fresh autorecon run

This commit is contained in:
2026-04-14 17:49:38 +10:00
parent c8f17a17e6
commit 3c3a192c79
1252 changed files with 4574573 additions and 1993899 deletions
@@ -1,12 +0,0 @@
HTTP/2 200
content-type: text/plain; charset=utf-8
date: Sun, 05 Apr 2026 08:07:57 GMT
etag: W/"19-2NTlN/votVlrfMtAaltZ799LfR0"
strict-transport-security: max-age=15552000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
content-length: 25
User-agent: *
Disallow: /
@@ -1,12 +0,0 @@
HTTP/2 302
content-type: text/plain; charset=utf-8
date: Sun, 05 Apr 2026 08:07:58 GMT
location: /dashboard
strict-transport-security: max-age=15552000; includeSubDomains; preload
vary: Accept
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
content-length: 32
Found. Redirecting to /dashboard
@@ -283,18 +283,3 @@ Configuration {
unique: false,
response_size_limit: 4194304,
}
302 GET 1l 4w 89c https://monitor-kuma.lan.ddnsgeek.com/.well-known/change-password => https://github.com/louislam/uptime-kuma/wiki/Reset-Password-via-CLI
200 GET 4l 33w 29264c https://monitor-kuma.lan.ddnsgeek.com/favicon.ico
200 GET 2l 4w 25c https://monitor-kuma.lan.ddnsgeek.com/robots.txt
404 GET 2l 12w 64c https://monitor-kuma.lan.ddnsgeek.com/api/status-page/
200 GET 9l 104w 1168c https://monitor-kuma.lan.ddnsgeek.com/icon.svg
200 GET 1l 2w 143c https://monitor-kuma.lan.ddnsgeek.com/api/status-page/default/manifest.json
200 GET 6l 6224w 323511c https://monitor-kuma.lan.ddnsgeek.com/assets/index-CeuBCM9A.css
200 GET 696l 43741w 2161652c https://monitor-kuma.lan.ddnsgeek.com/assets/index-HVtJ1YXj.js
200 GET 36l 106w 1906c https://monitor-kuma.lan.ddnsgeek.com/status
404 GET 2l 12w 64c https://monitor-kuma.lan.ddnsgeek.com/upload/
401 GET 2l 12w 75c https://monitor-kuma.lan.ddnsgeek.com/metrics
200 GET 36l 106w 1906c https://monitor-kuma.lan.ddnsgeek.com/STATUS
200 GET 2l 4w 25c https://monitor-kuma.lan.ddnsgeek.com/Robots.txt
200 GET 36l 106w 1906c https://monitor-kuma.lan.ddnsgeek.com/Status
401 GET 2l 12w 75c https://monitor-kuma.lan.ddnsgeek.com/Metrics
@@ -1,43 +0,0 @@
HTTP/2 200
content-type: text/html; charset=utf-8
date: Sun, 05 Apr 2026 08:07:57 GMT
etag: W/"4b0-7bnW31kE4H345fzkXKiptajgYts"
strict-transport-security: max-age=15552000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
content-length: 1200
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0, viewport-fit=cover" />
<link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png">
<link rel="icon" type="image/svg+xml" href="/icon.svg" />
<link rel="manifest" href="/manifest.json" />
<meta name="theme-color" id="theme-color" content="" />
<meta name="description" content="Uptime Kuma monitoring tool" />
<title>Uptime Kuma</title>
<style> .noscript-message {
font-size: 20px;
text-align: center;
padding: 10px;
max-width: 500px;
margin: 0 auto;
}
</style>
<script type="module" crossorigin src="/assets/index-HVtJ1YXj.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-CeuBCM9A.css">
</head>
<body>
<noscript>
<div class="noscript-message">
Sorry, you don't seem to have JavaScript enabled or your browser
doesn't support it.<br />This website requires JavaScript to function.
Please enable JavaScript in your browser settings to continue.
</div>
</noscript>
<div id="app"></div>
</body>
</html>
@@ -1,145 +1,23 @@
perl: warning: Setting locale failed.
perl: warning: Please check that your locale settings:
LANGUAGE = (unset),
LC_ALL = (unset),
LC_CTYPE = (unset),
LC_NUMERIC = "en_AU.UTF-8",
LC_COLLATE = (unset),
LC_TIME = "en_AU.UTF-8",
LC_MESSAGES = (unset),
LC_MONETARY = "en_AU.UTF-8",
LC_ADDRESS = "en_AU.UTF-8",
LC_IDENTIFICATION = "en_AU.UTF-8",
LC_MEASUREMENT = "en_AU.UTF-8",
LC_PAPER = "en_AU.UTF-8",
LC_TELEPHONE = "en_AU.UTF-8",
LC_NAME = "en_AU.UTF-8",
LANG = "en_US.UTF-8"
are supported and installed on your system.
perl: warning: Falling back to a fallback locale ("en_US.UTF-8").
- Nikto v2.6.0
---------------------------------------------------------------------------
+ Your Nikto installation is out of date.
+ Target IP: 167.179.167.166
+ Target Hostname: monitor-kuma.lan.ddnsgeek.com
+ Target Port: 443
---------------------------------------------------------------------------
+ SSL Info: Subject: /CN=monitor-kuma.lan.ddnsgeek.com
CN: monitor-kuma.lan.ddnsgeek.com
SAN: monitor-kuma.lan.ddnsgeek.com
Ciphers: TLS_AES_128_GCM_SHA256
Issuer: /C=US/O=Let's Encrypt/CN=R12
+ Platform: Unknown
+ Start Time: 2026-04-05 08:10:27 (GMT0)
---------------------------------------------------------------------------
+ Server: No banner retrieved
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 79 requests (~1% complete, ~3.9 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 81 requests (~1% complete, ~3.8 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 83 requests (~1% complete, ~3.8 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 85 requests (~1% complete, ~3.7 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 87 requests (~1% complete, ~3.6 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 89 requests (~1% complete, ~3.5 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 91 requests (~1% complete, ~3.5 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 93 requests (~1% complete, ~3.4 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 95 requests (~1% complete, ~3.3 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 97 requests (~1% complete, ~3.3 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 99 requests (~1% complete, ~3.2 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 101 requests (~1% complete, ~3.2 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 103 requests (~2% complete, ~3.1 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 105 requests (~2% complete, ~3.1 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 107 requests (~2% complete, ~3.0 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 109 requests (~2% complete, ~3.0 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 111 requests (~2% complete, ~3.0 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 113 requests (~2% complete, ~2.9 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 115 requests (~2% complete, ~2.9 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 117 requests (~2% complete, ~2.8 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 119 requests (~2% complete, ~2.8 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 121 requests (~2% complete, ~2.8 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 123 requests (~2% complete, ~2.7 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 125 requests (~2% complete, ~2.7 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 127 requests (~2% complete, ~2.6 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 129 requests (~2% complete, ~2.6 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 131 requests (~2% complete, ~2.6 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 133 requests (~2% complete, ~2.5 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 135 requests (~2% complete, ~2.5 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 137 requests (~2% complete, ~2.5 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ ERROR: *** Error limit (20) reached for host, giving up. Last error: Error reading chunked data length. ***
+ ERROR: *** Consider using mitmproxy to avoid TLS fingerprinting. ***
- STATUS: Completed 139 requests (~2% complete, ~2.5 hours left): currently in plugin 'OPTIONSBLEED (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9798) check'
- STATUS: Running average: Not enough data.
+ Scan terminated: 50 errors and 0 items reported on the remote host
+ End Time: 2026-04-05 08:11:05 (GMT0) (38 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
+ [FAIL] Unable to connect to monitor-kuma.lan.ddnsgeek.com:443.
