· 8 years ago · Sep 19, 2017, 09:58 PM
1#######################################################################################################################################
2Hostname www.nonudefree.com ISP Quasi Networks LTD. (AS29073)
3Continent Africa Flag
4SC
5Country Seychelles Country Code SC (SYC)
6Region Unknown Local time 19 Sep 2017 22:17 +04
7City Unknown Latitude -4.583
8IP Address 80.82.78.2 Longitude 55.667
9#######################################################################################################################################
10 OPDeathEathers V.S HunterUnit JTSEC full Recon #25
11whois nonudefree.com
12 Domain Name: NONUDEFREE.COM
13 Registry Domain ID: 1650464161_DOMAIN_COM-VRSN
14 Registrar WHOIS Server: whois.godaddy.com
15 Registrar URL: http://www.godaddy.com
16 Updated Date: 2017-04-09T16:26:46Z
17 Creation Date: 2011-04-12T09:44:40Z
18 Registry Expiry Date: 2018-04-12T09:44:40Z
19 Registrar: GoDaddy.com, LLC
20 Registrar IANA ID: 146
21 Registrar Abuse Contact Email: abuse@godaddy.com
22 Registrar Abuse Contact Phone: 480-624-2505
23 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
24 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
25 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
26 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
27 Name Server: NS1.DYNACLOUDNS.COM
28 Name Server: NS2.DYNACLOUDNS.COM
29
30Domain Name: NONUDEFREE.COM
31Registrar URL: http://www.godaddy.com
32Registrant Name: denis safimov
33Registrant Organization:
34Name Server: NS1.DYNACLOUDNS.COM
35Name Server: NS2.DYNACLOUDNS.COM
36DNSSEC: unsigned
37
38#################################################################################################################################
39
40dig nonudefree.com any
41
42; <<>> DiG 9.10.3-P4-Debian <<>> nonudefree.com any
43;; global options: +cmd
44;; Got answer:
45;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56654
46;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
47
48;; OPT PSEUDOSECTION:
49; EDNS: version: 0, flags:; udp: 4096
50;; QUESTION SECTION:
51;nonudefree.com. IN ANY
52
53;; ANSWER SECTION:
54nonudefree.com. 10781 IN MX 10 mx.nonudefree.com.
55nonudefree.com. 10778 IN A 80.82.78.2
56nonudefree.com. 10552 IN NS ns1.dynacloudns.com.
57
58;; Query time: 8 msec
59;; SERVER: 192.168.1.254#53(192.168.1.254)
60;; WHEN: Tue Sep 19 14:20:47 EDT 2017
61;; MSG SIZE rcvd: 108
62
63#################################################################################################################################
64
65tcptraceroute -i eth0 nonudefree.com
66
67Running:
68 traceroute -T -O info -i eth0 nonudefree.com
69traceroute to nonudefree.com (80.82.78.2), 30 hops max, 60 byte packets
70 1 gateway (192.168.1.254) 0.351 ms 0.660 ms 0.839 ms
71 2 10.135.18.1 (10.135.18.1) 7.008 ms 14.590 ms 14.665 ms
72 3 75.154.223.222 (75.154.223.222) 29.497 ms 29.926 ms 30.002 ms
73 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.135 ms 30.724 ms 30.805 ms
74 5 ae-240-3616.edge6.Amsterdam1.Level3.net (4.69.162.254) 104.492 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 105.083 ms 105.156 ms
75 6 * * *
76 7 80.82.78.2 (80.82.78.2) <syn,ack> 103.326 ms 103.774 ms 103.813 ms
77
78
79#################################################################################################################################
80
81cd /pentest/enumeration/lbd
82./lbd.sh nonudefree.com
83./Recon.sh: ligne 65 : cd: /pentest/enumeration/lbd: Aucun fichier ou dossier de ce type
84
85lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
86 Written by Stefan Behte (http://ge.mine.nu)
87 Proof-of-concept! Might give false positives.
88
89Checking for DNS-Loadbalancing: NOT FOUND
90Checking for HTTP-Loadbalancing [Server]:
91 nginx
92 NOT FOUND
93
94Checking for HTTP-Loadbalancing [Date]: 18:13:30, 18:13:30, 18:13:30, 18:13:31, 18:13:34, 18:13:35, 18:13:35, 18:13:35, 18:13:36, 18:13:37, 18:13:37, 18:13:37, 18:13:38, 18:13:39, 18:13:39, 18:13:40, 18:13:40, 18:13:40, 18:13:40, 18:13:41, 18:13:42, 18:13:42, 18:13:42, 18:13:43, 18:13:43, 18:13:43, 18:13:43, 18:13:44, 18:13:44, 18:13:44, 18:13:45, 18:13:45, 18:13:45, 18:13:45, 18:13:46, 18:13:46, 18:13:46, 18:13:46, 18:13:47, 18:13:47, 18:13:47, 18:13:47, 18:13:48, 18:13:48, 18:13:48, 18:13:49, 18:13:49, 18:13:49, 18:13:49, 18:13:50, NOT FOUND
95
96Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
97
98
99#################################################################################################################################
100
101nmap -PN -n -F -T4 -sV -A -oG temp.txt nonudefree.com
102
103Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 14:21 EDT
104Nmap scan report for nonudefree.com (80.82.78.2)
105Host is up (0.13s latency).
106Not shown: 90 closed ports
107PORT STATE SERVICE VERSION
10821/tcp open ftp vsftpd 2.2.2
10922/tcp open ssh OpenSSH 5.3 (protocol 2.0)
110| ssh-hostkey:
111| 1024 68:1b:d0:3a:82:e8:7f:ec:ec:7b:77:1c:1b:00:d2:8b (DSA)
112|_ 2048 c1:c8:b9:2b:20:db:9d:fc:3e:40:56:a6:06:32:98:89 (RSA)
11325/tcp filtered smtp
11453/tcp open domain
11580/tcp open http nginx
116| http-methods:
117|_ Potentially risky methods: TRACE
118|_http-server-header: nginx
119|_http-title: Nonude Free Child Models Galleries
120135/tcp filtered msrpc
121139/tcp filtered netbios-ssn
122445/tcp filtered microsoft-ds
123465/tcp filtered smtps
124587/tcp filtered submission
125Aggressive OS guesses: Linux 2.6.39 (99%), Linux 2.6.32 (95%), Linux 2.6.32 or 3.10 (95%), Linux 3.4 (95%), WatchGuard Fireware 11.8 (95%), Synology DiskStation Manager 5.1 (94%), Linux 3.10 (94%), Linux 3.1 - 3.2 (94%), Linux 2.6.32 - 2.6.39 (93%), Linux 2.6.32 - 3.0 (92%)
126No exact OS matches for host (test conditions non-ideal).
127Network Distance: 11 hops
128Service Info: OS: Unix
129
130TRACEROUTE (using port 993/tcp)
131HOP RTT ADDRESS
1321 109.51 ms 10.13.0.1
1332 110.64 ms 37.187.24.252
1343 110.62 ms 178.33.103.231
1354 111.78 ms 10.95.33.10
1365 119.07 ms 91.121.131.19
1376 119.08 ms 94.23.122.217
1387 ...
1398 124.57 ms 176.10.83.128
1409 120.33 ms 176.10.83.119
14110 ...
14211 120.41 ms 80.82.78.2
143
144OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
145Nmap done: 1 IP address (1 host up) scanned in 34.10 seconds
146
147#################################################################################################################################
148
149amap -i temp.txt
150amap v5.4 (www.thc.org/thc-amap) started at 2017-09-19 14:22:12 - APPLICATION MAPPING mode
151
152Protocol on 80.82.78.2:80/tcp matches http
153Protocol on 80.82.78.2:21/tcp matches ftp
154Protocol on 80.82.78.2:80/tcp matches http-apache-2
155Protocol on 80.82.78.2:22/tcp matches ssh
156Protocol on 80.82.78.2:22/tcp matches ssh-openssh
157Protocol on 80.82.78.2:53/tcp matches dns
158
159Unidentified ports: none.
160
161amap v5.4 finished at 2017-09-19 14:22:23
162
163#################################################################################################################################
164
165inetnum: 80.82.78.0 - 80.82.78.255
166netname: SC-QUASI79
167descr: QUASI
168country: SC
169org: ORG-QNL3-RIPE
170admin-c: QNL1-RIPE
171tech-c: QNL1-RIPE
172status: ASSIGNED PA
173mnt-by: QUASINETWORKS-MNT
174mnt-lower: QUASINETWORKS-MNT
175mnt-routes: QUASINETWORKS-MNT
176created: 2016-01-23T23:03:28Z
177last-modified: 2016-01-23T23:03:28Z
178source: RIPE
179
180organisation: ORG-QNL3-RIPE
181org-name: Quasi Networks LTD.
182org-type: OTHER
183address: Suite 1, Second Floor
184address: Sound & Vision House, Francis Rachel Street
185address: Victoria, Mahe, SEYCHELLES
186remarks: *****************************************************************************
187remarks: IMPORTANT INFORMATION
188remarks: *****************************************************************************
189remarks: We are a high bandwidth network provider offering bandwidth solutions.
190remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
191remarks: Please only use abuse@quasinetworks.com for abuse reports.
192remarks: For all other requests, please see the details on our website.
193remarks: *****************************************************************************
194abuse-mailbox: abuse@quasinetworks.com
195abuse-c: AR34302-RIPE
196mnt-ref: QUASINETWORKS-MNT
197mnt-by: QUASINETWORKS-MNT
198created: 2015-11-08T22:25:26Z
199last-modified: 2015-11-27T09:37:50Z
200source: RIPE # Filtered
201
202role: Quasi Networks LTD
203address: Suite 1, Second Floor
204address: Sound & Vision House, Francis Rachel Street
205address: Victoria, Mahe, SEYCHELLES
206remarks: *****************************************************************************
207remarks: IMPORTANT INFORMATION
208remarks: *****************************************************************************
209remarks: We are a high bandwidth network provider offering bandwidth solutions.
210remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
211remarks: Please only use abuse@quasinetworks.com for abuse reports.
212remarks: For all other requests, please see the details on our website.
213remarks: *****************************************************************************
214abuse-mailbox: abuse@quasinetworks.com
215nic-hdl: QNL1-RIPE
216mnt-by: QUASINETWORKS-MNT
217created: 2015-11-07T22:43:04Z
218last-modified: 2015-11-07T23:04:49Z
219source: RIPE # Filtered
220
221% Information related to '80.82.78.0/24AS29073'
222
223route: 80.82.78.0/24
224descr: Quasi Networks LTD (IBC)
225origin: AS29073
226mnt-by: QUASINETWORKS-MNT
227created: 2010-10-19T20:30:22Z
228last-modified: 2016-01-23T23:03:48Z
229source: RIPE
230
231% This query was served by the RIPE Database Query Service version 1.89.2 (WAGYU)
232
233
234
235#################################################################################################################################
236i] Scanning Site: http://nonudefree.com
237
238
239
240B A S I C I N F O
241====================
242
243
244[+] Site Title: Nonude Free Child Models Galleries
245[+] IP address: 80.82.78.2
246[+] Web Server: nginx
247[+] CMS: Could Not Detect
248[+] Cloudflare: Not Detected
249[+] Robots File: Could NOT Find robots.txt!
250
251
252
253
254W H O I S L O O K U P
255========================
256
257 Domain Name: NONUDEFREE.COM
258 Registry Domain ID: 1650464161_DOMAIN_COM-VRSN
259 Registrar WHOIS Server: whois.godaddy.com
260 Registrar URL: http://www.godaddy.com
261 Updated Date: 2017-04-09T16:26:46Z
262 Creation Date: 2011-04-12T09:44:40Z
263 Registry Expiry Date: 2018-04-12T09:44:40Z
264 Registrar: GoDaddy.com, LLC
265 Registrar IANA ID: 146
266 Registrar Abuse Contact Email: abuse@godaddy.com
267 Registrar Abuse Contact Phone: 480-624-2505
268 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
269 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
270 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
271 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
272
273
274G E O I P L O O K U P
275=========================
276
277[i] IP Address: 80.82.78.2
278[i] Country: SC
279[i] State: N/A
280[i] City: N/A
281[i] Latitude: -4.583300
282[i] Longitude: 55.666698
283
284
285
286
287H T T P H E A D E R S
288=======================
289
290
291[i] HTTP/1.1 200 OK
292[i] Server: nginx
293[i] Date: Tue, 19 Sep 2017 18:13:19 GMT
294[i] Content-Type: text/html; charset=UTF-8
295[i] Connection: close
296[i] Accept-Ranges: bytes
297
298
299
300
301D N S L O O K U P
302===================
303
304nonudefree.com. 10796 IN A 80.82.78.2
305nonudefree.com. 10800 IN NS ns1.dynacloudns.com.
306nonudefree.com. 10800 IN SOA ns1.nonudefree.com. root.nonudefree.com. 2 10800 3600 21600 3600
307nonudefree.com. 10800 IN MX 10 mx.nonudefree.com.
308
309
310
311
312S U B N E T C A L C U L A T I O N
313====================================
314
315Address = 80.82.78.2
316Network = 80.82.78.2 / 32
317Netmask = 255.255.255.255
318Broadcast = not needed on Point-to-Point links
319Wildcard Mask = 0.0.0.0
320Hosts Bits = 0
321Max. Hosts = 1 (2^0 - 0)
322Host Range = { 80.82.78.2 - 80.82.78.2 }
323
324
325
326N M A P P O R T S C A N
327============================
328
329
330Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-19 18:20 UTC
331Nmap scan report for nonudefree.com (80.82.78.2)
332Host is up (0.082s latency).
333PORT STATE SERVICE VERSION
33421/tcp open ftp vsftpd 2.2.2
33522/tcp open ssh OpenSSH 5.3 (protocol 2.0)
33623/tcp closed telnet
33725/tcp closed smtp
33880/tcp open http nginx
339110/tcp closed pop3
340143/tcp closed imap
341443/tcp closed https
342445/tcp closed microsoft-ds
3433389/tcp closed ms-wbt-server
344Service Info: OS: Unix
345
346Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
347Nmap done: 1 IP address (1 host up) scanned in 7.23 seconds
348
349
350
351S U B - D O M A I N F I N D E R
352==================================
353
354
355[i] Total Subdomains Found : 2
356
357[+] Subdomain: nonudefree.com
358[-] IP: 80.82.78.2
359
360[+] Subdomain: mx.nonudefree.com
361[-] IP: 80.82.78.2
362nonudefree.com
363
364
365 Domain Name: NONUDEFREE.COM
366 Registry Domain ID: 1650464161_DOMAIN_COM-VRSN
367 Registrar WHOIS Server: whois.godaddy.com
368 Registrar URL: http://www.godaddy.com
369 Updated Date: 2017-04-09T16:26:46Z
370 Creation Date: 2011-04-12T09:44:40Z
371 Registry Expiry Date: 2018-04-12T09:44:40Z
372 Registrar: GoDaddy.com, LLC
373 Registrar IANA ID: 146
374 Registrar Abuse Contact Email: abuse@godaddy.com
375 Registrar Abuse Contact Phone: 480-624-2505
376 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
377 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
378 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
379 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
380 Name Server: NS1.DYNACLOUDNS.COM
381 Name Server: NS2.DYNACLOUDNS.COM
382
383Domain Name: NONUDEFREE.COM
384Registrar URL: http://www.godaddy.com
385Registrant Name: denis safimov
386Registrant Organization:
387Name Server: NS1.DYNACLOUDNS.COM
388Name Server: NS2.DYNACLOUDNS.COM
389DNSSEC: unsigned
390
391
392
393; <<>> DiG 9.10.3-P4-Debian <<>> nonudefree.com any
394;; global options: +cmd
395;; Got answer:
396;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6893
397;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
398
399;; OPT PSEUDOSECTION:
400; EDNS: version: 0, flags:; udp: 4096
401;; QUESTION SECTION:
402;nonudefree.com. IN ANY
403
404;; ANSWER SECTION:
405nonudefree.com. 10582 IN NS ns1.dynacloudns.com.
