122.155.3.114

Basic Information

Network
CAT-CLOUD-AP CAT Telecom Public Company Limited (TH)
Routing
122.155.0.0/20 via AS6939 , AS4651 , AS9931 , AS9335
Protocols
80/HTTP, 3306/MYSQL, 993/IMAPS, 995/POP3S, 25/SMTP, 110/POP3, 143/IMAP, 53/DNS, 443/HTTPS, 587/SMTP, 2121/BANNER, 2222/BANNER, 3389/BANNER
Tags
http https database pop3s smtp imaps pop3 dns mysql dhe-export rsa-export imap

80/HTTP


Details Go

GET /

Server
Apache httpd 2
Status Line
200 OK
Page Title
Hosting ����͸�áԨ���������٧ Hosting �ç�ش������ Hosting ����١�������Ѻ
GET /
[view page]

443/HTTPS


Details Go

GET /

Server
Apache httpd 2
Status Line
200 OK
Page Title
Hosting ����͸�áԨ���������٧ Hosting �ç�ش������ Hosting ����١�������Ѻ
GET /
[view page]

Chrome TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x0039)

Heartbleed

Heartbleed
Heartbeat Disabled (OK)

Cryptographic Configuration

SSLv3 Support
True This host is vulnerable to the POODLE attack.
Export DHE
True This host is vulnerable to the Logjam attack.
Export RSA
True This host is vulnerable to the FREAK attack.
DHE Support
True

Certificate Chain

6e912235b916972e11f4fd379dcfa4e02932860607a9fcae012183de78e53b60
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

25/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Exim
Banner
220 ns5.bizqsoft.com ESMTP Exim 4.71 Sun, 17 Oct 2021 01:15:20 +0700
EHLO
250-ns5.bizqsoft.com Hello worker-11.sfj.censys-scanner.com [192.35.168.176]
250-SIZE 20971520
250-PIPELINING
250-AUTH PLAIN LOGIN
250-STARTTLS
250 HELP
STARTTLS
220 TLS go ahead

TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_RSA_WITH_RC4_128_SHA (0x0005)

Certificate Chain

76a81f425785496674ca9ceca5283627800b9aa60e5951a2cebc8d203da1ae28
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

587/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Exim
Banner
220 ns5.bizqsoft.com ESMTP Exim 4.71 Sat, 16 Oct 2021 09:53:50 +0700
EHLO
250-ns5.bizqsoft.com Hello worker-05.sfj.censys-scanner.com [192.35.168.80]
250-SIZE 20971520
250-PIPELINING
250-AUTH PLAIN LOGIN
250-STARTTLS
250 HELP
STARTTLS
220 TLS go ahead

TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_RSA_WITH_RC4_128_SHA (0x0005)

Certificate Chain

76a81f425785496674ca9ceca5283627800b9aa60e5951a2cebc8d203da1ae28
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

53/DNS


Details

Open Resolver Query

Open Resolver
False

110/POP3


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
+OK Dovecot DA ready.
STARTTLS
+OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_RSA_WITH_RC4_128_SHA (0x0005)

Certificate Chain

6e912235b916972e11f4fd379dcfa4e02932860607a9fcae012183de78e53b60
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

143/IMAP


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
* OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE STARTTLS AUTH=PLAIN] Dovecot DA ready.
STARTTLS
a001 OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_RSA_WITH_RC4_128_SHA (0x0005)

Certificate Chain

6e912235b916972e11f4fd379dcfa4e02932860607a9fcae012183de78e53b60
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

993/IMAPS


Details

Banner Grab

Banner
* OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE AUTH=PLAIN] Dovecot DA ready.

TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_RSA_WITH_RC4_128_SHA (0x0005)

Certificate Chain

6e912235b916972e11f4fd379dcfa4e02932860607a9fcae012183de78e53b60
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

995/POP3S


Details

Banner Grab

Banner
+OK Dovecot DA ready.

TLS Handshake

Version
TLSv1.0
Cipher Suite
TLS_RSA_WITH_RC4_128_SHA (0x0005)

Certificate Chain

6e912235b916972e11f4fd379dcfa4e02932860607a9fcae012183de78e53b60
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]
C=US, ST=Someprovince, L=Sometown, O=none, OU=none, CN=localhost, [email protected]

3306/MySQL


Details

Banner Grab

Version
(Unknown)
Protocol Version
0
Error Code
1130
Error
ER_HOST_NOT_PRIVILEGED
Error Message
Host '192.35.168.160' is not allowed to connect to this MySQL server

2121/BANNER View Only


Details

Banner Info

Port
2121
Protocol
TCP
Decoded Banner
220 ProFTPD 1.3.2c Server ready.

2222/BANNER View Only


Details

Banner Info

Port
2222
Protocol
TCP
Decoded Banner
HTTP/1.1 200 OK
Server: DirectAdmin Daemon v1.37.0 Registered to Hostparagon
Set-Cookie: session=; path=/; HttpOnly
Connection: close
Cache-Control: no-cache
Pragma: no-cache
X-DirectAdmin: unauthorized
Content-Type: text/html

<html>
<head>
<title>DirectAdmin Login</title>
<style>
*{ FONT-SIZE: 8pt; FONT-FAMILY: verdana; } b { FONT-WEIGHT: bold; } .listtitle { BACKGROUND: #425984; COLOR: #EEEEEE; white-space: nowrap; } td.list { BACKGROUND: #EEEEEE; white-space: nowrap; } </style>
</head>
<body onload="document.form.username.focus();if(document.form.referer.value.indexOf('#')==-1)document.form.referer.value+=location.hash;">
<center><br><br><br><br>
<h1>DirectAdmin Login Page</h1>
<table cellspacing=1 cellpadding=5>
<tr>
<td class=listtitle colspan=2>Please enter your Username and Password</td></tr>
<form action="/CMD_LOGIN" method="POST" name="form">
<input type=hidden name=referer value="/">
<tr><td class=list align=right>Username:</td><td class=list><input type=text name=username></td></tr>
<tr><

3389/BANNER View Only


Details

Banner Info

Port
3389
Protocol
TCP
Decoded Banner
HTTP/1.1 302 Found
Location: https://122.155.16.56:3389
Content-type: text/html

use https

Geographic Location

City
Udon Thani
Province
Udon Thani
Country
Thailand (TH)
Lat/Long
17.4158, 102.7849
Timezone
Asia/Bangkok