Apache
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522eb0f1831
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = https://github.com/Financierbuddy/answer24_backend.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "production"] remote = origin vscode-merge-base = origin/production github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" merge = refs/heads/production github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12"
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522eb0f1831
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = https://github.com/Financierbuddy/answer24_backend.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "production"] remote = origin vscode-merge-base = origin/production github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12" merge = refs/heads/production github-pr-owner-number = "Financierbuddy#answer24_backend#12" github-pr-owner-number = "Financierbuddy#answer24_backend#12"
Open service 162.241.121.210:443 · www.api.cretehost.com
2026-01-23 09:56
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 09:56:29 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6Ino0cmYxcUVpK3hHUFRzWEVISHNzZkE9PSIsInZhbHVlIjoia29CcUxCQ3NDU0Y3ejJiU2ljMDNwYzN4SVVONEcwbUcyRnUrK29kQmRRWG5sRlZldXdacTZHZ2gzRHZmWEZsVkdlMk95SWtCQnI0anNvZEFLbk5PeFFuVktxcnhLTjBQNWttRWFRTVhhOURidE9OcmFKN3llVEYxVXg0Ny8zSUQiLCJtYWMiOiI1NDkzMmEyMGIxNTUyMTU4NTY3NGU4NTEwNGEwMmZiNDIyMjBiMjYxOTQwNGRhZGFmZDExOGU3N2VlZWQwNTJjIiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 11:56:29 GMT; Max-Age=7200; path=/; secure; samesite=lax Set-Cookie: laravel_session=eyJpdiI6ImRoZ0c2MmtoQjVCYTEwZCtjK1kwdFE9PSIsInZhbHVlIjoiRm1nVU9PL0FXYkx5VWJGM3FmdUhYbWZiZFlqWjl3Qis5K3ZLMStyYkFvbkJFVTlaWThzNDEyQnVPdDI5b29iY1NNMkM3SzU5TXM1dStUMXFuOWl5K1JnTTczaXdsNVZuVUs1L3M0R0N4YlVyUkZHUFdwc0YrZVNGTEZ6UFBxeXEiLCJtYWMiOiJmNDE4ZTRlZDQ4ZmRiODZjMjdkOWM0YWEyNTdjOWI5ZGY1MWJjYzBmY2JiZmY4YmJiZGZjNTZmMzkxZWViYWZhIiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 11:56:29 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 162.241.121.210:443 · www.api.cretehost.com
2026-01-23 04:55
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 04:55:09 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6IlcxN1lYMTdjM01sUjNIaEJMV2dsaXc9PSIsInZhbHVlIjoiMVpiUnBsQWR1MGJ0N25GWkdNM1o3UTM4VzE0MGRQdzU3d2FpbFNkTXB1OE10QmxmY3c0RG10eE9qRWxPZnZwMkkwbkhzc3lVMHRTSTgxckxkODcxMFVwWCs1dEpTYmRPb0Rjc0x2ZVhtT2ROMGhkRVFGTHR0Z0VGRDVVaWdqL3MiLCJtYWMiOiI0ZmQyNDM0ZGRhZWQ4MjJiODM4NDEwNTM3MTlmMDFjMjA0N2Q2ODVhNDE1ZGY4NDlkMjViNTFjMGExNDc0ZmJiIiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 06:55:09 GMT; Max-Age=7200; path=/; secure; samesite=lax Set-Cookie: laravel_session=eyJpdiI6IjQyN0VMOFdoZUl0TzNUejJjZ21SMUE9PSIsInZhbHVlIjoiMzNMTmU1RTJleTMxczdRb1JZRGNtYWVwdDlwTnZOY0R2R0tWaEVLM2tTZmpLcE91bWRIbFlOQ2VrSGk3Q29lb3ZVaTlrMW1nTkpvc1Z1eUQ2N3daOUVtenJFQkZLL0VoQ1paOXJzMHJtZ01UWFZVV0VBd0U3T3VCNlJyVHNtL1MiLCJtYWMiOiJjNmU4MTM5MzQ1OTI4MDAxMWQ1YzVmNTE4YWU4ZjMwNjM4NjYwYmM1MTlkMTJmMThiMjMzMzhmOTlkMTUxOGFhIiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 06:55:09 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 162.241.121.210:443 · www.api.cretehost.com
2026-01-10 00:39
HTTP/1.1 200 OK Date: Sat, 10 Jan 2026 00:39:17 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6IjllSGgxQzNSMStKTmR5WVlpSzdOVmc9PSIsInZhbHVlIjoiUDJudTg1SEllTGlsb1NTQklDZGdlTkhPUGluQjArbEtEbnllOVNrMnBmMnJwOU9Ick5DYzd4aFFlMWx1Zmh1bFZVZnViRnY5dlZBSElUUFBQaUVHRkhrMjQ4bWNZeVRJRDVueFc0dlltT0Njelp3RVA1OERoOW1tUngrTFQrY0giLCJtYWMiOiIxMWVhMzBkYmFlNGJjM2U1ZGQ0OWVhYzMyOTNiNzFkZTM0N2IwODgxYTZmOGE5ZGQ3NTI0OTE2NGQ0M2M0YTU5IiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 02:39:17 GMT; Max-Age=7200; path=/; secure; samesite=lax Set-Cookie: laravel_session=eyJpdiI6ImE0cEpLYkVrdU95QU40OEZIMk1KNmc9PSIsInZhbHVlIjoiSmlIYWdBTjlOQ1MxaTdUTnh6SHRwbUk0ZFhUYkVLZXdCcXFPK3MyTUpkT0hKMEJic2NidVFhNFI4R3BHa1I1cFNidlBsM0h3Y0R0Z0xJVk5YeVZoaE5xbnBQYXpiV1dLeDZ6VGp5aExUVks2cWxhYVVqRXdJZFZFOWxsd3JHSEciLCJtYWMiOiI0YzkxNmMwYWVkNjdlOGZmZWRmZmJhNTA1MzdiMDcwOGEwNTU0ZGI2MzM3YzBmYTFmYzVkZDY4OWE5NjU4NzAzIiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 02:39:17 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8