cloudflare
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 104.21.227.134:443 ยท auth.kcpot.top
2026-01-23 14:55
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 14:55:39 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=766
Cache-Control: no-cache
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=mKdn15G2vnBX2Ffklc69iQJI%2Fpq%2FeQD8EzE5JHo2wbxIdCMpQF2mExX6bzhHP%2FgpaYbUYk%2FQH5L8K6aApSG025JbbFeoUdI2NBdq%2Fufm"}]}
last-modified: Fri, 22 Aug 2025 03:43:00 GMT
Server: cloudflare
Set-Cookie: casdoor_session_id=d7c6fa7f36c76b9ec4e477adb304cbc7; Path=/; Expires=Sun, 22 Feb 2026 14:55:39 GMT; Max-Age=2592000; HttpOnly
cf-cache-status: DYNAMIC
vary: accept-encoding
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
Speculation-Rules: "/cdn-cgi/speculation"
CF-RAY: 9c28221aaffb18ae-AMS
alt-svc: h3=":443"; ma=86400
Page title: Casdoor
<!doctype html><html lang="en"><head><meta charset="utf-8"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Casdoor - An Identity and Access Management (IAM) / Single-Sign-On (SSO) platform with web UI supporting OAuth 2.0, OIDC, SAML and CAS"/><link rel="apple-touch-icon" href="https://cdn.casbin.org/img/favicon.png"/><link rel="manifest" href="https://cdn.casbin.org/site/casdoor/manifest.json"/><title>Casdoor</title><script defer="defer" src="/static/js/main.a4e9d42d.js" type="be23d7eafd72f8cef04256b3-text/javascript"></script><link href="/static/css/main.f35879a1.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div><script src="/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js" data-cf-settings="be23d7eafd72f8cef04256b3-|49" defer></script><script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"e0324e278f2e49fc9a39ebaf21f127b3","r":1,"server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body></html>