The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652245c93401
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@gitee.com:bw_5iketang/eduoperateweb.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "develop"] remote = origin merge = refs/heads/develop [branch "feature-v1.1"] remote = origin merge = refs/heads/feature-v1.1
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652251cb0d6b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitee.com/bw_5iketang/eduoperateweb.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "temp"] remote = origin merge = refs/heads/temp [branch "feature-v1.1"] remote = origin merge = refs/heads/feature-v1.1
Elasticsearch and/or Kibana is currently open without authentication.
Additionaly a ransom note has been found in the dataset which indicates it has been compromised
This results in all the database data made available publicly.
Severity: critical
Fingerprint: 831cb76b8e05df46404ef49338dd0b583cef79a6179ab667af81feed9b3f62fd
Indices: 5, document count: 63129, size: 67.1 MB Found index needs-chats-data with 4055 documents (1.2 MB) Found index edusasssvc-api with 59067 documents (65.9 MB) Found index readme with 1 documents (5.5 kB) Found index edumediasvc-api with 6 documents (64.1 kB) Found index edumicrosvc-rpc with 0 documents (1.3 kB)
Severity: critical
Fingerprint: 831cb76b8e05df468174ba2be10ce3eb0bc5eca8acdf9535acdf9535acdf9535
Indices: 3, document count: 12973, size: 21.0 MB Found index needs-chats-data with 203 documents (287.8 kB) Found index edusasssvc-api with 12769 documents (20.7 MB) Found index readme with 1 documents (5.5 kB)
Severity: critical
Fingerprint: 831cb76b8e05df462ff999c883cbcc0e4e9e1f8382e4c13741f7f10e28e13867
Indices: 5, document count: 198476, size: 89.4 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 172528 documents (42.9 MB) Found index edusasssvc-api with 25840 documents (46.2 MB) Found index needs-files with 107 documents (258.5 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df465f366a595ded1fa9ee9a0bbaf9e44d8ded3afab127b31282
Indices: 5, document count: 193691, size: 85.5 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 169191 documents (42.1 MB) Found index edusasssvc-api with 24393 documents (43.2 MB) Found index needs-files with 106 documents (244.0 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df46a0b0ddd2c7b3048407a469be1fc2140f231baed0231baed0
Indices: 4, document count: 161878, size: 40.8 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 161780 documents (40.4 MB) Found index needs-files with 97 documents (392.0 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df469fa3f10aeb470bdc47538f3f9c62f8b47e6b09657e6b0965
Indices: 4, document count: 156970, size: 39.7 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 156875 documents (39.4 MB) Found index needs-files with 94 documents (358.9 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df46cfe0423012feb93654570e48d3321437a2716968a2716968
Indices: 4, document count: 154786, size: 39.2 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 154693 documents (38.8 MB) Found index needs-files with 92 documents (344.4 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df467573091ecec3b5805d272f1155ff6e3a3c0a56f33c0a56f3
Indices: 4, document count: 148079, size: 45.5 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 147986 documents (45.2 MB) Found index needs-files with 92 documents (344.4 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df468a90e04b52c7286765cbf4cb7a599fd57d9ab1767d9ab176
Indices: 4, document count: 143745, size: 44.4 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 143652 documents (44.0 MB) Found index needs-files with 92 documents (344.1 kB) Found index read_me with 1 documents (5.6 kB)
Severity: critical
Fingerprint: 831cb76b8e05df461904b07721b7ad83e31617dd7371f2a7b6b417f8b6b417f8
Indices: 4, document count: 140322, size: 36.3 MB Found index index with 0 documents (1.3 kB) Found index needs-chats with 140229 documents (35.9 MB) Found index needs-files with 92 documents (344.1 kB) Found index read_me with 1 documents (5.6 kB)
Severity: high
Fingerprint: 831cb76b8e05df468b1b16a4a85ec2b5a85ec2b5a85ec2b5a85ec2b5a85ec2b5
Indices: 1, document count: 1, size: 5.6 kB Found index read_me with 1 documents (5.6 kB)
Severity: high
Fingerprint: 831cb76b8e05df46feeb274c2babbe27c4775bbd5797c9c58c7963483dcc37b8
Indices: 8, document count: 9955, size: 3.2 MB Found index v2 with 1 documents (8.0 kB) Found index admin with 1 documents (5.7 kB) Found index actuator with 1 documents (5.7 kB) Found index v1 with 1 documents (7.6 kB) Found index needs-chats with 9845 documents (2.9 MB) Found index api with 1 documents (8.0 kB) Found index auth with 1 documents (4.7 kB) Found index needs-files with 104 documents (267.2 kB)
Severity: high
Fingerprint: 831cb76b8e05df46558af4c4e8d7222fbea7548577bb03bd1e2e87808b1166db
Indices: 8, document count: 8895, size: 3.4 MB Found index v2 with 1 documents (8.0 kB) Found index admin with 1 documents (5.7 kB) Found index actuator with 1 documents (5.7 kB) Found index v1 with 1 documents (7.6 kB) Found index needs-chats with 8785 documents (3.1 MB) Found index api with 1 documents (8.0 kB) Found index auth with 1 documents (4.7 kB) Found index needs-files with 104 documents (267.0 kB)
Severity: high
Fingerprint: 831cb76b8e05df461835bc1e7c6b06c55fab02b75fab02b75fab02b75fab02b7
Indices: 2, document count: 95697, size: 23.2 MB Found index needs-chats with 95366 documents (22.7 MB) Found index needs-files with 331 documents (521.2 kB)
Fingerprint: 831cb76b8e05df46fc901b6e2863532f0537ec319576d5b0f54d5f5fce21a145
Indices: 44, document count: 1111, size: 824.1 kB Found index rn7eye7jxs-meow with 0 documents (1.3 kB) Found index 7m3fta7033-meow with 0 documents (1.3 kB) Found index sdon7euv07-meow with 0 documents (1.3 kB) Found index 78r9n5ik52-meow with 0 documents (1.3 kB) Found index ylpz3piab7-meow with 0 documents (1.3 kB) Found index shk5vemttm-meow with 0 documents (1.3 kB) Found index botl3a89c1-meow with 0 documents (1.3 kB) Found index 9pk7n3li3e-meow with 0 documents (1.3 kB) Found index 01jy27hjgm-meow with 0 documents (1.3 kB) Found index 30tn0yysf1-meow with 0 documents (1.3 kB) Found index xo7w9o1mt2-meow with 0 documents (1.3 kB) Found index rru12pyfca-meow with 0 documents (1.3 kB) Found index z7cf568d0x-meow with 0 documents (1.3 kB) Found index i2j3p95s4n-meow with 0 documents (1.3 kB) Found index qexs1vqs82-meow with 0 documents (1.3 kB) Found index 1xsqco1yq1-meow with 0 documents (1.3 kB) Found index 9o3eu9l903-meow with 0 documents (1.3 kB) Found index 16nvolr8vj-meow with 0 documents (1.3 kB) Found index hw07gq7gds-meow with 0 documents (1.3 kB) Found index wtjp6zpl6m-meow with 0 documents (1.3 kB) Found index hy9ciayvhz-meow with 0 documents (1.3 kB) Found index rfhgdam7js-meow with 0 documents (1.3 kB) Found index 9017v9ep6c-meow with 0 documents (1.3 kB) Found index j8pcv1k07u-meow with 0 documents (1.3 kB) Found index sge7wfcknr-meow with 0 documents (1.3 kB) Found index o897isy7st-meow with 0 documents (1.3 kB) Found index y0c2s8wnyc-meow with 0 documents (1.3 kB) Found index q8dzi1fho2-meow with 0 documents (1.3 kB) Found index wp35dmrip2-meow with 0 documents (1.3 kB) Found index 4tw10locg5-meow with 0 documents (1.3 kB) Found index needs-files-data with 5 documents (39.8 kB) Found index 4wl559y5wk-meow with 0 documents (1.3 kB) Found index needs-chats with 0 documents (1.3 kB) Found index 0w469vbdjj-meow with 0 documents (1.3 kB) Found index 6srhj1qcff-meow with 0 documents (1.3 kB) Found index needs-files with 0 documents (1.3 kB) Found index kam6h6z2q1-meow with 0 documents (1.3 kB) Found index nc0q3cm3j3-meow with 0 documents (1.3 kB) Found index sazw9h37dw-meow with 0 documents (1.3 kB) Found index dqwt6q1ymp-meow with 0 documents (1.3 kB) Found index 7it1gdqzir-meow with 0 documents (1.3 kB) Found index needs-chats-data with 1106 documents (729.5 kB) Found index owt1a3lyxx-meow with 0 documents (1.3 kB) Found index 7nb5uczb5t-meow with 0 documents (1.3 kB)
The Consul server is public.
