awselb 2.0
tcp/443
nginx
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1926e27d0926e27d0926e27d0926e27d0926e27d0926e27d0
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1926e27d0926e27d0926e27d0926e27d0926e27d0926e27d0
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b5e009321ddfee6f87db6002deb617fd40855ac30
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
GET /v1/verification
GET /v1/verification/audit-trail
GET /v1/verification/evidence/type
GET /v1/verification/evidence/type/{idOrName}
GET /v1/verification/journey/step
GET /v1/verification/journey/step/{idOrName}
GET /v1/verification/journey/type
GET /v1/verification/journey/type/{idOrName}
GET /v1/verification/search
POST /v1/verification/applicant
POST /v1/verification/certificate/password
POST /v1/verification/done
POST /v1/verification/evidence
POST /v1/verification/journey
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b5e009321ddfee6f87db6002deb617fd4896c5c45
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
GET /v1/verification
GET /v1/verification/audit-trail
GET /v1/verification/evidence/type
GET /v1/verification/evidence/type/{idOrName}
GET /v1/verification/journey/step
GET /v1/verification/journey/step/{idOrName}
GET /v1/verification/journey/type
GET /v1/verification/journey/type/{idOrName}
GET /v1/verification/search
POST /v1/verification/applicant
POST /v1/verification/certificate/password
POST /v1/verification/evidence
POST /v1/verification/journey
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b5e009321ddfee6f815c0b255ce78916c7f171024
Public Swagger UI/API detected at path: /v3/api-docs - sample paths: GET /v1/verification GET /v1/verification/audit-trail GET /v1/verification/search POST /v1/verification/applicant POST /v1/verification/certificate/password
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b5e009321ddfee6f815c0b255112d0f11112d0f11
Public Swagger UI/API detected at path: /v3/api-docs - sample paths: GET /v1/verification GET /v1/verification/audit-trail GET /v1/verification/search POST /v1/verification/certificate/password
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bd106978014e0a638fa6a92e5389f9a16fdc43590
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
GET /v1/customer
GET /v1/customer/{customerId}/application
GET /v1/customer/{customerId}/configuration/order
GET /v1/customer/{customerId}/configuration/ssl-authenticator
GET /v1/customers
GET /v1/store
POST /v1/customer/application
POST /v1/customer/csv/imports
POST /v1/customer/{customerId}/manage/configuration/order
POST /v1/customer/{customerId}/manage/configuration/ssl-authenticator
PUT /v1/customer/application/{applicationId}
PUT /v1/customer/csv/configuration/update
Open service 2.16.6.31:443 · csat.help.openai.com
2026-02-11 22:54
HTTP/1.1 200 OK
X-Content-Type-Options: nosniff
Content-Security-Policy: frame-ancestors 'self'; report-uri /_/commcsp?disposition=enforce;
Strict-Transport-Security: max-age=63072000; includeSubDomains
Referrer-Policy: strict-origin-when-cross-origin
Cache-Control: max-age=0,must-revalidate,private
Content-Type: text/html; charset=utf-8
Content-Language: en-US
