· 8 years ago · Aug 30, 2017, 06:42 PM
1#######################################################################################################################################
2Hostname pro.world-collections.com ISP Quasi Networks LTD. (AS29073)
3Continent Africa Flag
4SC
5Country Seychelles Country Code SC (SYC)
6Region Unknown Local time 29 Aug 2017 13:03 +04
7City Unknown Latitude -4.583
8IP Address 94.102.49.234 Longitude 55.667
9#######################################################################################################################################
10p
11;; ANSWER SECTION:
12pro.world-collections.com. 3305 IN A 94.102.49.234
13
14;; Query time: 8 msec
15;; SERVER: 192.168.1.254#53(192.168.1.254)
16;; WHEN: Tue Aug 29 04:36:46 EDT 2017
17;; MSG SIZE rcvd: 70
18
19.
20
21----- pro.world-collections.com -----
22
23
24Host's addresses:
25__________________
26
27pro.world-collections.com. 3283 IN A 94.102.49.234
28
29
30Name Servers:
31______________
32
33 pro.world-collections.com NS record query failed: NOERROR
34
35
36dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
37
38[+] searching (sub)domains for pro.world-collections.com using built-in wordlist
39[+] using maximum random delay of 10 millisecond(s) between requests
40
41[+] 0 (sub)domains and 0 IP address(es) found
42[+] completion time: 159 second(s)
43
44
45Tracing to pro.world-collections.com[a] via 192.168.1.254, maximum of 3 retries
46192.168.1.254 (192.168.1.254) Got answer
47
48
49WhatWeb report for http://pro.world-collections.com
50Status : 200 OK
51Title : Young models.
52IP : 94.102.49.234
53Country : NETHERLANDS, NL
54
55Summary : Script[JavaScript], HTTPServer[CentOS][Apache/2.2.3 (CentOS)], Apache[2.2.3]
56
57Detected Plugins:
58[ Apache ]
59 The Apache HTTP Server Project is an effort to develop and
60 maintain an open-source HTTP server for modern operating
61 systems including UNIX and Windows NT. The goal of this
62 project is to provide a secure, efficient and extensible
63 server that provides HTTP services in sync with the current
64 HTTP standards.
65
66 Version : 2.2.3 (from HTTP Server Header)
67 Google Dorks: (3)
68 Website : http://httpd.apache.org/
69
70[ HTTPServer ]
71 HTTP server header string. This plugin also attempts to
72 identify the operating system from the server header.
73
74 OS : CentOS
75 String : Apache/2.2.3 (CentOS) (from server string)
76
77[ Script ]
78 This plugin detects instances of script HTML elements and
79 returns the script language/type.
80
81 String : JavaScript
82
83HTTP Headers:
84 HTTP/1.1 200 OK
85 Date: Tue, 29 Aug 2017 08:39:55 GMT
86 Server: Apache/2.2.3 (CentOS)
87 Last-Modified: Tue, 29 Aug 2017 08:30:28 GMT
88 Accept-Ranges: bytes
89 Content-Length: 52919
90 Connection: close
91 Content-Type: text/html; charset=UTF-8
92
93
94
95
96
97
98 ^ ^
99 _ __ _ ____ _ __ _ _ ____
100 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
101 | V V // o // _/ | V V // 0 // 0 // _/
102 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
103 <
104 ...'
105
106 WAFW00F - Web Application Firewall Detection Tool
107
108 By Sandro Gauci && Wendel G. Henrique
109
110Checking http://pro.world-collections.com
111Generic Detection results:
112No WAF detected by the generic detection
113Number of requests: 13
114
115
116
117
118Checking for HTTP-Loadbalancing [Date]: 08:40:56, 08:40:56, 08:40:56, 08:40:56, 08:40:57, 08:40:57, 08:40:58, 08:40:58, 08:40:58, 08:40:58, 08:40:59, 08:40:59, 08:40:59, 08:40:59, 08:41:02, 08:41:02, 08:41:02, 08:41:03, 08:41:03, 08:41:04, 08:41:05, 08:41:05, 08:41:06, 08:41:06, 08:41:06, 08:41:07, 08:41:07, 08:41:07, 08:41:08, 08:41:09, 08:41:09, 08:41:09, 08:41:09, 08:41:10, 08:41:10, 08:41:10, 08:41:11, 08:41:11, 08:41:11, 08:41:12, 08:41:13, 08:41:13, 08:41:13, 08:41:14, 08:41:14, 08:41:15, 08:41:16, 08:41:17, 08:41:17, 08:41:17, NOT FOUND
119
120Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
121
122pro.world-collections.com does NOT use Load-balancing.
123
124
125
126Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
127
128 ----------------------------------------------------------
129| Scan Information |
130 ----------------------------------------------------------
131
132Mode ..................... VRFY
133Worker Processes ......... 5
134Usernames file ........... users.txt
135Target count ............. 1
136Username count ........... 494
137Target TCP port .......... 25
138Query timeout ............ 5 secs
139Target domain ............
140
141######## Scan started at Tue Aug 29 04:41:27 2017 #########
142######## Scan completed at Tue Aug 29 04:49:42 2017 #########
1430 results.
144
145494 queries in 495 seconds (1.0 queries / sec)
146
147
148
149Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 04:49 EDT
150NSE: Loaded 146 scripts for scanning.
151NSE: Script Pre-scanning.
152Initiating NSE at 04:49
153Completed NSE at 04:49, 0.00s elapsed
154Initiating NSE at 04:49
155Completed NSE at 04:49, 0.00s elapsed
156Failed to resolve "pro.world-collections.com.txt".
157Initiating Parallel DNS resolution of 1 host. at 04:49
158Completed Parallel DNS resolution of 1 host. at 04:49, 0.72s elapsed
159Initiating SYN Stealth Scan at 04:49
160Scanning pro.world-collections.com (94.102.49.234) [100 ports]
161Discovered open port 111/tcp on 94.102.49.234
162Discovered open port 3306/tcp on 94.102.49.234
163Discovered open port 80/tcp on 94.102.49.234
164Discovered open port 21/tcp on 94.102.49.234
165Discovered open port 22/tcp on 94.102.49.234
166Increasing send delay for 94.102.49.234 from 0 to 5 due to 63 out of 157 dropped probes since last increase.
167Completed SYN Stealth Scan at 04:49, 3.28s elapsed (100 total ports)
168Initiating Service scan at 04:49
169Scanning 5 services on pro.world-collections.com (94.102.49.234)
170Completed Service scan at 04:49, 6.25s elapsed (5 services on 1 host)
171Initiating OS detection (try #1) against pro.world-collections.com (94.102.49.234)
172adjust_timeouts2: packet supposedly had rtt of -108722 microseconds. Ignoring time.
173adjust_timeouts2: packet supposedly had rtt of -108722 microseconds. Ignoring time.
174Retrying OS detection (try #2) against pro.world-collections.com (94.102.49.234)
175Initiating Traceroute at 04:50
176Completed Traceroute at 04:50, 3.00s elapsed
177Initiating Parallel DNS resolution of 7 hosts. at 04:50
178Completed Parallel DNS resolution of 7 hosts. at 04:50, 5.53s elapsed
179NSE: Script scanning 94.102.49.234.
180Initiating NSE at 04:50
181Completed NSE at 04:50, 22.55s elapsed
182Initiating NSE at 04:50
183Completed NSE at 04:50, 0.26s elapsed
184Nmap scan report for pro.world-collections.com (94.102.49.234)
185Host is up (0.13s latency).
186rDNS record for 94.102.49.234: no-reverse-dns-configured.com
187Not shown: 89 closed ports
188PORT STATE SERVICE VERSION
18921/tcp open ftp vsftpd 2.0.5
19022/tcp open ssh OpenSSH 5.1p1 Debian 5 (protocol 2.0)
191| ssh-hostkey:
192| 1024 e3:8d:c4:c5:fb:90:24:bd:e4:47:44:1d:8e:05:9e:66 (DSA)
193|_ 2048 d8:43:eb:53:4f:5a:29:0d:22:e3:e3:a8:19:01:e1:54 (RSA)
19425/tcp filtered smtp
19580/tcp open http Apache httpd 2.2.3
196| http-methods:
197| Supported Methods: GET HEAD POST OPTIONS TRACE
198|_ Potentially risky methods: TRACE
199|_http-server-header: Apache/2.2.3 (CentOS)
200|_http-title: Young models.
201111/tcp open rpcbind 2 (RPC #100000)
202| rpcinfo:
203| program version port/proto service
204| 100000 2 111/tcp rpcbind
205| 100000 2 111/udp rpcbind
206| 100024 1 44999/udp status
207|_ 100024 1 56279/tcp status
208135/tcp filtered msrpc
209139/tcp filtered netbios-ssn
210445/tcp filtered microsoft-ds
211465/tcp filtered smtps
212587/tcp filtered submission
2133306/tcp open mysql MySQL 5.0.77
214| mysql-info:
215| Protocol: 10
216| Version: 5.0.77
217| Thread ID: 4908434
218| Capabilities flags: 41516
219| Some Capabilities: LongColumnFlag, Support41Auth, ConnectWithDatabase, SupportsTransactions, SupportsCompression, Speaks41ProtocolNew
220| Status: Autocommit
221|_ Salt: 1asA(Eb=K?:E*DU_]64@
222Aggressive OS guesses: Endian 2.3 or IPCop firewall 1.4.10 - 1.4.21 (Linux 2.4.31 - 2.6.22) (93%), ZyXEL ZyWALL USG 20 or USG 50 firewall (ZyNOS 2.21) (93%), Citrix Access Gateway VPN gateway (92%), Juniper SA4000 SSL VPN gateway (IVE OS 7.0) (92%), Avaya Communication Manager (Linux 2.6.11) (92%), Cymphonix EX550 firewall (92%), Linux 2.4.21 (92%), Linux 2.6.24 (Gentoo) (92%), NSFOCUS WAF (92%), OpenWrt (Linux 2.4.32) (91%)
223No exact OS matches for host (test conditions non-ideal).
224Network Distance: 10 hops
225TCP Sequence Prediction: Difficulty=208 (Good luck!)
226IP ID Sequence Generation: All zeros
227Service Info: Host: dummy-host.example.com; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
228
229TRACEROUTE (using port 8888/tcp)
230HOP RTT ADDRESS
2311 110.45 ms 10.13.0.1
2322 110.60 ms 37.187.24.252
2333 110.55 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
2344 ...
2355 119.20 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
2366 ...
2377 129.94 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
2388 120.45 ms 176.10.83.5
2399 ...
24010 124.71 ms no-reverse-dns-configured.com (94.102.49.234)
241
242NSE: Script Post-scanning.
243Initiating NSE at 04:50
244Completed NSE at 04:50, 0.00s elapsed
245Initiating NSE at 04:50
246Completed NSE at 04:50, 0.00s elapsed
247Read data files from: /usr/bin/../share/nmap
248OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
249Nmap done: 1 IP address (1 host up) scanned in 49.99 seconds
250 Raw packets sent: 291 (17.266KB) | Rcvd: 217 (10.330KB)
251
252
253Error: can not open nmap file: pro.world-collections.com.txt
254
255
256httprint v0.301 (beta) - web server fingerprinting tool
257(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
258http://net-square.com/httprint/
259httprint@net-square.com
260
261Finger Printing on http://pro.world-collections.com:80/
262Finger Printing Completed on http://pro.world-collections.com:80/
263--------------------------------------------------
264Host: pro.world-collections.com
265Fingerprinting Error: Host/URL not found...
266
267--------------------------------------------------
268
269
270
271
272 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
273 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
274 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
275 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
276 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
277
278 _/ User-Agent Tester ↵
279 _/ AKA: Purple Pimp ↵
280 _/ ChrisJohnRiley ↵
281 _/ blog.c22.cc ↵
282
283 [>] Performing initial request and confirming stability
284 [>] Using User-Agent string Mozilla/5.0
285
286 [ ] URL (ENTERED): http://pro.world-collections.com
287 [ ] Response Code: 200 OK
288 [ ] Date: Tue, 29 Aug 2017 08:50:43 GMT
289 [ ] Server: Apache/2.2.3 (CentOS)
290 [ ] Last-Modified: Tue, 29 Aug 2017 08:50:29 GMT
291 [ ] Accept-Ranges: bytes
292 [ ] Content-Length: 52918
293 [ ] Connection: close
294 [ ] Content-Type: text/html; charset=UTF-8
295 [ ] Data (MD5): bfa6164e75fef640779fa1ba1637f74d
296
297 [1] Pass
298 [2] Pass
299 [3] Pass
300
301 [>] URL appears stable. Beginning test
302
303 [>] Using DEFAULT User-Agent Strings
304
305 [>] Using Crazy User-Agent Strings
306 [>] Using Bot User-Agent Strings
307
308 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
309
310
311 [>] User-Agent String : EMPTY USER-AGENT STRING!
312
313
314 [!] Data (MD5): 7cec76e9bbee92516af56fb96b22edc1
315
316
317 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
318
319
320 [!] Data (MD5): 7cec76e9bbee92516af56fb96b22edc1
321Traceback (most recent call last):
322 File "UAtester.py", line 766, in <module>
323 main()
324 File "UAtester.py", line 474, in main
325 ua_check_data = resp2.read()
326 File "/usr/lib/python2.7/socket.py", line 355, in read
327 data = self._sock.recv(rbufsize)
328 File "/usr/lib/python2.7/httplib.py", line 597, in read
329 s = self.fp.read(amt)
330 File "/usr/lib/python2.7/socket.py", line 384, in read
331 data = self._sock.recv(left)
332socket.timeout: timed out
333
334
335 Enter your target IP : 94.102.49.234
336
337 obtention site Joomla ...
338
339[i] Scanning Site: http://pro.world-collections.com
340
341
342
343B A S I C I N F O
344====================
345
346
347[+] Site Title: Young models.
348[+] IP address: 94.102.49.234
349[+] Web Server: Apache/2.2.3 (CentOS)
350[+] CMS: Could Not Detect
351[+] Cloudflare: Not Detected
352[+] Robots File: Could NOT Find robots.txt!
353
354
355
356
357
358
359G E O I P L O O K U P
360=========================
361
362[i] IP Address: 94.102.49.234
363[i] Country: SC
364[i] State: N/A
365[i] City: N/A
366[i] Latitude: -4.583300
367[i] Longitude: 55.666698
368
369
370
371
372H T T P H E A D E R S
373=======================
374
375
376[i] HTTP/1.1 200 OK
377[i] Date: Tue, 29 Aug 2017 08:37:28 GMT
378[i] Server: Apache/2.2.3 (CentOS)
379[i] Last-Modified: Tue, 29 Aug 2017 08:30:28 GMT
380[i] Accept-Ranges: bytes
381[i] Content-Length: 52919
382[i] Connection: close
383[i] Content-Type: text/html; charset=UTF-8
384
385
386
387
388D N S L O O K U P
389===================
390
391pro.world-collections.com. 3593 IN A 94.102.49.234
392
393
394
395
396S U B N E T C A L C U L A T I O N
397====================================
398
399Address = 94.102.49.234
400Network = 94.102.49.234 / 32
401Netmask = 255.255.255.255
402Broadcast = not needed on Point-to-Point links
403Wildcard Mask = 0.0.0.0
404Hosts Bits = 0
405Max. Hosts = 1 (2^0 - 0)
406Host Range = { 94.102.49.234 - 94.102.49.234 }
407
408
409
410N M A P P O R T S C A N
411============================
412
413
414Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 08:37 UTC
415Nmap scan report for pro.world-collections.com (94.102.49.234)
416Host is up (0.087s latency).
417rDNS record for 94.102.49.234: no-reverse-dns-configured.com
418PORT STATE SERVICE VERSION
41921/tcp open ftp vsftpd 2.0.5
42022/tcp open ssh OpenSSH 5.1p1 Debian 5 (protocol 2.0)
42123/tcp closed telnet
42225/tcp closed smtp
42380/tcp open http Apache httpd 2.2.3
424110/tcp closed pop3
425143/tcp closed imap
426443/tcp closed https
427445/tcp closed microsoft-ds
4283389/tcp closed ms-wbt-server
429Service Info: Host: dummy-host.example.com; OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
430
431Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
432Nmap done: 1 IP address (1 host up) scanned in 7.83 seconds
433
434
435
436S U B - D O M A I N F I N D E R
437==================================
438
439
440[i] Total Subdomains Found : 1
441
442[+] Subdomain: pro.world-collections.com
443[-] IP: 94.102.49.234
444
445
446
447
448--------------------------------------------------------------------------
449+ Target IP: 94.102.49.234
450+ Target Hostname: 94.102.49.234
451+ Target Port: 80
452+ Start Time: 2017-08-29 05:02:48 (GMT-4)
453---------------------------------------------------------------------------
454+ Server: Apache/2.2.3 (CentOS)
455+ The anti-clickjacking X-Frame-Options header is not present.
456+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
457+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
458+ Apache/2.2.3 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
459+ Allowed HTTP Methods: GET, HEAD, POST, OPTIONS, TRACE
460+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
461+ OSVDB-561: /server-status: This reveals Apache information. Comment out appropriate line in the Apache conf file or restrict access to allowed sources.
462+ OSVDB-3268: /icons/: Directory indexing found.
463+ Server leaks inodes via ETags, header found with file /icons/README, inode: 40763647, size: 4872, mtime: Thu Jun 24 15:46:08 2010
464+ OSVDB-3233: /icons/README: Apache default file found.
465+ 8346 requests: 0 error(s) and 10 item(s) reported on remote host
466+ End Time: 2017-08-29 05:25:30 (GMT-4) (1362 seconds)
467----<-----------------------------------------------------------------------
468#######################################################################################################################################
469http://newnnmodels.com/
470Hostname newnnmodels.com ISP Tele Asia Limited (AS133398)
471Continent Europe Flag
472LT
473Country Lithuania Country Code LT (LTU)
474Region 57 Local time 29 Aug 2017 12:32 EEST
475Metropolis Unknown Postal Code 44001
476City Kaunas Latitude 54.9
477IP Address 45.123.190.121 Longitude 23.9
478#######################################################################################################################################
479newnnmodels.com
480
481
482 Domain Name: NEWNNMODELS.COM
483 Registry Domain ID: 1935391710_DOMAIN_COM-VRSN
484 Registrar WHOIS Server: whois.PublicDomainRegistry.com
485 Registrar URL: http://www.publicdomainregistry.com
486 Updated Date: 2017-06-01T08:47:13Z
487 Creation Date: 2015-06-04T10:04:32Z
488 Registry Expiry Date: 2018-06-04T10:04:32Z
489 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
490 Registrar IANA ID: 303
491 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
492 Registrar Abuse Contact Phone: +1.2013775952
493 Domain Status: ok https://icann.org/epp#ok
494 Name Server: NS1.GEOSCALING.COM
495 Name Server: NS2.GEOSCALING.COM
496 Name Server: NS3.GEOSCALING.COM
497 Name Server: NS4.GEOSCALING.COM
498 Name Server: NS5.GEOSCALING.COM
499
500Domain Name: NEWNNMODELS.COM
501Registry Domain ID: 1935391710_DOMAIN_COM-VRSN
502Registrar WHOIS Server: whois.publicdomainregistry.com
503Registrar URL: www.publicdomainregistry.com
504Updated Date: 2017-07-07T10:24:05Z
505Creation Date: 2015-06-04T10:04:32Z
506Registrar Registration Expiration Date: 2018-06-04T10:04:32Z
507Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
508Registrar IANA ID: 303
509Domain Status: OK https://icann.org/epp#OK
510Registry Registrant ID: Not Available From Registry
511Registrant Name: ultralord
512Registrant Organization: ultralord
513Registrant Street: ultralord 112
514Registrant City: NY
515Registrant State/Province: Aginskiy Burjatskiy avtonomniy okrug
516Registrant Postal Code: 345555
517Registrant Country: RU
518Registrant Phone: +928.12436473
519Registrant Phone Ext:
520Registrant Fax:
521Registrant Fax Ext:
522Registrant Email: carwad@gmail.com
523Registry Admin ID: Not Available From Registry
524Admin Name: ultralord
525Admin Organization: ultralord
526Admin Street: ultralord 112
527Admin City: NY
528Admin State/Province: Aginskiy Burjatskiy avtonomniy okrug
529Admin Postal Code: 345555
530Admin Country: RU
531Admin Phone: +928.12436473
532Admin Phone Ext:
533Admin Fax:
534Admin Fax Ext:
535Admin Email: carwad@gmail.com
536Registry Tech ID: Not Available From Registry
537Tech Name: ultralord
538Tech Organization: ultralord
539Tech Street: ultralord 112
540Tech City: NY
541Tech State/Province: Aginskiy Burjatskiy avtonomniy okrug
542Tech Postal Code: 345555
543Tech Country: RU
544Tech Phone: +928.12436473
545Tech Phone Ext:
546Tech Fax:
547Tech Fax Ext:
548Tech Email: carwad@gmail.com
549Name Server: ns1.geoscaling.com
550Name Server: ns2.geoscaling.com
551Name Server: ns3.geoscaling.com
552Name Server: ns4.geoscaling.com
553Name Server: ns5.geoscaling.com
554
555
556;; ANSWER SECTION:
557newnnmodels.com. 7200 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
558newnnmodels.com. 260 IN A 45.123.190.121
559newnnmodels.com. 7200 IN NS ns1.geoscaling.com.
560newnnmodels.com. 7200 IN NS ns2.geoscaling.com.
561newnnmodels.com. 7200 IN NS ns3.geoscaling.com.
562newnnmodels.com. 7200 IN NS ns5.geoscaling.com.
563
564;; Query time: 116 msec
565;; SERVER: 192.168.1.254#53(192.168.1.254)
566;; WHEN: Tue Aug 29 05:32:40 EDT 2017
567;; MSG SIZE rcvd: 187
568
569
570
571;; Connection to 192.168.1.254#53(192.168.1.254) for newnnmodels.com failed: connection refused.
572Host newnnmodels.com not found: 9(NOTAUTH)
573; Transfer failed.
574
575
576Please type the name of your network interface Example: eth0
577eth0
578
579Running:
580 traceroute -T -O info -i eth0 newnnmodels.com
581traceroute to newnnmodels.com (45.123.190.121), 30 hops max, 60 byte packets
582 1 gateway (192.168.1.254) 0.493 ms 0.672 ms 0.834 ms
583 2 10.135.18.1 (10.135.18.1) 13.232 ms 17.467 ms 17.668 ms
584 3 CHCNIL23BR01.bb.telus.com (154.11.11.121) 32.301 ms 32.344 ms 32.598 ms
585 4 VANCBC01GR01.bb.telus.com (154.11.10.25) 33.622 ms 33.838 ms 33.979 ms
586 5 TenGE0-0-0-23.br02.frf06.pccwbtn.net (63.218.232.61) 120.193 ms 123.125 ms 123.165 ms
587 6 63-218-233-6.static.pccwglobal.net (63.218.233.6) 131.977 ms 119.029 ms 120.562 ms
588 7 mskn06.mskn202.transtelecom.net (188.43.9.190) 163.901 ms 168.372 ms 162.467 ms
589 8 * * *
590 9 * * *
59110 * * *
59211 ddos-guard.net (185.129.101.85) 167.002 ms 166.538 ms 165.160 ms
59312 eesmaarasti.net (45.123.190.121) <syn,ack> 189.879 ms 189.102 ms 190.768 ms
594
595
596----- newnnmodels.com -----
597
598
599Host's addresses:
600__________________
601
602newnnmodels.com. 206 IN A 45.123.190.121
603
604
605Name Servers:
606______________
607
608ns1.geoscaling.com. 300 IN A 91.121.64.153
609ns2.geoscaling.com. 300 IN A 91.121.64.153
610ns5.geoscaling.com. 300 IN A 91.121.64.153
611ns3.geoscaling.com. 300 IN A 91.121.64.153
612
613
614
615Brute forcing with dns.txt:
616____________________________
617
618www.newnnmodels.com. 300 IN CNAME newnnmodels.com.
619newnnmodels.com. 163 IN A 45.123.190.121
620
621
622Performing recursion:
623______________________
624
625
626 ---- Checking subdomains NS records ----
627newnnmodels.com. 7081 IN NS ns1.geoscaling.com.
628newnnmodels.com. 7081 IN NS ns2.geoscaling.com.
629newnnmodels.com. 7081 IN NS ns5.geoscaling.com.
630newnnmodels.com. 7081 IN NS ns3.geoscaling.com.
631
632 Can't perform recursion no NS records.
633
634
635newnnmodels.com class C netranges:
636___________________________________
637
638 45.123.190.0/24
639
640
641
642www.newnnmodels.com
643IP address #1: 45.123.190.121
644
645[+] 1 (sub)domains and 1 IP address(es) found
646[+] completion time: 159 second(s)
647
648
649Tracing to newnnmodels.com[a] via 192.168.1.254, maximum of 3 retries
650192.168.1.254 (192.168.1.254) Got answer
651
652
653WhatWeb report for http://newnnmodels.com
654Status : 200 OK
655Title : BEAUTIFUL HOT NAKED TEEN GIRLS SEX
656IP : <Unknown>
657Country : <Unknown>
658
659Summary : nginx[1.10.2], Script[text/javascript], PHP[5.4.45], AddThis, X-Powered-By[PHP/5.4.45], HTTPServer[nginx/1.10.2]
660
661Detected Plugins:
662[ AddThis ]
663 AddThis is a free way to boost traffic back to your site by
664 making it easier for visitors to share your content.
665
666 Website : http://www.addthis.com/
667
668[ HTTPServer ]
669 HTTP server header string. This plugin also attempts to
670 identify the operating system from the server header.
671
672 String : nginx/1.10.2 (from server string)
673
674[ PHP ]
675 PHP is a widely-used general-purpose scripting language
676 that is especially suited for Web development and can be
677 embedded into HTML. This plugin identifies PHP errors,
678 modules and versions and extracts the local file path and
679 username if present.
680
681 Version : 5.4.45
682 Google Dorks: (2)
683 Website : http://www.php.net/
684
685[ Script ]
686 This plugin detects instances of script HTML elements and
687 returns the script language/type.
688
689 String : text/javascript
690
691[ X-Powered-By ]
692 X-Powered-By HTTP header
693
694 String : PHP/5.4.45 (from x-powered-by string)
695
696[ nginx ]
697 Nginx (Engine-X) is a free, open-source, high-performance
698 HTTP server and reverse proxy, as well as an IMAP/POP3
699 proxy server.
700
701 Version : 1.10.2
702 Website : http://nginx.net/
703
704HTTP Headers:
705 HTTP/1.1 200 OK
706 Server: nginx/1.10.2
707 Date: Tue, 29 Aug 2017 06:37:42 GMT
708 Content-Type: text/html; charset=UTF-8
709 Content-Length: 4508
710 Connection: close
711 X-Powered-By: PHP/5.4.45
712 Vary: Accept-Encoding,User-Agent
713 Content-Encoding: gzip
714
715
716
717[+] Hosts found in search engines:
718------------------------------------
719[-] Resolving hostnames IPs...
72045.123.190.121:Green.newnnmodels.com
72145.123.190.121:green.newnnmodels.com
72245.123.190.121:ice.newnnmodels.com
72345.123.190.121:www.newnnmodels.com
724
725
726
727 ^ ^
728 _ __ _ ____ _ __ _ _ ____
729 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
730 | V V // o // _/ | V V // 0 // 0 // _/
731 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
732 <
733 ...'
734
735 WAFW00F - Web Application Firewall Detection Tool
736
737 By Sandro Gauci && Wendel G. Henrique
738
739Checking http://newnnmodels.com
740Generic Detection results:
741No WAF detected by the generic detection
742Number of requests: 13
743
744
745DNS Servers for newnnmodels.com:
746 ns5.geoscaling.com
747 ns2.geoscaling.com
748 ns1.geoscaling.com
749 ns3.geoscaling.com
750
751Trying zone transfer first...
752 Testing ns5.geoscaling.com
753 Request timed out or transfer not allowed.
754 Testing ns2.geoscaling.com
755 Request timed out or transfer not allowed.
756 Testing ns1.geoscaling.com
757 Request timed out or transfer not allowed.
758 Testing ns3.geoscaling.com
759 Request timed out or transfer not allowed.
760
761Unsuccessful in zone transfer (it was worth a shot)
762Okay, trying the good old fashioned way... brute force
763
764Checking for wildcard DNS...
765Nope. Good.
766Now performing 2280 test(s)...
76745.123.190.121 green.newnnmodels.com
76845.123.190.121 www.newnnmodels.com
769
770Subnets found (may want to probe here using nmap or unicornscan):
771 45.123.190.0-255 : 2 hostnames found.
772
773
774Checking for HTTP-Loadbalancing [Date]: 06:46:39, 06:46:40, 06:46:40, 06:46:42, 06:46:42, 06:46:43, 06:46:45, 06:46:46, 06:46:47, 06:46:48, 06:46:50, 06:46:51, 06:46:52, 06:46:53, 06:46:55, 06:46:56, 06:46:59, 06:47:01, 06:47:01, 06:47:03, 06:47:05, 06:47:08, 06:47:10, 06:47:11, 06:47:12, 06:47:15, 06:47:17, 06:47:17, 06:47:18, 06:47:19, 06:47:19, 06:47:21, 06:47:22, 06:47:25, 06:47:28, 06:47:29, 06:47:29, 06:47:30, 06:47:31, 06:47:34, 06:47:36, 06:47:39, 06:47:42, 06:47:44, 06:47:46, 06:47:47, 06:47:48, 06:47:49, 06:47:49, 06:47:50, NOT FOUND
775
776Checking for HTTP-Loadbalancing [Diff]: FOUND
777< HTTP/1.1 400 Bad Request
778> HTTP/1.1 500 Internal Server Error
779< Content-Type: text/html; charset=iso-8859-1
780> Content-Type: text/html
781> Content-Length: 193
782
783newnnmodels.com does Load-balancing. Found via Methods: HTTP[Diff]
784
785
786
787Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
788
789 ----------------------------------------------------------
790| Scan Information |
791 ----------------------------------------------------------
792
793Mode ..................... VRFY
794Worker Processes ......... 5
795Usernames file ........... users.txt
796Target count ............. 1
797Username count ........... 494
798Target TCP port .......... 25
799Query timeout ............ 5 secs
800Target domain ............
801
802######## Scan started at Tue Aug 29 05:48:04 2017 #########
803######## Scan completed at Tue Aug 29 05:56:19 2017 #########
8040 results.
805
806494 queries in 495 seconds (1.0 queries / sec)
807
808
809
810Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 05:56 EDT
811NSE: Loaded 146 scripts for scanning.
812NSE: Script Pre-scanning.
813Initiating NSE at 05:56
814Completed NSE at 05:56, 0.00s elapsed
815Initiating NSE at 05:56
816Completed NSE at 05:56, 0.00s elapsed
817Failed to resolve "newnnmodels.com.txt".
818Initiating Parallel DNS resolution of 1 host. at 05:56
819Completed Parallel DNS resolution of 1 host. at 05:56, 0.82s elapsed
820Initiating SYN Stealth Scan at 05:56
821Scanning newnnmodels.com (45.123.190.121) [100 ports]
822Discovered open port 80/tcp on 45.123.190.121
823Discovered open port 22/tcp on 45.123.190.121
824Completed SYN Stealth Scan at 05:56, 2.47s elapsed (100 total ports)
825Initiating Service scan at 05:56
826Scanning 2 services on newnnmodels.com (45.123.190.121)
827Completed Service scan at 05:56, 6.56s elapsed (2 services on 1 host)
828Initiating OS detection (try #1) against newnnmodels.com (45.123.190.121)
829Retrying OS detection (try #2) against newnnmodels.com (45.123.190.121)
830adjust_timeouts2: packet supposedly had rtt of -175728 microseconds. Ignoring time.
831adjust_timeouts2: packet supposedly had rtt of -175728 microseconds. Ignoring time.
832adjust_timeouts2: packet supposedly had rtt of -75608 microseconds. Ignoring time.
833adjust_timeouts2: packet supposedly had rtt of -75608 microseconds. Ignoring time.
834adjust_timeouts2: packet supposedly had rtt of -75749 microseconds. Ignoring time.
835adjust_timeouts2: packet supposedly had rtt of -75749 microseconds. Ignoring time.
836Initiating Traceroute at 05:56
837Completed Traceroute at 05:56, 3.01s elapsed
838Initiating Parallel DNS resolution of 7 hosts. at 05:56
839Completed Parallel DNS resolution of 7 hosts. at 05:56, 5.61s elapsed
840NSE: Script scanning 45.123.190.121.
841Initiating NSE at 05:56
842Completed NSE at 05:56, 13.59s elapsed
843Initiating NSE at 05:56
844Completed NSE at 05:56, 0.00s elapsed
845Nmap scan report for newnnmodels.com (45.123.190.121)
846Host is up (0.21s latency).
847rDNS record for 45.123.190.121: eesmaarasti.net
848Not shown: 92 closed ports
849PORT STATE SERVICE VERSION
85022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
851| ssh-hostkey:
852| 1024 56:1f:ed:a4:fc:ae:23:e0:3b:37:8e:46:4a:f2:aa:e3 (DSA)
853|_ 2048 d0:4f:06:cf:bd:fa:97:a5:6e:da:5d:cd:41:00:cd:c2 (RSA)
85425/tcp filtered smtp
85580/tcp open http nginx 1.10.2
856| http-methods:
857|_ Supported Methods: GET HEAD POST
858|_http-server-header: nginx/1.10.2
859|_http-title: BEAUTIFUL HOT NAKED TEEN GIRLS SEX
860135/tcp filtered msrpc
861139/tcp filtered netbios-ssn
862445/tcp filtered microsoft-ds
863465/tcp filtered smtps
864587/tcp filtered submission
865Aggressive OS guesses: Linux 2.6.32 (95%), Linux 2.6.32 or 3.10 (95%), WatchGuard Fireware 11.8 (95%), Linux 2.6.39 (94%), Synology DiskStation Manager 5.1 (94%), Linux 3.10 (94%), Linux 3.4 (94%), Linux 3.1 - 3.2 (93%), Linux 2.6.32 - 2.6.39 (93%), Linux 3.2 - 3.8 (91%)
866No exact OS matches for host (test conditions non-ideal).
867Uptime guess: 7.988 days (since Mon Aug 21 06:14:02 2017)
868Network Distance: 11 hops
869TCP Sequence Prediction: Difficulty=244 (Good luck!)
870IP ID Sequence Generation: All zeros
871
872TRACEROUTE (using port 554/tcp)
873HOP RTT ADDRESS
8741 117.68 ms 10.13.0.1
8752 109.62 ms 37.187.24.252
8763 110.19 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
8774 ...
8785 119.74 ms be100-1109.fra-1-a9.de.eu (213.186.32.213)
8796 138.98 ms be100-1166.var-5-a9.pl.eu (91.121.215.191)
8807 139.43 ms vl2.var-6-a72.pl.eu (91.121.215.209)
8818 ... 10
88211 219.77 ms eesmaarasti.net (45.123.190.121)
883
884NSE: Script Post-scanning.
885Initiating NSE at 05:56
886Completed NSE at 05:56, 0.00s elapsed
887Initiating NSE at 05:56
888Completed NSE at 05:56, 0.00s elapsed
889Read data files from: /usr/bin/../share/nmap
890OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
891Nmap done: 1 IP address (1 host up) scanned in 38.77 seconds
892 Raw packets sent: 189 (10.216KB) | Rcvd: 144 (7.616KB)
893
894
895Error: can not open nmap file: newnnmodels.com.txt
896
897
898httprint v0.301 (beta) - web server fingerprinting tool
899(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
900http://net-square.com/httprint/
901httprint@net-square.com
902
903Finger Printing on http://newnnmodels.com:80/
904Finger Printing Completed on http://newnnmodels.com:80/
905---------------------------------------------------------------------------------------------------------------------------------------
906Host: newnnmodels.com
907Fingerprinting Error: Host/URL not found...
908
909---------------------------------------------------------------------------------------------------------------------------------------
910
911
912
913
914 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
915 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
916 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
917 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
918 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
919
920 _/ User-Agent Tester ↵
921 _/ AKA: Purple Pimp ↵
922 _/ ChrisJohnRiley ↵
923 _/ blog.c22.cc ↵
924
925 [>] Performing initial request and confirming stability
926 [>] Using User-Agent string Mozilla/5.0
927
928 [ ] URL (ENTERED): http://newnnmodels.com
929 [ ] Response Code: 200 OK
930 [ ] Server: nginx/1.10.2
931 [ ] Date: Tue, 29 Aug 2017 06:57:22 GMT
932 [ ] Content-Type: text/html; charset=UTF-8
933 [ ] Transfer-Encoding: chunked
934 [ ] Connection: close
935 [ ] X-Powered-By: PHP/5.4.45
936 [ ] Vary: Accept-Encoding,User-Agent
937 [ ] Data (MD5): 85515a2ffaff9e086140706b3be86df8
938
939 [1] Pass
940 [2] Pass
941 [3] Pass
942
943 [>] URL appears stable. Beginning test
944
945 [>] Using DEFAULT User-Agent Strings
946
947 [>] Using Crazy User-Agent Strings
948 [>] Using Bot User-Agent Strings
949
950 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
951
952
953 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
954
955
956 [!] Data (MD5): 5215cd4fbcec4c55cfb109c0842543f8
957
958
959 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
960
961
962 [!] Data (MD5): d85e7d8606f0d4cb59fe7aaaea0f7bc8
963
964
965 [>] User-Agent String : TrackBack/1.02
966
967
968 [!] Data (MD5): 912066dbdf3368ad8eccbc42370c6d2b
969
970
971 [>] User-Agent String : wispr
972
973
974 [!] Data (MD5): 1fa6684505de353886cb3e92d208e7f8
975
976
977 [>] User-Agent String : EMPTY USER-AGENT STRING!
978
979
980 [!] Data (MD5): 6bb6f7bac95e7b4834de6d2ae5d34a46
981
982
983 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
984
985
986 [!] Data (MD5): d8b0a95b05a6a24c6c932c7c34d970ed
987
988
989 [>] User-Agent String : Googlebot-Image/1.0
990
991
992 [!] Data (MD5): b347bdf6e4c365e280eea99ba7937927
993
994
995 [>] User-Agent String : Mediapartners-Google
996
997
998 [!] Data (MD5): 14625d6113f4cee7f72b31cd6327e723
999
1000
1001 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
1002
1003
1004 [!] Data (MD5): fa9ff4bd4714b6d2c61e7a3d2b011420
1005
1006
1007 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
1008
1009
1010 [!] Data (MD5): 527d0278257ef3660ccfaf8892c9dc57
1011
1012
1013 [>] User-Agent String : mmcrawler
1014
1015
1016 [!] Data (MD5): 73f92eb2c95b689b1dbb1db11d96b0c4
1017
1018
1019 [>] Checks completed... try enabling VERBOSE mode for more detailed output
1020
1021 [>] That's all folks... Fo' Shizzle!
1022
1023
1024
1025
1026 Enter your target IP : 45.123.190.121
1027
1028 obtention site Joomla ...
1029
1030
1031
1032
1033 obtention site Wordpress ...
1034
1035https://0.r.bat.bing.com
1036https://156001245.r.bat.bing.com
1037https://37003667.r.bat.bing.com
1038https://37003672.r.bat.bing.com
1039[i] Scanning Site: http://newnnmodels.com
1040
1041
1042
1043B A S I C I N F O
1044====================
1045
1046
1047[+] Site Title: BEAUTIFUL HOT NAKED TEEN GIRLS SEX
1048[+] IP address: 45.123.190.121
1049[+] Web Server: nginx/1.10.2
1050[+] CMS: Could Not Detect
1051[+] Cloudflare: Not Detected
1052[+] Robots File: Could NOT Find robots.txt!
