Nmap scan report for logging-us-east-2.prd.api.a.intuit.com (3.13.232.212) Host is up (0.060s latency). Other addresses for logging-us-east-2.prd.api.a.intuit.com (not scanned): 18.224.111.163 3.130.110.145 3.133.73.179 18.190.131.14 13.58.187.133 rDNS record for 3.13.232.212: ec2-3-13-232-212.us-east-2.compute.amazonaws.com Not shown: 998 filtered ports PORT STATE SERVICE VERSION 80/tcp open http awselb/2.0 | fingerprint-strings: | FourOhFourRequest: | HTTP/1.1 301 Moved Permanently | Server: awselb/2.0 | Date: Mon, 20 Nov 2023 05:59:26 GMT | Content-Type: text/html | Content-Length: 134 | Connection: close | Location: https://apigw-use2-prd-dx11-978323985.us-east-2.elb.amazonaws.com:443/nice%20ports%2C/Tri%6Eity.txt%2ebak | | 301 Moved Permanently | |

301 Moved Permanently

| | | GetRequest, HTTPOptions: | HTTP/1.1 301 Moved Permanently | Server: awselb/2.0 | Date: Mon, 20 Nov 2023 05:59:25 GMT | Content-Type: text/html | Content-Length: 134 | Connection: close | Location: https://apigw-use2-prd-dx11-978323985.us-east-2.elb.amazonaws.com:443/ | | 301 Moved Permanently | |

301 Moved Permanently

| | | RTSPRequest: | | 400 Bad Request | |

400 Bad Request

| | | X11Probe: | HTTP/1.1 400 Bad Request | Server: awselb/2.0 | Date: Mon, 20 Nov 2023 05:59:26 GMT | Content-Type: text/html | Content-Length: 122 | Connection: close | | 400 Bad Request | |

400 Bad Request

| |_ |_http-server-header: awselb/2.0 |_http-title: Did not follow redirect to https://logging-us-east-2.prd.api.a.intuit.com:443/ 443/tcp open ssl/http-proxy (bad gateway) | fingerprint-strings: | FourOhFourRequest: | HTTP/1.1 502 Bad Gateway | Date: Mon, 20 Nov 2023 05:59:32 GMT | Content-Type: text/plain | Content-Length: 0 | Connection: close | x-envoy-upstream-service-time: 0 | strict-transport-security: max-age=31536000 | intuit_tid: 1-655af5c4-36a36be072f4b7eb7d6dadcf | x-request-id: 1-655af5c4-36a36be072f4b7eb7d6dadcf | server: istio-envoy | x-envoy-decorator-operation: intuit-gateway-envoy.services-gateway-apigwext-use2-prd-dx11:7000/* | GetRequest: | HTTP/1.1 502 Bad Gateway | Date: Mon, 20 Nov 2023 05:59:31 GMT | Content-Type: text/plain | Content-Length: 0 | Connection: close | x-envoy-upstream-service-time: 0 | strict-transport-security: max-age=31536000 | intuit_tid: 1-655af5c3-6cb2d56e50d6dc7a42cff57f | x-request-id: 1-655af5c3-6cb2d56e50d6dc7a42cff57f | server: istio-envoy | x-envoy-decorator-operation: intuit-gateway-envoy.services-gateway-apigwext-use2-prd-dx11:7000/* | HTTPOptions: | HTTP/1.1 502 Bad Gateway | Date: Mon, 20 Nov 2023 05:59:32 GMT | Content-Type: text/plain | Content-Length: 0 | Connection: close | x-envoy-upstream-service-time: 0 | strict-transport-security: max-age=31536000 | intuit_tid: 1-655af5c4-174f5ce02fc928e524071c03 | x-request-id: 1-655af5c4-174f5ce02fc928e524071c03 | server: istio-envoy | x-envoy-decorator-operation: intuit-gateway-envoy.services-gateway-apigwext-use2-prd-dx11:7000/* | Help: | HTTP/1.1 400 Bad Request | Server: awselb/2.0 | Date: Mon, 20 Nov 2023 05:59:38 GMT | Content-Type: text/html | Content-Length: 122 | Connection: close | | 400 Bad Request | |

