Scan of

Similar documents
Acunetix Website Audit. 31 October, Developer Report. Generated by Acunetix WVS Reporter (v9.0 Build )

Website Security Audit. 28 September, Developer Report. Generated by Acunetix WVS Reporter (v10.5 Build )

HTTP Protocol and Server-Side Basics

ECCouncil Exam v8 Certified Ethical Hacker v8 Exam Version: 7.0 [ Total Questions: 357 ]

COSC 2206 Internet Tools. The HTTP Protocol

RBS NetGain Enterprise Manager Multiple Vulnerabilities of 11

Activating Intrusion Prevention Service

Cisco Threat Awareness Service - Quick Start Guide. Last Updated: 16/06/16

User Manual. Admin Report Kit for IIS 7 (ARKIIS)

The HTTP Protocol HTTP

AN E-GOVERNANCE WEB SECURITY AUDIT Deven Pandya 1, Dr. N. J. Patel 2 1 Research Scholar, Department of Computer Application

Web Application & Web Server Vulnerabilities Assessment Pankaj Sharma

01/02/2014 SECURITY ASSESSMENT METHODOLOGIES SENSEPOST 2014 ALL RIGHTS RESERVED

Bomgar Vault Server Installation Guide

Browser Guide for PeopleSoft

Internet Architecture. Web Programming - 2 (Ref: Chapter 2) IP Software. IP Addressing. TCP/IP Basics. Client Server Basics. URL and MIME Types HTTP

Network Vulnerability Scan

GUI based and very easy to use, no security expertise required. Reporting in both HTML and RTF formats - Click here to view the sample report.

ICS 351: Today's plan. HTTPS: SSL and TLS certificates cookies DNS reminder Simple Network Management Protocol

ICS 351: Today's plan. web scripting languages HTTPS: SSL and TLS certificates cookies DNS reminder

Computer Forensics: Investigating Network Intrusions and Cyber Crime, 2nd Edition. Chapter 3 Investigating Web Attacks

CSC 5930/9010 Offensive Security: OSINT

Detecting Specific Threats

Penetration Test Report

Ethical Hacking as a Professional Penetration Testing Technique ISSA Southern Tier & Rochester Chapters

ICS 351: Today's plan. IPv6 routing protocols (summary) HTML HTTP web scripting languages certificates (review) cookies

Stopping Automated Application Attack Tools

Attacks Against Websites 3 The OWASP Top 10. Tom Chothia Computer Security, Lecture 14

HTTP Reading: Section and COS 461: Computer Networks Spring 2013

Threat Landscape 2017

ICS 351: Today's plan. web scripting languages HTTPS: SSL and TLS certificates cookies DNS reminder

Information Network Systems The application layer. Stephan Sigg

Actual4Test. Actual4test - actual test exam dumps-pass for IT exams

Ethical Hacking and Countermeasures: Web Applications, Second Edition. Chapter 3 Web Application Vulnerabilities

Scan Report. Contents. November 15, Result Overview 2

White Paper: Next-Gen Network Traffic Analysis (NTA): Log-based NTA vs. Packet-based NTA

[Frequently Asked Questions] Accommodation Booking Website

AppSpider Enterprise. Getting Started Guide

Combating Common Web App Authentication Threats

Creating a Multi-data Center (MDC) System

Frequently Asked Questions About Performance Monitor

Tenable.io for Thycotic

Andrew Muller, Canberra Managing Director, Ionize, Canberra The challenges of Security Testing. Security Testing. Taming the Wild West

Web Application Security GVSAGE Theater

Web Application Penetration Testing

CNIT 129S: Securing Web Applications. Ch 10: Attacking Back-End Components

DomainTools App for QRadar

IronWASP (Iron Web application Advanced Security testing Platform)

WEB TECHNOLOGIES CHAPTER 1

Proofpoint Threat Response

User Manual. Admin Report Kit for IIS (ARKIIS)

Microsoft Exchange Proxy Settings Outlook 2010 Gpo

AppGate 11.0 RELEASE NOTES

Application Layer Introduction; HTTP; FTP

Acunetix Website Audit. 31 October, Developer Report. Generated by Acunetix WVS Reporter (v9.0 Build )

COMP9321 Web Application Engineering

Table Of Contents INTRODUCTION... 6 USER GUIDE Software Installation Installing MSI-based Applications for Users...9

Offensive Technologies

CIS 700/002 : Special Topics : OWASP ZED (ZAP)

TCP/IP Networking Basics

Deploy and Secure an Internet Facing Application with the Barracuda Web Application Firewall in Amazon Web Services

Barracuda Web Application Firewall Foundation - WAF01. Lab Guide

SonicOS Enhanced Release Notes

Executive Summary. Performance Report for: The web should be fast. Top 4 Priority Issues

Configure ACE with Source NAT and Client IP Header Insert

Configuring the Management Access List

Partner Integration Portal (PIP) Installation Guide

COMP9321 Web Application Engineering

Monitoring the Device

OWASP Thailand. Proxy Caches and Web Application Security. OWASP AppSec Asia October 21, Using the Recent Google Docs 0-Day as an Example

Produced by. Mobile Application Development. Higher Diploma in Science in Computer Science. Eamonn de Leastar

Multiple vulnerabilities in WordPress Health Check & Troubleshooting plugin < 1.2.4

Web Application Whitepaper

TIBCO Cloud Integration Security Overview

Web Application Attacks

Click Studios. Passwordstate. Remote Session Launcher. Installation Instructions

McAfee Gateway Appliance Patch 7.5.3

Fireware-Essentials. Number: Fireware Essentials Passing Score: 800 Time Limit: 120 min File Version: 7.

