AmazonS3
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa320cf33c5fe40a407652f2265f6ba07b471a49f56
GraphQL introspection enabled at /graphql Types: 483 (by kind: ENUM: 36, INPUT_OBJECT: 102, INTERFACE: 25, OBJECT: 315, SCALAR: 5) Operations: - Query: Query | fields: advancedProductOptionsSettings, amGiftCardAccount, amGiftCardPreview, amGiftCardSetting, amLabelProvider - Mutation: Mutation | fields: AmxnotifPriceSubscribe, AmxnotifStockSubscribe, addAmGiftCardCodeToAccount, addAmGiftCardProductsToCart, addBundleProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa320cf33c5fe40a407652f2265f6ba07b4fdb6e4e5
GraphQL introspection enabled at /graphql Types: 483 (by kind: ENUM: 36, INPUT_OBJECT: 102, INTERFACE: 25, OBJECT: 315, SCALAR: 5) Operations: - Query: Query | fields: advancedProductOptionsSettings, amGiftCardAccount, amGiftCardPreview, amGiftCardSetting, amLabelProvider - Mutation: Mutation | fields: AmxnotifPriceSubscribe, AmxnotifStockSubscribe, addAmGiftCardCodeToAccount, addAmGiftCardProductsToCart, addBundleProductsToCart Directives: deprecated, include, oneOf, skip (total: 4) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa320cf33c5fe40a407652f2265f6ba07b4ef0ea8cc
GraphQL introspection enabled at /graphql Types: 483 (by kind: ENUM: 36, INPUT_OBJECT: 102, INTERFACE: 25, OBJECT: 315, SCALAR: 5) Operations: - Query: Query | fields: advancedProductOptionsSettings, amGiftCardAccount, amGiftCardPreview, amGiftCardSetting, amLabelProvider - Mutation: Mutation | fields: AmxnotifPriceSubscribe, AmxnotifStockSubscribe, addAmGiftCardCodeToAccount, addAmGiftCardProductsToCart, addBundleProductsToCart Directives: deprecated, include, skip (total: 3)
Open service 18.66.192.21:443 ยท eliassen.stran.store
2026-01-22 21:02
HTTP/1.1 200 OK
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Security-Policy-Report-Only: script-src 'self' 'unsafe-eval' 'unsafe-hashes' 'unsafe-inline' stran.store badger.stran.store trilogy.stran.store nov.stran.store uss.stran.store shakeshack.stran.store www.stran.store ussondemand.com www.ussondemand.com nasdaqvip.store www.nasdaqvip.store farmasigear.com newmill.stran.store bostonbeer.stran.store admin.stran.store trilogymarketing.stran.store con23.farmasigear.com shop.smuckerawayfromhome.com culturepop.stran.store moosehead.stran.store of3.stran.store eliassen.stran.store carlex.stran.store steeldynamics.stran.store millcreek.stran.store trilogyuniform.stran.store crosstree.stran.store merch.drinkculturepop.com demo.stran.store demo2.stran.store ellios.stran.store usap.stran.store exactsciences.stran.store exas.stran.store nasdaqgcs.store trilogyretail.stran.store exactessentials.stran.store exactteamshop.stran.store wwe-gift.stran.store wwe-vvip.stran.store cologuard.stran.store ss.stran.store cologuard-gift.stran.store daybright.stran.store sswelcome.stran.store spartannash.stran.store novuniform.stran.store shoptrilogy.stran.store legencevip.stran.store event.stran.store simplisafe.stran.store ethosipo.stran.store ethosnyc.stran.store badgercad.stran.store burroughs.stran.store *.discoverearly.com service.force.com d.la3-c1-ia2.salesforceliveagent.com widget.trustpilot.com invitejs.trustpilot.com js.stripe.com www.google.com www.gstatic.com stran.store *.stran.store login.microsoftonline.com cdn.mouseflow.com js-agent.newrelic.com bam.nr-data.net storage.googleapis.com ussondemand.com www.ussondemand.com uss.stran.store *.ussondemand.com www.googletagmanager.com cdn.attn.tv *.attn.tv cdn.cookielaw.org *.cloudfront.net; report-uri /.webscale/csp-report
