Kestrel
tcp/443
Microsoft-IIS 10.0
tcp/443 tcp/80
nginx 1.24.0
tcp/443
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f6356a6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://git.tt-rss.org/fox/tt-rss fetch = +refs/heads/master:refs/remotes/origin/master [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222f6356a6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://git.tt-rss.org/fox/tt-rss fetch = +refs/heads/master:refs/remotes/origin/master [branch "master"] remote = origin merge = refs/heads/master
Open service 79.247.234.62:80 · ttrss.fuechse-online.de
2024-10-16 19:56
HTTP/1.1 404 Not Found Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Wed, 16 Oct 2024 19:56:25 GMT Content-Length: 19 Connection: close 404 page not found
Open service 79.247.234.62:443 · ttrss.fuechse-online.de
2024-10-16 19:56
HTTP/1.1 200 OK Cache-Control: public Content-Type: text/html; charset=UTF-8 Date: Wed, 16 Oct 2024 19:56:26 GMT Server: nginx/1.24.0 X-Extern: externer response X-Powered-By: PHP/8.1.20 Connection: close Transfer-Encoding: chunked Page title: Tiny Tiny RSS : Login <!DOCTYPE html> <html> <head> <title>Tiny Tiny RSS : Login</title> <link rel="shortcut icon" type="image/png" href="images/favicon.png"> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> <script src="lib/dojo/dojo.js?1687656380" type="text/javascript" charset="utf-8"></script> <script src="lib/dojo/tt-rss-layer.js?1687656380" type="text/javascript" charset="utf-8"></script> <script src="js/common.js?1687656379" type="text/javascript" charset="utf-8"></script> <script src="js/utility.js?1687656379" type="text/javascript" charset="utf-8"></script> <script src="themes.local/local-overrides.js?1687656346" type="text/javascript" charset="utf-8"></script> <style type="text/css"> @media (prefers-color-scheme: dark) { body { background : #303030; } } body.css_loading * { display : none; } </style> <script type="text/javascript"> require({cache:{}}); </script> <script type="text/javascript"> /* exported Plugins */ const Plugins = {}; </script> </head> <body class="flat ttrss_utility ttrss_login css_loading"> <script type="text/javascript"> const UtilityApp = { previousLogin: "", init: function() { /* invoked by UtilityJS */ require(['dojo/parser', "dojo/ready", 'dijit/form/Button','dijit/form/CheckBox', 'dijit/form/Form', 'dijit/form/Select','dijit/form/TextBox','dijit/form/ValidationTextBox'],function(parser, ready){ ready(function() { parser.parse(); dijit.byId("bw_limit").attr("checked", Cookie.get("ttrss_bwlimit") == 'true'); dijit.byId("login").focus(); }); }); }, fetchProfiles: function() { const login = dijit.byId("login").attr('value'); if (login && login != this.previousLogin) { this.previousLogin = login; xhr.json("public.php", {op: "getprofiles", login: login}, (reply) => { const profile = dijit.byId('profile'); profile.removeOption(profile.getOptions()); reply.forEach((p) => { profile .attr("disabled", false) .addOption(p); }); }); } }, gotoRegForm: function() { window.location.href = "register.php"; return false; }, bwLimitChange: function(elem) { Cookie.set("ttrss_bwlimit", elem.checked, 86400); } }; </script> <div class="container"> <h1>Authentication</h1> <div class="content"> <form action="public.php?return=https%3A%2F%2Fttrss.fuechse-online.de%2F" dojoType="dijit.form.Form" method="POST"> <input dojoType="dijit.form.TextBox" style="display : none" name="op" value="login"> <fieldset> <label>Login:</label> <input name="login" id="login" dojoType="dijit.form.TextBox" type="text" onchange="UtilityApp.fetchProfiles()" onfocus="UtilityApp.fetchProfiles()" onblur="UtilityApp.fetchProfiles()" required="1" value="" /> </fieldset> <fieldset> <label>Password:</label> <input type="password" name="password" required="1" dojoType="dijit.form.TextBox" class="input input-text" onchange="UtilityApp.fetchProfiles()" onfocus="UtilityApp.fetchProfiles()" onblur="UtilityApp.fetchProfiles()" value=""/> </fieldset> <fieldset class="align-right"> <a href="public.php?op=forgotpass">I forgot my password</a> </fieldset> <fieldset> <label>Profile:</label> <select disabled='disabled' name="profile" id="profile" dojoType='dijit.form.Select'> <option>Default profile</option> </select> </fieldset> <fieldset class="narrow"> <label> </label> <label id="bw_limit_label"> <input dojoType='dijit.form.CheckBox' name="bw_limit" onchange="UtilityApp.bwLimitChange(this)" id="bw_limit">
Open service 79.247.234.62:443 · haus.fuechse-online.de
2024-10-15 19:58
HTTP/1.1 302 Found Content-Length: 0 Date: Tue, 15 Oct 2024 19:58:04 GMT Location: hc3 Server: Kestrel X-Extern: reponse nach aussen Connection: close
Open service 79.247.234.62:80 · haus.fuechse-online.de
2024-10-15 19:58
HTTP/1.1 404 Not Found Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Tue, 15 Oct 2024 19:58:04 GMT Content-Length: 19 Connection: close 404 page not found
Open service 217.160.0.111:443 · fuechse-online.de
2024-09-24 03:57
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: Microsoft-IIS/10.0 Strict-Transport-Security: max-age=2592000 X-Powered-By: ASP.NET Date: Tue, 24 Sep 2024 03:57:17 GMT Page title: Home page - FuechseOnlineNet6 <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <title>Home page - FuechseOnlineNet6</title> <link rel="stylesheet" href="/lib/bootstrap/dist/css/bootstrap.min.css" /> <link rel="stylesheet" href="/css/site.css?v=AKvNjO3dCPPS0eSU1Ez8T2wI280i08yGycV9ndytL-c" /> <link rel="stylesheet" href="/FuechseOnlineNet6.styles.css?v=a4VQNaXqbPDDVzSYCa0KfjYhw-dZvp9L6T2hLA16kcM" /> </head> <body> <header> <nav b-dkv2ncwh38 class="navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3"> <div b-dkv2ncwh38 class="container"> <a class="navbar-brand" href="/">Füchse-online</a> <button b-dkv2ncwh38 class="navbar-toggler" type="button" data-toggle="collapse" data-target=".navbar-collapse" aria-controls="navbarSupportedContent" aria-expanded="false" aria-label="Toggle navigation"> <span b-dkv2ncwh38 class="navbar-toggler-icon"></span> </button> <div b-dkv2ncwh38 class="navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse"> <ul b-dkv2ncwh38 class="navbar-nav flex-grow-1"> <li b-dkv2ncwh38 class="nav-item"> <a class="nav-link text-dark" href="/">Home</a> </li> <li b-dkv2ncwh38 class="nav-item"> <a b-dkv2ncwh38 class="nav-link text-dark" href="https://reisen.fuechse-online.de">Reiseberichte</a> </li> <li b-dkv2ncwh38 class="nav-item"> <a class="nav-link text-dark" href="/Impressum">Impressum</a> </li> <li b-dkv2ncwh38 class="nav-item"> <a class="nav-link text-dark" href="/Datenschutz">Datenschutz</a> </li> </ul> </div> </div> </nav> </header> <div b-dkv2ncwh38 class="container"> <main b-dkv2ncwh38 role="main" class="pb-3"> <div class="text-center"> <p>Immer noch Baustelle</p> <p>Derzeit sind nur die <a href="https://reisen.fuechse-online.de">Reiseberichte</a> verfügbar </p> </div> </main> </div> <footer b-dkv2ncwh38 class="border-top footer text-muted"> <div b-dkv2ncwh38 class="container"> © 2022 - FuechseOnlineNet6 - <a href="/Privacy">Privacy</a> </div> </footer> <script src="/lib/jquery/dist/jquery.min.js"></script> <script src="/lib/bootstrap/dist/js/bootstrap.bundle.min.js"></script> <script src="/js/site.js?v=4q1jwFhaPaZgr8WAUSrux6hAuh0XDg9kPS3xIVq36I0"></script> </body> </html>
