nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 88.214.203.46:443
2024-12-22 00:58
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:58:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXZQK14CER6SZMZM9E7GE7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXZQK14CER6SZMZM9E7GE7 X-Runtime: 0.057168 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-12-20 22:10
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 22:10:20 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFK1Y8DEHBXDAJJX2GPXQFAT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFK1Y8DEHBXDAJJX2GPXQFAT X-Runtime: 0.042179 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-12-20 00:34
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:34:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQSY13VHQJDD5D4YR82SKB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQSY13VHQJDD5D4YR82SKB X-Runtime: 0.053300 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-12-18 16:53
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 16:53:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDB0EMKXWSRQS0HXMT6A6H4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDB0EMKXWSRQS0HXMT6A6H4 X-Runtime: 0.064216 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-12-18 01:47
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:47:19 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBQ5DEX41BKWM9GYVMXPVJX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBQ5DEX41BKWM9GYVMXPVJX X-Runtime: 0.077042 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-12-15 23:52
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:52:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6BSTV9TD3TW7WDHWE0DXDB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6BSTV9TD3TW7WDHWE0DXDB X-Runtime: 0.068147 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-12-14 09:29
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 09:29:03 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF27ZZW334TCDY4HSET8CW5Y","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF27ZZW334TCDY4HSET8CW5Y X-Runtime: 0.055010 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-12-14 00:04
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 00:04:11 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF17NPPPTQN1HSDF1AKRVRN8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF17NPPPTQN1HSDF1AKRVRN8 X-Runtime: 0.083188 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-12-12 13:45
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 13:45:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXHWNMXFKTBFS914P5CXAKN","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXHWNMXFKTBFS914P5CXAKN X-Runtime: 0.020965 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-12-12 00:56
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 00:56:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW5W43CHCH67XH8RNVKECGB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW5W43CHCH67XH8RNVKECGB X-Runtime: 0.061363 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-12-02 13:34
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 13:34:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3S9PG4BPHA98TNY3R7F377","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3S9PG4BPHA98TNY3R7F377 X-Runtime: 0.066965 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-12-02 01:40
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 01:40:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2GE6188TK49PNEJYJGM8G2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2GE6188TK49PNEJYJGM8G2 X-Runtime: 0.083032 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-11-30 09:22
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 09:22:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDY62ESQ4TJ8ZWN4AM5CQAF4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDY62ESQ4TJ8ZWN4AM5CQAF4 X-Runtime: 0.019478 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-11-30 01:01
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 01:01:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX9CB96F9PMG5EP8J4ZWTMH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX9CB96F9PMG5EP8J4ZWTMH X-Runtime: 0.070302 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-11-28 09:06
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 09:06:58 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDS0C2MF3DNQ2KHEY4V7DJMW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDS0C2MF3DNQ2KHEY4V7DJMW X-Runtime: 0.058568 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-11-28 01:00
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 01:00:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR4J1Q7EDPYSJ83F95EKYDC","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR4J1Q7EDPYSJ83F95EKYDC X-Runtime: 0.041603 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-11-27 00:55
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 00:55:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNHV92MPGGH9AGT3XEHXQHN","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNHV92MPGGH9AGT3XEHXQHN X-Runtime: 0.073039 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443 · glbr.eastrelay.com
2024-11-21 03:05
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 03:05:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://glbr.eastrelay.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD6AXY24GJRZ3Z7E7E9YPRJ0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD6AXY24GJRZ3Z7E7E9YPRJ0 X-Runtime: 0.019900 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://glbr.eastrelay.com/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-11-20 17:47
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 17:47:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5B019T672KXD1DPQVKSYE9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5B019T672KXD1DPQVKSYE9 X-Runtime: 0.022658 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>
Open service 88.214.203.46:443
2024-11-20 13:29
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 13:29:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://88.214.203.46/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4W6CZ7X3ZXCB5YW4D4R2GA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4W6CZ7X3ZXCB5YW4D4R2GA X-Runtime: 0.059627 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://88.214.203.46/users/sign_in">redirected</a>.</body></html>