Date: Thu, 22 Jan 2026 21:02:49 GMT
Etag: W/"69bc614b75f73c87312f99a1eb62027b"
Last-Modified: Thu, 22 Jan 2026 11:57:52 GMT
Server: AmazonS3
Set-Cookie: lagrange_session=55760904-b6dd-4142-a02b-771377ae10db; Path=/; Max-Age=1800; HttpOnly; Secure; SameSite=Lax
Set-Cookie: wcid=luX0EwboOOx0AAAB; Path=/; Domain=127.0.0.1; Max-Age=31536000; HttpOnly; Secure; SameSite=Lax
Strict-Transport-Security: max-age=31557600
Vary: accept-encoding
X-Amz-Cf-Pop: IAD61-P8
X-Xss-Protection: 1
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Cache: Miss from cloudfront
Via: 1.1 badff53d2116a4b3d32a2dd1eb918a48.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: lISxYzEyAs85caPHpS3m0GnhmZwHcb02GnvMrdsoPuaoS-ttcr3K-w==
<!DOCTYPE html><html lang="en-US" data-image-optimizing-origin="auto" data-media-backend="https://eliassen.stran.store/media/"><head><meta charset="utf-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width,initial-scale=1"><meta name="theme-color" content="#FFFFFF"><link rel="manifest" href="/manifest.json"><meta name="robots" content="NOINDEX,NOFOLLOW"><link rel="icon" type="image/x-icon" href="/media/favicon/eliassen_default/favicon.ico"><link rel="apple-touch-icon" href="/media/favicon/eliassen_default/favicon.ico"><link rel="apple-touch-icon" sizes="180x180" href="/media/favicon/eliassen_default/favicon.ico"><link rel="preconnect" href="https://eliassen.stran.store/"></head><body class="bg-body font-sans text-base text-colorDefault"><div class="fallback-nocontent" style="visibility: hidden"><div class="fallback-message"><div><p>Oops! Looks like something went wrong. Sorry about that. Click to <a href="" onclick="window.location.reload()">Reload the Page</a></p></div><span class="close" onclick="this.closest('.fallback-nocontent').classList.remove('show')"></span></div></div><div id="root"></div><noscript><style>.fallback-nojs {
display: flex;
flex-direction: column;
justify-content: center;
align-items: center;
text-align: center;
}
.fallback-nojs a {
color: currentColor;
}
.fallback-closed {
height: 40vh;
}
.fallback-heading {
font-family: 'Source Serif Pro';
font-weight: 600;
padding-bottom: 16px;
font-size: xx-large;
}
.fallback-message {
font-family: 'Muli';
}
@media only screen and (max-width: 768px) {
.fallback-heading {
font-size: x-large;
}
}</style><div class="fallback-nojs"><img style="max-height: 110px" class="fallback-closed" alt="JavaScript is disabled" src="https://eliassen.stran.store/media/favicon/eliassen_default/favicon.ico"><div class="fallback-heading">Oops! JavaScript is disabled</div><div class="fallback-message">To browse the store,<br><a href="https://www.enable-javascript.com">enable JavaScript in your browser.</a></div></div></noscript><style>.fallback-nocontent {
position: fixed;
z-index: 50;
background: #f3f4f6;
width: 100%;
text-align: center;
top: -100%;
}
.fallback-nocontent a {
text-decoration: underline;
}
.fallback-nocontent.show {
visibility: visible !important;
top: 0;
transition: 2s ease-out;
box-shadow: 0 0 6px #9CA3AF;
}
.fallback-nocontent .close {
position: absolute;
right: 20px;
top: 0;
width: 22px;
height: 22px;
opacity: 0.3;
bottom: 0;
margin: auto;
cursor: pointer;
}
.fallback-nocontent .close:hover {
opacity: 1;
}
.fallback-nocontent .close:before, .close:after {
position: absolute;
left: 10px;
content: ' ';
height: 20px;
width: 3px;
background-color: #333;
}
.fallback-nocontent .close:before {
transform: rotate(45deg);
}
.fallback-nocontent .close:after {
transform: rotate(-45deg);
}
.fallback-nocontent .fallback-message {
position: relative;
padding: 6px 60px;
}</style><s