Vercel
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c11d3744d11d3744dfdb1c82af17f7726b4bc5accc53ede29
Found 12 files trough .DS_Store spidering: /icons /platform-assets /platform-assets/ehr /platform-assets/ehr/icons /platform-assets/exercise /platform-assets/exercise/icons /platform-assets/formbuilder /platform-assets/formbuilder/icons /platform-assets/prescription /platform-assets/prescription/icons /platform-assets/rehab /platform-assets/rehab/icons
Open service 216.150.1.1:443 · program.rehabprescribed.com
2026-01-09 16:16
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Age: 402689
Cache-Control: public, max-age=0, must-revalidate
Content-Disposition: inline
Content-Length: 1401
Content-Security-Policy: default-src 'self' blob: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://meet.prismehr.com https://cdn.withpersona.com https://cdn.auth0.com https://cdnjs.cloudflare.com https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; media-src 'self' blob: mediastream: data: https://meet.prismehr.com; connect-src 'self' https://api.stripe.com https://meet.prismehr.com wss://meet.prismehr.com https://*.facetec.com https://*.auth0.com https://test-api.rehabilitationhealth.com https://api.rehabilitationhealth.com https://withpersona.com https://*.withpersona.com https://*.sentry.io https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; worker-src 'self' blob:; frame-src 'self' https://js.stripe.com https://meet.prismehr.com https://*.auth0.com https://withpersona.com https://*.withpersona.com https://*.vouched.id; font-src 'self' data:;
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 16:16:11 GMT
Etag: "26da245c580279b12d7b4e00b0ec2dc5"
Last-Modified: Mon, 05 Jan 2026 00:24:41 GMT
Permissions-Policy: camera=(self "https://meet.prismehr.com" "https://*.facetec.com" "https://*.withpersona.com" "https://*.vouched.id"), microphone=(self "https://meet.prismehr.com"), display-capture=(self "https://meet.prismehr.com"), geolocation=(), accelerometer=(self), autoplay=(self), encrypted-media=(self), gyroscope=(self), magnetometer=(self)
Referrer-Policy: strict-origin-when-cross-origin
Server: Vercel
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Vercel-Cache: HIT
X-Vercel-Id: iad1::nm54h-1767975371109-efde4da91785
X-Xss-Protection: 1; mode=block
Connection: close
Page title: eRx Mobile
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="theme-color" content="#ffffff" />
<meta name="description" content="Electronic prescription mobile application for healthcare providers" />
<!-- PWA related links -->
<link rel="manifest" href="/manifest.json" />
<link rel="icon" type="image/png" href="/icons/icon-192x192.png" />
<link rel="apple-touch-icon" href="/icons/icon-192x192.png" />
<!-- iOS specific meta tags -->
<meta name="apple-mobile-web-app-capable" content="yes" />
<meta name="apple-mobile-web-app-status-bar-style" content="default" />
<meta name="apple-mobile-web-app-title" content="eRx Mobile" />
<title>eRx Mobile</title>
<!-- Load FaceTec SDK before React app - CRITICAL for FaceTec integration -->
<script type="text/javascript" src="/core-sdk/FaceTecSDK.js/FaceTecSDK.js"></script>
<script type="module" crossorigin src="/assets/index-DhulvI58.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-oKCHKb5P.css">
<link rel="manifest" href="/manifest.webmanifest"><script id="vite-plugin-pwa:register-sw" src="/registerSW.js"></script></head>
<body>
<div id="root"></div>
<noscript>You need to enable JavaScript to run this app.</noscript>
</body>
</html>
Open service 216.150.1.1:443 · program.rehabprescribed.com
2026-01-02 06:12
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Disposition: inline
Content-Length: 1401
Content-Security-Policy: default-src 'self' blob: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://meet.prismehr.com https://cdn.withpersona.com https://cdn.auth0.com https://cdnjs.cloudflare.com https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; media-src 'self' blob: mediastream: data: https://meet.prismehr.com; connect-src 'self' https://api.stripe.com https://meet.prismehr.com wss://meet.prismehr.com https://*.facetec.com https://*.auth0.com https://test-api.rehabilitationhealth.com https://api.rehabilitationhealth.com https://withpersona.com https://*.withpersona.com https://*.sentry.io https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; worker-src 'self' blob:; frame-src 'self' https://js.stripe.com https://meet.prismehr.com https://*.auth0.com https://withpersona.com https://*.withpersona.com https://*.vouched.id; font-src 'self' data:;
