Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549bb377b46265ef8fc392dfd364fd66a8dfdd867c7
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/webentry/v1/File/Folder/{path}
DELETE /api/webentry/v1/Security/UserRoles/{userid}/{roleid}
GET /api/v1/{nodeid}/Connectors
GET /api/v1/{nodeid}/Connectors/{connectorid}
GET /api/webentry/v1/EventListView
GET /api/webentry/v1/EventListView/{id}
GET /api/webentry/v1/EventTypePage
GET /api/webentry/v1/EventTypePage/GetForEventType/{eventtypeid}
GET /api/webentry/v1/EventTypePage/{id}
GET /api/webentry/v1/EventTypePage/{id}/toggle
GET /api/webentry/v1/File/Download/{path}
GET /api/webentry/v1/File/{path}
GET /api/webentry/v1/LandingTile
GET /api/webentry/v1/LandingTile/{id}
GET /api/webentry/v1/Notification
GET /api/webentry/v1/Notification/{id}
GET /api/webentry/v1/Security/IdentityProviders
GET /api/webentry/v1/Security/IdentityProviders/{identityproviderid}
GET /api/webentry/v1/Security/IdentityProviders/{identityproviderid}/roles
GET /api/webentry/v1/Security/IdentityProviders/{identityproviderid}/users
GET /api/webentry/v1/Security/RoleDataSecurity/{roleid}
GET /api/webentry/v1/Security/Roles
GET /api/webentry/v1/Security/Roles/AvailableRights
GET /api/webentry/v1/Security/Roles/{roleid}
GET /api/webentry/v1/Security/Roles/{roleid}/users
GET /api/webentry/v1/Security/Users
GET /api/webentry/v1/Security/Users/{userid}
GET /api/webentry/v1/Security/Users/{userid}/available-roles
GET /api/webentry/v1/Security/Users/{userid}/roles
GET /api/webentry/v1/Spaces
GET /api/webentry/v1/Spaces/ibssspaceclasses
GET /api/webentry/v1/Spaces/ibssspacetypes
GET /api/webentry/v1/Spaces/ibssspaceworktypes
GET /api/webentry/v1/Spaces/{spaceId}
GET /api/webentry/v1/Spaces/{spaceId}/agents
GET /api/webentry/v1/Spaces/{spaceId}/devices
GET /api/webentry/v1/Spaces/{spaceId}/hasPart
GET /api/webentry/v1/Spaces/{spaceId}/isPartOf
GET /api/webentry/v1/Spaces/{spaceId}/parameters
GET /api/webentry/v1/Spaces/{spaceId}/spacestates
GET /api/webentry/v1/Spaces/{spaceId}/taskcategories
GET /api/webentry/v1/Spaces/{spaceId}/taskstates
GET /api/webentry/v1/Spaces/{spaceId}/tasktypes
GET /v1/Service/heartbeat
GET /v1/Service/version
POST /api/webentry/v1/Security/UserRoles
PUT /api/webentry/v1/Notification/refresh
PUT /api/webentry/v1/Security/Users/{userid}/resetpassword
PUT /api/webentry/v1/Spaces/{spaceid}
Open service 20.90.134.37:443 · dataentryapi.ibss.theacre.iconics.cloud
2026-01-23 03:59
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 03:59:49 GMT Server: Kestrel Cache-Control: no-store Strict-Transport-Security: max-age=31536000; includeSubDomains x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 Content-Security-Policy: default-src 'self' X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Referrer-Policy: no-referrer Permissions-Policy: accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
Open service 20.90.134.37:443 · dataentryapi.ibss.theacre.iconics.cloud
2026-01-09 05:10
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 05:11:24 GMT Server: Kestrel Cache-Control: no-store Strict-Transport-Security: max-age=31536000; includeSubDomains x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 Content-Security-Policy: default-src 'self' X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Referrer-Policy: no-referrer Permissions-Policy: accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
Open service 20.90.134.37:443 · dataentryapi.ibss.theacre.iconics.cloud
2026-01-02 12:02
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 02 Jan 2026 12:02:39 GMT Server: Kestrel Cache-Control: no-store Strict-Transport-Security: max-age=31536000; includeSubDomains x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 Content-Security-Policy: default-src 'self' X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Referrer-Policy: no-referrer Permissions-Policy: accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()
Open service 20.90.134.37:443 · dataentryapi.ibss.theacre.iconics.cloud
2025-12-22 13:05
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 13:05:50 GMT Server: Kestrel Cache-Control: no-store Strict-Transport-Security: max-age=31536000; includeSubDomains x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 Content-Security-Policy: default-src 'self' X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN Referrer-Policy: no-referrer Permissions-Policy: accelerometer=(), ambient-light-sensor=(), autoplay=(), battery=(), camera=(), cross-origin-isolated=(), display-capture=(), document-domain=(), encrypted-media=(), execution-while-not-rendered=(), execution-while-out-of-viewport=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), navigation-override=(), payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(), usb=(), web-share=(), xr-spatial-tracking=()