nginx
tcp/443
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09cf35cbfb3f35cbfb3af8132f4042b9df98a1e37d16b8f7d37
Found 29 files trough .DS_Store spidering: /.git /888 /m /qphtml /qphtml/active /qphtml/css /qphtml/img /qphtml/img/active /qphtml/img/agency /qphtml/img/agent /qphtml/img/attendrule /qphtml/img/public /qphtml/img/sites /qphtml/img/src /qphtml/img/vipdetail /qphtml/js /qphtml/mp4 /static /static-qygj /ts-download /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download /tsnew-download/css /tsnew-download/images /tsnew-download/js /tsnew-download/muse-ui
Severity: low
Fingerprint: 5f32cf5d6962f09cccdd54a0ccdd54a0904d808d3a77cc4059f990506bd400af
Found 13 files trough .DS_Store spidering: /.git /888 /m /qphtml /qphtml/active /qphtml/css /qphtml/img /qphtml/js /qphtml/mp4 /static /static-qygj /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09cab28146bab28146b48c39a0cc5aa6571c11d5149621e6529
Found 21 files trough .DS_Store spidering: /.git /888 /m /qphtml /qphtml/active /qphtml/css /qphtml/img /qphtml/img/active /qphtml/img/agency /qphtml/img/agent /qphtml/img/attendrule /qphtml/img/public /qphtml/img/sites /qphtml/img/src /qphtml/img/vipdetail /qphtml/js /qphtml/mp4 /static /static-qygj /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09ca0cc0fcfa0cc0fcf947301c83d9eabc58a7a70fdb42cd990
Found 25 files trough .DS_Store spidering: /.git /888 /m /qphtml /qphtml/active /qphtml/css /qphtml/img /qphtml/img/active /qphtml/img/agency /qphtml/img/agent /qphtml/img/attendrule /qphtml/img/public /qphtml/img/sites /qphtml/img/src /qphtml/img/vipdetail /qphtml/js /qphtml/mp4 /static /static-qygj /ts-download /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09cc169dbbec169dbbe626f729baf90f152471845d6070974df
Found 15 files trough .DS_Store spidering: /.git /888 /m /qphtml /qphtml/active /qphtml/css /qphtml/img /qphtml/js /qphtml/mp4 /static /static/public /static/qygj /static-qygj /ts-download /tsnew-download
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652235613f57
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = root@6669786.com:lottery-site/lottery-repo-qygj fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 104.160.179.251:443 · www.x885555.com
2026-01-22 20:48
HTTP/1.1 601
Server: nginx
Date: Thu, 22 Jan 2026 20:48:32 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
<!DOCTYPE html>
<html>
<title></title>
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1">
<style>
body{font-family:-apple-system,system-ui,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol"}a{color:#000;font-size:18px}p{font-size:20px;height:40px;line-height:40px}.msg{margin-right:auto;margin-left:auto;position:relative;max-width:767px}.title{background-color:#3a4781;border-radius:15px 15px 0 0;box-shadow:0 0 10px 0 rgba(0,0,0,0.5);transition:background .3s,border .3s,border-radius .3s,box-shadow .3s;padding:10px 25px;display:flex;color:#fff}.body{padding:35px 25px;border-radius:0 0 15px 15px;box-shadow:0 0 10px 0 rgba(0,0,0,0.5);transition:background .3s,border .3s,border-radius .3s,box-shadow .3s}.footer{display:inline;margin:auto;position:relative}.line1,.line2{display:flex;justify-content:center;align-items:center}.logo{color:#24305e;font-size:20px;margin-right:15px;height:120px;display:flex}.subtitle{font-size:30px;font-weight:bolder;height:40px;line-height:40px}.txt{display:flex;text-align:center;justify-content:center;height:40px}@media(max-width:480px){.logo,.cdnlink{display:flex;justify-content:center;align-items:center}.line1{display:block}}
</style>
<script src="https://www.recaptcha.net/recaptcha/api.js?hl=zh-CN" async defer></script>
<script>
function onSubmit(token) {
document.getElementById('cdn_recaptcha_token').value = token;
document.getElementById('cdn_form').action = window.location.href;
document.getElementById('cdn_form').submit()
}
</script>
</head>
<body>
<div class="container">
<div class="msg">
<div class="title">
<h1>www.x885555.com - 需要进行额外的安全检查</h1>
</div>
<div class="body">
<div class="txt">
<form id="cdn_form" method="GET" action="">
<input type="hidden" name="cdn_recaptcha_token" id="cdn_recaptcha_token" value="" />
<button id="cdn_button" class="g-recaptcha" data-sitekey="6LdSDsMrAAAAAGHztBUkmv1fG5Xl84M1lxcG7-Pc"
data-callback="onSubmit" style="font-size: 20px;padding:5px">人机验证</button>
</form>
</div>
<div class="subtitle">发生了什么?</div>
<p>请求被阻挡。</p>
<div class="subtitle">我应该怎么做?</div>
<p>点击人机验证解除阻挡</p>
<p>代码: 601</p><p>编号: 0871bef45fe64e01aed222a8e55d08e2</p><p>访客地址: 157.245.204.205 </p><p>网址: https://www.x885555.com/ </p><p>请求方法: GET </p><p>时间: 2026-01-23 04:48:32 </p>
</div>
</div>
</div>
</body>
</html>