CloudFront
tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec70038cc4225d870deabf14163b902d35f2fa9d6b
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
DELETE /favorite/delete
DELETE /trade/cancel
DELETE /user/{userId}/deleteImage
GET /error
GET /favorite/getAll
GET /payment/account
GET /payment/addCard
GET /payment/bankAccount
GET /payment/bankInfo
GET /payment/checkAccount
GET /payment/checkCustomer
GET /payment/createCustomer
GET /payment/customAccount
GET /payment/customBankAccount
GET /payment/deleteBankAccount
GET /payment/deleteCard
GET /payment/getCards
GET /trade/accept
GET /trade/getAllTrades
GET /trade/getAllTradesAmountByUserIdAndDate
GET /trade/getAllTradesByCurrency
GET /trade/getAllTradesByStatus
GET /trade/getAllTradesByUserId
GET /trade/getAllTradesByUserIdAndDate
GET /transaction/getAllTransactions
GET /transaction/getAllTransactionsAmountByUserIdAndDate
GET /transaction/getAllTransactionsByUserId
GET /transaction/getAllTransactionsByUserIdAndDate
GET /user/{userId}
PATCH /trade/update
PATCH /user
PATCH /user/password
POST /aws/email/signup
POST /favorite/create
POST /trade/create
POST /user/login
POST /user/signup
POST /user/{userId}/postImage
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec70038cc4225d870d540d5e1663e36cad6e584732
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
DELETE /favorite/delete
DELETE /trade/cancel
GET /error
GET /favorite/getAll
GET /payment/account
GET /payment/addCard
GET /payment/bankAccount
GET /payment/bankInfo
GET /payment/checkAccount
GET /payment/checkCustomer
GET /payment/createCustomer
GET /payment/customAccount
GET /payment/customBankAccount
GET /payment/deleteBankAccount
GET /payment/deleteCard
GET /payment/getCards
GET /trade/accept
GET /trade/getAllTrades
GET /trade/getAllTradesAmountByUserIdAndDate
GET /trade/getAllTradesByCurrency
GET /trade/getAllTradesByStatus
GET /trade/getAllTradesByUserId
GET /trade/getAllTradesByUserIdAndDate
GET /transaction/getAllTransactions
GET /transaction/getAllTransactionsAmountByUserIdAndDate
GET /transaction/getAllTransactionsByUserId
GET /transaction/getAllTransactionsByUserIdAndDate
GET /user/deleteImage
GET /user/postImage
GET /user/{userId}
PATCH /trade/update
PATCH /user
PATCH /user/password
POST /aws/email/signup
POST /favorite/create
POST /trade/create
POST /user/login
POST /user/signup
Open service 18.66.192.56:443 · www.miracleapi.com
2026-01-09 16:19
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Fri, 09 Jan 2026 16:19:31 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 6ef87569c26a159f552948d3c30a2be0.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: asZDA4FaITrg3-uoqKgkjZtUfLAG9Ie8TONtZnANR-TQMwzNRxkQ3w==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.19:80 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Mon, 05 Jan 2026 10:30:44 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://www.miracleapi.com/ X-Cache: Redirect from cloudfront Via: 1.1 8c1abfbb8460bed752668233d296dba8.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: rwfl36WVa6T9qB7z9Atrtv701ceJTNz2gg3yIOaIHEil3U8qmdf04A== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.66.192.56:443 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Mon, 05 Jan 2026 10:30:44 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 2551fa016e0e39646c40c584001d7b4e.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: CMKTFx9J5fpT9T-aTEHYcXeaXlfZmfMJwOjoohb6ClqS3WgMgs998Q==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.56:80 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Mon, 05 Jan 2026 10:30:43 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://www.miracleapi.com/ X-Cache: Redirect from cloudfront Via: 1.1 f4c3162878591c5abd76f8ee1f873476.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: XX9E57IB2D-ZIMl3NSvau9VN2sI_-NedQDLT0LDTtwAwSK_jEFe6xw== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.66.192.106:443 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Mon, 05 Jan 2026 10:30:43 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 ec12d3de4ccd821a7e749609dcc62010.