nginx
tcp/443 tcp/80 tcp/8443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652267a6ad7c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = root@6669786.com:lottery-site/lottery-repo-js85 fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652267a6ad7c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = root@6669786.com:lottery-site/lottery-repo-js85 fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 52.229.200.23:80 · 2203s.com
2026-01-12 16:33
HTTP/1.1 301 Moved Permanently Server: nginx Date: Mon, 12 Jan 2026 16:33:41 GMT Content-Type: text/html Content-Length: 163 Connection: close Location: https://2203s.com:51422/ Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx </center> </body> </html>
Open service 52.229.200.23:8443 · 2203s.com
2026-01-12 16:33
HTTP/1.1 200 OK Server: nginx Date: Mon, 12 Jan 2026 16:33:42 GMT Content-Type: application/octet-stream Transfer-Encoding: chunked Connection: close Expires: Mon, 12 Jan 2026 16:33:41 GMT Cache-Control: no-cache success
Open service 52.229.200.23:443 · 2203s.com
2026-01-12 16:33
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Jan 2026 16:33:43 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 3526
Connection: close
Vary: Accept-Encoding
Last-Modified: Thu, 01 Jan 2026 09:18:09 GMT
ETag: "69563bd1-dc6"
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Accept-Ranges: bytes
Page title: Welcome
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" />
<title>Welcome</title>
<script>
function isMobile() {
return !!(navigator.userAgent.match(
/(phone|pad|pod|iPhone|iPod|ios|iPad|android|Mobile|BlackBerry|IEMobile|MQQBrowser|JUC|Fennec|wOSBrowser|BrowserNG|WebOS|Symbian|Windows Phone)/i
))
}
if (isMobile() !== false) {
if (location.href.indexOf('#') > -1) {
location.href = location.origin + '/m/#/home?' + (location.href.split('#')[1].split('?')[1] || '')
} else {
location.href = location.origin + '/m/#/home' + location.search
}
}
(function () {
var url = window.location.href,
obj = {},
keyvalue = [],
key = '',
value = '',
parseString = url.substring(url.indexOf('?') + 1, url.length).split('&')
for (var i in parseString) {
keyvalue = parseString[i].split('=')
key = keyvalue[0]
value = keyvalue[1] && keyvalue[1].includes('#/') ? keyvalue[1].split('#/')[0] : keyvalue[1]
obj[key] = value
}
if (obj.agent) {
localStorage.setItem('agent', obj.agent)
}
if(obj.register){
if(!localStorage.token){
localStorage.setItem('register', obj.register)
}
}
})()
window.vis = true
window.onblur = function () {
window.vis = false
}
window.onfocus = function () {
window.vis = true
if (typeof window.balanceTask === 'function') {
window.balanceTask()
}
}
if(!document.querySelector('.statistics')) {
let head = document.head || document.getElementsByTagName('head')[0];
let script = document.createElement('script');
let div = document.createElement('div');
div.classList = 'statistics'
div.style.position = 'fixed'
div.style.left = '-9999px'
div.style.top = '-9999px'
if(window.origin.indexOf('s2191.com')!= -1){
script.setAttribute("src", "https://s9.cnzz.com/z_stat.php?id=1280222126&web_id=1280222126");
div.appendChild(script);
head.appendChild(div);
}else if(window.origin.indexOf('s2531.com')!= -1){
script.setAttribute("src", "https://s4.cnzz.com/z_stat.php?id=1280222128&web_id=1280222128");
div.appendChild(script);
head.appendChild(div);
}
}
</script>
<link rel="shortcut icon" href="/static/js85/img/favicon.ico" type="image/x-icon">
<script src="/static/public/js/stomp.js"></script>
<script src="/static/public/js/qrcode.js"></script>
<!-- <script src="http://cstaticdun.126.net/load.min.js"></script> -->
<script src="https://cstaticdun.126.net/load.min.js?t=201903281201"></script>
<script type="text/javascript" src="https://acstatic-dun.126.net/tool.min.js?t=201903281201"></script>
<!-- <script src="/static/public//js/tn_code.js"></script> -->
<link href="/static-js85/style.css" rel="stylesheet"><link href="/static-js85/css/pages/js85/index.9b2a9a49a7ac144790594dd992c84a4d.css" rel="stylesheet"></head>
<body>
<div id="js85App">
</div>
<script type="text/javascript" src="/static-js85/js/manifest.378b0a2d666d2f964bf2.js?v=2026-1-1-15:21:55"></script><script type="text/javascript" src="/static-js85/js/vendor.90e7023873b20afadb07.js?v=2026-1-1-15:21:55"></script><script type="text/javascript" src="/static-js85/js/pages/js85/index.f21a1ccd25bc17b61111.js?v=2026-1-1-15:21:55"></script></body>
</html>