cloudflare
tcp/443
nginx 1.18.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354988652899a0a437869d717514831815c24bca28e1
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/CustomerPhoto/delete-photo/{id}
GET /api/Customer/avatar/me
GET /api/Customer/avatar/{customerId}
GET /api/Customer/profile
GET /api/Customer/profile/{customerId}
GET /api/CustomerMessage/detail/{messageId}
GET /api/CustomerMessage/list
GET /api/CustomerPhoto/get-photo/{id}
GET /api/CustomerPhoto/get-photos
GET /api/ImageFeed/get-random-photo
POST /api/Auth/login-firebase
POST /api/CustomerMessage/send-direct
POST /api/CustomerPhoto/create-photo
POST /api/ImageFeed/rate-photo
POST /api/Push/send/{customerId}
PUT /api/Customer/profile/avatar
PUT /api/CustomerPhoto/update-photo/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354988652899a0a437869d717514831815c2b2acbef6
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/CustomerPhoto/delete-photo/{id}
GET /api/Customer/avatar/me
GET /api/Customer/avatar/{customerId}
GET /api/Customer/profile
GET /api/Customer/profile/{customerId}
GET /api/CustomerMessage/detail/{messageId}
GET /api/CustomerMessage/list
GET /api/CustomerPhoto/get-photo/{id}
GET /api/CustomerPhoto/get-photos
GET /api/ImageFeed/get-random-photo
POST /api/Auth/login-firebase
POST /api/CustomerMessage/send-direct
POST /api/CustomerPhoto/create-photo
POST /api/ImageFeed/rate-photo
PUT /api/Customer/profile/avatar
PUT /api/CustomerPhoto/update-photo/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354988652899a0a437869d717514831815c28007b27e
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/CustomerPhoto/delete-photo/{id}
GET /api/Customer/avatar/me
GET /api/Customer/avatar/{customerId}
GET /api/Customer/profile
GET /api/Customer/profile/{customerId}
GET /api/CustomerPhoto/get-photo/{id}
GET /api/CustomerPhoto/get-photos
GET /api/ImageFeed/get-random-photo
POST /api/Auth/login-firebase
POST /api/CustomerPhoto/create-photo
POST /api/ImageFeed/rate-photo
PUT /api/Customer/profile/avatar
PUT /api/CustomerPhoto/update-photo/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354923c2ad5c0307b312deed3558ebd94e5047bf49c3
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Branch/business/{businessId}
GET /api/Branch/{id}
GET /api/Business
GET /api/Business/{id}
GET /api/Category/business/{businessId}
GET /api/Category/{id}
GET /api/Language
GET /api/Language/{id}
GET /api/Product/business/{businessId}
GET /api/Product/{id}
GET /api/User/{id}
POST /api/Branch
POST /api/Business/assign-languages
POST /api/Category
POST /api/Product
POST /api/User/create
POST /api/User/login
PUT /api/User
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549de8b87763d6c8f048c0875927aed1e5466b0ff37
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Customer/avatar/me
GET /api/Customer/avatar/{customerId}
GET /api/Customer/profile
GET /api/Customer/{customerId}
GET /api/CustomerPhotos
GET /api/CustomerPhotos/{id}
GET /api/ImageFeed
POST /api/Customer/avatar
POST /api/Customer/login-firebase
POST /api/Customer/refresh-token
POST /api/ImageFeed/rate
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549de8b87763d6c8f048c087592d55ffa29e3f928c9
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Customer/avatar/me
GET /api/Customer/avatar/{customerId}
GET /api/Customer/profile
GET /api/CustomerPhotos
GET /api/CustomerPhotos/{id}
GET /api/ImageFeed
POST /api/Customer/avatar
