Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d60384013956bd1c9c432813f4477d0b0d2c2507448
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /api/account/{id}
POST /api
POST /api/CustomerPortal
POST /api/Dot818
POST /api/Mexico
POST /api/TaxLead
Open service 74.113.16.90:443 · onlineinquiry-api.security-finance.com
2026-01-09 23:24
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 Request-Context: appId=cid-v1:f0b46f4d-5057-4053-beee-e7408959c850 X-Powered-By: ASP.NET Date: Fri, 09 Jan 2026 23:24:47 GMT
Open service 2.16.6.223:443 · security-finance.com
2026-01-07 16:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www.securityfinance.com/ Expires: Wed, 07 Jan 2026 16:42:50 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 16:42:50 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767804170183_34900575_1482983906_13_1354_0_8_-";dur=1
Open service 2.16.6.223:80 · security-finance.com
2026-01-07 16:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www.securityfinance.com/ Expires: Wed, 07 Jan 2026 16:43:31 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 16:43:31 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767804211212_34900575_1483268461_12_1409_0_0_-";dur=1
Open service 2.16.6.199:80 · security-finance.com
2026-01-07 16:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www.securityfinance.com/ Expires: Wed, 07 Jan 2026 16:43:31 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 16:43:31 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767804211889_34900551_1617155554_10_1443_93_0_-";dur=1
Open service 2.16.6.199:443 · security-finance.com
2026-01-07 16:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www.securityfinance.com/ Expires: Wed, 07 Jan 2026 16:42:50 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 16:42:50 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Server-Timing: ak_p; desc="1767804170087_34900551_1616817320_11_1654_12_16_-";dur=1
Open service 74.113.16.90:443 · onlineinquiry-api.security-finance.com
2025-12-30 10:38
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 Request-Context: appId=cid-v1:f0b46f4d-5057-4053-beee-e7408959c850 X-Powered-By: ASP.NET Date: Tue, 30 Dec 2025 10:38:47 GMT
Open service 74.113.16.90:443 · onlineinquiry-api.security-finance.com
2025-12-23 08:26
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 Request-Context: appId=cid-v1:f0b46f4d-5057-4053-beee-e7408959c850 X-Powered-By: ASP.NET Date: Tue, 23 Dec 2025 08:26:46 GMT
Open service 74.113.16.90:443 · onlineinquiry-api.security-finance.com
2025-12-21 10:30
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 Request-Context: appId=cid-v1:f0b46f4d-5057-4053-beee-e7408959c850 X-Powered-By: ASP.NET Date: Sun, 21 Dec 2025 10:30:31 GMT