@@ -1,62 +1,14 @@
# Nmap 7.98 scan initiated Sun Apr 5 08:08:00 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml monitor-kuma.lan.ddnsgeek.com
# Nmap 7.99 scan initiated Tue Apr 14 03:45:04 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml monitor-kuma.lan.ddnsgeek.com
Nmap scan report for monitor-kuma.lan.ddnsgeek.com (167.179.167.166)
Host is up, received user-set (0.014s latency).
Host is up, received user-set (0.023s latency).
rDNS record for 167.179.167.166: 167-179-167-166.a7b3a7.bne.nbn.aussiebb.net
Scanned at 2026-04-05 08:08:11 UTC for 399s
Scanned at 2026-04-14 03:45:15 UTC for 434s
PORT STATE SERVICE REASON VERSION
443/tcp open ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
|_http-feed: Couldn't find any feeds.
| http-php-version: Logo query returned unknown hash 766788bd1820615b01012c4ce5527e2d
|_Credits query returned unknown hash 766788bd1820615b01012c4ce5527e2d
| http-traceroute:
| Status Code
| Hop #1: 404
| Hop #2: 302
| Hop #3: 302
| content-length
| Hop #1: 19
| Hop #2: 32
| Hop #3: 32
| location
| Hop #1
| Hop #2: /dashboard
|_ Hop #3: /dashboard
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_ssl-date: TLS randomness does not represent time
| http-title: Uptime Kuma
|_Requested resource was /dashboard
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
|_http-fetch: Please enter the complete path of the directory to save data in.
|_http-comments-displayer: Couldn't find any comments.
| http-vhosts:
| auth.lan.ddnsgeek.com : 200
|_127 names had status 404
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-errors: ERROR: Script execution failed (use -d to debug)
| http-sitemap-generator:
| Directory structure:
| /
| Other: 1; json: 1; png: 1; svg: 1
| /assets/
| css: 1
| Longest directory structure:
| Depth: 1
| Dir: /assets/
| Total files found (by extension):
|_ Other: 1; css: 1; json: 1; png: 1; svg: 1
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-favicon: Unknown favicon MD5: 5EA4B467D984433398E1037469F13214
|_http-chrono: Request times for /; avg: 10123.28ms; min: 3915.42ms; max: 17769.75ms
| http-default-accounts:
| [Arris 2307] at /logo_t.gif
|_ (no valid default credentials found)
| http-methods:
|_ Supported Methods: GET HEAD POST
PORT STATE SERVICE REASON VERSION
443/tcp open ssl/https syn-ack ttl 55
|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
| http-useragent-tester:
| Status for browser useragent: 200
| Redirected To: /dashboard
| Status for browser useragent: 404
| Allowed User Agents:
| Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
| libwww
@@ -75,7 +27,26 @@ PORT STATE SERVICE REASON VERSION
| PECL::HTTP
| Wget/1.13.4 (linux-gnu)
|_ WWW-Mechanize/1.34
|_http-mobileversion-checker: No mobile version detected.
|_http-malware-host: Host appears to be clean
|_http-date: Tue, 14 Apr 2026 03:48:47 GMT; 0s from local time.
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
| http-headers:
| Content-Type: text/plain; charset=utf-8
| X-Content-Type-Options: nosniff
| Date: Tue, 14 Apr 2026 03:48:49 GMT
| Content-Length: 19
| Connection: close
|
|_ (Request type: GET)
| http-sitemap-generator:
| Directory structure:
| Longest directory structure:
| Depth: 0
| Dir: /
| Total files found (by extension):
|_
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| ssl-enum-ciphers:
| TLSv1.2:
| ciphers:
@@ -96,44 +67,80 @@ PORT STATE SERVICE REASON VERSION
| TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A
| cipher preference: server
|_ least strength: A
|_http-malware-host: false
| http-robots.txt: 1 disallowed entry
|_/
| http-headers:
| Content-Length: 1200
| Content-Type: text/html; charset=utf-8
| Date: Sun, 05 Apr 2026 08:10:30 GMT
| Etag: W/"4b0-7bnW31kE4H345fzkXKiptajgYts"
| Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
| X-Content-Type-Options: nosniff
| X-Frame-Options: SAMEORIGIN
| X-Xss-Protection: 1; mode=block
| Connection: close
|
|_ (Request type: HEAD)
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
|_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable
| http-waf-detect: IDS/IPS/WAF detected:
|_monitor-kuma.lan.ddnsgeek.com:443/?p4yl04d3=<script>alert(document.cookie)</script>
| http-vuln-cve2010-0738:
|_ /jmx-console/: Authentication was not required
|_http-csrf: Couldn't find any CSRF vulnerabilities.
| ssl-cert: Subject: commonName=monitor-kuma.lan.ddnsgeek.com
| Subject Alternative Name: DNS:monitor-kuma.lan.ddnsgeek.com
| Issuer: commonName=R12/organizationName=Let's Encrypt/countryName=US
| Public Key type: rsa
| Public Key bits: 4096
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-02-16T08:17:50
| Not valid after: 2026-05-17T08:17:49
| MD5: ec6c 1b16 27ff 4f78 41e8 8fea 77c4 6c1f
| SHA-1: 204e 574f 678e a6ac 2b43 3391 8a6c 8a2c d16f e1a2
| SHA-256: d7f3 395c 4185 95fa 966a bce5 cb58 5f03 7a6b a931 6fcf 99df 7f68 d1fa 1d7c e3ac
| -----BEGIN CERTIFICATE-----
| MIIGFDCCBPygAwIBAgISBn5e0uF5fviZdYbmtrMH72GSMA0GCSqGSIb3DQEBCwUA
| MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD
| EwNSMTIwHhcNMjYwMjE2MDgxNzUwWhcNMjYwNTE3MDgxNzQ5WjAoMSYwJAYDVQQD
| Ex1tb25pdG9yLWt1bWEubGFuLmRkbnNnZWVrLmNvbTCCAiIwDQYJKoZIhvcNAQEB
| BQADggIPADCCAgoCggIBALqtNqX0SNENyHOLkTUeqN3wL0L8y9DEim28fxjGlSER