Open service 2001:8d8:100f:f000::27a:80 · fuechse-online.de
2024-09-24 03:57
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Connection: close Location: https://fuechse-online.de/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Tue, 24 Sep 2024 03:57:16 GMT
Open service 2001:8d8:100f:f000::27a:443 · fuechse-online.de
2024-09-24 03:57
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: Microsoft-IIS/10.0 Strict-Transport-Security: max-age=2592000 X-Powered-By: ASP.NET Date: Tue, 24 Sep 2024 03:57:17 GMT Page title: Home page - FuechseOnlineNet6 <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <title>Home page - FuechseOnlineNet6</title> <link rel="stylesheet" href="/lib/bootstrap/dist/css/bootstrap.min.css" /> <link rel="stylesheet" href="/css/site.css?v=AKvNjO3dCPPS0eSU1Ez8T2wI280i08yGycV9ndytL-c" /> <link rel="stylesheet" href="/FuechseOnlineNet6.styles.css?v=a4VQNaXqbPDDVzSYCa0KfjYhw-dZvp9L6T2hLA16kcM" /> </head> <body> <header> <nav b-dkv2ncwh38 class="navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3"> <div b-dkv2ncwh38 class="container"> <a class="navbar-brand" href="/">Füchse-online</a> <button b-dkv2ncwh38 class="navbar-toggler" type="button" data-toggle="collapse" data-target=".navbar-collapse" aria-controls="navbarSupportedContent" aria-expanded="false" aria-label="Toggle navigation"> <span b-dkv2ncwh38 class="navbar-toggler-icon"></span> </button> <div b-dkv2ncwh38 class="navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse"> <ul b-dkv2ncwh38 class="navbar-nav flex-grow-1"> <li b-dkv2ncwh38 class="nav-item"> <a class="nav-link text-dark" href="/">Home</a> </li> <li b-dkv2ncwh38 class="nav-item"> <a b-dkv2ncwh38 class="nav-link text-dark" href="https://reisen.fuechse-online.de">Reiseberichte</a> </li> <li b-dkv2ncwh38 class="nav-item"> <a class="nav-link text-dark" href="/Impressum">Impressum</a> </li> <li b-dkv2ncwh38 class="nav-item"> <a class="nav-link text-dark" href="/Datenschutz">Datenschutz</a> </li> </ul> </div> </div> </nav> </header> <div b-dkv2ncwh38 class="container"> <main b-dkv2ncwh38 role="main" class="pb-3"> <div class="text-center"> <p>Immer noch Baustelle</p> <p>Derzeit sind nur die <a href="https://reisen.fuechse-online.de">Reiseberichte</a> verfügbar </p> </div> </main> </div> <footer b-dkv2ncwh38 class="border-top footer text-muted"> <div b-dkv2ncwh38 class="container"> © 2022 - FuechseOnlineNet6 - <a href="/Privacy">Privacy</a> </div> </footer> <script src="/lib/jquery/dist/jquery.min.js"></script> <script src="/lib/bootstrap/dist/js/bootstrap.bundle.min.js"></script> <script src="/js/site.js?v=4q1jwFhaPaZgr8WAUSrux6hAuh0XDg9kPS3xIVq36I0"></script> </body> </html>
Open service 217.160.0.111:80 · fuechse-online.de
2024-09-24 03:57
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Connection: close Location: https://fuechse-online.de/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Tue, 24 Sep 2024 03:57:16 GMT