Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: high
Fingerprint: 5f32cf5d6962f09c39aac35b39aac35b92705af73eecf6fbb17db4ac4119df6e
Found 14 files trough .DS_Store spidering: /404.html /422.html /500.html /apple-touch-icon-precomposed.png /apple-touch-icon.png /assets /assets/application-74b5a5706b31e5d0924e90d4de47ca5056e23f6c4c4c95eba05fed880fb8645f.css /assets/application-74b5a5706b31e5d0924e90d4de47ca5056e23f6c4c4c95eba05fed880fb8645f.css.gz /assets/application-7662428b2ed0af6bb03578f2703da6e3c56a7b5565ed0b758a84e5877a82b0d0.css /assets/application-7662428b2ed0af6bb03578f2703da6e3c56a7b5565ed0b758a84e5877a82b0d0.css.gz /assets/application-a51a53658dfaa975cb4363f51d14bccf24d66c3d90c2186bf834c157151c4bd1.js.gz /assets/fonts /favicon.ico /robots.txt
Open service 54.204.238.15:443 · api.slategolfapps.com
2025-12-30 04:33
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://slategolfapps.com
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=tVPeajru2zRDih5WWGQoukg%2Fq3y6EBxvmBA0OSJ6S2E%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767069226"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=tVPeajru2zRDih5WWGQoukg%2Fq3y6EBxvmBA0OSJ6S2E%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767069226"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: ba2ee0c7-233c-ba6d-7aad-062489b86d98
X-Runtime: 0.002018
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 04:33:46 GMT
Content-Length: 91
Connection: close
<html><body>You are being <a href="https://slategolfapps.com">redirected</a>.</body></html>