CloudPanel 2.5.3
tcp/8443
cloudflare
tcp/443 tcp/80 tcp/8443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522de891246
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://zahidprimex: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@github.com/zahidprimex/boombae.com.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e49b7a9f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://zahidprimex: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@github.com/zahidprimex/boombae.com.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 104.21.53.245:80 · boombae.com
2026-01-24 09:51
HTTP/1.1 301 Moved Permanently
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Length: 0
Connection: close
Location: https://boombae.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ldztJyiStH%2FJGkrhlMES3a%2BXwOAaFEgaNd%2FCYnWTxPjcnThmWFGntc672svB5Rb0gGC1y8jMlyN3mkSaxSADI6dYSbSXyD8m4MqB"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=7,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c2ea1e53b9e37c1-SJC
alt-svc: h3=":443"; ma=86400
Open service 2606:4700:3037::ac43:dd1c:443 · boombae.com
2026-01-24 09:51
HTTP/1.1 200 OK
Date: Sat, 24 Jan 2026 09:51:28 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=H1%2F16HeXhkrQfgz1ANlVS5hLBWQKtB1wresYGLX8YPKW6PvPqguRZLJ3A96cWo%2Bmx5s43yVVI3b1YITVDMVC8HLxj5OnIGFm%2Fb5iD8er5xbDExPKLg5g"}]}
wpo-cache-status: cached
last-modified: Fri, 23 Jan 2026 11:08:02 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-permitted-cross-domain-policies: master-only
referrer-policy: same-origin
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
vary: accept-encoding
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=216
CF-RAY: 9c2ea1e7eb91437b-EWR
Open service 172.67.221.28:80 · boombae.com
2026-01-24 09:51
HTTP/1.1 301 Moved Permanently
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Length: 0
Connection: close
Location: https://boombae.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=r5l5Jpl8x5mB8uUHVvY%2B6U1S6B9l%2FBcfbs2Z9uNzy8NusXVNEarX8aXp30dZqPIHZWfxgb%2Fx%2F9%2B4PWNMDmODINAsR5g0pXJzhWnt"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=7,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c2ea1e4d8cbb1f3-EWR
alt-svc: h3=":443"; ma=86400
Open service 2606:4700:3034::6815:35f5:443 · boombae.com
2026-01-24 09:51
HTTP/1.1 200 OK
Date: Sat, 24 Jan 2026 09:51:28 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=0juqb%2FfaxAixvjQVCw0j1v6eGEI0nuo245kahv%2FxvEffvec31WF3SPCKf5FOU3pFFH6dT%2B8Gi34cXoTbwwjIUnii%2Bnn24gwZ99P38ZalvQU7fXP%2FPAhB"}]}
wpo-cache-status: cached
last-modified: Fri, 23 Jan 2026 11:08:02 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-permitted-cross-domain-policies: master-only
referrer-policy: same-origin
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
vary: accept-encoding
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=460
CF-RAY: 9c2ea1e7bc790f79-EWR
Open service 2606:4700:3037::ac43:dd1c:8443 · boombae.com
2026-01-24 09:51
HTTP/1.1 302 Found
Date: Sat, 24 Jan 2026 09:51:28 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: max-age=0, must-revalidate, private
location: /login
expires: Sat, 24 Jan 2026 09:51:28 GMT
Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax
Set-Cookie: cloudpanel=v8o097hpr0qv8u4gqseltd1e4v; path=/; secure; httponly; samesite=lax
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=430
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=K3qB5RKudwvhiEqHRVdAvHvkmXWr%2FmOpVshL4rmb0buxxuDj0FDzlyBJJMxSeAIyrjy2DtwD9cduL6S7toHyhe8nhx3q5VcvQ%2B2Z3XXDZkInKr2sr3P7"}]}
CF-RAY: 9c2ea1e7bf34398d-YYZ
alt-svc: h3=":8443"; ma=86400
Page title: Redirecting to /login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/login'" />
<title>Redirecting to /login</title>
</head>
<body>
Redirecting to <a href="/login">/login</a>.
<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"43ae8e92227b4734ba2d3a524384cbfc","r":1,"server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body>
</html>
Open service 2606:4700:3034::6815:35f5:80 · boombae.com
2026-01-24 09:51
HTTP/1.1 301 Moved Permanently
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Length: 0
Connection: close
Location: https://boombae.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=8YEsGKFWBY9iXSMrkUGwtuCHhew5rK2zOf%2FO6FjmHpQUV6h%2BOA6Hkk17DlFW7snUisdakuLNqGsllJksfojwx3myVgKaBtwS6QeXcJAu7pmXe%2Bl6PrCR"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfEdge;dur=7,cfOrigin;dur=0
Server: cloudflare
CF-RAY: 9c2ea1e4ef9c64a6-YYZ
alt-svc: h3=":443"; ma=86400
Open service 2606:4700:3034::6815:35f5:8443 · boombae.com
2026-01-24 09:51
HTTP/1.1 302 Found
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: max-age=0, must-revalidate, private
location: /login
expires: Sat, 24 Jan 2026 09:51:27 GMT
Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax
Set-Cookie: cloudpanel=qb22i0v3ll1lb5l56qph7pl6bg; path=/; secure; httponly; samesite=lax
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=qDXLEpCn9pUsbptW7ZkiqDmzVpdpEbewC3%2FC5VvrpnJVdMp8v2MnUUXTf1n%2BPYd8GqVoaaA8SRuC6X7OQ0H6UkUsD8eS8ukfQxplAYoo1j0FwvGIxnxW"}]}
CF-RAY: 9c2ea1e53cf1dc78-FRA
alt-svc: h3=":8443"; ma=86400
Page title: Redirecting to /login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/login'" />
<title>Redirecting to /login</title>
</head>
<body>
Redirecting to <a href="/login">/login</a>.
