SLT
tcp/443 tcp/80
nginx 1.20.1
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9dda99fb9ada99fb9ada99fb9ada99fb9a
Found 1 files trough .DS_Store spidering: /static
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9dda99fb9ada99fb9ada99fb9ada99fb9a
Found 1 files trough .DS_Store spidering: /static
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Open service 221.204.15.51:443 · www.bkz.cn
2026-01-22 22:01
HTTP/1.1 418 Unknown Status Content-Length: 0 X-NWS-LOG-UUID: 515459610388506686 Connection: close Server: SLT Date: Thu, 22 Jan 2026 22:01:24 GMT X-Cache-Lookup: Return Directly
Open service 116.162.169.14:443 · bkz.cn
2026-01-22 21:54
HTTP/1.1 418 Unknown Status Content-Length: 0 X-NWS-LOG-UUID: 4174912796786253344 Connection: close Server: SLT Date: Thu, 22 Jan 2026 21:55:10 GMT X-Cache-Lookup: Return Directly
Open service 221.204.209.225:80 · www.bkz.cn
2026-01-22 20:12
HTTP/1.1 418 Unknown Status Content-Length: 0 X-NWS-LOG-UUID: 957151338974356359 Connection: close Server: SLT Date: Thu, 22 Jan 2026 20:12:42 GMT X-Cache-Lookup: Return Directly
Open service 47.83.25.201:80 · station-admin.bkz.cn
2026-01-10 06:06
HTTP/1.1 301 Moved Permanently Server: nginx/1.20.1 Date: Sat, 10 Jan 2026 06:06:08 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://station-admin.bkz.cn/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.20.1</center> </body> </html>
Open service 47.83.25.201:443 · station-admin.bkz.cn
2026-01-10 06:06
HTTP/1.1 200 OK
Server: nginx/1.20.1
Date: Sat, 10 Jan 2026 06:06:04 GMT
Content-Type: text/html
Content-Length: 5818
Last-Modified: Fri, 02 Jan 2026 04:37:12 GMT
Connection: close
ETag: "69574b78-16ba"
Accept-Ranges: bytes
Page title: 站群后台管理系统
<!DOCTYPE html><html><head><meta charset=utf-8><meta http-equiv=X-UA-Compatible content="IE=edge,chrome=1"><meta name=renderer content=webkit><meta name=viewport content="width=device-width,initial-scale=1,maximum-scale=1,user-scalable=no"><title>站群后台管理系统</title><link rel="shortcut icon" href=/favicon.ico><link href=/static/css/chunk-elementUI.4df39dd2.css rel=stylesheet><link href=/static/css/chunk-libs.825f9043.css rel=stylesheet><link href=/static/css/app.cd8c36f7.css rel=stylesheet></head><body><script src=/static/tinymce/tinymce.min.js></script><div id=app></div><script>(f=>{function n(n){for(var e,c,u=n[0],t=n[1],r=n[2],h=0,a=[];h<u.length;h++)c=u[h],d[c]&&a.push(d[c][0]),d[c]=0;for(e in t)Object.prototype.hasOwnProperty.call(t,e)&&(f[e]=t[e]);for(s&&s(n);a.length;)a.shift()();return k.push.apply(k,r||[]),o()}function o(){for(var n,e=0;e<k.length;e++){for(var c=k[e],u=!0,t=1;t<c.length;t++){var r=c[t];0!==d[r]&&(u=!1)}u&&(k.splice(e--,1),n=i(i.s=c[0]))}return n}var c={},a={runtime:0},d={runtime:0},k=[];function i(n){var e;return(c[n]||(e=c[n]={i:n,l:!1,exports:{}},f[n].call(e.exports,e,e.exports,i),e.l=!0,e)).exports}i.e=function(k){var n,t,e,r,c,u=[],h=(a[k]?u.push(a[k]):0!==a[k]&&{"chunk-3473":1,"chunk-3a7f":1,"chunk-4dc7":1,"chunk-4fde":1,"chunk-5759":1,"chunk-7440":1,"chunk-commons":1,"chunk-010a":1,"chunk-1859":1,"chunk-220c":1,"chunk-2ff6":1,"chunk-1e81":1,"chunk-c722":1,"chunk-5207":1,"chunk-5efb":1,"chunk-626f":1,"chunk-67aa":1,"chunk-738c":1,"chunk-a733":1,"chunk-b135":1,"chunk-011e":1,"chunk-12f2":1,"chunk-3a3f":1,"chunk-f091":1,"chunk-f229":1}[k]&&u.push(a[k]=new Promise(function(n,c){for(var e="static/css/"+({"chunk-commons":"chunk-commons"}[k]||k)+"."