.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c47dfe71947dfe719511acc516ca19a49c4e4557e255081b9
Found 16 files trough .DS_Store spidering: /404.html /422.html /500.html /apple-touch-icon-precomposed.png /apple-touch-icon.png /assets /chat-widget /chat-widget/1.0.0 /chat-widget/1.0.1 /chat-widget/DEV /export /favicon.ico /javascripts /ma /mc /robots.txt
Open service 54.69.95.100:80 · help.doe.org
2026-01-11 18:05
HTTP/1.1 404 Not Found Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Sun, 11 Jan 2026 18:06:15 GMT Content-Length: 19 Connection: close 404 page not found
Open service 54.69.95.100:443 · help.doe.org
2026-01-11 18:05
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Length: 11843
Content-Security-Policy: default-src 'self'; base-uri 'self'; object-src 'none'; img-src * data: blob:; media-src * data: blob:; font-src *; connect-src *; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://www.google-analytics.com https://cdn.ckeditor.com; style-src 'self' 'unsafe-inline'; frame-ancestors *; frame-src 'self' https://*.mojohelpdesk.com https://app.bamzooka.com https://*.youtube.com https://*.youtube-nocookie.com https://fast.wistia.net https://*.wistia.com
Content-Type: text/html; charset=utf-8
Date: Sun, 11 Jan 2026 18:06:15 GMT
Etag: W/"cf0b7eea5105bb6b09dda73fb45d8ce6"
Link: </assets/application-f5125179dad257f1def2a39f3bfc0b2cf8e14f3ad478051261ae5627993c6a02.css>; rel=preload; as=style; nopush,</assets/application-31e596ff1d720a45ee47c7464e2ca5b1a73c501d4cb6599c39354d71ee13cb32.js>; rel=preload; as=script; nopush,</assets/custom-29ffdb46c7eba2cbf17558e631b2a16e3b698ce09aa79c6e1e13a6064cdf9c38.css>; rel=preload; as=style; nopush,</assets/mojo-cooked-content-0158ceae484649b4a6aa0c8d2ab6f78d3f7d72d3198b0e0470299f83ebcbf347.css>; rel=preload; as=style; nopush,</assets/google-roboto-font-family-e9a2961f2e0e8e9525cc1a32ec66282668222752b3fe15ed59bca7e90be44046.css>; rel=preload; as=style; nopush,</assets/1-c0d45f470a22138d64d361c5a10cf40af74a21b00d04d3d24f03979f76b8244d.js>; rel=preload; as=script; nopush
Referrer-Policy: strict-origin-when-cross-origin
Set-Cookie: XSRF-TOKEN=_Yfnm6B-iw3-Zsx3pEGZw5-lJ16FBXZJfdRHWr_dR9UvqYuBVD61cWK7pSo0dpkJ2ya9Dfh6PfF2sw7YI1JLrA; path=/; SameSite=Lax
Set-Cookie: _user_session=4qrhzeGT9lJGmO%2B2QahKPgNAW4UYnlVOZUZbmh%2BS%2BS5xepYjql2TDUYtq4uJGnfYBwI%2BkCFu3O58Bg18shv0IlpU6K4QcGyhFVY%2ByY8bjG4pUrOz0RSd4rSKvQgQWn%2BnR7H7Clx8ngdwyk754Gw7At%2FhAfiC3OFglyGzOeL5hm%2B7QVAt5xqX8Zk3iC34LatESuiBoHdr5gRdsSQ%2BI%2FXTYzmSC%2BhOvPtf8JzM53tTUR90%2BV1Q7uQ2mxnBhSmqMDbeF8LlLfg9IGKymtB0AviuvQQ8sWCLZMmy3xlBhnR97Jppr%2BertYmSV5gQfg%3D%3D--DU1d5wlxkynu%2Fd40--4QKIYJxwZXkBc0tEuBgaBQ%3D%3D; path=/; expires=Mon, 15 Feb 2027 18:06:15 GMT; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: bb8612a3-83d4-44ec-afc3-5675de67557c
X-Runtime: 0.012187
X-Ua-Compatible: IE=edge,chrome=1
Connection: close
Page title: The Doe Fund | Mojo Helpdesk
<!DOCTYPE html>
<html>
<head>
<title>The Doe Fund | Mojo Helpdesk</title>
<meta property="og:title" content="The Doe Fund | Mojo Helpdesk">
<meta property="og:description" content="The Doe Fund Help Desk generated by Mojo Helpdesk.">
<meta name="csrf-param" content="authenticity_token" />
<meta name="csrf-token" content="jmjz8-hGkY39laxIkQ6FgXAkEVA5lS5oqdZaTrLEcUxcRp_pHAav8WFIxRUBOYVLNKeLA0TqZdCisRPMLkt9NQ" />
