Apache
tcp/443 tcp/80
awselb 2.0
tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbf243ce0a
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://gitee.com/heyingmin/vueadmin-thinkphp.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbf243ce0a
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://gitee.com/heyingmin/vueadmin-thinkphp.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 8.208.90.19:443 · www.hcfonlineorder.co.uk
2026-01-09 15:50
HTTP/1.1 200 OK Date: Fri, 09 Jan 2026 15:50:28 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=60c254b5579599738508e740c771dd95; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · hcfonlineorder.co.uk
2026-01-09 01:22
HTTP/1.1 200 OK Date: Fri, 09 Jan 2026 01:22:22 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=3add5834b38712544d3664e90369d4f2; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.hcfonlineorder.co.uk
2026-01-07 10:13
HTTP/1.1 200 OK Date: Wed, 07 Jan 2026 10:13:48 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=24ad4a476f331f21cbe4d2f2c9cb0dc4; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 3.33.251.168:443 · hcfonlineorder.co.uk
2026-01-07 10:13
HTTP/1.0 400 Bad Request Client sent an HTTP request to an HTTPS server.
Open service 15.197.225.128:80 · hcfonlineorder.co.uk
2026-01-07 10:13
HTTP/1.1 403 Forbidden Server: awselb/2.0 Date: Wed, 07 Jan 2026 10:13:47 GMT Content-Type: text/html Content-Length: 118 Connection: close Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 8.208.90.19:80 · www.hcfonlineorder.co.uk
2026-01-07 10:13
HTTP/1.1 301 Moved Permanently Date: Wed, 07 Jan 2026 10:14:26 GMT Server: Apache Location: https://www.hcfonlineorder.co.uk/ Content-Length: 315 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://www.hcfonlineorder.co.uk/">here</a>.</p> <hr> <address>Apache Server at www.hcfonlineorder.co.uk Port 80</address> </body></html>
Open service 3.33.251.168:80 · hcfonlineorder.co.uk
2026-01-07 10:13
HTTP/1.1 403 Forbidden Server: awselb/2.0 Date: Wed, 07 Jan 2026 10:13:47 GMT Content-Type: text/html Content-Length: 118 Connection: close Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> </body> </html>
Open service 15.197.225.128:443 · hcfonlineorder.co.uk
2026-01-07 10:13
HTTP/1.0 400 Bad Request Client sent an HTTP request to an HTTPS server.
Open service 8.208.90.19:443 · www.hcfonlineorder.co.uk
2026-01-02 09:47
HTTP/1.1 200 OK Date: Fri, 02 Jan 2026 09:47:11 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=42d8e38c0046fbf72e5c7da19ce01b0a; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · hcfonlineorder.co.uk
2026-01-01 22:37
HTTP/1.1 200 OK Date: Thu, 01 Jan 2026 22:37:23 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=7db0288aa3e44871c74d9921c18c6bfe; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · hcfonlineorder.co.uk
2025-12-30 07:59
HTTP/1.1 200 OK Date: Tue, 30 Dec 2025 07:59:29 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=625aa452735ee616bc43547238d7214e; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · hcfonlineorder.co.uk
2025-12-23 01:58
HTTP/1.1 200 OK Date: Tue, 23 Dec 2025 01:58:01 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=554a5fd4b8bfcda41095f6803f9d839c; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.hcfonlineorder.co.uk
2025-12-22 23:41
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 23:41:43 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=a1e3ff00b73178d86f6b387f999d92a4; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.hcfonlineorder.co.uk
2025-12-20 05:39
HTTP/1.1 200 OK Date: Sat, 20 Dec 2025 05:39:29 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=b9a2803a448233581c15262f7451f716; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8