AkamaiGHost
tcp/80
istio-envoy
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: high
Fingerprint: 5f32cf5d6962f09c8efce1938efce1937a208654a6958cbea6faf12bc96a1ee3
Found 36 files trough .DS_Store spidering: /.git /.idea /ajax /api /bgprocesses /BugFix /bulletin /business /devops /dialogs /docker /help /img /Import SQL Files /includes /includes/CacheLite /includes/Creole /includes/js /includes/projax /includes/Smarty /includes/Smarty/plugins /includes/tinymce /installation /jobs /js /kustomize /languages /modules /skins /sql /TextML export /tools /wcm_template /webservices /xml /xsl
Severity: high
Fingerprint: 5f32cf5d6962f09cf35cbfb3f35cbfb3af8132f4d8795b5eccf159cb19cdba89
Found 29 files trough .DS_Store spidering: /.git /.idea /ajax /api /bgprocesses /BugFix /bulletin /business /devops /dialogs /docker /help /img /Import SQL Files /includes /installation /jobs /js /kustomize /languages /modules /skins /sql /TextML export /tools /wcm_template /webservices /xml /xsl
Severity: high
Fingerprint: 5f32cf5d6962f09cd4047824d404782479c41899d33e800b5b4da2689acbf5a2
Found 35 files trough .DS_Store spidering: /.git /.idea /ajax /api /bgprocesses /BugFix /bulletin /business /devops /dialogs /docker /help /img /Import SQL Files /includes /includes/CacheLite /includes/Creole /includes/js /includes/projax /includes/Smarty /includes/tinymce /installation /jobs /js /kustomize /languages /modules /skins /sql /TextML export /tools /wcm_template /webservices /xml /xsl
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228ab2b2dc
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true hooksPath = /dev/null [remote "origin"] url = git@bitbucket.org:groupemedia/elephant.quebec.backend.git fetch = +refs/heads/master:refs/remotes/origin/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e6de2315
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@bitbucket.org:groupemedia/elephant.quebec.backend.git fetch = +refs/heads/master:refs/remotes/origin/master
Open service 104.126.36.209:443 · backend.dev.elephantcinema.quebec
2026-01-23 00:55
HTTP/1.1 200 OK
Content-Type: text/html;charset=UTF-8
Server: istio-envoy
x-powered-by: PHP/5.5.9-1ubuntu4.29
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate,post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Fri, 23 Jan 2026 00:55:44 GMT
x-envoy-upstream-service-time: 6
X-Akamai-Transformed: 9 939 0 pmb=mRUM,1
Date: Fri, 23 Jan 2026 00:55:45 GMT
Content-Length: 6477
Connection: close
Set-Cookie: PHPSESSID=g3cieu2kkdrbiv1dosavb7m377; path=/
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=94
Server-Timing: origin; dur=33
Server-Timing: ak_p; desc="1769129744833_1753097349_3199087_12751_1625_16_39_-";dur=1
Page title: Elephant
<html>
<head>
<title>Elephant</title>
<meta http-equiv="Content-Type" content="text/html;" />
<meta name="Generator" content="Nstein (2007). All rights reserved." />
<link rel="stylesheet" type="text/css" href="https://backend.dev.elephantcinema.quebec/skins/default/css/main.css" />
<script language="JavaScript" src="https://backend.dev.elephantcinema.quebec/js/main.js.php"></script>
