Apache
tcp/443 tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c7cf176427cf17642d9780b80eca74418eca74418eca74418
Found 2 files trough .DS_Store spidering: /core /install
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c7cf176427cf17642d9780b80eca74418eca74418eca74418
Found 2 files trough .DS_Store spidering: /core /install
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09cb7af8d83b7af8d8376c1a193ac0c9970eb5d98bb5ee4d375
Found 87 files trough .DS_Store spidering: /css /css/ajax-loader.gif /css/animate.css /css/bootstrap /css/bootstrap/bootstrap-grid.css /css/bootstrap/bootstrap-reboot.css /css/bootstrap-datepicker.css /css/bootstrap.min.css /css/css /css/css/bootstrap-reboot.css /css/css/mixins /css/flaticon.css /css/jquery.timepicker.css /css/magnific-popup.css /css/owl.carousel.min.css /css/owl.theme.default.min.css /css/style.css /fonts /fonts/flaticon /fonts/flaticon/backup.txt /fonts/flaticon/font /fonts/flaticon/license /images /images/image_1.jpg /images/loc.png /js /js/bootstrap-datepicker.js /js/bootstrap.min.js /js/google-map.js /js/jquery-3.2.1.min.js /js/jquery-migrate-3.0.1.min.js /js/jquery.animateNumber.min.js /js/jquery.easing.1.3.js /js/jquery.magnific-popup.min.js /js/jquery.min.js /js/jquery.stellar.min.js /js/jquery.timepicker.min.js /js/jquery.waypoints.min.js /js/main.js /js/owl.carousel.min.js /js/popper.min.js /js/scrollax.min.js /scss /scss/bootstrap /scss/bootstrap/_alert.scss /scss/bootstrap/_badge.scss /scss/bootstrap/_breadcrumb.scss /scss/bootstrap/_button-group.scss /scss/bootstrap/_buttons.scss /scss/bootstrap/_card.scss /scss/bootstrap/_carousel.scss /scss/bootstrap/_close.scss /scss/bootstrap/_code.scss /scss/bootstrap/_custom-forms.scss /scss/bootstrap/_dropdown.scss /scss/bootstrap/_forms.scss /scss/bootstrap/_functions.scss /scss/bootstrap/_grid.scss /scss/bootstrap/_images.scss /scss/bootstrap/_input-group.scss /scss/bootstrap/_jumbotron.scss /scss/bootstrap/_list-group.scss /scss/bootstrap/_media.scss /scss/bootstrap/_mixins.scss /scss/bootstrap/_modal.scss /scss/bootstrap/_nav.scss /scss/bootstrap/_navbar.scss /scss/bootstrap/_pagination.scss /scss/bootstrap/_popover.scss /scss/bootstrap/_print.scss /scss/bootstrap/_progress.scss /scss/bootstrap/_reboot.scss /scss/bootstrap/_root.scss /scss/bootstrap/_spinners.scss /scss/bootstrap/_tables.scss /scss/bootstrap/_toasts.scss /scss/bootstrap/_tooltip.scss /scss/bootstrap/_transitions.scss /scss/bootstrap/_type.scss /scss/bootstrap/_utilities.scss /scss/bootstrap/_variables.scss /scss/bootstrap/bootstrap-grid.scss /scss/bootstrap/bootstrap-reboot.scss /scss/bootstrap/bootstrap.scss /scss/bootstrap/mixins /scss/bootstrap/utilities /scss/style.scss
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b1ddc323
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = https://github.com/ownaz/bank-1.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main-new [branch "main-new"] remote = origin merge = refs/heads/main-new [branch "fixes/new"] remote = origin merge = refs/heads/fixes/new [branch "deploy"] remote = origin merge = refs/heads/deploy [pull] rebase = true
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b1ddc323
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = https://github.com/ownaz/bank-1.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main-new [branch "main-new"] remote = origin merge = refs/heads/main-new [branch "fixes/new"] remote = origin merge = refs/heads/fixes/new [branch "deploy"] remote = origin merge = refs/heads/deploy [pull] rebase = true
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09cb7af8d83b7af8d8376c1a193ac0c9970eb5d98bb5ee4d375
Found 87 files trough .DS_Store spidering: /css /css/ajax-loader.gif /css/animate.css /css/bootstrap /css/bootstrap/bootstrap-grid.css /css/bootstrap/bootstrap-reboot.css /css/bootstrap-datepicker.css /css/bootstrap.min.css /css/css /css/css/bootstrap-reboot.css /css/css/mixins /css/flaticon.css /css/jquery.timepicker.css /css/magnific-popup.css /css/owl.carousel.min.css /css/owl.theme.default.min.css /css/style.css /fonts /fonts/flaticon /fonts/flaticon/backup.txt /fonts/flaticon/font /fonts/flaticon/license /images /images/image_1.jpg /images/loc.png /js /js/bootstrap-datepicker.js /js/bootstrap.min.js /js/google-map.js /js/jquery-3.2.1.min.js /js/jquery-migrate-3.0.1.min.js /js/jquery.animateNumber.min.js /js/jquery.easing.1.3.js /js/jquery.magnific-popup.min.js /js/jquery.min.js /js/jquery.stellar.min.js /js/jquery.timepicker.min.js /js/jquery.waypoints.min.js /js/main.js /js/owl.carousel.min.js /js/popper.min.js /js/scrollax.min.js /scss /scss/bootstrap /scss/bootstrap/_alert.scss /scss/bootstrap/_badge.scss /scss/bootstrap/_breadcrumb.scss /scss/bootstrap/_button-group.scss /scss/bootstrap/_buttons.scss /scss/bootstrap/_card.scss /scss/bootstrap/_carousel.scss /scss/bootstrap/_close.scss /scss/bootstrap/_code.scss /scss/bootstrap/_custom-forms.scss /scss/bootstrap/_dropdown.scss /scss/bootstrap/_forms.scss /scss/bootstrap/_functions.scss /scss/bootstrap/_grid.scss /scss/bootstrap/_images.scss /scss/bootstrap/_input-group.scss /scss/bootstrap/_jumbotron.scss /scss/bootstrap/_list-group.scss /scss/bootstrap/_media.scss /scss/bootstrap/_mixins.scss /scss/bootstrap/_modal.scss /scss/bootstrap/_nav.scss /scss/bootstrap/_navbar.scss /scss/bootstrap/_pagination.scss /scss/bootstrap/_popover.scss /scss/bootstrap/_print.scss /scss/bootstrap/_progress.scss /scss/bootstrap/_reboot.scss /scss/bootstrap/_root.scss /scss/bootstrap/_spinners.scss /scss/bootstrap/_tables.scss /scss/bootstrap/_toasts.scss /scss/bootstrap/_tooltip.scss /scss/bootstrap/_transitions.scss /scss/bootstrap/_type.scss /scss/bootstrap/_utilities.scss /scss/bootstrap/_variables.scss /scss/bootstrap/bootstrap-grid.scss /scss/bootstrap/bootstrap-reboot.scss /scss/bootstrap/bootstrap.scss /scss/bootstrap/mixins /scss/bootstrap/utilities /scss/style.scss
Open service 207.174.214.35:443 · progresoinvestment.com
2026-01-11 12:59
HTTP/1.1 200 OK Date: Sun, 11 Jan 2026 12:59:51 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6IkMrMmZucUJ0RTZyaE5rbkM4czllZGc9PSIsInZhbHVlIjoiVjN5WS9DdlhqWitaTlpEc0dEYitvK1NEMnpZYzlUeERkdWVkZUs3MjVlUHdOOWVLMGMySDhFdmxHNjlrelFBQWlpbzNVQzg2MlY1bVhGWUVBdzcyL1NQaUlMRWkvcWJKeDFaSXNmYWZETjdTRENScmQvLzYzWTdiMy9mSEdnZkEiLCJtYWMiOiIxNzRmNTQyZjg2NjQ4Yzk1YmJmMzg2YmExMWM3MWRiN2JjMTIxMWQxZDkzZTUxMDA1ZWM0MzhiNWU0MDNkYzNmIiwidGFnIjoiIn0%3D; expires=Sun, 11 Jan 2026 14:59:51 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: laravel_session=eyJpdiI6Ik1idy84QXY2enptQ0E1eXpvSUZYR1E9PSIsInZhbHVlIjoiclc1T2FPbFBxSitieG1RTmw3WWpsckNRYU5HV25YOG9qbmYzME5xaUdLSnNXNjZhRVRDZkhTL0ZzUWNGSldLcFNWd0gvMW1NQU9Za21XeDA4NmtLUlY4Z1FjN3p0SzVHb0pRRThLMHlaTExnYXVwYVBLRklaZnRmTTE5RjRYMnEiLCJtYWMiOiI3NjJkM2M0ZmI4ZTViZTJkZDNiMzQ4ZGQ3OTJjYjM2ZDliNjkwZmE1OGY3NjU4OWNjOTZkZWE1NTk3MGUzOTA2IiwidGFnIjoiIn0%3D; expires=Sun, 11 Jan 2026 14:59:51 GMT; Max-Age=7200; path=/; httponly; samesite=lax Upgrade: h2,h2c Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 207.174.214.35:80 · progresoinvestment.com
2026-01-11 12:59
HTTP/1.1 200 OK Date: Sun, 11 Jan 2026 13:00:09 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6ImliMEFsSTY0M1R3YW9iNDBCMi9EY1E9PSIsInZhbHVlIjoiZFNUaFRxTEhBb2s0UlFTOUluN1NjTXA3UGFBc0hwbHAydHh0MHNZaVpLbzhBUEpFdzd4bG80K05kTVFiWmc2ckxzckdYYWJKVmhWQk5XUGZnbzdIckFUcE1NbExMWGdSTHZ5SE05T3ZTVkxRdVp2eDJiNVN3cS95NVltTVFPNHkiLCJtYWMiOiJjZDI1NGEzMmM1NGE0MWI0OTVhNTc2MDM0MWEyNmNhMTc0OGU4YTg0ZDMzMWU2ZDQzMjMzODU4MDcyOTY0MGRjIiwidGFnIjoiIn0%3D; expires=Sun, 11 Jan 2026 15:00:09 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: laravel_session=eyJpdiI6IjJ6OUd4V0hZbU5saGZHRW1hcE1JbHc9PSIsInZhbHVlIjoiWjhNMFV5YzVHZXNDcm5pVGpJUEF6TlFSUTR5T0JyN0MzWExZNStneDVaSm9mYXg5SHdMcEY0c0x6OVdGU2d5N05XOUViZkJKZldhSGIvRlZzbFZvT2FhekVEMldxU2dyZXh0bjQydWpHTnFGeW9QeitBQjFTWTE3ZTZFcFFnK3kiLCJtYWMiOiIxMjQwNWM2YzgwODQ1ZjZmZjA1MjhiZWY3NzY5ODkyY2U1NTY4YWYxMWE0OWMwYzBjOWQyOTg2OWVmOTgyZGFmIiwidGFnIjoiIn0%3D; expires=Sun, 11 Jan 2026 15:00:09 GMT; Max-Age=7200; path=/; httponly; samesite=lax Upgrade: h2,h2c Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 207.174.214.35:80 · duffsonresources.com.progresoinvestment.com
2025-12-31 12:57
HTTP/1.1 302 Found Date: Wed, 31 Dec 2025 12:57:44 GMT Server: Apache Location: https://duffsonresources.com/ Content-Length: 213 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://duffsonresources.com/">here</a>.</p> </body></html>
Open service 207.174.214.35:443 · duffsonresources.com.progresoinvestment.com
2025-12-31 12:57
HTTP/1.1 200 OK
Date: Wed, 31 Dec 2025 12:57:43 GMT
Server: Apache
Upgrade: h2,h2c
Connection: Upgrade, close
Last-Modified: Sun, 06 Oct 2024 03:12:06 GMT
Accept-Ranges: bytes
Content-Length: 1228913
Vary: Accept-Encoding
Content-Type: text/html
Page title: Duffson Resources – Mexican focused gold company
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8" />
<script type="text/javascript" src="./scripts/script.js"></script>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="profile" href="https://gmpg.org/xfn/11" />
<title>Duffson Resources – Mexican focused gold company</title>
<meta name="robots" content="max-image-preview:large" />
<link rel="alternate" hreflang="en" href="index.htm" />
