3928
3929
3930
3931 ^ ^
3932 _ __ _ ____ _ __ _ _ ____
3933 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
3934 | V V // o // _/ | V V // 0 // 0 // _/
3935 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
3936 <
3937 ...'
3938
3939 WAFW00F - Web Application Firewall Detection Tool
3940
3941 By Sandro Gauci && Wendel G. Henrique
3942
3943Checking http://dolce-forum.info
3944Generic Detection results:
3945No WAF detected by the generic detection
3946Number of requests: 13
3947
3948
3949DNS Servers for dolce-forum.info:
3950 ns3.geoscaling.com
3951 ns2.geoscaling.com
3952 ns1.geoscaling.com
3953 ns5.geoscaling.com
3954
3955Trying zone transfer first...
3956 Testing ns3.geoscaling.com
3957 Request timed out or transfer not allowed.
3958 Testing ns2.geoscaling.com
3959 Request timed out or transfer not allowed.
3960 Testing ns1.geoscaling.com
3961 Request timed out or transfer not allowed.
3962 Testing ns5.geoscaling.com
3963 Request timed out or transfer not allowed.
3964
3965Unsuccessful in zone transfer (it was worth a shot)
3966Okay, trying the good old fashioned way... brute force
3967
3968Checking for wildcard DNS...
3969Nope. Good.
3970Now performing 2280 test(s)...
3971176.114.5.138 www.dolce-forum.info
3972
3973Subnets found (may want to probe here using nmap or unicornscan):
3974 176.114.5.0-255 : 1 hostnames found.
3975
3976Done with Fierce scan: http://ha.ckers.org/fierce/
3977Found 1 entries.
3978
3979Have a nice day.
3980
3981
3982
3983lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
3984 Written by Stefan Behte (http://ge.mine.nu)
3985 Proof-of-concept! Might give false positives.
3986
3987Checking for DNS-Loadbalancing: NOT FOUND
3988Checking for HTTP-Loadbalancing [Server]:
3989 nginx/1.10.2
3990 NOT FOUND
3991
3992Checking for HTTP-Loadbalancing [Date]: 04:28:55, 04:28:55, 04:28:55, 04:28:56, 04:28:56, 04:28:57, 04:28:57, 04:28:58, 04:28:58, 04:28:58, 04:28:59, 04:28:59, 04:29:00, 04:29:00, 04:29:00, 04:29:01, 04:29:01, 04:29:02, 04:29:02, 04:29:02, 04:29:03, 04:29:03, 04:29:04, 04:29:04, 04:29:05, 04:29:05, 04:29:05, 04:29:06, 04:29:06, 04:29:07, 04:29:07, 04:29:08, 04:29:08, 04:29:09, 04:29:09, 04:29:10, 04:29:10, 04:29:10, 04:29:11, 04:29:11, 04:29:12, 04:29:12, 04:29:13, 04:29:13, 04:29:13, 04:29:14, 04:29:14, 04:29:15, 04:29:15, 04:29:15, NOT FOUND
3993
3994Checking for HTTP-Loadbalancing [Diff]: FOUND
3995< Date: Sun, 10 Sep 2017 04:29:09 GMT
3996< Content-Type: text/html
3997< Connection: close
3998< Accept-Ranges: bytes
3999< Vary: Accept-Encoding,User-Agent
4000<
4001< HTTP/1.1 200 OK
4002< Server: nginx/1.10.2
4003< Date: Sun, 10 Sep 2017 04:29:09 GMT
4004< Content-Type: text/html
4005< Connection: close
4006< Accept-Ranges: bytes
4007< Vary: Accept-Encoding,User-Agent
4008<
4009< HTTP/1.1 200 OK
4010< Server: nginx/1.10.2
4011< Date: Sun, 10 Sep 2017 04:29:10 GMT
4012< Content-Type: text/html
4013< Connection: close
4014< Accept-Ranges: bytes
4015< Vary: Accept-Encoding,User-Agent
4016<
4017< HTTP/1.1 200 OK
4018< Server: nginx/1.10.2
4019< Date: Sun, 10 Sep 2017 04:29:10 GMT
4020< Content-Type: text/html
4021< Connection: close
4022< Accept-Ranges: bytes
4023< Vary: Accept-Encoding,User-Agent
4024<
4025< HTTP/1.1 200 OK
4026< Server: nginx/1.10.2
4027< Date: Sun, 10 Sep 2017 04:29:10 GMT
4028< Content-Type: text/html
4029< Connection: close
4030< Accept-Ranges: bytes
4031< Vary: Accept-Encoding,User-Agent
4032<
4033< HTTP/1.1 200 OK
4034< Server: nginx/1.10.2
4035< Date: Sun, 10 Sep 2017 04:29:11 GMT
4036< Content-Type: text/html
4037< Connection: close
4038< Accept-Ranges: bytes
4039< Vary: Accept-Encoding,User-Agent
4040<
4041< HTTP/1.1 200 OK
4042< Server: nginx/1.10.2
4043< Date: Sun, 10 Sep 2017 04:29:11 GMT
4044< Content-Type: text/html
4045< Connection: close
4046< Accept-Ranges: bytes
4047< Vary: Accept-Encoding,User-Agent
4048<
4049< HTTP/1.1 200 OK
4050< Server: nginx/1.10.2
4051< Date: Sun, 10 Sep 2017 04:29:12 GMT
4052< Content-Type: text/html
4053< Connection: close
4054< Accept-Ranges: bytes
4055< Vary: Accept-Encoding,User-Agent
4056<
4057< HTTP/1.1 200 OK
4058< Server: nginx/1.10.2
4059< Date: Sun, 10 Sep 2017 04:29:12 GMT
4060< Content-Type: text/html
4061< Connection: close
4062< Accept-Ranges: bytes
4063< Vary: Accept-Encoding,User-Agent
4064<
4065< HTTP/1.1 200 OK
4066< Server: nginx/1.10.2
4067< Date: Sun, 10 Sep 2017 04:29:12 GMT
4068< Content-Type: text/html
4069< Connection: close
4070< Accept-Ranges: bytes
4071< Vary: Accept-Encoding,User-Agent
4072<
4073< HTTP/1.1 200 OK
4074< Server: nginx/1.10.2
4075< Date: Sun, 10 Sep 2017 04:29:13 GMT
4076< Content-Type: text/html
4077< Connection: close
4078< Accept-Ranges: bytes
4079< Vary: Accept-Encoding,User-Agent
4080<
4081< HTTP/1.1 200 OK
4082< Server: nginx/1.10.2
4083< Date: Sun, 10 Sep 2017 04:29:13 GMT
4084< Content-Type: text/html
4085< Connection: close
4086< Accept-Ranges: bytes
4087< Vary: Accept-Encoding,User-Agent
4088<
4089< HTTP/1.1 200 OK
4090< Server: nginx/1.10.2
4091< Date: Sun, 10 Sep 2017 04:29:14 GMT
4092< Content-Type: text/html
4093< Connection: close
4094< Accept-Ranges: bytes
4095< Vary: Accept-Encoding,User-Agent
4096<
4097< HTTP/1.1 200 OK
4098< Server: nginx/1.10.2
4099< Date: Sun, 10 Sep 2017 04:29:14 GMT
4100< Content-Type: text/html
4101< Connection: close
4102< Accept-Ranges: bytes
4103< Vary: Accept-Encoding,User-Agent
4104<
4105< HTTP/1.1 200 OK
4106< Server: nginx/1.10.2
4107< Date: Sun, 10 Sep 2017 04:29:15 GMT
4108< Content-Type: text/html
4109< Connection: close
4110< Accept-Ranges: bytes
4111< Vary: Accept-Encoding,User-Agent
4112<
4113< HTTP/1.1 200 OK
4114< Server: nginx/1.10.2
4115< Date: Sun, 10 Sep 2017 04:29:15 GMT
4116< Content-Type: text/html
4117< Connection: close
4118< Accept-Ranges: bytes
4119< Vary: Accept-Encoding,User-Agent
4120<
4121< HTTP/1.1 200 OK
4122< Server: nginx/1.10.2
4123< Date: Sun, 10 Sep 2017 04:29:15 GMT
4124< Content-Type: text/html
4125< Connection: close
4126< Accept-Ranges: bytes
4127< Vary: Accept-Encoding,User-Agent
4128<
4129< HTTP/1.1 200 OK
4130< Server: nginx/1.10.2
4131< Date: Sun, 10 Sep 2017 04:29:16 GMT
4132
4133dolce-forum.info does Load-balancing. Found via Methods: HTTP[Diff]
4134
4135
4136
4137Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
4138
4139 ----------------------------------------------------------
4140| Scan Information |
4141 ----------------------------------------------------------
4142
4143Mode ..................... VRFY
4144Worker Processes ......... 5
4145Usernames file ........... users.txt
4146Target count ............. 1
4147Username count ........... 494
4148Target TCP port .......... 25
4149Query timeout ............ 5 secs
4150Target domain ............
4151
4152######## Scan started at Sun Sep 10 00:29:16 2017 #########
4153######## Scan completed at Sun Sep 10 00:37:31 2017 #########
41540 results.
4155
4156494 queries in 495 seconds (1.0 queries / sec)
4157
4158
4159
4160Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:37 EDT
4161NSE: Loaded 146 scripts for scanning.
4162NSE: Script Pre-scanning.
4163Initiating NSE at 00:37
4164Completed NSE at 00:37, 0.00s elapsed
4165Initiating NSE at 00:37
4166Completed NSE at 00:37, 0.00s elapsed
4167Failed to resolve "dolce-forum.info.txt".
4168Initiating Parallel DNS resolution of 1 host. at 00:37
4169Completed Parallel DNS resolution of 1 host. at 00:37, 0.87s elapsed
4170Initiating SYN Stealth Scan at 00:37
4171Scanning dolce-forum.info (176.114.5.138) [100 ports]
4172Discovered open port 111/tcp on 176.114.5.138
4173Discovered open port 80/tcp on 176.114.5.138
4174Discovered open port 22/tcp on 176.114.5.138
4175Completed SYN Stealth Scan at 00:37, 5.75s elapsed (100 total ports)
4176Initiating Service scan at 00:37
4177Scanning 3 services on dolce-forum.info (176.114.5.138)
4178Completed Service scan at 00:37, 6.46s elapsed (3 services on 1 host)
4179Initiating OS detection (try #1) against dolce-forum.info (176.114.5.138)
4180Retrying OS detection (try #2) against dolce-forum.info (176.114.5.138)
4181Initiating Traceroute at 00:38
4182Completed Traceroute at 00:38, 3.03s elapsed
4183Initiating Parallel DNS resolution of 9 hosts. at 00:38
4184Completed Parallel DNS resolution of 9 hosts. at 00:38, 5.80s elapsed
4185NSE: Script scanning 176.114.5.138.
4186Initiating NSE at 00:38
4187Completed NSE at 00:38, 17.52s elapsed
4188Initiating NSE at 00:38
4189Completed NSE at 00:38, 0.31s elapsed
4190Nmap scan report for dolce-forum.info (176.114.5.138)
4191Host is up (0.22s latency).
4192rDNS record for 176.114.5.138: myserver.org
4193Not shown: 90 closed ports
4194PORT STATE SERVICE VERSION
419522/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
4196| ssh-hostkey:
4197| 2048 ce:2f:35:6c:4b:09:dd:5d:5e:b0:68:98:78:a2:65:0b (RSA)
4198| 256 f3:f4:05:37:96:9f:1a:8f:31:5d:18:69:f8:35:f7:a7 (ECDSA)
4199|_ 256 6a:f4:e1:4d:5e:9f:93:e3:e5:2f:cb:13:91:00:f6:ae (EdDSA)
420025/tcp filtered smtp
420153/tcp filtered domain
420280/tcp open http nginx 1.10.2
4203|_http-title: Site doesn't have a title (text/html).
4204111/tcp open rpcbind 2-4 (RPC #100000)
4205135/tcp filtered msrpc
4206139/tcp filtered netbios-ssn
4207445/tcp filtered microsoft-ds
4208465/tcp filtered smtps
4209587/tcp filtered submission
4210Aggressive OS guesses: Linux 3.10 - 3.12 (94%), Linux 4.4 (94%), Linux 3.10 (92%), Linux 4.0 (91%), Linux 2.6.39 (91%), Linux 3.11 - 4.1 (91%), Linux 2.6.32 (91%), Linux 2.6.32 or 3.10 (91%), Linux 3.4 (91%), Synology DiskStation Manager 5.1 (91%)
4211No exact OS matches for host (test conditions non-ideal).
4212Uptime guess: 24.814 days (since Wed Aug 16 05:06:16 2017)
4213Network Distance: 10 hops
4214TCP Sequence Prediction: Difficulty=258 (Good luck!)
4215IP ID Sequence Generation: All zeros
4216
4217TRACEROUTE (using port 8888/tcp)
4218HOP RTT ADDRESS
42191 201.38 ms 10.13.0.1
42202 210.35 ms 37.187.24.252
42213 206.08 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
42224 ...
42235 213.82 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
42246 219.85 ms be100-1166.var-5-a9.pl.eu (91.121.215.191)
42257 225.84 ms vl2.var-6-a72.pl.eu (91.121.215.209)
42268 236.35 ms dtel-ix-2.maximuma.net (193.25.180.159)
42279 231.84 ms gw.thehost.com.ua (91.196.149.36)
422810 239.65 ms myserver.org (176.114.5.138)
4229
4230NSE: Script Post-scanning.
4231Initiating NSE at 00:38
4232Completed NSE at 00:38, 0.00s elapsed
4233Initiating NSE at 00:38
4234Completed NSE at 00:38, 0.00s elapsed
4235Read data files from: /usr/bin/../share/nmap
4236OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4237Nmap done: 1 IP address (1 host up) scanned in 56.74 seconds
4238 Raw packets sent: 296 (15.942KB) | Rcvd: 299 (32.122KB)
4239
4240
4241Error: can not open nmap file: dolce-forum.info.txt
4242
4243
4244httprint v0.301 (beta) - web server fingerprinting tool
4245(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
4246http://net-square.com/httprint/
4247httprint@net-square.com
4248
4249Finger Printing on http://dolce-forum.info:80/
4250Finger Printing Completed on http://dolce-forum.info:80/
4251--------------------------------------------------
4252Host: dolce-forum.info
4253Fingerprinting Error: Host/URL not found...
4254
4255--------------------------------------------------
4256
4257
4258
4259
4260 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
4261 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4262 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
4263 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4264 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
4265
4266 _/ User-Agent Tester ↵
4267 _/ AKA: Purple Pimp ↵
4268 _/ ChrisJohnRiley ↵
4269 _/ blog.c22.cc ↵
4270
4271 [>] Performing initial request and confirming stability
4272 [>] Using User-Agent string Mozilla/5.0
4273
4274 [ ] URL (ENTERED): http://dolce-forum.info
4275 [ ] Response Code: 200 OK
4276 [ ] Server: nginx/1.10.2
4277 [ ] Date: Sun, 10 Sep 2017 04:38:34 GMT
4278 [ ] Content-Type: text/html
4279 [ ] Transfer-Encoding: chunked
4280 [ ] Connection: close
4281 [ ] Accept-Ranges: bytes
4282 [ ] Vary: Accept-Encoding,User-Agent
4283 [ ] Data (MD5): 73cf931a325a4ff262eb3a96d0ee49b5
4284
4285 [1] Pass
4286 [2] Pass
4287 [3] Pass
4288
4289 [>] URL appears stable. Beginning test
4290
4291 [>] Using DEFAULT User-Agent Strings
4292
4293 [>] Using Crazy User-Agent Strings
4294 [>] Using Bot User-Agent Strings
4295
4296 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
4297
4298
4299 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
4300
4301
4302 [!] Data (MD5): 622eb84d479fda7d0db197c3865f3315
4303
4304
4305 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
4306
4307
4308 [!] Data (MD5): 23537ad9ae0e8c5c30d0b6b82a957f04
4309
4310
4311 [>] User-Agent String : TrackBack/1.02
4312
4313
4314 [!] Data (MD5): af5dcc8f6a50155904b8ec050bf840f0
4315
4316
4317 [>] User-Agent String : wispr
4318
4319
4320 [!] Data (MD5): 6624932e3a4aaefdd68ca9e065fa981c
4321
4322
4323 [>] User-Agent String : EMPTY USER-AGENT STRING!
4324
4325
4326 [!] Data (MD5): a3d5c78234425ad795a6f0d50db144e6
4327
4328
4329 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
4330
4331
4332 [!] Data (MD5): 4f90fd4fb4733d5fc765b443438a53d1
4333
4334
4335 [>] User-Agent String : Googlebot-Image/1.0
4336
4337
4338 [!] Data (MD5): b4cdf4ad63f15d7fb2028bd23f361c1f
4339
4340
4341 [>] User-Agent String : Mediapartners-Google
4342
4343
4344 [!] Data (MD5): fe3420a421f884ccccab4c45fc492c9a
4345
4346
4347 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
4348
4349
4350 [!] Data (MD5): dc6a73ee6800f719718efa6fba1d461a
4351
4352
4353 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
4354
4355
4356 [!] Data (MD5): ce85abbe30f1720beb4d73f13be8ba56
4357
4358
4359 [>] User-Agent String : mmcrawler
4360
4361
4362 [!] Data (MD5): f8ca9f3fd85ffa66f5378139d52a8605
4363
4364
4365 [>] Checks completed... try enabling VERBOSE mode for more detailed output
4366
4367 [>] That's all folks... Fo' Shizzle!
4368
4369#######################################################################################
4370Hostname www.paradise-4u.info ISP FOP Sedinkin Olexandr Valeriyovuch (AS56485)
4371Continent Europe Flag
4372UA
4373Country Ukraine Country Code UA (UKR)
4374Region Unknown Local time 10 Sep 2017 07:16 EEST
4375City Unknown Latitude 50.45
4376IP Address 176.114.5.138 Longitude 30.523
4377#########################################################################################
4378paradise-4u.info
4379
4380###########################################################################################
4381
4382whois paradise-4u.info
4383Domain Name: PARADISE-4U.INFO
4384Registry Domain ID: D26601502-LRMS
4385Registrar WHOIS Server:
4386Registrar URL: http://www.joker.com
4387Updated Date: 2017-09-06T16:26:46Z
4388Creation Date: 2008-10-16T00:24:36Z
4389Registry Expiry Date: 2018-10-16T00:24:36Z
4390Registrar Registration Expiration Date:
4391Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
4392Registrar IANA ID: 113
4393Registrar Abuse Contact Email:
4394Registrar Abuse Contact Phone:
4395Reseller:
4396Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4397Domain Status: renewPeriod https://icann.org/epp#renewPeriod
4398Registry Registrant ID: C54428490-LRMS
4399Registrant Name: Alicia Daniel
4400Registrant Organization: Alicia Daniel
4401Registrant Street: 2370 1ST AVE
4402Registrant Street: 2370 1ST AVE
4403Registrant City: NEW YORK
4404Registrant State/Province: NY
4405Registrant Postal Code: 10035
4406Registrant Country: US
4407Registrant Phone: +646.3719637
4408Registrant Phone Ext:
4409Registrant Fax: +646.3719637
4410Registrant Fax Ext:
4411Registrant Email: aliciadan824@aol.com
4412Registry Admin ID: C54428480-LRMS
4413Admin Name: Alicia Daniel
4414Admin Organization: Alicia Daniel
4415Admin Street: 2370 1ST AVE
4416Admin Street: 2370 1ST AVE
4417Admin City: NEW YORK
4418Admin State/Province: NY
4419Admin Postal Code: 10035
4420Admin Country: US
4421Admin Phone: +646.3719637
4422Admin Phone Ext:
4423Admin Fax: +646.3719637
4424Admin Fax Ext:
4425Admin Email: aliciadan824@aol.com
4426Registry Tech ID: C54428480-LRMS
4427Tech Name: Alicia Daniel
4428Tech Organization: Alicia Daniel
4429Tech Street: 2370 1ST AVE
4430Tech Street: 2370 1ST AVE
4431Tech City: NEW YORK
4432Tech State/Province: NY
4433Tech Postal Code: 10035
4434Tech Country: US
4435Tech Phone: +646.3719637
4436Tech Phone Ext:
4437Tech Fax: +646.3719637
4438Tech Fax Ext:
4439Tech Email: aliciadan824@aol.com
4440Registry Billing ID: C54428480-LRMS
4441Billing Name: Alicia Daniel
4442Billing Organization: Alicia Daniel
4443Billing Street: 2370 1ST AVE
4444Billing Street: 2370 1ST AVE
4445Billing City: NEW YORK
4446Billing State/Province: NY
4447Billing Postal Code: 10035
4448Billing Country: US
4449Billing Phone: +646.3719637
4450Billing Phone Ext:
4451Billing Fax: +646.3719637
4452Billing Fax Ext:
4453Billing Email: aliciadan824@aol.com
4454Name Server: NS1.GEOSCALING.COM
4455Name Server: NS2.GEOSCALING.COM
4456Name Server: NS3.GEOSCALING.COM
4457Name Server: NS4.GEOSCALING.COM
4458
4459###########################################################################################
4460
4461;paradise-4u.info. IN ANY
4462
4463;; ANSWER SECTION:
4464paradise-4u.info. 300 IN A 176.114.5.138
4465paradise-4u.info. 7200 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
4466paradise-4u.info. 7200 IN NS ns5.geoscaling.com.
4467paradise-4u.info. 7200 IN NS ns3.geoscaling.com.
4468paradise-4u.info. 7200 IN NS ns2.geoscaling.com.
4469paradise-4u.info. 7200 IN NS ns1.geoscaling.com.
4470
4471;; Query time: 114 msec
4472;; SERVER: 192.168.1.254#53(192.168.1.254)
4473;; WHEN: Sun Sep 10 00:17:10 EDT 2017
4474;; MSG SIZE rcvd: 191
4475
4476###########################################################################################
4477
4478###########################################################################################
4479
4480nmap -PN -n -F -T4 -sV -A -oG temp.txt paradise-4u.info
4481
4482Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:21 EDT
4483Nmap scan report for paradise-4u.info (176.114.5.138)
4484Host is up (0.58s latency).
4485Not shown: 90 closed ports
4486PORT STATE SERVICE VERSION
448722/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
4488| ssh-hostkey:
4489| 2048 ce:2f:35:6c:4b:09:dd:5d:5e:b0:68:98:78:a2:65:0b (RSA)
4490| 256 f3:f4:05:37:96:9f:1a:8f:31:5d:18:69:f8:35:f7:a7 (ECDSA)
4491|_ 256 6a:f4:e1:4d:5e:9f:93:e3:e5:2f:cb:13:91:00:f6:ae (EdDSA)
449225/tcp filtered smtp
449353/tcp filtered domain
449480/tcp open http nginx 1.10.2
4495|_http-generator: CuteHTML
4496|_http-server-header: nginx/1.10.2
4497|_http-title: NN Magazine - Your Guide to the World of Preteen Modeling !
4498111/tcp open rpcbind 2-4 (RPC #100000)
4499| rpcinfo:
4500| program version port/proto service
4501| 100000 2,3,4 111/tcp rpcbind
4502|_ 100000 2,3,4 111/udp rpcbind
4503135/tcp filtered msrpc
4504139/tcp filtered netbios-ssn
4505445/tcp filtered microsoft-ds
4506465/tcp filtered smtps
4507587/tcp filtered submission
4508Aggressive OS guesses: Linux 4.4 (94%), Linux 3.10 - 3.12 (94%), Linux 4.0 (92%), Linux 3.11 - 4.1 (91%), Linux 3.10 (91%), Linux 2.6.32 (91%), Linux 3.5 (91%), Linux 4.2 (91%), Synology DiskStation Manager 5.1 (91%), WatchGuard Fireware 11.8 (91%)
4509No exact OS matches for host (test conditions non-ideal).
4510Network Distance: 10 hops
4511
4512TRACEROUTE (using port 1720/tcp)
4513HOP RTT ADDRESS
45141 893.70 ms 10.13.0.1
45152 902.69 ms 37.187.24.252
45163 898.44 ms 178.33.103.229
45174 ...
45185 906.20 ms 213.186.32.213
45196 912.16 ms 213.251.128.114
45207 947.70 ms 193.25.180.159
45218 922.91 ms 193.25.180.159
45229 918.21 ms 91.196.149.36
452310 947.82 ms 176.114.5.138
4524
4525Protocol on 176.114.5.138:80/tcp matches http
4526Protocol on 176.114.5.138:22/tcp matches ssh
4527Protocol on 176.114.5.138:22/tcp matches ssh-openssh
4528Protocol on 176.114.5.138:111/tcp matches rpc
4529Protocol on 176.114.5.138:111/tcp matches rpc-rpcbind-v4
4530
4531
4532inetnum: 176.114.0.0 - 176.114.15.255
4533netname: THEHOST-NETWORK-3
4534country: UA
4535org: ORG-FSOV1-RIPE
4536admin-c: SA7501-RIPE
4537tech-c: SA7501-RIPE
4538status: ASSIGNED PI
4539mnt-by: RIPE-NCC-END-MNT
4540mnt-by: THEHOST-MNT
4541mnt-routes: THEHOST-MNT
4542mnt-domains: THEHOST-MNT
4543created: 2012-04-10T13:34:51Z
4544last-modified: 2017-05-11T09:51:38Z
4545source: RIPE
4546sponsoring-org: ORG-ML410-RIPE
4547
4548organisation: ORG-FSOV1-RIPE
4549org-name: FOP Sedinkin Olexandr Valeriyovuch
4550org-type: other
4551address: 08154, Ukraine, Boyarka, Belogorodskaya str., 11a
4552abuse-c: AR19055-RIPE
4553abuse-mailbox: abuse@thehost.ua
4554remarks: -----------------------------------------------------
4555remarks: Hosting Provider TheHost
4556remarks: -----------------------------------------------------
4557remarks: For abuse/spam issues contact abuse@thehost.ua
4558remarks: For general/sales questions contact info@thehost.ua
4559remarks: For technical support contact support@thehost.ua
4560remarks: -----------------------------------------------------
4561phone: +380 44 222-9-888
4562phone: +7 499 403-36-28
4563fax-no: +380 44 222-9-888 ext. 4
4564admin-c: SA7501-RIPE
4565mnt-ref: THEHOST-MNT
4566mnt-by: THEHOST-MNT
4567created: 2011-03-01T10:48:14Z
4568last-modified: 2015-11-29T21:16:15Z
4569source: RIPE # Filtered
4570
4571person: Sedinkin Alexander
4572address: Ukraine, Boyarka, Belogorodskaya str., 11a
4573phone: +380 44 222-9-888 ext. 213
4574address: UKRAINE
4575nic-hdl: SA7501-RIPE
4576mnt-by: THEHOST-MNT
4577created: 2011-03-01T10:36:18Z
4578last-modified: 2017-05-03T11:09:44Z
4579source: RIPE # Filtered
4580
4581% Information related to '176.114.4.0/22AS56485'
4582
4583route: 176.114.4.0/22
4584descr: FOP Sedinkin Olexandr Valeriyovuch
4585origin: AS56485
4586mnt-by: THEHOST-MNT
4587created: 2014-04-26T22:56:24Z
4588last-modified: 2014-04-26T22:56:24Z
4589source: RIPE
4590
4591% This query was served by the RIPE Database Query Service version 1.89.2 (BLAARKOP)
4592
4593
4594###########################################################################################
4595[i] Scanning Site: http://paradise-4u.info
4596
4597
4598
4599B A S I C I N F O
4600====================
4601
4602
4603[+] Site Title: NN Magazine - Your Guide to the World of Preteen Modeling !
4604[+] IP address: 176.114.5.138
4605[+] Web Server: nginx/1.10.2
4606[+] CMS: Could Not Detect
4607[+] Cloudflare: Not Detected
4608[+] Robots File: Could NOT Find robots.txt!
4609
4610
4611
4612
4613W H O I S L O O K U P
4614========================
4615
4616 Domain Name: PARADISE-4U.INFO
4617Registry Domain ID: D26601502-LRMS
4618Registrar WHOIS Server:
4619Registrar URL: http://www.joker.com
4620Updated Date: 2017-09-06T16:26:46Z
4621Creation Date: 2008-10-16T00:24:36Z
4622Registry Expiry Date: 2018-10-16T00:24:36Z
4623Registrar Registration Expiration Date:
4624Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
4625Registrar IANA ID: 113
4626Registrar Abuse Contact Email:
4627Registrar Abuse Contact Phone:
4628Reseller:
4629Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4630Domain Status: renewPeriod https://icann.org/epp#renewPeriod
4631Registry Registrant ID: C54428490-LRMS
4632Registrant Name: Alicia Daniel
4633Registrant Organization: Alicia Daniel
4634Registrant Street: 2370 1ST AVE
4635Registrant Street: 2370 1ST AVE
4636Registrant City: NEW YORK
4637Registrant State/Province: NY
4638Registrant Postal Code: 10035
4639Registrant Country: US
4640Registrant Phone: +646.3719637
4641Registrant Phone Ext:
4642Registrant Fax: +646.3719637
4643Registrant Fax Ext:
4644Registrant Email: aliciadan824@aol.com
4645Registry Admin ID: C54428480-LRMS
4646Admin Name: Alicia Daniel
4647Admin Organization: Alicia Daniel
4648Admin Street: 2370 1ST AVE
4649Admin Street: 2370 1ST AVE
4650Admin City: NEW YORK
4651Admin State/Province: NY
4652Admin Postal Code: 10035
4653Admin Country: US
4654Admin Phone: +646.3719637
4655Admin Phone Ext:
4656Admin Fax: +646.3719637
4657Admin Fax Ext:
4658Admin Email: aliciadan824@aol.com
4659Registry Tech ID: C54428480-LRMS
4660Tech Name: Alicia Daniel
4661Tech Organization: Alicia Daniel
4662Tech Street: 2370 1ST AVE
4663Tech Street: 2370 1ST AVE
4664Tech City: NEW YORK
4665Tech State/Province: NY
4666Tech Postal Code: 10035
4667Tech Country: US
4668Tech Phone: +646.3719637
4669Tech Phone Ext:
4670Tech Fax: +646.3719637
4671Tech Fax Ext:
4672Tech Email: aliciadan824@aol.com
4673Registry Billing ID: C54428480-LRMS
4674Billing Name: Alicia Daniel
4675Billing Organization: Alicia Daniel
4676Billing Street: 2370 1ST AVE
4677Billing Street: 2370 1ST AVE
4678Billing City: NEW YORK
4679Billing State/Province: NY
4680Billing Postal Code: 10035
4681Billing Country: US
4682Billing Phone: +646.3719637
4683Billing Phone Ext:
4684Billing Fax: +646.3719637
4685Billing Fax Ext:
4686Billing Email: aliciadan824@aol.com
4687Name Server: NS1.GEOSCALING.COM
4688Name Server: NS2.GEOSCALING.COM
4689Name Server: NS3.GEOSCALING.COM
4690Name Server: NS4.GEOSCALING.COM
4691
4692
4693G E O I P L O O K U P
4694=========================
4695
4696[i] IP Address: 176.114.5.138
4697[i] Country: UA
4698[i] State: N/A
4699[i] City: N/A
4700[i] Latitude: 50.450001
4701[i] Longitude: 30.523300
4702
4703
4704
4705
4706H T T P H E A D E R S
4707=======================
4708
4709
4710[i] HTTP/1.1 200 OK
4711[i] Server: nginx/1.10.2
4712[i] Date: Sun, 10 Sep 2017 04:18:31 GMT
4713[i] Content-Type: text/html
4714[i] Connection: close
4715[i] Accept-Ranges: bytes
4716[i] Vary: Accept-Encoding,User-Agent
4717
4718
4719
4720
4721D N S L O O K U P
4722===================
4723
4724paradise-4u.info. 286 IN A 176.114.5.138
4725paradise-4u.info. 7200 IN NS ns2.geoscaling.com.
