cloudflare
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2df9b2641df9b2641df9b2641df9b2641df9b2641
GraphQL introspection enabled at /graphql/api Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3feb21e5604bf4b86dd39e257352bf3e4f7e77c9c
GraphQL introspection enabled at /graphql Types: 806 (by kind: ENUM: 53, INPUT_OBJECT: 163, INTERFACE: 30, OBJECT: 555, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa30e679750188361944b9085ed8882235eb06517ae
GraphQL introspection enabled at /graphql Types: 803 (by kind: ENUM: 53, INPUT_OBJECT: 162, INTERFACE: 30, OBJECT: 553, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3bfe51878781b289cf0cca965066fe50674e69ee6
GraphQL introspection enabled at /graphql Types: 802 (by kind: ENUM: 53, INPUT_OBJECT: 162, INTERFACE: 30, OBJECT: 552, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d59ad49cd5c0a8a011c721212dfb59aaac5c228a
GraphQL introspection enabled at /graphql Types: 800 (by kind: ENUM: 53, INPUT_OBJECT: 162, INTERFACE: 30, OBJECT: 550, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3feb21e5604bf4b86dd39e257352bf3e4f7e77c9c
GraphQL introspection enabled at /graphql Types: 806 (by kind: ENUM: 53, INPUT_OBJECT: 163, INTERFACE: 30, OBJECT: 555, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa30e679750188361944b9085ed8882235eb06517ae
GraphQL introspection enabled at /graphql Types: 803 (by kind: ENUM: 53, INPUT_OBJECT: 162, INTERFACE: 30, OBJECT: 553, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3bfe51878781b289cf0cca965066fe50674e69ee6
GraphQL introspection enabled at /graphql Types: 802 (by kind: ENUM: 53, INPUT_OBJECT: 162, INTERFACE: 30, OBJECT: 552, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d59ad49cd5c0a8a011c721212dfb59aaac5c228a
GraphQL introspection enabled at /graphql Types: 800 (by kind: ENUM: 53, INPUT_OBJECT: 162, INTERFACE: 30, OBJECT: 550, SCALAR: 5) Operations: - Query: Query | fields: CheckPriceChange, StoreLocators, addressDefault, archivedBlog, attributesForm - Mutation: Mutation | fields: addAllItemQuickOrderToCart, addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addMultipleProductsToListQuickOrder Directives: deprecated, include, skip (total: 3)
Open service 104.26.9.49:443 · admin.mmpro.vn
2026-01-23 12:12
HTTP/1.1 302 Found Date: Fri, 23 Jan 2026 12:12:29 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close location: https://old.mmpro.vn/ Server: cloudflare Set-Cookie: PHPSESSID=aag3pq9v93gfeg6hdpsigoo8of; expires=Sat, 24 Jan 2026 12:12:29 GMT; Max-Age=86400; path=/; domain=admin.mmpro.vn; secure; HttpOnly; SameSite=Lax pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store expires: Thu, 23 Jan 2025 12:12:29 GMT
Open service 172.67.74.162:443 · mmpro.vn
2026-01-22 20:57
HTTP/1.1 200 OK
Date: Thu, 22 Jan 2026 20:57:53 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
vary: Accept-Encoding
x-powered-by: Express
Cache-Control: s-maxage=60
content-security-policy: script-src http: https: 'unsafe-inline' http://internal-fe-internal-lb-1415956405.ap-southeast-1.elb.amazonaws.com/ *.goong.io *.googletagmanager.com td.doubleclick.net cdn.jsdelivr.net 'unsafe-eval'; style-src 'self' blob: https: 'unsafe-inline' http://internal-fe-internal-lb-1415956405.ap-southeast-1.elb.amazonaws.com/ *.goong.io cdn.jsdelivr.net; img-src 'self' data: http: https: *.goong.io; object-src 'none'; base-uri 'none'; child-src 'self' blob: *.goong.io cdn.jsdelivr.net; font-src 'self' *.antsomi.com fonts.gstatic.com; worker-src 'self' blob: *.goong.io cdn.jsdelivr.net; frame-src assets.braintreegateway.com *.google.com *.youtube.com *.youtu.be *.vimeo.com *.goong.io *.googletagmanager.com td.doubleclick.net *.freshchat.com cdn.jsdelivr.net *.my.canva.site canva.com *.canva.com
strict-transport-security: max-age=31536000
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
access-control-allow-origin: *
