Apache
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbb19d4a4e
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [submodule] active = . [remote "origin"] url = https://github.developer.allianz.io/Azlk-Git-Gen/E-Travel-etravel-backend.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [lfs] repositoryformatversion = 0 [branch "e-travel-tharsikan"] remote = origin merge = refs/heads/e-travel-tharsikan [branch "release/Live-sms-gateway-changes-V1"] remote = origin merge = refs/heads/release/Live-sms-gateway-changes-V1 [branch "Live-sms-gateway-changes-V1.1"] remote = origin merge = refs/heads/Live-sms-gateway-changes-V1.1 [branch "release/production"] remote = origin merge = refs/heads/release/production [branch "release/production-mfa"] remote = origin merge = refs/heads/release/production-mfa [branch "release/production-otp"] remote = origin merge = refs/heads/release/production-otp [branch "qa-otp"] remote = origin merge = refs/heads/qa-otp [branch "local-otp"] remote = origin merge = refs/heads/local-otp
Open service 2.17.100.234:80 · tracking.extsrv.com
2026-02-06 19:33
HTTP/1.1 307 Temporary Redirect Content-Length: 0 Location: https://tracking.extsrv.com/ Expires: Fri, 06 Feb 2026 19:34:23 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 06 Feb 2026 19:34:23 GMT Connection: close
Open service 2.17.100.234:80 · paxes.techmaster.in
2026-02-06 11:49
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 373 Expires: Fri, 06 Feb 2026 11:50:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 06 Feb 2026 11:50:17 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Set-Cookie: tboak=42c062e589294795a5ad6e8ff49859ad; path=/; domain=.paxes.techmaster.in Server-Timing: ak_p; desc="1770378617691_34694374_617969373_24_11635_6_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://paxes.techmaster.in/" on this server.<P> Reference #18.e6641102.1770378617.24d576dd <P>https://errors.edgesuite.net/18.e6641102.1770378617.24d576dd</P> </BODY> </HTML>
Open service 2.17.100.234:443 · college.vtwonen.nl
2026-01-23 04:43
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Apache
x-pingback: https://college.vtwonen.nl/wp/xmlrpc.php
x-frame-options: DENY
Link: <https://college.vtwonen.nl/>; rel=shortlink
Date: Fri, 23 Jan 2026 04:43:40 GMT
Content-Length: 47898
Connection: close
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Permissions-Policy: ch-ua-model=*,ch-ua-platform-version=*
Accept-CH: sec-ch-ua-model,sec-ch-ua-platform-version
Page title: vtwonen college | schrijf je nu in voor een online vtwonen cursus! | vtwonen
<!DOCTYPE html>
<!--[if lte IE 9]><html class="no-js legacy" lang="nl-NL"><![endif]-->
<!--[if gt IE 9]><!--><html lang="nl-NL"><!--<![endif]-->
<head>
<meta charset="UTF-8">
<title>vtwonen college | schrijf je nu in voor een online vtwonen cursus! | vtwonen</title>
<meta http-equiv="X-UA-Compatible" content="IE=edge, chrome=1">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="format-detection" content="telephone=no">
<link href="/wp-content/themes/magazines-base/assets/img/src/favicon.png" rel="shortcut icon">
<script src="https://cdn.jwplayer.com/libraries/MO9NWOuk.js?exp=1769147019&sig=c62143551f7048dd839a9eb7814297c1"></script>
<meta name='robots' content='index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1' />
<script data-type="consent-free">
_privacy = window._privacy || [];
window.cmpProperties = window.cmpProperties || {
siteKey: 'ismlqlfql5ciheja',
cmpCname: 'https://cmp.vtwonen.nl',
baseUrl: 'https://www.vtwonen.nl',
language: 'nl',
kids: 0,
};
consent_ajax_url = 'https://college.vtwonen.nl/wp/wp-admin/admin-ajax.php';
window._consent_stored = false;
</script>
<!-- SourcePoint crossDomainCheck -->
<script data-type="consent-free">
// This function gets cookie with a given name
function getCookie(name) {
let cookieValue = null;
if (document.cookie && document.cookie === '') {
return cookieValue;
}
const cookies = document.cookie.split(';');
for (let i = 0; i < cookies.length; i++) {
let cookie = cookies[i].trim();
// Does this cookie string begin with the name we want?