Link: </webruntime/framework/d7c1f160b4/prod/lwr_loader>; rel=preload; as=script; nopush, </webruntime/framework/1990ec5a0a/prod/lwr_bootstrap_locker>; rel=preload; as=script; nopush, </webruntime/framework/f6e4dea27d/prod/lwr_app_bootstrap_hook>; rel=preload; as=script; nopush, </webruntime/framework/84f03ee6d5/prod/lwr_lwc>; rel=preload; as=script; nopush, </webruntime/framework/38c562d24f/prod/lwr_app>; rel=preload; as=script; nopush, </webruntime/view/841d115d8345ce9d428985cfc7d40d1a/prod/en-US/home_view>; rel=preload; as=script; crossorigin; nopush, </webruntime/component/4e1519bb9e06f0d6ceca80c506e32780/prod/en-US/force/ldsEngineWebruntime_cmp>; rel=preload; as=script; crossorigin; nopush, </webruntime/component/259a789b5905e4a3e65c0942cc97421d/prod/en-US/force/luvioLwcBindings_cmp>; rel=preload; as=script; crossorigin; nopush, </webruntime/component/da6467b90bc1eda0c5728f07f2d9928c/prod/en-US/force/luvioRuntimeWebruntime_cmp>; rel=preload; as=script; crossorigin; nopush, </webruntime/view/099b29387908ab11712c19721cfd71b2/prod/en-US/scopedHeaderAndFooter_view>; rel=preload; as=script; crossorigin; nopush
ETag: "240DB3C12593C5C89E1633CAB25C24EB--gzip"
X-Frame-Options: SAMEORIGIN
Link: </assets/styles/salesforce-lightning-design-system.min.css?338c74158c>; rel=preload; as=style; nopush,</assets/styles/dxp-site-spacing-styling-hooks.min.css?338c74158c>; rel=preload; as=style; nopush,</assets/styles/dxp-styling-hooks.min.css?338c74158c>; rel=preload; as=style; nopush,</assets/styles/dxp-slds-extensions.min.css?338c74158c>; rel=preload; as=style; nopush,</sfsites/c/cms/delivery/media/MCKTIK4JICM5ATRHMOGVWQISJNWI?version=1.1&preloadAs=style>; rel=preload; as=style; nopush,</sfsites/c/cms/delivery/media/MCBXE354JXORBNXBUM7TKV66MOBE?version=1.1&preloadAs=style>; rel=preload; as=style; nopush
Date: Wed, 11 Feb 2026 22:54:16 GMT
Content-Length: 48027
Connection: close
x-origin-cache-control: max-age=0,must-revalidate,private
Akamai-GRN: 0.5f071002.1770850456.5cdd4786
<!DOCTYPE html>
<html lang="en-US">
<head><meta http-equiv="Content-Security-Policy" content="default-src 'self'; script-src 'self' 'unsafe-eval' https://service.force.com/embeddedservice/ https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/ https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/ https://payments.salesforce.com/ https://js.stripe.com/ https://www.paypal.com/sdk/js https://checkoutshopper-live.adyen.com/ https://checkoutshopper-test.adyen.com/ https://pal-test.adyen.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://pay.google.com import: blob: https://uip.canary.lwc.dev https://cdn.openai.com https://cdn.openai.com/brand/OpenAI-black-wordmark-cropped.svg 'sha256-+n4LCEXJICvQSyzevjP2UjIQHHrrkkW42kvjA4XOGW0=' 'sha256-/J6FNSBiuT91hXHo5uJczyGrwWR1Zu4pxo2KkqRL4xA=' 'sha256-0Z9MrNG30kig6RfQYN31xBuJuN+oNdBHiex+blPvH34=' 'sha256-134O3h0yXzYmYbgHbjtw0UaekHCG+MzY58F85WfDjCo=' 'sha256-2Ds/qr04k2ZAGDSuGicCFiHsl2tYDisrNOgujsrqZ+c=' 'sha256-4ctXOhCSJYLR34ca4ttTwurB/qBaQdSqwRWGSRyOhVA=' 'sha256-6/W2G0JymQ3hxOQghAII4U65HA3AhFezsPDM41XeSVA=' 'sha256-6LqG1hGVEMvoC4T+6Bq7NIAJGlMNziRTdyYHebHDL2k=' 'sha256-7Dv19IqxeeNJaln2mzU5xUdQyuqueRDYRvwITN15GyA=' 'sha256-843yjYOnlf+5ByGC0rK2v+bYh1ysmfP5lOHYxyARPpk=' 'sha256-EAearLdtz+2U1Ckb4rdLuqdnnMBc0KqMANJrQ+VKSlo=' 'sha256-EJ0K1BX6kFufT5NtONc7ztfrCNo57dIuXuEeIUFKwDQ=' 'sha256-EJxyB5G9diHtqi2BpsEOpQwm3yU+LskLO2tslz2Vd8E=' 'sha256-F/2HHbDsuh8Oa3XgxiUhtaIw1fFLqKXaPFVzapVMSdI=' 'sha256-Kpyf9FO1hi8gkOwxCoS8kk23jO+Ho6hvwRnvDxdURdM=' 'sha256-QNxiK9PLKLcdISxwj0xxJ98sEufgp71JHe9cKLoFfBI=' 'sha256-QO/FGbe6U/xCVHGZezOV6cpQ7l0JkxB9WXCMWQaGz8M=' 'sha256-Qg+eMtVyUgIinHexN53G+ZPqEI5ekYoF+uamAI6VUhk=' 'sha256-R9Ckux5LLsr88MeCbaIi9jZYmotvr38VrraEgds38sM=' 'sha256-T7kskaXZJWl72KrhnfvxyXbTUyX7gJVAhDrshTAAqsM=' 'sha256-VIQMdeYUBNMwBrHYVQusKv6FRVTHu1ZikrV2CaVYa3c=' 'sha256-XRhNk8WwOxG1po1vpWUePZ7efoZjB8H5DXcdHZBC7n0=' 'sha256-Y0ga6fCJJCF9gGEQQMLEdJltOFmfOtxhExPkjs5SD9I=' 'sha256-YU6V9LsdLBnL/FB+G38ZwOW5hBmIeS4i2jMSqa4mnQ0=' 'sha256-ZRR8af+z7cssAbV9R8le3+PnrdPOOdPJz3pMUPXaAK0=' 'sha256-Zf1PF5tlDiFO4gnwq5Nc5YhjwKMcoCRGCw5zDmekHA8=' 'sha256-akZRKId7o0VshY97czbqAJxEWDrGAAj7E1mRigDqzo0=' 'sha256-c3w67nqIdNJStZV6Hv1voXwx8hNbrEZtJZormlBznWw=' 'sha256-dAesODum6jYoGAXkiqX+tCqm3fqAEPQ41IejTWKc/zI=' 'sha256-dMH8B7mbf/vadfPMiY0zTbG6chlvS1SmfYe97xiHTzY=' 'sha256-hvZguXK7DHjfCmI1Bl6QVCkNFNf0PjYO+WuD6ECBhBc=' 'sha256-jBiNMEnIsKbyRVGnV1gGJoUjHQLqp+SpABnh/XsZgpA=' 'sha256-lsSEkUBja81Zh64wAyUjj/LG6kScmI2MRH0TaE/zqUo=' 'sha256-mVNXQzCNTUl5xMK8BviBsuoO+gsBnjAoCrG/LeyAtx8=' 'sha256-mZRB3b3oQ3sAfWxsSo16Qd1cbexyDjm3Lum11xvTTXo=' 'sha256-oFX5mP5AGKg6elCpFE1Rbrs8d3StnKfbwDGvmUB5T5U=' 'sha256-t7afVd2ccj7ZoiftvKklrl85IpsbNBvKh/EyvbRp8GA=' 'sha256-xQOLE3oNI5FLFKwqY/ReDrviKrkYW6OmVDFpYAnRJ/s=' 'sha256-xqk8KCGNQ2gpHwk+g2erjJRJOTBz2YRjLk8CD3MWffo=' 'sha256-xqqz7Ubs08ez4CXU+TnGjTEP1mKwmp6x50aAl2Gg4Ms=' 'sha256-ymgIrYoa3mRv6Ax4boR4beyeSJZ66rouhKrVn+DSqis=' 'sha256-RVa7XzcPHyas/c1szj9OEDbMS4M1uQj0gi90PBWfq4E='; object-src 'self' www.google.com; style-src 'self' 'unsafe-inline' https://service.force.com/embeddedservice/ https://fonts.googleapis.com/css2 https://fonts.googleapis.com/css https://checkoutshopper-live.adyen.com/ https://checkoutshopper-test.adyen.com/ blob: https://support-automation.gateway.unified-0s.internal.api.openai.org https://*.people.ai https://*.internal.api.openai.org https://login.microsoftonline.com; img-src 'self' data: blob: https://openai.my.salesforce.com https://openai.file.force.com https://img.youtube.com https://i.ytimg.com https://i.vimeocdn.com https://login.salesforce.com/icons/ https://payments.salesforce.com/icons/ https://cdn.content.aws-prod1-useast1.aws.sfdc.cl/icons/ https://cdn.content.aws-dev2-uswest2.aws.sfdc.cl/icons/ https://*.adyen.com https://www.sandbox.paypal.com https://www.paypal.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.gstatic.com https://usa700.sfdc-lywfpd.salesforce.com/icons/ https://support-automation.gateway.unified-0s.internal.api.openai.org https://cdn.openai.com https://integrations-api.linear.app https://*
Open service 2.16.6.31:443 · staging.aconytebooks.com
2026-02-02 01:48
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Link: <https://staging.aconytebooks.com/wp-json/>; rel="https://api.w.org/" Link: <https://staging.aconytebooks.com/wp-json/wp/v2/pages/470>; rel="alternate"; title="JSON"; type="application/json" Link: <https://staging.aconytebooks.com/>; rel=shortlink X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Referrer-Policy: strict-origin-when-cross-origin Expires: Mon, 02 Feb 2026 01:48:16 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 02 Feb 2026 01:48:16 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Set-Cookie: mailchimp_landing_site=https%3A%2F%2Fstaging.aconytebooks.com%2F; expires=Mon, 02 Mar 2026 01:48:04 GMT; Max-Age=2419200; path=/; secure; SameSite=Strict
Open service 2.16.6.31:443 · api-alpha.bewakoof.com
2026-01-27 08:41
HTTP/1.1 403 Forbidden
Content-Type: application/json
Content-Length: 42
x-amzn-RequestId: 3b793d57-4391-485c-9c4e-41246d793752
x-amzn-ErrorType: MissingAuthenticationTokenException
x-amz-apigw-id: X1gKcEHwhcwFdDg=
Date: Tue, 27 Jan 2026 08:41:38 GMT
Connection: close
{"message":"Missing Authentication Token"}
Open service 2.16.6.31:443 · p9.bewakoof.com
2026-01-27 08:41
HTTP/1.1 502 Bad Gateway Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 166 Date: Tue, 27 Jan 2026 08:41:38 GMT Connection: close Page title: 502 Bad Gateway <html> <head><title>502 Bad Gateway</title></head> <body bgcolor="white"> <center><h1>502 Bad Gateway</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.6.31:443 · staging-copernicus.bewakoof.com
2026-01-27 08:41
HTTP/1.1 503 Service Unavailable Server: awselb/2.0 Content-Type: text/plain; charset=utf-8 Content-Length: 0 Date: Tue, 27 Jan 2026 08:41:38 GMT Connection: close
Open service 2.16.6.31:80 · listerine.cz
2026-01-25 10:57
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 362 Expires: Sun, 25 Jan 2026 10:57:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 25 Jan 2026 10:57:53 GMT Connection: close Akamai-GRN: 0.5f071002.1769338673.c154e8d6 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://listerine.cz/" on this server.<P> Reference #18.5f071002.1769338673.c154e8d6 <P>https://errors.edgesuite.net/18.5f071002.1769338673.c154e8d6</P> </BODY> </HTML>
Open service 2.16.6.31:443 · dc-customer-dev.vcert.com.br
2026-01-23 02:38
HTTP/1.1 401 Unauthorized Content-Length: 0 Vary: Origin Vary: Access-Control-Request-Method Vary: Access-Control-Request-Headers WWW-Authenticate: Bearer X-Content-Type-Options: nosniff X-XSS-Protection: 0 X-Frame-Options: DENY Expires: Fri, 23 Jan 2026 02:38:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 23 Jan 2026 02:38:18 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=554 Server-Timing: origin; dur=134 Strict-Transport-Security: max-age=31536000 ; includeSubDomains Server-Timing: ak_p; desc="1769135897474_34604894_1191217570_68720_5762_80_104_-";dur=1
Open service 2.16.6.31:443 · dc-contract.vcert.com.br
2026-01-23 02:38
HTTP/1.1 404 Not Found
Content-Type: application/json
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Content-Length: 89
Expires: Fri, 23 Jan 2026 02:38:17 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 02:38:17 GMT
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=195
Server-Timing: origin; dur=6
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Server-Timing: ak_p; desc="1769135896829_34604886_1350388553_19983_4566_7_9_-";dur=1
{"timestamp":"2026-01-23T02:38:16.949+00:00","status":404,"error":"Not Found","path":"/"}
Open service 2.16.6.31:443 · perform.cdn-contentful.lululemon.com
2026-01-23 01:50
HTTP/1.1 200 OK
Content-Type: application/json
Expires: Fri, 23 Jan 2026 01:50:37 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 01:50:37 GMT
Content-Length: 2
Connection: close
Server-Timing: cdn-cache; desc=HIT
Server-Timing: edge; dur=14
Server-Timing: ak_p; desc="1769133037431_34604895_2324842143_1408_8269_94_108_-";dur=1
{}
dc-verification-hml.vcert.com.br 4 dc-customer-dev.vcert.com.br 1 dc-contract.vcert.com.br 1 dc-contract-dev.vcert.com.br 1 csat.help.openai.com 0 staging.aconytebooks.com 0 api-alpha.bewakoof.com 0 p9.bewakoof.com 0 staging-copernicus.bewakoof.com 0 listerine.cz 0 perform.cdn-contentful.lululemon.com 0