nginx
tcp/443 tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b6e32174b3b8064cccba7681b5670a3957
Found 28 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: low
Fingerprint: 5f32cf5d6962f09ca0cc0fcfa0cc0fcf947301c8696f0fbfaa45847cf2419411
Found 25 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: low
Fingerprint: 5f32cf5d6962f09c87f05b7087f05b7077e6845d16d5c92e7c175bd3a83e6038
Found 26 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: medium
Fingerprint: 5f32cf5d6962f09cef4770e6ef4770e63fc838639fbbb4bc2031472562c87b55
Found 42 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /imagens/estados /imagens/guia /imagens/iconestelas /imagens/iconsmaps /imagens/maps /imagens/social /imagens/turismo /images /images/prettyPhoto /images/prettyPhoto/dark_rounded /images/prettyPhoto/dark_square /images/prettyPhoto/default /images/prettyPhoto/facebook /images/prettyPhoto/light_rounded /images/prettyPhoto/light_square /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: medium
Fingerprint: 5f32cf5d6962f09cd4047824d404782479c418993ee6b6e27902130ffdb7d196
Found 35 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /imagens/estados /imagens/guia /imagens/iconestelas /imagens/iconsmaps /imagens/maps /imagens/social /imagens/turismo /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: medium
Fingerprint: 5f32cf5d6962f09c8efce1938efce1937a2086545dd2fd536d92377804cc10ab
Found 36 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /imagens/estados /imagens/guia /imagens/iconestelas /imagens/iconsmaps /imagens/maps /imagens/social /imagens/turismo /images /images/prettyPhoto /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c87f05b7087f05b7077e6845d16d5c92e7c175bd3a83e6038
Found 26 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b6e32174b3b8064cccba7681b5670a3957
Found 28 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: low
Fingerprint: 5f32cf5d6962f09ca0cc0fcfa0cc0fcf947301c8696f0fbfaa45847cf2419411
Found 25 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: medium
Fingerprint: 5f32cf5d6962f09c8efce1938efce1937a2086545dd2fd536d92377804cc10ab
Found 36 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /imagens/estados /imagens/guia /imagens/iconestelas /imagens/iconsmaps /imagens/maps /imagens/social /imagens/turismo /images /images/prettyPhoto /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: medium
Fingerprint: 5f32cf5d6962f09cef4770e6ef4770e63fc838639fbbb4bc2031472562c87b55
Found 42 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /imagens/estados /imagens/guia /imagens/iconestelas /imagens/iconsmaps /imagens/maps /imagens/social /imagens/turismo /images /images/prettyPhoto /images/prettyPhoto/dark_rounded /images/prettyPhoto/dark_square /images/prettyPhoto/default /images/prettyPhoto/facebook /images/prettyPhoto/light_rounded /images/prettyPhoto/light_square /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: medium
Fingerprint: 5f32cf5d6962f09cd4047824d404782479c418993ee6b6e27902130ffdb7d196
Found 35 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /areport/dompdf /areport/dompdf/lib /areport/dompdf/src /cache /classes /css /cssesic /diariooficial /fonts /fonts/icomoon /fonts/icomoon/demo-files /fonts/icomoon/fonts /imagens /imagens/estados /imagens/guia /imagens/iconestelas /imagens/iconsmaps /imagens/maps /imagens/social /imagens/turismo /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
Severity: low
Fingerprint: 5f32cf5d6962f09c9e04c3bc9e04c3bca7f85031e9b0633aef990c77135a4316
Found 22 files trough .DS_Store spidering: /.git /aicon /aicon/demo-files /aicon/fonts /anexo /areport /cache /classes /css /cssesic /diariooficial /fonts /imagens /images /img /include /js /mapadacidade /pdfjs /smtp /templatejustdo /uploadfiles
The following URL is publicly accessible and is leaking deployment credentials
Fingerprint: 13b3a7b18ffc92a5ebda39da75b07abfc96fbbcc19542539f8615a4dbb2e6023
HTTP/1.1 200 OK Server: nginx Date: Mon, 17 Jul 2023 00:17:24 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding Page title: Prefeitura de Coivaras{ "name": "My Server", "host": "129.148.24.140", "protocol": "ftp", "port": 21, "username": "tamboril_u", "remotePath": "httpdocs", "passive": true, "secure": false, "password": "C@a#156cAm@rA_32", "ignore": [ "\\.vscode", "\\.git", "\\.DS_Store" ], "uploadOnSave": true }
Fingerprint: 13b3a7b17cfc7502c36c325d2c9bda3f918bdcbdf008a15d804715353182d1ef
