cloudflare
tcp/443 tcp/80 tcp/8443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cec7f8772ec7f8772677f2617788558e7b9cc87b43b0e42ad
Found 11 files trough .DS_Store spidering: /.git /app /bootstrap /config /database /public /resources /routes /storage /tests /vendor
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d086d585a086d585a086d585a086d585a
Found 1 files trough .DS_Store spidering: /vendor
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522c42493fd
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab.com/farukasiroglu/ditran-laravel-backend.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Open service 104.21.65.199:443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 200 OK
Date: Mon, 26 Jan 2026 13:13:11 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache, private
Access-Control-Allow-Origin: https://gizembaloglu.com
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, PATCH
Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token
Vary: Origin
Access-Control-Allow-Credentials: true
Set-Cookie: XSRF-TOKEN=eyJpdiI6IjlZRHZLVm1SbmZ5MTYvUWRxOWJJMHc9PSIsInZhbHVlIjoiTUg0amhkTVBya3g1TExsYlc1K2dKWlQwaFVFU2NKbGVFYWpwOElwNWdJUzluSkhZakRPT3lvNGhHTmdERGVOTFI5VWo3ajFvTm1rQ3VxVTBKNHVMSGRDc2RHMGUxM3QvUm50aUUzbWZ6MVBkOHlFM0JtUnBuMVB2SjdmQktYd0EiLCJtYWMiOiI4M2ViZjFmNmUzNTg0NGZkOWU4YzBiNjlkOTQwNWNjNGZmZTkyMTRhOGE0YWViYTc2ZTkyNjBmYTkwNWIwY2ZkIiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:11 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6IjU1d1BJa2ZtempTRXowQ0xmSHZ4OGc9PSIsInZhbHVlIjoiZXl1dWR6OGw4em1FYVRYeFQwMzYvbWNKM01oemtoRTRneXBCTm5LZVE3T0hXQk83NzRKVlhtQUF6c0FzVjNtM1RyVnpFSWFKVGI2WTlIOCtXTVJ6aUVuY0kxdU1QRFNCM2VHOHVVaFhZUFpCMkZsZWd3ZHBxc3dKOWNVaDJMVU8iLCJtYWMiOiJiZDc2NzFmNDQzZWYwMDBhYTY0Y2UyZjU3NzUyYzZlMzk2MGY1MTA0MjBiZjU0NGU3Nzg3NDZlZjkyNjBlNjMxIiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:11 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Access-Control-Max-Age: 1000
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=6VxSvuwfhKLbvt91b1qQnuWhw%2BXokUyKDNKqxaNSzwUeUWYUvLAWeBqI6OJ9KrQ4XVaOkoGfhIipn2knd3zEure6ThG5oYzSEIYOSo20%2FxyFng%3D%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=883
CF-RAY: 9c404421b86ff87d-SIN
alt-svc: h3=":443"; ma=86400
{"Laravel":"10.47.0"}
Open service 172.67.191.246:8443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 521 <none> Date: Mon, 26 Jan 2026 13:13:09 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=49,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9c40441bff2ddbc8-FRA alt-svc: h3=":8443"; ma=86400 error code: 521
Open service 104.21.65.199:8443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 521 <none> Date: Mon, 26 Jan 2026 13:13:10 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=196,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9c40441c8e2ad176-SIN alt-svc: h3=":8443"; ma=86400 error code: 521
Open service 2606:4700:3033::ac43:bff6:8443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 521 <none> Date: Mon, 26 Jan 2026 13:13:09 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=130,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9c40441c3ab66d50-EWR alt-svc: h3=":8443"; ma=86400 error code: 521
Open service 2606:4700:3033::ac43:bff6:80 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 301 Moved Permanently
Date: Mon, 26 Jan 2026 13:13:09 GMT
Content-Length: 0
Connection: close
Location: https://api.gizembaloglu.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=tXvoDTXZF2SNHqPPBdiFq4DiAvvZBX0Pp7laCAhVNkHZ0HmWVj5jw6nqeOZOrerWtPEloFIhDtGG1zqyLtv3GyczGtP9NMnNKbV4EF%2BXArx%2FQ0AXgxOzDgLY%2FsVpaVcV"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=15,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c40441bead40a68-AMS
