nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 148.113.6.232:443 · www.painniramoy.com
2024-12-22 04:27
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 04:27:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP9XEYEXA5E9RE7GZBDQKHH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP9XEYEXA5E9RE7GZBDQKHH X-Runtime: 0.043109 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-12-20 07:39
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 07:39:17 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHG3AZVCWCR5018JFN5K7B8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHG3AZVCWCR5018JFN5K7B8 X-Runtime: 0.043766 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-12-18 06:40
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 06:40:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFC7XHR3EH4V7CJEE3A3G55W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFC7XHR3EH4V7CJEE3A3G55W X-Runtime: 0.035324 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-12-12 19:49
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 19:49:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEY6NYD07NHMQZXFTJPAM26Z","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEY6NYD07NHMQZXFTJPAM26Z X-Runtime: 0.032856 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-12-02 17:26
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 17:26:24 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE46HDQYSDGVJT1GH3Y2Q8XV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE46HDQYSDGVJT1GH3Y2Q8XV X-Runtime: 0.050224 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-11-30 15:23
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 15:23:56 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYTQR492N9MT1932KZ6TY9E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYTQR492N9MT1932KZ6TY9E X-Runtime: 0.030484 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-11-28 18:30
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 18:30:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT0MAA93N00AXG8Z2GZDE1F","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT0MAA93N00AXG8Z2GZDE1F X-Runtime: 0.030026 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>
Open service 148.113.6.232:443 · www.painniramoy.com
2024-11-20 12:11
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 12:12:03 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://www.painniramoy.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4QS6JRCK4VQK3FZQN4ZR5E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4QS6JRCK4VQK3FZQN4ZR5E X-Runtime: 0.035761 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://www.painniramoy.com/users/sign_in">redirected</a>.</body></html>