nginx
tcp/443 tcp/80 tcp/8443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Open service 206.119.101.253:443 · zt9pyz.com
2026-01-22 16:46
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 22 Jan 2026 16:46:14 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4584
Connection: close
Vary: Accept-Encoding
Vary: Accept-Encoding
Vary: Accept-Encoding
Accept-Charset: utf-8
GC: 1.0.0.54
GV: 2.0.11.47
GT: 1
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: *
Access-Control-Allow-Methods: *
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Page title: Plaza
<!doctype html>
<html lang="en">
<head>
<script>window.__siteConfig__ = { info: {"agentId":"926","groupId":"272","icon":"/scUpload/4e926fc4c62b446d930e8812dbe43ee0.png","masterId":"-1","name":{"default":{"hi":"चौक","tw":"廣場","pt":"Praça","th":"พลาซ่า","ko":"큰 광장","ja":"プラザ","vn":"Quảng trường","en":"Plaza","cn":"Plaza","es":"Plaza"}},"resourcePrefix":"img","sysId":"120"}, templateGroupId: 272, crypto: {"appKey":"02d025e583de49d5898261596e233b45","decryption":false,"encryption":false}, domains: ["https://static.21gptt.com","https://static.4cc844.com","https://static.4r4ss2.com","https://static.5xch.com","https://static.88d89q.com","https://static.adgco9.com","https://static.k88wpb.com","https://static.m2btc.com","https://static.ofox0j.com","https://static.prkk57.com","https://static.r22td2.com","https://static.ue3rrk.com"] }</script>
<meta name="version" version="2.0.11.20">
<meta charset="UTF-8"><!-- <link rel="icon" href="/favicon.png" /> -->
<meta http-equiv="X-UA-Compatible" content="IE=Edge">
<meta content="yes" name="apple-touch-fullscreen">
<meta content="black" name="apple-mobile-web-app-status-bar-style">
<meta content="telephone=no" name="format-detection">
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0, user-scalable=no, viewport-fit=cover">
<meta name="HandheldFriendly" content="true">
<meta name="format-detection" content="telephone=no, email=no">
<meta name="msapplication-tap-highlight" content="no">
<meta name="full-screen" content="yes">
<meta name="x5-fullscreen" content="true">
<meta name="apple-touch-fullscreen" content="YES">
<meta name="google" value="notranslate"> <!-- 将 HTML 链接到 manifest --> <!-- <link rel="manifest" href="/manifest.webmanifest?v2.0.9.1"> -->
<meta name="apple-mobile-web-app-capable" content="yes">
<meta name="apple-mobile-web-app-title" content=""><!-- <link rel="apple-touch-icon" sizes="180x180" href="../icons/512x512-d.png"> -->
<meta name="msapplication-TileColor" content="black">
<meta name="theme-color" content="#1a2b45">
<meta name="name" content="">
<meta name="short_name" content="">
<meta name="apple-mobile-web-app-capable" content="no"><!-- <meta name="apple-mobile-web-app-status-bar-style" content="black-translucent"> --> <!-- 将 HTML 链接到 manifest -->
<link rel="manifest" href="/manifest.webmanifest">
<style>
html, body {
margin:0;
min-height: 100%;
background-color: #1a2c45;
}
</style>
<script>
function getParams() {
let search = location.search
if (search.indexOf('?') === 0) {
search = search.substring(1)
}
const params = {}
search.split('&').forEach(function (pair) {
const parts = pair.split('=')
if (parts.length === 2) {
params[decodeURIComponent(parts[0])] = decodeURIComponent(parts[1])
}
})
return params
}
function redirectTo(url) {
try {
location.replace(url)
} catch {
location.href = url
}
}
;(function() {
const params = getParams()
if (params.clip === 'true' && params.forceRedirectUrl) {
redirectTo(params.forceRedirectUrl)
}
})();
</script>
<script type="module" crossorigin src="/assets/index.62d4366b.js"></script>
<link rel="modulepreload" crossorigin href="/assets/.pnpm.2e25d557.js">
<link rel="stylesheet" href="/assets/.pnpm.c32ed6f4.css">
<link rel="stylesheet" href="/assets/index.20f5ffae.css">
<title>Plaza</title>
<meta property="og:title" content="Plaza">
<meta property="og:url" content="https://zt9pyz.com">
<meta property="og:description" content="Plaza">
<meta property="og:image" content="https://img.zt9pyz.com/scUpload/4e926fc4c62b446d930e8812dbe43ee0.png">
<meta property="og:type" content="website">
</head>
<body>
<div id="app">
</div>
<p style="display: none;">security</p>
<sc
Open service 206.119.101.253:80 · zt9pyz.com
2026-01-22 16:46
HTTP/1.1 301 Moved Permanently Server: nginx Date: Thu, 22 Jan 2026 16:46:14 GMT Content-Type: text/html Content-Length: 163 Connection: close Location: https://zt9pyz.com:443/ Access-Control-Allow-Origin: * Access-Control-Allow-Credentials: true Access-Control-Allow-Headers: * Access-Control-Allow-Methods: * Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx </center> </body> </html>
Open service 206.119.101.253:8443 · zt9pyz.com
2026-01-22 16:46
HTTP/1.1 200 OK Server: nginx Date: Thu, 22 Jan 2026 16:46:14 GMT Content-Type: application/octet-stream Transfer-Encoding: chunked Connection: close Expires: Thu, 22 Jan 2026 16:46:13 GMT Cache-Control: no-cache success