Apache
tcp/443 tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c1a5d9b0f1a5d9b0f58862173d048e42ec46438f7c46438f7
Found 3 files trough .DS_Store spidering: /de /fr /images
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9db7f4c636b7f4c636b7f4c636b7f4c636
Found 1 files trough .DS_Store spidering: /images
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c1a5d9b0f1a5d9b0f58862173d048e42ec46438f7c46438f7
Found 3 files trough .DS_Store spidering: /de /fr /images
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9db7f4c636b7f4c636b7f4c636b7f4c636
Found 1 files trough .DS_Store spidering: /images
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d6d26bdd01f109bf3ae01179be3120c9be3120c9
GraphQL introspection enabled at /graphql Types: 24 (by kind: ENUM: 6, INPUT_OBJECT: 1, OBJECT: 11, SCALAR: 6) Operations: - Query: Query | fields: firms, getResultsAllPhase, getResultsPhaseA, votes Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d6d26bdd01f109bf3ae01179be3120c9be3120c9
GraphQL introspection enabled at /graphql Types: 24 (by kind: ENUM: 6, INPUT_OBJECT: 1, OBJECT: 11, SCALAR: 6) Operations: - Query: Query | fields: firms, getResultsAllPhase, getResultsPhaseA, votes Directives: deprecated, include, skip (total: 3)
Open service 83.166.138.100:80 · voting-api.prixiff.ch
2026-01-23 16:57
HTTP/1.1 200 OK date: Fri, 23 Jan 2026 16:57:38 GMT server: Apache cache-control: no-cache, private set-cookie: XSRF-TOKEN=eyJpdiI6InRUZEFZZCtJTi82RDBvby9rNk1EbkE9PSIsInZhbHVlIjoiTCtqNnIwSXVQOGY3cXdxME5aMHpndldDN3lEWUpmMDhDWWxYbVBSRHQycTNvY1ovNDR2d1pia2ZZd2l4MmFHb2RENUlSbzBhb3U1eEV2TFNNV1NQU2w4ck90MFluNnp3bVZWT2Q3NVp5QWdrTURGRVRKUnVYWXRiWko0T3pYdkIiLCJtYWMiOiIxODc0NjlmZWYzZTUzYTIwNDllNGNjMGVkYmY5MWUzOGYxMjIwYjdjYTVmMTM4ODQ1Y2FmOTY3N2IzNDdlODY4IiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 18:57:39 GMT; Max-Age=7200; path=/; samesite=lax set-cookie: laravel_session=eyJpdiI6IjhEa1NEQWx5Y1IzcTdtRFJMYkpnQ0E9PSIsInZhbHVlIjoiZnI1Y2M4T2paRVBlNDNqbStodXVxQWlnRDFwQUp1cHl1VTZLK3IrUGJvYWlsbHhMNlkzNmJpR0VJOStHWWFISStmdmtOMWhsZ3pyNGJOVXVzOWFxWlk4dXQ5VzI5Mk5oSFdnUlpTWG1hMFhrZlo2ZFBsV2NON1dCK2d1b0tXSlciLCJtYWMiOiJlM2Q5MWEwOTU5MDcxZWYzMDJjODA5Y2ZmMGMwMGRlZGUwNjJiODZhMWNkZjUyM2NkNGQ3NWJkNzNmZjU2MmY4IiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 18:57:39 GMT; Max-Age=7200; path=/; httponly; samesite=lax upgrade: h2 connection: Upgrade vary: Accept-Encoding transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:443 · maintenance.prixiff.ch
2026-01-23 07:46
HTTP/1.1 301 Moved Permanently date: Fri, 23 Jan 2026 07:46:58 GMT server: Apache vary: Accept-Encoding,Cookie x-redirect-by: WordPress strict-transport-security: max-age=16000000 upgrade: h2 connection: Upgrade location: https://prixiff.ch/ transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:443 · prixiff.ch
