.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c1a5d9b0f1a5d9b0fb246cfc73bb508b930b19b0630b19b06
Found 3 files trough .DS_Store spidering: /img /img/default /img/icons
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d9107ed4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@bitbucket.org:/cedricf/tma_pathefilm.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 2.16.183.22:443 · www.pathefilms.com
2026-01-27 17:49
HTTP/1.1 302 Moved Temporarily
Content-Type: text/html; charset=utf-8
Location: /fr/
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Content-Security-Policy: default-src 'self'; connect-src 'self' *.google-analytics.com api.privacy-center.org; media-src 'self' *.s3.eu-west-3.amazonaws.com; font-src 'self' fonts.googleapis.com fonts.gstatic.com data:; script-src 'self' 'unsafe-inline' sdk.privacy-center.org www.youtube.com/iframe_api www.youtube.com/s/player/ www.googletagmanager.com www.youtube-nocookie.com; style-src 'self' 'unsafe-inline' www.youtube-nocookie.com fonts.googleapis.com; frame-src 'self' www.youtube-nocookie.com; img-src 'self' www.googletagmanager.com i.ytimg.com img.youtube.com *.s3.eu-west-3.amazonaws.com www.youtube-nocookie.com yt3.ggpht.com data: image/svg+xml;
Content-Length: 262
Expires: Tue, 27 Jan 2026 17:49:51 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 27 Jan 2026 17:49:51 GMT
Connection: close
Set-Cookie: PHPSESSID=a9d452f8e153cce4a22a331a9a114ee4; path=/; secure; httponly; samesite=lax
Alt-Svc: h3=":443"; ma=93600
Akamai-Request-BC: [a=2.16.29.214,b=2619313622,c=g,n=DE_HH_HAMBURG,o=20940],[c=c,n=FR_IDF_PARIS,o=20940],[a=190,c=o]
Page title: Redirecting to /fr/
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='/fr/'" />
<title>Redirecting to /fr/</title>
</head>
<body>
Redirecting to <a href="/fr/">/fr/</a>.
</body>
</html>
Open service 2a02:26f0:3500:18::1724:a288:80 · www.pathefilms.com
2026-01-27 17:49
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www.pathefilms.com/ Expires: Tue, 27 Jan 2026 17:49:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 27 Jan 2026 17:49:53 GMT Connection: close Akamai-Request-BC: [a=23.36.160.136,b=843846810,c=g,n=DE_HE_FRANKFURT,o=20940]
Open service 2.16.183.22:80 · www.pathefilms.com
2026-01-27 17:49
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://www.pathefilms.com/ Expires: Tue, 27 Jan 2026 17:49:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 27 Jan 2026 17:49:53 GMT Connection: close Akamai-Request-BC: [a=2.16.29.214,b=2619322679,c=g,n=DE_HH_HAMBURG,o=20940]