cloudflare
tcp/443 tcp/80 tcp/8443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549da8dbabcb4095a4a217333e70877a90bb297c7a4
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /v1/api/transaction/stock/DeleteCodeStockTemp DELETE /v1/api/transaction/stock/DeleteGiftCardByPinCodexForStockRetriever DELETE /v1/api/transaction/stock/DeleteGiftCardInStock DELETE /v1/api/transaction/stock/DeleteGiftCardInStockByPinCodex GET /v1/api/transaction/order/GetOrderCancellationDetailsFromCodeSold GET /v1/api/transaction/stock/CheckAvailablesCodesStock GET /v1/api/transaction/stock/CheckBurnDate GET /v1/api/transaction/stock/CheckIfCodeExists GET /v1/api/transaction/stock/CheckReservationInStock GET /v1/api/transaction/stock/GetAttemptList GET /v1/api/transaction/stock/GetB2CPendingOrderCodeUsage GET /v1/api/transaction/stock/GetCodeStock GET /v1/api/transaction/stock/GetCurrencies GET /v1/api/transaction/stock/GetCurrencyById GET /v1/api/transaction/stock/GetCurrencyByIsoCode GET /v1/api/transaction/stock/GetCurrencyChanges GET /v1/api/transaction/stock/GetNotDeletableCodes GET /v1/api/transaction/stock/GetPaymentCard GET /v1/api/transaction/stock/GetPinCodeSoldBurnDate GET /v1/api/transaction/stock/GetPinCodeSoldDetails GET /v1/api/transaction/stock/GetRetailerShopsFromOperationsByCodexAndRetailerId GET /v1/api/transaction/stock/GetStockPinCodesSold GET /v1/api/transaction/stock/GetStockPinCodesSoldByRetailerId GET /v1/api/transaction/stock/IsValidSaleCodex GET /v1/api/transaction/stock/ReserveCodeStock PATCH /v1/api/transaction/stock/UpdateCodeStockExpiryDate POST /v1/api/transaction/order/MergeCodeStockTemp POST /v1/api/transaction/stock/ActivationCancel POST /v1/api/transaction/stock/AddJakalaCodeStock POST /v1/api/transaction/stock/BurnCancel POST /v1/api/transaction/stock/BurnCode POST /v1/api/transaction/stock/BurnLockCode POST /v1/api/transaction/stock/BurnWalletCode POST /v1/api/transaction/stock/CancelBurnWalletCode POST /v1/api/transaction/stock/CancelPinCode POST /v1/api/transaction/stock/CancelPinCodeNoRefund POST /v1/api/transaction/stock/CheckCode POST /v1/api/transaction/stock/CheckCodeJakala POST /v1/api/transaction/stock/CheckCodeLastLock POST /v1/api/transaction/stock/CheckCodeLastUsage POST /v1/api/transaction/stock/CheckCodeLocks POST /v1/api/transaction/stock/CheckCodeUsages POST /v1/api/transaction/stock/ExtendCode POST /v1/api/transaction/stock/FilterCodeStockGroup POST /v1/api/transaction/stock/GenerateAndInsertCodeStock POST /v1/api/transaction/stock/GetNotBurnedCodesByRetailerId POST /v1/api/transaction/stock/InsertAttempt POST /v1/api/transaction/stock/InsertCodeSold POST /v1/api/transaction/stock/InsertCodeStockTemp POST /v1/api/transaction/stock/InsertCodeUsage POST /v1/api/transaction/stock/InsertGiftCardInStock POST /v1/api/transaction/stock/InsertGiftCardInStockNoPinCodeSoldUpdate POST /v1/api/transaction/stock/LockCode POST /v1/api/transaction/stock/RefundBurn POST /v1/api/transaction/stock/RetrievePaymentCards POST /v1/api/transaction/stock/SyncSoldCodesInStock POST /v1/api/transaction/stock/UnlockCode POST /v1/api/transaction/stock/UpdateCodeStock PUT /v1/api/transaction/stock/UpdateOrBurnJakalaCode PUT /v1/api/transaction/stock/UpdatePinCodeSoldBurnedDate PUT /v1/api/transaction/stock/UpdateReserveCodeStock
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 188.114.97.12:443 · api-transaction.amldev.it
2026-01-09 23:38
HTTP/1.1 404 Not Found
Date: Fri, 09 Jan 2026 23:38:02 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=137
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=8Z7C%2BfUntDIqOOts7yXs0Dr4C3YL4m8LC%2FRRYkmWZ5A%2F1xzhzVsLZJcS5D2VPRyqZBXN%2FNufrf61CvcKeYcRZMe86O4K4u%2B3kex4Ij3H0sLY9mWrGQnydvo%3D"}]}
Server: cloudflare
CF-RAY: 9bb7c414ac885e45-LHR
alt-svc: h3=":443"; ma=86400
Open service 188.114.97.12:443 · api-transaction.amldev.it
2026-01-02 01:58
HTTP/1.1 404 Not Found
Date: Fri, 02 Jan 2026 01:58:11 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=89
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=9J7o0NEElbag6w9V2LYDoHnm%2B00Ied%2B6erILSpyCvl6%2Bgf3RDooCYzZbhePgJ%2Bzyo8LZ4FtUde3MToPXCYBkVfDjkNj3H6u1fa77D79CBm5iYpSrDmgxckM%3D"}]}
Server: cloudflare
CF-RAY: 9b76a65ebd0578ab-FRA
alt-svc: h3=":443"; ma=86400
Open service 2a06:98c1:3120::3:443 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 404 Not Found
Date: Tue, 30 Dec 2025 08:02:10 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=12,cfOrigin;dur=5212
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=znEfnBAVTEzku%2BTLa8Gh18YmCb4g7xHPI078nYHSRJ0OjjCoK6LtXhBxJlXRfIGit8q83rFURlydzVvbqFoWWgDKV21D0otZS2WpxJmnu%2Fb72KQB7JV6zFiSe9V48TfRaPdEfzo%3D"}]}
Server: cloudflare
