nginx 1.18.0
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 47.100.111.43:443 · interface.zhiji.info
2024-12-22 04:52
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Sun, 22 Dec 2024 04:52:42 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.071638 X-Gitlab-Meta: {"correlation_id":"0dcb85ca-0e38-4eef-8c9c-f8c20454fa1b","version":"1"} X-Request-Id: 0dcb85ca-0e38-4eef-8c9c-f8c20454fa1b <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-12-20 06:48
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Fri, 20 Dec 2024 06:48:36 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.030647 X-Gitlab-Meta: {"correlation_id":"bdd688c1-f6f6-43bb-8f54-32d6b7491cb3","version":"1"} X-Request-Id: bdd688c1-f6f6-43bb-8f54-32d6b7491cb3 <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-12-18 23:23
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Wed, 18 Dec 2024 23:23:49 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.066013 X-Gitlab-Meta: {"correlation_id":"09676292-736c-431b-b943-0f4589da547a","version":"1"} X-Request-Id: 09676292-736c-431b-b943-0f4589da547a <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-12-14 04:57
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Sat, 14 Dec 2024 04:57:32 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.028474 X-Gitlab-Meta: {"correlation_id":"35011bdf-a62a-4362-b449-4f3b0f14ae1f","version":"1"} X-Request-Id: 35011bdf-a62a-4362-b449-4f3b0f14ae1f <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-12-12 11:25
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Thu, 12 Dec 2024 11:25:43 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.072484 X-Gitlab-Meta: {"correlation_id":"7f56c267-93ad-45a9-aad6-7f13728b6b5f","version":"1"} X-Request-Id: 7f56c267-93ad-45a9-aad6-7f13728b6b5f <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-12-02 12:23
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Mon, 02 Dec 2024 12:23:52 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.039375 X-Gitlab-Meta: {"correlation_id":"ccdbd0d8-7408-46e9-b312-c53f45535dbd","version":"1"} X-Request-Id: ccdbd0d8-7408-46e9-b312-c53f45535dbd <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-11-30 12:17
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Sat, 30 Nov 2024 12:17:33 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.057823 X-Gitlab-Meta: {"correlation_id":"8129d0fb-4ca2-4524-8767-9d3785d81967","version":"1"} X-Request-Id: 8129d0fb-4ca2-4524-8767-9d3785d81967 <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>
Open service 47.100.111.43:443 · interface.zhiji.info
2024-11-28 12:09
HTTP/1.1 302 Found Server: nginx/1.18.0 Date: Thu, 28 Nov 2024 12:09:24 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Download-Options: noopen X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin-when-cross-origin Permissions-Policy: interest-cohort=() X-UA-Compatible: IE=edge Location: http://interface.zhiji.info/users/sign_in Cache-Control: no-cache Content-Security-Policy: X-Runtime: 0.074756 X-Gitlab-Meta: {"correlation_id":"1149e6ee-e433-4c89-b646-edfad21cc0e4","version":"1"} X-Request-Id: 1149e6ee-e433-4c89-b646-edfad21cc0e4 <html><body>You are being <a href="http://interface.zhiji.info/users/sign_in">redirected</a>.</body></html>