4726paradise-4u.info. 7200 IN NS ns3.geoscaling.com.
4727paradise-4u.info. 7200 IN NS ns1.geoscaling.com.
4728paradise-4u.info. 7200 IN NS ns5.geoscaling.com.
4729paradise-4u.info. 7200 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
4730
4731
4732
4733
4734S U B N E T C A L C U L A T I O N
4735====================================
4736
4737Address = 176.114.5.138
4738Network = 176.114.5.138 / 32
4739Netmask = 255.255.255.255
4740Broadcast = not needed on Point-to-Point links
4741Wildcard Mask = 0.0.0.0
4742Hosts Bits = 0
4743Max. Hosts = 1 (2^0 - 0)
4744Host Range = { 176.114.5.138 - 176.114.5.138 }
4745
4746
4747
4748N M A P P O R T S C A N
4749============================
4750
4751
4752Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 04:18 UTC
4753Nmap scan report for paradise-4u.info (176.114.5.138)
4754Host is up (0.12s latency).
4755rDNS record for 176.114.5.138: myserver.org
4756PORT STATE SERVICE VERSION
475721/tcp closed ftp
475822/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
475923/tcp closed telnet
476025/tcp closed smtp
476180/tcp open http nginx 1.10.2
4762110/tcp closed pop3
4763143/tcp closed imap
4764443/tcp closed https
4765445/tcp filtered microsoft-ds
47663389/tcp closed ms-wbt-server
4767
4768Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4769Nmap done: 1 IP address (1 host up) scanned in 8.44 seconds
4770
4771
4772
4773S U B - D O M A I N F I N D E R
4774==================================
4775
4776
4777[i] Total Subdomains Found : 1
4778
4779[+] Subdomain: paradise-4u.info
4780[-] IP: 176.114.5.138
4781
4782
4783
4784
4785
4786R E V E R S E I P L O O K U P
4787==================================
4788
4789
4790[i] Total Sites Found On This Server : 1
4791
4792
4793[#] paradise-4u.info,
4794[-] CMS: Could Not Detect
4795[*] Performing TLD Brute force Enumeration against paradise-4u.info
4796[*] The operation could take up to: 00:01:07
4797[*] A paradise-4u.biz.af 5.45.75.45
4798[*] CNAME paradise-4u.biz.at free.biz.at
4799[*] A free.biz.at 216.92.134.29
4800[*] A paradise-4u.co.asia 91.195.240.135
4801[*] A paradise-4u.org.aw 142.4.20.12
4802[*] A paradise-4u.co.ba 176.9.45.78
4803[*] A paradise-4u.com.ba 195.222.33.180
4804[*] A paradise-4u.com.be 95.173.170.166
4805[*] A paradise-4u.biz.by 71.18.52.2
4806[*] A paradise-4u.biz.bz 199.59.242.150
4807[*] A paradise-4u.com.cc 54.252.107.64
4808[*] A paradise-4u.net.cc 54.252.89.206
4809[*] A paradise-4u.co.cc 175.126.123.219
4810[*] A paradise-4u.org.ch 72.52.4.122
4811[*] A paradise-4u.co.cm 85.25.140.105
4812[*] A paradise-4u.net.cm 85.25.140.105
4813[*] A paradise-4u.biz.cl 185.53.178.8
4814[*] CNAME paradise-4u.biz.cm i.cns.cm
4815[*] A i.cns.cm 118.184.56.30
4816[*] A paradise-4u.com.com 52.33.196.199
4817[*] A paradise-4u.net.com 199.59.242.150
4818[*] A paradise-4u.org.com 23.23.86.44
4819[*] A paradise-4u.co.com 173.192.115.17
4820[*] A paradise-4u.biz.cr 72.52.4.122
4821[*] A paradise-4u.biz.cx 72.52.4.122
4822[*] A paradise-4u.com.cz 62.109.128.30
4823[*] A paradise-4u.biz.cz 185.53.179.7
4824[*] A paradise-4u.net.cz 80.250.24.177
4825[*] CNAME paradise-4u.co.de co.de
4826[*] A co.de 144.76.162.245
4827[*] CNAME paradise-4u.org.de www.org.de
4828[*] A www.org.de 78.47.128.8
4829[*] A paradise-4u.com.de 50.56.68.37
4830[*] A paradise-4u.net.eu 78.46.90.98
4831[*] A paradise-4u.org.eu 78.46.90.98
4832[*] A paradise-4u.biz.fi 185.55.85.123
4833[*] A paradise-4u.fm 173.230.131.38
4834[*] A paradise-4u.biz.fm 173.230.131.38
4835[*] A paradise-4u.org.fr 149.202.133.35
4836[*] A paradise-4u.biz.gl 72.52.4.122
4837[*] CNAME paradise-4u.co.gp co.gp
4838[*] A co.gp 144.76.162.245
4839[*] A paradise-4u.co.hn 208.100.40.203
4840[*] CNAME paradise-4u.net.hr net.hr
4841[*] A net.hr 192.0.78.24
4842[*] A net.hr 192.0.78.25
4843[*] A paradise-4u.co.ht 72.52.4.122
4844[*] CNAME paradise-4u.biz.hn parkmydomain.vhostgo.com
4845[*] A parkmydomain.vhostgo.com 107.186.245.118
4846[*] A paradise-4u.info 176.114.5.138
4847[*] A paradise-4u.co.jobs 50.17.193.222
4848[*] A paradise-4u.com.jobs 50.19.241.165
4849[*] A paradise-4u.net.jobs 50.19.241.165
4850[*] A paradise-4u.biz.jobs 50.19.241.165
4851[*] A paradise-4u.org.jobs 50.19.241.165
4852[*] A paradise-4u.biz.ky 199.184.144.27
4853[*] CNAME paradise-4u.biz.li 712936.parkingcrew.net
4854[*] A 712936.parkingcrew.net 185.53.179.29
4855[*] A paradise-4u.biz.lu 195.26.5.2
4856[*] A paradise-4u.biz.ly 64.136.20.39
4857[*] A paradise-4u.biz.md 72.52.4.122
4858[*] A paradise-4u.co.mk 87.76.31.211
4859[*] A paradise-4u.co.mobi 54.225.105.179
4860[*] A paradise-4u.biz.my 202.190.174.44
4861[*] A paradise-4u.co.net 188.166.216.219
4862[*] A paradise-4u.net.net 52.50.81.210
4863[*] A paradise-4u.org.net 23.23.86.44
4864[*] A paradise-4u.com.nl 83.98.157.102
4865[*] A paradise-4u.net.nl 83.98.157.102
4866[*] A paradise-4u.co.nl 37.97.184.204
4867[*] A paradise-4u.co.nr 208.100.40.202
4868[*] CNAME paradise-4u.co.nu co.nu
4869[*] A co.nu 144.76.162.245
4870[*] CNAME paradise-4u.com.nu com.nu
4871[*] A com.nu 144.76.162.245
4872[*] A paradise-4u.net.nu 199.102.76.78
4873[*] A paradise-4u.org.nu 80.92.84.139
4874[*] CNAME paradise-4u.net.org pewtrusts.org
4875[*] A pewtrusts.org 204.74.99.100
4876[*] A paradise-4u.com.org 23.23.86.44
4877[*] A paradise-4u.ph 45.79.222.138
4878[*] A paradise-4u.co.ph 45.79.222.138
4879[*] A paradise-4u.com.ph 45.79.222.138
4880[*] A paradise-4u.net.ph 45.79.222.138
4881[*] A paradise-4u.org.ph 45.79.222.138
4882[*] A paradise-4u.co.pl 212.91.6.55
4883[*] A paradise-4u.org.pm 208.73.210.202
4884[*] A paradise-4u.org.pm 208.73.211.165
4885[*] A paradise-4u.org.pm 208.73.211.177
4886[*] A paradise-4u.org.pm 208.73.210.217
4887[*] A paradise-4u.co.ps 66.96.132.56
4888[*] CNAME paradise-4u.biz.ps biz.ps
4889[*] A biz.ps 144.76.162.245
4890[*] A paradise-4u.co.pt 194.107.127.52
4891[*] A paradise-4u.pw 141.8.226.58
4892[*] A paradise-4u.co.pw 141.8.226.59
4893[*] A paradise-4u.net.pw 141.8.226.59
4894[*] A paradise-4u.biz.pw 141.8.226.59
4895[*] A paradise-4u.org.pw 141.8.226.59
4896[*] CNAME paradise-4u.co.ro now.co.ro
4897[*] A now.co.ro 185.27.255.9
4898[*] A paradise-4u.net.ro 69.64.52.127
4899[*] A paradise-4u.org.re 217.70.184.38
4900[*] A paradise-4u.com.ru 178.210.89.119
4901[*] A paradise-4u.biz.se 185.53.179.6
4902[*] CNAME paradise-4u.net.se 773147.parkingcrew.net
4903[*] A 773147.parkingcrew.net 185.53.179.29
4904[*] A paradise-4u.co.sl 91.195.240.135
4905[*] A paradise-4u.com.sr 143.95.106.249
4906[*] A paradise-4u.biz.st 91.121.28.115
4907[*] A paradise-4u.co.su 72.52.4.122
4908[*] A paradise-4u.biz.tc 64.136.20.39
4909[*] A paradise-4u.net.tf 188.40.70.29
4910[*] A paradise-4u.net.tf 188.40.117.12
4911[*] A paradise-4u.net.tf 188.40.70.27
4912[*] A paradise-4u.co.tl 208.100.40.202
4913[*] A paradise-4u.biz.tf 85.236.153.18
4914[*] A paradise-4u.co.to 175.118.124.44
4915[*] A paradise-4u.co.tv 31.186.25.163
4916[*] A paradise-4u.biz.tv 72.52.4.122
4917[*] A paradise-4u.org.tv 72.52.4.122
4918[*] CNAME paradise-4u.biz.uz biz.uz
4919[*] A biz.uz 144.76.162.245
4920[*] A paradise-4u.vg 88.198.29.97
4921[*] A paradise-4u.co.vg 88.198.29.97
4922[*] A paradise-4u.com.vg 88.198.29.97
4923[*] A paradise-4u.net.vg 68.178.254.180
4924[*] A paradise-4u.biz.vg 89.31.143.20
4925[*] A paradise-4u.ws 64.70.19.203
4926[*] A paradise-4u.com.ws 202.4.48.211
4927[*] A paradise-4u.biz.ws 184.168.221.104
4928[*] A paradise-4u.net.ws 202.4.48.211
4929[*] A paradise-4u.org.ws 202.4.48.211
4930<Domain Name: PARADISE-4U.INFO
4931Registry Domain ID: D26601502-LRMS
4932Registrar WHOIS Server:
4933Registrar URL: http://www.joker.com
4934Updated Date: 2017-09-06T16:26:46Z
4935Creation Date: 2008-10-16T00:24:36Z
4936Registry Expiry Date: 2018-10-16T00:24:36Z
4937Registrar Registration Expiration Date:
4938Registrar: CSL Computer Service Langenbach GmbH d/b/a joker.com
4939Registrar IANA ID: 113
4940Registrar Abuse Contact Email:
4941Registrar Abuse Contact Phone:
4942Reseller:
4943Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4944Domain Status: renewPeriod https://icann.org/epp#renewPeriod
4945Registry Registrant ID: C54428490-LRMS
4946Registrant Name: Alicia Daniel
4947Registrant Organization: Alicia Daniel
4948Registrant Street: 2370 1ST AVE
4949Registrant Street: 2370 1ST AVE
4950Registrant City: NEW YORK
4951Registrant State/Province: NY
4952Registrant Postal Code: 10035
4953Registrant Country: US
4954Registrant Phone: +646.3719637
4955Registrant Phone Ext:
4956Registrant Fax: +646.3719637
4957Registrant Fax Ext:
4958Registrant Email: aliciadan824@aol.com
4959Registry Admin ID: C54428480-LRMS
4960Admin Name: Alicia Daniel
4961Admin Organization: Alicia Daniel
4962Admin Street: 2370 1ST AVE
4963Admin Street: 2370 1ST AVE
4964Admin City: NEW YORK
4965Admin State/Province: NY
4966Admin Postal Code: 10035
4967Admin Country: US
4968Admin Phone: +646.3719637
4969Admin Phone Ext:
4970Admin Fax: +646.3719637
4971Admin Fax Ext:
4972Admin Email: aliciadan824@aol.com
4973Registry Tech ID: C54428480-LRMS
4974Tech Name: Alicia Daniel
4975Tech Organization: Alicia Daniel
4976Tech Street: 2370 1ST AVE
4977Tech Street: 2370 1ST AVE
4978Tech City: NEW YORK
4979Tech State/Province: NY
4980Tech Postal Code: 10035
4981Tech Country: US
4982Tech Phone: +646.3719637
4983Tech Phone Ext:
4984Tech Fax: +646.3719637
4985Tech Fax Ext:
4986Tech Email: aliciadan824@aol.com
4987Registry Billing ID: C54428480-LRMS
4988Billing Name: Alicia Daniel
4989Billing Organization: Alicia Daniel
4990Billing Street: 2370 1ST AVE
4991Billing Street: 2370 1ST AVE
4992Billing City: NEW YORK
4993Billing State/Province: NY
4994Billing Postal Code: 10035
4995Billing Country: US
4996Billing Phone: +646.3719637
4997Billing Phone Ext:
4998Billing Fax: +646.3719637
4999Billing Fax Ext:
5000Billing Email: aliciadan824@aol.com
5001Name Server: NS1.GEOSCALING.COM
5002Name Server: NS2.GEOSCALING.COM
5003Name Server: NS3.GEOSCALING.COM
5004Name Server: NS4.GEOSCALING.COM
5005
5006;paradise-4u.info. IN ANY
5007
5008;; ANSWER SECTION:
5009paradise-4u.info. 233 IN A 176.114.5.138
5010paradise-4u.info. 7133 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
5011paradise-4u.info. 7133 IN NS ns3.geoscaling.com.
5012paradise-4u.info. 7133 IN NS ns2.geoscaling.com.
5013paradise-4u.info. 7133 IN NS ns1.geoscaling.com.
5014paradise-4u.info. 7133 IN NS ns5.geoscaling.com.
5015
5016----- paradise-4u.info -----
5017
5018
5019Host's addresses:
5020__________________
5021
5022paradise-4u.info. 228 IN A 176.114.5.138
5023
5024
5025Name Servers:
5026______________
5027
5028ns2.geoscaling.com. 105 IN A 91.121.64.153
5029ns5.geoscaling.com. 105 IN A 91.121.64.153
5030ns1.geoscaling.com. 105 IN A 91.121.64.153
5031ns3.geoscaling.com. 105 IN A 91.121.64.153
5032
5033
5034
5035Brute forcing with dns.txt:
5036____________________________
5037
5038www.paradise-4u.info. 85 IN A 176.114.5.138
5039
5040Tracing to paradise-4u.info[a] via 192.168.1.254, maximum of 3 retries
5041192.168.1.254 (192.168.1.254)
5042 |\___ ns5.geoscaling.com [paradise-4u.info] (91.121.64.153) Got authoritative answer
5043 |\___ ns1.geoscaling.com [paradise-4u.info] (91.121.64.153) (cached)
5044 |\___ ns3.geoscaling.com [paradise-4u.info] (91.121.64.153) (cached)
5045 \___ ns2.geoscaling.com [paradise-4u.info] (91.121.64.153) (cached)
5046
5047
5048WhatWeb report for http://paradise-4u.info
5049Status : 200 OK
5050Title : NN Magazine - Your Guide to the World of Preteen Modeling !
5051IP : 176.114.5.138
5052Country : UKRAINE, UA
5053
5054Summary : MetaGenerator[CuteHTML], HTTPServer[nginx/1.10.2], nginx[1.10.2], Script[text/javascript]
5055
5056Detected Plugins:
5057[ HTTPServer ]
5058 HTTP server header string. This plugin also attempts to
5059 identify the operating system from the server header.
5060
5061 String : nginx/1.10.2 (from server string)
5062
5063[ MetaGenerator ]
5064 This plugin identifies meta generator tags and extracts its
5065 value.
5066
5067 String : CuteHTML
5068
5069[ Script ]
5070 This plugin detects instances of script HTML elements and
5071 returns the script language/type.
5072
5073 String : text/javascript
5074
5075[ nginx ]
5076 Nginx (Engine-X) is a free, open-source, high-performance
5077 HTTP server and reverse proxy, as well as an IMAP/POP3
5078 proxy server.
5079
5080 Version : 1.10.2
5081 Website : http://nginx.net/
5082
5083HTTP Headers:
5084 HTTP/1.1 200 OK
5085 Server: nginx/1.10.2
5086 Date: Sun, 10 Sep 2017 04:22:59 GMT
5087 Content-Type: text/html
5088 Content-Length: 5133
5089 Connection: close
5090 Accept-Ranges: bytes
5091 Vary: Accept-Encoding,User-Agent
5092 Content-Encoding: gzip
5093
5094
5095
5096[+] Hosts found in search engines:
5097------------------------------------
5098[-] Resolving hostnames IPs...
5099176.114.5.138:www.paradise-4u.info
5100
5101
5102
5103 ^ ^
5104 _ __ _ ____ _ __ _ _ ____
5105 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
5106 | V V // o // _/ | V V // 0 // 0 // _/
5107 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
5108 <
5109 ...'
5110
5111 WAFW00F - Web Application Firewall Detection Tool
5112
5113 By Sandro Gauci && Wendel G. Henrique
5114
5115Checking http://paradise-4u.info
5116Generic Detection results:
5117No WAF detected by the generic detection
5118Number of requests: 13
5119
5120
5121DNS Servers for paradise-4u.info:
5122 ns2.geoscaling.com
5123 ns3.geoscaling.com
5124 ns5.geoscaling.com
5125 ns1.geoscaling.com
5126
5127Trying zone transfer first...
5128 Testing ns2.geoscaling.com
5129 Request timed out or transfer not allowed.
5130 Testing ns3.geoscaling.com
5131 Request timed out or transfer not allowed.
5132 Testing ns5.geoscaling.com
5133 Request timed out or transfer not allowed.
5134 Testing ns1.geoscaling.com
5135 Request timed out or transfer not allowed.
5136
5137Unsuccessful in zone transfer (it was worth a shot)
5138Okay, trying the good old fashioned way... brute force
5139
5140Checking for wildcard DNS...
5141Nope. Good.
5142Now performing 2280 test(s)...
5143176.114.5.138 www.paradise-4u.info
5144
5145Subnets found (may want to probe here using nmap or unicornscan):
5146 176.114.5.0-255 : 1 hostnames found.
5147
5148Done with Fierce scan: http://ha.ckers.org/fierce/
5149Found 1 entries.
5150
5151Have a nice day.
5152
5153
5154
5155lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
5156 Written by Stefan Behte (http://ge.mine.nu)
5157 Proof-of-concept! Might give false positives.
5158
5159Checking for DNS-Loadbalancing: NOT FOUND
5160Checking for HTTP-Loadbalancing [Server]:
5161 nginx/1.10.2
5162grep: .nlog: Aucun fichier ou dossier de ce type
5163
5164cat: .nlog: Aucun fichier ou dossier de ce type
5165 nginx/1.10.2
5166 NOT FOUND
5167
5168Checking for HTTP-Loadbalancing [Date]: 04:29:30, 04:29:31, 04:29:31, 04:29:32, 04:29:32, 04:29:33, 04:29:34, 04:29:34, 04:29:34, 04:29:35, 04:29:35, 04:29:36, 04:29:36, 04:29:38, 04:29:38, 04:29:39, 04:29:39, 04:29:39, 04:29:40, 04:29:40, 04:29:41, 04:29:41, 04:29:41, 04:29:42, 04:29:42, 04:29:43, 04:29:43, 04:29:44, 04:29:44, 04:29:44, 04:29:45, 04:29:45, 04:29:46, 04:29:46, 04:29:46, 04:29:47, 04:29:47, 04:29:48, 04:29:48, 04:29:49, 04:29:49, 04:29:49, 04:29:50, 04:29:50, 04:29:51, 04:29:51, 04:29:51, 04:29:52, 04:29:52, 04:29:53, NOT FOUND
5169
5170Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
5171
5172paradise-4u.info does NOT use Load-balancing.
5173
5174
5175
5176Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
5177
5178 ----------------------------------------------------------
5179| Scan Information |
5180 ----------------------------------------------------------
5181
5182Mode ..................... VRFY
5183Worker Processes ......... 5
5184Usernames file ........... users.txt
5185Target count ............. 1
5186Username count ........... 494
5187Target TCP port .......... 25
5188Query timeout ............ 5 secs
5189Target domain ............
5190
5191######## Scan started at Sun Sep 10 00:30:14 2017 #########
5192######## Scan completed at Sun Sep 10 00:38:29 2017 #########
51930 results.
5194
5195494 queries in 495 seconds (1.0 queries / sec)
5196
5197
5198
5199Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:38 EDT
5200NSE: Loaded 146 scripts for scanning.
5201NSE: Script Pre-scanning.
5202Initiating NSE at 00:38
5203Completed NSE at 00:38, 0.00s elapsed
5204Initiating NSE at 00:38
5205Completed NSE at 00:38, 0.00s elapsed
5206Failed to resolve "paradise-4u.info.txt".
5207Initiating Parallel DNS resolution of 1 host. at 00:38
5208Completed Parallel DNS resolution of 1 host. at 00:38, 0.06s elapsed
5209Initiating SYN Stealth Scan at 00:38
5210Scanning paradise-4u.info (176.114.5.138) [100 ports]
5211Discovered open port 111/tcp on 176.114.5.138
5212Discovered open port 80/tcp on 176.114.5.138
5213Discovered open port 22/tcp on 176.114.5.138
5214Increasing send delay for 176.114.5.138 from 0 to 5 due to 50 out of 124 dropped probes since last increase.
5215Completed SYN Stealth Scan at 00:38, 12.52s elapsed (100 total ports)
5216Initiating Service scan at 00:38
5217Scanning 3 services on paradise-4u.info (176.114.5.138)
5218Completed Service scan at 00:38, 8.08s elapsed (3 services on 1 host)
5219Initiating OS detection (try #1) against paradise-4u.info (176.114.5.138)
5220Retrying OS detection (try #2) against paradise-4u.info (176.114.5.138)
5221adjust_timeouts2: packet supposedly had rtt of -335335 microseconds. Ignoring time.
5222adjust_timeouts2: packet supposedly had rtt of -335335 microseconds. Ignoring time.
5223Initiating Traceroute at 00:39
5224Completed Traceroute at 00:39, 2.75s elapsed
5225Initiating Parallel DNS resolution of 8 hosts. at 00:39
5226Completed Parallel DNS resolution of 8 hosts. at 00:39, 5.61s elapsed
5227NSE: Script scanning 176.114.5.138.
5228Initiating NSE at 00:39
5229Completed NSE at 00:40, 43.58s elapsed
5230Initiating NSE at 00:40
5231Completed NSE at 00:40, 2.86s elapsed
5232Nmap scan report for paradise-4u.info (176.114.5.138)
5233Host is up (0.72s latency).
5234rDNS record for 176.114.5.138: myserver.org
5235Not shown: 90 closed ports
5236PORT STATE SERVICE VERSION
523722/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
5238| ssh-hostkey:
5239| 2048 ce:2f:35:6c:4b:09:dd:5d:5e:b0:68:98:78:a2:65:0b (RSA)
5240| 256 f3:f4:05:37:96:9f:1a:8f:31:5d:18:69:f8:35:f7:a7 (ECDSA)
5241|_ 256 6a:f4:e1:4d:5e:9f:93:e3:e5:2f:cb:13:91:00:f6:ae (EdDSA)
524225/tcp filtered smtp
524353/tcp filtered domain
524480/tcp open http nginx 1.10.2
5245|_http-generator: CuteHTML
5246| http-methods:
5247|_ Supported Methods: GET HEAD POST OPTIONS
5248111/tcp open rpcbind
5249135/tcp filtered msrpc
5250139/tcp filtered netbios-ssn
5251445/tcp filtered microsoft-ds
5252465/tcp filtered smtps
5253587/tcp filtered submission
5254Aggressive OS guesses: Linux 3.10 - 3.12 (94%), Linux 4.4 (94%), Linux 4.0 (92%), Linux 3.11 - 4.1 (91%), Linux 3.10 (91%), Linux 2.6.32 (91%), Linux 3.4 (91%), Linux 3.5 (91%), Linux 4.2 (91%), Synology DiskStation Manager 5.1 (91%)
5255No exact OS matches for host (test conditions non-ideal).
5256Uptime guess: 24.815 days (since Wed Aug 16 05:06:15 2017)
5257Network Distance: 9 hops
5258TCP Sequence Prediction: Difficulty=262 (Good luck!)
5259IP ID Sequence Generation: All zeros
5260
5261TRACEROUTE (using port 3306/tcp)
5262HOP RTT ADDRESS
52631 693.67 ms 10.13.0.1
52642 702.90 ms 37.187.24.252
52653 698.43 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
52664 706.44 ms 10.95.33.8
52675 712.20 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
52686 718.23 ms be100-1102.var-5-a9.pl.eu (213.251.128.114)
52697 730.45 ms dtel-ix-2.maximuma.net (193.25.180.159)
52708 726.99 ms dtel-ix-2.maximuma.net (193.25.180.159)
52719 724.54 ms myserver.org (176.114.5.138)
5272
5273
5274
5275 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
5276 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5277 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
5278 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5279 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
5280
5281 _/ User-Agent Tester ↵
5282 _/ AKA: Purple Pimp ↵
5283 _/ ChrisJohnRiley ↵
5284 _/ blog.c22.cc ↵
5285
5286 [>] Performing initial request and confirming stability
5287 [>] Using User-Agent string Mozilla/5.0
5288
5289 [ ] URL (ENTERED): http://paradise-4u.info
5290 [ ] Response Code: 200 OK
5291 [ ] Server: nginx/1.10.2
5292 [ ] Date: Sun, 10 Sep 2017 04:40:26 GMT
5293 [ ] Content-Type: text/html
5294 [ ] Transfer-Encoding: chunked
5295 [ ] Connection: close
5296 [ ] Accept-Ranges: bytes
5297 [ ] Vary: Accept-Encoding,User-Agent
5298 [ ] Data (MD5): a2683911b1a703e646ed863aa48f5f2f
5299
5300 [1] Pass
5301 [2] Pass
5302 [3] Pass
5303
5304 [>] URL appears stable. Beginning test
5305
5306 [>] Using DEFAULT User-Agent Strings
5307
5308 [>] Using Crazy User-Agent Strings
5309 [>] Using Bot User-Agent Strings
5310
5311 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
5312
5313
5314 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
5315
5316
5317 [!] Data (MD5): 16e13290e213e6df4594dc7d9a7b44cd
5318
5319
5320 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
5321
5322
5323 [!] Data (MD5): 0138f135da4ebe22a7a0dd7267461688
5324
5325
5326 [>] User-Agent String : TrackBack/1.02
5327
5328
5329 [!] Data (MD5): 6963d7cf9a7013785305b177dd8af598
5330
5331
5332 [>] User-Agent String : wispr
5333
5334
5335 [!] Data (MD5): 5b01ffb1e5e4d3f99a14e58a90460870
5336
5337
5338 [>] User-Agent String : EMPTY USER-AGENT STRING!
5339
5340
5341 [!] Data (MD5): 07f541e6901286bac7575634d6afbad6
5342
5343
5344 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
5345
5346
5347 [!] Data (MD5): dd0ee60985394c4737f39ea71283659f
5348
5349
5350 [>] User-Agent String : Googlebot-Image/1.0
5351
5352
5353 [!] Data (MD5): cd4878affaf10f5e88800953921642ec
5354
5355
5356 [>] User-Agent String : Mediapartners-Google
5357
5358
5359 [!] Data (MD5): 5b072ce136a5d0b1b48d441479693b41
5360
5361
5362 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
5363
5364
5365 [!] Data (MD5): 1e23dd825a93a562aa496325bda94eb7
5366
5367
5368 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
5369
5370
5371 [!] Data (MD5): 231cc5a0a48a325604f59089cdd4f9a1
5372
5373
5374 [>] User-Agent String : mmcrawler
5375
5376
5377 [!] Data (MD5): d0a05778b90d8c72bcff2baa64c35787
5378
5379
5380 [>] Checks completed... try enabling VERBOSE mode for more detailed output
5381
5382 [>] That's all folks... Fo' Shizzle!
