nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-12-22 04:20
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 04:21:05 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP9HVR4ZFYXW6ABWB3MT42P","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP9HVR4ZFYXW6ABWB3MT42P X-Runtime: 0.021175 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-12-20 08:18
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 08:18:39 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHJBD7RT01WP5ZMA7BZAWWA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHJBD7RT01WP5ZMA7BZAWWA X-Runtime: 0.023576 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-12-13 02:24
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 02:24:43 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYXAABNHSM9KNM9FPS1Q80H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYXAABNHSM9KNM9FPS1Q80H X-Runtime: 0.061108 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-12-02 10:55
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 10:55:43 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3G61X7V6QS2PK66HDCTSBH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3G61X7V6QS2PK66HDCTSBH X-Runtime: 0.028545 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-11-30 06:24
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 06:24:12 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDXVVFG88YCJPZBWVDCEM6KW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDXVVFG88YCJPZBWVDCEM6KW X-Runtime: 0.053903 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-11-28 15:21
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 15:21:15 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSNSCF0Z26AFMD1NGFPE9CM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSNSCF0Z26AFMD1NGFPE9CM X-Runtime: 0.045471 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-11-26 18:42
HTTP/1.1 302 Found Server: nginx Date: Tue, 26 Nov 2024 18:42:46 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMWGYGS9EYWQA8N3MW37XTS","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMWGYGS9EYWQA8N3MW37XTS X-Runtime: 0.024461 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>
Open service 5.181.255.249:443 · www.git.lenin.ltd
2024-11-21 02:23
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 02:24:00 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.git.lenin.ltd/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD68H62RRHG1JF1CEA09RD2S","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD68H62RRHG1JF1CEA09RD2S X-Runtime: 0.048484 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.git.lenin.ltd/users/sign_in">redirected</a>.</body></html>