<script>!function(a){var e="https://s.go-mpulse.net/boomerang/",t="addEventListener";if("False"=="True")a.BOOMR_config=a.BOOMR_config||{},a.BOOMR_config.PageParams=a.BOOMR_config.PageParams||{},a.BOOMR_config.PageParams.pci=!0,e="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="6TL65-RTCBC-2YY73-FU4Y9-WNH7F",function(){function n(e){a.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!a.BOOMR||!a.BOOMR.version&&!a.BOOMR.snippetExecuted){a.BOOMR=a.BOOMR||{},a.BOOMR.snippetExecuted=!0;var i,_,o,r=document.createElement("iframe");if(a[t])a[t]("load",n,!1);else if(a.attachEvent)a.attachEvent("onload",n);r.src="javascript:void(0)",r.title="",r.role="presentation",(r.frameElement||r).style.cssText="width:0;height:0;border:0;display:none;",o=document.getElementsByTagName("script")[0],o.parentNode.insertBefore(r,o);try{_=r.contentWindow.document}catch(O){i=document.domain,r.src="javascript:var d=document.open();d.domain='"+i+"';void(0);",_=r.contentWindow.document}_.open()._l=function(){var a=this.createElement("script");if(i)this.domain=i;a.id="boomr-if-as",a.src=e+"6TL65-RTCBC-2YY73-FU4Y9-WNH7F",BOOMR_lstart=(new Date).getTime(),this.body.appendChild(a)},_.write("<bo"+'dy onload="document._l();">'),_.close()}}(),"".length>0)if(a&&"performance"in a&&a.performance&&"function"==typeof a.performance.setResourceTimingBufferSize)a.performance.setResourceTimingBufferSize();!function(){if(BOOMR=a.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var e=""=="true"?1:0,t="",n="t5arfrlipysnc2lsy4ia-f-6deaa96ac-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,_={"ak.v":"39","ak.cp":"1214536","ak.ai":parseInt("732893",10),"ak.ol":"0","ak.cr":16,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"30d06f","ak.r":40308,"ak.a2":e,"ak.m":"f","ak.n":"essl","ak.bpcip":"159.65.18.0","ak.cport":33132,"ak.gh":"104.126.36.133","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1769129744","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==1TqKfz91mgeWL/TCrx6hVhLXfPKlFBoLirmXEQNkaG3VMzOXixOJrJX6z7SdhJw1usj/bKtfRJ3Saye8dZwzEKwmGOIrH66qSLAbi4dhtQtyh9K4w+rICBaB3pYb4M1SzwF4hIQ/Wx4oseuCbl05Z4jkpB2KQrR4GjnYBJOKJBwGRm6SWfOei3tSvBAL2MEPFXl76e8bI27yCccMM6yNlxBcrd/n+PgClecnjX7Pbq87WFfL71V+3ecvRjH+CLP/AbLeh4slZk0Lpx16i6kJlgdye2ZCw6IRk975As0G03mRtgJ/Q41tvIuRe2hNzUz2VtvOq7IQ0/DnTtNWItEPmoEhbAfsE1AyQtm3W5VfZf8pcyAR1pVoCuX68hSH+PJbZrpkDunK3EM2yFzkEcniqol529OCOFWZ1ioTtpewCVA=","ak.pv":"6","ak.dpoabenc":"","ak.tf":i};if(""!==t)_["ak.ruds"]=t;var o={i:!1,av:function(e){var t="http.initiator";if(e&&(!e[t]||"spa_hard"===e[t]))_["ak.feo"]=void 0!==a.aFeoApplied?1:0,BOOMR.addVar(_)},rv:function(){var a=["ak.bpcip","ak.cport","ak.cr","ak.csrc","ak.gh","ak.ipv","ak.m","ak.n","ak.ol","ak.proto","ak.quicv","ak.tlsv","ak.0rtt","ak.0rtt.ed","ak.r","ak.acc","ak.t","ak.tf"];BOOMR.removeVar(a)}};BOOMR.plugins.AK={akVars:_,akDNSPreFetchDomain:n,init:function(){if(!o.i){var a=BOOMR.subscribe;a("before_beacon",o.av,null,null),a("onbeacon",o.rv,null,null),o.i=!0}return this},is_complete:function(){return!0}}}}()}(window);</script></head>
<body class="loginBody">
<div id="loginBlock">
<table cellpadding="0" cellspacing="0" width="100%" height="100%">
<tr>
<td><img src="https://backend.dev.elephantcinema.quebec/img/loginHeader.png"/></td>
</tr>
<tr bgcolor="#800000">
<td class="loginHeader"> Logiciel de conception et de publication Web </td>
</tr>
<tr height="99%">
<td align="center">
<table cellspacing="0" cellpadding="0" border="0">
<tr>
<td align="ce
