3.4 KiB
3.4 KiB
whatweb --color=never --no-errors -a 3 -v http://auth.lan.ddnsgeek.com:80 2>&1
/root/results/auth.lan.ddnsgeek.com/scans/tcp80/tcp_80_http_whatweb.txt:
WhatWeb report for http://auth.lan.ddnsgeek.com:80
Status : 301 Moved Permanently
Title : <None>
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : RedirectLocation[https://auth.lan.ddnsgeek.com/]
Detected Plugins:
[ RedirectLocation ]
HTTP Server string location. used with http-status 301 and
302
String : https://auth.lan.ddnsgeek.com/ (from location)
HTTP Headers:
HTTP/1.1 301 Moved Permanently
Location: https://auth.lan.ddnsgeek.com/
Date: Tue, 14 Apr 2026 03:26:46 GMT
Content-Length: 17
Connection: close
WhatWeb report for https://auth.lan.ddnsgeek.com/
Status : 200 OK
Title : <None>
IP : 167.179.167.166
Country : NEW ZEALAND, NZ
Summary : HTML5, Script[module], Strict-Transport-Security[max-age=15552000; includeSubDomains; preload], UncommonHeaders[content-security-policy,permissions-policy,referrer-policy,x-content-type-options,x-dns-prefetch-control], X-Frame-Options[SAMEORIGIN], X-XSS-Protection[1; mode=block]
Detected Plugins:
[ HTML5 ]
HTML version 5, detected by the doctype declaration
[ Script ]
This plugin detects instances of script HTML elements and
returns the script language/type.
String : module
[ Strict-Transport-Security ]
Strict-Transport-Security is an HTTP header that restricts
a web browser from accessing a website without the security
of the HTTPS protocol.
String : max-age=15552000; includeSubDomains; preload
[ UncommonHeaders ]
Uncommon HTTP server headers. The blacklist includes all
the standard headers and many non standard but common ones.
Interesting but fairly common headers should have their own
plugins, eg. x-powered-by, server and x-aspnet-version.
Info about headers can be found at www.http-stats.com
String : content-security-policy,permissions-policy,referrer-policy,x-content-type-options,x-dns-prefetch-control (from headers)
[ X-Frame-Options ]
This plugin retrieves the X-Frame-Options value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : SAMEORIGIN
[ X-XSS-Protection ]
This plugin retrieves the X-XSS-Protection value from the
HTTP header. - More Info:
http://msdn.microsoft.com/en-us/library/cc288472%28VS.85%29.
aspx
String : 1; mode=block
HTTP Headers:
HTTP/1.1 200 OK
Content-Length: 3760
Content-Security-Policy: default-src 'self'; base-uri 'self'; connect-src 'self'; frame-ancestors 'none'; frame-src 'none'; object-src 'none'; script-src 'self'; style-src 'self' 'nonce-AkEeWkqnDPAZ8YAnPXsNtFrBiXy4pPTh' 'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='
Content-Type: text/html; charset=utf-8
Date: Tue, 14 Apr 2026 03:27:00 GMT
Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Frame-Options: SAMEORIGIN
X-Xss-Protection: 1; mode=block
Connection: close