Apache
tcp/443
nginx
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c026392ab026392abce2ca2e7dc0235c284a12c0298238456
Found 7 files trough .DS_Store spidering: /bo /build /css /img /index.php /js /uploads
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07a87a8c4ea87a8c4ea87a8c4ea87a8c4ea87a8c4e
Symfony profiler enabled: https://carfit.olro.idp.lu/_profiler/empty/search/results
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2026-01-09 16:46
HTTP/1.1 200 OK Date: Fri, 09 Jan 2026 16:46:25 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-fLoS+qLcWS5x/fBFkntF5w==' 'nonce-0262a8527b14ff07a58a41a501143c14'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-fLoS+qLcWS5x/fBFkntF5w==' 'nonce-0262a8527b14ff07a58a41a501143c14'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: cc5dc1 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/cc5dc1 X-Robots-Tag: noindex Expires: Fri, 09 Jan 2026 16:46:26 GMT Set-Cookie: PHPSESSID=vk03kso47hmqu5q6086mcv2796; expires=Sun, 11-Jan-2026 16:46:26 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 149.202.89.160:443 · carfit.olro.idp.lu
2026-01-09 16:03
HTTP/1.1 200 OK Server: nginx Date: Fri, 09 Jan 2026 16:03:37 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.2.30 Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin pragma: no-cache Expires: Fri, 09 Jan 2026 16:03:37 GMT X-Frame-Options: DENY Content-Security-Policy: font-src 'self' fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com cdnjs.cloudflare.com code.ionicframework.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com cdn.cookielaw.org unpkg.com cdn.datatables.net cdn.tiny.cloud cdn.ckeditor.com cdnjs.cloudflare.com www.paypal.com ga.jspm.io 'nonce-pt1io6mpjWnIo3hOZmskCg==' 'nonce-1c59abcdec2f24029489c0e0cf67dbe4'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com cdnjs.cloudflare.com stackpath.bootstrapcdn.com code.ionicframework.com cdn.datatables.net cdn.tiny.cloud www.paypal.com; report-uri /nelmio/csp/report X-Content-Security-Policy: font-src 'self' fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com cdnjs.cloudflare.com code.ionicframework.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com cdn.cookielaw.org unpkg.com cdn.datatables.net cdn.tiny.cloud cdn.ckeditor.com cdnjs.cloudflare.com www.paypal.com ga.jspm.io 'nonce-pt1io6mpjWnIo3hOZmskCg==' 'nonce-1c59abcdec2f24029489c0e0cf67dbe4'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com cdnjs.cloudflare.com stackpath.bootstrapcdn.com code.ionicframework.com cdn.datatables.net cdn.tiny.cloud www.paypal.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: fa63c1 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/fa63c1 X-Robots-Tag: noindex Set-Cookie: PHPSESSID=78fjqj1job4lp5gsmf5hui27i3; expires=Sun, 11 Jan 2026 16:03:37 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax X-Powered-By: PleskLin
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2026-01-08 20:40
HTTP/1.1 200 OK Date: Thu, 08 Jan 2026 20:40:29 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-zjbPCXa7kh0TKtdDkZ1qyg==' 'nonce-9114f1a7d2ac2e5b072f70f906583f32'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-zjbPCXa7kh0TKtdDkZ1qyg==' 'nonce-9114f1a7d2ac2e5b072f70f906583f32'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: b59932 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/b59932 X-Robots-Tag: noindex Expires: Thu, 08 Jan 2026 20:40:29 GMT Set-Cookie: PHPSESSID=ijhktbhcqeg609v55l3tjt6a0v; expires=Sat, 10-Jan-2026 20:40:29 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2026-01-02 23:53
HTTP/1.1 200 OK Date: Fri, 02 Jan 2026 23:53:42 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-yZNKafz2whD+LSQ2KIbsxw==' 'nonce-15db8840944220e64fde59918749fc45'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-yZNKafz2whD+LSQ2KIbsxw==' 'nonce-15db8840944220e64fde59918749fc45'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: 8a0412 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/8a0412 X-Robots-Tag: noindex Expires: Fri, 02 Jan 2026 23:53:42 GMT Set-Cookie: PHPSESSID=ngf87c93cj7obfro3gnj9fpgqn; expires=Sun, 04-Jan-2026 23:53:42 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2026-01-01 21:00
HTTP/1.1 200 OK Date: Thu, 01 Jan 2026 21:00:59 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-YglbAR0ciqLohnc5D/q+uw==' 'nonce-3326766b600c28d374b7d4de23c019fa'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-YglbAR0ciqLohnc5D/q+uw==' 'nonce-3326766b600c28d374b7d4de23c019fa'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: c11916 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/c11916 X-Robots-Tag: noindex Expires: Thu, 01 Jan 2026 21:01:00 GMT Set-Cookie: PHPSESSID=h9546sdbe1hqbpc51ctt1mtnkj; expires=Sat, 03-Jan-2026 21:01:00 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2025-12-30 05:13
HTTP/1.1 200 OK Date: Tue, 30 Dec 2025 05:13:19 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-H48I7NXs3wb1v3toSxBCAQ==' 'nonce-c424d727e2b0cf388a6042abb7c3c43d'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-H48I7NXs3wb1v3toSxBCAQ==' 'nonce-c424d727e2b0cf388a6042abb7c3c43d'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: 9ca797 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/9ca797 X-Robots-Tag: noindex Expires: Tue, 30 Dec 2025 05:13:19 GMT Set-Cookie: PHPSESSID=2vaimr3a56nd41gdlb6al33k57; expires=Thu, 01-Jan-2026 05:13:19 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2025-12-23 07:37
HTTP/1.1 200 OK Date: Tue, 23 Dec 2025 07:37:09 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-FQmOSxeOT/nuwYWdJEoRSg==' 'nonce-a04d1abf55daced8b97bc00d7484567a'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-FQmOSxeOT/nuwYWdJEoRSg==' 'nonce-a04d1abf55daced8b97bc00d7484567a'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: f965dc X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/f965dc X-Robots-Tag: noindex Expires: Tue, 23 Dec 2025 07:37:09 GMT Set-Cookie: PHPSESSID=bbc9jgbfboi4pobclue72c1dg5; expires=Thu, 25-Dec-2025 07:37:09 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2025-12-23 05:21
HTTP/1.1 200 OK Date: Tue, 23 Dec 2025 05:21:41 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-XFmxnI1K3nf1gTskWYbG5w==' 'nonce-5a6f996bdae0435bb62168699645ba9f'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-XFmxnI1K3nf1gTskWYbG5w==' 'nonce-5a6f996bdae0435bb62168699645ba9f'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: 7de3d3 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/7de3d3 X-Robots-Tag: noindex Expires: Tue, 23 Dec 2025 05:21:41 GMT Set-Cookie: PHPSESSID=kps80l7flv2pn3gisqrpuon2t6; expires=Thu, 25-Dec-2025 05:21:41 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2025-12-21 05:35
HTTP/1.1 200 OK Date: Sun, 21 Dec 2025 05:35:05 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-bq4Fpawtj0+/wnq6O/JLOg==' 'nonce-ee9700b7d5ec0748aaa46858160b1435'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-bq4Fpawtj0+/wnq6O/JLOg==' 'nonce-ee9700b7d5ec0748aaa46858160b1435'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: a1b76b X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/a1b76b X-Robots-Tag: noindex Expires: Sun, 21 Dec 2025 05:35:05 GMT Set-Cookie: PHPSESSID=6t9ttqhac36h76k7maq7mn08vv; expires=Tue, 23-Dec-2025 05:35:05 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2025-12-21 02:39
HTTP/1.1 200 OK Date: Sun, 21 Dec 2025 02:39:49 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-fcYh3v88dncuSDQXuBDsBQ==' 'nonce-4a97aed05435582cc5900df5cc199ee1'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-fcYh3v88dncuSDQXuBDsBQ==' 'nonce-4a97aed05435582cc5900df5cc199ee1'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: ded871 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/ded871 X-Robots-Tag: noindex Expires: Sun, 21 Dec 2025 02:39:49 GMT Set-Cookie: PHPSESSID=1mccd27msnddtv3cgpg9bu61ap; expires=Tue, 23-Dec-2025 02:39:49 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 157.90.88.250:443 · carfit.olro.idp.lu
2025-12-19 04:05
HTTP/1.1 200 OK Date: Fri, 19 Dec 2025 04:05:04 GMT Server: Apache Cache-Control: max-age=0, must-revalidate, private X-Content-Type-Options: nosniff Referrer-Policy: no-referrer, strict-origin-when-cross-origin X-Frame-Options: DENY Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-P057m/yXAQfFHvMnbitOng==' 'nonce-a71d8786d7b95ac2773c9855581cbc22'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-Content-Security-Policy: block-all-mixed-content ; font-src fonts.googleapis.com pro.fontawesome.com use.typekit.net p.typekit.net fonts.gstatic.com widget-v3.smartsuppcdn.com; frame-ancestors 'none'; script-src 'self' 'unsafe-inline' cdn.jsdelivr.net code.jquery.com maps.googleapis.com js.stripe.com www.smartsuppchat.com losch.lu widget-v3.smartsuppcdn.com 'nonce-P057m/yXAQfFHvMnbitOng==' 'nonce-a71d8786d7b95ac2773c9855581cbc22'; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdn.jsdelivr.net pro.fontawesome.com use.typekit.net p.typekit.net widget-v3.smartsuppcdn.com; report-uri /nelmio/csp/report X-XSS-Protection: 1; mode=block; report=/nelmio/xss/report X-Debug-Token: 4bc596 X-Debug-Token-Link: https://carfit.olro.idp.lu/_profiler/4bc596 X-Robots-Tag: noindex Expires: Fri, 19 Dec 2025 04:05:04 GMT Set-Cookie: PHPSESSID=g1fhtsdb0flr2rnvec3bbucmgv; expires=Sun, 21-Dec-2025 04:05:04 GMT; Max-Age=172800; path=/; secure; httponly; samesite=lax Vary: Accept-Encoding Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8