thttpd 2.25b
tcp/80
This vulnerability kown as CVE-2018-9995 (with proof of concept (PoC) code) affects a wide range of DVR/NVR devices.
Exploiting the vulnerability leads to credentials disclosure and device takeover.
Severity: high
Fingerprint: f46dea8d13f5e4cabc3c1a71fc51e934fc51e934fc51e934fc51e934fc51e934
Running generic DVR software vulnerable to CVE-2018-9995 Found 2 users in the user list
Severity: high
Fingerprint: f46dea8d13f5e4cabc3c1a71d172ef91d172ef91d172ef91d172ef91d172ef91
Running generic DVR software vulnerable to CVE-2018-9995 Found 1 users in the user list
Open service 85.105.249.37:80
2024-12-21 23:55
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>
Open service 85.105.249.37:80
2024-12-17 22:19
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>
Open service 85.105.249.37:80
2024-12-15 21:31
HTTP/1.1 500 Internal Error Server: thttpd/2.25b 29dec2003 Content-Type: text/html; charset=UTF-8 Date: Sun, 15 Dec 2024 20:45:31 GMT Last-Modified: Sun, 15 Dec 2024 20:45:31 GMT Accept-Ranges: bytes Connection: close Cache-Control: no-cache,no-store Page title: 500 Internal Error <HTML> <HEAD><TITLE>500 Internal Error</TITLE></HEAD> <BODY BGCOLOR="#cc9999" TEXT="#000000" LINK="#2020ff" VLINK="#4040cc"> <H2>500 Internal Error</H2> There was an unusual problem serving the requested URL '/'. <HR> <ADDRESS><A HREF="http://www.acme.com/software/thttpd/">thttpd/2.25b 29dec2003</A></ADDRESS> </BODY> </HTML> HTTP/1.0 200 OK Common:CDebugger:SetLevel already close, Current output=0(0:std;1:file;10:telnet) [httpd:main.cpp:main:16 T:121503.5930] ======== /usr/local/bin/httpd start, argc:1 ========= [httpd:main.cpp:main:49 T:121503.5930]Httpd Wait web port param =============httpd get web port httpd not get port param, Web Port=80 [httpd:main.cpp:main:52 T:121503.5930]Pack httpd param port:80 ========================================================= =====================httpd(1344) v1.1==================== ====[/usr/local/bin]===[/usr/local/www]===(port:0080)==== ========================================================= ----debug state=1 max connect=4096 socket :: - Address family not supported by protocol thttpd main loop is run terminate=0 num_connect=0
Open service 85.105.249.37:80
2024-12-13 23:32
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>
Open service 85.105.249.37:80
2024-12-11 23:47
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>
Open service 85.105.249.37:80
2024-12-02 00:08
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>
Open service 85.105.249.37:80
2024-11-30 00:48
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>
Open service 85.105.249.37:80
2024-11-27 23:39
HTTP/1.0 302 Found content-type: text/html; charset=UTF-8 P3P: CP='IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT' Location: /login.rsp Page title: 302 Moved <HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8"><TITLE>302 Moved</TITLE></HEAD><BODY><H1>302 Moved</H1>The document has moved<A HREF='/login.rsp'>here</a></BODY></HTML>