WhatWeb report for http://passbolt.lan.ddnsgeek.com:80
Status    : 301 Moved Permanently
Title     : <None>
IP        : 167.179.167.166
Country   : NEW ZEALAND, NZ

Summary   : RedirectLocation[https://passbolt.lan.ddnsgeek.com/]

Detected Plugins:
[ RedirectLocation ]
	HTTP Server string location. used with http-status 301 and
	302

	String       : https://passbolt.lan.ddnsgeek.com/ (from location)

HTTP Headers:
	HTTP/1.1 301 Moved Permanently
	Location: https://passbolt.lan.ddnsgeek.com/
	Date: Sun, 05 Apr 2026 08:43:36 GMT
	Content-Length: 17
	Connection: close

WhatWeb report for https://passbolt.lan.ddnsgeek.com/
Status    : 302 Found
Title     : <None>
IP        : 167.179.167.166
Country   : NEW ZEALAND, NZ

Summary   : Cookies[passbolt_session], HTTPServer[nginx], HttpOnly[passbolt_session], nginx, RedirectLocation[/auth/login?redirect=%2F], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,x-content-type-options], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]

Detected Plugins:
[ Cookies ]
	Display the names of cookies in the HTTP headers. The
	values are not returned to save on space.

	String       : passbolt_session

[ HTTPServer ]
	HTTP server header string. This plugin also attempts to
	identify the operating system from the server header.

	String       : nginx (from server string)

[ HttpOnly ]
	If the HttpOnly flag is included in the HTTP set-cookie
	response header and the browser supports it then the cookie
	cannot be accessed through client side script - More Info:
	http://en.wikipedia.org/wiki/HTTP_cookie

	String       : passbolt_session

[ RedirectLocation ]
	HTTP Server string location. used with http-status 301 and
	302

	String       : /auth/login?redirect=%2F (from location)

[ Strict-Transport-Security ]
	Strict-Transport-Security is an HTTP header that restricts
	a web browser from accessing a website without the security
	of the HTTPS protocol.

	String       : max-age=15552000; includeSubDomains; preload

[ UncommonHeaders ]
	Uncommon HTTP server headers. The blacklist includes all
	the standard headers and many non standard but common ones.
	Interesting but fairly common headers should have their own
	plugins, eg. x-powered-by, server and x-aspnet-version.
	Info about headers can be found at www.http-stats.com

	String       : content-security-policy,x-content-type-options (from headers)

[ X-Frame-Options ]
	This plugin retrieves the X-Frame-Options value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : SAMEORIGIN

[ X-XSS-Protection ]
	This plugin retrieves the X-XSS-Protection value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : 1; mode=block

[ nginx ]
	Nginx (Engine-X) is a free, open-source, high-performance
	HTTP server and reverse proxy, as well as an IMAP/POP3
	proxy server.

	Website     : http://nginx.net/

HTTP Headers:
	HTTP/1.1 302 Found
	Cache-Control: no-store, no-cache, must-revalidate
	Content-Security-Policy: default-src 'none'; script-src 'self'; style-src 'self'; img-src 'self'; font-src 'self'; connect-src 'self'; base-uri 'self'; frame-src 'self'; frame-ancestors 'none'; form-action 'self' https://*.duosecurity.com
	Content-Type: text/html; charset=UTF-8
	Date: Sun, 05 Apr 2026 08:43:48 GMT
	Expires: Thu, 19 Nov 1981 08:52:00 GMT
	Location: /auth/login?redirect=%2F
	Pragma: no-cache
	Server: nginx
	Set-Cookie: passbolt_session=996d036795d4f6b88ad6c0fbed7ff748; path=/; HttpOnly; SameSite=Lax
	Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
	X-Content-Type-Options: nosniff
	X-Frame-Options: SAMEORIGIN
	X-Xss-Protection: 1; mode=block
	Connection: close
	Transfer-Encoding: chunked

WhatWeb report for https://passbolt.lan.ddnsgeek.com/auth/login?redirect=%2F
Status    : 200 OK
Title     : Passbolt | Open source password manager for teams
IP        : 167.179.167.166
Country   : NEW ZEALAND, NZ

Summary   : Cookies[csrfToken], Django, HTML5, HTTPServer[nginx], nginx, Script, Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[access-control-expose-headers,content-security-policy,referrer-policy,x-content-type-options,x-download-options,x-gpgauth-authenticated,x-gpgauth-debug,x-gpgauth-error,x-gpgauth-login-url,x-gpgauth-logout-url,x-gpgauth-progress,x-gpgauth-pubkey-url,x-gpgauth-verify-url,x-gpgauth-version,x-permitted-cross-domain-policies], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]

Detected Plugins:
[ Cookies ]
	Display the names of cookies in the HTTP headers. The
	values are not returned to save on space.

