Apache 2.4.41
tcp/443 tcp/80
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e076a5f965a6a5f965a6a5f965a6a5f965a6a5f965a
Symfony profiler enabled: https://siteonea-portal.pimcoredemos.com/_profiler/empty/search/results
Open service 52.70.21.189:443 · siteonea-portal.pimcoredemos.com
2024-12-21 17:16
HTTP/1.1 302 Found Date: Sat, 21 Dec 2024 17:16:29 GMT Server: Apache/2.4.41 (Ubuntu) Cache-Control: max-age=0, must-revalidate, private Location: /auth/login X-Powered-By: pimcore Content-Language: en Pragma: no-cache Expires: Sat, 21 Dec 2024 17:16:29 GMT X-Debug-Token: 303234 X-Debug-Token-Link: https://siteonea-portal.pimcoredemos.com/_profiler/303234 X-Robots-Tag: noindex Set-Cookie: _pc_tss=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE3MzQ4MDEzODkuNzY0OTgzLCJwdGciOnsiX20iOjEsIl9jIjoxNzM0ODAxMzg5LCJfdSI6MTczNDgwMTM4OSwidmk6c3J1IjpbN119LCJleHAiOjE3MzQ4MDMxODl9.sfLuWC3LzHxMR_lsQbdfiYxqDDccAWr3bd0TDPRnFXM; expires=Sat, 21-Dec-2024 17:46:29 GMT; Max-Age=1800; path=/; httponly; samesite=lax Set-Cookie: _pc_tvs=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE3MzQ4MDEzODkuNzY1MjkxLCJwdGciOnsiY21mOnNnIjp7Ijg2MCI6MX0sIl9jIjoxNzM0ODAxMzg5LCJfdSI6MTczNDgwMTM4OX0sImV4cCI6MTc2NjMzNzM4OX0.H6FtG408pD8n1gxLQ5AicSZNp_OrDCK8AwTbWbCd1_I; expires=Sun, 21-Dec-2025 17:16:29 GMT; Max-Age=31536000; path=/; httponly; samesite=lax Set-Cookie: sf_redirect=%7B%22token%22%3A%22303234%22%2C%22route%22%3A%22document_337%22%2C%22method%22%3A%22GET%22%2C%22controller%22%3A%7B%22class%22%3A%22Pimcore%5C%5CBundle%5C%5CPortalEngineBundle%5C%5CController%5C%5CPortalController%22%2C%22method%22%3A%22pageAction%22%2C%22file%22%3A%22%5C%2Fvar%5C%2Fwww%5C%2Fhtml%5C%2Fsiteone%5C%2Fvendor%5C%2Fpimcore%5C%2Fportal-engine%5C%2Fsrc%5C%2FController%5C%2FPortalController.php%22%2C%22line%22%3A26%7D%2C%22status_code%22%3A302%2C%22status_text%22%3A%22Found%22%7D; path=/; secure; httponly; samesite=lax Set-Cookie: PHPSESSID=2lvi5puqsjv1t5ibobv5bpnrj8; path=/; httponly; samesite=strict Content-Length: 516 Connection: close Content-Type: text/html; charset=UTF-8 Page title: Redirecting to /auth/login <!DOCTYPE html> <html> <head> <meta charset="UTF-8" /> <meta http-equiv="refresh" content="0;url='/auth/login'" /> <title>Redirecting to /auth/login</title> <script> var _ptg = _ptg || {}; _ptg.options = _ptg.options || {}; _ptg.options.log = true; </script> <script src="/bundles/pimcorecore/js/targeting.js" async></script></head> <body> Redirecting to <a href="/auth/login">/auth/login</a>. </body> </html>
Open service 52.70.21.189:80 · siteonea-portal.pimcoredemos.com
2024-12-21 17:16
HTTP/1.1 301 Moved Permanently Date: Sat, 21 Dec 2024 17:16:24 GMT Server: Apache/2.4.41 (Ubuntu) Location: https://siteonea-portal.pimcoredemos.com/ Content-Length: 347 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://siteonea-portal.pimcoredemos.com/">here</a>.</p> <hr> <address>Apache/2.4.41 (Ubuntu) Server at siteonea-portal.pimcoredemos.com Port 80</address> </body></html>