nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb583e3d39867420e8d67420e8d67420e8d67420e8d
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.6 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Open service 52.221.132.23:443
2024-12-22 00:58
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:58:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXZ6PCW3C7YZK7GJKTK43C","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXZ6PCW3C7YZK7GJKTK43C X-Runtime: 0.021686 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-20 00:30
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:30:02 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQHAPSWJNQTV77A4EDGAQK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQHAPSWJNQTV77A4EDGAQK X-Runtime: 0.072599 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-18 01:44
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:44:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBQ0355P3V32RR9A0D5BT2D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBQ0355P3V32RR9A0D5BT2D X-Runtime: 0.027617 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-17 21:14
HTTP/1.1 302 Found Server: nginx Date: Tue, 17 Dec 2024 21:14:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFB7JMXRRHRS7NGGNDK0VXE5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFB7JMXRRHRS7NGGNDK0VXE5 X-Runtime: 0.023783 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-15 23:48
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:48:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6BHQ2AT061X3967AGBWV2R","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6BHQ2AT061X3967AGBWV2R X-Runtime: 0.023914 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-14 00:01
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 00:01:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF17G5AYV0W4N8NHK8XRTS3B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF17G5AYV0W4N8NHK8XRTS3B X-Runtime: 0.028681 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-12 00:50
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 00:50:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW5HJWVK9BPAKT4YSWPTN72","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW5HJWVK9BPAKT4YSWPTN72 X-Runtime: 0.020229 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-12-02 00:39
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 00:39:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2CYAV0YHV96SS3TXTY9M5X","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2CYAV0YHV96SS3TXTY9M5X X-Runtime: 0.090666 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-11-30 00:27
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 00:27:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX7E73HXH3XE6N8KAGPYK71","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX7E73HXH3XE6N8KAGPYK71 X-Runtime: 0.038917 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>
Open service 52.221.132.23:443
2024-11-28 00:38
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 00:38:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.132.23/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR38Y78J22TDXVFWER5VF55","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR38Y78J22TDXVFWER5VF55 X-Runtime: 0.020552 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.132.23/users/sign_in">redirected</a>.</body></html>