nginx
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c248e4f81248e4f81cb3a648f866d48075ab2ff1828e84f37
Found 41 files trough .DS_Store spidering: /assets /css /css/mobile /dist /dist/js /fonts /images /images/admin /images/award /images/bot /images/collectword /images/corp /images/corpClinetRed /images/corpTask /images/cutprice /images/define /images/defineposter /images/desc /images/distribution /images/emoji /images/goodscode /images/groupPurchase /images/hypermarket /images/icon /images/livefission /images/liveturn /images/login /images/markPersonal /images/mobile /images/mobileCenter /images/official /images/proxy /images/share /images/test /images/thirdPart /images/vrheader /images/yzmpic /js /lib /svg /vendor
Severity: low
Fingerprint: 5f32cf5d6962f09cec7f8772ec7f877272a0bbae9752f4b6fa843b4b9976b809
Found 11 files trough .DS_Store spidering: /assets /css /css/mobile /dist /dist/js /fonts /images /js /lib /svg /vendor
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733fa0a2250193180dc12de2311a8bc1ef61
Found 10 files trough .DS_Store spidering: /assets /css /css/mobile /dist /fonts /images /js /lib /svg /vendor
Severity: low
Fingerprint: 5f32cf5d6962f09c684e525d684e525dcca2f42b547ac94b615547c351388a1e
Found 27 files trough .DS_Store spidering: /assets /css /css/admin /css/batch /css/channel /css/corpTask /css/crop /css/distribution /css/fan /css/fonts /css/groupPurchase /css/lib /css/mobile /css/offline /css/qrcord /css/review /css/scan /css/subgift /css/superreply /css/task /dist /fonts /images /js /lib /svg /vendor
The application has Laravel development panel enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 3ae8115d762f12d0fd32b3abfd32b3abfd32b3abfd32b3abfd32b3abfd32b3ab
Laravel Telescope enabled at https://syw.weigou007.com
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c3af247253af247259b6c8633f00cb043a175e1827b38d4d4
Found 9 files trough .DS_Store spidering: /assets /css /dist /fonts /images /js /lib /svg /vendor
Open service 182.44.41.47:443 · syw.weigou007.com
2024-12-22 01:58
HTTP/1.1 200 OK Server: nginx Date: Sun, 22 Dec 2024 01:58:55 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding X-Powered-By: PHP/7.2.31 Cache-Control: private, must-revalidate pragma: no-cache expires: -1 Set-Cookie: laravel_session=YPmQ4cpcCJXLx75z0YYtQtMpsjgo5vGqlJzoAFt6; expires=Mon, 30-Dec-2024 09:58:55 GMT; Max-Age=720000; path=/; httponly Strict-Transport-Security: max-age=31536000 Page title: 微老大私域王 <!DOCTYPE html v-cloak> <html lang="zh" style="height: 100%; font-size: 100px;"> <head> <meta charset="UTF-8" /> <meta name="viewport" content="width=device-width, initial-scale=1"> <meta http-equiv="X-UA-Compatible" content="ie=edge" /> <title>微老大私域王</title> <link rel="icon" href="/images/titleImg.png"/> <!-- <script src="/js/test.js"></script> --> <link rel="stylesheet" type="text/css" href="/css/login.css" /> <link rel="stylesheet" type="text/css" href="//at.alicdn.com/t/font_1565580_jgju61az6di.css" /> <script src="/lib/all.js"></script> <script src="/lib/axios.js?_version="></script> <script src="/lib/vue.js?_version="></script> <script src="/js/copy.js"></script> <script src="/lib/bootstrap.min.js?_version="></script> <link href="/lib/element/index.css?_version=" rel="stylesheet"> <script src="/js/elementUI.js?