nginx
tcp/443 tcp/80
No description available
Fingerprint: b17be75321b5afb46c3fa6a06c3fa6a06c3fa6a06c3fa6a06c3fa6a06c3fa6a0
{"_links":{"self":{"href":"https://gtsdirpool61webext.deloitte.com/Autodiscover/AutodiscoverService.svc/root?originalDomain=deloitte.gr"},"user":{"href":"https://gtsdirpool61webext.deloitte.com/Autodiscover/AutodiscoverService.svc/root/oauth/user?originalDomain=deloitte.gr"},"xframe":{"href":"https://gtsdirpool61webext.deloitte.com/Autodiscover/XFrame/XFrame.html"}}}
Fingerprint: b17be75321b5afb4375d9ecc375d9ecc375d9ecc375d9ecc375d9ecc375d9ecc
{"_links":{"self":{"href":"https://gtsdirpool65webext.deloitte.com/Autodiscover/AutodiscoverService.svc/root?originalDomain=deloitte.gr"},"user":{"href":"https://gtsdirpool65webext.deloitte.com/Autodiscover/AutodiscoverService.svc/root/oauth/user?originalDomain=deloitte.gr"},"xframe":{"href":"https://gtsdirpool65webext.deloitte.com/Autodiscover/XFrame/XFrame.html"}}}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 2a02:26f0:3500:18::1724:a29e:443 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:19 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199476_388276382_1177484636_14_2596_11_16_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29c:443 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:19 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199636_388276380_2158051765_16_2761_11_40_-";dur=1
Open service 2.16.204.17:443 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:19 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199744_34610457_1847726_16_2469_81_85_-";dur=1
Open service 2.16.204.17:80 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:01 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245241875_34610449_146785964_13_2485_174_0_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29c:80 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:01 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245241220_388276380_2158112463_13_2140_101_0_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29e:80 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:01 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245241259_388276382_1177534852_11_2178_155_0_-";dur=1
Open service 2.16.204.25:443 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:19 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199765_34610449_146726328_14_2133_98_102_-";dur=1
Open service 2.16.204.25:80 · www.deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:00 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:00 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245240358_34610457_1913201_10_2520_12_0_-";dur=1
Open service 2.16.204.25:443 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:20 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:20 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199896_34610449_146726613_14_2953_151_174_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29c:443 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:20 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:20 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199936_388276380_2158052371_12_2590_160_165_-";dur=1
Open service 2.16.204.17:80 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:58 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:58 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245238634_34610449_146781785_12_2473_147_0_-";dur=1
Open service 2.16.204.25:80 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:00 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:00 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245240919_34610457_1914075_10_2113_88_0_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29e:80 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:00 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:00 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245240159_388276382_1177533573_12_2681_1_0_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29e:443 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:19 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199221_388276382_1177484291_16_2648_6_11_-";dur=1
Open service 2.16.204.17:443 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:13:19 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:13:19 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245199291_34610457_1847188_14_2630_18_61_-";dur=1
Open service 2a02:26f0:3500:18::1724:a29c:80 · deloitte.gr
2026-01-12 19:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www2.deloitte.com/gr/en.html Expires: Mon, 12 Jan 2026 19:14:00 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 12 Jan 2026 19:14:00 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1768245240288_388276380_2158111269_12_2344_12_0_-";dur=1
Open service 3.78.250.23:443 · backend.employeeappnpd.deloitte.gr
2026-01-02 16:52
HTTP/1.1 302 Found Access-Control-Allow-Origin: * Alt-Svc: h3=":443"; ma=2592000 Content-Length: 44 Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests Content-Type: text/plain; charset=utf-8 Cross-Origin-Opener-Policy: same-origin Cross-Origin-Resource-Policy: same-origin Date: Fri, 02 Jan 2026 16:52:22 GMT Location: employeeapp://redirect Origin-Agent-Cluster: ?1 Referrer-Policy: no-referrer Strict-Transport-Security: max-age=31536000; includeSubDomains Vary: Accept Via: 1.1 Caddy X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Ratelimit-Limit: 10000 X-Ratelimit-Remaining: 9998 X-Ratelimit-Reset: 1767373643 X-Xss-Protection: 0 Connection: close Found. Redirecting to employeeapp://redirect
Open service 3.78.250.23:443 · backend.employeeappnpd.deloitte.gr
2025-12-30 14:10
HTTP/1.1 302 Found Access-Control-Allow-Origin: * Alt-Svc: h3=":443"; ma=2592000 Content-Length: 44 Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests Content-Type: text/plain; charset=utf-8 Cross-Origin-Opener-Policy: same-origin Cross-Origin-Resource-Policy: same-origin Date: Tue, 30 Dec 2025 14:10:24 GMT Location: employeeapp://redirect Origin-Agent-Cluster: ?1 Referrer-Policy: no-referrer Strict-Transport-Security: max-age=31536000; includeSubDomains Vary: Accept Via: 1.1 Caddy X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Ratelimit-Limit: 10000 X-Ratelimit-Remaining: 9998 X-Ratelimit-Reset: 1767104725 X-Xss-Protection: 0 Connection: close Found. Redirecting to employeeapp://redirect
Open service 52.213.221.52:443 · futureofliving.deloitte.gr
2025-12-23 18:27
HTTP/1.1 301 Moved Permanently Server: nginx Date: Tue, 23 Dec 2025 18:27:32 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://futureofliving.deloitte.it/ Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 52.213.221.52:80 · futureofliving.deloitte.gr
2025-12-23 18:27
HTTP/1.1 301 Moved Permanently Server: nginx Date: Tue, 23 Dec 2025 18:27:32 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://futureofliving.deloitte.gr/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 3.78.250.23:443 · backend.employeeappnpd.deloitte.gr
2025-12-23 05:24
HTTP/1.1 302 Found Access-Control-Allow-Origin: * Alt-Svc: h3=":443"; ma=2592000 Content-Length: 44 Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests Content-Type: text/plain; charset=utf-8 Cross-Origin-Opener-Policy: same-origin Cross-Origin-Resource-Policy: same-origin Date: Tue, 23 Dec 2025 05:24:58 GMT Location: employeeapp://redirect Origin-Agent-Cluster: ?1 Referrer-Policy: no-referrer Strict-Transport-Security: max-age=31536000; includeSubDomains Vary: Accept Via: 1.1 Caddy X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Ratelimit-Limit: 10000 X-Ratelimit-Remaining: 9998 X-Ratelimit-Reset: 1766468398 X-Xss-Protection: 0 Connection: close Found. Redirecting to employeeapp://redirect
Open service 3.78.250.23:443 · backend.employeeappnpd.deloitte.gr
2025-12-20 15:22
HTTP/1.1 302 Found Access-Control-Allow-Origin: * Alt-Svc: h3=":443"; ma=2592000 Content-Length: 44 Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests Content-Type: text/plain; charset=utf-8 Cross-Origin-Opener-Policy: same-origin Cross-Origin-Resource-Policy: same-origin Date: Sat, 20 Dec 2025 15:22:35 GMT Location: employeeapp://redirect Origin-Agent-Cluster: ?1 Referrer-Policy: no-referrer Strict-Transport-Security: max-age=31536000; includeSubDomains Vary: Accept Via: 1.1 Caddy X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Ratelimit-Limit: 10000 X-Ratelimit-Remaining: 9998 X-Ratelimit-Reset: 1766245056 X-Xss-Protection: 0 Connection: close Found. Redirecting to employeeapp://redirect