nginx 1.14.0
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: high
Fingerprint: 5f32cf5d6962f09c668fcbec668fcbecc9c3328cced6462fce1ae597e7cd22f7
Found 17 files trough .DS_Store spidering: /css /download /download/CGV.pdf /download/CRPN_Foncieres_cotees_europeenne_Q&A.pdf /download/documents_public_ao_crpn_2020.zip /download/mode_emploi_en.pdf /download/mode_emploi_fr.pdf /download/MySmartRFP-Cookie_Policy_EN.pdf /download/MySmartRFP-Cookie_Policy_FR.pdf /download/MySmartRFP.com-Legal_Notice_EN.pdf /download/MySmartRFP.com-Mentions_legales_FR.pdf /favicon.ico /images /index.php /js /mix-manifest.json /robots.txt
Open service 51.210.111.203:443 · www.mysmartrfp.com
2026-01-09 00:35
HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Fri, 09 Jan 2026 00:35:57 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding set-cookie: next-auth.csrf-token=79d13356c1c7d0decd3fe2e091d80c6f40cb9c86d7cc5f56cd5e26b233cae1e0%7C0952fa46256fb779c7d6f9929d3c414023fed0479213e8a49189370edf859dde; Path=/; HttpOnly; Secure; SameSite=Lax set-cookie: next-auth.callback-url=https%3A%2F%2Fwww.mysmartrfp.com; Path=/; HttpOnly; Secure; SameSite=Lax Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding link: </_next/static/media/793968fa3513f5d6-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/e4af272ccee01ff0-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/water-drop-background.a9ffccce.gif>; rel=preload; as="image" X-Powered-By: Next.js Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Open service 51.210.111.203:443 · www.mysmartrfp.com
2026-01-01 23:30
HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Thu, 01 Jan 2026 23:30:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding set-cookie: next-auth.csrf-token=a1b38b0b27b99f520fe044c6c2ae2079a6672a90a23f0cca9306a01cb9c53282%7Cd50ea743183fac81b54821e633bff3c252681cb18d9529b8366002df99e71642; Path=/; HttpOnly; Secure; SameSite=Lax set-cookie: next-auth.callback-url=https%3A%2F%2Fwww.mysmartrfp.com; Path=/; HttpOnly; Secure; SameSite=Lax Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding link: </_next/static/media/793968fa3513f5d6-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/e4af272ccee01ff0-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/water-drop-background.a9ffccce.gif>; rel=preload; as="image" X-Powered-By: Next.js Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Open service 51.210.111.203:443 · www.mysmartrfp.com
2025-12-30 09:29
HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Tue, 30 Dec 2025 09:29:25 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding set-cookie: next-auth.csrf-token=590c598f4e87e0c9cf051ae83d06cd58a9a72e285141ecefb79b5f19b55aa3ec%7Caef78e2d4d5984cb13281e6ae29a1ed71925ac6a647dfb4f34b6dda68f15352e; Path=/; HttpOnly; Secure; SameSite=Lax set-cookie: next-auth.callback-url=https%3A%2F%2Fwww.mysmartrfp.com; Path=/; HttpOnly; Secure; SameSite=Lax Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding link: </_next/static/media/793968fa3513f5d6-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/e4af272ccee01ff0-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/water-drop-background.a9ffccce.gif>; rel=preload; as="image" X-Powered-By: Next.js Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Open service 51.210.111.203:443 · www.mysmartrfp.com
2025-12-22 11:33
HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Mon, 22 Dec 2025 11:33:30 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding set-cookie: next-auth.csrf-token=bb8ce54542d2c01213b7398bf0d369ae9956a6383098e499becf729b1b121799%7C26ee49dcd23950ba3c0e23e3f925eb3cf18ed48dd60c7b4afb9b6071f4d6725c; Path=/; HttpOnly; Secure; SameSite=Lax set-cookie: next-auth.callback-url=https%3A%2F%2Fwww.mysmartrfp.com; Path=/; HttpOnly; Secure; SameSite=Lax Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding link: </_next/static/media/793968fa3513f5d6-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/e4af272ccee01ff0-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2" X-Powered-By: Next.js Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Open service 51.210.111.203:443 · www.mysmartrfp.com
2025-12-20 12:32
HTTP/1.1 200 OK Server: nginx/1.14.0 (Ubuntu) Date: Sat, 20 Dec 2025 12:32:28 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Vary: Accept-Encoding set-cookie: next-auth.csrf-token=a7959cb73987ab8bc1884d44b96fa841087ef544765822a2a31ab21b954ffd63%7C55be62f0912755b38a11c85e6d0988338b126fedbb69ff5f77632435a7e2b24e; Path=/; HttpOnly; Secure; SameSite=Lax set-cookie: next-auth.callback-url=https%3A%2F%2Fwww.mysmartrfp.com; Path=/; HttpOnly; Secure; SameSite=Lax Vary: RSC, Next-Router-State-Tree, Next-Router-Prefetch, Next-Router-Segment-Prefetch, Accept-Encoding link: </_next/static/media/793968fa3513f5d6-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2", </_next/static/media/e4af272ccee01ff0-s.p.woff2>; rel=preload; as="font"; crossorigin=""; type="font/woff2" X-Powered-By: Next.js Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate