nginx
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c8f03d7bd8f03d7bd6e3758f603d4b1a76e3a63c058f50637
Found 38 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09c99d3320899d33208c3af8875e1889108d2b85c0fe56ae2b1
Found 44 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /qphtml/static /qphtml/static/active /qphtml/static/css /qphtml/static/img /qphtml/static/js /qphtml/static/mp4 /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09c7d264b917d264b912bed5b224ff64ddb00a48a4c664f9918
Found 52 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /qphtml/static /qphtml/static/active /qphtml/static/css /qphtml/static/img /qphtml/static/js /qphtml/static/mp4 /static /static-amhg /ts-download /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download /tsnew-download/css /tsnew-download/images /tsnew-download/js /tsnew-download/muse-ui
Severity: medium
Fingerprint: 5f32cf5d6962f09c3e8b9cac3e8b9cac0b6b4661b29f418cb0ed470b6bce67d0
Found 48 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /qphtml/static /qphtml/static/active /qphtml/static/css /qphtml/static/img /qphtml/static/js /qphtml/static/mp4 /static /static-amhg /ts-download /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b6e32174b30812a2ea51c22c6d9a9d136b
Found 28 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c3838040e3838040e7ad6bcebe57a3e4242c116c55fdef6dd
Found 20 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09ca629b8b1a629b8b1461559c22d7bc4fbba3a33ecac0bc682
Found 34 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/images /landing-login/js /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c47dfe71947dfe719155d132a71296f030021b0d46c89c05f
Found 16 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /event /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09ca0cc0fcfa0cc0fcf947301c83d9eabc5c40700aa24fffbf6
Found 25 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/js /event/mp4 /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c8efce1938efce1937a2086540879bed91a31a9763bb40fdb
Found 36 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09c7d264b917d264b912bed5b224ff64ddb00a48a4c664f9918
Found 52 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /qphtml/static /qphtml/static/active /qphtml/static/css /qphtml/static/img /qphtml/static/js /qphtml/static/mp4 /static /static-amhg /ts-download /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download /tsnew-download/css /tsnew-download/images /tsnew-download/js /tsnew-download/muse-ui
Severity: medium
Fingerprint: 5f32cf5d6962f09c3e8b9cac3e8b9cac0b6b4661b29f418cb0ed470b6bce67d0
Found 48 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /qphtml/static /qphtml/static/active /qphtml/static/css /qphtml/static/img /qphtml/static/js /qphtml/static/mp4 /static /static-amhg /ts-download /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c47dfe71947dfe719155d132a71296f030021b0d46c89c05f
Found 16 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /event /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09c8f03d7bd8f03d7bd6e3758f603d4b1a76e3a63c058f50637
Found 38 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09c99d3320899d33208c3af8875e1889108d2b85c0fe56ae2b1
Found 44 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/css/h5 /landing-login/images /landing-login/images/pc /landing-login/js /landing-login/js/crypto-es /landing-login/js/qs /new-download /qphtml /qphtml/static /qphtml/static/active /qphtml/static/css /qphtml/static/img /qphtml/static/js /qphtml/static/mp4 /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b6e32174b30812a2ea51c22c6d9a9d136b
Found 28 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c3838040e3838040e7ad6bcebe57a3e4242c116c55fdef6dd
Found 20 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: medium
Fingerprint: 5f32cf5d6962f09ca629b8b1a629b8b1461559c22d7bc4fbba3a33ecac0bc682
Found 34 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /landing-login/css /landing-login/images /landing-login/js /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c2a439cf82a439cf8ce7a926524c8951840ac91df84782a88
Found 31 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/img/active /event/img/sites /event/img/src /event/js /event/mp4 /landing /landing/css /landing/images /landing/js /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09ca0cc0fcfa0cc0fcf947301c83d9eabc5c40700aa24fffbf6
Found 25 files trough .DS_Store spidering: /.git /888 /app-deskservice /app-deskservice/css /app-deskservice/js /app-deskservice/static /app-download /app-download/css /app-download/files /app-download/images /app-download/js /event /event/active /event/css /event/img /event/js /event/mp4 /landing /landing-login /new-download /qphtml /static /static-amhg /ts-download /tsnew-download
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522def08037
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = root@6669786.com:lottery-site/lottery-repo-amhg fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522def08037
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = root@6669786.com:lottery-site/lottery-repo-amhg fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 104.160.179.251:443 · www.h53995.com
2026-01-23 04:49
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 23 Jan 2026 04:49:33 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4350
Connection: close
Vary: Accept-Encoding
Last-Modified: Sat, 04 Oct 2025 12:00:55 GMT
ETag: "68e10c77-10fe"
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Accept-Ranges: bytes
Page title: Welcome
<!DOCTYPE html>
<html style="height: 100%;">
<head>
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" />
<title>Welcome</title>
<script>
function isMobile() {
return !!(navigator.userAgent.match(
/(phone|pad|pod|iPhone|iPod|ios|iPad|android|Mobile|BlackBerry|IEMobile|MQQBrowser|JUC|Fennec|wOSBrowser|BrowserNG|WebOS|Symbian|Windows Phone)/i
))
}
if (isMobile() !== false) {
if (location.href.indexOf('#') > -1) {
location.href = location.origin + '/m/#/home?' + (location.href.split('#')[1].split('?')[1] || '')
} else {
location.href = location.origin + '/m/#/home' + location.search
}
}
(function () {
var url = window.location.href,
obj = {},
keyvalue = [],
key = '',
value = '',
parseString = url.substring(url.indexOf('?') + 1, url.length).split('&')
for (var i in parseString) {
keyvalue = parseString[i].split('=')
key = keyvalue[0]
value = keyvalue[1] && keyvalue[1].includes('#/') ? keyvalue[1].split('#/')[0] : keyvalue[1]
obj[key] = value
}
if (obj.agent) {
localStorage.setItem('agent', obj.agent)
}
if (obj.isPcInfo) {
isPcInfo = obj.isPcInfo;
}
if(obj.register){
if(!localStorage.token){
localStorage.setItem('register', obj.register)
}
}
})()
window.vis = true
window.onblur = function () {
window.vis = false
}
window.onfocus = function () {
window.vis = true
if (typeof window.balanceTask === 'function') {
window.balanceTask()
}
}
if(!document.querySelector('.statistics')) {
let head = document.head || document.getElementsByTagName('head')[0];
let script = document.createElement('script');
let div = document.createElement('div');
div.classList = 'statistics'
div.style.position = 'fixed'
div.style.left = '-9999px'
div.style.top = '-9999px'
script.setAttribute("src", "https://hm.baidu.com/hm.js?d31496c5dd1bc8f680917e22dbaf6106");
div.appendChild(script);
head.appendChild(div);
}
if(!isMobile()) {
function loadJS( url, callback ) {
var script = document.createElement('script'),
fn = callback || function(){};
script.type = 'text/javascript';
//IE
if(script.readyState){
script.onreadystatechange = function(){
if( script.readyState == 'loaded' || script.readyState == 'complete' ){
script.onreadystatechange = null;
fn()
}
}
}else{
// 其他浏览器
script.onload = function(){
fn()
}
}
script.src = url;
document.getElementsByTagName('head')[0].appendChild(script);
}
let loadTable = ['/static/public/js/stomp.js', '/static/public/js/qrcode.js'
, `https://cstaticdun.126.net/load.min.js?t=1759565099345`,
`https://acstatic-dun.126.net/tool.min.js?t=1759565099345`
]
// 用法
loadTable.forEach( (url) => {
loadJS(url,function(e){
// console.log("🚀 ~ file: index.html ~ line 85 ~ loadJS ~ url loaded success", url)
})
})
}
</script>
<link rel="shortcut icon" href="/static/amhg/img/favicon.ico" type="image/x-icon">
<!-- <script src="/static/public/js/stomp.js"></script>
<script src="/static/public/js/qrcode.js"></script>
<script src="https://cstaticdun.126.net/load.min.js?t=201903281201"></script>
