212.69.32.71
Aggregated from public BGP, CT logs, our scan layer, honeypots and global probes.
Run a live full scan of 212.69.32.71
On-demand: ports, banners, TLS, tech-stack, subdomains and origin/IP-leak detection. Results are shared publicly for everyone to link to.
Autonomous System
Geolocation
Reverse DNS
Network
Open Ports
| Port | Proto | Service | Server | Last seen |
|---|---|---|---|---|
| 80 | tcp | http | Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips mod_fcgid/2.3.9 PHP/5.4.16 mod_perl/2.0.11 Perl/v5.16.3 | 2026-06-15 14:28:18.000 |
| 443 | tcp | https | Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips mod_fcgid/2.3.9 PHP/5.4.16 mod_perl/2.0.11 Perl/v5.16.3 | 2026-07-21 03:30:21.000 |
TLS Certificates
Known Vulnerabilities
Published CVEs matched to the software versions fingerprinted on this host. Matching is by product and version against the NVD dictionary — presence of a CVE does not confirm the host is exploitable (patches or backports may apply).
| CVE | Software | CVSS | Severity | Summary |
|---|---|---|---|---|
| CVE-2018-1312 | Apache 2.4.6 | 9.8 | N/A | In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated us... |
| CVE-2014-9912 | PHP 5.4.16 | 9.8 | N/A | The get_icu_disp_value_src_php function in ext/intl/locale/locale_methods.c in PHP before 5.3.29, 5.4.x before 5.4.30, and 5.5.x before 5.5.14 does not properly... |
| CVE-2016-1238 | Perl 5.16.3 | 7.8 | N/A | (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6)... |
| CVE-2016-0736 | Apache 2.4.6 | 7.5 | N/A | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB m... |
| CVE-2016-2161 | Apache 2.4.6 | 7.5 | N/A | In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for... |
| CVE-2017-15710 | Apache 2.4.6 | 7.5 | N/A | In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language head... |
| CVE-2017-9798 | Apache 2.4.6 | 7.5 | N/A | Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has... |
| CVE-2013-6420 | PHP 5.4.16 | 7.5 | HIGH | The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefor... |
| CVE-2014-3669 | PHP 5.4.16 | 7.5 | HIGH | Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remot... |
| CVE-2014-9427 | PHP 5.4.16 | 7.5 | HIGH | sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not p... |
| CVE-2015-0231 | PHP 5.4.16 | 7.5 | HIGH | Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before... |
| CVE-2016-7478 | PHP 5.4.16 | 7.5 | N/A | Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a craf... |
| CVE-2011-4718 | PHP 5.4.16 | 6.8 | MEDIUM | Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote attackers to hijack web sessions by specifying a session ID. |
| CVE-2014-3597 | PHP 5.4.16 | 6.8 | MEDIUM | Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a den... |
| CVE-2014-3670 | PHP 5.4.16 | 6.8 | MEDIUM | The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point ar... |
| CVE-2015-0232 | PHP 5.4.16 | 6.8 | MEDIUM | The exif_process_unicode function in ext/exif/exif.c in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitr... |
| CVE-2014-3478 | PHP 5.4.16 | 6.5 | N/A | Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, all... |
| CVE-2014-5120 | PHP 5.4.16 | 6.4 | MEDIUM | gd_ctx.c in the GD component in PHP 5.4.x before 5.4.32 and 5.5.x before 5.5.16 does not ensure that pathnames lack %00 sequences, which might allow remote atta... |
| CVE-2016-4975 | Apache 2.4.6 | 6.1 | N/A | Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32... |
| CVE-2013-5704 | Apache 2.4.6 | 5.0 | MEDIUM | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer po... |
| CVE-2014-3523 | Apache 2.4.6 | 5.0 | MEDIUM | Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default... |
| CVE-2014-3581 | Apache 2.4.6 | 5.0 | MEDIUM | The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to ca... |
| CVE-2015-3184 | Apache 2.4.6 | 5.0 | MEDIUM | mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, whic... |
| CVE-2012-1171 | PHP 5.4.16 | 5.0 | MEDIUM | The libxml RSHUTDOWN function in PHP 5.x allows remote attackers to bypass the open_basedir protection mechanism and read arbitrary files via vectors involving... |
| CVE-2014-3668 | PHP 5.4.16 | 5.0 | MEDIUM | Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x befor... |
| CVE-2013-4352 | Apache 2.4.6 | 4.3 | MEDIUM | The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled,... |
| CVE-2014-0117 | Apache 2.4.6 | 4.3 | MEDIUM | The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child... |
| CVE-2014-8109 | Apache 2.4.6 | 4.3 | MEDIUM | mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authoriza... |
| CVE-2015-3185 | Apache 2.4.6 | 4.3 | MEDIUM | The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associate... |
| CVE-2013-4248 | PHP 5.4.16 | 4.3 | MEDIUM | The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a do... |
| CVE-2014-3587 | PHP 5.4.16 | 4.3 | MEDIUM | Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5... |
Tech Stack
Wappalyzer fingerprinting pending
HTTP-body analysis identifies web frameworks, CMS platforms, analytics, JS libraries and server-side languages from this host.
Origin / IP-Leak
When a hostname is served behind a CDN (e.g. Cloudflare), the origin server can sometimes be identified by matching its TLS cert against the protected hostname. Findings shown here are heuristic candidates, not guarantees.
No origin-leak candidates for this IP
When this IP serves a TLS cert for a domain that fronts behind a CDN, that domain surfaces here as an origin-leak candidate with a confidence score.
Hosted Domains
5 domains resolve (A-record) to this IP.
| Domain |
|---|
| 70s.fast-rewind.com |
| fast-rewind.com |
| movie-locations.fast-rewind.com |
| www.artemislighting.com |
| www.fast-rewind.com |
Multi-Vantage Check
Reachability accrued passively from real user-triggered checks across our 65+ probe nodes. Run a live check to add fresh data.
No accumulated reachability data yet
Reachability accrues from real user-triggered checks. Trigger a Ping or HTTP check from our 65+ probe nodes to contribute the first data point.
Threat Intelligence
No threat-intel matches
This IP doesn't appear in any of the feeds we mirror (Tor exits, FireHOL Level 1-3, Spamhaus DROP/EDROP, URLhaus, OpenPhish). Absence here doesn't prove the IP is clean — it just means none of our public-feed sources flag it.
Co-Hosted Domains
Domains this host references in its HTML AND whose DNS A/AAAA record resolves back to this IP — i.e. actually hosted here.
External References
Domains the body links to whose DNS does NOT resolve to this IP — usually CDN assets, embeds, or third-party services. Boilerplate (Google Fonts, jsDelivr, w3.org…) is already filtered.
History
The full change-log (ASN moves, cert rotations, port-state diffs) accumulates as our archives grow.