406
407;; Query time: 8 msec
408;; SERVER: 192.168.1.254#53(192.168.1.254)
409;; WHEN: Tue Sep 19 14:20:17 EDT 2017
410;; MSG SIZE rcvd: 73
411
412
413
414Running:
415 traceroute -T -O info -i eth0 nonudefree.com
416traceroute to nonudefree.com (80.82.78.2), 30 hops max, 60 byte packets
417 1 gateway (192.168.1.254) 0.604 ms 0.931 ms 1.101 ms
418 2 10.135.18.1 (10.135.18.1) 7.233 ms 12.143 ms 17.194 ms
419 3 75.154.223.222 (75.154.223.222) 30.205 ms 30.263 ms 30.333 ms
420 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.680 ms 30.883 ms 31.214 ms
421 5 ae-240-3616.edge6.Amsterdam1.Level3.net (4.69.162.254) 104.725 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 105.098 ms ae-240-3616.edge6.Amsterdam1.Level3.net (4.69.162.254) 105.292 ms
422 6 * * *
423 7 80.82.78.2 (80.82.78.2) <syn,ack> 103.771 ms 104.124 ms 103.933 ms
424
425----- nonudefree.com -----
426
427
428Host's addresses:
429__________________
430
431nonudefree.com. 10798 IN A 80.82.78.2
432
433
434Name Servers:
435______________
436
437ns1.dynacloudns.com. 10800 IN A 80.82.78.2
438
439
440Mail (MX) Servers:
441___________________
442
443mx.nonudefree.com. 10800 IN A 80.82.78.2
444
445
446mx.nonudefree.com
447IP address #1: 80.82.78.2
448
449ns1.nonudefree.com
450IP address #1: 80.82.78.2
451
452ns2.nonudefree.com
453IP address #1: 80.82.78.2
454
455www.nonudefree.com
456IP address #1: 80.82.78.2
457
458[+] 4 (sub)domains and 4 IP address(es) found
459[+] completion time: 156 second(s)
460
461Detected Plugins:
462[ Google-Analytics ]
463 This plugin identifies the Google Analytics account.
464
465 Account : UA-22390726-4
466 Website : http://www.google.com/analytics/
467
468[ HTTPServer ]
469 HTTP server header string. This plugin also attempts to
470 identify the operating system from the server header.
471
472 String : nginx (from server string)
473
474[ Meta-Author ]
475 This plugin retrieves the author name from the meta name
476 tag - info:
477 http://www.webmarketingnow.com/tips/meta-tags-uncovered.html
478 #author
479
480 String : www.nonudefree.com Free NN Materials, Inc.
481
482[ Script ]
483 This plugin detects instances of script HTML elements and
484
485HTTP Headers:
486 HTTP/1.1 200 OK
487 Server: nginx
488 Date: Tue, 19 Sep 2017 18:15:32 GMT
489 Content-Type: text/html; charset=UTF-8
490 Transfer-Encoding: chunked
491 Connection: close
492 Content-Encoding: gzip
493
494
495
496
497[+] Hosts found in search engines:
498------------------------------------
499[-] Resolving hostnames IPs...
50080.82.78.2:Www.nonudefree.com
50180.82.78.2:mx.nonudefree.com
50280.82.78.2:ns1.nonudefree.com
50380.82.78.2:www.nonudefree.com
504
505
506
507 ^ ^
508 _ __ _ ____ _ __ _ _ ____
509 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
510 | V V // o // _/ | V V // 0 // 0 // _/
511 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
512 <
513 ...'
514
515 WAFW00F - Web Application Firewall Detection Tool
516
517 By Sandro Gauci && Wendel G. Henrique
518
519Checking http://nonudefree.com
520Generic Detection results:
521No WAF detected by the generic detection
522Number of requests: 13
523
524
525DNS Servers for nonudefree.com:
526 ns1.dynacloudns.com
527
528Trying zone transfer first...
529 Testing ns1.dynacloudns.com
530 Request timed out or transfer not allowed.
531
532Unsuccessful in zone transfer (it was worth a shot)
533Okay, trying the good old fashioned way... brute force
534
535Checking for wildcard DNS...
536Nope. Good.
537Now performing 2280 test(s)...
53880.82.78.2 mx.nonudefree.com
53980.82.78.2 ns1.nonudefree.com
54080.82.78.2 ns2.nonudefree.com
54180.82.78.2 www.nonudefree.com
542
543Subnets found (may want to probe here using nmap or unicornscan):
544 80.82.78.0-255 : 4 hostnames found.
545
546Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 14:31 EDT
547NSE: Loaded 146 scripts for scanning.
548NSE: Script Pre-scanning.
549Initiating NSE at 14:31
550Completed NSE at 14:31, 0.00s elapsed
551Initiating NSE at 14:31
552Completed NSE at 14:31, 0.00s elapsed
553Failed to resolve "nonudefree.com.txt".
554Initiating Parallel DNS resolution of 1 host. at 14:31
555Completed Parallel DNS resolution of 1 host. at 14:31, 0.63s elapsed
556Initiating SYN Stealth Scan at 14:31
557Scanning nonudefree.com (80.82.78.2) [100 ports]
558Discovered open port 53/tcp on 80.82.78.2
559Discovered open port 21/tcp on 80.82.78.2
560Discovered open port 22/tcp on 80.82.78.2
561Discovered open port 80/tcp on 80.82.78.2
562Increasing send delay for 80.82.78.2 from 0 to 5 due to 63 out of 157 dropped probes since last increase.
563Completed SYN Stealth Scan at 14:31, 3.05s elapsed (100 total ports)
564Initiating Service scan at 14:31
565Scanning 4 services on nonudefree.com (80.82.78.2)
566Completed Service scan at 14:31, 6.25s elapsed (4 services on 1 host)
567Initiating OS detection (try #1) against nonudefree.com (80.82.78.2)
568Initiating Traceroute at 14:31
569Completed Traceroute at 14:31, 3.02s elapsed
570Initiating Parallel DNS resolution of 7 hosts. at 14:31
571Completed Parallel DNS resolution of 7 hosts. at 14:31, 5.61s elapsed
572NSE: Script scanning 80.82.78.2.
573Initiating NSE at 14:31
574Completed NSE at 14:31, 12.99s elapsed
575Initiating NSE at 14:31
576Completed NSE at 14:31, 0.00s elapsed
577Nmap scan report for nonudefree.com (80.82.78.2)
578Host is up (0.13s latency).
579Not shown: 90 closed ports
580PORT STATE SERVICE VERSION
58121/tcp open ftp vsftpd 2.2.2
58222/tcp open ssh OpenSSH 5.3 (protocol 2.0)
583| ssh-hostkey:
584| 1024 68:1b:d0:3a:82:e8:7f:ec:ec:7b:77:1c:1b:00:d2:8b (DSA)
585|_ 2048 c1:c8:b9:2b:20:db:9d:fc:3e:40:56:a6:06:32:98:89 (RSA)
58625/tcp filtered smtp
58753/tcp open domain
58880/tcp open http nginx
589|_http-favicon: Unknown favicon MD5: FEB39A6DD992A95DCBADA31E7229B67C
590| http-methods:
591| Supported Methods: GET HEAD POST OPTIONS TRACE
592|_ Potentially risky methods: TRACE
593|_http-server-header: nginx
594|_http-title: Nonude Free Child Models Galleries
595135/tcp filtered msrpc
596139/tcp filtered netbios-ssn
597445/tcp filtered microsoft-ds
598465/tcp filtered smtps
599587/tcp filtered submission
600Device type: general purpose
601Running: Linux 2.6.X
602OS CPE: cpe:/o:linux:linux_kernel:2.6.39
603OS details: Linux 2.6.39
604Uptime guess: 9.245 days (since Sun Sep 10 08:38:57 2017)
605Network Distance: 11 hops
606TCP Sequence Prediction: Difficulty=255 (Good luck!)
607IP ID Sequence Generation: All zeros
608Service Info: OS: Unix
609
610TRACEROUTE (using port 143/tcp)
611HOP RTT ADDRESS
6121 109.37 ms 10.13.0.1
6132 ...
6143 109.97 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
6154 ...
6165 118.64 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
6176 118.65 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
6187 ...
6198 185.15 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
6209 120.40 ms 176.10.83.119
62110 ...
62211 120.50 ms 80.82.78.2
623
624
625#######################################################################################################################################
626Hostname www.itinyteens.com ISP DataWeb Global Group B.V. (AS39572)
627Continent North America Flag
628US
629Country United States Country Code US (USA)
630Region VA Local time 19 Sep 2017 14:34 EDT
631Metropolis* Washington Postal Code 20147
632City Ashburn Latitude 39.018
633IP Address 213.174.151.25 Longitude -77.539
634#######################################################################################################################################
635
636whois itinyteens.com
637 Domain Name: ITINYTEENS.COM
638 Registry Domain ID: 1642115735_DOMAIN_COM-VRSN
639 Registrar WHOIS Server: whois.evonames.com
640 Registrar URL: http://www.danesconames.com
641 Updated Date: 2017-01-04T12:21:06Z
642 Creation Date: 2011-02-25T13:38:15Z
643 Registry Expiry Date: 2018-02-25T13:38:15Z
644 Registrar: Danesco Trading Ltd.
645 Registrar IANA ID: 1418
646 Registrar Abuse Contact Email:
647 Registrar Abuse Contact Phone:
648 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
649 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
650 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
651 Name Server: NS5.PUBLIC-NS.COM
652 Name Server: NS6.PUBLIC-NS.COM
653
654
655Domain Name: ITINYTEENS.COM
656Registry Domain ID: 1642115735_DOMAIN_COM-VRSN
657Registrar WHOIS Server: whois.evonames.com
658Registrar URL: https://evonames.com/
659Updated Date: 2017-03-17 19:51:10.132701
660Creation Date: 2011-02-25
661Registrar Registration Expiration Date: 2018-02-25
662Registrar: DANESCO TRADING LTD
663Registrar IANA ID: 1418
664Registrar Abuse Contact Email: abuse@evonames.com
665Registrar Abuse Contact Phone: +357.95713635
666Reseller: AHnames.com https://www.AHnames.com/
667Domain Status: clientUpdateProhibited
668Domain Status: clientDeleteProhibited
669Domain Status: clientTransferProhibited
670Registry Registrant ID: MR_2382655WP
671Registrant Name: WhoisProtectService.net
672Registrant Organization: PROTECTSERVICE, LTD.
673Registrant Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
674Registrant City: Limassol
675Registrant State/Province:
676Registrant Postal Code: 3025
677Registrant Country: Cyprus
678Registrant Phone: +357.95713635
679Registrant Phone Ext:
680Registrant Fax:
681Registrant Fax Ext:
682Registrant Email: itinyteens.com@whoisprotectservice.net
683Registry Admin ID: MR_2382655WP
684Admin Name: WhoisProtectService.net
685Admin Organization: PROTECTSERVICE, LTD.
686Admin Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
687Admin City: Limassol
688Admin State/Province:
689Admin Postal Code: 3025
690Admin Country: Cyprus
691Admin Phone: +357.95713635
692Admin Phone Ext:
693Admin Fax:
694Admin Fax Ext:
695Admin Email: itinyteens.com@whoisprotectservice.net
696Registry Tech ID: MR_2382655WP
697Tech Name: WhoisProtectService.net
698Tech Organization: PROTECTSERVICE, LTD.
699Tech Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
700Tech City: Limassol
701Tech State/Province:
702Tech Postal Code: 3025
703Tech Country: Cyprus
704Tech Phone: +357.95713635
705Tech Phone Ext:
706Tech Fax:
707Tech Fax Ext:
708Tech Email: itinyteens.com@whoisprotectservice.net
709Registry Billing ID: MR_2382655WP
710Billing Name: WhoisProtectService.net
711Billing Organization: PROTECTSERVICE, LTD.
712Billing Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
713Billing City: Limassol
714Billing State/Province:
715Billing Postal Code: 3025
716Billing Country: Cyprus
717Billing Phone: +357.95713635
718Billing Phone Ext:
719Billing Fax:
720Billing Fax Ext:
721Billing Email: itinyteens.com@whoisprotectservice.net
722Name Server: NS5.PUBLIC-NS.COM
723Name Server: NS6.PUBLIC-NS.COM
724DNSSEC: unsigned
725URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
726>>> Last update of WHOIS database: 2017-08-19 15:25:36 <<<
727
728Abuse email: abuse@ahnames.com
729
730#################################################################################################################################
731
732dig itinyteens.com any
733
734; <<>> DiG 9.10.3-P4-Debian <<>> itinyteens.com any
735;; global options: +cmd
736;; Got answer:
737;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31281
738;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
739
740;; OPT PSEUDOSECTION:
741; EDNS: version: 0, flags:; udp: 4096
742;; QUESTION SECTION:
743;itinyteens.com. IN ANY
744
745;; ANSWER SECTION:
746itinyteens.com. 1172 IN MX 20 mail2.itinyteens.com.
747itinyteens.com. 1172 IN MX 10 mail.itinyteens.com.
748itinyteens.com. 1171 IN A 213.174.151.25
749itinyteens.com. 1000 IN NS ns5.public-ns.com.
750itinyteens.com. 1000 IN NS ns6.public-ns.com.
751
752;; Query time: 10 msec
753;; SERVER: 192.168.1.254#53(192.168.1.254)
754;; WHEN: Tue Sep 19 14:36:48 EDT 2017
755;; MSG SIZE rcvd: 148
756
757
758#################################################################################################################################
759
760tcptraceroute -i eth0 itinyteens.com
761
762Running:
763 traceroute -T -O info -i eth0 itinyteens.com
764traceroute to itinyteens.com (213.174.151.25), 30 hops max, 60 byte packets
765 1 gateway (192.168.1.254) 0.468 ms 0.767 ms 0.983 ms
766 2 10.135.18.1 (10.135.18.1) 8.901 ms 10.561 ms 11.049 ms
767 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 30.084 ms 30.164 ms 30.225 ms
768 4 * * *
769 5 * * *
770 6 * * *
771 7 * * *
772 8 * * *
773 9 213.174.151.25 (213.174.151.25) <syn,ack> 48.299 ms 56.353 ms 36.118 ms
774
775#################################################################################################################################
776
777cd /pentest/enumeration/lbd
778./lbd.sh itinyteens.com
779./Recon.sh: ligne 65 : cd: /pentest/enumeration/lbd: Aucun fichier ou dossier de ce type
780
781lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
782 Written by Stefan Behte (http://ge.mine.nu)
783 Proof-of-concept! Might give false positives.
784
785Checking for DNS-Loadbalancing: NOT FOUND
786Checking for HTTP-Loadbalancing [Server]:
787 Apache/2.2.25 (Unix) PHP/5.4.43
788 NOT FOUND
789
790Checking for HTTP-Loadbalancing [Date]: 18:37:49, 18:37:50, 18:37:52, 18:37:54, 18:37:57, 18:38:05, 18:38:12, 18:38:14, 18:38:16, 18:38:20, 18:38:23, 18:38:24, 18:38:25, 18:38:26, 18:38:27, 18:38:28, 18:38:29, 18:38:29, 18:38:30, 18:38:31, 18:38:34, 18:38:36, 18:38:41, 18:38:45, 18:38:48, 18:38:50, 18:38:51, 18:38:52, 18:38:55, 18:39:01, 18:39:04, 18:39:12, 18:39:21, 18:39:24, 18:39:26, 18:39:30, 18:39:33, 18:39:34, 18:39:37, 18:39:39, 18:39:42, 18:39:48, 18:40:03, 18:40:04, 18:40:04, 18:40:06, 18:40:13, 18:40:17, 18:40:22, 18:40:30, NOT FOUND
791
792#################################################################################################################################
793
794nmap -PN -n -F -T4 -sV -A -oG temp.txt itinyteens.com
795
796Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 14:43 EDT
797Nmap scan report for itinyteens.com (213.174.151.25)
798Host is up (0.20s latency).
799Not shown: 97 filtered ports
800PORT STATE SERVICE VERSION
80121/tcp open ftp OpenBSD ftpd
802| ftp-syst:
803| STAT:
804| DS2187 FTP server status:
805| Version: <suppressed>
806| Connected to 87.98.166.29
807| Waiting for user name
808| TYPE: ASCII, FORM: Nonprint; STRUcture: File; transfer MODE: Stream
809| No data connection
810| Traffic sent: 262 bytes in 0 transfers
811| Traffic received: 12 bytes in 0 transfers
812| Total traffic: 274 bytes in 0 transfers
813|_End of status
81422/tcp open ssh OpenSSH 5.8p2_hpn13v11 (FreeBSD 20110503; protocol 2.0)
815| ssh-hostkey:
816| 1024 a1:cb:bd:f0:bb:fe:ce:fb:94:de:c0:98:28:f9:bd:47 (DSA)
817|_ 2048 8b:e4:9d:12:00:6f:7a:ab:b6:86:f5:f1:e7:15:ff:14 (RSA)
81880/tcp open http Apache httpd 2.2.25 ((Unix) PHP/5.4.43)
819|_http-server-header: Apache/2.2.25 (Unix) PHP/5.4.43
820|_http-title: Did not follow redirect to http://www.itinyteens.com/
821Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
822Aggressive OS guesses: FreeBSD 9.3-RELEASE (94%), FreeBSD 9.0-RELEASE (94%), FreeBSD 9.0-RELEASE - 10.3-RELEASE (94%), FreeBSD 9.1-RELEASE or 10.1-RELEASE (92%), FreeBSD 10.1-RELEASE (91%), FreeBSD 7.0-RELEASE (91%), FreeBSD 7.1-PRERELEASE 7.2-STABLE (91%), FreeBSD 7.2-RELEASE - 8.0-RELEASE (91%), FreeBSD 8.1-RELEASE (91%), FreeBSD 8.2-RELEASE (91%)
823No exact OS matches for host (test conditions non-ideal).