5383###############################################################################################
5384Hostname candydollchan.net ISP Lucky Net Ltd (AS3254)
5385Continent Europe Flag
5386UA
5387Country Ukraine Country Code UA (UKR)
5388Region Unknown Local time 10 Sep 2017 07:54 EEST
5389City Unknown Latitude 50.45
5390IP Address 91.219.29.120 Longitude 30.523
5391##########################################################################################
5392candydollchan.net
5393
5394###########################################################################################
5395
5396whois candydollchan.net
5397 Domain Name: CANDYDOLLCHAN.NET
5398 Registry Domain ID: 1987658926_DOMAIN_NET-VRSN
5399 Registrar WHOIS Server: whois.nic.ru
5400 Registrar URL: http://nic.ru
5401 Updated Date: 2016-11-28T12:47:05Z
5402 Creation Date: 2015-12-16T07:57:08Z
5403 Registry Expiry Date: 2017-12-16T07:57:08Z
5404 Registrar: Regional Network Information Center, JSC dba RU-CENTER
5405 Registrar IANA ID: 463
5406 Registrar Abuse Contact Email: tld-abuse@nic.ru
5407 Registrar Abuse Contact Phone: +7 (495) 994-46-01
5408 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5409 Name Server: NS1.EUROGLOBALHOST.COM
5410 Name Server: NS2.EUROGLOBALHOST.COM
5411
5412Domain Name: CANDYDOLLCHAN.NET
5413Registry Domain ID: 1987658926_DOMAIN_NET-VRSN
5414Registrar WHOIS Server: whois.nic.ru
5415Registrar URL: http://www.nic.ru
5416Creation Date: 2015-12-16T07:57:08Z
5417Registrar Registration Expiration Date: 2017-12-15T21:00:00Z
5418Registrar: Regional Network Information Center, JSC dba RU-CENTER
5419Registrar IANA ID: 463
5420Registrar Abuse Contact Email: tld-abuse@nic.ru
5421Registrar Abuse Contact Phone: +7.4959944601
5422Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5423Registry Registrant ID:
5424Registrant Name: Chaplenko Yuri
5425Registrant Organization: Chaplenko Yuri
5426Registrant Street: Karadzhicha st. 13-35
5427Registrant City: Lvov
5428Registrant State/Province: Lvovskaya
5429Registrant Postal Code: 79054
5430Registrant Country: UA
5431Registrant Phone: +380.672306256
5432Registrant Phone Ext:
5433Registrant Email: ychaplenko@inbox.ru
5434Registry Admin ID:
5435Admin Name: Chaplenko Yuri
5436Admin Organization: Chaplenko Yuri
5437Admin Street: Karadzhicha st. 13-35
5438Admin City: Lvov
5439Admin State/Province: Lvovskaya
5440Admin Postal Code: 79054
5441Admin Country: UA
5442Admin Phone: +380.672306256
5443Admin Phone Ext:
5444Admin Email: ychaplenko@inbox.ru
5445Registry Tech ID:
5446Tech Name: Chaplenko Yuri
5447Tech Organization: Chaplenko Yuri
5448Tech Street: Karadzhicha st. 13-35
5449Tech City: Lvov
5450Tech State/Province: Lvovskaya
5451Tech Postal Code: 79054
5452Tech Country: UA
5453Tech Phone: +380.672306256
5454Tech Phone Ext:
5455Tech Email: ychaplenko@inbox.ru
5456Name Server: ns1.euroglobalhost.com
5457Name Server: ns2.euroglobalhost.com
5458DNSSEC: unsigned
5459URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
5460For more information on Whois status codes, please visit: https://icann.org/epp
5461>>> Last update of WHOIS database: 2017.09.10T04:33:22Z <<<
5462###########################################################################################
5463
5464###########################################################################################
5465
5466nmap -PN -n -F -T4 -sV -A -oG temp.txt candydollchan.net
5467
5468Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:35 EDT
5469Nmap scan report for candydollchan.net (91.219.29.120)
5470Host is up (0.19s latency).
5471Not shown: 92 closed ports
5472PORT STATE SERVICE VERSION
547322/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
5474| ssh-hostkey:
5475| 2048 2b:d0:38:0e:ca:11:3f:76:6c:5b:84:c1:e6:f2:1b:6c (RSA)
5476| 256 2b:b6:42:1b:ac:af:99:36:a4:f0:7b:89:17:bb:ec:81 (ECDSA)
5477|_ 256 88:ff:8e:62:bc:e6:75:1c:c0:06:72:75:e6:c4:66:57 (EdDSA)
547825/tcp filtered smtp
547980/tcp open http nginx 1.10.2
5480|_http-server-header: nginx/1.10.2
5481|_http-title: Candydoll Downloads - Candydollchan
5482135/tcp filtered msrpc
5483139/tcp filtered netbios-ssn
5484445/tcp filtered microsoft-ds
5485465/tcp filtered smtps
5486587/tcp filtered submission
5487Aggressive OS guesses: Linux 4.4 (95%), Linux 3.10 - 3.12 (94%), Linux 4.0 (92%), Linux 3.11 - 4.1 (91%), Linux 2.6.32 (91%), Linux 2.6.32 or 3.10 (91%), Linux 3.5 (91%), Linux 4.2 (91%), Synology DiskStation Manager 5.1 (91%), WatchGuard Fireware 11.8 (91%)
5488No exact OS matches for host (test conditions non-ideal).
5489Network Distance: 12 hops
5490
5491TRACEROUTE (using port 995/tcp)
5492HOP RTT ADDRESS
54931 303.34 ms 10.13.0.1
54942 ...
54953 720.56 ms 178.33.103.229
54964 ...
54975 725.36 ms 213.186.32.211
54986 731.32 ms 91.121.215.191
54997 ...
55008 739.84 ms 87.245.233.213
55019 743.11 ms 87.245.237.118
550210 750.32 ms 195.177.68.94
550311 747.07 ms 193.193.193.45
550412 737.42 ms 91.219.29.120
5505
5506OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5507Nmap done: 1 IP address (1 host up) scanned in 60.55 seconds
5508
5509###########################################################################################
5510
5511amap -i temp.txt
5512amap v5.4 (www.thc.org/thc-amap) started at 2017-09-10 00:36:00 - APPLICATION MAPPING mode
5513
5514Protocol on 91.219.29.120:80/tcp matches http
5515Protocol on 91.219.29.120:22/tcp matches ssh
5516Protocol on 91.219.29.120:22/tcp matches ssh-openssh
5517Protocol on 91.219.29.120:80/tcp matches http-apache-2
5518
5519inetnum: 91.219.28.0 - 91.219.31.255
5520netname: UKRSERVERS-NET
5521country: UA
5522org: ORG-FKAV1-RIPE
5523admin-c: KCH78-RIPE
5524tech-c: KCH78-RIPE
5525status: ASSIGNED PI
5526mnt-by: RIPE-NCC-END-MNT
5527mnt-by: UADOMEN-MNT
5528mnt-routes: UADOMEN-MNT
5529mnt-routes: DATAHARBOUR-MNT
5530mnt-domains: UADOMEN-MNT
5531created: 2010-09-06T11:31:55Z
5532last-modified: 2017-01-31T08:48:17Z
5533source: RIPE
5534sponsoring-org: ORG-SL452-RIPE
5535
5536organisation: ORG-FKAV1-RIPE
5537org-name: FLP Kochenov Aleksej Vladislavovich
5538org-type: OTHER
5539address: 38, Danilevskogo Str., Kharkov
5540address: Kharkov, Ukraine
5541phone: +38.0443039163
5542fax-no: +38.0577209170
5543abuse-c: AR18187-RIPE
5544admin-c: KCH78-RIPE
5545tech-c: KCH78-RIPE
5546mnt-ref: UADOMEN-MNT
5547mnt-ref: SINARO
5548abuse-mailbox: hostmaster@uadomen.com
5549mnt-by: UADOMEN-MNT
5550created: 2009-02-13T16:33:48Z
5551last-modified: 2017-01-20T20:50:23Z
5552source: RIPE # Filtered
5553
5554person: Aleksej V. Kochenov
5555address: 8, Donvar Zapolskogo Str.,
5556address: Kiev, Ukraine
5557phone: +38.0443039163
5558fax-no: +38.0577209170
5559nic-hdl: KCH78-RIPE
5560abuse-mailbox: support@uadomen.com
5561mnt-by: UADOMEN-MNT
5562created: 2009-02-13T13:13:18Z
5563last-modified: 2015-05-28T18:26:23Z
5564source: RIPE # Filtered
5565
5566% Information related to '91.219.29.0/24AS3254'
5567
5568route: 91.219.29.0/24
5569descr: AGGREGATE BLOCK FOR LuckyNet Datacenter
5570origin: AS3254
5571mnt-by: AS3254-MNT
5572created: 2011-03-23T09:12:24Z
5573last-modified: 2011-03-23T09:12:24Z
5574source: RIPE
5575
5576% This query was served by the RIPE Database Query Service version 1.89.2 (BLAARKOP)
5577
5578###########################################################################################
5579[i] Scanning Site: http://candydollchan.net
5580
5581
5582
5583B A S I C I N F O
5584====================
5585
5586
5587[+] Site Title: Candydoll Downloads - Candydollchan
5588[+] IP address: 91.219.29.120
5589[+] Web Server: nginx/1.10.2
5590[+] CMS: Could Not Detect
5591[+] Cloudflare: Not Detected
5592[+] Robots File: Found
5593
5594-------------[ contents ]----------------
5595User-agent: *
5596Disallow:
5597Host: candydollchan.net
5598Sitemap: http://candydollchan.net/sitemap.xml
5599-----------[end of contents]-------------
5600
5601
5602
5603W H O I S L O O K U P
5604========================
5605
5606 Domain Name: CANDYDOLLCHAN.NET
5607 Registry Domain ID: 1987658926_DOMAIN_NET-VRSN
5608 Registrar WHOIS Server: whois.nic.ru
5609 Registrar URL: http://nic.ru
5610 Updated Date: 2016-11-28T12:47:05Z
5611 Creation Date: 2015-12-16T07:57:08Z
5612 Registry Expiry Date: 2017-12-16T07:57:08Z
5613 Registrar: Regional Network Information Center, JSC dba RU-CENTER
5614 Registrar IANA ID: 463
5615 Registrar Abuse Contact Email: tld-abuse@nic.ru
5616 Registrar Abuse Contact Phone: +7 (495) 994-46-01
5617 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5618 Name Server: NS1.EUROGLOBALHOST.COM
5619 Name Server: NS2.EUROGLOBALHOST.COM
5620
5621
5622
5623
5624
5625G E O I P L O O K U P
5626=========================
5627
5628[i] IP Address: 91.219.29.120
5629[i] Country: UA
5630[i] State: N/A
5631[i] City: N/A
5632[i] Latitude: 50.450001
5633[i] Longitude: 30.523300
5634
5635
5636
5637
5638H T T P H E A D E R S
5639=======================
5640
5641
5642[i] HTTP/1.1 200 OK
5643[i] Server: nginx/1.10.2
5644[i] Date: Sun, 10 Sep 2017 04:33:22 GMT
5645[i] Content-Type: text/html
5646[i] Connection: close
5647[i] Accept-Ranges: bytes
5648[i] Vary: Accept-Encoding,User-Agent
5649
5650
5651
5652
5653D N S L O O K U P
5654===================
5655
5656candydollchan.net. 14394 IN A 91.219.29.120
5657candydollchan.net. 14400 IN NS ns2.euroglobalhost.com.
5658candydollchan.net. 14400 IN NS ns1.euroglobalhost.com.
5659candydollchan.net. 14400 IN SOA ns1.euroglobalhost.com. hostmaster.candydollchan.net. 2017031402 14400 3600 1209600 86400
5660candydollchan.net. 14400 IN MX 10 mail.candydollchan.net.
5661candydollchan.net. 14400 IN TXT "v=spf1 a mx ip4:80.82.64.110 ~all"
5662
5663
5664
5665
5666S U B N E T C A L C U L A T I O N
5667====================================
5668
5669Address = 91.219.29.120
5670Network = 91.219.29.120 / 32
5671Netmask = 255.255.255.255
5672Broadcast = not needed on Point-to-Point links
5673Wildcard Mask = 0.0.0.0
5674Hosts Bits = 0
5675Max. Hosts = 1 (2^0 - 0)
5676Host Range = { 91.219.29.120 - 91.219.29.120 }
5677
5678
5679
5680N M A P P O R T S C A N
5681============================
5682
5683
5684Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 04:34 UTC
5685Nmap scan report for candydollchan.net (91.219.29.120)
5686Host is up (0.46s latency).
5687rDNS record for 91.219.29.120: 120.29.219.91.colo.ukrservers.com
5688PORT STATE SERVICE VERSION
568921/tcp closed ftp
569022/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
569123/tcp closed telnet
569225/tcp closed smtp
569380/tcp open http nginx 1.10.2
5694110/tcp closed pop3
5695143/tcp closed imap
5696443/tcp closed https
5697445/tcp closed microsoft-ds
56983389/tcp closed ms-wbt-server
5699
5700Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5701Nmap done: 1 IP address (1 host up) scanned in 10.02 seconds
5702
5703[*] Performing TLD Brute force Enumeration against candydollchan.net
5704[*] The operation could take up to: 00:01:07
5705[*] A candydollchan.biz.af 5.45.75.45
5706[*] CNAME candydollchan.biz.at free.biz.at
5707[*] A free.biz.at 216.92.134.29
5708[*] A candydollchan.co.asia 91.195.240.135
5709[*] A candydollchan.org.aw 142.4.20.12
5710[*] A candydollchan.co.ba 176.9.45.78
5711[*] A candydollchan.com.ba 195.222.33.180
5712[*] A candydollchan.com.be 95.173.170.166
5713[*] A candydollchan.biz.by 71.18.52.2
5714[*] A candydollchan.biz.bz 199.59.242.150
5715[*] A candydollchan.net.cc 54.252.89.206
5716[*] A candydollchan.com.cc 54.252.107.64
5717[*] A candydollchan.co.cc 175.126.123.219
5718[*] A candydollchan.org.ch 72.52.4.122
5719[*] A candydollchan.co.cm 85.25.140.105
5720[*] A candydollchan.net.cm 85.25.140.105
5721[*] A candydollchan.biz.cl 185.53.178.8
5722[*] A candydollchan.com.com 52.33.196.199
5723[*] A candydollchan.net.com 199.59.242.150
5724[*] A candydollchan.co.com 173.192.115.17
5725[*] A candydollchan.com 162.210.196.168
5726[*] A candydollchan.org.com 23.23.86.44
5727[*] CNAME candydollchan.biz.cm i.cns.cm
5728[*] A i.cns.cm 118.184.56.30
5729[*] A candydollchan.biz.cr 72.52.4.122
5730[*] A candydollchan.biz.cx 72.52.4.122
5731[*] A candydollchan.net.cz 80.250.24.177
5732[*] A candydollchan.biz.cz 185.53.179.7
5733[*] A candydollchan.com.cz 62.109.128.30
5734[*] CNAME candydollchan.co.de co.de
5735[*] A co.de 144.76.162.245
5736[*] A candydollchan.com.de 50.56.68.37
5737[*] CNAME candydollchan.org.de www.org.de
5738[*] A www.org.de 78.47.128.8
5739[*] A candydollchan.net.eu 78.46.90.98
5740[*] A candydollchan.org.eu 78.46.90.98
5741[*] A candydollchan.biz.fi 185.55.85.123
5742[*] A candydollchan.fm 173.230.131.38
5743[*] A candydollchan.biz.fm 173.230.131.38
5744[*] A candydollchan.org.fr 149.202.133.35
5745[*] A candydollchan.biz.gl 72.52.4.122
5746[*] CNAME candydollchan.co.gp co.gp
5747[*] A co.gp 144.76.162.245
5748[*] A candydollchan.co.hn 208.100.40.203
5749[*] CNAME candydollchan.net.hr net.hr
5750[*] A net.hr 192.0.78.24
5751[*] A net.hr 192.0.78.25
5752[*] CNAME candydollchan.biz.hn parkmydomain.vhostgo.com
5753[*] A parkmydomain.vhostgo.com 107.186.245.118
5754[*] A candydollchan.co.ht 72.52.4.122
5755[*] A candydollchan.co.jobs 50.17.193.222
5756[*] A candydollchan.com.jobs 50.19.241.165
5757[*] A candydollchan.net.jobs 50.19.241.165
5758[*] A candydollchan.biz.jobs 50.19.241.165
5759[*] A candydollchan.org.jobs 50.19.241.165
5760[*] A candydollchan.biz.ky 199.184.144.27
5761[*] CNAME candydollchan.biz.li 712936.parkingcrew.net
5762[*] A 712936.parkingcrew.net 185.53.179.29
5763[*] A candydollchan.biz.lu 195.26.5.2
5764[*] A candydollchan.biz.ly 64.136.20.39
5765[*] A candydollchan.biz.md 72.52.4.122
5766[*] A candydollchan.co.mk 87.76.31.211
5767[*] A candydollchan.co.mobi 54.225.105.179
5768[*] A candydollchan.biz.my 202.190.174.44
5769[*] A candydollchan.net 91.219.29.120
5770[*] A candydollchan.co.net 188.166.216.219
5771[*] A candydollchan.net.net 52.50.81.210
5772[*] A candydollchan.org.net 23.23.86.44
5773[*] A candydollchan.com.nl 83.98.157.102
5774[*] A candydollchan.net.nl 83.98.157.102
5775[*] A candydollchan.co.nl 37.97.184.204
5776[*] A candydollchan.co.nr 208.100.40.202
5777[*] CNAME candydollchan.co.nu co.nu
5778[*] A co.nu 144.76.162.245
5779[*] CNAME candydollchan.com.nu com.nu
5780[*] A com.nu 144.76.162.245
5781[*] A candydollchan.org.nu 80.92.84.139
5782[*] A candydollchan.net.nu 199.102.76.78
5783[*] A candydollchan.org 104.18.42.230
5784[*] A candydollchan.org 104.18.43.230
5785[*] AAAA candydollchan.org 2400:cb00:2048:1::6812:2ae6
5786[*] AAAA candydollchan.org 2400:cb00:2048:1::6812:2be6
5787[*] A candydollchan.com.org 23.23.86.44
5788[*] CNAME candydollchan.net.org pewtrusts.org
5789[*] A pewtrusts.org 204.74.99.100
5790[*] A candydollchan.ph 45.79.222.138
5791[*] A candydollchan.co.ph 45.79.222.138
5792[*] A candydollchan.com.ph 45.79.222.138
5793[*] A candydollchan.net.ph 45.79.222.138
5794[*] A candydollchan.org.ph 45.79.222.138
5795[*] A candydollchan.co.pl 212.91.6.55
5796[*] A candydollchan.org.pm 208.73.210.217
5797[*] A candydollchan.org.pm 208.73.211.165
5798[*] A candydollchan.org.pm 208.73.210.202
5799[*] A candydollchan.org.pm 208.73.211.177
5800[*] A candydollchan.co.ps 66.96.132.56
5801[*] CNAME candydollchan.biz.ps biz.ps
5802[*] A biz.ps 144.76.162.245
5803[*] A candydollchan.co.pt 194.107.127.52
5804[*] A candydollchan.pw 141.8.226.58
5805[*] A candydollchan.co.pw 141.8.226.59
5806[*] A candydollchan.net.pw 141.8.226.59
5807[*] A candydollchan.biz.pw 141.8.226.59
5808[*] A candydollchan.org.pw 141.8.226.59
5809[*] CNAME candydollchan.co.ro now.co.ro
5810[*] A now.co.ro 185.27.255.9
5811[*] A candydollchan.net.ro 69.64.52.127
5812[*] A candydollchan.org.re 217.70.184.38
5813[*] A candydollchan.com.ru 178.210.89.119
5814[*] A candydollchan.biz.se 185.53.179.6
5815[*] CNAME candydollchan.net.se 773147.parkingcrew.net
5816[*] A 773147.parkingcrew.net 185.53.179.29
5817[*] A candydollchan.co.sl 91.195.240.135
5818[*] A candydollchan.com.sr 143.95.106.249
5819[*] A candydollchan.biz.st 91.121.28.115
5820[*] A candydollchan.co.su 72.52.4.122
5821[*] A candydollchan.biz.tc 64.136.20.39
5822[*] A candydollchan.biz.tf 85.236.153.18
5823[*] A candydollchan.net.tf 188.40.70.29
5824[*] A candydollchan.net.tf 188.40.117.12
5825[*] A candydollchan.net.tf 188.40.70.27
5826[*] A candydollchan.co.tl 208.100.40.202
5827[*] A candydollchan.co.to 175.118.124.44
5828[*] A candydollchan.co.tv 31.186.25.163
5829[*] A candydollchan.biz.tv 72.52.4.122
5830[*] A candydollchan.org.tv 72.52.4.122
5831[*] CNAME candydollchan.biz.uz biz.uz
5832[*] A biz.uz 144.76.162.245
5833[*] A candydollchan.vg 88.198.29.97
5834[*] A candydollchan.co.vg 88.198.29.97
5835[*] A candydollchan.com.vg 88.198.29.97
5836[*] A candydollchan.net.vg 68.178.254.180
5837[*] A candydollchan.biz.vg 89.31.143.20
5838[*] A candydollchan.com.ws 202.4.48.211
5839[*] A candydollchan.net.ws 202.4.48.211
5840[*] A candydollchan.biz.ws 184.168.221.104
5841[*] A candydollchan.org.ws 202.4.48.211
5842[*] A candydollchan.ws 64.70.19.203
5843
5844
5845S U B - D O M A I N F I N D E R
5846==================================
5847
5848
5849[i] Total Subdomains Found : 2
5850
5851[+] Subdomain: candydollchan.net
5852[-] IP: 91.219.29.120
5853
5854[+] Subdomain: mail.candydollchan.net
5855[-] IP: 80.82.64.193
5856
5857
5858
5859candydollchan.net
5860
5861
5862 Domain Name: CANDYDOLLCHAN.NET
5863 Registry Domain ID: 1987658926_DOMAIN_NET-VRSN
5864 Registrar WHOIS Server: whois.nic.ru
5865 Registrar URL: http://nic.ru
5866 Updated Date: 2016-11-28T12:47:05Z
5867 Creation Date: 2015-12-16T07:57:08Z
5868 Registry Expiry Date: 2017-12-16T07:57:08Z
5869 Registrar: Regional Network Information Center, JSC dba RU-CENTER
5870 Registrar IANA ID: 463
5871 Registrar Abuse Contact Email: tld-abuse@nic.ru
5872 Registrar Abuse Contact Phone: +7 (495) 994-46-01
5873 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5874 Name Server: NS1.EUROGLOBALHOST.COM
5875 Name Server: NS2.EUROGLOBALHOST.COM
5876
5877Domain Name: CANDYDOLLCHAN.NET
5878Registry Domain ID: 1987658926_DOMAIN_NET-VRSN
5879Registrar WHOIS Server: whois.nic.ru
5880Registrar URL: http://www.nic.ru
5881Creation Date: 2015-12-16T07:57:08Z
5882Registrar Registration Expiration Date: 2017-12-15T21:00:00Z
5883Registrar: Regional Network Information Center, JSC dba RU-CENTER
5884Registrar IANA ID: 463
5885Registrar Abuse Contact Email: tld-abuse@nic.ru
5886Registrar Abuse Contact Phone: +7.4959944601
5887Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5888Registry Registrant ID:
5889Registrant Name: Chaplenko Yuri
5890Registrant Organization: Chaplenko Yuri
5891Registrant Street: Karadzhicha st. 13-35
5892Registrant City: Lvov
5893Registrant State/Province: Lvovskaya
5894Registrant Postal Code: 79054
5895Registrant Country: UA
5896Registrant Phone: +380.672306256
5897Registrant Phone Ext:
5898Registrant Email: ychaplenko@inbox.ru
5899Registry Admin ID:
5900Admin Name: Chaplenko Yuri
5901Admin Organization: Chaplenko Yuri
5902Admin Street: Karadzhicha st. 13-35
5903Admin City: Lvov
5904Admin State/Province: Lvovskaya
5905Admin Postal Code: 79054
5906Admin Country: UA
5907Admin Phone: +380.672306256
5908Admin Phone Ext:
5909Admin Email: ychaplenko@inbox.ru
5910Registry Tech ID:
5911Tech Name: Chaplenko Yuri
5912Tech Organization: Chaplenko Yuri
5913Tech Street: Karadzhicha st. 13-35
5914Tech City: Lvov
5915Tech State/Province: Lvovskaya
5916Tech Postal Code: 79054
5917Tech Country: UA
5918Tech Phone: +380.672306256
5919Tech Phone Ext:
5920Tech Email: ychaplenko@inbox.ru
5921Name Server: ns1.euroglobalhost.com
5922Name Server: ns2.euroglobalhost.com
5923 IN ANY
5924
5925;; ANSWER SECTION:
5926candydollchan.net. 14331 IN MX 10 mail.candydollchan.net.
5927candydollchan.net. 14223 IN A 91.219.29.120
5928candydollchan.net. 14223 IN NS ns1.euroglobalhost.com.
5929candydollchan.net. 14223 IN NS ns2.euroglobalhost.com.
5930
5931----- candydollchan.net -----
5932
5933
5934Host's addresses:
5935__________________
5936
5937candydollchan.net. 14218 IN A 91.219.29.120
5938
5939
5940Name Servers:
5941______________
5942
5943
5944
5945Mail (MX) Servers:
5946___________________
5947
5948mail.candydollchan.net. 14400 IN A 80.82.64.193
5949
5950Brute forcing with dns.txt:
5951____________________________
5952
5953ftp.candydollchan.net. 14400 IN A 80.82.64.193
5954mail.candydollchan.net. 14378 IN A 80.82.64.193
5955pop.candydollchan.net. 14400 IN A 80.82.64.193
5956smtp.candydollchan.net. 14400 IN A 80.82.64.193
5957www.candydollchan.net. 14400 IN A 91.219.29.120
5958
5959candydollchan.net class C netranges:
5960_____________________________________
5961
5962 80.82.64.0/24
5963 91.219.29.0/24
5964
5965done.
5966
5967
5968dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
5969
5970[+] searching (sub)domains for candydollchan.net using built-in wordlist
5971[+] using maximum random delay of 10 millisecond(s) between requests
5972
5973ftp.candydollchan.net
5974IP address #1: 80.82.64.193
5975
5976localhost.candydollchan.net
5977IPv6 address #1: ::1
5978
5979localhost.candydollchan.net
5980IP address #1: 127.0.0.1
5981[+] warning: domain might be vulnerable to "same site" scripting (http://snipurl.com/etbcv)
5982
5983mail.candydollchan.net
5984IP address #1: 80.82.64.193
5985
5986pop.candydollchan.net
5987IP address #1: 80.82.64.193
5988
5989smtp.candydollchan.net
5990IP address #1: 80.82.64.193
5991
5992www.candydollchan.net
5993IP address #1: 91.219.29.120
5994
5995
5996WhatWeb report for http://candydollchan.net
5997Status : 200 OK
5998Title : Candydoll Downloads - Candydollchan
5999IP : 91.219.29.120
6000Country : UKRAINE, UA
6001
6002Summary : HTTPServer[nginx/1.10.2], nginx[1.10.2], Script[text/javascript], AddThis
6003
6004Detected Plugins:
6005[ AddThis ]
6006 AddThis is a free way to boost traffic back to your site by
6007 making it easier for visitors to share your content.
6008
6009 Website : http://www.addthis.com/
6010
6011[ HTTPServer ]
6012 HTTP server header string. This plugin also attempts to
6013 identify the operating system from the server header.
6014
6015 String : nginx/1.10.2 (from server string)
6016
6017[ Script ]
6018 This plugin detects instances of script HTML elements and
6019 returns the script language/type.
6020
6021 String : text/javascript
6022
6023[ nginx ]
6024 Nginx (Engine-X) is a free, open-source, high-performance
6025 HTTP server and reverse proxy, as well as an IMAP/POP3
6026 proxy server.
6027
6028 Version : 1.10.2
6029 Website : http://nginx.net/
6030
6031HTTP Headers:
6032 HTTP/1.1 200 OK
6033 Server: nginx/1.10.2
6034 Date: Sun, 10 Sep 2017 04:36:23 GMT
6035 Content-Type: text/html
6036 Content-Length: 10436
6037 Connection: close
6038 Accept-Ranges: bytes
6039 Vary: Accept-Encoding,User-Agent
6040 Content-Encoding: gzip
6041
6042
6043
6044
6045[+] Hosts found in search engines:
6046------------------------------------
6047[-] Resolving hostnames IPs...
604880.82.64.193:mail.candydollchan.net
604991.219.29.120:www.candydollchan.net
6050
6051
6052
6053 ^ ^
6054 _ __ _ ____ _ __ _ _ ____
6055 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
6056 | V V // o // _/ | V V // 0 // 0 // _/
6057 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
6058 <
6059 ...'
6060
6061 WAFW00F - Web Application Firewall Detection Tool
6062
6063 By Sandro Gauci && Wendel G. Henrique
6064
6065Checking http://candydollchan.net
6066ERROR:root:Site http://candydollchan.net appears to be down
6067
6068
6069DNS Servers for candydollchan.net:
6070 ns2.euroglobalhost.com
6071 ns1.euroglobalhost.com
6072
6073Trying zone transfer first...
6074unresolvable name: ns2.euroglobalhost.com at /usr/bin/fierce line 226.
6075 Testing ns2.euroglobalhost.com
6076 Request timed out or transfer not allowed.
6077unresolvable name: ns1.euroglobalhost.com at /usr/bin/fierce line 226.
6078 Testing ns1.euroglobalhost.com
6079 Request timed out or transfer not allowed.
6080unresolvable name: ns2.euroglobalhost.com at /usr/bin/fierce line 236.
6081unresolvable name: ns1.euroglobalhost.com at /usr/bin/fierce line 236.
6082
6083Unsuccessful in zone transfer (it was worth a shot)
6084Okay, trying the good old fashioned way... brute force
6085
6086Checking for wildcard DNS...
6087Nope. Good.
6088Now performing 2280 test(s)...
6089
6090Subnets found (may want to probe here using nmap or unicornscan):
6091
6092Done with Fierce scan: http://ha.ckers.org/fierce/
6093Found 0 entries.
6094
6095Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
6096
6097 ----------------------------------------------------------
6098| Scan Information |
6099 ----------------------------------------------------------
6100
6101Mode ..................... VRFY
6102Worker Processes ......... 5
6103Usernames file ........... users.txt
6104Target count ............. 1
6105Username count ........... 494
6106Target TCP port .......... 25
6107Query timeout ............ 5 secs
6108Target domain ............
6109
6110######## Scan started at Sun Sep 10 00:43:58 2017 #########
6111######## Scan completed at Sun Sep 10 00:52:13 2017 #########
61120 results.
6113
6114494 queries in 495 seconds (1.0 queries / sec)
6115
6116
6117
6118Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 00:52 EDT
6119NSE: Loaded 146 scripts for scanning.
6120NSE: Script Pre-scanning.
6121Initiating NSE at 00:52
6122Completed NSE at 00:52, 0.00s elapsed
6123Initiating NSE at 00:52
6124Completed NSE at 00:52, 0.00s elapsed
6125Failed to resolve "candydollchan.net.txt".
6126Initiating Parallel DNS resolution of 1 host. at 00:52
6127Completed Parallel DNS resolution of 1 host. at 00:52, 0.06s elapsed
6128Initiating SYN Stealth Scan at 00:52
6129Scanning candydollchan.net (91.219.29.120) [100 ports]
6130Discovered open port 22/tcp on 91.219.29.120
6131Discovered open port 80/tcp on 91.219.29.120
6132Completed SYN Stealth Scan at 00:52, 10.02s elapsed (100 total ports)
6133Initiating Service scan at 00:52
6134Scanning 2 services on candydollchan.net (91.219.29.120)
6135Completed Service scan at 00:52, 8.85s elapsed (2 services on 1 host)
6136Initiating OS detection (try #1) against candydollchan.net (91.219.29.120)
6137Retrying OS detection (try #2) against candydollchan.net (91.219.29.120)
6138Initiating Traceroute at 00:52
6139Completed Traceroute at 00:52, 3.14s elapsed
6140Initiating Parallel DNS resolution of 10 hosts. at 00:52
6141Completed Parallel DNS resolution of 10 hosts. at 00:52, 5.51s elapsed
6142NSE: Script scanning 91.219.29.120.
6143Initiating NSE at 00:52
6144Completed NSE at 00:53, 18.28s elapsed
6145Initiating NSE at 00:53
6146Completed NSE at 00:53, 0.00s elapsed
6147Nmap scan report for candydollchan.net (91.219.29.120)
6148Host is up (0.13s latency).
6149rDNS record for 91.219.29.120: 120.29.219.91.colo.ukrservers.com
6150Not shown: 92 closed ports
6151PORT STATE SERVICE VERSION
615222/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
6153| ssh-hostkey:
6154| 2048 2b:d0:38:0e:ca:11:3f:76:6c:5b:84:c1:e6:f2:1b:6c (RSA)
6155| 256 2b:b6:42:1b:ac:af:99:36:a4:f0:7b:89:17:bb:ec:81 (ECDSA)
6156|_ 256 88:ff:8e:62:bc:e6:75:1c:c0:06:72:75:e6:c4:66:57 (EdDSA)
615725/tcp filtered smtp
615880/tcp open http nginx 1.10.2
6159|_http-favicon: Unknown favicon MD5: D002D09E892B909EA8AF3007870FADAC
6160| http-methods:
6161|_ Supported Methods: OPTIONS GET HEAD POST
6162|_http-server-header: nginx/1.10.2
6163|_http-title: Candydoll Downloads - Candydollchan
6164135/tcp filtered msrpc
6165139/tcp filtered netbios-ssn
6166445/tcp filtered microsoft-ds
6167465/tcp filtered smtps
6168587/tcp filtered submission
6169Aggressive OS guesses: Linux 3.10 - 3.12 (95%), Linux 4.4 (95%), Linux 2.6.39 (92%), Linux 3.10 (92%), Linux 4.0 (91%), Linux 3.11 - 4.1 (91%), Linux 2.6.32 (91%), Linux 2.6.32 or 3.10 (91%), Linux 3.4 (91%), Linux 3.5 (91%)
6170No exact OS matches for host (test conditions non-ideal).
6171Uptime guess: 30.347 days (since Thu Aug 10 16:33:08 2017)
6172Network Distance: 12 hops
6173TCP Sequence Prediction: Difficulty=260 (Good luck!)
6174IP ID Sequence Generation: All zeros
6175
6176TRACEROUTE (using port 993/tcp)
6177HOP RTT ADDRESS
61781 109.82 ms 10.13.0.1
61792 ...
61803 110.73 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
61814 115.46 ms 10.95.33.8
61825 117.47 ms be100-1108.ams-1-a9.nl.eu (213.186.32.211)
61836 139.29 ms be100-1166.var-5-a9.pl.eu (91.121.215.191)
61847 ...
61858 152.47 ms ae0-1.RT1.NTL.KIV.UA.retn.net (87.245.233.213)
61869 152.75 ms GW-Fiberax.retn.net (87.245.237.118)
618710 152.74 ms 195.177.68.94
618811 152.97 ms runa.lucky.net (193.193.193.45)
618912 180.53 ms 120.29.219.91.colo.ukrservers.com (91.219.29.120)
6190
6191NSE: Script Post-scanning.
6192Initiating NSE at 00:53
6193Completed NSE at 00:53, 0.00s elapsed
6194Initiating NSE at 00:53
6195Completed NSE at 00:53, 0.00s elapsed
6196Read data files from: /usr/bin/../share/nmap
6197OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6198Nmap done: 1 IP address (1 host up) scanned in 53.49 seconds
6199 Raw packets sent: 311 (17.670KB) | Rcvd: 216 (28.974KB)
6200
6201
6202Error: can not open nmap file: candydollchan.net.txt
6203
6204
6205httprint v0.301 (beta) - web server fingerprinting tool
6206(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
6207http://net-square.com/httprint/
6208httprint@net-square.com
6209
6210Finger Printing on http://candydollchan.net:80/
6211Finger Printing Completed on http://candydollchan.net:80/
6212--------------------------------------------------
6213Host: candydollchan.net
6214Fingerprinting Error: Host/URL not found...
6215
6216--------------------------------------------------
6217
6218
6219
6220
6221 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
6222 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6223 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
6224 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6225 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
6226
6227 _/ User-Agent Tester ↵
6228 _/ AKA: Purple Pimp ↵
6229 _/ ChrisJohnRiley ↵
6230 _/ blog.c22.cc ↵
6231
6232 [>] Performing initial request and confirming stability
6233 [>] Using User-Agent string Mozilla/5.0
6234
6235 [ ] URL (ENTERED): http://candydollchan.net
6236 [ ] Response Code: 200 OK
6237 [ ] Server: nginx/1.10.2
6238 [ ] Date: Sun, 10 Sep 2017 04:51:42 GMT
6239 [ ] Content-Type: text/html
6240 [ ] Transfer-Encoding: chunked
6241 [ ] Connection: close
6242 [ ] Accept-Ranges: bytes
6243 [ ] Vary: Accept-Encoding,User-Agent
6244 [ ] Data (MD5): bcad1a9c3259a0b1f0dc1ba579073727
6245
6246 [1] Pass
6247 [2] Pass
6248 [3] Pass
6249
6250 [>] URL appears stable. Beginning test
6251
6252 [>] Using DEFAULT User-Agent Strings
6253
6254 [>] Using Crazy User-Agent Strings
6255 [>] Using Bot User-Agent Strings
6256
6257 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
6258
6259
6260 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
6261
6262
6263 [!] Data (MD5): bfb86163a0f3950d6d09e7fa2d01c4d9
6264
6265
6266 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
6267
6268
6269 [!] Data (MD5): 50883202accc64e1c77d5e9ff4c9e3c3
6270
6271
6272 [>] User-Agent String : TrackBack/1.02
6273
6274
6275 [!] Data (MD5): b82b43a091e003dc13e44c3fe2d0585c
6276
6277
6278 [>] User-Agent String : wispr
6279
6280
6281 [!] Data (MD5): 3679543d5e762e3294fca36078534d7f
6282
6283
6284 [>] User-Agent String : EMPTY USER-AGENT STRING!
6285
6286
6287 [!] Data (MD5): a52f6bf5e6969547841562123cf994b3
6288
6289
6290 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
6291
6292
6293 [!] Data (MD5): 4640b2e5e42e6420327d32bfc9625fce
6294
6295
6296 [>] User-Agent String : Googlebot-Image/1.0
6297
6298
6299 [!] Data (MD5): 553853d9ce3caa98835bf6bc5d81b2f1
6300
6301
6302 [>] User-Agent String : Mediapartners-Google
6303
6304
6305 [!] Data (MD5): 1ee33526fa6fcee77e0575b7d1764085
6306
6307
6308 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
6309
6310
6311 [!] Data (MD5): 3ec86ea5000f10f87a196d5c8af098ba
6312
6313
6314 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
6315
6316
6317 [!] Data (MD5): d0a4effa5c214ae59df46d312cbaf2d4
6318
6319
6320 [>] User-Agent String : mmcrawler
6321
6322
6323 [!] Data (MD5): 6d07d3b82245aba1dce688b970ba7cf9
6324
6325
6326 [>] Checks completed... try enabling VERBOSE mode for more detailed output
6327
6328 [>] That's all folks... Fo' Shizzle!
6329
6330##########################################################################################
6331Hostname www.dream-video.net ISP Mulgin Alexander Sergeevich (AS201094)
6332Continent Europe Flag
6333UA
6334Country Ukraine Country Code UA (UKR)
6335Region 04 Local time 10 Sep 2017 07:58 EEST
6336City Khmelnitskiy Latitude 47.728
6337IP Address 93.171.158.187 Longitude 34.137
6338#########################################################################################
6339dream-video.net
6340
6341###########################################################################################
6342
6343whois dream-video.net
6344 Domain Name: DREAM-VIDEO.NET
6345 Registry Domain ID: 1895999776_DOMAIN_NET-VRSN
6346 Registrar WHOIS Server: whois.nic.ru
6347 Registrar URL: http://nic.ru
6348 Updated Date: 2016-11-28T12:50:42Z
6349 Creation Date: 2015-01-15T10:59:57Z
6350 Registry Expiry Date: 2018-01-15T10:59:57Z
6351 Registrar: Regional Network Information Center, JSC dba RU-CENTER
6352 Registrar IANA ID: 463
6353 Registrar Abuse Contact Email: tld-abuse@nic.ru
6354 Registrar Abuse Contact Phone: +7 (495) 994-46-01
6355 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6356 Name Server: NS1.CLOUDNS.NET
6357 Name Server: NS1.FREEDNS.WS
6358 Name Server: NS2.CLOUDNS.NET
6359 Name Server: NS2.FREEDNS.WS
6360 Name Server: NS3.CLOUDNS.NET
6361 Name Server: NS4.CLOUDNS.NET
6362
6363Domain Name: DREAM-VIDEO.NET
6364Registry Domain ID: 1895999776_DOMAIN_NET-VRSN
6365Registrar WHOIS Server: whois.nic.ru
6366Registrar URL: http://www.nic.ru
6367Updated Date: 2015-01-16T16:05:32Z
6368Creation Date: 2015-01-15T10:59:58Z
6369Registrar Registration Expiration Date: 2018-01-14T21:00:00Z
6370Registrar: Regional Network Information Center, JSC dba RU-CENTER
6371Registrar IANA ID: 463
6372Registrar Abuse Contact Email: tld-abuse@nic.ru
6373Registrar Abuse Contact Phone: +7.4959944601
6374Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6375Registry Registrant ID:
6376Registrant Name: Bogdan Lubyanoy
6377Registrant Organization: Bogdan Lubyanoy
6378Registrant Street: Noginskaya st 41-5
6379Registrant City: Dnepropetrovsk
6380Registrant Postal Code: 49017
6381Registrant Country: UA
6382Registrant Phone: +380.503615560
6383Registrant Phone Ext:
6384Registrant Email: alubyanoy@inbox.ru
6385Registry Admin ID:
6386Admin Name: Bogdan Lubyanoy
6387Admin Organization: Bogdan Lubyanoy
6388Admin Street: Noginskaya st 41-5
6389Admin City: Dnepropetrovsk
6390Admin Postal Code: 49017
6391Admin Country: UA
6392Admin Phone: +380.503615560
6393Admin Phone Ext:
6394Admin Email: alubyanoy@inbox.ru
6395Registry Tech ID:
6396Tech Name: Bogdan Lubyanoy
6397Tech Organization: Bogdan Lubyanoy
6398Tech Street: Noginskaya st 41-5
6399Tech City: Dnepropetrovsk
6400Tech Postal Code: 49017
6401Tech Country: UA
6402Tech Phone: +380.503615560
6403Tech Phone Ext:
6404Tech Email: alubyanoy@inbox.ru
6405Name Server: ns1.cloudns.net
6406Name Server: ns1.freedns.ws
6407Name Server: ns2.cloudns.net
6408Name Server: ns2.freedns.ws
6409Name Server: ns3.cloudns.net
6410Name Server: ns4.cloudns.net
6411DNSSEC: unsigned
6412URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
6413For more information on Whois status codes, please visit: https://icann.org/epp
6414>>> Last update of WHOIS database: 2017.09.10T05:01:08Z <<<
6415###########################################################################################
6416
6417;dream-video.net. IN ANY
6418
6419;; ANSWER SECTION:
6420dream-video.net. 3581 IN A 93.171.158.187
6421dream-video.net. 3581 IN SOA ns1.cloudns.net. support.cloudns.net. 2016020602 7200 1800 1209600 3600
6422dream-video.net. 3581 IN NS ns1.cloudns.net.
6423dream-video.net. 3581 IN NS ns2.cloudns.net.
6424dream-video.net. 3581 IN NS ns4.cloudns.net.
6425dream-video.net. 3581 IN NS ns3.cloudns.net.
6426
6427###########################################################################################
6428
6429###########################################################################################
6430
6431tcptraceroute -i eth0 dream-video.net
6432
6433Running:
6434 traceroute -T -O info -i eth0 dream-video.net
6435traceroute to dream-video.net (93.171.158.187), 30 hops max, 60 byte packets
6436 1 gateway (192.168.1.254) 0.400 ms 0.582 ms 0.750 ms
6437 2 10.135.18.1 (10.135.18.1) 11.881 ms 20.254 ms 26.561 ms
6438 3 75.154.223.222 (75.154.223.222) 29.545 ms 29.601 ms 30.204 ms
6439 4 v704.core1.nyc4.he.net (209.51.184.241) 36.342 ms 36.424 ms 36.460 ms
6440 5 100ge4-1.core1.par2.he.net (184.105.81.78) 139.083 ms 160.124 ms 160.034 ms
6441 6 100ge8-2.core1.vie1.he.net (184.105.65.6) 116.777 ms 114.672 ms 114.588 ms
6442 7 10ge2-4.core1.kbp1.he.net (184.105.222.26) 134.971 ms 143.294 ms 134.696 ms
6443 8 uarnet-as-as3255.10gigabitethernet4-3.core1.kbp1.he.net (216.66.85.186) 141.667 ms 141.262 ms 141.655 ms
6444 9 194.44.6.58 (194.44.6.58) 145.211 ms 145.244 ms 145.701 ms
644510 zomro.com (93.171.158.2) 135.374 ms 135.430 ms 135.617 ms
644611 mystuff.net (93.171.158.187) <syn,ack> 143.810 ms 185.858 ms 141.779 ms
6447
6448###########################################################################################
6449
6450
6451Checking for HTTP-Loadbalancing [Date]: 05:01:44, 05:01:48, 05:01:53, 05:01:55, 05:01:56, 05:01:56, 05:02:01, 05:02:06, 05:02:06, 05:02:07, 05:02:07, 05:02:08, 05:02:11, 05:02:11, 05:02:12, 05:02:13, 05:02:18, 05:02:22, 05:02:23, 05:02:23, 05:02:24, 05:02:29, 05:02:33, 05:02:34, 05:02:35, 05:02:35, 05:02:36, 05:02:36, 05:02:37, 05:02:40, 05:02:40, 05:02:41, 05:02:41, 05:02:42, 05:02:45, 05:02:46, 05:02:46, 05:02:46, 05:02:49, 05:02:56, 05:02:57, 05:02:57, 05:02:58, 05:02:58, 05:03:02, 05:03:02, 05:03:02, 05:03:03, 05:03:04, 05:03:07, NOT FOUND
6452
6453Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
6454
6455dream-video.net does NOT use Load-balancing.
6456
6457###########################################################################################
6458
6459cd /pentest/enumeration/list-urls
6460./list-urls.py http://www.dream-video.net
6461./Recon.sh: ligne 71 : cd: /pentest/enumeration/list-urls: Aucun fichier ou dossier de ce type
6462./Recon.sh: ligne 72: ./list-urls.py: Aucun fichier ou dossier de ce type
6463
6464###########################################################################################
6465
6466nmap -PN -n -F -T4 -sV -A -oG temp.txt dream-video.net
6467
6468Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 01:04 EDT
6469Nmap scan report for dream-video.net (93.171.158.187)
6470Host is up (0.23s latency).
6471Not shown: 91 closed ports
6472PORT STATE SERVICE VERSION
647322/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
6474| ssh-hostkey:
6475| 2048 79:af:ae:28:df:dc:55:45:81:c3:3b:14:c9:52:60:e1 (RSA)
6476| 256 94:fe:42:fd:da:47:52:ea:ec:3a:86:66:fb:b1:b9:e8 (ECDSA)
6477|_ 256 8f:77:8b:a6:bc:c7:cd:65:71:46:7a:9d:73:e2:44:68 (EdDSA)
647825/tcp filtered smtp
647980/tcp open http nginx 1.10.2
6480|_http-server-header: nginx/1.10.2
6481|_http-title: DREAM-VIDEO - Young teen fashion models video collection
6482111/tcp open rpcbind 2-4 (RPC #100000)
6483| rpcinfo:
6484| program version port/proto service
6485| 100000 2,3,4 111/tcp rpcbind
6486|_ 100000 2,3,4 111/udp rpcbind
6487135/tcp filtered msrpc
6488139/tcp filtered netbios-ssn
6489445/tcp filtered microsoft-ds
6490465/tcp filtered smtps
6491587/tcp filtered submission
6492Device type: general purpose|firewall|storage-misc|webcam
6493Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (99%), WatchGuard Fireware 11.X (94%), Synology DiskStation Manager 5.X (94%), Tandberg embedded (90%)
6494OS CPE: cpe:/o:linux:linux_kernel:2.6.39 cpe:/o:watchguard:fireware:11.8 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:linux:linux_kernel:3.10 cpe:/o:linux:linux_kernel:4.2 cpe:/h:tandberg:vcs
6495Aggressive OS guesses: Linux 2.6.39 (99%), Linux 2.6.32 (94%), WatchGuard Fireware 11.8 (94%), Synology DiskStation Manager 5.1 (94%), Linux 3.10 (94%), Linux 2.6.32 or 3.10 (94%), Linux 3.4 (94%), Linux 3.1 - 3.2 (93%), Linux 2.6.32 - 2.6.39 (92%), Linux 3.2 - 3.8 (91%)
6496No exact OS matches for host (test conditions non-ideal).
6497Network Distance: 10 hops
6498
6499TRACEROUTE (using port 1720/tcp)
6500HOP RTT ADDRESS
65011 543.87 ms 10.13.0.1
65022 570.80 ms 37.187.24.252
65033 548.57 ms 178.33.103.231
65044 ...
65055 552.75 ms 213.251.128.67
65066 558.83 ms 91.121.215.193
65077 564.76 ms 91.121.215.209
65088 581.25 ms 193.25.180.221
65099 576.97 ms 93.171.158.2
651010 574.21 ms 93.171.158.187
6511
6512OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6513Nmap done: 1 IP address (1 host up) scanned in 42.39 seconds
6514
6515###########################################################################################
6516
6517amap -i temp.txt
6518amap v5.4 (www.thc.org/thc-amap) started at 2017-09-10 01:04:58 - APPLICATION MAPPING mode
6519
6520Protocol on 93.171.158.187:80/tcp matches http
6521Protocol on 93.171.158.187:22/tcp matches ssh
6522Protocol on 93.171.158.187:22/tcp matches ssh-openssh
6523Protocol on 93.171.158.187:111/tcp matches rpc
6524Protocol on 93.171.158.187:80/tcp matches http-apache-2
6525Protocol on 93.171.158.187:111/tcp matches rpc-rpcbind-v4
6526
6527Unidentified ports: none.
6528
6529amap v5.4 finished at 2017-09-10 01:05:12
6530
6531###########################################################################################
6532
6533inetnum: 93.171.158.0 - 93.171.159.255
6534netname: ZOMRO-NET
6535descr: PE Dunaeivskyi Denys Leonidovich
6536country: UA
6537org: ORG-PDDL1-RIPE
6538admin-c: PDDL4-RIPE
6539tech-c: PDDL4-RIPE
6540status: ASSIGNED PA
6541mnt-by: RIPE-DB-MNT
6542mnt-lower: RIPE-DB-MNT
6543mnt-domains: RIPE-DB-MNT
6544mnt-routes: RIPE-DB-MNT
6545mnt-routes: gmhost-mnt
6546created: 2015-06-01T12:01:38Z
6547last-modified: 2016-11-25T12:28:16Z
6548source: RIPE
6549
6550organisation: ORG-PDDL1-RIPE
6551org-name: PE Dunaeivskyi Denys Leonidovich
6552org-type: OTHER
6553phone: +380639774692
6554address: 95/1A Mira ave., Khmelnitsky, Ukraine
6555admin-c: PDDL4-RIPE
6556tech-c: PDDL4-RIPE
6557abuse-c: PDDL4-RIPE
6558abuse-mailbox: abuse@zomro.com
6559mnt-ref: RIPE-DB-MNT
6560mnt-by: RIPE-DB-MNT
6561created: 2015-06-01T12:01:37Z
6562last-modified: 2016-11-25T13:53:37Z
6563source: RIPE # Filtered
6564
6565role: PE Dunaeivskyi Denys Leonidovich NOC
6566address: 95/1A Mira ave., Khmelnitsky, Ukraine
6567admin-c: DD7504-RIPE
6568tech-c: LD4780-RIPE
6569nic-hdl: PDDL4-RIPE
6570abuse-mailbox: abuse@zomro.com
6571mnt-by: RIPE-DB-MNT
6572created: 2015-06-01T12:01:37Z
6573last-modified: 2016-11-25T14:20:33Z
6574source: RIPE # Filtered
6575
6576% Information related to '93.171.158.0/23AS201094'
6577
6578route: 93.171.158.0/23
6579descr: PE Dunaeivskyi Denys Leonidovich
6580origin: AS201094
6581mnt-by: GMHOST-MNT
6582created: 2015-06-08T14:26:00Z
6583last-modified: 2015-06-08T14:26:00Z
6584source: RIPE
6585
6586% This query was served by the RIPE Database Query Service version 1.89.2 (WAGYU)
6587
6588
6589###########################################################################################
6590[i] Scanning Site: http://dream-video.net
6591
6592
6593
6594B A S I C I N F O
6595====================
6596
6597
6598[+] Site Title: DREAM-VIDEO - Young teen fashion models video collection
6599[+] IP address: 93.171.158.187
6600[+] Web Server: nginx/1.10.2
6601[+] CMS: Could Not Detect
6602[+] Cloudflare: Not Detected
6603[+] Robots File: Found
6604
6605-------------[ contents ]----------------
6606User-agent: *
6607Disallow:
6608sitemap: http://dream-video.net/sitemap.xml
6609-----------[end of contents]-------------
6610
6611
6612
6613W H O I S L O O K U P
6614========================
6615
6616 Domain Name: DREAM-VIDEO.NET
6617 Registry Domain ID: 1895999776_DOMAIN_NET-VRSN
6618 Registrar WHOIS Server: whois.nic.ru
6619 Registrar URL: http://nic.ru
6620 Updated Date: 2016-11-28T12:50:42Z
6621 Creation Date: 2015-01-15T10:59:57Z
6622 Registry Expiry Date: 2018-01-15T10:59:57Z
6623 Registrar: Regional Network Information Center, JSC dba RU-CENTER
6624 Registrar IANA ID: 463
6625 Registrar Abuse Contact Email: tld-abuse@nic.ru
6626 Registrar Abuse Contact Phone: +7 (495) 994-46-01
6627 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6628 Name Server: NS1.CLOUDNS.NET
6629 Name Server: NS1.FREEDNS.WS
6630 Name Server: NS2.CLOUDNS.NET
6631 Name Server: NS2.FREEDNS.WS
6632 Name Server: NS3.CLOUDNS.NET
6633 Name Server: NS4.CLOUDNS.NET
6634
6635
6636
6637G E O I P L O O K U P
6638=========================
6639
6640[i] IP Address: 93.171.158.187
6641[i] Country: UA
6642[i] State: Dnipropetrovs'ka Oblast'
6643[i] City: Khmelnitskiy
6644[i] Latitude: 47.727798
6645[i] Longitude: 34.137199
6646
6647
6648
6649
6650H T T P H E A D E R S
6651=======================
6652
6653
6654[i] HTTP/1.1 200 OK
6655[i] Server: nginx/1.10.2
6656[i] Date: Sun, 10 Sep 2017 05:01:24 GMT
6657[i] Content-Type: text/html
6658[i] Connection: close
6659[i] Accept-Ranges: bytes
6660[i] Vary: Accept-Encoding,User-Agent
6661
6662
6663
6664
6665D N S L O O K U P
6666===================
6667
6668dream-video.net. 3595 IN A 93.171.158.187
6669dream-video.net. 3600 IN NS ns3.cloudns.net.
6670dream-video.net. 3600 IN NS ns4.cloudns.net.
6671dream-video.net. 3600 IN NS ns1.cloudns.net.
6672dream-video.net. 3600 IN NS ns2.cloudns.net.
6673dream-video.net. 3600 IN SOA ns1.cloudns.net. support.cloudns.net. 2016020602 7200 1800 1209600 3600
6674
6675
6676
6677
6678S U B N E T C A L C U L A T I O N
6679====================================
6680
6681Address = 93.171.158.187
6682Network = 93.171.158.187 / 32
6683Netmask = 255.255.255.255
6684Broadcast = not needed on Point-to-Point links
6685Wildcard Mask = 0.0.0.0
6686Hosts Bits = 0
6687Max. Hosts = 1 (2^0 - 0)
6688Host Range = { 93.171.158.187 - 93.171.158.187 }
6689
6690
6691
6692N M A P P O R T S C A N
6693============================
6694
6695
6696Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 05:01 UTC
6697Nmap scan report for dream-video.net (93.171.158.187)
6698Host is up (0.12s latency).
6699rDNS record for 93.171.158.187: mystuff.net
6700PORT STATE SERVICE VERSION
670121/tcp closed ftp
670222/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
670323/tcp closed telnet
670425/tcp closed smtp
670580/tcp open http nginx 1.10.2
6706110/tcp closed pop3
6707143/tcp closed imap
6708443/tcp closed https
6709445/tcp closed microsoft-ds
67103389/tcp closed ms-wbt-server
6711
6712Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6713Nmap done: 1 IP address (1 host up) scanned in 7.56 seconds
6714
6715
6716
6717S U B - D O M A I N F I N D E R
6718==================================
6719
6720
6721[i] Total Subdomains Found : 1
6722
6723[+] Subdomain: dream-video.net
6724[-] IP: 93.171.158.187
6725[*] Performing TLD Brute force Enumeration against dream-video.net
6726[*] The operation could take up to: 00:01:07
6727[*] A dream-video.biz.af 5.45.75.45
6728[*] CNAME dream-video.biz.at free.biz.at
6729[*] A free.biz.at 216.92.134.29
6730[*] A dream-video.co.asia 91.195.240.135
6731[*] A dream-video.org.aw 142.4.20.12
6732[*] A dream-video.com.ba 195.222.33.180
6733[*] A dream-video.co.ba 176.9.45.78
6734[*] A dream-video.com.be 95.173.170.166
6735[*] A dream-video.biz.by 71.18.52.2
6736[*] A dream-video.biz.bz 199.59.242.150
6737[*] A dream-video.com.cc 54.252.107.64
6738[*] A dream-video.net.cc 54.252.89.206
6739[*] A dream-video.co.cc 175.126.123.219
6740[*] A dream-video.org.ch 72.52.4.122
6741[*] A dream-video.co.cm 85.25.140.105
6742[*] A dream-video.net.cm 85.25.140.105
6743[*] A dream-video.biz.cl 185.53.178.8
6744[*] A dream-video.com.com 52.33.196.199
6745[*] A dream-video.net.com 199.59.242.150
6746[*] A dream-video.com 23.236.62.147
6747[*] A dream-video.co.com 173.192.115.17
6748[*] A dream-video.org.com 23.23.86.44
6749[*] A dream-video.biz.cr 72.52.4.122
6750[*] CNAME dream-video.biz.cm i.cns.cm
6751[*] A i.cns.cm 118.184.56.30
6752[*] A dream-video.biz.cx 72.52.4.122
6753[*] A dream-video.com.cz 62.109.128.30
6754[*] A dream-video.net.cz 80.250.24.177
6755[*] A dream-video.biz.cz 185.53.179.7
6756[*] A dream-video.de 217.160.231.140
6757[*] CNAME dream-video.co.de co.de
6758[*] A co.de 144.76.162.245
6759[*] A dream-video.com.de 50.56.68.37
6760[*] CNAME dream-video.org.de www.org.de
6761[*] A www.org.de 78.47.128.8
6762[*] A dream-video.net.eu 78.46.90.98
6763[*] A dream-video.org.eu 78.46.90.98
6764[*] A dream-video.biz.fi 185.55.85.123
6765[*] A dream-video.fm 173.230.131.38
6766[*] A dream-video.biz.fm 173.230.131.38
6767[*] A dream-video.org.fr 149.202.133.35
6768[*] A dream-video.biz.gl 72.52.4.122
6769[*] CNAME dream-video.co.gp co.gp
6770[*] A co.gp 144.76.162.245
6771[*] A dream-video.co.hn 208.100.40.203
6772[*] CNAME dream-video.net.hr net.hr
6773[*] A net.hr 192.0.78.25
6774[*] A net.hr 192.0.78.24
6775[*] A dream-video.co.ht 72.52.4.122
6776[*] CNAME dream-video.biz.hn parkmydomain.vhostgo.com
6777[*] A parkmydomain.vhostgo.com 107.186.245.118
6778[*] A dream-video.co.jobs 50.17.193.222
6779[*] A dream-video.net.jobs 50.19.241.165
6780[*] A dream-video.biz.jobs 50.19.241.165
6781[*] A dream-video.org.jobs 50.19.241.165
6782[*] A dream-video.com.jobs 50.19.241.165
6783[*] A dream-video.biz.ky 199.184.144.27
6784[*] CNAME dream-video.biz.li 712936.parkingcrew.net
6785[*] A 712936.parkingcrew.net 185.53.179.29
6786[*] A dream-video.biz.lu 195.26.5.2
6787[*] A dream-video.biz.ly 64.136.20.39
6788[*] A dream-video.biz.md 72.52.4.122
6789[*] A dream-video.co.mk 87.76.31.211
6790[*] A dream-video.co.mobi 54.225.105.179
6791[*] A dream-video.biz.my 202.190.174.44
6792[*] A dream-video.net 93.171.158.187
6793[*] A dream-video.co.net 188.166.216.219
6794[*] A dream-video.net.net 52.50.81.210
6795[*] A dream-video.org.net 23.23.86.44
6796[*] A dream-video.co.nl 37.97.184.204
6797[*] A dream-video.com.nl 83.98.157.102
6798[*] A dream-video.net.nl 83.98.157.102
6799[*] A dream-video.co.nr 208.100.40.202
6800[*] CNAME dream-video.co.nu co.nu
6801[*] A co.nu 144.76.162.245
6802[*] A dream-video.net.nu 199.102.76.78
6803[*] CNAME dream-video.com.nu com.nu
6804[*] A com.nu 144.76.162.245
6805[*] A dream-video.org.nu 80.92.84.139
6806[*] A dream-video.com.org 23.23.86.44
6807[*] CNAME dream-video.net.org pewtrusts.org
6808[*] A pewtrusts.org 204.74.99.100
6809[*] A dream-video.ph 45.79.222.138
6810[*] A dream-video.co.ph 45.79.222.138
6811[*] A dream-video.com.ph 45.79.222.138
6812[*] A dream-video.net.ph 45.79.222.138
6813[*] A dream-video.org.ph 45.79.222.138
6814[*] A dream-video.co.pl 212.91.6.55
6815[*] A dream-video.org.pm 208.73.211.177
6816[*] A dream-video.org.pm 208.73.210.217
6817[*] A dream-video.org.pm 208.73.210.202
6818[*] A dream-video.org.pm 208.73.211.165
6819[*] A dream-video.co.ps 66.96.132.56
6820[*] CNAME dream-video.biz.ps biz.ps
6821[*] A biz.ps 144.76.162.245
6822[*] A dream-video.co.pt 194.107.127.52
6823[*] A dream-video.pw 141.8.226.58
6824[*] A dream-video.co.pw 141.8.226.59
6825[*] A dream-video.net.pw 141.8.226.59
6826[*] A dream-video.biz.pw 141.8.226.59
6827[*] A dream-video.org.pw 141.8.226.59
6828[*] A dream-video.net.ro 69.64.52.127
6829[*] A dream-video.org.re 217.70.184.38
6830[*] CNAME dream-video.co.ro now.co.ro
6831[*] A now.co.ro 185.27.255.9
6832[*] A dream-video.com.ru 178.210.89.119
6833[*] A dream-video.ru 91.106.207.19
6834[*] A dream-video.biz.se 185.53.179.6
6835[*] CNAME dream-video.net.se 773147.parkingcrew.net
6836[*] A 773147.parkingcrew.net 185.53.179.29
6837[*] A dream-video.com.sr 143.95.106.249
6838[*] A dream-video.co.sl 91.195.240.135
6839[*] A dream-video.biz.st 91.121.28.115
6840[*] A dream-video.co.su 72.52.4.122
6841[*] A dream-video.biz.tc 64.136.20.39
6842[*] A dream-video.biz.tf 85.236.153.18
6843[*] A dream-video.net.tf 188.40.70.29
6844[*] A dream-video.net.tf 188.40.70.27
6845[*] A dream-video.net.tf 188.40.117.12
6846[*] A dream-video.co.tl 208.100.40.202
6847[*] A dream-video.co.to 175.118.124.44
6848[*] A dream-video.co.tv 31.186.25.163
6849[*] A dream-video.biz.tv 72.52.4.122
6850[*] A dream-video.org.tv 72.52.4.122
6851[*] CNAME dream-video.biz.uz biz.uz
6852[*] A biz.uz 144.76.162.245
6853[*] A dream-video.vg 88.198.29.97
6854[*] A dream-video.co.vg 88.198.29.97
6855[*] A dream-video.com.vg 88.198.29.97
6856[*] A dream-video.net.vg 68.178.254.180
6857[*] A dream-video.biz.vg 89.31.143.20
6858[*] A dream-video.ws 64.70.19.203
6859[*] A dream-video.net.ws 202.4.48.211
6860[*] A dream-video.biz.ws 184.168.221.104
6861[*] A dream-video.org.ws 202.4.48.211
6862[*] A dream-video.com.ws 202.4.48.211
6863R E V E R S E I P L O O K U P
6864==================================
6865
6866
6867[i] Total Sites Found On This Server : 1
6868
6869
6870[#] dream-video.net,
6871[-] CMS: Could Not Detect
6872dream-video.net
6873
6874
6875 Domain Name: DREAM-VIDEO.NET
6876 Registry Domain ID: 1895999776_DOMAIN_NET-VRSN
6877 Registrar WHOIS Server: whois.nic.ru
6878 Registrar URL: http://nic.ru
6879 Updated Date: 2016-11-28T12:50:42Z
6880 Creation Date: 2015-01-15T10:59:57Z
6881 Registry Expiry Date: 2018-01-15T10:59:57Z
6882 Registrar: Regional Network Information Center, JSC dba RU-CENTER
6883 Registrar IANA ID: 463
6884 Registrar Abuse Contact Email: tld-abuse@nic.ru
6885 Registrar Abuse Contact Phone: +7 (495) 994-46-01
6886 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6887 Name Server: NS1.CLOUDNS.NET
6888 Name Server: NS1.FREEDNS.WS
6889 Name Server: NS2.CLOUDNS.NET
6890 Name Server: NS2.FREEDNS.WS
6891 Name Server: NS3.CLOUDNS.NET
6892 Name Server: NS4.CLOUDNS.NET
6893
6894Domain Name: DREAM-VIDEO.NET
6895Registry Domain ID: 1895999776_DOMAIN_NET-VRSN
6896Registrar WHOIS Server: whois.nic.ru
6897Registrar URL: http://www.nic.ru
6898Updated Date: 2015-01-16T16:05:32Z
6899Creation Date: 2015-01-15T10:59:58Z
6900Registrar Registration Expiration Date: 2018-01-14T21:00:00Z
6901Registrar: Regional Network Information Center, JSC dba RU-CENTER
6902Registrar IANA ID: 463
6903Registrar Abuse Contact Email: tld-abuse@nic.ru
6904Registrar Abuse Contact Phone: +7.4959944601
6905Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6906Registry Registrant ID:
6907Registrant Name: Bogdan Lubyanoy
6908Registrant Organization: Bogdan Lubyanoy
6909Registrant Street: Noginskaya st 41-5
6910Registrant City: Dnepropetrovsk
6911Registrant Postal Code: 49017
6912Registrant Country: UA
6913Registrant Phone: +380.503615560
6914Registrant Phone Ext:
6915Registrant Email: alubyanoy@inbox.ru
6916Registry Admin ID:
6917Admin Name: Bogdan Lubyanoy
6918Admin Organization: Bogdan Lubyanoy
6919Admin Street: Noginskaya st 41-5
6920Admin City: Dnepropetrovsk
6921Admin Postal Code: 49017
6922Admin Country: UA
6923Admin Phone: +380.503615560
6924Admin Phone Ext:
6925Admin Email: alubyanoy@inbox.ru
6926Registry Tech ID:
6927Tech Name: Bogdan Lubyanoy
6928Tech Organization: Bogdan Lubyanoy
6929Tech Street: Noginskaya st 41-5
6930Tech City: Dnepropetrovsk
6931Tech Postal Code: 49017
6932Tech Country: UA
6933Tech Phone: +380.503615560
6934Tech Phone Ext:
6935Tech Email: alubyanoy@inbox.ru
6936Name Server: ns1.cloudns.net
6937Name Server: ns1.freedns.ws
6938Name Server: ns2.cloudns.net
6939Name Server: ns2.freedns.ws
6940Name Server: ns3.cloudns.net
6941Name Server: ns4.cloudns.net
6942
6943;dream-video.net. IN ANY
6944
6945;; ANSWER SECTION:
6946dream-video.net. 3600 IN A 93.171.158.187
6947dream-video.net. 3600 IN SOA ns1.cloudns.net. support.cloudns.net. 2016020602 7200 1800 1209600 3600
6948dream-video.net. 3600 IN NS ns1.cloudns.net.
6949dream-video.net. 3600 IN NS ns3.cloudns.net.
6950dream-video.net. 3600 IN NS ns4.cloudns.net.
6951dream-video.net. 3600 IN NS ns2.cloudns.net.
6952
6953----- dream-video.net -----
6954
6955
6956Host's addresses:
6957__________________
6958
6959dream-video.net. 3593 IN A 93.171.158.187
6960
6961
6962Name Servers:
6963______________
6964
6965ns4.cloudns.net. 102705 IN A 46.165.223.182
6966ns2.cloudns.net. 102705 IN A 108.59.1.205
6967ns3.cloudns.net. 102705 IN A 188.241.116.117
6968ns1.cloudns.net. 6583 IN A 85.159.233.17
6969
6970
6971
6972Brute forcing with dns.txt:
6973____________________________
6974
6975www.dream-video.net. 3600 IN A 93.171.158.187
6976
6977
6978Performing recursion:
6979______________________
6980
6981
6982 ---- Checking subdomains NS records ----
6983
6984 Can't perform recursion no NS records.
6985
6986
6987dream-video.net class C netranges:
6988___________________________________
6989
6990 93.171.158.0/24
6991
6992
6993Performing reverse lookup on 256 ip addresses:
6994_______________________________________________
6995
6996
69970 results out of 256 IP addresses.
6998
6999
7000WhatWeb report for http://dream-video.net
7001Status : 200 OK
7002Title : DREAM-VIDEO - Young teen fashion models video collection
7003IP : 93.171.158.187
7004Country : CZECH REPUBLIC, CZ
7005
7006Summary : HTML5, HTTPServer[nginx/1.10.2], nginx[1.10.2], Script[text/javascript], AddThis
7007
7008Detected Plugins:
7009[ AddThis ]
7010 AddThis is a free way to boost traffic back to your site by
7011 making it easier for visitors to share your content.
7012
7013 Website : http://www.addthis.com/
7014
7015[ HTML5 ]
7016 HTML version 5, detected by the doctype declaration
7017
7018
7019[ HTTPServer ]
7020 HTTP server header string. This plugin also attempts to
7021 identify the operating system from the server header.
7022
7023 String : nginx/1.10.2 (from server string)
7024
7025[ Script ]
7026 This plugin detects instances of script HTML elements and
7027 returns the script language/type.
7028
7029 String : text/javascript
7030
7031[ nginx ]
7032 Nginx (Engine-X) is a free, open-source, high-performance
7033 HTTP server and reverse proxy, as well as an IMAP/POP3
7034 proxy server.
7035
7036 Version : 1.10.2
7037 Website : http://nginx.net/
7038
7039HTTP Headers:
7040 HTTP/1.1 200 OK
7041 Server: nginx/1.10.2
7042 Date: Sun, 10 Sep 2017 05:06:50 GMT
7043 Content-Type: text/html
7044 Content-Length: 4916
7045 Connection: close
7046 Accept-Ranges: bytes
7047 Vary: Accept-Encoding,User-Agent
7048 Content-Encoding: gzip
7049
7050
7051------------------------------------
7052[-] Resolving hostnames IPs...
705393.171.158.187:www.dream-video.net
7054
7055
7056
7057 ^ ^
7058 _ __ _ ____ _ __ _ _ ____
7059 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
7060 | V V // o // _/ | V V // 0 // 0 // _/
7061 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
7062 <
7063 ...'
7064
7065 WAFW00F - Web Application Firewall Detection Tool
7066
7067 By Sandro Gauci && Wendel G. Henrique
7068
7069Checking http://dream-video.net
7070Generic Detection results:
7071No WAF detected by the generic detection
7072Number of requests: 13
7073
7074
7075DNS Servers for dream-video.net:
7076 ns3.cloudns.net
7077 ns1.cloudns.net
7078 ns2.cloudns.net
7079 ns4.cloudns.net
7080
7081Trying zone transfer first...
7082 Testing ns3.cloudns.net
7083 Request timed out or transfer not allowed.
7084 Testing ns1.cloudns.net
7085 Request timed out or transfer not allowed.
7086 Testing ns2.cloudns.net
7087 Request timed out or transfer not allowed.
7088 Testing ns4.cloudns.net
7089 Request timed out or transfer not allowed.
7090
7091Unsuccessful in zone transfer (it was worth a shot)
7092Okay, trying the good old fashioned way... brute force
7093
7094Checking for wildcard DNS...
7095Nope. Good.
7096Now performing 2280 test(s)...
709793.171.158.187 www.dream-video.net
7098
7099Subnets found (may want to probe here using nmap or unicornscan):
7100 93.171.158.0-255 : 1 hostnames found.
7101
7102Done with Fierce scan: http://ha.ckers.org/fierce/
7103Found 1 entries.
7104
7105Have a nice day.
7106
7107
7108
7109lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
7110 Written by Stefan Behte (http://ge.mine.nu)
7111 Proof-of-concept! Might give false positives.
7112
7113Checking for DNS-Loadbalancing: NOT FOUND
7114Checking for HTTP-Loadbalancing [Server]:
7115 nginx/1.10.2
7116 NOT FOUND
7117
7118Checking for HTTP-Loadbalancing [Date]: 05:34:00, 05:34:04, 05:34:10, 05:34:10, 05:34:12, 05:34:15, 05:34:27, 05:34:33, 05:34:35, 05:34:36, 05:34:42, 05:34:56, 05:34:58, 05:34:58, 05:35:01, 05:35:14, 05:35:21, 05:35:23, 05:35:26, 05:35:36, 05:35:45, 05:35:47, 05:35:48, 05:35:54, 05:36:08, 05:36:09, 05:36:11, 05:36:13, 05:36:25, 05:36:37, 05:36:48, 05:36:49, 05:36:49, 05:36:53, 05:37:00, 05:37:08, 05:37:08, 05:37:12, 05:37:13, 05:37:19, 05:37:21, 05:37:21, 05:37:24, 05:37:36, 05:37:45, 05:37:45, 05:37:46, 05:37:50, 05:37:54, 05:37:55, NOT FOUND
7119
7120Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
7121
7122dream-video.net does NOT use Load-balancing.
7123
7124
7125
7126Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
7127
7128 ----------------------------------------------------------
7129| Scan Information |
7130 ----------------------------------------------------------
7131
7132Mode ..................... VRFY
7133Worker Processes ......... 5
7134Usernames file ........... users.txt
7135Target count ............. 1
7136Username count ........... 494
7137Target TCP port .......... 25
7138Query timeout ............ 5 secs
7139Target domain ............
7140
7141######## Scan started at Sun Sep 10 01:41:13 2017 #########
7142######## Scan completed at Sun Sep 10 01:49:28 2017 #########
71430 results.
7144
7145494 queries in 495 seconds (1.0 queries / sec)
7146
7147
7148
7149Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 01:49 EDT
7150NSE: Loaded 146 scripts for scanning.
7151NSE: Script Pre-scanning.
7152Initiating NSE at 01:49
7153Completed NSE at 01:49, 0.00s elapsed
7154Initiating NSE at 01:49
7155Completed NSE at 01:49, 0.00s elapsed
7156Failed to resolve "dream-video.net.txt".
7157Initiating Parallel DNS resolution of 1 host. at 01:49
7158Completed Parallel DNS resolution of 1 host. at 01:49, 0.30s elapsed
7159Initiating SYN Stealth Scan at 01:49
7160Scanning dream-video.net (93.171.158.187) [100 ports]
7161Discovered open port 22/tcp on 93.171.158.187
7162Discovered open port 111/tcp on 93.171.158.187
7163Discovered open port 80/tcp on 93.171.158.187
7164Increasing send delay for 93.171.158.187 from 0 to 5 due to 11 out of 27 dropped probes since last increase.
7165Completed SYN Stealth Scan at 01:49, 9.28s elapsed (100 total ports)
7166Initiating Service scan at 01:49
7167Scanning 3 services on dream-video.net (93.171.158.187)
7168Completed Service scan at 01:50, 23.86s elapsed (3 services on 1 host)
7169Initiating OS detection (try #1) against dream-video.net (93.171.158.187)
7170Initiating Traceroute at 01:50
7171Completed Traceroute at 01:50, 3.00s elapsed
7172Initiating Parallel DNS resolution of 9 hosts. at 01:50
7173Completed Parallel DNS resolution of 9 hosts. at 01:50, 5.51s elapsed
7174NSE: Script scanning 93.171.158.187.
7175Initiating NSE at 01:50
7176Completed NSE at 01:50, 24.39s elapsed
7177Initiating NSE at 01:50
7178Completed NSE at 01:50, 0.32s elapsed
7179Nmap scan report for dream-video.net (93.171.158.187)
7180Host is up (0.40s latency).
7181rDNS record for 93.171.158.187: mystuff.net
7182Not shown: 91 closed ports
7183PORT STATE SERVICE VERSION
718422/tcp open ssh OpenSSH 6.6.1 (protocol 2.0)
7185| ssh-hostkey:
7186| 2048 79:af:ae:28:df:dc:55:45:81:c3:3b:14:c9:52:60:e1 (RSA)
7187| 256 94:fe:42:fd:da:47:52:ea:ec:3a:86:66:fb:b1:b9:e8 (ECDSA)
7188|_ 256 8f:77:8b:a6:bc:c7:cd:65:71:46:7a:9d:73:e2:44:68 (EdDSA)
718925/tcp filtered smtp
719080/tcp open http nginx 1.10.2
7191|_http-favicon: Unknown favicon MD5: A68371B9F8919CB1E72D9059FE00633A
7192| http-methods:
7193|_ Supported Methods: GET HEAD POST OPTIONS
7194|_http-server-header: nginx/1.10.2
7195111/tcp open rpcbind 2-4 (RPC #100000)
7196| rpcinfo:
7197| program version port/proto service
7198| 100000 2,3,4 111/tcp rpcbind
7199|_ 100000 2,3,4 111/udp rpcbind
7200135/tcp filtered msrpc
7201139/tcp filtered netbios-ssn
7202445/tcp filtered microsoft-ds
7203465/tcp filtered smtps
7204587/tcp filtered submission
7205Device type: general purpose
7206Running: Linux 2.6.X
7207OS CPE: cpe:/o:linux:linux_kernel:2.6.39
7208OS details: Linux 2.6.39
7209Uptime guess: 35.323 days (since Sat Aug 5 18:05:13 2017)
7210Network Distance: 10 hops
7211TCP Sequence Prediction: Difficulty=257 (Good luck!)
7212IP ID Sequence Generation: All zeros
7213
7214TRACEROUTE (using port 23/tcp)
7215HOP RTT ADDRESS
72161 110.08 ms 10.13.0.1
72172 110.11 ms 37.187.24.252
72183 110.11 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
72194 ...
72205 116.43 ms be100-1112.ams-5-a9.nl.eu (213.251.128.67)
72216 138.93 ms be100-1167.var-5-a9.pl.eu (91.121.215.193)
72227 139.46 ms vl2.var-6-a72.pl.eu (91.121.215.209)
72238 219.31 ms dtel-ix.gmhost.hosting (193.25.180.221)
72249 219.30 ms zomro.com (93.171.158.2)
722510 157.03 ms mystuff.net (93.171.158.187)
7226
7227NSE: Script Post-scanning.
7228Initiating NSE at 01:50
7229Completed NSE at 01:50, 0.00s elapsed
7230Initiating NSE at 01:50
7231Completed NSE at 01:50, 0.00s elapsed
7232Read data files from: /usr/bin/../share/nmap
7233OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7234Nmap done: 1 IP address (1 host up) scanned in 73.51 seconds
7235 Raw packets sent: 246 (11.778KB) | Rcvd: 183 (9.768KB)
7236
7237 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
7238 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
7239 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
7240 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
7241 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
7242
7243 _/ User-Agent Tester ↵
7244 _/ AKA: Purple Pimp ↵
7245 _/ ChrisJohnRiley ↵
7246 _/ blog.c22.cc ↵
7247
7248 [>] Performing initial request and confirming stability
7249 [>] Using User-Agent string Mozilla/5.0
7250
7251 [ ] URL (ENTERED): http://dream-video.net
7252 [ ] Response Code: 200 OK
7253 [ ] Server: nginx/1.10.2
7254 [ ] Date: Sun, 10 Sep 2017 05:50:47 GMT
7255 [ ] Content-Type: text/html
7256 [ ] Transfer-Encoding: chunked
7257 [ ] Connection: close
7258 [ ] Accept-Ranges: bytes
7259 [ ] Vary: Accept-Encoding,User-Agent
7260 [ ] Data (MD5): 20eb871f0e085edac539bfe225d08801
7261
7262 [1] Pass
7263 [2] Pass
7264 [3] Pass
7265
7266 [>] URL appears stable. Beginning test
7267
7268 [>] Using DEFAULT User-Agent Strings
7269
7270 [>] Using Crazy User-Agent Strings
7271 [>] Using Bot User-Agent Strings
7272
7273 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
7274
7275
7276 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
7277
7278
7279 [!] Data (MD5): 8657785b6bafebdc3af81df875c3c02d
7280
7281
7282 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
7283
7284
7285 [!] Data (MD5): 5922caaac34b70bb09ebb31ed658b19c
7286
7287
7288 [>] User-Agent String : TrackBack/1.02
7289
7290
7291 [!] Data (MD5): e3c0e103fc40c72db93e1172d2ae3143
7292
7293
7294 [>] User-Agent String : wispr
7295
7296
7297 [!] Data (MD5): 7d3015eb33c1092beec8a903881f6e51
7298
7299
7300 [>] User-Agent String : EMPTY USER-AGENT STRING!
7301
7302
7303 [!] Data (MD5): bb32e3924fffdb126c4710d0c0fdc149
7304
7305
7306 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
7307
7308
7309 [!] Data (MD5): f707a36a9fe9faefa5e32541c28da3a5
7310
7311
7312 [>] User-Agent String : Googlebot-Image/1.0
7313
7314
7315 [!] Data (MD5): d6d11d679495d170d25192001d063487
7316
7317
7318 [>] User-Agent String : Mediapartners-Google
7319
7320
7321 [!] Data (MD5): 809e69058eb9e6e392ca7932b47e8216
7322
7323
7324 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
7325
7326
7327 [!] Data (MD5): 1c1f76d94049809015c72e53ee8a3192
7328
7329
7330 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
7331
7332
7333 [!] Data (MD5): 54b673056a330033c761535bea367620
7334
7335
7336 [>] User-Agent String : mmcrawler
7337
7338
7339 [!] Data (MD5): ce9592f9eb6a226a052a83132a782b79
7340
7341
7342 [>] Checks completed... try enabling VERBOSE mode for more detailed output
7343
7344 [>] That's all folks... Fo' Shizzle!
7345##########################################################################################
7346 Hostname taboocollections.com ISP LeaseWeb Netherlands B.V. (AS60781)
7347Continent Europe Flag
7348NL
7349Country Netherlands Country Code NL (NLD)
7350Region Unknown Local time 10 Sep 2017 07:06 CEST
7351City Unknown Latitude 52.382
7352IP Address 95.211.6.26 Longitude 4.899
7353#########################################################################################
7354taboocollections.com
7355
7356###########################################################################################
7357
7358whois taboocollections.com
7359 Domain Name: TABOOCOLLECTIONS.COM
7360 Registry Domain ID: 1862378478_DOMAIN_COM-VRSN
7361 Registrar WHOIS Server: whois.PublicDomainRegistry.com
7362 Registrar URL: http://www.publicdomainregistry.com
7363 Updated Date: 2017-05-15T09:34:52Z
7364 Creation Date: 2014-06-11T06:02:10Z
7365 Registry Expiry Date: 2018-06-11T06:02:10Z
7366 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
7367 Registrar IANA ID: 303
7368 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
7369 Registrar Abuse Contact Phone: +1.2013775952
7370 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7371 Name Server: NS1.TABOOCOLLECTIONS.COM
7372
7373Domain Name: TABOOCOLLECTIONS.COM
7374Registry Domain ID: 1862378478_DOMAIN_COM-VRSN
7375Registrar WHOIS Server: whois.publicdomainregistry.com
7376Registrar URL: www.publicdomainregistry.com
7377Updated Date: 2017-05-15T09:34:52Z
7378Creation Date: 2014-06-11T06:02:10Z
7379Registrar Registration Expiration Date: 2018-06-11T06:02:10Z
7380Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
7381Registrar IANA ID: 303
7382Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7383Registry Registrant ID: Not Available From Registry
7384Registrant Name: Domain Admin
7385Registrant Organization: Privacy Protect, LLC (PrivacyProtect.org)
7386Registrant Street: 10 Corporate Drive
7387Registrant City: Burlington
7388Registrant State/Province: MA
7389Registrant Postal Code: 01803
7390Registrant Country: US
7391Registrant Phone: +1.8022274003
7392Registrant Phone Ext:
7393Registrant Fax:
7394Registrant Fax Ext:
7395Registrant Email: contact@privacyprotect.org
7396Registry Admin ID: Not Available From Registry
7397Admin Name: Domain Admin
7398Admin Organization: Privacy Protect, LLC (PrivacyProtect.org)
7399Admin Street: 10 Corporate Drive
7400Admin City: Burlington
7401Admin State/Province: MA
7402Admin Postal Code: 01803
7403Admin Country: US
7404Admin Phone: +1.8022274003
7405Admin Phone Ext:
7406Admin Fax:
7407Admin Fax Ext:
7408Admin Email: contact@privacyprotect.org
7409Registry Tech ID: Not Available From Registry
7410Tech Name: Domain Admin
7411Tech Organization: Privacy Protect, LLC (PrivacyProtect.org)
7412Tech Street: 10 Corporate Drive
7413Tech City: Burlington
7414Tech State/Province: MA
7415Tech Postal Code: 01803
7416Tech Country: US
7417Tech Phone: +1.8022274003
7418Tech Phone Ext:
7419Tech Fax:
7420Tech Fax Ext:
7421Tech Email: contact@privacyprotect.org
7422Name Server: ns1.taboocollections.com
7423
7424
7425###########################################################################################
7426
7427dig taboocollections.com any
7428
7429; <<>> DiG 9.10.3-P4-Debian <<>> taboocollections.com any
7430;; global options: +cmd
7431;; Got answer:
7432;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59619
7433;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
7434
7435;; OPT PSEUDOSECTION:
7436; EDNS: version: 0, flags:; udp: 4096
7437;; QUESTION SECTION:
7438;taboocollections.com. IN ANY
7439
7440;; ANSWER SECTION:
7441taboocollections.com. 3496 IN A 95.211.6.26
7442taboocollections.com. 3496 IN NS ns1.taboocollections.com.
7443taboocollections.com. 3496 IN NS ns2.taboocollections.com.
7444
7445;; Query time: 8 msec
7446;; SERVER: 192.168.1.254#53(192.168.1.254)
7447;; WHEN: Sun Sep 10 01:07:35 EDT 2017
7448;; MSG SIZE rcvd: 101
7449
7450Not shown: 85 closed ports
7451PORT STATE SERVICE VERSION
745221/tcp open ftp ProFTPD or KnFTPD
745322/tcp open ssh OpenSSH 5.3 (protocol 2.0)
7454| ssh-hostkey:
7455| 1024 21:60:f8:65:40:1c:3d:09:03:41:3a:fe:c4:e9:2c:ed (DSA)
7456|_ 2048 9b:53:08:ca:5f:13:2e:02:17:b0:f5:51:57:2d:38:56 (RSA)
745725/tcp filtered smtp
745853/tcp open domain ISC BIND 9.8.2rc1
7459| dns-nsid:
7460|_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6
746180/tcp open http nginx 1.10.1
7462|_http-server-header: nginx/1.10.1
7463|_http-title: Forbidden Collections
7464110/tcp open pop3 Dovecot pop3d
7465|_pop3-capabilities: UIDL TOP SASL(PLAIN LOGIN DIGEST-MD5 CRAM-MD5) USER PIPELINING RESP-CODES CAPA STLS
7466135/tcp filtered msrpc
7467139/tcp filtered netbios-ssn
7468143/tcp open imap Dovecot imapd
7469|_imap-capabilities: AUTH=PLAIN IDLE completed OK Capability ENABLE SASL-IR IMAP4rev1 ID STARTTLS LOGIN-REFERRALS AUTH=DIGEST-MD5 AUTH=CRAM-MD5A0001 LITERAL+ AUTH=LOGIN
7470445/tcp filtered microsoft-ds
7471465/tcp filtered smtps
7472587/tcp filtered submission
7473993/tcp open ssl/imap Dovecot imapd
7474|_imap-capabilities: CAPABILITY
7475| ssl-cert: Subject: commonName=lcimlw1013.amhost.net/organizationName=XX/stateOrProvinceName=XX/countryName=XX
7476| Not valid before: 2016-09-15T16:10:31
7477|_Not valid after: 2026-09-13T16:10:31
7478|_ssl-date: 2017-09-10T05:08:50+00:00; 0s from scanner time.
7479995/tcp open ssl/pop3 Dovecot pop3d
7480| ssl-cert: Subject: commonName=lcimlw1013.amhost.net/organizationName=XX/stateOrProvinceName=XX/countryName=XX
7481| Not valid before: 2016-09-15T16:10:31
7482|_Not valid after: 2026-09-13T16:10:31
7483|_ssl-date: 2017-09-10T05:08:50+00:00; 0s from scanner time.
