nginx
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
Open service 213.147.176.73:443 · gitlab.thmr.at
2026-01-23 05:14
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 102
Content-Security-Policy:
Content-Type: text/html; charset=utf-8
Date: Fri, 23 Jan 2026 05:14:55 GMT
Location: https://gitlab.thmr.at/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
Server: nginx
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KFMMDRMB3TQGJCPCVPPCSSYM","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KFMMDRMB3TQGJCPCVPPCSSYM
X-Runtime: 0.078374
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
<html><body>You are being <a href="https://gitlab.thmr.at/users/sign_in">redirected</a>.</body></html>
Open service 213.147.176.73:443 · ddns.thmr.at
2026-01-11 16:36
HTTP/1.1 200 OK Cache-Control: no-store Content-Security-Policy: base-uri 'self'; connect-src data: ws: wss: http: https:; default-src 'self' 'unsafe-eval' data: blob: https://*.synology.com https://www.synology.cn/ https://help.synology.cn/; font-src 'self' data: https://*.googleapis.com https://*.gstatic.com; form-action 'self'; frame-ancestors 'self' https://nas.thamer.xyz; frame-src 'self' data: blob: https://*.synology.com https://*.synology.cn http://*.synology.com http://*.synology.cn http://global.synologydownload.com https://global.synologydownload.com; img-src 'self' data: blob: https://*.google.com https://*.googleapis.com http://*.googlecode.com https://*.gstatic.com https://global.download.synology.com; media-src 'self' data: about: https://*.synology.com https://help.synology.cn; script-src 'self' 'unsafe-eval' data: blob: https://maps.google.com https://maps.googleapis.com https://ajax.googleapis.com https://help.synology.com https://help.synology.cn; style-src 'self' 'unsafe-inline' https://*.googleapis.com; Content-Type: text/html; charset="UTF-8" Date: Sun, 11 Jan 2026 16:37:02 GMT P3p: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT" Server: nginx Strict-Transport-Security: max-age=15552000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-Xss-Protection: 1; mode=block Connection: close Transfer-Encoding: chunked Page title: hermes - Synology NAS <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <meta http-equiv="X-UA-Compatible" content="IE=11" /> <meta name="msapplication-TileImage" content="resources/images/icon_tile.png?v=4398" /> <meta name="application-name" content="hermes - Synology NAS" /> <meta name="msapplication-TileColor" content="#246BB3"/> <meta name="description" content="Synology NAS provides a full-featured network attached storage (NAS) solution to help you manage, backup and share data among Windows, Mac and Linux easily." /> <meta name="keywords" content="Multitasking,Web Application,Personal Cloud" /> <meta name="viewport" content=""> <link rel="apple-touch-icon" href="webman/resources/images/icon_dsm_96.png?v=40438" /> <link rel="mask-icon" href="webman/safari_pin_icon.svg" color="#0086E5" /> <link rel="icon" href="webman/favicon.ico?v=40438" /> <link rel="icon" href="webman/resources/images/icon_dsm_96.png?v=40438" sizes="96x96"/> <link rel="icon" href="webman/resources/images/icon_dsm_64.png?v=40438" sizes="64x64"/> <link rel="icon" href="webman/resources/images/icon_dsm_48.png?v=40438" sizes="48x48"/> <link rel="icon" href="webman/resources/images/icon_dsm_32.png?v=40438" sizes="32x32"/> <link rel="icon" href="webman/resources/images/icon_dsm_16.png?v=40438" sizes="16x16"/> <title>hermes - Synology NAS</title> <link rel="stylesheet" type="text/css" href="webman/unsupported-browsers/dist/bundle.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="scripts/ext-3.4/resources/css/ext-all.css?v=1750385317" /> <link rel="stylesheet" type="text/css" href="scripts/syno-vue-components/style/syno-vue-components.css?v=1754462511" /> <link rel="stylesheet" type="text/css" href="scripts/scrollbar/flexcroll.css?v=1750385317" /> <link rel="stylesheet" type="text/css" href="scripts/ext-3/ux/ux-all.css?v=1750385317" /> <link rel="stylesheet" type="text/css" href="synoSDSjslib/sds.css?v=1756981479" /> <link rel="stylesheet" type="text/css" href="webman/desktop/dist/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/sds/dist/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/taskbar/dist/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/login/dist/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/resources/css/desktop.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/modules/VideoPlayer2/style.css?v=1750750572" /> <link rel="stylesheet" type="text/css" href="webman/modules/UpdateMaskApp/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/modules/Utils/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/C3/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/modules/PhotoViewer/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/SupportForm/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/DesktopProgress/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/TaskSchedulerUtils/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/PersonalSettings/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/EnableNewUpdateSetting/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/modules/PkgManApp/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/PollingTask/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/TaskSchedulerWidget/style.css?v=1758077520" /> <link rel="stylesheet" type="text/css" href="webman/modules/TinyMCE/style.css?v=1664290641" /> <link rel="stylesheet" type="text/css" href="webman/modules/ClipBoardJS/style.css?v=1758090778" /> <link rel="stylesheet" type="text/css" href="webman/modules/BackgroundTaskMonitor/style.css?v=1758090778" /> <link rel="stylesheet" type="text/c