Apache 2.4.38
tcp/5001
nginx 1.14.1
tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522c433f286
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/phoenix-stark/foodchoice-api fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzVWU3JSSjN3M0VUUDVia3VLWDRZakZQd0JDbXp5ZjBDOEVDSA== [branch "main"] remote = origin merge = refs/heads/main
Severity: medium
Fingerprint: 2580fa947e78dd08de9da9e3a549c38eb3642c6815c27e421483485ba82f6c2f
HTTP/1.1 403 Forbidden Date: Mon, 08 May 2023 20:46:27 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html> [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/phoenix-stark/foodchoice-api fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzVWU3JSSjN3M0VUUDVia3VLWDRZakZQd0JDbXp5ZjBDOEVDSA== [branch "main"] remote = origin merge = refs/heads/main
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65220b513b01
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/phoenix-stark/foodchoice-api fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2owVm9OS0NtblRhY29IRUJoRml1NTlBRDl3bElHdDBIR2d6UA== [branch "develop"] remote = origin merge = refs/heads/develop
Open service 150.95.27.68:5001
2025-01-13 22:59
HTTP/1.1 403 Forbidden Date: Mon, 13 Jan 2025 23:00:24 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2025-01-11 22:03
HTTP/1.1 403 Forbidden Date: Sat, 11 Jan 2025 22:04:48 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2025-01-09 21:06
HTTP/1.1 403 Forbidden Date: Thu, 09 Jan 2025 21:07:18 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2025-01-07 22:30
HTTP/1.1 403 Forbidden Date: Tue, 07 Jan 2025 22:31:01 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:80
2025-01-07 01:07
HTTP/1.1 200 OK Server: nginx/1.14.1 Date: Tue, 07 Jan 2025 01:08:58 GMT Content-Type: text/html Content-Length: 4057 Last-Modified: Mon, 07 Oct 2019 21:16:24 GMT Connection: close ETag: "5d9bab28-fd9" Accept-Ranges: bytes Page title: Test Page for the Nginx HTTP Server on Red Hat Enterprise Linux <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <title>Test Page for the Nginx HTTP Server on Red Hat Enterprise Linux</title> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <style type="text/css"> /*<![CDATA[*/ body { background-color: #fff; color: #000; font-size: 0.9em; font-family: sans-serif,helvetica; margin: 0; padding: 0; } :link { color: #c00; } :visited { color: #c00; } a:hover { color: #f50; } h1 { text-align: center; margin: 0; padding: 0.6em 2em 0.4em; background-color: #900; color: #fff; font-weight: normal; font-size: 1.75em; border-bottom: 2px solid #000; } h1 strong { font-weight: bold; font-size: 1.5em; } h2 { text-align: center; background-color: #900; font-size: 1.1em; font-weight: bold; color: #fff; margin: 0; padding: 0.5em; border-bottom: 2px solid #000; } hr { display: none; } .content { padding: 1em 5em; } .alert { border: 2px solid #000; } img { border: 2px solid #fff; padding: 2px; margin: 2px; } a:hover img { border: 2px solid #294172; } .logos { margin: 1em; text-align: center; } /*]]>*/ </style> </head> <body> <h1>Welcome to <strong>nginx</strong> on Red Hat Enterprise Linux!</h1> <div class="content"> <p>This page is used to test the proper operation of the <strong>nginx</strong> HTTP server after it has been installed. If you can read this page, it means that the web server installed at this site is working properly.</p> <div class="alert"> <h2>Website Administrator</h2> <div class="content"> <p>This is the default <tt>index.html</tt> page that is distributed with <strong>nginx</strong> on Red Hat Enterprise Linux. It is located in <tt>/usr/share/nginx/html</tt>.</p> <p>You should now put your content in a location of your choice and edit the <tt>root</tt> configuration directive in the <strong>nginx</strong> configuration file <tt>/etc/nginx/nginx.conf</tt>.