Apache
tcp/443 tcp/80
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652299c902bc
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/idb500/500mg-web.git fetch = +refs/heads/*:refs/remotes/origin/*
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652299c902bc
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/idb500/500mg-web.git fetch = +refs/heads/*:refs/remotes/origin/*
Open service 35.200.234.245:80 · www.fintech500mg.com
2026-01-23 16:46
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 16:47:10 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6InpZM3k5dFdjOFBTcDU4SEVPeEh5Zmc9PSIsInZhbHVlIjoiUGljRzlDL1l3ZzZpWGs5VThiR1R5VW5ZWXZoTVdZUjdQRmJVcGhCYTgyVFhsL3F4S0FUT0xEWkY5a1hJdzBQZ3Awc3gycWlJdStzZklsdWlMV1U3UW92SUxockt6REIvNzgzZ1BYSTZXZWVjTGZ5elJIVURPcHViTHZ3c1gxN2giLCJtYWMiOiIwNTQzMDRlYmE3ZGNlYjI5OTViNDg2NTE1NzgwNGJkY2RjYzJjZWM5MjhlMTFmYWJmZjdiYjU2M2ZiMDViMmM1IiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 18:47:10 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: fintech500mg_session=eyJpdiI6IjhJM1dqd2NubWZlY3cwZlBvLzFIaHc9PSIsInZhbHVlIjoidHZZVm9UeXV4a1VUd3c1Z2w0OTRRLy94VFhSV1g3aGU5KzVxZzlVWXQwaFNiK3FvVGQxdS9UR1Y4ZkpRZHFveVp3R3N2aG5BRE56VTFRL1hDQ013U2pqZFRHTTd1anNib2ZOeGNvdjYzTW5WRm1aWmlEb0l1UnlNRHdMeElicEQiLCJtYWMiOiI3MzcyYjY2NDI4YmFiOGQ4NDdmOTVlOWYwODEwZDkyZWYzMmUzMDRmZGU1YzYzY2U3Y2QwZTg2MGZkZGUzZWFhIiwidGFnIjoiIn0%3D; expires=Fri, 23 Jan 2026 18:47:10 GMT; Max-Age=7200; path=/; httponly; samesite=lax Access-Control-Allow-Origin: * Access-Control-Allow-Methods: GET, POST, OPTIONS, PUT, DELETE Access-Control-Allow-Headers: Origin, Content-Type, Accept, Authorization, X-Requested-With Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.200.234.245:443 · www.fintech500mg.com
2026-01-22 21:51
HTTP/1.1 200 OK Date: Thu, 22 Jan 2026 21:51:32 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6ImtHaVpyc1F6czFjTkQ4RjhRUHE3TGc9PSIsInZhbHVlIjoibWtjWmQrczRUVWhZQTZ4WERlYTRTQStOL0p4VVVHMFdQK1pBYStKbE5Hb3hMVVl6R0tuWXNHYlBJQlZHd21EeVl1ZVhFcFl6VXQ4K3RyR3FIa0dsK1pySERwUDZaeThVUkRVd1ZHWnVQQnl5bWFHbzNKVDVLQlIzUUoxOGNaWW0iLCJtYWMiOiJkZWQzZDExYWRkYzQwMzA4NmRhMWY0MmUxYTIwNDYzZTFhYmVhZjVkYWM1ZDI4YmZiNTExNzE1NjFjOTAyZmRmIiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 23:51:32 GMT; Max-Age=7200; path=/; secure; samesite=lax Set-Cookie: fintech500mg_session=eyJpdiI6IkUwSk04K1dPYmZubUs5NkZJbHFDalE9PSIsInZhbHVlIjoiY3lEc3MzS0sxNnY0NWRpc1ZodFA0NU9TZmIyNFM1R1BUL05ObXhsWTY3eGg1VVJhM2ltVHF0ZDhhcjJFaHozVWRHVDg4STEvTEdzZnB2aEVUV1JzcEFvT0k4TldJZXdEWFR1RGEydldqR1JqT0dPOGVzcVZPc1U1d0o5WXNmMysiLCJtYWMiOiJiNTRhMGY5Y2JmMThlOTljMWViYzQzOGUxYjVkYWFhMWMyMTNmMTBhMWE0ZTlmODc0ZGJjNWYyODA3NWRiMDQ0IiwidGFnIjoiIn0%3D; expires=Thu, 22 Jan 2026 23:51:32 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax Access-Control-Allow-Origin: * Access-Control-Allow-Methods: GET, POST, OPTIONS, PUT, DELETE Access-Control-Allow-Headers: Origin, Content-Type, Accept, Authorization, X-Requested-With Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8
Open service 35.200.234.245:80 · www.fintech500mg.com
2026-01-10 01:05
HTTP/1.1 200 OK Date: Sat, 10 Jan 2026 01:06:54 GMT Server: Apache Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6Ik9Pc3NtMEgzK3RtWDJHcUZNQXE1Umc9PSIsInZhbHVlIjoiQ3RIWEFrZDM3ejFuRW5CZFY4c3JaWlowazNIMFo5Rm05VEhUY011Qm9wbm5FUHdBb1RSL1ZuSnRvQ0pabmZPTm4ySHNCaTcycnkzcS9CSGFraTdiVC9mcXJHdjJtQ1ZyaHdscmZoYkFPN3NZNURucEF5WUxQWHlrL3N2ZVBjaUMiLCJtYWMiOiI3ZGRkZjlkNDcxNDVkOWJiNDI4ZTY4N2I1ZWZmMmNmYjljNzE1ZTNkNTBhNDk4YzI1MmVhZWUwNGUyMjFhMjk2IiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 03:06:54 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: fintech500mg_session=eyJpdiI6Im5EUWt0TEVER3h4aGFwVXZEbEh2ZXc9PSIsInZhbHVlIjoiNGpWUVRmVUtzeGdHTDVzVTJzSTA0SzhvUlpjcmJhNnBxa3NJQTlZT3dHRlk0cnYrdHBDQUFYT21MSCtkM1R0aDVyRzVpalU3UnZ0L05HUHZqeWkwMkRLM2xnL1duSWlrVHRvY0JrS05nZkRjOTZUZ3ZjTFZXVmxKU1ZZaDVFU1kiLCJtYWMiOiJmNmZiMjRlNjY2MTM2ZmZjZDJjMWE1YmI4MzExNTBiOTZmYTFhNjkxODM5OTAyMTQxNDAzMDhjYTFlMGFhYzNmIiwidGFnIjoiIn0%3D; expires=Sat, 10 Jan 2026 03:06:54 GMT; Max-Age=7200; path=/; httponly; samesite=lax Access-Control-Allow-Origin: * Access-Control-Allow-Methods: GET, POST, OPTIONS, PUT, DELETE Access-Control-Allow-Headers: Origin, Content-Type, Accept, Authorization, X-Requested-With Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8