- Server
- SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u2
- Host key
- ssh-ed25519 8b808ff006c582e0…
Raw response
SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u2
Host
Tags: Hosting Self-signed certificate
As of our latest check on 2026-08-26, 104.128.239.87 (HostUS, AS7489, United States) had 4 open ports (22, 80, 8080, 8443) and 87 known CVEs, 1 known to be exploited.
Open ports and CVEs as of our latest check of this host, 2026-08-26.
CVEs by severity: CRITICAL 11 HIGH 44 MEDIUM 25 LOW 7
A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list
Not counted: 5 fixed by the distribution (openssh 9.2p1). See them
Not counted: 2 only affect another platform (http_server 2.4.57). See them
Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.
SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u2
HTTP/1.1 200 OK Date: Wed, 26 Aug 2026 22:12:59 GMT Server: Apache/2.4.57 (Debian) Last-Modified: Wed, 20 Mar 2024 04:57:07 GMT ETag: "29cd-614106c36e8be-gzip" Accept-Ranges: bytes Vary: Accept-Encoding Content-Encoding: gzip Content-Length: 3041 Content-Type: text/html ��Z[s�6~��@��4�H��$�-��I|�d&m<���}�B$$a\��^����o��lSNS�$p.�]>�|s��j��� Y�D��_�~xE�0��˫0��^�������d�h���2�"o~��Ҙl���:X��Z��O�#�:�����Tv�����1��� stvv�v�ZB&KFc�_f(�#�ߜ�.W25,5��&c����a�&D �$ZR����ez;:��S2�v�&�ђ�k6�4��9ͅ!wt����!k��$t��Fm6��<�H�IX���@G��Ԋ���n7$T-x:&��c�߹}��8������7Cw@��w��������F%�4ERH5&�^�^��9�����hN.6c�O�b��!�pD#���oWi��pt���Q��L(3UJ�U�P��g\!�t�>&� j�...<truncated>
HTTP/1.1 400
Content-Type: text/html;charset=utf-8
Content-Language: en
Content-Length: 435
Date: Wed, 26 Aug 2026 22:12:59 GMT
Connection: close
<!doctype html><html lang="en"><head><title>HTTP Status 400 – Bad Request</title><style type="text/css">body {font-family:Tahoma,Arial,sans-serif;} h1, h2, h3, b {color:white;background-color:#525D76;} h1 {font-size:22px;} h2 {font-size:16px;} h3 {font-size:14px;} p {font-size:12px;} a {color:black;} .line {height:1px;background-color:#525D76;border:none;}</style></head><body><h1>HTTP Status 400 – Bad Request</h1></body></html>
HTTP/1.1 400 Bad Request Server: nginx Date: Wed, 26 Aug 2026 22:12:59 GMT Content-Type: text/html Content-Length: 650 Connection: close <html> <head><title>400 The plain HTTP request was sent to HTTPS port</title></head> <body> <center><h1>400 Bad Request</h1></center> <center>The plain HTTP request was sent to HTTPS port</center> <hr><center>nginx</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page -->
The distribution's security data says the package revision this service shows already has the fix for these CVEs, or that its build is not affected. They are not counted.
CVEs by severity: CRITICAL 2 MEDIUM 3
| CVE | Software |
|---|---|
| CVE-2023-28531 CRITICAL 9.8 | openssh 9.2p1 · port 22 |
| CVE-2023-38408 CRITICAL 9.8 | openssh 9.2p1 · port 22 |
| CVE-2023-51385 MEDIUM 6.5 | openssh 9.2p1 · port 22 |
| CVE-2023-48795 MEDIUM 5.9 | openssh 9.2p1 · port 22 |
| CVE-2023-51384 MEDIUM 5.5 | openssh 9.2p1 · port 22 |
These CVEs need a platform this host visibly does not run (for example a flaw of the Windows build on a Linux host). They are not counted.
CVEs by severity: HIGH 2
| CVE | Software |
|---|---|
| CVE-2024-40898 HIGH 7.5 | http_server 2.4.57 · port 80 |
| CVE-2024-43394 HIGH 7.5 | http_server 2.4.57 · port 80 |
Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.