1053
1054
1055
1056
1057W H O I S L O O K U P
1058========================
1059
1060 Domain Name: NEWNNMODELS.COM
1061 Registry Domain ID: 1935391710_DOMAIN_COM-VRSN
1062 Registrar WHOIS Server: whois.PublicDomainRegistry.com
1063 Registrar URL: http://www.publicdomainregistry.com
1064 Updated Date: 2017-06-01T08:47:13Z
1065 Creation Date: 2015-06-04T10:04:32Z
1066 Registry Expiry Date: 2018-06-04T10:04:32Z
1067 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
1068 Registrar IANA ID: 303
1069 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
1070 Registrar Abuse Contact Phone: +1.2013775952
1071 Domain Status: ok https://icann.org/epp#ok
1072 Name Server: NS1.GEOSCALING.COM
1073 Name Server: NS2.GEOSCALING.COM
1074 Name Server: NS3.GEOSCALING.COM
1075 Name Server: NS4.GEOSCALING.COM
1076 Name Server: NS5.GEOSCALING.COM
1077 DNSSEC: unsigned
1078 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
1079>>
1080
1081
1082
1083
1084G E O I P L O O K U P
1085=========================
1086
1087[i] IP Address: 45.123.190.121
1088[i] Country: LT
1089[i] State: Kauno Apskritis
1090[i] City: Kaunas
1091[i] Latitude: 54.900002
1092[i] Longitude: 23.900000
1093
1094
1095
1096
1097H T T P H E A D E R S
1098=======================
1099
1100
1101[i] HTTP/1.1 200 OK
1102[i] Server: nginx/1.10.2
1103[i] Date: Tue, 29 Aug 2017 06:34:24 GMT
1104[i] Content-Type: text/html; charset=UTF-8
1105[i] Connection: close
1106[i] X-Powered-By: PHP/5.4.45
1107[i] Vary: Accept-Encoding,User-Agent
1108
1109
1110
1111
1112D N S L O O K U P
1113===================
1114
1115newnnmodels.com. 294 IN A 45.123.190.121
1116newnnmodels.com. 7200 IN NS ns2.geoscaling.com.
1117newnnmodels.com. 7200 IN NS ns3.geoscaling.com.
1118newnnmodels.com. 7200 IN NS ns1.geoscaling.com.
1119newnnmodels.com. 7200 IN NS ns5.geoscaling.com.
1120newnnmodels.com. 7200 IN SOA ns1.geoscaling.com. support.geoscaling.com. 1 10800 3600 1814400 300
1121
1122
1123
1124
1125S U B N E T C A L C U L A T I O N
1126====================================
1127
1128Address = 45.123.190.121
1129Network = 45.123.190.121 / 32
1130Netmask = 255.255.255.255
1131Broadcast = not needed on Point-to-Point links
1132Wildcard Mask = 0.0.0.0
1133Hosts Bits = 0
1134Max. Hosts = 1 (2^0 - 0)
1135Host Range = { 45.123.190.121 - 45.123.190.121 }
1136
1137
1138
1139N M A P P O R T S C A N
1140============================
1141
1142
1143Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 09:34 UTC
1144Nmap scan report for newnnmodels.com (45.123.190.121)
1145Host is up (0.16s latency).
1146rDNS record for 45.123.190.121: eesmaarasti.net
1147PORT STATE SERVICE VERSION
114821/tcp closed ftp
114922/tcp open ssh OpenSSH 5.3 (protocol 2.0)
115023/tcp closed telnet
115125/tcp closed smtp
115280/tcp open http nginx 1.10.2
1153110/tcp closed pop3
1154143/tcp closed imap
1155443/tcp closed https
1156445/tcp closed microsoft-ds
11573389/tcp closed ms-wbt-server
1158
1159
1160---------------------------------------------------------------------------
1161+ Target IP: 45.123.190.121
1162+ Target Hostname: 45.123.190.121
1163+ Target Port: 80
1164+ Start Time: 2017-08-29 06:05:43 (GMT-4)
1165---------------------------------------------------------------------------
1166+ Server: nginx/1.10.2
1167+ Server leaks inodes via ETags, header found with file /, fields: 0x2c 0x5578fffb0f6bc
1168+ The anti-clickjacking X-Frame-Options header is not present.
1169+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
1170+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
1171+ Allowed HTTP Methods: GET, POST, OPTIONS, HEAD
1172+ Retrieved x-powered-by header: PHP/5.4.45
1173+ Uncommon header 'x-robots-tag' found, with contents: noindex, nofollow
1174+ Uncommon header 'x-dns-prefetch-control' found, with contents: off
1175+ Uncommon header 'x-ob_mode' found, with contents: 1
1176+ OSVDB-3092: /phpMyAdmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
1177+ OSVDB-3092: /phpmyadmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
1178+ OSVDB-3092: /pma/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
1179+ Cookie SQMSESSID created without the httponly flag
1180+ OSVDB-3093: /squirrelmail/src/read_body.php: SquirrelMail found
1181+ ERROR: Error limit (20) reached for host, giving up. Last error:
1182+ Scan terminated: 1 error(s) and 14 item(s) reported on remote host
1183+ End Time: 2017-08-29 06:59:36 (GMT-4) (3233 seconds)
1184---------------------------------------------------------------------------
1185#######################################################################################################################################
1186Crawling Types & Descriptions:
1187
1188Hostname dark-incest.com ISP Leaseweb USA, Inc. (AS30633)
1189Continent North America Flag
1190US
1191Country United States Country Code US (USA)
1192Region DE Local time 29 Aug 2017 06:58 EDT
1193Metropolis Unknown Postal Code Unknown
1194City Unknown Latitude 39.673
1195IP Address 108.59.13.136 Longitude -75.705
1196#######################################################################################################################################
1197dark-incest.com
1198
1199
1200 Domain Name: DARK-INCEST.COM
1201 Registry Domain ID: 1394954848_DOMAIN_COM-VRSN
1202 Registrar WHOIS Server: whois.evonames.com
1203 Registrar URL: http://www.danesconames.com
1204 Updated Date: 2017-07-14T08:23:12Z
1205 Creation Date: 2008-02-04T10:10:12Z
1206 Registry Expiry Date: 2018-02-04T10:10:12Z
1207 Registrar: Danesco Trading Ltd.
1208 Registrar IANA ID: 1418
1209 Registrar Abuse Contact Email:
1210 Registrar Abuse Contact Phone:
1211 Domain Status: ok https://icann.org/epp#ok
1212 Name Server: NS1.WOLFSTRADE.COM
1213 Name Server: NS2.WOLFSTRADE.COM
1214 DNSSEC: unsigned
1215
1216
1217Domain Name: DARK-INCEST.COM
1218Registry Domain ID:
1219Registrar WHOIS Server: whois.evonames.com
1220Registrar URL: https://evonames.com/
1221Updated Date: 2017-07-14 08:24:18.404497
1222Creation Date: 2008-02-04
1223Registrar Registration Expiration Date: 2018-02-04
1224Registrar: DANESCO TRADING LTD
1225Registrar IANA ID: 1418
1226Registrar Abuse Contact Email: abuse@evonames.com
1227Registrar Abuse Contact Phone: +357.95713635
1228Reseller: AHnames.com https://www.AHnames.com/
1229Domain Status: ok
1230Registry Registrant ID: MR_2941395WP
1231Registrant Name: WhoisProtectService.net
1232Registrant Organization: PROTECTSERVICE, LTD.
1233Registrant Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1234Registrant City: Limassol
1235Registrant State/Province:
1236Registrant Postal Code: 3025
1237Registrant Country: Cyprus
1238Registrant Phone: +357.95713635
1239Registrant Phone Ext:
1240Registrant Fax: +357.95713635
1241Registrant Fax Ext:
1242Registrant Email: dark-incest.com@whoisprotectservice.net
1243Registry Admin ID: MR_2941395WP
1244Admin Name: WhoisProtectService.net
1245Admin Organization: PROTECTSERVICE, LTD.
1246Admin Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1247Admin City: Limassol
1248Admin State/Province:
1249Admin Postal Code: 3025
1250Admin Country: Cyprus
1251Admin Phone: +357.95713635
1252Admin Phone Ext:
1253Admin Fax: +357.95713635
1254Admin Fax Ext:
1255Admin Email: dark-incest.com@whoisprotectservice.net
1256Registry Tech ID: MR_2941395WP
1257Tech Name: WhoisProtectService.net
1258Tech Organization: PROTECTSERVICE, LTD.
1259Tech Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1260Tech City: Limassol
1261Tech State/Province:
1262Tech Postal Code: 3025
1263Tech Country: Cyprus
1264Tech Phone: +357.95713635
1265Tech Phone Ext:
1266Tech Fax: +357.95713635
1267Tech Fax Ext:
1268Tech Email: dark-incest.com@whoisprotectservice.net
1269Registry Billing ID: MR_2941395WP
1270Billing Name: WhoisProtectService.net
1271Billing Organization: PROTECTSERVICE, LTD.
1272Billing Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1273Billing City: Limassol
1274Billing State/Province:
1275Billing Postal Code: 3025
1276Billing Country: Cyprus
1277Billing Phone: +357.95713635
1278Billing Phone Ext:
1279Billing Fax: +357.95713635
1280Billing Fax Ext:
1281Billing Email: dark-incest.com@whoisprotectservice.net
1282Name Server: NS1.WOLFSTRADE.COM
1283Name Server: NS2.WOLFSTRADE.COM
1284N:
1285;dark-incest.com. IN ANY
1286
1287;; ANSWER SECTION:
1288dark-incest.com. 14328 IN A 108.59.13.136
1289dark-incest.com. 14328 IN NS ns1.wolfstrade.com.
1290dark-incest.com. 14328 IN NS ns2.wolfstrade.com.
1291
1292;; Query time: 9 msec
1293;; SERVER: 192.168.1.254#53(192.168.1.254)
1294;; WHEN: Tue Aug 29 06:59:07 EDT 2017
1295;; MSG SIZE rcvd: 107
1296
1297
1298
1299Running:
1300 traceroute -T -O info -i eth0 dark-incest.com
1301traceroute to dark-incest.com (108.59.13.136), 30 hops max, 60 byte packets
1302 1 gateway (192.168.1.254) 0.550 ms 0.729 ms 0.892 ms
1303 2 10.135.18.1 (10.135.18.1) 10.071 ms 10.673 ms 10.728 ms
1304 3 75.154.223.209 (75.154.223.209) 32.460 ms 32.630 ms 32.766 ms
1305 4 * * *
1306 5 * * *
1307 6 po-1.ce02.wdc-01.us.leaseweb.net (108.59.15.139) 59.335 ms po-12.ce01.wdc-01.us.leaseweb.net (108.59.15.149) 56.829 ms po-1.ce01.wdc-01.us.leaseweb.net (108.59.15.133) 56.604 ms
1308 7 108.59.13.136 (108.59.13.136) <syn,ack> 56.983 ms 57.350 ms 57.475 ms
1309
1310
1311Smartmatch is experimental at /usr/bin/dnsenum line 698.
1312Smartmatch is experimental at /usr/bin/dnsenum line 698.
1313dnsenum VERSION:1.2.4
1314Warning: can't load Net::Whois::IP module, whois queries disabled.
1315
1316----- dark-incest.com -----
1317
1318
1319Host's addresses:
1320__________________
1321
1322dark-incest.com. 14268 IN A 108.59.13.136
1323
1324
1325Name Servers:
1326______________
1327
1328ns1.wolfstrade.com. 14400 IN A 198.7.56.76
1329ns2.wolfstrade.com. 14400 IN A 198.7.56.77
1330
1331
1332Mail (MX) Servers:
1333___________________
1334
1335mail.dark-incest.com. 14400 IN A 108.59.13.136
1336
1337
1338Trying Zone Transfers and getting Bind Versions:
1339_________________________________________________
1340
1341
1342Trying Zone Transfer for dark-incest.com on ns1.wolfstrade.com ...
1343dark-incest.com. 14400 IN SOA (
1344dark-incest.com. 14400 IN MX 10
1345dark-incest.com. 14400 IN TXT "v=spf1
1346dark-incest.com. 14400 IN NS ns1.wolfstrade.com.
1347dark-incest.com. 14400 IN NS ns2.wolfstrade.com.
1348dark-incest.com. 14400 IN A 108.59.13.136
1349ftp.dark-incest.com. 14400 IN A 108.59.13.136
1350localhost.dark-incest.com. 14400 IN A 127.0.0.1
1351mail.dark-incest.com. 14400 IN A 108.59.13.136
1352pop.dark-incest.com. 14400 IN A 108.59.13.136
1353smtp.dark-incest.com. 14400 IN A 108.59.13.136
1354www.dark-incest.com. 14400 IN A 108.59.13.136
1355
1356Trying Zone Transfer for dark-incest.com on ns2.wolfstrade.com ...
1357dark-incest.com. 14400 IN SOA (
1358dark-incest.com. 14400 IN MX 10
1359dark-incest.com. 14400 IN TXT "v=spf1
1360dark-incest.com. 14400 IN NS ns1.wolfstrade.com.
1361dark-incest.com. 14400 IN NS ns2.wolfstrade.com.
1362dark-incest.com. 14400 IN A 108.59.13.136
1363ftp.dark-incest.com. 14400 IN A 108.59.13.136
1364localhost.dark-incest.com. 14400 IN A 127.0.0.1
1365mail.dark-incest.com. 14400 IN A 108.59.13.136
1366pop.dark-incest.com. 14400 IN A 108.59.13.136
1367smtp.dark-incest.com. 14400 IN A 108.59.13.136
1368www.dark-incest.com. 14400 IN A 108.59.13.136
1369
1370
1371
1372dark-incest.com class C netranges:
1373___________________________________
1374
1375 108.59.13.0/24
1376
1377
1378
1379done.
1380
1381
1382dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
1383
1384[+] searching (sub)domains for dark-incest.com using built-in wordlist
1385[+] using maximum random delay of 10 millisecond(s) between requests
1386
1387ftp.dark-incest.com
1388IP address #1: 108.59.13.136
1389
1390localhost.dark-incest.com
1391IP address #1: 127.0.0.1
1392[+] warning: domain might be vulnerable to "same site" scripting (http://snipurl.com/etbcv)
1393
1394mail.dark-incest.com
1395IP address #1: 108.59.13.136
1396
1397pop.dark-incest.com
1398IP address #1: 108.59.13.136
1399
1400smtp.dark-incest.com
1401IP address #1: 108.59.13.136
1402
1403www.dark-incest.com
1404IP address #1: 108.59.13.136
1405
1406[+] 6 (sub)domains and 6 IP address(es) found
1407[+] completion time: 104 second(s)
1408
1409
1410Tracing to dark-incest.com[a] via 192.168.1.254, maximum of 3 retries
1411192.168.1.254 (192.168.1.254) Got answer
1412
1413
1414WhatWeb report for http://dark-incest.com
1415Status : 200 OK
1416Title : Dark Incest - Best Collection Of The Darkest Incest Pics & Videos!
1417IP : 108.59.13.136
1418Country : UNITED STATES, US
1419
1420Summary : nginx[1.6.2], Script[JavaScript,text/javascript], HTTPServer[nginx/1.6.2], Email[webmaster@bestcutesex.com]
1421
1422Detected Plugins:
1423[ Email ]
1424 Extract email addresses. Find valid email address and
1425 syntactically invalid email addresses from mailto: link
1426 tags. We match syntactically invalid links containing
1427 mailto: to catch anti-spam email addresses, eg. bob at
1428 gmail.com. This uses the simplified email regular
1429 expression from
1430 http://www.regular-expressions.info/email.html for valid
1431 email address matching.
1432
1433 String : webmaster@bestcutesex.com
1434 String : webmaster@bestcutesex.com
1435
1436[ HTTPServer ]
1437 HTTP server header string. This plugin also attempts to
1438 identify the operating system from the server header.
1439
1440 String : nginx/1.6.2 (from server string)
1441
1442[ Script ]
1443 This plugin detects instances of script HTML elements and
1444 returns the script language/type.
1445
1446 String : JavaScript,text/javascript
1447
1448[ nginx ]
1449 Nginx (Engine-X) is a free, open-source, high-performance
1450 HTTP server and reverse proxy, as well as an IMAP/POP3
1451 proxy server.
1452
1453 Version : 1.6.2
1454 Website : http://nginx.net/
1455
1456HTTP Headers:
1457 HTTP/1.1 200 OK
1458 Server: nginx/1.6.2
1459 Date: Tue, 29 Aug 2017 09:14:18 GMT
1460 Content-Type: text/html
1461 Content-Length: 27296
1462 Connection: close
1463 Accept-Ranges: bytes
1464 Vary: Accept-Encoding,User-Agent
1465 Content-Encoding: gzi
1466
1467
1468[+] Hosts found in search engines:
1469------------------------------------
1470[-] Resolving hostnames IPs...
1471108.59.13.136:mail.dark-incest.com
1472108.59.13.136:www.dark-incest.com
1473
1474
1475
1476 ^ ^
1477 _ __ _ ____ _ __ _ _ ____
1478 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
1479 | V V // o // _/ | V V // 0 // 0 // _/
1480 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
1481 <
1482 ...'
1483
1484 WAFW00F - Web Application Firewall Detection Tool
1485
1486 By Sandro Gauci && Wendel G. Henrique
1487
1488Checking http://dark-incest.com
1489Generic Detection results:
1490No WAF detected by the generic detection
1491Number of requests: 13
1492
1493
1494DNS Servers for dark-incest.com:
1495 ns2.wolfstrade.com
1496 ns1.wolfstrade.com
1497
1498Trying zone transfer first...
1499 Testing ns2.wolfstrade.com
1500
1501Whoah, it worked - misconfigured DNS server found:
1502dark-incest.com. 14400 IN SOA ( ns1.wolfstrade.com. hostmaster.dark-incest.com.
1503 2014092901 ;serial
1504 14400 ;refresh
1505 3600 ;retry
1506 1209600 ;expire
1507 86400 ;minimum
1508 )
1509dark-incest.com. 14400 IN MX 10 mail.dark-incest.com.
1510dark-incest.com. 14400 IN TXT "v=spf1 a mx ip4:108.59.13.136 ~all"
1511dark-incest.com. 14400 IN NS ns1.wolfstrade.com.
1512dark-incest.com. 14400 IN NS ns2.wolfstrade.com.
1513dark-incest.com. 14400 IN A 108.59.13.136
1514ftp.dark-incest.com. 14400 IN A 108.59.13.136
1515localhost.dark-incest.com. 14400 IN A 127.0.0.1
1516mail.dark-incest.com. 14400 IN A 108.59.13.136
1517pop.dark-incest.com. 14400 IN A 108.59.13.136
1518smtp.dark-incest.com. 14400 IN A 108.59.13.136
1519www.dark-incest.com. 14400 IN A 108.59.13.136
1520
1521
1522
1523Checking for HTTP-Loadbalancing [Date]: 09:15:13, 09:15:13, 09:15:13, 09:15:14, 09:15:14, 09:15:15, 09:15:15, 09:15:15, 09:15:16, 09:15:16, 09:15:17, 09:15:17, 09:15:17, 09:15:18, 09:15:18, 09:15:19, 09:15:19, 09:15:19, 09:15:20, 09:15:20, 09:15:21, 09:15:21, 09:15:22, 09:15:22, 09:15:22, 09:15:23, 09:15:23, 09:15:24, 09:15:24, 09:15:25, 09:15:25, 09:15:25, 09:15:26, 09:15:26, 09:15:27, 09:15:27, 09:15:27, 09:15:28, 09:15:28, 09:15:29, 09:15:29, 09:15:29, 09:15:30, 09:15:30, 09:15:31, 09:15:31, 09:15:31, 09:15:32, 09:15:32, 09:15:32, NOT FOUND
1524
1525Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
1526
1527dark-incest.com does NOT use Load-balancing.
1528
1529
1530
1531Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
1532
1533 ----------------------------------------------------------
1534| Scan Information |
1535 ----------------------------------------------------------
1536
1537Mode ..................... VRFY
1538Worker Processes ......... 5
1539Usernames file ........... users.txt
1540Target count ............. 1
1541Username count ........... 494
1542Target TCP port .......... 25
1543Query timeout ............ 5 secs
1544Target domain ............
1545
1546######## Scan started at Tue Aug 29 07:06:46 2017 #########
1547######## Scan completed at Tue Aug 29 07:15:01 2017 #########
15480 results.
1549
1550494 queries in 495 seconds (1.0 queries / sec)
1551
1552
1553
1554Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 07:15 EDT
1555NSE: Loaded 146 scripts for scanning.
1556NSE: Script Pre-scanning.
1557Initiating NSE at 07:15
1558Completed NSE at 07:15, 0.00s elapsed
1559Initiating NSE at 07:15
1560Completed NSE at 07:15, 0.00s elapsed
1561Failed to resolve "dark-incest.com.txt".
1562Initiating Parallel DNS resolution of 1 host. at 07:15
1563Completed Parallel DNS resolution of 1 host. at 07:15, 0.43s elapsed
1564Initiating SYN Stealth Scan at 07:15
1565Scanning dark-incest.com (108.59.13.136) [100 ports]
1566Discovered open port 993/tcp on 108.59.13.136
1567Discovered open port 143/tcp on 108.59.13.136
1568Discovered open port 53/tcp on 108.59.13.136
1569Discovered open port 443/tcp on 108.59.13.136
1570Discovered open port 995/tcp on 108.59.13.136
1571Discovered open port 110/tcp on 108.59.13.136
1572Increasing send delay for 108.59.13.136 from 0 to 5 due to 11 out of 25 dropped probes since last increase.
1573Discovered open port 80/tcp on 108.59.13.136
1574Discovered open port 81/tcp on 108.59.13.136
1575Completed SYN Stealth Scan at 07:15, 6.55s elapsed (100 total ports)
1576Initiating Service scan at 07:15
1577Scanning 8 services on dark-incest.com (108.59.13.136)
1578Completed Service scan at 07:15, 13.23s elapsed (8 services on 1 host)
1579Initiating OS detection (try #1) against dark-incest.com (108.59.13.136)
1580Retrying OS detection (try #2) against dark-incest.com (108.59.13.136)
1581adjust_timeouts2: packet supposedly had rtt of -78384 microseconds. Ignoring time.
1582adjust_timeouts2: packet supposedly had rtt of -78384 microseconds. Ignoring time.
1583adjust_timeouts2: packet supposedly had rtt of -79506 microseconds. Ignoring time.
1584adjust_timeouts2: packet supposedly had rtt of -79506 microseconds. Ignoring time.
1585adjust_timeouts2: packet supposedly had rtt of -79504 microseconds. Ignoring time.
1586adjust_timeouts2: packet supposedly had rtt of -79504 microseconds. Ignoring time.
1587Initiating Traceroute at 07:15
1588Completed Traceroute at 07:15, 3.01s elapsed
1589Initiating Parallel DNS resolution of 10 hosts. at 07:15
1590Completed Parallel DNS resolution of 10 hosts. at 07:15, 5.62s elapsed
1591NSE: Script scanning 108.59.13.136.
1592Initiating NSE at 07:15
1593Completed NSE at 07:16, 31.54s elapsed
1594Initiating NSE at 07:16
1595Completed NSE at 07:16, 0.00s elapsed
1596Nmap scan report for dark-incest.com (108.59.13.136)
1597Host is up (0.19s latency).
1598Not shown: 83 closed ports
1599PORT STATE SERVICE VERSION
160021/tcp filtered ftp
160122/tcp filtered ssh
160225/tcp filtered smtp
160353/tcp open domain ISC BIND 9.8.2rc1
1604| dns-nsid:
1605|_ bind.version: 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6_8.2
160680/tcp open http nginx 1.6.2
1607|_http-favicon: Unknown favicon MD5: 70754F3BCB2695D453477397E93B3A13
1608| http-methods:
1609|_ Supported Methods: GET HEAD POST OPTIONS
1610| http-robots.txt: 2 disallowed entries
1611|_/cgi-bin /progress
1612|_http-server-header: nginx/1.6.2
1613|_http-title: Dark Incest - Best Collection Of The Darkest Incest Pics & Vid...
161481/tcp open http Apache httpd 2
1615|_http-server-header: Apache/2
1616|_http-title: Dark Incest - Best Collection Of The Darkest Incest Pics & Vid...
1617110/tcp open pop3 Dovecot DirectAdmin pop3d
1618135/tcp filtered msrpc
1619139/tcp filtered netbios-ssn
1620143/tcp open imap Dovecot imapd
1621443/tcp open ssl/ssl Apache httpd (SSL-only mode)
1622| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
1623| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=US
1624| Public Key type: rsa
1625| Public Key bits: 1024
1626| Signature Algorithm: sha1WithRSAEncryption
1627| Not valid before: 2014-09-26T09:14:09
1628| Not valid after: 2042-02-10T09:14:09
1629| MD5: 4468 05d4 8d79 4b82 64bc 27ac ce48 efaa
1630|_SHA-1: f3a3 7aea 38ed 0a56 116e 8c5e 4e5a b6a2 15d8 9572
1631|_ssl-date: 2017-08-29T09:24:49+00:00; -1h50m58s from scanner time.
1632445/tcp filtered microsoft-ds
1633465/tcp filtered smtps
1634587/tcp filtered submission
1635993/tcp open ssl/imap Dovecot DirectAdmin imapd
1636| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
1637| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
1638| Public Key type: rsa
1639| Public Key bits: 1024
1640| Signature Algorithm: sha1WithRSAEncryption
1641| Not valid before: 2011-07-19T08:56:59
1642| Not valid after: 2038-12-03T08:56:59
1643| MD5: 7ca0 14bc e517 e437 b49c aca7 17cc fbc6
1644|_SHA-1: 77bc fd19 856a a562 f719 604a 0461 2093 b012 5405
1645|_ssl-date: 2017-08-29T09:24:56+00:00; -1h50m56s from scanner time.
1646995/tcp open ssl/pop3 Dovecot DirectAdmin pop3d
1647| ssl-cert: Subject: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
1648| Issuer: commonName=localhost/organizationName=none/stateOrProvinceName=Someprovince/countryName=GB
1649| Public Key type: rsa
1650| Public Key bits: 1024
1651| Signature Algorithm: sha1WithRSAEncryption
1652| Not valid before: 2011-07-19T08:56:59
1653| Not valid after: 2038-12-03T08:56:59
1654| MD5: 7ca0 14bc e517 e437 b49c aca7 17cc fbc6
1655|_SHA-1: 77bc fd19 856a a562 f719 604a 0461 2093 b012 5405
1656|_ssl-date: 2017-08-29T09:24:47+00:00; -1h50m56s from scanner time.
165710000/tcp filtered snet-sensor-mgmt
1658Device type: media device|general purpose|firewall|broadband router
1659Running (JUST GUESSING): Tiandy embedded (94%), Linux 3.X|2.6.X (94%), IPCop 2.X|1.X (91%), D-Link embedded (89%), IPFire 2.X (89%)
1660OS CPE: cpe:/o:linux:linux_kernel:3.2 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:ipcop:ipcop:2.0 cpe:/o:linux:linux_kernel:3.4 cpe:/h:dlink:dsl-2890al cpe:/o:linux:linux_kernel:2.6.25.20 cpe:/o:ipcop:ipcop:1.9.19 cpe:/o:ipfire:ipfire:2.9
1661Aggressive OS guesses: Tiandy NVR (94%), Linux 3.2 (94%), Linux 2.6.32 (93%), IPCop 2.0 (Linux 2.6.32) (91%), IPCop 2 firewall (Linux 3.4) (90%), Linux 3.0 (90%), Linux 3.18 (89%), Linux 2.6.18 - 2.6.22 (89%), D-Link DSL-2890AL ADSL router (89%), OpenWrt Kamikaze 8.09 (Linux 2.6.25.20) (89%)
1662No exact OS matches for host (test conditions non-ideal).
1663Network Distance: 12 hops
1664TCP Sequence Prediction: Difficulty=257 (Good luck!)
1665IP ID Sequence Generation: All zeros
1666Service Info: Host: localhost; OS: Red Hat Enterprise Linux 6; CPE: cpe:/o:redhat:enterprise_linux:6
1667
1668Host script results:
1669|_clock-skew: mean: -1h50m56s, deviation: 1s, median: -1h50m56s
1670
1671TRACEROUTE (using port 199/tcp)
1672HOP RTT ADDRESS
16731 109.75 ms 10.13.0.1
16742 149.69 ms 37.187.24.252
16753 110.27 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
16764 111.86 ms 10.95.33.8
16775 114.10 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
16786 179.91 ms be100-1295.nwk-1-a9.nj.us (192.99.146.127)
16797 181.97 ms be100-2.nwk-5-a9.nj.us (178.32.135.219)
16808 182.04 ms nyc-ms1.us.leaseweb.net (198.32.118.171)
16819 ... 10
168211 187.29 ms po-6.ce01.wdc-01.us.leaseweb.net (108.59.15.127)
168312 187.42 ms 108.59.13.136
1684
1685NSE: Script Post-scanning.
1686Initiating NSE at 07:16
1687Completed NSE at 07:16, 0.00s elapsed
1688Initiating NSE at 07:16
1689Completed NSE at 07:16, 0.00s elapsed
1690Read data files from: /usr/bin/../share/nmap
1691OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1692Nmap done: 1 IP address (1 host up) scanned in 66.71 seconds
1693 Raw packets sent: 215 (11.794KB) | Rcvd: 231 (32.261KB)
1694
1695
1696Error: can not open nmap file: dark-incest.com.txt
1697
1698
1699httprint v0.301 (beta) - web server fingerprinting tool
1700(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
1701http://net-square.com/httprint/
1702httprint@net-square.com
1703
1704Finger Printing on http://dark-incest.com:80/
1705Finger Printing Completed on http://dark-incest.com:80/
1706--------------------------------------------------
1707Host: dark-incest.com
1708Fingerprinting Error: Host/URL not found...
1709
1710--------------------------------------------------
1711
1712
1713
1714
1715 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
1716 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
1717 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
1718 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
1719 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
1720
1721 _/ User-Agent Tester ↵
1722 _/ AKA: Purple Pimp ↵
1723 _/ ChrisJohnRiley ↵
1724 _/ blog.c22.cc ↵
1725
1726 [>] Performing initial request and confirming stability
1727 [>] Using User-Agent string Mozilla/5.0
1728
1729 [ ] URL (ENTERED): http://dark-incest.com
1730 [ ] Response Code: 200 OK
1731 [ ] Server: nginx/1.6.2
1732 [ ] Date: Tue, 29 Aug 2017 09:25:19 GMT
1733 [ ] Content-Type: text/html
1734 [ ] Transfer-Encoding: chunked
1735 [ ] Connection: close
1736 [ ] Accept-Ranges: bytes
1737 [ ] Vary: Accept-Encoding,User-Agent
1738 [ ] Data (MD5): 0146164d84f13aa012b41e7c831a5ed2
1739
1740 [1] Pass
1741 [2] Pass
1742 [3] Pass
1743
1744 [>] URL appears stable. Beginning test
1745
1746 [>] Using DEFAULT User-Agent Strings
1747
1748 [>] Using Crazy User-Agent Strings
1749 [>] Using Bot User-Agent Strings
1750
1751 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
1752
1753
1754 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
1755
1756
1757 [!] Data (MD5): 539a27955a5ac1f57514f1c5f23e05db
1758
1759
1760 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
1761
1762
1763 [!] Data (MD5): b32988c172c60da85830ebdf41bb7cd9
1764
1765
1766 [>] User-Agent String : TrackBack/1.02
1767
1768
1769 [!] Data (MD5): fe4d5836dc2fbaf704edff4959951f4b
1770
1771
1772 [>] User-Agent String : wispr
1773
1774
1775 [!] Data (MD5): 2231568155890787f4f4384d92e62df2
1776
1777
1778 [>] User-Agent String : EMPTY USER-AGENT STRING!
1779
1780
1781 [!] Data (MD5): a971a97b6b5baa50949b9795bf1ed4d2
1782
1783
1784 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
1785
1786
1787 [!] Data (MD5): ff079578332b5018ba5e2bdff8a65334
1788
1789
1790 [>] User-Agent String : Googlebot-Image/1.0
1791
1792
1793 [!] Data (MD5): acad56d4a2059febebcc0095737ccdaf
1794
1795
1796 [>] User-Agent String : Mediapartners-Google
1797
1798
1799 [!] Data (MD5): df8f2cd8ee3dd667d12cf138f06fca8e
1800
1801
1802 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
1803
1804
1805 [!] Data (MD5): abcb689b27012166ab753ad5fef554ad
1806
1807
1808 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
1809
1810
1811 [!] Data (MD5): c93196dbe23f0655967ff4d832986e3f
1812
1813
1814 [>] User-Agent String : mmcrawler
1815
1816
1817 [!] Data (MD5): cc5afdaeea5e5dffead7d14fdaa3a4fc
1818
1819
1820 [>] Checks completed... try enabling VERBOSE mode for more detailed output
1821
1822 [>] That's all folks... Fo' Shizzle!
1823
1824
1825
1826
1827 Enter your target IP : 108.59.13.136
1828
1829 obtention site Joomla ...
1830
1831
1832
1833
1834 obtention site Wordpress ...
1835
1836https://0.r.bat.bing.com
1837https://37003672.r.bat.bing.com
1838https://390776.r.bat.bing.com
1839[i] Scanning Site: http://dark-incest.com
1840
1841
1842
1843B A S I C I N F O
1844====================
1845
1846
1847[+] Site Title: Dark Incest - Best Collection Of The Darkest Incest Pics & Videos!
1848[+] IP address: 108.59.13.136
1849[+] Web Server: nginx/1.6.2
1850[+] CMS: Could Not Detect
1851[+] Cloudflare: Not Detected
1852[+] Robots File: Found
1853
1854-------------[ contents ]----------------
1855User-agent: *
1856Disallow: /cgi-bin
1857Disallow: /progress
1858-----------[end of contents]-------------
1859
1860
1861
1862W H O I S L O O K U P
1863========================
1864
1865 Domain Name: DARK-INCEST.COM
1866 Registry Domain ID: 1394954848_DOMAIN_COM-VRSN
1867 Registrar WHOIS Server: whois.evonames.com
1868 Registrar URL: http://www.danesconames.com
1869 Updated Date: 2017-07-14T08:23:12Z
1870 Creation Date: 2008-02-04T10:10:12Z
1871 Registry Expiry Date: 2018-02-04T10:10:12Z
1872 Registrar: Danesco Trading Ltd.
1873 Registrar IANA ID: 1418
1874 Registrar Abuse Contact Email:
1875 Registrar Abuse Contact Phone:
1876 Domain Status: ok https://icann.org/epp#ok
1877 Name Server: NS1.WOLFSTRADE.COM
1878 Name Server: NS2.WOLFSTRADE.COM
1879
1880
1881
1882G E O I P L O O K U P
1883=========================
1884
1885[i] IP Address: 108.59.13.136
1886[i] Country: US
1887[i] State: Delaware
1888[i] City: N/A
1889[i] Latitude: 39.673401
1890[i] Longitude: -75.705200
1891
1892
1893
1894
1895H T T P H E A D E R S
1896=======================
1897
1898
1899[i] HTTP/1.1 200 OK
1900[i] Server: nginx/1.6.2
1901[i] Date: Tue, 29 Aug 2017 09:12:29 GMT
1902[i] Content-Type: text/html
1903[i] Connection: close
1904[i] Accept-Ranges: bytes
1905[i] Vary: Accept-Encoding,User-Agent
1906
1907
1908
1909
1910D N S L O O K U P
1911===================
1912
1913dark-incest.com. 14346 IN A 108.59.13.136
1914dark-incest.com. 14399 IN NS ns1.wolfstrade.com.
1915dark-incest.com. 14399 IN NS ns2.wolfstrade.com.
1916dark-incest.com. 14399 IN SOA ns1.wolfstrade.com. hostmaster.dark-incest.com. 2014092901 14400 3600 1209600 86400
1917dark-incest.com. 14399 IN MX 10 mail.dark-incest.com.
1918dark-incest.com. 14399 IN TXT "v=spf1 a mx ip4:108.59.13.136 ~all"
1919
1920
1921
1922
1923S U B N E T C A L C U L A T I O N
1924====================================
1925
1926Address = 108.59.13.136
1927Network = 108.59.13.136 / 32
1928Netmask = 255.255.255.255
1929Broadcast = not needed on Point-to-Point links
1930Wildcard Mask = 0.0.0.0
1931Hosts Bits = 0
1932Max. Hosts = 1 (2^0 - 0)
1933Host Range = { 108.59.13.136 - 108.59.13.136 }
1934
1935
1936
1937N M A P P O R T S C A N
1938============================
1939
1940
1941Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 11:03 UTC
1942Nmap scan report for dark-incest.com (108.59.13.136)
1943Host is up (0.056s latency).
1944PORT STATE SERVICE VERSION
194521/tcp filtered ftp
194622/tcp filtered ssh
194723/tcp closed telnet
194825/tcp open smtp Exim smtpd 4.76
194980/tcp open http nginx 1.6.2
1950110/tcp open pop3 Dovecot DirectAdmin pop3d
1951143/tcp open imap Dovecot imapd
1952443/tcp open ssl/http Apache httpd 2
1953445/tcp filtered microsoft-ds
19543389/tcp closed ms-wbt-server
1955
1956S U B - D O M A I N F I N D E R
1957==================================
1958
1959
1960[i] Total Subdomains Found : 2
1961
1962[+] Subdomain: dark-incest.com
1963[-] IP: 108.59.13.136
1964
1965[+] Subdomain: mail.dark-incest.com
1966[-] IP: 108.59.13.136
1967
1968
1969
1970
1971
1972R E V E R S E I P L O O K U P
1973==================================
1974
1975
1976[i] Total Sites Found On This Server : 3
1977
1978
1979[#] fame-girls.com
1980[-] CMS: Could Not Detect
1981
1982[#] members.fame-girls.com
1983[-] CMS: Could Not Detect
1984
1985[#] www.sonandmother.com,
1986[-] CMS: Could Not Detect
1987
1988
1989
1990
1991---------------------------------------------------------------------------
1992+ Target IP: 108.59.13.136
1993+ Target Hostname: 108.59.13.136
1994+ Target Port: 80
1995+ Start Time: 2017-08-29 07:06:15 (GMT-4)
1996---------------------------------------------------------------------------
1997+ Server: nginx/1.6.2
1998+ The anti-clickjacking X-Frame-Options header is not present.
1999+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
2000+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
2001+ Allowed HTTP Methods: GET, HEAD, POST, OPTIONS
2002+ Retrieved x-powered-by header: PHP/5.2.17
2003+ Server leaks inodes via ETags, header found with file /phpMyAdmin/ChangeLog, inode: 49152512, size: 32593, mtime: Sun Jul 28 06:34:50 2013
2004+ OSVDB-3092: /phpMyAdmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
2005+ OSVDB-3092: /phpmyadmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
2006+ Cookie SQMSESSID created without the httponly flag
2007+ OSVDB-3093: /squirrelmail/src/read_body.php: SquirrelMail found
2008+ OSVDB-3233: /icons/README: Apache default file found.
