Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 20.105.224.34:443 · beta-epsiloniris.epsilonnet.gr
2026-01-22 19:43
HTTP/1.1 200 OK
Connection: close
Content-Type: text/html; charset=utf-8
Date: Thu, 22 Jan 2026 19:44:19 GMT
Server: Kestrel
Transfer-Encoding: chunked
Request-Context: appId=cid-v1:360900d6-555f-4916-b915-8e2b40407c8c
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy: credentialless
Cross-Origin-Resource-Policy: same-site
Content-Security-Policy: object-src 'none'; form-action 'self'; frame-ancestors 'none'; style-src https: 'self' 'unsafe-inline'; block-all-mixed-content; img-src https: data: 'self'; font-src https:; base-uri 'self'; script-src 'self' https: https://challenges.cloudflare.com 'unsafe-eval' 'unsafe-inline'
Permissions-Policy: accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=*, geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), sync-xhr=(), usb=()
Page title: Epsilon Iris
<!DOCTYPE html>
<html lang="en" class="epsilonIris">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />
<title>Epsilon Iris</title>
<base href="/" />
<link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png">
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png">
<link rel="manifest" href="/site.webmanifest">
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Inter:ital,opsz,wght@0,14..32,100..900;1,14..32,100..900&display=swap" rel="stylesheet">
<link href="/css/fontawesome/all.min.css" rel="stylesheet" />
<link href="/css/Custom.css?v=5c076bUr5zfo2QcXZ0wFOa7Z_RLA5z_kwY9fgz8lyAs" rel="stylesheet" />
<link href="/css/App.css?v=dxXeZRiink83asYJnteksdaD5l0pGs5Rs45mDidC1Jk" rel="stylesheet" />
<link href="_content/Telerik.UI.for.Blazor/css/kendo-theme-default/all.css" rel="stylesheet"/>
</head>
<body>
<div id="app">
<div class="loader-box">
<div class="fullpage-loader"><div class="custom-loader"></div></div>
</div>
</div>
<div id="blazor-error-ui">
An unhandled error has occurred.
<a href="" class="reload">Reload</a>
<a class="dismiss">🗙</a>
</div>
<script src="js/cultureHandling.js?v=juqrzzk0fPc0FdNe6jBfu-D2NaUK76wrS_oA0gd1fo0"></script>
<script src="_framework/blazor.webassembly.js?v=-vIfWRbrna1rF-s8xknbrluJxgPx4vfKB0WJ74HdICo" autostart="true"></script>
<script src="_content/Telerik.UI.for.Blazor/js/telerik-blazor.js"></script>
<script src="js/cookieHashValidator.js?v=Ij9OVndzAJ_T07M0_LgcAA155o360Pc4-y8yXqaP8uQ"></script>
</body>
</html>
Open service 20.105.224.34:80 · beta-epsiloniris.epsilonnet.gr
2026-01-11 18:14
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sun, 11 Jan 2026 18:15:45 GMT Location: https://beta-epsiloniris.epsilonnet.gr/
Open service 20.105.224.34:443 · beta-epsiloniris.epsilonnet.gr
2026-01-11 18:14
HTTP/1.1 200 OK
Connection: close
Content-Type: text/html; charset=utf-8
Date: Sun, 11 Jan 2026 18:15:44 GMT
Server: Kestrel
Transfer-Encoding: chunked
Request-Context: appId=cid-v1:360900d6-555f-4916-b915-8e2b40407c8c
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Embedder-Policy: credentialless
Cross-Origin-Resource-Policy: same-site
Content-Security-Policy: object-src 'none'; form-action 'self'; frame-ancestors 'none'; style-src https: 'self' 'unsafe-inline'; block-all-mixed-content; img-src https: 'self'; font-src https:; base-uri 'self'; script-src 'self' https: https://challenges.cloudflare.com 'unsafe-eval' 'unsafe-inline'
Permissions-Policy: accelerometer=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=*, geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), sync-xhr=(), usb=()
Page title: Epsilon Iris
<!DOCTYPE html>
<html lang="en" class="epsilonIris">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />
<title>Epsilon Iris</title>
<base href="/" />
<link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png">
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png">
<link rel="manifest" href="/site.webmanifest">
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Inter:ital,opsz,wght@0,14..32,100..900;1,14..32,100..900&display=swap" rel="stylesheet">
<link href="/css/fontawesome/all.min.css" rel="stylesheet" />
<link href="/css/Custom.css?v=pc34RO-14X5j8GlAo1AhbodmG5UOQZaTECNhl_R-7WQ" rel="stylesheet" />
<link href="/css/App.css?v=jm0HNArnheTHyxS1sShfpm-7y647Mx6eSVUOE4l-3J0" rel="stylesheet" />
<link href="_content/Telerik.UI.for.Blazor/css/kendo-theme-default/all.css" rel="stylesheet"/>
</head>
<body>
<div id="app">
<div class="loader-box">
<div class="fullpage-loader"><div class="custom-loader"></div></div>
</div>
</div>
<div id="blazor-error-ui">
An unhandled error has occurred.
<a href="" class="reload">Reload</a>
<a class="dismiss">🗙</a>
</div>
<script src="js/cultureHandling.js?v=juqrzzk0fPc0FdNe6jBfu-D2NaUK76wrS_oA0gd1fo0"></script>
<script src="_framework/blazor.webassembly.js?v=-vIfWRbrna1rF-s8xknbrluJxgPx4vfKB0WJ74HdICo" autostart="true"></script>
<script src="_content/Telerik.UI.for.Blazor/js/telerik-blazor.js"></script>
<script src="js/cookieHashValidator.js?v=Ij9OVndzAJ_T07M0_LgcAA155o360Pc4-y8yXqaP8uQ"></script>
</body>
</html>