# Shodan Notebook <img src="assets/images/shodan_logo.png" alt="Shodan Logo" width="140" height="40">



## General Search Filters

- **ip:** Filter results by specific IP address.
- **asn:** Filter results by specific ASN (Autonomous System Number) ID.
- **hostname:** Filter results by specific hostname.
- **port:** Filter results by specific port number of service.
- **net:** Filter results from specified CIDR block.
- **isp:** Filter results by devices assigned a particular address (space) from a specified ISP.
- **city:** Filter results by specific city.
- **country:** Filter results by specific two-digit country code.
- **os:** Filter results by particular operating system.
- **product:** Filter results by particular software.
- **version:** Filter results by specified version of software.

## Premium API Search Filters

- **vuln:** Filter results by particular vulnerability ID (commonly CVE).
- **tag:** Filter results by tags on device.

## HTTP Filters

- **http.component:** Filter results by a particular web technology.
- **http.status:** Filter results by specific status code.
- **http.html:** Filter results by strings found in HTML of files served.
- **http.title:** Filter results by string found in title of web pages served.

## Common CLI Commands

- **count:** Returns the number of results for a search.
- **domain:** View all available information for a domain.
- **download:** Download search results and save them in a compressed JSON file.
- **honeyscore:** Check whether the IP is a honeypot or not.
- **host:** View all available information for an IP address.
- **parse:** Extract information out of compressed JSON files.
- **scan:** Scan an IP/netblock using Shodan.
- **search:** Search the Shodan database.

## Use Case Examples

- **host 8.8.8.8:** Display information about Google’s public DNS.
- **asn:15169 product:mysql:** Show information about devices within Google’s ASN that run MySQL.
- **shodan search "microsoft iis 6.0" --fields ip_str,port,org,hostnames:** Detect IIS servers running on version 6.0.
- **shodan honeyscore [TARGET]:** Detect if given target is a honeypot or not.

For more information, visit [Shodan Documentation](https://developer.shodan.io/api).


## Imports and default variables
Run this section to get started.

In [None]:
from shodan import Shodan
import os
from dotenv import load_dotenv
from pprint import pprint
import json

load_dotenv()
api = Shodan(os.getenv("SHODAN_API_KEY"))

## Search
- Define search
- Run search

In [None]:
# Define search query
search_query = 'ip:213.67.1.156'

In [None]:
# Perform the search
try:
    # Search Shodan
    results = api.search(query=search_query)

    # Show the results
    print('Results found: {}'.format(results['total']))
    for result in results['matches']:
        pprint(result)
        print('\n')


except Exception as e:
    print('Error: {}'.format(e))

### Scan using Shodan
- Define scan targets
    + Single IP scan
    scan_target_list = ['192.168.1.1']
    + Multiple IPs scan
    scan_target_list = ['192.168.1.1', '192.168.1.2']
    + Single IP with specific ports scan
    scan_target_list = {'192.168.1.1': [(80, 'http'), (443, 'https')]}
    + Multiple IPs with specific ports scan
    scan_target_list = {
        '192.168.1.1': [(80, 'http'), (443, 'https')],
        '192.168.1.2': [(22, 'ssh'), (3389, 'rdp')]
    }
- Run Scan
- Fetch Scan results

In [None]:
# Define scan targets
scan_target_list =  ['213.67.1.156']

In [None]:
# Run scan
try:
    scan_id = api.scan(scan_target_list)
except Exception as e:
    print('Failed to scan target: {}'.format(e))

In [None]:
# Check if scan is done
try:
    # Get the scan results
    scan_results = api.scan_status(scan_id['id'])
    pprint(scan_results['status'])
except Exception as e:
    print('Error: {}'.format(e))

### Download scan results

In [None]:
!shodan init $SHODAN_API_KEY
!shodan download data/{scan_results['id']}-shodan-scan-results.json.gz scan:{scan_results['id']}
!gunzip data/{scan_results['id']}-shodan-scan-results.json.gz
!rm data/{scan_results['id']}-shodan-scan-results.json.gz

In [None]:
# Load and print scan results (scan_results['id']}-shodan-scan-results.json)
with open(f'data/{scan_results["id"]}-shodan-scan-results.json', 'r') as f:
    scan_results = json.load(f)
    pprint(scan_results)

## Handle data output

### File Output

In [None]:
# Define the file path
file_path = 'results.json'

