# Nmap 7.98 scan initiated Sun Apr  5 08:04:07 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/influxdb.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/influxdb.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml influxdb.lan.ddnsgeek.com
Nmap scan report for influxdb.lan.ddnsgeek.com (167.179.167.166)
Host is up, received user-set (0.016s latency).
rDNS record for 167.179.167.166: 167-179-167-166.a7b3a7.bne.nbn.aussiebb.net
Scanned at 2026-04-05 08:04:16 UTC for 1423s

PORT    STATE SERVICE  REASON         VERSION
443/tcp open  ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
| http-waf-detect: IDS/IPS/WAF detected:
|_influxdb.lan.ddnsgeek.com:443/?p4yl04d3=<script>alert(document.cookie)</script>
|_http-userdir-enum: Potential Users: root, admin, administrator, webadmin, sysadmin, netadmin, guest, user, web, test
| http-vhosts: 
| auth.lan.ddnsgeek.com : 200
|_127 names had status 404
|_http-comments-displayer: Couldn't find any comments.
| ssl-cert: Subject: commonName=influxdb.lan.ddnsgeek.com
| Subject Alternative Name: DNS:influxdb.lan.ddnsgeek.com
| Issuer: commonName=R13/organizationName=Let's Encrypt/countryName=US
| Public Key type: rsa
| Public Key bits: 4096
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-22T15:48:20
| Not valid after:  2026-05-23T15:48:19
| MD5:     2a1b dec6 e158 18fd 5a4a ace0 d181 9bd2
| SHA-1:   9eaa 81c0 a726 6a3f c295 b0c2 83d9 dffa bf04 ec2c
| SHA-256: 7178 7a7d 4ff9 9bfc 5a9d c12c 7c36 bed6 5b04 a25d b1c9 9d97 21e1 b4e7 f65d 211f
| -----BEGIN CERTIFICATE-----
| MIIGBjCCBO6gAwIBAgISBiJMDiooySXBowJ+bWDK/3cUMA0GCSqGSIb3DQEBCwUA
| MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD
| EwNSMTMwHhcNMjYwMjIyMTU0ODIwWhcNMjYwNTIzMTU0ODE5WjAkMSIwIAYDVQQD
| ExlpbmZsdXhkYi5sYW4uZGRuc2dlZWsuY29tMIICIjANBgkqhkiG9w0BAQEFAAOC
| Ag8AMIICCgKCAgEA5wCxN+Nivlj4W10Y2kYaVvFJlbeiLT+1dSVOcgDyW5yRhFvN
| Cw79BuzmFzqEKzYG2Ogz8Z5FMuWltSt6I/V76/qoKtlYCWbF7/QctbqAJz/3qSbK
| fj7IN4zDaHSU+nfGD5BGJmp4Haw2bdI7jyLcvHUj8O/FsA+Rq9VJBzNVgrjzPSS3
| sKDr1wKvOoL6bKQahxJy9LM3LCU8BQKQcLdGlJKghVzZRxH2Yb/MkNuAQyrnVFMX
| xxzshQDDWzFoHNSuMCl8FUk+dPOfHhyVFwwewHPzvMQ7nUQH6hcZXLqCDLgXRQ8z
| lHZ4qxkUrSch+/L1gvW7Oye4Jul+oRqRAOfPaO+XsrMxNtxYF+7T20GMmKpU4Z1l
| yQriVB300aNYyBhICq0cgE57yyRIpLubu+xs0yuBSl70nCY7Jv2W+fHSTL4BuWfh
| 25QKXJ+7bf8m0l5jUJKInXlaP9q8RVD26as+J2vV8fh1JK1XrfylOSEQnNUQGbUB
| 4wHDR05r7Qkxq8ikLvDeaR9GJf42CThojrxetCW6MQLebTgJhnZKvNUIEoAJEjUz
| 44dRtBm39EXtF6tBb6J4Pkl4I72rBGDgCqYQNjsjYlSXo4PRBsiozZwL7IIkHfyE
| yR1WSmltxtLTCbFiIAcpDkRSvbnsSJu7mgX4gc07Jvbk/qIa73B/wDEQ3acCAwEA
| AaOCAiEwggIdMA4GA1UdDwEB/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAM
| BgNVHRMBAf8EAjAAMB0GA1UdDgQWBBQ54eJPhXqWn+SZMf4C1w4P2Bqk3zAfBgNV
| HSMEGDAWgBTnq58PLDOgU9NeT3jIsoQOO9aSMzAzBggrBgEFBQcBAQQnMCUwIwYI
| KwYBBQUHMAKGF2h0dHA6Ly9yMTMuaS5sZW5jci5vcmcvMCQGA1UdEQQdMBuCGWlu
| Zmx1eGRiLmxhbi5kZG5zZ2Vlay5jb20wEwYDVR0gBAwwCjAIBgZngQwBAgEwLgYD
| VR0fBCcwJTAjoCGgH4YdaHR0cDovL3IxMy5jLmxlbmNyLm9yZy8yMS5jcmwwggEG
| BgorBgEEAdZ5AgQCBIH3BIH0APIAdwAWgy2r8KklDw/wOqVF/8i/yCPQh0v2BCkn
| +OcfMxP1+gAAAZyGPyK0AAAEAwBIMEYCIQD1WEtgs1xEwCPrbZdVMfcCj+rsTBCN
| WKOxicyyG+8bCQIhAJTRIVgxeosMZpapiSuLKhYfpYzpwWMqq811YAQNWZE2AHcA
| lpdkv1VYl633Q4doNwhCd+nwOtX2pPM2bkakPw/KqcYAAAGchj8i7gAABAMASDBG
| AiEAtraWpCgfwscmWV/gszD3AbV3rmZYyydqkFg9mmfyN6ACIQCNPk7QpFXQQyM5
| OccIFebEbJCLIJz/BM4ctpLVtKouczANBgkqhkiG9w0BAQsFAAOCAQEAa70krO3l
| lsUx6m/RWEZk72zXBmpKFTMkkXTA8IJfKwOndOyAUhc8MhiuQY0eZK0xKcIILisr
| RSpqE+7yg8OFVD7SwA3hsURa75cdCx+SL3s2EKZTdAJEuVM6a3YCetdalmhFjsdq
| 1TV9l4+4ZB8mbNB4l6IMn3MobBwS04xpco5SiY1/8DTbyQztnvweSNJ6a+Y9e/Jo
| U+4BfZrWkCeS2NLq7QLMKoEuOxHnPGipbqd6uTARvkvrh8dnF9cAPc6tLYdpK6Yq
| MFlXrNJ3FArKKLMHNfPuhU+K6eoq2B0xBra4Rhho0avawUz7y6QEkCF6OtIWSCBy
| DxHdWeF7YfmABQ==
|_-----END CERTIFICATE-----
|_http-referer-checker: Couldn't find any cross-domain scripts.
| http-headers: 
|   Content-Type: text/plain; charset=utf-8
|   X-Content-Type-Options: nosniff
|   Date: Sun, 05 Apr 2026 08:04:36 GMT
|   Content-Length: 19
|   Connection: close
|   
|_  (Request type: GET)
|_http-date: Sun, 05 Apr 2026 08:04:36 GMT; -17s from local time.
|_http-fetch: Please enter the complete path of the directory to save data in.
|_http-csrf: Couldn't find any CSRF vulnerabilities.
| http-security-headers: 
|   Strict_Transport_Security: 
|     Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|   X_Frame_Options: 
|     Header: X-Frame-Options: SAMEORIGIN
|     Description: The browser must not display this content in any frame from a page of different origin than the content itself.
|   X_XSS_Protection: 
|     Header: X-XSS-Protection: 1; mode=block
|     Description: The browser will prevent the rendering of the page when XSS is detected.
|   X_Content_Type_Options: 
|     Header: X-Content-Type-Options: nosniff
|_    Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. 
| http-errors: 
| Spidering limited to: maxpagecount=40; withinhost=influxdb.lan.ddnsgeek.com
|   Found the following error pages: 
|   
|   Error Code: 404
|_  	http://influxdb.lan.ddnsgeek.com:443/
|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
| ssl-enum-ciphers: 
|   TLSv1.2: 
|     ciphers: 
|       TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A
|     compressors: 
|       NULL
|     cipher preference: client
|     warnings: 
|       Key exchange (secp256r1) of lower strength than certificate key
|   TLSv1.3: 
|     ciphers: 
|       TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A
|       TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A
|       TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A
|     cipher preference: server
|_  least strength: A
|_http-malware-host: Host appears to be clean
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
|_ssl-date: TLS randomness does not represent time
|_http-iis-webdav-vuln: Could not determine vulnerability, since root folder is password protected
|_http-chrono: Request times for /; avg: 6444.75ms; min: 1693.69ms; max: 24941.11ms
| http-sitemap-generator: 
|   Directory structure:
|   Longest directory structure:
|     Depth: 0
|     Dir: /
|   Total files found (by extension):
|_    
|_http-feed: Couldn't find any feeds.
|_http-mobileversion-checker: No mobile version detected.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-enum: 
|   /health/: Spring Boot Actuator endpoint
|   /healthcheck/: Spring Boot Actuator endpoint
|_  /healthchecks/: Spring Boot Actuator endpoint
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
| http-auth: 
| HTTP/1.1 401 Unauthorized\x0D
|_  Server returned status 401 but no WWW-Authenticate header.
