# Nmap 7.98 scan initiated Sun Apr  5 10:07:38 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/shifts.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/shifts.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml shifts.lan.ddnsgeek.com
Nmap scan report for shifts.lan.ddnsgeek.com (167.179.167.166)
Host is up, received user-set (0.014s latency).
rDNS record for 167.179.167.166: 167-179-167-166.a7b3a7.bne.nbn.aussiebb.net
Scanned at 2026-04-05 10:07:42 UTC for 158s

PORT    STATE SERVICE  REASON         VERSION
443/tcp open  ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
| http-comments-displayer: 
| Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=shifts.lan.ddnsgeek.com
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 9
|     Comment: 
|         /**
|          * @license React
|          * react-jsx-runtime.production.min.js
|          *
|          * Copyright (c) Facebook, Inc. and its affiliates.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE file in the root directory of this source tree.
|          */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 1
|     Comment: 
|         /**
|          * @license React
|          * react.production.min.js
|          *
|          * Copyright (c) Facebook, Inc. and its affiliates.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE file in the root directory of this source tree.
|          */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 25
|     Comment: 
|         /**
|          * @license React
|          * react-dom.production.min.js
|          *
|          * Copyright (c) Facebook, Inc. and its affiliates.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE file in the root directory of this source tree.
|          */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 49
|     Comment: 
|         /**
|          * React Router v6.28.0
|          *
|          * Copyright (c) Remix Software Inc.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE.md file in the root directory of this source tree.
|          *
|          * @license MIT
|          */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 40
|     Comment: 
|         /**
|          * @remix-run/router v1.21.0
|          *
|          * Copyright (c) Remix Software Inc.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE.md file in the root directory of this source tree.
|          *
|          * @license MIT
|          */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 75
|     Comment: 
|         /*! @gera2ld/tarjs v0.3.1 | MIT License */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 49
|     Comment: 
|         /*"),'Route path "'+e+'" will be treated as if it were '+('"'+e.replace(/\*$/,"/*")+'" because the `*` character must ')+"always follow a `/` in the pattern. To get rid of this warning, "+('please change the route path to "'+e.replace(/\*$/,"/*")+'".'));let r=[],a="^"+e.replace(/\/*\*?$/,"").replace(/^\/*/
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 58
|     Comment: 
|         /*/,"/"),f=_.useMemo(()=>({basename:c,navigator:i,static:s,future:al({v7_relativeSplatPath:!1},u)}),[c,u,i,s]);typeof r=="string"&&(r=Ws(r));let{pathname:g="/",search:p="",hash:w="",state:N=null,key:C="default"}=r,E=_.useMemo(()=>{let I=Ms(g,c);return I==null?null:{location:{pathname:I,search:p,hash:w,state:N,key:C},navigationType:a}},[c,g,p,w,N,C,a]);return E==null?null:_.createElement(qa.Provider,{value:f},_.createElement(Jc.Provider,{children:n,value:E}))}function L_(e){let{children:t,location:n}=e;return w_(zh(t),n)}new Promise(()=>{});function zh(e,t){t===void 0&&(t=[]);let n=[];return _.Children.forEach(e,(r,a)=>{if(!_.isValidElement(r))return;let i=[...t,a];if(r.type===_.Fragment){n.push.apply(n,zh(r.props.children,i));return}r.type!==Ku&&St(!1),!r.props.index||!r.props.children||St(!1);let s={id:r.props.id||i.join("-"),caseSensitive:r.props.caseSensitive,element:r.props.element,Component:r.props.Component,index:r.props.index,path:r.props.path,loader:r.props.loader,action:r.props.action,errorElement:r.props.errorElement,ErrorBoundary:r.props.ErrorBoundary,hasErrorBoundary:r.props.ErrorBoundary!=null||r.props.errorElement!=null,shouldRevalidate:r.props.shouldRevalidate,handle:r.props.handle,lazy:r.props.lazy};r.props.children&&(s.children=zh(r.props.children,i)),n.push(s)}),n}/**
|          * React Router DOM v6.28.0
|          *
|          * Copyright (c) Remix Software Inc.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE.md file in the root directory of this source tree.
|          *
|          * @license MIT
|          */
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 49
|     Comment: 
|         /*"?"(.*)$":"(?:\\/(.+)|\\/*)$"):n?a+="\\/*$":e!==""&&e!=="/"&&(a+="(?:(?=\\/|$))"),[new RegExp(a,t?void 0:"i"),r]}function l_(e){try{return e.split("/").map(t=>decodeURIComponent(t).replace(/\//g,"%2F")).join("/")}catch(t){return Gx(!1,'The URL path "'+e+'" could not be decoded because it is is a malformed URL segment. This is probably due to a bad percent '+("encoding ("+t+").")),e}}function Ms(e,t){if(t==="/")return e;if(!e.toLowerCase().startsWith(t.toLowerCase()))return null;let n=t.endsWith("/")?t.length-1:t.length,r=e.charAt(n);return r&&r!=="/"?null:e.slice(n)||"/"}function u_(e,t){t===void 0&&(t="/");let{pathname:n,search:r="",hash:a=""}=typeof e=="string"?Ws(e):e;return{pathname:n?n.startsWith("/")?n:c_(n,t):t,search:h_(r),hash:m_(a)}}function c_(e,t){let n=t.replace(/\/+$/,"").split("/");return e.split("/").forEach(a=>{a===".."?n.length>1&&n.pop():a!=="."&&n.push(a)}),n.length>1?n.join("/"):"/"}function ff(e,t,n,r){return"Cannot include a '"+e+"' character in a manually specified "+("`to."+t+"` field ["+JSON.stringify(r)+"].  Please separate it out to the ")+("`to."+n+"` field. Alternatively you may provide the full path as ")+'a string in <Link to="..."> and the router will parse it for you.'}function d_(e){return e.filter((t,n)=>n===0||t.route.path&&t.route.path.length>0)}function ew(e,t){let n=d_(e);return t?n.map((r,a)=>a===n.length-1?r.pathname:r.pathnameBase):n.map(r=>r.pathnameBase)}function tw(e,t,n,r){r===void 0&&(r=!1);let a;typeof e=="string"?a=Ws(e):(a=rl({},e),St(!a.pathname||!a.pathname.includes("?"),ff("?","pathname","search",a)),St(!a.pathname||!a.pathname.includes("#"),ff("#","pathname","hash",a)),St(!a.search||!a.search.includes("#"),ff("#","search","hash",a)));let i=e===""||a.pathname==="",s=i?"/":a.pathname,u;if(s==null)u=n;else{let p=t.length-1;if(!r&&s.startsWith("..")){let w=s.split("/");for(;w[0]==="..";)w.shift(),p-=1;a.pathname=w.join("/")}u=p>=0?t[p]:"/"}let c=u_(a,u),f=s&&s!=="/"&&s.endsWith("/"),g=(i||s===".")&&n.endsWith("/");return!c.pathname.endsWith("/")&&(f||g)&&(c.pathname+="/"),c}const Ma=e=>e.join("/").replace(/\/\/+/g,"/"),f_=e=>e.replace(/\/+$/,"").replace(/^\/*/
|     
|     Path: https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js
|     Line number: 17
|     Comment: 
|         /**
|          * @license React
|          * scheduler.production.min.js
|          *
|          * Copyright (c) Facebook, Inc. and its affiliates.
|          *
|          * This source code is licensed under the MIT license found in the
|          * LICENSE file in the root directory of this source tree.
|_         */
|_http-majordomo2-dir-traversal: ERROR: Script execution failed (use -d to debug)
|_http-date: Sun, 05 Apr 2026 10:08:12 GMT; -3s from local time.
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
|_http-favicon: Unknown favicon MD5: 201CC5A3633DB9EDF3FF294B124BCC5D
| http-php-version: Logo query returned unknown hash efc923f7ea125c3d88ff2eb2668a7f29
|_Credits query returned unknown hash efc923f7ea125c3d88ff2eb2668a7f29
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
| http-grep: 
|   (1) https://shifts.lan.ddnsgeek.com:443/assets/index-Cj6Lw8yT.js: 
|     (1) ip: 
|_      + 147.083.22.127
|_http-malware-host: false
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-errors: Couldn't find any error pages.
|_http-referer-checker: Couldn't find any cross-domain scripts.
| http-sitemap-generator: 
|   Directory structure:
|     /
|       Other: 1; webmanifest: 1
|     /assets/
|       css: 1; js: 1
|   Longest directory structure:
|     Depth: 1
|     Dir: /assets/
|   Total files found (by extension):
|_    Other: 1; css: 1; js: 1; webmanifest: 1
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| http-security-headers: 
|   Strict_Transport_Security: 
|     Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|   X_Frame_Options: 
|     Header: X-Frame-Options: SAMEORIGIN
|     Description: The browser must not display this content in any frame from a page of different origin than the content itself.
|   X_XSS_Protection: 
|     Header: X-XSS-Protection: 1; mode=block
|     Description: The browser will prevent the rendering of the page when XSS is detected.
|   X_Content_Type_Options: 
|     Header: X-Content-Type-Options: nosniff
|     Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. 
|   Content_Security_Policy: 
|     Header: Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self'; connect-src 'self' https://date.nager.at; img-src 'self' data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; worker-src 'self'; manifest-src 'self'
|     Description: Define the base uri for relative uri.
|     Description: Define loading policy for all resources type in case of a resource type dedicated directive is not defined (fallback).
