nginx
tcp/443 tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522ecb1e86f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@gitlab.endora.pl:endora/alphastats.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07b9764778b9764778b9764778b9764778b9764778
Symfony profiler enabled: https://sutru.endora.dev/_profiler/empty/search/results
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07fe5ce83bfe5ce83bfe5ce83bfe5ce83bfe5ce83b
Symfony profiler enabled: https://www.sutru.endora.dev/_profiler/empty/search/results
Open service 185.180.204.108:443 · www.sutru.endora.dev
2024-05-13 03:02
HTTP/1.1 302 Found Server: nginx Date: Mon, 13 May 2024 03:02:43 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.0.28 Location: https://alphastats.pl/wp-signup.php?new=www.sutru.endora.dev
Open service 185.180.204.108:443 · sutru.endora.dev
2024-05-12 21:02
HTTP/1.1 404 Not Found Server: nginx Date: Sun, 12 May 2024 21:02:40 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.11 Cache-Control: no-cache, private Link: <http://sutru.endora.dev/api/docs?_format=jsonld>; rel="http://www.w3.org/ns/hydra/core#apiDocumentation" X-Debug-Token: e95834 X-Debug-Token-Link: http://sutru.endora.dev/_profiler/e95834 X-Robots-Tag: noindex
Open service 185.180.204.108:443 · www.sutru.endora.dev
2024-05-08 21:48
HTTP/1.1 302 Found Server: nginx Date: Wed, 08 May 2024 21:48:14 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.0.28 Location: https://alphastats.pl/wp-signup.php?new=www.sutru.endora.dev
Open service 185.180.204.108:443 · sutru.endora.dev
2024-05-08 13:54
HTTP/1.1 404 Not Found Server: nginx Date: Wed, 08 May 2024 13:54:20 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.11 Cache-Control: no-cache, private Link: <http://sutru.endora.dev/api/docs?_format=jsonld>; rel="http://www.w3.org/ns/hydra/core#apiDocumentation" X-Debug-Token: 7acad5 X-Debug-Token-Link: http://sutru.endora.dev/_profiler/7acad5 X-Robots-Tag: noindex
Open service 185.180.204.108:80 · www.sutru.endora.dev
2024-05-01 07:14
HTTP/1.1 301 Moved Permanently Server: nginx Date: Wed, 01 May 2024 07:14:48 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://sutru.endora.dev/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 185.180.204.108:443 · www.sutru.endora.dev
2024-05-01 07:14
HTTP/1.1 302 Found Server: nginx Date: Wed, 01 May 2024 07:14:48 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.0.28 Location: https://alphastats.pl/wp-signup.php?new=www.sutru.endora.dev
Open service 185.180.204.108:443 · sutru.endora.dev
2024-05-01 07:14
HTTP/1.1 404 Not Found Server: nginx Date: Wed, 01 May 2024 07:14:49 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.11 Cache-Control: no-cache, private Link: <http://sutru.endora.dev/api/docs?_format=jsonld>; rel="http://www.w3.org/ns/hydra/core#apiDocumentation" X-Debug-Token: 732d11 X-Debug-Token-Link: http://sutru.endora.dev/_profiler/732d11 X-Robots-Tag: noindex
Open service 185.180.204.108:80 · sutru.endora.dev
2024-05-01 07:14
HTTP/1.1 301 Moved Permanently Server: nginx Date: Wed, 01 May 2024 07:14:48 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://sutru.endora.dev/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 185.180.204.108:443 · sutru.endora.dev
2024-05-01 02:17
HTTP/1.1 404 Not Found Server: nginx Date: Wed, 01 May 2024 02:17:40 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.11 Cache-Control: no-cache, private Link: <http://sutru.endora.dev/api/docs?_format=jsonld>; rel="http://www.w3.org/ns/hydra/core#apiDocumentation" X-Debug-Token: 083204 X-Debug-Token-Link: http://sutru.endora.dev/_profiler/083204 X-Robots-Tag: noindex
Open service 185.180.204.108:443 · www.sutru.endora.dev
2024-05-01 01:55
HTTP/1.1 302 Found Server: nginx Date: Wed, 01 May 2024 01:55:13 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.0.28 Location: https://alphastats.pl/wp-signup.php?new=www.sutru.endora.dev
Open service 185.180.204.108:443 · sutru.endora.dev
2024-04-29 01:30
HTTP/1.1 404 Not Found Server: nginx Date: Mon, 29 Apr 2024 01:30:54 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.11 Cache-Control: no-cache, private Link: <http://sutru.endora.dev/api/docs?_format=jsonld>; rel="http://www.w3.org/ns/hydra/core#apiDocumentation" X-Debug-Token: 9f2217 X-Debug-Token-Link: http://sutru.endora.dev/_profiler/9f2217 X-Robots-Tag: noindex
Open service 185.180.204.108:443 · www.sutru.endora.dev
2024-04-28 19:27
HTTP/1.1 302 Found Server: nginx Date: Sun, 28 Apr 2024 19:27:16 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.0.28 Location: https://alphastats.pl/wp-signup.php?new=www.sutru.endora.dev
Open service 185.180.204.108:443 · www.sutru.endora.dev
2024-04-18 21:49
HTTP/1.1 302 Found Server: nginx Date: Thu, 18 Apr 2024 21:49:42 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 0 Connection: close X-Powered-By: PHP/8.0.28 Location: https://alphastats.pl/wp-signup.php?new=www.sutru.endora.dev
Open service 185.180.204.108:443 · sutru.endora.dev
2024-04-18 21:38
HTTP/1.1 404 Not Found Server: nginx Date: Thu, 18 Apr 2024 21:38:24 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.11 Cache-Control: no-cache, private Link: <http://sutru.endora.dev/api/docs?_format=jsonld>; rel="http://www.w3.org/ns/hydra/core#apiDocumentation" X-Debug-Token: 541971 X-Debug-Token-Link: http://sutru.endora.dev/_profiler/541971 X-Robots-Tag: noindex