Microsoft-IIS 10.0
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549dbdfbb7014bf82528068a87aa030f99552c3bb26
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Activity/detail
GET /api/Activity/list
GET /api/Advert/brandList
GET /api/Advert/brandModelList
GET /api/Conversation/list
GET /api/Google/searchPlace
GET /api/Location/cities/{countryId}
GET /api/Location/countries
GET /api/Media/view
GET /api/Notification/list
GET /api/Place/activityList
GET /api/Place/propertyList
GET /api/Post/hashtagList
GET /api/Profile/favoritePlace
GET /api/Profile/followList
GET /api/Profile/socialProfile
GET /api/Profile/timeline
GET /api/Type/translation
POST /api/Account/checkValue
POST /api/Account/forgotPassword
POST /api/Account/login
POST /api/Account/register
POST /api/Account/saveDevice
POST /api/Account/sendValidateCode
POST /api/Account/validationAccount
POST /api/Advert/delete
POST /api/Advert/detail
POST /api/Advert/detailByCode
POST /api/Advert/save
POST /api/Advert/search
POST /api/Campaign/detail
POST /api/Company/addMedia
POST /api/Company/changeMeta
POST /api/Company/deleteMedia
POST /api/Company/detail
POST /api/Company/detailInfo
POST /api/Company/list
POST /api/Company/register
POST /api/Company/save
POST /api/CompanyComment/add
POST /api/CompanyComment/delete
POST /api/CompanyComment/list
POST /api/CompanyComment/setLike
POST /api/Conversation/detail
POST /api/Conversation/sendMessage
POST /api/Google/newPlace
POST /api/Google/validatePlace
POST /api/Media/upload
POST /api/Notification/push
POST /api/Notification/send
POST /api/Notification/sendV2
POST /api/Place/addMedia
POST /api/Place/changeMeta
POST /api/Place/deleteMedia
POST /api/Place/detail
POST /api/Place/detailByCode
POST /api/Place/nearBy
POST /api/Place/notifPlace
POST /api/Place/setFavorite
POST /api/Place/suggestPlace
POST /api/PlaceComment/add
POST /api/PlaceComment/askQuestion
POST /api/PlaceComment/delete
POST /api/PlaceComment/list
POST /api/PlaceComment/setLike
POST /api/Post/add
POST /api/Post/adminLike
POST /api/Post/block
POST /api/Post/delete
POST /api/Post/search
POST /api/Post/searchByTag
POST /api/Post/setLike
POST /api/Post/timeline
POST /api/PostComment/add
POST /api/PostComment/delete
POST /api/PostComment/list
POST /api/PostComment/setLike
POST /api/PostComment/update
POST /api/Profile/changePassword
POST /api/Profile/changeProfile
POST /api/Profile/changeProfilePhoto
POST /api/Profile/delete
POST /api/Profile/follow
POST /api/Type/list
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549dbdfbb7014bf82528068a87aa030f99552c3bb26
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Activity/detail
GET /api/Activity/list
GET /api/Advert/brandList
GET /api/Advert/brandModelList
GET /api/Conversation/list
GET /api/Google/searchPlace
GET /api/Location/cities/{countryId}
GET /api/Location/countries
GET /api/Media/view
GET /api/Notification/list
GET /api/Place/activityList
GET /api/Place/propertyList
GET /api/Post/hashtagList
GET /api/Profile/favoritePlace
GET /api/Profile/followList
GET /api/Profile/socialProfile
GET /api/Profile/timeline
GET /api/Type/translation
POST /api/Account/checkValue
POST /api/Account/forgotPassword
POST /api/Account/login
POST /api/Account/register
POST /api/Account/saveDevice
POST /api/Account/sendValidateCode
POST /api/Account/validationAccount
POST /api/Advert/delete
POST /api/Advert/detail
POST /api/Advert/detailByCode
POST /api/Advert/save
POST /api/Advert/search
POST /api/Campaign/detail
POST /api/Company/addMedia
POST /api/Company/changeMeta
POST /api/Company/deleteMedia
POST /api/Company/detail
POST /api/Company/detailInfo
POST /api/Company/list
POST /api/Company/register
POST /api/Company/save
POST /api/CompanyComment/add
POST /api/CompanyComment/delete
POST /api/CompanyComment/list
POST /api/CompanyComment/setLike
POST /api/Conversation/detail
POST /api/Conversation/sendMessage
POST /api/Google/newPlace
POST /api/Google/validatePlace
POST /api/Media/upload
POST /api/Notification/push
POST /api/Notification/send
POST /api/Notification/sendV2
POST /api/Place/addMedia
POST /api/Place/changeMeta
POST /api/Place/deleteMedia
POST /api/Place/detail
POST /api/Place/detailByCode
POST /api/Place/nearBy
POST /api/Place/notifPlace
POST /api/Place/setFavorite
POST /api/Place/suggestPlace
POST /api/PlaceComment/add
POST /api/PlaceComment/askQuestion
POST /api/PlaceComment/delete
POST /api/PlaceComment/list
POST /api/PlaceComment/setLike
POST /api/Post/add
POST /api/Post/adminLike
POST /api/Post/block
POST /api/Post/delete
POST /api/Post/search
POST /api/Post/searchByTag
POST /api/Post/setLike
