nginx 1.24.0
tcp/80
nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 91.201.55.247:80 · gitlab.glavportal.com
2024-12-21 02:04
HTTP/1.1 301 Moved Permanently Server: nginx/1.24.0 Date: Sat, 21 Dec 2024 02:04:31 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://gitlab.glavportal.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.24.0</center> </body> </html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-12-21 02:04
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 02:04:41 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKFBBQA9F0NZVH4A4F9WC60","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKFBBQA9F0NZVH4A4F9WC60 X-Runtime: 0.022549 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-12-20 20:09
HTTP/1.1 400 Bad Request Server: nginx Date: Fri, 20 Dec 2024 20:09:24 GMT Content-Type: text/html Content-Length: 650 Connection: close Page title: 400 The plain HTTP request was sent to HTTPS port <html> <head><title>400 The plain HTTP request was sent to HTTPS port</title></head> <body> <center><h1>400 Bad Request</h1></center> <center>The plain HTTP request was sent to HTTPS port</center> <hr><center>nginx</center> </body> </html> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page --> <!-- a padding to disable MSIE and Chrome friendly error page -->
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-12-18 19:36
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 19:36:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDMBXMDQGMKVMMHNQ72SS7D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDMBXMDQGMKVMMHNQ72SS7D X-Runtime: 0.073341 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-12-14 08:47
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 08:47:28 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF25KVP7728RMJ7JWFBQ4NZX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF25KVP7728RMJ7JWFBQ4NZX X-Runtime: 0.074981 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-12-12 14:31
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 14:31:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXMH3CQEQFTCR47Q9JBGY78","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXMH3CQEQFTCR47Q9JBGY78 X-Runtime: 0.086540 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-12-02 18:01
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 18:01:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE48H6Y1HRYV9M31VAZYV2PY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE48H6Y1HRYV9M31VAZYV2PY X-Runtime: 0.074028 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-11-30 18:53
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 18:53:13 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ6PYJAGFH7TKCA0YDS912Z","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ6PYJAGFH7TKCA0YDS912Z X-Runtime: 0.072647 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-11-28 08:30
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 08:30:39 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRY9JBNTPR8FPYYH7PJ6DS4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRY9JBNTPR8FPYYH7PJ6DS4 X-Runtime: 0.069181 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>
Open service 91.201.55.247:443 · gitlab.glavportal.com
2024-11-20 22:19
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 22:20:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.glavportal.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5TJKC3CA6K20TWAZ3HRY2F","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5TJKC3CA6K20TWAZ3HRY2F X-Runtime: 0.114664 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.glavportal.com/users/sign_in">redirected</a>.</body></html>