Vercel
tcp/443 tcp/80
cloudflare
tcp/443 tcp/80 tcp/8443
nginx 1.25.3
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa32e5caa4776456575893cc8a46cff0b5342216e39
GraphQL introspection enabled at /graphql Types: 921 (by kind: ENUM: 3, INPUT_OBJECT: 155, OBJECT: 748, SCALAR: 9, UNION: 6) Operations: - Query: Query | fields: form_field, form_field_aggregated, form_field_by_id, form_field_translations, form_field_translations_by_id - Subscription: Subscription | fields: directus_files_mutated, form_field_mutated, form_field_translations_mutated, global_media_mutated, globals_mutated Directives: deprecated, include, skip (total: 3) Readable stores: 1 globals (args: optional/default) : id=1
Open service 172.64.145.29:8443 · assets.ff-office.com
2026-01-12 04:32
Open service 2a06:98c1:3105::6812:2ae3:8443 · assets.ff-office.com
2026-01-12 04:32
Open service 2a06:98c1:3105::6812:2ae3:443 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee73e954e6fe-AMS x-amz-request-id: tx000002a8ba372410143e3-0069647969-184880e57-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=PLd7h64SeJn4BNk02cai3WLrgP7d3XBGcHH3hamidpI-1768192361-1.0.1.1-WMiPduqML_uC4UYQs18YAGgCljLP38qlkBb88dFZRwZBYRImv4kjNiixsZBrquzwkt3aHLXb.Blij6tUx9msbGW3ygRGUtSs9xWbc1Jtkzc; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly; Secure; SameSite=None Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx000002a8ba372410143e3-0069647969-184880e57-fra1b</RequestId><HostId>184880e57-fra1b-fra1-zg02</HostId></Error>
Open service 2606:4700:4405::ac40:911d:8443 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 522 Date: Mon, 12 Jan 2026 04:33:01 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Strict-Transport-Security: max-age=15552000; includeSubDomains; preload X-Frame-Options: SAMEORIGIN Referrer-Policy: same-origin Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Server: cloudflare CF-RAY: 9bc9ee79bc2dd36c-FRA error code: 522
Open service 2a06:98c1:3105::6812:2ae3:80 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee7388be3653-FRA x-amz-request-id: tx00000d891a238201f3c77-0069647969-1846a8f59-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=IDcS_iyI2nKhLvXqA9HFbV3f0YokqUDS8jIQWGqwuZM-1768192361-1.0.1.1-Xxj6kYfW0EWiGYg2xgwbY8JmBhg7WsLdKtKoJKWv749v4w1031BS_s92uuPbsLw0.cGQ3Y0hatb2.t.kp1jAStb7XkJvC2xzIhv767JbNDQ; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx00000d891a238201f3c77-0069647969-1846a8f59-fra1b</RequestId><HostId>1846a8f59-fra1b-fra1-zg02</HostId></Error>
Open service 104.18.42.227:80 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee738a8b9a15-FRA x-amz-request-id: tx00000f7714c6380dacf35-0069647969-184880ea2-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=S_bguf1fUwYBKcWyH7oGpOMd6U.6gX8BtMKbdxdpLcI-1768192361-1.0.1.1-2OVF6EtAVNO4.Uv9bMTNhU5C9x.4BBxGA2bqmn6EeQFjUonShiWnQRcFo.YcdXHKu4mK1WsIHafDNpB6LSNnWwUIcS_K2_kQ2I5ckYfW4xU; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx00000f7714c6380dacf35-0069647969-184880ea2-fra1b</RequestId><HostId>184880ea2-fra1b-fra1-zg02</HostId></Error>
Open service 172.64.145.29:443 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee739cb0972b-FRA x-amz-request-id: tx000009280335273546f29-0069647969-184880ea2-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=BNmakpDWLUXIPp4WJ6NK.ZBvSVhddNBEa6tm10V4F74-1768192361-1.0.1.1-B3MPDxo.MgoViYivtIGkU1VyRKoKkiUpklIIpmAMtLpPJHHvRTeVjVZBVeUS33FXDo.S43upnW1pZALOJm786Yn6308eSDWJW4Ap6iAtqlg; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly; Secure; SameSite=None Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx000009280335273546f29-0069647969-184880ea2-fra1b</RequestId><HostId>184880ea2-fra1b-fra1-zg02</HostId></Error>