POST /api/Customer/login-firebase
POST /api/Customer/refresh-token
POST /api/ImageFeed/rate
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035493ade6eed40c6968dee0bef11898bfe7736097fae
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Customer/profile
POST /api/Customer/avatar
POST /api/Customer/confirm-email
POST /api/Customer/forgot-password
POST /api/Customer/login
POST /api/Customer/refresh-token
POST /api/Customer/register
POST /api/Customer/reset-password
POST /api/Customer/{provider}/login
POST /api/Customer/{provider}/register
PUT /api/Customer/email
PUT /api/Customer/password
Open service 104.21.53.53:443 · ratematch.app
2026-01-23 09:57
HTTP/1.1 200 OK
Date: Fri, 23 Jan 2026 09:57:42 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Last-Modified: Thu, 15 Jan 2026 21:26:32 GMT
vary: accept-encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=rnCx5PxGhWSaNEkVoXQCCsGKaL6vVj8vUD5VIUMXcUyCPRmcPRZKpVHhhj3JewBhyB3qW4mDQS%2FVccY%2BAZfQ4%2Fx98KGaR1auJDHMbTE%3D"}]}
cf-cache-status: DYNAMIC
CF-RAY: 9c266dab0f5a7762-LHR
alt-svc: h3=":443"; ma=86400
Page title: admin-panel
<!doctype html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<link rel="icon" type="image/svg+xml" href="/vite.svg" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>admin-panel</title>
<script type="module" crossorigin src="/assets/index-ChtHRFf_.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-B6A4U1pM.css">
</head>
<body>
<div id="app"></div>
</body>
</html>
Open service 144.91.82.34:443 · dapi.ratematch.app
2026-01-22 20:40
HTTP/1.1 404 Not Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 22 Jan 2026 20:40:08 GMT Content-Length: 0 Connection: close
Open service 144.91.82.34:443 · dapi.ratematch.app
2026-01-09 22:43
HTTP/1.1 404 Not Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 09 Jan 2026 22:43:11 GMT Content-Length: 0 Connection: close
Open service 104.21.53.53:443 · ratematch.app
2026-01-09 08:22
HTTP/1.1 404 Not Found
Date: Fri, 09 Jan 2026 08:22:45 GMT
Content-Length: 0
Connection: close
Server: cloudflare
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=YyOxVhkRxnKzwxFxJicuzR5V7YeNlNTx5u99AjdYvAhyCkJDRK0S7qBKoMZA88sI52vGk23YzeBaMsfHFHBr0fLXIWehl6fSPAIeeeg%3D"}]}
CF-RAY: 9bb287577f997a09-LHR
alt-svc: h3=":443"; ma=86400
Open service 104.21.53.53:443 · ratematch.app
2026-01-02 10:40
HTTP/1.1 404 Not Found
Date: Fri, 02 Jan 2026 10:40:48 GMT
Content-Length: 0
Connection: close
Server: cloudflare
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=KAkqEk4YWIKu8QJRUdfFHcCwnEpg4XHKn0CIP9HJWaamAqoA6709wMed08wxDEKxvDx%2BMuV8qH3ZWo0LI2WXOwYu9F6diDJjxCpip6A%3D"}]}
CF-RAY: 9b79a3ebe996d2d2-FRA
alt-svc: h3=":443"; ma=86400
Open service 144.91.82.34:443 · dapi.ratematch.app
2025-12-22 21:59
HTTP/1.1 404 Not Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 22 Dec 2025 21:59:18 GMT Content-Length: 0 Connection: close
Open service 104.21.53.53:443 · ratematch.app
2025-12-22 15:13
HTTP/1.1 404 Not Found
Date: Mon, 22 Dec 2025 15:13:43 GMT
Content-Length: 0
Connection: close
Server: cloudflare
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
cf-cache-status: DYNAMIC
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=11,cfOrigin;dur=275
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=3WCFr7H%2BLrcZD2RdMufavjiHQXli7u51io%2Fl1WpsgtCXbKfxYPlJt7w0Kw6U%2FcZ925LgYUr6ybv6wyGszyaPB3LaLTMrpTj3FVd8x04%3D"}]}
CF-RAY: 9b2090946f732560-EWR
alt-svc: h3=":443"; ma=86400