cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa344ac665a4789324a7a7e7f5ee99c8a6e9832a99a
GraphQL introspection enabled at /graphql Types: 103 (by kind: ENUM: 10, INPUT_OBJECT: 24, OBJECT: 60, SCALAR: 9) Operations: - Query: Query | fields: aggregatedKpis, allClients, backfillState, bets, betsCsv - Mutation: Mutation | fields: backfillTransactions, cacheUrl, changeMyPassword, createClient, createCluster Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 104.26.11.163:443 · backoffice-v2.staging.devp7.com
2026-01-09 01:13
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 01:13:07 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
last-modified: Thu, 04 Dec 2025 10:07:08 GMT
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=v9a%2BV%2FgA%2B5MfyIr0m9OsrY%2Bsxf1bvOlPuNkk1U4J1RXfSlztl1ZUwjBnXIZyjKYvPrwYrdwfY1MEHM8rvqOdurCXGLknsVBJHACq8oIFdUIzRBSHV%2BXjUdwTWbczww%3D%3D"}]}
permissions-policy: autoplay=*, fullscreen=*
Accept-Ranges: bytes
strict-transport-security: max-age=31536000; includeSubDomains
x-powered-by: pivni
Server: cloudflare
x-content-type-options: nosniff
x-frame-options: allowall
x-xss-protection: 1
x-robots-tag: noindex, nofollow, nosnippet, noarchive
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=11,cfOrigin;dur=451
CF-RAY: 9bb011f89a6bde03-SJC
alt-svc: h3=":443"; ma=86400
Page title: Phoenix7 - Backoffice
<!doctype html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<link rel="icon" type="image/svg+xml" href="/favicon.ico" />
<title>Phoenix7 - Backoffice</title>
<script type="module" crossorigin src="/assets/index-KrZrEFLC.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-Bh76j7cs.css">
</head>
<body>
<noscript>You need to enable JavaScript to run this app.</noscript>
<div id="root"></div>
<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"3a45806b7bbf468299857b90bd142727","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
<script>(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'9bb011f89a6bde03',t:'MTc2NzkyMTE4Ng=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>
</html>
Open service 104.26.11.163:443 · backoffice-v2.staging.devp7.com
2026-01-01 23:03
HTTP/1.1 200 OK
Date: Thu, 01 Jan 2026 23:03:55 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
last-modified: Thu, 04 Dec 2025 10:07:08 GMT
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=k5KMf57idGViL%2B550OEpsZ259mqyZkMzfpzZ%2FBCQjbzVSGia1qOvYbwR0HGDSMXwRb2VmsFxXb8M1fYYGxgn3H7znXsJcCvHXAoH7ee5SOQDp4JfVgCQHjBvSaf92w%3D%3D"}]}
permissions-policy: autoplay=*, fullscreen=*
Accept-Ranges: bytes
strict-transport-security: max-age=31536000; includeSubDomains
x-powered-by: pivni
Server: cloudflare
x-content-type-options: nosniff
x-frame-options: allowall
x-xss-protection: 1
x-robots-tag: noindex, nofollow, nosnippet, noarchive
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=12,cfOrigin;dur=543
CF-RAY: 9b75a717dac7d3c6-SIN
alt-svc: h3=":443"; ma=86400
Page title: Phoenix7 - Backoffice
<!doctype html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<link rel="icon" type="image/svg+xml" href="/favicon.ico" />
<title>Phoenix7 - Backoffice</title>
<script type="module" crossorigin src="/assets/index-KrZrEFLC.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-Bh76j7cs.css">
</head>
<body>
<noscript>You need to enable JavaScript to run this app.</noscript>
<div id="root"></div>
<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"3a45806b7bbf468299857b90bd142727","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
<script>(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'9b75a717dac7d3c6',t:'MTc2NzMwODYzNA=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>
</html>