Heroku
tcp/443 tcp/80
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c7cf176427cf17642f59365a35b3b376e5b3b376e5b3b376e
Found 2 files trough .DS_Store spidering: /images /sitemaps
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c7cf176427cf17642f59365a35b3b376e5b3b376e5b3b376e
Found 2 files trough .DS_Store spidering: /images /sitemaps
Open service 15.197.149.68:443 · www.tailfig.com
2026-01-09 08:35
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Q3B8vtX29EhjZgbwrZPSMybvoiHbmlbZRKuOZbi05GU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767947744"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Q3B8vtX29EhjZgbwrZPSMybvoiHbmlbZRKuOZbi05GU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767947744"
Server: Heroku
Set-Cookie: ahoy_visitor=bb92ec1b-e72a-4c06-a3c3-a9a7524d6eb6; path=/; expires=Sun, 09 Jan 2028 08:35:44 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=c250a8aa-1a9a-4364-b6f9-d51e63e6fe95; path=/; expires=Fri, 09 Jan 2026 12:35:44 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: fb016470-f397-0df7-8661-7ed12e323d68
X-Runtime: 0.004642
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 08:35:44 GMT
Connection: close
HTTP Basic: Access denied.
Open service 76.223.57.73:80 · www.tailfig.com
2026-01-09 06:18
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dIveKQpbmk3rfhCHvQpsKF6lFd8FgiRGAbnI6%2BxxcVA%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767939576"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dIveKQpbmk3rfhCHvQpsKF6lFd8FgiRGAbnI6%2BxxcVA%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767939576"
Server: Heroku
Set-Cookie: ahoy_visitor=a44cfcb2-c410-4142-9dea-a73539d8764c; path=/; expires=Sun, 09 Jan 2028 06:19:36 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=2e10c6f4-711e-47d6-be0b-24fdfc7fc7df; path=/; expires=Fri, 09 Jan 2026 10:19:36 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 303edb88-aac0-930e-602f-696490cfd504
X-Runtime: 0.004025
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 06:19:36 GMT
Connection: close
HTTP Basic: Access denied.
Open service 15.197.149.68:443 · www.tailfig.com
2026-01-02 10:12
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zid3L%2Ba%2FrliGNqnvoMqh5KH0%2F62OrmPV3xhvNaMeO3k%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767348745"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zid3L%2Ba%2FrliGNqnvoMqh5KH0%2F62OrmPV3xhvNaMeO3k%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767348745"
Server: Heroku
Set-Cookie: ahoy_visitor=6f0124b8-d8b1-4837-8493-974055694603; path=/; expires=Sun, 02 Jan 2028 10:12:25 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=225fa1f7-0b5b-4274-9174-05b57f33c449; path=/; expires=Fri, 02 Jan 2026 14:12:25 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0d4a9f29-1834-dc27-c4eb-ba37aaa439ee
X-Runtime: 0.027254
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 10:12:25 GMT
Connection: close
HTTP Basic: Access denied.
Open service 15.197.149.68:443 · www.tailfig.com
2025-12-23 08:26
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=axLYg2fuGjpWagquJPgLdNzwUVxJmRT4KTiKSsY%2FidY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766478405"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=axLYg2fuGjpWagquJPgLdNzwUVxJmRT4KTiKSsY%2FidY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766478405"
Server: Heroku
Set-Cookie: ahoy_visitor=4b40a05f-1518-47f0-a823-ffae6c973772; path=/; expires=Thu, 23 Dec 2027 08:26:45 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=9b528dde-a078-400c-96df-7f7b124a908d; path=/; expires=Tue, 23 Dec 2025 12:26:45 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 318b0fae-90e8-2c49-d096-035a38a7b726
X-Runtime: 0.005470
X-Xss-Protection: 0
Date: Tue, 23 Dec 2025 08:26:45 GMT
Connection: close
HTTP Basic: Access denied.
Open service 76.223.57.73:80 · www.tailfig.com
2025-12-22 09:31
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=BM2s77mCM5Wb2Um0YIhCVdJiL4rj33ZlS8kCQXXD3YM%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766395898"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=BM2s77mCM5Wb2Um0YIhCVdJiL4rj33ZlS8kCQXXD3YM%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766395898"
Server: Heroku
Set-Cookie: ahoy_visitor=00b3c7b9-f8a0-4ad2-9214-736d088efb54; path=/; expires=Wed, 22 Dec 2027 09:31:38 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=e2891db8-c68d-48e0-baf5-109e24faaed3; path=/; expires=Mon, 22 Dec 2025 13:31:38 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 3a8322db-ce8d-3b85-8ce8-354cbe8f6e54
X-Runtime: 0.006008
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 09:31:38 GMT
Connection: close
HTTP Basic: Access denied.
Open service 15.197.149.68:443 · www.tailfig.com
2025-12-21 06:52
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iJDN%2B7UTgm8a%2FFrYlPS0bDethqT0hx9bAm4SFhWow6M%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766299972"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iJDN%2B7UTgm8a%2FFrYlPS0bDethqT0hx9bAm4SFhWow6M%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766299972"
Server: Heroku
Set-Cookie: ahoy_visitor=3eb6cbd2-7904-4b2a-a8af-872fd0d8caf7; path=/; expires=Tue, 21 Dec 2027 06:52:52 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=3fb6761a-69e4-4526-83be-6af0e8f50754; path=/; expires=Sun, 21 Dec 2025 10:52:52 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: c395303e-f8e4-2d5b-64ed-81abb6b7cffb
X-Runtime: 0.004036
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 06:52:52 GMT
Connection: close
HTTP Basic: Access denied.
Open service 76.223.57.73:80 · www.tailfig.com
2025-12-20 08:46
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=rztQhcSYSVRsgz14QAO8XdrzxJHL%2BRW6yX%2B4uDGzLQU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766220408"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=rztQhcSYSVRsgz14QAO8XdrzxJHL%2BRW6yX%2B4uDGzLQU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766220408"
Server: Heroku
Set-Cookie: ahoy_visitor=89c6784e-3a81-4e15-b201-ba517a4c66ce; path=/; expires=Mon, 20 Dec 2027 08:46:48 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=673c4598-d71a-4c7b-8680-194086144af3; path=/; expires=Sat, 20 Dec 2025 12:46:48 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 0f67a841-62bf-23c9-70f6-c69e6a851384
X-Runtime: 0.003348
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 08:46:48 GMT
Connection: close
HTTP Basic: Access denied.
Open service 15.197.149.68:443 · www.tailfig.com
2025-12-19 01:38
HTTP/1.1 401 Unauthorized
Cache-Control: no-cache
Content-Length: 27
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GbhVSJUyC2MflZ1WCDfnbo%2BjHkqiL05rZfF9memsl3M%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766108308"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GbhVSJUyC2MflZ1WCDfnbo%2BjHkqiL05rZfF9memsl3M%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766108308"
Server: Heroku
Set-Cookie: ahoy_visitor=88e29c7d-08a5-448e-a189-43b2e1318f1e; path=/; expires=Sun, 19 Dec 2027 01:38:28 GMT; samesite=lax; secure
Set-Cookie: ahoy_visit=4f6218a9-d6c2-479e-be11-ef378ba32ac9; path=/; expires=Fri, 19 Dec 2025 05:38:28 GMT; samesite=lax; secure
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
Www-Authenticate: Basic realm="Application"
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 4ef87939-4a27-89eb-83e2-33a8b137c605
X-Runtime: 0.003666
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 01:38:28 GMT
Connection: close
HTTP Basic: Access denied.