AmazonS3
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: high
Fingerprint: 5f32cf5d6962f09c7b6beb587b6beb5857246f95ffa1d911867f517506389c7e
Found 57 files trough .DS_Store spidering: /.well-known /account-settings /actions /appointments /assets /browser /campaigns /care-plans /carium-feedback /challenges /communications /dashboard /devices /devices/connect /devices/order /error-pages /form /forms /get-app /get-provider-app /groups /health-feed /help-center /images /images/email-templates /images/webapp /join /journal /learning /legal /live-chat /manage-organization /medications /messages /notes /notifications /nutrition /organization-dashboard /organization-todos /participants /pathways /patients /reset-password /shield /sign-in /sign-up /sources /storybook /survey /surveys /swagger /test-results /todos /translations /verify-email /video /video-chat
Severity: high
Fingerprint: 5f32cf5d6962f09cecc85b04ecc85b04003171c9ad5e70154ff7c16923967715
Found 53 files trough .DS_Store spidering: /.well-known /account-settings /actions /appointments /assets /browser /campaigns /care-plans /carium-feedback /challenges /communications /dashboard /devices /error-pages /form /forms /get-app /get-provider-app /groups /health-feed /help-center /images /join /journal /learning /legal /live-chat /manage-organization /medications /messages /notes /notifications /nutrition /organization-dashboard /organization-todos /participants /pathways /patients /reset-password /shield /sign-in /sign-up /sources /storybook /survey /surveys /swagger /test-results /todos /translations /verify-email /video /video-chat
Severity: high
Fingerprint: 5f32cf5d6962f09c910c508a910c508a1e2cc5eff7d9ca0b91ee3c2b72a97ca1
Found 55 files trough .DS_Store spidering: /.well-known /account-settings /actions /appointments /assets /browser /campaigns /care-plans /carium-feedback /challenges /communications /dashboard /devices /devices/connect /devices/order /error-pages /form /forms /get-app /get-provider-app /groups /health-feed /help-center /images /join /journal /learning /legal /live-chat /manage-organization /medications /messages /notes /notifications /nutrition /organization-dashboard /organization-todos /participants /pathways /patients /reset-password /shield /sign-in /sign-up /sources /storybook /survey /surveys /swagger /test-results /todos /translations /verify-email /video /video-chat
Severity: high
Fingerprint: 5f32cf5d6962f09c75d69a7675d69a76ce06aa035003aebf0f0bfa9f5bcd1693
Found 51 files trough .DS_Store spidering: /.well-known /account-settings /actions /appointments /assets /browser /campaigns /care-plans /carium-feedback /challenges /communications /communications-beta /dashboard /devices /error-pages /form /get-app /get-provider-app /groups /health-feed /help-center /images /join /journal /learning /legal /live-chat /manage-organization /medications /messages /notes /nutrition /organization-dashboard /organization-todos /participants /patients /reset-password /shield /sign-in /sign-up /sources /specialists /storybook /survey /surveys /swagger /test-results /todos /verify-email /video /video-chat
Open service 18.66.192.23:443 · app.carium.com
2026-01-09 18:34
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 352 Connection: close Date: Fri, 09 Jan 2026 18:34:18 GMT Server: AmazonS3 Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block X-Powered-By: Coffee from 2nd St X-Frame-Options: deny Location: /sign-in/ X-Cache: Hit from cloudfront Via: 1.1 badff53d2116a4b3d32a2dd1eb918a48.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: 3Wz1h3mLhsjZeX9R2RDQrX2vzg7NsthRZC7NByHS9ykT-q8JLba-xQ== Age: 2 Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <h1>404 Not Found</h1> <ul> <li>Code: NoSuchKey</li> <li>Message: The specified key does not exist.</li> <li>Key: web-ui/index.html</li> <li>RequestId: KDFRJDWB6QNX6DX8</li> <li>HostId: t8IQbT67rTZ+vag8vER92VUIhJK+C14uXSkeG2+FviCp7WTY+dRSIuFoKOKsMe3DRFba1riFtL4=</li> </ul> <hr/> </body> </html>
Open service 18.66.192.23:443 · app.carium.com
2026-01-02 21:50
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 372 Connection: close Date: Fri, 02 Jan 2026 21:50:11 GMT Server: AmazonS3 Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block X-Powered-By: Coffee from 2nd St X-Frame-Options: deny Location: /sign-in/ X-Cache: Hit from cloudfront Via: 1.1 32162aed20605276097da109dc97c5b0.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: iKm2TN7hFpifl6PWxuLVWK7YOTkbPVlpQ7ywvif_Kb-Mv2R-lqT-WQ== Age: 1 Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <h1>404 Not Found</h1> <ul> <li>Code: NoSuchKey</li> <li>Message: The specified key does not exist.</li> <li>Key: web-ui/index.html</li> <li>RequestId: BDV6TCR3H3SDJ8ZQ</li> <li>HostId: /FnnbbQmFc3itKpDDWVOiBSGGEyn9rZWm2xxBEeZDW8yqNHRP8JR8ImAuATyMQ+gnoD8BPLOusounQ4qmFDJjYPeebnBeF9V</li> </ul> <hr/> </body> </html>
Open service 18.66.192.23:443 · app.carium.com
2025-12-23 04:28
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 372 Connection: close Date: Tue, 23 Dec 2025 04:28:40 GMT Server: AmazonS3 Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block X-Powered-By: Coffee from 2nd St X-Frame-Options: deny Location: /sign-in/ X-Cache: Hit from cloudfront Via: 1.1 5cc4b35b46cb9b55d49e7f47442e6838.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: Thd9rxF8lfsRRNDsMGS_RLPFxVru8AY8rnpiiEVKYbO76XzXFvnVeQ== Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <h1>404 Not Found</h1> <ul> <li>Code: NoSuchKey</li> <li>Message: The specified key does not exist.</li> <li>Key: web-ui/index.html</li> <li>RequestId: SJD22D6XYY8X9BQV</li> <li>HostId: 1mzHB/WIZg7kS/NKsRTrhEzesYjhqNrB/M6+3GQEadYMOYAkftOIH0YdWzICvV0oM/Ron5JWTq/5ixqnsnT8+3Kz6JZ+7s9m</li> </ul> <hr/> </body> </html>
Open service 18.66.192.23:443 · app.carium.com
2025-12-19 00:13
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 352 Connection: close Date: Fri, 19 Dec 2025 00:13:33 GMT Server: AmazonS3 Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block X-Powered-By: Coffee from 2nd St X-Frame-Options: deny Location: /sign-in/ X-Cache: Hit from cloudfront Via: 1.1 28e56b9ddced4ed414e75f87cbd0d976.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 Alt-Svc: h3=":443"; ma=86400 X-Amz-Cf-Id: ptqhhX_n9xzBZz_y4wBG-2XB2dTR76k8hCj9S8be_BKRDhlFHDqGZg== Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <h1>404 Not Found</h1> <ul> <li>Code: NoSuchKey</li> <li>Message: The specified key does not exist.</li> <li>Key: web-ui/index.html</li> <li>RequestId: MTB3TAT2V95DKJMZ</li> <li>HostId: HDG7gBXu9szXoWgoL3Yb9j7Bnydsuu+zqKN7fKqkQCvvsqTq6VdlTbt6P2/wucTyT+gfmtyyM9M=</li> </ul> <hr/> </body> </html>