Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 23.36.162.196:443 · topsapi.apmterminals.com
2026-01-08 22:50
HTTP/1.1 200 OK
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Cache-Control: max-age=0
Expires: Thu, 08 Jan 2026 22:51:00 GMT
Date: Thu, 08 Jan 2026 22:51:00 GMT
Content-Length: 204
Connection: close
Set-Cookie: ApplicationGatewayAffinityCORS=b26c81394597e92960f8904af5f0e2b1; Path=/; SameSite=None; Secure
Set-Cookie: ApplicationGatewayAffinity=b26c81394597e92960f8904af5f0e2b1; Path=/
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Set-Cookie: _abck=98FB19A388DCF5BB86C65C20F4339BF5~-1~YAAQ1tXOFxRQXjqbAQAAT1/Onw++DS0pNbtXNZMVrcW44uWl0gKo5j/HsEkUZXwb1hfqdW6Ca3XmhruL6VWvtCUALQCZ5uyDRzFFxHcKI1zS1+BFo1B5HiHfEK/0Gxh+4ZiM3hbnpp6smVvFMjFoN2vXPjtTgOhUAT1+FwP+V+XzaHdu7KmlcEvvjPB04IiGS1aNnrKsuNXhjB/txlli/JMYbRHht/vv1x9ynECoC2spvtAAccrWoD/uV+QZ6QBU27suTAlM7eD8VUHw5EY7pKaDwJyQOT2lKKTKKK5k1jIAhAuidzxXOEGo9HBh9mQkN2xV7uVlE9HAC/XJKKCm0FGe/IzRUrpoDO/aK3uzaqosk+jDUawmoVuKfmX7Zd1Evuqy3SpPLjsQKUQt/UkVQLiZfSjK2mTMv62cYWkMhvExGVByZMLTRfZWWQAPd+q63khkrutWXA2+zNY=~-1~-1~-1~-1~-1; Domain=.apmterminals.com; Path=/; Expires=Fri, 08 Jan 2027 22:51:00 GMT; Max-Age=31536000; Secure
Set-Cookie: bm_sz=DF5350B63388008C9CE3667084D61599~YAAQ1tXOFxVQXjqbAQAAT1/Onx7QV38tb/QX1i8iNVyHfpLnKC/nsVN7cLAAZQkv/drePMv0wzAYLAwDd+icJm3ypnXidIOcFB75hgZFw77vQVKU3JASrb3K7hJpqSC2E4OL8QjmqZ0eCD+3J4Nve/coTGiNrA6NMXUEESQD+MqTWzwgQJSMTHQnWlW/6P+X3zwxCdYL9kpuJastYMkZpdIqBXwfrUUbYFm42k3y4LXPXorZS+jHypugy9I1Z+BLTXGAHEmSOgATm0aIY12RnQdobtFo3CRqpq8U2TYo0w1K1Y5JNk8tFE/I2jLVik+Fr12RwNEaFAXkqaNm4A6SbNd8FHqQURK8xyX52vKC07KIUCwp7Q==~3158597~4470073; Domain=.apmterminals.com; Path=/; Expires=Fri, 09 Jan 2026 02:50:59 GMT; Max-Age=14399
{"status":{"StatusCode":401,"ReasonPhrase":"Unauthorized"},"responseBody":{"ResponseData":null,"UserMessages":[{"MessageNo":602,"MessageDescription":"Requested token is not found.","MessageSeverity":3}]}}
Open service 23.36.162.196:443 · topsapi.apmterminals.com
2026-01-01 22:10
HTTP/1.1 200 OK
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Cache-Control: max-age=0
Expires: Thu, 01 Jan 2026 22:10:11 GMT
Date: Thu, 01 Jan 2026 22:10:11 GMT
Content-Length: 204
Connection: close
Set-Cookie: ApplicationGatewayAffinityCORS=b26c81394597e92960f8904af5f0e2b1; Path=/; SameSite=None; Secure
Set-Cookie: ApplicationGatewayAffinity=b26c81394597e92960f8904af5f0e2b1; Path=/
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Set-Cookie: _abck=544F99F3CF38DB718B69EC0E128E3338~-1~YAAQ1tXOFw6QIjWbAQAAcnqcew80hPoCmv764LV9kwac87zoN51VXkFb/wrIoNNrBoa4r57ArnoXZWskVc0HmnkAJ8Fz16p2/NX/SQeL2/YYytxei/ZApcHNsR14OHMz9h10+qd7zAR3WYxW7jXXAHf894WwXtvqyWxmG+eT7ZnUuYyAN9u2s2EEwp/hWlDmNb2+AspJepA/e78aqN3LXoEBLkO1IIYbogplbVtpd/XpFYhoff3uz2yaa5+PkmLQJUJsMNONexAL9/BsvFmU2+MAew+cgYITQlhoQpyFDImCPgGDUjmfqj4aQhJK4oxZyLUUuNIBfsFIfp00nGnrvbI65e2aR/wYWjt5k3ah5Cf1QCi9yu3xH8WoiF7TgmVCdNa0/RRqrxr0htNvBgCzxg3mM3txdIPscwNPL6pGD+FQJmNF6NODsVcoZjPadz0e17xCS6z0ytIPrYw=~-1~-1~-1~-1~-1; Domain=.apmterminals.com; Path=/; Expires=Fri, 01 Jan 2027 22:10:11 GMT; Max-Age=31536000; Secure
