β File: targeted
ββββββββΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
1 β # Nmap 7.95 scan initiated Tue Jul 15 00:24:03 2025 as: /usr/lib/nmap/nmap --privileged -sCV -p135,139,1433,3268,3269,389,4411,445,464,49666,49673,49674,
β 49716,49720,593,5985,636,80,88,9389,53 -oN targeted 10.10.11.168
2 β Nmap scan report for 10.10.11.168
3 β Host is up (0.38s latency).
4 β
5 β Bug in ms-sql-ntlm-info: no string output.
6 β PORT STATE SERVICE VERSION
7 β 53/tcp open domain Simple DNS Plus
8 β 80/tcp open http Microsoft IIS httpd 10.0
9 β |_http-server-header: Microsoft-IIS/10.0
10 β |_http-title: Scramble Corp Intranet
11 β 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-07-14 22:24:12Z)
12 β 135/tcp open msrpc Microsoft Windows RPC
13 β 139/tcp open netbios-ssn Microsoft Windows netbios-ssn
14 β 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: scrm.local0., Site: Default-First-Site-Name)
15 β |_ssl-date: 2025-07-14T22:27:30+00:00; 0s from scanner time.
16 β | ssl-cert: Subject:
17 β | Subject Alternative Name: DNS:DC1.scrm.local
18 β | Not valid before: 2024-09-04T11:14:45
19 β |_Not valid after: 2121-06-08T22:39:53
20 β 445/tcp open microsoft-ds?
21 β 464/tcp open kpasswd5?
22 β 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
23 β 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: scrm.local0., Site: Default-First-Site-Name)
24 β |_ssl-date: 2025-07-14T22:27:29+00:00; 0s from scanner time.
25 β | ssl-cert: Subject:
26 β | Subject Alternative Name: DNS:DC1.scrm.local
27 β | Not valid before: 2024-09-04T11:14:45
28 β |_Not valid after: 2121-06-08T22:39:53
29 β 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM
30 β | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
31 β | Not valid before: 2025-07-14T22:21:42
32 β |_Not valid after: 2055-07-14T22:21:42
33 β |_ssl-date: 2025-07-14T22:27:30+00:00; 0s from scanner time.
34 β | ms-sql-info:
35 β | 10.10.11.168:1433:
36 β | Version:
37 β | name: Microsoft SQL Server 2019 RTM
38 β | number: 15.00.2000.00
39 β | Product: Microsoft SQL Server 2019
40 β | Service pack level: RTM
41 β | Post-SP patches applied: false
42 β |_ TCP port: 1433
43 β 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: scrm.local0., Site: Default-First-Site-Name)
44 β |_ssl-date: 2025-07-14T22:27:30+00:00; 0s from scanner time.
45 β | ssl-cert: Subject:
46 β | Subject Alternative Name: DNS:DC1.scrm.local
47 β | Not valid before: 2024-09-04T11:14:45
48 β |_Not valid after: 2121-06-08T22:39:53
49 β 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: scrm.local0., Site: Default-First-Site-Name)
50 β |_ssl-date: 2025-07-14T22:27:29+00:00; 0s from scanner time.
51 β | ssl-cert: Subject:
52 β | Subject Alternative Name: DNS:DC1.scrm.local
53 β | Not valid before: 2024-09-04T11:14:45
54 β |_Not valid after: 2121-06-08T22:39:53
55 β 4411/tcp open found?
56 β | fingerprint-strings:
57 β | DNSStatusRequestTCP, DNSVersionBindReqTCP, GenericLines, JavaRMI, Kerberos, LANDesk-RC, LDAPBindReq, LDAPSearchReq, NCP, NULL, NotesRPC, RPCCheck, SM
β BProgNeg, SSLSessionReq, TLSSessionReq, TerminalServer, TerminalServerCookie, WMSRequest, X11Probe, afp, ms-sql-s, oracle-tns:
58 β | SCRAMBLECORP_ORDERS_V1.0.3;
59 β | FourOhFourRequest, GetRequest, HTTPOptions, Help, LPDString, RTSPRequest, SIPOptions:
60 β | SCRAMBLECORP_ORDERS_V1.0.3;
61 β |_ ERROR_UNKNOWN_COMMAND;
62 β 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
63 β |_http-title: Not Found
64 β |_http-server-header: Microsoft-HTTPAPI/2.0
65 β 9389/tcp open mc-nmf .NET Message Framing
66 β 49666/tcp open msrpc Microsoft Windows RPC
67 β 49673/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
68 β 49674/tcp open msrpc Microsoft Windows RPC
69 β 49716/tcp open msrpc Microsoft Windows RPC
70 β 49720/tcp open msrpc Microsoft Windows RPC
71 β 1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submi
β t.cgi?new-service :
72 β SF-Port4411-TCP:V=7.95%I=7%D=7/15%Time=6875838B%P=x86_64-pc-linux-gnu%r(NU
73 β SF:LL,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(GenericLines,1D,"SCRAMBLEC
74 β SF:ORP_ORDERS_V1\.0\.3;\r\n")%r(GetRequest,35,"SCRAMBLECORP_ORDERS_V1\.0\.
75 β SF:3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(HTTPOptions,35,"SCRAMBLECORP_ORDER
76 β SF:S_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(RTSPRequest,35,"SCRAMBLEC
77 β SF:ORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(RPCCheck,1D,"SCR
78 β SF:AMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(DNSVersionBindReqTCP,1D,"SCRAMBLECOR
79 β SF:P_ORDERS_V1\.0\.3;\r\n")%r(DNSStatusRequestTCP,1D,"SCRAMBLECORP_ORDERS_
80 β SF:V1\.0\.3;\r\n")%r(Help,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNO
81 β SF:WN_COMMAND;\r\n")%r(SSLSessionReq,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n
82 β SF:")%r(TerminalServerCookie,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(TLS
83 β SF:SessionReq,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(Kerberos,1D,"SCRAM
84 β SF:BLECORP_ORDERS_V1\.0\.3;\r\n")%r(SMBProgNeg,1D,"SCRAMBLECORP_ORDERS_V1\
85 β SF:.0\.3;\r\n")%r(X11Probe,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(FourO
86 β SF:hFourRequest,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND
87 β SF:;\r\n")%r(LPDString,35,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_
88 β SF:COMMAND;\r\n")%r(LDAPSearchReq,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%
89 β SF:r(LDAPBindReq,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(SIPOptions,35,"
90 β SF:SCRAMBLECORP_ORDERS_V1\.0\.3;\r\nERROR_UNKNOWN_COMMAND;\r\n")%r(LANDesk
91 β SF:-RC,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(TerminalServer,1D,"SCRAMB
92 β SF:LECORP_ORDERS_V1\.0\.3;\r\n")%r(NCP,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r
93 β SF:\n")%r(NotesRPC,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(JavaRMI,1D,"S
94 β SF:CRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(WMSRequest,1D,"SCRAMBLECORP_ORDERS
95 β SF:_V1\.0\.3;\r\n")%r(oracle-tns,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r
96 β SF:(ms-sql-s,1D,"SCRAMBLECORP_ORDERS_V1\.0\.3;\r\n")%r(afp,1D,"SCRAMBLECOR
97 β SF:P_ORDERS_V1\.0\.3;\r\n");
98 β Service Info: Host: DC1; OS: Windows; CPE: cpe:/o:microsoft:windows
99 β
100 β Host script results:
101 β | smb2-time:
102 β | date: 2025-07-14T22:26:54
103 β |_ start_date: N/A
104 β | smb2-security-mode:
105 β | 3:1:1:
106 β |_ Message signing enabled and required
107 β