Apache
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa37dd2db492eb743ebbd7f0c0cdef2a19a5e28dcda
GraphQL introspection enabled at /graphql Types: 55 (by kind: ENUM: 10, INPUT_OBJECT: 6, OBJECT: 33, SCALAR: 6) Operations: - Query: Query | fields: me, product, products, shopInfo, shoppingCart - Mutation: Mutation | fields: addToCart, loginWeb, removeFromCart, removeFromWaitlist, updateCartQuantity Directives: deprecated, include, skip (total: 3)
Open service 151.101.130.132:443 · chicshackboutique.com
2026-01-10 01:32
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 383b9410-8010-4a7b-949f-1bd5cb8b33c8 Set-Cookie: laravel_session=eyJpdiI6ImYwcDVPaU1JVFJ4SlR6QitVb1N5UlE9PSIsInZhbHVlIjoiWmk2Ynh0VFJqdmw0a2hEa0g0M0tjc3NSaXpwTmUvblo2Vk9FN3p1S2s0WG9BOWJ5YVBCL3hHajJpUHVTUTFScERSWVF5Y3kwWmUrSUY5RUZ0dDUrVkhxQnpVRFFpOTRMWXBpdjZkakhaSVRoWEpkcU1GbEIrZjQvNk5iOXZFOXEiLCJtYWMiOiI5ZTFjMmMyN2VhN2M0NDM3ZWIyZjY1NGRiODFlMzcwOTM1M2Q4NDAxZmRlODExZTRmNDRjMGUzOTFlN2RiOGQ2IiwidGFnIjoiIn0%3D; expires=Wed, 11 Mar 2026 01:32:27 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: ky2o1Q35tVovMOqE2NdUuUCRY4jk6nWGAN6VLYYF=eyJpdiI6InpMeHNDQ2lYRURxU1lrOHNlVDlPTXc9PSIsInZhbHVlIjoicUNHVVVuSTdXcnF1UXFTNkYyRHRDL2pwV1F3bVdRUFAwaHdEeVR0UFVHaWZhenBkTXRQUngyMnQ1VXBiaG51OVNxS2xZS1FzU1U0RWtkaUdPcm8vWWJyaTRyZENCbGFKaytXN0NRTGJUd2R5eldIZEd4d0VoVHo3RjAybHQwblhnekFNNzI1ZEVZRVhIVVEzcVF3RVVicXJxZ2tURHZFbWROOCtTVVp1Y3hiUTNjVUkrUWRXTU5wOXg0anFyZSswNitmZ0dXSzduWk5nWTlpNTg4VVpJMW42ZXErblBoMktoZG9tUXY1WW5jMHR3aXg0aWdueU0rbSt0dHFoQWhvTWdlbTRpdzhJN1U0aE44eU5yVjFJaVcyc3hray9IWTJsZDRJZVhDT3BNUWtUNHphbzliT2VDTGcrMjFLV2pvRmFtbzM2NC9WVFlCM3I1YmpMWlE1VnBvZk5GUkVVclBvT05US092N01IdE93UjhBZ3VKWFlNNk1tc3JKSGZDNXpyUmNsbUFZc0dIQmVJTEFMVHlWS0Z4RHFQbWJKMmp6aE51RUdycTNYVkM1NVd0NExqYUo0M3lUNnYyM3VLMTFnZjZOaG94ZkZUVEZpL0gzeEJBMzZGSFNkRnFhalFaSGY4UEtuakJRNmF3VjAwRlVhSXovajNNUFlBU0RGOWNPV28iLCJtYWMiOiIyYTI3MzRkOWM2OGRkODFlMjUyMzcyN2QwODRiYzFhNzRiMDE2MjlkNmQ5ZjA2NGU0OTBmMWI0ZDU2ZjVlYmQ5IiwidGFnIjoiIn0%3D; expires=Wed, 11 Mar 2026 01:32:27 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Sat, 10 Jan 2026 01:32:27 GMT X-Served-By: cache-chi-kigq8000119-CHI, cache-fra-eddf8230097-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1768008747.546720,VS0,VE546 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · chicshackboutique.com
