BunnyCDN-DE1-722
tcp/443 tcp/80
BunnyCDN-DE1-864
tcp/443
BunnyCDN-DE1-874
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36f496548573beeecdadfd76e5ba2af61a8fa12c1
GraphQL introspection enabled at /graphql Types: 206 (by kind: ENUM: 2, INPUT_OBJECT: 45, OBJECT: 149, SCALAR: 9, UNION: 1) Operations: - Query: Query | fields: Blog, Blog_aggregated, Blog_by_id, Property_Statuses_Property_2, Property_Statuses_Property_2_by_id - Mutation: Mutation | fields: create_Blog_item, create_Blog_items, create_comments_item, create_comments_items, update_Blog_items Directives: deprecated, include, skip (total: 3) Readable stores: 0
Open service 138.199.37.230:443 · api.osatropicalproperties.com
2026-01-10 01:41
HTTP/1.1 302 Found Date: Sat, 10 Jan 2026 01:41:48 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Server: BunnyCDN-DE1-864 CDN-PullZone: 1300875 CDN-RequestCountryCode: SG Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Cache-Control: no-cache Location: ./admin Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io;media-src 'self' https://cdn.directus.io;connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 01/10/2026 01:41:48 CDN-EdgeStorageId: 1078 CDN-RequestId: 3682f8e2811a5a93e584e0ae8c081ade CDN-Cache: MISS CDN-Status: 302 CDN-RequestTime: 0 Found. Redirecting to ./admin
Open service 2400:52e0:1e00::722:1:443 · api.osatropicalproperties.com
2026-01-06 22:01
HTTP/1.1 302 Found Date: Tue, 06 Jan 2026 22:01:47 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Server: BunnyCDN-DE1-722 CDN-PullZone: 1300875 CDN-RequestCountryCode: US Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Cache-Control: no-cache Location: ./admin Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io;media-src 'self' https://cdn.directus.io;connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 01/06/2026 22:01:47 CDN-EdgeStorageId: 1078 CDN-RequestId: cc0dd58b2a4d5e6deceb514132cb9d55 CDN-Cache: MISS CDN-Status: 302 CDN-RequestTime: 0 Found. Redirecting to ./admin
Open service 138.199.37.232:443 · api.osatropicalproperties.com
2026-01-06 22:01
HTTP/1.1 302 Found Date: Tue, 06 Jan 2026 22:01:47 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Server: BunnyCDN-DE1-874 CDN-PullZone: 1300875 CDN-RequestCountryCode: IN Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Cache-Control: no-cache Location: ./admin Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io;media-src 'self' https://cdn.directus.io;connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 01/06/2026 22:01:47 CDN-EdgeStorageId: 1078 CDN-RequestId: ade6cf58ed86d44a6b024e7b89da1c9b CDN-Cache: MISS CDN-Status: 302 CDN-RequestTime: 0 Found. Redirecting to ./admin
Open service 138.199.37.232:80 · api.osatropicalproperties.com
2026-01-06 22:01
HTTP/1.1 301 Moved Permanently Date: Tue, 06 Jan 2026 22:01:47 GMT Content-Type: text/html Content-Length: 166 Connection: close Server: BunnyCDN-DE1-874 CDN-PullZone: 1300875 CDN-RequestCountryCode: US Location: https://api.osatropicalproperties.com/ CDN-RequestId: daea206c8dc00c1b238080099995fcf6 CDN-RequestTime: 0 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>openresty</center> </body> </html>
Open service 2400:52e0:1e00::722:1:80 · api.osatropicalproperties.com
2026-01-06 22:01
HTTP/1.1 301 Moved Permanently Date: Tue, 06 Jan 2026 22:01:47 GMT Content-Type: text/html Content-Length: 166 Connection: close Server: BunnyCDN-DE1-722 CDN-PullZone: 1300875 CDN-RequestCountryCode: US Location: https://api.osatropicalproperties.com/ CDN-RequestId: 262351252bf9a932333cdcf0254fdf7b CDN-RequestTime: 0 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>openresty</center> </body> </html>
Open service 138.199.37.230:443 · api.osatropicalproperties.com
2026-01-03 00:28
HTTP/1.1 302 Found Date: Sat, 03 Jan 2026 00:28:02 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Server: BunnyCDN-DE1-864 CDN-PullZone: 1300875 CDN-RequestCountryCode: US Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Cache-Control: no-cache Location: ./admin Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io;media-src 'self' https://cdn.directus.io;connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 01/03/2026 00:28:02 CDN-EdgeStorageId: 1078 CDN-RequestId: 69f6f13c5c8a2ca67b416c0cdda0e415 CDN-Cache: MISS CDN-Status: 302 CDN-RequestTime: 0 Found. Redirecting to ./admin
Open service 138.199.37.230:443 · api.osatropicalproperties.com
2025-12-21 09:43
HTTP/1.1 302 Found Date: Sun, 21 Dec 2025 09:43:40 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Server: BunnyCDN-DE1-864 CDN-PullZone: 1300875 CDN-RequestCountryCode: NL Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Cache-Control: no-cache Location: ./admin Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io;media-src 'self' https://cdn.directus.io;connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/21/2025 09:43:40 CDN-EdgeStorageId: 1078 CDN-RequestId: 7001f8713c38b4bc19e4ecaeaf554ec8 CDN-Cache: MISS CDN-Status: 302 CDN-RequestTime: 0 Found. Redirecting to ./admin
Open service 138.199.37.230:443 · api.osatropicalproperties.com
2025-12-19 11:08
HTTP/1.1 302 Found Date: Fri, 19 Dec 2025 11:08:34 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Server: BunnyCDN-DE1-864 CDN-PullZone: 1300875 CDN-RequestCountryCode: US Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Cache-Control: no-cache Location: ./admin Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io;media-src 'self' https://cdn.directus.io;connect-src 'self' https://*;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/19/2025 11:08:34 CDN-EdgeStorageId: 1078 CDN-RequestId: 14ca8600140a328430b35b82abfa8591 CDN-Cache: MISS CDN-Status: 302 CDN-RequestTime: 0 Found. Redirecting to ./admin