cloudflare
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65225a3a900e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3l1cElSWEl5bngwbFUyZXhPTUEzVHpBWUg2dlY2cDBvZW9xZw== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652207414905
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzAzTlRoOWh5UVFXYW5GQ1B4N0VWT29RemZMc3R5STBVcjdnbw== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522706fbca0
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX29QQTVtOVM1cW5LRWxqMGU2eEVuS3dYMDdmSXhScTRWNnJXcQ== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228dc8235f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX20wVlNiWkc5MWlMM1R5Z0gzclA5bHVjaThLQ01aZzQxeUcyOQ== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e2477df3
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0ZlMUtPWDM3UmlFbFVqSGJkb3FWUGlXVFZJbUxqdjBXczJ3Mw== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522be1fd8ca
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX21odk1LYjNvUmJDVG8yRTR1YzFyTVpqQkJRb29LVTRUVXl1OQ== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65229a11acbf
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0RZeUtMSE53UVFWN3NjcDJldVdWaVJTNjVmUDAyaDJRSEtIYQ== [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228074b1d4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1RCbUpUdGowdVNvdjMwdmxaMkRIdkJ0SDdNN3d5NDNaek9neQ== [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522db722950
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/zapisp fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3JDeUluUjZ5NGQ1SnRNaVdUMXFIelByWXBIc2NHVTA4YXhWYQ== [branch "release/2.2.0"] remote = origin merge = refs/heads/release/2.2.0
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d71aa9d4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/zapisp/aws-teste fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3lWOWE4WUhyamZYa2lTbXlsM1ZPaFBlVDQxcDkyMjBmeEZWZg== [branch "release/1.0.0"] remote = origin merge = refs/heads/release/1.0.0
Open service 172.66.162.122:443 · faculdade.zapisp.com.br
2026-01-22 22:16
HTTP/1.1 302 Found
Date: Thu, 22 Jan 2026 22:16:52 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=27,cfOrigin;dur=87
Cache-Control: no-cache, private
Location: https://faculdade.zapisp.com.br/auth/login?redirect=%2F
X-Frame-Options: SAMEORIGIN
Set-Cookie: XSRF-TOKEN=eyJpdiI6Ink4b2s2SURybkR4bTQ2VlEwY2pJYXc9PSIsInZhbHVlIjoiYk44YUVVcFZwWkRmNjEyVlJMOGtOWjdmMmFtQ0xQbzNqZlFSN3BVUWlQNWtkcUNpTHhkbUIzZG1WN2hYNWd2U3JUQjh4SlMzYWJoOERwVWxWYnhyMzEreTBNNzNlTTRrU29EeWhna0FzTDZwVFkxZGMxWUcxMzBReStPQUdjNk0iLCJtYWMiOiIxN2Q2ZjM4NzRiOGVjMDVjOWIxMzBhYmRiYWNmYjgwNTIzYTNkODNlZjhhMDU0Yzg0ZDZhYzUyOTQ2N2M5NWRiIn0%3D; expires=Fri, 23-Jan-2026 00:16:52 GMT; Max-Age=7200; path=/; secure; samesite=none
Set-Cookie: laravel_session=Ya7ZFjCaJhgkw06P2OLPTlfNQ2dC2RojsIColpJG; expires=Fri, 23-Jan-2026 00:16:52 GMT; Max-Age=7200; path=/; secure; httponly; samesite=none
X-Debug-Backend: php74
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubdomains; preload
cf-cache-status: DYNAMIC
CF-RAY: 9c226b0f095ea1ea-YYZ
alt-svc: h3=":443"; ma=86400
Page title: Redirecting to https://faculdade.zapisp.com.br/auth/login?redirect=%2F
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://faculdade.zapisp.com.br/auth/login?redirect=%2F'" />
<title>Redirecting to https://faculdade.zapisp.com.br/auth/login?redirect=%2F</title>
</head>
<body>
Redirecting to <a href="https://faculdade.zapisp.com.br/auth/login?redirect=%2F">https://faculdade.zapisp.com.br/auth/login?redirect=%2F</a>.
<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"8a78ae05f76e47baae69d6b8bdbe035e","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body>
</html>
Open service 172.67.70.236:443 · drones.zapisp.com.br
2026-01-10 07:58
HTTP/1.1 200 OK
Date: Sat, 10 Jan 2026 07:58:38 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
access-control-allow-origin: *
Cache-Control: no-cache, no-store
feature-policy: geolocation 'none';midi 'none';sync-xhr 'none';microphone 'none';camera 'none';magnetometer 'none';gyroscope 'none';fullscreen 'self';payment 'none';accelerometer 'none';usb 'none';autoplay 'none'
nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
report-to: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=htJCnYGS9ezo2fNuVZBnqt%2FhvUi5ZXnBQUSvty6KqDw%3D\u0026sid=67ff5de4-ad2b-4112-9289-cf96be89efed\u0026ts=1768031918"}],"max_age":3600}
reporting-endpoints: heroku-nel="https://nel.heroku.com/reports?s=htJCnYGS9ezo2fNuVZBnqt%2FhvUi5ZXnBQUSvty6KqDw%3D&sid=67ff5de4-ad2b-4112-9289-cf96be89efed&ts=1768031918"
Server: cloudflare
strict-transport-security: max-age=31536000; includeSubDomains; preload
vary: Accept-Encoding
via: 2.0 heroku-router
x-content-type-options: nosniff
x-download-options: noopen
x-frame-options: deny
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cf-cache-status: DYNAMIC
CF-RAY: 9bbaa160b930f78f-EWR
alt-svc: h3=":443"; ma=86400