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 06:12:28 GMT
Etag: "374ad8d0122e311dc1cb3167e20fd492"
Last-Modified: Fri, 02 Jan 2026 06:12:27 GMT
Permissions-Policy: camera=(self "https://meet.prismehr.com" "https://*.facetec.com" "https://*.withpersona.com" "https://*.vouched.id"), microphone=(self "https://meet.prismehr.com"), display-capture=(self "https://meet.prismehr.com"), geolocation=(), accelerometer=(self), autoplay=(self), encrypted-media=(self), gyroscope=(self), magnetometer=(self)
Referrer-Policy: strict-origin-when-cross-origin
Server: Vercel
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Vercel-Cache: HIT
X-Vercel-Id: fra1::ttkmz-1767334347975-3c0d81f88fd4
X-Xss-Protection: 1; mode=block
Connection: close
Page title: eRx Mobile
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="theme-color" content="#ffffff" />
<meta name="description" content="Electronic prescription mobile application for healthcare providers" />
<!-- PWA related links -->
<link rel="manifest" href="/manifest.json" />
<link rel="icon" type="image/png" href="/icons/icon-192x192.png" />
<link rel="apple-touch-icon" href="/icons/icon-192x192.png" />
<!-- iOS specific meta tags -->
<meta name="apple-mobile-web-app-capable" content="yes" />
<meta name="apple-mobile-web-app-status-bar-style" content="default" />
<meta name="apple-mobile-web-app-title" content="eRx Mobile" />
<title>eRx Mobile</title>
<!-- Load FaceTec SDK before React app - CRITICAL for FaceTec integration -->
<script type="text/javascript" src="/core-sdk/FaceTecSDK.js/FaceTecSDK.js"></script>
<script type="module" crossorigin src="/assets/index-C5YAphgg.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-oKCHKb5P.css">
<link rel="manifest" href="/manifest.webmanifest"><script id="vite-plugin-pwa:register-sw" src="/registerSW.js"></script></head>
<body>
<div id="root"></div>
<noscript>You need to enable JavaScript to run this app.</noscript>
</body>
</html>
Open service 216.150.1.1:443 · program.rehabprescribed.com
2025-12-22 13:54
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Disposition: inline
Content-Length: 1401
Content-Security-Policy: default-src 'self' blob: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://meet.prismehr.com https://cdn.withpersona.com https://cdn.auth0.com https://cdnjs.cloudflare.com https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; media-src 'self' blob: mediastream: data: https://meet.prismehr.com; connect-src 'self' https://api.stripe.com https://meet.prismehr.com wss://meet.prismehr.com https://*.facetec.com https://*.auth0.com https://test-api.rehabilitationhealth.com https://api.rehabilitationhealth.com https://withpersona.com https://*.withpersona.com https://*.sentry.io https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; worker-src 'self' blob:; frame-src 'self' https://js.stripe.com https://meet.prismehr.com https://*.auth0.com https://withpersona.com https://*.withpersona.com https://*.vouched.id; font-src 'self' data:;
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 13:54:56 GMT
Etag: "84554880eefc1a4f8c039d28c0c9cd8b"
Last-Modified: Mon, 22 Dec 2025 13:54:56 GMT
Permissions-Policy: camera=(self "https://meet.prismehr.com" "https://*.facetec.com" "https://*.withpersona.com" "https://*.vouched.id"), microphone=(self "https://meet.prismehr.com"), display-capture=(self "https://meet.prismehr.com"), geolocation=(), accelerometer=(self), autoplay=(self), encrypted-media=(self), gyroscope=(self), magnetometer=(self)
Referrer-Policy: strict-origin-when-cross-origin
Server: Vercel
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Vercel-Cache: HIT
X-Vercel-Id: fra1::k2r6d-1766411696770-c8df9c3c0e25
X-Xss-Protection: 1; mode=block
Connection: close
Page title: eRx Mobile
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="theme-color" content="#ffffff" />
