ESF
tcp/443 tcp/80
Microsoft-IIS 10.0
tcp/80
cloudflare
tcp/443 tcp/80 tcp/8443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035497e949ad484818be00fa84a5956373dd1a6b426c0
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/account/get-settingmaster-value/{settingParameter}
GET /api/category
GET /api/category/get-category-by-vendor/{vendorId}
GET /api/customerprofile/get-customerprofile-forpossearch
GET /api/publicrequest/Test
GET /api/sales/get-sales-data/{invoiceNo}
GET /api/terminal
GET /api/terminal/{terminalid}
GET /api/userpaymentoptions/get-userpaymentoptions/{posprofileId}
GET /api/vendor
GET /api/vendor/{vendorid}
POST /api/account/check-account
POST /api/account/check-card-balance
POST /api/account/check-spend-limit
POST /api/account/get-allergens
POST /api/account/get-banneditems
POST /api/account/get-restricted-days
POST /api/changepassword
POST /api/customerprofile/get-profilephoto-photosync
POST /api/logout
POST /api/order/latest-order
POST /api/order/order-detail-by-orderid
POST /api/order/order-report
POST /api/order/update-orderstatus
POST /api/poslayer/get-poslayeritem
POST /api/poslayer/get-poslayermaster
POST /api/product
POST /api/product/get-item-details
POST /api/sales/SalesInsert
POST /api/sales/cancelsale
POST /api/sales/get-running-invoice-number
POST /api/sales/get-sale-details
POST /api/sales/get-sale-summary
POST /api/sales/get-sale-summary-byterminal
POST /api/sales/get-sales-byprofileid
POST /api/sales/issaleslimitexceed
POST /api/terminal/get-terminalprintermapping
POST /api/terminal/update-terminalstatus
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035497e949ad484818be00fa84a5956373dd1a6b426c0
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/account/get-settingmaster-value/{settingParameter}
GET /api/category
GET /api/category/get-category-by-vendor/{vendorId}
GET /api/customerprofile/get-customerprofile-forpossearch
GET /api/publicrequest/Test
GET /api/sales/get-sales-data/{invoiceNo}
GET /api/terminal
GET /api/terminal/{terminalid}
GET /api/userpaymentoptions/get-userpaymentoptions/{posprofileId}
GET /api/vendor
GET /api/vendor/{vendorid}
POST /api/account/check-account
POST /api/account/check-card-balance
POST /api/account/check-spend-limit
POST /api/account/get-allergens
POST /api/account/get-banneditems
POST /api/account/get-restricted-days
POST /api/changepassword
POST /api/customerprofile/get-profilephoto-photosync
POST /api/logout
POST /api/order/latest-order
POST /api/order/order-detail-by-orderid
POST /api/order/order-report
POST /api/order/update-orderstatus
POST /api/poslayer/get-poslayeritem
POST /api/poslayer/get-poslayermaster
POST /api/product
POST /api/product/get-item-details
POST /api/sales/SalesInsert
POST /api/sales/cancelsale
POST /api/sales/get-running-invoice-number
POST /api/sales/get-sale-details
POST /api/sales/get-sale-summary
POST /api/sales/get-sale-summary-byterminal
POST /api/sales/get-sales-byprofileid
POST /api/sales/issaleslimitexceed
POST /api/terminal/get-terminalprintermapping
POST /api/terminal/update-terminalstatus
Open service 2a00:1450:400a:1009::79:443 · cas.isb.ac.th
2026-01-26 12:15
HTTP/1.1 302 Found Content-Type: application/binary X-Frame-Options: DENY Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Mon, 26 Jan 2026 12:15:01 GMT Location: https://accounts.google.com/ServiceLogin?passive=1209600&osid=1&continue=https://sites.google.com/isb.ac.th/hscas&followup=https://sites.google.com/isb.ac.th/hscas Cross-Origin-Opener-Policy: unsafe-none Cross-Origin-Resource-Policy: same-site Content-Security-Policy: base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-HvsLwiBHoOu2B8qYqZsjdg' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Content-Type-Options: nosniff Connection: close
Open service 192.178.170.121:443 · cas.isb.ac.th
2026-01-26 12:15
HTTP/1.1 302 Found Content-Type: application/binary X-Frame-Options: DENY Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Mon, 26 Jan 2026 12:15:02 GMT Location: https://accounts.google.com/ServiceLogin?passive=1209600&osid=1&continue=https://sites.google.com/isb.ac.th/hscas&followup=https://sites.google.com/isb.ac.th/hscas Content-Security-Policy: base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-YUEumNXORswbdPFc33Pq5w' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/ Cross-Origin-Resource-Policy: same-site Cross-Origin-Opener-Policy: unsafe-none Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Content-Type-Options: nosniff Connection: close
Open service 2a00:1450:400a:1009::79:80 · cas.isb.ac.th
2026-01-26 12:15
HTTP/1.1 301 Moved Permanently Content-Type: application/binary Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Mon, 26 Jan 2026 12:15:30 GMT Location: https://cas.isb.ac.th/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Connection: close
Open service 192.178.170.121:80 · cas.isb.ac.th
2026-01-26 12:15
HTTP/1.1 301 Moved Permanently Content-Type: application/binary Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Mon, 26 Jan 2026 12:15:31 GMT Location: https://cas.isb.ac.th/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Connection: close
Open service 34.149.87.45:80 · iasas.isb.ac.th
2026-01-23 07:19
HTTP/1.1 429 Too Many Requests content-type: text/html; charset=UTF-8 Content-Length: 142 via: 1.1 google date: Fri, 23 Jan 2026 07:19:29 GMT glb-x-seen-by: bS8wRlGzu0Hc+WrYuHB8QIg44yfcdCMJRkBoQ1h6Vjc= Connection: close Page title: 429 <!doctype html><meta charset="utf-8"><meta name=viewport content="width=device-width, initial-scale=1"><title>429</title>429 Too Many Requests
Open service 34.149.87.45:80 · www.iasas.isb.ac.th
2026-01-23 07:19
HTTP/1.1 429 Too Many Requests content-type: text/html; charset=UTF-8 Content-Length: 142 via: 1.1 google date: Fri, 23 Jan 2026 07:19:30 GMT glb-x-seen-by: bS8wRlGzu0Hc+WrYuHB8QIg44yfcdCMJRkBoQ1h6Vjc= Connection: close Page title: 429 <!doctype html><meta charset="utf-8"><meta name=viewport content="width=device-width, initial-scale=1"><title>429</title>429 Too Many Requests
Open service 18.141.40.12:80 · api-campuscard.isb.ac.th
2026-01-22 23:21
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Location: https://api-campuscard.isb.ac.th/ Server: Microsoft-IIS/10.0 Date: Thu, 22 Jan 2026 23:22:01 GMT Connection: close
Open service 2a00:1450:400a:1000::79:80 · uni.isb.ac.th
2026-01-22 18:48
HTTP/1.1 301 Moved Permanently Content-Type: application/binary Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 18:49:16 GMT Location: https://uni.isb.ac.th/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Connection: close
Open service 2a00:1450:400a:1000::79:443 · uni.isb.ac.th
2026-01-22 18:48
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 X-Frame-Options: DENY Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 18:48:47 GMT Content-Security-Policy: base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-uhyIH36wOn_afN_Jblq2WA' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/ Cross-Origin-Opener-Policy: unsafe-none Cross-Origin-Resource-Policy: same-site reporting-endpoints: default="/web-reports?jobset=prod&wcrumsspbp=false&bl=editors.sites-viewer-frontend_20260114.02_p1&app=25&clss=1&context=eJwN0GtYkwUAxfHX7X0PhdBkMJkkMN-VDRWblEkCwZpspEWl2Zb2KIkoqIBxV0vhMcrsol28ZCWGmCRiKpaU9lRgJZqJ3YzCS4KTy2AbDBhW0vnw-_L_do5_qariNptQO9omPBFiE56ioK02YQLd2mkT7njPJoiVNiGETEdtgu2KTVhOjU6b8AstGmcXcsgbbhfECLtQeJddKKf0ZLuQT8X0Cs2cfFG4RZhyUYigxGt9CisZSwcUseQqG1AM0ZqVQ4oyaor3KS7QyQSf4hQNZvgUt2j_Zp_iU1pyZlixgnKEEUUR-caPKITwEYW3ZETxL903T6mMo8QypdJKc68rlQuoxDVTLCXFznjRn744GC9-SymxCeIT5JltEofpr3UPi22UC7NYTNtWm8UPKb3ILK4kxWGz6E8Pfm4WTTQ0OVkcodgVyWIS3f18shhNLzmSxdfJPt0iplHTZxaxhd590ypWUTXV040hq-iiypUp4gFqUz8idlOr32yxnYrnVUgbqDuzQuqnP45XSFfpQv8eqYV0j1dKBnquda-URS-69krldCKzSmqkA6uqpKN0pq1K-pm0R_ZJOjqX-rH0GwWW75c0NC6yWppAhmeqJSPN7TogLaBPUmukI_RVdY30HeWlH5LWUlf2IamPVMVdUijtqu2SKun06W6pmeyJTimNFjY4pXT6zd4jXSLV-z1SKCmvB2A0HVYFop4m1gdiKl08dQeuUFGMCuvpsQoV5pNj3xj0Uk1HEOoosysIq8nPqIaKvjykRgONkoNxO9XNCMYJSooNRgrFXArBTCpSa7CeNKkahNPbazXYRTde1sBFGyrH4hW6p3Us7iX_VaFQ082cUPjnhuJVnRZv0fLpWnRmaOGhY7VanCRfkxbCGS1e-GgcXqJfK8ehlYo3h2ED3XSFQeEOw4dDYdhH7VvvhJO2mcZjFy2cPR5pdKUmAqf_jMA5amuNQAcZXBEw0nxPBBbQyYWR-HpZJE5R17FI9NEcPx3mUd0MHbfr0J2lQ2-9DoO0bu8EbKRZrgl4lFbdK6OAHrDKiCNNoYxw-qdchvJlGSc2yWiklXtk5NNX52Q0UMBPMoJoiP4ly3kZc6iaaimoWcZYeuOWjG1UOU2PA_RfvB5Sgh6HE_WoJ2eWHl5yr9FjgBb8qscSmm2biLnUZp-IbjoIA45RX6ABN0kVZEAIyVMMmEQ_VBpwnn53GHCZ6lVR-Ibag6LgpJbgKPxN_4REQamJws9CHM7WxOEXWnokDll09mgcmqkmNR51NCIkwG9UAuJGJ2AOrd6egBJaqH0I6dT69kNoJ_-7E6Gm1ilJaKdvzEloJv2pJEymbLMJhdSy04TtZ0zYTZ3NJniorMuEV-ktixnvkWeVGcPk125GAM1wmpFILuUsjFDgs7Ogocu9s-CgS-uScZ2C0y3Q0vJSC3JJX2XBZNq934KP6cHTFpiop8CKAZIPWjGJ-mqtuEmlV63YRO9MTcH71HglBWfp8uZrcNDijmtYSuon2xFGP9B58h9uh5p2RDvwAeWVOrCWdA0OGOjHxBu4QPacDqRRdlUHCskY0IlY2nK1EztozWAnyuiCswstdLSkG19SxXEn9lNRgxPrKT2yB5m0PaMHu6knvhcDZDjeC_UmF55PcENe5MYkqslzo44ObnTDvtWNHa1u9Fx1w3i_B2FPeRBJacs8yKSOPR6Uf-bBNrr0aB9-XNGH4EN90NL8kH44FvcjdUk_vk7yInuZF4X09Fov__fiyUYvSii524sUimoaQDQNZw-i849B9NKeRUOYvnwI3wf4cGe4D0myD9P_HMZMUgfctuVa01mMqe-of21UmPh0VkaxPCVjaVZBbl7-1Pysgoz86CK2jLzoZXm5OQUZOUsXxxhjHjBOm3b_VGPM4tXT_gfvWduk&build-label=editors.sites-viewer-frontend_20260114.02_p1&imp-sid=CI6Anu3nn5IDFWaILQkdcKE5ZA&is-cached-offline=false" document-policy: include-js-call-stacks-in-crash-reports Referrer-Policy: origin Server: ESF X-XSS-Protection: 0 X-Content-Type-Options: nosniff Accept-Ranges: none Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site,Accept-Encoding Connection: close Transfer-Encoding: chunked
Open service 74.125.29.121:443 · uni.isb.ac.th
2026-01-22 18:48
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 X-Frame-Options: DENY Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 18:48:47 GMT Cross-Origin-Resource-Policy: same-site Cross-Origin-Opener-Policy: unsafe-none Content-Security-Policy: base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-Bq-SR_vV8o0CsYtCJXmdKQ' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/ reporting-endpoints: default="/web-reports?jobset=prod&wcrumsspbp=false&bl=editors.sites-viewer-frontend_20260114.02_p1&app=25&clss=1&context=eJwNz2tYkwUDxvGn7XluCqHFYDJJYD4rGyo2KZMEAppspEWl2ZZ2KYmoiIIBgsr7KlxKmVcHO5iHMg0xCcRULCk7ghVoJnQyah5ewclhsA0HG1jy3h9-X_7f_oFbVftutwp1Y6zCU2FW4RkK2W4VJtCtXVbhzt1WQay0CmFkOm4VrJetwnJqclqFX2nROJuQR95ImyBG2YS199iECspKswmFVEIv08zJF4RbhCkXhChKvjqgsJCxbFART67yQYWP1uf6FOXUkuhXtNGXSX7FaRrK9itu0aFtfsUntOTMsGIl5QmjimLyjx9VCJGjCu-6UcU_9MA8pTKBksuVSgvNvaZULqB1rpliGSl2JYqB9PnhRPE7So9PEp8iz-xUcZj-Ln1U7KB8mMQS2rHGJO6lrGKTmEuKoyYxkB7-zCSmkm9ymjhK8SvTxBS698U0MZa2ONLEV8k23SxmUsunZrGd3nndIlZRNTXQdZ9FdFFlbrpYQx3qx8ResgfMFjupZN4-aRP9eXKfdIXabuyX2kn3ZKVkoBfsB6Qc-q_rgFRBp1ZUSU1Us6pKOk5nOqqkX0h77KCko3MZH0m_U3DFIUlD46KrpQlkeK5aMtLcnhppAZXSZvo4o1Y6Rl9V10rfU0HWEWkD9aw-Ig2QqqRHCqc9dT1SJTU390qtZEt2Spm0sNEpZdHvtj7pIqne65PCSXktCGPoqCoYDTSxIRhT6cLpO3GZiuNU2EhP7FNhPjkO3oV-qu0KQT2t6AnBGgowqqGiL46o0Ui3yaG4g-pnhOIUpcSHIp3iLoZhJhWrNdhImgwNIumtDRrsoesvaeCiTZVj8TLdZx-L-ylwVTjUNJIXjsD8cLyi0-JNWj5di-5sLTx0ok6LL8nfooVwRov_fDgOW-i3ynGwU8m2CGyiEVcEFO4I7PVF4CB1br8bTtqROh57aOHs8ciky7VRaP4rCueowx6FLjK4omCk-Z4oLKDPFkbj82XR-Jp6TkRjgOYE6DCP6mfo-K5Db44O_Q06DFHpgQnYTLNcE_A4rbpfRhE9ZJGRQJq1MiLpZoUM5UsyTm2V0US5-2UU0lfnZDRS0M8yQshH_5D5vIw5VE11FNIqYyy9dkvGDqqcpkcN_Zuoh5Skx9FkPRrImaOHl9zr9RikBb_psYRmWydiLnXYJqKXDsOAEzQQbMAIqUIMCCN5igGT6MdKA87THw4DLlGDKgbfUmdIDJzUHhqD_9HNsBgoNTFoExJwtjYBv9LSYwnIobPHE9BKtRmJqKdRIQkBtyUhYUwS5tCad5OwjhZqH0EW2d96BJ0UeG8y1GSfkoJO-taUglbSn07BZFptSsVaat-Viu7WVHiovCcVr9CbZhN2k2eVCcMU0GlCEM1wmpBMLuUsjFLw87OgoUv9s-Cgi6VpuEahWWZoaXmZGfmkrzJjMn1wyIyP6OFmM1Kpr8iCQZIPWzCJBuosGKGyKxZspbenpuM9arqcjrN0adtVOGhx11UsJfXTnYigH-k8BQ53Qk07Yx14nwrKHNhAukYHDPRT8nW0kS2vC5m0uqoLa8kY1I14euNKN3bS-qFulFObswftdHxdL76gj086cYyKG53YSFnRfVhB72b34QPqS-zHIE082Q9sdeHFJDfkRW5MotoCN-qpZrMbc7e7sdPuhvOKG8YHPYh4xoNoylzmwQrq2u9Bxace7KC_Hx_ATysHEHpkAFqaH3YDjsU3kLHkBr5J8SJrmRe59OwGL-ylXjzd5EUJpfV6kU4xLYOIpeHVQ-j-cwj99OEiH6Yv9-GHID_ujvQjRfbj3xE_pJt-XN89DB9N_2sYM0k95vY3rracxV3uvc3PRYjP5mSXyFOyl-YU5RcUTi3MKcoujC1myy6IXVaQn1eUnbd0cZwx7iHjtGkPTjXGLV4z7f-1BuIv&build-label=editors.sites-viewer-frontend_20260114.02_p1&imp-sid=CILHl-3nn5IDFfFJqwId31YMNg&is-cached-offline=false" document-policy: include-js-call-stacks-in-crash-reports Referrer-Policy: origin Server: ESF X-XSS-Protection: 0 X-Content-Type-Options: nosniff Accept-Ranges: none Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site,Accept-Encoding Connection: close Transfer-Encoding: chunked
Open service 74.125.29.121:80 · uni.isb.ac.th
2026-01-22 18:48
HTTP/1.1 301 Moved Permanently Content-Type: application/binary Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 18:49:17 GMT Location: https://uni.isb.ac.th/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Connection: close
Open service 142.250.185.147:443 · isbcentral.isb.ac.th
2026-01-22 12:16
HTTP/1.1 302 Found Content-Type: application/binary X-Frame-Options: DENY Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 12:16:38 GMT Location: https://accounts.google.com/ServiceLogin?passive=1209600&osid=1&continue=https://sites.google.com/isb.ac.th/isb-central&followup=https://sites.google.com/isb.ac.th/isb-central Content-Security-Policy: base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-zbrNp8ZQrW8l8n_vM7ESsw' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/ Cross-Origin-Resource-Policy: same-site Cross-Origin-Opener-Policy: unsafe-none Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Content-Type-Options: nosniff Connection: close
Open service 2a00:1450:4001:810::2013:443 · isbcentral.isb.ac.th
2026-01-22 12:16
HTTP/1.1 302 Found Content-Type: application/binary X-Frame-Options: DENY Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 12:16:38 GMT Location: https://accounts.google.com/ServiceLogin?passive=1209600&osid=1&continue=https://sites.google.com/isb.ac.th/isb-central&followup=https://sites.google.com/isb.ac.th/isb-central Cross-Origin-Resource-Policy: same-site Content-Security-Policy: base-uri 'self';object-src 'none';report-uri /_/view/cspreport;script-src 'report-sample' 'nonce-VwqnCI_t3MwvtVdsxtZl1A' 'unsafe-inline' 'unsafe-eval';worker-src 'self';frame-ancestors https://google-admin.corp.google.com/ Cross-Origin-Opener-Policy: unsafe-none Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Content-Type-Options: nosniff Connection: close
Open service 142.250.185.147:80 · isbcentral.isb.ac.th
2026-01-22 12:16
HTTP/1.1 301 Moved Permanently Content-Type: application/binary Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 12:17:07 GMT Location: https://isbcentral.isb.ac.th/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Connection: close
Open service 2a00:1450:4001:810::2013:80 · isbcentral.isb.ac.th
2026-01-22 12:16
HTTP/1.1 301 Moved Permanently Content-Type: application/binary Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Mon, 01 Jan 1990 00:00:00 GMT Date: Thu, 22 Jan 2026 12:17:08 GMT Location: https://isbcentral.isb.ac.th/ Server: ESF Content-Length: 0 X-XSS-Protection: 0 X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Connection: close
Open service 104.17.69.73:8443 · isb.ac.th
2026-01-21 17:27
HTTP/1.1 403 Forbidden
Date: Wed, 21 Jan 2026 17:27:18 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
CF-RAY: 9c188581f97ef838-SIN
X-Frame-Options: SAMEORIGIN
Referrer-Policy: same-origin
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Strict-Transport-Security: max-age=31536000
Set-Cookie: __cfruid=33f8443e6ee258f06d5e2a5a2e80281f939267c0-1769016438; path=/; domain=.isb.ac.th; HttpOnly; Secure; SameSite=None
Server: cloudflare
alt-svc: h3=":8443"; ma=86400
Page title: Attention Required! | Cloudflare
<!DOCTYPE html>
<!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->
<!--[if IE 7]> <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->
<!--[if IE 8]> <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->
<!--[if gt IE 8]><!--> <html class="no-js" lang="en-US"> <!--<![endif]-->
<head>
<title>Attention Required! | Cloudflare</title>
<meta charset="UTF-8" />
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=Edge" />
<meta name="robots" content="noindex, nofollow" />
<meta name="viewport" content="width=device-width,initial-scale=1" />
<link rel="stylesheet" id="cf_styles-css" href="/cdn-cgi/styles/cf.errors.css" />
<!--[if lt IE 9]><link rel="stylesheet" id='cf_styles-ie-css' href="/cdn-cgi/styles/cf.errors.ie.css" /><![endif]-->
<style>body{margin:0;padding:0}</style>
<!--[if gte IE 10]><!-->
<script>
if (!navigator.cookieEnabled) {
window.addEventListener('DOMContentLoaded', function () {
var cookieEl = document.getElementById('cookie-alert');
