nginx
tcp/443 tcp/8080 tcp/8443
The following CloudPanel instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since it could lead to RCE ( Remote Code Execution ). Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 8bb944476a146f564acb1065676cae8c22dc3d2e6a7521e86a7521e86a7521e8
Found vulnerable CloudPanel: Affected by CVE-2023-35885 Affected by CVE-2023-36630 Affected by CVE-2023-33747
Open service 178.62.14.227:8443
2024-12-21 23:52
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 21 Dec 2024 23:52:16 GMT Location: /login Expires: Sat, 21 Dec 2024 23:52:16 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=gv5d5esi7q24efa5m13dtvuts1; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-21 21:05
HTTP/1.1 200 OK Server: nginx Date: Sat, 21 Dec 2024 21:05:27 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Cache-Control: no-store, no-cache X-Cache-Enabled: False Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-12-19 23:00
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 19 Dec 2024 23:00:31 GMT Location: /login Expires: Thu, 19 Dec 2024 23:00:31 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=n0dcm4e53clmju73a2anrvch5j; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-19 22:30
HTTP/1.1 200 OK Server: nginx Date: Thu, 19 Dec 2024 22:31:04 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Cache-Control: no-store, no-cache X-Cache-Enabled: False Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-12-18 01:15
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Wed, 18 Dec 2024 01:15:43 GMT Location: /login Expires: Wed, 18 Dec 2024 01:15:43 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=r0cr50vbe7fl7bh84bpb6q7se4; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-17 22:47
HTTP/1.1 200 OK Server: nginx Date: Tue, 17 Dec 2024 22:47:13 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Cache-Control: no-store, no-cache X-Cache-Enabled: False Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-12-15 23:47
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sun, 15 Dec 2024 23:47:16 GMT Location: /login Expires: Sun, 15 Dec 2024 23:47:16 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=tcd3fpfmvjus8qj09ca1v9nt6s; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-15 21:06
HTTP/1.1 200 OK Server: nginx Date: Sun, 15 Dec 2024 21:06:58 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-12-14 00:03
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 14 Dec 2024 00:03:04 GMT Location: /login Expires: Sat, 14 Dec 2024 00:03:04 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=8er6mtsoapisdj0vopmvdj9i7o; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-13 21:17
HTTP/1.1 200 OK Server: nginx Date: Fri, 13 Dec 2024 21:17:32 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8080
2024-12-13 20:59
HTTP/1.1 200 OK Server: nginx Date: Fri, 13 Dec 2024 20:59:07 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-12-12 01:01
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 12 Dec 2024 01:01:38 GMT Location: /login Expires: Thu, 12 Dec 2024 01:01:38 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=ntfoqiqbub6noju57k4810i7iv; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-11 21:07
HTTP/1.1 200 OK Server: nginx Date: Wed, 11 Dec 2024 21:07:52 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-12-02 01:15
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Mon, 02 Dec 2024 01:15:48 GMT Location: /login Expires: Mon, 02 Dec 2024 01:15:48 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=om9dt4mr9nbomgbmk9varkhd1a; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-12-01 21:33
HTTP/1.1 200 OK Server: nginx Date: Sun, 01 Dec 2024 21:33:46 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Cache-Control: no-store, no-cache X-Cache-Enabled: False Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-11-30 00:41
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 30 Nov 2024 00:41:53 GMT Location: /login Expires: Sat, 30 Nov 2024 00:41:53 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=fsm0o5104b1m7pmba82snul50n; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-11-29 21:21
HTTP/1.1 200 OK Server: nginx Date: Fri, 29 Nov 2024 21:21:11 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-11-28 01:01
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 28 Nov 2024 01:01:27 GMT Location: /login Expires: Thu, 28 Nov 2024 01:01:27 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=3jbgfic84n05svbnemrjd71f41; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 178.62.14.227:443
2024-11-27 21:14
HTTP/1.1 200 OK Server: nginx Date: Wed, 27 Nov 2024 21:14:39 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Link: <https://blog.dalendo.com/wp-json/>; rel="https://api.w.org/" X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Permitted-Cross-Domain-Policies: master-only Referrer-Policy: same-origin
Open service 178.62.14.227:8443
2024-11-20 14:26
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Wed, 20 Nov 2024 14:26:39 GMT Location: /login Expires: Wed, 20 Nov 2024 14:26:39 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=o5t5bhh8rlg4tng9e90up9dp3b; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>