cloudflare
tcp/443 tcp/80 tcp/8443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 104.20.17.141:80
2026-01-26 15:33
HTTP/1.1 403 Forbidden Date: Mon, 26 Jan 2026 15:34:10 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 16 Connection: close X-Frame-Options: SAMEORIGIN Referrer-Policy: same-origin Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Server: cloudflare CF-RAY: 9c4112a8dd1d4f72-AMS error code: 1003
Open service 104.20.17.141:8443 · bakim.hipicon.com
2026-01-25 18:46
HTTP/1.1 522 <none> Date: Sun, 25 Jan 2026 18:46:51 GMT Content-Length: 0 Connection: close Server: cloudflare Cache-Control: private, no-store cf-cache-status: DYNAMIC X-Content-Type-Options: nosniff set-cookie: cf_use_ob=8443; Expires=Sun, 25 Jan 2026 18:47:21 GMT set-cookie: cf_ob_info=522:9c39ef128eb97fa8:BLR; Expires=Sun, 25 Jan 2026 18:47:21 GMT Strict-Transport-Security: max-age=15552000; includeSubDomains; preload CF-RAY: 9c39ef128eb97fa8-BLR alt-svc: h3=":8443"; ma=86400
Open service 104.20.17.141:443 · bakim.hipicon.com
2026-01-25 18:46
HTTP/1.1 200 OK
Date: Sun, 25 Jan 2026 18:46:31 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
Last-Modified: Sat, 27 Sep 2025 18:52:18 GMT
Referrer-Policy: strict-origin-when-cross-origin
Server: cloudflare
Vary: Accept-Encoding
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9c39ef0da812773b-LHR
alt-svc: h3=":443"; ma=86400
Page title: Hipicon — Bakımdayız
<!doctype html>
<html lang="tr">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta name="robots" content="noindex, nofollow" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<title>Hipicon — Bakımdayız</title>
<meta name="description" content="Hipicon kısa süreli bakım çalışması yapıyor." />
<!-- Optional: make mobile status bar nice -->
<meta name="theme-color" content="#ffffff">
<style>
:root{ --bg:#ffffff; --fg:#374151; --muted:#6b7280; --accent:#6b7280; --card:#ffffff; }
*{ box-sizing:border-box }
html,body{ height:100% }
body{
margin:0;
background:var(--bg);
color:var(--fg);
font: 16px/1.5 system-ui, -apple-system, Segoe UI, Roboto, Helvetica, Arial, "Apple Color Emoji","Segoe UI Emoji";
display:grid; place-items:center;
}
.wrap{ width:min(680px, 92vw); text-align:center; padding:40px 20px; }
.card{
background:var(--card);
border:1px solid rgba(0,0,0,.08);
border-radius:20px;
padding:32px 24px;
box-shadow:0 4px 12px rgba(0,0,0,.1);
}
.brand{ display:flex; align-items:center; justify-content:center; gap:12px; margin-bottom:10px; }
.brand svg{ width:28px; height:28px; }
h1{ font-size: clamp(26px, 3.5vw, 34px); margin: 10px 0 8px; letter-spacing:-.02em }
p{ margin:6px 0; color:var(--muted) }
.dots{ display:inline-flex; gap:6px; margin-left:.2rem; }
.dot{ width:6px; height:6px; border-radius:999px; background:var(--muted); opacity:.45; animation:bounce 1.4s infinite ease-in-out; }
.dot:nth-child(2){ animation-delay:.15s }
.dot:nth-child(3){ animation-delay:.3s }
@keyframes bounce{ 0%,80%,100%{ transform:translateY(0); opacity:.35 } 40%{ transform:translateY(-5px); opacity:.9 } }
.row{ display:flex; flex-wrap:wrap; gap:10px; justify-content:center; margin-top:16px }
.pill{ padding:8px 12px; border-radius:999px; border:1px solid rgba(0,0,0,.15); color:var(--muted); font-size:14px; background:rgba(0,0,0,.02); }