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
|_http-title: Site doesn't have a title (text/plain; charset=utf-8).
| http-useragent-tester: 
|   Status for browser useragent: 404
|   Allowed User Agents: 
|     GT::WWW
|   Change in Status Code: 
|     libwww: 401
|     WWW-Mechanize/1.34: 401
|     URI::Fetch: 401
|     PECL::HTTP: 401
|     PHP/: 401
|     http client: 401
|     Zend_Http_Client: 401
|     PHPCrawl: 401
|     libcurl-agent/1.0: 401
|     lwp-trivial: 401
|     Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html): 401
|     Wget/1.13.4 (linux-gnu): 401
|     HTTP::Lite: 401
|     Snoopy: 401
|     Python-urllib/2.5: 401
|_    MFC_Tear_Sample: 401
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| http-wordpress-enum: 
| Search limited to top 100 themes/plugins
|   themes
|     astra
|     twentyseventeen
|     twentyfifteen
|     twentynineteen
|     twentytwenty
|     twentysixteen
|     twentyfourteen
|     twentytwentyone
|     hello-elementor
|     twentythirteen
|     oceanwp
|     twentytwelve
|     storefront
|     twentyeleven
|     twentytwentytwo
|     twentyten
|     generatepress
|     twentytwentythree
|     neve
|     responsive
|     sydney
|     blocksy
|     hestia
|     customizr
|     colormag
|     kadence
|     vantage
|     hueman
|     twentytwentyfour
|     spacious
|     lightning
|     virtue
|     newsup
|     onepress
|     specia
|     ashe
|     mh-magazine-lite
|     zakra
|     sinatra
|     phlox
|     mesmerize
|     evolve
|     graphene
|     shapely
|     colibri-wp
|     sparkling
|     colorway
|     enigma
|     make
|     flash
|     customify
|     total
|     mantra
|     appointment
|     ifeature
|     inspiro
|     go
|     covernews
|     iconic-one
|     popularfx
|     minamaze
|     omega
|     twentytwentyfive
|     catch-box
|     bard
|     bizberg
|     dispatch
|     poseidon
|     page-builder-framework
|     illdy
|     coraline
|     accelerate
|     alexandria
|     pinboard
|     hemingway
|     wallstreet
|     royal-elementor-kit
|     portfolio-press
|     startkit
|     radiate
|     attitude
|     nirvana
|     arilewp
|     avril
|     custom-community
|     argent
|     blogus
|     rife-free
|     raindrops
|     activello
|     tempera
|     spicepress
|     mystique
|     estore
|     sela
|     suevafree
|     delicate
|     travelify
|     woostify
|     agama
|   plugins
|     wordpress-seo
|     elementor
|     jetpack
|     wordfence
|     woocommerce
|     contact-form-7
|     akismet
|     wpforms-lite
|     google-analytics-for-wordpress
|     google-site-kit
|     really-simple-ssl
|     all-in-one-seo-pack
|     all-in-one-wp-migration
|     updraftplus
|     seo-by-rank-math
|     optinmonster
|     litespeed-cache
|     essential-addons-for-elementor-lite
|     sg-cachepress
|     classic-editor
|     astra-sites
|     the-events-calendar
|     limit-login-attempts-reloaded
|     insert-headers-and-footers
|     wp-mail-smtp
|     mailchimp-for-wp
|     redirection
|     advanced-custom-fields
|     wp-smushit
|     wordpress-importer
|     wp-super-cache
|     w3-total-cache
|     wp-fastest-cache
|     siteorigin-panels
|     mailpoet
|     ninja-forms
|     wp-optimize
|     google-analytics-dashboard-for-wp
|     duplicator
|     instagram-feed
|     header-footer-elementor
|     premium-addons-for-elementor
|     gutenberg
|     so-widgets-bundle
|     facebook-for-woocommerce
|     nextgen-gallery
|     woocommerce-services
|     ewww-image-optimizer
|     autoptimize
|     google-sitemap-generator
|     woocommerce-gateway-stripe
|     cookie-law-info
|     duplicate-post
|     elementskit-lite
|     woocommerce-payments
|     tinymce-advanced
|     ultimate-addons-for-gutenberg
|     better-wp-security
|     google-listings-and-ads
|     mainwp-child
|     all-in-one-wp-security-and-firewall
|     cookie-notice
|     wp-statistics
|     loco-translate
|     ml-slider
|     newsletter
|     duplicate-page
|     redux-framework
|     sg-security
|     coming-soon
|     yith-woocommerce-wishlist
|     kadence-blocks
|     sucuri-scanner
|     wp-file-manager
|     wps-hide-login
|     loginizer
|     disable-comments
|     wp-google-maps
|     coblocks
|     ocean-extra
|     formidable
|     polylang
|     worker
|     shortcodes-ultimate
|     mailchimp-for-woocommerce
|     regenerate-thumbnails
|     complianz-gdpr
|     creative-mail-by-constant-contact
|     meta-box
|     user-role-editor
|     broken-link-checker
|     custom-post-type-ui
|     smart-slider-3
|     cleantalk-spam-protect
|     tablepress
|     photo-gallery
|     backwpup
|     woocommerce-paypal-payments
|     accelerated-mobile-pages
|_    woocommerce-pdf-invoices-packing-slips

Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Apr  5 08:28:01 2026 -- 1 IP address (1 host up) scanned in 1434.42 seconds
