# Nmap 7.98 scan initiated Sun Apr  5 08:49:58 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/portainer.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/portainer.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml portainer.lan.ddnsgeek.com
Nmap scan report for portainer.lan.ddnsgeek.com (167.179.167.166)
Host is up, received user-set (0.015s latency).
rDNS record for 167.179.167.166: 167-179-167-166.a7b3a7.bne.nbn.aussiebb.net
Scanned at 2026-04-05 08:50:07 UTC for 1015s

PORT    STATE SERVICE  REASON         VERSION
443/tcp open  ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
| http-grep: 
|   (4) http://portainer.lan.ddnsgeek.com:443/vendor.5912aaf498ef1cf92d1e.css: 
|     (4) email: 
|       + rzajac@gmail.com
|       + valentin@hervi.eu
|       + jusasi@gmail.com
|_      + angelin.sirbu@gmail.com
|_http-date: Sun, 05 Apr 2026 08:53:34 GMT; -4s from local time.
|_http-malware-host: Host appears to be clean
| http-security-headers: 
|   Strict_Transport_Security: 
|     Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|   X_Frame_Options: 
|     Header: X-Frame-Options: SAMEORIGIN
|     Description: The browser must not display this content in any frame from a page of different origin than the content itself.
|   X_XSS_Protection: 
|     Header: X-XSS-Protection: 1; mode=block
|     Description: The browser will prevent the rendering of the page when XSS is detected.
|   X_Content_Type_Options: 
|     Header: X-Content-Type-Options: nosniff
|     Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. 
|   Content_Security_Policy: 
|     Header: Content-Security-Policy: script-src 'self' https://js.hsforms.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; object-src 'none'; frame-ancestors 'none'; frame-src https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/
|     Description: Define which scripts the protected resource can execute.
|     Description: Define from where the protected resource can load plugins.
|     Description: Deprecated and replaced by child-src. Define from where the protected resource can embed frames.
|     Description: Define from where the protected resource can be embedded in frames.
|   Cache_Control: 
|_    Header: Cache-Control: max-age=31536000
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
|_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-mobileversion-checker: No mobile version detected.
|_http-title: Portainer
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
|_http-fetch: Please enter the complete path of the directory to save data in.
|_http-comments-displayer: Couldn't find any comments.
| http-sitemap-generator: 
|   Directory structure:
|     /
|       Other: 1
|   Longest directory structure:
|     Depth: 0
|     Dir: /
|   Total files found (by extension):
|_    Other: 1
| http-vhosts: 
| auth.lan.ddnsgeek.com : 200
|_127 names had status 404
| http-methods: 
|_  Supported Methods: GET HEAD POST OPTIONS
| ssl-enum-ciphers: 
|   TLSv1.2: 
|     ciphers: 
|       TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A
|     compressors: 
|       NULL
|     cipher preference: client
|     warnings: 
|       Key exchange (secp256r1) of lower strength than certificate key
|   TLSv1.3: 
|     ciphers: 
|       TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A
|       TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A
|       TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A
|     cipher preference: server
|_  least strength: A
| http-headers: 
|   Accept-Ranges: bytes
|   Cache-Control: max-age=31536000
|   Content-Length: 14202
|   Content-Security-Policy: script-src 'self' https://js.hsforms.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/; object-src 'none'; frame-ancestors 'none'; frame-src https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/
|   Content-Type: text/html; charset=utf-8
|   Date: Sun, 05 Apr 2026 08:53:28 GMT
|   Last-Modified: Thu, 19 Mar 2026 21:55:31 GMT
|   Permissions-Policy: accelerometer=(),ambient-light-sensor=(),attribution-reporting=(),autoplay=(),battery=(),browsing-topics=(),camera=(),captured-surface-control=(),ch-device-memory=(),ch-downlink=(),ch-dpr=(),ch-ect=(),ch-prefers-color-scheme=(),ch-prefers-reduced-motion=(),ch-prefers-reduced-transparency=(),ch-rtt=(),ch-save-data=(),ch-ua=(),ch-ua-arch=(),ch-ua-bitness=(),ch-ua-form-factors=(),ch-ua-full-version=(),ch-ua-full-version-list=(),ch-ua-mobile=(),ch-ua-model=(),ch-ua-platform=(),ch-ua-platform-version=(),ch-ua-wow64=(),ch-viewport-height=(),ch-viewport-width=(),ch-width=(),compute-pressure=(),conversion-measurement=(),cross-origin-isolated=(),deferred-fetch=(),deferred-fetch-minimal=(),display-capture=(),document-domain=(),encrypted-media=(),execution-while-not-rendered=(),execution-while-out-of-viewport=(),focus-without-user-activation=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),hid=(),identity-credentials-get=(),idle-detection=(),interest-cohort=(),join-ad-interest-group=(),keyboard-map=(),language-detector=(),local-fonts=(),magnetometer=(),microphone=(),midi=(),navigation-override=(),otp-credentials=(),payment=(),picture-in-picture=(),private-aggregation=(),private-state-token-issuance=(),private-state-token-redemption=(),publickey-credentials-create=(),publickey-credentials-get=(),rewriter=(),run-ad-auction=(),screen-wake-lock=(),serial=(),shared-storage=(),shared-storage-select-url=(),speaker-selection=(),storage-access=(),summarizer=(),sync-script=(),sync-xhr=(),translator=(),trust-token-redemption=(),unload=(),usb=(),vertical-scroll=(),web-share=(),window-management=(),window-placement=(),writer=(),xr-spatial-tracking=()
|   Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|   Vary: Accept-Encoding
|   X-Content-Type-Options: nosniff
|   X-Csrf-Token: 
|   X-Frame-Options: SAMEORIGIN
|   X-Xss-Protection: 1; mode=block
|   Connection: close
|   
|_  (Request type: HEAD)
|_http-errors: ERROR: Script execution failed (use -d to debug)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
| http-useragent-tester: 
|   Status for browser useragent: 200
|   Allowed User Agents: 
|     Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
|     libwww
|     lwp-trivial
|     libcurl-agent/1.0
|     PHP/
|     Python-urllib/2.5
|     GT::WWW
|     Snoopy
|     MFC_Tear_Sample
|     HTTP::Lite
|     URI::Fetch
|     Zend_Http_Client
|     http client
|     PECL::HTTP
|     Wget/1.13.4 (linux-gnu)
|     WWW-Mechanize/1.34
|   Change in Status Code: 
|_    PHPCrawl: 404
|_http-chrono: Request times for /; avg: 3701.07ms; min: 2889.80ms; max: 4836.97ms
| http-waf-detect: IDS/IPS/WAF detected:
|_portainer.lan.ddnsgeek.com:443/?p4yl04d3=<script>alert(document.cookie)</script>
|_ssl-date: TLS randomness does not represent time
|_http-feed: Couldn't find any feeds.
| http-php-version: Logo query returned unknown hash 7d7fd0684387b6c83a9f48f4eba1cad8
|_Credits query returned unknown hash 7d7fd0684387b6c83a9f48f4eba1cad8
|_http-traceroute: ERROR: Script execution failed (use -d to debug)
|_http-csrf: Couldn't find any CSRF vulnerabilities.
| http-referer-checker: 
| Spidering limited to: maxpagecount=30
|_  http://html5shim.googlecode.com:80/svn/trunk/html5.js

Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Apr  5 09:07:02 2026 -- 1 IP address (1 host up) scanned in 1025.54 seconds