.footer{ margin-top:18px; font-size:12px; color:var(--muted) }
.sr-only{ position:absolute; width:1px; height:1px; padding:0; margin:-1px; overflow:hidden; clip:rect(0,0,0,0); border:0 }
.lang-toggle{
position:absolute;
top:20px;
right:20px;
background:var(--card);
border:1px solid rgba(0,0,0,.15);
border-radius:8px;
padding:8px 12px;
font-size:14px;
cursor:pointer;
transition:all 0.2s ease;
box-shadow:0 2px 4px rgba(0,0,0,.1);
}
.lang-toggle:hover{ background:var(--accent); color:white; transform:translateY(-1px); box-shadow:0 4px 8px rgba(0,0,0,.15); }
</style>
</head>
<body>
<main class="wrap" role="main" aria-labelledby="title">
<div class="card" role="region" aria-label="Bakım Bildirimi">
<div class="brand" aria-hidden="true">
<strong aria-label="Hipicon">Hipicon</strong>
</div>
<!-- Turkish Content -->
<div id="tr-content">
<h1 id="title">Bakımdayız <span class="dots" aria-hidden="true"><span class="dot"></span><span class="dot"></span><span class="dot"></span></span></h1>
<p>Kısa süreli bir bakım çalışması yapıyoruz. Çok yakında tekrar buradayız.</p>
<div class="row" aria-label="Durum Bilgileri">
<span class="pill">Durum: <strong style="color:inherit">Planlı</strong></span>
<span class="pill">Tahmini süre: <strong style="color:inherit">Kısa</strong></span>
</div>
<p class="footer">— Anlayışınız için teşekkürler</p>
<p class="sr-only">Bu sayfa yalnızca bilgilendirme amaçlıdır ve otomatik olarak yenilenmez.</p>
</div>
<!-- English Content -->
<div id="en-content" style="display:none;">
<h1 id="title-en">Under Maintenance <span class="dots" aria-hidden="true"><span class="dot"></span><span class="dot"></span><span class="dot"></span></span></h1>
<p>We're performing a brief maintenance operation. We'll be back v
Open service 104.20.17.141:80 · bakim.hipicon.com
2026-01-25 18:46
HTTP/1.1 301 Moved Permanently Date: Sun, 25 Jan 2026 18:46:31 GMT Content-Length: 0 Connection: close Location: https://bakim.hipicon.com/ X-Content-Type-Options: nosniff Server: cloudflare CF-RAY: 9c39ef0c3ade57b0-EWR alt-svc: h3=":443"; ma=86400
Open service 104.20.17.141:8443 · cpn.ca.greendot.org
2026-01-23 12:14
HTTP/1.1 401 Unauthorized
Date: Fri, 23 Jan 2026 12:14:07 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
cf-apo-via: origin,host
Vary: accept-encoding
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=210,cfOrigin;dur=0
CF-Ray: 9c2735822d057db1-YYZ
CF-Cache-Status: DYNAMIC
Server: cloudflare
Set-Cookie: __cf_bm=0QjJbEhB7E.afdr1luA28UHKeV1cxSreNtI1DnI91FU-1769170447-1.0.1.1-G_NDFFJetjK36ecuZxKqv9Jz51vVn0H4d6Dc1l1r5u3vGMTJCH4rUbPIlBu3iRMbyzShvCcbXYUMTsDtiIM_iKRaX9dzhIg2SKiFxb87_a4; path=/; expires=Fri, 23-Jan-26 12:44:07 GMT; domain=.greendot.org; HttpOnly; Secure; SameSite=None
WWW-Authenticate: Basic realm="cpncagreendot"
Page title: 401 Authorization Required
<html>
<head><title>401 Authorization Required</title></head>
<body>
<center><h1>401 Authorization Required</h1></center>
<hr><center>nginx</center>
<script>(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'9c27358230147db1',t:'MTc2OTE3MDQ0Ny4wMDAwMDA='};var a=document.createElement('script');a.nonce='';a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script><script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"0f17df7b89ac4db7a8bfee4caad8d0ab","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body>
