fresh autorecon run

This commit is contained in:
2026-04-14 17:49:38 +10:00
parent c8f17a17e6
commit 3c3a192c79
1252 changed files with 4574573 additions and 1993899 deletions
@@ -1,144 +1 @@
WhatWeb report for https://node-red.lan.ddnsgeek.com/
Status : 302 Found
Title : <None>
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : Cookies[authelia_session], HttpOnly[authelia_session], RedirectLocation[https://auth.lan.ddnsgeek.com/?rd=https%3A%2F%2Fnode-red.lan.ddnsgeek.com%2F&rm=GET], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[permissions-policy,referrer-policy,x-content-type-options,x-dns-prefetch-control], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ Cookies ]
Display the names of cookies in the HTTP headers. The
values are not returned to save on space.
String : authelia_session
[ HttpOnly ]
If the HttpOnly flag is included in the HTTP set-cookie
response header and the browser supports it then the cookie
cannot be accessed through client side script - More Info:
http://en.wikipedia.org/wiki/HTTP_cookie
String : authelia_session
[ RedirectLocation ]
HTTP Server string location. used with http-status 301 and
302
String : https://auth.lan.ddnsgeek.com/?rd=https%3A%2F%2Fnode-red.lan.ddnsgeek.com%2F&rm=GET (from location)
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : permissions-policy,referrer-policy,x-content-type-options,x-dns-prefetch-control (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 302 Found
Content-Length: 111
Content-Type: text/html; charset=utf-8
Date: Sun, 05 Apr 2026 12:03:17 GMT
Location: https://auth.lan.ddnsgeek.com/?rd=https%3A%2F%2Fnode-red.lan.ddnsgeek.com%2F&rm=GET
Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
Set-Cookie: authelia_session=L7eTuMPS!7S$!Kmv8L2iID-im_gGmWgb; expires=Sun, 05 Apr 2026 13:03:17 GMT; domain=lan.ddnsgeek.com; path=/; HttpOnly; secure; SameSite=Lax
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close
WhatWeb report for https://auth.lan.ddnsgeek.com/?rd=https%3A%2F%2Fnode-red.lan.ddnsgeek.com%2F&rm=GET
Status : 200 OK
Title : <None>
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : HTML5, Script[module], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,permissions-policy,referrer-policy,x-content-type-options,x-dns-prefetch-control], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ HTML5 ]
HTML version 5, detected by the doctype declaration
[ Script ]
This plugin detects instances of script HTML elements and
returns the script language/type.
String : module
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : content-security-policy,permissions-policy,referrer-policy,x-content-type-options,x-dns-prefetch-control (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 200 OK
Content-Length: 2675
Content-Security-Policy: default-src 'self'; base-uri 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src 'none'; object-src 'none'; script-src 'self'; style-src 'self' 'nonce-LKNHCmIxj8AwkonXEhTGBzOgvnpl81cg' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='
Content-Type: text/html; charset=utf-8
Date: Sun, 05 Apr 2026 12:03:23 GMT
Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close