Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- | |__ | | __ _ ___| | _| |__ __ _| |_ __ _| | ___ | |__ __ _| |
- | '_ \| |/ _` |/ __| |/ / '_ \ / _` | __| / _` | |/ _ \| '_ \ / _` | |
- | |_) | | (_| | (__| <| | | | (_| | |_ | (_| | | (_) | |_) | (_| | |
- |_.__/|_|\__,_|\___|_|\_\_| |_|\__,_|\__| \__, |_|\___/|_.__/ \__,_|_|
- |___/
- TARGET: https://www.yesbackpage.com/
- https://ibb.co/n8C3ptz
- https://ibb.co/T8z65WP
- https://ibb.co/g6pW0Lb
- https://ibb.co/bXNc10w
- https://ibb.co/3Tjb9y1
- https://ibb.co/Rysf0ht
- https://ibb.co/1MMNYb3
- https://ibb.co/WkRCJJQ
- https://ibb.co/612SRnT
- https://ibb.co/7Cpm0SM
- email address:
- https://www.yesbackpage.com/contact-us
- Registrar:
- https://yesbackpage.com.ipaddress.com/
- domain history:
- https://securitytrails.com/domain/yesbackpage.com/history/a
- What does that means?
- Imagine the website originally had the IP Address:
- 199.188.200.48
- then passed to the next IP Address:
- 136.144.132.31
- We can ignore the IP Addresses that are shown as 1 day only cause they switched from one IP to the other.
- So please ignore the 1 day IP Addresses history.
- Finally they passed to the Cloudflare DNS.
- Now the Cloudflare DNS masquerade the real IP Address of the website.
- Cloudflare self doesn't host the website.
- They only host the DNS of the website.
- So everytime you navigate the website you'll always see Cloudflare DNS but the webhost is not there.
- Domain Creation Date April 11, 2018
- What are YesBackpage.com's nameservers?
- DNS for YesBackpage.com is provided by the nameservers
- clark.ns.cloudflare.com
- and
- liv.ns.cloudflare.com.
- Who is the registrar for the YesBackpage.com domain?
- The domain has been registered at Key-Systems GmbH. You can visit the registrar's website at http://www.key-systems.net.
- The registrar's WHOIS server can be reached at whois.rrpproxy.net.
- Site is registered in Germany by Key-Systems GmbH.
- This is their WebHosting Company:
- https://www.key-systems.net/
- and this is the NameCheap for the Domain Name:
- http://dc-7a362e5dec9e.yes back page.com/cgi-sys/defaultwebpage.cgi
- IP address: 198.187.29.237
- Reverse DNS (PTR record)
- business17-1.web- hosting.com
- https://www.shodan.io/host/198.187.29.237
- https://www.ipneighbour.com/#/lookup/business17-1.web-hosting.com
- https://www.dailydot.com/irl/mailchimp-sex-trafficking-lawsuit/
- [*] Searching Twitter usernames using Google.
- [*] Users found: 17
- ---------------------
- @Aryaunna_heart
- @BeauchampNaomie
- @Jessi4BBC1
- @MistressMiaVon
- @Nick_Ramsy
- @RisaJenner
- @TheMistressNova
- @TheYesBackpage
- @WarrenB850
- @bigtsbitches
- @dearmasarmando
- @denisecouponer
- @mabe_misty
- @mskarinsin
- @sinndatruth
- @trt_FAMU
- https://www.whatruns.com/website/yesbackpage.com
- Technologies Used by Yesbackpage.com
- Web Framework
- Bootstrap
- Tag Managers
- Google Tag Manager
- Javascript Frameworks
- jQuery 1.4.1
- Web Server
- Apache 2.4.23
- https://censys.io/ipv4/149.210.248.3
- https://censys.io/ipv4/149.210.248.4
- https://censys.io/ipv4/149.210.248.98
- https://censys.io/ipv4/149.210.248.99
- root@blackbox:/opt/WhatWeb# amass enum -d yesbackpage.de
- mail.yesbackpage.de
- sendmail.yesbackpage.de
- webmail.yesbackpage.de
- newhosting.yesbackpage.de