400 Bad Request

| | | RTSPRequest: | | 400 Bad Request | |

400 Bad Request

| |_ | http-server-header: | awselb/2.0 |_ istio-envoy |_http-title: Site doesn't have a title (text/plain). | ssl-cert: Subject: commonName=*.intuit.com/organizationName=INTUIT INC./stateOrProvinceName=California/countryName=US | Subject Alternative Name: DNS:*.intuit.com, DNS:*.sbfinance.intuit.com, DNS:*.iep.intuit.com, DNS:*.prd.platform.intuit.com, DNS:*.accountants.intuit.com, DNS:*.api.intuit.ae, DNS:*.api.intuit.com.au, DNS:*.prd.api.a.intuit.com, DNS:*.api.intuit.mx, DNS:*.sbfinance.stage.intuit.com, DNS:*.intuit.ca, DNS:*.workforce.intuit.com, DNS:*.appfabric.intuit.com, DNS:*.experimentation.intuit.com, DNS:*.platform.intuit.ca, DNS:*.stgl.intuit.com, DNS:*.finance.intuit.com, DNS:*.app.intuit.com, DNS:*.api.intuit.com, DNS:*.prf.api.a.intuit.com, DNS:*.qbo.intuit.com, DNS:*.api.intuit.fr, DNS:*.qa.api.a.intuit.com, DNS:*.banking.intuit.com, DNS:*.turbotaxonline.intuit.com, DNS:*.api.intuit.sg, DNS:*.turbotax.intuit.com, DNS:*.quickbooks.intuit.com, DNS:*.e2e.api.a.intuit.com, DNS:*.api.intuit.ca, DNS:*.api.intuit.net, DNS:*.accountant.intuit.com, DNS:*.tax.intuit.com, DNS:*.a.intuit.com, DNS:*.hosting.intuit.com, DNS:*.aws.api.intuit.com, DNS:*.api.intuit.co.za, DNS:*.ffffprdstg.intuit.com, DNS:*.api.intuit.ph, DNS:*.api.quickbooks.com.br, DNS:*.statefillableforms.com, DNS:*.business.intuit.com, DNS:*.ffffprd.intuit.com, DNS:*.api.intuit.hk, DNS:*.platform.intuit.com, DNS:*.qb.intuit.com, DNS:*.api.quickbooks.co.uk, DNS:*.mint.com, DNS:*.quickbooks.com | Not valid before: 2023-04-22T00:00:00 |_Not valid after: 2024-05-22T23:59:59 |_ssl-date: TLS randomness does not represent time | tls-alpn: | h2 |_ http/1.1 | tls-nextprotoneg: | h2 |_ http/1.1 2 services unrecognized despite returning data. If you know the service/version, please submit the following fingerprints at https://nmap.org/cgi-bin/submit.cgi?new-service : ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== SF-Port80-TCP:V=7.70%I=7%D=11/19%Time=655AF5BC%P=x86_64-redhat-linux-gnu%r SF:(GetRequest,174,"HTTP/1\.1\x20301\x20Moved\x20Permanently\r\nServer:\x2 SF:0awselb/2\.0\r\nDate:\x20Mon,\x2020\x20Nov\x202023\x2005:59:25\x20GMT\r SF:\nContent-Type:\x20text/html\r\nContent-Length:\x20134\r\nConnection:\x SF:20close\r\nLocation:\x20https://apigw-use2-prd-dx11-978323985\.us-east- SF:2\.elb\.amazonaws\.com:443/\r\n\r\n\r\n301\x20Moved\ SF:x20Permanently\r\n\r\n

