Apache 2.4.62
tcp/443 tcp/80
Jetty(12.0.14)
tcp/443
OpenSSL 3.2.2
tcp/443 tcp/80
Synapse 1.121.1
tcp/443
WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb583e3d399fac9c920fac9c920fac9c920fac9c920
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.7 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522fd39412a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = ssh://git@dev.haprosgames.com:22222/koca2000/homepage.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652206c510b1
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@dev.haprosgames.com:koca2000/homepage.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522fd39412a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = ssh://git@dev.haprosgames.com:22222/koca2000/homepage.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652206c510b1
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@dev.haprosgames.com:koca2000/homepage.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Jenkins instance is publicly available.
This could leak to source code or artifact leaks if not properly configured.
Fingerprint: fccae5bcd22b6a595c0788952a0071d49045353c20598887892af6df160c1ef4
Found Jenkins job NoteBlockAPI Found artifact NoteBlockAPI-1.6.2-SNAPSHOT-javadoc.jar in build 35 Found artifact NoteBlockAPI-1.6.2-SNAPSHOT.jar in build 35 Found Jenkins job NoteBlockAPI-2.0 Found artifact NoteBlockAPI-2.0-SNAPSHOT-javadoc.jar in build 11 Found artifact NoteBlockAPI-2.0-SNAPSHOT.jar in build 11 Found Jenkins job NoteBlockMusicPlayer Found artifact NoteBlockMusicPlayer-1.9.0-SNAPSHOT.jar in build 23
Fingerprint: fccae5bcd22b6a595c0788952a0071d49045353c2059888735a2ba1db50af843
Found Jenkins job NoteBlockAPI Found artifact NoteBlockAPI-1.6.2-SNAPSHOT-javadoc.jar in build 35 Found artifact NoteBlockAPI-1.6.2-SNAPSHOT.jar in build 35 Found Jenkins job NoteBlockAPI-2.0 Found artifact NoteBlockAPI-2.0-SNAPSHOT-javadoc.jar in build 6 Found artifact NoteBlockAPI-2.0-SNAPSHOT.jar in build 6 Found Jenkins job NoteBlockMusicPlayer Found artifact NoteBlockMusicPlayer-1.9.0-SNAPSHOT.jar in build 22
Open service 89.221.222.22:80 · matrix.kocandrle.net
2024-12-22 04:18
HTTP/1.1 301 Moved Permanently Date: Sun, 22 Dec 2024 04:18:44 GMT Server: Apache/2.4.62 (Rocky Linux) OpenSSL/3.2.2 Location: https://matrix.kocandrle.net/ Content-Length: 237 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://matrix.kocandrle.net/">here</a>.</p> </body></html>
Open service 89.221.222.22:443 · matrix.kocandrle.net
2024-12-22 04:18
HTTP/1.1 302 Found Date: Sun, 22 Dec 2024 04:18:44 GMT Server: Synapse/1.121.1 Content-Type: text/html; charset=utf-8 Location: /_matrix/static Content-Length: 208 Connection: close <html> <head> <meta http-equiv="refresh" content="0;URL=/_matrix/static"> </head> <body bgcolor="#FFFFFF" text="#000000"> <a href="/_matrix/static">click here</a> </body> </html>
Open service 89.221.222.22:80 · ci.haprosgames.com
2024-12-22 04:18
HTTP/1.1 301 Moved Permanently Date: Sun, 22 Dec 2024 04:18:42 GMT Server: Apache/2.4.62 (Rocky Linux) OpenSSL/3.2.2 Location: https://ci.haprosgames.com/ Content-Length: 235 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://ci.haprosgames.com/">here</a>.</p> </body></html>
Open service 89.221.222.22:443 · ci.haprosgames.com
2024-12-22 04:18
