istio-envoy
tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 47.79.87.5:80 · auth.logto.ip-ddns.com
2026-01-09 01:37
HTTP/1.1 503 Service Unavailable date: Fri, 09 Jan 2026 01:37:08 GMT server: istio-envoy connection: close content-length: 0
Open service 47.79.87.5:80 · auth.logto.ip-ddns.com
2026-01-02 00:18
HTTP/1.1 503 Service Unavailable date: Fri, 02 Jan 2026 00:18:22 GMT server: istio-envoy connection: close content-length: 0
Open service 47.79.145.132:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 503 Service Unavailable date: Mon, 22 Dec 2025 12:33:13 GMT server: istio-envoy connection: close content-length: 0
Open service 47.79.144.155:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 200 OK accept-ranges: bytes content-length: 760 content-type: text/html; charset=utf-8 last-modified: Thu, 18 Dec 2025 13:31:35 GMT server: istio-envoy set-cookie: casdoor_session_id=0e428b3736460f2bc1983b8266d61e40; Path=/; Expires=Wed, 21 Jan 2026 12:33:13 GMT; Max-Age=2592000; HttpOnly date: Mon, 22 Dec 2025 12:33:13 GMT req-cost-time: 1 req-arrive-time: 1766406793975 resp-start-time: 1766406793976 x-envoy-upstream-service-time: 1 connection: close Page title: Casdoor <!doctype html><html lang="en"><head><meta charset="utf-8"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Casdoor - An Identity and Access Management (IAM) / Single-Sign-On (SSO) platform with web UI supporting OAuth 2.0, OIDC, SAML and CAS"/><link rel="apple-touch-icon" href="https://cdn.casbin.org/img/favicon.png"/><link rel="manifest" href="https://cdn.casbin.org/site/casdoor/manifest.json"/><title>Casdoor</title><script defer="defer" src="/static/js/main.2a450bae.js"></script><link href="/static/css/main.f35879a1.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 47.79.93.100:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 200 OK accept-ranges: bytes content-length: 760 content-type: text/html; charset=utf-8 last-modified: Thu, 18 Dec 2025 13:31:35 GMT server: istio-envoy set-cookie: casdoor_session_id=82741a1f287a650a3b9e8ee83add27e9; Path=/; Expires=Wed, 21 Jan 2026 12:33:13 GMT; Max-Age=2592000; HttpOnly date: Mon, 22 Dec 2025 12:33:13 GMT req-cost-time: 2 req-arrive-time: 1766406793799 resp-start-time: 1766406793801 x-envoy-upstream-service-time: 2 connection: close Page title: Casdoor <!doctype html><html lang="en"><head><meta charset="utf-8"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Casdoor - An Identity and Access Management (IAM) / Single-Sign-On (SSO) platform with web UI supporting OAuth 2.0, OIDC, SAML and CAS"/><link rel="apple-touch-icon" href="https://cdn.casbin.org/img/favicon.png"/><link rel="manifest" href="https://cdn.casbin.org/site/casdoor/manifest.json"/><title>Casdoor</title><script defer="defer" src="/static/js/main.2a450bae.js"></script><link href="/static/css/main.f35879a1.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 47.79.144.214:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 503 Service Unavailable date: Thu, 18 Dec 2025 17:14:28 GMT server: istio-envoy connection: close content-length: 0
Open service 47.79.87.5:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 200 OK accept-ranges: bytes content-length: 760 content-type: text/html; charset=utf-8 last-modified: Thu, 18 Dec 2025 13:31:35 GMT server: istio-envoy set-cookie: casdoor_session_id=4df3ee1ceaf7259fdbd25cab17982bca; Path=/; Expires=Wed, 21 Jan 2026 12:33:13 GMT; Max-Age=2592000; HttpOnly date: Mon, 22 Dec 2025 12:33:13 GMT req-cost-time: 7 req-arrive-time: 1766406793342 resp-start-time: 1766406793349 x-envoy-upstream-service-time: 6 connection: close Page title: Casdoor <!doctype html><html lang="en"><head><meta charset="utf-8"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Casdoor - An Identity and Access Management (IAM) / Single-Sign-On (SSO) platform with web UI supporting OAuth 2.0, OIDC, SAML and CAS"/><link rel="apple-touch-icon" href="https://cdn.casbin.org/img/favicon.png"/><link rel="manifest" href="https://cdn.casbin.org/site/casdoor/manifest.json"/><title>Casdoor</title><script defer="defer" src="/static/js/main.2a450bae.js"></script><link href="/static/css/main.f35879a1.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 47.79.37.186:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 503 Service Unavailable date: Mon, 22 Dec 2025 12:33:12 GMT server: istio-envoy connection: close content-length: 0
Open service 47.79.95.174:80 · auth.logto.ip-ddns.com
2025-12-22 12:33
HTTP/1.1 200 OK accept-ranges: bytes content-length: 760 content-type: text/html; charset=utf-8 last-modified: Thu, 18 Dec 2025 13:31:35 GMT server: istio-envoy set-cookie: casdoor_session_id=90cb057db01473c66a25a0abe21764ea; Path=/; Expires=Wed, 21 Jan 2026 12:33:14 GMT; Max-Age=2592000; HttpOnly date: Mon, 22 Dec 2025 12:33:14 GMT req-cost-time: 40 req-arrive-time: 1766406794016 resp-start-time: 1766406794057 x-envoy-upstream-service-time: 40 connection: close Page title: Casdoor <!doctype html><html lang="en"><head><meta charset="utf-8"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Casdoor - An Identity and Access Management (IAM) / Single-Sign-On (SSO) platform with web UI supporting OAuth 2.0, OIDC, SAML and CAS"/><link rel="apple-touch-icon" href="https://cdn.casbin.org/img/favicon.png"/><link rel="manifest" href="https://cdn.casbin.org/site/casdoor/manifest.json"/><title>Casdoor</title><script defer="defer" src="/static/js/main.2a450bae.js"></script><link href="/static/css/main.f35879a1.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>