	String       : csrfToken

[ Django ]
	Django is a high-level Python Web framework that encourages
	rapid development and clean, pragmatic design.

	Website     : https://www.djangoproject.com/

[ HTML5 ]
	HTML version 5, detected by the doctype declaration


[ HTTPServer ]
	HTTP server header string. This plugin also attempts to
	identify the operating system from the server header.

	String       : nginx (from server string)

[ Script ]
	This plugin detects instances of script HTML elements and
	returns the script language/type.


[ Strict-Transport-Security ]
	Strict-Transport-Security is an HTTP header that restricts
	a web browser from accessing a website without the security
	of the HTTPS protocol.

	String       : max-age=15552000; includeSubDomains; preload

[ UncommonHeaders ]
	Uncommon HTTP server headers. The blacklist includes all
	the standard headers and many non standard but common ones.
	Interesting but fairly common headers should have their own
	plugins, eg. x-powered-by, server and x-aspnet-version.
	Info about headers can be found at www.http-stats.com

	String       : access-control-expose-headers,content-security-policy,referrer-policy,x-content-type-options,x-download-options,x-gpgauth-authenticated,x-gpgauth-debug,x-gpgauth-error,x-gpgauth-login-url,x-gpgauth-logout-url,x-gpgauth-progress,x-gpgauth-pubkey-url,x-gpgauth-verify-url,x-gpgauth-version,x-permitted-cross-domain-policies (from headers)

[ X-Frame-Options ]
	This plugin retrieves the X-Frame-Options value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : SAMEORIGIN

[ X-XSS-Protection ]
	This plugin retrieves the X-XSS-Protection value from the
	HTTP header. - More Info:
	http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
	aspx

	String       : 1; mode=block

[ nginx ]
	Nginx (Engine-X) is a free, open-source, high-performance
	HTTP server and reverse proxy, as well as an IMAP/POP3
	proxy server.

	Website     : http://nginx.net/

HTTP Headers:
	HTTP/1.1 200 OK
	Access-Control-Expose-Headers: X-GPGAuth-Verify-Response
	Access-Control-Expose-Headers: X-GPGAuth-Progress
	Access-Control-Expose-Headers: X-GPGAuth-User-Auth-Token
	Access-Control-Expose-Headers: X-GPGAuth-Authenticated
	Access-Control-Expose-Headers: X-GPGAuth-Refer
	Access-Control-Expose-Headers: X-GPGAuth-Debug
	Access-Control-Expose-Headers: X-GPGAuth-Error
	Access-Control-Expose-Headers: X-GPGAuth-Pubkey
	Access-Control-Expose-Headers: X-GPGAuth-Logout-Url
	Access-Control-Expose-Headers: X-GPGAuth-Version
	Cache-Control: no-store, no-cache, must-revalidate
	Content-Encoding: gzip
	Content-Security-Policy: default-src 'none'; script-src 'self'; style-src 'self'; img-src 'self'; font-src 'self'; connect-src 'self'; base-uri 'self'; frame-src 'self'; frame-ancestors 'none'; form-action 'self' https://*.duosecurity.com
	Content-Type: text/html; charset=UTF-8
	Date: Sun, 05 Apr 2026 08:46:40 GMT
	Expires: Thu, 19 Nov 1981 08:52:00 GMT
	Pragma: no-cache
	Referrer-Policy: same-origin
	Server: nginx
	Set-Cookie: csrfToken=ed154ab1727451a6923c86d61facb81e77d14b234e830561789897fec2577daccf9005ac69a9161ec06ea7df0b5b13e8b46715b1bf6525827f96699b014d863c; path=/
	Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
	X-Content-Type-Options: nosniff
	X-Download-Options: noopen
	X-Frame-Options: SAMEORIGIN
	X-Gpgauth-Authenticated: false
	X-Gpgauth-Debug: There is no user associated with this key. No key id set.
	X-Gpgauth-Error: true
	X-Gpgauth-Login-Url: /auth/login
	X-Gpgauth-Logout-Url: /auth/logout
	X-Gpgauth-Progress: stage0
	X-Gpgauth-Pubkey-Url: /auth/verify.json
	X-Gpgauth-Verify-Url: /auth/verify
	X-Gpgauth-Version: 1.3.0
	X-Permitted-Cross-Domain-Policies: all
	X-Xss-Protection: 1; mode=block
	Connection: close
	Transfer-Encoding: chunked