| 29BbsNWaPbqR1NLOqnhb2Won10Ocb5kSEIXxqnQVnSulwRUTWMeJLiYxoVbtjTZt
| 5tS4O7kINjTVf1EwHNXpMRhpVDlwSNgdaHbsOE29X8eWqGPg0ZaTNvfUbHd0E5fR
| Rp29kEcWZT3UQIgyAGA04D+lHjZj3njiAwaY0eXFqhQjN5w+2zMUQBU/4Rg2tv76
| tIP4dhc70pV/UxE4palreRsWnohNGvjr0LtidqdjMc3ntERbzlqKs12Sj+C51/Ts
| khqtU+d1/SlRZSSb2rskgduJABN0wjTJTwIZueU6fTN0zkSbrU9QYTlMiuNj+wAo
| 09baAIjK0/MmpIWEKh7lydRYV6sjYV7S5a07bFxnUkdv3X7viO1gMFjDLs82bpys
| Q7hfiTpI5555Hgdl+xefwp/bhCLd6UWMvhagzX0tmERar7tlC7MrzrE1z3QCa0dV
| /+OUh3uU9aYC8EhidPMwiGEGcnoKHNALng24tyO8Zr0qfpfW8kzrlV4GVtiYWFKs
| O1hn9krHglbkYTTDfDQBaiG+Krw+s3IwTJ6OGygn1TJEeEZqz74ZzBhfDuUlwV4e
| DMRWKediqg0Soni6wCr8Kvdagp2g6/gor+EcvFI1KwFvsWJTAAwi/LxeGR6nZ8aJ
| AgMBAAGjggIrMIICJzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUH
| AwEwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUu6cNgdWxrMiRMCEWov9bEGClLcYw
| HwYDVR0jBBgwFoAUALUp8i2ObzHom0yteD763OkM0dIwMwYIKwYBBQUHAQEEJzAl
| MCMGCCsGAQUFBzAChhdodHRwOi8vcjEyLmkubGVuY3Iub3JnLzAoBgNVHREEITAf
| gh1tb25pdG9yLWt1bWEubGFuLmRkbnNnZWVrLmNvbTATBgNVHSAEDDAKMAgGBmeB
| DAECATAuBgNVHR8EJzAlMCOgIaAfhh1odHRwOi8vcjEyLmMubGVuY3Iub3JnLzE5
| LmNybDCCAQwGCisGAQQB1nkCBAIEgf0EgfoA+AB1AJaXZL9VWJet90OHaDcIQnfp
| 8DrV9qTzNm5GpD8PyqnGAAABnGW8h/YAAAQDAEYwRAIgd21v0+zvMSe47Sbt8ONb
| MtFnjFQbZ/k1BTblbYGdCA8CIElRr+FAoQdykqxtk/mCLWQso0Wc0XSRklCH6UO3
| au8VAH8AcX6V88I4im2x44RJPTHhWqliCHYtQgDgBQzQZ7WmYeIAAAGcZbyIOAAI
| AAAFAAmVFhAEAwBIMEYCIQDSqw3sFHaH9EICTzyAyeIk1xD3BTSs8xBRrmbN17mi
| xgIhALXQSw0vsbOdvaH6AKAKyCWYADhl+5qMokBS5sIIapptMA0GCSqGSIb3DQEB
| CwUAA4IBAQAW1nYKtFasFPe8JA15C72y4EkIz3rx+8Qg06cvPTrRo+Sz0lZU1MLH
| zbDIIbt8v8SEXk4Ha1FRmQHsxBgWFJjNdmW1FRBLe0mv63aQh9vKbYj8yJke9pXU
| FJ5/gXsj1O/isOnYMVpn5b6MLyPGdtisbybUWmG8f0cgpGgh+blIfVAYSFiPVJar
| UEq27l9U7agrWCWL4Yp41WXtjcsRMjexK/93EzyEkS3TKpOhv/AB4TPz6SQF5KHR
| gubLUVhPetDd+FyLz51dLh8bXEtq8Lp/ficAUj+X5hfuLLDtZCN/gzUDLzWdQBsK
| jsAhAJl8edhVJ3pBDFn/HBmj+2YKYz2J
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
| http-vhosts:
|_128 names had status 404
|_http-referer-checker: Couldn't find any cross-domain scripts.
|_http-date: Sun, 05 Apr 2026 08:10:34 GMT; -5s from local time.
|_http-jsonp-detection: Couldn't find any JSONP endpoints.
|_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php
|_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages.
|_http-comments-displayer: Couldn't find any comments.
|_http-fetch: Please enter the complete path of the directory to save data in.
| http-security-headers:
| Strict_Transport_Security:
| Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
| X_Frame_Options:
| Header: X-Frame-Options: SAMEORIGIN
| Description: The browser must not display this content in any frame from a page of different origin than the content itself.
| X_XSS_Protection:
| Header: X-XSS-Protection: 1; mode=block
| Description: The browser will prevent the rendering of the page when XSS is detected.
| HSTS not configured in HTTPS Server
| X_Content_Type_Options:
| Header: X-Content-Type-Options: nosniff
|_ Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type.
|_http-chrono: Request times for /; avg: 714.58ms; min: 419.12ms; max: 1278.12ms
|_http-title: Site doesn't have a title (text/plain; charset=utf-8).
|_http-feed: Couldn't find any feeds.
|_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number=<number|all> for deeper analysis)
| http-errors:
| Spidering limited to: maxpagecount=40; withinhost=monitor-kuma.lan.ddnsgeek.com
| Found the following error pages:
|
| Error Code: 404
|_ http://monitor-kuma.lan.ddnsgeek.com:443/
|_http-mobileversion-checker: No mobile version detected.
|_http-dombased-xss: Couldn't find any DOM based XSS.
|_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit=<number|all> for deeper analysis)
Read data files from: /usr/share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Sun Apr 5 08:14:51 2026 -- 1 IP address (1 host up) scanned in 412.58 seconds
# Nmap done at Tue Apr 14 03:52:30 2026 -- 1 IP address (1 host up) scanned in 446.63 seconds
@@ -1,124 +1 @@
WhatWeb report for https://monitor-kuma.lan.ddnsgeek.com/
Status : 302 Found
Title : <None>
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : RedirectLocation[/dashboard], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[x-content-type-options], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ RedirectLocation ]
HTTP Server string location. used with http-status 301 and
302
String : /dashboard (from location)
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : x-content-type-options (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 302 Found
Content-Length: 32
Content-Type: text/plain; charset=utf-8
Date: Sun, 05 Apr 2026 08:11:41 GMT
Location: /dashboard
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
Vary: Accept
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
WhatWeb report for https://monitor-kuma.lan.ddnsgeek.com/dashboard
Status : 200 OK
Title : Uptime Kuma
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : HTML5, Script[module], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[x-content-type-options], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ HTML5 ]
HTML version 5, detected by the doctype declaration
[ Script ]
This plugin detects instances of script HTML elements and
returns the script language/type.
