Exposed GoAnywhere MFT are subject to an unfixed 0day RCE and should be considered unsafe when made public.
Fingerprint: b1a07937b9045eb34a1c93d7760939874f03b46a978e81611034daf2797d04f4
HTTP/1.1 302 Cache-control: no-cache="set-cookie" Content-Type: text/html;charset=UTF-8 Date: Sat, 04 Feb 2023 16:29:43 GMT Location: /goanywhere Set-Cookie: RSESSIONID=0F818324A8EFB41E1DB32715CBB9D0F2; Path=/; Secure; HttpOnly Set-Cookie: AWSELB=A38937BB086412602C70F15C8454F9CCB7202D224DB2D1FC6DF709D8FEBCDFA197CA4492F44C686409D73E8F553FC329C0396A01245BEC4B0CED8B3E72B1917C8978385BBE;PATH=/ Set-Cookie: AWSELBCORS=A38937BB086412602C70F15C8454F9CCB7202D224DB2D1FC6DF709D8FEBCDFA197CA4492F44C686409D73E8F553FC329C0396A01245BEC4B0CED8B3E72B1917C8978385BBE;PATH=/;SECURE;SAMESITE=None Content-Length: 0 Connection: Close
Fingerprint: b1a07937b9045eb34a1c93d7760939874f03b46a978e8161bf668b602c83a99a
HTTP/1.1 302 Cache-control: no-cache="set-cookie" Content-Type: text/html;charset=UTF-8 Date: Tue, 31 Jan 2023 17:47:40 GMT Location: /goanywhere Set-Cookie: RSESSIONID=ABD6CDB2DD46665E4A2A601FD068EEFF; Path=/; Secure; HttpOnly Set-Cookie: AWSELB=A38937BB086412602C70F15C8454F9CCB7202D224DB2D1FC6DF709D8FEBCDFA197CA4492F40D4E1115B7BEA18539035001B3C443CA948A32BB778324A2B3B3E187D59E4289;PATH=/ Set-Cookie: AWSELBCORS=A38937BB086412602C70F15C8454F9CCB7202D224DB2D1FC6DF709D8FEBCDFA197CA4492F40D4E1115B7BEA18539035001B3C443CA948A32BB778324A2B3B3E187D59E4289;PATH=/;SECURE;SAMESITE=None Content-Length: 0 Connection: Close
Fingerprint: b1a07937b204538315d3f403854a68665e2b7a35477000a5db5cc4a80baf7299
Cache-control: no-cache="set-cookie" Content-Type: text/html;charset=UTF-8 Date: Fri, 13 Jan 2023 01:03:06 GMT Location: /goanywhere Set-Cookie: RSESSIONID=35A438CCF217BE0C69928325448BC7A7; Path=/; Secure; HttpOnly Set-Cookie: AWSELB=A38937BB086412602C70F15C8454F9CCB7202D224DB2D1FC6DF709D8FEBCDFA197CA4492F40D4E1115B7BEA18539035001B3C443CA948A32BB778324A2B3B3E187D59E4289;PATH=/ Set-Cookie: AWSELBCORS=A38937BB086412602C70F15C8454F9CCB7202D224DB2D1FC6DF709D8FEBCDFA197CA4492F40D4E1115B7BEA18539035001B3C443CA948A32BB778324A2B3B3E187D59E4289;PATH=/;SECURE;SAMESITE=None Content-Length: 0 Connection: Close
Elasticsearch and/or Kibana is currently open without authentication.
This results in all the database data made available publicly.
Fingerprint: 831cb76b8e05df467f309bbf1b0d1225711f87e1711f87e1711f87e1711f87e1
Indices: 2, document count: 8, size: 53.2 kB Found index .opendistro_security with 8 documents (52.9 kB) Found index .kibana_1 with 0 documents (283 B)