Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733f93b77d9b240ac757bb18cb8317310bd8
Found 10 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Severity: low
Fingerprint: 5f32cf5d6962f09cec7f8772ec7f8772159855a0eb5bbe5662f82d32553b6d83
Found 11 files trough .DS_Store spidering: /404.html /422.html /assets /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Severity: low
Fingerprint: 5f32cf5d6962f09cc169dbbec169dbbecc9a916cd8c9f71acf8ba7e20494e8c1
Found 15 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /default_user_photos /favicon.ico /loading.svg /packs /portraits /pulse.svg /robot.png /robot_party.png /spinner.svg /tangrams /users.png
Severity: low
Fingerprint: 5f32cf5d6962f09c39aac35b39aac35b92705af73eecf6fb46614f27bdec08ce
Found 14 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /default_user_photos /favicon.ico /loading.svg /packs /portraits /pulse.svg /robot.png /robot_party.png /spinner.svg /users.png
Open service 75.101.184.39:443 · app.prepi.pro
2026-01-08 22:49
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.prepi.pro/organizations/prepi/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=EoWA4iy34TwzP3uvQIQBb%2BjAGdadY2v84c33eBrq%2FxQ%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767912559"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=EoWA4iy34TwzP3uvQIQBb%2BjAGdadY2v84c33eBrq%2FxQ%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767912559"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: d1313188-54f1-25e5-a053-443c948f5981
X-Runtime: 0.011381
X-Xss-Protection: 0
Date: Thu, 08 Jan 2026 22:49:19 GMT
Connection: close
Open service 75.101.184.39:443 · app.prepi.pro
2025-12-30 06:32
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.prepi.pro/organizations/prepi/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2BM2t%2F6Hnc5uhtYD0%2F4k1xYsUlUmxMTmBA40OMUQyKh8%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767076353"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2BM2t%2F6Hnc5uhtYD0%2F4k1xYsUlUmxMTmBA40OMUQyKh8%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767076353"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 90b6f2a6-1a86-d6ea-6312-d83941f5faec
X-Runtime: 0.014991
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 06:32:33 GMT
Connection: close
Open service 75.101.184.39:443 · app.prepi.pro
2025-12-22 14:50
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.prepi.pro/organizations/prepi/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=WXEvD0gwTYHVxDFyqoP3jrFhuH4R0t%2BdmF2wi9M1x5g%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766415031"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=WXEvD0gwTYHVxDFyqoP3jrFhuH4R0t%2BdmF2wi9M1x5g%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766415031"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 61615bcf-823a-bb90-83c5-b0f487527a73
X-Runtime: 0.010477
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 14:50:31 GMT
Connection: close
Open service 75.101.184.39:443 · app.prepi.pro
2025-12-20 12:55
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.prepi.pro/organizations/prepi/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=yRtHgeILl%2Bp9qHAauxfeUxoC05ivSimSo4iCcPGtYOY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766235340"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=yRtHgeILl%2Bp9qHAauxfeUxoC05ivSimSo4iCcPGtYOY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766235340"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 5fcf13ad-f246-eebf-49a5-bf101d1a2c53
X-Runtime: 0.010505
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 12:55:40 GMT
Connection: close