String : module
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : x-content-type-options (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 200 OK
Content-Length: 1200
Content-Type: text/html; charset=utf-8
Date: Sun, 05 Apr 2026 08:12:01 GMT
Etag: W/"4b0-7bnW31kE4H345fzkXKiptajgYts"
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
@@ -1,5 +1,5 @@
Version: 2.1.5
OpenSSL 3.5.3 16 Sep 2025
OpenSSL 3.5.5 27 Jan 2026
Connected to 167.179.167.166
@@ -1,61 +1,43 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE nmaprun>
<?xml-stylesheet href="file:///usr/share/nmap/nmap.xsl" type="text/xsl"?>
<!-- Nmap 7.98 scan initiated Sun Apr 5 08:08:00 2026 as: /usr/lib/nmap/nmap -vv -&#45;reason -Pn -T4 -sV -p 443 &quot;-&#45;script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)&quot; -oN /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml monitor-kuma.lan.ddnsgeek.com -->
<nmaprun scanner="nmap" args="/usr/lib/nmap/nmap -vv -&#45;reason -Pn -T4 -sV -p 443 &quot;-&#45;script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)&quot; -oN /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml monitor-kuma.lan.ddnsgeek.com" start="1775376480" startstr="Sun Apr 5 08:08:00 2026" version="7.98" xmloutputversion="1.05">
<!-- Nmap 7.99 scan initiated Tue Apr 14 03:45:04 2026 as: /usr/lib/nmap/nmap -vv -&#45;reason -Pn -T4 -sV -p 443 &quot;-&#45;script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)&quot; -oN /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml monitor-kuma.lan.ddnsgeek.com -->
<nmaprun scanner="nmap" args="/usr/lib/nmap/nmap -vv -&#45;reason -Pn -T4 -sV -p 443 &quot;-&#45;script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)&quot; -oN /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/monitor-kuma.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml monitor-kuma.lan.ddnsgeek.com" start="1776138304" startstr="Tue Apr 14 03:45:04 2026" version="7.99" xmloutputversion="1.05">
<scaninfo type="syn" protocol="tcp" numservices="1" services="443"/>
<verbose level="2"/>
<debugging level="0"/>
<taskbegin task="NSE" time="1775376491"/>
<taskend task="NSE" time="1775376491"/>
<taskbegin task="NSE" time="1775376491"/>
<taskend task="NSE" time="1775376491"/>
<taskbegin task="NSE" time="1775376491"/>
<taskend task="NSE" time="1775376491"/>
<taskbegin task="Parallel DNS resolution of 1 host." time="1775376491"/>
<taskend task="Parallel DNS resolution of 1 host." time="1775376491"/>
<taskbegin task="Parallel DNS resolution of 1 host." time="1775376491"/>
<taskend task="Parallel DNS resolution of 1 host." time="1775376491"/>
<taskbegin task="SYN Stealth Scan" time="1775376491"/>
<taskend task="SYN Stealth Scan" time="1775376491" extrainfo="1 total ports"/>
<taskbegin task="Service scan" time="1775376496"/>
<taskend task="Service scan" time="1775376511" extrainfo="1 service on 1 host"/>
<taskbegin task="NSE" time="1775376512"/>
<taskprogress task="NSE" time="1775376624" percent="17.36" remaining="534" etc="1775377157"/>
<taskprogress task="NSE" time="1775376654" percent="70.37" remaining="60" etc="1775376714"/>
<taskprogress task="NSE" time="1775376684" percent="87.30" remaining="26" etc="1775376709"/>
<taskprogress task="NSE" time="1775376714" percent="88.60" remaining="26" etc="1775376740"/>
<taskprogress task="NSE" time="1775376744" percent="90.58" remaining="25" etc="1775376768"/>
<taskprogress task="NSE" time="1775376774" percent="92.21" remaining="23" etc="1775376796"/>
<taskprogress task="NSE" time="1775376804" percent="94.17" remaining="19" etc="1775376822"/>
<taskprogress task="NSE" time="1775376834" percent="96.12" remaining="14" etc="1775376847"/>
<taskprogress task="NSE" time="1775376864" percent="98.71" remaining="5" etc="1775376869"/>
<taskend task="NSE" time="1775376880"/>
<taskbegin task="NSE" time="1775376880"/>
<taskend task="NSE" time="1775376889"/>
<taskbegin task="NSE" time="1775376889"/>
<taskend task="NSE" time="1775376890"/>
<host starttime="1775376491" endtime="1775376890"><status state="up" reason="user-set" reason_ttl="0"/>
<taskbegin task="NSE" time="1776138310"/>
<taskend task="NSE" time="1776138310"/>
<taskbegin task="NSE" time="1776138311"/>
<taskend task="NSE" time="1776138311"/>
<taskbegin task="NSE" time="1776138311"/>
<taskend task="NSE" time="1776138311"/>
<taskbegin task="Parallel DNS resolution of 1 host." time="1776138314"/>
<taskend task="Parallel DNS resolution of 1 host." time="1776138314"/>
<taskbegin task="Parallel DNS resolution of 1 host." time="1776138315"/>
<taskend task="Parallel DNS resolution of 1 host." time="1776138315"/>
<taskbegin task="SYN Stealth Scan" time="1776138315"/>
<taskend task="SYN Stealth Scan" time="1776138315" extrainfo="1 total ports"/>
<taskbegin task="Service scan" time="1776138411"/>
<taskend task="Service scan" time="1776138463" extrainfo="1 service on 1 host"/>
<taskbegin task="NSE" time="1776138463"/>
<taskprogress task="NSE" time="1776138509" percent="18.06" remaining="209" etc="1776138718"/>
<taskprogress task="NSE" time="1776138539" percent="98.71" remaining="1" etc="1776138540"/>
<taskprogress task="NSE" time="1776138590" percent="99.35" remaining="1" etc="1776138591"/>
<taskprogress task="NSE" time="1776138625" percent="99.35" remaining="2" etc="1776138626"/>
<taskprogress task="NSE" time="1776138723" percent="99.35" remaining="2" etc="1776138725"/>
<taskend task="NSE" time="1776138744"/>
<taskbegin task="NSE" time="1776138744"/>
<taskend task="NSE" time="1776138749"/>
<taskbegin task="NSE" time="1776138749"/>
<taskend task="NSE" time="1776138749"/>
<host starttime="1776138315" endtime="1776138749"><status state="up" reason="user-set" reason_ttl="0"/>
<address addr="167.179.167.166" addrtype="ipv4"/>
<hostnames>
<hostname name="monitor-kuma.lan.ddnsgeek.com" type="user"/>
<hostname name="167-179-167-166.a7b3a7.bne.nbn.aussiebb.net" type="PTR"/>
</hostnames>
