nginx
tcp/443 tcp/80
The following CentOS Web Panel is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: b200c4085dcca515084ebea24b907d604b907d604b907d604b907d604b907d60
Found outdated CentOS Web Panel vulnerable to RCE Found CVE-2022-44877
The following CentOS Web Panel is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since a vulnerability allow remote attackers to achieve RCE (Remote code execution) on the service. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: b200c4085dcca515084ebea24b907d604b907d604b907d604b907d604b907d60
Found outdated CentOS Web Panel vulnerable to RCE Found CVE-2022-44877
Open service 143.198.162.240:8080
2024-12-17 21:31
HTTP/1.1 400 Content-Type: text/html;charset=utf-8 Content-Language: en Content-Length: 435 Date: Tue, 17 Dec 2024 21:31:30 GMT Connection: close Page title: HTTP Status 400 – Bad Request <!doctype html><html lang="en"><head><title>HTTP Status 400 – Bad Request</title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3 {font-size:14px;} p {font-size:12px;} a {color:black;} .line {height:1px;background-color:#525D76;border:none;}</style></head><body><h1>HTTP Status 400 – Bad Request</h1></body></html>
Open service 143.198.162.240:8443
2024-12-17 19:31
HTTP/1.1 404 Content-Length: 0 Date: Tue, 17 Dec 2024 19:31:47 GMT Connection: close
Open service 143.198.162.240:443 · 076ea4fd-ed6c-43bd-8666-f04a095984a0.unifi-hosting.ui.com
2024-11-20 23:21
HTTP/1.1 200 OK Server: nginx Date: Wed, 20 Nov 2024 23:21:45 GMT Content-Type: text/html Content-Length: 511 Last-Modified: Thu, 15 Aug 2024 18:27:58 GMT Connection: close ETag: "66be48ae-1ff" Expires: Wed, 20 Nov 2024 23:21:44 GMT Cache-Control: no-cache Access-Control-Allow-Credentials: false Access-Control-Expose-Headers: Content-Disposition, Content-Range, Filename, Location, Range, Upload-Length, Upload-Offset, X-Connection-Type, X-Csrf-Token, X-File-Id, X-Token-Expire-Time, X-Updated-Csrf-Token Referrer-Policy: no-referrer Strict-Transport-Security: max-age=15552000; includeSubDomains X-Content-Type-Options: nosniff X-DNS-Prefetch-Control: off X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Accept-Ranges: bytes Page title: UniFi OS <!doctype html><html lang="en"><head><meta charset="utf-8"><link rel="icon" href="/favicon.ico?v3" sizes="any"><link rel="icon" href="/favicon.svg?v3" type="image/svg+xml"><link rel="apple-touch-icon" href="/apple-touch-icon.png?v3"><title>UniFi OS</title><meta name="viewport" content="width=device-width,initial-scale=1"><script defer="defer" src="/main.0178b959830932983dec.js"></script><link href="/main.6bc650de.css" rel="stylesheet"></head><body id="portal-body"><div id="portal-root"></div></body></html>
Open service 143.198.162.240:8443 · 076ea4fd-ed6c-43bd-8666-f04a095984a0.unifi-hosting.ui.com
2024-11-20 23:21
HTTP/1.1 404 Content-Length: 0 Date: Wed, 20 Nov 2024 23:21:45 GMT Connection: close
Open service 143.198.162.240:80 · 076ea4fd-ed6c-43bd-8666-f04a095984a0.unifi-hosting.ui.com
2024-11-20 23:21
HTTP/1.1 301 Moved Permanently Server: nginx Date: Wed, 20 Nov 2024 23:21:43 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://076ea4fd-ed6c-43bd-8666-f04a095984a0.unifi-hosting.ui.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>