74843306/tcp open mysql MySQL (unauthorized)
7485Device type: general purpose|firewall|storage-misc|webcam
7486Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (99%), WatchGuard Fireware 11.X (94%), Synology DiskStation Manager 5.X (94%), Tandberg embedded (90%)
7487OS CPE: cpe:/o:linux:linux_kernel:2.6.39 cpe:/o:linux:linux_kernel:3.4 cpe:/o:watchguard:fireware:11.8 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:linux:linux_kernel:4.2 cpe:/h:tandberg:vcs
7488Aggressive OS guesses: Linux 2.6.39 (99%), Linux 2.6.32 (94%), Linux 3.4 (94%), WatchGuard Fireware 11.8 (94%), Synology DiskStation Manager 5.1 (94%), Linux 3.10 (94%), Linux 3.1 - 3.2 (94%), Linux 2.6.32 or 3.10 (94%), Linux 2.6.32 - 2.6.39 (92%), Linux 3.2 - 3.8 (91%)
7489No exact OS matches for host (test conditions non-ideal).
7490Network Distance: 9 hops
7491Service Info: OSs: Unix, Red Hat Enterprise Linux 6; CPE: cpe:/o:redhat:enterprise_linux:6
7492
7493TRACEROUTE (using port 8888/tcp)
7494HOP RTT ADDRESS
74951 110.56 ms 10.13.0.1
74962 110.60 ms 37.187.24.252
74973 110.59 ms 178.33.103.231
74984 112.78 ms 10.95.33.10
74995 117.06 ms 213.251.128.67
75006 ... 8
75019 116.12 ms 95.211.6.26
7502
7503OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7504Nmap done: 1 IP address (1 host up) scanned in 65.98 seconds
7505
7506###########################################################################################
7507
7508amap -i temp.txt
7509amap v5.4 (www.thc.org/thc-amap) started at 2017-09-10 01:09:34 - APPLICATION MAPPING mode
7510
7511Protocol on 95.211.6.26:110/tcp matches pop3
7512Protocol on 95.211.6.26:22/tcp matches ssh
7513Protocol on 95.211.6.26:22/tcp matches ssh-openssh
7514Protocol on 95.211.6.26:21/tcp matches ftp
7515Protocol on 95.211.6.26:80/tcp matches http
7516Protocol on 95.211.6.26:143/tcp matches imap
7517Protocol on 95.211.6.26:3306/tcp matches mysql
7518Protocol on 95.211.6.26:3306/tcp matches mysql-secured
7519Protocol on 95.211.6.26:993/tcp matches ntp
7520Protocol on 95.211.6.26:993/tcp matches ssl
7521Protocol on 95.211.6.26:995/tcp matches ntp
7522Protocol on 95.211.6.26:995/tcp matches ssl
7523Protocol on 95.211.6.26:53/tcp matches dns
7524Protocol on 95.211.6.26:21/tcp matches smtp
7525
7526inetnum: 95.211.4.64 - 95.211.10.255
7527netname: LEASEWEB
7528descr: LeaseWeb Netherlands B.V.
7529remarks: Please send all abuse notifications to the following email address: abuse@nl.leaseweb.com. To ensure proper processing of your abuse notification, please visit the website www.leaseweb.com/abuse for notification requirements. All police and other government agency requests must be sent to subpoenas@nl.leaseweb.com.
7530country: NL
7531admin-c: LSW1-RIPE
7532tech-c: LSW1-RIPE
7533status: ASSIGNED PA
7534mnt-by: LEASEWEB-NL-MNT
7535created: 2012-01-13T11:17:38Z
7536last-modified: 2015-09-30T22:18:28Z
7537source: RIPE
7538
7539person: RIP Mean
7540address: P.O. Box 93054
7541address: 1090BB AMSTERDAM
7542address: Netherlands
7543phone: +31 20 3162880
7544fax-no: +31 20 3162890
7545abuse-mailbox: abuse@nl.leaseweb.com
7546nic-hdl: LSW1-RIPE
7547mnt-by: LEASEWEB-NL-MNT
7548created: 2005-06-07T14:36:03Z
7549last-modified: 2017-03-30T12:29:00Z
7550source: RIPE # Filtered
7551
7552% Information related to '95.211.0.0/16AS60781'
7553
7554route: 95.211.0.0/16
7555descr: LEASEWEB
7556origin: AS60781
7557remarks: LeaseWeb
7558mnt-by: LEASEWEB-NL-MNT
7559created: 2014-03-11T14:28:00Z
7560last-modified: 2015-09-30T23:00:04Z
7561source: RIPE
7562
7563% This query was served by the RIPE Database Query Service version 1.89.2 (HEREFORD)
7564
7565###########################################################################################
7566[i] Scanning Site: http://taboocollections.com
7567
7568
7569
7570B A S I C I N F O
7571====================
7572
7573
7574[+] Site Title: Forbidden Collections
7575[+] IP address: 95.211.6.26
7576[+] Web Server: nginx/1.10.1
7577[+] CMS: Could Not Detect
7578[+] Cloudflare: Not Detected
7579[+] Robots File: Could NOT Find robots.txt!
7580
7581
7582
7583
7584W H O I S L O O K U P
7585========================
7586
7587 Domain Name: TABOOCOLLECTIONS.COM
7588 Registry Domain ID: 1862378478_DOMAIN_COM-VRSN
7589 Registrar WHOIS Server: whois.PublicDomainRegistry.com
7590 Registrar URL: http://www.publicdomainregistry.com
7591 Updated Date: 2017-05-15T09:34:52Z
7592 Creation Date: 2014-06-11T06:02:10Z
7593 Registry Expiry Date: 2018-06-11T06:02:10Z
7594 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
7595 Registrar IANA ID: 303
7596 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
7597 Registrar Abuse Contact Phone: +1.2013775952
7598 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7599 Name Server: NS1.TABOOCOLLECTIONS.COM
7600
7601
7602
7603H T T P H E A D E R S
7604=======================
7605
7606
7607[i] HTTP/1.1 200 OK
7608[i] Server: nginx/1.10.1
7609[i] Date: Sun, 10 Sep 2017 05:08:42 GMT
7610[i] Content-Type: text/html; charset=UTF-8
7611[i] Connection: close
7612[i] X-Powered-By: PHP/5.3.3
7613
7614
7615
7616
7617D N S L O O K U P
7618===================
7619
7620no records found
7621
7622
7623
7624S U B N E T C A L C U L A T I O N
7625====================================
7626
7627Address = 95.211.6.26
7628Network = 95.211.6.26 / 32
7629Netmask = 255.255.255.255
7630Broadcast = not needed on Point-to-Point links
7631Wildcard Mask = 0.0.0.0
7632Hosts Bits = 0
7633Max. Hosts = 1 (2^0 - 0)
7634Host Range = { 95.211.6.26 - 95.211.6.26 }
7635
7636
7637
7638N M A P P O R T S C A N
7639============================
7640
7641
7642Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 05:09 UTC
7643Nmap scan report for taboocollections.com (95.211.6.26)
7644Host is up (0.12s latency).
7645PORT STATE SERVICE VERSION
764621/tcp open ftp ProFTPD or KnFTPD
764722/tcp open ssh OpenSSH 5.3 (protocol 2.0)
764823/tcp closed telnet
764925/tcp open smtp Exim smtpd 4.84_2
765080/tcp open http nginx 1.10.1
7651110/tcp open pop3 Dovecot pop3d
7652143/tcp open imap Dovecot imapd
7653443/tcp closed https
7654445/tcp filtered microsoft-ds
76553389/tcp closed ms-wbt-server
7656Service Info: Host: lcimlw1013.amhost.net; OS: Unix
7657
7658Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7659Nmap done: 1 IP address (1 host up) scanned in 8.86 seconds
7660
7661
7662
7663S U B - D O M A I N F I N D E R
7664==================================
7665
7666
7667[i] Total Subdomains Found : 4
7668
7669[+] Subdomain: taboocollections.com
7670[-] IP: 95.211.6.26
7671
7672[+] Subdomain: ns1.taboocollections.com
7673[-] IP: 95.211.6.26
7674
7675[+] Subdomain: ns2.taboocollections.com
7676[-] IP: 95.211.6.26
7677
7678[+] Subdomain: mail.taboocollections.com
7679[-] IP: 95.211.6.26
7680taboocollections.com
7681[*] Performing TLD Brute force Enumeration against taboocollections.com
7682[*] The operation could take up to: 00:01:07
7683[*] A taboocollections.biz.af 5.45.75.45
7684[*] CNAME taboocollections.biz.at free.biz.at
7685[*] A free.biz.at 216.92.134.29
7686[*] A taboocollections.co.asia 91.195.240.135
7687[*] A taboocollections.org.aw 142.4.20.12
7688[*] A taboocollections.com.ba 195.222.33.180
7689[*] A taboocollections.co.ba 176.9.45.78
7690[*] A taboocollections.com.be 95.173.170.166
7691[*] A taboocollections.biz.by 71.18.52.2
7692[*] A taboocollections.biz.bz 199.59.242.150
7693[*] A taboocollections.com.cc 54.252.107.64
7694[*] A taboocollections.net.cc 54.252.89.206
7695[*] A taboocollections.co.cc 175.126.123.219
7696[*] A taboocollections.org.ch 72.52.4.122
7697[*] A taboocollections.co.cm 85.25.140.105
7698[*] A taboocollections.net.cm 85.25.140.105
7699[*] A taboocollections.biz.cl 185.53.178.8
7700[*] CNAME taboocollections.biz.cm i.cns.cm
7701[*] A i.cns.cm 118.184.56.30
7702[*] A taboocollections.com.com 52.33.196.199
7703[*] A taboocollections.net.com 199.59.242.150
7704[*] A taboocollections.org.com 23.23.86.44
7705[*] A taboocollections.co.com 173.192.115.17
7706[*] A taboocollections.com 95.211.6.26
7707[*] A taboocollections.biz.cr 72.52.4.122
7708[*] A taboocollections.biz.cx 72.52.4.122
7709[*] A taboocollections.biz.cz 185.53.179.7
7710[*] A taboocollections.net.cz 80.250.24.177
7711[*] A taboocollections.com.cz 62.109.128.30
7712[*] CNAME taboocollections.co.de co.de
7713[*] A co.de 144.76.162.245
7714[*] A taboocollections.com.de 50.56.68.37
7715[*] CNAME taboocollections.org.de www.org.de
7716[*] A www.org.de 78.47.128.8
7717[*] A taboocollections.net.eu 78.46.90.98
7718[*] A taboocollections.org.eu 78.46.90.98
7719[*] A taboocollections.biz.fi 185.55.85.123
7720[*] A taboocollections.fm 173.230.131.38
7721[*] A taboocollections.biz.fm 173.230.131.38
7722[*] A taboocollections.org.fr 149.202.133.35
7723[*] A taboocollections.biz.gl 72.52.4.122
7724[*] CNAME taboocollections.co.gp co.gp
7725[*] A co.gp 144.76.162.245
7726[*] A taboocollections.co.hn 208.100.40.203
7727[*] CNAME taboocollections.net.hr net.hr
7728[*] A net.hr 192.0.78.24
7729[*] A net.hr 192.0.78.25
7730[*] CNAME taboocollections.biz.hn parkmydomain.vhostgo.com
7731[*] A parkmydomain.vhostgo.com 107.186.245.118
7732[*] A taboocollections.co.ht 72.52.4.122
7733[*] A taboocollections.co.jobs 50.17.193.222
7734[*] A taboocollections.com.jobs 50.19.241.165
7735[*] A taboocollections.net.jobs 50.19.241.165
7736[*] A taboocollections.org.jobs 50.19.241.165
7737[*] A taboocollections.biz.jobs 50.19.241.165
7738[*] A taboocollections.biz.ky 199.184.144.27
7739[*] CNAME taboocollections.biz.li 712936.parkingcrew.net
7740[*] A 712936.parkingcrew.net 185.53.179.29
7741[*] A taboocollections.biz.lu 195.26.5.2
7742[*] A taboocollections.biz.ly 64.136.20.39
7743[*] A taboocollections.biz.md 72.52.4.122
7744[*] A taboocollections.co.mk 87.76.31.211
7745[*] A taboocollections.biz.my 202.190.174.44
7746[*] A taboocollections.co.mobi 54.225.105.179
7747[*] A taboocollections.co.net 188.166.216.219
7748[*] A taboocollections.net.net 52.50.81.210
7749[*] A taboocollections.org.net 23.23.86.44
7750[*] A taboocollections.co.nl 37.97.184.204
7751[*] A taboocollections.com.nl 83.98.157.102
7752[*] A taboocollections.net.nl 83.98.157.102
7753[*] A taboocollections.co.nr 208.100.40.202
7754[*] CNAME taboocollections.co.nu co.nu
7755[*] A co.nu 144.76.162.245
7756[*] CNAME taboocollections.com.nu com.nu
7757[*] A com.nu 144.76.162.245
7758[*] A taboocollections.org.nu 80.92.84.139
7759[*] A taboocollections.net.nu 199.102.76.78
7760[*] A taboocollections.com.org 23.23.86.44
7761[*] CNAME taboocollections.net.org pewtrusts.org
7762[*] A pewtrusts.org 204.74.99.100
7763[*] A taboocollections.ph 45.79.222.138
7764[*] A taboocollections.co.ph 45.79.222.138
7765[*] A taboocollections.com.ph 45.79.222.138
7766[*] A taboocollections.net.ph 45.79.222.138
7767[*] A taboocollections.org.ph 45.79.222.138
7768[*] A taboocollections.co.pl 212.91.6.55
7769[*] A taboocollections.org.pm 208.73.210.217
7770[*] A taboocollections.org.pm 208.73.210.202
7771[*] A taboocollections.org.pm 208.73.211.177
7772[*] A taboocollections.org.pm 208.73.211.165
7773[*] A taboocollections.co.ps 66.96.132.56
7774[*] CNAME taboocollections.biz.ps biz.ps
7775[*] A biz.ps 144.76.162.245
7776[*] A taboocollections.co.pt 194.107.127.52
7777[*] A taboocollections.pw 141.8.226.58
7778[*] A taboocollections.co.pw 141.8.226.59
7779[*] A taboocollections.net.pw 141.8.226.59
7780[*] A taboocollections.biz.pw 141.8.226.59
7781[*] A taboocollections.org.pw 141.8.226.59
7782[*] CNAME taboocollections.co.ro now.co.ro
7783[*] A now.co.ro 185.27.255.9
7784[*] A taboocollections.net.ro 69.64.52.127
7785[*] A taboocollections.org.re 217.70.184.38
7786[*] A taboocollections.com.ru 178.210.89.119
7787[*] A taboocollections.biz.se 185.53.179.6
7788[*] CNAME taboocollections.net.se 773147.parkingcrew.net
7789[*] A 773147.parkingcrew.net 185.53.179.29
7790[*] A taboocollections.co.sl 91.195.240.135
7791[*] A taboocollections.com.sr 143.95.106.249
7792[*] A taboocollections.biz.st 91.121.28.115
7793[*] A taboocollections.co.su 72.52.4.122
7794[*] A taboocollections.biz.tc 64.136.20.39
7795[*] A taboocollections.biz.tf 85.236.153.18
7796[*] A taboocollections.net.tf 188.40.70.27
7797[*] A taboocollections.net.tf 188.40.70.29
7798[*] A taboocollections.net.tf 188.40.117.12
7799[*] A taboocollections.co.tl 208.100.40.202
7800[*] A taboocollections.co.to 175.118.124.44
7801[*] A taboocollections.co.tv 31.186.25.163
7802[*] A taboocollections.biz.tv 72.52.4.122
7803[*] A taboocollections.org.tv 72.52.4.122
7804[*] CNAME taboocollections.biz.uz biz.uz
7805[*] A biz.uz 144.76.162.245
7806[*] A taboocollections.vg 88.198.29.97
7807[*] A taboocollections.co.vg 88.198.29.97
7808[*] A taboocollections.com.vg 88.198.29.97
7809[*] A taboocollections.net.vg 68.178.254.180
7810[*] A taboocollections.biz.vg 89.31.143.20
7811[*] A taboocollections.ws 64.70.19.203
7812[*] A taboocollections.com.ws 202.4.48.211
7813[*] A taboocollections.net.ws 202.4.48.211
7814[*] A taboocollections.org.ws 202.4.48.211
7815[*] A taboocollections.biz.ws 184.168.221.104
7816 Domain Name: TABOOCOLLECTIONS.COM
7817 Registry Domain ID: 1862378478_DOMAIN_COM-VRSN
7818 Registrar WHOIS Server: whois.PublicDomainRegistry.com
7819 Registrar URL: http://www.publicdomainregistry.com
7820 Updated Date: 2017-05-15T09:34:52Z
7821 Creation Date: 2014-06-11T06:02:10Z
7822 Registry Expiry Date: 2018-06-11T06:02:10Z
7823 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
7824 Registrar IANA ID: 303
7825 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
7826 Registrar Abuse Contact Phone: +1.2013775952
7827 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7828 Name Server: NS1.TABOOCOLLECTIONS.COM
7829
7830Domain Name: TABOOCOLLECTIONS.COM
7831Registry Domain ID: 1862378478_DOMAIN_COM-VRSN
7832Registrar WHOIS Server: whois.publicdomainregistry.com
7833Registrar URL: www.publicdomainregistry.com
7834Updated Date: 2017-05-15T09:34:52Z
7835Creation Date: 2014-06-11T06:02:10Z
7836Registrar Registration Expiration Date: 2018-06-11T06:02:10Z
7837Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
7838Registrar IANA ID: 303
7839Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7840Registry Registrant ID: Not Available From Registry
7841Registrant Name: Domain Admin
7842Registrant Organization: Privacy Protect, LLC (PrivacyProtect.org)
7843Registrant Street: 10 Corporate Drive
7844Registrant City: Burlington
7845Registrant State/Province: MA
7846Registrant Postal Code: 01803
7847Registrant Country: US
7848Registrant Phone: +1.8022274003
7849Registrant Phone Ext:
7850Registrant Fax:
7851Registrant Fax Ext:
7852Registrant Email: contact@privacyprotect.org
7853Registry Admin ID: Not Available From Registry
7854Admin Name: Domain Admin
7855Admin Organization: Privacy Protect, LLC (PrivacyProtect.org)
7856Admin Street: 10 Corporate Drive
7857Admin City: Burlington
7858Admin State/Province: MA
7859Admin Postal Code: 01803
7860Admin Country: US
7861Admin Phone: +1.8022274003
7862Admin Phone Ext:
7863Admin Fax:
7864Admin Fax Ext:
7865Admin Email: contact@privacyprotect.org
7866Registry Tech ID: Not Available From Registry
7867Tech Name: Domain Admin
7868Tech Organization: Privacy Protect, LLC (PrivacyProtect.org)
7869Tech Street: 10 Corporate Drive
7870Tech City: Burlington
7871Tech State/Province: MA
7872Tech Postal Code: 01803
7873Tech Country: US
7874Tech Phone: +1.8022274003
7875Tech Phone Ext:
7876Tech Fax:
7877Tech Fax Ext:
7878Tech Email: contact@privacyprotect.org
7879Name Server: ns1.taboocollections.com
7880DNSSEC:Unsigned
7881Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
7882Registrar Abuse Contact Phone: +1.2013775952
7883
7884;taboocollections.com. IN ANY
7885
7886;; ANSWER SECTION:
7887taboocollections.com. 3584 IN MX 10 mail.taboocollections.com.
7888taboocollections.com. 3584 IN MX 20 mail.taboocollections.com.
7889taboocollections.com. 3477 IN A 95.211.6.26
7890taboocollections.com. 3584 IN NS ns2.taboocollections.com.
7891taboocollections.com. 3584 IN NS ns1.taboocollections.com.
7892
7893
7894----- taboocollections.com -----
7895
7896
7897Host's addresses:
7898__________________
7899
7900taboocollections.com. 3443 IN A 95.211.6.26
7901
7902
7903Name Servers:
7904______________
7905
7906ns1.taboocollections.com. 3600 IN A 95.211.6.26
7907ns2.taboocollections.com. 3600 IN A 95.211.6.26
7908
7909
7910Mail (MX) Servers:
7911___________________
7912
7913mail.taboocollections.com. 3600 IN A 95.211.6.26
7914mail.taboocollections.com. 3600 IN A 95.211.6.26
7915
7916
7917Trying Zone Transfers and getting Bind Versions:
7918_________________________________________________
7919
7920
7921Trying Zone Transfer for taboocollections.com on ns2.taboocollections.com ...
7922taboocollections.com. 3600 IN SOA (
7923taboocollections.com. 3600 IN NS ns1.taboocollections.com.
7924taboocollections.com. 3600 IN NS ns2.taboocollections.com.
7925taboocollections.com. 3600 IN TXT "v=spf1
7926taboocollections.com. 3600 IN MX 10
7927taboocollections.com. 3600 IN MX 20
7928taboocollections.com. 3600 IN A 95.211.6.26
7929ftp.taboocollections.com. 3600 IN A 95.211.6.26
7930mail.taboocollections.com. 3600 IN A 95.211.6.26
7931ns1.taboocollections.com. 3600 IN A 95.211.6.26
7932ns2.taboocollections.com. 3600 IN A 95.211.6.26
7933pop.taboocollections.com. 3600 IN A 95.211.6.26
7934smtp.taboocollections.com. 3600 IN A 95.211.6.26
7935www.taboocollections.com. 3600 IN A 95.211.6.26
7936
7937Trying Zone Transfer for taboocollections.com on ns1.taboocollections.com ...
7938taboocollections.com. 3600 IN SOA (
7939taboocollections.com. 3600 IN NS ns1.taboocollections.com.
7940taboocollections.com. 3600 IN NS ns2.taboocollections.com.
7941taboocollections.com. 3600 IN TXT "v=spf1
7942taboocollections.com. 3600 IN MX 10
7943taboocollections.com. 3600 IN MX 20
7944taboocollections.com. 3600 IN A 95.211.6.26
7945ftp.taboocollections.com. 3600 IN A 95.211.6.26
7946mail.taboocollections.com. 3600 IN A 95.211.6.26
7947ns1.taboocollections.com. 3600 IN A 95.211.6.26
7948ns2.taboocollections.com. 3600 IN A 95.211.6.26
7949pop.taboocollections.com. 3600 IN A 95.211.6.26
7950smtp.taboocollections.com. 3600 IN A 95.211.6.26
7951www.taboocollections.com. 3600 IN A 95.211.6.26
7952
7953
7954
7955
7956Performing recursion:
7957______________________
7958
7959
7960 ---- Checking subdomains NS records ----
7961
7962 Can't perform recursion no NS records.
7963
7964
7965taboocollections.com class C netranges:
7966________________________________________
7967
7968 95.211.6.0/24
7969
7970
7971Performing reverse lookup on 256 ip addresses:
7972_______________________________________________
7973
7974
79750 results out of 256 IP addresses.
7976
7977
7978taboocollections.com ip blocks:
7979________________________________
7980
7981
7982done.
7983
7984
7985dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
7986
7987[+] searching (sub)domains for taboocollections.com using built-in wordlist
7988[+] using maximum random delay of 10 millisecond(s) between requests
7989
7990ftp.taboocollections.com
7991IP address #1: 95.211.6.26
7992
7993mail.taboocollections.com
7994IP address #1: 95.211.6.26
7995
7996ns1.taboocollections.com
7997IP address #1: 95.211.6.26
7998
7999ns2.taboocollections.com
8000IP address #1: 95.211.6.26
8001
8002pop.taboocollections.com
8003IP address #1: 95.211.6.26
8004
8005smtp.taboocollections.com
8006IP address #1: 95.211.6.26
8007
8008www.taboocollections.com
8009IP address #1: 95.211.6.26
8010
8011[+] 7 (sub)domains and 7 IP address(es) found
8012[+] completion time: 154 second(s)
8013
8014
8015Tracing to taboocollections.com[a] via 192.168.1.254, maximum of 3 retries
8016192.168.1.254 (192.168.1.254) Got answer
8017
8018
8019WhatWeb report for http://taboocollections.com
8020Status : 200 OK
8021Title : Forbidden Collections
8022IP : 95.211.6.26
8023Country : NETHERLANDS, NL
8024
8025Summary : X-Powered-By[PHP/5.3.3], Email[martincatalog[at]gmail.com], HTTPServer[nginx/1.10.1], PHP[5.3.3], nginx[1.10.1], Script[text/javascript]
8026
8027Detected Plugins:
8028[ Email ]
8029 Extract email addresses. Find valid email address and
8030 syntactically invalid email addresses from mailto: link
8031 tags. We match syntactically invalid links containing
8032 mailto: to catch anti-spam email addresses, eg. bob at
8033 gmail.com. This uses the simplified email regular
8034 expression from
8035 http://www.regular-expressions.info/email.html for valid
8036 email address matching.
8037
8038 String : martincatalog[at]gmail.com
8039
8040[ HTTPServer ]
8041 HTTP server header string. This plugin also attempts to
8042 identify the operating system from the server header.
8043
8044 String : nginx/1.10.1 (from server string)
8045
8046[ PHP ]
8047 PHP is a widely-used general-purpose scripting language
8048 that is especially suited for Web development and can be
8049 embedded into HTML. This plugin identifies PHP errors,
8050 modules and versions and extracts the local file path and
8051 username if present.
8052
8053 Version : 5.3.3
8054 Google Dorks: (2)
8055 Website : http://www.php.net/
8056
8057[ Script ]
8058 This plugin detects instances of script HTML elements and
8059 returns the script language/type.
8060
8061 String : text/javascript
8062
8063[ X-Powered-By ]
8064 X-Powered-By HTTP header
8065
8066 String : PHP/5.3.3 (from x-powered-by string)
8067
8068[ nginx ]
8069 Nginx (Engine-X) is a free, open-source, high-performance
8070 HTTP server and reverse proxy, as well as an IMAP/POP3
8071 proxy server.
8072
8073 Version : 1.10.1
8074 Website : http://nginx.net/
8075
8076HTTP Headers:
8077 HTTP/1.1 200 OK
8078 Server: nginx/1.10.1
8079 Date: Sun, 10 Sep 2017 05:13:02 GMT
8080 Content-Type: text/html; charset=UTF-8
8081 Transfer-Encoding: chunked
8082 Connection: close
8083 X-Powered-By: PHP/5.3.3
8084
8085
8086------------------------------------
8087[-] Resolving hostnames IPs...
808895.211.6.26:mail.taboocollections.com
808995.211.6.26:ns1.taboocollections.com
809095.211.6.26:ns2.taboocollections.com
809195.211.6.26:www.taboocollections.com
8092
8093
8094
8095 ^ ^
8096 _ __ _ ____ _ __ _ _ ____
8097 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
8098 | V V // o // _/ | V V // 0 // 0 // _/
8099 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
8100 <
8101 ...'
8102
8103 WAFW00F - Web Application Firewall Detection Tool
8104
8105 By Sandro Gauci && Wendel G. Henrique
8106
8107Checking http://taboocollections.com
8108Generic Detection results:
8109No WAF detected by the generic detection
8110Number of requests: 13
8111
8112
8113DNS Servers for taboocollections.com:
8114 ns2.taboocollections.com
8115 ns1.taboocollections.com
8116
8117Trying zone transfer first...
8118 Testing ns2.taboocollections.com
8119
8120Whoah, it worked - misconfigured DNS server found:
8121taboocollections.com. 3600 IN SOA ( lcimlw1013.amhost.net. root.example.com.
8122 2016091605 ;serial
8123 10800 ;refresh
8124 3600 ;retry
8125 604800 ;expire
8126 86400 ;minimum
8127 )
8128taboocollections.com. 3600 IN NS ns1.taboocollections.com.
8129taboocollections.com. 3600 IN NS ns2.taboocollections.com.
8130taboocollections.com. 3600 IN TXT "v=spf1 ip4:95.211.6.25 a mx ~all"
8131taboocollections.com. 3600 IN MX 10 mail.taboocollections.com.
8132taboocollections.com. 3600 IN MX 20 mail.taboocollections.com.
8133taboocollections.com. 3600 IN A 95.211.6.26
8134ftp.taboocollections.com. 3600 IN A 95.211.6.26
8135mail.taboocollections.com. 3600 IN A 95.211.6.26
8136ns1.taboocollections.com. 3600 IN A 95.211.6.26
8137ns2.taboocollections.com. 3600 IN A 95.211.6.26
8138pop.taboocollections.com. 3600 IN A 95.211.6.26
8139smtp.taboocollections.com. 3600 IN A 95.211.6.26
8140www.taboocollections.com. 3600 IN A 95.211.6.26
8141
8142
8143Checking for HTTP-Loadbalancing [Date]: 05:13:58, 05:13:59, 05:13:59, 05:13:59, 05:13:59, 05:14:00, 05:14:00, 05:14:00, 05:14:00, 05:14:01, 05:14:01, 05:14:01, 05:14:02, 05:14:02, 05:14:02, 05:14:02, 05:14:03, 05:14:03, 05:14:03, 05:14:03, 05:14:04, 05:14:04, 05:14:04, 05:14:04, 05:14:05, 05:14:05, 05:14:05, 05:14:05, 05:14:06, 05:14:06, 05:14:06, 05:14:07, 05:14:07, 05:14:07, 05:14:07, 05:14:08, 05:14:08, 05:14:08, 05:14:10, 05:14:11, 05:14:11, 05:14:11, 05:14:11, 05:14:12, 05:14:12, 05:14:12, 05:14:12, 05:14:13, 05:14:13, 05:14:13, NOT FOUND
8144
8145Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
8146
8147taboocollections.com does NOT use Load-balancing.
8148
8149
8150
8151Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
8152
8153 ----------------------------------------------------------
8154| Scan Information |
8155 ----------------------------------------------------------
8156
8157Mode ..................... VRFY
8158Worker Processes ......... 5
8159Usernames file ........... users.txt
8160Target count ............. 1
8161Username count ........... 494
8162Target TCP port .......... 25
8163Query timeout ............ 5 secs
8164Target domain ............
8165
8166######## Scan started at Sun Sep 10 01:14:27 2017 #########
8167######## Scan completed at Sun Sep 10 01:22:42 2017 #########
81680 results.
8169
8170494 queries in 495 seconds (1.0 queries / sec)
8171
8172
8173
8174Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 01:22 EDT
8175NSE: Loaded 146 scripts for scanning.
8176NSE: Script Pre-scanning.
8177Initiating NSE at 01:22
8178Completed NSE at 01:22, 0.00s elapsed
8179Initiating NSE at 01:22
8180Completed NSE at 01:22, 0.00s elapsed
8181Failed to resolve "taboocollections.com.txt".
8182Initiating Parallel DNS resolution of 1 host. at 01:22
8183Completed Parallel DNS resolution of 1 host. at 01:22, 0.74s elapsed
8184Initiating SYN Stealth Scan at 01:22
8185Scanning taboocollections.com (95.211.6.26) [100 ports]
8186Discovered open port 3306/tcp on 95.211.6.26
8187Discovered open port 21/tcp on 95.211.6.26
8188Discovered open port 143/tcp on 95.211.6.26
8189Discovered open port 995/tcp on 95.211.6.26
8190Discovered open port 993/tcp on 95.211.6.26
8191Discovered open port 53/tcp on 95.211.6.26
8192Discovered open port 80/tcp on 95.211.6.26
8193Discovered open port 110/tcp on 95.211.6.26
8194Discovered open port 22/tcp on 95.211.6.26
8195Completed SYN Stealth Scan at 01:22, 3.39s elapsed (100 total ports)
8196Initiating Service scan at 01:22
8197Scanning 9 services on taboocollections.com (95.211.6.26)
8198Completed Service scan at 01:22, 7.78s elapsed (9 services on 1 host)
8199Initiating OS detection (try #1) against taboocollections.com (95.211.6.26)
8200adjust_timeouts2: packet supposedly had rtt of -134600 microseconds. Ignoring time.
8201adjust_timeouts2: packet supposedly had rtt of -134600 microseconds. Ignoring time.
8202Retrying OS detection (try #2) against taboocollections.com (95.211.6.26)
8203WARNING: OS didn't match until try #2
8204Initiating Traceroute at 01:23
8205Completed Traceroute at 01:23, 3.01s elapsed
8206Initiating Parallel DNS resolution of 6 hosts. at 01:23
8207Completed Parallel DNS resolution of 6 hosts. at 01:23, 5.51s elapsed
8208NSE: Script scanning 95.211.6.26.
8209Initiating NSE at 01:23
8210Completed NSE at 01:24, 54.95s elapsed
8211Initiating NSE at 01:24
8212Completed NSE at 01:24, 0.01s elapsed
8213Nmap scan report for taboocollections.com (95.211.6.26)
8214Host is up (0.13s latency).
8215Not shown: 85 closed ports
8216PORT STATE SERVICE VERSION
821721/tcp open ftp ProFTPD or KnFTPD
821822/tcp open ssh OpenSSH 5.3 (protocol 2.0)
8219| ssh-hostkey:
8220| 1024 21:60:f8:65:40:1c:3d:09:03:41:3a:fe:c4:e9:2c:ed (DSA)
8221|_ 2048 9b:53:08:ca:5f:13:2e:02:17:b0:f5:51:57:2d:38:56 (RSA)
822225/tcp filtered smtp
822353/tcp open domain ISC BIND 9.8.2rc1
8224| dns-nsid:
8225|_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6
822680/tcp open http nginx 1.10.1
8227| http-methods:
8228|_ Supported Methods: GET HEAD
8229|_http-title: Forbidden Collections
8230110/tcp open pop3 Dovecot pop3d
8231135/tcp filtered msrpc
8232139/tcp filtered netbios-ssn
8233143/tcp open imap Dovecot imapd
8234445/tcp filtered microsoft-ds
8235465/tcp filtered smtps
8236587/tcp filtered submission
8237993/tcp open ssl/imap Dovecot imapd
8238| ssl-cert: Subject: commonName=lcimlw1013.amhost.net/organizationName=XX/stateOrProvinceName=XX/countryName=XX
8239| Issuer: commonName=lcimlw1013.amhost.net/organizationName=XX/stateOrProvinceName=XX/countryName=XX
8240| Public Key type: rsa
8241| Public Key bits: 1024
8242| Signature Algorithm: sha1WithRSAEncryption
8243| Not valid before: 2016-09-15T16:10:31
8244| Not valid after: 2026-09-13T16:10:31
8245| MD5: d23a 521b 25a2 0835 e460 b409 de75 734b
8246|_SHA-1: 91a1 ecac bddb b6d1 2446 a4fa 3aeb e6f0 1189 561b
8247995/tcp open ssl/pop3 Dovecot pop3d
8248| ssl-cert: Subject: commonName=lcimlw1013.amhost.net/organizationName=XX/stateOrProvinceName=XX/countryName=XX
8249| Issuer: commonName=lcimlw1013.amhost.net/organizationName=XX/stateOrProvinceName=XX/countryName=XX
8250| Public Key type: rsa
8251| Public Key bits: 1024
8252| Signature Algorithm: sha1WithRSAEncryption
8253| Not valid before: 2016-09-15T16:10:31
8254| Not valid after: 2026-09-13T16:10:31
8255| MD5: d23a 521b 25a2 0835 e460 b409 de75 734b
8256|_SHA-1: 91a1 ecac bddb b6d1 2446 a4fa 3aeb e6f0 1189 561b
8257|_ssl-date: 2017-09-10T05:23:10+00:00; -5s from scanner time.
82583306/tcp open mysql MySQL (unauthorized)
8259Device type: general purpose
8260Running: Linux 2.6.X
8261OS CPE: cpe:/o:linux:linux_kernel:2.6.39
8262OS details: Linux 2.6.39
8263Uptime guess: 20.152 days (since Sun Aug 20 21:45:18 2017)
8264Network Distance: 9 hops
8265TCP Sequence Prediction: Difficulty=262 (Good luck!)
8266IP ID Sequence Generation: All zeros
8267Service Info: OSs: Unix, Red Hat Enterprise Linux 6; CPE: cpe:/o:redhat:enterprise_linux:6
8268
8269Host script results:
8270|_clock-skew: mean: -5s, deviation: 0s, median: -5s
8271
8272TRACEROUTE (using port 199/tcp)
8273HOP RTT ADDRESS
82741 110.41 ms 10.13.0.1
82752 110.64 ms 37.187.24.252
82763 110.45 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
82774 112.18 ms 10.95.33.10
82785 152.48 ms be100-1112.ams-5-a9.nl.eu (213.251.128.67)
82796 ... 8
82809 115.95 ms 95.211.6.26
8281
8282NSE: Script Post-scanning.
8283Initiating NSE at 01:24
8284Completed NSE at 01:24, 0.00s elapsed
8285Initiating NSE at 01:24
8286Completed NSE at 01:24, 0.00s elapsed
8287Read data files from: /usr/bin/../share/nmap
8288OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
8289Nmap done: 1 IP address (1 host up) scanned in 82.87 seconds
8290 Raw packets sent: 306 (18.752KB) | Rcvd: 298 (19.157KB)
8291
8292 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
8293 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
8294 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
8295 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
8296 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
8297
8298 _/ User-Agent Tester ↵
8299 _/ AKA: Purple Pimp ↵
8300 _/ ChrisJohnRiley ↵
8301 _/ blog.c22.cc ↵
8302
8303 [>] Performing initial request and confirming stability
8304 [>] Using User-Agent string Mozilla/5.0
8305
8306 [ ] URL (ENTERED): http://taboocollections.com
8307 [ ] Response Code: 200 OK
8308 [ ] Server: nginx/1.10.1
8309 [ ] Date: Sun, 10 Sep 2017 05:24:10 GMT
8310 [ ] Content-Type: text/html; charset=UTF-8
8311 [ ] Transfer-Encoding: chunked
8312 [ ] Connection: close
8313 [ ] X-Powered-By: PHP/5.3.3
8314 [ ] Data (MD5): 04b5a3042fbd56b56fd51297c0960bf8
8315
8316 [1] Pass
8317 [2] Pass
8318 [3] Pass
8319
8320 [>] URL appears stable. Beginning test
8321
8322 [>] Using DEFAULT User-Agent Strings
8323
8324 [>] Using Crazy User-Agent Strings
8325 [>] Using Bot User-Agent Strings
8326
8327 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
8328
8329
8330 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
8331
8332
8333 [!] Data (MD5): 9af566dcae9e8ebef048d13cfb1c8667
8334
8335
8336 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
8337
8338
8339 [!] Data (MD5): bb1ba681cf04eb960c7c5c5ffbe01afd
8340
8341
8342 [>] User-Agent String : TrackBack/1.02
8343
8344
8345 [!] Data (MD5): 27b026d60b3fc3818287bfb92ed73318
8346
8347
8348 [>] User-Agent String : wispr
8349
8350
8351 [!] Data (MD5): dcd7ea082bf6cda6e1bf3bad42220e0b
8352
8353
8354 [>] User-Agent String : EMPTY USER-AGENT STRING!
8355
8356
8357 [!] Data (MD5): 1b482bd6ce61d4a5bff759c191ec3a1f
8358
8359
8360 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
8361
8362
8363 [!] Data (MD5): c9a6a1f86dabf98ad4673cc1333b77fd
8364
8365
8366 [>] User-Agent String : Googlebot-Image/1.0
8367
8368
8369 [!] Data (MD5): 1f46250e48bfcd75c10b50828f5ecd42
8370
8371
8372 [>] User-Agent String : Mediapartners-Google
8373
8374
8375 [!] Data (MD5): 2647898c55bd3a9e51d7a35d194a93ef
8376
8377
8378 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
8379
8380
8381 [!] Data (MD5): f37ab32127dfe2114969ab4138a24240
8382
8383
8384 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
8385
8386
8387 [!] Data (MD5): 1d80c29a4884eb5b697f3f3f071e1ea2
8388
8389
8390 [>] User-Agent String : mmcrawler
8391
8392
8393 [!] Data (MD5): fc94e253b00a032df75773caa8d3168a
8394
8395
8396 [>] Checks completed... try enabling VERBOSE mode for more detailed output
8397
8398 [>] That's all folks... Fo' Shizzle!
8399#########################################################################################
8400Hostname young-holes.net ISP Host Sailor Ltd. (AS60117)
8401Continent Europe Flag
8402NL
8403Country Netherlands Country Code NL (NLD)
8404Region 07 Local time 10 Sep 2017 07:20 CEST
8405Metropolis Unknown Postal Code 1091
8406City Amsterdam Latitude 52.35
8407IP Address 185.82.203.139 Longitude 4.917
8408########################################################################################
8409young-holes.net
8410
8411###########################################################################################
8412
8413whois young-holes.net
8414 Domain Name: YOUNG-HOLES.NET
8415 Registry Domain ID: 1971134373_DOMAIN_NET-VRSN
8416 Registrar WHOIS Server: whois.namesilo.com
8417 Registrar URL: http://www.namesilo.com
8418 Updated Date: 2017-04-05T01:17:04Z
8419 Creation Date: 2015-10-23T08:08:22Z
8420 Registry Expiry Date: 2017-10-23T08:08:22Z
8421 Registrar: NameSilo, LLC
8422 Registrar IANA ID: 1479
8423 Registrar Abuse Contact Email: abuse@namesilo.com
8424 Registrar Abuse Contact Phone: +1.4805240066
8425 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
8426 Name Server: NS1.DNSOWL.COM
8427 Name Server: NS2.DNSOWL.COM
8428 Name Server: NS3.DNSOWL.COM
8429 DNSSEC: unsigned
8430
8431Domain Name: young-holes.net
8432Registry Domain ID: 1971134373_DOMAIN_NET-VRSN
8433Registrar WHOIS Server: whois.namesilo.com
8434Registrar URL: https://www.namesilo.com/
8435Updated Date: 2017-09-06
8436Creation Date: 2015-10-23
8437Registrar Registration Expiration Date: 2017-10-23
8438Registrar: NameSilo, LLC
8439Registrar IANA ID: 1479
8440Registrar Abuse Contact Email: abuse@namesilo.com
8441Registrar Abuse Contact Phone: +1.4805240066
8442Status: clientTransferProhibited
8443Registry Registrant ID:
8444Registrant Name: Domain Administrator
8445Registrant Organization: See PrivacyGuardian.org
8446Registrant Street: 1928 E. Highland Ave. Ste F104 PMB# 255
8447Registrant City: Phoenix
8448Registrant State/Province: AZ
8449Registrant Postal Code: 85016
8450Registrant Country: US
8451Registrant Phone: +1.3478717726
8452Registrant Phone Ext:
8453Registrant Fax:
8454Registrant Fax Ext:
8455Registrant Email: pw-e7629bed44d86f8a91043903b3f5ab96@privacyguardian.org
8456Registry Admin ID:
8457Admin Name: Domain Administrator
8458Admin Organization: See PrivacyGuardian.org
8459Admin Street: 1928 E. Highland Ave. Ste F104 PMB# 255
8460Admin City: Phoenix
8461Admin State/Province: AZ
8462Admin Postal Code: 85016
8463Admin Country: US
8464Admin Phone: +1.3478717726
8465Admin Phone Ext:
8466Admin Fax:
8467Admin Fax Ext:
8468Admin Email: pw-e7629bed44d86f8a91043903b3f5ab96@privacyguardian.org
8469Registry Tech ID:
8470Tech Name: Domain Administrator
8471Tech Organization: See PrivacyGuardian.org
8472Tech Street: 1928 E. Highland Ave. Ste F104 PMB# 255
8473Tech City: Phoenix
8474Tech State/Province: AZ
8475Tech Postal Code: 85016
8476Tech Country: US
8477Tech Phone: +1.3478717726
8478Tech Phone Ext:
8479Tech Fax:
8480Tech Fax Ext:
8481Tech Email: pw-e7629bed44d86f8a91043903b3f5ab96@privacyguardian.org
8482Name Server: ns1.dnsowl.com
8483Name Server: ns2.dnsowl.com
8484Name Server: ns3.dnsowl.com
8485
8486
8487###########################################################################################
8488
8489dig young-holes.net any
8490
8491; <<>> DiG 9.10.3-P4-Debian <<>> young-holes.net any
8492;; global options: +cmd
8493;; Got answer:
8494;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25367
8495;; flags: qr rd ra; QUERY: 1, ANSWER: 4, AUTHORITY: 0, ADDITIONAL: 1
8496
8497;; OPT PSEUDOSECTION:
8498; EDNS: version: 0, flags:; udp: 4096
8499;; QUESTION SECTION:
8500;young-holes.net. IN ANY
8501
8502;; ANSWER SECTION:
8503young-holes.net. 172660 IN A 185.82.203.139
8504young-holes.net. 172644 IN NS ns3.dnsowl.com.
8505young-holes.net. 172644 IN NS ns1.dnsowl.com.
8506young-holes.net. 172644 IN NS ns2.dnsowl.com.
8507
8508;; Query time: 8 msec
8509;; SERVER: 192.168.1.254#53(192.168.1.254)
8510;; WHEN: Sun Sep 10 01:22:15 EDT 2017
8511;; MSG SIZE rcvd: 124
8512
8513###########################################################################################
8514
8515host -l young-holes.net
8516
8517;; Connection to 192.168.1.254#53(192.168.1.254) for young-holes.net failed: connection refused.
8518Host young-holes.net not found: 9(NOTAUTH)
8519; Transfer failed.
8520
8521###########################################################################################
8522
8523tcptraceroute -i eth0 young-holes.net
8524
8525Running:
8526 traceroute -T -O info -i eth0 young-holes.net
8527traceroute to young-holes.net (185.82.203.139), 30 hops max, 60 byte packets
8528 1 gateway (192.168.1.254) 0.433 ms 0.595 ms 0.758 ms
8529 2 10.135.18.1 (10.135.18.1) 6.887 ms 7.346 ms 7.427 ms
8530 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 29.557 ms 29.831 ms 30.166 ms
8531 4 ae4-1.nyk10.core-backbone.com (206.130.10.42) 30.308 ms 30.441 ms 30.566 ms
8532 5 ae3-2072.ams10.core-backbone.com (80.255.15.165) 106.781 ms 106.814 ms 106.993 ms
8533 6 core-backbone.nforce.com (5.56.18.71) 108.720 ms 112.500 ms 106.703 ms
8534 7 46.166.186.129 (46.166.186.129) 106.109 ms 106.235 ms 106.174 ms
8535 8 dedi21685.hostsailor.com (185.82.203.139) <syn,ack> 105.127 ms 104.670 ms 106.949 ms
8536
8537###########################################################################################
8538
8539cd /pentest/enumeration/dnsenum
8540perl dnsenum.pl --enum -f dns.txt --update a -r young-holes.net
8541
8542./Recon.sh: ligne 44 : cd: /pentest/enumeration/dnsenum: Aucun fichier ou dossier de ce type
8543Can't open perl script "dnsenum.pl": Aucun fichier ou dossier de ce type
8544
8545###########################################################################################
8546
8547###########################################################################################
8548
8549nmap -PN -n -F -T4 -sV -A -oG temp.txt young-holes.net
8550
8551Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 01:23 EDT
8552Nmap scan report for young-holes.net (185.82.203.139)
8553Host is up (0.12s latency).
8554Not shown: 84 closed ports
8555PORT STATE SERVICE VERSION
855621/tcp open ftp Pure-FTPd
8557|_ssl-date: 2017-09-10T05:21:58+00:00; -2m13s from scanner time.
855822/tcp open ssh OpenSSH 5.3 (protocol 2.0)
8559| ssh-hostkey:
8560| 1024 7b:41:fb:d8:5e:04:70:a2:78:ee:38:4c:97:42:9b:49 (DSA)
8561|_ 2048 5f:d2:a2:cd:01:76:d6:52:11:db:7f:21:8a:80:b5:6e (RSA)
856225/tcp filtered smtp
856353/tcp open domain
8564| dns-nsid:
8565|_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6_8.3
856680/tcp open ssl/http Apache/2
8567|_http-server-header: Apache/2
8568|_http-title: Young Holes
8569110/tcp open pop3 Dovecot DirectAdmin pop3d
8570|_ssl-date: 2017-09-10T05:21:55+00:00; -2m13s from scanner time.
8571135/tcp filtered msrpc
8572139/tcp filtered netbios-ssn
8573143/tcp open imap
8574| fingerprint-strings:
8575| GenericLines, GetRequest, NULL:
8576|_ * OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE STARTTLS AUTH=PLAIN] Dovecot DA ready.
8577| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
8578| Not valid before: 2016-05-13T00:22:04
8579|_Not valid after: 2043-09-28T00:22:04
8580|_ssl-date: 2017-09-10T05:21:56+00:00; -2m13s from scanner time.
8581443/tcp open ssl/https Apache/2
8582|_http-server-header: Apache/2
8583|_http-title: 400 Bad Request
8584| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
8585| Not valid before: 2017-01-16T11:03:05
8586|_Not valid after: 2044-06-02T11:03:05
8587|_ssl-date: 2017-09-10T05:21:41+00:00; -2m15s from scanner time.
8588445/tcp filtered microsoft-ds
8589465/tcp filtered smtps
8590587/tcp filtered submission
8591993/tcp open ssl/imaps?
8592| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
8593| Not valid before: 2016-05-13T00:22:04
8594|_Not valid after: 2043-09-28T00:22:04
8595|_ssl-date: 2017-09-10T05:21:39+00:00; -2m13s from scanner time.
8596995/tcp open ssl/pop3s?
8597| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
8598| Not valid before: 2016-05-13T00:22:04
8599|_Not valid after: 2043-09-28T00:22:04
8600|_ssl-date: 2017-09-10T05:21:39+00:00; -2m13s from scanner time.
86013306/tcp open mysql MySQL (unauthorized)
86021 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
8603SF-Port143-TCP:V=7.60%I=7%D=9/10%Time=59B4CC41%P=x86_64-pc-linux-gnu%r(NUL
8604SF:L,73,"\*\x20OK\x20\[CAPABILITY\x20IMAP4rev1\x20LITERAL\+\x20SASL-IR\x20
8605SF:LOGIN-REFERRALS\x20ID\x20ENABLE\x20IDLE\x20STARTTLS\x20AUTH=PLAIN\]\x20
8606SF:Dovecot\x20DA\x20ready\.\r\n")%r(GetRequest,73,"\*\x20OK\x20\[CAPABILIT
8607SF:Y\x20IMAP4rev1\x20LITERAL\+\x20SASL-IR\x20LOGIN-REFERRALS\x20ID\x20ENAB
8608SF:LE\x20IDLE\x20STARTTLS\x20AUTH=PLAIN\]\x20Dovecot\x20DA\x20ready\.\r\n"
8609SF:)%r(GenericLines,73,"\*\x20OK\x20\[CAPABILITY\x20IMAP4rev1\x20LITERAL\+
8610SF:\x20SASL-IR\x20LOGIN-REFERRALS\x20ID\x20ENABLE\x20IDLE\x20STARTTLS\x20A
8611SF:UTH=PLAIN\]\x20Dovecot\x20DA\x20ready\.\r\n");
8612Device type: general purpose|firewall|storage-misc
8613Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (98%), WatchGuard Fireware 11.X (93%), Synology DiskStation Manager 5.X (93%)
8614OS CPE: cpe:/o:linux:linux_kernel:2.6.39 cpe:/o:linux:linux_kernel:3.4 cpe:/o:watchguard:fireware:11.8 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:linux:linux_kernel:4.2
8615Aggressive OS guesses: Linux 2.6.39 (98%), Linux 2.6.32 (93%), Linux 3.4 (93%), WatchGuard Fireware 11.8 (93%), Synology DiskStation Manager 5.1 (93%), Linux 3.10 (92%), Linux 2.6.32 or 3.10 (92%), Linux 3.1 - 3.2 (92%), Linux 2.6.32 - 2.6.39 (91%), Linux 3.0 (90%)
8616No exact OS matches for host (test conditions non-ideal).
8617Network Distance: 11 hops
8618
8619Host script results:
8620|_clock-skew: mean: -2m13s, deviation: 0s, median: -2m13s
8621
8622TRACEROUTE (using port 8888/tcp)
8623HOP RTT ADDRESS
86241 992.02 ms 10.13.0.1
86252 224.31 ms 37.187.24.252
86263 125.86 ms 178.33.103.229
86274 ...
86285 136.45 ms 213.186.32.213
86296 130.17 ms 94.23.122.218
86307 ...
86318 224.34 ms 5.56.18.86
86329 224.38 ms 5.56.18.71
863310 144.96 ms 46.166.186.129
863411 142.50 ms 185.82.203.139
8635
8636OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
8637Nmap done: 1 IP address (1 host up) scanned in 130.20 seconds
8638
8639###########################################################################################
8640
8641amap -i temp.txt
8642amap v5.4 (www.thc.org/thc-amap) started at 2017-09-10 01:25:13 - APPLICATION MAPPING mode
8643
8644Protocol on 185.82.203.139:21/tcp matches ftp
8645Protocol on 185.82.203.139:22/tcp matches ssh
8646Protocol on 185.82.203.139:22/tcp matches ssh-openssh
8647Protocol on 185.82.203.139:80/tcp matches http
8648Protocol on 185.82.203.139:80/tcp matches http-apache-2
8649Protocol on 185.82.203.139:110/tcp matches pop3
8650Protocol on 185.82.203.139:443/tcp matches http
8651Protocol on 185.82.203.139:443/tcp matches http-apache-2
8652Protocol on 185.82.203.139:443/tcp matches teamspeak2
8653Protocol on 185.82.203.139:143/tcp matches imap
8654Protocol on 185.82.203.139:3306/tcp matches mysql
8655Protocol on 185.82.203.139:3306/tcp matches mysql-secured
8656Protocol on 185.82.203.139:80/tcp matches teamspeak2
8657Protocol on 185.82.203.139:995/tcp matches ssl
8658Protocol on 185.82.203.139:443/tcp matches ssl
8659Protocol on 185.82.203.139:993/tcp matches ssl
8660Protocol on 185.82.203.139:53/tcp matches dns
8661Protocol on 185.82.203.139:21/tcp matches smtp
8662
8663inetnum: 185.82.203.0 - 185.82.203.255
8664netname: EU-HOSTSAILOR-20150101
8665descr: HostSailor NL Services
8666country: NL
8667admin-c: AF11712-RIPE
8668tech-c: AF11712-RIPE
8669status: ASSIGNED PA
8670mnt-by: MNT-HS
8671created: 2015-01-01T11:36:07Z
8672last-modified: 2015-01-01T11:36:07Z
8673source: RIPE
8674
8675person: Host Sailor Ltd - Administrative role account
8676address: HDS Business Centre 3204
8677address: Jumeirah Lakes Towers
8678address: Dubai
8679address: United Arab Emirates
8680phone: +97145577845
8681nic-hdl: AF11712-RIPE
8682mnt-by: MNT-HS
8683abuse-mailbox: abuse@hostsailor.com
8684created: 2014-06-30T16:22:26Z
8685last-modified: 2017-02-12T07:59:29Z
8686source: RIPE
8687
8688% Information related to '185.82.203.0/24AS60117'
8689
8690route: 185.82.203.0/24
8691descr: EU-HOSTSAILOR 185.82.200.0/24
8692origin: AS60117
8693mnt-by: MNT-HS
8694created: 2015-01-01T11:32:56Z
8695last-modified: 2015-01-01T11:32:56Z
8696source: RIPE
8697
8698% This query was served by the RIPE Database Query Service version 1.89.2 (BLAARKOP)
8699
8700
8701###########################################################################################
8702[i] Scanning Site: http://young-holes.net
8703
8704
8705
8706B A S I C I N F O
8707====================
8708
8709
8710[+] Site Title: Young Holes
8711[+] IP address: 185.82.203.139
8712[+] Web Server: Apache/2
8713[+] CMS: Could Not Detect
8714[+] Cloudflare: Not Detected
8715[+] Robots File: Could NOT Find robots.txt!
8716
8717
8718
8719
8720W H O I S L O O K U P
8721========================
8722
8723 Domain Name: YOUNG-HOLES.NET
8724 Registry Domain ID: 1971134373_DOMAIN_NET-VRSN
8725 Registrar WHOIS Server: whois.namesilo.com
8726 Registrar URL: http://www.namesilo.com
8727 Updated Date: 2017-04-05T01:17:04Z
8728 Creation Date: 2015-10-23T08:08:22Z
8729 Registry Expiry Date: 2017-10-23T08:08:22Z
8730 Registrar: NameSilo, LLC
8731 Registrar IANA ID: 1479
8732 Registrar Abuse Contact Email: abuse@namesilo.com
8733 Registrar Abuse Contact Phone: +1.4805240066
8734 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
8735 Name Server: NS1.DNSOWL.COM
8736 Name Server: NS2.DNSOWL.COM
8737 Name Server: NS3.DNSOWL.COM
8738 DNSSEC: unsigned
8739
8740
8741
8742G E O I P L O O K U P
8743=========================
8744
8745[i] IP Address: 185.82.203.139
8746[i] Country: NL
8747[i] State: Noord-Holland
8748[i] City: Amsterdam
8749[i] Latitude: 52.349998
8750[i] Longitude: 4.916700
8751
8752
8753
8754
8755H T T P H E A D E R S
8756=======================
8757
8758
8759[i] HTTP/1.1 200 OK
8760[i] Date: Sun, 10 Sep 2017 05:20:19 GMT
8761[i] Server: Apache/2
8762[i] Accept-Ranges: bytes
8763[i] Vary: Accept-Encoding,User-Agent
8764[i] Connection: close
8765[i] Content-Type: text/html
8766
8767
8768
8769
8770
8771S U B N E T C A L C U L A T I O N
8772====================================
8773
8774Address = 185.82.203.139
8775Network = 185.82.203.139 / 32
8776Netmask = 255.255.255.255
8777Broadcast = not needed on Point-to-Point links
8778Wildcard Mask = 0.0.0.0
8779Hosts Bits = 0
8780Max. Hosts = 1 (2^0 - 0)
8781Host Range = { 185.82.203.139 - 185.82.203.139 }
8782
8783
8784
8785N M A P P O R T S C A N
8786============================
8787
8788
8789Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-10 05:22 UTC
8790Nmap scan report for young-holes.net (185.82.203.139)
8791Host is up (0.083s latency).
8792rDNS record for 185.82.203.139: dedi21685.hostsailor.com
8793PORT STATE SERVICE VERSION
879421/tcp open ftp Pure-FTPd
879522/tcp open ssh OpenSSH 5.3 (protocol 2.0)
879623/tcp closed telnet
879725/tcp open smtp Exim smtpd 4.87
879880/tcp open http?
8799110/tcp open pop3 Dovecot DirectAdmin pop3d
8800143/tcp open imap Dovecot imapd
8801443/tcp open ssl/https?