Open service 2606:4700:4405::ac40:911d:443 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee738c263657-FRA x-amz-request-id: tx00000c3ab19ee1dbda1fd-0069647969-184668d08-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=wxreAZqIhrviNNwSeT9uhWSnrS0BfbIAm0.SY3CNmA8-1768192361-1.0.1.1-Y3Ba8f4j1BNvlgVo9AJ79fuEvlmxsgwMPZcj6Z9XVKsY130256BEpOV3mlqORUIr8unZZ8sj_gmn9gK14x7ovROpu4PBB_yanbKNFOO.xpA; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly; Secure; SameSite=None Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx00000c3ab19ee1dbda1fd-0069647969-184668d08-fra1b</RequestId><HostId>184668d08-fra1b-fra1-zg02</HostId></Error>
Open service 104.18.42.227:8443 · assets.ff-office.com
2026-01-12 04:32
Open service 172.64.145.29:80 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee734f2f9a21-FRA x-amz-request-id: tx00000a41fe6fe446f74f5-0069647969-184880ea2-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=6ZzgLLwhUgaVZGe.A.beojcNkM30xv01jHy28Ws.ZpA-1768192361-1.0.1.1-ziDGqkQLpSvKUQDhhKRpeGz1XdSj1Hb0Y6RjAlgj0oGP3q9YByYdxCO4RMHU7jvz4y4pP221PfHDGRG.nmbuvP46ILwxp6BXKz0K0HmEXk0; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx00000a41fe6fe446f74f5-0069647969-184880ea2-fra1b</RequestId><HostId>184880ea2-fra1b-fra1-zg02</HostId></Error>
Open service 104.18.42.227:443 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee736e51b97a-AMS x-amz-request-id: tx000000184758f38726b8a-0069647969-1846a8f6d-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=LTwWNW0ssG3gcvSQHefl3QpQGp2iXThKO8v3vpjNAD4-1768192361-1.0.1.1-eZF7PRLxuy31FRhoWxpAGcVgLrAxFhkiU_nf40flqRu3mpOczfmVW9t9Tw7kiWWX4EEtAwb6uPwEgodtec6b.Xl6m5T0CJ9oLmERH63Wtyc; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly; Secure; SameSite=None Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx000000184758f38726b8a-0069647969-1846a8f6d-fra1b</RequestId><HostId>1846a8f6d-fra1b-fra1-zg02</HostId></Error>
Open service 216.150.1.1:443 · ff-office.com
2026-01-12 04:32
HTTP/1.1 302 Found Age: 0 Cache-Control: public, max-age=0, must-revalidate Date: Mon, 12 Jan 2026 04:32:41 GMT Location: /en/ Server: Vercel Strict-Transport-Security: max-age=63072000 X-Vercel-Cache: MISS X-Vercel-Id: iad1::fra1::ws4mg-1768192361905-b8c82c1a5780 Connection: close Transfer-Encoding: chunked
Open service 2606:4700:4405::ac40:911d:80 · assets.ff-office.com
2026-01-12 04:32
HTTP/1.1 403 Forbidden Date: Mon, 12 Jan 2026 04:32:41 GMT Content-Type: application/xml Content-Length: 255 Connection: close CF-RAY: 9bc9ee733daa7692-LHR x-amz-request-id: tx0000039298cd5c914f5ca-0069647969-184880e57-fra1b Cache-Control: max-age=0 strict-transport-security: max-age=15552000; includeSubDomains; preload x-do-cdn-uuid: 931c7b15-3b66-4dba-94bf-05de249a140c CF-Cache-Status: MISS Set-Cookie: __cf_bm=1eQKMWQkBWTAD6QTnSLjVBsibwKMiWpo2S0bIrjqo30-1768192361-1.0.1.1-AjenjEHwUbJhj1wuYYUylVNOMzUt.D0oVGm0Yyk8v1lgtQGq.zB0PAQRI8OHQ9zdKixylG8J0BakrFXtJHPeYlyDks_57cua3rtEkA.kuWw; path=/; expires=Mon, 12-Jan-26 05:02:41 GMT; domain=.assets.ff-office.com; HttpOnly Server: cloudflare <?xml version="1.0" encoding="UTF-8"?><Error><Code>AccessDenied</Code><Message></Message><BucketName>fuchsfabrik-assets</BucketName><RequestId>tx0000039298cd5c914f5ca-0069647969-184880e57-fra1b</RequestId><HostId>184880e57-fra1b-fra1-zg02</HostId></Error>
Open service 216.150.1.1:80 · ff-office.com
2026-01-12 04:32
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://ff-office.com/ Refresh: 0;url=https://ff-office.com/ server: Vercel Redirecting...