</p> <p>For information on Red Hat Enterprise Linux, please visit the <a href="http://www.redhat.com/">Red Hat, Inc. website</a>. The documentation for Red Hat Enterprise Linux is <a href="http://www.redhat.com/docs/manuals/enterprise/">available on the Red Hat, Inc. website</a>.</p> </div> </div> <div class="logos"> <a href="http://nginx.net/"><img src="nginx-logo.png" alt="[ Powered by nginx ]" width="121" height="32" /></a> <a href="http://www.redhat.com/"><img src="poweredby.png" alt="[ Powered by Red Hat Enterprise Linux ]" width="88" height="31" /></a> </div> </div> </body> </html>
Open service 150.95.27.68:5000
2025-01-06 18:26
HTTP/1.1 200 OK X-Powered-By: Express Access-Control-Allow-Origin: * Access-Control-Allow-Methods: * Access-Control-Allow-Headers: * Content-Type: text/html; charset=utf-8 Accept-Ranges: bytes Content-Length: 1694 ETag: W/"69e-SkTunDtc5520rYh+mO1G/ObSNCE" Vary: Accept-Encoding Date: Mon, 06 Jan 2025 18:27:34 GMT Connection: close Page title: Foodchoice <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8" /> <link rel="icon" href="/favicon.ico" /> <meta name="viewport" content="width=device-width, initial-scale=1" /> <meta name="theme-color" content="#000000" /> <meta name="description" content="Foodchoice backoffice" /> <link rel="apple-touch-icon" href="/logo192.png" /> <!-- manifest.json provides metadata used when your web app is installed on a user's mobile device or desktop. See https://developers.google.com/web/fundamentals/web-app-manifest/ --> <link rel="manifest" href="/manifest.json" /> <!-- Notice the use of in the tags above. It will be replaced with the URL of the `public` folder during the build. Only files inside the `public` folder can be referenced from the HTML. Unlike "/favicon.ico" or "favicon.ico", "/favicon.ico" will work correctly both with client-side routing and a non-root public URL. Learn how to configure a non-root public URL by running `npm run build`. --> <title>Foodchoice</title> <script defer src="/static/js/bundle.js"></script></head> <body> <noscript>You need to enable JavaScript to run this app.</noscript> <div id="root"></div> <!-- This HTML file is a template. If you open it directly in the browser, you will see an empty page. You can add webfonts, meta tags, or analytics to this file. The build step will place the bundled scripts into the <body> tag. To begin the development, run `npm start` or `yarn start`. To create a production bundle, use `npm run build` or `yarn build`. --> </body> </html>
Open service 150.95.27.68:5001
2025-01-03 21:51
HTTP/1.1 403 Forbidden Date: Fri, 03 Jan 2025 21:52:05 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2025-01-01 23:21
HTTP/1.1 403 Forbidden Date: Wed, 01 Jan 2025 23:22:19 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2024-12-31 21:51
HTTP/1.1 403 Forbidden Date: Tue, 31 Dec 2024 21:52:09 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2024-12-24 00:46
HTTP/1.1 403 Forbidden Date: Tue, 24 Dec 2024 00:47:41 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2024-12-22 00:11
HTTP/1.1 403 Forbidden Date: Sun, 22 Dec 2024 00:11:45 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2024-12-19 22:11
HTTP/1.1 403 Forbidden Date: Thu, 19 Dec 2024 22:12:17 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>
Open service 150.95.27.68:5001
2024-12-18 00:22
HTTP/1.1 403 Forbidden Date: Wed, 18 Dec 2024 00:23:12 GMT Server: Apache/2.4.38 (Debian) Content-Length: 277 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 403 Forbidden <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>403 Forbidden</title> </head><body> <h1>Forbidden</h1> <p>You don't have permission to access this resource.</p> <hr> <address>Apache/2.4.38 (Debian) Server at 150.95.27.68 Port 80</address> </body></html>