95.110.129.38

Basic Information

Network
ARUBA-ASN (IT)
Routing
95.110.128.0/21 via AS7018 , AS174 , AS31034
Protocols
993/IMAPS, 465/SMTP, 995/POP3S, 25/SMTP, 110/POP3, 21/FTP, 143/IMAP, 53/DNS, 443/HTTPS, 22/SSH, 4190/BANNER, 7080/BANNER, 7081/BANNER, 8443/BANNER, 873/BANNER, 8880/BANNER
Tags
pop3 ftp dns ssh https pop3s smtp imap imaps

443/HTTPS


Details Go

Chrome TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xCCA8)
Browser Trusted
True

Heartbleed

Heartbleed
Heartbeat Disabled (OK)

Cryptographic Configuration

Export DHE
False
Export RSA
False
DHE Support
False

Certificate Chain

c427d0dafd22c639598fec0a38e7ddb4a4c29cf020f795f7e86d06af0c31dfc2
CN=tecnosky.eu
C=US, O=Let's Encrypt, CN=R3
67add1166b020ae61b8f5fc96813c04c2aa589960796865572a3c7e737613dfd
C=US, O=Let's Encrypt, CN=R3
C=US, O=Internet Security Research Group, CN=ISRG Root X1
6d99fb265eb1c5b3744765fcbc648f3cd8e1bffafdc4c2f99b9d47cf7ff1c24f
C=US, O=Internet Security Research Group, CN=ISRG Root X1
O=Digital Signature Trust Co., CN=DST Root CA X3

21/FTP


Details

Banner Grab

Banner:
220 ProFTPD Server (ProFTPD) [95.110.129.38]

22/SSH


Details

SSHv2 Handshake

Server
OpenSSH 7.4
Banner
SSH-2.0-OpenSSH_7.4

Host Key

Algorithm
ecdsa-sha2-nistp256
Fingerprint
e822d7f4aaea23d94d4a8a2f76743b95d34da9eba20dd893573189498e54e3e5

Negotiated Algorithm

Key Exchange
[email protected]
Symmetric Cipher
aes128-ctr [] | aes128-ctr []
MAC
hmac-sha2-256 [] | hmac-sha2-256 []

25/SMTP


Details

Banner Grab and StartTLS Initiation

Server
Postfix
Banner
220 admin90850657.localhost ESMTP Postfix
EHLO
250-admin90850657.localhost
250-PIPELINING
250-SIZE 10240000
250-ETRN
250-STARTTLS
250-AUTH DIGEST-MD5 CRAM-MD5 PLAIN LOGIN
250-ENHANCEDSTATUSCODES
250-8BITMIME
250-DSN
250 CHUNKING
STARTTLS
220 2.0.0 Ready to start TLS

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

9ff74167fab8ace1ec97912271aeb7acf0af9f8b0e603963958e895e088fe808
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]

465/SMTP


Details

Banner Grab

Banner
220 admin90850657.localhost ESMTP Postfix

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xC02F)

Certificate Chain

9ff74167fab8ace1ec97912271aeb7acf0af9f8b0e603963958e895e088fe808
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]

53/DNS


Details

Open Resolver Query

Open Resolver
False

110/POP3


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
+OK Dovecot ready. <[email protected]>
STARTTLS
+OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xC014)

Certificate Chain

9ff74167fab8ace1ec97912271aeb7acf0af9f8b0e603963958e895e088fe808
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]

143/IMAP


Details

Banner Grab and StartTLS Initiation

Server
Dovecot
Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN AUTH=DIGEST-MD5 AUTH=CRAM-MD5] Dovecot ready.
STARTTLS
a001 OK Begin TLS negotiation now.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xC014)

Certificate Chain

9ff74167fab8ace1ec97912271aeb7acf0af9f8b0e603963958e895e088fe808
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]

993/IMAPS


Details

Banner Grab

Banner
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ AUTH=PLAIN AUTH=LOGIN AUTH=DIGEST-MD5 AUTH=CRAM-MD5] Dovecot ready.