Open service 23.53.43.40:80 · backend.dev.elephantcinema.quebec
2026-01-05 16:52
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://backend.dev.elephantcinema.quebec/ Date: Mon, 05 Jan 2026 16:52:53 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767631973314_389360420_488254845_12_602_94_0_-";dur=1
Open service 23.53.43.40:443 · backend.dev.elephantcinema.quebec
2026-01-05 16:52
HTTP/1.1 200 OK
Content-Type: text/html;charset=UTF-8
Server: istio-envoy
x-powered-by: PHP/5.5.9-1ubuntu4.29
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate,post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Mon, 05 Jan 2026 16:52:12 GMT
x-envoy-upstream-service-time: 5
X-Akamai-Transformed: 9 939 0 pmb=mRUM,1
Date: Mon, 05 Jan 2026 16:52:12 GMT
Content-Length: 6476
Connection: close
Set-Cookie: PHPSESSID=b7dntbnuktjkgbup0ke07nhbk3; path=/
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=95
Server-Timing: origin; dur=211
Server-Timing: ak_p; desc="1767631932191_389360366_365940353_30607_865_9_24_-";dur=1
Page title: Elephant
<html>
<head>
<title>Elephant</title>
<meta http-equiv="Content-Type" content="text/html;" />
<meta name="Generator" content="Nstein (2007). All rights reserved." />
<link rel="stylesheet" type="text/css" href="https://backend.dev.elephantcinema.quebec/skins/default/css/main.css" />
<script language="JavaScript" src="https://backend.dev.elephantcinema.quebec/js/main.js.php"></script>
<script>!function(a){var e="https://s.go-mpulse.net/boomerang/",t="addEventListener";if("False"=="True")a.BOOMR_config=a.BOOMR_config||{},a.BOOMR_config.PageParams=a.BOOMR_config.PageParams||{},a.BOOMR_config.PageParams.pci=!0,e="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="6TL65-RTCBC-2YY73-FU4Y9-WNH7F",function(){function n(e){a.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!a.BOOMR||!a.BOOMR.version&&!a.BOOMR.snippetExecuted){a.BOOMR=a.BOOMR||{},a.BOOMR.snippetExecuted=!0;var i,_,o,r=document.createElement("iframe");if(a[t])a[t]("load",n,!1);else if(a.attachEvent)a.attachEvent("onload",n);r.src="javascript:void(0)",r.title="",r.role="presentation",(r.frameElement||r).style.cssText="width:0;height:0;border:0;display:none;",o=document.getElementsByTagName("script")[0],o.parentNode.insertBefore(r,o);try{_=r.contentWindow.document}catch(O){i=document.domain,r.src="javascript:var d=document.open();d.domain='"+i+"';void(0);",_=r.contentWindow.document}_.open()._l=function(){var a=this.createElement("script");if(i)this.domain=i;a.id="boomr-if-as",a.src=e+"6TL65-RTCBC-2YY73-FU4Y9-WNH7F",BOOMR_lstart=(new Date).getTime(),this.body.appendChild(a)},_.write("<bo"+'dy onload="document._l();">'),_.close()}}(),"".length>0)if(a&&"performance"in a&&a.performance&&"function"==typeof a.performance.setResourceTimingBufferSize)a.performance.setResourceTimingBufferSize();!function(){if(BOOMR=a.