cloudflare
tcp/443 tcp/8443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a7edf4f1b1e35dd9d9b3c9a7b2b4097b0a1b0df
GraphQL introspection enabled at /graphql Types: 1018 (by kind: ENUM: 81, INPUT_OBJECT: 256, INTERFACE: 34, OBJECT: 637, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: MpRewardConfig, MpRewardIcon, MpRewardShoppingCartSpendingRules, NewestBlogPosts, RelatedBlogPosts - Mutation: Mutation | fields: AmxnotifStockSubscribe, MpRewardInvite, MpRewardRefer, MpRewardSpendingPoint, MpRewardSubscribe Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
Open service 104.26.12.78:8443 · rs.qa24.gymbeam.dev
2026-01-10 05:16
HTTP/1.1 522 <none> Date: Sat, 10 Jan 2026 05:16:53 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=19620,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9bb9b3f92b9918d1-FRA alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 104.21.27.42:443 · rs.qa24.gymbeam.dev
2026-01-09 00:25
HTTP/1.1 500 Internal Server Error
Date: Fri, 09 Jan 2026 00:25:13 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Set-Cookie: PHPSESSID=90d462e83377d65c849a7e2c0f267e54; expires=Fri, 09 Jan 2026 20:25:13 GMT; Max-Age=72000; path=/; domain=rs.qa24.gymbeam.dev; secure; HttpOnly; SameSite=Lax
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
vary: Accept-Encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=xKznNDpA7nySesbdBfqtJOwUtcC%2FqQ%2FXH69AyiseGpg4g3Gihe%2FW%2FnjeW9nIUsGX91ky7JVT6WSia5hWqw%2By7eC%2FLD1QHBP6iesfYhqcMTEh6Q%3D%3D"}]}
x-varnish-status: MISS
pragma: no-cache
expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=4,cfOrigin;dur=7742
CF-RAY: 9bafcba398247093-FRA
Open service 104.21.27.42:443 · rs.qa24.gymbeam.dev
2026-01-02 00:19
HTTP/1.1 500 Internal Server Error
Date: Fri, 02 Jan 2026 00:19:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Set-Cookie: PHPSESSID=80acd05a57562f8043dea39300a55089; expires=Fri, 02 Jan 2026 20:19:33 GMT; Max-Age=72000; path=/; domain=rs.qa24.gymbeam.dev; secure; HttpOnly; SameSite=Lax
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
x-frame-options: SAMEORIGIN
vary: Accept-Encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Lg68vRULhhd5kra%2BSXMofETwdinDiWiVZX%2F69CjamUToqlcuhWw7oMS1lMI3lIHvymZWERDpZxPpXayQM5LB2tbA%2BKnf%2FXYRurJjTmOl29vfqw%3D%3D"}]}
x-varnish-status: MISS
pragma: no-cache
expires: -1
Cache-Control: no-store, no-cache, must-revalidate, max-age=0
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=9733
CF-RAY: 9b7615aa58ea3803-FRA
Open service 104.21.27.42:443 · rs.qa24.gymbeam.dev
2025-12-22 08:04
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 08:04:58 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Server: cloudflare Set-Cookie: PHPSESSID=2b1d326afde20aee142bd19230070afa; expires=Tue, 23 Dec 2025 04:04:58 GMT; Max-Age=72000; path=/; domain=rs.qa24.gymbeam.dev; secure; HttpOnly; SameSite=Lax