46.189.33.245

25 May 2025, 16:43:56 UTC
{
  "scan_id": 1747899065,
  "ip": "46.189.33.245",
  "is_ipv4": true,
  "is_ipv6": false,
  "location": {
    "network": "46.189.33.192/26",
    "postal_code": "13357",
    "coordinates": {
      "latitude": "52.5481",
      "longitude": "13.3844"
    },
    "geo_point": "52.5481, 13.3844",
    "locale_code": "en",
    "continent": "Europe",
    "country_code": "DE",
    "country_name": "Germany",
    "city": "Berlin"
  },
  "location_updated_at": "2025-05-25T12:08:17Z",
  "asn": {
    "number": "AS8881",
    "organization": "1&1 Versatel Deutschland GmbH",
    "country_code": ""
  },
  "asn_updated_at": "0001-01-01T00:00:00Z",
  "whois": {
    "network": "46.189.0.0/17",
    "organization": "Versatel Deutschland",
    "descr": "Versatel Deutschland",
    "_encoding": {
      "raw": "BASE64"
    }
  },
  "whois_updated_at": "2024-12-09T08:53:11Z",
  "tags": [
    {
      "name": "is_anonymous_proxy",
      "pretty_name": "Anonymous Proxy",
      "value": false,
      "last_updated_at": "2025-05-25T12:08:17Z"
    },
    {
      "name": "is_cdn",
      "pretty_name": "CDN",
      "value": false,
      "last_updated_at": "2025-05-25T12:10:05Z"
    },
    {
      "name": "is_satellite_provider",
      "pretty_name": "Satellite Provider",
      "value": false,
      "last_updated_at": "2025-05-25T12:08:17Z"
    }
  ],
  "services": [
    {
      "port": 80,
      "protocol": "tcp",
      "name": "http",
      "version": "",
      "product": "Apache httpd",
      "extra_info": "",
      "tunnel": "",
      "softwares": [
        {
          "uri": "cpe:/a:apache:http_server",
          "part": "a",
          "vendor": "apache",
          "product": "http_server",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "body_murmur": 1927249570,
          "body_sha256": "6a0dc9833b21bad29e6b4e2a539aa8e48635dcdff27a1c1c1a500a1daaa5cca8",
          "component": [
            "Apache HTTP Server",
            "Django",
            "Python"
          ],
          "content_length": -1,
          "headers": {
            "cache_control": [
              "max-age=0"
            ],
            "content_language": [
              "en"
            ],
            "content_type": [
              "text/html; charset=utf-8"
            ],
            "date": [
              "Sun, 25 May 2025 16:43:53 GMT"
            ],
            "expires": [
              "Sun, 25 May 2025 16:43:53 GMT"
            ],
            "last_modified": [
              "Sun, 25 May 2025 16:43:53 GMT"
            ],
            "server": [
              "Apache"
            ],
            "set_cookie": [
              "csrftoken=4dK8gjtnT7VC2zdgwTctgYSdWNHmUgbQ; expires=Sun, 24-May-2026 16:43:53 GMT; httponly; Max-Age=31449600; Path=/; secure",
              "sessionid=m3776w3ax1j3g4f7ktf35e5vwhrrmr9e; httponly; Path=/; secure"
            ],
            "vary": [
              "Cookie,Accept-Language,Accept-Encoding"
            ],
            "x_content_type_options": [
              "nosniff"
            ],
            "x_xss_protection": [
              "1; mode=block"
            ]
          },
          "protocol": "HTTP/1.1",
          "redirects": [
            {
              "body_murmur": -1189535228,
              "body_sha256": "8d60c4d57b0dce9ff3e01525654d67f9efc31269ba5d429896b6f9f52a9aba09",
              "content_length": 210,
              "location": "https://46.189.33.245:443/",
              "status_code": 302,
              "status_line": "302 Found"
            },
            {
              "location": "https://46.189.33.245:443/wbm/login/",
              "status_code": 302,
              "status_line": "302 FOUND"
            }
          ],
          "status_code": 200,
          "title": "Logon - SINEMA Remote Connect"
        }
      },
      "cve": [
        {
          "id": "CVE-1999-0070",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-1199",
          "severity": "high"
        },
        {
          "id": "CVE-2023-25690",
          "severity": "critical"
        }
      ],
