โ† Dashboard / Scan #1

https://linens.brubai.net

๐Ÿ• Mar 05, 2026 10:09 โ— completed Modules: ssl, headers, stack, nikto, zap, nmap, infra Stack: python
โฌ‡ Export JSON
Risk Score
100 /100
Critical Risk
Findings Breakdown
5
critical
3
high
3
medium
4
low
9
info

๐Ÿ“‹ Executive Summary

Security scan of https://linens.brubai.net completed on March 05, 2026. A total of 24 finding(s) were identified across 7 scan module(s).

โ›” 5 critical issue(s) require immediate attention โ€” these represent active security risks that could lead to data breach or system compromise.

โš ๏ธ 3 high-severity issue(s) should be remediated within 24โ€“72 hours.

๐Ÿ”ถ 3 medium-severity issue(s) should be addressed in the next sprint.

Detailed Findings

CRITICAL Cloud Metadata Reachable: GCP Metadata API infra โ–ผ
CRITICAL Cloud Metadata Reachable: GCP Metadata (internal) infra โ–ผ
CRITICAL Exposed: /.git/HEAD infra โ–ผ
CRITICAL Exposed: /.git/config infra โ–ผ
CRITICAL Exposed: /.env infra โ–ผ
HIGH Missing Header: Strict-Transport-Security headers โ–ผ
HIGH Missing Header: Content-Security-Policy headers โ–ผ
HIGH ReDoc API Docs Found: /redoc infra โ–ผ
MEDIUM Missing Header: X-Frame-Options headers โ–ผ
MEDIUM Missing Header: X-Content-Type-Options headers โ–ผ
MEDIUM Information Disclosure: Server headers โ–ผ
LOW Missing Header: Referrer-Policy headers โ–ผ
LOW Missing Header: Permissions-Policy headers โ–ผ
LOW Port 80/tcp Open: HTTP nmap โ–ผ
LOW Port 8443/tcp Open: HTTPS-Alt nmap โ–ผ
INFO SSL/TLS Configuration Looks Good ssl โ–ผ
INFO Target Unreachable stack โ–ผ
INFO Nikto: No Issues Found nikto โ–ผ
INFO ZAP Scan Error zap โ–ผ
INFO Port 22/tcp Open: SSH nmap โ–ผ
INFO Port 443/tcp Open: HTTPS nmap โ–ผ
INFO Host: linens.brubai.net โ†’ 34.1.129.53 infra โ–ผ
INFO GCP IP Range Detected infra โ–ผ
INFO SSH Port 22 Open infra โ–ผ