cloudflare
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cae99eea9ae99eea96ba46591629a2ee1cbb56ea163e836bb
Found 23 files trough .DS_Store spidering: /admin /admin/img /admin/js /build /build/admin /build/frontend /bundles /css /flags /frontend /frontend/img /img /media /media/cache /media/cache/pb_block_image /media/cache/pb_image /nav-icons /pagebuilder /svg /svg/games /svg/socials /uploads /uploads/media
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e079d783da39d783da39d783da39d783da39d783da3
Symfony profiler enabled: https://winspirit-ca.io/_profiler/empty/search/results
Open service 2a06:98c1:3120::3:443 · winspirit-ca.io
2026-01-09 05:52
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 05:52:53 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=EiaiKqAk9dLAypAh8vza%2BciVpgZN5imZg%2BPueavE7AeXg6u1ChwN1Z7lXETjufN51qVFYyj5BUOXnHtJ2z1DLkDRtJj9vkKeersZeKbuCpaScAo7DyF7V7qVAA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 05:52:52 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=13,cfOrigin;dur=1090
CF-RAY: 9bb1abc49cd744c1-SIN
Open service 188.114.97.3:443 · winspirit-ca.io
2026-01-09 04:00
HTTP/1.1 200 OK
Date: Fri, 09 Jan 2026 04:01:02 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=z%2BSoeNuKEr%2BFuLet2bZaU51syp%2F%2FVhqEnYX%2Fau4MS8Ue2ysu5ae8Hzri48EfXJeSOlzwZ609oMpWVnJdh6yFLR5zNQcgAnELLMIdJgEKPQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 09 Feb 2026 04:01:02 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=833
CF-RAY: 9bb107eebf17726b-EWR
Open service 188.114.97.3:443 · winspirit-ca.io
2026-01-02 09:46
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 09:46:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=MJbRzTmKYLFZ6iGcFTz3u8sOBpblREQ1o5iCFf2DKr3q7OnYuiVuXwAPBCDYHBJHeseHKE70%2BPj8PO6RYFgVkrBwQabk3V%2BI2u1d5f4GbQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 02 Feb 2026 09:46:50 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=10,cfOrigin;dur=1093
CF-RAY: 9b7954dc09501d99-SJC
Open service 2a06:98c1:3120::3:443 · winspirit-ca.io
2026-01-02 06:24
HTTP/1.1 200 OK
Date: Fri, 02 Jan 2026 06:24:29 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=7dv%2FdMTTTpgjcecOig6qvl5T3lPHQbbuJNcbiHp%2F5kQ%2FrbjCFHtZmxZLdw%2FkpeQYAhC%2BnUfdlVsNQpBuicAc9W8I767Gq%2F3ugXCqC9r95b%2F8XFjPGCIQSaguaQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 02 Feb 2026 06:24:29 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b782c73f9c26371-LHR
Open service 2a06:98c1:3120::3:443 · winspirit-ca.io
2025-12-30 13:55
HTTP/1.1 200 OK
Date: Tue, 30 Dec 2025 13:55:30 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=PsifOI6rbwU97OYwUNkAFf29oFc2O4eSYkk9ZLbTXtwhJQmm7JQWvgn0YRvyzibAAkR%2BVQlGDrdGLGoVJxoMgR%2Bx%2F2upfHIznnnitOStLBtUEVs1eOfJPiLKfQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Fri, 30 Jan 2026 13:55:29 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=846
CF-RAY: 9b6208fb5ffd422b-EWR
Open service 188.114.97.3:443 · winspirit-ca.io
2025-12-22 17:25
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 17:25:27 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=UaAuRcq5stifyw3Oq2jpzE%2BUV1m9S6MtzCzwIhpSMY2aqS4x5Ox5KIZeuVCNsycFCbEkgrnCRLRlr8%2BKKPeP0wFutqqBqsK2p52VOP0JNg%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 17:25:26 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=4,cfOrigin;dur=513
CF-RAY: 9b215188ecf6a450-YYZ
Open service 2a06:98c1:3120::3:443 · winspirit-ca.io
2025-12-22 17:13
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 17:13:53 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=0GhEMeWiv5NUukPL0c3GWixQiRxgkPqFyITUZlQlayCMg1%2BnNlfbri%2BXbUbKMjLiI%2BciCQt1z5Tj9jCQh8qwzoIdYIlAgTkdWYOz38%2FG08HAwsnVcKffHoeVbQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Thu, 22 Jan 2026 17:13:53 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=11,cfOrigin;dur=1152
CF-RAY: 9b2140963b2b2f2a-SIN
Open service 2a06:98c1:3120::3:443 · winspirit-ca.io
2025-12-20 20:15
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 20:15:15 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=it57xFD3M9cMhY0artgJseoM4eXt9iJgxhpFt0JjieORvUHeE23RHE%2FjoqWhfe3t8aQAeCv4i57luw4Ww7h4lo088o4aCwlJ1G%2FHu%2BcXV98xuI%2BxN6RdBt3BDQ%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 20:15:15 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b11cf878c3990cc-AMS
Open service 188.114.97.3:443 · winspirit-ca.io
2025-12-20 17:11
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 17:11:59 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=wG%2FLDEWf1uMkJVK68WDUImqBhiFDNLCnUrM73y2Moah9i7IfTGnlJ7TGm0BZf9VnVvZriBEGrCrOZ0EzqbC%2FVzK%2F%2FxaJpd9gWdlNnpNJjw%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Tue, 20 Jan 2026 17:11:58 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b10c30dc9570030-LHR
Open service 188.114.97.3:443 · winspirit-ca.io
2025-12-19 06:54
HTTP/1.1 200 OK
Date: Fri, 19 Dec 2025 06:54:31 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
alt-svc: h3=":443"; ma=86400
Cache-Control: no-cache, private
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=OxFPauFWDXlXpG3%2FYjnD7pPkB%2BO4XpvH%2BFz1huDhPgK3oC%2B4Cy9pGshyZS8E2bPuquvzKrXIxqXgxllv4cbwbgaBEDF1A8O6TJ2UUD2nhA%3D%3D"}]}
Server: cloudflare
Set-Cookie: geo_country=us; expires=Mon, 19 Jan 2026 06:54:31 GMT; Max-Age=2678400; path=/; samesite=lax
vary: Accept-Encoding
x-powered-by: PHP/8.3.28
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b04fd36cfa565d6-FRA