2009+ OSVDB-3092: /phpMyAdmin/Documentation.html: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
2010+ OSVDB-3092: /phpmyadmin/Documentation.html: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
2011+ 8497 requests: 0 error(s) and 13 item(s) reported on remote host
2012+ End Time: 2017-08-29 07:39:34 (GMT-4) (1999 seconds)
2013---
2014#######################################################################################################################################
2015http://www.asian-teen-pussy.com/
2016Hostname www.asian-teen-pussy.com ISP Quasi Networks LTD. (AS29073)
2017Continent Africa Flag
2018SC
2019Country Seychelles Country Code SC (SYC)
2020Region Unknown Local time 29 Aug 2017 17:01 +04
2021City Unknown Latitude -4.583
2022IP Address 80.82.77.146 Longitude 55.667
2023#######################################################################################################################################
2024asian-teen-pussy.com
2025
2026
2027 Domain Name: ASIAN-TEEN-PUSSY.COM
2028 Registry Domain ID: 2128898117_DOMAIN_COM-VRSN
2029 Registrar WHOIS Server: whois.PublicDomainRegistry.com
2030 Registrar URL: http://www.publicdomainregistry.com
2031 Updated Date: 2017-05-29T13:30:40Z
2032 Creation Date: 2017-05-29T13:29:26Z
2033 Registry Expiry Date: 2018-05-29T13:29:26Z
2034 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
2035 Registrar IANA ID: 303
2036 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
2037 Registrar Abuse Contact Phone: +1.2013775952
2038 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2039 Name Server: NS1.MYGIRLSSEX.COM
2040 Name Server: NS2.MYGIRLSSEX.COM
2041
2042Domain Name: ASIAN-TEEN-PUSSY.COM
2043Registry Domain ID: 2128898117_DOMAIN_COM-VRSN
2044Registrar WHOIS Server: whois.publicdomainregistry.com
2045Registrar URL: www.publicdomainregistry.com
2046Updated Date: 2017-07-29T02:33:28Z
2047Creation Date: 2017-05-29T13:29:26Z
2048Registrar Registration Expiration Date: 2018-05-29T13:29:26Z
2049Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
2050Registrar IANA ID: 303
2051Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2052Registry Registrant ID: Not Available From Registry
2053Registrant Name: dmitry
2054Registrant Organization:
2055Registrant Street: ketcherskaya
2056Registrant City: moscow
2057Registrant State/Province: Moscow
2058Registrant Postal Code: 117422
2059Registrant Country: RU
2060Registrant Phone: +7.9281262378
2061Registrant Phone Ext:
2062Registrant Fax:
2063Registrant Fax Ext:
2064Registrant Email: carterserv@safe-mail.net
2065Registry Admin ID: Not Available From Registry
2066Admin Name: dmitry
2067Admin Organization:
2068Admin Street: ketcherskaya
2069Admin City: moscow
2070Admin State/Province: Moscow
2071Admin Postal Code: 117422
2072Admin Country: RU
2073Admin Phone: +7.9281262378
2074Admin Phone Ext:
2075Admin Fax:
2076Admin Fax Ext:
2077Admin Email: carterserv@safe-mail.net
2078Registry Tech ID: Not Available From Registry
2079Tech Name: dmitry
2080Tech Organization:
2081Tech Street: ketcherskaya
2082Tech City: moscow
2083Tech State/Province: Moscow
2084Tech Postal Code: 117422
2085Tech Country: RU
2086Tech Phone: +7.9281262378
2087Tech Phone Ext:
2088Tech Fax:
2089Tech Fax Ext:
2090Tech Email: carterserv@safe-mail.net
2091Name Server: ns1.mygirlssex.com
2092Name Server: ns2.mygirlssex.com
2093DNSSEC:Unsigned
2094Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
2095
2096; <<>> DiG 9.10.3-P4-Debian <<>> asian-teen-pussy.com any
2097;; global options: +cmd
2098;; Got answer:
2099;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60610
2100;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
2101
2102;; OPT PSEUDOSECTION:
2103; EDNS: version: 0, flags:; udp: 4096
2104;; QUESTION SECTION:
2105;asian-teen-pussy.com. IN ANY
2106
2107;; ANSWER SECTION:
2108asian-teen-pussy.com. 14314 IN NS ns2.mygirlssex.com.
2109asian-teen-pussy.com. 14314 IN NS ns1.mygirlssex.com.
2110
2111;; Query time: 8 msec
2112;; SERVER: 192.168.1.254#53(192.168.1.254)
2113;; WHEN: Tue Aug 29 08:59:51 EDT 2017
2114;; MSG SIZE rcvd: 96
2115
2116
2117
2118;; Connection to 192.168.1.254#53(192.168.1.254) for asian-teen-pussy.com failed: connection refused.
2119Host asian-teen-pussy.com not found: 9(NOTAUTH)
2120; Transfer failed.
2121
2122
2123Please type the name of your network interface Example: eth0
2124eth0
2125
2126Running:
2127 traceroute -T -O info -i eth0 asian-teen-pussy.com
2128traceroute to asian-teen-pussy.com (80.82.77.146), 30 hops max, 60 byte packets
2129 1 gateway (192.168.1.254) 0.587 ms 0.765 ms 0.924 ms
2130 2 10.135.18.1 (10.135.18.1) 7.187 ms 17.444 ms *
2131 3 75.154.223.222 (75.154.223.222) 29.782 ms 29.822 ms 29.887 ms
2132 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.556 ms 30.620 ms 30.856 ms
2133 5 ae-239-3615.edge6.Amsterdam1.Level3.net (4.69.162.250) 104.715 ms 104.763 ms 104.809 ms
2134 6 * * *
2135 7 * * *
2136 8 80.82.77.146 (80.82.77.146) <syn,ack> 103.148 ms 103.531 ms 103.124 ms
2137
2138
2139Smartmatch is experimental at /usr/bin/dnsenum line 698.
2140Smartmatch is experimental at /usr/bin/dnsenum line 698.
2141dnsenum VERSION:1.2.4
2142Warning: can't load Net::Whois::IP module, whois queries disabled.
2143
2144----- asian-teen-pussy.com -----
2145
2146
2147Host's addresses:
2148__________________
2149
2150asian-teen-pussy.com. 14392 IN A 80.82.77.146
2151
2152
2153Name Servers:
2154______________
2155
2156ns1.mygirlssex.com. 14400 IN A 80.82.77.146
2157ns2.mygirlssex.com. 14400 IN A 80.82.77.146
2158
2159
2160Mail (MX) Servers:
2161___________________
2162
2163mail.asian-teen-pussy.com. 14400 IN A 80.82.77.146
2164
2165
2166
2167Google Results:
2168________________
2169
2170www.asian-teen-pussy.com. 14263 IN A 80.82.77.146
2171
2172
2173Brute forcing with dns.txt:
2174____________________________
2175
2176ftp.asian-teen-pussy.com. 14400 IN A 80.82.77.146
2177mail.asian-teen-pussy.com. 14379 IN A 80.82.77.146
2178pop.asian-teen-pussy.com. 14400 IN A 80.82.77.146
2179
2180
2181Performing recursion:
2182______________________
2183
2184
2185 ---- Checking subdomains NS records ----
2186
2187 Can't perform recursion no NS records.
2188
2189
2190asian-teen-pussy.com class C netranges:
2191________________________________________
2192
2193 80.82.77.0/24
2194
2195
2196Performing reverse lookup on 256 ip addresses:
2197_______________________________________________
2198
2199
22000 results out of 256 IP addresses.
2201
2202
2203asian-teen-pussy.com ip blocks:
2204________________________________
2205
2206
2207done.
2208
2209
2210dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
2211
2212[+] searching (sub)domains for asian-teen-pussy.com using built-in wordlist
2213[+] using maximum random delay of 10 millisecond(s) between requests
2214
2215ftp.asian-teen-pussy.com
2216IP address #1: 80.82.77.146
2217
2218mail.asian-teen-pussy.com
2219IP address #1: 80.82.77.146
2220
2221pop.asian-teen-pussy.com
2222IP address #1: 80.82.77.146
2223
2224www.asian-teen-pussy.com
2225IP address #1: 80.82.77.146
2226
2227[+] 4 (sub)domains and 4 IP address(es) found
2228[+] completion time: 147 second(s)
2229
2230
2231Tracing to asian-teen-pussy.com[a] via 192.168.1.254, maximum of 3 retries
2232192.168.1.254 (192.168.1.254) Got answer
2233
2234
2235WhatWeb report for http://asian-teen-pussy.com
2236Status : 301 Moved Permanently
2237Title : 301 Moved Permanently
2238IP : 80.82.77.146
2239Country : NETHERLANDS, NL
2240
2241Summary : nginx, RedirectLocation[http://www.asian-teen-pussy.com/], HTTPServer[nginx]
2242
2243Detected Plugins:
2244[ HTTPServer ]
2245 HTTP server header string. This plugin also attempts to
2246 identify the operating system from the server header.
2247
2248 String : nginx (from server string)
2249
2250[ RedirectLocation ]
2251 HTTP Server string location. used with http-status 301 and
2252 302
2253
2254 String : http://www.asian-teen-pussy.com/ (from location)
2255
2256[ nginx ]
2257 Nginx (Engine-X) is a free, open-source, high-performance
2258 HTTP server and reverse proxy, as well as an IMAP/POP3
2259 proxy server.
2260
2261 Website : http://nginx.net/
2262
2263HTTP Headers:
2264 HTTP/1.1 301 Moved Permanently
2265 Server: nginx
2266 Date: Tue, 29 Aug 2017 13:03:59 GMT
2267 Content-Type: text/html; charset=iso-8859-1
2268 Content-Length: 326
2269 Connection: close
2270 Location: http://www.asian-teen-pussy.com/
2271
2272WhatWeb report for http://www.asian-teen-pussy.com/
2273Status : 200 OK
2274Title : Cute amature asian teen pussy galleries pics.
2275IP : 80.82.77.146
2276Country : NETHERLANDS, NL
2277
2278Summary : HTML5, nginx, Script[text/Javascript,text/javascript], PHP[5.4.45], X-Powered-By[PHP/5.4.45], HTTPServer[nginx]
2279
2280Detected Plugins:
2281[ HTML5 ]
2282 HTML version 5, detected by the doctype declaration
2283
2284
2285[ HTTPServer ]
2286 HTTP server header string. This plugin also attempts to
2287 identify the operating system from the server header.
2288
2289 String : nginx (from server string)
2290
2291[ PHP ]
2292 PHP is a widely-used general-purpose scripting language
2293 that is especially suited for Web development and can be
2294 embedded into HTML. This plugin identifies PHP errors,
2295 modules and versions and extracts the local file path and
2296 username if present.
2297
2298 Version : 5.4.45
2299 Google Dorks: (2)
2300 Website : http://www.php.net/
2301
2302[ Script ]
2303 This plugin detects instances of script HTML elements and
2304 returns the script language/type.
2305
2306 String : text/Javascript,text/javascript
2307
2308[ X-Powered-By ]
2309 X-Powered-By HTTP header
2310
2311 String : PHP/5.4.45 (from x-powered-by string)
2312
2313[ nginx ]
2314 Nginx (Engine-X) is a free, open-source, high-performance
2315 HTTP server and reverse proxy, as well as an IMAP/POP3
2316 proxy server.
2317
2318 Website : http://nginx.net/
2319
2320HTTP Headers:
2321 HTTP/1.1 200 OK
2322 Server: nginx
2323 Date: Tue, 29 Aug 2017 13:03:59 GMT
2324 Content-Type: text/html; charset=UTF-8
2325 Transfer-Encoding: chunked
2326 Connection: close
2327 X-Powered-By: PHP/5.4.45
2328 Content-Encoding: gzip
2329
2330
2331
2332
2333------------------------------------
2334[-] Resolving hostnames IPs...
233580.82.77.146:www.asian-teen-pussy.com
2336
2337
2338
2339 ^ ^
2340 _ __ _ ____ _ __ _ _ ____
2341 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2342 | V V // o // _/ | V V // 0 // 0 // _/
2343 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2344 <
2345 ...'
2346
2347 WAFW00F - Web Application Firewall Detection Tool
2348
2349 By Sandro Gauci && Wendel G. Henrique
2350
2351Checking http://asian-teen-pussy.com
2352The site http://asian-teen-pussy.com is behind a IBM Web Application Security
2353Number of requests: 3
2354
2355
2356DNS Servers for asian-teen-pussy.com:
2357 ns2.mygirlssex.com
2358 ns1.mygirlssex.com
2359
2360Trying zone transfer first...
2361 Testing ns2.mygirlssex.com
2362 Request timed out or transfer not allowed.
2363 Testing ns1.mygirlssex.com
2364 Request timed out or transfer not allowed.
2365
2366Unsuccessful in zone transfer (it was worth a shot)
2367Okay, trying the good old fashioned way... brute force
2368
2369Checking for wildcard DNS...
2370Nope. Good.
2371Now performing 2280 test(s)...
237280.82.77.146 ftp.asian-teen-pussy.com
237380.82.77.146 mail.asian-teen-pussy.com
237480.82.77.146 pop.asian-teen-pussy.com
237580.82.77.146 www.asian-teen-pussy.com
2376
2377Subnets found (may want to probe here using nmap or unicornscan):
2378 80.82.77.0-255 : 4 hostnames found.
2379
2380
2381Checking for HTTP-Loadbalancing [Date]: 13:09:51, 13:09:51, 13:09:51, 13:09:52, 13:09:52, 13:09:52, 13:09:53, 13:09:53, 13:09:53, 13:09:54, 13:09:54, 13:09:54, 13:09:54, 13:09:55, 13:09:55, 13:09:55, 13:09:55, 13:09:56, 13:09:56, 13:09:56, 13:09:57, 13:09:57, 13:09:57, 13:09:57, 13:09:58, 13:09:58, 13:09:58, 13:09:58, 13:09:59, 13:09:59, 13:09:59, 13:10:00, 13:10:00, 13:10:00, 13:10:00, 13:10:01, 13:10:01, 13:10:01, 13:10:01, 13:10:02, 13:10:02, 13:10:02, 13:10:02, 13:10:03, 13:10:03, 13:10:03, 13:10:04, 13:10:04, 13:10:04, 13:10:04, NOT FOUND
2382
2383Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2384
2385asian-teen-pussy.com does NOT use Load-balancing.
2386
2387
2388
2389Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
2390
2391 ----------------------------------------------------------
2392| Scan Information |
2393 ----------------------------------------------------------
2394
2395Mode ..................... VRFY
2396Worker Processes ......... 5
2397Usernames file ........... users.txt
2398Target count ............. 1
2399Username count ........... 494
2400Target TCP port .......... 25
2401Query timeout ............ 5 secs
2402Target domain ............
2403
2404######## Scan started at Tue Aug 29 09:10:12 2017 #########
2405######## Scan completed at Tue Aug 29 09:18:27 2017 #########
24060 results.
2407
2408494 queries in 495 seconds (1.0 queries / sec)
2409
2410
2411
2412Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 09:18 EDT
2413NSE: Loaded 146 scripts for scanning.
2414NSE: Script Pre-scanning.
2415Initiating NSE at 09:18
2416Completed NSE at 09:18, 0.00s elapsed
2417Initiating NSE at 09:18
2418Completed NSE at 09:18, 0.00s elapsed
2419Failed to resolve "asian-teen-pussy.com.txt".
2420Initiating Parallel DNS resolution of 1 host. at 09:18
2421Completed Parallel DNS resolution of 1 host. at 09:18, 0.66s elapsed
2422Initiating SYN Stealth Scan at 09:18
2423Scanning asian-teen-pussy.com (80.82.77.146) [100 ports]
2424Discovered open port 21/tcp on 80.82.77.146
2425Discovered open port 80/tcp on 80.82.77.146
2426Discovered open port 8080/tcp on 80.82.77.146
2427Discovered open port 53/tcp on 80.82.77.146
2428Completed SYN Stealth Scan at 09:18, 3.32s elapsed (100 total ports)
2429Initiating Service scan at 09:18
2430Scanning 4 services on asian-teen-pussy.com (80.82.77.146)
2431Completed Service scan at 09:18, 6.29s elapsed (4 services on 1 host)
2432Initiating OS detection (try #1) against asian-teen-pussy.com (80.82.77.146)
2433adjust_timeouts2: packet supposedly had rtt of -105238 microseconds. Ignoring time.
2434adjust_timeouts2: packet supposedly had rtt of -105238 microseconds. Ignoring time.
2435Retrying OS detection (try #2) against asian-teen-pussy.com (80.82.77.146)
2436Initiating Traceroute at 09:18
2437Completed Traceroute at 09:18, 3.13s elapsed
2438Initiating Parallel DNS resolution of 8 hosts. at 09:18
2439Completed Parallel DNS resolution of 8 hosts. at 09:18, 5.62s elapsed
2440NSE: Script scanning 80.82.77.146.
2441Initiating NSE at 09:18
2442Completed NSE at 09:19, 9.34s elapsed
2443Initiating NSE at 09:19
2444Completed NSE at 09:19, 0.00s elapsed
2445Nmap scan report for asian-teen-pussy.com (80.82.77.146)
2446Host is up (0.12s latency).
2447Not shown: 94 filtered ports
2448PORT STATE SERVICE VERSION
244921/tcp open ftp vsftpd 2.2.2
245053/tcp open domain ISC BIND get lost
2451| dns-nsid:
2452|_ bind.version: get lost
245380/tcp open http nginx
2454| http-methods:
2455|_ Supported Methods: GET HEAD POST OPTIONS
2456|_http-server-header: nginx
2457|_http-title: Did not follow redirect to http://www.asian-teen-pussy.com/
245881/tcp closed hosts2-ns
2459443/tcp closed https
24608080/tcp open http Apache httpd 2.2.15 ((CentOS))
2461| http-methods:
2462|_ Supported Methods: GET HEAD POST OPTIONS
2463|_http-open-proxy: Proxy might be redirecting requests
2464|_http-server-header: Apache/2.2.15 (CentOS)
2465|_http-title: Did not follow redirect to http://www.asian-teen-pussy.com/
2466Aggressive OS guesses: Linux 2.6.32 (93%), Linux 3.4 (93%), WatchGuard Fireware 11.8 (93%), Synology DiskStation Manager 5.1 (92%), Linux 3.10 (92%), Linux 2.6.32 or 3.10 (92%), Linux 2.6.39 (92%), Linux 3.1 - 3.2 (92%), Linux 2.6.32 - 2.6.39 (90%), Linux 3.2 - 3.8 (88%)
2467No exact OS matches for host (test conditions non-ideal).
2468Uptime guess: 23.204 days (since Sun Aug 6 04:26:00 2017)
2469Network Distance: 12 hops
2470TCP Sequence Prediction: Difficulty=262 (Good luck!)
2471IP ID Sequence Generation: All zeros
2472Service Info: OS: Unix
2473
2474TRACEROUTE (using port 443/tcp)
2475HOP RTT ADDRESS
24761 110.33 ms 10.13.0.1
24772 110.48 ms 37.187.24.252
24783 110.43 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
24794 ...
24805 119.23 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
24816 119.20 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
24827 ...
24838 201.50 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
24849 120.48 ms 176.10.83.119
248510 ... 11
248612 121.06 ms 80.82.77.146
2487
2488NSE: Script Post-scanning.
2489Initiating NSE at 09:19
2490Completed NSE at 09:19, 0.00s elapsed
2491Initiating NSE at 09:19
2492Completed NSE at 09:19, 0.00s elapsed
2493Read data files from: /usr/bin/../share/nmap
2494OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2495Nmap done: 1 IP address (1 host up) scanned in 39.09 seconds
2496 Raw packets sent: 316 (18.518KB) | Rcvd: 210 (69.588KB)
2497
2498
2499Error: can not open nmap file: asian-teen-pussy.com.txt
2500
2501
2502httprint v0.301 (beta) - web server fingerprinting tool
2503(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
2504http://net-square.com/httprint/
2505httprint@net-square.com
2506
2507Finger Printing on http://asian-teen-pussy.com:80/
2508Finger Printing Completed on http://asian-teen-pussy.com:80/
2509--------------------------------------------------
2510Host: asian-teen-pussy.com
2511Fingerprinting Error: Host/URL not found...
2512
2513--------------------------------------------------
2514
2515
2516
2517
2518 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
2519 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2520 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
2521 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
2522 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
2523
2524 _/ User-Agent Tester ↵
2525 _/ AKA: Purple Pimp ↵
2526 _/ ChrisJohnRiley ↵
2527 _/ blog.c22.cc ↵
2528
2529 [>] Performing initial request and confirming stability
2530 [>] Using User-Agent string Mozilla/5.0
2531
2532 [ ] URL (ENTERED): http://asian-teen-pussy.com
2533 [!] URL (FINAL): http://www.asian-teen-pussy.com/
2534 [!] Response Code: 301 Moved Permanently
2535 [ ] Server: nginx
2536 [ ] Date: Tue, 29 Aug 2017 13:19:17 GMT
2537 [ ] Content-Type: text/html; charset=UTF-8
2538 [ ] Transfer-Encoding: chunked
2539 [ ] Connection: close
2540 [ ] X-Powered-By: PHP/5.4.45
2541 [ ] Data (MD5): d42601ed6800483bc16fb56371c025cb
2542
2543 [1] Pass
2544 [2] Pass
2545 [3] Pass
2546
2547 [>] URL appears stable. Beginning test
2548
2549 [>] Using DEFAULT User-Agent Strings
2550
2551 [>] Using Crazy User-Agent Strings
2552 [>] Using Bot User-Agent Strings
2553
2554 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
2555
2556
2557 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
2558
2559
2560 [!] Data (MD5): 4e3977696afe328539f6d6ea01d97126
2561
2562
2563 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
2564
2565
2566 [!] Data (MD5): 502e9c012ae157fa2ef53cd9ae7187bf
2567
2568
2569 [>] User-Agent String : TrackBack/1.02
2570
2571
2572 [!] Data (MD5): 13c6b790b8ebef7a18fbeda78734a2ce
2573
2574
2575 [>] User-Agent String : wispr
2576
2577
2578 [!] Data (MD5): f590469d9d43631f155227b199242f8d
2579
2580
2581 [>] User-Agent String : EMPTY USER-AGENT STRING!
2582
2583
2584 [!] Data (MD5): 088d78f33d85df33b6a65f8605754653
2585
2586
2587 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
2588
2589
2590 [!] Data (MD5): 969368d312b6223e3fc946118619987b
2591
2592
2593 [>] User-Agent String : Googlebot-Image/1.0
2594
2595
2596 [!] Data (MD5): 7471215346af6aaf2bd5c05eb8d68c29
2597
2598
2599 [>] User-Agent String : Mediapartners-Google
2600
2601
2602 [!] Data (MD5): e44e8f8a9aceb3c7cb228786039a3b36
2603
2604
2605 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
2606
2607
2608 [!] Data (MD5): fda096175a98078e2ef682e3e1eecec8
2609
2610
2611 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
2612
2613
2614 [!] Data (MD5): 28f7203815f657b67aa26260bab1ad62
2615
2616
2617 [>] User-Agent String : mmcrawler
2618
2619
2620 [!] Data (MD5): 4ba6ef7780368052c7a79458b0d25f9a
2621
2622
2623 [>] Checks completed... try enabling VERBOSE mode for more detailed output
2624
2625 [>] That's all folks... Fo' Shizzle!
2626
2627
2628
2629
2630 Enter your target IP : 80.82.77.146
2631
2632 obtention site Joomla ...
2633
2634
2635
2636
2637 obtention site Wordpress ...
2638
2639https://0.r.bat.bing.com
2640https://136002338.r.bat.bing.com
2641https://139092434.r.bat.bing.com
2642https://1871817.r.bat.bing.com
2643https://1871821.r.bat.bing.com
2644[i] Scanning Site: http://asian-teen-pussy.com
2645
2646
2647
2648B A S I C I N F O
2649====================
2650
2651
2652[+] Site Title: Cute amature asian teen pussy galleries pics.
2653[+] IP address: 80.82.77.146
2654[+] Web Server: nginx
2655[+] CMS: Could Not Detect
2656[+] Cloudflare: Not Detected
2657[+] Robots File: Found
2658
2659-------------[ contents ]----------------
2660# vestacp autogenerated robots.txt
2661User-agent: *
2662Crawl-delay: 10
2663
2664-----------[end of contents]-------------
2665
2666
2667
2668W H O I S L O O K U P
2669========================
2670
2671 Domain Name: ASIAN-TEEN-PUSSY.COM
2672 Registry Domain ID: 2128898117_DOMAIN_COM-VRSN
2673 Registrar WHOIS Server: whois.PublicDomainRegistry.com
2674 Registrar URL: http://www.publicdomainregistry.com
2675 Updated Date: 2017-05-29T13:30:40Z
2676 Creation Date: 2017-05-29T13:29:26Z
2677 Registry Expiry Date: 2018-05-29T13:29:26Z
2678 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
2679 Registrar IANA ID: 303
2680 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
2681 Registrar Abuse Contact Phone: +1.2013775952
2682 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2683 Name Server: NS1.MYGIRLSSEX.COM
2684 Name Server: NS2.MYGIRLSSEX.COM
2685
2686
2687
2688
2689G E O I P L O O K U P
2690=========================
2691
2692[i] IP Address: 80.82.77.146
2693[i] Country: SC
2694[i] State: N/A
2695[i] City: N/A
2696[i] Latitude: -4.583300
2697[i] Longitude: 55.666698
2698
2699
2700
2701
2702H T T P H E A D E R S
2703=======================
2704
2705
2706[i] HTTP/1.1 301 Moved Permanently
2707[i] Server: nginx
2708[i] Date: Tue, 29 Aug 2017 13:00:58 GMT
2709[i] Content-Type: text/html; charset=iso-8859-1
2710[i] Content-Length: 326
2711[i] Connection: close
2712[i] Location: http://www.asian-teen-pussy.com/
2713[i] HTTP/1.1 200 OK
2714[i] Server: nginx
2715[i] Date: Tue, 29 Aug 2017 13:00:58 GMT
2716[i] Content-Type: text/html; charset=UTF-8
2717[i] Connection: close
2718[i] X-Powered-By: PHP/5.4.45
2719
2720
2721
2722
2723D N S L O O K U P
2724===================
2725
2726asian-teen-pussy.com. 14395 IN A 80.82.77.146
2727asian-teen-pussy.com. 14400 IN NS ns2.mygirlssex.com.
2728asian-teen-pussy.com. 14400 IN NS ns1.mygirlssex.com.
2729asian-teen-pussy.com. 14400 IN SOA ns1.mygirlssex.com. root.asian-teen-pussy.com. 2017052901 7200 3600 1209600 180
2730asian-teen-pussy.com. 14400 IN MX 10 mail.asian-teen-pussy.com.
2731asian-teen-pussy.com. 14400 IN TXT "v=spf1 a mx ip4:80.82.77.146 ?all"
2732
2733
2734
2735
2736S U B N E T C A L C U L A T I O N
2737====================================
2738
2739Address = 80.82.77.146
2740Network = 80.82.77.146 / 32
2741Netmask = 255.255.255.255
2742Broadcast = not needed on Point-to-Point links
2743Wildcard Mask = 0.0.0.0
2744Hosts Bits = 0
2745Max. Hosts = 1 (2^0 - 0)
2746Host Range = { 80.82.77.146 - 80.82.77.146 }
2747
2748
2749
2750N M A P P O R T S C A N
2751============================
2752
2753
2754Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 13:01 UTC
2755Nmap scan report for asian-teen-pussy.com (80.82.77.146)
2756Host is up (0.083s latency).
2757PORT STATE SERVICE VERSION
275821/tcp open ftp vsftpd 2.2.2
275922/tcp filtered ssh
276023/tcp filtered telnet
276125/tcp open smtp Exim smtpd 4.89
276280/tcp open http nginx
2763110/tcp filtered pop3
2764143/tcp filtered imap
2765443/tcp closed https
2766445/tcp filtered microsoft-ds
27673389/tcp filtered ms-wbt-server
2768Service Info: Host: g10s34.example.com; OS: Unix
2769
2770Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2771Nmap done: 1 IP address (1 host up) scanned in 8.47 seconds
2772
2773
2774
2775S U B - D O M A I N F I N D E R
2776==================================
2777
2778
2779[i] Total Subdomains Found : 1
2780
2781[+] Subdomain: asian-teen-pussy.com
2782[-] IP: 80.82.77.146
2783
2784
2785
2786
2787
2788R E V E R S E I P L O O K U P
2789==================================
2790
2791
2792[i] Total Sites Found On This Server : 4
2793
2794
2795[#] asian-teen-pussy.com,1,babegirlsex.com,1,crazynudeteens.com
2796[-] CMS: Could Not Detect
2797
2798[#] teen-home-tube.com
2799[-] CMS: Could Not Detect
2800
2801[#] www.girlspornvids.com,1,www.sexpornteenage.com,1,www.teenamatureporn.com,1,www.teencutiespics.com
2802[-] CMS: Could Not Detect
2803
2804[#] www.teensexvidoe.com,1,www.xxlpornoteen.com,1
2805[-] CMS: Could Not Detect
2806
2807
2808
2809
2810Crawling Types & Descriptions:
2811 Nikto v2.1.6
2812---------------------------------------------------------------------------
2813+ Target IP: 80.82.77.146
2814+ Target Hostname: asian-teen-pussy.com
2815+ Target Port: 80
2816+ Start Time: 2017-08-29 09:01:04 (GMT-4)
2817---------------------------------------------------------------------------
2818+ Server: nginx
2819+ The anti-clickjacking X-Frame-Options header is not present.
2820+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
2821+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
2822+ Root page / redirects to: http://www.asian-teen-pussy.com/
2823+ Server leaks inodes via ETags, header found with file /cgi-bin/, inode: 56996516, size: 1212, mtime: Mon May 29 09:43:26 2017
2824+ OSVDB-3268: /icons/: Directory indexing found.
2825+ OSVDB-3233: /icons/README: Apache default file found.
2826+ 8256 requests: 0 error(s) and 6 item(s) reported on remote host
2827+ End Time: 2017-08-29 09:21:07 (GMT-4) (1203 seconds)
2828---------------------------------------------------------------------------
2829+ 1 host(s) tested
2830#######################################################################################################################################
2831http://www.teen-pussy-fuck.com
2832 Hostname www.teen-pussy-fuck.com ISP Quasi Networks LTD. (AS29073)
2833Continent Africa Flag
2834SC
2835Country Seychelles Country Code SC (SYC)
2836Region Unknown Local time 29 Aug 2017 18:16 +04
2837City Unknown Latitude -4.583
2838IP Address 80.82.77.146 Longitude 55.667
2839#######################################################################################################################################
2840teen-pussy-fuck.com
2841
2842
2843 Domain Name: TEEN-PUSSY-FUCK.COM
2844 Registry Domain ID: 2128898121_DOMAIN_COM-VRSN
2845 Registrar WHOIS Server: whois.PublicDomainRegistry.com
2846 Registrar URL: http://www.publicdomainregistry.com
2847 Updated Date: 2017-05-29T13:30:41Z
2848 Creation Date: 2017-05-29T13:29:27Z
2849 Registry Expiry Date: 2018-05-29T13:29:27Z
2850 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
2851 Registrar IANA ID: 303
2852 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
2853 Registrar Abuse Contact Phone: +1.2013775952
2854 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
2855 Name Server: NS1.MYGIRLSSEX.COM
2856
2857;teen-pussy-fuck.com. IN ANY
2858
2859;; ANSWER SECTION:
2860teen-pussy-fuck.com. 14381 IN A 80.82.77.146
2861teen-pussy-fuck.com. 14259 IN NS ns1.mygirlssex.com.
2862teen-pussy-fuck.com. 14259 IN NS ns2.mygirlssex.com.
2863
2864;; Query time: 8 msec
2865;; SERVER: 192.168.1.254#53(192.168.1.254)
2866;; WHEN: Tue Aug 29 10:15:58 EDT 2017
2867;; MSG SIZE rcvd: 111
2868
2869
2870
2871Please type the name of your network interface Example: eth0
2872eth0
2873
2874Running:
2875 traceroute -T -O info -i eth0 teen-pussy-fuck.com
2876traceroute to teen-pussy-fuck.com (80.82.77.146), 30 hops max, 60 byte packets
2877 1 gateway (192.168.1.254) 0.575 ms 0.719 ms 0.844 ms
2878 2 10.135.18.1 (10.135.18.1) 8.106 ms 12.772 ms 13.449 ms
2879 3 75.154.223.222 (75.154.223.222) 29.706 ms 29.895 ms 30.043 ms
2880 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.405 ms 30.464 ms 30.750 ms
2881 5 ae-239-3615.edge6.Amsterdam1.Level3.net (4.69.162.250) 104.163 ms 104.206 ms 104.216 ms
2882 6 * * *
2883 7 * * *
2884 8 80.82.77.146 (80.82.77.146) <syn,ack> 104.074 ms 103.321 ms 103.599 ms
2885
2886
2887----- teen-pussy-fuck.com -----
2888
2889
2890Host's addresses:
2891__________________
2892
2893teen-pussy-fuck.com. 14352 IN A 80.82.77.146
2894
2895
2896Name Servers:
2897______________
2898
2899ns1.mygirlssex.com. 14400 IN A 80.82.77.146
2900ns2.mygirlssex.com. 14400 IN A 80.82.77.146
2901
2902
2903Mail (MX) Servers:
2904___________________
2905
2906mail.teen-pussy-fuck.com. 14400 IN A 80.82.77.146
2907
2908
2909Google Results:
2910________________
2911
2912 perhaps Google is blocking our queries.
2913 Check manually.
2914
2915
2916Brute forcing with dns.txt:
2917____________________________
2918
2919ftp.teen-pussy-fuck.com. 14400 IN A 80.82.77.146
2920mail.teen-pussy-fuck.com. 14378 IN A 80.82.77.146
2921pop.teen-pussy-fuck.com. 14400 IN A 80.82.77.146
2922www.teen-pussy-fuck.com. 14193 IN A 80.82.77.146
2923
2924
2925teen-pussy-fuck.com class C netranges:
2926_______________________________________
2927
2928 80.82.77.0/24
2929
2930
2931Performing reverse lookup on 256 ip addresses:
2932_______________________________________________
2933
2934
29350 results out of 256 IP addresses.
2936
2937
2938teen-pussy-fuck.com ip blocks:
2939_______________________________
2940
2941
2942done.
2943
2944
2945dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
2946
2947[+] searching (sub)domains for teen-pussy-fuck.com using built-in wordlist
2948[+] using maximum random delay of 10 millisecond(s) between requests
2949
2950ftp.teen-pussy-fuck.com
2951IP address #1: 80.82.77.146
2952
2953mail.teen-pussy-fuck.com
2954IP address #1: 80.82.77.146
2955
2956pop.teen-pussy-fuck.com
2957IP address #1: 80.82.77.146
2958
2959www.teen-pussy-fuck.com
2960IP address #1: 80.82.77.146
2961
2962[+] 4 (sub)domains and 4 IP address(es) found
2963[+] completion time: 155 second(s)
2964
2965
2966Tracing to teen-pussy-fuck.com[a] via 192.168.1.254, maximum of 3 retries
2967192.168.1.254 (192.168.1.254) Got answer
2968
2969
2970WhatWeb report for http://teen-pussy-fuck.com
2971Status : 301 Moved Permanently
2972Title : 301 Moved Permanently
2973IP : 80.82.77.146
2974Country : NETHERLANDS, NL
2975
2976Summary : nginx, RedirectLocation[http://www.teen-pussy-fuck.com/], HTTPServer[nginx]
2977
2978Detected Plugins:
2979[ HTTPServer ]
2980 HTTP server header string. This plugin also attempts to
2981 identify the operating system from the server header.
2982
2983 String : nginx (from server string)
2984
2985[ RedirectLocation ]
2986 HTTP Server string location. used with http-status 301 and
2987 302
2988
2989 String : http://www.teen-pussy-fuck.com/ (from location)
2990
2991[ nginx ]
2992 Nginx (Engine-X) is a free, open-source, high-performance
2993 HTTP server and reverse proxy, as well as an IMAP/POP3
2994 proxy server.
2995
2996 Website : http://nginx.net/
2997
2998HTTP Headers:
2999 HTTP/1.1 301 Moved Permanently
3000 Server: nginx
3001 Date: Tue, 29 Aug 2017 14:19:57 GMT
3002 Content-Type: text/html; charset=iso-8859-1
3003 Content-Length: 324
3004 Connection: close
3005 Location: http://www.teen-pussy-fuck.com/
3006
3007WhatWeb report for http://www.teen-pussy-fuck.com/
3008Status : 200 OK
3009Title : Young sexy teen virgin girls pussy fuck.
3010IP : 80.82.77.146
3011Country : NETHERLANDS, NL
3012
3013Summary : HTML5, nginx, Script[text/javascript], PHP[5.4.45], X-Powered-By[PHP/5.4.45], HTTPServer[nginx]
3014
3015Detected Plugins:
3016[ HTML5 ]
3017 HTML version 5, detected by the doctype declaration
3018
3019
3020[ HTTPServer ]
3021 HTTP server header string. This plugin also attempts to
3022 identify the operating system from the server header.
3023
3024 String : nginx (from server string)
3025
3026[ PHP ]
3027 PHP is a widely-used general-purpose scripting language
3028 that is especially suited for Web development and can be
3029 embedded into HTML. This plugin identifies PHP errors,
3030 modules and versions and extracts the local file path and
3031 username if present.
3032
3033 Version : 5.4.45
3034 Google Dorks: (2)
3035 Website : http://www.php.net/
3036
3037[ Script ]
3038 This plugin detects instances of script HTML elements and
3039 returns the script language/type.
3040
3041 String : text/javascript
3042
3043[ X-Powered-By ]
3044 X-Powered-By HTTP header
3045
3046 String : PHP/5.4.45 (from x-powered-by string)
3047
3048[ nginx ]
3049 Nginx (Engine-X) is a free, open-source, high-performance
3050 HTTP server and reverse proxy, as well as an IMAP/POP3
3051 proxy server.
3052
3053 Website : http://nginx.net/
3054
3055HTTP Headers:
3056 HTTP/1.1 200 OK
3057 Server: nginx
3058 Date: Tue, 29 Aug 2017 14:19:57 GMT
3059 Content-Type: text/html; charset=UTF-8
3060 Transfer-Encoding: chunked
3061 Connection: close
3062 X-Powered-By: PHP/5.4.45
3063 Content-Encoding: gzip
3064
3065
3066
3067
3068[-] Resolving hostnames IPs...
306980.82.77.146:www.teen-pussy-fuck.com
3070
3071
3072
3073 ^ ^
3074 _ __ _ ____ _ __ _ _ ____
3075 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
3076 | V V // o // _/ | V V // 0 // 0 // _/
3077 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
3078 <
3079 ...'
3080
3081 WAFW00F - Web Application Firewall Detection Tool
3082
3083 By Sandro Gauci && Wendel G. Henrique
3084
3085Checking http://teen-pussy-fuck.com
3086Generic Detection results:
3087No WAF detected by the generic detection
3088Number of requests: 13
3089
3090
3091DNS Servers for teen-pussy-fuck.com:
3092 ns2.mygirlssex.com
3093 ns1.mygirlssex.com
3094
3095Trying zone transfer first...
3096 Testing ns2.mygirlssex.com
3097 Request timed out or transfer not allowed.
3098 Testing ns1.mygirlssex.com
3099 Request timed out or transfer not allowed.
3100
3101Unsuccessful in zone transfer (it was worth a shot)
3102Okay, trying the good old fashioned way... brute force
3103
3104Checking for wildcard DNS...
3105Nope. Good.
3106Now performing 2280 test(s)...
310780.82.77.146 ftp.teen-pussy-fuck.com
310880.82.77.146 mail.teen-pussy-fuck.com
310980.82.77.146 pop.teen-pussy-fuck.com
311080.82.77.146 www.teen-pussy-fuck.com
3111
3112
3113Checking for HTTP-Loadbalancing [Date]: 14:25:12, 14:25:12, 14:25:13, 14:25:13, 14:25:14, 14:25:14, 14:25:14, 14:25:14, 14:25:15, 14:25:15, 14:25:15, 14:25:16, 14:25:16, 14:25:16, 14:25:16, 14:25:17, 14:25:17, 14:25:17, 14:25:17, 14:25:18, 14:25:18, 14:25:18, 14:25:18, 14:25:19, 14:25:19, 14:25:19, 14:25:20, 14:25:20, 14:25:20, 14:25:20, 14:25:21, 14:25:21, 14:25:21, 14:25:21, 14:25:22, 14:25:22, 14:25:22, 14:25:22, 14:25:23, 14:25:23, 14:25:23, 14:25:24, 14:25:24, 14:25:24, 14:25:24, 14:25:25, 14:25:25, 14:25:25, 14:25:25, 14:25:26, NOT FOUND
3114
3115Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
3116
3117teen-pussy-fuck.com does NOT use Load-balancing.
3118
3119
3120
3121Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
3122
3123 ----------------------------------------------------------
3124| Scan Information |
3125 ----------------------------------------------------------
3126
3127Mode ..................... VRFY
3128Worker Processes ......... 5
3129Usernames file ........... users.txt
3130Target count ............. 1
3131Username count ........... 494
3132Target TCP port .......... 25
3133Query timeout ............ 5 secs
3134Target domain ............
3135
3136######## Scan started at Tue Aug 29 10:25:33 2017 #########
3137######## Scan completed at Tue Aug 29 10:33:48 2017 #########
31380 results.
3139
3140494 queries in 495 seconds (1.0 queries / sec)
3141
3142
3143
3144Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 10:33 EDT
3145NSE: Loaded 146 scripts for scanning.
3146NSE: Script Pre-scanning.
3147Initiating NSE at 10:33
3148Completed NSE at 10:33, 0.00s elapsed
3149Initiating NSE at 10:33
3150Completed NSE at 10:33, 0.00s elapsed
3151Failed to resolve "teen-pussy-fuck.com.txt".
3152Initiating Parallel DNS resolution of 1 host. at 10:33
3153Completed Parallel DNS resolution of 1 host. at 10:33, 0.59s elapsed
3154Initiating SYN Stealth Scan at 10:33
3155Scanning teen-pussy-fuck.com (80.82.77.146) [100 ports]
3156Discovered open port 53/tcp on 80.82.77.146
3157Discovered open port 8080/tcp on 80.82.77.146
3158Discovered open port 80/tcp on 80.82.77.146
3159Discovered open port 21/tcp on 80.82.77.146
3160Completed SYN Stealth Scan at 10:33, 3.11s elapsed (100 total ports)
3161Initiating Service scan at 10:33
3162Scanning 4 services on teen-pussy-fuck.com (80.82.77.146)
3163Completed Service scan at 10:33, 6.38s elapsed (4 services on 1 host)
3164Initiating OS detection (try #1) against teen-pussy-fuck.com (80.82.77.146)
3165adjust_timeouts2: packet supposedly had rtt of -130340 microseconds. Ignoring time.
3166adjust_timeouts2: packet supposedly had rtt of -130340 microseconds. Ignoring time.
3167Retrying OS detection (try #2) against teen-pussy-fuck.com (80.82.77.146)
3168Initiating Traceroute at 10:34
3169Completed Traceroute at 10:34, 3.12s elapsed
3170Initiating Parallel DNS resolution of 8 hosts. at 10:34
3171Completed Parallel DNS resolution of 8 hosts. at 10:34, 5.62s elapsed
3172NSE: Script scanning 80.82.77.146.
3173Initiating NSE at 10:34
3174Completed NSE at 10:34, 9.60s elapsed
3175Initiating NSE at 10:34
3176Completed NSE at 10:34, 0.00s elapsed
3177Nmap scan report for teen-pussy-fuck.com (80.82.77.146)
3178Host is up (0.12s latency).
3179Not shown: 94 filtered ports
3180PORT STATE SERVICE VERSION
318121/tcp open ftp vsftpd 2.2.2
318253/tcp open domain ISC BIND get lost
3183| dns-nsid:
3184|_ bind.version: get lost
318580/tcp open http nginx
3186| http-methods:
3187|_ Supported Methods: HEAD POST OPTIONS
3188|_http-server-header: nginx
3189|_http-title: Did not follow redirect to http://www.teen-pussy-fuck.com/
319081/tcp closed hosts2-ns
3191443/tcp closed https
31928080/tcp open http Apache httpd 2.2.15 ((CentOS))
3193| http-methods:
3194|_ Supported Methods: HEAD POST OPTIONS
3195|_http-open-proxy: Proxy might be redirecting requests
3196|_http-server-header: Apache/2.2.15 (CentOS)
3197|_http-title: Did not follow redirect to http://www.teen-pussy-fuck.com/
3198Device type: general purpose|firewall|storage-misc
3199Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (93%), WatchGuard Fireware 11.X (93%), Synology DiskStation Manager 5.X (92%), FreeBSD 6.X (86%)
3200OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3.4 cpe:/o:watchguard:fireware:11.8 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:linux:linux_kernel:4.4 cpe:/o:freebsd:freebsd:6.2
3201Aggressive OS guesses: Linux 2.6.32 (93%), Linux 2.6.39 (93%), Linux 3.4 (93%), WatchGuard Fireware 11.8 (93%), Synology DiskStation Manager 5.1 (92%), Linux 3.10 (92%), Linux 2.6.32 or 3.10 (91%), Linux 3.1 - 3.2 (91%), Linux 2.6.32 - 2.6.39 (90%), Linux 3.2 - 3.8 (87%)
3202No exact OS matches for host (test conditions non-ideal).
3203Uptime guess: 23.256 days (since Sun Aug 6 04:26:00 2017)
3204Network Distance: 12 hops
3205TCP Sequence Prediction: Difficulty=262 (Good luck!)
3206IP ID Sequence Generation: All zeros
3207Service Info: OS: Unix
3208
3209TRACEROUTE (using port 443/tcp)
3210HOP RTT ADDRESS
32111 110.21 ms 10.13.0.1
32122 ...
32133 110.26 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
32144 111.45 ms 10.95.33.10
32155 118.82 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
32166 156.17 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
32177 ...
32188 156.34 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
32199 156.32 ms 176.10.83.119
322010 ... 11
322112 121.67 ms 80.82.77.146
3222
3223NSE: Script Post-scanning.
3224Initiating NSE at 10:34
3225Completed NSE at 10:34, 0.00s elapsed
3226Initiating NSE at 10:34
3227Completed NSE at 10:34, 0.00s elapsed
3228Read data files from: /usr/bin/../share/nmap
3229OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
3230Nmap done: 1 IP address (1 host up) scanned in 38.49 seconds
3231 Raw packets sent: 319 (19.324KB) | Rcvd: 316 (150.896KB)
3232
3233
3234Error: can not open nmap file: teen-pussy-fuck.com.txt
3235
3236
3237httprint v0.301 (beta) - web server fingerprinting tool
3238(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
3239http://net-square.com/httprint/
3240httprint@net-square.com
3241
3242Finger Printing on http://teen-pussy-fuck.com:80/
3243Finger Printing Completed on http://teen-pussy-fuck.com:80/
3244--------------------------------------------------
3245Host: teen-pussy-fuck.com
3246Fingerprinting Error: Host/URL not found...
3247
3248--------------------------------------------------
3249
3250
3251
3252
3253 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
3254 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3255 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
3256 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
3257 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
3258
3259 _/ User-Agent Tester ↵
3260 _/ AKA: Purple Pimp ↵
3261 _/ ChrisJohnRiley ↵
3262 _/ blog.c22.cc ↵
3263
3264 [>] Performing initial request and confirming stability
3265 [>] Using User-Agent string Mozilla/5.0
3266
3267 [ ] URL (ENTERED): http://teen-pussy-fuck.com
3268 [!] URL (FINAL): http://www.teen-pussy-fuck.com/
3269 [!] Response Code: 301 Moved Permanently
3270 [ ] Server: nginx
3271 [ ] Date: Tue, 29 Aug 2017 14:34:38 GMT
3272 [ ] Content-Type: text/html; charset=UTF-8
3273 [ ] Transfer-Encoding: chunked
3274 [ ] Connection: close
3275 [ ] X-Powered-By: PHP/5.4.45
3276 [ ] Data (MD5): a98d0c0103ce51ca06f7b5ddcb5e9278
3277
3278 [1] Pass
3279 [2] Pass
3280 [3] Pass
3281
3282 [>] URL appears stable. Beginning test
3283
3284 [>] Using DEFAULT User-Agent Strings
3285
3286 [>] Using Crazy User-Agent Strings
3287 [>] Using Bot User-Agent Strings
3288
3289 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
3290
3291
3292 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
3293
3294
3295 [!] Data (MD5): 3014a4c5bac0480515aca214619c2458
3296
3297
3298 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
3299
3300
3301 [!] Data (MD5): 2a0eec7378a76c44ce1fa7735efa7676
3302
3303
3304 [>] User-Agent String : TrackBack/1.02
3305
3306
3307 [!] Data (MD5): 94148c7b2e8754fa1b24055862d943c2
3308
3309
3310 [>] User-Agent String : wispr
3311
3312
3313 [!] Data (MD5): 896abfc264c5b0e31664410cfe07a3f2
3314
3315
3316 [>] User-Agent String : EMPTY USER-AGENT STRING!
3317
3318
3319 [!] Data (MD5): 95983f32ca3137ae25b3b42dbc49be5e
3320
3321
3322 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
3323
3324
3325 [!] Data (MD5): 4bcfdef9f59248d92f24546ae90582b1
3326
3327
3328 [>] User-Agent String : Googlebot-Image/1.0
3329
3330
3331 [!] Data (MD5): e197d2c2bfd0f119c590e7b0d954908a
3332
3333
3334 [>] User-Agent String : Mediapartners-Google
3335
3336
3337 [!] Data (MD5): 079eb9fbe7e377cab01aaa97cd7e6cfd
3338
3339
3340 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
3341
3342
3343 [!] Data (MD5): 799a37803851529887d2235a500e2e46
3344
3345
3346 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
3347
3348
3349 [!] Data (MD5): c626d80c5b82415dbd03f5419560f94a
3350
3351
3352 [>] User-Agent String : mmcrawler
3353
3354
3355 [!] Data (MD5): a15543d7f4965502d766b24db7a39d52
3356
3357
3358 [>] Checks completed... try enabling VERBOSE mode for more detailed output
3359
3360 [>] That's all folks... Fo' Shizzle!
3361
3362
3363
3364
3365 Enter your target IP : 80.82.77.146
3366
3367 obtention site Joomla ...
3368
3369
3370
3371
3372 obtention site Wordpress ...
3373
3374https://0.r.bat.bing.com
3375https://136002338.r.bat.bing.com
3376https://1871817.r.bat.bing.com
3377https://52000348.r.bat.bing.com
3378[i] Scanning Site: http://teen-pussy-fuck.com
3379
3380
3381
3382B A S I C I N F O
3383====================
3384
3385
3386[+] Site Title: Young sexy teen virgin girls pussy fuck.
3387[+] IP address: 80.82.77.146
3388[+] Web Server: nginx
3389[+] CMS: Could Not Detect
3390[+] Cloudflare: Not Detected
3391[+] Robots File: Found
3392
3393-------------[ contents ]----------------
3394# vestacp autogenerated robots.txt
3395User-agent: *
3396Crawl-delay: 10
3397
3398-----------[end of contents]-------------
3399
3400
3401
3402W H O I S L O O K U P
3403========================
3404
3405 Domain Name: TEEN-PUSSY-FUCK.COM
3406 Registry Domain ID: 2128898121_DOMAIN_COM-VRSN
3407 Registrar WHOIS Server: whois.PublicDomainRegistry.com
3408 Registrar URL: http://www.publicdomainregistry.com
3409 Updated Date: 2017-05-29T13:30:41Z
3410 Creation Date: 2017-05-29T13:29:27Z
3411 Registry Expiry Date: 2018-05-29T13:29:27Z
3412 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
3413 Registrar IANA ID: 303
3414 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
3415 Registrar Abuse Contact Phone: +1.2013775952
3416 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3417 Name Server: NS1.MYGIRLSSEX.COM
3418 Name Server: NS2.MYGIRLSSEX.COM
3419
3420
3421G E O I P L O O K U P
3422=========================
3423
3424[i] IP Address: 80.82.77.146
3425[i] Country: SC
3426[i] State: N/A
3427[i] City: N/A
3428[i] Latitude: -4.583300
3429[i] Longitude: 55.666698
3430
3431
3432
3433
3434H T T P H E A D E R S
3435=======================
3436
3437
3438[i] HTTP/1.1 301 Moved Permanently
3439[i] Server: nginx
3440[i] Date: Tue, 29 Aug 2017 14:16:48 GMT
3441[i] Content-Type: text/html; charset=iso-8859-1
3442[i] Content-Length: 324
3443[i] Connection: close
3444[i] Location: http://www.teen-pussy-fuck.com/
3445[i] HTTP/1.1 200 OK
3446[i] Server: nginx
3447[i] Date: Tue, 29 Aug 2017 14:16:49 GMT
3448[i] Content-Type: text/html; charset=UTF-8
3449[i] Connection: close
3450[i] X-Powered-By: PHP/5.4.45
3451
3452
3453
3454
3455D N S L O O K U P
3456===================
3457
3458teen-pussy-fuck.com. 14395 IN A 80.82.77.146
3459teen-pussy-fuck.com. 14400 IN NS ns1.mygirlssex.com.
3460teen-pussy-fuck.com. 14400 IN NS ns2.mygirlssex.com.
3461teen-pussy-fuck.com. 14400 IN SOA ns1.mygirlssex.com. root.teen-pussy-fuck.com. 2017052901 7200 3600 1209600 180
3462teen-pussy-fuck.com. 14400 IN MX 10 mail.teen-pussy-fuck.com.
3463teen-pussy-fuck.com. 14400 IN TXT "v=spf1 a mx ip4:80.82.77.146 ?all"
3464
3465
3466
3467
3468S U B N E T C A L C U L A T I O N
3469====================================
3470
3471Address = 80.82.77.146
3472Network = 80.82.77.146 / 32
3473Netmask = 255.255.255.255
3474Broadcast = not needed on Point-to-Point links
3475Wildcard Mask = 0.0.0.0
3476Hosts Bits = 0
3477Max. Hosts = 1 (2^0 - 0)
3478Host Range = { 80.82.77.146 - 80.82.77.146 }
3479
3480
3481
3482N M A P P O R T S C A N
3483============================
3484
3485
3486Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 14:16 UTC
3487Nmap scan report for teen-pussy-fuck.com (80.82.77.146)
3488Host is up (0.064s latency).
3489PORT STATE SERVICE VERSION
349021/tcp open ftp vsftpd 2.2.2
349122/tcp filtered ssh
349223/tcp filtered telnet
349325/tcp open smtp Exim smtpd 4.89
349480/tcp open http nginx
3495110/tcp filtered pop3
3496143/tcp filtered imap
3497443/tcp closed https
3498445/tcp filtered microsoft-ds
34993389/tcp filtered ms-wbt-server
3500Service Info: Host: g10s34.example.com; OS: Unix
3501
3502Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
3503Nmap done: 1 IP address (1 host up) scanned in 8.47 seconds
3504
3505
3506
3507S U B - D O M A I N F I N D E R
3508==================================
3509
3510
3511[i] Total Subdomains Found : 1
3512
3513[+] Subdomain: teen-pussy-fuck.com
3514[-] IP: 80.82.77.146
3515
3516
3517
3518
3519
3520R E V E R S E I P L O O K U P
3521==================================
3522
3523
3524[i] Total Sites Found On This Server : 4
3525
3526
3527[#] asian-teen-pussy.com,1,babegirlsex.com,1,crazynudeteens.com
3528[-] CMS: Could Not Detect
3529
3530[#] teen-home-tube.com
3531[-] CMS: Could Not Detect
3532
3533[#] teen-pussy-fuck.com,1,www.girlspornvids.com,1,www.sexpornteenage.com,1,www.teenamatureporn.com,1,www.teencutiespics.com
3534[-] CMS: Could Not Detect
3535
3536[#] www.teensexvidoe.com,1,www.xxlpornoteen.com,1
3537[-] CMS: Could Not Detect
3538
3539
3540Crawling Types & Descriptions:
3541---------------------------------------------------------------------------
3542+ Target IP: 80.82.77.146
3543+ Target Hostname: 80.82.77.146
3544+ Target Port: 80
3545+ Start Time: 2017-08-29 10:32:26 (GMT-4)
3546---------------------------------------------------------------------------
3547+ Server: nginx
3548+ Server leaks inodes via ETags, header found with file /, inode: 55026466, size: 1059, mtime: Sat Apr 29 10:10:33 2017
3549+ The anti-clickjacking X-Frame-Options header is not present.
3550+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
3551+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
3552+ Allowed HTTP Methods: GET, HEAD, POST, OPTIONS, TRACE
3553+ Retrieved x-powered-by header: PHP/5.4.45
3554+ Uncommon header 'x-ob_mode' found, with contents: 0
3555+ OSVDB-3092: /phpmyadmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
3556+ OSVDB-3268: /icons/: Directory indexing found.
3557+ OSVDB-3233: /icons/README: Apache default file found.
3558+ /phpmyadmin/: phpMyAdmin directory found
3559+ 8346 requests: 0 error(s) and 11 item(s) reported on remote host
3560+ End Time: 2017-08-29 10:51:24 (GMT-4) (1138 seconds)
3561#######################################################################################################################################
3562http://www.teen-girls-suck.com/
3563 Hostname www.teen-girls-suck.com ISP Quasi Networks LTD. (AS29073)
3564Continent Africa Flag
3565SC
3566Country Seychelles Country Code SC (SYC)
3567Region Unknown Local time 29 Aug 2017 19:25 +04
3568City Unknown Latitude -4.583
3569IP Address 80.82.77.146 Longitude 55.667
3570#######################################################################################################################################
3571teen-girls-suck.com
3572
3573
3574 Domain Name: TEEN-GIRLS-SUCK.COM
3575 Registry Domain ID: 2128898113_DOMAIN_COM-VRSN
3576 Registrar WHOIS Server: whois.PublicDomainRegistry.com
3577 Registrar URL: http://www.publicdomainregistry.com
3578 Updated Date: 2017-05-29T13:30:40Z
3579 Creation Date: 2017-05-29T13:29:26Z
3580 Registry Expiry Date: 2018-05-29T13:29:26Z
3581 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
3582 Registrar IANA ID: 303
3583 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
3584 Registrar Abuse Contact Phone: +1.2013775952
3585 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3586 Name Server: NS1.MYGIRLSSEX.COM
3587 Name Server: NS2.MYGIRLSSEX.COM
3588
3589Domain Name: TEEN-GIRLS-SUCK.COM
3590Registry Domain ID: 2128898113_DOMAIN_COM-VRSN
3591Registrar WHOIS Server: whois.publicdomainregistry.com
3592Registrar URL: www.publicdomainregistry.com
3593Updated Date: 2017-07-29T02:17:27Z
3594Creation Date: 2017-05-29T13:29:26Z
3595Registrar Registration Expiration Date: 2018-05-29T13:29:26Z
3596Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
3597Registrar IANA ID: 303
3598Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
3599Registry Registrant ID: Not Available From Registry
3600Registrant Name: dmitry
3601Registrant Organization:
3602Registrant Street: ketcherskaya
3603Registrant City: moscow
3604Registrant State/Province: Moscow
3605Registrant Postal Code: 117422
3606Registrant Country: RU
3607Registrant Phone: +7.9281262378
3608Registrant Phone Ext:
3609Registrant Fax:
3610Registrant Fax Ext:
3611Registrant Email: carterserv@safe-mail.net
3612Registry Admin ID: Not Available From Registry
3613Admin Name: dmitry
3614Admin Organization:
3615Admin Street: ketcherskaya
3616Admin City: moscow
3617Admin State/Province: Moscow
3618Admin Postal Code: 117422
3619Admin Country: RU
3620Admin Phone: +7.9281262378
3621Admin Phone Ext:
3622Admin Fax:
3623Admin Fax Ext:
3624Admin Email: carterserv@safe-mail.net
3625Registry Tech ID: Not Available From Registry
3626Tech Name: dmitry
3627Tech Organization:
3628Tech Street: ketcherskaya
3629Tech City: moscow
3630Tech State/Province: Moscow
3631Tech Postal Code: 117422
3632Tech Country: RU
3633Tech Phone: +7.9281262378
3634Tech Phone Ext:
3635Tech Fax:
3636Tech Fax Ext:
3637Tech Email: carterserv@safe-mail.net
3638Name Server: ns1.mygirlssex.com
3639Name Server: ns2.mygirlssex.com
3640DNSSEC:Unsigned
3641Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
3642Registrar Abuse Contact Phone: +1.2013775952
3643; <<>> DiG 9.10.3-P4-Debian <<>> teen-girls-suck.com any
3644;; global options: +cmd
3645;; Got answer:
3646;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 63970
3647;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
3648
3649;; OPT PSEUDOSECTION:
3650; EDNS: version: 0, flags:; udp: 4096
3651;; QUESTION SECTION:
3652;teen-girls-suck.com. IN ANY
3653
3654;; ANSWER SECTION:
3655teen-girls-suck.com. 4094 IN NS ns1.mygirlssex.com.
3656teen-girls-suck.com. 4094 IN NS ns2.mygirlssex.com.
3657
3658;; Query time: 8 msec
3659;; SERVER: 192.168.1.254#53(192.168.1.254)
3660;; WHEN: Tue Aug 29 11:25:38 EDT 2017
3661;; MSG SIZE rcvd: 95
3662
3663
3664Running:
3665 traceroute -T -O info -i eth0 teen-girls-suck.com
3666traceroute to teen-girls-suck.com (80.82.77.146), 30 hops max, 60 byte packets
3667 1 gateway (192.168.1.254) 0.514 ms 0.676 ms 0.826 ms
3668 2 10.135.18.1 (10.135.18.1) 7.214 ms 7.859 ms 8.346 ms
3669 3 75.154.223.222 (75.154.223.222) 30.025 ms 29.940 ms 30.064 ms
3670 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.314 ms 30.432 ms 31.027 ms
3671 5 ae-239-3615.edge6.Amsterdam1.Level3.net (4.69.162.250) 104.314 ms 104.684 ms 105.038 ms
3672 6 * * *
3673 7 * * *
3674 8 80.82.77.146 (80.82.77.146) <syn,ack> 104.103 ms 103.615 ms 103.342 ms
3675
3676
3677Smartmatch is experimental at /usr/bin/dnsenum line 698.
3678Smartmatch is experimental at /usr/bin/dnsenum line 698.
3679dnsenum VERSION:1.2.4
3680Warning: can't load Net::Whois::IP module, whois queries disabled.
3681
3682----- teen-girls-suck.com -----
3683
3684
3685Host's addresses:
3686__________________
3687
3688teen-girls-suck.com. 14388 IN A 80.82.77.146
3689
3690
3691Name Servers:
3692______________
3693
3694ns1.mygirlssex.com. 10203 IN A 80.82.77.146
3695ns2.mygirlssex.com. 10203 IN A 80.82.77.146
3696
3697
3698Mail (MX) Servers:
3699___________________
3700
3701mail.teen-girls-suck.com. 14400 IN A 80.82.77.146
3702
3703
3704
3705 ---- Google search page: 1 ----
3706
3707
3708
3709Google Results:
3710________________
3711
3712 perhaps Google is blocking our queries.
3713 Check manually.
3714
3715
3716Brute forcing with dns.txt:
3717____________________________
3718
3719ftp.teen-girls-suck.com. 14400 IN A 80.82.77.146
3720mail.teen-girls-suck.com. 14370 IN A 80.82.77.146
3721pop.teen-girls-suck.com. 14400 IN A 80.82.77.146
3722www.teen-girls-suck.com. 4004 IN A 80.82.77.146
3723
3724
3725Performing recursion:
3726______________________
3727
3728
3729 ---- Checking subdomains NS records ----
3730
3731 Can't perform recursion no NS records.
3732
3733
3734teen-girls-suck.com class C netranges:
3735_______________________________________
3736
3737 80.82.77.0/24
3738
3739
3740Performing reverse lookup on 256 ip addresses:
3741_______________________________________________
3742
3743
37440 results out of 256 IP addresses.
3745
3746
3747teen-girls-suck.com ip blocks:
3748_______________________________
3749
3750
3751done.
3752
3753
3754dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
3755
3756[+] searching (sub)domains for teen-girls-suck.com using built-in wordlist
3757[+] using maximum random delay of 10 millisecond(s) between requests
3758
3759ftp.teen-girls-suck.com
3760IP address #1: 80.82.77.146
3761
3762mail.teen-girls-suck.com
3763IP address #1: 80.82.77.146
3764
3765pop.teen-girls-suck.com
3766IP address #1: 80.82.77.146
3767
3768www.teen-girls-suck.com
3769IP address #1: 80.82.77.146
3770
3771[+] 4 (sub)domains and 4 IP address(es) found
3772[+] completion time: 150 second(s)
3773
3774
3775Tracing to teen-girls-suck.com[a] via 192.168.1.254, maximum of 3 retries
3776192.168.1.254 (192.168.1.254) Got answer
3777
3778
3779WhatWeb report for http://teen-girls-suck.com
3780Status : 301 Moved Permanently
3781Title : 301 Moved Permanently
3782IP : 80.82.77.146
3783Country : NETHERLANDS, NL
3784
3785Summary : nginx, RedirectLocation[http://www.teen-girls-suck.com/], HTTPServer[nginx]
3786
3787Detected Plugins:
3788[ HTTPServer ]
3789 HTTP server header string. This plugin also attempts to
3790 identify the operating system from the server header.
3791
3792 String : nginx (from server string)
3793
3794[ RedirectLocation ]
3795 HTTP Server string location. used with http-status 301 and
3796 302
3797
3798 String : http://www.teen-girls-suck.com/ (from location)
3799
3800[ nginx ]
3801 Nginx (Engine-X) is a free, open-source, high-performance
3802 HTTP server and reverse proxy, as well as an IMAP/POP3
3803 proxy server.
3804
3805 Website : http://nginx.net/
3806
3807HTTP Headers:
3808 HTTP/1.1 301 Moved Permanently
3809 Server: nginx
3810 Date: Tue, 29 Aug 2017 15:31:02 GMT
3811 Content-Type: text/html; charset=iso-8859-1
3812 Content-Length: 324
3813 Connection: close
3814 Location: http://www.teen-girls-suck.com/
3815
3816WhatWeb report for http://www.teen-girls-suck.com/
3817Status : 200 OK
3818Title : Teen girls suck.
3819IP : 80.82.77.146
3820Country : NETHERLANDS, NL
3821
3822Summary : HTML5, nginx, Script[text/javascript], PHP[5.4.45], X-Powered-By[PHP/5.4.45], HTTPServer[nginx]
3823
3824Detected Plugins:
3825[ HTML5 ]
3826 HTML version 5, detected by the doctype declaration
3827
3828
3829[ HTTPServer ]
3830 HTTP server header string. This plugin also attempts to
3831 identify the operating system from the server header.
3832
3833 String : nginx (from server string)
3834
3835[ PHP ]
3836 PHP is a widely-used general-purpose scripting language
3837 that is especially suited for Web development and can be
3838 embedded into HTML. This plugin identifies PHP errors,
3839 modules and versions and extracts the local file path and
3840 username if present.
3841
3842 Version : 5.4.45
3843 Google Dorks: (2)
3844 Website : http://www.php.net/
3845
3846[ Script ]
3847 This plugin detects instances of script HTML elements and
3848 returns the script language/type.
3849
3850 String : text/javascript
3851
3852[ X-Powered-By ]
3853 X-Powered-By HTTP header
3854
3855 String : PHP/5.4.45 (from x-powered-by string)
3856
3857[ nginx ]
3858 Nginx (Engine-X) is a free, open-source, high-performance
3859 HTTP server and reverse proxy, as well as an IMAP/POP3
3860 proxy server.
3861
3862 Website : http://nginx.net/
3863
3864HTTP Headers:
3865 HTTP/1.1 200 OK
3866 Server: nginx
3867 Date: Tue, 29 Aug 2017 15:31:02 GMT
3868 Content-Type: text/html; charset=UTF-8
3869 Transfer-Encoding: chunked
3870 Connection: close
3871 X-Powered-By: PHP/5.4.45
3872 Content-Encoding: gzip
3873
3874
3875
3876 ^ ^
3877 _ __ _ ____ _ __ _ _ ____
3878 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
3879 | V V // o // _/ | V V // 0 // 0 // _/
3880 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
3881 <
3882 ...'
3883
3884 WAFW00F - Web Application Firewall Detection Tool
3885
3886 By Sandro Gauci && Wendel G. Henrique
3887
3888Checking http://teen-girls-suck.com
3889Generic Detection results:
3890No WAF detected by the generic detection
3891Number of requests: 13
3892
3893
3894DNS Servers for teen-girls-suck.com:
3895 ns2.mygirlssex.com
3896 ns1.mygirlssex.com
3897
3898Trying zone transfer first...
3899 Testing ns2.mygirlssex.com
3900 Request timed out or transfer not allowed.
3901 Testing ns1.mygirlssex.com
3902 Request timed out or transfer not allowed.
3903
3904Unsuccessful in zone transfer (it was worth a shot)
3905Okay, trying the good old fashioned way... brute force
3906
3907Checking for wildcard DNS...
3908Nope. Good.
3909Now performing 2280 test(s)...
391080.82.77.146 ftp.teen-girls-suck.com
391180.82.77.146 mail.teen-girls-suck.com
391280.82.77.146 pop.teen-girls-suck.com
391380.82.77.146 www.teen-girls-suck.com
3914
3915Subnets found (may want to probe here using nmap or unicornscan):
3916 80.82.77.0-255 : 4 hostnames found.
3917
3918Done with Fierce scan: http://ha.ckers.org/fierce/
3919Found 4 entries.
3920
3921Have a nice day.
3922
3923
3924
3925lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
3926 Written by Stefan Behte (http://ge.mine.nu)
3927 Proof-of-concept! Might give false positives.
3928
3929Checking for DNS-Loadbalancing: NOT FOUND
3930Checking for HTTP-Loadbalancing [Server]:
3931 nginx
3932 NOT FOUND
3933
3934Checking for HTTP-Loadbalancing [Date]: 15:36:35, 15:36:35, 15:36:35, 15:36:36, 15:36:36, 15:36:36, 15:36:36, 15:36:37, 15:36:37, 15:36:37, 15:36:38, 15:36:38, 15:36:38, 15:36:38, 15:36:39, 15:36:39, 15:36:39, 15:36:39, 15:36:40, 15:36:40, 15:36:40, 15:36:40, 15:36:41, 15:36:41, 15:36:41, 15:36:41, 15:36:42, 15:36:42, 15:36:42, 15:36:43, 15:36:43, 15:36:43, 15:36:43, 15:36:44, 15:36:44, 15:36:44, 15:36:44, 15:36:45, 15:36:45, 15:36:45, 15:36:45, 15:36:46, 15:36:46, 15:36:46, 15:36:46, 15:36:47, 15:36:47, 15:36:47, 15:36:48, 15:36:48, NOT FOUND
3935
3936Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
3937
3938teen-girls-suck.com does NOT use Load-balancing.
3939
3940
3941
3942Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
3943
3944 ----------------------------------------------------------
3945| Scan Information |
3946 ----------------------------------------------------------
3947
3948Mode ..................... VRFY
3949Worker Processes ......... 5
3950Usernames file ........... users.txt
3951Target count ............. 1
3952Username count ........... 494
3953Target TCP port .......... 25
3954Query timeout ............ 5 secs
3955Target domain ............
3956
3957######## Scan started at Tue Aug 29 11:36:55 2017 #########
3958######## Scan completed at Tue Aug 29 11:45:10 2017 #########
39590 results.
3960
3961494 queries in 495 seconds (1.0 queries / sec)
3962
3963
3964
3965Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 11:45 EDT
3966NSE: Loaded 146 scripts for scanning.
3967NSE: Script Pre-scanning.
3968Initiating NSE at 11:45
3969Completed NSE at 11:45, 0.00s elapsed
3970Initiating NSE at 11:45
3971Completed NSE at 11:45, 0.00s elapsed
3972Failed to resolve "teen-girls-suck.com.txt".
3973Initiating Parallel DNS resolution of 1 host. at 11:45
3974Completed Parallel DNS resolution of 1 host. at 11:45, 0.63s elapsed
3975Initiating SYN Stealth Scan at 11:45
3976Scanning teen-girls-suck.com (80.82.77.146) [100 ports]
3977Discovered open port 53/tcp on 80.82.77.146
3978Discovered open port 8080/tcp on 80.82.77.146
3979Discovered open port 80/tcp on 80.82.77.146
3980Discovered open port 21/tcp on 80.82.77.146
3981Completed SYN Stealth Scan at 11:45, 6.13s elapsed (100 total ports)
3982Initiating Service scan at 11:45
3983Scanning 4 services on teen-girls-suck.com (80.82.77.146)
3984Completed Service scan at 11:45, 6.36s elapsed (4 services on 1 host)
3985Initiating OS detection (try #1) against teen-girls-suck.com (80.82.77.146)
3986adjust_timeouts2: packet supposedly had rtt of -69580 microseconds. Ignoring time.
3987adjust_timeouts2: packet supposedly had rtt of -69580 microseconds. Ignoring time.
3988Retrying OS detection (try #2) against teen-girls-suck.com (80.82.77.146)
3989Initiating Traceroute at 11:45
3990Completed Traceroute at 11:45, 3.14s elapsed
3991Initiating Parallel DNS resolution of 9 hosts. at 11:45
3992Completed Parallel DNS resolution of 9 hosts. at 11:45, 5.51s elapsed
3993NSE: Script scanning 80.82.77.146.
3994Initiating NSE at 11:45
3995Completed NSE at 11:45, 9.84s elapsed
3996Initiating NSE at 11:45
3997Completed NSE at 11:45, 0.00s elapsed
3998Nmap scan report for teen-girls-suck.com (80.82.77.146)
3999Host is up (0.12s latency).
4000Not shown: 94 filtered ports
4001PORT STATE SERVICE VERSION
400221/tcp open ftp vsftpd 2.2.2
400353/tcp open domain ISC BIND get lost
4004| dns-nsid:
4005|_ bind.version: get lost
400680/tcp open http nginx
4007|_http-favicon: Unknown favicon MD5: D41D8CD98F00B204E9800998ECF8427E
4008| http-methods:
4009|_ Supported Methods: GET HEAD POST OPTIONS
4010|_http-server-header: nginx
4011|_http-title: Did not follow redirect to http://www.teen-girls-suck.com/
401281/tcp closed hosts2-ns
4013443/tcp closed https
40148080/tcp open http Apache httpd 2.2.15 ((CentOS))
4015| http-methods:
4016|_ Supported Methods: GET HEAD POST OPTIONS
4017|_http-open-proxy: Proxy might be redirecting requests
4018|_http-server-header: Apache/2.2.15 (CentOS)
4019|_http-title: Did not follow redirect to http://www.teen-girls-suck.com/
4020Aggressive OS guesses: Linux 2.6.32 (93%), Linux 2.6.32 or 3.10 (93%), Linux 2.6.39 (93%), Linux 3.4 (93%), Synology DiskStation Manager 5.1 (92%), WatchGuard Fireware 11.8 (92%), Linux 3.1 - 3.2 (92%), Linux 3.10 (91%), Linux 2.6.32 - 2.6.39 (90%), Linux 2.6.32 - 3.0 (89%)
4021No exact OS matches for host (test conditions non-ideal).
4022Uptime guess: 23.305 days (since Sun Aug 6 04:26:00 2017)
4023Network Distance: 12 hops
4024TCP Sequence Prediction: Difficulty=260 (Good luck!)
4025IP ID Sequence Generation: All zeros
4026Service Info: OS: Unix
4027
4028TRACEROUTE (using port 443/tcp)
4029HOP RTT ADDRESS
40301 110.23 ms 10.13.0.1
40312 110.02 ms 37.187.24.252
40323 110.32 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
40334 111.34 ms 10.95.33.10
40345 118.83 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
40356 219.97 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
40367 ...
40378 220.15 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
40389 220.12 ms 176.10.83.119
403910 ... 11
404012 121.26 ms 80.82.77.146
4041
4042NSE: Script Post-scanning.
4043Initiating NSE at 11:45
4044Completed NSE at 11:45, 0.00s elapsed
4045Initiating NSE at 11:45
4046Completed NSE at 11:45, 0.00s elapsed
4047Read data files from: /usr/bin/../share/nmap
4048OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4049Nmap done: 1 IP address (1 host up) scanned in 38.49 seconds
4050 Raw packets sent: 401 (22.106KB) | Rcvd: 62 (4.458KB)
4051
4052
4053Error: can not open nmap file: teen-girls-suck.com.txt
4054
4055
4056httprint v0.301 (beta) - web server fingerprinting tool
4057(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
4058http://net-square.com/httprint/
4059httprint@net-square.com
4060
4061Finger Printing on http://teen-girls-suck.com:80/
4062Finger Printing Completed on http://teen-girls-suck.com:80/
4063--------------------------------------------------
4064Host: teen-girls-suck.com
4065Fingerprinting Error: Host/URL not found...
4066
4067--------------------------------------------------
4068
4069
4070
4071
4072 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
4073 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4074 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
4075 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
4076 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
4077
4078 _/ User-Agent Tester ↵
4079 _/ AKA: Purple Pimp ↵
4080 _/ ChrisJohnRiley ↵
4081 _/ blog.c22.cc ↵
4082
4083 [>] Performing initial request and confirming stability
4084 [>] Using User-Agent string Mozilla/5.0
4085
4086 [ ] URL (ENTERED): http://teen-girls-suck.com
4087 [!] URL (FINAL): http://www.teen-girls-suck.com/
4088 [!] Response Code: 301 Moved Permanently
4089 [ ] Server: nginx
4090 [ ] Date: Tue, 29 Aug 2017 15:46:00 GMT
4091 [ ] Content-Type: text/html; charset=UTF-8
4092 [ ] Transfer-Encoding: chunked
4093 [ ] Connection: close
4094 [ ] X-Powered-By: PHP/5.4.45
4095 [ ] Data (MD5): 52a7c20cff25074f6c6b1b27f8bc6129
4096
4097 [1] Pass
4098 [2] Pass
4099 [3] Pass
4100
4101 [>] URL appears stable. Beginning test
4102
4103 [>] Using DEFAULT User-Agent Strings
4104
4105 [>] Using Crazy User-Agent Strings
4106 [>] Using Bot User-Agent Strings
4107
4108 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
4109
4110
4111 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
4112
4113
4114 [!] Data (MD5): 35f532b672e28ff997ae1afdf774467e
4115
4116
4117 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
4118
4119
4120 [!] Data (MD5): ed0a4140f4d281f7ea1e790aaccced9e
4121
4122
4123 [>] User-Agent String : TrackBack/1.02
4124
4125
4126 [!] Data (MD5): b9022944f0df95708fca11a418728481
4127
4128
4129 [>] User-Agent String : wispr
4130
4131
4132 [!] Data (MD5): 46860c580718f2f03bafda6041681a1c
4133
4134
4135 [>] User-Agent String : EMPTY USER-AGENT STRING!
4136
4137
4138 [!] Data (MD5): 50b6cba3cfca92b7dbd9fb12e194fb8e
4139
4140
4141 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
4142
4143
4144 [!] Data (MD5): 42f9ca35db4b3cbafdf71c2a2c178c71
4145
4146
4147 [>] User-Agent String : Googlebot-Image/1.0
4148
4149
4150 [!] Data (MD5): 5d21b885b3613e0147f8a42601634a5f
4151
4152
4153 [>] User-Agent String : Mediapartners-Google
4154
4155
4156 [!] Data (MD5): a066c1ec5919b363d77b07a478636e92
4157
4158
4159 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
4160
4161
4162 [!] Data (MD5): c30da553b5967873a98d5b1ce7e51f1e
4163
4164
4165 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
4166
4167
4168 [!] Data (MD5): 3e64cc95d843780d5e27e995650878d0
4169
4170
4171 [>] User-Agent String : mmcrawler
4172
4173
4174 [!] Data (MD5): e69c4642a62ca4600f6f74bacd213779
4175
4176
4177 [>] Checks completed... try enabling VERBOSE mode for more detailed output
4178
4179 [>] That's all folks... Fo' Shizzle!
4180
4181
4182
4183
4184 Enter your target IP : 80.82.77.146
4185
4186 obtention site Joomla ...
4187
4188
4189
4190
4191 obtention site Wordpress ...
4192
4193https://0.r.bat.bing.com
4194https://1871817.r.bat.bing.com
4195i] Scanning Site: http://teen-girls-suck.com
4196
4197
4198
4199B A S I C I N F O
4200====================
4201
4202
4203[+] Site Title: Teen girls suck.
