AmazonS3
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d8dab0b348dab0b348dab0b348dab0b34
Found 1 files trough .DS_Store spidering: /embed-test
Open service 52.85.65.34:443 · embed.voomly.softwarepublishingapp.com
2026-01-09 21:30
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 311
Connection: close
Date: Thu, 11 Sep 2025 19:09:22 GMT
Last-Modified: Thu, 11 Sep 2025 11:52:29 GMT
ETag: "35ba23b9739233603992ad53b3278e25"
x-amz-server-side-encryption: AES256
Cache-Control: max-age=31104000
Accept-Ranges: bytes
Server: AmazonS3
X-Cache: Hit from cloudfront
Via: 1.1 2ba0d127e96dd7ba71375daa47032990.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P6
X-Amz-Cf-Id: BCNMsyvYV3ALxvPCXjsdbFTQHBPY1EsuYLYtghyj1V4UAwP_Zu5Ghw==
Age: 10376481
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self'; img-src 'self' blob: data: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; media-src 'self' blob: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; script-src 'self' blob: 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com; style-src 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com fonts.gstatic.com fonts.googleapis.com; object-src 'none'; font-src data: fonts.gstatic.com; connect-src *.voomly.com *.voomly-staging.com *.voomly-dev.com *.bootstrap-cloud-dev.com *.bootstrap-cloud-stage.com *.bootstrap-cloud.com r.lr-ingest.io sentry.io;
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Vary: Origin
Page title: Embed open in modal layer
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>Embed open in modal layer</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="favicon.ico" />
</head>
<body></body>
</html>
Open service 52.85.65.34:443 · embed.voomly.softwarepublishingapp.com
2026-01-02 12:59
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 311
Connection: close
Date: Thu, 11 Sep 2025 19:09:22 GMT
Last-Modified: Thu, 11 Sep 2025 11:52:29 GMT
ETag: "35ba23b9739233603992ad53b3278e25"
x-amz-server-side-encryption: AES256
Cache-Control: max-age=31104000
Accept-Ranges: bytes
Server: AmazonS3
X-Cache: Hit from cloudfront
Via: 1.1 33dbd20675fb00285d976b6fbceb3f70.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P6
X-Amz-Cf-Id: MdYs1NBF40WSf80ocuzuhf-4uK9dZQes5KQRDY_fg6oOFJDmjfmfTg==
Age: 9741003
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self'; img-src 'self' blob: data: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; media-src 'self' blob: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; script-src 'self' blob: 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com; style-src 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com fonts.gstatic.com fonts.googleapis.com; object-src 'none'; font-src data: fonts.gstatic.com; connect-src *.voomly.com *.voomly-staging.com *.voomly-dev.com *.bootstrap-cloud-dev.com *.bootstrap-cloud-stage.com *.bootstrap-cloud.com r.lr-ingest.io sentry.io;
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Vary: Origin
Page title: Embed open in modal layer
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>Embed open in modal layer</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="favicon.ico" />
</head>
<body></body>
</html>
Open service 52.85.65.34:443 · embed.voomly.softwarepublishingapp.com
2025-12-22 16:45
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 311
Connection: close
Date: Thu, 11 Sep 2025 19:09:22 GMT
Last-Modified: Thu, 11 Sep 2025 11:52:29 GMT
ETag: "35ba23b9739233603992ad53b3278e25"
x-amz-server-side-encryption: AES256
Cache-Control: max-age=31104000
Accept-Ranges: bytes
Server: AmazonS3
X-Cache: Hit from cloudfront
Via: 1.1 2c313927575349c92f098e6f1111a7ce.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P6
X-Amz-Cf-Id: M74nmpmJOnysrRTMcQJomDtrTr-8_rPrLg7XjNZ3PjqqXH7dKPU59A==
Age: 8804194
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self'; img-src 'self' blob: data: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; media-src 'self' blob: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; script-src 'self' blob: 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com; style-src 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com fonts.gstatic.com fonts.googleapis.com; object-src 'none'; font-src data: fonts.gstatic.com; connect-src *.voomly.com *.voomly-staging.com *.voomly-dev.com *.bootstrap-cloud-dev.com *.bootstrap-cloud-stage.com *.bootstrap-cloud.com r.lr-ingest.io sentry.io;
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Vary: Origin
Page title: Embed open in modal layer
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>Embed open in modal layer</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="favicon.ico" />
</head>
<body></body>
</html>
Open service 52.85.65.34:443 · embed.voomly.softwarepublishingapp.com
2025-12-20 17:52
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 311
Connection: close
Date: Thu, 11 Sep 2025 19:09:22 GMT
Last-Modified: Thu, 11 Sep 2025 11:52:29 GMT
ETag: "35ba23b9739233603992ad53b3278e25"
x-amz-server-side-encryption: AES256
Cache-Control: max-age=31104000
Accept-Ranges: bytes
Server: AmazonS3
X-Cache: Hit from cloudfront
Via: 1.1 ddcc211ea1d565c67eac00a91dda8304.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P6
X-Amz-Cf-Id: D7lzCF2xik17k4ROZEB7W1cZHhR1ml-WaiRTMXwUfBvmYbCZh_TyCg==
Age: 8635394
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self'; img-src 'self' blob: data: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; media-src 'self' blob: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; script-src 'self' blob: 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com; style-src 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com fonts.gstatic.com fonts.googleapis.com; object-src 'none'; font-src data: fonts.gstatic.com; connect-src *.voomly.com *.voomly-staging.com *.voomly-dev.com *.bootstrap-cloud-dev.com *.bootstrap-cloud-stage.com *.bootstrap-cloud.com r.lr-ingest.io sentry.io;
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Vary: Origin
Page title: Embed open in modal layer
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>Embed open in modal layer</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="favicon.ico" />
</head>
<body></body>
</html>
Open service 52.85.65.34:443 · embed.voomly.softwarepublishingapp.com
2025-12-19 06:25
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 311
Connection: close
Date: Thu, 11 Sep 2025 19:09:22 GMT
Last-Modified: Thu, 11 Sep 2025 11:52:29 GMT
ETag: "35ba23b9739233603992ad53b3278e25"
x-amz-server-side-encryption: AES256
Cache-Control: max-age=31104000
Accept-Ranges: bytes
Server: AmazonS3
X-Cache: Hit from cloudfront
Via: 1.1 6b15d1c60d9f387a4132de8eb9595b1e.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P6
X-Amz-Cf-Id: uEjpzCV4ka6gIvr4wThMORrShge3GoKakuKw3X_cFh4tWJCwhc6E5Q==
Age: 8507796
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self'; img-src 'self' blob: data: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; media-src 'self' blob: media.voomly.com media.voomly-staging.com media.voomly-dev.com *.bootstrap-cloud.com *.bootstrap-cloud-staging.com *.bootstrap-cloud-dev.com; script-src 'self' blob: 'unsafe-eval'; script-src-elem 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com; style-src 'self' 'unsafe-inline' *.voomly.com *.voomly-staging.com *.voomly-dev.com fonts.gstatic.com fonts.googleapis.com; object-src 'none'; font-src data: fonts.gstatic.com; connect-src *.voomly.com *.voomly-staging.com *.voomly-dev.com *.bootstrap-cloud-dev.com *.bootstrap-cloud-stage.com *.bootstrap-cloud.com r.lr-ingest.io sentry.io;
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
Vary: Origin
Page title: Embed open in modal layer
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>Embed open in modal layer</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="favicon.ico" />
</head>
<body></body>
</html>