Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733f93b77d9b240ac757bb18cb8317310bd8
Found 10 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Severity: low
Fingerprint: 5f32cf5d6962f09cec7f8772ec7f8772159855a0eb5bbe5662f82d32553b6d83
Found 11 files trough .DS_Store spidering: /404.html /422.html /assets /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Open service 75.101.184.39:443 · app.blkstylist.com
2026-01-09 18:33
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.blkstylist.com/organizations/blkstylist/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=6DhWHK4csz7%2Fw57TQ6RYtJON4KjKarniXXewIx5R70k%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767983632"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=6DhWHK4csz7%2Fw57TQ6RYtJON4KjKarniXXewIx5R70k%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767983632"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 26d2b448-230b-0970-3774-23f9be414d0b
X-Runtime: 0.009649
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 18:33:52 GMT
Connection: close
Open service 75.101.184.39:443 · app.blkstylist.com
2026-01-02 06:30
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.blkstylist.com/organizations/blkstylist/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mvjU2SxWWKR%2BDHWbuoq3lgvuV0XR9j9E3pd9zbA5vF4%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767335422"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mvjU2SxWWKR%2BDHWbuoq3lgvuV0XR9j9E3pd9zbA5vF4%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767335422"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 8d350f99-3663-0ad5-d8c1-0031251faab5
X-Runtime: 0.008905
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 06:30:22 GMT
Connection: close
Open service 75.101.184.39:443 · app.blkstylist.com
2025-12-30 11:27
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.blkstylist.com/organizations/blkstylist/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=W%2F5r5C4Bvi4VS7BOrAp1RZnvIxTXZaeAlXRhaisrVLg%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767094079"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=W%2F5r5C4Bvi4VS7BOrAp1RZnvIxTXZaeAlXRhaisrVLg%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767094079"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 67f31eb6-f910-1a1a-ec18-33ca94d26512
X-Runtime: 0.015583
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 11:27:59 GMT
Connection: close
Open service 75.101.184.39:443 · app.blkstylist.com
2025-12-22 12:19
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.blkstylist.com/organizations/blkstylist/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3%2FGww%2BAO0Ty5Hrn%2F%2FAuhtZlT%2BW9NJy3rSeOIOrdBuWk%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766405960"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3%2FGww%2BAO0Ty5Hrn%2F%2FAuhtZlT%2BW9NJy3rSeOIOrdBuWk%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766405960"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 9fdc9c73-e176-3a95-7064-54652527e814
X-Runtime: 0.010395
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 12:19:20 GMT
Connection: close
Open service 75.101.184.39:443 · app.blkstylist.com
2025-12-20 11:30
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.blkstylist.com/organizations/blkstylist/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=89PvA8kj6pYZEiug76BMdKb0JNjPH0oMG7H15G5m%2Fxw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766230218"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=89PvA8kj6pYZEiug76BMdKb0JNjPH0oMG7H15G5m%2Fxw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766230218"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 6acd4452-6558-df35-83ff-57429b43dcf6
X-Runtime: 0.012173
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 11:30:18 GMT
Connection: close