The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65224496f9fc
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = http://bitbucket.org/marcustoolkit/toolkit-header-image fetch = +refs/heads/master:refs/remotes/origin/master [branch "master"] remote = origin merge = refs/heads/master [user] name = bitbucket-pipelines email = commits-noreply@bitbucket.org [push] default = current [http "http://bitbucket.org/marcustoolkit/toolkit-header-image"] proxy = http://localhost:29418/
Open service 20.4.244.223:443 · header.toolkit.uk
2026-01-09 14:20
HTTP/1.1 200 OK Content-Length: 1 Connection: close Content-Type: text/html Date: Fri, 09 Jan 2026 14:21:13 GMT Cache-Control: public, must-revalidate, max-age=30 ETag: "84880142" Last-Modified: Sat, 03 Jan 2026 09:05:25 GMT Strict-Transport-Security: max-age=10886400; includeSubDomains; preload Referrer-Policy: same-origin X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-DNS-Prefetch-Control: off
Open service 20.4.244.223:443 · header.toolkit.uk
2026-01-02 18:48
HTTP/1.1 200 OK Content-Length: 1 Connection: close Content-Type: text/html Date: Fri, 02 Jan 2026 18:48:12 GMT Cache-Control: public, must-revalidate, max-age=30 ETag: "46683183" Last-Modified: Wed, 03 Dec 2025 14:21:13 GMT Strict-Transport-Security: max-age=10886400; includeSubDomains; preload Referrer-Policy: same-origin X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-DNS-Prefetch-Control: off
Open service 20.4.244.223:80 · header.toolkit.uk
2025-12-23 19:11
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Tue, 23 Dec 2025 19:11:12 GMT Location: https://header.toolkit.uk/
Open service 20.4.244.223:443 · header.toolkit.uk
2025-12-23 19:11
HTTP/1.1 200 OK Content-Length: 1 Connection: close Content-Type: text/html Date: Tue, 23 Dec 2025 19:11:13 GMT Cache-Control: public, must-revalidate, max-age=30 ETag: "46683183" Last-Modified: Wed, 03 Dec 2025 14:21:13 GMT Strict-Transport-Security: max-age=10886400; includeSubDomains; preload Referrer-Policy: same-origin X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-DNS-Prefetch-Control: off
Open service 20.4.244.223:443 · header.toolkit.uk
2025-12-22 10:48
HTTP/1.1 200 OK Content-Length: 1 Connection: close Content-Type: text/html Date: Mon, 22 Dec 2025 10:48:26 GMT Cache-Control: public, must-revalidate, max-age=30 ETag: "46683183" Last-Modified: Wed, 03 Dec 2025 14:21:13 GMT Strict-Transport-Security: max-age=10886400; includeSubDomains; preload Referrer-Policy: same-origin X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-DNS-Prefetch-Control: off
Open service 20.4.244.223:443 · header.toolkit.uk
2025-12-21 05:16
HTTP/1.1 200 OK Content-Length: 1 Connection: close Content-Type: text/html Date: Sun, 21 Dec 2025 05:16:57 GMT Cache-Control: public, must-revalidate, max-age=30 ETag: "46683183" Last-Modified: Wed, 03 Dec 2025 14:21:13 GMT Strict-Transport-Security: max-age=10886400; includeSubDomains; preload Referrer-Policy: same-origin X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-DNS-Prefetch-Control: off