- hostingserver.yesbackpage.de
- dc-d3321fe7c60f.yesbackpage.de
- yesbackpage.de
- www.yesbackpage.de
- OWASP Amass v3.1.10 https://github.com/OWASP/Amass
- --------------------------------------------------------------------------------
- 8 names discovered - api: 4, cert: 2, dns: 2
- --------------------------------------------------------------------------------
- ASN: 13335 - CLOUDFLARENET
- 104.26.0.0/20 12 Subdomain Name(s)
- 172.67.64.0/20 5 Subdomain Name(s)
- 2606:4700:20::/44 15 Subdomain Name(s)
- ASN: 22612 - NAMECHEAP-NET
- 198.187.29.0/24 1 Subdomain Name(s)
- https://www.shodan.io/search?query=hostingserver.yesbackpage.de
- https://www.shodan.io/host/149.210.248.3
- root@blackbox:/opt# dmitry -winsepfb host hostingserver.yesbackpage.de
- Deepmagic Information Gathering Tool
- "There be some deep magic going on"
- HostIP:149.210.248.98
- HostName:hostingserver.yesbackpage.de
- Gathered Inet-whois information for 149.210.248.98
- ---------------------------------
- inetnum: 149.210.248.0 - 149.210.248.255
- netname: TRANSIP-NL-VPS-POD5-AMS4-CUSTOMERS
- descr:
- country: NL
- admin-c: IPRO1-RIPE
- tech-c: IPRO1-RIPE
- status: ASSIGNED PA
- remarks: -------------------------------------------------------
- remarks: Network abuse reports: [email protected]
- remarks: NOC and contact details: http://www.transip.nl/contact/
- remarks: -------------------------------------------------------
- mnt-by: TRANSIP-MNT
- mnt-lower: TRANSIP-MNT
- mnt-routes: TRANSIP-MNT
- created: 2018-02-05T15:01:34Z
- last-modified: 2018-02-05T15:01:34Z
- source: RIPE
- role: TransIP B.V. Admin
- address: Schipholweg 9B
- address: 2316 XB Leiden
- address: NL
- remarks: -------------------------------------------------------
- remarks: Network abuse reports: [email protected]
- remarks: NOC and contact details: http://www.transip.nl/contact/
- remarks: -------------------------------------------------------
- phone: +31 71 524 1919
- fax-no: +31 71 524 1918
- abuse-mailbox: [email protected]
- admin-c: RSK48-RIPE
- tech-c: IPRS1-RIPE
- nic-hdl: IPRO1-RIPE
- mnt-by: TRANSIP-MNT
- created: 2003-05-10T09:33:07Z
- last-modified: 2018-02-18T14:20:18Z
- source: RIPE # Filtered
- % Information related to '149.210.128.0/17AS20857'
- route: 149.210.128.0/17
- descr: TransIP BV
- descr: Amsterdam, The Netherlands
- origin: AS20857
- mnt-by: TRANSIP-MNT
- mnt-lower: TRANSIP-MNT
- mnt-routes: TRANSIP-MNT
- created: 2013-04-12T15:07:15Z
- last-modified: 2013-04-12T15:07:15Z
- source: RIPE # Filtered
- % This query was served by the RIPE Database Query Service version 1.97.1 (ANGUS)
- Gathered TCP Port information for 149.210.248.98
- ---------------------------------
- Port State
- 21/tcp open
- >> 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------
- 220-You are user number 1 of 50 allowed.
- 220-Local time is now 0���b
- 22/tcp open
- >> SSH-2.0-OpenSSH_7.4
- 53/tcp open
- Portscan Finished: Scanned 150 ports, 98 ports were in state closed
- http://hostingserver.yesbackpage.de/domainnotknown.html
- Hostnames newhosting.yesbackpage.de
- root@blackbox:/opt# nmap -A -Pn 149.210.248.3
- Starting Nmap 7.80 ( https://nmap.org ) at 2020-07-05 14:05 CDT
- Nmap scan report for newhosting.yesbackpage.de (149.210.248.3)
- Host is up (0.13s latency).