</html>
Open service 104.20.17.141:443 · cpn.ca.greendot.org
2026-01-23 12:14
HTTP/1.1 401 Unauthorized
Date: Fri, 23 Jan 2026 12:14:08 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
cf-apo-via: origin,host
Vary: accept-encoding
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=509,cfOrigin;dur=0
CF-Ray: 9c273581a9190a6b-AMS
CF-Cache-Status: DYNAMIC
Server: cloudflare
Set-Cookie: __cf_bm=hDKMlUFjpj1KBXatNQqNuP0Vf30oISI8p31UN0nmwSk-1769170448-1.0.1.1-y7i1kT6VpUzqb6Wn1pWy6xvQPRbTt_QfOfP9JfXmGx_hoeEIeQYdUHqt3_AY7_qndW2H3Rm75SGR6JEfZ8.CzEKiENOL86SFVojaSr6BLsA; path=/; expires=Fri, 23-Jan-26 12:44:08 GMT; domain=.greendot.org; HttpOnly; Secure; SameSite=None
WWW-Authenticate: Basic realm="cpncagreendot"
Page title: 401 Authorization Required
<html>
<head><title>401 Authorization Required</title></head>
<body>
<center><h1>401 Authorization Required</h1></center>
<hr><center>nginx</center>
<script>(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'9c273581c50e0a6b',t:'MTc2OTE3MDQ0OC4wMDAwMDA='};var a=document.createElement('script');a.nonce='';a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script><script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"0f17df7b89ac4db7a8bfee4caad8d0ab","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body>
</html>
Open service 104.20.17.141:80 · cpn.ca.greendot.org
2026-01-23 12:14
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 12:14:07 GMT Content-Length: 0 Connection: close Location: https://cpn.ca.greendot.org/ Server-Timing: cfEdge;dur=11,cfOrigin;dur=0 Server: cloudflare CF-RAY: 9c273581af4537b0-AMS
Open service 104.20.17.141:8443 · garage.redbull.com
2026-01-10 07:35
HTTP/1.1 403 Forbidden
Date: Sat, 10 Jan 2026 07:35:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
accept-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
cf-mitigated: challenge
critical-ch: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
cross-origin-embedder-policy: require-corp
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
permissions-policy: accelerometer=(),browsing-topics=(),camera=(),clipboard-read=(),clipboard-write=(),geolocation=(),gyroscope=(),hid=(),interest-cohort=(),magnetometer=(),microphone=(),payment=(),publickey-credentials-get=(),screen-wake-lock=(),serial=(),sync-xhr=(),usb=()
referrer-policy: same-origin
server-timing: chlray;desc="9bba7f91ec63f591"
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Strict-Transport-Security: max-age=2592000; includeSubDomains
Server: cloudflare
CF-RAY: 9bba7f91ec63f591-SJC
Page title: Just a moment...
<!DOCTYPE html><html lang="en-US"><head><title>Just a moment...</title><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=Edge"><meta name="robots" content="noindex,nofollow"><meta name="viewport" content="width=device-width,initial-scale=1"><style>*{box-sizing:border-box;margin:0;padding:0}html{line-height:1.15;-webkit-text-size-adjust:100%;color:#313131;font-family:system-ui,-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue",Arial,"Noto Sans",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"}body{display:flex;flex-direction:column;height:100vh;min-height:100vh}.main-content{margin:8rem auto;padding-left:1.5rem;max-width:60rem}@media (width <= 