The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba91884022e566c81220218b7
[init] defaultBranch = none [fetch] recurseSubmodules = false [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:64_uLr8r7xyf8ceZa1Q4Lnh@gitlab.com/cookr2/cookr-website.git fetch = +refs/heads/*:refs/remotes/origin/*
Open service 199.59.243.228:443 · cookr.us
2025-12-21 00:24
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 00:24:58 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 1030
X-Request-Id: 526267b7-9c3c-4ade-a416-2eeef2209ebd
Cache-Control: no-store, max-age=0
Accept-Ch: sec-ch-prefers-color-scheme
Critical-Ch: sec-ch-prefers-color-scheme
Vary: sec-ch-prefers-color-scheme
X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_K0QYR/ISoXcckZU6eTMpYm3GChveUhIiGSPDdqGJxtK6pi2TG+PucV4CqQxPvK9tcR0wAxvZ6W31ek1tYgqIng==
Set-Cookie: parking_session=526267b7-9c3c-4ade-a416-2eeef2209ebd; expires=Sun, 21 Dec 2025 00:39:58 GMT; path=/
Connection: close
<!doctype html>
<html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_K0QYR/ISoXcckZU6eTMpYm3GChveUhIiGSPDdqGJxtK6pi2TG+PucV4CqQxPvK9tcR0wAxvZ6W31ek1tYgqIng==" lang="en" style="background: #2B2B2B;">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC">
<link rel="preconnect" href="https://www.google.com" crossorigin>
</head>
<body>
<div id="target" style="opacity: 0"></div>
<script>window.park = "eyJ1dWlkIjoiNTI2MjY3YjctOWMzYy00YWRlLWE0MTYtMmVlZWYyMjA5ZWJkIiwicGFnZV90aW1lIjoxNzY2Mjc2Njk4LCJwYWdlX3VybCI6Imh0dHBzOi8vY29va3IudXMvIiwicGFnZV9tZXRob2QiOiJHRVQiLCJwYWdlX3JlcXVlc3QiOnt9LCJwYWdlX2hlYWRlcnMiOnt9LCJob3N0IjoiY29va3IudXMiLCJpcCI6IjIwNi4xODkuOTUuMjMyIn0K";</script>
<script src="/bptjDWjll.js"></script>
</body>
</html>
Open service 199.59.243.228:80 · cookr.us
2025-12-21 00:24
HTTP/1.1 200 OK
date: Sun, 21 Dec 2025 00:24:56 GMT
content-type: text/html; charset=utf-8
content-length: 1026
x-request-id: ac1a77a6-8b85-46f9-9355-cfb7442c309e
cache-control: no-store, max-age=0
accept-ch: sec-ch-prefers-color-scheme
critical-ch: sec-ch-prefers-color-scheme
vary: sec-ch-prefers-color-scheme
x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_K0QYR/ISoXcckZU6eTMpYm3GChveUhIiGSPDdqGJxtK6pi2TG+PucV4CqQxPvK9tcR0wAxvZ6W31ek1tYgqIng==
set-cookie: parking_session=ac1a77a6-8b85-46f9-9355-cfb7442c309e; expires=Sun, 21 Dec 2025 00:39:57 GMT; path=/
connection: close
<!doctype html>
<html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_K0QYR/ISoXcckZU6eTMpYm3GChveUhIiGSPDdqGJxtK6pi2TG+PucV4CqQxPvK9tcR0wAxvZ6W31ek1tYgqIng==" lang="en" style="background: #2B2B2B;">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC">
<link rel="preconnect" href="https://www.google.com" crossorigin>
</head>
<body>
<div id="target" style="opacity: 0"></div>
<script>window.park = "eyJ1dWlkIjoiYWMxYTc3YTYtOGI4NS00NmY5LTkzNTUtY2ZiNzQ0MmMzMDllIiwicGFnZV90aW1lIjoxNzY2Mjc2Njk3LCJwYWdlX3VybCI6Imh0dHA6Ly9jb29rci51cy8iLCJwYWdlX21ldGhvZCI6IkdFVCIsInBhZ2VfcmVxdWVzdCI6e30sInBhZ2VfaGVhZGVycyI6e30sImhvc3QiOiJjb29rci51cyIsImlwIjoiMTQyLjkzLjAuNjYifQo=";</script>
<script src="/bCjkBvAIT.js"></script>
</body>
</html>