|     Description: Define which scripts the protected resource can execute.
|     Description: Define from where the protected resource can load plugins.
|     Description: Define which styles (CSS) the user applies to the protected resource.
|     Description: Define from where the protected resource can load images.
|     Description: Define from where the protected resource can be embedded in frames.
|     Description: Define from where the protected resource can load fonts.
|     Description: Define which URIs the protected resource can load using script interfaces.
|     Description: Define which URIs can be used as the action of HTML form elements.
|   Cache_Control: 
|_    Header: Cache-Control: no-store
|_http-title: Chrona \xC2\xB7 Intelligent shift tracking
|_http-dombased-xss: Couldn't find any DOM based XSS.
| ssl-cert: Subject: commonName=shifts.lan.ddnsgeek.com
| Subject Alternative Name: DNS:shifts.lan.ddnsgeek.com
| Issuer: commonName=R13/organizationName=Let's Encrypt/countryName=US
| Public Key type: rsa
| Public Key bits: 4096
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-03-31T03:04:05
| Not valid after:  2026-06-29T03:04:04
| MD5:     c3d1 fb74 73dc 5b68 6f54 b13a dac8 86c2
| SHA-1:   3fa4 51ca 75eb 6f8c a112 3b2e 14c9 9f5b bec8 8ad3
| SHA-256: bc5f 25c2 95e4 bd28 c356 90a0 e1e4 b558 e9e8 21c5 1148 3965 540d 5c25 fe5f 208a
| -----BEGIN CERTIFICATE-----
| MIIGCjCCBPKgAwIBAgISBsLb1bx7gFH5NhOK7fPJaGtyMA0GCSqGSIb3DQEBCwUA
| MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD
| EwNSMTMwHhcNMjYwMzMxMDMwNDA1WhcNMjYwNjI5MDMwNDA0WjAiMSAwHgYDVQQD
| ExdzaGlmdHMubGFuLmRkbnNnZWVrLmNvbTCCAiIwDQYJKoZIhvcNAQEBBQADggIP
| ADCCAgoCggIBAOFTQguvhZIWkVyicive/yfgrKHyxBdvR8+c1zcvxV9xPx2VTweK
| RDxR+GLs6rNN+Oo/Zk+S8w0qYKAKZ/Jeen+8U2QsvMYtzOTRRtLLWCelRJHpkRXI
| e7xvvYdb36X/G+fcdiMbXKo64ITh+zhA6PXRfvdv3hJz8ibX2pcZJQQQjD2DdhAU
| dGXut1h37BXD4ZpQ3dgKZ9mCgv8rOXvPCsSoi3ueOZ1dL5Bt8vzF0SwgHlWEcO/V
| iUhxNyPMY3ORt9uDzcudtgpUyyoaWHSKMIs5JEpNmsuaDP50AWSKTnWMrj9RLu1o
| jJZgFzm3e01RDVJilcMccvLzxZJfhcaTXmU5g0iD7c5vyiCo0rNWsGmMDAcRGMCs
| b+H8aklOPgc8yvD7e8p08LSU6i6mwVkjsRWjaw4+sLnKgag5au1x7y15CL3+6nVt
| F7o/lNuUbIUCP9xqlzzNNB70fSU11yCUUx4EpOnn6u33XN/O9eNyc2MoeZbeFoFM
| WLU0ASPhitO9YXXXzFIsdKuzBh82x2zRvSPaJh0oiYpxGOPCmRtHA8jIqhc4evsj
| N8351FbwwUkXFztbhgU1gC09e3gGF9/73HD2S0xccF5GjQkcSHN5yloIGf0+MqBw
| Lpf3vYqOvNiqSDU0B7XxxzvmxSKM7aRnTlqSO5h545JTNhR0SH8z0helAgMBAAGj
| ggInMIICIzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYD
| VR0TAQH/BAIwADAdBgNVHQ4EFgQUh9xjMBozVdPfLtVnzdCS0ZSLOJQwHwYDVR0j
| BBgwFoAU56ufDywzoFPTXk94yLKEDjvWkjMwMwYIKwYBBQUHAQEEJzAlMCMGCCsG
| AQUFBzAChhdodHRwOi8vcjEzLmkubGVuY3Iub3JnLzAiBgNVHREEGzAZghdzaGlm
| dHMubGFuLmRkbnNnZWVrLmNvbTATBgNVHSAEDDAKMAgGBmeBDAECATAvBgNVHR8E
| KDAmMCSgIqAghh5odHRwOi8vcjEzLmMubGVuY3Iub3JnLzExNS5jcmwwggENBgor
| BgEEAdZ5AgQCBIH+BIH7APkAfwCoJsvjCsY1EkZTP+Bl8U8Z2W4ZCBPEHdlteQCz
| EjxVJwAAAZ1CDsFSAAgAAAUABOYyUgQDAEgwRgIhAK1V3FZ4YQCDzeJU3pB81bAD
| LG+6Qxi2Q06zKewS34hWAiEAvOnMiYZHXkydYeqK5RmTUthlAfsr/VeM8uEXiknX
| i3YAdgDRbqmlaAd+ZjWgPzel3bwDpTxBEhTUiBj16TGzI8uVBAAAAZ1CDr/GAAAE
| AwBHMEUCIQDeQsHb4m3Avs/mXWBHrJrYRtZn7fx8N8cb8rmuT5kaCQIgFZTwg0AH
| juXF8+Eep1ES1OhTt9TyhTrF/YKgjFLh5zowDQYJKoZIhvcNAQELBQADggEBAFHP
| g+Oymtv7OUPWOcJrJF6I7/be21Gcv691xRY6ff60c0Op4TDKrgaQaukyD8aecLN7
| fg3hoDKDR2ex+CQlDlSizMqxVNfUpTmN6vuy5uQTRFEtl9K6Q62RXaVlvDLyRvKd
