.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c8f03d7bd8f03d7bde086d3f395cd447f33310f8288ae965b
Found 38 files trough .DS_Store spidering: /apple-touch-icon.png /apple-touch-icon2.png /apple-touch-icon3.png /assets /assets/css /assets/fonts /assets/images /assets/js /calle /css /favicon.ico /fotos /iconos /iconos/contacto /iconos/eventos /iconos/galeria /iconos/iniciales-logo /iconos/inicio /iconos/logo /iconos/LOGOS /iconos/LOGOS /INICIALES /iconos/LOGOS /TEXTO /iconos/nosotros /images /images/parroquia_edit.jpg /index.php /js /logos /logos/iniciales /logos/iniciales/logo-amarillo.png /logos/iniciales/LOGOINICIALES-AZUL.png /logos/iniciales/LOGOINICIALES-MAGENTA.png /logos/iniciales/LOGOINICIALES-NEGRO.png /logos/texto /robots.txt /storage /vendor /videos
Severity: low
Fingerprint: 5f32cf5d6962f09cf35cbfb3f35cbfb39c5be2a9b2f5ce5dbebec5a84cfbcad1
Found 29 files trough .DS_Store spidering: /apple-touch-icon.png /apple-touch-icon2.png /apple-touch-icon3.png /assets /assets/css /assets/fonts /assets/images /assets/js /calle /css /favicon.ico /fotos /iconos /iconos/contacto /iconos/eventos /iconos/galeria /iconos/iniciales-logo /iconos/inicio /iconos/logo /iconos/LOGOS /iconos/nosotros /images /index.php /js /logos /robots.txt /storage /vendor /videos
Severity: medium
Fingerprint: 5f32cf5d6962f09cb3107650b3107650c59d9b00d2819680b26da2211c7e1b1b
Found 39 files trough .DS_Store spidering: /apple-touch-icon.png /apple-touch-icon2.png /apple-touch-icon3.png /assets /assets/css /assets/fonts /assets/images /assets/js /calle /css /favicon.ico /fotos /iconos /iconos/contacto /iconos/eventos /iconos/galeria /iconos/iniciales-logo /iconos/inicio /iconos/logo /iconos/LOGOS /iconos/LOGOS /INICIALES /iconos/LOGOS /TEXTO /iconos/nosotros /images /images/parroquia_edit.jpg /index.php /js /logos /logos/iniciales /logos/iniciales/logo-amarillo.png /logos/iniciales/LOGOINICIALES-AZUL.png /logos/iniciales/LOGOINICIALES-MAGENTA.png /logos/iniciales/LOGOINICIALES-NEGRO.png /logos/texto /robots.txt /storage /vendor /videos /videos/video1.mp4
Severity: low
Fingerprint: 5f32cf5d6962f09cab28146bab28146bae28260125a9f2c55102bec0660ef4f1
Found 21 files trough .DS_Store spidering: /apple-touch-icon.png /apple-touch-icon2.png /apple-touch-icon3.png /assets /assets/css /assets/fonts /assets/images /assets/js /calle /css /favicon.ico /fotos /iconos /images /index.php /js /logos /robots.txt /storage /vendor /videos
Severity: low
Fingerprint: 5f32cf5d6962f09c81c345f781c345f75f2e05adce744a39f57e512c1c40ffae
Found 32 files trough .DS_Store spidering: /apple-touch-icon.png /apple-touch-icon2.png /apple-touch-icon3.png /assets /assets/css /assets/fonts /assets/images /assets/js /calle /css /favicon.ico /fotos /iconos /iconos/contacto /iconos/eventos /iconos/galeria /iconos/iniciales-logo /iconos/inicio /iconos/logo /iconos/LOGOS /iconos/LOGOS /INICIALES /iconos/LOGOS /TEXTO /iconos/nosotros /images /images/parroquia_edit.jpg /index.php /js /logos /robots.txt /storage /vendor /videos
Severity: low
Fingerprint: 5f32cf5d6962f09c2a439cf82a439cf8f70dc1683601e4385e100e49a65ed6dd
Found 31 files trough .DS_Store spidering: /apple-touch-icon.png /apple-touch-icon2.png /apple-touch-icon3.png /assets /assets/css /assets/fonts /assets/images /assets/js /calle /css /favicon.ico /fotos /iconos /iconos/contacto /iconos/eventos /iconos/galeria /iconos/iniciales-logo /iconos/inicio /iconos/logo /iconos/LOGOS /iconos/LOGOS /INICIALES /iconos/LOGOS /TEXTO /iconos/nosotros /images /index.php /js /logos /robots.txt /storage /vendor /videos
