nginx
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 103.139.1.205:443
2024-12-22 00:58
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 01:02:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNY5JPSYV5V5PJ9Y5BAM4NS","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNY5JPSYV5V5PJ9Y5BAM4NS X-Runtime: 0.031263 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-12-20 17:59
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 18:02:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFJKQV6JEYWV09NJ73KH9BAJ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFJKQV6JEYWV09NJ73KH9BAJ X-Runtime: 0.068446 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-12-20 00:34
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:37:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQYK06V2MAZ8VQC7W1RV29","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQYK06V2MAZ8VQC7W1RV29 X-Runtime: 0.028774 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-12-18 20:35
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 20:38:19 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDQWB3G9G4JDHQ2H4Z2A48A","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDQWB3G9G4JDHQ2H4Z2A48A X-Runtime: 0.068660 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-12-18 01:47
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:50:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBQBCZYK6875DW07HW8H266","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBQBCZYK6875DW07HW8H266 X-Runtime: 0.032966 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-12-15 23:51
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:54:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6BXFDFKCMEEFW8X1KP8FW0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6BXFDFKCMEEFW8X1KP8FW0 X-Runtime: 0.026945 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-12-14 00:06
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 00:09:34 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF17ZHRMSDVGQSRPTX0YMWC3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF17ZHRMSDVGQSRPTX0YMWC3 X-Runtime: 0.077679 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-12-12 14:36
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 14:39:56 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXMZT65X5WY2BJ4B2G1HZBJ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXMZT65X5WY2BJ4B2G1HZBJ X-Runtime: 0.036704 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-12-12 01:02
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 01:05:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW6CZSNW6TXZ16ATRCCMWSB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW6CZSNW6TXZ16ATRCCMWSB X-Runtime: 0.028316 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-12-02 15:59
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 16:02:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE41RMMPA7TB0W5J3Q92FJNY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE41RMMPA7TB0W5J3Q92FJNY X-Runtime: 0.071586 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-12-02 01:39
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 01:42:34 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2GH7JHJK5VPWFSDB0CVHHV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2GH7JHJK5VPWFSDB0CVHHV X-Runtime: 0.027897 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-11-30 13:53
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 13:56:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYNR9XNF2CKNSCJEEC0C53P","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYNR9XNF2CKNSCJEEC0C53P X-Runtime: 0.070261 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-11-30 01:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 01:05:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX9KJ14ZRYE6BRZN3R6WSMX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX9KJ14ZRYE6BRZN3R6WSMX X-Runtime: 0.062001 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-11-28 12:49
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 12:52:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSD8XKJJCGMY4310AW428CM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSD8XKJJCGMY4310AW428CM X-Runtime: 0.064274 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-11-28 01:01
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 01:04:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR4SD7FX6M250EWA97CBCG3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR4SD7FX6M250EWA97CBCG3 X-Runtime: 0.041227 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443
2024-11-20 16:53
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 16:56:06 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://103.139.1.205/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD581AY1KBDZW3907WTXKAC5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD581AY1KBDZW3907WTXKAC5 X-Runtime: 0.083137 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://103.139.1.205/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-11-20 16:29
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 16:32:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD56NFE05GNQGSWM8EGEYNVB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD56NFE05GNQGSWM8EGEYNVB X-Runtime: 0.035674 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>
Open service 103.139.1.205:80 · git.zetahuman.com
2024-11-20 16:29
HTTP/1.1 301 Moved Permanently Server: nginx Date: Wed, 20 Nov 2024 16:32:04 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://git.zetahuman.com:443/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 103.139.1.205:443 · git.zetahuman.com
2024-11-20 16:28
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 16:31:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.zetahuman.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD56MCF4JV8Y9Y2ZBFB4CVX2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD56MCF4JV8Y9Y2ZBFB4CVX2 X-Runtime: 0.029064 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.zetahuman.com/users/sign_in">redirected</a>.</body></html>