The Kafka instance is available to the public without authentication.
An attacker could connect to the queue to extract private/confidential information in real-time.
Fingerprint: 43224224eeda9da960defeaa3c693ea2ac57d9dd421117c395f737a6ddadac27
NoAuth Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic act-control
Fingerprint: 43224224eeda9da960defeaa7a7cc72fd0b67cf622843e2522ab843e19da745f
NoAuth Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data
Fingerprint: 43224224eeda9da960defeaaa3eb12754475692ba1bf5e1e848d043148b3a373
NoAuth Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic act-control Found topic ctrl-webhook
Fingerprint: 43224224eeda9da960defeaab6516b250b9edc9a876c27dbee598c7ffa71992b
NoAuth Found topic sns-control Found topic slikemonitor Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket
Fingerprint: 43224224eeda9da960defeaaa11912b9eb92e93acb359772262f1bed36710c99
NoAuth Found topic slikemonitor Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control
Fingerprint: 43224224eeda9da960defeaaeb88674b24df146faf62b08c405a8ca6450f05b9
NoAuth Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor
Fingerprint: 43224224eeda9da960defeaa4f1471fc108d99d911cde7e0aefcdf1359c5ccff
NoAuth Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic act-control Found topic ctrl-webhook Found topic act-server
Fingerprint: 43224224eeda9da960defeaab6516b250b9edc9a44424061e36d64425c59666e
NoAuth Found topic sns-control Found topic slikemonitor Found topic hello_human Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket
Fingerprint: 43224224eeda9da960defeaaeb88674b24df146faf62b08c405a8ca6ce35a528
NoAuth Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic hello_human
Fingerprint: 43224224eeda9da960defeaac8833271cc5305f247261ecacc4a215544076e76
NoAuth Found topic hello_human Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor
Fingerprint: 43224224eeda9da960defeaa7a7cc72fd0b67cf622843e25570442447a595f10
NoAuth Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic hello_human Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data
Fingerprint: 43224224eeda9da960defeaaa11912b92d6a2428693fe4a12a95d66565495098
NoAuth Found topic slikemonitor Found topic hello_human Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control
Fingerprint: 43224224eeda9da960defeaa4f1471fc108d99d911cde7e0aefcdf13cec0d7e8
NoAuth Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic hello_human Found topic act-control Found topic ctrl-webhook Found topic act-server
Fingerprint: 43224224eeda9da960defeaaa3eb12754475692ba1bf5e1e848d0431d12d981e
NoAuth Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic hello_human Found topic act-control Found topic ctrl-webhook
Fingerprint: 43224224eeda9da960defeaa3c693ea2ac57d9dd421117c395f737a6ba4a96fe
NoAuth Found topic ctrl-webhook Found topic act-server Found topic act-data Found topic act-socket Found topic sns-control Found topic slikemonitor Found topic hello_human Found topic act-control
Fingerprint: 43224224eeda9da960defeaaa3eb12754475692ba1bf5e1e24275c97a3028e1b
NoAuth Found topic act-server Found topic act-data Found topic act-socket Found topic act-control Found topic ctrl-webhook
Fingerprint: 43224224eeda9da960defeaa7a7cc72f866c0b403a3ac1b8282155536a2708e9
NoAuth Found topic act-socket Found topic act-control Found topic ctrl-webhook Found topic act-server Found topic act-data
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652215d5e17e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/arkayappsteam/mmp-admin fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652215d5e17e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/arkayappsteam/mmp-admin fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652215d5e17e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/arkayappsteam/mmp-admin fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
PHPinfo page has been found in this directory. The PHPinfo page outputs a large amount of information about the current state of PHP.
This includes information about PHP compilation options and extensions, the PHP version, server information and environment (if compiled as a module), the PHP environment, OS version information, paths, master and local values of configuration options, HTTP headers, and the PHP License.
Environment variables may contain credentials.
Fingerprint: 2c44e2a6278fb0134173d6faf17664eef759381663957a4ec587e4b0caef8a92
Found PHP info page: $_SERVER['HTTP_HOST'] = 139.59.28.34 $_SERVER['HTTP_USER_AGENT'] = l9explore/v0.8.0 $_SERVER['HTTP_ACCEPT_ENCODING'] = gzip $_SERVER['HTTP_CONNECTION'] = close $_SERVER['PATH'] = /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin $_SERVER['SERVER_SIGNATURE'] = <address>Apache/2.4.18 (Ubuntu) Server at 139.59.28.34 Port 80</address> $_SERVER['SERVER_SOFTWARE'] = Apache/2.4.18 (Ubuntu) $_SERVER['SERVER_NAME'] = 139.59.28.34 $_SERVER['SERVER_ADDR'] = 139.59.28.34 $_SERVER['SERVER_PORT'] = 80 $_SERVER['REMOTE_ADDR'] = 167.71.13.196 $_SERVER['DOCUMENT_ROOT'] = /var/www/html $_SERVER['REQUEST_SCHEME'] = http $_SERVER['CONTEXT_PREFIX'] = no value $_SERVER['CONTEXT_DOCUMENT_ROOT'] = /var/www/html $_SERVER['SERVER_ADMIN'] = webmaster@localhost $_SERVER['SCRIPT_FILENAME'] = /var/www/html/info.php $_SERVER['REMOTE_PORT'] = 49636 $_SERVER['GATEWAY_INTERFACE'] = CGI/1.1 $_SERVER['SERVER_PROTOCOL'] = HTTP/1.1 $_SERVER['REQUEST_METHOD'] = GET $_SERVER['QUERY_STRING'] = no value $_SERVER['REQUEST_URI'] = /info.php $_SERVER['SCRIPT_NAME'] = /info.php $_SERVER['PHP_SELF'] = /info.php $_SERVER['REQUEST_TIME_FLOAT'] = 1622121778.299 $_SERVER['REQUEST_TIME'] = 1622121778