<link rel="alternate" hreflang="fr" href="index-1.htm?lang=fr" />
<link rel="alternate" hreflang="x-default" href="index.htm" />
<link rel="dns-prefetch" href="//fonts.googleapis.com" />
<link
rel="alternate"
type="application/rss+xml"
title="Perseus Mining » Feed"
href="feed/index.htm"
/>
<script>
window._wpemojiSettings = {
baseUrl: "https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/",
ext: ".png",
svgUrl: "https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/svg\/",
svgExt: ".svg",
source: {
concatemoji:
"https:\/\/perseusmining.com\/lib\/js\/wp-emoji-release.min.js",
},
};
/*! This file is auto-generated */
!(function (i, n) {
var o, s, e;
function c(e) {
try {
var t = { supportTests: e, timestamp: new Date().valueOf() };
sessionStorage.setItem(o, JSON.stringify(t));
} catch (e) {}
}
function p(e, t, n) {
e.clearRect(0, 0, e.canvas.width, e.canvas.height),
e.fillText(t, 0, 0);
var t = new Uint32Array(
e.getImageData(0, 0, e.canvas.width, e.canvas.height).data
),
r =
(e.clearRect(0, 0, e.canvas.width, e.canvas.height),
e.fillText(n, 0, 0),
new Uint32Array(
e.getImageData(0, 0, e.canvas.width, e.canvas.height).data
));
return t.every(function (e, t) {
return e === r[t];
});
}
function u(e, t, n) {
switch (t) {
case "flag":
return n(
e,
"\ud83c\udff3\ufe0f\u200d\u26a7\ufe0f",
"\ud83c\udff3\ufe0f\u200b\u26a7\ufe0f"
)
? !1
: !n(
e,
"\ud83c\uddfa\ud83c\uddf3",
"\ud83c\uddfa\u200b\ud83c\uddf3"
) &&
!n(
e,
"\ud83c\udff4\udb40\udc67\udb40\udc62\udb40\udc65\udb40\udc6e\udb40\udc67\udb40\udc7f",
"\ud83c\udff4\u200b\udb40\udc67\u200b\udb40\udc62\u200b\udb40\udc65\u200b\udb40\udc6e\u200b\udb40\udc67\u200b\udb40\udc7f"
);
case "emoji":
return !n(
e,
"\ud83d\udc26\u200d\u2b1b",
"\ud83d\udc26\u200b\u2b1b"
);
}
return !1;
}
function f(e, t, n) {
var r =
"undefined" != typeof WorkerGlobalScope &&
self instanceof WorkerGlobalScope
? new OffscreenCanvas(300, 150)
: i.createElement("canvas"),
a = r.getContext("2d", { willReadFrequently: !0 }),
o = ((a.textBaseline = "top"), (a.font = "600 32px Arial"), {});
return (
e.forEach(function (e) {
o[e] = t(a, e, n);
}),
o
);
}
function t(e) {
var t = i.createElement("script");
(t.src = e), (t.defer = !0), i.head.appendChild(t);
}
"undefined" != typeof Promise &&
((o = "wpEmojiSettingsSupports"),
(s = ["flag", "emoji"]),
(n.supports = { everything: !0, everythingExceptFlag: !0 }),
(e = new Promise(function (e) {
i.addEventListener("DOMContentLoaded", e, { once: !0 });
})),
new Promise(function (t) {
Open service 207.174.214.35:443 · www.duffsonresources.com.progresoinvestment.com
2025-12-31 12:57
HTTP/1.1 200 OK
Date: Wed, 31 Dec 2025 12:57:43 GMT
Server: Apache
Upgrade: h2,h2c
Connection: Upgrade, close
Last-Modified: Sun, 06 Oct 2024 03:12:06 GMT
Accept-Ranges: bytes
Content-Length: 1228913
Vary: Accept-Encoding
Content-Type: text/html
Page title: Duffson Resources – Mexican focused gold company
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8" />
<script type="text/javascript" src="./scripts/script.js"></script>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="profile" href="https://gmpg.org/xfn/11" />
