.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: high
Fingerprint: 5f32cf5d6962f09c87f05b7087f05b706e7a2760593b78ec7879624295bfacdc
Found 26 files trough .DS_Store spidering: /assets /assets/favicons /assets/fronttemplate /assets/fronttemplate/css /assets/fronttemplate/img /assets/fronttemplate/img/favicons /assets/fronttemplate/img/feedback /assets/fronttemplate/img/Hero /assets/fronttemplate/img/icons /assets/fronttemplate/img/illustrations /assets/fronttemplate/img/logos /assets/fronttemplate/js /assets/fronttemplate/vendors /assets/fronttemplate/video /assets/kvkk /assets/logo.svg /assets/logoonly.svg /assets/tabler /build /favicon.ico /index.php /panel /robots.txt /uploads /uploads/20231220-stklist.json /vendor
Open service 31.40.198.13:80 · mail.ekurul.com
2026-01-22 14:30
HTTP/1.1 302 Found Location: /interface/root Content-Security-Policy: default-src 'self';frame-src 'self' *.youtube.com youtu.be *.smartertools.com docs.google.com;script-src * 'unsafe-inline';font-src * 'unsafe-inline' data:;img-src * 'unsafe-inline' data: blob:;style-src * 'unsafe-inline';media-src *;frame-ancestors 'self';connect-src *; X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Robots-Tag: noindex X-Powered-By: ARR/3.0 X-Powered-By: ASP.NET Date: Thu, 22 Jan 2026 14:30:53 GMT Connection: close Content-Length: 0
Open service 31.40.198.11:80 · mail.ekurul.com
2026-01-22 14:30
HTTP/1.1 302 Found Location: /interface/root Content-Security-Policy: default-src 'self';frame-src 'self' *.youtube.com youtu.be *.smartertools.com docs.google.com;script-src * 'unsafe-inline';font-src * 'unsafe-inline' data:;img-src * 'unsafe-inline' data: blob:;style-src * 'unsafe-inline';media-src *;frame-ancestors 'self';connect-src *; X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Robots-Tag: noindex X-Powered-By: ARR/3.0 X-Powered-By: ASP.NET Date: Thu, 22 Jan 2026 14:30:54 GMT Connection: close Content-Length: 0
Open service 31.40.198.10:80 · mail.ekurul.com
2026-01-22 14:30
HTTP/1.1 302 Found Location: /interface/root Content-Security-Policy: default-src 'self';frame-src 'self' *.youtube.com youtu.be *.smartertools.com docs.google.com;script-src * 'unsafe-inline';font-src * 'unsafe-inline' data:;img-src * 'unsafe-inline' data: blob:;style-src * 'unsafe-inline';media-src *;frame-ancestors 'self';connect-src *; X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Robots-Tag: noindex X-Powered-By: ARR/3.0 X-Powered-By: ASP.NET Date: Thu, 22 Jan 2026 14:30:53 GMT Connection: close Content-Length: 0
Open service 31.40.198.12:80 · mail.ekurul.com
2026-01-22 14:30
HTTP/1.1 302 Found Location: /interface/root Content-Security-Policy: default-src 'self';frame-src 'self' *.youtube.com youtu.be *.smartertools.com docs.google.com;script-src * 'unsafe-inline';font-src * 'unsafe-inline' data:;img-src * 'unsafe-inline' data: blob:;style-src * 'unsafe-inline';media-src *;frame-ancestors 'self';connect-src *; X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Robots-Tag: noindex X-Powered-By: ARR/3.0 X-Powered-By: ASP.NET Date: Thu, 22 Jan 2026 14:30:53 GMT Connection: close Content-Length: 0
Open service 31.40.198.14:80 · mail.ekurul.com
2026-01-22 14:30
HTTP/1.1 302 Found Location: /interface/root Content-Security-Policy: default-src 'self';frame-src 'self' *.youtube.com youtu.be *.smartertools.com docs.google.com;script-src * 'unsafe-inline';font-src * 'unsafe-inline' data:;img-src * 'unsafe-inline' data: blob:;style-src * 'unsafe-inline';media-src *;frame-ancestors 'self';connect-src *; X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Robots-Tag: noindex X-Powered-By: ARR/3.0 X-Powered-By: ASP.NET Date: Thu, 22 Jan 2026 14:30:53 GMT Connection: close Content-Length: 0