GTIC Monthly Threat Report June 2017

Page 1 of 20 webforms Browser Configuration Guide

Exploiting and Defending: Common Web Application Vulnerabilities

CSCE 813 Internet Security Case Study II: XSS

Lecture 9a: Sessions and Cookies

Lab 5: Web Attacks using Burp Suite

FlightPATH. User Manual:

Host Website from Home Anonymously

Web Browser Application Troubleshooting Guide. Table of Contents

Unraveling the Mysteries of J2EE Web Application Communications

Impact of WannaCry and Petya Ransomware on Leica Biosystems CytoVision, Aperio, Ariol scanners and software

Practical Automated Web Application Attack Techniques Justin Clarke Gotham Digital Science Gotham Digital Science Ltd

HyperText Transfer Protocol

Threat Response Auto Pull (TRAP) - Installation Guide

Secure Access Troubleshooting Rewrite related issues (Core/Web Based Access)

How to Configure IPS Policies

Computer Networks. Wenzhong Li. Nanjing University

Using CSC SSM with Trend Micro Damage Cleanup Services

Penetration Testing with Kali Linux

Installation and Upgrade

Executive Summary. Performance Report for: The web should be fast. How does this affect me?

20486 Developing ASP.NET MVC 5 Web Applications

Transcription:

Scan of http://www.post.ir:80/ Scan details Scan information Starttime Finish time Scan time Profile Server information Responsive Server banner Server OS Server technologies 3/6/202 5:58:3 AM 3/6/202 :20:58 PM 7 hours, 22 minutes Default True Microsoft-IIS/6.0 Windows ASP,ASP.NET,PHP,Perl,Java/J2EE,ColdFusion/Jrun,Python,Ruby,mod_ssl,mod_perl,mod_python,OpenSSL,FrontPage Threat level Acunetix Threat Level 2 One or more medium-severity type vulnerabilities have been by the scanner. You should investigate each of these vulnerabilities to ensure they will not escalate to more severe problems. Alerts distribution Total alerts found High Medium Low 03 0 25 0 Informational 68 Knowledge base ASP-NET ASP-NET Version: 2.0.50727 Whois lookup Whois result for IP address 80.9..40: % This is the RIPE Database query service. % The objects are in RPSL format. % % The RIPE Database is subject to Terms and Conditions. % See http://www.ripe.net/db/support/db-terms-conditions.pdf % Note: this output has been filtered. % To receive output for a database update, use the "-B" flag. % Information related to '80.9..0-80.9..255' : 80.9..0-80.9..255: IRPOST: Iran Post Co., Mechanized Postal Services Center: Tehran, Iran: IRc: gm2679-ripec: gm2679-ripe: ASSIGNED PAby: as2880-mnt: RIPE # Filtered : gholamreza montajab: Iran Post Co., Mechanized Postal Services Center: +98 2 874 9308no: +98 2 874 448mail: montajab@tehran.irpost.irhdl: gm2679-ripe: RIPE # Filtered % Information related to '80.9.0.0/6AS2880' : 80.9.0.0/6: DCI-Route: AS2880by: AS2880-MNT: RIPE # Filtered 2

% Information related to '80.9.0.0/8AS2880' : 80.9.0.0/8: DCI-Route: AS2880by: AS2880-MNT: RIPE # Filtered % Information related to '80.9.0.0/7AS2880' : 80.9.0.0/7: DCI-Route: AS2880by: AS2880-MNT: RIPE # Filtered % Information related to '80.9.0.0/9As2880' : 80.9.0.0/9: DCI-Route: As2880by: AS2880-MNT: RIPE # Filtered DNS server running A DNS server is running on UDP port 53. NTP server running A NTP (Network Time Protocol) server is running on UDP port 23. Information gathered from this service: version="4", processor="unknown", system="unix", leap=0, stratum=2,=-24, rootdelay=99.885, rootdispersion=25.202, peer=63753,=0796867, 968670796867=0xD2FFF3C3.7947A43, =0, clock=0xd2fff64f.5fe7da3d, state=4, offset=0.487,=3.593, jitter=0.08, noise=.764, stabili Alerts summary Application error message Affects /desktopmodules/news/newsview.aspx /desktopmodules/pictures/pictureview.aspx /homepage.aspx /webresource.axd Error message on page Affects /ajax/douranportal.ui.webcontrols.headersearch,douranportal.ui.ashx /webresource.axd ASP.NET debugging enabled Affects / Possible sensitive directories Affects /_douranportal/backup /_douranportal/test /admin /desktopmodules/backup /logs /radcontrols/editor /radcontrols/tabstrip/scripts /radcontrols/upload Session Cookie without Secure flag set Affects / Variations 3 5 4 Variations Variations Variations Variations 3

