nginx
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c63442d9d63442d9d819fde85819fde85819fde85819fde85
Found 1 files trough .DS_Store spidering: /js
Open service 18.193.174.91:443 · uat.alert.ag
2026-01-09 03:06
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 09 Jan 2026 03:06:06 GMT
Content-Type: text/html
Content-Length: 2118
Connection: close
expires: Thu, 9 Jan 2025 03:06:06 GMT
x-frame-options: sameorigin
cache-control: no-cache
last-modified: Tue, 21 Oct 2025 09:11:41 GMT
Strict-Transport-Security: max-age=31536000
Permissions-Policy: interest-cohort=()
Page title: Mendix
<!doctype html>
<html>
<head>
<script type="text/javascript">
// Redirect to unsupported browser page if opened from browser that doesn't support async/arrow functions
try {
eval("async () => {}");
} catch (error) {
var homeUrl = window.location.origin + window.location.pathname;
var appUrl = homeUrl.slice(0, homeUrl.lastIndexOf("/") + 1);
window.location.replace(appUrl + "unsupported-browser.html");
}
</script>
<meta charset="utf-8">
<title>Mendix</title>
<meta name="viewport" content="width=device-width, initial-scale=1">
<link rel="stylesheet" href="theme.compiled.css?638823004498094448">
<link rel="apple-touch-icon" sizes="180x180" href="apple-touch-icon.png?638823004498094448">
<link rel="icon" sizes="32x32" href="icon-32.png?638823004498094448">
<link rel="icon" sizes="16x16" href="icon-16.png?638823004498094448">
<link rel="manifest" href="manifest.webmanifest?638823004498094448" crossorigin="use-credentials">
</head>
<body dir="ltr">
<noscript>To use this application, please enable JavaScript.</noscript>
<div id="content"></div>
<script>
dojoConfig = {
isDebug: false,
useCustomLogger: true,
async: true,
baseUrl: "mxclientsystem/dojo/",
cacheBust: "638823004498094448",
rtlRedirect: "index-rtl.html"
};
</script>
<script>
if (!document.cookie || !document.cookie.match(/(^|;) *originURI=/gi)) {
const url = new URL(window.location.href);
const subPath = url.pathname.substring(0, url.pathname.lastIndexOf("/"));
document.cookie = `originURI=${subPath}/login.html${window.location.protocol === "https:" ? ";SameSite=None;Secure" : ""}`;
}
</script>
<script src="mxclientsystem/mxui/mxui.js?638823004498094448"></script>
</body>
</html>
Open service 18.193.174.91:443 · uat.alert.ag
2025-12-22 07:42
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 22 Dec 2025 07:42:22 GMT
Content-Type: text/html
Content-Length: 2118
Connection: close
expires: Sun, 22 Dec 2024 07:42:22 GMT
x-frame-options: sameorigin
cache-control: no-cache
last-modified: Tue, 21 Oct 2025 09:11:41 GMT
Strict-Transport-Security: max-age=31536000
Permissions-Policy: interest-cohort=()
Page title: Mendix
<!doctype html>
<html>
<head>
<script type="text/javascript">
// Redirect to unsupported browser page if opened from browser that doesn't support async/arrow functions
try {
eval("async () => {}");
} catch (error) {
var homeUrl = window.location.origin + window.location.pathname;
var appUrl = homeUrl.slice(0, homeUrl.lastIndexOf("/") + 1);
window.location.replace(appUrl + "unsupported-browser.html");
}
</script>
<meta charset="utf-8">
<title>Mendix</title>
<meta name="viewport" content="width=device-width, initial-scale=1">
<link rel="stylesheet" href="theme.compiled.css?638823004498094448">
<link rel="apple-touch-icon" sizes="180x180" href="apple-touch-icon.png?638823004498094448">
<link rel="icon" sizes="32x32" href="icon-32.png?638823004498094448">
<link rel="icon" sizes="16x16" href="icon-16.png?638823004498094448">
<link rel="manifest" href="manifest.webmanifest?638823004498094448" crossorigin="use-credentials">
</head>
<body dir="ltr">
<noscript>To use this application, please enable JavaScript.</noscript>
<div id="content"></div>
<script>
dojoConfig = {
isDebug: false,
useCustomLogger: true,
async: true,
baseUrl: "mxclientsystem/dojo/",
cacheBust: "638823004498094448",
rtlRedirect: "index-rtl.html"
};
</script>
<script>
if (!document.cookie || !document.cookie.match(/(^|;) *originURI=/gi)) {
const url = new URL(window.location.href);
const subPath = url.pathname.substring(0, url.pathname.lastIndexOf("/"));
document.cookie = `originURI=${subPath}/login.html${window.location.protocol === "https:" ? ";SameSite=None;Secure" : ""}`;
}
</script>
<script src="mxclientsystem/mxui/mxui.js?638823004498094448"></script>
</body>
</html>