<title>Duffson Resources – Mexican focused gold company</title>
<meta name="robots" content="max-image-preview:large" />
<link rel="alternate" hreflang="en" href="index.htm" />
<link rel="alternate" hreflang="fr" href="index-1.htm?lang=fr" />
<link rel="alternate" hreflang="x-default" href="index.htm" />
<link rel="dns-prefetch" href="//fonts.googleapis.com" />
<link
rel="alternate"
type="application/rss+xml"
title="Perseus Mining » Feed"
href="feed/index.htm"
/>
<script>
window._wpemojiSettings = {
baseUrl: "https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/72x72\/",
ext: ".png",
svgUrl: "https:\/\/s.w.org\/images\/core\/emoji\/15.0.3\/svg\/",
svgExt: ".svg",
source: {
concatemoji:
"https:\/\/perseusmining.com\/lib\/js\/wp-emoji-release.min.js",
},
};
/*! This file is auto-generated */
!(function (i, n) {
var o, s, e;
function c(e) {
try {
var t = { supportTests: e, timestamp: new Date().valueOf() };
sessionStorage.setItem(o, JSON.stringify(t));
} catch (e) {}
}
function p(e, t, n) {
e.clearRect(0, 0, e.canvas.width, e.canvas.height),
e.fillText(t, 0, 0);
var t = new Uint32Array(
e.getImageData(0, 0, e.canvas.width, e.canvas.height).data
),
r =
(e.clearRect(0, 0, e.canvas.width, e.canvas.height),
e.fillText(n, 0, 0),
new Uint32Array(
e.getImageData(0, 0, e.canvas.width, e.canvas.height).data
));
return t.every(function (e, t) {
return e === r[t];
});
}
function u(e, t, n) {
switch (t) {
case "flag":
return n(
e,
"\ud83c\udff3\ufe0f\u200d\u26a7\ufe0f",
"\ud83c\udff3\ufe0f\u200b\u26a7\ufe0f"
)
? !1
: !n(
e,
"\ud83c\uddfa\ud83c\uddf3",
"\ud83c\uddfa\u200b\ud83c\uddf3"
) &&
!n(
e,
"\ud83c\udff4\udb40\udc67\udb40\udc62\udb40\udc65\udb40\udc6e\udb40\udc67\udb40\udc7f",
"\ud83c\udff4\u200b\udb40\udc67\u200b\udb40\udc62\u200b\udb40\udc65\u200b\udb40\udc6e\u200b\udb40\udc67\u200b\udb40\udc7f"
);
case "emoji":
return !n(
e,
"\ud83d\udc26\u200d\u2b1b",
"\ud83d\udc26\u200b\u2b1b"
);
}
return !1;
}
function f(e, t, n) {
var r =
"undefined" != typeof WorkerGlobalScope &&
self instanceof WorkerGlobalScope
? new OffscreenCanvas(300, 150)
: i.createElement("canvas"),
a = r.getContext("2d", { willReadFrequently: !0 }),
o = ((a.textBaseline = "top"), (a.font = "600 32px Arial"), {});
return (
e.forEach(function (e) {
o[e] = t(a, e, n);
}),
o
);
}
function t(e) {
var t = i.createElement("script");
(t.src = e), (t.defer = !0), i.head.appendChild(t);
}
"undefined" != typeof Promise &&
((o = "wpEmojiSettingsSupports"),
(s = ["flag", "emoji"]),
(n.supports = { everything: !0, everythingExceptFlag: !0 }),
(e = new Promise(function (e) {
i.addEventListener("DOMContentLoaded", e, { once: !0 });
})),
new Promise(function (t) {
Open service 207.174.214.35:80 · www.duffsonresources.com.progresoinvestment.com
2025-12-31 12:57
HTTP/1.1 302 Found Date: Wed, 31 Dec 2025 12:57:43 GMT Server: Apache Location: https://duffsonresources.com/ Content-Length: 213 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 302 Found <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://duffsonresources.com/">here</a>.</p> </body></html>