envoy
tcp/443
nginx
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d60b2ea5f828fc0503d0d9f7319866afd6ba1b2fa06
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /account/profile
GET /auth/register
GET /auth/rotate-secret
GET /customlobby
GET /device
GET /device/data
GET /experiences
GET /experiences/{experienceId}/invitation
GET /headsetcenters
GET /langs
GET /lobby/get-version
GET /lobbycore
GET /servicecore
GET /setup/download/{id}
GET /setup/get-last-version
GET /turn/credentials
GET /videoplayer
GET /videoplayer/get-download-url
GET /videoplayer/get-last-version
PATCH /experiences/{experienceId}/installed
PATCH /experiences/{experienceId}/removed
POST /auth/login
POST /auth/refresh
POST /experiences/session/{experienceId}/{experienceType}/started
POST /experiences/session/{sessionId}/stopped
POST /experiences/{experienceId}/notations
POST /experiences/{experienceId}/notations/{notationId}/screenshot
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d60b2ea5f828fc0503d0d9f7319866afd6b2857e481
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /account/profile
GET /auth/register
GET /auth/rotate-secret
GET /customlobby
GET /device
GET /experiences
GET /experiences/{experienceId}/invitation
GET /headsetcenters
GET /langs
GET /lobby/get-version
GET /lobbycore
GET /servicecore
GET /setup/download/{id}
GET /setup/get-last-version
GET /videoplayer
GET /videoplayer/get-download-url
GET /videoplayer/get-last-version
PATCH /experiences/{experienceId}/installed
PATCH /experiences/{experienceId}/removed
POST /auth/login
POST /auth/refresh
POST /experiences/session/{experienceId}/{experienceType}/started
POST /experiences/session/{sessionId}/stopped
POST /experiences/{experienceId}/notations
POST /experiences/{experienceId}/notations/{notationId}/screenshot
Open service 85.208.145.196:443 · staging-standalone.vrcxp.com
2026-01-23 16:29
HTTP/1.1 301 Moved Permanently content-length: 0 date: Fri, 23 Jan 2026 16:29:32 GMT server: envoy location: index.html x-envoy-upstream-service-time: 1 connection: close
Open service 85.208.144.202:443 · staging-standalone.vrcxp.com
2026-01-09 20:03
HTTP/1.1 301 Moved Permanently Server: nginx Date: Fri, 09 Jan 2026 20:03:34 GMT Content-Length: 0 Connection: close Location: index.html Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: same-origin X-Clacks-Overhead: GNU Terry Pratchett
Open service 85.208.144.202:443 · staging-standalone.vrcxp.com
2026-01-02 18:24
HTTP/1.1 301 Moved Permanently Server: nginx Date: Fri, 02 Jan 2026 18:24:53 GMT Content-Length: 0 Connection: close Location: index.html Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: same-origin X-Clacks-Overhead: GNU Terry Pratchett
Open service 85.208.144.202:443 · staging-standalone.vrcxp.com
2025-12-22 23:58
HTTP/1.1 301 Moved Permanently Server: nginx Date: Mon, 22 Dec 2025 23:58:49 GMT Content-Length: 0 Connection: close Location: index.html Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Referrer-Policy: same-origin X-Clacks-Overhead: GNU Terry Pratchett