Heroku
tcp/443 tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733f93b77d9b240ac757bb18cb8317310bd8
Found 10 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Open service 15.197.149.68:443 · app.ther33f.com
2026-01-09 06:04
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=DhkrlHo%2F4yLp9JdCAdb%2FjM3DcduDN2DCGqZlihb%2FYv0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767938689"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=DhkrlHo%2F4yLp9JdCAdb%2FjM3DcduDN2DCGqZlihb%2FYv0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767938689"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: da3b4259-b5ec-3373-47aa-34e4f19655a2
X-Runtime: 0.072846
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 06:04:49 GMT
Connection: close
Open service 15.197.149.68:443 · app.ther33f.com
2026-01-02 06:57
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=JXV212NJVLTRQchnQLdcMZiiDjFopD7hLDn%2FEGVwU9Y%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767337041"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=JXV212NJVLTRQchnQLdcMZiiDjFopD7hLDn%2FEGVwU9Y%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767337041"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 18516cf9-2a6c-9f2f-2309-10cd40342ff7
X-Runtime: 0.008846
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 06:57:21 GMT
Connection: close
Open service 15.197.149.68:443 · app.ther33f.com
2025-12-30 09:58
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=lBV%2Ffn%2B0O%2FwEfldHAXy3%2BPDDPB7YFVi52rmsmoDHjlg%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767088715"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=lBV%2Ffn%2B0O%2FwEfldHAXy3%2BPDDPB7YFVi52rmsmoDHjlg%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767088715"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: c5341a08-081a-e9ec-0e2d-930a0498e72d
X-Runtime: 0.010343
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 09:58:35 GMT
Connection: close
Open service 15.197.149.68:443 · app.ther33f.com
2025-12-23 00:52
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=y6B%2Fus2zrNyG80vIvuoAXb2dz%2F8dH6tMK74V16PwvJI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766451145"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=y6B%2Fus2zrNyG80vIvuoAXb2dz%2F8dH6tMK74V16PwvJI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766451145"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 7821531e-3c18-f061-a67b-39920a88bcb1
X-Runtime: 0.009686
X-Xss-Protection: 0
Date: Tue, 23 Dec 2025 00:52:25 GMT
Connection: close
Open service 15.197.149.68:443 · app.ther33f.com
2025-12-21 08:23
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=S%2FCMl0h7ssUbQJxYR2W8Spszumu988UuSDv%2BjSVVlso%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766305413"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=S%2FCMl0h7ssUbQJxYR2W8Spszumu988UuSDv%2BjSVVlso%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766305413"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 419cff52-1067-6f52-eac6-3ffd1c3efc36
X-Runtime: 0.011822
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 08:23:33 GMT
Connection: close
Open service 15.197.149.68:443 · app.ther33f.com
2025-12-19 09:24
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=W5hERT%2FM6XoVpYu5hcF%2BXxmrhdxAix4M7e6aTrGaN28%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766136297"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=W5hERT%2FM6XoVpYu5hcF%2BXxmrhdxAix4M7e6aTrGaN28%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766136297"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 3ab38152-e24d-02cb-0695-bfc216650d39
X-Runtime: 0.008934
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 09:24:58 GMT
Connection: close
Open service 3.33.241.96:443 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sOKg98NDhNOatCz5iDCRPKRTCuUWJOktv3uB8Pb%2FDuY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107957"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sOKg98NDhNOatCz5iDCRPKRTCuUWJOktv3uB8Pb%2FDuY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107957"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f72197f6-7fcd-3251-ed48-09495deee7a7
X-Runtime: 0.007979
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 01:32:37 GMT
Connection: close
Open service 13.248.213.92:443 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cgLiJetTlGsCXOwo%2FxvFRBy1NpMs7enlHP0fnhVaYHg%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107958"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cgLiJetTlGsCXOwo%2FxvFRBy1NpMs7enlHP0fnhVaYHg%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107958"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: c230b5f1-d4ab-8ef8-0b6c-60b12cc13e49
X-Runtime: 0.008064
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 01:32:38 GMT
Connection: close
Open service 15.197.149.68:443 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sOKg98NDhNOatCz5iDCRPKRTCuUWJOktv3uB8Pb%2FDuY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107957"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sOKg98NDhNOatCz5iDCRPKRTCuUWJOktv3uB8Pb%2FDuY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107957"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 216d4228-4d18-ef9b-b3ae-1d1faa0e15de
X-Runtime: 0.010035
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 01:32:37 GMT
Connection: close
Open service 15.197.149.68:80 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 301 Moved Permanently
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://app.ther33f.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Etp8XzTDY59Kp3Nk7UC3ZH8L0gBTn84q4bTthqWYbXQ%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107961"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Etp8XzTDY59Kp3Nk7UC3ZH8L0gBTn84q4bTthqWYbXQ%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107961"
Server: Heroku
Via: 1.1 heroku-router
Date: Fri, 19 Dec 2025 01:32:41 GMT
Connection: close
Open service 13.248.213.92:80 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 301 Moved Permanently
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://app.ther33f.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9bwj752Bn5kBaYCVM7OERJGitsz9hXjEZKJW5N4a1ko%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107960"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9bwj752Bn5kBaYCVM7OERJGitsz9hXjEZKJW5N4a1ko%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107960"
Server: Heroku
Via: 1.1 heroku-router
Date: Fri, 19 Dec 2025 01:32:40 GMT
Connection: close
Open service 76.223.57.73:443 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://app.ther33f.com/organizations/ther33f/deactivated
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sOKg98NDhNOatCz5iDCRPKRTCuUWJOktv3uB8Pb%2FDuY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107957"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sOKg98NDhNOatCz5iDCRPKRTCuUWJOktv3uB8Pb%2FDuY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107957"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 8cec2160-31a0-0682-3aa5-9464fb1a5653
X-Runtime: 0.008594
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 01:32:37 GMT
Connection: close
Open service 76.223.57.73:80 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 301 Moved Permanently
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://app.ther33f.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9bwj752Bn5kBaYCVM7OERJGitsz9hXjEZKJW5N4a1ko%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107960"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9bwj752Bn5kBaYCVM7OERJGitsz9hXjEZKJW5N4a1ko%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107960"
Server: Heroku
Via: 1.1 heroku-router
Date: Fri, 19 Dec 2025 01:32:40 GMT
Connection: close
Open service 3.33.241.96:80 · app.ther33f.com
2025-12-19 01:32
HTTP/1.1 301 Moved Permanently
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://app.ther33f.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9bwj752Bn5kBaYCVM7OERJGitsz9hXjEZKJW5N4a1ko%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766107960"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9bwj752Bn5kBaYCVM7OERJGitsz9hXjEZKJW5N4a1ko%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766107960"
Server: Heroku
Via: 1.1 heroku-router
Date: Fri, 19 Dec 2025 01:32:40 GMT
Connection: close