nginx
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 125.229.182.241:80 · gitlab.yflelite.com
2024-12-22 04:31
HTTP/1.1 301 Moved Permanently Server: nginx Date: Sun, 22 Dec 2024 04:31:39 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://gitlab.yflelite.com:443/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 125.229.182.241:443 · gitlab.yflelite.com
2024-12-22 04:31
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 04:31:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 107 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.yflelite.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFPA5BWC3C49XBP1T21XGASA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFPA5BWC3C49XBP1T21XGASA X-Runtime: 0.027404 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.yflelite.com/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-22 00:53
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:53:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXP7RPR891M9QFNMZ9GJ4F","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXP7RPR891M9QFNMZ9GJ4F X-Runtime: 0.026403 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-20 00:04
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:04:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGP1YMH0Z0BTMS9M2S7GG4T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGP1YMH0Z0BTMS9M2S7GG4T X-Runtime: 0.027324 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-17 21:52
HTTP/1.1 302 Found Server: nginx Date: Tue, 17 Dec 2024 21:52:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFB9QYVCGJR3GDV11QGZ3VXA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFB9QYVCGJR3GDV11QGZ3VXA X-Runtime: 0.026957 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-15 21:54
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 21:54:30 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF651P0PSNH43DDSMJD9A65D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF651P0PSNH43DDSMJD9A65D X-Runtime: 0.033171 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-13 21:48
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 21:48:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF0ZWPXH3EJ3B2J1ZCXE417E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF0ZWPXH3EJ3B2J1ZCXE417E X-Runtime: 0.011395 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-11 23:54
HTTP/1.1 302 Found Server: nginx Date: Wed, 11 Dec 2024 23:54:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW2B4Z9THAPR94EW4C4AKZW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW2B4Z9THAPR94EW4C4AKZW X-Runtime: 0.032902 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-12-01 23:30
HTTP/1.1 302 Found Server: nginx Date: Sun, 01 Dec 2024 23:30:53 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2903FYFM7MY6V0CVRBM8A9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2903FYFM7MY6V0CVRBM8A9 X-Runtime: 0.027315 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-11-29 23:18
HTTP/1.1 302 Found Server: nginx Date: Fri, 29 Nov 2024 23:18:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX3FGC1MF476G72X294YVZG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX3FGC1MF476G72X294YVZG X-Runtime: 0.033231 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>
Open service 125.229.182.241:443
2024-11-28 00:14
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 00:14:05 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://125.229.182.241/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR1WACXT7MREHHH9BE6MTJ6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR1WACXT7MREHHH9BE6MTJ6 X-Runtime: 0.032474 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://125.229.182.241/users/sign_in">redirected</a>.</body></html>