2026-01-23 05:07
HTTP/1.1 200 OK date: Fri, 23 Jan 2026 05:07:31 GMT server: Apache vary: Accept-Encoding,Cookie cache-control: max-age=3, must-revalidate strict-transport-security: max-age=16000000 upgrade: h2 connection: Upgrade transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:443 · www.prixiff.ch
2026-01-23 02:17
HTTP/1.1 301 Moved Permanently date: Fri, 23 Jan 2026 02:17:07 GMT server: Apache vary: Accept-Encoding,Cookie x-redirect-by: WordPress strict-transport-security: max-age=16000000 upgrade: h2 connection: Upgrade location: https://prixiff.ch/ transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:80 · www.prixiff.ch
2026-01-22 23:33
HTTP/1.1 301 Moved Permanently date: Thu, 22 Jan 2026 23:33:02 GMT server: Apache vary: Accept-Encoding,Cookie x-redirect-by: WordPress upgrade: h2 connection: Upgrade location: https://prixiff.ch/ transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:80 · voting.prixiff.ch
2026-01-22 23:31
HTTP/1.1 200 OK
date: Thu, 22 Jan 2026 23:31:11 GMT
server: Apache
upgrade: h2
connection: Upgrade
last-modified: Wed, 06 Nov 2024 18:24:49 GMT
etag: "41d12-62642a213ff04"
accept-ranges: bytes
content-length: 269586
vary: Accept-Encoding
content-type: text/html
<!DOCTYPE html><html data-capo=""><head><meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<style id="nuxt-ui-colors">:root {
--color-primary-50: 240 253 244;
--color-primary-100: 220 252 231;
--color-primary-200: 187 247 208;
--color-primary-300: 134 239 172;
--color-primary-400: 74 222 128;
--color-primary-500: 34 197 94;
--color-primary-600: 22 163 74;
--color-primary-700: 21 128 61;
--color-primary-800: 22 101 52;
--color-primary-900: 20 83 45;
--color-primary-950: 5 46 22;
--color-primary-DEFAULT: var(--color-primary-500);
--color-gray-50: 249 250 251;
--color-gray-100: 243 244 246;
--color-gray-200: 229 231 235;
--color-gray-300: 209 213 219;
--color-gray-400: 156 163 175;
--color-gray-500: 107 114 128;
--color-gray-600: 75 85 99;
--color-gray-700: 55 65 81;
--color-gray-800: 31 41 55;
--color-gray-900: 17 24 39;
--color-gray-950: 3 7 18;
}
.dark {
--color-primary-DEFAULT: var(--color-primary-400);
}
</style>