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: 1ey2c4TqMsOjILZc7c_YcStk5fRUehgwedrmbSaq8miCqQ-PBh6q_g==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.4:80 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Mon, 05 Jan 2026 10:30:43 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://www.miracleapi.com/ X-Cache: Redirect from cloudfront Via: 1.1 fb542039f97bb702c0e68d2142c449aa.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: p2HCL_3NhFGhQjTF6Mgrxd9egs9h-sHxXBcWF6U12-g7MZk11a9U5A== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.66.192.19:443 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Mon, 05 Jan 2026 10:30:43 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 8eb3c67b1958af32e15515c8eb27fbb4.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: ox3_p90VZYgc5usi_4zOj_8TgXRVCRDI701UqhwKjENyhby5Bc3pdw==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.4:443 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Mon, 05 Jan 2026 10:30:44 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 29473aa9cc185f2a037ec3a7e2ffd74c.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: ZPErH7oQLvRW-efizHG8hl5feQjiTjtyKzVVGkgeXg7X7MxS6vTcxA==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.106:80 · www.miracleapi.com
2026-01-05 10:30
HTTP/1.1 301 Moved Permanently Server: CloudFront Date: Mon, 05 Jan 2026 10:30:43 GMT Content-Type: text/html Content-Length: 167 Connection: close Location: https://www.miracleapi.com/ X-Cache: Redirect from cloudfront Via: 1.1 af1bbc213b3a9ee2f125be77ca3609a0.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: Bi14NO_gq4U9Zi88WfnV08FH_FJJdubhsSHZgNA6O2Nx-mRFpWeClQ== Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>CloudFront</center> </body> </html>
Open service 18.66.192.56:443 · www.miracleapi.com
2026-01-02 01:21
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Fri, 02 Jan 2026 01:21:18 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 878a01abbb158ab50d28bd4e882dc33a.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: ZZo1GxJ7jRwuKjGApT6JFqh2o5zUHGgbVTnIxUzhcXXyaVCvBsmhmQ==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.56:443 · www.miracleapi.com
2025-12-30 13:09
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Tue, 30 Dec 2025 13:09:55 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 f8d34d99bd5a267bad6857ae101ea8e2.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: zqhtLH7PIawXk9hsO1VVkBVxEr0zCNAJTivmtb_3AbCVpTotnmo4fg==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.56:443 · www.miracleapi.com
2025-12-22 06:45
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Mon, 22 Dec 2025 06:45:49 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 66ce4848bcf993e3c57b596461cd0b82.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: QMnntZvmOrM4oC60XeLhlBTaSteG-BVJl64EI59VkyVSvq81vYKFLA==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.56:443 · www.miracleapi.com
2025-12-20 17:32
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Sat, 20 Dec 2025 17:32:03 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 551f2461af0b3bf4faaad831ee6e5b1e.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: Zlx7GjMSJJPPXSB6Q1FEQPhnWPQX4t37ssP-6roKmW8JTFVGq8X6Xw==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>
Open service 18.66.192.56:443 · www.miracleapi.com
2025-12-19 03:20
HTTP/1.1 200
Content-Type: text/html;charset=UTF-8
Content-Length: 174
Connection: close
Date: Fri, 19 Dec 2025 03:20:32 GMT
Content-Language: en
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Last-Modified: Thu, 20 Nov 2025 00:10:51 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
X-Cache: Miss from cloudfront
Via: 1.1 32700c539a5f821aadd3624288c4aeb6.cloudfront.net (CloudFront)
X-Amz-Cf-Pop: MUC50-P1
X-Amz-Cf-Id: u-g64F_AyA5VrTBeaWosEh8fRbl_RpaKbAPICax-wGL-SpmLw5Xb3g==
Page title: Miracle Pace Backend
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Miracle Pace Backend</title>
</head>
<body>
Miracle Pace Backend v1.0.0
</body>
</html>