2026-01-03 00:40
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: c61d4f1b-1974-4800-aece-c25678f7a31a Set-Cookie: laravel_session=eyJpdiI6IlFRRWpiS3l5OExiYnZUVlE4a0Z5T3c9PSIsInZhbHVlIjoicmlmdUZzQnV4UXpEUThYcWE5cHVUK1pPU3dXaUxLN0E0RER1OTE1SHNWZGs2RjBndy96elZOc0J2R0RkSVdXeTlEYzhkV1VIZE5FOGk2OExiaVVQQUV6ZitjREtDMlg1RkEyMmJzM29vUGU3anZZRVo2dy9EMlhNNWsvdG5tSWYiLCJtYWMiOiI0NjNkNGI3N2I3YmNjMDZmMzU4ZjhlYjNmMWY2NTRiMGY3ODczNjhmY2JkOWUzNGM3MzFiMmU2N2VjZjIyODJlIiwidGFnIjoiIn0%3D; expires=Wed, 04 Mar 2026 00:40:17 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: F0dVIP66MOCuevA5A5hkieFTedlTPyJY87qYhWf9=eyJpdiI6IlRITi9JeTBoT2VRdGcvRUtBNzJaUWc9PSIsInZhbHVlIjoiSjF6QTdmV2NYQjFUbzdySGx3aVFYNVZNNWl0MCtJSHZ5djM3ejNhdTJUQWowZS93MmlIa002c2dyWGdIanhiSWt2M3R4ekNkMkF6Mk90VnkzWUVRL09jTmFHa1krWi9DOHJDNlZvaS95ekhzZnZyRmE0b1FIRDJacDZab3dTazVmanJTT1J5UDViSHl4S1B3ZmdKSjhqUVRxb0R3YUcwOGRPMzU1OEQ2WTczVXdSU2Z6b2UzeUtHM2dqcWxmMEFMclBGMzZIU2FhVmF3bHRDRGxZMUY1bWhsUlVPUUx3N3pMS2czTzYvMktlMGkyY2RMdGp3SU5uYUxNR2tua0tpRFRjTXRTdW1ZcjVRbG5pNUJmK3oyZWF5eG9xU3NlT3dQT2gyblJqclk4MG9KQm9RY2dIM0lUWGZpQXdJOUYwNzUwdDNXTnI1a3g2dUtsSGo4VzVHSjN5c3ZhL0gwbzJTeXZxVHFGV1NnZmtnMWhLYTlZVmFOeis1NDkwVnVFQkpLc0FScERMVlVKMEJwK0ZKZ2N2NmdmakowekFKbDhvMDFxZVNGeEd3dDlJaWxab3BUcW1SVUJIMGlOVVQranpndXZDUzRPLzlTdVNseXJudXNJZUhEMDJaektySis0eDZXMS9SWUJMMklEMVkzakFrelhBdjQzbm9ZQ0JSSU9sTGYiLCJtYWMiOiIwMjdjYTRkZDFhMjc4ZjhiZThiMGE2NmJhZWM2NDRjNWMxYTAxNTJiMTlmYmM4YjQ0MDE1YTRlNjBlMTkzNDVlIiwidGFnIjoiIn0%3D; expires=Wed, 04 Mar 2026 00:40:17 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Sat, 03 Jan 2026 00:40:17 GMT X-Served-By: cache-chi-klot8100113-CHI, cache-vie6375-VIE X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767400817.496811,VS0,VE341 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · chicshackboutique.com
2025-12-23 03:55