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c3c1fc5e93c1fc5e94a7e05591a2fde597957dbc1c250b35e
Found 5 files trough .DS_Store spidering: /css /css/color-theme /img /img/backgrounds-min /js
The application has Symfony verbose mode enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 05ab011344cbe668203a32192fc2b1c5403885121dad4af9fde06baf012eb6d8
app_FacturacionModerna_numero_certificado: '20001000000200000192' app_FacturacionModerna_rfc_emisor: ESI920427886 app_FacturacionModerna_url_timbrado: 'https://t1demo.facturacionmoderna.com/timbrado/wsdl' app_FacturacionModerna_user_id: UsuarioPruebasWS app_FacturacionModerna_user_password: b9ec2afa3361a59af4b4d102d3f704eabdf097d4 app_correo_emisor: no-reply@sectorvisual.com app_dominio: sectorvisual.com app_facebook: facebook.com/sectorvisual app_icono_correo: logo_mail.jpg app_icono_sitio: sitio_logo.png app_keywords: 'Proyecto desarrollo' app_nombre_empresa: 'Sector Visual' app_nombre_sitio: sectorvisual app_sf_admin_dash_categories: Pedidos: { menu_lateral: true, menu_imagen: fa-tasks, credentials: [[admin, supervisor]], items: { Listado: { url: pedido }, Proyectos: { url: proyecto }, Cargos: { url: cargo }, Procesos: { url: proceso } } } Clientes: { menu_lateral: true, menu_imagen: fa-users, credentials: [[admin, supervisor, produccion, auxiliar]], items: { Clientes: { url: cliente, credentials: [[admin, supervisor]] }, Peticiones: { url: peticion }, 'Direcciones de entrega': { url: direccionentrega, credentials: [[admin, supervisor]] }, 'Categorías de clientes': { url: categoriacliente, credentials: [[admin]] } } } Compras: { menu_lateral: true, menu_imagen: fa-shopping-cart, items: { Compras: { url: compra }, 'Sucursales de Proveedores': { credentials: [[admin, supervisor]], url: sucursalproveedor }, Proveedores: { credentials: [[admin, supervisor]], url: proveedor } } } Contabilidad: { menu_lateral: true, menu_imagen: fa-money, credentials: [[admin, supervisor]], items: { Gasto: { url: gasto }, Nómina: { url: nomina_corte }, Penalizaciones: { url: penalizacion }, 'Parámetros de nómina': { url: nomina_parametro }, Préstamos: { url: prestamo }, Bonos: { url: bono/index }, 'Órdenes de Pagos': { url: pago }, 'Flujo de Efectivo': { url: efectivo }, 'Categoría de Gastos': { url: categoria_gasto }, Facturas: { url: factura } } } Inventario: { menu_lateral: true, menu_imagen: fa-inbox, credentials: [[admin, supervisor, auxiliar]], items: { Movimientos: { url: producto_movimiento, credentials: [[admin, supervisor, auxiliar]] }, Insumos: { url: producto, credentials: [[admin, supervisor, auxiliar]] }, Categorias: { url: categoria, credentials: [[admin, supervisor]] }, 'Grupos de categorías': { url: tipo_categoria, credentials: [[admin, supervisor]] }, Marcas: { url: marca }, 'Países procedencia': { url: paisprocedencia, credentials: [[admin, supervisor]] } } } Configuración: { menu_lateral: true, menu_imagen: fa-cogs, credentials: [admin], items: { 'Actividades de planeación': { url: tarea_actividad }, 'Calificaciones de clientes': { url: calificacioncliente }, 'Métodos de pago': { url: metodopago }, Documentos: { url: documento }, 'Días festivos': { url: dias_festivos }, Usuarios: { url: sf_guard_user }, Configuración: { url: 'configuracion/edit?id=1' }, 'Log Accesos': { url: acceso_log/index } } } app_sf_admin_dash_default_image: settings.png app_sf_admin_dash_image_dir: /fooAdminKatnissPlugin/images/gemicon/ app_sf_admin_dash_include_jquery_no_conflict: false app_sf_admin_dash_include_path: true app_sf_admin_dash_items: null app_sf_admin_dash_jquery_filename: jquery-1.9.1.min.js app_sf_admin_dash_login_route: sf_guard_signin app_sf_admin_dash_logo: logo_header.png app_sf_admin_dash_logout: true app_sf_admin_dash_logout_route: sf_guard_signout app_sf_admin_dash_resize_mode: thumbnail app_sf_admin_dash_site: inews app_sf_admin_dash_web_dir: /fooAdminKatnissPlugin app_twitter: twitter.com/sectorvisual sfTCPDFPlugin_dir: /home/ubuntu/www/sectorvisual/plugins/sfTCPDFPlugin/lib/tcpdf/ sfTCPDFPlugin_font_dir: /home/ubuntu/www/sectorvisual/plugins/sfTCPDFPlugin/lib/tcpdf/fonts/ sf_admin_module_web_dir: /sfDoctrinePlugin sf_admin_web_dir: /sf/sf_admin sf_app: admin sf_app_base_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin sf_app_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin/prod sf_app_config_dir: /home/ubuntu/www/sectorvisual/apps/admin/config sf_app_dir: /home/ubuntu/www/sectorvisual/apps/admin sf_app_i18n_dir: /home/ubuntu/www/sectorvisual/apps/admin/i18n sf_app_lib_dir: /home/ubuntu/www/sectorvisual/apps/admin/lib sf_app_module_dir: /home/ubuntu/www/sectorvisual/apps/admin/modules sf_app_template_dir: /home/ubuntu/www/sectorvisual/apps/admin/templates sf_apps_dir: /home/ubuntu/www/sectorvisual/apps sf_cache: false sf_cache_dir: /home/ubuntu/www/sectorvisual/cache sf_charset: utf-8 sf_check_lock: false sf_compressed: false sf_config_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin/prod/config sf_config_dir: /home/ubuntu/www/sectorvisual/config sf_csrf_secret: 2d080d055f0fcbf64cb9b19f77287cdcc0d9d699 sf_data_dir: /home/ubuntu/www/sectorvisual/data sf_debug: true sf_default_culture: es sf_enabled_modules: - default - fooAdminKatniss - sfGuardAuth - sfGuardUser sf_encode: utf-8 sf_environment: prod sf_error_404_action: error404 sf_error_404_module: default sf_error_reporting: 341 sf_escaping_method: ESC_SPECIALCHARS sf_escaping_strategy: false sf_etag: true sf_file_link_format: null sf_i18n: off sf_i18n_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin/prod/i18n sf_lib_dir: /home/ubuntu/www/sectorvisual/lib sf_log_dir: /home/ubuntu/www/sectorvisual/log sf_logging_enabled: false sf_login_action: signin sf_login_module: sfGuardAuth sf_module_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin/prod/modules sf_module_disabled_action: disabled sf_module_disabled_module: default sf_no_script_name: false sf_orm: doctrine sf_plugins_dir: /home/ubuntu/www/sectorvisual/plugins sf_root_dir: /home/ubuntu/www/sectorvisual sf_secure_action: secure sf_secure_module: sfGuardAuth sf_standard_helpers: - Partial - Cache - I18N sf_symfony_lib_dir: /home/ubuntu/www/sectorvisual/lib/vendor/symfony/lib sf_template_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin/prod/template sf_test_cache_dir: /home/ubuntu/www/sectorvisual/cache/admin/prod/test sf_test_dir: /home/ubuntu/www/sectorvisual/test sf_upload_dir: /home/ubuntu/www/sectorvisual/web/uploads sf_use_database: true sf_web_debug: false sf_web_debug_web_dir: /sf/sf_web_debug sf_web_dir: /home/ubuntu/www/sectorvisual/web