Nmap
Scan Summary :
severity | service | vulnerability |
info | http (port:80) | |
info | https (port:443) | |
info | IIS (port:1027) | |
info | unknown (port:1028) | |
info | ms-lsa (port:1029) |
Mozilla HTTP observatory
Scan Summary :
Impact | Description | Documentation |
Content Security Policy (CSP) header not implemented | Implement one, see MDN's Content Security Policy (CSP) documentation. | |
| Documentation for x-frame-options-sameorigin-or-deny |
Scan OWASP
risk | name |
Medium (High) | Content Security Policy (CSP) Header Not Set |
Medium (High) | Sub Resource Integrity Attribute Missing |
Medium (Medium) | Missing Anti-clickjacking Header |
Low (High) | Strict-Transport-Security Header Not Set |
Low (Medium) | Insufficient Site Isolation Against Spectre Vulnerability |
Low (Medium) | Permissions Policy Header Not Set |
Low (Medium) | X-Content-Type-Options Header Missing |
Informational (High) | Sec-Fetch-Dest Header is Missing |
Informational (High) | Sec-Fetch-Mode Header is Missing |
Informational (High) | Sec-Fetch-Site Header is Missing |
Informational (High) | Sec-Fetch-User Header is Missing |
Informational (Medium) | Base64 Disclosure |
Informational (Medium) | Modern Web Application |
Informational (Medium) | Storable and Cacheable Content |
Informational (Medium) | Storable but Non-Cacheable Content |
Informational (Low) | Re-examine Cache-control Directives |
Nuclei
Séverité | Name | Matcher |
info | SPF Record - Detection | spf-record-detect |
info | DNS TXT Record Detected | txt-fingerprint |
info | CAA Record | caa-fingerprint |
info | DNS DMARC - Detect | dmarc-detect |
info | NS Record Detection | nameserver-fingerprint |
info | MX Record Detection | mx-fingerprint |
info | Microsoft Azure Domain Tenant ID - Detect | azure-domain-tenant |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | RDAP WHOIS | rdap-whois |
info | Missing Subresource Integrity | missing-sri |
info | Detect SSL Certificate Issuer | ssl-issuer |
info | SSL DNS Names | ssl-dns-names |
info | TLS Version - Detect | tls-version |
info | TLS Version - Detect | tls-version |