nginx
tcp/443 tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65220ab4e5c9
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:qoddiapps/evercontact-websitev3.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Open service 139.64.165.162:80 · fzatdqnkjw.us05.fldrv.com
2024-12-17 21:39
HTTP/1.1 302 Moved Temporarily Server: nginx Date: Tue, 17 Dec 2024 21:39:15 GMT Content-Type: text/html Content-Length: 138 Connection: close Location: https://fzatdqnkjw.us05.fldrv.com/ Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>nginx</center> </body> </html>
Open service 139.64.165.162:443 · fzatdqnkjw.us05.fldrv.com
2024-12-17 21:39
HTTP/1.1 200 OK Server: nginx Date: Tue, 17 Dec 2024 21:39:18 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Strict-Transport-Security: max-age=63072000; includeSubDomains X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff