BaseHTTP 0.6
tcp/8080
Python 3.10.12
tcp/8080
nginx 1.18.0
tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522148b0405
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://hoteza:M6GP2RVKSa228W9LtjwU@bitbucket.org/hotezateam/tv.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "develop"] remote = origin merge = refs/heads/develop
Severity: critical
Fingerprint: 2580fa947e78dd08e645819d1eba35318214f26e226b0e978e60310b2f780043
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Sat, 06 May 2023 21:23:42 GMT Content-Type: text/html Content-Length: 674 Last-Modified: Thu, 02 Mar 2023 14:14:48 GMT Connection: close ETag: "6400af58-2a2" Accept-Ranges: bytes Page title: Hoteza <!DOCTYPE html> <html> <head> <meta name="viewport" content="width=1280, user-scalable=no"> <title>Hoteza</title> <meta charset="utf-8"> <link rel="icon" type="image/png" sizes="32x32" href="i/favicons/favicon-32x32.png"> <link rel="icon" type="image/png" sizes="16x16" href="i/favicons/favicon-16x16.png"> <link rel="shortcut icon" href="favicon.ico"> <script type="text/javascript" src="tv/start.js?v=6"></script> <script type="text/javascript"> window.onload = function(){ hoteza_start(); }; </script> </head> <body class="landscape_layout tv loading"> <div id="container"></div> <div id="splashscreen"></div> <div id="tv_cur"></div> </body> </html> [core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://hoteza:M6GP2RVKSa228W9LtjwU@bitbucket.org/hotezateam/tv.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "develop"] remote = origin merge = refs/heads/develop
Open service 178.177.33.179:80
2024-05-08 13:48
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Wed, 08 May 2024 13:48:13 GMT Content-Type: text/html Content-Length: 674 Last-Modified: Thu, 02 Mar 2023 14:14:48 GMT Connection: close ETag: "6400af58-2a2" Accept-Ranges: bytes Page title: Hoteza <!DOCTYPE html> <html> <head> <meta name="viewport" content="width=1280, user-scalable=no"> <title>Hoteza</title> <meta charset="utf-8"> <link rel="icon" type="image/png" sizes="32x32" href="i/favicons/favicon-32x32.png"> <link rel="icon" type="image/png" sizes="16x16" href="i/favicons/favicon-16x16.png"> <link rel="shortcut icon" href="favicon.ico"> <script type="text/javascript" src="tv/start.js?v=6"></script> <script type="text/javascript"> window.onload = function(){ hoteza_start(); }; </script> </head> <body class="landscape_layout tv loading"> <div id="container"></div> <div id="splashscreen"></div> <div id="tv_cur"></div> </body> </html>
Open service 178.177.33.179:80
2024-04-30 19:43
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Tue, 30 Apr 2024 19:43:59 GMT Content-Type: text/html Content-Length: 674 Last-Modified: Thu, 02 Mar 2023 14:14:48 GMT Connection: close ETag: "6400af58-2a2" Accept-Ranges: bytes Page title: Hoteza <!DOCTYPE html> <html> <head> <meta name="viewport" content="width=1280, user-scalable=no"> <title>Hoteza</title> <meta charset="utf-8"> <link rel="icon" type="image/png" sizes="32x32" href="i/favicons/favicon-32x32.png"> <link rel="icon" type="image/png" sizes="16x16" href="i/favicons/favicon-16x16.png"> <link rel="shortcut icon" href="favicon.ico"> <script type="text/javascript" src="tv/start.js?v=6"></script> <script type="text/javascript"> window.onload = function(){ hoteza_start(); }; </script> </head> <body class="landscape_layout tv loading"> <div id="container"></div> <div id="splashscreen"></div> <div id="tv_cur"></div> </body> </html>
Open service 178.177.33.179:80
2024-04-28 18:40
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Sun, 28 Apr 2024 18:40:07 GMT Content-Type: text/html Content-Length: 674 Last-Modified: Thu, 02 Mar 2023 14:14:48 GMT Connection: close ETag: "6400af58-2a2" Accept-Ranges: bytes Page title: Hoteza <!DOCTYPE html> <html> <head> <meta name="viewport" content="width=1280, user-scalable=no"> <title>Hoteza</title> <meta charset="utf-8"> <link rel="icon" type="image/png" sizes="32x32" href="i/favicons/favicon-32x32.png"> <link rel="icon" type="image/png" sizes="16x16" href="i/favicons/favicon-16x16.png"> <link rel="shortcut icon" href="favicon.ico"> <script type="text/javascript" src="tv/start.js?v=6"></script> <script type="text/javascript"> window.onload = function(){ hoteza_start(); }; </script> </head> <body class="landscape_layout tv loading"> <div id="container"></div> <div id="splashscreen"></div> <div id="tv_cur"></div> </body> </html>
Open service 178.177.33.179:80
2024-04-25 23:41
HTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Thu, 25 Apr 2024 23:41:38 GMT Content-Type: text/html Content-Length: 674 Last-Modified: Thu, 02 Mar 2023 14:14:48 GMT Connection: close ETag: "6400af58-2a2" Accept-Ranges: bytes Page title: Hoteza <!DOCTYPE html> <html> <head> <meta name="viewport" content="width=1280, user-scalable=no"> <title>Hoteza</title> <meta charset="utf-8"> <link rel="icon" type="image/png" sizes="32x32" href="i/favicons/favicon-32x32.png"> <link rel="icon" type="image/png" sizes="16x16" href="i/favicons/favicon-16x16.png"> <link rel="shortcut icon" href="favicon.ico"> <script type="text/javascript" src="tv/start.js?v=6"></script> <script type="text/javascript"> window.onload = function(){ hoteza_start(); }; </script> </head> <body class="landscape_layout tv loading"> <div id="container"></div> <div id="splashscreen"></div> <div id="tv_cur"></div> </body> </html>
Open service 178.177.33.179:8080
2024-04-25 12:25
HTTP/1.0 501 Unsupported method ('GET') Server: BaseHTTP/0.6 Python/3.10.12 Date: Thu, 25 Apr 2024 12:25:51 GMT Connection: close Content-Type: text/html;charset=utf-8 Content-Length: 496 Page title: Error response <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"> <html> <head> <meta http-equiv="Content-Type" content="text/html;charset=utf-8"> <title>Error response</title> </head> <body> <h1>Error response</h1> <p>Error code: 501</p> <p>Message: Unsupported method ('GET').</p> <p>Error code explanation: HTTPStatus.NOT_IMPLEMENTED - Server does not support this operation.</p> </body> </html>