{ "name": "My Server", "host": "129.148.24.140", "protocol": "ftp", "port": 21, "username": "tamboril_u", "remotePath": "httpdocs", "passive": true, "secure": false, "password": "C@a#156cAm@rA_32", "ignore": [ "\\.vscode", "\\.git", "\\.DS_Store" ], "uploadOnSave": true }
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a4d4c78f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@gitlab.com:php-developer2/aexecutivo.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a4d4c78f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@gitlab.com:php-developer2/aexecutivo.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL is publicly accessible and is leaking deployment credentials
Fingerprint: 13b3a7b17cfc7502c36c325d2c9bda3f918bdcbdf008a15d804715353182d1ef
{ "name": "My Server", "host": "129.148.24.140", "protocol": "ftp", "port": 21, "username": "tamboril_u", "remotePath": "httpdocs", "passive": true, "secure": false, "password": "C@a#156cAm@rA_32", "ignore": [ "\\.vscode", "\\.git", "\\.DS_Store" ], "uploadOnSave": true }
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-28 09:48
HTTP/1.1 200 OK Server: nginx Date: Tue, 28 May 2024 09:48:51 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-28 05:21
HTTP/1.1 200 OK Server: nginx Date: Tue, 28 May 2024 05:21:47 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-27 22:56
HTTP/1.1 200 OK Server: nginx Date: Mon, 27 May 2024 22:56:19 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-27 06:43
HTTP/1.1 200 OK Server: nginx Date: Mon, 27 May 2024 06:43:22 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-26 18:04
HTTP/1.1 200 OK Server: nginx Date: Sun, 26 May 2024 18:04:39 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-26 08:23
HTTP/1.1 200 OK Server: nginx Date: Sun, 26 May 2024 08:23:20 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-25 10:27
HTTP/1.1 200 OK Server: nginx Date: Sat, 25 May 2024 10:27:43 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-25 10:02
HTTP/1.1 200 OK Server: nginx Date: Sat, 25 May 2024 10:02:24 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-24 20:55
HTTP/1.1 200 OK Server: nginx Date: Fri, 24 May 2024 20:55:27 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-24 03:52
HTTP/1.1 200 OK Server: nginx Date: Fri, 24 May 2024 03:52:52 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-23 18:42
HTTP/1.1 200 OK Server: nginx Date: Thu, 23 May 2024 18:42:18 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-23 02:54
HTTP/1.1 200 OK Server: nginx Date: Thu, 23 May 2024 02:54:41 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-14 06:17
HTTP/1.1 200 OK Server: nginx Date: Tue, 14 May 2024 06:17:33 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:80 · www.coivaras.pi.gov.br
2024-05-14 06:17
HTTP/1.1 301 Moved Permanently Server: nginx Date: Tue, 14 May 2024 06:17:28 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://www.coivaras.pi.gov.br/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body bgcolor="white"> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-14 06:17
HTTP/1.1 200 OK Server: nginx Date: Tue, 14 May 2024 06:17:33 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:80 · coivaras.pi.gov.br
2024-05-14 06:17
HTTP/1.1 301 Moved Permanently Server: nginx Date: Tue, 14 May 2024 06:17:28 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://coivaras.pi.gov.br/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body bgcolor="white"> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-13 02:18
HTTP/1.1 200 OK Server: nginx Date: Mon, 13 May 2024 02:18:46 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-12 23:23
HTTP/1.1 200 OK Server: nginx Date: Sun, 12 May 2024 23:23:55 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-08 20:29
HTTP/1.1 200 OK Server: nginx Date: Wed, 08 May 2024 20:29:49 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:443 · www.coivaras.pi.gov.br
2024-05-08 16:51
HTTP/1.1 200 OK Server: nginx Date: Wed, 08 May 2024 16:52:40 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding
Open service 140.238.239.97:80 · coivaras.pi.gov.br
2024-05-07 04:32
HTTP/1.1 301 Moved Permanently Server: nginx Date: Tue, 07 May 2024 04:32:28 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://coivaras.pi.gov.br/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body bgcolor="white"> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 140.238.239.97:443 · coivaras.pi.gov.br
2024-05-07 04:32
HTTP/1.1 200 OK Server: nginx Date: Tue, 07 May 2024 04:32:29 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Vary: Accept-Encoding