Set-Cookie: bm_sz=81C853223DD33F68005F79CEE4D704C6~YAAQ1tXOFw+QIjWbAQAAcnqcex61fX+EIancX6qNO4dQmZous2kh0lT2oqnfv6X68EsZ5Th+d5IzTVIlvcl0coH2F/5xsRFUrY+Q4YG7d2p1D7eAHA2Dg3+AM4CmVFU5SnXDuZczTh8i+Z22QwQ9aRQLjSVU92G+bVMRLZU/J8NBR+AzXrpApvyrmM8Dwq5CmB+ymZVv9rQ7yCf0SPbfddKnGUpwibQqi/yAwqcu4Ns98OueAb71Ip+oO2+gxwCnerkUQrdiOBwvoUcHyfJF8F5Pf7ezwe9qF6dKO1g9oc4YbBhGjsIqTHoBum8MG6YUq8SolqW6nLhklPrdFL/+qBIW2K93iAVVxYOf1DpaAwFjARWodKQ=~3486276~3159874; Domain=.apmterminals.com; Path=/; Expires=Fri, 02 Jan 2026 02:10:09 GMT; Max-Age=14398
{"status":{"StatusCode":401,"ReasonPhrase":"Unauthorized"},"responseBody":{"ResponseData":null,"UserMessages":[{"MessageNo":602,"MessageDescription":"Requested token is not found.","MessageSeverity":3}]}}
Open service 23.36.162.196:443 · topsapi.apmterminals.com
2025-12-22 14:58
HTTP/1.1 200 OK
Content-Length: 204
Server: Microsoft-IIS/10.0
X-Powered-By: ASP.NET
Cache-Control: max-age=0
Expires: Mon, 22 Dec 2025 14:58:21 GMT
Date: Mon, 22 Dec 2025 14:58:21 GMT
Connection: close
Set-Cookie: ApplicationGatewayAffinityCORS=b26c81394597e92960f8904af5f0e2b1; Path=/; SameSite=None; Secure
Set-Cookie: ApplicationGatewayAffinity=b26c81394597e92960f8904af5f0e2b1; Path=/
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Set-Cookie: _abck=EF2E2786777E720F331E6C4AE84335D6~-1~YAAQx9XOFxIibz+bAQAAzIiRRg/d1Q2EHsqgBpqWhR9vRolbZ6J4cU0dcL7ECdBUsIp6RkygP5zVVkZ6NsZFYZrfYF19iMU6jXgF8J4/dtmiXLGfIj4AkngdlVRUTXDr9CoMOwyLK5cx8gWm19KPnjcB80phonrPMm7vUuUeAUfNNwElC8SVuLbI01j5i44HT/y03m0ccLp4EX7/y0JsQ4zEIKbhx7yJjtHpYn3yv3UInrJ247cHr/0QRIcuRVFTirDpUk/RE/P3cPQVdrr1gJxDYPHJeLkMXJN7zh+5u3YzirEnMviaY9RNdj0byHNWJExRoVinBn+2JXPgl2WIaOzkdEPp9nIwRIGTOIwkb9v2XjiKy6qdmjzJyuB92wJBGNSuHO6XqJnVK5PLNL5HZGS4n3O9cqJxkxyTVojJtfbILompWJCrnLMBLfLY7HJcIqk4i03DNj6w5bM=~-1~-1~-1~-1~-1; Domain=.apmterminals.com; Path=/; Expires=Tue, 22 Dec 2026 14:58:21 GMT; Max-Age=31536000; Secure
Set-Cookie: bm_sz=56C1B3E5A8AF71D4F4F35C3164040B37~YAAQx9XOFxMibz+bAQAAzIiRRh5UVeZRgDPLFf+z1xAwrgTgWpI7iguDHf1e2LjZmmbv4tXP7xiRyN6Sgat0JXfrRGSoydoWpE8DDUceftpVZQ5N9YhrjbKNuHutbmbkcEhrmIvwyBkshOCjnYEGs70QgDaly3zdjN1LfIPlf4YG5XFmIbDwUvlQSvLo3n1gd7rBdHKVWTvreaFyrE6/BKjwlPn3YHl7AIgdzXYJsSvrxHlpZf5o3SXf09RcsQFvLhVVy0aROnp56f3eTQC4rEP6+NGKuBmL7pjicLqHCgXSPsRJ3UjiAg7WqUac7gaQf3vJ9YHzcddFcoOS+XexTICNMUU9oEsoqAJ0TH3+AzRwi6sc~3160372~4273464; Domain=.apmterminals.com; Path=/; Expires=Mon, 22 Dec 2025 18:58:19 GMT; Max-Age=14398
{"status":{"StatusCode":401,"ReasonPhrase":"Unauthorized"},"responseBody":{"ResponseData":null,"UserMessages":[{"MessageNo":602,"MessageDescription":"Requested token is not found.","MessageSeverity":3}]}}