.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09cccd847a3ccd847a3d93c1ff46f63c4f566aedd51b1638e6e
Found 43 files trough .DS_Store spidering: /images /images/auth-overlalay-image.png /images/ballazo-logo.png /images/feature-image-01.png /images/feature-image-02.png /images/hero-image.png /images/svg /images/svg/auth-image.svg /images/svg/ballazo-small.svg /images/svg/benefit-img.svg /images/svg/benefits.svg /images/svg/china.svg /images/svg/coins-stacked.svg /images/svg/credit-card.svg /images/svg/globe-05.svg /images/svg/globe.svg /images/svg/how-it-works-icon.svg /images/svg/how-it-works.svg /images/svg/map-footer.svg /images/svg/rocket.svg /images/svg/send.svg /images/svg/trinindad.svg /images/svg/tunisia.svg /images/svg/turkey.svg /images/svg/turkmenistan.svg /images/svg/turks.svg /images/svg/tuvalu.svg /images/svg/uae.svg /images/svg/uganda.svg /images/svg/ukraine.svg /images/svg/united arab emirates.svg /images/svg/upload-cloud.svg /images/svg/uraguay.svg /images/svg/usa.svg /images/svg/uzbekistan.svg /images/svg/vanuatu.svg /images/svg/venezuela.svg /images/svg/vietnam.svg /images/svg/wales.svg /images/svg/yemen.svg /images/svg/zambia.svg /images/svg/zimbabwe.svg /images/world.png
Open service 44.199.12.48:80 · spiral.rabafast.com
2026-01-12 19:12
HTTP/1.1 308 Permanent Redirect Date: Mon, 12 Jan 2026 19:12:23 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://spiral.rabafast.com Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · spiral.rabafast.com
2026-01-12 19:12
HTTP/1.1 200 OK
Date: Mon, 12 Jan 2026 19:12:21 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 32
Connection: close
Vary: Origin, Accept-Encoding
Access-Control-Allow-Credentials: true
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
X-DNS-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 0
ETag: W/"20-iwsribXMxQh3YXVmmaqZWLi3K1w"
{"status":true,"statusCode":200}
Open service 44.199.12.48:80 · dev.zeus.bluebulb.co.uk
2026-01-12 03:17
HTTP/1.1 308 Permanent Redirect Date: Mon, 12 Jan 2026 03:17:36 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://dev.zeus.bluebulb.co.uk Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · dev.zeus.bluebulb.co.uk
2026-01-12 03:17
HTTP/1.1 302 Found
Date: Mon, 12 Jan 2026 03:17:37 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
X-Powered-By: PHP/8.4.14
Cache-Control: no-cache, private
Location: https://dev.zeus.bluebulb.co.uk/login
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.datatables.net https://cdnjs.cloudflare.com https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.datatables.net https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://fonts.googleapis.com; img-src 'self' data: blob: https:; font-src 'self' data: https://fonts.gstatic.com https://cdnjs.cloudflare.com; connect-src 'self'; frame-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self'; upgrade-insecure-requests
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Referrer-Policy: strict-origin-when-cross-origin
