Skip to content

Research: Bolivia Passive Recon 2026 — 397 live hosts, 32 findings, 5 critical RCE#31

Open
leetcrypt wants to merge 1 commit into
Ringmast4r:mainfrom
leetcrypt:research/bolivia-passive-recon-2026
Open

Research: Bolivia Passive Recon 2026 — 397 live hosts, 32 findings, 5 critical RCE#31
leetcrypt wants to merge 1 commit into
Ringmast4r:mainfrom
leetcrypt:research/bolivia-passive-recon-2026

Conversation

@leetcrypt
Copy link
Copy Markdown

Bolivia Government Passive Reconnaissance

Summary

🌐 Subdomains 962
🖥️ Live Hosts 397
🌍 Web Services 102
📜 Historical URLs 475,668
🔴 Vulnerabilities 32 (5 critical)

What's Included

  • RESEARCH/bolivia-passive-2026/README.md — Full report with findings, CVE details, risk assessment
  • CYBER RECON TOUR/South America/bolivian-websites.txt — Domain list updated (195 → 464 domains)

Methodology

subfinderdnsxhttpxgaunuclei
Rate-limited: 5 req/s. 100% passive. No exploitation.

Key Findings

  • 5 CRITICAL: CVE-2022-41352 (Zimbra RCE) on 4 government mail servers running unpatched v8.8.15
  • 7 Zimbra email servers across ministries (Interior, Environment, Health Authority, Public Admin)
  • 5 exposed admin panels (cPanel, GitLab, LDAP, Senate intranet)
  • PHP 4.4.9 in production on human rights portal (16+ years EOL)
  • Symfony debug profiler exposed on education portal
  • 475,668 historical URLs catalogued via Wayback Machine

Affected Government Entities

  • Ministry of Government (correo.mingobierno.gob.bo)
  • Ministry of Environment (correo.mmaya.gob.bo)
  • Health & Food Safety Authority (correo.aspb.gob.bo)
  • School of Public Administration (correo.egpp.gob.bo)
  • National GeoServer (geo.gob.bo)
  • Senate (intranet.senado.gob.bo)
  • Anti-Narcotics Police (mail.felcn.gob.bo)

All data from publicly available sources. No systems accessed or exploited.
Contributed by OptinAmpOut

… critical RCE

Campaign: bo_20260314_143141
Scope: gob.bo government infrastructure

Key findings:
- 962 subdomains discovered (cert transparency)
- 397 live hosts confirmed (41.1% survival)
- 102 web services fingerprinted
- 475,668 historical URLs collected
- 32 vulnerabilities confirmed (5 critical)
- CVE-2022-41352: Zimbra RCE on 4 government mail servers
- 7 Zimbra email servers, 5 exposed admin panels
- PHP 4.4.9 in production on human rights portal

100% passive reconnaissance. No exploitation.
Contributed by OptinAmpOut
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant