nginx
tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa349a4e55245e6b3a2fbb07958066a570db1cb631a
GraphQL introspection enabled at /graphql Types: 289 (by kind: ENUM: 3, INPUT_OBJECT: 79, OBJECT: 196, SCALAR: 11) Operations: - Query: Query | fields: allGiftCampaigns, allPromotedProducts, allSameGroupNcCampaigns, appliedVariantsDiscount, banners - Mutation: Mutation | fields: addToList, addUserPermission, applyListToCart, approveLevel2Order, buildOrderItemsInWarehouse - Subscription: Subscription | fields: allOrderItemsWereRemoved, newUserNotification, orderItemWasUpdated, passwordWasChangedNotification, priceWasUpdated Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a64601f25512d702b0a0183871e8e32d9071befa
GraphQL introspection enabled at /graphql Types: 286 (by kind: ENUM: 3, INPUT_OBJECT: 79, OBJECT: 193, SCALAR: 11) Operations: - Query: Query | fields: allGiftCampaigns, allPromotedProducts, allSameGroupNcCampaigns, appliedVariantsDiscount, banners - Mutation: Mutation | fields: addToList, addUserPermission, applyListToCart, approveLevel2Order, buildOrderItemsInWarehouse - Subscription: Subscription | fields: allOrderItemsWereRemoved, newUserNotification, orderItemWasUpdated, passwordWasChangedNotification, priceWasUpdated Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a83dd1aad4f6829a20a1b450e2e04d055657671b
GraphQL introspection enabled at /graphql Types: 279 (by kind: ENUM: 3, INPUT_OBJECT: 79, OBJECT: 186, SCALAR: 11) Operations: - Query: Query | fields: allGiftCampaigns, allPromotedProducts, allSameGroupNcCampaigns, appliedVariantsDiscount, banners - Mutation: Mutation | fields: addToList, addUserPermission, applyListToCart, approveLevel2Order, buildOrderItemsInWarehouse - Subscription: Subscription | fields: allOrderItemsWereRemoved, newUserNotification, orderItemWasUpdated, passwordWasChangedNotification, requestingOrderWasRemoved Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3fdf3fb7596165c77001b9dbff3a520ce7d62c3d9
GraphQL introspection enabled at /graphql Types: 281 (by kind: ENUM: 3, INPUT_OBJECT: 79, OBJECT: 188, SCALAR: 11) Operations: - Query: Query | fields: allGiftCampaigns, allPromotedProducts, allSameGroupNcCampaigns, appliedVariantsDiscount, banners - Mutation: Mutation | fields: addToList, addUserPermission, applyListToCart, approveLevel2Order, buildOrderItemsInWarehouse - Subscription: Subscription | fields: allOrderItemsWereRemoved, newUserNotification, orderItemWasUpdated, passwordWasChangedNotification, priceWasUpdated Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa399d7ae9ef9db188ee7ee27e497b5f71985366e5f
GraphQL introspection enabled at /graphql Types: 249 (by kind: ENUM: 2, INPUT_OBJECT: 69, OBJECT: 168, SCALAR: 10) Operations: - Query: Query | fields: allGiftCampaigns, allPromotedProducts, allSameGroupNcCampaigns, appliedVariantsDiscount, banners - Mutation: Mutation | fields: addToList, addUserPermission, applyListToCart, approveLevel2Order, buildOrderItemsInWarehouse - Subscription: Subscription | fields: allOrderItemsWereRemoved, newUserNotification, orderItemWasUpdated, passwordWasChangedNotification, requestingOrderWasRemoved Directives: deprecated, include, skip (total: 3)
Open service 18.143.254.155:80 ยท api.dichvulapdat.ampo.vn
2026-02-08 02:47
HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache, private Date: Sun, 08 Feb 2026 02:47:25 GMT Set-Cookie: XSRF-TOKEN=eyJpdiI6IlZaeGtMdTc0c2plZXlUZHNpWDJYMWc9PSIsInZhbHVlIjoiMWNWcUhvTGxFM0N6SzQyajJkN01uQW1ZZUxVdERwTklUWmdBTDMwV0pzUFhWbWNId3dsSHZoMXFrU3ZQV0xKbU9JK0tLTitXVzFKaVI5T0pPdmJuRHJpQWxYRjd5d2ErNG5OZm5jR0R6WnhsYVdUTmErWXpvWm1SaXF5S2JxMFciLCJtYWMiOiJmYmJhZDE4MWM3ZmQyODE3ZjhhYmNiNWI4ZGU4MjliNTE4YWM4ZTY3ZDgzYzAxNDM5OWQyYjBhYmUwODU5YWIxIiwidGFnIjoiIn0%3D; expires=Sun, 08 Feb 2026 04:47:25 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: landingpage_session=eyJpdiI6IkM1OWd0NENvMWZBQUxrdkhOSFVkQmc9PSIsInZhbHVlIjoiUjBJUmlvU2JIV2JjaXk5Umg0Ky8xZXJDT0s0MHJUYWliWUVDUko3SkZyTWRKUWN2SnhoeWkvbWV6YTZRcUtUUktLOXVPdFV0MEYxZUFmUnRudkl5NEpzRVdnTkhBUnZ6MldHTWZtaE40SnY4Q2lxTzBFTWo4dlhyOGZrRzBVeEciLCJtYWMiOiIwYTcxOTY0OGUyM2I0NjZmNTYwMjBiMjhiNzkxZmVkODNkNTdlMmM3NGU2MjA5YjhiNjczYTJjN2I5MjExMzE2IiwidGFnIjoiIn0%3D; expires=Sun, 08 Feb 2026 04:47:25 GMT; Max-Age=7200; path=/; httponly; samesite=lax X-Frame-Options: SAMEORIGIN