nginx 1.29.1
tcp/80
nginx
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222cfd375b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/autochina/maextro fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1dRQ0xuT3c0bkFzeFJvMUNkTjVoWHNJWXJEOTdjeDJ1TWNFNw== [branch "main"] remote = origin merge = refs/heads/main
Open service 136.243.155.233:80 · mail.maextro.me
2026-01-21 15:15
HTTP/1.1 301 Moved Permanently Server: nginx/1.29.1 Date: Wed, 21 Jan 2026 15:15:30 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://mail.maextro.me/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.29.1</center> </body> </html>
Open service 136.243.155.233:80 · autodiscover.maextro.me
2026-01-21 15:15
HTTP/1.1 301 Moved Permanently Server: nginx/1.29.1 Date: Wed, 21 Jan 2026 15:15:29 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://autodiscover.maextro.me/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.29.1</center> </body> </html>
Open service 136.243.155.233:80 · autoconfig.maextro.me
2026-01-21 15:15
HTTP/1.1 301 Moved Permanently Server: nginx/1.29.1 Date: Wed, 21 Jan 2026 15:15:29 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://autoconfig.maextro.me/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.29.1</center> </body> </html>
Open service 136.243.155.233:443 · mail.maextro.me
2026-01-21 15:15
HTTP/1.1 200 OK Server: nginx Date: Wed, 21 Jan 2026 15:15:30 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Set-Cookie: MCSESSID=b593171dc0ec91f4c6bb44cf33efa456; path=/; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Strict-Transport-Security: max-age=15768000; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Robots-Tag: none X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin
Open service 136.243.155.233:443 · autoconfig.maextro.me
2026-01-21 15:15
HTTP/1.1 200 OK Server: nginx Date: Wed, 21 Jan 2026 15:15:29 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Set-Cookie: MCSESSID=c8d6bf697dfda2f060c3592dddf2749e; path=/; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Strict-Transport-Security: max-age=15768000; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Robots-Tag: none X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin
Open service 136.243.155.233:443 · autodiscover.maextro.me
2026-01-21 15:15
HTTP/1.1 200 OK Server: nginx Date: Wed, 21 Jan 2026 15:15:30 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding Set-Cookie: MCSESSID=15e588288cb1371d0799007b80755bc5; path=/; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Strict-Transport-Security: max-age=15768000; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block X-Robots-Tag: none X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none Referrer-Policy: strict-origin