cloudflare
tcp/443 tcp/80
nginx
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa32da5e0c7607b4cf57260deff56289e19a2882385
GraphQL introspection enabled at /graphql Types: 78 (by kind: ENUM: 2, INPUT_OBJECT: 13, OBJECT: 56, SCALAR: 7) Operations: - Query: Query | fields: activity, course, courseContent, enrollment, media - Mutation: Mutation | fields: examAnswersCommit, lessonProgressUpdate, paymentRefund, userSignIn, userSignOut Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 172.64.153.235:8443 · newsletter.innovc.com.br
2026-01-23 22:51
Open service 172.64.153.235:443 · newsletter.innovc.com.br
2026-01-23 22:51
HTTP/1.1 404 Not Found Date: Fri, 23 Jan 2026 22:51:07 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 47 Connection: close CF-RAY: 9c2ada999df12f06-EWR cf-cache-status: DYNAMIC Set-Cookie: __cf_bm=8DYpALyKUr.kgKr3dYD7esOa4BDEM3Y1SIoVh6zjJmk-1769208667-1.0.1.1-kTOBJhkeBhkSYO0EK0HKeY_OqIt81qn6FP52fX9adYeDt_NGZGMYaT3iR.dAnuT.XtiphvLRmA6919doyIE0eM6AVzFGKZfHYvXn5hLVUwU; path=/; expires=Fri, 23-Jan-26 23:21:07 GMT; domain=.newsletter.innovc.com.br; HttpOnly; Secure; SameSite=None speculation-rules: "/cdn-cgi/speculation" Referrer-Policy: no-referrer Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline' Server: cloudflare alt-svc: h3=":443"; ma=86400 The requested URL was not found on this server.
Open service 104.18.34.21:8443 · newsletter.innovc.com.br
2026-01-23 22:51
Open service 104.18.34.21:443 · newsletter.innovc.com.br
2026-01-23 22:51
HTTP/1.1 404 Not Found Date: Fri, 23 Jan 2026 22:51:07 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 47 Connection: close CF-RAY: 9c2ada999e0b0b6a-AMS cf-cache-status: DYNAMIC Set-Cookie: __cf_bm=YFpKwpKIM1b.sTtCigkD9z3ylJ4tPdg0TwswqfWrFy0-1769208667-1.0.1.1-03GoHvJ6wyn5BQ5VQgtjgT7jqyA91i4qLLixYbluMzBHkhV8KJVLNh29Hvu7dqtXR6BfcnVtOwXsrBYXmVzA.CMdjqDnjDcBGg3cz9cCyOg; path=/; expires=Fri, 23-Jan-26 23:21:07 GMT; domain=.newsletter.innovc.com.br; HttpOnly; Secure; SameSite=None speculation-rules: "/cdn-cgi/speculation" Referrer-Policy: no-referrer Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline' Server: cloudflare alt-svc: h3=":443"; ma=86400 The requested URL was not found on this server.
Open service 104.18.34.21:80 · newsletter.innovc.com.br
2026-01-23 22:51
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 22:51:07 GMT Content-Length: 0 Connection: close CF-RAY: 9c2ada994d9da1b2-SIN location: https://newsletter.innovc.com.br/ cf-cache-status: DYNAMIC Set-Cookie: __cf_bm=6M3DAbS64VbJOOIDDsaUeE_QKfEPdTL5ZzHAuhJ6XoE-1769208667-1.0.1.1-frUCNGd2V28PzE6ILuIYxaeWGU0bpHRYgNQEyFsqT4pD2cyb8sxQXHBNjejnLuSyE5Nl0Vnw3RdNPsn3WsjJK2o7TnCX3RPP76fBh_44CKg; path=/; expires=Fri, 23-Jan-26 23:21:07 GMT; domain=.newsletter.innovc.com.br; HttpOnly speculation-rules: "/cdn-cgi/speculation" Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 172.64.153.235:80 · newsletter.innovc.com.br
2026-01-23 22:51
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 22:51:07 GMT Content-Length: 0 Connection: close CF-RAY: 9c2ada98ad4bc45b-YYZ location: https://newsletter.innovc.com.br/ cf-cache-status: DYNAMIC Set-Cookie: __cf_bm=Hw_aArAlGsHIpG7nMh2OmZcKFWbnkBrVwuyYwEKk4y4-1769208667-1.0.1.1-21y6ochpVlYevJoxt0tzVlSc1fSVQsNCZO3IAwRbeiL03hAtfb8_fLAOCd7jpWDfer4dKqQM6RGAX8vPuVdazjyOsfARDyj7H17UYcTq9NE; path=/; expires=Fri, 23-Jan-26 23:21:07 GMT; domain=.newsletter.innovc.com.br; HttpOnly speculation-rules: "/cdn-cgi/speculation" Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 177.55.111.8:443 · innovc.com.br
2026-01-23 15:57
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 15:57:08 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: X-Proxy-Provider Link: <https://innovc.com.br/wp-json/>; rel="https://api.w.org/" Link: <https://innovc.com.br/wp-json/wp/v2/pages/84>; rel="alternate"; title="JSON"; type="application/json" Link: <https://innovc.com.br/>; rel=shortlink Cache-Control: max-age=0, no-cache, no-store, must-revalidate Expires: Wed, 11 Jan 1984 05:00:00 GMT
Open service 177.55.111.8:443 · www.innovc.com.br
2026-01-23 15:57
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 15:57:08 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close Vary: X-Proxy-Provider X-Redirect-By: WordPress Location: https://innovc.com.br/ Cache-Control: max-age=0, no-cache, no-store, must-revalidate Expires: Wed, 11 Jan 1984 05:00:00 GMT
Open service 104.26.7.134:443 · membros.innovc.com.br
2026-01-23 05:02
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 05:02:47 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
vary: Accept-Encoding
last-modified: Mon, 12 Jan 2026 13:19:27 GMT
x-amz-server-side-encryption: AES256
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
x-cache: Hit from cloudfront
via: 1.1 5df90d8b07f873c947e7e3d9ff174026.cloudfront.net (CloudFront)
x-amz-cf-pop: GRU3-P1
x-amz-cf-id: pU1lIzhcE5_uUQ5qIEtcpwsNgD51mk16JjFBrfyu5tpXiEBYYALJig==
Age: 2491
application-env: production
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=3pGAol4K5oAQtu8wTa9HEgDhQI%2F6IjIYcwNgfNc2oAKVY493E2X4NPtpSYu8Ee%2BR%2FaC4NFmRjKRe0DJjGGEIuIJl440QLVg9d5Z5avFJoQ4RcYmb"}]}
strict-transport-security: max-age=2592000; includeSubDomains
cf-cache-status: DYNAMIC
Server: cloudflare
CF-RAY: 9c24bdab1aa3ab57-YYZ
Page title: HeroSpark
<!DOCTYPE html>
<html lang="pt-BR">
<head>
<meta charset="utf-8" />
<meta httpEquiv="X-UA-Compatible" content="IE=edge" />
<!--
This viewport works for phones with notches.
It's optimized for gestures by disabling global zoom.
