openresty
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957d8ddd9d3
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/admin/v1/transactions/request-id/{ticketId}
GET /api/admin/v1/transactions/ticket-id/{requestId}
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f3ca51b9
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957a32b58bd
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f7336a95
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957d8ddd9d3
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/admin/v1/transactions/request-id/{ticketId}
GET /api/admin/v1/transactions/ticket-id/{requestId}
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f3ca51b9
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957d8ddd9d3
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/admin/v1/transactions/request-id/{ticketId}
GET /api/admin/v1/transactions/ticket-id/{requestId}
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f3ca51b9
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957a32b58bd
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f7336a95
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957d8ddd9d3
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/admin/v1/transactions/request-id/{ticketId}
GET /api/admin/v1/transactions/ticket-id/{requestId}
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f3ca51b9
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957a32b58bd
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957d8ddd9d3
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/admin/v1/transactions/request-id/{ticketId}
GET /api/admin/v1/transactions/ticket-id/{requestId}
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1926e27d0926e27d0926e27d0926e27d0926e27d0926e27d0
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f3ca51b9
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957a32b58bd
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957f7336a95
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e58acc6fab074af1eaab95ba95eb9d8957d8ddd9d3
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /api/admin/v1/betshops
GET /api/admin/v1/betshops/manual-sync
GET /api/admin/v1/betshops/{betshopId}
GET /api/admin/v1/report-filters
GET /api/admin/v1/reports
GET /api/admin/v1/reports/export
GET /api/admin/v1/transactions/request-id/{ticketId}
GET /api/admin/v1/transactions/ticket-id/{requestId}
GET /api/cemp/v1/players/{id}
GET /api/query/v1/betting-tickets
GET /api/seven/v1/devices/{id}
GET /api/seven/v1/online-player/
GET /validation-url/online
POST /api/admin/v1/reports/regenerate
POST /api/cemp/v1/sync
POST /api/imports/v1/betting/bet
POST /api/imports/v1/betting/bet/combo
POST /api/imports/v1/betting/jackpot
POST /api/imports/v1/betting/rollback
POST /api/imports/v1/betting/win
POST /api/imports/v1/betting/win/combo
POST /api/imports/v1/casino
POST /api/imports/v1/slot-periodic
POST /api/imports/v1/slot/deposit
POST /api/imports/v1/slot/jackpot
POST /api/imports/v1/slot/rollback
POST /api/imports/v1/slot/withdraw
POST /api/seven/v1/online-player/rollback
POST /tickets
POST /validation-url/retail
Open service 151.236.216.4:443 · p-svntax-app-c04n01.lon.lin.nsoft.io
2026-01-10 01:02
HTTP/1.1 404
Server: openresty
Date: Sat, 10 Jan 2026 01:02:08 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-10T01:02:08.175+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlindjija.7platform.com
2026-01-09 19:26
HTTP/1.1 404
Server: openresty
Date: Fri, 09 Jan 2026 19:26:24 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-09T19:26:24.008+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-ads.7platform.com
2026-01-09 18:30
HTTP/1.1 404
Server: openresty
Date: Fri, 09 Jan 2026 18:30:07 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-09T18:30:07.747+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · li560-4.members.linode.com
2026-01-09 15:46
HTTP/1.1 404
Server: openresty
Date: Fri, 09 Jan 2026 15:46:09 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-09T15:46:09.055+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlantik.7platform.com
2026-01-09 02:32
HTTP/1.1 404
Server: openresty
Date: Fri, 09 Jan 2026 02:32:11 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-09T02:32:11.526+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443
2026-01-08 15:01
HTTP/1.1 404
Server: openresty
Date: Thu, 08 Jan 2026 15:01:47 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-08T15:01:47.179+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:80 · tax-authority-v2-srb-atlindjija.7platform.com
2026-01-04 09:37
HTTP/1.1 301 Moved Permanently Server: openresty Date: Sun, 04 Jan 2026 09:37:25 GMT Content-Type: text/html Content-Length: 166 Connection: close Location: https://tax-authority-v2-srb-atlindjija.7platform.com/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>openresty</center> </body> </html>
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlindjija.7platform.com
2026-01-04 09:37
HTTP/1.1 404
Server: openresty
Date: Sun, 04 Jan 2026 09:37:25 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-04T09:37:25.806+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · p-svntax-app-c04n01.lon.lin.nsoft.io