if (cookie.substring(0, name.length + 1) === (name + '=')) {
cookieValue = decodeURIComponent(cookie.substring(name.length + 1));
break;
}
}
return cookieValue;
}
let halfYearFuture = new Date();
halfYearFuture.setMonth(halfYearFuture.getMonth() + 6);
// first sniff url for authId, and set cookie if it exists.
let authId = new URLSearchParams(window.location.search).get('authId');
if (authId) {
document.cookie = 'authId=' + authId + '; expires=' + halfYearFuture.toUTCString() + ';path=/';
let params = new URLSearchParams(window.location.search);
if ('referrer' in window.sessionStorage && '' !== window.sessionStorage.getItem('referrer') ) {
params.delete('referrer');
params.append('referrer', window.sessionStorage.getItem('referrer'));
window.sessionStorage.removeItem('referrer');
}
// remove the AuthID and referer, but keep the referrer for GTM
params.delete('authId');
params.delete('referer');
let paramsUrl = params.toString();
if ('' !== paramsUrl) {
paramsUrl = '?' + paramsUrl;
}
window.location.replace(window.location.protocol + '//' + window.location.host + window.location.pathname + paramsUrl);
}
// no cookie? Redirect to Privacy Gate
let re = /google|facebook|slurp|yahoo|twitter|bing|bot|spider|crawler|ia_archiver|ptst|dpp|nuzzel|whatsapp|android 4|chrome-lighthouse|crawl/i;
let userAgent = navigator.userAgent;
if (1 === cmpProperties.kids) {
document.cookie = 'isKids=true ' + '; expires=' + halfYearFuture.toUTCString() + ';path=/';
} else if (re.test(userAgent)) {
document.cookie = 'isBot=true ' + '; expires=' + halfYearFuture.toUTCString() + ';path=/';
} else if (!getCookie('authId')) {
window.sessionStorage.setItem('referrer', document.referrer);
const callBackUrl = encodeURIComponent(window.location.href);
window.location.replace('https://myprivacy.dpgmedia.nl/consent/?siteKey=' + cmpProperties.siteKey + '&callbackUrl=' + callBackUrl);
}
</script>
<!-- end SourcePoint crossDomainCheck -->
<!-- CMP consent tag -->
<script async data-type="consent-free" src="https://myprivacy-static.dpgmedia.net/consent.js"></script>
<!-- end CMP consent tag -->
<meta name="description" content="vtwonen college is dé online plek voor iedereen die van interieurstyling houdt en graag met z��
Open service 2.17.100.234:443 · college.vtwonen.nl
2026-01-09 20:49
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Server: Apache
x-pingback: https://college.vtwonen.nl/wp/xmlrpc.php
x-frame-options: DENY
Link: <https://college.vtwonen.nl/>; rel=shortlink
Date: Fri, 09 Jan 2026 20:49:52 GMT
Content-Length: 47950
Connection: close
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Permissions-Policy: ch-ua-model=*,ch-ua-platform-version=*
Accept-CH: sec-ch-ua-model,sec-ch-ua-platform-version
Page title: vtwonen college | schrijf je nu in voor een online vtwonen cursus! | vtwonen
<!DOCTYPE html>
<!--[if lte IE 9]><html class="no-js legacy" lang="nl-NL"><![endif]-->
<!--[if gt IE 9]><!--><html lang="nl-NL"><!--<![endif]-->
<head>
<meta charset="UTF-8">
<title>vtwonen college | schrijf je nu in voor een online vtwonen cursus! | vtwonen</title>
<meta http-equiv="X-UA-Compatible" content="IE=edge, chrome=1">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="format-detection" content="telephone=no">
<link href="/wp-content/themes/magazines-base/assets/img/src/favicon.png" rel="shortcut icon">
<script src="https://cdn.jwplayer.com/libraries/MO9NWOuk.js?exp=1767995292&sig=5caf10b98af34f95b68368adeb0f2f67"></script>
<meta name='robots' content='index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1' />
<script data-type="consent-free">
_privacy = window._privacy || [];
window.cmpProperties = window.cmpProperties || {
siteKey: 'ismlqlfql5ciheja',
cmpCname: 'https://cmp.vtwonen.nl',
baseUrl: 'https://www.vtwonen.nl',
language: 'nl',
kids: 0,
};
consent_ajax_url = 'https://college.vtwonen.nl/wp/wp-admin/admin-ajax.php';
window._consent_stored = false;
</script>
<!-- SourcePoint crossDomainCheck -->
<script data-type="consent-free">
// This function gets cookie with a given name
function getCookie(name) {
let cookieValue = null;
if (document.cookie && document.cookie === '') {
return cookieValue;
}
const cookies = document.cookie.split(';');
for (let i = 0; i < cookies.length; i++) {
let cookie = cookies[i].trim();
// Does this cookie string begin with the name we want?