Set-Cookie: XSRF-TOKEN=eyJpdiI6IkpWN3Zva2c5c1Q3T1ZPYUh5cDhpdHc9PSIsInZhbHVlIjoiK0FaSlU0UWNSdXRiSkJLMFpJSi9xa21aWmY1OENITHZXMHhBQ09mNWdtQ1drZElUQ0lvOHczR09lUnFYRzZvVElpUFVHYWlSS0swV0RVL3loYmVhcDF2eDhOdTRXbCtaRnh3elpIOVN3Mm9qRHIyN2dkbzlBNGpmN2c3TGtQOWkiLCJtYWMiOiI3MDA0MmZlMjNhMzI5MmFjYWNjZDFhMmY5ODNlMjFkOGY0NzVjZjhjNTIzNTRjNjJkMTgyNmUwYmNjZDMxYTE2IiwidGFnIjoiIn0%3D; expires=Mon, 12 Jan 2026 05:17:37 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: worksuite_session=eyJpdiI6Iko5bjI3UFY2OFppdXpzaFRuUEpwUlE9PSIsInZhbHVlIjoidUlQQVN2allaZDJyWjhaTHVDS3NCeWF3dXlBOHR0ZDIranpZTisvLzNJUGlUMmM4RGRybTJ1bVlxTWtoMEVvUGxueW1BbFRQekxaL0lEcEI4OThhS2RDRDBBd2NWL29OdlZoaWdRajZjY1lmbkZvQXg2c1V4NC8xMktzdUpSWEgiLCJtYWMiOiJlOGRhMWEwMGVmNWZkOWI4NDVjZDc0OTU4ZGI1MjdiZTEwMzJlMjYwYjE2ZDA3MDMxYzc5ZDY3NGQzNjM5NDcxIiwidGFnIjoiIn0%3D; expires=Mon, 12 Jan 2026 05:17:37 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax
Strict-Transport-Security: max-age=31536000; includeSubDomains
Page title: Redirecting to https://dev.zeus.bluebulb.co.uk/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://dev.zeus.bluebulb.co.uk/login'" />
<title>Redirecting to https://dev.zeus.bluebulb.co.uk/login</title>
</head>
<body>
Redirecting to <a href="https://dev.zeus.bluebulb.co.uk/login">https://dev.zeus.bluebulb.co.uk/login</a>.
</body>
</html>
Open service 44.199.12.48:443 · dev.onboarding.balazooexpress.co.uk
2026-01-09 21:15
HTTP/1.1 503 Service Temporarily Unavailable Date: Fri, 09 Jan 2026 21:15:27 GMT Content-Type: text/html Content-Length: 190 Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains Page title: 503 Service Temporarily Unavailable <html> <head><title>503 Service Temporarily Unavailable</title></head> <body> <center><h1>503 Service Temporarily Unavailable</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:80 · devadmin.chrisborough.tech
2026-01-09 10:48
HTTP/1.1 404 Not Found Date: Fri, 09 Jan 2026 10:48:34 GMT Content-Type: text/html Content-Length: 146 Connection: close Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:80 · devapi.buyletlive.com
2026-01-07 01:54
HTTP/1.1 308 Permanent Redirect Date: Wed, 07 Jan 2026 01:54:31 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://devapi.buyletlive.com Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · devapi.buyletlive.com
2026-01-07 01:54
HTTP/1.1 302 Found
Date: Wed, 07 Jan 2026 01:54:29 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache, private
Location: https://devapi.buyletlive.com/login
Referrer-Policy: no-referrer-when-downgrade
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
Strict-Transport-Security: max-age=31536000; includeSubDomains
Access-Control-Allow-Origin: *
Set-Cookie: buyletlive_session=eyJpdiI6IjNzbjZjVGVSR1A2QkQyV2V0R3AwT0E9PSIsInZhbHVlIjoiVGN1c203c1Q2YmFUMWhzQldWZFZ6dHI2VjhXV2g1UzBRaSswQm1FZnJMY2o0NUJpSDFiallrNTZBN0s1WHFkWlZlazlaUkE2MVNxWjhEUTVmR1d4NGtCTkFsaDBJUkN2M1kra29oMzFJcGhBeU5mQk5LcEZLOTdyVHZpak9HY1ciLCJtYWMiOiJiMGE3MGVhODIzYjY2NDQ4YWVlMDNhZWZiYWIyN2NmOTc1NDc4YTE2ZGU1NzkwM2U0MWRhMDliZDhhMWUzN2I2IiwidGFnIjoiIn0%3D; expires=Wed, 07 Jan 2026 03:54:29 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax
Page title: Redirecting to https://devapi.buyletlive.com/login
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://devapi.buyletlive.com/login'" />
<title>Redirecting to https://devapi.buyletlive.com/login</title>
</head>
<body>
Redirecting to <a href="https://devapi.buyletlive.com/login">https://devapi.buyletlive.com/login</a>.