<style>/*! tailwindcss v3.4.4 | MIT License | https://tailwindcss.com*/*,:after,:before{border-color:rgb(var(--color-gray-200)/1);border-style:solid;border-width:0;box-sizing:border-box}:after,:before{--tw-content:""}:host,html{line-height:1.5;-webkit-text-size-adjust:100%;font-family:ui-sans-serif,system-ui,sans-serif,Apple Color Emoji,Segoe UI Emoji,Segoe UI Symbol,Noto Color Emoji;font-feature-settings:normal;font-variation-settings:normal;tab-size:4;-webkit-tap-highlight-color:transparent}body{line-height:inherit;margin:0}hr{border-top-width:1px;color:inherit;height:0}abbr:where([title]){-webkit-text-decoration:underline dotted;text-decoration:underline dotted}h1,h2,h3,h4,h5,h6{font-size:inherit;font-weight:inherit}a{color:inherit;text-decoration:inherit}b,strong{font-weight:bolder}code,kbd,pre,samp{font-family:ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,Liberation Mono,Courier New,monospace;font-feature-settings:normal;font-size:1em;font-variation-settings:normal}small{font-size:80%}sub,sup{font-size:75%;line-height:0;position:relative;vertical-align:initial}sub{bottom:-.25em}sup{top:-.5em}table{border-collapse:collapse;border-color:inherit;text-indent:0}button,input,optgroup,select,textarea{color:inherit;font-family:inherit;font-feature-settings:inherit;font-size:100%;font-variation-settings:inherit;font-weight:inherit;letter-spacing:inherit;line-height:inherit;margin:0;padding:0}button,select{text-transform:none}button,input:where([type=button]),input:where([type=reset]),input:where([type=submit]){-webkit-appearance:button;background-color:initial;background-image:none}:-moz-focusring{outline:auto}:-moz-ui-invalid{box-shadow:none}progress{vertical-align:initial}::-webkit-inner-spin-button,::-webkit-outer-spin-button{height:auto}[type=search]{-webkit-appearance:textfield;outline-offset:-2px}::-webkit-search-decoration{-webkit-appearance:none}::-webkit-file-upload-button{-webkit-appearance:button;font:inherit}summary{display:list-item}blockquote,dd,dl,figure,h1,h2,h3,h4,h5,h6,hr,p,pre{margin:0}fieldset{margin:0}fieldset,legend{padding:0}menu,ol,ul{list-style:none;margin:0;padding:0}dialog{padding:0}textarea{resize:vertical}input::placeholder,textarea::placeholder{color:rgb(var(--color-gray-400)/1);opacity:1}[role=button],button{cursor:pointer}:disabled{cursor:default}audio,canvas,embed,iframe,img,object,svg,video{display:block;vertical-align:middle}img,video{height:auto;max-width:100%}[hidden]{display:none}*,::backdrop,:after,:before{--tw-border-spacing-x:0;--tw-border-spacing-y:0;--tw-translate-x:0;--tw-translate-y:0;--tw-rotate:0;--tw-skew-x:0;--tw-skew-y:0;--tw-scale-x:1;--tw-scale-y:1;--tw-pan-x: ;--tw-pan-y: ;--tw-pinch-zoom: ;--tw-scroll-snap-strictness:proximity;--tw-gradient-from-position: ;--tw-gradient-via-position: ;--tw-gradient-to-position: ;--tw-ordinal: ;--tw-slashed-zero: ;--tw-numeric-figure: ;--tw-numeric-spacing: ;--tw-numeric-fraction: ;--tw-ring-inset: ;--tw-ring-offset-width:0px;--tw-ring-offset-color:#fff;--tw-ring-color:#3b82f680;--tw-ring-offset-shadow:0 0 #0000;--tw-ring-shadow:0 0 #0000;--tw-shadow:0 0 #0000;--tw-shadow-colored