Open service 207.154.213.215:443 · cms.ff-office.com
2026-01-09 09:49
HTTP/1.1 302 Found Server: nginx/1.25.3 Date: Fri, 09 Jan 2026 09:49:47 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;frame-src self http://localhost:3000 https://ff.ff.works/ https://ff-office.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus Access-Control-Allow-Origin: * Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Vary: Accept alt-svc: h3-23=":443"; ma=86400 Found. Redirecting to ./admin
Open service 216.150.1.1:80 · ff-office.com
2026-01-08 15:40
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://ff-office.com/ Refresh: 0;url=https://ff-office.com/ server: Vercel Redirecting...
Open service 216.150.1.1:443 · ff-office.com
2026-01-08 15:40
HTTP/1.1 302 Found Age: 0 Cache-Control: public, max-age=0, must-revalidate Date: Thu, 08 Jan 2026 15:40:04 GMT Location: /en/ Server: Vercel Strict-Transport-Security: max-age=63072000 X-Vercel-Cache: MISS X-Vercel-Id: fra1::fra1::d6vpr-1767886803965-f859e58478cb Connection: close Transfer-Encoding: chunked
Open service 76.76.21.142:80 · www.ff-office.com
2026-01-05 09:54
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://www.ff-office.com/ Refresh: 0;url=https://www.ff-office.com/ server: Vercel Redirecting...
Open service 66.33.60.66:443 · www.ff-office.com
2026-01-05 09:54
HTTP/1.1 308 Permanent Redirect Cache-Control: public, max-age=0, must-revalidate Content-Type: text/plain Date: Mon, 05 Jan 2026 09:54:19 GMT Location: https://ff-office.com/ Refresh: 0;url=https://ff-office.com/ Server: Vercel Strict-Transport-Security: max-age=63072000 X-Vercel-Id: bom1::dhsmk-1767606858814-d9094451996f Connection: close Transfer-Encoding: chunked Redirecting...
Open service 76.76.21.142:443 · www.ff-office.com
2026-01-05 09:54
HTTP/1.1 308 Permanent Redirect Cache-Control: public, max-age=0, must-revalidate Content-Type: text/plain Date: Mon, 05 Jan 2026 09:54:19 GMT Location: https://ff-office.com/ Refresh: 0;url=https://ff-office.com/ Server: Vercel Strict-Transport-Security: max-age=63072000 X-Vercel-Id: bom1::gzd6c-1767606858933-806b947959c6 Connection: close Transfer-Encoding: chunked Redirecting...
Open service 66.33.60.66:80 · www.ff-office.com
2026-01-05 09:54
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://www.ff-office.com/ Refresh: 0;url=https://www.ff-office.com/ server: Vercel Redirecting...
Open service 207.154.213.215:443 · cms.ff-office.com
2026-01-02 10:56
HTTP/1.1 302 Found Server: nginx/1.25.3 Date: Fri, 02 Jan 2026 10:56:47 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;frame-src self http://localhost:3000 https://ff.ff.works/ https://ff-office.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus Access-Control-Allow-Origin: * Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Vary: Accept alt-svc: h3-23=":443"; ma=86400 Found. Redirecting to ./admin
Open service 207.154.213.215:443 · cms.ff-office.com
2025-12-22 15:37
HTTP/1.1 302 Found Server: nginx/1.25.3 Date: Mon, 22 Dec 2025 15:37:29 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;frame-src self http://localhost:3000 https://ff.ff.works/ https://ff-office.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus Access-Control-Allow-Origin: * Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Vary: Accept alt-svc: h3-23=":443"; ma=86400 Found. Redirecting to ./admin
Open service 207.154.213.215:443 · cms.ff-office.com
2025-12-20 16:21
HTTP/1.1 302 Found Server: nginx/1.25.3 Date: Sat, 20 Dec 2025 16:21:53 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 29 Connection: close Content-Security-Policy: script-src 'self' 'unsafe-eval';worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob:;media-src 'self';connect-src 'self' https://*;frame-src self http://localhost:3000 https://ff.ff.works/ https://ff-office.com;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline' X-Powered-By: Directus Access-Control-Allow-Origin: * Access-Control-Allow-Credentials: true Access-Control-Expose-Headers: Content-Range Location: ./admin Vary: Accept alt-svc: h3-23=":443"; ma=86400 Found. Redirecting to ./admin