# Nmap 7.99 scan initiated Tue Apr 14 03:33:49 2026 as: /usr/lib/nmap/nmap -vv --reason -Pn -T4 -sV -p 443 "--script=banner,(http* or ssl*) and not (brute or broadcast or dos or external or http-slowloris* or fuzzer)" -oN /root/results/grafana.lan.ddnsgeek.com/scans/tcp443/tcp_443_https_nmap.txt -oX /root/results/grafana.lan.ddnsgeek.com/scans/tcp443/xml/tcp_443_https_nmap.xml grafana.lan.ddnsgeek.com Nmap scan report for grafana.lan.ddnsgeek.com (167.179.167.166) Host is up, received user-set (0.015s latency). rDNS record for 167.179.167.166: 167-179-167-166.a7b3a7.bne.nbn.aussiebb.net Scanned at 2026-04-14 03:33:52 UTC for 100s PORT STATE SERVICE REASON VERSION 443/tcp open ssl/https syn-ack ttl 55 |_http-dombased-xss: Couldn't find any DOM based XSS. | http-vhosts: |_128 names had status 404 | http-sitemap-generator: | Directory structure: | Longest directory structure: | Depth: 0 | Dir: / | Total files found (by extension): |_ | http-security-headers: | Strict_Transport_Security: | HSTS not configured in HTTPS Server | X_Content_Type_Options: | Header: X-Content-Type-Options: nosniff |_ Description: Will prevent the browser from MIME-sniffing a response away from the declared content-type. |_http-csrf: Couldn't find any CSRF vulnerabilities. |_http-drupal-enum: Nothing found amongst the top 100 resources,use --script-args number= for deeper analysis) |_ssl-date: TLS randomness does not represent time | ssl-enum-ciphers: | TLSv1.2: | ciphers: | TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (secp256r1) - A | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A | TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (secp256r1) - A | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (secp256r1) - A | compressors: | NULL | cipher preference: client | warnings: | Key exchange (secp256r1) of lower strength than certificate key | TLSv1.3: | ciphers: | TLS_AKE_WITH_AES_128_GCM_SHA256 (X25519MLKEM768) - A | TLS_AKE_WITH_AES_256_GCM_SHA384 (X25519MLKEM768) - A | TLS_AKE_WITH_CHACHA20_POLY1305_SHA256 (X25519MLKEM768) - A | cipher preference: server |_ least strength: A |_http-date: Tue, 14 Apr 2026 03:34:10 GMT; -3s from local time. |_http-feed: Couldn't find any feeds. |_http-mobileversion-checker: No mobile version detected. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages. |_http-wordpress-enum: Nothing found amongst the top 100 resources,use --script-args search-limit= for deeper analysis) |_http-comments-displayer: Couldn't find any comments. |_http-jsonp-detection: Couldn't find any JSONP endpoints. |_http-referer-checker: Couldn't find any cross-domain scripts. | http-errors: | Spidering limited to: maxpagecount=40; withinhost=grafana.lan.ddnsgeek.com | Found the following error pages: | | Error Code: 404 |_ http://grafana.lan.ddnsgeek.com:443/ | http-useragent-tester: | Status for browser useragent: 404 | Allowed User Agents: | Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html) | libwww | lwp-trivial | libcurl-agent/1.0 | PHP/ | Python-urllib/2.5 | GT::WWW | Snoopy | MFC_Tear_Sample | HTTP::Lite | PHPCrawl | URI::Fetch | Zend_Http_Client | http client | PECL::HTTP | Wget/1.13.4 (linux-gnu) |_ WWW-Mechanize/1.34 |_http-wordpress-users: [Error] Wordpress installation was not found. We couldn't find wp-login.php | http-headers: | Content-Type: text/plain; charset=utf-8 | X-Content-Type-Options: nosniff | Date: Tue, 14 Apr 2026 03:34:18 GMT | Content-Length: 19 | Connection: close | |_ (Request type: GET) |_http-litespeed-sourcecode-download: Request with null byte did not work. This web server might not be vulnerable |_http-chrono: Request times for /; avg: 358.72ms; min: 251.88ms; max: 689.42ms |_http-malware-host: Host appears to be clean |_http-title: Site doesn't have a title (text/plain; charset=utf-8). |_http-stored-xss: Couldn't find any stored XSS vulnerabilities. |_http-fetch: Please enter the complete path of the directory to save data in. | ssl-cert: Subject: commonName=grafana.lan.ddnsgeek.com | Subject Alternative Name: DNS:grafana.lan.ddnsgeek.com | Issuer: commonName=R13/organizationName=Let's Encrypt/countryName=US | Public Key type: rsa | Public Key bits: 4096 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2026-03-29T18:41:52 | Not valid after: 2026-06-27T18:41:51 | MD5: 07d9 97d8 f40d a2d9 1403 9a5d f226 8e1e | SHA-1: a41d 6cbf 7307 408e 9f56 246c 53e7 7f8d 12ce a374 | SHA-256: a829 2621 ef33 c82d 54bc 1466 b7b9 fd97 b794 be37 f4b3 c3a2 4d93 b593 21c7 fd33 | -----BEGIN CERTIFICATE----- | MIIGCjCCBPKgAwIBAgISBkiVQNwIJIiZUfr5fE1dW9QvMA0GCSqGSIb3DQEBCwUA | MDMxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQD | EwNSMTMwHhcNMjYwMzI5MTg0MTUyWhcNMjYwNjI3MTg0MTUxWjAjMSEwHwYDVQQD | ExhncmFmYW5hLmxhbi5kZG5zZ2Vlay5jb20wggIiMA0GCSqGSIb3DQEBAQUAA4IC | DwAwggIKAoICAQC2Wlye1RGu1O4N2S+n/shOsGEOlOFsGYzyu7NhPoRVAhM3r/cF | bNi+AnXqt+aHVRIYqJBZlQNYZJ0c+M/viW+vX1qGFN4dZiUhqHWp9Mi2snmtFbWB | pdzXQpNH7a6LQYKyX+LeCuJwWERXKPTUTgd9JYgwnOCGJdu9tbBRjbE0cjhWWWOC | M/eHPJXFYLuDY7YpWXB8AViWFvhE13cGMwyy1TLX8qom2dBoR3EPDKKJ/uo6MCfa | zXBRpKve2d48U7S7BbKQ9IrlWwruGL43/ghCde7MbYpR1RiAydB79dn65PQJ7TNc | bNKz9A7ar1wwqBhMH0sDbUiNvs81S20gL0vBxy4r0sYUxefTcepLUH5yaiYk7ZcD | U/Zud9uTvjVkbz1yLxst71dLoUdwXruFDZRZz1oaDsWFz9EfvUad5NLvlr9EQhqV | 5TrOiP3g6UsA78uruuDHMiNooXGxCZux6FXrNJV4/QXFebeVaHlSk3hiYHUudqN6 | UROgctzzK8aH1mfadN8PyXD08QlbtCgeL1NtxQJ28FUMspkSXJSq9txmxhrWbI8P | yaikXVV/ut5UwlfOKYVCuLD8kDDYR4wf77GPbt2oPuiDnqb0nOqzTlogMWcZ0/QW | nrbX6o/0Tczl5H8DmS2hbTq00bj//CwIr6WhC3ofZOFOtC4lgCRnLUOGQQIDAQAB | o4ICJjCCAiIwDgYDVR0PAQH/BAQDAgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAwG | A1UdEwEB/wQCMAAwHQYDVR0OBBYEFG00g9+MwX+8cnYYxWRNm1bap+60MB8GA1Ud | IwQYMBaAFOernw8sM6BT015PeMiyhA471pIzMDMGCCsGAQUFBwEBBCcwJTAjBggr | BgEFBQcwAoYXaHR0cDovL3IxMy5pLmxlbmNyLm9yZy8wIwYDVR0RBBwwGoIYZ3Jh | ZmFuYS5sYW4uZGRuc2dlZWsuY29tMBMGA1UdIAQMMAowCAYGZ4EMAQIBMC4GA1Ud | HwQnMCUwI6AhoB+GHWh0dHA6Ly9yMTMuYy5sZW5jci5vcmcvNDguY3JsMIIBDAYK | KwYBBAHWeQIEAgSB/QSB+gD4AHYASZybad4dfOz8Nt7Nh2SmuFuvCoeAGdFVUvvp | 6ynd+MMAAAGdOxyVfwAABAMARzBFAiEA31C4QUdMPck+Q7dCbjWs0cBTXLOmzEEC | 7fujXIvNrQUCIG0SSU6AzEX35sGsawCoVYXyqSSYZVU+xYNH2cfoOSHaAH4AbP5Q | GUOoXqkWvFLRM+TcyR7xQRx9JYQg0XOAnhgY6zoAAAGdOxyY7wAIAAAFAATUAfQE | AwBHMEUCIQDXheUsAJm96qrhW/XUdYDMLdhUONzavisbnO0I3hIBLQIgLfE5yIME | eBR7sOWX0NYAuHpx/nBei4viZ+nYLiv9iHQwDQYJKoZIhvcNAQELBQADggEBACvw | ZvNVT/KDSGJNtGy4FqDRAYZEM2yfeHgWJz5+6wizK2I0h1AGM7a2gG9Uh7l3uspY | Pd24f+/QKnrgBLDt/LocdK0H4h8tRrijn6aQBt29Eo9xWZo/2L/L5qZeceyjmiSM | 3V2kPsKN6m+bKeBGkjSWKcz1jv2ZhE1Vk+XWC8/VBHZJIAmzWJfZQ7isoNtaSVl4 | yi52ZIMoNhvGXOAui6yQtl4igByTJ3BuJeix0RYclP6DZvlZSBeg/csGcIYWah4o | iwPRzaJWZAeMuMarmka2LIdm+jmHExv8j0vRyULPlPtXVQrwoIiK58Kvh2kq+UHD | ANVNGekVQAyZvBHOA4g= |_-----END CERTIFICATE----- Read data files from: /usr/share/nmap Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Tue Apr 14 03:35:32 2026 -- 1 IP address (1 host up) scanned in 102.95 seconds