Microsoft-IIS 8.5
tcp/80
Sophos Firewall
tcp/8443
xxxx
tcp/8443
The following Sophos firewall is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible since multiple CVEs allow remote attackers to DoS or achieve RCE (Remote code execution) on the firewall. Those vulnerabilities are currently used in ransomware campaign and could damage your network.
Reference:
Severity: critical
Fingerprint: 0b25d4f0a9de5b4d45769e527b15558e7b15558e7b15558e7b15558e7b15558e
Found SOPHOS firewall user portal Vulnerable to CVE-2022-1040
Open service 62.77.40.115:8443
2024-11-20 00:27
HTTP/1.1 302 Found Date: Wed, 20 Nov 2024 00:20:30 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Fri, 20 Dec 2024 00:20:30 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-11-20 00:27
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-11-18 00:18
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-11-18 00:18
HTTP/1.1 302 Found Date: Mon, 18 Nov 2024 00:10:56 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Wed, 18 Dec 2024 00:10:56 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-11-16 01:06
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-11-16 01:06
HTTP/1.1 302 Found Date: Sat, 16 Nov 2024 00:59:20 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Mon, 16 Dec 2024 00:59:20 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-11-02 02:05
HTTP/1.1 302 Found Date: Sat, 02 Nov 2024 01:57:34 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Mon, 02 Dec 2024 01:57:34 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-11-02 02:05
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-10-31 23:25
HTTP/1.1 302 Found Date: Thu, 31 Oct 2024 23:17:51 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Sat, 30 Nov 2024 23:17:51 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-10-31 23:25
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-10-30 00:17
HTTP/1.1 302 Found Date: Wed, 30 Oct 2024 00:10:00 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Fri, 29 Nov 2024 00:10:00 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-10-30 00:17
Found SOPHOS firewall user portal
Open service 62.77.40.115:80
2024-10-28 23:10
HTTP/1.1 200 OK Content-Type: text/html Last-Modified: Thu, 24 Sep 2015 17:27:18 GMT Accept-Ranges: bytes ETag: "7428143eef6d01:0" Server: Microsoft-IIS/8.5 X-Powered-By: ASP.NET Date: Mon, 28 Oct 2024 23:10:33 GMT Connection: close Content-Length: 701 Page title: IIS Windows Server <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /> <title>IIS Windows Server</title> <style type="text/css"> <!-- body { color:#000000; background-color:#0072C6; margin:0; } #container { margin-left:auto; margin-right:auto; text-align:center; } a img { border:none; } --> </style> </head> <body> <div id="container"> <a href="http://go.microsoft.com/fwlink/?linkid=66138&clcid=0x409"><img src="iis-85.png" alt="IIS" width="960" height="600" /></a> </div> </body> </html>
Open service 62.77.40.115:8443
2024-10-21 23:43
HTTP/1.1 302 Found Date: Mon, 21 Oct 2024 23:35:50 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Wed, 20 Nov 2024 23:35:50 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-10-21 23:43
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-10-19 23:44
Found SOPHOS firewall user portal
Open service 62.77.40.115:8443
2024-10-19 23:44
HTTP/1.1 302 Found Date: Sat, 19 Oct 2024 23:37:17 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Mon, 18 Nov 2024 23:37:17 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-10-17 21:53
HTTP/1.1 302 Found Date: Thu, 17 Oct 2024 21:46:33 GMT Server: xxxx X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000 X-Content-Type-Options: nosniff Location: https://62.77.40.115/userportal/webpages/myaccount/login.jsp Cache-Control: max-age=2592000 Expires: Sat, 16 Nov 2024 21:46:33 GMT Content-Length: 244 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://62.77.40.115/userportal/webpages/myaccount/login.jsp">here</a>.</p> </body></html>
Open service 62.77.40.115:8443
2024-10-17 21:53
Found SOPHOS firewall user portal