access-control-allow-methods: GET, OPTIONS
access-control-allow-headers: Origin, Content-Type, Accept, Authorization
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=96stUukMVqdWd1lOlbtRDJS3I4%2FBtX34a6BIjxBg%2BjZ4H4ZlXjTMdicjmipMDaIZc8cinTsEiieMFA%2Bd9phGBq2zhjZbS3g%3D"}]}
cf-cache-status: DYNAMIC
CF-RAY: 9c21f7577be85d66-FRA
Open service 104.26.9.49:443 · admin.mmpro.vn
2026-01-09 06:57
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 06:57:24 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close location: https://old.mmpro.vn/ Server: cloudflare Set-Cookie: PHPSESSID=c77ugo2vufvsgbd4o3ria7bq78; expires=Sat, 10 Jan 2026 06:57:24 GMT; Max-Age=86400; path=/; domain=admin.mmpro.vn; secure; HttpOnly; SameSite=Lax pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store expires: Thu, 09 Jan 2025 06:57:24 GMT
Open service 104.26.9.49:80 · mmpro.vn
2026-01-08 21:00
HTTP/1.1 301 Moved Permanently
Date: Thu, 08 Jan 2026 21:00:36 GMT
Content-Length: 0
Connection: close
Location: https://mmpro.vn/
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=pcDmR3DtmL7nmkFeY3Ek%2BVbUqcX4c0QYsuujV0aJFd6jqcJx38oXgzZsYza%2FNMY5VFgraF5N%2BEMlDmZ1nCpBZQFAKHxL5zI%3D"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server: cloudflare
CF-RAY: 9baea01abba0d86d-BLR
Open service 172.67.74.162:443 · mmpro.vn
2026-01-08 19:30
HTTP/1.1 403 Forbidden
Date: Thu, 08 Jan 2026 19:30:09 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Referrer-Policy: same-origin
X-Frame-Options: SAMEORIGIN
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=EYCRSRwFk%2B494NXG2dzrswSicG59dVxwYyVCqby3dMslfgq9bRwY7zH9XWPYNgm9qmZUX%2BkpbBpgNUulv4N5uAMgoEcS"}]}
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server: cloudflare
CF-RAY: 9bae1b98cbe5fb97-AMS
Page title: Attention Required! | Cloudflare
<!DOCTYPE html>
<!--[if lt IE 7]> <html class="no-js ie6 oldie" lang="en-US"> <![endif]-->
<!--[if IE 7]> <html class="no-js ie7 oldie" lang="en-US"> <![endif]-->
<!--[if IE 8]> <html class="no-js ie8 oldie" lang="en-US"> <![endif]-->
<!--[if gt IE 8]><!--> <html class="no-js" lang="en-US"> <!--<![endif]-->
<head>
<title>Attention Required! | Cloudflare</title>
<meta charset="UTF-8" />
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=Edge" />
<meta name="robots" content="noindex, nofollow" />
<meta name="viewport" content="width=device-width,initial-scale=1" />
<link rel="stylesheet" id="cf_styles-css" href="/cdn-cgi/styles/cf.errors.css" />
<!--[if lt IE 9]><link rel="stylesheet" id='cf_styles-ie-css' href="/cdn-cgi/styles/cf.errors.ie.css" /><![endif]-->
<style>body{margin:0;padding:0}</style>
<!--[if gte IE 10]><!-->
<script>
if (!navigator.cookieEnabled) {
window.addEventListener('DOMContentLoaded', function () {
var cookieEl = document.getElementById('cookie-alert');
cookieEl.style.display = 'block';
})
}
</script>
<!--<![endif]-->
</head>
<body>
<div id="cf-wrapper">
<div class="cf-alert cf-alert-error cf-cookie-error" id="cookie-alert" data-translate="enable_cookies">Please enable cookies.</div>
<div id="cf-error-details" class="cf-error-details-wrapper">
<div class="cf-wrapper cf-header cf-error-overview">
<h1 data-translate="block_headline">Sorry, you have been blocked</h1>
<h2 class="cf-subheadline"><span data-translate="unable_to_access">You are unable to access</span> mmpro.vn</h2>
</div><!-- /.header -->
<div class="cf-section cf-highlight">
<div class="cf-wrapper">
<div class="cf-screenshot-container cf-screenshot-full">
<span class="cf-no-screenshot error"></span>
</div>
</div>
</div><!-- /.captcha-container -->
<div class="cf-section cf-wrapper">
<div class="cf-columns two">
<div class="cf-column">
<h2 data-translate="blocked_why_headline">Why have I been blocked?</h2>
<p data-translate="blocked_why_detail">This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.</p>
</div>
<div class="cf-column">
<h2 data-translate="blocked_resolve_headline">What can I do to resolve this?</h2>
<p data-translate="blocked_resolve_detail">You can email the site owner to let them know you were blocked. Please include what you were doing when this page came up and the Cloudflare Ray ID found at the bottom of this page.</p>
</div>
</div>
</div><!-- /.section -->
<div class="cf-error-footer cf-wrapper w-240 lg:w-full py-10 sm:py-4 sm:px-8 mx-auto text-center sm:text-left border-solid border-0 border-t border-gray-300">
<p class="text-13">
<span class="cf-footer-item sm:block sm:mb-1">Cloudflare Ray ID: <strong class="font-semibold">9bae1b98cbe5fb97</strong></span>
<span class="cf-footer-separator sm:hidden">•</span>
<span id="cf-footer-item-ip" class="cf-footer-item hidden sm:block sm:mb-1">
Your IP:
<button type="button" id="cf-footer-ip-reveal" class="cf-footer-ip-reveal-btn">Click to reveal</button>
<span class="hidden" id="cf-footer-ip">64.225.75.246</span>
<span class="cf-footer-separator sm:hidden">•</span>
</span>
<span class="cf-footer-item sm:block sm:mb-1"><span>Performance & security by</span> <a rel="noopener noreferrer" href="https://www.cloudflare.com/5xx-error-landing" id="brand_link" target="_blank">Cloudflare</a></span>
</p>
<script>(function(){function d(){var b=a.getElementById("cf-footer-item-ip"),c=a.getElementById("cf-footer-ip-reveal");b&&"classL
Open service 104.26.9.49:443 · admin.mmpro.vn
2026-01-02 08:10
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 08:11:01 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close location: https://old.mmpro.vn/ Server: cloudflare Set-Cookie: PHPSESSID=gbs018eb4bl1f6nm9qrh3v4l97; expires=Sat, 03 Jan 2026 08:11:00 GMT; Max-Age=86400; path=/; domain=admin.mmpro.vn; secure; HttpOnly; SameSite=Lax pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store expires: Thu, 02 Jan 2025 08:11:00 GMT
Open service 104.26.9.49:443 · admin.mmpro.vn
2025-12-22 15:42
HTTP/1.1 302 Found Date: Mon, 22 Dec 2025 15:42:22 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close location: https://old.mmpro.vn/ Server: cloudflare Set-Cookie: PHPSESSID=2vi3k1e8ndkkna88p1ujuc9l4l; expires=Tue, 23 Dec 2025 15:42:22 GMT; Max-Age=86400; path=/; domain=admin.mmpro.vn; secure; HttpOnly; SameSite=Lax pragma: no-cache Cache-Control: max-age=0, must-revalidate, no-cache, no-store expires: Sun, 22 Dec 2024 15:42:22 GMT
Open service 172.67.74.162:443 · mmpro.vn
2025-12-22 11:05
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 11:05:22 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
vary: Accept-Encoding
x-powered-by: Express
Cache-Control: s-maxage=60
content-security-policy: script-src http: https: 'unsafe-inline' http://internal-fe-internal-lb-1415956405.ap-southeast-1.elb.amazonaws.com/ *.goong.io *.googletagmanager.com td.doubleclick.net cdn.jsdelivr.net 'unsafe-eval'; style-src 'self' blob: https: 'unsafe-inline' http://internal-fe-internal-lb-1415956405.ap-southeast-1.elb.amazonaws.com/ *.goong.io cdn.jsdelivr.net; img-src 'self' data: http: https: *.goong.io; object-src 'none'; base-uri 'none'; child-src 'self' blob: *.goong.io cdn.jsdelivr.net; font-src 'self' *.antsomi.com fonts.gstatic.com; worker-src 'self' blob: *.goong.io cdn.jsdelivr.net; frame-src assets.braintreegateway.com *.google.com *.youtube.com *.youtu.be *.vimeo.com *.goong.io *.googletagmanager.com td.doubleclick.net *.freshchat.com cdn.jsdelivr.net *.my.canva.site canva.com *.canva.com
strict-transport-security: max-age=31536000
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
access-control-allow-origin: *
access-control-allow-methods: GET, OPTIONS
access-control-allow-headers: Origin, Content-Type, Accept, Authorization
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=rclV61HzyTPQCXRVTiTWE%2FnS5nfKC%2Buq03kVYXY4fztM53hkeCN0dkSKKHE%2Bo1LUrnO8aPgmEWRAJsmvStoLWMhss%2FhqZ%2FY%3D"}]}
cf-cache-status: DYNAMIC
CF-RAY: 9b1f24c1aa27432b-EWR