# Write the results to the JSON file
with open(file_path, 'w') as f:
    json.dump(results['matches'], f)


In [4]:
results = {'matches': [{'_shodan': {'crawler': '85a5be66a1913a867d4f8cd62bd10fb79f410a2a',
                          'id': '16d8705f-c563-48d4-9e1a-ffe79d8773db',
                          'module': 'ssh',
                          'options': {'scan': 'kQITQYgNnmr95UsT'},
                          'ptr': True,
                          'region': 'na'},
              'asn': 'AS3301',
              'cpe': ['cpe:/a:openbsd:openssh'],
              'cpe23': ['cpe:2.3:a:openbsd:openssh'],
              'data': 'SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.7\n'
                      'Key type: ecdsa-sha2-nistp256\n'
                      'Key: '
                      'AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBB5tixTDl0dBWJ+FZM1fnuZd\n'
                      'Ejyi2MHH75S26xn7JbfG2IV4hGrKugvKoiwXekVGC77oc6RFvQ3Hf6HT6M+tmWA=\n'
                      'Fingerprint: '
                      '0c:7e:18:dd:c8:fe:b9:9e:7f:4e:dc:5d:61:cb:01:a8\n'
                      '\n'
                      'Kex Algorithms:\n'
                      '\tcurve25519-sha256\n'
                      '\tcurve25519-sha256@libssh.org\n'
                      '\tecdh-sha2-nistp256\n'
                      '\tecdh-sha2-nistp384\n'
                      '\tecdh-sha2-nistp521\n'
                      '\tsntrup761x25519-sha512@openssh.com\n'
                      '\tdiffie-hellman-group-exchange-sha256\n'
                      '\tdiffie-hellman-group16-sha512\n'
                      '\tdiffie-hellman-group18-sha512\n'
                      '\tdiffie-hellman-group14-sha256\n'
                      '\tkex-strict-s-v00@openssh.com\n'
                      '\n'
                      'Server Host Key Algorithms:\n'
                      '\trsa-sha2-512\n'
                      '\trsa-sha2-256\n'
                      '\tecdsa-sha2-nistp256\n'
                      '\tssh-ed25519\n'
                      '\n'
                      'Encryption Algorithms:\n'
                      '\tchacha20-poly1305@openssh.com\n'
                      '\taes128-ctr\n'
                      '\taes192-ctr\n'
                      '\taes256-ctr\n'
                      '\taes128-gcm@openssh.com\n'
                      '\taes256-gcm@openssh.com\n'
                      '\n'
                      'MAC Algorithms:\n'
                      '\tumac-64-etm@openssh.com\n'
                      '\tumac-128-etm@openssh.com\n'
                      '\thmac-sha2-256-etm@openssh.com\n'
                      '\thmac-sha2-512-etm@openssh.com\n'
                      '\thmac-sha1-etm@openssh.com\n'
                      '\tumac-64@openssh.com\n'
                      '\tumac-128@openssh.com\n'
                      '\thmac-sha2-256\n'
                      '\thmac-sha2-512\n'
                      '\thmac-sha1\n'
                      '\n'
                      'Compression Algorithms:\n'
                      '\tnone\n'
                      '\tzlib@openssh.com\n',
              'domains': ['telia.com'],
              'hash': 667895948,
              'hostnames': ['213-67-1-156-no600.tbcn.telia.com'],
              'info': 'protocol 2.0',
              'ip': 3577938332,
              'ip_str': '213.67.1.156',
              'isp': 'Telia Company AB',
              'location': {'area_code': None,
                           'city': 'Nykvarn',
                           'country_code': 'SE',
                           'country_name': 'Sweden',
                           'latitude': 59.17718,
                           'longitude': 17.4323,
                           'region_code': 'AB'},
              'org': 'Telia Network services',
              'os': None,
              'port': 22,
              'product': 'OpenSSH',
              'ssh': {'cipher': 'aes128-ctr',
                      'fingerprint': '0c:7e:18:dd:c8:fe:b9:9e:7f:4e:dc:5d:61:cb:01:a8',
                      'hassh': '41ff3ecd1458b0bf86e1b4891636213e',
                      'kex': {'compression_algorithms': ['none',
                                                         'zlib@openssh.com'],
                              'encryption_algorithms': ['chacha20-poly1305@openssh.com',
                                                        'aes128-ctr',
                                                        'aes192-ctr',
                                                        'aes256-ctr',
                                                        'aes128-gcm@openssh.com',
                                                        'aes256-gcm@openssh.com'],
                              'kex_algorithms': ['curve25519-sha256',
                                                 'curve25519-sha256@libssh.org',
                                                 'ecdh-sha2-nistp256',
                                                 'ecdh-sha2-nistp384',
                                                 'ecdh-sha2-nistp521',
                                                 'sntrup761x25519-sha512@openssh.com',
                                                 'diffie-hellman-group-exchange-sha256',
                                                 'diffie-hellman-group16-sha512',
                                                 'diffie-hellman-group18-sha512',
                                                 'diffie-hellman-group14-sha256',
                                                 'kex-strict-s-v00@openssh.com'],
                              'kex_follows': False,
                              'languages': [''],
                              'mac_algorithms': ['umac-64-etm@openssh.com',
                                                 'umac-128-etm@openssh.com',
                                                 'hmac-sha2-256-etm@openssh.com',
                                                 'hmac-sha2-512-etm@openssh.com',
                                                 'hmac-sha1-etm@openssh.com',
                                                 'umac-64@openssh.com',
                                                 'umac-128@openssh.com',
                                                 'hmac-sha2-256',
                                                 'hmac-sha2-512',
                                                 'hmac-sha1'],
                              'server_host_key_algorithms': ['rsa-sha2-512',
                                                             'rsa-sha2-256',
                                                             'ecdsa-sha2-nistp256',
                                                             'ssh-ed25519'],
                              'unused': 0},
                      'key': 'AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBB5tixTDl0dBWJ+FZM1fnuZd\n'
                             'Ejyi2MHH75S26xn7JbfG2IV4hGrKugvKoiwXekVGC77oc6RFvQ3Hf6HT6M+tmWA=\n',
                      'mac': 'hmac-sha2-256',
                      'type': 'ecdsa-sha2-nistp256'},
              'timestamp': '2024-05-09T15:23:35.237266',
              'transport': 'tcp',
              'version': '8.9p1 Ubuntu-3ubuntu0.7'},
             {'_shodan': {'crawler': '85a5be66a1913a867d4f8cd62bd10fb79f410a2a',
                          'id': 'cf8575a6-d988-49b1-a88c-df8345d54898',
                          'module': 'mikrotik-routeros',
                          'options': {'scan': 'kQITQYgNnmr95UsT'},
                          'ptr': True,
                          'region': 'na'},
              'asn': 'AS3301',
              'data': 'MikroTik Winbox:\n'
                      '  list:\n'
                      '    advtool.jg: 7.14.3\n'
                      '    dhcp.jg: 7.14.3\n'
                      '    hotspot.jg: 7.14.3\n'
                      '    icons.png: 7.14.3\n'
                      '    icons24.png: \n'
                      '    icons32.png: \n'
                      '    ipv6.jg: 7.14.3\n'
                      '    ppp.jg: 7.14.3\n'
                      '    roteros.jg: 7.14.3\n'
                      '    secure.jg: 7.14.3\n'
                      '    wave2.jg: 7.14.3\n'
                      '    wlan6.jg: 7.14.3',
              'domains': ['telia.com'],
              'hash': 261322238,
              'hostnames': ['213-67-1-156-no600.tbcn.telia.com'],
              'ip': 3577938332,
              'ip_str': '213.67.1.156',
              'isp': 'Telia Company AB',
              'location': {'area_code': None,
                           'city': 'Nykvarn',
                           'country_code': 'SE',
                           'country_name': 'Sweden',
                           'latitude': 59.17718,
                           'longitude': 17.4323,
                           'region_code': 'AB'},
              'mikrotik_winbox': {'list': {'advtool.jg': {'crc': 1069879267,
                                                          'size': 2069,
                                                          'version': '7.14.3'},
                                           'dhcp.jg': {'crc': 2877861086,
                                                       'size': 3840,
                                                       'version': '7.14.3'},
                                           'hotspot.jg': {'crc': 2763222791,
                                                          'size': 4216,
                                                          'version': '7.14.3'},
                                           'icons.png': {'crc': 626617846,
                                                         'size': 20380,
                                                         'version': '7.14.3'},
                                           'icons24.png': {'crc': 528157417,
                                                           'size': 32822},
                                           'icons32.png': {'crc': 1496435930,
                                                           'size': 45923},
                                           'ipv6.jg': {'crc': 4282491243,
                                                       'size': 7298,
                                                       'version': '7.14.3'},
                                           'ppp.jg': {'crc': 4026782222,
                                                      'size': 6099,
                                                      'version': '7.14.3'},
                                           'roteros.jg': {'crc': 2115056920,
                                                          'size': 94300,
                                                          'version': '7.14.3'},
                                           'secure.jg': {'crc': 429710380,
                                                         'size': 4284,
                                                         'version': '7.14.3'},
                                           'wave2.jg': {'crc': 1060069207,
                                                        'size': 7760,
                                                        'version': '7.14.3'},
                                           'wlan6.jg': {'crc': 702101985,
                                                        'size': 19254,
                                                        'version': '7.14.3'}}},
              'org': 'Telia Network services',
              'os': None,
              'port': 8291,
              'product': 'MikroTik Winbox',
              'timestamp': '2024-05-09T15:23:28.422998',
              'transport': 'tcp'},
             {'_shodan': {'crawler': '85a5be66a1913a867d4f8cd62bd10fb79f410a2a',
                          'id': 'e85dea96-8a52-4038-a84f-3209d990fc06',
                          'module': 'http',
                          'options': {'scan': 'kQITQYgNnmr95UsT'},
                          'ptr': True,
                          'region': 'na'},
              'asn': 'AS3301',
              'cpe': ['cpe:/a:f5:nginx:1.18.0',
                      'cpe:/o:canonical:ubuntu_linux',
                      'cpe:/o:linux:linux_kernel'],
              'cpe23': ['cpe:2.3:a:f5:nginx:1.18.0',
                        'cpe:2.3:o:canonical:ubuntu_linux',
                        'cpe:2.3:o:linux:linux_kernel'],
              'data': 'HTTP/1.1 200 OK\r\n'
                      'Server: nginx/1.18.0 (Ubuntu)\r\n'
                      'Date: Thu, 09 May 2024 15:12:08 GMT\r\n'
                      'Content-Type: text/html\r\n'
                      'Content-Length: 815\r\n'
                      'Last-Modified: Mon, 18 Mar 2024 19:48:54 GMT\r\n'
                      'Connection: keep-alive\r\n'
                      'ETag: "65f89aa6-32f"\r\n'
                      'Accept-Ranges: bytes\r\n'
                      '\r\n',
              'domains': ['telia.com'],
              'hash': 523864069,
              'hostnames': ['213-67-1-156-no600.tbcn.telia.com'],
              'http': {'components': {},
                       'headers_hash': 1245094173,
                       'host': '213.67.1.156',
                       'html': '<!DOCTYPE html>\n'
                               '<html lang="en">\n'
                               '<head>\n'
                               '    <meta charset="UTF-8">\n'
                               '    <meta name="viewport" '
                               'content="width=device-width, '
                               'initial-scale=1.0">\n'
                               '    <title>dig-sec</title>\n'
                               '    <style>\n'
                               '        body {\n'
                               '            display: flex;\n'
                               '            justify-content: center;\n'
                               '            align-items: center;\n'
                               '            height: 100vh;\n'
                               '            background-color: #333;\n'
                               '            color: white;\n'
                               '        }\n'
                               '        .navbar-header {\n'
                               '            font-size: xx-small;\n'
                               '            padding-top: 10px;\n'
                               '            padding-left: 10px;\n'
                               '            text-align: center;\n'
                               '        }\n'
                               '    </style>\n'
                               '</head>\n'
                               '<body>\n'
                               '    <div>\n'
                               '        <strong>█▀▄\u2003█\u2003█▀▀\u2003'
                               '▄▄\u2003█▀\u2003█▀▀\u2003█▀▀</strong><br>\n'
                               '        <strong>█▄▀\u2003█\u2003█▄█\u2003'
                               '░░\u2003▄█\u2003██▄\u2003█▄▄</strong>\n'
                               '    </div>\n'
                               '</body>\n'
                               '</html>\n'
                               '\n',
                       'html_hash': -1498086337,
                       'location': '/',
                       'redirects': [],
                       'robots': None,
                       'robots_hash': None,
                       'securitytxt': None,
                       'securitytxt_hash': None,
                       'server': 'nginx/1.18.0 (Ubuntu)',
                       'sitemap': None,
                       'sitemap_hash': None,
                       'status': 200,
                       'title': 'dig-sec'},
              'ip': 3577938332,
              'ip_str': '213.67.1.156',
              'isp': 'Telia Company AB',
              'location': {'area_code': None,
                           'city': 'Nykvarn',
                           'country_code': 'SE',
                           'country_name': 'Sweden',
                           'latitude': 59.17718,
                           'longitude': 17.4323,
                           'region_code': 'AB'},
              'org': 'Telia Network services',
              'os': 'Ubuntu',
              'port': 80,
              'product': 'nginx',
              'tags': ['eol-product'],
              'timestamp': '2024-05-09T15:12:08.469332',
              'transport': 'tcp',
              'version': '1.18.0',
              'vulns': {'CVE-2021-23017': {'cvss': 6.8,
                                           'cvss_v2': 6.8,
                                           'epss': 0.51967,
