Heroku
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c8329733f8329733f93b77d9b240ac757bb18cb8317310bd8
Found 10 files trough .DS_Store spidering: /404.html /422.html /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Severity: low
Fingerprint: 5f32cf5d6962f09cec7f8772ec7f8772159855a0eb5bbe5662f82d32553b6d83
Found 11 files trough .DS_Store spidering: /404.html /422.html /assets /blank.png /confirmation.html /favicon.ico /packs /portraits /pulse.svg /spinner.svg /tangrams
Open service 15.197.149.68:443 · www.thebazaarapp.com
2026-01-09 17:44
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://www.thebazaarapp.com/organizations/bazaar/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FvTZSMAx48UnFJujvvAwtU7GSvHDqXgA%2BoAjucRGGH8%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767980655"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FvTZSMAx48UnFJujvvAwtU7GSvHDqXgA%2BoAjucRGGH8%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767980655"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 1c7d39a9-73ee-cc00-79ab-8f8d8e8b6e2b
X-Runtime: 0.015111
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 17:44:15 GMT
Connection: close
Open service 15.197.149.68:443 · www.thebazaarapp.com
2026-01-02 22:53
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://www.thebazaarapp.com/organizations/bazaar/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=1DY1BosXj58yiaKYCzpjBJnl3%2FxqFJnAnR3zAkEemxQ%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767394411"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=1DY1BosXj58yiaKYCzpjBJnl3%2FxqFJnAnR3zAkEemxQ%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767394411"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 41dbb94d-29e0-f5b8-d343-bc1d9d02c1e6
X-Runtime: 0.012171
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 22:53:31 GMT
Connection: close
Open service 15.197.149.68:443 · www.thebazaarapp.com
2025-12-22 20:19
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://www.thebazaarapp.com/organizations/bazaar/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jwbQs2Rsmay8knHxLj9%2Fv8b%2BfZ55et0GkhPM7Fyn89E%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766434782"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jwbQs2Rsmay8knHxLj9%2Fv8b%2BfZ55et0GkhPM7Fyn89E%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766434782"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 049642c9-a2f6-b001-f3d3-22f4e3f03ee0
X-Runtime: 0.011141
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 20:19:42 GMT
Connection: close
Open service 15.197.149.68:443 · www.thebazaarapp.com
2025-12-21 00:13
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://www.thebazaarapp.com/organizations/bazaar/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=fw0Tc7xY%2F7zzvIC9rsc0YW3jbkKS6aRJK%2FZjFs6kmCc%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766275996"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=fw0Tc7xY%2F7zzvIC9rsc0YW3jbkKS6aRJK%2FZjFs6kmCc%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766275996"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: b52a0d9a-c507-a769-daf8-d436619e0337
X-Runtime: 0.022325
X-Xss-Protection: 0
Date: Sun, 21 Dec 2025 00:13:16 GMT
Connection: close
Open service 15.197.149.68:443 · www.thebazaarapp.com
2025-12-18 23:57
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 0
Content-Type: text/html; charset=utf-8
Feature-Policy: geolocation 'self'; camera 'none'; microphone 'none'; usb 'none'; fullscreen 'self'; payment 'self'
Location: https://www.thebazaarapp.com/organizations/bazaar/tangram_subscription
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SdyQZjG7%2FO56t6vXBw9p7IRL9yFMwhf3PTrYPGY0vJI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766102276"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SdyQZjG7%2FO56t6vXBw9p7IRL9yFMwhf3PTrYPGY0vJI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766102276"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: b672b772-c40a-c01c-f02c-8178b3e8c3af
X-Runtime: 0.010374
X-Xss-Protection: 0
Date: Thu, 18 Dec 2025 23:57:56 GMT
Connection: close