Apache
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c11d3744d11d3744d186028153dfdadc2dee0c43b7994db78
Found 12 files trough .DS_Store spidering: /404.html /500.html /build /cors /favicon.ico /holding.html /import_accounts.csv /import_meetings.csv /index.php /outlook /robots.txt /uploads
Open service 2.17.100.146:443 · test-hoteling.saipem.com
2026-01-23 10:32
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache, private
Location: /account/login
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: ALLOW-FROM https://teams.microsoft.com/
Content-Length: 302
Date: Fri, 23 Jan 2026 10:32:03 GMT
Connection: close
Page title: Redirecting to /account/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/account/login'" />
<title>Redirecting to /account/login</title>
</head>
<body>
Redirecting to <a href="/account/login">/account/login</a>.
</body>
</html>
Open service 2.17.100.146:443 · test-hoteling.saipem.com
2026-01-09 19:35
HTTP/1.1 302 Moved Temporarily
Server: Apache
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache, private
Location: /account/login
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: ALLOW-FROM https://teams.microsoft.com/
Content-Length: 302
Date: Fri, 09 Jan 2026 19:35:29 GMT
Connection: close
Page title: Redirecting to /account/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/account/login'" />
<title>Redirecting to /account/login</title>
</head>
<body>
Redirecting to <a href="/account/login">/account/login</a>.
</body>
</html>
Open service 2.17.100.146:443 · test-hoteling.saipem.com
2026-01-02 22:25
HTTP/1.1 302 Moved Temporarily
Server: Apache
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache, private
Location: /account/login
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: ALLOW-FROM https://teams.microsoft.com/
Content-Length: 302
Date: Fri, 02 Jan 2026 22:25:53 GMT
Connection: close
Page title: Redirecting to /account/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/account/login'" />
<title>Redirecting to /account/login</title>
</head>
<body>
Redirecting to <a href="/account/login">/account/login</a>.
</body>
</html>
Open service 2.17.100.146:443 · test-hoteling.saipem.com
2025-12-23 06:34
HTTP/1.1 302 Moved Temporarily
Server: Apache
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache, private
Location: /account/login
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: ALLOW-FROM https://teams.microsoft.com/
Content-Length: 302
Date: Tue, 23 Dec 2025 06:34:07 GMT
Connection: close
Page title: Redirecting to /account/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/account/login'" />
<title>Redirecting to /account/login</title>
</head>
<body>
Redirecting to <a href="/account/login">/account/login</a>.
</body>
</html>