Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d325beceb325beceb325beceb325beceb
Found 1 files trough .DS_Store spidering: /assets
Open service 54.204.238.15:443 · pt.whatsthatcharge.com
2026-01-09 12:08
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"cdd325ecc0dd6ed32269c4f727d4b1d7"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=InL%2B%2B%2F0rY7cY9A0s2GtSk9v0B6m%2Bu9O%2FTqKGK2W2EdE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767960483"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=InL%2B%2B%2F0rY7cY9A0s2GtSk9v0B6m%2Bu9O%2FTqKGK2W2EdE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767960483"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=VWJHaWxpcVR5YUkwUklmUm9LOWgyOStSdXEvYk9JS2dJOCtVUDFLaW5PNTB2cUk2dTJtdHgvS1JXVHUxc3Q2d2lDQ1JrL01BQUJtcGE1dGJBSDVEMXQrTGs5Y1c4NmdIZnhhbjM4aTgvTE1SaXZrNmMyZEMyNFRzTStXUGJ0R0x5bGNXM01mREVLZU9rSDRLd3JPQXVrM0FBM2c3QkRsbE95STZocUZiVVNiTG9QYWZLTmNUZmRXNEQwYldLM0FOLS1OTENIVWtveVA3QlBseThwZjl6Vld3PT0%3D--2a98f732de320fb3d155c8e127aefad089824766; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: a2c275f1-f380-40cb-7ba2-ee97d6c9df1f
X-Runtime: 0.027520
X-Xss-Protection: 1; mode=block
Date: Fri, 09 Jan 2026 12:08:03 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · pt.whatsthatcharge.com
2026-01-02 20:40
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"02d34256c769dafc9ed6b15ddbed4dca"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=icRrOGJPCgfua%2Bx4cpLJdzIT7gM7KdcHcDq9QkFoSls%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767386448"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=icRrOGJPCgfua%2Bx4cpLJdzIT7gM7KdcHcDq9QkFoSls%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767386448"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=dEhmVHFyK3NiLzVwZTV4R2pDT3VhWFB3YTJVcGJJbHF4bEdKQlAwN09XNldURCtkaVgxdHZFWFE4Z0xHTWtrLzd0SzU0dHppNjZjbFA4aUJPS0NsOElEMlBTOHpYWmxVbkhNL1dQKy9pSFc0eFd6ZTRQblA4bGVGRTFxZndXVUJZcXJ1dm5rSUF5b0NEMUYwZkNkdndlS3NKTVptMElZMmRaejNuWDJqWGlsRjBzNHAxb0RNU2k5ZWpNUXMyL1dsLS1xTitnckdLWW9EWjVrd2tJbWRLekNnPT0%3D--fc7bd3879cec0bfe223b2182b149e172b41b93ad; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 6a932613-c4d1-59ac-f580-bdb935760354
X-Runtime: 0.028130
X-Xss-Protection: 1; mode=block
Date: Fri, 02 Jan 2026 20:40:48 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · pt.whatsthatcharge.com
2025-12-23 01:24
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"0e1efc91d0ef3ac7e04616a6dbb4d615"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Fkpx0d2Hd3Lqo8asgyEBlXy4vhoBhhF9LbrL48CYpzw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766453040"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Fkpx0d2Hd3Lqo8asgyEBlXy4vhoBhhF9LbrL48CYpzw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766453040"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=TFBPLzR6RWdBR0NEc2VSK000YkhYTEQ2dUtvVGx3T0F6ekNyOGN1dU1oRWFwS01ULzM2cG83YzRTREdRUUNpWGFYQTV1THFEcFc1K2VwcGI4cVRNNnlrMEpCbmRoMEtJQXFoVUMvQ1VMWkd3WSs3QjAzY1BSalJFaEtldlhDVWlwd3BiMVVjaitSbmt0TXQ1ZGFSN3p3bXBQZnZ4YnBJcnJPZDYyLzlaNGlxN09LQmxhb0JHS0hSOFRXTWZSMGd1LS16ZGR5SkYvNXZ1bVNJRnhPeXN1NlF3PT0%3D--b63a69b59cdc50f694a58bed28ba25a1aac5dc28; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0a719fcd-3e61-8d6d-05ed-eb8bb9cb0fb4
X-Runtime: 0.027286
X-Xss-Protection: 1; mode=block
Date: Tue, 23 Dec 2025 01:24:00 GMT
Connection: close
Transfer-Encoding: chunked
Open service 54.204.238.15:443 · pt.whatsthatcharge.com
2025-12-20 15:01
HTTP/1.1 200 OK
Cache-Control: max-age=0, private, must-revalidate
Content-Type: text/html; charset=utf-8
Etag: W/"0f98bc6402b806910da96ea2a90edb07"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jHLX9kHV9Fyng9y0ExKsATtw%2Bb4kDhVuynD0lAXgP9g%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766242862"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jHLX9kHV9Fyng9y0ExKsATtw%2Bb4kDhVuynD0lAXgP9g%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766242862"
Server: Heroku
Set-Cookie: _WhatsThatCharge_session=eldxVGd0OHhwL2VVYTRuVlRHVDFXMEdjekNPYkN4VG5DUXJvYmoxUkZualRLb2VrR3VNMDBLWFFlb1hZaHpDQWgvNGRObFRodkFOVnB3K1pTMmJ5TXI3b3IwU1ExZ2RsWTVRd2d2QVN3R1FPVHlzeUlnRXVDZEQ3Q3VmRC9sOFJ6Umk3TC8rZzVjUWRHamNXUS9hYjZjcFpCcmlYak5Sb2pWR1dJQzJTVkd6ZXdoODM1enlqUFlMckhnTGtxNVZuLS1McFRDMldZMUs1K3dtQ0w5anZPMHJ3PT0%3D--c78e0de5f49c065eb0b3d6d3d0798a2cfec15a3f; path=/; secure; HttpOnly
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 9107ed02-e0e8-d9a3-4d68-8b19d0e54aad
X-Runtime: 0.042608
X-Xss-Protection: 1; mode=block
Date: Sat, 20 Dec 2025 15:01:02 GMT
Connection: close
Transfer-Encoding: chunked