nginx
tcp/443
xxxxxxxx-xxxxx
tcp/10443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 210.18.180.20:443
2024-12-22 00:55
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:55:11 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXRV1XE4RVGXDZ15CN7ZK6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXRV1XE4RVGXDZ15CN7ZK6 X-Runtime: 0.030191 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-12-21 23:55
HTTP/1.1 200 OK Date: Sat, 21 Dec 2024 23:55:17 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-12-20 22:52
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 22:52:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFK4B7M6MFJGJ2PXSXTWK79F","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFK4B7M6MFJGJ2PXSXTWK79F X-Runtime: 0.040363 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-12-20 00:07
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:08:02 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGP92MC039DMBQ1AS80FSFQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGP92MC039DMBQ1AS80FSFQ X-Runtime: 0.027469 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-12-19 23:14
HTTP/1.1 200 OK Date: Thu, 19 Dec 2024 23:14:46 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-12-19 01:07
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 01:07:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE79TCQPSB6GSN1RV922QEZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE79TCQPSB6GSN1RV922QEZ X-Runtime: 0.026647 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-12-17 23:39
Open service 210.18.180.20:10443
2024-12-17 22:44
HTTP/1.1 200 OK Date: Tue, 17 Dec 2024 22:44:49 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443
2024-12-15 22:55
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 22:55:53 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF68J31QS90AQ6A3K1945P3A","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF68J31QS90AQ6A3K1945P3A X-Runtime: 0.028122 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-12-15 22:22
HTTP/1.1 200 OK Date: Sun, 15 Dec 2024 22:23:04 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-12-14 16:07
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 16:07:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2YSFXTM689DNGEWGBT41N6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2YSFXTM689DNGEWGBT41N6 X-Runtime: 0.010674 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-12-13 23:54
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 23:54:13 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF173ES6A1FKPM4X14PBHQXS","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF173ES6A1FKPM4X14PBHQXS X-Runtime: 0.028225 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-12-13 21:47
HTTP/1.1 200 OK Date: Fri, 13 Dec 2024 21:47:16 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-12-13 02:58
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 02:58:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYZ7QNGSATN4MMFM8A5RXAG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYZ7QNGSATN4MMFM8A5RXAG X-Runtime: 0.028593 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-12-12 00:36
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 00:36:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW4RA9WW9P7PFMQG1DNH6ZJ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW4RA9WW9P7PFMQG1DNH6ZJ X-Runtime: 0.027171 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-12-11 21:37
HTTP/1.1 200 OK Date: Wed, 11 Dec 2024 21:37:47 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-12-02 19:50
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 19:50:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4ES41QW396YKBYYRPFYHTB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4ES41QW396YKBYYRPFYHTB X-Runtime: 0.011720 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-12-02 00:10
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 00:10:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2B97K1AYN0JJK131BS5NEA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2B97K1AYN0JJK131BS5NEA X-Runtime: 0.029178 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-12-01 23:48
HTTP/1.1 200 OK Date: Sun, 01 Dec 2024 23:48:29 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-11-30 13:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 13:02:30 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYJMRTDCTZEG0KYG5VRA0Q7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYJMRTDCTZEG0KYG5VRA0Q7 X-Runtime: 0.039860 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-11-29 23:45
Open service 210.18.180.20:10443
2024-11-29 23:08
HTTP/1.1 200 OK Date: Fri, 29 Nov 2024 23:09:03 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-11-28 11:03
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 11:03:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDS71FDR35VSGN96QW0N9870","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDS71FDR35VSGN96QW0N9870 X-Runtime: 0.015572 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:443
2024-11-27 23:39
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 23:39:23 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://210.18.180.20/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDQZWSGSR46XCG4T5XJR7NGM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDQZWSGSR46XCG4T5XJR7NGM X-Runtime: 0.010295 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://210.18.180.20/users/sign_in">redirected</a>.</body></html>
Open service 210.18.180.20:10443
2024-11-27 23:04
HTTP/1.1 200 OK Date: Wed, 27 Nov 2024 23:05:05 GMT Server: xxxxxxxx-xxxxx Last-Modified: Tue, 09 May 2023 00:00:00 GMT ETag: "83-64598d00" Accept-Ranges: bytes Content-Length: 131 Connection: close Content-Type: text/html X-Frame-Options: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self'; object-src 'self'; script-src 'self' https: 'unsafe-eval' 'unsafe-inline' blob:; X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Strict-Transport-Security: max-age=31536000
Open service 210.18.180.20:443 · tagit.transactionanalysts.com
2024-11-20 22:11
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 22:11:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 117 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://tagit.transactionanalysts.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5T39TVP677MZPD83VRS7DT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5T39TVP677MZPD83VRS7DT X-Runtime: 0.074424 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://tagit.transactionanalysts.com/users/sign_in">redirected</a>.</body></html>