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var e=""=="true"?1:0,t="",n="rzoydpqxguvsq2k35q6a-f-81ff07b38-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,_={"ak.v":"39","ak.cp":"1214536","ak.ai":parseInt("732893",10),"ak.ol":"0","ak.cr":6,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"15cfce81","ak.r":37582,"ak.a2":e,"ak.m":"","ak.n":"essl","ak.bpcip":"142.93.129.0","ak.cport":60614,"ak.gh":"23.53.42.238","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1767631932","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==Ib+s9HQoJlbatTUHNiJ5z8MR4ulbET+3kc6Y+PVLqRjLAdN4pLHpM9kCZQN6t8n7uHPytSVh7LdXCMn0DLUSp42VjRkrP5lkIFS0roxRc9/GMng99g6u+X3aBlz8ceiUiKkQMb4TLjwIhUwp+dBbydwEpb9g/wA5467zLW97zif/jkXeZQB1u3RiPy3jsctWg2D1asMHgHL9SmLNnGCvzjTrZJAOLtyOWodYUKhIBSCQnlULMwHiqKtNI8cdJ75CDHLBoy8DHsdbkR/LFFcS0myFB5szCFjnaVfwyyvJ2fYwQN6Y6yM2kqvjr3U6JgZTLXMClZ6696L+3vh68af31Pji81zvtulOOuB7g3yc1OCpLsQg+ZcaF6B4LnCBAI/LxNdMGDxTWDbQJ4eKAwgDby+VVLD1ZmWkHf8RzxbWVgI=","ak.pv":"6","ak.dpoabenc":"","ak.tf":i};if(""!==t)_["ak.ruds"]=t;var o={i:!1,av:function(e){var t="http.initiator";if(e&&(!e[t]||"spa_hard"===e[t]))_["ak.feo"]=void 0!==a.aFeoApplied?1:0,BOOMR.addVar(_)},rv:function(){var a=["ak.bpcip","ak.cport","ak.cr","ak.csrc","ak.gh","ak.ipv","ak.m","ak.n","ak.ol","ak.proto","ak.quicv","ak.tlsv","ak.0rtt","ak.0rtt.ed","ak.r","ak.acc","ak.t","ak.tf"];BOOMR.removeVar(a)}};BOOMR.plugins.AK={akVars:_,akDNSPreFetchDomain:n,init:function(){if(!o.i){var a=BOOMR.subscribe;a("before_beacon",o.av,null,null),a("onbeacon",o.rv,null,null),o.i=!0}return this},is_complete:function(){return!0}}}}()}(window);</script></head>
<body class="loginBody">
<div id="loginBlock">
<table cellpadding="0" cellspacing="0" width="100%" height="100%">
<tr>
<td><img src="https://backend.dev.elephantcinema.quebec/img/loginHeader.png"/></td>
</tr>
<tr bgcolor="#800000">
<td class="loginHeader"> Logiciel de conception et de publication Web </td>
</tr>
<tr height="99%">
<td align="center">
<table cellspacing="0" cellpadding="0" border="0">
<tr>
<td align="cen
Open service 23.53.42.242:80 · backend.dev.elephantcinema.quebec
2026-01-05 16:52
HTTP/1.1 301 Moved Permanently Server: AkamaiGHost Content-Length: 0 Location: https://backend.dev.elephantcinema.quebec/ Date: Mon, 05 Jan 2026 16:52:53 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767631973216_389360366_365950978_16_1086_94_0_-";dur=1
Open service 23.53.42.242:443 · backend.dev.elephantcinema.quebec
2026-01-05 16:52
HTTP/1.1 200 OK
Content-Type: text/html;charset=UTF-8
Server: istio-envoy
x-powered-by: PHP/5.5.9-1ubuntu4.29
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-store, no-cache, must-revalidate,post-check=0, pre-check=0
Pragma: no-cache
Last-Modified: Mon, 05 Jan 2026 16:52:12 GMT
x-envoy-upstream-service-time: 5
X-Akamai-Transformed: 9 939 0 pmb=mRUM,1
Date: Mon, 05 Jan 2026 16:52:12 GMT
Content-Length: 6480
Connection: close
Set-Cookie: PHPSESSID=2ln952g8prki123sg303b2vur4; path=/
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=102
Server-Timing: origin; dur=33
Server-Timing: ak_p; desc="1767631932594_389360366_365940444_13424_937_159_161_-";dur=1
Page title: Elephant
<html>
<head>
<title>Elephant</title>
<meta http-equiv="Content-Type" content="text/html;" />
<meta name="Generator" content="Nstein (2007). All rights reserved." />
<link rel="stylesheet" type="text/css" href="https://backend.dev.elephantcinema.quebec/skins/default/css/main.css" />
<script language="JavaScript" src="https://backend.dev.elephantcinema.quebec/js/main.js.php"></script>