cookieEl.style.display = 'block';
})
}
</script>
<!--<![endif]-->
</head>
<body>
<div id="cf-wrapper">
<div class="cf-alert cf-alert-error cf-cookie-error" id="cookie-alert" data-translate="enable_cookies">Please enable cookies.</div>
<div id="cf-error-details" class="cf-error-details-wrapper">
<div class="cf-wrapper cf-header cf-error-overview">
<h1 data-translate="block_headline">Sorry, you have been blocked</h1>
<h2 class="cf-subheadline"><span data-translate="unable_to_access">You are unable to access</span> finalsitecdn.com</h2>
</div><!-- /.header -->
<div class="cf-section cf-highlight">
<div class="cf-wrapper">
<div class="cf-screenshot-container cf-screenshot-full">
<span class="cf-no-screenshot error"></span>
</div>
</div>
</div><!-- /.captcha-container -->
<div class="cf-section cf-wrapper">
<div class="cf-columns two">
<div class="cf-column">
<h2 data-translate="blocked_why_headline">Why have I been blocked?</h2>
<p data-translate="blocked_why_detail">This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.</p>
</div>
<div class="cf-column">
<h2 data-translate="blocked_resolve_headline">What can I do to resolve this?</h2>
<p data-translate="blocked_resolve_detail">You can email the site owner to let them know you were blocked. Please include what you were doing when this page came up and the Cloudflare Ray ID found at the bottom of this page.</p>
</div>
</div>
</div><!-- /.section -->
<div class="cf-error-footer cf-wrapper w-240 lg:w-full py-10 sm:py-4 sm:px-8 mx-auto text-center sm:text-left border-solid border-0 border-t border-gray-300">
<p class="text-13">
<span class="cf-footer-item sm:block sm:mb-1">Cloudflare Ray ID: <strong class="font-semibold">9c188581f97ef838</strong></span>
<span class="cf-footer-separator sm:hidden">•</span>
<span id="cf-footer-item-ip" class="cf-footer-item hidden sm:block sm:mb-1">
Your IP:
<button type="button" id="cf-footer-ip-reveal" class="cf-footer-ip-reveal-btn">Click to reveal</button>
<span class="hidden" id="cf-footer-ip">206.189.95.232</span>
<span class="cf-footer-separator sm:hidden">•</span>
</span>
<span class="cf-footer-item sm:block sm:mb-1"><span>Performance & security by</span> <a rel="noopener noreferrer" href="https://www.cloudflare.com/5xx-error-landing" id="brand_link" target="_blank">Cloudflare</a></span>
</p>
<script>(function(){function d(){var b=a.getElementById("cf-footer-item-ip"),c=a.getElementById("cf-footer-ip-reveal");b&&"classList"in b&&(b.cla
Open service 104.17.69.73:80 · isb.ac.th
2026-01-21 17:27
HTTP/1.1 301 Moved Permanently Date: Wed, 21 Jan 2026 17:27:18 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Wed, 21 Jan 2026 18:27:18 GMT Location: https://isb.ac.th/ Set-Cookie: __cfruid=33f8443e6ee258f06d5e2a5a2e80281f939267c0-1769016438; path=/; domain=.isb.ac.th; HttpOnly Server: cloudflare CF-RAY: 9c188581ff7b3231-SIN alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 104.17.69.73:443 · isb.ac.th
2026-01-21 17:27
HTTP/1.1 301 Moved Permanently Date: Wed, 21 Jan 2026 17:27:18 GMT Content-Length: 0 Connection: close CF-RAY: 9c1885820dd2afe4-SIN Location: https://www.isb.ac.th/ Strict-Transport-Security: max-age=31536000 Set-Cookie: __cfruid=33f8443e6ee258f06d5e2a5a2e80281f939267c0-1769016438; path=/; domain=.isb.ac.th; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400