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: dbdbe09c-6a9a-43f6-aa62-69057aa074c2 Set-Cookie: laravel_session=eyJpdiI6InM4OHExL0ltQXVkdjh3dlVaSjcvQVE9PSIsInZhbHVlIjoiS1dhZkxGWmtwRWdUMUFWMzhWekp6REEwZHUxRzJJNTAwWGViZnlhU1FJSjR1YjYzRkYwL2VOYzc1MzNMUGRuUEdBbkYvOElHQ3JZZGlOUDRDN3N5ZEJkWlp1NGtWMml3WSt2QmV3S1hLaEQ1VzV3MkM0aHdjRkt2SDhIVGNzZ0ciLCJtYWMiOiI2N2VhM2IyNTFlZjk4NzM0YjMwZmQ5YTkwMWRjZjU0ZDg3MjcwZGYxNmUwODA0MTU5MmI1ZDJhMDJiOWM0ODFmIiwidGFnIjoiIn0%3D; expires=Sat, 21 Feb 2026 03:55:11 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: HQG1C1y674hwKRqyZYTha0FDfhK5MzXZKUID4Sim=eyJpdiI6IktDOStZdG54MkZ2TVNhNVVJQW9XUGc9PSIsInZhbHVlIjoiWVBkT3luc1dIZmhQcEorNkNqN1g2RFJzaTlrNWo4SmJ5OWxYb29qT0lEaDd5S2V2elRNQnd5QmQrL1R0YWpMcEMrZHBDR05LL3JaMGNSdi9mTTdFWHMzVFlrRVl5Zmt5Nm5TQ1VEdThMd2lFZzNxY2llMGdFbUxxV3U2U2k1MHlGcm1LTmJSelgrcEJNc0F4L3hxZXhaMzkzSEdySFRDLytMWDljT20xK3NsejJSdUpCK3pwdGE2Mmk2SVA4UnhWUDNQSlNVY0ZpZ212VE1IanRkS3VFY3FrNU1jZDJkZXM5NUFYcm1kcFRaRW5KandrbkF0cG9VU25nM2RiNkNNcXFSMkFUZWZiazRETHpwZjBJL0RXQkpYN29FSFV5ZVZnbzM0TTJDdFNINFRER2RVcUZjQ21KNGRVS3VsVXZJQ3d0aXRDUzB3SFB5V0h2bGtzaWtydVdOekRGNjA3Q29SRktZaEN6b1ozSS81Nk1mcTdGZlBXdzRNRXlLUjdwUFFpdmZMa2JYN0U3aWUyL0FLQkl4Tit1MytqRU9NcDcxNm5uTXA2TFArVGlaRWtpUWlmVU0zVmMrNEFWa3NDSnhJZDZOcklQdTZLcVY4Q3VXNHErb0RnV0YyNDhJbmlENHZPMUpMNjZDbDZidjAzVkhOK2ZFanZtcE1NdTQrMVRMbm0iLCJtYWMiOiJkMDI4ZTQyMjk3MTY4Yzg1YTcyY2Q2MmQyNThiMzk4MTFjOGI4NmVjYTI4MGFiYmU0YzZlY2ViMjNlMzdhZDdmIiwidGFnIjoiIn0%3D; expires=Sat, 21 Feb 2026 03:55:11 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Tue, 23 Dec 2025 03:55:11 GMT X-Served-By: cache-chi-klot8100089-CHI, cache-lga21942-LGA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766462111.007840,VS0,VE254 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked
Open service 151.101.130.132:443 · chicshackboutique.com
2025-12-20 16:36
HTTP/1.1 200 OK Connection: close Content-Type: text/html; charset=UTF-8 Server: Apache Cache-Control: no-cache, private Content-Security-Policy-Report-Only: default-src 'self'; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; img-src * data: blob: android-webview-video-poster:; font-src * data:; connect-src * blob:; media-src * blob:; frame-src * blob: navigate:; worker-src 'self' blob:; frame-ancestors *; form-action 'self' www.facebook.com tr.snapchat.com pos.commentsold.com; object-src 'none'; manifest-src *; child-src 'self' blob:; report-uri