nginx 1.22.1
tcp/443 tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbd94c5f4f
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://github.com/Raphael-Jesus-11/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "pix"] remote = origin merge = refs/heads/pix [branch "black-promotion"] remote = origin merge = refs/heads/black-promotion [branch "subscription-popup"] remote = origin merge = refs/heads/subscription-popup [branch "blog"] remote = origin merge = refs/heads/blog
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbb4cedfcbd
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://github.com/Raphael-Jesus-11/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "pix"] remote = origin merge = refs/heads/pix [branch "black-promotion"] remote = origin merge = refs/heads/black-promotion
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbb7b00c332
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://github.com/Raphael-Jesus-11/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "pix"] remote = origin merge = refs/heads/pix
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbb3160dd1b
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://github.com/Raphael-Jesus-11/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652263260998
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:GembaGroup/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "validacao_email"] remote = origin merge = refs/heads/validacao_email [branch "hotfix"] remote = origin merge = refs/heads/hotfix [branch "validacao_ddd"] remote = origin merge = refs/heads/validacao_ddd [branch "jwplayerAPI"] remote = origin merge = refs/heads/jwplayerAPI [branch "new_checkout"] remote = origin merge = refs/heads/new_checkout [branch "custom_combos"] vscode-merge-base = origin/new_checkout [branch "session_orders"] remote = origin merge = refs/heads/session_orders [branch "session_expiring_handle"] remote = origin merge = refs/heads/session_expiring_handle
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d03b70f6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:GembaGroup/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "validacao_email"] remote = origin merge = refs/heads/validacao_email [branch "hotfix"] remote = origin merge = refs/heads/hotfix [branch "validacao_ddd"] remote = origin merge = refs/heads/validacao_ddd [branch "jwplayerAPI"] remote = origin merge = refs/heads/jwplayerAPI [branch "new_checkout"] remote = origin merge = refs/heads/new_checkout [branch "custom_combos"] vscode-merge-base = origin/new_checkout
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65220d135dd0
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:GembaGroup/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "validacao_email"] remote = origin merge = refs/heads/validacao_email [branch "hotfix"] remote = origin merge = refs/heads/hotfix [branch "validacao_ddd"] remote = origin merge = refs/heads/validacao_ddd [branch "jwplayerAPI"] remote = origin merge = refs/heads/jwplayerAPI [branch "new_checkout"] remote = origin merge = refs/heads/new_checkout
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652271e1c83e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:GembaGroup/Produzzi.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main [branch "validacao_email"] remote = origin merge = refs/heads/validacao_email [branch "hotfix"] remote = origin merge = refs/heads/hotfix [branch "validacao_ddd"] remote = origin merge = refs/heads/validacao_ddd
Open service 177.101.158.79:80 · produzzi.com
2026-01-08 12:47
HTTP/1.1 301 Moved Permanently Server: nginx/1.22.1 Date: Thu, 08 Jan 2026 12:47:06 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://produzzi.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.22.1</center> </body> </html>
