# Nmap 7.95 scan initiated Sat Apr 19 20:21:32 2025 as: nmap -e utun4 -sC -sV -vv -oA nmap/default 10.10.11.49 Nmap scan report for 10.10.11.49 Host is up, received echo-reply ttl 63 (0.12s latency). Scanned at 2025-04-19 20:21:45 CST for 23s Not shown: 996 closed tcp ports (reset) PORT STATE SERVICE REASON VERSION 22/tcp open ssh syn-ack ttl 63 OpenSSH 9.2p1 Debian 2+deb12u4 (protocol 2.0) | ssh-hostkey: | 256 7d:6b:ba:b6:25:48:77:ac:3a:a2:ef:ae:f5:1d:98:c4 (ECDSA) | ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBJuxaL9aCVxiQGLRxQPezW3dkgouskvb/BcBJR16VYjHElq7F8C2ByzUTNr0OMeiwft8X5vJaD9GBqoEul4D1QE= | 256 be:f3:27:9e:c6:d6:29:27:7b:98:18:91:4e:97:25:99 (ED25519) |_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA2oT7Hn4aUiSdg4vO9rJIbVSVKcOVKozd838ZStpwj8 443/tcp open ssl/http syn-ack ttl 63 nginx 1.22.1 |_http-title: 404 Not Found |_http-server-header: nginx/1.22.1 | tls-alpn: | http/1.1 | http/1.0 |_ http/0.9 | ssl-cert: Subject: commonName=127.0.0.1/organizationName=CO/stateOrProvinceName=Illinois/countryName=US/postalCode=7201/localityName=Aurora/streetAddress= | Subject Alternative Name: IP Address:127.0.0.1 | Issuer: commonName=127.0.0.1/organizationName=CO/stateOrProvinceName=Illinois/countryName=US/postalCode=7201/localityName=Aurora/streetAddress= | Public Key type: rsa | Public Key bits: 2048 | Signature Algorithm: sha256WithRSAEncryption | Not valid before: 2025-04-17T19:41:43 | Not valid after: 2028-04-16T19:41:43 | MD5: 9476:5696:8322:7e6b:6c32:9475:a7b6:84ec | SHA-1: 2776:0116:2b52:4a61:ad4a:bd45:d1a3:72d0:bbaa:249a | -----BEGIN CERTIFICATE----- | MIID1TCCAr2gAwIBAgIRAL3BA9vc2XqEqCGX0JDOFcowDQYJKoZIhvcNAQELBQAw | bDELMAkGA1UEBhMCVVMxETAPBgNVBAgTCElsbGlub2lzMQ8wDQYDVQQHEwZBdXJv | cmExCTAHBgNVBAkTADENMAsGA1UEERMENzIwMTELMAkGA1UEChMCQ08xEjAQBgNV | BAMTCTEyNy4wLjAuMTAeFw0yNTA0MTcxOTQxNDNaFw0yODA0MTYxOTQxNDNaMGwx | CzAJBgNVBAYTAlVTMREwDwYDVQQIEwhJbGxpbm9pczEPMA0GA1UEBxMGQXVyb3Jh | MQkwBwYDVQQJEwAxDTALBgNVBBETBDcyMDExCzAJBgNVBAoTAkNPMRIwEAYDVQQD | EwkxMjcuMC4wLjEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCXJKil | TwjPIEVSELZ8ipTegKP00yLysnFv2jM8jwgZrrhCFJF8QHk5zuWDcUyqG4ku1chF | I0BtMJshtWe8NiiQoYvfVjiT6FPhmVwjkFtF0brp5n7HLH+LcAowv5ubfkVxor7b | xxIDKvoACYB4q/FLadLN55vPb+rD4s2ESDPxzwPnTBGqLwTb26GB+718138z1OV/ | Gu+H+7AHwbFub4oUsV4EM3KjAX8Bn6Nk84QoELGUhXzW4Y/7AvH587hgc5lBM4mo | KKj9RJ6XG3kJllXrknGTwbAmxrtK5PejMcn/IEGAmoLZIdMmBJGayPRJF/2t4W0U | LCt1TyMCfdC4gPJRAgMBAAGjcjBwMA4GA1UdDwEB/wQEAwICpDAdBgNVHSUEFjAU | BggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQU | hPux5PLvntKxY1dIciyPd03gkZAwDwYDVR0RBAgwBocEfwAAATANBgkqhkiG9w0B | AQsFAAOCAQEAZI3bdSQVvQxa14wtN7ywTBZT17UHCGectxo5fi6loJM9KQ4OidQv | u1g+bhO4e4cgxZP7Neg1r6kq8s5RaApLIWeWUu9HWCVtnpKaNrc1WaMKNZ5xvkqj | AE9wlVTTmZGfMuhEfmYZr2PpxzWFYkzW35zRLqB7TZMIJhtCmp/vkalFekqRgYDm | ynihWq9V/P4lRP+ohcAU/PE8EBdCAqc3T25bEKgLaNTXKslYFO4oUVhZYMSiSQ6X | 4ElAqD9uv3hBlqU24Y/7WUrbuwWvPPp/OKOktQl7Zccu0AwLansDvVZAuzt6nrp7 | 1tpn9Grc0ltHzMD7WHLm5X3qQML/QaFAKA== |_-----END CERTIFICATE----- |_ssl-date: TLS randomness does not represent time 5000/tcp filtered upnp port-unreach ttl 63 8000/tcp open http syn-ack ttl 63 nginx 1.22.1 |_http-title: Index of / | http-methods: |_ Supported Methods: GET HEAD POST |_http-server-header: nginx/1.22.1 |_http-open-proxy: Proxy might be redirecting requests | http-ls: Volume / | SIZE TIME FILENAME | 1559 17-Dec-2024 12:31 disable_tls.patch | 875 17-Dec-2024 12:34 havoc.yaotl |_ Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Read data files from: /opt/homebrew/bin/../share/nmap Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sat Apr 19 20:22:08 2025 -- 1 IP address (1 host up) scanned in 36.29 seconds
Disable TLS for Websocket management port 40056, so I can prove that sergej is not doing any work Management port only allows local connections (we use ssh forwarding) so this will not compromize our teamserver
$ ilya@backfire:~$ cat hardhat.txt Sergej said he installed HardHatC2 for testing and not made any changes to the defaults I hope he prefers Havoc bcoz I don't wanna learn another C2 framework, also Go > C#