POST /api/Post/timeline
POST /api/PostComment/add
POST /api/PostComment/delete
POST /api/PostComment/list
POST /api/PostComment/setLike
POST /api/PostComment/update
POST /api/Profile/changePassword
POST /api/Profile/changeProfile
POST /api/Profile/changeProfilePhoto
POST /api/Profile/delete
POST /api/Profile/follow
POST /api/Type/list
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-25 21:06
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Sun, 25 Jan 2026 21:06:44 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-23 21:06
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Fri, 23 Jan 2026 21:07:18 GMT Content-Length: 20 Connection: close no available server
Open service 195.142.1.194:80 · api.vanliferoad.com
2026-01-23 09:54
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Location: https://api.vanliferoad.com/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Fri, 23 Jan 2026 09:54:26 GMT Connection: close
Open service 195.142.1.194:443 · api.vanliferoad.com
2026-01-23 09:54
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Fri, 23 Jan 2026 09:54:26 GMT Connection: close
Open service 195.142.1.194:80 · api.vanliferoad.com
2026-01-23 00:48
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Location: https://api.vanliferoad.com/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Fri, 23 Jan 2026 00:48:58 GMT Connection: close
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-22 21:10
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Thu, 22 Jan 2026 21:11:08 GMT Content-Length: 20 Connection: close no available server
Open service 195.142.1.194:443 · api.vanliferoad.com
2026-01-22 20:55
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Thu, 22 Jan 2026 20:55:15 GMT Connection: close
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-21 21:05
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Wed, 21 Jan 2026 21:06:06 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-12 21:04
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Mon, 12 Jan 2026 21:05:58 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-10 21:04
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Sat, 10 Jan 2026 21:05:39 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-09 21:14
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Fri, 09 Jan 2026 21:15:20 GMT Content-Length: 20 Connection: close no available server
Open service 195.142.1.194:443 · api.vanliferoad.com
2026-01-09 01:40
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Fri, 09 Jan 2026 01:40:44 GMT Connection: close
Open service 195.142.1.194:80 · api.vanliferoad.com
2026-01-08 23:44
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Location: https://api.vanliferoad.com/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Thu, 08 Jan 2026 23:44:13 GMT Connection: close
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-08 21:16
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Thu, 08 Jan 2026 21:17:31 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-07 21:09
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Wed, 07 Jan 2026 21:10:12 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-06 21:04
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Tue, 06 Jan 2026 21:05:40 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-03 21:04
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Sat, 03 Jan 2026 21:04:06 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:80 · cms.vanliferoad.com
2026-01-03 14:28
HTTP/1.1 503 Service Unavailable Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Sat, 03 Jan 2026 14:28:30 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · cms.vanliferoad.com
2026-01-03 14:28
HTTP/1.1 200 OK
Alt-Svc: h3=":443"; ma=2592000
Content-Security-Policy: connect-src 'self' https:;img-src 'self' data: blob: https://market-assets.strapi.io;media-src 'self' data: blob:;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
Content-Type: text/html; charset=utf-8
Date: Sat, 03 Jan 2026 14:28:30 GMT
Referrer-Policy: no-referrer
Strict-Transport-Security: max-age=31536000; includeSubDomains
Vary: Origin
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Powered-By: Strapi <strapi.io>
Connection: close
Transfer-Encoding: chunked
Page title: Welcome to your Strapi app
<!doctype html>
<html>
<head>
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" />
<title>Welcome to your Strapi app</title>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="robots" content="noindex, nofollow">
<link href="https://cdnjs.cloudflare.com/ajax/libs/meyer-reset/2.0/reset.min.css" rel="stylesheet" />
