============================================================ BURKINA FASO PRIVATE SECTOR DOMAIN PROBE Date: 2026-03-04 02:37:10 UTC Total Domains Probed: 107 ============================================================ !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! CRITICAL FINDINGS - WORDPRESS SITES WITH OPEN USER ENDPOINTS !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 7 sites expose WordPress user enumeration via /wp-json/wp/v2/users: 1. bank-of-africa.net (BANKING) - Users: "admin" (id:1), "Yassine CHRAIBI" / slug:webmaster (id:14) - WP API: Full REST API open (RankMath, WPJM, Polylang, Popup Maker) - Server: Apache, HSTS, Imperva absent on this domain - Gravatar hashes exposed 2. burkina.coris.bank (BANKING) - Users: "coris" (id:2), "coris_admin" / slug:cb-international (id:1) - WP API: Full REST API open (Jetpack, RankMath, Elementor, Akismet) - Server: Apache/2.4.52 (Ubuntu) - version disclosure - Gravatar hashes exposed 3. rcpb.bf (BANKING) - Users: "Aminata SEDOGO" / slug:asedogorcpb-bf (id:4) - WP API: Full REST API open (Jetpack, Yoast, Polylang, WP Super Cache) - Server: Apache, HSTS - Yoast SEO metadata leaking full author archive URLs 4. cisandco.bf (COMMERCIAL) -- redirects to cisandco.be - Users: "didier.goore" (id:1) - URL reveals dev domain: cisandco.rhyno.fun - WP API: Full REST API open (LiteSpeed, Elementor Pro, CF7) - Server: Apache + LiteSpeed - Gravatar hashes exposed 5. clinique-opportunites.bf (HEALTH) - Users: "admincmo" (id:1) - WP API: Full REST API (AIOSEO, Elementor, MonsterInsights, Image Optimizer) - Server: Apache, X-Powered-By: PHP/8.1.33 (version disclosure) - Elementor introduction metadata leaking in user object 6. visionsante.bf (HEALTH) - Users: "Gouwindpolo" (id:1) - WP API: Full REST API (Akismet, Sendinblue/Mailin, Yoast, WP Super Cache, MonsterInsights) - Server: fastestcache/Varnish edge cache - Yoast SEO metadata leaking full author archive URLs 7. diasporaburkina.bf (OTHER) - Users: "ad_zep" (id:2), "diasp_ad" (id:1) - WP API: Full REST API (LiteSpeed, MasterStudy LMS, Slider Revolution) - Has LMS platform (MasterStudy) - potential student data - Server: LiteSpeed + LiteSpeed Cache - Also responds to Drupal /core/misc/drupal.js (false positive or dual-stack) 8. laposte.bf (STATE ENTERPRISES) - GOVERNMENT POSTAL SERVICE - Users: "atraore" (id:3), "doatchade" (id:5) - WP API: Full REST API (AIOSEO, WPDM, Elementor, LoginPress, MonsterInsights) - Server: Apache, HSTS - LoginPress plugin present (custom login page) - WPDM (WP Download Manager) namespace present - potential file exposure !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! WORDPRESS SITES WITH RESTRICTED USER ENDPOINTS (API still open) !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 9 sites have WP REST API active but users endpoint blocked: 1. camco.bf (COMMERCIAL) -> www.camco.bf - "Centre d'Arbitrage, Mediation et Conciliation de Ouagadougou" - Plugins: Wordfence, Elementor, SEOPress, WP Rocket, WPML - Server: o2switch-PowerBoost 2. profel.bf (COMMERCIAL) -> www.profimetal.bf - "Profimetal" - construction materials - Plugins: Wordfence, Slider Revolution, SEOPress, WP Rocket - Server: o2switch-PowerBoost 3. profimetal.bf (COMMERCIAL) -> www.profimetal.bf - Same as profel.bf (shared WordPress install) 4. technibois.bf (COMMERCIAL) -> groupefadoul.com/technibois/ - "Groupe Fadoul Afrique" parent site - Plugins: Wordfence, WPML, SEOPress, WP Rocket - Server: o2switch-PowerBoost 5. aber.bf (ENERGY) -> www.aber.bf - "Agence Burkinabe de l'Electrification Rurale" - X-Powered-By: PHP/8.2 (version disclosure) - Plugins: Jetpack, Wordfence, AMP, WonderPlugin Slider - Server: OVHcloud 6. arse.bf (ENERGY) -> www.arse.bf - "Autorite de regulation du secteur de l'energie" - X-Powered-By: PHP/8.4 (version disclosure) - Plugins: Jetpack, Wordfence, Slider Revolution, tagDiv themes - Server: OVHcloud 7. lepays.bf (MEDIA) - "Editions Le Pays" - news site - Plugins: iThemes Security (Solid Security), Yoast, WooCommerce, Jetpack, Sendinblue - WooCommerce store namespace present (wc/v3) - potential e-commerce data - Server: Cloudflare 8. sotraco.bf (STATE ENTERPRISES) - "SOTRACO" - state transport company - Plugins: Wordfence, Yoast, LiteSpeed, Matomo Analytics, Elementor Pro - Also responds to Drupal /core/misc/drupal.js - Server: LiteSpeed + N0C 9. sogetel.bf (TELECOMS) -> groupefadoul.com/sogetel/ - Same parent WP as technibois.bf (Groupe Fadoul) - Server: o2switch-PowerBoost 10. telecelfaso.bf (TELECOMS) -> www.telecelfaso.bf - "Telecel Faso" - major telecom operator - Plugins: Wordfence, WPML, Slider Revolution, WP Grid Builder, WP Rocket, SEOPress - Server: o2switch-PowerBoost !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! OTHER CMS DETECTIONS !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! DRUPAL SITES: - cci.bf (STATE ENTERPRISES) - Drupal 7, X-Generator confirmed Server: Apache/2.4.65 (Debian), PHP/5.6.40 (ANCIENT - EOL) X-Drupal-Cache: HIT - caching active - lonab.bf (STATE ENTERPRISES) - Drupal 9, X-Generator confirmed Server: Cloudflare fronted, Apache behind - bumigeb.bf (STATE ENTERPRISES) - Drupal detected (core JS) Laravel XSRF-TOKEN + session cookies (dual framework?) Server: Apache/2.4.52 (Ubuntu) - anacburkina.org (AVIATION) - Drupal detected (core JS) PHPSESSID cookie, custom PHP app or Drupal - edimedia.bf (MEDIA) - suspended hosting, Drupal JS still responds - ouagafm.bf (MEDIA) - suspended hosting, Drupal JS still responds - scpa-kamsome.bf (OTHER) - "Site en construction", Drupal JS responds JOOMLA SITES: - hagemateriaux.bf (COMMERCIAL) -> redirects to groupehage.bf with Joomla URL params com_content, Itemid parameters in redirect URL !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! ADDITIONAL INTERESTING FINDINGS !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! EXPOSED SERVER VERSIONS: - cci.bf: PHP/5.6.40 (CRITICAL - end of life since 2018) - formationenligne.bf: PHP/7.3 (EOL since 2021) - clinique-opportunites.bf: PHP/8.1.33 - aber.bf: PHP/8.2 - arse.bf: PHP/8.4 - msoft.bf: Apache/2.4.57 (AlmaLinux) OpenSSL/3.0.7 - burkina.coris.bank: Apache/2.4.52 (Ubuntu) - bumigeb.bf: Apache/2.4.52 (Ubuntu) - cci.bf: Apache/2.4.65 (Debian) SUSPENDED / ERROR SITES (hosting active, site down): - edifice.bf: 302 -> /ph-sys/suspended/ (N0C/LiteSpeed) - edimedia.bf: 302 -> /ph-sys/suspended/ (N0C/LiteSpeed) - ouagafm.bf: 302 -> /ph-sys/suspended/ (N0C/LiteSpeed) - gras.bf: 500 Internal Server Error (o2switch, WP broken) - richmedia.bf: 500 Internal Server Error (Apache, WP cache headers) - eauduliptako.bf: 503 Service Unavailable - ujkz.bf: 503 Service Temporarily Unavailable (OVHcloud) - jumia.bf: 530 (Cloudflare, origin unreachable) NOT INSTALLED / PARKED: - cathedralebobo.bf: "Site not installed - OVHcloud" - otc.bf: "Site not installed - OVHcloud" - paejf.bf: "Site not installed - OVHcloud" - sicar-marsh.bf: "Site not installed - OVHcloud" INTERESTING REDIRECTS: - cisandco.bf -> cisandco.be (Belgium, reveals dev domain rhyno.fun) - smile.bf -> synelia.tech (rebranded, WP on Rocky Linux) - rmo.bf -> rmo-jobcenter.com (job portal, Apache/Debian) - gemco.bf -> gemco.africa (Wix site) - sbifbourse.bf -> www.sbifbourse.bf (Wix/Pepyaka) - formationenligne.bf -> formationenligne.org (WP + LearnPress LMS) - technibois.bf -> groupefadoul.com/technibois/ - sogetel.bf -> groupefadoul.com/sogetel/ - profel.bf -> www.profimetal.bf - brakina.bf -> brakina-bf.com (Cloudflare) WAF / CDN DETECTIONS: - societegenerale.bf: Imperva CDN + TYPO3 CMS (x-redirect-by: TYPO3 Redirect 17) - sonar.bf: Sucuri/Cloudproxy WAF - lepays.bf: Cloudflare - lonab.bf: Cloudflare - jumia.bf: Cloudflare (origin down) NOTABLE LIVE SITES (non-WP, non-Drupal): - investirauburkina.net: Joomla-based (x-frame-options, CleanTalk cookies) - ticmagazine.bf: WP REST API restricted to authenticated users only - mediacom.bf: Apache, 403 Forbidden, "Access denied" - sonar.bf: Custom app behind Sucuri WAF, heavy CSP policy - faso-coton.bf: Static HTML (last modified 2018) - msoft.bf: Static HTML on AlmaLinux (last modified 2017) - vipnet.bf: Static HTML (last modified 2020) - ispp.bf: openresty/1.27.1.1 (415 response) - sbiftrade.bf: Microsoft-HTTPAPI/2.0 (404) - talentys.bf: OVHcloud, custom app on port 80 COMPLETELY UNREACHABLE (55 domains): airburkina.bf, ouagadougou-airport.bf, apbef-b.net.bf, bacb.bf, bcb.bf, cbaofaso.bf, corisbank.bf, sportcash.bf, apidev.bf, fidelisfinance.bf, globalsolutions.bf, jovago.bf, lwili.bf, patronat.bf, pixelplus.bf, sdhl.bf, sortir.bf, valconstruction.bf, worldaudit.bf, etalonenergy.bf, cnrfp.bf, dufaso.bf, fasoblog.bf, lerenouveau.bf, lesoir.bf, rmofm.bf, amnestyburkina.bf, competences-feminines.bf, keduburkinabe.bf, pneburkina.bf, praps.bf, sahelsolidarite.bf, wendpanga.bf, openburkina.bf (HTTP-only), ordre-sages-femmes.bf, airtel.bf, btic.bf, fasonet.bf, softnet.bf, telecel.bf, colycee.bf, univ-bobo.bf, univ-ouaga.bf, universiteenligne.bf, cameg.bf, sanaco.bf, sodibo.bf, groupehage.bf (WP detected but API not accessible via /wp-json/), graine.bf (403), sidwaya.info (403) ============================================================ DETAILED PROBE OUTPUT BELOW ============================================================ === airburkina.bf (AVIATION) === [HTTPS Headers] (HTTPS failed, trying HTTP...) UNREACHABLE (both HTTPS and HTTP failed) --- === anacburkina.org (AVIATION) === [HTTPS Headers] HTTP/1.1 200 OK Date: Wed, 04 Mar 2026 07:36:29 GMT Content-Type: text/html; charset=UTF-8 Connection: keep-alive Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=75jbqfjubg35rqnf1teniv0pi2; path=/ Vary: Accept-Encoding X-Orig-Rid: b2fb5bd9ecebc3615f459a9799823147 X-Anubis-Action: X-Anubis-Rule: X-Anubis-Status: Edge-Cache-Engine-Mode: ACTIVE Accept-Ranges: bytes X-Cache-Status: MISS Alt-Svc: h3=":443" X-Request-Id: b2fb5bd9ecebc3615f459a9799823147 [WordPress API Check: /wp-json/]
The document has moved
You don't have permission to ac
[Drupal Detected: /core/misc/drupal.js exists]
---
=== groupehage.bf (COMMERCIAL) ===
[HTTPS Headers]
HTTP/1.1 301 Moved Permanently
Date: Wed, 04 Mar 2026 07:38:10 GMT
Server: Apache
X-Redirect-By: WordPress
Location: https://www.groupehage.bf/
Content-Type: text/html; charset=UTF-8
HTTP/1.1 200 OK
Date: Wed, 04 Mar 2026 07:38:12 GMT
Server: Apache
Link: The document has moved
The server
---
=== etalonenergy.bf (ENERGY) ===
[HTTPS Headers]
(HTTPS failed, trying HTTP...)
UNREACHABLE (both HTTPS and HTTP failed)
---
=== clinique-opportunites.bf (HEALTH) ===
[HTTPS Headers]
HTTP/1.1 415 Unsupported Media Type
Date: Wed, 04 Mar 2026 07:41:04 GMT
Server: Apache
X-Powered-By: PHP/8.1.33
Permissions-Policy: private-state-token-redemption=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com"), private-state-token-issuance=(self "https://www.google.com" "https://www.gstatic.com" "https://recaptcha.net" "https://challenges.cloudflare.com" "https://hcaptcha.com")
Link: The document has moved
Forbidden
415 Unsupported Media Type
302 Found
Moved Permanently
415 Unsupported Media Type
415 Unsupported Media Type
Service Unavailable
Found
Found