cloudflare
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea96ba46591629a2ee1cbb56ea163e836bb
Found 23 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads /uploads/media
Severity: low
Fingerprint: 5f32cf5d6962f09c3838040e3838040e5e6a8b7a70bcfd92ae23e35cca3b362b
Found 20 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /uploads
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07aa121ee1aa121ee1aa121ee1aa121ee1aa121ee1
Symfony profiler enabled: https://magicred-nz.com/_profiler/empty/search/results
Open service 188.114.97.3:443 · magicred-nz.com
2026-01-08 22:24
HTTP/1.1 200 OK
Date: Thu, 08 Jan 2026 22:24:14 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=9VdC9%2BinNh41cteYyZo8LVIn86S3lnoIVBVFkf2zaePCbry1T7UVy6az%2FGZk11MxPyqAcHBLQbyei4xSFXZFdg%2FZ1KhbLTkr95FTqeK%2FJw%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 08 Feb 2026 22:24:14 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9baf1a97fd8fd1b8-LHR
Open service 2a06:98c1:3120::3:443 · magicred-nz.com
2026-01-08 19:09
HTTP/1.1 200 OK
Date: Thu, 08 Jan 2026 19:09:59 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=HsoF2guXFBCqX6mSmAxG7rRUKS11KfKe9NfBtCiJa2TYUvQWbX9wBgFw99ijJslHzP2rNdZMdai%2FlMrj4bfTN2DZdradBlgdbRssvqoV78vNnMyz9rqkxBvRtA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 08 Feb 2026 19:09:59 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=1080
CF-RAY: 9badfe081ce0fdce-SIN
Open service 188.114.97.3:443 · magicred-nz.com
2026-01-02 11:29
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 11:29:22 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=nliLuc%2Bct%2FbRtzubZ3q9nbV1C3nwq86hqgXgfJgH3F%2FJrG73BOCKSCI4ukeek00S%2B7wgH0Bm4Ur4cbc0YbyJ2%2BtmvoeSnc6hO5%2FdUi0%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 02 Feb 2026 11:29:22 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=780
CF-RAY: 9b79eb0caa262067-EWR
Open service 2a06:98c1:3120::3:443 · magicred-nz.com
2026-01-01 20:01
HTTP/1.1 200 OK
Date: Thu, 01 Jan 2026 20:01:56 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Bn54DCorANEgV2FnYsrzhLtwOSZq%2BJz0WpVe1L1et%2BaHGczHuQq5gZyZV6cDJshziCvYv%2FRk46%2BssGIWROiM7gKLiIogJJk6R7pMqT8YpHvMO%2F2aOPAVbDjXng%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 01 Feb 2026 20:01:56 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b749c87ef75d2ae-FRA
Open service 2a06:98c1:3120::3:443 · magicred-nz.com
2025-12-30 04:09
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 04:09:46 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=GytQe3dMlcyO03ObZnOhEIhN%2FCwNVQe4iocHc5iJ4PkSgGkVrHsMaLrqJ%2BVxhQbL8i5f9bB0mxkgCqsSNysLt5WvbnDzt6dgBk9CAmh9T8hqQ8tnfn5Gq%2FHT5A%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Fri, 30 Jan 2026 04:09:45 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b5eaefb5b01d252-FRA
Open service 188.114.97.3:443 · magicred-nz.com
2025-12-22 21:42
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 21:42:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=MwgbqhQdiefFNTkbrVqcCgxCJxUix2B70nJZyo3heHZxXCh%2BaRSlOJzQgs1rQfD3l%2FZYjfnYCgotqDF9%2Fztld8mW8egPXLFSyOGXhqBqPw%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 21:42:25 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=1107
CF-RAY: 9b22c9f2bea2ca4b-SIN
Open service 2a06:98c1:3120::3:443 · magicred-nz.com
2025-12-22 04:55
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 04:55:23 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=y5M%2Fg9lWhPPJuXShRjnIdS7JjrkACxPrc5fMFQ7FU6pQ1XgCNmIfkzUORUM0t8iDAK2BW3h71BtFDo2Yfdjt1ZgeyCL4GN8t4QnBb05046lJVHBvDqi4P4uGgQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 04:55:23 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=16,cfOrigin;dur=1085
CF-RAY: 9b1d06cc4a28fda8-SIN
Open service 188.114.97.3:443 · magicred-nz.com
2025-12-20 23:30
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 23:30:13 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=9sNecNC5VaTliLoDWquJINPOi3TIS3MyPUZLwJ1o7XGrSAiH2w9l2oa1PRpd9tMUVGL6KA7UVQpbimZbhbVjjECwAZJPI1eLq3dedcs7eA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 23:30:12 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b12ed1bac47c542-LHR
Open service 2a06:98c1:3120::3:443 · magicred-nz.com
2025-12-20 04:54
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 04:54:29 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=uFQ6fUqXWUJXp0vdSqd7t5k5WfQF%2FqCTbgQkdeJuJwAMJGgdMys36k4BGLjD0fZSIdubdatBLcnZVH1GLBNd1Ue%2Fsb3MCOVaJrxneWG1qYuYkTLRabV61T5%2BGA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 04:54:29 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=5,cfOrigin;dur=499
CF-RAY: 9b0c8abf7918f4c4-SJC
Open service 188.114.97.3:443 · magicred-nz.com
2025-12-19 00:35
HTTP/1.1 200 OK
Date: Fri, 19 Dec 2025 00:35:55 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=59LBwnxEi1vzf733eraFEHpxBLKvST0Q8kx%2B4Dm7wS6lScqHXtBwGUa7uyiOnktQl3GOCG%2FmaQaT4BXGhK8ey1bw4bdmNWr2v1O6XlW4Sg%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 19 Jan 2026 00:35:55 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=4,cfOrigin;dur=595
CF-RAY: 9b02d29a299bcb4f-BOM