<ports><port protocol="tcp" portid="443"><state state="open" reason="syn-ack" reason_ttl="55"/><service name="http" product="Golang net/http server" extrainfo="Go-IPFS json-rpc or InfluxDB API" tunnel="ssl" method="probed" conf="10"><cpe>cpe:/a:protocol_labs:go-ipfs</cpe></service><script id="http-feed" output="Couldn&apos;t find any feeds."/><script id="http-php-version" output="Logo query returned unknown hash 766788bd1820615b01012c4ce5527e2d&#xa;Credits query returned unknown hash 766788bd1820615b01012c4ce5527e2d"/><script id="http-traceroute" output="&#xa; Status Code&#xa; Hop #1: 404&#xa; Hop #2: 302&#xa; Hop #3: 302&#xa; content-length&#xa; Hop #1: 19&#xa; Hop #2: 32&#xa; Hop #3: 32&#xa; location&#xa; Hop #1&#xa; Hop #2: /dashboard&#xa; Hop #3: /dashboard&#xa;"/><script id="http-dombased-xss" output="Couldn&apos;t find any DOM based XSS."/><script id="ssl-date" output="TLS randomness does not represent time"></script><script id="http-title" output="Uptime Kuma&#xa;Requested resource was /dashboard"><elem key="title">Uptime Kuma</elem>
<elem key="redirect_url">/dashboard</elem>
</script><script id="http-vuln-cve2017-1001000" output="ERROR: Script execution failed (use -d to debug)"/><script id="http-fetch" output="Please enter the complete path of the directory to save data in."><elem key="ERROR">Please enter the complete path of the directory to save data in.</elem>
</script><script id="http-comments-displayer" output="Couldn&apos;t find any comments."/><script id="http-vhosts" output="&#xa;auth.lan.ddnsgeek.com : 200&#xa;127 names had status 404"/><script id="http-stored-xss" output="Couldn&apos;t find any stored XSS vulnerabilities."/><script id="http-errors" output="ERROR: Script execution failed (use -d to debug)"/><script id="http-sitemap-generator" output="&#xa; Directory structure:&#xa; /&#xa; Other: 1; json: 1; png: 1; svg: 1&#xa; /assets/&#xa; css: 1&#xa; Longest directory structure:&#xa; Depth: 1&#xa; Dir: /assets/&#xa; Total files found (by extension):&#xa; Other: 1; css: 1; json: 1; png: 1; svg: 1&#xa;"/><script id="http-drupal-enum" output="Nothing found amongst the top 100 resources,use -&#45;script-args number=&lt;number|all&gt; for deeper analysis)"/><script id="http-csrf" output="Couldn&apos;t find any CSRF vulnerabilities."/><script id="http-favicon" output="Unknown favicon MD5: 5EA4B467D984433398E1037469F13214"/><script id="http-chrono" output="Request times for /; avg: 10123.28ms; min: 3915.42ms; max: 17769.75ms"/><script id="http-default-accounts" output="&#xa; [Arris 2307] at /logo_t.gif&#xa; (no valid default credentials found)&#xa;"><table key="Arris 2307">
<elem key="path">/logo_t.gif</elem>
<table key="credentials">
</table>
</table>
</script><script id="http-methods" output="&#xa; Supported Methods: GET HEAD POST"><table key="Supported Methods">
<elem>GET</elem>
<elem>HEAD</elem>
<elem>POST</elem>
</table>
</script><script id="http-useragent-tester" output="&#xa; Status for browser useragent: 200&#xa; Redirected To: /dashboard&#xa; Allowed User Agents: &#xa; Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)&#xa; libwww&#xa; lwp-trivial&#xa; libcurl-agent/1.0&#xa; PHP/&#xa; Python-urllib/2.5&#xa; GT::WWW&#xa; Snoopy&#xa; MFC_Tear_Sample&#xa; HTTP::Lite&#xa; PHPCrawl&#xa; URI::Fetch&#xa; Zend_Http_Client&#xa; http client&#xa; PECL::HTTP&#xa; Wget/1.13.4 (linux-gnu)&#xa; WWW-Mechanize/1.34"><elem key="Status for browser useragent">200</elem>
<elem key="Redirected To">/dashboard</elem>
<ports><port protocol="tcp" portid="443"><state state="open" reason="syn-ack" reason_ttl="55"/><service name="https" tunnel="ssl" method="probed" conf="10"/><script id="http-wordpress-users" output="[Error] Wordpress installation was not found. We couldn&apos;t find wp-login.php"/><script id="http-useragent-tester" output="&#xa; Status for browser useragent: 404&#xa; Allowed User Agents: &#xa; Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)&#xa; libwww&#xa; lwp-trivial&#xa; libcurl-agent/1.0&#xa; PHP/&#xa; Python-urllib/2.5&#xa; GT::WWW&#xa; Snoopy&#xa; MFC_Tear_Sample&#xa; HTTP::Lite&#xa; PHPCrawl&#xa; URI::Fetch&#xa; Zend_Http_Client&#xa; http client&#xa; PECL::HTTP&#xa; Wget/1.13.4 (linux-gnu)&#xa; WWW-Mechanize/1.34"><elem key="Status for browser useragent">404</elem>
<table key="Allowed User Agents">
<elem>Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)</elem>
<elem>libwww</elem>
@@ -75,32 +57,34 @@
<elem>Wget/1.13.4 (linux-gnu)</elem>
<elem>WWW-Mechanize/1.34</elem>
</table>
</script><script id="http-mobileversion-checker" output="No mobile version detected."/><script id="ssl-enum-ciphers" output="&#xa; TLSv1.2: &#xa; ciphers: &#xa; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A&#xa; compressors: &#xa; NULL&#xa; cipher preference: client&#xa; warnings: &#xa; Key exchange (secp256r1) of lower strength than certificate key&#xa; TLSv1.3: &#xa; ciphers: &#xa; TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A&#xa; TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A&#xa; TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A&#xa; cipher preference: server&#xa; least strength: A"><table key="TLSv1.2">
</script><script id="http-malware-host" output="Host appears to be clean"/><script id="http-date" output="Tue, 14 Apr 2026 03:48:47 GMT; 0s from local time."><elem key="date">2026-04-14T03:48:47+00:00</elem>
<elem key="delta">0.0</elem>
</script><script id="http-jsonp-detection" output="Couldn&apos;t find any JSONP endpoints."/><script id="http-headers" output="&#xa; Content-Type: text/plain; charset=utf-8&#xa; X-Content-Type-Options: nosniff&#xa; Date: Tue, 14 Apr 2026 03:48:49 GMT&#xa; Content-Length: 19&#xa; Connection: close&#xa; &#xa; (Request type: GET)&#xa;"/><script id="http-sitemap-generator" output="&#xa; Directory structure:&#xa; Longest directory structure:&#xa; Depth: 0&#xa; Dir: /&#xa; Total files found (by extension):&#xa; &#xa;"/><script id="http-litespeed-sourcecode-download" output="Request with null byte did not work. This web server might not be vulnerable"/><script id="http-stored-xss" output="Couldn&apos;t find any stored XSS vulnerabilities."/><script id="ssl-enum-ciphers" output="&#xa; TLSv1.2: &#xa; ciphers: &#xa; TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A&#xa; TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A&#xa; compressors: &#xa; NULL&#xa; cipher preference: client&#xa; warnings: &#xa; Key exchange (secp256r1) of lower strength than certificate key&#xa; TLSv1.3: &#xa; ciphers: &#xa; TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A&#xa; TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A&#xa; TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A&#xa; cipher preference: server&#xa; least strength: A"><table key="TLSv1.2">
