Apache
tcp/443 tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbd081bfa2
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://jpcifuentes_dmc@bitbucket.org/ofimarket/seller-center.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master vscode-merge-base = origin/master
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c3c1fc5e93c1fc5e93d77e0f576b42c4dfee4eccfcfab7f6e
Found 5 files trough .DS_Store spidering: /app /app/Actions /app/Console /public /routes
Open service 162.241.2.177:443 · sc.dimerc.cl
2026-01-10 17:33
HTTP/1.1 302 Found
Date: Sat, 10 Jan 2026 17:33:27 GMT
Server: Apache
Cache-Control: no-cache, private
Set-Cookie: XSRF-TOKEN=eyJpdiI6ImtBek04TS8zbHpxVlB0MkhLOFhBRkE9PSIsInZhbHVlIjoiOHNmQ1daSFQ3b2hDbFJhbWxlNFIyT0NxbXJNbFNrYWpkdmUrWTJTZDB0V2FKWFJsQkpEMHVMRmpmMTd1MVJxc2lVZEdGWUxnQjVWV2g2STFjK0x6QzRKQkw4ZlYybUdtcVlKemd4dk9kSjFuMjM3MVlFaWpwQmNwT1g3bDMvOTYiLCJtYWMiOiJlYzJmZGQ0NTgwY2M0MWNhMTE4YjM5MDg4YWQ5MTk5ZTQ4NDNkZTVmZTY2MTViMTIwNTM3YzQ2ODhhNTA5NDc1IiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 19:33:27 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6InVNQjRCM0FNbE1XVDJnZ2pzaURaTVE9PSIsInZhbHVlIjoiZlBLcS9WbjFWZlRqWXNMQVNRa0lPWXJwcEU5OHZad0RoZXFHV0RqMEI5Yk1DYUhGbGtSb0UxYUJtTXg3bEdoTDZvNTlVSzdkTVg0NGpWT3hkczdRQk90c0E4RTRJV1N0anR5SkhkdXJyV2tpc09HbTdDSGJGc0lXVW5hTlZzeGEiLCJtYWMiOiI3OTZlNTA4ZWU5ODJjZmU0MjBlNGEzZDliNDA1MDVjOTA4ODNlMzliNTY5MzkzNGJmMTRmZTE1ZGFmYWQ3MDUzIiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 19:33:27 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Upgrade: h2,h2c
Connection: Upgrade, close
Location: https://sc.dimerc.cl/login
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
Page title: Redirecting to https://sc.dimerc.cl/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://sc.dimerc.cl/login'" />
<title>Redirecting to https://sc.dimerc.cl/login</title>
</head>
<body>
Redirecting to <a href="https://sc.dimerc.cl/login">https://sc.dimerc.cl/login</a>.
</body>
</html>
Open service 162.241.2.177:80 · sc.dimerc.cl
2026-01-10 17:33
HTTP/1.1 302 Found
Date: Sat, 10 Jan 2026 17:33:45 GMT
Server: Apache
Cache-Control: no-cache, private
Set-Cookie: XSRF-TOKEN=eyJpdiI6Im12U3R4TFRhdWJpaWp1SlFUa3FaUEE9PSIsInZhbHVlIjoiWEt5WktNYklWS0tZQkV1RkJGY2NHYWhmeFNSamVRUUdoSHpCSCtKUWVNbEpUVzYxTU9LbkpaVkF6VkZkLzQxUksyc2JBV3BoZ09VT1k2V3BEV3RJeDQyOWV3MDU1VjJNV3RGeEhNVGlGOUlYUEQvOHE1elN5aUIrSnE1RHJCaGgiLCJtYWMiOiIzMGQ1NjM5Y2Q0YWI2YjA2M2MzMGJiZGFjMTE5YTg2OTIzY2FiMGM2ODY0ZWZkZDAwYWI0MjFlNjQxNWIyZDZiIiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 19:33:45 GMT; Max-Age=7200; path=/; samesite=lax
Set-Cookie: laravel_session=eyJpdiI6IkQ4R0JxYWI2djVmWml6QzVPdVNXdlE9PSIsInZhbHVlIjoibnZ0UlU5S3NjSjlseG1TWXJhMXhEcTVsaW9PRUZheFA1ZFNERE5BVDZPbUh0eWVUWmFmZ0RSdjRRMVBxelVvS3F4NlFhQ1E3anQrWTUzRi9ZelBLN0NVVFBBQU4yKytRTXk4cDM5TzVIa0RsZ3daWEQwOWowQkdSNHNiUVNxckUiLCJtYWMiOiJmNDIxZDQwZjVmZTBjZTNmNzBlYWZkNTBiNmJiODY1Y2Y4ZTA2N2FkYWI5MDlkZjE1MDhkYzNiMTkxOWM5MjEwIiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 19:33:45 GMT; Max-Age=7200; path=/; httponly; samesite=lax
Upgrade: h2,h2c
Connection: Upgrade, close
Location: http://sc.dimerc.cl/login
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
Page title: Redirecting to http://sc.dimerc.cl/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='http://sc.dimerc.cl/login'" />
<title>Redirecting to http://sc.dimerc.cl/login</title>
</head>
<body>
Redirecting to <a href="http://sc.dimerc.cl/login">http://sc.dimerc.cl/login</a>.
</body>
</html>