cloudflare
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba9188402a1076f5f9897525c
[init] defaultBranch = none [fetch] recurseSubmodules = false [http "https://gitlab.tag.app.br"] sslCAInfo = /home/gitlab-runner/builds/BNC5BD7u/0/grupoab/site.tmp/CI_SERVER_TLS_CA_FILE [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:HuXQ7vcsiQsEqJinBGMk@gitlab.tag.app.br/grupoab/site.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba9188402a1076f5f56a92fda
[init] defaultBranch = none [fetch] recurseSubmodules = false [http "https://gitlab.tag.app.br"] sslCAInfo = /home/gitlab-runner/builds/BNC5BD7u/0/grupoab/site.tmp/CI_SERVER_TLS_CA_FILE [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:maQ76cqhSByrBBXnxHjf@gitlab.tag.app.br/grupoab/site.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba9188402a1076f5f6ecd19be
[init] defaultBranch = none [fetch] recurseSubmodules = false [http "https://gitlab.tag.app.br"] sslCAInfo = /home/gitlab-runner/builds/BNC5BD7u/0/grupoab/site.tmp/CI_SERVER_TLS_CA_FILE [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:oTSsJVSdz_SZrby4DUnH@gitlab.tag.app.br/grupoab/site.git fetch = +refs/heads/*:refs/remotes/origin/*
Open service 104.26.5.114:443 ยท grupoab.com.br
2026-01-10 14:01
HTTP/1.1 301 Moved Permanently
Date: Sat, 10 Jan 2026 14:01:59 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
location: https://www.grupoab.com.br/
strict-transport-security: max-age=31536000; includeSubDomains
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=13,cfOrigin;dur=548
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=35DKuv%2BRsm9cX0zkhFuaTc%2FyLTpfweADsQ097zyI7TJhrd6U0IOqXPg3PKW0YGnrj2X%2BcnfSRKrFcSbyOWLlBj45eFyNjGVBb1g6"}]}
CF-RAY: 9bbcb59e1c1ba22e-YYZ
alt-svc: h3=":443"; ma=86400
Page title: 301 Moved Permanently
<html>
<head><title>301 Moved Permanently</title></head>
<body>
<center><h1>301 Moved Permanently</h1></center>
<hr><center>nginx</center>
<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"8ced716e22e1439cbf0234a12f81b3f6","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body>
</html>