CF-RAY: 9b600350bba6da4a-SIN
alt-svc: h3=":443"; ma=86400
Open service 188.114.97.3:8443 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 522 <none> Date: Tue, 30 Dec 2025 08:02:25 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=19624,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9b600350af4d5857-BOM alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 188.114.97.3:80 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 301 Moved Permanently
Date: Tue, 30 Dec 2025 08:02:04 GMT
Content-Length: 0
Connection: close
Location: https://api-transaction.amldev.it/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Y7OU1F%2BWGe3UptlLHz5HHPdFBfNvk5%2FoLhdqvo7GT6jNOL0PZ3ZBErS04TUVmX2fsx3p%2BjdDh9kUKKaeJKTa5s%2BpGBPtC9N7LccfG8%2BE1gCtjCmHx8Mb7uo%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=10,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9b6003498a49439a-EWR
alt-svc: h3=":443"; ma=86400
Open service 2a06:98c1:3121::3:443 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 404 Not Found
Date: Tue, 30 Dec 2025 08:02:10 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=5315
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=pn11F9b9wP1%2FkGVWRxAxAXMyaBpfpjhZpuEwfuKbagK0XDRaAcP6tdtlccMrZeg8MvDCeOrsI3ri95RZoZ0Pc8gGLdlkjV5bRM1VGQ9hSG1Tu23PZOWJtDTusS1MmnZuYfUUQoY%3D"}]}
Server: cloudflare
CF-RAY: 9b60034fcc1355af-AMS
alt-svc: h3=":443"; ma=86400
Open service 2a06:98c1:3121::3:8443 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 522 <none> Date: Tue, 30 Dec 2025 08:02:24 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=19330,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9b60034fdf57b8d0-AMS alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 2a06:98c1:3121::3:80 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 301 Moved Permanently
Date: Tue, 30 Dec 2025 08:02:04 GMT
Content-Length: 0
Connection: close
Location: https://api-transaction.amldev.it/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=LE%2BrBbch9MUd7hNxYdSS80oJQAA3%2B8x%2BgL%2FuGxzRmqTFWZEjoNoOlmovkSLdolMcSpzmzc%2BIM5n9ntcNdp7QSo9Kx52xMMh2kw9a97j0gHtZrWRJUG1tVr3LogT7wvddWyFtgQ0%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=10,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9b6003493c17effe-SJC
alt-svc: h3=":443"; ma=86400
Open service 188.114.97.3:443 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 404 Not Found
Date: Tue, 30 Dec 2025 08:02:10 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=5266
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=fIuFc2fTkE6RptEWZV48Q2BAl%2BLcErfTDlNgmakLPUo6Syocn7c%2Bsutg2PTkr3YS01EYn99Ya6ACT4wzs6ooJHR7r726%2Bm%2BS6qRuNjsQtpB4Kb0bHrYsfp8%3D"}]}
Server: cloudflare
CF-RAY: 9b6003501bee8071-AMS
alt-svc: h3=":443"; ma=86400
Open service 2a06:98c1:3120::3:8443 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 522 <none> Date: Tue, 30 Dec 2025 08:02:24 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=19612,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9b60034f5e180f4f-EWR alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 2a06:98c1:3120::3:80 · api-transaction.amldev.it
2025-12-30 08:02
HTTP/1.1 301 Moved Permanently
Date: Tue, 30 Dec 2025 08:02:04 GMT
Content-Length: 0
Connection: close
Location: https://api-transaction.amldev.it/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=HoCRHlLVLyf%2FTnUcc4frRPazwGki7AMV0TdtS8yRk1EERxOcRq42YM8Lk0Vh4XWP7KS3Kjv622brMgpC0kJMldrC%2FU6VWgGBGzGRsfnL5%2FnE3oW1IjaQAseYTusfHeU%2FkHVy9zM%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=7,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9b6003490b968e83-YYZ
alt-svc: h3=":443"; ma=86400
Open service 188.114.97.12:443 · api-transaction.amldev.it
2025-12-23 03:13
HTTP/1.1 404 Not Found
Date: Tue, 23 Dec 2025 03:13:36 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=5,cfOrigin;dur=109
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=pnEthPgNDS5AewjaYS3IB%2BZqsEFJ1H%2FAZ%2FZ9Qk1wbnmpLEJlQTaVCoCc5I%2Fi2nR9Ohe%2B3KhF5bbq9Iw6kp4uK1GluVfSvOySCYES3%2BM4U4ekV%2BAEiEhJ9QI%3D"}]}
Server: cloudflare
CF-RAY: 9b24af1bacdbc48a-YYZ
alt-svc: h3=":443"; ma=86400
Open service 188.114.97.12:443 · api-transaction.amldev.it
2025-12-20 17:39
HTTP/1.1 404 Not Found
Date: Sat, 20 Dec 2025 17:39:43 GMT
Transfer-Encoding: chunked
Connection: close
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=0; includeSubDomains
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=5,cfOrigin;dur=110
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ZxOhfecdtA1l6mdU89jJquYruJdNTxysQDxEMGV5A5F6PmTQLc%2F8TKMaxZNbMY7ZZxV9qvkpJ5%2BTZXK2hd8dozvvxFMmJThEkwT2e8n4%2BLSjNyPXLEFdFFA%3D"}]}
Server: cloudflare
CF-RAY: 9b10ebb50d28e080-YYZ
alt-svc: h3=":443"; ma=86400