4204[+] IP address: 80.82.77.146
4205[+] Web Server: nginx
4206[+] CMS: Could Not Detect
4207[+] Cloudflare: Not Detected
4208[+] Robots File: Found
4209
4210-------------[ contents ]----------------
4211# vestacp autogenerated robots.txt
4212User-agent: *
4213Crawl-delay: 10
4214
4215-----------[end of contents]-------------
4216
4217
4218
4219W H O I S L O O K U P
4220========================
4221
4222 Domain Name: TEEN-GIRLS-SUCK.COM
4223 Registry Domain ID: 2128898113_DOMAIN_COM-VRSN
4224 Registrar WHOIS Server: whois.PublicDomainRegistry.com
4225 Registrar URL: http://www.publicdomainregistry.com
4226 Updated Date: 2017-05-29T13:30:40Z
4227 Creation Date: 2017-05-29T13:29:26Z
4228 Registry Expiry Date: 2018-05-29T13:29:26Z
4229 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
4230 Registrar IANA ID: 303
4231 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
4232 Registrar Abuse Contact Phone: +1.2013775952
4233 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4234 Name Server: NS1.MYGIRLSSEX.COM
4235 Name Server: NS2.MYGIRLSSEX.COM
4236 DNSSEC: unsigned
4237
4238
4239G E O I P L O O K U P
4240=========================
4241
4242[i] IP Address: 80.82.77.146
4243[i] Country: SC
4244[i] State: N/A
4245[i] City: N/A
4246[i] Latitude: -4.583300
4247[i] Longitude: 55.666698
4248
4249
4250
4251
4252H T T P H E A D E R S
4253=======================
4254
4255
4256[i] HTTP/1.1 301 Moved Permanently
4257[i] Server: nginx
4258[i] Date: Tue, 29 Aug 2017 15:28:31 GMT
4259[i] Content-Type: text/html; charset=iso-8859-1
4260[i] Content-Length: 324
4261[i] Connection: close
4262[i] Location: http://www.teen-girls-suck.com/
4263[i] HTTP/1.1 200 OK
4264[i] Server: nginx
4265[i] Date: Tue, 29 Aug 2017 15:28:31 GMT
4266[i] Content-Type: text/html; charset=UTF-8
4267[i] Connection: close
4268[i] X-Powered-By: PHP/5.4.45
4269
4270
4271
4272
4273D N S L O O K U P
4274===================
4275
4276teen-girls-suck.com. 14395 IN A 80.82.77.146
4277teen-girls-suck.com. 14400 IN NS ns2.mygirlssex.com.
4278teen-girls-suck.com. 14400 IN NS ns1.mygirlssex.com.
4279teen-girls-suck.com. 14400 IN SOA ns1.mygirlssex.com. root.teen-girls-suck.com. 2017052901 7200 3600 1209600 180
4280teen-girls-suck.com. 14400 IN MX 10 mail.teen-girls-suck.com.
4281teen-girls-suck.com. 14400 IN TXT "v=spf1 a mx ip4:80.82.77.146 ?all"
4282
4283
4284
4285
4286S U B N E T C A L C U L A T I O N
4287====================================
4288
4289Address = 80.82.77.146
4290Network = 80.82.77.146 / 32
4291Netmask = 255.255.255.255
4292Broadcast = not needed on Point-to-Point links
4293Wildcard Mask = 0.0.0.0
4294Hosts Bits = 0
4295Max. Hosts = 1 (2^0 - 0)
4296Host Range = { 80.82.77.146 - 80.82.77.146 }
4297
4298
4299
4300N M A P P O R T S C A N
4301============================
4302
4303
4304Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 15:28 UTC
4305Nmap scan report for teen-girls-suck.com (80.82.77.146)
4306Host is up (0.082s latency).
4307PORT STATE SERVICE VERSION
430821/tcp open ftp vsftpd 2.2.2
430922/tcp filtered ssh
431023/tcp filtered telnet
431125/tcp open smtp Exim smtpd 4.89
431280/tcp open http nginx
4313110/tcp filtered pop3
4314143/tcp filtered imap
4315443/tcp closed https
4316445/tcp filtered microsoft-ds
43173389/tcp filtered ms-wbt-server
4318
4319
4320
4321S U B - D O M A I N F I N D E R
4322==================================
4323
4324
4325[i] Total Subdomains Found : 1
4326
4327[+] Subdomain: teen-girls-suck.com
4328[-] IP: 80.82.77.146
4329
4330
4331
4332
4333
4334R E V E R S E I P L O O K U P
4335==================================
4336
4337
4338[i] Total Sites Found On This Server : 5
4339
4340
4341[#] asian-teen-pussy.com,1,babegirlsex.com,1,crazynudeteens.com
4342[-] CMS: Could Not Detect
4343
4344[#] teen-girls-suck.com
4345[-] CMS: Could Not Detect
4346
4347[#] teen-home-tube.com
4348[-] CMS: Could Not Detect
4349
4350[#] teen-pussy-fuck.com,1,www.girlspornvids.com,1,www.sexpornteenage.com,1,www.teenamatureporn.com,1,www.teencutiespics.com
4351[-] CMS: Could Not Detect
4352
4353[#] www.teensexvidoe.com,1,www.xxlpornoteen.com,1
4354[-] CMS: Could Not Detect
4355
4356#######################################################################################################################################
4357Hostname www.thumbedgalleries.com ISP Serverius Holding B.V. (AS50673)
4358Continent Europe Flag
4359NL
4360Country Netherlands Country Code NL (NLD)
4361Region Unknown Local time 29 Aug 2017 19:29 CEST
4362City Unknown Latitude 52.382
4363IP Address 5.45.79.40 Longitude 4.899
4364#######################################################################################################################################
4365thumbedgalleries.com
4366
4367
4368 Domain Name: THUMBEDGALLERIES.COM
4369 Registry Domain ID: 1650054018_DOMAIN_COM-VRSN
4370 Registrar WHOIS Server: whois.PublicDomainRegistry.com
4371 Registrar URL: http://www.publicdomainregistry.com
4372 Updated Date: 2016-04-05T10:13:47Z
4373 Creation Date: 2011-04-09T15:24:36Z
4374 Registry Expiry Date: 2020-04-09T15:24:36Z
4375 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
4376 Registrar IANA ID: 303
4377 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
4378 Registrar Abuse Contact Phone: +1.2013775952
4379 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4380 Name Server: NS1.CJEMPIRE.COM
4381 Name Server: NS2.CJEMPIRE.COM
4382 DNSSEC: unsigned
4383
4384Domain Name: THUMBEDGALLERIES.COM
4385Registry Domain ID: 1650054018_DOMAIN_COM-VRSN
4386Registrar WHOIS Server: whois.publicdomainregistry.com
4387Registrar URL: www.publicdomainregistry.com
4388Updated Date: 2016-07-13T10:44:04Z
4389Creation Date: 2011-04-09T15:24:36Z
4390Registrar Registration Expiration Date: 2020-04-09T15:24:36Z
4391Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
4392Registrar IANA ID: 303
4393Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4394Registry Registrant ID: Not Available From Registry
4395Registrant Name: Dmitry Ivanov
4396Registrant Organization: Dmitry Ivanov
4397Registrant Street: Valnu street 34-15
4398Registrant City: Riga
4399Registrant State/Province:
4400Registrant Postal Code: LV-1050
4401Registrant Country: LV
4402Registrant Phone: +371.7965412
4403Registrant Phone Ext:
4404Registrant Fax:
4405Registrant Fax Ext:
4406Registrant Email: webmaster@relif.com
4407Registry Admin ID: Not Available From Registry
4408Admin Name: Dmitry Ivanov
4409Admin Organization: Dmitry Ivanov
4410Admin Street: Valnu street 34-15
4411Admin City: Riga
4412Admin State/Province:
4413Admin Postal Code: LV-1050
4414Admin Country: LV
4415Admin Phone: +371.7965412
4416Admin Phone Ext:
4417Admin Fax:
4418Admin Fax Ext:
4419Admin Email: webmaster@relif.com
4420Registry Tech ID: Not Available From Registry
4421Tech Name: Dmitry Ivanov
4422Tech Organization: Dmitry Ivanov
4423Tech Street: Valnu street 34-15
4424Tech City: Riga
4425Tech State/Province:
4426Tech Postal Code: LV-1050
4427Tech Country: LV
4428Tech Phone: +371.7965412
4429Tech Phone Ext:
4430Tech Fax:
4431Tech Fax Ext:
4432Tech Email: webmaster@relif.com
4433Name Server: ns1.cjempire.com
4434Name Server: ns2.cjempire.com
4435DNSSEC:Unsigned
4436Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
4437Registrar Abuse Contact Phone: +1.2013775952
4438
4439
4440
4441
4442; <<>> DiG 9.10.3-P4-Debian <<>> thumbedgalleries.com any
4443;; global options: +cmd
4444;; Got answer:
4445;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 50899
4446;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
4447
4448;; OPT PSEUDOSECTION:
4449; EDNS: version: 0, flags:; udp: 4096
4450;; QUESTION SECTION:
4451;thumbedgalleries.com. IN ANY
4452
4453;; ANSWER SECTION:
4454thumbedgalleries.com. 3247 IN NS ns1.server.domain.com.
4455thumbedgalleries.com. 3247 IN NS ns2.server.domain.com.
4456
4457;; Query time: 8 msec
4458;; SERVER: 192.168.1.254#53(192.168.1.254)
4459;; WHEN: Tue Aug 29 13:06:18 EDT 2017
4460;; MSG SIZE rcvd: 99
4461
4462
4463
4464;; Connection to 192.168.1.254#53(192.168.1.254) for thumbedgalleries.com failed: connection refused.
4465Host thumbedgalleries.com not found: 9(NOTAUTH)
4466; Transfer failed.
4467
4468
4469Please type the name of your network interface Example: eth0
4470eth0
4471
4472Running:
4473 traceroute -T -O info -i eth0 thumbedgalleries.com
4474traceroute to thumbedgalleries.com (5.45.79.40), 30 hops max, 60 byte packets
4475 1 gateway (192.168.1.254) 0.533 ms 0.694 ms 0.849 ms
4476 2 10.135.18.1 (10.135.18.1) 7.355 ms 17.536 ms 19.187 ms
4477 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 30.070 ms 30.069 ms 30.100 ms
4478 4 ae4-1.nyk10.core-backbone.com (206.130.10.42) 30.582 ms 30.602 ms 30.622 ms
4479 5 ae3-2072.ams10.core-backbone.com (80.255.15.165) 106.819 ms 106.886 ms 106.937 ms
4480 6 core-backbone.serverius.nl (81.95.2.222) 115.632 ms core-backbone.serverius.nl (81.95.2.106) 110.130 ms 106.525 ms
4481 7 178.21.17.23 (178.21.17.23) 111.303 ms 111.418 ms 178.21.17.21 (178.21.17.21) 106.606 ms
4482 8 5.45.79.40 (5.45.79.40) <syn,ack> 106.330 ms 108.389 ms 105.079 ms
4483
4484
4485Smartmatch is experimental at /usr/bin/dnsenum line 698.
4486Smartmatch is experimental at /usr/bin/dnsenum line 698.
4487dnsenum VERSION:1.2.4
4488Warning: can't load Net::Whois::IP module, whois queries disabled.
4489
4490----- thumbedgalleries.com -----
4491
4492
4493Host's addresses:
4494__________________
4495
4496thumbedgalleries.com. 3587 IN A 5.45.79.40
4497
4498
4499Name Servers:
4500______________
4501
4502ns2.server.domain.com. 574 IN A 66.96.162.92
4503ns1.server.domain.com. 574 IN A 66.96.162.92
4504
4505
4506Mail (MX) Servers:
4507___________________
4508
4509mail.thumbedgalleries.com. 3600 IN A 5.45.79.40
4510mail.thumbedgalleries.com. 3600 IN A 5.45.79.40
4511
4512
4513
4514
4515www.thumbedgalleries.com. 3176 IN A 5.45.79.40
4516
4517
4518Brute forcing with dns.txt:
4519____________________________
4520
4521ftp.thumbedgalleries.com. 3600 IN A 5.45.79.40
4522mail.thumbedgalleries.com. 3600 IN A 5.45.79.40
4523pop.thumbedgalleries.com. 3600 IN A 5.45.79.40
4524smtp.thumbedgalleries.com. 3600 IN A 5.45.79.40
4525
4526
4527Performing recursion:
4528______________________
4529
4530
4531 ---- Checking subdomains NS records ----
4532
4533 Can't perform recursion no NS records.
4534
4535
4536thumbedgalleries.com class C netranges:
4537________________________________________
4538
4539 5.45.79.0/24
4540
4541
4542Performing reverse lookup on 256 ip addresses:
4543_______________________________________________
4544[i] Scanning Site: http://thumbedgalleries.com
4545
4546
4547
4548B A S I C I N F O
4549====================
4550
4551
4552[+] Site Title: Thumbed Mature Galleries
4553[+] IP address: 5.45.79.40
4554[+] Web Server: Apache/2.2.15 (CentOS)
4555[+] CMS: Could Not Detect
4556[+] Cloudflare: Not Detected
4557[+] Robots File: Could NOT Find robots.txt!
4558
4559
4560
4561
4562W H O I S L O O K U P
4563========================
4564
4565 Domain Name: THUMBEDGALLERIES.COM
4566 Registry Domain ID: 1650054018_DOMAIN_COM-VRSN
4567 Registrar WHOIS Server: whois.PublicDomainRegistry.com
4568 Registrar URL: http://www.publicdomainregistry.com
4569 Updated Date: 2016-04-05T10:13:47Z
4570 Creation Date: 2011-04-09T15:24:36Z
4571 Registry Expiry Date: 2020-04-09T15:24:36Z
4572 Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
4573 Registrar IANA ID: 303
4574 Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
4575 Registrar Abuse Contact Phone: +1.2013775952
4576 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4577 Name Server: NS1.CJEMPIRE.COM
4578 Name Server: NS2.CJEMPIRE.COM
4579 DNSSEC: unsigned
4580 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
4581>>> Last update of whois database: 2017-08-29T17:08:58Z <<<
4582
4583For more information on Whois status codes, please visit https://icann.org/epp
4584
4585
4586
4587The Registry database contains ONLY .COM, .NET, .EDU domains and
4588Registrars.
4589
4590
4591
4592
4593G E O I P L O O K U P
4594=========================
4595
4596[i] IP Address: 5.45.79.40
4597[i] Country: NL
4598[i] State: N/A
4599[i] City: N/A
4600[i] Latitude: 52.382401
4601[i] Longitude: 4.899500
4602
4603
4604
4605
4606H T T P H E A D E R S
4607=======================
4608
4609
4610[i] HTTP/1.1 200 OK
4611[i] Date: Tue, 29 Aug 2017 19:10:41 GMT
4612[i] Server: Apache/2.2.15 (CentOS)
4613[i] X-Powered-By: PHP/5.3.3
4614[i] Connection: close
4615[i] Content-Type: text/html; charset=UTF-8
4616
4617
4618
4619
4620D N S L O O K U P
4621===================
4622
4623thumbedgalleries.com. 3600 IN A 5.45.79.40
4624thumbedgalleries.com. 3600 IN NS ns1.server.domain.com.
4625thumbedgalleries.com. 3600 IN NS ns2.server.domain.com.
4626thumbedgalleries.com. 3600 IN SOA server.domain.com. root.server.domain.com. 2014022500 10800 3600 604800 86400
4627thumbedgalleries.com. 3600 IN MX 20 mail.thumbedgalleries.com.
4628thumbedgalleries.com. 3600 IN MX 10 mail.thumbedgalleries.com.
4629thumbedgalleries.com. 3600 IN TXT "v=spf1 ip4:5.45.79.40 a mx ~all"
4630
4631
4632
4633
4634S U B N E T C A L C U L A T I O N
4635====================================
4636
4637Address = 5.45.79.40
4638Network = 5.45.79.40 / 32
4639Netmask = 255.255.255.255
4640Broadcast = not needed on Point-to-Point links
4641Wildcard Mask = 0.0.0.0
4642Hosts Bits = 0
4643Max. Hosts = 1 (2^0 - 0)
4644Host Range = { 5.45.79.40 - 5.45.79.40 }
4645
4646
4647
4648N M A P P O R T S C A N
4649============================
4650
4651
4652Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 17:09 UTC
4653Nmap scan report for thumbedgalleries.com (5.45.79.40)
4654Host is up (0.090s latency).
4655PORT STATE SERVICE VERSION
465621/tcp open ftp ProFTPD or KnFTPD
465722/tcp open ssh OpenSSH 5.3 (protocol 2.0)
465823/tcp closed telnet
465925/tcp open smtp Sendmail 8.14.4/8.14.4
466080/tcp open http Apache httpd 2.2.15 ((CentOS))
4661110/tcp open pop3 Dovecot pop3d
4662143/tcp open imap Dovecot imapd
4663443/tcp open ssl/http Apache httpd 2.2.15
4664445/tcp closed microsoft-ds
46653389/tcp closed ms-wbt-server
4666Service Info: Hosts: server.domain.com, www.example.com; OS: Unix
4667
4668Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
4669Nmap done: 1 IP address (1 host up) scanned in 13.76 seconds
4670
4671
4672
4673S U B - D O M A I N F I N D E R
4674==================================
4675
4676
4677[i] Total Subdomains Found : 3
4678
4679[+] Subdomain: thumbedgalleries.com
4680[-] IP: 5.45.79.40
4681
4682[+] Subdomain: mail.thumbedgalleries.com
4683[-] IP: 5.45.79.40
4684
4685[+] Subdomain: www.thumbedgalleries.com
4686[-] IP: 5.45.79.40
4687
4688
4689
4690
4691
4692R E V E R S E I P L O O K U P
4693==================================
4694
4695
4696[i] Total Sites Found On This Server : 6
4697
4698
4699[#] cleangalleries.com
4700[-] CMS: Could Not Detect
4701
4702[#] gyno.categorizedporn.com,1,incest.categorizedporn.com,1,midget.amoralpeople.com
4703[-] CMS: Could Not Detect
4704
4705[#] shitting.amoralpeople.com,1,thumbedgalleries.com
4706[-] CMS: Could Not Detect
4707
4708[#] www.anygalleries.com
4709[-] CMS: Could Not Detect
4710
4711[#] www.cleangalleries.com
4712[-] CMS: Could Not Detect
4713
4714[#] www.thumbedgalleries.com,
4715[-] CMS: Could Not Detect
4716
4717
4718
4719Crawling Types & Descriptions:
4720--------------------------------------------------------------------------------------------------------------------------------------
4721+ Target IP: 5.45.79.40
4722+ Target Hostname: 5.45.79.40
4723+ Target Port: 80
4724+ Start Time: 2017-08-29 13:10:05 (GMT-4)
4725--------------------------------------------------------------------------------------------------------------------------------------
4726+ Server: Apache/2.2.15 (CentOS)
4727+ Retrieved x-powered-by header: PHP/5.3.3
4728+ The anti-clickjacking X-Frame-Options header is not present.
4729+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
4730+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
4731+ Cookie iJijkdaMnerys created without the httponly flag
4732+ Multiple index files found: /index.html, /index.php
4733+ Apache/2.2.15 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
4734+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
4735+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST
4736+ /IlohaMail/blank.html: IlohaMail 0.8.10 contains a XSS vulnerability. Previous versions contain other non-descript vulnerabilities.
4737+ /index.php?option=search&searchword=<script>alert(document.cookie);</script>: Mambo Site Server 4.0 build 10 is vulnerable to Cross Site Scripting (XSS). http://www.cert.org/advisories/CA-2000-02.html.
4738+ OSVDB-2820: /index.php?dir=<script>alert('Vulnerable')</script>: Auto Directory Index 1.2.3 and prior are vulnerable to XSS attacks.
4739+ OSVDB-50552: /index.php?file=Liens&op=\"><script>alert('Vulnerable');</script>: Nuked-klan 1.3b is vulnerable to Cross Site Scripting (XSS). http://www.cert.org/advisories/CA-2000-02.html.
4740+ /index.php?action=storenew&username=<script>alert('Vulnerable')</script>: SunShop is vulnerable to Cross Site Scripting (XSS) in the signup page. CA-200-02.
4741+ OSVDB-50553: /index.php/content/search/?SectionID=3&SearchText=<script>alert(document.cookie)</script>: eZ publish v3 and prior allow Cross Site Scripting (XSS). http://www.cert.org/advisories/CA-2000-02.html.
4742+ OSVDB-50553: /index.php/content/advancedsearch/?SearchText=<script>alert(document.cookie)</script>&PhraseSearchText=<script>alert(document.cookie)</script>&SearchContentClassID=-1&SearchSectionID=-1&SearchDate=-1&SearchButton=Search: eZ publish v3 and prior allow Cross Site Scripting (XSS). http://www.cert.org/advisories/CA-2000-02.html.
4743+ OSVDB-38019: /?mod=<script>alert(document.cookie)</script>&op=browse: Sage 1.0b3 is vulnerable to Cross Site Scripting (XSS). http://www.cert.org/advisories/CA-2000-02.html.
4744+ /cfide/Administrator/startstop.html: Can start/stop the server
4745+ OSVDB-613: /SiteScope/htdocs/SiteScope.html: The SiteScope install may allow remote users to get sensitive information about the hosts being monitored.
4746+ OSVDB-113: /ncl_items.html: This may allow attackers to reconfigure your Tektronix printer.
4747+ OSVDB-25497: /index.php?rep=<script>alert(document.cookie)</script>: GPhotos index.php rep Variable XSS.
4748+ OSVDB-376: /jk-manager/contextAdmin/contextAdmin.html: Tomcat may be configured to let attackers read arbitrary files. Restrict access to /admin.
4749+ OSVDB-376: /jk-status/contextAdmin/contextAdmin.html: Tomcat may be configured to let attackers read arbitrary files. Restrict access to /admin.
4750+ OSVDB-376: /admin/contextAdmin/contextAdmin.html: Tomcat may be configured to let attackers read arbitrary files. Restrict access to /admin.
4751+ OSVDB-376: /host-manager/contextAdmin/contextAdmin.html: Tomcat may be configured to let attackers read arbitrary files. Restrict access to /admin.
4752+ OSVDB-12606: /index.php?err=3&email=\"><script>alert(document.cookie)</script>: MySQL Eventum is vulnerable to XSS in the email field.
4753+ OSVDB-2790: /index.php?vo=\"><script>alert(document.cookie);</script>: Ralusp Sympoll 1.5 is vulnerable to Cross Site Scripting (XSS). http://www.cert.org/advisories/CA-2000-02.html.
4754+ OSVDB-3092: /admin.html: This might be interesting...
4755+ OSVDB-3092: /easylog/easylog.html: This might be interesting...
4756+ OSVDB-3092: /log.html: This might be interesting...
4757+ OSVDB-3092: /logfile.html: This might be interesting...
4758+ OSVDB-3092: /logger.html: This might be interesting...
4759+ OSVDB-3092: /stats.html: This might be interesting...
4760+ OSVDB-3092: /test.html: This might be interesting...
4761+ OSVDB-3092: /wwwstats.html: This might be interesting...
4762+ OSVDB-3092: /manager/: May be a web server or site manager.
4763+ OSVDB-3093: /mail/include.html: This might be interesting... has been seen in web logs from an unknown scanner.
4764+ OSVDB-3093: /mail/settings.html: This might be interesting... has been seen in web logs from an unknown scanner.
4765+ OSVDB-3093: /security/web_access.html: This might be interesting... has been seen in web logs from an unknown scanner.
4766+ Cookie SQMSESSID created without the httponly flag
4767+ OSVDB-3093: /webmail/src/read_body.php: SquirrelMail found
4768+ OSVDB-3233: /tomcat-docs/index.html: Default Apache Tomcat documentation found.
4769+ OSVDB-3233: /help/home.html: Default Netscape manual found. All default pages should be removed.
4770+ OSVDB-3268: /icons/: Directory indexing found.
4771+ OSVDB-3396: /mlog.html: Remote file read vulnerability 1999-0068
4772+ OSVDB-3396: /php/mlog.html: Remote file read vulnerability 1999-0346
4773+ OSVDB-3501: /_private/form_results.html: This file may contain information submitted by other web users via forms. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1052.
4774+ OSVDB-4908: /securelogin/1,2345,A,00.html: Vignette Story Server v4.1, 6, may disclose sensitive information via a buffer overflow.
4775+ OSVDB-5523: /MWS/HandleSearch.html?searchTarget=test&B1=Submit: MyWebServer 1.0.2 may be vulnerable to a buffer overflow (untested). Upgrade to a later version if 990b of searched data crashes the server.
4776+ OSVDB-3233: /WebCacheDemo.html: Oracle WebCache Demo
4777+ OSVDB-3233: /OA_HTML/webtools/doc/index.html: Cabo DHTML Components Help Page
4778+ OSVDB-3233: /aplogon.html: Oracle Applications Portal Page
4779+ OSVDB-3233: /appdet.html: Oracle Applications Portal Pages
4780+ Server leaks inodes via ETags, header found with file /icons/README, inode: 20337632, size: 5108, mtime: Tue Aug 28 06:48:10 2007
4781+ OSVDB-3233: /icons/README: Apache default file found.
4782+ /admin/account.html: Admin login page/section found.
4783+ /admin/controlpanel.html: Admin login page/section found.
4784+ /admin/cp.html: Admin login page/section found.
4785+ /admin/index.html: Admin login page/section found.
4786+ /admin/login.html: Admin login page/section found.
4787+ /admin1.html: Admin login page/section found.
4788+ /admin2.html: Admin login page/section found.
4789+ /admincontrol.html: Admin login page/section found.
4790+ /administr8.html: Admin login page/section found.
4791+ /administration.html: Admin login page/section found.
4792+ /administrator.html: Admin login page/section found.
4793+ /administrator/account.html: Admin login page/section found.
4794+ /administrator/index.html: Admin login page/section found.
4795+ /administrator/login.html: Admin login page/section found.
4796+ /adminpanel.html: Admin login page/section found.
4797+ /admins.html: Admin login page/section found.
4798+ /controlpanel.html: Admin login page/section found.
4799+ /cp.html: Admin login page/section found.
4800+ /fileadmin.html: Admin login page/section found.
4801+ /login.html: Admin login page/section found.
4802+ /moderator.html: Admin login page/section found.
4803+ /moderator/admin.html: Admin login page/section found.
4804+ /moderator/login.html: Admin login page/section found.
4805+ /myadmin/: Admin login page/section found.
4806+ /Server.html: Admin login page/section found.
4807+ /sysadmin.html: Admin login page/section found.
4808+ /ur-admin.html: Admin login page/section found.
4809+ /webadmin.html: Admin login page/section found.
4810+ /yonetici.html: Admin login page/section found.
4811+ /yonetim.html: Admin login page/section found.
4812+ /webmail/src/configtest.php: Squirrelmail configuration test may reveal version and system info.
4813+ OSVDB-3092: /3rdparty/phpMyAdmin/Documentation.html: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
4814+ 8345 requests: 0 error(s) and 87 item(s) reported on remote host
4815+ End Time: 2017-08-29 13:52:44 (GMT-4) (2559 seconds)
4816---------------------------------------------------------------------------
4817#######################################################################################################################################
4818http://youngteensonly.com/?fref=gc
4819Hostname youngteensonly.com ISP QuadraNet, Inc (AS8100)
4820Continent North America Flag
4821US
4822Country United States Country Code US (USA)
4823Region CA Local time 29 Aug 2017 12:32 PDT
4824Metropolis* Los Angeles Postal Code 90014
4825City Los Angeles Latitude 34.049
4826IP Address 96.44.128.242 Longitude -118.264
4827#######################################################################################################################################
4828youngteensonly.com
4829
4830
4831 Domain Name: YOUNGTEENSONLY.COM
4832 Registry Domain ID: 1263475332_DOMAIN_COM-VRSN
4833 Registrar WHOIS Server: whois.godaddy.com
4834 Registrar URL: http://www.godaddy.com
4835 Updated Date: 2016-11-01T05:03:08Z
4836 Creation Date: 2007-10-08T18:37:05Z
4837 Registry Expiry Date: 2017-10-08T18:37:05Z
4838 Registrar: GoDaddy.com, LLC
4839 Registrar IANA ID: 146
4840 Registrar Abuse Contact Email: abuse@godaddy.com
4841 Registrar Abuse Contact Phone: 480-624-2505
4842 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
4843 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
4844 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
4845 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
4846 Name Server: NS1.GOOGLEJOKES.ORG
4847 Name Server: NS2.GOOGLEJOKES.ORG
4848
4849Domain Name: YOUNGTEENSONLY.COM
4850Registrar URL: http://www.godaddy.com
4851Registrant Name: Matias meyer
4852Registrant Organization: mati web
4853Name Server: NS1.GOOGLEJOKES.ORG
4854Name Server: NS2.GOOGLEJOKES.ORG
4855DNSSEC: unsigned
4856
4857;; ANSWER SECTION:
4858youngteensonly.com. 14244 IN A 96.44.128.242
4859youngteensonly.com. 14244 IN NS NS2.googlejokes.org.
4860youngteensonly.com. 14244 IN NS NS1.googlejokes.org.
4861
4862;; Query time: 8 msec
4863;; SERVER: 192.168.1.254#53(192.168.1.254)
4864;; WHEN: Tue Aug 29 14:48:14 EDT 2017
4865;;
4866
4867Running:
4868 traceroute -T -O info -i eth0 youngteensonly.com
4869traceroute to youngteensonly.com (96.44.128.242), 30 hops max, 60 byte packets
4870 1 gateway (192.168.1.254) 0.521 ms 0.707 ms 0.871 ms
4871 2 10.135.18.1 (10.135.18.1) 8.043 ms 8.467 ms 8.630 ms
4872 3 CHCNIL23BR01.bb.telus.com (154.11.11.121) 32.043 ms 32.690 ms 32.734 ms
4873 4 VANCBC01GR01.bb.telus.com (154.11.10.25) 33.526 ms 33.814 ms 34.042 ms
4874 5 TenGE0-0-0-4.br04.lax05.pccwbtn.net (63.223.43.10) 100.121 ms TenGE0-0-0-0.br04.lax05.pccwbtn.net (63.223.43.2) 97.100 ms TenGE0-0-0-4.br04.lax05.pccwbtn.net (63.223.43.10) 100.327 ms
4875 6 TenGigE0-1-0-0-371.br04.lax05.pccwbtn.net (63.218.212.170) 86.417 ms 83.989 ms 84.214 ms
4876 7 colo-lax9.as8100.net (96.44.180.2) 90.967 ms 91.040 ms 90.841 ms
4877 8 96.44.128.242.static.quadranet.com (96.44.128.242) <syn,ack> 89.127 ms 84.842 ms 84.600 ms
4878
4879
4880Smartmatch is experimental at /usr/bin/dnsenum line 698.
4881Smartmatch is experimental at /usr/bin/dnsenum line 698.
4882dnsenum VERSION:1.2.4
4883Warning: can't load Net::Whois::IP module, whois queries disabled.
4884
4885----- youngteensonly.com -----
4886
4887
4888Host's addresses:
4889__________________
4890
4891youngteensonly.com. 14227 IN A 96.44.128.242
4892
4893
4894Name Servers:
4895______________
4896
4897NS1.googlejokes.org. 14227 IN A 96.44.128.242
4898NS2.googlejokes.org. 14227 IN A 96.44.128.243
4899
4900
4901Mail (MX) Servers:
4902___________________
4903
4904mail.youngteensonly.com. 14400 IN A 96.44.128.242
4905
4906
4907
4908Brute forcing with dns.txt:
4909____________________________
4910
4911ftp.youngteensonly.com. 14400 IN A 96.44.128.242
4912localhost.youngteensonly.com. 14400 IN A 127.0.0.1
4913mail.youngteensonly.com. 14382 IN A 96.44.128.242
4914pop.youngteensonly.com. 14400 IN A 96.44.128.242
4915smtp.youngteensonly.com. 14400 IN A 96.44.128.242
4916www.youngteensonly.com. 14400 IN A 96.44.128.242
4917
4918
4919youngteensonly.com class C netranges:
4920______________________________________
4921
4922 96.44.128.0/24
4923
4924
4925Performing reverse lookup on 256 ip addresses:
4926_______________________________________________
4927
4928
49290 results out of 256 IP addresses.
4930
4931
4932youngteensonly.com ip blocks:
4933______________________________
4934
4935
4936done.
4937
4938
4939dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
4940
4941[+] searching (sub)domains for youngteensonly.com using built-in wordlist
4942[+] using maximum random delay of 10 millisecond(s) between requests
4943
4944ftp.youngteensonly.com
4945IP address #1: 96.44.128.242
4946
4947localhost.youngteensonly.com
4948IP address #1: 127.0.0.1
4949[+] warning: domain might be vulnerable to "same site" scripting (http://snipurl.com/etbcv)
4950
4951mail.youngteensonly.com
4952IP address #1: 96.44.128.242
4953
4954pop.youngteensonly.com
4955IP address #1: 96.44.128.242
4956
4957smtp.youngteensonly.com
4958IP address #1: 96.44.128.242
4959
4960www.youngteensonly.com
4961IP address #1: 96.44.128.242
4962
4963[+] 6 (sub)domains and 6 IP address(es) found
4964[+] completion time: 136 second(s)
4965
4966
4967Tracing to youngteensonly.com[a] via 192.168.1.254, maximum of 3 retries
4968192.168.1.254 (192.168.1.254) Got answer
4969
4970
4971WhatWeb report for http://youngteensonly.com
4972Status : 200 OK
4973Title : Welcome to Young Teens Only +18y
4974IP : 96.44.128.242
4975Country : UNITED STATES, US
4976
4977Summary : ActiveX[D27CDB6E-AE6D-11cf-96B8-444553540000], Adobe-Flash, Object[http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,24,0][clsid:D27CDB6E-AE6D-11cf-96B8-444553540000], Script[text/javascript], PHP[5.3.3], X-Powered-By[PHP/5.3.3], HTTPServer[CentOS][Apache/2.2.3 (CentOS)], Apache[2.2.3], Frame, Cookies[sloth_cc,sloth_nosend,sloth_ref,sloth_sc,sloth_src]
4978
4979Detected Plugins:
4980[ ActiveX ]
4981 ActiveX is a framework based on Microsoft's Component
4982 Object Model (COM) and Object Linking and Embedding (OLE)
4983 technologies. ActiveX components officially operate only
4984 with Microsoft's Internet Explorer web browser and the
4985 Microsoft Windows operating system. - More info:
4986 http://en.wikipedia.org/wiki/ActiveX
4987
4988 Module : D27CDB6E-AE6D-11cf-96B8-444553540000
4989
4990[ Adobe-Flash ]
4991 This plugin identifies instances of embedded adobe flash
4992 files.
4993
4994 Google Dorks: (1)
4995
4996[ Apache ]
4997 The Apache HTTP Server Project is an effort to develop and
4998 maintain an open-source HTTP server for modern operating
4999 systems including UNIX and Windows NT. The goal of this
5000 project is to provide a secure, efficient and extensible
5001 server that provides HTTP services in sync with the current
5002 HTTP standards.
5003
5004 Version : 2.2.3 (from HTTP Server Header)
5005 Google Dorks: (3)
5006 Website : http://httpd.apache.org/
5007
5008[ Cookies ]
5009 Display the names of cookies in the HTTP headers. The
5010 values are not returned to save on space.
5011
5012 String : sloth_src
5013 String : sloth_cc
5014 String : sloth_sc
5015 String : sloth_ref
5016 String : sloth_nosend
5017
5018[ Frame ]
5019 This plugin detects instances of frame and iframe HTML
5020 elements.
5021
5022
5023[ HTTPServer ]
5024 HTTP server header string. This plugin also attempts to
5025 identify the operating system from the server header.
5026
5027 OS : CentOS
5028 String : Apache/2.2.3 (CentOS) (from server string)
5029
5030[ Object ]
5031 HTML object tag. This can be audio, video, Flash, ActiveX,
5032 Python, etc. More info:
5033 http://www.w3schools.com/tags/tag_object.asp
5034
5035 Module : clsid:D27CDB6E-AE6D-11cf-96B8-444553540000 (from classid)
5036 String : http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,24,0
5037
5038[ PHP ]
5039 PHP is a widely-used general-purpose scripting language
5040 that is especially suited for Web development and can be
5041 embedded into HTML. This plugin identifies PHP errors,
5042 modules and versions and extracts the local file path and
5043 username if present.
5044
5045 Version : 5.3.3
5046 Google Dorks: (2)
5047 Website : http://www.php.net/
5048
5049[ Script ]
5050 This plugin detects instances of script HTML elements and
5051 returns the script language/type.
5052
5053 String : text/javascript
5054
5055[ X-Powered-By ]
5056 X-Powered-By HTTP header
5057
5058 String : PHP/5.3.3 (from x-powered-by string)
5059
5060HTTP Headers:
5061 HTTP/1.1 200 OK
5062 Date: Tue, 29 Aug 2017 18:51:52 GMT
5063 Server: Apache/2.2.3 (CentOS)
5064 X-Powered-By: PHP/5.3.3
5065 Set-Cookie: sloth_src=noref; expires=Thu, 31-Aug-2017 18:51:52 GMT; path=/
5066 Set-Cookie: sloth_cc=0; expires=Thu, 31-Aug-2017 18:51:52 GMT; path=/
5067 Set-Cookie: sloth_sc=0; expires=Thu, 31-Aug-2017 18:51:52 GMT; path=/
5068 Set-Cookie: sloth_ref=deleted; expires=Mon, 29-Aug-2016 18:51:51 GMT; path=/
5069 Set-Cookie: sloth_nosend=59a5b7c8%253A00%253ATnoref%253A; expires=Thu, 31-Aug-2017 18:51:52 GMT; path=/
5070 Connection: close
5071 Transfer-Encoding: chunked
5072 Content-Type: text/html; charset=UTF-8
5073
5074
5075
5076[+] Hosts found in search engines:
5077------------------------------------
5078[-] Resolving hostnames IPs...
507996.44.128.242:www.youngteensonly.com
5080
5081
5082
5083 ^ ^
5084 _ __ _ ____ _ __ _ _ ____
5085 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
5086 | V V // o // _/ | V V // 0 // 0 // _/
5087 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
5088 <
5089 ...'
5090
5091 WAFW00F - Web Application Firewall Detection Tool
5092
5093 By Sandro Gauci && Wendel G. Henrique
5094
5095Checking http://youngteensonly.com
5096Generic Detection results:
5097No WAF detected by the generic detection
5098Number of requests: 13
5099
5100
5101DNS Servers for youngteensonly.com:
5102 NS2.googlejokes.org
5103 NS1.googlejokes.org
5104
5105Trying zone transfer first...
5106 Testing NS2.googlejokes.org
5107 Request timed out or transfer not allowed.
5108 Testing NS1.googlejokes.org
5109 Request timed out or transfer not allowed.
5110
5111Unsuccessful in zone transfer (it was worth a shot)
5112Okay, trying the good old fashioned way... brute force
5113
5114Checking for wildcard DNS...
5115Nope. Good.
5116Now performing 2280 test(s)...
511796.44.128.242 ftp.youngteensonly.com
5118127.0.0.1 localhost.youngteensonly.com
511996.44.128.242 mail.youngteensonly.com
512096.44.128.242 pop.youngteensonly.com
512196.44.128.242 smtp.youngteensonly.com
512296.44.128.242 www.youngteensonly.com
5123
5124Subnets found (may want to probe here using nmap or unicornscan):
5125 127.0.0.0-255 : 1 hostnames found.
5126 96.44.128.0-255 : 5 hostnames found.
5127
5128Done with Fierce scan: http://ha.ckers.org/fierce/
5129Found 6 entries.
5130
5131Have a nice day.
5132
5133
5134
5135lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
5136 Written by Stefan Behte (http://ge.mine.nu)
5137 Proof-of-concept! Might give false positives.
5138
5139Checking for DNS-Loadbalancing: NOT FOUND
5140Checking for HTTP-Loadbalancing [Server]:
5141 Apache/2.2.3 (CentOS)
5142 NOT FOUND
5143
5144Checking for HTTP-Loadbalancing [Date]: 19:02:40, 19:02:41, 19:02:42, 19:02:42, 19:02:43, 19:02:43, 19:02:44, 19:02:44, 19:02:45, 19:02:45, 19:02:46, 19:02:46, 19:02:47, 19:02:47, 19:02:48, 19:02:48, 19:02:49, 19:02:49, 19:02:50, 19:02:50, 19:02:51, 19:02:51, 19:02:52, 19:02:52, 19:02:53, 19:02:53, 19:02:54, 19:02:54, 19:02:55, 19:02:55, 19:02:56, 19:02:56, 19:02:57, 19:02:58, 19:02:58, 19:02:59, 19:02:59, 19:03:00, 19:03:00, 19:03:01, 19:03:01, 19:03:02, 19:03:02, 19:03:03, 19:03:03, 19:03:04, 19:03:04, 19:03:05, 19:03:05, 19:03:06, NOT FOUND
5145
5146Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
5147
5148youngteensonly.com does NOT use Load-balancing.
