openresty
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-12-21 02:07
HTTP/1.1 302 Found Server: openresty Date: Sat, 21 Dec 2024 02:07:37 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKFGR23Z3J9GQDBD1WNYR1K","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKFGR23Z3J9GQDBD1WNYR1K X-Runtime: 0.055153 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-12-19 17:46
HTTP/1.1 302 Found Server: openresty Date: Thu, 19 Dec 2024 17:46:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFG0E0ES3D5BS6H5YMAGDQA1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFG0E0ES3D5BS6H5YMAGDQA1 X-Runtime: 0.308796 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:80 · zhuk.k-lab.su
2024-12-19 17:46
HTTP/1.1 301 Moved Permanently Server: openresty Date: Thu, 19 Dec 2024 17:46:05 GMT Content-Type: text/html Content-Length: 166 Connection: close Location: https://zhuk.k-lab.su/ Strict-Transport-Security: max-age=63072000;includeSubDomains; preload Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>openresty</center> </body> </html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-12-18 15:49
HTTP/1.1 302 Found Server: openresty Date: Wed, 18 Dec 2024 15:50:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFD7CH6GNGZY0KZN25GVQXJF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFD7CH6GNGZY0KZN25GVQXJF X-Runtime: 0.017971 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-12-14 12:04
HTTP/1.1 302 Found Server: openresty Date: Sat, 14 Dec 2024 12:05:05 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2GXPJ50CGXX8HDXPP99G1C","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2GXPJ50CGXX8HDXPP99G1C X-Runtime: 0.044399 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-12-12 10:45
HTTP/1.1 302 Found Server: openresty Date: Thu, 12 Dec 2024 10:45:34 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEX7JNBV6Y9V6Q13SYJB1D7J","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEX7JNBV6Y9V6Q13SYJB1D7J X-Runtime: 0.020049 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-12-03 05:28
HTTP/1.1 302 Found Server: openresty Date: Tue, 03 Dec 2024 05:28:15 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE5FV5GEDEC76PCKRHW7QXNM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE5FV5GEDEC76PCKRHW7QXNM X-Runtime: 0.031355 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-11-30 21:56
HTTP/1.1 302 Found Server: openresty Date: Sat, 30 Nov 2024 21:57:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZH7JTBT6HJAJKWCDM18ZB0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZH7JTBT6HJAJKWCDM18ZB0 X-Runtime: 0.052878 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-11-28 17:49
HTTP/1.1 302 Found Server: openresty Date: Thu, 28 Nov 2024 17:49:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSY89DQMX2VB6VW5DKGR4AT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSY89DQMX2VB6VW5DKGR4AT X-Runtime: 0.034730 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-11-26 16:27
HTTP/1.1 302 Found Server: openresty Date: Tue, 26 Nov 2024 16:27:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMMRWKJM8T8J6G5S5PA0MB9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMMRWKJM8T8J6G5S5PA0MB9 X-Runtime: 0.117066 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>
Open service 212.192.134.141:443 · zhuk.k-lab.su
2024-11-20 08:57
HTTP/1.1 302 Found Server: openresty Date: Wed, 20 Nov 2024 08:57:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://zhuk.k-lab.su/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4CNAWE6N77DTYQ8RZJ4QTR","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4CNAWE6N77DTYQ8RZJ4QTR X-Runtime: 0.032994 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=63072000;includeSubDomains; preload X-Served-By: zhuk.k-lab.su <html><body>You are being <a href="https://zhuk.k-lab.su/users/sign_in">redirected</a>.</body></html>