nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-12-22 01:04
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 01:04:30 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNY9VXM2XEBBEPRYSWK4Y36","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNY9VXM2XEBBEPRYSWK4Y36 X-Runtime: 1.040254 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-12-20 01:17
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 01:18:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGT95WFSWK3JW3RSMNGD6BW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGT95WFSWK3JW3RSMNGD6BW X-Runtime: 0.050560 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-12-18 12:49
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 12:49:29 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFCX1W68T1JP8GM782XQ87AQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFCX1W68T1JP8GM782XQ87AQ X-Runtime: 0.123304 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-12-14 02:16
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 02:16:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF1F7C15PAGBPSMT5H9XBC1D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF1F7C15PAGBPSMT5H9XBC1D X-Runtime: 0.039972 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-12-12 08:20
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 08:20:37 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEWZ97KD381NHYZBSXJA7TYH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEWZ97KD381NHYZBSXJA7TYH X-Runtime: 0.695198 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-12-02 14:23
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 14:23:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3W2BBG5WY5DMMC9JYVJG3E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3W2BBG5WY5DMMC9JYVJG3E X-Runtime: 0.863781 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-11-30 11:53
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 11:53:38 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYEPNVM2F5KW1HBKKRM99HJ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYEPNVM2F5KW1HBKKRM99HJ X-Runtime: 0.330819 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-11-28 14:03
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 14:03:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSHAHA6M80RP6VHTXQCJ7X8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSHAHA6M80RP6VHTXQCJ7X8 X-Runtime: 0.803365 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-11-26 16:31
HTTP/1.1 302 Found Server: nginx Date: Tue, 26 Nov 2024 16:31:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMMZY5N41JQNK01NWZ4B25T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMMZY5N41JQNK01NWZ4B25T X-Runtime: 0.192414 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>
Open service 5.135.171.190:443 · repo.fanampiana.com
2024-11-20 14:58
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 14:59:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Location: https://repo.fanampiana.com/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD51B8WCKSXVMY55YFMRHFH3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD51B8WCKSXVMY55YFMRHFH3 X-Runtime: 0.031987 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block <html><body>You are being <a href="https://192.168.1.11/users/sign_in">redirected</a>.</body></html>