Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d325beceb325beceb325beceb325beceb
Found 1 files trough .DS_Store spidering: /assets
Open service 75.101.184.39:443 · ja.whatsthatcharge.com
2026-01-09 02:05
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"c021f68bf7dcfb4f6f0d296acdb2792f"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=l36ypU%2Bz5J8XbRFlAzp3jZvtDDX%2FKSP6bAT%2FVIg%2FydQ%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767924326"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=l36ypU%2Bz5J8XbRFlAzp3jZvtDDX%2FKSP6bAT%2FVIg%2FydQ%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767924326"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=WUFjTnVzRU9XN25ONUdoOFZEbHRvS29FOENCQ0RzM0w1SDJaR3o2Nm4xUElYTmh1ZTh2cTFaQUJFajZCRnNrTElmZGVTQnhsZDZlM01lOXBmWHpDTWpBcXhqRTZtREVnMmYzbkFBY3pWYVh1ZU5OY0txUFdGSlFWazVwZitOb1dPc1VicmFhUnJSWFlaS2NsaDdOMnNWdFlMM20xZjUxMVVvV3lWQXFOaWk2ZEJqR0VYWlV4WThZVFdzMDB1dUdSLS0zZ05vb1FFNDRCbHA4SDRaSjhsT2ZRPT0%3D--493f3071e4281ef5276db1b3a560c3b68cad5faa; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 636bc6ee-e261-312e-6112-c7cdeb82135b
X-Runtime: 0.014757
X-Xss-Protection: 1; mode=block
Date: Fri, 09 Jan 2026 02:05:26 GMT
Connection: close
Transfer-Encoding: chunked
Open service 75.101.184.39:443 · ja.whatsthatcharge.com
2025-12-30 09:08
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"4b1ced3bdcfcc2069257f7a3b99a2a86"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=QphCwStMW0AozPcz1U8urDAHujQqpUb2OlPZs8snizo%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767085693"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=QphCwStMW0AozPcz1U8urDAHujQqpUb2OlPZs8snizo%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767085693"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=OUlRblRicE9wL1p4Y0R0SUY5eVQ3WS82enpqMEJwNVg5Q09yNUFkc0dMalpNZFpZNHhlRjBJaWxnbGM3a1Q2SkRnQTQ5UUhwNUdaZVc4RGdwYkpSOCtaMzFpZU12MGIzcEtZSmhIUk9QWFhVYjNpZk0wSEhWNEFaQ0NIbVFwaENKcHBhbDZINkxkUUZOeFpOa0JLOXllaDI2UE05Y0hZWDlUSld4SEVkbVVHbUF5dGlDRVhmWHh0MU5NUjFWTmFxLS1hYUpnZWwrOW4zZGNiNnBydVlvNmFRPT0%3D--cf89dcf0bfbe224f75bcf3aa08414951515ea52e; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: c1bf677d-3a80-879e-ce23-260839b2be99
X-Runtime: 0.014588
X-Xss-Protection: 1; mode=block
Date: Tue, 30 Dec 2025 09:08:13 GMT
Connection: close
Transfer-Encoding: chunked
Open service 75.101.184.39:443 · ja.whatsthatcharge.com
2025-12-23 09:29
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"deb185147487a50c9be7b5ec91b18789"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Qpy0g8z4Gh8MSJzKS0LkM8HVhb3MFRa%2BP8UveQ9rUwY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766482174"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Qpy0g8z4Gh8MSJzKS0LkM8HVhb3MFRa%2BP8UveQ9rUwY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766482174"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=THhTOTh4R2hTVVlYMk9wdDJldkxJUW15MWJ6NmhOSTNrZHUzU0R2RFJKRDlOS0s0ampVdDBFRkFGVEJCNEkzVHdRTldxNUR3Wk9MR084N3Q4TE9FSUJac0pPU0k2b2xtaFhLRVovdjJOeDY3c1hGdTRteVJ5aWRBT05ZVk9XcmZoUm84eDFUdFh6MVBXQWVlTmF5Y0dQS0RWMmlERzZrNWxQUmxmS1Evc1UydlhjSHRmaDZMbHROOTJtL0IrQWNZLS1idjBsdTYvK3BZQVFYOUlIb3ZZZUt3PT0%3D--d77ed940924e0e30ed59fdb32f0d51f05aca6ce2; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 05b99109-2d48-16a4-05e4-2465a3cbb6bc
X-Runtime: 0.011092
X-Xss-Protection: 1; mode=block
Date: Tue, 23 Dec 2025 09:29:34 GMT
Connection: close
Transfer-Encoding: chunked
Open service 75.101.184.39:443 · ja.whatsthatcharge.com
2025-12-21 05:12
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"c28395c1662963d70d06d2e7157466f0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=eejFTyYNyMu5oGKMPh%2B2ftygp79oNGAbuZm2qK%2BVx6s%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766293921"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=eejFTyYNyMu5oGKMPh%2B2ftygp79oNGAbuZm2qK%2BVx6s%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766293921"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=WnFVMW02ck9mUXJRZllXK3JFLzZxTmxPVWtzSWx4ZjlzRXcyTzVQWU1oL2lzbHRxamRXTXJDeUtYRS85Yk15Y09Pa0IxL1BvanNFQUZNU3FjM0tkSllVQWk5NHZNSnRLWjJNVlZtanlFTWU5VFVPNDhvMmkxS3pGbmJWUEQ1WjA3N0xyQXNzeFhrOUYyUU9lQ3FrSjFEdzdERDhRRU0zeGJuZ0M5RCtJZWg0OHFkUENlMFNBTUhuU2pqNzQrWmZZLS04TG5jY0Q3MzlLRmNCZC9SMlVNcmFBPT0%3D--3acea48887fbb8b9b2981a0eebd2f117a9201262; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: d4621cde-6af0-c72a-6508-e1a34bbe02e3
X-Runtime: 0.012834
X-Xss-Protection: 1; mode=block
Date: Sun, 21 Dec 2025 05:12:01 GMT
Connection: close
Transfer-Encoding: chunked
Open service 75.101.184.39:443 · ja.whatsthatcharge.com
2025-12-19 08:48
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"f6ce4bc964d78ae2b91d0ec2a217b1b0"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=j1lNHqegIBHp1B6w9ix478Ibca7bJHvoPx63tadAenw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766134080"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=j1lNHqegIBHp1B6w9ix478Ibca7bJHvoPx63tadAenw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766134080"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=WnN6cU9LSzZUZzlVdC9yRzNBaUhTVnQvZ3RKYVFLRHd1eVNDQ29GZVJYZ2RmdU10YmJXeFA3RXh6cjcyUUtBZmE5OUplQTdYUlExbm1MTzVoNkpzb3JBOVdBcXZSMWVIZXlrQ2cwMlVYQ3ZJQllHTm40RzljL0VhdmpZdU9mbWVXM2JSei95ZGl6b2I4dlNaR3IzZTdHWFZmOG1ZTE0vOVZ5dHppU294MVNSMGZYc2N2MmV6YTF0L3VCWUw2RjhrLS0zZTdpakVJaXpVVTJUalc1ZzdxaHdBPT0%3D--951dba58ec64827d76acae2041d1013a082cbe27; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: a30092ab-cf27-6f84-54ad-64674ff69f11
X-Runtime: 0.012707
X-Xss-Protection: 1; mode=block
Date: Fri, 19 Dec 2025 08:48:00 GMT
Connection: close
Transfer-Encoding: chunked