https://o43862.ingest.sentry.io/api/239693/security/?sentry_key=deb2fc6b7d104f7ea6241356c26c14d0 x-robots-tag: all X-Request-Id: 1d95445a-87d0-4af7-944e-ff9be07dd1cc Set-Cookie: laravel_session=eyJpdiI6Ik51R05SdXRDdUZ2aG90WlZ5S05uQ3c9PSIsInZhbHVlIjoidSszb3Zpc2dtRVVCalJ2ZGp6OGZHdVFUcTlpYlVRNTg5UWI1R3BGbTIzUzRTM2pPMDlJdzkvWXZyY2FZNktHR0VIeFEzVXNMS3RTZDRlMmgrM2pMZGE0a2NKUjRyR245WFhFSkhpdjFob2FyT3BGMUJXbmZqNkFmUFRSM2pDNGsiLCJtYWMiOiJkMjkwMjRhOGM0ZjJkOGVmZjRiODEyZWIxMWQ4YmYzYzlkMjg3Nzk4MTA1NTRlYzM3NTZhY2EyOWRmYjFmNGE0IiwidGFnIjoiIn0%3D; expires=Wed, 18 Feb 2026 16:36:39 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Set-Cookie: OZTUT8eEvXkU4RmMgRj0elhrbJy5uoq9UsVmft7t=eyJpdiI6IlBzSlVsNjhxZlRPQU1lZ05ZRCtML3c9PSIsInZhbHVlIjoiMTk3b0FwN2x5SCsrT0pQcFJNRE9Uc25jTVJCRU0zdXNBemdYdjk0blR1cEtORXhDdXFyYi95U3ZMaFg2QjlXOG82d0xjN04xZFNHeWhEdm16eUU5eFdRUFcvenQ2a1hITExySUs0L2ZPWGloWkREM0FqZkMvWEUxOFFiTGtEcHJtV2FSb3MxcFdWem5DcDVaM3Rvb3ppZXlIbEozQ1d6VHpKcWx6eVgyKzRFaHFKUVh6ajlaaHlOWEs3K3U3S0lWWGt3MXdqd1BmdXJuMU1UVS9JNG9uYktlRWwvZHBIeDFtMFZMcm1BUlA5akNYbEVXYk9rTHBJZjBWT0JCRXRDMlRQMURGU1RNaWlJNVNSOXNFcDhwdnQwZWphU3RqOGZwWkRyeFFsTHN4YXZBMnVHem8ySVZPeC8ya2xMVzc2SE90VGErQVlldkU0NWxlcEsxdDllM2ZGVXZpdXVSdW9MNzZ2TTRFSm1CQlFRbWx3OHAwSjBrd2RCVXVES0ZnZDh2VUh3SXhuY0lqclRUaCtWdVZ2M3BIbm1ORlFXNmJLTXByR2pzMW1LWHdveitidlRRWVZFWi9acndNUkRnS1dSMmFwMzVGMTU4NGdFUTVuQjJzdEpvcmkwMU13WEczb2FPei91QmRmc3ZWTVpra3MzYmlDdlBzWmdnU1hBeDlyS0UiLCJtYWMiOiI0ZWQxZmZlNDFjOTI5MGE1ZWNlZDhkYzM1NTZhOTQ0MzA0NTI0MTA3ODc5OTUwMDljODJmNGM3Njk3ZTYxYzlkIiwidGFnIjoiIn0%3D; expires=Wed, 18 Feb 2026 16:36:39 GMT; Max-Age=5184000; path=/; secure; httponly; samesite=none Access-Control-Allow-Origin: * Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE, PUT Access-Control-Max-Age: 1000 Access-Control-Allow-Headers: x-requested-with, Content-Type, origin, authorization, accept, client-security-token, Accept-Encoding Accept-Ranges: bytes Via: 1.1 varnish, 1.1 varnish X-Cacheable: NO:Set-Cookie Date: Sat, 20 Dec 2025 16:36:39 GMT X-Served-By: cache-chi-klot8100058-CHI, cache-lcy-egml8630025-LCY X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766248599.904680,VS0,VE307 Vary: Accept-Encoding Strict-Transport-Security: max-age=900 transfer-encoding: chunked