Apache 2.4.41
tcp/443 tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f1c57038
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/crane-cloud/mira-frontend.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
An attacker can make use of this vulnerability to step out of the root directory and access other parts of the file system.
This might give the attacker the ability to view restricted files, which could provide the attacker with more information required to further compromise the system.
https://www.acunetix.com/websitesecurity/directory-traversal/
Severity: critical
Fingerprint: ac4d53c4832b2491c591c07dcc7199b722e62e9f22e62e9ff325eea1f55252fb
Found host file trough Directory traversal: 127.0.0.1 localhost 127.0.1.1 docker-containerizer # the following lines are desirable for ipv6 capable hosts ::1 ip6-localhost ip6-loopback fe00::0 ip6-localnet ff00::0 ip6-mcastprefix ff02::1 ip6-allnodes ff02::2 ip6-allrouters
Open service 102.134.147.245:443 · mira.cranecloud.io
2024-12-12 02:31
HTTP/1.1 200 OK Date: Thu, 12 Dec 2024 02:32:00 GMT Server: Apache/2.4.41 (Ubuntu) X-Powered-By: Express Access-Control-Allow-Origin: * Content-Type: text/html; charset=utf-8 Content-Length: 19 ETag: W/"13-LijBw5seNads7sRWIROpqdA+KEo" Connection: close Welcome to mira API
Open service 102.134.147.245:80 · mira.cranecloud.io
2024-12-12 02:31
HTTP/1.1 301 Moved Permanently Date: Thu, 12 Dec 2024 02:31:55 GMT Server: Apache/2.4.41 (Ubuntu) Location: https://mira.cranecloud.io/ Content-Length: 319 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://mira.cranecloud.io/">here</a>.</p> <hr> <address>Apache/2.4.41 (Ubuntu) Server at mira.cranecloud.io Port 80</address> </body></html>
Open service 102.134.147.245:443
2024-11-20 16:18
HTTP/1.1 200 OK Date: Wed, 20 Nov 2024 16:18:30 GMT Server: Apache/2.4.41 (Ubuntu) X-Powered-By: Express Access-Control-Allow-Origin: * Content-Type: text/html; charset=utf-8 Content-Length: 19 ETag: W/"13-LijBw5seNads7sRWIROpqdA+KEo" Connection: close Welcome to mira API