nginx
tcp/443 tcp/8443
The following CloudPanel instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since it could lead to RCE ( Remote Code Execution ). Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 8bb944476a146f564acb1065676cae8c22dc3d2e6a7521e86a7521e86a7521e8
Found vulnerable CloudPanel: Affected by CVE-2023-35885 Affected by CVE-2023-36630 Affected by CVE-2023-33747
Open service 24.199.76.246:8443
2024-11-20 09:48
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Wed, 20 Nov 2024 09:48:52 GMT Location: /login Expires: Wed, 20 Nov 2024 09:48:52 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=lig2e4rajuk5j20hrh4hl01cfj; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-11-19 22:38
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Tue, 19 Nov 2024 22:38:41 GMT Location: /login Expires: Tue, 19 Nov 2024 22:38:41 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=87g9scs82kicn36cgj1kk4es71; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:443
2024-11-19 21:12
HTTP/1.1 400 Bad Request Server: nginx Date: Tue, 19 Nov 2024 21:12:16 GMT Content-Type: text/html Content-Length: 650 Connection: close Page title: 400 The plain HTTP request was sent to HTTPS port <html> <head><title>400 The plain HTTP request was sent to HTTPS port</title></head> <body> <center><h1>400 Bad Request</h1></center> <center>The plain HTTP request was sent to HTTPS port</center> <hr><center>nginx</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page -->
Open service 24.199.76.246:8443
2024-11-17 22:02
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sun, 17 Nov 2024 22:02:34 GMT Location: /login Expires: Sun, 17 Nov 2024 22:02:34 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=t7vgt62hnslha19pu9u1ap8e8n; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-11-16 01:28
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 16 Nov 2024 01:28:06 GMT Location: /login Expires: Sat, 16 Nov 2024 01:28:06 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=g1cmm018ga7an170eur2l1sa6o; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-11-15 23:48
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Fri, 15 Nov 2024 23:49:02 GMT Location: /login Expires: Fri, 15 Nov 2024 23:49:02 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=8aau4fv0aq2t5d3eqmpce0oph8; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:443
2024-11-15 17:17
HTTP/1.1 400 Bad Request Server: nginx Date: Fri, 15 Nov 2024 17:17:16 GMT Content-Type: text/html Content-Length: 650 Connection: close Page title: 400 The plain HTTP request was sent to HTTPS port <html> <head><title>400 The plain HTTP request was sent to HTTPS port</title></head> <body> <center><h1>400 Bad Request</h1></center> <center>The plain HTTP request was sent to HTTPS port</center> <hr><center>nginx</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page -->
Open service 24.199.76.246:8443
2024-11-02 00:28
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 02 Nov 2024 00:28:16 GMT Location: /login Expires: Sat, 02 Nov 2024 00:28:16 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=idb4gvejapb1o4nk6du0opah2s; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-11-01 00:34
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Fri, 01 Nov 2024 00:34:54 GMT Location: /login Expires: Fri, 01 Nov 2024 00:34:54 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=s7nn5sg9dnl8s69b0506vq743m; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-10-30 00:08
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Wed, 30 Oct 2024 00:08:48 GMT Location: /login Expires: Wed, 30 Oct 2024 00:08:48 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=m536ocl8a5maslanhtge7sfjp1; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-10-21 23:08
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Mon, 21 Oct 2024 23:08:54 GMT Location: /login Expires: Mon, 21 Oct 2024 23:08:54 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=cubp6e94ueg5hnbu65ssccm16g; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-10-19 21:14
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Sat, 19 Oct 2024 21:15:01 GMT Location: /login Expires: Sat, 19 Oct 2024 21:15:01 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=22gm5jpro67qk71g7fq8gv35cv; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>
Open service 24.199.76.246:8443
2024-10-17 23:44
HTTP/1.1 302 Found Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: max-age=0, must-revalidate, private Date: Thu, 17 Oct 2024 23:44:15 GMT Location: /login Expires: Thu, 17 Oct 2024 23:44:15 GMT Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax Set-Cookie: cloudpanel=4n74v3npdfk2vvpsrnafkupus0; path=/; secure; httponly; samesite=lax Page title: Redirecting to /login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/login'" /> <title>Redirecting to /login</title> </head> <body> Redirecting to <a href="/login">/login</a>. </body> </html>