<script>!function(a){var e="https://s.go-mpulse.net/boomerang/",t="addEventListener";if("False"=="True")a.BOOMR_config=a.BOOMR_config||{},a.BOOMR_config.PageParams=a.BOOMR_config.PageParams||{},a.BOOMR_config.PageParams.pci=!0,e="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="6TL65-RTCBC-2YY73-FU4Y9-WNH7F",function(){function n(e){a.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!a.BOOMR||!a.BOOMR.version&&!a.BOOMR.snippetExecuted){a.BOOMR=a.BOOMR||{},a.BOOMR.snippetExecuted=!0;var i,_,o,r=document.createElement("iframe");if(a[t])a[t]("load",n,!1);else if(a.attachEvent)a.attachEvent("onload",n);r.src="javascript:void(0)",r.title="",r.role="presentation",(r.frameElement||r).style.cssText="width:0;height:0;border:0;display:none;",o=document.getElementsByTagName("script")[0],o.parentNode.insertBefore(r,o);try{_=r.contentWindow.document}catch(O){i=document.domain,r.src="javascript:var d=document.open();d.domain='"+i+"';void(0);",_=r.contentWindow.document}_.open()._l=function(){var a=this.createElement("script");if(i)this.domain=i;a.id="boomr-if-as",a.src=e+"6TL65-RTCBC-2YY73-FU4Y9-WNH7F",BOOMR_lstart=(new Date).getTime(),this.body.appendChild(a)},_.write("<bo"+'dy onload="document._l();">'),_.close()}}(),"".length>0)if(a&&"performance"in a&&a.performance&&"function"==typeof a.performance.setResourceTimingBufferSize)a.performance.setResourceTimingBufferSize();!function(){if(BOOMR=a.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var e=""=="true"?1:0,t="",n="sk7gozyxguvpe2k35q6a-f-81ec769c5-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,_={"ak.v":"39","ak.cp":"1214536","ak.ai":parseInt("732893",10),"ak.ol":"0","ak.cr":159,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"15cfcedc","ak.r":37582,"ak.a2":e,"ak.m":"f","ak.n":"essl","ak.bpcip":"146.190.103.0","ak.cport":50388,"ak.gh":"23.53.42.238","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1767631932","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==7UnCKU80/knprCrWsvsIDWEEgq99gwJba5g0yOi8APF9ZNcCj8WXtiCxNQMPmIT3chg9JZnz2foJDBYDaQdCGbytZLHXiHHId2oE1EwVFhprBVZ6w0Yv+hUzBGdN/sUlDsvOfugLpAugAuQMgYm9edduClQ9eH6lhDguRLYcYb0cmz8MKVaX9I8niT3SyUANe5hl2MD9uZP2u39iYf3bkhMxVS1Wsb0S0doKZh8BQjUMhgqY5ixwNG8A7U/o72xyYmVKDmJL+kqZNZEOXf9eBMjPoLC/TyemQ78noJM5STheIrunum9cRP3dh5zYi3unARXXo18NCAIb8LwO/8WhgdJo1WD7DbgzoN6TMSrIETCIBklNnQ1WEAprNE3I2I5Y5zW+9YtL1pchWPPNGMs3s9jSJA+Yw4DFVlTxqedH1aE=","ak.pv":"6","ak.dpoabenc":"","ak.tf":i};if(""!==t)_["ak.ruds"]=t;var o={i:!1,av:function(e){var t="http.initiator";if(e&&(!e[t]||"spa_hard"===e[t]))_["ak.feo"]=void 0!==a.aFeoApplied?1:0,BOOMR.addVar(_)},rv:function(){var a=["ak.bpcip","ak.cport","ak.cr","ak.csrc","ak.gh","ak.ipv","ak.m","ak.n","ak.ol","ak.proto","ak.quicv","ak.tlsv","ak.0rtt","ak.0rtt.ed","ak.r","ak.acc","ak.t","ak.tf"];BOOMR.removeVar(a)}};BOOMR.plugins.AK={akVars:_,akDNSPreFetchDomain:n,init:function(){if(!o.i){var a=BOOMR.subscribe;a("before_beacon",o.av,null,null),a("onbeacon",o.rv,null,null),o.i=!0}return this},is_complete:function(){return!0}}}}()}(window);</script></head>
<body class="loginBody">
<div id="loginBlock">
<table cellpadding="0" cellspacing="0" width="100%" height="100%">
<tr>
<td><img src="https://backend.dev.elephantcinema.quebec/img/loginHeader.png"/></td>
</tr>
<tr bgcolor="#800000">
<td class="loginHeader"> Logiciel de conception et de publication Web </td>
</tr>
<tr height="99%">
<td align="center">
<table cellspacing="0" cellpadding="0" border="0">
<tr>
<td align=