HTTP/1.1 200 OK Date: Sun, 22 Dec 2024 04:18:42 GMT Server: Jetty(12.0.14) Vary: Accept-Encoding X-Content-Type-Options: nosniff Content-Type: text/html;charset=utf-8 Expires: Thu, 01 Jan 1970 00:00:00 GMT Cache-Control: no-cache,no-store,must-revalidate X-Hudson-Theme: default Referrer-Policy: same-origin Cross-Origin-Opener-Policy: same-origin X-Hudson: 1.395 X-Jenkins: 2.489 X-Jenkins-Session: e753ea72 X-Frame-Options: sameorigin X-Instance-Identity: MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsR4Nii8RSmqyJI1bZ6Y7s0/a6bg9yyOrw/Bc9ieZOm2q4TUtLb8wA1+lOi9+S5T1hTeJbWELDEcPUkBMs2GCZCi7dcQ2+vvMLUh/8OUsjKolJ9BfzZOdM/IOmzWymOcwfBCjhuovpgFd+w1TPiDxKFpViwxNrVKN4IrmRHNz8/pAlJaAHEnYe6s3jCBnmeODMLDEMoGTMXq4/wPGjY+M+A02eaY7PQZqC3tWPg6w/bGaV3+BEGAp3oQBA52JoYr8atPvKWS6lPtqA/1bn8YeAM8GI3Ws2n2Yke2f33ztGHEpCIcYE3FgNsA9u+5lJ0hUb1soJl6NNgJduNl2QlXJdwIDAQAB Set-Cookie: JSESSIONID.7d7d9b35=node0tkiq84e1smb9o0c1ny84ftz491.node0; Path=/; HttpOnly Connection: close Transfer-Encoding: chunked
Open service 89.221.222.22:443 · kocandrle.net
2024-12-21 04:15
HTTP/1.1 200 OK Date: Sat, 21 Dec 2024 04:15:31 GMT Server: Apache/2.4.62 (Rocky Linux) OpenSSL/3.2.2 X-Powered-By: PHP/8.3.14 Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 Page title: Domovská stránka <!DOCTYPE html> <html> <head> <title>Domovská stránka</title> <link rel="stylesheet" href="css/style.css"> <script src="js/script.js"></script> <script src="js/Sortable.min.js"></script> </head> <body > <div class="container-center-wrapper"> <div id="login" class="container-center"> <div class="title">Přihlášení</div> <form action="login.php" method="POST"> <div class="fields"> <label for="password">Heslo:</label> <input id="password" name="password" type="password" required /> </div> <div class="buttons"> <input type="submit" value="Přihlásit se" /> </div> </form> </div> </div> </body> </html>
Open service 89.221.222.22:80 · kocandrle.net
2024-12-21 04:15
HTTP/1.1 301 Moved Permanently Date: Sat, 21 Dec 2024 04:15:30 GMT Server: Apache/2.4.62 (Rocky Linux) OpenSSL/3.2.2 Location: https://kocandrle.net/ Content-Length: 230 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://kocandrle.net/">here</a>.</p> </body></html>
Open service 89.221.222.22:443 · www.kocandrle.net
2024-12-21 04:15
HTTP/1.1 200 OK Date: Sat, 21 Dec 2024 04:15:31 GMT Server: Apache/2.4.62 (Rocky Linux) OpenSSL/3.2.2 X-Powered-By: PHP/8.3.14 Upgrade: h2 Connection: Upgrade, close Vary: Accept-Encoding Transfer-Encoding: chunked Content-Type: text/html; charset=UTF-8 Page title: Domovská stránka <!DOCTYPE html> <html> <head> <title>Domovská stránka</title> <link rel="stylesheet" href="css/style.css"> <script src="js/script.js"></script> <script src="js/Sortable.min.js"></script> </head> <body > <div class="container-center-wrapper"> <div id="login" class="container-center"> <div class="title">Přihlášení</div> <form action="login.php" method="POST"> <div class="fields"> <label for="password">Heslo:</label> <input id="password" name="password" type="password" required /> </div> <div class="buttons"> <input type="submit" value="Přihlásit se" /> </div> </form> </div> </div> </body> </html>
Open service 89.221.222.22:80 · www.kocandrle.net
2024-12-21 04:15
HTTP/1.1 301 Moved Permanently Date: Sat, 21 Dec 2024 04:15:30 GMT Server: Apache/2.4.62 (Rocky Linux) OpenSSL/3.2.2 Location: https://www.kocandrle.net/ Content-Length: 234 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://www.kocandrle.net/">here</a>.</p> </body></html>