Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d325beceb325beceb325beceb325beceb
Found 1 files trough .DS_Store spidering: /assets
Open service 54.204.238.15:443 · fr.whatsthatcharge.com
2026-01-09 12:02
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"106c5a45f27f442beff704130c5814b1"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=nSnlUEVOqT6wzFgjyp3a7nxMBZ%2FLtkSIXhWZKUqoIb4%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767960128"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=nSnlUEVOqT6wzFgjyp3a7nxMBZ%2FLtkSIXhWZKUqoIb4%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767960128"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=Q21OTXE3bng2bG1BSit3ejBBVll0MncrS214ZHA1TzJNU2k0NUR4d2ZhVUpUOUxFK3FqdjNGenhTcDRQVUZWNDAzWVV4alRjR0VIcEVTSTA4VjlacTA1TFZNUkl4T3lTOEVJeDk2TU9nSFVTSDJmSlZqMlNDQmp2ZlJHRjFLOTZia3RBeEYyaVB1UU5DQ3gxWW5ITnBKR0h0L21WMnhPbUppOFpqQWNDOFZJclBDdnhZTHhTa3hXSzNsWnM4bnFULS00NHlpdlJWYkFFOTczRHNRN2lBTzl3PT0%3D--3af0fe978f8a1f1df512b7eba21eebc6ec39ae5d; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 2a3f9449-2357-29d0-85d2-f3af143d95c3
X-Runtime: 0.037460
X-Xss-Protection: 1; mode=block
Date: Fri, 09 Jan 2026 12:02:08 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · fr.whatsthatcharge.com
2026-01-02 15:47
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"e0701ed0d1b2fe2e3c630826f313a11c"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xKwErMTJ6jtYc8mdb5rnf9LTWkxtITBk9WG1JidiVQY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767368857"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xKwErMTJ6jtYc8mdb5rnf9LTWkxtITBk9WG1JidiVQY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767368857"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=UEZ5VXNhQk0wZExadmcrRXphaStZaVkyMkxFR0JubGFJRkx6OU5ZeU9ickE3amI2RFczVFVZOHRNcGxxcnh5VUhhMS9EYXdmZlgzQkFHUmxiSDhsT2ppc0xFVWNnWWVZWmE5WGJHUXNFcDE5MmFRZDNEZ0FUUDVnYnZFVmtVc2RrejFQR3FlZ3FWeURpbW50aTAwekNTb2wraTl0cEVCRyt3OEJNd2hrZWp0YXdNQk5MVGZIWHdWSUhZVm56SkNSLS1mSXJXTjMzNzZLMlVmajYrMVRxdTlRPT0%3D--225b257c90f0f92eaf6acae1c1f335f509abd7c3; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0e2edaa2-0a25-5b0f-3809-9b0e43827d27
X-Runtime: 0.026310
X-Xss-Protection: 1; mode=block
Date: Fri, 02 Jan 2026 15:47:37 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · fr.whatsthatcharge.com
2025-12-22 10:16
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"0806652926c8f02938775a0b0fcda6b1"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=R7nEYKBpbZPom8TYnddTRiXapct84%2FUCDysvNPwBGB0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766398565"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=R7nEYKBpbZPom8TYnddTRiXapct84%2FUCDysvNPwBGB0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766398565"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=OUQvNTlJZHlFMmk2QmV3aGl2ODQvR2ZPSjNNSXV5TzNUU0swWnJud2w4dVVKb2dKaktpMnEvV1lzeTExbWdNNTZmR1lSQnVabkZ5ZFB4MmtWNEF3NkJkU2Z6NWZOem0vcU1UYkJzWnpETXBYV3N3S0FpU0FyM2dETkN1eDJ6TzF1NmVHYnNhVGRQd3JlVEhHcnJzOXVXUEZsbHpzMXNQWEErK2hrRTBNM1MvU2h1cHFlb0ZxUUxaNnU3VUROZDZiLS1ad3cwVXRJb3lwbnJoSmthZVpNSCt3PT0%3D--02cd09ab348cc303794a4c8a7c644b022e5aa4ca; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 645a1ea2-463c-51da-924d-6205730bac1b
X-Runtime: 0.028869
X-Xss-Protection: 1; mode=block
Date: Mon, 22 Dec 2025 10:16:05 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · fr.whatsthatcharge.com
2025-12-21 11:20
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"a473ff62ec307d3a144b3e6b11d7c91c"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=IwuozLE70VxikAU5XnqGbkjVNscVc032EvfZsRptnbY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766316008"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=IwuozLE70VxikAU5XnqGbkjVNscVc032EvfZsRptnbY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766316008"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=UzQxQ253eGVlN2tEc05xSTVINTREdmVDMUlaUDh0cEE3dEd1aVUzekViSWorOS9sTk5sQmJtUm11dTlXUTYva01CMmhnZ2xqWWJjYVpXU3JHb3RHeXQzUGw0RjhvVndRRkwwK21uaUh5U2dtWG1teWMyMGVxMitSalFDOU5Kdkx0NVFjVG8rNG5tMGVtNnBIOWhPSjZHM2RpTWpwQm1kUFZmcTVleHZhTzZVU1NnMHoyQkoyT3ZoUnoyTlZFQTAwLS15bVBydXpiWDYvMzB5a3h6Qk9QZEZnPT0%3D--9210a820623daf05ec3f255cebfb4bc31fa44f98; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 1c4418a3-1035-4d88-b6c1-9b32834f8788
X-Runtime: 0.029110
X-Xss-Protection: 1; mode=block
Date: Sun, 21 Dec 2025 11:20:09 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · fr.whatsthatcharge.com
2025-12-19 07:18
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"0ed3189e0d5de9aa7796cf0a8a286482"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=QSwUEAfqX8GKHBYagxnIG7nzN8aFuD43%2BPWt3sAQ5CM%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766128723"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=QSwUEAfqX8GKHBYagxnIG7nzN8aFuD43%2BPWt3sAQ5CM%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766128723"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=QTRMSno5Vmp0WEJWbWRZckd2WnFhV2kzRnVvR0xzajk3RHF0TFNaQzk1K0VTUU0weGVTQ0VsVjV2NUVuNTFZVm92UjdmN1dnSFJoQkM0NFgrR1M2cEpwTDc4eHlTYklTbUdvTm8ydmt1OVFHMWxpc1p3bEIvRjYrdjJOMjVrc09xUUNQYk9EQjFQa1lodmVLcjVhc0ZRQnh2K3JZaE8zM2hFY2E4cm5OOXhqVE1CSWw2VzF5WXJpN05yMHZHbVZ5LS1GdzJsQzNKa0tPUEk1VDhYT0t0TlJnPT0%3D--dc4b41fea9fd545fe88413fb9483ab7276fdf79f; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 250deea0-aea1-1d33-63a9-4d12c1b6b977
X-Runtime: 0.027030
X-Xss-Protection: 1; mode=block
Date: Fri, 19 Dec 2025 07:18:43 GMT
Connection: close
Transfer-Encoding: chunked