AmazonS3
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c48b4adea48b4adea106df51d03fdc43e57333c427a7338c5
Found 91 files trough .DS_Store spidering: /ajax-loader.gif /amazon-federate.png /AmazonEmber /AmazonEmber_Bd.woff2 /AmazonEmber_Rg.woff2 /AmazonEmber_W_Lt.woff2 /aws-cloud.png /aws-header-bg.jpg /aws-jam-logo-150x150.png /aws-jam-logo-200x200.png /aws-jam-logo-70x70.png /aws-jam-logo-alt-2.png /aws-jam-logo-alt-3.png /aws-jam-logo-alt.png /aws-jam-logo-gray.png /aws-jam-logo-green.png /aws-jam-logo.png /aws-jam-short.mp4 /aws-logo-black.png /aws-logo.png /aws-re-inforce-logo.svg /aws-summit-sf.png /aws-training.png /AWS_ProServ_Lockup-OnDark.png /aws_sko_2017.png /background-cubes.png /BlankMap-World_gray.svg /challenge-status-workflow-polaris.png /challenge-status-workflow.png /challenges.png /cloudformation.png /clues.png /code-whisperer-logo-black.png /complete-icon.png /completed-warmup-challenge.jpg /css /cute-monkey-alt-2.png /cute-monkey-alt-3.png /cute-monkey-alt.png /cute-monkey.png /datacenter.png /dc-summit-2017-logo.png /download-samples /event-template-details-image-thumbnail.png /event-template-details-page-image.png /favicon.ico /first-logo.png /grid.png /incident-response.png /intern-panic.jpeg /jam-logo-black-transparent-alt.png /jam-logo-green-transparent-alt.png /jam-logo-white-transparent-alt.png /jam-logo-white-transparent.png /jam-spinner.css /js /leaderboard.png /loading.gif /macbook-leaderboard.png /map-black.png /map-green.png /map-white.png /monkey-small.jpeg /monolithic-problems.jpeg /mozilla-logo-blue-transparent.png /mozilla-logo-blue.png /oculus-rift.png /rank.png /reinforce-jam.png /reinforce2019.png /reinvent-keynote.png /reinvent18-sponsor-logos.png /reinvent18-sponsor-map.png /reinvent_logo.png /replay.png /score.png /security-jam-jitter.mp4 /security-jam.png /server.png /servers.png /SKO-2021.mp4 /splash.jpg /splash.png /splash_transparent.png /splunk_logo.png /tech-summit.png /Tech_Day_2018_Logo_white.png /trendmicro_logo.png /vr-experience.png /warmup-challenge.jpg /warmup.png
Open service 18.244.18.38:443 · static.jam.awsevents.com
2026-01-23 11:29
HTTP/1.1 403 Forbidden Content-Type: application/xml Transfer-Encoding: chunked Connection: close Server: AmazonS3 Date: Fri, 23 Jan 2026 11:29:20 GMT X-Cache: Error from cloudfront Via: 1.1 0be2062deeede74cb37dc047454ddbce.cloudfront.net (CloudFront) X-Amz-Cf-Pop: FRA56-P11 X-Amz-Cf-Id: TAcxraoDU2N_aHM-D2e9iFdDOpzaww7FAnAOqA6tIVnbsooBEP1teg== X-XSS-Protection: 1; mode=block X-Frame-Options: DENY Referrer-Policy: same-origin Content-Security-Policy: upgrade-insecure-requests; default-src 'none'; frame-src https://www.google.com/recaptcha/ https://us-west-2.quicksight.aws.amazon.com https://www.recaptcha.net/recaptcha/ https://aws.demdex.net https://dpm.demdex.net; media-src 'self' https://s3-us-west-2.amazonaws.com/aws-jam-challenge-resources https://aws-jam-challenge-resources.s3.amazonaws.com; img-src 'self' data: https://s3-us-west-2.amazonaws.com/aws-jam-challenge-resources https://aws-jam-challenge-resources.s3.amazonaws.com https://dashboard.eventengine.run https://ba0.awsstatic.com/ https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net; script-src 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.google.cn/recaptcha/ https://www.recaptcha.net/recaptcha/ https://ba0.awsstatic.com/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; frame-ancestors 'none'; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://*.amazonaws.com wss://*.amazonaws.com https://*.amazoncognito.com https://*.chime.aws wss://*.chime.aws https://*.shortbread.aws.dev https://api.jam.awsevents.com https://ba0.awsstatic.com/ https://d2c-beta.dse.marketing.aws.a2z.com https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net; X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=47304000; includeSubDomains; preload <?xml version="1.0" encoding="UTF-8"?> <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
Open service 18.244.18.38:443 · static.jam.awsevents.com
2026-01-09 11:54
HTTP/1.1 403 Forbidden Content-Type: application/xml Transfer-Encoding: chunked Connection: close Server: AmazonS3 Date: Fri, 09 Jan 2026 11:54:50 GMT X-Cache: Error from cloudfront Via: 1.1 012ed5015dc2306833b5abb65b3a0378.cloudfront.net (CloudFront) X-Amz-Cf-Pop: FRA56-P11 X-Amz-Cf-Id: 4Lh6pNShOGYAvh_fUlR8o_mhiH1V57HYIyjH52aA21TARyuhRknQzw== X-XSS-Protection: 1; mode=block X-Frame-Options: DENY Referrer-Policy: same-origin Content-Security-Policy: upgrade-insecure-requests; default-src 'none'; frame-src https://www.google.com/recaptcha/ https://us-west-2.quicksight.aws.amazon.com https://www.recaptcha.net/recaptcha/ https://aws.demdex.net https://dpm.demdex.net; media-src 'self' https://s3-us-west-2.amazonaws.com/aws-jam-challenge-resources https://aws-jam-challenge-resources.s3.amazonaws.com; img-src 'self' data: https://s3-us-west-2.amazonaws.com/aws-jam-challenge-resources https://aws-jam-challenge-resources.s3.amazonaws.com https://dashboard.eventengine.run https://ba0.awsstatic.com/ https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net; script-src 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.google.cn/recaptcha/ https://www.recaptcha.net/recaptcha/ https://ba0.awsstatic.com/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; frame-ancestors 'none'; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://*.amazonaws.com wss://*.amazonaws.com https://*.amazoncognito.com https://*.chime.aws wss://*.chime.aws https://*.shortbread.aws.dev https://api.jam.awsevents.com https://ba0.awsstatic.com/ https://d2c-beta.dse.marketing.aws.a2z.com https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net; X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=47304000; includeSubDomains; preload <?xml version="1.0" encoding="UTF-8"?> <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>
Open service 18.244.18.38:443 · static.jam.awsevents.com
2025-12-22 23:15
HTTP/1.1 403 Forbidden Content-Type: application/xml Transfer-Encoding: chunked Connection: close Server: AmazonS3 Date: Mon, 22 Dec 2025 23:15:25 GMT X-Cache: Error from cloudfront Via: 1.1 e4f83d72be7853fbcceb590827a5b68a.cloudfront.net (CloudFront) X-Amz-Cf-Pop: FRA56-P11 X-Amz-Cf-Id: Ldm5yYrGlVNQyuHvq39l5dEyaSgv_IGHcVHGxKuYIHI0FFv8cMXmxg== X-XSS-Protection: 1; mode=block X-Frame-Options: DENY Referrer-Policy: same-origin Content-Security-Policy: upgrade-insecure-requests; default-src 'none'; frame-src https://www.google.com/recaptcha/ https://us-west-2.quicksight.aws.amazon.com https://www.recaptcha.net/recaptcha/ https://aws.demdex.net https://dpm.demdex.net; media-src 'self' https://s3-us-west-2.amazonaws.com/aws-jam-challenge-resources https://aws-jam-challenge-resources.s3.amazonaws.com; img-src 'self' data: https://s3-us-west-2.amazonaws.com/aws-jam-challenge-resources https://aws-jam-challenge-resources.s3.amazonaws.com https://dashboard.eventengine.run https://ba0.awsstatic.com/ https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net; script-src 'self' https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.google.cn/recaptcha/ https://www.recaptcha.net/recaptcha/ https://ba0.awsstatic.com/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; object-src 'none'; frame-ancestors 'none'; font-src 'self' https://fonts.gstatic.com data:; connect-src 'self' https://*.amazonaws.com wss://*.amazonaws.com https://*.amazoncognito.com https://*.chime.aws wss://*.chime.aws https://*.shortbread.aws.dev https://api.jam.awsevents.com https://ba0.awsstatic.com/ https://d2c-beta.dse.marketing.aws.a2z.com https://amazonwebservices.d2.sc.omtrdc.net https://aws.demdex.net https://dpm.demdex.net https://cm.everesttech.net; X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=47304000; includeSubDomains; preload <?xml version="1.0" encoding="UTF-8"?> <Error><Code>AccessDenied</Code><Message>Access Denied</Message></Error>