<meta name="description" content="Electronic prescription mobile application for healthcare providers" />
<!-- PWA related links -->
<link rel="manifest" href="/manifest.json" />
<link rel="icon" type="image/png" href="/icons/icon-192x192.png" />
<link rel="apple-touch-icon" href="/icons/icon-192x192.png" />
<!-- iOS specific meta tags -->
<meta name="apple-mobile-web-app-capable" content="yes" />
<meta name="apple-mobile-web-app-status-bar-style" content="default" />
<meta name="apple-mobile-web-app-title" content="eRx Mobile" />
<title>eRx Mobile</title>
<!-- Load FaceTec SDK before React app - CRITICAL for FaceTec integration -->
<script type="text/javascript" src="/core-sdk/FaceTecSDK.js/FaceTecSDK.js"></script>
<script type="module" crossorigin src="/assets/index-DWPiHTtH.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-oKCHKb5P.css">
<link rel="manifest" href="/manifest.webmanifest"><script id="vite-plugin-pwa:register-sw" src="/registerSW.js"></script></head>
<body>
<div id="root"></div>
<noscript>You need to enable JavaScript to run this app.</noscript>
</body>
</html>
Open service 216.150.1.1:443 · program.rehabprescribed.com
2025-12-20 13:57
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Disposition: inline
Content-Length: 1401
Content-Security-Policy: default-src 'self' blob: data:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.stripe.com https://meet.prismehr.com https://cdn.withpersona.com https://cdn.auth0.com https://cdnjs.cloudflare.com https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; media-src 'self' blob: mediastream: data: https://meet.prismehr.com; connect-src 'self' https://api.stripe.com https://meet.prismehr.com wss://meet.prismehr.com https://*.facetec.com https://*.auth0.com https://test-api.rehabilitationhealth.com https://api.rehabilitationhealth.com https://withpersona.com https://*.withpersona.com https://*.sentry.io https://*.amplitude.com https://*.lab.amplitude.com https://*.jsdelivr.net https://*.vouched.id https://*.googleapis.com https://*.fontawesome.com https://*.gstatic.com https://*.browser-intake-datadoghq.com; worker-src 'self' blob:; frame-src 'self' https://js.stripe.com https://meet.prismehr.com https://*.auth0.com https://withpersona.com https://*.withpersona.com https://*.vouched.id; font-src 'self' data:;
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 13:57:29 GMT
Etag: "84554880eefc1a4f8c039d28c0c9cd8b"
Last-Modified: Sat, 20 Dec 2025 13:57:29 GMT
Permissions-Policy: camera=(self "https://meet.prismehr.com" "https://*.facetec.com" "https://*.withpersona.com" "https://*.vouched.id"), microphone=(self "https://meet.prismehr.com"), display-capture=(self "https://meet.prismehr.com"), geolocation=(), accelerometer=(self), autoplay=(self), encrypted-media=(self), gyroscope=(self), magnetometer=(self)
Referrer-Policy: strict-origin-when-cross-origin
Server: Vercel
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Vercel-Cache: HIT
X-Vercel-Id: sin1::kj8dd-1766239049686-7b0ad1b1072a
X-Xss-Protection: 1; mode=block
Connection: close
Page title: eRx Mobile
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<meta name="theme-color" content="#ffffff" />
<meta name="description" content="Electronic prescription mobile application for healthcare providers" />
<!-- PWA related links -->
<link rel="manifest" href="/manifest.json" />
<link rel="icon" type="image/png" href="/icons/icon-192x192.png" />
<link rel="apple-touch-icon" href="/icons/icon-192x192.png" />
<!-- iOS specific meta tags -->
<meta name="apple-mobile-web-app-capable" content="yes" />
<meta name="apple-mobile-web-app-status-bar-style" content="default" />
<meta name="apple-mobile-web-app-title" content="eRx Mobile" />
<title>eRx Mobile</title>
<!-- Load FaceTec SDK before React app - CRITICAL for FaceTec integration -->
<script type="text/javascript" src="/core-sdk/FaceTecSDK.js/FaceTecSDK.js"></script>
<script type="module" crossorigin src="/assets/index-DWPiHTtH.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-oKCHKb5P.css">
<link rel="manifest" href="/manifest.webmanifest"><script id="vite-plugin-pwa:register-sw" src="/registerSW.js"></script></head>
<body>
<div id="root"></div>
<noscript>You need to enable JavaScript to run this app.</noscript>
</body>
</html>