nginx
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cccdd54a0ccdd54a0f587de0d97b2fdfb9455a0fed28d0700
Found 13 files trough .DS_Store spidering: /.vscode /assets /case-studies /case-studies/Crowdar-EXISOFT-Coaching-on-test-automation-Quality-deliverables.pdf /Crowdar-ToS.html /crowdar-uk.html /css /fonts /images /index.html /index_es.html /js /lippia.html
Severity: medium
Fingerprint: 5f32cf5d6962f09c8c9af8b78c9af8b7edf5591eb810a11ab7ac9ab101ffde69
Found 128 files trough .DS_Store spidering: /.vscode /assets /case-studies /case-studies/Crowdar-EXISOFT-Coaching-on-test-automation-Quality-deliverables.pdf /Crowdar-ToS.html /crowdar-uk.html /css /fonts /images /images/Appcheck-logo-bw.png /images/Appcheck-ng-logo3.png /images/appcheck_logo.png /images/apple-touch-icon-114x114.png /images/apple-touch-icon-72x72.png /images/apple-touch-icon.png /images/arquitecture.png /images/arrow2.png /images/arrow3.png /images/arrow4.png /images/arrow_left.png /images/arrow_right.png /images/automatization.jpg /images/back.jpg /images/back2.jpg /images/BannerCrowdar.jpg /images/BannerCrowdar.png /images/bg-image-1_landx.jpg /images/bg-image-1_old.jpg /images/bg-image-2-low.jpg /images/bg-image-2_landx.jpg /images/bg-image-elephant.jpg /images/certified-partner-logo.png /images/city-dusk-landscape.jpg /images/client-pics /images/clients /images/clients/logo10Pines.png /images/clients/logo_alpari.png /images/clients/logo_evalues.png /images/clients/logoAlpari.png /images/clients/logoArgentinaIT.png /images/clients/logoAudio.png /images/clients/logoBancoComafi.png /images/clients/logoBancoComafi_white.png /images/clients/logoBancoSaenz.png /images/clients/logoCessi.png /images/clients/logoClaro.png /images/clients/logoCrowtix.png /images/clients/logoEdesur.png /images/clients/logoEdesur_white.png /images/clients/logoentrepreneurs.png /images/clients/logoFravega.png /images/clients/logoGire.png /images/clients/logoGire_white.png /images/clients/logoIlluminet.png /images/clients/logoInterservices.png /images/clients/logoKapsch.png /images/clients/logoKCC.png /images/clients/logoKCC_white.png /images/clients/logomanchesterdigital.png /images/clients/logomidas.png /images/clients/logoNubi.png /images/clients/logoPuente.png /images/clients/logoRaet.png /images/clients/logoRAET_white.png /images/clients/logoSupervielle.png /images/clients/logoTA.png /images/clients/logotechnorth.png /images/clients/logoTR.png /images/clients/logoTR_white.png /images/clients/logoTuAlacena.png /images/clients/logoTultix.png /images/Codified-logo-bw.png /images/codified_logo.png /images/cropped-city-night-landscape1.jpg /images/crowd-48.png /images/crowd-out.jpg /images/crowd.jpg /images/DeathtoStock_Medium6-low.jpg /images/favicon.ico /images/favicon_landx.ico /images/gift-3-48.png /images/ico2.png /images/ico_pdf.png /images/icon_automation.png /images/icon_english.png /images/icon_manual.png /images/icon_reports.png /images/icon_security.png /images/icon_spanish.png /images/image-1.jpg /images/image-2.jpg /images/lightbulb-2-48.png /images/loading.gif /images/logo-crowdar-old.png /images/logo-crowdar.png /images/logo-dark.png /images/logo-dark@2x.png /images/logo.gif /images/logo.png /images/logo@2x-old.png /images/logo@2x.png /images/logo@2x_landx.png /images/logo_BYN_invertido.jpg /images/logo_cuadro.png /images/logo_evalues.png /images/logo_gartner.png /images/logo_imprenta_blanco.png /images/logo_imprenta_verde-old.png /images/logo_imprenta_verde.png /images/logo_imprenta_verde_114x114.png /images/logo_imprenta_verde_32x32.png /images/logo_imprenta_verde_72x72.png /images/logo_imprenta_verde_footer-old.png /images/logo_imprenta_verde_footer.png /images/logo_lippia.jpg /images/logo_lippia.png /images/logo_lippia_2.jpg /images/logoCrowdarSolo.jpg /images/logoverde_solo_logo.png /images/manager-48.png /images/manchester-night-2.jpeg /images/manchester-night-3.jpeg /images/manchester-night-3.jpg /images/manchester-night.jpeg /images/mcd-bee-crowdar.png /images/outsourcing.jpg /images/package-2-48.png /images/project-48.png
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65229c93774e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/delimce/QuinielaFutbol.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 138.197.60.224:443 · gitlab.crowdaronline.com
2026-01-23 14:22
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 23 Jan 2026 14:22:41 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 112
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.crowdaronline.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KFNKRQZS57Z4DWXY5Q9C1BWQ","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KFNKRQZS57Z4DWXY5Q9C1BWQ
X-Runtime: 0.046706
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://gitlab.crowdaronline.com/users/sign_in">redirected</a>.</body></html>