<table key="ciphers">
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA</elem>
<elem key="kex_info">secp256r1</elem>
<elem key="strength">A</elem>
</table>
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</elem>
<elem key="kex_info">secp256r1</elem>
<elem key="strength">A</elem>
</table>
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA</elem>
<elem key="kex_info">secp256r1</elem>
<elem key="strength">A</elem>
</table>
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</elem>
<elem key="kex_info">secp256r1</elem>
<elem key="strength">A</elem>
</table>
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256</elem>
<elem key="kex_info">secp256r1</elem>
<elem key="strength">A</elem>
</table>
</table>
<table key="compressors">
@@ -114,51 +98,109 @@
<table key="TLSv1.3">
<table key="ciphers">
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_AKE_WITH_AES_128_GCM_SHA256</elem>
<elem key="kex_info">X25519MLKEM768</elem>
<elem key="strength">A</elem>
</table>
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_AKE_WITH_AES_256_GCM_SHA384</elem>
<elem key="kex_info">X25519MLKEM768</elem>
<elem key="strength">A</elem>
</table>
<table>
<elem key="strength">A</elem>
<elem key="name">TLS_AKE_WITH_CHACHA20_POLY1305_SHA256</elem>
<elem key="kex_info">X25519MLKEM768</elem>
<elem key="strength">A</elem>
</table>
</table>
<elem key="cipher preference">server</elem>
</table>
<elem key="least strength">A</elem>
</script><script id="http-malware-host" output="false">false</script><script id="http-robots.txt" output="1 disallowed entry &#xa;/"/><script id="http-headers" output="&#xa; Content-Length: 1200&#xa; Content-Type: text/html; charset=utf-8&#xa; Date: Sun, 05 Apr 2026 08:10:30 GMT&#xa; Etag: W/&quot;4b0-7bnW31kE4H345fzkXKiptajgYts&quot;&#xa; Strict-Transport-Security: max-age=15552000; includeSubDomains; preload&#xa; X-Content-Type-Options: nosniff&#xa; X-Frame-Options: SAMEORIGIN&#xa; X-Xss-Protection: 1; mode=block&#xa; Connection: close&#xa; &#xa; (Request type: HEAD)&#xa;"/><script id="http-devframework" output="Couldn&apos;t determine the underlying framework or CMS. Try increasing &apos;httpspider.maxpagecount&apos; value to spider more pages."/><script id="http-litespeed-sourcecode-download" output="Request with null byte did not work. This web server might not be vulnerable"/><script id="http-waf-detect" output="IDS/IPS/WAF detected:&#xa;monitor-kuma.lan.ddnsgeek.com:443/?p4yl04d3=&lt;script&gt;alert(document.cookie)&lt;/script&gt;"/><script id="http-vuln-cve2010-0738" output="&#xa; /jmx-console/: Authentication was not required&#xa;"/><script id="http-referer-checker" output="Couldn&apos;t find any cross-domain scripts."/><script id="http-date" output="Sun, 05 Apr 2026 08:10:34 GMT; -5s from local time."><elem key="date">2026-04-05T08:10:34+00:00</elem>
<elem key="delta">-5.0</elem>
</script><script id="http-jsonp-detection" output="Couldn&apos;t find any JSONP endpoints."/><script id="http-wordpress-users" output="[Error] Wordpress installation was not found. We couldn&apos;t find wp-login.php"/><script id="http-security-headers" output="&#xa; Strict_Transport_Security: &#xa; Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload&#xa; X_Frame_Options: &#xa; Header: X-Frame-Options: SAMEORIGIN&#xa; Description: The browser must not display this content in any frame from a page of different origin than the content itself.&#xa; X_XSS_Protection: &#xa; Header: X-XSS-Protection: 1; mode=block&#xa; Description: The browser will prevent the rendering of the page when XSS is detected.&#xa; X_Content_Type_Options: &#xa; Header: X-Content-Type-Options: nosniff&#xa; Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. "><table key="Strict_Transport_Security">
<elem>Header: Strict-Transport-Security: max-age=15552000; includeSubDomains; preload</elem>
</script><script id="http-csrf" output="Couldn&apos;t find any CSRF vulnerabilities."/><script id="ssl-cert" output="Subject: commonName=monitor-kuma.lan.ddnsgeek.com&#xa;Subject Alternative Name: DNS:monitor-kuma.lan.ddnsgeek.com&#xa;Issuer: commonName=R12/organizationName=Let&apos;s Encrypt/countryName=US&#xa;Public Key type: rsa&#xa;Public Key bits: 4096&#xa;Signature Algorithm: sha256WithRSAEncryption&#xa;Not valid before: 2026-02-16T08:17:50&#xa;Not valid after: 2026-05-17T08:17:49&#xa;MD5: ec6c 1b16 27ff 4f78 41e8 8fea 77c4 6c1f&#xa;SHA-1: 204e 574f 678e a6ac 2b43 3391 8a6c 8a2c d16f e1a2&#xa;SHA-256: d7f3 395c 4185 95fa 966a bce5 cb58 5f03 7a6b a931 6fcf 99df 7f68 d1fa 1d7c e3ac&#xa;-&#45;&#45;&#45;&#45;BEGIN