<link href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.11.2/css/all.min.css" rel="stylesheet" />
<link href="https://fonts.googleapis.com/css?family=Lato:400,700&display=swap" rel="stylesheet" />
<style>
*{-webkit-box-sizing:border-box;text-decoration:none}body,html{margin:0;padding:0;font-size:62.5%;-webkit-font-smoothing:antialiased}body{font-size:1.3rem;font-family:Lato,Helvetica,Arial,Verdana,sans-serif;background:#fafafb;margin:0;padding:80px 0;color:#333740;line-height:1.8rem}strong{font-weight:700}.wrapper{width:684px;margin:auto}h1{text-align:center}h2{font-size:1.8rem;font-weight:700;margin-bottom:1px}.logo{height:40px;margin-bottom:74px}.informations{position:relative;overflow:hidden;display:flex;justify-content:space-between;width:100%;height:126px;margin-top:18px;padding:20px 30px;background:#fff;border-radius:2px;box-shadow:0 2px 4px 0 #e3e9f3}.informations:before{position:absolute;top:0;left:0;content:'';display:block;width:100%;height:2px;background:#007eff}.environment{display:inline-block;padding:0 10px;height:20px;margin-bottom:36px;background:#e6f0fb;border:1px solid #aed4fb;border-radius:2px;text-transform:uppercase;color:#007eff;font-size:1.2rem;font-weight:700;line-height:20px;letter-spacing:.05rem}.cta{display:inline-block;height:30px;padding:0 15px;margin-top:32px;border-radius:2px;color:#fff;font-weight:700;line-height:28px}.cta i{position:relative;display:inline-block;height:100%;vertical-align:middle;font-size:1rem;margin-right:20px}.cta i:before{position:absolute;top:8px}.cta-primary{background:#007eff}.cta-secondary{background:#6dbb1a}.text-align-right{text-align:right}.lets-started{position:relative;overflow:hidden;width:100%;height:144px;margin-top:18px;padding:20px 30px;background:#fff;border-radius:2px;box-shadow:0 2px 4px 0 #e3e9f3}.people-saying-hello{position:absolute;right:30px;bottom:-8px;width:113px;height:70px}.visible{opacity:1!important}.people-saying-hello img{position:absolute;max-width:100%;opacity:0;transition:opacity .2s ease-out}@media only screen and (max-width:768px){.wrapper{width:auto!important;margin:0 20px}.informations{flex-direction:column;height:auto}.environment{width:100%;text-align:center;margin-bottom:18px}.text-align-right{margin-top:18px;text-align:center}.cta{width:100%;text-align:center}.lets-started{height:auto}.people-saying-hello{display:none}}
</style>
</head>
<body lang="en">
<section class="wrapper">
<h1><img class="logo" src="/assets/images/logo_login.png" /></h1>
<div class="informations">
<div>
<span class="environment">production</span>
<p>The server is running successfully.</p>
</div>
<div class="text-align-right">
<p>Sat, 03 Jan 2026 14:28:30 GMT</p>
</div>
</div>
</section>
</body>
</html>
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-02 21:15
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Fri, 02 Jan 2026 21:15:32 GMT Content-Length: 20 Connection: close no available server
Open service 195.142.1.194:80 · api.vanliferoad.com
2026-01-02 02:04
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Location: https://api.vanliferoad.com/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Fri, 02 Jan 2026 02:04:26 GMT Connection: close
Open service 193.148.252.140:443 · vanliferoad.com
2026-01-01 21:08
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Thu, 01 Jan 2026 21:08:20 GMT Content-Length: 20 Connection: close no available server
Open service 193.148.252.140:443 · vanliferoad.com
2025-12-31 21:10
HTTP/1.1 503 Service Unavailable Alt-Svc: h3=":443"; ma=2592000 Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Wed, 31 Dec 2025 21:10:03 GMT Content-Length: 20 Connection: close no available server
Open service 195.142.1.194:80 · api.vanliferoad.com
2025-12-23 05:59
HTTP/1.1 307 Temporary Redirect Transfer-Encoding: chunked Location: https://api.vanliferoad.com/ Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Tue, 23 Dec 2025 05:59:42 GMT Connection: close
Open service 195.142.1.194:443 · api.vanliferoad.com
2025-12-22 13:49
HTTP/1.1 404 Not Found Transfer-Encoding: chunked Server: Microsoft-IIS/10.0 X-Powered-By: ASP.NET Date: Mon, 22 Dec 2025 13:49:09 GMT Connection: close
Open service 193.148.252.140:443 · vanliferoad.com
2025-12-22 06:16
HTTP/1.1 200 OK Alt-Svc: h3=":443"; ma=2592000 Cache-Control: s-maxage=31536000, stale-while-revalidate Content-Type: text/html; charset=utf-8 Date: Mon, 22 Dec 2025 06:16:13 GMT Etag: "xu1eu28sn51ohw" Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Url, Accept-Encoding X-Nextjs-Cache: HIT X-Powered-By: Next.js Connection: close Transfer-Encoding: chunked