WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb563aa8aacd8f3bb51d8f3bb51d8f3bb51d8f3bb51
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u2 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
The server is accepting NTLM anonymous credentials.
This allows for authentication bypass to access the underlying application.
https://blog.leakix.net/2022/03/bypassing-ntlm-auth-over-http/
Fingerprint: 40fea8e6a9bd2c3671ce48dbe86f199c98a4427affcaeb0b979824ff9a5503b0
Server didn't refuse ANONYMOUS NTLM connection Found NTLM information: Running Windows 10.0 build 20348 MsvAvNbComputerName: WIN-PR4A4CP2ZI2 MsvAvNbDomainName: A720 MsvAvDNSComputerName: WIN-PR4A4CP2ZI2.A720.LOCAL MsvAvDNSDomainName: A720.LOCAL MsvAvDNSTreeName: A720.LOCAL 200 OK Content-Length: 0 Content-Type: text/html Date: Wed, 13 Nov 2024 08:44:20 GMT Server: Microsoft-IIS/10.0 Www-Authenticate: NTLM
Fingerprint: 40fea8e6a9bd2c3671ce48dbe86f199c98a4427ac92850ac9d9d1009f6598c04
Server didn't refuse ANONYMOUS NTLM connection Found NTLM information: Running Windows 10.0 build 20348 MsvAvNbComputerName: WIN-927P3P6JG51 MsvAvNbDomainName: 9XOG MsvAvDNSComputerName: WIN-927P3P6JG51.9XOG.LOCAL MsvAvDNSDomainName: 9XOG.LOCAL MsvAvDNSTreeName: 9XOG.LOCAL 200 OK Content-Length: 0 Content-Type: text/html Date: Fri, 18 Oct 2024 15:01:28 GMT Server: Microsoft-IIS/10.0 Www-Authenticate: NTLM
Open service 13.38.203.182:443
2024-12-21 23:39
Open service 13.38.203.182:80
2024-12-21 23:37
Open service 13.38.203.182:80
2024-12-21 23:33
Open service 13.38.203.182:80
2024-12-19 23:23
Open service 13.38.203.182:80
2024-12-19 23:10
Open service 13.38.203.182:443
2024-12-19 22:37
Open service 13.38.203.182:443
2024-12-17 23:58
Open service 13.38.203.182:80
2024-12-17 23:50
Open service 13.38.203.182:80
2024-12-17 23:47
Open service 13.38.203.182:80
2024-12-15 22:55
Open service 13.38.203.182:80
2024-12-15 22:36
Open service 13.38.203.182:443
2024-12-15 22:01
Open service 13.38.203.182:80
2024-12-13 23:01
Open service 13.38.203.182:443
2024-12-13 22:52
Open service 13.38.203.182:80
2024-12-13 22:50
Open service 13.38.203.182:80
2024-12-11 23:26
Open service 13.38.203.182:80
2024-12-11 23:23
Open service 13.38.203.182:443
2024-12-11 22:59
Open service 13.38.203.182:80
2024-12-01 23:25
Open service 13.38.203.182:80
2024-12-01 23:22
Open service 13.38.203.182:443
2024-12-01 22:47
Open service 13.38.203.182:80
2024-11-29 23:26
Open service 13.38.203.182:80
2024-11-29 21:44
Open service 13.38.203.182:80
2024-11-27 23:38
Open service 13.38.203.182:80
2024-11-27 21:19