CERTIFICATE-&#45;&#45;&#45;&#45;&#xa;MIIGFDCCBPygAwIBAgISBn5e0uF5fviZdYbmtrMH72GSMA0GCSqGSIb3DQEBCwUA&#xa;MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD&#xa;EwNSMTIwHhcNMjYwMjE2MDgxNzUwWhcNMjYwNTE3MDgxNzQ5WjAoMSYwJAYDVQQD&#xa;Ex1tb25pdG9yLWt1bWEubGFuLmRkbnNnZWVrLmNvbTCCAiIwDQYJKoZIhvcNAQEB&#xa;BQADggIPADCCAgoCggIBALqtNqX0SNENyHOLkTUeqN3wL0L8y9DEim28fxjGlSER&#xa;29BbsNWaPbqR1NLOqnhb2Won10Ocb5kSEIXxqnQVnSulwRUTWMeJLiYxoVbtjTZt&#xa;5tS4O7kINjTVf1EwHNXpMRhpVDlwSNgdaHbsOE29X8eWqGPg0ZaTNvfUbHd0E5fR&#xa;Rp29kEcWZT3UQIgyAGA04D+lHjZj3njiAwaY0eXFqhQjN5w+2zMUQBU/4Rg2tv76&#xa;tIP4dhc70pV/UxE4palreRsWnohNGvjr0LtidqdjMc3ntERbzlqKs12Sj+C51/Ts&#xa;khqtU+d1/SlRZSSb2rskgduJABN0wjTJTwIZueU6fTN0zkSbrU9QYTlMiuNj+wAo&#xa;09baAIjK0/MmpIWEKh7lydRYV6sjYV7S5a07bFxnUkdv3X7viO1gMFjDLs82bpys&#xa;Q7hfiTpI5555Hgdl+xefwp/bhCLd6UWMvhagzX0tmERar7tlC7MrzrE1z3QCa0dV&#xa;/+OUh3uU9aYC8EhidPMwiGEGcnoKHNALng24tyO8Zr0qfpfW8kzrlV4GVtiYWFKs&#xa;O1hn9krHglbkYTTDfDQBaiG+Krw+s3IwTJ6OGygn1TJEeEZqz74ZzBhfDuUlwV4e&#xa;DMRWKediqg0Soni6wCr8Kvdagp2g6/gor+EcvFI1KwFvsWJTAAwi/LxeGR6nZ8aJ&#xa;AgMBAAGjggIrMIICJzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUH&#xa;AwEwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUu6cNgdWxrMiRMCEWov9bEGClLcYw&#xa;HwYDVR0jBBgwFoAUALUp8i2ObzHom0yteD763OkM0dIwMwYIKwYBBQUHAQEEJzAl&#xa;MCMGCCsGAQUFBzAChhdodHRwOi8vcjEyLmkubGVuY3Iub3JnLzAoBgNVHREEITAf&#xa;gh1tb25pdG9yLWt1bWEubGFuLmRkbnNnZWVrLmNvbTATBgNVHSAEDDAKMAgGBmeB&#xa;DAECATAuBgNVHR8EJzAlMCOgIaAfhh1odHRwOi8vcjEyLmMubGVuY3Iub3JnLzE5&#xa;LmNybDCCAQwGCisGAQQB1nkCBAIEgf0EgfoA+AB1AJaXZL9VWJet90OHaDcIQnfp&#xa;8DrV9qTzNm5GpD8PyqnGAAABnGW8h/YAAAQDAEYwRAIgd21v0+zvMSe47Sbt8ONb&#xa;MtFnjFQbZ/k1BTblbYGdCA8CIElRr+FAoQdykqxtk/mCLWQso0Wc0XSRklCH6UO3&#xa;au8VAH8AcX6V88I4im2x44RJPTHhWqliCHYtQgDgBQzQZ7WmYeIAAAGcZbyIOAAI&#xa;AAAFAAmVFhAEAwBIMEYCIQDSqw3sFHaH9EICTzyAyeIk1xD3BTSs8xBRrmbN17mi&#xa;xgIhALXQSw0vsbOdvaH6AKAKyCWYADhl+5qMokBS5sIIapptMA0GCSqGSIb3DQEB&#xa;CwUAA4IBAQAW1nYKtFasFPe8JA15C72y4EkIz3rx+8Qg06cvPTrRo+Sz0lZU1MLH&#xa;zbDIIbt8v8SEXk4Ha1FRmQHsxBgWFJjNdmW1FRBLe0mv63aQh9vKbYj8yJke9pXU&#xa;FJ5/gXsj1O/isOnYMVpn5b6MLyPGdtisbybUWmG8f0cgpGgh+blIfVAYSFiPVJar&#xa;UEq27l9U7agrWCWL4Yp41WXtjcsRMjexK/93EzyEkS3TKpOhv/AB4TPz6SQF5KHR&#xa;gubLUVhPetDd+FyLz51dLh8bXEtq8Lp/ficAUj+X5hfuLLDtZCN/gzUDLzWdQBsK&#xa;jsAhAJl8edhVJ3pBDFn/HBmj+2YKYz2J&#xa;-&#45;&#45;&#45;&#45;END CERTIFICATE-&#45;&#45;&#45;&#45;&#xa;"><table key="subject">
<elem key="commonName">monitor-kuma.lan.ddnsgeek.com</elem>
</table>
<table key="X_Frame_Options">
<elem>Header: X-Frame-Options: SAMEORIGIN</elem>
<elem>Description: The browser must not display this content in any frame from a page of different origin than the content itself.</elem>
<table key="issuer">
<elem key="commonName">R12</elem>
<elem key="countryName">US</elem>
<elem key="organizationName">Let&apos;s Encrypt</elem>
</table>
<table key="X_XSS_Protection">
<elem>Header: X-XSS-Protection: 1; mode=block</elem>
<elem>Description: The browser will prevent the rendering of the page when XSS is detected.</elem>
<table key="pubkey">
<elem key="type">rsa</elem>
<elem key="bits">4096</elem>
<elem key="modulus">BAAD36A5F448D10DC8738B91351EA8DDF02F42FCCBD0C48A6DBC7F18C6952111DBD05BB0D59A3DBA91D4D2CEAA785BD96A27D7439C6F99121085F1AA74159D2BA5C1151358C7892E2631A156ED8D366DE6D4B83BB9083634D57F51301CD5E931186954397048D81D6876EC384DBD5FC796A863E0D1969336F7D46C77741397D1469DBD904716653DD4408832006034E03FA51E3663DE78E2030698D1E5C5AA1423379C3EDB331440153FE11836B6FEFAB483F876173BD2957F531138A5A96B791B169E884D1AF8EBD0BB6276A76331CDE7B4445BCE5A8AB35D928FE0B9D7F4EC921AAD53E775FD295165249BDABB2481DB89001374C234C94F0219B9E53A7D3374CE449BAD4F5061394C8AE363FB0028D3D6DA0088CAD3F326A485842A1EE5C9D45857AB23615ED2E5AD3B6C5C6752476FDD7EEF88ED603058C32ECF366E9CAC43B85F893A48E79E791E0765FB179FC29FDB8422DDE9458CBE16A0CD7D2D98445AAFBB650BB32BCEB135CF74026B4755FFE394877B94F5A602F0486274F330886106727A0A1CD00B9E0DB8B723BC66BD2A7E97D6F24CEB955E0656D8985852AC3B5867F64AC78256E46134C37C34016A21BE2ABC3EB372304C9E8E1B2827D5324478466ACFBE19CC185F0EE525C15E1E0CC45629E762AA0D12A278BAC02AFC2AF75A829DA0EBF828AFE11CBC52352B016FB16253000C22FCBC5E191EA767C689</elem>
<elem key="exponent">65537</elem>
</table>
<table key="extensions">
<table>
<elem key="name">X509v3 Key Usage</elem>
<elem key="value">Digital Signature, Key Encipherment</elem>
<elem key="critical">true</elem>
</table>
<table>
<elem key="name">X509v3 Extended Key Usage</elem>
<elem key="value">TLS Web Server Authentication</elem>
</table>
<table>
<elem key="name">X509v3 Basic Constraints</elem>
<elem key="value">CA:FALSE</elem>
<elem key="critical">true</elem>
</table>
<table>
<elem key="name">X509v3 Subject Key Identifier</elem>
<elem key="value">BB:A7:0D:81:D5:B1:AC:C8:91:30:21:16:A2:FF:5B:10:60:A5:2D:C6</elem>
</table>
<table>
<elem key="name">X509v3 Authority Key Identifier</elem>
<elem key="value">00:B5:29:F2:2D:8E:6F:31:E8:9B:4C:AD:78:3E:FA:DC:E9:0C:D1:D2</elem>
</table>
<table>
<elem key="name">Authority Information Access</elem>
<elem key="value">CA Issuers - URI:http://r12.i.lencr.org/</elem>
</table>
<table>
<elem key="name">X509v3 Subject Alternative Name</elem>
<elem key="value">DNS:monitor-kuma.lan.ddnsgeek.com</elem>
</table>
<table>
<elem key="name">X509v3 Certificate Policies</elem>
<elem key="value">Policy: 2.23.140.1.2.1</elem>
</table>
<table>
<elem key="name">X509v3 CRL Distribution Points</elem>
<elem key="value">Full Name:&#xa; URI:http://r12.c.lencr.org/19.crl&#xa;</elem>
</table>
<table>
<elem key="name">CT Precertificate SCTs</elem>
<elem key="value">Signed Certificate Timestamp:&#xa; Version : v1 (0x0)&#xa; Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:&#xa; E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6&#xa; Timestamp : Feb 16 09:16:20.342 2026 GMT&#xa; Extensions: none&#xa; Signature : ecdsa-with-SHA256&#xa; 30:44:02:20:77:6D:6F:D3:EC:EF:31:27:B8:ED:26:ED:&#xa; F0:E3:5B:32:D1:67:8C:54:1B:67:F9:35:05:36:E5:6D:&#xa; 81:9D:08:0F:02:20:49:51:AF:E1:40:A1:07:72:92:AC:&#xa; 6D:93:F9:82:2D:64:2C:A3:45:9C:D1:74:91:92:50:87:&#xa; E9:43:B7:6A:EF:15&#xa;Signed Certificate Timestamp:&#xa; Version : v1 (0x0)&#xa; Log ID : 71:7E:95:F3:C2:38:8A:6D:B1:E3:84:49:3D:31:E1:5A:&#xa; A9:62:08:76:2D:42:00:E0:05:0C:D0:67:B5:A6:61:E2&#xa; Timestamp : Feb 16 09:16:20.408 2026 GMT&#xa; Extensions: 00:00:05:00:09:95:16:10&#xa; Signature : ecdsa-with-SHA256&#xa; 30:46:02:21:00:D2:AB:0D:EC:14:76:87:F4:42:02:4F:&#xa; 3C:80:C9:E2:24:D7:10:F7:05:34:AC:F3:10:51:AE:66:&#xa; CD:D7:B9:A2:C6:02:21:00:B5:D0:4B:0D:2F:B1:B3:9D:&#xa; BD:A1:FA:00:A0:0A:C8:25:98:00:38:65:FB:9A:8C:A2:&#xa; 40:52:E6:C2:08:6A:9A:6D</elem>
</table>
</table>
<elem key="sig_algo">sha256WithRSAEncryption</elem>
<table key="validity">
<elem key="notBefore">2026-02-16T08:17:50</elem>
<elem key="notAfter">2026-05-17T08:17:49</elem>
</table>
<elem key="md5">ec6c1b1627ff4f7841e88fea77c46c1f</elem>
<elem key="sha1">204e574f678ea6ac2b4333918a6c8a2cd16fe1a2</elem>
<elem key="sha256">d7f3395c418595fa966abce5cb585f037a6ba9316fcf99df7f68d1fa1d7ce3ac</elem>
<elem key="pem">-&#45;&#45;&#45;&#45;BEGIN CERTIFICATE-&#45;&#45;&#45;&#45;&#xa;MIIGFDCCBPygAwIBAgISBn5e0uF5fviZdYbmtrMH72GSMA0GCSqGSIb3DQEBCwUA&#xa;MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD&#xa;EwNSMTIwHhcNMjYwMjE2MDgxNzUwWhcNMjYwNTE3MDgxNzQ5WjAoMSYwJAYDVQQD&#xa;Ex1tb25pdG9yLWt1bWEubGFuLmRkbnNnZWVrLmNvbTCCAiIwDQYJKoZIhvcNAQEB&#xa;BQADggIPADCCAgoCggIBALqtNqX0SNENyHOLkTUeqN3wL0L8y9DEim28fxjGlSER&#xa;29BbsNWaPbqR1NLOqnhb2Won10Ocb5kSEIXxqnQVnSulwRUTWMeJLiYxoVbtjTZt&#xa;5tS4O7kINjTVf1EwHNXpMRhpVDlwSNgdaHbsOE29X8eWqGPg0ZaTNvfUbHd0E5fR&#xa;Rp29kEcWZT3UQIgyAGA04D+lHjZj3njiAwaY0eXFqhQjN5w+2zMUQBU/4Rg2tv76&#xa;tIP4dhc70pV/UxE4palreRsWnohNGvjr0LtidqdjMc3ntERbzlqKs12Sj+C51/Ts&#xa;khqtU+d1/SlRZSSb2rskgduJABN0wjTJTwIZueU6fTN0zkSbrU9QYTlMiuNj+wAo&#xa;09baAIjK0/MmpIWEKh7lydRYV6sjYV7S5a07bFxnUkdv3X7viO1gMFjDLs82bpys&#xa;Q7hfiTpI5555Hgdl+xefwp/bhCLd6UWMvhagzX0tmERar7tlC7MrzrE1z3QCa0dV&#xa;/+OUh3uU9aYC8EhidPMwiGEGcnoKHNALng24tyO8Zr0qfpfW8kzrlV4GVtiYWFKs&#xa;O1hn9krHglbkYTTDfDQBaiG+Krw+s3IwTJ6OGygn1TJEeEZqz74ZzBhfDuUlwV4e&#xa;DMRWKediqg0Soni6wCr8Kvdagp2g6/gor+EcvFI1KwFvsWJTAAwi/LxeGR6nZ8aJ&#xa;AgMBAAGjggIrMIICJzAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUH&#xa;AwEwDAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUu6cNgdWxrMiRMCEWov9bEGClLcYw&#xa;HwYDVR0jBBgwFoAUALUp8i2ObzHom0yteD763OkM0dIwMwYIKwYBBQUHAQEEJzAl&#xa;MCMGCCsGAQUFBzAChhdodHRwOi8vcjEyLmkubGVuY3Iub3JnLzAoBgNVHREEITAf&#xa;gh1tb25pdG9yLWt1bWEubGFuLmRkbnNnZWVrLmNvbTATBgNVHSAEDDAKMAgGBmeB&#xa;DAECATAuBgNVHR8EJzAlMCOgIaAfhh1odHRwOi8vcjEyLmMubGVuY3Iub3JnLzE5&#xa;LmNybDCCAQwGCisGAQQB1nkCBAIEgf0EgfoA+AB1AJaXZL9VWJet90OHaDcIQnfp&#xa;8DrV9qTzNm5GpD8PyqnGAAABnGW8h/YAAAQDAEYwRAIgd21v0+zvMSe47Sbt8ONb&#xa;MtFnjFQbZ/k1BTblbYGdCA8CIElRr+FAoQdykqxtk/mCLWQso0Wc0XSRklCH6UO3&#xa;au8VAH8AcX6V88I4im2x44RJPTHhWqliCHYtQgDgBQzQZ7WmYeIAAAGcZbyIOAAI&#xa;AAAFAAmVFhAEAwBIMEYCIQDSqw3sFHaH9EICTzyAyeIk1xD3BTSs8xBRrmbN17mi&#xa;xgIhALXQSw0vsbOdvaH6AKAKyCWYADhl+5qMokBS5sIIapptMA0GCSqGSIb3DQEB&#xa;CwUAA4IBAQAW1nYKtFasFPe8JA15C72y4EkIz3rx+8Qg06cvPTrRo+Sz0lZU1MLH&#xa;zbDIIbt8v8SEXk4Ha1FRmQHsxBgWFJjNdmW1FRBLe0mv63aQh9vKbYj8yJke9pXU&#xa;FJ5/gXsj1O/isOnYMVpn5b6MLyPGdtisbybUWmG8f0cgpGgh+blIfVAYSFiPVJar&#xa;UEq27l9U7agrWCWL4Yp41WXtjcsRMjexK/93EzyEkS3TKpOhv/AB4TPz6SQF5KHR&#xa;gubLUVhPetDd+FyLz51dLh8bXEtq8Lp/ficAUj+X5hfuLLDtZCN/gzUDLzWdQBsK&#xa;jsAhAJl8edhVJ3pBDFn/HBmj+2YKYz2J&#xa;-&#45;&#45;&#45;&#45;END CERTIFICATE-&#45;&#45;&#45;&#45;&#xa;</elem>
</script><script id="ssl-date" output="TLS randomness does not represent time"></script><script id="http-vhosts" output="&#xa;128 names had status 404"/><script id="http-referer-checker" output="Couldn&apos;t find any cross-domain scripts."/><script id="http-devframework" output="Couldn&apos;t determine the underlying framework or CMS. Try increasing &apos;httpspider.maxpagecount&apos; value to spider more pages."/><script id="http-comments-displayer" output="Couldn&apos;t find any comments."/><script id="http-fetch" output="Please enter the complete path of the directory to save data in."><elem key="ERROR">Please enter the complete path of the directory to save data in.</elem>
</script><script id="http-security-headers" output="&#xa; Strict_Transport_Security: &#xa; HSTS not configured in HTTPS Server&#xa; X_Content_Type_Options: &#xa; Header: X-Content-Type-Options: nosniff&#xa; Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. "><table key="Strict_Transport_Security">
<elem>HSTS not configured in HTTPS Server</elem>
</table>
<table key="X_Content_Type_Options">
<elem>Header: X-Content-Type-Options: nosniff</elem>
<elem>Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. </elem>
</table>
</script></port>
</script><script id="http-chrono" output="Request times for /; avg: 714.58ms; min: 419.12ms; max: 1278.12ms"/><script id="http-title" output="Site doesn&apos;t have a title (text/plain; charset=utf-8)."></script><script id="http-feed" output="Couldn&apos;t find any feeds."/><script id="http-drupal-enum" output="Nothing found amongst the top 100 resources,use -&#45;script-args number=&lt;number|all&gt; for deeper analysis)"/><script id="http-errors" output="&#xa;Spidering limited to: maxpagecount=40; withinhost=monitor-kuma.lan.ddnsgeek.com&#xa; Found the following error pages: &#xa; &#xa; Error Code: 404&#xa; &#x9;http://monitor-kuma.lan.ddnsgeek.com:443/&#xa;"/><script id="http-mobileversion-checker" output="No mobile version detected."/><script id="http-dombased-xss" output="Couldn&apos;t find any DOM based XSS."/><script id="http-wordpress-enum" output="Nothing found amongst the top 100 resources,use -&#45;script-args search-limit=&lt;number|all&gt; for deeper analysis)"/></port>
</ports>
<times srtt="14334" rttvar="14334" to="100000"/>
<times srtt="23382" rttvar="23382" to="116910"/>
</host>
<taskbegin task="NSE" time="1775376890"/>
<taskend task="NSE" time="1775376890"/>
<taskbegin task="NSE" time="1775376890"/>
<taskend task="NSE" time="1775376890"/>
<taskbegin task="NSE" time="1775376890"/>
<taskend task="NSE" time="1775376890"/>
<runstats><finished time="1775376891" timestr="Sun Apr 5 08:14:51 2026" summary="Nmap done at Sun Apr 5 08:14:51 2026; 1 IP address (1 host up) scanned in 412.58 seconds" elapsed="412.58" exit="success"/><hosts up="1" down="0" total="1"/>
<taskbegin task="NSE" time="1776138750"/>
<taskend task="NSE" time="1776138750"/>
<taskbegin task="NSE" time="1776138750"/>
<taskend task="NSE" time="1776138750"/>
<taskbegin task="NSE" time="1776138750"/>
<taskend task="NSE" time="1776138750"/>
<runstats><finished time="1776138750" timestr="Tue Apr 14 03:52:30 2026" summary="Nmap done at Tue Apr 14 03:52:30 2026; 1 IP address (1 host up) scanned in 446.63 seconds" elapsed="446.63" exit="success"/><hosts up="1" down="0" total="1"/>
</runstats>
</nmaprun>