Apache
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbf243ce0a
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://gitee.com/heyingmin/vueadmin-thinkphp.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 8.208.90.19:443 · www.luckystarchinese.co.uk
2026-01-09 15:07
HTTP/1.1 200 OK Date: Fri, 09 Jan 2026 15:07:13 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=b7b059f23f8e2b1a59c4262e308bd946; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.luckystarchinese.co.uk
2025-12-22 18:58
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 18:58:08 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=1214f4285f4b8301a51915290e21cc92; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 8.208.90.19:443 · www.luckystarchinese.co.uk
2025-12-20 20:20
HTTP/1.1 200 OK Date: Sat, 20 Dec 2025 20:20:26 GMT Server: Apache Access-Control-Allow-Credentials: true Access-Control-Max-Age: 1800 Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Authorization, Content-Type, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, X-CSRF-TOKEN, X-Requested-With Access-Control-Allow-Origin: * Set-Cookie: PHPSESSID=4aefc70f74f1c487d7bbeaaafaf6b2c7; path=/ Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8