+{"7zzA":"31d6cfe0",JEtC:"31d6cfe0","chunk-091c":"31d6cfe0","chunk-3473":"a170c1b2","chunk-3a7f":"40afe9ad","chunk-48d5":"31d6cfe0","chunk-4dc7":"7586e0f5","chunk-4fde":"8d5a0e28","chunk-5759":"642db4e6","chunk-6e07":"31d6cfe0","chunk-7440":"9f9c453f","chunk-commons":"f863789b","chunk-010a":"a756b561","chunk-1859":"3560f17c","chunk-220c":"03832e17","chunk-c7b0":"31d6cfe0","chunk-2ff6":"7c49c017","chunk-637f":"31d6cfe0","chunk-1e81":"f5a496e4","chunk-c722":"1da012fb","chunk-5207":"8f39dcff","chunk-5efb":"510ee50a","chunk-626f":"90091706","chunk-67aa":"66e5d7d8","chunk-738c":"94b5a590","chunk-a733":"c2430542","chunk-b135":"51543d29","chunk-bb1a":"31d6cfe0","chunk-011e":"17787f70","chunk-12f2":"e4528e44","chunk-3a3f":"0a41183d","chunk-f091":"676ba582","chunk-f229":"d199c239","chunk-3e35":"31d6cfe0","chunk-17b5":"31d6cfe0"}[k]+".css",u=i.p+e,t=document.getElementsByTagName("link"),r=0;r<t.length;r++){var h=(a=t[r]).getAttribute("data-href")||a.getAttribute("href");if("stylesheet"===a.rel&&(h===e||h===u))return n()}for(var a,f=document.getElementsByTagName("style"),r=0;r<f.length;r++)if((h=(a=f[r]).getAttribute("data-href"))===e||h===u)return n();var o=document.createElement("link");o.rel="stylesheet",o.type="text/css",o.onload=n,o.onerror=function(n){var n=n&&n.target&&n.target.src||u,e=new Error("Loading CSS chunk "+k+" failed.\n("+n+")");e.request=n,c(e)},o.href=u,document.getElementsByTagName("head")[0].appendChild(o)}).then(function(){a[k]=0})),d[k]);return 0!==h&&(h?u.push(h[2]):(n=new Promise(function(n,e){h=d[k]=[n,e]}),u.push(h[2]=n),n=document.getElementsByTagName("head")[0],(t=document.createElement("script")).charset="utf-8",t.timeout=120,i.nc&&t.setAttribute("nonce",i.nc),t.src=i.p+"static/js/"+({"chunk-commons":"chunk-commons"}[c=k]||c)+"."+{"7zzA":"7cec4e01",JEtC:"039b92ca","chunk-091c":"40a42fa3","chunk-3473":"65198c0d","chunk-3a7f":"fe5b3097","chunk-48d5":"a05dce1f","chunk-4dc7":"ac297d2f","chunk-4fde":"08099422","chunk-5759":"7b8adefb","chunk-6e07":"061d20f3","chunk-7440":"4582601b","chunk-commons":"55a0a08d","chunk-010a":"126cb050","chunk-1859":"47b20fba","chunk-220c":"55fe808b","chunk-c7b0":"771c38fd","chunk-2ff6":"0596aa19","chunk-637f":"04b0f450","chunk-1e81":"ad77b3f8","chunk-c722":"645fa646","chunk-5207":"b4d1aca0","chunk-5efb":"24c80022","chunk-626f":"a89893a2","chunk-67aa":"bd4f2af0","chunk-738c":"06dbfd26","chunk-a733"
Open service 47.83.25.201:443 · b.bkz.cn
2026-01-05 15:35
HTTP/1.1 500 Internal Server Error
Server: nginx/1.20.1
Date: Mon, 05 Jan 2026 15:36:00 GMT
Content-Type: text/html;charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Content-Language: zh-
Page title: 500 pages
<html>
<head>
<title>500 pages</title>
</head>
<body>
<h2 style="color: red;">Server exception!</h2>
<a href="/">Back to Home</a>
</body>
</html>
Open service 47.83.25.201:80 · b.bkz.cn
2026-01-05 15:35
HTTP/1.1 301 Moved Permanently Server: nginx/1.20.1 Date: Mon, 05 Jan 2026 15:35:53 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://b.bkz.cn/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.20.1</center> </body> </html>
Open service 47.83.25.201:443 · a.bkz.cn
2026-01-05 15:35
HTTP/1.1 500 Internal Server Error
Server: nginx/1.20.1
Date: Mon, 05 Jan 2026 15:35:43 GMT
Content-Type: text/html;charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Content-Language: zh-
Page title: 500 pages
<html>
<head>
<title>500 pages</title>
</head>
<body>
<h2 style="color: red;">Server exception!</h2>
<a href="/">Back to Home</a>
</body>
</html>
Open service 47.83.25.201:80 · a.bkz.cn
2026-01-05 15:35
HTTP/1.1 301 Moved Permanently Server: nginx/1.20.1 Date: Mon, 05 Jan 2026 15:35:37 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://a.bkz.cn/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.20.1</center> </body> </html>
Open service 47.83.25.201:443 · c.bkz.cn
2026-01-05 15:34
HTTP/1.1 500 Internal Server Error
Server: nginx/1.20.1
Date: Mon, 05 Jan 2026 15:34:28 GMT
Content-Type: text/html;charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Content-Language: zh-
Page title: 500 pages
<html>
<head>
<title>500 pages</title>
</head>
<body>
<h2 style="color: red;">Server exception!</h2>
<a href="/">Back to Home</a>
</body>
</html>