- Banner
- 220 (vsFTPd 3.0.2)
Raw response
220 (vsFTPd 3.0.2)
Host
Tags: Cloud Hosting Expired certificate
As of our latest check on 2026-08-13, 95.40.1.6 (Amazon.com, Inc., AS16509, Hong Kong) had 4 open ports (21, 22, 80, 443) and 21 known CVEs.
Open ports and CVEs as of our latest check of this host, 2026-08-13.
CVEs by severity: HIGH 5 MEDIUM 10 LOW 6
A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list
Not counted: 15 on a distribution build — the fix may be backported (openssh 7.4). See them
Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.
220 (vsFTPd 3.0.2)
SSH-2.0-OpenSSH_7.4
HTTP/1.1 200 OK Date: Thu, 13 Aug 2026 17:00:50 GMT Server: Apache/2.4.68 () OpenSSL/1.1.1zh X-Powered-By: PHP/7.4.33 Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6Img0bWxENmNkeDN5TTlyS3BWZFFaRmc9PSIsInZhbHVlIjoiN2MySHRlVmIwT1pkR1FpM2JmRmVjZjZrWWFzMTFGVElVWjFpd2NYSUZGTUZYNHMvUUFTTXR6YXRsZVlMaGFYTjQzSktpL2ZWeFAzaXAvaVFmRUFvUlYycStzSHVzYTFsQ0VWZTBUQ2kyMkttTXBDRmRzYm5mcnhkeXhTdm9ralMiLCJtYWMiOiJlOWEwNTcwNGNlM2M2OTY2NTU0MzFiZGI2ZDcyNGY5MWE2NDJmM2FhZDQwMjAzZjY4ZDhjMGY4ZTYzYzk4MTY2IiwidGFnIjoiIn0%3D; expires=Thu, 13-Aug-2026 19:00:50 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: hkrita_session=eyJpdiI6InVXU0FWdVZ3RUt6STNDQnQ3YS8wNGc9PSIsInZhbHVlIjoiTzR3OTBmNWdrTFprYmdqL3liUWtQV3hkZy9aZ3AzcUpjWTJieExNSW1BdUpVNnhoZUVvV21OcWFPS3lWYjZkU1RWOGZSRkV5T0tXekR0cVcyem45cGRtVm0rdVZsWU5sYzYzOU5JOGtVQ0pwMU5qRXZUc1B5cnUzYWlnbi91RlQiLCJtYWMiOiJiMWRlZjhmNGQ2NDk5MDAxYzVkMGE2MDY0NjgyODhlMTE4ZmQwNDhjODUyMmEzNDkzYWNlYWVjN2FkMjIzODJjIiwidGFnIjoiIn0%3D; e
HTTP/1.1 400 Bad Request Date: Thu, 13 Aug 2026 17:00:49 GMT Server: Apache/2.4.68 () OpenSSL/1.1.1zh Content-Length: 402 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <html><head> <title>400 Bad Request</title> </head><body> <h1>Bad Request</h1> <p>Your browser sent a request that this server could not understand.<br /> Reason: You're speaking plain HTTP to an SSL-enabled server port.<br /> Instead use the HTTPS scheme to access this URL, please.<br /> </p> </body></html>
These CVEs were matched on software built by an operating-system distribution whose package revision the service does not show. Distributions often fix a flaw without changing the upstream version number, so whether this build is affected cannot be told from its version. They are not counted.
CVEs by severity: CRITICAL 1 HIGH 2 MEDIUM 11 LOW 1
| CVE | Software |
|---|---|
| CVE-2023-38408 CRITICAL 9.8 | openssh 7.4 · port 22 |
| CVE-2020-15778 HIGH 7.4 | openssh 7.4 · port 22 |
| CVE-2021-41617 HIGH 7.0 | openssh 7.4 · port 22 |
| CVE-2019-6109 MEDIUM 6.8 | openssh 7.4 · port 22 |
| CVE-2019-6110 MEDIUM 6.8 | openssh 7.4 · port 22 |
| CVE-2023-51385 MEDIUM 6.5 | openssh 7.4 · port 22 |
| CVE-2019-6111 MEDIUM 5.9 | openssh 7.4 · port 22 |
| CVE-2020-14145 MEDIUM 5.9 | openssh 7.4 · port 22 |
| CVE-2023-48795 MEDIUM 5.9 | openssh 7.4 · port 22 |
| CVE-2016-20012 MEDIUM 5.3 | openssh 7.4 · port 22 |
| CVE-2017-15906 MEDIUM 5.3 | openssh 7.4 · port 22 |
| CVE-2018-15473 MEDIUM 5.3 | openssh 7.4 · port 22 |
| CVE-2018-15919 MEDIUM 5.3 | openssh 7.4 · port 22 |
| CVE-2018-20685 MEDIUM 5.3 | openssh 7.4 · port 22 |
| CVE-2021-36368 LOW 3.7 | openssh 7.4 · port 22 |
Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.