      "url": "http://46.189.33.245/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-05-25T16:43:56.4Z"
    },
    {
      "port": 443,
      "protocol": "tcp",
      "name": "http",
      "version": "",
      "product": "Apache httpd",
      "extra_info": "",
      "tunnel": "ssl",
      "softwares": [
        {
          "uri": "cpe:/a:apache:http_server",
          "part": "a",
          "vendor": "apache",
          "product": "http_server",
          "version": "ANY",
          "language": "ANY",
          "edition": "ANY",
          "update": "ANY"
        }
      ],
      "modules": {
        "http": {
          "body_murmur": 903357496,
          "body_sha256": "c02016e7971750a1db61fad940abee35a069bf71151c2d80d97b7f90c512fb7b",
          "component": [
            "Apache HTTP Server",
            "Django",
            "Python"
          ],
          "content_length": -1,
          "headers": {
            "cache_control": [
              "max-age=0"
            ],
            "content_language": [
              "en"
            ],
            "content_type": [
              "text/html; charset=utf-8"
            ],
            "date": [
              "Sun, 25 May 2025 01:43:02 GMT"
            ],
            "expires": [
              "Sun, 25 May 2025 01:43:02 GMT"
            ],
            "last_modified": [
              "Sun, 25 May 2025 01:43:02 GMT"
            ],
            "server": [
              "Apache"
            ],
            "set_cookie": [
              "csrftoken=ET4xkSS0M1Y15ircUimtbGSjitpoAaeC; expires=Sun, 24-May-2026 01:43:02 GMT; httponly; Max-Age=31449600; Path=/; secure",
              "sessionid=da2hb6v9qd5hplskt5roof8fy0dnp6bq; httponly; Path=/; secure"
            ],
            "vary": [
              "Cookie,Accept-Language,Accept-Encoding"
            ],
            "x_content_type_options": [
              "nosniff"
            ],
            "x_xss_protection": [
              "1; mode=block"
            ]
          },
          "protocol": "HTTP/1.1",
          "redirects": [
            {
              "location": "https://46.189.33.245/wbm/login/",
              "status_code": 302,
              "status_line": "302 FOUND"
            }
          ],
          "status_code": 200,
          "title": "Logon - SINEMA Remote Connect"
        },
        "tls": {
          "certificate": {
            "extensions": {
              "authority_info_access": {
                "issuer_urls": [
                  "http://crt.comodoca.com/COMODORSADomainValidationSecureServerCA.crt"
                ],
                "ocsp_urls": [
                  "http://ocsp.comodoca.com"
                ]
              },
              "authority_key_id": "90af6a3a945a0bd890ea125673df43b43a28dae7",
              "basic_constraints": {
                "is_ca": true
              },
              "certificate_policies": [
                {
                  "cps": [
                    "https://secure.comodo.com/CPS"
                  ],
                  "id": "1.3.6.1.4.1.6449.1.2.2.7"
                },
                {
                  "id": "2.23.140.1.2.1"
                }
              ],
              "crl_distribution_points": [
                "http://crl.comodoca.com/COMODORSADomainValidationSecureServerCA.crl"
              ],
              "extended_key_usage": {
                "any": false,
                "apple_code_signing": false,
                "apple_code_signing_development": false,
                "apple_code_signing_third_party": false,
                "apple_crypto_development_env": false,
                "apple_crypto_env": false,
                "apple_crypto_maintenance_env": false,
                "apple_crypto_production_env": false,
                "apple_crypto_qos": false,
                "apple_crypto_test_env": false,
                "apple_crypto_tier0_qos": false,
                "apple_crypto_tier1_qos": false,
                "apple_crypto_tier2_qos": false,
                "apple_crypto_tier3_qos": false,
                "apple_ichat_encryption": false,
                "apple_ichat_signing": false,
                "apple_resource_signing": false,