</body>
</html>
Open service 44.199.12.48:80 · stagingapi.buyletlive.com
2026-01-03 06:59
HTTP/1.1 308 Permanent Redirect Date: Sat, 03 Jan 2026 06:59:57 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://stagingapi.buyletlive.com Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:80 · devapi.sendova.co.uk
2026-01-01 09:43
HTTP/1.1 308 Permanent Redirect Date: Thu, 01 Jan 2026 09:43:57 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://devapi.sendova.co.uk Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · devapi.sendova.co.uk
2026-01-01 09:43
HTTP/1.1 404 Not Found Date: Thu, 01 Jan 2026 09:43:57 GMT Content-Type: text/html Content-Length: 146 Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:80 · stagingapi.sendova.co.uk
2025-12-31 20:25
HTTP/1.1 308 Permanent Redirect Date: Wed, 31 Dec 2025 20:25:14 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://stagingapi.sendova.co.uk Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · stagingapi.sendova.co.uk
2025-12-31 20:25
HTTP/1.1 404 Not Found Date: Wed, 31 Dec 2025 20:25:14 GMT Content-Type: text/html Content-Length: 146 Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains Page title: 404 Not Found <html> <head><title>404 Not Found</title></head> <body> <center><h1>404 Not Found</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · app.chrisborough.com
2025-12-30 16:42
HTTP/1.1 302 Found Date: Tue, 30 Dec 2025 16:42:51 GMT Transfer-Encoding: chunked Connection: close location: /sign-in Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 44.199.12.48:80 · app.chrisborough.com
2025-12-30 16:42
HTTP/1.1 308 Permanent Redirect Date: Tue, 30 Dec 2025 16:42:51 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://app.chrisborough.com Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 44.199.12.48:443 · dev.onboarding.balazooexpress.co.uk
2025-12-22 22:10
HTTP/1.1 200 OK Date: Mon, 22 Dec 2025 22:10:34 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.4.14 Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6IkFPVXlBMWY3a3ZYVTViYlRDV0tOTmc9PSIsInZhbHVlIjoiQitVREdvZWJmZis5bHJVMjlXMW9Ua2xZK1YvR2NOb25hRXhhVVZwUHRlZ2Rmb0JWNldLRG93NVRMZHNJQlVoMmFmaCtBT3FLM3NXR2NyclF1UE5GeEdGSEhiMDB3WVF4WDBTZ3B5QkVzaCsrbUVHeUVUUHNzZk4waGdKUnBJU2UiLCJtYWMiOiJhNWVlOWFkZjI0MTRkNmRiYWU2NzM2ZmNmZjZmNzFhZmMwZWQ4ZTc1ZGU3NzdmN2FkZjA1MjY2MmU4ZjdkMTQ0IiwidGFnIjoiIn0%3D; expires=Tue, 23 Dec 2025 00:10:34 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: balazoo_session=eyJpdiI6IjB4cHFiM0NQMnNCUkFVNEFGRHV6YkE9PSIsInZhbHVlIjoiTUdNa1I3enpQVEVKOTNFM1RDQTRrSnYvc3g2MUw3UFJFWEtCZFp6MytHaEdZR3R2Vjg4Ly9NeGhIdFczTkRmZDh3b2lkc0NtZVhwQVpPYkZwbmxUWElnU1prTlNXeW5uQXUxTU1Mb25TTWtZSmI3ZmE3R3ZVcXg0U1J3bDFrdlYiLCJtYWMiOiJiZTg0ZmMxODgxNTNjMmZhZjE3NWNlNGNkMzllYWIyNGZiYzM1Zjk2ZDEzMjViOGE2MGZmM2JiNDg3OWY3NTRjIiwidGFnIjoiIn0%3D; expires=Tue, 23 Dec 2025 00:10:34 GMT; Max-Age=7200; path=/; httponly; samesite=lax Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 44.199.12.48:443 · dev.onboarding.balazooexpress.co.uk