Broken links Affects /_douranportal/album/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/flash/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/flashgallery/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/images/bazresi/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/images/citna/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/images/citna/new/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/images/citna/service_pic/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/images/english/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/images/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/logos/en-us/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/logos/fa-ir/homepage.aspx (ff20028de7af3393068ba869229674) /_douranportal/logos/homepage.aspx (ff20028de7af3393068ba869229674) /a /design/desktoplayouts/homepage.aspx (ff20028de7af3393068ba869229674) /design/desktoplayouts/newskingray4/homepage.aspx (ff20028de7af3393068ba869229674) /design/homepage.aspx (ff20028de7af3393068ba869229674) /design/themes/homepage.aspx (ff20028de7af3393068ba869229674) /design/themes/newskingray4new/homepage.aspx (ff20028de7af3393068ba869229674) /design/themes/newskingray4new/rtl/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/articles/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/articles/stylesheets/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/articles/stylesheets/images/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/mostpopularnews/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/mostpopularnews/stylesheets/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/mostpopularnews/stylesheets/images/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/mostpopularnews/stylesheets/images/viewitems/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/mostpopularnews/stylesheets/images/window/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/news/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/news/stylesheets/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/news/stylesheets/images/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/news/stylesheets/images/viewitems/homepage.aspx (ff20028de7af3393068ba869229674) /desktopmodules/pictures/homepage.aspx (ff20028de7af3393068ba869229674) /handlers/homepage.aspx (ff20028de7af3393068ba869229674) /images/flags/homepage.aspx (ff20028de7af3393068ba869229674) /images/homepage.aspx (ff20028de7af3393068ba869229674) /images/tree/homepage.aspx (ff20028de7af3393068ba869229674) /images/tree/rtllines/homepage.aspx (ff20028de7af3393068ba869229674) /intro_files/homepage.aspx (ff20028de7af3393068ba869229674) /javascripts/globaldatepicker/homepage.aspx (ff20028de7af3393068ba869229674) /javascripts/homepage.aspx (ff20028de7af3393068ba869229674) /javascripts/jquery/homepage.aspx (ff20028de7af3393068ba869229674) /javascripts/visual%20lightbox/css/homepage.aspx (ff20028de7af3393068ba869229674) /javascripts/visual%20lightbox/homepage.aspx (ff20028de7af3393068ba869229674) /javascripts/visual%20lightbox/images/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/ajax/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/ajax/skins/default/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/ajax/skins/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/combobox/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/combobox/skins/classic/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/combobox/skins/homepage.aspx (ff20028de7af3393068ba869229674) Variations 4

/radcontrols/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/tabstrip/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/tabstrip/skins/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/tabstrip/skins/telerik/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/tabstrip/skins/telerik/img/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/treeview/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/treeview/skins/homepage.aspx (ff20028de7af3393068ba869229674) /radcontrols/treeview/skins/rtl/homepage.aspx (ff20028de7af3393068ba869229674) /styles/homepage.aspx (ff20028de7af3393068ba869229674) /styles/jqthemes/homepage.aspx (ff20028de7af3393068ba869229674) /webresource.axd Content type is not specified Affects /handlers/sitestats.ashx Password type input with autocomplete enabled Affects /homepage.aspx (0a69ba3b474b5f0aa6f6d002f6bf65ce) /homepage.aspx (72e8a07b78a0a4a22bef4b0aded03) /homepage.aspx (77325a942328aa7f3cadbcd304fd6f) /homepage.aspx (bc03b3778bfff07cdd5bf6fa4e8) Variations Variations 5

Alert details Application error message Severity Type Reported by module Medium Validation Scripting (Error_Message.script) Description This page contains an error/warning message that may disclose sensitive information.the message can also contain the location of the file that produced the unhandled exception. This may be a false positive if the error message is found in documentation pages. Impact The error messages may disclose sensitive information. This information can be used to launch further attacks. Recommendation Review the source code for this script. Affected items /desktopmodules/news/newsview.aspx URL encoded GET input mid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/news/newsview.aspx?itemid=0034&lang=en-us&mid=&site=postportal&tabid=& wversion=staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 56 Date: Tue, 06 Mar 202 07:6:55 GMT 6

/desktopmodules/news/newsview.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/news/newsview.aspx?itemid=0032&lang=en-us&mid=2626&site=postportal&tab ID=&wVersion=Staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 555 Date: Tue, 06 Mar 202 07:20:34 GMT /desktopmodules/news/newsview.aspx URL encoded GET input tabid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/news/newsview.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 586 Date: Tue, 06 Mar 202 09:42:09 GMT 7

/desktopmodules/pictures/pictureview.aspx URL encoded GET input ItemID was set to e309 Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=e309&lang=en-us&mid=6930&site=postpor tal&tabid=3542&wversion=staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 564 Date: Tue, 06 Mar 202 06:2:30 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input ItemID was set to e309 Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=e309&lang=en-us&mid=6930&site=postpor tal&tabid=&wversion=staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 564 Date: Tue, 06 Mar 202 06:2:03 GMT 8

/desktopmodules/pictures/pictureview.aspx URL encoded GET input ItemID was set to e309 Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=e309&lang=en-us&mid=6930&site=postpor tal&tabid=&wversion=staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 564 Date: Tue, 06 Mar 202 06:2:6 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input mid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=3&lang=en-us&mid=&site=postportal&tab ID=9925&wversion=Staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error 9

Content-Length: 568 Date: Tue, 06 Mar 202 06:9:29 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input mid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=3&lang=en-us&mid=&site=postportal&tab ID=3408&wversion=Staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 568 Date: Tue, 06 Mar 202 06:9:20 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input mid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=8&lang=en-us&mid=&site=postportal&tab ID=&wversion=Staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 0