<meta name="csp-nonce" />
<link rel="stylesheet" href="/assets/application-f5125179dad257f1def2a39f3bfc0b2cf8e14f3ad478051261ae5627993c6a02.css" data-turbo-track="reload" />
<script src="/assets/application-31e596ff1d720a45ee47c7464e2ca5b1a73c501d4cb6599c39354d71ee13cb32.js" data-turbo-track="reload"></script>
<!--responsive viewport meta tag-->
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<link rel="stylesheet" href="/assets/custom-29ffdb46c7eba2cbf17558e631b2a16e3b698ce09aa79c6e1e13a6064cdf9c38.css" data-turbo-track="reload" />
<link rel="stylesheet" href="/assets/mojo-cooked-content-0158ceae484649b4a6aa0c8d2ab6f78d3f7d72d3198b0e0470299f83ebcbf347.css" data-turbo-track="reload" />
<link rel="stylesheet" href="/assets/google-roboto-font-family-e9a2961f2e0e8e9525cc1a32ec66282668222752b3fe15ed59bca7e90be44046.css" data-turbo-track="reload" />
<script src="/assets/1-c0d45f470a22138d64d361c5a10cf40af74a21b00d04d3d24f03979f76b8244d.js" data-turbolinks-track="reload"></script>
<!-- Notifications -->
<!-- Enhanced Flash Messages for Admin Interface -->
<style>
.flash-messages-container {
position: fixed;
top: 20px;
right: 20px;
z-index: 1050;
max-width: 400px;
width: 100%;
}
.flash-message {
border-radius: 0.5rem;
border: none;
box-shadow: 0 0.5rem 1rem rgba(0, 0, 0, 0.15);
margin-bottom: 1rem;
animation: slideInRight 0.3s ease-out;
}
.flash-message.alert-success {
background-color: #d4edda;
color: #155724;
border-left: 4px solid #28a745;
}
.flash-message.alert-danger {
background-color: #f8d7da;
color: #721c24;
border-left: 4px solid #dc3545;
}
.flash-message.alert-warning {
background-color: #fff3cd;
color: #856404;
border-left: 4px solid #ffc107;
}
.flash-message.alert-info {
background-color: #d1ecf1;
color: #0c5460;
border-left: 4px solid #17a2b8;
}
.flash-message .alert-heading {
font-weight: 600;
margin-bottom: 0.5rem;
}
.flash-message ul {
margin-bottom: 0;
padding-left: 1.2rem;
}
.flash-message .btn-close {
opacity: 0.7;
transition: opacity 0.2s;
}
.flash-message .btn-close:hover {
opacity: 1;
}
@keyframes slideInRight {
from {
transform: translateX(100%);
opacity: 0;
}
to {
transform: translateX(0);
opacity: 1;
}
}
/* Auto-hide flash messages after 5 seconds */
.flash-message {
animation: slideInRight 0.3s ease-out, fadeOut 0.3s ease-in 4.7s forwards;
}
@keyframes fadeOut {
to {
opacity: 0;
transform: translateX(100%);
}
}
/* Responsive adjustments */
@media (max-width: 768px) {
.flash-messages-container {
top: 10px;
right: 10px;
left: 10px;
max-width: none;
}
}
</style>
<script>
document.addEventListener('DOMContentLoaded', function() {
// Auto-hide flash messages after 5 seconds
const flashMessages = document.querySelectorAll('.flash-message');
flashMessages.forEach(function(message) {
setTimeout(function() {
message.style.animation = 'fadeOut 0.3s ease-in forwards';
setTimeout(function() {
message.remove();
}, 300);
}, 5000);
});
// Manual close functionality
const closeButtons = document.querySelectorAll('.flash-message .btn-close');
closeButtons.forEach(function(button) {
button.addEventListener('click', function() {
const message = this.closest('.flash-message');
message.style.animation = 'fadeOut 0.3s ease-in forwards';
setTimeout(function() {
message.remove();
}, 300);
});
});
});
</script>
<!-- Favicon -->
<link rel="icon" type="image/x-icon" href="/assets/mojofavicon-