if (cookie.substring(0, name.length + 1) === (name + '=')) {
cookieValue = decodeURIComponent(cookie.substring(name.length + 1));
break;
}
}
return cookieValue;
}
let halfYearFuture = new Date();
halfYearFuture.setMonth(halfYearFuture.getMonth() + 6);
// first sniff url for authId, and set cookie if it exists.
let authId = new URLSearchParams(window.location.search).get('authId');
if (authId) {
document.cookie = 'authId=' + authId + '; expires=' + halfYearFuture.toUTCString() + ';path=/';
let params = new URLSearchParams(window.location.search);
if ('referrer' in window.sessionStorage && '' !== window.sessionStorage.getItem('referrer') ) {
params.delete('referrer');
params.append('referrer', window.sessionStorage.getItem('referrer'));
window.sessionStorage.removeItem('referrer');
}
// remove the AuthID and referer, but keep the referrer for GTM
params.delete('authId');
params.delete('referer');
let paramsUrl = params.toString();
if ('' !== paramsUrl) {
paramsUrl = '?' + paramsUrl;
}
window.location.replace(window.location.protocol + '//' + window.location.host + window.location.pathname + paramsUrl);
}
// no cookie? Redirect to Privacy Gate
let re = /google|facebook|slurp|yahoo|twitter|bing|bot|spider|crawler|ia_archiver|ptst|dpp|nuzzel|whatsapp|android 4|chrome-lighthouse|crawl/i;
let userAgent = navigator.userAgent;
if (1 === cmpProperties.kids) {
document.cookie = 'isKids=true ' + '; expires=' + halfYearFuture.toUTCString() + ';path=/';
} else if (re.test(userAgent)) {
document.cookie = 'isBot=true ' + '; expires=' + halfYearFuture.toUTCString() + ';path=/';
} else if (!getCookie('authId')) {
window.sessionStorage.setItem('referrer', document.referrer);
const callBackUrl = encodeURIComponent(window.location.href);
window.location.replace('https://myprivacy.dpgmedia.nl/consent/?siteKey=' + cmpProperties.siteKey + '&callbackUrl=' + callBackUrl);
}
</script>
<!-- end SourcePoint crossDomainCheck -->
<!-- CMP consent tag -->
<script async data-type="consent-free" src="https://myprivacy-static.dpgmedia.net/consent.js"></script>
<!-- end CMP consent tag -->
<meta name="description" content="vtwonen college is dé online plek voor iedereen die van interieurstyling houdt en graag met z��
Open service 2.17.100.234:443 · college.vtwonen.nl
2026-01-03 00:14
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Apache x-pingback: https://college.vtwonen.nl/wp/xmlrpc.php x-frame-options: DENY Link: <https://college.vtwonen.nl/>; rel=shortlink Date: Sat, 03 Jan 2026 00:14:42 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Permissions-Policy: ch-ua-model=*,ch-ua-platform-version=* Accept-CH: sec-ch-ua-model,sec-ch-ua-platform-version
Open service 2.17.100.234:443 · college.vtwonen.nl
2025-12-23 06:29
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Server: Apache x-pingback: https://college.vtwonen.nl/wp/xmlrpc.php x-frame-options: DENY Link: <https://college.vtwonen.nl/>; rel=shortlink Date: Tue, 23 Dec 2025 06:29:44 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding X-XSS-Protection: 1; mode=block X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Permissions-Policy: ch-ua-model=*,ch-ua-platform-version=* Accept-CH: sec-ch-ua-model,sec-ch-ua-platform-version