- Not shown: 988 filtered ports
- PORT STATE SERVICE VERSION
- 21/tcp open ftp Pure-FTPd
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:11
- |_Not valid after: 2020-11-05T19:23:11
- |_ssl-date: TLS randomness does not represent time
- 22/tcp open ssh OpenSSH 7.4 (protocol 2.0)
- | ssh-hostkey:
- | 2048 4d:dd:1a:1e:36:7b:97:7e:64:43:6f:10:1e:d4:ae:7b (RSA)
- | 256 23:b9:77:f9:3d:46:1c:26:e1:b4:82:29:c3:8f:8b:1a (ECDSA)
- |_ 256 17:43:31:05:08:cd:e9:dc:90:b8:7e:74:67:90:a6:cb (ED25519)
- 53/tcp open domain ISC BIND 9.11.4-P2 (RedHat Enterprise Linux 7)
- | dns-nsid:
- |_ bind.version: 9.11.4-P2-RedHat-9.11.4-16.P2.el7_8.6
- 80/tcp open http Apache httpd
- |_http-server-header: Apache
- | http-title: 404 Not Found
- |_Requested resource was http://hostingserver.yesbackpage.de/domainnotknown.html
- 110/tcp open pop3 Dovecot pop3d
- |_pop3-capabilities: CAPA USER PIPELINING SASL(PLAIN LOGIN) RESP-CODES TOP UIDL STLS AUTH-RESP-CODE
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:10
- |_Not valid after: 2020-11-05T19:23:10
- 143/tcp open imap Dovecot imapd
- |_imap-capabilities: LOGIN-REFERRALS AUTH=LOGINA0001 IMAP4rev1 more Pre-login have listed NAMESPACE AUTH=PLAIN STARTTLS OK ID ENABLE IDLE post-login SASL-IR LITERAL+ capabilities
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:10
- |_Not valid after: 2020-11-05T19:23:10
- 443/tcp open http Apache httpd
- |_http-server-header: Apache
- |_http-title: Did not follow redirect to http://hostingserver.yesbackpage.de/domainnotknown.html
- 465/tcp open ssl/smtp Exim smtpd 4.93
- | smtp-commands: hostingserver.yesbackpage.de Hello newhosting.yesbackpage.de [82.102.16.196], SIZE 52428800, 8BITMIME, PIPELINING, AUTH PLAIN LOGIN, HELP,
- |_ Commands supported: AUTH HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:10
- |_Not valid after: 2020-11-05T19:23:10
- 587/tcp open smtp Exim smtpd 4.93
- | smtp-commands: hostingserver.yesbackpage.de Hello newhosting.yesbackpage.de [82.102.16.196], SIZE 52428800, 8BITMIME, PIPELINING, STARTTLS, HELP,
- |_ Commands supported: AUTH STARTTLS HELO EHLO MAIL RCPT DATA BDAT NOOP QUIT RSET HELP
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:10
- |_Not valid after: 2020-11-05T19:23:10
- 993/tcp open imaps?
- |_imap-capabilities: LOGIN-REFERRALS AUTH=LOGINA0001 IMAP4rev1 more Pre-login have listed NAMESPACE post-login OK ID ENABLE IDLE AUTH=PLAIN SASL-IR LITERAL+ capabilities
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:10
- |_Not valid after: 2020-11-05T19:23:10
- 995/tcp open pop3s?
- |_pop3-capabilities: TOP PIPELINING SASL(PLAIN LOGIN) RESP-CODES USER UIDL AUTH-RESP-CODE CAPA
- | ssl-cert: Subject: commonName=hostingserver.yesbackpage.de
- | Subject Alternative Name: DNS:hostingserver.yesbackpage.de
- | Not valid before: 2019-11-06T19:23:10
- |_Not valid after: 2020-11-05T19:23:10
- Device type: general purpose|storage-misc|firewall
- Running (JUST GUESSING): Linux 4.X|3.X|2.6.X (92%), Synology DiskStation Manager 5.X (85%), WatchGuard Fireware 11.X (85%)
- OS CPE: cpe:/o:linux:linux_kernel:4.0 cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel cpe:/a:synology:diskstation_manager:5.1 cpe:/o:watchguard:fireware:11.8
- Aggressive OS guesses: Linux 4.0 (92%), Linux 3.10 - 3.12 (91%), Linux 4.4 (91%), Linux 3.10 (90%), Linux 3.10 - 3.16 (90%), Linux 4.9 (89%), Linux 3.11 - 4.1 (86%), Linux 3.16 (86%), Linux 2.6.32 or 3.10 (86%), Linux 4.2 (86%)
- No exact OS matches for host (test conditions non-ideal).
- Network Distance: 11 hops
- Service Info: Host: hostingserver.yesbackpage.de; OS: Linux; CPE: cpe:/o:redhat:enterprise_linux:7
- TRACEROUTE (using port 20/tcp)
- HOP RTT ADDRESS
- 1 150.55 ms 10.16.0.1
- 2 ...
- 3 150.67 ms vlan164.as11.fra4.de.m247.com (82.102.16.193)
- 4 150.67 ms vlan2917.agg1.fra4.de.m247.com (212.103.51.190)
- 5 150.70 ms vlan299.bb2.fra1.de.m247.com (185.206.226.92)
- 6 150.70 ms te0-0-0-9.agr21.fra06.atlas.cogentco.com (149.11.20.249)
- 7 150.72 ms be2844.rcr22.fra06.atlas.cogentco.com (130.117.0.29)
- 8 150.72 ms be2846.ccr42.fra03.atlas.cogentco.com (154.54.37.29)
- 9 ...
- 10 79.39 ms be2456.rcr21.b015960-1.ams03.atlas.cogentco.com (130.117.49.146)
- 11 137.41 ms newhosting.yesbackpage.de (149.210.248.3)
- OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
- Nmap done: 1 IP address (1 host up) scanned in 174.33 seconds
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement