Apache 2.4.65
tcp/443 tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652285e03841
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/kanboard/kanboard.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652285e03841
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/kanboard/kanboard.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 194.95.207.181:80 · pm.mebis.alp.dillingen.de
2026-01-09 12:53
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 12:53:51 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=qqd9n419da7m2j06ml0vjfkeje; path=/; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Location: /?controller=AuthController&action=login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:443 · pm.mebis.alp.dillingen.de
2026-01-02 09:33
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 09:33:42 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=jfkh1qmajnvjqs6sc8o73pej4t; path=/; secure; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Strict-Transport-Security: max-age=31536000 Location: /?controller=AuthController&action=login Strict-Transport-Security: max-age=15768000;includeSubdomains Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:80 · pm.mebis.alp.dillingen.de
2026-01-02 01:38
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 01:38:28 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=h2teg50f7ugrg4ijfbtkjja0l5; path=/; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Location: /?controller=AuthController&action=login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:80 · pm.mebis.alp.dillingen.de
2025-12-30 12:33
HTTP/1.1 302 Found Date: Tue, 30 Dec 2025 12:33:40 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=fdbp8cnbsb5crf6lc0r036ej2f; path=/; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Location: /?controller=AuthController&action=login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:443 · pm.mebis.alp.dillingen.de
2025-12-22 23:55
HTTP/1.1 302 Found Date: Mon, 22 Dec 2025 23:55:37 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=eohv5285cvoa1urg4v98k487u6; path=/; secure; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Strict-Transport-Security: max-age=31536000 Location: /?controller=AuthController&action=login Strict-Transport-Security: max-age=15768000;includeSubdomains Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:80 · pm.mebis.alp.dillingen.de
2025-12-22 08:02
HTTP/1.1 302 Found Date: Mon, 22 Dec 2025 08:02:39 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=qlknmk30mtbha19lcpduv558sb; path=/; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Location: /?controller=AuthController&action=login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:80 · pm.mebis.alp.dillingen.de
2025-12-20 06:51
HTTP/1.1 302 Found Date: Sat, 20 Dec 2025 06:51:26 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=shijbhqogec3li3bq0ef7p6025; path=/; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Location: /?controller=AuthController&action=login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 194.95.207.181:443 · pm.mebis.alp.dillingen.de
2025-12-20 05:31
HTTP/1.1 302 Found Date: Sat, 20 Dec 2025 05:31:43 GMT Server: Apache/2.4.65 (Debian) Set-Cookie: KB_SID=s7nabjtpjdcb08nut48l74ba2l; path=/; secure; HttpOnly Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Security-Policy: default-src 'self'; style-src 'self' 'unsafe-inline'; img-src * data:; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" X-Frame-Options: DENY Strict-Transport-Security: max-age=31536000 Location: /?controller=AuthController&action=login Strict-Transport-Security: max-age=15768000;includeSubdomains Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8