2026-01-02 19:15
HTTP/1.1 404
Server: openresty
Date: Fri, 02 Jan 2026 19:15:11 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-02T19:15:11.062+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlindjija.7platform.com
2026-01-02 12:56
HTTP/1.1 404
Server: openresty
Date: Fri, 02 Jan 2026 12:56:54 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-02T12:56:54.736+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · li560-4.members.linode.com
2026-01-02 09:56
HTTP/1.1 404
Server: openresty
Date: Fri, 02 Jan 2026 09:56:28 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-02T09:56:28.961+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-ads.7platform.com
2026-01-02 06:35
HTTP/1.1 404
Server: openresty
Date: Fri, 02 Jan 2026 06:35:58 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-02T06:35:58.341+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlantik.7platform.com
2026-01-02 00:44
HTTP/1.1 404
Server: openresty
Date: Fri, 02 Jan 2026 00:44:58 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-02T00:44:58.294+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443
2026-01-01 18:12
HTTP/1.1 404
Server: openresty
Date: Thu, 01 Jan 2026 18:12:30 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2026-01-01T18:12:30.163+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-ads.7platform.com
2025-12-30 11:22
HTTP/1.1 404
Server: openresty
Date: Tue, 30 Dec 2025 11:22:51 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-30T11:22:51.319+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlantik.7platform.com
2025-12-30 07:54
HTTP/1.1 404
Server: openresty
Date: Tue, 30 Dec 2025 07:54:47 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-30T07:54:47.069+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443
2025-12-30 03:30
HTTP/1.1 404
Server: openresty
Date: Tue, 30 Dec 2025 03:30:42 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-30T03:30:42.055+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · p-svntax-app-c04n01.lon.lin.nsoft.io
2025-12-23 08:20
HTTP/1.1 404
Server: openresty
Date: Tue, 23 Dec 2025 08:20:21 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-23T08:20:21.655+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlantik.7platform.com
2025-12-23 02:09
HTTP/1.1 404
Server: openresty
Date: Tue, 23 Dec 2025 02:09:07 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-23T02:09:07.332+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · li560-4.members.linode.com
2025-12-22 23:29
HTTP/1.1 404
Server: openresty
Date: Mon, 22 Dec 2025 23:29:28 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-22T23:29:28.867+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlindjija.7platform.com
2025-12-22 18:41
HTTP/1.1 404
Server: openresty
Date: Mon, 22 Dec 2025 18:41:32 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-22T18:41:32.286+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-ads.7platform.com
2025-12-22 12:31
HTTP/1.1 404
Server: openresty
Date: Mon, 22 Dec 2025 12:31:20 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-22T12:31:20.630+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:80 · p-svntax-app-c04n01.lon.lin.nsoft.io
2025-12-22 09:37
HTTP/1.1 301 Moved Permanently Server: openresty Date: Mon, 22 Dec 2025 09:37:46 GMT Content-Type: text/html Content-Length: 166 Connection: close Location: https://p-svntax-app-c04n01.lon.lin.nsoft.io/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>openresty</center> </body> </html>
Open service 151.236.216.4:443 · p-svntax-app-c04n01.lon.lin.nsoft.io
2025-12-22 09:37
HTTP/1.1 404
Server: openresty
Date: Mon, 22 Dec 2025 09:37:45 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-22T09:37:45.810+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443
2025-12-22 01:40
HTTP/1.1 404
Server: openresty
Date: Mon, 22 Dec 2025 01:40:41 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-22T01:40:41.918+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · p-svntax-app-c04n01.lon.lin.nsoft.io
2025-12-21 10:34
HTTP/1.1 404
Server: openresty
Date: Sun, 21 Dec 2025 10:34:48 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-21T10:34:48.873+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-atlindjija.7platform.com
2025-12-20 18:43
HTTP/1.1 404
Server: openresty
Date: Sat, 20 Dec 2025 18:43:10 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-20T18:43:10.952+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · tax-authority-v2-srb-ads.7platform.com
2025-12-20 09:55
HTTP/1.1 404
Server: openresty
Date: Sat, 20 Dec 2025 09:55:07 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-20T09:55:07.266+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443 · li560-4.members.linode.com
2025-12-20 05:49
HTTP/1.1 404
Server: openresty
Date: Sat, 20 Dec 2025 05:49:30 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-20T05:49:30.239+00:00","status":404,"error":"Not Found","path":"/"}
Open service 151.236.216.4:443
2025-12-19 22:49
HTTP/1.1 404
Server: openresty
Date: Fri, 19 Dec 2025 22:49:47 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
{"timestamp":"2025-12-19T22:49:47.816+00:00","status":404,"error":"Not Found","path":"/"}