nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb563aa8aaf4222caca4222caca4222caca4222caca
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u1 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 173.255.193.144:443
2024-12-22 00:54
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:54:19 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXQ872Q2MJSMGQ25M65YK8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXQ872Q2MJSMGQ25M65YK8 X-Runtime: 0.026187 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-12-21 21:15
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-12-21 00:26
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 00:26:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFK9QYY6PF5K2KMBYBFJW361","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFK9QYY6PF5K2KMBYBFJW361 X-Runtime: 0.043683 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443
2024-12-19 23:58
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 23:58:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGNR0NH7R5AEKNDRGBEC5CT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGNR0NH7R5AEKNDRGBEC5CT X-Runtime: 0.022398 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-12-19 21:43
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-12-18 21:13
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 21:13:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDSWXDHCG5NZ27N4DFWDE3G","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDSWXDHCG5NZ27N4DFWDE3G X-Runtime: 0.027359 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443
2024-12-17 22:03
HTTP/1.1 302 Found Server: nginx Date: Tue, 17 Dec 2024 22:03:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBABENMFVDS99CWX2M4K806","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBABENMFVDS99CWX2M4K806 X-Runtime: 0.072643 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-12-17 22:03
Open service 173.255.193.144:22
2024-12-15 21:46
Open service 173.255.193.144:443
2024-12-15 21:46
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 21:46:28 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF64JYXX88KZQFXFKK2SRY0G","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF64JYXX88KZQFXFKK2SRY0G X-Runtime: 0.016719 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-12-14 14:21
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 14:21:34 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2RQKNXGZ3KQHEWSNZEJD9P","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2RQKNXGZ3KQHEWSNZEJD9P X-Runtime: 0.019330 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-12-13 22:27
Open service 173.255.193.144:443
2024-12-13 21:57
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 21:57:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF10E6R0CHP41XCQ35Z021BY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF10E6R0CHP41XCQ35Z021BY X-Runtime: 0.020969 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-12-12 14:39
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 14:39:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXMZSAG7N1CZG0DXS50D2KH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXMZSAG7N1CZG0DXS50D2KH X-Runtime: 0.026070 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443
2024-12-11 23:42
HTTP/1.1 302 Found Server: nginx Date: Wed, 11 Dec 2024 23:42:24 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW1MC5MZ5CEZ8CQ5CWNR8M0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW1MC5MZ5CEZ8CQ5CWNR8M0 X-Runtime: 0.019245 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-12-11 22:50
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-12-02 23:24
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 23:24:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4V19G93NGTZK4HEHK8GCN8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4V19G93NGTZK4HEHK8GCN8 X-Runtime: 0.017735 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443
2024-12-01 22:04
HTTP/1.1 302 Found Server: nginx Date: Sun, 01 Dec 2024 22:04:24 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE241QNYW385QEX6847TJ41S","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE241QNYW385QEX6847TJ41S X-Runtime: 0.075840 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-12-01 21:33
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-11-30 19:26
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 19:26:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ8MH3YCNRPG13FHAGHENHV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ8MH3YCNRPG13FHAGHENHV X-Runtime: 0.026304 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443
2024-11-29 21:39
HTTP/1.1 302 Found Server: nginx Date: Fri, 29 Nov 2024 21:39:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDWXV1464MRAACXNHDQ75RQT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDWXV1464MRAACXNHDQ75RQT X-Runtime: 0.030816 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-11-29 21:21
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-11-28 22:40
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 22:40:17 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDTEX9RY2SZDSPGZHW5YRM3J","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDTEX9RY2SZDSPGZHW5YRM3J X-Runtime: 0.061440 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443
2024-11-27 23:40
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 23:41:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://173.255.193.144/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDQZZS4KD105E73C0DBCWM8Q","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDQZZS4KD105E73C0DBCWM8Q X-Runtime: 0.019361 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://173.255.193.144/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:22
2024-11-27 21:14
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-11-27 00:33
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 00:33:02 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNGJ9VNWSH057K3207KJ5RR","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNGJ9VNWSH057K3207KJ5RR X-Runtime: 0.061179 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>
Open service 173.255.193.144:443 · gitlab.innovadata.com.br
2024-11-20 16:18
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 16:18:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 112 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.innovadata.com.br/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD55W1H4BY6X6AJPRK7HPA78","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD55W1H4BY6X6AJPRK7HPA78 X-Runtime: 0.058325 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.innovadata.com.br/users/sign_in">redirected</a>.</body></html>