824Network Distance: 11 hops
825Service Info: Host: DS2187; OS: FreeBSD; CPE: cpe:/o:freebsd:freebsd
826
827TRACEROUTE (using port 21/tcp)
828HOP RTT ADDRESS
8291 110.02 ms 10.13.0.1
8302 ...
8313 110.67 ms 178.33.103.231
8324 111.98 ms 10.95.33.10
8335 114.00 ms 213.251.128.65
8346 ... 10
83511 219.91 ms 213.174.151.25
836
837OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
838Nmap done: 1 IP address (1 host up) scanned in 49.51 seconds
839
840#################################################################################################################################
841
842amap -i temp.txt
843amap v5.4 (www.thc.org/thc-amap) started at 2017-09-19 14:43:51 - APPLICATION MAPPING mode
844
845Protocol on 213.174.151.25:21/tcp matches ftp
846Protocol on 213.174.151.25:22/tcp matches ssh
847Protocol on 213.174.151.25:22/tcp matches ssh-openssh
848Protocol on 213.174.151.25:80/tcp matches http
849Protocol on 213.174.151.25:80/tcp matches http-apache-2
850
851Unidentified ports: none.
852
853amap v5.4 finished at 2017-09-19 14:43:59
854
855######################################################################################################################################
856
857inetnum: 213.174.151.0 - 213.174.151.255
858netname: ADVANCEDHOSTERS-NET
859descr: Advanced Hosters B.V.
860country: US
861admin-c: AH36-RIPE
862tech-c: AH36-RIPE
863status: ASSIGNED PA
864remarks: INFRA-AW
865remarks: Send abuse reports to abuse@advancedhosters.com
866mnt-by: ADVANCEDHOSTERS-MNT
867mnt-lower: ADVANCEDHOSTERS-MNT
868mnt-routes: ADVANCEDHOSTERS-MNT
869created: 2011-07-11T07:43:18Z
870last-modified: 2015-03-31T08:16:14Z
871source: RIPE
872
873role: Advanced Hosters B.V.
874address: Ganzenstraat 1
875address: 3815 JA, Amersfoort, Nederland
876org: ORG-AH11-RIPE
877abuse-mailbox: abuse@advancedhosters.com
878nic-hdl: AH36-RIPE
879mnt-by: ADVANCEDHOSTERS-MNT
880created: 2009-03-31T09:52:43Z
881last-modified: 2015-03-19T12:49:43Z
882source: RIPE # Filtered
883
884% Information related to '213.174.128.0/19AS39572'
885
886route: 213.174.128.0/19
887descr: Hosting segment
888origin: AS39572
889mnt-by: ADVANCEDHOSTERS-MNT
890created: 2008-05-05T11:18:22Z
891last-modified: 2009-04-03T12:27:49Z
892source: RIPE
893
894% This query was served by the RIPE Database Query Service version 1.89.2 (WAGYU)
895
896
897#################################################################################################################################
898[i] Scanning Site: http://itinyteens.com
899
900
901
902B A S I C I N F O
903====================
904
905
906[+] Site Title: Tiny Teens - Nude Skinny Teens with Small Tits and Tight Young Pussies
907[+] IP address: 213.174.151.25
908[+] Web Server: Apache/2.2.25 (Unix) PHP/5.4.43
909[+] CMS: Could Not Detect
910[+] Cloudflare: Not Detected
911[+] Robots File: Could NOT Find robots.txt!
912
913
914
915
916W H O I S L O O K U P
917========================
918
919 Domain Name: ITINYTEENS.COM
920 Registry Domain ID: 1642115735_DOMAIN_COM-VRSN
921 Registrar WHOIS Server: whois.evonames.com
922 Registrar URL: http://www.danesconames.com
923 Updated Date: 2017-01-04T12:21:06Z
924 Creation Date: 2011-02-25T13:38:15Z
925 Registry Expiry Date: 2018-02-25T13:38:15Z
926 Registrar: Danesco Trading Ltd.
927 Registrar IANA ID: 1418
928 Registrar Abuse Contact Email:
929 Registrar Abuse Contact Phone:
930 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
931 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
932 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
933 Name Server: NS5.PUBLIC-NS.COM
934 Name Server: NS6.PUBLIC-NS.COM
935
936
937
938
939
940G E O I P L O O K U P
941=========================
942
943[i] IP Address: 213.174.151.25
944[i] Country: US
945[i] State: Virginia
946[i] City: Ashburn
947[i] Latitude: 39.018002
948[i] Longitude: -77.539001
949
950
951
952
953H T T P H E A D E R S
954=======================
955
956
957[i] HTTP/1.1 301 Moved Permanently
958[i] Date: Tue, 19 Sep 2017 18:37:37 GMT
959[i] Server: Apache/2.2.25 (Unix) PHP/5.4.43
960[i] Location: http://www.itinyteens.com/
961[i] Vary: Accept-Encoding
962[i] Content-Length: 363
963[i] Connection: close
964[i] Content-Type: text/html; charset=iso-8859-1
965[i] X-Pad: avoid browser bug
966[i] HTTP/1.1 200 OK
967[i] Date: Tue, 19 Sep 2017 18:37:38 GMT
968[i] Server: Apache/2.2.25 (Unix) PHP/5.4.43
969[i] X-Powered-By: PHP/5.4.43
970[i] Vary: Accept-Encoding
971[i] Connection: close
972[i] Content-Type: text/html
973
974
975
976
977D N S L O O K U P
978===================
979
980itinyteens.com. 1191 IN A 213.174.151.25
981itinyteens.com. 1200 IN NS ns6.public-ns.com.
982itinyteens.com. 1200 IN NS ns5.public-ns.com.
983itinyteens.com. 1200 IN SOA ns6.public-ns.com. admin.itinyteens.com. 1399048204 21600 3600 691200 38400
984itinyteens.com. 1200 IN MX 10 mail.itinyteens.com.
985itinyteens.com. 1200 IN MX 20 mail2.itinyteens.com.
986
987
988
989
990S U B N E T C A L C U L A T I O N
991====================================
992
993Address = 213.174.151.25
994Network = 213.174.151.25 / 32
995Netmask = 255.255.255.255
996Broadcast = not needed on Point-to-Point links
997Wildcard Mask = 0.0.0.0
998Hosts Bits = 0
999Max. Hosts = 1 (2^0 - 0)
1000Host Range = { 213.174.151.25 - 213.174.151.25 }
1001
1002
1003
1004N M A P P O R T S C A N
1005============================
1006
1007
1008Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-19 18:37 UTC
1009Nmap scan report for itinyteens.com (213.174.151.25)
1010Host is up (0.017s latency).
1011PORT STATE SERVICE VERSION
101221/tcp open ftp OpenBSD ftpd
101322/tcp open ssh OpenSSH 5.8p2_hpn13v11 (FreeBSD 20110503; protocol 2.0)
101423/tcp filtered telnet
101525/tcp filtered smtp
101680/tcp open http Apache httpd 2.2.25 ((Unix) PHP/5.4.43)
1017110/tcp filtered pop3
1018143/tcp filtered imap
1019443/tcp filtered https
1020445/tcp filtered microsoft-ds
10213389/tcp filtered ms-wbt-server
1022Service Info: Host: DS2187; OS: FreeBSD; CPE: cpe:/o:freebsd:freebsd
1023
1024Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1025Nmap done: 1 IP address (1 host up) scanned in 8.37 seconds
1026
1027
1028
1029S U B - D O M A I N F I N D E R
1030==================================
1031
1032
1033[i] Total Subdomains Found : 4
1034
1035[+] Subdomain: itinyteens.com
1036[-] IP: 213.174.151.25
1037
1038[+] Subdomain: mail2.itinyteens.com
1039[-] IP: 88.208.36.36
1040
1041[+] Subdomain: mail.itinyteens.com
1042[-] IP: 213.174.151.151
1043
1044[+] Subdomain: www.itinyteens.com
1045[-] IP: 213.174.151.25
1046
1047
1048
1049
1050
1051R E V E R S E I P L O O K U P
1052==================================
1053
1054
1055[i] Total Sites Found On This Server : 0
1056itinyteens.com
1057
1058
1059 Domain Name: ITINYTEENS.COM
1060 Registry Domain ID: 1642115735_DOMAIN_COM-VRSN
1061 Registrar WHOIS Server: whois.evonames.com
1062 Registrar URL: http://www.danesconames.com
1063 Updated Date: 2017-01-04T12:21:06Z
1064 Creation Date: 2011-02-25T13:38:15Z
1065 Registry Expiry Date: 2018-02-25T13:38:15Z
1066 Registrar: Danesco Trading Ltd.
1067 Registrar IANA ID: 1418
1068 Registrar Abuse Contact Email:
1069 Registrar Abuse Contact Phone:
1070 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
1071 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
1072 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
1073 Name Server: NS5.PUBLIC-NS.COM
1074 Name Server: NS6.PUBLIC-NS.COM
1075
1076
1077Domain Name: ITINYTEENS.COM
1078Registry Domain ID: 1642115735_DOMAIN_COM-VRSN
1079Registrar WHOIS Server: whois.evonames.com
1080Registrar URL: https://evonames.com/
1081Updated Date: 2017-03-17 19:51:10.132701
1082Creation Date: 2011-02-25
1083Registrar Registration Expiration Date: 2018-02-25
1084Registrar: DANESCO TRADING LTD
1085Registrar IANA ID: 1418
1086Registrar Abuse Contact Email: abuse@evonames.com
1087Registrar Abuse Contact Phone: +357.95713635
1088Reseller: AHnames.com https://www.AHnames.com/
1089Domain Status: clientUpdateProhibited
1090Domain Status: clientDeleteProhibited
1091Domain Status: clientTransferProhibited
1092Registry Registrant ID: MR_2382655WP
1093Registrant Name: WhoisProtectService.net
1094Registrant Organization: PROTECTSERVICE, LTD.
1095Registrant Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1096Registrant City: Limassol
1097Registrant State/Province:
1098Registrant Postal Code: 3025
1099Registrant Country: Cyprus
1100Registrant Phone: +357.95713635
1101Registrant Phone Ext:
1102Registrant Fax:
1103Registrant Fax Ext:
1104Registrant Email: itinyteens.com@whoisprotectservice.net
1105Registry Admin ID: MR_2382655WP
1106Admin Name: WhoisProtectService.net
1107Admin Organization: PROTECTSERVICE, LTD.
1108Admin Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1109Admin City: Limassol
1110Admin State/Province:
1111Admin Postal Code: 3025
1112Admin Country: Cyprus
1113Admin Phone: +357.95713635
1114Admin Phone Ext:
1115Admin Fax:
1116Admin Fax Ext:
1117Admin Email: itinyteens.com@whoisprotectservice.net
1118Registry Tech ID: MR_2382655WP
1119Tech Name: WhoisProtectService.net
1120Tech Organization: PROTECTSERVICE, LTD.
1121Tech Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1122Tech City: Limassol
1123Tech State/Province:
1124Tech Postal Code: 3025
1125Tech Country: Cyprus
1126Tech Phone: +357.95713635
1127Tech Phone Ext:
1128Tech Fax:
1129Tech Fax Ext:
1130Tech Email: itinyteens.com@whoisprotectservice.net
1131Registry Billing ID: MR_2382655WP
1132Billing Name: WhoisProtectService.net
1133Billing Organization: PROTECTSERVICE, LTD.
1134Billing Street: Agios Fylaxeos 66 and Chr. Perevou 2, Kalia Court, off. 601
1135Billing City: Limassol
1136Billing State/Province:
1137Billing Postal Code: 3025
1138Billing Country: Cyprus
1139Billing Phone: +357.95713635
1140Billing Phone Ext:
1141Billing Fax:
1142Billing Fax Ext:
1143Billing Email: itinyteens.com@whoisprotectservice.net
1144Name Server: NS5.PUBLIC-NS.COM
1145Name Server: NS6.PUBLIC-NS.COM
1146DNSSEC: unsigned
1147URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
1148>>> Last update of WHOIS database: 2017-08-19 15:25:36 <<<
1149
1150Abuse email: abuse@ahnames.com
1151
1152
1153
1154
1155; <<>> DiG 9.10.3-P4-Debian <<>> itinyteens.com any
1156;; global options: +cmd
1157;; Got answer:
1158;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 18863
1159;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
1160
1161;; OPT PSEUDOSECTION:
1162; EDNS: version: 0, flags:; udp: 4096
1163;; QUESTION SECTION:
1164;itinyteens.com. IN ANY
1165
1166;; ANSWER SECTION:
1167itinyteens.com. 1035 IN NS ns5.public-ns.com.
1168itinyteens.com. 1035 IN NS ns6.public-ns.com.
1169
1170;; Query time: 9 msec
1171;; SERVER: 192.168.1.254#53(192.168.1.254)
1172;; WHEN: Tue Sep 19 14:36:13 EDT 2017
1173;; MSG SIZE rcvd: 89
1174
1175 traceroute -T -O info -i eth0 itinyteens.com
1176traceroute to itinyteens.com (213.174.151.25), 30 hops max, 60 byte packets
1177 1 gateway (192.168.1.254) 0.449 ms 0.612 ms 0.761 ms
1178 2 10.135.18.1 (10.135.18.1) 13.905 ms 17.817 ms 18.506 ms
1179 3 NYCMNYCIZR01.bb.telus.com (75.154.223.248) 30.302 ms 30.379 ms 30.432 ms
1180 4 * * *
1181 5 * * *
1182 6 * * *
1183 7 * * *
1184 8 * * *
1185 9 213.174.151.25 (213.174.151.25) <syn,ack> 45.417 ms 71.652 ms 35.412 ms
1186
1187
1188----- itinyteens.com -----
1189
1190
1191Host's addresses:
1192__________________
1193
1194itinyteens.com. 1199 IN A 213.174.151.25
1195
1196
1197Name Servers:
1198______________
1199
1200ns5.public-ns.com. 1200 IN A 213.174.157.35
1201ns6.public-ns.com. 1200 IN A 88.208.29.10
1202
1203
1204Mail (MX) Servers:
1205___________________
1206
1207mail.itinyteens.com. 1200 IN A 213.174.151.151
1208mail2.itinyteens.com. 1200 IN A 88.208.36.36
1209
1210mail.itinyteens.com
1211IP address #1: 213.174.151.151
1212
1213www.itinyteens.com
1214IP address #1: 213.174.151.25
1215
1216[+] 2 (sub)domains and 2 IP address(es) found
1217[+] completion time: 92 second(s)
1218
1219
1220Tracing to itinyteens.com[a] via 192.168.1.254, maximum of 3 retries
1221192.168.1.254 (192.168.1.254) Got answer
1222
1223
1224WhatWeb report for http://itinyteens.com
1225Status : 301 Moved Permanently
1226Title : 301 Moved Permanently
1227IP : 213.174.151.25
1228Country : NETHERLANDS, NL
1229
1230Summary : Email[[no address given]], HTTPServer[Unix][Apache/2.2.25 (Unix) PHP/5.4.43], RedirectLocation[http://www.itinyteens.com/], PHP[5.4.43], Apache[2.2.25]
1231
1232Detected Plugins:
1233[ Apache ]
1234 The Apache HTTP Server Project is an effort to develop and
1235 maintain an open-source HTTP server for modern operating
1236 systems including UNIX and Windows NT. The goal of this
1237 project is to provide a secure, efficient and extensible
1238 server that provides HTTP services in sync with the current
1239 HTTP standards.
1240
1241 Version : 2.2.25 (from HTTP Server Header)
1242 Google Dorks: (3)
1243 Website : http://httpd.apache.org/
1244
1245[ Email ]
1246 Extract email addresses. Find valid email address and
1247 syntactically invalid email addresses from mailto: link
1248 tags. We match syntactically invalid links containing
1249 mailto: to catch anti-spam email addresses, eg. bob at
1250 gmail.com. This uses the simplified email regular
1251 expression from
1252 http://www.regular-expressions.info/email.html for valid
1253 email address matching.
1254
1255 String : [no address given]
1256
1257[ HTTPServer ]
1258 HTTP server header string. This plugin also attempts to
1259 identify the operating system from the server header.
1260
1261 OS : Unix
1262 String : Apache/2.2.25 (Unix) PHP/5.4.43 (from server string)
1263
1264[ PHP ]
1265 PHP is a widely-used general-purpose scripting language
1266 that is especially suited for Web development and can be
1267 embedded into HTML. This plugin identifies PHP errors,
1268 modules and versions and extracts the local file path and
1269 username if present.