Open service 177.101.158.79:443 · produzzi.com
2026-01-08 12:47
HTTP/1.1 200 OK Server: nginx/1.22.1 Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache, private Date: Thu, 08 Jan 2026 12:47:06 GMT Set-Cookie: XSRF-TOKEN=eyJpdiI6Ijd4SkRIMEQyb05mNkZZMUpQOFlNUEE9PSIsInZhbHVlIjoibGptM2l4Nzkyc1I4cjJlNlRJVnFVSWoyY0JDbU1QVVI2SkZkOE5ieUxhZmNhaHRzTy9tMHFjUGY4S1laTW94NTdyS08yeWh2TFZTd3VaZkFGeEM1VUNaejhDbkVMbklnenRmYjBXYUZYYi9ObDhIdGhEZHNiZXZJdnZXd0J3OG8iLCJtYWMiOiJhNmI4NTJmZmYxNTlkNDlkMDM3N2QxNmFhMTgwYjk3NzRmNWM5ODU5ZmE3NjVkMWI4ZjY3M2E5Yjg4ZmJkOGZjIn0%3D; expires=Thu, 08-Jan-2026 14:47:06 GMT; Max-Age=7200; path=/ Set-Cookie: produzzi_session=eyJpdiI6InVoY05PZ0tiUW1nNEczd3RYdHBzRGc9PSIsInZhbHVlIjoicTl1anpUUndGQnErM3RwT0wwWWFoY2lMa1d5a0ViVjBNZnRpQi83Wm9KOXhYbE4yQkw1TTdONjRaZzNnWjlYYmJHWUlwUEJGQUhOeWFXY05IdzdKVThMU1VHODJhWnFuRUZOMWNVbFB1M3FVRlNTYUhDZ0M0WFcxckQ5Sy9IazEiLCJtYWMiOiI1MmRjMWI3ZDFkNGUxNjlmOGJiZTBhNzkwYjRjMGIzZWFlZWRkMzIxZTA5M2FjODZjOTViNjU0NzRmMTlkY2MxIn0%3D; expires=Thu, 08-Jan-2026 14:47:06 GMT; Max-Age=7200; path=/; httponly
Open service 177.101.158.79:80 · phpmyadmin.produzzi.com
2026-01-08 12:46
HTTP/1.1 301 Moved Permanently Server: nginx/1.22.1 Date: Thu, 08 Jan 2026 12:46:04 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://phpmyadmin.produzzi.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.22.1</center> </body> </html>
Open service 177.101.158.79:443 · phpmyadmin.produzzi.com
2026-01-08 12:46
HTTP/1.1 200 OK
Server: nginx/1.22.1
Date: Thu, 08 Jan 2026 12:46:04 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Set-Cookie: pma_lang_https=en; expires=Sat, 07 Feb 2026 12:46:04 GMT; Max-Age=2592000; path=/; secure; HttpOnly; SameSite=Strict
Set-Cookie: phpMyAdmin_https=ho95h3id4jc53stq9v3qpmlhr3; path=/; secure; HttpOnly; SameSite=Strict
X-ob_mode: 1
X-Frame-Options: DENY
Referrer-Policy: no-referrer
Content-Security-Policy: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval' ;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none';
X-Content-Security-Policy: default-src 'self' ;options inline-script eval-script;referrer no-referrer;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none';
X-WebKit-CSP: default-src 'self' ;script-src 'self' 'unsafe-inline' 'unsafe-eval';referrer no-referrer;style-src 'self' 'unsafe-inline' ;img-src 'self' data: *.tile.openstreetmap.org;object-src 'none';
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
X-Permitted-Cross-Domain-Policies: none
X-Robots-Tag: noindex, nofollow
Expires: Thu, 08 Jan 2026 12:46:04 +0000
Cache-Control: no-store, no-cache, must-revalidate, pre-check=0, post-check=0, max-age=0
Pragma: no-cache
Last-Modified: Thu, 08 Jan 2026 12:46:04 +0000
Vary: Accept-Encoding
Page title: phpMyAdmin
<!doctype html>
<html lang="en" dir="ltr">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="referrer" content="no-referrer">
<meta name="robots" content="noindex,nofollow,notranslate">
<meta name="google" content="notranslate">
<style id="cfs-style">html{display: none;}</style>
<link rel="icon" href="favicon.ico" type="image/x-icon">
<link rel="shortcut icon" href="favicon.ico" type="image/x-icon">
<link rel="stylesheet" type="text/css" href="./themes/pmahomme/jquery/jquery-ui.css">
<link rel="stylesheet" type="text/css" href="js/vendor/codemirror/lib/codemirror.css?v=5.2.1deb1">
<link rel="stylesheet" type="text/css" href="js/vendor/codemirror/addon/hint/show-hint.css?v=5.2.1deb1">
<link rel="stylesheet" type="text/css" href="js/vendor/codemirror/addon/lint/lint.css?v=5.2.1deb1">
<link rel="stylesheet" type="text/css" href="./themes/pmahomme/css/theme.css?v=5.2.1deb1">
