Apache 2.4.52
tcp/80
nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-12-22 03:50
HTTP/1.1 302 Found Date: Sun, 22 Dec 2024 03:50:35 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP7T0A1SAEKZZN78BDYZSFY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP7T0A1SAEKZZN78BDYZSFY X-Runtime: 0.024075 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-12-20 06:17
HTTP/1.1 302 Found Date: Fri, 20 Dec 2024 06:16:48 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHBC97Q9JE1R2FYQ64505QE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHBC97Q9JE1R2FYQ64505QE X-Runtime: 0.103606 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-12-19 00:13
HTTP/1.1 302 Found Date: Thu, 19 Dec 2024 00:12:57 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE45B44S8A2H69NMEPQZBSZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE45B44S8A2H69NMEPQZBSZ X-Runtime: 0.044951 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-12-14 15:19
HTTP/1.1 302 Found Date: Sat, 14 Dec 2024 15:18:55 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2W0M4M50WYHM1M2WJK5X0E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2W0M4M50WYHM1M2WJK5X0E X-Runtime: 0.023631 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-12-12 22:13
HTTP/1.1 302 Found Date: Thu, 12 Dec 2024 22:13:22 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYEY2J05W77JV42V27YE0M4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYEY2J05W77JV42V27YE0M4 X-Runtime: 0.024073 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-12-03 00:31
HTTP/1.1 302 Found Date: Tue, 03 Dec 2024 00:30:47 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4YTFM2GDVF085YMNZG59HW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4YTFM2GDVF085YMNZG59HW X-Runtime: 0.120707 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-11-30 17:17
HTTP/1.1 302 Found Date: Sat, 30 Nov 2024 17:17:29 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ17NXRRZ03J8RNK1MD0G9Q","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ17NXRRZ03J8RNK1MD0G9Q X-Runtime: 0.032591 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-11-28 15:56
HTTP/1.1 302 Found Date: Thu, 28 Nov 2024 15:55:35 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSQR91QXD9T8SDYJFGNGJ7C","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSQR91QXD9T8SDYJFGNGJ7C X-Runtime: 0.074630 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-11-26 22:55
HTTP/1.1 302 Found Date: Tue, 26 Nov 2024 22:54:52 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNAYJ3W2AE5MZ12N3Q8H5Q6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNAYJ3W2AE5MZ12N3Q8H5Q6 X-Runtime: 0.050066 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-11-26 16:39
HTTP/1.1 302 Found Date: Tue, 26 Nov 2024 16:38:52 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMNE37AGTJ97G67NHMEDQRG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMNE37AGTJ97G67NHMEDQRG X-Runtime: 0.033682 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>
Open service 187.102.80.227:80 · git.bnet.dev.br
2024-11-26 16:39
HTTP/1.1 301 Moved Permanently Date: Tue, 26 Nov 2024 16:38:45 GMT Server: Apache/2.4.52 (Ubuntu) Location: https://git.bnet.dev.br/ Content-Length: 313 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://git.bnet.dev.br/">here</a>.</p> <hr> <address>Apache/2.4.52 (Ubuntu) Server at git.bnet.dev.br Port 80</address> </body></html>
Open service 187.102.80.227:443 · git.bnet.dev.br
2024-11-21 00:15
HTTP/1.1 302 Found Date: Thu, 21 Nov 2024 00:14:57 GMT Server: nginx Strict-Transport-Security: max-age=15768000 Content-Type: text/html; charset=utf-8 Content-Length: 102 Cache-Control: no-cache Content-Security-Policy: Location: http://git.bnet.dev.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD614W157WGKK192TANWPG7V","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD614W157WGKK192TANWPG7V X-Runtime: 0.026559 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://git.bnet.dev.br/users/sign_in">redirected</a>.</body></html>