Open service 83.166.138.100:443 · voting-api.prixiff.ch
2026-01-22 18:48
HTTP/1.1 200 OK date: Thu, 22 Jan 2026 18:48:28 GMT server: Apache cache-control: no-cache, private set-cookie: XSRF-TOKEN=eyJpdiI6IkorR0dSYXVDbHhrUWRWSWNkUW9xSEE9PSIsInZhbHVlIjoic1Qzam1NV3hjdGttOXo1cDhzN2tSQjdkNGk2ZVZOK0RCZVF2aVEzNjVhdllPZm9DUFhCelVaMmtCa1FtVEw2dW8zWU5sTjU3UitGQjc0MXE2N3V1bTdVTlVrUFY3YWZkWlFvczBJV3A2cU1BSVFRblpETWkxOUx2dVhBNWN1VVAiLCJtYWMiOiI1MTVhZWY4NTgzNDBjNGFhOTdjYzIzMDkzM2I5OGY2OWQxMjA5ODhhYmExYmU5ZDE1OThmYWJmZmY5NGEzZjcxIiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 20:48:28 GMT; Max-Age=7200; path=/; secure; samesite=lax set-cookie: laravel_session=eyJpdiI6Ilpqc0FNbUs2Y015K3d0SE1WTVZrZWc9PSIsInZhbHVlIjoiL1p1bzFBdnhMZi82a3FCSTFHTkZDV29KZ0ZRdjhEVUxZV3BKZmNmd3A2cTB5VCsxcnhDNkZZUkR2TW5vT0tYSmRUSWEwRlRZOTRMVFQraEplbTVHWU1hdG1RbDJXeEdUSUdtMTllUllDbGwzbC9nSGFuRVplL0JIeGVaQVNkWEQiLCJtYWMiOiJjZTEzZTkyMTI4ZDNhODNhNGE2ODM5NjU5MWQ2ZGMzYjg3YzcwNjY4OGFlMTQxNDNkNGZhZDc2OTc3YzVlZTU1IiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 20:48:28 GMT; Max-Age=7200; path=/; httponly; samesite=lax strict-transport-security: max-age=16000000 upgrade: h2 connection: Upgrade vary: Accept-Encoding transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 2001:1600:4:13:1a66:daff:feaf:fceb:443 · voting-api.prixiff.ch
2026-01-22 02:48
HTTP/1.1 200 OK date: Thu, 22 Jan 2026 02:48:15 GMT server: Apache cache-control: no-cache, private set-cookie: XSRF-TOKEN=eyJpdiI6IkdPZGRLZXVHMy9pbXdPaTZDd25XN1E9PSIsInZhbHVlIjoiMk03emc1R2ZxMTBIVDFCUG5sZzJhZi9icmR2RkdPcjJXeXVFS3JOSSthdkczWlhKcGozOUlMaDB0MkwxbWdwTVpCbXZCUEpmbEorNHhZTnBzekpsUSsxZ0NReTZweDk2blN2OU9JTlE0V1I2bENWTGV4M1lZdktWU1M0eWdqdzAiLCJtYWMiOiJiZTk5NjdlNjg1NjE0MzBmZjk4ZDM1OGUxZGQzZTA3MWNiYzc1MjJhNDYyZTdhMWQ2YmZmMGE5M2FkYzIwZmQ3IiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 04:48:15 GMT; Max-Age=7200; path=/; secure; samesite=lax set-cookie: laravel_session=eyJpdiI6IllSbDdSYmNUcDlwRDR3cHRTbjlXUnc9PSIsInZhbHVlIjoibjJDUHZxdEhxZWJjYkZPR09MekdwR2dieHhIT0hDUEdKcS9YUFFUUklWc3Bsd0pnOGFwbDZYeVhWK1FWZFA0aDFyTVJUZm9sNkNXV1FEaURnRlpaWEwyTzQ4VHhoOHp6QUpULzdxamdZckd6Nml3UHdPSFhWRWZhM1haMGMwOTEiLCJtYWMiOiJkMmJkNWEzOGIwNGQ2N2JmYzEzZDNkNTc1MTVhNThlNTNhYzg0M2E1MDI1NmVkMjNkZDQ3NmNlN2UzNjA2YjFiIiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 04:48:15 GMT; Max-Age=7200; path=/; httponly; samesite=lax strict-transport-security: max-age=16000000 upgrade: h2 connection: Upgrade vary: Accept-Encoding transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:80 · voting-api.prixiff.ch
2026-01-22 02:48
HTTP/1.1 200 OK date: Thu, 22 Jan 2026 02:48:15 GMT server: Apache cache-control: no-cache, private set-cookie: XSRF-TOKEN=eyJpdiI6ImE2T243ZmV1ZlRzWVRUQlJTbFZSRHc9PSIsInZhbHVlIjoiQVFyR09qWmZDS0lVU3p6cVFyc25UMkZYOGtBMWJhTDgySGxIRlBjVEJPTnFIbkpmWDB4MGlkMThmRWFEcHlpbXN6VWM2cWR5ZUtoQ1E2djJ6VVNsM1dMUDc3Q3NVblR6TzU1NzNOZHFFQ3RBRVNuQVV0cU56WlNvYlh3ZURNakkiLCJtYWMiOiIwNTVkMDcwM2RiOTEwYzZhODFiNTU4ZDhlNDMyNDRhMzcyNzBmOGIxNGU2MTAzMWRlOThhYmQ5MjdmMTFlOTU4IiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 04:48:15 GMT; Max-Age=7200; path=/; samesite=lax set-cookie: laravel_session=eyJpdiI6IlIvRHJ2RWI2RXgzUFgvK09VdldyM0E9PSIsInZhbHVlIjoib0k4VnVad1IxajJGK1cvOUh0U1M5NjBQQkU3bDhsWVpsajZLMWRiaW5OSWNUaFhDc3NLR1B6QjFTR2hPb2kxOFh6ZlFSS21oNTl1N0RCSE9xTlJwWGtTdFEvMEhROTJ1OWlCeDd0UDFsbkZnZ3VjVWxoOGxkOWEyZlJKeng1dzIiLCJtYWMiOiJkMGYwYWQzOWJiYjY1YTJjNmYyMjRiYzMxNWEyNWQ5OGM1ZGY4ZGY4MTYzZDE4YTE2MGUzY2YzZjk4ZDIzZTJkIiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 04:48:15 GMT; Max-Age=7200; path=/; httponly; samesite=lax upgrade: h2 connection: Upgrade vary: Accept-Encoding transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 2001:1600:4:13:1a66:daff:feaf:fceb:80 · voting-api.prixiff.ch
2026-01-22 02:48
HTTP/1.1 200 OK date: Thu, 22 Jan 2026 02:48:14 GMT server: Apache cache-control: no-cache, private set-cookie: XSRF-TOKEN=eyJpdiI6InFTMElQT3h3a01nVkszLzNUcXVDbUE9PSIsInZhbHVlIjoidC9TRmw4ckF1M3JyR3Zid2JTTXhYYzkvSENvTjRyclVVakJKeHM4dmkyckdZUDJ1OGtJYmRBSkRXZXdsMTR2ZXRNaXU2QURndElQbzh2Rk9YMTBxSE1PajJtczZTYnNJams4Z0dvT2tBelFHUmVjQ0pzT3hyT0htZ2NHREEzQnEiLCJtYWMiOiJhMzVlMDlhNzUwMzM4MzJmOTAwNGY0ZDg0MTkxMzE1YTk5MmQ3ZmQxMjhhODU5NGNkMjJmY2EzYjljYWZiMWVlIiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 04:48:14 GMT; Max-Age=7200; path=/; samesite=lax set-cookie: laravel_session=eyJpdiI6Iml0YUZvN2pqb3RiUW1oVUVIaWw3amc9PSIsInZhbHVlIjoidjhUQVhhUmNpRDhkaEZBV2RlRDhYbWtlYjdoQldBYzFoK01peDFQZE01RFhUY2hFS3dEcmtocFFjN1N3RjQ4ZVcrNkk1TFZxQWUvY2lGYjFnUVhZTTFuTzJmaTExWGx3L010eGdLZ3JaY2tRTVB1RXUwVE1BREtoeTBiZG5wd2wiLCJtYWMiOiIxNjk5MGI3NGFiMjFiOWM5NjlhYTNjM2NkYTllNTJjNjZmNmYzMTcwYzk1MDZlYTY0NGI1NzIwYmU1NzBhMjEyIiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 04:48:14 GMT; Max-Age=7200; path=/; httponly; samesite=lax upgrade: h2 connection: Upgrade vary: Accept-Encoding transfer-encoding: chunked content-type: text/html; charset=UTF-8
Open service 83.166.138.100:443 · maintenance.prixiff.ch
2026-01-10 01:05
HTTP/1.1 301 Moved Permanently date: Sat, 10 Jan 2026 01:05:53 GMT server: Apache vary: Accept-Encoding,Cookie x-redirect-by: WordPress strict-transport-security: max-age=16000000 upgrade: h2 connection: Upgrade location: https://prixiff.ch/ transfer-encoding: chunked content-type: text/html; charset=UTF-8