1270
1271 Version : 5.4.43
1272 Google Dorks: (2)
1273 Website : http://www.php.net/
1274
1275[ RedirectLocation ]
1276 HTTP Server string location. used with http-status 301 and
1277 302
1278
1279 String : http://www.itinyteens.com/ (from location)
1280
1281HTTP Headers:
1282 HTTP/1.1 301 Moved Permanently
1283 Date: Tue, 19 Sep 2017 18:37:56 GMT
1284 Server: Apache/2.2.25 (Unix) PHP/5.4.43
1285 Location: http://www.itinyteens.com/
1286 Vary: Accept-Encoding
1287 Content-Encoding: gzip
1288 Content-Length: 276
1289 Connection: close
1290 Content-Type: text/html; charset=iso-8859-1
1291
1292WhatWeb report for http://www.itinyteens.com/
1293Status : 200 OK
1294Title : Tiny Teens - Nude Skinny Teens with Small Tits and Tight Young Pussies
1295IP : 213.174.151.25
1296Country : NETHERLANDS, NL
1297
1298Summary : HTML5, X-Powered-By[PHP/5.4.43], HTTPServer[Unix][Apache/2.2.25 (Unix) PHP/5.4.43], Google-Analytics[UA-22861151-41], PHP[5.4.43], Script[text/javascript], Apache[2.2.25], AddThis
1299
1300Detected Plugins:
1301[ AddThis ]
1302 AddThis is a free way to boost traffic back to your site by
1303 making it easier for visitors to share your content.
1304
1305 Website : http://www.addthis.com/
1306
1307[ Apache ]
1308 The Apache HTTP Server Project is an effort to develop and
1309 maintain an open-source HTTP server for modern operating
1310 systems including UNIX and Windows NT. The goal of this
1311 project is to provide a secure, efficient and extensible
1312 server that provides HTTP services in sync with the current
1313 HTTP standards.
1314
1315 Version : 2.2.25 (from HTTP Server Header)
1316 Google Dorks: (3)
1317 Website : http://httpd.apache.org/
1318
1319[ Google-Analytics ]
1320 This plugin identifies the Google Analytics account.
1321
1322 Account : UA-22861151-41
1323 Website : http://www.google.com/analytics/
1324
1325[ HTML5 ]
1326 HTML version 5, detected by the doctype declaration
1327
1328
1329[ HTTPServer ]
1330 HTTP server header string. This plugin also attempts to
1331 identify the operating system from the server header.
1332
1333 OS : Unix
1334 String : Apache/2.2.25 (Unix) PHP/5.4.43 (from server string)
1335
1336[ PHP ]
1337 PHP is a widely-used general-purpose scripting language
1338 that is especially suited for Web development and can be
1339 embedded into HTML. This plugin identifies PHP errors,
1340 modules and versions and extracts the local file path and
1341 username if present.
1342
1343 Version : 5.4.43
1344 Version : 5.4.43
1345 Google Dorks: (2)
1346 Website : http://www.php.net/
1347
1348[ Script ]
1349 This plugin detects instances of script HTML elements and
1350 returns the script language/type.
1351
1352 String : text/javascript
1353
1354[ X-Powered-By ]
1355 X-Powered-By HTTP header
1356
1357 String : PHP/5.4.43 (from x-powered-by string)
1358
1359HTTP Headers:
1360 HTTP/1.1 200 OK
1361 Date: Tue, 19 Sep 2017 18:38:02 GMT
1362 Server: Apache/2.2.25 (Unix) PHP/5.4.43
1363 X-Powered-By: PHP/5.4.43
1364 Vary: Accept-Encoding
1365 Content-Encoding: gzip
1366 Content-Length: 13880
1367 Connection: close
1368 Content-Type: text/html
1369
1370
1371[+] Hosts found in search engines:
1372------------------------------------
1373[-] Resolving hostnames IPs...
1374213.174.151.25:www.itinyteens.com
1375
1376
1377
1378 ^ ^
1379 _ __ _ ____ _ __ _ _ ____
1380 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
1381 | V V // o // _/ | V V // 0 // 0 // _/
1382 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
1383 <
1384 ...'
1385
1386 WAFW00F - Web Application Firewall Detection Tool
1387
1388 By Sandro Gauci && Wendel G. Henrique
1389
1390Checking http://itinyteens.com
1391Generic Detection results:
1392No WAF detected by the generic detection
1393Number of requests: 13
1394
1395
1396DNS Servers for itinyteens.com:
1397 ns5.public-ns.com
1398 ns6.public-ns.com
1399
1400Trying zone transfer first...
1401 Testing ns5.public-ns.com
1402 Request timed out or transfer not allowed.
1403 Testing ns6.public-ns.com
1404 Request timed out or transfer not allowed.
1405
1406Unsuccessful in zone transfer (it was worth a shot)
1407Okay, trying the good old fashioned way... brute force
1408
1409Checking for wildcard DNS...
1410Nope. Good.
1411Now performing 2280 test(s)...
1412213.174.151.151 mail.itinyteens.com
141388.208.36.36 mail2.itinyteens.com
1414213.174.151.25 www.itinyteens.com
1415
1416Subnets found (may want to probe here using nmap or unicornscan):
1417 213.174.151.0-255 : 2 hostnames found.
1418 88.208.36.0-255 : 1 hostnames found.
1419
1420
1421Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 15:28 EDT
1422NSE: Loaded 146 scripts for scanning.
1423NSE: Script Pre-scanning.
1424Initiating NSE at 15:28
1425Completed NSE at 15:28, 0.00s elapsed
1426Initiating NSE at 15:28
1427Completed NSE at 15:28, 0.00s elapsed
1428Failed to resolve "itinyteens.com.txt".
1429Initiating Parallel DNS resolution of 1 host. at 15:28
1430Completed Parallel DNS resolution of 1 host. at 15:28, 0.48s elapsed
1431Initiating SYN Stealth Scan at 15:28
1432Scanning itinyteens.com (213.174.151.25) [100 ports]
1433Discovered open port 21/tcp on 213.174.151.25
1434Discovered open port 22/tcp on 213.174.151.25
1435Discovered open port 80/tcp on 213.174.151.25
1436Completed SYN Stealth Scan at 15:28, 5.74s elapsed (100 total ports)
1437Initiating Service scan at 15:28
1438Scanning 3 services on itinyteens.com (213.174.151.25)
1439Completed Service scan at 15:28, 10.53s elapsed (3 services on 1 host)
1440Initiating OS detection (try #1) against itinyteens.com (213.174.151.25)
1441adjust_timeouts2: packet supposedly had rtt of -133782 microseconds. Ignoring time.
1442adjust_timeouts2: packet supposedly had rtt of -133782 microseconds. Ignoring time.
1443adjust_timeouts2: packet supposedly had rtt of -105767 microseconds. Ignoring time.
1444adjust_timeouts2: packet supposedly had rtt of -105767 microseconds. Ignoring time.
1445Retrying OS detection (try #2) against itinyteens.com (213.174.151.25)
1446Initiating Traceroute at 15:28
1447Completed Traceroute at 15:28, 3.01s elapsed
1448Initiating Parallel DNS resolution of 4 hosts. at 15:28
1449Completed Parallel DNS resolution of 4 hosts. at 15:29, 5.62s elapsed
1450NSE: Script scanning 213.174.151.25.
1451Initiating NSE at 15:29
1452Completed NSE at 15:29, 6.70s elapsed
1453Initiating NSE at 15:29
1454Completed NSE at 15:29, 0.00s elapsed
1455Nmap scan report for itinyteens.com (213.174.151.25)
1456Host is up (0.21s latency).
1457Not shown: 97 filtered ports
1458PORT STATE SERVICE VERSION
145921/tcp open ftp OpenBSD ftpd
1460| ftp-syst:
1461| STAT:
1462| DS2187 FTP server status:
1463| Version: <suppressed>
1464| Connected to 87.98.166.29
1465| Waiting for user name
1466| TYPE: ASCII, FORM: Nonprint; STRUcture: File; transfer MODE: Stream
1467| No data connection
1468| Traffic sent: 262 bytes in 0 transfers
1469| Traffic received: 12 bytes in 0 transfers
1470| Total traffic: 274 bytes in 0 transfers
1471|_End of status
147222/tcp open ssh OpenSSH 5.8p2_hpn13v11 (FreeBSD 20110503; protocol 2.0)
1473| ssh-hostkey:
1474| 1024 a1:cb:bd:f0:bb:fe:ce:fb:94:de:c0:98:28:f9:bd:47 (DSA)
1475|_ 2048 8b:e4:9d:12:00:6f:7a:ab:b6:86:f5:f1:e7:15:ff:14 (RSA)
147680/tcp open http Apache httpd 2.2.25 ((Unix) PHP/5.4.43)
1477| http-methods:
1478|_ Supported Methods: GET HEAD POST OPTIONS
1479|_http-server-header: Apache/2.2.25 (Unix) PHP/5.4.43
1480|_http-title: Did not follow redirect to http://www.itinyteens.com/
1481Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
1482Aggressive OS guesses: FreeBSD 9.3-RELEASE (94%), FreeBSD 9.0-RELEASE (94%), FreeBSD 9.0-RELEASE - 10.3-RELEASE (94%), FreeBSD 9.1-RELEASE or 10.1-RELEASE (94%), FreeBSD 7.0-RELEASE (91%), FreeBSD 7.1-PRERELEASE 7.2-STABLE (91%), FreeBSD 7.2-RELEASE - 8.0-RELEASE (91%), FreeBSD 8.1-RELEASE (91%), FreeBSD 8.2-RELEASE (91%), FreeBSD 10.1-RELEASE (89%)
1483No exact OS matches for host (test conditions non-ideal).
1484Uptime guess: 0.000 days (since Tue Sep 19 15:28:52 2017)
1485Network Distance: 11 hops
1486TCP Sequence Prediction: Difficulty=258 (Good luck!)
1487IP ID Sequence Generation: Busy server or unknown class
1488Service Info: Host: DS2187; OS: FreeBSD; CPE: cpe:/o:freebsd:freebsd
1489
1490TRACEROUTE (using port 21/tcp)
1491HOP RTT ADDRESS
14921 110.14 ms 10.13.0.1
14932 ...
14943 110.18 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
14954 ...
14965 113.40 ms be100-1111.ldn-5-a9.uk.eu (213.251.128.65)
14976 ... 10
149811 235.90 ms 213.174.151.25
1499
1500NSE: Script Post-scanning.
1501Initiating NSE at 15:29
1502Completed NSE at 15:29, 0.00s elapsed
1503Initiating NSE at 15:29
1504Completed NSE at 15:29, 0.00s elapsed
1505Read data files from: /usr/bin/../share/nmap
1506OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1507Nmap done: 1 IP address (1 host up) scanned in 40.34 seconds
1508 Raw packets sent: 309 (17.518KB) | Rcvd: 39 (2.722KB)
1509
1510######################################################################################################################################
1511Hostname candydoll3.tinyjewels.net ISP Quasi Networks LTD. (AS29073)
1512Continent Africa Flag
1513SC
1514Country Seychelles Country Code SC (SYC)
1515Region Unknown Local time 19 Sep 2017 23:31 +04
1516City Unknown Latitude -4.583
1517IP Address 93.174.93.40 Longitude 55.667
1518######################################################################################################################################
1519
1520
1521; <<>> DiG 9.10.3-P4-Debian <<>> candydoll3.tinyjewels.net any
1522;; global options: +cmd
1523;; Got answer:
1524;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 47860
1525;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
1526
1527;; OPT PSEUDOSECTION:
1528; EDNS: version: 0, flags:; udp: 4096
1529;; QUESTION SECTION:
1530;candydoll3.tinyjewels.net. IN ANY
1531
1532;; ANSWER SECTION:
1533candydoll3.tinyjewels.net. 86226 IN A 93.174.93.40
1534
1535;; Query time: 8 msec
1536;; SERVER: 192.168.1.254#53(192.168.1.254)
1537;; WHEN: Tue Sep 19 15:33:57 EDT 2017
1538;; MSG SIZE rcvd: 70
1539
1540#################################################################################################################################
1541
1542tcptraceroute -i eth0 candydoll3.tinyjewels.net
1543
1544Running:
1545 traceroute -T -O info -i eth0 candydoll3.tinyjewels.net
1546traceroute to candydoll3.tinyjewels.net (93.174.93.40), 30 hops max, 60 byte packets
1547 1 gateway (192.168.1.254) 0.426 ms 0.595 ms 0.760 ms
1548 2 10.135.18.1 (10.135.18.1) 14.402 ms 14.948 ms 15.449 ms
1549 3 75.154.223.222 (75.154.223.222) 29.870 ms 29.807 ms 29.936 ms
1550 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.377 ms 30.538 ms 30.896 ms
1551 5 ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.319 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 104.764 ms ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.910 ms
1552 6 * * *
1553 7 93.174.93.40 (93.174.93.40) <syn,ack> 103.865 ms 103.894 ms 103.681 ms
1554
1555#################################################################################################################################
1556
1557cd /pentest/enumeration/lbd
1558./lbd.sh candydoll3.tinyjewels.net
1559./Recon.sh: ligne 65 : cd: /pentest/enumeration/lbd: Aucun fichier ou dossier de ce type
1560
1561lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
1562 Written by Stefan Behte (http://ge.mine.nu)
1563 Proof-of-concept! Might give false positives.
1564
1565Checking for DNS-Loadbalancing: NOT FOUND
1566Checking for HTTP-Loadbalancing [Server]:
1567 nginx/1.0.15
1568 NOT FOUND
1569
1570Checking for HTTP-Loadbalancing [Date]: 18:11:13, 18:11:13, 18:11:13, 18:11:13, 18:11:14, 18:11:14, 18:11:14, 18:11:15, 18:11:15, 18:11:15, 18:11:16, 18:11:16, 18:11:16, 18:11:16, 18:11:17, 18:11:17, 18:11:17, 18:11:18, 18:11:18, 18:11:18, 18:11:18, 18:11:19, 18:11:19, 18:11:19, 18:11:20, 18:11:20, 18:11:20, 18:11:21, 18:11:21, 18:11:21, 18:11:21, 18:11:22, 18:11:22, 18:11:22, 18:11:23, 18:11:23, 18:11:23, 18:11:23, 18:11:24, 18:11:24, 18:11:24, 18:11:25, 18:11:25, 18:11:25, 18:11:25, 18:11:26, 18:11:26, 18:11:26, 18:11:27, 18:11:27, NOT FOUND
1571
1572#################################################################################################################################
1573
1574nmap -PN -n -F -T4 -sV -A -oG temp.txt candydoll3.tinyjewels.net
1575
1576Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 15:34 EDT
1577Nmap scan report for candydoll3.tinyjewels.net (93.174.93.40)
1578Host is up (0.14s latency).
1579Not shown: 92 closed ports
1580PORT STATE SERVICE VERSION
158122/tcp open ssh OpenSSH 5.3 (protocol 2.0)
1582| ssh-hostkey:
1583| 1024 9f:2f:13:4e:dd:22:bd:06:cf:83:c4:46:69:40:0c:71 (DSA)
1584|_ 2048 c6:97:3d:68:af:14:9e:c0:1a:9c:a4:f6:75:32:ae:6f (RSA)
158525/tcp filtered smtp
158680/tcp open http nginx 1.0.15
1587|_http-server-header: nginx/1.0.15
1588|_http-title: Candydolls Issue #3 :: Nonude Preteen Models
1589135/tcp filtered msrpc
1590139/tcp filtered netbios-ssn
1591445/tcp filtered microsoft-ds
1592465/tcp filtered smtps
1593587/tcp filtered submission
1594Aggressive OS guesses: Linux 2.6.32 (92%), Linux 3.10 (92%), Linux 3.4 (92%), Linux 4.2 (92%), Synology DiskStation Manager 5.1 (92%), Linux 3.1 - 3.2 (91%), Linux 2.6.32 or 3.10 (90%), Linux 2.6.35 (90%), Linux 2.6.39 (90%), Linux 3.10 - 3.12 (90%)
1595No exact OS matches for host (test conditions non-ideal).
1596Network Distance: 11 hops
1597
1598TRACEROUTE (using port 1720/tcp)
1599HOP RTT ADDRESS
16001 110.40 ms 10.13.0.1
16012 ...
16023 110.43 ms 178.33.103.231
16034 ...
16045 119.53 ms 91.121.131.19
16056 119.52 ms 94.23.122.217
16067 ...
16078 219.82 ms 176.10.83.128
16089 219.81 ms 176.10.83.5
160910 ...
161011 120.68 ms 93.174.93.40
1611
1612OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1613Nmap done: 1 IP address (1 host up) scanned in 27.38 seconds
1614
1615#################################################################################################################################
1616
1617amap -i temp.txt
1618amap v5.4 (www.thc.org/thc-amap) started at 2017-09-19 15:35:10 - APPLICATION MAPPING mode
1619
1620Protocol on 93.174.93.40:80/tcp matches http
1621Protocol on 93.174.93.40:22/tcp matches ssh
1622Protocol on 93.174.93.40:22/tcp matches ssh-openssh
1623Protocol on 93.174.93.40:80/tcp matches http-apache-2
1624
1625Unidentified ports: none.
1626
1627amap v5.4 finished at 2017-09-19 15:35:16
1628
1629#################################################################################################################################
1630
1631inetnum: 93.174.93.0 - 93.174.93.255
1632netname: SC-QUASI55
1633descr: QUASI
1634country: SC
1635org: ORG-QNL3-RIPE
1636admin-c: QNL1-RIPE
1637tech-c: QNL1-RIPE
1638status: ASSIGNED PA
1639mnt-by: QUASINETWORKS-MNT
1640mnt-lower: QUASINETWORKS-MNT
1641mnt-routes: QUASINETWORKS-MNT
1642created: 2008-06-29T21:36:16Z
1643last-modified: 2016-01-23T22:23:14Z
1644source: RIPE
1645
1646organisation: ORG-QNL3-RIPE
1647org-name: Quasi Networks LTD.
1648org-type: OTHER
1649address: Suite 1, Second Floor
1650address: Sound & Vision House, Francis Rachel Street
1651address: Victoria, Mahe, SEYCHELLES
1652remarks: *****************************************************************************
1653remarks: IMPORTANT INFORMATION
1654remarks: *****************************************************************************
1655remarks: We are a high bandwidth network provider offering bandwidth solutions.
1656remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
1657remarks: Please only use abuse@quasinetworks.com for abuse reports.
1658remarks: For all other requests, please see the details on our website.
1659remarks: *****************************************************************************
1660abuse-mailbox: abuse@quasinetworks.com
1661abuse-c: AR34302-RIPE
1662mnt-ref: QUASINETWORKS-MNT
1663mnt-by: QUASINETWORKS-MNT
1664created: 2015-11-08T22:25:26Z
1665last-modified: 2015-11-27T09:37:50Z
1666source: RIPE # Filtered
1667
1668role: Quasi Networks LTD
1669address: Suite 1, Second Floor
1670address: Sound & Vision House, Francis Rachel Street
1671address: Victoria, Mahe, SEYCHELLES
1672remarks: *****************************************************************************
1673remarks: IMPORTANT INFORMATION
1674remarks: *****************************************************************************
1675remarks: We are a high bandwidth network provider offering bandwidth solutions.
1676remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
1677remarks: Please only use abuse@quasinetworks.com for abuse reports.
1678remarks: For all other requests, please see the details on our website.
1679remarks: *****************************************************************************
1680abuse-mailbox: abuse@quasinetworks.com
1681nic-hdl: QNL1-RIPE
1682mnt-by: QUASINETWORKS-MNT
1683created: 2015-11-07T22:43:04Z
1684last-modified: 2015-11-07T23:04:49Z
1685source: RIPE # Filtered
1686
1687% Information related to '93.174.88.0/21as29073'
1688
1689route: 93.174.88.0/21
1690descr: Quasi Networks LTD (IBC)
1691origin: as29073
1692mnt-by: QUASINETWORKS-MNT
1693created: 2008-06-20T15:33:47Z
1694last-modified: 2016-01-23T22:26:12Z
1695source: RIPE
1696
1697% This query was served by the RIPE Database Query Service version 1.89.2 (ANGUS)
1698
1699#################################################################################################################################
1700i] Scanning Site: http://candydoll3.tinyjewels.net
1701
1702
1703
1704B A S I C I N F O
1705====================
1706
1707
1708[+] Site Title: Candydolls Issue #3 :: Nonude Preteen Models
1709[+] IP address: 93.174.93.40
1710[+] Web Server: nginx/1.0.15
1711[+] CMS: Could Not Detect
1712[+] Cloudflare: Not Detected
1713[+] Robots File: Could NOT Find robots.txt!
1714
1715
1716
1717G E O I P L O O K U P
1718=========================
1719
1720[i] IP Address: 93.174.93.40
1721[i] Country: SC
1722[i] State: N/A
1723[i] City: N/A
1724[i] Latitude: -4.583300
1725[i] Longitude: 55.666698
1726
1727
1728
1729
1730H T T P H E A D E R S
1731=======================
1732
1733
1734[i] HTTP/1.1 200 OK
1735[i] Server: nginx/1.0.15
1736[i] Date: Tue, 19 Sep 2017 18:10:59 GMT
1737[i] Content-Type: text/html; charset=UTF-8
1738[i] Connection: close
1739[i] X-Powered-By: PHP/5.5.9-1ubuntu4.14
1740[i] Vary: Accept-Encoding
1741[i] Content-Length: 2688
1742
1743
1744
1745
1746D N S L O O K U P
1747===================
1748
1749candydoll3.tinyjewels.net. 86393 IN A 93.174.93.40
1750
1751
1752
1753
1754S U B N E T C A L C U L A T I O N
1755====================================
1756
1757Address = 93.174.93.40
1758Network = 93.174.93.40 / 32
1759Netmask = 255.255.255.255
1760Broadcast = not needed on Point-to-Point links
1761Wildcard Mask = 0.0.0.0
1762Hosts Bits = 0
1763Max. Hosts = 1 (2^0 - 0)
1764Host Range = { 93.174.93.40 - 93.174.93.40 }
1765
1766
1767
1768N M A P P O R T S C A N
1769============================
1770
1771
1772Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-19 19:34 UTC
1773Nmap scan report for candydoll3.tinyjewels.net (93.174.93.40)
1774Host is up (0.084s latency).
1775PORT STATE SERVICE VERSION
177621/tcp closed ftp
177722/tcp open ssh OpenSSH 5.3 (protocol 2.0)
177823/tcp closed telnet
177925/tcp closed smtp
178080/tcp open http nginx 1.0.15
1781110/tcp closed pop3
1782143/tcp closed imap
1783443/tcp closed https
1784445/tcp closed microsoft-ds
17853389/tcp closed ms-wbt-server
1786
1787Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
1788Nmap done: 1 IP address (1 host up) scanned in 7.22 seconds
1789
1790
1791
1792S U B - D O M A I N F I N D E R
1793==================================
1794
1795
1796[i] Total Subdomains Found : 1
1797
1798[+] Subdomain: candydoll3.tinyjewels.net
1799[-] IP: 93.174.93.40
1800
1801
1802
1803
1804; <<>> DiG 9.10.3-P4-Debian <<>> candydoll3.tinyjewels.net any
1805;; global options: +cmd
1806;; Got answer:
1807;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 23300
1808;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
1809
1810;; OPT PSEUDOSECTION:
1811; EDNS: version: 0, flags:; udp: 4096
1812;; QUESTION SECTION:
1813;candydoll3.tinyjewels.net. IN ANY
1814
1815;; ANSWER SECTION:
1816candydoll3.tinyjewels.net. 86268 IN A 93.174.93.40
1817
1818;; Query time: 9 msec
1819;; SERVER: 192.168.1.254#53(192.168.1.254)
1820;; WHEN: Tue Sep 19 15:33:15 EDT 2017
1821;; MSG SIZE rcvd: 70
1822
1823
1824 traceroute -T -O info -i eth0 candydoll3.tinyjewels.net
1825traceroute to candydoll3.tinyjewels.net (93.174.93.40), 30 hops max, 60 byte packets
1826 1 gateway (192.168.1.254) 0.478 ms 0.668 ms 0.835 ms
1827 2 10.135.18.1 (10.135.18.1) 6.887 ms 7.352 ms 7.852 ms
1828 3 75.154.223.222 (75.154.223.222) 29.391 ms 30.074 ms 29.909 ms
1829 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 31.365 ms 31.432 ms 31.496 ms
1830 5 ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 104.602 ms ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.789 ms 104.845 ms
1831 6 * * *
1832 7 93.174.93.40 (93.174.93.40) <syn,ack> 103.907 ms 103.763 ms 104.005 ms
1833
1834----- candydoll3.tinyjewels.net -----
1835
1836
1837Host's addresses:
1838__________________
1839
1840candydoll3.tinyjewels.net. 86262 IN A 93.174.93.40
1841
1842
1843Wildcard detection using: fbaokmjvuilw
1844_______________________________________
1845
1846fbaokmjvuilw.candydoll3.tinyjewels.net. 86400 IN A 93.174.93.40
1847
1848
1849
1850dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
1851
1852[+] warning: domain might use wildcards. 93.174.93.40 will be ignored from results
1853[+] searching (sub)domains for candydoll3.tinyjewels.net using built-in wordlist
1854[+] using maximum random delay of 10 millisecond(s) between requests
1855
1856[+] 0 (sub)domains and 0 IP address(es) found
1857[+] completion time: 281 second(s)
1858
1859
1860Tracing to candydoll3.tinyjewels.net[a] via 192.168.1.254, maximum of 3 retries
1861192.168.1.254 (192.168.1.254) Got answer
1862
1863
1864WhatWeb report for http://candydoll3.tinyjewels.net
1865Status : 200 OK
1866Title : Candydolls Issue #3 :: Nonude Preteen Models
1867IP : 93.174.93.40
1868Country : NETHERLANDS, NL
1869
1870Summary : X-Powered-By[PHP/5.5.9-1ubuntu4.14], HTTPServer[nginx/1.0.15], Google-Analytics[UA-38217984-1], PHP[5.5.9-1ubuntu4.14], nginx[1.0.15], Script[JavaScript,text/javascript]
1871
1872Detected Plugins:
1873[ Google-Analytics ]
1874 This plugin identifies the Google Analytics account.
1875
1876 Account : UA-38217984-1
1877 Website : http://www.google.com/analytics/
1878
1879[ HTTPServer ]
1880 HTTP server header string. This plugin also attempts to
1881 identify the operating system from the server header.
1882
1883 String : nginx/1.0.15 (from server string)
1884
1885[ PHP ]
1886 PHP is a widely-used general-purpose scripting language
1887 that is especially suited for Web development and can be
1888 embedded into HTML. This plugin identifies PHP errors,
1889 modules and versions and extracts the local file path and
1890 username if present.
1891
1892 Version : 5.5.9-1ubuntu4.14
1893 Google Dorks: (2)
1894 Website : http://www.php.net/
1895
1896[ Script ]
1897 This plugin detects instances of script HTML elements and
1898 returns the script language/type.
1899
1900 String : JavaScript,text/javascript
1901
1902[ X-Powered-By ]
1903 X-Powered-By HTTP header
1904
1905 String : PHP/5.5.9-1ubuntu4.14 (from x-powered-by string)
1906
1907[ nginx ]
1908 Nginx (Engine-X) is a free, open-source, high-performance
1909 HTTP server and reverse proxy, as well as an IMAP/POP3
1910 proxy server.
1911
1912 Version : 1.0.15
1913 Website : http://nginx.net/
1914
1915HTTP Headers:
1916 HTTP/1.1 200 OK
1917 Server: nginx/1.0.15
1918 Date: Tue, 19 Sep 2017 18:15:01 GMT
1919 Content-Type: text/html; charset=UTF-8
1920 Connection: close
1921 X-Powered-By: PHP/5.5.9-1ubuntu4.14
1922 Vary: Accept-Encoding
1923 Content-Encoding: gzip
1924 Content-Length: 1382
1925
1926
1927 ^ ^
1928 _ __ _ ____ _ __ _ _ ____
1929 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
1930 | V V // o // _/ | V V // 0 // 0 // _/
1931 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
1932 <
1933 ...'
1934
1935 WAFW00F - Web Application Firewall Detection Tool
1936
1937 By Sandro Gauci && Wendel G. Henrique
1938
1939Checking http://candydoll3.tinyjewels.net
1940Generic Detection results:
1941No WAF detected by the generic detection
1942Number of requests: 13
1943
1944
1945
1946Trying zone transfer first...
1947
1948Unsuccessful in zone transfer (it was worth a shot)
1949Okay, trying the good old fashioned way... brute force
1950
1951Checking for wildcard DNS...
1952 ** Found 94915067286.candydoll3.tinyjewels.net at 93.174.93.40.
1953 ** High probability of wildcard DNS.
1954Now performing 2280 test(s)...
1955
1956Subnets found (may want to probe here using nmap or unicornscan):
1957
1958Done with Fierce scan: http://ha.ckers.org/fierce/
1959Found 0 entries.
1960
1961Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 15:38 EDT
1962NSE: Loaded 146 scripts for scanning.
1963NSE: Script Pre-scanning.
1964Initiating NSE at 15:38
1965Completed NSE at 15:38, 0.00s elapsed
1966Initiating NSE at 15:38
1967Completed NSE at 15:38, 0.00s elapsed
1968Failed to resolve "candydoll3.tinyjewels.net.txt".
1969Initiating Parallel DNS resolution of 1 host. at 15:38
1970Completed Parallel DNS resolution of 1 host. at 15:38, 0.69s elapsed
1971Initiating SYN Stealth Scan at 15:38
1972Scanning candydoll3.tinyjewels.net (93.174.93.40) [100 ports]
1973Discovered open port 22/tcp on 93.174.93.40
1974Discovered open port 80/tcp on 93.174.93.40
1975Increasing send delay for 93.174.93.40 from 0 to 5 due to 63 out of 157 dropped probes since last increase.
1976Completed SYN Stealth Scan at 15:38, 3.11s elapsed (100 total ports)
1977Initiating Service scan at 15:38
1978Scanning 2 services on candydoll3.tinyjewels.net (93.174.93.40)
1979Completed Service scan at 15:38, 6.28s elapsed (2 services on 1 host)
1980Initiating OS detection (try #1) against candydoll3.tinyjewels.net (93.174.93.40)
1981Retrying OS detection (try #2) against candydoll3.tinyjewels.net (93.174.93.40)
1982adjust_timeouts2: packet supposedly had rtt of -180618 microseconds. Ignoring time.
1983adjust_timeouts2: packet supposedly had rtt of -180618 microseconds. Ignoring time.
1984Initiating Traceroute at 15:38
1985Completed Traceroute at 15:38, 3.01s elapsed
1986Initiating Parallel DNS resolution of 7 hosts. at 15:38
1987Completed Parallel DNS resolution of 7 hosts. at 15:38, 5.51s elapsed
1988NSE: Script scanning 93.174.93.40.
1989Initiating NSE at 15:38
1990Completed NSE at 15:39, 8.40s elapsed
1991Initiating NSE at 15:39
1992Completed NSE at 15:39, 0.00s elapsed
1993Nmap scan report for candydoll3.tinyjewels.net (93.174.93.40)
1994Host is up (0.14s latency).
1995Not shown: 92 closed ports
1996PORT STATE SERVICE VERSION
199722/tcp open ssh OpenSSH 5.3 (protocol 2.0)
1998| ssh-hostkey:
1999| 1024 9f:2f:13:4e:dd:22:bd:06:cf:83:c4:46:69:40:0c:71 (DSA)
2000|_ 2048 c6:97:3d:68:af:14:9e:c0:1a:9c:a4:f6:75:32:ae:6f (RSA)
200125/tcp filtered smtp
200280/tcp open http nginx 1.0.15
2003| http-methods:
2004|_ Supported Methods: GET HEAD POST OPTIONS
2005|_http-server-header: nginx/1.0.15
2006|_http-title: Candydolls Issue #3 :: Nonude Preteen Models
2007135/tcp filtered msrpc
2008139/tcp filtered netbios-ssn
2009445/tcp filtered microsoft-ds
2010465/tcp filtered smtps
2011587/tcp filtered submission
2012Aggressive OS guesses: Linux 2.6.32 (92%), Linux 3.10 (92%), Linux 3.4 (92%), Linux 4.2 (92%), Synology DiskStation Manager 5.1 (92%), Linux 3.1 - 3.2 (91%), Linux 2.6.32 or 3.10 (90%), Linux 2.6.35 (90%), Linux 3.5 (90%), Linux 4.4 (90%)
2013No exact OS matches for host (test conditions non-ideal).
2014Uptime guess: 31.992 days (since Fri Aug 18 15:50:37 2017)
2015Network Distance: 11 hops
2016TCP Sequence Prediction: Difficulty=266 (Good luck!)
2017IP ID Sequence Generation: All zeros
2018
2019TRACEROUTE (using port 110/tcp)
2020HOP RTT ADDRESS
20211 110.44 ms 10.13.0.1
20222 ...
20233 110.48 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
20244 ...
20255 119.18 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
20266 118.73 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
20277 ...
20288 219.81 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
20299 219.80 ms 176.10.83.5
203010 ...
203111 120.29 ms 93.174.93.40
2032
2033NSE: Script Post-scanning.
2034Initiating NSE at 15:39
2035Completed NSE at 15:39, 0.00s elapsed
2036Initiating NSE at 15:39
2037Completed NSE at 15:39, 0.00s elapsed
2038Read data files from: /usr/bin/../share/nmap
2039OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2040Nmap done: 1 IP address (1 host up) scanned in 34.51 seconds
2041 Raw packets sent: 310 (17.964KB) | Rcvd: 214 (22.379KB)
2042#######################################################################################################################################
2043Hostname missalli.swittydolls.com ISP Quasi Networks LTD. (AS29073)
2044Continent Africa Flag
2045SC
2046Country Seychelles Country Code SC (SYC)
2047Region Unknown Local time 19 Sep 2017 23:53 +04
2048City Unknown Latitude -4.583
2049IP Address 93.174.93.40 Longitude 55.667
2050######################################################################################################################################
2051
2052dig missalli.swittydolls.com any
2053
2054; <<>> DiG 9.10.3-P4-Debian <<>> missalli.swittydolls.com any
2055;; global options: +cmd
2056;; Got answer:
2057;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4093
2058;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
2059
2060;; OPT PSEUDOSECTION:
2061; EDNS: version: 0, flags:; udp: 4096
2062;; QUESTION SECTION:
2063;missalli.swittydolls.com. IN ANY
2064
2065;; ANSWER SECTION:
2066missalli.swittydolls.com. 57783 IN A 93.174.93.40
2067
2068;; Query time: 8 msec
2069;; SERVER: 192.168.1.254#53(192.168.1.254)
2070;; WHEN: Tue Sep 19 15:56:40 EDT 2017
2071;; MSG SIZE rcvd: 69
2072
2073#################################################################################################################################
2074
2075host -l missalli.swittydolls.com
2076
2077;; Connection to 192.168.1.254#53(192.168.1.254) for missalli.swittydolls.com failed: connection refused.
2078Host missalli.swittydolls.com not found: 9(NOTAUTH)
2079; Transfer failed.
2080
2081#################################################################################################################################
2082
2083tcptraceroute -i eth0 missalli.swittydolls.com
2084
2085Running:
2086 traceroute -T -O info -i eth0 missalli.swittydolls.com
2087traceroute to missalli.swittydolls.com (93.174.93.40), 30 hops max, 60 byte packets
2088 1 gateway (192.168.1.254) 0.440 ms 0.674 ms 0.860 ms
2089 2 10.135.18.1 (10.135.18.1) 13.013 ms 17.189 ms 18.900 ms
2090 3 75.154.223.222 (75.154.223.222) 29.482 ms 29.937 ms 30.134 ms
2091 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.532 ms 30.719 ms 31.061 ms
2092 5 ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.706 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 104.790 ms 104.846 ms
2093 6 * * *
2094 7 93.174.93.40 (93.174.93.40) <syn,ack> 103.921 ms 103.879 ms 103.822 ms
2095
2096#################################################################################################################################
2097
2098Checking for HTTP-Loadbalancing [Date]: 18:34:02, 18:34:02, 18:34:02, 18:34:03, 18:34:03, 18:34:04, 18:34:04, 18:34:05, 18:34:05, 18:34:05, 18:34:06, 18:34:06, 18:34:06, 18:34:07, 18:34:07, 18:34:07, 18:34:07, 18:34:08, 18:34:08, 18:34:08, 18:34:09, 18:34:09, 18:34:09, 18:34:10, 18:34:10, 18:34:10, 18:34:11, 18:34:11, 18:34:11, 18:34:11, 18:34:12, 18:34:12, 18:34:12, 18:34:13, 18:34:13, 18:34:13, 18:34:14, 18:34:14, 18:34:14, 18:34:15, 18:34:15, 18:34:15, 18:34:15, 18:34:16, 18:34:16, 18:34:16, 18:34:17, 18:34:17, 18:34:17, 18:34:18, NOT FOUND
2099
2100Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2101
2102missalli.swittydolls.com does NOT use Load-balancing.
2103
2104#################################################################################################################################
2105
2106nmap -PN -n -F -T4 -sV -A -oG temp.txt missalli.swittydolls.com
2107
2108Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 15:57 EDT
2109Nmap scan report for missalli.swittydolls.com (93.174.93.40)
2110Host is up (0.13s latency).
2111Not shown: 92 closed ports
2112PORT STATE SERVICE VERSION
211322/tcp open ssh OpenSSH 5.3 (protocol 2.0)
2114| ssh-hostkey:
2115| 1024 9f:2f:13:4e:dd:22:bd:06:cf:83:c4:46:69:40:0c:71 (DSA)
2116|_ 2048 c6:97:3d:68:af:14:9e:c0:1a:9c:a4:f6:75:32:ae:6f (RSA)
211725/tcp filtered smtp
211880/tcp open http nginx 1.0.15
2119|_http-server-header: nginx/1.0.15
2120|_http-title: Miss Alli :: Preteen Model
2121135/tcp filtered msrpc
2122139/tcp filtered netbios-ssn
2123445/tcp filtered microsoft-ds
2124465/tcp filtered smtps
2125587/tcp filtered submission
2126Aggressive OS guesses: Synology DiskStation Manager 5.1 (91%), Linux 2.6.32 (90%), Linux 2.6.32 or 3.10 (90%), Linux 2.6.37 (90%), Tandberg VCS video conferencing system (90%), Linux 3.18 (89%), DD-WRT v24-sp2 (Linux 2.4.36) (89%), Linux 2.6.32 - 2.6.35 (89%), Linux 2.6.35 (89%), Linux 2.6.39 (89%)
2127No exact OS matches for host (test conditions non-ideal).
2128Network Distance: 11 hops
2129
2130TRACEROUTE (using port 3306/tcp)
2131HOP RTT ADDRESS
21321 110.49 ms 10.13.0.1
21332 117.07 ms 37.187.24.252
21343 110.51 ms 178.33.103.231
21354 ...
21365 220.02 ms 91.121.131.19
21376 119.06 ms 94.23.122.217
21387 ...
21398 220.06 ms 176.10.83.128
21409 220.06 ms 176.10.83.5
214110 ...
214211 120.42 ms 93.174.93.40
2143
2144OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2145Nmap done: 1 IP address (1 host up) scanned in 27.47 seconds
2146
2147#################################################################################################################################
2148
2149amap -i temp.txt
2150amap v5.4 (www.thc.org/thc-amap) started at 2017-09-19 15:58:03 - APPLICATION MAPPING mode
2151
2152Protocol on 93.174.93.40:22/tcp matches ssh
2153Protocol on 93.174.93.40:22/tcp matches ssh-openssh
2154Protocol on 93.174.93.40:80/tcp matches http
2155Protocol on 93.174.93.40:80/tcp matches http-apache-2
2156
2157Unidentified ports: none.
2158
2159amap v5.4 finished at 2017-09-19 15:58:09
2160
2161#################################################################################################################################
2162
2163
2164inetnum: 93.174.93.0 - 93.174.93.255
2165netname: SC-QUASI55
2166descr: QUASI
2167country: SC
2168org: ORG-QNL3-RIPE
2169admin-c: QNL1-RIPE
2170tech-c: QNL1-RIPE
2171status: ASSIGNED PA
2172mnt-by: QUASINETWORKS-MNT
2173mnt-lower: QUASINETWORKS-MNT
2174mnt-routes: QUASINETWORKS-MNT
2175created: 2008-06-29T21:36:16Z
2176last-modified: 2016-01-23T22:23:14Z
2177source: RIPE
2178
2179organisation: ORG-QNL3-RIPE
2180org-name: Quasi Networks LTD.
2181org-type: OTHER
2182address: Suite 1, Second Floor
2183address: Sound & Vision House, Francis Rachel Street
2184address: Victoria, Mahe, SEYCHELLES
2185remarks: *****************************************************************************
2186remarks: IMPORTANT INFORMATION
2187remarks: *****************************************************************************
2188remarks: We are a high bandwidth network provider offering bandwidth solutions.
2189remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
2190remarks: Please only use abuse@quasinetworks.com for abuse reports.
2191remarks: For all other requests, please see the details on our website.
2192remarks: *****************************************************************************
2193abuse-mailbox: abuse@quasinetworks.com
2194abuse-c: AR34302-RIPE
2195mnt-ref: QUASINETWORKS-MNT
2196mnt-by: QUASINETWORKS-MNT
2197created: 2015-11-08T22:25:26Z
2198last-modified: 2015-11-27T09:37:50Z
2199source: RIPE # Filtered
2200
2201role: Quasi Networks LTD
2202address: Suite 1, Second Floor
2203address: Sound & Vision House, Francis Rachel Street
2204address: Victoria, Mahe, SEYCHELLES
2205remarks: *****************************************************************************
2206remarks: IMPORTANT INFORMATION
2207remarks: *****************************************************************************
2208remarks: We are a high bandwidth network provider offering bandwidth solutions.
2209remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
2210remarks: Please only use abuse@quasinetworks.com for abuse reports.
2211remarks: For all other requests, please see the details on our website.
2212remarks: *****************************************************************************
2213abuse-mailbox: abuse@quasinetworks.com
2214nic-hdl: QNL1-RIPE
2215mnt-by: QUASINETWORKS-MNT
2216created: 2015-11-07T22:43:04Z
2217last-modified: 2015-11-07T23:04:49Z
2218source: RIPE # Filtered
2219
2220% Information related to '93.174.88.0/21as29073'
2221
2222route: 93.174.88.0/21
2223descr: Quasi Networks LTD (IBC)
2224origin: as29073
2225mnt-by: QUASINETWORKS-MNT
2226created: 2008-06-20T15:33:47Z
2227last-modified: 2016-01-23T22:26:12Z
2228source: RIPE
2229
2230% This query was served by the RIPE Database Query Service version 1.89.2 (HEREFORD)
2231
2232
2233#################################################################################################################################
2234[i] Scanning Site: http://93.174.93.40
2235
2236
2237
2238B A S I C I N F O
2239====================
2240
2241
2242[+] Site Title: 10 years NN Super Models - Top list 200
2243[+] IP address: 93.174.93.40
2244[+] Web Server: nginx/1.0.15
2245[+] CMS: Could Not Detect
2246[+] Cloudflare: Not Detected
2247[+] Robots File: Could NOT Find robots.txt!
2248
2249
2250
2251
2252inetnum: 93.174.93.0 - 93.174.93.255
2253netname: SC-QUASI55
2254descr: QUASI
2255country: SC
2256org: ORG-QNL3-RIPE
2257admin-c: QNL1-RIPE
2258tech-c: QNL1-RIPE
2259status: ASSIGNED PA
2260mnt-by: QUASINETWORKS-MNT
2261mnt-lower: QUASINETWORKS-MNT
2262mnt-routes: QUASINETWORKS-MNT
2263created: 2008-06-29T21:36:16Z
2264last-modified: 2016-01-23T22:23:14Z
2265source: RIPE
2266
2267organisation: ORG-QNL3-RIPE
2268org-name: Quasi Networks LTD.
2269org-type: OTHER
2270address: Suite 1, Second Floor
2271address: Sound & Vision House, Francis Rachel Street
2272address: Victoria, Mahe, SEYCHELLES
2273remarks: *****************************************************************************
2274remarks: IMPORTANT INFORMATION
2275remarks: *****************************************************************************
2276remarks: We are a high bandwidth network provider offering bandwidth solutions.
2277remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
2278remarks: Please only use abuse@quasinetworks.com for abuse reports.
2279remarks: For all other requests, please see the details on our website.
2280remarks: *****************************************************************************
2281abuse-mailbox: abuse@quasinetworks.com
2282abuse-c: AR34302-RIPE
2283mnt-ref: QUASINETWORKS-MNT
2284mnt-by: QUASINETWORKS-MNT
2285created: 2015-11-08T22:25:26Z
2286last-modified: 2015-11-27T09:37:50Z
2287source: RIPE # Filtered
2288
2289role: Quasi Networks LTD
2290address: Suite 1, Second Floor
2291address: Sound & Vision House, Francis Rachel Street
2292address: Victoria, Mahe, SEYCHELLES
2293remarks: *****************************************************************************
2294remarks: IMPORTANT INFORMATION
2295remarks: *****************************************************************************
2296remarks: We are a high bandwidth network provider offering bandwidth solutions.
2297remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
2298remarks: Please only use abuse@quasinetworks.com for abuse reports.
2299remarks: For all other requests, please see the details on our website.
2300remarks: *****************************************************************************
2301abuse-mailbox: abuse@quasinetworks.com
2302nic-hdl: QNL1-RIPE
2303mnt-by: QUASINETWORKS-MNT
2304created: 2015-11-07T22:43:04Z
2305last-modified: 2015-11-07T23:04:49Z
2306source: RIPE # Filtered
2307
2308% Information related to '93.174.88.0/21as29073'
2309
2310route: 93.174.88.0/21
2311descr: Quasi Networks LTD (IBC)
2312origin: as29073
2313mnt-by: QUASINETWORKS-MNT
2314created: 2008-06-20T15:33:47Z
2315last-modified: 2016-01-23T22:26:12Z
2316source: RIPE
2317
2318% This query was served by the RIPE Database Query Service version 1.89.2 (BLAARKOP)
2319
2320
2321
2322
2323
2324
2325G E O I P L O O K U P
2326=========================
2327
2328[i] IP Address: 93.174.93.40
2329[i] Country: SC
2330[i] State: N/A
2331[i] City: N/A
2332[i] Latitude: -4.583300
2333[i] Longitude: 55.666698
2334
2335
2336
2337
2338H T T P H E A D E R S
2339=======================
2340
2341
2342[i] HTTP/1.1 200 OK
2343[i] Server: nginx/1.0.15
2344[i] Date: Tue, 19 Sep 2017 18:33:41 GMT
2345[i] Content-Type: text/html; charset=UTF-8
2346[i] Connection: close
2347[i] X-Powered-By: PHP/5.5.9-1ubuntu4.14
2348[i] Vary: Accept-Encoding
2349
2350
2351
2352
2353D N S L O O K U P
2354===================
2355
2356no records found
2357
2358
2359
2360S U B N E T C A L C U L A T I O N
2361====================================
2362
2363Address = 93.174.93.40
2364Network = 93.174.93.40 / 32
2365Netmask = 255.255.255.255
2366Broadcast = not needed on Point-to-Point links
2367Wildcard Mask = 0.0.0.0
2368Hosts Bits = 0
2369Max. Hosts = 1 (2^0 - 0)
2370Host Range = { 93.174.93.40 - 93.174.93.40 }
2371
2372
2373
2374N M A P P O R T S C A N
2375============================
2376
2377
2378Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-19 19:56 UTC
2379Nmap scan report for 93.174.93.40
2380Host is up (0.082s latency).
2381PORT STATE SERVICE VERSION
238221/tcp closed ftp
238322/tcp open ssh OpenSSH 5.3 (protocol 2.0)
238423/tcp closed telnet
238525/tcp closed smtp
238680/tcp open http nginx 1.0.15
2387110/tcp closed pop3
2388143/tcp closed imap
2389443/tcp closed https
2390445/tcp closed microsoft-ds
23913389/tcp closed ms-wbt-server
2392
2393
2394
2395; <<>> DiG 9.10.3-P4-Debian <<>> missalli.swittydolls.com any
2396;; global options: +cmd
2397;; Got answer:
2398;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 51618
2399;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
2400
2401;; OPT PSEUDOSECTION:
2402; EDNS: version: 0, flags:; udp: 4096
2403;; QUESTION SECTION:
2404;missalli.swittydolls.com. IN ANY
2405
2406;; ANSWER SECTION:
2407missalli.swittydolls.com. 57706 IN A 93.174.93.40
2408
2409;; Query time: 8 msec
2410;; SERVER: 192.168.1.254#53(192.168.1.254)
2411;; WHEN: Tue Sep 19 15:57:57 EDT 2017
2412;; MSG SIZE rcvd: 69
2413
2414
2415
2416;; Connection to 192.168.1.254#53(192.168.1.254) for missalli.swittydolls.com failed: connection refused.
2417Host missalli.swittydolls.com not found: 9(NOTAUTH)
2418; Transfer failed.
2419
2420
2421Please type the name of your network interface Example: eth0
2422eth0
2423
2424Running:
2425 traceroute -T -O info -i eth0 missalli.swittydolls.com
2426traceroute to missalli.swittydolls.com (93.174.93.40), 30 hops max, 60 byte packets
2427 1 gateway (192.168.1.254) 0.558 ms 0.749 ms 0.922 ms
2428 2 10.135.18.1 (10.135.18.1) 10.418 ms 10.854 ms 11.880 ms
2429 3 75.154.223.222 (75.154.223.222) 30.409 ms 30.485 ms 30.554 ms
2430 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.681 ms 30.812 ms 31.279 ms
2431 5 ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.652 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 105.309 ms 105.461 ms
2432 6 * * *
2433 7 93.174.93.40 (93.174.93.40) <syn,ack> 103.884 ms 104.288 ms 104.108 ms
2434--
2435
2436
2437Host's addresses:
2438__________________
2439
2440missalli.swittydolls.com. 57698 IN A 93.174.93.40
2441
2442
2443Wildcard detection using: frrxuhpqkfxa
2444_______________________________________
2445
2446frrxuhpqkfxa.missalli.swittydolls.com. 86400 IN A 93.174.93.40
2447
2448
2449!!!!!!!!!!!!!!!!!!!!!!!!!!!!
2450
2451 Wildcards detected, all subdomains will point to the same IP address
2452 Omitting results containing 93.174.93.40.
2453 Maybe you are using OpenDNS servers.
2454
2455!!!!!!!!!!!!!!!!!!!!!!!!!!!!
2456
2457
2458Name Servers:
2459______________
2460
2461 missalli.swittydolls.com NS record query failed: NOERROR
2462
2463
2464dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
2465
2466[+] warning: domain might use wildcards. 93.174.93.40 will be ignored from results
2467[+] searching (sub)domains for missalli.swittydolls.com using built-in wordlist
2468[+] using maximum random delay of 10 millisecond(s) between requests
2469
2470[+] 0 (sub)domains and 0 IP address(es) found
2471[+] completion time: 289 second(s)
2472
2473
2474Tracing to missalli.swittydolls.com[a] via 192.168.1.254, maximum of 3 retries
2475192.168.1.254 (192.168.1.254) Got answer
2476
2477
2478WhatWeb report for http://missalli.swittydolls.com
2479Status : 200 OK
2480Title : Miss Alli :: Preteen Model
2481IP : 93.174.93.40
2482Country : NETHERLANDS, NL
2483
2484Summary : X-Powered-By[PHP/5.5.9-1ubuntu4.14], HTTPServer[nginx/1.0.15], Google-Analytics[UA-38217984-1], PHP[5.5.9-1ubuntu4.14], nginx[1.0.15], Script[JavaScript,text/javascript]
2485
2486Detected Plugins:
2487[ Google-Analytics ]
2488 This plugin identifies the Google Analytics account.
2489
2490 Account : UA-38217984-1
2491 Website : http://www.google.com/analytics/
2492
2493[ HTTPServer ]
2494 HTTP server header string. This plugin also attempts to
2495 identify the operating system from the server header.
2496
2497 String : nginx/1.0.15 (from server string)
2498
2499[ PHP ]
2500 PHP is a widely-used general-purpose scripting language
2501 that is especially suited for Web development and can be
2502 embedded into HTML. This plugin identifies PHP errors,
2503 modules and versions and extracts the local file path and
2504 username if present.
2505
2506 Version : 5.5.9-1ubuntu4.14
2507 Google Dorks: (2)
2508 Website : http://www.php.net/
2509
2510[ Script ]
2511 This plugin detects instances of script HTML elements and
2512 returns the script language/type.
2513
2514 String : JavaScript,text/javascript
2515
2516[ X-Powered-By ]
2517 X-Powered-By HTTP header
2518
2519 String : PHP/5.5.9-1ubuntu4.14 (from x-powered-by string)
2520
2521[ nginx ]
2522 Nginx (Engine-X) is a free, open-source, high-performance
2523 HTTP server and reverse proxy, as well as an IMAP/POP3
2524 proxy server.
2525
2526 Version : 1.0.15
2527 Website : http://nginx.net/
2528
2529HTTP Headers:
2530 HTTP/1.1 200 OK
2531 Server: nginx/1.0.15
2532 Date: Tue, 19 Sep 2017 18:39:53 GMT
2533 Content-Type: text/html; charset=UTF-8
2534 Connection: close
2535 X-Powered-By: PHP/5.5.9-1ubuntu4.14
2536 Vary: Accept-Encoding
2537 Content-Encoding: gzip
2538 Content-Length: 1519
2539
2540
2541 ^ ^
2542 _ __ _ ____ _ __ _ _ ____
2543 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
2544 | V V // o // _/ | V V // 0 // 0 // _/
2545 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
2546 <
2547 ...'
2548
2549 WAFW00F - Web Application Firewall Detection Tool
2550
2551 By Sandro Gauci && Wendel G. Henrique
2552
2553Checking http://missalli.swittydolls.com
2554Generic Detection results:
2555No WAF detected by the generic detection
2556Number of requests: 13
2557
2558
2559
2560Trying zone transfer first...
2561
2562Unsuccessful in zone transfer (it was worth a shot)
2563Okay, trying the good old fashioned way... brute force
2564
2565Checking for wildcard DNS...
2566 ** Found 98614442921.missalli.swittydolls.com at 93.174.93.40.
2567 ** High probability of wildcard DNS.
2568Now performing 2280 test(s)...
2569
2570Subnets found (may want to probe here using nmap or unicornscan):
2571
2572Done with Fierce scan: http://ha.ckers.org/fierce/
2573Found 0 entries.
2574
2575
2576
2577Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 16:03 EDT
2578NSE: Loaded 146 scripts for scanning.
2579NSE: Script Pre-scanning.
2580Initiating NSE at 16:03
2581Completed NSE at 16:03, 0.00s elapsed
2582Initiating NSE at 16:03
2583Completed NSE at 16:03, 0.00s elapsed
2584Failed to resolve "missalli.swittydolls.com.txt".
2585Initiating Parallel DNS resolution of 1 host. at 16:03
2586Completed Parallel DNS resolution of 1 host. at 16:03, 0.64s elapsed
2587Initiating SYN Stealth Scan at 16:03
2588Scanning missalli.swittydolls.com (93.174.93.40) [100 ports]
2589Discovered open port 80/tcp on 93.174.93.40
2590Discovered open port 22/tcp on 93.174.93.40
2591Completed SYN Stealth Scan at 16:03, 3.21s elapsed (100 total ports)
2592Initiating Service scan at 16:03
2593Scanning 2 services on missalli.swittydolls.com (93.174.93.40)
2594Completed Service scan at 16:03, 6.27s elapsed (2 services on 1 host)
2595Initiating OS detection (try #1) against missalli.swittydolls.com (93.174.93.40)
2596Retrying OS detection (try #2) against missalli.swittydolls.com (93.174.93.40)
2597Initiating Traceroute at 16:03
2598Completed Traceroute at 16:03, 3.02s elapsed
2599Initiating Parallel DNS resolution of 8 hosts. at 16:03
2600Completed Parallel DNS resolution of 8 hosts. at 16:03, 5.62s elapsed
2601NSE: Script scanning 93.174.93.40.
2602Initiating NSE at 16:03
2603Completed NSE at 16:03, 8.67s elapsed
2604Initiating NSE at 16:03
2605Completed NSE at 16:03, 0.00s elapsed
2606Nmap scan report for missalli.swittydolls.com (93.174.93.40)
2607Host is up (0.14s latency).
2608Not shown: 92 closed ports
2609PORT STATE SERVICE VERSION
261022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
2611| ssh-hostkey:
2612| 1024 9f:2f:13:4e:dd:22:bd:06:cf:83:c4:46:69:40:0c:71 (DSA)
2613|_ 2048 c6:97:3d:68:af:14:9e:c0:1a:9c:a4:f6:75:32:ae:6f (RSA)
261425/tcp filtered smtp
261580/tcp open http nginx 1.0.15
2616| http-methods:
2617|_ Supported Methods: HEAD POST OPTIONS
2618|_http-server-header: nginx/1.0.15
2619|_http-title: Miss Alli :: Preteen Model
2620135/tcp filtered msrpc
2621139/tcp filtered netbios-ssn
2622445/tcp filtered microsoft-ds
2623465/tcp filtered smtps
2624587/tcp filtered submission
2625Aggressive OS guesses: Linux 2.6.32 (92%), Linux 2.6.32 or 3.10 (92%), Linux 2.6.35 (92%), Linux 3.10 (92%), Linux 3.5 (92%), Linux 4.2 (92%), Linux 4.4 (92%), Synology DiskStation Manager 5.1 (92%), WatchGuard Fireware 11.8 (92%), DD-WRT v24-sp1 (Linux 2.4) (91%)
2626No exact OS matches for host (test conditions non-ideal).
2627Uptime guess: 32.009 days (since Fri Aug 18 15:50:37 2017)
2628Network Distance: 11 hops
2629TCP Sequence Prediction: Difficulty=259 (Good luck!)
2630IP ID Sequence Generation: All zeros
2631
2632TRACEROUTE (using port 111/tcp)
2633HOP RTT ADDRESS
26341 110.56 ms 10.13.0.1
26352 ...
26363 110.59 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
26374 111.51 ms 10.95.33.10
26385 119.52 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
26396 118.82 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
26407 ...
26418 125.55 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
26429 120.59 ms 176.10.83.5
264310 ...
264411 120.29 ms 93.174.93.40
2645
2646NSE: Script Post-scanning.
2647Initiating NSE at 16:03
2648Completed NSE at 16:03, 0.00s elapsed
2649Initiating NSE at 16:03
2650Completed NSE at 16:03, 0.00s elapsed
2651Read data files from: /usr/bin/../share/nmap
2652OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2653Nmap done: 1 IP address (1 host up) scanned in 34.95 seconds
2654 Raw packets sent: 284 (17.028KB) | Rcvd: 193 (24.543KB)
2655
2656
2657#######################################################################################################################################
2658
2659Hostname cns.swittydolls.com ISP Quasi Networks LTD. (AS29073)
2660Continent Africa Flag
2661SC
2662Country Seychelles Country Code SC (SYC)
2663Region Unknown Local time 20 Sep 2017 00:50 +04
2664City Unknown Latitude -4.583
2665IP Address 93.174.93.40 Longitude 55.667
2666#######################################################################################################################################
2667
2668dig cns.swittydolls.com any
2669
2670; <<>> DiG 9.10.3-P4-Debian <<>> cns.swittydolls.com any
2671;; global options: +cmd
2672;; Got answer:
2673;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 26544
2674;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
2675
2676;; OPT PSEUDOSECTION:
2677; EDNS: version: 0, flags:; udp: 4096
2678;; QUESTION SECTION:
2679;cns.swittydolls.com. IN ANY
2680
2681;; ANSWER SECTION:
2682cns.swittydolls.com. 16051 IN A 93.174.93.40
2683
2684;; Query time: 8 msec
2685;; SERVER: 192.168.1.254#53(192.168.1.254)
2686;; WHEN: Tue Sep 19 16:52:24 EDT 2017
2687;; MSG SIZE rcvd: 64
2688
2689#################################################################################################################################
2690
2691tcptraceroute -i eth0 cns.swittydolls.com
2692
2693Running:
2694 traceroute -T -O info -i eth0 cns.swittydolls.com
2695traceroute to cns.swittydolls.com (93.174.93.40), 30 hops max, 60 byte packets
2696 1 gateway (192.168.1.254) 0.586 ms 0.782 ms 0.952 ms
2697 2 10.135.18.1 (10.135.18.1) 11.519 ms 12.110 ms 12.473 ms
2698 3 75.154.223.222 (75.154.223.222) 30.141 ms 30.203 ms 30.314 ms
2699 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.528 ms 31.195 ms 31.362 ms
2700 5 ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.750 ms 104.816 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 106.098 ms
2701 6 * * *
2702 7 93.174.93.40 (93.174.93.40) <syn,ack> 103.707 ms 104.267 ms 104.317 ms
2703
2704#################################################################################################################################
2705
2706lbd - load balancing detector 0.2 - Checks if a given domain uses load-balancing.
2707 Written by Stefan Behte (http://ge.mine.nu)
2708 Proof-of-concept! Might give false positives.
2709
2710Checking for DNS-Loadbalancing: NOT FOUND
2711Checking for HTTP-Loadbalancing [Server]:
2712 nginx/1.0.15
2713 NOT FOUND
2714
2715Checking for HTTP-Loadbalancing [Date]: 19:29:45, 19:29:45, 19:29:46, 19:29:46, 19:29:46, 19:29:47, 19:29:47, 19:29:47, 19:29:47, 19:29:48, 19:29:48, 19:29:48, 19:29:49, 19:29:50, 19:29:50, 19:29:50, 19:29:51, 19:29:51, 19:29:51, 19:29:51, 19:29:52, 19:29:52, 19:29:52, 19:29:53, 19:29:53, 19:29:53, 19:29:53, 19:29:54, 19:29:54, 19:29:54, 19:29:55, 19:29:55, 19:29:55, 19:29:55, 19:29:56, 19:29:56, 19:29:56, 19:29:57, 19:29:57, 19:29:57, 19:29:58, 19:29:58, 19:29:58, 19:29:58, 19:29:59, 19:29:59, 19:29:59, 19:30:00, 19:30:01, 19:30:01, NOT FOUND
2716
2717Checking for HTTP-Loadbalancing [Diff]: NOT FOUND
2718
2719cns.swittydolls.com does NOT use Load-balancing.
2720
2721#################################################################################################################################
2722
2723nmap -PN -n -F -T4 -sV -A -oG temp.txt cns.swittydolls.com
2724
2725Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 16:53 EDT
2726Nmap scan report for cns.swittydolls.com (93.174.93.40)
2727Host is up (0.14s latency).
2728Not shown: 92 closed ports
2729PORT STATE SERVICE VERSION
273022/tcp open ssh OpenSSH 5.3 (protocol 2.0)
2731| ssh-hostkey:
2732| 1024 9f:2f:13:4e:dd:22:bd:06:cf:83:c4:46:69:40:0c:71 (DSA)
2733|_ 2048 c6:97:3d:68:af:14:9e:c0:1a:9c:a4:f6:75:32:ae:6f (RSA)
273425/tcp filtered smtp
273580/tcp open http nginx 1.0.15
2736|_http-server-header: nginx/1.0.15
2737|_http-title: Cindy & Susanna :: Preteen Models :: Fashion Portfolio
2738135/tcp filtered msrpc
2739139/tcp filtered netbios-ssn
2740445/tcp filtered microsoft-ds
2741465/tcp filtered smtps
2742587/tcp filtered submission
2743Aggressive OS guesses: Linux 2.6.32 (92%), Linux 2.6.35 (92%), Linux 2.6.39 (92%), Linux 3.10 (92%), Linux 3.10 - 3.12 (92%), Linux 3.4 (92%), Linux 3.5 (92%), Linux 4.2 (92%), Linux 4.4 (92%), Synology DiskStation Manager 5.1 (92%)
2744No exact OS matches for host (test conditions non-ideal).
2745Network Distance: 11 hops
2746
2747TRACEROUTE (using port 143/tcp)
2748HOP RTT ADDRESS
27491 110.03 ms 10.13.0.1
27502 ...
27513 110.06 ms 178.33.103.231
27524 ...
27535 118.95 ms 91.121.131.19
27546 118.94 ms 94.23.122.217
27557 ...
27568 124.68 ms 176.10.83.128
27579 120.43 ms 176.10.83.5
275810 ...
275911 120.73 ms 93.174.93.40
2760
2761OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
2762Nmap done: 1 IP address (1 host up) scanned in 54.57 seconds
2763
2764#################################################################################################################################
2765
2766amap -i temp.txt
2767amap v5.4 (www.thc.org/thc-amap) started at 2017-09-19 16:54:12 - APPLICATION MAPPING mode
2768
2769Protocol on 93.174.93.40:80/tcp matches http
2770Protocol on 93.174.93.40:22/tcp matches ssh
2771Protocol on 93.174.93.40:22/tcp matches ssh-openssh
2772Protocol on 93.174.93.40:80/tcp matches http-apache-2
2773
2774Unidentified ports: none.
2775
2776amap v5.4 finished at 2017-09-19 16:54:18
2777
2778#################################################################################################################################
2779
2780inetnum: 93.174.93.0 - 93.174.93.255
2781netname: SC-QUASI55
2782descr: QUASI
2783country: SC
2784org: ORG-QNL3-RIPE
2785admin-c: QNL1-RIPE
2786tech-c: QNL1-RIPE
2787status: ASSIGNED PA
2788mnt-by: QUASINETWORKS-MNT
2789mnt-lower: QUASINETWORKS-MNT
2790mnt-routes: QUASINETWORKS-MNT
2791created: 2008-06-29T21:36:16Z
2792last-modified: 2016-01-23T22:23:14Z
2793source: RIPE
2794
2795organisation: ORG-QNL3-RIPE
2796org-name: Quasi Networks LTD.
2797org-type: OTHER
2798address: Suite 1, Second Floor
2799address: Sound & Vision House, Francis Rachel Street
2800address: Victoria, Mahe, SEYCHELLES
2801remarks: *****************************************************************************
2802remarks: IMPORTANT INFORMATION
2803remarks: *****************************************************************************
2804remarks: We are a high bandwidth network provider offering bandwidth solutions.
