cloudflare
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea96ba46591629a2ee1cbb56ea163e836bb
Found 23 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads /uploads/media
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07c6ff1707c6ff1707c6ff1707c6ff1707c6ff1707
Symfony profiler enabled: https://manekicasino-ca.com/_profiler/empty/search/results
Open service 188.114.97.3:443 · manekicasino-ca.com
2026-01-23 07:46
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 07:46:34 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=CovTxwrfbBPiYjHu4shDW0NDb%2FddPLu74HvuvxULwU5yVsg7oWJcFMlDKjPvo%2F1OKjJ5FmiD7B6EBtfzoWYhpZJbYogSFrQs0dt2j0yXdpa4ezo%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 23 Feb 2026 07:46:34 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=6,cfOrigin;dur=922
CF-RAY: 9c25ad91df95eef5-EWR
Open service 2a06:98c1:3121::3:443 · manekicasino-ca.com
2026-01-22 19:56
HTTP/1.1 200 OK
Date: Thu, 22 Jan 2026 19:56:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=cwZgq4Cw9NKEYDGoFWiqVVsOE%2FZ9vkOpxMGGQVF8PSRqiPimifiTwgtO0RUl6bNZ5ehrxo72%2Boym2EvRnGe0NgzRDvLejAF6gj38uuTVltSv5vk6lgNprGT181Ym%2F88%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 22 Feb 2026 19:56:33 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=5,cfOrigin;dur=617
CF-RAY: 9c219d81b818978e-SIN
Open service 188.114.97.3:443 · manekicasino-ca.com
2026-01-10 01:10
HTTP/1.1 200 OK
Date: Sat, 10 Jan 2026 01:10:57 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=9uKdPmJCZ%2F80Qe5%2BvFj5N%2FtjTWkgU6nqtWZaswfAxGEbJ5tEQAe%2BL0lmyq0HbRukUDCEtum4ZK1t92grMCJ5zOUWFhxKHAMAsd313n4b3tD0P90%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 10 Feb 2026 01:10:56 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=6,cfOrigin;dur=1565
CF-RAY: 9bb84c233f9834be-BOM