nginx
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Open service 3.64.246.65:443 · gitlab.bfops.io
2026-01-25 00:37
HTTP/1.1 302 Found
Server: nginx
Date: Sun, 25 Jan 2026 00:37:43 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 103
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.bfops.io/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KFS9BMF9R75C7KZC7XNHSNE1","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KFS9BMF9R75C7KZC7XNHSNE1
X-Runtime: 0.031203
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://gitlab.bfops.io/users/sign_in">redirected</a>.</body></html>
Open service 3.64.246.65:80 · gitlab.bfops.io
2026-01-25 00:37
HTTP/1.1 301 Moved Permanently Server: nginx Date: Sun, 25 Jan 2026 00:37:42 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://gitlab.bfops.io:443/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 3.64.246.65:443 · gitlab.bfops.io
2026-01-22 23:36
HTTP/1.1 302 Found
Server: nginx
Date: Thu, 22 Jan 2026 23:36:10 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 103
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.bfops.io/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KFM11G36EXAA1J5D1J6VS7S8","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KFM11G36EXAA1J5D1J6VS7S8
X-Runtime: 0.025583
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://gitlab.bfops.io/users/sign_in">redirected</a>.</body></html>
Open service 3.64.246.65:443 · gitlab.bfops.io
2026-01-09 22:06
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 09 Jan 2026 22:06:34 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 103
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.bfops.io/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KEJCR2RJGDC7X5P43W4PM9RR","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KEJCR2RJGDC7X5P43W4PM9RR
X-Runtime: 0.024740
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://gitlab.bfops.io/users/sign_in">redirected</a>.</body></html>
Open service 3.64.246.65:443 · gitlab.bfops.io
2025-12-22 12:50
HTTP/1.1 302 Found
Server: nginx
Date: Mon, 22 Dec 2025 12:50:18 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 103
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.bfops.io/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD31RKAHVAXCCP0DYGKA8BGJ","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD31RKAHVAXCCP0DYGKA8BGJ
X-Runtime: 0.026135
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://gitlab.bfops.io/users/sign_in">redirected</a>.</body></html>