5149
5150
5151
5152Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
5153
5154 ----------------------------------------------------------
5155| Scan Information |
5156 ----------------------------------------------------------
5157
5158Mode ..................... VRFY
5159Worker Processes ......... 5
5160Usernames file ........... users.txt
5161Target count ............. 1
5162Username count ........... 494
5163Target TCP port .......... 25
5164Query timeout ............ 5 secs
5165Target domain ............
5166
5167######## Scan started at Tue Aug 29 15:03:25 2017 #########
5168######## Scan completed at Tue Aug 29 15:11:40 2017 #########
51690 results.
5170
5171494 queries in 495 seconds (1.0 queries / sec)
5172
5173
5174
5175Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 15:11 EDT
5176NSE: Loaded 146 scripts for scanning.
5177NSE: Script Pre-scanning.
5178Initiating NSE at 15:11
5179Completed NSE at 15:11, 0.00s elapsed
5180Initiating NSE at 15:11
5181Completed NSE at 15:11, 0.00s elapsed
5182Failed to resolve "youngteensonly.com.txt".
5183Initiating Parallel DNS resolution of 1 host. at 15:11
5184Completed Parallel DNS resolution of 1 host. at 15:11, 0.47s elapsed
5185Initiating SYN Stealth Scan at 15:11
5186Scanning youngteensonly.com (96.44.128.242) [100 ports]
5187Discovered open port 53/tcp on 96.44.128.242
5188Discovered open port 80/tcp on 96.44.128.242
5189Discovered open port 3306/tcp on 96.44.128.242
5190Discovered open port 21/tcp on 96.44.128.242
5191Discovered open port 22/tcp on 96.44.128.242
5192Discovered open port 111/tcp on 96.44.128.242
5193Increasing send delay for 96.44.128.242 from 0 to 5 due to 63 out of 156 dropped probes since last increase.
5194Completed SYN Stealth Scan at 15:11, 4.10s elapsed (100 total ports)
5195Initiating Service scan at 15:11
5196Scanning 6 services on youngteensonly.com (96.44.128.242)
5197Completed Service scan at 15:11, 6.51s elapsed (6 services on 1 host)
5198Initiating OS detection (try #1) against youngteensonly.com (96.44.128.242)
5199adjust_timeouts2: packet supposedly had rtt of -187681 microseconds. Ignoring time.
5200adjust_timeouts2: packet supposedly had rtt of -187681 microseconds. Ignoring time.
5201Retrying OS detection (try #2) against youngteensonly.com (96.44.128.242)
5202Initiating Traceroute at 15:12
5203Completed Traceroute at 15:12, 3.01s elapsed
5204Initiating Parallel DNS resolution of 9 hosts. at 15:12
5205Completed Parallel DNS resolution of 9 hosts. at 15:12, 5.54s elapsed
5206NSE: Script scanning 96.44.128.242.
5207Initiating NSE at 15:12
5208Completed NSE at 15:12, 47.81s elapsed
5209Initiating NSE at 15:12
5210Completed NSE at 15:12, 0.56s elapsed
5211Nmap scan report for youngteensonly.com (96.44.128.242)
5212Host is up (0.26s latency).
5213rDNS record for 96.44.128.242: 96.44.128.242.static.quadranet.com
5214Not shown: 88 closed ports
5215PORT STATE SERVICE VERSION
521621/tcp open ftp vsftpd 2.0.5
521722/tcp open ssh OpenSSH 4.3 (protocol 2.0)
5218| ssh-hostkey:
5219| 1024 9e:5e:2b:a6:8e:a3:f9:97:71:a0:79:c6:32:5a:24:16 (DSA)
5220|_ 2048 18:d2:c6:55:09:38:56:5f:69:4e:b9:1c:41:0d:36:d1 (RSA)
522125/tcp filtered smtp
522253/tcp open domain ISC BIND Not available
522380/tcp open http Apache httpd 2.2.3
5224| http-methods:
5225|_ Supported Methods: HEAD POST OPTIONS
5226|_http-server-header: Apache/2.2.3 (CentOS)
5227|_http-title: Welcome to Young Teens Only +18y
5228111/tcp open rpcbind 2 (RPC #100000)
5229135/tcp filtered msrpc
5230139/tcp filtered netbios-ssn
5231445/tcp filtered microsoft-ds
5232465/tcp filtered smtps
5233587/tcp filtered submission
52343306/tcp open mysql MySQL 5.1.56
5235| mysql-info:
5236| Protocol: 10
5237| Version: 5.1.56
5238| Thread ID: 3612840
5239| Capabilities flags: 63487
5240| Some Capabilities: Speaks41ProtocolNew, ODBCClient, FoundRows, SupportsCompression, InteractiveClient, SupportsTransactions, IgnoreSigpipes, DontAllowDatabaseTableColumn, ConnectWithDatabase, IgnoreSpaceBeforeParenthesis, Speaks41ProtocolOld, SupportsLoadDataLocal, LongColumnFlag, LongPassword, Support41Auth
5241| Status: Autocommit
5242|_ Salt: E7&Wdn~NKjVOh><QawQo
5243Device type: general purpose|firewall|proxy server|PBX|WAP|remote management|printer
5244Running (JUST GUESSING): Linux 2.6.X (95%), Cisco embedded (93%), Riverbed embedded (93%), Ruckus embedded (93%), Check Point GAiA OS (92%), Dell embedded (91%), Kyocera embedded (91%)
5245OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:2.6 cpe:/h:cisco:sa520 cpe:/h:riverbed:steelhead_200 cpe:/h:cisco:uc320w cpe:/h:ruckus:7363 cpe:/o:checkpoint:gaia_os cpe:/h:kyocera:cs_255
5246Aggressive OS guesses: Linux 2.6.32 (95%), Linux 2.6.18 (95%), Linux 2.6.9 - 2.6.18 (94%), Linux 2.6.9 (94%), Cisco SA520 firewall (Linux 2.6) (93%), Linux 2.6.9 - 2.6.27 (93%), Riverbed Steelhead 200 proxy server (93%), Cisco UC320W PBX (Linux 2.6) (93%), Ruckus 7363 WAP (93%), Linux 2.6.9 (CentOS 4.4) (92%)
5247No exact OS matches for host (test conditions non-ideal).
5248Uptime guess: 45.891 days (since Fri Jul 14 17:50:01 2017)
5249Network Distance: 11 hops
5250TCP Sequence Prediction: Difficulty=262 (Good luck!)
5251IP ID Sequence Generation: All zeros
5252Service Info: Host: postyourgfs.com; OS: Unix
5253
5254TRACEROUTE (using port 143/tcp)
5255HOP RTT ADDRESS
52561 109.77 ms 10.13.0.1
52572 ...
52583 110.51 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
52594 ...
52605 113.68 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
52616 179.97 ms be100-1295.nwk-1-a9.nj.us (192.99.146.127)
52627 184.76 ms be100-1039.ash-5-a9.va.us (198.27.73.203)
52638 243.10 ms be100-1036.lax-la1-bb1-a9.ca.us (178.32.135.157)
52649 243.05 ms quadranet.as8100.any2ix.coresite.com (206.72.210.159)
526510 244.00 ms colo-lax9.as8100.net (96.44.180.6)
526611 244.27 ms 96.44.128.242.static.quadranet.com (96.44.128.242)
5267
5268NSE: Script Post-scanning.
5269Initiating NSE at 15:12
5270Completed NSE at 15:12, 0.00s elapsed
5271Initiating NSE at 15:12
5272Completed NSE at 15:12, 0.00s elapsed
5273Read data files from: /usr/bin/../share/nmap
5274OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5275Nmap done: 1 IP address (1 host up) scanned in 77.95 seconds
5276 Raw packets sent: 272 (14.654KB) | Rcvd: 210 (10.902KB)
5277
5278
5279Error: can not open nmap file: youngteensonly.com.txt
5280
5281
5282httprint v0.301 (beta) - web server fingerprinting tool
5283(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
5284http://net-square.com/httprint/
5285httprint@net-square.com
5286
5287Finger Printing on http://youngteensonly.com:80/
5288Finger Printing Completed on http://youngteensonly.com:80/
5289--------------------------------------------------
5290Host: youngteensonly.com
5291Fingerprinting Error: Host/URL not found...
5292
5293--------------------------------------------------
5294
5295
5296
5297
5298 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
5299 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5300 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
5301 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
5302 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
5303
5304 _/ User-Agent Tester ↵
5305 _/ AKA: Purple Pimp ↵
5306 _/ ChrisJohnRiley ↵
5307 _/ blog.c22.cc ↵
5308
5309 [>] Performing initial request and confirming stability
5310 [>] Using User-Agent string Mozilla/5.0
5311
5312 [ ] URL (ENTERED): http://youngteensonly.com
5313 [ ] Response Code: 200 OK
5314 [ ] Date: Tue, 29 Aug 2017 19:13:10 GMT
5315 [ ] Server: Apache/2.2.3 (CentOS)
5316 [ ] X-Powered-By: PHP/5.3.3
5317 [ ] Set-Cookie: sloth_src=noref; expires=Thu, 31-Aug-2017 19:13:11 GMT; path=/
5318 [ ] Set-Cookie: sloth_cc=0; expires=Thu, 31-Aug-2017 19:13:11 GMT; path=/
5319 [ ] Set-Cookie: sloth_sc=0; expires=Thu, 31-Aug-2017 19:13:11 GMT; path=/
5320 [ ] Set-Cookie: sloth_ref=deleted; expires=Mon, 29-Aug-2016 19:13:10 GMT; path=/
5321 [ ] Set-Cookie: sloth_nosend=59a5bcc7%253A00%253ATnoref%253A; expires=Thu, 31-Aug-2017 19:13:11 GMT;
5322 path=/
5323 [ ] Connection: close
5324 [ ] Transfer-Encoding: chunked
5325 [ ] Content-Type: text/html; charset=UTF-8
5326 [ ] Data (MD5): 977d4a50b65c2321e763febeed78cb2d
5327
5328 [1] Pass
5329 [2] Pass
5330 [3] Pass
5331
5332 [>] URL appears stable. Beginning test
5333
5334 [>] Using DEFAULT User-Agent Strings
5335
5336 [>] Using Crazy User-Agent Strings
5337 [>] Using Bot User-Agent Strings
5338
5339 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
5340
5341
5342 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
5343
5344
5345 [!] Data (MD5): 1189a3c7350d5dac8eff009ec1eb4cb5
5346
5347
5348 [>] User-Agent String : Googlebot-Image/1.0
5349
5350
5351 [!] Data (MD5): 1189a3c7350d5dac8eff009ec1eb4cb5
5352
5353
5354 [>] User-Agent String : Mediapartners-Google
5355
5356
5357 [!] Data (MD5): 1189a3c7350d5dac8eff009ec1eb4cb5
5358
5359
5360 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
5361
5362
5363 [!] Data (MD5): 1189a3c7350d5dac8eff009ec1eb4cb5
5364
5365
5366 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
5367
5368
5369 [!] Data (MD5): 1189a3c7350d5dac8eff009ec1eb4cb5
5370
5371
5372 [>] User-Agent String : mmcrawler
5373
5374
5375 [!] Data (MD5): 1189a3c7350d5dac8eff009ec1eb4cb5
5376
5377
5378 [>] Checks completed... try enabling VERBOSE mode for more detailed output
5379
5380 [>] That's all folks... Fo' Shizzle!
5381
5382
5383
5384
5385 Enter your target IP : 96.44.128.242
5386
5387 obtention site Joomla ...
5388
5389
5390[i] Scanning Site: http://youngteensonly.com
5391
5392
5393
5394B A S I C I N F O
5395====================
5396
5397
5398[+] Site Title: Welcome to Young Teens Only +18y
5399[+] IP address: 96.44.128.242
5400[+] Web Server: Apache/2.2.3 (CentOS)
5401[+] CMS: Could Not Detect
5402[+] Cloudflare: Not Detected
5403[+] Robots File: Could NOT Find robots.txt!
5404
5405
5406
5407
5408W H O I S L O O K U P
5409========================
5410
5411 Domain Name: YOUNGTEENSONLY.COM
5412 Registry Domain ID: 1263475332_DOMAIN_COM-VRSN
5413 Registrar WHOIS Server: whois.godaddy.com
5414 Registrar URL: http://www.godaddy.com
5415 Updated Date: 2016-11-01T05:03:08Z
5416 Creation Date: 2007-10-08T18:37:05Z
5417 Registry Expiry Date: 2017-10-08T18:37:05Z
5418 Registrar: GoDaddy.com, LLC
5419 Registrar IANA ID: 146
5420 Registrar Abuse Contact Email: abuse@godaddy.com
5421 Registrar Abuse Contact Phone: 480-624-2505
5422 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
5423 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
5424 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5425 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
5426 Name Server: NS1.GOOGLEJOKES.ORG
5427 Name Server: NS2.GOOGLEJOKES.ORG
5428 DNSSEC: unsigned
5429
5430
5431G E O I P L O O K U P
5432=========================
5433
5434[i] IP Address: 96.44.128.242
5435[i] Country: US
5436[i] State: California
5437[i] City: Los Angeles
5438[i] Latitude: 34.049400
5439[i] Longitude: -118.264099
5440
5441
5442
5443
5444H T T P H E A D E R S
5445=======================
5446
5447
5448[i] HTTP/1.1 200 OK
5449[i] Date: Tue, 29 Aug 2017 18:48:33 GMT
5450[i] Server: Apache/2.2.3 (CentOS)
5451[i] X-Powered-By: PHP/5.3.3
5452[i] Set-Cookie: sloth_src=noref; expires=Thu, 31-Aug-2017 18:48:33 GMT; path=/
5453[i] Set-Cookie: sloth_cc=0; expires=Thu, 31-Aug-2017 18:48:33 GMT; path=/
5454[i] Set-Cookie: sloth_sc=0; expires=Thu, 31-Aug-2017 18:48:33 GMT; path=/
5455[i] Set-Cookie: sloth_ref=deleted; expires=Mon, 29-Aug-2016 18:48:32 GMT; path=/
5456[i] Set-Cookie: sloth_nosend=59a5b701%253A00%253ATnoref%253A; expires=Thu, 31-Aug-2017 18:48:33 GMT; path=/
5457[i] Connection: close
5458[i] Content-Type: text/html; charset=UTF-8
5459
5460
5461
5462
5463D N S L O O K U P
5464===================
5465
5466youngteensonly.com. 14396 IN A 96.44.128.242
5467youngteensonly.com. 14400 IN NS ns1.googlejokes.org.
5468youngteensonly.com. 14400 IN NS ns2.googlejokes.org.
5469youngteensonly.com. 14400 IN SOA ns.googlejokes.org. hostmaster.youngteensonly.com. 2009111769 14400 3600 1209600 86400
5470youngteensonly.com. 14400 IN MX 10 mail.youngteensonly.com.
5471youngteensonly.com. 14400 IN TXT "v=spf1 a mx ip4:96.44.128.242 ~all"
5472
5473
5474
5475
5476S U B N E T C A L C U L A T I O N
5477====================================
5478
5479Address = 96.44.128.242
5480Network = 96.44.128.242 / 32
5481Netmask = 255.255.255.255
5482Broadcast = not needed on Point-to-Point links
5483Wildcard Mask = 0.0.0.0
5484Hosts Bits = 0
5485Max. Hosts = 1 (2^0 - 0)
5486Host Range = { 96.44.128.242 - 96.44.128.242 }
5487
5488
5489
5490N M A P P O R T S C A N
5491============================
5492
5493
5494Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 18:48 UTC
5495Nmap scan report for youngteensonly.com (96.44.128.242)
5496Host is up (0.055s latency).
5497rDNS record for 96.44.128.242: 96.44.128.242.static.quadranet.com
5498PORT STATE SERVICE VERSION
549921/tcp open ftp vsftpd 2.0.5
550022/tcp open ssh OpenSSH 4.3 (protocol 2.0)
550123/tcp closed telnet
550225/tcp closed smtp
550380/tcp open http Apache httpd 2.2.3
5504110/tcp closed pop3
5505143/tcp closed imap
5506443/tcp closed https
5507445/tcp closed microsoft-ds
55083389/tcp closed ms-wbt-server
5509Service Info: Host: postyourgfs.com; OS: Unix
5510
5511Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
5512Nmap done: 1 IP address (1 host up) scanned in 6.94 seconds
5513
5514
5515
5516S U B - D O M A I N F I N D E R
5517==================================
5518
5519
5520[i] Total Subdomains Found : 3
5521
5522[+] Subdomain: youngteensonly.com
5523[-] IP: 96.44.128.242
5524
5525[+] Subdomain: mail.youngteensonly.com
5526[-] IP: 96.44.128.242
5527
5528[+] Subdomain: www.youngteensonly.com
5529[-] IP: 96.44.128.242
5530
5531
5532
5533
5534
5535R E V E R S E I P L O O K U P
5536==================================
5537
5538
5539[i] Total Sites Found On This Server : 14
5540
5541
5542[#] es.postyourgfs.com
5543[-] CMS: WordPress
5544
5545[#] kissingirl.com
5546[-] CMS: WordPress
5547
5548[#] kudastraffic.com
5549[-] CMS: Could Not Detect
5550
5551[#] specialteensx.com
5552[-] CMS: Could Not Detect
5553
5554[#] www.kissingirl.com
5555[-] CMS: WordPress
5556
5557[#] www.littlevirginteens.net
5558[-] CMS: Could Not Detect
5559
5560[#] www.liveamateurgirls.org
5561[-] CMS: Drupal
5562
5563[#] www.nudecelebarchive.net
5564[-] CMS: Could Not Detect
5565
5566[#] www.postyourgfs.com
5567[-] CMS: WordPress
5568
5569[#] www.sexycamteens.com,1,www.specialteensx.com
5570[-] CMS: Could Not Detect
5571
5572[#] www.youngestpussies.net
5573[-] CMS: Could Not Detect
5574
5575[#] www.youngteengalleries.com
5576[-] CMS: Could Not Detect
5577
5578[#] youngteengalleries.com
5579[-] CMS: Could Not Detect
5580
5581[#] youngteensonly.com,
5582[-] CMS: Could Not Detect
5583
5584
5585
5586
5587Crawling Types & Descriptions:
5588---------------------------------------------------------------------------
5589+ Target IP: 96.44.128.242
5590+ Target Hostname: 96.44.128.242
5591+ Target Port: 80
5592+ Start Time: 2017-08-29 15:33:44 (GMT-4)
5593---------------------------------------------------------------------------
5594+ Server: Apache/2.2.3 (CentOS)
5595+ The anti-clickjacking X-Frame-Options header is not present.
5596+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
5597+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
5598+ Root page / redirects to: http://www.96.44.128.242/
5599+ ERROR: Error limit (20) reached for host, giving up. Last error:
5600+ Scan terminated: 0 error(s) and 3 item(s) reported on remote host
5601+ End Time: 2017-08-29 15:35:40 (GMT-4) (116 seconds)
5602#######################################################################################################################################
5603http://www.japanese-schoolgirls.net/?fref=gc
5604Hostname www.japanese-schoolgirls.net ISP Yellow Fiber Networks (AS40015)
5605Continent North America Flag
5606US
5607Country United States Country Code US (USA)
5608Region VA Local time 29 Aug 2017 16:57 EDT
5609Metropolis* Washington Postal Code 20191
5610City Reston Latitude 38.931
5611IP Address 67.23.100.162 Longitude -77.349
5612#######################################################################################################################################
5613japanese-schoolgirls.net
5614
5615
5616 Domain Name: JAPANESE-SCHOOLGIRLS.NET
5617 Registry Domain ID: 1551959487_DOMAIN_NET-VRSN
5618 Registrar WHOIS Server: whois.godaddy.com
5619 Registrar URL: http://www.godaddy.com
5620 Updated Date: 2016-04-03T10:59:45Z
5621 Creation Date: 2009-04-11T15:48:02Z
5622 Registry Expiry Date: 2018-04-11T15:48:02Z
5623 Registrar: GoDaddy.com, LLC
5624 Registrar IANA ID: 146
5625 Registrar Abuse Contact Email: abuse@godaddy.com
5626 Registrar Abuse Contact Phone: 480-624-2505
5627 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
5628 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
5629 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
5630 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
5631 Name Server: NS1.M3XS.NET
5632 Name Server: NS2.M3XS.NET
5633 Name Server: NS3.M3XS.NET
5634 Name Server: NS4.M3XS.NET
5635
5636Domain Name: JAPANESE-SCHOOLGIRLS.NET
5637Registrar URL: http://www.godaddy.com
5638Registrant Name: Elliot Deane
5639Registrant Organization:
5640Name Server: NS1.M3XS.NET
5641Name Server: NS2.M3XS.NET
5642Name Server: NS3.M3XS.NET
5643Name Server: NS4.M3XS.NET
5644DNSSEC: unsigned
5645
5646
5647
5648;; OPT PSEUDOSECTION:
5649; EDNS: version: 0, flags:; udp: 4096
5650;; QUESTION SECTION:
5651;japanese-schoolgirls.net. IN ANY
5652
5653;; ANSWER SECTION:
5654japanese-schoolgirls.net. 3479 IN NS ns3.m3xs.net.
5655japanese-schoolgirls.net. 3479 IN NS ns4.m3xs.net.
5656japanese-schoolgirls.net. 3479 IN NS ns1.m3xs.net.
5657japanese-schoolgirls.net. 3479 IN NS ns2.m3xs.net.
5658
5659;; Query time: 8 msec
5660;; SERVER: 192.168.1.254#53(192.168.1.254)
5661;; WHEN: Tue Aug 29 16:58:44 EDT 2017
5662;; MSG SIZE rcvd: 130
5663
5664
5665Running:
5666 traceroute -T -O info -i eth0 japanese-schoolgirls.net
5667traceroute to japanese-schoolgirls.net (67.23.100.162), 30 hops max, 60 byte packets
5668 1 gateway (192.168.1.254) 0.621 ms 0.800 ms 0.946 ms
5669 2 10.135.18.1 (10.135.18.1) 12.928 ms 21.451 ms 28.653 ms
5670 3 75.154.223.222 (75.154.223.222) 29.891 ms 29.953 ms 30.388 ms
5671 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.567 ms 30.782 ms 31.004 ms
5672 5 * * *
5673 6 4.53.116.210 (4.53.116.210) 36.509 ms 34.464 ms 34.612 ms
5674 7 yellow-bboi.bboi.net (66.216.1.218) 35.851 ms 35.451 ms 35.278 ms
5675 8 67.23.113.49 (67.23.113.49) 35.590 ms 35.608 ms 35.775 ms
5676 9 te2-2.NVARSX-AGA02.yellowfiber.net (67.23.112.186) 236.412 ms 236.475 ms 236.512 ms
567710 v3423.m3xs.net (67.23.100.162) <syn,ack> 35.895 ms 36.050 ms 36.169 ms
5678
5679d.
5680
5681----- japanese-schoolgirls.net -----
5682
5683
5684Host's addresses:
5685__________________
5686
5687japanese-schoolgirls.net. 3598 IN A 67.23.100.162
5688
5689
5690Wildcard detection using: irbjqdzwqwtw
5691_______________________________________
5692
5693irbjqdzwqwtw.japanese-schoolgirls.net. 3600 IN A 67.23.100.162
5694
5695
5696
5697Name Servers:
5698______________
5699
5700ns2.m3xs.net. 3600 IN A 184.175.106.2
5701ns4.m3xs.net. 3600 IN A 65.175.104.4
5702ns3.m3xs.net. 3600 IN A 216.177.153.200
5703ns1.m3xs.net. 3600 IN A 67.23.100.5
5704
5705
5706Mail (MX) Servers:
5707___________________
5708
5709
5710
5711
5712Scraping japanese-schoolgirls.net subdomains from Google:
5713__________________________________________________________
5714
5715
5716
5717Google Results:
5718________________
5719
5720www.japanese-schoolgirls.net. 3433 IN CNAME v3423.japanese-schoolgirls.net.
5721
5722
5723japanese-schoolgirls.net class C netranges:
5724____________________________________________
5725
5726 67.23.100.0/24
5727
5728
5729Performing reverse lookup on 256 ip addresses:
5730_______________________________________________
5731
5732
57330 results out of 256 IP addresses.
5734
5735
5736japanese-schoolgirls.net ip blocks:
5737____________________________________
5738
5739
5740done.
5741
5742
5743dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
5744
5745[+] warning: domain might use wildcards. 67.23.100.162 will be ignored from results
5746[+] searching (sub)domains for japanese-schoolgirls.net using built-in wordlist
5747[+] using maximum random delay of 10 millisecond(s) between requests
5748
5749[+] 0 (sub)domains and 0 IP address(es) found
5750[+] completion time: 112 second(s)
5751
5752
5753Tracing to japanese-schoolgirls.net[a] via 192.168.1.254, maximum of 3 retries
5754192.168.1.254 (192.168.1.254) Got answer
5755
5756
5757WhatWeb report for http://japanese-schoolgirls.net
5758Status : 200 OK
5759Title : Japanese Schoolgirls
5760IP : 67.23.100.162
5761Country : UNITED STATES, US
5762
5763Summary : SmartThumbs, Google-Analytics[UA-36831857-1], Script[text/javascript], HTTPServer[Apache], Apache, Frame
5764
5765Detected Plugins:
5766[ Apache ]
5767 The Apache HTTP Server Project is an effort to develop and
5768 maintain an open-source HTTP server for modern operating
5769 systems including UNIX and Windows NT. The goal of this
5770 project is to provide a secure, efficient and extensible
5771 server that provides HTTP services in sync with the current
5772 HTTP standards.
5773
5774 Google Dorks: (3)
5775 Website : http://httpd.apache.org/
5776
5777[ Frame ]
5778 This plugin detects instances of frame and iframe HTML
5779 elements.
5780
5781
5782[ Google-Analytics ]
5783 This plugin identifies the Google Analytics account.
5784
5785 Account : UA-36831857-1
5786 Website : http://www.google.com/analytics/
5787
5788[ HTTPServer ]
5789 HTTP server header string. This plugin also attempts to
5790 identify the operating system from the server header.
5791
5792 String : Apache (from server string)
5793
5794[ Script ]
5795 This plugin detects instances of script HTML elements and
5796 returns the script language/type.
5797
5798 String : text/javascript
5799
5800[ SmartThumbs ]
5801 SmartThumbs is a complete tgp script (thumbnail gallery
5802 post management script), it makes your work easier and
5803 faster by automating gallery preview and thumbnail
5804 cropping. Productivity based thumbnail rotation makes your
5805 productivity higher and brings fast traffic growth.
5806
5807 Website : http://www.smart-scripts.com/?action=smartthumbs
5808
5809HTTP Headers:
5810 HTTP/1.1 200 OK
5811 Date: Tue, 29 Aug 2017 21:02:00 GMT
5812 Server: Apache
5813 Accept-Ranges: bytes
5814 Connection: close
5815 Transfer-Encoding: chunked
5816 Content-Type: text/html
5817
5818
5819
5820[+] Hosts found in search engines:
5821------------------------------------
5822[-] Resolving hostnames IPs...
582367.23.100.162:www.japanese-schoolgirls.net
5824
5825
5826
5827 ^ ^
5828 _ __ _ ____ _ __ _ _ ____
5829 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
5830 | V V // o // _/ | V V // 0 // 0 // _/
5831 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
5832 <
5833 ...'
5834
5835 WAFW00F - Web Application Firewall Detection Tool
5836
5837 By Sandro Gauci && Wendel G. Henrique
5838
5839Checking http://japanese-schoolgirls.net
5840Generic Detection results:
5841No WAF detected by the generic detection
5842Number of requests: 13
5843
5844
5845DNS Servers for japanese-schoolgirls.net:
5846 ns4.m3xs.net
5847 ns3.m3xs.net
5848 ns1.m3xs.net
5849 ns2.m3xs.net
5850
5851Trying zone transfer first...
5852 Testing ns4.m3xs.net
5853 Request timed out or transfer not allowed.
5854 Testing ns3.m3xs.net
5855 Request timed out or transfer not allowed.
5856 Testing ns1.m3xs.net
5857 Request timed out or transfer not allowed.
5858 Testing ns2.m3xs.net
5859 Request timed out or transfer not allowed.
5860
5861Unsuccessful in zone transfer (it was worth a shot)
5862Okay, trying the good old fashioned way... brute force
5863
5864Checking for wildcard DNS...
5865 ** Found 97888654936.japanese-schoolgirls.net at 67.23.100.162.
5866 ** High probability of wildcard DNS.
5867Now performing 2280 test(s)...
5868
5869Subnets found (may want to probe here using nmap or unicornscan):
5870
5871Done with Fierce scan: http://ha.ckers.org/fierce/
5872Found 0 entries.
5873
5874Have a nice day.
5875
5876
5877
5878lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
5879 Written by Stefan Behte (http://ge.mine.nu)
5880 Proof-of-concept! Might give false positives.
5881
5882Checking for DNS-Loadbalancing: NOT FOUND
5883Checking for HTTP-Loadbalancing [Server]:
5884 Apache
5885 NOT FOUND
5886
5887Checking for HTTP-Loadbalancing [Date]: 21:11:23, 21:11:23, 21:11:24, 21:11:24, 21:11:25, 21:11:25, 21:11:26, 21:11:26, 21:11:26, 21:11:27, 21:11:27, 21:11:28, 21:11:28, 21:11:28, 21:11:29, 21:11:29, 21:11:30, 21:11:30, 21:11:30, 21:11:31, 21:11:31, 21:11:32, 21:11:32, 21:11:32, 21:11:33, 21:11:33, 21:11:34, 21:11:34, 21:11:35, 21:11:35, 21:11:35, 21:11:36, 21:11:36, 21:11:37, 21:11:37, 21:11:37, 21:11:38, 21:11:38, 21:11:39, 21:11:39, 21:11:39, 21:11:40, 21:11:40, 21:11:41, 21:11:41, 21:11:41, 21:11:42, 21:11:42, 21:11:43, 21:11:43, NOT FOUND
5888
5889Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
5890
5891japanese-schoolgirls.net does NOT use Load-balancing.
5892
5893
5894
5895Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
5896
5897 ----------------------------------------------------------
5898| Scan Information |
5899 ----------------------------------------------------------
5900
5901Mode ..................... VRFY
5902Worker Processes ......... 5
5903Usernames file ........... users.txt
5904Target count ............. 1
5905Username count ........... 494
5906Target TCP port .......... 25
5907Query timeout ............ 5 secs
5908Target domain ............
5909
5910######## Scan started at Tue Aug 29 17:11:56 2017 #########
5911######## Scan completed at Tue Aug 29 17:20:11 2017 #########
59120 results.
5913
5914494 queries in 495 seconds (1.0 queries / sec)
5915
5916
5917
5918Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-29 17:20 EDT
5919NSE: Loaded 146 scripts for scanning.
5920NSE: Script Pre-scanning.
5921Initiating NSE at 17:20
5922Completed NSE at 17:20, 0.00s elapsed
5923Initiating NSE at 17:20
5924Completed NSE at 17:20, 0.00s elapsed
5925Failed to resolve "japanese-schoolgirls.net.txt".
5926Initiating Parallel DNS resolution of 1 host. at 17:20
5927Completed Parallel DNS resolution of 1 host. at 17:20, 0.42s elapsed
5928Initiating SYN Stealth Scan at 17:20
5929Scanning japanese-schoolgirls.net (67.23.100.162) [100 ports]
5930Discovered open port 21/tcp on 67.23.100.162
5931Discovered open port 22/tcp on 67.23.100.162
5932Discovered open port 995/tcp on 67.23.100.162
5933Discovered open port 993/tcp on 67.23.100.162
5934Discovered open port 110/tcp on 67.23.100.162
5935Discovered open port 443/tcp on 67.23.100.162
5936Discovered open port 80/tcp on 67.23.100.162
5937Discovered open port 143/tcp on 67.23.100.162
5938Completed SYN Stealth Scan at 17:20, 3.47s elapsed (100 total ports)
5939Initiating Service scan at 17:20
5940Scanning 8 services on japanese-schoolgirls.net (67.23.100.162)
5941Completed Service scan at 17:20, 14.51s elapsed (8 services on 1 host)
5942Initiating OS detection (try #1) against japanese-schoolgirls.net (67.23.100.162)
5943adjust_timeouts2: packet supposedly had rtt of -63154 microseconds. Ignoring time.
5944adjust_timeouts2: packet supposedly had rtt of -63154 microseconds. Ignoring time.
5945Initiating Traceroute at 17:20
5946Completed Traceroute at 17:20, 3.02s elapsed
5947Initiating Parallel DNS resolution of 14 hosts. at 17:20
5948Completed Parallel DNS resolution of 14 hosts. at 17:20, 5.55s elapsed
5949NSE: Script scanning 67.23.100.162.
5950Initiating NSE at 17:20
5951Completed NSE at 17:22, 76.90s elapsed
5952Initiating NSE at 17:22
5953Completed NSE at 17:22, 0.45s elapsed
5954Nmap scan report for japanese-schoolgirls.net (67.23.100.162)
5955Host is up (0.19s latency).
5956rDNS record for 67.23.100.162: v3423.m3xs.net
5957Not shown: 89 filtered ports
5958PORT STATE SERVICE VERSION
595921/tcp open ftp Pure-FTPd
596022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
5961| ssh-hostkey:
5962| 1024 ea:e2:f0:ca:13:a5:cd:18:f3:f2:f8:74:4d:d9:e4:22 (DSA)
5963|_ 2048 8d:4f:c9:05:f5:d6:24:18:a7:9f:2b:bd:33:16:9a:65 (RSA)
596453/tcp closed domain
596580/tcp open http Apache httpd (PHP 5.6.31)
5966| http-methods:
5967|_ Supported Methods: HEAD
5968|_http-server-header: Apache
5969|_http-title: Japanese Schoolgirls
5970110/tcp open pop3 Dovecot pop3d
5971143/tcp open imap Dovecot imapd
5972443/tcp open ssl/https?
5973|_ssl-date: 2017-08-29T21:20:56+00:00; +6s from scanner time.
5974993/tcp open ssl/imap Dovecot imapd
5975| ssl-cert: Subject: commonName=*.m3xs.net
5976| Subject Alternative Name: DNS:*.m3xs.net, DNS:m3xs.net
5977| Issuer: commonName=COMODO RSA Domain Validation Secure Server CA/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
5978| Public Key type: rsa
5979| Public Key bits: 2048
5980| Signature Algorithm: sha256WithRSAEncryption
5981| Not valid before: 2015-01-12T00:00:00
5982| Not valid after: 2018-01-13T23:59:59
5983| MD5: b2cf 7b17 4364 6bb0 d1b5 f2e2 33ed e6cf
5984|_SHA-1: d902 6e78 67bc 2302 2d2f c2f9 1629 43e8 7cdd da92
5985|_ssl-date: 2017-08-29T21:21:00+00:00; +7s from scanner time.
5986995/tcp open ssl/pop3 Dovecot pop3d
5987| ssl-cert: Subject: commonName=*.m3xs.net
5988| Subject Alternative Name: DNS:*.m3xs.net, DNS:m3xs.net
5989| Issuer: commonName=COMODO RSA Domain Validation Secure Server CA/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
5990| Public Key type: rsa
5991| Public Key bits: 2048
5992| Signature Algorithm: sha256WithRSAEncryption
5993| Not valid before: 2015-01-12T00:00:00
5994| Not valid after: 2018-01-13T23:59:59
5995| MD5: b2cf 7b17 4364 6bb0 d1b5 f2e2 33ed e6cf
5996|_SHA-1: d902 6e78 67bc 2302 2d2f c2f9 1629 43e8 7cdd da92
5997|_ssl-date: 2017-08-29T21:20:59+00:00; +6s from scanner time.
59988000/tcp closed http-alt
59998080/tcp closed http-proxy
6000Device type: general purpose
6001Running: Linux 2.6.X
6002OS CPE: cpe:/o:linux:linux_kernel:2.6.39
6003OS details: Linux 2.6.39
6004Uptime guess: 0.952 days (since Mon Aug 28 18:30:36 2017)
6005Network Distance: 16 hops
6006TCP Sequence Prediction: Difficulty=261 (Good luck!)
6007IP ID Sequence Generation: All zeros
6008
6009Host script results:
6010|_clock-skew: mean: 6s, deviation: 0s, median: 5s
6011
6012TRACEROUTE (using port 8080/tcp)
6013HOP RTT ADDRESS
60141 110.18 ms 10.13.0.1
60152 ...
60163 110.51 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
60174 ...
60185 113.92 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
60196 113.35 ms ge-3-3-0.mpr1.lhr3.uk.above.net (195.66.236.76)
60207 113.89 ms ae6.mpr3.lhr3.uk.zip.zayo.com (64.125.21.21)
60218 189.92 ms ae27.cs1.lhr15.uk.eth.zayo.com (64.125.30.234)
60229 216.21 ms ae5.cs1.dca2.us.eth.zayo.com (64.125.29.131)
602310 188.99 ms ae0.cs2.dca2.us.eth.zayo.com (64.125.29.229)
602411 187.67 ms ae27.cr2.dca2.us.zip.zayo.com (64.125.30.249)
602512 189.53 ms ae15.er5.iad10.us.zip.zayo.com (64.125.31.42)
602613 189.55 ms 64.125.170.2.available.above.net (64.125.170.2)
602714 189.42 ms 67.23.108.66
602815 189.34 ms te2-1.rsx.a01.yellowfiber.net (67.23.107.234)
602916 188.21 ms v3423.m3xs.net (67.23.100.162)
6030
6031NSE: Script Post-scanning.
6032Initiating NSE at 17:22
6033Completed NSE at 17:22, 0.00s elapsed
6034Initiating NSE at 17:22
6035Completed NSE at 17:22, 0.00s elapsed
6036Read data files from: /usr/bin/../share/nmap
6037OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6038Nmap done: 1 IP address (1 host up) scanned in 108.86 seconds
6039 Raw packets sent: 262 (13.502KB) | Rcvd: 154 (44.926KB)
6040
6041
6042
6043--------------------------------------------------
6044
6045
6046
6047
6048 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
6049 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6050 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
6051 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6052 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
6053
6054 _/ User-Agent Tester ↵
6055 _/ AKA: Purple Pimp ↵
6056 _/ ChrisJohnRiley ↵
6057 _/ blog.c22.cc ↵
6058
6059 [>] Performing initial request and confirming stability
6060 [>] Using User-Agent string Mozilla/5.0
6061
6062 [ ] URL (ENTERED): http://japanese-schoolgirls.net
6063 [ ] Response Code: 200 OK
6064 [ ] Date: Tue, 29 Aug 2017 21:22:13 GMT
6065 [ ] Server: Apache
6066 [ ] Accept-Ranges: bytes
6067 [ ] Connection: close
6068 [ ] Transfer-Encoding: chunked
6069 [ ] Content-Type: text/html
6070 [ ] Data (MD5): 95f11612321d4004881d3543d65e8cc2
6071
6072 [1] Pass
6073 [2] Pass
6074 [3] Pass
6075
6076 [>] URL appears stable. Beginning test
6077
6078 [>] Using DEFAULT User-Agent Strings
6079
6080 [>] Using Crazy User-Agent Strings
6081 [>] Using Bot User-Agent Strings
6082
6083 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
6084
6085
6086 [>] User-Agent String : Windows-Media-Player/9.00.00.4503
6087
6088
6089 [!] Data (MD5): 93383e4df43ee8184bfa2101809f5e48
6090
6091
6092 [>] User-Agent String : Mozilla/5.0 (PLAYSTATION 3; 2.00)
6093
6094
6095 [!] Data (MD5): ef960ac693f01898521613412a540824
6096
6097
6098 [>] User-Agent String : TrackBack/1.02
6099
6100
6101 [!] Data (MD5): e990ce71410a7774c9f6500605741ac8
6102
6103
6104 [>] User-Agent String : wispr
6105
6106
6107 [!] Data (MD5): f973ee9296b867349564b47e3cd7ff98
6108
6109
6110 [>] User-Agent String : EMPTY USER-AGENT STRING!