2805remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
2806remarks: Please only use abuse@quasinetworks.com for abuse reports.
2807remarks: For all other requests, please see the details on our website.
2808remarks: *****************************************************************************
2809abuse-mailbox: abuse@quasinetworks.com
2810abuse-c: AR34302-RIPE
2811mnt-ref: QUASINETWORKS-MNT
2812mnt-by: QUASINETWORKS-MNT
2813created: 2015-11-08T22:25:26Z
2814last-modified: 2015-11-27T09:37:50Z
2815source: RIPE # Filtered
2816
2817role: Quasi Networks LTD
2818address: Suite 1, Second Floor
2819address: Sound & Vision House, Francis Rachel Street
2820address: Victoria, Mahe, SEYCHELLES
2821remarks: *****************************************************************************
2822remarks: IMPORTANT INFORMATION
2823remarks: *****************************************************************************
2824remarks: We are a high bandwidth network provider offering bandwidth solutions.
2825remarks: Government agencies can sent their requests to gov.request@quasinetworks.com
2826remarks: Please only use abuse@quasinetworks.com for abuse reports.
2827remarks: For all other requests, please see the details on our website.
2828remarks: *****************************************************************************
2829abuse-mailbox: abuse@quasinetworks.com
2830nic-hdl: QNL1-RIPE
2831mnt-by: QUASINETWORKS-MNT
2832created: 2015-11-07T22:43:04Z
2833last-modified: 2015-11-07T23:04:49Z
2834source: RIPE # Filtered
2835
2836% Information related to '93.174.88.0/21as29073'
2837
2838route: 93.174.88.0/21
2839descr: Quasi Networks LTD (IBC)
2840origin: as29073
2841mnt-by: QUASINETWORKS-MNT
2842created: 2008-06-20T15:33:47Z
2843last-modified: 2016-01-23T22:26:12Z
2844source: RIPE
2845
2846% This query was served by the RIPE Database Query Service version 1.89.2 (HEREFORD)
2847
2848#################################################################################################################################
2849[i] Scanning Site: http://cns.swittydolls.com
2850
2851
2852
2853B A S I C I N F O
2854====================
2855
2856
2857[+] Site Title: Cindy & Susanna :: Preteen Models :: Fashion Portfolio
2858[+] IP address: 93.174.93.40
2859[+] Web Server: nginx/1.0.15
2860[+] CMS: Could Not Detect
2861[+] Cloudflare: Not Detected
2862[+] Robots File: Could NOT Find robots.txt!
2863
2864
2865
2866
2867G E O I P L O O K U P
2868=========================
2869
2870[i] IP Address: 93.174.93.40
2871[i] Country: SC
2872[i] State: N/A
2873[i] City: N/A
2874[i] Latitude: -4.583300
2875[i] Longitude: 55.666698
2876
2877
2878
2879
2880H T T P H E A D E R S
2881=======================
2882
2883
2884[i] HTTP/1.1 200 OK
2885[i] Server: nginx/1.0.15
2886[i] Date: Tue, 19 Sep 2017 19:29:48 GMT
2887[i] Content-Type: text/html; charset=UTF-8
2888[i] Connection: close
2889[i] X-Powered-By: PHP/5.5.9-1ubuntu4.14
2890[i] Vary: Accept-Encoding
2891
2892
2893
2894
2895D N S L O O K U P
2896===================
2897
2898cns.swittydolls.com. 86396 IN A 93.174.93.40
2899
2900
2901
2902
2903S U B N E T C A L C U L A T I O N
2904====================================
2905
2906Address = 93.174.93.40
2907Network = 93.174.93.40 / 32
2908Netmask = 255.255.255.255
2909Broadcast = not needed on Point-to-Point links
2910Wildcard Mask = 0.0.0.0
2911Hosts Bits = 0
2912Max. Hosts = 1 (2^0 - 0)
2913Host Range = { 93.174.93.40 - 93.174.93.40 }
2914
2915
2916
2917N M A P P O R T S C A N
2918============================
2919
2920
2921Starting Nmap 7.01 ( https://nmap.org ) at 2017-09-19 20:52 UTC
2922Nmap scan report for cns.swittydolls.com (93.174.93.40)
2923Host is up (0.084s latency).
2924PORT STATE SERVICE VERSION
292521/tcp closed ftp
292622/tcp open ssh OpenSSH 5.3 (protocol 2.0)
292723/tcp closed telnet
292825/tcp closed smtp
292980/tcp open http nginx 1.0.15
2930110/tcp closed pop3
2931143/tcp closed imap
2932443/tcp closed https
2933445/tcp closed microsoft-ds
29343389/tcp closed ms-wbt-server
2935cns.swittydolls.com
2936
2937; <<>> DiG 9.10.3-P4-Debian <<>> cns.swittydolls.com any
2938;; global options: +cmd
2939;; Got answer:
2940;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 14842
2941;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
2942
2943;; OPT PSEUDOSECTION:
2944; EDNS: version: 0, flags:; udp: 4096
2945;; QUESTION SECTION:
2946;cns.swittydolls.com. IN ANY
2947
2948;; ANSWER SECTION:
2949cns.swittydolls.com. 16048 IN A 93.174.93.40
2950
2951;; Query time: 8 msec
2952;; SERVER: 192.168.1.254#53(192.168.1.254)
2953;; WHEN: Tue Sep 19 16:52:27 EDT 2017
2954;; MSG SIZE rcvd: 64
2955
2956
2957Running:
2958 traceroute -T -O info -i eth0 cns.swittydolls.com
2959traceroute to cns.swittydolls.com (93.174.93.40), 30 hops max, 60 byte packets
2960 1 gateway (192.168.1.254) 0.353 ms 0.540 ms 0.824 ms
2961 2 10.135.18.1 (10.135.18.1) 7.231 ms 8.945 ms 9.009 ms
2962 3 75.154.223.222 (75.154.223.222) 29.474 ms 30.022 ms 30.185 ms
2963 4 lag-113.ear3.NewYork1.Level3.net (4.15.212.245) 30.553 ms 30.727 ms 31.144 ms
2964 5 ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 104.476 ms ae-237-3613.edge6.Amsterdam1.Level3.net (4.69.162.242) 104.509 ms ae-238-3614.edge6.Amsterdam1.Level3.net (4.69.162.246) 104.919 ms
2965 6 * * *
2966 7 93.174.93.40 (93.174.93.40) <syn,ack> 103.901 ms 103.993 ms 104.182 ms
2967
2968Host's addresses:
2969__________________
2970
2971cns.swittydolls.com. 16042 IN A 93.174.93.40
2972
2973
2974Wildcard detection using: rrwztmapfdpc
2975_______________________________________
2976
2977rrwztmapfdpc.cns.swittydolls.com. 86400 IN A 93.174.93.40
2978
2979
2980!!!!!!!!!!!!!!!!!!!!!!!!!!!!
2981
2982 Wildcards detected, all subdomains will point to the same IP address
2983 Omitting results containing 93.174.93.40.
2984 Maybe you are using OpenDNS servers.
2985
2986!!!!!!!!!!!!!!!!!!!!!!!!!!!!
2987
2988
2989Name Servers:
2990______________
2991
2992 cns.swittydolls.com NS record query failed: NOERROR
2993
2994
2995dnsmap 0.30 - DNS Network Mapper by pagvac (gnucitizen.org)
2996
2997[+] warning: domain might use wildcards. 93.174.93.40 will be ignored from results
2998[+] searching (sub)domains for cns.swittydolls.com using built-in wordlist
2999[+] using maximum random delay of 10 millisecond(s) between requests
3000
3001[+] 0 (sub)domains and 0 IP address(es) found
3002[+] completion time: 273 second(s)
3003
3004
3005Tracing to cns.swittydolls.com[a] via 192.168.1.254, maximum of 3 retries
3006192.168.1.254 (192.168.1.254) Got answer
3007
3008
3009WhatWeb report for http://cns.swittydolls.com
3010Status : 200 OK
3011Title : Cindy & Susanna :: Preteen Models :: Fashion Portfolio
3012IP : 93.174.93.40
3013Country : NETHERLANDS, NL
3014
3015Summary : X-Powered-By[PHP/5.5.9-1ubuntu4.14], HTTPServer[nginx/1.0.15], Google-Analytics[UA-38217984-1], PHP[5.5.9-1ubuntu4.14], nginx[1.0.15], Script[JavaScript,text/javascript]
3016
3017Detected Plugins:
3018[ Google-Analytics ]
3019 This plugin identifies the Google Analytics account.
3020
3021 Account : UA-38217984-1
3022 Website : http://www.google.com/analytics/
3023
3024[ HTTPServer ]
3025 HTTP server header string. This plugin also attempts to
3026 identify the operating system from the server header.
3027
3028 String : nginx/1.0.15 (from server string)
3029
3030[ PHP ]
3031 PHP is a widely-used general-purpose scripting language
3032 that is especially suited for Web development and can be
3033 embedded into HTML. This plugin identifies PHP errors,
3034 modules and versions and extracts the local file path and
3035 username if present.
3036
3037 Version : 5.5.9-1ubuntu4.14
3038 Google Dorks: (2)
3039 Website : http://www.php.net/
3040
3041[ Script ]
3042 This plugin detects instances of script HTML elements and
3043 returns the script language/type.
3044
3045 String : JavaScript,text/javascript
3046
3047[ X-Powered-By ]
3048 X-Powered-By HTTP header
3049
3050 String : PHP/5.5.9-1ubuntu4.14 (from x-powered-by string)
3051
3052[ nginx ]
3053 Nginx (Engine-X) is a free, open-source, high-performance
3054 HTTP server and reverse proxy, as well as an IMAP/POP3
3055 proxy server.
3056
3057 Version : 1.0.15
3058 Website : http://nginx.net/
3059
3060HTTP Headers:
3061 HTTP/1.1 200 OK
3062 Server: nginx/1.0.15
3063 Date: Tue, 19 Sep 2017 19:34:05 GMT
3064 Content-Type: text/html; charset=UTF-8
3065 Connection: close
3066 X-Powered-By: PHP/5.5.9-1ubuntu4.14
3067 Vary: Accept-Encoding
3068 Content-Encoding: gzip
3069 Content-Length: 2324
3070
3071
3072 ^ ^
3073 _ __ _ ____ _ __ _ _ ____
3074 ///7/ /.' \ / __////7/ /,' \ ,' \ / __/
3075 | V V // o // _/ | V V // 0 // 0 // _/
3076 |_n_,'/_n_//_/ |_n_,' \_,' \_,'/_/
3077 <
3078 ...'
3079
3080 WAFW00F - Web Application Firewall Detection Tool
3081
3082 By Sandro Gauci && Wendel G. Henrique
3083
3084Checking http://cns.swittydolls.com
3085Generic Detection results:
3086No WAF detected by the generic detection
3087Number of requests: 13
3088
3089
3090
3091Trying zone transfer first...
3092
3093Unsuccessful in zone transfer (it was worth a shot)
3094Okay, trying the good old fashioned way... brute force
3095
3096Checking for wildcard DNS...
3097 ** Found 92829292512.cns.swittydolls.com at 93.174.93.40.
3098 ** High probability of wildcard DNS.
3099Now performing 2280 test(s)...
3100
3101Subnets found (may want to probe here using nmap or unicornscan):
3102
3103Done with Fierce scan: http://ha.ckers.org/fierce/
3104Found 0 entries.
3105
3106Have a nice day.
3107
3108
3109./ghost.sh: ligne 206 : cd: /opt/tools: Aucun fichier ou dossier de ce type
3110./ghost.sh: ligne 207: ./lbd.sh: Aucun fichier ou dossier de ce type
3111
3112
3113./ghost.sh: ligne 210 : cd: /opt/tools: Aucun fichier ou dossier de ce type
3114Can't open perl script "smtp-user-enum.pl": Aucun fichier ou dossier de ce type
3115
3116
3117
3118Starting Nmap 7.60 ( https://nmap.org ) at 2017-09-19 16:57 EDT
3119NSE: Loaded 146 scripts for scanning.
3120NSE: Script Pre-scanning.
3121Initiating NSE at 16:57
3122Completed NSE at 16:57, 0.00s elapsed
3123Initiating NSE at 16:57
3124Completed NSE at 16:57, 0.00s elapsed
3125Failed to resolve "cns.swittydolls.com.txt".
3126Initiating Parallel DNS resolution of 1 host. at 16:57
3127Completed Parallel DNS resolution of 1 host. at 16:57, 0.57s elapsed
3128Initiating SYN Stealth Scan at 16:57
3129Scanning cns.swittydolls.com (93.174.93.40) [100 ports]
3130Discovered open port 22/tcp on 93.174.93.40
3131Discovered open port 80/tcp on 93.174.93.40
3132Completed SYN Stealth Scan at 16:57, 3.69s elapsed (100 total ports)
3133Initiating Service scan at 16:57
3134Scanning 2 services on cns.swittydolls.com (93.174.93.40)
3135Completed Service scan at 16:57, 6.28s elapsed (2 services on 1 host)
3136Initiating OS detection (try #1) against cns.swittydolls.com (93.174.93.40)
3137Retrying OS detection (try #2) against cns.swittydolls.com (93.174.93.40)
3138Initiating Traceroute at 16:57
3139Completed Traceroute at 16:58, 3.02s elapsed
3140Initiating Parallel DNS resolution of 7 hosts. at 16:58
3141Completed Parallel DNS resolution of 7 hosts. at 16:58, 5.51s elapsed
3142NSE: Script scanning 93.174.93.40.
3143Initiating NSE at 16:58
3144Completed NSE at 16:58, 25.88s elapsed
3145Initiating NSE at 16:58
3146Completed NSE at 16:58, 0.00s elapsed
3147Nmap scan report for cns.swittydolls.com (93.174.93.40)
3148Host is up (0.13s latency).
3149Not shown: 92 closed ports
3150PORT STATE SERVICE VERSION
315122/tcp open ssh OpenSSH 5.3 (protocol 2.0)
3152| ssh-hostkey:
3153| 1024 9f:2f:13:4e:dd:22:bd:06:cf:83:c4:46:69:40:0c:71 (DSA)
3154|_ 2048 c6:97:3d:68:af:14:9e:c0:1a:9c:a4:f6:75:32:ae:6f (RSA)
315525/tcp filtered smtp
315680/tcp open http nginx 1.0.15
3157| http-methods:
3158|_ Supported Methods: GET HEAD POST OPTIONS
3159|_http-server-header: nginx/1.0.15
3160|_http-title: Cindy & Susanna :: Preteen Models :: Fashion Portfolio
3161135/tcp filtered msrpc
3162139/tcp filtered netbios-ssn
3163445/tcp filtered microsoft-ds
3164465/tcp filtered smtps
3165587/tcp filtered submission
3166Aggressive OS guesses: Linux 2.6.32 (92%), Linux 3.10 (92%), Linux 3.4 (92%), Linux 3.5 (92%), Linux 4.2 (92%), Synology DiskStation Manager 5.1 (92%), Linux 3.1 - 3.2 (91%), Linux 2.6.32 or 3.10 (90%), Linux 2.6.35 (90%), Linux 2.6.39 (90%)
3167No exact OS matches for host (test conditions non-ideal).
3168Uptime guess: 32.047 days (since Fri Aug 18 15:50:38 2017)
3169Network Distance: 11 hops
3170TCP Sequence Prediction: Difficulty=264 (Good luck!)
3171IP ID Sequence Generation: All zeros
3172
3173TRACEROUTE (using port 8080/tcp)
3174HOP RTT ADDRESS
31751 110.42 ms 10.13.0.1
31762 ...
31773 110.45 ms po101.gra-g2-a75.fr.eu (178.33.103.231)
31784 ...
31795 119.40 ms be100-1113.fra-5-a9.de.eu (91.121.131.19)
31806 118.91 ms be100-2.fra-1-a9.de.eu (94.23.122.217)
31817 ...
31828 124.43 ms vlan3555.bb1.ams2.nl.m247.com (176.10.83.128)
31839 120.18 ms 176.10.83.5
318410 ...
318511 120.23 ms 93.174.93.40
3186
3187NSE: Script Post-scanning.
3188Initiating NSE at 16:58
3189Completed NSE at 16:58, 0.00s elapsed
3190Initiating NSE at 16:58
3191Completed NSE at 16:58, 0.00s elapsed
3192Read data files from: /usr/bin/../share/nmap
3193OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
3194Nmap done: 1 IP address (1 host up) scanned in 51.23 seconds
3195 Raw packets sent: 265 (16.594KB) | Rcvd: 169 (21.209KB)
3196##############################################################################################################################################################################################################################################################################
3197 OPDeathEathers V.S HunterUnit JTSEC full Recon #25