nginx
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 192.0.66.101:80 · preprod.dailycamera.com
2026-01-10 21:29
HTTP/1.1 301 Moved Permanently Server: nginx Date: Sat, 10 Jan 2026 21:29:52 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://preprod.dailycamera.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a04:fa87:fffd::c000:4265:80 · preprod.dailycamera.com
2026-01-10 21:29
HTTP/1.1 301 Moved Permanently Server: nginx Date: Sat, 10 Jan 2026 21:29:52 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://preprod.dailycamera.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a04:fa87:fffd::c000:4265:443 · preprod.dailycamera.com
2026-01-10 21:29
HTTP/1.1 200 OK Server: nginx Date: Sat, 10 Jan 2026 21:29:53 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink cache-control: private x-rq: jfk1 0 20 9980 accept-ranges: bytes x-cache: HIT Strict-Transport-Security: max-age=31536000;includeSubdomains
Open service 192.0.66.101:443 · preprod.dailycamera.com
2026-01-10 21:29
HTTP/1.1 200 OK Server: nginx Date: Sat, 10 Jan 2026 21:29:53 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink x-rq: lhr3 0 20 9980 accept-ranges: bytes cache-control: private x-cache: HIT Strict-Transport-Security: max-age=31536000;includeSubdomains
Open service 192.0.66.101:443 · preprod.dailycamera.com
2026-01-09 20:26
HTTP/1.1 200 OK Server: nginx Date: Fri, 09 Jan 2026 20:26:40 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink cache-control: private x-rq: sjc3 177 253 80 accept-ranges: bytes x-cache: HIT Strict-Transport-Security: max-age=31536000;includeSubdomains
Open service 192.0.66.101:443 · preprod.dailycamera.com
2026-01-03 00:41
HTTP/1.1 200 OK Server: nginx Date: Sat, 03 Jan 2026 00:42:06 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink cache-control: private accept-ranges: bytes x-cache: MISS x-rq: yyz1 0 20 9980 Strict-Transport-Security: max-age=31536000;includeSubdomains
Open service 192.0.66.101:443 · preprod.dailycamera.com
2025-12-23 07:37
HTTP/1.1 200 OK Server: nginx Date: Tue, 23 Dec 2025 07:37:55 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink x-rq: lhr2 0 20 9980 cache-control: private accept-ranges: bytes x-cache: MISS Strict-Transport-Security: max-age=31536000;includeSubdomains
Open service 192.0.66.101:443 · preprod.dailycamera.com
2025-12-21 05:34
HTTP/1.1 200 OK Server: nginx Date: Sun, 21 Dec 2025 05:34:17 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink x-rq: lhr3 0 20 9980 cache-control: private accept-ranges: bytes x-cache: EXPIRED Strict-Transport-Security: max-age=31536000;includeSubdomains
Open service 192.0.66.101:443 · preprod.dailycamera.com
2025-12-19 04:05
HTTP/1.1 200 OK Server: nginx Date: Fri, 19 Dec 2025 04:05:38 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Content-Security-Policy: default-src data: 'unsafe-inline' 'unsafe-eval' https:; script-src data: 'unsafe-inline' 'unsafe-eval' https: blob: *.visualwebsiteoptimizer.com; style-src 'unsafe-inline' https: *.visualwebsiteoptimizer.com app.vwo.com; img-src data: https: blob: *.visualwebsiteoptimizer.com app.vwo.com useruploads.vwo.io; font-src data: https:; connect-src https: data: blob: *.visualwebsiteoptimizer.com app.vwo.com; media-src blob: data: https:; object-src https:; child-src https: data: blob: 'self' *.visualwebsiteoptimizer.com app.vwo.com; upgrade-insecure-requests; block-all-mixed-content; X-hacker: If you're reading this, you should visit https://join.a8c.com/viphacker and apply to join the fun, mention this header. X-Powered-By: WordPress VIP <https://wpvip.com> Host-Header: a9130478a60e5f9135f765b23f26593b X-Robots-Tag: noindex, nofollow Link: <https://preprod.dailycamera.com/wp-json/>; rel="https://api.w.org/" Link: <https://wp.me/bgxJk>; rel=shortlink x-rq: sin2 177 253 80 accept-ranges: bytes cache-control: private x-cache: HIT Strict-Transport-Security: max-age=31536000;includeSubdomains