alt-svc: h3=":443"; ma=86400
Open service 2606:4700:3036::6815:41c7:443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 200 OK
Date: Mon, 26 Jan 2026 13:13:11 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache, private
Access-Control-Allow-Origin: https://gizembaloglu.com
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, PATCH
Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token
Vary: Origin
Access-Control-Allow-Credentials: true
Set-Cookie: XSRF-TOKEN=eyJpdiI6IlhRQlEvQzdueTZkYWMwbU5aby9QRVE9PSIsInZhbHVlIjoiRGtXQXJuRnJaLyttU3VCRTFIc0NTenRzbE5ubHV2STVSTmZNM1J5UDVBdjBneWxMbUowSjc1ZVo1ZGxINTFjN2NtZmt3NEprdWFMTFRJZWdtRnJYNnpBREcycGg2V0gyNnBOWmJHZWVnQTJmaVRCb0dZSkhCSVhndmN6VGhKSlMiLCJtYWMiOiJhMzgyZTc0NmMyODFhM2U0NjE3M2I4MGY1NjFhM2NhM2FjOWQ0ZGRmMGU1MGEwYmE3ZDY2Y2Y4MmQ4YjMxOTIwIiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:11 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6Ilc3eXNqNW5jZ1VieVNhRlpIOC9sWFE9PSIsInZhbHVlIjoiSVIzSzlZSmdHb0tzU2ZTQks4cXVzOElvVzlzUUEwa0RyUUgzbTFMRGhoOWlpd3ZWREhiQ1JsMXNBNWs2VWlIMzZLY295ZmQ2cC9RMUhjNS9TQ0lHTmVTbTFGT1RPMWl1c0F1N1lFMURja2xZMWh3ZFpjY1JyWUN2enM1N09uQS8iLCJtYWMiOiI2OWE5M2FjNjNmZGYwNjMxNzFhZmRhNGQ0MzI4ZWZkMWQ2ZjQ0MTJhNDBjM2VmNGMzNDVjYTk3ZjFiMzJjYmY3IiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:11 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Access-Control-Max-Age: 1000
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=g5J8yXI3tPD8UpVlCgZylKS40Zgaf2qVSj6qVCkR7vii8r9EwAd%2Bi7uaqpYr%2FF6bKC0IWmfuPLT7JwBtq3Zc1G2iWoJ4mvOayZzMVudmHmOGTSIlFeqaF5AZbCYC8yJ2"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=793
CF-RAY: 9c4044217929aacd-YYZ
alt-svc: h3=":443"; ma=86400
{"Laravel":"10.47.0"}
Open service 172.67.191.246:443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 200 OK
Date: Mon, 26 Jan 2026 13:13:10 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache, private
Access-Control-Allow-Origin: https://gizembaloglu.com
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, PATCH
Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token
Vary: Origin
Access-Control-Allow-Credentials: true
Set-Cookie: XSRF-TOKEN=eyJpdiI6Im9RbURGSjFHTDlST2NkL1hCYi9tNlE9PSIsInZhbHVlIjoidEFlMVRacU9vTlB3QW1tWldzeGl6emRoOU50ckNsa1hUN3hoZDVwbkxSWW9MSjdXQVlHUjQrUFNjY2l2cFRrWUZ1ekFkajVGRFRuYXRvalBqcjN4VlBBZzVXRDM1MWR5RUFSN29semx3Mk9YRkJ3STR2T3FuZ29QcmFOQXNrSTUiLCJtYWMiOiI0MzZmYjQ5NGQ3OGU1NGMzNGY0NWNlOWNlNTk5ZTI1YTQyYTJhYjY2YTU0OGNlNzVkZjM5NTJhY2UwZjViYWE2IiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:10 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6ImhPWHZPTytlaGpvY1JKb1kveFIvT0E9PSIsInZhbHVlIjoieitYQVBoZlZIeUlxNWNqdWRZQ3c4T2J0TVlYUHQvaERoN1ZCekR4dFloZHJMMFp5QmVpNE96SHJ4VXVyNk90eDhNKzZDeis0M1p6L0xZbG1Ra1UzVWcxeGxUbWlWTkorVXovbnBMY3pkRkdvTjUvRFdjUjVYbE9EbThxajVDZU0iLCJtYWMiOiI0ODk5OTY3OWFkODNmNTIyZTY3ZDhkY2Q4NzU3MTg3ZDdjMGNlY2MxY2FhOGNhMWMyNTQ1NjUxZWQ0MTkzNDgyIiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:10 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Access-Control-Max-Age: 1000
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=VMtf17J7xRvp0o%2F1OeOn0AkQ3SGlbNMg2z6jci6z43aPTj6RExo2wnajc5ZhRKEabyUSpHgDFPaBwYHZBnsJiaqnBVWj7rNQosnsdOHYx7XYBFh9"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=373
CF-RAY: 9c404420bb24f51f-FRA
alt-svc: h3=":443"; ma=86400
{"Laravel":"10.47.0"}