<title>phpMyAdmin</title>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.min.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery-migrate.min.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/sprintf.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/ajax.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/keyhandler.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery-ui.min.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/name-conflict-fixes.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/bootstrap/bootstrap.bundle.min.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/js.cookie.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.validate.min.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery-ui-timepicker-addon.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/jquery/jquery.debounce-1.0.6.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/menu_resizer.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/cross_framing_protection.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/messages.php?l=en&v=5.2.1deb1&lang=en"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/config.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/doclinks.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/functions.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/navigation.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/indexes.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/common.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/dist/page_settings.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/codemirror/lib/codemirror.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/codemirror/mode/sql/sql.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/codemirror/addon/runmode/runmode.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/codemirror/addon/hint/show-hint.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javascript" src="js/vendor/codemirror/addon/hint/sql-hint.js?v=5.2.1deb1"></script>
<script data-cfasync="false" type="text/javasc
Open service 177.101.158.79:443 · admin.produzzi.com
2026-01-08 12:35
HTTP/1.1 302 Found
Server: nginx/1.22.1
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache, private
Date: Thu, 08 Jan 2026 12:35:46 GMT
Location: https://admin.produzzi.com/login
Set-Cookie: XSRF-TOKEN=eyJpdiI6IlFJZ2JOQXh4cEl3TWpmcDVRUmJwc3c9PSIsInZhbHVlIjoiSlQvaDI2RkNjTmlaaUE5UjFGV2VoQXFSblZDb2F3b3IrelQ3T25IbW4rL0xLVy9yK29ScE55Q3lpSU44c2JDeW9iN3UyYTN0bVRDVUNqNkZ2T3g5a2x0OW1mbmU2aUE2c3BKeGNkRXZ0MUhPQzNxNHcvN09XcjRWK0ZqOVhVT1UiLCJtYWMiOiI2MjY4YzFkMjM1ZGQxMzJkMjI5NDJmNzQyMjYzN2FjNWNmYTI1M2IwNWQ3MWU5MjdkZGExMzA4MjJkZjhmNDJjIiwidGFnIjoiIn0%3D; expires=Thu, 08 Jan 2026 14:35:46 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6IktKVllwN29zL3FObGlzdnIrUmw2SlE9PSIsInZhbHVlIjoiQm5mU0NQZ2tUL01rMVVaZjBJZitiQXdVSnMzOWRWam9ka2lxcVlVc1lMQmpyQjRmNWVFM0dOMzdFRU9VWFFVSGRuVjJYRFVuK1N5UHpYdU1NWUVyS214Z3JpaExWRksrRnNZaXFNbWNqcU0yZ1RRVmF5b0hOYTNJZ3NIbmFxNm8iLCJtYWMiOiI5NzljYzJjMzIzNzE2N2IwMjQ3YzNiM2FkNTY4NDI0YzA1OWZlZmQ2ZWZkYzY1YmMwMWJkZjgwOTQ3OWZjMTM5IiwidGFnIjoiIn0%3D; expires=Thu, 08 Jan 2026 14:35:46 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Page title: Redirecting to https://admin.produzzi.com/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://admin.produzzi.com/login'" />
<title>Redirecting to https://admin.produzzi.com/login</title>
</head>
<body>
Redirecting to <a href="https://admin.produzzi.com/login">https://admin.produzzi.com/login</a>.
</body>
</html>
Open service 177.101.158.79:80 · admin.produzzi.com
2026-01-08 12:35
HTTP/1.1 404 Not Found Server: nginx/1.22.1 Date: Thu, 08 Jan 2026 12:35:45 GMT Content-Type: text/html Content-Length: 153 Connection: close Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx/1.22.1</center> </body> </html>