cloudflare
tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c7cf176427cf176427eaedafc18487a2818487a2818487a28
Found 2 files trough .DS_Store spidering: /bp_config /img
Open service 172.67.185.196:80 · carstorageco.com
2026-01-09 09:31
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 09:31:20 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
set-cookie: PHPSESSID=u1pguv90bsvt3e31sp4kcdho1a; path=/; secure; HttpOnly; SameSite=Strict
expires: 0
cache-control: no-cache, no-store, must-revalidate
pragma: no-cache
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=18,cfOrigin;dur=149
vary: Origin
vary: accept-encoding
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
access-control-allow-methods: GET, POST, OPTIONS
access-control-allow-headers: Content-Type, Authorization
access-control-allow-credentials: true
edit: Set-Cookie ^(.*)$ "$1; HttpOnly; SameSite=Lax"
server: cloudflare
x-powered-by: ASP.NET
x-turbo-charged-by: LiteSpeed
cf-cache-status: DYNAMIC
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=r6TDIe9lrOUBxgkNxmRGUc2GDt0fFrRGYNHYka9EtwFdG5mgntuGpIJq1%2FLocQF2nbrBMZLcTs2wBpfcE1Zdr24kr5FjeEhCidm0984z"}]}
CF-RAY: 9bb2ebcf1b260cc2-EWR
alt-svc: h3=":443"; ma=86400
Open service 172.67.185.196:80 · carstorageco.com
2026-01-02 07:56
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 07:56:40 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
set-cookie: PHPSESSID=fl2a28m1l94emhpu4ghlfukiho; path=/; secure; HttpOnly; SameSite=Strict
expires: 0
cache-control: no-cache, no-store, must-revalidate
pragma: no-cache
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=d9UgzH%2FhEet1qtBv7CS96qesjcAlyMemjrMROOTOdisaPnkDGihFzYMECScFhQUqZICEucIVQzmHQ9zNgkozwHUIdGZYwU7vfhKodtl8o60%3D"}]}
vary: Origin
vary: accept-encoding
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
access-control-allow-methods: GET, POST, OPTIONS
access-control-allow-headers: Content-Type, Authorization
access-control-allow-credentials: true
edit: Set-Cookie ^(.*)$ "$1; HttpOnly; SameSite=Lax"
server: cloudflare
x-powered-by: ASP.NET
x-turbo-charged-by: LiteSpeed
cf-cache-status: DYNAMIC
CF-RAY: 9b78b38169f19f2f-FRA
alt-svc: h3=":443"; ma=86400
Open service 172.67.185.196:80 · carstorageco.com
2025-12-23 03:30
HTTP/1.1 200 OK
Date: Tue, 23 Dec 2025 03:30:45 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
set-cookie: PHPSESSID=130ntber750jpnb6jbe7iu30ka; path=/; secure; HttpOnly; SameSite=Strict
expires: 0
cache-control: no-cache, no-store, must-revalidate
pragma: no-cache
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ovVDxo07ZU1aOuFlbhu7KfZnAxL%2FmdkASQ0K6bYCf9x4OEVPGup5n9fnEaJgdI%2Fp6nH7%2B2P66kFOy1Zi%2FljuoG0Cn%2Fii5AwUM5OD1ibcl94%3D"}]}
vary: Origin
vary: accept-encoding
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
access-control-allow-methods: GET, POST, OPTIONS
access-control-allow-headers: Content-Type, Authorization
access-control-allow-credentials: true
edit: Set-Cookie ^(.*)$ "$1; HttpOnly; SameSite=Lax"
server: cloudflare
x-powered-by: ASP.NET
x-turbo-charged-by: LiteSpeed
cf-cache-status: DYNAMIC
CF-RAY: 9b24c83a0e8fae0b-FRA
alt-svc: h3=":443"; ma=86400
Open service 172.67.185.196:80 · carstorageco.com
2025-12-21 01:57
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 01:57:28 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
set-cookie: PHPSESSID=v861ntin3ign6n93rktk4o5ftj; path=/; secure; HttpOnly; SameSite=Strict
expires: 0
cache-control: no-cache, no-store, must-revalidate
pragma: no-cache
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=120
vary: Origin
vary: accept-encoding
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
referrer-policy: strict-origin-when-cross-origin
access-control-allow-methods: GET, POST, OPTIONS
access-control-allow-headers: Content-Type, Authorization
access-control-allow-credentials: true
edit: Set-Cookie ^(.*)$ "$1; HttpOnly; SameSite=Lax"
server: cloudflare
x-powered-by: ASP.NET
x-turbo-charged-by: LiteSpeed
cf-cache-status: DYNAMIC
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=avGeYstAhTtEr0qXTXPSXRbNDnCOcFI%2Fc9gpgJKGlEPoc1YYIHAwuGQotcRgYu8cpj%2F1b4JByeQR3BUs2tMyYFhUI%2FyZKguGPONoOlCMBvo%3D"}]}
CF-RAY: 9b13c4d17fef28db-YYZ
alt-svc: h3=":443"; ma=86400