nginx
tcp/443 tcp/8443
WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb583e3d39f683fe95a683fe95a683fe95a683fe95a
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.1 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
The following CloudPanel instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since it could lead to RCE ( Remote Code Execution ). Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 8bb944476a146f564acb1065676cae8c22dc3d2e6a7521e86a7521e86a7521e8
Found vulnerable CloudPanel: Affected by CVE-2023-35885 Affected by CVE-2023-36630 Affected by CVE-2023-33747
Open service 161.35.136.205:22
2024-12-22 00:25
Open service 161.35.136.205:8443
2024-12-21 23:43
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 21 Dec 2024 23:43:22 GMT Location: /login Expires: Sat, 21 Dec 2024 23:43:22 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=ct18t77nplndaulv24058g44g2; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-12-20 00:17
Open service 161.35.136.205:8443
2024-12-19 23:10
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 19 Dec 2024 23:10:38 GMT Location: /login Expires: Thu, 19 Dec 2024 23:10:38 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=5mpmggkbq6n1bifvl9et5cafct; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:8443
2024-12-18 00:58
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Wed, 18 Dec 2024 00:58:10 GMT Location: /login Expires: Wed, 18 Dec 2024 00:58:10 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=0l794prpoqf0vr3junurqilqkt; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-12-18 00:34
Open service 161.35.136.205:8443
2024-12-15 23:37
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sun, 15 Dec 2024 23:37:42 GMT Location: /login Expires: Sun, 15 Dec 2024 23:37:42 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=f41bso7ebs2poc2c9fn2bs2phq; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-12-15 23:05
Open service 161.35.136.205:8443
2024-12-14 00:01
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 14 Dec 2024 00:01:41 GMT Location: /login Expires: Sat, 14 Dec 2024 00:01:41 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=do82hmvujh636cqqhnr4uvo8gm; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-12-13 21:38
Open service 161.35.136.205:8443
2024-12-12 01:02
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 12 Dec 2024 01:02:05 GMT Location: /login Expires: Thu, 12 Dec 2024 01:02:05 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=a138idnavjq13ie4jldgvribmq; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-12-11 21:47
Open service 161.35.136.205:8443
2024-12-02 01:36
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Mon, 02 Dec 2024 01:36:27 GMT Location: /login Expires: Mon, 02 Dec 2024 01:36:27 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=fcbv34qe9ao4p3r4oflord8uhg; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-12-01 23:35
Open service 161.35.136.205:8443
2024-11-30 00:59
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 30 Nov 2024 00:59:21 GMT Location: /login Expires: Sat, 30 Nov 2024 00:59:21 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=srgfou74s6nt4m6a6agj0of20e; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-11-29 23:00
Open service 161.35.136.205:8443
2024-11-28 01:02
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 28 Nov 2024 01:03:02 GMT Location: /login Expires: Thu, 28 Nov 2024 01:03:02 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=rv6dso1k4j6lgdngn40nqk90qh; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 161.35.136.205:22
2024-11-27 23:32
Open service 161.35.136.205:443
2024-11-20 09:28
HTTP/1.1 400 Bad Request Server: nginx Date: Wed, 20 Nov 2024 09:28:47 GMT Content-Type: text/html Content-Length: 650 Connection: close Page title: 400 The plain HTTP request was sent to HTTPS port <html> <head><title>400 The plain HTTP request was sent to HTTPS port</title></head> <body> <center><h1>400 Bad Request</h1></center> <center>The plain HTTP request was sent to HTTPS port</center> <hr><center>nginx</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page -->