                                           'ranking_epss': 0.97553,
                                           'references': ['http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html',
                                                          'http://packetstormsecurity.com/files/167720/Nginx-1.20.0-Denial-Of-Service.html',
                                                          'https://lists.apache.org/thread.html/r37e6b2165f7c910d8e15fd54f4697857619ad2625f56583802004009%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/r4d4966221ca399ce948ef34884652265729d7d9ef8179c78d7f17e7f%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/r6fc5c57b38e93e36213e9a18c8a4e5dbd5ced1c7e57f08a1735975ba%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/rf232eecd47fdc44520192810560303073cefd684b321f85e311bad31%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/rf318aeeb4d7a3a312734780b47de83cefb7e6995da0b2cae5c28675c%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SFVYHC7OXTEO4SMBWXDVK6E5IMEYMEE/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNKOP2JR5L7KCIZTJRZDCUPJTUONMC5I/',
                                                          'https://security.netapp.com/advisory/ntap-20210708-0006/',
                                                          'https://support.f5.com/csp/article/K12331123%2C',
                                                          'https://www.oracle.com/security-alerts/cpuapr2022.html',
                                                          'https://www.oracle.com/security-alerts/cpujan2022.html',
                                                          'https://www.oracle.com/security-alerts/cpuoct2021.html'],
                                           'summary': 'A security issue in '
                                                      'nginx resolver was '
                                                      'identified, which might '
                                                      'allow an attacker who '
                                                      'is able to forge UDP '
                                                      'packets from the DNS '
                                                      'server to cause 1-byte '
                                                      'memory overwrite, '
                                                      'resulting in worker '
                                                      'process crash or '
                                                      'potential other impact.',
                                           'verified': False},
                        'CVE-2021-3618': {'cvss': 5.8,
                                          'cvss_v2': 5.8,
                                          'epss': 0.0011,
                                          'ranking_epss': 0.44022,
                                          'references': ['https://alpaca-attack.com/',
                                                         'https://bugzilla.redhat.com/show_bug.cgi?id=1975623',
                                                         'https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html'],
                                          'summary': 'ALPACA is an application '
                                                     'layer protocol content '
                                                     'confusion attack, '
                                                     'exploiting TLS servers '
                                                     'implementing different '
                                                     'protocols but using '
                                                     'compatible certificates, '
                                                     'such as multi-domain or '
                                                     'wildcard certificates. A '
                                                     'MiTM attacker having '
                                                     "access to victim's "
                                                     'traffic at the TCP/IP '
                                                     'layer can redirect '
                                                     'traffic from one '
                                                     'subdomain to another, '
                                                     'resulting in a valid TLS '
                                                     'session. This breaks the '
                                                     'authentication of TLS '
                                                     'and cross-protocol '
                                                     'attacks may be possible '
                                                     'where the behavior of '
                                                     'one protocol service may '
                                                     'compromise the other at '
                                                     'the application layer.',
                                          'verified': False},
                        'CVE-2023-44487': {'cvss': None,
                                           'cvss_v2': None,
                                           'epss': 0.72011,
                                           'kev': True,
                                           'ranking_epss': 0.9805,
                                           'ransomware_campaign': 'Unknown',
                                           'references': ['http://www.openwall.com/lists/oss-security/2023/10/13/4',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/13/9',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/18/4',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/18/8',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/19/6',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/20/8',
                                                          'https://access.redhat.com/security/cve/cve-2023-44487',
                                                          'https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/',
                                                          'https://aws.amazon.com/security/security-bulletins/AWS-2023-011/',
                                                          'https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/',
                                                          'https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/',
                                                          'https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/',
                                                          'https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack',
                                                          'https://blog.vespa.ai/cve-2023-44487/',
                                                          'https://bugzilla.proxmox.com/show_bug.cgi?id=4988',
                                                          'https://bugzilla.redhat.com/show_bug.cgi?id=2242803',
                                                          'https://bugzilla.suse.com/show_bug.cgi?id=1216123',
                                                          'https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9',
                                                          'https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/',
                                                          'https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack',
                                                          'https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125',
                                                          'https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715',
                                                          'https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve',
                                                          'https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764',
                                                          'https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088',
                                                          'https://github.com/Azure/AKS/issues/3947',
                                                          'https://github.com/Kong/kong/discussions/11741',
                                                          'https://github.com/advisories/GHSA-qppj-fm5r-hxr3',
                                                          'https://github.com/advisories/GHSA-vx74-f528-fxqg',
                                                          'https://github.com/advisories/GHSA-xpw8-rcwv-8f8p',
                                                          'https://github.com/akka/akka-http/issues/4323',
                                                          'https://github.com/alibaba/tengine/issues/1872',
                                                          'https://github.com/apache/apisix/issues/10320',
                                                          'https://github.com/apache/httpd-site/pull/10',
                                                          'https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113',
                                                          'https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2',
                                                          'https://github.com/apache/trafficserver/pull/10564',
                                                          'https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487',
                                                          'https://github.com/bcdannyboy/CVE-2023-44487',
                                                          'https://github.com/caddyserver/caddy/issues/5877',
                                                          'https://github.com/caddyserver/caddy/releases/tag/v2.7.5',
                                                          'https://github.com/dotnet/announcements/issues/277',
                                                          'https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73',
                                                          'https://github.com/eclipse/jetty.project/issues/10679',
                                                          'https://github.com/envoyproxy/envoy/pull/30055',
                                                          'https://github.com/etcd-io/etcd/issues/16740',
                                                          'https://github.com/facebook/proxygen/pull/466',
                                                          'https://github.com/golang/go/issues/63417',
                                                          'https://github.com/grpc/grpc-go/pull/6703',
                                                          'https://github.com/h2o/h2o/pull/3291',
                                                          'https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf',
                                                          'https://github.com/haproxy/haproxy/issues/2312',
                                                          'https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244',
                                                          'https://github.com/junkurihara/rust-rpxy/issues/97',
                                                          'https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1',
                                                          'https://github.com/kazu-yamamoto/http2/issues/93',
                                                          'https://github.com/kubernetes/kubernetes/pull/121120',
                                                          'https://github.com/line/armeria/pull/5232',
                                                          'https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632',
                                                          'https://github.com/micrictor/http2-rst-stream',
                                                          'https://github.com/microsoft/CBL-Mariner/pull/6381',
                                                          'https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61',
                                                          'https://github.com/nghttp2/nghttp2/pull/1961',
                                                          'https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0',
                                                          'https://github.com/ninenines/cowboy/issues/1615',
                                                          'https://github.com/nodejs/node/pull/50121',
                                                          'https://github.com/openresty/openresty/issues/930',
                                                          'https://github.com/opensearch-project/data-prepper/issues/3474',
                                                          'https://github.com/oqtane/oqtane.framework/discussions/3367',
                                                          'https://github.com/projectcontour/contour/pull/5826',
                                                          'https://github.com/tempesta-tech/tempesta/issues/1986',
                                                          'https://github.com/varnishcache/varnish-cache/issues/3996',
                                                          'https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo',
                                                          'https://istio.io/latest/news/security/istio-security-2023-004/',
                                                          'https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/',
                                                          'https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/',
                                                          'https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html',
                                                          'https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html',
                                                          'https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html',
                                                          'https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/',
                                                          'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487',
                                                          'https://my.f5.com/manage/s/article/K000137106',
                                                          'https://netty.io/news/2023/10/10/4-1-100-Final.html',
                                                          'https://news.ycombinator.com/item?id=37830987',
                                                          'https://news.ycombinator.com/item?id=37830998',
                                                          'https://news.ycombinator.com/item?id=37831062',
                                                          'https://news.ycombinator.com/item?id=37837043',
                                                          'https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/',
                                                          'https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected',
                                                          'https://security.gentoo.org/glsa/202311-09',
                                                          'https://security.netapp.com/advisory/ntap-20231016-0001/',
                                                          'https://security.netapp.com/advisory/ntap-20240426-0007/',
                                                          'https://security.paloaltonetworks.com/CVE-2023-44487',
                                                          'https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14',
                                                          'https://ubuntu.com/security/CVE-2023-44487',
                                                          'https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/',
                                                          'https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487',
                                                          'https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event',