2025-12-21 09:30
HTTP/1.1 200 OK Date: Sun, 21 Dec 2025 09:30:35 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.4.14 Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6IkFCU1hpTVZXTUp2YVRCTzlQd3E5NkE9PSIsInZhbHVlIjoiYXdoMFUrSlo5Rkhsa1pPODJISXJhYWV1MmFFRktCZ1pKK2E1SS9qMnk5aU5zbGhWVThuUWtvNWhRU09DTjRHRGxtWFJNODZSU3lUNm1GdXNlbGc2S2JkbmtaVm96T1dGVU91SFdhUXlHUzdieEV4eUd3amUwUkhyRTRVa2pta1oiLCJtYWMiOiIzZjcyZTExMTBiYTg2YTVmZmYzMjRjMzFkYTczZDgzODc1YzI0NGVhMGQ1NDlmMTZmYjc3NTBhZjkwMTIzZGU1IiwidGFnIjoiIn0%3D; expires=Sun, 21 Dec 2025 11:30:35 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: balazoo_session=eyJpdiI6IlJDR05zeGVReEIrdHVSdmtiVU01T2c9PSIsInZhbHVlIjoiNVdaakxvWC9WeXkydCt2azdYdFQ5RkJiems0TG95QzV4UGF5ZytPdlA4Z1NabXhvZUVzVGM1YUF1ZENIMy9GbXNHUGRRSExEQVVzWXFNUTRZZzdybzRldHQ1ZGdnZi84YXdXSU5LaGxMSU9Sc1JSaEVqYzBCUG9XMUhFOStUZlAiLCJtYWMiOiJkN2Q2ZWMwNzlhOTE4MjVjZjFkNjZiZmEyN2U0MWQ3NDg0OGZiYWU5ZjVhNDI2MmE1NjE1MWRhNzc4NjhjN2ViIiwidGFnIjoiIn0%3D; expires=Sun, 21 Dec 2025 11:30:35 GMT; Max-Age=7200; path=/; httponly; samesite=lax Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 44.199.12.48:443 · dev.onboarding.balazooexpress.co.uk
2025-12-19 10:52
HTTP/1.1 200 OK Date: Fri, 19 Dec 2025 10:52:36 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.4.14 Cache-Control: no-cache, private Set-Cookie: XSRF-TOKEN=eyJpdiI6ImJWbG83dkNwaVYrRGI5cmhZQktRZ3c9PSIsInZhbHVlIjoiOFluc1FMN0RwTDFTaTdvQ0Rtb1Y5K2greVc0MFRKY1lUUUQzS0JreHFWZ3B6cUlyVHB5Mjl2Sk5BYlBXRGdyM3JCRGtJRXA2aXZtRFJSM1NDNEFQMDR5cVBudXNnMzc2RzhoMjNzZ2pwODVMVHl3Nnhna3lTUjNac096VXdHUVYiLCJtYWMiOiIzYzVhZjJiMWY1YjAzNTc0YWFjYTAxMGNiZDM5MzQ3NjlmNWM0YjlhYWNiNmJkYjUxN2E4YWY4MDhjYWYzMDE4IiwidGFnIjoiIn0%3D; expires=Fri, 19 Dec 2025 12:52:36 GMT; Max-Age=7200; path=/; samesite=lax Set-Cookie: balazoo_session=eyJpdiI6ImwwRUd0Z29FSjR5cGl1MkNJK0F0V0E9PSIsInZhbHVlIjoicjJqeU90N0FzWC9tRmVBdWpNKzN0S3hVWVgveDN4cUFsMVpGQkozL1VPVWJxaDlNaHRuVS9SKzZUcmpLNVZzaU1Ua0VQMWtNcHMwN3pENXhmQnViQS9qTGp3OU9PdmVqd29ab3JvNXN1RDd4V1dWTVdrMXV3OGl6alJicGZMaGwiLCJtYWMiOiJhYWE1M2U2M2VhNzIyNmM2NzhiNDc3ZDk0NjMyYjE0MjNiZWJiNjg0NjMxNDRiZGE5NjhkMDlmMzAzNzVhYTQzIiwidGFnIjoiIn0%3D; expires=Fri, 19 Dec 2025 12:52:36 GMT; Max-Age=7200; path=/; httponly; samesite=lax Strict-Transport-Security: max-age=31536000; includeSubDomains