cloudflare
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d601ea5f2ae301dda87301dda87301dda87301dda87
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths: POST /Leads POST /api/v1/LeadQueue/webForms
Open service 104.18.0.230:443 · api.crm.nextech.com
2026-01-08 23:36
HTTP/1.1 301 Moved Permanently Date: Thu, 08 Jan 2026 23:36:40 GMT Content-Length: 0 Connection: close CF-RAY: 9baf84b539160b30-AMS Location: index.html Set-Cookie: ARRAffinity=05d68cc9b1c2238be704eb8dbad1df2c2dbcfb1dca7286a3610a47e6bb0ec373;Path=/;HttpOnly;Secure;Domain=api.crm.nextech.com Set-Cookie: ARRAffinitySameSite=05d68cc9b1c2238be704eb8dbad1df2c2dbcfb1dca7286a3610a47e6bb0ec373;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.crm.nextech.com Set-Cookie: __cf_bm=_0FAxRZCYzGQWweic4hLWvsNQZQz6S8kWOFxd45qAP4-1767915400-1.0.1.1-R7hp8UJnuL6tq3P.d5OwJ5Q_quNdZSfi50Aja2UuslJbBUlziQzguc0HNEVi.ne_bjdqPDWXVlVQlqmEOaXNIdlDYy5at9TiIAVuZfnHG2I; path=/; expires=Fri, 09-Jan-26 00:06:40 GMT; domain=.nextech.com; HttpOnly; Secure; SameSite=None Request-Context: appId=cid-v1:7c15bb79-54ff-498f-b769-2f6aa8c97946 X-Powered-By: ASP.NET cf-cache-status: DYNAMIC Server: cloudflare
Open service 104.18.0.230:443 · api.crm.nextech.com
2026-01-02 02:20
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 02:20:17 GMT Content-Length: 0 Connection: close CF-RAY: 9b76c6bf1c5c3641-FRA Location: index.html Set-Cookie: ARRAffinity=05d68cc9b1c2238be704eb8dbad1df2c2dbcfb1dca7286a3610a47e6bb0ec373;Path=/;HttpOnly;Secure;Domain=api.crm.nextech.com Set-Cookie: ARRAffinitySameSite=05d68cc9b1c2238be704eb8dbad1df2c2dbcfb1dca7286a3610a47e6bb0ec373;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.crm.nextech.com Set-Cookie: __cf_bm=fy1TC2f0MU.ZIMHBLePqvFNMy4jby79x3P_qve.1aok-1767320417-1.0.1.1-7u5KUJP5xIyUJ_buI33FuUbWqablBNxD8NT5EPCHPtKih1cEHicNLxC1QyhdQYGdj_Pq8R4tCxMCtao8MS6_SNhl3hJOWSfxukxDZ33Wk84; path=/; expires=Fri, 02-Jan-26 02:50:17 GMT; domain=.nextech.com; HttpOnly; Secure; SameSite=None Request-Context: appId=cid-v1:7c15bb79-54ff-498f-b769-2f6aa8c97946 X-Powered-By: ASP.NET cf-cache-status: DYNAMIC Server: cloudflare
Open service 104.18.0.230:443 · api.crm.nextech.com
2025-12-23 05:48
HTTP/1.1 301 Moved Permanently Date: Tue, 23 Dec 2025 05:48:55 GMT Content-Length: 0 Connection: close CF-RAY: 9b25929a7a6cfffb-AMS Location: index.html Set-Cookie: ARRAffinity=e37f4405361523875c4c355a795e917ae7821a1a0d0cabe60b5b39fae7fd5264;Path=/;HttpOnly;Secure;Domain=api.crm.nextech.com Set-Cookie: ARRAffinitySameSite=e37f4405361523875c4c355a795e917ae7821a1a0d0cabe60b5b39fae7fd5264;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.crm.nextech.com Set-Cookie: __cf_bm=jSTvxyqkbVp2re.wVrJGtbdmxTWviDDPA00w90mun4E-1766468935-1.0.1.1-slZ_tyYdHRJ7aoCZhGVI29vghZ.tplF.CIAiNFai5m.h2.lhMjlH7DYeJeVTWUx7.XrFOvBkSrg979w3uqgzE1MLHDw93AQelFwVdZRh1s8; path=/; expires=Tue, 23-Dec-25 06:18:55 GMT; domain=.nextech.com; HttpOnly; Secure; SameSite=None Request-Context: appId=cid-v1:7c15bb79-54ff-498f-b769-2f6aa8c97946 X-Powered-By: ASP.NET cf-cache-status: DYNAMIC Server: cloudflare
Open service 104.18.0.230:443 · api.crm.nextech.com
2025-12-21 00:59
HTTP/1.1 301 Moved Permanently Date: Sun, 21 Dec 2025 00:59:45 GMT Content-Length: 0 Connection: close CF-RAY: 9b1370463804001a-LHR Location: index.html Set-Cookie: ARRAffinity=a0fe454dc2b6bb16ebb059fc3911bfb190ecd766bc7d5d1b9782ca8b4c5f9561;Path=/;HttpOnly;Secure;Domain=api.crm.nextech.com Set-Cookie: ARRAffinitySameSite=a0fe454dc2b6bb16ebb059fc3911bfb190ecd766bc7d5d1b9782ca8b4c5f9561;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.crm.nextech.com Set-Cookie: __cf_bm=Tqq4HDy4SSlbyb2qiYePox0iGyiqNZpqWVAteeflH1U-1766278785-1.0.1.1-DNZIRA.V_MColPnBWPLRcUy86Feh87i8YHnXLfl8U6y6xHDN5vt.S6OdK04e3e0or3uGVPNgl5Lv2DXiUVNo4QCotVcOKRhzh1akkMrJnsU; path=/; expires=Sun, 21-Dec-25 01:29:45 GMT; domain=.nextech.com; HttpOnly; Secure; SameSite=None Request-Context: appId=cid-v1:7c15bb79-54ff-498f-b769-2f6aa8c97946 X-Powered-By: ASP.NET cf-cache-status: DYNAMIC Server: cloudflare
Open service 104.18.0.230:443 · api.crm.nextech.com
2025-12-19 05:56
HTTP/1.1 301 Moved Permanently Date: Fri, 19 Dec 2025 05:56:02 GMT Content-Length: 0 Connection: close CF-RAY: 9b04a78b9eb9dc62-FRA Location: index.html Set-Cookie: ARRAffinity=a857e6a3794e655e87bed831b640d66a4333c77bf5594bb280e160d03f6f1828;Path=/;HttpOnly;Secure;Domain=api.crm.nextech.com Set-Cookie: ARRAffinitySameSite=a857e6a3794e655e87bed831b640d66a4333c77bf5594bb280e160d03f6f1828;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.crm.nextech.com Set-Cookie: __cf_bm=3CfGPAdsnLxhyqoYYXw.LfBLPwTQ0g.OOXupUzUsJuU-1766123762-1.0.1.1-JZds1Mio_CK8fRucPuY0IQyhG.9A21wXRoW_4S6_NwQ.dga8ViLMTx0Ckwk9xuHxE7cnCp8kzuTMj0BxH1je11OEPG9l7EZ3zCmj0khqLow; path=/; expires=Fri, 19-Dec-25 06:26:02 GMT; domain=.nextech.com; HttpOnly; Secure; SameSite=None Request-Context: appId=cid-v1:7c15bb79-54ff-498f-b769-2f6aa8c97946 X-Powered-By: ASP.NET cf-cache-status: DYNAMIC Server: cloudflare