WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb581e37d9a6fcdf7e36fcdf7e36fcdf7e36fcdf7e3
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.11 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Open service 157.180.74.8:80 · demo.kitscan.com
2025-12-21 16:21
HTTP/1.1 301 Moved Permanently Connection: close Content-Type: text/html; charset=utf-8 Location: https://demo.kitscan.com/ Date: Sun, 21 Dec 2025 16:21:27 GMT Content-Length: 60 <a href="https://demo.kitscan.com/">Moved Permanently</a>.
Open service 157.180.74.8:443 · demo.kitscan.com
2025-12-21 16:21
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 0 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-eval' 'nonce-aea23ee03eae667f43c67e44b88d60b9'; style-src 'self' 'nonce-aea23ee03eae667f43c67e44b88d60b9' Content-Type: text/html; charset=utf-8 Cross-Origin-Embedder-Policy: require-corp Cross-Origin-Opener-Policy: same-origin Cross-Origin-Resource-Policy: same-origin Date: Sun, 21 Dec 2025 16:21:27 GMT Location: https://demo.kitscan.com/session/new Permissions-Policy: geolocation=(), microphone=(), camera=(), fullscreen=*, payment=() Referrer-Policy: strict-origin-when-cross-origin Set-Cookie: kitscan_session=3ROziw2p9l4sRWArvykQyGSi6mf56NkPXG%2FHBIQgqUq8wgL1GwyxPnjLeWm38pu%2BpKpzOVKXXl%2F0y%2BIA6qHp2lZKd0Pphgzhl54A3wQKA5Mm5RVVcMN4RnlIzSDkIn3csq4koJS4UgOuRrZ4Vpw8aXGpnstQ04JOxBpP6aq%2F%2FeV0pUn1lntQVYGVCzBm%2FcUSOeKfhko3Tv3Q7VLhRiokfErqJ28TQ0dBEdd%2FgxE2KR2a%2FySGXQ%2FCyhzWeriKoyM8fIxdC7z64EXmfgOKLEO2bPX9ft2oppA2EmBnt5etwey4cbINhXkIpCPlr%2Ff3HcnBQgJFt8ToGF%2F1YLU3tFyq5cDPJIY%2Fs6C%2FJvw7gYi%2FW0wyyZokGoSz--VaCnewESKAPtI7Rp--SxyuSMORqLzoFqWMGBVIBQ%3D%3D; path=/; secure; httponly; samesite=lax Strict-Transport-Security: max-age=63072000; includeSubDomains Vary: Accept-Encoding X-Cache: miss X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Request-Id: 6a93d0d5-b66d-4f4a-a0fb-fa5070a9b7b6 X-Runtime: 0.002548 X-Xss-Protection: 0 Connection: close