cloudflare
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea96ba46591629a2ee1cbb56ea163e836bb
Found 23 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads /uploads/media
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07cfd01403cfd01403cfd01403cfd01403cfd01403
Symfony profiler enabled: https://nomini-nz.com/_profiler/empty/search/results
Open service 188.114.97.3:443 · nomini-nz.com
2026-01-09 22:44
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 22:44:36 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=oDQXCc8CbjKiOBQXDyWPoULOTwFRBvbysqrtNNL8saJfYDEj%2BO0ZkhCyNpcA8UP9hjBoGPVScpIYUoEKGiPc%2FVDlLsT%2FnIZPEcnmD1E%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 22:44:36 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9bb775c9ac7968a5-FRA
Open service 2a06:98c1:3120::3:443 · nomini-nz.com
2026-01-09 03:03
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 03:03:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ECx20NOWCdkOgDPzvMN9sKHM1gq%2Fc7zp%2FxCjrmJ0huAAzS1Y3F8e%2BwbHOimZMXjvUK9S58zUm5IqNeEzfKtvFrEoGzFupB4RNElYoomER%2FpNVDpUD4X2oGY%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 03:03:27 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=839
CF-RAY: 9bb0b395bcbdebb9-YYZ
Open service 2a06:98c1:3120::3:443 · nomini-nz.com
2026-01-02 03:41
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 03:41:07 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=KqzT%2FYCsKJbFG7zV9JUKdxB7Z54FXkArZg%2BSXdhyeYrTjB7NnYd3%2BqMQbhJZpv6GDAf9DAC8IzIrzLq4mBrS6Je4CPEcOh9I%2Fzp7nAxSaDMKMWF7mJLBm18%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 02 Feb 2026 03:41:07 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=1063
CF-RAY: 9b773d218d87fd0b-SIN
Open service 2a06:98c1:3120::3:443 · nomini-nz.com
2025-12-30 13:48
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 13:48:53 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=3yv7jN94noq3ccZoytbjj4VITX4zisSIlEOoJH5h2DIvygWn44xH5GaMibcTiO5BVK9xG9Dq%2BqND%2Bf3jo7D70WZ3jEkDde5qtKG2kCIP3bPED%2FduE7xKz94%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Fri, 30 Jan 2026 13:48:52 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=575
CF-RAY: 9b61ff4a7e9c3add-BOM
Open service 188.114.97.3:443 · nomini-nz.com
2025-12-30 12:18
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 12:18:35 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=M3mje2to%2B2%2FKnUTjlHd0%2F9373aU%2F5M1uCYfQnFz9zZNU7talUIUViXBsjePTdkzcVjN62XyjVBbK5H6%2F8RvwqW99%2BfCOYcEvaRxGE28%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Fri, 30 Jan 2026 12:18:35 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=771
CF-RAY: 9b617b05fdf14308-EWR
Open service 188.114.97.3:443 · nomini-nz.com
2025-12-22 22:08
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 22:08:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=oKh52fQilDosIHEPWf%2F5JBJxJDLzqDf5SiKTmGeiCWJ8899EoY08lSt6xvjH5fyRCjbT7%2Fw%2BF60CTiYuulaxmJT2%2FqhArNmnVyeC"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 22:08:33 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b22f03ba8f26997-FRA
Open service 2a06:98c1:3120::3:443 · nomini-nz.com
2025-12-22 14:29
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 14:29:37 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=HWV2BCgrz4ErPCiaeN24M4NiJ4uK0wR2df0Df0rcmdprvAijZK1j06Qa6ODHOu8YYq16BeCs6p0VgcTIV%2BdBiAZFlyI6YkS111HiUbkjg7sfmmIZFoTVLxI%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 14:29:37 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b204ffbae7737eb-FRA
Open service 188.114.97.3:443 · nomini-nz.com
2025-12-21 04:01
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 04:01:04 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=SH9oV9G10HuEA1MPIQdNnOKodMRHeol8NZ%2F6njoE9aL6eoB%2FjSOEawBSkWKGNFqdWt4DUgGLuzcpv%2FumlDcQcN4CSK%2FSGPiT3cX4f1Q%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Wed, 21 Jan 2026 04:01:03 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=8,cfOrigin;dur=1393
CF-RAY: 9b1479d61e064461-BOM
Open service 2a06:98c1:3120::3:443 · nomini-nz.com
2025-12-20 17:35
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 17:35:22 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=tYf1TLtN03tCHDuA4q5T%2FoUK4osDUNqLKSgB0XaESNY6Hu7BW0UBXrByCLWy%2FHGFL2psIWEoCSRAsuCjqW%2Bi2r7emE%2Fmylb%2BSYFACw%2F%2F2YwXh0WyG1wm"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 17:35:22 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=12,cfOrigin;dur=1066
CF-RAY: 9b10e54fdc3367c7-SJC
Open service 188.114.97.3:443 · nomini-nz.com
2025-12-19 02:39
HTTP/1.1 200 OK
Date: Fri, 19 Dec 2025 02:39:58 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=trXrIn5ePrL96dnMcbPxu%2F4fbSC3gMF7Vl2uoxCjzJy1Wv7B5TtEdOs0jTRqvlW2w0uw%2BC6fpbcdwzOZjH7nGLWFB2HVYt26op0PXX8%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 19 Jan 2026 02:39:58 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b0388526e9ddc9e-FRA