cloudflare
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea96ba46591629a2ee1cbb56ea163e836bb
Found 23 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads /uploads/media
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07b46ef9b9b46ef9b9b46ef9b9b46ef9b9b46ef9b9
Symfony profiler enabled: https://bassbett.org/_profiler/empty/search/results
Open service 2a06:98c1:3121::3:443 · bassbett.org
2026-01-09 03:52
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 03:53:02 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=iwFDAbGs81VIhEjswz6aeFECG%2BMq2W0wXlrOBNICcsBOShjAItTN6yNodP%2BAHx7DIZoxqSzAKYrRqZ8vGxvQYnxEFUb86hUWLR%2F%2FdaFHU1xkCfGqs0bVpA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 03:53:02 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=490
CF-RAY: 9bb0fc392c2ef52c-EWR
Open service 188.114.97.3:443 · bassbett.org
2026-01-09 03:29
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 03:29:58 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=g1dkjC2XhGyageq0educM6xSudZ0JVtEqeo8J%2Ftm6JgisEC3uY%2BELCEIckBs6sviVscpHHEC2KhTYaMR%2FKjDu7x0vxrYLVKS%2B%2Fl42Q%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 03:29:58 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9bb0da6ed970d289-FRA
Open service 188.114.97.3:443 · bassbett.org
2026-01-02 09:53
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 09:53:04 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=4Nx%2BJBGJAX9RHDOjnlO9buVd8rD6EWAoUwXQELkbEQG%2FUr9pAI02DDZodQYeT5iFlTHlINwEJVFxJpqo4fB6kahDdK5bhupeT1QAkA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 02 Feb 2026 09:53:03 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=11,cfOrigin;dur=1505
CF-RAY: 9b795df669d43ada-BOM
Open service 2a06:98c1:3121::3:443 · bassbett.org
2026-01-02 04:13
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 04:13:43 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=%2FEwpsJRwivvWQXp3ZFb6jlDzkwEVQm67tbc%2FShNm387IdXR24UH6P9RAdEGqkfGGUdN2MipUTWMXRKe33dr8nRM7f%2FTg5JTlX0dkHu%2F02nw3%2F5pu4sh9jQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 02 Feb 2026 04:13:43 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b776ce9f8a90b77-AMS
Open service 2a06:98c1:3121::3:443 · bassbett.org
2025-12-30 14:04
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 14:04:53 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=RNHrkeQblrQd7NhxG%2FRMXYK6J6gDXvpYr6dzQnYQOYdzVfs9tSxie67DDrkOJNj8UH8u4h5tNNsF1iDSiMPYrH0wth5jXtwtZQ5BRY6Drq7rldD9WBOI%2BA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Fri, 30 Jan 2026 14:04:53 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b6216bf287f1c32-FRA
Open service 188.114.97.3:443 · bassbett.org
2025-12-22 17:17
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 17:17:45 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=iLh7oHztPu2UtWVn6oBU1LPxipIWqyTX318OAz7v9CF2RAhuZvGmnSopS7h9Zw3ZR2j%2BSnppg6ZrgAXBO91xXyKeXFN7CILAUX%2F05w%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 17:17:45 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b21464399da814d-FRA
Open service 2a06:98c1:3121::3:443 · bassbett.org
2025-12-22 14:53
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 14:53:49 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=VYpPmWzZnE%2FBalkauQlakiMp1hCYyAvJ8%2Fy%2Bbo9puAhDmhAwhLKpj5ZBdEPSORBEP1Xm%2FwmA5JoscJDCxRetYZpnvyMrQB7%2FGtqqWlNwctHoMIQpQVCJkA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 14:53:49 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b20736e2fc7d2db-FRA
Open service 2a06:98c1:3121::3:443 · bassbett.org
2025-12-20 18:08
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 18:08:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=8i7g9K%2By15XyJ%2F84JKItT%2FgNODm4JnIMBG%2BhfwyksSGLupsMd%2FNuwyTm5SZnHP5uDLjipcNo2Bzhm%2Bwoph9P1CXU6sqSlX3j4YQ9Q4qbJWXWqgBYpgg2dQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 18:08:25 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b1115bd0bb2d2e3-FRA
Open service 188.114.97.3:443 · bassbett.org
2025-12-20 17:18
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 17:18:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=i9fL40sgwymZRYm6nLksHMYPr3fakBP9PCvtT4y74K7stdGgfbSNqBZANCVrpIPlBLjYV6YVCiXPkIVJ%2FcCAalj76R5mzgxEwg6BHA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 17:18:25 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=25,cfOrigin;dur=877
CF-RAY: 9b10cc7b7bf5dd37-EWR
Open service 188.114.97.3:443 · bassbett.org
2025-12-19 06:46
HTTP/1.1 200 OK
Date: Fri, 19 Dec 2025 06:46:16 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=vjlWoAXcRmzGKZADp9SOd8OIaJLcIDfJn2qBfT6LGYtdU3J5e3w%2Bf7K3TPePMvY%2Bid1pUL%2F2rXS%2FI4s%2FYIT3E1CiU4L0yIyPGoH5UQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 19 Jan 2026 06:46:16 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=12,cfOrigin;dur=1157
CF-RAY: 9b04f11b6806833c-SIN