Open service 2606:4700:3036::6815:41c7:8443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 521 <none> Date: Mon, 26 Jan 2026 13:13:09 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=67,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9c40441b990c974f-FRA alt-svc: h3=":8443"; ma=86400 error code: 521
Open service 104.21.65.199:80 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 301 Moved Permanently
Date: Mon, 26 Jan 2026 13:13:09 GMT
Content-Length: 0
Connection: close
Location: https://api.gizembaloglu.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Dq0IHSQ6vLDIh2r4GrRKXrhTFasr3gQJ9U24f3szGe7vUj1YyQ0RzpUrpQtr%2BbvY8OwhP0T4WECFvEuxGvVDcj0BepT2m0KtBLcnv9TgS6kyZw%3D%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=31,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c40441b1e979a3b-FRA
alt-svc: h3=":443"; ma=86400
Open service 2606:4700:3033::ac43:bff6:443 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 200 OK
Date: Mon, 26 Jan 2026 13:13:11 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache, private
Access-Control-Allow-Origin: https://gizembaloglu.com
Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT, PATCH
Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token
Vary: Origin
Access-Control-Allow-Credentials: true
Set-Cookie: XSRF-TOKEN=eyJpdiI6IlRmR0hLVEpYdHBFN0xadDBKQWhtYnc9PSIsInZhbHVlIjoiRHlvalZKcTNxM3VGNHIyQjZwc0d1MGxnOFdqZTRiRWp1eVl6UDBrOEVPZ0tEV1NoWTlubEZtdWVFbk1qVTZOMElhaUNSWDc1elg2OW9KU2QrZXM3ODV0ZXlsR3RjYTZKN2lidDlERFN3dWh0aUFpWkh4MGxaT1liRWlRYlhYY24iLCJtYWMiOiI3Y2NkYWMxM2JiMWI1OTRiNDUyOTdkNWI0MmFmYWE3NmZjYjYyOTA1ODhiYWQ3Yzk0Y2JmOWMyNWU1ZGY5MzM5IiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:11 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6IndXSW9QQWVsSlc1VVo3ZTJHSGxhdmc9PSIsInZhbHVlIjoiS3A4QmZmRHJpclQ3SWhxeUZqOEVWbEVEN2o3OUVLVEZWNEExNllsLytPbjVNSU9tYzRiT2JLN3duZ0FJT1J3VXpHM2l4TUZhQ0dTSXloQ05saFFRbTF0TTFZKzZpdWJxMGlpSytCWFZWK2Z2eTBsYnNDbEkyWFlDVi8rZDIwNE8iLCJtYWMiOiI2NzAzNTQyNWVkOWFlOWJmYzg5MDI5M2FkNDkzM2IyOWM1YzE3MTFjNGRlOTUxZjZlMGI1ZTFiN2E2NjE5ZGY4IiwidGFnIjoiIn0%3D; expires=Mon, 26 Jan 2026 15:13:11 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Access-Control-Max-Age: 1000
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=YV7xWS3Q50k1OWO%2BXYtz%2BDy6XKRReVAOZVnqE4A8xDtYQbN7rAiK4ehZp8zKwQEHkcQDEYuE1i9zGESz2KMUZ6%2F40y6G2IRDC8AIErXFzpy6t%2BUZO1NgcsIPBq%2BrTnpJ"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=680
CF-RAY: 9c404420fbb41f47-EWR
alt-svc: h3=":443"; ma=86400
{"Laravel":"10.47.0"}
Open service 172.67.191.246:80 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 301 Moved Permanently
Date: Mon, 26 Jan 2026 13:13:09 GMT
Content-Length: 0
Connection: close
Location: https://api.gizembaloglu.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=mUBQkfLdwJ9E3x6BoV6Rcv6UKpKiL9XKoJhHrK9EcqeVRalIXzbEqtwQzMC%2BJfpCbDUX5FI0Hhh2mQDtyer6ZOHmXtZ5UlIHy0CWIYso0BKnZRJa"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=13,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c40441aec3ed391-FRA
alt-svc: h3=":443"; ma=86400
Open service 2606:4700:3036::6815:41c7:80 · api.gizembaloglu.com
2026-01-26 13:13
HTTP/1.1 301 Moved Permanently
Date: Mon, 26 Jan 2026 13:13:09 GMT
Content-Length: 0
Connection: close
Location: https://api.gizembaloglu.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=1i6Nu7PLVVeYv12d0Y8HsdpG%2FHHPq%2FgUx0gTDipATKKK%2FZiN17XyarsOvKXqzKmUKoIQz7RwcKJE6bs0AtXCZcCta9IVPUyaWj3kbkJqmDFOEYqbjV7B3IQaQsnqlraG"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=8,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c40441a9b140c18-LHR
alt-svc: h3=":443"; ma=86400