6111
6112
6113 [!] Data (MD5): f3b514679cee9d3d1ec9f8076258b1e5
6114
6115
6116 [>] User-Agent String : Googlebot/2.1 (+http://www.google.com/bot.html)
6117
6118
6119 [!] Data (MD5): e67fb6d17fcd2175e2c9e30185140f6a
6120
6121
6122 [>] User-Agent String : Googlebot-Image/1.0
6123
6124
6125 [!] Data (MD5): 8b500f5914579a9bf6630d0e31368607
6126
6127
6128 [>] User-Agent String : Mediapartners-Google
6129
6130
6131 [!] Data (MD5): ba507fbe7a171003d18a34aacd759546
6132
6133
6134 [>] User-Agent String : Mozilla/2.0 (compatible; Ask Jeeves)
6135
6136
6137 [!] Data (MD5): ce02cd5a7bca52660c3f8a8f56cc5b4e
6138
6139
6140 [>] User-Agent String : msnbot-Products/1.0 (+http://search.msn.com/msnbot.htm)
6141
6142
6143 [!] Data (MD5): 8649f80544713efceb9e080ede54594d
6144
6145
6146 [>] User-Agent String : mmcrawler
6147
6148
6149 [!] Data (MD5): 079df88745f397e2ed1a0802d3c52abc
6150
6151
6152 [>] Checks completed... try enabling VERBOSE mode for more detailed output
6153
6154 [>] That's all folks... Fo' Shizzle!
6155
6156
6157
6158
6159B A S I C I N F O
6160====================
6161
6162
6163[+] Site Title: Japanese Schoolgirls
6164[+] IP address: 67.23.100.162
6165[+] Web Server: Apache
6166[+] CMS: Could Not Detect
6167[+] Cloudflare: Not Detected
6168[+] Robots File: Could NOT Find robots.txt!
6169
6170
6171
6172
6173W H O I S L O O K U P
6174========================
6175
6176 Domain Name: JAPANESE-SCHOOLGIRLS.NET
6177 Registry Domain ID: 1551959487_DOMAIN_NET-VRSN
6178 Registrar WHOIS Server: whois.godaddy.com
6179 Registrar URL: http://www.godaddy.com
6180 Updated Date: 2016-04-03T10:59:45Z
6181 Creation Date: 2009-04-11T15:48:02Z
6182 Registry Expiry Date: 2018-04-11T15:48:02Z
6183 Registrar: GoDaddy.com, LLC
6184 Registrar IANA ID: 146
6185 Registrar Abuse Contact Email: abuse@godaddy.com
6186 Registrar Abuse Contact Phone: 480-624-2505
6187 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
6188 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
6189 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6190 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
6191 Name Server: NS1.M3XS.NET
6192 Name Server: NS2.M3XS.NET
6193 Name Server: NS3.M3XS.NET
6194 Name Server: NS4.M3XS.NET
6195 DNSSEC: unsigned
6196
6197
6198
6199
6200G E O I P L O O K U P
6201=========================
6202
6203[i] IP Address: 67.23.100.162
6204[i] Country: US
6205[i] State: Virginia
6206[i] City: Reston
6207[i] Latitude: 38.931099
6208[i] Longitude: -77.348900
6209
6210
6211
6212
6213H T T P H E A D E R S
6214=======================
6215
6216
6217[i] HTTP/1.1 200 OK
6218[i] Date: Tue, 29 Aug 2017 21:00:13 GMT
6219[i] Server: Apache
6220[i] Accept-Ranges: bytes
6221[i] Connection: close
6222[i] Content-Type: text/html
6223
6224
6225
6226
6227D N S L O O K U P
6228===================
6229
6230japanese-schoolgirls.net. 3596 IN A 67.23.100.162
6231japanese-schoolgirls.net. 3600 IN NS ns2.m3xs.net.
6232japanese-schoolgirls.net. 3600 IN NS ns1.m3xs.net.
6233japanese-schoolgirls.net. 3600 IN NS ns3.m3xs.net.
6234japanese-schoolgirls.net. 3600 IN NS ns4.m3xs.net.
6235japanese-schoolgirls.net. 3600 IN SOA ns1.m3xs.net. dns.m3xs.net. 2013121001 3600 1800 1209600 3600
6236japanese-schoolgirls.net. 3600 IN MX 30 v3423.m3xs.net.
6237
6238
6239
6240
6241S U B N E T C A L C U L A T I O N
6242====================================
6243
6244Address = 67.23.100.162
6245Network = 67.23.100.162 / 32
6246Netmask = 255.255.255.255
6247Broadcast = not needed on Point-to-Point links
6248Wildcard Mask = 0.0.0.0
6249Hosts Bits = 0
6250Max. Hosts = 1 (2^0 - 0)
6251Host Range = { 67.23.100.162 - 67.23.100.162 }
6252
6253
6254
6255N M A P P O R T S C A N
6256============================
6257
6258
6259Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-29 21:00 UTC
6260Nmap scan report for japanese-schoolgirls.net (67.23.100.162)
6261Host is up (0.0033s latency).
6262rDNS record for 67.23.100.162: v3423.m3xs.net
6263PORT STATE SERVICE VERSION
626421/tcp open ftp Pure-FTPd
626522/tcp open ssh OpenSSH 5.3 (protocol 2.0)
626623/tcp filtered telnet
626725/tcp open smtp Sendmail 8.14.4/8.13.8
626880/tcp open http Apache httpd (PHP 5.6.31)
6269110/tcp open pop3 Dovecot pop3d
6270143/tcp open imap Dovecot imapd
6271443/tcp open ssl/http Apache httpd (PHP 5.6.31)
6272445/tcp filtered microsoft-ds
62733389/tcp filtered ms-wbt-server
6274Service Info: OS: Unix
6275
6276
6277
6278[i] Total Subdomains Found : 2
6279
6280[+] Subdomain: japanese-schoolgirls.net
6281[-] IP: 67.23.100.162
6282
6283[+] Subdomain: v3423.japanese-schoolgirls.net
6284[-] IP: 67.23.100.162
6285
6286
6287
6288
6289
6290R E V E R S E I P L O O K U P
6291==================================
6292
6293
6294[i] Total Sites Found On This Server : 9
6295
6296
6297[#] howtobeprepared.org
6298[-] CMS: Could Not Detect
6299
6300[#] japanese-schoolgirls.net
6301[-] CMS: Could Not Detect
6302
6303[#] spankthoseteens.com,1,teencuties.org
6304[-] CMS: Could Not Detect
6305
6306[#] www.cuteteenangels.com
6307[-] CMS: Could Not Detect
6308
6309[#] www.japanese-schoolgirls.net
6310[-] CMS: Could Not Detect
6311
6312[#] www.teencuties.org
6313[-] CMS: Could Not Detect
6314
6315[#] www.teenparty.org
6316[-] CMS: Could Not Detect
6317
6318[#] www.tightlittlepackage.com
6319[-] CMS: WordPress
6320
6321[#] youngteenies.net,
6322[-] CMS: Could Not Detect
6323
6324Crawling Types & Descriptions:
6325---------------------------------------------------------------------------
6326+ Target IP: 67.23.100.162
6327+ Target Hostname: 67.23.100.162
6328+ Target Port: 80
6329+ Start Time: 2017-08-29 17:01:03 (GMT-4)
6330---------------------------------------------------------------------------
6331+ Server: Apache
6332+ Retrieved x-powered-by header: PHP/5.6.31
6333+ The anti-clickjacking X-Frame-Options header is not present.
6334+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
6335+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
6336+ No CGI Directories found (use '-C all' to force check all possible dirs)
6337+ Web Server returns a valid response with junk HTTP methods, this may cause false positives.
6338+ OSVDB-3268: /icons/: Directory indexing found.
6339+ OSVDB-3233: /icons/README: Apache default file found.
6340+ ERROR: Error limit (20) reached for host, giving up. Last error:
6341+ Scan terminated: 0 error(s) and 7 item(s) reported on remote host
6342+
6343######################################################################################################################################
6344Hostname wowlovetube.com ISP Unknown
6345Continent Unknown Flag
6346US
6347Country United States Country Code US
6348Region Unknown Local time 30 Aug 2017 08:49 CDT
6349City Unknown Latitude 37.751
6350IP Address (IPv6) 2400:cb00:2048:1::6818:608c Longitude -97.822
6351##########################################################################################################################################
6352wowlovetube.com
6353
6354
6355 Domain Name: WOWLOVETUBE.COM
6356 Registry Domain ID: 2012416232_DOMAIN_COM-VRSN
6357 Registrar WHOIS Server: whois.namesilo.com
6358 Registrar URL: http://www.namesilo.com
6359 Updated Date: 2017-04-06T06:44:20Z
6360 Creation Date: 2016-03-15T11:11:30Z
6361 Registry Expiry Date: 2018-03-15T11:11:30Z
6362 Registrar: NameSilo, LLC
6363 Registrar IANA ID: 1479
6364 Registrar Abuse Contact Email: abuse@namesilo.com
6365 Registrar Abuse Contact Phone: +1.4805240066
6366 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6367 Name Server: JADE.NS.CLOUDFLARE.COM
6368 Name Server: MILES.NS.CLOUDFLARE.COM
6369
6370Domain Name: wowlovetube.com
6371Registry Domain ID: 2012416232_DOMAIN_COM-VRSN
6372Registrar WHOIS Server: whois.namesilo.com
6373Registrar URL: https://www.namesilo.com/
6374Updated Date: 2017-08-25
6375Creation Date: 2016-03-15
6376Registrar Registration Expiration Date: 2018-03-15
6377Registrar: NameSilo, LLC
6378Registrar IANA ID: 1479
6379Registrar Abuse Contact Email: abuse@namesilo.com
6380Registrar Abuse Contact Phone: +1.4805240066
6381Reseller: QHOSTER.COM
6382Status: clientTransferProhibited
6383Registry Registrant ID:
6384Registrant Name: Ruslan Dazaev
6385Registrant Organization:
6386Registrant Street: Moscow street
6387Registrant City: Moscow
6388Registrant State/Province: Moscow
6389Registrant Postal Code: 119618
6390Registrant Country: RU
6391Registrant Phone: +7.9254127894
6392Registrant Phone Ext:
6393Registrant Fax:
6394Registrant Fax Ext:
6395Registrant Email: dazdark@mail.com
6396Registry Admin ID:
6397Admin Name: Ruslan Dazaev
6398Admin Organization:
6399Admin Street: Moscow street
6400Admin City: Moscow
6401Admin State/Province: Moscow
6402Admin Postal Code: 119618
6403Admin Country: RU
6404Admin Phone: +7.9254127894
6405Admin Phone Ext:
6406Admin Fax:
6407Admin Fax Ext:
6408Admin Email: dazdark@mail.com
6409Registry Tech ID:
6410Tech Name: Ruslan Dazaev
6411Tech Organization:
6412Tech Street: Moscow street
6413Tech City: Moscow
6414Tech State/Province: Moscow
6415Tech Postal Code: 119618
6416Tech Country: RU
6417Tech Phone: +7.9254127894
6418Tech Phone Ext:
6419Tech Fax:
6420Tech Fax Ext:
6421Tech Email: dazdark@mail.com
6422Name Server: JADE.NS.CLOUDFLARE.COM
6423Name Server: MILES.NS.CLOUDFLARE.COM
6424
6425
6426
6427 IN ANY
6428
6429;; ANSWER SECTION:
6430wowlovetube.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
6431wowlovetube.com. 246 IN AAAA 2400:cb00:2048:1::6818:618c
6432wowlovetube.com. 246 IN AAAA 2400:cb00:2048:1::6818:608c
6433wowlovetube.com. 246 IN A 104.24.96.140
6434wowlovetube.com. 246 IN A 104.24.97.140
6435wowlovetube.com. 9225 IN NS miles.ns.cloudflare.com.
6436wowlovetube.com. 9225 IN NS jade.ns.cloudflare.com.
6437
6438;; Query time: 32 msec
6439;; SERVER: 192.168.1.254#53(192.168.1.254)
6440;; WHEN: Wed Aug 30 09:48:26 EDT 2017
6441;; MSG SIZE rcvd: 243
6442
6443
6444Running:
6445 traceroute -T -O info -i eth0 wowlovetube.com
6446traceroute to wowlovetube.com (104.24.97.140), 30 hops max, 60 byte packets
6447 1 gateway (192.168.1.254) 0.469 ms 0.636 ms 0.780 ms
6448 2 10.135.18.1 (10.135.18.1) 7.569 ms 8.191 ms 15.201 ms
6449 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 29.720 ms 29.967 ms 30.070 ms
6450 4 de-cix-new-york.as13335.net (206.130.10.31) 30.688 ms 30.828 ms 31.049 ms
6451 5 104.24.97.140 (104.24.97.140) <syn,ack> 30.930 ms 31.143 ms 31.262 ms
6452
6453
6454Host's addresses:
6455__________________
6456
6457wowlovetube.com. 218 IN A 104.24.96.140
6458wowlovetube.com. 218 IN A 104.24.97.140
6459
6460
6461Name Servers:
6462______________
6463
6464jade.ns.cloudflare.com. 26539 IN A 173.245.58.167
6465miles.ns.cloudflare.com. 86400 IN A 173.245.59.207
6466
6467
6468Mail (MX) Servers:
6469___________________
6470
6471
6472
6473Brute forcing with dns.txt:
6474____________________________
6475
6476www.wowlovetube.com. 300 IN A 104.24.96.140
6477www.wowlovetube.com. 300 IN A 104.24.97.140
6478
6479
6480Performing recursion:
6481______________________
6482
6483
6484 ---- Checking subdomains NS records ----
6485
6486 Can't perform recursion no NS records.
6487
6488
6489wowlovetube.com class C netranges:
6490___________________________________
6491
6492 104.24.96.0/24
6493 104.24.97.0/24
6494
6495
6496[+] searching (sub)domains for wowlovetube.com using built-in wordlist
6497[+] using maximum random delay of 10 millisecond(s) between requests
6498
6499www.wowlovetube.com
6500IPv6 address #1: 2400:cb00:2048:1::6818:608c
6501IPv6 address #2: 2400:cb00:2048:1::6818:618c
6502
6503www.wowlovetube.com
6504IP address #1: 104.24.97.140
6505IP address #2: 104.24.96.140
6506
6507[+] 2 (sub)domains and 4 IP address(es) found
6508[+] completion time: 108 second(s)
6509
6510
6511Tracing to wowlovetube.com[a] via 192.168.1.254, maximum of 3 retries
6512192.168.1.254 (192.168.1.254) Got answer
6513
6514
6515WhatWeb report for http://wowlovetube.com
6516Status : 200 OK
6517Title : WOW Love Tube
6518IP : 104.24.97.140
6519Country : UNITED STATES, US
6520
6521Summary : HTML5, CloudFlare, Script[text/javascript], PHP[5.5.9-1ubuntu4.20], HttpOnly[__cfduid], X-Powered-By[PHP/5.5.9-1ubuntu4.20], UncommonHeaders[cf-ray], HTTPServer[cloudflare-nginx], Cookies[PHPSESSID,__cfduid,tpl], JQuery
6522
6523Detected Plugins:
6524[ CloudFlare ]
6525 CloudFlare is a content delivery network. Its features
6526 include DDoS protection and Web Application Firewall
6527 functionality
6528
6529 Google Dorks: (1)
6530 Website : https://www.cloudflare.com/
6531
6532[ Cookies ]
6533 Display the names of cookies in the HTTP headers. The
6534 values are not returned to save on space.
6535
6536 String : __cfduid
6537 String : PHPSESSID
6538 String : tpl
6539
6540[ HTML5 ]
6541 HTML version 5, detected by the doctype declaration
6542
6543
6544[ HTTPServer ]
6545 HTTP server header string. This plugin also attempts to
6546 identify the operating system from the server header.
6547
6548 String : cloudflare-nginx (from server string)
6549
6550[ HttpOnly ]
6551 If the HttpOnly flag is included in the HTTP set-cookie
6552 response header and the browser supports it then the cookie
6553 cannot be accessed through client side script - More Info:
6554 http://en.wikipedia.org/wiki/HTTP_cookie
6555
6556 String : __cfduid
6557
6558[ JQuery ]
6559 A fast, concise, JavaScript that simplifies how to traverse
6560 HTML documents, handle events, perform animations, and add
6561 AJAX.
6562
6563 Website : http://jquery.com/
6564
6565[ PHP ]
6566 PHP is a widely-used general-purpose scripting language
6567 that is especially suited for Web development and can be
6568 embedded into HTML. This plugin identifies PHP errors,
6569 modules and versions and extracts the local file path and
6570 username if present.
6571
6572 Version : 5.5.9-1ubuntu4.20
6573 Google Dorks: (2)
6574 Website : http://www.php.net/
6575
6576[ Script ]
6577 This plugin detects instances of script HTML elements and
6578 returns the script language/type.
6579
6580 String : text/javascript
6581
6582[ UncommonHeaders ]
6583 Uncommon HTTP server headers. The blacklist includes all
6584 the standard headers and many non standard but common ones.
6585 Interesting but fairly common headers should have their own
6586 plugins, eg. x-powered-by, server and x-aspnet-version.
6587 Info about headers can be found at www.http-stats.com
6588
6589 String : cf-ray (from headers)
6590
6591[ X-Powered-By ]
6592 X-Powered-By HTTP header
6593
6594 String : PHP/5.5.9-1ubuntu4.20 (from x-powered-by string)
6595
6596HTTP Headers:
6597 HTTP/1.1 200 OK
6598 Date: Wed, 30 Aug 2017 13:51:08 GMT
6599 Content-Type: text/html
6600 Transfer-Encoding: chunked
6601 Connection: close
6602 Set-Cookie: __cfduid=d45fdb1cd491ab73366cfde1b738313791504101068; expires=Thu, 30-Aug-18 13:51:08 GMT; path=/; domain=.wowlovetube.com; HttpOnly
6603 X-Powered-By: PHP/5.5.9-1ubuntu4.20
6604 Set-Cookie: PHPSESSID=fesofm7vi2i952fj1p7ll91n91; path=/
6605 Expires: Thu, 19 Nov 1981 08:52:00 GMT
6606 Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
6607 Pragma: no-cache
6608 Set-Cookie: tpl=default_tpl; expires=Thu, 31-Aug-2017 13:51:08 GMT; Max-Age=86400
6609 Vary: Accept-Encoding
6610 Server: cloudflare-nginx
6611 CF-RAY: 3968391d91f22156-EWR
6612 Content-Encoding: gzip
6613
6614
6615
6616
6617------------------------------------
6618[-] Resolving hostnames IPs...
6619104.24.96.140:www.wowlovetube.com
6620
6621
6622
6623 ^ ^
6624 _ __ _ ____ _ __ _ _ ____
6625 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
6626 | V V // o // _/ | V V // 0 // 0 // _/
6627 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
6628 <
6629 ...'
6630
6631 WAFW00F - Web Application Firewall Detection Tool
6632
6633 By Sandro Gauci && Wendel G. Henrique
6634
6635Checking http://wowlovetube.com
6636The site http://wowlovetube.com is behind a CloudFlare
6637Number of requests: 1
6638
6639
6640DNS Servers for wowlovetube.com:
6641 miles.ns.cloudflare.com
6642 jade.ns.cloudflare.com
6643
6644Trying zone transfer first...
6645 Testing miles.ns.cloudflare.com
6646 Request timed out or transfer not allowed.
6647 Testing jade.ns.cloudflare.com
6648 Request timed out or transfer not allowed.
6649
6650Unsuccessful in zone transfer (it was worth a shot)
6651Okay, trying the good old fashioned way... brute force
6652
6653Checking for wildcard DNS...
6654Nope. Good.
6655Now performing 2280 test(s)...
6656104.24.96.140 www.wowlovetube.com
6657104.24.97.140 www.wowlovetube.com
6658
6659Subnets found (may want to probe here using nmap or unicornscan):
6660 104.24.96.0-255 : 1 hostnames found.
6661 104.24.97.0-255 : 1 hostnames found.
6662
6663
6664Checking for HTTP-Loadbalancing [Date]: 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:46, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:47, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:48, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:49, 13:52:50, 13:52:50, 13:52:50, 13:52:50, NOT FOUND
6665
6666Checking for HTTP-Loadbalancing [Diff]: FOUND
6667< CF-RAY: 39683b9ad77446f2-EWR
6668> CF-RAY: 39683b9b44424728-EWR
6669
6670wowlovetube.com does Load-balancing. Found via Methods: DNS HTTP[Diff]
6671
6672
6673
6674Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
6675
6676 ----------------------------------------------------------
6677| Scan Information |
6678 ----------------------------------------------------------
6679
6680Mode ..................... VRFY
6681Worker Processes ......... 5
6682Usernames file ........... users.txt
6683Target count ............. 1
6684Username count ........... 494
6685Target TCP port .......... 25
6686Query timeout ............ 5 secs
6687Target domain ............
6688
6689######## Scan started at Wed Aug 30 09:52:42 2017 #########
6690######## Scan completed at Wed Aug 30 10:00:57 2017 #########
66910 results.
6692
6693494 queries in 495 seconds (1.0 queries / sec)
6694
6695
6696
6697Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-30 10:00 EDT
6698NSE: Loaded 146 scripts for scanning.
6699NSE: Script Pre-scanning.
6700Initiating NSE at 10:00
6701Completed NSE at 10:00, 0.00s elapsed
6702Initiating NSE at 10:00
6703Completed NSE at 10:00, 0.00s elapsed
6704Failed to resolve "wowlovetube.com.txt".
6705Initiating Parallel DNS resolution of 1 host. at 10:00
6706Completed Parallel DNS resolution of 1 host. at 10:01, 11.12s elapsed
6707Initiating SYN Stealth Scan at 10:01
6708Scanning wowlovetube.com (104.24.97.140) [100 ports]
6709Discovered open port 443/tcp on 104.24.97.140
6710Discovered open port 8080/tcp on 104.24.97.140
6711Discovered open port 80/tcp on 104.24.97.140
6712Discovered open port 8443/tcp on 104.24.97.140
6713Completed SYN Stealth Scan at 10:01, 6.55s elapsed (100 total ports)
6714Initiating Service scan at 10:01
6715Scanning 4 services on wowlovetube.com (104.24.97.140)
6716Completed Service scan at 10:01, 12.21s elapsed (4 services on 1 host)
6717Initiating OS detection (try #1) against wowlovetube.com (104.24.97.140)
6718Retrying OS detection (try #2) against wowlovetube.com (104.24.97.140)
6719Initiating Traceroute at 10:01
6720Completed Traceroute at 10:01, 0.04s elapsed
6721Initiating Parallel DNS resolution of 5 hosts. at 10:01
6722Completed Parallel DNS resolution of 5 hosts. at 10:01, 11.11s elapsed
6723NSE: Script scanning 104.24.97.140.
6724Initiating NSE at 10:01
6725Completed NSE at 10:02, 73.41s elapsed
6726Initiating NSE at 10:02
6727Completed NSE at 10:02, 0.00s elapsed
6728Nmap scan report for wowlovetube.com (104.24.97.140)
6729Host is up (0.030s latency).
6730Other addresses for wowlovetube.com (not scanned): 2400:cb00:2048:1::6818:618c 2400:cb00:2048:1::6818:608c 104.24.96.140
6731Not shown: 96 filtered ports
6732PORT STATE SERVICE VERSION
673380/tcp open http Cloudflare nginx
6734| http-cookie-flags:
6735| /:
6736| PHPSESSID:
6737|_ httponly flag not set
6738| http-methods:
6739|_ Supported Methods: GET HEAD POST OPTIONS
6740|_http-server-header: cloudflare-nginx
6741|_http-title: WOW Love Tube
6742443/tcp open ssl/http Cloudflare nginx
6743| http-cookie-flags:
6744| /:
6745| PHPSESSID:
6746|_ httponly flag not set
6747| http-methods:
6748|_ Supported Methods: GET HEAD POST OPTIONS
6749|_http-server-header: cloudflare-nginx
6750|_http-title: WOW Love Tube
6751| ssl-cert: Subject: commonName=sni139671.cloudflaressl.com
6752| Subject Alternative Name: DNS:sni139671.cloudflaressl.com, DNS:*.59uo.com, DNS:*.69vk.com, DNS:*.834l.com, DNS:*.avnnsdmup-a.ml, DNS:*.barkark.org, DNS:*.businessspace.net, DNS:*.classifieds.id, DNS:*.eagerhole.xyz, DNS:*.fapspace.info, DNS:*.furpoor.xyz, DNS:*.ibeergr.cf, DNS:*.kata.life, DNS:*.ktmcouriers.com, DNS:*.madsirp.cf, DNS:*.nuccia-centroestetico.tk, DNS:*.photographers-elan-studio.com, DNS:*.princessfragrance.com, DNS:*.rickbolla.com, DNS:*.sp00ky.pw, DNS:*.vimotools.us, DNS:*.webtraffichub.net, DNS:*.wowlovetube.com, DNS:*.xlkxszova.tk, DNS:*.xxxsector.info, DNS:59uo.com, DNS:69vk.com, DNS:834l.com, DNS:avnnsdmup-a.ml, DNS:barkark.org, DNS:businessspace.net, DNS:classifieds.id, DNS:eagerhole.xyz, DNS:fapspace.info, DNS:furpoor.xyz, DNS:ibeergr.cf, DNS:kata.life, DNS:ktmcouriers.com, DNS:madsirp.cf, DNS:nuccia-centroestetico.tk, DNS:photographers-elan-studio.com, DNS:princessfragrance.com, DNS:rickbolla.com, DNS:sp00ky.pw, DNS:vimotools.us, DNS:webtraffichub.net, DNS:wowlovetube.com, DNS:xlkxszova.tk, DNS:xxxsector.info
6753| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
6754| Public Key type: ec
6755| Public Key bits: 256
6756| Signature Algorithm: ecdsa-with-SHA256
6757| Not valid before: 2017-08-27T00:00:00
6758| Not valid after: 2018-03-05T23:59:59
6759| MD5: 7f22 a80d 57e0 d1b8 60a3 bd82 48f7 7d41
6760|_SHA-1: aaf3 84f5 400c a7ab 6454 1185 1275 d249 babb 8f32
67618080/tcp open http Cloudflare nginx
6762|_http-server-header: cloudflare-nginx
67638443/tcp open ssl/http Cloudflare nginx
6764|_http-server-header: cloudflare-nginx
6765|_http-title: 400 The plain HTTP request was sent to HTTPS port
6766| ssl-cert: Subject: commonName=sni139671.cloudflaressl.com
6767| Subject Alternative Name: DNS:sni139671.cloudflaressl.com, DNS:*.59uo.com, DNS:*.69vk.com, DNS:*.834l.com, DNS:*.avnnsdmup-a.ml, DNS:*.barkark.org, DNS:*.businessspace.net, DNS:*.classifieds.id, DNS:*.eagerhole.xyz, DNS:*.fapspace.info, DNS:*.furpoor.xyz, DNS:*.ibeergr.cf, DNS:*.kata.life, DNS:*.ktmcouriers.com, DNS:*.madsirp.cf, DNS:*.nuccia-centroestetico.tk, DNS:*.photographers-elan-studio.com, DNS:*.princessfragrance.com, DNS:*.rickbolla.com, DNS:*.sp00ky.pw, DNS:*.vimotools.us, DNS:*.webtraffichub.net, DNS:*.wowlovetube.com, DNS:*.xlkxszova.tk, DNS:*.xxxsector.info, DNS:59uo.com, DNS:69vk.com, DNS:834l.com, DNS:avnnsdmup-a.ml, DNS:barkark.org, DNS:businessspace.net, DNS:classifieds.id, DNS:eagerhole.xyz, DNS:fapspace.info, DNS:furpoor.xyz, DNS:ibeergr.cf, DNS:kata.life, DNS:ktmcouriers.com, DNS:madsirp.cf, DNS:nuccia-centroestetico.tk, DNS:photographers-elan-studio.com, DNS:princessfragrance.com, DNS:rickbolla.com, DNS:sp00ky.pw, DNS:vimotools.us, DNS:webtraffichub.net, DNS:wowlovetube.com, DNS:xlkxszova.tk, DNS:xxxsector.info
6768| Issuer: commonName=COMODO ECC Domain Validation Secure Server CA 2/organizationName=COMODO CA Limited/stateOrProvinceName=Greater Manchester/countryName=GB
6769| Public Key type: ec
6770| Public Key bits: 256
6771| Signature Algorithm: ecdsa-with-SHA256
6772| Not valid before: 2017-08-27T00:00:00
6773| Not valid after: 2018-03-05T23:59:59
6774| MD5: 7f22 a80d 57e0 d1b8 60a3 bd82 48f7 7d41
6775|_SHA-1: aaf3 84f5 400c a7ab 6454 1185 1275 d249 babb 8f32
6776Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
6777Device type: general purpose|specialized|WAP
6778Running (JUST GUESSING): Linux 3.X|4.X|2.6.X (98%), Crestron 2-Series (89%)
6779OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:crestron:2_series cpe:/o:linux:linux_kernel:2.6.22
6780Aggressive OS guesses: Linux 3.12 - 4.4 (98%), Crestron XPanel control system (89%), OpenWrt Kamikaze 7.09 (Linux 2.6.22) (89%)
6781No exact OS matches for host (test conditions non-ideal).
6782Network Distance: 5 hops
6783TCP Sequence Prediction: Difficulty=251 (Good luck!)
6784IP ID Sequence Generation: All zeros
6785
6786TRACEROUTE (using port 443/tcp)
6787HOP RTT ADDRESS
67881 1.77 ms 192.168.1.254
67892 11.66 ms 10.135.18.1
67903 29.99 ms NYCMNYCIZR01.bb.telus.com (75.154.223.248)
67914 30.35 ms de-cix-new-york.as13335.net (206.130.10.31)
67925 30.18 ms 104.24.97.140
6793
6794NSE: Script Post-scanning.
6795Initiating NSE at 10:02
6796Completed NSE at 10:02, 0.00s elapsed
6797Initiating NSE at 10:02
6798Completed NSE at 10:02, 0.00s elapsed
6799Read data files from: /usr/bin/../share/nmap
6800OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6801Nmap done: 1 IP address (1 host up) scanned in 120.24 seconds
6802 Raw packets sent: 503 (27.380KB) | Rcvd: 69 (5.192KB)
6803
6804
6805
6806
6807
6808 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
6809 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6810 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
6811 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
6812 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
6813
6814 _/ User-Agent Tester ↵
6815 _/ AKA: Purple Pimp ↵
6816 _/ ChrisJohnRiley ↵
6817 _/ blog.c22.cc ↵
6818
6819 [>] Performing initial request and confirming stability
6820 [>] Using User-Agent string Mozilla/5.0
6821
6822 [ ] URL (ENTERED): http://wowlovetube.com
6823 [ ] Response Code: 200 OK
6824 [ ] Date: Wed, 30 Aug 2017 14:03:11 GMT
6825 [ ] Content-Type: text/html
6826 [ ] Transfer-Encoding: chunked
6827 [ ] Connection: close
6828 [ ] Set-Cookie: __cfduid=df048ce1b3995c57dc37469a643bdd1631504101791; expires=Thu, 30-Aug-18 14:03:11 GMT;
6829 path=/; domain=.wowlovetube.com; HttpOnly
6830 [ ] X-Powered-By: PHP/5.5.9-1ubuntu4.20
6831 [ ] Set-Cookie: PHPSESSID=7slgr983a3md339o697cqa4lm6; path=/
6832 [ ] Expires: Thu, 19 Nov 1981 08:52:00 GMT
6833 [ ] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
6834 [ ] Pragma: no-cache
6835 [ ] Set-Cookie: tpl=default_tpl; expires=Thu, 31-Aug-2017 14:03:11 GMT; Max-Age=86400
6836 [ ] Vary: Accept-Encoding
6837 [ ] Server: cloudflare-nginx
6838 [ ] CF-RAY: 39684ac3f4be0efd-EWR
6839 [ ] Data (MD5): 89dd34219e5abbb050ccfe1c413a8f79
6840
6841 [1] Pass
6842 [2] Pass
6843 [3] Pass
6844
6845
6846http://0dayporn.info
6847http://contactemr.com
6848http://nationfirst.today
6849http://sims.pauleanr.com
6850http://supersadovod.ru
6851http://theoldwellinn.co.uk
6852http://uniqueholistichappiness.com
6853http://wordpressdesignerb.xyz
6854http://www.contentza.com
6855http://www.tivolicasas.com
6856http://www.treetrimminginsandiegoca.com
6857http://yosoypepe.altervista.org
6858https://0.r.bat.bing.com
6859https://2290498.r.bat.bing.com
6860https://36003960.r.bat.bing.com
6861https://blog.pauleanr.com
6862https://builtfordreams.com
6863https://colehennen.com
6864https://contactemr.com
6865https://kumpulancerpen.com
6866https://rockharbour.ca
6867https://skiengokart.no
6868https://themango.co
6869https://www.brickarchitects.com.au
6870https://www.clocktrust.com
6871https://www.pauleanr.com
6872[i] Scanning Site: http://wowlovetube.com
6873
6874
6875
6876B A S I C I N F O
6877====================
6878
6879
6880[+] Site Title: WOW Love Tube
6881[+] IP address: 104.24.96.140
6882[+] Web Server: cloudflare-nginx
6883[+] CMS: Could Not Detect
6884[+] Cloudflare: Detected
6885[+] Robots File: Could NOT Find robots.txt!
6886
6887
6888
6889
6890W H O I S L O O K U P
6891========================
6892
6893 Domain Name: WOWLOVETUBE.COM
6894 Registry Domain ID: 2012416232_DOMAIN_COM-VRSN
6895 Registrar WHOIS Server: whois.namesilo.com
6896 Registrar URL: http://www.namesilo.com
6897 Updated Date: 2017-04-06T06:44:20Z
6898 Creation Date: 2016-03-15T11:11:30Z
6899 Registry Expiry Date: 2018-03-15T11:11:30Z
6900 Registrar: NameSilo, LLC
6901 Registrar IANA ID: 1479
6902 Registrar Abuse Contact Email: abuse@namesilo.com
6903 Registrar Abuse Contact Phone: +1.4805240066
6904 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
6905 Name Server: JADE.NS.CLOUDFLARE.COM
6906 Name Server: MILES.NS.CLOUDFLARE.COM
6907
6908
6909
6910G E O I P L O O K U P
6911=========================
6912
6913[i] IP Address: 104.24.96.140
6914[i] Country: US
6915[i] State: California
6916[i] City: San Francisco
6917[i] Latitude: 37.769699
6918[i] Longitude: -122.393303
6919
6920
6921
6922
6923H T T P H E A D E R S
6924=======================
6925
6926
6927[i] HTTP/1.1 200 OK
6928[i] Date: Wed, 30 Aug 2017 13:51:14 GMT
6929[i] Content-Type: text/html
6930[i] Connection: close
6931[i] Set-Cookie: __cfduid=d07dd7c89bd840166facd482efe84c47d1504101074; expires=Thu, 30-Aug-18 13:51:14 GMT; path=/; domain=.wowlovetube.com; HttpOnly
6932[i] X-Powered-By: PHP/5.5.9-1ubuntu4.20
6933[i] Set-Cookie: PHPSESSID=r88srth1ohj9udfqfndohfpdq4; path=/
6934[i] Expires: Thu, 19 Nov 1981 08:52:00 GMT
6935[i] Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
6936[i] Pragma: no-cache
6937[i] Set-Cookie: tpl=default_tpl; expires=Thu, 31-Aug-2017 13:51:14 GMT; Max-Age=86400
6938[i] Vary: Accept-Encoding
6939[i] Server: cloudflare-nginx
6940[i] CF-RAY: 39683944b45b46f8-EWR
6941
6942
6943
6944
6945D N S L O O K U P
6946===================
6947
6948wowlovetube.com. 298 IN A 104.24.97.140
6949wowlovetube.com. 298 IN A 104.24.96.140
6950wowlovetube.com. 3789 IN HINFO "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"
6951wowlovetube.com. 298 IN AAAA 2400:cb00:2048:1::6818:608c
6952wowlovetube.com. 298 IN AAAA 2400:cb00:2048:1::6818:618c
6953
6954
6955
6956
6957S U B N E T C A L C U L A T I O N
6958====================================
6959
6960Address = 2400:cb00:2048:1::6818:618c
6961Network = 2400:cb00:2048:1::6818:618c / 128
6962Netmask = ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff
6963Wildcard Mask = ::
6964Hosts Bits = 0
6965Max. Hosts = 0 (2^0 - 1)
6966Host Range = { 2400:cb00:2048:1::6818:618d - 2400:cb00:2048:1::6818:618c }
6967
6968
6969
6970N M A P P O R T S C A N
6971============================
6972
6973
6974Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-30 13:51 UTC
6975Nmap scan report for wowlovetube.com (104.24.97.140)
6976Host is up (0.0079s latency).
6977Other addresses for wowlovetube.com (not scanned): 104.24.96.140 2400:cb00:2048:1::6818:618c 2400:cb00:2048:1::6818:608c
6978PORT STATE SERVICE VERSION
697921/tcp filtered ftp
698022/tcp filtered ssh
698123/tcp filtered telnet
698225/tcp filtered smtp
698380/tcp open http Cloudflare nginx
6984110/tcp filtered pop3
6985143/tcp filtered imap
6986443/tcp open ssl/http Cloudflare nginx
6987445/tcp filtered microsoft-ds
69883389/tcp filtered ms-wbt-server
6989
6990Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
6991Nmap done: 1 IP address (1 host up) scanned in 14.10 seconds
6992
6993
6994
6995S U B - D O M A I N F I N D E R
6996==================================
6997
6998
6999[i] Total Subdomains Found : 2
7000
7001[+] Subdomain: wowlovetube.com
7002[-] IP: 104.24.96.140
7003
7004[+] Subdomain: wowlovetube.com
7005[-] IP: 104.24.97.140
7006
7007
7008
7009
7010
7011R E V E R S E I P L O O K U P
7012==================================
7013
7014
7015[i] Total Sites Found On This Server : 9
7016
7017
7018[#] contactemr.com
7019[-] CMS: WordPress
7020
7021[#] healthyoilsummit.com
7022[-] CMS: WordPress
7023
7024[#] nazdikiyan.com
7025[-] CMS: Could Not Detect
7026
7027[#] sims-download.pauleanr.com
7028[-] CMS: Could Not Detect
7029
7030[#] theoldwellinn.co.uk
7031[-] CMS: WordPress
7032
7033[#] wowlovetube.com
7034[-] CMS: Could Not Detect
7035
7036[#] www.24display.com
7037[-] CMS: Could Not Detect
7038
7039[#] www.mendesstudio.com
7040[-] CMS: Could Not Detect
7041
7042[#] www.shreksfloaters.com.au,
7043[-] CMS: Could Not Detect
7044
7045
7046Crawling Types & Descriptions:
7047--------------------------------------------------------------------------
7048+ Target IP: 104.24.96.140
7049+ Target Hostname: 104.24.96.140
7050+ Target Port: 80
7051+ Start Time: 2017-08-30 10:04:21 (GMT-4)
7052---------------------------------------------------------------------------
7053+ Server: cloudflare-nginx
7054+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
7055+ Uncommon header 'cf-ray' found, with contents: 39684cae30b621fe-EWR
7056+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
7057+ All CGI directories 'found', use '-C none' to test none
7058+ Server banner has changed from 'cloudflare-nginx' to '-nginx' which may suggest a WAF, load balancer or proxy is in place
7059+ 26187 requests: 0 error(s) and 3 item(s) reported on remote host
7060+ End Time: 2017-08-30 10:31:39 (GMT-4) (1638 seconds)
7061---------------------------------------------------------------------------
7062#############################################################################################################################################
7063http://babyserv.com/dark-lolita-bbs/index.html
7064Hostname babyserv.com ISP LeaseWeb Netherlands B.V. (AS60781)
7065Continent Europe Flag
7066NL
7067Country Netherlands Country Code NL (NLD)
7068Region Unknown Local time 30 Aug 2017 16:38 CEST
7069City Unknown Latitude 52.382
7070IP Address 95.211.239.7 Longitude 4.899
7071###########################################################################################################################################
7072 babyserv.com
7073
7074
7075 Domain Name: BABYSERV.COM
7076 Registry Domain ID: 1676418_DOMAIN_COM-VRSN
7077 Registrar WHOIS Server: whois.onlinenic.com
7078 Registrar URL: http://www.onlinenic.com
7079 Updated Date: 2016-10-22T07:05:41Z
7080 Creation Date: 1997-10-23T04:00:00Z
7081 Registry Expiry Date: 2017-10-22T04:00:00Z
7082 Registrar: OnlineNIC, Inc.
7083 Registrar IANA ID: 82
7084 Registrar Abuse Contact Email: abuse@onlinenic.com
7085 Registrar Abuse Contact Phone: +1.5107698492
7086 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7087 Name Server: NS1.BABYSERV.COM
7088 Name Server: NS2.BABYSERV.COM
7089
7090Domain Name: babyserv.com
7091Registry Domain ID: 4621804_DOMAIN_COM-VRSN
7092Registrar WHOIS Server: whois.onlinenic.com
7093Registrar URL: http://www.onlinenic.com
7094Updated Date: 2016-10-22T03:05:31Z
7095Creation Date: 1997-10-23T04:00:00Z
7096Registrar Registration Expiration Date: 2017-10-22T04:00:00Z
7097Registrar: Onlinenic Inc
7098Registrar IANA ID: 82
7099Registrar Abuse Contact Email: onlinenic-enduser@onlinenic.com
7100Registrar Abuse Contact Phone: +1.5107698492
7101Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7102Registry Registrant ID: Not Available From Registry
7103Registrant Name: Maxim Perov
7104Registrant Organization: Maxim Perov
7105Registrant Street: Veresayeva str 8-32
7106Registrant City:
7107Registrant State/Province:
7108Registrant Postal Code:
7109Registrant Country: Russia
7110Registrant Phone: +01.3348733
7111Registrant Phone Ext:
7112Registrant Fax: +01.7071595
7113Registrant Fax Ext:
7114Registrant Email:
7115Registry Admin ID: Not Available From Registry
7116Admin Name: Perov, Maxim
7117Admin Organization: Veresayeva str 8-32
7118Admin Street: Moscow, Moscow 121307
7119Admin City:
7120Admin State/Province:
7121Admin Postal Code:
7122Admin Country: +7.749
7123Admin Phone: +7.74997310947
7124Admin Phone Ext:
7125Admin Fax: +01.7865652
7126Admin Fax Ext:
7127Admin Email: maximperov@yahoo.com
7128Registry Tech ID: Not Available From Registry
7129Tech Name: Perov, Maxim
7130Tech Organization: Veresayeva str 8-32
7131Tech Street: Moscow, Moscow 121307
7132Tech City:
7133Tech State/Province:
7134Tech Postal Code:
7135Tech Country: +7.749
7136Tech Phone: +7.74997310947
7137Tech Phone Ext:
7138Tech Fax: +01.3609555
7139Tech Fax Ext:
7140Tech Email: maximperov@yahoo.com
7141Name Server: ns1.babyserv.com
7142Name Server: ns2.babyserv.com
7143D
7144; <<>> DiG 9.10.3-P4-Debian <<>> babyserv.com any
7145;; global options: +cmd
7146;; Got answer:
7147;; ->>HEADER<<- opcode: QUERY, status: SERVFAIL, id: 64068
7148;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
7149
7150;; OPT PSEUDOSECTION:
7151; EDNS: version: 0, flags:; udp: 4096
7152;; QUESTION SECTION:
7153;babyserv.com. IN ANY
7154
7155;; Query time: 470 msec
7156;; SERVER: 192.168.1.254#53(192.168.1.254)
7157;; WHEN: Wed Aug 30 10:40:22 EDT 2017
7158;; MSG SIZE rcvd: 41
7159
7160
7161Running:
7162 traceroute -T -O info -i eth0 babyserv.com
7163traceroute to babyserv.com (95.211.239.7), 30 hops max, 60 byte packets
7164 1 gateway (192.168.1.254) 0.614 ms 0.726 ms 0.849 ms
7165 2 10.135.18.1 (10.135.18.1) 7.388 ms 7.510 ms 8.128 ms
7166 3 75.154.223.209 (75.154.223.209) 32.331 ms 32.361 ms 32.380 ms
7167 4 * * *
7168 5 * * *
7169 6 * * *
7170 7 * * *
7171 8 hosted-by.leaseweb.com (95.211.239.7) <syn,ack> 122.144 ms 121.827 ms 123.012 ms
7172
7173Host's addresses:
7174__________________
7175
7176babyserv.com. 47 IN A 95.211.239.7
7177
7178
7179Name Servers:
7180______________
7181
7182220.66.212.62.in-addr.arpa. 33384 IN PTR hosted-by.leaseweb.com.
7183
7184
7185
7186babyserv.com class C netranges:
7187________________________________
7188
7189 95.211.239.0/24
7190
7191
7192
7193B A S I C I N F O
7194====================
7195
7196
7197[+] Site Title: Pics preteen girls free nude preteen lolis pics
7198 pre teen models free galleries
7199
7200[+] IP address: 95.211.239.7
7201[+] Web Server: Apache/2
7202[+] CMS: Could Not Detect
7203[+] Cloudflare: Not Detected
7204[+] Robots File: Found
7205
7206-------------[ contents ]----------------
7207User-agent: *
7208Disallow: red.js
7209-----------[end of contents]-------------
7210
7211
7212
7213W H O I S L O O K U P
7214========================
7215
7216 Domain Name: BABYSERV.COM
7217 Registry Domain ID: 1676418_DOMAIN_COM-VRSN
7218 Registrar WHOIS Server: whois.onlinenic.com
7219 Registrar URL: http://www.onlinenic.com
7220 Updated Date: 2016-10-22T07:05:41Z
7221 Creation Date: 1997-10-23T04:00:00Z
7222 Registry Expiry Date: 2017-10-22T04:00:00Z
7223 Registrar: OnlineNIC, Inc.
7224 Registrar IANA ID: 82
7225 Registrar Abuse Contact Email: abuse@onlinenic.com
7226 Registrar Abuse Contact Phone: +1.5107698492
7227 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7228 Name Server: NS1.BABYSERV.COM
7229 Name Server: NS2.BABYSERV.COM
7230
7231
7232G E O I P L O O K U P
7233=========================
7234
7235[i] IP Address: 95.211.239.7
7236[i] Country: NL
7237[i] State: N/A
7238[i] City: N/A
7239[i] Latitude: 52.382401
7240[i] Longitude: 4.899500
7241
7242
7243
7244
7245H T T P H E A D E R S
7246=======================
7247
7248
7249[i] HTTP/1.1 200 OK
7250[i] Date: Wed, 30 Aug 2017 14:26:46 GMT
7251[i] Server: Apache/2
7252[i] Last-Modified: Fri, 10 Feb 2012 22:29:35 GMT
7253[i] ETag: "2e1f44-bc8b-4b8a3a9cff1c0"
7254[i] Accept-Ranges: bytes
7255[i] Content-Length: 48267
7256[i] Vary: Accept-Encoding,User-Agent
7257[i] Connection: close
7258[i] Content-Type: text/html
7259
7260
7261
7262
7263D N S L O O K U P
7264===================
7265
7266no records found
7267
7268
7269
7270S U B N E T C A L C U L A T I O N
7271====================================
7272
7273Address = 95.211.239.7
7274Network = 95.211.239.7 / 32
7275Netmask = 255.255.255.255
7276Broadcast = not needed on Point-to-Point links
7277Wildcard Mask = 0.0.0.0
7278Hosts Bits = 0
7279Max. Hosts = 1 (2^0 - 0)
7280Host Range = { 95.211.239.7 - 95.211.239.7 }
7281
7282
7283
7284N M A P P O R T S C A N
7285============================
7286
7287
7288Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-30 14:41 UTC
7289Nmap scan report for babyserv.com (95.211.239.7)
7290Host is up (0.11s latency).
7291rDNS record for 95.211.239.7: hosted-by.leaseweb.com
7292PORT STATE SERVICE VERSION
729321/tcp open ftp ProFTPD 1.3.3e
729422/tcp open ssh OpenSSH 5.3 (protocol 2.0)
729523/tcp closed telnet
729625/tcp filtered smtp
729780/tcp open http Apache httpd 2
7298110/tcp filtered pop3
7299143/tcp filtered imap
7300443/tcp open ssl/http Apache httpd 2
7301445/tcp filtered microsoft-ds
73023389/tcp closed ms-wbt-server
7303Service Info: Host: localhost; OS: Unix
7304
7305Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7306Nmap done: 1 IP address (1 host up) scanned in 15.14 seconds
7307
7308OPDeathEathers Anonymous JTSEC full recon #16
7309
7310
7311---------------------------------------------------------------------------
7312+ Target IP: 95.211.239.7
7313+ Target Hostname: 95.211.239.7
7314+ Target Port: 80
7315+ Start Time: 2017-08-30 11:02:39 (GMT-4)
7316---------------------------------------------------------------------------
7317+ Server: Apache/2
7318+ Server leaks inodes via ETags, header found with file /, inode: 7735646, size: 44, mtime: Wed Jul 16 18:27:07 2014
7319+ The anti-clickjacking X-Frame-Options header is not present.
7320+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS
7321+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type
7322+ Apache/2 appears to be outdated (current is at least Apache/2.4.12). Apache 2.0.65 (final release) and 2.2.29 are also current.
7323+ Allowed HTTP Methods: POST, OPTIONS, GET, HEAD
7324+ Retrieved x-powered-by header: PHP/5.2.17
7325+ OSVDB-2695: /photo/: My Photo Gallery pre 3.6 contains multiple vulnerabilities including directory traversal, unspecified vulnerabilities and remote management interface access.
7326+ OSVDB-3092: /phpMyAdmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
7327+ OSVDB-3092: /phpmyadmin/ChangeLog: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
7328+ Cookie SQMSESSID created without the httponly flag
7329+ OSVDB-3093: /squirrelmail/src/read_body.php: SquirrelMail found
7330+ OSVDB-3233: /icons/README: Apache default file found.
7331+ OSVDB-3092: /phpMyAdmin/Documentation.html: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
7332+ OSVDB-3092: /phpmyadmin/Documentation.html: phpMyAdmin is for managing MySQL databases, and should be protected or limited to authorized hosts.
7333+ 8497 requests: 0 error(s) and 15 item(s) reported on remote host
7334+ End Time: 2017-08-30 11:24:48 (GMT-4) (1329 seconds)
7335---------------------------------------------------------------------------
7336#######################################################################################################################################
7337
7338Hostname www.popularfreeporn.com ISP Cogent Communications (AS174)
7339Continent North America Flag
7340US
7341Country United States Country Code US (USA)
7342Region NY Local time 30 Aug 2017 13:44 EDT
7343Metropolis* New York Postal Code 10011
7344City New York Latitude 40.731
7345IP Address 50.7.70.123 Longitude -73.998
7346#######################################################################################################################################
7347OPDeathEathers Anonymous JTSEC full recon #16
7348popularfreeporn.com
7349
7350
7351 Domain Name: POPULARFREEPORN.COM
7352 Registry Domain ID: 1648226889_DOMAIN_COM-VRSN
7353 Registrar WHOIS Server: whois.godaddy.com
7354 Registrar URL: http://www.godaddy.com
7355 Updated Date: 2017-02-28T13:38:34Z
7356 Creation Date: 2011-03-30T11:14:57Z
7357 Registry Expiry Date: 2018-03-30T11:14:57Z
7358 Registrar: GoDaddy.com, LLC
7359 Registrar IANA ID: 146
7360 Registrar Abuse Contact Email: abuse@godaddy.com
7361 Registrar Abuse Contact Phone: 480-624-2505
7362 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
7363 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
7364 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7365 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
7366 Name Server: NS69.DOMAINCONTROL.COM
7367 Name Server: NS70.DOMAINCONTROL.COM
7368
7369Domain Name: POPULARFREEPORN.COM
7370Registrar URL: http://www.godaddy.com
7371Registrant Name: Preston Richards
7372Registrant Organization:
7373Name Server: NS69.DOMAINCONTROL.COM
7374Name Server: NS70.DOMAINCONTROL.COM
7375
7376;popularfreeporn.com. IN ANY
7377
7378;; ANSWER SECTION:
7379popularfreeporn.com. 3600 IN MX 0 smtp.secureserver.net.
7380popularfreeporn.com. 3600 IN MX 10 mailstore1.secureserver.net.
7381popularfreeporn.com. 3600 IN SOA ns69.domaincontrol.com. dns.jomax.net. 2016072500 28800 7200 604800 3600
7382popularfreeporn.com. 3600 IN A 50.7.70.123
7383popularfreeporn.com. 3600 IN NS ns69.domaincontrol.com.
7384popularfreeporn.com. 3600 IN NS ns70.domaincontrol.com.
7385
7386
7387Running:
7388 traceroute -T -O info -i eth0 popularfreeporn.com
7389traceroute to popularfreeporn.com (50.7.70.123), 30 hops max, 60 byte packets
7390 1 gateway (192.168.1.254) 0.548 ms 0.733 ms 0.888 ms
7391 2 10.135.18.1 (10.135.18.1) 14.660 ms 24.825 ms 25.726 ms
7392 3 75.154.223.222 (75.154.223.222) 29.635 ms 29.668 ms 29.716 ms
7393 4 be4627.ccr21.jfk10.atlas.cogentco.com (38.140.107.1) 30.813 ms 30.888 ms 30.954 ms
7394 5 be2057.ccr42.jfk02.atlas.cogentco.com (154.54.80.177) 31.045 ms be2056.ccr41.jfk02.atlas.cogentco.com (154.54.44.217) 31.451 ms be2057.ccr42.jfk02.atlas.cogentco.com (154.54.80.177) 31.070 ms
7395 6 be2897.rcr24.jfk01.atlas.cogentco.com (154.54.84.214) 31.627 ms be2896.rcr23.jfk01.atlas.cogentco.com (154.54.84.202) 29.426 ms 29.528 ms
7396 7 be2804.rcr21.b001362-2.jfk01.atlas.cogentco.com (154.54.80.6) 29.865 ms 29.797 ms 29.355 ms
7397 8 core02.aggr0.nyc.fdcservers.net (38.140.161.10) 29.577 ms 29.859 ms 29.944 ms
7398 9 50.7.70.123 (50.7.70.123) <syn,ack> 29.461 ms 29.399 ms 29.473 ms
7399
7400----- popularfreeporn.com -----
7401
7402
7403Host's addresses:
7404__________________
7405
7406popularfreeporn.com. 3540 IN A 50.7.70.123
7407
7408
7409Name Servers:
7410______________
7411
7412ns69.domaincontrol.com. 154933 IN A 216.69.185.45
7413ns70.domaincontrol.com. 169208 IN A 208.109.255.45
7414
7415
7416Mail (MX) Servers:
7417___________________
7418
7419mailstore1.secureserver.net. 60 IN A 68.178.213.244
7420mailstore1.secureserver.net. 60 IN A 68.178.213.243
7421mailstore1.secureserver.net. 60 IN A 72.167.238.32
7422smtp.secureserver.net. 60 IN A 68.178.213.37
7423smtp.secureserver.net. 60 IN A 72.167.238.29
7424smtp.secureserver.net. 60 IN A 68.178.213.203
7425
7426
7427e.popularfreeporn.com
7428IP address #1: 173.201.193.5
7429IP address #2: 72.167.218.45
7430IP address #3: 173.201.192.5
7431IP address #4: 173.201.192.133
7432IP address #5: 97.74.135.45
7433IP address #6: 72.167.218.55
7434IP address #7: 97.74.135.133
7435IP address #8: 72.167.218.173
7436IP address #9: 97.74.135.55
7437IP address #10: 173.201.192.20
7438IP address #11: 97.74.135.148
7439IP address #12: 72.167.218.183
7440IP address #13: 173.201.193.20
7441IP address #14: 173.201.192.148
7442IP address #15: 173.201.193.148
7443IP address #16: 173.201.193.133
7444
7445imap.popularfreeporn.com
7446IP address #1: 68.178.252.71
7447IP address #2: 72.167.218.187
7448IP address #3: 72.167.218.82
7449IP address #4: 97.74.135.193
7450IP address #5: 97.74.135.69
7451IP address #6: 173.201.192.71
7452IP address #7: 173.201.193.226
7453IP address #8: 173.201.193.71
7454IP address #9: 45.40.130.32
7455IP address #10: 68.178.252.221
7456IP address #11: 68.178.252.222
7457
7458mail.popularfreeporn.com
7459IP address #1: 97.74.135.111
7460IP address #2: 173.201.193.200
7461IP address #3: 97.74.135.218
7462IP address #4: 68.178.252.115
7463IP address #5: 45.40.130.44
7464
7465www.popularfreeporn.com
7466IP address #1: 50.7.70.123
7467
7468[+] 4 (sub)domains and 33 IP address(es) found
7469[+] completion time: 105 second(s)
7470
7471
7472Tracing to popularfreeporn.com[a] via 192.168.1.254, maximum of 3 retries
7473192.168.1.254 (192.168.1.254) Got answer
7474
7475
7476WhatWeb report for http://popularfreeporn.com
7477Status : 301 Moved Permanently
7478Title : Document Moved
7479IP : 50.7.70.123
7480Country : UNITED STATES, US
7481
7482Summary : RedirectLocation[http://www.popularfreeporn.com/], X-Powered-By[ASP.NET], UncommonHeaders[content-speed], HTTPServer[Microsoft-IIS/7.5], Microsoft-IIS[7.5]
7483
7484Detected Plugins:
7485[ HTTPServer ]
7486 HTTP server header string. This plugin also attempts to
7487 identify the operating system from the server header.
7488
7489 String : Microsoft-IIS/7.5 (from server string)
7490
7491[ Microsoft-IIS ]
7492 Microsoft Internet Information Services (IIS) for Windows
7493 Server is a flexible, secure and easy-to-manage Web server
7494 for hosting anything on the Web. From media streaming to
7495 web application hosting, IIS's scalable and open
7496 architecture is ready to handle the most demanding tasks.
7497
7498 Version : 7.5
7499 Website : http://www.iis.net/
7500
7501[ RedirectLocation ]
7502 HTTP Server string location. used with http-status 301 and
7503 302
7504
7505 String : http://www.popularfreeporn.com/ (from location)
7506
7507[ UncommonHeaders ]
7508 Uncommon HTTP server headers. The blacklist includes all
7509 the standard headers and many non standard but common ones.
7510 Interesting but fairly common headers should have their own
7511 plugins, eg. x-powered-by, server and x-aspnet-version.
7512 Info about headers can be found at www.http-stats.com
7513
7514 String : content-speed (from headers)
7515
7516[ X-Powered-By ]
7517 X-Powered-By HTTP header
7518
7519 String : ASP.NET (from x-powered-by string)
7520
7521HTTP Headers:
7522 HTTP/1.1 301 Moved Permanently
7523 Content-Type: text/html; charset=UTF-8
7524 Location: http://www.popularfreeporn.com/
7525 Server: Microsoft-IIS/7.5
7526 X-Powered-By: ASP.NET
7527 Content-Speed: proxy
7528 Date: Wed, 30 Aug 2017 17:48:08 GMT
7529 Connection: close
7530 Content-Length: 154
7531
7532WhatWeb report for http://www.popularfreeporn.com/
7533Status : 200 OK
7534Title : Popular Free Porn
7535IP : 50.7.70.123
7536Country : UNITED STATES, US
7537
7538Summary : HTML5, Script[text/javascript], Google-API[ajax/libs/jquery/1.7.1/jquery.min.js], X-Powered-By[ASP.NET], UncommonHeaders[content-speed], HTTPServer[Microsoft-IIS/7.5], JQuery, Microsoft-IIS[7.5]
7539
7540Detected Plugins:
7541[ Google-API ]
7542 This plugin identifies references to Google API in
7543 <script>.
7544
7545 String : ajax/libs/jquery/1.7.1/jquery.min.js
7546
7547[ HTML5 ]
7548 HTML version 5, detected by the doctype declaration
7549
7550
7551[ HTTPServer ]
7552 HTTP server header string. This plugin also attempts to
7553 identify the operating system from the server header.
7554
7555 String : Microsoft-IIS/7.5 (from server string)
7556
7557[ JQuery ]
7558 A fast, concise, JavaScript that simplifies how to traverse
7559 HTML documents, handle events, perform animations, and add
7560 AJAX.
7561
7562 Website : http://jquery.com/
7563
7564[ Microsoft-IIS ]
7565 Microsoft Internet Information Services (IIS) for Windows
7566 Server is a flexible, secure and easy-to-manage Web server
7567 for hosting anything on the Web. From media streaming to
7568 web application hosting, IIS's scalable and open
7569 architecture is ready to handle the most demanding tasks.
7570
7571 Version : 7.5
7572 Website : http://www.iis.net/
7573
7574[ Script ]
7575 This plugin detects instances of script HTML elements and
7576 returns the script language/type.
7577
7578 String : text/javascript
7579
7580[ UncommonHeaders ]
7581 Uncommon HTTP server headers. The blacklist includes all
7582 the standard headers and many non standard but common ones.
7583 Interesting but fairly common headers should have their own
7584 plugins, eg. x-powered-by, server and x-aspnet-version.
7585 Info about headers can be found at www.http-stats.com
7586
7587 String : content-speed (from headers)
7588
7589[ X-Powered-By ]
7590 X-Powered-By HTTP header
7591
7592 String : ASP.NET (from x-powered-by string)
7593
7594HTTP Headers:
7595 HTTP/1.1 200 OK
7596 Cache-Control: private
7597 Content-Length: 22304
7598 Content-Type: text/html
7599 Server: Microsoft-IIS/7.5
7600 X-Powered-By: ASP.NET
7601 Content-Speed: proxy
7602 Date: Wed, 30 Aug 2017 17:48:09 GMT
7603 Connection: close
7604
7605
7606
7607
7608
7609
7610 ^ ^
7611 _ __ _ ____ _ __ _ _ ____
7612 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
7613 | V V // o // _/ | V V // 0 // 0 // _/
7614 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
7615 <
7616 ...'
7617
7618 WAFW00F - Web Application Firewall Detection Tool
7619
7620 By Sandro Gauci && Wendel G. Henrique
7621
7622Checking http://popularfreeporn.com
7623Generic Detection results:
7624No WAF detected by the generic detection
7625Number of requests: 13
7626
7627
7628DNS Servers for popularfreeporn.com:
7629 ns69.domaincontrol.com
7630 ns70.domaincontrol.com
7631
7632Trying zone transfer first...
7633 Testing ns69.domaincontrol.com
7634 Request timed out or transfer not allowed.
7635 Testing ns70.domaincontrol.com
7636 Request timed out or transfer not allowed.
7637
7638Unsuccessful in zone transfer (it was worth a shot)
7639Okay, trying the good old fashioned way... brute force
7640
7641Checking for wildcard DNS...
7642Nope. Good.
7643Now performing 2280 test(s)...
764450.7.70.123 static.popularfreeporn.com
764550.7.70.123 www.popularfreeporn.com
7646
7647Subnets found (may want to probe here using nmap or unicornscan):
7648 50.7.70.0-255 : 2 hostnames found.
7649
7650Done with Fierce scan: http://ha.ckers.org/fierce/
7651Found 2 entries.
7652
7653Have a nice day.
7654
7655
7656
7657lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
7658 Written by Stefan Behte (http://ge.mine.nu)
7659 Proof-of-concept! Might give false positives.
7660
7661Checking for DNS-Loadbalancing: NOT FOUND
7662Checking for HTTP-Loadbalancing [Server]:
7663 Microsoft-IIS/7.5
7664 NOT FOUND
7665
7666Checking for HTTP-Loadbalancing [Date]: 17:53:25, 17:53:26, 17:53:26, 17:53:26, 17:53:27, 17:53:27, 17:53:28, 17:53:28, 17:53:28, 17:53:29, 17:53:29, 17:53:29, 17:53:30, 17:53:30, 17:53:31, 17:53:31, 17:53:32, 17:53:32, 17:53:32, 17:53:33, 17:53:33, 17:53:34, 17:53:34, 17:53:34, 17:53:35, 17:53:35, 17:53:36, 17:53:36, 17:53:37, 17:53:37, 17:53:37, 17:53:38, 17:53:38, 17:53:39, 17:53:39, 17:53:39, 17:53:40, 17:53:40, 17:53:41, 17:53:41, 17:53:41, 17:53:42, 17:53:42, 17:53:43, 17:53:43, 17:53:43, 17:53:44, 17:53:44, 17:53:45, 17:53:45, NOT FOUND
7667
7668Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
7669
7670popularfreeporn.com does NOT use Load-balancing.
7671
7672
7673
7674Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )
7675
7676 ----------------------------------------------------------
7677| Scan Information |
7678 ----------------------------------------------------------
7679
7680Mode ..................... VRFY
7681Worker Processes ......... 5
7682Usernames file ........... users.txt
7683Target count ............. 1
7684Username count ........... 494
7685Target TCP port .......... 25
7686Query timeout ............ 5 secs
7687Target domain ............
7688
7689######## Scan started at Wed Aug 30 13:54:01 2017 #########
7690######## Scan completed at Wed Aug 30 14:02:16 2017 #########
76910 results.
7692
7693494 queries in 495 seconds (1.0 queries / sec)
7694
7695OPDeathEathers Anonymous JTSEC full recon #16
7696
7697Starting Nmap 7.60 ( https://nmap.org ) at 2017-08-30 14:02 EDT
7698NSE: Loaded 146 scripts for scanning.
7699NSE: Script Pre-scanning.
7700Initiating NSE at 14:02
7701Completed NSE at 14:02, 0.00s elapsed
7702Initiating NSE at 14:02
7703Completed NSE at 14:02, 0.00s elapsed
7704Failed to resolve "popularfreeporn.com.txt".
7705Initiating Parallel DNS resolution of 1 host. at 14:02
7706Completed Parallel DNS resolution of 1 host. at 14:02, 0.44s elapsed
7707Initiating SYN Stealth Scan at 14:02
7708Scanning popularfreeporn.com (50.7.70.123) [100 ports]
7709Discovered open port 80/tcp on 50.7.70.123
7710Discovered open port 8080/tcp on 50.7.70.123
7711Discovered open port 49154/tcp on 50.7.70.123
7712Discovered open port 49153/tcp on 50.7.70.123
7713Completed SYN Stealth Scan at 14:02, 2.57s elapsed (100 total ports)
7714Initiating Service scan at 14:02
7715Scanning 4 services on popularfreeporn.com (50.7.70.123)
7716Completed Service scan at 14:03, 61.56s elapsed (4 services on 1 host)
7717Initiating OS detection (try #1) against popularfreeporn.com (50.7.70.123)
7718Retrying OS detection (try #2) against popularfreeporn.com (50.7.70.123)
7719adjust_timeouts2: packet supposedly had rtt of -136371 microseconds. Ignoring time.
7720adjust_timeouts2: packet supposedly had rtt of -136371 microseconds. Ignoring time.
7721adjust_timeouts2: packet supposedly had rtt of -132486 microseconds. Ignoring time.
7722adjust_timeouts2: packet supposedly had rtt of -132486 microseconds. Ignoring time.
7723adjust_timeouts2: packet supposedly had rtt of -136329 microseconds. Ignoring time.
7724adjust_timeouts2: packet supposedly had rtt of -136329 microseconds. Ignoring time.
7725Initiating Traceroute at 14:03
7726Completed Traceroute at 14:03, 3.03s elapsed
7727Initiating Parallel DNS resolution of 12 hosts. at 14:03
7728Completed Parallel DNS resolution of 12 hosts. at 14:03, 5.63s elapsed
7729NSE: Script scanning 50.7.70.123.
7730Initiating NSE at 14:03
7731Completed NSE at 14:03, 5.12s elapsed
7732Initiating NSE at 14:03
7733Completed NSE at 14:03, 0.00s elapsed
7734Nmap scan report for popularfreeporn.com (50.7.70.123)
7735Host is up (0.20s latency).
7736Not shown: 89 closed ports
7737PORT STATE SERVICE VERSION
773825/tcp filtered smtp
773980/tcp open http Microsoft IIS httpd 7.5
7740| http-methods:
7741|_ Supported Methods: GET HEAD POST OPTIONS
7742|_http-server-header: Microsoft-IIS/7.5
7743|_http-title: Did not follow redirect to http://www.popularfreeporn.com/
7744135/tcp filtered msrpc
7745139/tcp filtered netbios-ssn
7746445/tcp filtered microsoft-ds
7747465/tcp filtered smtps
7748587/tcp filtered submission
77498080/tcp open http Microsoft IIS httpd 7.5
7750| http-cookie-flags:
7751| /:
7752| ASPSESSIONIDQQSBCQQD:
7753|_ httponly flag not set
7754|_http-favicon: Unknown favicon MD5: 980E2B664CF20523890297CD4BC07017
7755| http-methods:
7756| Supported Methods: OPTIONS TRACE GET HEAD POST
7757|_ Potentially risky methods: TRACE
7758|_http-open-proxy: Proxy might be redirecting requests
7759|_http-server-header: Microsoft-IIS/7.5
7760|_http-title: Site doesn't have a title (text/html).
776149152/tcp filtered unknown
776249153/tcp open msrpc Microsoft Windows RPC
776349154/tcp open msrpc Microsoft Windows RPC
7764Aggressive OS guesses: Microsoft Windows Server 2008 R2 (94%), Microsoft Windows 7 SP1 (94%), Microsoft Windows Server 2008 or 2008 Beta 3 (94%), Microsoft Windows 7 (94%), Microsoft Windows 7 SP1 or Windows Server 2008 R2 (94%), Microsoft Windows Vista SP0 or SP1, Windows Server 2008 SP1, or Windows 7 (94%), Microsoft Windows Vista SP2 (94%), Microsoft Windows Vista SP2, Windows 7 SP1, or Windows Server 2008 (94%), Microsoft Windows Server 2008 (93%), Microsoft Windows Server 2008 R2 or Windows 8 (93%)
7765No exact OS matches for host (test conditions non-ideal).
7766Uptime guess: 21.330 days (since Wed Aug 9 06:08:13 2017)
7767Network Distance: 13 hops
7768TCP Sequence Prediction: Difficulty=260 (Good luck!)
7769IP ID Sequence Generation: Busy server or unknown class
7770Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
7771
7772TRACEROUTE (using port 993/tcp)
7773HOP RTT ADDRESS
77741 109.79 ms 10.13.0.1
77752 219.19 ms 37.187.24.252
77763 109.80 ms po101.gra-g1-a75.fr.eu (178.33.103.229)
77774 111.84 ms 10.95.33.8
77785 113.83 ms be100-1107.ldn-1-a9.uk.eu (91.121.215.179)
77796 223.13 ms be100-2.ldn-5-a9.uk.eu (213.251.130.122)
77807 ...
77818 113.90 ms be2868.ccr41.lon13.atlas.cogentco.com (154.54.57.153)
77829 223.31 ms be2317.ccr41.jfk02.atlas.cogentco.com (154.54.30.185)
778310 223.42 ms be2897.rcr24.jfk01.atlas.cogentco.com (154.54.84.214)
778411 223.38 ms be2804.rcr21.b001362-2.jfk01.atlas.cogentco.com (154.54.80.6)
778512 223.49 ms core02.aggr0.nyc.fdcservers.net (38.140.161.10)
778613 223.33 ms 50.7.70.123
7787
7788NSE: Script Post-scanning.
7789Initiating NSE at 14:03
7790Completed NSE at 14:03, 0.00s elapsed
7791Initiating NSE at 14:03
7792Completed NSE at 14:03, 0.00s elapsed
7793Read data files from: /usr/bin/../share/nmap
7794OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
7795Nmap done: 1 IP address (1 host up) scanned in 85.35 seconds
7796 Raw packets sent: 193 (11.450KB) | Rcvd: 128 (6.950KB)
7797
7798
7799Error: can not open nmap file: popularfreeporn.com.txt
7800
7801
7802httprint v0.301 (beta) - web server fingerprinting tool
7803(c) 2003-2005 net-square solutions pvt. ltd. - see readme.txt
7804http://net-square.com/httprint/
7805httprint@net-square.com
7806
7807Finger Printing on http://popularfreeporn.com:80/
7808Finger Printing Completed on http://popularfreeporn.com:80/
7809--------------------------------------------------
7810Host: popularfreeporn.com
7811Fingerprinting Error: Host/URL not found...
7812
7813--------------------------------------------------
7814
7815
7816
7817
7818 _/ _/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/ _/_/_/_/
7819 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
7820 _/ _/ _/_/_/_/ _/_/_/ _/ _/_/_/ _/_/_/_/ _/ _/_/_/ _/_/_/_
7821 _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/
7822 _/_/_/_/ _/ _/ _/ _/_/_/_/ _/_/_/_/ _/ _/_/_/_/ _/ _/ [v1.06]
7823
7824 _/ User-Agent Tester ↵
7825 _/ AKA: Purple Pimp ↵
7826 _/ ChrisJohnRiley ↵
7827 _/ blog.c22.cc ↵
7828
7829 [>] Performing initial request and confirming stability
7830 [>] Using User-Agent string Mozilla/5.0
7831
7832 [ ] URL (ENTERED): http://popularfreeporn.com
7833 [!] URL (FINAL): http://www.popularfreeporn.com/
7834 [!] Response Code: 301 Moved Permanently
7835 [ ] Cache-Control: private
7836 [ ] Content-Length: 22304
7837 [ ] Content-Type: text/html
7838 [ ] Server: Microsoft-IIS/7.5
7839 [ ] X-Powered-By: ASP.NET
7840 [ ] Content-Speed: proxy
7841 [ ] Date: Wed, 30 Aug 2017 18:03:52 GMT
7842 [ ] Connection: close
7843 [ ] Data (MD5): 098b8273426330b93869cc9130717b82
7844
7845 [1] Pass
7846 [2] Pass
7847 [3] Pass
7848
7849 [>] URL appears stable. Beginning test
7850
7851 [>] Using DEFAULT User-Agent Strings
7852
7853 [>] Using Crazy User-Agent Strings
7854 [>] Using Bot User-Agent Strings
7855
7856 [>] Output: [+] Added Headers, [-] Removed Headers, [!] Altered Headers, [ ] No Change
7857
7858
7859 [>] Checks completed... try enabling VERBOSE mode for more detailed output
7860
7861 [>] That's all folks... Fo' Shizzle!
7862[i] Scanning Site: http://popularfreeporn.com
7863
7864
7865
7866B A S I C I N F O
7867====================
7868
7869
7870[+] Site Title: Popular Free Porn
7871[+] IP address: 50.7.70.123
7872[+] Web Server: Microsoft-IIS/7.5
7873[+] CMS: Could Not Detect
7874[+] Cloudflare: Not Detected
7875[+] Robots File: Could NOT Find robots.txt!
7876
7877OPDeathEathers Anonymous JTSEC full recon #16
7878
7879W H O I S L O O K U P
7880========================
7881
7882 Domain Name: POPULARFREEPORN.COM
7883 Registry Domain ID: 1648226889_DOMAIN_COM-VRSN
7884 Registrar WHOIS Server: whois.godaddy.com
7885 Registrar URL: http://www.godaddy.com
7886 Updated Date: 2017-02-28T13:38:34Z
7887 Creation Date: 2011-03-30T11:14:57Z
7888 Registry Expiry Date: 2018-03-30T11:14:57Z
7889 Registrar: GoDaddy.com, LLC
7890 Registrar IANA ID: 146
7891 Registrar Abuse Contact Email: abuse@godaddy.com
7892 Registrar Abuse Contact Phone: 480-624-2505
7893 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
7894 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
7895 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
7896 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
7897 Name Server: NS69.DOMAINCONTROL.COM
7898 Name Server: NS70.DOMAINCONTROL.COM
7899 DNSSEC: unsigned
7900 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
7901>>> Last update of whois database: 2017-08-30T17:46:23Z <<<
7902
7903For more information on Whois status codes, please visit https://icann.org/epp
7904
7905
7906
7907The Registry database contains ONLY .COM, .NET, .EDU domains and
7908Registrars.
7909
7910
7911
7912
7913G E O I P L O O K U P
7914=========================
7915
7916[i] IP Address: 50.7.70.123
7917[i] Country: US
7918[i] State: New York
7919[i] City: New York
7920[i] Latitude: 40.730801
7921[i] Longitude: -73.997498
7922
7923OPDeathEathers Anonymous JTSEC full recon #16
7924
7925
7926H T T P H E A D E R S
7927=======================
7928
7929
7930[i] HTTP/1.1 301 Moved Permanently
7931[i] Content-Type: text/html; charset=UTF-8
7932[i] Location: http://www.popularfreeporn.com/
7933[i] Server: Microsoft-IIS/7.5
7934[i] X-Powered-By: ASP.NET
7935[i] Content-Speed: proxy
7936[i] Date: Wed, 30 Aug 2017 17:46:26 GMT
7937[i] Connection: close
7938[i] Content-Length: 154
7939[i] HTTP/1.1 200 OK
7940[i] Cache-Control: private
7941[i] Content-Length: 22304
7942[i] Content-Type: text/html
7943[i] Server: Microsoft-IIS/7.5
7944[i] X-Powered-By: ASP.NET
7945[i] Content-Speed: proxy
7946[i] Date: Wed, 30 Aug 2017 17:46:27 GMT
7947[i] Connection: close
7948
7949OPDeathEathers Anonymous JTSEC full recon #16
7950
7951
7952D N S L O O K U P
7953===================
7954
7955popularfreeporn.com. 3596 IN A 50.7.70.123
7956popularfreeporn.com. 3600 IN NS ns69.domaincontrol.com.
7957popularfreeporn.com. 3600 IN NS ns70.domaincontrol.com.
7958popularfreeporn.com. 3600 IN SOA ns69.domaincontrol.com. dns.jomax.net. 2016072500 28800 7200 604800 3600
7959popularfreeporn.com. 3600 IN MX 10 mailstore1.secureserver.net.
7960popularfreeporn.com. 3600 IN MX 0 smtp.secureserver.net.
7961
7962
7963
7964
7965S U B N E T C A L C U L A T I O N
7966====================================
7967
7968Address = 50.7.70.123
7969Network = 50.7.70.123 / 32
7970Netmask = 255.255.255.255
7971Broadcast = not needed on Point-to-Point links
7972Wildcard Mask = 0.0.0.0
7973Hosts Bits = 0
7974Max. Hosts = 1 (2^0 - 0)
7975Host Range = { 50.7.70.123 - 50.7.70.123 }
7976
7977
7978
7979N M A P P O R T S C A N
7980============================
7981
7982
7983Starting Nmap 7.01 ( https://nmap.org ) at 2017-08-30 17:46 UTC
7984Nmap scan report for popularfreeporn.com (50.7.70.123)
7985Host is up (0.0099s latency).
7986PORT STATE SERVICE VERSION
798721/tcp closed ftp
798822/tcp closed ssh
798923/tcp closed telnet
799025/tcp closed smtp
799180/tcp open http Microsoft IIS httpd 7.5
7992110/tcp closed pop3
7993143/tcp closed imap
7994443/tcp closed https
7995445/tcp open microsoft-ds Microsoft Windows Server 2008 R2 microsoft-ds
79963389/tcp closed ms-wbt-server
7997Service Info: OSs: Windows, Windows Server 2008 R2; CPE: cpe:/o:microsoft:windows, cpe:/o:microsoft:windows_server_2008:r2
7998
7999Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
8000Nmap done: 1 IP address (1 host up) scanned in 6.79 seconds
8001
8002OPDeathEathers Anonymous JTSEC full recon #16
8003
8004S U B - D O M A I N F I N D E R
8005==================================
8006
8007
8008[i] Total Subdomains Found : 1
8009
8010[+] Subdomain: popularfreeporn.com
8011[-] IP: 50.7.70.123
8012
8013
8014
8015
8016
8017R E V E R S E I P L O O K U P
8018==================================
8019
8020
8021[i] Total Sites Found On This Server : 2
8022
8023
8024[#] www.lowes.com
8025[-] CMS: Could Not Detect
8026
8027[#] www.popularfreeporn.com,1,www.youngpornarchive.com,1
8028[-] CMS: Could Not Detect
8029##############################################################################################################################################################################################################################################################################