HTTP/. 500 Internal Server Error Content-Length: 568 Date: Tue, 06 Mar 202 06:9:05 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input mid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=9&lang=en-us&mid=&site=postportal&tab ID=&wversion=Staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 568 Date: Tue, 06 Mar 202 06:9:0 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input mid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=3&lang=en-us&mid=&site=postportal&tab ID=3542&wversion=Staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80

HTTP/. 500 Internal Server Error Content-Length: 568 Date: Tue, 06 Mar 202 06:9:4 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input tabid was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 593 Date: Tue, 06 Mar 202 09:27:28 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=8&lang=en-us&mid=6930&site=postporta l&tabid=&wversion=staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 2

HTTP/. 500 Internal Server Error Content-Length: 562 Date: Tue, 06 Mar 202 06:26:03 GMT /desktopmodules/pictures/pictureview.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /desktopmodules/pictures/pictureview.aspx?itemid=9&lang=en-us&mid=6930&site=postporta l&tabid=&wversion=staging HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 562 Date: Tue, 06 Mar 202 06:26:06 GMT /homepage.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> POST /homepage.aspx?lang=en-us&site=postportal&tabid= HTTP/. Content-Length: 85 Content-Type: application/x-www-form-urlencoded portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bb 3

CF55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949 FABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 (line truncated)...sw%2fros4obflakdjhtwdwpjhkpyjuwjc0vjyprofrggyrvl3ltpaufedmdkyqz0h%2but4bhecwsbiruxj zey8ntnafrnyqivpvrn4wf3ndnllh%2fiwl32wxizygdvkoyloipnut%2fkewemamzr%2bjg6odcafehoj4aptbg N3wCKGE%2fjFy5bPbIyL6DJBejS7mfYZw8J9I%3d& VIEWSTATEENCRYPTED=NY&ctl0%24Banner%24ctl0_ Banner_HeaderSearch_SearchButton=Search&ctl0%24Banner%24ctl0_Banner_HeaderSearch_Searc htextbox=&ctl0%24banner%24ctl0_banner_ln ComboLanguage=fa-IR&ctl0%24ctl06%24catHidd HTTP/. 500 Internal Server Error Content-Length: 6653 Date: Tue, 06 Mar 202 05:09:54 GMT /homepage.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> POST /homepage.aspx?lang=en-us&site=postportal&tabid= HTTP/. Content-Length: 83 Content-Type: application/x-www-form-urlencoded portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 (line truncated)...rb2sypumijdkm2fnxvhciamsbc7x0lgp74cllhp9omh2wdorju2tslzlkqlm2kh897usrclk4bwubdlovyzpp X8ll6DBf6dHtyIXO9CPZvN%2ftD9KaBbKTq92sVjnVlAbo%2f2an7sha3I96VFNrekQ4vOJwsdqVouk0mrME6% 2fdzwTAF7wnHcAipmvmY6CmiWXO76IRM4mh5c%3d& VIEWSTATEENCRYPTED=NY&ctl0%24Banner%24ctl0_ Banner_HeaderSearch_SearchButton=Search&ctl0%24Banner%24ctl0_Banner_HeaderSearch_Searc htextbox=&ctl0%24banner%24ctl0_banner_ln ComboLanguage=en-US&ctl0%24ctl06%24catHidde n=&ctl0%24ctl06%24deletecathidden=&ctl0%24ctl06%24imgarchive= HTTP/. 500 Internal Server Error Content-Length: 6653 Date: Tue, 06 Mar 202 05:09:49 GMT 4

/homepage.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> POST /homepage.aspx?lang=en-us&site=postportal&tabid= HTTP/. Content-Length: 848 Content-Type: application/x-www-form-urlencoded portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 (line truncated)...wgsw%2fros4obflakdjhtwdwpjhkpyjuwjc0vjyprofrggyrvl3ltpaufedmdkyqz0h%2but4bhecwsbiru xjzey8ntnafrnyqivpvrn4wf3ndnllh%2fiwl32wxizygdvkoyloipnut%2fkewemamzr%2bjg6odcafehoj4apt BgN3wCKGE%2fjFy5bPbIyL6DJBejS7mfYZw8J9I%3d& VIEWSTATEENCRYPTED=&ctl0%24Banner%24ctl0_ Banner_HeaderSearch_SearchButton=Search&ctl0%24Banner%24ctl0_Banner_HeaderSearch_Searc htextbox=&ctl0%24banner%24ctl0_banner_ln ComboLanguage=en-US&ctl0%24ctl06%24catHidde n=&ctl0%24ctl06%24deletecathidden=&ctl0%24ctl06%24imgarchive= HTTP/. 500 Internal Server Error Content-Length: 6653 Date: Tue, 06 Mar 202 05:0:8 GMT /homepage.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> POST /homepage.aspx?lang=en-us&site=postportal&tabid= HTTP/. Content-Length: 842 Content-Type: application/x-www-form-urlencoded portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 5

(line truncated)...erb2sypumijdkm2fnxvhciamsbc7x0lgp74cllhp9omh2wdorju2tslzlkqlm2kh897usrclk4bwubdlovyz ppx8ll6dbf6dhtyixo9cpzvn%2ftd9kabbktq92svjnvlabo%2f2an7sha3i96vfnrekq4vojwsdqvouk0mrme 6%2fdzwTAF7wnHcAipmvmY6CmiWXO76IRM4mh5c%3d& VIEWSTATEENCRYPTED=&ctl0%24Banner%24ctl0_ Banner_HeaderSearch_SearchButton=Search&ctl0%24Banner%24ctl0_Banner_HeaderSearch_Searc htextbox=&ctl0%24banner%24ctl0_banner_ln ComboLanguage=en-US&ctl0%24ctl06%24catHidd HTTP/. 500 Internal Server Error Content-Length: 6653 Date: Tue, 06 Mar 202 05:0: GMT /homepage.aspx URL encoded GET input TabID was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /homepage.aspx?lang=en-us&site=postportal&tabid= HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 500 Internal Server Error Content-Length: 6653 Date: Tue, 06 Mar 202 03:55:4 GMT /webresource.axd URL encoded GET input d was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /webresource.axd?d=&t=63465232999843750 HTTP/. 6

portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 404 Not Found Date: Tue, 06 Mar 202 08:59:4 GMT Vary: Accept-Encoding Content-Length: 238 /webresource.axd URL encoded GET input d was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /webresource.axd?d=&t=634465869798426936 HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 404 Not Found Date: Tue, 06 Mar 202 08:59:58 GMT Vary: Accept-Encoding Content-Length: 238 /webresource.axd URL encoded GET input d was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /webresource.axd?d=&t=63465232999843750 HTTP/. 7

portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 404 Not Found Date: Tue, 06 Mar 202 08:58:49 GMT Vary: Accept-Encoding Content-Length: 238 /webresource.axd URL encoded GET input d was set to Error message found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /webresource.axd?d=&t=634465869867795 HTTP/. portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 404 Not Found Date: Tue, 06 Mar 202 08:59:40 GMT Vary: Accept-Encoding Content-Length: 238 Error message on page Severity Type Reported by module Medium Validation Scripting (Text_Search.script) Description This page contains an error/warning message that may disclose sensitive information.the message can also contain the location of the file that produced the unhandled exception. 8

This may be a false positive if the error message is found in documentation pages. Impact The error messages may disclose sensitive information. This information can be used to launch further attacks. Recommendation Review the source code for this script. Affected items /ajax/douranportal.ui.webcontrols.headersearch,douranportal.ui.ashx Pattern found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /ajax/douranportal.ui.webcontrols.headersearch,douranportal.ui.ashx HTTP/. Referer: http://www.post.ir/homepage.aspx HTTP/. 500 Internal Server Error Content-Length: 366 Date: Tue, 06 Mar 202 02:29:5 GMT /webresource.axd Pattern found: <span><h>server Error in '/' Application.<hr width=00% size= color=silver></h> GET /webresource.axd HTTP/. Referer: http://www.post.ir/homepage.aspx 9

HTTP/. 404 Not Found Content-Length: 238 Date: Tue, 06 Mar 202 02:29:4 GMT ASP.NET debugging enabled Severity Type Reported by module Low Validation Scripting (ASP-NET_Debugging_Enabled.script) Description ASP.NET debugging is enabled on this application. It is recommended to disable debug mode before deploying a production application. By default, debugging is disabled, and although debugging is frequently enabled to troubleshoot a problem, it is also frequently not disabled again after the problem is resolved. Impact It may be possible to disclose sensitive information about the web sever the ASP.NET application. Recommendation Check References for details on how to fix this problem. Affected items / DEBUG /acunetix_invalid_filename.aspx HTTP/. Command: stop-debug portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 200 OK Content-Length: 2 Date: Tue, 06 Mar 202 03:8:58 GMT Possible sensitive directories 20

Severity Low Type Reported by module Validation Scripting (Possible_Sensitive_Directories.script) Description A possible sensitive directory has been found. This directory is not directly linked from the website.this check looks for common sensitive resources like backup directories, database dumps, administration pages, temporary directories. Each one of these directories could help an attacker to learn more about his target. Impact This directory may expose sensitive information that could help a malicious user to prepare more advanced attacks. Recommendation Restrict access to this directory or remove it from the website. Affected items /_douranportal/backup GET /_douranportal/backup HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 65 Date: Tue, 06 Mar 202 03:47:49 GMT Location: http://www.post.ir/%5fdouranportal/backup/ Content-Type: text/html /_douranportal/test GET /_douranportal/test HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949 2

FABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 63 Date: Tue, 06 Mar 202 03:47:27 GMT Location: http://www.post.ir/%5fdouranportal/test/ Content-Type: text/html /admin GET /admin HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 48 Date: Tue, 06 Mar 202 03:9:45 GMT Location: http://www.post.ir/admin/ Content-Type: text/html /desktopmodules/backup GET /desktopmodules/backup HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 22

HTTP/. 30 Moved Permanently Content-Length: 64 Date: Tue, 06 Mar 202 03:39:7 GMT Location: http://www.post.ir/desktopmodules/backup/ Content-Type: text/html /logs GET /logs HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 47 Date: Tue, 06 Mar 202 03:9:37 GMT Location: http://www.post.ir/logs/ Content-Type: text/html /radcontrols/editor GET /radcontrols/editor HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 6 23

Date: Tue, 06 Mar 202 05:42:49 GMT Location: http://www.post.ir/radcontrols/editor/ Content-Type: text/html /radcontrols/tabstrip/scripts GET /radcontrols/tabstrip/scripts HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 7 Date: Tue, 06 Mar 202 05:43:39 GMT Location: http://www.post.ir/radcontrols/tabstrip/scripts/ Content-Type: text/html /radcontrols/upload GET /radcontrols/upload HTTP/. Accept: acunetix/wvs Range: bytes=0-99999 portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= :80 HTTP/. 30 Moved Permanently Content-Length: 6 Date: Tue, 06 Mar 202 05:40:25 GMT Location: http://www.post.ir/radcontrols/upload/ Content-Type: text/html 24

Session Cookie without Secure flag set Severity Type Reported by module Low Informational Crawler Description This session cookie doesn't have the Secure flag set. When a cookie is set with the Secure flag, it instructs the browser that the cookie can only be accessed over secure SSL channels. This is an important security protection for session cookies. Impact None Recommendation If possible, you should set the Secure flag for this cookie. Affected items / Cookie name: "ASP.NET_SessionId" Cookie domain: "www.post.ir" GET / HTTP/. HTTP/. 200 OK Set- HttpOnly; Path=/ Content-Length: 2647 Date: Tue, 06 Mar 202 02:29:03 GMT Content-Location: http://www.post.ir/default.htm Content-Type: text/html ETag: "e04a9a7933cc:946" Last-Modified: Sat, 25 Jun 20 07:29:44 GMT Accept-Ranges: bytes Broken links Severity Type Reported by module Informational Informational Crawler Description A broken link refers to any link that should take you to a document, image or webpage, that actually results in an error. This page was linked from the website but it is inaccessible. 25

Impact Problems navigating the site. Recommendation Remove the links to this file or make it accessible. Affected items /_douranportal/album/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/album/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/album/default.aspx HTTP/. 404 Not Found Content-Length: 3563 Date: Tue, 06 Mar 202 02:29:49 GMT /_douranportal/flash/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/flash/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/flash/default.aspx HTTP/. 404 Not Found Content-Length: 3563 Date: Tue, 06 Mar 202 02:29:49 GMT 26

/_douranportal/flashgallery/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/flashgallery/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/flashgallery/default.aspx HTTP/. 404 Not Found Content-Length: 3577 Date: Tue, 06 Mar 202 02:29:49 GMT /_douranportal/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/default.aspx HTTP/. 404 Not Found Content-Length: 355 Date: Tue, 06 Mar 202 02:29:48 GMT 27

/_douranportal/images/bazresi/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/images/bazresi/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/images/bazresi/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 358 Date: Tue, 06 Mar 202 02:30:34 GMT /_douranportal/images/citna/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/images/citna/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/images/citna/default.aspx HTTP/. 404 Not Found Content-Length: 3577 Date: Tue, 06 Mar 202 02:29:50 GMT /_douranportal/images/citna/new/homepage.aspx (ff20028de7af3393068ba869229674) 28

GET /_douranportal/images/citna/new/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/images/citna/new/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3585 Date: Tue, 06 Mar 202 02:30:34 GMT /_douranportal/images/citna/service_pic/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/images/citna/service_pic/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/images/citna/service_pic/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 360 Date: Tue, 06 Mar 202 02:30:2 GMT /_douranportal/images/english/homepage.aspx (ff20028de7af3393068ba869229674) 29

GET /_douranportal/images/english/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/images/english/default.aspx HTTP/. 404 Not Found Content-Length: 358 Date: Tue, 06 Mar 202 02:29:49 GMT /_douranportal/images/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/images/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/images/default.aspx HTTP/. 404 Not Found Content-Length: 3565 Date: Tue, 06 Mar 202 02:29:49 GMT /_douranportal/logos/en-us/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/logos/en-us/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. 30

Referer: http://www.post.ir/_douranportal/logos/en-us/default.aspx HTTP/. 404 Not Found Content-Length: 3575 Date: Tue, 06 Mar 202 02:29:48 GMT /_douranportal/logos/fa-ir/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/logos/fa-ir/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/logos/fa-ir/default.aspx Esperantus_Language_PostPortal=fa-IR; PortalAlias=Managing.post; portalroles= HTTP/. 404 Not Found Content-Length: 3575 Date: Tue, 06 Mar 202 02:30:7 GMT /_douranportal/logos/homepage.aspx (ff20028de7af3393068ba869229674) GET /_douranportal/logos/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/_douranportal/logos/default.aspx 3

HTTP/. 404 Not Found Content-Length: 3563 Date: Tue, 06 Mar 202 02:29:48 GMT /a GET /a HTTP/. Referer: http://www.post.ir/homepage.aspx portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D HTTP/. 404 Not Found Content-Length: 635 Date: Tue, 06 Mar 202 03:5:32 GMT Content-Type: text/html /design/desktoplayouts/homepage.aspx (ff20028de7af3393068ba869229674) GET /design/desktoplayouts/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/design/desktoplayouts/default.aspx HTTP/. 404 Not Found 32

Content-Length: 3567 Date: Tue, 06 Mar 202 02:29:50 GMT /design/desktoplayouts/newskingray4/homepage.aspx (ff20028de7af3393068ba869229674) GET /design/desktoplayouts/newskingray4/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/design/desktoplayouts/newskingray4/default.aspx HTTP/. 404 Not Found Content-Length: 3593 Date: Tue, 06 Mar 202 02:29:50 GMT /design/homepage.aspx (ff20028de7af3393068ba869229674) GET /design/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/design/default.aspx HTTP/. 404 Not Found Content-Length: 3537 Date: Tue, 06 Mar 202 02:29:42 GMT 33

