nginx
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d60bbf16caa188b5e2c6cf374eeaac1bc803ce86fa4
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths: GET /account/get-experience GET /account/get-session GET /chapter GET /dev/changelog/get-latest GET /dev/version GET /end GET /initialize GET /manage/close GET /manage/retry GET /manage/start GET /reporting/check POST /account/generate-access-token POST /account/save-experience POST /action POST /dev/changelog/set POST /manage/update POST /reporting/send POST /reporting/upload-screenshot POST /save
Open service 85.208.144.202:443 · staging-sdk.vrcxp.com
2026-01-09 03:54
HTTP/1.1 301 Moved Permanently Server: nginx Date: Fri, 09 Jan 2026 03:54:04 GMT Content-Length: 0 Connection: close Location: index.html Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: same-origin X-Clacks-Overhead: GNU Terry Pratchett
Open service 85.208.144.202:443 · staging-sdk.vrcxp.com
2026-01-02 09:09
HTTP/1.1 301 Moved Permanently Server: nginx Date: Fri, 02 Jan 2026 09:10:00 GMT Content-Length: 0 Connection: close Location: index.html Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: same-origin X-Clacks-Overhead: GNU Terry Pratchett
Open service 85.208.144.202:443 · staging-sdk.vrcxp.com
2025-12-23 04:00
HTTP/1.1 301 Moved Permanently Server: nginx Date: Tue, 23 Dec 2025 04:00:44 GMT Content-Length: 0 Connection: close Location: index.html Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: same-origin X-Clacks-Overhead: GNU Terry Pratchett