Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3dbd2b7f1573b4d73a7c1b92c652b6f18d3c5d560
GraphQL introspection enabled at /graphql Types: 34 (by kind: ENUM: 2, OBJECT: 26, SCALAR: 6) Operations: - Query: Query | fields: currencyWithdrawals, currentUser, myClusters, myHardwareClusters, test - Mutation: Mutation | fields: createUser, resendVerificationCode, signinUser, startTrial, verifyPhone Directives: deprecated, include, skip (total: 3)
Open service 3.33.161.45:443 · api.krambu.com
2026-01-10 00:13
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 14
Content-Type: application/json; charset=utf-8
Date: Sat, 10 Jan 2026 00:13:29 GMT
Etag: W/"e-xIoDZCQm5+glU5sPa2BU1rDG6Mc"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=rYfrAY68MClSai%2BIomiCuGGbX92GAC2s4Jsu5t5Owpo%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768004009"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=rYfrAY68MClSai%2BIomiCuGGbX92GAC2s4Jsu5t5Owpo%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768004009"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
{"hello":true}
Open service 3.33.161.45:443 · api.krambu.com
2026-01-02 20:08
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 14
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 20:08:26 GMT
Etag: W/"e-xIoDZCQm5+glU5sPa2BU1rDG6Mc"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GfEN%2BDB9FZylPfoJN8RPDVPl194z4VxvZvh0B%2BXNDdE%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1767384506"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GfEN%2BDB9FZylPfoJN8RPDVPl194z4VxvZvh0B%2BXNDdE%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1767384506"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
{"hello":true}
Open service 3.33.161.45:443 · api.krambu.com
2025-12-23 08:30
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 14
Content-Type: application/json; charset=utf-8
Date: Tue, 23 Dec 2025 08:30:13 GMT
Etag: W/"e-xIoDZCQm5+glU5sPa2BU1rDG6Mc"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=IUgykjCHVQI6759xTvZ7BREGgYH32GcjVkyVbD%2FWaUE%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1766478613"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=IUgykjCHVQI6759xTvZ7BREGgYH32GcjVkyVbD%2FWaUE%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1766478613"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
{"hello":true}
Open service 3.33.161.45:443 · api.krambu.com
2025-12-21 06:49
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 14
Content-Type: application/json; charset=utf-8
Date: Sun, 21 Dec 2025 06:49:13 GMT
Etag: W/"e-xIoDZCQm5+glU5sPa2BU1rDG6Mc"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7KfmWTofsoSklO%2F6%2FWlvzURfF5TdMkSbRfqDkv6JNmo%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1766299753"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7KfmWTofsoSklO%2F6%2FWlvzURfF5TdMkSbRfqDkv6JNmo%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1766299753"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
{"hello":true}
Open service 3.33.161.45:443 · api.krambu.com
2025-12-19 01:46
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 14
Content-Type: application/json; charset=utf-8
Date: Fri, 19 Dec 2025 01:46:43 GMT
Etag: W/"e-xIoDZCQm5+glU5sPa2BU1rDG6Mc"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=NIT19SY845t9xPMF8mC2l1dBJ7yqFqcVBPuOMX%2B3aBY%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1766108803"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=NIT19SY845t9xPMF8mC2l1dBJ7yqFqcVBPuOMX%2B3aBY%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1766108803"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
{"hello":true}