8802445/tcp closed microsoft-ds
88033389/tcp closed ms-wbt-server
8804
8805
8806
8807S U B - D O M A I N F I N D E R
8808==================================
8809
8810
8811[i] Total Subdomains Found : 1
8812
8813[+] Subdomain: young-holes.net
8814[-] IP: 185.82.203.139
8815
8816
8817
8818
8819
8820R E V E R S E I P L O O K U P
8821==================================
8822
8823
8824[i] Total Sites Found On This Server : 4
8825
8826
8827[#] teeny-pussys.com,1,www.atlasphones.com
8828[-] CMS: Could Not Detect
8829
8830[#] www.tacticalsoftware.com
8831[-] CMS: Could Not Detect
8832
8833[#] young-archive.com
8834[-] CMS: Could Not Detect
8835
8836[#] young-holes.net,
8837[-] CMS: Could Not Detect
8838young-holes.net
8839[*] Performing TLD Brute force Enumeration against young-holes.net
8840[*] The operation could take up to: 00:01:07
8841[*] A young-holes.biz.af 5.45.75.45
8842[*] CNAME young-holes.biz.at free.biz.at
8843[*] A free.biz.at 216.92.134.29
8844[*] A young-holes.co.asia 91.195.240.135
8845[*] A young-holes.org.aw 142.4.20.12
8846[*] A young-holes.co.ba 176.9.45.78
8847[*] A young-holes.com.ba 195.222.33.180
8848[*] A young-holes.com.be 95.173.170.166
8849[*] A young-holes.biz.by 71.18.52.2
8850[*] A young-holes.biz.bz 199.59.242.150
8851[*] A young-holes.com.cc 54.252.107.64
8852[*] A young-holes.net.cc 54.252.89.206
8853[*] A young-holes.co.cc 175.126.123.219
8854[*] A young-holes.org.ch 72.52.4.122
8855[*] A young-holes.co.cm 85.25.140.105
8856[*] A young-holes.biz.cl 185.53.178.8
8857[*] A young-holes.net.cm 85.25.140.105
8858[*] A young-holes.com.com 52.33.196.199
8859[*] A young-holes.com 67.227.226.240
8860[*] A young-holes.net.com 199.59.242.150
8861[*] A young-holes.org.com 23.23.86.44
8862[*] CNAME young-holes.biz.cm i.cns.cm
8863[*] A i.cns.cm 118.184.56.30
8864[*] A young-holes.co.com 173.192.115.17
8865[*] A young-holes.biz.cr 72.52.4.122
8866[*] A young-holes.biz.cx 72.52.4.122
8867[*] A young-holes.com.cz 62.109.128.30
8868[*] A young-holes.net.cz 80.250.24.177
8869[*] A young-holes.biz.cz 185.53.179.7
8870[*] CNAME young-holes.co.de co.de
8871[*] A co.de 144.76.162.245
8872[*] A young-holes.com.de 50.56.68.37
8873[*] CNAME young-holes.org.de www.org.de
8874[*] A www.org.de 78.47.128.8
8875[*] A young-holes.net.eu 78.46.90.98
8876[*] A young-holes.org.eu 78.46.90.98
8877[*] A young-holes.biz.fi 185.55.85.123
8878[*] A young-holes.fm 173.230.131.38
8879[*] A young-holes.biz.fm 173.230.131.38
8880[*] A young-holes.org.fr 149.202.133.35
8881[*] A young-holes.biz.gl 72.52.4.122
8882[*] CNAME young-holes.co.gp co.gp
8883[*] A co.gp 144.76.162.245
8884[*] A young-holes.co.hn 208.100.40.203
8885[*] CNAME young-holes.net.hr net.hr
8886[*] A net.hr 192.0.78.25
8887[*] A net.hr 192.0.78.24
8888[*] A young-holes.co.ht 72.52.4.122
8889[*] CNAME young-holes.biz.hn parkmydomain.vhostgo.com
8890[*] A parkmydomain.vhostgo.com 107.186.245.118
8891[*] A young-holes.co.jobs 50.17.193.222
8892[*] A young-holes.com.jobs 50.19.241.165
8893[*] A young-holes.net.jobs 50.19.241.165
8894[*] A young-holes.biz.jobs 50.19.241.165
8895[*] A young-holes.org.jobs 50.19.241.165
8896[*] A young-holes.biz.ky 199.184.144.27
8897[*] CNAME young-holes.biz.li 712936.parkingcrew.net
8898[*] A 712936.parkingcrew.net 185.53.179.29
8899[*] A young-holes.biz.lu 195.26.5.2
8900[*] A young-holes.biz.ly 64.136.20.39
8901[*] A young-holes.biz.md 72.52.4.122
8902[*] A young-holes.co.mk 87.76.31.211
8903[*] A young-holes.co.mobi 54.225.105.179
8904[*] A young-holes.biz.my 202.190.174.44
8905[*] A young-holes.net 185.82.203.139
8906[*] A young-holes.co.net 188.166.216.219
8907[*] A young-holes.net.net 52.50.81.210
8908[*] A young-holes.org.net 23.23.86.44
8909[*] A young-holes.co.nl 37.97.184.204
8910[*] A young-holes.com.nl 83.98.157.102
8911[*] A young-holes.net.nl 83.98.157.102
8912[*] A young-holes.co.nr 208.100.40.202
8913[*] A young-holes.org.nu 80.92.84.139
8914[*] CNAME young-holes.co.nu co.nu
8915[*] A co.nu 144.76.162.245
8916[*] CNAME young-holes.com.nu com.nu
8917[*] A com.nu 144.76.162.245
8918[*] A young-holes.net.nu 199.102.76.78
8919[*] CNAME young-holes.net.org pewtrusts.org
8920[*] A pewtrusts.org 204.74.99.100
8921[*] A young-holes.com.org 23.23.86.44
8922[*] A young-holes.ph 45.79.222.138
8923[*] A young-holes.co.ph 45.79.222.138
8924[*] A young-holes.com.ph 45.79.222.138
8925[*] A young-holes.net.ph 45.79.222.138
8926[*] A young-holes.org.ph 45.79.222.138
8927[*] A young-holes.co.pl 212.91.6.55
8928[*] A young-holes.org.pm 208.73.210.217
8929[*] A young-holes.org.pm 208.73.210.202
8930[*] A young-holes.org.pm 208.73.211.177
8931[*] A young-holes.org.pm 208.73.211.165
8932[*] A young-holes.co.ps 66.96.132.56
8933[*] CNAME young-holes.biz.ps biz.ps
8934[*] A biz.ps 144.76.162.245
8935[*] A young-holes.co.pt 194.107.127.52
8936[*] A young-holes.pw 141.8.226.58
8937[*] A young-holes.co.pw 141.8.226.59
8938[*] A young-holes.net.pw 141.8.226.59
8939[*] A young-holes.biz.pw 141.8.226.59
8940[*] A young-holes.org.pw 141.8.226.59
8941[*] A young-holes.net.ro 69.64.52.127
8942[*] CNAME young-holes.co.ro now.co.ro
8943[*] A now.co.ro 185.27.255.9
8944[*] A young-holes.org.re 217.70.184.38
8945[*] A young-holes.com.ru 178.210.89.119
8946[*] A young-holes.biz.se 185.53.179.6
8947[*] CNAME young-holes.net.se 773147.parkingcrew.net
8948[*] A 773147.parkingcrew.net 185.53.179.29
8949[*] A young-holes.co.sl 91.195.240.135
8950[*] A young-holes.com.sr 143.95.106.249
8951[*] A young-holes.co.su 72.52.4.122
8952[*] A young-holes.biz.st 91.121.28.115
8953[*] A young-holes.biz.tc 64.136.20.39
8954[*] A young-holes.biz.tf 85.236.153.18
8955[*] A young-holes.net.tf 188.40.117.12
8956[*] A young-holes.net.tf 188.40.70.27
8957[*] A young-holes.net.tf 188.40.70.29
8958[*] A young-holes.co.tl 208.100.40.202
8959[*] A young-holes.co.to 175.118.124.44
8960[*] A young-holes.co.tv 31.186.25.163
8961[*] A young-holes.biz.tv 72.52.4.122
8962[*] A young-holes.org.tv 72.52.4.122
8963[*] CNAME young-holes.biz.uz biz.uz
8964[*] A biz.uz 144.76.162.245
8965[*] A young-holes.vg 88.198.29.97
8966[*] A young-holes.co.vg 88.198.29.97
8967[*] A young-holes.com.vg 88.198.29.97
8968[*] A young-holes.net.vg 68.178.254.180
8969[*] A young-holes.biz.vg 89.31.143.20
8970[*] A young-holes.ws 64.70.19.203
8971[*] A young-holes.com.ws 202.4.48.211
8972[*] A young-holes.net.ws 202.4.48.211
8973[*] A young-holes.org.ws 202.4.48.211
8974[*] A young-holes.biz.ws 184.168.221.104
8975 Domain Name: YOUNG-HOLES.NET
8976 Registry Domain ID: 1971134373_DOMAIN_NET-VRSN
8977 Registrar WHOIS Server: whois.namesilo.com
8978 Registrar URL: http://www.namesilo.com
8979 Updated Date: 2017-04-05T01:17:04Z
8980 Creation Date: 2015-10-23T08:08:22Z
8981 Registry Expiry Date: 2017-10-23T08:08:22Z
8982 Registrar: NameSilo, LLC
8983 Registrar IANA ID: 1479
8984 Registrar Abuse Contact Email: abuse@namesilo.com
8985 Registrar Abuse Contact Phone: +1.4805240066
8986 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
8987 Name Server: NS1.DNSOWL.COM
8988 Name Server: NS2.DNSOWL.COM
8989 Name Server: NS3.DNSOWL.COM
8990
8991Domain Name: young-holes.net
8992Registry Domain ID: 1971134373_DOMAIN_NET-VRSN
8993Registrar WHOIS Server: whois.namesilo.com
8994Registrar URL: https://www.namesilo.com/
8995Updated Date: 2017-09-06
8996Creation Date: 2015-10-23
8997Registrar Registration Expiration Date: 2017-10-23
8998Registrar: NameSilo, LLC
8999Registrar IANA ID: 1479
9000Registrar Abuse Contact Email: abuse@namesilo.com
9001Registrar Abuse Contact Phone: +1.4805240066
9002Status: clientTransferProhibited
9003Registry Registrant ID:
9004Registrant Name: Domain Administrator
9005Registrant Organization: See PrivacyGuardian.org
9006Registrant Street: 1928 E. Highland Ave. Ste F104 PMB# 255
9007Registrant City: Phoenix
9008Registrant State/Province: AZ
9009Registrant Postal Code: 85016
9010Registrant Country: US
9011Registrant Phone: +1.3478717726
9012Registrant Phone Ext:
9013Registrant Fax:
9014Registrant Fax Ext:
9015Registrant Email: pw-e7629bed44d86f8a91043903b3f5ab96@privacyguardian.org
9016Registry Admin ID:
9017Admin Name: Domain Administrator
9018Admin Organization: See PrivacyGuardian.org
9019Admin Street: 1928 E. Highland Ave. Ste F104 PMB# 255
9020Admin City: Phoenix
9021Admin State/Province: AZ
9022Admin Postal Code: 85016
9023Admin Country: US
9024Admin Phone: +1.3478717726
9025Admin Phone Ext:
9026Admin Fax:
9027Admin Fax Ext:
9028Admin Email: pw-e7629bed44d86f8a91043903b3f5ab96@privacyguardian.org
9029Registry Tech ID:
9030Tech Name: Domain Administrator
9031Tech Organization: See PrivacyGuardian.org
9032Tech Street: 1928 E. Highland Ave. Ste F104 PMB# 255
9033Tech City: Phoenix
9034Tech State/Province: AZ
9035Tech Postal Code: 85016
9036Tech Country: US
9037Tech Phone: +1.3478717726
9038Tech Phone Ext:
9039Tech Fax:
9040Tech Fax Ext:
9041Tech Email: pw-e7629bed44d86f8a91043903b3f5ab96@privacyguardian.org
9042Name Server: ns1.dnsowl.com
9043Name Server: ns2.dnsowl.com
9044Name Server: ns3.dnsowl.com
9045
9046;young-holes.net. IN ANY
9047
9048;; ANSWER SECTION:
9049young-holes.net. 172669 IN A 185.82.203.139
9050young-holes.net. 172653 IN NS ns3.dnsowl.com.
9051young-holes.net. 172653 IN NS ns2.dnsowl.com.
9052young-holes.net. 172653 IN NS ns1.dnsowl.com.
9053
9054;; Query time: 8 msec
9055;; SERVER: 192.168.1.254#53(192.168.1.254)
9056;; WHEN: Sun Sep 10 01:22:06 EDT 2017
9057;; MSG SIZE rcvd: 124
9058
9059
9060Host's addresses:
9061__________________
9062
9063young-holes.net. 172662 IN A 185.82.203.139
9064
9065
9066Name Servers:
9067______________
9068
9069ns1.dnsowl.com. 31495 IN A 198.251.84.105
9070ns1.dnsowl.com. 31495 IN A 185.34.216.59
9071ns1.dnsowl.com. 31495 IN A 37.187.179.91
9072ns3.dnsowl.com. 41431 IN A 158.69.33.230
9073ns3.dnsowl.com. 41431 IN A 198.251.80.184
9074ns3.dnsowl.com. 41431 IN A 70.39.65.12
9075ns2.dnsowl.com. 43200 IN A 104.143.9.16
9076ns2.dnsowl.com. 43200 IN A 167.114.213.239
9077ns2.dnsowl.com. 43200 IN A 107.191.99.216
9078
9079
9080
9081
9082Google Results:
9083________________
9084
9085 perhaps Google is blocking our queries.
9086 Check manually.
9087
9088
9089Brute forcing with dns.txt:
9090____________________________
9091
9092www.young-holes.net. 34493 IN CNAME young-holes.net.
9093young-holes.net. 172639 IN A 185.82.203.139
9094
9095
9096Performing recursion:
9097______________________
9098
9099
9100 ---- Checking subdomains NS records ----
9101young-holes.net. 172623 IN NS ns2.dnsowl.com.
9102young-holes.net. 172623 IN NS ns1.dnsowl.com.
9103young-holes.net. 172623 IN NS ns3.dnsowl.com.
9104
9105 Can't perform recursion no NS records.
9106
9107
9108young-holes.net class C netranges:
9109___________________________________
9110
9111 185.82.203.0/24
9112
9113www.young-holes.net
9114IP address #1: 185.82.203.139
9115
9116[+] 1 (sub)domains and 1 IP address(es) found
9117[+] completion time: 92 second(s)
9118
9119WhatWeb report for http://young-holes.net
9120Status : 200 OK
9121Title : Young Holes
9122IP : <Unknown>
9123Country : <Unknown>
9124
9125Summary : HTTPServer[Apache/2], Script[text/javascript,text/javascript>], Apache[2]
9126
9127Detected Plugins:
9128[ Apache ]
9129 The Apache HTTP Server Project is an effort to develop and
9130 maintain an open-source HTTP server for modern operating
9131 systems including UNIX and Windows NT. The goal of this
9132 project is to provide a secure, efficient and extensible
9133 server that provides HTTP services in sync with the current
9134 HTTP standards.
9135
9136 Version : 2 (from HTTP Server Header)
9137 Google Dorks: (3)
9138 Website : http://httpd.apache.org/
9139
9140[ HTTPServer ]
9141 HTTP server header string. This plugin also attempts to
9142 identify the operating system from the server header.
9143
9144 String : Apache/2 (from server string)
9145
9146[ Script ]
9147 This plugin detects instances of script HTML elements and
9148 returns the script language/type.
9149
9150 String : text/javascript,text/javascript>
9151
9152HTTP Headers:
9153 HTTP/1.1 200 OK
9154 Date: Sun, 10 Sep 2017 05:22:04 GMT
9155 Server: Apache/2
9156 Accept-Ranges: bytes
9157 Vary: Accept-Encoding,User-Agent
9158 Content-Encoding: gzip
9159 Content-Length: 2680
9160 Connection: close
9161 Content-Type: text/html
9162
9163
9164[+] Hosts found in search engines:
9165------------------------------------
9166[-] Resolving hostnames IPs...
9167185.82.203.139:www.young-holes.net
9168
9169
9170
9171 ^ ^
9172 _ __ _ ____ _ __ _ _ ____
9173 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
9174 | V V // o // _/ | V V // 0 // 0 // _/
9175 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
9176 <
9177 ...'
9178
9179 WAFW00F - Web Application Firewall Detection Tool
9180
9181 By Sandro Gauci && Wendel G. Henrique
9182
9183Checking http://young-holes.net
9184Generic Detection results:
9185No WAF detected by the generic detection
9186Number of requests: 13
9187
9188
9189DNS Servers for young-holes.net:
9190 ns3.dnsowl.com
9191 ns2.dnsowl.com
9192 ns1.dnsowl.com
9193
9194Trying zone transfer first...
9195 Testing ns3.dnsowl.com
9196 Request timed out or transfer not allowed.
9197 Testing ns2.dnsowl.com
9198 Request timed out or transfer not allowed.
9199 Testing ns1.dnsowl.com
9200 Request timed out or transfer not allowed.
9201
9202Unsuccessful in zone transfer (it was worth a shot)
9203Okay, trying the good old fashioned way... brute force
9204
9205Checking for wildcard DNS...
9206Nope. Good.
9207Now performing 2280 test(s)...
9208
9209Subnets found (may want to probe here using nmap or unicornscan):
9210
9211Done with Fierce scan: http://ha.ckers.org/fierce/
9212Found 0 entries.
9213
9214Have a nice day.
9215
9216
9217
9218lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
9219 Written by Stefan Behte (http://ge.mine.nu)
9220 Proof-of-concept! Might give false positives.
9221
9222Checking for DNS-Loadbalancing: NOT FOUND
9223Checking for HTTP-Loadbalancing [Server]:
9224 Apache/2
9225 NOT FOUND
9226
9227Checking for HTTP-Loadbalancing [Date]: 05:51:51, 05:51:51, 05:51:52, 05:51:52, 05:51:52, 05:51:53, 05:51:53, 05:51:53, 05:51:53, 05:51:54, 05:51:54, 05:51:54, 05:51:54, 05:51:55, 05:51:55, 05:51:55, 05:51:56, 05:51:56, 05:51:56, 05:51:56, 05:51:57, 05:51:57, 05:51:57, 05:51:57, 05:51:58, 05:51:58, 05:51:58, 05:51:58, 05:51:59, 05:51:59, 05:51:59, 05:52:00, 05:52:00, 05:52:00, 05:52:00, 05:52:01, 05:52:01, 05:52:01, 05:52:01, 05:52:02, 05:52:02, 05:52:02, 05:52:03, 05:52:03, 05:52:03, 05:52:03, 05:52:04, 05:52:04, 05:52:04, 05:52:04, NOT FOUND
9228
9229Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
9230
9231young-holes.net does NOT use Load-balancing.
9232
9233
9234
9235Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
9236
9237 ----------------------------------------------------------
9238| Scan Information |
9239 ----------------------------------------------------------
9240
9241Mode ..................... VRFY
9242Worker Processes ......... 5
9243Usernames file ........... users.txt
9244Target count ............. 1
9245Username count ........... 494
9246Target TCP port .......... 25
9247Query timeout ............ 5 secs
9248Target domain ............
9249
9250######## Scan started at Sun Sep 10 01:54:30 2017 #########
9251######## Scan completed at Sun Sep 10 02:02:45 2017 #########
92520 results.
9253
9254494 queries in 495 seconds (1.0 queries / sec)
9255
9256
9257
9258Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-10 02:02 EDT
9259NSE: Loaded 146 scripts for scanning.
9260NSE: Script Pre-scanning.
9261Initiating NSE at 02:02
9262Completed NSE at 02:02, 0.00s elapsed
9263Initiating NSE at 02:02
9264Completed NSE at 02:02, 0.00s elapsed
9265Failed to resolve "young-holes.net.txt".
9266Initiating Parallel DNS resolution of 1 host. at 02:02
9267Completed Parallel DNS resolution of 1 host. at 02:02, 0.66s elapsed
9268Initiating SYN Stealth Scan at 02:02
9269Scanning young-holes.net (185.82.203.139) [100 ports]
9270Discovered open port 110/tcp on 185.82.203.139
9271Discovered open port 443/tcp on 185.82.203.139
9272Discovered open port 22/tcp on 185.82.203.139
9273Discovered open port 995/tcp on 185.82.203.139
9274Discovered open port 21/tcp on 185.82.203.139
9275Discovered open port 80/tcp on 185.82.203.139
9276Discovered open port 143/tcp on 185.82.203.139
9277Discovered open port 3306/tcp on 185.82.203.139
9278Discovered open port 53/tcp on 185.82.203.139
9279Discovered open port 993/tcp on 185.82.203.139
9280Completed SYN Stealth Scan at 02:02, 3.06s elapsed (100 total ports)
9281Initiating Service scan at 02:02
9282Scanning 10 services on young-holes.net (185.82.203.139)
9283Completed Service scan at 02:03, 15.08s elapsed (10 services on 1 host)
9284Initiating OS detection (try #1) against young-holes.net (185.82.203.139)
9285adjust_timeouts2: packet supposedly had rtt of -80099 microseconds. Ignoring time.
9286adjust_timeouts2: packet supposedly had rtt of -80099 microseconds. Ignoring time.
9287adjust_timeouts2: packet supposedly had rtt of -79823 microseconds. Ignoring time.
9288adjust_timeouts2: packet supposedly had rtt of -79823 microseconds. Ignoring time.
9289Initiating Traceroute at 02:03
9290Completed Traceroute at 02:03, 3.00s elapsed
9291Initiating Parallel DNS resolution of 8 hosts. at 02:03
9292Completed Parallel DNS resolution of 8 hosts. at 02:03, 5.62s elapsed
9293NSE: Script scanning 185.82.203.139.
9294Initiating NSE at 02:03
9295Completed NSE at 02:04, 68.63s elapsed
9296Initiating NSE at 02:04
9297Completed NSE at 02:04, 1.13s elapsed
9298Nmap scan report for young-holes.net (185.82.203.139)
9299Host is up (0.13s latency).
9300rDNS record for 185.82.203.139: dedi21685.hostsailor.com
9301Not shown: 84 closed ports
9302PORT STATE SERVICE VERSION
930321/tcp open ftp Pure-FTPd
9304| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
9305| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
9306| Public Key type: rsa
9307| Public Key bits: 2048
9308| Signature Algorithm: sha1WithRSAEncryption
9309| Not valid before: 2017-01-16T11:03:05
9310| Not valid after: 2044-06-02T11:03:05
9311| MD5: 642e ed18 b740 de7e b74d 7b38 0ab3 d968
9312|_SHA-1: 027a d527 92b1 c651 1f9d 7fa5 48fa 783d 0641 40d2
931322/tcp open ssh OpenSSH 5.3 (protocol 2.0)
9314| ssh-hostkey:
9315| 1024 7b:41:fb:d8:5e:04:70:a2:78:ee:38:4c:97:42:9b:49 (DSA)
9316|_ 2048 5f:d2:a2:cd:01:76:d6:52:11:db:7f:21:8a:80:b5:6e (RSA)
931725/tcp filtered smtp
931853/tcp open domain ISC BIND 9.8.2rc1
9319| dns-nsid:
9320|_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6_8.3
932180/tcp open ssl/http?
9322| http-methods:
9323|_ Supported Methods: GET HEAD POST OPTIONS
9324|_http-title: Young Holes
9325110/tcp open pop3 Dovecot DirectAdmin pop3d
9326| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9327| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9328| Public Key type: rsa
9329| Public Key bits: 4096
9330| Signature Algorithm: sha1WithRSAEncryption
9331| Not valid before: 2016-05-13T00:22:04
9332| Not valid after: 2043-09-28T00:22:04
9333| MD5: 2d54 e03b 7b9c 669b 6385 ddb0 6d7c 972b
9334|_SHA-1: a4c5 829a 425b 42d5 9697 503b a0fd fb73 3374 e41d
9335135/tcp filtered msrpc
9336139/tcp filtered netbios-ssn
9337143/tcp open imap Dovecot imapd
9338|_imap-capabilities: AUTH=PLAINA0001 LITERAL+ SASL-IR have STARTTLS ENABLE capabilities more ID listed IMAP4rev1 OK Pre-login post-login LOGIN-REFERRALS IDLE
9339| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9340| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9341| Public Key type: rsa
9342| Public Key bits: 4096
9343| Signature Algorithm: sha1WithRSAEncryption
9344| Not valid before: 2016-05-13T00:22:04
9345| Not valid after: 2043-09-28T00:22:04
9346| MD5: 2d54 e03b 7b9c 669b 6385 ddb0 6d7c 972b
9347|_SHA-1: a4c5 829a 425b 42d5 9697 503b a0fd fb73 3374 e41d
9348|_ssl-date: 2017-09-10T06:01:05+00:00; -2m13s from scanner time.
9349443/tcp open ssl/ssl Apache httpd (SSL-only mode)
9350| http-methods:
9351|_ Supported Methods: GET POST
9352|_http-title: 400 Bad Request
9353| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
9354| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
9355| Public Key type: rsa
9356| Public Key bits: 2048
9357| Signature Algorithm: sha1WithRSAEncryption
9358| Not valid before: 2017-01-16T11:03:05
9359| Not valid after: 2044-06-02T11:03:05
9360| MD5: 642e ed18 b740 de7e b74d 7b38 0ab3 d968
9361|_SHA-1: 027a d527 92b1 c651 1f9d 7fa5 48fa 783d 0641 40d2
9362|_ssl-date: 2017-09-10T06:01:09+00:00; -2m14s from scanner time.
9363445/tcp filtered microsoft-ds
9364465/tcp filtered smtps
9365587/tcp filtered submission
9366993/tcp open ssl/imap Dovecot DirectAdmin imapd
9367| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9368| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9369| Public Key type: rsa
9370| Public Key bits: 4096
9371| Signature Algorithm: sha1WithRSAEncryption
9372| Not valid before: 2016-05-13T00:22:04
9373| Not valid after: 2043-09-28T00:22:04
9374| MD5: 2d54 e03b 7b9c 669b 6385 ddb0 6d7c 972b
9375|_SHA-1: a4c5 829a 425b 42d5 9697 503b a0fd fb73 3374 e41d
9376|_ssl-date: 2017-09-10T06:01:13+00:00; -2m13s from scanner time.
9377995/tcp open ssl/pop3 Dovecot DirectAdmin pop3d
9378| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9379| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
9380| Public Key type: rsa
9381| Public Key bits: 4096
9382| Signature Algorithm: sha1WithRSAEncryption
9383| Not valid before: 2016-05-13T00:22:04
9384| Not valid after: 2043-09-28T00:22:04
9385| MD5: 2d54 e03b 7b9c 669b 6385 ddb0 6d7c 972b
9386|_SHA-1: a4c5 829a 425b 42d5 9697 503b a0fd fb73 3374 e41d
9387|_ssl-date: 2017-09-10T06:01:04+00:00; -2m13s from scanner time.
93883306/tcp open mysql MySQL (unauthorized)
9389Device type: general purpose
9390Running: Linux 2.6.X
9391OS CPE: cpe:/o:linux:linux_kernel:2.6.39
9392OS details: Linux 2.6.39
9393Uptime guess: 0.738 days (since Sat Sep 9 08:21:13 2017)
9394Network Distance: 11 hops
9395TCP Sequence Prediction: Difficulty=258 (Good luck!)
9396IP ID Sequence Generation: All zeros
9397Service Info: OS: Red Hat Enterprise Linux 6; CPE: cpe:/o:redhat:enterprise_linux:6
9398
9399Host script results:
9400|_clock-skew: mean: -2m13s, deviation: 0s, median: -2m13s
9401
9402TRACEROUTE (using port 8080/tcp)
9403HOP RTT ADDRESS
94041 109.43 ms 10.13.0.1
94052 ...
94063 110.54 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
94074 ...
94085 119.09 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
94096 119.11 ms be100-2.fra-5-a9.de.eu (94.23.122.218)
94107 ...
94118 124.31 ms ae10-2075.ams10.core-backbone.com (5.56.18.86)
94129 121.36 ms core-backbone.nforce.com (5.56.18.71)
941310 121.82 ms 46.166.186.129
941411 120.89 ms dedi21685.hostsailor.com (185.82.203.139)
9415
9416NSE: Script Post-scanning.
9417Initiating NSE at 02:04
9418Completed NSE at 02:04, 0.00s elapsed
9419Initiating NSE at 02:04
9420Completed NSE at 02:04, 0.00s elapsed
9421Read data files from: /usr/bin/../share/nmap
9422OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
9423Nmap done: 1 IP address (1 host up) scanned in 100.35 seconds
9424 Raw packets sent: 226 (10.970KB) | Rcvd: 183 (8.913KB)
9425
9426
9427
9428
9429 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
9430 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
9431 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
9432 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
9433 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
9434
9435 _/ User-Agent Tester ↵
9436 _/ AKA: Purple Pimp ↵
9437 _/ ChrisJohnRiley ↵
9438 _/ blog.c22.cc ↵
9439
9440 [>] Performing initial request and confirming stability
9441 [>] Using User-Agent string Mozilla/5.0
9442
9443 [ ] URL (ENTERED): http://young-holes.net
9444 [ ] Response Code: 200 OK
9445 [ ] Date: Sun, 10 Sep 2017 06:02:19 GMT
9446 [ ] Server: Apache/2
9447 [ ] Accept-Ranges: bytes
9448 [ ] Vary: Accept-Encoding,User-Agent
9449 [ ] Connection: close
9450 [ ] Transfer-Encoding: chunked
9451 [ ] Content-Type: text/html
9452 [ ] Data (MD5): d9975d3495155282726820482ed8642a
9453
9454 [1] Pass
9455 [2] Pass
9456 [3] Pass
9457
9458 [>] URL appears stable. Beginning test
9459
9460 [>] Using DEFAULT User-Agent Strings
9461
9462 [>] Using Crazy User-Agent Strings
9463 [>] Using Bot User-Agent Strings
9464
9465 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
9466
9467
9468 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
9469
9470
9471 [!] Data (MD5): 9393a890e3f97cdbc3f68f0a4d0fe632
9472
9473
9474 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
9475
9476
9477 [!] Data (MD5): 35e1aa9cc82c2752153a2e83f9bae3ed
9478
9479
9480 [>] User-Agent String : TrackBack/1.02
9481
9482
9483 [!] Data (MD5): 37b29e8b78e3fa7a8db24c0157a20cf9
9484
9485
9486 [>] User-Agent String : wispr
9487
9488
9489 [!] Data (MD5): e58284cad2c524168cf063346dd0becc
9490
9491
9492 [>] User-Agent String : EMPTY USER-AGENT STRING!
9493
9494
9495 [!] Data (MD5): aa5d4bdc9d0ebe63069b57e15fa0fba6
9496
9497
9498 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
9499
9500
9501 [!] Data (MD5): cb7aec54fcdb3f54946d8854b8c376eb
9502
9503
9504 [>] User-Agent String : Googlebot-Image/1.0
9505
9506
9507 [!] Data (MD5): 2b56982869ad1555a929180a8380b03f
9508
9509
9510 [>] User-Agent String : Mediapartners-Google
9511
9512
9513 [!] Data (MD5): d7db1a8e211ca3e6c37f9c60e3c4815c
9514
9515
9516 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
9517
9518
9519 [!] Data (MD5): 87bf7b3122a10d2e981b4f84aee6e192
9520
9521
9522 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
9523
9524
9525 [!] Data (MD5): 806edb99da21e63e2da2a3943d1f8e70
9526
9527
9528 [>] User-Agent String : mmcrawler
9529
9530
9531 [!] Data (MD5): 48dc05ebf88beb08a185271fb53f70ce
9532
9533
9534 [>] Checks completed... try enabling VERBOSE mode for more detailed output
9535
9536 [>] That's all folks... Fo' Shizzle!
9537#########################################################################################