720px){.main-content{margin-top:4rem}}.h2{line-height:2.25rem;font-size:1.5rem;font-weight:500}@media (width <= 720px){.h2{line-height:1.5rem;font-size:1.25rem}}#challenge-error-text{background-image:url("data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIzMiIgaGVpZ2h0PSIzMiIgZmlsbD0ibm9uZSI+PHBhdGggZmlsbD0iI0IyMEYwMyIgZD0iTTE2IDNhMTMgMTMgMCAxIDAgMTMgMTNBMTMuMDE1IDEzLjAxNSAwIDAgMCAxNiAzbTAgMjRhMTEgMTEgMCAxIDEgMTEtMTEgMTEuMDEgMTEuMDEgMCAwIDEtMTEgMTEiLz48cGF0aCBmaWxsPSIjQjIwRjAzIiBkPSJNMTcuMDM4IDE4LjYxNUgxNC44N0wxNC41NjMgOS41aDIuNzgzem0tMS4wODQgMS40MjdxLjY2IDAgMS4wNTcuMzg4LjQwNy4zODkuNDA3Ljk5NCAwIC41OTYtLjQwNy45ODQtLjM5Ny4zOS0xLjA1Ny4zODktLjY1IDAtMS4wNTYtLjM4OS0uMzk4LS4zODktLjM5OC0uOTg0IDAtLjU5Ny4zOTgtLjk4NS40MDYtLjM5NyAxLjA1Ni0uMzk3Ii8+PC9zdmc+");background-repeat:no-repeat;background-size:contain;padding-left:34px}@media (prefers-color-scheme: dark){body{background-color:#222;color:#d9d9d9}}</style><meta http-equiv="refresh" content="360"></head><body><div class="main-wrapper" role="main"><div class="main-content"><noscript><div class="h2"><span id="challenge-error-text">Enable JavaScript and cookies to continue</span></div></noscript></div></div><script>(function(){window._cf_chl_opt = {cvId: '3',cZone: 'garage.redbull.com',cType: 'managed',cRay: '9bba7f91ec63f591',cH: 'AhW.3BVFq05XdRooQB_s_PrsOilqAphkMxrDC9OAsEw-1768030533-1.2.1.1-CgW.85tfdqad8UwCWHXIpVBN.LJzONCOh83sX_EPHSTzngc7PTnBd8RHxmukpclj',cUPMDTk:"\/?__cf_chl_tk=O3n4OjnoraJwlGj7DZQ2kVi5WwCgtwtn02xA_2vNNDs-1768030533-1.0.1.1-O_1IoYVlpgrXfBgIa5Go0.8LtVKdlGISebNzB_ZMQIo",cFPWv: 'g',cITimeS: '1768030533',cTplC:0,cTplV:5,cTplB: '0',fa:"\/?__cf_chl_f_tk=O3n4OjnoraJwlGj7DZQ2kVi5WwCgtwtn02xA_2vNNDs-1768030533-1.0.1.1-O_1IoYVlpgrXfBgIa5Go0.8LtVKdlGISebNzB_ZMQIo",md: 'BPhUj_rn5P8iA4o4b20uCjaaWq1eNiO6NUloNN73Two-1768030533-1.2.1.1-eLFSBf7Q_wcxm4EVjnPnVJg0F.oi1kDAGjKm2kna_UVIHaICoUU8Oq4RBffubHd0jRPxvwXE_ceivz78wFp9ptp8kd7hY4cAyEwmHrqEXMFruUy76GilULUdhAje7vLQER7erOh6npAHpa1UfuzGEC4dC7b.cRVhmUTtSKIyEYjWLY0RosOCSNxEicey3ELitFta4yxCcZvVGDlyr2TeMVyIvl4.WzIALurfSOeIirO09hcpUnvRMfUcNzVbUaFjmgqFgS.Q1VPM2_BqY7zp_SiieZU.Ix_jeuvsI0esYm9QKcAiY8m6Ocu2xe_2GaRyRKs.4lKhSXu51cp_.L6XJxxR4pWUKjK52DVlp9fjo7d4S3J0Y33UMiS7RkC_.fbcCHoXtutehgwRs0bE3297_9CwRjzZIEOx.DaODJr_b7uFolwOHyeQL4n7tSyiURdTX1TzC9_J6Nrrv1w3nzCK6A81QETZlqHhMooA8i3VNrMSDKZ7RrWgY9X2l8u.GWrwepB2TUm7bmMeyMaJgN_jeGDRHouUZ9jRMl.kM2o2Q3sjsStROJI1KxT2akfVcVsSsOaiwFI5_.UlUFLwYzHEsjEBXUX2jlA4Ktn76RRbFruLiyJSkksTfSOVtbercmODBDGJ8KVwptlcPWYYaUI_hD.QdiyOALs3VKnLlrYh0_jjQy1uJ3TX1CB3U__0RIzfpvbeVBKd_tileMTUbZ3gridpEca9DxsbKtQloMC1QW1DYmTQ3uhTmWVxdUa5gIJIpSrgC9h8TIfs1.2WYX4C5NCCzanC7fZnkjOqpibRSys6rahiqN8JMpqFfkAokOhE1hbie3CICucDwTykBP4LfEiWr4pJDTsHdmP7z.kefJoqzl7Xtz8H0AyMR1feNEyATLR9TMHnlUgz_1vvdRz6.XTfxCeTvoFvC7vWYPm1gNbdLsNn.y2sc31EUWlo2AwbrD71rI0FwF0MkcjIBu8tmoSLPO6CQO5IhZtK_1hdYvNGH11hcgeCYQYy1IABXPOY',mdrd: 'DF5wPwNsrPZs5nbBkwI9BiSwsswhO4tuHK9diNpgewo-1768030533-1.2.1.1-y4jxLWiMOHW28TotDnKb3Nt.64D.55XIxqQzu4KmULWWI9d39rYG8Up..RRe_Hnjp91RUGRiBpbHMf1PO8l2a9wkcTd3eChAE9e8h3y8ZAMlNKL6ltrS3hnlEYMCspqR4yX.27BiTXQxyzuuwI3JWJAWD4Px0.nS1R.zPMuFOw_lOsHMJSIeV8U8xLfd1zZ.t8LodM.aa1yHC.CjjUTWVjEmCY1zSzNNFy0j3OLGQ_HsAgWP_Sw4JxV..0zk1Yrxl71Gxt.usZPsTmV8qLhzzNUbo4X88pmG2ccXHGrgGR6fVAVjAzhI8mBfXd0mPKp6z_V9JsSeS5LJkdUfHK94lxQt6rvUqSsNEFXLRN5SJnyPYeAeS7qfl8mT4LYxOMqB