/design/themes/homepage.aspx (ff20028de7af3393068ba869229674) GET /design/themes/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/design/themes/default.aspx HTTP/. 404 Not Found Content-Length: 355 Date: Tue, 06 Mar 202 02:29:45 GMT /design/themes/newskingray4new/homepage.aspx (ff20028de7af3393068ba869229674) GET /design/themes/newskingray4new/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/design/themes/newskingray4new/default.aspx HTTP/. 404 Not Found Content-Length: 3583 Date: Tue, 06 Mar 202 02:29:47 GMT 34

/design/themes/newskingray4new/rtl/homepage.aspx (ff20028de7af3393068ba869229674) GET /design/themes/newskingray4new/rtl/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/design/themes/newskingray4new/rtl/default.aspx HTTP/. 404 Not Found Content-Length: 359 Date: Tue, 06 Mar 202 02:30:09 GMT /desktopmodules/articles/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/articles/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/articles/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 357 Date: Tue, 06 Mar 202 02:30:28 GMT /desktopmodules/articles/stylesheets/homepage.aspx (ff20028de7af3393068ba869229674) 35

GET /desktopmodules/articles/stylesheets/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/articles/stylesheets/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3595 Date: Tue, 06 Mar 202 02:30:28 GMT /desktopmodules/articles/stylesheets/images/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/articles/stylesheets/images/homepage.aspx?lang=fa-ir&site=postportal&tab id= HTTP/. Referer: http://www.post.ir/desktopmodules/articles/stylesheets/images/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3609 Date: Tue, 06 Mar 202 02:30:34 GMT /desktopmodules/homepage.aspx (ff20028de7af3393068ba869229674) 36

GET /desktopmodules/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/default.aspx HTTP/. 404 Not Found Content-Length: 3553 Date: Tue, 06 Mar 202 02:29:47 GMT /desktopmodules/mostpopularnews/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/mostpopularnews/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/mostpopularnews/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3585 Date: Tue, 06 Mar 202 02:30:25 GMT /desktopmodules/mostpopularnews/stylesheets/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/mostpopularnews/stylesheets/homepage.aspx?lang=fa-ir&site=postportal&tab id= HTTP/. 37

Referer: http://www.post.ir/desktopmodules/mostpopularnews/stylesheets/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3609 Date: Tue, 06 Mar 202 02:30:25 GMT /desktopmodules/mostpopularnews/stylesheets/images/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/mostpopularnews/stylesheets/images/homepage.aspx?lang=fa-ir&site=postpor tal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/mostpopularnews/stylesheets/images/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3623 Date: Tue, 06 Mar 202 02:30:26 GMT /desktopmodules/mostpopularnews/stylesheets/images/viewitems/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/mostpopularnews/stylesheets/images/viewitems/homepage.aspx?lang=fa-ir&si te=postportal&tabid= HTTP/. 38

Referer: http://www.post.ir/desktopmodules/mostpopularnews/stylesheets/images/viewitems/default.a spx portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= HTTP/. 404 Not Found Content-Length: 3643 Date: Tue, 06 Mar 202 03:6:08 GMT /desktopmodules/mostpopularnews/stylesheets/images/window/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/mostpopularnews/stylesheets/images/window/homepage.aspx?lang=fa-ir&site= PostPortal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/mostpopularnews/stylesheets/images/window/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3637 Date: Tue, 06 Mar 202 02:30:34 GMT /desktopmodules/news/homepage.aspx (ff20028de7af3393068ba869229674) 39

GET /desktopmodules/news/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/news/default.aspx HTTP/. 404 Not Found Content-Length: 3563 Date: Tue, 06 Mar 202 02:29:47 GMT /desktopmodules/news/stylesheets/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/news/stylesheets/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/news/stylesheets/default.aspx HTTP/. 404 Not Found Content-Length: 3587 Date: Tue, 06 Mar 202 02:29:47 GMT /desktopmodules/news/stylesheets/images/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/news/stylesheets/images/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. 40

Referer: http://www.post.ir/desktopmodules/news/stylesheets/images/default.aspx HTTP/. 404 Not Found Content-Length: 360 Date: Tue, 06 Mar 202 02:29:49 GMT /desktopmodules/news/stylesheets/images/viewitems/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/news/stylesheets/images/viewitems/homepage.aspx?lang=fa-ir&site=postport al&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/news/stylesheets/images/viewitems/default.aspx HTTP/. 404 Not Found Content-Length: 362 Date: Tue, 06 Mar 202 02:29:53 GMT /desktopmodules/pictures/homepage.aspx (ff20028de7af3393068ba869229674) GET /desktopmodules/pictures/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/desktopmodules/pictures/default.aspx 4

HTTP/. 404 Not Found Content-Length: 357 Date: Tue, 06 Mar 202 02:29:49 GMT /handlers/homepage.aspx (ff20028de7af3393068ba869229674) GET /handlers/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/handlers/default.aspx portalroles=ccf5cb973de6b8430279daa2aac93aa6463d4902489937acb803586599d6c9f89d84f079bbc F55E2C3D84B2FAB48FEED5367F9A77CD37AD2B680F7868329266320F4CDC9A9BE4BC3C6F022EF4949F ABC9DF3A7AC7FD24E3D25CF6DC7406DAE4D; stat_0_0_0_065= HTTP/. 404 Not Found Content-Length: 354 Date: Tue, 06 Mar 202 03:5:46 GMT /images/flags/homepage.aspx (ff20028de7af3393068ba869229674) GET /images/flags/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/images/flags/default.aspx 42

HTTP/. 404 Not Found Content-Length: 3549 Date: Tue, 06 Mar 202 02:29:48 GMT /images/homepage.aspx (ff20028de7af3393068ba869229674) GET /images/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/images/default.aspx HTTP/. 404 Not Found Content-Length: 3537 Date: Tue, 06 Mar 202 02:29:48 GMT /images/tree/homepage.aspx (ff20028de7af3393068ba869229674) GET /images/tree/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/images/tree/default.aspx HTTP/. 404 Not Found 43

Content-Length: 3547 Date: Tue, 06 Mar 202 02:30:03 GMT /images/tree/rtllines/homepage.aspx (ff20028de7af3393068ba869229674) GET /images/tree/rtllines/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/images/tree/rtllines/default.aspx HTTP/. 404 Not Found Content-Length: 3565 Date: Tue, 06 Mar 202 02:30:04 GMT /intro_files/homepage.aspx (ff20028de7af3393068ba869229674) GET /intro_files/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/intro_files/default.aspx HTTP/. 404 Not Found Content-Length: 3547 Date: Tue, 06 Mar 202 02:29:0 GMT 44

/javascripts/globaldatepicker/homepage.aspx (ff20028de7af3393068ba869229674) GET /javascripts/globaldatepicker/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/javascripts/globaldatepicker/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 358 Date: Tue, 06 Mar 202 02:30:34 GMT /javascripts/homepage.aspx (ff20028de7af3393068ba869229674) GET /javascripts/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/javascripts/default.aspx HTTP/. 404 Not Found Content-Length: 3547 Date: Tue, 06 Mar 202 02:29:50 GMT 45

/javascripts/jquery/homepage.aspx (ff20028de7af3393068ba869229674) GET /javascripts/jquery/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/javascripts/jquery/default.aspx HTTP/. 404 Not Found Content-Length: 356 Date: Tue, 06 Mar 202 02:29:50 GMT /javascripts/visual%20lightbox/css/homepage.aspx (ff20028de7af3393068ba869229674) GET /javascripts/visual%20lightbox/css/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/javascripts/visual%20lightbox/css/default.aspx Esperantus_Language_PostPortal=fa-IR; PortalAlias=Managing.post; portalroles= HTTP/. 404 Not Found Content-Length: 3587 Date: Tue, 06 Mar 202 02:30:8 GMT /javascripts/visual%20lightbox/homepage.aspx (ff20028de7af3393068ba869229674) 46

GET /javascripts/visual%20lightbox/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/javascripts/visual%20lightbox/default.aspx Esperantus_Language_PostPortal=fa-IR; PortalAlias=Managing.post; portalroles= HTTP/. 404 Not Found Content-Length: 3579 Date: Tue, 06 Mar 202 02:30:7 GMT /javascripts/visual%20lightbox/images/homepage.aspx (ff20028de7af3393068ba869229674) GET /javascripts/visual%20lightbox/images/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/javascripts/visual%20lightbox/images/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3593 Date: Tue, 06 Mar 202 02:30:27 GMT /radcontrols/ajax/homepage.aspx (ff20028de7af3393068ba869229674) 47

GET /radcontrols/ajax/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/ajax/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3557 Date: Tue, 06 Mar 202 02:30:26 GMT /radcontrols/ajax/skins/default/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/ajax/skins/default/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/ajax/skins/default/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3585 Date: Tue, 06 Mar 202 02:30:27 GMT /radcontrols/ajax/skins/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/ajax/skins/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. 48

Referer: http://www.post.ir/radcontrols/ajax/skins/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3569 Date: Tue, 06 Mar 202 02:30:27 GMT /radcontrols/combobox/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/combobox/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/combobox/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3565 Date: Tue, 06 Mar 202 02:30:33 GMT /radcontrols/combobox/skins/classic/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/combobox/skins/classic/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/combobox/skins/classic/default.aspx 49

portalroles= HTTP/. 404 Not Found Content-Length: 3593 Date: Tue, 06 Mar 202 02:30:34 GMT /radcontrols/combobox/skins/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/combobox/skins/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/combobox/skins/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3577 Date: Tue, 06 Mar 202 02:30:33 GMT /radcontrols/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/default.aspx portalroles= 50

HTTP/. 404 Not Found Content-Length: 3547 Date: Tue, 06 Mar 202 02:30:26 GMT /radcontrols/tabstrip/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/tabstrip/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/tabstrip/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3565 Date: Tue, 06 Mar 202 02:30:25 GMT /radcontrols/tabstrip/skins/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/tabstrip/skins/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/tabstrip/skins/default.aspx portalroles= 5

HTTP/. 404 Not Found Content-Length: 3577 Date: Tue, 06 Mar 202 02:30:26 GMT /radcontrols/tabstrip/skins/telerik/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/tabstrip/skins/telerik/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/tabstrip/skins/telerik/default.aspx portalroles= HTTP/. 404 Not Found Content-Length: 3593 Date: Tue, 06 Mar 202 02:30:26 GMT /radcontrols/tabstrip/skins/telerik/img/homepage.aspx (ff20028de7af3393068ba869229674) GET /radcontrols/tabstrip/skins/telerik/img/homepage.aspx?lang=fa-ir&site=postportal&tabid= HTTP/. Referer: http://www.post.ir/radcontrols/tabstrip/skins/telerik/img/default.aspx portalroles= HTTP/. 404 Not Found 52