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xC014)

Certificate Chain

9ff74167fab8ace1ec97912271aeb7acf0af9f8b0e603963958e895e088fe808
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]

995/POP3S


Details

Banner Grab

Banner
+OK Dovecot ready. <[email protected]>

TLS Handshake

Version
TLSv1.2
Cipher Suite
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xC014)

Certificate Chain

9ff74167fab8ace1ec97912271aeb7acf0af9f8b0e603963958e895e088fe808
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk, [email protected]

4190/BANNER View Only


Details

Banner Info

Port
4190
Protocol
TCP
Decoded Banner
"IMPLEMENTATION" "Dovecot Pigeonhole"
"SIEVE" "fileinto reject envelope encoded-character vacation subaddress comparator-i;ascii-numeric relational regex imap4flags copy include variables body enotify environment mailbox date index ihave duplicate mime foreverypart extracttext imapflags notify"
"NOTIFY" "mailto"
"SASL" "PLAIN LOGIN DIGEST-MD5 CRAM-MD5"
"STARTTLS"
"VERSION" "1.0"
OK "Dovecot ready."

7080/BANNER View Only


Details

Banner Info

Port
7080
Protocol
TCP
Decoded Banner
HTTP/1.1 301 Moved Permanently
Date: Wed, 16 Jun 2021 19:39:09 GMT
Server: Apache
Location: https://95.110.129.38:7080/
Content-Length: 235
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>301 Moved Permanently</title>
</head><body>
<h1>Moved Permanently</h1>
<p>The document has moved <a href="https://95.110.129.38:7080/">here</a>.</p>
</body></html>

7081/BANNER View Only


Details

Banner Info

Port
7081
Protocol
TCP
Decoded Banner
HTTP/1.1 400 Bad Request
Date: Wed, 16 Jun 2021 19:39:09 GMT
Server: Apache
Last-Modified: Sat, 07 Dec 2019 08:05:56 GMT
ETag: "435-59918a1d3c116"
Accept-Ranges: bytes
Content-Length: 1077
Connection: close
Content-Type: text/html

<HTML>
<HEAD>
<TITLE>400 Bad Request</TITLE>
<BASE href="/error_docs/"><!--[if lte IE 6]></BASE><![endif]-->
</HEAD>
<BODY>
<H1>Bad Request</H1>
Your browser sent a request that this server could not understand.
<P>
Client sent malformed Host header
<P>
<HR>
<ADDRESS>
Web Server at tecnosky.eu
</ADDRESS>
</BODY>
</HTML>

<!--
   - Unfortunately, Microsoft has added a clever new
   - "feature" to Internet Explorer. If the text of
   - an error's message is "too small", specifically
   - less than 512 bytes, Internet Explorer returns
   - its own error message. You can turn that off,
   - but it's pretty tricky to find switch called
   - "smart error messages". That means, of course,
   - that short error messages are censored by default.
   - IIS always returns error messa

8443/BANNER View Only


Details

Banner Info

Port
8443
Protocol
TCP
Decoded Banner
HTTP/1.1 302 Moved Temporarily
Server: sw-cp-server
Date: Wed, 16 Jun 2021 19:39:09 GMT
Content-Type: text/html
Content-Length: 138
Connection: close
Location: https://95.110.129.38:8443/

<html>
<head><title>302 Found</title></head>
<body>
<center><h1>302 Found</h1></center>
<hr><center>nginx</center>
</body>
</html>

873/BANNER View Only


Details

Banner Info

Port
873
Protocol
TCP
Decoded Banner
@RSYNCD: 31.0

8880/BANNER View Only


Details

Banner Info

Port
8880
Protocol
TCP
Decoded Banner
HTTP/1.1 303 See Other
Server: sw-cp-server
Date: Wed, 16 Jun 2021 19:39:09 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Expires: Fri, 28 May 1999 00:00:00 GMT
Last-Modified: Wed, 16 Jun 2021 19:39:09 GMT
Cache-Control: no-store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Pragma: no-cache
P3P: CP="NON COR CURa ADMa OUR NOR UNI COM NAV STA"
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Location: http://95.110.129.38:8880/login.php?success_redirect_url=%2F

0

Geographic Location

City
Arezzo
Province
Tuscany
Country
Italy (IT)
Lat/Long
43.4631, 11.8783
Timezone
Europe/Rome