-->
<meta name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1.00001, viewport-fit=cover" />
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Mulish:wght@400;600;700&display=swap" rel="stylesheet">
<title>HeroSpark</title>
<style>
/**
* Extend the react-native-web reset:
* https://github.com/necolas/react-native-web/blob/master/packages/react-native-web/src/exports/StyleSheet/initialRules.js
*/
html,
body,
#root {
width: 100%;
/* To smooth any scrolling behavior */
-webkit-overflow-scrolling: touch;
margin: 0px;
padding: 0px;
/* Allows content to fill the viewport and go beyond the bottom */
min-height: 100%;
}
#root {
flex-shrink: 0;
flex-basis: auto;
flex-grow: 1;
display: flex;
flex: 1;
}
html {
scroll-behavior: smooth;
/* Prevent text size change on orientation change https://gist.github.com/tfausak/2222823#file-ios-8-web-app-html-L138 */
-webkit-text-size-adjust: 100%;
height: calc(100% + env(safe-area-inset-top));
}
body {
display: flex;
/* Allows you to scroll below the viewport; default value is visible */
overflow-y: auto;
overscroll-behavior-y: none;
text-rendering: optimizeLegibility;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
-ms-overflow-style: scrollbar;
}
/* Enable for apps that support dark-theme */
/*@media (prefers-color-scheme: dark) {
body {
background-color: black;
}
}*/
</style>
<link rel="preload" href="/_expo/static/css/keen-slider.min-56a5879271df2060873cdcc47226f57c.css" as="style"><link rel="stylesheet" href="/_expo/static/css/keen-slider.min-56a5879271df2060873cdcc47226f57c.css"><link rel="preload" href="/_expo/static/css/adyen-26204cf88e8830c2d4d1de3c0c047b78.css" as="style"><link rel="stylesheet" href="/_expo/static/css/adyen-26204cf88e8830c2d4d1de3c0c047b78.css"><link rel="icon" href="/favicon.ico" /></head>
<body>
<!--
A generic no script element with a reload button and a message.
Feel free to customize this however you'd like.
-->
<noscript>
<form action="" style="
background-color: #fff;
position: fixed;
top: 0;
left: 0;
right: 0;
bottom: 0;
z-index: 9999;
">
<div style="
font-size: 18px;
font-family: Helvetica, sans-serif;
line-height: 24px;
margin: 10%;
width: 80%;
">
<p>Oh no! It looks like JavaScript is not enabled in your browser.</p>
<p style="margin: 20px 0;">
<button type="submit" style="
background-color: #4630eb;
border-radius: 100px;
border: none;
box-shadow: none;
color: #fff;
cursor: pointer;
font-weight: bold;
line-height: 20px;
padding: 6px 16px;
">
Reload
</button>
</p>
</div>
</form>
</noscript>
<!-- The root element for your Expo app. -->
<div id="root"></div>
<script src="/_expo/static/js/web/entry-c99b0f4ceff6f2ab6e8224f7cef7d31d.js" defer></script>
</body>
</html>
Open service 138.197.114.43:443 · hubcpin.innovc.com.br
2026-01-12 03:44
HTTP/1.1 302 Found
Server: nginx
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache, private
Date: Mon, 12 Jan 2026 03:44:04 GMT
Location: https://hubcpin.innovc.com.br/login
Set-Cookie: laravel_session=eyJpdiI6IktWMFpRZk5uZ0pwTzJoSU1Nb2JPdlE9PSIsInZhbHVlIjoiK3IxSE1vOEN5QmxJRjBobWZSMHpYQ0ZGaHBNcWo3cGRQazJXeVRTcDI5dE9tNDB3VmFhR1NvWmpLYmlFYnpHbWFFSUlxWWZzcVh2UDRwNW9DU2lxVi9kN2kvdG9LVGUwMjlQV0N4UitaWC9VQ1IzSnkvRkM4eGdGakJUOWdRR3oiLCJtYWMiOiJjMTNhNTViMmIyYWRkZjY1MzJhZjQyNDMwNDUyYTA0MTdmNjlkY2QyNDE2ZDFiMWFmZWNlNjEwNTg0ZTFmNjk1IiwidGFnIjoiIn0%3D; expires=Mon, 12 Jan 2026 05:44:04 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Page title: Redirecting to https://hubcpin.innovc.com.br/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://hubcpin.innovc.com.br/login'" />
<title>Redirecting to https://hubcpin.innovc.com.br/login</title>
</head>
<body>
Redirecting to <a href="https://hubcpin.innovc.com.br/login">https://hubcpin.innovc.com.br/login</a>.
</body>
</html>
Open service 138.197.114.43:80 · hubcpin.innovc.com.br
2026-01-12 03:44
HTTP/1.1 301 Moved Permanently Server: nginx Date: Mon, 12 Jan 2026 03:44:02 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://hubcpin.innovc.com.br/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>