The following are the details of the server:
hostname:informatics.edu.np
uptime:803209s
last reboot:Thu July 08 9:36:45 2010
ip: 74.54.219.66
hostnames:(name-type)
informatics.edu.np-user
lamborghini.websitewelcome.com-PTR
OS-DD_WRT v23(linux kernel version 2.4.36)(ports used: 21,231)
The details are as follows:
Port | Protocol | State(0-open/x-filtered) | Service/version |
7 | TCP | X | echo |
9 | TCP | X | Discard |
13 | TCP | X | Daytime |
21 | TCP | 0 | ftp/PureFTPd |
22 | TCP | X | Ssh |
25 | TCP | X | SMTP |
26 | TCP | 0 | Smtp/EximSMTPd 469 |
53 | TCP | 0 | Domain |
80 | TCP | 0 | http |
110 | TCP | 0 | Pop3/CourierPOP3d |
135 | TCP | X | Msrpc |
139 | TCP | X | Netbios-ssn |
143 | TCP | 0 | Imap/CourierIMAPd 2006 released |
443 | TCP | 0 | |
445 | TCP | X | Microsoft-ds |
465 | TCP | 0 | |
993 | TCP | 0 | Imap/CourierIMAPd2008 released |
995 | TCP | 0 | |
5800 | TCP | X | Vnc-http |
5900 | TCP | x | vnc |
also more than that i think that it is vulnerable to the sqli attack
url entered: http://www.informatics.edu.np/about_us.php?inst=asdasdvasdv
returned: ERROR: Unknown column 'asdasdvasdv' in 'where clause'
url entered:http://www.informatics.edu.np/course_matter.php?mid=asdvasdv
returned: Unknown column 'asdvasdv' in 'where clause'
also the college uses the webmail based in zimbra...you can look at milw0rm for the vuls of zimbra( i dont want to tell the which version it is....try this by your own)
म एडम्स KEVIN, Aiico बीमा plc को एक प्रतिनिधि, हामी भरोसा र एक ऋण बाहिर दिन मा व्यक्तिगत मतभेद आदर। हामी ऋण चासो दर को 2% प्रदान गर्नेछ। तपाईं यस व्यवसाय मा चासो हो भने अब आफ्नो ऋण कागजातहरू ठीक जारी हस्तांतरण ई-मेल (adams.credi@gmail.com) गरेर हामीलाई सम्पर्क। Plc.you पनि इमेल गरेर हामीलाई सम्पर्क गर्न सक्नुहुन्छ तपाईं aiico बीमा गर्न धेरै स्वागत छ भने व्यापार वा स्कूल स्थापित गर्न एक ऋण आवश्यकता हो (aiicco_insuranceplc@yahoo.com) हामी सन्तुलन स्थानान्तरण अनुरोध गर्न सक्छौं पहिलो हप्ता।
ReplyDeleteव्यक्तिगत व्यवसायका लागि ऋण चाहिन्छ? तपाईं आफ्नो इमेल संपर्क भने उपरोक्त तुरुन्तै आफ्नो ऋण स्थानान्तरण प्रक्रिया गर्न
ठीक।