Microsoft-IIS 10.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43395e71390adb04ab2a8cd035cc08962fbe4edbb7
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /api/branches
GET /api/branches/count
GET /api/branches/page
GET /api/branches/{id}
GET /api/callplans
GET /api/callplans/count
GET /api/callplans/page
GET /api/callplans/{id}
GET /api/cesreport
GET /api/cesreport/count
GET /api/cesreport/page
GET /api/cesreport/{id}
GET /api/deliveries
GET /api/deliveries/count
GET /api/deliveries/csv
GET /api/deliveries/page
GET /api/deliveries/{id}
GET /api/fillings
GET /api/fillings/count
GET /api/fillings/page
GET /api/fillings/{id}
GET /api/logout
GET /api/manualnote
GET /api/manualnote/count
GET /api/manualnote/countremaining
GET /api/manualnote/page
GET /api/manualnote/{id}
GET /api/materials
GET /api/materials/count
GET /api/materials/page
GET /api/materials/{id}
GET /api/ppmreport
GET /api/ppmreport/count
GET /api/ppmreport/page
GET /api/ppmreport/{id}
GET /api/repcodes
GET /api/repcodes/count
GET /api/repcodes/page
GET /api/repcodes/{id}
GET /api/reset
GET /api/reset/count
GET /api/reset/page
GET /api/reset/{id}
GET /api/servicecategories
GET /api/servicecategories/count
GET /api/servicecategories/page
GET /api/servicecategories/{id}
GET /api/services
GET /api/services/count
GET /api/services/page
GET /api/services/{id}
GET /api/servicetypes
GET /api/servicetypes/count
GET /api/servicetypes/page
GET /api/servicetypes/{id}
GET /api/users
GET /api/users/count
GET /api/users/coverdetails
GET /api/users/page
GET /api/users/rtdReport
GET /api/users/{id}
GET /api/vehicles
GET /api/vehicles/count
GET /api/vehicles/initvolumes/{id}
GET /api/vehicles/page
GET /api/vehicles/{id}
GET /api/vessels
GET /api/vessels/count
GET /api/vessels/page
GET /api/vessels/{id}
GET /api/vesseltypes
GET /api/vesseltypes/count
GET /api/vesseltypes/page
GET /api/vesseltypes/{id}
GET /api/waypoints
GET /api/waypoints/count
GET /api/waypoints/csv
GET /api/waypoints/page
GET /api/waypoints/{id}
PATCH /api/deliveries/full/{id}
PATCH /api/repcodes/{id}/productcodes
PATCH /api/vehicles/{id}/materials
PATCH /api/waypoints/{id}/ownership
POST /api/callplans/generate
POST /api/callplans/generate/{id}
POST /api/callplans/tmtsync
POST /api/deliveries/full
POST /api/forgot
POST /api/login
POST /api/manualnote/addinterval
POST /api/reset/upsert
POST /api/users/{id}/coverage
POST /password-reset/{token}
PUT /api/deliveries/{id}/action/{action}
Open service 23.212.110.121:443 · tst.cryospeed.boc.com
2026-01-23 12:34
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/10.0 Access-Control-Allow-Origin: * ETag: W/"3b-dDbejPBQVwx85eMaXi+7q8wsx4o" request-context: appId=cid-v1:b33d47fd-9864-4f9f-9fd2-a98d78ed9d2f X-Powered-By: Express X-Powered-By: ASP.NET Date: Fri, 23 Jan 2026 12:34:22 GMT Content-Length: 59 Connection: close Set-Cookie: ARRAffinity=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;Secure;Domain=tst.cryospeed.boc.com Set-Cookie: ARRAffinitySameSite=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;SameSite=None;Secure;Domain=tst.cryospeed.boc.com Cryospeed API server running fine. Thanks for your concern.
Open service 23.212.110.121:443 · tst.cryospeed.boc.com
2026-01-09 18:23
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/10.0 Access-Control-Allow-Origin: * ETag: W/"3b-dDbejPBQVwx85eMaXi+7q8wsx4o" request-context: appId=cid-v1:b33d47fd-9864-4f9f-9fd2-a98d78ed9d2f X-Powered-By: Express X-Powered-By: ASP.NET Date: Fri, 09 Jan 2026 18:23:27 GMT Content-Length: 59 Connection: close Set-Cookie: ARRAffinity=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;Secure;Domain=tst.cryospeed.boc.com Set-Cookie: ARRAffinitySameSite=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;SameSite=None;Secure;Domain=tst.cryospeed.boc.com Cryospeed API server running fine. Thanks for your concern.
Open service 23.212.110.121:443 · tst.cryospeed.boc.com
2026-01-02 06:46
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/10.0 Access-Control-Allow-Origin: * ETag: W/"3b-dDbejPBQVwx85eMaXi+7q8wsx4o" request-context: appId=cid-v1:b33d47fd-9864-4f9f-9fd2-a98d78ed9d2f X-Powered-By: Express X-Powered-By: ASP.NET Date: Fri, 02 Jan 2026 06:46:05 GMT Content-Length: 59 Connection: close Set-Cookie: ARRAffinity=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;Secure;Domain=tst.cryospeed.boc.com Set-Cookie: ARRAffinitySameSite=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;SameSite=None;Secure;Domain=tst.cryospeed.boc.com Cryospeed API server running fine. Thanks for your concern.
Open service 23.212.110.121:443 · tst.cryospeed.boc.com
2025-12-22 14:10
HTTP/1.1 200 OK Content-Type: text/html; charset=utf-8 Server: Microsoft-IIS/10.0 Access-Control-Allow-Origin: * ETag: W/"3b-dDbejPBQVwx85eMaXi+7q8wsx4o" request-context: appId=cid-v1:b33d47fd-9864-4f9f-9fd2-a98d78ed9d2f X-Powered-By: Express X-Powered-By: ASP.NET Date: Mon, 22 Dec 2025 14:10:47 GMT Content-Length: 59 Connection: close Set-Cookie: ARRAffinity=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;Secure;Domain=tst.cryospeed.boc.com Set-Cookie: ARRAffinitySameSite=d3d05c556974089e6b10a53f90a836f35a73bb3fdfc4fc86550a3ec99b3783aa;Path=/;HttpOnly;SameSite=None;Secure;Domain=tst.cryospeed.boc.com Cryospeed API server running fine. Thanks for your concern.