Apache
tcp/443
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652202f51e01
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://Hiba-Mahmoud:glpat-BFG_4tgrDxa77MVxrfA6@gitlab.com/BadrSmartSystems/badrshop2021.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/badrshop43 [pull] rebase = true [branch "badrshop43"] remote = origin merge = refs/heads/badrshop43 [branch "badrshop43_staging"] remote = origin merge = refs/heads/badrshop43_staging [user] name = badrshop43 testing server email = test@test.com
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65227b1c7cf4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://Hiba-Mahmoud:glpat-9XKKUE5T9WyTjt9gxzdj@gitlab.com/BadrSmartSystems/badrshop2021.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/badrshop43 [pull] rebase = false [branch "badrshop43"] remote = origin merge = refs/heads/badrshop43
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65227b1c7cf4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://Hiba-Mahmoud:glpat-9XKKUE5T9WyTjt9gxzdj@gitlab.com/BadrSmartSystems/badrshop2021.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/badrshop43 [pull] rebase = false [branch "badrshop43"] remote = origin merge = refs/heads/badrshop43
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-11-20 13:27
HTTP/1.1 302 Found Date: Wed, 20 Nov 2024 13:27:12 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=5271fae9145603dd021c0f2d1b4f7efe; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-11-18 11:19
HTTP/1.1 302 Found Date: Mon, 18 Nov 2024 11:19:43 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=b35fdc4c8e359ab12470df24619ff508; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-11-16 12:02
HTTP/1.1 302 Found Date: Sat, 16 Nov 2024 12:02:40 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=efb49b6917ad7cf0fd50fe848b198ca0; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-11-02 19:25
HTTP/1.1 302 Found Date: Sat, 02 Nov 2024 19:25:38 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=33d289a9f7426b9323eca90dc0eaad50; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-11-01 23:50
HTTP/1.1 302 Found Date: Fri, 01 Nov 2024 23:51:03 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=f4170bacdeb448544d99b646383bac58; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-10-31 00:13
HTTP/1.1 302 Found Date: Thu, 31 Oct 2024 00:13:21 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=0fa661737a794ce6a66c171c275cb99d; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-10-20 21:59
HTTP/1.1 302 Found Date: Sun, 20 Oct 2024 21:59:35 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=a7079aa23210202879be8483e1f2ebf1; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-10-18 21:08
HTTP/1.1 302 Found Date: Fri, 18 Oct 2024 21:08:38 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=92fc308ef8a53530417aa2967646817e; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 203.161.42.101:443 · badrshop43.albadrsales.com
2024-10-16 23:21
HTTP/1.1 302 Found Date: Wed, 16 Oct 2024 23:21:25 GMT Server: Apache Cache-Control: no-cache, no-store, must-revalidate Pragma: no-cache Expires: 0 Set-Cookie: PHPSESSID=af6d868cf3161534ac56da255045bf29; path=/ Location: https://badrshop43.albadrsales.com/login.php?lan=ar Vary: Accept-Encoding Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8