cloudflare
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea96ba46591629a2ee1cbb56ea163e836bb
Found 23 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads /uploads/media
Severity: low
Fingerprint: 5f32cf5d6962f09c9e04c3bc9e04c3bcc68b1780bf80d660e08e14da7f2276dc
Found 22 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e0754c61e0d54c61e0d54c61e0d54c61e0d54c61e0d
Symfony profiler enabled: https://spinfest-fr.com/_profiler/empty/search/results
Open service 188.114.97.3:443 · spinfest-fr.com
2026-01-09 01:52
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 01:52:59 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=VYDJhsWOos0hHlPivMObnf4qCqdkjHG2JoQeLRoeiw9uBhxHkdbNJUD47oWiAwMIJb2fR1xjmkqTQJCOE78OZK%2BB94lToG5Mwt5gXNvORw%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 01:52:58 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9bb04c5e8959dbde-FRA
Open service 2a06:98c1:3120::3:443 · spinfest-fr.com
2026-01-08 21:43
HTTP/1.1 200 OK
Date: Thu, 08 Jan 2026 21:43:38 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=bw2HRgXO60z7mSw2E1ThBj90hsJjXD%2FGtqHjHPQdpoqcsqzIsu2djzJw3yF9evsGgQN%2B0EENSgIDeExl4coL7DuxWBLxeeHqGEzpGH%2FW22OUg00oAsTYMljy9Q%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 08 Feb 2026 21:43:38 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9baedf1ebd4118d3-FRA
Open service 2a06:98c1:3120::3:443 · spinfest-fr.com
2026-01-01 22:00
HTTP/1.1 200 OK
Date: Thu, 01 Jan 2026 22:00:37 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=sE7ySQ%2FuVifhbK4MQXkXzSKGyOQwUwCmnGNzGrdlSRYmFdNN%2FELRXWI%2FvcCIYvxcvKB%2FSzg7F4NMFKJekUtaCmToQvvkhKKtqv8Yepe%2FXLNoiqnufPReb10GQg%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 01 Feb 2026 22:00:37 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=19,cfOrigin;dur=768
CF-RAY: 9b754a5f5a185e70-EWR
Open service 188.114.97.3:443 · spinfest-fr.com
2026-01-01 19:45
HTTP/1.1 200 OK
Date: Thu, 01 Jan 2026 19:45:35 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=NHizL7w1%2FG8d6ywdgNas0HVdCwsNzTZBeK1FPLNPnBFiIF8D%2B9oX7QcxhIWvfYBqBHgotDpS4cUcm3askic3Q8h4AQHbeLK3R7XAdU8iNw%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Sun, 01 Feb 2026 19:45:35 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b748490ac635d42-FRA
Open service 2a06:98c1:3120::3:443 · spinfest-fr.com
2025-12-30 05:24
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 05:24:11 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=sFfmkFGFkPxNdtzW0xZ3VqnpSjw6x5Njc7mya%2BJPbT%2BidlMWC5alSbLCHtvCav0sc4UelUeYxbdeGx%2F2k6mPCgegD1onvFHxXuAV%2B%2Bztw%2BJfjTWTWRm5dUCCGA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Fri, 30 Jan 2026 05:24:11 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b5f1bfe8f2be5a3-FRA
Open service 188.114.97.3:443 · spinfest-fr.com
2025-12-22 20:19
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 20:19:37 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=HGIHR%2F6x0xfNhy7%2BsJUdqAm90M%2BZJSj%2BGzef5RYUMLjnj7RNzAkJBIVl448A2b207YlfZ346fm63AcyFW2kXRZxeynV0ILspG5zeUA10pg%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 20:19:36 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=802
CF-RAY: 9b2250a75e0a72ab-EWR
Open service 2a06:98c1:3120::3:443 · spinfest-fr.com
2025-12-22 06:16
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 06:16:10 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=rmH70m3hvyexGgBlJqfb4LOfIoOwnGNQSpo80pJj0m5PPB%2FEksaq8kEJ75M3v7Rvyx%2F0CuaXF9qHVTvLoG4TVmiRp%2FU5tJRorol4UxE9HunCrm9EBrYhPnIhAA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 06:16:10 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=782
CF-RAY: 9b1d7d26fbe7785b-EWR
Open service 188.114.97.3:443 · spinfest-fr.com
2025-12-21 03:54
HTTP/1.1 200 OK
Date: Sun, 21 Dec 2025 03:54:36 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=wVMULX0NRhnsN1wvmJn5iGXhQCdz5q6B%2FEp00teLuctQ7mGck7lEOXcdW3SGl9QMPRq785io8w6%2FqnLMujFObCJTdDyPz%2BdCw%2BdYSdlfUw%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Wed, 21 Jan 2026 03:54:36 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b1470671ebdbb49-FRA
Open service 2a06:98c1:3120::3:443 · spinfest-fr.com
2025-12-20 06:50
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 06:50:26 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Crxjh0dCy%2FAlzNP8YzDdrhiNVYJ2ePKyDRCIF%2BTw2EqNWhOxMgwRAehXfVhxsvLTvZ%2FlFV6p%2BZyHIG2%2BXsU6TZkwQdoBVOvbxVJ3sNYLPdAg2gZ1uaL1qlbLeg%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 06:50:25 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=1103
CF-RAY: 9b0d3491cc0cf93a-SIN
Open service 188.114.97.3:443 · spinfest-fr.com
2025-12-19 04:54
HTTP/1.1 200 OK
Date: Fri, 19 Dec 2025 04:54:14 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=UC6lRD2JZQRKQjtRdn9p%2BOCrVlqwGFOWtRq8J20f2pYmlSgicaxu1ZapZaZXpyhB9KeNIEsK7QfTwzik%2Fd%2FLw5xAajnOx2AuOkV%2F3LInmg%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 19 Jan 2026 04:54:14 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=13,cfOrigin;dur=802
CF-RAY: 9b044d01b9984245-EWR