                "apple_software_update_signing": false,
                "apple_system_identity": false,
                "client_auth": true,
                "code_signing": false,
                "dvcs": false,
                "eap_over_lan": false,
                "eap_over_ppp": false,
                "email_protection": false,
                "ipsec_end_system": false,
                "ipsec_intermediate_system_usage": false,
                "ipsec_tunnel": false,
                "ipsec_user": false,
                "microsoft_ca_exchange": false,
                "microsoft_cert_trust_list_signing": false,
                "microsoft_csp_signature": false,
                "microsoft_document_signing": false,
                "microsoft_drm": false,
                "microsoft_drm_individualization": false,
                "microsoft_efs_recovery": false,
                "microsoft_embedded_nt_crypto": false,
                "microsoft_encrypted_file_system": false,
                "microsoft_enrollment_agent": false,
                "microsoft_kernel_mode_code_signing": false,
                "microsoft_key_recovery_21": false,
                "microsoft_key_recovery_3": false,
                "microsoft_license_server": false,
                "microsoft_licenses": false,
                "microsoft_lifetime_signing": false,
                "microsoft_mobile_device_software": false,
                "microsoft_nt5_crypto": false,
                "microsoft_oem_whql_crypto": false,
                "microsoft_qualified_subordinate": false,
                "microsoft_root_list_signer": false,
                "microsoft_server_gated_crypto": false,
                "microsoft_sgc_serialized": false,
                "microsoft_smart_display": false,
                "microsoft_smartcard_logon": false,
                "microsoft_system_health": false,
                "microsoft_system_health_loophole": false,
                "microsoft_timestamp_signing": false,
                "microsoft_whql_crypto": false,
                "netscape_server_gated_crypto": false,
                "ocsp_signing": false,
                "sbgp_cert_aa_service_auth": false,
                "server_auth": true,
                "time_stamping": false
              },
              "key_usage": {
                "certificate_sign": false,
                "content_commitment": false,
                "crl_sign": false,
                "data_encipherment": false,
                "decipher_only": false,
                "digital_signature": true,
                "encipher_only": false,
                "key_agreement": false,
                "key_encipherment": true
              },
              "subject_alt_name": {
                "dns_names": [
                  "management.novacolonia.de",
                  "www.management.novacolonia.de"
                ]
              },
              "subject_key_id": "c3270b2dbb8fed2cbaf2a3245f383eb15b428bdd"
            },
            "fingerprint_md5": "D7989005DAD9C94ACAC3BA000CA98344",
            "fingerprint_sha1": "F483EC2FB2E69CB57A96B99ED66159EF8EBE6F0D",
            "fingerprint_sha256": "D02413E1082DF07134F1046D42CE6EA3D51B8D35218D17597CC97FAA13FC6E00",
            "issuer": {
              "common_name": [
                "COMODO RSA Domain Validation Secure Server CA"
              ],
              "country": [
                "GB"
              ],
              "locality": [
                "Salford"
              ],
              "organization": [
                "COMODO CA Limited"
              ],
              "province": [
                "Greater Manchester"
              ]
            },
            "jarm": "16d16d16d14d16d00016d16d16d16d7bf6e7a34fd706e3a25b03da2a17f6af",
            "redacted": false,
            "revocation": {
              "crl": {
                "next_update": "2025-05-31T10:51:04",
                "reason": "UNKNOWN",
                "revoked": false
              },
              "ocsp": {
                "reason": "UNKNOWN",
                "revoked": false
              }
            },
