Apache
tcp/80
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a47c0d8c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://gitlab.com/athomenetwork/crm.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "prod"] remote = origin merge = refs/heads/prod
Open service 52.29.8.89:80
2024-11-20 01:21
HTTP/1.1 200 OK Date: Wed, 20 Nov 2024 01:21:32 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=dp84k6ck7si8e5m5cso7ef26se; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Wed, 20 Nov 2024 01:21:32 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 52.29.8.89:80
2024-11-19 20:15
HTTP/1.1 200 OK Date: Tue, 19 Nov 2024 20:15:10 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=00bqbh6emh9fkvo0aso41fqr2h; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Tue, 19 Nov 2024 20:15:10 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 52.29.8.89:80
2024-11-02 02:45
HTTP/1.1 200 OK Date: Sat, 02 Nov 2024 02:45:11 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=rva0u0tmae968s89abnh0bn554; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Sat, 02 Nov 2024 02:45:11 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 52.29.8.89:80
2024-10-30 01:44
HTTP/1.1 200 OK Date: Wed, 30 Oct 2024 01:44:37 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=thkuol00dveg8n8unnd4ou6jal; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Wed, 30 Oct 2024 01:44:37 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 52.29.8.89:80
2024-10-29 01:02
HTTP/1.1 200 OK Date: Tue, 29 Oct 2024 01:02:10 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=6dcvktb0ojjeb3ag1f21ao06qo; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Tue, 29 Oct 2024 01:02:10 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 52.29.8.89:80
2024-10-21 22:12
HTTP/1.1 200 OK Date: Mon, 21 Oct 2024 22:12:41 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=ipmfvregjemkc7ol227jr8gnsd; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Mon, 21 Oct 2024 22:12:41 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8
Open service 52.29.8.89:80
2024-10-17 23:23
HTTP/1.1 200 OK Date: Thu, 17 Oct 2024 23:23:16 GMT Server: Apache Expires: Sun, 05 Jan 1997 00:00:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: PHPSESSID=v4rmajtm1feemmvj7a7ni7ekcp; path=/ X-Frame-Options: SAMEORIGIN Last-Modified: Thu, 17 Oct 2024 23:23:16 GMT X-XSS-Protection: 1; mode=block Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Connection: close Transfer-Encoding: chunked Content-Type: text/html; charset=utf-8