                                                          'https://www.debian.org/security/2023/dsa-5521',
                                                          'https://www.debian.org/security/2023/dsa-5522',
                                                          'https://www.debian.org/security/2023/dsa-5540',
                                                          'https://www.debian.org/security/2023/dsa-5549',
                                                          'https://www.debian.org/security/2023/dsa-5558',
                                                          'https://www.debian.org/security/2023/dsa-5570',
                                                          'https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487',
                                                          'https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/',
                                                          'https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/',
                                                          'https://www.openwall.com/lists/oss-security/2023/10/10/6',
                                                          'https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack',
                                                          'https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/'],
                                           'summary': 'The HTTP/2 protocol '
                                                      'allows a denial of '
                                                      'service (server '
                                                      'resource consumption) '
                                                      'because request '
                                                      'cancellation can reset '
                                                      'many streams quickly, '
                                                      'as exploited in the '
                                                      'wild in August through '
                                                      'October 2023.',
                                           'verified': False}}},
             {'_shodan': {'crawler': '85a5be66a1913a867d4f8cd62bd10fb79f410a2a',
                          'id': 'e72eabf0-2c6c-4dd4-a7d1-2b7d8cb21b37',
                          'module': 'https',
                          'options': {'scan': 'kQITQYgNnmr95UsT'},
                          'ptr': True,
                          'region': 'na'},
              'asn': 'AS3301',
              'cpe': ['cpe:/a:f5:nginx:1.18.0',
                      'cpe:/o:canonical:ubuntu_linux',
                      'cpe:/o:linux:linux_kernel'],
              'cpe23': ['cpe:2.3:a:f5:nginx:1.18.0',
                        'cpe:2.3:o:canonical:ubuntu_linux',
                        'cpe:2.3:o:linux:linux_kernel'],
              'data': 'HTTP/1.1 200 OK\r\n'
                      'Server: nginx/1.18.0 (Ubuntu)\r\n'
                      'Date: Thu, 09 May 2024 15:03:19 GMT\r\n'
                      'Content-Type: text/html\r\n'
                      'Content-Length: 815\r\n'
                      'Last-Modified: Mon, 18 Mar 2024 19:48:54 GMT\r\n'
                      'Connection: keep-alive\r\n'
                      'ETag: "65f89aa6-32f"\r\n'
                      'Accept-Ranges: bytes\r\n'
                      '\r\n',
              'domains': ['dig-sec.com', 'telia.com'],
              'hash': -127351118,
              'hostnames': ['www.dig-sec.com',
                            '213-67-1-156-no600.tbcn.telia.com'],
              'http': {'components': {},
                       'headers_hash': 1245094173,
                       'host': '213.67.1.156',
                       'html': '<!DOCTYPE html>\n'
                               '<html lang="en">\n'
                               '<head>\n'
                               '    <meta charset="UTF-8">\n'
                               '    <meta name="viewport" '
                               'content="width=device-width, '
                               'initial-scale=1.0">\n'
                               '    <title>dig-sec</title>\n'
                               '    <style>\n'
                               '        body {\n'
                               '            display: flex;\n'
                               '            justify-content: center;\n'
                               '            align-items: center;\n'
                               '            height: 100vh;\n'
                               '            background-color: #333;\n'
                               '            color: white;\n'
                               '        }\n'
                               '        .navbar-header {\n'
                               '            font-size: xx-small;\n'
                               '            padding-top: 10px;\n'
                               '            padding-left: 10px;\n'
                               '            text-align: center;\n'
                               '        }\n'
                               '    </style>\n'
                               '</head>\n'
                               '<body>\n'
                               '    <div>\n'
                               '        <strong>█▀▄\u2003█\u2003█▀▀\u2003'
                               '▄▄\u2003█▀\u2003█▀▀\u2003█▀▀</strong><br>\n'
                               '        <strong>█▄▀\u2003█\u2003█▄█\u2003'
                               '░░\u2003▄█\u2003██▄\u2003█▄▄</strong>\n'
                               '    </div>\n'
                               '</body>\n'
                               '</html>\n'
                               '\n',
                       'html_hash': -1498086337,
                       'location': '/',
                       'redirects': [],
                       'robots': None,
                       'robots_hash': None,
                       'securitytxt': None,
                       'securitytxt_hash': None,
                       'server': 'nginx/1.18.0 (Ubuntu)',
                       'sitemap': None,
                       'sitemap_hash': None,
                       'status': 200,
                       'title': 'dig-sec'},
              'ip': 3577938332,
              'ip_str': '213.67.1.156',
              'isp': 'Telia Company AB',
              'location': {'area_code': None,
                           'city': 'Nykvarn',
                           'country_code': 'SE',
                           'country_name': 'Sweden',
                           'latitude': 59.17718,
                           'longitude': 17.4323,
                           'region_code': 'AB'},
              'org': 'Telia Network services',
              'os': 'Ubuntu',
              'port': 443,
              'product': 'nginx',
              'ssl': {'acceptable_cas': [],
                      'alpn': [],
                      'cert': {'expired': False,
                               'expires': '20240625094458Z',
                               'extensions': [{'critical': True,
                                               'data': '\\x03\\x02\\x05\\xa0',
                                               'name': 'keyUsage'},
                                              {'data': '0\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02',
                                               'name': 'extendedKeyUsage'},
                                              {'critical': True,
                                               'data': '0\\x00',
                                               'name': 'basicConstraints'},
                                              {'data': '\\x04\\x14\\x8e\\xb1A\\x14pf\\xb7\\xe5\\xe6\\x94B\\xa9-8S\\xb8\\xd5\\xb3\\x08\\xef',
                                               'name': 'subjectKeyIdentifier'},
                                              {'data': '0\\x16\\x80\\x14\\x14.\\xb3\\x17\\xb7XV\\xcb\\xaeP\\t@\\xe6\\x1f\\xaf\\x9d\\x8b\\x14\\xc2\\xc6',
                                               'name': 'authorityKeyIdentifier'},
                                              {'data': '0G0!\\x06\\x08+\\x06\\x01\\x05\\x05\\x070\\x01\\x86\\x15http://r3.o.lencr.org0"\\x06\\x08+\\x06\\x01\\x05\\x05\\x070\\x02\\x86\\x16http://r3.i.lencr.org/',
                                               'name': 'authorityInfoAccess'},
                                              {'data': '0\\x11\\x82\\x0fwww.dig-sec.com',
                                               'name': 'subjectAltName'},
                                              {'data': '0\\n0\\x08\\x06\\x06g\\x81\\x0c\\x01\\x02\\x01',
                                               'name': 'certificatePolicies'},
                                              {'data': "\\x04\\x81\\xf4\\x00\\xf2\\x00w\\x00\\xa2\\xe2\\xbf\\xd6\\x1e\\xde//\\x07\\xa0\\xd6Nm7\\xa7\\xdceC\\xb0\\xc6\\xb5.\\xa2\\xda\\xb7\\x8a\\xf8\\x9am\\xf5\\x17\\xd8\\x00\\x00\\x01\\x8e\\x7f\\x83]\\xec\\x00\\x00\\x04\\x03\\x00H0F\\x02!\\x00\\x84\\xa8\\xeb\\x83\\x86\\t\\xfc\\xd7T\\x01(\\xb3\\x96\\x11\\xa0\\xf2\\x95d\\xad\\x078\\xc1\\xdf\\xf4A\\xac\\xb0\\x8aU\\xdbc\\xf8\\x02!\\x00\\x98\\x89e\\x03\\xfc\\xa2\\\\uNJ\\x9d\\xc3\\x14a\\x9d\\x01\\xc9A\\'k\\x06\\xf5\\x97Ze\\x83?\\xab\\x12:\\x98\\xbf\\x00w\\x00v\\xff\\x88?\\n\\xb6\\xfb\\x95Q\\xc2a\\xcc\\xf5\\x87\\xba4\\xb4\\xa4\\xcd\\xbb)\\xdchB\\n\\x9f\\xe6gLZ:t\\x00\\x00\\x01\\x8e\\x7f\\x83^\\x0f\\x00\\x00\\x04\\x03\\x00H0F\\x02!\\x00\\x98\\xbf\\xbcm)\\x07\\x05/\\xd8\\x12\\x91\\x88\\xc8\\x82\\xb4\\xd6\\xb0$B\\xc8$\\xc7\\x84XmT\\x13\\xbf\\xf4\\xa8\\xe9K\\x02!\\x00\\xecPb\\xc89\\xfdb8\\x0er7\\x87\\x92\\xe6\\x11\\x16\\xdcr\\x10\\x9c\\\\\\xeb\\x02s\\xf0\\x04\\x1cWU\\xc8\\x95\\xd2",
                                               'name': 'ct_precert_scts'}],
                               'fingerprint': {'sha1': '5134f56c33c14438e0c6f348e094e89edbf39ed3',
                                               'sha256': '38015f6973a438493da571c95e31c4a293b7ab1e79ff3891a1b8abff1c7d9e63'},
                               'issued': '20240327094459Z',
                               'issuer': {'C': 'US',
                                          'CN': 'R3',
                                          'O': "Let's Encrypt"},
                               'pubkey': {'bits': 2048, 'type': 'rsa'},
                               'serial': 278836030169971730477719834552628033739705,
                               'sig_alg': 'sha256WithRSAEncryption',
                               'subject': {'CN': 'www.dig-sec.com'},
                               'version': 2},
                      'chain': ['-----BEGIN CERTIFICATE-----\n'
                                'MIIE7TCCA9WgAwIBAgISAzNs6gIB4El5evriuCXQTdu5MA0GCSqGSIb3DQEBCwUA\n'
                                'MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD\n'
                                'EwJSMzAeFw0yNDAzMjcwOTQ0NTlaFw0yNDA2MjUwOTQ0NThaMBoxGDAWBgNVBAMT\n'
                                'D3d3dy5kaWctc2VjLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB\n'
                                'AMNtc5NxSgxAE1e6fIn+XBZyb4KHZ/CdFcrtkaUjYSZxqw3xWz7F5S/iW+ezOtT0\n'
                                '5jnjr6J5oAzqst4meai2/yZyAiWdeoZ7Z2xKYQbgfwqz32a2d7w7gt40UTnnk+ya\n'
                                '8ZNM26eyafyZHi+E0G5JB6lDvk1Jgiak2aEtDlRfDoi3UrBehCp8uErMX/TY82rw\n'
                                '4kI5O33XFGX8oWNLG79mJP39MMZqc5gFPGIKwnxFvuKVkF0fu4XYc572zVI0eNdk\n'
                                '+UJKHqMIpnssNc1msFiLYIp9WcVfRyizJMOAjoCnU9Tl07BRt7o9tPnvKlQZLO8H\n'
                                'K03pe0yu3ZQ6pfz/myPOeQcCAwEAAaOCAhMwggIPMA4GA1UdDwEB/wQEAwIFoDAd\n'
                                'BgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH/BAIwADAdBgNV\n'
                                'HQ4EFgQUjrFBFHBmt+XmlEKpLThTuNWzCO8wHwYDVR0jBBgwFoAUFC6zF7dYVsuu\n'
                                'UAlA5h+vnYsUwsYwVQYIKwYBBQUHAQEESTBHMCEGCCsGAQUFBzABhhVodHRwOi8v\n'
                                'cjMuby5sZW5jci5vcmcwIgYIKwYBBQUHMAKGFmh0dHA6Ly9yMy5pLmxlbmNyLm9y\n'
                                'Zy8wGgYDVR0RBBMwEYIPd3d3LmRpZy1zZWMuY29tMBMGA1UdIAQMMAowCAYGZ4EM\n'
                                'AQIBMIIBBgYKKwYBBAHWeQIEAgSB9wSB9ADyAHcAouK/1h7eLy8HoNZObTen3GVD\n'
                                'sMa1LqLat4r4mm31F9gAAAGOf4Nd7AAABAMASDBGAiEAhKjrg4YJ/NdUASizlhGg\n'
                                '8pVkrQc4wd/0QaywilXbY/gCIQCYiWUD/KJcdU5KncMUYZ0ByUEnawb1l1plgz+r\n'
                                'EjqYvwB3AHb/iD8KtvuVUcJhzPWHujS0pM27KdxoQgqf5mdMWjp0AAABjn+DXg8A\n'
                                'AAQDAEgwRgIhAJi/vG0pBwUv2BKRiMiCtNawJELIJMeEWG1UE7/0qOlLAiEA7FBi\n'
                                'yDn9YjgOcjeHkuYRFtxyEJxc6wJz8AQcV1XIldIwDQYJKoZIhvcNAQELBQADggEB\n'
                                'AAAQx3T/odYynZhCLx5Ioi6yA2ZroPQh32uQDA+ITGu+JADbq2XytJojESiLeBm2\n'
                                'z1ltI/WH2KVDBidZov69zRHxQXvBAV/6OCcTnhXzWWo8SoItpzzDxKoj+dB/puHe\n'
                                'ix187lIW4YCXAxb5HxiUzO24GL+rH63/nNOV+oZPNKpA0pYOUxKk+EhaxAQwUWPx\n'
                                'VEixJdCL8c5F1i5dEmixozzM990c+q/WK+IfzoujB7rRqFmukf4jjleJgI1BQi5Y\n'
                                'PuSxjCCLuRGjh5H6yoNxJYiiMJTFTb9ZWQlNxCdnJG6gXUJbTytmRkfRrPn45Gfb\n'
                                'gfLT0Ta1rwnjTDW14SqfCwM=\n'
                                '-----END CERTIFICATE-----\n',
                                '-----BEGIN CERTIFICATE-----\n'
                                'MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw\n'
                                'TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh\n'
                                'cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw\n'
                                'WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg\n'
                                'RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK\n'
                                'AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP\n'
                                'R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx\n'
                                'sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm\n'
                                'NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg\n'
                                'Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG\n'
                                '/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC\n'
                                'AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB\n'
                                'Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA\n'
                                'FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw\n'
                                'AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw\n'
                                'Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB\n'
                                'gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W\n'
                                'PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl\n'
                                'ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz\n'
                                'CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm\n'
                                'lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4\n'
                                'avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2\n'
                                'yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O\n'
                                'yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids\n'
                                'hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+\n'
                                'HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv\n'
                                'MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX\n'
                                'nLRbwHOoq7hHwg==\n'
                                '-----END CERTIFICATE-----\n'],
                      'chain_sha256': ['38015f6973a438493da571c95e31c4a293b7ab1e79ff3891a1b8abff1c7d9e63',
                                       '67add1166b020ae61b8f5fc96813c04c2aa589960796865572a3c7e737613dfd'],
                      'cipher': {'bits': 256,
                                 'name': 'TLS_AES_256_GCM_SHA384',
                                 'version': 'TLSv1.3'},
                      'dhparams': {'bits': 2048,
                                   'generator': 2,
                                   'prime': 'ffffffffffffffffadf85458a2bb4a9aafdc5620273d3cf1d8b9c583ce2d3695a9e13641146433fbcc939dce249b3ef97d2fe363630c75d8f681b202aec4617ad3df1ed5d5fd65612433f51f5f066ed0856365553ded1af3b557135e7f57c935984f0c70e0e68b77e2a689daf3efe8721df158a136ade73530acca4f483a797abc0ab182b324fb61d108a94bb2c8e3fbb96adab760d7f4681d4f42a3de394df4ae56ede76372bb190b07a7c8ee0a6d709e02fce1cdf7e2ecc03404cd28342f619172fe9ce98583ff8e4f1232eef28183c3fe3b1b4c6fad733bb5fcbc2ec22005c58ef1837d1683b2c6f34a26c1b2effa886b423861285c97ffffffffffffffff',
                                   'public_key': '9d73a61d6a5db8b2dedbf5cb233de4c10221e95749f18cdb69b8a091be96c74c395be3a98ccc2c7409f01774b5a82c5046d4dd3c24b73f0b61aca25389063253483b60a6513228cff7a1279ad762214163a9d3b555a2e1de6c16cfef4eb388030f3450a754e00f7f8fb0dd306415a52a54a4235b9f55d181d16954383a3497ef11a7c902158eef594b39f07d2fb554d73fba20427c521c7c4bc213682526f50d7287793cfe40f8f12a0bc6a31b875eac079cfbbe087d4c4fff902a7345c75f24c4b4931ee21dd5132c93bbb82e7e0c6ac84ce866709bd139fe32ce740cad206619e02fd57988b6fee1f623ffa4a7ddc390f2935adf19a37d601d058907e0695e'},
                      'handshake_states': ['before SSL initialization',
                                           'SSLv3/TLS write client hello',
                                           'SSLv3/TLS read server hello',
                                           'TLSv1.3 read encrypted extensions',
                                           'SSLv3/TLS read server certificate',
                                           'TLSv1.3 read server certificate '
                                           'verify',
                                           'SSLv3/TLS read finished',
                                           'SSLv3/TLS write change cipher spec',
                                           'SSLv3/TLS write finished',
                                           'SSL negotiation finished '
                                           'successfully'],
                      'ja3s': '574866101f64002c6421cc329e4d5458',
                      'jarm': '15d3fd16d29d29d00042d43d000000fe02290512647416dcf0a400ccbc0b6b',
                      'ocsp': {},
                      'tlsext': [{'id': 43, 'name': 'supported_versions'},
                                 {'id': 51, 'name': 'key_share'},
                                 {'id': 0, 'name': 'server_name'}],
                      'trust': {'browser': None, 'revoked': False},
                      'versions': ['-TLSv1',
                                   '-SSLv2',
                                   '-SSLv3',
                                   '-TLSv1.1',
                                   'TLSv1.2',
                                   'TLSv1.3']},
              'tags': ['eol-product'],
              'timestamp': '2024-05-09T15:03:19.993790',
              'transport': 'tcp',
              'version': '1.18.0',
              'vulns': {'CVE-2021-23017': {'cvss': 6.8,
                                           'cvss_v2': 6.8,
                                           'epss': 0.51967,
                                           'ranking_epss': 0.97553,
                                           'references': ['http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html',
                                                          'http://packetstormsecurity.com/files/167720/Nginx-1.20.0-Denial-Of-Service.html',
                                                          'https://lists.apache.org/thread.html/r37e6b2165f7c910d8e15fd54f4697857619ad2625f56583802004009%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/r4d4966221ca399ce948ef34884652265729d7d9ef8179c78d7f17e7f%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/r6fc5c57b38e93e36213e9a18c8a4e5dbd5ced1c7e57f08a1735975ba%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/rf232eecd47fdc44520192810560303073cefd684b321f85e311bad31%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/rf318aeeb4d7a3a312734780b47de83cefb7e6995da0b2cae5c28675c%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SFVYHC7OXTEO4SMBWXDVK6E5IMEYMEE/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNKOP2JR5L7KCIZTJRZDCUPJTUONMC5I/',
                                                          'https://security.netapp.com/advisory/ntap-20210708-0006/',
                                                          'https://support.f5.com/csp/article/K12331123%2C',
                                                          'https://www.oracle.com/security-alerts/cpuapr2022.html',
                                                          'https://www.oracle.com/security-alerts/cpujan2022.html',
                                                          'https://www.oracle.com/security-alerts/cpuoct2021.html'],
                                           'summary': 'A security issue in '
                                                      'nginx resolver was '
                                                      'identified, which might '
                                                      'allow an attacker who '
                                                      'is able to forge UDP '
                                                      'packets from the DNS '
                                                      'server to cause 1-byte '
                                                      'memory overwrite, '
                                                      'resulting in worker '
                                                      'process crash or '
                                                      'potential other impact.',
                                           'verified': False},
                        'CVE-2021-3618': {'cvss': 5.8,
                                          'cvss_v2': 5.8,
                                          'epss': 0.0011,
                                          'ranking_epss': 0.44022,
                                          'references': ['https://alpaca-attack.com/',
                                                         'https://bugzilla.redhat.com/show_bug.cgi?id=1975623',
                                                         'https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html'],
                                          'summary': 'ALPACA is an application '
                                                     'layer protocol content '
                                                     'confusion attack, '
                                                     'exploiting TLS servers '
                                                     'implementing different '
                                                     'protocols but using '
                                                     'compatible certificates, '
                                                     'such as multi-domain or '
                                                     'wildcard certificates. A '
                                                     'MiTM attacker having '
                                                     "access to victim's "
                                                     'traffic at the TCP/IP '
                                                     'layer can redirect '
                                                     'traffic from one '
                                                     'subdomain to another, '
                                                     'resulting in a valid TLS '
                                                     'session. This breaks the '
                                                     'authentication of TLS '
                                                     'and cross-protocol '
                                                     'attacks may be possible '
                                                     'where the behavior of '
                                                     'one protocol service may '
                                                     'compromise the other at '
                                                     'the application layer.',
                                          'verified': False},
                        'CVE-2023-44487': {'cvss': None,
                                           'cvss_v2': None,
                                           'epss': 0.72011,
                                           'kev': True,
                                           'ranking_epss': 0.9805,
                                           'ransomware_campaign': 'Unknown',
                                           'references': ['http://www.openwall.com/lists/oss-security/2023/10/13/4',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/13/9',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/18/4',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/18/8',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/19/6',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/20/8',
                                                          'https://access.redhat.com/security/cve/cve-2023-44487',
                                                          'https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/',
                                                          'https://aws.amazon.com/security/security-bulletins/AWS-2023-011/',
                                                          'https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/',
                                                          'https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/',
                                                          'https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/',
                                                          'https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack',
                                                          'https://blog.vespa.ai/cve-2023-44487/',
                                                          'https://bugzilla.proxmox.com/show_bug.cgi?id=4988',
                                                          'https://bugzilla.redhat.com/show_bug.cgi?id=2242803',
                                                          'https://bugzilla.suse.com/show_bug.cgi?id=1216123',
                                                          'https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9',
                                                          'https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/',
                                                          'https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack',
                                                          'https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125',
                                                          'https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715',
                                                          'https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve',
                                                          'https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764',
                                                          'https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088',
                                                          'https://github.com/Azure/AKS/issues/3947',
                                                          'https://github.com/Kong/kong/discussions/11741',
                                                          'https://github.com/advisories/GHSA-qppj-fm5r-hxr3',
                                                          'https://github.com/advisories/GHSA-vx74-f528-fxqg',
                                                          'https://github.com/advisories/GHSA-xpw8-rcwv-8f8p',
                                                          'https://github.com/akka/akka-http/issues/4323',
                                                          'https://github.com/alibaba/tengine/issues/1872',
                                                          'https://github.com/apache/apisix/issues/10320',
                                                          'https://github.com/apache/httpd-site/pull/10',
                                                          'https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113',
                                                          'https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2',
                                                          'https://github.com/apache/trafficserver/pull/10564',
                                                          'https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487',
                                                          'https://github.com/bcdannyboy/CVE-2023-44487',
                                                          'https://github.com/caddyserver/caddy/issues/5877',
                                                          'https://github.com/caddyserver/caddy/releases/tag/v2.7.5',
                                                          'https://github.com/dotnet/announcements/issues/277',
                                                          'https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73',
                                                          'https://github.com/eclipse/jetty.project/issues/10679',
                                                          'https://github.com/envoyproxy/envoy/pull/30055',
                                                          'https://github.com/etcd-io/etcd/issues/16740',
                                                          'https://github.com/facebook/proxygen/pull/466',
                                                          'https://github.com/golang/go/issues/63417',
                                                          'https://github.com/grpc/grpc-go/pull/6703',
                                                          'https://github.com/h2o/h2o/pull/3291',
                                                          'https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf',
                                                          'https://github.com/haproxy/haproxy/issues/2312',
                                                          'https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244',
                                                          'https://github.com/junkurihara/rust-rpxy/issues/97',
                                                          'https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1',
                                                          'https://github.com/kazu-yamamoto/http2/issues/93',
                                                          'https://github.com/kubernetes/kubernetes/pull/121120',
                                                          'https://github.com/line/armeria/pull/5232',
                                                          'https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632',
                                                          'https://github.com/micrictor/http2-rst-stream',
                                                          'https://github.com/microsoft/CBL-Mariner/pull/6381',
                                                          'https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61',
                                                          'https://github.com/nghttp2/nghttp2/pull/1961',
                                                          'https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0',
                                                          'https://github.com/ninenines/cowboy/issues/1615',
                                                          'https://github.com/nodejs/node/pull/50121',
                                                          'https://github.com/openresty/openresty/issues/930',
                                                          'https://github.com/opensearch-project/data-prepper/issues/3474',
                                                          'https://github.com/oqtane/oqtane.framework/discussions/3367',
                                                          'https://github.com/projectcontour/contour/pull/5826',
                                                          'https://github.com/tempesta-tech/tempesta/issues/1986',
                                                          'https://github.com/varnishcache/varnish-cache/issues/3996',
                                                          'https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo',
                                                          'https://istio.io/latest/news/security/istio-security-2023-004/',
                                                          'https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/',
                                                          'https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/',
                                                          'https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html',
                                                          'https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html',
                                                          'https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html',
                                                          'https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/',
                                                          'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487',
                                                          'https://my.f5.com/manage/s/article/K000137106',
                                                          'https://netty.io/news/2023/10/10/4-1-100-Final.html',
                                                          'https://news.ycombinator.com/item?id=37830987',
                                                          'https://news.ycombinator.com/item?id=37830998',
                                                          'https://news.ycombinator.com/item?id=37831062',
                                                          'https://news.ycombinator.com/item?id=37837043',
                                                          'https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/',
                                                          'https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected',
                                                          'https://security.gentoo.org/glsa/202311-09',
                                                          'https://security.netapp.com/advisory/ntap-20231016-0001/',
                                                          'https://security.netapp.com/advisory/ntap-20240426-0007/',
                                                          'https://security.paloaltonetworks.com/CVE-2023-44487',
                                                          'https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14',
                                                          'https://ubuntu.com/security/CVE-2023-44487',
                                                          'https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/',
                                                          'https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487',
                                                          'https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event',
                                                          'https://www.debian.org/security/2023/dsa-5521',
                                                          'https://www.debian.org/security/2023/dsa-5522',
                                                          'https://www.debian.org/security/2023/dsa-5540',
                                                          'https://www.debian.org/security/2023/dsa-5549',
                                                          'https://www.debian.org/security/2023/dsa-5558',
                                                          'https://www.debian.org/security/2023/dsa-5570',
                                                          'https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487',
                                                          'https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/',
                                                          'https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/',
                                                          'https://www.openwall.com/lists/oss-security/2023/10/10/6',
                                                          'https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack',
                                                          'https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/'],
                                           'summary': 'The HTTP/2 protocol '
                                                      'allows a denial of '
                                                      'service (server '
                                                      'resource consumption) '
                                                      'because request '
                                                      'cancellation can reset '
                                                      'many streams quickly, '
                                                      'as exploited in the '
                                                      'wild in August through '
                                                      'October 2023.',
                                           'verified': False}}},
             {'_shodan': {'crawler': 'dfd12d70c30ccb3812bf26f89905deeb85e98c77',
                          'id': '91086395-e1da-468a-9c35-6061a6979a17',
                          'module': 'ssh',
                          'options': {},
                          'ptr': True,
                          'region': 'eu'},
              'asn': 'AS3301',
              'cpe': ['cpe:/a:openbsd:openssh'],
              'cpe23': ['cpe:2.3:a:openbsd:openssh'],
              'data': 'SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.7\n'
                      'Key type: ecdsa-sha2-nistp256\n'
                      'Key: '
                      'AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBB5tixTDl0dBWJ+FZM1fnuZd\n'
                      'Ejyi2MHH75S26xn7JbfG2IV4hGrKugvKoiwXekVGC77oc6RFvQ3Hf6HT6M+tmWA=\n'
                      'Fingerprint: '
                      '0c:7e:18:dd:c8:fe:b9:9e:7f:4e:dc:5d:61:cb:01:a8\n'
                      '\n'
                      'Kex Algorithms:\n'
                      '\tcurve25519-sha256\n'
                      '\tcurve25519-sha256@libssh.org\n'
                      '\tecdh-sha2-nistp256\n'
                      '\tecdh-sha2-nistp384\n'
                      '\tecdh-sha2-nistp521\n'
                      '\tsntrup761x25519-sha512@openssh.com\n'
                      '\tdiffie-hellman-group-exchange-sha256\n'
                      '\tdiffie-hellman-group16-sha512\n'
                      '\tdiffie-hellman-group18-sha512\n'
                      '\tdiffie-hellman-group14-sha256\n'
                      '\tkex-strict-s-v00@openssh.com\n'
                      '\n'
                      'Server Host Key Algorithms:\n'
                      '\trsa-sha2-512\n'
                      '\trsa-sha2-256\n'
                      '\tecdsa-sha2-nistp256\n'
                      '\tssh-ed25519\n'
                      '\n'
                      'Encryption Algorithms:\n'
                      '\tchacha20-poly1305@openssh.com\n'
                      '\taes128-ctr\n'
                      '\taes192-ctr\n'
                      '\taes256-ctr\n'
                      '\taes128-gcm@openssh.com\n'
                      '\taes256-gcm@openssh.com\n'
                      '\n'
                      'MAC Algorithms:\n'
                      '\tumac-64-etm@openssh.com\n'
                      '\tumac-128-etm@openssh.com\n'
                      '\thmac-sha2-256-etm@openssh.com\n'
                      '\thmac-sha2-512-etm@openssh.com\n'
                      '\thmac-sha1-etm@openssh.com\n'
                      '\tumac-64@openssh.com\n'
                      '\tumac-128@openssh.com\n'
                      '\thmac-sha2-256\n'
                      '\thmac-sha2-512\n'
                      '\thmac-sha1\n'
                      '\n'
                      'Compression Algorithms:\n'
                      '\tnone\n'
                      '\tzlib@openssh.com\n',
              'domains': ['telia.com'],
              'hash': 667895948,
              'hostnames': ['213-67-1-156-no600.tbcn.telia.com'],
              'info': 'protocol 2.0',
              'ip': 3577938332,
              'ip_str': '213.67.1.156',
              'isp': 'Telia Company AB',
              'location': {'area_code': None,
                           'city': 'Stockholm',
                           'country_code': 'SE',
                           'country_name': 'Sweden',
                           'latitude': 59.32938,
                           'longitude': 18.06871,
                           'region_code': 'AB'},
              'org': 'Telia Network services',
              'os': None,
              'port': 2222,
              'product': 'OpenSSH',
              'ssh': {'cipher': 'aes128-ctr',
                      'fingerprint': '0c:7e:18:dd:c8:fe:b9:9e:7f:4e:dc:5d:61:cb:01:a8',
                      'hassh': '41ff3ecd1458b0bf86e1b4891636213e',
                      'kex': {'compression_algorithms': ['none',
                                                         'zlib@openssh.com'],
                              'encryption_algorithms': ['chacha20-poly1305@openssh.com',
                                                        'aes128-ctr',
                                                        'aes192-ctr',
                                                        'aes256-ctr',
                                                        'aes128-gcm@openssh.com',
                                                        'aes256-gcm@openssh.com'],
                              'kex_algorithms': ['curve25519-sha256',
                                                 'curve25519-sha256@libssh.org',
                                                 'ecdh-sha2-nistp256',
                                                 'ecdh-sha2-nistp384',
                                                 'ecdh-sha2-nistp521',
                                                 'sntrup761x25519-sha512@openssh.com',
                                                 'diffie-hellman-group-exchange-sha256',
                                                 'diffie-hellman-group16-sha512',
                                                 'diffie-hellman-group18-sha512',
                                                 'diffie-hellman-group14-sha256',
                                                 'kex-strict-s-v00@openssh.com'],
                              'kex_follows': False,
                              'languages': [''],
                              'mac_algorithms': ['umac-64-etm@openssh.com',
                                                 'umac-128-etm@openssh.com',
                                                 'hmac-sha2-256-etm@openssh.com',
                                                 'hmac-sha2-512-etm@openssh.com',
                                                 'hmac-sha1-etm@openssh.com',
                                                 'umac-64@openssh.com',
                                                 'umac-128@openssh.com',
                                                 'hmac-sha2-256',
                                                 'hmac-sha2-512',
                                                 'hmac-sha1'],
                              'server_host_key_algorithms': ['rsa-sha2-512',
                                                             'rsa-sha2-256',
                                                             'ecdsa-sha2-nistp256',
                                                             'ssh-ed25519'],
                              'unused': 0},
                      'key': 'AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBB5tixTDl0dBWJ+FZM1fnuZd\n'
                             'Ejyi2MHH75S26xn7JbfG2IV4hGrKugvKoiwXekVGC77oc6RFvQ3Hf6HT6M+tmWA=\n',
                      'mac': 'hmac-sha2-256',
                      'type': 'ecdsa-sha2-nistp256'},
              'timestamp': '2024-05-02T16:52:23.722231',
              'transport': 'tcp',
              'version': '8.9p1 Ubuntu-3ubuntu0.7'},
             {'_shodan': {'crawler': 'bf213bc419cc8491376c12af31e32623c1b6f467',
                          'id': '222e0f19-b18f-44cb-af2f-139f002bda43',
                          'module': 'https',
                          'options': {},
                          'ptr': True,
                          'region': 'eu'},
              'asn': 'AS3301',
              'cpe': ['cpe:/a:f5:nginx:1.18.0',
                      'cpe:/o:canonical:ubuntu_linux',
                      'cpe:/o:linux:linux_kernel'],
              'cpe23': ['cpe:2.3:a:f5:nginx:1.18.0',
                        'cpe:2.3:o:canonical:ubuntu_linux',
                        'cpe:2.3:o:linux:linux_kernel'],
              'data': 'HTTP/1.1 200 OK\r\n'
                      'Server: nginx/1.18.0 (Ubuntu)\r\n'
                      'Date: Tue, 23 Apr 2024 05:15:54 GMT\r\n'
                      'Content-Type: text/html\r\n'
                      'Transfer-Encoding: chunked\r\n'
                      'Connection: keep-alive\r\n'
                      '\r\n',
              'domains': ['telia.com', 'dig-sec.com'],
              'hash': -1312139988,
              'hostnames': ['213-67-1-156-no600.tbcn.telia.com',
                            'cyberrange.dig-sec.com'],
              'http': {'components': {},
                       'headers_hash': -723384840,
                       'host': '213.67.1.156',
                       'html': '<html>\r\n'
                               '<head><title>Index of /</title></head>\r\n'
                               '<body>\r\n'
                               '<h1>Index of /</h1><hr><pre><a '
                               'href="../">../</a>\r\n'
                               '<a '
                               'href="ISOs/">ISOs/</a>                                              '
                               '27-Mar-2024 12:56                   -\r\n'
                               '<a '
                               'href="archive/">archive/</a>                                           '
                               '22-Apr-2024 21:54                   -\r\n'
                               '<a '
                               'href="bsd/">bsd/</a>                                               '
                               '17-Apr-2024 09:23                   -\r\n'
                               '<a '
                               'href="facts_files_fam1_morning/">facts_files_fam1_morning/</a>                          '
                               '16-Apr-2024 08:32                   -\r\n'
                               '<a '
                               'href="fam_baseline_exchange_ca/">fam_baseline_exchange_ca/</a>                          '
                               '16-Apr-2024 09:06                   -\r\n'
                               '<a '
                               'href="linux/">linux/</a>                                             '
                               '17-Apr-2024 09:17                   -\r\n'
                               '<a '
                               'href="windows/">windows/</a>                                           '
                               '23-Apr-2024 04:39                   -\r\n'
                               '<a '
                               'href="ls24-bt03_public.cer">ls24-bt03_public.cer</a>                               '
                               '20-Apr-2024 13:04                1255\r\n'
                               '</pre><hr></body>\r\n'
                               '</html>\r\n',
                       'html_hash': 1728522135,
                       'location': '/',
                       'redirects': [],
                       'robots': None,
                       'robots_hash': None,
                       'securitytxt': None,
                       'securitytxt_hash': None,
                       'server': 'nginx/1.18.0 (Ubuntu)',
                       'sitemap': None,
                       'sitemap_hash': None,
                       'status': 200,
                       'title': 'Index of /'},
              'ip': 3577938332,
              'ip_str': '213.67.1.156',
              'isp': 'Telia Company AB',
              'location': {'area_code': None,
                           'city': 'Stockholm',
                           'country_code': 'SE',
                           'country_name': 'Sweden',
                           'latitude': 59.32938,
                           'longitude': 18.06871,
                           'region_code': 'AB'},
              'org': 'Telia Network services',
              'os': 'Ubuntu',
              'port': 8443,
              'product': 'nginx',
              'ssl': {'acceptable_cas': [],
                      'alpn': [],
                      'cert': {'expired': False,
                               'expires': '20240718105853Z',
                               'extensions': [{'critical': True,
                                               'data': '\\x03\\x02\\x05\\xa0',
                                               'name': 'keyUsage'},
                                              {'data': '0\\x14\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x01\\x06\\x08+\\x06\\x01\\x05\\x05\\x07\\x03\\x02',
                                               'name': 'extendedKeyUsage'},
                                              {'critical': True,
                                               'data': '0\\x00',
                                               'name': 'basicConstraints'},
                                              {'data': '\\x04\\x14}0}.\\xa9\\x1e\\xaf1o\\xe2\\x15\\xae\\x91l\\x87fS\\x17\\xbb\\xd3',
                                               'name': 'subjectKeyIdentifier'},
                                              {'data': '0\\x16\\x80\\x14\\x14.\\xb3\\x17\\xb7XV\\xcb\\xaeP\\t@\\xe6\\x1f\\xaf\\x9d\\x8b\\x14\\xc2\\xc6',
                                               'name': 'authorityKeyIdentifier'},
                                              {'data': '0G0!\\x06\\x08+\\x06\\x01\\x05\\x05\\x070\\x01\\x86\\x15http://r3.o.lencr.org0"\\x06\\x08+\\x06\\x01\\x05\\x05\\x070\\x02\\x86\\x16http://r3.i.lencr.org/',
                                               'name': 'authorityInfoAccess'},
                                              {'data': '0\\x18\\x82\\x16cyberrange.dig-sec.com',
                                               'name': 'subjectAltName'},
                                              {'data': '0\\n0\\x08\\x06\\x06g\\x81\\x0c\\x01\\x02\\x01',
                                               'name': 'certificatePolicies'},
                                              {'data': '\\x04\\x81\\xf2\\x00\\xf0\\x00v\\x00;Swu>-\\xb9\\x80N\\x8b0[\\x06\\xfe@;g\\xd8O\\xc3\\xf4\\xc7\\xbd\\x00\\r-ro\\xe1\\xfa\\xd4\\x17\\x00\\x00\\x01\\x8e\\xf69P0\\x00\\x00\\x04\\x03\\x00G0E\\x02 '
                                                       '\\x1fwm\\xa6\\xcf\\x96~\\x86G\\xb1\\x06\\xd6\\x93\\xba<\\xd2\\xe1+\\xf9\\xa1\\x13\\x9d\\xb0}\\t\\x1b\\x11\\x85\\xabI\\x8c"\\x02!\\x00\\xac\\x9f\\xf5\\x87\\xebf\\xa71m}A\\x1b\\xdb\\xf0\\xcb\\x8f\\xbf\\xd3\\xa80Tl,\\x94\\x08\\xb23c\\xf0!)~\\x00v\\x00\\x19\\x98\\x10q\\t\\xf0\\xd6R.0\\x80\\xd2\\x9e?d\\xbb\\x83n(\\xcc\\xf9\\x0fR\\x8e\\xee\\xdf\\xceJ?\\x16\\xb4\\xca\\x00\\x00\\x01\\x8e\\xf69P\\t\\x00\\x00\\x04\\x03\\x00G0E\\x02 '
                                                       'd\\x84\\x82>M\\xadT5\\xec\\x9ej\\x06\\x13&b\\x9c\\x1aT\\x15\\xb0&1\\xb2\\x98\\xac\\xa0N\\xb9\\xad:\\x8eV\\x02!\\x00\\xc1\\xd7f\\xaf)\\xeb\\xbfT\\xe8R\\x92l\\x8e{\\xd3\\x0e\\xe1\\xe53\\xd2\\x0b\\xaeY39K\\x97"~\\xdc;\\xd3',
                                               'name': 'ct_precert_scts'}],
                               'fingerprint': {'sha1': '5fb4001d6ad19270cd4284c61a1f576366ad5111',
                                               'sha256': '3c08752adc8913b553ad4c30ec4c46160439dc59e2ab32413d6b54ef1f229e6e'},
                               'issued': '20240419105854Z',
                               'issuer': {'C': 'US',
                                          'CN': 'R3',
                                          'O': "Let's Encrypt"},
                               'pubkey': {'bits': 2048, 'type': 'rsa'},
                               'serial': 289791622555049949657849686483802048681404,
                               'sig_alg': 'sha256WithRSAEncryption',
                               'subject': {'CN': 'cyberrange.dig-sec.com'},
                               'version': 2},
                      'chain': ['-----BEGIN CERTIFICATE-----\n'
                                'MIIE+TCCA+GgAwIBAgISA1Oe/Fnj4ThEcxw8GqL1b9W8MA0GCSqGSIb3DQEBCwUA\n'
                                'MDIxCzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQswCQYDVQQD\n'
                                'EwJSMzAeFw0yNDA0MTkxMDU4NTRaFw0yNDA3MTgxMDU4NTNaMCExHzAdBgNVBAMT\n'
                                'FmN5YmVycmFuZ2UuZGlnLXNlYy5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw\n'
                                'ggEKAoIBAQCtx30aea3QoO8dpeK9SVf6TCF1qC31D5sH35GVdaxF1fAMNPo7uIWR\n'
                                'ys+ptaZKO8ovUXYWXRQ3INnHc725tLNBsb8qi6PXhGCngh1MYBXKco7I9bBYg5Uy\n'
                                'E6kc5CR2cj9LbWmhp1C59DAlLjF3VMcW+C1QBskc1aZuWLa1Aze7jeZ3r0kb8b3Z\n'
                                '8A/d0Xnc/2gzHpcpJdkmDWYET0LsF5dptu0WGYuDnYe9k8fdEP3IBmDmINaVGdQX\n'
                                'mJO1YoyJnxad3HL/IoXKJakaM5/RPmIzadgCqaRutmdPhvQjnRoFJUwKykESlMad\n'
                                'HpAIYF2R2GrMqrpVlGDh7RDpt5MYot5xAgMBAAGjggIYMIICFDAOBgNVHQ8BAf8E\n'
                                'BAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMAwGA1UdEwEB/wQC\n'
                                'MAAwHQYDVR0OBBYEFH0wfS6pHq8xb+IVrpFsh2ZTF7vTMB8GA1UdIwQYMBaAFBQu\n'
                                'sxe3WFbLrlAJQOYfr52LFMLGMFUGCCsGAQUFBwEBBEkwRzAhBggrBgEFBQcwAYYV\n'
                                'aHR0cDovL3IzLm8ubGVuY3Iub3JnMCIGCCsGAQUFBzAChhZodHRwOi8vcjMuaS5s\n'
                                'ZW5jci5vcmcvMCEGA1UdEQQaMBiCFmN5YmVycmFuZ2UuZGlnLXNlYy5jb20wEwYD\n'
                                'VR0gBAwwCjAIBgZngQwBAgEwggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdgA7U3d1\n'
                                'Pi25gE6LMFsG/kA7Z9hPw/THvQANLXJv4frUFwAAAY72OVAwAAAEAwBHMEUCIB93\n'
                                'babPln6GR7EG1pO6PNLhK/mhE52wfQkbEYWrSYwiAiEArJ/1h+tmpzFtfUEb2/DL\n'
                                'j7/TqDBUbCyUCLIzY/AhKX4AdgAZmBBxCfDWUi4wgNKeP2S7g24ozPkPUo7u385K\n'
                                'Pxa0ygAAAY72OVAJAAAEAwBHMEUCIGSEgj5NrVQ17J5qBhMmYpwaVBWwJjGymKyg\n'
                                'TrmtOo5WAiEAwddmrynrv1ToUpJsjnvTDuHlM9ILrlkzOUuXIn7cO9MwDQYJKoZI\n'
                                'hvcNAQELBQADggEBAAIv2s9h7n/xA0qVfOHXzvRNwTpsjuAqbtRIYltb7KMFtLT5\n'
                                'iVjBbBREQw8CLTpNHVe4Et4JJwZXU5oQlZaJR9nMt8RYYPdzlOlZTI2v4vKg1737\n'
                                'TjYDcXJRL+xVpOOn4g12SzzDZDIH/v+/6eE23pcIdh1n+5Ccvv17+C6unesyMKz9\n'
                                'OVw/OVAUtm4c9Sw/MsXgGiqey2bMvWLMDt8EmVrfTTBAAjfqX42k0vKc4Mxt9zlX\n'
                                'zsRsKpOsA5otpz9ATAfJK+Q1gMRDWAkAvc2N48oA2bZFS5WxyLgAfz6hieMKr6/V\n'
                                'ENF2NZiGCAp7aKYZwkIk8o/xXhEccLRvbRo88+0=\n'
                                '-----END CERTIFICATE-----\n',
                                '-----BEGIN CERTIFICATE-----\n'
                                'MIIFFjCCAv6gAwIBAgIRAJErCErPDBinU/bWLiWnX1owDQYJKoZIhvcNAQELBQAw\n'
                                'TzELMAkGA1UEBhMCVVMxKTAnBgNVBAoTIEludGVybmV0IFNlY3VyaXR5IFJlc2Vh\n'
                                'cmNoIEdyb3VwMRUwEwYDVQQDEwxJU1JHIFJvb3QgWDEwHhcNMjAwOTA0MDAwMDAw\n'
                                'WhcNMjUwOTE1MTYwMDAwWjAyMQswCQYDVQQGEwJVUzEWMBQGA1UEChMNTGV0J3Mg\n'
                                'RW5jcnlwdDELMAkGA1UEAxMCUjMwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK\n'
                                'AoIBAQC7AhUozPaglNMPEuyNVZLD+ILxmaZ6QoinXSaqtSu5xUyxr45r+XXIo9cP\n'
                                'R5QUVTVXjJ6oojkZ9YI8QqlObvU7wy7bjcCwXPNZOOftz2nwWgsbvsCUJCWH+jdx\n'
                                'sxPnHKzhm+/b5DtFUkWWqcFTzjTIUu61ru2P3mBw4qVUq7ZtDpelQDRrK9O8Zutm\n'
                                'NHz6a4uPVymZ+DAXXbpyb/uBxa3Shlg9F8fnCbvxK/eG3MHacV3URuPMrSXBiLxg\n'
                                'Z3Vms/EY96Jc5lP/Ooi2R6X/ExjqmAl3P51T+c8B5fWmcBcUr2Ok/5mzk53cU6cG\n'
                                '/kiFHaFpriV1uxPMUgP17VGhi9sVAgMBAAGjggEIMIIBBDAOBgNVHQ8BAf8EBAMC\n'
                                'AYYwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMBIGA1UdEwEB/wQIMAYB\n'
                                'Af8CAQAwHQYDVR0OBBYEFBQusxe3WFbLrlAJQOYfr52LFMLGMB8GA1UdIwQYMBaA\n'
                                'FHm0WeZ7tuXkAXOACIjIGlj26ZtuMDIGCCsGAQUFBwEBBCYwJDAiBggrBgEFBQcw\n'
                                'AoYWaHR0cDovL3gxLmkubGVuY3Iub3JnLzAnBgNVHR8EIDAeMBygGqAYhhZodHRw\n'
                                'Oi8veDEuYy5sZW5jci5vcmcvMCIGA1UdIAQbMBkwCAYGZ4EMAQIBMA0GCysGAQQB\n'
                                'gt8TAQEBMA0GCSqGSIb3DQEBCwUAA4ICAQCFyk5HPqP3hUSFvNVneLKYY611TR6W\n'
                                'PTNlclQtgaDqw+34IL9fzLdwALduO/ZelN7kIJ+m74uyA+eitRY8kc607TkC53wl\n'
                                'ikfmZW4/RvTZ8M6UK+5UzhK8jCdLuMGYL6KvzXGRSgi3yLgjewQtCPkIVz6D2QQz\n'
                                'CkcheAmCJ8MqyJu5zlzyZMjAvnnAT45tRAxekrsu94sQ4egdRCnbWSDtY7kh+BIm\n'
                                'lJNXoB1lBMEKIq4QDUOXoRgffuDghje1WrG9ML+Hbisq/yFOGwXD9RiX8F6sw6W4\n'
                                'avAuvDszue5L3sz85K+EC4Y/wFVDNvZo4TYXao6Z0f+lQKc0t8DQYzk1OXVu8rp2\n'
                                'yJMC6alLbBfODALZvYH7n7do1AZls4I9d1P4jnkDrQoxB3UqQ9hVl3LEKQ73xF1O\n'
                                'yK5GhDDX8oVfGKF5u+decIsH4YaTw7mP3GFxJSqv3+0lUFJoi5Lc5da149p90Ids\n'
                                'hCExroL1+7mryIkXPeFM5TgO9r0rvZaBFOvV2z0gp35Z0+L4WPlbuEjN/lxPFin+\n'
                                'HlUjr8gRsI3qfJOQFy/9rKIJR0Y/8Omwt/8oTWgy1mdeHmmjk7j1nYsvC9JSQ6Zv\n'
                                'MldlTTKB3zhThV1+XWYp6rjd5JW1zbVWEkLNxE7GJThEUG3szgBVGP7pSWTUTsqX\n'
                                'nLRbwHOoq7hHwg==\n'
                                '-----END CERTIFICATE-----\n'],
                      'chain_sha256': ['3c08752adc8913b553ad4c30ec4c46160439dc59e2ab32413d6b54ef1f229e6e',
                                       '67add1166b020ae61b8f5fc96813c04c2aa589960796865572a3c7e737613dfd'],
                      'cipher': {'bits': 256,
                                 'name': 'TLS_AES_256_GCM_SHA384',
                                 'version': 'TLSv1.3'},
                      'dhparams': {'bits': 2048,
                                   'generator': 2,
                                   'prime': 'ffffffffffffffffadf85458a2bb4a9aafdc5620273d3cf1d8b9c583ce2d3695a9e13641146433fbcc939dce249b3ef97d2fe363630c75d8f681b202aec4617ad3df1ed5d5fd65612433f51f5f066ed0856365553ded1af3b557135e7f57c935984f0c70e0e68b77e2a689daf3efe8721df158a136ade73530acca4f483a797abc0ab182b324fb61d108a94bb2c8e3fbb96adab760d7f4681d4f42a3de394df4ae56ede76372bb190b07a7c8ee0a6d709e02fce1cdf7e2ecc03404cd28342f619172fe9ce98583ff8e4f1232eef28183c3fe3b1b4c6fad733bb5fcbc2ec22005c58ef1837d1683b2c6f34a26c1b2effa886b423861285c97ffffffffffffffff',
                                   'public_key': 'e3ecca37a70fcd1d32e9aa881e663f2e428dfd9c80a16c2190e00ab55184833f1200e985b5804089a77cd8bc56be548eed4726d033f30c53abe3ad2cbb41eeaacf10887097cf414ae3f5eae9b4971e0d613f45ea231efc848e5e2c01edd9a3ef837c20a872a8a171f2dcf8555c94c5e68021ba8f2ab87baea42826e307642255a127d1f34f4f09570a7bedca9b5a184881044d957db3a3d5594063189c5921bac01bcca0f08ac1f2116671373f6de83a109906475edb085d7f5df2320490af8f978b07d0091a26cd3c744f5a938e66aa6071bb01a83f9b1baa5a181698dd3d4e143d42a50b608eef360b95c34c1c99942d116221c13ab3dbd41cb4ea01edd51f'},
                      'handshake_states': ['before SSL initialization',
                                           'SSLv3/TLS write client hello',
                                           'SSLv3/TLS read server hello',
                                           'TLSv1.3 read encrypted extensions',
                                           'SSLv3/TLS read server certificate',
                                           'TLSv1.3 read server certificate '
                                           'verify',
                                           'SSLv3/TLS read finished',
                                           'SSLv3/TLS write change cipher spec',
                                           'SSLv3/TLS write finished',
                                           'SSL negotiation finished '
                                           'successfully'],
                      'ja3s': '574866101f64002c6421cc329e4d5458',
                      'jarm': '15d3fd16d29d29d00042d43d000000fe02290512647416dcf0a400ccbc0b6b',
                      'ocsp': {},
                      'tlsext': [{'id': 43, 'name': 'supported_versions'},
                                 {'id': 51, 'name': 'key_share'},
                                 {'id': 0, 'name': 'server_name'}],
                      'trust': {'browser': None, 'revoked': False},
                      'versions': ['-TLSv1',
                                   '-SSLv2',
                                   '-SSLv3',
                                   '-TLSv1.1',
                                   'TLSv1.2']},
              'tags': ['eol-product'],
              'timestamp': '2024-04-23T05:15:54.916069',
              'transport': 'tcp',
              'version': '1.18.0',
              'vulns': {'CVE-2021-23017': {'cvss': 6.8,
                                           'cvss_v2': 6.8,
                                           'epss': 0.5818,
                                           'ranking_epss': 0.97687,
                                           'references': ['http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html',
                                                          'http://packetstormsecurity.com/files/167720/Nginx-1.20.0-Denial-Of-Service.html',
                                                          'https://lists.apache.org/thread.html/r37e6b2165f7c910d8e15fd54f4697857619ad2625f56583802004009%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/r4d4966221ca399ce948ef34884652265729d7d9ef8179c78d7f17e7f%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/r6fc5c57b38e93e36213e9a18c8a4e5dbd5ced1c7e57f08a1735975ba%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/rf232eecd47fdc44520192810560303073cefd684b321f85e311bad31%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.apache.org/thread.html/rf318aeeb4d7a3a312734780b47de83cefb7e6995da0b2cae5c28675c%40%3Cnotifications.apisix.apache.org%3E',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SFVYHC7OXTEO4SMBWXDVK6E5IMEYMEE/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNKOP2JR5L7KCIZTJRZDCUPJTUONMC5I/',
                                                          'https://security.netapp.com/advisory/ntap-20210708-0006/',
                                                          'https://support.f5.com/csp/article/K12331123%2C',
                                                          'https://www.oracle.com/security-alerts/cpuapr2022.html',
                                                          'https://www.oracle.com/security-alerts/cpujan2022.html',
                                                          'https://www.oracle.com/security-alerts/cpuoct2021.html'],
                                           'summary': 'A security issue in '
                                                      'nginx resolver was '
                                                      'identified, which might '
                                                      'allow an attacker who '
                                                      'is able to forge UDP '
                                                      'packets from the DNS '
                                                      'server to cause 1-byte '
                                                      'memory overwrite, '
                                                      'resulting in worker '
                                                      'process crash or '
                                                      'potential other impact.',
                                           'verified': False},
                        'CVE-2021-3618': {'cvss': 5.8,
                                          'cvss_v2': 5.8,
                                          'epss': 0.0011,
                                          'ranking_epss': 0.43792,
                                          'references': ['https://alpaca-attack.com/',
                                                         'https://bugzilla.redhat.com/show_bug.cgi?id=1975623',
                                                         'https://lists.debian.org/debian-lts-announce/2022/11/msg00031.html'],
                                          'summary': 'ALPACA is an application '
                                                     'layer protocol content '
                                                     'confusion attack, '
                                                     'exploiting TLS servers '
                                                     'implementing different '
                                                     'protocols but using '
                                                     'compatible certificates, '
                                                     'such as multi-domain or '
                                                     'wildcard certificates. A '
                                                     'MiTM attacker having '
                                                     "access to victim's "
                                                     'traffic at the TCP/IP '
                                                     'layer can redirect '
                                                     'traffic from one '
                                                     'subdomain to another, '
                                                     'resulting in a valid TLS '
                                                     'session. This breaks the '
                                                     'authentication of TLS '
                                                     'and cross-protocol '
                                                     'attacks may be possible '
                                                     'where the behavior of '
                                                     'one protocol service may '
                                                     'compromise the other at '
                                                     'the application layer.',
                                          'verified': False},
                        'CVE-2023-44487': {'cvss': None,
                                           'cvss_v2': None,
                                           'epss': 0.73226,
                                           'kev': True,
                                           'ranking_epss': 0.98063,
                                           'ransomware_campaign': 'Unknown',
                                           'references': ['http://www.openwall.com/lists/oss-security/2023/10/13/4',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/13/9',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/18/4',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/18/8',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/19/6',
                                                          'http://www.openwall.com/lists/oss-security/2023/10/20/8',
                                                          'https://access.redhat.com/security/cve/cve-2023-44487',
                                                          'https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/',
                                                          'https://aws.amazon.com/security/security-bulletins/AWS-2023-011/',
                                                          'https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/',
                                                          'https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/',
                                                          'https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/',
                                                          'https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack',
                                                          'https://blog.vespa.ai/cve-2023-44487/',
                                                          'https://bugzilla.proxmox.com/show_bug.cgi?id=4988',
                                                          'https://bugzilla.redhat.com/show_bug.cgi?id=2242803',
                                                          'https://bugzilla.suse.com/show_bug.cgi?id=1216123',
                                                          'https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9',
                                                          'https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/',
                                                          'https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack',
                                                          'https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125',
                                                          'https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715',
                                                          'https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve',
                                                          'https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764',
                                                          'https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088',
                                                          'https://github.com/Azure/AKS/issues/3947',
                                                          'https://github.com/Kong/kong/discussions/11741',
                                                          'https://github.com/advisories/GHSA-qppj-fm5r-hxr3',
                                                          'https://github.com/advisories/GHSA-vx74-f528-fxqg',
                                                          'https://github.com/advisories/GHSA-xpw8-rcwv-8f8p',
                                                          'https://github.com/akka/akka-http/issues/4323',
                                                          'https://github.com/alibaba/tengine/issues/1872',
                                                          'https://github.com/apache/apisix/issues/10320',
                                                          'https://github.com/apache/httpd-site/pull/10',
                                                          'https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113',
                                                          'https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2',
                                                          'https://github.com/apache/trafficserver/pull/10564',
                                                          'https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487',
                                                          'https://github.com/bcdannyboy/CVE-2023-44487',
                                                          'https://github.com/caddyserver/caddy/issues/5877',
                                                          'https://github.com/caddyserver/caddy/releases/tag/v2.7.5',
                                                          'https://github.com/dotnet/announcements/issues/277',
                                                          'https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73',
                                                          'https://github.com/eclipse/jetty.project/issues/10679',
                                                          'https://github.com/envoyproxy/envoy/pull/30055',
                                                          'https://github.com/etcd-io/etcd/issues/16740',
                                                          'https://github.com/facebook/proxygen/pull/466',
                                                          'https://github.com/golang/go/issues/63417',
                                                          'https://github.com/grpc/grpc-go/pull/6703',
                                                          'https://github.com/h2o/h2o/pull/3291',
                                                          'https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf',
                                                          'https://github.com/haproxy/haproxy/issues/2312',
                                                          'https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244',
                                                          'https://github.com/junkurihara/rust-rpxy/issues/97',
                                                          'https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1',
                                                          'https://github.com/kazu-yamamoto/http2/issues/93',
                                                          'https://github.com/kubernetes/kubernetes/pull/121120',
                                                          'https://github.com/line/armeria/pull/5232',
                                                          'https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632',
                                                          'https://github.com/micrictor/http2-rst-stream',
                                                          'https://github.com/microsoft/CBL-Mariner/pull/6381',
                                                          'https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61',
                                                          'https://github.com/nghttp2/nghttp2/pull/1961',
                                                          'https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0',
                                                          'https://github.com/ninenines/cowboy/issues/1615',
                                                          'https://github.com/nodejs/node/pull/50121',
                                                          'https://github.com/openresty/openresty/issues/930',
                                                          'https://github.com/opensearch-project/data-prepper/issues/3474',
                                                          'https://github.com/oqtane/oqtane.framework/discussions/3367',
                                                          'https://github.com/projectcontour/contour/pull/5826',
                                                          'https://github.com/tempesta-tech/tempesta/issues/1986',
                                                          'https://github.com/varnishcache/varnish-cache/issues/3996',
                                                          'https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo',
                                                          'https://istio.io/latest/news/security/istio-security-2023-004/',
                                                          'https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/',
                                                          'https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html',
                                                          'https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/',
                                                          'https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/',
                                                          'https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html',
                                                          'https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html',
                                                          'https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html',
                                                          'https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/',
                                                          'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487',
                                                          'https://my.f5.com/manage/s/article/K000137106',
                                                          'https://netty.io/news/2023/10/10/4-1-100-Final.html',
                                                          'https://news.ycombinator.com/item?id=37830987',
                                                          'https://news.ycombinator.com/item?id=37830998',
                                                          'https://news.ycombinator.com/item?id=37831062',
                                                          'https://news.ycombinator.com/item?id=37837043',
                                                          'https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/',
                                                          'https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected',
                                                          'https://security.gentoo.org/glsa/202311-09',
                                                          'https://security.netapp.com/advisory/ntap-20231016-0001/',
                                                          'https://security.paloaltonetworks.com/CVE-2023-44487',
                                                          'https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14',
                                                          'https://ubuntu.com/security/CVE-2023-44487',
                                                          'https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/',
                                                          'https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487',
                                                          'https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event',
                                                          'https://www.debian.org/security/2023/dsa-5521',
                                                          'https://www.debian.org/security/2023/dsa-5522',
                                                          'https://www.debian.org/security/2023/dsa-5540',
                                                          'https://www.debian.org/security/2023/dsa-5549',
                                                          'https://www.debian.org/security/2023/dsa-5558',
                                                          'https://www.debian.org/security/2023/dsa-5570',
                                                          'https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487',
                                                          'https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/',
                                                          'https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/',
                                                          'https://www.openwall.com/lists/oss-security/2023/10/10/6',
                                                          'https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack',
                                                          'https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/'],
                                           'summary': 'The HTTP/2 protocol '
                                                      'allows a denial of '
                                                      'service (server '
                                                      'resource consumption) '
                                                      'because request '
                                                      'cancellation can reset '
                                                      'many streams quickly, '
                                                      'as exploited in the '
                                                      'wild in August through '
                                                      'October 2023.',
                                           'verified': False}}}],
 'total': 6}


### Elasticsearch

In [5]:
from elasticsearch_integration import es_connector

# Establish connection to elasticsearch
es = es_connector.create_es_connection()

# Define the Elasticsearch index name
index_name = "shodan"

# # Clean scan_results and set as document
# document = scan_results

for result in results['matches']:
    document=result

    # Remove ssl.cert from document
    document.pop('ssl', None)

    # Commit the document to the Elasticsearch index
    es.index(index=index_name, body=document)