| 8+8kfi8uh+4EjgVFVNiiZ2rOS98AUJccUH7XAEGQ2DagWU/tSMGv5C0XzUt6iGDV
| Un3rl7KL/qvsqj0MEmWIKGkfvjqU3ag/6Tmzto+PZCUOhLcI73UBrNdhUSug50jw
| oTGj3mlk7tR6vk/w8EjKiromakRLHU2OWzRu/eUyy6mbsKn6EFTIzwKrOIBrATNz
| XNmVDbwlfwWaV+2mu9A=
|_-----END CERTIFICATE-----
| http-vuln-cve2011-3192: 
|   VULNERABLE:
|   Apache byterange filter DoS
|     State: VULNERABLE
|     IDs:  CVE:CVE-2011-3192  BID:49303
|       The Apache web server is vulnerable to a denial of service attack when numerous
|       overlapping byte ranges are requested.
|     Disclosure date: 2011-08-19
|     References:
|       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3192
|       https://seclists.org/fulldisclosure/2011/Aug/175
|       https://www.tenable.com/plugins/nessus/55976
|_      https://www.securityfocus.com/bid/49303
| http-useragent-tester: 
|   Status for browser useragent: 200
|   Allowed User Agents: 
|     Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
|     libwww
|     lwp-trivial
|     libcurl-agent/1.0
|     PHP/
|     Python-urllib/2.5
|     GT::WWW
|     Snoopy
|     MFC_Tear_Sample
|     HTTP::Lite
|     PHPCrawl
|     URI::Fetch
|     Zend_Http_Client
|     http client
|     PECL::HTTP
|     Wget/1.13.4 (linux-gnu)
|_    WWW-Mechanize/1.34
|_ssl-date: TLS randomness does not represent time
|_http-feed: Couldn't find any feeds.
| http-headers: 
|   Accept-Ranges: bytes
|   Cache-Control: no-store
|   Content-Length: 564
|   Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self'; connect-src 'self' https://date.nager.at; img-src 'self' data:; font-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; worker-src 'self'; manifest-src 'self'
|   Content-Type: text/html
|   Date: Sun, 05 Apr 2026 10:07:58 GMT
|   Etag: "69c9ee89-234"
|   Last-Modified: Mon, 30 Mar 2026 03:31:21 GMT
|   Permissions-Policy: accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), display-capture=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()
|   Referrer-Policy: no-referrer
|   Server: nginx/1.29.7
|   Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
|   X-Content-Type-Options: nosniff
|   X-Frame-Options: SAMEORIGIN
|   X-Xss-Protection: 1; mode=block
|   Connection: close
|   
|_  (Request type: HEAD)
| http-vhosts: 
| 127 names had status 404
|_auth.lan.ddnsgeek.com : 200
|_http-server-header: nginx/1.29.7
|_http-mobileversion-checker: No mobile version detected.
| http-methods: 
|_  Supported Methods: GET HEAD
|_http-fetch: Please enter the complete path of the directory to save data in.
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
|_http-chrono: Request times for /; avg: 7783.07ms; min: 953.73ms; max: 19054.87ms
| ssl-enum-ciphers: 
|   TLSv1.2: 
|     ciphers: 
|       TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A
|     compressors: 
|       NULL
|     cipher preference: client
|     warnings: 
|       Key exchange (secp256r1) of lower strength than certificate key
|   TLSv1.3: 
|     ciphers: 
|       TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A
|       TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A
|       TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A
|     cipher preference: server
|_  least strength: A
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)

Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Apr  5 10:10:20 2026 -- 1 IP address (1 host up) scanned in 162.01 seconds