<script type="text/javascript" src="https://acstatic-dun.126.net/tool.min.js?t=201903281201"></script> -->
<link href="/static-amhg/style.css" rel="stylesheet"><link href="/static-amhg/css/pages/amhg/index.162c11812b5978cb64ae8485fdf0170d.css" rel="stylesheet"></head>
<body style="height: 100%;">
<div id="klkApp">
</div>
<script type="text/javascript" src="/static-amhg/js/manifest.8c360726061d06cd94fe.js?v=2025-10-4-16:04:46"></script><
Open service 104.160.179.226:443 · h53995.com
2026-01-23 03:08
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 23 Jan 2026 03:08:45 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4350
Connection: close
Vary: Accept-Encoding
Last-Modified: Sat, 04 Oct 2025 12:00:55 GMT
ETag: "68e10c77-10fe"
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Accept-Ranges: bytes
Page title: Welcome
<!DOCTYPE html>
<html style="height: 100%;">
<head>
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" />
<title>Welcome</title>
<script>
function isMobile() {
return !!(navigator.userAgent.match(
/(phone|pad|pod|iPhone|iPod|ios|iPad|android|Mobile|BlackBerry|IEMobile|MQQBrowser|JUC|Fennec|wOSBrowser|BrowserNG|WebOS|Symbian|Windows Phone)/i
))
}
if (isMobile() !== false) {
if (location.href.indexOf('#') > -1) {
location.href = location.origin + '/m/#/home?' + (location.href.split('#')[1].split('?')[1] || '')
} else {
location.href = location.origin + '/m/#/home' + location.search
}
}
(function () {
var url = window.location.href,
obj = {},
keyvalue = [],
key = '',
value = '',
parseString = url.substring(url.indexOf('?') + 1, url.length).split('&')
for (var i in parseString) {
keyvalue = parseString[i].split('=')
key = keyvalue[0]
value = keyvalue[1] && keyvalue[1].includes('#/') ? keyvalue[1].split('#/')[0] : keyvalue[1]
obj[key] = value
}
if (obj.agent) {
localStorage.setItem('agent', obj.agent)
}
if (obj.isPcInfo) {
isPcInfo = obj.isPcInfo;
}
if(obj.register){
if(!localStorage.token){
localStorage.setItem('register', obj.register)
}
}
})()
window.vis = true
window.onblur = function () {
window.vis = false
}
window.onfocus = function () {
window.vis = true
if (typeof window.balanceTask === 'function') {
window.balanceTask()
}
}
if(!document.querySelector('.statistics')) {
let head = document.head || document.getElementsByTagName('head')[0];
let script = document.createElement('script');
let div = document.createElement('div');
div.classList = 'statistics'
div.style.position = 'fixed'
div.style.left = '-9999px'
div.style.top = '-9999px'
script.setAttribute("src", "https://hm.baidu.com/hm.js?d31496c5dd1bc8f680917e22dbaf6106");
div.appendChild(script);
head.appendChild(div);
}
if(!isMobile()) {
function loadJS( url, callback ) {
var script = document.createElement('script'),
fn = callback || function(){};
script.type = 'text/javascript';
//IE
if(script.readyState){
script.onreadystatechange = function(){
if( script.readyState == 'loaded' || script.readyState == 'complete' ){
script.onreadystatechange = null;
fn()
}
}
}else{
// 其他浏览器
script.onload = function(){
fn()
}
}
script.src = url;
document.getElementsByTagName('head')[0].appendChild(script);
}
let loadTable = ['/static/public/js/stomp.js', '/static/public/js/qrcode.js'
, `https://cstaticdun.126.net/load.min.js?t=1759565099345`,
`https://acstatic-dun.126.net/tool.min.js?t=1759565099345`
]
// 用法
loadTable.forEach( (url) => {
loadJS(url,function(e){
// console.log("🚀 ~ file: index.html ~ line 85 ~ loadJS ~ url loaded success", url)
})
})
}
</script>
<link rel="shortcut icon" href="/static/amhg/img/favicon.ico" type="image/x-icon">
<!-- <script src="/static/public/js/stomp.js"></script>
<script src="/static/public/js/qrcode.js"></script>
<script src="https://cstaticdun.126.net/load.min.js?t=201903281201"></script>
<script type="text/javascript" src="https://acstatic-dun.126.net/tool.min.js?t=201903281201"></script> -->
<link href="/static-amhg/style.css" rel="stylesheet"><link href="/static-amhg/css/pages/amhg/index.162c11812b5978cb64ae8485fdf0170d.css" rel="stylesheet"></head>
<body style="height: 100%;">
<div id="klkApp">
</div>
<script type="text/javascript" src="/static-amhg/js/manifest.8c360726061d06cd94fe.js?v=2025-10-4-16:04:46"></script><