Apache 2.4.41
tcp/443
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a736464b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab.awishcar.com/civicgov/civicgov-responsive-secure.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "nashua_responsive_secure"] remote = origin merge = refs/heads/nashua_responsive_secure
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-11-20 20:52
HTTP/1.1 403 Forbidden Date: Wed, 20 Nov 2024 20:52:41 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-11-18 20:35
HTTP/1.1 403 Forbidden Date: Mon, 18 Nov 2024 20:35:37 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-11-16 19:52
HTTP/1.1 403 Forbidden Date: Sat, 16 Nov 2024 19:52:37 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-11-02 17:46
HTTP/1.1 403 Forbidden Date: Sat, 02 Nov 2024 17:46:30 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-11-01 15:16
HTTP/1.1 403 Forbidden Date: Fri, 01 Nov 2024 15:16:21 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-10-30 14:18
HTTP/1.1 403 Forbidden Date: Wed, 30 Oct 2024 14:19:00 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-10-20 19:21
HTTP/1.1 403 Forbidden Date: Sun, 20 Oct 2024 19:21:31 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-10-18 22:15
HTTP/1.1 403 Forbidden Date: Fri, 18 Oct 2024 22:15:43 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: vibrate=(self), microphone=(none), payment=(none), geolocation=(self 'https://dev.civicgov4.com') sync-xhr=(self 'dev.civicgov4.com') X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-eval' 'unsafe-inline'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>
Open service 3.132.176.230:443 · qa.civicgov4.com
2024-10-16 20:49
HTTP/1.1 403 Forbidden Date: Wed, 16 Oct 2024 20:49:29 GMT Server: Apache/2.4.41 (Ubuntu) X-Permitted-Cross-Domain-Policies: master-only Permissions-Policy: camera=*; microphone=*; geolocation=* X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Referrer-Policy: same-origin Content-Security-Policy: script-src 'self' civicgov4.com *.civicgov4.com static.cloudflareinsights.com update.googleapis.com content-autofill.googleapis.com data.pendo.io cdn.pendo.io optimizationguide-pa.googleapis.com unpkg.com audioeye.com *.audioeye.com 'unsafe-inline' 'unsafe-eval'; Strict-Transport-Security: max-age=63072000; includeSubDomains Content-Length: 199 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> </body></html>