301\x20Moved\x20 SF:Permanently

\r\n\r\n\r\n")%r(HTTPOptions,174 SF:,"HTTP/1\.1\x20301\x20Moved\x20Permanently\r\nServer:\x20awselb/2\.0\r\ SF:nDate:\x20Mon,\x2020\x20Nov\x202023\x2005:59:25\x20GMT\r\nContent-Type: SF:\x20text/html\r\nContent-Length:\x20134\r\nConnection:\x20close\r\nLoca SF:tion:\x20https://apigw-use2-prd-dx11-978323985\.us-east-2\.elb\.amazona SF:ws\.com:443/\r\n\r\n\r\n301\x20Moved\x20Permanently< SF:/title></head>\r\n<body>\r\n<center><h1>301\x20Moved\x20Permanently</h1 SF:></center>\r\n</body>\r\n</html>\r\n")%r(RTSPRequest,7A,"<html>\r\n<hea SF:d><title>400\x20Bad\x20Request\r\n\r\n

SF:400\x20Bad\x20Request

\r\n\r\n\r\n")%r(X11Pr SF:obe,110,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nServer:\x20awselb/2\.0\r SF:\nDate:\x20Mon,\x2020\x20Nov\x202023\x2005:59:26\x20GMT\r\nContent-Type SF::\x20text/html\r\nContent-Length:\x20122\r\nConnection:\x20close\r\n\r\ SF:n\r\n400\x20Bad\x20Request\r\n\ SF:r\n

400\x20Bad\x20Request

\r\n\r\n\r\n")%r(FourOhFourRequest,197,"HTTP/1\.1\x20301\x20Moved\x20Permanent SF:ly\r\nServer:\x20awselb/2\.0\r\nDate:\x20Mon,\x2020\x20Nov\x202023\x200 SF:5:59:26\x20GMT\r\nContent-Type:\x20text/html\r\nContent-Length:\x20134\ SF:r\nConnection:\x20close\r\nLocation:\x20https://apigw-use2-prd-dx11-978 SF:323985\.us-east-2\.elb\.amazonaws\.com:443/nice%20ports%2C/Tri%6Eity\.t SF:xt%2ebak\r\n\r\n\r\n301\x20Moved\x20Permanently</tit SF:le></head>\r\n<body>\r\n<center><h1>301\x20Moved\x20Permanently</h1></c SF:enter>\r\n</body>\r\n</html>\r\n"); ==============NEXT SERVICE FINGERPRINT (SUBMIT INDIVIDUALLY)============== SF-Port443-TCP:V=7.70%T=SSL%I=7%D=11/19%Time=655AF5C3%P=x86_64-redhat-linu SF:x-gnu%r(GetRequest,1AB,"HTTP/1\.1\x20502\x20Bad\x20Gateway\r\nDate:\x20 SF:Mon,\x2020\x20Nov\x202023\x2005:59:31\x20GMT\r\nContent-Type:\x20text/p SF:lain\r\nContent-Length:\x200\r\nConnection:\x20close\r\nx-envoy-upstrea SF:m-service-time:\x200\r\nstrict-transport-security:\x20max-age=31536000\ SF:r\nintuit_tid:\x201-655af5c3-6cb2d56e50d6dc7a42cff57f\r\nx-request-id:\ SF:x201-655af5c3-6cb2d56e50d6dc7a42cff57f\r\nserver:\x20istio-envoy\r\nx-e SF:nvoy-decorator-operation:\x20intuit-gateway-envoy\.services-gateway-api SF:gwext-use2-prd-dx11:7000/\*\r\n\r\n")%r(HTTPOptions,1AB,"HTTP/1\.1\x205 SF:02\x20Bad\x20Gateway\r\nDate:\x20Mon,\x2020\x20Nov\x202023\x2005:59:32\ SF:x20GMT\r\nContent-Type:\x20text/plain\r\nContent-Length:\x200\r\nConnec SF:tion:\x20close\r\nx-envoy-upstream-service-time:\x200\r\nstrict-transpo SF:rt-security:\x20max-age=31536000\r\nintuit_tid:\x201-655af5c4-174f5ce02 SF:fc928e524071c03\r\nx-request-id:\x201-655af5c4-174f5ce02fc928e524071c03 SF:\r\nserver:\x20istio-envoy\r\nx-envoy-decorator-operation:\x20intuit-ga SF:teway-envoy\.services-gateway-apigwext-use2-prd-dx11:7000/\*\r\n\r\n")% SF:r(FourOhFourRequest,1AB,"HTTP/1\.1\x20502\x20Bad\x20Gateway\r\nDate:\x2 SF:0Mon,\x2020\x20Nov\x202023\x2005:59:32\x20GMT\r\nContent-Type:\x20text/ SF:plain\r\nContent-Length:\x200\r\nConnection:\x20close\r\nx-envoy-upstre SF:am-service-time:\x200\r\nstrict-transport-security:\x20max-age=31536000 SF:\r\nintuit_tid:\x201-655af5c4-36a36be072f4b7eb7d6dadcf\r\nx-request-id: SF:\x201-655af5c4-36a36be072f4b7eb7d6dadcf\r\nserver:\x20istio-envoy\r\nx- SF:envoy-decorator-operation:\x20intuit-gateway-envoy\.services-gateway-ap SF:igwext-use2-prd-dx11:7000/\*\r\n\r\n")%r(RTSPRequest,7A,"<html>\r\n<hea SF:d><title>400\x20Bad\x20Request\r\n\r\n

SF:400\x20Bad\x20Request

\r\n\r\n\r\n")%r(Help, SF:110,"HTTP/1\.1\x20400\x20Bad\x20Request\r\nServer:\x20awselb/2\.0\r\nDa SF:te:\x20Mon,\x2020\x20Nov\x202023\x2005:59:38\x20GMT\r\nContent-Type:\x2 SF:0text/html\r\nContent-Length:\x20122\r\nConnection:\x20close\r\n\r\n\r\n400\x20Bad\x20Request\r\n\r\n< SF:center>

400\x20Bad\x20Request

\r\n\r\n\r\ SF:n"); Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|PBX Running (JUST GUESSING): Linux 2.6.X|3.X|4.X (90%), Vodavi embedded (87%) OS CPE: cpe:/o:linux:linux_kernel:2.6.32 cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/h:vodavi:xts-ip Aggressive OS guesses: Linux 2.6.32 (90%), Linux 3.2 - 4.9 (90%), Linux 2.6.32 - 3.10 (89%), Linux 2.6.32 - 3.13 (89%), Vodavi XTS-IP PBX (87%), Linux 3.10 - 3.13 (86%) No exact OS matches for host (test conditions non-ideal). Network Distance: 19 hops TRACEROUTE (using port 80/tcp) HOP RTT ADDRESS 1 28.35 ms 208.76.251.177 2 0.79 ms gw.mcom-colocationamerica.com (208.64.231.81) 3 0.57 ms multacom.com (96.45.162.9) 4 15.19 ms ae-8.a03.lsanca07.us.bb.gin.ntt.net (129.250.205.121) 5 ... 6 32.84 ms ae-3.r22.dllstx14.us.bb.gin.ntt.net (129.250.7.68) 7 29.60 ms ae-17.r20.dllstx14.us.bb.gin.ntt.net (129.250.2.68) 8 25.97 ms ae-0.a01.dllstx14.us.bb.gin.ntt.net (129.250.4.22) 9 37.21 ms ae-3.amazon.dllstx14.us.bb.gin.ntt.net (129.250.201.22) 10 34.73 ms 54.239.105.117 11 38.84 ms 15.230.48.20 12 ... 13 57.48 ms 108.166.252.11 14 ... 15 58.30 ms 108.166.244.1 16 ... 18 19 57.84 ms ec2-3-13-232-212.us-east-2.compute.amazonaws.com (3.13.232.212) OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 58.28 seconds