Apache
tcp/443 tcp/80
nginx 1.24.0
tcp/443 tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522dd44af8f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:glcbt-68_SGaV94Yx4R5Rw9ryQm2J@gitlab.com/rightech1/website.git fetch = +refs/heads/*:refs/remotes/origin/* [lfs] repositoryformatversion = 0
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba91884029ffc42c1a16a4e17
[init] defaultBranch = none [fetch] recurseSubmodules = false [transfer] bundleURI = true [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:glcbt-66_aSztUzz-p8LHM7FKXjHM@gitlab.com/rightech1/website.git fetch = +refs/heads/*:refs/remotes/origin/* [lfs] repositoryformatversion = 0
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba91884029ffc42c111585d02
[init] defaultBranch = none [fetch] recurseSubmodules = false [transfer] bundleURI = true [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:glcbt-66_fjW4sqkq4YpHz9h8C_jt@gitlab.com/rightech1/website.git fetch = +refs/heads/*:refs/remotes/origin/* [lfs] repositoryformatversion = 0
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba91884022e566c81a94fa24e
[init] defaultBranch = none [fetch] recurseSubmodules = false [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:64_nzkN5B9RSE6cshdoweVs@gitlab.com/rightech1/website.git fetch = +refs/heads/*:refs/remotes/origin/*
Severity: critical
Fingerprint: 2580fa947178c88c8f88f4f64b143e4f192660cba91884022e566c81a6225bc6
[init] defaultBranch = none [fetch] recurseSubmodules = false [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab-ci-token:64_FDsLz6p5GhLUehxSLcrN@gitlab.com/rightech1/website.git fetch = +refs/heads/*:refs/remotes/origin/*
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9db7f4c636b7f4c636b7f4c636b7f4c636
Found 1 files trough .DS_Store spidering: /images
Open service 35.187.113.220:443 · sms.rightech.co.ke
2026-01-23 14:20
HTTP/1.1 302 Found Date: Fri, 23 Jan 2026 14:20:07 GMT Server: Apache X-Powered-By: PHP/7.4.20 Set-Cookie: PHPSESSID=50pqouiqovts8cqvf8tcs09eii; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: /auth/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.187.113.220:443 · sms.rightech.co.ke
2026-01-09 22:32
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 22:32:24 GMT Server: Apache X-Powered-By: PHP/7.4.20 Set-Cookie: PHPSESSID=di5b3cmjld0mt3ufd599lf4atj; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: /auth/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 108.128.163.184:443 · api.mivida.rightech.co.ke
2026-01-09 01:32
HTTP/1.1 404 Not Found
Server: nginx/1.24.0 (Ubuntu)
Date: Fri, 09 Jan 2026 01:32:14 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 2681
Connection: close
X-Frame-Options: DENY
Vary: origin
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
Page title: Page not found at /
<!DOCTYPE html>
<html lang="en">
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<title>Page not found at /</title>
<meta name="robots" content="NONE,NOARCHIVE">
<style type="text/css">
html * { padding:0; margin:0; }
body * { padding:10px 20px; }
body * * { padding:0; }
body { font:small sans-serif; background:#eee; color:#000; }
body>div { border-bottom:1px solid #ddd; }
h1 { font-weight:normal; margin-bottom:.4em; }
h1 span { font-size:60%; color:#666; font-weight:normal; }
table { border:none; border-collapse: collapse; width:100%; }
td, th { vertical-align:top; padding:2px 3px; }
th { width:12em; text-align:right; color:#666; padding-right:.5em; }
#info { background:#f6f6f6; }
#info ol { margin: 0.5em 4em; }
#info ol li { font-family: monospace; }
#summary { background: #ffc; }
#explanation { background:#eee; border-bottom: 0px none; }
pre.exception_value { font-family: sans-serif; color: #575757; font-size: 1.5em; margin: 10px 0 10px 0; }
</style>
</head>
<body>
<div id="summary">
<h1>Page not found <span>(404)</span></h1>
<table class="meta">
<tr>
<th>Request Method:</th>
<td>GET</td>
</tr>
<tr>
<th>Request URL:</th>
<td>http://api.mivida.rightech.co.ke/</td>
</tr>
</table>
</div>
<div id="info">
<p>
Using the URLconf defined in <code>mivida.urls</code>,
Django tried these URL patterns, in this order:
</p>
<ol>
<li>
admin/
</li>
<li>
api/
</li>
<li>
admin/django_celery_results/
</li>
<li>
^media/(?P<path>.*)$
</li>
<li>
^static/(?P<path>.*)$
</li>
<li>
^media/(?P<path>.*)$
</li>
</ol>
<p>
The empty path
didn’t match any of these.
</p>
</div>
<div id="explanation">
<p>
You’re seeing this error because you have <code>DEBUG = True</code> in
your Django settings file. Change that to <code>False</code>, and Django
will display a standard 404 page.
</p>
</div>
</body>
</html>
Open service 108.128.163.184:80 · api.mivida.rightech.co.ke
2026-01-09 01:32
HTTP/1.1 301 Moved Permanently Server: nginx/1.24.0 (Ubuntu) Date: Fri, 09 Jan 2026 01:32:14 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://api.mivida.rightech.co.ke/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.24.0 (Ubuntu)</center> </body> </html>
Open service 35.187.113.220:443 · sms.rightech.co.ke
2026-01-02 15:44
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 15:44:26 GMT Server: Apache X-Powered-By: PHP/7.4.20 Set-Cookie: PHPSESSID=kfplkraiqhe1k70lecs9siensv; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: /auth/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.187.113.220:80 · sms.rightech.co.ke
2026-01-02 02:42
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 02:42:51 GMT Server: Apache Location: https://sms.rightech.co.ke/ Content-Length: 235 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://sms.rightech.co.ke/">here</a>.</p> </body></html>
Open service 35.187.113.220:443 · sms.rightech.co.ke
2026-01-02 02:42
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 02:42:51 GMT Server: Apache X-Powered-By: PHP/7.4.20 Set-Cookie: PHPSESSID=srjkabmgtinua0regc8hmj9s3n; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: /auth/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8
Open service 35.187.113.220:443 · sms.rightech.co.ke
2025-12-23 00:48
HTTP/1.1 302 Found Date: Tue, 23 Dec 2025 00:48:42 GMT Server: Apache X-Powered-By: PHP/7.4.20 Set-Cookie: PHPSESSID=nb5cit20dgsr75ab84ptib6r87; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: /auth/login Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8