.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c4239b3d84239b3d86bfb45c8b0a4b69ccf6d8952044adce9
Found 8 files trough .DS_Store spidering: /assets /fft.js /index.html /manifest.json /onnx /robots.txt /vad /vad-audio-worklet.js
Open service 20.82.12.44:443 · teams.app.dev.sbrain.fr
2026-01-09 00:44
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 00:45:52 GMT Location: https://app.dev.sbrain.fr/ Content-Security-Policy: default-src 'self' https: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; img-src 'self' https://media.sbrain.io https://media.sbrain.io https://maps.gstatic.com https://maps.googleapis.com blob: data: https://lh3.googleusercontent.com https://sbdatahub.blob.core.windows.net; connect-src 'self' blob: wss://*.sbrain.io wss://*.sbrain.fr https://graph.microsoft.com https://*.sbrain.io https://*.sbrain.fr https://maps.googleapis.com https://maps.gstatic.com https://sbdatahub.blob.core.windows.net https://res.cdn.office.net https://ka-f.fontawesome.com https://js.monitor.azure.com https://dc.services.visualstudio.com https://*.applicationinsights.azure.com https://*.in.applicationinsights.azure.com; script-src 'self' https://trustedscripts.com https://kit.fontawesome.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; permissions-policy: microphone=*, camera=*, geolocation=*, media-playback-while-not-visible=*
Open service 20.82.12.44:443 · teams.app.dev.sbrain.fr
2026-01-01 23:36
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Thu, 01 Jan 2026 23:36:05 GMT Location: https://app.dev.sbrain.fr/ Content-Security-Policy: default-src 'self' https: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; img-src 'self' https://media.sbrain.io https://media.sbrain.io https://maps.gstatic.com https://maps.googleapis.com blob: data: https://lh3.googleusercontent.com https://sbdatahub.blob.core.windows.net; connect-src 'self' blob: wss://*.sbrain.io wss://*.sbrain.fr https://graph.microsoft.com https://*.sbrain.io https://*.sbrain.fr https://maps.googleapis.com https://maps.gstatic.com https://sbdatahub.blob.core.windows.net https://res.cdn.office.net https://ka-f.fontawesome.com https://js.monitor.azure.com https://dc.services.visualstudio.com https://*.applicationinsights.azure.com https://*.in.applicationinsights.azure.com; script-src 'self' https://trustedscripts.com https://kit.fontawesome.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; permissions-policy: microphone=*, camera=*, geolocation=*, media-playback-while-not-visible=*
Open service 20.82.12.44:443 · teams.app.dev.sbrain.fr
2025-12-30 09:48
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Tue, 30 Dec 2025 09:48:44 GMT Location: https://app.dev.sbrain.fr/ Content-Security-Policy: default-src 'self' https: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; img-src 'self' https://media.sbrain.io https://media.sbrain.io https://maps.gstatic.com https://maps.googleapis.com blob: data: https://lh3.googleusercontent.com https://sbdatahub.blob.core.windows.net; connect-src 'self' blob: wss://*.sbrain.io wss://*.sbrain.fr https://graph.microsoft.com https://*.sbrain.io https://*.sbrain.fr https://maps.googleapis.com https://maps.gstatic.com https://sbdatahub.blob.core.windows.net https://res.cdn.office.net https://ka-f.fontawesome.com https://js.monitor.azure.com https://dc.services.visualstudio.com https://*.applicationinsights.azure.com https://*.in.applicationinsights.azure.com; script-src 'self' https://trustedscripts.com https://kit.fontawesome.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; permissions-policy: microphone=*, camera=*, geolocation=*, media-playback-while-not-visible=*
Open service 20.82.12.44:443 · teams.app.dev.sbrain.fr
2025-12-22 11:51
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 11:51:11 GMT Location: https://app.dev.sbrain.fr/ Content-Security-Policy: default-src 'self' https: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; img-src 'self' https://media.sbrain.io https://media.sbrain.io https://maps.gstatic.com https://maps.googleapis.com blob: data: https://lh3.googleusercontent.com https://sbdatahub.blob.core.windows.net; connect-src 'self' blob: wss://*.sbrain.io wss://*.sbrain.fr https://graph.microsoft.com https://*.sbrain.io https://*.sbrain.fr https://maps.googleapis.com https://maps.gstatic.com https://sbdatahub.blob.core.windows.net https://res.cdn.office.net https://ka-f.fontawesome.com https://js.monitor.azure.com https://dc.services.visualstudio.com https://*.applicationinsights.azure.com https://*.in.applicationinsights.azure.com; script-src 'self' https://trustedscripts.com https://kit.fontawesome.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; permissions-policy: microphone=*, camera=*, geolocation=*, media-playback-while-not-visible=*
Open service 20.82.12.44:443 · teams.app.dev.sbrain.fr
2025-12-20 12:52
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sat, 20 Dec 2025 12:52:22 GMT Location: https://app.dev.sbrain.fr/ Content-Security-Policy: default-src 'self' https: 'unsafe-eval' 'unsafe-inline'; object-src 'none'; img-src 'self' https://media.sbrain.io https://media.sbrain.io https://maps.gstatic.com https://maps.googleapis.com blob: data: https://lh3.googleusercontent.com https://sbdatahub.blob.core.windows.net; connect-src 'self' blob: wss://*.sbrain.io wss://*.sbrain.fr https://graph.microsoft.com https://*.sbrain.io https://*.sbrain.fr https://maps.googleapis.com https://maps.gstatic.com https://sbdatahub.blob.core.windows.net https://res.cdn.office.net https://ka-f.fontawesome.com https://js.monitor.azure.com https://dc.services.visualstudio.com https://*.applicationinsights.azure.com https://*.in.applicationinsights.azure.com; script-src 'self' https://trustedscripts.com https://kit.fontawesome.com https://maps.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; permissions-policy: microphone=*, camera=*, geolocation=*, media-playback-while-not-visible=*