</body>
</html>
Open service 104.21.53.245:8443 · boombae.com
2026-01-24 09:51
Found CloudPanel version: 2.5.3
Open service 104.21.53.245:8443 · boombae.com
2026-01-24 09:51
HTTP/1.1 302 Found
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: max-age=0, must-revalidate, private
location: /login
expires: Sat, 24 Jan 2026 09:51:27 GMT
Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax
Set-Cookie: cloudpanel=tlan5l83fs3ve8o73s6mg5blhv; path=/; secure; httponly; samesite=lax
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Q50fO9sVvZAWJJv0NBbKgM2FpSYiWXvSPlIAgv6srLeM1j%2BeXsJ%2FAn89JwZ36iCbS3IsqoNsaY%2BeTJO5YL22lM7TqcZVK8rUEsKo"}]}
CF-RAY: 9c2ea1e599d4b6cd-LHR
alt-svc: h3=":8443"; ma=86400
Page title: Redirecting to /login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/login'" />
<title>Redirecting to /login</title>
</head>
<body>
Redirecting to <a href="/login">/login</a>.
</body>
</html>
Open service 104.21.53.245:443 · boombae.com
2026-01-24 09:51
HTTP/1.1 200 OK
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=1Q%2B3W%2F8Eocf97wTAzhHAS6ebtM%2FmzvFDVMg2PNY7D6f%2F0ocLJBL0Zl0mWylkw1UuJ1bCJx5uPnoDk%2F6RlzfFYn2eML3TaWnpJvWC"}]}
wpo-cache-status: cached
last-modified: Fri, 23 Jan 2026 11:08:02 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-permitted-cross-domain-policies: master-only
referrer-policy: same-origin
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
vary: accept-encoding
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9c2ea1e53d6ed22f-FRA
Open service 172.67.221.28:443 · boombae.com
2026-01-24 09:51
HTTP/1.1 200 OK
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=wEOdXGZLWA%2BAKAMheEt5bVQi4GjDawrDohDfP2WVZRMJH9KhvQrZEK680Hn76FgK5Oqb4bxno9LGC2wCZHvU9RatoVQC9Y2UN0pd"}]}
wpo-cache-status: cached
last-modified: Fri, 23 Jan 2026 11:08:02 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-permitted-cross-domain-policies: master-only
referrer-policy: same-origin
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
vary: accept-encoding
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9c2ea1e51ed1d39e-FRA
Open service 2606:4700:3037::ac43:dd1c:80 · boombae.com
2026-01-24 09:51
HTTP/1.1 301 Moved Permanently
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Length: 0
Connection: close
Location: https://boombae.com/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=fP3VHStMGey%2FoyJF7%2Bk3uC%2BQKMtWp7bZmQhK8ywfLP%2BOM0tkz3reTFYTRyrtyZi%2FDn8GY2H0OpKvUcpO1hRL1EXcYpX89johpeduZMbzcK6sSXgW%2FZNc"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server: cloudflare
CF-RAY: 9c2ea1e46da065f5-AMS
alt-svc: h3=":443"; ma=86400
Open service 172.67.221.28:8443 · boombae.com
2026-01-24 09:51
Found CloudPanel version: 2.5.3
Open service 172.67.221.28:8443 · boombae.com
2026-01-24 09:51
HTTP/1.1 302 Found
Date: Sat, 24 Jan 2026 09:51:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: max-age=0, must-revalidate, private
location: /login
expires: Sat, 24 Jan 2026 09:51:27 GMT
Set-Cookie: locale=en; path=/; secure; httponly; samesite=lax
Set-Cookie: cloudpanel=rd79k68kp7u9o5o1lir3h8otkk; path=/; secure; httponly; samesite=lax
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=zHypf%2B%2BoK%2F6dJP5ogfrfqI4ZR%2BdXWQ%2BlZx7%2FRROycAN9CzDmfk1Jy%2Fu1R%2Bg7xF5HCASwr392qLANSiZeBRvZVW8%2BI1OUuCkJL0%2Fb"}]}
CF-RAY: 9c2ea1e50f6f35e8-FRA
alt-svc: h3=":8443"; ma=86400
Page title: Redirecting to /login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/login'" />
<title>Redirecting to /login</title>
</head>
<body>
Redirecting to <a href="/login">/login</a>.
</body>
</html>