_version="></script> <style> .message p a{ color: #7A8A9A; } .message1 p a{ color: #000; } .back1Img { position: fixed; top: 0; left: 0; width: 100%; height: 100%; z-index: -999; object-fit: cover; background-repeat: no-repeat; } .cover1Img{ position: fixed; left: 50%; top: 50%; transform: translate(-50%,-50%); width: 65vw; height: 25vw; z-index: -888; object-fit: cover; border-radius: 10px; } .cover2Img{ position: fixed; right: 5.2%; top: 50%; transform: translatey(-50%); width: 37.5vw; height: 83.33vh; z-index: -888; border-radius:0 20px 20px 0 ; } .temp1Content{ top: 50%; left: 65%; transform: translate(-50%, -50%); position: fixed; width: 31.25vw; height: 30vw; background: #FFFFFF; box-shadow: 0px 0px 10px 1px rgba(54,130,244,0.49); border-radius: 8px 8px 8px 8px; display: flex; flex-direction: column; justify-content: space-evenly; align-items: center; } .temp2Content{ top: 50%; right: 42.7%; transform: translatey(-50%); position: fixed; width: 27.08vw; height: 83.33vh; background: #FFFFFF; box-shadow: 0px 0px 10px 1px rgba(0,0,0,0.13); border-radius:20px 0 0 20px; display: flex; flex-direction: column; justify-content: space-evenly; align-items: center; overflow: auto; } .inputContainer{ display: flex; justify-content: center; align-items: center; border-bottom: 1px solid #dfdfdf; padding: 0.7vw 0.7vw 0.7vw 0; } .inputBody{ min-width: 0; flex:1; border: none; outline: none; margin-left: 0.2rem; font-size: .15rem; } @media (max-width: 600px) { .temp1Content { width: 80%; left: 50%; height: 80vw; transform: translate(-50%,-50%); min-width: 200px; min-height: 200px; } .temp2Content { width: 80% !important; left: 50%; height: 80vw; transform: translate(-50%,-50%); min-width: 200px; min-height: 200px; border-radius: 20px; } .cover2Img{ width: 0; height: 0; } .logi
Open service 8.136.147.135:443 · syw.weigou007.com
2024-12-20 05:02
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 05:02:49 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=8da87f897779ea019573ad0fd2ff0194; expires=Sat, 21-Dec-2024 05:02:49 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 8.136.147.135:443 · syw.weigou007.com
2024-12-18 05:53
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 05:53:24 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=ae25aec2d046f06affbfb0cf6e598690; expires=Thu, 19-Dec-2024 05:53:24 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 8.136.147.135:443 · syw.weigou007.com
2024-12-16 02:53
HTTP/1.1 302 Found Server: nginx Date: Mon, 16 Dec 2024 02:53:18 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=be5c4d575bac87a2d88441c26ec90426; expires=Tue, 17-Dec-2024 02:53:18 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 8.136.147.135:443 · syw.weigou007.com
2024-12-12 04:58
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 04:58:49 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=8500f1f5626c0847d5f1905bc959c865; expires=Fri, 13-Dec-2024 04:58:49 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 8.136.147.135:443 · syw.weigou007.com
2024-12-02 12:13
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 12:14:02 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=23e34ea90c7b2771ed1218abf2064247; expires=Tue, 03-Dec-2024 12:14:02 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 182.44.41.47:443 · syw.weigou007.com
2024-11-30 07:14
HTTP/1.1 200 OK Server: nginx Date: Sat, 30 Nov 2024 07:14:59 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding X-Powered-By: PHP/7.2.31 Cache-Control: private, must-revalidate pragma: no-cache expires: -1 Set-Cookie: laravel_session=MmXt3ZurSsSiQOYovdhK4F8ffFtQEJiNdRE2Xs6e; expires=Sun, 08-Dec-2024 15:14:59 GMT; Max-Age=720000; path=/; httponly Strict-Transport-Security: max-age=31536000 Page title: 微老大私域王 <!DOCTYPE html v-cloak> <html lang="zh" style="height: 100%; font-size: 100px;"> <head> <meta charset="UTF-8" /> <meta name="viewport" content="width=device-width, initial-scale=1"> <meta http-equiv="X-UA-Compatible" content="ie=edge" /> <title>微老大私域王</title> <link rel="icon" href="/images/titleImg.png"/> <!-- <script src="/js/test.js"></script> --> <link rel="stylesheet" type="text/css" href="/css/login.css" /> <link rel="stylesheet" type="text/css" href="//at.alicdn.com/t/font_1565580_jgju61az6di.css" /> <script src="/lib/all.js"></script> <script src="/lib/axios.js?_version="></script> <script src="/lib/vue.js?_version="></script> <script src="/js/copy.js"></script> <script src="/lib/bootstrap.min.js?_version="></script> <link href="/lib/element/index.css?_version=" rel="stylesheet"> <script src="/js/elementUI.js?_version="></script> <style> .message p a{ color: #7A8A9A; } .message1 p a{ color: #000; } .back1Img { position: fixed; top: 0; left: 0; width: 100%; height: 100%; z-index: -999; object-fit: cover; background-repeat: no-repeat; } .cover1Img{ position: fixed; left: 50%; top: 50%; transform: translate(-50%,-50%); width: 65vw; height: 25vw; z-index: -888; object-fit: cover; border-radius: 10px; } .cover2Img{ position: fixed; right: 5.2%; top: 50%; transform: translatey(-50%); width: 37.5vw; height: 83.33vh; z-index: -888; border-radius:0 20px 20px 0 ; } .temp1Content{ top: 50%; left: 65%; transform: translate(-50%, -50%); position: fixed; width: 31.25vw; height: 30vw; background: #FFFFFF; box-shadow: 0px 0px 10px 1px rgba(54,130,244,0.49); border-radius: 8px 8px 8px 8px; display: flex; flex-direction: column; justify-content: space-evenly; align-items: center; } .temp2Content{ top: 50%; right: 42.7%; transform: translatey(-50%); position: fixed; width: 27.08vw; height: 83.33vh; background: #FFFFFF; box-shadow: 0px 0px 10px 1px rgba(0,0,0,0.13); border-radius:20px 0 0 20px; display: flex; flex-direction: column; justify-content: space-evenly; align-items: center; overflow: auto; } .inputContainer{ display: flex; justify-content: center; align-items: center; border-bottom: 1px solid #dfdfdf; padding: 0.7vw 0.7vw 0.7vw 0; } .inputBody{ min-width: 0; flex:1; border: none; outline: none; margin-left: 0.2rem; font-size: .15rem; } @media (max-width: 600px) { .temp1Content { width: 80%; left: 50%; height: 80vw; transform: translate(-50%,-50%); min-width: 200px; min-height: 200px; } .temp2Content { width: 80% !important; left: 50%; height: 80vw; transform: translate(-50%,-50%); min-width: 200px; min-height: 200px; border-radius: 20px; } .cover2Img{ width: 0; height: 0; } .logi
Open service 8.136.147.135:443 · syw.weigou007.com
2024-11-30 01:21
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 01:21:47 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=8ecd7de61b841e0bee39f9e0213815f8; expires=Sun, 01-Dec-2024 01:21:47 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 8.136.147.135:443 · syw.weigou007.com
2024-11-28 01:30
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 01:30:10 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=b18d2058fd62571cc2152ea62d195aa4; expires=Fri, 29-Nov-2024 01:30:10 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000
Open service 8.136.147.135:443 · syw.weigou007.com
2024-11-20 11:59
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 11:59:51 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Location: /admin/auth/login.html Cache-control: no-cache,must-revalidate Set-Cookie: redirect_url=%2F; path=/ Set-Cookie: PHPSESSID=c3454c06403f24a3b36e6e58d18a4304; expires=Thu, 21-Nov-2024 11:59:51 GMT; Max-Age=86400; path=/ Strict-Transport-Security: max-age=31536000