            "serial_number": "7448081861766509030916739633881871679",
            "signature": {
              "algorithm": {
                "name": "SHA256-RSA",
                "oid": "1.2.840.113549.1.1.11"
              },
              "self_signed": false
            },
            "signed_certificate_timestamps": [
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "ee4bbdb775ce60bae142691fabe19e66a30f7e5fb072d88300c47b897aa8fdcb",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "3046022100a96da1937217ae3f174418a2b11ace2fcfb1ce64c581b2726df7fda4fa7f76ed022100bf95d5795e8a0c41103cef2ce16676d1bf36442067cf4f674359fe10addeef99"
                },
                "timestamp": "2018-08-28T23:31:16.015000",
                "version": "v1"
              },
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "5ea773f9df56c0e7b536487dd049e0327a919a0c84a112128418759681714558",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "304402203cb72f8da42d4c424f1984a6597554c6e7754192fb21f23a49c0a4527d9f372702204143295d744625d01f61fb740581b3791aff7cec87638c7c2a2c0ca50a71525b"
                },
                "timestamp": "2018-08-28T23:31:15.852000",
                "version": "v1"
              },
              {
                "entry_type": "PRE_CERTIFICATE",
                "log_id": "5581d4c2169036014aea0b9b573c53f0c0e43878702508172fa3aa1d0713d30c",
                "signature": {
                  "algorithm": "ECDSA",
                  "hash_algorithm": "SHA256",
                  "value": "304502210091ab9b8a5c9f04e6dac70a51d7fe7b21cb35e7845f4c52d1b2c7a373ca409fc80220042e9b0117b9be8a95d822141a8efd6f24b3fd25fe5c23e9c78151248cc6ed73"
                },
                "timestamp": "2018-08-28T23:31:16.041000",
                "version": "v1"
              }
            ],
            "signed_certificate_timestamps_oid": "1.3.6.1.4.1.11129.2.4.2",
            "subject": {
              "common_name": [
                "management.novacolonia.de"
              ],
              "organizational_unit": [
                "Domain Control Validated",
                "PositiveSSL"
              ]
            },
            "subject_alt_name": {
              "dns_names": [
                "management.novacolonia.de",
                "www.management.novacolonia.de"
              ],
              "extended_dns_names": [
                {
                  "domain": "novacolonia",
                  "fld": "novacolonia.de",
                  "subdomain": "management",
                  "tld": "de"
                },
                {
                  "domain": "novacolonia",
                  "fld": "novacolonia.de",
                  "subdomain": "www.management",
                  "tld": "de"
                }
              ]
            },
            "subject_key_info": {
              "_key": "rsa",
              "dh": [],
              "dsa": [],
              "ecdsa": [],
              "fingerprint_sha256": "262ae72cd679b11d7063f4c101f7178f6644d946a3b5a20b4e6301a726dd364b",
              "key_algorithm": "RSA",
              "rsa": {
                "exponent": 65537,
                "length": 2048
              }
            },
            "tbs_fingerprint": "e718b647e7f5e43e8f355130465b40969834131b098a7b2291a3747eb1546a84",
            "tbs_noct_fingerprint": "2061975bee09f8a293bd721c44cd82bd00e12294886850ef0c1d2fc98e6ab2ce",
            "validation_level": "OV",
            "validity": {
              "length_seconds": 63158400,
              "not_after": "2020-08-27T23:59:59",
              "not_before": "2018-08-28T00:00:00"
            },
            "version": 2
          },
          "fingerprint_sha256": "D02413E1082DF07134F1046D42CE6EA3D51B8D35218D17597CC97FAA13FC6E00",
          "precert": false,
          "tags": [
            "ov",
            "trusted"
          ]
        }
      },
      "cve": [
        {
          "id": "CVE-1999-0070",
          "severity": "medium"
        },
        {
          "id": "CVE-1999-1199",
          "severity": "high"
        },
        {
          "id": "CVE-2023-25690",
          "severity": "critical"
        }
      ],
      "url": "https://46.189.33.245/",
      "_meta": {
        "name": "",
        "desc": "",
        "category": ""
      },
      "last_updated_at": "2025-05-25T04:03:25.666Z"
    }
  ],
  "services_hash": "36fe48639232966d8469f99909eac929d9eec421beeab93996636162bae55fff",
  "last_updated_at": "2025-05-25T16:43:56.4Z",
  "banner": [
    "http",
    "tls"
  ],
  "is_vuln": true,
  "cveDetails": {
    "CVE-1999-0070": {
      "id": "CVE-1999-0070",
      "references": [
        "https://lists.apache.org/thread.html/rc5d27fc1e76dc5650e1a3f1db1de403120f4c2d041cb7352850455c2%40%3Cusers.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rc5d27fc1e76dc5650e1a3f1db1de403120f4c2d041cb7352850455c2%40%3Cusers.httpd.apache.org%3E"
      ],
      "score": 5,
      "services": [
        "80/http"
      ],
      "severity": "medium",
      "summary": "test-cgi program allows an attacker to list files on the server.",
      "vector_string": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
      "weakness": "NVD-CWE-noinfo"
    },
    "CVE-1999-1199": {
      "id": "CVE-1999-1199",
      "references": [
        "http://marc.info/?l=bugtraq&m=90252779826784&w=2",
        "http://marc.info/?l=bugtraq&m=90276683825862&w=2",
        "http://marc.info/?l=bugtraq&m=90280517007869&w=2",
        "http://marc.info/?l=bugtraq&m=90286768232093&w=2",
        "http://www.redhat.com/support/errata/rh51-errata-general.html#apache",
        "https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E",
        "http://marc.info/?l=bugtraq&m=90252779826784&w=2",
        "http://marc.info/?l=bugtraq&m=90276683825862&w=2",
        "http://marc.info/?l=bugtraq&m=90280517007869&w=2",
        "http://marc.info/?l=bugtraq&m=90286768232093&w=2",
        "http://www.redhat.com/support/errata/rh51-errata-general.html#apache",
        "https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E",
        "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E"
      ],
      "score": 10,
      "services": [
        "80/http"
      ],
      "severity": "high",
      "summary": "Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the \"sioux\" vulnerability.",
      "vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
      "weakness": "NVD-CWE-Other"
    },
    "CVE-2023-25690": {
      "id": "CVE-2023-25690",
      "references": [
        "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",
        "https://security.gentoo.org/glsa/202309-01",
        "http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html",
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",
        "https://security.gentoo.org/glsa/202309-01"
      ],
      "score": 9.8,
      "services": [
        "80/http"
      ],
      "severity": "critical",
      "summary": "Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.\n\n\n\n\nConfigurations are affected when mod_proxy is enabled along with some form of RewriteRule\n or ProxyPassMatch in which a non-specific pattern matches\n some portion of the user-supplied request-target (URL) data and is then\n re-inserted into the proxied request-target using variable \nsubstitution. For example, something like:\n\n\n\n\nRewriteEngine on\nRewriteRule \"^/here/(.*)\" \"http://example.com:8080/elsewhere?$1\"; [P]\nProxyPassReverse /here/ http://example.com:8080/\n\n\nRequest splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "weakness": "CWE-444"
    },
    "CVE-2023-27522": {
      "id": "CVE-2023-27522",
      "references": [
        "https://httpd.apache.org/security/vulnerabilities_24.html",
        "https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",
        "https://security.gentoo.org/glsa/202309-01"
      ],
      "score": 7.5,
      "services": [
        "80/http"
      ],
      "severity": "high",
      "summary": "HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.nnSpecial characters in the origin response header can truncate/split the response forwarded to the client.nnn",
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
      "weakness": "CWE-444"
    }
  }
}
0 people
are viewing this site
0 people
viewed this page
in the last