This could leak in infrastructure details and/or credentials being leaked and exploited by attackers.
Severity: high
Fingerprint: 96e51961ecd20ac07e1f8836618e057cbe3e4b7a07cdf36791d9157a004931cd
Found 16 keys in consul: Hostname: devs-test Keys: needs/go.micro.dcenter/all/apps/133VKB147 needs/go.micro.dcenter/all/apps/13cf9a277278dccaa51f0c6d722bc935 needs/go.micro.dcenter/all/apps/1b1d4749d4bbd5f98ae79dcaf13da072 needs/go.micro.dcenter/all/apps/1c24115242b3b62645ab98f093d245b3 needs/go.micro.dcenter/all/apps/215E30RU2 needs/go.micro.dcenter/all/apps/3e4dcb6fa18ed2a465ef55774495cfe4 needs/go.micro.dcenter/all/apps/4fae1f4e042e22f6f6b524f966f4d8cc needs/go.micro.dcenter/all/apps/558f895b8a3ccf536cf50075ae6f7c41 needs/go.micro.dcenter/all/apps/572bf8db1dd6a9d8e130405d0cc7ddb1 needs/go.micro.dcenter/all/apps/71ecc03f12b419a5018d31faa13d4245 needs/go.micro.dcenter/all/apps/754dc6500d12cefa93a046a6c8d42cdc needs/go.micro.dcenter/all/apps/8aaf4d9f7aebd03ef9f39c01e3280acd needs/go.micro.dcenter/all/apps/8dd6e5cdcc72f8accb47ca831abda7a3 needs/go.micro.dcenter/all/apps/be94dac697b1ca4b700f1cb97a2846a2 needs/go.micro.dcenter/all/apps/c6ca4045b52f05a4b4132c3b2be65991 needs/go.micro.hat/all/hatms/queues
Severity: high
Fingerprint: 96e51961ecd20ac07e1f8836f7e3d559fcecaa192d2bd56248dfd103ad08148c
Found 16 keys in consul: Hostname: vm-0-17-centos Keys: needs/go.micro.dcenter/all/apps/133VKB147 needs/go.micro.dcenter/all/apps/13cf9a277278dccaa51f0c6d722bc935 needs/go.micro.dcenter/all/apps/1b1d4749d4bbd5f98ae79dcaf13da072 needs/go.micro.dcenter/all/apps/1c24115242b3b62645ab98f093d245b3 needs/go.micro.dcenter/all/apps/215E30RU2 needs/go.micro.dcenter/all/apps/3e4dcb6fa18ed2a465ef55774495cfe4 needs/go.micro.dcenter/all/apps/4fae1f4e042e22f6f6b524f966f4d8cc needs/go.micro.dcenter/all/apps/558f895b8a3ccf536cf50075ae6f7c41 needs/go.micro.dcenter/all/apps/572bf8db1dd6a9d8e130405d0cc7ddb1 needs/go.micro.dcenter/all/apps/71ecc03f12b419a5018d31faa13d4245 needs/go.micro.dcenter/all/apps/754dc6500d12cefa93a046a6c8d42cdc needs/go.micro.dcenter/all/apps/8aaf4d9f7aebd03ef9f39c01e3280acd needs/go.micro.dcenter/all/apps/8dd6e5cdcc72f8accb47ca831abda7a3 needs/go.micro.dcenter/all/apps/be94dac697b1ca4b700f1cb97a2846a2 needs/go.micro.dcenter/all/apps/c6ca4045b52f05a4b4132c3b2be65991 needs/go.micro.hat/all/hatms/queues
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c8c9af8b78c9af8b7a4a90c496d4548397d244cfd2385b204
Found 128 files trough .DS_Store spidering: /add.php /apijs /APITest.html /crossdomain.xml /css /delete.php /demo.html /favicon.ico /favicon.xcf /fonts /images /images/1.png /images/2.png /images/3.png /images/4.png /images/5.png /images/5i.png /images/5i_ad.jpg /images/5i_logo.png /images/add.png /images/admin /images/Ali.png /images/Alipay.png /images/arrow_down.png /images/arrow_normal.png /images/arrow_right.png /images/arrow_selected.png /images/arrow_up.png /images/banner-bg.jpg /images/banner.jpg /images/bbs /images/bg_nav_mr.png /images/bg_tab_off_long.png /images/bg_tab_on_long.png /images/btn_s_left.png /images/btn_s_right.png /images/C1.png /images/check2.png /images/checkbox1.png /images/checkbox_bg.png /images/checkp.png /images/closeline.png /images/cloud /images/column /images/common /images/course /images/course-table /images/data /images/default /images/device /images/disc.png /images/drop_down_normal.png /images/drop_down_selected.png /images/duxue /images/fail.png /images/fengge1.png /images/fengge2.png /images/fengge3.png /images/finance /images/Group.png /images/h5_style_1.png /images/h5_style_2.png /images/h5Login /images/hdb /images/help_img.png /images/huo_jian.png /images/ic-home-class-pressed.png /images/ic-home-class-pressed.svg /images/ic-home-class-unpressed.png /images/ic-home-class-unpressed.svg /images/ic-home-community-pressed.png /images/ic-home-community-pressed.svg /images/ic-home-community-unpressed.png /images/ic-home-community-unpressed.svg /images/ic-home-home-pressed.png /images/ic-home-home-pressed.svg /images/ic-home-home-unpressed.png /images/ic-home-home-unpressed.svg /images/ic-home-mine-pressed.png /images/ic-home-mine-pressed.svg /images/ic-home-mine-unpressed.png /images/ic-home-mine-unpressed.svg /images/ic-home-tutoring-pressed.png /images/ic-home-tutoring-unpressed.png /images/ico-home-tutoring-pressed.svg /images/ico-home-tutoring-unpressed.svg /images/icon /images/icon_arrow_down.png /images/icon_arrow_top.png /images/icon_x.png /images/interact /images/ios-pay /images/left1.png /images/left10.png /images/license /images/live /images/live.png /images/live_bf.png /images/load_img.gif /images/loading.gif /images/loading1.gif /images/login /images/logo.png /images/logo3.png /images/main_bg.png /images/manage_bg.png /images/market /images/meida-proxy /images/modal_bg.png /images/more_arrow_right.png /images/more_normal.png /images/more_selected.png /images/my /images/no_picture.jpg /images/operator-data /images/order /images/quiz /images/resource /images/right1.png /images/right10.png /images/search.png /images/search110.png /images/search2.png /images/setting.png /images/setting_bg_face.jpg /images/shi_pin.png /images/show /images/shuaxin.png
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b68d3c666c595ae6809b8c6636d58dd7c9
Found 28 files trough .DS_Store spidering: /add.php /apijs /APITest.html /crossdomain.xml /css /delete.php /demo.html /favicon.ico /favicon.xcf /fonts /images /index.html /index.php /index_api.php /index_daas.php /index_dev.php /js /kindeditor.html /limL3PAF2H.txt /networkTest.php /patrol /playVideoDemo.html /robots.txt /static /stats.json /template /themes /version.html
Severity: low
Fingerprint: 5f32cf5d6962f09c4239b3d84239b3d8e7988dc4065fd23456cf4de74268a691
Found 8 files trough .DS_Store spidering: /apijs /css /fonts /images /js /static /template /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09c92dfb71592dfb715179ac6fd2acf3b45492f2fae38953418
Found 45 files trough .DS_Store spidering: /apijs /css /fonts /images /images/admin /images/bbs /images/cloud /images/column /images/common /images/course /images/course-table /images/data /images/default /images/device /images/duxue /images/finance /images/h5Login /images/hdb /images/icon /images/interact /images/ios-pay /images/license /images/live /images/login /images/market /images/meida-proxy /images/my /images/operator-data /images/order /images/quiz /images/resource /images/show /images/site /images/smartData /images/statistic /images/student /images/styj /images/test /images/user /images/web /images/wutonghui /js /static /template /themes
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c8c9af8b78c9af8b7a4a90c496d4548397d244cfd2385b204
Found 128 files trough .DS_Store spidering: /add.php /apijs /APITest.html /crossdomain.xml /css /delete.php /demo.html /favicon.ico /favicon.xcf /fonts /images /images/1.png /images/2.png /images/3.png /images/4.png /images/5.png /images/5i.png /images/5i_ad.jpg /images/5i_logo.png /images/add.png /images/admin /images/Ali.png /images/Alipay.png /images/arrow_down.png /images/arrow_normal.png /images/arrow_right.png /images/arrow_selected.png /images/arrow_up.png /images/banner-bg.jpg /images/banner.jpg /images/bbs /images/bg_nav_mr.png /images/bg_tab_off_long.png /images/bg_tab_on_long.png /images/btn_s_left.png /images/btn_s_right.png /images/C1.png /images/check2.png /images/checkbox1.png /images/checkbox_bg.png /images/checkp.png /images/closeline.png /images/cloud /images/column /images/common /images/course /images/course-table /images/data /images/default /images/device /images/disc.png /images/drop_down_normal.png /images/drop_down_selected.png /images/duxue /images/fail.png /images/fengge1.png /images/fengge2.png /images/fengge3.png /images/finance /images/Group.png /images/h5_style_1.png /images/h5_style_2.png /images/h5Login /images/hdb /images/help_img.png /images/huo_jian.png /images/ic-home-class-pressed.png /images/ic-home-class-pressed.svg /images/ic-home-class-unpressed.png /images/ic-home-class-unpressed.svg /images/ic-home-community-pressed.png /images/ic-home-community-pressed.svg /images/ic-home-community-unpressed.png /images/ic-home-community-unpressed.svg /images/ic-home-home-pressed.png /images/ic-home-home-pressed.svg /images/ic-home-home-unpressed.png /images/ic-home-home-unpressed.svg /images/ic-home-mine-pressed.png /images/ic-home-mine-pressed.svg /images/ic-home-mine-unpressed.png /images/ic-home-mine-unpressed.svg /images/ic-home-tutoring-pressed.png /images/ic-home-tutoring-unpressed.png /images/ico-home-tutoring-pressed.svg /images/ico-home-tutoring-unpressed.svg /images/icon /images/icon_arrow_down.png /images/icon_arrow_top.png /images/icon_x.png /images/interact /images/ios-pay /images/left1.png /images/left10.png /images/license /images/live /images/live.png /images/live_bf.png /images/load_img.gif /images/loading.gif /images/loading1.gif /images/login /images/logo.png /images/logo3.png /images/main_bg.png /images/manage_bg.png /images/market /images/meida-proxy /images/modal_bg.png /images/more_arrow_right.png /images/more_normal.png /images/more_selected.png /images/my /images/no_picture.jpg /images/operator-data /images/order /images/quiz /images/resource /images/right1.png /images/right10.png /images/search.png /images/search110.png /images/search2.png /images/setting.png /images/setting_bg_face.jpg /images/shi_pin.png /images/show /images/shuaxin.png
Severity: low
Fingerprint: 5f32cf5d6962f09c31c2f0b631c2f0b68d3c666c595ae6809b8c6636d58dd7c9
Found 28 files trough .DS_Store spidering: /add.php /apijs /APITest.html /crossdomain.xml /css /delete.php /demo.html /favicon.ico /favicon.xcf /fonts /images /index.html /index.php /index_api.php /index_daas.php /index_dev.php /js /kindeditor.html /limL3PAF2H.txt /networkTest.php /patrol /playVideoDemo.html /robots.txt /static /stats.json /template /themes /version.html
Severity: low
Fingerprint: 5f32cf5d6962f09c4239b3d84239b3d8e7988dc4065fd23456cf4de74268a691
Found 8 files trough .DS_Store spidering: /apijs /css /fonts /images /js /static /template /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09c92dfb71592dfb715179ac6fd2acf3b45492f2fae38953418
Found 45 files trough .DS_Store spidering: /apijs /css /fonts /images /images/admin /images/bbs /images/cloud /images/column /images/common /images/course /images/course-table /images/data /images/default /images/device /images/duxue /images/finance /images/h5Login /images/hdb /images/icon /images/interact /images/ios-pay /images/license /images/live /images/login /images/market /images/meida-proxy /images/my /images/operator-data /images/order /images/quiz /images/resource /images/show /images/site /images/smartData /images/statistic /images/student /images/styj /images/test /images/user /images/web /images/wutonghui /js /static /template /themes
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522fcbdb838
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/tobias74/elasticsearch-head.git fetch = +refs/heads/master:refs/remotes/origin/master [branch "master"] remote = origin merge = refs/heads/master